בחסות

הכנס הארצי למדעי המחשב והמידע

בחסות הפקולטה למדעי המחשב והמידע ע"ש שטיין
{{tariff.title}}

{{tariff.validUntilDescription}}

 
מחיר

הרשמו עכשיו

Cyber Security Track

The session will be dedicated to the security of the online space, an area of ​​increasing importance in an era where infrastructure, services, organizations, and daily life depend on complex digital systems. The session will feature invited lectures by senior researchers in the field, who will present current research and challenges in both theoretical and practical aspects of cybersecurity, privacy, and information systems protection.
In addition to the invited talks, the conference will include a special Graduate Research Session. 

Invited Speakers

Photo of Anat Bremler-Barr

Keynote Speaker: Anat Bremler-Barr

Blavatnik School of Computer Science and AI, Tel Aviv University

Logical Vulnerabilities: The Blind Spots of Network Protocol Design

Abstract

In this talk, we will explore logical vulnerabilities and their root weaknesses. We will cover several of our recently discovered vulnerabilities, starting with the MadeYouReset attack, a novel Denial of Service (DoS) attack on HTTP/2 servers. We will demonstrate that the underlying logic of the notorious Rapid Reset attack, which was actively exploited as a zero-day vulnerability, was never fully understood, ultimately leaving the door open to the MadeYouReset vulnerability.

Next, we will showcase newly discovered logical vulnerabilities in DNS, specifically focusing on the CacheFlush attack, which triggers a DDoS attack by flushing the resolver cache. We will show how this logical weakness can be weaponized to create a side-channel attack on DNS forwarders. Finally, we will conclude by discussing the key lessons these logical vulnerabilities teach us about designing secure network protocols. The work covered in this talk was conducted in collaboration with Yehuda Afek, Gal Bar-Nachum, Shoham Danino, Yaniv Harel, Amit Klein, Gilad Moav, and Yuval Shavitt.

Bio

Prof. Anat Bremler-Barr is a Full Professor at the Blavatnik School of Computer Science and AI at Tel Aviv University. Her current research focuses on DNS security, cloud security, IoT security, DDoS mitigation, and CVE analysis. In 2001, she co-founded Riverhead Networks Inc., a company providing systems to protect against Denial-of-Service attacks, which was acquired by Cisco Systems in 2004. In 2010, she was awarded a prestigious European Research Council (ERC) Starting Grant for her research into Deep Packet Inspection of Next-Generation Network Devices. She is the founder and director of the Deepness Lab, which focuses on designing reliable and efficient networks and network devices.

Photo of Amit Klein

Amit Klein

School of Computer Science and Engineering, Hebrew University of Jerusalem

You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network Stack

Abstract

This research is the first holistic analysis of the algorithmic security of the Google Fuchsia/gVisor network stack. Google Fuchsia is a new operating system developed by Google in a "clean slate" fashion. It is conjectured to eventually replace Android as an operating system for smartphones, tablets, and IoT devices. Fuchsia is already running in millions of Google Nest Hub consumer products. Google gVisor is an application kernel used by Google's App Engine, Cloud Functions, Cloud ML Engine, Cloud Run, and Google Kubernetes Engine (GKE). Google Fuchsia uses the gVisor network stack code for its TCP/IP implementation.

We report multiple vulnerabilities in the algorithms used by Fuchsia/gVisor to populate network protocol header fields, specifically the TCP initial sequence number, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID fields. In our holistic analysis, we show how a combination of multiple attacks results in the exposure of a PRNG seed and a hashing key used to generate the above fields. This enables an attacker to predict future values of the fields, which facilitates several network attacks. Our work focuses on web-based device tracking based on the stability and relative uniqueness of the PRNG seed and the hashing key. We demonstrate our device tracking techniques over the Internet with browsers running on multiple Fuchsia devices, in multiple browser modes (regular/privacy), and over multiple networks (including IPv4 vs. IPv6). Our tests verify that device tracking for Fuchsia is practical and yields a reliable device ID.

We conclude with recommendations on mitigating the attacks and their root causes. We reported our findings to Google, which issued CVEs and patches for the security vulnerabilities we disclosed.

Bio

Prof. Amit Klein is a faculty member in the Hebrew University school of computer science and engineering, and the head of the Federmann cyber security research center. Prior to the faculty position in the Hebrew University, he was a post-doctoral researcher at the Hebrew University, hosted by Prof. Michael Schapira. Prior to that, Amit earned a Ph.D. in Computer Science in Bar Ilan University, advised by Prof. Benny Pinkas. Prior to that, Amit spent more than 20 years in four cyber security startups, mostly in executive positions (VP Security Research for Safebreach; CTO of Trusteer, acquired by IBM for $650,000,000; Chief Scientist for Cyota, acquired by RSA Security for $145,000,000; Director of Security for Sanctum). Amit is a graduate of the IDF Talpiot Programme, with B.Sc. in Mathematics and Physics (double major), magna cum laude, from the Hebrew University.

Photo of Yisroel Mirsky

Yisroel Mirsky

Stein Faculty of Computer and Information Science, Ben-Gurion University

AI Agents: You Can’t Defend What You Can’t See

Abstract

As LLMs become increasingly agentic, defenders face a basic visibility problem: we can observe what models are given and what they produce, but we often cannot see what they are actually interpreting, pursuing, or trying to achieve. For security, that gap matters. An agent can misunderstand its environment, follow a hidden objective, or carry out harmful behavior while everything at the surface appears perfectly normal.

In this talk, I present three recent A* papers from our lab that explore this problem from different angles. We begin with Familiar Pattern Attacks (NDSS ’26), which uncover a blind spot in code agents and reasoning models: familiar programming patterns can cause LLMs to confidently miss critical logic, allowing adversaries to hide behavior from or hijack LLM-based static analysis. We then move from machine reasoning to human manipulation with Love, Lies, and Language Models (USENIX Security ’26), showing that LLM agents are already entering organized social-engineering operations and can outperform human operators at building trust and eliciting compliance—while existing safeguards fail because the malicious behavior looks like ordinary, friendly conversation.

These works point to the same underlying challenge: the dangerous part of an agent may not be visible in its inputs or outputs. I conclude with our recent EMNLP ’26 work showing that the active instructions, constraints, and hidden objectives steering an LLM can be recovered in plain language from its internal activations, suggesting a path toward safeguards that monitor what a model is actually trying to do—not just what it says.

Bio

Yisroel Mirsky is a tenured Assistant Professor and Zuckerman Faculty Scholar in the Institute of Software Systems and Security at Ben-Gurion University, where he leads the Offensive AI Research Lab at CBG. His main research interests include AI safety, AI agent security, deepfakes and adversarial machine learning. Dr. Mirsky is an ERC-STG 2025 recipient and a board member of the Coalition for AI Safety (CoSAI) with leading AI industry members such as Google, NVIDIA, Microsoft, OpenAI and Anthropic. He has published his work in some of the best security venues: Black Hat, DEF CON, RSA, USENIX, CCS, NDSS, CSF, AI Security Forum, AISec, Code Blue, etc. His research has also been featured in many well-known media outlets: Wired, Ars Technica, Tech Crunch, The Wall Street Journal, Forbes, Popular Science, and Scientific American. His work has earned numerous accolades over the years, including more than $10,000 in bug bounties for discovering AI security vulnerabilities. Some of his works include the exposure of vulnerabilities in the US 911 emergency services and exposing the threat of deepfakes in medical scans, both featured in The Washington Post.

Photo of Eyal Ronen

Eyal Ronen

Blavatnik School of Computer Science and AI, Tel Aviv University

Microarchitectural Weird Machines

Abstract

Over the last few decades, computers have become incredibly complex. Modern computers are an intricate combination of hundreds of microarchitectural components, such as caches, execution engines, and various predictors. These are all orchestrated to achieve the ever-increasing performance we expect as the field advances. As in many complex systems, the complexity of modern computers' microarchitectural components and their interaction gives rise to emergent behavior that was not anticipated from the design. Microarchitectural side-channel and speculative execution attacks (such as Spectre and Meltdown) exploit this behavior to compromise cryptographic keys.

In this talk, we demonstrate that the microarchitectural state is complex enough to support arbitrary computations hidden from the user at the architectural state. The main mechanism we use is weird gates, which are software constructs whose execution performs logical functions on cache state. We then show how these gates can be exploited to improve the state-of-the-art in microarchitectural attacks, and conclude by discussing how more advanced constructions can be realized.

Bio

Eyal is a faculty member at TAU's School of CS and AI. His research interests are in cybersecurity and applied cryptography. Eyal is interested in analyzing and designing real-world implementations of cryptographic and security protocols and primitives (both in software and hardware). In particular, his research spans side-channel attacks (e.g., power analysis and cache attacks), cryptographic protocols (e.g., TLS and WPA3), cryptanalysis of cryptographic primitives (e.g., AES), and machine learning security.

Photo of Itsik Mantin

Itsik Mantin

‏ Head of AI Security Research, Intuit

AI Moved My Cheese. Now What?

Abstract

The question is no longer whether AI can do serious technical work. It writes production code, autonomously finds vulnerabilities (and evades sandboxes), finds new cryptanalysis results and solves long-standing mathematical problems. Its impact is already visible in career choices, research paths and software markets.

Security is no exception. Tools from leading vendors, like Claude Mythos, are changing what vulnerability research looks like, and the Hugging Face incident last July was a reminder that these capabilities do not always stay where we put them.

In this talk, I will explore how AI's growing ability to get things done is forcing technology companies, technology builders and security teams to adapt and transform towards a moving target that the tech world is still struggling to define.

I will also share my perspective on the role of academia in this transformation..

Bio

Itsik Mantin is a technology leader and an expert in applied security research. His work mostly includes threat research and security innovation, and sits at the intersection of academic research and real-world technology, with a focus on turning research ideas into practical solutions.

He holds an M.Sc. in Applied Mathematics and Computer Science from the Weizmann Institute of Science. Over the past 25 years, his work has spanned cryptography research, algorithms, machine learning, AI and cybersecurity across small startups, leading Israeli cybersecurity companies and global enterprises..

His work includes academic publications in cryptography and AI security, more than 40 patents and presentations at leading cryptography, AI and security conferences, including Eurocrypt, Asiacrypt, FSE, Black Hat, RSAC, OWASP, the Berkeley Agentic AI Summit and BSides events in six locations.

Today, Itsik leads research on threats and defenses for AI systems, including agentic AI, at Intuit, a global financial technology company. This work gives him a firsthand view of the global transformation driven by the rapid adoption of advanced AI technologies.

Schedule

Time Session
8:30-9:30 Gathering and Reception
9:30-11:30 Cyber Security Track Session I
↪ 9:30-9:45 ↪ Opening words: Yuval Elovici, Ben-Gurion University of the Negev
↪ 9:45-10:20 Keynote: Anat Bremler-Barr, Tel Aviv University
↪ 10:20-10:55 Amit Klein, Hebrew University of Jerusalem
↪ 10:55-11:30 Yisroel Mirsky, Ben-Gurion University of the Negev
11:45-13:15 Joint Plenary Session
13:15-14:15 Lunch
14:15-16:50 Cyber Security Track Session II
↪ 14:30-15:30 Graduate Research Session chaired by Itamar Levi, Bar Ilan University 
↪ 15:30-16:10 Eyal Ronen, Tel Aviv University
↪ 16:10-16:50 Itsik Mantin, Intuit

Graduate Research Session

In addition to the invited talks, the conference will include a special Graduate Research Session. We encourage suitable students to submit their work for consideration by filling in this form.

Session Chair: Itamar Levi, Bar Ilan University 

מושב באבטחת המרחב המקוון

במסגרת הכנס הארצי למדעי המחשב והמידע, אשר יתקיים ב08/10/26, אנו נקיים מושב באבטחת המרחב המקוון.  המושב יוקדש לאבטחת המרחב המקוון, תחום בעל חשיבות הולכת וגוברת בעידן שבו תשתיות, שירותים, ארגונים וחיי היומיום תלויים במערכות דיגיטליות מורכבות. במסגרת המושב יתקיימו הרצאות מוזמנות של חוקרות וחוקרים בכירים בתחום, אשר יציגו מחקרים ואתגרים עדכניים הן בהיבטים תיאורטיים והן בהיבטים פרקטיים של אבטחת סייבר, פרטיות והגנה על מערכות מידע.

בנוסף להרצאות המוזמנות, יוקצה במושב זמן ל״במת תלמידי מחקר״, שבה יציגו תלמידות ותלמידי מחקר עבודות עדכניות בנושאים אלה.

{{tariff.title}}

{{tariff.validUntilDescription}}

 
מחיר

הרשמו עכשיו
ראש המושב
פרופ׳ יוסי אורן

פרופ׳ יוסי אורן

פרופסור חבר במכון לתוכנה, מערכות ואבטחה.
yos@bgu.ac.il