Publications
-
Hardware-Assisted Fault Isolation: Going Beyond the Limits of Software-Based Sandboxing
IEEE Micro Top Picks 2024 : [Preprint]
-
Going Beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFI
Distinguished paper award
ASPLOS 2023: [ Code, Conference Video, HFI Region simulator ]
-
WaVe: a verifiably secure WebAssembly sandboxing runtime
Distinguished paper award
IEEE S&P 2023
-
Half&Half: Demystifying Intel’s Directional Branch Predictors for Fast, Secure Partitioned Execution
IEEE S&P 2023
-
Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern x86
-
Isolation without Taxation: Near-Zero-Cost Transitions for WebAssembly and SFI
POPL 2022: [ Code, Conference video ]
-
Tutorial: Using RLBox to sandbox unsafe C code
IEEE SecDev 2021: [ Presentation ]
-
Swivel: Hardening WebAssembly against Spectre
USENIX Security 2021: [ Code, Conference video ]
-
Довер ́яй, но провер ́яй: SFI safety for native-compiled Wasm
(The title prefix means trust but verify )
NDSS 2021: [ Code, Conference video, How to cite this paper in Latex (handling cyrillic text) ]
-
The Road to Less Trusted Code: Lowering the Barrier to In-Process Sandboxing
Article in USENIX ;login; newsletter Winter 2020
-
RLBox: Retrofitting Fine Grain Isolation in the Firefox Renderer
Distinguished paper award
USENIX Security 2020: [ Extended version, Code (from the paper), Conference video, Longer video ]
RLBox production version: [ Code, Docs Initial Firefox rollout, Full Firefox rollout ]
-
Towards verified programming of embedded devices
Invited paper, DATE 2019
-
USENIX WOOT 2018
-
Finding and Preventing Bugs in JavaScript Bindings
IEEE S&P 2017: [ Code ]
Others (talks, articles, posters, non-refereed)
-
Strange Loop Conference 2022
-
Black Hat USA Conference 2022
-
Invited Poster - RLBox: Retrofitting Fine Grain Isolation in the Firefox Renderer
IEEE S&P 2021
-
Making Software Sandboxing Practical using Language-based Techniques
Article in SIGPLAN PL Perspectives blog, Jul 2021
-
Gobi: WebAssembly as a Practical Path to Library Sandboxing
Unpublished short paper, originally written Jan 2019, updated Nov 2019