VLDB 2026 Research / reviewers in the wild / expert
Fabian Monrose
dblp:50/6700
· DBLP profile ↗
96ranked-venue papers
6as first author
20since 2021 · last 2026
0000-0002-9805-2217ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 79 · 5 first-author · 13 since 2021Human-computer interaction and ubiquitous computing · 8 · 4 since 2021Systems, architecture and hardware · 7 · 1 first-author · 2 since 2021Computer networks · 5 · 1 since 2021Artificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LUMEN: A Systems Approach to LLM-Guided Activation of Hidden Behaviors in Malware
Kevin Valakuzhy, Miuyin Yong Wong, Douglas M. Blough, Mustaque Ahamad, Fabian Monrose |
DSN | 5 |
| 2026 | Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti, Michael D. Bailey, Fabian Monrose |
NDSS | 6 |
| 2026 | Actively Understanding the Dynamics and Risks of the Threat Intelligence Ecosystem
Tillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis, Manos Antonakakis, Fabian Monrose |
NDSS | 6 |
| 2026 | The Impact of Emerging AI Practices on the Cybersecurity Workforce
Miuyin Yong Wong, Alan F. Luo, Yunze Zhao, Shubham Bhatnagar, Fabian Monrose, Michelle L. Mazurek |
SOUPS | 5 |
| 2025 | The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Michael D. Bailey, Fabian Monrose |
NDSS | 5 |
| 2025 | From Concealment to Exposure: Understanding the Lifecycle and Infrastructure of APT DomainsabstractAdvanced Persistent Threats (APTs) are sophisticated and long-lived attacks that are often backed by nationstates. Despite the security community’s efforts to design and deploy specialized systems to combat them, APTs have remained prevalent while persisting undetected for significantly more time than commodity cyber threats. In this paper, we measure this difference by conducting the first longitudinal analysis of APT infrastructure by shedding light on the lifecycle of their domain names. To enable this study, we build Atropos, a novel measurement methodology that automatically and accurately labels DNS records of APT domain names, enabling us to understand their lifecycle and gain a more comprehensive and contextualized infrastructure picture than the one that is shared in public reports. Using the comprehensive infrastructure view that Atropos provides, we study 405 APT actors over a period spanning a decade and unveil several novel findings regarding their utilization of network infrastructure that have practical implications. We find that APT actors provision their IPs to their domain names 317 days on average before an attack is publicly reported. Furthermore, $73.6 \%$ of the APT IPs that are part of the attack infrastructure no longer point to their domains at the time of first public disclosure, highlighting that researchers and security practitioners need to consider historic DNS data in order to get a more comprehensive and accurate picture when training network detection, investigation, or attribution systems. Organizations that are more sensitive to APT attacks will need to retain network logs for at least 19 to 25 months in order to have higher probabilities of discovering whether they have been a target of an APT attack. Finally, we provide evidence that APT actors re-use hosting providers, deploy APT network infrastructure close to their intended attack targets, and increasingly utilize more cloud-fronting. These findings are important because they can guide future threat detection and attribution works. Athanasios Avgetidis, Aaron Faulkenberry, Boladji Vinny Adjibi, Tillson Galloway, Panagiotis Kintis, Omar Alrawi, Zane Ma, Fabian Monrose, Angelos D. Keromytis, Roberto Perdisci, Manos Antonakakis |
RAID | 8 |
| 2024 | CrashTalk: Automated Generation of Precise, Human Readable, Descriptions of Software Security BugsabstractUnderstanding the cause, consequences, and severity of a security bug are critical facets of the overall bug triaging and remediation process. Unfortunately, diagnosing failures is often a laborious process that requires developers to expend significant time and effort. While solutions have been proposed to help expedite the process of pinpointing the cause of a security bug, few proposals provide an explanation along with a diagnosis to make the bug discovery and triaging process less taxing. Moreover, even in cases where descriptions are provided, they are not guided by classification models that support precise descriptions of the flaw. We present an approach that uses static and dynamic analysis techniques to automatically infer the cause and consequences of a software crash and present diagnostic information following NIST's recently released Bugs Framework taxonomy. Specifically, starting from a crash, we generate a detailed and accessible English description of the failure along with its weakness types and severity, thereby easing the burden on developers and security analysts alike. To evaluate the effectiveness of our approach, we compare our ability to find fault locations and generate explanations compared to that of professional software developers by using a benchmark specifically designed to assist with realistic evaluation of tools in software engineering. In addition, using 33 real-world vulnerabilities we collected, we show that our approach correctly diagnoses over 94% of the failures and, in some cases, generates weakness types that are more specific than those that were originally assigned by the submitter or National Vulnerability Database analysts. We also generate initial vulnerability scores that can be used by project managers to assist with prioritizing bug fixes. On average, the overall process takes just over a minute, which is orders of magnitude faster than what professional developers can do. Kedrian James, Kevin Valakuzhy, Kevin Z. Snow, Fabian Monrose |
CODASPY | 4 |
| 2023 | Improving Security Tasks Using Compiler Provenance Information Recovered At the Binary-LevelabstractThe complex optimizations supported by modern compilers allow for compiler provenance recovery at many levels. For instance, it is possible to identify the compiler family and optimization level used when building a binary, as well as the individual compiler passes applied to functions within the binary. Yet, many downstream applications of compiler provenance remain unexplored. To bridge that gap, we train and evaluate a multi-label compiler provenance model on data collected from over 27,000 programs built using LLVM 14, and apply the model to a number of security-related tasks. Our approach considers 68 distinct compiler passes and achieves an average F-1 score of 84.4%. We first use the model to examine the magnitude of compiler-induced vulnerabilities, identifying 53 information leak bugs in 10 popular projects. We also show that several compiler optimization passes introduce a substantial amount of functional code reuse gadgets that negatively impact security. Beyond vulnerability detection, we evaluate other security applications, including using recovered provenance information to verify the correctness of Rich header data in Windows binaries (e.g., forensic analysis), as well as for binary decomposition tasks (e.g., third party library detection). Yufei Du, Omar Alrawi, Kevin Z. Snow, Manos Antonakakis, Fabian Monrose |
CCS | 5 |
| 2023 | Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS KeysabstractCertificate authorities enable TLS server authentication by generating certificates that attest to the mapping between a domain name and a cryptographic keypair, for up to 398 days. This static, name-to-key caching mechanism belies a complex reality: a tangle of dynamic infrastructure involving domains, servers, cryptographic keys, etc. When any of these operations changes, the authentication information in a certificate becomes stale and no longer accurately reflects reality. In this work, we examine the broader phenomenon of certificate invalidation events and discover three classes of security-relevant events that enable a third-party to impersonate a domain outside of their control. Longitudinal measurement of these precarious scenarios reveals that they affect over 15K new domains per day, on average. Unfortunately, modern certificate revocation provides little recourse, so we examine the potential impact of reducing certificate lifetimes (cache duration): shortening the current 398-day limit to 90 days yields a 75% decrease in precarious access to valid TLS keys. Zane Ma, Aaron Faulkenberry, Thomas Papastergiou, Zakir Durumeric, Michael D. Bailey, Angelos D. Keromytis, Fabian Monrose, Manos Antonakakis |
IMC | 7 |
| 2023 | More Carrot or Less Stick: Organically Improving Student Time Management With Practice Tasks and Gamified AssignmentsabstractStudents often struggle with time management. They delay work on assignments for too long and/or allocate too little time for the tasks given to them. This negatively impacts their performance, increases stress, and even leads some to switch majors. As such, there is a wealth of previous research on improving student time management through direct intervention. In particular, there is a heavy focus on having students start assignments earlier and spend more time-on-task -- as these metrics have been shown to positively correlate with student performance. In this paper, however, we theorize that poor student time management (at least in CS) is often due to confounding factors -- such as academic stress -- and not a missing skill set. We demonstrate that changes in assignment design and style can cause students to organically manage their time better. Specifically, we compare two alternative designs -- a low risk preparatory assignment and a highly engaging gamified assignment -- against a conventional programming assignment. While the conventional assignment follows common trends, students do better on the alternative designs and exhibit novel behavior on the usual metrics of earliness of work and time-on-task. Of note, on the preparatory assignment, time-on-task is negatively (albeit weakly) correlated with performance -- the opposite of what is standard in the literature. Finally, we provide takeaways and recommendations for other instructors to use in their own approaches and research. Mac Malone, Fabian Monrose |
ITiCSE (1) | 2 |
| 2023 | Securely Autograding Cybersecurity Exercises Using Web Accessible Jupyter NotebooksabstractThe rapidly growing demand for computer science expertise combined with the pandemic era forced much education into large hybrid or fully remote learning environments, placing new emphasis on online learning platforms and automatic grading. Jupyter notebooks are a popular way to teach coding skills, as they provide an online way to distribute assignments with a low-cost Python coding environment to students and are also heavily used in data science, making the skills learned transferrable to the real world. However, autograding Jupyter notebooks is challenging, and contemporary tools have a number of pitfalls that make it difficult to integrate into a larger learning platform. As such, we implement our own grading system for Jupyter notebooks within the context of a broader gamified learning platform used in a cybersecurity course. Significant emphasis is given to the design, feedback, and security, as we often wish to introduce vulnerabilities within the student's learning environment for them to exploit while simultaneously protecting the system from misuse. We evaluate the system during its use in the Fall 2021 semester, discussing both its successes and failures, and provide transferrable lessons other instructors can use in their own systems, as the autograding systems used by many instructors are home-grown. Mac Malone, Fabian Monrose |
SIGCSE (1) | 3 |
| 2023 | Beyond The Gates: An Empirical Analysis of HTTP-Managed Password Stealers and Operators
Athanasios Avgetidis, Omar Alrawi, Kevin Valakuzhy, Charles Lever, Paul Burbage, Angelos D. Keromytis, Fabian Monrose, Manos Antonakakis |
USENIX Security Symposium | 7 |
| 2022 | View from Above: Exploring the Malware Ecosystem from the Upper DNS HierarchyabstractThis work explores authoritative DNS (AuthDNS) as a new measurement perspective for studying the large-scale epidemiology of the malware ecosystem—when and where infections occur, and what infrastructure spreads and controls malware. Utilizing an AuthDNS dataset from a top registrar, we observe malware heterogeneity (202 families), global infrastructure (399,830 IPs in 151 countries) and infection (40,937 querying Autonomous Systems (ASes)) visibility, as well as breadth of temporal coverage (2017–2021). This combination of factors enables an extensive analysis of the malware ecosystem that reinforces prior work on malware infrastructure and also contributes new perspectives on malware infection distribution and lifecycle. We find that malware families re-use infrastructure, especially in cloud hosting countries, but contrary to prior work, we do not detect targeting of clients by countries or industry sector. Furthermore, our 4-year lifecycle analysis of diverse malware families shows that infection analysis is temporally sensitive: over 90% of ASes first query a malicious domain after public detection, and a median of 38.6% ASes only query after domain expiration or takedown. To fit AuthDNS into the broader context of malware research, we conclude with a comparison of experimental vantage points on four qualitative aspects and discuss their advantages and limitations. Ultimately, we establish AuthDNS as a unique measurement perspective capable of measuring global malware infections. Aaron Faulkenberry, Athanasios Avgetidis, Zane Ma, Omar Alrawi, Charles Lever, Panagiotis Kintis, Fabian Monrose, Angelos D. Keromytis, Manos Antonakakis |
ACSAC | 7 |
| 2022 | Leveraging Disentangled Representations to Improve Vision-Based Keystroke Inference Attacks Under Low Data ConstraintsabstractKeystroke inference attacks are a form of side-channel attacks in which an attacker leverages various techniques to recover a user's keystrokes as she inputs information into some display (e.g., while sending a text message or entering her pin). Typically, these attacks leverage machine learning approaches, but assessing the realism of the threat space has lagged behind the pace of machine learning advancements, due in-part, to the challenges in curating large real-life datasets. We aim to overcome the challenge of having limited number of real data by introducing a video domain adaptation technique that is able to leverage synthetic data through supervised disentangled learning. Specifically, for a given domain, we decompose the observed data into two factors of variation: Style and Content. Doing so provides four learned representations: real-life style, synthetic style, real-life content and synthetic content. Then, we combine them into feature representations from all combinations of style-content pairings across domains, and train a model on these combined representations to classify the content (i.e., labels) of a given datapoint in the style of another domain. We evaluate our method on real-life data using a variety of metrics to quantify the amount of information an attacker is able to recover. We show that our method prevents our model from overfitting to a small real-life training set, indicating that our method is an effective form of data augmentation, thereby making keystroke inference attacks more practical. John Lim, Jan-Michael Frahm, Fabian Monrose |
CODASPY | 3 |
| 2022 | Separating the Wheat from the Chaff: Using Indexing and Sub-Sequence Mining Techniques to Identify Related Crashes During Bug TriageabstractBug triaging entails a laborious process wherein triagers spend time examining new bug reports, localizing the bugs, and assigning them to the appropriate developer(s) to fix the bugs. In recent years, the adoption of automated software testing techniques (e.g., fuzzing) further complicates the process because bug hunters can submit an overwhelming number of reports in a short period. To lessen these pain points, we present an approach that extracts a fingerprint from crash information within a bug report, and returns a group of bugs with similar behaviors. Our approach uses symptoms of the crash to create a robust fingerprint, and leverages MinHashing and Locality Sensitive Hashing to match crashes, as well as a sequential pattern mining algorithm to find frequent closed sequences among bugs. Our evaluation shows that our approach outperforms contemporary approaches (e.g., finding previously unknown duplicates among 81 CVEs), and saves triagers time and effort. Kedrian James, Yufei Du, Sanjeev Das, Fabian Monrose |
QRS | 4 |
| 2022 | Automatic Recovery of Fine-grained Compiler Artifacts at the Binary Level
Yufei Du, Ryan Court, Kevin Z. Snow, Fabian Monrose |
USENIX ATC | 4 |
| 2021 | Applicable Micropatches and Where to Find Them: Finding and Applying New Security Hot Fixes to Old SoftwareabstractWith the complexity and interdependency of modern software sharply rising, the impact of security vulnerabilities and thus the value of broadly available patches has increased drastically. Despite this, it is unclear if the current landscape supports the same level of patch discoverability as that of vulnerabilities - raising questions about whether patches are simply scare or if they are just hard to find (i.e., are there a lot of "secret patches" [1]), and, equally important, what kind of patches are they (e.g., are they micropatchable). We seek to assess the current state of patching by analyzing patches for a four-month period of recent Common Vulnerabilities and Exposures (CVEs). At first glance, the state of patching seems abysmal - only one-fourth of CVEs have a labelled patch on the National Vulnerability Database (NVD). However, by searching for indicators on other popular security trackers (e.g., Debian's), we were able to find a lot more "secret patches", but the ratio of patched CVEs plateaued around fifty percent.Examining the discovered patches, we noticed that many were version updates, and less than one-tenth had machine accessible source-code micropatches. Using a custom tool that leverages contemporary version control, we were able to test the feasibility of automatically applying these micropatches to older versions of the software and found that approximately two-thirds of the patches can be applied to at least one old version. The failure cases were mostly due to lax practices pertaining to security fixes and general software development (e.g., releasing the fix along with other extraneous features). Reflecting on our investigations, we surmise that between existence, discoverability, and versatility of security patches, existence and discoverability are the bigger problems. As to why this is the case, we find that the answer may lie in the perverse incentive structures of the industry. We conclude with possible remediations and hope that our work at least raises public awareness of the current state of patching and encourages future work to improve the situation. Mac Malone, Kevin Z. Snow, Fabian Monrose |
ICST | 4 |
| 2021 | To Gamify or Not?: On Leaderboard Effects, Student Engagement and Learning Outcomes in a Cybersecurity InterventionabstractWe present a gamified learning experience for cybersecurity education that is designed to provide learners with an understanding of the knowledge and techniques needed to solve everyday problems while simultaneously immersing them in a competitive environment. We provide a framework for measuring skills demonstrated by students within an active learning setting where the primary focus is on practical expertise. We also examine several unique aspects of designing such a gamified framework (e.g. the game itself must be insecure enough to be "hackable'', but secure enough not to be abused), and discuss how the framework was used to expose students to various security concepts. Mac Malone, Kedrian James, Murray Anderegg, Jan Werner, Fabian Monrose |
SIGCSE | 6 |
| 2021 | DynPTA: Combining Static and Dynamic Analysis for Practical Selective Data ProtectionabstractAs control flow hijacking attacks become more challenging due to the deployment of various exploit mitigation technologies, the leakage of sensitive process data through the exploitation of memory disclosure vulnerabilities is becoming an increasingly important threat. To make matters worse, recently introduced transient execution attacks provide a new avenue for leaking confidential process data. As a response, various approaches for selectively protecting subsets of critical in-memory data have been proposed, which though either require a significant code refactoring effort, or do not scale for large applications.In this paper we present DynPTA, a selective data protection approach that combines static analysis with scoped dynamic data flow tracking (DFT) to keep a subset of manually annotated sensitive data always encrypted in memory. DynPTA ameliorates the inherent overapproximation of pointer analysis—a significant challenge that has prevented previous approaches from supporting large applications—by relying on lightweight label lookups to determine if potentially sensitive data is actually sensitive. Labeled objects are tracked only within the subset of value flows that may carry potentially sensitive data, requiring only a fraction of the program’s code to be instrumented for DFT. We experimentally evaluated DynPTA with real-world applications and demonstrate that it can prevent memory disclosure (Heartbleed) and transient execution (Spectre) attacks from leaking the protected data, while incurring a modest runtime overhead of up to 19.2% when protecting the private TLS key of Nginx with OpenSSL. Tapti Palit, Jarin Firose Moon, Fabian Monrose, Michalis Polychronakis |
SP | 3 |
| 2021 | The Circle Of Life: A Large-Scale Study of The IoT Malware Lifecycle
Omar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court, Kevin Z. Snow, Fabian Monrose, Manos Antonakakis |
USENIX Security Symposium | 6 |
| 2020 | A Flexible Framework for Expediting Bug Finding by Leveraging Past (Mis-)Behavior to Discover New BugsabstractAmong various fuzzing approaches, coverage-guided grey-box fuzzing is perhaps the most prominent, due to its ease of use and effectiveness. Using this approach, the selection of inputs focuses on maximizing program coverage, e.g., in terms of the different branches that have been traversed. In this work, we begin with the observation that selecting any input that explores a new path, and giving equal weight to all paths, can lead to severe inefficiencies. For instance, although seemingly “new” crashes involving previously unexplored paths may be discovered, these often have the same root cause and actually correspond to the same bug. Sanjeev Das, Kedrian James, Jan Werner, Manos Antonakakis, Michalis Polychronakis, Fabian Monrose |
ACSAC | 6 |
| 2020 | Methodologies for Quantifying (Re-)randomization Security and Timing under JIT-ROPabstractJust-in-time return-oriented programming (JIT-ROP) allows one to dynamically discover instruction pages and launch code reuse attacks, effectively bypassing most fine-grained address space layout randomization (ASLR) protection. However, in-depth questions regarding the impact of code (re-)randomization on code reuse attacks have not been studied. For example, how would one compute the re-randomization interval effectively by considering the speed of gadget convergence to defeat JIT-ROP attacks? ; how do starting pointers in JIT-ROP impact gadget availability and gadget convergence time? ; what impact do fine-grained code randomizations have on the Turing-complete expressive power of JIT-ROP payloads? We conduct a comprehensive measurement study on the effectiveness of fine-grained code randomization schemes, with 5 tools, 20 applications including 6 browsers, 1 browser engine, and 25 dynamic libraries. We provide methodologies to measure JIT-ROP gadget availability, quality, and their Turing-complete expressiveness, as well as to empirically determine the upper bound of re-randomization intervals in re-randomization schemes using the Turing-complete (TC), priority, MOV TC, and payload gadget sets. Experiments show that the upper bound ranges from 1.5 to 3.5 seconds in our tested applications. Besides, our results show that locations of leaked pointers used in JIT-ROP attacks have no impacts on gadget availability but have an impact on how fast attackers find gadgets. Our results also show that instruction-level single-round randomization thwarts current gadget finding techniques under the JIT-ROP threat model. Salman Ahmed 0001, Ya Xiao 0002, Kevin Z. Snow, Gang Tan, Fabian Monrose, Danfeng Yao |
CCS | 5 |
| 2019 | Mitigating data leakage by protecting memory-resident sensitive dataabstractGaining reliable arbitrary code execution through the exploitation of memory corruption vulnerabilities is becoming increasingly more difficult in the face of modern exploit mitigations. Facing this challenge, adversaries have started shifting their attention to data leakage attacks, which can lead to equally damaging outcomes, such as the disclosure of private keys or other sensitive data. Tapti Palit, Fabian Monrose, Michalis Polychronakis |
ACSAC | 2 |
| 2019 | The SEVerESt Of Them All: Inference Attacks Against Secure Virtual EnclavesabstractThe success of cloud computing has shown that the cost and convenience benefits of outsourcing infrastructure, platform, and software resources outweigh concerns about confidentiality. Still, many businesses and individuals resist moving private data to cloud providers due to intellectual property and privacy reasons. A recent wave of hardware virtualization technologies aims to alleviate these concerns by offering encrypted virtualization features that support data confidentiality of guest virtual machines (e.g., by transparently encrypting memory) even when running on top untrusted hypervisors. We introduce two new attacks that can breach the confidentiality of protected enclaves. First, we show how a cloud adversary can judiciously inspect the general purpose registers to unmask the computation that passes through them. Specifically, we demonstrate a set of attacks that can precisely infer the executed instructions and eventually capture sensitive data given only indirect access to the CPU state as observed via the general purpose registers. Second, we show that even under a more restrictive environment - where access to the general purpose registers is no longer available - we can apply a different inference attack to recover the structure of an unknown, running, application as a stepping stone towards application fingerprinting. We demonstrate the practicality of these inference attacks by showing how an adversary can identify different applications and even distinguish between versions of the same application and the compiler used, recover data transferred over TLS connections within the encrypted guest, retrieve the contents of sensitive data as it is being read from disk by the guest, and inject arbitrary data within the guest. Taken as a whole, these attacks serve as a cautionary tale of what can go wrong when the state of registers (e.g., in AMD's SEV) and application performance data (e.g. in AMD's SEV-ES) are left unprotected. The latter is the first known attack that was designed to specifically target SEV-ES. Jan Werner, Joshua Mason, Manos Antonakakis, Michalis Polychronakis, Fabian Monrose |
AsiaCCS | 5 |
| 2019 | SoK: Security Evaluation of Home-Based IoT DeploymentsabstractHome-based IoT devices have a bleak reputation regarding their security practices.On the surface, the insecurities of IoT devices seem to be caused by integration problems that may be addressed by simple measures, but this work finds that to be a naive assumption.The truth is, IoT deployments, at their core, utilize traditional compute systems, such as embedded, mobile, and network.These components have many unexplored challenges such as the effect of over-privileged mobile applications on embedded devices.Our work proposes a methodology that researchers and practitioners could employ to analyze security properties for home-based IoT devices.We systematize the literature for homebased IoT using this methodology in order to understand attack techniques, mitigations, and stakeholders.Further, we evaluate 45 devices to augment the systematized literature in order to identify neglected research areas.To make this analysis transparent and easier to adapt by the community, we provide a public portal to share our evaluation data and invite the community to contribute their independent findings. Omar Alrawi, Charles Lever, Manos Antonakakis, Fabian Monrose |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | SoK: The Challenges, Pitfalls, and Perils of Using Hardware Performance Counters for SecurityabstractHardware Performance Counters (HPCs) have been available in processors for more than a decade. These counters can be used to monitor and measure events that occur at the CPU level. Modern processors provide hundreds of hardware events that can be monitored, and with each new processor architecture more are added. Yet, there has been little in the way of systematic studies on how performance counters can best be utilized to accurately monitor events in real-world settings. Especially when it comes to the use of HPCs for security applications, measurement imprecisions or incorrect assumptions regarding the measured values can undermine the offered protection. To shed light on this issue, we embarked on a year-long effort to (i) study the best practices for obtaining accurate measurement of events using performance counters, (ii) understand the challenges and pitfalls of using HPCs in various settings, and (iii) explore ways to obtain consistent and accurate measurements across different settings and architectures. Additionally, we then empirically evaluated the way HPCs have been used throughout a wide variety of papers. Not wanting to stop there, we explored whether these widely used techniques are in fact obtaining performance counter data correctly. As part of that assessment, we (iv) extended the seminal work of Weaver and McKee from almost 10 years ago on non-determinism in HPCs, and applied our findings to 56 papers across various application domains. In that follow-up study, we found the acceptance of HPCs in security applications is in stark contrast to other application areas - especially in the last five years. Given that, we studied an additional representative set of 41 works from the security literature that rely on HPCs, to better elucidate how the intricacies we discovered can impact the soundness and correctness of their approaches and conclusions. Toward that goal, we (i) empirically evaluated how failure to accommodate for various subtleties in the use of HPCs can undermine the effectiveness of security applications, specifically in the case of exploit prevention and malware detection. Lastly, we showed how (ii) an adversary can manipulate HPCs to bypass certain security defenses. Sanjeev Das, Jan Werner, Manos Antonakakis, Michalis Polychronakis, Fabian Monrose |
IEEE Symposium on Security and Privacy | 5 |
| 2018 | Security Risks in Asynchronous Web Servers: When Performance Optimizations Amplify the Impact of Data-Oriented AttacksabstractOver the past decade, many innovations have been achieved with respect to improving the responsiveness of highly-trafficked servers. These innovations are fueled by a desire to support complex and data-rich web applications while consuming minimal resources. One of the chief advancements has been the emergence of the asynchronous web server architecture, which is built from the ground up for scalability. While this architecture can offer a significant boost in performance over classic forking servers, it does so at the cost of abandoning memory space isolation between client interactions. This shift in design, that delegates the handling of many unrelated requests within the same process, enables powerful and covert data-oriented attacks that rival complete web server takeover - without ever hijacking the control flow of the server application. To demonstrate the severity of this threat, we present a technique for identifying security-critical web server data by tracing memory accesses committed by the program in generating responses to client requests. We further develop a framework for performing live memory analysis of a running server in order to understand how low-level memory structures can be corrupted for malicious intent. A fundamental goal of our work is to assess the realism of such data-oriented attacks in terms of the types of memory errors that can be leveraged to perform them, and to understand the prominence of these errors in real-world web servers. Our case study on a leading asynchronous architecture, namely Nginx, shows how dataoriented attacks allow an adversary to re-configure an Nginx instance on the fly in order to degrade or disable services (e.g., error reporting, security headers like HSTS, access control), steal sensitive information, as well as distribute arbitrary web content to unsuspecting clients - all by manipulating only a few bytes in memory. Our empirical findings on the susceptibility of modern asynchronous web servers to two wellknown CVEs show that the damage could be severe. To address this threat, we also discuss several potential mitigations. Taken as a whole, our work tells a cautionary tale regarding the risks of blindly pushing forward with performance optimizations. Micah Morton, Jan Werner, Panagiotis Kintis, Kevin Z. Snow, Manos Antonakakis, Michalis Polychronakis, Fabian Monrose |
EuroS&P | 7 |
| 2017 | Practical Attacks Against Graph-based ClusteringabstractGraph modeling allows numerous security problems to be tackled in a general way, however, little work has been done to understand their ability to withstand adversarial attacks. We design and evaluate two novel graph attacks against a state-of-the-art network-level, graph-based detection system. Our work highlights areas in adversarial machine learning that have not yet been addressed, specifically: graph-based clustering techniques, and a global feature space where realistic attackers without perfect knowledge must be accounted for (by the defenders) in order to be practical. Even though less informed attackers can evade graph clustering with low cost, we show that some practical defenses are possible. Yizheng Chen 0001, Yacin Nadji, Athanasios Kountouras, Fabian Monrose, Roberto Perdisci, Manos Antonakakis, Nikolaos Vasiloglou |
CCS | 4 |
| 2017 | Revisiting Browser Security in the Modern Era: New Data-Only Attacks and DefensesabstractThe continuous discovery of exploitable vulnerabilitiesin popular applications (e.g., web browsers and documentviewers), along with their heightening protections against control flow hijacking, has opened the door to an oftenneglected attack strategy-namely, data-only attacks. In thispaper, we demonstrate the practicality of the threat posedby data-only attacks that harness the power of memorydisclosure vulnerabilities. To do so, we introduce memorycartography, a technique that simplifies the construction ofdata-only attacks in a reliable manner. Specifically, we showhow an adversary can use a provided memory mapping primitive to navigate through process memory at runtime, andsafely reach security-critical data that can then be modifiedat will. We demonstrate this capability by using our cross-platform memory cartography framework implementation toconstruct data-only exploits against Internet Explorer and Chrome. The outcome of these exploits ranges from simple HTTP cookie leakage, to the alteration of the same originpolicy for targeted domains, which enables the cross-originexecution of arbitrary script code. The ease with which we can undermine the security ofmodern browsers stems from the fact that although isolationpolicies (such as the same origin policy) are enforced atthe script level, these policies are not well reflected in theunderlying sandbox process models used for compartmentalization. This gap exists because the complex demands oftoday's web functionality make the goal of enforcing thesame origin policy through process isolation a difficult oneto realize in practice, especially when backward compatibility is a priority (e.g., for support of cross-origin IFRAMEs). While fixing the underlying problems likely requires a majorrefactoring of the security architecture of modern browsers(in the long term), we explore several defenses, includingglobal variable randomization, that can limit the power ofthe attacks presented herein. Roman Rogowski, Micah Morton, Forrest Li, Fabian Monrose, Kevin Z. Snow, Michalis Polychronakis |
EuroS&P | 4 |
| 2016 | No-Execute-After-Read: Preventing Code Disclosure in Commodity SoftwareabstractMemory disclosure vulnerabilities enable an adversary to successfully mount arbitrary code execution attacks against applications via so-called just-in-time code reuse attacks, even when those applications are fortified with fine-grained address space layout randomization. This attack paradigm requires the adversary to first read the contents of randomized application code, then construct a code reuse payload using that knowledge. In this paper, we show that the recently proposed Execute-no-Read (XnR) technique fails to prevent just-in-time code reuse attacks. Next, we introduce the design and implementation of a novel memory permission primitive, dubbed No-Execute-After-Read (near), that foregoes the problems of XnR and provides strong security guarantees against just-in-time attacks in commodity binaries. Specifically, near allows all code to be disclosed, but prevents any disclosed code from subsequently being executed, thus thwarting just-in-time code reuse. At the same time, commodity binaries with mixed code and data regions still operate correctly, as legitimate data is still readable. To demonstrate the practicality and portability of our approach we implemented prototypes for both Linux and Android on the ARMv8 architecture, as well as a prototype that protects unmodified Microsoft Windows executables and dynamically linked libraries. In addition, our evaluation on the SPEC2006 benchmark demonstrates that our prototype has negligible runtime overhead, making it suitable for practical deployment. Jan Werner, George Baltas, Rob Dallara, Nathan Otterness, Kevin Z. Snow, Fabian Monrose, Michalis Polychronakis |
AsiaCCS | 6 |
| 2016 | Detecting Malicious Exploit Kits using Tree-based Similarity Searches
Teryl Taylor, Xin Hu 0001, Ting Wang 0006, Jiyong Jang, Marc Ph. Stoecklin, Fabian Monrose, Reiner Sailer |
CODASPY | 6 |
| 2016 | Cache, Trigger, Impersonate: Enabling Context-Sensitive Honeyclient Analysis On-the-Wire
Teryl Taylor, Kevin Z. Snow, Nathan Otterness, Fabian Monrose |
NDSS | 4 |
| 2016 | Return to the Zombie Gadgets: Undermining Destructive Code Reads via Code Inference AttacksabstractThe concept of destructive code reads is a new defensive strategy that prevents code reuse attacks by coupling fine-grained address space layout randomization with a mitigation for online knowledge gathering that destroys potentially useful gadgets as they are disclosed by an adversary. The intuition is that by destroying code as it is read, an adversary is left with no usable gadgets to reuse in a control-flow hijacking attack. In this paper, we examine the security of this new mitigation. We show that while the concept initially appeared promising, there are several unforeseen attack tactics that render destructive code reads ineffective in practice. Specifically, we introduce techniques for leveraging constructive reloads, wherein multiple copies of native code are loaded into a process' address space (either side-by-side or one-after-another). Constructive reloads allow the adversary to disclose one code copy, destroying it in the process, then use another code copy for their code reuse payload. For situations where constructive reloads are not viable, we show that an alternative, and equally powerful, strategy exists: leveraging code association via implicit reads, which allows an adversary to undo in-place code randomization by inferring the layout of code that follows already disclosed bytes. As a result, the implicitly learned code is not destroyed, and can be used in the adversary's code reuse attack. We demonstrate the effectiveness of our techniques with concrete instantiations of these attacks against popular applications. In light of our successes, we argue that the code inference strategies presented herein paint a cautionary tale for defensive approaches whose security blindly rests on the perceived inability to undo the application of in-place randomization. Kevin Z. Snow, Roman Rogowski, Jan Werner, Hyungjoon Koo, Fabian Monrose, Michalis Polychronakis |
IEEE Symposium on Security and Privacy | 5 |
| 2016 | Virtual U: Defeating Face Liveness Detection by Building Virtual Models from Your Public Photos
Yi Xu 0006, True Price, Jan-Michael Frahm, Fabian Monrose |
USENIX Security Symposium | 4 |
| 2015 | Isomeron: Code Randomization Resilient to (Just-In-Time) Return-Oriented Programming
Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi, Kevin Z. Snow, Fabian Monrose |
NDSS | 5 |
| 2014 | Watching the Watchers: Automatically Inferring TV Content From Outdoor Light EffusionsabstractThe flickering lights of content playing on TV screens in our living rooms are an all too familiar sight at night --- and one that many of us have paid little attention to with regards to the amount of information these diffusions may leak to an inquisitive outsider. In this paper, we introduce an attack that exploits the emanations of changes in light (e.g., as seen through the windows and recorded over 70 meters away) to reveal the programs we watch. Our empirical results show that the attack is surprisingly robust to a variety of noise signals that occur in real-world situations, and moreover, can successfully identify the content being watched among a reference library of tens of thousands of videos within several seconds. The robustness and efficiency of the attack can be attributed to the use of novel feature sets and an elegant online algorithm for performing index-based matches. Yi Xu 0006, Jan-Michael Frahm, Fabian Monrose |
CCS | 3 |
| 2014 | Isn't that Fantabulous: Security, Linguistic and Usability Challenges of Pronounceable TokensabstractOver the past few decades, passwords as a means of user authentication have been consistently criticized by users and security analysts alike. However, password-based systems are ubiquitous and entrenched in modern society-users understand how to use them, system administrators are intimately familiar with their operation, and many robust frameworks exist to make deploying passwords simple. Unfortunately, much of the formal research on user authentication has focused on attempting to provide alternatives (e.g., biometrics) to password-based mechanisms (or belated analyses of users' password choices), forcing administrators to use ad-hoc methods in attempts to improve security. This practice has lead to user frustration and inflated estimates of system security. We challenge common wisdom and re-examine whether pronounceable authentication strings might indeed offer a more reasonable alternative to traditional passwords. We argue that pronounceable authentication strings can lead to both improved system security and a decreased burden on users. To re-examine this potential, we explore questions related to how one might develop techniques for rating the pronounceability of word-like strings, and in doing so, enable one to quantify pronunciation difficulty. Armed with such an understanding, we posit new directions for generating usable passwords which are pronounceable and, we hope, memorable, hint-able and resistant to attack. Andrew M. White 0002, Katherine Shaw, Fabian Monrose, Elliott Moreton |
NSPW | 3 |
| 2014 | Stitching the Gadgets: On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection
Lucas Davi, Ahmad-Reza Sadeghi, Daniel Lehmann 0002, Fabian Monrose |
USENIX Security Symposium | 4 |
| 2014 | Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in MotionabstractWe explore the robustness and usability of moving-image object recognition (video) CAPTCHAS, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image CAPTCHAS involving rigid objects. We first present an attack that defeats instances of such a CAPTCHA (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely, randomly changing the font of individual characters, or even randomly varying the number of characters in the codeword). We implement the modified CAPTCHAS and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets. Worse yet, our GPU-based implementation shows that our automated approach can decode these captchas faster than humans can, and we can do so at a relatively low cost of roughly 50 cents per 1,000 captchas solved based on Amazon EC2 rates circa 2012. To further demonstrate the challenges in designing usable captchas, we also implement and test another variant of moving text strings using the known emerging images concept. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images idea resist our current attack where others fail. Yi Xu 0006, Gerardo Reynaga, Sonia Chiasson, Jan-Michael Frahm, Fabian Monrose, Paul C. van Oorschot |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2013 | Seeing double: reconstructing obscured typed input from repeated compromising reflectionsabstractOf late, threats enabled by the ubiquitous use of mobile devices have drawn much interest from the research community. However, prior threats all suffer from a similar, and profound, weakness - namely the requirement that the adversary is either within visual range of the victim (e.g., to ensure that the pop-out events in reflections in the victim's sunglasses can be discerned) or is close enough to the target to avoid the use of expensive telescopes. In this paper, we broaden the scope of the attacks by relaxing these requirements and show that breaches of privacy are possible even when the adversary is around a corner. The approach we take overcomes challenges posed by low image resolution by extending computer vision methods to operate on small, high-noise, images. Moreover, our work is applicable to all types of keyboards because of a novel application of fingertip motion analysis for key-press detection. In doing so, we are also able to exploit reflections in the eyeball of the user or even repeated reflections (i.e., a reflection of a reflection of the mobile device in the eyeball of the user). Our empirical results show that we can perform these attacks with high accuracy, and can do so in scenarios that aptly demonstrate the realism of this threat. Yi Xu 0006, Jared Heinly, Andrew M. White 0002, Fabian Monrose, Jan-Michael Frahm |
CCS | 4 |
| 2013 | Crossing the threshold: Detecting network malfeasance via sequential hypothesis testingabstractThe domain name system plays a vital role in the dependability and security of modern network. Unfortunately, it has also been widely misused for nefarious activities. Recently, attackers have turned their attention to the use of algorithmically generated domain names (AGDs) in an effort to circumvent network defenses. However, because such domain names are increasingly being used in benign applications, this transition has significant implications for techniques that classify AGDs based solely on the format of a domain name. To highlight the challenges they face, we examine contemporary approaches and demonstrate their limitations. We address these shortcomings by proposing an online form of sequential hypothesis testing that classifies clients based solely on the non-existent (NX) responses they elicit. Our evaluations on real-world data show that we outperform existing approaches, and for the vast majority of cases, we detect malware before they are able to successfully rendezvous with their command and control centers. Srinivas Krishnan, Teryl Taylor, Fabian Monrose, John McHugh |
DSN | 3 |
| 2013 | Clear and Present Data: Opaque Traffic and its Security Implications for the Future
Andrew M. White 0002, Srinivas Krishnan, Michael D. Bailey, Fabian Monrose, Phillip A. Porras |
NDSS | 4 |
| 2013 | Check My Profile: Leveraging Static Analysis for Fast and Accurate Detection of ROP Gadgets
Blaine Stancill, Kevin Z. Snow, Nathan Otterness, Fabian Monrose, Lucas Davi, Ahmad-Reza Sadeghi |
RAID | 4 |
| 2013 | Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout RandomizationabstractFine-grained address space layout randomization (ASLR) has recently been proposed as a method of efficiently mitigating runtime attacks. In this paper, we introduce the design and implementation of a framework based on a novel attack strategy, dubbed just-in-time code reuse, that undermines the benefits of fine-grained ASLR. Specifically, we derail the assumptions embodied in fine-grained ASLR by exploiting the ability to repeatedly abuse a memory disclosure to map an application's memory layout on-the-fly, dynamically discover API functions and gadgets, and JIT-compile a target program using those gadgets -- all within a script environment at the time an exploit is launched. We demonstrate the power of our framework by using it in conjunction with a real-world exploit against Internet Explorer, and also provide extensive evaluations that demonstrate the practicality of just-in-time code reuse attacks. Our findings suggest that fine-grained ASLR may not be as promising as first thought. Kevin Z. Snow, Fabian Monrose, Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen, Ahmad-Reza Sadeghi |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | On the Privacy Risks of Virtual Keyboards: Automatic Reconstruction of Typed Input from Compromising ReflectionsabstractWe investigate the implications of the ubiquity of personal mobile devices and reveal new techniques for compromising the privacy of users typing on virtual keyboards. Specifically, we show that so-called compromising reflections (in, for example, a victim's sunglasses) of a device's screen are sufficient to enable automated reconstruction, from video, of text typed on a virtual keyboard. Through the use of advanced computer vision and machine learning techniques, we are able to operate under extremely realistic threat models, in real-world operating conditions, which are far beyond the range of more traditional OCR-based attacks. In particular, our system does not require expensive and bulky telescopic lenses: rather, we make use of off-the-shelf, handheld video cameras. In addition, we make no limiting assumptions about the motion of the phone or of the camera, nor the typing style of the user, and are able to reconstruct accurate transcripts of recorded input, even when using footage captured in challenging environments (e.g., on a moving bus). To further underscore the extent of this threat, our system is able to achieve accurate results even at very large distances-up to 61 m for direct surveillance, and 12 m for sunglass reflections. We believe these results highlight the importance of adjusting privacy expectations in response to emerging technologies. Rahul Raguram, Andrew M. White 0002, Yi Xu 0006, Jan-Michael Frahm, Pierre Fite Georgel, Fabian Monrose |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2012 | Toward Efficient Querying of Compressed Network Payloads
Teryl Taylor, Scott E. Coull, Fabian Monrose, John McHugh |
USENIX ATC | 3 |
| 2012 | Security and Usability Challenges of Moving-Object CAPTCHAs: Decoding Codewords in Motion
Yi Xu 0006, Gerardo Reynaga, Sonia Chiasson, Jan-Michael Frahm, Fabian Monrose, Paul C. van Oorschot |
USENIX Security Symposium | 5 |
| 2012 | Understanding domain registration abuses
Scott E. Coull, Andrew M. White 0002, Ting-Fang Yen, Fabian Monrose, Michael K. Reiter |
Comput. Secur. | 4 |
| 2012 | Trail of Bytes: New Techniques for Supporting Data Provenance and Limiting Privacy BreachesabstractForensic analysis of computer systems requires that one first identify suspicious objects or events, and then examine them in enough detail to form a hypothesis as to their cause and effect. Sadly, while our ability to gather vast amounts of data has improved significantly over the past two decades, it is all too often the case that we lack detailed information just when we need it the most. In this paper, we attempt to improve on the state of the art by providing a forensic platform that transparently monitors and records data access events within a virtualized environment using only the abstractions exposed by the hypervisor. Our approach monitors accesses to objects on disk and follows the causal chain of these accesses across processes, even after the objects are copied into memory. Our forensic layer records these transactions in a tamper evident version-based audit log that allows for faithful, and efficient, reconstruction of the recorded events and the changes they induced. To demonstrate the utility of our approach, we provide an extensive empirical evaluation, including a real-world case study demonstrating how our platform can be used to reconstruct valuable information about the what, when, and how, after a compromise has been detected. We also extend our earlier work by providing a tracking mechanism that can monitor data exfiltration attempts across multiple disks and also block attempts to copy data over the network. Srinivas Krishnan, Kevin Z. Snow, Fabian Monrose |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2011 | iSpy: automatic reconstruction of typed input from compromising reflectionsabstractWe investigate the implications of the ubiquity of personal mobile devices and reveal new techniques for compromising the privacy of users typing on virtual keyboards. Specifi- cally, we show that so-called compromising reflections (in, for example, a victim's sunglasses) of a device's screen are sufficient to enable automated reconstruction, from video, of text typed on a virtual keyboard. Despite our deliberate use of low cost commodity video cameras, we are able to compensate for variables such as arbitrary camera and device positioning and motion through the application of advanced computer vision and machine learning techniques. Using footage captured in realistic environments (e.g., on a bus), we show that we are able to reconstruct fluent translations of recorded data in almost all of the test cases, correcting users' typing mistakes at the same time. We believe these results highlight the importance of adjusting privacy expectations in response to emerging technologies. Rahul Raguram, Andrew M. White 0002, Dibyendusekhar Goswami, Fabian Monrose, Jan-Michael Frahm |
CCS | 4 |
| 2011 | Amplifying limited expert input to sanitize large network tracesabstractWe present a methodology for identifying sensitive data in packet payloads, motivated by the need to sanitize packets before releasing them (e.g., for network security/dependability analysis). Our methodology accommodates packets recorded from an incompletely documented protocol, in which case it will be necessary to consult a human expert to determine what packet data is sensitive. Since expert availability for such tasks is limited, however, our methodology adopts a hierarchical approach in which most packet inspection is done by less-trained workers whose designations of sensitive data in selected packets best match the expert's. At the core of our methodology is a data reduction and presentation algorithm that selects candidate workers based on their evaluations of a small number of packets; that solicits these workers' designations of sensitive data in a larger (but still minuscule) subset of packets; and then applies these designations to mark sensitive data in the entire data set. We detail our algorithms and evaluate them in a realistic user study. Fabian Monrose, Michael K. Reiter |
DSN | 2 |
| 2011 | An empirical study of the performance, security and privacy implications of domain name prefetchingabstractAn increasingly popular technique for decreasing user-perceived latency while browsing the Web is to optimistically pre-resolve (or prefetch) domain name resolutions. In this paper, we present a large-scale evaluation of this practice using data collected over the span of several months, and show that it leads to noticeable increases in load on name servers-with questionable caching benefits. Furthermore, to assess the impact that prefetching can have on the deployment of security extensions to DNS (DNSSEC), we use a custom-built cache simulator to perform trace-based simulations using millions of DNS requests and responses collected campus-wide. We also show that the adoption of domain name prefetching raises privacy issues. Specifically, we examine how prefetching amplifies information disclosure attacks to the point where it is possible to infer the context of searches issued by clients. Srinivas Krishnan, Fabian Monrose |
DSN | 2 |
| 2011 | On Measuring the Similarity of Network Hosts: Pitfalls, New Metrics, and Empirical Analyses
Scott E. Coull, Fabian Monrose, Michael D. Bailey |
NDSS | 2 |
| 2011 | Phonotactic Reconstruction of Encrypted VoIP Conversations: Hookt on Fon-iksabstractIn this work, we unveil new privacy threats against Voice-over-IP (VoIP) communications. Although prior work has shown that the interaction of variable bit-rate codecs and length-preserving stream ciphers leaks information, we show that the threat is more serious than previously thought. In particular, we derive approximate transcripts of encrypted VoIP conversations by segmenting an observed packet stream into subsequences representing individual phonemes and classifying those subsequences by the phonemes they encode. Drawing on insights from the computational linguistics and speech recognition communities, we apply novel techniques for unmasking parts of the conversation. We believe our ability to do so underscores the importance of designing secure (yet efficient) ways to protect the confidentiality of VoIP conversations. Andrew M. White 0002, Austin R. Matthews, Kevin Z. Snow, Fabian Monrose |
IEEE Symposium on Security and Privacy | 4 |
| 2011 | SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks
Kevin Z. Snow, Srinivas Krishnan, Fabian Monrose, Niels Provos |
USENIX Security Symposium | 3 |
| 2010 | Trail of bytes: efficient support for forensic analysisabstractFor the most part, forensic analysis of computer systems requires that one first identify suspicious objects or events, and then examine them in enough detail to form a hypothesis as to their cause and effect. Sadly, while our ability to gather vast amounts of data has improved significantly over the past two decades, it is all too often the case that we tend to lack detailed information just when we need it the most. Simply put, the current state of computer forensics leaves much to be desired. In this paper, we attempt to improve on the state of the art by providing a forensic platform that transparently monitors and records data access events within a virtualized environment using only the abstractions exposed by the hypervisor. Our approach monitors accesses to objects on disk and follows the causal chain of these accesses across processes, even after the objects are copied into memory. Our forensic layer records these transactions in a version-based audit log that allows for faithful, and efficient, reconstruction of the recorded events and the changes they induced. To demonstrate the utility of our approach, we provide an extensive empirical evaluation, including a real-world case study demonstrating how our platform can be used to reconstruct valuable information about the what, when, and how, after a compromised has been detected. Srinivas Krishnan, Kevin Z. Snow, Fabian Monrose |
CCS | 3 |
| 2010 | The security of modern password expiration: an algorithmic framework and empirical analysisabstractThis paper presents the first large-scale study of the success of password expiration in meeting its intended purpose, namely revoking access to an account by an attacker who has captured the account's password. Using a dataset of over 7700 accounts, we assess the extent to which passwords that users choose to replace expired ones pose an obstacle to the attacker's continued access. We develop a framework by which an attacker can search for a user's new password from an old one, and design an efficient algorithm to build an approximately optimal search strategy. We then use this strategy to measure the difficulty of breaking newly chosen passwords from old ones. We believe our study calls into question the merit of continuing the practice of password expiration. Yinqian Zhang, Fabian Monrose, Michael K. Reiter |
CCS | 2 |
| 2010 | Understanding Domain Registration Abuses
Scott E. Coull, Andrew M. White 0002, Ting-Fang Yen, Fabian Monrose, Michael K. Reiter |
SEC | 4 |
| 2010 | Traffic classification using visual motifs: an empirical evaluationabstractIn this paper, we explore the effectiveness of using graphical methods for isolating the differences between common application protocols---both in their transient and steady-state behavior. Specifically, we take advantage of the observation that many Internet application protocols proscribe a very specific series of client/server interactions that are clearly visible in the sizes and timing of packets produced at the network layer and below. We show how so-called "visual motifs" built on these features can be used to assist a human operator to recognize application protocols in unidentified traffic. From a practical point of view, visual traffic classification can be used, for example, for anomaly detection to verify that all traffic to a web server on TCP port 80 does indeed exhibit the characteristic behavior patterns of HTTP, or for misuse detection to find unauthorized servers or to identify traffic generated by prohibited applications. We present our technique for building a classifier based on the notion of visual motifs and report on our experience using this technique to automatically classify on-the-wire behavioral patterns from network flow data collected from a campus network. Specifically, we analyze over 1 billion flows corresponding to over 5 million sessions on nearly 200 distinct ports and show that our approach achieves high recall and precision. Wilson Lian, Fabian Monrose, John McHugh |
VizSEC | 2 |
| 2010 | Uncovering Spoken Phrases in Encrypted Voice over IP ConversationsabstractAlthough Voice over IP (VoIP) is rapidly being adopted, its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that it is possible toidentify the phrases spoken within encrypted VoIP callswhen the audio is encoded using variable bit rate codecs. To do so, we train a hidden Markov model using only knowledge of the phonetic pronunciations of words, such as those provided by a dictionary, and search packet sequences for instances of specified phrases. Our approach does not require examples of the speaker’s voice, or even example recordings of the words that make up the target phrase. We evaluate our techniques on a standard speech recognition corpus containing over 2,000 phonetically rich phrases spoken by 630 distinct speakers from across the continental United States. Our results indicate that we can identify phrases within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2010 | Peeking Through the Cloud: Client Density Estimation via DNS Cache ProbingabstractReliable network demographics are quickly becoming a much sought-after digital commodity. However, as the need for more refined Internet demographics has grown, so too has the tension between privacy and utility. Unfortunately, current techniques lean too much in favor of functional requirements over protecting the privacy of users. For example, the most prominent proposals for measuring the relative popularity of a Web site depend on the deployment of client-side measurement agents that are generally perceived as infringing on users’ privacy, thereby limiting their wide-scale adoption. Moreover, the client-side nature of these techniques also makes them susceptible to various manipulation tactics that undermine the integrity of their results. In this article, we propose a new estimation technique that uses DNS cache probing to infer the density of clients accessing a given service. Compared to earlier techniques, our scheme is less invasive as it does not reveal user-specific traits, and is more robust against manipulation. We demonstrate the flexibility of our approach through two important security applications. First, we illustrate how our scheme can be used as a lightweight technique for measuring and verifying the relative popularity rank of different Web sites. Second, using data from several hundred botnets, we apply our technique to indirectly measure the infected population of this increasing Internet phenomenon. Moheeb Abu Rajab, Fabian Monrose, Niels Provos |
ACM Trans. Internet Techn. | 2 |
| 2009 | English shellcodeabstractHistory indicates that the security community commonly takes a divide-and-conquer approach to battling malware threats: identify the essential and inalienable components of an attack, then develop detection and prevention techniques that directly target one or more of the essential components. This abstraction is evident in much of the literature for buffer overflow attacks including, for instance, stack protection and NOP sled detection. It comes as no surprise then that we approach shellcode detection and prevention in a similar fashion. However, the common belief that components of polymorphic shellcode (e.g., the decoder) cannot reliably be hidden suggests a more implicit and broader assumption that continues to drive contemporary research: namely, that valid and complete representations of shellcode are fundamentally different in structure than benign payloads. While the first tenet of this assumption is philosophically undeniable (i.e., a string of bytes is either shellcode or it is not), truth of the latter claim is less obvious if there exist encoding techniques capable of producing shellcode with features nearly indistinguishable from non-executable content. In this paper, we challenge the assumption that shellcode must conform to superficial and discernible representations. Specifically, we demonstrate a technique for automatically producing English Shellcode, transforming arbitrary shellcode into a representation that is superficially similar to English prose. The shellcode is completely self-contained---i.e., it does not require an external loader and executes as valid IA32 code)---and can typically be generated in under an hour on commodity hardware. Our primary objective in this paper is to promote discussion and stimulate new ideas for thinking ahead about preventive measures for tackling evolutions in code-injection attacks. Joshua Mason, Sam Small, Fabian Monrose, Greg MacManus |
CCS | 3 |
| 2009 | Browser Fingerprinting from Coarse Traffic Summaries: Techniques and Implications
Ting-Fang Yen, Fabian Monrose, Michael K. Reiter |
DIMVA | 3 |
| 2009 | Toward Resisting Forgery Attacks via Pseudo-SignaturesabstractRecent work has shown that certain handwriting biometrics are susceptible to forgery attacks, both human- and machine-based. In this paper, we examine a new scheme for using handwritten input that attempts to address such concerns. Pseudo-signatures are intended to be easy for users to create and reproduce while being resilient to forgeries. Here we evaluate their feasibility in terms of usability and security through several user studies. Our initial experiments suggest that, when well-chosen, pseudo-signatures may prove to be an attractive biometric,although more research is required. Jin Chen 0005, Daniel P. Lopresti, Fabian Monrose |
ICDAR | 3 |
| 2009 | Traffic Morphing: An Efficient Defense Against Statistical Traffic Analysis
Charles V. Wright, Scott E. Coull, Fabian Monrose |
NDSS | 3 |
| 2008 | Peeking Through the Cloud: DNS-Based Estimation and Its Applications
Moheeb Abu Rajab, Fabian Monrose, Andreas Terzis, Niels Provos |
ACNS | 2 |
| 2008 | Towards practical biometric key generation with randomized biometric templatesabstractAlthough biometrics have garnered significant interest as a source of entropy for cryptographic key generation, recent studies indicate that many biometric modalities may not actually offer enough uncertainty for this purpose. In this paper, we exploit a novel source of entropy that can be used with any biometric modality but that has yet to be utilized for key generation, namely associating uncertainty with the way in which the biometric input is measured. Our construction poses only a modest requirement on a user: the ability to remember a low-entropy password. We identify the technical challenges of this approach, and develop novel techniques to overcome these difficulties. Our analysis of this approach indicates that it may offer the potential to generate stronger keys: In our experiments, 40% of the users are able to generate keys that are at least 230 times stronger than passwords alone. Lucas Ballard, Seny Kamara, Fabian Monrose, Michael K. Reiter |
CCS | 3 |
| 2008 | Taming the Devil: Techniques for Evaluating Anonymized Network Data
Scott E. Coull, Charles V. Wright, Angelos D. Keromytis, Fabian Monrose, Michael K. Reiter |
NDSS | 4 |
| 2008 | Spot Me if You Can: Uncovering Spoken Phrases in Encrypted VoIP ConversationsabstractDespite the rapid adoption of Voice over IP (VoIP), its security implications are not yet fully understood. Since VoIP calls may traverse untrusted networks, packets should be encrypted to ensure confidentiality. However, we show that when the audio is encoded using variable bit rate codecs, the lengths of encrypted VoIP packets can be used to identify the phrases spoken within a call. Our results indicate that a passive observer can identify phrases from a standard speech corpus within encrypted calls with an average accuracy of 50%, and with accuracy greater than 90% for some phrases. Clearly, such an attack calls into question the efficacy of current VoIP encryption standards. In addition, we examine the impact of various features of the underlying audio on our performance and discuss methods for mitigation. Charles V. Wright, Lucas Ballard, Scott E. Coull, Fabian Monrose, Gerald M. Masson |
SP | 4 |
| 2008 | All Your iFRAMEs Point to Us
Niels Provos, Panayiotis Mavrommatis, Moheeb Abu Rajab, Fabian Monrose |
USENIX Security Symposium | 4 |
| 2008 | To Catch a Predator: A Natural Language Approach for Eliciting Malicious Payloads
Sam Small, Joshua Mason, Fabian Monrose, Niels Provos, Adam Stubblefield |
USENIX Security Symposium | 3 |
| 2007 | Toward Valley-Free Inter-domain RoutingabstractASes in inter-domain routing receive little information about the quality of the routes they receive. This lack of information can lead to inefficient and even incorrect routing. In this paper, we quantitatively characterize BGP announcements that violate the so-called valley- free property-an indicator that universal best practices are not being preserved in the propagation of routes. Our analysis indicates that valley announcements are more pervasive than expected. Approximately ten thousand valley announcements appear every day and involve a substantial number of prefixes. 11 % of provider ASes propagate valley announcements, with a majority of violations happening at intermediate providers. We find that large surges of violating announcements can be attributed to transient configuration errors. We further propose a dynamic mechanism that provides route propagation information as transitive attributes of BGP. This information implicitly reflects the policies of the ASes along the path, without revealing the relationship of each AS pair. BGP-speaking routers use this information to identify (and presumably avoid) routes that violate the valley-free property. Sophie Y. Qiu, Patrick D. McDaniel, Fabian Monrose |
ICC | 3 |
| 2007 | Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces
Scott E. Coull, Charles V. Wright, Fabian Monrose, Michael P. Collins, Michael K. Reiter |
NDSS | 3 |
| 2007 | On Web Browsing Privacy in Anonymized NetFlows
Scott E. Coull, Michael P. Collins, Charles V. Wright, Fabian Monrose, Michael K. Reiter |
USENIX Security Symposium | 4 |
| 2007 | Language Identification of Encrypted VoIP Traffic: Alejandra y Roberto or Alice and Bob?
Charles V. Wright, Lucas Ballard, Fabian Monrose, Gerald M. Masson |
USENIX Security Symposium | 3 |
| 2007 | Forgery Quality and Its Implications for Behavioral Biometric SecurityabstractBiometric security is a topic of rapidly growing importance in the areas of user authentication and cryptographic key generation. In this paper, we describe our steps toward developing evaluation methodologies for behavioral biometrics that take into account threat models that have been largely ignored. We argue that the pervasive assumption that forgers are minimally motivated (or, even worse, naive) is too optimistic and even dangerous. Taking handwriting as a case in point, we show through a series of experiments that some users are significantly better forgers than others, that such forgers can be trained in a relatively straightforward fashion to pose an even greater threat, that certain users are easy targets for forgers, and that most humans are a relatively poor judge of handwriting authenticity, and hence, their unaided instincts cannot be trusted. Additionally, to overcome current labor-intensive hurdles in performing more accurate assessments of system security, we present a generative attack model based on concatenative synthesis that can provide a rapid indication of the security afforded by the system. We show that our generative attacks match or exceed the effectiveness of forgeries rendered by the skilled humans we have encountered. Lucas Ballard, Daniel P. Lopresti, Fabian Monrose |
IEEE Trans. Syst. Man Cybern. Part B | 3 |
| 2006 | Efficient Memory Bound Puzzles Using Pattern Databases
Sujata Doshi, Fabian Monrose, Aviel D. Rubin |
ACNS | 2 |
| 2006 | A multifaceted approach to understanding the botnet phenomenonabstractThe academic community has long acknowledged the existence of malicious botnets, however to date, very little is known about the behavior of these distributed computing platforms. To the best of our knowledge, botnet behavior has never been methodically studied, botnet prevalence on the Internet is mostly a mystery, and the botnet life cycle has yet to be modeled. Uncertainty abounds. In this paper, we attempt to clear the fog surrounding botnets by constructing a multifaceted and distributed measurement infrastructure. Throughout a period of more than three months, we used this infrastructure to track 192 unique IRC botnets of size ranging from a few hundred to several thousand infected end-hosts. Our results show that botnets represent a major contributor to unwanted Internet traffic - 27% of all malicious connection attempts observed from our distributed darknet can be directly attributed to botnet-related spreading activity. Furthermore, we discovered evidence of botnet infections in 11% of the 800,000 DNS domains we examined, indicating a high diversity among botnet victims. Taken as a whole, these results not only highlight the prominence of botnets, but also provide deep insights that may facilitate further research to curtail this phenomenon. Moheeb Abu Rajab, Jay Zarfoss, Fabian Monrose, Andreas Terzis |
Internet Measurement Conference | 3 |
| 2006 | Characterizing Address Use Structure and Stability of Origin Advertisement in Inter-domain RoutingabstractThe stability and robustness of BGP remains one of the most critical elements in sustaining today’s Internet. In this paper, we study the structure and stability of origin advertisements in inter-domain routing. We visualize and quantitatively characterize the frequency, size, and effect of address assignment and origin changes by analyzing realworld BGP updates for a period of one year from multiple vantage points. Broad classes of prefix behaviors are developed. We show that a significant portion of BGP traffic is due to prefix flapping and explore the contributing factors which include a number of prefixes with abnormal short upand- down cycles. A significant portion of prefixes have high origin stability. Most ASes are involved in few, if any, prefix movement events, while a small number of ASes are responsible for most of the origin churn. Additionally, we find that a high volume of new prefixes can be attributed to actively evolving countries, that some abnormal prefix flapping is most likely due to misconfiguration, and that some culprit ASes characterize the places where multi-origin prefixes oscillate. Sophie Y. Qiu, Patrick D. McDaniel, Fabian Monrose, Aviel D. Rubin |
ISCC | 3 |
| 2006 | Fast and Evasive Attacks: Highlighting the Challenges Ahead
Moheeb Abu Rajab, Fabian Monrose, Andreas Terzis |
RAID | 2 |
| 2006 | Biometric Authentication Revisited: Understanding the Impact of Wolves in Sheep's Clothing
Lucas Ballard, Fabian Monrose, Daniel P. Lopresti |
USENIX Security Symposium | 2 |
| 2006 | Using visual motifs to classify encrypted trafficabstractIn an effort to make robust traffic classification more accessible to human operators, we present visualization techniques for network traffic. Our techniques are based solely on network information that remains intact after application-layer encryption, and so offer a way to visualize traffic "in the dark". Our visualizations clearly illustrate the differences between common application protocols, both in their transient (i.e., time-dependent)and steady-state behavior. We show how these visualizations can be used to assist a human operator to recognize application protocols in unidentified traffic and to verify the results of an automated classifier via visual inspection. In particular, our preliminary results show that we can visually scan almost 45,000 connections in less than one hour and correctly identify known application behaviors. Moreover, using visualizations together with an automated comparison technique based on Dynamic Time Warping of the motifs, we can rapidly develop accurate recognizers for new or previously unknown applications. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
VizSEC | 2 |
| 2006 | On Inferring Application Protocol Behaviors in Encrypted Network TrafficabstractSeveral fundamental security mechanisms for restricting access to network resources rely on the ability of a reference monitor to inspect the contents of traffic as it traverses the network. However, with the increasing popularity of cryptographic protocols, the traditional means of inspecting packet contents to enforce security policies is no longer a viable approach as message contents are concealed by encryption. In this paper, we investigate the extent to which common application protocols can be identified using only the features that remain intact after encryption---namely packet size, timing, and direction. We first present what we believe to be the first exploratory look at protocol identification in encrypted tunnels which carry traffic from many TCP connections simultaneously, using only post-encryption observable features. We then explore the problem of protocol identification in individual encrypted TCP connections, using much less data than in other recent approaches. The results of our evaluation show that our classifiers achieve accuracy greater than 90% for several protocols in aggregate traffic, and, for most protocols, greater than 80% when making fine-grained classifications on single connections. Moreover, perhaps most surprisingly, we show that one can even estimate the number of live connections in certain classes of encrypted tunnels to within, on average, better than 20%. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
J. Mach. Learn. Res. | 2 |
| 2005 | Achieving Efficient Conjunctive Keyword Searches over Encrypted Data
Lucas Ballard, Seny Kamara, Fabian Monrose |
ICICS | 3 |
| 2005 | On the Effectiveness of Distributed Worm Monitoring
Moheeb Abu Rajab, Fabian Monrose, Andreas Terzis |
USENIX Security Symposium | 2 |
| 2004 | Time-Scoped Searching of Encrypted Audit Logs
Darren Davis, Fabian Monrose, Michael K. Reiter |
ICICS | 2 |
| 2004 | On User Choice in Graphical Password Schemes
Darren Davis, Fabian Monrose, Michael K. Reiter |
USENIX Security Symposium | 2 |
| 2004 | HMM profiles for network traffic classificationabstractWe present techniques for building HMM profiles for network applications using only the packet-level information that remains intact and observable after encryption, namely, packet size and arrival time. Using less information than previously thought possible, we demonstrate classification accuracy close to that of other recent techniques, and show success in classifying a variety of common network applications as observed from real Internet traffic traces. Charles V. Wright, Fabian Monrose, Gerald M. Masson |
VizSEC | 2 |
| 2002 | Toward Speech-Generated Cryptographic Keys on Resource-Constrained Devices
Fabian Monrose, Michael K. Reiter, Daniel P. Lopresti, Chilin Shih |
USENIX Security Symposium | 1 |
| 2001 | Cryptographic Key Generation from VoiceabstractWe propose a technique to reliably generate a cryptographic key from a user's voice while speaking a password. The key resists cryptanalysis even against an attacker who captures all system information related to generating or verifying the cryptographic key. Moreover, the technique is sufficiently robust to enable the user to reliably regenerate the key by uttering her password again. We describe an empirical evaluation of this technique using 250 utterances recorded from 50 users. Fabian Monrose, Michael K. Reiter, Susanne Wetzel |
S&P | 1 |
| 2000 | Privacy-preserving global customizationabstractWe present an architecture for global customization of web content, by w h i c h a w eb site can customize content for each visitor based on the activities undertaken by the same user on other, unrelated sites.Our architecture distinguishes itself in the privacy mechanisms it provides: each u s e r c o n trols what information a merchant can learn about her activities at other merchants, and each merchant controls to what other merchants the information it contributes is revealed.To a c hieve t h i s w e i n troduce novel data protection mechanisms for merchants and users.We further describe aspects of a prototype implementation of our architecture.Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page.To copy Robert M. Arlein, Ben Jai, Markus Jakobsson, Fabian Monrose, Michael K. Reiter |
EC | 4 |
| 2000 | Keystroke dynamics as a biometric for authenticationabstractMore than ever before the Internet is changing computing as we know it. Global access to information and resources is becoming an integral part of nearly every aspect of our lives. Unfortunately, with this global network access comes increased chances of malicious attack and intrusion. In an effort to confront the new threats unveiled by the networking revolution of the past few years reliable, rapid, and unintrusive means for automatically recognizing the identity of individuals are now being sought. In this paper we examine an emerging non-static biometric technique that aims to identify users based on analyzing habitual rhythm patterns in the way they type. Fabian Monrose, Aviel D. Rubin |
Future Gener. Comput. Syst. | 1 |
| 1999 | Password Hardening Based on Keystroke DynamicsabstractWe present a novel approach to improving the security of passwords. In our approach, the legitimate user's typing patterns (e.g., durations of keystrokes, and latencies between keystrokes) are combined with the user's password to generate a hardened password that is convincingly more secure than conventional passwords against both online and offline attackers. In addition, our scheme automatically adapts to gradual changes in a user's typing patterns while maintaining the same hardened password across multiple logins, for use in file encryption or other applications requiring a longterm secret key. Using empirical data and a prototype implementation of our scheme, we give evidence that our approach is viable in practice, in terms of ease of use, improved security, and performance Fabian Monrose, Michael K. Reiter, Susanne Wetzel |
CCS | 1 |
| 1999 | Distributed Execution with Remote Audit
Fabian Monrose, Peter Wyckoff, Aviel D. Rubin |
NDSS | 1 |
| 1999 | The Design and Analysis of Graphical Passwords
Ian H. Jermyn, Alain J. Mayer, Fabian Monrose, Michael K. Reiter, Aviel D. Rubin |
USENIX Security Symposium | 3 |
| 1997 | Authentication via Keystroke DynamicsabstractIn an effort to confront the challenges brought forward by the networking revolution of the past few years, we present im-proved techniques for authorized access to computer system resources and data. More than ever before, the Internet is changing computing as we know it. The possibilities of this global network seem limitless; unfortunately, with this global access comes increased chances of malicious attack and in-trusion. Alternatives to traditional access control measures are in high demand. In what follows we present one such alternative: computer access via keystroke dynamics. A database of 42 profiles was constructed based on key-stroke patterns gathered from various users performing struc-tured and unstructured tasks. We study the performance of a system for recognition of these users, and present a toolkit for analyzing system performance under varying criteria. Fabian Monrose, Aviel D. Rubin |
CCS | 1 |