EDBT 2026 Demo / reviewers in the wild / expert
Craig A. Shue
dblp:66/5330
· DBLP profile ↗
31ranked-venue papers
7as first author
10since 2021 · last 2026
0000-0003-1012-3576ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 7 first-author · 2 since 2021Security and privacy · 8 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bringing Your Own Privacy: Towards Measurable Privacy in Mobile Device Management and Security
Shuwen Liu 0009, Craig A. Shue |
DSN | 2 |
| 2026 | See, Record, Do: Automated Generation of UI Workflows from Tutorial Videos
Adam Beauchaine, Craig A. Shue |
WACV | 2 |
| 2025 | Making (Only) the Right Calls: Preventing Remote Code Execution Attacks in PHP Applications with Contextual, State-Sensitive System Call Filtering
Yunsen Lei, Craig A. Shue |
DIMVA (1) | 2 |
| 2025 | Functional Control: Leveraging Function-as-a-Service Platforms for Software-Defined Networking ControllersabstractThe function-as-a-service (FaaS) paradigm, often called "serverless computing," allows computing providers to scalably perform short-lived computational tasks at low cost. While the benefits of FaaS have been demonstrated for ephemeral computational tasks, the research community has not fully explored the applicability of FaaS platforms for longer-term, periodic tasks, like network controllers. Shuwen Liu 0009, Craig A. Shue |
MobiHoc | 2 |
| 2025 | Mobile SDNs: Associating End-User Commands with Network Flows in Android DevicesabstractABSTRACT Mobile devices pose several distinct challenges from a security perspective. First, they have varied and ephemeral network connections, often using a cellular provider network as a backup option when connectivity is not available via wireless local access networks. This varied network connectivity makes it difficult to comprehensively deploy in‐network solutions, such as firewalls or intrusion detection systems, since they would have to be active in every network the device would use. Second, with personally owned devices, the device owner may have security goals and privacy priorities that are distinct from organizations that provide connectivity or data assets, such as employers or schools. These complex relationships may complicate efforts to protect the devices. This paper explores a technique that runs on the mobile device endpoints to learn about the usage patterns associated with the device, in order to enforce network policy. We explore sensors that examine the mobile device's user interface, using physical inputs via finger taps, and that link them with the network activity on the device. We incorporate with allow‐list policies that can be provided by organizations to make on‐device access control decisions. Using IP address and DNS host name allow‐lists as a baseline, we explore the accuracy of interface‐aware allow‐lists. We find the interface‐aware allow‐lists can reach over 98.5% accuracy, even when user‐specified destinations are used, greatly exceeding the baseline accuracy. Our performance evaluation indicates our approach introduces a median of 3.87 ms of overall delay with low CPU usage. Shuwen Liu 0009, Craig A. Shue, Joseph P. Petitti, Yunsen Lei |
IET Commun. | 2 |
| 2023 | Attackers as Instructors: Using Container Isolation to Reduce Risk and Understand Vulnerabilities
Yunsen Lei, Julian P. Lanson, Craig A. Shue, Timothy W. Wood |
DIMVA | 3 |
| 2023 | Inspecting Traffic in Residential Networks with Opportunistically Outsourced MiddleboxesabstractHome networks lack the powerful security tools and trained personnel available in enterprise networks. This complicates efforts to address security risks in residential settings. While prior efforts explore outsourcing network traffic to cloud or cloudlet services, such an approach exposes that network traffic to a third party, which introduces privacy risks, particularly where traffic is decrypted (e.g., using Transport Layer Security Inspection (TLSI)). To enable security screening locally, home networks could introduce new physical hardware, but the capital and deployment costs may impede deployment. In this work, we explore a system to leverage existing available devices, such as smartphones, tablets and laptops, already inside a home network to create a platform for traffic inspection. This software-based solution avoids new hardware deployment and allows decryption of traffic without risk of new third parties. Our investigation compares on-router inspection of traffic with an approach using that same router to direct traffic through smartphones in the local network. Our performance evaluation shows that smartphone middleboxes can substantially increase the throughput of communication from around 10 Mbps in the on-router case to around 90 Mbps when smartphones are used. This approach increases CPU usage at the router by around 15%, with a 20% CPU usage increase on a smartphone (with single core processing). The network packet latency increases by about 120 milliseconds. Shuwen Liu 0009, Craig A. Shue |
NOMS | 3 |
| 2022 | Exploring Phone-Based Authentication Vulnerabilities in Single Sign-On Systems
Matthew M. Tolbert, Elie M. Hess, Mattheus C. Nascimento, Yunsen Lei, Craig A. Shue |
ICICS | 5 |
| 2022 | Visualizing Web Application Execution Logs to Improve Software Security Defect LocalizationabstractInteractive web-based applications play an important role for both service providers and consumers. However, web applications tend to be complex, produce high-volume data, and are often ripe for attack. Attack analysis and remediation are complicated by adversary obfuscation and the difficulty in assembling and analyzing logs. In this work, we explore the web application analysis task through log file fusion, distillation, and visualization. Our approach consists of visualizing the logs of web and database traffic with detailed function execution traces. We establish causal links between events and their associated behaviors. We evaluate the effectiveness of this process using data volume reduction statistics, user interaction models, and usage scenarios. Across a set of scenarios, we find that our techniques can filter at least 97.5% of log data and reduce analysis time by 93–96%. Matthew A. Puentes, Yunsen Lei, Noëlle Rakotondravony, Lane Harrison, Craig A. Shue |
SANER | 5 |
| 2021 | Avoiding VPN Bottlenecks: Exploring Network-Level Client Identity Validation Options
Craig A. Shue |
QSHINE | 2 |
| 2020 | Beyond the VPN: Practical Client Identity in an Internet with Widespread IP Address SharingabstractTo support remote employees, organizations often use virtual private networks (VPNs) to provide confidential and authenticated tunnels between the organization's networks and the employees' systems. With widespread end-to-end application-layer encryption and authentication, the cryptographic features of VPNs are often redundant. However, many organizations still rely upon VPNs. We examine the motivations and limitations associated with VPNs and find that VPNs are often used to simplify access control and filtering for enterprise services.To avoid limitations associated with VPNs, we propose an approach that allows straightforward filtering. Our approach provides evidence a remote user belongs in a network, despite the address sharing present in tools like Carrier-Grade Network Address Translation. We preserve simple access control and eliminate the need for VPN servers, redundant cryptography, and VPN packet headers overheads. The approach is incrementally deployable and provides a second factor for authenticating users and systems while minimizing performance overheads. Craig A. Shue |
LCN | 2 |
| 2020 | Community Cleanup: Incentivizing Network Hygiene via Distributed Attack ReportingabstractResidential networks are difficult to secure due to resource constraints and lack of local security expertise. These networks primarily use consumer-grade routers that lack meaningful security mechanisms, providing a safe-haven for adversaries to launch attacks, including damaging distributed denial-of-service (DDoS) attacks. Prior efforts have suggested outsourcing residential network security to experts, but motivating user adoption has been a challenge. This work explores combining residential SDN techniques with prior work on collaborative DDoS reporting to identify residential network compromises. This combination provides incentives for end-users to deploy the technique, including rapid notification of compromises on their own devices and reduced upstream bandwidth consumption, while incurring minimal performance overheads. Craig A. Shue |
NOMS | 2 |
| 2019 | Control-Flow Integrity for Real-Time Embedded SystemsabstractAttacks on real-time embedded systems can endanger lives and critical infrastructure. Despite this, techniques for securing embedded systems software have not been widely studied. Many existing security techniques for general-purpose computers rely on assumptions that do not hold in the embedded case. This paper focuses on one such technique, control-flow integrity (CFI), that has been vetted as an effective countermeasure against control-flow hijacking attacks on general-purpose computing systems. Without the process isolation and fine-grained memory protections provided by a general-purpose computer with a rich operating system, CFI cannot provide any security guarantees. This work proposes RECFISH, a system for providing CFI guarantees on ARM Cortex-R devices running minimal real-time operating systems. We provide techniques for protecting runtime structures, isolating processes, and instrumenting compiled ARM binaries with CFI protection. We empirically evaluate RECFISH and its performance implications for real-time systems. Our results suggest RECFISH can be directly applied to binaries without compromising real-time performance; in a test of over six million realistic task systems running FreeRTOS, 85% were still schedulable after adding RECFISH. Robert J. Walls, Nicholas F. Brown, Thomas Le Baron, Craig A. Shue, Hamed Okhravi, Bryan C. Ward |
ECRTS | 4 |
| 2019 | Detecting Root-Level Endpoint Sensor Compromises with Correlated Activity
Yunsen Lei, Craig A. Shue |
SecureComm (2) | 2 |
| 2019 | Account Lockouts: Characterizing and Preventing Account Denial-of-Service Attacks
Matthew R. Squires, Curtis R. Taylor, Robert J. Walls, Craig A. Shue |
SecureComm (2) | 5 |
| 2017 | DeepContext: An OpenFlow-Compatible, Host-Based SDN for Enterprise NetworksabstractThe software-defined networking (SDN) paradigm promises greater control and understanding of enterprise network activities, particularly for management applications that need awareness of network-wide behavior. However, the current focus on switch-based SDNs raises concerns about data-plane scalability, especially when using fine-grained flows. Further, these switch-centric approaches lack visibility into end-host and application behaviors, which are valuable when making access control decisions.In recent work, we proposed a host-based SDN in which we installed software on the end-hosts and used a centralized network control to manage the flows. This improve scalability and provided application information for use in network policy. However, that approach was not compatible with OpenFlow and had provided only conservative estimates of possible network performance.In this work, we create a high performance host-based SDN that is compatible with the OpenFlow protocol. Our approach, DeepContext, provides details about the application context to the network controller, allowing enhanced decision-making. We evaluate the performance of DeepContext, comparing it to traditional networks and Open vSwitch deployments. We further characterize the completeness of the data provided by the system and the resulting benefits. Mohamed E. Najd, Craig A. Shue |
LCN | 2 |
| 2017 | The best bang for the byte: Characterizing the potential of DNS amplification attacks
Douglas C. MacFarland, Craig A. Shue, Andrew J. Kalafut |
Comput. Networks | 2 |
| 2016 | Whole home proxies: Bringing enterprise-grade security to residential networksabstractWhile enterprise networks follow best practices and security measures, residential networks often lack these protections. Home networks have constrained resources and lack a dedicated IT staff that can secure and manage the network and systems. At the same time, homes must tackle the same challenges of securing heterogeneous devices when communicating to the Internet. In this work, we explore combining software-defined networking and proxies with commodity residential Internet routers. We evaluate a “whole home” proxy solution for the Skype video conferencing application to determine the viability of the approach in practice. We find that we are able to automatically detect when a device is about to use Skype and dynamically intercept all of the Skype communication and route it through a proxy while not disturbing unrelated network flows. Our approach works across multiple operating systems, form factors, and versions of Skype. Curtis R. Taylor, Craig A. Shue, Mohamed E. Najd |
ICC | 2 |
| 2016 | Contextual, flow-based access control with scalable host-based SDN techniquesabstractNetwork operators can better understand their networks when armed with a detailed understanding of the network traffic and host activities. Software-defined networking (SDN) techniques have the potential to improve enterprise security, but the current techniques have well-known data plane scalability concerns and limited visibility into the host's operating context. In this work, we provide both detailed host-based context and fine-grained control of network flows by shifting the SDN agent functionality from the network infrastructure into the end-hosts. We allow network operators to write detailed network policy that can discriminate based on user and program information associated with network flows. In doing so, we find our approach scales far beyond the capabilities of OpenFlow switching hardware, allowing each host to create over 25 new flows per second with no practical bound on the number of established flows in the network. Curtis R. Taylor, Douglas C. MacFarland, Doran R. Smestad, Craig A. Shue |
INFOCOM | 4 |
| 2015 | Characterizing Optimal DNS Amplification Attacks and Effective Mitigation
Douglas C. MacFarland, Craig A. Shue, Andrew J. Kalafut |
PAM | 2 |
| 2013 | Resolvers Revealed: Characterizing DNS Resolvers and their ClientsabstractThe Domain Name System (DNS) allows clients to use resolvers, sometimes called caches, to query a set of authoritative servers to translate host names into IP addresses. Prior work has proposed using the interaction between these DNS resolvers and the authoritative servers as an access control mechanism. However, while prior work has examined the DNS from many angles, the resolver component has received little scrutiny. Essential factors for using a resolver in an access control system, such as whether a resolver is part of an ISP’s infrastructure or running on an end-user’s system, have not been examined. In this study, we examine DNS resolver behavior and usage, from query patterns and reactions to nonstandard responses to passive association techniques to pair resolvers with their client hosts. In doing so, we discover evidence of security protocol support, misconfigured resolvers, techniques to fingerprint resolvers, and features for detecting automated clients. These measurements can influence the implementation and design of these resolvers and DNS-based access control systems. Craig A. Shue, Andrew J. Kalafut |
ACM Trans. Internet Techn. | 1 |
| 2012 | Understanding new anonymity networks from a user's perspectiveabstractAnonymity networks have been studied for decades, from both theoretical and practical perspectives. Several anonymity systems, such as Tor and Java Anon Proxy (JAP), have become popular enough for general Internet users. However, both noticeably constrain the performance of a user's network and are considered too complicated for some users. A new anonymity service, SurfEasy, has created a physical device that purports to provide easy, high performance anonymous network usage. However, the service does not readily describe the anonymity system it uses. In this work, we examine Tor, JAP, and SurfEasy from a performance and end-user perspective to characterize the tradeoffs in these systems and to provide a guide for analyzing future anonymity systems. In doing so, we find that SurfEasy does indeed offer better browsing performance in some cases, but at the cost of robust anonymity. Érik Archambault, Craig A. Shue |
CCS | 2 |
| 2012 | Abnormally Malicious Autonomous Systems and Their Internet ConnectivityabstractWhile many attacks are distributed across botnets, investigators and network operators have recently identified malicious networks through high profile autonomous system (AS) depeerings and network shutdowns. In this paper, we explore whether some ASs indeed are safe havens for malicious activity. We look for ISPs and ASs that exhibit disproportionately high malicious behavior using 10 popular blacklists, plus local spam data, and extensive DNS resolutions based on the contents of the blacklists. We find that some ASs have over 80% of their routable IP address space blacklisted. Yet others account for large fractions of blacklisted IP addresses. Several ASs regularly peer with ASs associated with significant malicious activity. We also find that malicious ASs as a whole differ from benign ones in other properties not obviously related to their malicious activities, such as more frequent connectivity changes with their BGP peers. Overall, we conclude that examining malicious activity at AS granularity can unearth networks with lax security or those that harbor cybercrime. Craig A. Shue, Andrew J. Kalafut, Minaxi Gupta 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2011 | Touring DNS Open Houses for Trends and ConfigurationsabstractThe Domain Name System (DNS) is a critical component of the Internet. It maps domain names to IP addresses and serves as a distributed database for various other applications, including mail, Web, and spam filtering. This paper examines DNS zones in the Internet for diversity, adoption rates of new technologies, and prevalence of configuration issues. To gather data, we sweep 60% of the Internet's domains in June-August 2007 for zone transfers. Of them, 6.6% allow us to transfer their complete information. Surprisingly, this includes a large fraction of the domains deploying DNS security extensions (DNSSEC). We find that DNS zones vary significantly in size and some span many autonomous systems. Also, while anti-spam technologies appear to be getting deployed, the adoption rates of DNSSEC and IPv6 continue to be low. Finally, we also find that carelessness in handing DNS records can lead to reduced availability of name servers, e-mail, and Web servers. This also undermines anti-spam efforts and the efforts to shut down phishing sites or to contain malware infections. Andrew J. Kalafut, Craig A. Shue, Minaxi Gupta 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2010 | Malicious Hubs: Detecting Abnormally Malicious Autonomous SystemsabstractWhile many attacks are distributed across botnets, investigators and network operators have recently targeted malicious networks through high profile autonomous system (AS) de-peerings and network shut-downs. In this paper, we explore whether some ASes indeed are safe havens for malicious activity. We look for ISPs and ASes that exhibit disproportionately high malicious behavior using 12 popular blacklists. We find that some ASes have over 80% of their routable IP address space blacklisted and others account for large fractions of blacklisted IPs. Overall, we conclude that examining malicious activity at the AS granularity can unearth networks with lax security or those that harbor cybercrime. Andrew J. Kalafut, Craig A. Shue, Minaxi Gupta 0001 |
INFOCOM | 2 |
| 2010 | An Internet without the Internet protocol
Craig A. Shue, Minaxi Gupta 0001 |
Comput. Networks | 1 |
| 2009 | Sensitive Data Requests: Do Sites Ask Correctly?abstractTo ensure the security of sensitive Web content, an organization must use TLS and do so correctly. However, little is known about how TLS is actually used on the Web. In this work, we perform large-scale Internet-wide measurements to determine if Web sites use TLS when needed and when they do, if they use it correctly. We find hundreds of thousands of pages where TLS is either not used when it should be or is used improperly, putting sensitive data at risk. Craig A. Shue, Minaxi Gupta 0001 |
ICC | 1 |
| 2008 | Understanding implications of DNS zone provisioningabstractDNS is a critical component of the Internet. This paper takes a comprehensive look at the provisioning of Internet domains and its impact on the availability of various services. To gather data, we sweep 60 % of the Internet’s domains for zone transfers. 6.6 % of them allow us to transfer their complete information. We find that carelessness in handling DNS records can lead to reduced availability of name servers, email, and Web servers. It also undermines anti-spam efforts and the efforts to shut down phishing sites or to contain malware infections. Andrew J. Kalafut, Craig A. Shue, Minaxi Gupta 0001 |
Internet Measurement Conference | 2 |
| 2008 | Packet forwarding with source verification
Craig A. Shue, Minaxi Gupta 0001, Matthew P. Davy |
Comput. Networks | 1 |
| 2007 | IPSec: Performance Analysis and EnhancementsabstractAbstract — Internet Protocol Security (IPSec) is a widely deployed mechanism for implementing Virtual Private Networks (VPNs). In previous work, we examined the overheads incurred by an IPSec server in a single client setting. In this paper, we extend that work by examining the scaling of a VPN server in a multiple client environment and by evaluating the effectiveness of connection credential caching. Motivated by the potential benefits of caching, we also propose a cryptographically secure cache resumption protocol for IPSec connections to reduce the connection establishment overheads. I. Craig A. Shue, Minaxi Gupta 0001, Steven Myers |
ICC | 1 |
| 2007 | The web is smaller than it seemsabstractThe Web has grown beyond anybody's imagination. While significant research has been devoted to understanding aspects of the Web from the perspective of the documents that comprise it, we have little data on the relationship among servers that comprise the Web. In this paper, we explore the extent to which Web servers are co-located with other Web servers in the Internet. In terms of the location of servers, we find that the Web is surprisingly smaller than it seems. Our work has important implications for the availability of Web servers in case of DoS attacks and blocklisting. Craig A. Shue, Andrew J. Kalafut, Minaxi Gupta 0001 |
Internet Measurement Conference | 1 |