Karen R. Sollins

dblp:15/3878 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
2since 2021 · last 2025
0000-0003-3686-4065ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 3 first-authorSecurity and privacy · 5 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 SYN Proof-of- Work: Improving Volumetric DoS Resilience in TCP
abstract
This paper presents and evaluates SYN PoW, a novel approach to mitigating TCP SYN flooding attacks using minia-ture proofs-of-work. SYN Floods have been a common threat on the Internet for decades, and have increased dramatically in both scale and frequency in recent years. Currently, SYN Cookies are widely deployed as a mitigation against this threat, but as we demonstrate they scale poorly with the volume of attack and can be detrimental to performance. SYN PoW plays a similar role, but with several key advantages: (1) it protects bandwidth by dropping malicious SYN s without sending SYN-ACKs in response; (2) it facilitates in-network verification, enabling middle boxes to detect and drop malicious packets before they reach their target; (3) it shifts the primary cost burden of mitigation from attack victims to attackers themselves; and (4) it protects against spoofing attacks without requiring source address validation. We explain how proofs-of-work can be added to SYN packets in a way that complies with the current TCP standard, and demonstrate how SYN Po W outperforms SYN Cookies under high-volume SYN floods in controlled testbed experiments.
Samuel DeLaughter, Karen R. Sollins
SP2
2023 Speranza: Usable, Privacy-friendly Software Signing
abstract
Software repositories, used for wide-scale open software distribution, are a significant vector for security attacks. Software signing provides authenticity, mitigating many such attacks. Developer-managed signing keys pose usability challenges, but certificate-based systems introduce privacy problems. This work, Speranza, uses certificates to verify software authenticity but still provides anonymity to signers using zero-knowledge identity co-commitments.
Kelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen R. Sollins
CCS4
2019 IoT Big Data Security and Privacy Versus Innovation
abstract
In this paper, we address the conflict in the collection, use, and management of Big Data at the intersection of security and privacy requirements and the demand of innovative uses of the data. This problem is exaggerated in the context of the Internet of Things (IoT). We propose a three-part decomposition of the design space, in order to clarify requirements and constraints. To reach this final analysis, we begin by clarifying the challenges in the design space: 1) there is a little agreement on what is meant by IoT, and in particular the security and privacy implications of different definitions; 2) we then consider the requirement and constraints on the Big Data that result from various IoT system designs; and 3) in parallel, we examine the intricacies of the demand for innovation from both the legal and economic perspectives. In this context, we then can decompose the set of drivers and objectives for security/privacy of data as well as innovation into: 1) the regulatory and social policy context; 2) economic and business context; and 3) technology and design context. By identifying these distinct objectives for the design of IoT Big Data management, we propose that more effective design and control is possible at the intersection of these forces, through an iterative process of review and redesign.
Karen R. Sollins
IEEE Internet Things J.1
2011 Challenges to Privacy in Social Networking Mashups: Social TV as a Case Study
abstract
Social networking provides opportunities to expand the nature of existing applications and user activities in cyberspace. Consider the idea of "social TV". Along with these opportunities to combine activities such as social networking and TV or entertainment, comes an interesting set of challenges to the privacy of identity information. In this paper we will examine a key set of these challenges. These include issues of merged identities, inference across identities, merged privacy policies, and flow of information among the composition identity management systems involved in a new composite application service. We conclude with a set of observations to keep in mind when designing such a composition or mashup of existing services, especially with respect to identity and privacy.
Karen R. Sollins
ICCCN1
2011 Data Delivery Properties of Human Contact Networks
abstract
Pocket Switched Networks take advantage of social contacts to opportunistically create data paths over time. This work employs empirical traces to examine the effect of the human contact process on data delivery in such networks. The contact occurrence distribution is found to be highly uneven: contacts between a few node pairs occur too frequently, leading to inadequate mixing in the network, while the majority of contacts occur rarely, but are essential for global connectivity. This distribution of contacts leads to a significant variation in the fraction of node pairs that can be connected over time windows of similar duration. Good time windows tend to have a large clique of nodes that can all reach each other. It is shown that the clustering coefficient of the contact graph over a time window is a good predictor of achievable connectivity. We then examine all successful paths found by flooding and show that though delivery times vary widely, randomly sampling a small number of paths between each source and destination is sufficient to yield a delivery time distribution close to that of flooding over all paths. This result suggests that the rate at which the network can deliver data is remarkably robust to path failures.
Nishanth Sastry, D. Manjunath, Karen R. Sollins, Jon Crowcroft
IEEE Trans. Mob. Comput.3
2009 Delivery Properties of Human Social Networks
abstract
The recently proposed packet switched network paradigm takes advantage of human social contacts to opportunistically create data paths over time. Our goal is to examine the effect of the human contact process on data delivery. We find that the contact occurrence distribution is highly uneven: contacts between a few node-pairs occur too frequently, leading to inadequate mixing in the network, while the majority of contacts are rare, and essential for connectivity. This distribution of contacts leads to a significant variation in performance over short time windows. We discover that the formation of a large clique core during the window is correlated with the fraction of data delivered, as well as the speed of delivery. We then show that the clustering co-efficient of the contact graph over a time window is a good predictor of performance during the window. Taken together, our findings suggest new directions for designing forwarding algorithms in ad-hoc or delay-tolerant networking schemes using humans as data mules.
Nishanth Sastry, Karen R. Sollins, Jon Crowcroft
INFOCOM2
2007 Architecting Citywide Ubiquitous Wi-Fi Access
Nishanth Sastry, Jon Crowcroft, Karen R. Sollins
HotNets3
2007 Effective keyword-based selection of relational databases
abstract
The wide popularity of free-and-easy keyword based searches over World Wide Web has fueled the demand for incorporating keyword-based search over structured databases. However, most of the current research work focuses on keyword-based searching over a single structured data source. With the growing interest in distributed databases and service oriented architecture over the Internet, it is important to extend such a capability over multiple structured data sources. One of the most important problems for enabling such a query facility is to be able to select the most useful data sources relevant to the keyword query. Traditional database summary techniques used for selecting unstructured datasources developed in IR literature are inadequate for our problem, as they do not capture the structure of the data sources. In this paper, we study the database selection problem for relational data sources, and propose a method that effectively summarizes the relationships between keywords in a relational database based on its structure. We develop effective ranking methods based on the keyword relationship summaries in order to select the most useful databases for a given keyword query. We have implemented our system on PlanetLab. In that environment we use extensive experiments with real datasets to demonstrate the effectiveness of our proposed summarization method.
Bei Yu 0003, Guoliang Li 0001, Karen R. Sollins, Anthony K. H. Tung
SIGMOD Conference3
2005 Tussle in cyberspace: defining tomorrow's internet
abstract
The architecture of the Internet is based on a number of principles, including the self-describing datagram packet, the end-to-end arguments, diversity in technology and global addressing. As the Internet has moved from a research curiosity to a recognized component of mainstream society, new requirements have emerged that suggest new design principles, and perhaps suggest that we revisit some old ones. This paper explores one important reality that surrounds the Internet today: different stakeholders that are part of the Internet milieu have interests that may be adverse to each other, and these parties each vie to favor their particular interests. We call this process "the tussle". Our position is that accommodating this tussle is crucial to the evolution of the network's technical architecture. We discuss some examples of tussle, and offer some technical design principles that take it into account.
David D. Clark, John Wroclawski, Karen R. Sollins, Bob Braden
IEEE/ACM Trans. Netw.3
2004 Exploiting Autonomous System Information in Structured Peer-to-Peer Networks
abstract
With the rise of peer-to-peer networks, two problems have become prominent: (1) significant network traffic among peers, to probe the latency among those peers to improve lookup performance; (2) the need for increased information flow across protocol layer boundaries, to allow for cross-layer adaptations. The particular work here focuses on improvements in structured peer-to-peer networks based on autonomous system information. We find that by using autonomous system information effectively we can achieve lookup performance approaching that based on proximity neighbor selection, but with much less network traffic. We also demonstrate improvements in replication in structured peer-to-peer networks using AS topology and scoping information. Finally, we review this approach in the context of network architecture.
Ji Li 0010, Karen R. Sollins
ICCCN2
2002 Tussle in cyberspace: defining tomorrow's internet
abstract
The architecture of the Internet is based on a number of principles, including the self-describing datagram packet, the end to end arguments, diversity in technology and global addressing. As the Internet has moved from a research curiosity to a recognized component of mainstream society, new requirements have emerged that suggest new design principles, and perhaps suggest that we revisit some old ones. This paper explores one important reality that surrounds the Internet today: different stakeholders that are part of the Internet milieu have interests that may be adverse to each other, and these parties each vie to favor their particular interests. We call this process "the tussle". Our position is that accommodating this tussle is crucial to the evolution of the network's technical architecture. We discuss some examples of tussle, and offer some technical design principles that take it into account.
David D. Clark, John Wroclawski, Karen R. Sollins, Bob Braden
SIGCOMM3
1998 Expanding and Extending the Security Features of Java
Karen R. Sollins, Nimisha V. Mehta
USENIX Security Symposium1
1992 Towards Security in an Open Systems Federation
John A. Bull, Karen R. Sollins
ESORICS3
1988 Cascaded authentication
abstract
The author addresses a problem that has arisen in building distributed systems in which incomplete trust exists and program composition is necessary. The problem is to permit authentication for both access control and accounting when cascading invocations. The problem can be identified as one of providing cascaded authentication. The author has developed a mechanism she calls passports that are passed along with each stage of the cascade and digitally signed at each transition. The information thus signed is that which is critical to the authentication. The focus is both on recognizing the problem and on devising a solution that is efficient enough to be usable, although there will be some cost associated with such a mechanism.>
Karen R. Sollins
S&P1
1981 Copying Structured Objects in a Distributed System
Karen R. Sollins
Comput. Networks1