
Daniël Trujillo
@thedantrujillo
PhD student in EECS at MIT.
MSc CS from ETH Zürich and BSc CS from VU Amsterdam.
ID: 1680258119325106179
15-07-2023 16:49:28
15 Tweet
142 Takipçi
53 Takip Edilen

Our uncontained paper USENIX Security is online! Find out how the Linux kernel is the "container of" several type confusion bugs, detected by our sanitizer & static analyzer. Joint work by Jakob Koschel Pietro Borrello Daniele Cono D'Elia Herbert Bos Cristiano Giuffrida: vusec.net/projects/uncon…

Our FloatZone paper USENIX Security is online: a branchless memory sanitizer that efficiently catches buffer overflows (+ use-after-frees) with floating-point underflows! Joint work by Floris Gorter @Enrico barberis @teemperor Erik van der Kouwe Cristiano Giuffrida Herbert Bos: vusec.net/projects/float…

Paper from Victor van der Veen & me about using the DRAM row conflict signal as a sidechannel on uncached execution (for protection): dramsec.ethz.ch/papers/dramaqu… - the thought: can we mitigate all uarch side channels by selectively bypassing cache? answer: perhaps, but DRAM sidechannel remains


We built a RISC-V CPU fuzzer that generates test programs in a clever way and it rained CVEs! Cascade brings CI/CD to CPU designers 😀 Check Flavien's thread if you want to know more. To be presented at USENIX Security

Phantom just won a best paper award at MICRO 2024! Phantom shows the security implications of pre-decode speculation that is fundamental in achieving high performance. We are happy and deeply honored! (with johannes Daniël Trujillo)



The first ever end-to-end cross-process Spectre exploit? I worked on this during an internship with grsecurity! An in-depth write-up here: grsecurity.net/cross_process_…
