VLDB 2026 Research / reviewers in the wild / expert
Amit Klein 0001
dblp:98/3396
· DBLP profile ↗
14ranked-venue papers
9as first author
5since 2021 · last 2025
0000-0002-8024-8756ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 6 first-author · 5 since 2021Computer networks · 3 · 3 first-authorSystems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network Stack
Inon Kaplan, Ron Even, Amit Klein 0001 |
NDSS | 3 |
| 2025 | DNS FLaRE: A Flush-Reload Attack on DNS Forwarders
Gilad Moav, Yehuda Afek, Anat Bremler-Barr, Amit Klein 0001 |
USENIX Security Symposium | 4 |
| 2023 | Device Tracking via Linux's New TCP Source Port Selection Algorithm
Moshe Kol, Amit Klein 0001, Yossi Gilad |
USENIX Security Symposium | 2 |
| 2022 | Subverting Stateful Firewalls with Protocol States
Amit Klein 0001 |
NDSS | 1 |
| 2021 | Cross Layer Attacks and How to Use Them (for DNS Cache Poisoning, Device Tracking and More)abstractWe analyze the prandom pseudo random number generator (PRNG) in use in the Linux kernel (which is the kernel of the Linux operating system, as well as of Android) and demonstrate that this PRNG is weak. The prandom PRNG is in use by many "consumers" in the Linux kernel. We focused on three consumers at the network level – the UDP source port generation algorithm, the IPv6 flow label generation algorithm and the IPv4 ID generation algorithm. The flawed prandom PRNG is shared by all these consumers, which enables us to mount "cross layer attacks" against the Linux kernel. In these attacks, we infer the internal state of the prandom PRNG from one OSI layer, and use it to either predict the values of the PRNG employed by the other OSI layer, or to correlate it to an internal state of the PRNG inferred from the other protocol.Using this approach we can mount a very efficient DNS cache poisoning attack against Linux. We collect TCP/IPv6 flow label values, or UDP source ports, or TCP/IPv4 IP ID values, reconstruct the internal PRNG state, then predict an outbound DNS query UDP source port, which speeds up the attack by a factor of x3000 to x6000. This attack works remotely, but can also be mounted locally, across Linux users and across containers, and (depending on the stub resolver) can poison the cache with an arbitrary DNS record. Additionally, we can identify and track Linux and Android devices – we collect TCP/IPv6 flow label values and/or UDP source port values and/or TCP/IPv4 ID fields, reconstruct the PRNG internal state and correlate this new state to previously extracted PRNG states to identify the same device. Amit Klein 0001 |
SP | 1 |
| 2020 | Black-box caches fingerprintingabstractWe propose the first methodologies for remotely inferring and fingerprinting the software of DNS caches in the Internet based solely on the exchange of queries/responses with the DNS platform. Our techniques are robust and cannot be altered in transit, e.g., by firewalls, which does not hold for the existing fingerprinting techniques. In particular, the only way to alter the outcome of our fingerprinting methods is by modifying the DNS software itself. Amit Klein 0001, Elias Heftrig, Haya Schulmann, Michael Waidner |
CoNEXT | 1 |
| 2020 | Cryptanalysis of FNV-Based CookiesabstractDNS cookies is a recently standardised proposal of the IETF meant to protect DNS against off-path cache poisoning attacks. In contrast to other defences for DNS, DNS cookies is a lightweight mechanism, is easy to deploy and does not introduce overhead on the DNS servers. In this work we demonstrate off-path attacks allowing to circumvent the DNS cookies mechanism and impersonate legitimate Internet sources, exposing the DNS servers to cache poisoning and amplification reflection DoS attacks. We implement and evaluate the attacks, and provide recommendations for countermeasures. Amit Klein 0001, Haya Schulmann, Michael Waidner |
GLOBECOM | 1 |
| 2020 | Flaw Label: Exploiting IPv6 Flow LabelabstractThe IPv6 protocol was designed with security in mind. One of the changes that IPv6 has introduced over IPv4 is a new 20-bit flow label field in its protocol header.We show that remote servers can use the flow label field in order to assign a unique ID to each device when communicating with machines running Windows 10 (versions 1703 and higher), and Linux and Android (kernel versions 4.3 and higher). The servers are then able to associate the respective device IDs with subsequent transmissions sent from those machines. This identification is done by exploiting the flow label field generation logic and works across all browsers regardless of network changes. Furthermore, a variant of this attack also works passively, namely without actively triggering traffic from those machines.To design the attack we reverse-engineered and cryptanalyzed the Windows flow label generation code and inspected the Linux kernel flow label generation code. We provide a practical technique to partially extract the key used by each of these algorithms, and observe that this key can identify individual devices across networks, VPNs, browsers and privacy settings. We deployed a demo (for both Windows and Linux/Android) showing that key extraction and machine fingerprinting works in the wild, and tested it from networks around the world. Jonathan Berger, Amit Klein 0001, Benny Pinkas |
SP | 2 |
| 2019 | DNS Cache-Based User Tracking
Amit Klein 0001, Benny Pinkas |
NDSS | 1 |
| 2019 | From IP ID to Device ID and KASLR Bypass
Amit Klein 0001, Benny Pinkas |
USENIX Security Symposium | 1 |
| 2018 | Domain Validation++ For MitM-Resilient PKIabstractThe security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a weak off-path attacker can effectively subvert the trustworthiness of popular commercially used CAs. Our attack targets CAs which use Domain Validation (DV) for authenticating domain ownership; collectively these CAs control 99% of the certificates market. The attack utilises DNS Cache poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. We discuss short and long term defences, but argue that they fall short of securing DV. To mitigate the threats we propose Domain Validation++ (DV++). DV++ replaces the need in cryptography through assumptions in distributed systems. While retaining the benefits of DV (automation, efficiency and low costs) DV++ is secure even against Man-in-the-Middle (MitM) attackers. Deployment of DV++ is simple and does not require changing the existing infrastructure nor systems of the CAs. We demonstrate security of DV++ under realistic assumptions and provide open source access to DV++ implementation. Markus Brandt, Tianxiang Dai, Amit Klein 0001, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2017 | POSTER: X-Ray Your DNSabstractWe design and develop DNS X-Ray which performs analyses of DNS platforms on the networks where it is invoked. The analysis identifies the caches and the IP addresses used by the DNS platform, fingerprints the DNS software on the caches, and evaluates vulnerabilities allowing injection of spoofed records into the caches. DNS X-Ray is the first tool to perform an extensive analysis of the caching component on the DNS platforms. In addition, DNS X-Ray also provides statistics from previous invocations, enabling networks to check which for popular DNS software on the caches, the number of caches typically used on DNS platforms and more. We set up DNS X-Ray online, it can be accessed via a website http://www.dns.xray.sit.fraunhofer.de. Amit Klein 0001, Vladimir Kravtsov, Alon Perlmuter, Haya Schulmann, Michael Waidner |
CCS | 1 |
| 2017 | Counting in the Dark: DNS Caches Discovery and Enumeration in the InternetabstractDomain Name System (DNS) is a fundamental element of the Internet providing lookup services for end users as well as for a multitude of applications, systems and security mechanisms that depend on DNS, such as antispam defences, routing security, firewalls, certificates and more. Caches constitute a critical component of DNS, allowing to improve efficiency and reduce latency and traffic in the Internet. Understanding the behaviour, configurations and topologies of caches in the DNS platforms in the Internet is important for efficiency and security of Internet users and services. In this work we present methodologies for efficiently discovering and enumerating the caches of the DNS resolution platforms in the Internet. We apply our techniques and methodologies for studying caches in popular DNS resolution platforms in the Internet. Our study includes networks of major ISPs, enterprises and professionally managed open DNS resolvers. The results of our Internet measurements shed light on architectures and configurations of the caches in DNS resolution platforms. Amit Klein 0001, Haya Schulmann, Michael Waidner |
DSN | 1 |
| 2017 | Internet-wide study of DNS cache injectionsabstractDNS caches are an extremely important tool, providing services for DNS as well as for a multitude of applications, systems and security mechanisms, such as anti-spam defences, routing security (e.g., RPKI), firewalls. Subverting the security of DNS is detrimental to the stability and security of the clients and services, and can facilitate attacks, circumventing even cryptographic mechanisms. We study the caching component of DNS resolution platforms in diverse networks in the Internet, and evaluate injection vulnerabilities allowing cache poisoning attacks. Our evaluation includes networks of leading Internet Service Providers and enterprises, and professionally managed open DNS resolvers. We test injection vulnerabilities against known payloads as well as a new class of indirect attacks that we define in this work. Our Internet evaluation indicates that more than 92% of the Internet's DNS resolution platforms are vulnerable to records injection and can be persistently poisoned. Amit Klein 0001, Haya Schulmann, Michael Waidner |
INFOCOM | 1 |