VLDB 2026 Research / reviewers in the wild / expert
Onur Aciiçmez
dblp:34/767
· DBLP profile ↗
16ranked-venue papers
10as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 8 first-authorSystems, architecture and hardware · 2Computer networks · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Hardware security and side channels · 39% Systems and software security · 30% Authentication and access control · 14% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Memory systems · 78% Hardware reliability and fault tolerance · 22% |
Topics — the 16 heaviest of 16, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › side-channel attack
cache side-channel attacks |
0.4 | 3 | 2013 | Architecting against Software Cache-Based Side-Channel Attacks · IEEE Trans. Computers 2013 New Results on Instruction Cache Attacks · CHES 2010 Hardware-software integrated approaches to defend against software cache-based side channel attacks · HPCA 2009 |
Authentication and access control › access control
integrity protection |
0.2 | 1 | 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile Platforms · IEEE Trans. Mob. Comput. 2014 |
Systems and software security
operating system security |
0.2 | 1 | 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile Platforms · IEEE Trans. Mob. Comput. 2014 |
Web and mobile security
browser security |
0.1 | 1 | 2010 | Alhambra: a system for creating, enforcing, and testing browser security policies · WWW 2010 |
Systems and software security › exploitation › injection attacks › code injection attack
cross-site scripting prevention |
0.1 | 1 | 2010 | Alhambra: a system for creating, enforcing, and testing browser security policies · WWW 2010 |
Systems and software security
security policy enforcement |
0.1 | 1 | 2010 | Alhambra: a system for creating, enforcing, and testing browser security policies · WWW 2010 |
Hardware security and side channels
side-channel attack |
0.1 | 2 | 2013 | Improving Brumley and Boneh timing attack on unprotected SSL implementations · CCS 2005 Architecting against Software Cache-Based Side-Channel Attacks · IEEE Trans. Computers 2013 |
Memory systems
cache design |
0.1 | 2 | 2013 | Architecting against Software Cache-Based Side-Channel Attacks · IEEE Trans. Computers 2013 New Results on Instruction Cache Attacks · CHES 2010 |
Web and mobile security
mobile security |
0.1 | 1 | 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile Platforms · IEEE Trans. Mob. Comput. 2014 |
Cryptographic primitives and cryptanalysis › public-key cryptography
RSA |
0.1 | 1 | 2005 | Improving Brumley and Boneh timing attack on unprotected SSL implementations · CCS 2005 |
Hardware security and side channels › side-channel attack
timing side channel |
0.1 | 1 | 2005 | Improving Brumley and Boneh timing attack on unprotected SSL implementations · CCS 2005 |
Hardware reliability and fault tolerance › error correction
cache error correction |
0.0 | 1 | 2013 | Architecting against Software Cache-Based Side-Channel Attacks · IEEE Trans. Computers 2013 |
Program analysis › static analysis
taint analysis |
0.0 | 1 | 2010 | Alhambra: a system for creating, enforcing, and testing browser security policies · WWW 2010 |
Memory systems › cache › CPU cache
instruction cache |
0.0 | 1 | 2010 | New Results on Instruction Cache Attacks · CHES 2010 |
Memory systems
cache |
0.0 | 1 | 2009 | Hardware-software integrated approaches to defend against software cache-based side channel attacks · HPCA 2009 |
Memory systems
cache coherence |
0.0 | 1 | 2009 | Hardware-software integrated approaches to defend against software cache-based side channel attacks · HPCA 2009 |
Methods — techniques the papers use, named apart from their topics
preloading · 0.5software random permutation · 0.3hardware-software integrated defense · 0.3taint tracking · 0.2profiling · 0.2cache timing analysis · 0.2access control rules · 0.2informing loads · 0.2policy specification · 0.2integrity protection rules · 0.2software permutation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Design and Implementation of Efficient Integrity Protection for Open Mobile PlatformsabstractThe security of mobile devices such as cellular phones and smartphones has gained extensive attention due to their increasing usage in people's daily life. The problem is challenging as the computing environments of these devices have become more open and general-purpose while at the same time they have the constraints of performance and user experience. We propose and implement SEIP, a simple and efficient but yet effective solution for the integrity protection of real-world cellular phone platforms, which is motivated by the disadvantages of applying traditional integrity models on these performance and user experience constrained devices. The major security objective of SEIP is to protect trusted services and resources (e.g., those belonging to cellular service providers and device manufacturers) from third-party code. We propose a set of simple integrity protection rules based upon open mobile operating system environments and application behaviors. Our design leverages the unique features of mobile devices, such as service convergence and limited permissions of user installed applications, and easily identifies the borderline between trusted and untrusted domains on mobile platforms. Our approach, thus, significantly simplifies policy specifications while still achieves a high assurance of platform integrity. SEIP is deployed within a commercially available Linux-based smartphone and demonstrates that it can effectively prevent certain malware. The security policy of our implementation is less than 20 kB, and a performance study shows that it is lightweight. Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
IEEE Trans. Mob. Comput. | 3 |
| 2013 | Architecting against Software Cache-Based Side-Channel AttacksabstractUsing cache-like architectural components including data caches, instruction caches, or branch target buffers as a side channel, software cache-based side-channel attacks are able to derive secret keys used in cryptographic operations through legitimate software activities. Existing software solutions are typically application specific and incur substantial performance overhead. Recent hardware proposals against attacks on data caches, although effective in reducing performance overhead, may still be vulnerable to advanced attacks. Furthermore, efficient defenses against attacks on other cache structures, including instruction caches and branch target buffers, are missing. In this paper, we propose hardware-software integrated approaches to defend against software cache-based attacks comprehensively. For attacks on data caches, we propose to use preloading, informing loads, and informing loads with software random permutation to secure the partition-locked cache (PLcache), the random permutation (RPcache) and regular caches, respectively. These approaches present different tradeoffs between hardware complexity and performance overhead. To defend against attacks on instruction caches, we show that the PLcache with preloading and the RPcache provide good protection. To defend against attacks based on branch target buffers, we propose to adopt a new update policy to eliminate potential information leaking. Our experiments show that the proposed schemes not only provide strong security protection but also incur small performance overhead. Jingfei Kong, Onur Aciiçmez, Jean-Pierre Seifert, Huiyang Zhou |
IEEE Trans. Computers | 2 |
| 2010 | New Results on Instruction Cache Attacks
Onur Aciiçmez, Billy Bob Brumley, Philipp Grabher |
CHES | 1 |
| 2010 | SEIP: Simple and Efficient Integrity Protection for Open Mobile Platforms
Xinwen Zhang, Jean-Pierre Seifert, Onur Aciiçmez |
ICICS | 3 |
| 2010 | Alhambra: a system for creating, enforcing, and testing browser security policiesabstractAlhambra is a browser-based system designed to enforce and test web browser security policies. At the core of Alhambra is a policy-enhanced browser supporting fine-grain security policies that restrict web page contents and execution. Alhambra requires no server-side modifications or additions to the web application. Policies can restrict the construction of the document as well as the execution of JavaScript using access control rules and a taint-tracking engine. Using the Alhambra browser, we present two security policies that we have built using our architecture, both designed to prevent cross-site scripting. The first policy uses a taint-tracking engine to prevent cross-site scripting attacks that exploit bugs in the client-side of the web applications. The second one uses browsing history to create policies that restrict the contents of documents and prevent the inclusion of malicious content. Chris Grier, Onur Aciiçmez, Samuel T. King |
WWW | 3 |
| 2009 | A Secure DVB Set-Top Box via Trusting Computing TechnologiesabstractrdquoThis paper presents a very natural "killer applcation" of modern Commercially Off The Shelf (COTS) available Trusted Computing technologies. The application which we propose is a secure and cost optimized DVB Set-top Box. Our respective reference architecture is exclusively build upon such COTS Trusted Computing technologies and completely avoids the use of any proprietary and thus expensive hardware. Particularly, we will use an orchestration of the following TC concepts from the PC field and standardized by the Trusted Computing Group: Secure Boot, Remote Attestation, Trusted Channels, Virtualization for Domain Isolation, and the Trusted Platform Module (TPM). The Trusted Domain Isolation concept (as realized through Trusted Virtualization) allows the simple subscription to different Service Providers (SP) without the need of any SP-specific hardware requirements. The vast computing power of modern CPU architectures allows for the pure software virtualization of any SP-proprietary hardware. In addition to that isolation concept, the novel hardware assisted security ingredients of modern CPUs allow in combination with the TPM for a verifiable evidence of a tamper-free execution environment for the different SP's. I.e., at all times during the execution of a SP's "virtual set-top box", the respective SP is able to remotely request an attestation of the whole execution platform and ensure its fundamental system integrity. This attestation proves either that no "malicous platform tampering" or "unintended platform use" is happening, or in case that it fails, it gives the SP the possibility to deny further services by simply cutting the content delivery channel. Thus, at all times we can guarantee the various SP's strong security assurances. Moreover, the nowadays very well understood and very efficient (even real-time capable!) virtualization concept allows a simple and efficient migration of different SP architectures to such a universal DVB Set-top Box. In some cases a simple binary migration with only little modifications might be possible. Also, our architecture inherently supports the easy integration of an open but strongly isolated user partition, thus allowing the user for a kind of his own PC within his home TV and Set-top Box combination. Moreover, this also allows for an elegant realization of very recent initiatives aiming to merge the home TV experience with the full Web experience (e.g. See'N'Search [27]). In addition to being a very natural killer application of such Trusted Computing. Onur Aciiçmez, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 1 |
| 2009 | Hardware-software integrated approaches to defend against software cache-based side channel attacksabstractSoftware cache-based side channel attacks present serious threats to modern computer systems. Using caches as a side channel, these attacks are able to derive secret keys used in cryptographic operations through legitimate activities. Among existing countermeasures, software solutions are typically application specific and incur substantial performance overhead. Recent hardware proposals including the partition-locked cache (PLcache) and random-permutation cache (RPcache) (Wang and Lee, 2007), although very effective in reducing performance overhead while enhancing the security level, may still be vulnerable to advanced cache attacks. In this paper, we propose three hardware-software approaches to defend against software cache-based attacks - they present different tradeoffs between hardware complexity and performance overhead. First, we propose to use preloading to secure the PLcache. Second, we leverage informing loads, which is a lightweight architectural support originally proposed to improve memory performance, to protect the RPcache. Third, we propose novel software permutation to replace the random permutation hardware in the RPcache. This way, regular caches can be protected with hardware support for informing loads. In our experiments, we analyze various processor models for their vulnerability to cache attacks and demonstrate that even to the processor model that is most vulnerable to cache attacks, our proposed software-hardware integrated schemes provide strong security protection. Jingfei Kong, Onur Aciiçmez, Jean-Pierre Seifert, Huiyang Zhou |
HPCA | 2 |
| 2008 | A Trusted Mobile Phone PrototypeabstractDue to the increasing security demands in mobile devices, the Trusted Computing Group (TCG) formed a dedicated Mobile Phone Working Group (MPWG) to address these security needs. MPWG recently released a Trusted Mobile Phone Reference Architecture (TCG-MPRA) specification that integrates well-known security concepts (TPM, isolation, Integrity Measurement and Verification (IMV), etc.) from the trusted" PC universe, tailored for mobile phones. The business needs of the mobile phone industry mandate 4 different stakeholders (platform owners): device "manufacturer, cellular service provider, general service provider, and the end-user. The specification requires separate trusted and isolated operational domains (Trusted Engines) for each stakeholder. Although the TCG MPWG does not explicitly prescribe a specific technical realization of these trusted engines, a general consensus is use of established (Trusted) Virtualization concepts from corresponding PC architectures. However, we will demo another isolation technique specifically crafted for mobile platforms that respects their resource limitations. We achieve this goal by realizing the MPWG specification by leveraging SELinux which provides a generic domain isolation concept at the kernel level. In addition to utilizing SELinux to realize mobile phone specific (isolated) operational domains, we are also able to seamlessly integrate the important IMV concept into our SELinux-based Trusted Mobile Phone architecture. In our demo we will present a hardware prototvpe, representing a generic mobile phone, implementing the TCG MPWG specification. First, we will "Securely Boot" our TC-aware SELinux kernel out of a hardware Mobile Trusted Module (MTM). Next, we will show how easy and efficient we can realize the 4 isolated Trusted Engines. The value of the Trusted Engines and the fundamental IMV principle will be demonstrated through successful mitigation of two automatic Linux cell-phone worms. The prototype in this demo is in effect, the world's first novel, efficient and inherently secure implementation of MPWG specification. Onur Aciiçmez, Afshin Latifi, Jean-Pierre Seifert, Xinwen Zhang |
CCNC | 1 |
| 2008 | A Vulnerability in RSA Implementations Due to Instruction Cache Analysis and Its Demonstration on OpenSSL
Onur Aciiçmez, Werner Schindler |
CT-RSA | 1 |
| 2007 | Predicting Secret Keys Via Branch Prediction
Onur Aciiçmez, Çetin Kaya Koç, Jean-Pierre Seifert |
CT-RSA | 1 |
| 2007 | Cache Based Remote Timing Attack on the AES
Onur Aciiçmez, Werner Schindler, Çetin Kaya Koç |
CT-RSA | 1 |
| 2007 | Cheap Hardware Parallelism Implies Cheap SecurityabstractThe paper presents a new aspect within that PC oriented side-channel attack arena. Specifically, we present a novel square vs. multiplication oriented side-channel attack which is very unique to certain simultaneous multi threading CPU architectures and it seems that it cannot be carried out on CPU architectures without SMT hardware assistance. The simple reason for this uniqueness of our novel attack is the fact that it doesn't rest - as all other previous MicroArchitectural side-channel attacks - upon a shared resource with the persistent state property between context/process switches, for e.g., caches, BTBs, etc. Instead, it is based upon the fact that Intel's hyper-threading technology shares the ALU's large parallel integer (floating-point) multiplier between its two hardware threads, where it is noteworthy that the multiplier obviously doesn't preserve its state during context switches. As the latest OpenSSL changes, i.e., protections against side-channels attacks are already in place, cf. (Brickell et al., 2006), our paper doesn't introduce a new vulnerability into the OpenSSL library at all. Nevertheless, our attack has the following unintuitive property. Longer key sizes just make our attack scenario easier and not more difficult as one could assume at first sight. Thus, the present paper teaches that the sole presence of particular multi threading implementations requires a very deep understanding of the interplay between the underlying hardware and software, in order to appropriately judge the implied security consequences. Onur Aciiçmez, Jean-Pierre Seifert |
FDTC | 1 |
| 2007 | An Analytical Model for Time-Driven Cache Attacks
Kris Tiri, Onur Aciiçmez, Michael Neve, Flemming Andersen |
FSE | 2 |
| 2007 | New Branch Prediction Vulnerabilities in OpenSSL and Necessary Software Countermeasures
Onur Aciiçmez, Shay Gueron, Jean-Pierre Seifert |
IMACC | 1 |
| 2006 | Trace-Driven Cache Attacks on AES (Short Paper)
Onur Aciiçmez, Çetin Kaya Koç |
ICICS | 1 |
| 2005 | Improving Brumley and Boneh timing attack on unprotected SSL implementationsabstractSince the remarkable work of Kocher [7], several papers considering different types of timing attacks have been published. In 2003, Brumley and Boneh presented a timing attack on unprotected OpenSSL implementations [2]. In this paper, we improve the efficiency of their attack by a factor of more than 10. We exploit the timing behavior of Montgomery multiplications in the table initialization phase, which allows us to increase the number of multiplications that provide useful information to reveal one of the prime factors of RSA moduli. We also present other improvements, which can be applied to the attack in [2]. Onur Aciiçmez, Werner Schindler, Çetin Kaya Koç |
CCS | 1 |