Jack Wampler

dblp:236/6947 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
1since 2021 · last 2021
0009-0005-8785-0570ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Network security · 55% Hardware security and side channels · 25% Malware analysis · 20%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Reconfigurable computing and FPGAs · 77% Processor architecture and microarchitecture · 23%
Computer networks
1 paper
Internet architecture and protocols · 100%

Topics — the 7 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › anonymity networks
censorship circumvention
0.522020
Conjure: Summoning Proxies from Unused Address Space · CCS 2019
Detecting Probe-resistant Proxies · NDSS 2020
Network security
traffic analysis
0.412020
Detecting Probe-resistant Proxies · NDSS 2020
Hardware security and side channels › integrated circuit security
FPGA security
0.412019
Breaking the Trust Dependence on Third Party Processes for Reconfigurable Secure Hardware · FPGA 2019
Malware analysis
malware detection evasion
0.412019
ExSpectre: Hiding Malware in Speculative Execution · NDSS 2019
Network security
anonymity networks
0.112020
Detecting Probe-resistant Proxies · NDSS 2020
Hardware security and side channels › trusted execution environments
remote attestation
0.112019
Breaking the Trust Dependence on Third Party Processes for Reconfigurable Secure Hardware · FPGA 2019
Processor architecture and microarchitecture
speculative execution
0.112019
ExSpectre: Hiding Malware in Speculative Execution · NDSS 2019

Methods — techniques the papers use, named apart from their topics

side channel · 0.8self-provisioning · 0.8secure update mechanism · 0.8active probing · 0.4
YearPublicationVenuePosition
2021 NATting Else Matters: Evaluating IPv6 Access Control Policies in Residential Networks
Karl Olson, Jack Wampler, Nolen Scaife
PAM2
2020 Detecting Probe-resistant Proxies
Sergey Frolov, Jack Wampler, Eric Wustrow
NDSS2
2020 Running Refraction Networking for Real
abstract
Abstract Refraction networking is a next-generation censorship circumvention approach that locates proxy functionality in the network itself, at participating ISPs or other network operators. Following years of research and development and a brief pilot, we established the world’s first production deployment of a Refraction Networking system. Our deployment uses a highperformance implementation of the TapDance protocol and is enabled as a transport in the popular circumvention app Psiphon. It uses TapDance stations at four physical uplink locations of a mid-sized ISP, Merit Network, with an aggregate bandwidth of 140 Gbps. By the end of 2019, our system was enabled as a transport option in 559,000 installations of Psiphon, and it served upwards of 33,000 unique users per month. This paper reports on our experience building the deployment and operating it for the first year. We describe how we overcame engineering challenges, present detailed performance metrics, and analyze how our system has responded to dynamic censor behavior. Finally, we review lessons learned from operating this unique artifact and discuss prospects for further scaling Refraction Networking to meet the needs of censored users.
Benjamin VanderSloot, Sergey Frolov, Jack Wampler, Sze Chuen Tan, Irv Simpson, Michael G. Kallitsis, J. Alex Halderman, Nikita Borisov, Eric Wustrow
Proc. Priv. Enhancing Technol.3
2019 Conjure: Summoning Proxies from Unused Address Space
abstract
Refraction Networking (formerly known as "Decoy Routing") has emerged as a promising next-generation approach for circumventing Internet censorship. Rather than trying to hide individual circumvention proxy servers from censors, proxy functionality is implemented in the core of the network, at cooperating ISPs in friendly countries. Any connection that traverses these ISPs could be a conduit for the free flow of information, so censors cannot easily block access without also blocking many legitimate sites. While one Refraction scheme, TapDance, has recently been deployed at ISP-scale, it suffers from several problems: a limited number of "decoy" sites in realistic deployments, high technical complexity, and undesirable tradeoffs between performance and observability by the censor. These challenges may impede broader deployment and ultimately allow censors to block such techniques. We present Conjure, an improved Refraction Networking approach that overcomes these limitations by leveraging unused address space at deploying ISPs. Instead of using real websites as the decoy destinations for proxy connections, our scheme connects to IP addresses where no web server exists leveraging proxy functionality from the core of the network. These phantom hosts are difficult for a censor to distinguish from real ones, but can be used by clients as proxies. We define the Conjure protocol, analyze its security, and evaluate a prototype using an ISP testbed. Our results suggest that Conjure can be harder to block than TapDance, is simpler to maintain and deploy, and offers substantially better network performance.
Sergey Frolov, Jack Wampler, Sze Chuen Tan, J. Alex Halderman, Nikita Borisov, Eric Wustrow
CCS2
2019 Breaking the Trust Dependence on Third Party Processes for Reconfigurable Secure Hardware
abstract
Modern CPU designs are beginning to incorporate secure hardware features, but leave developers with little control over both the set of features and when and whether updates are available. Reconfigurable logic (e.g., FPGAs) has been proposed as an alternative as it is both hardware, so can have similar capabilities at a reasonable performance degradation, and programmable, allowing customization of the secure hardware. This programmability, however, opens new attack vectors that allow an adversary to re-program the FPGA. Past attempts to solve this rely on a party maintaining a shared key with the FPGA, but these business processes to keep that key secret have been shown to be quite vulnerable. In this paper, we propose a new mechanism which eliminates the trust dependence on third party processes. This new mechanism consists of a self-provisioning stage, where keys are generated internal to the FPGA and never exposed externally, coupled with a secure update mechanism which allows updates to be governed by a policy defined by the secure hardware application. To demonstrate, we fully implemented these mechanisms on a Xilinx Zynq UltraScale+ FPGA along with an example secure co-processor with remote attestation with a flexible root of trust (in contrast to Intel SGX which fixes the root of trust to be Intel). Our performance evaluation of two applications, a password manager and a contact matching application, illustrates using FPGAs is practical.
Aimee Coughlin, Greg Cusack, Jack Wampler, Eric Keller, Eric Wustrow
FPGA3
2019 ExSpectre: Hiding Malware in Speculative Execution
Jack Wampler, Ian Martiny, Eric Wustrow
NDSS1