BitBlaze Publications

[Refereed Papers]][Books and Book Chapters] [Technical Reports][Back to BitBlaze]


Refereed Papers

"Dispatcher: Enabling Active Botnet Infiltration using Automatic Protocol Reverse-Engineering"
Juan Caballero, Pongsin Poosankam, Christian Kreibich, and Dawn Song.. In Proceedings of the 16th ACM Conference on Computer and Communication Security, November 2009
PDF BIB Project
"Emulating Emulation-Resistant Malware"
Min Gyung Kang, Heng Yin, Steve Hanna, Steve McCamant, and Dawn Song. In Proceedings of the 2nd Workshop on Virtual Machine Security, November 2009
PDF
"Towards Generating High Coverage Vulnerability-Based Signatures with Protocol-Level Constraint-Guided Exploration"
Juan Caballero, Zhenkai Liang, Pongsin Poosankam, and Dawn Song.. In Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection, September 2009
PDF BIB Project
"Loop-Extended Symbolic Execution on Binary Programs"
Prateek Saxena, Pongsin Poosankam, Stephen McCamant, and Dawn Song. In Proceedings of the ACM/SIGSOFT International Symposium on Software Testing and Analysis, July 2009

PDF BIB Project
"Measuring Channel Capacity to Distinguish Undue Influence"
James Newsome, Stephen McCamant, and Dawn Song. In Proceedings of the Fourth ACM SIGPLAN Workshop on Programming Languages and Analysis for Security, June 2009.

PDF BIB Project
"Secure Content Sniffing for Web Browsers or How to Stop Papers from Reviewing Themselves"
Adam Barth, Juan Caballero, and Dawn Song. In Proceedings of the IEEE Symposium on Security and Privacy, May 2009.

PDF BIB Project
"BinHunt: Automatically Finding Semantic Differences in Binary Programs"
Debin Gao, Michael K. Reiter, and Dawn Song. In Proceedings of the 4th International Conference on Information Systems Security, December 2008.

PDF BIB
"BitBlaze: A New Approach to Computer Security via Binary Analysis"
Dawn Song, David Brumley, Heng Yin, Juan Caballero, Ivan Jager, Min Gyung Kang, Zhenkai Liang, James Newsome, Pongsin Poosankam, and Prateek Saxena. In Proceedings of the 4th International Conference on Information Systems Security, December 2008.
* Keynote Invited Paper

PDF BIB
"Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications"
David Brumley, Pongsin Poosankam, Dawn Song, and Jiang Zheng. In Proceedings of the IEEE Symposium on Security and Privacy, May 2008.

PDF BIB Project
"HookFinder: Identifying and Understanding Malware Hooking Behaviors"
Heng Yin, Zhenkai Liang, and Dawn Song. In Proceedings of the 15th Annual Network and Distributed System Security Symposium, February 2008.

PDF BIB Project
"Polyglot: Automatic Extraction of Protocol Message Format using Dynamic Binary Analysis."
Juan Caballero, Heng Yin, Zhenkai Liang, and Dawn Song. In Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS), October 2007.

PDF BIB Project
"Panorama: Capturing System-wide Information Flow for Malware Detection and Analysis."
Heng Yin, Dawn Song, Manuel Egele, Christopher Kruegel, and Engin Kirda. In Proceedings of ACM Conference on Computer and Communication Security, Oct 2007.

PDF BIB Project
"Renovo: A Hidden Code Extractor for Packed Executables."
Min Gyung Kang, Pongsin Poosankam, and Heng Yin. In Proceedings of the 5th ACM Workshop on Recurring Malcode (WORM), Oct 2007.

PDF BIB Project
"Towards Automatic Discovery of Deviations in Binary Implementations with Applications to Error Detection and Fingerprint Generation."
David Brumley, Juan Caballero, Zhenkai Liang, James Newsome, and Dawn Song. In Proceedings of USENIX Security Symposium, Aug 2007.
* Conference Best Paper Award

PDF BIB Project
"Creating Vulnerability Signatures Using Weakest Pre-conditions."
David Brumley, Hao Wang, Somesh Jha, and Dawn Song. In Proceedings of Computer Security Foundations Symposium, Jul 2007.

PDF BIB Project
"Dynamic Spyware Analysis."
Manuel Egele, Christopher Kruegel, Engin Kirda, Heng Yin, and Dawn Song. In Proceedings of USENIX Annual Technical Conference, Jun 2007.

PDF BIB Project
"Sweeper: a Lightweight End-to-End System for Defending against Fast Worms."
Joseph Tucek, James Newsome, Shan Lu, Chengdu Huang, Spiros Xanthos, David Brumley, Yuanyuan Zhou, and Dawn Song. In Proceedings of European Conference on Computer Systems (EuroSys), Mar 2007.

PDF BIB Project
"Replayer: Automatic Protocol Replay by Binary Analysis."
James Newsome, David Brumley, Jason Franklin, and Dawn Song. In Proceedings of the 13th ACM Conference on Computer and Communications Security (CCS), October 2006.

PDF BIB Project
"Towards Automatic Generation of Vulnerability Signatures."
David Brumley, James Newsome, Dawn Song, Hao Wang, and Somesh Jha. In Proceedings of the IEEE Symposium on Security and Privacy, May 2006.

PDF BIB Project
"Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity Software."
James Newsome, David Brumley, and Dawn Song. In Proceedings of the 13th Annual Network and Distributed Systems Security Symposium (NDSS), 2006.

PDF BIB Project
"Dynamic Taint Analysis: Automatic Detection, Analysis, and Signature Generation of Exploit Attacks on Commodity Software"
James Newsome and Dawn Song. In Proceedings of the Network and Distributed Systems Security Symposium, Feb 2005.

PDF BIB Project

Books and Book Chapters

"Automatically Identifying Trigger-based Behavior in Malware"
David Brumley, Cody Hartwig, Zhenkai Liang James Newsome, Dawn Song, and Heng Yin. Book chapter in "Botnet Analysis and Defense", Editors Wenke Lee et. al., 2007.

PDF BIB Project
"Sting: an End-to-End Self-healing System for Defending against Internet Worms"
David Brumley, James Newsome, and Dawn Song. Book chapter in "Malware Detection and Defense", Editors Christodorescu, Jha, Maughn, Song, 2007.

PDF BIB Project

Technical Reports

"Extracting Models of Security-Sensitive Operations using String-Enhanced White-Box Exploration on Binaries"
Juan Caballero, Stephen McCamant, Adam Barth, and Dawn Song. UCB/EECS-2009-36, EECS Department, University of California, Berkeley, March 6, 2009.

PDF BIB
"BitScope: Automatically Dissecting Malicious Binaries"
David Brumley, Cody Hartwig, Min Gyung Kang, Zhenkai Liang James Newsome, Pongsin Poosankam, Dawn Song, and Heng Yin. CS-07-133, School of Computer Science, Carnegie Mellon University, March 18, 2007.

PDF BIB Project
"Sting: an End-to-End Self-healing System for Defending against Zero-day Worm Attacks on Commodity Software."
James Newsome, David Brumley, and Dawn Song. Technical Report CMU-CS-05-191.

PDF BIB Project