AbdelRahman Abdou

dblp:157/0157 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0002-2783-107XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2026 DeCerts: Secure and Fine-grained CDN Delegation
abstract
The use of Content Delivery Networks (CDNs) has significantly increased over the past decade, with over 44 million websites relying on CDN services. Emerging solutions, such as Delegated Credentials (RFC 9345), lack fine-grained definitions of many critical aspects of delegation, such as the length of delegation chains, revocation mechanisms, permitted operations, and a well-defined scope for said delegation. We present Delegation Certificates (DeCerts), which modify X.509 certificate standard and add new extensions to enable fine-grained CDN delegation. DeCerts allow domain owners to specify delegated and non-delegated subdomains, and control the depth of delegation extended by CDN, which provides flexibility in delegation management. But more importantly, DeCerts are built on a new principle which provides full autonomy to domain owners. Domain owners can issue DeCerts fully independent of Certificate Authorities (CAs), allowing greater flexibility in policy control, including revocation mechanisms. Such level of flexibility would be hard to match if CAs were to issue such certificates. Revoking a DeCert revokes delegation. We discuss multiple revocation mechanisms for DeCerts balancing security, performance, and delegator control. We modify Firefox to support DeCerts and implement proper validation as a proof-of-concept to demonstrate the feasibility and compatibility of DeCerts with browsers and TLS/HTTPS protocols. DeCerts enhance the security, scalability, and manageability of CDN delegation, offering a practical solution for Internet services.
Ethan Thompson, Ali Sadeghi Jahromi, AbdelRahman Abdou
CODASPY3
2025 Formal Security Analysis of ss2DNS
Ali Sadeghi Jahromi, AbdelRahman Abdou, Paul C. van Oorschot
ESORICS (3)2
2021 Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols
Enis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson, Srdjan Capkun
USENIX Security Symposium3
2021 Comparative Analysis and Framework Evaluating Mimicry-Resistant and Invisible Web Authentication Schemes
abstract
Many password alternatives for web authentication proposed over the years, despite having different designs and objectives, all predominantly rely on the knowledge of some secret. This motivates us, herein, to provide the first detailed exploration of the integration of a fundamentally different element of defense into the design of web authentication schemes: a mimicry-resistance dimension. We analyze web authentication mechanisms with respect to new usability and security properties related to mimicry-resistance (augmenting the UDS framework), and in particular evaluate invisible techniques (those requiring neither user actions, nor awareness) that provide some mimicry-resistance (unlike those relying solely on static secrets), including device fingerprinting schemes, PUFs (physically unclonable functions), and a subset of Internet geolocation mechanisms.
Furkan Alaca, AbdelRahman Abdou, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.2
2020 SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust
abstract
The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These problems are exacerbated by the lack of a native delegation mechanism in TLS, which increasingly leads domain owners to engage in dangerous practices such as sharing their private keys with third parties. We analyze solutions that address the longstanding delegation and revocation shortcomings of the web PKI, with a focus on approaches that directly affect the chain of trust (i.e., the X.509 certification path). For this purpose, we propose a 19-criteria framework for characterizing revocation and delegation schemes. We also show that combining short-lived delegated credentials or proxy certificates with an appropriate revocation system would solve several pressing problems.
Laurent Chuat, AbdelRahman Abdou, Ralf Sasse, Christoph Sprenger 0001, David A. Basin, Adrian Perrig
EuroS&P2
2019 UWB-ED: Distance Enlargement Attack Detection in Ultra-Wideband
Mridula Singh, Patrick Leu, AbdelRahman Abdou, Srdjan Capkun
USENIX Security Symposium3
2018 Server Location Verification (SLV) and Server Location Pinning: Augmenting TLS Authentication
abstract
We introduce the first known mechanism providing realtime server location verification. Its uses include enhancing server authentication by enabling browsers to automatically interpret server location information. We describe the design of this new measurement-based technique, Server Location Verification (SLV), and evaluate it using PlanetLab. We explain how SLV is compatible with the increasing trends of geographically distributed content dissemination over the Internet, without causing any new interoperability conflicts. Additionally, we introduce the notion of (verifiable)server location pinning(conceptually similar to certificate pinning) to support SLV, and evaluate their combined impact using a server-authentication evaluation framework. The results affirm the addition of new security benefits to the existing TLS-based authentication mechanisms. We implement SLV through a location verification service, the simplest version of which requires no server-side changes. We also implement a simple browser extension that interacts seamlessly with the verification infrastructure to obtain realtime server location-verification results.
AbdelRahman Abdou, Paul C. van Oorschot
ACM Trans. Priv. Secur.1
2017 Accurate Manipulation of Delay-based Internet Geolocation
abstract
Delay-based Internet geolocation techniques are repeatedly positioned as well suited for security-sensitive applications, e.g., location-based access control, and credit-card verification. We present new strategies enabling adversaries to accurately control the forged location. Evaluation showed that using the new strategies, adversaries could misrepresent their true locations by over 15000km, and in some cases within 100km of an intended geographic location. This work significantly improves the adversary's control in misrepresenting its location, directly refuting the appropriateness of current techniques for security-sensitive applications. We finally discuss countermeasures to mitigate such strategies.
AbdelRahman Abdou, Ashraf Matrawy, Paul C. van Oorschot
AsiaCCS1
2017 A survey on forensic event reconstruction systems
abstract
Security related incidents such as unauthorised system access, data tampering and theft have been noticeably rising. Tools such as firewalls, intrusion detection systems and anti-virus software strive to prevent these incidents. Since these tools only prevent an attack, once an illegal intrusion occurs, they cease to provide useful information beyond this point. Consequently, system administrators are interested in identifying the vulnerability in order to: 1) avoid future exploitation; 2) recover corrupted data; 3) present the attacker to law enforcement where possible. As such, forensic event reconstruction systems are used to provide the administrators with possible information. We present a survey on the current approaches towards forensic event reconstruction systems proposed over the past few years. Technical details are discussed, as well as analysis to their effectiveness, advantages and limitations. The presented tools are compared and assessed based on the primary principles that a forensic technique is expected to follow.
Abes Dabir, AbdelRahman Abdou, Ashraf Matrawy
Int. J. Inf. Comput. Secur.2
2017 CPV: Delay-Based Location Verification for the Internet
abstract
The number of location-aware services over the Internet continues growing. Some of these require the client's geographic location for security-sensitive applications. Examples include location-aware authentication, location-aware access policies, fraud prevention, complying with media licensing, and regulating online gambling/voting. An adversary can evade existing geolocation techniques, e.g., by faking GPS coordinates or employing a non-local IP address through proxy and virtual private networks. We devise Client Presence Verification (CPV), a delay-based verification technique designed to verify an assertion about a device's presence inside a prescribed geographic region. CPV does not identify devices by their IP addresses. Rather, the device's location is corroborated in a novel way by leveraging geometric properties of triangles, which prevents an adversary from manipulating measured delays. To achieve high accuracy, CPV mitigates Internet path asymmetry using a novel method to deduce one-way application-layer delays to/from the client's participating device, and mines these delays for evidence supporting/refuting the asserted location. We evaluate CPV through detailed experiments on PlanetLab, exploring various factors that affect its efficacy, including the granularity of the verified location, and the verification time. Results highlight the potential of CPV for practical adoption.
AbdelRahman Abdou, Ashraf Matrawy, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.1