VLDB 2026 Research / reviewers in the wild / expert
Alexandru G. Bardas
dblp:145/6877
· DBLP profile ↗
13ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0003-3043-5905ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 5 since 2021Computer networks · 2Human-computer interaction and ubiquitous computing · 2Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | CloudCover: Enforcement of Multi-Hop Network Connections in Microservice DeploymentsabstractMicroservices have emerged as a strong architecture for large-scale, distributed systems in the context of cloud computing and containerization. However, the size and complexity of microservice systems have strained current access control mechanisms. Intricate dependency structures, such as multi-hop dependency chains, go uncaptured by existing access control mechanisms and leave microservice deployments open to adversarial actions and influence.This work introduces CloudCover, an access control mechanism and enforcement framework for microservices. CloudCover provides holistic, deployment-wide analysis of microservice operations and behaviors. It implements a verification-in-the-loop access control approach, mitigating multi-hop microservice threats through control-flow integrity checks. We evaluate these domain-relevant multi-hop threats and CloudCover under existing, real-world scenarios such as Istio’s opensource microservice example and under theoretic and synthetic network loads of 10,000 requests per second. Our results show that CloudCover is appropriate for use in real deployments, requiring no microservice code changes by administrators. Dalton A. Brucker-Hahn, Shanchao Li, Matthew Petillo, Alexandru G. Bardas, Drew Davidson, Yuede Ji |
ACSAC | 5 |
| 2024 | Web-Armour: Mitigating Reconnaissance and Vulnerability Scanning with Scan-Impeding Delays in Web DeploymentsabstractReconnaissance is a critical phase in many cyber attacks. Vulnerability scanning, a key component of reconnaissance, has been shown to be a widespread phenomenon on the internet and commonly targets web application/server deployments. By increasing the costs for vulnerability scanning, many of these attacks may be deterred or even prevented, especially for large-scale, internet-wide campaigns.In this paper, we propose Web-Armour, a mitigation approach to adversarial reconnaissance. Operating as a delay injection mechanism to infrequently executed code portions of a web deployment, Web-Armour significantly increases the cost for attackers to perform automated reconnaissance and vulnerability scanning, while introducing minimal to negligible impact for benign users. We evaluated Web-Armour in a live environment, operated by real users, and in controlled (offline) scenarios. Using Web-Armour, our results show that automated scanning tools may require up to 396 times longer in an offline setting, and up to 357 times longer in a real-world operational deployment to complete compared to unprotected installations. In many instances, scanning tools fail to complete their tasks, due to request timeouts. Furthermore, the performance overhead incurred to benign users is minimal, and can be as low as a 0.6% increase over the baseline. Yousif Dafalla, Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas |
ACSAC | 4 |
| 2024 | "But they have overlooked a few things in Afghanistan: " An Analysis of the Integration of Biometric Voter Verification in the 2019 Afghan Presidential Elections
Kabir Panahi, Shawn Robertson, Yasemin Acar, Alexandru G. Bardas, Tadayoshi Kohno, Lucy Simko |
USENIX Security Symposium | 4 |
| 2023 | Work-From-Home and COVID-19: Trajectories of Endpoint Security Management in a Security Operations Center
Kailani R. Jones, Dalton A. Brucker-Hahn, Bradley Fidler, Alexandru G. Bardas |
USENIX Security Symposium | 4 |
| 2021 | Defensive Technology Use by Political Activists During the Sudanese RevolutionabstractPolitical activism is a worldwide force in geopolitical change and has, historically, helped lead to greater justice, equality, and stopping human rights abuses. A modern revolution—an extreme form of political activism—pits activists, who rely on technology for critical operational tasks, against a resource-rich government that controls the very telecommunications network they must use to operationalize, putting the technology they use under extreme stress. Our work presents insights about activists’ technological defense strategies from interviews with 13 political activists who were active during the 2018-2019 Sudanese revolution. We find that politics and society are driving factors of security and privacy behavior and app adoption. Moreover, a social media blockade can trigger a series of anti-censorship approaches at scale, while a complete internet blackout can cripple activists’ use of technology. Even though the activists’ technological defenses against the threats of surveillance, arrest and physical device seizure were low tech, they were largely sufficient against their adversary. Through these results, we surface key design principles, but we observe that the generalization of design recommendations often runs into fundamental tensions between the security and usability needs of different user groups. Thus, we provide a set of structured questions in an attempt to turn these tensions into opportunities for technology designers and policy makers. Alaa Daffalla, Lucy Simko, Tadayoshi Kohno, Alexandru G. Bardas |
SP | 4 |
| 2020 | Deploying Android Security Updates: an Extensive Study Involving Manufacturers, Carriers, and End UsersabstractAndroid's fragmented ecosystem makes the delivery of security updates and OS upgrades cumbersome and complex. While Google initiated various projects such as Android One, Project Treble, and Project Mainline to address this problem, and other involved entities (e.g., chipset vendors, manufacturers, carriers) continuously strive to improve their processes, it is still unclear how effective these efforts are on the delivery of updates to supported end-user devices. In this paper, we perform an extensive quantitative study (Aug. 2015 to Dec. 2019) to measure the Android security updates and OS upgrades rollout process. Our study leverages multiple data sources: the Android Open Source Project (AOSP), device manufacturers, and the top four U.S. carriers (AT&T, Verizon, T-Mobile, and Sprint). Furthermore, we analyze an end-user dataset captured in 2019 (152M anonymized HTTP requests associated with 9.1M unique user identifiers) from a U.S.-based social network. Our findings include unique measurements that, due to the fragmented and inconsistent ecosystem, were previously challenging to perform. For example, manufacturers and carriers introduce a median latency of 24 days before rolling out security updates, with an additional median delay of 11 days before end devices update. We show that these values alter per carrier-manufacturer relationship, yet do not alter greatly based on a model's age. Our results also delve into the effectiveness of current Android projects. For instance, security updates for Treble devices are available on average 7 days faster than for non-Treble devices. While this constitutes an improvement, the security update delay for Treble devices still averages 19 days. Kailani R. Jones, Ting-Fang Yen, Sathya Chandran Sundaramurthy, Alexandru G. Bardas |
CCS | 4 |
| 2020 | Measuring the Prevalence of the Password Authentication Vulnerability in SSHabstractSecuring and hardening network protocols and services is a resource-consuming and continuous effort. Thus, it is important to question how prolific known, mitigable features of those protocols are. The Secure Shell (SSH) protocol is a good example due to its known vulnerability in using password based authentication. We take a closer look at these configurations to identify how prevalent the use of password authentication is at an internet scale. We show that current scanning tools and services provide a starting point in evaluating prevalence, but need to be validated for specific implementations. We also demonstrate that it is possible to augment some of these tools and services to determine the prevalence of password authentication in SSH specifically. As part of our evaluation, we propose a novel method for probing an SSH service to establish if password authentication is allowed, without being intrusive or causing harm to the host. Finally, we show that our analysis has resulted in determining that more than 65% of the over 20 million SSH servers on the public internet allow password authentication. Ron Andrews, Dalton A. Brucker-Hahn, Alexandru G. Bardas |
ICC | 3 |
| 2020 | MisMesh: Security Issues and Challenges in Service Meshes
Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas |
SecureComm (1) | 3 |
| 2018 | eyeDNS: Monitoring a University Campus NetworkabstractThe Domain Name System (DNS) is responsible for mapping human readable domain names to internet protocol (IP) addresses. DNS is a ubiquitous part of internet and intranet communication, making it a convenient and comprehensive source for data to infer network health, performance, and security. A victim of its own success, monitoring real-time DNS traffic is a challenge due to sheer volume: huge amounts of DNS packets flow through a typical enterprise in a single day. In this paper, we describe eyeDNS, a scalable and extensible system for near real-time aggregation, storage, analysis, and visualization of DNS traffic collected by a hardware back-end. We report on eyeDNS's deployment and data collection on a large public university's network over a timeframe of 15 months. Moreover, we leveraged data from the following 6 months to validate findings made during the initial timeframe. With fast query response, aggregation, and visualization of DNS data, eyeDNS helped identify instances of anomalous network use, malware-specific behaviors, and scamming activities. eyeDNS is currently being used by the university's security personnel and has demonstrated its effectiveness in extracting trends and outliers from large volumes of DNS data collected from a diverse environment, where even commercial tools struggle to provide timely and actionable analysis. Chandan Chowdhury, Dalton A. Brucker-Hahn, Matthew R. French, Eugene Y. Vasserman, Pratyusa K. Manadhata, Alexandru G. Bardas |
ICC | 6 |
| 2017 | MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
Alexandru G. Bardas, Sathya Chandran Sundaramurthy, Xinming Ou, Scott A. DeLoach |
ESORICS (1) | 1 |
| 2016 | Turning Contradictions into Innovations or: How We Learned to Stop Whining and Improve Security Operations
Sathya Chandran Sundaramurthy, John McHugh, Xinming Ou, Michael Wesch, Alexandru G. Bardas, S. Raj Rajagopalan |
SOUPS | 5 |
| 2015 | A Human Capital Model for Mitigating Security Analyst Burnout
Sathya Chandran Sundaramurthy, Alexandru G. Bardas, Jacob Case, Xinming Ou, Michael Wesch, John McHugh, S. Raj Rajagopalan |
SOUPS | 2 |
| 2014 | Compiling Abstract Specifications into Concrete Systems - Bringing Order to the Cloud
Ian Unruh, Alexandru G. Bardas, Rui Zhuang, Xinming Ou, Scott A. DeLoach |
LISA | 2 |