EDBT 2026 Demo / reviewers in the wild / expert
Alexei Czeskis
dblp:66/625
· DBLP profile ↗
9ranked-venue papers
5as first author
1since 2021 · last 2023
0000-0002-9048-0460ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Usable security · 30% Authentication and access control · 30% Web and mobile security · 18% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Embedded and real-time systems · 100% |
Topics — the 13 heaviest of 17, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cyber-physical and IoT security
automotive security |
0.2 | 2 | 2011 | Comprehensive Experimental Analyses of Automotive Attack Surfaces · USENIX Security Symposium 2011 Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010 |
Authentication and access control › multi-factor authentication
two-factor authentication |
0.1 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Authentication and access control
user authentication |
0.1 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Web and mobile security
web authentication |
0.1 | 1 | 2012 | Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web · USENIX Security Symposium 2012 |
Cyber-physical and IoT security
in-vehicle network security |
0.1 | 1 | 2010 | Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010 |
Authentication and access control › authentication
context-based authentication |
0.1 | 1 | 2008 | RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008 |
Network security › wireless network security
RFID security |
0.1 | 1 | 2008 | RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008 |
Web and mobile security
browser security |
0.0 | 1 | 2013 | Lightweight server support for browser-based CSRF protection · WWW 2013 |
Web and mobile security
phishing resistance |
0.0 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Systems and software security
exploitation |
0.0 | 1 | 2011 | Comprehensive Experimental Analyses of Automotive Attack Surfaces · USENIX Security Symposium 2011 |
Embedded and real-time systems
automotive systems |
0.0 | 1 | 2010 | Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010 |
Embedded and real-time systems
cyber-physical system platforms |
0.0 | 1 | 2010 | Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010 |
Interaction techniques and input › input sensing › gesture recognition
accelerometer-based gesture recognition |
0.0 | 1 | 2008 | RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008 |
Methods — techniques the papers use, named apart from their topics
online study · 0.7dataset analysis · 0.7experimental security analysis · 0.3road tests · 0.2browser extension implementation · 0.2gesture recognition · 0.2accelerometer sensing · 0.2cryptographic protocol design · 0.1certificate-based authentication · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | How Language Formality in Security and Privacy Interfaces Impacts Intended ComplianceabstractStrong end-user security practices benefit both the user and hosting platform, but it is not well understood how companies communicate with their users to encourage these practices. This paper explores whether web companies and their platforms use different levels of language formality in these communications and tests the hypothesis that higher language formality leads to users’ increased intention to comply. We contribute a dataset and systematic analysis of 1,817 English language strings in web security and privacy interfaces across 13 web platforms, showing strong variations in language. An online study with 512 participants further demonstrated that people perceive differences in the language formality across platforms and that a higher language formality is associated with higher self-reported intention to comply. Our findings suggest that formality can be an important factor in designing effective security and privacy prompts. We discuss implications of these results, including how to balance formality with platform language style. In addition to being the first piece of work to analyze language formality in user security, these findings provide valuable insights into how platforms can best communicate with users about account security. Jackson Stokes, Tal August, Robert A Marver, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno, Katharina Reinecke |
CHI | 4 |
| 2013 | Lightweight server support for browser-based CSRF protectionabstractCross-Site Request Forgery (CSRF) attacks are one of the top threats on the web today. These attacks exploit ambient authority in browsers (eg cookies, HTTP authentication state), turning them into confused deputies and causing undesired side effects on vulnerable web sites. Existing defenses against CSRFs fall short in their coverage and/or ease of deployment. In this paper, we present a browser/server solution, Allowed Referrer Lists (ARLs), that addresses the root cause of CSRFs and removes ambient authority for participating web sites that want to be resilient to CSRF attacks. Our solution is easy for web sites to adopt and does not affect any functionality on non-participating sites. We have implemented our design in Firefox and have evaluated it with real-world sites. We found that ARLs successfully block CSRF attacks, are simpler to implement than existing defenses, and do not significantly impact browser performance. Alexei Czeskis, Alexander Moshchuk, Tadayoshi Kohno, Helen J. Wang |
WWW | 1 |
| 2012 | Strengthening user authentication through opportunistic cryptographic identity assertionsabstractUser authentication systems are at an impasse. The most ubiquitous method -- the password -- has numerous problems, including susceptibility to unintentional exposure via phishing and cross-site password reuse. Second-factor authentication schemes have the potential to increase security but face usability and deployability challenges. For example, conventional second-factor schemes change the user authentication experience. Furthermore, while more secure than passwords, second-factor schemes still fail to provide sufficient protection against (single-use) phishing attacks. Alexei Czeskis, Michael Dietz, Tadayoshi Kohno, Dan S. Wallach, Dirk Balfanz |
CCS | 1 |
| 2012 | Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web
Michael Dietz, Alexei Czeskis, Dirk Balfanz, Dan S. Wallach |
USENIX Security Symposium | 2 |
| 2011 | Comprehensive Experimental Analyses of Automotive Attack Surfaces
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno |
USENIX Security Symposium | 8 |
| 2010 | Parenting from the pocket: value tensions and technical directions for secure and private parent-teen mobile safetyabstractAn increasing number of high-tech devices, such as driver monitoring systems and Internet usage monitoring tools, are advertised as useful or even necessary for good parenting of teens. Simultaneously, there is a growing market for mobile personal safety devices. As these trends merge, there will be significant implications for parent-teen relationships, affecting domains such as privacy, trust, and maturation. Not only the teen and his or her parents are affected; other important stakeholders include the teen's friends who may be unwittingly monitored. This problem space, with less clear-cut assets, risks, and affected parties, thus lies well outside of more typical computer security applications.To help understand this problem domain and what, if anything, should be built, we turn to the theory and methods of Value Sensitive Design, a systematic approach to designing for human values in technology. We first develop value scenarios that highlight potential issues, benefits, harms, and challenges. We then conducted semi-structured interviews with 18 participants (9 teens and their parents). Results show significant differences with respect to information about: 1) internal state (e.g., mood) versus external environment (e.g., location) state; 2) situation (e.g., emergency vs. non-emergency); and 3) awareness (e.g., notification vs. non-notification). The value scenario and interview results positioned us to identify key technical challenges -- such as strongly protecting the privacy of a teen's contextual information during ordinary situations but immediately exposing that information to others as appropriate in an emergency -- and corresponding architectural levers for these technologies.In addition to laying a foundation for future work in this area, this research serves as a prototypical example of using Value Sensitive Design to explicate the underlying human values in complex security domains. Alexei Czeskis, Ivayla Dermendjieva, Hussein Yapit, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno |
SOUPS | 1 |
| 2010 | Experimental Security Analysis of a Modern AutomobileabstractModern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks. In this paper we experimentally evaluate these issues on a modern automobile and demonstrate the fragility of the underlying system structure. We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input\dash including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car's two internal subnets. We also present composite attacks that leverage individual weaknesses, including an attack that embeds malicious code in a car's telematics unit and that will completely erase any evidence of its presence after a crash. Looking forward, we discuss the complex challenges in addressing these vulnerabilities while considering the existing automotive ecosystem. Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage |
IEEE Symposium on Security and Privacy | 2 |
| 2008 | RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communicationsabstractWe tackle the problem of defending against ghost-and-leech (a.k.a. proxying, relay, or man-in-the-middle) attacks against RFID tags and other contactless cards. The approach we take -- which we dub secret handshakes -- is to incorporate gesture recognition techniques directly on the RFID tags or contactless cards. These cards will only engage in wireless communications when they internally detect these secret handshakes. We demonstrate the effectiveness of this approach by implementing our secret handshake recognition system on a passive WISP RFID tag with a built-in accelerometer. Our secret handshakes approach is backward compatible with existing deployments of RFID tag and contactless card readers. Alexei Czeskis, Karl Koscher, Joshua R. Smith 0001, Tadayoshi Kohno |
CCS | 1 |
| 2008 | Defeating Encrypted and Deniable File Systems: TrueCrypt v5.1a and the Case of the Tattling OS and Applications
Alexei Czeskis, David J. St. Hilaire, Karl Koscher, Steve D. Gribble, Tadayoshi Kohno, Bruce Schneier |
HotSec | 1 |