Ercan Ozturk

dblp:205/2579 · also Ercan Oztürk · DBLP profile ↗
← Back
7ranked-venue papers
0as first author
5since 2021 · last 2023
0000-0002-8789-8372ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 since 2021
YearPublicationVenuePosition
2023 VICEROY: GDPR-/CCPA-compliant Enforcement of Verifiable Accountless Consumer Requests
Scott Jordan 0001, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik
NDSS3
2023 Parakeet: Practical Key Transparency for End-to-End Encrypted Messaging
Harjasleen Malvai, Eleftherios Kokoris-Kogias, Alberto Sonnino, Esha Ghosh, Ercan Ozturk, Kevin Lewi, Sean F. Lawlor
NDSS5
2023 An Empirical Study & Evaluation of Modern CAPTCHAs
Andrew Searles, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik, Ai Enkoji
USENIX Security Symposium3
2023 Balancing Security and Privacy in Genomic Range Queries
abstract
Exciting recent advances in genome sequencing, coupled with greatly reduced storage and computation costs, make genomic testing increasingly accessible to individuals. Already today, one’s digitized DNA can be easily obtained from a sequencing lab and later used to conduct numerous tests by engaging with a testing facility. Due to the inherent sensitivity of genetic material and the often-proprietary nature of genomic tests, privacy is a natural and crucial issue. While genomic privacy received a great deal of attention within and outside the research community, genomic security has not been sufficiently studied. This is surprising since the usage of fake or altered genomes can have grave consequences, such as erroneous drug prescriptions and genetic test outcomes. Unfortunately, in the genomic domain, privacy and security (as often happens) are at odds with each other. In this article, we attempt to reconcile security with privacy in genomic testing by designing a novel technique for a secure and private genomic range query protocol between a genomic testing facility and an individual user. The proposed technique ensures authenticity and completeness of user-supplied genomic material while maintaining its privacy by releasing only the minimum thereof. To confirm its broad usability, we show how to apply the proposed technique to a previously proposed genomic private substring matching protocol. Experiments show that the proposed technique offers good performance and is quite practical. Furthermore, we generalize the genomic range query problem to sparse integer sets and discuss potential use cases.
Seoyeon Hwang, Ercan Ozturk, Gene Tsudik
ACM Trans. Priv. Secur.2
2021 CACTI: Captcha Avoidance via Client-side TEE Integration
Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, Gene Tsudik
USENIX Security Symposium2
2019 Thermanator: Thermal Residue-Based Post Factum Attacks on Keyboard Data Entry
abstract
Being warm-blooded mammals, we humans routinely leave thermal residues on various objects with which we come in contact. This includes common input devices, such as keyboards, that are used for entering (among other things) secret information, such as passwords and PINs. Although thermal residue dissipates over time, there is always a certain time window during which thermal energy readings can be harvested from input devices to recover recently entered, and potentially sensitive, information. To-date, there has been no systematic investigation of thermal profiles of keyboards, and thus no efforts have been made to secure them. This serves as our main motivation for constructing a means for password harvesting from keyboard thermal emanations. Specifically, we introduce Thermanator, a new post factum insider attack based on heat transfer caused by a user typing a password on a typical external keyboard. We conduct and describe a user study that collected thermal residues from 30 users entering 10 unique passwords (both weak and strong) on 4 popular commodity keyboards. Results show that entire sets of key-presses can be recovered by non-expert users as late as 30 seconds after initial password entry, while partial sets can be recovered as late as 1 minute after entry. Furthermore, we find that Hunt-and-Peck typists are particularly vulnerable. The take-away of our work is three-fold: (1) using keyboards to enter passwords is even less secure than previously recognized, (2) post factum (either planned or impromptu) thermal imaging attacks are realistic, and (3) we should either stop using keyboards for password entry, or abandon passwords altogether.
Tyler Kaczmarek, Ercan Ozturk, Gene Tsudik
AsiaCCS2
2018 Assentication: User De-authentication and Lunchtime Attack Mitigation with Seated Posture Biometric
Tyler Kaczmarek, Ercan Ozturk, Gene Tsudik
ACNS2