VLDB 2026 Research / reviewers in the wild / expert
Hugo L. Jonker
dblp:33/1453 · also Hugo Jonker
· DBLP profile ↗
19ranked-venue papers
4as first author
5since 2021 · last 2023
0000-0002-7958-8921ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 4 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Reconstructing Timelines: From NTFS Timestamps to File HistoriesabstractFile history facilitates the creation of a timeline of attributed events, which is crucial in digital forensics. Timestamps play an important role for determining what happened to a file. Previous studies into leveraging timestamps to determine file history focused on identification of the last operation applied to a file. In contrast, in this paper, we determine all possible file histories given a file’s current NTFS timestamps. That is, we infer all possible sequences of file system operations which culminate in the file’s current NTFS timestamps. This results in a tree of timelines, with root node the current file state. Our method accounts for various forms of timestamp forgery. We provide an implementation of this method that depicts possible histories graphically. Jelle Bouma, Hugo L. Jonker, Vincent van der Meer, Eddy Van Den Aker |
ARES | 2 |
| 2022 | How gullible are web measurement tools?: a case study analysing and strengthening OpenWPM's reliabilityabstractAutomated browsers are widely used to study the web at scale. Their premise is that they measure what regular browsers would encounter on the web. In practice, deviations due to detection of automation have been found. To what extent automated browsers can be improved to reduce such deviations has so far not been investigated in detail. In this paper, we investigate this for a specific web automation framework: OpenWPM, a popular research framework specifically designed to study web privacy. We analyse (1) detectability of OpenWPM, (2) resilience of OpenWPM's data recording, and (3) prevalence of OpenWPM detection. Benjamin Krumnow, Hugo L. Jonker, Stefan Karsch |
CoNEXT | 2 |
| 2022 | Elysium: Context-Aware Bytecode-Level Patching to Automatically Heal Vulnerable Smart ContractsabstractFixing bugs is easiest by patching source code. However, source code is not always available: only 0.3% of the ∼ 49M smart contracts that are currently deployed on Ethereum have their source code publicly available. Moreover, since contracts may call functions from other contracts, security flaws in closed-source contracts may affect open-source contracts as well. However, current state-of-the-art approaches that operate on closed-source contracts (i.e., EVM bytecode), such as EVMPatch and SmartShield, make use of purely hard-coded templates that leverage fix patching patterns. As a result, they cannot dynamically adapt to the bytecode that is being patched, which severely limits their flexibility and scalability. For instance, when patching integer overflows using hard-coded templates, a particular patch template needs to be employed as the bounds to be checked are different for each integer size (i.e., one template for uint256, another template for uint64, etc.). Christof Ferreira Torres, Hugo L. Jonker, Radu State |
RAID | 2 |
| 2021 | HLISA: towards a more reliable measurement toolabstractAutomated browsers (web bots) are an invaluable tool for studying the web. However, research has shown that web bots can be distinguished from regular browsers and that they may be served different content as a consequence. This undermines their utility as a measurement tool. So far, three methods have been used to detect web bots: browser fingerprint, order of site traversal, and aspects of page interaction. Daniel Goßen, Hugo L. Jonker, Stefan Karsch, Benjamin Krumnow, David Roefs |
Internet Measurement Conference | 2 |
| 2021 | Measuring Web Session Security at Scale
Stefano Calzavara, Hugo L. Jonker, Benjamin Krumnow, Alvise Rabitti |
Comput. Secur. | 2 |
| 2020 | ÆGIS: Shielding Vulnerable Smart Contracts Against AttacksabstractIn recent years, smart contracts have suffered major exploits, cost- ing millions of dollars. Unlike traditional programs, smart contracts are deployed on a blockchain. As such, they cannot be modified once deployed. Though various tools have been proposed to detect vulnerable smart contracts, the majority fails to protect vulnera- ble contracts that have already been deployed on the blockchain. Only very few solutions have been proposed so far to tackle the issue of post-deployment. However, these solutions suffer from low precision and are not generic enough to prevent any type of attack. In this work, we introduce ÆGIS, a dynamic analysis tool that protects smart contracts from being exploited during runtime. Its capability of detecting new vulnerabilities can easily be extended through so-called attack patterns. These patterns are written in a domain-specific language that is tailored to the execution model of Ethereum smart contracts. The language enables the description of malicious control and data flows. In addition, we propose a novel mechanism to streamline and speed up the process of managing attack patterns. Patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by the blockchain. We compare ÆGIS to current state-of-the-art tools and demonstrate that our solution achieves higher precision in detecting attacks. Finally, we perform a large-scale analysis on the first 4.5 million blocks of the Ethereum blockchain, thereby confirming the occurrences of well reported and yet unreported attacks in the wild. Christof Ferreira Torres, Mathis Baden, Robert Norvill, Beltran Borja Fiz Pontiveros, Hugo L. Jonker, Sjouke Mauw |
AsiaCCS | 5 |
| 2019 | ÆGIS: Smart Shielding of Smart ContractsabstractIn recent years, smart contracts have suffered major exploits, losing millions of dollars. Unlike traditional programs, smart contracts cannot be updated once deployed. Though various tools were proposed to detect vulnerable smart contracts, they all fail to protect contracts that have already been deployed on the blockchain. Moreover, they focus on vulnerabilities, but do not address scams (e.g., honeypots). In this work, we introduce Æ GIS, a tool that shields smart contracts and users on the blockchain from being exploited. To this end, ÆGIS reverts transactions in real-time based on pattern matching. These patterns encode the detection of malicious transactions that trigger exploits or scams. New patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by blockchain. By allowing its protection to be updated, the smart contract acts as a smart shield. Christof Ferreira Torres, Mathis Baden, Robert Norvill, Hugo L. Jonker |
CCS | 4 |
| 2019 | Fingerprint Surface-Based Detection of Web Bot Detectors
Hugo L. Jonker, Benjamin Krumnow, Gabry Vlot |
ESORICS (2) | 1 |
| 2018 | Investigating Fingerprinters and Fingerprinting-Alike Behaviour of Android Applications
Christof Ferreira Torres, Hugo L. Jonker |
ESORICS (2) | 2 |
| 2017 | Formal modelling and analysis of receipt-free auction protocols in applied pi
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
Comput. Secur. | 2 |
| 2015 | FP-Block: Usable Web Privacy by Controlling Browser Fingerprinting
Christof Ferreira Torres, Hugo L. Jonker, Sjouke Mauw |
ESORICS (2) | 2 |
| 2013 | Defining verifiability in e-auction protocolsabstractAn electronic auction protocol will only be used by those who trust that it operates correctly. Therefore, e-auction protocols must be verifiable: seller, buyer and losing bidders must all be able to determine that the result was correct. We pose that the importance of verifiability for e-auctions necessitates a formal analysis. Consequently, we identify notions of verifiability for each stakeholder. We formalize these and then use the developed framework to study the verifiability of two examples, the protocols due to Curtis et al. and Brandt, identifying several issues. Jannik Dreier, Hugo L. Jonker, Pascal Lafourcade 0001 |
AsiaCCS | 2 |
| 2013 | Enforcing Privacy in the Presence of Others: Notions, Formalisations and Relations
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
ESORICS | 2 |
| 2012 | Formal Analysis of Privacy in an eHealth Protocol
Naipeng Dong, Hugo L. Jonker, Jun Pang 0001 |
ESORICS | 2 |
| 2011 | Bulletin Boards in Voting Systems: Modelling and Measuring PrivacyabstractTransparency is crucial to ensuring fair, honest elections. Transparency is achieved by making information (e.g. election result) public. In e-voting literature, this publication is often described in terms of a bulletin board. While privacy of voting systems has been actively studied in recent years, resulting in various analysis frameworks, to date there has not been an explicit modelling of bulletin board in any such framework. Privacy implications of bulletin boards are thus understudied. In this paper, we extend the semantics of the framework of Jonker, Mauw and Pang to model a bulletin board and capture coercion-resistance. The usage of the extended framework is illustrated by an application to the Pret a Voter voting system. Moreover, we present an information-theoretical measure of privacy loss in elections. Hugo L. Jonker, Jun Pang 0001 |
ARES | 1 |
| 2010 | Anonymity and Verifiability in Voting: Understanding (Un)Linkability
Lucie Langer, Hugo L. Jonker, Wolter Pieters |
ICICS | 2 |
| 2009 | Measuring Voter-Controlled PrivacyabstractIn voting, the notion of receipt-freeness has been proposed to express that a voter cannot gain any information to prove that she has voted in a certain way. Receipt-freeness aims to prevent vote buying, even when a voter chooses to renounce her privacy. In this paper, we distinguish various ways that a voter can communicate with the intruder to reduce her privacy and classify them according to their ability to reduce the privacy of a voter. We develop a formal framework combining knowledge reasoning and trace equivalences to formally model voting protocols and define vote privacy for the voters. Our framework is quantitative, in the sense that it defines a measure for the privacy of a voter. Therefore, the framework can precisely measure the level of privacy for a voter for each of the identified privacy classes. The quantification allows our framework to capture receipts that reduce, but not nullify, the privacy of the voter. This has not been identified and dealt with by other formal approaches. Hugo L. Jonker, Sjouke Mauw, Jun Pang 0001 |
ARES | 1 |
| 2008 | Nuovo DRM Paradiso: Designing a Secure, Verified, Fair Exchange DRM Scheme
Muhammad Torabi Dashti, Srijith Krishnan Nair, Hugo L. Jonker |
Fundam. Informaticae | 3 |
| 2006 | Formalising Receipt-Freeness
Hugo L. Jonker, Erik P. de Vink |
ISC | 1 |