Alexei Czeskis

dblp:66/625 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
1since 2021 · last 2023
0000-0002-9048-0460ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
7 papers
Usable security · 30% Authentication and access control · 30% Web and mobile security · 18%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Embedded and real-time systems · 100%

Topics — the 13 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cyber-physical and IoT security
automotive security
0.222011
Comprehensive Experimental Analyses of Automotive Attack Surfaces · USENIX Security Symposium 2011
Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010
Authentication and access control › multi-factor authentication
two-factor authentication
0.112012
Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012
Authentication and access control
user authentication
0.112012
Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012
Web and mobile security
web authentication
0.112012
Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web · USENIX Security Symposium 2012
Cyber-physical and IoT security
in-vehicle network security
0.112010
Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010
Authentication and access control › authentication
context-based authentication
0.112008
RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008
Network security › wireless network security
RFID security
0.112008
RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008
Web and mobile security
browser security
0.012013
Lightweight server support for browser-based CSRF protection · WWW 2013
Web and mobile security
phishing resistance
0.012012
Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012
Systems and software security
exploitation
0.012011
Comprehensive Experimental Analyses of Automotive Attack Surfaces · USENIX Security Symposium 2011
Embedded and real-time systems
automotive systems
0.012010
Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010
Embedded and real-time systems
cyber-physical system platforms
0.012010
Experimental Security Analysis of a Modern Automobile · IEEE Symposium on Security and Privacy 2010
Interaction techniques and input › input sensing › gesture recognition
accelerometer-based gesture recognition
0.012008
RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications · CCS 2008

Methods — techniques the papers use, named apart from their topics

online study · 0.7dataset analysis · 0.7experimental security analysis · 0.3road tests · 0.2browser extension implementation · 0.2gesture recognition · 0.2accelerometer sensing · 0.2cryptographic protocol design · 0.1certificate-based authentication · 0.1
YearPublicationVenuePosition
2023 How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
abstract
Strong end-user security practices benefit both the user and hosting platform, but it is not well understood how companies communicate with their users to encourage these practices. This paper explores whether web companies and their platforms use different levels of language formality in these communications and tests the hypothesis that higher language formality leads to users’ increased intention to comply. We contribute a dataset and systematic analysis of 1,817 English language strings in web security and privacy interfaces across 13 web platforms, showing strong variations in language. An online study with 512 participants further demonstrated that people perceive differences in the language formality across platforms and that a higher language formality is associated with higher self-reported intention to comply. Our findings suggest that formality can be an important factor in designing effective security and privacy prompts. We discuss implications of these results, including how to balance formality with platform language style. In addition to being the first piece of work to analyze language formality in user security, these findings provide valuable insights into how platforms can best communicate with users about account security.
Jackson Stokes, Tal August, Robert A Marver, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno, Katharina Reinecke
CHI4
2013 Lightweight server support for browser-based CSRF protection
abstract
Cross-Site Request Forgery (CSRF) attacks are one of the top threats on the web today. These attacks exploit ambient authority in browsers (eg cookies, HTTP authentication state), turning them into confused deputies and causing undesired side effects on vulnerable web sites. Existing defenses against CSRFs fall short in their coverage and/or ease of deployment. In this paper, we present a browser/server solution, Allowed Referrer Lists (ARLs), that addresses the root cause of CSRFs and removes ambient authority for participating web sites that want to be resilient to CSRF attacks. Our solution is easy for web sites to adopt and does not affect any functionality on non-participating sites. We have implemented our design in Firefox and have evaluated it with real-world sites. We found that ARLs successfully block CSRF attacks, are simpler to implement than existing defenses, and do not significantly impact browser performance.
Alexei Czeskis, Alexander Moshchuk, Tadayoshi Kohno, Helen J. Wang
WWW1
2012 Strengthening user authentication through opportunistic cryptographic identity assertions
abstract
User authentication systems are at an impasse. The most ubiquitous method -- the password -- has numerous problems, including susceptibility to unintentional exposure via phishing and cross-site password reuse. Second-factor authentication schemes have the potential to increase security but face usability and deployability challenges. For example, conventional second-factor schemes change the user authentication experience. Furthermore, while more secure than passwords, second-factor schemes still fail to provide sufficient protection against (single-use) phishing attacks.
Alexei Czeskis, Michael Dietz, Tadayoshi Kohno, Dan S. Wallach, Dirk Balfanz
CCS1
2012 Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web
Michael Dietz, Alexei Czeskis, Dirk Balfanz, Dan S. Wallach
USENIX Security Symposium2
2011 Comprehensive Experimental Analyses of Automotive Attack Surfaces
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno
USENIX Security Symposium8
2010 Parenting from the pocket: value tensions and technical directions for secure and private parent-teen mobile safety
abstract
An increasing number of high-tech devices, such as driver monitoring systems and Internet usage monitoring tools, are advertised as useful or even necessary for good parenting of teens. Simultaneously, there is a growing market for mobile personal safety devices. As these trends merge, there will be significant implications for parent-teen relationships, affecting domains such as privacy, trust, and maturation. Not only the teen and his or her parents are affected; other important stakeholders include the teen's friends who may be unwittingly monitored. This problem space, with less clear-cut assets, risks, and affected parties, thus lies well outside of more typical computer security applications.To help understand this problem domain and what, if anything, should be built, we turn to the theory and methods of Value Sensitive Design, a systematic approach to designing for human values in technology. We first develop value scenarios that highlight potential issues, benefits, harms, and challenges. We then conducted semi-structured interviews with 18 participants (9 teens and their parents). Results show significant differences with respect to information about: 1) internal state (e.g., mood) versus external environment (e.g., location) state; 2) situation (e.g., emergency vs. non-emergency); and 3) awareness (e.g., notification vs. non-notification). The value scenario and interview results positioned us to identify key technical challenges -- such as strongly protecting the privacy of a teen's contextual information during ordinary situations but immediately exposing that information to others as appropriate in an emergency -- and corresponding architectural levers for these technologies.In addition to laying a foundation for future work in this area, this research serves as a prototypical example of using Value Sensitive Design to explicate the underlying human values in complex security domains.
Alexei Czeskis, Ivayla Dermendjieva, Hussein Yapit, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno
SOUPS1
2010 Experimental Security Analysis of a Modern Automobile
abstract
Modern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks. In this paper we experimentally evaluate these issues on a modern automobile and demonstrate the fragility of the underlying system structure. We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input\dash including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car's two internal subnets. We also present composite attacks that leverage individual weaknesses, including an attack that embeds malicious code in a car's telematics unit and that will completely erase any evidence of its presence after a crash. Looking forward, we discuss the complex challenges in addressing these vulnerabilities while considering the existing automotive ecosystem.
Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage
IEEE Symposium on Security and Privacy2
2008 RFIDs and secret handshakes: defending against ghost-and-leech attacks and unauthorized reads with context-aware communications
abstract
We tackle the problem of defending against ghost-and-leech (a.k.a. proxying, relay, or man-in-the-middle) attacks against RFID tags and other contactless cards. The approach we take -- which we dub secret handshakes -- is to incorporate gesture recognition techniques directly on the RFID tags or contactless cards. These cards will only engage in wireless communications when they internally detect these secret handshakes. We demonstrate the effectiveness of this approach by implementing our secret handshake recognition system on a passive WISP RFID tag with a built-in accelerometer. Our secret handshakes approach is backward compatible with existing deployments of RFID tag and contactless card readers.
Alexei Czeskis, Karl Koscher, Joshua R. Smith 0001, Tadayoshi Kohno
CCS1
2008 Defeating Encrypted and Deniable File Systems: TrueCrypt v5.1a and the Case of the Tattling OS and Applications
Alexei Czeskis, David J. St. Hilaire, Karl Koscher, Steve D. Gribble, Tadayoshi Kohno, Bruce Schneier
HotSec1