My interests are in any area of computer security. My current focus is
on software security. In particular, my recent focus is on
performing security analysis on program binaries [BitBlaze]. I have also worked in applied cryptography and
network security.
Publications
Peer Reviewed
Automatic Patch-Based Exploit Generation is Possible:
Techniques and Implications.PDF
By David Brumley, Pongsin Poosankam, Dawn Song, and Jiang Zheng.
Proceedings of the IEEE Security and Privacy
Symposium, May, 2008.
Towards Automatic Discovery of Deviations in Binary
Implementations with Applications to Error Detection and Fingerprint
Generation. PDFBiBTeX
By David Brumley, Juan Caballero, Zhenkai Liang, James Newsome, Dawn Song
Proceedings of the 2007 USENIX Security Conference, 2007. * Conference Best Paper Award
Creating Vulnerability Signatures Using Weakest
Pre-conditions. PDFBiBTeX
By David Brumley, Hao Wang, Somesh Jha, Dawn Song
Proceedings of the 2007 Computer Security Foundations Symposium, 2007.
Sweeper: A Lightweight End-to-End System for Defending Against
Fast Worms. PDFBiBTeX
By Joseph Tucek, James Newsome, Shan Lu, Chengdu Huang, Spiros
Xanthos, David Brumley, Yuanyuan Zhou and Dawn Song
In the Proceedings of the 2007 EuroSys Conference,
2007.
A Generic Application-Level Protocol Analyzer and its
Language. PDFBiBTeX
Nikita Borisov, David Brumley, Helen Wang, John Dunagan, Pallavi
Joshi, and Chuanxiong Guo. In the Proceedings of the 14th Annual
Network and Distributed System Security Symposium (NDSS 07)
Efficient and Accurate Detection of Integer-based Attacks. PDFBiBTeX
David Brumley, Tzi-cker Chiueh, Robert Johnson, Huijia Lin, and Dawn Song
In the Proceedings of
the 14th Annual Network and Distributed System Security Symposium
(NDSS 07)
Replayer: Automatic Protocol Replay by Binary Analysis. PDFBiBTeX
James Newsome and David Brumley and Jason Franklin and Dawn Song.
In the Proceedings of the 13th ACM Conference on
Computer and Communications Security (CCS 06)
Towards Attack-Agnostic Defenses. PDFBiBTeX
David Brumley and Dawn Song.
In the Proceedings of the First Workshop on Hot Topics in Security
(HOTSEC 06)
Towards Automatic Generation of Vulnerability-Based Signatures. PDFBibTeX
David Brumley, James Newsome, Dawn Song, Hao Wang, and Somesh Jha.
In the Proceedings of the 2006 IEEE Symposium on Security and Privacy. * Selected by program committe for recommendation to IEEE Transactions on Dependable and
Secure Computing
Vulnerability-Specific Execution Filtering for Exploit Prevention
on Commodity Software. PDFBiBTeX
James Newsome, David Brumley, and Dawn Song.
In the Proceedings of the 13th Annual Network
and Distributed Systems Security Symposium (NDSS 2006).
Design Space and Analysis of Worm Defense Strategies. PDFBiBTeX David Brumley, Li-Hao Liu,
Pongsin Poosankam, and Dawn Song. In the Proceedings of the 2006
ACM Symposium on Information, Computer, and Communication Security
(ASIACCS 2006).
Remote timing attacks are practical. PDFBiBTeX
David Brumley and Dan Boneh.
Journal of Computer Networks, 2005. * This is the updated and more complete journal version of the
2003 USENIX Security paper.
Privtrans: Automatically Partitioning Programs for Privilege
Separation. PDFBiBTeX
David Brumley and Dawn Song.
In the Proceedings of the 13th USENIX Security Symposium, August 2004.
Virtual appliances for deploying and maintaing software. PDFBiBTeX
C. Sapuntzakis, D. Brumley, R. Chandra, N. Zeldovich, J. Chow, M. S. Lam, and M. Rosenblum
In the Proceedings of the 17th Large Installation System Administration Conference (LISA 2003), October 2003.
Remote timing attacks are practical. PDFPSBiBTeX
David Brumley and Dan Boneh
In the Proceedings of the 12th USENIX Security Symposium, August 2003.
* Conference Best Paper Award
Book Chapters
Sting: An End-to-End Self-Healing System for Definding against
Internet Worms.
by David Brumley, James Newsome, and Dawn Song. In
Malware Detection, Springer Publications, 2007.
Articles/Unreviewed
Alias analysis for assembly. PDFPSBiBTeX
David Brumley and James Newsome
Carnegie Mellon University School of Computer Science Technical
Report. CMU-CS-06-180. December, 2006.
A Crash Course in Managing Security.PDF
USENIX ;login, 2001
A Cache-Based System Management Architecture with Virtual
Appliances, Network Repositories, and Virtual Appliance
Transceivers. With Monica Lam, Constantine Sapuntzakis, Ramesh Chandra, Nickolai Zeldovich, Mendel Rosenblum, and James Chow. Issued May 13, 2008. Patent #7373451
Licensed to Moka5
Professional Activities
Program Committee Member
16th
Annual Network and Distributed System Security Symposium (NDSS
2009), San Diego, CA.
4th European Conference on Computer Network Defense
(EC2ND). Dublin, Ireland.