Steven M. Bellovin

dblp:00/1396 · DBLP profile ↗
← Back
49ranked-venue papers
17as first author
2since 2021 · last 2022
0000-0002-1231-0407ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 36 · 12 first-author · 1 since 2021Systems, architecture and hardware · 6 · 2 first-authorComputer networks · 5 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1Theory of computation · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
28 papers
Privacy and data protection · 59% Cryptographic protocols and secure computation · 22% Usable security · 6%
Computer networks
12 papers
Network management and operations · 54% Internet architecture and protocols · 24% Network measurement and analytics · 10%
Software engineering, system software, and programming languages
1 paper
Requirements engineering and software design · 100%

Topics — the 30 heaviest of 56, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Privacy and data protection
anonymization
0.612022
Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census · SP 2022
Privacy and data protection
differential privacy
0.612022
Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census · SP 2022
Privacy and data protection
statistical database privacy
0.612022
Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census · SP 2022
Cryptographic protocols and secure computation
key management
0.522021
Why Joanie Can Encrypt: Easy Email Encryption with Easy Key Management · EuroSys 2019
Encrypted cloud photo storage using Google photos · MobiSys 2021
Cryptographic protocols and secure computation
client-side encryption
0.512021
Encrypted cloud photo storage using Google photos · MobiSys 2021
Privacy and data protection
web tracking
0.312017
A Privacy Analysis of Cross-device Tracking · USENIX Security Symposium 2017
Authentication and access control
access control
0.212015
Malicious-Client Security in Blind Seer: A Scalable Private DBMS · IEEE Symposium on Security and Privacy 2015
Privacy and data protection › privacy policy
privacy policy analysis
0.212014
Privee: An Architecture for Automatically Analyzing Web Privacy Policies · USENIX Security Symposium 2014
Cryptographic protocols and secure computation
private query
0.212014
Blind Seer: A Scalable Private DBMS · IEEE Symposium on Security and Privacy 2014
Privacy and data protection
web privacy
0.212014
Privee: An Architecture for Automatically Analyzing Web Privacy Policies · USENIX Security Symposium 2014
Computational social science and digital humanities
demographic data analysis
0.212022
Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census · SP 2022
Privacy and data protection › data confidentiality › content privacy
email privacy
0.112019
Why Joanie Can Encrypt: Easy Email Encryption with Easy Key Management · EuroSys 2019
Cryptographic primitives and cryptanalysis
public-key cryptography
0.122006
Permissive Action Links, Nuclear Weapons, and the History of Public Key Cryptography · USENIX ATC, General Track 2006
Nuclear Weapons, Permissive Action Links, and the History of Public Key Cryptography · USENIX Security Symposium 2004
Network management and operations
configuration management
0.112009
Configuration management and security · IEEE J. Sel. Areas Commun. 2009
Network management and operations › network configuration
security configuration
0.112009
Configuration management and security · IEEE J. Sel. Areas Commun. 2009
Query processing and optimization › secure query processing
privacy-preserving query processing
0.112015
Malicious-Client Security in Blind Seer: A Scalable Private DBMS · IEEE Symposium on Security and Privacy 2015
Cryptographic primitives and cryptanalysis
hash functions
0.112006
Deploying a New Hash Algorithm · NDSS 2006
Network security
firewall
0.122001
Transient Addressing for Related Processes: Improved Firewalling by Using IPV6 and Multiple Addresses per Host · USENIX Security Symposium 2001
Implementing a distributed firewall · CCS 2000
Information retrieval › query processing
boolean query processing
0.112014
Blind Seer: A Scalable Private DBMS · IEEE Symposium on Security and Privacy 2014
Cryptographic protocols and secure computation
key exchange
0.132002
Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002
An attack on the Interlock Protocol when used for authentication · IEEE Trans. Inf. Theory 1994
Encrypted key exchange: password-based protocols secure against dictionary attacks · S&P 1992
Cryptographic protocols and secure computation › key exchange
authenticated key exchange
0.022002
Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002
An attack on the Interlock Protocol when used for authentication · IEEE Trans. Inf. Theory 1994
Cryptographic primitives and cryptanalysis
cryptographic foundations
0.012012
Privacy and Cybersecurity: The Next 100 Years · Proc. IEEE 2012
Network measurement and analytics
topology measurement
0.012002
A technique for counting natted hosts · Internet Measurement Workshop 2002
Network security › attack resilience › attack mitigation › denial-of-service defense
DDoS defense
0.012002
Implementing Pushback: Router-Based Defense Against DDoS Attacks · NDSS 2002
Cryptographic protocols and secure computation › key exchange
perfect forward secrecy
0.012002
Efficient, DoS-resistant, secure key exchange for internet protocols · CCS 2002
Network security
peer-to-peer network security
0.012001
Security Risks Of Peer-To-Peer Networking · NDSS 2001
Internet architecture and protocols › network security
IP security
0.021999
Transport-Friendly ESP · NDSS 1999
Problem Areas for the IP Security Protocols · USENIX Security Symposium 1996
Authentication and access control
trust management
0.012000
Implementing a distributed firewall · CCS 2000
Edge and fog computing › mobile edge computing
edge server placement
0.011999
Transport-Friendly ESP · NDSS 1999
Authentication and access control
password authentication
0.021994
An attack on the Interlock Protocol when used for authentication · IEEE Trans. Inf. Theory 1994
Augmented Encrypted Key Exchange: A Password-Based Protocol Secure against Dictionary Attacks and Password File Compromise · CCS 1993

Methods — techniques the papers use, named apart from their topics

record swapping · 1.1linkage attack · 1.1natural language processing · 0.8format-preserving encryption · 0.5QR code communication · 0.5receiver-controlled encryption · 0.4S/MIME · 0.4PGP · 0.4privacy analysis · 0.3measurement · 0.3semi-private function secure function evaluation · 0.2SPF-SFE · 0.2search pattern leakage · 0.2access control integration · 0.2historical analysis · 0.0trace data processing · 0.0pushback · 0.0IP ID field analysis · 0.0
YearPublicationVenuePosition
2022 Differential Privacy and Swapping: Examining De-Identification's Impact on Minority Representation and Privacy Preservation in the U.S. Census
abstract
There has been considerable controversy regarding the accuracy and privacy of de-identification mechanisms used in the U.S. Decennial Census. We theoretically and experimentally analyze two such classes of mechanisms, swapping and differential privacy, especially examining their effects on ethnoracial minority groups.We first prove that the expected error of queries made on swapped demographic datasets is greater in sub-populations whose racial distributions differ more from the racial distribution of the global population. We also prove that the probability that m unique entries exist in a sub-population shrinks exponentially as the sub-population size grows. These properties suggest that swapping, which prioritizes unique entries, will produce poor accuracy for minority groups.We then empirically analyze the impact of swapping and differential privacy on the accuracy and privacy of a demographic dataset. We evaluate accuracy in several ways, including methods that stress the effect on minority groups. We evaluate privacy by counting the number of re-identified entries in a simulated linkage attack. Finally, we explore the disproportionate presence of minority groups in identified entries.Our empirical lindings corroborate our theoretical results: for minority representation, the utility of differential privacy is comparable to the utility of swapping, while providing a stronger privacy guarantee. Swapping places a disproportionate privacy burden on minority groups, whereas an ε-differentially private mechanism is ε-differentially private for all subgroups.
Miranda Christ, Sarah Radway, Steven M. Bellovin
SP3
2021 Encrypted cloud photo storage using Google photos
abstract
Cloud photo services are widely used for persistent, convenient, and often free photo storage, which is especially useful for mobile devices. As users store more and more photos in the cloud, significant privacy concerns arise because even a single compromise of a user's credentials give attackers unfettered access to all of the user's photos. We have created Easy Secure Photos (ESP) to enable users to protect their photos on cloud photo services such as Google Photos. ESP introduces a new client-side encryption architecture that includes a novel format-preserving image encryption algorithm, an encrypted thumbnail display mechanism, and a usable key management system. ESP encrypts image data such that the result is still a standard format image like JPEG that is compatible with cloud photo services. ESP efficiently generates and displays encrypted thumbnails for fast and easy browsing of photo galleries from trusted user devices. ESP's key management makes it simple to authorize multiple user devices to view encrypted image content via a process similar to device pairing, but using the cloud photo service as a QR code communication channel. We have implemented ESP in a popular Android photos app for use with Google Photos and demonstrate that it is easy to use and provides encryption functionality transparently to users, maintains good interactive performance and image quality while providing strong privacy guarantees, and retains the sharing and storage benefits of Google Photos without any changes to the cloud service.
John S. Koh, Jason Nieh, Steven M. Bellovin
MobiSys3
2019 Why Joanie Can Encrypt: Easy Email Encryption with Easy Key Management
abstract
Email privacy is of crucial importance. Existing email encryption approaches are comprehensive but seldom used due to their complexity and inconvenience. We take a new approach to simplify email encryption and improve its usability by implementing receiver-controlled encryption: newly received messages are transparently downloaded and encrypted to a locally-generated key; the original message is then replaced. To avoid the problem of moving a single private key between devices, we implement per-device key pairs: only public keys need be synchronized via a simple verification step. Compromising an email account or server only provides access to encrypted emails. We implemented this scheme on several platforms, showing it works with PGP and S/MIME, is compatible with widely used mail clients and email services including Gmail, has acceptable overhead, and that users consider it intuitive and easy to use.
John S. Koh, Steven M. Bellovin, Jason Nieh
EuroSys2
2017 Automated Analysis of Privacy Requirements for Mobile Apps
Sebastian Zimmeck, Ziqi Wang 0007, Lieyong Zou, Roger Iyengar, Bin Liu 0017, Florian Schaub, Shomir Wilson, Norman M. Sadeh, Steven M. Bellovin, Joel R. Reidenberg
NDSS9
2017 A Privacy Analysis of Cross-device Tracking
Sebastian Zimmeck, Hyungtae Kim, Steven M. Bellovin, Tony Jebara
USENIX Security Symposium4
2015 "I Don't Have a Photograph, But You Can Have My Footprints" - Revealing the Demographics of Location Data
Christopher J. Riederer, Sebastian Zimmeck, Coralie Phanord, Augustin Chaintreau, Steven M. Bellovin
ICWSM5
2015 Malicious-Client Security in Blind Seer: A Scalable Private DBMS
abstract
The Blind Seer system (Oakland 2014) is an efficient and scalable DBMS that affords both client query privacy and server data protection. It also provides the ability to enforce authorization policies on the system, restricting client's queries while maintaining the privacy of both query and policy. Blind Seer supports a rich query set, including arbitrary boolean formulas, and is provably secure with respect to a controlled amount of search pattern leakage. No other system to date achieves this tradeoff of performance, generality, and provable privacy. A major shortcoming of Blind Seer is its reliance on semi-honest security, particularly for access control and data protection. A malicious client could easily cheat the query authorization policy and obtain any database records satisfying any query of its choice, thus violating basic security features of any standard DBMS. In sum, Blind Seer offers additional privacy to a client, but sacrifices a basic security tenet of DBMS. In the present work, we completely resolve the issue of a malicious client. We show how to achieve robust access control and data protection in Blind Seer with virtually no added cost to performance or privacy. Our approach also involves a novel technique for a semi-private function secure function evaluation (SPF-SFE) that may have independent applications. We fully implement our solution and report on its performance.
Ben Fisch, Binh Vo, Fernando Krell, Abishek Kumarasubramanian, Vladimir Kolesnikov, Tal Malkin, Steven M. Bellovin
IEEE Symposium on Security and Privacy7
2014 Anonymous Publish-Subscribe Systems
Binh Vo, Steven M. Bellovin
SecureComm (1)2
2014 Blind Seer: A Scalable Private DBMS
abstract
Query privacy in secure DBMS is an important feature, although rarely formally considered outside the theoretical community. Because of the high overheads of guaranteeing privacy in complex queries, almost all previous works addressing practical applications consider limited queries (e.g., just keyword search), or provide a weak guarantee of privacy. In this work, we address a major open problem in private DB: efficient sub linear search for arbitrary Boolean queries. We consider scalable DBMS with provable security for all parties, including protection of the data from both server (who stores encrypted data) and client (who searches it), as well as protection of the query, and access control for the query. We design, build, and evaluate the performance of a rich DBMS system, suitable for real-world deployment on today medium-to large-scale DBs. On a modern server, we are able to query a formula over 10TB, 100M-record DB, with 70 searchable index terms per DB row, in time comparable to (insecure) MySQL (many practical queries can be privately executed with work 1.2-3 times slower than MySQL, although some queries are costlier). We support a rich query set, including searching on arbitrary boolean formulas on keywords and ranges, support for stemming, and free keyword searches over text fields. We identify and permit a reasonable and controlled amount of leakage, proving that no further leakage is possible. In particular, we allow leakage of some search pattern information, but protect the query and data, provide a high level of privacy for individual terms in the executed search formula, and hide the difference between a query that returned no results and a query that returned a very small result set. We also support private and complex access policies, integrated in the search process so that a query with empty result set and a query that fails the policy are hard to tell apart.
Vasilis Pappas, Fernando Krell, Binh Vo, Vladimir Kolesnikov, Tal Malkin, Seung Geol Choi, Wesley George, Angelos D. Keromytis, Steven M. Bellovin
IEEE Symposium on Security and Privacy9
2014 Privee: An Architecture for Automatically Analyzing Web Privacy Policies
Sebastian Zimmeck, Steven M. Bellovin
USENIX Security Symposium2
2012 Facebook and privacy: it's complicated
abstract
We measure users' attitudes toward interpersonal privacy concerns on Facebook and measure users' strategies for reconciling their concerns with their desire to share content online. To do this, we recruited 260 Facebook users to install a Facebook application that surveyed their privacy concerns, their friend network compositions, the sensitivity of posted content, and their privacy-preserving strategies. By asking participants targeted questions about people randomly selected from their friend network and posts shared on their profiles, we were able to quantify the extent to which users trust their "friends" and the likelihood that their content was being viewed by unintended audiences. We found that while strangers are the most concerning audience, almost 95% of our participants had taken steps to mitigate those concerns. At the same time, we observed that 16.5% of participants had at least one post that they were uncomfortable sharing with a specific friend---someone who likely already had the ability to view it---and that 37% raised more general concerns with sharing their content with friends. We conclude that the current privacy controls allow users to effectively manage the outsider threat, but that they are unsuitable for mitigating concerns over the insider threat---members of the friend network who dynamically become inappropriate audiences based on the context of a post.
Maritza L. Johnson, Serge Egelman, Steven M. Bellovin
SOUPS3
2012 Privacy and Cybersecurity: The Next 100 Years
abstract
The past and the future of privacy and cybersecurity are addressed from four perspectives, by different authors: theory and algorithms, technology, policy, and economics. Each author considers the role of the threat from the corresponding perspective, and each adopts an individual tone, ranging from a relatively serious look at the prospects for improvement in underlying theory and algorithms to more lighthearted considerations of the unpredictable futures of policy and economics.
Carl E. Landwehr, Dan Boneh, John C. Mitchell, Steven M. Bellovin, Susan Landau 0001, Michael E. Lesk
Proc. IEEE4
2011 Private search in the real world
abstract
Encrypted search --- performing queries on protected data --- has been explored in the past; however, its inherent inefficiency has raised questions of practicality. Here, we focus on improving the performance and extending its functionality enough to make it practical. We do this by optimizing the system, and by stepping back from the goal of achieving maximal privacy guarantees in an encrypted search scenario and consider efficiency and functionality as priorities.
Vasilis Pappas, Mariana Raykova 0001, Binh Vo, Steven M. Bellovin, Tal Malkin
ACSAC4
2011 Policy refinement of network services for MANETs
abstract
In this paper, we describe a framework for a refinement scheme located in a centralized policy server that consists of three components: a knowledge database, a refinement rule set, and a policy repository. The refinement process includes two successive steps: policy transformation and policy composition. Our refinement scheme takes policies written in our logic-based abstract policy language as input and generates low level rules directly implementable by individual enforcement points. We provide concrete policy examples in a coalition scenario that forms a mobile ad hoc network (MANET). We demonstrate policy composition using a distributed firewall scheme named ROFL (ROuting as the Firewall Layer) and access control list as enforcement mechanisms.
Jorge Lobo 0001, Arnab Roy 0001, Steven M. Bellovin
Integrated Network Management4
2010 Privacy-Preserving, Taxable Bank Accounts
Elli Androulaki, Binh Vo, Steven M. Bellovin
ESORICS3
2010 High Performance Firewalls in MANETs
abstract
Doing route selection based in part on source addresses is a form of policy routing, which has started to receive increased amounts of attention. In this paper, we extend our previous work on ROLF (ROuting as the Firewall Layer) to achieve source prefix filtering. This permits easy definition of “inside” and “outside”, even in MANET environment where there is no topological boundary. We present algorithms for route propagation and packet forwarding using ROFL, we measure its performance in a simulated environment with two different ad hoc routing protocols. Simulation results demonstrate that ROFL can significantly reduce unwanted packets without extra control traffic incurred, and thus improves overall system performance and preserves battery power of mobile nodes. ROFL is the first scheme to provide a concrete defense against some battery exhaustion attacks in MANETs. Moreover, it requires only minor changes to existing ad hoc network routing protocols, making it practical and feasible to be deployed in real world.
Steven M. Bellovin
MSN2
2009 Two-Person Control Administation: Preventing Administation Faults through Duplication
Shaya Potter, Steven M. Bellovin, Jason Nieh
LISA2
2009 Laissez-faire file sharing: access control designed for individuals at the endpoints
abstract
When organizations deploy file systems with access control mechanisms that prevent users from reliably sharing files with others, these users will inevitably find alternative means to share. Alas, these alternatives rarely provide the same level of confidentiality, integrity, or auditability provided by the prescribed file systems. Thus, the imposition of restrictive mechanisms and policies by system designers and administrators may actually reduce the system's security.
Maritza L. Johnson, Steven M. Bellovin, Robert W. Reeder, Stuart E. Schechter
NSPW2
2009 APOD: Anonymous Physical Object Delivery
Elli Androulaki, Steven M. Bellovin
Privacy Enhancing Technologies2
2009 An Anonymous Credit Card System
Elli Androulaki, Steven M. Bellovin
TrustBus2
2009 Configuration management and security
abstract
Proper configuration management is vital for host and network security. We outline the problems, especially for large-scale environments, and discuss the security aspects of a number of different configuration scenarios, including security appliances (e.g., firewalls), desktop and server computers, and PDAs. We conclude by discussing research challenges.
Steven M. Bellovin, Randy Bush
IEEE J. Sel. Areas Commun.1
2008 ROFL: routing as the firewall layer
abstract
We propose a new firewall architecture that treats port numbers as part of the IP address. Hosts permit connectivity to a service by advertising the IPaddr:port/48 address; they block connectivity by ensuring that there is no route to it. This design, which is especially well-suited to MANETs, provides greater protection against insider attacks than do conventional firewalls, but drops unwanted traffic far earlier than distributed firewalls do.
Sid Chi-Kin Chau, Steven M. Bellovin
NSPW3
2008 Reputation Systems for Anonymous Networks
Elli Androulaki, Seung Geol Choi, Steven M. Bellovin, Tal Malkin
Privacy Enhancing Technologies3
2008 PAR: Payment for Anonymous Routing
Elli Androulaki, Mariana Raykova 0001, Shreyas Srivatsan, Angelos Stavrou, Steven M. Bellovin
Privacy Enhancing Technologies5
2006 Deploying a New Hash Algorithm
Steven M. Bellovin, Eric Rescorla
NDSS1
2006 Permissive Action Links, Nuclear Weapons, and the History of Public Key Cryptography
Steven M. Bellovin
USENIX ATC, General Track1
2006 Privacy & Cryptography
Steven M. Bellovin
USENIX ATC, General Track1
2004 A Look Back at "Security Problems in the TCP/IP Protocol Suite"
abstract
About fifteen years ago, I wrote a paper on security problems in the TCP/IP protocol suite, In particular, I focused on protocol-level issues, rather than implementation flaws. It is instructive to look back at that paper, to see where my focus and my predictions were accurate, where I was wrong, and where dangers have yet to happen. This is a reprint of the original paper, with added commentary.
Steven M. Bellovin
ACSAC1
2004 Nuclear Weapons, Permissive Action Links, and the History of Public Key Cryptography
Steven M. Bellovin
USENIX Security Symposium1
2004 Just fast keying: Key agreement in a hostile internet
abstract
We describe Just Fast Keying (JFK), a new key-exchange protocol, primarily designed for use in the IP security architecture. It is simple, efficient, and secure; we sketch a proof of the latter property. JFK also has a number of novel engineering parameters that permit a variety of tradeoffs, most notably the ability to balance the need for perfect forward secrecy against susceptibility to denial-of-service attacks.
William Aiello, Steven M. Bellovin, Matt Blaze, Ran Canetti, John Ioannidis, Angelos D. Keromytis, Omer Reingold
ACM Trans. Inf. Syst. Secur.2
2002 Efficient, DoS-resistant, secure key exchange for internet protocols
abstract
We describe JFK, a new key exchange protocol, primarily designed for use in the IP Security Architecture. It is simple, efficient, and secure; we sketch a proof of the latter property. JFK also has a number of novel engineering parameters that permit a variety of trade-offs, most notably the ability to balance the need for perfect forward secrecy against susceptibility to denial-of-service attacks.
William Aiello, Steven M. Bellovin, Matt Blaze, John Ioannidis, Omer Reingold, Ran Canetti, Angelos D. Keromytis
CCS2
2002 Intrusion Tolerant Systems Workshop
Carl E. Landwehr, Steven M. Bellovin
DSN2
2002 A technique for counting natted hosts
abstract
There have been many attempts to measure how many hosts are on the Internet. Many of those end-points, however, are NAT boxes (Network Address Translators), and actually represent several different computers. We describe a technique for detecting NATs and counting the number of active hosts behind them. The technique is based on the observation that on many operating systems, the IP header's ID field is a simple counter. By suitable processing of trace data, packets emanating from individual machines can be isolated, and the number of machines determined. Our implementation, tested on aggregated local trace data, demonstrates the feasibility (and limitations) of the scheme.
Steven M. Bellovin
Internet Measurement Workshop1
2002 Implementing Pushback: Router-Based Defense Against DDoS Attacks
John Ioannidis, Steven M. Bellovin
NDSS2
2001 Security Risks Of Peer-To-Peer Networking
Steven M. Bellovin
NDSS1
2001 Transient Addressing for Related Processes: Improved Firewalling by Using IPV6 and Multiple Addresses per Host
Peter M. Gleitz, Steven M. Bellovin
USENIX Security Symposium2
2000 Implementing a distributed firewall
abstract
Conventional rewalls rely on topology restrictions and controlled network entry points to enforce traÆc ltering.Furthermore, a rewall cannot lter traÆc it does not see, so, eectively, e v eryone on the protected side is trusted.While this model has worked well for small to medium size networks, networking trends such as increased connectivity, higher line speeds, extranets, and telecommuting threaten to make it obsolete.To address the shortcomings of traditional rewalls, the concept of a \distributed rewall" has been proposed.In this scheme, security policy is still centrally de ned, but enforcement is left up to the individual endpoints.IPsec may be used to distribute credentials that express parts of the overall network policy.Alternately, these credentials may be obtained through out-of-band means.In this paper, we present the design and implementation of a distributed rewall using the KeyNote trust management system to specify, distribute, and resolve policy, and OpenBSD, an open source UNIX operating system.
Sotiris Ioannidis, Angelos D. Keromytis, Steven M. Bellovin, Jonathan M. Smith
CCS3
1999 Moat: a Virtual Private Network Appliance and Services Platform
John S. Denker, Steven M. Bellovin, Hugh Daniel, Nancy L. Mintz, Tom Killian, Mark Plotnick
LISA2
1999 Why Do We Need More Research?
Steven M. Bellovin
NDSS1
1999 Transport-Friendly ESP
Steven M. Bellovin
NDSS1
1998 Cryptography and the Internet
Steven M. Bellovin
CRYPTO1
1997 Probable Plaintext Cryptanalysis of the IP Security Protocols
abstract
The Internet Engineering Task Force (IETF) is in the process of adopting standards for IP-layer encryption and authentication (IPSEC). We describe how "probable plaintext" can be used to aid in cryptanalytic attacks, and analyze the protocol to show how much probable plaintext is available. We also show how traffic analysis is a powerful aid to the cryptanalyst. We conclude by outlining some likely changes to the underlying protocols that may strengthen them against these attacks.
Steven M. Bellovin
NDSS1
1996 A "bump in the stack" encryptor for MS-DOS systems
abstract
Most implementations of IP security are deeply entwined in the source of the protocol stack. However, such source code is not readily available for MS-DOS systems. We implemented a version using the packet driver interface. Our module sits between the generic Ethernet driver and the hardware driver; it emulates each to the other. Most of the code is straightforward; in a few places, though, we were forced to compensate for inadequate interface definitions.
David A. Wagner 0001, Steven M. Bellovin
NDSS2
1996 Problem Areas for the IP Security Protocols
Steven M. Bellovin
USENIX Security Symposium1
1995 Using the Domain Name System for System Break-ins
Steven M. Bellovin
USENIX Security Symposium1
1995 Session-Layer Encryption
Matt Blaze, Steven M. Bellovin
USENIX Security Symposium2
1994 An attack on the Interlock Protocol when used for authentication
abstract
Exponential key exchange may be used to establish secure communications between two parties who do not share a private key. It fails in the presence of an active wiretap, however. Davies and Price suggest the use of Shamir and Rivest's "Interlock Protocol" to surmount this difficulty. The authors demonstrate that an active attacker can, at the cost of a timeout alarm, bypass the passwork exchange, and capture the passwords used. Furthermore, if the attack is from a terminal or workstation attempting to contact a computer, the attacker will have access before any alarm can be sounded.>
Steven M. Bellovin, Michael Merritt
IEEE Trans. Inf. Theory1
1993 Augmented Encrypted Key Exchange: A Password-Based Protocol Secure against Dictionary Attacks and Password File Compromise
abstract
The encrypted key exchange (EKE) protocol is augmented so that hosts do not store cleartext passwords. Consequently, adversaries who obtain the one-way encrypted password file may (i) successfully mimic (spoof) the host to the user, and (ii) mount dictionary attacks against the encrypted passwords, but cannot mimic the user to the host. Moreover, the important security properties of EKE are preserved—an active network attacker obtains insufficient information to mount dictionary attacks. Two ways to accomplish this are shown, one using digital signatures and one that relies on a family of commutative one-way functions.
Steven M. Bellovin, Michael Merritt
CCS1
1992 Encrypted key exchange: password-based protocols secure against dictionary attacks
abstract
Classic cryptographic protocols based on user-chosen keys allow an attacker to mount password-guessing attacks. A combination of asymmetric (public-key) and symmetric (secret-key) cryptography that allow two parties sharing a common password to exchange confidential and authenticated information over an insecure network is introduced. In particular, a protocol relying on the counter-intuitive motion of using a secret key to encrypt a public key is presented. Such protocols are secure against active attacks, and have the property that the password is protected against offline dictionary attacks.>
Steven M. Bellovin, Michael Merritt
S&P1