Prof. Dr.-Ing. Lucas Vincenzo Davi

Lehrstuhlinhaber

Zur Person

Lucas Davi ist Professor für Informatik an der Universität Duisburg-Essen und Direktor des paluno - the Ruhr Institute for Software Technology. Er ist PI im Sonderforschungsbereich (SFB) CROSSING und dem Exzellenzcluster CASA. Er hat aktuell einen ERC Starting Grant für Smart Contract Sicherheit.

Lebenslauf

  • Seit 02/2024
    Direktor des paluno - the Ruhr Institute for Software Technology
  • Seit 12/2022
    W3-Professor für Informatik an der Universität Duisburg-Essen
  • 12/2016-11/2022
    Juniorprofessor für Informatik an der Universität Duisburg-Essen
  • 10/2015-11/2016
    Independent Claude Shannon Research Group Leader für Sichere und Vertrauenswürdige Systeme an der TU Darmstadt
  • 07/2015-09/2015
    Post-Doc am System Security Lab der TU Darmstadt
  • 06/2013-08/2013
    Summer Internship bei Intel Labs, Portland, OR, USA
  • 01/2011-06/2015
    Wissenschaftlicher Mitarbeiter und Doktorand am Center for Advanced Security Research Darmstadt (CASED) - Titel der Dissertation: "Code-Reuse Attacks and Defenses" [PDF]
  • 01/2010-12/2010
    Wissenschaftlicher Mitarbeiter und Doktorand am Horst-Görtz Institut für IT-Sicherheit (HGI)
  • 04/2007-12/2009
    Master of Science in IT-Sicherheit an der Ruhr-Universität Bochum
  • 09/2003-01/2007
    Diplom (FH) Wirtschaftsinformatik an der FOM Neuss & Ausbildung zum Informatikkaufmann bei der ThyssenKrupp Steel AG, Duisburg
  • 2003
    Abitur am Michael-Ende Gymnasium Tönisvorst

Forschungsgebiete

Seine Forschung konzentriert sich auf praktische Problemstellungen der Software- und Systemsicherheit. Insbesondere forscht er an sogenannten Laufzeitangriffen (Software Exploits), die Sicherheitslücken in Software ausnutzen, um Schadverhalten auszulösen.

Publikationen

Filterung nach mehreren Suchwörtern möglich, getrennt durch Leerzeichen.

2026

2025

2024

2023

2022

2021

2020

2019

2018

2017

2016

2015

2014

2013

2012

2011

2010

2009

Gutachtertätigkeiten

Programmkomitee Mitglied

  • NDSS 2026- 33rd Network and Distributed System Security Symposium
  • CCS 2025- 32nd ACM Conference on Computer and Communications Security (Track: Software Security)
  • WiSec 2025 - 18th ACM Conference on Security and Privacy in Wireless and Mobile Networks
  • CCS 2024- 31st ACM Conference on Computer and Communications Security (Track: Blockchain and Distributed Systems)
  • WiSec 2024 - 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks
  • EURO SP 2024- 9th IEEE European Symposium on Security and Privacy
  • USENIX SEC 2024 - 33rd USENIX Security Symposium
  • EURO SP 2023 - 8th IEEE European Symposium on Security and Privacy
  • CCS 2023 - 30th ACM Conference on Computer and Communications Security (Track: Blockchain and Distributed Systems)
  • ASIACCS 2023 - 18th ACM Asia Conference on Computer and Communications Security
  • NDSS 2023 - 30th Network and Distributed System Security Symposium
  • DAC 2022 - 59th Design Automation Conference, Track SEC3. Embedded and Cross-Layer Security
  • PETS 2022 - 22nd Privacy Enhancing Technologies Symposium
  • NDSS 2022 - 29th Network and Distributed System Security Symposium
  • S&P 2022 - 43rd IEEE Symposium on Security and Privacy
  • CCS 2021 - 28th ACM Conference on Computer and Communications Security
  • SecureComm 2021 - 17th EAI International Conference on Security and Privacy in Communication Networks
  • SILM 2021 - 3rd Workshop on the Security of Software/Hardware Interfaces
  • DAC 2021 - 58th Design Automation Conference, Track SEC3. Embedded and Cross-Layer Security
  • USENIX SEC 2021 - 30th USENIX Security Symposium
  • NDSS 2021 - 28th Network and Distributed System Security Symposium
  • PETS 2021 - 21st Privacy Enhancing Technologies Symposium
  • CCS 2020 - 27th ACM Conference on Computer and Communications Security
  • SILM 2020 - 2nd Workshop on the Security of Software/Hardware Interfaces
  • USENIX SEC 2020 - 29th USENIX Security Symposium
  • NDSS 2020 - 27th Network and Distributed System Security Symposium
  • ASIACCS 2020 - 15th ACM Asia Conference on Computer and Communications Security
  • CCS 2019 - 26th ACM Conference on Computer and Communications Security
  • WOOT 2019 - 13th USENIX Workshop on Offensive Technologies
  • ISC 2019 - 22nd Information Security Conference (ISC)
  • ASIACCS 2019 - 14th ACM Asia Conference on Computer and Communications Security
  • WWW 2019 - 30th The Web Conference
  • NDSS 2019 - 26th Network and Distributed System Security Symposium
  • DATE 2019 - 22nd Conference on Design, Automation and Test in Europe (Track A5 Secure Systems, Circuits, and Architectures)
  • CCS 2018 - 25th ACM Conference on Computer and Communications Security
  • RAID 2018 - 21st International Symposium on Research in Attacks, Intrusions and Defenses
  • ISC 2018 - 21st Information Security Conference (ISC)
  • DIMVA 2018 - 15th International Conference on Detection of Intrusions and Malware & Vulnerability Assessment
  • USENIX SEC 2018 - 27th USENIX Security Symposium
  • ASIACCS 2018 - 13th ACM Asia Conference on Computer and Communications Security
  • ROOTS 2017 -  1st Reversing and Offensive-oriented Trends Symposium
  • CARDIS 2017 - 17th Smart Card Research and Advanced Application Conference
  • CCS 2017 - 24th ACM Conference on Computer and Communications Security
  • ACSAC 2017 - 33nd Annual Computer Security Applications Conference
  • CSET 2017 - 10th USENIX Workshop on Cyber Security Experimentation and Test
  • WOOT 2017 - 11th USENIX Workshop on Offensive Technologies
  • EuroSec 2017 - 10th European Workshop on Systems Security
  • DIMVA 2017 - 14th International Conference on Detection of Intrusions and Malware & Vulnerability Assessment
  • MoST 2017 - 6th IEEE Mobile Security Technologies Workshop
  • SEMS 2017 - Workshop on Security for Embedded and Mobile Systems
  • ICDCS 2017 - 37th IEEE International Conference on Distributed Computing Systems
  • ASIACCS 2017 - 12th ACM Asia Conference on Computer and Communications Security
  • SPSM 2016 - 6th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices
  • ACSAC 2016 - 32nd Annual Computer Security Applications Conference
  • RAID 2016 - 19th International Symposium on Research in Attacks, Intrusions and Defenses
  • DIMVA 2016 - 13th International Conference on Detection of Intrusions and Malware & Vulnerability Assessment
  • EuroSec 2016 - 9th European Workshop on Systems Security
  • ICDCS 2016 - 36th IEEE International Conference on Distributed Computing Systems
  • ACNS 2016 - 14th International Conference on Applied Cryptography and Network Security
  • TrustED 2015 - 5th International Workshop on Trustworthy Embedded Devices
  • WOOT 2015 - 9th USENIX Workshop on Offensive Technologies
  • RAID 2015 - 18th International Symposium on Research in Attacks, Intrusions and Defenses
  • AReS - International Conference on Availability, Reliability and Security, 2012 - 2014

Editorial Board

  • TOPS - ACM Transactions on Privacy and Security

Poster/Demo (Co-)Chair

  • ASIACCS 2017 - 12th ACM Asia Conference on Computer and Communications Security

Vorträge

  • Davi, Lucas: Smart Contract Attacks and Defenses. Distinguished Cybersecurity Lecture Series, 19. Jan. 2022, Ohio State University.
  • Davi, Lucas: How Secure are Trusted Execution Environments? Finding and Exploiting Memory Corruption Errors in Enclave Code. OpenS3 Workshop on Building Intelligent Trustworthy Computing Systems: Challenges and Opportunities, 04. Nov. 2021, Darmstadt (Virtual).
  • Davi, Lucas: Finding and Exploiting Bugs in Intel SGX Enclaves. Cybersecurity Seminar Series, Texas A&M Cybersecurity Center, 11. Nov. 2020.
  • Davi, Lucas: Memory Corruption Attacks Against Intel SGX - Invited Talk. DC-Area Anonymity, Privacy, and Security Seminar, 05. Dec. 2019, Washington D.C., USA.
  • Davi, Lucas: Memory Corruption Attacks in the Context of Trusted Execution Environments - Invited Talk. SILM seminar on the Security of Software/Hardware Interfaces, 08. Nov. 2019, INRIA, Rennes, France.
  • Davi, Lucas: Exploiting Software Errors: From Control-Flow to Data-Oriented Exploits. International Summer School on System Security (S3), 04. Sep. 2019, University of Padua, Italy.
  • Davi, Lucas: Your Contract is at Risk: Towards Secure Execution of Smart Contracts. Informatik-Kolloquium, 15. Jul. 2019, Julius-Maximilians-Universität (JMU), Würzburg, Germany.
  • Davi, Lucas: Hardware-Assisted Application Security and Attacks. Huawei Security Technology SAB Summit, 11. Jul. 2019, Munich, Germany.
  • Davi, Lucas: Protecting the Immutable: Can We Prevent Re-Entrancy Attacks Against Deployed Smart Contracts? - Lecture. Lecture Series in Distributed Ledgers and Smart Contracts, 05. Apr. 2019, Darmstadt, Germany.
  • Davi, Lucas: Protecting Existing Smart Contracts Against Attacks - Invited Talk. CYSMICS Picks Workshop, 28. Feb. 2019, UC San Diego, CA, USA.
  • Davi, Lucas: Return and Re-Enter: Modern Software Attack Techniques and Defenses - Invited Talk. Cybersecurity Speaker Series at Northeastern University, 31. Oct. 2018, Boston, USA.
  • Davi, Lucas: Memory Corruption Attacks Against Intel SGX Shielded Software - Invited Talk. CASES: Special Session - Towards Secure Computer Architecture: Understanding Security Vulnerabilities and Emerging Attacks for Better Defenses, 03. Oct. 2018, Torino.
  • Davi, Lucas: Dangerous Bit Flips in Memory: Rowhammer Attacks and Defenses - Keynote. CROSSING Conference 2017 - From Tweets to Quantum, 16. May. 2017, Darmstadt.
  • Davi, Lucas: Control-Flow Attestation of Embedded Systems Software - Invited Talk. Workshop on Hardware Enhancements for Secure Embedded Systems (HESES), 25. Jan. 2017, Stockholm, Sweden.
  • Davi, Lucas: The Continuing Arms Race: A Journey in the World of Runtime Exploits and Defenses - Tutorial. 53rd Design Automation Conference (DAC), 05. Jun. 2016, Austin, TX, USA.
  • Kevin Snow, Lucas Davi: Just-In-Time Code Reuse: The more things change, the more they stay the same. Black Hat USA, 31. Jul. 2013, Las Vegas, USA.

Weitere Funktionen

Publications (Co-)Chair

  • PAC 2017 - 1st IEEE Symposium on Privacy-Aware Computing
  • SPSM 2013 - 3rd ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices

Student Travel Grants Komitee

  • NDSS 2019 - 26th Network and Distributed System Security Symposium

Lokales Organisationskomitee Mitglied

  • CCS 2013 - 20th ACM Conference on Computer and Communications Security
  • ETISS 2011 - 6th European Trusted Infrastructure Summer School

Lehrstuhlinhaber

Prof. Dr.-Ing. Lucas Vincenzo Davi

Telefon: +49 201 18-36445
E-Mail:
Raum: S-GW 212
Sprechstunde:
Do, 16-17 Uhr (Anmeldung erforderlich)