EDBT 2026 Demo / reviewers in the wild / expert
Christopher A. Wood
dblp:163/1886
· DBLP profile ↗
20ranked-venue papers
0as first author
8since 2021 · last 2023
0000-0003-3297-4216ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 2 since 2021Security and privacy · 7 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Password-Authenticated TLS via OPAQUE and Post-Handshake Authentication
Julia Hesse, Stanislaw Jarecki, Hugo Krawczyk, Christopher A. Wood |
EUROCRYPT (5) | 4 |
| 2023 | Evaluating practical QUIC website fingerprinting defenses for the massesabstractWebsite fingerprinting (WF) is a well-known threat to users' web privacy. New Internet standards, such as QUIC, include padding to support defenses against WF. Previous work on QUIC WF only analyzes the effectiveness of defenses when users are behind a VPN. Yet, this is not how most users browse the Internet. In this paper, we provide a comprehensive evaluation of QUIC-padding-based defenses against WF when users directly browse the web, i.e., without VPNs, HTTPS proxies, or other tunneling protocols. We confirm previous claims that network-layer padding cannot provide effective protection against powerful adversaries capable of observing all traffic traces. We show that the claims hold even against adversaries with constraints on traffic visibility and processing power. We then show that the current approach to web development, in which the use of third-party resources is the norm, impedes the effective use of padding-based defenses as it requires first and third parties to coordinate in order to thwart traffic analysis. We show that even when coordination is possible, in most cases, protection comes at a high cost. Sandra Deepthy Siby, Ludovic Barman, Christopher A. Wood, Marwan Fayed, Nick Sullivan, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | A Symbolic Analysis of Privacy for TLS 1.3 with Encrypted Client HelloabstractTLS 1.3, the newest version of the Transport Layer Security (TLS) protocol, provides strong authentication and confidentiality guarantees that have been comprehensively analyzed in a variety of formal models. However, despite its controversial use of handshake meta-data encryption, the privacy guarantees of TLS 1.3 remain weak and poorly understood. For example, the protocol reveals the identity of the target server to network attackers, allowing the passive surveillance and active censorship of TLS connections. To close this gap, the IETF TLS working group is standardizing a new privacy extension called Encrypted Client Hello (ECH, previously called ESNI), but the absence of a formal privacy model makes it hard to verify that this extension works. Indeed, several early drafts of ECH were found to be vulnerable to active network attacks. Karthikeyan Bhargavan, Vincent Cheval, Christopher A. Wood |
CCS | 3 |
| 2022 | A Fast and Simple Partially Oblivious PRF, with Applications
Nirvan Tyagi, Sofía Celi, Thomas Ristenpart, Nick Sullivan, Stefano Tessaro, Christopher A. Wood |
EUROCRYPT (2) | 6 |
| 2022 | Respect the ORIGIN!: a best-case evaluation of connection coalescing in the wildabstractConnection coalescing, enabled by HTTP/2, permits a client to use an existing connection to request additional resources at the connected hostname. The potential for requests to be coalesced is hindered by the practice of domain sharding introduced by HTTP/1.1, because subresources are scattered across subdomains in an effort to improve performance with additional connections. When this happens, HTTP/2 clients invoke additional DNS queries and new connections to retrieve content that is available at the same server. ORIGIN Frame is an HTTP/2 extension that can be used by servers to inform clients about other domains that are reachable on the same connection. Despite being proposed by content delivery network (CDN) operators and standardized by the IETF in 2018, the extension has no known server implementation and is supported by only one browser. In this paper, we collect and characterize a large dataset. We use that dataset to model connection coalescing and identify a least-effort set of certificate changes that maximize opportunities for clients to coalesce. We then implemented and deployed ORIGIN Frame support at a large CDN. To evaluate and validate our modeling at scale, 5000 certificates were reissued. Passive measurements were conducted on production traffic over two weeks, during which we also actively measured on the 5000 domains. Sudheesh Singanamalla, Muhammad Talha Paracha, Suleman Ahmad, Jonathan Hoyland, Luke Valenta, Yevgen Safronov, Peter Wu, Andrew Galloni, Kurtis Heimerl, Nick Sullivan, Christopher A. Wood, Marwan Fayed |
IMC | 11 |
| 2022 | Might I Get Pwned: A Second Generation Compromised Credential Checking Service
Bijeeta Pal, Mazharul Islam 0002, Marina Sanusi Bohuk, Nick Sullivan, Luke Valenta, Tara Whalen, Christopher A. Wood, Thomas Ristenpart, Rahul Chatterjee 0001 |
USENIX Security Symposium | 7 |
| 2021 | The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scaleabstractThe couplings between IP addresses, names of content or services, and socket interfaces, are too tight. This impedes system manageability, growth, and overall provisioning. In turn, large-scale content providers are forced to use staggering numbers of addresses, ultimately leading to address exhaustion (IPv4) and inefficiency (IPv6). Marwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola, Marek Majkowski, Pavel Odintsov, Jakub Sitnicki, Taejoong Chung, Dave Levin, Alan Mislove, Christopher A. Wood, Nick Sullivan |
SIGCOMM | 11 |
| 2021 | Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNSabstractAbstract The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records. Traditional DNS is unencrypted and leaks user information to on-lookers. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting DNS messages from third parties. However, the small number of available public large-scale DoT and DoH resolvers has reinforced DNS privacy concerns, specifically that DNS operators could use query contents and client IP addresses to link activities with identities. Oblivious DNS over HTTPS (ODoH) safeguards against these problems. In this paper we implement and deploy interoperable instantiations of the protocol, construct a corresponding formal model and analysis, and evaluate the protocols’ performance with wide-scale measurements. Results suggest that ODoH is a practical privacy-enhancing replacement for DNS. Sudheesh Singanamalla, Suphanat Chunhapanya, Jonathan Hoyland, Marek Vavrusa, Tanya Verma, Peter Wu, Marwan Fayed, Kurtis Heimerl, Nick Sullivan, Christopher A. Wood |
Proc. Priv. Enhancing Technol. | 10 |
| 2019 | Privacy-Aware Caching in Information-Centric NetworkingabstractInformation-Centric Networking (ICN) is an emerging networking paradigm where named and routable data (content) is the focal point. Users send explicit requests (interests) which specify content by name, and the network handles routing these interests to some entity capable of satisfying them with the appropriate data response (producer). One key feature of ICN is opportunistic in-network content caching. This property facilitates efficient content distribution by reducing bandwidth consumption, lessening network congestion, and improving the content retrieval latency by users (consumers). Unfortunately, the same feature is also detrimental to privacy of content consumers and producers. Simple to implement, and difficult to detect, timing attacks can exploit ICN routers as “oracles” and allow an adversary to learn whether a nearby consumer recently requested certain content. The attack leverages a timing side channel that relies on router caches and is implemented by requesting a few packets from each piece of content being probed. Similarly, probing attacks that target content producers can be used to discover whether certain content has been recently distributed. After analyzing the scope and feasibility of such attacks, we propose and evaluate some efficient countermeasures that offer quantifiable privacy guarantees while retaining the benefits of ICN. Gergely Ács, Mauro Conti, Paolo Gasti, Cesar Ghali, Gene Tsudik, Christopher A. Wood |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2017 | Secure off-path replication in content-centric networksabstractWe present SCR, a secure content replication protocol for the Content-Centric Networking (CCN) architecture. The goal of SCR is to allow a data producer to cache protected content in off-path semi-trusted caches or replicas. In contrast to the standard “take what you want” model of CCN, SCR ensures that no unauthorized, off-path entity can obtain data from these replicas, even if the content is encrypted. SCR allows a producer to encrypt data under any viable access control scheme, such as group-based access backed by broadcast encryption, and delegate the delivery of said content to distributed replicas in the network. SCR is analogous to “blind caching” in IP-based networks, which aim to provide caching as a service in the presence of end-to-end encryption via TLS. We discuss the design details and security features, e.g., revocation, of SCR. We then compare SCR to the HTTP(S)-based blind caching model. We show that our scheme can outperform blind caching due to (1) less protocol complexity and message overhead, (2) faster session establishment, and (3) the ability to obtain data in parallel from multiple, independent replicas. Marc Mosko, Christopher A. Wood |
ICC | 2 |
| 2017 | Closing the Floodgate with Stateless Content-Centric NetworkingabstractInformation-Centric Networking (ICN) is a recent paradigm that claims to mitigate some limitations of the current IP-based Internet architecture. The centerpiece of ICN is named and addressable content, rather than hosts or interfaces. Content-Centric Networking (CCN) is a prominent ICN instance that shares the fundamental architectural design with its equally popular academic sibling Named- Data Networking (NDN). CCN eschews source addresses and creates one-time virtual circuits for every content request (called an interest). As an interest is forwarded it creates state in intervening routers and the requested content back is delivered over the reverse path using that state. Although a stateful forwarding plane might be beneficial in terms of efficiency and resilience to certain types of attacks, this has not been decisively proven via realistic experiments. Since keeping per-interest state complicates router operations and makes the infrastructure susceptible to router state exhaustion attacks (e.g., there is currently no effective defense against Interest Flooding attacks), the value of the stateful forwarding plane in CCN should be re-examined. In this paper, we explore supposed benefits and various problems of the stateful forwarding plane. We then argue that its benefits are uncertain at best and it should not be a mandatory CCN feature. To this end, we propose a new stateless architecture for CCN that provides nearly all functionality of the stateful design without its headaches. We analyze performance and resource requirements of the proposed architecture via experiments. Cesar Ghali, Gene Tsudik, Ersin Uzun, Christopher A. Wood |
ICCCN | 4 |
| 2017 | Mitigating On-Path Adversaries in Content-Centric NetworksabstractContent-Centric Networking (CCN) is a recently proposed Internet paradigm that focuses on scalable, secure and efficient content distribution. The main abstraction is named and addressable content. A consumer requests desired named content by generating a so-called interest, which is then routed by the network towards an in-network cached copy, or the authoritative producer, of that content. Since all CCN content must be signed by its producer, consumers and routers can cryptographically verify its correctness, authenticity, and integrity. Thus, in principle, attacks that introduce fake (poisoned) content can be detected. However, verifying content signatures is optional for CCN routers, detection of fake content only implies presence of a malicious upstream entity. A major outstanding problem in CCN is how to react to such attacks, determine their source(s), and re-route interests accordingly. In this work, we construct a technique based on efficient per-hop packet integrity checks. Routers share secrets with neighboring routers and use them to verify and generate efficient per-hop packet authenticators. An on-path attacker that tampers with content in transit is quickly detected by downstream routers. Moreover, an on-path attacker that hijacks a namespace is discoverable. Our experimental assessment indicates that the proposed technique incurs very low per-packet overhead. Furthermore, since our approach is not CCN-specific, it can be applied to IP-based networks as well. Cesar Ghali, Gene Tsudik, Christopher A. Wood |
LCN | 3 |
| 2017 | Namespace Tunnels in Content-Centric NetworksabstractContent-Centric Networking (CCN) is a candidate next-generation Internet architecture that offers an alternative to the current IP-based model. CCN emphasizes scalable and efficient content distribution by making content explicitly named and addressable. It also offers some appealing privacy features, such as lack of source and destination addresses in packets. However, to be considered a fully viable Internet architecture, CCN must support private and anonymous communication that is at least on par with IP. Within this space, a VPN is an important and popular tool that enables users to communicate across insecure public networks as if they were connected over a private network. At present, VPN support is also absent from the repertoire of CCN research. To fill this void, we design, implement and evaluate CCVPN - a content-centric analog to IP-based VPNs of the current Internet architecture. To the best of our knowledge, CCVPN is the first such CCN-based design. Though functionally equivalent to IP-based VPNs, CCVPN offers better privacy due to unlinkability of encapsulated packets to the originating network. We analyze security of CCVPN and experimentally assess its performance. Ivan Oliveira Nunes, Gene Tsudik, Christopher A. Wood |
LCN | 3 |
| 2016 | AC3N: Anonymous communication in Content-Centric NetworkingabstractContent-Centric Networking (CCN) is an emerging (inter-)networking architecture with the goal of becoming an alternative to the IP-based Internet. To be considered a viable candidate, CCN must at least have parity with existing solutions for confidential and anonymous communication, e.g., TLS, tcpcrypt, and Tor. ANDa̅NA (Anonymous Named Data Networking Application) was the first proposed solution that addressed the lack of anonymous communication in Named Data Networking (NDN)-a variant of CCN. However, its design and implementation led to performance issues that hinder practical use. In this paper we introduce AC3N: Anonymous Communication for Content-Centric Networking. AC3N is an evolution of the ANDa̅NA system that supports high-throughput and low-latency anonymous content retrieval. We discuss the design and initial performance results of this new system. Gene Tsudik, Ersin Uzun, Christopher A. Wood |
CCNC | 3 |
| 2016 | Trust in Information-Centric Networking: From Theory to PracticeabstractWe present the logical design of a trust engine for Information-Centric Networking (ICN) that is capable of efficiently and correctly verifying content integrity and authenticity. Our primary contribution is the synthesis and unified treatment of four different and popular trust models. We show in which operational aspects they vary and emphasize which parts of the verification mechanics are invariant. The verifier logic is expressed in Prolog to show its simplicity (abstracting away, e.g., procedural certification chain verification steps) and to highlight subtle errors that can occur in the use and enforcement of trust models. The details of an implementation of our trust engine in the CCNx network stack are presented to demonstrate its viability and general modularity. A simplistic interface enables the trust engine to be easily ported to any ICN-style network software. Finally, we demonstrate how application instantiations of various trust models are natively supported by the trust engine to illustrate its flexibility. Christian F. Tschudin, Ersin Uzun, Christopher A. Wood |
ICCCN | 3 |
| 2016 | Practical accounting in content-centric networkingabstractContent-Centric Networking (CCN) is a recent network paradigm designed to address some key limitations of the current IP-based Internet. One of its main features is innetwork content caching which allows requests for content to be served by routers. Despite the benefits of improved bandwidth utilization and lower latency of retrieving popular content, innetwork caching inhibits producers from collecting information about content that is requested and later served from network caches. Such information is often needed for accounting and popularity purposes. In this paper, we address accounting in CCN by varying the degree of consumer, router, and producer involvement. We also identify and analyze inherent performance and security tradeoffs. We show that fine-grained accounting is infeasible with router caches and without explicit application support. We then recommend accounting strategies that entail a few simple requirements for CCN architectures. Finally, we show, via experimental results, that network-layer CCN accounting is viable and incurs low overhead for all parties involved. approaches. Cesar Ghali, Gene Tsudik, Christopher A. Wood, Edmund M. Yeh |
NOMS | 3 |
| 2015 | Secure Fragmentation for Content Centric NetworkingabstractInformation Centric Networks (ICN), such as Content Centric Networks (CCNx) or Named Data Networks (NDN) disseminate data using hierarchal names for each chunk of data, where a chunk is roughly the size of an IP datagram. To secure the named exchange, each chunk has a digital signature or a hash-based name. Because these datagrams may be much larger than a link MTU, there is a need for fragmentation, and to date several hop-by-hop, end-to-end, and mid-to-end fragmentation schemes have been proposed. Only one scheme, FIGOA, a cut-through mid-to-end fragmentation scheme (i.e. Without reassembly) claims to be secure by using delayed authentication. We propose a secure cut-through fragmentation scheme derived from FIGOA that allows immediate validation. We also consider queuing and timing issues that were not discussed in FIGOA. Marc Mosko, Christopher A. Wood |
MASS | 2 |
| 2015 | Secure Fragmentation for Content-Centric NetworksabstractContent-Centric Networking (CCN) is a communication paradigm that emphasizes content distribution. Named-Data Networking (NDN) is an instantiation of CCN, a candidate Future Internet Architecture. NDN supports human-readable content naming and router-based content caching which lends itself to efficient, secure, and scalable content distribution. Because of NDN's fundamental requirement that each content object must be signed by its producer, fragmentation has been considered incompatible with NDN since it precludes authentication of individual content fragments by routers. The alternative is to perform hop-by-hop reassembly, which incurs prohibitive delays. In this paper, we show that secure and efficient content fragmentation is both possible and even advantageous in NDN and similar content-centric network architectures that involve signed content. We design a concrete technique that facilitates efficient and secure content fragmentation in NDN, discuss its security guarantees and assess performance. We also describe a prototype implementation and compare performance of cut-through with hop-by-hop fragmentation and reassembly. Cesar Ghali, Ashok Narayanan, Dave Oran, Gene Tsudik, Christopher A. Wood |
NCA | 5 |
| 2015 | An encryption-based access control framework for content-centric networkingabstractThis paper proposes a comprehensive encryption-based access control framework for content centric networking (CCN), called CCN-AC. This framework is both flexible and extensible, enabling the specification, implementation, and enforcement of a variety of access control policies for sensitive content in the network. The design of CCN-AC heavily relies on the concept of secure content object manifests and leverages them to decouple encrypted content from access policy and specifications for minimum communication overhead and maximum utilization of in-network caches. To demonstrate the flexibility of framework, we also describe how to implement two sample access control schemes, group-based access control and broadcast access control, within CCN-AC framework. Jun Kurihara, Ersin Uzun, Christopher A. Wood |
Networking | 3 |
| 2014 | Cybersecurity Education: Bridging the Gap Between Hardware and Software DomainsabstractWith the continuous growth of cyberinfrastructure throughout modern society, the need for secure computing and communication is more important than ever before. As a result, there is also an increasing need for entry-level developers who are capable of designing and building practical solutions for systems with stringent security requirements. This calls for careful attention to algorithm choice and implementation method, as well as trade-offs between hardware and software implementations. This article describes motivation and efforts taken by three departments at Rochester Institute of Technology (Computer Engineering, Computer Science, and Software Engineering) that were focused on creating a multidisciplinary course that integrates the algorithmic, engineering, and practical aspects of security as exemplified by applied cryptography. In particular, the article presents the structure of this new course, topics covered, lab tools and results from the first two spring quarter offerings in 2011 and 2012. Marcin Lukowiak, Stanislaw P. Radziszowski, James R. Vallino, Christopher A. Wood |
ACM Trans. Comput. Educ. | 4 |