Vashek Matyas

dblp:97/3759 · also Vashek Matyás · DBLP profile ↗
← Back
44ranked-venue papers
1as first author
13since 2021 · last 2026
0000-0001-7957-7694ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 34 · 12 since 2021Theory of computation · 3Artificial intelligence and machine learning · 2Computer networks · 2Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Clear, Actionable and Confidence-Inspiring Recommendations? Comparative Study of AI-Generated and Human-Written PT Reports
Katarína Galanská, Maria Pibilota Murumaa, Vashek Matyas, Agata Kruzikova, Mike Just, Tomás Cerný
SOUPS3
2025 Revisiting the analysis of references among Common Criteria certified products
Adam Janovsky, Lukasz Chmielewski, Petr Svenda, Jan Jancar, Vashek Matyas
Comput. Secur.5
2024 What Johnny thinks about using two-factor authentication on GitHub: A survey among open-source developers
abstract
Several security issues in open-source projects demonstrate that developer accounts get misused or stolen if weak authentication is used. Many services have started to enforce second-factor authentication (2FA) for their users. This is also the case for GitHub, the largest open-source development platform. We surveyed 110 open-source developers using GitHub to explore how they perceive the importance of authentication on GitHub. Our participants perceived secure authentication as important as other security mechanisms (e.g., commit signing) to improve open-source security. 2FA usage of the project owner was perceived as one of the most important mechanisms. Around half of the participants (51%) were aware of the planned 2FA enforcement on GitHub. Their perception of this enforcement was rather positive. They agreed to enforce 2FA for new devices and new locations, but they were slightly hesitant to use it after some time. They also rather agreed to enforce various user groups on GitHub to use 2FA. Our participants also perceived GitHub authentication methods positively with respect to their usability and security. Most of our participants (68%) reported that they had enabled 2FA on their GitHub accounts.
Agata Kruzikova, Jakub Suchanek, Milan Broz, Martin Ukrop, Vashek Matyas
ARES5
2024 Chain of Trust: Unraveling References Among Common Criteria Certified Products
Adam Janovsky, Lukasz Chmielewski, Petr Svenda, Jan Jancar, Vashek Matyas
SEC5
2024 sec-certs: Examining the security certification practice for better vulnerability mitigation
Adam Janovsky, Jan Jancar, Petr Svenda, Lukasz Chmielewski, Jiri Michalik, Vashek Matyas
Comput. Secur.6
2024 Two-factor authentication time: How time-efficiency and time-satisfaction are associated with perceived security and satisfaction
Agata Kruzikova, Michal Muzik, Lenka Knapova, Lenka Dedkova, David Smahel, Vashek Matyas
Comput. Secur.6
2023 Fingerprint forgery training: Easy to learn, hard to perform
abstract
Many services offer fingerprint authentication, including sensitive services such as mobile banking. This broad adoption could make an impression to the end-users that fingerprint authentication is secure. However, fingerprint authentication is vulnerable to various attacks performed even by not-very-sophisticated attackers, e.g., fingerprint forgery. Will participants perceive fingerprint authentication differently after relevant theory education and the creation of their fingerprint counterfeit to overcome misunderstandings, especially regarding security? How will they perceive the fingerprint forgery process? We prepared a hands-on seminar with fingerprint forgery simulation. We focused on the difference in perception before and after the theoretical lecture on biometrics and a practical seminar on forgery creation. We applied an uncommon approach, reconstructing the fingerprint from a photo of the actual finger rather than its print on some surface – to illustrate the case of an attack based merely on a “thumb-up” photograph. Our results show that 19% of participants (out of 221) were successful in spoofing, according to the NIST Biometric Image Software, and 27% of participants could register their counterfeit into the smartphone. Participants perceived fingerprint authentication as less secure after the simulation and reported their intention to use it less for mobile banking operations. They also perceived the forgery attack as easier to learn than before the simulation – but harder to perform. Our study implies that participants intend to change their behaviour based on their experience from our seminar, however, they did not consider two-factor authentication as an option.
Agata Kruzikova, Vashek Matyas
ARES2
2023 Want to Raise Cybersecurity Awareness? Start with Future IT Professionals
abstract
As cyber threats endanger everyone, from regular users to computing professionals, spreading cybersecurity awareness becomes increasingly critical. Therefore, our university designed an innovative cybersecurity awareness course that is freely available online for students, employees, and the general public. The course offers simple, actionable steps that anyone can use to implement defensive countermeasures. Compared to other resources, the course not only suggests learners what to do, but explains why and how to do it. To measure the course impact, we administered it to 138 computer science undergraduates within a compulsory information security and cryptography course. They completed the course as a part of their homework and filled out a questionnaire after each lesson. Analysis of the questionnaire responses revealed that the students valued the course highly. They reported new learning, perspective changes, and transfer to practice. Moreover, they suggested suitable improvements to the course. Based on the results, we have distilled specific insights to help security educators design similar courses. Lessons learned from this study are relevant for cybersecurity instructors, course designers, and educational managers.
Lydia Kraus, Valdemar Svábenský, Martin Horák, Vashek Matyas, Jan Vykopal, Pavel Celeda
ITiCSE (1)4
2022 Usability Insights from Establishing TLS Connections
Lydia Kraus, Matej Grabovský, Martin Ukrop, Katarína Galanská, Vashek Matyas
SEC5
2022 A Longitudinal Study of Cryptographic API: A Decade of Android Malware
abstract
Cryptography has been extensively used in Android applications to guarantee secure communications, conceal critical data from reverse engineering, or ensure mobile users' privacy. Various system-based and third-party libraries for Android provide cryptographic functionalities, and previous works mainly explored the misuse of cryptographic API in benign applications. However, the role of cryptographic API has not yet been explored in Android malware. This paper performs a comprehensive, longitudinal analysis of cryptographic API in Android malware. In particular, we analyzed 603 937 Android applications (half of them malicious, half benign) released between 2012 and 2020, gathering more than 1 million cryptographic API expressions. Our results reveal intriguing trends and insights on how and why cryptography is employed in Android malware. For instance, we point out the widespread use of weak hash functions and the late transition from insecure DES to AES. Additionally, we show that cryptography-related characteristics can help to improve the performance of learning-based systems in detecting malicious applications.
Adam Janovsky, Davide Maiorca, Dominik Macko, Vashek Matyas, Giorgio Giacinto
SECRYPT4
2022 Large-scale Randomness Study of Security Margins for 100+ Cryptographic Functions
abstract
The output of cryptographic functions, be it encryption routines or hash functions, should be statistically indistinguishable from a truly random data for an external observer. The property can be partially tested automatically using batteries of statistical tests. However, it is not easy in practice: multiple incompatible test suites exist, with possibly overlapping and correlated tests, making the statistically robust interpretation of results difficult. Additionally, a significant amount of data processing is required to test every separate cryptographic function. Due to these obstacles, no large-scale systematic analysis of the the round-reduced cryptographic functions w.r.t their input mixing capability, which would provide an insight into the behaviour of the whole classes of functions rather than few selected ones, was yet published. We created a framework to consistently run 414 statistical tests and their variants from the commonly used statistical testing batteries (NIST ST S, Dieharder, TestU01, and BoolTest). Using the distributed computational cluster providing required significant processing power, we analyzed the output of 109 round-reduced cryptographic functions (hash, lightweight, and block-based encryption functions) in the multiple configurations, scrutinizing the mixing property of each one. As a result, we established the fraction of a function’s rounds with still detectable bias (a.k.a. security margin) when analyzed by randomness statistical tests.
Dusan Klinec, Marek Sýs, Karel Kubicek 0001, Petr Svenda, Vashek Matyas
SECRYPT5
2022 Usable and secure? User perception of four authentication methods for mobile banking
Agata Kruzikova, Lenka Knapova, David Smahel, Lenka Dedkova, Vashek Matyas
Comput. Secur.5
2022 A Bad Day to Die Hard: Correcting the Dieharder Battery
Marek Sýs, Lubomír Obrátil, Vashek Matyas, Dusan Klinec
J. Cryptol.3
2020 Biased RSA Private Keys: Origin Attribution of GCD-Factorable Keys
Adam Janovsky, Matús Nemec, Petr Svenda, Peter Sekan, Vashek Matyas
ESORICS (2)5
2020 Privacy-Friendly Monero Transaction Signing on a Hardware Wallet
Dusan Klinec, Vashek Matyas
SEC2
2019 Will you trust this TLS certificate?: perceptions of people working in IT
abstract
Flawed TLS certificates are not uncommon on the Internet. While they signal a potential issue, in most cases they have benign causes (e.g., misconfiguration or even deliberate deployment). This adds fuzziness to the decision on whether to trust a connection or not. Little is known about perceptions of flawed certificates by IT professionals, even though their decisions impact high numbers of end users. Moreover, it is unclear how much does the content of error messages and documentation influence these perceptions.
Martin Ukrop, Lydia Kraus, Vashek Matyas, Heider A. M. Wahsheh
ACSAC3
2019 When Lagged Fibonacci Generators jump
Moon K. Chetry, Susil Kumar Bishoi, Vashek Matyas
Discret. Appl. Math.3
2019 Examining PBKDF2 security margin - Case study of LUKS
Andrea Visconti, Ondrej Mosnácek, Milan Broz, Vashek Matyas
J. Inf. Secur. Appl.4
2018 Why Johnny the Developer Can't Work with Public Key Certificates - An Experimental Study of OpenSSL Usability
Martin Ukrop, Vashek Matyas
CT-RSA2
2018 Adaptive Secrecy Amplification with Radio Channel Key Extraction
abstract
Wireless sensor networks with a large number of cheap low-power interconnected devices bring up challenging tasks when considering the security of their communications. Our paper addresses the issue how cryptographic link keys between communicating sensor nodes can be continuously re-secured even in presence of an attacker who can read the memory of captured nodes. Distributed sensor systems enable us to use two different approaches to link key (re-)establishment - secrecy amplification and key extraction from radio channel fading. A secrecy amplification protocol lets a group of neighboring nodes cooperate together to re-secure previously compromised link keys using the non-compromised paths, and previous research showed the ability of secrecy amplification protocols to improve the security of a network from 50% of compromised link keys to 90% of secure keys. Key extraction then exploits radio channel properties to generate secret bits shared between two radio-enabled devices. We propose to combine secrecy amplification and key extraction into a dynamic protocol, where every node will dynamically decide what approach provides a greater benefit, considering the probability of getting the link key re-secured and the resources available. In principle, the more standard traffic messages are exchanged on a given link, the more beneficiary is the usage of key extractions. And less busy links then rely on secrecy amplification.
Lukas Nemec, Radim Ostádal, Vashek Matyas, Petr Svenda
DCOSS3
2018 Evolving boolean functions for fast and efficient randomness testing
abstract
The security of cryptographic algorithms (such as block ciphers and hash functions) is often evaluated in terms of their output randomness. This paper presents a novel method for the statistical randomness testing of cryptographic primitives, which is based on the evolutionary construction of the so-called randomness distinguisher. Each distinguisher is represented as a Boolean polynomial in the Algebraic Normal Form. The previous approach, in which the distinguishers were developed in two phases by means of the brute-force method, is replaced with a more scalable evolutionary algorithm (EA). On seven complex datasets, this EA provided distinguishers of the same quality as the previous approach, but the execution time was in practice reduced 40 times. This approach allowed us to perform a more efficient search in the space of Boolean distinguishers and to obtain more complex high-quality distinguishers than the previous approach.
Vojtech Mrazek, Marek Sýs, Zdenek Vasícek, Lukás Sekanina, Vashek Matyas
GECCO5
2018 Practical Cryptographic Data Integrity Protection with Full Disk Encryption
Milan Broz, Mikulás Patocka, Vashek Matyas
SEC3
2018 Bringing Kleptography to Real-World TLS
Adam Janovsky, Jan Krhovjak, Vashek Matyas
WISTP3
2018 Experimental large-scale review of attractors for detection of potentially unwanted applications
Vlasta Stavova, Lenka Dedkova, Vashek Matyas, Mike Just, David Smahel, Martin Ukrop
Comput. Secur.3
2018 Investigating results and performance of search and construction algorithms for word-based LFSRs, σ-LFSRs
Susil Kumar Bishoi, Vashek Matyas
Discret. Appl. Math.2
2017 Measuring Popularity of Cryptographic Libraries in Internet-Wide Scans
abstract
We measure the popularity of cryptographic libraries in large datasets of RSA public keys. We do so by improving a recently proposed method based on biases introduced by alternative implementations of prime selection in different cryptographic libraries. We extend the previous work by applying statistical inference to approximate a share of libraries matching an observed distribution of RSA keys in an inspected dataset (e.g., Internet-wide scan of TLS handshakes). The sensitivity of our method is sufficient to detect transient events such as a periodic insertion of keys from a specific library into Certificate Transparency logs and inconsistencies in archived datasets.
Matús Nemec, Dusan Klinec, Petr Svenda, Peter Sekan, Vashek Matyas
ACSAC5
2017 The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA Moduli
abstract
We report on our discovery of an algorithmic flaw in the construction of primes for RSA key generation in a widely-used library of a major manufacturer of cryptographic hardware. The primes generated by the library suffer from a significant loss of entropy. We propose a practical factorization method for various key lengths including 1024 and 2048 bits. Our method requires no additional information except for the value of the public modulus and does not depend on a weak or a faulty random number generator. We devised an extension of Coppersmith's factorization attack utilizing an alternative form of the primes in question. The library in question is found in NIST FIPS 140-2 and CC~EAL~5+ certified devices used for a wide range of real-world applications, including identity cards, passports, Trusted Platform Modules, PGP and tokens for authentication or software signing. As the relevant library code was introduced in 2012 at the latest (and probably earlier), the impacted devices are now widespread. Tens of thousands of such keys were directly identified, many with significant impacts, especially for electronic identity documents, software signing, Trusted Computing and PGP. We estimate the number of affected devices to be in the order of at least tens of millions.
Matús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec, Vashek Matyas
CCS5
2017 Algorithm 970: Optimizing the NIST Statistical Test Suite and the Berlekamp-Massey Algorithm
abstract
The NIST Statistical Test Suite (NIST STS) is one of the most popular tools for the analysis of randomness. This test battery is widely used, but its implementation is quite inefficient. A complete randomness analysis using the NIST STS can take hours on a standard computer when the tested data volume is on the order of GB. We improved the most time-consuming test (Linear Complexity) from the previous most efficient implementation of the NIST STS. We also optimized other tests and achieved an overall speedup of 50.6 × compared with the reference implementation. This means that 20MB of data can be tested within a minute using our new optimized version of the NIST STS. To speed up the Linear Complexity test, we proposed a new version of the Berlekamp-Massey algorithm that computes only the linear complexity of a sequence. This new variant does not construct a linear feedback shift register and is approximately 187 × faster than the original NIST implementation of the Berlekamp-Massey algorithm.
Marek Sýs, Zdenek Ríha, Vashek Matyas
ACM Trans. Math. Softw.3
2016 Attackers in Wireless Sensor Networks Will Be Neither Random Nor Jumping - Secrecy Amplification Case
Radim Ostádal, Petr Svenda, Vashek Matyas
CANS3
2016 The Million-Key Question - Investigating the Origins of RSA Public Keys
Petr Svenda, Matús Nemec, Peter Sekan, Rudolf Kvasnovský, David Formánek, David Komárek, Vashek Matyas
USENIX Security Symposium7
2016 Codes v. People: A Comparative Usability Study of Two Password Recovery Mechanisms
Vlasta Stavova, Vashek Matyas, Mike Just
WISTP2
2015 Service in Denial - Clouds Going with the Winds
Vit Bukac, Vlasta Stavova, Lukas Nemec, Zdenek Ríha, Vashek Matyas
NSS5
2015 On Secrecy Amplification Protocols
Radim Ostádal, Petr Svenda, Vashek Matyas
WISTP3
2014 Improving Intrusion Detection Systems for Wireless Sensor Networks
Andriy Stetsko, Tobiás Smolka, Vashek Matyas, Martin Stehlík
ACNS3
2014 Constructing Empirical Tests of Randomness
abstract
In this paper we introduce a general framework for automatic construction of empirical tests of randomness. Our new framework generalises and improves a previous approach (Svenda et al., 2013) and it also provides a clear statistical interpretation of its results. This new approach was tested on selected stream ciphers from the eSTREAM competition. Results show that our approach can lay foundations to randomness testing and it is comparable to the Statistical Test Suite developed by NIST. Additionally, the proposed approach is able to perform randomness analysis even when presented with sequences shorter by several orders of magnitude than required by the NIST suite. Although the Dieharder battery still provides a slightly better randomness analysis, our framework is able to detect non-randomness for stream ciphers with limited number of rounds (Hermes, Fubuki) where both above-mentioned batteries fail.
Marek Sýs, Petr Svenda, Martin Ukrop, Vashek Matyas
SECRYPT4
2014 Traversing symmetric NAT with predictable port allocation
abstract
Network Address Translators often cause trouble for VoIP and other P2P services since central servers are needed for communication. The presence of such potentially malicious hosts in a communication path is not desired, mainly due to security consequences, poor link quality and increased cost. Several solutions exist for traversing NAT, but a symmetric one is still problematic. We propose algorithms using a single source port for symmetric NAT traversal. Each with different properties and applicability.
Dusan Klinec, Vashek Matyas
SIN2
2014 A Protocol for Intrusion Detection in Location Privacy-Aware Wireless Sensor Networks
Jirí Kur, Vashek Matyas
TrustBus2
2013 Using encryption for authentication: Wireless sensor network case
abstract
In this paper we discuss the possibility of using encryption to provide authenticity and explore various options for using authentication primitives, namely MAC, to provide confidentiality in wireless sensor networks. We briefly discuss the theoretical background and focus more deeply on the performance questions. We have found and implemented a set of both encryption and MAC functions, measured the timings and memory requirements of these on a mainstream wireless sensor node. Our paper also brings a performance analysis of existing cryptographic implementations.
Filip Jurnecka, Vashek Matyas
SECON2
2013 Towards Cryptographic Function Distinguishers with Evolutionary Circuits
Petr Svenda, Martin Ukrop, Vashek Matyas
SECRYPT3
2012 Evolutionary Design of Message Efficient Secrecy Amplification Protocols
Tobiás Smolka, Petr Svenda, Lukás Sekanina, Vashek Matyas
EuroGP4
2012 Two Improvements of Random Key Predistribution for Wireless Sensor Networks
Jirí Kur, Vashek Matyas, Petr Svenda
SecureComm2
2011 Calibrating and Comparing Simulators for Wireless Sensor Networks
abstract
In this paper, we present our findings from the calibration and comparison of selected simulators for wireless sensor networks. This work is motivated by our current research on a framework that optimizes a network-based intrusion detection system for a given application. For this purpose, we need a simulator that supports realistic models for topology, antenna, radio propagation, noise, radio, medium access control and energy consumption - factors that can influence the performance of an intrusion detection system, which is intended to be run on the medium access control layer. In the paper, we consider four open-source simulators - Castalia, MiXiM, TOSSIM and WSNet. We compare these simulators and run a set of experiments on MICAz sensor nodes in the indoor and outdoor environment. Based on the data gathered from the real experiments, we calibrate the radio propagation and noise models of Castalia, MiXiM, TOSSIM and WSNet. Also, we calibrate the energy consumption model of Castalia, MiXiM and WSNet according to the MICAz datasheet. We present the results from the simulations and compare them between each other. Even though the simulators are set in the same way, their results significantly differ from each other. In the paper, we discuss possible reasons of the differences.
Andriy Stetsko, Martin Stehlík, Vashek Matyas
MASS3
2009 User Profiling and Re-identification: Case of University-Wide Network Analysis
Marek Kumpost, Vashek Matyas
TrustBus2
2007 Location Privacy Pricing and Motivation
abstract
This paper examines the results of our European-wide study on the price of location privacy of individuals using mobile phones. There were 1200 active participants from five EU countries in our experiment. We used tools from experimental psychology and economics to assess the value that users attach to their location data. This paper extends the results that are provided in [D. Cvrcek et al., 2006]. Our main focus in this paper was the motivation of the participants to take part in the experiment and further investigation of their bids. This paper presents a more detailed view of the motivation and a correlations between the motivation and the bids.
Vashek Matyas, Marek Kumpost
MDM1