Fuzzing and Securing the Server-Side Event-Driven Architecture, DONGYOON LEE, Virginia Polytechnic Institute

Speaker: Dongyoon Lee
Affiliation: Virginia Polytechnic Institute

ABSTRACT: The software development community is adopting the Event-Driven Architecture (EDA) to provide scalable web services, most prominently through Node.js. Though the EDA scales well, it comes with two inherent risks: concurrency errors and Event Handler Poisoning (EHP) Denial of Service attacks. Just as thread-based programs can have concurrency errors between unordered threads, event-driven programs may have them between unordered events. When an EDA-based server multiplexes many clients onto few threads, a blocked thread (EHP) renders the whole server unresponsive. In this talk, I present Node.fz and Node.cure to address these problems. First, Node.fz provides a schedule fuzzing test tool that randomly perturbs the execution of a Node.js program, allowing Node.js developers to explore a variety of possible schedules during testing. Second, Node.cure proposes First-Class Timeouts, which incorporates timeouts at the EDA framework level, defending Node.js applications against all known EHP attacks. BIO: Dongyoon Lee is an Assistant Professor in the Computer Science department at Virginia Tech. He obtained the M.S. (2009) and Ph.D. (2013) degrees in Computer Science and Engineering at the University of Michigan, Ann Arbor. Before joining Virginia Tech, he worked as an academic visitor in the next generation middleware platforms department at IBM T. J. Watson Research Center (Fall 2013). He also interned in the operating systems group at Microsoft Research, Redmond (Summer 2012), and in the systems analysis and verification department at NEC Laboratories America (Summer 2011). He received a Virginia Tech ICTAS Junior Faculty Award in 2017, a Google Research Award in 2015, a ProQuest Distinguished Dissertation Award in 2013, and a VMWare Graduate Fellowship in 2011. His co-authored papers won the best student paper finalist at SC 2016, and the best paper at ASPLOS 2011.

 Hosted by Professor Harry Xu

REFRESHMENTS at 3:45 pm, SPEAKER at 4:15 pm

Date/Time:
Date(s) - Oct 11, 2018
4:15 pm - 5:45 pm

Location:
3400 Boelter Hall
420 Westwood Plaza Los Angeles California 90095