Professor of Computer Science at Brown University and Director of the Secure Systems Lab (SSL) | Brown Hat | Research on OS, systems, and software security | 🏴☠️🇬🇷🇺🇸
Vasileios Kemerlis
@vkemerlis@infosec.exchange
infosec.exchange
Huge congrats to Meghna Pancholi for presenting our paper, Santa -- a language-agnostic approach to system call policy learning for microservices -- at #DIMVA2026 (the Conference on Detection of Intrusions and Malware & Vulnerability Assessment) in Chania, Crete! 🇬🇷
Cloud teams securing microservices are usually stuck choosing between heavy isolation that hurts latency, or system call filters that are either too loose (based on static analysis) or too brittle (based on dynamic tracing). Our work, Santa, resolves this by running two versions of an app side-by-side: a fast production version and a "hardened" security-oracle version (instrumented, for example, to catch memory-safety and concurrency errors). When the production service hits a syscall outside its current policy, Santa re-runs the request against the hardened oracle -- if it's benign, the policy is safely expanded; if it's bogus, an attack is caught and blocked. This lets Santa build tight, workload-specific syscall allow-lists on the fly, without paying the full cost of heavyweight hardening in steady-state traffic.
Joint work with Andreas D. Kellas, Kostis Kaffes, @SteveBellovin@infosec.exchange and Simha Sethumadhavan!
Thanks to @sotiris@ioc.exchange and Michalis Diamantaris for organizing a great conference! It was a real pleasure attending and catching up with so many friends and colleagues along the way.
✳️ Paper: https://cs.brown.edu/people/vpk/papers/santa.dimva26.pdf
💾 Code: https://github.com/meghna-pancholi/santa-ebpf
#dimva2026 #browncs #brownssl
Pratik M. Kamble
@pratikkamble@infosec.exchange
infosec.exchange
Our recent work "Dead Weight: Analyzing Code Bloat and Its Security Implications in WebAssembly Binaries" was presented at DIMVA 2026 in Chania, Greece.
We analyzed over 8,000 real-world WebAssembly binaries and found that 70-85% of compiled functions are never executed. Beyond just taking up space, this dead code leaves a large attack surface for indirect exploitation primitives.
Proceedings to appear in Springer LNCS.
Author preprint: https://www.pratikkamble.com/DIMVA2026_WasmBloat.pdf
Work done with my advisor Dr. Aravind Prakash. Thank you for the guidance and support.
#WebAssembly #SecurityResearch #BinaryAnalysis #DIMVA2026
Stefan Gast
@notbobbytables@infosec.exchange
Postdoc in the group of @lavados at @isec_tugraz #tugraz, focusing on side-channel security. Apart from that, I also post #Linux and #privacy related stuff. Opinions posted here are my own and do not necessarily reflect those of my employer.
infosec.exchange
DIMVA 2026 in Chania really was the perfect ending for my PhD:
Great talks, nice people, amazing food – and all this at a fantastic location!
Currently, I'm extending my stay at Chania for a nice vacation. 🌴
This feels a lot like a closing scene in a movie, after the happy end. 🏖️
#DIMVA2026 #Chania #Crete #Greece #Vacation #PhD
Just back from #DIMVA2026 in Chania, and what a place to spend a conference week. Great talks, good people, and a beautiful spot for all of it.
If you want to know how a security mechanism can actually help performance instead of costing it, read our paper, "Fast and Secure LLC Caches via Spatial Windows".
Paper: https://www.rolandczerny.com/publications/2026-obfuscache/
Chania delivered too: winding streets in the old town, harbourside dinners that ran long, and a quick swim or two between sessions. Good to share the week with @hweissi@infosec.exchange and @notbobbytables@infosec.exchange.
DIMVA Conference
@DIMVAConf@infosec.exchange
The 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA '26) 📅 July 1 to 3, 2026 at 📍Chania, Greece 🇬🇷
infosec.exchange
That's a wrap on DIMVA Conference in Chania! 🎉
Thanks to everyone who helped make #DIMVA2026 in Chania such a success.
We’re happy to announce that DIMVA 2027 will be held in Enschede, Netherlands, hosted by the University of Twente 🇳🇱See you there!
Stefan Gast
@notbobbytables@infosec.exchange
Postdoc in the group of @lavados at @isec_tugraz #tugraz, focusing on side-channel security. Apart from that, I also post #Linux and #privacy related stuff. Opinions posted here are my own and do not necessarily reflect those of my employer.
infosec.exchange
I'm having a great time at #DIMVA2026 in Chania. 🙂
Today, @hweissi@infosec.exchange and @wayna@infosec.exchange from our group presented their papers "FROST: Fingerprinting Remotely using OPFS-based SSD Timing" and "Fast and Secure LLC Caches via Spatial Windows", respectively.
Tomorrow, I will be presenting our mitigation against #SnailLoad-style attacks in "Client-Side Mitigation of Remote Latency Side-Channel Attacks".
#DIMVA #DIMVA2026 #sidechannel #conference #Chania
You've seen all posts