Matt Bishop

dblp:b/MattBishop · DBLP profile ↗
← Back
74ranked-venue papers
28as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 49 · 21 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 11 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 7 · 4 first-authorComputer networks · 3 · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS)
abstract
This paper presents and advocates for an initiative to expand access to secure programming education. The Strengthening Workforce Education: Excellence in Programming Securely (SWEEPS) initiative, funded by the National Centers of Academic Excellence in Cybersecurity (NCAE-C) program, seeks to advance secure programming and help achieve security aims. SWEEPS establishes a secure programming curriculum and workforce development coalition of seven institutions across two CAE (Center of Academic Excellence) regions (Northeast and Southwest) and five states (California, Massachusetts, Maryland, Indiana, and North Carolina). This coalition includes industry-based stakeholders collaborating with the US Army and government agencies on various projects. SWEEPS draws on prior work establishing critical concepts in secure programming, assessment tools, learning aids, and system infrastructure. The initiative offers a series of interconnected, stackable learning experiences tailored for early to mid-career professionals looking to enhance their cybersecurity skills. These experiences, which include practical one-day workshops and comprehensive year-long graduate certificates, provide a reassuring path for upskilling in secure programming. This paper recommends the efficacy of stackable training approaches in secure programming by exploring the practices of targeting and training individuals with diverse proficiency levels of programming experience who would benefit from increased knowledge and training.
Deborah Kariuki, Ida Ngambeki, Jun Dai 0001, Matt Bishop, Xiaoyan Sun 0003, Melissa Dark, Jenny Daugherty, Alex Lowrie, Markus Geissler, Phillip Nico, Arshad Noor
SIGCSE (1)4
2025 Case Study 2: Mapping between an E-Voting Curriculum and the DHS/NSA CAE Knowledge Units
abstract
To become a DHS/NSA Center of Academic Excellence in Cyber Defense (CAE-CD), academic institutions must satisfy several specific Knowledge Units (KUs). How they achieve this is up to the institutions. In this case study, we follow the methodology of an earlier work to demonstrate how key parts of an electronic voting (E-voting)-oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, maps into the DHS/NSA KUs supporting the CAE-CD designation, from two aspects: E-voting principle based topics, i.e., from theory and a plug-and-play e-voting system's composing components, i.e., from practice. We grouped CAE-CD KUs into those required as prerequisites, closely related, related/supported, and not covered by the E-voting curriculum. Teachers can then choose which KUs they will use and teach using only the parts of the E-voting-oriented curriculum they deem relevant, and in a depth they find appropriate to their educational objectives, while meeting the requirements of the selected KUs. We conclude with a discussion of how LLMs (Large Language Models) and quantum computing might be added to the E-voting-oriented curriculum.
Edwin Antonio Sanchez, Muwei Zheng, Matt Bishop, Xukai Zou
SIGCSE (1)3
2023 Validation of a Secure Programming Concept Inventory
abstract
Security failures in software arising from failures to practice secure programming are commonplace. Improving this situation requires that practitioners have a clear understanding of the foundational concepts in secure programming to serve as a basis for building new knowledge and responding to new challenges. We developed a Secure Programing Concept Inventory (SPCI) to measure students' understanding of foundational concepts in secure programming. The SPCI consists of thirty-five multiple choice items targeting ten concept areas of secure programming. The SPCI was developed by establishing the content domain of secure programming, developing a pool of test items, multiple rounds of testing and refining the items, and finally testing and inventory reduction to produce the final scale.
Ida Ngambeki, Matt Bishop, Jun Dai 0001, Phillip Nico
SIGCSE (2)2
2023 Case Study: Mapping an E-Voting Based Curriculum to CSEC2017
abstract
An electronic voting (E-voting) oriented cybersecurity curriculum, proposed by Hostler et al. [4] in 2021, leverages the rich security features of E-voting systems and E-voting process to teach essential concepts of cybersecurity. Existing curricular guidelines describe topics in computer security, but do not instantiate them with examples. This is because their goals are different. In this case study, we map the e-voting curriculum into the CSEC2017 curriculum guidelines, to demonstrate how such a mapping is done. Further, this enables teachers to select the parts of the e-voting curriculum most relevant to their classes, by basing the selection on the relevant CSEC2017 learning objectives. We conclude with a brief discussion on generalizing this mapping to other curricular guidelines.
Muwei Zheng, Nathan Swearingen, Steven Mills, Croix Gyurek, Matt Bishop, Xukai Zou
SIGCSE (1)5
2022 Autonomous Vehicle Security: Composing Attack, Defense, and Policy Surfaces
abstract
An attack surface enumerates resources accessible to an attacker for cyber attacks on a system. These resources are: methods that can be called as part of an attack; channels that an attacker outside the system can use to get to a system’s interface; and untrusted data that an attacker can use in conjunction with the system’s programs and channels. Historically, a system’s attacks surface has provided a metric on the vulnerability of a system, in part to compare two systems’ exposure to attack.
Michael Clifford, Miriam Heller, Karl N. Levitt, Matt Bishop
NSPW4
2022 A Praise for Defensive Programming: Leveraging Uncertainty for Effective Malware Mitigation
abstract
A promising avenue for improving the effectiveness of behavioral-based malware detectors is to leverage two-phase detection mechanisms. Existing problem in two-phase detection is that after the first phase produces borderline decision, suspicious behaviors are not well contained before the second phase completes. This article improvesChameleon, a framework to realize the uncertain environment.Chameleonoffers two environments: standard—for software identified as benign by the first phase, and uncertain—for software received borderline classification from the first phase. The uncertain environment adds obstacles to software execution through random perturbations applied probabilistically. We introduce a dynamic perturbation threshold that can target malware disproportionately more than benign software. We analyzed the effects of the uncertain environment by manually studying 113 software and 100 malware, and found that 92 percent malware and 10 percent benign software disrupted during execution. The results were then corroborated by an extended dataset (5,679 Linux malware samples) on a newer system. Finally, a careful inspection of the benign software crashes revealed some software bugs, highlightingChameleon's potential as a practical complementary anti-malware solution.
Ruimin Sun, Marcus Botacin, Nikolaos Sapountzis, Xiaoyong Yuan, Matt Bishop, Donald E. Porter, Xiaolin Li 0001, André Ricardo Abed Grégio, Daniela Oliveira 0001
IEEE Trans. Dependable Secur. Comput.5
2021 A New Method for Flow-Based Network Intrusion Detection Using the Inverse Potts Model
abstract
Network Intrusion Detection Systems (NIDS) play an important role as tools for identifying potential network threats. In the context of ever-increasing traffic volume on computer networks, flow-based NIDS arise as good solutions for real-time traffic classification. In recent years, different flow-based classifiers have been proposed using Machine Learning (ML) algorithms. Nevertheless, classical ML-based classifiers have some limitations. For instance, they require large amounts of labeled data for training, which might be difficult to obtain. Additionally, most ML-based classifiers are not capable of domain adaptation, i.e., after being trained on an specific data distribution, they are not general enough to be applied to other related data distributions. And, finally, many of the models inferred by these algorithms are black boxes, which do not provide explainable results. To overcome these limitations, we propose a new algorithm, called Energy-based Flow Classifier (EFC). This anomaly-based classifier uses inverse statistics to infer a statistical model based on labeled benign examples. We show that EFC is capable of accurately performing binary flow classification and is more adaptable to different data distributions than classical ML-based classifiers. Given the positive results obtained on three different datasets (CIDDS-001, CICIDS17 and CICDDoS19), we consider EFC to be a promising algorithm to perform robust flow-based traffic classification.
Camila F. T. Pontes, Manuela M. C. de Souza, João J. C. Gondim, Matt Bishop, Marcelo Antonio Marotta
IEEE Trans. Netw. Serv. Manag.4
2020 Trust-Based Security; Or, Trust Considered Harmful
abstract
Our review of common, popular risk analysis frameworks finds that they are very homogenous in their approach. These are considered IT Security Industry ”best practices.” However, one wonders if they are indeed ”best”, as evinced by the almost daily news of large companies suffering major compromises.
Abe Singer, Matt Bishop
NSPW2
2020 Education for the Multifaith Community of Cybersecurity
Steven Furnell, Matt Bishop
WISE2
2018 Concept Inventories in Cybersecurity Education: An Example from Secure Programming
abstract
This Innovative Practice Work in Progress paper makes the case for using concept inventories in cybersecurity education and presents an example of the development of a concept inventory in the field of secure programming. The secure programming concept inventory is being developed by a team of researchers from four universities. We used a Delphi study to define the content area to be covered by the concept inventory. Participants in the Delphi study included ten experts from academia, government, and industry. Based on the results, we constructed a concept map of secure programming concepts. We then compared this concept map to the Joint Task Force on Cybersecurity Education Curriculum 2017 guidelines to ensure complete coverage of secure programming concepts. Our mapping indicates a substantial match between the concept map and those guidelines.
Ida Ngambeki, Phillip Nico, Jun Dai 0001, Matt Bishop
FIE4
2018 Augmenting Machine Learning with Argumentation
abstract
The information security community is haunted by the failure of an appropriate break-the-glass access control at the United States Center for Disease Control that led to an estimated additional 1.2 million deaths in North America in 2036. In this paper we review what caused the security failures in this system and argue that, by combining human intelligence with multiple technological approaches to create a system that emphasizes human approaches to guide analysis, the failures that occurred will not recur. We also leverage people and technologies to identify and fill gaps in the training data to minimize the threat of unexpected events. While we use this scenario as our running example, we note that our approach is generalizable to a broader problem space where machine learning approaches have been deployed to make decisions.
Matt Bishop, Carrie Gates, Karl N. Levitt
NSPW1
2018 Special Session: Joint Task Force on Cybersecurity Education
abstract
In this special session, members of the Joint Task Force (JTF) on Cybersecurity Education will provide an overview of the CSEC2017 curricular guidelines (finalized in December 2017) and engage session participants in a discussion of the curricular framework and body of knowledge. The session will conclude with an interactive panel discussion on implementing the curricular guidance.
Diana L. Burley, Matt Bishop, Siddharth Kaza, David S. Gibson, Scott Buck, Allen S. Parrish, Herbert J. Mattord
SIGCSE2
2018 Internet- and cloud-of-things cybersecurity research challenges and advances
Kim-Kwang Raymond Choo, Matt Bishop, William Glisson, Kara L. Nance
Comput. Secur.2
2017 LeakSemantic: Identifying abnormal sensitive network transmissions in mobile applications
abstract
Mobile applications (apps) often transmit sensitive data through network with various intentions. Some transmissions are needed to fulfill the app's functionalities. However, transmissions with malicious receivers may lead to privacy leakage and tend to behave stealthily to evade detection. The problem is twofold: how does one unveil sensitive transmissions in mobile apps, and given a sensitive transmission, how does one determine if it is legitimate? In this paper, we propose LeakSemantic, a framework that can automatically locate abnormal sensitive network transmissions from mobile apps. LeakSemantic consists of a hybrid program analysis component and a machine learning component. Our program analysis component combines static analysis and dynamic analysis to precisely identify sensitive transmissions. Compared to existing taint analysis approaches, LeakSemantic achieves better accuracy with fewer false positives and is able to collect runtime data such as network traffic for each transmission. Based on features derived from the runtime data, machine learning classifiers are built to further differentiate between the legal and illegal disclosures. Experiments show that LeakSemantic achieves 91% accuracy on 2279 sensitive connections from 1404 apps.
Hao Fu 0003, Zizhan Zheng, Somdutta Bose, Matt Bishop, Prasant Mohapatra
INFOCOM4
2017 A Model of Owner Controlled, Full-Provenance, Non-Persistent, High-Availability Information Sharing
abstract
In this paper, we propose principles of information control and sharing that support ORCON (ORiginator COntrolled access control) models while simultaneously improving components of confidentiality, availability, and integrity needed to inherently support, when needed, responsibility to share policies, rapid information dissemination, data provenance, and data redaction. This new paradigm of providing unfettered and unimpeded access to information by authorized users, while at the same time, making access by unauthorized users impossible, contrasts with historical approaches to information sharing that have focused on need to know rather than need to (or responsibility to) share.
Sean Peisert, Matt Bishop, Edward B. Talbot
NSPW2
2017 ACM Joint Task Force on Cybersecurity Education
abstract
In this special session, members of the ACM Joint Task Force (JTF) on Cybersecurity Education will provide an overview of the task force mission, objectives, and release a draft of the curricular guidelines. After the overview, task force members will engage session participants in the curricular development process and solicit feedback on the draft guidelines.
Diana L. Burley, Matt Bishop, Siddharth Kaza, David S. Gibson, Elizabeth K. Hawthorne, Scott Buck
SIGCSE2
2017 Iterative Analysis to Improve Key Properties of Critical Human-Intensive Processes: An Election Security Example
abstract
In this article, we present an approach for systematically improving complex processes, especially those involving human agents, hardware devices, and software systems. We illustrate the utility of this approach by applying it to part of an election process and show how it can improve the security and correctness of that subprocess. We use the Little-JIL process definition language to create a precise and detailed definition of the process. Given this process definition, we use two forms of automated analysis to explore whether specified key properties, such as security and safety policies, can be undermined. First, we use model checking to identify process execution sequences that fail to conform to event-sequence properties. After these are addressed, we apply fault tree analysis to identify when the misperformance of steps might allow undesirable outcomes, such as security breaches. The results of these analyses can provide assurance about the process; suggest areas for improvement; and, when applied to a modified process definition, evaluate proposed changes.
Leon J. Osterweil, Matt Bishop, Heather M. Conboy, Huong Phan, Borislava I. Simidchieva, George S. Avrunin, Lori A. Clarke, Sean Peisert
ACM Trans. Priv. Secur.2
2016 Bear: A Framework for Understanding Application Sensitivity to OS (Mis) Behavior
abstract
Applications are generally written assuming a predictable and well-behaved OS. In practice, they experience unpredictable misbehavior at the OS level and across OSes: different OSes can handle network events differently, APIs can behave differently across OSes, and OSes may be compromised or buggy. This unpredictability is challenging because its sources typically manifest during deployment and are hard to reproduce. This paper introduces Bear, a framework for statistical analysis of application sensitivity to OS unpredictability that can help developers build more resilient software, discover challenging bugs and identify the scenarios that most need validation. Bear analyzes a program with a set of perturbation strategies on a set of commonly used system calls in order to discover the most sensitive system calls for each application, the most impactful strategies, and how they predict abnormal program outcome. We evaluated Bear with 113 CPU and IO-bound programs, and our results show that null memory dereferencing and erroneous buffer operations are the most impactful strategies for predicting abnormal program execution and that their impacts increase ten-fold with workload increase (e.g. number of network requests from 10 to 1000). Generic system calls are more sensitive than specialized system calls-for example, write and sendto can both be used to send data through a socket, but the sensitivity of write is twice that of sendto. System calls with an array parameter (e.g. read) are more sensitive to perturbations than those having a struct parameter with a buffer (e.g readv). Moreover, the fewer parameters a system call has, the more sensitive it is.
Ruimin Sun, Aokun Chen, Donald E. Porter, Matt Bishop, Daniela Oliveira 0001
ISSRE5
2016 I'm not sure if we're okay: uncertainty for attackers and defenders
abstract
Asymmetry and uncertainty have been written about at length in the context of computer security. Indeed, many cutting edge defensive techniques provide system protection by relying on attacker uncertainty about certain aspects of the system. However, with these defensive countermeasures, typically the defender has the ability to derive full knowledge of the system (as is the case in, for example, Instruction Set Randomization), but the attacker has limited knowledge.
Mark E. Fioravanti II, Matt Bishop, Richard Ford
NSPW2
2016 Special Session: ACM Joint Task Force on Cyber Education
abstract
In this special session, members of the ACM Joint Task Force on Cyber Education to Develop Undergraduate Curricular Guidance will provide an overview of the task force mission, objectives, and work plan. After the overview, task force members will engage session participants in the curricular development process.
Diana L. Burley, Matt Bishop, Elizabeth K. Hawthorne, Siddharth Kaza, Scott Buck, Lynn Futcher
SIGCSE2
2015 The Case for Less Predictable Operating System Behavior
Ruimin Sun, Donald E. Porter, Daniela Oliveira 0001, Matt Bishop
HotOS4
2013 Information behaving badly
abstract
Traditionally, insider threat detection has focused on observing human actors -- or, more precisely, computer accounts and processes acting on behalf of those actors -- to model their "normal" behavior, then determine if they have performed some anomalous action and, further, if that action is malicious. In this paper, we shift the paradigm from observing human behavior to observing information behavior by modeling how documents flow through an organization. We hypothesize that similar types of documents will exhibit similar workflows, and that a document deviating from its expected workflow indicates potential data leakage.
Julie Boxwell Ard, Matt Bishop, Carrie Gates, Michael Xin Sun
NSPW2
2013 Forgive and forget: return to obscurity
abstract
Traditionally, if someone did some act that required forgiveness, there were social norms in place for such forgiveness to happen. Over time, the act is also typically forgotten. And, should the person not be forgiven and the social pressure become too great, he had the option of moving to a new location for a fresh start. Yet with the Internet, these options are no longer available. Worse, activities which traditionally did not even require forgiveness are now impacting lives in unexpected ways, and are never forgotten. There are, however, technical approaches that could be applied to the problem, such as (1) controlling dissemination through new access control models or cryptographic approaches, (2) flooding the web with contrary information, (3) leading users to believe the information applies to someone else, (4) changing the semantics of what was written, and (5) finding a way to take advantage of the inconvenient information. In this paper we discuss the social act of forgiveness, and go into detail on the possible technical approaches to "forgetting" without deleting.
Matt Bishop, Emily Rine Butler, Kevin R. B. Butler, Carrie Gates, Steven Greenspan
NSPW1
2013 Introducing secure coding in CS0 and CS1 (abstract only)
abstract
The CS 2013 curriculum draft includes Information Assurance and Security as a pervasive knowledge area. However, introducing security in CS0 and CS1 is challenging because of lack of appropriate teaching resources and training. This workshop will provide a well-tested strategy for introducing secure coding concepts in CS0 and CS1. We will introduce attendees to secure coding through hands-on exercises, and provide self-contained, lab-based modules designed to be injected into CS0/CS1 with minimal impact on the course (www.towson.edu/securityinjections). Participants will be encouraged to bring in their own syllabus and labs to modify to include secure coding concepts. The first 15 participants will be reimbursed for the workshop cost on attendance. Laptop recommended.
Matt Bishop, Blair Taylor, Elizabeth K. Hawthorne, Diana L. Burley, Siddharth Kaza
SIGCSE1
2013 Teaching secure coding: the myths and the realities
abstract
Teaching secure coding has never been more important. The CS2013 Ironman draft includes Information Assurance and Security as a new Knowledge Area and recommends that security be cross-cutting across all undergraduate computer science curricula. The Summit on Education in Secure Software recommended: 1) increasing the number of faculty who understand the importance of secure programming principles, and will require students to practice them; 2) integrating computer security content into existing technical and non-technical courses; and 3) using innovative teaching methods to strengthen the foundation of computer security knowledge. In this panel, we will speak to these recommendations and the new curricular guidelines and discuss the importance and challenges of teaching secure coding.
Blair Taylor, Matt Bishop, Elizabeth K. Hawthorne, Kara L. Nance
SIGCSE2
2013 Multiclass classification of distributed memory parallel computations
Sean Whalen, Sean Peisert, Matt Bishop
Pattern Recognit. Lett.3
2012 Turtles all the way down: a clean-slate, ground-up, first-principles approach to secure systems
abstract
In this paper, we present a set of security requirements for critical systems, fundamental premises that those requirements would entail, and ideas for implementations that would instantiate those premises. We discuss the overriding requirement guiding our paradigm: that "first principles" reflects the only real security strategy, where first principles are ideally provable, often measurable; and at minimum, possible to order and bound. These principles allow us to take into account that many security policies may be even be in conflict, and as such, proofs, measures, and ordering gives an analyst (or even better, an automated system) the metrics that one needs in order to make informed decisions about how to resolve conflicts. We demonstrate several metrics that enable this, including state replication, data slicing, collusion, and information theory.
Sean Peisert, Edward B. Talbot, Matt Bishop
NSPW3
2012 Teaching secure coding: report from summit on education in secure software
abstract
Software is critical to life in the 21st century. It drives financial, medical, and government computer systems as well as systems that provide critical infrastructures in areas such as transportation, energy, networking, and telecommunications. As the number and severity of attacks that exploit software vulnerabilities increase, writing reliable, robust, and secure programs will substantially improve the ability of systems and infrastructure to resist such attacks. Education plays a critical role in addressing cybersecurity challenges of the future, such as designing curricula that integrate principles and practices of secure programming into educational programs. To help guide this process, the National Science Foundation Directorates of Computer and Information Science and Engineering (CISE) and Education and Human Resources (EHR) jointly sponsored the Summit on Education in Secure Software (SESS), held in Washington, DC in October, 2010. The goal of this session is to share some of the key findings and challenges identified by the summit and to actively engage the community in the discussions. Each of the speakers participated in the summit and brings a unique viewpoint to the session.
Blair Taylor, Matt Bishop, Diana L. Burley, Steve Cooper, Ronald C. Dodge, Robert C. Seacord
SIGCSE2
2012 A Taxonomy of Buffer Overflow Characteristics
abstract
Significant work on vulnerabilities focuses on buffer overflows, in which data exceeding the bounds of an array is loaded into the array. The loading continues past the array boundary, causing variables and state information located adjacent to the array to change. As the process is not programmed to check for these additional changes, the process acts incorrectly. The incorrect action often places the system in a nonsecure state. This work develops a taxonomy of buffer overflow vulnerabilities based upon characteristics, or preconditions that must hold for an exploitable buffer overflow to exist. We analyze several software and hardware countermeasures to validate the approach. We then discuss alternate approaches to ameliorating this vulnerability.
Matt Bishop, Sophie Engle, Damien Howard, Sean Whalen
IEEE Trans. Dependable Secur. Comput.1
2011 Resilience is more than availability
abstract
In applied sciences there is a tendency to rely on terminology that is either ill-defined or applied inconsistently across areas of research and application domains. Examples in information assurance include the terms resilience, robustness and survivability, where there exists subtle shades of meaning between researchers. These nuances can result in confusion and misinterpretations of goals and results, hampering communication and complicating collaboration. In this paper, we propose security-related definitions for these terms. Using this terminology, we argue that research in these areas must consider the functionality of the system holistically, beginning with a careful examination of what we actually want the system to do. We note that much of the published research focuses on a single aspect of a system -- availability -- as opposed to the system's ability to complete its function without disclosing confidential information or, to a lesser extent, with the correct output. Finally, we discuss ways in which researchers can explore resilience with respect to integrity, availability and confidentiality.
Matt Bishop, Marco M. Carvalho, Richard Ford, Liam M. Mayron
NSPW1
2010 Relationships and data sanitization: a study in scarlet
abstract
Research in data sanitization (including anonymization) emphasizes ways to prevent an adversary from desanitizing data. Most work focuses on using mathematical mappings to sanitize data. A few papers examine incorporation of privacy requirements, either in the guise of templates or prioritization. Essentially these approaches reduce the information that can be gleaned from a data set. In contrast, this paper considers both the need to ``desanitize'' and the need to support privacy. We consider conflicts between privacy requirements and the needs of analysts examining the redacted data. Our goal is to enable an informed decision about the effects of redacting, and failing to redact data. We begin with relationships among the data being examined, including relationships with a known data set and other, additional, external data. By capturing these relationships, desanitization techniques that exploit them can be identified, and the information that must be concealed in order to thwart them can be determined. Knowing that, a realistic assessment of whether the information and relationships are already widely known or available will enable the sanitizers to assess whether irreversible sanitization is possible, and if so, what to conceal to prevent desanitization.
Matt Bishop, Justin Cummins, Sean Peisert, Anhad Singh, Bhume Bhumiratana, Deborah A. Agarwal, Deborah A. Frincke, Michael A. Hogarth
NSPW1
2010 Hidden Markov Models for Automated Protocol Learning
Sean Whalen, Matt Bishop, James P. Crutchfield
SecureComm2
2010 Reflections on the 30th Anniversary of the IEEE Symposium on Security and Privacy
Peter G. Neumann, Matt Bishop, Sean Peisert, Marvin Schaefer
IEEE Symposium on Security and Privacy2
2009 Investigating the Implications of Virtual Machine Introspection for Digital Forensics
abstract
Researchers and practitioners in computer forensics currently must base their analysis on information that is either incomplete or produced by tools that may themselves be compromised as a result of the intrusion. Complicating these issues are the techniques employed by the investigators themselves. If the system is quiescent when examined, most of the information in memory has been lost. If the system is active, the kernel and programs used by the forensic investigators are likely to influence the results and as such are themselves suspect. Using virtual machines and a technique called virtual machine introspection can help overcome these limits, but it introduces its own research challenges. Recent developments in virtual machine introspection have led to the identification of four initial priority research areas in virtual machine introspection including virtual machine introspection tool development, applications of virtual machine introspection to non-quiescent virtual machines, virtual machine introspection covert operations, and virtual machine introspection detection.
Kara L. Nance, Brian Hay, Matt Bishop
ARES3
2009 Reflections on UNIX Vulnerabilities
abstract
The UNIX operating system was developed in a friendly, collaborative environment without any particular predefined objectives. As it entered less friendly environments, expanded its functionality, and became the basis for commercial, infrastructure, and home systems, vulnerabilities in the system affected its robustness and security. This paper presents a brief history of UNIX vulnerabilities, beginning with a report written in 1981-1983, but never published. It examines how the nature of vulnerabilities has (and has not) changed since then, and presents some thoughts on the future of vulnerabilities in the UNIX operating system and its variants and other UNIX-like systems.
Matt Bishop
ACSAC1
2009 The sisterhood of the traveling packets
abstract
From a cyber-security perspective, attribution is considered to be the ability to determine the originating location for an attack. However, should such an attribution system be developed and deployed, it would provide attribution for all traffic, not just attack traffic. This has several implications for both the senders and receivers of traffic, as well as the intervening organizations, Internet service providers and nation-states. In this paper we examine the requirements for an attribution system, identifying all of the actors, their potential interests, and the resulting policies they might therefore have. We provide a general framework that represents the attribution problem, and outline the technical and policy requirements for a solution. We discuss the inevitable policy conflicts due to the social, legal and cultural issues that would surround such a system. Categories and Subject Descriptors K.4.1 [Computers and Society]: Public Policy Issues – abuse and crime involving computers, ethics, privacy, regulation,
Matt Bishop, Carrie Gates, Jeffrey Hunker
NSPW1
2009 Quis Custodiet ipsos Custodes?: a new paradigm for analyzing security paradigms with appreciation to the Roman poet Juvenal
abstract
Do you believe that more than one single security paradigm exists? We do.
Sean Peisert, Matt Bishop, Laura Corriss, Steven J. Greenwald
NSPW2
2008 We have met the enemy and he is us
abstract
The insider threat has long been considered one of the most serious threats in computer security, and one of the most difficult to combat. But the problem has never been defined precisely, and that lack of precise definition inhibits solutions. This paper presents a precise definition of insider threat, and shows how the definition enables an analysis of the set of problems traditionally lumped into \the insider threat". It introduces a hierarchy of policy abstractions, and argues that the discrepancies between the different layers of abstraction expose the potential for insider threat. It also presents a methodology for analyzing the threat based upon our definitions. In the process, we introduce Attribute-Based Group Access Control, a generalization of the Role-Based Access Control model that allows any attributes to define a group. We apply this to the insider threat by defining groups based on access capabilities, and using that to identify users with a high level of threat with respect to high-risk resources.
Matt Bishop, Sophie Engle, Sean Peisert, Sean Whalen, Carrie Gates
NSPW1
2007 Cost-Sensitive Intrusion Responses for Mobile Ad Hoc Networks
Shiau-Huey Wang, Chinyang Henry Tseng, Karl N. Levitt, Matt Bishop
RAID4
2007 Analysis of Computer Intrusions Using Sequences of Function Calls
abstract
This paper demonstrates the value of analyzing sequences of function calls for forensic analysis. Although this approach has been used for intrusion detection (that is, determining that a system has been attacked), its value in isolating the cause and effects of the attack has not previously been shown. We also look for not only the presence of unexpected events but also the absence of expected events. We tested these techniques using reconstructed exploits in su, ssh, and lpr, as well as proof-of-concept code, and, in all cases, were able to detect the anomaly and the nature of the vulnerability.
Sean Peisert, Matt Bishop, Sidney Karin, Keith Marzullo
IEEE Trans. Dependable Secur. Comput.2
2007 Modeling network intrusion detection alerts for correlation
abstract
Signature-based network intrusion-detection systems (NIDSs) often report a massive number of simple alerts of low-level security-related events. Many of these alerts are logically involved in a single multi-stage intrusion incident and a security officer often wants to analyze the complete incident instead of each individual simple alert. This paper proposes a well-structured model that abstracts the logical relation between the alerts in order to support automatic correlation of those alerts involved in the same intrusion. The basic building block of the model is a logical formula called a capability . We use capability to abstract consistently and precisely all levels of accesses obtained by the attacker in each step of a multistage intrusion. We then derive inference rules to define logical relations between different capabilities. Based on the model and the inference rules, we have developed several novel alert correlation algorithms and implemented a prototype alert correlator. The experimental results of the correlator using several intrusion datasets demonstrate that the approach is effective in both alert fusion and alert correlation and has the ability to correlate alerts of complex multistage intrusions. In several instances, the alert correlator successfully correlated more than two thousand Snort alerts involved in massive scanning incidents. It also helped us find two multistage intrusions that were missed in auditing by the security officers.
Jingmin Zhou, Mark R. Heckman, Brennen Reynolds, Adam Carlson, Matt Bishop
ACM Trans. Inf. Syst. Secur.5
2006 Using Type Qualifiers to Analyze Untrusted Integers and Detecting Security Flaws in C Programs
Ebrima N. Ceesay, Jingmin Zhou, Michael Gertz 0001, Karl N. Levitt, Matt Bishop
DIMVA5
2006 Sanitization models and their limitations
Rick Crawford, Matt Bishop, Bhume Bhumiratana, Lisa Clark, Karl N. Levitt
NSPW2
2006 Inconsistency in deception for defense
Vicentiu Neagoe, Matt Bishop
NSPW2
2006 Teaching context in information security
abstract
This article investigates teaching the application of technical ideas by non-technical means, especially by using puzzles to engage students. After discussing the need to teach students to evaluate contexts in which decisions about computer security must be made, we suggest questions and scenarios drawn from political science, history, as well as other humanities, to force students to apply or derive principles of computer security in unusual and unexpected situations. Our experience shows that students find the process enjoyable, stimulating, and effective.
Matt Bishop
ACM J. Educ. Resour. Comput.1
2005 Verify Results of Network Intrusion Alerts Using Lightweight Protocol Analysis
abstract
We propose a method to verify the result of attacks detected by signature-based network intrusion detection systems using lightweight protocol analysis. The observation is that network protocols often have short meaningful status codes saved at the beginning of server responses upon client requests. A successful intrusion that alters the behavior of a network application server often results in an unexpected server response, which does not contain the valid protocol status code. This can be used to verify the result of the intrusion attempt. We then extend this method to verify the result of attacks that still generate valid protocol status code in the server responses. We evaluate this approach by augmenting Snort signatures and testing on real world data. We show that some simple changes to Snort signatures can effectively verify the result of attacks against the application servers, thus significantly improve the quality of alerts
Jingmin Zhou, Adam J. Carlson, Matt Bishop
ACSAC3
2005 The insider problem revisited
abstract
The "insider problem" is considered the most difficult and critical problem in computer security. But studies that survey the seriousness of the problem, and research that analyzes the problem, rarely define the problem precisely. Implicit definitions vary in meaning. Different definitions imply different countermeasures, as well as different assumptions.
Matt Bishop
NSPW1
2005 Position: "insider" is relative
abstract
A security policy defines "security" for a given site or set of sites. Most security policies provide for trusted users to whom the policy either does not apply or to whom some parts of the policy do not apply. For example, in a traditional Bell-LaPadula model with strong tranquility, labels of entities do not change. In practise, this is too restrictive, so a trusted user (the site security officer) is allowed to set and change labels. Indeed, in their demonstration that Multics satisfies the model [1], Bell and LaPadula explicitly defined trusted users as subjects against whom the *-property is not enforced. The users are trusted not to violate that property.
Matt Bishop
NSPW1
2005 Principles-driven forensic analysis
abstract
It is possible to enhance our understanding of what has happened on a computer system by using forensic techniques that do not require prediction of the nature of the attack, the skill of the attacker, or the details of the system resources or objects affected. These techniques address five fundamental principles of computer forensics. These principles include recording data about the entire operating system, particularly user space events and environments, and interpreting events at different layers of abstraction, aided by the context in which they occurred. They also deal with modeling the recorded data as a multi-resolution, finite state machine so that results can be established to a high degree of certainty rather than merely inferred.
Sean Peisert, Sidney Karin, Matt Bishop, Keith Marzullo
NSPW3
2004 Traducement: A model for record security
abstract
Security models generally incorporate elements of both confidentiality and integrity. We examine a case where confidentiality is irrelevant to the process being modeled. In this case, integrity includes not only the authentication of origin and the lack of unauthorized changes to a document, but also the acceptance of all parties that the document is complete, signed by all parties, and cannot be modified further. This is especially critical when the document is recorded, so that it is legally the agreement or statement of record, and any copies of the document have no legal force. We show that current security models do not capture the details of this process. We then present a new security model for this process. This model captures the recordation process, and augments, rather than supplants, existing models. Hence it can also be used with existing security models to describe other situations.
Tom Walcott, Matt Bishop
ACM Trans. Inf. Syst. Secur.2
2003 Miracle Cures and Toner Cartridges: Finding Solutions to the Spam Problem
Michael Clifford, Daniel Faigin, Matt Bishop, Tasneem G. Brutch
ACSAC3
2003 Testing C Programs for Buffer Overflow Vulnerabilities
Eric Haugh, Matt Bishop
NDSS2
2003 Addressing Software Security and Mitigations in the Life Cycle
abstract
Traditionally, security is viewed as an organizational and information technology (IT) systems function comprising of firewalls, intrusion detection systems (IDS), system security settings and patches to the operating system (OS) and applications running on it. Until recently, little thought has been given to the importance of security as a formal approach in the software life cycle. The Jet Propulsion Laboratory has approached the problem through the development of an integrated formal software security assessment instrument (SSAI) with six foci for the software life cycle.
David P. Gilliam, John D. Powell, Eric Haugh, Matt Bishop
SEW4
2002 A Flexible Containment Mechanism for Executing Untrusted Code
David S. Peterson, Matt Bishop, Raju Pandey
USENIX Security Symposium2
2002 Trends in academic research: vulnerabilities analysis and intrusion detection
Matt Bishop
Comput. Secur.1
2001 How Useful is Software Fault Injection for Evaluating the Security of COTS Products?
Matt Bishop, Anup K. Ghosh, James A. Whittaker
ACSAC1
2000 Analyzing Single-Server Network Inhibition
abstract
Network inhibition is a denial-of-service attack where the adversary attempts to disconnect network elements by disabling a limited number of communication links or nodes. We analyze a common variation of network inhibition where the links have infinite capacity and the goal of the attacker is to deny connections from a single server to as many clients as possible. The problem is defined formally and shown to be NP complete. Nevertheless, we develop a practical technique for network-inhibition analysis based on logic programming with stable-model semantics. The analysis scales well up to moderate-size networks. The results are a step towards quantitative analysis of denial of service and they can be applied to the design of robust network topologies.
Tuomas Aura, Matt Bishop, Dean Sniegowski
CSFW2
2000 Using Conservation of Flow as a Security Mechanism in Network Protocols
abstract
The law of conservation of flow, which states that an input must either be absorbed or sent on as an output (possibly with modification), is an attractive tool with which to analyze network protocols for security properties. One of its uses is to detect disruptive network elements that launch denial of service attacks by absorbing or discarding packets. Its use requires several assumptions about the protocols being analyzed. We examine the WATCHERS algorithm to detect misbehaving routers. We show that it uses conservation of flow without sufficient verification of its assumptions, and can consequently be defeated. We suggest improvements to make the use of conservation of flow valid.
John R. Hughes, Tuomas Aura, Matt Bishop
S&P3
2000 Supporting reconfigurable security policies for mobile programs
Brant Hashii, Scott Malabarba, Raju Pandey, Matt Bishop
Comput. Networks4
1999 Vulnerability Analysis: An Extended Abstract
Matt Bishop
Recent Advances in Intrusion Detection1
1998 The Solar Trust Model: Authentication Without Limitation
abstract
The PEM and PGP/X.509 authentication models and the Biba Integrity Model have limitations inherent in their design that diminish their practicality in real world applications. The ICE-TEL trust model addresses some of these difficulties, and introduces a few new limitations. The Common Security Services Manager's Trust Policy Interface Specification provides the guidelines with which new trust policies may be encoded, but does not implement an actual policy. This paper describes a new model that permits both the identity of the sender of a message, and the trustworthiness of the sender of the message to be determined. The model works regardless of whether or not the message was signed by a certificate authority with which the recipient has a relationship. The model can be implemented without changing the format of certificates that are currently in use, and could be used as a module in a broader security framework, such as the Common Security Services Manager.
Michael Clifford, C. Lavine, Matt Bishop
ACSAC3
1996 Conspiracy and Information Flow in the Take-Grant Protection Model
abstract
The Take-Grant Protection Model is a theoretic model of access control that captures the notion of information flow throughout the modelled system. This paper analyzes the problem of sharing information in the context of paths along which information
Matt Bishop
J. Comput. Secur.1
1995 Improving system security via proactive password checking
Matt Bishop, Daniel V. Klein
Comput. Secur.1
1995 Theft of Information in the Take-Grant Protection Model
abstract
Questions of information flow are in many ways more important than questions of access control, because the goal of many security policies is to thwart the unauthorized release of information, not merely the illicit obtaining of access rights to that information. The Take-Grant Protection Model is an excellent theoretical tool for examining such issues because conditions necessary and sufficient for information to flow between two objects, and for rights to objects to be obtained or stolen, are known. In this paper we extend these results by examining the question of information flow from an object the owner of which is unwilling to release that information. Necessary and sufficient conditions for such “theft of information” to occur are derived. To emphasize the usefulness of these results, the security policies of complete isolation, transfer of rights with the cooperation of an owner, and transfer of information (but not rights) with the cooperation of the owner are presented; the last is used to model a subject guarding a resource.
Matt Bishop
J. Comput. Secur.1
1993 Teaching Computer Security
Matt Bishop
SEC1
1990 A security analysis of the NTP protocol version 2
abstract
The network time protocol (NTP) is being used throughout the Internet to provide an accurate time service. The author examines the security requirements of such a service, analyzes version 2 of the NTP protocol to determine how well it meets these requirements, and suggests improvements where appropriate. Five types of security attacks on a time service are possible. An attacker could cause a nontime server to impersonate a time server (masquerade), an attacker could modify some (or all) time messages sent by a time server (modification), an attacker could resend a time server's time messages (replay), an attacker could intercept a time server's time messages and delete them (denial of service), and an attacker could delay the time messages by, for example, deliberately flooding the network, thereby introducing large transmission delays (delay).>
Matt Bishop
ACSAC1
1990 Collaboration using Roles
abstract
Abstract Segregation of roles into alternative accounts is a model which provides not only the ability to collaborate but also enables accurate accounting of resources consumed by collaborative projects, protects the resources and objects of such a project, and does not introduce new security vulnerabilities. The implementation presented here does not require users to remember additional passwords and provides a very simple consistent interface.
Matt Bishop
Softw. Pract. Exp.1
1989 A model of security monitoring
abstract
A formal model of security monitoring that distinguishes two different methods of recording information (logging) and two different methods of analyzing information (auditing) is presented. From this model, implications for the design and use of security monitoring mechanisms are drawn. The model is then applied to security mechanisms for statistical databases, monitoring mechanisms for computer systems, and backups, in order to demonstrate its usefulness. It is concluded that the proposed model of logging and auditing is comprehensive enough to encompass very different schemes used in a variety of contexts. For example. Statistical database query control and file access monitoring systems do not seem to be related, and yet they create closely related security problems, and the mechanisms designed to improve the security of one will also improve the security of the other.>
Matt Bishop
ACSAC1
1989 UNIX security in a supercomputing environment
abstract
The [email protected]@@@ operating system is designed for collaborative work and not for security. Vendors have modified this operating system (in some cases, radically) to provide levels of security acceptable to their customers, but the versions used in supercomputing environments would benefit from enhancements present in so-called secure versions. This paper discusses the need for security in a supercomputing environment and suggests modifications to the UNIX operating system that would decrease the vulnerability of those sites to attacks. Among the issues are additional auditing controls, changes to network programs, improved user authentication, and better application of the principle of least privilege.
Matt Bishop
SC1
1988 Theft of Information in the Take-Grant Protection Model
Matt Bishop
CSFW1
1987 Profiling Under UNIX by Patching
abstract
Abstract Profiling under UNIX is done by inserting counters into programs either before compiling, during compiling or during assembly. A fourth type of profiling involves monitoring the execution of a program, and gathering relevant statistics during the run. This paper looks at this method and an implementation of it, and discusses its advantages and disadvantages.
Matt Bishop
Softw. Pract. Exp.1
1986 A pauper's callback scheme
Matt Bishop
Comput. Secur.1
1981 Hierarchical Take-Grant Protection Systems
abstract
The application of the Take-Grant Protection Model to hierarchical protection systems is explored. The proposed model extends the results of Wu [7] and applies the results of Bishop and Snyder [2] to obtain necessary and sufficient conditions for a hierarchical protection graph to be secure. In addition, restrictions on the take and grant rules are developed that ensure the security of all graphs generated by these restricted rules.
Matt Bishop
SOSP1
1979 The Transfer of Information and Authority in a Protection System
abstract
In the context of a capability-based protection system, the term “transfer” is used (here) to refer to the situation where a user receives information when he does not initially have a direct “right” to it. Two transfer methods are identified: de jure transfer refers to the case when the user acquires the direct authority to read the information; de facto transfer refers to the case when the user acquires the information (usually in the form of a copy and with the assistance of others), without necessarily being able to get the direct authority to read the information. The Take-Grant Protection Model, which already models de jure transfers, is extended with four rewriting rules to model de facto transfer. The configurations under which de facto transfer can arise are characterized. Considerable motivational discussion is included.
Matt Bishop, Lawrence Snyder 0001
SOSP1