Britta Hale

dblp:167/7329 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0003-1131-2109ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Blockchain-Based Authenticated Stego-Channels and Application to Ethereum
abstract
Given their usefulness for evading traceability in networks, it is not surprising that steganographic techniques continue in the modern era and have been looked at through the lens of modern threats and technologies. Among such threats include the linkage of contextual information (associated data) to de-anonymize traffic. Such detection would be fatal to steganographic goals. Cryptographic analyses have expanded to include associated data when analyzing confidentiality and authenticity in channel security; in this work we take a similar approach and extrapolate the security model for steganographic analysis to also account for contextual information. We introduce the security definition of Authenticated Stegotext with Associated Data (ASAD), which captures steganographic properties even when there is contextual information sent alongside the hidden data, and provide a concrete stego-embedding scheme, Authenticated SteGotex with Associated tRansaction Data (ASGARD). Our scheme leverages a blockchain-based channel medium for the transmission of hidden data, namely the Ethereum blockchain. We analyze ASGARD in the ASAD framework and present details on implementation and real-world security considerations.
Vikram Kanth, Britta Hale
IEEE Trans. Dependable Secur. Comput.2
2024 DRACO: Production Network Deployment and Evaluation of Deceptive Defense As-a-Service
abstract
Cybersecurity increasingly involves not only passive security measures, but also an active approach to network defense whereby network managers can potentially gain an a priori view of potential threats. Honeypots have long offered one such active measure through cyber deception, but present realistic deployment challenges in government contexts due to increased security risks (internal honeypots) or disassociation with the real network (external honeypots). Furthermore, while various deployment methods have been proposed, organizational management agreement for deployment of honeypots on real, operational networks is a common research obstacle, leading to a lack of insight about actual use on such systems. In this work, we deploy and analyze a honeypot architecture concept, Deceptive Resistance to Adversary Cyber Operations (DRACO) – a live network honeypot for a government associated network. DRACO strikes a balance between external and internal honeypot placement, successfully mitigating risk and enabling system security management approval. We validate the concept, with analysis showing a difference in adversarial activity on DRACO, as connected to a live government-operated network, versus control honeypot deployments and provides insight on potential honeypot deployment without risk to production networks.
Mathieu Couillard, Britta Hale
IEEE Big Data2
2021 Secure Messaging Authentication against Active Man-in-the-Middle Attacks
abstract
Modern messaging applications often rely on out-of-band communication to achieve entity authentication, with human users verifying and attesting to long-term public keys. This is done primarily to reduce reliance on trusted third parties by replacing that role with the user. Despite a great deal of research focusing on analyzing the confidentiality aspect of secure messaging, the entity authenticity aspect of it, which relies on the user mediation, has been largely assumed away. Consequently, while many existing protocols provide some confidentiality guarantees after a compromise, such as post-compromise security (PCS), authenticity guarantees are generally lost, especially against an active attacker. This leads to potential man-in-the-middle (MitM) attacks. In this work, we address this gap by proposing a model to formally capture user-mediated entity authentication, as used by realworld protocols, that can be composed with any ratcheted key exchange. Our threat model captures active post-compromise entity authentication security. We demonstrate that the Signal application's user-mediated authentication protocol cannot be proven secure in this model and suggest a straightforward fix for Signal that allows the detection of an active adversary. Our results have direct implications for other existing and future ratcheted secure messaging applications.
Benjamin Dowling, Britta Hale
EuroS&P2
2021 The Bluetooth CYBORG: Analysis of the Full Human-Machine Passkey Entry AKE Protocol
Michael Troncoso, Britta Hale
NDSS2
2021 Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks
abstract
Software-defined networking (SDN) has become a fundamental technology for data centers and 5G networks. Transport Layer Security (TLS) has been proposed as its single security layer for SDN networks; however, use of TLS is optional and TLS connections between the controller and switches are still vulnerable to downgrade attacks. In this paper, we propose a protocol dialecting approach to provide additional and customizable security assurance for network control messages. We consider and evaluate two dialecting approaches for OpenFlow protocol operation, adding per-message authentication to the SDN control channel that is independent of TLS and provides robustness against downgrade attacks targeting TLS. Furthermore, we measure the performance impact of using these dialecting primitives in a Mininet experiment. The results show a modest increase of communication latency of less than 22%.
Michael Sjoholmsierchio, Britta Hale, Daniel Lukaszewski, Geoffrey G. Xie
NetSoft2
2021 The Complexities of Healing in Secure Group Messaging: Why Cross-Group Effects Matter
Cas Cremers, Britta Hale, Konrad Kohbrok
USENIX Security Symposium2
2018 User-Mediated Authentication Protocols and Unforgeability in Key Collision
Britta Hale
ProvSec1
2017 Simple Security Definitions for and Constructions of 0-RTT Key Exchange
Britta Hale, Tibor Jager, Sebastian Lauer, Jörg Schwenk
ACNS1
2017 0-RTT Key Exchange with Full Forward Secrecy
Felix Günther 0001, Britta Hale, Tibor Jager, Sebastian Lauer
EUROCRYPT (3)2
2016 From Stateless to Stateful: Generic Authentication and Authenticated Encryption Constructions with Application to TLS
Colin Boyd, Britta Hale, Stig Fr. Mjølsnes, Douglas Stebila
CT-RSA2