Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Collin Jackson

dblp:45/4319 · DBLP profile ↗
← Back
24ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 2 first-authorDatabases, data management, data science and information retrieval · 7 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 3 first-authorSoftware engineering, systems software and programming languages · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
21 papers
Web and mobile security · 48% Network security · 15% Privacy and data protection · 12%
Computer networks
4 papers
Network measurement and analytics · 47% Internet architecture and protocols · 42% Transport protocols and congestion control · 11%

Topics — the 30 heaviest of 41, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security
browser security
0.562013
Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013
App isolation: get the security of multiple browsers with just one · CCS 2011
Forcehttps: protecting high-security web sites from network attacks · WWW 2008
Web and mobile security › web attacks
cross-origin attacks
0.532014
All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API · IEEE Symposium on Security and Privacy 2014
Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013
Protecting browsers from cross-origin CSS attacks · CCS 2010
Web and mobile security
web security
0.332011
App isolation: get the security of multiple browsers with just one · CCS 2011
Protecting browsers from cross-origin CSS attacks · CCS 2010
Securing Frame Communication in Browsers · USENIX Security Symposium 2008
Network security › attack strategy
man-in-the-middle attack
0.212014
Analyzing Forged SSL Certificates in the Wild · IEEE Symposium on Security and Privacy 2014
Authentication and access control › password security › password management
password managers
0.212014
Password Managers: Attacks and Defenses · USENIX Security Symposium 2014
Privacy and data protection › web privacy
browser privacy
0.222010
An Analysis of Private Browsing Modes in Modern Browsers · USENIX Security Symposium 2010
Protecting browser state from web privacy attacks · WWW 2006
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate authority trust
0.212013
Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013
Cryptographic protocols and secure computation › key management
public key infrastructure
0.212013
Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013
Hardware security and side channels › side-channel attack
timing side channel
0.212013
Cross-origin pixel stealing: timing attacks using CSS filters · CCS 2013
Network security › attack resilience
attack mitigation
0.112012
Clickjacking: Attacks and Defenses · USENIX Security Symposium 2012
Web and mobile security › web security
clickjacking
0.112012
Clickjacking: Attacks and Defenses · USENIX Security Symposium 2012
Web and mobile security › web application security
mashup security
0.122007
Subspace: secure cross-domain communication for web mashups · WWW 2007
Protection and communication abstractions for web browsers in MashupOS · SOSP 2007
Network security › secure communication › secure communication protocol
TLS
0.112012
The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012
Web and mobile security › web PKI
TLS certificate validation
0.112012
The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012
Web and mobile security › browser security
same-origin policy
0.122007
Protecting browsers from dns rebinding attacks · CCS 2007
Protecting browser state from web privacy attacks · WWW 2006
Systems and software security › isolation
application isolation
0.112011
App isolation: get the security of multiple browsers with just one · CCS 2011
Privacy and data protection › web privacy
browsing history leakage
0.112011
I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks · IEEE Symposium on Security and Privacy 2011
Hardware security and side channels
side-channel attack
0.112011
I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks · IEEE Symposium on Security and Privacy 2011
Security and privacy of machine learning › federated learning defense
client-side defense
0.112010
Protecting browsers from cross-origin CSS attacks · CCS 2010
Network security › wireless network security › cognitive radio network security
cooperative spectrum sensing attack
0.112010
Protecting browsers from cross-origin CSS attacks · CCS 2010
Web and mobile security › web security
cross-site scripting
0.112010
Regular expressions considered harmful in client-side XSS filters · WWW 2010
Privacy and data protection › web privacy › browser privacy
private browsing mode
0.112010
An Analysis of Private Browsing Modes in Modern Browsers · USENIX Security Symposium 2010
Web and mobile security › web attacks
cross-site request forgery
0.112008
Robust defenses for cross-site request forgery · CCS 2008
Privacy and data protection › data sharing
cross-domain data sharing
0.112007
Subspace: secure cross-domain communication for web mashups · WWW 2007
Privacy and data protection › web tracking
third-party tracking
0.112006
Protecting browser state from web privacy attacks · WWW 2006
Privacy and data protection
information disclosure
0.112014
All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API · IEEE Symposium on Security and Privacy 2014
Authentication and access control
password authentication
0.112005
Stronger Password Authentication Using Browser Extensions · USENIX Security Symposium 2005
Authentication and access control › revocation
key revocation
0.012013
Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure · WWW 2013
Transport protocols and congestion control
transport protocols
0.012012
The Case for Prefetching and Prevalidating TLS Server Certificates · NDSS 2012
Network security › attack resilience › attack mitigation
man-in-the-middle attack prevention
0.012012
Practical end-to-end web content integrity · WWW 2012

Methods — techniques the papers use, named apart from their topics

measurement study · 0.4prevalidation · 0.3prefetching · 0.3caching proxy · 0.3CDN · 0.3password manager analysis · 0.2history sniffing · 0.2cross-site request forgery · 0.2checks-and-balances · 0.2accountability architecture · 0.2finite state model checking · 0.1header analysis · 0.1empirical measurement · 0.1
YearPublicationVenuePosition
2014 Analyzing Forged SSL Certificates in the Wild
abstract
The SSL man-in-the-middle attack uses forged SSL certificates to intercept encrypted connections between clients and servers. However, due to a lack of reliable indicators, it is still unclear how commonplace these attacks occur in the wild. In this work, we have designed and implemented a method to detect the occurrence of SSL man-in-the-middle attack on a top global website, Facebook. Over 3 million real-world SSL connections to this website were analyzed. Our results indicate that 0.2% of the SSL connections analyzed were tampered with forged SSL certificates, most of them related to antivirus software and corporate-scale content filters. We have also identified some SSL connections intercepted by malware. Limitations of the method and possible defenses to such attacks are also discussed.
Lin-Shung Huang, Alex Rice, Erling Ellingsen, Collin Jackson
IEEE Symposium on Security and Privacy4
2014 All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API
abstract
HTML5 changes many aspects in the browser world by introducing numerous new concepts, in particular, the new HTML5 screen sharing API impacts the security implications of browsers tremendously. One of the core assumptions on which browser security is built is that there is no cross-origin feedback loop from the client to the server. However, the screen sharing API allows creating a cross-origin feedback loop. Consequently, websites will potentially be able to see all visible content from the user's screen, irrespective of its origin. This cross-origin feedback loop, when combined with human vision limitations, can introduce new vulnerabilities. An attacker can capture sensitive information from victim's screen using the new API without the consensus of the victim. We investigate the security implications of the screen sharing API and discuss how existing defenses against traditional web attacks fail during screen sharing. We show that several attacks are possible with the help of the screen sharing API: cross-site request forgery, history sniffing, and information stealing. We discuss how popular websites such as Amazon and Wells Fargo can be attacked using this API and demonstrate the consequences of the attacks such as economic losses, compromised account and information disclosure. The objective of this paper is to present the attacks using the screen sharing API, analyze the fundamental cause and motivate potential defenses to design a more secure screen sharing API.
Yuan Tian 0001, Ying Chuan Liu, Amar Bhosale, Lin-Shung Huang, Patrick Tague, Collin Jackson
IEEE Symposium on Security and Privacy6
2014 Password Managers: Attacks and Defenses
Suman Jana, Dan Boneh, Eric Yawei Chen, Collin Jackson
USENIX Security Symposium5
2013 Cross-origin pixel stealing: timing attacks using CSS filters
abstract
Timing attacks rely on systems taking varying amounts of time to process different input values. This is usually the result of either conditional branching in code or differences in input size. Using CSS default filters, we have discovered a variety of timing attacks that work in multiple browsers and devices. The first attack exploits differences in time taken to render various DOM trees. This knowledge can be used to determine boolean values such as whether or not a user has an account with a particular website. Second, we introduce pixel stealing. Pixel stealing attacks can be used to sniff user history and read text tokens.
Robert Kotcher, Yutong Pei, Pranjal Jumde, Collin Jackson
CCS4
2013 Accountable key infrastructure (AKI): a proposal for a public-key validation infrastructure
abstract
Recent trends in public-key infrastructure research explore the tradeoff between decreased trust in Certificate Authorities (CAs), resilience against attacks, communication overhead (bandwidth and latency) for setting up an SSL/TLS connection, and availability with respect to verifiability of public key information. In this paper, we propose AKI as a new public-key validation infrastructure, to reduce the level of trust in CAs. AKI integrates an architecture for key revocation of all entities (e.g., CAs, domains) with an architecture for accountability of all infrastructure parties through checks-and-balances. AKI efficiently handles common certification operations, and gracefully handles catastrophic events such as domain key loss or compromise. We propose AKI to make progress towards a public-key validation infrastructure with key revocation that reduces trust in any single entity.
Tiffany Hyun-Jin Kim, Lin-Shung Huang, Adrian Perrig, Collin Jackson, Virgil D. Gligor
WWW4
2012 The Case for Prefetching and Prevalidating TLS Server Certificates
Emily Stark 0001, Lin-Shung Huang, Dinesh Israni, Collin Jackson, Dan Boneh
NDSS4
2012 Clickjacking: Attacks and Defenses
Lin-Shung Huang, Alexander Moshchuk, Helen J. Wang, Stuart Schecter, Collin Jackson
USENIX Security Symposium5
2012 Practical end-to-end web content integrity
abstract
Widespread growth of open wireless hotspots has made it easy to carry out man-in-the-middle attacks and impersonate web sites. Although HTTPS can be used to prevent such attacks, its universal adoption is hindered by its performance cost and its inability to leverage caching at intermediate servers (such as CDN servers and caching proxies) while maintaining end-to-end security. To complement HTTPS, we revive an old idea from SHTTP, a protocol that offers end-to-end web integrity without confidentiality. We name the protocol HTTPi and give it an efficient design that is easy to deploy for today's web. In particular, we tackle several previously-unidentified challenges, such as supporting progressive page loading on the client's browser, handling mixed content, and defining access control policies among HTTP, HTTPi, and HTTPS content from the same domain. Our prototyping and evaluation experience show that HTTPi incurs negligible performance overhead over HTTP, can leverage existing web infrastructure such as CDNs or caching proxies without any modifications to them, and can make many of the mixed-content problems in existing HTTPS web sites easily go away. Based on this experience, we advocate browser and web server vendors to adopt HTTPi.
Kapil Singh, Helen J. Wang, Alexander Moshchuk, Collin Jackson, Wenke Lee
WWW4
2011 App isolation: get the security of multiple browsers with just one
abstract
Many browser-based attacks can be prevented by using separate browsers for separate web sites. However, most users access the web with only one browser. We explain the security benefits that using multiple browsers provides in terms of two concepts: entry-point restriction and state isolation. We combine these concepts into a general app isolation mechanism that can provide the same security benefits in a single browser. While not appropriate for all types of web sites, many sites with high-value user data can opt in to app isolation to gain defenses against a wide variety of browser-based attacks. We implement app isolation in the Chromium browser and verify its security properties using finite-state model checking. We also measure the performance overhead of app isolation and conduct a large-scale study to evaluate its adoption complexity for various types of sites, demonstrating how the app isolation mechanisms are suitable for protecting a number of high-value Web applications, such as online banking.
Eric Yawei Chen, Jason Bau, Charles Reis, Adam Barth, Collin Jackson
CCS5
2011 I Still Know What You Visited Last Summer: Leaking Browsing History via User Interaction and Side Channel Attacks
abstract
History sniffing attacks allow web sites to learn about users' visits to other sites. The major browsers have recently adopted a defense against the current strategies for history sniffing. In a user study with 307 participants, we demonstrate that history sniffing remains feasible via interactive techniques which are not covered by the defense. While these techniques are slower and cannot hope to learn as much about users' browsing history, we see no practical way to defend against them.
Zachary Weinberg, Eric Yawei Chen, Pavithra Ramesh Jayaraman, Collin Jackson
IEEE Symposium on Security and Privacy4
2010 Protecting browsers from cross-origin CSS attacks
abstract
Cross-origin CSS attacks use style sheet import to steal confidential information from a victim website, hijacking a user's existing authenticated session; existing XSS defenses are ineffective. We show how to conduct these attacks with any browser, even if JavaScript is disabled, and propose a client-side defense with little or no impact on the vast majority of web sites. We have implemented and deployed defenses in Firefox, Google Chrome, and Safari. Our defense proposal has also been adopted by Opera.
Lin-Shung Huang, Zachary Weinberg, Chris Evans, Collin Jackson
CCS4
2010 An Analysis of Private Browsing Modes in Modern Browsers
Gaurav Aggarwal, Elie Bursztein, Collin Jackson, Dan Boneh
USENIX Security Symposium3
2010 Regular expressions considered harmful in client-side XSS filters
abstract
Cross-site scripting flaws have now surpassed buffer overflows as the world's most common publicly-reported security vulnerability. In recent years, browser vendors and researchers have tried to develop client-side filters to mitigate these attacks. We analyze the best existing filters and find them to be either unacceptably slow or easily circumvented. Worse, some of these filters could introduce vulnerabilities into sites that were previously bug-free. We propose a new filter design that achieves both high performance and high precision by blocking scripts after HTML parsing but before execution. Compared to previous approaches, our approach is faster, protects against more vulnerabilities, and is harder for attackers to abuse. We have contributed an implementation of our filter design to the WebKit open source rendering engine, and the filter is now enabled by default in the Google Chrome browser.
Daniel Bates, Adam Barth, Collin Jackson
WWW3
2009 Protecting browsers from DNS rebinding attacks
abstract
DNS rebinding attacks subvert the same-origin policy of browsers, converting them into open network proxies. Using DNS rebinding, an attacker can circumvent organizational and personal firewalls, send spam email, and defraud pay-per-click advertisers. We evaluate the cost effectiveness of mounting DNS rebinding attacks, finding that an attacker requires less than $100 to hijack 100,000 IP addresses. We analyze defenses to DNS rebinding attacks, including improvements to the classic “DNS pinning,” and recommend changes to browser plug-ins, firewalls, and Web servers. Our defenses have been adopted by plug-in vendors and by a number of open-source firewall implementations.
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh
ACM Trans. Web1
2008 Robust defenses for cross-site request forgery
abstract
Cross-Site Request Forgery (CSRF) is a widely exploited web site vulnerability. In this paper, we present a new variation on CSRF attacks, login CSRF, in which the attacker forges a cross-site request to the login form, logging the victim into the honest web site as the attacker. The severity of a login CSRF vulnerability varies by site, but it can be as severe as a cross-site scripting vulnerability. We detail three major CSRF defense techniques and find shortcomings with each technique. Although the HTTP Referer header could provide an effective defense, our experimental observation of 283,945 advertisement impressions indicates that the header is widely blocked at the network layer due to privacy concerns. Our observations do suggest, however, that the header can be used today as a reliable CSRF defense over HTTPS, making it particularly well-suited for defending against login CSRF. For the long term, we propose that browsers implement the Origin header, which provides the security benefits of the Referer header while responding to privacy concerns.
Adam Barth, Collin Jackson, John C. Mitchell
CCS2
2008 Securing Frame Communication in Browsers
Adam Barth, Collin Jackson, John C. Mitchell
USENIX Security Symposium2
2008 Forcehttps: protecting high-security web sites from network attacks
abstract
As wireless networks proliferate, web browsers operate in an increasingly hostile network environment. The HTTPS protocol has the potential to protect web users from network attackers, but real-world deployments must cope with misconfigured servers, causing imperfect web sites and users to compromise browsing sessions inadvertently. ForceHTTPS is a simple browser security mechanism that web sites or users can use to opt in to stricter error processing, improving the security of HTTPS by preventing network attacks that leverage the browser's lax error processing. By augmenting the browser with a database of custom URL rewrite rules, ForceHTTPS allows sophisticated users to transparently retrofit security onto some insecure sites that support HTTPS. We provide a prototype implementation of ForceHTTPS as a Firefox browser extension.
Collin Jackson, Adam Barth
WWW1
2007 Protecting browsers from dns rebinding attacks
abstract
DNS rebinding attacks subvert the same-origin policy of browsers and convert them into open network proxies. We survey new DNS rebinding attacks that exploit the interaction between browsers and their plug-ins, such as Flash and Java. These attacks can be used to circumvent firewalls and are highly cost-effective for sending spam e-mail and defrauding pay-per-click advertisers, requiring less than $100 to temporarily hijack 100,000 IP addresses. We show that the classic defense against these attacks, called "DNS pinning," is ineffective in modern browsers. The primary focus of this work, however, is the design of strong defenses against DNS rebinding attacks that protect modern browsers: we suggest easy-to-deploy patches for plug-ins that prevent large-scale exploitation, provide a defense tool, dnswall, that prevents firewall circumvention, and detail two defense options, policy-based pinning and host name authorization.
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh
CCS1
2007 MashupOS: Operating System Abstractions for Client Mashups
Jon Howell, Collin Jackson, Helen J. Wang, Xiaofeng Fan
HotOS2
2007 Protection and communication abstractions for web browsers in MashupOS
abstract
Web browsers have evolved from a single-principal platform on which one site is browsed at a time into a multi-principal platform on which data and code from mutually distrusting sites interact programmatically in a single page at the browser. Today's "Web 2.0" applications (or mashups) offer rich services, rivaling those of desktop PCs. However, the protection andcommunication abstractions offered by today's browsers remain suitable onlyfor a single-principal system--either no trust through completeisolation between principals (sites) or full trust by incorporating third party code as libraries. In this paper, we address this deficiency by identifying and designing the missing abstractions needed for a browser-based multi-principal platform. We have designed our abstractions to be backward compatible and easily adoptable. We have built a prototype system that realizes almost all of our abstractions and their associated properties. Our evaluation shows that our abstractions make it easy to build more secure and robust client-side Web mashups and can be easily implemented with negligible performance overhead.
Helen J. Wang, Xiaofeng Fan, Jon Howell, Collin Jackson
SOSP4
2007 Transaction Generators: Root Kits for Web
Collin Jackson, Dan Boneh, John C. Mitchell
HotSec1
2007 Subspace: secure cross-domain communication for web mashups
abstract
Combining data and code from third-party sources has enabled a new wave of web mashups that add creativity and functionality to web applications. However, browsers are poorly designed to pass data between domains, often forcing web developers to abandon security in the name of functionality. To address this deficiency, we developed Subspace, a cross-domain communication mechanism that allows efficient communication across domains without sacrificing security. Our prototype requires only a small JavaScript library, and works across all major browsers. We believe Subspace can serve as a new secure communication primitive for web mashups.
Collin Jackson, Helen J. Wang
WWW1
2006 Protecting browser state from web privacy attacks
abstract
Through a variety of means, including a range of browser cache methods and inspecting the color of a visited hyperlink, client-side browser state can be exploited to track users against their wishes. This tracking is possible because persistent, client-side browser state is not properly partitioned on per-site basis in current browsers. We address this problem by refining the general notion of a "same-origin" policy and implementing two browser extensions that enforce this policy on the browser cache and visited links.We also analyze various degrees of cooperation between sites to track users, and show that even if long-term browser state is properly partitioned, it is still possible for sites to use modern web features to bounce users between sites and invisibly engage in cross-domain tracking of their visitors. Cooperative privacy attacks are an unavoidable consequence of all persistent browser state that affects the behavior of the browser, and disabling or frequently expiring this state is the only way to achieve true privacy against colluding parties.
Collin Jackson, Andrew Bortz, Dan Boneh, John C. Mitchell
WWW1
2005 Stronger Password Authentication Using Browser Extensions
Blake Ross, Collin Jackson, Nick Miyake, Dan Boneh, John C. Mitchell
USENIX Security Symposium2