EDBT 2026 Demo / reviewers in the wild / expert
Samuel Jero
dblp:164/3347
· DBLP profile ↗
18ranked-venue papers
7as first author
5since 2021 · last 2022
0000-0002-6014-0107ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 first-author · 3 since 2021Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | The Thundering Herd: Amplifying Kernel Interference to Attack Response TimesabstractEmbedded and real-time systems are increasingly attached to networks. This enables broader coordination beyond the physical system, but also opens the system to attacks. The increasingly complex workloads of these systems include software of varying assurance levels, including that which might be susceptible to compromise by remote attackers. To limit the impact of compromise, μ-kernels focus on maintaining strong memory protection domains between different bodies of software, including system services. They enable limited coordination between processes through Inter-Process Communication (IPC). Real-time systems also require strong temporal guarantees for tasks, and thus need temporal isolation to limit the impact of malicious software. This is challenging as multiple client threads that use IPC to request service from a shared server will impact each other’s response times.To constrain the temporal interference between threads, modern μ-kernels often build priority and budget awareness into the system. Unfortunately, this paper demonstrates that this is more challenging than previously thought. Adding priority awareness to IPC processing can lead to significant interference due to the kernel’s prioritization logic. Adding budget awareness similarly creates opportunities for interference due to the budget tracking and management operations. In both situations, a Thundering Herd of malicious threads can significantly delay the activation of mission-critical tasks. The Thundering Herd effects are evaluated on seL4 and results demonstrate that high-priority threads can be delayed by over 100,000 cycles per malicious thread. This paper reveals a challenging dilemma: the temporal protections μ-kernels add can, themselves, provide means of threatening temporal isolation. Finally, to defend the system, we identify and empirically evaluate possible mitigations, and propose an admission-control test based upon an interference-aware analysis. Samuel Mergendahl, Samuel Jero, Bryan C. Ward, Juliana Furgala, Gabriel Parmer, Richard Skowyra |
RTAS | 2 |
| 2021 | More than a Fair Share: Network Data Remanence Attacks against Secret Sharing-based Schemes
Leila Rashidi, Daniel Kostecki, Alexander James, Anthony Peterson, Majid Ghaderi, Samuel Jero, Cristina Nita-Rotaru, Hamed Okhravi, Reihaneh Safavi-Naini |
NDSS | 6 |
| 2021 | Practical Principle of Least Privilege for Secure Embedded SystemsabstractMany embedded systems have evolved from simple bare-metal control systems to highly complex network-connected systems. These systems increasingly demand rich and feature-full operating-systems (OS) functionalities. Furthermore, the network connectedness offers attack vectors that require stronger security designs. To that end, this paper defines a prototypical RTOS API called Patina that provides services common in featurerich OSes (e.g., Linux) but absent in more trustworthy μ -kernel based systems. Examples of such services include communication channels, timers, event management, and synchronization. Two Patina implementations are presented, one on Composite and the other on seL4, each of which is designed based on the Principle of Least Privilege (PoLP) to increase system security. This paper describes how each of these μ -kernels affect the PoLP based design, as well as discusses security and performance tradeoffs in the two implementations. Results of comprehensive evaluations demonstrate that the performance of the PoLP based implementation of Patina offers comparable or superior performance to Linux, while offering heightened isolation. Samuel Jero, Juliana Furgala, Runyu Pan, Phani Kishore Gadepalli, Alexandra Clifford, Bite Ye, Roger I. Khazan, Bryan C. Ward, Gabriel Parmer, Richard Skowyra |
RTAS | 1 |
| 2021 | Causal Analysis for Software-Defined Networking Attacks
Benjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates 0001, William H. Sanders, Hamed Okhravi |
USENIX Security Symposium | 2 |
| 2021 | Secure Communication Channel Establishment: TLS 1.3 (over TCP Fast Open) versus QUICabstractAbstract Secure channel establishment protocols such as Transport Layer Security (TLS) are some of the most important cryptographic protocols, enabling the encryption of Internet traffic. Reducing latency (the number of interactions between parties before encrypted data can be transmitted) in such protocols has become an important design goal to improve user experience. The most important protocols addressing this goal are TLS 1.3, the latest TLS version standardized in 2018 to replace the widely deployed TLS 1.2, and Quick UDP Internet Connections (QUIC), a secure transport protocol from Google that is implemented in the Chrome browser. There have been a number of formal security analyses for TLS 1.3 and QUIC, but their security, when layered with their underlying transport protocols, cannot be easily compared. Our work is the first to thoroughly compare the security and availability properties of these protocols. Toward this goal, we develop novel security models that permit “layered” security analysis. In addition to the standard goals of server authentication and data confidentiality and integrity, we consider the goals of IP spoofing prevention, key exchange packet integrity, secure channel header integrity, and reset authentication, which capture a range of practical threats not usually taken into account by existing security models that focus mainly on the cryptographic cores of the protocols. Equipped with our new models we provide a detailed comparison of three low-latency layered protocols: TLS 1.3 over TCP Fast Open (TFO), QUIC over UDP, and QUIC[TLS] (a new design for QUIC that uses TLS 1.3 key exchange) over UDP. In particular, we show that TFO’s cookie mechanism does provably achieve the security goal of IP spoofing prevention. Additionally, we find several new availability attacks that manipulate the early key exchange packets without being detected by the communicating parties. By including packet-level attacks in our analysis, our results shed light on how the reliability, flow control, and congestion control of the above layered protocols compare, in adversarial settings. We hope that our models will help protocol designers in their future protocol analyses and that our results will help practitioners better understand the advantages and limitations of secure channel establishment protocols. Samuel Jero, Matthew Jagielski, Alexandra Boldyreva, Cristina Nita-Rotaru |
J. Cryptol. | 2 |
| 2020 | Automated Discovery of Cross-Plane Event-Based Vulnerabilities in Software-Defined Networking
Benjamin E. Ujcich, Samuel Jero, Richard Skowyra, Steven R. Gomez, Adam Bates 0001, William H. Sanders, Hamed Okhravi |
NDSS | 2 |
| 2020 | aBBRate: Automating BBR Attack Exploration Using a Model-Based Approach
Anthony Peterson, Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Cristina Nita-Rotaru |
RAID | 2 |
| 2019 | Leveraging Textual Specifications for Grammar-Based Fuzzing of Network ProtocolsabstractGrammar-based fuzzing is a technique used to find software vulnerabilities by injecting well-formed inputs generated following rules that encode application semantics. Most grammar-based fuzzers for network protocols rely on human experts to manually specify these rules. In this work we study automated learning of protocol rules from textual specifications (i.e. RFCs). We evaluate the automatically extracted protocol rules by applying them to a state-of-the-art fuzzer for transport protocols and show that it leads to a smaller number of test cases while finding the same attacks as the system that uses manually specified rules. Samuel Jero, Maria Leonor Pacheco, Dan Goldwasser, Cristina Nita-Rotaru |
AAAI | 1 |
| 2019 | Controller-Oblivious Dynamic Access Control in Software-Defined NetworksabstractConventional network access control approaches are static (e.g., user roles in Active Directory), coarse-grained (e.g., 802.1x), or both (e.g., VLANs). Such systems are unable to meaningfully stop or hinder motivated attackers seeking to spread throughout an enterprise network. To address this threat, we present Dynamic Flow Isolation (DFI), a novel architecture for supporting dynamic, fine-grained access control policies enforced in a Software-Defined Network (SDN). These policies can emit and revoke specific access control rules automatically in response to network events like users logging off, letting the network adaptively reduce unnecessary reachability that could be potentially leveraged by attackers. DFI is oblivious to the SDN controller implementation and processes new packets prior to the controller, making DFI's access control resilient to a malicious or faulty controller or its applications. We implemented DFI for OpenFlow networks and demonstrated it on an enterprise SDN testbed with around 100 end hosts and servers. Finally, we evaluated the performance of DFI and how it enables a novel policy, which is otherwise difficult to enforce, that protects against a surrogate of the recent NotPetya malware in an infection scenario. We found that the threat was most limited in its ability to spread using our policy, which automatically restricted network flows over the course of the attack, compared to no access control or a static role-based policy. Steven R. Gomez, Samuel Jero, Richard Skowyra, Patrick Sullivan, David Bigelow, Zachary Ellenbogen, Bryan C. Ward, Hamed Okhravi, James Landry |
DSN | 2 |
| 2019 | Secure Communication Channel Establishment: TLS 1.3 (over TCP Fast Open) vs. QUIC
Samuel Jero, Matthew Jagielski, Alexandra Boldyreva, Cristina Nita-Rotaru |
ESORICS (1) | 2 |
| 2018 | Cross-App Poisoning in Software-Defined NetworkingabstractSoftware-defined networking (SDN) continues to grow in popularity because of its programmable and extensible control plane realized through network applications (apps). However, apps introduce significant security challenges that can systemically disrupt network operations, since apps must access or modify data in a shared control plane state. If our understanding of how such data propagate within the control plane is inadequate, apps can co-opt other apps, causing them to poison the control plane's integrity. We present a class of SDN control plane integrity attacks that we call cross-app poisoning (CAP), in which an unprivileged app manipulates the shared control plane state to trick a privileged app into taking actions on its behalf. We demonstrate how role-based access control (RBAC) schemes are insufficient for preventing such attacks because they neither track information flow nor enforce information flow control (IFC). We also present a defense, ProvSDN, that uses data provenance to track information flow and serves as an online reference monitor to prevent CAP attacks. We implement ProvSDN on the ONOS SDN controller and demonstrate that information flow can be tracked with low-latency overheads. Benjamin E. Ujcich, Samuel Jero, Anne Edmundson, Qi Wang 0017, Richard Skowyra, James Landry, Adam Bates 0001, William H. Sanders, Cristina Nita-Rotaru, Hamed Okhravi |
CCS | 2 |
| 2018 | Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach
Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove, Cristina Nita-Rotaru |
NDSS | 1 |
| 2017 | Taking a long look at QUIC: an approach for rigorous evaluation of rapidly evolving transport protocolsabstractGoogle's QUIC protocol, which implements TCP-like properties at the application layer atop a UDP transport, is now used by the vast majority of Chrome clients accessing Google properties but has no formal state machine specification, limited analysis, and ad-hoc evaluations based on snapshots of the protocol implementation in a small number of environments. Further frustrating attempts to evaluate QUIC is the fact that the protocol is under rapid development, with extensive rewriting of the protocol occurring over the scale of months, making individual studies of the protocol obsolete before publication. Arash Molavi Kakhki, Samuel Jero, David R. Choffnes, Cristina Nita-Rotaru, Alan Mislove |
Internet Measurement Conference | 2 |
| 2017 | BEADS: Automated Attack Discovery in OpenFlow-Based SDN Systems
Samuel Jero, Xiangyu Bu, Cristina Nita-Rotaru, Hamed Okhravi, Richard Skowyra, Sonia Fahmy |
RAID | 1 |
| 2017 | Identifier Binding Attacks and Defenses in Software-Defined Networks
Samuel Jero, William Koch, Richard Skowyra, Hamed Okhravi, Cristina Nita-Rotaru, David Bigelow |
USENIX Security Symposium | 1 |
| 2016 | Dynamic control of real-time communication (RTC) using SDN: A case study of a 5G end-to-end serviceabstractThe next-generation 5G mobile network architecture will support the rapid deployment of new, dynamic network services that are capable of responding to current network conditions and demands. Software-defined Networking (SDN), virtualization technologies, and real-time analytics are the core components that will enable an adaptive and responsive 5G network. We present a case study of a real-time communications (RTC) video service that highlights the manner in which the core components (SDN, virtualization, analytics) allow a flexible and elastic 5G network. Because an end-to-end 5G network does not exist today, we construct one using artifacts from the current 4G/LTE network to host our dynamic network enabled RTC service. We identify three main insights from executing our service that could prove beneficial to the 5G network evolution: need for efficient horizontal control, need to limit identifier proliferation, and the existence of control-plane network functions in service network-function graphs. Samuel Jero, Vijay K. Gurbani, Ray Miller, Bruce Cilli, Charles Payette, Sameer Sharma |
NOMS | 1 |
| 2015 | Leveraging State Information for Automated Attack Discovery in Transport Protocol ImplementationsabstractWe present a new method for finding attacks in unmodified transport protocol implementations using the specification of the protocol state machine to reduce the search space of possible attacks. Such reduction is obtained by appling malicious actions to all packets of the same type observed in the same state instead of applying them to individual packets. Our method requires knowledge of the packet formats and protocol state machine. We demonstrate our approach by developing SNAKE, a tool that automatically finds performance and resource exhaustion attacks on unmodified transport protocol implementations. SNAKE utilizes virtualization to run unmodified implementations in their intended environments and network emulation to create the network topology. SNAKE was able to find 9 attacks on 2 transport protocols, 5 of which we believe to be unknown in the literature. Samuel Jero, Hyojeong Lee Seibert, Cristina Nita-Rotaru |
DSN | 1 |
| 2015 | How Secure and Quick is QUIC? Provable Security and Performance AnalysesabstractQUIC is a secure transport protocol developed by Google and implemented in Chrome in 2013, currently representing one of the most promising solutions to decreasing latency while intending to provide security properties similar with TLS. In this work we shed some light on QUIC's strengths and weaknesses in terms of its provable security and performance guarantees in the presence of attackers. We first introduce a security model for analyzing performance-driven protocols like QUIC and prove that QUIC satisfies our definition under reasonable assumptions on the protocol's building blocks. However, we find that QUIC does not satisfy the traditional notion of forward secrecy that is provided by some modes of TLS, e.g., TLS-DHE. Our analyses also reveal that with simple bit-flipping and replay attacks on some public parameters exchanged during the handshake, an adversary could easily prevent QUIC from achieving minimal latency advantages either by having it fall back to TCP or by causing the client and server to have an inconsistent view of their handshake leading to a failure to complete the connection. We have implemented these attacks and demonstrated that they are practical. Our results suggest that QUIC's security weaknesses are introduced by the very mechanisms used to reduce latency, which highlights the seemingly inherent trade off between minimizing latency and providing "good" security guarantees. Robert Lychev, Samuel Jero, Alexandra Boldyreva, Cristina Nita-Rotaru |
IEEE Symposium on Security and Privacy | 2 |