Program

NOTE: These presentations were selected on the basis of submitted abstracts by the organizing committee and were not peer-reviewed; there are also no proceedings from this workshop since most presentations are about research in progress.

9:00am to 10:00am

Breakfast and poster session (LWSN Commons Area)

10:00am to 10:10am

Opening remarks (LWSN 1142)

10:10am to 12:10 pm

Session 1: Software Systems Security (LWSN 1142)

  • Dynamic Malware Detection
    Somesh Jha (U. Winsconsin.)
  • The Search for Optimality in Automated Intrusion Response
    Yu-Sung Wu, Saurabh Bagchi.  (Purdue)
  • Candid: Preventing SQL Injection Attacks using Symbolic Queries
    Sruthi Bandhakavi (UIUC), Prithvi Bisht (UIC), P. Madhusudan (UIUC), V.N. Venkatakrishnan (UIC)
  • An Architectural Approach to Preventing Code Injection Attacks
    Ryan Riley, Xuxian Jiang, Dongyan Xu.  (Purdue)
  • Click fraud: slide effects of online advertising
    Mona Gandhi Markus Jakobsson.  (IUB)
  • Usable mandatory integrity protection for operating systems
    Ninghui Li, Ziqing Mao, Hong Chen.  (Purdue)

12:10pm to 02:10pm

Lunch and poster session (LWSN Commons Area)

2:10pm to 3:50pm

Session 2: Privacy and Information Flow (LWSN 1142)

  • TrustBuilder2: A Reconfigurable Framework for Trust Negotiation
    Adam Lee (UIUC), Marianne Winslett (UIUC), and Ken Perano (Sandia National Laboratories).
  • Privacy Graphs: A conceptual model for understanding privacy
    Jodie P. Boyer (UIUC)
  • Towards Efficient Detection of Stepping Stone Attacks With Spread-Spectrum Watermarks
    Amir Houmansadr, Negar Kiyavash, and Nikita Borisov (UIUC)
  • Data Sandboxing: A Technique for Enforcing Confidentiality Policies
    Tejas Khatiwala Raj Swaminathan V.N. Venkatakrishnan (UIC)
  • Do As I SaY! Programmatic Access Control with Explicit Identities
    Andrew Cirillo, Radha Jagadeesan, Corin Pitcher and James Riely (DePaul)

3:50pm to 4:20pm

Break (LWSN Commons Area)

4:20pm to 6:00pm

Session 3: Policies (LWSN 1142)

  • An Automated Framework for Validating Firewall Policy Enforcement
    Adel El-Atawy, Taghrid Samak, Zein Wali, Ehab Al-Shaer  (DePaul), Sheng Li, Frank Lin, and Christopher Pham (Cisco)
  • SayAnything: A New Security Architecture for Authentication
    Jon Solworth (UIC)
  • EXAM -- a Comprehensive Environment for the Analysis of Access Control Policies
    Dan Lin (Purdue), Prathima Rao (Purdue), Elisa Bertino (Purdue), and Jorge Lobo (IBM Research)
  • Consistent Security Policy Enforcement in a Changing Environment
    Alan M. Carroll and Susan Hinrichs (Network Geographics and UIUC)
  • Towards High-level Firewall Policy Language for Multi-domain Networks
    Bin Zhang, Ehab Al-Shaer, Radha Jagadeesan, James Riely, Corin Pitcher (DePaul)