EDBT 2026 Demo / reviewers in the wild / expert
Phillip A. Porras
dblp:48/3729 · also Phil Porras
· DBLP profile ↗
63ranked-venue papers
6as first author
9since 2021 · last 2024
0000-0003-4661-2443ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 40 · 6 first-author · 5 since 2021Computer networks · 15 · 4 since 2021Software engineering, systems software and programming languages · 4Systems, architecture and hardware · 3Databases, data management, data science and information retrieval · 2Artificial intelligence and machine learning · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | 6G-XSec: Explainable Edge Security for Emerging OpenRAN ArchitecturesabstractThe evolution from 5G to 6G cellular networks signifies a crucial advancement towards enhanced robustness and automation driven by the promise of ubiquitous Artificial Intelligence (AI) to overhaul network operations, commonly referred to as AIOps. However, 6G network operators also need to deal with evolving threats at the edge to ensure data integrity and availability. We introduce 6G-XSEC, the first framework that seeks to automatically monitor, analyze, and explain anomalies and threats at the cellular network edge. Our framework enhances the emerging Open Radio Access Network (O-RAN) control plane with run-time analytic capabilities and explainability. A distinguishing aspect of our framework is the use of expert referencing, a coupling of lightweight unsupervised deep learning-based anomaly detection with large language models (LLMs) to first detect, analyze, and subsequently explain complicated real-world cellular threats and anomalies at run-time, based on enhanced security telemetry from the O-RAN data plane. We build a prototype 6G-XSEC framework and evaluate it against 5 end-to-end cellular attacks from the literature, achieving 100% detection rate with our best model. We also propose effective LLM prompt templates for attack analysis and present qualitative results from 5 popular LLMs. Haohuang Wen, Prakhar Sharma, Vinod Yegneswaran, Phillip A. Porras, Ashish Gehani, Zhiqiang Lin 0001 |
HotNets | 4 |
| 2024 | 5G-Spector: An O-RAN Compliant Layer-3 Cellular Attack Detection Service
Haohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani, Zhiqiang Lin 0001 |
NDSS | 2 |
| 2024 | Enhancing security in SDN: Systematizing attacks and defenses from a penetration perspective
Jinwoo Kim 0006, Minjae Seo, Seungsoo Lee 0001, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu, Seungwon Shin 0001 |
Comput. Networks | 6 |
| 2023 | Thwarting Smartphone SMS Attacks at the Radio Interface Layer
Haohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Zhiqiang Lin 0001 |
NDSS | 2 |
| 2023 | Extended data plane architecture for in-network security services in software-defined networks
Jinwoo Kim 0006, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001, Taejune Park |
Comput. Secur. | 4 |
| 2023 | Secure Inter-Container Communications Using XDP/eBPFabstractWhile the use of containerization technologies for virtual application deployment has grown at an astonishing rate, the question of the robustness of container networking has not been well scrutinized from a security perspective, even though inter-container networking is indispensable for microservices. Thus, this paper first analyzes container networks from a security perspective, discussing the implications based on their architectural limitations. Then, it presents Bastion+, a secure inter-container communication bridge. Bastion+ introduces ($i$) a network security enforcement stack that provides fine-grained control per container application and securely isolates inter- container traffic in a point-to-point manner. Bastion+ also supports ($ii$) selective security function chaining, enabling various security functions to be chained between containers for further security inspections (e.g., deep packet inspection) according to the container’s network context. Bastion+ incorporates ($iii$) a security policy assistant that helps an administrator discover inter-container networking dependencies correctly. Our evaluation demonstrates how Bastion+ can effectively mitigate several adversarial attacks in container networks while improving the overall performance up to 25.4% within single-host containers and 17.7% for cross-host container communications. Jaehyun Nam, Seungsoo Lee 0001, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | A Framework for Policy Inconsistency Detection in Software-Defined NetworksabstractSoftware-Defined Networking (SDN) has aggressively grown in data center networks, telecommunication providers, and enterprises by virtue of its programmable and extensible control plane. Also, there have been many kinds of research on the security of SDN components along with the growth of SDN. Some of them have inspected network policy inconsistency problems that can severely cause network reliability and security issues in SDN. However, they do not consider whether a single network policy itself is corrupted during processing inside and between SDN components. In this paper, we thus focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among those components. We then present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise inOpenFlownetworks, the most prevalent SDN protocol. To prove its feasibility, we applied AudiSDN to two widely used SDN controllers, Floodlight and ONOS, and uncovered three separate CVEs (Common Vulnerabilities and Exposures) that cause the network policy inconsistencies among SDN components. Furthermore, we investigate the design flaws that cause the inconsistencies in modern SDN components, suggesting specific validations to address such a serious but understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2021 | GapFinder: Finding Inconsistency of Security Information From Unstructured TextabstractTextual data mining of open source intelligence on the Web has become an increasingly important topic across a wide range of domains such as business, law enforcement, military, and cybersecurity. Text mining efforts utilize natural language processing to transform unstructured web content into structured forms that can drive various machine learning applications and data indexing services. For example, applications for text mining in cybersecurity have produced a range of threat intelligence services that serve the IT industry. However, a less studied problem is that of automating the identification of semantic inconsistencies among various text input sources. In this paper, we introduce GapFinder, a new inconsistency checking system for identifying semantic inconsistencies within the cybersecurity domain. Specifically, we examine the problem of identifying technical inconsistencies that arise in the functional descriptions of open source malware threat reporting information. Our evaluation, using tens of thousands of relations derived from web-based malware threat reports, demonstrates the ability of GapFinder to identify the presence of inconsistencies. Hyeonseong Jo, Jinwoo Kim 0006, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | BottleNet: Hiding Network Bottlenecks Using SDN-Based Topology DeceptionabstractThe robustness of a network’s connectivity to other networks is often highly dependent on a few critical nodes and links that tie the network to the larger topology. The failure or degradation to such network bottlenecks can result in outages that may propagate throughout the network. Unfortunately, the presence of the bottlenecks also offers opportunities for targetedlink flooding attacks (LFAs). Researchers have proposed a new and promising defense to counter LFAs, referred to astopology deception. This strategy centers on hindering the discovery of bottlenecks by presenting false trace responses to adversaries as they perform topological probing of the target network. Even though the goal of topology deception centers on obscuring critical links, node dependencies can be exploited by an adversary. However, current approaches do not consider a wide range of metrics that may reveal important and diverse aspects of network bottlenecks. Furthermore, existing approaches create a simple form of virtual topology, which is subject to relatively easy detection by the adversary, reducing its effectiveness. In this paper, we propose a comprehensive topology deception framework, which we refer to as BottleNet. Our suggested approach can analyze various network topology features both with respect to static and dynamic metrics and then use this information to identify bottlenecks, finally producing complex virtual topologies that are resilient to adversarial detection. Jinwoo Kim 0006, Jaehyun Nam, Suyeol Lee, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksabstractAt the foundation of every network security architecture lies the premise that formulated network flow policies are reliably deployed and enforced by the network infrastructure. However, software-defined networks (SDNs) add a particular challenge to satisfying this premise, as for SDNs the flow pol-icy implementation spans multiple applications and abstraction layers across the SDN stack. In this paper, we focus on the question of how to automatically identify cases in which the SDN stack fails to prevent policy inconsistencies from arising among these components. This question is rather essential, as when such inconsistencies arise the implications to the security and reliability of the network are devastating. We present AudiSDN, an automated fuzz-testing framework designed to formulate test cases in which policy inconsistencies can arise in OpenFlow networks, the most prevalent SDN protocol used today. We also present results from applying AudiSDN to two widely used SDN controllers, Floodlight and ONOS. In fact, our test results have led to the filing of 3 separate CVE reports. We believe that the approach presented in this paper is applicable to the breadth of OpenFlow platforms used today, and that its broader usage will help to address a serious but yet understudied pragmatic concern. Seungsoo Lee 0001, Seungwon Woo, Jinwoo Kim 0006, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
INFOCOM | 5 |
| 2020 | BASTION: A Security Enforcement Network Stack for Container Networks
Jaehyun Nam, Seungsoo Lee 0001, Hyunmin Seo, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
USENIX ATC | 4 |
| 2020 | A comprehensive security assessment framework for software-defined networks
Seungsoo Lee 0001, Jinwoo Kim 0006, Seungwon Woo, Changhoon Yoon, Sandra Scott-Hayward, Vinod Yegneswaran, Phillip A. Porras, Seungwon Shin 0001 |
Comput. Secur. | 7 |
| 2020 | Automated Permission Model Generation for Securing SDN Control-PlaneabstractAn important consideration in software-defined networks (SDNs), is that one SDN application, through a bug or API misuse, can break an entire SDN. While previous works have tried to mitigate such concerns by implementing access control mechanisms (permission models) for an SDN controller, they commonly require serious manual efforts in creating a permission model. Moreover, they do not support flexible permission models, and they are often tightly coupled with a specific SDN controller. To address such limitations, we introduce an automated permission generation and verification system called VOGUE. A distinguishing aspect of VOGUE is that it automatically generates flexible permission models and yet is completely separated from the SDN controller implementation. To demonstrate the feasibility of our approach, we implement a prototype, evaluate its completeness and soundness, and examine its performance. In addition, to show the effectiveness of VOGUE, we demonstrate its use cases and security impact to SDN in the context of popular SDN controllers. Heedo Kang, Vinod Yegneswaran, Shalini Ghosh, Phillip A. Porras, Seungwon Shin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Coordinated dataflow protection for ultra-high bandwidth science networksabstractThe Science DMZ (SDMZ) is a special purpose network architecture proposed by ESnet (Energy Sciences Network) to facilitate distributed science experimentation on terabyte- (or petabyte-) scale data, exchanged over ultra-high bandwidth WAN links. Critical security challenges faced by these networks include: (i) network monitoring at high bandwidths, (ii) reconciling site-specific policies with project-level policies for conflict-free policy enforcement, (iii) dealing with geographically-distributed datasets with varying levels of sensitivity, and (iv) dynamically enforcing appropriate security rules. To address these challenges, we develop a fine-grained dataflow-based security enforcement system, called CoordiNetZ (CNZ), that provides coordinated situational awareness, i.e., the use of context-aware tagging for policy enforcement using the dynamic contextual information derived from hosts and network elements. We also developed tag and IP-based security microservices that incur minimal overheads in enforcing security to data flows exchanged across geographically-distributed SDMZ sites. We evaluate our prototype implementation across two geographically distributed SDMZ sites with SDN-based case studies, and present performance measurements that respectively highlight the utility of our framework and demonstrate efficient implementation of security policies across distributed SDMZ networks. Vasudevan Nagendra, Vinod Yegneswaran, Phillip A. Porras, Samir Ranjan Das |
ACSAC | 3 |
| 2019 | DPX: Data-Plane eXtensions for SDN Security Service Instantiation
Taejune Park, Yeonkeun Kim, Vinod Yegneswaran, Phillip A. Porras, Zhaoyan Xu, KyoungSoo Park, Seungwon Shin 0001 |
DIMVA | 4 |
| 2019 | Operator-Defined Reconfigurable Network OS for Software-Defined NetworksabstractBarista is a novel architecture that seeks to enable flexible and customizable instantiations of network operating systems (NOSs) for software-defined networks (SDNs). As the NOS is the strategic control center of an SDN, implementing logic for management of network switches as well as higher-level applications, its design is critical to the welfare of the network. In this paper, we focus on three aspects of composable controller design: component synthesis, dynamic event control, and predictive NOS assessment. First, the modular design of the Barista enables flexible composition of functionalities prevalent in contemporary SDN controllers. Second, its event handling mechanism enables dynamic customization of control flows in a NOS. Third, its predictive NOS assessment helps to discover the optimal composition for the requirements specified by operators. These capabilities allow Barista operators to optimally select functionalities and dynamically handle events for their operating requirements while maximizing the resource utilization of the given system. Our results demonstrate that Barista can synthesize NOSs with many functionalities found in commodity controllers with competitive performance profiles. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | Barista: An Event-centric NOS Composition Framework for Software-Defined NetworksabstractAs the network operating system (NOS) is the strategic control center of a software-defined network (SDN), its design is critical to the welfare of the network. Contemporary research has largely focused on specialized NOSs that seek to optimize controller design across one or a few dimensions (e.g., scalability, performance, or security) due to fundamental differences in architectural trade-offs needed to support competing demands. We thus designed Barista, as a new framework that enables flexible and customizable instantiations of network operating systems (NOSs) supporting diverse design choices. The Barista framework incorporates two mechanisms to harmonize architectural differences across design choices: component synthesis and dynamic event control. First, the modular design of the Barista framework enables flexible composition of functionalities prevalent in contemporary SDN controllers. Second, its event-handling mechanism enables dynamic adjustment of control flows in a NOS. These capabilities allow operators to easily enable functionalities and dynamically handle associated events, thereby satisfying network operating requirements. Our results demonstrate that Barista can synthesize NOSs with many functionalities found in commodity NOSs with competitive performance profiles. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
INFOCOM | 4 |
| 2017 | A Security-Mode for Carrier-Grade SDN ControllersabstractManagement approaches to modern networks are increasingly influenced by software-defined networks (SDNs), and this increased influence is reflected in the growth of commercially available innovative SDN-based switches, controllers and applications. To date, there have been a number of commercial and open-source SDN operating systems (NOS) introduced for various purposes, including distributed controller frameworks targeting large, carrier-grade networks such as the Open Network Operating System (ONOS) and OpenDayLight (ODL). These frameworks are distinguished by their (i) elastic cluster controller architecture, (ii) network virtualization support, and (iii) modular design. Given their flexible design, growing list of supported features, and collaborative community support, these are attractive hosting platforms for a wide range of third-party distributed network management applications. This paper identifies the common security requirements for policy enforcement in such distributed controller environments. We present the design of a network application permission-enforcement model and an integrated security subsystem (SM-ONOS) for managing distributed applications running on an ONOS controller. We discuss the underlying motivations of its security extensions and their implications for improving our understanding of how to securely manage large-scale SDNs. Our performance assessments demonstrate that the security-mode extension imposed reasonable overheads (ranging from 5 to 20% for 1-7 node clusters). Changhoon Yoon, Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran, Heedo Kang, Martin W. Fong, Brian O'Connor, Thomas Vachuska |
ACSAC | 3 |
| 2017 | Bridging the architectural gap between NOS design principles in software-defined networksabstractWe design Barista, as a new framework that seeks to enable flexible and customizable instantiations of network operating systems (NOSs) supporting diverse design choices, using two key features that harmonize architectural differences across design choices: component synthesis and dynamic event control. With these capabilities, Barista operators to easily enable functionalities and dynamically adjust the control flows among those functionalities. Jaehyun Nam, Hyeonseong Jo, Yeonkeun Kim, Phillip A. Porras, Vinod Yegneswaran, Seungwon Shin 0001 |
SoCC | 4 |
| 2017 | Athena: A Framework for Scalable Anomaly Detection in Software-Defined NetworksabstractNetwork-based anomaly detection is a well-mined area of research, with many projects that have produced algorithms to detect suspicious and anomalous activities at strategic points in a network. In this paper, we examine how to integrate an anomaly detection development framework into existing software-defined network (SDN) infrastructures to support sophisticated anomaly detection services across the entire network data plane, not just at network egress boundaries. We present Athena as a new SDN-based software solution that exports a well-structured development interface and provides general purpose functions for rapidly synthesizing a wide range of anomaly detection services and network monitoring functions with minimal programming effort. Athena is a fully distributed application hosting architecture, enabling a unique degree of scalability from prior SDN security monitoring and analysis projects. We discuss example use-case scenarios with Athena's development libraries, and evaluate system performance with respect to usability, scalability, and overhead in real world environments. Jinwoo Kim 0006, Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran |
DSN | 4 |
| 2017 | Securing Ultra-High-Bandwidth Science DMZ Networks with Coordinated Situational AwarenessabstractThe Science DMZ (SDMZ) is a special purpose network infrastructure that is engineered to cater to the ultra-high bandwidth needs of the scientific and high performance computing (HPC) communities. These networks are isolated from stateful security devices such as firewalls and deep packet inspection (DPI) engines to allow HPC data transfer nodes (DTNs) to efficiently transfer petabytes of data without associated bandwidth and performance bottlenecks. This paper presents our ongoing effort toward the development of more fine-grained data flow access control policies to manage SDMZ networks that service large-scale experiments with varying data sensitivity levels and privacy constraints. Vasudevan Nagendra, Vinod Yegneswaran, Phillip A. Porras |
HotNets | 3 |
| 2017 | Automated Categorization of Onion Sites for Analyzing the Darkweb EcosystemabstractOnion sites on the darkweb operate using the Tor Hidden Service (HS) protocol to shield their locations on the Internet, which (among other features) enables these sites to host malicious and illegal content while being resistant to legal action and seizure. Identifying and monitoring such illicit sites in the darkweb is of high relevance to the Computer Security and Law Enforcement communities. We have developed an automated infrastructure that crawls and indexes content from onion sites into a large-scale data repository, called LIGHTS, with over 100M pages. In this paper we describe Automated Tool for Onion Labeling (ATOL), a novel scalable analysis service developed to conduct a thematic assessment of the content of onion sites in the LIGHTS repository. ATOL has three core components -- (a) a novel keyword discovery mechanism (ATOLKeyword) which extends analyst-provided keywords for different categories by suggesting new descriptive and discriminative keywords that are relevant for the categories; (b) a classification framework (ATOLClassify) that uses the discovered keywords to map onion site content to a set of categories when sufficient labeled data is available; (c) a clustering framework (ATOLCluster) that can leverage information from multiple external heterogeneous knowledge sources, ranging from domain expertise to Bitcoin transaction data, to categorize onion content in the absence of sufficient supervised data. The paper presents empirical results of ATOL on onion datasets derived from the LIGHTS repository, and additionally benchmarks ATOL's algorithms on the publicly available 20 Newsgroups dataset to demonstrate the reproducibility of its results. On the LIGHTS dataset, ATOLClassify gives a 12% performance gain over an analyst-provided baseline, while ATOLCluster gives a 7% improvement over state-of-the-art semi-supervised clustering algorithms. We also discuss how ATOL has been deployed and externally evaluated, as part of the LIGHTS system. Shalini Ghosh, Ariyam Das, Phillip A. Porras, Vinod Yegneswaran, Ashish Gehani |
KDD | 3 |
| 2017 | DELTA: A Security Assessment Framework for Software-Defined Networks
Seungsoo Lee 0001, Changhoon Yoon, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras |
NDSS | 6 |
| 2017 | Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined NetworksabstractEmerging software defined network (SDN) stacks have introduced an entirely new attack surface that is exploitable from a wide range of launch points. Through an analysis of the various attack strategies reported in prior work, and through our own efforts to enumerate new and variant attack strategies, we have gained two insights. First, we observe that different SDN controller implementations, developed independently by different groups, seem to manifest common sets of pitfalls and design weakness that enable the extensive set of attacks compiled in this paper. Second, through a principled exploration of the underlying design and implementation weaknesses that enables these attacks, we introduce a taxonomy to offer insight into the common pitfalls that enable SDN stacks to be broken or destabilized when fielded within hostile computing environments. This paper first captures our understanding of the SDN attack surface through a comprehensive survey of existing SDN attack studies, which we extend by enumerating 12 new vectors for SDN abuse. We then organize these vulnerabilities within the well-known confidentiality, integrity, and availability model, assess the severity of these attacks by replicating them in a physical SDN testbed, and evaluate them against three popular SDN controllers. We also evaluate the impact of these attacks against published SDN defense solutions. Finally, we abstract our findings to offer the research and development communities with a deeper understanding of the common design and implementation pitfalls that are enabling the abuse of SDN networks. Changhoon Yoon, Seungsoo Lee 0001, Heedo Kang, Taejune Park, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
IEEE/ACM Trans. Netw. | 7 |
| 2016 | Reexamining DNS From a Global Recursive Resolver PerspectiveabstractThe performance and operational characteristics of the Domain Name System (DNS) protocol are of deep interest to the research and network operations community. In this paper, we present measurement results from a unique dataset containing more than 26 billion DNS query-response pairs collected from more than 600 globally distributed recursive DNS resolvers. We use this dataset to reaffirm findings in published work and notice some significant differences that could be attributed both to the evolving nature of DNS traffic and to our differing perspective. For example, we find that although characteristics of DNS traffic vary greatly across networks, the resolvers within an organization tend to exhibit similar behavior. We further find that more than 50% of DNS queries issued to root servers do not return successful answers, and that the primary cause of lookup failures at root servers is malformed queries with invalid top-level domains (TLDs). Furthermore, we propose a novel approach that detects malicious domain groups using temporal correlation in DNS queries. Our approach requires no comprehensive labeled training set, which can be difficult to build in practice. Instead, it uses a known malicious domain as anchor and identifies the set of previously unknown malicious domains that are related to the anchor domain. Experimental results illustrate the viability of this approach, i.e., we attain a true positive rate of more than 96%, and each malicious anchor domain results in a malware domain group with more than 53 previously unknown malicious domains on average. Vinod Yegneswaran, Jian Jiang 0002, Yan Chen 0004, Phillip A. Porras, Shalini Ghosh, Hai-Xin Duan |
IEEE/ACM Trans. Netw. | 5 |
| 2015 | EKHunter: A Counter-Offensive Toolkit for Exploit Kit Infiltration
Birhanu Eshete, Abeer Alhuzali, Maliheh Monshizadeh, Phillip A. Porras, V. N. Venkatakrishnan, Vinod Yegneswaran |
NDSS | 4 |
| 2015 | Securing the Software Defined Network Control Layer
Phillip A. Porras, Steven Cheung, Martin W. Fong, Keith Skinner, Vinod Yegneswaran |
NDSS | 1 |
| 2014 | Rosemary: A Robust, Secure, and High-performance Network Operating SystemabstractWithin the hierarchy of the Software Defined Network (SDN) network stack, the control layer operates as the critical middleware facilitator of interactions between the data plane and the network applications, which govern flow routing decisions. In the OpenFlow implementation of the SDN model, the control layer, commonly referred to as a network operating system (NOS), has been realized by a range of competing implementations that offer various performance and functionality advantages: Floodlight, POX, NOX, and ONIX. In this paper we focus on the question of control layer resilience, when rapidly developed prototype network applications go awry, or third-party network applications incorporate unexpected vulnerabilities, fatal instabilities, or even malicious logic. We demonstrate how simple and common failures in a network application may lead to loss of the control layer, and in effect, loss of network control. To address these concerns we present the ROSEMARY controller, which implements a network application containment and resilience strategy based around the notion of spawning applications independently within a micro-NOS. ROSEMARY distinguishes itself by its blend of process containment, resource utilization monitoring, and an application permission structure, all designed to prevent common failures of network applications from halting operation of the SDN Stack. We present our design and implementation of ROSEMARY, along with an extensive evaluation of its performance relative to several of the mostly well-known and widely used controllers. Rather than imposing significant performance costs, we find that with the integration of two optimization features, ROSEMARY offers a competitive performance advantage over the majority of other controllers. Seungwon Shin 0001, YongJoo Song, Taekyung Lee, Sangho Lee 0003, Jaewoong Chung, Phillip A. Porras, Vinod Yegneswaran, Brent ByungHoon Kang |
CCS | 6 |
| 2014 | DroidMiner: Automated Mining and Characterization of Fine-grained Malicious Behaviors in Android Applications
Chao Yang 0022, Zhaoyan Xu, Guofei Gu, Vinod Yegneswaran, Phillip A. Porras |
ESORICS (1) | 5 |
| 2013 | AVANT-GUARD: scalable and vigilant switch flow management in software-defined networksabstractAmong the leading reference implementations of the Software Defined Networking (SDN) paradigm is the OpenFlow framework, which decouples the control plane into a centralized application. In this paper, we consider two aspects of OpenFlow that pose security challenges, and we propose two solutions that could address these concerns. The first challenge is the inherent communication bottleneck that arises between the data plane and the control plane, which an adversary could exploit by mounting a "control plane saturation attack" that disrupts network operations. Indeed, even well-mined adversarial models, such as scanning or denial-of-service (DoS) activity, can produce more potent impacts on OpenFlow networks than traditional networks. To address this challenge, we introduce an extension to the OpenFlow data plane called "connection migration", which dramatically reduces the amount of data-to-control-plane interactions that arise during such attacks. The second challenge is that of enabling the control plane to expedite both detection of, and responses to, the changing flow dynamics within the data plane. For this, we introduce "actuating triggers" over the data plane's existing statistics collection services. These triggers are inserted by control layer applications to both register for asynchronous call backs, and insert conditional flow rules that are only activated when a trigger condition is detected within the data plane's statistics module. We present Avant-Guard, an implementation of our two data plane extensions, evaluate the performance impact, and examine its use for developing more scalable and resilient SDN security services. Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
CCS | 3 |
| 2013 | Model checking invariant security properties in OpenFlowabstractThe OpenFlow (OF) switching specification represents an innovative and open standard for enabling the dynamic programming of flow control policies in production networks. Unfortunately, thus far researchers have paid little attention to the development of methods for verifying that dynamic flow policies inserted within an OpenFlow network do not violate the network's underlying security policy. We introduce Flover, a model checking system which verifies that the aggregate of flow policies instantiated within an OpenFlow network does not violate the network's security policy. We have implemented Flover using the Yices SMT solver, which we then integrated into NOX, a popular OpenFlow network controller. Flover provides NOX a formal validation of the OpenFlow network's security posture. Sooel Son, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
ICC | 4 |
| 2013 | Clear and Present Data: Opaque Traffic and its Security Implications for the Future
Andrew M. White 0002, Srinivas Krishnan, Michael D. Bailey, Fabian Monrose, Phillip A. Porras |
NDSS | 5 |
| 2013 | FRESCO: Modular Composable Security Services for Software-Defined Networks
Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Guofei Gu, Mabry Tyson |
NDSS | 2 |
| 2013 | An empirical reexamination of global DNS behaviorabstractThe performance and operational characteristics of the DNS protocol are of deep interest to the research and network operations community. In this paper, we present measurement results from a unique dataset containing more than 26 billion DNS query-response pairs collected from more than 600 globally distributed recursive DNS resolvers. We use this dataset to reaffirm findings in published work and notice some significant differences that could be attributed both to the evolving nature of DNS traffic and to our differing perspective. For example, we find that although characteristics of DNS traffic vary greatly across networks, the resolvers within an organization tend to exhibit similar behavior. We further find that more than 50% of DNS queries issued to root servers do not return successful answers, and that the primary cause of lookup failures at root servers is malformed queries with invalid TLDs. Furthermore, we propose a novel approach that detects malicious domain groups using temporal correlation in DNS queries. Our approach requires no comprehensive labeled training set, which can be difficult to build in practice. Instead, it uses a known malicious domain as anchor, and identifies the set of previously unknown malicious domains that are related to the anchor domain. Experimental results illustrate the viability of this approach, i.e. , we attain a true positive rate of more than 96%, and each malicious anchor domain results in a malware domain group with more than 53 previously unknown malicious domains on average. Vinod Yegneswaran, Yan Chen 0004, Phillip A. Porras, Shalini Ghosh, Jian Jiang 0002, Hai-Xin Duan |
SIGCOMM | 4 |
| 2012 | Efficient Runtime Policy Enforcement Using Counterexample-Guided Abstraction Refinement
Matt Fredrikson, Richard Joiner, Somesh Jha, Thomas W. Reps, Phillip A. Porras, Hassen Saïdi, Vinod Yegneswaran |
CAV | 5 |
| 2012 | Detecting money-stealing apps in alternative Android marketsabstractThe prevalence of malware in Android marketplaces is a growing and significant problem. Among the most worrisome concerns are with regarding to malicious Android applications that attempt to steal money from unsuspecting users. These malicious applications get uploaded under the guise of benign applications, typically to third-party alternative market places that lack proper security vetting procedures, and are subsequently downloaded and executed by unsuspecting victims. In this work, we propose "Money-Guard", a systematic approach to detect stealthy moneystealing applications in popular Android markets. Our technique relies on detecting two key behavioral heuristics that seem to be common across many money-stealing Android malware: hardcoded exfiltration and notification suppression. In our preliminary analysis of 47 SMS-based money stealing applications, we confirm that 41 of these applications follow the above pattern, and describe a light weight detection approach that will identify this behavioral pattern. Chao Yang 0022, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu |
CCS | 3 |
| 2012 | PathCutter: Severing the Self-Propagation Path of XSS JavaScript Worms in Social Web Networks
Yinzhi Cao, Vinod Yegneswaran, Phillip A. Porras, Yan Chen 0004 |
NDSS | 3 |
| 2012 | Evading Censorship with Browser-Based Proxies
David Fifield, Nate Hardison, Jonathan D. Ellithorpe, Emily Stark 0001, Dan Boneh, Roger Dingledine, Phillip A. Porras |
Privacy Enhancing Technologies | 7 |
| 2011 | Poster: a path-cutting approach to blocking XSS worms in social web networks
Yinzhi Cao, Vinod Yegneswaran, Phillip A. Porras, Yan Chen 0004 |
CCS | 3 |
| 2010 | BLADE: an attack-agnostic approach for preventing drive-by malware infectionsabstractWeb-based surreptitious malware infections (i.e., drive-by downloads) have become the primary method used to deliver malicious software onto computers across the Internet. To address this threat, we present a browser independent operating system kernel extension designed to eliminate driveby malware installations. The BLADE (Block All Drive-by download Exploits) system asserts that all executable files delivered through browser downloads must result from explicit user consent and transparently redirects every unconsented browser download into a nonexecutable secure zone of disk. BLADE thwarts the ability of browser-based exploits to surreptitiously download and execute malicious content by remapping to the file system only those browser downloads to which a programmatically inferred user-consent is correlated, BLADE provides its protection without explicit knowledge of any exploits and is thus resilient against code obfuscation and zero-day threats that directly contribute to the pervasiveness of today's drive-by malware. We present the design of our BLADE prototype implementation for the Microsoft Windows platform, and report results from as extensive empirical evaluation of its effectiveness on popular browsers. Our evaluation includes multiple versions of IE and Firefox, against 1,934 active malicious URLs, representing a broad spectrum of web-based exploits not plaguing the Internet. BLADE successfully blocked all drive-by malware install attempts with zero false positives and a 3% worst-case performance cost. Long Lu, Vinod Yegneswaran, Phillip A. Porras, Wenke Lee |
CCS | 3 |
| 2009 | Active Botnet Probing to Identify Obscure Command and Control ChannelsabstractWe consider the problem of identifying obscure chat-like botnet command and control (C & C) communications, which are indistinguishable from human-human communication using traditional signature-based techniques. Existing passive-behavior-based anomaly detection techniques are limited because they either require monitoring multiple bot-infected machines that belong to the same botnet or require extended monitoring times. In this paper, we explore the potential use of active botnet probing techniques in a network middle-box as a means to augment and complement existing passive botnet C & C detection strategies, especially for small botnets with obfuscated C & C content and infrequent C & C interactions. We present an algorithmic framework that uses hypothesis testing to separate botnet C & C dialogs from human-human conversations with desired accuracy and implement a prototype system called BotProbe. Experimental results on multiple real-world IRC bots demonstrate that our proposed active methods can successfully identify obscure and obfuscated botnet communications. A real-world user study on about one hundred participants also shows that the technique has a low false positive rate on human-human conversations. We discuss the limitations of BotProbe and hope this preliminary feasibility study on the use of active techniques in botnet research can inspire new thoughts and directions within the malware research community. Guofei Gu, Vinod Yegneswaran, Phillip A. Porras, Jennifer Stoll, Wenke Lee |
ACSAC | 3 |
| 2009 | ALICE@home: Distributed Framework for Detecting Malicious Sites
Ikpeme Erete, Vinod Yegneswaran, Phillip A. Porras |
RAID | 3 |
| 2009 | BLADE: Slashing the Invisible Channel of Drive-by Download Malware
Long Lu, Vinod Yegneswaran, Phillip A. Porras, Wenke Lee |
RAID | 3 |
| 2008 | Eureka: A Framework for Enabling Static Malware Analysis
Monirul Islam Sharif, Vinod Yegneswaran, Hassen Saïdi, Phillip A. Porras, Wenke Lee |
ESORICS | 4 |
| 2008 | Gaussian Process Learning for Cyber-Attack Early WarningabstractNetwork security has been a serious concern for many years. For example, firewalls often record thousands of exploit attempts on a daily basis. Network administrators could benefit from information on potential aggressive attack sources, as such information can help to proactively defend their networks. For this purpose, several large-scale information sharing systems have been established, in which information on cyberattacks targeting each participant network is shared such that a network can be forewarned of attacks observed by others. However, the total number of reported attackers is huge in these systems. Thus, a challenging problem is to identify the attackers that are most relevant to each individual network (i.e., most likely to come to that network in the near future). We present a framework to estimate the relevance of each attacker with respect to each network. In particular, we model each attacker's relevance as a function over the networks. Different attackers have different functions. The distribution of the functions is modeled using a Gaussian process (GP). The relevance function of each attacker is then inferred from the Gaussian process, that itself is learned from the collection of attack information. We test our framework on the attack reports in the DShield information sharing system. Experiments show that attackers found relevant to a network by our framework are indeed more likely to come to that network in the future. Jian Zhang 0004, Phillip A. Porras, Johannes Ullrich |
SDM | 2 |
| 2008 | Highly Predictive Blacklisting
Jian Zhang 0004, Phillip A. Porras, Johannes Ullrich |
USENIX Security Symposium | 2 |
| 2007 | Applying Formal Evaluation to Worm Defense DesignabstractWe discuss the early insertion of formal analyses in distributed malware defense evaluation, and provide an example method for applying an executable rewriting logic specification to drive both simulation and property validation of a collaborative group-based worm defense. An important aspect of the algorithm under consideration is its distributed and probabilistic nature, which makes the defense system harder to attack but unfortunately also complicates the ability of designers to fully understand its behavioral properties. We demonstrate one approach to formally analyze our case study worm defense algorithm, employing tools that facilitate both statistical simulation and property validation. Our approach is posed as complementary to the current practice of informal design specification and evaluation through network simulation. Raman Sharykin, Phillip A. Porras |
IPCCC | 2 |
| 2007 | How to Secure Bluetooth-Based Pico Networks
Dennis K. Nilsson, Phillip A. Porras, Erland Jonsson |
SAFECOMP | 2 |
| 2007 | BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation
Guofei Gu, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Wenke Lee |
USENIX Security Symposium | 2 |
| 2006 | Automatically deducing propagation sequences that circumvent a collaborative worm defenseabstractWe present an approach to the question of evaluating worm defenses against future, yet unseen, and possibly defense-aware worm behavior. Our scheme employs model checking to produce worm propagation sequences that defeat a worm defense of interest. We demonstrate this approach using an exemplar collaborative worm defense, in which LANs share alerts about encountered infections. Through model checking experiments, we then generate propagation sequences that are able to infect the whole population in the modeled network. We discuss these experimental results and also identify open problems in applying formal methods more generally in the context of worm quarantine research Linda Briesemeister, Phillip A. Porras |
IPCCC | 2 |
| 2006 | Large-scale collection and sanitization of network security data: risks and challenges
Phillip A. Porras, Vitaly Shmatikov |
NSPW | 1 |
| 2004 | Privacy-Preserving Sharing and Correlation of Security Alerts
Patrick Lincoln, Phillip A. Porras, Vitaly Shmatikov |
USENIX Security Symposium | 2 |
| 2002 | A Mission-Impact-Based Approach to INFOSEC Alarm Correlation
Phillip A. Porras, Martin W. Fong, Alfonso Valdes |
RAID | 1 |
| 2001 | eXpert-BSM: A Host-Based Intrusion Detection Solution for Sun SolarisabstracteXpert-BSM is a real time forward-reasoning expert system that analyzes Sun Solaris audit trails. Based on many years of intrusion detection research, eXpert-BSM's knowledge base detects a wide range of specific and general forms of misuse, provides detailed reports and recommendations to the system operator, and has a low false-alarm rate. Host-based intrusion detection offers the ability to detect misuse and subversion through the direct monitoring of processes inside the host, providing an important complement to network-based surveillance. Suites of eXpert-BSMs may be deployed throughout a network, and their alarms managed, correlated, and acted on by remote or local subscribing security services, thus helping to address issues of decentralized management. Inside the host, eXpert-BSM is intended to operate as a true security daemon for host systems, consuming few CPU cycles and very little memory and secondary storage. eXpert-BSM has been available for download on the Internet since April 2000, and has been successfully deployed in several production environments. Ulf Lindqvist, Phillip A. Porras |
ACSAC | 2 |
| 1999 | An Adaptable Network COntrol and Reporting System (ANCORS)abstractWe present ANCORS, an Adaptable Network Control and Reporting System that merges technology from network management and distributed simulation to provide a unified paradigm for assessing, controlling, and designing active networks. ANCORS introduces a framework to assist in managing the substantial complexities of software reuse and scalability in active network environments. Specifically, ANCORS provides an extensible approach to the dynamic integration, management, and runtime assessment of various network protocols in live network operations. We present some of the advantages that can be obtained by merging technology from network management, distributed simulation, and active networking, and describe how ANCORS leverages complementary elements of each. We also introduce an ANCORS facility called the active network daemon Anetd, which supports the deployment and system management of a large class of legacy software and newer active network applications under the ANCORS framework. Lastly, we present a prototype network engineering service that was developed to demonstrate ANCORS's capabilities. Livio Ricciulli, Phillip A. Porras |
Integrated Network Management | 2 |
| 1999 | Detecting Computer and Network Misuse through the Production-based Expert System Toolset (P-BEST)abstractThe paper describes an expert system development toolset called the Production-Based Expert System Toolset (P-BEST) and how it is employed in the development of a modern generic signature analysis engine for computer and network misuse detection. For more than a decade, earlier versions of P-BEST have been used in intrusion detection research and in the development of some of the most well known intrusion detection systems, but this is the first time the principles and language of P-BEST are described to a wide audience. We present rule sets for detecting subversion methods against which there are few defenses-specifically, SYN flooding and buffer overruns-and provide performance measurements. Together, these examples and performance measurements indicate that P-BEST based expert systems are well suited for real time misuse detection in contemporary computing environments. In addition, the simplicity of the P-BEST language and its close integration with the C programming language makes it easy to use while still being very powerful and flexible. Ulf Lindqvist, Phillip A. Porras |
S&P | 2 |
| 1998 | Live Traffic Analysis of TCP/IP Gateways
Phillip A. Porras, Alfonso Valdes |
NDSS | 1 |
| 1996 | An Analysis of the Intel 80x86 Security Architecture and ImplementationsabstractAn in depth analysis of the 80/spl times/86 processor families identifies architectural properties that may have unexpected, and undesirable, results in secure computer systems. In addition, reported implementation errors in some processor versions render them undesirable for secure systems because of potential security and reliability problems. We discuss the imbalance in scrutiny for hardware protection mechanisms relative to software, and why this imbalance is increasingly difficult to justify as hardware complexity increases. We illustrate this difficulty with examples of architectural subtleties and reported implementation errors. Olin Sibert, Phillip A. Porras, Robert Lindell |
IEEE Trans. Software Eng. | 2 |
| 1995 | The Intel 80×86 processor architecture: pitfalls for secure systemsabstractAn in-depth analysis of the 80/spl times/86 processor families identifies architectural properties that may have unexpected, and undesirable, results in secure computer systems. In addition, reported implementation errors in some processor versions render them undesirable for secure systems because of potential security and reliability problems. We discuss the imbalance in scrutiny for hardware protection mechanisms relative to software, and why this imbalance is increasingly difficult to justify as hardware complexity increases. We illustrate this difficulty with examples of architectural subtleties and reported implementation errors.> Olin Sibert, Phillip A. Porras, Robert Lindell |
S&P | 2 |
| 1995 | State Transition Analysis: A Rule-Based Intrusion Detection ApproachabstractThe paper presents a new approach to representing and detecting computer penetrations in real time. The approach, called state transition analysis, models penetrations as a series of state changes that lead from an initial secure state to a target compromised state. State transition diagrams, the graphical representation of penetrations, identify precisely the requirements for and the compromise of a penetration and present only the critical events that must occur for the successful completion of the penetration. State transition diagrams are written to correspond to the states of an actual computer system, and these diagrams form the basis of a rule based expert system for detecting penetrations, called the state transition analysis tool (STAT). The design and implementation of a Unix specific prototype of this expert system, called USTAT, is also presented. This prototype provides a further illustration of the overall design and functionality of this intrusion detection approach. Lastly, STAT is compared to the functionality of comparable intrusion detection tools.> Koral Ilgun, Richard A. Kemmerer, Phillip A. Porras |
IEEE Trans. Software Eng. | 3 |
| 1992 | Penetration state transition analysis: A rule-based intrusion detection approachabstractA new approach to representing computer penetrations is introduced called penetration state transition analysis. This approach models penetrations as a series of state transitions described in terms of signature actions and state descriptions. State transition diagrams are written to correspond to the states of an actual computer system, and these diagrams form the basis of a rule-based expert system for detecting penetrations, referred to as STAT.> Phillip A. Porras, Richard A. Kemmerer |
ACSAC | 1 |
| 1991 | Covert Flow Trees: A Technique for Identifying and Analyzing Covert Storage ChannelsabstractA technique for detecting covert storage channels using a tree structure called a covert flow tree (CFT) is introduced. By traversing the paths of a CFT a comprehensive list of scenarios that potentially support covert communication via particular resource attributes can be automatically constructed. CFTs graphically illustrate the process through which information regarding the state of one attribute is relayed to another attribute, and how in turn that information is relayed to a listening process. Algorithms for automating the construction of CFT and potential covert channel operation sequences are presented. Two example systems are analyzed and their results are compared to two other analysis techniques performed on identical systems. The CFT approach not only identified all covert storage channels found by the other techniques, but discovered a channel not detected by the other techniques.> Phillip A. Porras, Richard A. Kemmerer |
S&P | 1 |
| 1991 | Covert Flow Trees: A Visual Approach to Analyzing Covert Storage ChannelsabstractThe authors introduce a technique for detecting covert storage channels using a tree structure called a covert flow tree (CFT). CFTs are used to perform systematic searches for operation sequences that allow information to be relayed through attributes and eventually detected by a listening process. When traversed, the paths of a CFT yield a comprehensive list of operation sequences which support communication via a particular resource attribute. These operation sequences are then analyzed and either discharged as benign or determined to be covert communication channels. Algorithms for automating the construction of CFTs and potential covert channel operation sequences are presented. To illustrate this technique, two example systems are analyzed and their results compared to two currently accepted analysis techniques performed on identical systems. This comparison shows that the CFT approach not only identified all covert storage channels found by the other analysis techniques, but discovered a channel not detected by the other techniques.> Richard A. Kemmerer, Phillip A. Porras |
IEEE Trans. Software Eng. | 2 |