Paul Pearce

dblp:61/1749 · DBLP profile ↗
← Back
27ranked-venue papers
5as first author
14since 2021 · last 2026
0000-0001-6418-9699ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 4 first-author · 11 since 2021Computer networks · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2026 Papers, Please: A First Look at Age Verification on the Web
Shreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, Michael A. Specter
SP4
2025 Understanding IPv6 Aliases and Detection Methods
Mert Erdemir, Frank Li 0001, Paul Pearce
PAM3
2024 Understanding Routing-Induced Censorship Changes Globally
abstract
Internet censorship is pervasive, with significant effort dedicated to understanding what is censored, and where. Prior censorship measurements however have identified significant inconsistencies in their results; experiments show unexplained non-deterministic behaviors thought to be caused by censor load, end-host geographic diversity, or incomplete censorship—inconsistencies which impede reliable, repeatable and correct understanding of global censorship. In this work we investigate the extent to which Equal-cost Multi-path (ECMP) routing is the cause for these inconsistencies, developing methods to measure and compensate for them.
Abhishek Bhaskar, Paul Pearce
CCS2
2024 Seeds of Scanning: Exploring the Effects of Datasets, Methods, and Metrics on IPv6 Internet Scanning
Grant Williams, Paul Pearce
IMC2
2024 Poster: Investigating Network Security Post-Outage: Open Ports Vulnerabilities
abstract
The Internet has become an important part of our lives today, hence ensuring its security and reliability is critical. Internet outages happen frequently due to various factors, including human inter- ventions, natural disasters, and power outages. A key question is whether hosts become vulnerable when a network recovers from an outage impacting Internet infrastructure. This could happen if firewalls malfunction, even for a short while, allowing some ports to become unexpectedly open. This can potentially lead to expo- sure of previously restricted services to external users, making the network vulnerable to security threats. Previous work has shown that, in general, unnecessary open ports can increase vulnerabil- ities in systems. This study proposes a practical approach to examine network security post-outage by identifying newly open ports that can increase system vulnerability. The goal of this work is to show that such risks can indeed arise after an outage and that the proposed methodology detects these new ports.
Zahra Yazdani, Paul Pearce, Alberto Dainotti, Cecilia Testart
IMC2
2024 A First Look at NAT64 Deployment In-The-Wild
Amanda Hsu, Frank Li 0001, Paul Pearce, Oliver Gasser
PAM (1)3
2024 BluePrint: Automatic Malware Signature Generation for Internet Scanning
abstract
Traditional malware-detection research has focused on techniques for detection on end hosts or passively on networks. In contrast, global malware detection on the Internet using active Internet scanning remains relatively unstudied, with research still relying on manual reverse engineering and handwritten scanning code.
Kevin Stevens, Mert Erdemir, Hang Zhang 0012, Taesoo Kim, Paul Pearce
RAID5
2024 6Sense: Internet-Wide IPv6 Scanning and its Security Applications
Grant Williams, Mert Erdemir, Amanda Hsu, Shraddha Bhat, Abhishek Bhaskar, Frank Li 0001, Paul Pearce
USENIX Security Symposium7
2024 Arcanum: Detecting and Evaluating the Privacy Risks of Browser Extensions on Web Pages and Web Content
Qinge Xie, Manoj Vignesh Kasi Murali, Paul Pearce, Frank Li 0001
USENIX Security Symposium3
2023 Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the Wild
Hammas Bin Tanveer, Rachee Singh, Paul Pearce, Rishab Nithyanand
USENIX Security Symposium3
2022 Cart-ology: Intercepting Targeted Advertising via Ad Network Identity Entanglement
abstract
Targeted advertising is a pervasive practice in the advertising ecosystem, with complex representations of user identity central to targeting. Ad networks are incentivized to tie ephemeral cookies across devices to lasting durable identifiers such as email addresses in order to develop comprehensive cross-device user profiles. Third-party ad networks typically do not have relationships with users and must rely on external parties such as merchant websites for durable identity information, introducing intricate trust relationships. We find attackers can exploit these trust relationships to confuse an ad network into linking an unprivileged attacker's browser to a victim's identity, thus "impersonating" the victim to the ad network.
ChangSeok Oh, Chris Kanich, Damon McCoy, Paul Pearce
CCS4
2022 ZDNS: a fast DNS toolkit for internet measurement
abstract
Active DNS measurement is fundamental to understanding and improving the DNS ecosystem. However, the absence of an extensible, high-performance, and easy-to-use DNS toolkit has limited both the reproducibility and coverage of DNS research. In this paper, we introduce ZDNS, a modular and open-source active DNS measurement framework optimized for large-scale research studies of DNS on the public Internet. We describe ZDNS's architecture, evaluate its performance, and present two case studies that highlight how the tool can be used to shed light on the operational complexities of DNS. We hope that ZDNS will enable researchers to better---and in a more reproducible manner---understand Internet behavior.
Liz Izhikevich, Gautam Akiwate, Briana Berger, Spencer Drakontaidis, Anna Ascheman, Paul Pearce, David Adrian, Zakir Durumeric
IMC6
2022 Many Roads Lead To Rome: How Packet Headers Influence DNS Censorship Measurement
Abhishek Bhaskar, Paul Pearce
USENIX Security Symposium2
2021 Deep Entity Classification: Abusive Account Detection for Online Social Networks
Teng Xu 0009, Gerard Goossen, Huseyin Kerem Cevahir, Sara Khodeir, Yingyezhe Jin, Frank Li 0001, Shawn Shan, David Mandell Freeman, Paul Pearce
USENIX Security Symposium10
2020 Evaluating Changes to Fake Account Verification Systems
Fedor Kozlov, Isabella Yuen, Jakub Kowalczyk, Daniel Bernhardt, Paul Pearce
RAID6
2020 DELF: Safeguarding deletion correctness in Online Social Networks
Katriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova, Benoît Reitz, Benjamin Strahs, Daniel Obenshain, Paul Pearce, Ioannis Papagiannis, Available Media
USENIX Security Symposium8
2019 Reading the Tea leaves: A Comparative Analysis of Threat Intelligence
Vector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy, Geoffrey M. Voelker, Stefan Savage
USENIX Security Symposium3
2018 Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan Ecosystem
Mohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce, Kirill Levchenko, Damon McCoy
USENIX Security Symposium4
2017 To Catch a Ratter: Monitoring the Behavior of Amateur DarkComet RAT Operators in the Wild
abstract
Remote Access Trojans (RATs) give remote attackers interactive control over a compromised machine. Unlike large-scale malware such as botnets, a RAT is controlled individually by a human operator interacting with the compromised machine remotely. The versatility of RATs makes them attractive to actors of all levels of sophistication: they've been used for espionage, information theft, voyeurism and extortion. Despite their increasing use, there are still major gaps in our understanding of RATs and their operators, including motives, intentions, procedures, and weak points where defenses might be most effective. In this work we study the use of DarkComet, a popular commercial RAT. We collected 19,109 samples of DarkComet malware found in the wild, and in the course of two, several-week-long experiments, ran as many samples as possible in our honeypot environment. By monitoring a sample's behavior in our system, we are able to reconstruct the sequence of operator actions, giving us a unique view into operator behavior. We report on the results of 2,747 interactive sessions captured in the course of the experiment. During these sessions operators frequently attempted to interact with victims via remote desktop, to capture video, audio, and keystrokes, and to exfiltrate files and credentials. To our knowledge, we are the first large-scale systematic study of RAT use.
Brown Farinholt, Mohammad Rezaeirad, Paul Pearce, Hitesh Dharmdasani, Haikuo Yin, Stevens Le Blond, Damon McCoy, Kirill Levchenko
IEEE Symposium on Security and Privacy3
2017 Augur: Internet-Wide Detection of Connectivity Disruptions
abstract
Anecdotes, news reports, and policy briefings collectively suggest that Internet censorship practices are pervasive. The scale and diversity of Internet censorship practices makes it difficult to precisely monitor where, when, and how censorship occurs, as well as what is censored. The potential risks in performing the measurements make this problem even more challenging. As a result, many accounts of censorship begin-and end-with anecdotes or short-term studies from only a handful of vantage points. We seek to instead continuously monitor information about Internet reachability, to capture the onset or termination of censorship across regions and ISPs. To achieve this goal, we introduce Augur, a method and accompanying system that utilizes TCP/IP side channels to measure reachability between two Internet locations without directly controlling a measurement vantage point at either location. Using these side channels, coupled with techniques to ensure safety by not implicating individual users, we develop scalable, statistically robust methods to infer network-layer filtering, and implement a corresponding system capable of performing continuous monitoring of global censorship. We validate our measurements of Internet-wide disruption in nearly 180 countries over 17 days against sites known to be frequently blocked, we also identify the countries where connectivity disruption is most prevalent.
Paul Pearce, Roya Ensafi, Frank Li 0001, Nick Feamster, Vern Paxson
IEEE Symposium on Security and Privacy1
2017 Global Measurement of DNS Manipulation
Paul Pearce, Ben Jones, Frank Li 0001, Roya Ensafi, Nick Feamster, Nicholas Weaver, Vern Paxson
USENIX Security Symposium1
2017 Characterizing the Nature and Dynamics of Tor Exit Blocking
Rachee Singh, Rishab Nithyanand, Sadia Afroz 0001, Paul Pearce, Michael Carl Tschantz, Phillipa Gill, Vern Paxson
USENIX Security Symposium4
2015 Ad Injection at Scale: Assessing Deceptive Advertisement Modifications
abstract
Today, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Google -- tens of millions of users around the globe. Injected ads arrive on a client's machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved.
Kurt Thomas, Elie Bursztein, Chris Grier, Grant Ho, Nav Jagpal, Alexandros Kapravelos, Damon McCoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab
IEEE Symposium on Security and Privacy10
2014 Characterizing Large-Scale Click Fraud in ZeroAccess
abstract
Click fraud is a scam that hits a criminal sweet spot by both tapping into the vast wealth of online advertising and exploiting that ecosystem's complex structure to obfuscate the flow of money to its perpetrators. In this work, we illuminate the intricate nature of this activity through the lens of ZeroAccess--one of the largest click fraud botnets in operation. Using a broad range of data sources, including peer-to-peer measurements, command-and-control telemetry, and contemporaneous click data from one of the top ad networks, we construct a view into the scale and complexity of modern click fraud operations. By leveraging the dynamics associated with Microsoft's attempted takedown of ZeroAccess in December 2013, we employ this coordinated view to identify "ad units" whose traffic (and hence revenue) primarily derived from ZeroAccess. While it proves highly challenging to extrapolate from our direct observations to a truly global view, by anchoring our analysis in the data for these ad units we estimate that the botnet's fraudulent activities plausibly induced advertising losses on the order of $100,000 per day.
Paul Pearce, Vacha Dave, Chris Grier, Kirill Levchenko, Saikat Guha 0002, Damon McCoy, Vern Paxson, Stefan Savage, Geoffrey M. Voelker
CCS1
2012 AdDroid: privilege separation for applications and advertisers in Android
abstract
Advertising is a critical part of the Android ecosystem---many applications use one or more advertising services as a source of revenue. To use these services, developers must bundle third-party, binary-only libraries into their applications. In this model, applications and their advertising libraries share permissions. Advertising-supported applications must request multiple privacy-sensitive permissions on behalf of their advertising libraries, and advertising libraries receive access to all of their host applications' other permissions. We conducted a study of the Android Market and found that 49% of Android applications contain at least one advertising library, and these libraries overprivilege 46% of advertising-supported applications. Further, we find that 56% of the applications with advertisements that request location (34% of all applications) do so only because of advertisements. Such pervasive overprivileging is a threat to user privacy. We introduce AdDroid, a privilege separated advertising framework for the Android platform. AdDroid introduces a new advertising API and corresponding advertising permissions for the Android platform. This enables AdDroid to separate privileged advertising functionality from host applications, allowing applications to show advertisements without requesting privacy-sensitive permissions.
Paul Pearce, Adrienne Porter Felt, Gabriel Nunez, David A. Wagner 0001
AsiaCCS1
2011 What's Clicking What? Techniques and Innovations of Today's Clickbots
Brad Miller 0002, Paul Pearce, Chris Grier, Christian Kreibich, Vern Paxson
DIMVA2
2003 The Wargame Infrastructure and Simulation Environment (Wise)
Paul Pearce, Alan Robinson, Susan Wright
KES1