EDBT 2026 Demo / reviewers in the wild / expert
Hsu-Chun Hsiao
dblp:59/7124
· DBLP profile ↗
41ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0001-9592-6911ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 4 first-author · 12 since 2021Computer networks · 7 · 1 first-author · 1 since 2021Systems, architecture and hardware · 4 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bot Among Us: Exploring User Awareness and Privacy Concerns About Chatbots in Group ChatsabstractAs chatbots become increasingly integrated into group conversations on instant messaging platforms, concerns arise about their impact on user privacy. While prior research has examined chatbot risks in one-on-one interactions, little is known about how users perceive and respond to privacy threats in group settings, where chatbots may silently access messages and metadata. To address this gap, we conducted an online survey (N=374) across five popular messaging platforms—WhatsApp, Discord, Telegram, Viber, and LINE—to evaluate user awareness, understanding of chatbot access, privacy concerns, and behavioral responses. We found that many users were unaware of bots in their group chats and significantly underestimated their data access: only 41.7% correctly identified what messages chatbots could access. Privacy concerns also rose sharply after users learned about actual bot permissions. Based on our findings, we propose a five-stage model that captures how users detect, interpret, and respond to chatbot-related privacy risks. We further analyzed the designs of platforms with official chatbot support through this model and found mismatches between design choices and user expectations. Finally, we offer design recommendations to improve transparency and user control in group chatbot-interactions. Kai-Hsiang Chou, Yi-An Wang, Chong Kai Lau, Mahmood Sharif, Hsu-Chun Hsiao |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | Uncovering Hidden Proxy Smart Contracts for Finding Collision Vulnerabilities in EthereumabstractThe proxy design pattern allows Ethereum smart contracts to be simultaneously immutable and upgradeable, in which an original contract is split into a proxy contract containing the data storage and a logic contract containing the implementation logic. This architecture is known to have security issues, namely function collisions and storage collisions between the proxy and logic contracts, and has been exploited in real-world incidents to steal users’ millions of dollars worth of digital assets. In response to this concern, several previous works have sought to identify proxy contracts in Ethereum and detect their collisions. However, they all fell short due to their limited coverage, often restricting analysis to only contracts with available source code or past transactions.To bridge this gap, we present Proxion, an automated cross-contract analyzer that identifies all proxy smart contracts and their collisions in Ethereum. What sets Proxion apart is its ability to analyze hidden smart contracts that lack both source code and past transactions. Equipped with various techniques to enhance efficiency and accuracy, Proxion outperforms the state-of-the-art tools, notably identifying millions more proxy contracts and thousands of unreported collisions. We apply Proxion to analyze over 36 million alive contracts from 2015 to 2023, revealing that 54.2% of them are proxy contracts, and about 1.5 million contracts exhibit at least one collision issue. Cheng-Kang Chen, Wen-Yi Chu, Muoi Tran, Laurent Vanbever, Hsu-Chun Hsiao |
ICDCS | 5 |
| 2025 | Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats
Kai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li, Tiffany Hyun-Jin Kim, Hsu-Chun Hsiao |
USENIX Security Symposium | 6 |
| 2024 | Verifying Loot-box Probability Without Source-code DisclosureabstractLoot boxes, a common revenue model in contemporary mobile games, offer players the opportunity to acquire random rewards. However, their fairness has been the subject of numerous disputes worldwide, in part because game players cannot directly observe the logic of the loot-box mechanism. Apple App Store has required app providers to disclose the odds associated with their loot boxes to customers since 2017, and Google Play followed suit beginning in 2019. However, a practical method for allowing the public to verify whether a game complies with its probability statements has not previously been devised. Existing methods, such as source-code audits and statistical examination of player-reported samples, are misaligned with the game companies’ interests, and/or may encounter biased samples. Therefore, this paper proposes a verifiable loot-box process without disclosing their source codes. We utilize two cryptographic components, functional commitment and public randomness beacon, to devise a verifiable loot-box process comprising a verifiable loot-box function and a verifiable random source. In particular, we propose two protocols: one for probability verification and the other for loot-box opening. The former allows players to verify the winning probability of loot boxes using publicly verifiable random sources. The latter establishes a mechanism whereby game servers and players can agree on a random input, ensuring that neither party can manipulate the outcome. Our implementations of both these protocols, along with experiments to evaluate their performance, demonstrate that they are practical. Jing-Jie Wang, An-Jie Li, Ting-Yu Fang, Hsu-Chun Hsiao |
ACSAC | 4 |
| 2024 | Poster: YFuzz: Data-Driven FuzzingabstractCode coverage is an effective objective for guiding fuzzers to explore code and identify bugs, and it has been a key factor in the success of greybox fuzzing. However, code coverage has a critical limitation: coverage-guided fuzzers can miss bugs even when the associated code is covered. This limitation arises because merely executing the associated code is often insufficient to trigger a bug; specific conditions are usually also required. These conditions are not fully captured by code coverage, which focuses only on whether the code was executed. Chun-Chia Huang, Tatsuya Mori 0003, Hsu-Chun Hsiao |
CCS | 4 |
| 2024 | Risky Cohabitation: Understanding and Addressing Over-privilege Risks of Commodity Application Virtualization Platforms in AndroidabstractThe Android system protects its users' privacy via app permissions, which govern apps' access to sensitive data and resources. However, recent research has reported that, during app virtualization, the current Android permission model fails to prevent illegal permission usage: apps can exploit the User ID shared among co-hosted apps in the same virtualized environment to perform unauthorized actions. To the best of our knowledge, such over-privilege issues have not been thoroughly investigated; neither has a practical defense proposed to address them. Shou-Ching Hsiao, Shih-Wei Li, Hsu-Chun Hsiao |
CODASPY | 3 |
| 2024 | Detecting IP Prefix Mismatches on SDN Data PlaneabstractSoftware-defined networking (SDN) enables centralized network management by separating the control and data plane. However, the actual packet behavior on data-plane may deviate from the control-plane rules sometimes. Many probe-based tools have been developed to verify the data plane’s correctness and detect forwarding errors by sending test packets. However, they all assume simple fault models, such as incorrect action fields in the forwarding rules. To address this gap, this paper identifies a new class of error affecting the IP match field called IP prefix mismatch, which previous tools failed to identify thoroughly. We categorize IP prefix mismatches into prefix shrinkage and prefix expansion. We then present novel test packet generation algorithms to construct test packets designed to exhibit different behaviors depending on the presence of these errors. Using these algorithms, we develop a system that guarantees the discovery of at least one prefix mismatch in every detection round, even in the worst-case scenario.Several experiments were conducted to compare our system to a conventional probe-based method that sends a single test packet per rule. The results demonstrate that our system achieves perfect fault coverage within a minimal number of detection rounds. Even when faced with a network containing 50% erroneous rules, it successfully identifies all prefix mismatches within an average of only two detection rounds. In contrast, the conventional method fails to uncover all errors, even after spending on additional detection rounds. Shu-Po Tung, Yu-Min Lin, Keng-Lun Chang, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim |
ICCCN | 4 |
| 2024 | SPArch: A Hardware-oriented Sketch-based Architecture for High-speed Network Flow MeasurementsabstractNetwork flow measurement is an integral part of modern high-speed applications for network security and data-stream processing. However, processing at line rate while maintaining the required data structure within the on-chip memory of the hardware platform is a challenging task for measurement algorithms, especially when accuracy is of primary importance, such as in network security applications. Most of the existing measurement algorithms are no exception to such issues when deployed in high-speed networking environments and are also not tailored for efficient hardware implementation. Sketch-based measurement algorithms minimize the memory requirement and are suitable for high-speed networks but possess a low memory-accuracy trade-off and lack the versatility of individual flow mapping. To address these challenges, we present a hardware-friendly data structure named Sketch-based Pseudo-associative array Architecture (SPArch). SPArch is highly accurate and extremely memory-efficient, making it suitable for network flow measurement and security applications. The parallelism in SPArch ensures minimal and constant memory access cycles. Unlike other sketch architectures, SPArch provides the functionality of individual flow mapping similar to associative arrays, and the optimized version of SPArch allows the organization of counters in multiple buckets based on the flow sizes. An in-depth analysis of SPArch is carried out in this article and implemented SPArch on the Alveo data center accelerator card, demonstrating its suitability for high-speed networks. Arish Sateesan, Jo Vliegen, Simon Scherrer, Hsu-Chun Hsiao, Adrian Perrig, Nele Mentens |
ACM Trans. Priv. Secur. | 4 |
| 2023 | Capturing Antique Browsers in Modern Devices: A Security Analysis of Captive Portal Mini-Browsers
Ping-Lun Wang, Kai-Hsiang Chou, Shou-Ching Hsiao, Ann Tene Low, Tiffany Hyun-Jin Kim, Hsu-Chun Hsiao |
ACNS (1) | 6 |
| 2023 | ALBUS: a Probabilistic Monitoring Algorithm to Counter Burst-Flood AttacksabstractModern DDoS defense systems rely on probabilistic monitoring algorithms to identify flows that exceed a volume threshold and should thus be penalized. Commonly, classic sketch algorithms are considered sufficiently accurate for usage in DDoS defense. However, as we show in this paper, these algorithms achieve poor detection accuracy under burst-flood attacks, i.e., volumetric DDoS attacks composed of a swarm of medium-rate sub-second traffic bursts. Under this challenging attack pattern, traditional sketch algorithms can only detect a high share of the attack bursts by incurring a large number of false positives. In this paper, we present ALBUS, a probabilistic monitoring algorithm that overcomes the inherent limitations of previous schemes: ALBUS is highly effective at detecting large bursts while reporting no legitimate flows, and therefore improves on prior work regarding both recall and precision. Besides improving accuracy, ALBUS scales to high traffic rates, which we demonstrate with an FPGA implementation, and is suitable for programmable switches, which we showcase with a P4 implementation. Simon Scherrer, Jo Vliegen, Arish Sateesan, Hsu-Chun Hsiao, Nele Mentens, Adrian Perrig |
SRDS | 4 |
| 2022 | Tool: An Efficient and Flexible Simulator for Byzantine Fault-Tolerant ProtocolsabstractA Byzantine Fault-Tolerant (BFT) protocol protects a distributed system from faulty participants. To provide both liveness and safety, many such protocols assume they are dealing with a partially-synchronous network, which will eventually stabilize after a global stabilization time (GST). In a real-world network environment, however, there is no such guarantee of bounded transmission time for network packets. For this reason, even if a BFT protocol is mathematically proven to achieve both liveness and safety, its overall performance is difficult to analyze theoretically, especially if there are bad network conditions or adversarial behaviors. Accordingly, we propose a simulator for evaluating the performance of BFT protocols under various network conditions and attacks, and we implement it to empirically compare the performance of eight representative protocols. Experiment results show that our simulator can simulate 16 times as many nodes as an existing simulator supports (512 vs. 32), and it is over 500 times faster when simulating 32 nodes (38 milliseconds vs. 19.4 seconds). Ping-Lun Wang, Tzu-Wei Chao, Chia-Chien Wu, Hsu-Chun Hsiao |
DSN | 4 |
| 2022 | HeadStart: Efficiently Verifiable and Low-Latency Participatory Randomness Generation at Scale
Hsun Lee, Yuming Hsu, Jing-Jie Wang, Yu-Heng Chen, Yih-Chun Hu, Hsu-Chun Hsiao |
NDSS | 7 |
| 2022 | Investigating Advertisers' Domain-changing Behaviors and Their Impacts on Ad-blocker Filter ListsabstractAd blockers heavily rely on filter lists to block ad domains, which can serve advertisements and trackers. However, recent research has reported that some advertisers keep registering replica ad domains (RAD domains)—new domains that serve the same purpose as the original ones—which tend to slip through ad-blocker filter lists. Although this phenomenon might negatively affect ad blockers’ effectiveness, no study to date has thoroughly investigated its prevalence and the issues caused by RAD domains. In this work, we proposed methods to discover RAD domains and categorized their change patterns. From a crawl of 50,000 websites, we identified 1,748 unique RAD domains, 1,096 of which survived for an average of 410.5 days before they were blocked; the rest have not been blocked as of February 2021. Notably, we found that non-blocked RAD domains could extend the timespan of ad or tracker distribution by more than two years. Our analysis further revealed a taxonomy of four techniques used to create RAD domains, including two less-studied ones. Additionally, we discovered that the RAD domains affected 10.2% of the websites we crawled, and 23.7% of the RAD domains exhibiting privacy-intrusive behaviors, undermining ad blockers’ privacy protection. Su-Chin Lin, Kai-Hsiang Chou, Yen Chen, Hsu-Chun Hsiao, Darion Cassel, Lujo Bauer, Limin Jia 0001 |
WWW | 4 |
| 2022 | OmniCrawl: Comprehensive Measurement of Web Tracking With Real Desktop and Mobile BrowsersabstractAbstract Over half of all visits to websites now take place in a mobile browser, yet the majority of web privacy studies take the vantage point of desktop browsers, use emulated mobile browsers, or focus on just a single mobile browser instead. In this paper, we present a comprehensive web-tracking measurement study on mobile browsers and privacy-focused mobile browsers. Our study leverages a new web measurement infrastructure, OmniCrawl, which we develop to drive browsers on desktop computers and smartphones located on two continents. We capture web tracking measurements using 42 different non-emulated browsers simultaneously. We find that the third-party advertising and tracking ecosystem of mobile browsers is more similar to that of desktop browsers than previous findings suggested. We study privacy-focused browsers and find their protections differ significantly and in general are less for lower-ranked sites. Our findings also show that common methodological choices made by web measurement studies, such as the use of emulated mobile browsers and Selenium, can lead to website behavior that deviates from what actual users experience. Darion Cassel, Su-Chin Lin, Alessio Buraggina, Lujo Bauer, Hsu-Chun Hsiao, Limin Jia 0001, Timothy Libert |
Proc. Priv. Enhancing Technol. | 7 |
| 2021 | Speed Records in Network Flow Measurement on FPGAabstractNetwork traffic measurement keeps track of the amount of traffic sent by each flow in the network. It is a core functionality in applications such as traffic engineering and network intrusion detection. In high-speed networks, it is impossible to keep an exact count of the flow traffic, due to limitations with respect to memory and computational speed. Therefore, probabilistic data structures, such as sketches, are used. This paper proposes Approximate Count-Min sketch or ACM sketch, a novel variant of the Count-Min sketch algorithm that uses less memory and has a higher throughput compared to other FPGA-based sketch implementations. A-CM sketch relies on optimizations at two levels: (1) it uses approximate counters and the newly proposed Hardware-oriented Simple Active Counter algorithm to efficiently implement these counters; (2) it uses a distribution of the embedded memory, optimized towards maximum operating frequency. To the best of our knowledge, A-CM sketch outperforms all other FPGA-based sketch implementations. Arish Sateesan, Jo Vliegen, Simon Scherrer, Hsu-Chun Hsiao, Adrian Perrig, Nele Mentens |
FPL | 4 |
| 2021 | Low-Rate Overuse Flow Tracer (LOFT): An Efficient and Scalable Algorithm for Detecting Overuse FlowsabstractCurrent probabilistic flow-size monitoring can only detect heavy hitters (e.g., flows utilizing 10 times their permitted bandwidth), but cannot detect smaller overuse (e.g., flows utilizing 50-100 % more than their permitted bandwidth). Thus, these systems lack accuracy in the challenging environment of high-throughput packet processing, where fast-memory resources are scarce. Nevertheless, many applications rely on accurate flow-size estimation, e.g., for network monitoring, anomaly detection and Quality of Service. We design, analyze, implement, and evaluate LOFT, a new approach for efficiently detecting overuse flows that achieves dramatically better properties than prior work. LOFT can detect 1.50x overuse flows in one second, whereas prior approaches can only reliably detect flows that overuse their allocation by at least 3x. We demonstrate LOFT's suitability for high-speed packet processing with implementations in the DPDK framework and on an FPGA. Simon Scherrer, Che-Yu Wu, Yu-Hsi Chiang, Benjamin Rothenberger, Daniele Enrico Asoni, Arish Sateesan, Jo Vliegen, Nele Mentens, Hsu-Chun Hsiao, Adrian Perrig |
SRDS | 9 |
| 2020 | Poster: Challenges in Stopping Ticket Scalping Bots
Hsun Lee, Hsu-Chun Hsiao |
AsiaCCS | 3 |
| 2020 | On the Privacy Risks of Compromised Trigger-Action Platforms
Yu-Hsi Chiang, Hsu-Chun Hsiao, Chia-Mu Yu, Tiffany Hyun-Jin Kim |
ESORICS (2) | 2 |
| 2019 | On the Feasibility of Rerouting-Based DDoS DefensesabstractLarge botnet-based flooding attacks have recently demonstrated unprecedented damage. However, the best-known end-to-end availability guarantees against flooding attacks require costly global-scale coordination among autonomous systems (ASes). A recent proposal called routing around congestion (or RAC) attempts to offer strong end-to-end availability to a selected critical flow by dynamically rerouting it to an uncongested detour path without requiring any inter-AS coordination. This paper presents an in-depth analysis of the (in)feasibility of the RAC defense and points out that its rerouting approach, though intriguing, cannot possibly solve the challenging flooding problem. An effective RAC solution should find an inter-domain detour path for its critical flow with the two following desired properties: (1) it guarantees the establishment of an arbitrary detour path of its choice, and (2) it isolates the established detour path from non-critical flows so that the path is used exclusively for its critical flow. However, we show a fundamental trade-off between the two desired properties, and as a result, only one of them can be achieved but not both. Worse yet, we show that failing to achieve either of the two properties makes the RAC defense not just ineffective but nearly unusable. When the newly established detour path is not isolated, a new adaptive adversary can detect it in real time and immediately congest the path, defeating the goals of the RAC defense. Conversely, when the establishment of an arbitrary detour path is not guaranteed, more than 80% of critical flows we test have only a small number (e.g., three or less) of detour paths that can actually be established and disjoint from each other, which significantly restricts the available options for the reliable RAC operation. The first lesson of this study is that BGP-based rerouting solutions in the current inter-domain infrastructure seem to be impractical due to implicit assumptions (e.g., the invisibility of poisoning messages) that are unattainable in BGP's current practice. Second, we learn that the analysis of protocol specifications alone is insufficient for the feasibility study of any new defense proposal and, thus, additional rigorous security analysis and various network evaluations, including real-world testing, are required. Finally, our findings in this paper agree well with the conclusion of the major literature about end-to-end guarantees; that is, strong end-to-end availability should be a security feature of the Internet routing by design, not an ad hoc feature obtained via exploiting current routing protocols. Muoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang, Shu-Po Tung |
IEEE Symposium on Security and Privacy | 3 |
| 2019 | An Investigation of Cyber Autonomy on Government WebsitesabstractFrom a national security viewpoint, a higher degree of cyber autonomy is crucial to reduce the reliance on external, oftentimes untrustworthy entities, in order to achieve better resilience against adversaries. To probe into the concept of government cyber autonomy, this study examines the external dependency of public-facing government websites across the world's major industrialized, Group of Seven (G7) countries. Over a two-year period, we measured HTTPS adoption rates, the autonomy status of CAs, and the autonomy status of CPs on G7 government websites. We find that approximately 85% of web resources loaded by G7 government sites originate from the United States. By reviewing policy documents and surveying technicians who maintain government websites, we identify four significant forces that can influence the degree of a government's autonomy, including government mandates on HTTPS adoption, website development outsourcing, the citizens' fear of large-scale surveillance, and user confusion. Because a government websites are considered critical information infrastructures, we expect this study to raise awareness of their complex dependency, thereby reducing the risk of blindly trusting external entities when using critical government services. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Yu-Ming Ku, Chun-Ming Chang, Hung-Fang Chen, Chun-Wen Wang, Wei Jeng |
WWW | 1 |
| 2019 | SafeChain: Securing Trigger-Action Programming From Attack ChainsabstractThe proliferation of the Internet of Things (IoT) is reshaping our lifestyle. With IoT sensors and devices communicating with each other via the Internet, people can customize automation rules to meet their needs. Unless carefully defined, however, such rules can easily become points of security failure as the number of devices and complexity of rules increase. Device owners may end up unintentionally providing access or revealing private information to unauthorized entities due to complex chain reactions among devices. Prior work on trigger-action programming either focuses on conflict resolution or usability issues or fails to accurately and efficiently detect such attack chains. This paper explores the security vulnerabilities when users have the freedom to customize automation rules using trigger-action programming. We define two broad classes of attack-privilege escalation and privacy leakage -and present a practical model-checking-based system called SafeChain that detects hidden attack chains exploiting the combination of rules. Built upon existing model-checking techniques, SafeChain identifies attack chains by modeling the IoT ecosystem as a finite-state machine. To improve practicability, SafeChain avoids the need to accurately model an environment by frequently rechecking the automation rules given the current states and employs rule-aware optimizations to further reduce overhead. Our comparative analysis shows that SafeChain can efficiently and accurately identify attack chains, and our prototype implementation of SafeChain can verify 100 rules in less than 1 s with no false positives. Kai-Hsiang Hsu, Yu-Hsi Chiang, Hsu-Chun Hsiao |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | CLEF: Limiting the Damage Caused by Large Flows in the Internet Core
Hao Wu 0018, Hsu-Chun Hsiao, Daniele Enrico Asoni, Simon Scherrer, Adrian Perrig, Yih-Chun Hu |
CANS | 2 |
| 2018 | SDNProbe: Lightweight Fault Localization in the Error-Prone EnvironmentabstractProbe-based fault localization identifies potential faulty nodes, which are manually inspected for confirmation. This work explores efficient and accurate fault localization, which is crucial for reducing the manual effort without affecting network functionality. Prior work suffers from either high bandwidth overhead or false detection (i.e., incorrectly attributing good nodes or missing faulty nodes), especially in the presence of multiple or inconsistent faults. We propose SDNProbe, a lightweight SDN application that sends a provably minimized number of probe packets to pinpoint malfunctioning switches. We extend SDNProbe to randomize tested paths and packet headers to further improve the detection accuracy. Using realistic topologies and flow rules, our evaluation results confirm that SDNProbe can rapidly localize faulty switches while reducing the number of required test packets by 30%, compared to prior approaches. Even with 50% of switches being faulty, the extended SDNProbe can detect all faulty switches in 33 seconds, whereas prior approaches have false negative rates of 15-40%. Yu-Ming Ke, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim |
ICDCS | 2 |
| 2018 | DAMUP: Practical and privacy-aware cloud-based DDoS mitigationabstractCloud-based DDoS mitigation techniques have been widely deployed. However, existing approaches severely violate user privacy as they intercept HTTPS to uncover non-volumetric attacks. This paper presents DAMUP, DDoS Attack Mitigation Upholding Privacy. DAMUP is a practical and privacy-aware solution that empowers the cloud to blindly filter encrypted traffic while remaining deployable on the current Internet. The main idea underlying DAMUP is to encode the server's filtering policy, e.g., client's priority level or rate limit, into cryptographic tokens that can be stapled to an encrypted connection and be efficiently verified by the cloud. DAMUP is designed to be deployable on the current Internet because it requires no modification to the Internet architecture. For example, DAMUP leverages the Server Name Indication field in the TLS handshake to exchange tokens, and uses SOCKS proxy to override DNS. Our evaluation shows that DAMUP can significantly improve the connection success rate from 11.4% to 99.8% under HTTP(S) floods. Su-Chin Lin, Po-Wei Huang, Hsin-Yi Wang, Hsu-Chun Hsiao |
NOMS | 4 |
| 2018 | GroupIt: Lightweight Group Key Management for Dynamic IoT EnvironmentsabstractWith the proliferation of Internet of Things (IoT) devices that collect sensitive data, access control is more crucial than ever to safeguard IoT data from unauthorized use. To enforce access control policies without trusted online entity, one promising approach is to maintain a group key shared between a device and its current subscribers, such that the device can encrypt its data and only the subscribers can decrypt it. However, prior group key management (GKM) schemes fail to efficiently address new challenges introduced by the massive scale of IoT devices, dynamic memberships of users, and changes in the number of devices. This paper explores efficient GKM to accommodate multiple devices (in addition to multiple users) and to handle frequent membership and device number changes. Inspired by the observation that devices with similar functionalities often have similar access permissions, we propose a two-tier GKM architecture called GroupIt, in which each device is assigned to one of many predefined groups, and key management is performed within each group as well as between groups to improve efficiency. Despite being conceptually simple, GroupIt addresses technical challenges including: 1) preventing a malicious device from obtaining extra information about other devices in the same group and 2) ensuring forward/backward secrecy and preventing collusion attacks when gluing two existing GKMs together. The probability of a successful collusion attack quickly drops to 0.3% after five membership changes even in a small device group (e.g., 8). This paper provides both theoretical analysis and a proof-of-concept implementation based on Alljoyn, an opensource IoT communication framework to demonstrate the feasibility of GroupIt. Yi-Hsuan Kung, Hsu-Chun Hsiao |
IEEE Internet Things J. | 2 |
| 2017 | Security Implications of Redirection Trail in Popular Websites WorldwideabstractURL redirection is a popular technique that automatically navigates users to an intended destination webpage with- out user awareness. However, such a seemingly advantageous feature may offer inadequate protection from security vulnerabilities unless every redirection is performed over HTTPS. Even worse, as long as the final redirection to a website is performed over HTTPS, the browser's URL bar indicates that the website is secure regardless of the security of prior redirections, which may provide users with a false sense of security. This paper reports a well-rounded investigation to analyze the wellness of URL redirection security. As an initial large-scale investigation, we screened the integrity and consistency of URL redirections for the Alexa top one million (1M) websites, and further examined 10,000 (10K) websites with their login features. Our results suggest that 1) the majority (83.3% in the 1M dataset and 78.6% in the 10K dataset) of redirection trails among web- sites that support only HTTPS are vulnerable to attacks, and 2) current incoherent practices (e.g., naked domains and www subdomains being redirected to different destinations with varying security levels) undermine the security guarantees provided by HTTPS and HSTS. Li Chang, Hsu-Chun Hsiao, Wei Jeng, Tiffany Hyun-Jin Kim, Wei-Hsi Lin |
WWW | 2 |
| 2016 | CICADAS: Congesting the Internet with Coordinated and Decentralized Pulsating AttacksabstractThis study stems from the premise that we need to break away from the "reactive" cycle of developing defenses against new DDoS attacks (e.g., amplification) by proactively investigating the potential for new types of DDoS attacks. Our specific focus is on pulsating attacks, a particularly debilitating type that has been hypothesized in the literature. In a pulsating attack, bots coordinate to generate intermittent pulses at target links to significantly reduce the throughput of TCP connections traversing the target. With pulsating attacks, attackers can cause significantly greater damage to legitimate users than traditional link flooding attacks. To date, however, pulsating attacks have been either deemed ineffective or easily defendable for two reasons: (1) they require a central coordinator and can thus be tracked; and (2) they require tight synchronization of pulses, which is difficult even in normal non-congestion scenarios. This paper argues that, in fact, the perceived drawbacks of pulsating attacks are in fact not fundamental. We develop a practical pulsating attack called CICADAS using two key ideas: using both (1) congestion as an implicit signal for decentralized implementation, and (2) a Kalman-filter-based approach to achieve tight synchronization. We validate CICADAS using simulations and wide-area experiments. We also discuss possible countermeasures against this attack. Yu-Ming Ke, Chih-Wei Chen, Hsu-Chun Hsiao, Adrian Perrig, Vyas Sekar |
AsiaCCS | 3 |
| 2016 | SIBRA: Scalable Internet Bandwidth Reservation Architecture
Cristina Basescu, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig, Hsu-Chun Hsiao, Ayumu Kubota, Junpei Urakawa |
NDSS | 6 |
| 2015 | A Practical System for Guaranteed Access in the Presence of DDoS Attacks and Flash CrowdsabstractWith the growing incidents of flash crowds and sophisticated DDoS attacks mimicking benign traffic, it becomes challenging to protect Internet-based services solely by differentiating attack traffic from legitimate traffic. While fair-sharing schemes are commonly suggested as a defense when differentiation is difficult, they alone may suffer from highly variable or even unbounded waiting times. We propose RainCheck Filter (RCF), a lightweight primitive that guarantees bounded waiting time for clients despite server flooding without keeping per-client state on the server. RCF achieves strong waiting time guarantees by prioritizing clients based on how long the clients have waited - as if the server maintained a queue in which the clients lined up waiting for service. To avoid keeping state for every incoming client request, the server sends to the client a raincheck, a timestamped cryptographic token that not only informs the client to retry later but also serves as a proof of the client's priority level within the virtual queue. We prove that every client complying with RCF can access the server in bounded time, even under a flash crowd incident or a DDoS attack. Our large-scale simulations confirm that RCF provides a small and predictable maximum waiting time while existing schemes cannot. To demonstrate its deployability, we implement RCF as a Python module such that web developers can protect a critical server resource by adding only three lines of code. Yi-Hsuan Kung, Taeho Lee 0003, Po-Ning Tseng, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Soo Bum Lee, Yue-Hsun Lin, Adrian Perrig |
ICNP | 4 |
| 2014 | YourPassword: applying feedback loops to improve security behavior of managing multiple passwordsabstractVarious mechanisms exist to secure users' passwords, yet users continue to struggle with the complexity of multiple password management. We explore the effectiveness of a feedback loop to improve users' password management. We introduce YourPassword, a web-based application that uses feedback to inform users about the security of their password behavior. YourPassword has two main components: a password behavior checker that converts password strengths into numerical scores and a dashboard interface that visualizes users' overall password behavior and provides visual feedback in real time. YourPassword not only provides a total score on all passwords, but also visualizes when passwords are too similar to each other. To test the efficacy of YourPassword, we conducted a between-subjects experiment and think-aloud test with 48 participants. Participants either had access to YourPassword, an existing commercial password checker, or no password tool (control condition). YourPassword helped participants improve their password behavior as compared with the commercial tool or no tool. Tiffany Hyun-Jin Kim, H. Colleen Stuart, Hsu-Chun Hsiao, Yue-Hsun Lin, Leon Zhang, Laura A. Dabbish, Sara B. Kiesler |
AsiaCCS | 3 |
| 2014 | Efficient Large Flow Detection over Arbitrary Windows: An Algorithm Exact Outside an Ambiguity RegionabstractMany networking and security applications can benefit from exact detection of large flows over arbitrary windows (i.e. any possible time window). Existing large flow detectors that only check the average throughput over certain time period cannot detect bursty flows and are therefore easily fooled by attackers. However, no scalable approaches provide exact classification in one pass. To address this challenge, we consider a new model of exactness outside an ambiguity region, which is defined to be a range of bandwidths below a high-bandwidth threshold and above a low-bandwidth threshold. Given this new model, we propose a deterministic algorithm, EARDet, that detects all large flows (including bursty flows) and avoids false accusation against any small flows, regardless of the input traffic distribution. EARDet monitors flows over arbitrary time windows and is built on a frequent items finding algorithm based on average frequency. Despite its strong properties, EARDet has low storage overhead regardless of input traffic and is surprisingly scalable because it focuses on accurate classification of large flows and small flows only. Our evaluations confirm that existing approaches suffer from high error rates (e.g., misclassifying 1% of small flows as large flows) in the presence of large flows and bursty flows, whereas EARDet can accurately detect both at gigabit line rate using a small amount of memory that fits into on-chip SRAM. Hao Wu 0018, Hsu-Chun Hsiao, Yih-Chun Hu |
Internet Measurement Conference | 2 |
| 2013 | Policy-based secure deletionabstractSecurely deleting data from storage systems has become difficult today. Most storage space is provided as a virtual resource and traverses many layers between the user and the actual physical storage medium. Operations to properly erase data and wipe out all its traces are typically not foreseen, particularly not in networked and cloud-storage systems. This paper introduces a general cryptographic model for policy-based secure deletion of data in storage systems, whose security relies on the proper erasure of cryptographic keys. Deletion operations are expressed in terms of a policy that describes data destruction through deletion attributes and protection classes. The policy links attributes as specified in deletion operations to the protection class(es) that must be erased accordingly. A cryptographic construction is presented for deletion policies given by directed acyclic graphs; it is built in a modular way from exploiting that secure deletion schemes may be composed with each other. The model and the construction unify and generalize all previous encryption-based techniques for secure deletion. Finally, the paper describes a prototype implementation of a Linux filesystem with policy-based secure deletion. Christian Cachin, Kristiyan Haralambiev, Hsu-Chun Hsiao, Alessandro Sorniotti |
CCS | 3 |
| 2013 | STRIDE: sanctuary trail - refuge from internet DDoS entrapmentabstractWe propose STRIDE, a new DDoS-resilient Internet architecture that isolates attack traffic through viable bandwidth allocation, preventing a botnet from crowding out legitimate flows. This new architecture presents several novel concepts including tree-based bandwidth allocation and long-term static paths with guaranteed bandwidth. In concert, these mechanisms provide domain-based bandwidth guarantees within a trust domain - administrative domains grouped within a legal jurisdiction with enforceable accountability; each administrative domain in the trust domain can then internally split such guarantees among its endhosts to provide (1) connection establishment with high probability, and (2) precise bandwidth guarantees for established flows, regardless of the size or distribution of the botnet outside the source and the destination domains. Moreover, STRIDE maintains no per-flow state on backbone routers and requires no key establishment across administrative domains. We demonstrate that STRIDE achieves these DDoS defense properties through formal analysis and simulation. We also show that STRIDE mitigates emerging DDoS threats such as Denial-of-Capability (DoC) [6] and N2 attacks [22] based on these properties that none of the existing DDoS defense mechanisms can achieve. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Sangjae Yoo, Xin Zhang 0003, Soo Bum Lee, Virgil D. Gligor, Adrian Perrig |
AsiaCCS | 1 |
| 2012 | ShortMAC: Efficient Data-Plane Fault Localization
Xin Zhang 0003, Zongwei Zhou, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Patrick Tague |
NDSS | 3 |
| 2012 | LAP: Lightweight Anonymity and PrivacyabstractPopular anonymous communication systems often require sending packets through a sequence of relays on dilated paths for strong anonymity protection. As a result, increased end-to-end latency renders such systems inadequate for the majority of Internet users who seek an intermediate level of anonymity protection while using latency-sensitive applications, such as Web applications. This paper serves to bridge the gap between communication systems that provide strong anonymity protection but with intolerable latency and non-anonymous communication systems by considering a new design space for the setting. More specifically, we explore how to achieve near-optimal latency while achieving an intermediate level of anonymity with a weaker yet practical adversary model (i.e., protecting an end-host's identity and location from servers) such that users can choose between the level of anonymity and usability. We propose Lightweight Anonymity and Privacy (LAP), an efficient network-based solution featuring lightweight path establishment and stateless communication, by concealing an end-host's topological location to enhance anonymity against remote tracking. To show practicality, we demonstrate that LAP can work on top of the current Internet and proposed future Internet architectures. Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Akira Yamada 0001, Samuel C. Nelson, Marco Gruteser, Wei Meng 0001 |
IEEE Symposium on Security and Privacy | 1 |
| 2011 | Flooding-resilient broadcast authentication for VANETsabstractDigital signatures are one of the fundamental security primitives in Vehicular Ad-Hoc Networks (VANETs) because they provide authenticity and non-repudiation in broadcast communication. However, the current broadcast authentication standard in VANETs is vulnerable to signature flooding: excessive signature verification requests that exhaust the computational resources of victims. In this paper, we propose two efficient broadcast authentication schemes, Fast Authentication (FastAuth) and Selective Authentication (SelAuth), as two countermeasures to signature flooding. FastAuth secures periodic single-hop beacon messages. By exploiting the sender's ability to predict its own future beacons, FastAuth enables 50 times faster verification than previous mechanisms using the Elliptic Curve Digital Signature Algorithm. SelAuth secures multi-hop applications in which a bogus signature may spread out quickly and impact a significant number of vehicles. SelAuth pro- vides fast isolation of malicious senders, even under a dynamic topology, while consuming only 15%--30% of the computational resources compared to other schemes. We provide both analytical and experimental evaluations based on real traffic traces and NS-2 simulations. With the near-term deployment plans of VANET on all vehicles, our approaches can make VANETs practical. Hsu-Chun Hsiao, Ahren Studer, Chen Chen 0013, Adrian Perrig, Fan Bai 0002, Bhargav Bellur, Aravind Iyer |
MobiCom | 1 |
| 2011 | SCION: Scalability, Control, and Isolation on Next-Generation NetworksabstractWe present the first Internet architecture designed to provide route control, failure isolation, and explicit trust information for end-to-end communications. SCION separates ASes into groups of independent routing sub-planes, called trust domains, which then interconnect to form complete routes. Trust domains provide natural isolation of routing failures and human misconfiguration, give endpoints strong control for both inbound and outbound traffic, provide meaningful and enforceable trust, and enable scalable routing updates with high path freshness. As a result, our architecture provides strong resilience and security properties as an intrinsic consequence of good design principles, avoiding piecemeal add-on protocols as security patches. Meanwhile, SCION only assumes that a few top-tier ISPs in the trust domain are trusted for providing reliable end-to-end communications, thus achieving a small Trusted Computing Base. Both our security analysis and evaluation results show that SCION naturally prevents numerous attacks and provides a high level of resilience, scalability, control, and isolation. Xin Zhang 0003, Hsu-Chun Hsiao, Geoffrey Hasker, Haowen Chan, Adrian Perrig, David G. Andersen |
IEEE Symposium on Security and Privacy | 2 |
| 2011 | Efficient and secure threshold-based event validation for VANETsabstractDetermining whether the number of vehicles reporting an event is above a threshold is an important mechanism for VANETs, because many applications rely on a threshold number of notifications to reach agreement among vehicles, to determine the validity of an event, or to prevent the abuse of emergency alarms. We present the first efficient and secure threshold-based event validation protocol for VANETs. Quite counter-intuitively, we found that the z-smallest approach [3] offers the best tradeoff between security and efficiency since other approaches perform better for probabilistic counting. Analysis and simulation shows that our protocol provides > 99% accuracy despite the presence of attackers, collection and distribution of alerts in less than 1 second, and negligible impact on network performance. Hsu-Chun Hsiao, Ahren Studer, Rituik Dubey, Elaine Shi, Adrian Perrig |
WISEC | 1 |
| 2010 | SPATE: Small-Group PKI-Less Authenticated Trust EstablishmentabstractEstablishing trust between a group of individuals remains a difficult problem. Prior works assume trusted infrastructure, require an individual to trust unknown entities, or provide relatively low probabilistic guarantees of authenticity (95 percent for realistic settings). This work presents SPATE, a primitive that allows users to establish trust via mobile devices and physical interaction. Once the SPATE protocol runs to completion, its participants' mobile devices have authentic data that their applications can use to interact securely (i.e., the probability of a successful attack is 2-24). For this work, we leverage SPATE as part of a larger system to facilitate efficient, secure, and user-friendly collaboration via e-mail, file-sharing, and text messaging services. Our implementation of SPATE on Nokia N70 smartphones allows users to establish trust in small groups of up to eight users in less than one minute. The example SPATE applications provide increased security with little overhead noticeable to users once keys are established. Yue-Hsun Lin, Ahren Studer, Yao-Hsin Chen, Hsu-Chun Hsiao, Eric Li-Hsiang Kuo, Jonathan M. McCune, King-Hang Wang, Maxwell N. Krohn, Adrian Perrig, Bo-Yin Yang, Phen-Lan Lin |
IEEE Trans. Mob. Comput. | 4 |
| 2009 | A Study of User-Friendly Hash Comparison SchemesabstractSeveral security protocols require a human to compare two hash values to ensure successful completion. When the hash values are represented as long sequences of numbers, humans may make a mistake or require significant time and patience to accurately compare the hash values. To improve usability during comparison, a number of researchers have proposed various hash representations that use words, sentences, or images rather than numbers. This is the first work to perform a comparative study of these hash comparison schemes to determine which scheme allows the fastest and most accurate comparison. To evaluate the schemes, we performed an online user study with more than 400 participants. Our findings indicate that only a small number of schemes allow quick and accurate comparison across a wide range of subjects from varying backgrounds. Hsu-Chun Hsiao, Yue-Hsun Lin, Ahren Studer, Cassandra Studer, King-Hang Wang, Hiroaki Kikuchi, Adrian Perrig, Bo-Yin Yang |
ACSAC | 1 |
| 2009 | SPATE: small-group PKI-less authenticated trust establishmentabstractEstablishing trust between a group of individuals remains a difficult problem. Prior works assume trusted infrastructure, require an individual to trust unknown entities, or provide relatively low probabilistic guarantees of authenticity (95% for realistic settings). This work presents SPATE, a primitive that allows users to establish trust via device mobility and physical interaction. Once the SPATE protocol runs to completion, its participants' mobile devices have authentic data that their applications can use to interact securely (i.e., the probability of a successful attack is 2-24). For this work, we leverage SPATE as part of a larger system to facilitate efficient, secure, and user-friendly collaboration via email and file-sharing services. Our implementation of SPATE on Nokia N70 smartphones allows users to establish trust in small groups of up to eight users in less than one minute. The two example SPATE applications provide increased security with no overhead noticeable to users once keys are established. Yue-Hsun Lin, Ahren Studer, Hsu-Chun Hsiao, Jonathan M. McCune, King-Hang Wang, Maxwell N. Krohn, Phen-Lan Lin, Adrian Perrig, Bo-Yin Yang |
MobiSys | 3 |