EDBT 2026 Demo / reviewers in the wild / expert
David A. Wagner 0001
dblp:42/5626
· DBLP profile ↗
140ranked-venue papers
18as first author
19since 2021 · last 2025
0000-0002-9944-9232ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 108 · 17 first-author · 9 since 2021Artificial intelligence and machine learning · 9 · 8 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 since 2021Computer networks · 7Theory of computation · 6Software engineering, systems software and programming languages · 5 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SecAlign: Defending Against Prompt Injection with Preference Optimization
Sizhe Chen, Arman Zharmagambetov, Saeed Mahloujifar, Kamalika Chaudhuri, David A. Wagner 0001, Chuan Guo 0001 |
CCS | 5 |
| 2025 | PromptShield: Deployable Detection for Prompt Injection AttacksabstractApplication designers have moved to integrate large language models (LLMs) into their products. However, many LLM-integrated applications are vulnerable to prompt injections. While attempts have been made to address this problem by building prompt injection detectors, many are not yet suitable for practical deployment. To support research in this area, we introduce PromptShield, a benchmark for training and evaluating deployable prompt injection detectors. Our benchmark is carefully curated and includes both conversational and application-structured data. In addition, we use insights from our curation process to fine-tune a new prompt injection detector that achieves significantly higher performance in the low false positive rate (FPR) evaluation regime compared to prior schemes. Our work suggests that careful curation of training data and larger models can contribute to strong detector performance. Dennis Jacob, Hend Alzahrani, Zhanhao Hu, Basel Alomair, David A. Wagner 0001 |
CODASPY | 5 |
| 2025 | Vulnerability Detection with Code Language Models: How Far are We?abstractIn the context of the rising interest in code language models (code LMs) and vulnerability detection, we study the effectiveness of code LMs for detecting vulnerabilities. Our analysis reveals significant shortcomings in existing vulnerability datasets, including poor data quality, low label accuracy, and high duplication rates, leading to unreliable model performance in realistic vulnerability detection scenarios. Additionally, the evaluation methods used with these datasets are not representative of real-world vulnerability detection. To address these challenges, we introduce Primevul, a new dataset for training and evaluating code LMs for vulnerability detection. Primevul incorporates a novel set of data labeling techniques that achieve comparable label accuracy to human-verified benchmarks while significantly expanding the dataset. It also implements a rigorous data de-duplication and chronological data splitting strategy to mitigate data leakage issues, alongside introducing more realistic evaluation metrics and settings. This comprehensive approach aims to provide a more accurate assessment of code LMs' performance in real-world conditions. Evaluating code LMs on Primevul reveals that existing benchmarks significantly overestimate the performance of these models. For instance, a state-of-the-art 7B model scored 68.26% Fl on BigVul but only 3.09% Fl on Primevul. Attempts to improve performance through advanced training techniques and larger models like GPT-3.5 and GPT-4 were unsuccessful, with results akin to random guessing in the most stringent settings. These findings underscore the considerable gap between current capabilities and the practical requirements for deploying code LMs in security roles, highlighting the need for more innovative research in this domain. Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim, Chawin Sitawarin, Basel Alomair, David A. Wagner 0001, Baishakhi Ray, Yizheng Chen 0001 |
ICSE | 7 |
| 2025 | Stronger Universal and Transferable Attacks by Suppressing RefusalsabstractDavid Huang, Avidan Shah, Alexandre Araujo, David Wagner, Chawin Sitawarin. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2025. Avidan Shah, Alexandre Araujo, David A. Wagner 0001, Chawin Sitawarin |
NAACL (Long Papers) | 4 |
| 2025 | StruQ: Defending Against Prompt Injection with Structured Queries
Sizhe Chen, Julien Piet, Chawin Sitawarin, David A. Wagner 0001 |
USENIX Security Symposium | 4 |
| 2024 | Jatmo: Prompt Injection Defense by Task-Specific Finetuning
Julien Piet, Maha Alrashed, Chawin Sitawarin, Sizhe Chen, Zeming Wei, Elizabeth Sun, Basel Alomair, David A. Wagner 0001 |
ESORICS (1) | 8 |
| 2024 | PubDef: Defending Against Transfer Attacks From Public ModelsabstractAdversarial attacks have been a looming and unaddressed threat in the industry. However, through a decade-long history of the robustness evaluation literature, we have learned that mounting a strong or optimal attack is challenging. It requires both machine learning and domain expertise. In other words, the white-box threat model, religiously assumed by a large majority of the past literature, is unrealistic. In this paper, we propose a new practical threat model where the adversary relies on transfer attacks through publicly available surrogate models. We argue that this setting will become the most prevalent for security-sensitive applications in the future. We evaluate the transfer attacks in this setting and propose a specialized defense method based on a game-theoretic perspective. The defenses are evaluated under 24 public models and 11 attack algorithms across three datasets (CIFAR-10, CIFAR-100, and ImageNet). Under this threat model, our defense, PubDef, outperforms the state-of-the-art white-box adversarial training by a large margin with almost no loss in the normal accuracy. For instance, on ImageNet, our defense achieves 62% accuracy under the strongest transfer attack vs only 36% of the best adversarially trained model. Its accuracy when not under attack is only 2% lower than that of an undefended model (78% vs 80%). We release our code at https://github.com/wagner-group/pubdef. Chawin Sitawarin, Jaewon Chang, Wesson Altoyan, David A. Wagner 0001 |
ICLR | 5 |
| 2024 | Toxicity Detection for FreeabstractCurrent LLMs are generally aligned to follow safety requirements and tend to refuse toxic prompts. However, LLMs can fail to refuse toxic prompts or be overcautious and refuse benign examples. In addition, state-of-the-art toxicity detectors have low TPRs at low FPR, incurring high costs in real-world applications where toxic examples are rare. In this paper, we introduce Moderation Using LLM Introspection (MULI), which detects toxic prompts using the information extracted directly from LLMs themselves. We found we can distinguish between benign and toxic prompts from the distribution of the first response token's logits. Using this idea, we build a robust detector of toxic prompts using a sparse logistic regression model on the first response token logits. Our scheme outperforms SOTA detectors under multiple metrics. Zhanhao Hu, Julien Piet, Geng Zhao 0002, Jiantao Jiao, David A. Wagner 0001 |
NeurIPS | 5 |
| 2023 | REAP: A Large-Scale Realistic Adversarial Patch BenchmarkabstractMachine learning models are known to be susceptible to adversarial perturbation. One famous attack is the adversarial patch, a particularly crafted sticker that makes the model mispredict the object it is placed on. This attack presents a critical threat to cyber-physical systems that rely on cameras such as autonomous cars. Despite the significance of the problem, conducting research in this setting has been difficult; evaluating attacks and defenses in the real world is exceptionally costly while synthetic data are unrealistic. In this work, we propose the REAP (REalistic Adversarial Patch) benchmark, a digital benchmark that enables the evaluations on real images under real-world conditions. Built on top of the Mapillary Vistas dataset, our benchmark contains over 14,000 traffic signs. Each sign is augmented with geometric and lighting transformations for applying a digitally generated patch realistically onto the sign. Using our benchmark, we perform the first large-scale assessments of adversarial patch attacks under realistic conditions. Our experiments suggest that patch attacks may present a smaller threat than previously believed and that the success rate of an attack on simpler digital simulations is not predictive of its actual effectiveness in practice. Our benchmark is released publicly at https://github.com/wagner-group/reap-benchmark. Nabeel Hingun, Chawin Sitawarin, David A. Wagner 0001 |
ICCV | 4 |
| 2023 | Part-Based Models Improve Adversarial Robustness
Chawin Sitawarin, Kornrapat Pongmala, Yizheng Chen 0001, Nicholas Carlini, David A. Wagner 0001 |
ICLR | 5 |
| 2023 | DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability DetectionabstractWe propose and release a new vulnerable source code dataset. We curate the dataset by crawling security issue websites, extracting vulnerability-fixing commits and source codes from the corresponding projects. Our new dataset contains 18,945 vulnerable functions spanning 150 CWEs and 330,492 non-vulnerable functions extracted from 7,514 commits. Our dataset covers 295 more projects than all previous datasets combined. Yizheng Chen 0001, Zhoujie Ding, Lamya Alowain, David A. Wagner 0001 |
RAID | 5 |
| 2023 | Continuous Learning for Android Malware Detection
Yizheng Chen 0001, Zhoujie Ding, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2023 | Network Detection of Interactive SSH Impostors Using Deep Learning
Julien Piet, Aashish Sharma, Vern Paxson, David A. Wagner 0001 |
USENIX Security Symposium | 4 |
| 2022 | SLIP: Self-supervision Meets Language-Image Pre-training
Norman Mu, Alexander Kirillov, David A. Wagner 0001, Saining Xie |
ECCV (26) | 3 |
| 2022 | Demystifying the Adversarial Robustness of Random Transformation DefensesabstractNeural networks’ lack of robustness against attacks raises concerns in security-sensitive settings such as autonomous vehicles. While many countermeasures may look promising, only a few withstand rigorous evaluation. Defenses using random transformations (RT) have shown impressive results, particularly BaRT (Raff et al., 2019) on ImageNet. However, this type of defense has not been rigorously evaluated, leaving its robustness properties poorly understood. Their stochastic properties make evaluation more challenging and render many proposed attacks on deterministic models inapplicable. First, we show that the BPDA attack (Athalye et al., 2018a) used in BaRT’s evaluation is ineffective and likely overestimates its robustness. We then attempt to construct the strongest possible RT defense through the informed selection of transformations and Bayesian optimization for tuning their parameters. Furthermore, we create the strongest possible attack to evaluate our RT defense. Our new attack vastly outperforms the baseline, reducing the accuracy by 83% compared to the 19% reduction by the commonly used EoT attack ($4.3\times$ improvement). Our result indicates that the RT defense on the Imagenette dataset (a ten-class subset of ImageNet) is not robust against adversarial examples. Extending the study further, we use our new attack to adversarially train RT defense (called AdvRT), resulting in a large robustness gain. Code is available at https://github.com/wagnergroup/demystify-random-transform. Chawin Sitawarin, Zachary J. Golan-Strieb, David A. Wagner 0001 |
ICML | 3 |
| 2022 | Can Humans Detect Malicious Always-Listening Assistants? A Framework for Crowdsourcing Test DrivesabstractAs intelligent voice assistants become more widespread and the scope of their listening increases, they become attractive targets for attackers. In the future, a malicious actor could train voice assistants to listen to audio outside their purview, creating a threat to users' privacy and security. How can this misbehavior be detected? Due to the ambiguities of natural language, people may need to work in conjunction with algorithms to determine whether a given conversation should be heard. To investigate how accurately humans can perform this task, we developed a framework for people to conduct "Test Drives" of always-listening services: after submitting sample conversations, users receive instant feedback about whether these would have been captured. Leveraging a Wizard of Oz interface, we conducted a study with 200 participants to determine whether they could detect one of four types of attacks on three different services. We studied the behavior of individuals, as well as groups working collaboratively, and investigated the effects of task framing on performance. We found that individuals were able to successfully detect malicious apps at varying rates (7.5% to 75%), depending on the type of malicious attack, and that groups were highly successful when considered collectively. Our results suggest that the Test Drive framework can be an effective tool for studying user behaviors and concerns, as well as a potentially welcome addition to voice assistant app stores, where it could decrease privacy concerns surrounding always-listening services. Nathan Malkin, David A. Wagner 0001, Serge Egelman |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2021 | Learning Security Classifiers with Verified Global Robustness PropertiesabstractMany recent works have proposed methods to train classifiers with local robustness properties, which can provably eliminate classes of evasion attacks for most inputs, but not all inputs. Since data distribution shift is very common in security applications, e.g., often observed for malware detection, local robustness cannot guarantee that the property holds for unseen inputs at the time of deploying the classifier. Therefore, it is more desirable to enforce global robustness properties that hold for all inputs, which is strictly stronger than local robustness. In this paper, we present a framework and tools for training classifiers that satisfy global robustness properties. We define new notions of global robustness that are more suitable for security classifiers. We design a novel booster-fixer training framework to enforce global robustness properties. We structure our classifier as an ensemble of logic rules and design a new verifier to verify the properties. In our training algorithm, the booster increases the classifier's capacity, and the fixer enforces verified global robustness properties following counterexample guided inductive synthesis. Yizheng Chen 0001, Shiqi Wang 0002, Xiaojing Liao, Suman Jana, David A. Wagner 0001 |
CCS | 6 |
| 2021 | Adversarial Examples for k-Nearest Neighbor Classifiers Based on Higher-Order Voronoi DiagramsabstractAdversarial examples are a widely studied phenomenon in machine learning models. While most of the attention has been focused on neural networks, other practical models also suffer from this issue. In this work, we propose an algorithm for evaluating the adversarial robustness of $k$-nearest neighbor classification, i.e., finding a minimum-norm adversarial example. Diverging from previous proposals, we propose the first geometric approach by performing a search that expands outwards from a given input point. On a high level, the search radius expands to the nearby higher-order Voronoi cells until we find a cell that classifies differently from the input point. To scale the algorithm to a large $k$, we introduce approximation steps that find perturbation with smaller norm, compared to the baselines, in a variety of datasets. Furthermore, we analyze the structural properties of a dataset where our approach outperforms the competition. Chawin Sitawarin, Evgenios M. Kornaropoulos, Dawn Song, David A. Wagner 0001 |
NeurIPS | 4 |
| 2021 | Hopper: Modeling and Detecting Lateral Movement
Grant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson, Stefan Savage, Geoffrey M. Voelker, David A. Wagner 0001 |
USENIX Security Symposium | 7 |
| 2019 | Privacy controls for always-listening devicesabstractIntelligent voice assistants (IVAs) and other voice-enabled devices already form an integral component of the Internet of Things and will continue to grow in popularity. As their capabilities evolve, they will move beyond relying on the wake-words today's IVAs use, engaging instead in continuous listening. Though potentially useful, the continuous recording and analysis of speech can pose a serious threat to individuals' privacy. Ideally, users would be able to limit or control the types of information such devices have access to. But existing technical approaches are insufficient for enforcing any such restrictions. To begin formulating a solution, we develop a systematic methodology for studying continuous-listening applications and survey architectural approaches to designing a system that enhances privacy while preserving the benefits of always-listening assistants. Nathan Malkin, Serge Egelman, David A. Wagner 0001 |
NSPW | 3 |
| 2019 | Detecting and Characterizing Lateral Phishing at Scale
Grant Ho, Asaf Cidon, Lior Gavish, Marco Schweighauser, Vern Paxson, Stefan Savage, Geoffrey M. Voelker, David A. Wagner 0001 |
USENIX Security Symposium | 8 |
| 2019 | Privacy Attitudes of Smart Speaker UsersabstractAbstract As devices with always-on microphones located in people’s homes, smart speakers have significant privacy implications. We surveyed smart speaker owners about their beliefs, attitudes, and concerns about the recordings that are made and shared by their devices. To ground participants’ responses in concrete interactions, rather than collecting their opinions abstractly, we framed our survey around randomly selected recordings of saved interactions with their devices. We surveyed 116 owners of Amazon and Google smart speakers and found that almost half did not know that their recordings were being permanently stored and that they could review them; only a quarter reported reviewing interactions, and very few had ever deleted any. While participants did not consider their own recordings especially sensitive, they were more protective of others’ recordings (such as children and guests) and were strongly opposed to use of their data by third parties or for advertising. They also considered permanent retention, the status quo, unsatisfactory. Based on our findings, we make recommendations for more agreeable data retention policies and future privacy controls. Nathan Malkin, Joe Deatrick, Allen Tong, Primal Wijesekera, Serge Egelman, David A. Wagner 0001 |
Proc. Priv. Enhancing Technol. | 6 |
| 2018 | Contextualizing Privacy Decisions for Better Prediction (and Protection)abstractModern mobile operating systems implement an ask-on-first-use policy to regulate applications' access to private user data: the user is prompted to allow or deny access to a sensitive resource the first time an app attempts to use it. Prior research shows that this model may not adequately capture user privacy preferences because subsequent requests may occur under varying contexts. To address this shortcoming, we implemented a novel privacy management system in Android, in which we use contextual signals to build a classifier that predicts user privacy preferences under various scenarios. We performed a 37-person field study to evaluate this new permission model under normal device usage. From our exit interviews and collection of over 5 million data points from participants, we show that this new permission model reduces the error rate by 75% (i.e., fewer privacy violations), while preserving usability. We offer guidelines for how platforms can better support user privacy decision making. Primal Wijesekera, Joel Reardon, Irwin Reyes, Lynn Tsai, Jung-Wei Chen, Nathaniel Good, David A. Wagner 0001, Konstantin Beznosov, Serge Egelman |
CHI | 7 |
| 2018 | Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial ExamplesabstractWe identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples. While defenses that cause obfuscated gradients appear to defeat iterative optimization-based attacks, we find defenses relying on this effect can be circumvented. We describe characteristic behaviors of defenses exhibiting the effect, and for each of the three types of obfuscated gradients we discover, we develop attack techniques to overcome it. In a case study, examining non-certified white-box-secure defenses at ICLR 2018, we find obfuscated gradients are a common occurrence, with 7 of 9 defenses relying on obfuscated gradients. Our new attacks successfully circumvent 6 completely, and 1 partially, in the original threat model each paper considers. Anish Athalye, Nicholas Carlini, David A. Wagner 0001 |
ICML | 3 |
| 2018 | Inferring Phone Location StateabstractSmartphone sensors are becoming more universal and more accurate. In this paper, we aim to distinguish between four common positions or states a phone can be in: in the hand, pocket, backpack, or on a table. Using a uniquely designed neural network and data from the accelerometer and the screen state, we achieve a 92% accuracy on the same phone. We also explore extending this to different phones and propose an acceleration calibration technique to do so. Steven Chen, Won Park, Joanna Yang, David A. Wagner 0001 |
WiMob | 4 |
| 2017 | Security and Machine LearningabstractMachine learning has seen increasing use for a wide range of practical applications. What are the security implications of relying upon machine learning in these settings? Recent research suggests that modern machine learning methods are fragile and easily attacked, which raises concerns about their use in security-critical settings. This talk will explore several attacks on machine learning and survey directions for making machine learning more robust against attack. David A. Wagner 0001 |
CCS | 1 |
| 2017 | Turtle Guard: Helping Android Users Apply Contextual Privacy Preferences
Lynn Tsai, Primal Wijesekera, Joel Reardon, Irwin Reyes, Serge Egelman, David A. Wagner 0001, Nathaniel Good, Jung-Wei Chen |
SOUPS | 6 |
| 2017 | Towards Evaluating the Robustness of Neural NetworksabstractNeural networks provide state-of-the-art results for most machine learning tasks. Unfortunately, neural networks are vulnerable to adversarial examples: given an input x and any target classification t, it is possible to find a new input x' that is similar to x but classified as t. This makes it difficult to apply neural networks in security-critical areas. Defensive distillation is a recently proposed approach that can take an arbitrary neural network, and increase its robustness, reducing the success rate of current attacks' ability to find adversarial examples from 95% to 0.5%. In this paper, we demonstrate that defensive distillation does not significantly increase the robustness of neural networks by introducing three new attack algorithms that are successful on both distilled and undistilled neural networks with 100% probability. Our attacks are tailored to three distance metrics used previously in the literature, and when compared to previous adversarial example generation algorithms, our attacks are often much more effective (and never worse). Furthermore, we propose using high-confidence adversarial examples in a simple transferability test we show can also be used to break defensive distillation. We hope our attacks will be used as a benchmark in future defense attempts to create neural networks that resist adversarial examples. Nicholas Carlini, David A. Wagner 0001 |
IEEE Symposium on Security and Privacy | 2 |
| 2017 | The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesabstractCurrent smartphone operating systems regulate application permissions by prompting users on an ask-on-first-use basis. Prior research has shown that this method is ineffective because it fails to account for context: the circumstances under which an application first requests access to data may be vastly different than the circumstances under which it subsequently requests access. We performed a longitudinal 131-person field study to analyze the contextuality behind user privacy decisions to regulate access to sensitive resources. We built a classifier to make privacy decisions on the user's behalf by detecting when context has changed and, when necessary, inferring privacy preferences based on the user's past decisions and behavior. Our goal is to automatically grant appropriate resource requests without further user intervention, deny inappropriate requests, and only prompt the user when the system is uncertain of the user's preferences. We show that our approach can accurately predict users' privacy decisions 96.8% of the time, which is a four-fold reduction in error rate compared to current systems. Primal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon, Serge Egelman, David A. Wagner 0001, Konstantin Beznosov |
IEEE Symposium on Security and Privacy | 6 |
| 2017 | Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling Pointers
Thurston H. Y. Dang, Petros Maniatis, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2017 | Detecting Credential Spearphishing in Enterprise Settings
Grant Ho, Aashish Sharma, Mobin Javed, Vern Paxson, David A. Wagner 0001 |
USENIX Security Symposium | 5 |
| 2017 | A Usability Evaluation of Tor LauncherabstractAbstract Although Tor has state-of-the art anticensorship measures, users in heavily censored environments will not be able to connect to Tor if they cannot configure their connections. We perform the first usability evaluation of Tor Launcher, the graphical user interface (GUI) that Tor Browser uses to configure connections to Tor. Our study shows that 79% (363 of 458) of user attempts to connect to Tor in simulated censored environments failed. We found that users were often frustrated during the process and tried options at random. In this paper, we measure potential usability issues, discuss design constraints unique to Tor, and provide recommendations based on what we learned to help more users connect to Tor while reducing the time they take to do so. Tor Browser incorporated the changes proposed by this study. Linda Naeun Lee, David Fifield, Nathan Malkin, Ganesh Iyer, Serge Egelman, David A. Wagner 0001 |
Proc. Priv. Enhancing Technol. | 6 |
| 2016 | Attestation Transparency: Building secure Internet services for legacy clientsabstractInternet services can provide a wealth of functionality, yet their usage raises privacy, security and integrity concerns for users. This is caused by a lack of guarantees about what is happening on the server side. As a worst case scenario, the service might be subjected to an insider attack. We use remote attestation of the server to obtain guarantees about the programming of the service. On top of that, we augment Certificate Transparency to distribute information about which services exist and what they do. Combined, this creates a platform that allows legacy clients to obtain security guarantees about Internet services. Jethro G. Beekman, John Manferdelli, David A. Wagner 0001 |
AsiaCCS | 3 |
| 2016 | Smart Locks: Lessons for Securing Commodity Internet of Things DevicesabstractWe examine the security of home smart locks: cyber-physical devices that replace traditional door locks with deadbolts that can be electronically controlled by mobile devices or the lock manufacturer's remote servers. We present two categories of attacks against smart locks and analyze the security of five commercially-available locks with respect to these attacks. Our security analysis reveals that flaws in the design, implementation, and interaction models of existing locks can be exploited by several classes of adversaries, allowing them to learn private information about users and gain unauthorized home access. To guide future development of smart locks and similar Internet of Things devices, we propose several defenses that mitigate the attacks we present. One of these defenses is a novel approach to securely and usably communicate a user's intended actions to smart locks, which we prototype and evaluate. Ultimately, our work takes a first step towards illuminating security challenges in the system design and novel functionality introduced by emerging IoT systems. Grant Ho, Derek Leung, Pratyush Mishra 0001, Ashkan Hosseini, Dawn Song, David A. Wagner 0001 |
AsiaCCS | 6 |
| 2016 | Hidden Voice Commands
Nicholas Carlini, Pratyush Mishra 0001, Tavish Vaidya, Yuankai Zhang 0001, Micah Sherr, Clay Shields, David A. Wagner 0001, Wenchao Zhou |
USENIX Security Symposium | 7 |
| 2015 | The Performance Cost of Shadow Stacks and Stack CanariesabstractControl flow defenses against ROP either use strict, expensive, but strong protection against redirected RET instructions with shadow stacks, or much faster but weaker protections without. In this work we study the inherent overheads of shadow stack schemes. We find that the overhead is roughly 10% for a traditional shadow stack. We then design a new scheme, the parallel shadow stack, and show that its performance cost is significantly less: 3.5%. Our measurements suggest it will not be easy to improve performance on current x86 processors further, due to inherent costs associated with RET and memory load/store instructions. We conclude with a discussion of the design decisions in our shadow stack instrumentation, and possible lighter-weight alternatives. Thurston H. Y. Dang, Petros Maniatis, David A. Wagner 0001 |
AsiaCCS | 3 |
| 2015 | Somebody's Watching Me?: Assessing the Effectiveness of Webcam Indicator LightsabstractMost laptops and personal computers have webcams with LED indicators to notify users when they are recording. Because hackers use surreptitiously captured webcam recordings to extort users, we explored the effectiveness of these indicators under varying circumstances and how they could be improved. We observed that, on average, fewer than half of our participants (45%) noticed the existing indicator during computer-based tasks. When seated in front of the computer performing a paper-based task, only 5% noticed the indicator. We performed a followup experiment to evaluate a new indicator and observed that adding onscreen glyphs had a significant impact on both computer-based and non-computer-based tasks (93% and 59% noticed the new indicator, respectively). We discuss how our results can be integrated into current systems, as well as future ubiquitous computing systems. Rebecca S. Portnoff, Linda Naeun Lee, Serge Egelman, Pratyush Mishra 0001, Derek Leung, David A. Wagner 0001 |
CHI | 6 |
| 2015 | Control-Flow Bending: On the Effectiveness of Control-Flow Integrity
Nicholas Carlini, Antonio Barresi, Mathias Payer, David A. Wagner 0001, Thomas R. Gross |
USENIX Security Symposium | 4 |
| 2015 | Android Permissions Remystified: A Field Study on Contextual Integrity
Primal Wijesekera, Arjun Baokar, Ashkan Hosseini, Serge Egelman, David A. Wagner 0001, Konstantin Beznosov |
USENIX Security Symposium | 5 |
| 2014 | Are You Ready to Lock?abstractIn addition to storing a plethora of sensitive personal and work information, smartphones also store sensor data about users and their daily activities. In order to understand users' behaviors and attitudes towards the security of their smartphone data, we conducted 28 qualitative interviews. We examined why users choose (or choose not) to employ locking mechanisms (e.g., PINs) and their perceptions and awareness about the sensitivity of the data stored on their devices. We performed two additional online experiments to quantify our interview results and the extent to which sensitive data could be found in a user's smartphone-accessible email archive. We observed a strong correlation between use of security features and risk perceptions, which indicates rational behavior. However, we also observed that most users likely underestimate the extent to which data stored on their smartphones pervades their identities, online and offline. Serge Egelman, Sakshi Jain, Rebecca S. Portnoff, Kerwell Liao, Sunny Consolvo, David A. Wagner 0001 |
CCS | 6 |
| 2014 | The effect of developer-specified explanations for permission requests on smartphone user behaviorabstractIn Apple's iOS 6, when an app requires access to a protected resource (e.g., location or photos), the user is prompted with a permission request that she can allow or deny. These permission request dialogs include space for developers to optionally include strings of text to explain to the user why access to the resource is needed. We examine how app developers are using this mechanism and the effect that it has on user behavior. Through an online survey of 772 smartphone users, we show that permission requests that include explanations are significantly more likely to be approved. At the same time, our analysis of 4,400 iOS apps shows that the adoption rate of this feature by developers is relatively small: around 19% of permission requests include developer-specified explanations. Finally, we surveyed 30 iOS developers to better understand why they do or do not use this feature. Joshua Tan 0002, Michael Theodorides, Heidi Negrón-Arroyo, Christopher Thompson 0002, Serge Egelman, David A. Wagner 0001 |
CHI | 7 |
| 2014 | ROP is Still Dangerous: Breaking Modern Defenses
Nicholas Carlini, David A. Wagner 0001 |
USENIX Security Symposium | 2 |
| 2013 | Do Android users write about electric sheep? Examining consumer reviews in Google PlayabstractConsumer reviews and star ratings are integral to application markets. The content of reviews help consumers determine whether an application is “good” or not. Since consumers rely heavily on reviews when selecting applications, we wanted to know what was being written about in reviews. In particular, we wanted to know if users were discussing privacy and security risks of an application, and if not, what were they writing about instead? In our work, we manually analyzed Android users' reviews to see what they write about when reviewing Google Play applications. Overall, only 1% of our reviews mentioned application permissions. We also found that a small subset of reviews relating to preinstalled applications and applications that requested a user's rating had underlying privacy and security implications. The majority of reviews focused on the quality of applications: people often described an application using an adjective (e.g., “great app” or “horrible”), wrote about its feature/functionality, specifically said if the application worked or not, and/or put their phone or tablet model in the review. We also found that sentiment did influence reviewers' ratings of the applications. In general, the overall star rating of our sample was overwhelmingly positive, suggesting that Google Play is no different from other e-commerce sites. Elizabeth Ha, David A. Wagner 0001 |
CCNC | 2 |
| 2013 | Symbolic software model validation
Cynthia Sturton, Rohit Sinha 0001, Thurston H. Y. Dang, Sakshi Jain, Michael McCoyd, Wei Yang Tan, Petros Maniatis, Sanjit A. Seshia, David A. Wagner 0001 |
MEMOCODE | 9 |
| 2013 | When it's better to ask forgiveness than get permission: attribution mechanisms for smartphone resourcesabstractSmartphone applications pose interesting security problems because the same resources they use to enhance the user experience may also be used in ways that users might find objectionable. We performed a set of experiments to study whether attribution mechanisms could help users understand how smartphone applications access device resources. First, we performed an online survey and found that, as attribution mechanisms have become available on the Android platform, users notice and use them. Second, we designed new attribution mechanisms; a qualitative experiment suggested that our proposed mechanisms are intuitive to understand. Finally, we performed a laboratory experiment in which we simulated application misbehaviors to observe whether users equipped with our attribution mechanisms were able to identify the offending applications. Our results show that, for users who notice application misbehaviors, these attribution mechanisms are significantly more effective than the status quo. Christopher Thompson 0002, Maritza L. Johnson, Serge Egelman, David A. Wagner 0001, Jennifer King |
SOUPS | 4 |
| 2013 | An Empirical Study of Vulnerability Rewards Programs
Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2012 | AdDroid: privilege separation for applications and advertisers in AndroidabstractAdvertising is a critical part of the Android ecosystem---many applications use one or more advertising services as a source of revenue. To use these services, developers must bundle third-party, binary-only libraries into their applications. In this model, applications and their advertising libraries share permissions. Advertising-supported applications must request multiple privacy-sensitive permissions on behalf of their advertising libraries, and advertising libraries receive access to all of their host applications' other permissions. We conducted a study of the Android Market and found that 49% of Android applications contain at least one advertising library, and these libraries overprivilege 46% of advertising-supported applications. Further, we find that 56% of the applications with advertisements that request location (34% of all applications) do so only because of advertisements. Such pervasive overprivileging is a threat to user privacy. We introduce AdDroid, a privilege separated advertising framework for the Android platform. AdDroid introduces a new advertising API and corresponding advertising permissions for the Android platform. This enables AdDroid to separate privileged advertising functionality from host applications, allowing applications to show advertisements without requesting privacy-sensitive permissions. Paul Pearce, Adrienne Porter Felt, Gabriel Nunez, David A. Wagner 0001 |
AsiaCCS | 4 |
| 2012 | Verification with small and short worlds
Rohit Sinha 0001, Cynthia Sturton, Petros Maniatis, Sanjit A. Seshia, David A. Wagner 0001 |
FMCAD | 5 |
| 2012 | Measuring user confidence in smartphone security and privacyabstractIn order to direct and build an effective, secure mobile ecosystem, we must first understand user attitudes toward security and privacy for smartphones and how they may differ from attitudes toward more traditional computing systems. What are users' comfort levels in performing different tasks? How do users select applications? What are their overall perceptions of the platform? This understanding will help inform the design of more secure smartphones that will enable users to safely and confidently benefit from the potential and convenience offered by mobile platforms. Erika Chin, Adrienne Porter Felt, Vyas Sekar, David A. Wagner 0001 |
SOUPS | 4 |
| 2012 | Android permissions: user attention, comprehension, and behaviorabstractAndroid's permission system is intended to inform users about the risks of installing applications. When a user installs an application, he or she has the opportunity to review the application's permission requests and cancel the installation if the permissions are excessive or objectionable. We examine whether the Android permission system is effective at warning users. In particular, we evaluate whether Android users pay attention to, understand, and act on permission information during installation. We performed two usability studies: an Internet survey of 308 Android users, and a laboratory study wherein we interviewed and observed 25 Android users. Study participants displayed low attention and comprehension rates: both the Internet survey and laboratory study found that 17% of participants paid attention to permissions during installation, and only 3% of Internet survey respondents could correctly answer all three permission comprehension questions. This indicates that current Android permission warnings do not help most users make correct security decisions. However, a notable minority of users demonstrated both awareness of permission warnings and reasonable rates of comprehension. We present recommendations for improving user attention and comprehension, as well as identify open challenges. Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, David A. Wagner 0001 |
SOUPS | 6 |
| 2012 | An Evaluation of the Google Chrome Extension Security Architecture
Nicholas Carlini, Adrienne Porter Felt, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2012 | How to Ask for Permission
Adrienne Porter Felt, Serge Egelman, Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
HotSec | 5 |
| 2011 | Android permissions demystifiedabstractAndroid provides third-party applications with an extensive API that includes access to phone hardware, settings, and user data. Access to privacy- and security-relevant parts of the API is controlled with an install-time application permission system. We study Android applications to determine whether Android developers follow least privilege with their permission requests. We built Stowaway, a tool that detects overprivilege in compiled Android applications. Stowaway determines the set of API calls that an application uses and then maps those API calls to permissions. We used automated testing tools on the Android API in order to build the permission map that is necessary for detecting overprivilege. We apply Stowaway to a set of 940 applications and find that about one-third are overprivileged. We investigate the causes of overprivilege and find evidence that developers are trying to follow least privilege but sometimes fail due to insufficient API documentation. Adrienne Porter Felt, Erika Chin, Steve Hanna, Dawn Song, David A. Wagner 0001 |
CCS | 5 |
| 2011 | Diesel: applying privilege separation to database accessabstractDatabase-backed applications typically grant complete database access to every part of the application. In this scenario, a flaw in one module can expose data that the module never uses for legitimate purposes. Drawing parallels to traditional privilege separation, we argue that database data should be subject to limitations such that each section of code receives access to only the data it needs. We call this data separation. Data separation defends against SQL-based errors including buggy queries and SQL injection attacks and facilitates code review, since a module's policy makes the extent of its database access explicit to programmers and code reviewers. We construct a system called Diesel, which implements data separation by intercepting database queries and applying modules' restrictions to the queries. We evaluate Diesel on three widely-used applications: Drupal, JForum, and WordPress. Adrienne Porter Felt, Matthew Finifter, Joel Weinberger, David A. Wagner 0001 |
AsiaCCS | 4 |
| 2011 | Analyzing inter-application communication in AndroidabstractModern smartphone operating systems support the development of third-party applications with open system APIs. In addition to an open API, the Android operating system also provides a rich inter-application message passing system. This encourages inter-application collaboration and reduces developer burden by facilitating component reuse. Unfortunately, message passing is also an application attack surface. The content of messages can be sniffed, modified, stolen, or replaced, which can compromise user privacy. Also, a malicious application can inject forged or otherwise malicious messages, which can lead to breaches of user data and violate application security policies. Erika Chin, Adrienne Porter Felt, Kate Greenwood, David A. Wagner 0001 |
MobiSys | 4 |
| 2011 | Defeating UCI: Building Stealthy and Malicious HardwareabstractIn previous work Hicks et al. proposed a method called Unused Circuit Identification (UCI) for detecting malicious backdoors hidden in circuits at design time. The UCI algorithm essentially looks for portions of the circuit that go unused during design-time testing and flags them as potentially malicious. In this paper we construct circuits that have malicious behavior, but that would evade detection by the UCI algorithm and still pass design-time test cases. To enable our search for such circuits, we define one class of malicious circuits and perform a bounded exhaustive enumeration of all circuits in that class. Our approach is simple and straight forward, yet it proves to be effective at finding circuits that can thwart UCI. We use the results of our search to construct a practical attack on an open-source processor. Our malicious backdoor allows any user-level program running on the processor to enter supervisor mode through the use of a secret â knock. We close with a discussion on what we see as a major challenge facing any future design-time malicious hardware detection scheme: identifying a sufficient class of malicious circuits to defend against. Cynthia Sturton, Matthew Hicks, David A. Wagner 0001, Samuel T. King |
IEEE Symposium on Security and Privacy | 3 |
| 2011 | Tweakable Block CiphersabstractA common trend in applications of block ciphers over the past decades has been to employ block ciphers as one piece of a “mode of operation”—possibly, a way to make a secure symmetric-key cryptosystem, but more generally, any cryptographic application. Most of the time, these modes of operation use a wide variety of techniques to achieve a subgoal necessary for their main goal: instantiation of “essentially different” instances of the block cipher. We formalize a cryptographic primitive, the “ tweakable block cipher .” Such a cipher has not only the usual inputs—message and cryptographic key—but also a third input, the “tweak.” The tweak serves much the same purpose that an initialization vector does for CBC mode or that a nonce does for OCB mode. Our abstraction brings this feature down to the primitive block-cipher level, instead of incorporating it only at the higher modes-of-operation levels. We suggest that (1) tweakable block ciphers are easy to design, (2) the extra cost of making a block cipher “tweakable” is small, and (3) it is easier to design and prove the security of applications of block ciphers that need this variability using tweakable block ciphers. Moses D. Liskov, Ronald L. Rivest, David A. Wagner 0001 |
J. Cryptol. | 3 |
| 2010 | Joe-E: A Security-Oriented Subset of Java
Adrian Mettler, David A. Wagner 0001, Tyler Close |
NDSS | 2 |
| 2010 | Fine-grained privilege separation for web applicationsabstractWe present a programming model for building web applications with security properties that can be confidently verified during a security review. In our model, applications are divided into isolated, privilege-separated components, enabling rich security policies to be enforced in a way that can be checked by reviewers. In our model, the web framework enforces privilege separation and isolation of web applications by requiring the use of an object-capability language and providing interfaces that expose limited, explicitly-specified privileges to application components. This approach restricts what each component of the application can do and quarantines buggy or compromised code. It also provides a way to more safely integrate third-party, less-trusted code into a web application. We have implemented a prototype of this model based upon the Java Servlet framework and used it to build a webmail application. Our experience with this example suggests that the approach is viable and helpful at establishing reviewable application-specific security properties. Akshay Krishnamurthy, Adrian Mettler, David A. Wagner 0001 |
WWW | 3 |
| 2009 | On voting machine design for verification and testabilityabstractWe present an approach for the design and analysis of an electronic voting machine based on a novel combination of formal verification and systematic testing. The system was designed specifically to enable verification and testing. In our architecture, the voting machine is a finite-state transducer that implements the bare essentials required for an election. We formally specify how each component of the machine is intended to work and formally verify that a Verilog implementation of our design meets this specification. However, it is more challenging to verify that the composition of these components will behave as a voter would expect, because formalizing human expectations is difficult. We show how systematic testing can be used to address this issue, and in particular to verify that the machine will behave correctly on election day. Cynthia Sturton, Susmit Jha, Sanjit A. Seshia, David A. Wagner 0001 |
CCS | 4 |
| 2009 | Conditioned-safe Ceremonies and a User Study of an Application to Web Authentication
Chris Karlof, J. D. Tygar, David A. Wagner 0001 |
NDSS | 3 |
| 2009 | Conditioned-safe ceremonies and a user study of an application to web authenticationabstractNo abstract available. Chris Karlof, J. D. Tygar, David A. Wagner 0001 |
SOUPS | 3 |
| 2009 | Dynamic Test Generation to Find Integer Bugs in x86 Binary Linux Programs
David Molnar, Xue Cong Li, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2009 | A graph approach to quantitative analysis of control-flow obfuscating transformationsabstractModern obfuscation techniques are intended to discourage reverse engineering and malicious tampering of software programs. We study control-flow obfuscation, which works by modifying the control flow of the program to be obfuscated, and observe that it is difficult to evaluate the robustness of these obfuscation techniques. In this paper, we present a framework for quantitative analysis of control-flow obfuscating transformations. Our framework is based upon the control-flow graph of the program, and we show that many existing control-flow obfuscation techniques can be expressed as a sequence of basic transformations on these graphs. We also propose a new measure of the difficulty of reversing these obfuscated programs, and we show that our framework can be used to easily evaluate the space penalty due to the transformations. Hsin-Yi Tsai, Yu-Lun Huang, David A. Wagner 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2008 | Verifiable functional purity in javaabstractProving that particular methods within a code base are functionally pure--deterministic and side-effect free--would aid verification of security properties including function invertibility, reproducibility of computation, and safety of untrusted code execution. Until now it has not been possible to automatically prove a method is functionally pure within a high-level imperative language in wide use, such as Java. We discuss a technique to prove that methods are functionally pure by writing programs in a subset of Java called Joe-E; a static verifier ensures that programs fall within the subset. In Joe-E, pure methods can be trivially recognized from their method signature. To demonstrate the practicality of our approach, we refactor an AES library, an experimental voting machine implementation, and an HTML parser to use our techniques. We prove that their top-level methods are verifiably pure and show how this provides high-level security guarantees about these routines. Our approach to verifiable purity is an attractive way to permit functional-style reasoning about security properties while leveraging the familiarity, convenience, and legacy code of imperative languages. Matthew Finifter, Adrian Mettler, Naveen Sastry, David A. Wagner 0001 |
CCS | 4 |
| 2008 | Portably Solving File TOCTTOU Races with Hardness Amplification
Dan Tsafrir, Tomer Hertz, David A. Wagner 0001, Dilma Da Silva |
FAST | 3 |
| 2008 | Algebraic and Slide Attacks on KeeLoq
Nicolas T. Courtois, Gregory V. Bard, David A. Wagner 0001 |
FSE | 3 |
| 2008 | Portably solving file races with hardness amplificationabstractThe file-system API of contemporary systems makes programs vulnerable to TOCTTOU (time-of-check-to-time-of-use) race conditions. Existing solutions either help users to detect these problems (by pinpointing their locations in the code), or prevent the problem altogether (by modifying the kernel or its API). But the latter alternative is not prevalent, and the former is just the first step: Programmers must still address TOCTTOU flaws within the limits of the existing API with which several important tasks cannot be accomplished in a portable straightforward manner. Recently, Dean and Hu [2004] addressed this problem and suggested a probabilistic hardness amplification approach that alleviated the matter. Alas, shortly after, Borisov et al. [2005] responded with an attack termed “filesystem maze” that defeated the new approach. We begin by noting that mazes constitute a generic way to deterministically win many TOCTTOU races (gone are the days when the probability was small). In the face of this threat, we: (1) develop a new user-level defense that can withstand mazes; and (2) show that our method is undefeated even by much stronger hypothetical attacks that provide the adversary program with ideal conditions to win the race (enjoying complete and instantaneous knowledge about the defending program's actions and being able to perfectly synchronize accordingly). The fact that our approach is immune to these unrealistic attacks suggests it can be used as a simple and portable solution to a large class of TOCTTOU vulnerabilities, without requiring modifications to the underlying operating system. Dan Tsafrir, Tomer Hertz, David A. Wagner 0001, Dilma Da Silva |
ACM Trans. Storage | 3 |
| 2007 | Dynamic pharming attacks and locked same-origin policies for web browsersabstractWe describe a new attack against web authentication, which we call dynamic pharming. Dynamic pharming works by hijacking DNS and sending the victim's browser malicious Javascript, which then exploits DNS rebinding vulnerabilities and the name-based same-origin policy to hijack a legitimate session after authentication has taken place. As a result, the attack works regardless of the authentication scheme used. Dynamic pharming enables the adversary to eavesdrop on sensitive content, forge transactions, sniff secondary passwords, etc. To counter dynamic pharming attacks, we propose two locked same-origin policies for web browsers. In contrast to the legacy same-origin policy, which regulates cross-object access control in browsers using domain names, the locked same-origin policies enforce access using servers' X.509 certificates and public keys. We show how our policies help two existing web authentication mechanisms, client-side SSL and SSL-only cookies, resist both pharming and stronger active attacks. Also, we present a deployability analysis of our policies based on a study of 14651 SSL domains. Our results suggest one of our policies can be deployed today and interoperate seamlessly with the vast majority of legacy web servers. For our other policy, we present a simple incrementally deployable opt-in mechanism for legacy servers using policy files, and show how web sites can use policy files to support self-signed and untrusted certificates, shared subdomain objects, and key updates. Chris Karlof, Umesh Shankar, J. D. Tygar, David A. Wagner 0001 |
CCS | 4 |
| 2007 | Cryptanalysis of a Cognitive Authentication Scheme (Extended Abstract)abstractWe present attacks against two cognitive authentication schemes [9] proposed at the 2006 IEEE Symposium on Security and Privacy. These authentication schemes are designed to be secure against eavesdropping attacks while relying only on human cognitive skills. They achieve authentication via challenge response protocols based on a shared secret set of pictures. Our attacks use a SAT solver to recover a user's secret key in a few seconds, after observing only a small number of successful logins. These attacks demonstrate that the authentication schemes of [9] are not secure against an eavesdropping adversary. Philippe Golle, David A. Wagner 0001 |
S&P | 2 |
| 2007 | From Weak to Strong Watermarking
Nicholas Hopper, David Molnar, David A. Wagner 0001 |
TCC | 3 |
| 2006 | Cryptographic Protocols for Electronic Voting
David A. Wagner 0001 |
CRYPTO | 1 |
| 2006 | Private Circuits II: Keeping Secrets in Tamperable Circuits
Yuval Ishai, Manoj Prabhakaran 0001, Amit Sahai, David A. Wagner 0001 |
EUROCRYPT | 4 |
| 2006 | Preventing Secret Leakage from fork(): Securing Privilege-Separated ApplicationsabstractIf trusted processes' secrets or privileged system objects such as file handles are leaked to an untrusted process, the result could be the loss of secrecy and integrity of the data produced by the program. The advent of privilege-separated programs has led to an additional risk: sensitive data or system objects may be leaked when the trusted process of the privilege-separated application forks an untrusted child process. We have identified several channels by which information may flow to the child process: memory, the environment, memory mappings, filesystem information, and file descriptors. We propose fixes for each of these leaks. Some are handled by a novel static source code analysis of the target privilege-separated application's source code, but some require modifications to the kernel or compiler. As a proof of concept, we applied our technique to privilege-separated OpenSSH running on the Linux 2.6 kernel. Using our tools, we were able to verify easily that it does not leak secrets from its trusted components to its untrusted components; all sensitive data is erased or downgraded appropriately before being inherited by untrusted components. This suggests that our method is a useful way of reasoning about privilege-separated programs. Umesh Shankar, David A. Wagner 0001 |
ICC | 2 |
| 2006 | Tamper-Evident, History-Independent, Subliminal-Free Data Structures on PROM Storage-or-How to Store Ballots on a Voting Machine (Extended Abstract)abstractWe enumerate requirements and give constructions for the vote storage unit of an electronic voting machine. In this application, the record of votes must survive even an unexpected failure of the machine; hence the data structure should be durable. At the same time, the order in which votes are cast must be hidden to protect the privacy of voters, so the data structure should be history-independent. Adversaries may try to surreptitiously add or delete votes from the storage unit after the election has concluded, so the storage should be tamper-evident. Finally, we must guard against an adversarial voting machine's attempts to mark ballots through the representation of the data structure, so we desire a subliminal-free representation. We leverage the properties of Programmable Read Only Memory (PROM), a special kind of write-once storage medium, to meet these requirements. We give constructions for data structures on PROM storage that simultaneously satisfy all our desired properties. Our techniques can significantly reduce the need to verify code running on a voting machine. David Molnar, Tadayoshi Kohno, Naveen Sastry, David A. Wagner 0001 |
S&P | 4 |
| 2006 | Security considerations for incremental hash functions based on pair block chaining
Raphael C.-W. Phan, David A. Wagner 0001 |
Comput. Secur. | 2 |
| 2005 | Model Checking An Entire Linux Distribution for Security ViolationsabstractSoftware model checking has become a popular tool for verifying programs' behavior. Recent results suggest that it is viable for finding and eradicating security bugs quickly. However, even state-of-the-art model checkers are limited in use when they report an overwhelming number of false positives, or when their lengthy running time dwarfs other software development processes. In this paper we report our experiences with software model checking for security properties on an extremely large scale - an entire Linux distribution consisting of 839 packages and 60 million lines of code. To date, we have discovered 108 exploitable bugs. Our results indicate that model checking can be both a feasible and integral part of the software development process Benjamin Schwarz, Hao Chen 0003, David A. Wagner 0001, Jeremy Lin, Wei Tu 0001, Geoff Morrison, Jacob West |
ACSAC | 3 |
| 2005 | Fault Attacks on Dual-Rail Encoded SystemsabstractFault induction attacks are a serious concern for designers of secure embedded systems. An ideal solution would be a generic circuit transformation that would produce circuits that are robust against fault induction attacks. We develop a framework for analyzing the security of systems against single fault attacks and apply it to a recent proposed method (dual-rail encoding) for generically securing circuits against single fault attacks. Ultimately, we find that the method does not hold up under our threat models: n-bit cryptographic keys can be extracted from the device with roughly n trials. We conclude that secure designs should incorporate explicit countermeasures to either directly address or attempt to invalidate our threat models. Jason Waddle, David A. Wagner 0001 |
ACSAC | 2 |
| 2005 | Security and Privacy Issues in E-passportsabstractWithin the next year, travelers from dozens of nations may be carrying a new form of passport in response to a mandate by the United States government. The e-passport, as it is sometimes called, represents a bold initiative in the deployment of two new technologies: Radio-Frequency Identification (RFID) and biometrics. Important in their own right, e-passports are also the harbinger of a wave of next-generation ID cards: several national governments plan to deploy identity cards integrating RFID and biometrics for domestic use. We explore the privacy and security implications of this impending worldwide experiment in next-generation authentication technology. We describe privacy and security issues that apply to e-passports, then analyze these issues in the context of the International Civil Aviation Organization (ICAO) standard for e-passports. 1 Ari Juels, David Molnar, David A. Wagner 0001 |
SecureComm | 3 |
| 2005 | Cryptographic Voting Protocols: A Systems Perspective
Chris Karlof, Naveen Sastry, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2005 | A class of polynomially solvable range constraints for interval analysis without widenings
Zhendong Su 0001, David A. Wagner 0001 |
Theor. Comput. Sci. | 2 |
| 2004 | Privacy and security in library RFID: issues, practices, and architecturesabstractWe expose privacy issues related to Radio Frequency Identification (RFID) in libraries, describe current deployments, and suggest novel architectures for library RFID. Libraries are a fast growing application of RFID; the technology promises to relieve repetitive strain injury, speed patron self-checkout, and make possible comprehensive inventory. Unlike supply-chain RFID, library RFID requires item-level tagging, thereby raising immediate patron privacy issues. Current conventional wisdom suggests that privacy risks are negligible unless an adversary has access to library databases. We show this is not the case. In addition, we identify private authentication as a key technical issue: how can a reader and tag that share a secret efficiently authenticate each other without revealing their identities to an adversary? Previous solutions to this problem require reader work linear in the number of tags. We give a general scheme for building private authentication with work logarithmic in the number of tags, given a scheme with linear work as a sub protocol. This scheme may be of independent interest beyond RFID applications. We also give a simple scheme that provides security against a passive eavesdropper using XOR alone, without pseudo-random functions or other heavy crypto operations. David Molnar, David A. Wagner 0001 |
CCS | 2 |
| 2004 | Cryptanalysis of a provably secure CRT-RSA algorithmabstractWe study a countermeasure proposed to protect Chinese remainder theorem (CRT) computations for RSA against fault attacks. The scheme was claimed to be provably secure. However, we demonstrate that the proposal is in fact insecure: it can be broken with a simple and practical fault attack. We conclude that the proposed countermeasure is not safe for use in its present form. David A. Wagner 0001 |
CCS | 1 |
| 2004 | Towards Efficient Second-Order Power Analysis
Jason Waddle, David A. Wagner 0001 |
CHES | 2 |
| 2004 | The EAX Mode of Operation
Mihir Bellare, Phillip Rogaway, David A. Wagner 0001 |
FSE | 3 |
| 2004 | Towards a Unifying View of Block Cipher Cryptanalysis
David A. Wagner 0001 |
FSE | 1 |
| 2004 | Model Checking One Million Lines of C Code
Hao Chen 0003, Drew Dean, David A. Wagner 0001 |
NDSS | 3 |
| 2004 | TinySec: a link layer security architecture for wireless sensor networksabstractWe introduce TinySec, the first fully-implemented link layer security architecture for wireless sensor networks. In our design, we leverage recent lessons learned from design vulnerabilities in security protocols for other wireless networks such as 802.11b and GSM. Conventional security protocols tend to be conservative in their security guarantees, typically adding 16--32 bytes of overhead. With small memories, weak processors, limited energy, and 30 byte packets, sensor networks cannot afford this luxury. TinySec addresses these extreme resource constraints with careful design; we explore the tradeoffs among different cryptographic primitives and use the inherent sensor network limitations to our advantage when choosing parameters to find a sweet spot for security, packet overhead, and resource requirements. TinySec is portable to a variety of hardware and radio platforms. Our experimental results on a 36 node distributed sensor network application clearly demonstrate that software based link layer protocols are feasible and efficient, adding less than 10% energy, latency, and bandwidth overhead. Chris Karlof, Naveen Sastry, David A. Wagner 0001 |
SenSys | 3 |
| 2004 | A Class of Polynomially Solvable Range Constraints for Interval Analysis without Widenings and Narrowings
Zhendong Su 0001, David A. Wagner 0001 |
TACAS | 2 |
| 2004 | On Compressing Encrypted Data without the Encryption Key
David A. Wagner 0001, Kannan Ramchandran |
TCC | 2 |
| 2004 | Finding User/Kernel Pointer Bugs with Type Inference
David A. Wagner 0001 |
USENIX Security Symposium | 2 |
| 2003 | Hidden Markov Model Cryptanalysis
Chris Karlof, David A. Wagner 0001 |
CHES | 2 |
| 2003 | Private Circuits: Securing Hardware against Probing Attacks
Yuval Ishai, Amit Sahai, David A. Wagner 0001 |
CRYPTO | 3 |
| 2003 | Cryptanalysis of an Algebraic Privacy Homomorphism
David A. Wagner 0001 |
ISC | 1 |
| 2003 | Secure routing in wireless sensor networks: attacks and countermeasures
Chris Karlof, David A. Wagner 0001 |
Ad Hoc Networks | 2 |
| 2002 | MOPS: an infrastructure for examining security properties of softwareabstractWe describe a formal approach for finding bugs in security-relevant software and verifying their absence. The idea is as follows: we identify rules of safe programming practice, encode them as safety properties, and verify whether these properties are obeyed. Because manual verification is too expensive, we have built a program analysis tool to automate this process. Our program analysis models the program to be verified as a pushdown automaton, represents the security property as a finite state automaton, and uses model checking techniques to identify whether any state violating the desired security goal is reachable in the program. The major advantages of this approach are that it is sound in verifying the absence of certain classes of vulnerabilities, that it is fully interprocedural, and that it is efficient and scalable. Experience suggests that this approach will be useful in finding a wide range of security vulnerabilities in large programs efficiently. Hao Chen 0003, David A. Wagner 0001 |
CCS | 2 |
| 2002 | Mimicry attacks on host-based intrusion detection systemsabstractWe examine several host-based anomaly detection systems and study their security against evasion attacks. First, we introduce the notion of a mimicry attack, which allows a sophisticated attacker to cloak their intrusion to avoid detection by the IDS. Then, we develop a theoretical framework for evaluating the security of an IDS against mimicry attacks. We show how to break the security of one published IDS with these methods, and we experimentally confirm the power of mimicry attacks by giving a worked example of an attack on a concrete IDS implementation. We conclude with a call for further research on intrusion detection from both attacker's and defender's viewpoints. David A. Wagner 0001, Paolo Soto |
CCS | 1 |
| 2002 | Tweakable Block Ciphers
Moses D. Liskov, Ronald L. Rivest, David A. Wagner 0001 |
CRYPTO | 3 |
| 2002 | A Generalized Birthday Problem
David A. Wagner 0001 |
CRYPTO | 1 |
| 2002 | Homomorphic Signature Schemes
David Molnar, Dawn Song, David A. Wagner 0001 |
CT-RSA | 4 |
| 2002 | Multiplicative Differentials
Nikita Borisov, Monica Chew, David A. Wagner 0001 |
FSE | 4 |
| 2002 | Integral Cryptanalysis
Lars R. Knudsen, David A. Wagner 0001 |
FSE | 2 |
| 2002 | Insecurity in ATM-based passive optical networksabstractWe consider the security of an ITU standard for ATM-based passive optical networks. First, we show that the standard's encryption algorithm, called churning, has an effective 8-bit key length and thus is trivial to break with exhaustive keysearch. Second, we show that the authentication mechanisms have significant weaknesses. The conclusion is that these measures should not be relied upon to provide security. David A. Wagner 0001 |
ICC | 2 |
| 2002 | Securing Wireless and Mobile Networks - Is It Possible?
William D. Ivancic, David A. Wagner 0001, Aviel D. Rubin, E. Paul Ratazzi, James P. G. Sterbenz |
INFOCOM | 2 |
| 2002 | Cool security trendsabstractTrent Jarger will discuss ongoing work in the verification of authorization hook placement in Linux. The idea is that we can develop tools to check that all security-sensitive kernel operations can be mediated properly. Dawson Engler will discuss ongoing work in static checking for kernal and driver bugs, including security bugs, based on his meta-complier xgcc. The idea is that reguirements can be expressed in a high-level language that the xgcc can check.David Wagner will discuss using formal modeling to guide the identifcation of security bugs. The idea is that a formal model generated fromteh source code can be more easily analyzed to find bugs.Cynthia Irvine will discuss security quality-of-service. The idea is that the cost of security in terms of performance and resource usage can be compared with the security benefits in such a way that decisions about security improvements can be made. Dawson R. Engler, Cynthia E. Irvine, Trent Jaeger, David A. Wagner 0001 |
SACMAT | 4 |
| 2002 | Setuid Demystified
Hao Chen 0003, David A. Wagner 0001, Drew Dean |
USENIX Security Symposium | 2 |
| 2001 | Relating Cryptography and Cryptographic Protocols
Andre Scedrov, Ran Canetti, Joshua D. Guttman, David A. Wagner 0001, Michael Waidner |
CSFW | 4 |
| 2001 | Intercepting mobile communications: the insecurity of 802.11abstractThe 802.11 standard for wireless networks includes a Wired Equivalent Privacy (WEP) protocol, used to protect link-layer communications from eavesdropping and other attacks. We have discovered several serious security flaws in the protocol, stemming from mis-application of cryptographic primitives. The flaws lead to a number of practical attacks that demonstrate that WEP fails to achieve its security goals. In this paper, we discuss in detail each of the flaws, the underlying security principle violations, and the ensuing attacks. Nikita Borisov, Ian Goldberg 0001, David A. Wagner 0001 |
MobiCom | 3 |
| 2001 | Static Analysis and Software Assurance
David A. Wagner 0001 |
SAS | 1 |
| 2001 | Intrusion Detection via Static AnalysisabstractOne of the primary challenges in intrusion detection is modelling typical application behavior so that we can recognize attacks by their atypical effects without raising too many false alarms. We show how static analysis may be used to automatically derive a model of application behavior. The result is a host-based intrusion detection system with three advantages: a high degree of automation, protection against a broad class of attacks based on corrupted code, and the elimination of false alarms. We report on our experience with a prototype implementation of this technique. David A. Wagner 0001, Drew Dean |
S&P | 1 |
| 2001 | Detecting Format String Vulnerabilities with Type Qualifiers
Umesh Shankar, Kunal Talwar, Jeffrey S. Foster, David A. Wagner 0001 |
USENIX Security Symposium | 4 |
| 2001 | Timing Analysis of Keystrokes and Timing Attacks on SSH
Dawn Song, David A. Wagner 0001, Xuqing Tian |
USENIX Security Symposium | 2 |
| 2001 | On the structure of Skipjack
Lars R. Knudsen, David A. Wagner 0001 |
Discret. Appl. Math. | 2 |
| 2000 | Security Weaknesses in a Randomized Stream Cipher
Niels Ferguson, Bruce Schneier, David A. Wagner 0001 |
ACISP | 3 |
| 2000 | Cryptanalysis of the Yi-Lam Hash
David A. Wagner 0001 |
ASIACRYPT | 1 |
| 2000 | Proofs of Security for the Unix Password Hashing Algorithm
David A. Wagner 0001, Ian Goldberg 0001 |
ASIACRYPT | 1 |
| 2000 | Advanced Slide Attacks
Alex Biryukov, David A. Wagner 0001 |
EUROCRYPT | 2 |
| 2000 | Real Time Cryptanalysis of A5/1 on a PC
Alex Biryukov, Adi Shamir, David A. Wagner 0001 |
FSE | 3 |
| 2000 | Improved Cryptanalysis of Rijndael
Niels Ferguson, John Kelsey, Stefan Lucks, Bruce Schneier, Mike Stay, David A. Wagner 0001, Doug Whiting |
FSE | 6 |
| 2000 | A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities
David A. Wagner 0001, Jeffrey S. Foster, Eric A. Brewer, Alex Aiken |
NDSS | 1 |
| 2000 | Practical Techniques for Searches on Encrypted DataabstractIt is desirable to store data on data storage servers such as mail servers and file servers in encrypted form to reduce security and privacy risks. But this usually implies that one has to sacrifice functionality for security. For example, if a client wishes to retrieve only documents containing certain words, it was not previously known how to let the data storage server perform the search and answer the query, without loss of data confidentiality. We describe our cryptographic schemes for the problem of searching on encrypted data and provide proofs of security for the resulting crypto systems. Our techniques have a number of crucial advantages. They are provably secure: they provide provable secrecy for encryption, in the sense that the untrusted server cannot learn anything about the plaintext when only given the ciphertext; they provide query isolation for searches, meaning that the untrusted server cannot learn anything more about the plaintext than the search result; they provide controlled searching, so that the untrusted server cannot search for an arbitrary word without the user's authorization; they also support hidden queries, so that the user may ask the untrusted server to search for a secret word without revealing the word to the server. The algorithms presented are simple, fast (for a document of length n, the encryption and search algorithms only need O(n) stream cipher and block cipher operations), and introduce almost no space and communication overhead, and hence are practical to use today. Dawn Song, David A. Wagner 0001, Adrian Perrig |
S&P | 2 |
| 2000 | Side Channel Cryptanalysis of Product CiphersabstractBuilding on the work of Kocher (1996), Jaffe and Yun (1998), we discuss the notion of side-channel cryptanalysis: cryptanalysis using implementation data. We discuss the notion of side-channel attacks and the vulnerabilities they introduce, demonstra John Kelsey, Bruce Schneier, David A. Wagner 0001, Chris Hall |
J. Comput. Secur. | 3 |
| 1999 | Truncated Differentials and Skipjack
Lars R. Knudsen, Matthew J. B. Robshaw, David A. Wagner 0001 |
CRYPTO | 3 |
| 1999 | Slide Attacks
Alex Biryukov, David A. Wagner 0001 |
FSE | 2 |
| 1999 | Mod n Cryptanalysis, with Applications Against RC5P and M6
John Kelsey, Bruce Schneier, David A. Wagner 0001 |
FSE | 3 |
| 1999 | The Boomerang Attack
David A. Wagner 0001 |
FSE | 1 |
| 1998 | Building PRFs from PRPs
Chris Hall, David A. Wagner 0001, John Kelsey, Bruce Schneier |
CRYPTO | 2 |
| 1998 | Side Channel Cryptanalysis of Product Ciphers
John Kelsey, Bruce Schneier, David A. Wagner 0001, Chris Hall |
ESORICS | 3 |
| 1998 | Cryptanalysis of TWOPRIME
Don Coppersmith, David A. Wagner 0001, Bruce Schneier, John Kelsey |
FSE | 2 |
| 1998 | Cryptanalytic Attacks on Pseudorandom Number Generators
John Kelsey, Bruce Schneier, David A. Wagner 0001, Chris Hall |
FSE | 3 |
| 1998 | Cryptanalysis of Some Recently-Proposed Multiple Modes of Operation
David A. Wagner 0001 |
FSE | 1 |
| 1998 | Differential Cryptanalysis of KHF
David A. Wagner 0001 |
FSE | 1 |
| 1998 | Cryptanalysis of SPEED
Chris Hall, John Kelsey, Vincent Rijmen, Bruce Schneier, David A. Wagner 0001 |
Selected Areas in Cryptography | 5 |
| 1998 | On the Twofish Key Schedule
Bruce Schneier, John Kelsey, Doug Whiting, David A. Wagner 0001, Chris Hall |
Selected Areas in Cryptography | 4 |
| 1998 | Cryptanalysis of ORYX
David A. Wagner 0001, Leonie Ruth Simpson, Ed Dawson, John Kelsey, William Millan, Bruce Schneier |
Selected Areas in Cryptography | 1 |
| 1997 | Cryptanalysis of the Cellular Encryption Algorithm
David A. Wagner 0001, Bruce Schneier, John Kelsey |
CRYPTO | 1 |
| 1997 | Related-key cryptanalysis of 3-WAY, Biham-DES, CAST, DES-X, NewDES, RC2, and TEA
John Kelsey, Bruce Schneier, David A. Wagner 0001 |
ICICS | 3 |
| 1996 | Key-Schedule Cryptanalysis of IDEA, G-DES, GOST, SAFER, and Triple-DES
John Kelsey, Bruce Schneier, David A. Wagner 0001 |
CRYPTO | 3 |
| 1996 | A "bump in the stack" encryptor for MS-DOS systemsabstractMost implementations of IP security are deeply entwined in the source of the protocol stack. However, such source code is not readily available for MS-DOS systems. We implemented a version using the packet driver interface. Our module sits between the generic Ethernet driver and the hardware driver; it emulates each to the other. Most of the code is straightforward; in a few places, though, we were forced to compensate for inadequate interface definitions. David A. Wagner 0001, Steven M. Bellovin |
NDSS | 1 |
| 1996 | A Secure Environment for Untrusted Helper Applications
Ian Goldberg 0001, David A. Wagner 0001, Randi Thomas, Eric A. Brewer |
USENIX Security Symposium | 2 |