VLDB 2026 Research / reviewers in the wild / expert
Jeffrey Knockel
dblp:41/11468
· DBLP profile ↗
13ranked-venue papers
3as first author
7since 2021 · last 2026
0009-0006-6239-9725ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 first-author · 7 since 2021Computer networks · 3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Banned Books: Analysis of Censorship on Amazon.comabstractWe analyze the system Amazon deploys on the US “amazon.com” storefront to restrict shipments of certain products to other regions in the world. We found 17,842 products that Amazon restricted from being shipped to at least one world region. While many of the shipping restrictions are related to regulations involving WiFi, car seats, and other heavily regulated product categories, the most common product category restricted by Amazon in our study was books. Banned books were largely related to LGBTIQ, the occult, erotica, Christianity, and health and wellness. The regions affected by this censorship were the UAE, Saudi Arabia, and many other Middle Eastern countries as well as Brunei Darussalam, Papua New Guinea, Seychelles, and Zambia. In our Common Crawl test sample, Amazon restricted shipment of over 1.1% of the books sold on amazon.com to at least one of these regions. We identified three major blocklists which Amazon assigns to different regions. In numerous cases, Amazon’s restrictions were either overly broad or miscategorized. Examples include the restriction of books relating to breast cancer, recipe books invoking “food porn” euphemisms, and Nietzsche’s Gay Science. To justify why restricted products cannot be shipped, Amazon used varying and often misleading error messages such as by conveying that an item is temporarily out of stock. We reported our findings to Amazon. A year later, we found that Amazon reduced its use of misleading error messages and had eliminated many of its false positive restrictions. Although we cannot conclusively link Amazon’s improvements to our reporting, we believe that our findings serve as evidence that measurement studies can effect change in problematic company behavior. Jeffrey Knockel, Jakub Dalek, Noura Aljizawi, Levi Meletti, Justin Lau |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | WireWatch: Measuring the Security of Proprietary Network Encryption in the Global Android EcosystemabstractWe present WireWatch, a large-scale measurement pipeline to evaluate the network security of Android apps. WireWatch measures apps' usage of plaintext network traffic and non-standard, proprietary network cryptography. We found that 47.6% of top Mi Store applications used proprietary network cryptography without any additional encryption, compared to only 3.51% of top Google Play Store applications. We analyzed the 18 most popular protocols from WireWatch, which belonged to 9 protocol families, including cryptosystems designed by Alibaba, iQIYI, Kuaishou, and Tencent. We found that 8 of these protocol families sent requests that allowed network eavesdroppers to decrypt underlying data, including browsing data and device metadata, among various other issues, such as being downgradable, not validating TLS certificates, and the use of RSA without OAEP. These vulnerabilities affected 26.9% of our Mi Store dataset with a cumulative 130 billion downloads. Ultimately, WireWatch reveals that a large portion of massively popular applications are using insecure proprietary network protocols to encrypt sensitive user data. Mona Wang, Jeffrey Knockel, Zoë Reichert, Prateek Mittal, Jonathan R. Mayer |
SP | 2 |
| 2025 | An Analysis of Chinese Censorship Bias in LLMsabstractWhen a large language model (LLM) has been trained on text featuring social biases, those biases implicitly impact the outputs of the model. Training an LLM on sanitized content, i.e., those pieces of content which remain after being subjected to state censorship (including alterations, deletions, and self-imposed censorship), results in what we term censorship bias. A model impacted by censorship bias may be less likely to reflect views that are routinely prohibited and more likely to reflect views that are not. This may particularly be an issue when interfacing with a model in a language that is predominantly used in a region with strong censorship laws. In this work, we outline what censorship bias is, introduce a novel methodology for identifying and measuring it, and apply that methodology to evaluate the most popular current LLMs. As part of the contributions of this work we designed and evaluated CensorshipDetector, a Chinese language text classification model which we use as part of our experimental design. Our evaluation of CensorshipDetector found it to be 91% accurate at differentiating between sanitized content and non-sanitized content. Our testing revealed evidence of censorship bias across all of the models we evaluated. Finally, we outline the potential harms of censorship bias, namely the exportation of information manipulation that would have primarily harmed a domestic audience to diaspora, as well as recommendations to various stakeholders to limit the harms of censorship bias and prevent it in the future. Jeffrey Knockel, Rachel Greenstadt |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App EcosystemabstractThis work studies the analytics and first-party tracking ecosystem of WeChat Mini Programs. WeChat Mini Programs have almost one billion monthly active users, comprising one of the largest ap- plication and analytics ecosystems in the world. A key challenge in investigating the privacy of WeChat’s Mini Programs is WeChat’s use of a proprietary network encryption protocol, MMTLS, to trans- mit analytics data. First, we reverse-engineer WeChat’s network stack, and release tooling and specifications for investigating net- work requests sent to WeChat servers. Leveraging this tooling, we analyze the requests sent by 104 popular Mini Programs to perform the first characterization and analysis of WeChat’s user tracking across their Mini Program ecosystem. Overall, we identified fine- grained browsing data in 76.0% of the network traces we decrypted. This tracking including browsing and search queries performed within third-party Mini Programs, some of which manage particu- larly sensitive data; for instance, we also identified browsing data in 89.7% of the traces we decrypted from 40 health-related Mini Programs. We ultimately find that the first-party platform, WeChat, is comprehensively tracking user activity with third-party Mini Programs, at an unprecedented scale. There is no way for users nor Mini Program developers to opt-out of this data collection. Mona Wang, Pellaeon Lin, Jeffrey Knockel, Will Greenberg, Jonathan Mayer, Prateek Mittal |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | The Not-So-Silent Type: Vulnerabilities in Chinese IME Keyboards' Network Security ProtocolsabstractPopular Chinese Input Method Editor (IME) keyboards almost universally feature cloud-based features that improve character prediction when typing. Handling such sensitive data (i.e., keystrokes) in transit demands security in transit. In this work, we perform a comprehensive security measurement of the Chinese IME keyboard ecosystem, investigating the network security of keystrokes sent in transit by popular Chinese IME keyboards from nine vendors. We studied the three most popular third-party keyboards, comprising 95.9% of the third-party keyboard market share in China, as well as the default Chinese IME keyboards pre-installed on six popular Android mobile device manufacturers in China. We found that the vast majority of IME keyboards utilize proprietary, non-TLS network encryption protocols. Our measurement revealed critical vulnerabilities in these encryption protocols from eight out of the nine vendors in which network attackers could completely reveal the contents of users' keystrokes in transit. We estimate that up to one billion users were affected by these vulnerabilities. Finally, we provide recommendations to various stakeholders to limit the harm from this existing set of vulnerabilities, as well as to prevent future vulnerabilities of this kind. Jeffrey Knockel, Mona Wang, Zoë Reichert |
CCS | 1 |
| 2024 | Attacking Connection Tracking Frameworks as used by Virtual Private NetworksabstractVPNs (Virtual Private Networks) have become an essential privacy-enhancing technology, particularly for at-risk users like dissidents, journalists, NGOs, and others vulnerable to targeted threats. While previous research investigating VPN security has focused on cryptographic strength or traffic leakages, there remains a gap in understanding how lower-level primitives fundamental to VPN operations, like connection tracking, might undermine the security and privacy that VPNs are intended to provide. In this paper, we examine the connection tracking frameworks used in common operating systems, identifying a novel exploit primitive that we refer to as the port shadow. We use the port shadow to build four attacks against VPNs that allow an attacker to intercept and redirect encrypted traffic, de-anonymize a VPN peer, or even portscan a VPN peer behind the VPN server. We build a formal model of modern connection tracking frameworks and identify that the root cause of the port shadow lies in five shared, limited resources. Through bounded model checking, we propose and verify six mitigations in terms of enforcing process isolation. We hope our work leads to more attention on the security aspects of lower-level systems and the implications of integrating them into security-critical applications. Benjamin Mixon-Baca, Jeffrey Knockel, Diwen Xue, Tarun Ayyagari, Deepak Kapur, Roya Ensafi, Jedidiah R. Crandall |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | How Great is the Great Firewall? Measuring China's DNS Censorship
Nguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel, Pellaeon Lin, William R. Marczak, Masashi Crete-Nishihata, Phillipa Gill, Michalis Polychronakis |
USENIX Security Symposium | 4 |
| 2018 | ONIS: Inferring TCP/IP-based Trust Relationships Completely Off-PathabstractWe present ONIS, a new scanning technique that can perform network measurements such as: inferring TCP/IP-based trust relationships off-path, stealthily port scanning a target without using the scanner's IP address, detecting off-path packet drops between two international hosts. These tasks typically rely on a core technique called the idle scan, which is a special kind of port scan that appears to come from a third machine called a zombie. The scanner learns the target's status from the zombie by using its TCP/IP side channels. Unfortunately, the idle scan assumes that the zombie has IP identifiers (IPIDs) which exhibit the now-discouraged behavior of being globally incrementing. The use of this kind of IPID counter is becoming increasingly rare in practice. Our technique, unlike the idle scan, is based on a much more advanced IPID generation scheme, that of the prevalent Linux kernel. Although Linux's IPID generation scheme is specifically intended to reduce information flow, we show that using Linux machines as zombies in an indirect scan is still possible. ONIS has 87% accuracy, which is comparable to nmap's implementation of the idle scan at 86%. ONIS's much broader choice of zombies will enable it to be a widely used technique which can fulfill various network measurement tasks. Jeffrey Knockel, Jedidiah R. Crandall |
INFOCOM | 2 |
| 2016 | V-DIFT: Vector-Based Dynamic Information Flow Tracking with Application to Locating Cryptographic Keys for Reverse EngineeringabstractDynamic Information Flow Tracking (DIFT) is a technique for tracking information as it flows through a program's execution. DIFT systems track information by tainting data and propagating the taint marks throughout execution. These systems are designed to have minimal overhead and thus often miss indirect flows. If indirect flows were propagated naively overtainting would result, whereas propagating them effectively causes overhead. We describe the design and evaluation of a system intended for offline analysis, such as reverse engineering, that can track information through indirect flows. Our system, V-DIFT, uses a vector of floating point values for each taint mark. The use of vectors enables us to track a taint's provenance and handle indirect flows, trading off some performance for these abilities. These indirect flows via control and address dependencies are thought to be critical to tracking information flow of cryptographic programs. Therefore we tested V-DIFT's effectiveness by automatically locating keys in simple programs that use a variety of symmetric cryptographic algorithms found in three common libraries. This application does not require that the program run in real time, just that it be much faster than a manual approach. Our V-DIFT implementation tests average 3.6 seconds, and with the right parameters can identify memory locations that contain keys for 24 out of 27 algorithms tested. Our results show that many cryptographic algorithm implementations' address and/or control dependencies must be tracked for DIFT to be effective. Antonio M. Espinoza, Jeffrey Knockel, Pedro Comesaña Alfaro, Jedidiah R. Crandall |
ARES | 2 |
| 2016 | High Fidelity Off-Path Round-Trip Time Measurement via TCP/IP Side Channels with Duplicate SYNsabstractOff-path round-trip time (RTT) measurement has many potential applications, including: improved geolocation capabilities, measuring the performance of parts of the Internet where there is not much measurement infrastructure (e.g., PlanetLab), and providing data plane measurements to better understand global Internet routing. Off-path means that the measurement machine is not on the path being measured. More specifically, we can measure the RTT between essentially any two machines (A and B) on the Internet without having special access to A or B or having any presence in the path between A and B. Alexander and Crandall proposed a new technique for off-path RTT measurements that made fewer assumptions than previous techniques, such as King (based on DNS). Alexander and Crandall's technique assumed only that one of A or B was a standard Linux machine with at least one open port and the other replied to unsolicited SYN-ACKs with RSTs. Thus, their technique is widely applicable across many parts of the Internet. However, their technique's accuracy was severely impacted by short RTTs or high packet loss rates. In this paper, we propose an improved technique that overcomes both of these limitations. Our new technique is shown to have 82.95% of the RTT measurement results within 10% of the actual RTT, and 91.18% of the results within 20% of the actual RTT; while the previous technique by Alexander and Crandall only had 60.7% of the results within 10% and 81.33% of the results within 20%. Jeffrey Knockel, Jedidiah R. Crandall |
GLOBECOM | 2 |
| 2015 | Original SYN: Finding machines hidden behind firewallsabstractWe present an Internet measurement technique for finding machines that are hidden behind firewalls. That is, if a firewall prevents outside IP addresses from sending packets to an internal protected machine that is only accessible on the local network, our technique can still find the machine. We employ a novel TCP/IP side channel technique to achieve this. The technique uses side channels in “zombie” machines to learn information about the network from the perspective of a zombie. Unlike previous TCP/IP side channel techniques, our technique does not require a high packet rate and does not cause denial-of-service. We also make no assumptions about globally incrementing IPIDs, as do idle scans. This paper addresses two key questions about our technique: how many machines are there on the Internet that are hidden behind firewalls, and how common is ingress filtering that prevents our scan by not allowing spoofed IP packets into the network. We answer both of these questions, respectively, by finding 1,296 hidden machines and measuring that only 23.9% of our candidate zombie machines are on networks that perform ingress filtering. Jeffrey Knockel, Jedidiah R. Crandall |
INFOCOM | 2 |
| 2014 | Detecting Intentional Packet Drops on the Internet via TCP/IP Side Channels
Roya Ensafi, Jeffrey Knockel, Geoffrey Alexander, Jedidiah R. Crandall |
PAM | 2 |
| 2013 | Self-Healing of Byzantine Faults
Jeffrey Knockel, George Saad, Jared Saia |
SSS | 1 |