VLDB 2026 Research / reviewers in the wild / expert
Haya Schulmann
dblp:94/7397
· DBLP profile ↗
93ranked-venue papers
16as first author
52since 2021 · last 2026
0000-0002-8130-0472ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 13 first-author · 40 since 2021Computer networks · 17 · 2 first-author · 8 since 2021Systems, architecture and hardware · 9 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pruning the Tree: Rethinking RPKI Architecture from the Ground up
Haya Schulmann, Niklas Vogel |
NDSS | 1 |
| 2026 | The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Softwareabstract2815 Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner |
SP | 3 |
| 2026 | Batch Me If You Can: Coverage-Guided RPKI Fuzzing at Scale
Haya Schulmann, Niklas Vogel |
SP | 1 |
| 2026 | Too Much Sharing, Too Little Security: Authentication Cookie Theft At Scale
Tobias Gattermayer, Haya Schulmann |
WWW | 2 |
| 2026 | All That Glitters is Not Gold: RPKI's Stumbling Speedrun to the TopabstractThe democratization of access has transformed the Internet into the primary platform for social interaction and economic activity. The COVID-19 pandemic significantly accelerated the digitalization of services, finance and communication. As critical infrastructure increasingly moves online, routing security is becoming a national security concern. U.S. regulatory bodies were the first to sound the alarm by formally recognizing the urgency of Internet routing security and calling for nationwide adoption of security protocols. The Resource Public Key Infrastructure (RPKI) protocol is already the leading standard for protecting Internet routing from hijacking attacks and route leaks. However, RPKI is not secure by design. Research on its security guarantees has shown that despite the minimal public facing interfaces, the software implementations are not only rife with issues, but the nature of these issues is such that they can be easily triggered and disconnect the RPKI security framework from Internet routing, thus severely downgrading RPKI protection benefits. In this work, we evaluate the security properties of RPKI, analyze its attack surface, the required attacker capabilities to launch them, and their consequences on global routing security. We propose that RPKI requires fundamental changes and improvements to mitigate its vulnerabilities, and become robust enough to withstand the eye of the storm. Donika Mirdita, Haya Schulmann, Michael Waidner |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Learning to Identify Conflicts in RPKIabstract1490 Haya Schulmann, Shujie Zhao |
AsiaCCS | 1 |
| 2025 | Demo: Stopping Production Testing: A Graphical RPKI Test-SuiteabstractThe Resource Public Key Infrastructure (RPKI) is increasingly protecting global BGP routing and major players are pushing for wide-scale adoption. RPKI protection relies on correct publication and validity of RPKI objects: If a prefix has no valid covering RPKI object, e.g., because the object is invalid or expired, the prefix is not protected from hijacks. At the same time, ASes that issue RPKI objects lack any feedback whether their objects are considered valid by all RPKI validation software. This lack of feedback has repeatedly led to operational issues, and problems with object validity are persistent to this day. Oftentimes, issues with objects are only detected in production, after they have caused damage to routing. A prominent example of this is an issue with Amazon objects in 2023 that left 6000 of its prefixes open to hijack in any AS using a specific RPKI validator software implementation. In this work, we present a novel RPKI toolsuite that allows for comprehensive testing of RPKI objects, enabling operators to detect issues in their object configurations before production use. For this, our tool allows parsing arbitrary DER/base64 encoded objects, editing their content and structure, and live-testing them against all current RPKI validator implementations to probe for inconsistent validation results, errors, and even vulnerabilities. Our work provides an important foundation to ensure RPKI resilience against misconfigurations and facilitates future research into RPKI security. We make our tool open-source and provide a hosted web application to enable usage by the community. Tobias Kirsch, Haya Schulmann, Niklas Vogel |
CCS | 2 |
| 2025 | Poster: The Rocky Road Towards RPKI Algorithm AgilityabstractThe Resource Public Key Infrastructure (RPKI) already protects around 50% of announced BGP prefixes, and around 28% of systems enforce RPKI validity in routing. RPKI binds ownership of prefixes to public keys inside certificates, which are signed by the respective issuer. For signatures and keys, RPKI currently exclusively supports RSA-2048, forbidding other algorithms and key sizes. In this work, we practically show that RPKI efficiency could significantly benefit from algorithm agility, allowing for smaller more efficient algorithms like Elliptic Curve Cryptography (ECC). We further illustrate that current plans for shifting algorithms, which will eventually become necessary to shift towards quantum-secure algorithms, are infeasible due to bandwidth limitations, validation overhead, and issues with patch management. From our observations, we derive a new agility procedure that uses separate repository versions additional to two separate trees (a mixed tree and a legacy tree) to enable incremental deployment of a new algorithm. In contrast to existing approaches, our procedure provides benefits also for early adopters, facilitating deployment. Katharina Miesch, Haya Schulmann, Niklas Vogel |
CCS | 2 |
| 2025 | Poster: Exploring the Landscape of RPKI Relying PartiesabstractThe Resource Public Key Infrastructure (RPKI) is the most successful routing defense mechanism currently deployed throughout critical Internet infrastructures around the world. According to recent works, RPKI deployment boasts over 55% global prefix resource coverage, and at least 27% global protocol enforcement; all this success over a short period of time. In this work, we investigate for the first time deployment trends of the Relying Party (RP), the RPKI component responsible for collecting and enforcing RPKI on routers. We map RP locations, deployment parameters, vulnerability distributions, and describe the evolution of deployment trends over two measurement periods three years apart. Through this exploratory analysis, we map global patterns and the preferred deployment configurations by network operators. We observe how within three years, RP traffic increased by 45%, while 89% of traffic stems from one software type. Our measurements show a strong preference by operators to self-host, coupled with inadequate rates of RP vulnerability mitigation. Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2025 | Poster: We must talk about RPKI RepositoriesabstractThe Resource Public Key Infrastructure (RPKI) increasingly protects global routing against attacks. RPKI protection builds on the security and availability of RPKI objects, which are stored in public RPKI repositories. Despite their critical role, not much is known about the technical specifics of these repositories. Which implementations do they use? Is the software maintained and secure? Which vulnerabilities persist? Answering these questions is essential to evaluate security and resilience of current RPKI architecture. Haya Schulmann, Niklas Vogel |
CCS | 1 |
| 2025 | ValidaTor: Domain Validation over Tor
Jens Frieß, Haya Schulmann, Michael Waidner |
NSDI | 2 |
| 2025 | SoK: An Introspective Analysis of RPKI Security
Donika Mirdita, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 2 |
| 2024 | External Attack-Surface of Modern OrganizationsabstractNavigating the maze of contemporary organizational attack surfaces is paramount in fortifying our defenses against the relentless tide of cyber incidents. However, existing network reconnaissance and security measurements, which enumerate IP addresses or scan popular domains searching for vulnerabilities, capture only a fragmented view of the risk landscape, neglecting the nuanced reality of modern organizational assets. We experimentally show that such scans miss out on most assets of large organizations since they do not consider the increasingly complex IT architectures. Nethanel Gelernter, Haya Schulmann, Michael Waidner |
AsiaCCS | 2 |
| 2024 | Poster: Kill Krill or Proxy RPKIabstractResource Public Key Infrastructure (RPKI), designed to protect Internet routing from hijacks, is gaining traction: over 50% of prefixes have digital certificates, at least 27% of Autonomous Systems actively validate certificates against BGP announcements, and filter invalid routing announcements. In this study, we present the first security analysis of Krill, the only public and open-source RPKI publication point software. Publication points are hosted by the five Regional Internet Registries across the globe, or by independent Internet operators that wish to manage their own RPKI repositories. Louis Cattepoel, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2024 | Byzantine-Secure Relying Party for Resilient RPKIabstractBGP is a gaping hole in Internet security, as evidenced by numerous hijacks and outages. The significance of BGP for stability and security of the Internet has made it a top priority on the cyber security agenda of the US government, with CISA, FCC, and other federal agencies leading the efforts. Jens Frieß, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2024 | The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSECabstractAvailability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers. Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 2 |
| 2024 | Poster: Patching NSEC3-Encloser: The Good, the Bad, and the UglyabstractThis paper evaluates the effectiveness of patches designed to mitigate the NSEC3-encloser attack in DNS resolvers. NSEC3, used in DNSSEC to authenticate non-existence of records, can be exploited to exhaust resolver resources through excessive SHA-1 hashing. Despite recent patches, our study reveals that major DNS resolvers remain vulnerable. We test the NSEC3 exhaustion attacks against pre- and post-patch versions of popular DNS resolvers (Unbound, BIND9, PowerDNS, and Knot Resolver), and observe a 72-fold increase in CPU instructions during attacks. PowerDNS 5.0.5 and Knot Resolver 5.7.3 showed improvements, limiting CPU load with strict hash limits. Conversely, BIND9 exhibited marginal improvement, and Unbound 1.20.0 experienced increased CPU load. At an attack rate of 150 malicious NSEC3 records per second, benign DNS request loss rates ranged from 2.7% to 30%. Our study indicates the need for robust countermeasures to address NSEC3 vulnerabilities. Oliver Jacobsen, Haya Schulmann |
CCS | 2 |
| 2024 | Poster: From Fort to Foe: The Threat of RCE in RPKIabstractIn this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers. We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise systems running the software over a benign coding mistake. We disclosed the vulnerability, which has been assigned a CVE rated 9.8 critical (CVE-2024-45237). Oliver Jacobsen, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 2 |
| 2024 | Poster: Security of Login Interfaces in Modern OrganizationsabstractLogin pages, including those for processes like sign-up, registration, and password recovery are interfaces that implement access control to company services or functionalities. Insufficient security on these pages could allow malicious individuals to gain access to services and network of an organization and launch attacks. In this work, we perform a comprehensive study of the security of 73.4k login interfaces of the 100-top European companies from the Fortune report, which we call EU100. We find over 9 million vulnerabilities, which we analyze from a technical perspective, and categorize them according to the hosting model. Our work provides details on the most commonly observed vulnerabilities on login pages across different sectors and according to the hosting strategy adopted by each company. Kevin Nsieyanji Tchokodeu, Haya Schulmann, Gil Sobol, Michael Waidner |
CCS | 2 |
| 2024 | Crowdsourced Distributed Domain ValidationabstractDomain validation is the primary method used by Certificate Authorities for affirming administrative control over a domain for issuing TLS certificates. Prior work has repeatedly shown its vulnerability to hijacking, prompting the use of multiple vantage points for validation. However, the use of static vantage points, as in Let's Encrypt's MultiVA system, is still subject to targeted attacks. Validators should therefore be both distributed and selected in an unpredictable fashion, which is expensive to achieve with dedicated infrastructure. Jens Frieß, Haya Schulmann, Michael Waidner |
HotNets | 2 |
| 2024 | The CURE to Vulnerabilities in RPKI Validation
Donika Mirdita, Haya Schulmann, Niklas Vogel, Michael Waidner |
NDSS | 2 |
| 2024 | Cloudy with a Chance of Cyberattacks: Dangling Resources Abuse on Cloud Platforms
Jens Frieß, Tobias Gattermayer, Nethanel Gelernter, Haya Schulmann, Michael Waidner |
NSDI | 4 |
| 2024 | Insights into SAV Implementations in the Internet
Haya Schulmann, Shujie Zhao |
PAM (2) | 1 |
| 2024 | ZPredict: ML-Based IPID Side-channel MeasurementsabstractNetwork reconnaissance and measurements play a central role in improving Internet security and are important for understanding the current deployments and trends. Such measurements often require coordination with the measured target. This limits the scalability and the coverage of the existing proposals. IP Identification (IPID) provides a side channel for remote measurements without requiring the targets to install agents or visit the measurement infrastructure. However, current IPID-based techniques have technical limitations due to their reliance on the idealistic assumption of stable IPID changes or prior knowledge, making them challenging to adopt for practical measurements. In this work, we aim to tackle the limitations of existing techniques by introducing a novel approach: predictive analysis of IPID counter behavior. This involves utilizing a machine learning (ML) model to understand the historical patterns of IPID counter changes and predict future IPID values. To validate our approach, we implement six ML models and evaluate them on realistic IPID data collected from 4,698 Internet sources. Our evaluations demonstrate that among the six models, the Gaussian Process (GP) model has superior accuracy in tracking and predicting IPID values. Using the GP-based predictive analysis, we implement a tool, called ZPredict, to infer various favorable information about target networks or servers. Our evaluation on a large dataset of public servers demonstrates its effectiveness in idle port scanning, measuring Russian censorship, and inferring Source Address Validation. Our study methodology is ethical and was developed to mitigate any potential harm, taking into account the concerns associated with measurements. Haya Schulmann, Shujie Zhao |
ACM Trans. Priv. Secur. | 1 |
| 2023 | Poster: Longitudinal Analysis of DoS AttacksabstractDenial-of-Service (DoS) attacks have become a regular occurrence in the digital world of today. Easy-to-use attack software via download and botnet services that can be rented cheaply in the darknet enable adversaries to conduct such attacks without requiring a comprehensive knowledge of the techniques. Fabian Kaiser, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2023 | Poster: Off-Path DNSSEC Downgrade AttacksabstractRecent works found that signing zones with new cryptographic ciphers may disable DNSSEC validation in DNS resolvers. Adversaries could exploit this to manipulate algorithm numbers of ciphers in DNS responses, to make them appear as unknown, hence maliciously downgrading DNSSEC validation. In this work we show that these manipulation of DNSSEC records can also be launched remotely by off-path adversaries. We develop a DNSSEC downgrade attack using IP fragmentation. The idea is to create large DNS responses, that exceed the Maximum Transmission Unit on that path. The off-path adversary injects a malicious IP fragment, which when reassembled with the genuine IP fragment, overwrites the algorithm number of the ciphers in DNSSEC records. Elias Heftrig, Haya Schulmann, Michael Waidner |
SIGCOMM | 2 |
| 2023 | Beyond Limits: How to Disable Validators in Secure NetworksabstractRelying party validator is a critical component of RPKI: it fetches and validates signed authorizations mapping prefixes to their owners. Routers use this information to block bogus BGP routes. Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
SIGCOMM | 4 |
| 2023 | Poster: LeMon: Global Route Leak Monitoring ServiceabstractWe develop LeMon for real-time detection of route leaks and explain how we resolved the shortcomings in previous approaches. We perform extensive evaluations of LeMon on heuristically derived datasets as well as on live BGP traffic demonstrating its performance and accuracy. We also confirm the events identified by LeMon with survey of network operators. We provide access1 to our implementation of LeMon and to the datasets. Haya Schulmann, Shujie Zhao |
SIGCOMM | 1 |
| 2023 | Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed Zones
Elias Heftrig, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 2 |
| 2023 | Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
Tomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael Waidner |
USENIX Security Symposium | 2 |
| 2022 | Poster: The Unintended Consequences of Algorithm Agility in DNSSECabstractCryptographic algorithm agility is an important property for DNSSEC: it allows easy deployment of new algorithms if the existing ones are no longer secure. In this work we show that the cryptographic agility in DNSSEC, although critical for provisioning DNS with strong cryptography, also introduces a vulnerability. We find that under certain conditions, when new algorithms are listed in signed DNS responses, the resolvers do not validate DNSSEC. As a result, domains that deploy new ciphers may in fact cause the resolvers not to validate DNSSEC. We exploit this to develop DNSSEC-downgrade attacks and experimentally and ethically evaluate them against popular DNS resolver implementations, public DNS providers, and DNS services used by web clients worldwide. We find that major DNS providers as well as 45% of DNS resolvers used by web clients are vulnerable to our attacks. Elias Heftrig, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2022 | Behind the Scenes of RPKIabstractBest practices for making RPKI resilient to failures and attacks recommend using multiple URLs and certificates for publication points as well as multiple relying parties. We find that these recommendations are already supported by 63% of the ASes with RPKI. Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 4 |
| 2022 | Poster: RPKI Kill SwitchabstractRelying party implementations are an important component of RPKI: they fetch and validate the signed authorizations mapping prefixes to their owners. Border routers use this information to check which Autonomous Systems (ASes) are authorized to originate given prefixes and to enforce Route Origin Validation (ROV) in order to block bogus BGP announcements, preventing accidental and malicious prefix hijacks. In 2021 the RPKI relying party implementations were patched against attacks by malicious publication points. In such attacks the relying parties are stalled processing malformed RPKI objects. In this work we perform a black-box analysis of the patched relying party implementations and find that out of five popular relying parties, two major implementations (Routinator and OctoRPKI) have vulnerabilities that can be exploited to cause large scale blackouts in the RPKI ecosystem. We show that the vulnerabilities we found apply to 84.9% of the networks supporting RPKI. We analyze the code to understand the factors causing the bugs. We show that these vulnerabilities can be exploited to crash the deployed relying parties, disabling RPKI validation and exposing the networks to prefix hijack attacks. Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2022 | Poster: Insights into Global Deployment of RPKI ValidationabstractIP prefix hijacks, due to malicious attacks or benign misconfigurations, pose a threat to the Internet's stability and security. RPKI was designed to enable networks to block prefix hijacks by enforcing Route Origin Validation (ROV). In this work we evaluate the effectiveness of the global ROV deployment in blocking prefix hijacks. We perform control-plane and data-plane experiments and provide an in-depth analysis of the collected results. Our analysis is based on new methodologies we developed that allow more accurate identification of ROV enforcing ASes. Our analysis shows that the current ROV enforcement rate is significantly higher than found in previous studies: in contrast to 0.6% in a study from 2021, in our work we find that 37.8% enforce ROV. Our results indicate that ROV has finally gained traction and offers substantial protection against prefix hijacks. Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 1 |
| 2022 | Poster: DNS in Routers Considered HarmfulabstractTo save costs residential routers often do not implement most of the functionalities and security features of DNS, yet they still contain DNS forwarders which merely proxy the clients' requests to another address. These forwarders separate the network configuration of the internal client network from the network of the ISP. This provides connectivity without the need for synchronization. History of cache poisoning attacks shows however that such simplified implementations expose a wide range of vulnerabilities. We propose to remove DNS from routers. We show that the performance impact is negligible, while security gain is substantial. We discuss a number of ways for implementing our approach Haya Schulmann, Michael Waidner |
CCS | 1 |
| 2022 | How (Not) to Deploy Cryptography on the InternetabstractThe core protocols in the Internet infrastructure play a central role in delivering packets to their destination. The inter-domain routing with BGP (Border Gateway Protocol) computes the correct paths in the global Internet, and DNS (Domain Name System) looks up the destination addresses. Due to their critical function they are often attacked: the adversaries redirect victims to malicious servers or networks by making them traverse incorrect routes or reach incorrect destinations, e.g., for cyber-espionage, for spam distribution, for theft of crypto-currency, for censorship [1, 4-6]. This results in relatively stealthy attacks which cannot be immediately detected and prevented [2, 3]. By the time the attacks are detected, damage was already done. Haya Schulmann |
CODASPY | 1 |
| 2022 | Smart RPKI Validation: Avoiding Errors and Preventing Hijacks
Tomas Hlavacek, Haya Schulmann, Michael Waidner |
ESORICS (1) | 2 |
| 2022 | Stalloris: RPKI Downgrade Attack
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 4 |
| 2022 | XDRI Attacks - and - How to Enhance Resilience of Residential Routers
Philipp Jeitner, Haya Schulmann, Lucas Teichmann, Michael Waidner |
USENIX Security Symposium | 2 |
| 2022 | Special issue ESORICS 2021abstractFollowing the tradition of the European Symposium European Symposium on Research in Computer Security (ESORICS), this special issue includes selected papers from the 2021 edition of ESORICS.This edition was held (virtually) in Darmstadt (Germany) on October 4-8, 2021.ESORICS 2021 introduced for the first time in the ESORICS series two review cycles: a winter cycle and a spring cycle.Multiple submission cycles are today common in top conferences; they are not only more convenient for the authors but also allow revision and resubmission of papers.In response to the call for papers, 351 papers were submitted to ESORICS 2021.The papers were peer reviewed and discussed based on their novelty, quality, and contribution by the members of the Program Committee.Based on the reviews and discussions 71 high quality papers were selected for presentation at the conference.As a result, ESORICS had an interesting program covering timely and interesting security and privacy topics in theory, systems, networks, and applications.Because of the high quality of the papers accepted for presentation at ESORICS 2021, selecting the papers to invite for the special issue was challenging.To select the papers, we analyzed the top ranked papers and also asked for inputs by the PC members, and finally identified and invited six papers.Out of those six papers, one was not submitted owning to some resource issues by the authors.The remaining five papers went through the customary review cycles and were all accepted.These papers cover a broad set of topics, ranging from zero-knowledge proof protocols and privacy-preserving neural network inferences to privacy-preserving searching techniques, malware sandbox evasion and password strength estimation.Overall the selected papers address timely and crucial topics and provide novel solutions.We now briefly describe the main contributions of these papers. Elisa Bertino, Haya Schulmann, Michael Waidner |
J. Comput. Secur. | 2 |
| 2021 | SMap: Internet-wide Scanning for SpoofingabstractTo protect themselves from attacks, networks need to enforce ingress filtering, i.e., block inbound packets sent from spoofed IP addresses. Although this is a widely known best practice, it is still not clear how many networks do not block spoofed packets. Inferring the extent of spoofability at Internet scale is challenging and despite multiple efforts the existing studies currently cover only a limited set of the Internet networks: they can either measure networks that operate servers with faulty network-stack implementations, or require installation of the measurement software on volunteer networks, or assume specific properties, like traceroute loops. Improving coverage of the spoofing measurements is critical. Tianxiang Dai, Haya Schulmann |
ACSAC | 2 |
| 2021 | Evaluating Resilience of Domains in PKIabstractDomain Validation of PKI, allows to verify ownership over domains and poses the basis for cryptography. A number of recent attacks led to efforts to enhance the security of domain validation by improving the resilience of the vantage points used by the certificate authorities. Markus Brandt, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2021 | Let's Downgrade Let's EncryptabstractFollowing the recent off-path attacks against PKI, Let's Encrypt deployed in 2020 domain validation from multiple vantage points to ensure security even against the stronger on-path MitM adversaries. The idea behind such distributed domain validation is that even if the adversary can hijack traffic of some vantage points, it will not be able to intercept traffic of all the vantage points to all the nameservers in a domain. Tianxiang Dai, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2021 | Predictive Cipher-Suite Negotiation for Boosting Deployment of New CiphersabstractDeployment of strong cryptographic ciphers for DNSSEC is essential for long term security of DNS. Unfortunately, due to the hurdles involved in adoption of new ciphers coupled with the limping deployment of DNSSEC, most domains use the weak RSA-1024 cipher. Elias Heftrig, Jean-Pierre Seifert, Haya Schulmann, Michael Waidner, Nils Wisiol |
CCS | 3 |
| 2021 | The Master and Parasite AttackabstractWe explore a new type of malicious script attacks: the persistent parasite attack. Persistent parasites are stealthy scripts, which persist for a long time in the browser's cache. We show to infect the caches of victims with parasite scripts via TCP injection. Once the cache is infected, we implement methodologies for propagation of the parasites to other popular domains on the victim client as well as to other caches on the network. We show how to design the parasites so that they stay long time in the victim's cache not restricted to the duration of the user's visit to the web site. We develop covert channels for communication between the attacker and the parasites, which allows the attacker to control which scripts are executed and when, and to exfiltrate private information to the attacker, such as cookies and passwords. We then demonstrate how to leverage the parasites to perform sophisticated attacks, and evaluate the attacks against a range of applications and security mechanisms on popular browsers. Finally we provide recommendations for countermeasures. Lukas Baumann, Elias Heftrig, Haya Schulmann, Michael Waidner |
DSN | 3 |
| 2021 | Poster: Off-path VoIP Interception AttacksabstractThe proliferation of Voice-over-IP (VoIP) technologies make them a lucrative target of attacks. While many attack vectors have been uncovered, one critical vector has not yet received attention: hijacking telephony via DNS cache poisoning. We demonstrate practical VoIP hijack attacks by manipulating DNS responses with a weak off-path attacker. We evaluate our attacks against popular telephony VoIP systems in the Internet and provide a live demo of the attack against Extensible Messaging and Presence Protocol at https://sit4.me/M4. Tianxiang Dai, Haya Schulmann, Michael Waidner |
ICDCS | 2 |
| 2021 | Poster: Fragmentation Attacks on DNS over TCPabstractThe research and operational community believe that TCP provides protection against IP fragmentation based attacks and recommend that servers avoid sending responses over UDP and use TCP instead. In this work we show for the first time that IP fragmentation attacks may also apply to communication over TCP. We perform a study of the nameservers in the 100K-top Alexa domains and find that 454 domains are vulnerable to IP fragmentation attacks. Of these domains, we find 366 additional domains that are vulnerable only to IP fragmentation attacks on communication with TCP. We also find that the servers vulnerable to TCP fragmentation can be forced to fragment packets to much smaller sizes (of less than 292 bytes) than servers vulnerable to UDP fragmentation (not below 548 bytes). This makes the impact of the attacks against servers vulnerable to fragmentation of TCP segments much more detrimental. Our study not only shows that the recommendation to use TCP and avoid UDP is risky but it also shows that the attack surface due to fragmentation is larger than was previously believed. We evaluate known IP fragmentation-based DNS cache poisoning attacks against DNS responses over TCP. Tianxiang Dai, Haya Schulmann, Michael Waidner |
ICDCS | 2 |
| 2021 | Poster: WallGuard - A Deep Learning Approach for Avoiding Regrettable Posts in Social MediaabstractWe develop WallGuard for helping users in online social networks (OSNs) avoid regrettable posts and disclosure of sensitive information. Using WallGuard the users can control their posts and can (i) detect inappropriate, regrettable messages before they are posted, as well as (ii) identify already posted messages that could negatively impact user's reputation and life. WallGuard is based on deep learning architectures and NLP based methods. To evaluate the effectiveness of WallGuard, we developed a semi-supervised self-training methodology, which we use to create a new, large-scale corpus for regret detection with 4,7 million OSN messages. The corpus is generated by incrementally labelling messages from large OSN platforms relying on human-labelled and machine-labelled messages. Training Facebook's FastText word embeddings and Word2vec embeddings on our corpus, we created domain specific word embeddings, we referred to as regret embeddings. Our approach allows us to extract features that are discriminative/intrinsic for regrettable disclosures. Leveraging both regret embeddings and the new corpus, we successfully train and evaluate five new multi-label deep-learning based models for automatically classifying regrettable posts. Our evaluation of the proposed models demonstrate that we can detect messages with regrettable topics, achieving up to 0,975 weighted AUC, 82,2% precision and 74,6% recall. WallGuard is free and open-source. Haya Schulmann, Hervais Simo Fhom |
ICDCS | 1 |
| 2021 | Privacy Preserving and Resilient RPKIabstractResource Public Key Infrastructure (RPKI) is vital to the security of inter-domain routing. However, RPKI enables Regional Internet Registries (RIRs) to unilaterally takedown IP prefixes - indeed, such attacks have been launched by nation-state adversaries. The threat of IP prefix takedowns is one of the factors hindering RPKI adoption.In this work, we propose the first distributed RPKI system, based on threshold signatures, that requires the coordination of a number of RIRs to make changes to RPKI objects; hence, preventing unilateral prefix takedown. We perform extensive evaluations using our implementation demonstrating the practicality of our solution. Furthermore, we show that our system is scalable and remains efficient even when RPKI is widely deployed. Kris Shrishak, Haya Schulmann |
INFOCOM | 2 |
| 2021 | From IP to transport and beyond: cross-layer attacks against applicationsabstractWe perform the first analysis of methodologies for launching DNS cache poisoning: manipulation at the IP layer, hijack of the inter-domain routing and probing open ports via side channels. We evaluate these methodologies against DNS resolvers in the Internet and compare them with respect to effectiveness, applicability and stealth. Our study shows that DNS cache poisoning is a practical and pervasive threat. Tianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael Waidner |
SIGCOMM | 3 |
| 2021 | The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources
Tianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 3 |
| 2021 | Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS
Philipp Jeitner, Haya Schulmann |
USENIX Security Symposium | 2 |
| 2020 | Black-box caches fingerprintingabstractWe propose the first methodologies for remotely inferring and fingerprinting the software of DNS caches in the Internet based solely on the exchange of queries/responses with the DNS platform. Our techniques are robust and cannot be altered in transit, e.g., by firewalls, which does not hold for the existing fingerprinting techniques. In particular, the only way to alter the outcome of our fingerprinting methods is by modifying the DNS software itself. Amit Klein 0001, Elias Heftrig, Haya Schulmann, Michael Waidner |
CoNEXT | 3 |
| 2020 | Performance penalties of resilient SDN infrastructuresabstractSecure software and hardware are critical to the functionality and stability of the Internet as well as to its clients and services. Unfortunately, benign vulnerabilities and maliciously infiltrated backdoors can often not be identified in advance, which eliminates the possibility to mitigate them. When security assurances are not known, robust combiners can be applied to ensure resilience of networks and systems. In this work we present resilient constructions based on robust combiners for network devices in Software Defined Networking, and perform extensive evaluations to show the impact of robust combiners on the efficiency of network devices. Our results demonstrate that combining devices and software provides a reasonable performance for practical systems and is a promising approach for ensuring resilience when using potentially faulty or malicious components. Daniel Senf, Haya Schulmann, Michael Waidner |
CoNEXT | 2 |
| 2020 | The Impact of DNS Insecurity on TimeabstractWe demonstrate the first practical off-path time shifting attacks against NTP as well as against Man-in-the-Middle (MitM) secure Chronos-enhanced NTP. Our attacks exploit the insecurity of DNS allowing us to redirect the NTP clients to attacker controlled servers. We perform large scale measurements of the attack surface in NTP clients and demonstrate the threats to NTP due to vulnerable DNS. Philipp Jeitner, Haya Schulmann, Michael Waidner |
DSN | 2 |
| 2020 | Diving into Email Bomb AttackabstractWe explore Email Bomb - a particularly devastating type of Denial of Service (DOS) attack that recently gained traction. During the attack Email account of a victim is targeted with a flood of Emails. Existing anti-spam defences fail at filtering this Emails' flood, since the Emails are not sent from spoofed addresses, but originate from legitimate web services on the Internet which are exploited as reflectors. We perform a two-year study of the Email bomb attack and the affected actors - the victims and the reflectors. We show that although the attack is rented for one day, the Email flood proceeds over longer time periods often lasting months after the initial attack. We identify the properties that allow the attackers to recruit web sites as potential reflectors and demonstrate how the attackers harvest web reflectors. We show that even popular Alexa web sites, such as booking.com, are exploited to launch Email bomb attacks. The main problem is that such attacks are extremely simple to launch and can be rented for 5USD on darknet. We setup a tool which periodically collects and analyses the Emails received during the attack, the analysis as well as the data is presented online at http://emailbombresearch.xyz. We argue that email bomb attacks do not only pose inconvenience and hinder the ability of victims to function, but also we provide the first demonstration how such attacks can be leveraged for hiding other devastating attacks which take place in parallel. We show that existing countermeasures fall short of preventing email bomb attacks and provide effective mitigation recommendations that are based on our study of this attack. Markus Schneider 0002, Haya Schulmann, Adi Sidis, Ravid Sidis, Michael Waidner |
DSN | 2 |
| 2020 | Securing DNSSEC Keys via Threshold ECDSA from Generic MPC
Anders P. K. Dalskov, Claudio Orlandi, Marcel Keller, Kris Shrishak, Haya Schulmann |
ESORICS (2) | 5 |
| 2020 | Cryptanalysis of FNV-Based CookiesabstractDNS cookies is a recently standardised proposal of the IETF meant to protect DNS against off-path cache poisoning attacks. In contrast to other defences for DNS, DNS cookies is a lightweight mechanism, is easy to deploy and does not introduce overhead on the DNS servers. In this work we demonstrate off-path attacks allowing to circumvent the DNS cookies mechanism and impersonate legitimate Internet sources, exposing the DNS servers to cache poisoning and amplification reflection DoS attacks. We implement and evaluate the attacks, and provide recommendations for countermeasures. Amit Klein 0001, Haya Schulmann, Michael Waidner |
GLOBECOM | 2 |
| 2020 | Blocking Email Bombs with EmailGlassabstractWe develop a defence against email bomb attacks, we call EmailGlass. Email bomb is a targeted Denial of Service (DOS) attack during which the email account of a victim is flooded with multiple emails. The emails are sent by legitimate web services which the attackers abuse as reflectors, to reflect unwanted email traffic at victim email accounts.The lack of defences coupled with low costs of the attack and the devastating outcome, make email bomb attack particularly popular. The email bomb attacks do not only pose inconvenience and hinder the ability of victims to function, but can also be used to hide other attacks which take place concurrently.The design of EmailGlass is based on a two year study of the email bomb attack and the relevant actors - the victims and the reflectors. During the study we setup victim email accounts, and rented email bomb attacks on darknet. We analysed the attack traffic that was received on our victim accounts to derive conclusions for development of an effective defence mechanism. Markus Schneider 0002, Haya Schulmann, Michael Waidner |
GLOBECOM | 2 |
| 2020 | DISCO: Sidestepping RPKI's Deployment Barriers
Tomas Hlavacek, Ítalo S. Cunha, Yossi Gilad, Amir Herzberg, Ethan Katz-Bassett, Michael Schapira, Haya Schulmann |
NDSS | 7 |
| 2018 | Domain Validation++ For MitM-Resilient PKIabstractThe security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a weak off-path attacker can effectively subvert the trustworthiness of popular commercially used CAs. Our attack targets CAs which use Domain Validation (DV) for authenticating domain ownership; collectively these CAs control 99% of the certificates market. The attack utilises DNS Cache poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. We discuss short and long term defences, but argue that they fall short of securing DV. To mitigate the threats we propose Domain Validation++ (DV++). DV++ replaces the need in cryptography through assumptions in distributed systems. While retaining the benefits of DV (automation, efficiency and low costs) DV++ is secure even against Man-in-the-Middle (MitM) attackers. Deployment of DV++ is simple and does not require changing the existing infrastructure nor systems of the CAs. We demonstrate security of DV++ under realistic assumptions and provide open source access to DV++ implementation. Markus Brandt, Tianxiang Dai, Amit Klein 0001, Haya Schulmann, Michael Waidner |
CCS | 4 |
| 2018 | Off-Path Attacks Against PKIabstractThe security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a very weak attacker, namely, an off-path attacker, can effectively subvert the trustworthiness of popular commercially used CAs. We demonstrate an attack against one popular CA which uses Domain Validation (DV) for authenticating domain ownership. The attack exploits DNS Cache Poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. Tianxiang Dai, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2018 | Removing the Bottleneck for Practical 2PCabstractSecure Two Party Computation (2PC) has the potential to facilitate a wide range of real life applications where privacy of the computation and participants is critical. Nevertheless, this potential has not translated to widespread industry acceptance due to performance issues. Over the years a significant research effort has focused on optimising the performance of 2PC. The computation complexity has been continually improved and recently, following circuit optimisations and hardware support for cryptographic operations, evaluations of 2PC on a single host currently produce efficient results. Unfortunately, when evaluated on remote hosts, the performance remains prohibitive for practical purposes. The bottleneck is believed to be the bandwidth. In this work we explore the networking layer of 2PC implementations and show that the performance bottleneck is inherent in the usage of TCP sockets in implementations of 2PC schemes. Through experimental evaluations, we demonstrate that other transport protocols can significantly improve the performance of 2PC, making it suitable for practical applications. Kris Shrishak, Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2018 | Practical Experience: Methodologies for Measuring Route Origin ValidationabstractPerforming Route Origin Validation (ROV) to filter BGP announcements, which contradict Route Origin Authorizations (ROAs) is critical for protection against BGP prefix hijacks. Recent works quantified ROV enforcing Autonomous Systems (ASes) using control-plane experiments. In this work we show that control-plane experiments do not provide accurate information about ROV-enforcing ASes. We devise data-plane approaches for evaluating ROV in the Internet and perform both control and data-plane experiments using different data acquisition sources. We analyze and correlate the results of our study to identify the number of ASes enforcing ROV, and hence protected with RPKI. We perform simulations with the ROV-enforcing ASes that we identified, and find that their impact on the Internet security against prefix hijacks is negligible. As a countermeasure we provide recommendations how to cope with the main factor hindering wide adoption of ROV. Tomas Hlavacek, Amir Herzberg, Haya Schulmann, Michael Waidner |
DSN | 3 |
| 2018 | Internet As a Source of RandomnessabstractPseudorandom Generators (PRGs) play an important role in security of systems and cryptographic mechanisms. Yet, there is a long history of vulnerabilities in practical PRGs. Markus Brandt, Haya Schulmann, Michael Waidner |
HotNets | 2 |
| 2018 | Perfect is the Enemy of Good: Setting Realistic Goals for BGP SecurityabstractS.57-63 Yossi Gilad, Tomas Hlavacek, Amir Herzberg, Michael Schapira, Haya Schulmann |
HotNets | 5 |
| 2018 | Path MTU Discovery Considered HarmfulabstractPath MTU Discovery (PMTUD) allows to optimize the performance in the Internet by identifying the maximal packet size that can be transmitted through a network. Despite the central role that PMTUD plays in the Internet communication, it has a long history of software bugs, failures and misconfigurations. In this work we explore the benefits versus drawbacks of PMTUD in the Internet from the clients and servers perspective. First, we examine the fraction of clients that use PMTUD. To that end we analyse ICMP PTB messages in CAIDA Internet Traces and show that the fraction of networks using PMTUD is negligible and that this number is further decreasing over the period of 2008 - 2016. Second, we evaluate the fraction of popular web servers that support the PMTUD mechanism and show that a large number of the servers block "ICMP packet too big" messages. On the other hand, we show easy and efficient - even though well-known - degradation of service attacks that exploit the availability of PMTUD. Since the benefit of PMTUD is questionable, and in contrast it exposes to degradation of service attacks, we advocate to stop using it. As with any new change in the Internet, the implications of our recommendation should be carefully evaluated and gradually implemented. In the meanwhile, we provide recommendations for mitigations against the degradation of service attacks. Matthias Gohring, Haya Schulmann, Michael Waidner |
ICDCS | 2 |
| 2017 | POSTER: X-Ray Your DNSabstractWe design and develop DNS X-Ray which performs analyses of DNS platforms on the networks where it is invoked. The analysis identifies the caches and the IP addresses used by the DNS platform, fingerprints the DNS software on the caches, and evaluates vulnerabilities allowing injection of spoofed records into the caches. DNS X-Ray is the first tool to perform an extensive analysis of the caching component on the DNS platforms. In addition, DNS X-Ray also provides statistics from previous invocations, enabling networks to check which for popular DNS software on the caches, the number of caches typically used on DNS platforms and more. We set up DNS X-Ray online, it can be accessed via a website http://www.dns.xray.sit.fraunhofer.de. Amit Klein 0001, Vladimir Kravtsov, Alon Perlmuter, Haya Schulmann, Michael Waidner |
CCS | 4 |
| 2017 | Counting in the Dark: DNS Caches Discovery and Enumeration in the InternetabstractDomain Name System (DNS) is a fundamental element of the Internet providing lookup services for end users as well as for a multitude of applications, systems and security mechanisms that depend on DNS, such as antispam defences, routing security, firewalls, certificates and more. Caches constitute a critical component of DNS, allowing to improve efficiency and reduce latency and traffic in the Internet. Understanding the behaviour, configurations and topologies of caches in the DNS platforms in the Internet is important for efficiency and security of Internet users and services. In this work we present methodologies for efficiently discovering and enumerating the caches of the DNS resolution platforms in the Internet. We apply our techniques and methodologies for studying caches in popular DNS resolution platforms in the Internet. Our study includes networks of major ISPs, enterprises and professionally managed open DNS resolvers. The results of our Internet measurements shed light on architectures and configurations of the caches in DNS resolution platforms. Amit Klein 0001, Haya Schulmann, Michael Waidner |
DSN | 2 |
| 2017 | Internet-wide study of DNS cache injectionsabstractDNS caches are an extremely important tool, providing services for DNS as well as for a multitude of applications, systems and security mechanisms, such as anti-spam defences, routing security (e.g., RPKI), firewalls. Subverting the security of DNS is detrimental to the stability and security of the clients and services, and can facilitate attacks, circumventing even cryptographic mechanisms. We study the caching component of DNS resolution platforms in diverse networks in the Internet, and evaluate injection vulnerabilities allowing cache poisoning attacks. Our evaluation includes networks of leading Internet Service Providers and enterprises, and professionally managed open DNS resolvers. We test injection vulnerabilities against known payloads as well as a new class of indirect attacks that we define in this work. Our Internet evaluation indicates that more than 92% of the Internet's DNS resolution platforms are vulnerable to records injection and can be persistently poisoned. Amit Klein 0001, Haya Schulmann, Michael Waidner |
INFOCOM | 2 |
| 2017 | Are We There Yet? On RPKI's Deployment and Security
Yossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira, Haya Schulmann |
NDSS | 5 |
| 2017 | One Key to Sign Them All Considered Vulnerable: Evaluation of DNSSEC in the Internet
Haya Schulmann, Michael Waidner |
NSDI | 1 |
| 2016 | DNSSEC Misconfigurations in Popular Domains
Tianxiang Dai, Haya Schulmann, Michael Waidner |
CANS | 2 |
| 2016 | Obfuscation Combiners
Marc Fischlin, Amir Herzberg, Hod Bin Noon, Haya Schulmann |
CRYPTO (2) | 4 |
| 2015 | Towards Security of Internet Naming InfrastructureabstractWe study the operational characteristics of the server-side of the Internet’s naming infrastructure. Our findings discover common architectures whereby name servers are ‘hidden’ behind server-side caching DNS resolvers. We explore the extent and the scope of the name servers that use server-side caching resolvers, and find such configurations in at least $$38\,\%$$ of the domains in a forward DNS tree, and higher percents of the domains in a reverse DNS tree. We characterise the operators of the server-side caching resolvers and provide motivations, explaining their prevalence. Our experimental evaluation indicates that the caching infrastructures are typically run by third parties, and that the services, provided by the third parties, often do not deploy best practices, resulting in misconfigurations, vulnerabilities and degraded performance of the DNS servers in popular domains. Haya Schulmann, Michael Waidner |
ESORICS (1) | 1 |
| 2015 | Detection and Forensics of Domains HijackingabstractThe naming service provided by Domain Name System (DNS) is essential for locating resources on the Internet, for distributing security mechanisms in an authenticated manner, and for facilitating future applications. Unfortunately, despite the critical function that the naming service of the DNS infrastructure fulfills, it is extremely vulnerable to domain hijacking attacks. While most of the attacks go undetected, they are detrimental for the availability of the Internet services, and the security and privacy of clients and networks. We designed and developed a system, we call LUDIC (LookUp DIstributed Cache), for detection of domain hijacking attacks. Our system also enables forensic analysis and provides victims with signed evidences allowing them to prove breaches to third parties, such as a court of law or a resolution authority. LUDIC uses distributed vantage points to validate DNS records, and does not require establishing a chain of trust to a centralised trust anchor, hence sidestepping the adoption challenges inherent in DNSSEC. Our system does not introduce any changes to the existing infrastructure and can be easily integrated into an Intrusion Detection System (IDS) or a firewall, while providing an immediate benefit to adopters. Andreas Borgwart, Spyros Boukoros, Haya Schulmann, Carel van Rooyen, Michael Waidner |
GLOBECOM | 3 |
| 2014 | Fragmentation Considered Leaking: Port Inference for DNS Poisoning
Haya Schulmann, Michael Waidner |
ACNS | 1 |
| 2014 | DNS authentication as a service: preventing amplification attacksabstractWe present the first defence against DNS-amplification DoS attacks, which is compatible with the common DNS servers configurations and with the (important standard) DNSSEC. We show that the proposed DNS-authentication system is efficient, and effectively prevents DNS-based amplification DoS attacks abusing DNS name servers. We present a game-theoretic model and analysis, predicting a wide-spread adoption of our design, sufficient to reduce the threat of DNS amplification DoS attacks. To further reduce costs and provide additional defences for DNS servers, we show how to deploy our design as a cloud based service. Amir Herzberg, Haya Schulmann |
ACSAC | 2 |
| 2014 | Less is more: cipher-suite negotiation for DNSSECabstractWe propose a transport layer cipher-suite negotiation mechanism for DNSSEC standard, allowing name-servers to send responses containing only the keys and signatures that correspond to the cipher-suite option negotiated with the resolver, rather than sending all the signatures and keys (as is done currently). Amir Herzberg, Haya Schulmann, Bruno Crispo |
ACSAC | 2 |
| 2014 | Negotiating DNSSEC Algorithms over Legacy Proxies
Amir Herzberg, Haya Schulmann |
CANS | 2 |
| 2014 | POSTER: On the Resilience of DNS InfrastructureabstractWe study the operational characteristics of the DNS infrastructure: transitive-trust, coresidence and servers placement. We discuss how these factors impact resilience, stability and security of the DNS services. As our study indicates, common configuration choices, that domain operators make, result in a fragile DNS infrastructure, susceptible to malicious attacks and benign failures. We provide recommendations for improving robustness of DNS. Haya Schulmann, Shiran Ezra |
CCS | 1 |
| 2014 | DNSSEC for cyber forensicsabstractDomain Name System (DNS) cache poisoning is a stepping stone towards advanced (cyber) attacks. DNS cache poisoning can be used to monitor users’ activities for censorship, to distribute malware and spam and to subvert correctness and availability of Internet clients and services. Currently, the DNS infrastructure relies on challenge-response defences against attacks by (the common) off-path adversaries. Such defences do not suffice against stronger, man-in-the-middle (MitM), adversaries. However, MitM is not believed to be common; hence, there seems to be little motivation to adopt systematic, cryptographic mechanisms. We show that challenge-response do not protect against cache poisoning. In particular, we review common situations where (1) attackers can frequently obtain MitM capabilities and (2) even weaker attackers can subvert DNS security. We also experimentally study dependencies in the DNS infrastructure, in particular, dependencies within domain registrars and within domains, and show that multiple dependencies result in more vulnerable DNS. We review domain name system security extensions (DNSSEC), the defence against DNS cache poisoning, and argue that not only it is the most suitable mechanism for preventing cache poisoning but it is also the only proposed defence that enables a posteriori forensic analysis of attacks. Haya Schulmann, Michael Waidner |
EURASIP J. Inf. Secur. | 1 |
| 2013 | Limiting MitM to MitE Covert-ChannelsabstractWe study covert channels between a MitM attacker, and her MitE 'malware', running within the protected network of a victim organisation, and how to prevent or limit such channels. Our focus is on advanced timing channels, that allow communication between the MitM and MitE, even when hosts inside the protected network are restricted to only communicate to other (local and remote) hosts in the protected network. Furthermore, we assume communication is encrypted with fixed packet size (padding). We show that these do not suffice to prevent covert channels between MitM and MitE; furthermore, we show that even if we restrict communication to a constant rate, e.g., one packet everysecond, communication from MitE to MitM is still possible.We present efficient traffic shapers against covert channels between MitM and MitE. Our solutions preserve efficiency and bounded delay (QoS), while limiting covert traffic leakage, in both directions. Amir Herzberg, Haya Schulmann |
ARES | 2 |
| 2013 | DNSSEC: Interoperability Challenges and Transition MechanismsabstractRecent cache poisoning attacks motivate protecting DNS with strong cryptography, by adopting DNSSEC, rather than with challenge-response 'defenses'. We discuss the state of DNSSEC deployment and obstacles to adoption. We then present an overview of challenges and potential pitfalls of DNSSEC, including: Incremental Deployment: we review deployment status of DNSSEC, and discuss potential for increased vulnerability due to popular practices of incremental deployment, and provide recommendations. Long DNSSEC Responses; Long DNS responses are vulnerable to attacks, we review cache poisoning attack on fragmented DNS responses, and discuss mitigations; Trust Model of DNS: we review the trust model of DNS and show that it may not be aligned with the security model of DNSSEC. We discuss using trust anchor repositories (TARs) to mitigate the trust problem. TARs were proposed to allow transition to DNSSEC and to provide security for early adopters. Amir Herzberg, Haya Schulmann |
ARES | 2 |
| 2013 | Socket overloading for fun and cache-poisoningabstractWe present a new technique, which we call socket overloading, that we apply for off-path attacks on DNS. Socket overloading consists of short, low-rate, bursts of inbound packets, sent by off-path attacker to a victim host. Socket overloading exploits the priority assigned by the kernel to hardware interrupts, and enables an off-path attacker to illicit a side-channel on client hosts, which can be applied to circumvent source port and name server randomisation. Both port and name server randomisation are popular and standardised defenses, recommended in [RFC5452], against attacks by off-path adversaries. We show how to apply socket overloading for DNS cache poisoning and name server pinning against popular systems that support algorithms recommended in [RFC6056] and [RFC4097] respectively. Amir Herzberg, Haya Schulmann |
ACSAC | 2 |
| 2013 | Vulnerable Delegation of DNS Resolution
Amir Herzberg, Haya Schulmann |
ESORICS | 2 |
| 2013 | Oblivious and fair server-aided two-party computation
Amir Herzberg, Haya Schulmann |
Inf. Secur. Tech. Rep. | 2 |
| 2012 | Oblivious and Fair Server-Aided Two-Party ComputationabstractWe show efficient, practical (server-aided) securetwo-party computation protocols ensuring privacy, correctnessand fairness in the presence of malicious (Byzantine) faults. Ourrequirements from the server are modest: to ensure privacyand correctness, we only assume offline set-up prior to protocolexecution; and to also ensure fairness, we further assume atrusted-decryption service, providing decryption service usingknown public key. The fairness-ensuring protocol is optimistic, i.e., the decryption service is invoked only in case of faults. Bothassumptions are feasible in practice and formally presented inthe hybrid model. The resulting protocols may be sufficientlyefficient, to allow deployment, in particular for financial appli-cations. Amir Herzberg, Haya Schulmann |
ARES | 2 |
| 2012 | Antidotes for DNS Poisoning by Off-Path AdversariesabstractFollowing to Kaminsky's attack (2008), cachingresolvers were patched with defenses against poisoning. So far, the main improvements were non-cryptographic and easy todeploy (requiring changes only in resolvers). Some of these improvements are widely deployed, and it is believed that they suffice to prevent poisoning, at least by off-path, spoofingattackers. We perform a critical study of the prominent defense mechanisms against poisoning attacks by off-path adversaries. We present weaknesses and limitations, and suggest counter-measures. Our main message is that the DNS infrastructure shouldnot rely on short term, 'easy-to-deploy' defenses, and efforts should be increased towards transition to DNSSEC. Amir Herzberg, Haya Schulmann |
ARES | 2 |
| 2012 | Security of Patched DNS
Amir Herzberg, Haya Schulmann |
ESORICS | 2 |
| 2011 | Unilateral Antidotes to DNS Poisoning
Amir Herzberg, Haya Schulmann |
SecureComm | 2 |
| 2010 | Stealth DoS Attacks on Secure Channels
Amir Herzberg, Haya Schulmann |
NDSS | 2 |
| 2009 | Towards a Theory of White-Box Security
Amir Herzberg, Haya Schulmann, Amitabh Saxena, Bruno Crispo |
SEC | 2 |