EDBT 2026 Demo / reviewers in the wild / expert
Micah Sherr
dblp:57/3752
· DBLP profile ↗
74ranked-venue papers
10as first author
22since 2021 · last 2026
0000-0001-7413-7673ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 51 · 8 first-author · 22 since 2021Databases, data management, data science and information retrieval · 8Computer networks · 7 · 1 first-authorSystems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3Human-computer interaction and ubiquitous computing · 3Artificial intelligence and machine learning · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mirage: Private, Mobility-based Routing for Censorship Evasion
Zachary Ratliff, RuoxingYang, Avery Bai, Harel Berger, Micah Sherr, James W. Mickens |
NDSS | 5 |
| 2025 | Censorship Evasion with Unidentified Protocol Generation
Ryan Wails, Rob Jansen, Aaron Johnson 0001, Micah Sherr |
USENIX Security Symposium | 4 |
| 2025 | SCIF: Privacy-Preserving Statistics Collection with Input Validation and Full SecurityabstractSecure aggregation is the distributed task of securely computing a sum of values (or a vector of values) held by a set of parties, revealing only the output (i.e., the sum) in the computation. Existing protocols, such as Prio (NDSI’17), Prio+ (SCN’22), Elsa (S&P’23), and Whisper (S&P’24), support secure aggregation with input validation to ensure inputs belong to a specified domain. However, when malicious servers are present, these protocols primarily guarantee privacy but not input validity. Also, malicious server(s) can cause the protocol to abort. We introduce SCIF, a novel multi-server secure aggregation protocol with input validation, that remains secure even in the presence of malicious actors, provided fewer than one-third of the servers are malicious. Our protocol overcomes previous limitations by providing two key properties: (1) guaranteed output delivery, ensuring malicious parties cannot prevent the protocol from completing, and (2) guaranteed input inclusion, ensuring no malicious party can prevent an honest party’s input from being included in the computation. Together, these guarantees provide strong resilience against denial-of-service attacks. Moreover, SCIF offers these guarantees without increasing client costs over Prio and keeps server costs moderate. We present a robust end-to-end implementation of SCIF and demonstrate the ease with which it can be instrumented by integrating it in a simulated Tor network for privacy-preserving measurement. Jianan Su, Laasya Bangalore, Harel Berger, Jason Yi, Sophia Castor, Micah Sherr, Muthuramakrishnan Venkitasubramaniam |
Proc. Priv. Enhancing Technol. | 6 |
| 2024 | "Modern problems require modern solutions": Community-Developed Techniques for Online Exam Proctoring EvasionabstractCOVID-19 caused an abrupt shift towards remote learning, and along with it, an increased adoption of remote, online proctoring technology to both dissuade and identify academic dishonesty (i.e., cheating). This shift also came with significant discontent from students who took to online platforms to both express their displeasure with remote proctoring and the methods they used for evading monitoring methods, essentially discussing _hacks_ to subvert the software and cheat on exams. In this paper, we seek to understand both the methods this online community shares for evading online proctoring and why they do so. Through qualitative analysis of social media videos (n=137) and comments (n=4,297) on YouTube and TikTok, we find both non-technical (e.g., sticky-notes) and deeply technical (e.g., custom virtual machines) methods of evading proctoring. The online videos, as well as the active comment sections, provide an important window into both an (unethical) desire to cheat but also the development of a security mindset. Many see proctoring software as invasive surveillance technology, and the discussion and sharing of methods to subvert it have similar tones to that of the hacker/tinkerer communities who also seek to share their experiences of subverting technology, for fun and profit. We conclude with lessons for the security and privacy community about evading online exam proctoring, as well as a conversation about fairness and equity in proctoring design. Lucy Simko, Adryana Hutchinson, Alvin Isaac, Evan Fries, Micah Sherr, Adam J. Aviv |
CCS | 5 |
| 2024 | On Precisely Detecting Censorship Circumvention in Real-World Networks
Ryan Wails, George Arnold Sullivan, Micah Sherr, Rob Jansen |
NDSS | 3 |
| 2024 | You Can Find Me Here: A Study of the Early Adoption of Geofeeds
Rahel A. Fainchtein, Micah Sherr |
PAM (2) | 2 |
| 2024 | NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgeabstractNetShuffle is a censorship resistance system that offers "shuffle proxies," where regular proxy services (e.g., HTTPS proxies, Tor bridges) are decoupled from their addresses via continuous in-network change. This makes shuffle proxies significantly more difficult to block compared to their traditional counterparts, because the network locations are now in constant flux. NetShuffle is also designed to engage a new class of support base—edge networks—which have received scant attention from existing work. NetShuffle uses emerging programmable switches to provide the shuffle, while staying otherwise transparent to services and clients, enabling it to be applied as a drop-in network appliance to help promote Internet freedom. We have prototyped NetShuffle in testbed environments and operated it seamlessly on a slice of a live campus network for more than a month, showing that it provides network shuffles in a way that is transparent and incurs negligible overheads. Patrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Diogo Barradas, Ang Chen 0001, Micah Sherr, Benjamin E. Ujcich |
SP | 7 |
| 2024 | SpotProxy: Rediscovering the Cloud for Censorship Circumvention
Patrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas, Ang Chen 0001, Micah Sherr, Moti Yung |
USENIX Security Symposium | 6 |
| 2024 | Editors' IntroductionabstractFace images are a rich source of information that can be used to identify individuals and infer private information about them.To mitigate this privacy risk, anonymizations employ transformations on clear images to obfuscate sensitive information, all while retaining some utility.Albeit published with impressive claims, they sometimes are not evaluated with convincing methodology.Reversing anonymized images to resemble their real input -and even be identified by face recognition approaches -represents the strongest indicator for flawed anonymization.Some recent results indeed indicate that this is possible for some approaches.It is, however, not well understood, which approaches are reversible, and why.In this paper, we provide an exhaustive investigation in the phenomenon of face anonymization reversibility.Among other things, we find that 11 out of 15 tested face anonymizations are at least partially reversible and highlight how both reconstruction and inversion are the underlying processes that make reversal possible. Micah Sherr, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Editors' IntroductionabstractIn this model, articles are published throughout the year at regular intervals, and the papers for the year are then presented at an annual conference.Reviewers can request revisions of submitted articles, which may then be revised and resubmitted in the same year.PoPETs publishes four issues per year.By enabling resubmission across these issues, PoPETs provides a high-quality peer-review process that enables authors and reviewers to work together to produce and recognize significant scholarly contributions.The PoPETs double-blind peer-review process is similar to other top-tier computer-security publications.The process includes initial review by the Editors-in-Chief for rules compliance and in-scope content, written reviews by multiple independent reviewers, author rebuttal, discussion among reviewers, and consensus decisions with disagreements resolved by the Editors-in-Chief or the Vice Chairs.The output of the review process is a set of reviews, a meta-review summarizing the reviewers' opinions after discussion (for papers that are not rejected during the first round), and one of the following decisions: Accept, Accept with Minor Micah Sherr, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Editors' IntroductionabstractEditors' Introduction, Issue 3 of PETS Volume 2024 Micah Sherr, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Editors' IntroductionabstractEditors' Introduction, Issue 4 of PETS Volume 2024 Micah Sherr, Zubair Shafiq |
Proc. Priv. Enhancing Technol. | 1 |
| 2023 | Educators' Perspectives of Using (or Not Using) Online Exam Proctoring
David G. Balash, Elena Korkes, Miles Grant, Adam J. Aviv, Rahel A. Fainchtein, Micah Sherr |
USENIX Security Symposium | 6 |
| 2023 | Editors' IntroductionabstractPrivacy of machine learning models is one of the remaining challenges that hinder the broad adoption of Artificial Intelligent (AI). This paper considers this problem in the context of image datasets containing faces. Anonymization of such datasets is becoming increasingly important due to their central role in the training of autonomous cars, for example, and the vast amount of data generated by surveillance systems. While most prior work de-identifies facial images by modifying identity features in pixel space, we instead project the image onto the latent space of a Generative Adversarial Network (GAN) model, find the features that provide the biggest identity disentanglement, and then manipulate these features in latent space, pixel space, or both. The main contribution of the paper is the design of a feature-preserving anonymization framework, StyleID, which protects the individuals’ identity, while preserving as many characteristics of the original faces in the image dataset as possible. As part of the contribution, we present a novel disentanglement metric, three complementing disentanglement methods, and new insights into identity disentanglement. StyleID provides tunable privacy, has low computational complexity, and is shown to outperform current state-of-the-art solutions. Michelle L. Mazurek, Micah Sherr |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Editors' Introduction
Michelle L. Mazurek, Micah Sherr |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Editors' Introduction
Michelle L. Mazurek, Micah Sherr |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Editors' Introduction
Michelle L. Mazurek, Micah Sherr |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | User Perceptions of the Privacy and Usability of Smart DNSabstractSmart DNS (SDNS) services enable their users to avoid geographic restrictions to content (i.e., geoblocking) with minimal internet quality of service overhead. While previous research has shown that usage of SDNS has numerous associated privacy risks, the security and privacy perceptions of users of SDNS are unexplored. In this paper, we perform a survey of n = 63 SDNS users, finding that many have limited understandings both of how these systems work and their overall security/privacy properties. As a result, many users put undue trust in purveyors of SDNS services and in the security they provide. Rahel A. Fainchtein, Adam J. Aviv, Micah Sherr |
ACSAC | 3 |
| 2022 | Learning to Behave: Improving Covert Channel Security with Behavior-Based DesignsabstractCensorship-resistant communication systems generally use real-world cover protocols to establish a covert channel through which uncensored communication can occur. Unfortunately, many previously proposed systems use cover protocols inconsistently with the way humans normally use those protocols, leading to anomalous network traffic patterns that have been shown to be discoverable by real-world censors. In this paper, we argue that censorship-resistant communication systems should follow two behavior-based design properties: (i) behavioral independence: systems should isolate the operation of their covert channels from the operation of their cover protocols, and (ii) behavioral realism: systems should either opportunistically use existing genuine cover protocol instances or run new protocol instances that are modeled after genuine ones. These properties ensure that the behavior of a system’s users will not degrade its security. We demonstrate how to achieve these properties through the design and evaluation of Raven, a censorship-resistant messaging system that uses email cover protocols identically to the way humans use email. Raven uses a generative adversarial network that is trained on genuine email data to control the timing and sizes of the email messages it sends and receives, and these messages are transferred independently of user actions. Our evaluation shows that, compared to the state-of-the-art email-based Mailet system, Raven raises the false-positive rate from 3% to 50% when detecting covert channel usage with 100% recall. Ryan Wails, Andrew Stange, Eliana Troper, Aylin Caliskan, Roger Dingledine, Rob Jansen, Micah Sherr |
Proc. Priv. Enhancing Technol. | 7 |
| 2022 | Accountable Private Set Cardinality for Distributed MeasurementabstractWe introduce cryptographic protocols for securely and efficiently computing the cardinality of set union and set intersection. Our private set-cardinality protocols ( PSC ) are designed for the setting in which a large set of parties in a distributed system makes observations, and a small set of parties with more resources and higher reliability aggregates the observations. PSC allows for secure and useful statistics gathering in privacy-preserving distributed systems. For example, it allows operators of anonymity networks such as Tor to securely answer the questions: How many unique users are using the network? and How many hidden services are being accessed? We prove the correctness and security of PSC in the Universal Composability framework against an active adversary that compromises all but one of the aggregating parties. Although successful output cannot be guaranteed in this setting, PSC either succeeds or terminates with an abort, and we furthermore make the adversary accountable for causing an abort by blaming at least one malicious party. We also show that PSC prevents adaptive corruption of the data parties from revealing past observations, which prevents them from being victims of targeted compromise, and we ensure safe measurements by making outputs differentially private. We present a proof-of-concept implementation of PSC and use it to demonstrate that PSC operates with low computational overhead and reasonable bandwidth. It can count tens of thousands of unique observations from tens to hundreds of data-collecting parties while completing within hours. PSC is thus suitable for daily measurements in a distributed system. Ellis Fenske, Akshaya Mani, Aaron Johnson 0001, Micah Sherr |
ACM Trans. Priv. Secur. | 4 |
| 2021 | Residue-Free Computing
Logan Arkema, Micah Sherr |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Holes in the Geofence: Privacy Vulnerabilities in "Smart" DNS ServicesabstractSmart DNS (SDNS) services advertise access to geofenced content (typically, video streaming sites such as Netflix or Hulu) that is normally inaccessible unless the client is within a prescribed geographic region. SDNS is simple to use and involves no software installation. Instead, it requires only that users modify their DNS settings to point to an SDNS resolver. The SDNS resolver “smartly” identifies geofenced domains and, in lieu of their proper DNS resolutions, returns IP addresses of proxy servers located within the geofence. These servers then transparently proxy traffic between the users and their intended destinations, allowing for the bypass of these geographic restrictions. Rahel A. Fainchtein, Adam J. Aviv, Micah Sherr, Stephen Ribaudo, Armaan Khullar |
Proc. Priv. Enhancing Technol. | 3 |
| 2020 | Bypassing Tor Exit Blocking with Exit Bridge Onion ServicesabstractTor exit blocking, in which websites disallow clients arriving from Tor, is a growing and potentially existential threat to the anonymity network. This paper introduces HebTor, a new and robust architecture for exit bridges---short-lived proxies that serve as alternative egress points for Tor. A key insight of HebTor is that exit bridges can operate as Tor onion services, allowing any device that can create outbound TCP connections to serve as an exit bridge, regardless of the presence of NATs and/or firewalls. HebTor employs a micropayment system that compensates exit bridge operators for their services, and a privacy-preserving reputation scheme that prevents freeloading. We show that HebTor effectively thwarts server-side blocking of Tor, and we describe the security, privacy, and legal implications of our design. Wenchao Zhou, Micah Sherr |
CCS | 3 |
| 2020 | Ephemeral Exit Bridges for TorabstractThis paper examines an existential threat to Tor---the increasing frequency at which websites apply discriminatory behavior to users who arrive via the anonymity network. Our main contribution is the introduction of Tor exit bridges. Exit bridges, constructed as short-lived virtual machines on cloud service providers, serve as alternative egress points for Tor and are designed to bypass server-side censorship. Due to the proliferation of managed cloud-based desktop services (e.g., Amazon Workspaces), there is already a surprisingly large fraction of web requests that originate in the cloud. Trivially disrupting exit bridges by blocking requests from the cloud would thus lead to significant collateral damage. Our experiments demonstrate that exit bridges effectively circumvent server-side blocking of Tor with low overhead. Additionally, we perform a cost-analysis of exit bridges and show that even a large-scale deployment can be done at low cost. Tavish Vaidya, Kartik Subramanian, Wenchao Zhou, Micah Sherr |
DSN | 5 |
| 2019 | Whisper: a unilateral defense against VoIP traffic re-identification attacksabstractEncrypted voice-over-IP (VoIP) communication often uses variable bit rate (VBR) codecs to achieve good audio quality while minimizing bandwidth costs. Prior work has shown that encrypted VBR-based VoIP streams are vulnerable to re-identification attacks in which an attacker can infer attributes (e.g., the language being spoken, the identities of the speakers, and key phrases) about the underlying audio by analyzing the distribution of packet sizes. Existing defenses require the participation of both the sender and receiver to secure their VoIP communications. Tavish Vaidya, Timothy Walsh 0002, Micah Sherr |
ACSAC | 3 |
| 2019 | Does Being Verified Make You More Credible?: Account Verification's Effect on Tweet CredibilityabstractMany popular social networking and microblogging sites support verified accounts---user accounts that are deemed of public interest and whose owners have been authenticated by the site. Importantly, the content of messages contributed by verified account owners is not verified. Such messages may be factually correct, or not. This paper investigates whether users confuse authenticity with credibility by posing the question: Are users more likely to believe content from verified accounts than from non-verified accounts? We conduct two online studies, a year apart, with 748 and 2041 participants respectively, to assess how the presence or absence of verified account indicators influences users' perceptions of tweets. Surprisingly, across both studies, we find that---in the context of unfamiliar accounts---most users can effectively distinguish between authenticity and credibility. The presence or absence of an authenticity indicator has no significant effect on willingness to share a tweet or take action based on its contents. Tavish Vaidya, Daniel Votipka, Michelle L. Mazurek, Micah Sherr |
CHI | 4 |
| 2019 | Point Break: A Study of Bandwidth Denial-of-Service Attacks against Tor
Rob Jansen, Tavish Vaidya, Micah Sherr |
USENIX Security Symposium | 3 |
| 2019 | KIST: Kernel-Informed Socket Transport for TorabstractTor’s growing popularity and user diversity has resulted in network performance problems that are not well understood, though performance is understood to be a significant factor in Tor’s security. A large body of work has attempted to solve performance problems without a complete understanding of where congestion occurs in Tor. In this article, we first study congestion in Tor at individual relays as well as along the entire end-to-end Tor path and find that congestion occurs almost exclusively in egress kernel socket buffers. We then analyze Tor’s socket interactions and discover two major contributors to Tor’s congestion: Tor writes sockets sequentially, and Tor writes as much as possible to each socket. To improve Tor’s performance, we design, implement, and test KIST: a new socket management algorithm that uses real-time kernel information to dynamically compute the amount to write to each socket while considering all circuits of all writable sockets when scheduling cells. We find that, in the medians, KIST reduces circuit congestion by more than 30%, reduces network latency by 18%, and increases network throughput by nearly 10%. We also find that client and relay performance with KIST improves as more relays deploy it and as network load and packet loss rates increase. We analyze the security of KIST and find an acceptable performance and security tradeoff, as it does not significantly affect the outcome of well-known latency, throughput, and traffic correlation attacks. KIST has been merged and configured as the default socket scheduling algorithm in Tor version 0.3.2.1-alpha (released September 18, 2017) and became stable in Tor version 0.3.2.9 (released January 9, 2018). While our focus is Tor, our techniques and observations should help analyze and improve overlay and application performance, both for security applications and in general. Rob Jansen, Matthew Traudt, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson |
ACM Trans. Priv. Secur. | 5 |
| 2018 | DeDoS: Defusing DoS with Dispersion Oriented SoftwareabstractThis paper presents DeDoS, a novel platform for mitigating asymmetric DoS attacks. These attacks are particularly challenging since even attackers with limited resources can exhaust the resources of well-provisioned servers. DeDoS offers a framework to deploy code in a highly modular fashion. If part of the application stack is experiencing a DoS attack, DeDoS can massively replicate only the affected component, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. Our evaluation results show that DeDoS incurs reasonable overheads in normal operations, and that it significantly outperforms standard replication techniques when defending against a range of asymmetric attacks. Henri Maxime Demoulin, Tavish Vaidya, Isaac Pedisich, Bob DiMaiolo, Jingyu Qian, Yuankai Zhang 0001, Ang Chen 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
ACSAC | 12 |
| 2018 | An Extensive Evaluation of the Internet's Open ProxiesabstractOpen proxies forward traffic on behalf of any Internet user. Listed on open proxy aggregator sites, they are often used to bypass geographic region restrictions or circumvent censorship. Open proxies sometimes also provide a weak form of anonymity by concealing the requestor's IP address. Akshaya Mani, Tavish Vaidya, David Dworken, Micah Sherr |
ACSAC | 4 |
| 2018 | Understanding Tor Usage with Privacy-Preserving Measurement
Akshaya Mani, T. Wilson-Brown, Rob Jansen, Aaron Johnson 0001, Micah Sherr |
Internet Measurement Conference | 5 |
| 2017 | Distributed Measurement with Private Set-Union CardinalityabstractThis paper introduces a cryptographic protocol for efficiently aggregating a count of unique items across a set of data parties privately - that is, without exposing any information other than the count. Our protocol allows for more secure and useful statistics gathering in privacy-preserving distributed systems such as anonymity networks; for example, it allows operators of anonymity networks such as Tor to securely answer the questions: how many unique users are using the distributed service? and how many hidden services are being accessed?. We formally prove the correctness and security of our protocol in the Universal Composability framework against an active adversary that compromises all but one of the aggregation parties. We also show that the protocol provides security against adaptive corruption of the data parties, which prevents them from being victims of targeted compromise. To ensure safe measurements, we also show how the output can satisfy differential privacy. Ellis Fenske, Akshaya Mani, Aaron Johnson 0001, Micah Sherr |
CCS | 4 |
| 2017 | HisTorε: Differentially Private and Robust Statistics Collection for Tor
Akshaya Mani, Micah Sherr |
NDSS | 2 |
| 2017 | Privacy-preserving Network ProvenanceabstractNetwork accountability, forensic analysis, and failure diagnosis are becoming increasingly important for network management and security. Network provenance significantly aids network administrators in these tasks by explaining system behavior and revealing the dependencies between system states. Although resourceful, network provenance can sometimes be too rich, revealing potentially sensitive information that was involved in system execution. In this paper, we propose a cryptographic approach to preserve the confidentiality of provenance (sub)graphs while allowing users to query and access the parts of the graph for which they are authorized. Our proposed solution is a novel application of searchable symmetric encryption (SSE) and more generally structured encryption (SE). Our SE-enabled provenance system allows a node to enforce access control policies over its provenance data even after the data has been shipped to remote nodes ( e.g. , for optimization purposes). We present a prototype of our design and demonstrate its practicality, scalability, and efficiency for both provenance maintenance and querying. Yuankai Zhang 0001, Adam O'Neill, Micah Sherr, Wenchao Zhou |
Proc. VLDB Endow. | 3 |
| 2016 | Generating risk reduction recommendations to decrease vulnerability of public online profilesabstractPreserving online privacy is becoming increasingly challenging due in large part to the continued growth of social media. Those who choose to share their information publicly may not realize what features of their profiles make their public data more identifiable and potentially vulnerable to cross-site record linkage. This paper proposes a risk reduction recommendation method that suggests removal or modification of a small number of attributes to make a profile less unique, thereby reducing the identifiability and vulnerability of the user. Empirical results on data collected from Google+, LinkedIn, and Foursquare show that users' vulnerability in terms of identifiability and data exposure level can be significantly reduced while public profile utility can be maintained using our proposed approach. Janet Zhu, Sicong Zhang, Lisa Singh, Grace Hui Yang, Micah Sherr |
ASONAM | 5 |
| 2016 | On Manufacturing Resilient Opaque Constructs Against Static Analysis
Brendan Sheridan, Micah Sherr |
ESORICS (2) | 2 |
| 2016 | Dispersing Asymmetric DDoS Attacks with SplitStackabstractThis paper presents SplitStack, an architecture targeted at mitigating asymmetric DDoS attacks. These attacks are particularly challenging, since attackers can use a limited amount of resources to trigger exhaustion of a particular type of system resource on the server side. SplitStack resolves this by splitting the monolithic stack into many separable components called minimum splittable units (MSUs). If part of the application stack is experiencing a DDoS attack, SplitStack massively replicates just the affected MSUs, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. We validate SplitStack via a preliminary case study, and show that it outperforms naive replication in defending against asymmetric attacks. Ang Chen 0001, Akshay Sriraman, Tavish Vaidya, Yuankai Zhang 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
HotNets | 8 |
| 2016 | Hidden Voice Commands
Nicholas Carlini, Pratyush Mishra 0001, Tavish Vaidya, Yuankai Zhang 0001, Micah Sherr, Clay Shields, David A. Wagner 0001, Wenchao Zhou |
USENIX Security Symposium | 5 |
| 2016 | Scalable and Anonymous Group Communication with MTorabstractAbstract This paper presents MTor, a low-latency anonymous group communication system. We construct MTor as an extension to Tor, allowing the construction of multi-source multicast trees on top of the existing Tor infrastructure. MTor does not depend on an external service to broker the group communication, and avoids central points of failure and trust. MTor’s substantial bandwidth savings and graceful scalability enable new classes of anonymous applications that are currently too bandwidth-intensive to be viable through traditional unicast Tor communication-e.g., group file transfer, collaborative editing, streaming video, and real-time audio conferencing. We detail the design of MTor and then analyze its performance and anonymity. By simulating MTor in Shadow and TorPS using realistic models of the live Tor network’s topology and recent consensus records from the live Tor network, we show that MTor achieves a 29% savings in network bandwidth and a 73% reduction in transmission time as compared to the baseline approach for anonymous group communication among 20 group members. We also demonstrate that MTor scales gracefully with the number of group participants, and allows dynamic group composition over time. Importantly, as more Tor users switch to group communication, we show that the overall performance and utilization for group communication improves. Finally, we discuss the anonymity implications of MTor and measure its resistance to traffic correlation. Dong Lin, Micah Sherr, Boon Thau Loo |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Data-plane Defenses against Routing Attacks on TorabstractAbstract Tor is susceptible to traffic correlation attacks in which an adversary who observes flows entering and leaving the anonymity network can apply statistical techniques to correlate flows and de-anonymize their endpoints. While an adversary may not be naturally positioned to conduct such attacks, a recent study shows that the Internet’s control-plane can be manipulated to increase an adversary’s view of the network, and consequently, improve its ability to perform traffic correlation. This paper explores, in-depth, the effects of control-plane attacks on the security of the Tor network. Using accurate models of the live Tor network, we quantify Tor’s susceptibility to these attacks by measuring the fraction of the Tor network that is vulnerable and the advantage to the adversary of performing the attacks. We further propose defense mechanisms that protect Tor users from manipulations at the control-plane. Perhaps surprisingly, we show that by leveraging existing trust anchors in Tor, defenses deployed only in the data-plane are sufficient to detect most control-plane attacks. Our defenses do not assume the active participation of Internet Service Providers, and require only very small changes to Tor. We show that our defenses result in a more than tenfold decrease in the effectiveness of certain control-plane attacks. Henry Tan, Micah Sherr, Wenchao Zhou |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | Private and Verifiable Interdomain Routing DecisionsabstractExisting secure interdomain routing protocols can verify validity properties about individual routes, such as whether they correspond to a real network path. It is often useful to verify more complex properties relating to the route decision procedure - for example, whether the chosen route was the best one available, or whether it was consistent with the network's peering agreements. However, this is difficult to do without knowing a network's routing policy and full routing state, which are not normally disclosed. In this paper, we show how a network can allow its peers to verify a number of nontrivial properties of its interdomain routing decisions without revealing any additional information. If all the properties hold, the peers learn nothing beyond what the interdomain routing protocol already reveals; if a property does not hold, at least one peer can detect this and prove the violation. We present SPIDeR, a practical system that applies this approach to the Border Gateway Protocol, and we report results from an experimental evaluation to demonstrate that SPIDeR has a reasonable overhead. Mingchen Zhao, Wenchao Zhou, Alexander J. T. Gurney, Andreas Haeberlen, Micah Sherr, Boon Thau Loo |
IEEE/ACM Trans. Netw. | 5 |
| 2015 | Public Information Exposure Detection: Helping Users Understand Their Web FootprintsabstractTo help users better understand the potential risks associated with publishing data publicly, as well as the quantity and sensitivity of information that can be obtained by combining data from various online sources, we introduce a novel information exposure detection framework that generates and analyzes the web footprints users leave across the social web. Web footprints are the traces of one's online social activities represented by a set of attributes that are known or can be inferred with a high probability by an adversary who has basic information about a user from his/her public profiles. Our framework employs new probabilistic operators, novel pattern-based attribute extraction from text, and a population-based inference engine to generate web footprints. Using a web footprint, the framework then quantifies a user's level of information exposure relative to others with similar traits, as well as with regard to others in the population. Evaluation over public profiles from multiple sites (Google+, LinkeIn, FourSquare, and Twitter) shows that the proposed framework effectively detects and quantifies information exposure using a small amount of initial knowledge. Lisa Singh, Grace Hui Yang, Micah Sherr, Andrew Hian-Cheong, Kevin Tian, Janet Zhu, Sicong Zhang |
ASONAM | 3 |
| 2015 | Accountable wiretapping - or - I know they can hear you nowabstractAbstract In many democratic countries, Communications Assistance for Law Enforcement Act (CALEA) wiretaps are used by law enforcement agencies to perform investigations and gather evidence for legal procedures. However, existing CALEA wiretap implementations are often engineered with the assumption that wiretap operators are trustworthy and wiretap targets do not attempt to evade the wiretap. Although it may be possible to construct more robust wiretap architectures by reengineering significant portions of the telecommunications infrastructure, such efforts are prohibitively costly. This paper instead proposes a lightweight accountable wiretapping system for enabling secure audits of existing CALEA wiretapping systems. Our proposed system maintains a tamper-evident encrypted log over wiretap events, enforces access controls over wiretap records, and enables privacy-preserving aggregate queries and compliance checks. We demonstrate using campus-wide telephone trace data from a large university that our approach provides efficient auditing functionalities while incurring only modest overhead. Based on publicly available wiretap reporting statistics, we conservatively estimate that our architecture can support tamper-evident logging for all of the United States’ ongoing CALEA wiretaps using three commodity PCs. Adam Bates 0001, Kevin R. B. Butler, Micah Sherr, Clay Shields, Patrick Traynor, Dan S. Wallach |
J. Comput. Secur. | 3 |
| 2014 | Fair Maximal Independent SetsabstractFinding a maximal independent set (MIS) is a classic problem in graph theory that has been widely studied in the context of distributed algorithms. Standard distributed solutions to the MIS problem focus on time complexity. In this paper, we also consider fairness. For a given MIS algorithm A and graph G, we define the inequality factor for A on G to be the largest ratio between the probabilities of the nodes joining an MIS in the graph. We say an algorithm is fair with respect to a family of graphs if it achieves a constant inequality factor for all graphs in the family. In this paper, we seek efficient and fair algorithms for common graph families. We begin by describing an algorithm that is fair and runs in O(log* n)-time in rooted trees of size n. Moving to unrooted trees, we describe a fair algorithm that runs in O(log n) time. Generalizing further to bipartite graphs, we describe a third fair algorithm that requires O(log2 n) rounds. We also show a fair algorithm for planar graphs that runs in O(log2 n) rounds, and describe an algorithm that can be run in any graph, yielding good bounds on inequality in regions that can be efficiently colored with a small number of colors. We conclude our theoretical analysis with a lower bound that identifies a graph where all MIS algorithms achieve an inequality bound in Ω(n)-eliminating the possibility of an MIS algorithm that is fair in all graphs. Finally, to motivate the need for provable fairness guarantees, we simulate both our tree algorithm and Luby's MIS algorithm [13] in a variety of different tree topologies-some synthetic and some derived from real world data. Whereas our algorithm always yield an inequality factor ≤3.25 in these simulations, Luby's algorithms yields factors as large as 168. Jeremy T. Fineman, Calvin C. Newport, Micah Sherr, Tonghe Wang |
IPDPS | 3 |
| 2014 | A Disruption-Resistant MAC Layer for Multichannel Wireless Networks
Henry Tan, Chris Wacek, Calvin C. Newport, Micah Sherr |
OPODIS | 4 |
| 2014 | Detecting Covert Timing Channels with Time-Deterministic Replay
Ang Chen 0001, W. Brad Moore, Hanjun Xiao, Andreas Haeberlen, Linh T. X. Phan, Micah Sherr, Wenchao Zhou |
OSDI | 6 |
| 2014 | Never Been KIST: Tor's Congestion Management Blossoms with Kernel-Informed Socket Transport
Rob Jansen, John Geddes, Chris Wacek, Micah Sherr, Paul F. Syverson |
USENIX Security Symposium | 4 |
| 2014 | The design and implementation of the A3 application-aware anonymity platform
Micah Sherr, Harjot Gill, Taher Saeed, Andrew Mao, William R. Marczak, Saravana Soundararajan, Wenchao Zhou, Boon Thau Loo, Matt Blaze |
Comput. Networks | 1 |
| 2014 | Privacy-aware message exchanges for HumaNets
Adam J. Aviv, Matt Blaze, Micah Sherr, Jonathan M. Smith |
Comput. Commun. | 3 |
| 2013 | Validating web content with senserabstractThis paper introduces Senser, a system for validating retrieved web content. Senser does not rely on a PKI and operates even when SSL/TLS is not supported by the web server. Senser operates as a network of proxies located at different vantage points on the Internet. Clients query a random subset of Senser proxies for compact descriptions of a desired web page, and apply consensus and matching algorithms to the returned results to locally render a "majority" web page. To ensure diverse selections of proxies (and consequently decrease an adversary's ability to manipulate a majority of the proxies' requests), Senser leverages Internet mapping systems that accurately predict AS-level paths between available proxies and the desired web page. We demonstrate using a deployment of Senser on Amazon EC2 that Senser detects and mitigates attempts by adversaries to manipulate web content --- even when controlling large collections of autonomous systems --- while maintaining reasonable performance overheads. Jordan Wilberding, Andrew Yates, Micah Sherr, Wenchao Zhou |
ACSAC | 3 |
| 2013 | Users get routed: traffic correlation on tor by realistic adversariesabstractWe present the first analysis of the popular Tor anonymity network that indicates the security of typical users against reasonably realistic adversaries in the Tor network or in the underlying Internet. Our results show that Tor users are far more susceptible to compromise than indicated by prior work. Specific contributions of the paper include(1)a model of various typical kinds of users,(2)an adversary model that includes Tor network relays, autonomous systems(ASes), Internet exchange points (IXPs), and groups of IXPs drawn from empirical study,(3) metrics that indicate how secure users are over a period of time,(4) the most accurate topological model to date of ASes and IXPs as they relate to Tor usage and network configuration,(5) a novel realistic Tor path simulator (TorPS), and(6)analyses of security making use of all the above. To show that our approach is useful to explore alternatives and not just Tor as currently deployed, we also analyze a published alternative path selection algorithm, Congestion-Aware Tor. We create an empirical model of Tor congestion, identify novel attack vectors, and show that it too is more vulnerable than previously indicated. Aaron Johnson 0001, Chris Wacek, Rob Jansen, Micah Sherr, Paul F. Syverson |
CCS | 4 |
| 2013 | An Empirical Evaluation of Relay Selection in Tor
Chris Wacek, Henry Tan, Kevin S. Bauer, Micah Sherr |
NDSS | 4 |
| 2013 | Identifying individual vulnerability based on public dataabstractCompanies and government agencies frequently own data sets containing personal information about clients, survey responders, or users of a product. Sometimes these organizations are required or wish to release anonymized versions of this information to the public. Prior to releasing these data, they use established privacy preservation methods such as binning, data perturbation, and data suppression to maintain the anonymity of clients, customers, or survey participants. However, existing work has shown that common privacy preserving measures fail when anonymized data are combined with data from online social networks, social media sites, and data aggregation sites. This paper introduces a methodology for determining the vulnerability of individuals in a pre-released data set to reidentification using public data. As part of this methodology, we propose novel metrics to quantify the amount of information that can be gained from combining pre-released data with publicly available online data. We then investigate how to utilize our metrics to identify individuals in the data set who may be particularly vulnerable to this form of data combination. We demonstrate the effectiveness of our methodology on a real world data set using public data from both social networking and data aggregation sites. John Ferro, Lisa Singh, Micah Sherr |
PST | 3 |
| 2012 | Privacy-Aware Message Exchanges for Geographically Routed Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
ESORICS | 2 |
| 2012 | Accountable Wiretapping -or- I know they can hear you now
Adam Bates 0001, Kevin R. B. Butler, Micah Sherr, Clay Shields, Patrick Traynor, Dan S. Wallach |
NDSS | 3 |
| 2012 | Recent Advances in Declarative Networking
Boon Thau Loo, Harjot Gill, Changbin Liu, Yun Mao, William R. Marczak, Micah Sherr, Anduo Wang, Wenchao Zhou |
PADL | 6 |
| 2012 | Private and verifiable interdomain routing decisionsabstractExisting secure interdomain routing protocols can verify validity properties about individual routes, such as whether they correspond to a real network path. It is often useful to verify more complex properties relating to the route decision procedure - for example, whether the chosen route was the best one available, or whether it was consistent with the network's peering agreements. However, this is difficult to do without knowing a network's routing policy and full routing state, which are not normally disclosed. In this paper, we show how a network can allow its peers to verify a number of nontrivial properties of its interdomain routing decisions without revealing any additional information. If all the properties hold, the peers learn nothing beyond what the interdomain routing protocol already reveals; if a property does not hold, at least one peer can detect this and prove the violation. We present SPIDeR, a practical system that applies this approach to the Border Gateway Protocol, and we report results from an experimental evaluation to demonstrate that SPIDeR has a reasonable overhead. Mingchen Zhao, Wenchao Zhou, Alexander J. T. Gurney, Andreas Haeberlen, Micah Sherr, Boon Thau Loo |
SIGCOMM | 5 |
| 2012 | $100, 000 prize jackpot. call now!: identifying the pertinent features of SMS spamabstractMobile SMS spam is on the rise and is a prevalent problem. While recent work has shown that simple machine learning techniques can distinguish between ham and spam with high accuracy, this paper explores the individual contributions of various textual features in the classification process. Our results reveal the surprising finding that simple is better: using the largest spam corpus of which we are aware, we find that using simple textual features is sufficient to provide accuracy that is nearly identical to that achieved by the best known techniques, while achieving a twofold speedup. Henry Tan, Nazli Goharian, Micah Sherr |
SIGIR | 3 |
| 2012 | Distributed Time-aware ProvenanceabstractThe ability to reason about changes in a distributed system's state enables network administrators to better diagnose protocol misconfigurations, detect intrusions, and pinpoint performance bottlenecks. We propose a novel provenance model called Distributed Time-aware Provenance (DTaP) that aids forensics and debugging in distributed systems by explicitly representing time, distributed state, and state changes. Using a distributed Datalog abstraction for modeling distributed protocols, we prove that the DTaP model provides a sound and complete representation that correctly captures dependencies among events in a distributed system. We additionally introduce DistTape, an implementation of the DTaP model that uses novel distributed storage structures, query processing, and cost-based optimization techniques to efficiently query time-aware provenance in a distributed setting. Using two example systems (declarative network routing and Hadoop MapReduce), we demonstrate that DistTape can efficiently maintain and query time-aware provenance at low communication and computation cost. Wenchao Zhou, Suyog Mapara, Yiqing Ren, Yang Li 0025, Andreas Haeberlen, Zachary G. Ives, Boon Thau Loo, Micah Sherr |
Proc. VLDB Endow. | 8 |
| 2011 | Exploring the potential benefits of expanded rate limiting in Tor: slow and steady wins the race with TortoiseabstractTor is a volunteer-operated network of application-layer relays that enables users to communicate privately and anonymously. Unfortunately, Tor often exhibits poor performance due to congestion caused by the unbalanced ratio of clients to available relays, as well as a disproportionately high consumption of network capacity by a small fraction of filesharing users. W. Brad Moore, Chris Wacek, Micah Sherr |
ACSAC | 3 |
| 2011 | Having your cake and eating it too: routing security with privacy protectionsabstractInternet Service Providers typically do not reveal details of their interdomain routing policies due to security concerns, or for commercial or legal reasons. As a result, it is difficult to hold ISPs accountable for their contractual agreements. Existing solutions can check basic properties, e.g., whether route announcements correspond to valid routes, but they do not verify how these routes were chosen. In essence, today's Internet forces us to choose between per-AS privacy and verifiability. Alexander J. T. Gurney, Andreas Haeberlen, Wenchao Zhou, Micah Sherr, Boon Thau Loo |
HotNets | 4 |
| 2011 | NetTrails: a declarative platform for maintaining and querying provenance in distributed systemsabstractWe demonstrate NetTrails, a declarative platform for maintaining and interactively querying network provenance in a distributed system. Network provenance describes the history and derivations of network state that result from the execution of a distributed protocol. It has broad applicability in the management, diagnosis, and security analysis of networks. Our demonstration shows the use of NetTrails for maintaining and querying network provenance in a variety of distributed settings, ranging from declarative networks to unmodified legacy distributed systems. We conclude our demonstration with a discussion of our ongoing research on enhancing the query language and security guarantees. Wenchao Zhou, Qiong Fei, Shengzhi Sun, Andreas Haeberlen, Zachary G. Ives, Boon Thau Loo, Micah Sherr |
SIGMOD Conference | 8 |
| 2011 | Secure network provenanceabstractThis paper introduces secure network provenance (SNP), a novel technique that enables networked systems to explain to their operators why they are in a certain state -- e.g., why a suspicious routing table entry is present on a certain router, or where a given cache entry originated. SNP provides network forensics capabilities by permitting operators to track down faulty or misbehaving nodes, and to assess the damage such nodes may have caused to the rest of the system. SNP is designed for adversarial settings and is robust to manipulation; its tamper-evident properties ensure that operators can detect when compromised nodes lie or falsely implicate correct nodes. Wenchao Zhou, Qiong Fei, Arjun Narayan, Andreas Haeberlen, Boon Thau Loo, Micah Sherr |
SOSP | 6 |
| 2010 | A3: An Extensible Platform for Application-Aware Anonymity
Micah Sherr, Andrew Mao, William R. Marczak, Wenchao Zhou, Boon Thau Loo, Matt Blaze |
NDSS | 1 |
| 2010 | SecureBlox: customizable secure distributed data processingabstractWe present SecureBlox, a declarative system that unifies a distributed query processor with a security policy framework. SecureBlox decouples security concerns from system specification, allowing easy reconfiguration of a system's security properties to suit a given execution environment. Our implementation of SecureBlox is a series of extensions to LogicBlox, an emerging commercial Datalog-based platform for enterprise software systems. SecureBlox enhances LogicBlox to enable distribution and static meta-programmability, and makes novel use of existing LogicBlox features such as integrity constraints. SecureBlox allows meta-programmability via BloxGenerics - a language extension for compile-time code generation based on the security requirements and trust policies of the deployed environment. We present and evaluate detailed use-cases in which SecureBlox enables diverse applications, including an authenticated declarative routing protocol with encrypted advertisements and an authenticated and encrypted parallel hash join operation. Our results demonstrate SecureBlox's abilities to specify and implement a wide range of different security constructs for distributed systems as well as to enable tradeoffs between performance and security. William R. Marczak, Shan Shan Huang, Martin Bravenboer, Micah Sherr, Boon Thau Loo, Molham Aref |
SIGMOD Conference | 4 |
| 2010 | Efficient querying and maintenance of network provenance at internet-scaleabstractNetwork accountability, forensic analysis, and failure diagnosis are becoming increasingly important for network management and security. Such capabilities often utilize network provenance - the ability to issue queries over network meta-data. For example, network provenance may be used to trace the path a message traverses on the network as well as to determine how message data were derived and which parties were involved in its derivation. Wenchao Zhou, Micah Sherr, Boon Thau Loo, Yun Mao |
SIGMOD Conference | 2 |
| 2010 | Evading Cellular Data Monitoring with Human Movement Networks
Adam J. Aviv, Micah Sherr, Matt Blaze, Jonathan M. Smith |
HotSec | 2 |
| 2009 | Can they hear me now?: a security analysis of law enforcement wiretapsabstractAlthough modern communications services are susceptible to third-party eavesdropping via a wide range of possible techniques, law enforcement agencies in the US and other countries generally use one of two technologies when they conduct legally-authorized interception of telephones and other communications traffic. The most common of these, designed to comply with the 1994 Communications Assistance for Law Enforcement Act(CALEA), use a standard interface provided in network switches. Micah Sherr, Gaurav Shah, Eric Cronin, Sandy Clark, Matt Blaze |
CCS | 1 |
| 2009 | Scalable Link-Based Relay Selection for Anonymous Routing
Micah Sherr, Matt Blaze, Boon Thau Loo |
Privacy Enhancing Technologies | 1 |
| 2009 | Veracity: Practical Secure Network Coordinates via Vote-based Agreements
Micah Sherr, Matt Blaze, Boon Thau Loo |
USENIX ATC | 1 |
| 2007 | Towards Application-Aware Anonymous Routing
Micah Sherr, Boon Thau Loo, Matt Blaze |
HotSec | 1 |
| 2006 | On the Reliability of Network Eavesdropping Tools
Eric Cronin, Micah Sherr, Matt Blaze |
IFIP Int. Conf. Digital Forensics | 2 |
| 2006 | Sensor Network Security: More Interesting Than You Think
Madhukar Anand, Eric Cronin, Micah Sherr, Zachary G. Ives, Insup Lee 0001 |
HotSec | 3 |
| 2001 | Metadata Tables to Enable Dynamic Data Modeling and Web Interface Design: The SEER Example
Mark G. Weiner, Micah Sherr, Abigail Cohen |
AMIA | 2 |