Justin Cappos

dblp:27/5136 · DBLP profile ↗
← Back
47ranked-venue papers
10as first author
10since 2021 · last 2026
0000-0003-1926-8544ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 3 first-author · 6 since 2021Systems, architecture and hardware · 8 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 8 · 2 since 2021Human-computer interaction and ubiquitous computing · 8 · 2 first-author · 1 since 2021Computer networks · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorTheory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 SourceFabric: Consistent and Scalable Security Policies for Git Repositories
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Marcela S. Melara, Dennis Roellke, Reza Curtmola, Justin Cappos
EuroS&P6
2026 Enhancing Legal Document Security and Accessibility with TAF
Renata Vaderna, Dusan Nikolic, Patrick Zielinski, David Greisen, BJ Ard, Justin Cappos
NDSS6
2025 Rethinking Trust in Forge-Based Git Security
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Reza Curtmola, Justin Cappos
NDSS4
2024 CovSBOM: Enhancing Software Bill of Materials with Integrated Code Coverage Analysis
abstract
The widespread integration of open-source software into commercial codebases, government systems, and critical infrastructure presents significant security challenges, particularly due to the inclusion of vulnerable components. Software Bills of Materials (SBOMs) are crucial for tracking these components; however, they lack detailed insights into the actual utilization of each component, thereby limiting their effectiveness in vulnerability management. This paper introduces CovSBOM, a novel tool that integrates code coverage analysis into SBOMs to provide enhanced transparency and facilitate precise vulnerability detection. CovSBOM addresses the gap between current SBOM and security scanning tools by providing detailed insights into which parts of third-party libraries are actually being used, thereby reducing inefficiencies and the misallocation of developer resources caused by overemphasizing irrelevant vulnerabilities. Through a comprehensive evaluation of 23 large-scale applications, encompassing 1,614 dependencies and 145 vulnerability alerts, CovSBOM has demonstrated a significant reduction in false positives, accurately identifying 105 such instances. This improvement enhances the precision of vulnerability detection by approximately 72%, while effectively maintaining a reasonable level of scalability and usability.
Yunze Zhao, Dan Chacko, Justin Cappos
ISSRE4
2023 Artemis: Defanging Software Supply Chain Attacks in Multi-repository Update Systems
abstract
Modern software installation tools often use packages from more than one repository, presenting a unique set of security challenges. Such a configuration increases the risk of repository compromise and introduces attacks like dependency confusion and repository fallback. In this paper, we offer the first exploration of attacks that specifically target multiple repository update systems, and propose a unique defensive strategy we call articulated trust. Articulated trust is a principle that allows software installation tools to specify trusted developers and repositories for each package. To implement articulated trust, we built Artemis, a framework that introduces several new security techniques, such as per-package prioritization of repositories, multi-role delegations, multiple-repository consensus, and key pinning. These techniques allow for a greater diversity of trust relationships while eliminating the security risk of single points of failure.
Marina Moore, Trishank Karthik Kuppusamy, Justin Cappos
ACSAC3
2023 Towards verifiable web-based code review systems
abstract
Although code review is an essential step for ensuring the quality of software, it is surprising that current code review systems do not have mechanisms to protect the integrity of the code review process. We uncover multiple attacks against the code review infrastructure which are easy to execute, stealthy in nature, and can have a significant impact, such as allowing malicious or buggy code to be merged and propagated to future releases. To improve this status quo, in this work we lay the foundations for securing the code review process. Towards this end, we first identify a set of key design principles necessary to secure the code review process. We then use these principles to propose SecureReview , a security mechanism that can be applied on top of a Git-based code review system to ensure the integrity of the code review process and provide verifiable guarantees that the code review process followed the intended review policy. We implement SecureReview as a Chrome browser extension for GitHub and Gerrit. Our security analysis shows that SecureReview is effective in mitigating the aforementioned attacks. An experimental evaluation shows that the SecureReview implementation only adds a slight storage overhead ( i.e., less than 0.0006 of the repository size).
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
J. Comput. Secur.4
2022 Demo: EdgeNet, a Production Internet-Scale Container-Based Distributed System Testbed
abstract
The EdgeNet software is free, open-source, liberally licensed code that extends the Kubernetes container orchestration system to the edge cloud. We use this code to run the EdgeNet testbed, an internet-scale edge cloud for distributed systems researchers. This demonstration showcases three features of EdgeNet: its multitenancy model, its multi-provider aspect, and its geographically-based selective deployment capability. Multitenancy allows multiple teams to use the platform concurrently; being multi-provider, independent contributors can make nodes available to the platform; and selective deployment facilitates location-based placement of software. Under our guidance, demo participants invoke the Kubernetes command-line interface to use the testbed. In so doing, they get experience with the testbed, which they can continue to use afterwards. They also gain insight into how the demonstrated features are useful for edge cloud container deployment in general. Participants who volunteer to help EdgeNet nodes receive Odroid devices to host in their homes or workplaces.
Berat Can Senel, Maxime Mouchet, Justin Cappos, Timur Friedman, Olivier Fourmaux, Rick McGeer
ICDCS3
2022 Needles in a Haystack: Using PORT to Catch Bad Behaviors within Application Recordings
Preston Moore, Thomas Wies, Marc Waldman, Phyllis G. Frankl, Justin Cappos
ICSOFT5
2022 Bootstrapping Trust in Community Repository Projects
Sangat Vaidya, Santiago Torres-Arias, Justin Cappos, Reza Curtmola
SecureComm3
2022 Cybersecurity Shuffle: Using Card Magic to Introduce Cybersecurity Concepts
abstract
One of the main challenges in designing lessons for an introductory information security class is how to present new technical concepts in a manner comprehensible to students with widely different backgrounds. A non-traditional approach can help students engage with the material and master these unfamiliar ideas. We have devised a series of lessons that teach important information security topics, such as social engineering, side-channel attacks, and attacks on randomness using card magic. Each lesson centers around a card trick that allows the instructor to simulate the described attack in such a way that prior technical background is not required. In this work, we describe our experience using these lessons in teaching cybersecurity topics to high school students with limited computer science education. Students were assessed before and after the demonstration to gauge their mastery of the material, and their opinions on each lesson. Students indicated they enjoyed the lesson and their pre- and post-test scores improved by between 15% and 30%.
Preston Moore, Justin Cappos
SIGCSE (2)2
2020 Thinking aloud about confusing code: a qualitative investigation of program comprehension and atoms of confusion
abstract
Atoms of confusion are small patterns of code that have been empirically validated to be difficult to hand-evaluate by programmers. Previous research focused on defining and quantifying this phenomenon, but not on explaining or critiquing it. In this work, we address core omissions to the body of work on atoms of confusion, focusing on the ‘how’ and ‘why’ of programmer misunderstanding.
Daniel Gopstein, Anne-Laure Fayard, Sven Apel, Justin Cappos
ESEC/SIGSOFT FSE4
2020 Towards adding verifiability to web-based Git repositories
abstract
Web-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature – the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended. In this paper, we show a range of high-impact attacks that can be executed stealthily when developers use the web UI of a Git hosting service to perform common actions such as editing files or merging branches. We then propose le-git-imate , a defense against these attacks, which enables users to protect their commits using Git’s standard commit signing mechanism. We implement le-git-imate as a Chrome browser extension. le-git-imate does not require changes on the server side and can thus be used immediately. It also preserves current workflows used in Github/GitLab and does not require the user to leave the browser, and it allows anyone to verify that the server’s actions faithfully follow the user’s requested actions. Moreover, experimental evaluation using the browser extension shows that le-git-imate has comparable performance with Git’s standard commit signature mechanism. With our solution in place, users can take advantage of GitHub/GitLab’s web-based features without sacrificing security, thus paving the way towards verifiable web-based Git repositories.
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
J. Comput. Secur.4
2019 Charting a Course Through Uncertain Environments: SEA Uses Past Problems to Avoid Future Failures
abstract
A common problem for developers is applications exhibiting new bugs after deployment. Many of these bugs can be traced to unexpected network, operating system, and file system differences that cause program executions that were successful in a development environment to fail once deployed. Preventing these bugs is difficult because it is impractical to test an application in every environment. Enter Simulating Environmental Anomalies (SEA), a technique that utilizes evidence of one application's failure in a given environment to generate tests that can be applied to other applications, to see whether they suffer from analogous faults. In SEA, models of unusual properties extracted from interactions between an application, A, and its environment guide simulations of another application, B, running in the anomalous environment. This reveals faults B may experience in this environment without the expense of deployment. By accumulating these anomalies, applications can be tested against an increasing set of problematic conditions. We implemented a tool called CrashSimulator, which uses SEA, and evaluated it against Linux applications selected from coreutils and the Debian popularity contest. Our tests found a total of 63 bugs in 31 applications with effects including hangs, crashes, data loss, and remote denial of service conditions.
Preston Moore, Justin Cappos, Phyllis G. Frankl, Thomas Wies
ISSRE2
2019 Commit Signatures for Centralized Version Control Systems
Sangat Vaidya, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
SEC4
2019 in-toto: Providing farm-to-table guarantees for bits and bytes
Santiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola, Justin Cappos
USENIX Security Symposium5
2018 le-git-imate: Towards Verifiable Web-based Git Repositories
abstract
Web-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature - the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended.
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
AsiaCCS4
2018 Prevalence of confusing code in software projects: atoms of confusion in the wild
abstract
Prior work has shown that extremely small code patterns, such as the conditional operator and implicit type conversion, can cause considerable misunderstanding in programmers. Until now, the real world impact of these patterns - known as 'atoms of confusion' - was only speculative. This work uses a corpus of 14 of the most popular and influential open source C and C++ projects to measure the prevalence and significance of these small confusing patterns. Our results show that the 15 known types of confusing micro patterns occur millions of times in programs like the Linux kernel and GCC, appearing on average once every 23 lines. We show there is a strong correlation between these confusing patterns and bug-fix commits as well as a tendency for confusing patterns to be commented. We also explore patterns at the project level showing the rate of security vulnerabilities is higher in projects with more atoms. Finally, we examine real code examples containing these atoms, including ones that were used to find and fix bugs in our corpus. In total this work demonstrates that beyond simple misunderstanding in the lab setting, atoms of confusion are both prevalent - occurring often in real projects, and meaningful - being removed by bug-fix commits at an elevated rate.
Daniel Gopstein, Hongwei Henry Zhou, Phyllis G. Frankl, Justin Cappos
MSR4
2018 Tsumiki: A Meta-Platform for Building Your Own Testbed
abstract
Network testbeds are essential research tools that have been responsible for valuable network measurements and major advances in distributed systems research. However, no single testbed can satisfy the requirements of every research project, prompting continual efforts to develop new testbeds. The common practice is to re-implement functionality anew for each testbed. This work introduces a set of ready-to-use software components and interfaces called Tsumiki to help researchers to rapidly prototype custom networked testbeds without substantial effort. We derive Tsumiki's design using a set of component and interface design principles, and demonstrate that Tsumiki can be used to implement new, diverse, and useful testbeds. We detail a few such testbeds: a testbed composed of Android devices, a testbed that uses Docker for sandboxing, and a testbed that shares computation and storage resources among Facebook friends. A user study demonstrated that students with no prior experience with networked testbeds were able to use Tsumiki to create a testbed with new functionality and run an experiment on this testbed in under an hour. Furthermore, Tsumiki has been used in production in multiple testbeds, resulting in installations on tens of thousands of devices and use by thousands of researchers.
Justin Cappos, Yanyan Zhuang, Albert Rafetseder, Ivan Beschastnikh
IEEE Trans. Parallel Distributed Syst.1
2017 Understanding misunderstandings in source code
abstract
Humans often mistake the meaning of source code, and so misjudge a program's true behavior. These mistakes can be caused by extremely small, isolated patterns in code, which can lead to significant runtime errors. These patterns are used in large, popular software projects and even recommended in style guides. To identify code patterns that may confuse programmers we extracted a preliminary set of `atoms of confusion' from known confusing code. We show empirically in an experiment with 73 participants that these code patterns can lead to a significantly increased rate of misunderstanding versus equivalent code without the patterns. We then go on to take larger confusing programs and measure (in an experiment with 43 participants) the impact, in terms of programmer confusion, of removing these confusing patterns. All of our instruments, analysis code, and data are publicly available online for replication, experimentation, and feedback.
Daniel Gopstein, Jake Iannacone, Lois DeLong, Yanyan Zhuang, Martin K.-C. Yeh, Justin Cappos
ESEC/SIGSOFT FSE7
2017 Mercury: Bandwidth-Effective Prevention of Rollback Attacks Against Community Repositories
Trishank Karthik Kuppusamy, Vladimir Diaz, Justin Cappos
USENIX ATC3
2017 Lock-in-Pop: Securing Privileged Operating System Kernels by Keeping on the Beaten Path
Brendan Dolan-Gavitt, Sam Weber 0001, Justin Cappos
USENIX ATC4
2017 CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified Builds
Kirill Nikitin 0001, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Justin Cappos, Bryan Ford
USENIX Security Symposium7
2016 Finding Sensitive Accounts on Twitter: An Automated Approach Based on Follower Anonymity
Sai Teja Peddinti, Keith W. Ross, Justin Cappos
ICWSM3
2016 Diplomat: Using Delegations to Protect Community Repositories
Trishank Karthik Kuppusamy, Santiago Torres-Arias, Vladimir Diaz, Justin Cappos
NSDI4
2016 On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities
Santiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin Cappos
USENIX Security Symposium4
2015 A Fast Multi-Server, Multi-Block Private Information Retrieval Protocol
abstract
Private Information Retrieval (PIR) allows users to retrieve information from a database without revealing the content of these queries to anyone. The traditional information-theoretic PIR schemes utilize multiple servers to download single data block, thus incur high communication overhead and high computation burden. In this paper, we develop an Information- theoretic multi-block PIR scheme that significantly reduce the client communication and computation overheads by downloading multiple data blocks at a time. The design of k-safe binary matrices insures the information will not be revealed even if up to k servers collude. Our scheme has much lower overhead than the classic PIR schemes. The implementation of fast XOR operations benefits both servers and clients in reducing coding and decoding time. Our work demonstrates that multi-block PIR scheme can be optimized to simultaneously achieve low communication and computation overhead, comparable to even non-PIR systems, while maintaining a high level of privacy.
Luqin Wang, Trishank Karthik Kuppusamy, Yong Liu 0013, Justin Cappos
GLOBECOM4
2015 Detecting latent cross-platform API violations
abstract
Many APIs enable cross-platform system development by abstracting over the details of a platform, allowing application developers to write one implementation that will run on a wide variety of platforms. Unfortunately, subtle differences in the behavior of the underlying platforms make cross-platform behavior difficult to achieve. As a result, applications using these APIs can be plagued by bugs difficult to observe before deployment. These portability bugs can be particularly difficult to diagnose and fix because they arise from the API implementation, the operating system, or hardware, rather than application code. This paper describes CheckAPI, a technique for detecting violations of cross-platform portability. CheckAPI compares an application's interactions with the API implementation to its interactions with a partial specification-based API implementation, and does so efficiently enough to be used in real production systems and at runtime. CheckAPI finds latent errors that escape pre-release testing. This paper discusses the subtleties of different kinds of API calls and strategies for effectively producing the partial implementations. Validating CheckAPI on JavaScript, the Seattle project's Repy VM, and POSIX detects dozens of violations that are confirmed bugs in widely-used software.
Jeff Rasley, Eleni Gessiou, Tony Ohmann, Yuriy Brun, Shriram Krishnamurthi, Justin Cappos
ISSRE6
2015 Can the Security Mindset Make Students Better Testers?
abstract
Writing secure code requires a programmer to think both as a defender and an attacker. One can draw a parallel between this model of thinking and techniques used in test-driven development, where students learn by thinking about how to effectively test their code and anticipate possible bugs. In this study, we analyzed the quality of both attack and defense code that students wrote for an assignment given in an introductory security class of 75 (both graduate and senior undergraduate levels) at NYU. We made several observations regarding students' behaviors and the quality of both their defensive and offensive code. We saw that student defensive programs (i.e., assignments) are highly unique and that their attack programs (i.e., test cases) are also relatively unique. In addition, we examined how student behaviors in writing defense programs correlated with their attack program's effectiveness. We found evidence that students who learn to write good defensive programs can write effective attack programs, but the converse is not true. While further exploration of causality is needed, our results indicate that a greater pedagogical emphasis on defensive security may benefit students more than one that emphasizes offense.
Sara Hooshangi, Richard Weiss 0001, Justin Cappos
SIGCSE3
2015 Teaching Security Using Hands-on Exercises in 2015 (Abstract Only)
abstract
We see teaching cybersecurity through hands-on, interactive exercises as a way to engage students. Some of the exercises that we have seen require significant preparation on the part of the instructor. Having a community makes it easier to share exercises, knowing what works and what problems students and instructors have encountered. The purpose of this BOF is to bring together instructors who have developed hands-on exercises, those who have used them and those who would like to. We recognize that few CS programs can afford new required courses, so we will discuss ways to integrate security-related exercises into existing ones. This could include networking, OS, computer architecture, programming languages, software engineering, algorithms and programming. The questions we will ask are, "What exercises have you tried? What are your experiences? What are you looking for?"
Richard Weiss 0001, Michael E. Locasto, Jens Mache, Blair Taylor, Elizabeth K. Hawthorne, Justin Cappos, Ambareen Siraj
SIGCSE6
2015 Fence: Protecting Device Availability With Uniform Resource Control
Albert Rafetseder, Rodrigo Fonseca, Justin Cappos
USENIX ATC4
2015 Selectively Taming Background Android Apps to Improve Battery Lifetime
Marcelo Martins, Justin Cappos, Rodrigo Fonseca
USENIX ATC2
2014 It's the psychology stupid: how heuristics explain software vulnerabilities and how priming can illuminate developer's blind spots
abstract
Despite the security community's emphasis on the importance of building secure software, the number of new vulnerabilities found in our systems is increasing. In addition, vulnerabilities that have been studied for years are still commonly reported in vulnerability databases. This paper investigates a new hypothesis that software vulnerabilities are blind spots in developer's heuristic-based decision-making processes. Heuristics are simple computational models to solve problems without considering all the information available. They are an adaptive response to our short working memory because they require less cognitive effort. Our hypothesis is that as software vulnerabilities represent corner cases that exercise unusual information flows, they tend to be left out from the repertoire of heuristics used by developers during their programming tasks.
Daniela Oliveira 0001, Marissa Rosenthal, Nicole Morin, Martin K.-C. Yeh, Justin Cappos, Yanyan Zhuang
ACSAC5
2014 NetCheck: Network Diagnoses from Blackbox Traces
Yanyan Zhuang, Eleni Gessiou, Steven Portzer, Fraida Fund, Monzur Muhammad, Ivan Beschastnikh, Justin Cappos
NSDI7
2014 Vulnerabilities as Blind Spots in Developer's Heuristic-Based Decision-Making Processes
abstract
The security community spares no effort in emphasizing security awareness and the importance of building secure software. However, the number of new vulnerabilities found in today's systems is still increasing. Furthermore, old and well-studied vulnerability types such as buffer overflows and SQL injections, are still repeatedly reported in vulnerability databases. Historically, the common response has been to blame the developers for their lack of security education. This paper discusses a new hypothesis to explain this problem by introducing a new security paradigm where software vulnerabilities are viewed as developers' blind spots in their decision making. We argue that such a flawed mental process is heuristic-based, where humans solve problems without considering all the information available, just like taking shortcuts. This paper's thesis is that security thinking tends to be left out by developers during their programming, as vulnerabilities usually exist in corner cases with unusual information flows. Leveraging this paradigm, this paper introduces a novel methodology for capturing and understanding security-related blind spots in Application Programming Interfaces (APIs). Finally, it discusses how this methodology can be applied to the design and implementation of the next generation of automated diagnosis tools.
Justin Cappos, Yanyan Zhuang, Daniela Oliveira 0001, Marissa Rosenthal, Martin K.-C. Yeh
NSPW1
2014 Teaching the security mindset with reference monitors
abstract
One of the central skills in computer security is reasoning about how programs fail. As a result, computer security necessarily involves thinking about the corner cases that arise when software executes. An unfortunate side effect of this is that computer security assignments typically necessitate deep understanding of a topic, such as how the stack is laid out in memory or how web applications interact with databases. This work presents a series of assignments that require very little background knowledge from students, yet provide them with the ability to reason about failures in programs. In this set of assignments, students implement two very simple programs in a high-level language (Python). Students first implement a reference monitor that tries to uphold a security property within a sandbox. For the second portion, the students are provided each others' reference monitors and then write attack code to try to bypass the reference monitors. By leveraging a Python-based sandbox, student code is isolated cleanly, which simplifies development and grading. These assignments have been used in about a dozen classes in a range of environments, including a research university, online classes, and a four year liberal arts school. Student and instructor feedback has been overwhelmingly positive. Furthermore, survey results demonstrate that after a 2-3 week module, 76% of the students who did not understand reference monitors and access control learned these key security concepts.
Justin Cappos, Richard Weiss 0001
SIGCSE1
2014 Teaching security using hands-on exercises (abstract only)
abstract
We see teaching information security through hands-on, interactive exercises as a way to engage students. Some of the exercises that we have tried require significant preparation on the part of the instructor. Having a community makes it easier to share exercises, knowing what works and what problems students and instructors have encountered. The purpose of this BOF is to bring together instructors who have used hands-on exercises and those who would like to. We recognize that few CS programs can afford new required courses, so we would be discussing ways to integrate security-related exercises into existing ones. This could include networking, OS, computer architecture, programming languages, software engineering and algorithms. The questions we will ask are, "What exercises, if any, have you tried" What are your experiences? What are you looking for?
Richard Weiss 0001, Michael E. Locasto, Jens Mache, Elizabeth K. Hawthorne, Justin Cappos
SIGCSE5
2010 Retaining sandbox containment despite bugs in privileged memory-safe code
abstract
Flaws in the standard libraries of secure sandboxes represent a major security threat to billions of devices worldwide. The standard libraries are hard to secure because they frequently need to perform low-level operations that are forbidden in untrusted application code. Existing designs have a single, large trusted computing base that contains security checks at the boundaries between trusted and untrusted code. Unfortunately, flaws in the standard library often allow an attacker to escape the security protections of the sandbox.
Justin Cappos, Armon Dadgar, Jeff Rasley, Justin Samuel, Ivan Beschastnikh, Cosmin Barsan, Arvind Krishnamurthy, Thomas E. Anderson
CCS1
2010 Survivable key compromise in software update systems
abstract
Today's software update systems have little or no defense against key compromise. As a result, key compromises have put millions of software update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure software updates. Analyzing existing software update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current software update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow software update systems to survive key compromise. Using these ideas, we design and implement TUF, a software update framework that increases resilience to key compromise.
Justin Samuel, Nick Mathewson, Justin Cappos, Roger Dingledine
CCS3
2009 Rhizoma: A Runtime for Self-deploying, Self-managing Overlays
Qin Yin, Adrian Schüpbach, Justin Cappos, Andrew Baumann, Timothy Roscoe
Middleware3
2009 Seattle: a platform for educational cloud computing
abstract
Cloud computing is rapidly increasing in popularity. Companies such as RedHat, Microsoft, Amazon, Google, and IBM are increasingly funding cloud computing infrastructure and research, making it important for students to gain the necessary skills to work with cloud-based resources. This paper presents a free, educational research platform called Seattle that is community-driven, a common denominator for diverse platform types, and is broadly deployed.
Justin Cappos, Ivan Beschastnikh, Arvind Krishnamurthy, Thomas E. Anderson
SIGCSE1
2009 Simultaneous graph embedding with bends and circular arcs
Justin Cappos, Alejandro Estrella-Balderrama, J. Joseph Fowler, Stephen G. Kobourov
Comput. Geom.1
2008 A look in the mirror: attacks on package managers
abstract
This work studies the security of ten popular package managers. These package managers use different security mechanisms that provide varying levels of usability and resilience to attack. We find that, despite their existing security mechanisms, all of these package managers have vulnerabilities that can be exploited by a man-in-the-middle or a malicious mirror. While all current package managers suffer from vulnerabilities, their security is also positively or negatively impacted by the distribution's security practices. Weaknesses in package managers are more easily exploited when distributions use third-party mirrors as official mirrors. We were successful in using false credentials to obtain an official mirror on all five of the distributions we attempted. We also found that some security mechanisms that control where a client obtains metadata and packages from may actually decrease security. We analyze current package managers to show that by exploiting vulnerabilities, an attacker with a mirror can compromise or crash hundreds to thousands of clients weekly. The problems we disclose are now being corrected by many different package manager maintainers.
Justin Cappos, Justin Samuel, Scott M. Baker, John H. Hartman
CCS1
2008 San Fermín: Aggregating Large Data Sets Using a Binomial Swap Forest
Justin Cappos, John H. Hartman
NSDI1
2007 Stork: Package Management for Distributed VM Environments
Justin Cappos, Scott M. Baker, Jeremy Plichta, Duy Nguyen 0002, Jason Hardies, Matt Borgard, Jeffry Johnston, John H. Hartman
LISA1
2006 Simultaneous Graph Embedding with Bends and Circular Arcs
Justin Cappos, Alejandro Estrella-Balderrama, J. Joseph Fowler, Stephen G. Kobourov
GD1
2005 Collaboration with DiamondTouch
Stephen G. Kobourov, Kyriacos E. Pavlou, Justin Cappos, Michael Stepp, Mark Miles, Amanda Wixted
INTERACT3
2005 Proper: Privileged Operations in a Virtualised System Environment
Steve Muir, Larry L. Peterson, Marc E. Fiuczynski, Justin Cappos, John H. Hartman
USENIX ATC, General Track4