Skip to main content

Showing 1–4 of 4 results for author: Davidson, D

Searching in archive cs. Search in all archives.
.
  1. arXiv:2010.11079  [pdf, other

    cs.CR

    Security Issues and Challenges in Service Meshes -- An Extended Study

    Authors: Dalton A. Hahn, Drew Davidson, Alexandru G. Bardas

    Abstract: Service meshes have emerged as an attractive DevOps solution for collecting, managing, and coordinating microservice deployments. However, current service meshes leave fundamental security mechanisms missing or incomplete. The security burden means service meshes may actually cause additional workload and overhead for administrators over traditional monolithic systems. By assessing the effectivene… ▽ More

    Submitted 21 October, 2020; originally announced October 2020.

  2. arXiv:2003.03471  [pdf, other

    cs.SE cs.CR

    SpellBound: Defending Against Package Typosquatting

    Authors: Matthew Taylor, Ruturaj K. Vaidya, Drew Davidson, Lorenzo De Carli, Vaibhav Rastogi

    Abstract: Package managers for software repositories based on a single programming language are very common. Examples include npm (JavaScript), and PyPI (Python). These tools encourage code reuse, making it trivial for developers to import external packages. Unfortunately, repositories' size and the ease with which packages can be published facilitates the practice of typosquatting: the uploading of a packa… ▽ More

    Submitted 6 March, 2020; originally announced March 2020.

  3. arXiv:1903.02613  [pdf, other

    cs.CR

    Security Issues in Language-based Software Ecosystems

    Authors: Ruturaj K. Vaidya, Lorenzo De Carli, Drew Davidson, Vaibhav Rastogi

    Abstract: Language-based ecosystems (LBE), i.e., software ecosystems based on a single programming language, are very common. Examples include the npm ecosystem for JavaScript, and PyPI for Python. These environments encourage code reuse between packages, and incorporate utilities - package managers - for automatically resolving dependencies. However, the same aspects that make these systems popular - ease… ▽ More

    Submitted 30 November, 2021; v1 submitted 6 March, 2019; originally announced March 2019.

  4. arXiv:1602.08410  [pdf, other

    cs.CR

    Towards Least Privilege Containers with Cimplifier

    Authors: Vaibhav Rastogi, Drew Davidson, Lorenzo De Carli, Somesh Jha, Patrick McDaniel

    Abstract: Application containers, such as Docker containers, have recently gained popularity as a solution for agile and seamless deployment of applications. These light-weight virtualization environments run applications that are packed together with their resources and configuration information, and thus can be deployed across various software platforms. However, these software ecosystems are not conduciv… ▽ More

    Submitted 26 February, 2016; originally announced February 2016.