J. Doug Tygar

38 papers A* 4A 3B 1Misc 2Journal 9Unranked 18
YearRankTypeTitle / Venue / Authors
2017 J jnl
Inf. Comput. Secur.
Lena Yuryna Connolly, Michael Lang, John Gathegi, J. Doug Tygar
2016 conf
IWSPA@CODASPY
J. Doug Tygar
2016 conf
HAISA
Lena Yuryna Connolly, Michael Lang, John Gathegi, J. Doug Tygar
2015 conf
AISec@CCS
Alex Kantchelian, Michael Carl Tschantz, Sadia Afroz, Brad Miller, Vaishaal Shankar, Rekha Bachwani, Anthony D. Joseph, J. Doug Tygar
2015 Misc conf
SEC
Lena Yuryna Connolly, Michael Lang, J. Doug Tygar
2015 conf
AISec@CCS
David Fifield, Alexandru Geana, Luis MartinGarcia, Mathias Morbitzer, J. Doug Tygar
2014 conf
AISec@CCS
Brad Miller, Alex Kantchelian, Sadia Afroz, Rekha Bachwani, Edwin Dauber, Ling Huang, Michael Carl Tschantz, Anthony D. Joseph, J. Doug Tygar
2014 J jnl
CoRR
Brad Miller, Ling Huang, Anthony D. Joseph, J. Doug Tygar
2014 conf
NIPS
Alex Kantchelian, Michael Carl Tschantz, Ling Huang, Peter L. Bartlett, Anthony D. Joseph, J. Doug Tygar
2014 Misc conf
SEC
Lena Yuryna Connolly, Michael Lang, J. Doug Tygar
2014 J jnl
CoRR
Michael Carl Tschantz, Sadia Afroz, Vern Paxson, J. Doug Tygar
2013 J jnl
ACM Trans. Sens. Networks
Phoebus Chen, Kirak Hong, Nikhil Naikal, S. Shankar Sastry, J. Doug Tygar, Posu Yan, Allen Y. Yang, Lung-Chung Chang, Leon Lin, Simon Wang, Edgar J. Lobaton, Songhwai Oh, Parvez Ahammad
2013 J jnl
Dagstuhl Manifestos
Anthony D. Joseph, Pavel Laskov, Fabio Roli, J. Doug Tygar, Blaine Nelson
2012 J jnl
Dagstuhl Reports
Anthony D. Joseph, Pavel Laskov, Fabio Roli, J. Doug Tygar, Blaine Nelson
2010 B conf
AINA
Takumi Yamamoto, J. Doug Tygar, Masakatsu Nishigaki
2010 A conf
AISTATS
Blaine Nelson, Benjamin I. P. Rubinstein, Ling Huang, Anthony D. Joseph, Shing-Hon Lau, Steven J. Lee, Satish Rao, Anthony Tran, J. Doug Tygar
2009 A* conf
NDSS
Chris Karlof, J. Doug Tygar, David A. Wagner
2009 J jnl
Comput. Secur.
Yu-Lun Huang, P. H. Lu, J. Doug Tygar, Anthony D. Joseph
2008 conf
UPSEC
Chris Karlof, J. Doug Tygar, David A. Wagner
2008 conf
ICDSC
Phoebus Chen, Parvez Ahammad, Colby Boyer, Shih-I Huang, Leon Lin, Edgar J. Lobaton, Marci Meingast, Songhwai Oh, Simon Wang, Posu Yan, Allen Y. Yang, Chuohao Yeo, Lung-Chung Chang, J. Doug Tygar, Shankar Sastry
2008 conf
LEET
Li Zhuang, John Dunagan, Daniel R. Simon, Helen J. Wang, Ivan Osipkov, J. Doug Tygar
2008 A conf
RAID
Benjamin I. P. Rubinstein, Blaine Nelson, Ling Huang, Anthony D. Joseph, Shing-Hon Lau, Nina Taft, J. Doug Tygar
2008 conf
LEET
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D. Joseph, Benjamin I. P. Rubinstein, Udam Saini, Charles Sutton, J. Doug Tygar, Kai Xia
2008 conf
AISec
Marco Barreno, Peter L. Bartlett, Fuching Jack Chi, Anthony D. Joseph, Blaine Nelson, Benjamin I. P. Rubinstein, Udam Saini, J. Doug Tygar
2008 conf
CSET
Yu-Lun Huang, J. Doug Tygar, Hsiao-Ying Lin, L. Y. Yeh, Hsin-Yi Tsai, Keith Sklower, Shiuh-Pyng Shieh, C. C. Wu, P. H. Lu, S. Y. Chien, Z. S. Lin, L. W. Hsu, Chia-Wei Hsu, C. T. Hsu, Y. C. Wu, M. S. Leong
2007 A* conf
CCS
Chris Karlof, Umesh Shankar, J. Doug Tygar, David A. Wagner
2007 conf
NIPS
Marco Barreno, Alvaro A. Cárdenas, J. Doug Tygar
2005 A conf
SOUPS
Rachna Dhamija, J. Doug Tygar
2004 J jnl
Commun. ACM
Ruzena Bajcsy, Terry Benzel, Matt Bishop, Robert Braden, Carla E. Brodley, Sonia Fahmy, Sally Floyd, Wes Hardaker, Anthony D. Joseph, George Kesidis, Karl N. Levitt, Robert Lindell, Peng Liu, David J. Miller, Russ Mundy, Clifford Neuman, Ron Ostrenga, Vern Paxson, Phillip A. Porras, Catherine Rosenberg, J. Doug Tygar, Shankar Sastry, Daniel F. Sterne, Shyhtsun Felix Wu
2003 book
Adrian Perrig, J. Doug Tygar
1999 A* conf
USENIX Security Symposium
Alma Whitten, J. Doug Tygar
1998 conf
USENIX Workshop on Electronic Commerce
Michael Harkavy, J. Doug Tygar, Hiroaki Kikuchi
1995 J jnl
IEEE Wirel. Commun.
Marvin A. Sirbu, J. Doug Tygar
1995 conf
USENIX Workshop on Electronic Commerce
L. Jean Camp, Marvin A. Sirbu, J. Doug Tygar
1994 conf
S&P
Nevin Heintze, J. Doug Tygar
1989 conf
VL
Allan Heydon, Mark W. Maimone, J. Doug Tygar, Jeannette M. Wing, Amy Moormann Zaremski
1988 conf
VL
Mark W. Maimone, J. Doug Tygar, Jeannette M. Wing
1985 A* conf
DAC
J. Doug Tygar, Ron Ellickson
docs/new_database_schema.md
← Index docs/new_database_schema.md markdown

## LLIL function

| Field Name | Field Type | Description |
|-------------|-------------|-------------|
| function_type | string | The inferred type of the analyzed function, determined by the FunctionTypeAnalysis module (e.g., standard, library, thunk). |
| sha256_llil | string | SHA-256 hash computed from the Low-Level Intermediate Language (LLIL) instructions of the function. |
| ssdeep_llil | string | Fuzzy hash (ssdeep) of the LLIL instruction sequence, used for similarity detection. |
| tlsh_llil | string | TLSH (Trend Locality Sensitive Hash) value of the LLIL instructions, used for approximate matching and similarity comparison. |
| instructions_types_llil | list[string] | List of unique LLIL instruction types (e.g., arithmetic, control flow, memory operations). |
| control_flow_count_llil | integer | Number of control flow instructions in the LLIL representation (e.g., branches, jumps, calls). |
| memory_access_pattern_llil | dict | Patterns of memory access operations detected in the LLIL code (e.g., loads, stores, stack operations). |
| register_usage | dict | Summary of register usage, indicating which registers are read and written in the function. |
| total_reg_reads | integer | Total number of register read operations in the LLIL code. |
| total_reg_written | integer | Total number of register write operations in the LLIL code. |
| data_references_count | integer | Number of data references in the LLIL code (e.g., constants, global variables). |
| max_block_size | integer | Size of the largest basic block in the LLIL representation, measured in number of instructions. |
| num_calls | integer | Total number of function call instructions present in the LLIL code. |
| stack_size | integer | Estimated stack size used by the function, inferred from LLIL analysis. |


## CFG level

| Field Name          | Field Type    | Description                                                                                                                               |
|---------------------|---------------|-------------------------------------------------------------------------------------------------------------------------------------------|
| block_id            | integer       | Unique identifier for the basic block within the function (block_instructions + str(block.start) + str(block.end) + str(function.start)). |
| function_address    | integer       | Starting memory address of the parent function containing this block.                                                                     |
| block_start_address | integer       | Starting address of the basic block in memory.                                                                                            |
| block_end_address   | integer       | Ending address of the basic block in memory.                                                                                              |
| block_size          | integer       | Size of the basic block in bytes (computed as end - start).                                                                               |
| instructions_count  | integer       | Number of instructions contained in the basic block.                                                                                      |
| block_instructions  | string        | MD5 hash of the block's instruction sequence, used for integrity or similarity checks.                                                    |
| predecessor_blocks  | list[u64]     | List of addresses or IDs of predecessor blocks in the control flow graph (CFG).                                                           |
| successor_blocks    | list[u64]     | List of addresses or IDs of successor blocks in the CFG.                                                                                  |
| depth               | integer       | Depth level of the block in the control flow graph, starting from the entry block.                                                        |
| position            | integer       | Sequential position or index of the block within the function’s block map.                                                                |
| branch_type         | string        | Type of branch ending the block (e.g., conditional, unconditional, call, return).                                                         |
| block_type          | string        | Classification of the block (e.g., entry, exit, loop header, regular).                                                                    |
| flags               | dict          | Metadata or attributes extracted from the block (e.g., specific behavior or conditions).                                                  |
| dominators          | list[integer] | List of block addresses or IDs that dominate this block in the control flow graph.                                                        |
| post_dominators     | list[integer] | List of block addresses or IDs that post-dominate this block in the control flow graph.                                                   |
 | measures            | list[tuples]  | List of measures to be defined                                                                                                            |

## Disassembly

| Field Name | Field Type | Description |
|-------------|-------------|-------------|
| disassembled_function_hash | string | SHA-256 hash of the disassembled function string, used as a unique identifier. |
| disassembled_function | string | The disassembled function including instruction addresses. |
| disassembled_function_no_addresses | string | The disassembled function without instruction addresses, containing only the instruction mnemonics and operands. |
| disassembled_function_name | string | The name of the analyzed function. |
| disassembled_function_address | integer | The starting memory address of the disassembled function. |
| instructions_count | integer | Total number of instructions within the disassembled function. |
| function_type | string | The inferred type of the function as determined by the FunctionTypeAnalysis module (e.g., standard, library, thunk). |
| instructions_types | list[string] | List of unique instruction types (e.g., arithmetic, logic, control flow, memory). |
| control_flow_count | integer | Number of control flow instructions (e.g., jumps, calls, returns). |
| memory_access_pattern | dict | Patterns of memory access operations detected in the function (e.g., loads, stores, stack operations). |
| register_usage | dict | Summary of register usage, showing which registers are read from or written to. |
| data_references_count | integer | Count of data references made by the function (e.g., global variables or constants). |
| max_block_size | integer | The size of the largest basic block (in number of instructions). |
| num_calls | integer | Total number of function call instructions. |
| stack_size | integer | Estimated stack size used by the function. |

## Decompilation

| Field Name | Field Type | Description |
|-------------|-------------|-------------|
| decompiled_function_hash | string | SHA-256 hash of the decompiled function code, used as a unique identifier. |
| decompiled_function | string | The decompiled function source code in high-level representation. |
| decompiled_function_name | string | The name of the decompiled function. |
| decompiled_function_prototype | string | The function prototype, including return type, name, and parameters. |
| decompiled_function_address | integer | The starting memory address of the decompiled function. |
| function_type | string | The inferred function type from the FunctionTypeAnalysis module (e.g., standard, library, thunk). |
| functions_caller | list[string] | List of functions that call this function (incoming call references). |
| functions_call | list[string] | List of functions called by this function (outgoing call references). |
| flattened_score | float | Score representing the degree of control-flow flattening detected in the function. |
| mba_score | float | Score representing the presence or intensity of mixed boolean arithmetic (MBA) obfuscation patterns. |