home.social

#binwrap β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #binwrap, aggregated by home.social.

  1. πŸ“’ Last week, I had the pleasure of visiting the beautiful University of Delaware to speak about supply chain security, and reconnect with friends and colleagues!

    My talk, titled "Hardening the Software Supply Chain: Practical Post-Compilation Defenses", was part of the SAVES (Securing Autonomous Vehicle Ecosystems and Supply Chains) workshop at IEEE MOST (International Conference on Mobility: Operations, Services, and Technologies -- ieeemobility.org/MOST2025/). I discussed both the pressing open problems in this rapidly evolving field and the next-generation challenges of protecting critical infrastructure from software supply chain attacks.

    I also shared a few highlights from our recent research efforts over the past five years re: supply-chain security:

    ✳️ BinWrap (ACM ASIACCS 2023, Distinguished Paper Award πŸ†: πŸ“„ cs.brown.edu/~vpk/papers/binwr, πŸ’Ύ github.com/atlas-brown/binwrap) -- HW-assisted (via Intel MPK) sandboxing of native Node.js add-ons.

    ✳️ sysfilter (RAID 2020: πŸ“„ cs.brown.edu/~vpk/papers/sysfi, πŸ’Ύ gitlab.com/brown-ssl/sysfilter) -- Automated system-call policy extraction and enforcement in binary-only applications.

    ✳️ Nibbler (ACSAC 2019: πŸ“„ cs.brown.edu/~vpk/papers/nibbl, πŸ’Ύ gitlab.com/brown-ssl/libfilter) -- Shared-library code debloating.

    (Joint work with Nikos Vasilakis, Sotiris Ioannidis, Georgios Portokalidis, Rodrigo Fonseca, Di Jin, Grigoris Ntousakis, George Christou, David Williams-King, Ioannis Agadakos, and Nicholas DeMarinis.)

    If this area of research interests you, you might also find our recent work on Quack (hardening PHP code against deserialization attacks, NDSS 2024: πŸ“„ cs.brown.edu/~vpk/papers/quack πŸ’Ύ github.com/columbia/quack) worth a look.

    Thank you, Xing Gao and the University of Delaware CIS department for the warm welcome, thoughtful discussions, and the tour of the acclaimed CAR (thecarlab.org) lab!

    #binwrap #sysfilter #nibbler #brownssl

  2. πŸ“’ Last week, I had the pleasure of visiting the beautiful University of Delaware to speak about supply chain security, and reconnect with friends and colleagues!

    My talk, titled "Hardening the Software Supply Chain: Practical Post-Compilation Defenses", was part of the SAVES (Securing Autonomous Vehicle Ecosystems and Supply Chains) workshop at IEEE MOST (International Conference on Mobility: Operations, Services, and Technologies -- ieeemobility.org/MOST2025/). I discussed both the pressing open problems in this rapidly evolving field and the next-generation challenges of protecting critical infrastructure from software supply chain attacks.

    I also shared a few highlights from our recent research efforts over the past five years re: supply-chain security:

    ✳️ BinWrap (ACM ASIACCS 2023, Distinguished Paper Award πŸ†: πŸ“„ cs.brown.edu/~vpk/papers/binwr, πŸ’Ύ github.com/atlas-brown/binwrap) -- HW-assisted (via Intel MPK) sandboxing of native Node.js add-ons.

    ✳️ sysfilter (RAID 2020: πŸ“„ cs.brown.edu/~vpk/papers/sysfi, πŸ’Ύ gitlab.com/brown-ssl/sysfilter) -- Automated system-call policy extraction and enforcement in binary-only applications.

    ✳️ Nibbler (ACSAC 2019: πŸ“„ cs.brown.edu/~vpk/papers/nibbl, πŸ’Ύ gitlab.com/brown-ssl/libfilter) -- Shared-library code debloating.

    (Joint work with Nikos Vasilakis, Sotiris Ioannidis, Georgios Portokalidis, Rodrigo Fonseca, Di Jin, Grigoris Ntousakis, George Christou, David Williams-King, Ioannis Agadakos, and Nicholas DeMarinis.)

    If this area of research interests you, you might also find our recent work on Quack (hardening PHP code against deserialization attacks, NDSS 2024: πŸ“„ cs.brown.edu/~vpk/papers/quack πŸ’Ύ github.com/columbia/quack) worth a look.

    Thank you, Xing Gao and the University of Delaware CIS department for the warm welcome, thoughtful discussions, and the tour of the acclaimed CAR (thecarlab.org) lab!

    #binwrap #sysfilter #nibbler #brownssl

  3. πŸ“’ Last week, I had the pleasure of visiting the beautiful University of Delaware to speak about supply chain security, and reconnect with friends and colleagues!

    My talk, titled "Hardening the Software Supply Chain: Practical Post-Compilation Defenses", was part of the SAVES (Securing Autonomous Vehicle Ecosystems and Supply Chains) workshop at IEEE MOST (International Conference on Mobility: Operations, Services, and Technologies -- ieeemobility.org/MOST2025/). I discussed both the pressing open problems in this rapidly evolving field and the next-generation challenges of protecting critical infrastructure from software supply chain attacks.

    I also shared a few highlights from our recent research efforts over the past five years re: supply-chain security:

    ✳️ BinWrap (ACM ASIACCS 2023, Distinguished Paper Award πŸ†: πŸ“„ cs.brown.edu/~vpk/papers/binwr, πŸ’Ύ github.com/atlas-brown/binwrap) -- HW-assisted (via Intel MPK) sandboxing of native Node.js add-ons.

    ✳️ sysfilter (RAID 2020: πŸ“„ cs.brown.edu/~vpk/papers/sysfi, πŸ’Ύ gitlab.com/brown-ssl/sysfilter) -- Automated system-call policy extraction and enforcement in binary-only applications.

    ✳️ Nibbler (ACSAC 2019: πŸ“„ cs.brown.edu/~vpk/papers/nibbl, πŸ’Ύ gitlab.com/brown-ssl/libfilter) -- Shared-library code debloating.

    (Joint work with Nikos Vasilakis, Sotiris Ioannidis, Georgios Portokalidis, Rodrigo Fonseca, Di Jin, Grigoris Ntousakis, George Christou, David Williams-King, Ioannis Agadakos, and Nicholas DeMarinis.)

    If this area of research interests you, you might also find our recent work on Quack (hardening PHP code against deserialization attacks, NDSS 2024: πŸ“„ cs.brown.edu/~vpk/papers/quack πŸ’Ύ github.com/columbia/quack) worth a look.

    Thank you, Xing Gao and the University of Delaware CIS department for the warm welcome, thoughtful discussions, and the tour of the acclaimed CAR (thecarlab.org) lab!

    #binwrap #sysfilter #nibbler #brownssl

  4. πŸ“’ Last week, I had the pleasure of visiting the beautiful University of Delaware to speak about supply chain security, and reconnect with friends and colleagues!

    My talk, titled "Hardening the Software Supply Chain: Practical Post-Compilation Defenses", was part of the SAVES (Securing Autonomous Vehicle Ecosystems and Supply Chains) workshop at IEEE MOST (International Conference on Mobility: Operations, Services, and Technologies -- ieeemobility.org/MOST2025/). I discussed both the pressing open problems in this rapidly evolving field and the next-generation challenges of protecting critical infrastructure from software supply chain attacks.

    I also shared a few highlights from our recent research efforts over the past five years re: supply-chain security:

    ✳️ BinWrap (ACM ASIACCS 2023, Distinguished Paper Award πŸ†: πŸ“„ cs.brown.edu/~vpk/papers/binwr, πŸ’Ύ github.com/atlas-brown/binwrap) -- HW-assisted (via Intel MPK) sandboxing of native Node.js add-ons.

    ✳️ sysfilter (RAID 2020: πŸ“„ cs.brown.edu/~vpk/papers/sysfi, πŸ’Ύ gitlab.com/brown-ssl/sysfilter) -- Automated system-call policy extraction and enforcement in binary-only applications.

    ✳️ Nibbler (ACSAC 2019: πŸ“„ cs.brown.edu/~vpk/papers/nibbl, πŸ’Ύ gitlab.com/brown-ssl/libfilter) -- Shared-library code debloating.

    (Joint work with Nikos Vasilakis, Sotiris Ioannidis, Georgios Portokalidis, Rodrigo Fonseca, Di Jin, Grigoris Ntousakis, George Christou, David Williams-King, Ioannis Agadakos, and Nicholas DeMarinis.)

    If this area of research interests you, you might also find our recent work on Quack (hardening PHP code against deserialization attacks, NDSS 2024: πŸ“„ cs.brown.edu/~vpk/papers/quack πŸ’Ύ github.com/columbia/quack) worth a look.

    Thank you, Xing Gao and the University of Delaware CIS department for the warm welcome, thoughtful discussions, and the tour of the acclaimed CAR (thecarlab.org) lab!

    #binwrap #sysfilter #nibbler #brownssl

  5. BinWrap won one of the Distinguished Paper awards at #ASIACCS 2023!! Extremely grateful to the technical program committee for this honor -- thank you, ASIACCS! #binwrap #brownssl

  6. πŸ“’ Our work on hardening Node.js against memory-safety vulnerabilities in native (C/C++) add-ons has been accepted at #ASIACCS 2023! Joint work with Nikos Vasilakis, Sotiris Ioannidis, Aarno Labs, Grigoris Ntousakis, and George Christou! #binwrap #brownssl