publications
publications by categories in reversed chronological order
2024
-
UntrustIDE: Exploiting Weaknesses in VS Code ExtensionsIn Network and Distributed System Security Symposium (NDSS 2024) Feb 2024
2023
-
ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and ActionsIn 32nd USENIX Security Symposium (USENIX Security 23) Aug 2023
2022
-
yoU aRe a Liar://A Unified Framework for Cross-Testing URL ParsersIn Proceedings of the IEEE SecWeb Workshop Jun 2022
-
Characterizing the Security of Github CI WorkflowsIn 31st USENIX Security Symposium (USENIX Security 22) Aug 2022
2020
-
Mininode: Reducing the Attack Surface of Node.js ApplicationsIn 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) Oct 2020