EDBT 2026 Demo / reviewers in the wild / expert
Chase Cotton
dblp:70/10305
· DBLP profile ↗
14ranked-venue papers
0as first author
10since 2021 · last 2024
0000-0001-6218-1327ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 3 since 2021Security and privacy · 5 · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Silent Observers Make a Difference: A Large-scale Analysis of Transparent Proxies on the InternetabstractTransparent web proxies have been widely deployed on the Internet, bridging the communications between clients and servers and providing desirable benefits to both sides, such as load balancing, security monitoring, and privacy enhancement. Meanwhile, they work silently as clients and servers may not be aware of their existence. However, due to their invisibility and stealthiness, transparent proxies remain understudied for their behaviors, suspicious activities, and potential vulnerabilities that could be exploited by attackers. To better understand transparent proxies, we design and develop a framework to systematically investigate them in the wild. We identify two major types of transparent web proxies, named FDR and CPV, respectively. FDR is a type of transparent proxy that independently performs Forced DNS Resolution during interception. CPV is a type of transparent proxy that presents Cache Poisoning Vulnerability. We perform a large-scale measurement to detect each type of transparent web proxy and scrutinize their security implications. In total, we observe 32,246 FDR and 11,286 CPV cases through our acquired vantage points. We confirm that these two types of transparent proxies are distributed globally — FDRs are observed in 98 countries and CPVs are observed in 51 countries. Our work highlights the issues of vulnerable transparent proxies and provides insights for mitigating such problems. Rui Bian, Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
INFOCOM | 5 |
| 2022 | A Comprehensive, Longitudinal Study of Government DNS Deployment at Global ScaleabstractWithin the Domain Name System (DNS), government domains form a particularly valuable part of the names-pace, representing trusted sources of information, vital services, and gateways for government personnel to engage in their duties. As the COVID-19 pandemic has unfolded, governments’ digital resources have become increasingly important to provide support to populations largely in isolation. The accessibility of these resources relies largely on the trustworthiness of the domains that represent them. In this paper, we conduct an extensive measurement study focused on the availability and legitimacy of DNS records in the authoritative nameservers of government domains for over 190 countries. Our measurements reveal that thousands of domains do not use replicated authoritative name-servers, as well as a substantial increase in the trend of more domains relying on a single third-party DNS services provider. We also find more than 1,000 domains vulnerable to hijacking due to defective delegations. Our work shows that although robust overall, the deployments of authoritative nameservers in government domains still contain a non-trivial number of configurations that do not meet RFC requirements, leading to poor performance and reduced reliability that may leave domains vulnerable to hijacking. Rebekah Houser, Shuai Hao 0001, Chase Cotton, Haining Wang 0001 |
DSN | 3 |
| 2022 | Time-Print: Authenticating USB Flash Drives with Novel Timing FingerprintsabstractUniversal Serial Bus (USB) ports are a ubiquitous feature in computer systems and offer a cheap and efficient way to provide power and data connectivity between a host and peripheral devices. Even with the rise of cloud and off-site computing, USB has played a major role in enabling data transfer between devices. Its usage is especially prevalent in high-security environments where systems are ‘air-gapped’ and not connected to the Internet. However, recent research has demonstrated that USB is not nearly as secure as once thought, with different attacks showing that modified firmware on USB mass storage devices can compromise a host system. While many defenses have been proposed, they require user interaction, advanced hardware support (incompatible with legacy devices), or utilize device identifiers that can be subverted by an attacker. In this paper, we present Time-Print, a novel timing-based fingerprinting method, for identifying USB mass storage devices. We create a fingerprint by timing a series of read operations from different locations on a drive, as the timing variations are unique enough to identify individual USB devices. Time-Print is low overhead, completely software-based, and does not require any extra or specialized hardware. To validate the efficacy of Time-Print, we examine more than 40 USB flash drives and conduct experiments in multiple authentication scenarios. The experimental results show that Time-Print can (1) identify known/unknown brand/model USB devices with greater than 99.5% accuracy, (2) identify seen/unseen devices of the same brand/model with 95% accuracy, and (3) classify USB devices from the same brand/model with an average accuracy of 98.7%. Patrick Cronin, Xing Gao 0001, Haining Wang 0001, Chase Cotton |
SP | 4 |
| 2022 | Shining a light on dark places: A comprehensive analysis of open proxy ecosystem
Rui Bian, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
Comput. Networks | 4 |
| 2021 | An Exploration of ARM System-Level Cache and GPU Side ChannelsabstractAdvanced RISC Machines (ARM) processors have recently gained market share in both cloud computing and desktop applications. Meanwhile, ARM devices have shifted to a more peripheral based design, wherein designers attach a number of coprocessors and accelerators to the System-on-a-Chip (SoC). By adopting a System-Level Cache, which acts as a shared cache between the CPU-cores and peripherals, ARM attempts to alleviate the memory bottleneck issues that exist between data sources and accelerators. This paper investigates emerging security threats introduced by this new System-Level Cache. Specifically, we demonstrate that the System-Level Cache can still be exploited to create a cache occupancy channel to accurately fingerprint websites. We redesign and optimize the attack for various browsers based on the ARM cache design, which can significantly reduce the attack duration while increasing accuracy. Moreover, we introduce a novel GPU contention channel in mobile devices, which can achieve similar accuracy to the cache occupancy channel. We conduct a thorough evaluation by examining these attacks across multiple devices, including iOS, Android, and MacOS with the new M1 MacBook Air. The experimental results demonstrate that (1) the System-Level Cache based website fingerprinting technique can achieve promising accuracy in both open (up to 90%) and closed (up to 95%) world scenarios, and (2) our GPU contention channel is more effective than the CPU cache channel on Android devices. Patrick Cronin, Xing Gao 0001, Haining Wang 0001, Chase Cotton |
ACSAC | 4 |
| 2021 | DNSonChain: Delegating Privacy-Preserved DNS Resolution to BlockchainabstractDomain Name System (DNS) is known to present privacy concerns. To this end, decentralized blockchains have been used to host DNS records, so that users can synchronize with the blockchain to maintain a local DNS database and resolve domain names locally. However, existing blockchain-based solutions either do not guarantee a domain name is controlled by its "true" owner; or have to resort to DNSSEC, a not yet widely adopted protocol, for verifying ownership. In this paper, we present DNSonChain, a new blockchain-based naming service compatible with DNS. It allows domain owners to claim their domain ownership on the blockchain where DNS records are hosted. The core function of DNSonChain is to validate the domain ownership in a decentralized manner. We propose a majority vote mechanism that randomly selects multiple participants (i.e., voters) in the system to vote for the authority of domain ownership. To provide resistance to attacks from fraudulent voters, DNSonChain requires two rounds of voting processes. Our security analysis shows that DNSonChain is robust against several types of security failures, able to recover from various attacks. We implemented a prototype of DNSonChain as an Ethereum decentralized application and evaluate it on an Ethereum Testnet. Lin Jin, Shuai Hao 0001, Yan Huang 0001, Haining Wang 0001, Chase Cotton |
ICNP | 5 |
| 2021 | A Comprehensive Measurement-based Investigation of DNS HijackingabstractAttacks against the domain name system (DNS) have long plagued the Internet, requiring continual investigation and vigilance to prevent the abuse of this critical infrastructure. Among these attacks, DNS hijacking has repeatedly asserted itself as one of the most serious threats. In recent years, the severity of DNS hijacking has motivated renewed interest in developing more robust defenses. The size, dynamism, and diversity of the DNS ecosystem present nontrivial challenges to crafting an effective and scalable defense. Further, the relative rarity of documented DNS hijacking attacks makes them difficult to study in-depth. In this paper, we attempt to address the challenges in two thrusts. We first conduct an analysis based on the reports of confirmed DNS hijacking attacks and passive DNS records to characterize known DNS hijacking attacks and identify features for building defense mechanisms. Then we explore the extent to which the characteristic features can be used to build a DNS hijacking detection mechanism and evaluate its effectiveness from the perspective of a network gateway. Rebekah Houser, Shuai Hao 0001, Zhou Li 0001, Daiping Liu, Chase Cotton, Haining Wang 0001 |
SRDS | 5 |
| 2021 | Understanding the Impact of Encrypted DNS on Internet CensorshipabstractDNS traffic is transmitted in plaintext, resulting in privacy leakage. To combat this problem, secure protocols have been used to encrypt DNS messages. Existing studies have investigated the performance overhead and privacy benefits of encrypted DNS communications, yet little has been done from the perspective of censorship. In this paper, we study the impact of the encrypted DNS on Internet censorship in two aspects. On one hand, we explore the severity of DNS manipulation, which could be leveraged for Internet censorship, given the use of encrypted DNS resolvers. In particular, we perform 7.4 million DNS lookup measurements on 3,813 DoT and 75 DoH resolvers and identify that 1.66% of DoT responses and 1.42% of DoH responses undergo DNS manipulation. More importantly, we observe that more than two-thirds of the DoT and DoH resolvers manipulate DNS responses from at least one domain, indicating that the DNS manipulation is prevalent in encrypted DNS, which can be further exploited for enhancing Internet censorship. On the other hand, we evaluate the effectiveness of using encrypted DNS resolvers for censorship circumvention. Specifically, we first discover those vantage points that involve DNS manipulation through on-path devices, and then we apply encrypted DNS resolvers at these vantage points to access the censored domains. We reveal that 37% of the domains are accessible from the vantage points in China, but none of the domains is accessible from the vantage points in Iran, indicating that the censorship circumvention of using encrypted DNS resolvers varies from country to country. Moreover, for a vantage point, using a different encrypted DNS resolver does not lead to a noticeable difference in accessing the censored domains. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
WWW | 4 |
| 2021 | Intelligence in cyberspace: the road to cyber singularityabstractIntelligence has been defined in many ways like logic, awareness, reasoning, critical thinking, etc. Many researchers insist on the possibility of a Technological Singularity shortly, which may see machines gaining intelligence similar to, or greater than humans. While many researchers believe that Technological Singularity is at an arm’s length, many counter-question the possibility of the same due to the lack of concrete evidence. Recently Cybersecurity has manoeuvred its way through technology to become one of the most rapidly advancing fields. Artificial Intelligence introduced to Cybersecurity has seen a tremendous increase in the number of systems that are capable of performing tasks faster and better than humans. This has led us to believe that there is intelligence in cyberspace along with the possibility of Cyber Singularity. We emphasise the intelligence of systems using a set of characteristics that insist on how sophisticated the systems have become over time that might lead to Cyber Singularity. We map these characteristics to the characteristics of living species with the hope of locating intelligence in the biomedical domain and further, try to identify systems displaying such characteristics in cyberspace. Keeping in mind the concept of technological singularity proposed before, we also perform an extensive survey of the past research works related to the field and also, use the concepts of set theory to reinforce the possibility of Cyber Singularity in the coming years. Ishaani Priyadarshini, Chase Cotton |
J. Exp. Theor. Artif. Intell. | 2 |
| 2021 | A novel LSTM-CNN-grid search-based deep neural network for sentiment analysis
Ishaani Priyadarshini, Chase Cotton |
J. Supercomput. | 2 |
| 2019 | An investigation on information leakage of DNS over TLSabstractDNS over TLS (DoT) protects the confidentiality and integrity of DNS communication by encrypting DNS messages transmitted between users and resolvers. In recent years, DoT has been deployed by popular recursive resolvers like Cloudflare and Google. While DoT is supposed to prevent on-path adversaries from learning and tampering with victims' DNS requests and responses, it is unclear how much information can be deduced through traffic analysis on DoT messages. To answer this question, in this work, we develop a DoT fingerprinting method to analyze DoT traffic and determine if a user has visited websites of interest to adversaries. Given that a visit to a website typically introduces a sequence of DNS packets, we can infer the visited websites by modeling the temporal patterns of packet sizes. Our method can identify DoT traffic for websites with a false negative rate of less than 17% and a false positive rate of less than 0.5% when DNS messages are not padded. Moreover, we show that information leakage is still possible even when DoT messages are padded. These findings highlight the challenges of protecting DNS privacy, and indicate the necessity of a thorough analysis of the threats underlying DNS communications for effective defenses. Rebekah Houser, Zhou Li 0001, Chase Cotton, Haining Wang 0001 |
CoNEXT | 3 |
| 2019 | Unveil the Hidden Presence: Characterizing the Backend Interface of Content Delivery NetworksabstractContent Delivery Networks (CDNs) are critical to today’s Internet ecosystem for delivering rich content to end-users. CDNs augment the Internet infrastructure by deploying geographically distributed edge servers, which play a dual role in CDNs: one as frontend interface to facilitate end-user’s proximal access and the other as backend interface to fetch content from origin servers. Previous research has well studied the frontend interface of CDNs, but no active approach has yet been provided to investigate the backend interface. In this paper, we first propose an active approach to measuring the backend interface of CDNs. Then, we present a large-scale measurement study to characterize the backend interface for three CDN platforms, so as to understand the CDN’s globally distributed infrastructure, which is essential to its performance and security. In particular, we discover the address space and operation patterns of the backend interface of CDNs. Then, by analyzing the backend addresses and their associated frontend addresses, we study their geolocation association. Furthermore, we issue traceroutes from origin servers to the backend addresses of the CDNs to analyze their performance implications, and perform port scanning on the backend addresses to investigate their security implications. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
ICNP | 4 |
| 2018 | Your Remnant Tells Secret: Residual Resolution in DDoS Protection ServicesabstractThe increasing prevalence of Distributed Denial of Service (DDoS) attacks on the Internet has led to the wide adoption of DDoS Protection Service (DPS), which is typically provided by Content Delivery Networks (CDNs) and is integrated with CDN's security extensions. The effectiveness of DPS mainly relies on hiding the IP address of an origin server and rerouting the traffic to the DPS provider's distributed infrastructure, where malicious traffic can be blocked. In this paper, we perform a measurement study on the usage dynamics of DPS customers and reveal a new vulnerability in DPS platforms, called residual resolution, by which a DPS provider may leak origin IP addresses when its customers terminate the service or switch to other platforms, resulting in the failure of protection from future DPS providers as adversaries are able to discover the origin IP addresses and launch the DDoS attack directly to the origin servers. We identify that two major DPS/CDN providers, Cloudflare and Incapsula, are vulnerable to such residual resolution exposure, and we then assess the magnitude of the problem in the wild. Finally, we discuss the root causes of residual resolution and the practical countermeasures to address this security vulnerability. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
DSN | 4 |
| 2015 | Next generation resilient redundant routerabstractThe need in the commercial Internet to continually improve unit capital costs coupled with the increased reliability needed to carry all service types drives carrier architectures toward ever larger routers deployed in non-redundant configurations. This requires advancements in High Availability (HA) Non-Stop operation of these systems. We propose and implement a distributed architecture for these next generation core routers by implementing N-Modular Redundancy for control process software. The system employs an eventually consistent framework based on a Distributed Hash Table database. The overall goal is a system capable of non-stop routing, meaning that a router can still process both control and data messages, even after multiple software and hardware failures. Details on the architecture are provided and an estimation of scalability, overhead, and fault recovery time is presented. Hristo Asenov, Chase Cotton |
HPSR | 2 |