Jonathan Fuller 0001

dblp:151/1951-1 · also Jonathan D. Fuller · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0006-8626-1325ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Enhanced Web Application Security Through Proactive Dead Drop Resolver Remediation
Jonathan Fuller 0001, Mingxuan Yao, Saumya Agarwal, Srimanta Barua, Taleb Hirani, Amit Kumar Sikder, Brendan Saltaformaggio
CCS1
2023 Hiding in Plain Sight: An Empirical Study of Web Application Abuse in Malware
Mingxuan Yao, Jonathan Fuller 0001, Ranjita Pai Kasturi, Saumya Agarwal, Amit Kumar Sikder, Brendan Saltaformaggio
USENIX Security Symposium2
2022 Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress Marketplaces
Ranjita Pai Kasturi, Jonathan Fuller 0001, Yiting Sun, Omar Chabklo, Andres Rodriguez 0005, Jeman Park 0001, Brendan Saltaformaggio
USENIX Security Symposium2
2021 C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol Infiltration
abstract
Current techniques to monitor botnets towards disruption or takedown are likely to result in inaccurate data gathered about the botnet or be detected by C&C orchestrators. Seeking a covert and scalable solution, we look to an evolving pattern in modern malware that integrates standardized over-permissioned protocols, exposing privileged access to C&C servers. We implement techniques to detect and exploit these protocols from over-permissioned bots toward covert C&C server monitoring. Our empirical study of 200k malware captured since 2006 revealed 62,202 over-permissioned bots (nearly 1 in 3) and 443,905 C&C monitoring capabilities, with a steady increase of over-permissioned protocol use over the last 15 years. Due to their ubiquity, we conclude that even though over-permissioned protocols allow for C&C server infiltration, the efficiency and ease of use they provide continue to make them prevalent in the malware operational landscape. This paper presents C3PO, a pipeline that enables our study and empowers incident responders to automatically identify over-permissioned protocols, infiltration vectors to spoof bot-to-C&C communication, and C&C monitoring capabilities that guide covert monitoring post infiltration. Our findings suggest the over-permissioned protocol weakness provides a scalable approach to covertly monitor C&C servers, which is a fundamental enabler of botnet disruptions and takedowns.
Jonathan Fuller 0001, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu, Berat Arik, Ehsan Asdar, Brendan Saltaformaggio
CCS1
2017 Misuse-based detection of Z-Wave network attacks
Jonathan Fuller 0001, Benjamin W. P. Ramsey, Mason Rice, John M. Pecarina
Comput. Secur.1