Luke Valenta

dblp:166/6979 · DBLP profile ↗
← Back
12ranked-venue papers
2as first author
4since 2021 · last 2023
0000-0001-8936-0499ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 1 since 2021Computer networks · 5 · 3 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
7 papers
Network security · 30% Authentication and access control · 25% Cryptographic protocols and secure computation · 18%
Computer networks
5 papers
Network measurement and analytics · 52% Internet architecture and protocols · 25% Content delivery and video streaming · 17%
Databases, data mining, and information retrieval
1 paper
Web and social media mining · 100%

Topics — the 19 heaviest of 27, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics › internet measurement
censorship measurement
0.712023
Global, Passive Detection of Connection Tampering · SIGCOMM 2023
Internet architecture and protocols › world wide web › web protocols
HTTP/2
0.612022
Respect the ORIGIN!: a best-case evaluation of connection coalescing in the wild · IMC 2022
Network measurement and analytics
web measurement
0.612022
Toppling top lists: evaluating the accuracy of popular website lists · IMC 2022
Authentication and access control › password security
compromised credential checking
0.612022
Might I Get Pwned: A Second Generation Compromised Credential Checking Service · USENIX Security Symposium 2022
Authentication and access control › user authentication
credential verification
0.612022
Might I Get Pwned: A Second Generation Compromised Credential Checking Service · USENIX Security Symposium 2022
Network security › secure communication › secure communication protocol
TLS
0.522016
DROWN: Breaking TLS Using SSLv2 · USENIX Security Symposium 2016
Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015
Cryptographic protocols and secure computation
key exchange
0.432017
Measuring small subgroup attacks against Diffie-Hellman · NDSS 2017
May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519 · CCS 2017
DROWN: Breaking TLS Using SSLv2 · USENIX Security Symposium 2016
Network measurement and analytics › web measurement
CDN measurement
0.312018
403 Forbidden: A Global View of CDN Geoblocking · Internet Measurement Conference 2018
Content delivery and video streaming
content delivery network
0.312018
403 Forbidden: A Global View of CDN Geoblocking · Internet Measurement Conference 2018
Cryptographic protocols and secure computation › key exchange
diffie-hellman key exchange
0.312017
Measuring small subgroup attacks against Diffie-Hellman · NDSS 2017
Hardware security and side channels
microarchitectural side channel
0.312017
May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519 · CCS 2017
Hardware security and side channels
side-channel attack
0.312017
May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519 · CCS 2017
Routing and switching › routing
packet routing
0.212015
Alibi Routing · SIGCOMM 2015
Cryptographic primitives and cryptanalysis
discrete logarithm
0.212015
Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015
Cryptographic primitives and cryptanalysis › integer factorization
number field sieve
0.212015
Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice · CCS 2015
Network security › intrusion detection and prevention
intrusion detection
0.212023
Global, Passive Detection of Connection Tampering · SIGCOMM 2023
Cryptographic protocols and secure computation › key exchange
ECDH
0.112017
May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519 · CCS 2017
Cryptographic primitives and cryptanalysis › public-key cryptography
elliptic curve cryptography
0.112017
May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519 · CCS 2017
Network security
traffic analysis
0.112015
Alibi Routing · SIGCOMM 2015

Methods — techniques the papers use, named apart from their topics

passive network measurement · 1.3server-side request analysis · 1.1measurement study · 0.6private set intersection · 0.6passive measurement · 0.6certificate reissuance · 0.6active measurement · 0.6microarchitectural analysis · 0.3protocol analysis · 0.2cryptanalysis · 0.2number field sieve discrete log · 0.2man-in-the-middle attack · 0.2
YearPublicationVenuePosition
2023 Global, Passive Detection of Connection Tampering
abstract
In-network devices around the world monitor and tamper with connections for many reasons, including intrusion prevention, combating spam or phishing, and country-level censorship. Connection tampering seeks to block access to specific domain names or keywords, and it affects billions of users worldwide with little-to-no transparency. To detect, diagnose, and measure connection-level blocking, "active" measurement techniques originate queries with domains or keywords believed to be blocked and send them from vantage points within networks of interest. Active measurement efforts have been critical to understanding how traffic tampering occurs, but they inherently are unable to capture critical parts of the picture. For instance, knowing the set of domains in a block-list (i.e., what could get blocked) is not the same as knowing what real users are actively experiencing (i.e., what is actively getting blocked).
Ram Sundara Raman, Louis-Henri Merino, Kevin Bock 0001, Marwan Fayed, Dave Levin, Nick Sullivan, Luke Valenta
SIGCOMM7
2022 Toppling top lists: evaluating the accuracy of popular website lists
abstract
Researchers rely on lists of popular websites like the Alexa Top Million both to measure the web and to evaluate proposed protocols and systems. Prior work has questioned the correctness and consistency of these lists, but without ground truth data to compare against, there has been no direct evaluation of list accuracy. In this paper, we evaluate the relative accuracy of the most popular top lists of websites. We derive a set of popularity metrics from server-side requests seen at Cloudflare, which authoritatively serves a significant portion of the most popular websites. We evaluate top lists against these metrics and show that most lists capture web popularity poorly, with the exception of the Chrome User Experience Report (CrUX) dataset, which is the most accurate top list compared to Cloudflare across all metrics. We explore the biases that lower the accuracy of other lists, and we conclude with recommendations for researchers studying the web in the future.
Kimberly Ruth, Deepak Kumar 0006, Brandon Wang, Luke Valenta, Zakir Durumeric
IMC4
2022 Respect the ORIGIN!: a best-case evaluation of connection coalescing in the wild
abstract
Connection coalescing, enabled by HTTP/2, permits a client to use an existing connection to request additional resources at the connected hostname. The potential for requests to be coalesced is hindered by the practice of domain sharding introduced by HTTP/1.1, because subresources are scattered across subdomains in an effort to improve performance with additional connections. When this happens, HTTP/2 clients invoke additional DNS queries and new connections to retrieve content that is available at the same server. ORIGIN Frame is an HTTP/2 extension that can be used by servers to inform clients about other domains that are reachable on the same connection. Despite being proposed by content delivery network (CDN) operators and standardized by the IETF in 2018, the extension has no known server implementation and is supported by only one browser. In this paper, we collect and characterize a large dataset. We use that dataset to model connection coalescing and identify a least-effort set of certificate changes that maximize opportunities for clients to coalesce. We then implemented and deployed ORIGIN Frame support at a large CDN. To evaluate and validate our modeling at scale, 5000 certificates were reissued. Passive measurements were conducted on production traffic over two weeks, during which we also actively measured on the 5000 domains.
Sudheesh Singanamalla, Muhammad Talha Paracha, Suleman Ahmad, Jonathan Hoyland, Luke Valenta, Yevgen Safronov, Peter Wu, Andrew Galloni, Kurtis Heimerl, Nick Sullivan, Christopher A. Wood, Marwan Fayed
IMC5
2022 Might I Get Pwned: A Second Generation Compromised Credential Checking Service
Bijeeta Pal, Mazharul Islam 0002, Marina Sanusi Bohuk, Nick Sullivan, Luke Valenta, Tara Whalen, Christopher A. Wood, Thomas Ristenpart, Rahul Chatterjee 0001
USENIX Security Symposium5
2018 In Search of CurveSwap: Measuring Elliptic Curve Implementations in the Wild
abstract
We survey elliptic curve implementations from several vantage points. We perform internet-wide scans for TLS on a large number of ports, as well as SSH and IPsec to measure elliptic curve support and implementation behaviors, and collect passive measurements of client curve support for TLS. We also perform active measurements to estimate server vulnerability to known attacks against elliptic curve implementations, including support for weak curves, invalid curve attacks, and curve twist attacks. We estimate that 1.53% of HTTPS hosts, 0.04% of SSH hosts, and 4.04% of IKEv2 hosts that support elliptic curves do not perform curve validity checks as specified in elliptic curve standards. We describe how such vulnerabilities could be used to construct an elliptic curve parameter downgrade attack called CurveSwap for TLS, and observe that there do not appear to be combinations of weak behaviors we examined enabling a feasible CurveSwap attack in the wild. We also analyze source code for elliptic curve implementations, and find that a number of libraries fail to perform point validation for JSON Web Encryption, and find a flaw in the Java and NSS multiplication algorithms.
Luke Valenta, Nick Sullivan, Antonio Sanso, Nadia Heninger
EuroS&P1
2018 403 Forbidden: A Global View of CDN Geoblocking
Allison McDonald, Matthew Bernhard, Luke Valenta, Benjamin VanderSloot, Will Scott, Nick Sullivan, J. Alex Halderman, Roya Ensafi
Internet Measurement Conference3
2017 May the Fourth Be With You: A Microarchitectural Side Channel Attack on Several Real-World Applications of Curve25519
abstract
In recent years, applications increasingly adopt security primitives designed with better countermeasures against side channel attacks. A concrete example is Libgcrypt's implementation of ECDH encryption with Curve25519. The implementation employs the Montgomery ladder scalar-by-point multiplication, uses the unified, branchless Montgomery double-and-add formula and implements a constant-time argument swap within the ladder. However, Libgcrypt's field arithmetic operations are not implemented in a constant-time side-channel-resistant fashion.
Daniel Genkin, Luke Valenta, Yuval Yarom
CCS2
2017 Measuring small subgroup attacks against Diffie-Hellman
Luke Valenta, David Adrian, Antonio Sanso, Shaanan Cohney, Joshua Fried, Marcella Hastings, J. Alex Halderman, Nadia Heninger
NDSS1
2017 Post-quantum RSA
Daniel J. Bernstein, Nadia Heninger, Paul Lou, Luke Valenta
PQCrypto4
2016 DROWN: Breaking TLS Using SSLv2
Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger, Maik Dankel, Jens Steube, Luke Valenta, David Adrian, J. Alex Halderman, Viktor Dukhovni, Emilia Käsper, Shaanan Cohney, Susanne Engels, Christof Paar, Yuval Shavitt
USENIX Security Symposium7
2015 Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice
abstract
We investigate the security of Diffie-Hellman key exchange as used in popular Internet protocols and find it to be less secure than widely believed. First, we present Logjam, a novel flaw in TLS that lets a man-in-the-middle downgrade connections to "export-grade" Diffie-Hellman. To carry out this attack, we implement the number field sieve discrete log algorithm. After a week-long precomputation for a specified 512-bit group, we can compute arbitrary discrete logs in that group in about a minute. We find that 82% of vulnerable servers use a single 512-bit group, allowing us to compromise connections to 7% of Alexa Top Million HTTPS sites. In response, major browsers are being changed to reject short groups. We go on to consider Diffie-Hellman with 768- and 1024-bit groups. We estimate that even in the 1024-bit case, the computations are plausible given nation-state resources. A small number of fixed or standardized groups are used by millions of servers; performing precomputation for a single 1024-bit group would allow passive eavesdropping on 18% of popular HTTPS sites, and a second group would allow decryption of traffic to 66% of IPsec VPNs and 26% of SSH servers. A close reading of published NSA leaks shows that the agency's attacks on VPNs are consistent with having achieved such a break. We conclude that moving to stronger key exchange methods should be a priority for the Internet community.
David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green 0001, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, Paul Zimmermann 0001
CCS10
2015 Alibi Routing
abstract
There are several mechanisms by which users can gain insight into where their packets have gone, but no mechanisms allow users undeniable proof that their packets did not traverse certain parts of the world while on their way to or from another host. This paper introduces the problem of finding "proofs of avoidance": evidence that the paths taken by a packet and its response avoided a user-specified set of "forbidden" geographic regions. Proving that something did not happen is often intractable, but we demonstrate a low-overhead proof structure built around the idea of what we call "alibis": relays with particular timing constraints that, when upheld, would make it impossible to traverse both the relay and the forbidden regions.
Dave Levin, Youndo Lee, Luke Valenta, Victoria Lai, Cristian Lumezanu, Neil Spring, Bobby Bhattacharjee
SIGCOMM3