VLDB 2026 Research / reviewers in the wild / expert
Billy Bob Brumley
dblp:25/1876
· DBLP profile ↗
27ranked-venue papers
9as first author
7since 2021 · last 2023
0000-0001-9160-0463ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 7 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Malware Finances and Operations: a Data-Driven Study of the Value Chain for Infections and Compromised AccessabstractWe investigate the criminal market dynamics of infostealer malware and publish three evidence datasets on malware infections and trade. We justify the value chain between illicit enterprises using the datasets, compare the prices and added value, and use the value chain to identify the most effective countermeasures. Juha Nurmi, Mikko S. Niemelä, Billy Bob Brumley |
ARES | 3 |
| 2023 | SoK: A Systematic Review of TEE Usage for Developing Trusted ApplicationsabstractTrusted Execution Environments (TEEs) are a feature of modern central processing units (CPUs) that aim to provide a high assurance, isolated environment in which to run workloads that demand both confidentiality and integrity. Hardware and software components in the CPU isolate workloads, commonly referred to as Trusted Applications (TAs), from the main operating system (OS). This article aims to analyse the TEE ecosystem, determine its usability, and suggest improvements where necessary to make adoption easier. To better understand TEE usage, we gathered academic and practical examples from a total of 223 references. We summarise the literature and provide a publication timeline, along with insights into the evolution of TEE research and deployment. We categorise TAs into major groups and analyse the tools available to developers. Lastly, we evaluate trusted container projects, test performance, and identify the requirements for migrating applications inside them. Arttu Paju, Muhammad Owais Javed, Juha Nurmi, Juha Savimäki, Brian McGillion, Billy Bob Brumley |
ARES | 6 |
| 2022 | HyperDegrade: From GHz to MHz Effective CPU Frequencies
Alejandro Cabrera Aldaya, Billy Bob Brumley |
USENIX Security Symposium | 2 |
| 2022 | OpenSSLNTRU: Faster post-quantum TLS key exchange
Daniel J. Bernstein, Billy Bob Brumley, Ming-Shing Chen, Nicola Tuveri |
USENIX Security Symposium | 2 |
| 2021 | SoK: Remote Power AnalysisabstractIn recent years, numerous attacks have appeared that aim to steal secret information from their victim using the power side-channel vector, yet without direct physical access. These attacks are called Remote Power Attacks or Remote Power Analysis, utilizing resources that are natively present inside the victim environment. However, there is no unified definition about the limitations that a power attack requires to be defined as remote. This paper aims to propose a unified definition and concrete threat models to clearly differentiate remote power attacks from non-remote ones. Additionally, we collect the main remote power attacks performed so far from the literature, and the principal proposed countermeasures to avoid them. The search of such countermeasures denoted a clear gap in preventing remote power attacks at the technical level. Thus, the academic community must face an important challenge to avoid this emerging threat, given the clear room for improvement that should be addressed in terms of defense and security of devices that work with private information. Macarena C. Martínez-Rodríguez, Ignacio M. Delgado-Lozano, Billy Bob Brumley |
ARES | 3 |
| 2021 | A Formula for Disaster: A Unified Approach to Elliptic Curve Special-Point-Based Attacks
Vladimir Sedlacek, Jesús-Javier Chi-Domínguez, Jan Jancar, Billy Bob Brumley |
ASIACRYPT (1) | 4 |
| 2021 | Attestation Waves: Platform Trust via Remote Power Analysis
Ignacio M. Delgado-Lozano, Macarena C. Martínez-Rodríguez, Alexandros Bakas, Billy Bob Brumley, Antonis Michalas |
CANS | 4 |
| 2020 | Set It and Forget It! Turnkey ECC for Instant IntegrationabstractHistorically, Elliptic Curve Cryptography (ECC) is an active field of applied cryptography where recent focus is on high speed, constant time, and formally verified implementations. While there are a handful of outliers where all these concepts join and land in real-world deployments, these are generally on a case-by-case basis: e.g. a library may feature such X25519 or P-256 code, but not for all curves. In this work, we propose and implement a methodology that fully automates the implementation, testing, and integration of ECC stacks with the above properties. We demonstrate the flexibility and applicability of our methodology by seamlessly integrating into three real-world projects: OpenSSL, Mozilla’s NSS, and the GOST OpenSSL Engine, achieving roughly 9.5x, 4.5x, 13.3x, and 3.7x speedup on any given curve for key generation, key agreement, signing, and verifying, respectively. Furthermore, we showcase the efficacy of our testing methodology by uncovering flaws and vulnerabilities in OpenSSL, and a specification-level vulnerability in a Russian standard. Our work bridges the gap between significant applied cryptography research results and deployed software, fully automating the process. Dmitry Belyavsky, Billy Bob Brumley, Jesús-Javier Chi-Domínguez, Luis Rivera-Zamarripa, Igor Ustinov |
ACSAC | 2 |
| 2020 | Déjà Vu: Side-Channel Analysis of Mozilla's NSSabstractRecent work on Side Channel Analysis (SCA) targets old, well-known vulnerabilities, even previously exploited, reported, and patched in high-profile cryptography libraries. Nevertheless, researchers continue to find and exploit the same vulnerabilities in old and new products, highlighting a big issue among vendors: effectively tracking and fixing security vulnerabilities when disclosure is not done directly to them. In this work, we present another instance of this issue by performing the first library-wide SCA security evaluation of Mozilla's NSS security library. We use a combination of two independently-developed SCA security frameworks to identify and test security vulnerabilities. Our evaluation uncovers several new vulnerabilities in NSS affecting DSA, ECDSA, and RSA cryptosystems. We exploit said vulnerabilities and implement key recovery attacks using signals---extracted through different techniques such as timing, microarchitecture, and EM---and improved lattice methods. Sohaib ul Hassan, Iaroslav Gridin, Ignacio M. Delgado-Lozano, Cesar Pereida García, Jesús-Javier Chi-Domínguez, Alejandro Cabrera Aldaya, Billy Bob Brumley |
CCS | 7 |
| 2020 | Certified Side Channels
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin, Alejandro Cabrera Aldaya, Billy Bob Brumley |
USENIX Security Symposium | 6 |
| 2019 | Triggerflow: Regression Testing by Advanced Execution Path Inspection
Iaroslav Gridin, Cesar Pereida García, Nicola Tuveri, Billy Bob Brumley |
DIMVA | 4 |
| 2019 | Port Contention for Fun and ProfitabstractSimultaneous Multithreading (SMT) architectures are attractive targets for side-channel enabled attackers, with their inherently broader attack surface that exposes more per physical core microarchitecture components than cross-core attacks. In this work, we explore SMT execution engine sharing as a side-channel leakage source. We target ports to stacks of execution units to create a high-resolution timing side-channel due to port contention, inherently stealthy since it does not depend on the memory subsystem like other cache or TLB based attacks. Implementing our channel on Intel Skylake and Kaby Lake architectures featuring Hyper-Threading, we mount an end-to-end attack that recovers a P-384 private key from an OpenSSL-powered TLS server using a small number of repeated TLS handshake attempts. Furthermore, we show that traces targeting shared libraries, static builds, and SGX enclaves are essentially identical, hence our channel has wide target application. Alejandro Cabrera Aldaya, Billy Bob Brumley, Sohaib ul Hassan, Cesar Pereida García, Nicola Tuveri |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | Side-Channel Analysis of SM2: A Late-Stage Featurization Case StudyabstractSM2 is a public key cryptography suite originating from Chinese standards, including digital signatures and public key encryption. Ahead of schedule, code for this functionality was recently mainlined in OpenSSL, marked for the upcoming 1.1.1 release. We perform a security review of this implementation, uncovering various deficiencies ranging from traditional software quality issues to side-channel risks. To assess the latter, we carry out a side-channel security evaluation and discover that the implementation hits every pitfall seen for OpenSSL's ECDSA code in the past decade. We carry out remote timings, cache timings, and EM analysis, with accompanying empirical data to demonstrate secret information leakage during execution of both digital signature generation and public key decryption. Finally, we propose, implement, and empirically evaluate countermeasures. Nicola Tuveri, Sohaib ul Hassan, Cesar Pereida García, Billy Bob Brumley |
ACSAC | 4 |
| 2017 | Constant-Time Callees with Variable-Time Callers
Cesar Pereida García, Billy Bob Brumley |
USENIX Security Symposium | 2 |
| 2016 | Amplifying side channels through performance degradation
Thomas Allan, Billy Bob Brumley, Katrina Falkner, Joop van de Pol, Yuval Yarom |
ACSAC | 2 |
| 2016 | "Make Sure DSA Signing Exponentiations Really are Constant-Time"abstractTLS and SSH are two of the most commonly used protocols for securing Internet traffic. Many of the implementations of these protocols rely on the cryptographic primitives provided in the OpenSSL library. In this work we disclose a vulnerability in OpenSSL, affecting all versions and forks (e.g. LibreSSL and BoringSSL) since roughly October 2005, which renders the implementation of the DSA signature scheme vulnerable to cache-based side-channel attacks. Exploiting the software defect, we demonstrate the first published cache-based key-recovery attack on these protocols: 260 SSH-2 handshakes to extract a 1024/160-bit DSA host key from an OpenSSH server, and 580 TLS 1.2 handshakes to extract a 2048/256-bit DSA key from an stunnel server. Cesar Pereida García, Billy Bob Brumley, Yuval Yarom |
CCS | 2 |
| 2015 | Cache Storage Attacks
Billy Bob Brumley |
CT-RSA | 1 |
| 2013 | Faster 128-EEA3 and 128-EIA3 Software
Roberto Maria Avanzi, Billy Bob Brumley |
ISC | 2 |
| 2012 | Practical Realisation and Elimination of an ECC-Related Software Bug Attack
Billy Bob Brumley, Manuel Barbosa, Dan Page, Frederik Vercauteren |
CT-RSA | 1 |
| 2011 | Bit-Sliced Binary Normal Basis MultiplicationabstractThe performance of many cryptographic primitives is reliant on efficient algorithms and implementation techniques for arithmetic in binary fields. While dedicated hardware support for said arithmetic is an emerging trend, the study of software-only implementation techniques remains important for legacy or non-equipped processors. One such technique is that of software-based bit-slicing. In the context of binary fields, this is an interesting option since there is extensive previous work on bit-oriented designs for arithmetic in hardware, such designs are intuitively well suited to bit-slicing in software. In this paper we harness previous work, using it to investigate bit-sliced, software-only implementation arithmetic for binary fields, over a range of practical field sizes and using a normal basis representation. We apply our results to demonstrate significant performance improvements for a stream cipher, and over the frequently employed Ning-Yin approach to normal basis implementation in software. Billy Bob Brumley, Dan Page |
IEEE Symposium on Computer Arithmetic | 1 |
| 2011 | Remote Timing Attacks Are Still Practical
Billy Bob Brumley, Nicola Tuveri |
ESORICS | 1 |
| 2010 | New Results on Instruction Cache Attacks
Onur Aciiçmez, Billy Bob Brumley, Philipp Grabher |
CHES | 2 |
| 2010 | Consecutive S-box Lookups: A Timing Attack on SNOW 3G
Billy Bob Brumley, Risto M. Hakala, Kaisa Nyberg, Sampo Sovio |
ICICS | 1 |
| 2010 | Conversion Algorithms and Implementations for Koblitz Curve CryptographyabstractIn this paper, we discuss conversions between integers and tau-adic expansions and we provide efficient algorithms and hardware architectures for these conversions. The results have significance in elliptic curve cryptography using Koblitz curves, a family of elliptic curves offering faster computation than general elliptic curves. However, in order to enable these faster computations, scalars need to be reduced and represented using a special base-tau expansion. Hence, efficient conversion algorithms and implementations are necessary. Existing conversion algorithms require several complicated operations, such as multiprecision multiplications and computations with large rationals, resulting in slow and large implementations in hardware and microcontrollers with limited instruction sets. Our algorithms are designed to utilize only simple operations, such as additions and shifts, which are easily implementable on practically all platforms. We demonstrate the practicability of the new algorithms by implementing them on Altera Stratix II FPGAs. The implementations considerably improve both computation speed and required area compared to the existing solutions. Billy Bob Brumley, Kimmo Järvinen 0001 |
IEEE Trans. Computers | 1 |
| 2009 | Cache-Timing Template Attacks
Billy Bob Brumley, Risto M. Hakala |
ASIACRYPT | 1 |
| 2007 | Differential Properties of Elliptic Curves and Blind Signatures
Billy Bob Brumley, Kaisa Nyberg |
ISC | 1 |
| 2006 | Left-to-Right Signed-Bit tau-Adic Representations of n Integers (Short Paper)
Billy Bob Brumley |
ICICS | 1 |