Wed 13 Nov 2019 11:55 - 12:10 at South Park - Student Research Competition - Selected Presentations (Graduate) Chair(s): Jin L.C. Guo, Jie M. Zhang
Machine image sniping is a difficult-to-detect security vulnerability in cloud computing code. When programmatically initializing a machine, a developer must specify which machine image (operating system and file system) to use as the basis for the new machine. The developer should restrict the search to only those machine images which their organization controls: otherwise, an attacker can insert a similar but malicious image into the public database, where it might be selected instead of the image intended by the developer when initializing a new machine. We present a lightweight type and effect system that detects requests to a cloud provider that are vulnerable to an image sniping attack, or proves that no vulnerable request exists in a codebase. We prototyped our type system for Java programs that request Amazon Web Services machines, and evaluated it on more than 500 codebases, detecting 12 vulnerable requests with only 3 false positives.
Iām a Ph.D. student at the University of Washington Paul G. Allen School of Computer Science & Engineering. I work in the PLSE group on lightweight software verification. My advisor is Mike Ernst.
My current work is focused on building type systems on top of the Checker Framework to solve practical problems in software engineering.
Tue 12 NovDisplayed time zone: Tijuana, Baja California change
Wed 13 NovDisplayed time zone: Tijuana, Baja California change
10:40 - 12:20 | Student Research Competition - Selected Presentations (Graduate)Student Research Competition at South Park Chair(s): Jin L.C. Guo McGill University, Jie M. Zhang University College London, UK | ||
10:40 15m | Toward Practical Automatic Program Repair Student Research Competition Ali Ghanbari Iowa State University | ||
10:55 15m | Verifying Determinism in Sequential Programs Student Research Competition Rashmi Mudduluru University of Washington, Seattle | ||
11:10 15m | An Image-inspired and CNN-based Android Malware Detection Approach Student Research Competition Shao Yang Case Western Reserve University | ||
11:25 15m | User Preference Aware Multimedia Pricing Model using Game Theory and Prospect Theory for Wireless Communications Student Research Competition Krishna Murthy Kattiyan Ramamoorthy San Diego State University | ||
11:40 15m | API Design Implications of Boilerplate Client Code Student Research Competition Daye Nam Carnegie Mellon University | ||
11:55 15m | Compile-time detection of machine image sniping Student Research Competition Martin Kellogg University of Washington, Seattle |