Keep me updated: An empirical study on embedded javascript engines in android apps

E Wen, J Zhou, X Luo, G Russello… - Proceedings of the 21st …, 2024 - dl.acm.org
Although JavaScript (JS) has been widely used in mobile development, little is known about
the security implications of utilizing JS engines shipped as native app libraries. In this paper …

Constraint-based diversification of jop gadgets

RM Tsoupidi, RC Lozano, B Baudry - Journal of Artificial Intelligence …, 2021 - jair.org
Modern software deployment process produces software that is uniform, and hence
vulnerable to large-scale code-reuse attacks, such as Jump-Oriented Programming (JOP) …

Automatic diversity in the software supply chain

N Harrand, T Durieux, D Broman, B Baudry - arxiv preprint arxiv …, 2021 - arxiv.org
Despite its obvious benefits, the increased adoption of package managers to automate the
reuse of libraries has opened the door to a new class of hazards: supply chain attacks. By …