David A. McGrew

dblp:m/DavidAMcGrew · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
1since 2021 · last 2023
0009-0007-4033-8662ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-authorSecurity and privacy · 4 · 1 since 2021Systems, architecture and hardware · 3Databases, data management, data science and information retrieval · 2Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Theory of computation · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Network security · 56% Malware analysis · 34% Cryptographic primitives and cryptanalysis · 7%
Computer architecture, parallel and distributed computing, and storage systems
4 papers
Integrated circuit design · 58% Reconfigurable computing and FPGAs · 30% Hardware accelerators and domain-specific architectures · 13%
Computer networks
2 papers
Network measurement and analytics · 69% Internet architecture and protocols · 31%

Topics — the 18 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › traffic analysis › encrypted traffic analysis
encrypted traffic classification
0.312017
Machine Learning for Encrypted Malware Traffic Classification: Accounting for Noisy Labels and Non-Stationarity · KDD 2017
Malware analysis › malware
malware traffic classification
0.312017
Machine Learning for Encrypted Malware Traffic Classification: Accounting for Noisy Labels and Non-Stationarity · KDD 2017
Malware analysis › malware defense
network-based malware detection
0.312017
Machine Learning for Encrypted Malware Traffic Classification: Accounting for Noisy Labels and Non-Stationarity · KDD 2017
Network measurement and analytics
flow monitoring
0.212016
Enhanced telemetry for encrypted threat analytics · ICNP 2016
Network security › traffic analysis
encrypted traffic analysis
0.212016
Enhanced telemetry for encrypted threat analytics · ICNP 2016
Internet architecture and protocols › network security
TLS
0.112019
TLS Beyond the Browser: Combining End Host and Network Data to Understand Application Behavior · Internet Measurement Conference 2019
Integrated circuit design › digital circuit design
cryptographic hardware
0.122006
Divide-and-concatenate: an architecture level optimization technique for universal hash functions · DAC 2004
A High-Speed Hardware Architecture for Universal Message Authentication Code · IEEE J. Sel. Areas Commun. 2006
Cryptographic primitives and cryptanalysis
message authentication codes
0.112006
A High-Speed Hardware Architecture for Universal Message Authentication Code · IEEE J. Sel. Areas Commun. 2006
Reconfigurable computing and FPGAs
FPGA implementation
0.112006
A High-Speed Hardware Architecture for Universal Message Authentication Code · IEEE J. Sel. Areas Commun. 2006
Integrated circuit design
low-power circuit design
0.112005
Divide-and-concatenate: an architecture-level optimization technique for universal hash functions · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2005
Hardware accelerators and domain-specific architectures
cryptographic accelerator
0.012004
Divide and concatenate: a scalable hardware architecture for universal MAC · FPGA 2004
Integrated circuit design
digital circuit design
0.012004
Divide-and-concatenate: an architecture level optimization technique for universal hash functions · DAC 2004
Reconfigurable computing and FPGAs › FPGA accelerator
FPGA cryptographic accelerator
0.012004
Divide and concatenate: a scalable hardware architecture for universal MAC · FPGA 2004
Integrated circuit design › digital circuit design › arithmetic circuit design
multiplier design
0.012004
Divide-and-concatenate: an architecture level optimization technique for universal hash functions · DAC 2004
Cryptographic primitives and cryptanalysis › searchable encryption
forward and backward privacy
0.012003
Key Establishment in Large Dynamic Groups Using One-Way Function Trees · IEEE Trans. Software Eng. 2003
Cryptographic protocols and secure computation › key exchange
group key agreement
0.012003
Key Establishment in Large Dynamic Groups Using One-Way Function Trees · IEEE Trans. Software Eng. 2003
Cryptographic primitives and cryptanalysis › hash functions
universal hash functions
0.012005
Divide-and-concatenate: an architecture-level optimization technique for universal hash functions · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2005
Network security › secure communication
secure group communication
0.012003
Key Establishment in Large Dynamic Groups Using One-Way Function Trees · IEEE Trans. Software Eng. 2003

Methods — techniques the papers use, named apart from their topics

end host and network data correlation · 0.8machine learning classifier · 0.5divide-and-concatenate · 0.3random forest · 0.3linear regression · 0.3feature engineering · 0.3pipelining · 0.2one-way function trees · 0.0
YearPublicationVenuePosition
2023 Detecting Weak Keys in Manufacturing Certificates: A Case Study
abstract
Weak entropy is an industry-wide challenge for network device vendors. We conducted a large scale analysis of RSA keys in about 226 million device certificates from one vendor, covering products that were manufactured over a 12-year time period. By focusing on specific data features of the manufacturing certificates, we tested for common keys and common factors across distinct devices. The scale of our analysis enabled the detection of entropy failures that manifested in the RSA keys of millions of devices. The affected devices included several products not implicated in any prior studies, resulting in the discovery of three new vulnerabilities in actively supported products. The entropy failures were complex, resulting from both low initial entropy and the faulty composition of manufacturing processes. Most affected product families were lower-margin devices past their end-of-support date; higher-end products that used a vendor-sanctioned hardware entropy source did not exhibit these weaknesses. However, our findings warrant more proactive and systematic entropy testing by device vendors.
Andrew Chi, Brandon Enright, David A. McGrew
ACSAC3
2019 Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption
abstract
We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-Type, and Server, and the presence or absence of several additional HTTP header fields, e.g., Cookie and Referer. Our goals are to improve the understanding of the confidentiality limitations of HTTPS, and to explore benign uses of traffic analysis that could replace HTTPS interception and static private keys in some scenarios. We found that our techniques increase the efficacy of malware detection, but they do not enable more powerful website fingerprinting attacks against Tor. Our broader set of results raises concerns about the confidentiality goals of TLS relative to a user's expectation of privacy, warranting future research. We apply our methods to the semantics of both HTTP/1.1 and HTTP/2 on data collected from automated runs of Firefox 58.0, Chrome 63.0, and Tor Browser 7.0.11 in a lab setting, and from applications running in a malware sandbox. We obtain ground truth plaintext for a diverse set of applications from the malware sandbox by extracting the key material needed for decryption from RAM post-execution. We developed an iterative approach to simultaneously solve several multi-class (field values) and binary (field presence) classification problems, and we show that our inference algorithm achieves an unweighted $F_1$ score greater than 0.900 for most HTTP fields examined.
Blake Anderson, Andrew Chi, Scott Dunlop, David A. McGrew
CODASPY4
2019 TLS Beyond the Browser: Combining End Host and Network Data to Understand Application Behavior
abstract
The Transport Layer Security (TLS) protocol has evolved in response to different attacks and is increasingly relied on to secure Internet communications. Web browsers have led the adoption of newer and more secure cryptographic algorithms and protocol versions, and thus improved the security of the TLS ecosystem. Other application categories, however, are increasingly using TLS, but too often are relying on obsolete and insecure protocol options.
Blake Anderson, David A. McGrew
Internet Measurement Conference2
2017 Machine Learning for Encrypted Malware Traffic Classification: Accounting for Noisy Labels and Non-Stationarity
abstract
The application of machine learning for the detection of malicious network traffic has been well researched over the past several decades; it is particularly appealing when the traffic is encrypted because traditional pattern-matching approaches cannot be used. Unfortunately, the promise of machine learning has been slow to materialize in the network security domain. In this paper, we highlight two primary reasons why this is the case: inaccurate ground truth and a highly non-stationary data distribution. To demonstrate and understand the effect that these pitfalls have on popular machine learning algorithms, we design and carry out experiments that show how six common algorithms perform when confronted with real network data. With our experimental results, we identify the situations in which certain classes of algorithms underperform on the task of encrypted malware traffic classification. We offer concrete recommendations for practitioners given the real-world constraints outlined. From an algorithmic perspective, we find that the random forest ensemble method outperformed competing methods. More importantly, feature engineering was decisive; we found that iterating on the initial feature set, and including features suggested by domain experts, had a much greater impact on the performance of the classification system. For example, linear regression using the more expressive feature set easily outperformed the random forest method using a standard network traffic representation on all criteria considered. Our analysis is based on millions of TLS encrypted sessions collected over 12 months from a commercial malware sandbox and two geographically distinct, large enterprise networks.
Blake Anderson, David A. McGrew
KDD2
2016 Enhanced telemetry for encrypted threat analytics
abstract
Traditional flow monitoring provides a high-level view of network communications by reporting the addresses, ports, and byte and packet counts of a flow. This data is valuable, but it gives little insight into the actual content or context of a flow. To obtain this missing insight, we investigated intra-flow data, that is, information about events that occur inside of a flow that can be conveniently collected, stored, and analyzed within a flow monitoring framework. The focus of our work is on new types of data that are independent of protocol details, such as the lengths and arrival times of messages within a flow. These data elements have the attractive property that they apply equally well to both encrypted and unencrypted flows. Protocol-aware telemetry, specifically TLS-aware telemetry, is also analyzed. In this paper, we explore the benefits of enhanced telemetry, desirable properties of new intra-flow data features with respect to a flow monitoring system, and how best to use machine learning classifiers that operate on this data. We provide results on millions of flows processed by our open source program. Finally, we show that leveraging appropriate data features and simple machine learning models can successfully identify threats in encrypted network traffic.
David A. McGrew, Blake Anderson
ICNP1
2014 Pipelineable On-line Encryption
Farzaneh Abed, Scott R. Fluhrer, Christian Forler, Eik List, Stefan Lucks, David A. McGrew, Jakob Wenzel 0001
FSE6
2006 (R)Evolutionary Bootstrapping of a Global PKI for Securing BGP
Yih-Chun Hu, David A. McGrew, Adrian Perrig, Brian Weis, Dan Wendlandt
HotNets2
2006 A High-Speed Hardware Architecture for Universal Message Authentication Code
abstract
We present an architecture level optimization technique called divide-and-concatenate based on two observations: 1) the area of an array multiplier and its associated data path decreases quadratically and their delay decreases linearly as their operand size is reduced and 2) in universal hash functions and their associated message authentication codes, two one-way hash functions are equivalent if they have the same collision probability property. In the proposed approach, we divide a 2w-bit data path (with collision probability 2-2w) into two w-bit data paths (each with collision probability 2-w) and concatenate their results to construct an equivalent 2w-bit data path (with a collision probability 2-2w). We applied this technique on NH universal hash, a universal hash function that uses multiplications and additions. We implemented the straightforward 32-bit pipelined NH universal hash data path and the divide-and-concatenate architecture that uses four equivalent 8-bit divide-and-concatenate NH universal hash data paths on a Xilinx Virtex II XC2VP7-7 field programmable gate array (FPGA) device. This divide-and-concatenate architecture yielded a 94% increase in throughput with only 40% hardware overhead. Finally, the implementation of universal message authentication code (UMAC) with collision probability 2-32using the divide-and-concatenate NH hash as a building block yielded a throughput of 79.2 Gb/s with only 3840 Virtex II XC2VP7-7 FPGA slices
Bo Yang 0010, Ramesh Karri, David A. McGrew
IEEE J. Sel. Areas Commun.3
2005 Minimizing center key storage in hybrid one-way function based group key management with communication constraints
Radha Poovendran, David A. McGrew
Inf. Process. Lett.3
2005 Divide-and-concatenate: an architecture-level optimization technique for universal hash functions
abstract
The authors present an architectural optimization technique called divide-and-concatenate for hardware architectures of universal hash functions based on three observations: 1) the area of a multiplier and associated data path decreases quadratically and their speeds increase gradually as their operand size is reduced; 2) multiplication is at the core of universal hash functions and multipliers consume most of the area of universal hash function hardware; and 3) two universal hash functions are equivalent if they have the same collision-probability property. In the proposed approach, the authors divide a 2w-bit data path (with collision probability 2/sup -2w/) into two w-bit data paths (each with collision probability 2/sup -w/), apply one message word to these two w-bit data paths and concatenate their results to construct an equivalent 2w-bit data path (with a collision probability 2/sup -2w/). The divide-and-concatenate technique is complementary to all circuit-, logic-, and architecture-optimization techniques. The authors applied this technique on a linear congruential universal hash (LCH) family. When compared to the 100% overhead associated with duplicating a straightforward 32-bit LCH data path, the divide-and-concatenate approach that uses four equivalent 8-bit data paths yields a 101% increase in throughput with only 52% hardware overhead.
Bo Yang 0010, Ramesh Karri, David A. McGrew
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2004 Divide-and-concatenate: an architecture level optimization technique for universal hash functions
abstract
We present an architecture optimization technique called divide-and-concatenate for universal hash functions. The area of a multiplier increases quadratically and its speed increases gradually with the operand size and two universal hash functions are equivalent if they have the same collision probability property. Based on these observations, the divide-and-concatenate approach divides a 2w-bit data path (with collision probability 2-2w) into two w-bit data paths (each with collision probability 2-w), applies one message word to these two w-bit data paths and concatenates their results to construct an equivalent 2w-bit data path (with collision probability 2-2w). We demonstrate this technique on Linear Congruential Hash (LCH) family. When compared to the 100% overhead associated with duplicating a straightforward 32-bit LCH data path, the divide-and-concatenate approach that uses four equivalent 8-bit data paths yields a 101% increase in throughput with only 52% hardware overhead.
Bo Yang 0010, Ramesh Karri, David A. McGrew
DAC3
2004 Divide and concatenate: a scalable hardware architecture for universal MAC
abstract
We present a cryptographic architecture optimization technique called divide-and-concatenate based on two observations: (i) the area of a multiplier and associated data path decreases quadratically and their speeds increase gradually as their operand size is reduced. (ii) in hash functions, message authentication codes and related cryptographic algorithms, two functions are equivalent if they have the same collision probability property. In the proposed approach we divide a 2w-bit data path into two w-bit data paths and concatenate their results to construct an equivalent 2w-bit data path. We applied this technique on NH hash. When compared to the 100% overhead associated with duplicating a straightforward 32-bit pipelined NH hash data path, the divide-and-concatenate approach yields a 94% increase in throughput with only 40% hardware overhead. The NH hash associated message authentication code UMAC architecture with collision probability 2-32 that uses four equivalent 8-bit divide-and-concatenate NH hash data paths yields a throughput of 79.2 Gbps with only 3840 FPGA slices when implemented on a Xilinx FPGA.
Bo Yang 0010, Ramesh Karri, David A. McGrew
FPGA3
2003 Key Establishment in Large Dynamic Groups Using One-Way Function Trees
abstract
We present, implement, and analyze a new scalable centralized algorithm, called OFT, for establishing shared cryptographic keys in large, dynamically changing groups. Our algorithm is based on a novel application of one-way function trees. In comparison with the top-down logical key hierarchy (LKH) method of Wallner et al., our bottom-up algorithm approximately halves the number of bits that need to be broadcast to members in order to rekey after a member is added or evicted. The number of keys stored by group members, the number of keys broadcast to the group when new members are added or evicted, and the computational efforts of group members, are logarithmic in the number of group members. Among the hierarchical methods, OFT is the first to achieve an approximate halving in broadcast length, an idea on which subsequent algorithms have built. Our algorithm provides complete forward and backward security: Newly admitted group members cannot read previous messages, and evicted members cannot read future messages, even with collusion by arbitrarily many evicted members. In addition, and unlike LKH, our algorithm has the option of being member contributory in that members can be allowed to contribute entropy to the group key. Running on a Pentium II, our prototype has handled groups with up to 10 million members. This algorithm offers a new scalable method for establishing group session keys for secure large-group applications such as broadcast encryption, electronic conferences, multicast sessions, and military command and control.
Alan T. Sherman, David A. McGrew
IEEE Trans. Software Eng.2
2000 Statistical Analysis of the Alleged RC4 Keystream Generator
Scott R. Fluhrer, David A. McGrew
FSE2