Dalton A. Brucker-Hahn

dblp:224/0849 · also Dalton A. Hahn · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
4since 2021 · last 2024
0000-0002-7117-2155ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 2Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2024 CloudCover: Enforcement of Multi-Hop Network Connections in Microservice Deployments
abstract
Microservices have emerged as a strong architecture for large-scale, distributed systems in the context of cloud computing and containerization. However, the size and complexity of microservice systems have strained current access control mechanisms. Intricate dependency structures, such as multi-hop dependency chains, go uncaptured by existing access control mechanisms and leave microservice deployments open to adversarial actions and influence.This work introduces CloudCover, an access control mechanism and enforcement framework for microservices. CloudCover provides holistic, deployment-wide analysis of microservice operations and behaviors. It implements a verification-in-the-loop access control approach, mitigating multi-hop microservice threats through control-flow integrity checks. We evaluate these domain-relevant multi-hop threats and CloudCover under existing, real-world scenarios such as Istio’s opensource microservice example and under theoretic and synthetic network loads of 10,000 requests per second. Our results show that CloudCover is appropriate for use in real deployments, requiring no microservice code changes by administrators.
Dalton A. Brucker-Hahn, Shanchao Li, Matthew Petillo, Alexandru G. Bardas, Drew Davidson, Yuede Ji
ACSAC1
2024 Web-Armour: Mitigating Reconnaissance and Vulnerability Scanning with Scan-Impeding Delays in Web Deployments
abstract
Reconnaissance is a critical phase in many cyber attacks. Vulnerability scanning, a key component of reconnaissance, has been shown to be a widespread phenomenon on the internet and commonly targets web application/server deployments. By increasing the costs for vulnerability scanning, many of these attacks may be deterred or even prevented, especially for large-scale, internet-wide campaigns.In this paper, we propose Web-Armour, a mitigation approach to adversarial reconnaissance. Operating as a delay injection mechanism to infrequently executed code portions of a web deployment, Web-Armour significantly increases the cost for attackers to perform automated reconnaissance and vulnerability scanning, while introducing minimal to negligible impact for benign users. We evaluated Web-Armour in a live environment, operated by real users, and in controlled (offline) scenarios. Using Web-Armour, our results show that automated scanning tools may require up to 396 times longer in an offline setting, and up to 357 times longer in a real-world operational deployment to complete compared to unprotected installations. In many instances, scanning tools fail to complete their tasks, due to request timeouts. Furthermore, the performance overhead incurred to benign users is minimal, and can be as low as a 0.6% increase over the baseline.
Yousif Dafalla, Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas
ACSAC2
2023 Raw Packet Data Ingestion with Transformers for Malicious Activity Classifications
abstract
Traffic diversity, novel attacks, and sheer volume of network traffic creates a significant challenge in detecting and identifying malicious actions against a network. Due to these factors, human auditing of network events is unfeasible, requiring advanced approaches, such as machine learning techniques. Furthermore, the increasing novelty of network attacks render traditional filtering mechanisms unable to handle such threats. In this paper, we propose a novel, natural language processing approach to detecting malicious, network-based attacks, using ByT5. Our approach classifies network packet data as malicious or benign. ByT5 is a token-free sequence to sequence model, enabling the model to take in raw packet streams and classify the packets without feature extraction or preprocessing via an encoding schema. The results of our approach in classifying traffic as benign or malicious indicates promising results. Namely, when applied to the ISOT dataset, our approach achieves a maximal recall of 0.834 and a maximal F1 score of 0.693.
Nitin Sharan, Thomas Quig, Eric Goodman, Yung Ryn Choe, Dalton A. Brucker-Hahn
ICMLA5
2023 Work-From-Home and COVID-19: Trajectories of Endpoint Security Management in a Security Operations Center
Kailani R. Jones, Dalton A. Brucker-Hahn, Bradley Fidler, Alexandru G. Bardas
USENIX Security Symposium2
2020 Measuring the Prevalence of the Password Authentication Vulnerability in SSH
abstract
Securing and hardening network protocols and services is a resource-consuming and continuous effort. Thus, it is important to question how prolific known, mitigable features of those protocols are. The Secure Shell (SSH) protocol is a good example due to its known vulnerability in using password based authentication. We take a closer look at these configurations to identify how prevalent the use of password authentication is at an internet scale. We show that current scanning tools and services provide a starting point in evaluating prevalence, but need to be validated for specific implementations. We also demonstrate that it is possible to augment some of these tools and services to determine the prevalence of password authentication in SSH specifically. As part of our evaluation, we propose a novel method for probing an SSH service to establish if password authentication is allowed, without being intrusive or causing harm to the host. Finally, we show that our analysis has resulted in determining that more than 65% of the over 20 million SSH servers on the public internet allow password authentication.
Ron Andrews, Dalton A. Brucker-Hahn, Alexandru G. Bardas
ICC2
2020 MisMesh: Security Issues and Challenges in Service Meshes
Dalton A. Brucker-Hahn, Drew Davidson, Alexandru G. Bardas
SecureComm (1)1
2018 eyeDNS: Monitoring a University Campus Network
abstract
The Domain Name System (DNS) is responsible for mapping human readable domain names to internet protocol (IP) addresses. DNS is a ubiquitous part of internet and intranet communication, making it a convenient and comprehensive source for data to infer network health, performance, and security. A victim of its own success, monitoring real-time DNS traffic is a challenge due to sheer volume: huge amounts of DNS packets flow through a typical enterprise in a single day. In this paper, we describe eyeDNS, a scalable and extensible system for near real-time aggregation, storage, analysis, and visualization of DNS traffic collected by a hardware back-end. We report on eyeDNS's deployment and data collection on a large public university's network over a timeframe of 15 months. Moreover, we leveraged data from the following 6 months to validate findings made during the initial timeframe. With fast query response, aggregation, and visualization of DNS data, eyeDNS helped identify instances of anomalous network use, malware-specific behaviors, and scamming activities. eyeDNS is currently being used by the university's security personnel and has demonstrated its effectiveness in extracting trends and outliers from large volumes of DNS data collected from a diverse environment, where even commercial tools struggle to provide timely and actionable analysis.
Chandan Chowdhury, Dalton A. Brucker-Hahn, Matthew R. French, Eugene Y. Vasserman, Pratyusa K. Manadhata, Alexandru G. Bardas
ICC2