VLDB 2026 Research / reviewers in the wild / expert
Scott E. Coull
dblp:43/4410
· DBLP profile ↗
19ranked-venue papers
9as first author
2since 2021 · last 2021
0009-0003-6921-1842ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 9 first-author · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Explanation-Guided Backdoor Poisoning Attacks Against Malware Classifiers
Giorgio Severi, Jim Meyer, Scott E. Coull, Alina Oprea |
USENIX Security Symposium | 3 |
| 2021 | Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware DetectionabstractRecent work has shown that adversarial Windows malware samples—referred to as adversarial EXE mples in this article—can bypass machine learning-based detection relying on static code analysis by perturbing relatively few input bytes. To preserve malicious functionality, previous attacks either add bytes to existing non-functional areas of the file, potentially limiting their effectiveness, or require running computationally demanding validation steps to discard malware variants that do not correctly execute in sandbox environments. In this work, we overcome these limitations by developing a unifying framework that does not only encompass and generalize previous attacks against machine-learning models, but also includes three novel attacks based on practical, functionality-preserving manipulations to the Windows Portable Executable file format. These attacks, named Full DOS , Extend , and Shift , inject the adversarial payload by respectively manipulating the DOS header, extending it, and shifting the content of the first section. Our experimental results show that these attacks outperform existing ones in both white-box and black-box scenarios, achieving a better tradeoff in terms of evasion rate and size of the injected payload, while also enabling evasion of models that have been shown to be robust to previous attacks. To facilitate reproducibility of our findings, we open source our framework and all the corresponding attack implementations as part of the secml-malware Python library. We conclude this work by discussing the limitations of current machine learning-based malware detectors, along with potential mitigation strategies based on embedding domain knowledge coming from subject-matter experts directly into the learning process. Luca Demetrio, Scott E. Coull, Battista Biggio, Giovanni Lagorio, Alessandro Armando, Fabio Roli |
ACM Trans. Priv. Secur. | 2 |
| 2015 | Marionette: A Programmable Network Traffic Obfuscation System
Kevin P. Dyer, Scott E. Coull, Thomas Shrimpton |
USENIX Security Symposium | 2 |
| 2013 | Protocol misidentification made easy with format-transforming encryptionabstractDeep packet inspection (DPI) technologies provide much-needed visibility and control of network traffic using port-independent protocol identification, where a network flow is labeled with its application-layer protocol based on packet contents. In this paper, we provide the first comprehensive evaluation of a large set of DPI systems from the point of view of protocol misidentification attacks, in which adversaries on the network attempt to force the DPI to mislabel connections. Our approach uses a new cryptographic primitive called format-transforming encryption (FTE), which extends conventional symmetric encryption with the ability to transform the ciphertext into a format of our choosing. We design an FTE-based record layer that can encrypt arbitrary application-layer traffic, and we experimentally show that this forces misidentification for all of the evaluated DPI systems. This set includes a proprietary, enterprise-class DPI system used by large corporations and nation-states. We also show that using FTE as a proxy system incurs no latency overhead and as little as 16\% bandwidth overhead compared to standard SSH tunnels. Finally, we integrate our FTE proxy into the Tor anonymity network and demonstrate that it evades real-world censorship by the Great Firewall of China. Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
CCS | 2 |
| 2012 | Peek-a-Boo, I Still See You: Why Efficient Traffic Analysis Countermeasures FailabstractWe consider the setting of HTTP traffic over encrypted tunnels, as used to conceal the identity of websites visited by a user. It is well known that traffic analysis (TA) attacks can accurately identify the website a user visits despite the use of encryption, and previous work has looked at specific attack/countermeasure pairings. We provide the first comprehensive analysis of general-purpose TA countermeasures. We show that nine known countermeasures are vulnerable to simple attacks that exploit coarse features of traffic (e.g., total time and bandwidth). The considered countermeasures include ones like those standardized by TLS, SSH, and IPsec, and even more complex ones like the traffic morphing scheme of Wright et al. As just one of our results, we show that despite the use of traffic morphing, one can use only total upstream and downstream bandwidth to identify -- with 98% accuracy - which of two websites was visited. One implication of what we find is that, in the context of website identification, it is unlikely that bandwidth-efficient, general-purpose TA countermeasures can ever provide the type of security targeted in prior work. Kevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | Toward Efficient Querying of Compressed Network Payloads
Teryl Taylor, Scott E. Coull, Fabian Monrose, John McHugh |
USENIX ATC | 2 |
| 2012 | Understanding domain registration abuses
Scott E. Coull, Andrew M. White 0002, Ting-Fang Yen, Fabian Monrose, Michael K. Reiter |
Comput. Secur. | 1 |
| 2011 | Bounded vector signatures and their applicationsabstractAlthough malleability is undesirable in traditional digital signatures, schemes with limited malleability properties enable interesting functionalities that may be impossible to obtain otherwise (e.g., homomorphic signatures). In this paper, we introduce a new malleable signature scheme called bounded vector signatures. The proposed scheme allows a user to sign a multi-dimensional vector of values, along with a description of the context within which the vector should be interpreted. The scheme includes a unique malleability property, which we refer to as the stretch property, that allows the components of the signed vector to be increased up to a pre-defined limit without access to the signing key. Decreasing these values, however, remains computationally infeasible. We prove the security of our construction under the strong RSA and decisional Diffie-Hellman assumptions in the random oracle model. Finally, we underscore the utility of bounded vector signatures by discussing their use in distributed systems security applications. Lei Wei 0004, Scott E. Coull, Michael K. Reiter |
AsiaCCS | 2 |
| 2011 | On Measuring the Similarity of Network Hosts: Pitfalls, New Metrics, and Empirical Analyses
Scott E. Coull, Fabian Monrose, Michael D. Bailey |
NDSS | 1 |
| 2011 | Access controls for oblivious and anonymous systemsabstractThe use of privacy-enhancing cryptographic protocols, such as anonymous credentials and oblivious transfer, could have a detrimental effect on the ability of providers to effectively implement access controls on their content. In this article, we propose a stateful anonymous credential system that allows the provider to implement nontrivial, real-world access controls on oblivious protocols conducted with anonymous users. Our system models the behavior of users as a state machine and embeds that state within an anonymous credential to restrict access to resources based on the state information. The use of state machine models of user behavior allows the provider to restrict the users' actions according to a wide variety of access control models without learning anything about the users' identities or actions. Our system is secure in the standard model under basic assumptions and, after an initial setup phase, each transaction requires only constant time. As a concrete example, we show how to implement the Brewer--Nash (Chinese Wall) and Bell-La Padula (Multilevel Security) access control models within our credential system. Furthermore, we combine our credential system with an adaptive oblivious transfer scheme to create a privacy-friendly oblivious database with strong access controls. Scott E. Coull, Matthew Green 0001, Susan Hohenberger |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2010 | Understanding Domain Registration Abuses
Scott E. Coull, Andrew M. White 0002, Ting-Fang Yen, Fabian Monrose, Michael K. Reiter |
SEC | 1 |
| 2010 | Uncovering Spoken Phrases in Encrypted Voice over IP ConversationsabstractAlthough Voice over IP (VoIP) is rapidly being adopted, its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that it is possible toidentify the phrases spoken within encrypted VoIP callswhen the audio is encoded using variable bit rate codecs. To do so, we train a hidden Markov model using only knowledge of the phonetic pronunciations of words, such as those provided by a dictionary, and search packet sequences for instances of specified phrases. Our approach does not require examples of the speaker’s voice, or even example recordings of the words that make up the target phrase. We evaluate our techniques on a standard speech recognition corpus containing over 2,000 phonetically rich phrases spoken by 630 distinct speakers from across the continental United States. Our results indicate that we can identify phrases within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis
Charles V. Wright, Scott E. Coull, Fabian Monrose |
NDSS | 2 |
| 2009 | On the development of an internetwork-centric defense for scanning worms
Scott E. Coull, Boleslaw K. Szymanski |
Comput. Secur. | 1 |
| 2008 | Taming the Devil: Techniques for Evaluating Anonymized Network Data
Scott E. Coull, Charles V. Wright, Angelos D. Keromytis, Fabian Monrose, Michael K. Reiter |
NDSS | 1 |
| 2008 | Spot Me if You Can: Uncovering Spoken Phrases in Encrypted VoIP ConversationsabstractDespite the rapid adoption of Voice over IP (VoIP), its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that when the audio is encoded using variable bit rate codecs, the lengths of encrypted VoIP packets can be used to identify the phrases spoken within a call. Our results indicate that a passive observer can identify phrases from a standard speech corpus within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
SP | 3 |
| 2007 | Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces
Scott E. Coull, Charles V. Wright, Fabian Monrose, Michael P. Collins, Michael K. Reiter |
NDSS | 1 |
| 2007 | On Web Browsing Privacy in Anonymized NetFlows
Scott E. Coull, Michael P. Collins, Charles V. Wright, Fabian Monrose, Michael K. Reiter |
USENIX Security Symposium | 1 |
| 2003 | Intrusion Detection: A Bioinformatics ApproachabstractWe address the problem of detecting masquerading, a security attack in which an intruder assumes the identity of a legitimate user. Many approaches based on hidden Markov models and various forms of finite state automata have been proposed to solve this problem. The novelty of our approach results from the application of techniques used in bioinformatics for a pair-wise sequence alignment to compare the monitored session with past user behavior. Our algorithm uses a semiglobal alignment and a unique scoring system to measure similarity between a sequence of commands produced by a potential intruder and the user signature, which is a sequence of commands collected from a legitimate user. We tested this algorithm on the standard intrusion data collection set. As discussed, the results of the test showed that the described algorithm yields a promising combination of intrusion detection rate and false positive rate, when compared to published intrusion detection algorithms. Scott E. Coull, Joel W. Branch, Boleslaw K. Szymanski, Eric Breimer |
ACSAC | 1 |