Kaan Onarlioglu

dblp:77/8031 · DBLP profile ↗
← Back
25ranked-venue papers
7as first author
7since 2021 · last 2024
0009-0003-7832-5884ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 7 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2024 Untangle: Multi-Layer Web Server Fingerprinting
Cem Topcuoglu, Kaan Onarlioglu, Bahruz Jabiyev, Engin Kirda
NDSS2
2024 Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
abstract
Modern web applications involve multiple HTTP processors on the traffic path, each acting as a reverse proxy and processing client requests. Even when such proxies are secure in isolation, when combined into complex systems, minor HTTP parsing discrepancies between them can lead to various severe attacks such as cache poisoning and HTTP request smuggling attacks.
Bahruz Jabiyev, Anthony Gavazzi, Kaan Onarlioglu, Engin Kirda
RAID3
2023 OAuth 2.0 Redirect URI Validation Falls Short, Literally
abstract
OAuth 2.0 requires a complex redirection trail between websites and Identity Providers (IdPs). In particular, the "redirect URI" parameter included in the popular Authorization Grant Code flow governs the callback endpoint that users are routed to, together with their security tokens. The protocol specification, therefore, includes guidelines on protecting the integrity of the redirect URI.
Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Seyed Ali Mirheidari, Bruno Crispo, Engin Kirda
ACSAC3
2022 FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu, Engin Kirda
USENIX Security Symposium5
2022 Web Cache Deception Escalates!
Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda, Bruno Crispo
USENIX Security Symposium3
2021 FADE: Detecting Fake News Articles on the Web
abstract
Internet-based media and social networks enable quick access to information; however, that has also made it easy to conduct disinformation campaigns. Fake news poses a serious threat to the functioning and safety of our society, as demonstrated by nation-state-sponsored campaigns to sway the 2016 US presidential election, and more recently COVID-19 pandemic hoaxes that promote false cures, putting lives at risk.
Bahruz Jabiyev, Sinan Pehlivanoglu, Kaan Onarlioglu, Engin Kirda
ARES3
2021 T-Reqs: HTTP Request Smuggling with Differential Fuzzing
abstract
HTTP Request Smuggling (HRS) is an attack that exploits the HTTP processing discrepancies between two servers deployed in a proxy-origin configuration, allowing attackers to smuggle hidden requests through the proxy. While this idea is not new, HRS is soaring in popularity due to recently revealed novel exploitation techniques and real-life abuse scenarios. In this work, we step back from the highly-specific exploits hogging the spotlight, and present the first work that systematically explores HRS within a scientific framework. We design an experiment infrastructure powered by a novel grammar-based differential fuzzer, test 10 popular server/proxy/CDN technologies in combinations, identify pairs that result in processing discrepancies, and discover exploits that lead to HRS. Our experiment reveals previously unknown ways to manipulate HTTP requests for exploitation, and for the first time documents the server pairs prone to HRS.
Bahruz Jabiyev, Steven Sprecher, Kaan Onarlioglu, Engin Kirda
CCS3
2020 Cached and Confused: Web Cache Deception in the Wild
Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda, William K. Robertson
USENIX Security Symposium3
2018 Eraser: Your Data Won't Be Back
abstract
Secure deletion of data from non-volatile storage is a well-recognized problem. While numerous solutions have been proposed, advances in storage technologies have stymied efforts to solve the problem. For instance, SSDs make use of techniques such as wear leveling that involve replication of data; this is in direct opposition to efforts to securely delete sensitive data from storage. We present a technique to provide secure deletion guarantees at file granularity, independent of the characteristics of the underlying storage medium. The approach builds on prior seminal work on cryptographic erasure, encrypting every file on an insecure medium with a unique key that can later be discarded to cryptographically render the data irrecoverable. To make the approach scalable and, therefore, usable on commodity systems, keys are organized in an efficient tree structure where a single master key is confined to a secure store. We describe an implementation of this scheme as a file-aware stackable block device, deployed as a standalone Linux kernel module that does not require modifications to the operating system. Our prototype demonstrates that secure deletion independent of the underlying storage medium can be achieved with comparable overhead to existing full disk encryption implementations.
Kaan Onarlioglu, William K. Robertson, Engin Kirda
EuroS&P1
2017 Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers
Tobias Lauinger, Abdelberi Chaabane, Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson
USENIX Security Symposium4
2016 Overhaul: Input-Driven Access Control for Better Privacy on Traditional Operating Systems
abstract
The prevailing security model for OSes focuses on isolating users from each other, however, the changing computing landscape has led to the extension of traditional access control models for single-user devices. Modern OSes for mobile devices such as iOS and Android have taken the opportunity provided by these new platforms to introduce permission systems in which users can manage access to sensitive resources during application installation or runtime. One drawback of similar efforts on desktop environments is that applications must be rewritten with this security model in mind, which hinders traditional OSes from enjoying the benefits of user-driven access control. We present a novel architecture for retrofitting a dynamic, input-driven access control model into traditional OSes. In this model, access to privacy-sensitive resources is mediated based on the temporal proximity of user interactions to access requests, and requests are communicated back to the user via visual alerts. We present a prototype implementation and demonstrate how input-driven access control can be realized for resources such as the microphone, camera, clipboard, and screen contents. Our approach is transparent to applications and users, and incurs no discernible performance overhead.
Kaan Onarlioglu, William K. Robertson, Engin Kirda
DSN1
2016 WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, William K. Robertson, Engin Kirda
Internet Measurement Conference2
2016 CrossFire: An Analysis of Firefox Extension-Reuse Vulnerabilities
Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson, Engin Kirda
NDSS2
2016 Trellis: Privilege Separation for Multi-user Applications Made Easy
Andrea Mambretti, Kaan Onarlioglu, Collin Mulliner, William K. Robertson, Engin Kirda, Federico Maggi 0001, Stefano Zanero
RAID2
2015 SENTINEL: Securing Legacy Firefox Extensions
Kaan Onarlioglu, Ahmet Salih Buyukkayhan, William K. Robertson, Engin Kirda
Comput. Secur.1
2014 TrueClick: automatically distinguishing trick banners from genuine download links
abstract
The ubiquity of Internet advertising has made it a popular target for attackers. One well-known instance of these attacks is the widespread use of trick banners that use social engineering techniques to lure victims into clicking on deceptive fake links, potentially leading to a malicious domain or malware. A recent and pervasive trend by attackers is to imitate the "download" or "play" buttons in popular file sharing sites (e.g., one-click hosters, video-streaming sites, bittorrent sites) in an attempt to trick users into clicking on these fake banners instead of the genuine link.
Sevtap Duman, Kaan Onarlioglu, Ali O. Ulusoy, William K. Robertson, Engin Kirda
ACSAC2
2014 Toward Robust Hidden Volumes Using Write-Only Oblivious RAM
abstract
With sensitive data being increasingly stored on mobile devices and laptops, hard disk encryption is more important than ever. In particular, being able to plausibly deny that a hard disk contains certain information is a very useful and interesting research goal. However, it has been known for some time that existing ``hidden volume'' solutions, like TrueCrypt, fail in the face of an adversary who is able to observe the contents of a disk on multiple, separate occasions. In this work, we explore more robust constructions for hidden volumes and present HiVE, which is resistant to more powerful adversaries with multiple-snapshot capabilities. In pursuit of this, we propose the first security definitions for hidden volumes, and prove HiVE secure under these definitions. At the core of HiVE, we design a new write-only Oblivious RAM. We show that, when only hiding writes, it is possible to achieve ORAM with optimal O(1) communication complexity and only poly-logarithmic user memory. This is a significant improvement over existing work and an independently interesting result. We go on to show that our write-only ORAM is specially equipped to provide hidden volume functionality with low overhead and significantly increased security. Finally, we implement HiVE as a Linux kernel block device to show both its practicality and usefulness on existing platforms.
Erik-Oliver Blass, Travis Mayberry, Guevara Noubir, Kaan Onarlioglu
CCS4
2013 Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks
abstract
As more and more Internet-based attacks arise, organizations are responding by deploying an assortment of security products that generate situational intelligence in the form of logs. These logs often contain high volumes of interesting and useful information about activities in the network, and are among the first data sources that information security specialists consult when they suspect that an attack has taken place. However, security products often come from a patchwork of vendors, and are inconsistently installed and administered. They generate logs whose formats differ widely and that are often incomplete, mutually contradictory, and very large in volume. Hence, although this collected information is useful, it is often dirty.
Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu, Todd Leetham, William K. Robertson, Ari Juels, Engin Kirda
ACSAC3
2013 Securing Legacy Firefox Extensions with SENTINEL
Kaan Onarlioglu, Mustafa Battal, William K. Robertson, Engin Kirda
DIMVA1
2013 Clickonomics: Determining the Effect of Anti-Piracy Measures for One-Click Hosting
Tobias Lauinger, Martin Szydlowski, Kaan Onarlioglu, Gilbert Wondracek, Engin Kirda, Christopher Krügel
NDSS3
2013 Holiday Pictures or Blockbuster Movies? Insights into Copyright Infringement in User Uploads to One-Click File Hosters
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, Engin Kirda, William K. Robertson, Mohamed Ali Kâafar
RAID2
2013 PrivExec: Private Execution as an Operating System Service
abstract
Privacy has become an issue of paramount importance for many users. As a result, encryption tools such as True Crypt, OS-based full-disk encryption such as File Vault, and privacy modes in all modern browsers have become popular. However, although such tools are useful, they are not perfect. For example, prior work has shown that browsers still leave many traces of user information on disk even if they are started in private browsing mode. In addition, disk encryption alone is not sufficient, as key disclosure through coercion remains possible. Clearly, it would be useful and highly desirable to have OS-level support that provides strong privacy guarantees for any application -- not only browsers. In this paper, we present the design and implementation of PrivExec, the first operating system service for private execution. PrivExec provides strong, general guarantees of private execution, allowing any application to execute in a mode where storage writes, either to the filesystem or to swap, will not be recoverable by others during or after execution. PrivExec does not require explicit application support, recompilation, or any other preconditions. We have implemented a prototype of PrivExec by extending the Linux kernel that is performant, practical, and that secures sensitive data against disclosure.
Kaan Onarlioglu, Collin Mulliner, William K. Robertson, Engin Kirda
IEEE Symposium on Security and Privacy1
2012 Insights into User Behavior in Dealing with Internet Attacks
Kaan Onarlioglu, Utku Ozan Yilmaz, Engin Kirda, Davide Balzarotti
NDSS1
2010 G-Free: defeating return-oriented programming through gadget-less binaries
abstract
Despite the numerous prevention and protection mechanisms that have been introduced into modern operating systems, the exploitation of memory corruption vulnerabilities still represents a serious threat to the security of software systems and networks. A recent exploitation technique, called Return-Oriented Programming (ROP), has lately attracted a considerable attention from academia. Past research on the topic has mostly focused on refining the original attack technique, or on proposing partial solutions that target only particular variants of the attack.
Kaan Onarlioglu, Leyla Bilge, Andrea Lanzi, Davide Balzarotti, Engin Kirda
ACSAC1
2010 Efficient broadcast encryption with user profiles
Murat Ak, Kamer Kaya, Kaan Onarlioglu, Ali Aydin Selçuk
Inf. Sci.3