Collin Mulliner

dblp:34/1145 · DBLP profile ↗
← Back
14ranked-venue papers
9as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 9 first-authorSystems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Systems and software security · 32% Web and mobile security · 28% Malware analysis · 22%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%
Computer networks
1 paper
Cellular and mobile networks · 100%
Human-computer interaction and pervasive computing
1 paper
User interface design and tools · 100%

Topics — the 8 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis › ransomware
ransomware detection
0.212016
UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware · USENIX Security Symposium 2016
Web and mobile security › web application vulnerability
access control vulnerability
0.212014
Hidden GEMs: Automated Discovery of Access Control Vulnerabilities in Graphical User Interfaces · IEEE Symposium on Security and Privacy 2014
Systems and software security
vulnerability discovery
0.212014
Hidden GEMs: Automated Discovery of Access Control Vulnerabilities in Graphical User Interfaces · IEEE Symposium on Security and Privacy 2014
Hardware security and side channels › memory security
data remanence
0.212013
PrivExec: Private Execution as an Operating System Service · IEEE Symposium on Security and Privacy 2013
Web and mobile security
mobile security
0.112011
SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale · USENIX Security Symposium 2011
User interface design and tools › graphical user interface
graphical widgets
0.112014
Hidden GEMs: Automated Discovery of Access Control Vulnerabilities in Graphical User Interfaces · IEEE Symposium on Security and Privacy 2014
Systems and software security
operating system security
0.012013
PrivExec: Private Execution as an Operating System Service · IEEE Symposium on Security and Privacy 2013
Network security › attack strategy
denial-of-service attack
0.012011
SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale · USENIX Security Symposium 2011

Methods — techniques the papers use, named apart from their topics

static analysis · 0.4classification of misuse patterns · 0.4kernel extension · 0.3large-scale measurement · 0.2automated detection · 0.2
YearPublicationVenuePosition
2018 USBlock: Blocking USB-Based Keypress Injection Attacks
Sebastian Neuner, Artemios G. Voyiatzis, Spiros Fotopoulos, Collin Mulliner, Edgar R. Weippl
DBSec4
2016 Trellis: Privilege Separation for Multi-user Applications Made Easy
Andrea Mambretti, Kaan Onarlioglu, Collin Mulliner, William K. Robertson, Engin Kirda, Federico Maggi 0001, Stefano Zanero
RAID3
2016 UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware
Amin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson, Engin Kirda
USENIX Security Symposium3
2014 VirtualSwindle: an automated attack against in-app billing on android
abstract
Since its introduction, Android's in-app billing service has quickly gained popularity. The in-app billing service allows users to pay for options, services, subscriptions, and virtual goods from within mobile apps themselves. In-app billing is attractive for developers because it is easy to integrate, and has the advantage that the developer does not need to be concerned with managing financial transactions. In this paper, we present the first fully-automated attack against the in-app billing service on Android. Using our prototype, we conducted a robustness study against our attack, analyzing 85 of the most popular Android apps that make use of in-app billing. We found that 60% of these apps were easily and automatically crackable. We were able to bypass highly popular and prominent games such as Angry Birds and Temple Run, each of which have millions of users. Based on our study, we developed a defensive technique that specifically counters automated attacks against in-app billing. Our technique is lightweight and can be easily added to existing applications.
Collin Mulliner, William K. Robertson, Engin Kirda
AsiaCCS1
2014 Hidden GEMs: Automated Discovery of Access Control Vulnerabilities in Graphical User Interfaces
abstract
Graphical user interfaces (GUIs) are the predominant means by which users interact with modern programs. GUIs contain a number of common visual elements or widgets such as labels, text fields, buttons, and lists, and GUIs typically provide the ability to set attributes on these widgets to control their visibility, enabled status, and whether they are writable. While these attributes are extremely useful to provide visual cues to users to guide them through an application's GUI, they can also be misused for purposes they were not intended. In particular, in the context of GUI-based applications that include multiple privilege levels within the application, GUI element attributes are often misused as a mechanism for enforcing access control policies. In this work, we introduce GEMs, or instances of GUI element misuse, as a novel class of access control vulnerabilities in GUI-based applications. We present a classification of different GEMs that can arise through misuse of widget attributes, and describe a general algorithm for identifying and confirming the presence of GEMs in vulnerable applications. We then present GEM Miner, an implementation of our GEM analysis for the Windows platform. We evaluate GEM Miner over a test set of three complex, real-world GUI-based applications targeted at the small business and enterprise markets, and demonstrate the efficacy of our analysis by finding numerous previously unknown access control vulnerabilities in these applications. We have reported the vulnerabilities we discovered to the developers of each application, and in one case have received confirmation of the issue.
Collin Mulliner, William K. Robertson, Engin Kirda
IEEE Symposium on Security and Privacy1
2013 PatchDroid: scalable third-party security patches for Android devices
abstract
Android is currently the largest mobile platform with around 750 million devices worldwide. Unfortunately, more than 30% of all devices contain publicly known security vulnerabilities and, in practice, cannot be updated through normal mechanisms since they are not longer supported by the manufacturer and mobile operator. This failure of traditional patch distribution systems has resulted in the creation of a large population of vulnerable mobile devices.
Collin Mulliner, Jon Oberheide, William K. Robertson, Engin Kirda
ACSAC1
2013 SMS-Based One-Time Passwords: Attacks and Defense - (Short Paper)
Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, Jean-Pierre Seifert
DIMVA1
2013 PrivExec: Private Execution as an Operating System Service
abstract
Privacy has become an issue of paramount importance for many users. As a result, encryption tools such as True Crypt, OS-based full-disk encryption such as File Vault, and privacy modes in all modern browsers have become popular. However, although such tools are useful, they are not perfect. For example, prior work has shown that browsers still leave many traces of user information on disk even if they are started in private browsing mode. In addition, disk encryption alone is not sufficient, as key disclosure through coercion remains possible. Clearly, it would be useful and highly desirable to have OS-level support that provides strong privacy guarantees for any application -- not only browsers. In this paper, we present the design and implementation of PrivExec, the first operating system service for private execution. PrivExec provides strong, general guarantees of private execution, allowing any application to execute in a mode where storage writes, either to the filesystem or to swap, will not be recoverable by others during or after execution. PrivExec does not require explicit application support, recompilation, or any other preconditions. We have implemented a prototype of PrivExec by extending the Linux kernel that is performant, practical, and that secures sensitive data against disclosure.
Kaan Onarlioglu, Collin Mulliner, William K. Robertson, Engin Kirda
IEEE Symposium on Security and Privacy2
2012 Taming Mr Hayes: Mitigating signaling based attacks on smartphones
abstract
Malicious injection of cellular signaling traffic from mobile phones is an emerging security issue. The respective attacks can be performed by hijacked smartphones and by malware resident on mobile phones. Until today there are no protection mechanisms in place to prevent signaling based attacks other than implementing expensive additions to the cellular core network. In this work we present a protection system that resides on the mobile phone. Our solution works by partitioning the phone software stack into the application operating system and the communication partition. The application system is a standard fully featured Android system. On the other side, communication to the cellular network is mediated by a flexible monitoring and enforcement system running on the communication partition. We implemented and evaluated our protection system on a real smartphone. Our evaluation shows that it can mitigate all currently known signaling based attacks and in addition can protect users from cellular Trojans.
Collin Mulliner, Steffen Liebergeld, Jean-Pierre Seifert
DSN1
2011 Poster: Towards detecting DMA malware
Patrick Stewin, Jean-Pierre Seifert, Collin Mulliner
CCS3
2011 SMS of Death: From Analyzing to Attacking Mobile Phones on a Large Scale
Collin Mulliner, Nico Golde, Jean-Pierre Seifert
USENIX Security Symposium1
2009 Vulnerability Analysis and Attacks on NFC-Enabled Mobile Phones
abstract
Near Field Communication (NFC)-enabled mobile phones and services are starting to appear in the field, yet no attempt was made to analyze the security of NFC-enabled mobile phones. The situation is critical because NFC is mostly used in the area of payment and ticketing. This paper presents our approach to security testing of NFC-enabled mobile phones. Our approach takes into account not only the NFC-subsystem but also software components that can be controlled through the NFC-interface. Through our testing approach, we were able to identify a number of previously unknown vulnerabilities, some of which can be exploited for spoofing of tag content, an NFC-based worm, and for denial-of-service attacks. We further show that our findings can be applied to real world NFC-services.
Collin Mulliner
ARES1
2006 Vulnerability Analysis of MMS User Agents
abstract
The Multimedia Messaging Service (MMS) is becoming more popular, as mobile phones integrate audio and video recording functionality. Multimedia messages are delivered to users through a multi-step process, whose end-points are the MMS User Agents that reside on the users mobile phones. The security of these components is critical, because they might have access to private information and, if compromised, could be leveraged to spread an MMS-based worm. Unfortunately, the vulnerability analysis of these components is made more difficult by the fact that they are mostly closed-source and the testing has to be performed through the mobile phone network, which makes the testing time-consuming and costly. This paper presents a novel approach to the security testing of MMS User Agents. Our approach takes into account the effects of the infrastructure on the delivery of MMS messages and then uses a virtual infrastructure to speed up the testing process. Our testing approach was able to identify a number of previously unknown vulnerabilities, which, in one case, allowed for the execution of arbitrary code.
Collin Mulliner, Giovanni Vigna
ACSAC1
2006 Using Labeling to Prevent Cross-Service Attacks Against Smart Phones
Collin Mulliner, Giovanni Vigna, David Dagon, Wenke Lee
DIMVA1