Martin Hell

dblp:10/6874 · DBLP profile ↗
← Back
36ranked-venue papers
12as first author
5since 2021 · last 2022
0000-0002-5694-5447ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 6 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 3 first-authorSoftware engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Theory of computation · 3 · 2 first-author
YearPublicationVenuePosition
2022 Security Issue Classification for Vulnerability Management with Semi-supervised Learning
abstract
Open-Source Software (OSS) is increasingly common in industry software and enables developers to build better applications, at a higher pace, and with better security. These advantages also come with the cost of including vulnerabilities through these third-party libraries. The largest publicly available database of easily machine-readable vulnerabilities is the National Vulnerability Database (NVD). However, reporting to this database is a human-dependent process, and it fails to provide an acceptable coverage of all open source vulnerabilities. We propose the use of semi-supervised machine learning to classify issues as security-related to provide additional vulnerabilities in an automated pipeline. Our models, based on a Hierarchical Attention Network (HAN), outperform previously proposed models on our manually labelled test dataset, with an F1 score of 71%. Based on the results and the vast number of GitHub issues, our model potentially identifies about 191 036 security-related issues with prediction power over 80%.
Emil Wåreus, Anton Duppils, Magnus Tullberg, Martin Hell
ICISSP4
2021 Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier, Hirotaka Yoshida
CANS1
2021 Communicating Cybersecurity Vulnerability Information: A Producer-Acquirer Case Study
Martin Hell, Martin Höst
PROFES1
2021 Using Program Analysis to Identify the Use of Vulnerable Functions
abstract
Open-Source Software (OSS) is increasingly used by software applications. It allows for code reuse, but also comes with the problem of potentially being affected by the vulnerabilities that are found in the OSS libraries. With large numbers of OSS components and a large number of published vulnerabilities, it becomes challenging to identify and analyze which OSS components need to be patched and updated. In addition to matching vulnerable libraries to those used in software products, it is also necessary to analyze if the vulnerable functionality is actually used by the software. This process is both time-consuming and error-prone. Automating this process presents several challenges, but has the potential to significantly decrease vulnerability exposure time. In this paper, we propose a modular framework for analyzing if software code is using the vulnerable part of a library, by analyzing and matching the call graphs of the software with changes resulting from security patches. Further, we provide an implementation of the framework targeting Java and the Maven dependency management system. This allows us to identify 20% of the dependencies in our sample projects as false positives. We also identify and discuss challenges and limitations in our approach
Rasmus Hagberg, Martin Hell, Christoph Reichenbach
SECRYPT2
2021 Flowrider: Fast On-Demand Key Provisioning for Cloud Networks
Nicolae Paladi, Marco Tiloca, Pegah Nikbakht Bideh, Martin Hell
SecureComm (2)4
2020 Automated CPE Labeling of CVE Summaries with Machine Learning
Emil Wåreus, Martin Hell
DIMVA2
2020 Evaluation of the HAVOSS software process maturity model
abstract
The HAVOSS (Handling Vulnerabilities in OSS) maturity model describes important processes for managing security vulnerabilities in OSS modules in developed products. So far, the model has not been evaluated in any real assessment process. Here we present a study where the model was evaluated by using it in assessments of processes for two product types in one organization. Each assessment was conducted in a focus group meeting where their procedures were analyzed. The evaluation was conducted by posing specific questions about the model during the focus group meetings and by investigating how difficult it was to assess the maturity of practices from the transcribed text. It was found that some practices were easy to assess, while other could be analysed separately for different parts of the products. Further work can be conducted on how assessments can be conducted and how they can be combined with other software security initiatives.
Martin Höst, Martin Hell
SEAA2
2020 On the Suitability of Using SGX for Secure Key Storage in the Cloud
Joakim Brorsson, Pegah Nikbakht Bideh, Alexander Nilsson, Martin Hell
TrustBus4
2019 A Recommender System for User-Specific Vulnerability Scoring
Linus Karlsson, Pegah Nikbakht Bideh, Martin Hell
CRiSIS3
2019 Sharing of Vulnerability Information Among Companies - A Survey of Swedish Companies
abstract
Software products are rarely developed from scratch and vulnerabilities in such products might reside in parts that are either open source software or provided by another organization. Hence, the total cybersecurity of a product often depends on cooperation, explicit or implicit, between several organizations. We study the attitudes and practices of companies in software ecosystems towards sharing vulnerability information. Furthermore, we compare these practices to contemporary cybersecurity recommendations. This is performed through a questionnaire-based qualitative survey. The questionnaire is divided into two parts: the providers' perspective and the acquirers' perspective. The results show that companies are willing to share information with each other regarding vulnerabilities. Sharing is not considered to be harmful neither to the cybersecurity nor their business, even though a majority of the respondents consider vulnerability information sensitive. However, the companies, despite being open to sharing, are less inclined to proactively sharing vulnerability information. Furthermore, the providers do not perceive that there is a large interest in vulnerability information from their customers. Hence, the companies' overall attitude to sharing vulnerability information is passive but open. In contrast, contemporary cybersecurity guidelines recommend active disclosure and sharing among actors in an ecosystem.
Thomas Olsson 0001, Martin Hell, Martin Höst, Ulrik Franke, Markus Borg
SEAA2
2018 HAVOSS: A Maturity Model for Handling Vulnerabilities in Third Party OSS Components
Pegah Nikbakht Bideh, Martin Höst, Martin Hell
PROFES3
2017 Improved Greedy Nonrandomness Detectors for Stream Ciphers
abstract
We consider the problem of designing distinguishers and nonrandomness detectors for stream ciphers using the maximum degree monomial test. We construct an improved algorithm to determine the subset of key and IV-bits used in the test. The algorithm is generic, and can be applied to any stream cipher. In addition to this, the algorithm is highly tweakable, and can be adapted depending on the desired computational complexity. We test the algorithm on the stream ciphers Grain-128a and Grain-128, and achieve significantly better results compared to an earlier greedy approach.
Linus Karlsson, Martin Hell, Paul Stankovski Wagner
ICISSP2
2016 Exploiting Trust in Deterministic Builds
Christopher Jämthagen, Patrik Lantz, Martin Hell
SAFECOMP3
2014 The efficiency of optimal sampling in the random S-box model
abstract
In this paper we show a closed caption formula for the efficiency of the optimal sampling technique in the random S-box model. This formula is derived by analyzing the given model and sampling technique using statistical techniques. We further generalize the original random S-box model in two ways; allowing multiple-bit entries, xor of several random S-box outputs. For all cases we show the corresponding closed caption efficiency formula. Using these new formulas, it is now possible to instantaneously give accurate analytical estimates of the output quality of random S-boxes. This can be of great practical importance in, for example, analysis and design of cryptographic primitives based on such building blocks.
Paul Stankovski Wagner, Lennart Brynielsson, Martin Hell
ISIT3
2014 eavesROP: Listening for ROP Payloads in Data Streams
Christopher Jämthagen, Linus Karlsson, Paul Stankovski Wagner, Martin Hell
ISC4
2014 An Efficient State Recovery Attack on the X-FCSR Family of Stream Ciphers
Paul Stankovski Wagner, Martin Hell, Thomas Johansson 0001
J. Cryptol.2
2012 Analysis of Xorrotation with Application to an HC-128 Variant
Paul Stankovski Wagner, Martin Hell, Thomas Johansson 0001
ACISP2
2012 An optimal sampling technique for distinguishing random S-boxes
abstract
The nonrandom behavior of the outputs of a random S-box can be exploited when constructing distinguishers for cryptographic primitives. Different methods of constructing samples from the outputs have been used in the literature. However, it has been unclear exactly how these methods differ and which method is optimal. We analyze four different sampling techniques. We prove that two of these sampling techniques result in dependent samples. We further show one sampling technique that is optimal in terms of error probabilities in the resulting distinguisher. However, this sampling technique is quite impractical as it requires very large storage. We further show a fourth sampling technique that is much more practical, and we prove that it is equivalent to the optimal one. We also show an improved algorithm for calculating the associated probability distributions that are required for the attack.
Paul Stankovski Wagner, Martin Hell
ISIT2
2012 Improved distinguishers for HC-128
Paul Stankovski Wagner, Sushmita Ruj, Martin Hell, Thomas Johansson 0001
Des. Codes Cryptogr.3
2012 On hardware-oriented message authentication
abstract
The authors consider hardware-oriented message authentication, more specifically universal hash functions. The authors propose a new type of constructions that appear promising. These constructions are based on the framework of universal hash functions, Toeplitz matrices and ɛ-biased sample spaces. Some new theoretical results in this area are derived. The new constructions come at the price of not being able to prove the exact substitution probability. The expected probability is examined both through theoretical methods as well as through simulation.
Martin Ågren, Martin Hell, Thomas Johansson 0001
IET Inf. Secur.2
2012 Improved Distinguishers on Stream Ciphers With Certain Weak Feedback Polynomials
abstract
It is well known that fast correlation attacks can be very efficient if the feedback polynomial is of low weight. These feedback polynomials can be considered weak in the context of stream ciphers. This paper generalizes the class of weak feedback polynomials into polynomials were taps are located in several groups, possibly far apart. Low-weight feedback polynomials are thus a special case of this class. For the general class, it is shown that attacks can sometimes be very efficient even though the polynomials are of large weight. The main idea is to consider vectors of noise variables. It is shown how the complexity of a distinguishing attack can be efficiently computed and that the complexity is closely related to the minimum row distance of a generator matrix for a convolutional code. Moreover, theoretical results on the size of the vectors are given.
Martin Hell, Thomas Johansson 0001, Lennart Brynielsson, Håkan Englund
IEEE Trans. Inf. Theory1
2011 Cryptanalysis of the stream cipher BEAN
abstract
BEAN is a recent stream cipher proposal that uses Feedback with Carry Shift Registers (FCSRs) and an output function. There is a sound motivation behind the use of FCSRs in BEAN as they provide several cryptographically interesting properties. In this paper, we show that the output function is not optimal. We give an efficient distinguisher and a key recovery attack that is slightly better than brute force, requiring no significant memory. We then show how this attack can be made better with access to more keystream. Already with access to 6 KiB, the 80-bit key is recovered in time 273.
Martin Ågren, Martin Hell
SIN2
2011 Breaking the Stream Ciphers F-FCSR-H and F-FCSR-16 in Real Time
Martin Hell, Thomas Johansson 0001
J. Cryptol.1
2010 Using coding techniques to analyze weak feedback polynomials
abstract
We consider a class of weak feedback polynomials for LFSRs in the nonlinear combiner. When feedback taps are located in small groups, a distinguishing attack can sometimes be improved considerably, compared to the common attack that uses low weight multiples. This class of weak polynomials was introduced in 2004 and the main property of the attack is that the noise variables are represented as vectors. We analyze the complexity of the attack using coding theory. We show that the groups of polynomials can be seen as generator polynomials of a convolutional code. Then, the problem of finding the attack complexity is equivalent to finding the minimum row distance of the corresponding generator matrix. A modified version of BEAST is used to search all encoders of memory up to 13. Moreover, we give a tight upper bound on the required size of the vectors in the attack.
Martin Hell
ISIT1
2009 Improving the Rainbow Attack by Reusing Colours
Martin Ågren, Thomas Johansson 0001, Martin Hell
CANS3
2009 An Efficient State Recovery Attack on X-FCSR-256
Paul Stankovski Wagner, Martin Hell, Thomas Johansson 0001
FSE2
2009 Another look at weak feedback polynomials in the nonlinear combiner
abstract
Feedback polynomials with low degree multiples of low weight should be avoided in linear feedback shift registers when used in nonlinear combiners. We consider another class of weak feedback polynomials, namely the class when taps are located in small groups. This class was introduced in 2004 demonstrating that the resulting distinguishing attack can sometimes be better than the one using low weight multiples. In this paper we take another look at these polynomials and give further insight to the theory behind the attack complexity. Using the Walsh transform we show an easy way to determine the attack complexity given a polynomial. Further, we show that the size of the vectors should sometimes be larger than previously known. We also give a simple relation showing when the new attack will outperform the simple attack based on low weight multiples.
Martin Hell, Lennart Brynielsson
ISIT1
2008 Breaking the F-FCSR-H Stream Cipher in Real Time
Martin Hell, Thomas Johansson 0001
ASIACRYPT1
2007 A Key Recovery Attack on Edon80
Martin Hell, Thomas Johansson 0001
ASIACRYPT1
2007 Two General Attacks on Pomaranch-Like Keystream Generators
Håkan Englund, Martin Hell, Thomas Johansson 0001
FSE2
2007 A Note on Distinguishing Attacks
abstract
A new distinguishing attack scenario for stream ciphers, allowing a resynchronization collision attack, is presented. The attack can succeed if the part of the state that depends on both the key and the IV is smaller than twice the key size. It is shown that the attack is applicable to block ciphers in OFB mode. For OFB mode, the attack is more powerful than the previously known generic distinguishing attack since it will directly recover a part of the plaintext while having the same asymptotic complexity as the generic distinguishing attack. The attack is also demonstrated on the eSTREAM candidate LEX. LEX is not vulnerable to any of the previously known generic distinguishing attack but is vulnerable to the new attack. It is shown that if approximately 265.7resynchro-nizations using LEX are performed for the same key, some plaintext might be recovered.
Håkan Englund, Martin Hell, Thomas Johansson 0001
ITW2
2007 Cryptanalysis of Achterbahn-128/80
abstract
A key recovery attack on the stream cipher Achterbahn-128/80, a cipher in the second phase of eSTREAM, is given. The key observation is a high dependency between some input bits to the Boolean combining function generating the keystream. It results in the first known attacks on both the 128-bit and the 80-bit variants of the cipher. The number of keystream bits required in the attacks is less than 264, the maximum frame length.
Martin Hell, Thomas Johansson 0001
IET Inf. Secur.1
2006 A Stream Cipher Proposal: Grain-128
abstract
A new stream cipher, Grain-128, is proposed. The design is very small in hardware and it targets environments with very limited resources in gate count, power consumption, and chip area. Grain-128 supports key size of 128 bits and IV size of 96 bits. The design is very simple and based on two shift registers, one linear and one nonlinear, and an output function
Martin Hell, Thomas Johansson 0001, Alexander Maximov, Willi Meier
ISIT1
2006 Two New Attacks on the Self-Shrinking Generator
abstract
The self-shrinking generator was introduced in 1994. It is based on the idea behind the shrinking generator and despite its simplicity it has remained remarkably resistant to efficient attacks. Several known plaintext attacks have been proposed on the generator, some operating on a short keystream and others requiring a longer sequence to succeed. In this paper, two new attacks on the self-shrinking generator are proposed. The first attack, using a short known keystream, has the same complexity as the BDD-based attack, which is the best previously known attack. However, while the BDD-based attack requires a huge amount of memory, the proposed algorithm uses almost no memory, leaving it as the preferred alternative. The second attack operates on a longer known keystream, exponential in the length of the LFSR. The attack considers one or several segments of keystream bits and guesses that these bits stem from LFSR segments of some size. It is shown that this attack achieves better complexity than any previously known attack
Martin Hell, Thomas Johansson 0001
IEEE Trans. Inf. Theory1
2005 Some Attacks on the Bit-Search Generator
Martin Hell, Thomas Johansson 0001
FSE1
2004 Correlation Attacks Using a New Class of Weak Feedback Polynomials
Håkan Englund, Martin Hell, Thomas Johansson 0001
FSE2