Publications By Year
- Online Signature Generation for Windows Systems
, and
Annual Computer Security Applications Conference (ACSAC) December, 2009. - Practical Techniques for Regeneration and Immunization of COTS Applications
, , , and
Workshop on Recent Advances on Intrusion-Tolerant Systems (WRAITS) June, 2009. - Fast Packet Classification using Condition Factorization
, and
Applied Cryptography and Network Security (ACNS) June, 2009. - An Efficient Black-box Technique for Defeating Web Application Attacks
ISOC Network and Distributed Systems Symposium (NDSS) February, 2009. - Alcatraz: An Isolated Environment for Experimenting with Untrusted Software
, , and
ACM Transactions on Information and System Security (TISSEC) January, 2009.2008
- Fast Packet Classification for Snort
, and
USENIX Large Installation System Administration Conference (LISA) November, 2008. - Anomalous Taint Detection (Extended Abstract)
and
Recent Advances in Intrusion Detection (RAID) September, 2008.
(Full version available as Technical Report SECLAB08-06). - V-NetLab: An Approach for Realizing Logically Isolated Networks for Security Experiments
, , and
Workshop on Cyber Security Experimentation and Test (in conjunction with USENIX Security) (CSET) July, 2008. - Expanding Malware Defense by Securing Software Installations
, , and
Detection of Intrusions, Malware and Vulnerability Analysis (DIMVA) July, 2008. - Data Space Randomization
and
Detection of Intrusions, Malware and Vulnerability Analysis (DIMVA) July, 2008. - On the Limits of Information Flow Techniques for Malware Analysis and Containment
, and
Detection of Intrusions, Malware and Vulnerability Analysis (DIMVA) July, 2008.
(Supercedes SECLAB07-03, November 2007). - Practical Proactive Integrity Preservation: A Basis for Malware Defense
, , and
IEEE Symposium on Security and Privacy (IEEE S&P) May, 2008. - Efficient Fine-Grained Binary Instrumentation with Applications to Taint-Tracking
, and
ACM/IEEE International Symposium on Code Generation and Optimization (CGO) April, 2008. - A Practical Mimicry Attack Against Powerful System-Call Monitors
, and
ACM Symposium on Information, Computer and Communications Security (ASIACCS) March, 2008.
(Supercedes Technical Report SECLAB07-01).2007
- Inferring Higher Level Policies from Firewall Rules
, and
USENIX Large Installation System Administration Conference (LISA) November, 2007.2006
- Address-Space Randomization for Windows Systems
, and
Annual Computer Security Applications Conference (ACSAC) December, 2006. - Provably Correct Runtime Enforcement of Non-Interference Properties
, , and
International Conference on Information and Communications Security (ICICS) December, 2006.
(Supercedes Technical Report SECLAB-04-01, Stony Brook University, March, 2004.).- On Supporting Active User Feedback in P3P
, and
Secure Knowledge Management Workshop (SKM) September, 2006.- A Framework for Building Privacy-Conscious Composite Web Services
, , and
IEEE International Conference on Web Services (ICWS) September, 2006.
(Application Services and Industry Track).- Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks
, and
USENIX Security Symposium (USENIX Security) August, 2006.
(An earlier version appeared as Technical Report SECLAB-05-06, November 2005. Also supercedes Technical Report SECLAB-05-05 A Unified Approach for Preventing Attacks Exploiting a Range of Software Vulnerabilities, August 2005, and Technical Report SECLAB-05-04 Practical dynamic taint analysis for countering input validation attacks on web applications, May 2005, [PDF]).- MCC End-User Management Framework
Technical Report (TR) August, 2006.
Technical Report SECLAB06-01, Secure Systems Laboratory, Stony Brook University.- Dataflow Anomaly Detection
, and
IEEE Symposium on Security and Privacy (IEEE S&P) May, 2006.
(Supercedes Technical Report SECLAB-05-03 Improving Attack Detection in Host-Based IDS by Learning Properties of System Call Arguments, July 2005.).2005
- Automatic Generation of Buffer Overflow Attack Signatures: An Approach Based on Program Behavior Models
and
Annual Computer Security Applications Conference (ACSAC) December, 2005.
(Supercedes Technical Report SECLAB-05-01 An Immune System Inspired Approach for Protection from Repetitive Attacks, March 2005.).- Fast and Automated Generation of Attack Signatures: A Basis for Building Self-Protecting Servers
and
ACM Conference on Computer and Communications Security (CCS) November, 2005.
(Supercedes Technical Report SECLAB-05-02 Automated, Sub-second Attack Signature Generation: A Basis for Building Self-Protecting Servers, May 2005.).- Efficient Techniques for Comprehensive Protection from Memory Error Exploits
, and
USENIX Security Symposium (USENIX Security) August, 2005.- V-NetLab: A Cost-Effective Platform to Support Course Projects in Computer Security
, , , and
Annual Colloquium for Information Systems Security Education (CISSE) June, 2005.- An Approach for Realizing Privacy-Preserving Web-Based Services (Poster)
, , and
14th International World Wide Web Conference (WWW) May, 2005.- A Secure Composition Framework for Trustworthy Personal Information Assistants
, , and
IEEE International Conference on Integration of Knowledge Intensive Multi-Agent Systems (KIMAS) April, 2005.- Automatic Synthesis of Filters to Discard Buffer Overflow Attacks: A Step Towards Realizing Self-Healing Systems (Short Paper)
, and
USENIX Annual Technical Conference (USENIX) April, 2005.- One-way Isolation: An Effective Approach for Realizing Safe Execution Environments
, , and
ISOC Network and Distributed Systems Symposium (NDSS) February, 2005.
(Revised version of conference paper).2004
- Using Predators to Combat Worms and Viruses: A Simulation-Based Study
and
Annual Computer Security Applications Conference (ACSAC) December, 2004.- An Efficient and Backwards-Compatible Transformation to Ensure Memory Safety of C Programs
, and
ACM SIGSOFT International Symposium on the Foundations of Software Engineering (FSE) November, 2004.2003
- Isolated Program Execution: An Application Transparent Approach for Executing Untrusted Programs
, and
Annual Computer Security Applications Conference (ACSAC) December, 2003.
Best paper award.- Model-Carrying Code: A Practical Approach for Safe Execution of Untrusted Applications
, , , and
ACM Symposium on Operating Systems Principles (SOSP) October, 2003.- An Approach for Detecting Self-Propagating Email Using Anomaly Detection
and
Recent Advances in Intrusion Detection (RAID) September, 2003.- SELF: a Transparent Security Extension for ELF Binaries
, and
New Security Paradigms Workshop (NSPW) August, 2003.- Address Obfuscation: An Efficient Approach to Combat a Broad Range of Memory Error Exploits
, and
USENIX Security Symposium (USENIX Security) August, 2003.- Generation of All Counter-Examples for Push-Down Systems
, , and
Formal Description Techniques for Distributed Systems and Communication Protocols (FORTE) June, 2003.2002
- An approach for Secure Software Installation
, , , and
USENIX Large Installation System Administration Conference (LISA) November, 2002.- Specification-based anomaly detection: a new approach for detecting network intrusions
, , , , , and
ACM Conference on Computer and Communications Security (CCS) October, 2002.- Empowering mobile code using expressive security policies
, and
New Security Paradigms Workshop (NSPW) September, 2002.- Model-Based Analysis of Configuration Vulnerabilities
and
Journal of Computer Security (JCS) January, 2002.2001
- Experiences with Specification Based Intrusion Detection System
and
Recent Advances in Intrusion Detection (RAID) October, 2001.- Model-Carrying Code (MCC): A New Paradigm for Mobile-Code Security
, , and
New Security Paradigms Workshop (NSPW) September, 2001.- A Fast Automaton-Based~Method for Detecting Anomalous Program Behaviors
, , and
IEEE Symposium on Security and Privacy (IEEE S&P) May, 2001.2000
- Model-Based Analysis of Configuration Vulnerabilities
and
ACM CCS Workshop on Intrusion Detection Systems (WIDS) October, 2000.- User-Level Infrastructure for System Call Interposition: A Platform for Intrusion Detection and Confinement
and
ISOC Network and Distributed Systems Symposium (NDSS) February, 2000.- Building Survivable Systems: An Integrated Approach based on Intrusion Detection and Damage Containment
, , , , and
DISCEX (DISCEX) February, 2000.1999
- A High-Performance Network Intrusion Detection System
, , and
ACM Conference on Computer and Communications Security (CCS) November, 1999.- Synthesizing Fast Intrusion Detection/Prevention Systems from High-Level Specifications
and
USENIX Security Symposium (USENIX Security) August, 1999.- On Preventing Intrusions by Process Behavior Monitoring
, and
USENIX Intrusion Detection Workshop () April, 1999.1998
- A Specification-Based Approach for Building Survivable Systems
, and
National Information Systems Security Conference (NISSC) October, 1998.- Model-Based Vulnerability Analysis of Computer Systems
and
Verification, Model Checking, and Abstract Interpretation (VMCAI) September, 1998. - On Supporting Active User Feedback in P3P



