EDBT 2026 Demo / reviewers in the wild / expert
Kurt Friday
dblp:246/5571
· DBLP profile ↗
9ranked-venue papers
3as first author
6since 2021 · last 2024
0009-0009-0883-6615ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | DCPsolver: Enhancing DNS Cache Poisoning Defenses with Resolver-Based SmartNICsabstractThe Domain Name System (DNS) is a critical component of the internet infrastructure, yet it remains vulnerable to DNS Cache Poisoning (DCP) attacks, which can mislead users by redirecting them to malicious websites. Although various countermeasures have been proposed to safeguard DNS infrastructure, they predominantly address off-path attacks, leaving DNS resolvers susceptible to on-path attacks, and often face challenges in widespread adoption due to impractical deployment requirements. To address these shortcomings, we present a novel solution leveraging Smart Network Interface Cards (SmartNICs) to detect and mitigate both on-path and off-path DCP attacks in real-time. Our approach operates exclusively within recursive DNS resolvers, independent of existing DNS protocols and infrastructure, thereby enhancing practicality and deployability. The proposed methodology was rigorously evaluated using a comprehensive, recently-released dataset of DCP attacks. Results demonstrate that the SmartNIC-based solution accurately identifies and mitigates both attack types while efficiently leveraging hardware resources. Indeed, the approach detailed herein offers a practical, effective, and efficient solution for enhancing DNS security without the need for a widespread infrastructure overhaul. Bharath Kollanur, Kurt Friday, Elias Bou-Harb |
NCA | 2 |
| 2024 | On DGA Detection and Classification Using P4 Programmable Switches
Ali AlSabeh, Kurt Friday, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Secur. | 2 |
| 2023 | Effective DGA Family Classification Using a Hybrid Shallow and Deep Packet Inspection Technique on P4 Programmable SwitchesabstractDomain Generation Algorithms (DGAs) are one of the most effective strategies for malware to obtain a connection with the adversary's Command and Control (C2) server. Moreover, the growing number of DGA families makes it increasingly challenging for defense strategies to promptly identify the DGA family behind a given compromise. State-of-the-art high-dimensional DGA detection models perform poorly in such multiclass classification scenarios because their domain name-based features fail to distinguish between DGA families. To this extent, this paper proposes a novel framework that harnesses the flexibility, per-packet granularity, and Terabits per second (Tbps) processing capabilities of P4 Programmable Data Plane (PDP) switches to swiftly and accurately classify DGA families. In particular, the P4 PDP switch is leveraged to extract a combination of unique network heuristics and domain name features through shallow and Deep Packet Inspection (DPI) with minimal throughput reduction. Such collected features cannot be tracked on commodity hardware without significantly degrading the throughput in high-speed networks, nor on traditional layer 2/3 switches due to their limited and fixed functionalities. We crawled hundreds of Gigabytes (GBs) of malware samples from different sources to obtain instances of 50 DGA families and show that the proposed approach can promptly classify each family with high accuracy. Such a reliable multiclass classification enables the immediate halting of malicious communications while allowing network operators to initiate appropriate mitigation, incident management, and provisioning strategies. Ali AlSabeh, Kurt Friday, Jorge Crichigno, Elias Bou-Harb |
ICC | 2 |
| 2023 | A Comprehensive Survey of Recent Internet Measurement Techniques for Cyber SecurityabstractAs the Internet has transformed into a critical infrastructure, society has become more vulnerable to its security flaws. Despite substantial efforts to address many of these vulnerabilities by industry, government, and academia, cyber security attacks continue to increase in intensity, diversity, and impact. Thus, it becomes intuitive to investigate the current cyber security threats, assess the extent to which corresponding defenses have been deployed, and evaluate the effectiveness of risk mitigation efforts. Addressing these issues in a sound manner requires large-scale empirical data to be collected and analyzed via numerous Internet measurement techniques. Although such measurements can generate comprehensive and reliable insights, doing so encompasses complex procedures involving the development of novel methodologies to ensure accuracy and completeness. Therefore, a systematic examination of recently developed Internet measurement approaches for cyber security must be conducted to enable thorough studies that employ several vantage points, correlate multiple data sources, and potentially leverage past successful techniques for more recent issues. Unfortunately, performing such an examination is challenging, as the literature is highly scattered. In large part, this is due to each research effort only focusing on a small portion of the many constituent parts of the Internet measurement domain. Moreover, to the best of our knowledge, no studies have offered an in-depth examination of this critical research domain in order to promote future advancements. To bridge these gaps, we explore all pertinent facets of utilizing Internet measurement techniques for cyber security, ranging from threats within specific application domains to threats themselves. We provide a taxonomy of cyber security-related Internet measurement studies across two dimensions. One dimension relates to the many vertical layers (and components) of the Internet ecosystem, while the other relates to internal normal functions vs. the negative impact of external parties in the Internet and physical world. A comprehensive comparison of the gathered studies is also offered in terms of measurement technique, scope, measurement size, vantage size, and the analysis approach that was leveraged. Finally, a discussion of the roadblocks to performing effective Internet measurements and possible future research directions is elaborated. Morteza Safaei Pour, Christelle Nader, Kurt Friday, Elias Bou-Harb |
Comput. Secur. | 3 |
| 2022 | INC: In-Network Classification of Botnet Propagation at Line Rate
Kurt Friday, Elie F. Kfoury, Elias Bou-Harb, Jorge Crichigno |
ESORICS (1) | 1 |
| 2022 | A Learning Methodology for Line-Rate Ransomware Mitigation with P4 Switches
Kurt Friday, Elias Bou-Harb, Jorge Crichigno |
NSS | 1 |
| 2020 | Towards a Unified In-Network DDoS Detection and Mitigation StrategyabstractDistributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies. Kurt Friday, Elie F. Kfoury, Elias Bou-Harb, Jorge Crichigno |
NetSoft | 1 |
| 2020 | On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild
Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Sagar Samtani, Jorge Crichigno, Nasir Ghani |
Comput. Secur. | 3 |
| 2019 | Data-driven Curation, Learning and Analysis for Inferring Evolving IoT Botnets in the WildabstractThe insecurity of the Internet-of-Things (IoT) paradigm continues to wreak havoc in consumer and critical infrastructure realms. Several challenges impede addressing IoT security at large, including, the lack of IoT-centric data that can be collected, analyzed and correlated, due to the highly heterogeneous nature of such devices and their widespread deployments in Internet-wide environments. To this end, this paper explores macroscopic, passive empirical data to shed light on this evolving threat phenomena. This not only aims at classifying and inferring Internet-scale compromised IoT devices by solely observing such one-way network traffic, but also endeavors to uncover, track and report on orchestrated "in the wild" IoT botnets. Initially, to prepare the effective utilization of such data, a novel probabilistic model is designed and developed to cleanse such traffic from noise samples (i.e., misconfiguration traffic). Subsequently, several shallow and deep learning models are evaluated to ultimately design and develop a multi-window convolution neural network trained on active and passive measurements to accurately identify compromised IoT devices. Consequently, to infer orchestrated and unsolicited activities that have been generated by well-coordinated IoT botnets, hierarchical agglomerative clustering is deployed by scrutinizing a set of innovative and efficient network feature sets. By analyzing 3.6 TB of recent darknet traffic, the proposed approach uncovers a momentous 440,000 compromised IoT devices and generates evidence-based artifacts related to 350 IoT botnets. While some of these detected botnets refer to previously documented campaigns such as the Hide and Seek, Hajime and Fbot, other events illustrate evolving threats such as those with cryptojacking capabilities and those that are targeting industrial control system communication and control services. Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Khaled B. Shaban, Abdelkarim Erradi |
ARES | 3 |