Jonathan M. Spring

dblp:170/1882 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
2since 2021 · last 2023
0000-0001-9356-219XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2023 An analysis of how many undiscovered vulnerabilities remain in information systems
Jonathan M. Spring
Comput. Secur.1
2021 Accurately Measuring Global Risk of Amplification Attacks using AmpMap
Soo-Jin Moon, Yucheng Yin, Rahul Anand Sharma, Jonathan M. Spring, Vyas Sekar
USENIX Security Symposium5
2020 On managing vulnerabilities in AI/ML systems
abstract
This paper explores how the current paradigm of vulnerability management might adapt to include machine learning systems through a thought experiment: what if flaws in machine learning (ML) were assigned Common Vulnerabilities and Exposures (CVE) identifiers (CVE-IDs)? We consider both ML algorithms and model objects. The hypothetical scenario is structured around exploring the changes to the six areas of vulnerability management: discovery, report intake, analysis, coordination, disclosure, and response. While algorithm flaws are well-known in academic research community, there is no apparent clear line of communication between this research community and the operational communities that deploy and manage systems that use ML. The thought experiments identify some ways in which CVE-IDs may establish some useful lines of communication between these two communities. In particular, it would start to introduce the research community to operational security concepts, which appears to be a gap left by existing efforts.
Jonathan M. Spring, April Galyardt, Allen D. Householder, Nathan M. VanHoudnos
NSPW1
2019 Why Jenny can't figure out which of these messages is a covert information operation
abstract
We view foreign interference in US and UK elections via social manipulation through the lens of usable security. Our goal is to provide advice on what interventions on the socio-technical election system are likely to work, and which are likely to fail. Strategies that the usable security literature indicates are likely to work are those that (1) avoid overloading the user's primary task; (2) help people understand negative consequences of their actions; and (3) support the long-term education of users with analytic reasoning skills and adequate background knowledge. Several of the responses to election interference proposed by governments and technology companies so far do not abide by these recommendations and are likely to be ineffective.
Tristan Caulfield, Jonathan M. Spring, M. Angela Sasse
NSPW2
2017 Practicing a Science of Security: A Philosophy of Science Perspective
abstract
Our goal is to refocus the question about cybersecurity research from 'is this process scientific' to 'why is this scientific process producing unsatisfactory results'. We focus on five common complaints that claim cybersecurity is not or cannot be scientific. Many of these complaints presume views associated with the philosophical school known as Logical Empiricism that more recent scholarship has largely modified or rejected. Modern philosophy of science, supported by mathematical modeling methods, provides constructive resources to mitigate all purported challenges to a science of security. Therefore, we argue the community currently practices a science of cybersecurity. A philosophy of science perspective suggests the following form of practice: structured observation to seek intelligible explanations of phenomena, evaluating explanations in many ways, with specialized fields (including engineering and forensics) constraining explanations within their own expertise, inter-translating where necessary. A natural question to pursue in future work is how collecting, evaluating, and analyzing evidence for such explanations is different in security than other sciences.
Jonathan M. Spring, Tyler Moore 0001, David J. Pym
NSPW1
2014 The Long "Taile" of Typosquatting Domain Names
Janos Szurdi, Balazs Kocso, Gabor Cseh, Jonathan M. Spring, Márk Félegyházi, Chris Kanich
USENIX Security Symposium4