wkr | home
Biography
I am a research assistant with the Reliable Software Group, a computer security research group at UC Santa Barbara. I received my B.S. in Computer Science from UCSB in June 2002, and entered the PhD program at UCSB in September 2003. I am currently a primary developer on STAT, a modular, signature-based intrusion detection system. Some other research areas which interest me include anomaly detection, static and dynamic analysis of binary code, vulnerability analysis, reverse engineering, and system hardening.
Contact Information
Recent News
An initial release of pltsec has been made. pltsec is a patch against OpenBSD 3.7-STABLE for i386 that blocks procedure linkage table (PLT) hijacking attempts by detecting malicious writes to the PLT.

The patch can be downloaded here.
After three straight days of attacks, counterattacks, and constant caffeine consumption, Shellphish triumphed among a worthy field of eight teams to take first place at the 2005 DEFCON CTF! Kenshoto, the organizers who were tasked with following the footsteps of the ghettohackers and succeeded beyond all expectations, have posted the final scores on their site. Slashdot has a story on the CTF, along with SecurityFocus (which includes Crispin Cowan's take on the setup), but for the blow-by-blow, read on.
Last Friday, the RSL ran another edition of the UCSB iCTF, with the Tower of Hanoi from the Politecnico di Milano taking top honors in a hard fought contest with Old Eur0pe of Aachen and the Wizards of DoS from TU Darmstadt. Slashdot has a story on the contest, and some teams have put up pictures.

Finally, congratulations are deserved by Vika and Greg for making the entire event run smoothly!
A new release of itrace has been made. The main change has been the addition of memory inspection, as well as numerous bugfixes.

Source can be downloaded here.
The next version of dlmalloc (v2.8) is slated to include a variant of the heap protection patch as a compile-time option. As a result, the versions hosted here are now deprecated in favor of the officially supported version in glibc.