TU Wien Informatics

20 Years

About

Hello! My research focuses on web security and how to apply formal methods to reason about the security of the web platform at its core. I am also interested in side-channel attacks and their impact on client-side web security.

Outside of my research, I play CTF competitions with STT and w0y, where I explore my passion for the low-level aspects of computer security. Additionally, I participated in the ENISA European Cyber Security Challenge 2021 as a player for Team Portugal.

Role

  • Web Platform Threats: Automated Detection of Web Security Issues With WPT / Bernardo, P., Veronese, L., DALLA VALLE, V., Calzavara, S., Squarcina, M., Adão, P., & Maffei, M. (2024). Web Platform Threats: Automated Detection of Web Security Issues With WPT. In Proceedings of the 33rd USENIX Security Symposium (pp. 757–774).
    Projects: Browsec (2018–2024) / SPFBT (2020–2024) / W4MP (2023–2027)
  • WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms / Veronese, L., Farinier, B., Bernardo, P., Tempesta, M., Squarcina, M., & Maffei, M. (2023). WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms. In 2023 IEEE Symposium on Security and Privacy (SP) (pp. 2761–2779). IEEE. https://doi.org/10.1109/SP46215.2023.10179465
    Projects: Browsec (2018–2024) / ViSP (2019–2023)
  • Systematic Analysis of Programming Languages and Their Execution Environments for Spectre Attacks / Naseredini, A., Gast, S., Schwarzl, M., Sousa Bernardo, P. M., Smajic, A., Canella, C., Berger, M., & Gruss, D. (2022). Systematic Analysis of Programming Languages and Their Execution Environments for Spectre Attacks. In P. Mori, G. Lenzini, & S. Furnell (Eds.), Proceedings of the 8th International Conference on Information Systems Security and Privacy (pp. 48–59). SciTePress. http://hdl.handle.net/20.500.12708/58799