{"650018":{"#nid":"650018","#data":{"type":"event","title":"PhD Proposal by Carter Yagemann","body":[{"value":"\u003Cp\u003ETitle: Hardware-Assisted Processor Tracing for Automated Bug Finding and Exploit Prevention\u003C\/p\u003E\r\n\r\n\u003Cp\u003EDate: Thursday, September 2nd, 2021\u003C\/p\u003E\r\n\r\n\u003Cp\u003ETime: 3:00-4:00pm (EST)\u003C\/p\u003E\r\n\r\n\u003Cp\u003ELocation (Physical): Coda C0903 (Ansley) Location (Virtual): \u003Ca href=\u0022https:\/\/bluejeans.com\/885383300\u0022\u003Ehttps:\/\/bluejeans.com\/885383300\u003C\/a\u003E\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003ECarter Yagemann\u003C\/p\u003E\r\n\r\n\u003Cp\u003EPhD Student, Computer Science\u003C\/p\u003E\r\n\r\n\u003Cp\u003ESchool of Cybersecurity and Privacy\u003C\/p\u003E\r\n\r\n\u003Cp\u003ECollege of Computing\u003C\/p\u003E\r\n\r\n\u003Cp\u003EGeorgia Institute of Technology\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003ECommittee:\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003EDr. Wenke Lee (advisor), School of Cybersecurity and Privacy, Georgia Institute of Technology Dr. Brendan Saltaformaggio, School of Cybersecurity and Privacy, Georgia Institute of Technology Dr. Mustaque Ahamad, School of Cybersecurity and Privacy, Georgia Institute of Technology Dr. Alessandro Orso, School of Computer Science, Georgia Institute of Technology Dr. Weidong Cui, Partner Research Manager, Microsoft Research\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003EAbstract:\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003EThe proliferation of hardware-supported tracing within commodity processors has opened new doors to observing low-level behaviors in computer software with superior efficiency, transparency, and integrity than prior instrumentation-based solutions. Unfortunately, while it is intuitive that observing program executions can benefit program security analysis, several trade-offs in the design of processor tracing result in serious technical challenges for this purpose, limiting its widespread adoption. First, processor tracing achieves its efficiency by limiting recording to only low-level control flow events, making it difficult to recover all the information necessary to formulate informed security decisions. Second, tracing captures the lowest possible level of program behavior, creating a semantic gap for modeling, detecting, and analyzing software vulnerabilities. Third, the sheer volume of recorded data requires careful management to preserve the low overhead required for feasible deployment within end-host systems.\u003C\/p\u003E\r\n\r\n\u003Cp\u003E\u0026nbsp;\u003C\/p\u003E\r\n\r\n\u003Cp\u003EIn this thesis, I propose solutions to the above challenges. First, I present a system called ARCUS, which is capable of analyzing processor traces flagged by host-based IDS monitors to detect, localize, and provide preliminary patches to developers for overflow, use-after-free, double free, and format string vulnerabilities. In my evaluation, ARCUS demonstrates promising results, detecting 27 previously known vulnerabilities alongside 4 novel cases, leading to the issuance of several CVE advisories and official developer patches. Next, I present another system, MARSARA, which protects the integrity of execution unit partitioning (EUP) for data provenance used in forensic analysis.\u003C\/p\u003E\r\n\r\n\u003Cp\u003EMARSARA prevents several expertly crafted exploits from corrupting EUP-partitioned graphs while incurring little overhead compared to existing system auditing frameworks. Finally, I propose Bunkerbuster, a system that proactively searches for and analyzes binary vulnerabilities using processor traces and memory snapshots collected from multiple end-host systems.\u003C\/p\u003E\r\n","summary":null,"format":"limited_html"}],"field_subtitle":"","field_summary":"","field_summary_sentence":[{"value":"Hardware-Assisted Processor Tracing for Automated Bug Finding and Exploit Prevention"}],"uid":"27707","created_gmt":"2021-08-24 13:39:19","changed_gmt":"2021-08-24 13:39:19","author":"Tatianna Richardson","boilerplate_text":"","field_publication":"","field_article_url":"","field_event_time":{"event_time_start":"2021-09-02T16:00:00-04:00","event_time_end":"2021-09-02T17:00:00-04:00","event_time_end_last":"2021-09-02T17:00:00-04:00","gmt_time_start":"2021-09-02 20:00:00","gmt_time_end":"2021-09-02 21:00:00","gmt_time_end_last":"2021-09-02 21:00:00","rrule":null,"timezone":"America\/New_York"},"extras":[],"groups":[{"id":"221981","name":"Graduate Studies"}],"categories":[],"keywords":[{"id":"102851","name":"Phd proposal"}],"core_research_areas":[],"news_room_topics":[],"event_categories":[{"id":"1788","name":"Other\/Miscellaneous"}],"invited_audience":[{"id":"78761","name":"Faculty\/Staff"},{"id":"78771","name":"Public"},{"id":"174045","name":"Graduate students"},{"id":"78751","name":"Undergraduate students"}],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[],"email":[],"slides":[],"orientation":[],"userdata":""}}}