Jonathan Anderson

dblp:48/7188 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
3since 2021 · last 2025
0000-0002-7352-6463ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 since 2021Human-computer interaction and ubiquitous computing · 3Systems, architecture and hardware · 2 · 1 first-authorArtificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Leash: A Transparent Capability-Based Sandboxing Supervisor for Unix
Mahya Soleimani Jadidi, Jonathan Anderson
ICISSP (2)2
2025 Empirical Evaluation and Reclassification of Cryptographic Algorithms for Energy-Efficient Secure Communication in Medical IoT Devices
abstract
Internet of Medical Things (IoMT) devices demand cryptographic solutions that balance robust security with extreme resource efficiency, given strict constraints on power, memory, and processing. This study presents a detailed empirical evaluation of ten cryptographic algorithms—including symmetric ciphers and hash functions —across two representative microcontroller platforms: TM4C123GXL (ARM Cortex-M4F) and PIC32MX440F256H (MIPS32). Algorithms tested include AES-256-ECB, Tiny-AES (AES-128), XTEA, ChaCha20, Poly1305, NORX, HMAC, SHA-256, AEAD (AES-256-EAX), and Ascon-AEAD.Comprehensive measurements of energy, execution time, and memory footprint reveal substantial discrepancies between prior classifications and practical performance. Lightweight algorithms such as ChaCha20 and Ascon-AEAD consistently achieved superior energy and speed efficiency, while certain “lightweight” candidates like Poly1305 and Tiny-AES demonstrated higher resource demands. The study introduces a performance-based reclassification of cryptographic algorithms grounded in empirical results. It also evaluates end-to-end session behavior by integrating ECDH key exchange with ChaCha20-Poly1305 encryption in a real-world IoMT setup. Results confirm the viability of these algorithms in real-time telemetry pipelines and battery-sensitive wearables. The findings offer hardware-aware, use-case-driven guidelines for cryptographic algorithm selection in secure and sustainable IoMT systems aligned with emerging NIST standards.
Sidra Anwar, Jonathan Anderson
PST2
2024 UPSS: A Global, Least-Privileged Storage System with Stronger Security and Better Performance
abstract
Strong confidentiality, integrity, user control, reliability and performance are critical requirements in privacy-sensitive applications. Such applications would benefit from a data storage and sharing infrastructure that provides these properties even in decentralized topologies with untrusted storage backends, but users today are forced to choose between systemic security properties and system reliability or performance. As an alternative to this status quo we present UPSS: the user-centric private sharing system, a cryptographic storage system that can be used as a conventional filesystem or as the foundation for security-sensitive applications such as redaction with integrity and private revision control. We demonstrate that both the security and performance properties of UPSS exceed that of existing cryptographic filesystems and that its performance is comparable to mature conventional filesystems - in some cases, even superior. Whether used directly via its Rust API or as a conventional filesystem, UPSS provides strong security and practical performance on untrusted storage.
Arastoo Bozorgi, Mahya Soleimani Jadidi, Jonathan Anderson
ICISSP3
2019 CapExec: Towards Transparently-Sandboxed Services
abstract
Network services are among the riskiest programs executed by production systems. Such services execute large quantities of complex code and process data from arbitrary - and untrusted - network sources, often with high levels of system privilege. It is desirable to confine system services to a least-privileged environment so that the potential damage from a malicious attacker can be limited, but existing mechanisms for sandboxing services require invasive and system-specific code changes and are insufficient to confine broad classes of network services. Rather than sandboxing one service at a time, we propose that the best place to add sandboxing to network services is in the service manager that starts those services. As a first step towards this vision, we propose CapExec, a process supervisor that can execute a single service within a sandbox based on a service declaration file in which, required resources whose limited access to are supported by Caper services, are specified. Using the Capsicum compartmentalization framework and its Casper service framework, CapExec provides robust application sandboxing without requiring any modifications to the application itself. We believe that this is the first step towards ubiquitous sandboxing of network services without the costs of virtualization.
Mahya Soleimani Jadidi, Mariusz Zaborski, Brian J. Kidney, Jonathan Anderson
CNSM4
2015 Clean Application Compartmentalization with SOAAP
abstract
Application compartmentalization, a vulnerability mitigation technique employed in programs such as OpenSSH and the Chromium web browser, decomposes software into isolated components to limit privileges leaked or otherwise available to attackers. However, compartmentalizing applications -- and maintaining that compartmentalization -- is hindered by ad hoc methodologies and significantly increased programming effort. In practice, programmers stumble through (rather than overtly reason about) compartmentalization spaces of possible decompositions, unknowingly trading off correctness, security, complexity, and performance. We present a new conceptual framework embodied in an LLVM-based tool: the Security-Oriented Analysis of Application Programs (SOAAP) that allows programmers to reason about compartmentalization using source-code annotations (compartmentalization hypotheses). We demonstrate considerable benefit when creating new compartmentalizations for complex applications, and analyze existing compartmentalized applications to discover design faults and maintenance issues arising from application evolution.
Khilan Gudka, Robert N. M. Watson, Jonathan Anderson, David Chisnall, Brooks Davis, Ben Laurie, Ilias Marinos, Peter G. Neumann, Alex Richardson 0001
CCS3
2015 CHERI: A Hybrid Capability-System Architecture for Scalable Software Compartmentalization
abstract
CHERI extends a conventional RISC Instruction-Set Architecture, compiler, and operating system to support fine-grained, capability-based memory protection to mitigate memory-related vulnerabilities in C-language TCBs. We describe how CHERI capabilities can also underpin a hardware-software object-capability model for application compartmentalization that can mitigate broader classes of attack. Prototyped as an extension to the open-source 64-bit BERI RISC FPGA soft-core processor, Free BSD operating system, and LLVM compiler, we demonstrate multiple orders-of-magnitude improvement in scalability, simplified programmability, and resulting tangible security benefits as compared to compartmentalization based on pure Memory-Management Unit (MMU) designs. We evaluate incrementally deployable CHERI-based compartmentalization using several real-world UNIX libraries and applications.
Robert N. M. Watson, Jonathan Woodruff, Peter G. Neumann, Simon W. Moore, Jonathan Anderson, David Chisnall, Nirav Dave, Brooks Davis, Khilan Gudka, Ben Laurie, Steven J. Murdoch, Robert M. Norton, Michael Roe, Stacey D. Son, Munraj Vadera
IEEE Symposium on Security and Privacy5
2014 TESLA: temporally enhanced system logic assertions
abstract
Large, complex, rapidly evolving pieces of software such as operating systems are notoriously difficult to prove correct. Developers instead describe expected behaviour through assertions and check actual behaviour through testing. However, many dynamic safety properties cannot be validated this way as they are temporal: they depend on events in the past or future and are not easily expressed in assertions.
Jonathan Anderson, Robert N. M. Watson, David Chisnall, Khilan Gudka, Ilias Marinos, Brooks Davis
EuroSys1
2014 The CHERI capability model: Revisiting RISC in an age of risk
abstract
Motivated by contemporary security challenges, we reevaluate and refine capability-based addressing for the RISC era. We present CHERI, a hybrid capability model that extends the 64-bit MIPS ISA with byte-granularity memory protection. We demonstrate that CHERI enables language memory model enforcement and fault isolation in hardware rather than software, and that the CHERI mechanisms are easily adopted by existing programs for efficient in-program memory safety. In contrast to past capability models, CHERI complements, rather than replaces, the ubiquitous page-based protection mechanism, providing a migration path towards deconflating data-structure protection and OS memory management. Furthermore. CHERI adheres to a strict RISC philosophy: it maintains a load-store architecture and requires only single-cycle instructions, and supplies protection primitives to the compiler, language runtime, and operating system. We demonstrate a mature FPGA implementation that runs the FreeBSD operating system with a full range of software and an open-source application suite compiled with an extended LLVM to use CHERI memory protection. A limit study compares published memory safety mechanisms in terms of instruction count and memory overheads. The study illustrates that CHERI is performance-competitive even while providing assurance and greater flexibility with simpler hardware.
Jonathan Woodruff, Robert N. M. Watson, David Chisnall, Simon W. Moore, Jonathan Anderson, Brooks Davis, Ben Laurie, Peter G. Neumann, Robert M. Norton, Michael Roe
ISCA5
2013 Declarative, Temporal, and Practical Programming with Capabilities
abstract
New operating systems, such as the Capsicum capability system, allow a programmer to write an application that satisfies strong security properties by invoking security- specific system calls at a few key points in the program. However, rewriting an application to invoke such system calls correctly is an error-prone process: even the Capsicum developers have reported difficulties in rewriting programs to correctly invoke system calls. This paper describes capweave, a tool that takes as input (i) an LLVM program, and (ii) a declarative policy of the possibly-changing capabilities that a program must hold during its execution, and rewrites the program to use Capsicum system calls to enforce the policy. Our experiments demonstrate that capweave can be applied to rewrite security-critical UNIX utilities to satisfy practical security policies. capweave itself works quickly, and the runtime overhead incurred in the programs that capweave produces is generally low for practical workloads.
William R. Harris, Somesh Jha, Thomas W. Reps, Jonathan Anderson, Robert N. M. Watson
IEEE Symposium on Security and Privacy4
2010 Capsicum: Practical Capabilities for UNIX
Robert N. M. Watson, Jonathan Anderson, Ben Laurie, Kris Kennaway
USENIX Security Symposium2
2009 Prying Data out of a Social Network
abstract
Preventing adversaries from compiling significant amounts of user data is a major challenge for social network operators. We examine the difficulty of collecting profile and graph information from the popular social networking Website Facebook and report two major findings. First, we describe several novel ways in which data can be extracted by third parties. Second, we demonstrate the efficiency of these methods on crawled data. Our findings highlight how the current protection of personal data is inconsistent with user's expectations of privacy.
Joseph Bonneau, Jonathan Anderson, George Danezis
ASONAM2
2009 Privacy suites: shared privacy for social networks
abstract
No abstract available.
Joseph Bonneau, Jonathan Anderson, Luke Church
SOUPS2
2009 Privacy stories: confidence in privacy behaviors through end user programming
abstract
No abstract available.
Luke Church, Jonathan Anderson, Joseph Bonneau, Frank Stajano
SOUPS2