<node id="657237">
  <nid>657237</nid>
  <type>event</type>
  <uid>
    <user id="27707"><![CDATA[27707]]></user>
  </uid>
  <created>1649856070</created>
  <changed>1649856070</changed>
  <title><![CDATA[PhD Defense by Carter Yagemann]]></title>
  <body><![CDATA[<p>Title: Hardware-Assisted Processor Tracing for Automated Bug Finding and Exploit Prevention</p>

<p>&nbsp;</p>

<p>Date: Thursday, May 5th, 2022</p>

<p>Time: 4:00 PM - 6:00 PM (EST)</p>

<p>Location: <a href="https://gatech.zoom.us/j/96588444591">https://gatech.zoom.us/j/96588444591</a></p>

<p>&nbsp;</p>

<p>Carter Yagemann</p>

<p>Ph.D. Candidate</p>

<p>School of Cybersecurity and Privacy</p>

<p>College of Computing</p>

<p>Georgia Institute of Technology</p>

<p>&nbsp;</p>

<p>Committee:</p>

<p>&nbsp;</p>

<p>Dr. Wenke Lee (Advisor, School of Cybersecurity and Privacy, Georgia Institute of Technology) Dr. Brendan Saltaformaggio (School of Cybersecurity and Privacy, Georgia Institute of Technology) Dr. Mustaque Ahamad (School of Cybersecurity and Privacy, Georgia Institute of Technology) Dr. Alessandro Orso (School of Computer Science, Georgia Institute of</p>

<p>Technology)</p>

<p>Dr. Weidong Cui (Partner Research Manager, Microsoft Research)</p>

<p>&nbsp;</p>

<p>Abstract:</p>

<p>&nbsp;</p>

<p>The proliferation of hardware-supported tracing within commodity processors has opened new doors to observing low-level behaviors in computer software with superior efficiency, transparency, and integrity than prior instrumentation-based solutions. Unfortunately, while it is intuitive that observing program executions can benefit program security analysis, several trade-offs in the design of processor tracing result in serious technical challenges for this purpose, limiting its widespread adoption. First, processor tracing achieves its efficiency by limiting recording to only low-level control flow events, making it difficult to recover all the information necessary to formulate informed security decisions. Second, tracing captures the lowest possible level of program behavior, creating a semantic gap for modeling, detecting, and analyzing software vulnerabilities. Third, the sheer volume of recorded data requires careful management to preserve the low overhead required for feasible deployment within end-host systems.</p>

<p>&nbsp;</p>

<p>To solve the above challenges, I propose control-oriented record and replay, which combines concrete traces with symbolic analysis to uncover vulnerabilities and exploits. To demonstrate the efficacy and versatility of my approach, I first present a system called ARCUS, which is capable of analyzing processor traces flagged by host-based monitors to detect, localize, and provide preliminary patches to developers for memory corruption vulnerabilities. ARCUS has detected 27 previously known vulnerabilities alongside 4 novel cases, leading to the issuance of several advisories and official developer patches. Next, I present MARSARA, a system that protects the integrity of execution unit partitioning in data provenance-based forensic analysis. MARSARA prevents several expertly crafted exploits from corrupting partitioned provenance graphs while incurring little overhead compared to prior work. Finally, I present Bunkerbuster, which extends the ideas from ARCUS into a system capable of proactively hunting for bugs across multiple end-hosts simultaneously.</p>
]]></body>
  <field_summary_sentence>
    <item>
      <value><![CDATA[ Hardware-Assisted Processor Tracing for Automated Bug Finding and Exploit Prevention]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_summary>
  <field_time>
    <item>
      <value><![CDATA[2022-05-05T17:00:00-04:00]]></value>
      <value2><![CDATA[2022-05-05T19:00:00-04:00]]></value2>
      <rrule><![CDATA[]]></rrule>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_time>
  <field_fee>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_fee>
  <field_extras>
      </field_extras>
  <field_audience>
          <item>
        <value><![CDATA[Faculty/Staff]]></value>
      </item>
          <item>
        <value><![CDATA[Public]]></value>
      </item>
          <item>
        <value><![CDATA[Undergraduate students]]></value>
      </item>
      </field_audience>
  <field_media>
      </field_media>
  <field_contact>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_contact>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_phone>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_phone>
  <field_url>
    <item>
      <url><![CDATA[https://gatech.zoom.us/j/96588444591]]></url>
      <title><![CDATA[Zoom]]></title>
            <attributes><![CDATA[]]></attributes>
    </item>
  </field_url>
  <field_email>
    <item>
      <email><![CDATA[]]></email>
    </item>
  </field_email>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <links_related>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>221981</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[Graduate Studies]]></item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>1788</tid>
        <value><![CDATA[Other/Miscellaneous]]></value>
      </item>
      </field_categories>
  <field_keywords>
          <item>
        <tid>100811</tid>
        <value><![CDATA[Phd Defense]]></value>
      </item>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
