VLDB 2026 Research / reviewers in the wild / expert
Nolen Scaife
dblp:167/0436
· DBLP profile ↗
14ranked-venue papers
4as first author
2since 2021 · last 2021
0000-0003-2305-299XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 3 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Prognosis Negative: Evaluating Real-Time Behavioral Ransomware DetectorsabstractRansomware attacks continue to grow in both severity and prevalence as attackers target public infrastructure, governments, and companies. This problem has spawned a wide range of anti-ransomware techniques which are evaluated by their capability of detecting known samples, but these samples are difficult to obtain and unreliable. Due to polymorphism and the ease of implementing new methods of attack, anti-ransomware is more likely needed to protect against an unknown binary than a known sample. In this paper, we create an extensible framework (Farfel) for testing anti-ransomware products that does not rely on evaluation with known samples. Our framework consists of 21 unique fundamental behavior variations which can be selected to form 1,536 unique attacks. Using this, we evaluate seven commercial and academic anti-ransomware products to identify gaps in coverage of fundamental behaviors. Our evaluation uncovers significant gaps in every product, with three commercial products detecting zero cases. We believe that testing on a wide variety of behaviors will ultimately result in more effective detectors in the future. Aditi Prakash, Nolen Scaife |
EuroS&P | 3 |
| 2021 | NATting Else Matters: Evaluating IPv6 Access Control Policies in Residential Networks
Karl Olson, Jack Wampler, Nolen Scaife |
PAM | 4 |
| 2019 | Digital Healthcare-Associated Infection: A Case Study on the Security of a Major Multi-Campus Hospital System
Luis Vargas, Logan Blue, Vanessa Frost, Christopher Patton, Nolen Scaife, Kevin R. B. Butler, Patrick Traynor |
NDSS | 5 |
| 2019 | Kiss from a Rogue: Evaluating Detectability of Pay-at-the-Pump Card SkimmersabstractCredit and debit cards enable financial transactions at unattended "pay-at-the-pump" gas station terminals across North America. Attackers discreetly open these pumps and install skimmers, which copy sensitive card data. While EMV (“chip-and-PIN”) has made substantial inroads in traditional retailers, such systems have virtually no deployment at pay-at-the-pump terminals due to dramatically higher costs and logistical/regulatory constraints, leaving consumers vulnerable in these contexts. In an effort to improve security, station owners have deployed security indicators such as low-cost tamper-evident seals, and technologists have developed skimmer detection apps for mobile phones. Not only do these solutions put the onus on consumers to notice and react to security concerns at the pump, but the efficacy of these solutions has not been measured. In this paper, we evaluate the indicators available to consumers to detect skimmers. We perform a comprehensive teardown of all known skimmer detection apps for iOS and Android devices, and then conduct a forensic analysis of real-world gas pump skimmer hardware recovered by multiple law enforcement agencies. Finally, we analyze anti-skimmer mechanisms deployed by pump owners/operators, and augment this investigation with an analysis of skimmer reports and accompanying security measures collected by the Florida Department of Agriculture and Consumer Services over four years, making this the most comprehensive long-term study of such devices. Our results show that common gas pump security indicators are not only ineffective at empowering consumers to detect tampering, but may be providing a false sense of security. Accordingly, stronger, reliable, inexpensive measures must be developed to protect consumers and merchants from fraud. Nolen Scaife, Jasmine D. Bowers, Christian Peeters, Grant Hernandez, Imani N. S. Munyaka, Patrick Traynor, Lisa Anthony |
IEEE Symposium on Security and Privacy | 1 |
| 2019 | Characterizing the Security of the SMS Ecosystem with Public GatewaysabstractRecent years have seen the Short Message Service (SMS) become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this article, we provide a comprehensive longitudinal study to answer these questions, analyzing over 900,000 text messages sent to public online SMS gateways over the course of 28 months. From this data, we uncover the geographical distribution of spam messages, study SMS as a transmission medium of malicious content, and find that changes in benign and malicious behaviors in the SMS ecosystem have been minimal during our collection period. The key takeaways of this research show many services sending sensitive security-based messages through an unencrypted medium, implementing low entropy solutions for one-use codes, and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for combating phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent. Bradley Reaves, Luis Vargas, Nolen Scaife, Jing (Dave) Tian, Logan Blue, Patrick Traynor, Kevin R. B. Butler |
ACM Trans. Priv. Secur. | 3 |
| 2018 | Sonar: Detecting SS7 Redirection Attacks with Audio-Based Distance BoundingabstractThe global telephone network is relied upon by billions every day. Central to its operation is the Signaling System 7 (SS7) protocol, which is used for setting up calls, managing mobility, and facilitating many other network services. This protocol was originally built on the assumption that only a small number of trusted parties would be able to directly communicate with its core infrastructure. As a result, SS7 - as a feature - allows all parties with core access to redirect and intercept calls for any subscriber anywhere in the world. Unfortunately, increased interconnectivity with the SS7 network has led to a growing number of illicit call redirection attacks. We address such attacks with Sonar, a system that detects the presence of SS7 redirection attacks by securely measuring call audio round-trip times between telephony devices. This approach works because redirection attacks force calls to travel longer physical distances than usual, thereby creating longer end-to-end delay. We design and implement a distance bounding-inspired protocol that allows us to securely characterize the round-trip time between the two endpoints. We then use custom hardware deployed in 10 locations across the United States and a redirection testbed to characterize how distance affects round trip time in phone networks. We develop a model using this testbed and show Sonar is able to detect 70.9% of redirected calls between call endpoints of varying attacker proximity (300-7100 miles) with low false positive rates (0.3%). Finally, we ethically perform actual SS7 redirection attacks on our own devices with the help of an industry partner to demonstrate that Sonar detects 100% of such redirections in a real network (with no false positives). As such, we demonstrate that telephone users can reliably detect SS7 redirection attacks and protect the integrity of their calls. Christian Peeters, Hadi Abdullah, Nolen Scaife, Jasmine D. Bowers, Patrick Traynor, Bradley Reaves, Kevin R. B. Butler |
IEEE Symposium on Security and Privacy | 3 |
| 2018 | The Cards Aren't Alright: Detecting Counterfeit Gift Cards Using Encoding JitterabstractGift cards are an increasingly popular payment platform. Much like credit cards, gift cards rely on a magnetic stripe to encode account information. Unlike credit cards, however, the EMV standard is entirely infeasible for gift cards due to compatibility and cost. As such, much of the fraud that has plagued credit cards has started to move towards gift cards, resulting in billions of dollars of loss annually. In this paper, we present a system for detecting counterfeit magnetic stripe gift cards that does not require the original card to be measured at the time of manufacture. Our system relies on a phenomenon known as jitter, which is present on all ISO/IEC-standard magnetic stripe cards. Variances in bit length are induced by the card encoding hardware and are difficult and expensive to reduce. We verify this hypothesis with a high-resolution magneto-optical microscope, then build our detector using inexpensive, commodity card readers. We then partnered with Walmart to evaluate their gift cards and distinguished legitimate gift cards from our clones with up to 99.3% accuracy. Our results show that measurement and detection of jitter increases the difficulty for adversaries to produce undetectable counterfeits, thereby creating significant opportunity to reduce gift card fraud. Nolen Scaife, Christian Peeters, Camilo Velez, Patrick Traynor, David P. Arnold |
IEEE Symposium on Security and Privacy | 1 |
| 2018 | SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CabstractUSB-based attacks have increased in complexity in recent years. Modern attacks now incorporate a wide range of attack vectors, from social engineering to signal injection. To address these challenges, the security community has responded with a growing set of fragmented defenses. In this work, we survey and categorize USB attacks and defenses, unifying observations from both peer-reviewed research and industry. Our systematization extracts offensive and defensive primitives that operate across layers of communication within the USB ecosystem. Based on our taxonomy, we discover that USB attacks often abuse the trust-by-default nature of the ecosystem, and transcend different layers within a software stack; none of the existing defenses provide a complete solution, and solutions expanding multiple layers are most effective. We then develop the first formal verification of the recently released USB Type-C Authentication specification, and uncover fundamental flaws in the specification's design. Based on the findings from our systematization, we observe that while the spec has successfully pinpointed an urgent need to solve the USB security problem, its flaws render these goals unattainable. We conclude by outlining future research directions to ensure a safer computing experience with USB. Jing (Dave) Tian, Nolen Scaife, Deepak Kumar 0006, Michael D. Bailey, Adam Bates 0001, Kevin R. B. Butler |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | Fear the Reaper: Characterization and Fast Detection of Card Skimmers
Nolen Scaife, Christian Peeters, Patrick Traynor |
USENIX Security Symposium | 1 |
| 2017 | Mo(bile) Money, Mo(bile) Problems: Analysis of Branchless Banking ApplicationsabstractMobile money, also known as branchless banking, leverages ubiquitous cellular networks to bring much-needed financial services to the unbanked in the developing world. These services are often deployed as smartphone apps, and although marketed as secure, these applications are often not regulated as strictly as traditional banks, leaving doubt about the truth of such claims. In this article, we evaluate these claims and perform the first in-depth measurement analysis of branchless banking applications. We first perform an automated analysis of all 46 known Android mobile money apps across the 246 known mobile money providers from 2015. We then perform a comprehensive manual teardown of the registration, login, and transaction procedures of a diverse 15% of these apps. We uncover pervasive vulnerabilities spanning botched certification validation, do-it-yourself cryptography, and other forms of information leakage that allow an attacker to impersonate legitimate users, modify transactions, and steal financial records. These findings show that the majority of these apps fail to provide the protections needed by financial services. In an expanded re-evaluation one year later, we find that these systems have only marginally improved their security. Additionally, we document our experiences working in this sector for future researchers and provide recommendations to improve the security of this critical ecosystem. Finally, through inspection of providers’ terms of service, we also discover that liability for these problems unfairly rests on the shoulders of the customer, threatening to erode trust in branchless banking and hinder efforts for global financial inclusion. Bradley Reaves, Jasmine D. Bowers, Nolen Scaife, Adam Bates 0001, Arnav Bhartiya, Patrick Traynor, Kevin R. B. Butler |
ACM Trans. Priv. Secur. | 3 |
| 2016 | CryptoLock (and Drop It): Stopping Ransomware Attacks on User DataabstractRansomware is a growing threat that encrypts auser's files and holds the decryption key until a ransom ispaid by the victim. This type of malware is responsible fortens of millions of dollars in extortion annually. Worse still, developing new variants is trivial, facilitating the evasion of manyantivirus and intrusion detection systems. In this work, we presentCryptoDrop, an early-warning detection system that alerts a userduring suspicious file activity. Using a set of behavior indicators, CryptoDrop can halt a process that appears to be tampering witha large amount of the user's data. Furthermore, by combininga set of indicators common to ransomware, the system can beparameterized for rapid detection with low false positives. Ourexperimental analysis of CryptoDrop stops ransomware fromexecuting with a median loss of only 10 files (out of nearly5,100 available files). Our results show that careful analysis ofransomware behavior can produce an effective detection systemthat significantly mitigates the amount of victim data loss. Nolen Scaife, Henry Carter, Patrick Traynor, Kevin R. B. Butler |
ICDCS | 1 |
| 2016 | Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public GatewaysabstractText messages sent via the Short Message Service (SMS) have revolutionized interpersonal communication. Recent years have also seen this service become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this paper, we provide the first longitudinal study to answer these questions, analyzing nearly 400,000 text messages sent to public online SMS gateways over the course of 14 months. From this data, we are able to identify not only a range of services sending extremely sensitive plaintext data and implementing low entropy solutions for one-use codes, but also offer insights into the prevalence of SMS spam and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for research combatting phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent. Bradley Reaves, Nolen Scaife, Jing (Dave) Tian, Logan Blue, Patrick Traynor, Kevin R. B. Butler |
IEEE Symposium on Security and Privacy | 2 |
| 2016 | Making USB Great Again with USBFILTER
Jing (Dave) Tian, Nolen Scaife, Adam Bates 0001, Kevin R. B. Butler, Patrick Traynor |
USENIX Security Symposium | 2 |
| 2015 | Mo(bile) Money, Mo(bile) Problems: Analysis of Branchless Banking Applications in the Developing World
Bradley Reaves, Nolen Scaife, Adam Bates 0001, Patrick Traynor, Kevin R. B. Butler |
USENIX Security Symposium | 2 |