Johannes Krupp

dblp:153/5752 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
3since 2021 · last 2022
0000-0002-5106-3736ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 6 first-author · 2 since 2021Computer networks · 1
YearPublicationVenuePosition
2022 AmpFuzz: Fuzzing for Amplification DDoS Vulnerabilities
Johannes Krupp, Ilya Grishchenko, Christian Rossow
USENIX Security Symposium1
2021 ANYway: Measuring the Amplification DDoS Potential of Domains
abstract
DDoS attacks threaten Internet security and stability, with attacks reaching the Tbps range. A popular approach involves DNS-based reflection and amplification, a type of attack in which a domain name, known to return a large answer, is queried using spoofed requests. Do the chosen names offer the largest amplification, however, or have we yet to see the full amplification potential? And while operational countermeasures are proposed, chiefly limiting responses to ‘ANY’ queries, up to what point will these countermeasures be effective? In this paper we make three main contributions. First, we propose and validate a scalable method to estimate the amplification potential of a domain name, based on the expected ANY response size. Second, we create estimates for hundreds of millions of domain names and rank them by their amplification potential. By comparing the overall ranking to the set of domains observed in actual attacks in honeypot data, we show whether attackers are using the most-potent domains for their attacks, or if we may expect larger attacks in the future. Finally, we evaluate the effectiveness of blocking ANY queries, as proposed by the IETF, to limit DNS-based DDoS attacks, by estimating the decrease in attack volume when switching from ANY to other query types. Our results show that by blocking ANY, the response size of domains observed in attacks can be reduced by 57%, and the size of most-potent domains decreases by 69%. However, we also show that dropping ANY is not an absolute solution to DNS-based DDoS, as a small but potent portion of domains remain leading to an expected response size of over 2,048 bytes to queries other than ANY.
Olivier van der Toorn, Johannes Krupp, Mattijs Jonker, Roland van Rijswijk-Deij, Christian Rossow, Anna Sperotto
CNSM2
2021 BGPeek-a-Boo: Active BGP-based Traceback for Amplification DDoS Attacks
abstract
Amplification DDoS attacks inherently rely on IP spoofing to steer attack traffic to the victim. At the same time, IP spoofing undermines prosecution, as the originating attack infrastructure remains hidden. Researchers have therefore proposed various mechanisms to trace back amplification attacks (or IP-spoofed attacks in general). However, existing traceback techniques require either the cooperation of external parties or a priori knowledge about the attacker. We propose BGPEEK-A-Boo, a BGP-based approach to trace back amplification attacks to their origin network. BGPEEK-A-Boo monitors amplification attacks with honeypots and uses BGP Poisoning to temporarily shut down ingress traffic from selected Autonomous Systems. By systematically probing the entire AS space, we detect systems forwarding and originating spoofed traffic. We then show how a graph-based model of BGP route propagation can reduce the search space, resulting in a 5 x median speed-up and over 20x for ¼ of all cases. BGPEEK-A-Boo achieves a unique traceback result 60% of the time in a simulation-based evaluation supported by real-world experiments.
Johannes Krupp, Christian Rossow
EuroS&P1
2018 teEther: Gnawing at Ethereum to Automatically Exploit Smart Contracts
Johannes Krupp, Christian Rossow
USENIX Security Symposium1
2018 Efficient unlinkable sanitizable signatures from signatures with re-randomizable keys
abstract
A sanitizable signature scheme is a malleable signature scheme where a designated third party has the permission to modify certain parts of the message and adapt the signature accordingly. This primitive was introduced by Ateniese et al . (ESORICS 2005) and Brzuska et al . (PKC 2009) formalized the initially suggested five security properties. In the subsequent year, Brzuska et al . (PKC 2010) introduced a notion called unlinkability where the basic idea is that linking message‐signature pairs of the same document should be infeasible. Brzuska et al . formalized this notion and suggested a generic instantiation based on group signatures with a special structure. Unfortunately, the most efficient instantiations of group signatures do not have this property. In this work, we present the first efficient construction of unlinkable sanitizable signatures based on a novel type of signature schemes with re‐randomizable keys. This property allows one to re‐randomize both the signing and the verification key separately but consistently. Given a signature scheme with re‐randomizable keys, we obtain a sanitizable signature scheme by signing the message with a re‐randomized key and proving in zero‐knowledge that the derived key originates from either the signer or the sanitizer. To obtain an efficient instantiation, we instantiate this generic idea with Schnorr signatures and efficient ‐protocols that we turn into a non‐interactive zero‐knowledge proof via the Fiat‐Shamir transformation. In this work, we present an optimized version that is more efficient than the construction we suggested in the extended abstract of this work at PKC 2016.
Nils Fleischhacker, Johannes Krupp, Giulio Malavolta, Jonas Schneider-Bensch, Dominique Schröder, Mark Simkin 0001
IET Inf. Secur.2
2017 Millions of targets under attack: a macroscopic characterization of the DoS ecosystem
abstract
Denial-of-Service attacks have rapidly increased in terms of frequency and intensity, steadily becoming one of the biggest threats to Internet stability and reliability. However, a rigorous comprehensive characterization of this phenomenon, and of countermeasures to mitigate the associated risks, faces many infrastructure and analytic challenges. We make progress toward this goal, by introducing and applying a new framework to enable a macroscopic characterization of attacks, attack targets, and DDoS Protection Services (DPSs). Our analysis leverages data from four independent global Internet measurement infrastructures over the last two years: backscatter traffic to a large network telescope; logs from amplification honeypots; a DNS measurement platform covering 60% of the current namespace; and a DNS-based data set focusing on DPS adoption. Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all / 24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks. In our data, Web servers were the most prominent attack target; an average of 3% of the Web sites in .com, .net, and .org were involved with attacks, daily. Finally, we shed light on factors influencing migration to a DPS.
Mattijs Jonker, Alistair King, Johannes Krupp, Christian Rossow, Anna Sperotto, Alberto Dainotti
Internet Measurement Conference3
2017 Linking Amplification DDoS Attacks to Booter Services
Johannes Krupp, Mohammad Karami, Christian Rossow, Damon McCoy, Michael Backes 0001
RAID1
2016 Identifying the Scan and Attack Infrastructures Behind Amplification DDoS Attacks
abstract
Amplification DDoS attacks have gained popularity and become a serious threat to Internet participants. However, little is known about where these attacks originate, and revealing the attack sources is a non-trivial problem due to the spoofed nature of the traffic.
Johannes Krupp, Michael Backes 0001, Christian Rossow
CCS1
2016 Two-Message, Oblivious Evaluation of Cryptographic Functionalities
Nico Döttling, Nils Fleischhacker, Johannes Krupp, Dominique Schröder
CRYPTO (3)3
2015 AmpPot: Monitoring and Defending Against Amplification DDoS Attacks
Lukas Krämer, Johannes Krupp, Daisuke Makita, Tomomi Nishizoe, Takashi Koide, Katsunari Yoshioka, Christian Rossow
RAID2
2014 POSTER: Enhancing Security and Privacy with Google Glass
abstract
In the past years wearable computing devices, such as head-mounted displays, and ubiquitous computing increasingly gained importance. Head-mounted displays are comprised of a front-facing camera and a little screen in front of the user's eye. They provide their users with a seamless extension of their perceptual abilities in an unobtrusive and user-friendly manner. The Ubic-framework combines these new devices with mathematically sound digital cryptographic primitives and resource-friendly computer vision techniques to provide users with novel security and privacy guarantees in their everyday life. In our hands-on demo we show how Ubic allows users to read encrypted and verify digitally signed physical documents. In addition, we present an identification scheme, which is secure against real-world attacks, such as skimming and shoulder-surfing, but remains user friendly and easily deployable in current infrastructures. The Ubic-framework first appeared at ESORICS 2014.
Johannes Krupp, Dominique Schröder, Mark Simkin 0001
CCS1