EDBT 2026 Demo / reviewers in the wild / expert
Adam Doupé
dblp:28/8280
· DBLP profile ↗
76ranked-venue papers
8as first author
47since 2021 · last 2026
0000-0003-2634-3901ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 66 · 7 first-author · 39 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 3 since 2021Computer networks · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ARVO: Atlas of Reproducible Vulnerabilities for Open-Source SoftwareabstractAchieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at the cost of the others. In practice, reproducibility has been the dimension most often neglected. This has limited what can be automatically extracted from historical bug datasets, and has reduced their utility for downstream security research. In this work, we propose a method to produce a new security dataset which ensures reproducibility for diverse vulnerabilities at scale by identifying the key obstacles to large-scale bug reproduction and addressing them with general solutions. Using this method, we introduce full reproducibility to the largest open source software vulnerability dataset (OSS-Fuzz) and construct the ARVO dataset (an Atlas of Reproducible Vulnerabilities in Open-source software). ARVO is a large-scale dataset consisting of over 6,100 real-world vulnerabilities across 311 projects. Focusing on reproducibility, ARVO differs from existing datasets by providing each vulnerability in a form that can be consistently rebuilt, triggered, and analyzed across versions. Reproducibility also enables automatic identification of the corresponding patch for each vulnerability and supports direct interaction with vulnerabilities after code changes, capabilities that existing large-scale datasets do not provide. In our evaluation, ARVO successfully reproduces 81% of vulnerabilities and achieves 89.4% accuracy on the located patches. We also discuss ARVO's influence on both upstream practices and downstream security research. Xiang Mei, Jordi Del Castillo, Pulkit Singh Singaria, Haoran Xi, Abdelouahab Benchikh, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Hammond A. Pearce, Brendan Dolan-Gavitt |
EuroS&P | 9 |
| 2026 | Fragile Deliveries: Inconsistencies in Android Parcel and Their Security ConsequencesabstractThe Parcel mechanism is a key component in inter-process communication in Android. However, due to the lack of security considerations, incorrect implementation of the Parcel mechanism can lead to security vulnerabilities. In the past decade, these security vulnerabilities have impacted numerous Android users. In this paper, we identify two major security issues of the Parcel mechanism. First, the reading and writing components are implemented inconsistently in some Parcelable classes, compromising data integrity. Second, malformed Parcels introduce the potential for Denial-of-Service (DoS) attacks on critical apps. We then describe two types of attacks to exploit these two issues: a privilege escalation attack and the Malformed Parcel DoS attack, the latter of which renders phones unusable and prevents users from accessing critical services. To understand the scope of our proposed attacks across the entire Android ecosystem, we perform the first large-scale analysis on 324 Android firmware samples and 10,161 Android apps. Among them, we identify 36 unique data mismatch vulnerabilities and 3,858 apps vulnerable to the DoS attack. We responsibly disclosed our findings to vendors, and 10 of them have been confirmed. Finally, we propose mitigations against the attacks. Chao Wang 0113, Yuqing Yang 0003, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Zhiqiang Lin 0001, Yan Shoshitaishvili |
MobiSys | 7 |
| 2026 | Decompiling the Synergy: An Empirical Study of Human-LLM Teaming in Software Reverse Engineering
Zion Leonahenahe Basque, Samuele Doria, Ananta Soneji, Wil Gibbs, Adam Doupé, Yan Shoshitaishvili, Eleonora Losiouk, Ruoyu Wang 0001, Simone Aonzo |
NDSS | 5 |
| 2026 | Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine Recovery
Fangzhou Dong, Arvind S. Raj, Efrén López-Morales, Yan Shoshitaishvili, Tiffany Bao, Adam Doupé, Muslum Ozgur Ozmen, Ruoyu Wang 0001 |
NDSS | 7 |
| 2026 | ropbot: Reimaging Code Reuse Attack Synthesis
Kyle Zeng, Moritz Schloegel, Christopher Salls, Adam Doupé, Ruoyu Wang 0001, Yan Shoshitaishvili, Tiffany Bao |
NDSS | 4 |
| 2026 | Open Cybersecurity Education: Five Years of pwn.collegeabstractOver five years, pwn.college evolved from a demanding upper-division cybersecurity elective into a global, continuously running learning ecosystem—free and open to the world—with more than 50,000 learners having solved at least one challenge. As participation expanded beyond a single university cohort, the curriculum itself stopped functioning as a semester-bounded artifact and became a continuously lived experience, with learners engaging year-round and improvements propagating immediately. At this scale, thousands of learners effectively ''playtest'' the platform and its curriculum in real time, surfacing issues invisible in conventional courses and creating a feedback loop that improves the material our university students use. Voluntary global participants often persisted longer than enrolled students, became the most active mentors, and contributed significantly to refining both content and infrastructure. This ecosystem is anchored by incremental, education-first CTF challenges delivered through DOJO and supported by Twitch instruction, YouTube archives, and near-real-time peer help on Discord. Yet an always-on, openly archived curriculum also introduces tensions, including a form of ''digital archaeology'' in which past debugging sessions become both learning scaffolds and tempting shortcuts. Opening a CTF-based cybersecurity course to the world did not merely scale enrollment—it fundamentally changed the curriculum, how students learned, and how instructors taught. Connor Nelson, Robert Wasinger, Adam Doupé, Yan Shoshitaishvili |
SIGCSE (1) | 3 |
| 2026 | The Linux Luminarium: Learning Linux by Leveraging Lightweight Labs and Ludicrous Lessons
Yan Shoshitaishvili, Adam Doupé, Connor Nelson |
SIGCSE (1) | 2 |
| 2026 | Oxidizer: Toward Concise and High-fidelity Rust Decompilation
Zion Leonahenahe Basque, Arvind S. Raj, Chavin Udomwongsa, Jie Hu 0031, Changyu Zhao, Fangzhou Dong, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001 |
SP | 9 |
| 2026 | Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware Ecosystem
Hui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001 |
SP | 8 |
| 2025 | ScamNet: Toward Explainable Large Language Model-Based Fraudulent Shopping Website DetectionabstractFraudulent shopping websites pose a significant threat to online consumers and legitimate businesses: in 2023, victims of such scams reported $392 million in losses to the Federal Trade Commission. This alarming trend not only impacts individuals but also erodes societal trust in e-commerce, necessitating urgent countermeasures. While previous studies have attempted to identify these fraudulent websites at scale, they face limitations such as potential bias in data collection, overreliance on easily manipulated features, and the lack of explainable results. This study explores the potential of Large Language Models (LLMs) in identifying fraudulent shopping websites, revealing that current LLMs underperform compared to existing machine learning models. To address this, we propose ScamNet, a fine-tuned LLM for explainable fraudulent shopping website detection. Our experimental results on real-world datasets demonstrate a breakthrough in detection performance from 22.35% detection rate to 95.59%, particularly in identifying subtle deceptive tactics such as using a legitimate-looking website template. ScamNet offers interpretable insights into its decision-making process, enhancing transparency and overcoming a key limitation of previous approaches. Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Ahmadreza Mosallanezhad, Adam Oest, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
AAAI | 9 |
| 2025 | SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website Campaigns
Marzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest, Dhruv Kuchhal, Muhammad Saad 0001, Gail-Joon Ahn, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
NDSS | 11 |
| 2025 | SENSAI: Large Language Models as Applied Cybersecurity TutorsabstractThe modern educational landscape faces the challenge of maintaining effective, personalized mentorship amid expanding class sizes. This challenge is particularly pronounced in fields requiring hands-on practice, such as cybersecurity education. Teaching assistants and peer interactions provide some relief, but the student-to-educator ratio often remains high, limiting individualized attention. The advent of Large Language Models (LLMs) offers a promising solution by potentially providing scalable and personalized guidance. In this paper, we introduce SENSAI, an AI-powered tutoring system that leverages LLMs to offer tailored feedback and assistance by transparently extracting and utilizing the learner's working context, including their active terminals and edited files. Over the past year, SENSAI has been deployed in an applied cybersecurity curriculum at a large public R1 university and made available to a broader online community of global learners, assisting 2,742 users with hundreds of educational challenges. In total 178,074 messages were exchanged across 15,413 sessions, incurring a total cost of 1,979--comparable to that of a single undergraduate teaching assistant but with a significantly wider reach. SENSAI demonstrates significant improvements in student problem-solving efficiency and satisfaction, offering insights into the future role of AI in education. Connor Nelson, Adam Doupé, Yan Shoshitaishvili |
SIGCSE (1) | 2 |
| 2025 | "It's almost like Frankenstein": Investigating the Complexities of Scientific Collaboration and Privilege Management within Research Computing InfrastructuresabstractResearch Computing Infrastructures (RCIs) inte-grate high-performance computing, advanced data storage solutions, and sophisticated network protocols, connecting people, data, and computing resources to facilitate scientific collaboration in today's data-driven world. Access control is essential in such highly collaborative environments to prevent resource misutilization, safeguard data integrity, and allocate resources effectively, thereby enabling secure and trusted in-teractions among different users. However, unlocking the full potential of RCIs for collaborative research through effective access control requires more than technological exploration-it demands a deep, human-centered understanding of the stakeholders who operate and utilize these systems. In this paper, we present the first qualitative study that explores the human dimensions of RCI interactions, drawing insights from 24 key stakeholders, including researchers and system administrators, across 12 research institutions to ex-amine the collaborative practices, challenges, and needs with a focus on access control. Our findings reveal operational complexities and project-specific, trust-based resource-sharing dynamics, highlighting tensions between security and usability. Based on these insights, we provide stakeholder-driven rec-ommendations and requirements for adaptive, user-centered access control for RCIs, laying the groundwork for advancing human-centered security practices in RCIs. Souradip Nath, Ananta Soneji, Jaejong Baek, Tiffany Bao, Adam Doupé, Carlos E. Rubio-Medrano, Gail-Joon Ahn |
SP | 5 |
| 2025 | System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System
Manas Ghandat, Kyle Zeng, Abdelouahab Benchikh, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili |
USENIX Security Symposium | 8 |
| 2025 | Automatically Mitigating Vulnerabilities in Binary Programs via Partially Recompilable DecompilationabstractVulnerabilities are challenging to locate and repair, especially when source code is unavailable and binary patching is required. Manual methods are time-consuming, require significant expertise, and do not scale to the rate at which new vulnerabilities are discovered. Automated methods are an attractive alternative, and we propose Partially Recompilable Decompilation (PRD) to help automate the process. PRD lifts suspect binary functions to source, available for analysis, revision, or review, and creates a patched binary using source- and binary-level techniques. Although decompilation and recompilation do not typically succeed on an entire binary, our approach does because it is limited to a few functions, such as those identified by our binary fault localization. We evaluate the assumptions underlying our approach and find that, without any grammar or compilation restrictions, up to 79% of individual functions are successfully decompiled and recompiled. In comparison, only 1.7% of the full C-binaries succeed. When recompilation succeeds, PRD produces test-equivalent binaries 93.0% of the time. We evaluate PRD in two contexts: a fully automated process incorporating source-level Automated Program Repair (APR) methods; and human-edited source-level repairs. When evaluated on DARPA Cyber Grand Challenge (CGC) binaries, we find that PRD-enabled APR tools, operating only on binaries, perform as well as, and sometimes better than full-source tools, collectively mitigating 85 of the 148 scenarios, a success rate consistent with the same tools operating with access to the entire source code. PRD achieves similar success rates as the winning CGC entries, sometimes finding higher-quality mitigations than those produced by top CGC teams. For generality, the evaluation includes two independently developed APR tools andC++, Rode0day, and real-world binaries. Pemma Reiter, Hui Jun Tay, Westley Weimer, Adam Doupé, Ruoyu Wang 0001, Stephanie Forrest |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Deep Dive into Client-Side Anti-Phishing: A Longitudinal Study Bridging Academia and IndustryabstractClient-side anti-phishing methods are crucial for safeguarding individuals against phishing attacks, offering a proactive approach beyond traditional blocklisting strategies. This study expands the scope to include a comprehensive evaluation of client-side anti-phishing techniques within the Chrome browser, alongside an in-depth analysis of academic research in the field of phishing over the past five years. Our findings highlight the inherent limitations of current client-side anti-phishing measures, which demonstrated a detection rate of only 14% for phishing websites and blocked merely 10% of login-based phishing sites within the first hour, resulting in a substantial false negative rate. Additionally, our analysis reveals that attackers can readily circumvent these defenses by altering the content of phishing websites. The study also critically assesses recent academic contributions to understand their alignment and potential integration with client-side anti-phishing frameworks. Based on these insights, we propose targeted recommendations to enhance the efficacy and responsiveness of the client-side anti-phishing ecosystem, addressing the challenges of low detection coverage, slow response times, and high rates of false negatives. Rana Pourmohamad, Steven Wirsz, Adam Oest, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001, Adam Doupé, Rida A. Bazzi |
AsiaCCS | 7 |
| 2024 | Fuzz to the Future: Uncovering Occluded Future Vulnerabilities via Robust FuzzingabstractThe security landscape of software systems has witnessed considerable advancements through dynamic testing methodologies, especially fuzzing. Traditionally, fuzzing involves a sequential, cyclic process where software is tested to identify crashes. These crashes are then triaged and patched, leading to subsequent cycles that uncover further vulnerabilities. While effective, this method is not efficient as each cycle potentially reveals new issues previously obscured by earlier crashes, thus resulting in vulnerabilities being discovered sequentially. Arvind S. Raj, Wil Gibbs, Fangzhou Dong, Jayakrishna Vadayath, Michael Tompkins, Steven Wirsz, Zhenghao Hu, Gokulkrishna Praveen Menon, Brendan Dolan-Gavitt, Adam Doupé, Ruoyu Wang 0001, Yan Shoshitaishvili, Tiffany Bao |
CCS | 12 |
| 2024 | Nothing Personal: Understanding the Spread and Use of Personally Identifiable Information in the Financial EcosystemabstractOnline services leverage various authentication methods with differing usability and reliability trade-offs, such as password-based or multi-factor authentication (MFA). However, financial service providers face a unique challenge; authenticating the user's legal identity, which involves verifying Personally Identifiable Information (PII), which we call PII-based authentication (PII-BA). These methods assume that PII is private; however, identity theft victimizes millions annually and exposes their PII to criminals. Mehrnoosh Zaeifi, Faezeh Kalantari, Adam Oest, Gail-Joon Ahn, Yan Shoshitaishvili, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé |
CODASPY | 9 |
| 2024 | SandPuppy: Deep-State Fuzzing Guided by Automatic Detection of State-Representative Variables
Vivin Paliath, Erik Trickel, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili |
DIMVA | 5 |
| 2024 | Browser Polygraph: Efficient Deployment of Coarse-Grained Browser Fingerprints for Web-Scale Detection of Fraud BrowsersabstractIn this paper, we address the prevalent issue of account takeover (ATO) fraud, which significantly impacts businesses through stolen user information. Websites have adopted risk-based authentication, incorporating browser fingerprinting techniques to counteract this threat. However, attackers have adapted by using anti-detect browsers, referred to as fraud browsers, to spoof user information effectively. While traditional fingerprinting methods are capable of identifying fraud browsers, they encounter scalability and performance challenges in risk-based systems. To address these issues, we developed Browser Polygraph, an ML-based tool that applies coarse-grained privacy-preserving fingerprints to assess browser authenticity and assigns risk factors to suspicious sessions. Coarse-grained fingerprints, by design, cannot be used for user tracking but only for fraud detection purposes. Deployed at a major financial company, Browser Polygraph has flagged suspicious sessions, enabling more targeted identification of potential fraud, thus enhancing the company's ability to tackle ATO attempts. Faezeh Kalantari, Mehrnoosh Zaeifi, Yeganeh Safaei, Marzieh Bitaab, Adam Oest, Gianluca Stringhini, Yan Shoshitaishvili, Adam Doupé |
IMC | 8 |
| 2024 | From Victims to Defenders: An Exploration of the Phishing Attack Reporting EcosystemabstractReporting phishing attacks can significantly shorten the time required to take down their operations and deter further victimization by the same phishing websites. However, little research has been conducted to understand the phishing reporting ecosystem and its effectiveness. In this paper, we comprehensively evaluate the phishing reporting ecosystem to identify the critical challenges people face and their concerns when reporting smishing, vishing, and phishing email attacks. First, we analyze the existing security advice and channels for reporting phishing attacks in both the public and private sectors. Then, we conduct a scenario-based experiment involving 89 participants to investigate what factors affect a participant’s decision to report a phishing attack and what challenges they face in preparing the report. Third, we report phishing attacks ourselves and monitor the status of the reported phishing websites to empirically measure how reports are acted upon and how that affects the reported phishing websites. Finally, we propose approaches under five major concern categories to mitigate the challenges that we discover in the phishing reporting ecosystem. Faris Bugra Kokulu, Adam Oest, Gianluca Stringhini, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
RAID | 9 |
| 2024 | "Watching over the shoulder of a professional": Why Hackers Make Mistakes and How They Fix ThemabstractThe complex and diverse nature of software systems necessitates a careful manual approach to unveil vulnerabilities, involving deep analysis, creative problem-solving, and specialized expertise. Like all complex tasks, it’s susceptible to mistakes stemming from cognitive limitations and behavioral factors that hinder optimal performance. Although there are significant research efforts focused on vulnerability discovery, little attention has been given to comprehending mistakes within the process. Understanding these mistakes could pave the way for better-designed education programs and automated tools, aiming to mitigate and prevent potential mistakes and enhance the efficiency of vulnerability research.In this paper, we leverage social media, specifically YouTube, to examine mistakes made by security content creators exploiting vulnerabilities in CTF-style challenges. Analyzing 30 screencasts from 11 hackers, we identified 124 distinct issues and investigated their types, underlying causes, and time investments. Additionally, we delved into the cognitive and behavioral aspects associated with these issues. Irina Ford, Ananta Soneji, Faris Bugra Kokulu, Jayakrishna Vadayath, Zion Leonahenahe Basque, Gaurav Vipat, Adam Doupé, Ruoyu Wang 0001, Gail-Joon Ahn, Tiffany Bao, Yan Shoshitaishvili |
SP | 7 |
| 2024 | "Len or index or count, anything but v1": Predicting Variable Names in Decompilation Output with Transfer LearningabstractBinary reverse engineering is an arduous and tedious task performed by skilled and expensive human analysts. Information about the source code is irrevocably lost in the compilation process. While modern decompilers attempt to generate C-style source code from a binary, they cannot recover lost variable names. Prior works have explored machine learning techniques for predicting variable names in decompiled code. However, the state-of-the-art systems, DIRE and DIRTY, generalize poorly to functions in the testing set that are not included in the training set—31.8% for DIRE on DIRTY’s data set and 36.9% for DIRTY on DIRTY’s data set.In this paper, we present VarBERT, a Bidirectional Encoder Representations from Transformers (BERT) to predict meaningful variable names in decompilation output. An advantage of VarBERT is that we can pre-train on human source code and then fine-tune the model to the task of predicting variable names. We also create a new data set VarCorpus, which significantly expands the size and variety of the data set. Our evaluation of VarBERT on VarCorpus, demonstrates a significant improvement in predicting the developer’s original variable names for O2 optimized binaries achieving accuracies of 54.43% for IDA and 54.49% for Ghidra. VarBERT is strictly better than state-of-the-art techniques: On a subset of VarCorpus, VarBERT could predict the developer’s original variable names 50.70% of the time, while DIRE and DIRTY predicted original variable names 35.94% and 38.00% of the time, respectively. Kuntal Kumar Pal, Ati Priya Bajaj, Pratyay Banerjee, Audrey Dutcher, Mutsumi Nakamura, Zion Leonahenahe Basque, Saurabh Arjun Sawant, Ujjwala Anantheswaran, Yan Shoshitaishvili, Adam Doupé, Chitta Baral, Ruoyu Wang 0001 |
SP | 11 |
| 2024 | Spider-Scents: Grey-box Database-aware Web Scanning for Stored XSS
Eric Olsson 0001, Benjamin Eriksson, Adam Doupé, Andrei Sabelfeld |
USENIX Security Symposium | 3 |
| 2024 | Ahoy SAILR! There is No Need to DREAM of C: A Compiler-Aware Structuring Algorithm for Binary Decompilation
Zion Leonahenahe Basque, Ati Priya Bajaj, Wil Gibbs, Jude O'Kain, Derron Miao, Tiffany Bao, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001 |
USENIX Security Symposium | 7 |
| 2024 | Operation Mango: Scalable Discovery of Taint-Style Vulnerabilities in Binary Firmware Services
Wil Gibbs, Arvind S. Raj, Jayakrishna Vadayath, Hui Jun Tay, Justin Miller, Akshay Ajayan, Zion Leonahenahe Basque, Audrey Dutcher, Fangzhou Dong, Xavier J. Maso, Giovanni Vigna, Christopher Krügel, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001 |
USENIX Security Symposium | 13 |
| 2024 | Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation
Dang K. Le, Zhenpeng Lin, Kyle Zeng, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé, Xinyu Xing 0001 |
USENIX Security Symposium | 8 |
| 2024 | "I feel physically safe but not politically safe": Understanding the Digital Threats and Safety Practices of OnlyFans Creators
Ananta Soneji, Vaughn Hamilton, Adam Doupé, Allison McDonald, Elissa M. Redmiles |
USENIX Security Symposium | 3 |
| 2024 | TYGR: Type Inference on Stripped Binaries using Graph Neural Networks
Ziyang Li 0002, Anton Xue, Ati Priya Bajaj, Wil Gibbs, Rajeev Alur, Tiffany Bao, Hanjun Dai, Adam Doupé, Mayur Naik, Yan Shoshitaishvili, Ruoyu Wang 0001, Aravind Machiry |
USENIX Security Symposium | 10 |
| 2023 | RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsabstractLeveraging a control flow hijacking primitive (CFHP) to gain root privileges is critical to attackers striving to exploit Linux kernel vulnerabilities. Such attack has become increasingly elusive as security researchers propose capable kernel security mitigations, leading to the development of complex (and, as a trade-off, brittle and unreliable) attack techniques to regain it. In this paper, we obviate the need for complexity by proposing RetSpill, a powerful yet elegant exploitation technique that employs user space data already present on the kernel stack for privilege escalation. Kyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing 0001, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao |
CCS | 6 |
| 2023 | Targeted Privacy Attacks by Fingerprinting Mobile Apps in LTE Radio LayerabstractWe investigate the feasibility of targeted privacy attacks using only information available in physical channels of LTE mobile networks and propose three privacy attacks to demonstrate this feasibility: mobile-app fingerprinting attack, history attack, and correlation attack. These attacks can reveal the geolocation of targeted mobile devices, the victim's app usage patterns, and even the relationship between two users within the same LTE network cell. An attacker also may launch these attacks stealthily by capturing radio signals transmitted over the air, using only a passive sniffer as equipment. To ensure the impact of these attacks on mobile users' privacy, we perform evaluations in both laboratory and real-world settings, demonstrating their practicality and dependability. Furthermore, we argue that these attacks can target not only 4G/LTE but also the evolving 5G standards. Jaejong Baek, Pradeepkumar Duraisamy, Sukwha Kyung, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
DSN | 6 |
| 2023 | Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at ScaleabstractDespite recent advancements in malicious website detection and phishing mitigation, the security ecosystem has paid little attention to Fraudulent e-Commerce Websites (FCWs), such as fraudulent shopping websites, fake charities, and cryptocurrency scam websites. Even worse, there are no active large-scale mitigation systems or publicly available datasets for FCWs.In this paper, we first propose an efficient and automated approach to gather FCWs through crowdsourcing. We identify eight different types of non-phishing FCWs and derive key defining characteristics. Then, we find that anti-phishing mitigation systems, such as Google Safe Browsing, have a detection rate of just 0.46% on our dataset. We create a classifier, BEYOND PHISH, to identify FCWs using manually defined features based on our analysis. Validating BEYOND PHISH on never-before-seen (untrained and untested data) through a user study indicates that our system has a high detection rate and a low false positive rate of 98.34% and 1.34%, respectively. Lastly, we collaborated with a major Internet security company, Palo Alto Networks, as well as a major financial services provider, to evaluate our classifier on manually labeled real-world data. The model achieves a false positive rate of 2.46% and a 94.88% detection rate, showing potential for real-world defense against FCWs. Marzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu, Jorij Abraham, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
SP | 10 |
| 2023 | Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesabstractBlack-box web application vulnerability scanners attempt to automatically identify vulnerabilities in web applications without access to the source code. However, they do so by using a manually curated list of vulnerability-inducing inputs, which significantly reduces the ability of a black-box scanner to explore the web application’s input space and which can cause false negatives. In addition, black-box scanners must attempt to infer that a vulnerability was triggered, which causes false positives.To overcome these limitations, we propose Witcher, a novel web vulnerability discovery framework that is inspired by grey-box coverage-guided fuzzing. Witcher implements the concept of fault escalation to detect both SQL and command injection vulnerabilities. Additionally, Witcher captures coverage information and creates output-derived input guidance to focus the input generation and, therefore, to increase the state-space exploration of the web application. On a dataset of 18 web applications written in PHP, Python, Node.js, Java, Ruby, and C, 13 of which had known vulnerabilities, Witcher was able to find 23 of the 36 known vulnerabilities (64%), and additionally found 67 previously unknown vulnerabilities, 4 of which received CVE numbers. In our experiments, Witcher outperformed state of the art scanners both in terms of number of vulnerabilities found, but also in terms of coverage of web applications. Erik Trickel, Fabio Pagani, Lukas Dresel, Giovanni Vigna, Christopher Krügel, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Adam Doupé |
SP | 10 |
| 2023 | Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space Emulation
Hui Jun Tay, Kyle Zeng, Jayakrishna Vadayath, Arvind S. Raj, Audrey Dutcher, Tejesh Reddy, Wil Gibbs, Zion Leonahenahe Basque, Fangzhou Dong, Zack Smith, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang 0001 |
USENIX Security Symposium | 11 |
| 2022 | ViK: practical mitigation of temporal memory safety violations through object ID inspectionabstractTemporal memory safety violations, such as use-after-free (UAF) vulnerabilities, are a critical security issue for software written in memory-unsafe languages such as C and C++. Haehyun Cho, Jinbum Park, Adam Oest, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ASPLOS | 7 |
| 2022 | I'm SPARTACUS, No, I'm SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking BehaviorabstractPhishing is a ubiquitous and increasingly sophisticated online threat. To evade mitigations, phishers try to "cloak" malicious content from defenders to delay their appearance on blacklists, while still presenting the phishing payload to victims. This cat-and-mouse game is variable and fast-moving, with many distinct cloaking methods---we construct a dataset identifying 2,933 real-world phishing kits that implement cloaking mechanisms. These kits use information from the host, browser, and HTTP request to classify traffic as either anti-phishing entity or potential victim and change their behavior accordingly. Sukwha Kyung, Hans Behrens, Zion Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang 0001, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, Adam Doupé |
CCS | 12 |
| 2022 | Improving source-code representations to enhance search-based software repairabstractAutomatically improving and repairing software using search-based methods is an active research topic. Many current systems use existing source code as the ingredients of repairs, either through evolutionary computation derived random mutation or other heuristic operators. However, these code transformation operators are not always well-matched to the granularity of the source code on which they operate. This paper proposes a static source-to-source preprocessing step to produce code with more uniform granularity that exposes relevant program components to the repair process. This approach, called Program Repair Enhancement via Preprocessing (PREP), has been applied to three different repair tools, each of which uses different code transformation operators and search algorithms. In every case, applying PREP before the search allows the tool to repair software defects that were previously unattainable by that tool. PREP finds 88 unique previously-unreported correct repairs across these tools. This result is significant because it is applicable to most search-based software improvement methods, and it addresses the fundamental issue of how to match the granularity of the representation to the granularity of operators. Pemma Reiter, Antonio M. Espinoza, Adam Doupé, Ruoyu Wang 0001, Westley Weimer, Stephanie Forrest |
GECCO | 3 |
| 2022 | Above and Beyond: Organizational Efforts to Complement U.S. Digital Security Compliance Mandates
Rock Stevens, Faris Bugra Kokulu, Adam Doupé, Michelle L. Mazurek |
NDSS | 3 |
| 2022 | Context-Auditor: Context-sensitive Content Injection MitigationabstractCross-site scripting (XSS) is the most common vulnerability class in web applications over the last decade. Much research attention has focused on building exploit mitigation defenses for this problem, but no technique provides adequate protection in the face of advanced attacks. One technique that bypasses XSS mitigations is the scriptless attack: a content injection technique that uses (among other options) CSS and HTML injection to infiltrate data. In studying this technique and others, we realized that the common property among the exploitation of all content injection vulnerabilities, including not just XSS and scriptless attacks, but also command injections and several others, is an unintended context switch in the victim program’s parsing engine that is caused by untrusted user input. Faezeh Kalantari, Mehrnoosh Zaeifi, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé |
RAID | 6 |
| 2022 | "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security PapersabstractThe academic computer security community has traditionally adopted peer review as an integral part of scientific publishing and dissemination, in a process that grows organically and nourishes itself by internal communications and intuitions, rather than repeatable experiments and investigations. Recently, key community members have shared a series of concerns regarding this process in public. To support or disprove some of these concerns, this paper presents the first qualitative study to examine the peer review process in the computer security field. Through semi-structured interviews (n=21) with Program Committee members, we systematically collect the reviewers’ insights on how papers are evaluated in top-tier security conferences and investigate their concerns regarding the current security peer review system. Based on the collected data, we identify several issues in the security review system: whereas some have been previously observed by the community (e.g., the randomness in reviewers’ decisions), others (e.g., reviewers have much more diverse and concrete opinions on the metrics of rejecting papers) have been observed for the first time in our study. Finally, through a series of recommendations, we aim to encourage the collaborative establishment of community norms that will significantly improve the security peer review process. Ananta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé |
SP | 7 |
| 2022 | Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention
Soroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso, Erik Trickel, Panagiotis Ilia, Yan Shoshitaishvili, Adam Doupé, Iasonas Polakis |
USENIX Security Symposium | 8 |
| 2022 | Arbiter: Bridging the Static and Dynamic Divide in Vulnerability Discovery on Binary Programs
Jayakrishna Vadayath, Moritz Eckert, Kyle Zeng, Nicolaas Weideman, Gokulkrishna Praveen Menon, Yanick Fratantonio, Davide Balzarotti, Adam Doupé, Tiffany Bao, Ruoyu Wang 0001, Christophe Hauser, Yan Shoshitaishvili |
USENIX Security Symposium | 8 |
| 2022 | Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability
Kyle Zeng, Yueqi Chen 0001, Haehyun Cho, Xinyu Xing 0001, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao |
USENIX Security Symposium | 5 |
| 2021 | Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing EcosystemabstractPhishing attacks are causing substantial damage albeit extensive effort in academia and industry. Recently, a large volume of phishing attacks transit toward adopting HTTPS, leveraging TLS certificates issued from Certificate Authorities (CAs), to make the attacks more effective. In this paper, we present a comprehensive study on the security practices of CAs in the HTTPS phishing ecosystem. We focus on the CAs, critical actors under-studied in previous literature, to better understand the importance of the security practices of CAs and thwart the proliferating HTTPS phishing. In particular, we first present the current landscape and effectiveness of HTTPS phishing attacks comparing to traditional HTTP ones. Then, we conduct an empirical experiment on the CAs' security practices in terms of the issuance and revocation of the certificates. Our findings highlight serious conflicts between the expected security practices of CAs and reality, raising significant security concerns. We further validate our findings using a longitudinal dataset of abusive certificates used for real phishing attacks in the wild. We confirm that the security concerns of CAs prevail in the wild and these concerns can be one of the main contributors to the recent surge of HTTPS phishing attacks. Doowon Kim, Haehyun Cho, Yonghwi Kwon 0001, Adam Doupé, Sooel Son, Gail-Joon Ahn, Tudor Dumitras |
AsiaCCS | 4 |
| 2021 | Favocado: Fuzzing the Binding Code of JavaScript Engines Using Semantically Correct Test Cases
Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Kyle Zeng, Alexandros Kapravelos, Gail-Joon Ahn, Tiffany Bao, Ruoyu Wang 0001, Adam Doupé, Yan Shoshitaishvili |
NDSS | 10 |
| 2021 | CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingabstractPhishing is a critical threat to Internet users. Although an extensive ecosystem serves to protect users, phishing websites are growing in sophistication, and they can slip past the ecosystem’s detection systems—and subsequently cause real-world damage—with the help of evasion techniques. Sophisticated client-side evasion techniques, known as cloaking, leverage JavaScript to enable complex interactions between potential victims and the phishing website, and can thus be particularly effective in slowing or entirely preventing automated mitigations. Yet, neither the prevalence nor the impact of client-side cloaking has been studied.In this paper, we present CrawlPhish, a framework for automatically detecting and categorizing client-side cloaking used by known phishing websites. We deploy CrawlPhish over 14 months between 2018 and 2019 to collect and thoroughly analyze a dataset of 112,005 phishing websites in the wild. By adapting state-of-the-art static and dynamic code analysis, we find that 35,067 of these websites have 1,128 distinct implementations of client-side cloaking techniques. Moreover, we find that attackers’ use of cloaking grew from 23.32% initially to 33.70% by the end of our data collection period. Detection of cloaking by our framework exhibited low false-positive and false-negative rates of 1.45% and 1.75%, respectively. We analyze the semantics of the techniques we detected and propose a taxonomy of eight types of evasion across three high-level categories: User Interaction, Fingerprinting, and Bot Behavior.Using 150 artificial phishing websites, we empirically show that each category of evasion technique is effective in avoiding browser-based phishing detection (a key ecosystem defense). Additionally, through a user study, we verify that the techniques generally do not discourage victim visits. Therefore, we propose ways in which our methodology can be used to not only improve the ecosystem’s ability to mitigate phishing websites with client-side cloaking, but also continuously identify emerging cloaking techniques as they are launched by attackers. Adam Oest, Haehyun Cho, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
SP | 12 |
| 2021 | Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service
Adam Oest, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang 0001, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
USENIX Security Symposium | 9 |
| 2020 | You shall not pass: Mitigating SQL Injection Attacks on Legacy Web ApplicationsabstractSQL injection (SQLi) attacks pose a significant threat to the security of web applications. Existing approaches do not support object-oriented programming that renders these approaches unable to protect the real-world web apps such as Wordpress, Joomla, or Drupal against SQLi attacks. We propose a novel hybrid static-dynamic analysis for PHP web applications that limits each PHP function for accessing the database. Our tool, SQLBlock, reduces the attack surface of the vulnerable PHP functions in a web application to a set of query descriptors that demonstrate the benign functionality of the PHP function. We implement SQLBlock as a plugin for MySQL and PHP. Our approach does not require any modification to the web app. We evaluate SQLBlock on 11 SQLi vulnerabilities in Wordpress, Joomla, Drupal, Magento, and their plugins. We demonstrate that SQLBlock successfully prevents all 11 SQLi exploits with negligible performance overhead (i.e., a maximum of 3% on a heavily-loaded web server). Rasoul Jahanshahi, Adam Doupé, Manuel Egele |
AsiaCCS | 2 |
| 2020 | HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsabstractIndustrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis. Efrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001, Tiffany Bao, Gail-Joon Ahn |
CCS | 3 |
| 2020 | SmokeBomb: effective mitigation against cache side-channel attacks on the ARM architectureabstractCache side-channel attacks abuse microarchitectural designs meant to optimize memory access to infer information about victim processes, threatening data privacy and security. Recently, the ARM architecture has come into the spotlight of cache side-channel attacks with its unprecedented growth in the market. Haehyun Cho, Jinbum Park, Donguk Kim 0003, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
MobiSys | 6 |
| 2020 | PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists
Adam Oest, Yeganeh Safaei, Brad Wardman, Kevin Tyers, Yan Shoshitaishvili, Adam Doupé |
USENIX Security Symposium | 7 |
| 2020 | Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale
Adam Oest, Brad Wardman, Eric Nunes, Jakub Burgis, Ali Zand, Kurt Thomas, Adam Doupé, Gail-Joon Ahn |
USENIX Security Symposium | 8 |
| 2019 | Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesabstractOrganizations, such as companies and governments, created Security Operations Centers (SOCs) to defend against computer security attacks. SOCs are central defense groups that focus on security incident management with capabilities such as monitoring, preventing, responding, and reporting. They are one of the most critical defense components of a modern organization's defense. Despite their critical importance to organizations, and the high frequency of reported security incidents, only a few research studies focus on problems specific to SOCs. In this study, to understand and identify the issues of SOCs, we conducted 18 semi-structured interviews with SOC analysts and managers who work for organizations from different industry sectors. Through our analysis of the interview data, we identified technical and non-technical issues that exist in SOC. Moreover, we found inherent disagreements between SOC managers and their analysts that, if not addressed, could entail a risk to SOC efficiency and effectiveness. We distill these issues into takeaways that apply both to future academic research and to SOC management. We believe that research should focus on improving the efficiency and effectiveness of SOCs. Faris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CCS | 6 |
| 2019 | Understanding and Predicting Private Interactions in Underground ForumsabstractThe studies on underground forums and marketplaces have significantly advanced our understandings of cybercrime workflows and underground economies. Researchers of underground economies have conducted comprehensive studies on public interactions. However, little research focuses on private interactions. The lack of the investigation on private interactions may cause misunderstandings on underground economies, as users in underground forums and marketplaces tend to share the minimal amount of information in public interactions and resort to private messages for follow-up conversations. In this paper, we propose methods to investigate the underground private interactions and we analyze a recently leaked dataset from Nulled.io. We present analyses on the contents and purposes of private messages. In addition, we design machine learning-based models that only use the publicly available information to detect if two underground users privately communicate with each other. Finally, we perform adversarial analysis to evaluate the robustness of the detector to different types of attacks. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Tiffany Bao, Adam Doupé, Gail-Joon Ahn |
CODASPY | 5 |
| 2019 | History and Future of Automated Vulnerability AnalysisabstractThe software upon which our modern society operates is riddled with security vulnerabilities. These vulnerabilities allow hackers access to our sensitive data and make our system insecure. To identify vulnerabilities in software, human experts, or vulnerability researchers, are employed. These human experts are quite expensive. And, more fundamentally, human experts cannot analyze every change made to every piece of software (any of which could introduce a security vulnerability). Therefore, automated vulnerability analysis techniques were developed to automatically perform the process of identifying security vulnerabilities in software systems. These tools attempt to democratize the vulnerability analysis process: allowing any developer to identify vulnerabilities in their software automatically, thus finding such vulnerabilities before a malicious hacker. Adam Doupé |
SACMAT | 1 |
| 2019 | PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsabstractPhishing attacks have reached record volumes in recent years. Simultaneously, modern phishing websites are growing in sophistication by employing diverse cloaking techniques to avoid detection by security infrastructure. In this paper, we present PhishFarm: a scalable framework for methodically testing the resilience of anti-phishing entities and browser blacklists to attackers' evasion efforts. We use PhishFarm to deploy 2,380 live phishing sites (on new, unique, and previously-unseen .com domains) each using one of six different HTTP request filters based on real phishing kits. We reported subsets of these sites to 10 distinct anti-phishing entities and measured both the occurrence and timeliness of native blacklisting in major web browsers to gauge the effectiveness of protection ultimately extended to victim users and organizations. Our experiments revealed shortcomings in current infrastructure, which allows some phishing sites to go unnoticed by the security community while remaining accessible to victims. We found that simple cloaking techniques representative of real-world attacks- including those based on geolocation, device type, or JavaScript- were effective in reducing the likelihood of blacklisting by over 55% on average. We also discovered that blacklisting did not function as intended in popular mobile browsers (Chrome, Safari, and Firefox), which left users of these browsers particularly vulnerable to phishing attacks. Following disclosure of our findings, anti-phishing entities are now better able to detect and mitigate several cloaking techniques (including those that target mobile users), and blacklisting has also become more consistent between desktop and mobile platforms- but work remains to be done by anti-phishing entities to ensure users are adequately protected. Our PhishFarm framework is designed for continuous monitoring of the ecosystem and can be extended to test future state-of-the-art evasion techniques used by malicious websites. Adam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn, Brad Wardman, Kevin Tyers |
IEEE Symposium on Security and Privacy | 3 |
| 2019 | Everyone is Different: Client-side Diversification for Defending Against Extension Fingerprinting
Erik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis, Adam Doupé |
USENIX Security Symposium | 5 |
| 2019 | Users Really Do Answer Telephone Scams
Huahong Tu, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
USENIX Security Symposium | 2 |
| 2018 | Wi Not Calling: Practical Privacy and Availability Attacks in Wi-Fi CallingabstractWi-Fi Calling, which is used to make and receive calls over the Wi-Fi network, has been widely adopted and deployed to extend the coverage and increase the capacity in weak signal areas by moving traffic from LTE to Wi-Fi networks. However, the security of Wi-Fi Calling mechanism has not been fully analyzed, and Wi-Fi Calling may inherently have greater security risks than conventional LTE calling. To provide secure connections with confidentiality and integrity, Wi-Fi Calling leverages the IETF protocols IKEv2 and IPSec. Jaejong Baek, Sukwha Kyung, Haehyun Cho, Ziming Zhao 0001, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn |
ACSAC | 6 |
| 2018 | Prime+Count: Novel Cross-world Covert Channels on ARM TrustZoneabstractThe security of ARM TrustZone relies on the idea of splitting system-on-chip hardware and software into two worlds, namely normal world and secure world. In this paper, we report cross-world covert channels, which exploit the world-shared cache in the TrustZone architecture. We design a Prime+Count technique that only cares about how many cache sets or lines have been occupied. The coarser-grained approach significantly reduces the noise introduced by the pseudo-random replacement policy and world switching. Using our Prime+Count technique, we build covert channels in single-core and cross-core scenarios in the TrustZone architecture. Our results demonstrate that Prime+Count is an effective technique for enabling cross-world covert channels on ARM TrustZone. Haehyun Cho, Donguk Kim 0003, Jinbum Park, Choong-Hoon Lee, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
ACSAC | 7 |
| 2018 | AIM-SDN: Attacking Information Mismanagement in SDN-datastoresabstractNetwork Management is a critical process for an enterprise to configure and monitor the network devices using cost effective methods. It is imperative for it to be robust and free from adversarial or accidental security flaws. With the advent of cloud computing and increasing demands for centralized network control, conventional management protocols like SNMP appear inadequate and newer techniques like NMDA and NETCONF have been invented. However, unlike SNMP which underwent improvements concentrating on security, the new data management and storage techniques have not been scrutinized for the inherent security flaws. In this paper, we identify several vulnerabilities in the widely used critical infrastructures which leverage the Network Management Datastore Architecture design (NMDA). Software Defined Networking (SDN), a proponent of NMDA, heavily relies on its datastores to program and manage the network. We base our research on the security challenges put forth by the existing datastore's design as implemented by the SDN controllers. The vulnerabilities identified in this work have a direct impact on the controllers like OpenDayLight, Open Network Operating System and their proprietary implementations (by CISCO, Ericsson, RedHat, Brocade, Juniper, etc). Using our threat detection methodology, we demonstrate how the NMDA-based implementations are vulnerable to attacks which compromise availability, integrity, and confidentiality of the network. We finally propose defense measures to address the security threats in the existing design and discuss the challenges faced while employing these countermeasures. Vaibhav Hemant Dixit, Adam Doupé, Yan Shoshitaishvili, Ziming Zhao 0001, Gail-Joon Ahn |
CCS | 2 |
| 2018 | SeCore: Continuous Extrospection with High Visibility on Multi-core ARM PlatformsabstractWe present SeCore, which is a novel continuous extrospection system on multi-core ARM platform. SeCore leverages ARM TrustZone technology to keep one core in the secure world and assure the integrity of the static kernel data and code in the normal world. By breaking the original time-sharing paradigm of such systems, SeCore enables continuous coprocessor-like monitoring with high visibility into the rich execution environment on mobile and IoT platforms. By ensuring that secure tools execute on certain physical CPU cores, the system's attack surface is also significantly reduced. Bernard Ngabonziza, Haehyun Cho, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 5 |
| 2018 | Challenges, Opportunities and a Framework for Web Environment Forensics
Mike Mabey, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
IFIP Int. Conf. Digital Forensics | 2 |
| 2017 | Panel: Trustworthy Data ScienceabstractMuch of the research that our community publishes is based on data. However, an open question remains: are the results of data science trustworthy, and how can we increase our trust in data science? Accomplishing this goal is difficult, as we must trust the inputs, systems, and results of data science. This panel will discuss the current state of trustworthy data science, and explore possible technical, legal, and cultural solutions that can increase our trust in the input, systems, and results of data science. Adam Doupé |
CODASPY | 1 |
| 2017 | Deep Android Malware DetectionabstractIn this paper, we propose a novel android malware detection system that uses a deep convolutional neural network (CNN). Malware classification is performed based on static analysis of the raw opcode sequence from a disassembled program. Features indicative of malware are automatically learned by the network from the raw opcode sequence thus removing the need for hand-engineered malware features. The training pipeline of our proposed system is much simpler than existing n-gram based malware detection methods, as the network is trained end-to-end to jointly learn appropriate features and to perform classification, thus removing the need to explicitly enumerate millions of n-grams during training. The network design also allows the use of long n-gram like features, not computationally feasible with existing methods. Once trained, the network can be efficiently executed on a GPU, allowing a very large number of files to be scanned quickly. Niall McLaughlin, Jesús Martínez del Rincón, Boojoong Kang, Suleiman Y. Yerima, Paul Miller 0003, Sakir Sezer, Yeganeh Safaei, Erik Trickel, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 10 |
| 2016 | Checking Intent-based Communication in Android with Intent Space AnalysisabstractIntent-based communication is an inter-application communication mechanism in Android. While its importance has been proven by plenty of security extensions that protect it with policy-driven mandatory access control, an overlooked problem is the verification of the security policies. Checking one security extension's policy is indeed complex. Furthermore, intent-based communication introduces even more complexities because it is mediated by multiple security extensions that respectively enforce their own incompatible, distributed, and dynamic policies. Yiming Jing, Gail-Joon Ahn, Adam Doupé, Jeong Hyun Yi |
AsiaCCS | 3 |
| 2016 | Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing Policy
Vitor Monte Afonso, Paulo Lício de Geus, Antonio Bianchi, Yanick Fratantonio, Christopher Krügel, Giovanni Vigna, Adam Doupé, Mario Polino |
NDSS | 7 |
| 2016 | State-aware Network Access Management for Software-Defined NetworksabstractOpenFlow, as the prevailing technique for Software-Defined Networks (SDNs), introduces significant programmability, granularity, and flexibility for many network applications to effectively manage and process network flows. However, because OpenFlow attempts to keep the SDN data plane simple and efficient, it focuses solely on L2/L3 network transport and consequently lacks the fundamental ability of stateful forwarding for the data plane. Also, OpenFlow provides a very limited access to connection-level information in the SDN controller. In particular, for any network access management applications on SDNs that require comprehensive network state information, these inherent limitations of OpenFlow pose significant challenges in supporting network services. To address these challenges, we propose an innovative connection tracking framework called STATEMON that introduces a global state-awareness to provide better access control in SDNs. STATEMON is based on a lightweight extension of OpenFlow for programming the stateful SDN data plane, while keeping the underlying network devices as simple as possible. To demonstrate the practicality and feasibility of STATEMON, we implement and evaluate a stateful network firewall and port knocking applications for SDNs, using the APIs provided by STATEMON. Our evaluations show that STATEMON introduces minimal message exchanges for monitoring active connections in SDNs with manageable overhead (3.27% throughput degradation). Wonkyu Han, Hongxin Hu, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn, Kuang-Ching Wang, Juan Deng |
SACMAT | 4 |
| 2016 | SoK: Everyone Hates Robocalls: A Survey of Techniques Against Telephone SpamabstractTelephone spam costs United States consumers $8.6 billion annually. In 2014, the Federal Trade Commission has received over 22 million complaints of illegal and wanted calls. Telephone spammers today are leveraging recent technical advances in the telephony ecosystem to distribute massive automated spam calls known as robocalls. Given that anti-spam techniques and approaches are effective in the email domain, the question we address is: what are the effective defenses against spam calls? In this paper, we first describe the telephone spam ecosystem, specifically focusing on the differences between email and telephone spam. Then, we survey the existing telephone spam solutions and, by analyzing the failings of the current techniques, derive evaluation criteria that are critical to an acceptable solution. We believe that this work will help guide the development of effective telephone spam defenses, as well as provide a framework to evaluate future defenses. Huahong Tu, Adam Doupé, Ziming Zhao 0001, Gail-Joon Ahn |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | Federated Access Management for Collaborative Network Environments: Framework and Case StudyabstractWith the advent of various collaborative sharing mechanisms such as Grids, P2P and Clouds, organizations including private and public sectors have recognized the benefits of being involved in inter-organizational, multi-disciplinary, and collaborative projects that may require diverse resources to be shared among participants. In particular, an environment that often makes use of a group of high-performance network facilities would involve large-scale collaborative projects and tremendously seek a robust and flexible access control for allowing collaborators to leverage and consume resources, e.g., computing power and bandwidth. In this paper, we propose a federated access management scheme that leverages the notion of attributes. Our approach allows resource-sharing organizations to provide distributed provisioning (publication, location, communication, and evaluation) of both attributes and policies for federated access management purposes. Also, we provide a proof-of-concept implementation that leverages distributed hash tables (DHT) to traverse chains of attributes and effectively handle the federated access management requirements devised for inter-organizational resource sharing and collaborations. Carlos E. Rubio-Medrano, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
SACMAT | 3 |
| 2013 | deDacota: toward preventing server-side XSS via automatic code and data separationabstractWeb applications are constantly under attack. They are popular, typically accessible from anywhere on the Internet, and they can be abused as malware delivery systems. Adam Doupé, Weidong Cui, Mariusz H. Jakubowski, Marcus Peinado, Christopher Krügel, Giovanni Vigna |
CCS | 1 |
| 2013 | Writing groups in computer science research labsabstractResearchers must excel at writing to effectively engage the scientific community. Clear and engaging writing advances new knowledge and increases the impact of a researcher's work. As developing researchers, it is essential that graduate students learn to write clearly and effectively so that their work is accessible to their peers and colleagues. An essential part of graduate school education should include the teaching of formal writing skills. In most graduate programs, students learn formal writing skills from two sources, their advisors or a writing class. We identify a third source: the graduate student peer group. In this paper, we describe how we leveraged the existing collaborative research dynamic among students in a graduate research lab and created a writing group, similar in spirit to the concept of a reading group. We describe the inspiration, implementation, and impact of a writing group in a real-world research lab. We show how the writing group started organically after a PhD student took a graduate writing class in the Computer Science Department and thereafter initiated the writing group in his research lab. We also describe how a writing group can be implemented in other research labs to improve the writing of graduate students worldwide. Adam Doupé, Janet L. Kayfetz |
FIE | 1 |
| 2012 | Enemy of the State: A State-Aware Black-Box Web Vulnerability Scanner
Adam Doupé, Ludovico Cavedon, Christopher Krügel, Giovanni Vigna |
USENIX Security Symposium | 1 |
| 2011 | Hit 'em where it hurts: a live security exercise on cyber situational awarenessabstractLive security exercises are a powerful educational tool to motivate students to excel and foster research and development of novel security solutions. Our insight is to design a live security exercise to provide interesting datasets in a specific area of security research. In this paper we validated this insight, and we present the design of a novel kind of live security competition centered on the concept of Cyber Situational Awareness. The competition was carried out in December 2010, and involved 72 teams (900 students) spread across 16 countries, making it the largest educational live security exercise ever performed. We present both the innovative design of this competition and the novel dataset we collected. In addition, we define Cyber Situational Awareness metrics to characterize the toxicity and effectiveness of the attacks performed by the participants with respect to the missions carried out by the targets of the attack. Adam Doupé, Manuel Egele, Benjamin Caillat, Gianluca Stringhini, Gorkem Yakin, Ali Zand, Ludovico Cavedon, Giovanni Vigna |
ACSAC | 1 |
| 2011 | Fear the EAR: discovering and mitigating execution after redirect vulnerabilitiesabstractThe complexity of modern web applications makes it difficult for developers to fully understand the security implications of their code. Attackers exploit the resulting security vulnerabilities to gain unauthorized access to the web application environment. Previous research into web application vulnerabilities has mostly focused on input validation flaws, such as cross site scripting and SQL injection, while logic flaws have received comparably less attention. In this paper, we present a comprehensive study of a relatively unknown logic flaw in web applications, which we call Execution After Redirect, or EAR. A web application developer can introduce an EAR by calling a redirect method under the assumption that execution will halt. A vulnerability occurs when server-side execution continues after the developer's intended halting point, which can lead to broken/insufficient access controls and information leakage. We start with an analysis of how susceptible applications written in nine web frameworks are to EAR vulnerabilities. We then discuss the results from the EAR challenge contained within the 2010 International Capture the Flag Competition. Finally, we present an open-source, white-box, static analysis tool to detect EARs in Ruby on Rails web applications. This tool found 3,944 EAR instances in 18,127 open-source applications. Finally, we describe an approach to prevent EARs in web frameworks. Adam Doupé, Bryce Boe, Christopher Krügel, Giovanni Vigna |
CCS | 1 |
| 2010 | Why Johnny Can't Pentest: An Analysis of Black-Box Web Vulnerability Scanners
Adam Doupé, Marco Cova, Giovanni Vigna |
DIMVA | 1 |