VLDB 2026 Research / reviewers in the wild / expert
Matt Blaze
dblp:05/6499
· DBLP profile ↗
31ranked-venue papers
14as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 11 first-authorSystems, architecture and hardware · 3 · 2 first-authorComputer networks · 2Theory of computation · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
15 papers |
Network security · 49% Systems and software security · 22% Cryptographic protocols and secure computation · 19% | |
| Software engineering, system software, and programming languages
2 papers |
Software maintenance and evolution · 60% Empirical software engineering · 36% Operating systems · 3% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Distributed systems · 78% Storage systems · 22% | |
| Computer networks
3 papers |
Internet architecture and protocols · 100% |
Topics — the 20 heaviest of 27, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability analysis |
0.2 | 1 | 2014 | Moving Targets: Security and Rapid-Release in Firefox · CCS 2014 |
Network security
wireless network security |
0.1 | 1 | 2011 | Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System · USENIX Security Symposium 2011 |
Network security
anonymity networks |
0.1 | 1 | 2010 | A3: An Extensible Platform for Application-Aware Anonymity · NDSS 2010 |
Empirical software engineering
mining software repositories |
0.1 | 1 | 2014 | Moving Targets: Security and Rapid-Release in Firefox · CCS 2014 |
Empirical software engineering › mining software repositories › vulnerability analysis
vulnerability data analysis |
0.1 | 1 | 2014 | Moving Targets: Security and Rapid-Release in Firefox · CCS 2014 |
Distributed systems
distributed coordination |
0.0 | 2 | 2009 | Veracity: Practical Secure Network Coordinates via Vote-based Agreements · USENIX ATC 2009 Decentralized Trust Management · S&P 1996 |
Cryptographic primitives and cryptanalysis
encryption |
0.0 | 1 | 2011 | Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System · USENIX Security Symposium 2011 |
Cryptographic protocols and secure computation › key exchange
authenticated key exchange |
0.0 | 1 | 2002 | Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002 |
Cryptographic protocols and secure computation
key exchange |
0.0 | 1 | 2002 | Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002 |
Cryptographic protocols and secure computation › key exchange
perfect forward secrecy |
0.0 | 1 | 2002 | Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002 |
Authentication and access control
trust management |
0.0 | 2 | 2001 | Trust Management for IPsec · NDSS 2001 Decentralized Trust Management · S&P 1996 |
Distributed systems › distributed system security › trust management
decentralized trust management |
0.0 | 1 | 1996 | Decentralized Trust Management · S&P 1996 |
Distributed systems › distributed system security
trust management |
0.0 | 1 | 1996 | Decentralized Trust Management · S&P 1996 |
Cryptographic protocols and secure computation › key management
key escrow |
0.0 | 1 | 1994 | Protocol Failure in the Escrowed Encryption Standard · CCS 1994 |
Network security › secure communication
network-layer security |
0.0 | 1 | 1993 | The Architecture and Implementation of Network Layer Security in UNIX · USENIX Security Symposium 1993 |
Systems and software security
secure storage |
0.0 | 1 | 1993 | A Cryptographic File System for UNIX · CCS 1993 |
Operating systems › operating system family
UNIX |
0.0 | 1 | 1993 | The Architecture and Implementation of Network Layer Security in UNIX · USENIX Security Symposium 1993 |
Storage systems › file systems › file system design
cryptographic file system |
0.0 | 1 | 1993 | A Cryptographic File System for UNIX · CCS 1993 |
Storage systems
file systems |
0.0 | 1 | 1993 | A Cryptographic File System for UNIX · CCS 1993 |
Internet architecture and protocols › network security
IP security |
0.0 | 1 | 2001 | Trust Management for IPsec · NDSS 2001 |
Methods — techniques the papers use, named apart from their topics
quantitative correlation analysis · 0.4voting · 0.2agreement protocols · 0.2security proof · 0.0protocol design · 0.0session-layer encryption · 0.0formal security modeling · 0.0provable security · 0.0formal modeling · 0.0cryptographic protocol design · 0.0cryptographic key management · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Moving Targets: Security and Rapid-Release in FirefoxabstractSoftware engineering practices strongly affect the security of the code produced. The increasingly popular Rapid Release Cycle (RRC) development methodology and easy network software distribution have enabled rapid feature introduction. RRC's defining characteristic of frequent software revisions would seem to conflict with traditional software engineering wisdom regarding code maturity, reliability and reuse, as well as security. Our investigation of the consequences of rapid release comprises a quantitative, data-driven study of the impact of rapid-release methodology on the security of the Mozilla Firefox browser. We correlate reported vulnerabilities in multiple rapid release versions of Firefox code against those in corresponding extended release versions of the same system; using a common software base with different release cycles eliminates many causes other than RRC for the observables. Surprisingly, the resulting data show that Firefox RRC does not result in higher vulnerability rates and, further, that it is exactly the unfamiliar, newly released software (the "moving targets") that requires time to exploit. These provocative results suggest that a rethinking of the consequences of software engineering practices for security may be warranted. Sandy Clark, Michael Collis, Matt Blaze, Jonathan M. Smith |
CCS | 3 |
| 2014 | The design and implementation of the A3 application-aware anonymity platform
Micah Sherr, Harjot Gill, Taher Saeed, Andrew Mao, William R. Marczak, Saravana Soundararajan, Wenchao Zhou, Boon Thau Loo, Matt Blaze |
Comput. Networks | 9 |
| 2014 | Privacy-aware message exchanges for HumaNets
Adam J. Aviv, Matt Blaze, Micah Sherr, Jonathan M. Smith |
Comput. Commun. | 2 |
| 2012 | Practicality of accelerometer side channels on smartphonesabstractModern smartphones are equipped with a plethora of sensors that enable a wide range of interactions, but some of these sensors can be employed as a side channel to surreptitiously learn about user input. In this paper, we show that the accelerometer sensor can also be employed as a high-bandwidth side channel; particularly, we demonstrate how to use the accelerometer sensor to learn user tap- and gesture-based input as required to unlock smartphones using a PIN/password or Android's graphical password pattern. Using data collected from a diverse group of 24 users in controlled (while sitting) and uncontrolled (while walking) settings, we develop sample rate independent features for accelerometer readings based on signal processing and polynomial fitting techniques. In controlled settings, our prediction model can on average classify the PIN entered 43% of the time and pattern 73% of the time within 5 attempts when selecting from a test set of 50 PINs and 50 patterns. In uncontrolled settings, while users are walking, our model can still classify 20% of the PINs and 40% of the patterns within 5 attempts. We additionally explore the possibility of constructing an accelerometer-reading-to-input dictionary and find that such dictionaries would be greatly challenged by movement-noise and cross-user training. Adam J. Aviv, Benjamin Sapp, Matt Blaze, Jonathan M. Smith |
ACSAC | 3 |
| 2012 | Privacy-Aware Message Exchanges for Geographically Routed Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
ESORICS | 3 |
| 2011 | Key escrow from a safe distance: looking back at the Clipper ChipabstractIn 1993, the US Government proposed a novel (and highly controversial) approach to cryptography, called key escrow. Key escrow cryptosystems used standard symmetric- and public- key ciphers, key management techniques and protocols, but with one added feature: a copy of the current session key, itself encrypted with a key known to the government, was sent at the beginning of every encrypted communication stream. In this way, if a government wiretapper encountered ciphertext produced under a key escrowed cryptosystem, recovering the plaintext would be a simple matter of decrypting the session key with the government's key, regardless of the strength of the underlying cipher algorithms. Key escrow was intended to strike a "balance" between the needs for effective communications security against bad guys on the one hand and the occasional need for the good guys to be able to recover meaningful content from (presumably) legally-authorized wiretaps. Matt Blaze |
ACSAC | 1 |
| 2011 | Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System
Sandy Clark, Travis Goodspeed, Perry Metzger, Zachary Wasserman, Kevin Xu, Matt Blaze |
USENIX Security Symposium | 6 |
| 2010 | Familiarity breeds contempt: the honeymoon effect and the role of legacy code in zero-day vulnerabilitiesabstractWork on security vulnerabilities in software has primarily focused on three points in the software life-cycle: (1) finding and removing software defects, (2) patching or hardening software after vulnerabilities have been discovered, and (3) measuring the rate of vulnerability exploitation. This paper examines an earlier period in the software vulnerability life-cycle, starting from the release date of a version through to the disclosure of the fourth vulnerability, with a particular focus on the time from release until the very first disclosed vulnerability.Analysis of software vulnerability data, including up to a decade of data for several versions of the most popular operating systems, server applications and user applications (both open and closed source), shows that properties extrinsic to the software play a much greater role in the rate of vulnerability discovery than do intrinsic properties such as software quality. This leads us to the observation that (at least in the first phase of a product's existence), software vulnerabilities have different properties from software defects.We show that the length of the period after the release of a software product (or version) and before the discovery of the first vulnerability (the 'Honeymoon' period) is primarily a function of familiarity with the system. In addition, we demonstrate that legacy code resulting from code re-use is a major contributor to both the rate of vulnerability discovery and the numbers of vulnerabilities found; this has significant implications for software engineering principles and practice. Sandy Clark, Stefan Frei, Matt Blaze, Jonathan M. Smith |
ACSAC | 3 |
| 2010 | A3: An Extensible Platform for Application-Aware Anonymity
Micah Sherr, Andrew Mao, William R. Marczak, Wenchao Zhou, Boon Thau Loo, Matt Blaze |
NDSS | 6 |
| 2010 | Evading Cellular Data Monitoring with Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
HotSec | 3 |
| 2009 | Can they hear me now?: a security analysis of law enforcement wiretapsabstractAlthough modern communications services are susceptible to third-party eavesdropping via a wide range of possible techniques, law enforcement agencies in the US and other countries generally use one of two technologies when they conduct legally-authorized interception of telephones and other communications traffic. The most common of these, designed to comply with the 1994 Communications Assistance for Law Enforcement Act(CALEA), use a standard interface provided in network switches. Micah Sherr, Gaurav Shah, Eric Cronin, Sandy Clark, Matt Blaze |
CCS | 5 |
| 2009 | Scalable Link-Based Relay Selection for Anonymous Routing
Micah Sherr, Matt Blaze, Boon Thau Loo |
Privacy Enhancing Technologies | 2 |
| 2009 | Veracity: Practical Secure Network Coordinates via Vote-based Agreements
Micah Sherr, Matt Blaze, Boon Thau Loo |
USENIX ATC | 2 |
| 2007 | Towards Application-Aware Anonymous Routing
Micah Sherr, Boon Thau Loo, Matt Blaze |
HotSec | 3 |
| 2006 | On the Reliability of Network Eavesdropping Tools
Eric Cronin, Micah Sherr, Matt Blaze |
IFIP Int. Conf. Digital Forensics | 3 |
| 2005 | Picking Locks with Cryptology
Matt Blaze |
LISA | 1 |
| 2004 | Just fast keying: Key agreement in a hostile internetabstractWe describe Just Fast Keying (JFK), a new key-exchange protocol, primarily designed for use in the IP security architecture. It is simple, efficient, and secure; we sketch a proof of the latter property. JFK also has a number of novel engineering parameters that permit a variety of tradeoffs, most notably the ability to balance the need for perfect forward secrecy against susceptibility to denial-of-service attacks. William Aiello, Steven M. Bellovin, Matt Blaze, Ran Canetti, John Ioannidis, Angelos D. Keromytis, Omer Reingold |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2002 | Efficient, DoS-resistant, secure key exchange for internet protocolsabstractWe describe JFK, a new key exchange protocol, primarily designed for use in the IP Security Architecture. It is simple, efficient, and secure; we sketch a proof of the latter property. JFK also has a number of novel engineering parameters that permit a variety of trade-offs, most notably the ability to balance the need for perfect forward secrecy against susceptibility to denial-of-service attacks. William Aiello, Steven M. Bellovin, Matt Blaze, John Ioannidis, Omer Reingold, Ran Canetti, Angelos D. Keromytis |
CCS | 3 |
| 2002 | Trust management for IPsecabstractIPsec is the standard suite of protocols for network-layer confidentiality and authentication of Internet traffic. The IPsec protocols, however, do not address the policies for how protected traffic should be handled at security end points. This article introduces an efficient policy management scheme for IPsec, based on the principles of trust management. A compliance check is added to the IPsec architecture that tests packet filters proposed when new security associations are created for conformance with the local security policy, based on credentials presented by the peer host. Security policies and credentials can be quite sophisticated (and specified in the trust-management language), while still allowing very efficient packet-filtering for the actual IPsec traffic. We present a practical portable implementation of this design, based on the KeyNote trust-management language, that works with a variety of UNIX-based IPsec implementations. Finally, we discuss some applications of the enhanced IPsec architecture. Matt Blaze, John Ioannidis, Angelos D. Keromytis |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2001 | Trust Management for IPsec
Matt Blaze, John Ioannidis, Angelos D. Keromytis |
NDSS | 1 |
| 1999 | A Formal Treatment of Remotely Keyed Encryption
Matt Blaze, Joan Feigenbaum, Moni Naor |
SODA | 1 |
| 1998 | Divertible Protocols and Atomic Proxy Cryptography
Matt Blaze, Gerrit Bleumer, Martin Strauss 0001 |
EUROCRYPT | 1 |
| 1998 | A Formal Treatment of Remotely Keyed Encryption
Matt Blaze, Joan Feigenbaum, Moni Naor |
EUROCRYPT | 1 |
| 1996 | High-Bandwidth Encryption with Low-Bandwidth Smartcards
Matt Blaze |
FSE | 1 |
| 1996 | Decentralized Trust Management
Matt Blaze, Joan Feigenbaum, Jack Lacy |
S&P | 1 |
| 1995 | Session-Layer Encryption
Matt Blaze, Steven M. Bellovin |
USENIX Security Symposium | 1 |
| 1994 | Protocol Failure in the Escrowed Encryption StandardabstractThe Escrowed Encryption Standard (EES) defines a US Government family of cryptographic processors, popularly known as “Clipper” chips, intended to protect unclassified government and private-sector communications and data. A basic feature of key setup between pairs of EES processors involves the exchange of a “Law Enforcement Access Field” (LEAF) that contains an encrypted copy of the current session key. The LEAF is intended to facilitate government access to the cleartext of data encrypted under the system. Several aspects of the design of the EES, which employs a classified cipher algorithm and tamper-resistant hardware, attempt to make it infeasible to deploy the system without transmitting the LEAF. We evaluated the publicly released aspects of the EES protocols as well as a prototype version of a PCMCIA-based EES device. This paper outlines various techniques that enable cryptographic communication among EES processors without transmission of the valid LEAF. We identify two classes of techniques. The simplest allow communication only between pairs of “rogue” parties. The second, more complex methods permit rogue applications to take unilateral action to interoperate with legal EES users. We conclude with techniques that could make the fielded EES architecture more robust against these failures. Matt Blaze |
CCS | 1 |
| 1994 | The MacGuffin Block Cipher Algorithm
Matt Blaze, Bruce Schneier |
FSE | 1 |
| 1993 | A Cryptographic File System for UNIXabstractAlthough cryptographic techniques are playing an increasingly important role in modern computing system security, user-level tools for encrypting file data are cumbersome and suffer from a number of inherent vulnerabilities. The Cryptographic File System (CFS) pushes encryption services into the file system itself. CFS supports secure storage at the system level through a standard Unix file system interface to encrypted files. Users associate a cryptographic key with the directories they wish to protect. Files in these directories (as well as their pathname components) are transparently encrypted and decrypted with the specified key without further user intervention; cleartext is never stored on a disk or sent to a remote file server. CFS can use any available file system for its underlying storage without modification, including remote file servers such as NFS. System management functions, such as file backup, work in a normal manner and without knowledge of the key. Matt Blaze |
CCS | 1 |
| 1993 | The Architecture and Implementation of Network Layer Security in UNIX
John Ioannidis, Matt Blaze |
USENIX Security Symposium | 2 |
| 1992 | Dynamic Hierarchical Caching for Large-Scale Distributed File SystemsabstractA simple method for constructing dynamic heirarchies on a file-by-file basis is described. The results of a trace-driven simulation of a dynamic hierarchical file system are presented. A reduction in server traffic of a factor of more than two for shared files compared with a flat scheme is obtained, without a large increase in client access time. Low-overhead techniques for maintaining cache consistency by detecting missed cache invalidation are discussed.> Matt Blaze, Rafael Alonso |
ICDCS | 1 |