EDBT 2026 Demo / reviewers in the wild / expert
Collin Jackson
dblp:45/4319
· DBLP profile ↗
24ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 first-authorDatabases, data management, data science and information retrieval · 7 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 3 first-authorSoftware engineering, systems software and programming languages · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
21 papers |
Web and mobile security · 48% Network security · 15% Privacy and data protection · 12% | |
| Computer networks
4 papers |
Network measurement and analytics · 47% Internet architecture and protocols · 42% Transport protocols and congestion control · 11% |
Topics — the 30 heaviest of 41, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
browser security |
0.5 | 6 | 2013 | Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013 App isolation: get the security of multiple browsers with just one · CCS 2011 Forcehttps: protecting high-security web sites from network attacks · WWW 2008 |
Web and mobile security › web attacks
cross-origin attacks |
0.5 | 3 | 2014 | All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API · IEEE Symposium on Security and Privacy 2014 Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013 Protecting browsers from cross-origin CSS attacks · CCS 2010 |
Web and mobile security
web security |
0.3 | 3 | 2011 | App isolation: get the security of multiple browsers with just one · CCS 2011 Protecting browsers from cross-origin CSS attacks · CCS 2010 Securing Frame Communication in Browsers · USENIX Security Symposium 2008 |
Network security › attack strategy
man-in-the-middle attack |
0.2 | 1 | 2014 | Analyzing Forged SSL Certificates in the Wild · IEEE Symposium on Security and Privacy 2014 |
Authentication and access control › password security › password management
password managers |
0.2 | 1 | 2014 | Password Managers: Attacks and Defenses · USENIX Security Symposium 2014 |
Privacy and data protection › web privacy
browser privacy |
0.2 | 2 | 2010 | An Analysis of Private Browsing Modes in Modern Browsers · USENIX Security Symposium 2010 Protecting browser state from web privacy attacks · WWW 2006 |
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate authority trust |
0.2 | 1 | 2013 | Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013 |
Cryptographic protocols and secure computation › key management
public key infrastructure |
0.2 | 1 | 2013 | Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013 |
Hardware security and side channels › side-channel attack
timing side channel |
0.2 | 1 | 2013 | Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013 |
Network security › attack resilience
attack mitigation |
0.1 | 1 | 2012 | Clickjacking: Attacks and Defenses · USENIX Security Symposium 2012 |
Web and mobile security › web security
clickjacking |
0.1 | 1 | 2012 | Clickjacking: Attacks and Defenses · USENIX Security Symposium 2012 |
Web and mobile security › web application security
mashup security |
0.1 | 2 | 2007 | Subspace: secure cross-domain communication for web mashups · WWW 2007 Protection and communication abstractions for web browsers in MashupOS · SOSP 2007 |
Network security › secure communication › secure communication protocol
TLS |
0.1 | 1 | 2012 | The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012 |
Web and mobile security › web PKI
TLS certificate validation |
0.1 | 1 | 2012 | The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012 |
Web and mobile security › browser security
same-origin policy |
0.1 | 2 | 2007 | Protecting browsers from dns rebinding attacks · CCS 2007 Protecting browser state from web privacy attacks · WWW 2006 |
Systems and software security › isolation
application isolation |
0.1 | 1 | 2011 | App isolation: get the security of multiple browsers with just one · CCS 2011 |
Privacy and data protection › web privacy
browsing history leakage |
0.1 | 1 | 2011 | I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks · IEEE Symposium on Security and Privacy 2011 |
Hardware security and side channels
side-channel attack |
0.1 | 1 | 2011 | I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks · IEEE Symposium on Security and Privacy 2011 |
Security and privacy of machine learning › federated learning defense
client-side defense |
0.1 | 1 | 2010 | Protecting browsers from cross-origin CSS attacks · CCS 2010 |
Network security › wireless network security › cognitive radio network security
cooperative spectrum sensing attack |
0.1 | 1 | 2010 | Protecting browsers from cross-origin CSS attacks · CCS 2010 |
Web and mobile security › web security
cross-site scripting |
0.1 | 1 | 2010 | Regular expressions considered harmful in client-side XSS filters · WWW 2010 |
Privacy and data protection › web privacy › browser privacy
private browsing mode |
0.1 | 1 | 2010 | An Analysis of Private Browsing Modes in Modern Browsers · USENIX Security Symposium 2010 |
Web and mobile security › web attacks
cross-site request forgery |
0.1 | 1 | 2008 | Robust defenses for cross-site request forgery · CCS 2008 |
Privacy and data protection › data sharing
cross-domain data sharing |
0.1 | 1 | 2007 | Subspace: secure cross-domain communication for web mashups · WWW 2007 |
Privacy and data protection › web tracking
third-party tracking |
0.1 | 1 | 2006 | Protecting browser state from web privacy attacks · WWW 2006 |
Privacy and data protection
information disclosure |
0.1 | 1 | 2014 | All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API · IEEE Symposium on Security and Privacy 2014 |
Authentication and access control
password authentication |
0.1 | 1 | 2005 | Stronger Password Authentication Using Browser Extensions · USENIX Security Symposium 2005 |
Authentication and access control › revocation
key revocation |
0.0 | 1 | 2013 | Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013 |
Transport protocols and congestion control
transport protocols |
0.0 | 1 | 2012 | The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012 |
Network security › attack resilience › attack mitigation
man-in-the-middle attack prevention |
0.0 | 1 | 2012 | Practical end-to-end web content integrity · WWW 2012 |
Methods — techniques the papers use, named apart from their topics
measurement study · 0.4prevalidation · 0.3prefetching · 0.3caching proxy · 0.3CDN · 0.3password manager analysis · 0.2history sniffing · 0.2cross-site request forgery · 0.2checks-and-balances · 0.2accountability architecture · 0.2finite state model checking · 0.1header analysis · 0.1empirical measurement · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Analyzing Forged SSL Certificates in the WildabstractThe SSL man-in-the-middle attack uses forged SSL certificates to intercept encrypted connections between clients and servers. However, due to a lack of reliable indicators, it is still unclear how commonplace these attacks occur in the wild. In this work, we have designed and implemented a method to detect the occurrence of SSL man-in-the-middle attack on a top global website, Facebook. Over 3 million real-world SSL connections to this website were analyzed. Our results indicate that 0.2% of the SSL connections analyzed were tampered with forged SSL certificates, most of them related to antivirus software and corporate-scale content filters. We have also identified some SSL connections intercepted by malware. Limitations of the method and possible defenses to such attacks are also discussed. Lin-Shung Huang, Alex Rice, Erling Ellingsen, Collin Jackson |
IEEE Symposium on Security and Privacy | 4 |
| 2014 | All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing APIabstractHTML5 changes many aspects in the browser world by introducing numerous new concepts, in particular, the new HTML5 screen sharing API impacts the security implications of browsers tremendously. One of the core assumptions on which browser security is built is that there is no cross-origin feedback loop from the client to the server. However, the screen sharing API allows creating a cross-origin feedback loop. Consequently, websites will potentially be able to see all visible content from the user's screen, irrespective of its origin. This cross-origin feedback loop, when combined with human vision limitations, can introduce new vulnerabilities. An attacker can capture sensitive information from victim's screen using the new API without the consensus of the victim. We investigate the security implications of the screen sharing API and discuss how existing defenses against traditional web attacks fail during screen sharing. We show that several attacks are possible with the help of the screen sharing API: cross-site request forgery, history sniffing, and information stealing. We discuss how popular websites such as Amazon and Wells Fargo can be attacked using this API and demonstrate the consequences of the attacks such as economic losses, compromised account and information disclosure. The objective of this paper is to present the attacks using the screen sharing API, analyze the fundamental cause and motivate potential defenses to design a more secure screen sharing API. Yuan Tian 0001, Ying Chuan Liu, Amar Bhosale, Lin-Shung Huang, Patrick Tague, Collin Jackson |
IEEE Symposium on Security and Privacy | 6 |
| 2014 | Password Managers: Attacks and Defenses
Suman Jana, Dan Boneh, Eric Yawei Chen, Collin Jackson |
USENIX Security Symposium | 5 |
| 2013 | Cross-origin pixel stealing: timing attacks using CSS filtersabstractTiming attacks rely on systems taking varying amounts of time to process different input values. This is usually the result of either conditional branching in code or differences in input size. Using CSS default filters, we have discovered a variety of timing attacks that work in multiple browsers and devices. The first attack exploits differences in time taken to render various DOM trees. This knowledge can be used to determine boolean values such as whether or not a user has an account with a particular website. Second, we introduce pixel stealing. Pixel stealing attacks can be used to sniff user history and read text tokens. Robert Kotcher, Yutong Pei, Pranjal Jumde, Collin Jackson |
CCS | 4 |
| 2013 | Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructureabstractRecent trends in public-key infrastructure research explore the tradeoff between decreased trust in Certificate Authorities (CAs), resilience against attacks, communication overhead (bandwidth and latency) for setting up an SSL/TLS connection, and availability with respect to verifiability of public key information. In this paper, we propose AKI as a new public-key validation infrastructure, to reduce the level of trust in CAs. AKI integrates an architecture for key revocation of all entities (e.g., CAs, domains) with an architecture for accountability of all infrastructure parties through checks-and-balances. AKI efficiently handles common certification operations, and gracefully handles catastrophic events such as domain key loss or compromise. We propose AKI to make progress towards a public-key validation infrastructure with key revocation that reduces trust in any single entity. Tiffany Hyun-Jin Kim, Lin-Shung Huang, Adrian Perrig, Collin Jackson, Virgil D. Gligor |
WWW | 4 |
| 2012 | The Case for Prefetching and Prevalidating TLS Server Certificates
Emily Stark 0001, Lin-Shung Huang, Dinesh Israni, Collin Jackson, Dan Boneh |
NDSS | 4 |
| 2012 | Clickjacking: Attacks and Defenses
Lin-Shung Huang, Alexander Moshchuk, Helen J. Wang, Stuart Schecter, Collin Jackson |
USENIX Security Symposium | 5 |
| 2012 | Practical end-to-end web content integrityabstractWidespread growth of open wireless hotspots has made it easy to carry out man-in-the-middle attacks and impersonate web sites. Although HTTPS can be used to prevent such attacks, its universal adoption is hindered by its performance cost and its inability to leverage caching at intermediate servers (such as CDN servers and caching proxies) while maintaining end-to-end security. To complement HTTPS, we revive an old idea from SHTTP, a protocol that offers end-to-end web integrity without confidentiality. We name the protocol HTTPi and give it an efficient design that is easy to deploy for today's web. In particular, we tackle several previously-unidentified challenges, such as supporting progressive page loading on the client's browser, handling mixed content, and defining access control policies among HTTP, HTTPi, and HTTPS content from the same domain. Our prototyping and evaluation experience show that HTTPi incurs negligible performance overhead over HTTP, can leverage existing web infrastructure such as CDNs or caching proxies without any modifications to them, and can make many of the mixed-content problems in existing HTTPS web sites easily go away. Based on this experience, we advocate browser and web server vendors to adopt HTTPi. Kapil Singh, Helen J. Wang, Alexander Moshchuk, Collin Jackson, Wenke Lee |
WWW | 4 |
| 2011 | App isolation: get the security of multiple browsers with just oneabstractMany browser-based attacks can be prevented by using separate browsers for separate web sites. However, most users access the web with only one browser. We explain the security benefits that using multiple browsers provides in terms of two concepts: entry-point restriction and state isolation. We combine these concepts into a general app isolation mechanism that can provide the same security benefits in a single browser. While not appropriate for all types of web sites, many sites with high-value user data can opt in to app isolation to gain defenses against a wide variety of browser-based attacks. We implement app isolation in the Chromium browser and verify its security properties using finite-state model checking. We also measure the performance overhead of app isolation and conduct a large-scale study to evaluate its adoption complexity for various types of sites, demonstrating how the app isolation mechanisms are suitable for protecting a number of high-value Web applications, such as online banking. Eric Yawei Chen, Jason Bau, Charles Reis, Adam Barth, Collin Jackson |
CCS | 5 |
| 2011 | I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel AttacksabstractHistory sniffing attacks allow web sites to learn about users' visits to other sites. The major browsers have recently adopted a defense against the current strategies for history sniffing. In a user study with 307 participants, we demonstrate that history sniffing remains feasible via interactive techniques which are not covered by the defense. While these techniques are slower and cannot hope to learn as much about users' browsing history, we see no practical way to defend against them. Zachary Weinberg, Eric Yawei Chen, Pavithra Ramesh Jayaraman, Collin Jackson |
IEEE Symposium on Security and Privacy | 4 |
| 2010 | Protecting browsers from cross-origin CSS attacksabstractCross-origin CSS attacks use style sheet import to steal confidential information from a victim website, hijacking a user's existing authenticated session; existing XSS defenses are ineffective. We show how to conduct these attacks with any browser, even if JavaScript is disabled, and propose a client-side defense with little or no impact on the vast majority of web sites. We have implemented and deployed defenses in Firefox, Google Chrome, and Safari. Our defense proposal has also been adopted by Opera. Lin-Shung Huang, Zachary Weinberg, Chris Evans, Collin Jackson |
CCS | 4 |
| 2010 | An Analysis of Private Browsing Modes in Modern Browsers
Gaurav Aggarwal, Elie Bursztein, Collin Jackson, Dan Boneh |
USENIX Security Symposium | 3 |
| 2010 | Regular expressions considered harmful in client-side XSS filtersabstractCross-site scripting flaws have now surpassed buffer overflows as the world's most common publicly-reported security vulnerability. In recent years, browser vendors and researchers have tried to develop client-side filters to mitigate these attacks. We analyze the best existing filters and find them to be either unacceptably slow or easily circumvented. Worse, some of these filters could introduce vulnerabilities into sites that were previously bug-free. We propose a new filter design that achieves both high performance and high precision by blocking scripts after HTML parsing but before execution. Compared to previous approaches, our approach is faster, protects against more vulnerabilities, and is harder for attackers to abuse. We have contributed an implementation of our filter design to the WebKit open source rendering engine, and the filter is now enabled by default in the Google Chrome browser. Daniel Bates, Adam Barth, Collin Jackson |
WWW | 3 |
| 2009 | Protecting browsers from DNS rebinding attacksabstractDNS rebinding attacks subvert the same-origin policy of browsers, converting them into open network proxies. Using DNS rebinding, an attacker can circumvent organizational and personal firewalls, send spam email, and defraud pay-per-click advertisers. We evaluate the cost effectiveness of mounting DNS rebinding attacks, finding that an attacker requires less than $100 to hijack 100,000 IP addresses. We analyze defenses to DNS rebinding attacks, including improvements to the classic “DNS pinning,” and recommend changes to browser plug-ins, firewalls, and Web servers. Our defenses have been adopted by plug-in vendors and by a number of open-source firewall implementations. Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh |
ACM Trans. Web | 1 |
| 2008 | Robust defenses for cross-site request forgeryabstractCross-Site Request Forgery (CSRF) is a widely exploited web site vulnerability. In this paper, we present a new variation on CSRF attacks, login CSRF, in which the attacker forges a cross-site request to the login form, logging the victim into the honest web site as the attacker. The severity of a login CSRF vulnerability varies by site, but it can be as severe as a cross-site scripting vulnerability. We detail three major CSRF defense techniques and find shortcomings with each technique. Although the HTTP Referer header could provide an effective defense, our experimental observation of 283,945 advertisement impressions indicates that the header is widely blocked at the network layer due to privacy concerns. Our observations do suggest, however, that the header can be used today as a reliable CSRF defense over HTTPS, making it particularly well-suited for defending against login CSRF. For the long term, we propose that browsers implement the Origin header, which provides the security benefits of the Referer header while responding to privacy concerns. Adam Barth, Collin Jackson, John C. Mitchell |
CCS | 2 |
| 2008 | Securing Frame Communication in Browsers
Adam Barth, Collin Jackson, John C. Mitchell |
USENIX Security Symposium | 2 |
| 2008 | Forcehttps: protecting high-security web sites from network attacksabstractAs wireless networks proliferate, web browsers operate in an increasingly hostile network environment. The HTTPS protocol has the potential to protect web users from network attackers, but real-world deployments must cope with misconfigured servers, causing imperfect web sites and users to compromise browsing sessions inadvertently. ForceHTTPS is a simple browser security mechanism that web sites or users can use to opt in to stricter error processing, improving the security of HTTPS by preventing network attacks that leverage the browser's lax error processing. By augmenting the browser with a database of custom URL rewrite rules, ForceHTTPS allows sophisticated users to transparently retrofit security onto some insecure sites that support HTTPS. We provide a prototype implementation of ForceHTTPS as a Firefox browser extension. Collin Jackson, Adam Barth |
WWW | 1 |
| 2007 | Protecting browsers from dns rebinding attacksabstractDNS rebinding attacks subvert the same-origin policy of browsers and convert them into open network proxies. We survey new DNS rebinding attacks that exploit the interaction between browsers and their plug-ins, such as Flash and Java. These attacks can be used to circumvent firewalls and are highly cost-effective for sending spam e-mail and defrauding pay-per-click advertisers, requiring less than $100 to temporarily hijack 100,000 IP addresses. We show that the classic defense against these attacks, called "DNS pinning," is ineffective in modern browsers. The primary focus of this work, however, is the design of strong defenses against DNS rebinding attacks that protect modern browsers: we suggest easy-to-deploy patches for plug-ins that prevent large-scale exploitation, provide a defense tool, dnswall, that prevents firewall circumvention, and detail two defense options, policy-based pinning and host name authorization. Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh |
CCS | 1 |
| 2007 | MashupOS: Operating System Abstractions for Client Mashups
Jon Howell, Collin Jackson, Helen J. Wang, Xiaofeng Fan |
HotOS | 2 |
| 2007 | Protection and communication abstractions for web browsers in MashupOSabstractWeb browsers have evolved from a single-principal platform on which one site is browsed at a time into a multi-principal platform on which data and code from mutually distrusting sites interact programmatically in a single page at the browser. Today's "Web 2.0" applications (or mashups) offer rich services, rivaling those of desktop PCs. However, the protection andcommunication abstractions offered by today's browsers remain suitable onlyfor a single-principal system--either no trust through completeisolation between principals (sites) or full trust by incorporating third party code as libraries. In this paper, we address this deficiency by identifying and designing the missing abstractions needed for a browser-based multi-principal platform. We have designed our abstractions to be backward compatible and easily adoptable. We have built a prototype system that realizes almost all of our abstractions and their associated properties. Our evaluation shows that our abstractions make it easy to build more secure and robust client-side Web mashups and can be easily implemented with negligible performance overhead. Helen J. Wang, Xiaofeng Fan, Jon Howell, Collin Jackson |
SOSP | 4 |
| 2007 | Transaction Generators: Root Kits for Web
Collin Jackson, Dan Boneh, John C. Mitchell |
HotSec | 1 |
| 2007 | Subspace: secure cross-domain communication for web mashupsabstractCombining data and code from third-party sources has enabled a new wave of web mashups that add creativity and functionality to web applications. However, browsers are poorly designed to pass data between domains, often forcing web developers to abandon security in the name of functionality. To address this deficiency, we developed Subspace, a cross-domain communication mechanism that allows efficient communication across domains without sacrificing security. Our prototype requires only a small JavaScript library, and works across all major browsers. We believe Subspace can serve as a new secure communication primitive for web mashups. Collin Jackson, Helen J. Wang |
WWW | 1 |
| 2006 | Protecting browser state from web privacy attacksabstractThrough a variety of means, including a range of browser cache methods and inspecting the color of a visited hyperlink, client-side browser state can be exploited to track users against their wishes. This tracking is possible because persistent, client-side browser state is not properly partitioned on per-site basis in current browsers. We address this problem by refining the general notion of a "same-origin" policy and implementing two browser extensions that enforce this policy on the browser cache and visited links.We also analyze various degrees of cooperation between sites to track users, and show that even if long-term browser state is properly partitioned, it is still possible for sites to use modern web features to bounce users between sites and invisibly engage in cross-domain tracking of their visitors. Cooperative privacy attacks are an unavoidable consequence of all persistent browser state that affects the behavior of the browser, and disabling or frequently expiring this state is the only way to achieve true privacy against colluding parties. Collin Jackson, Andrew Bortz, Dan Boneh, John C. Mitchell |
WWW | 1 |
| 2005 | Stronger Password Authentication Using Browser Extensions
Blake Ross, Collin Jackson, Nick Miyake, Dan Boneh, John C. Mitchell |
USENIX Security Symposium | 2 |