Reiner Sailer

dblp:86/4992 · DBLP profile ↗
← Back
25ranked-venue papers
7as first author
0since 2021 · last 2016
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 19 · 5 first-authorDatabases, data management, data science and information retrieval · 3Computer networks · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
10 papers
Network security · 37% Hardware security and side channels · 21% Systems and software security · 18%
Computer networks
2 papers
Network measurement and analytics · 57% Internet architecture and protocols · 43%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Storage systems · 70% Cloud and datacenter computing · 30%
Software engineering, system software, and programming languages
3 papers
Software maintenance and evolution · 46% Program verification · 27% Operating systems · 27%

Topics — the 19 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention › intrusion detection › attack detection
advanced persistent threat detection
0.212015
FCCE: Highly scalable distributed Feature Collection and Correlation Engine for low latency big data analytics · ICDE 2015
Network security › intrusion detection and prevention › intrusion detection › malicious traffic detection
botnet detection
0.212015
FCCE: Highly scalable distributed Feature Collection and Correlation Engine for low latency big data analytics · ICDE 2015
Hardware security and side channels
trusted execution environments
0.242008
Trustworthy and personalized computing on public kiosks · MobiSys 2008
vTPM: Virtualizing the Trusted Platform Module · USENIX Security Symposium 2006
Attestation-based policy enforcement for remote access · CCS 2004
Cryptographic protocols and secure computation
authenticated data structure
0.212014
Outsourcing multi-version key-value stores with verifiable data freshness · ICDE 2014
Storage systems
key-value storage
0.212014
Outsourcing multi-version key-value stores with verifiable data freshness · ICDE 2014
Internet architecture and protocols › domain name system
DNS security
0.212013
Practical Comprehensive Bounds on Surreptitious Communication over DNS · USENIX Security Symposium 2013
Network security › intrusion detection and prevention
covert channel detection
0.212013
Practical Comprehensive Bounds on Surreptitious Communication over DNS · USENIX Security Symposium 2013
Hardware security and side channels › trusted execution environments
trusted platform module
0.122008
Trustworthy and personalized computing on public kiosks · MobiSys 2008
Attestation-based policy enforcement for remote access · CCS 2004
Malware analysis › malware detection
behavior-based malware detection
0.112010
Synthesizing Near-Optimal Malware Specifications from Suspicious Behaviors · IEEE Symposium on Security and Privacy 2010
Systems and software security › program analysis
specification mining
0.112010
Synthesizing Near-Optimal Malware Specifications from Suspicious Behaviors · IEEE Symposium on Security and Privacy 2010
Systems and software security › data integrity
data-flow integrity
0.112006
Toward Automated Information-Flow Integrity Verification for Security-Critical Applications · NDSS 2006
Cloud and datacenter computing
data outsourcing
0.112014
Outsourcing multi-version key-value stores with verifiable data freshness · ICDE 2014
Cryptographic primitives and cryptanalysis
message authentication codes
0.012003
Analyzing Integrity Protection in the SELinux Example Policy · USENIX Security Symposium 2003
Systems and software security
operating system security
0.012003
Analyzing Integrity Protection in the SELinux Example Policy · USENIX Security Symposium 2003
Software maintenance and evolution
concept analysis
0.012010
Synthesizing Near-Optimal Malware Specifications from Suspicious Behaviors · IEEE Symposium on Security and Privacy 2010
Cloud and datacenter computing
virtualization
0.012008
Trustworthy and personalized computing on public kiosks · MobiSys 2008
Program verification › security property verification
information flow verification
0.012006
Toward Automated Information-Flow Integrity Verification for Security-Critical Applications · NDSS 2006
Operating systems
virtualization
0.012006
vTPM: Virtualizing the Trusted Platform Module · USENIX Security Symposium 2006
Systems and software security › security engineering
security policy analysis
0.012003
Analyzing Integrity Protection in the SELinux Example Policy · USENIX Security Symposium 2003

Methods — techniques the papers use, named apart from their topics

feature collection · 0.4correlation engine · 0.4merkle tree · 0.4incremental digest structure · 0.4bloom filter · 0.4information-theoretic bounds · 0.3probabilistic sampling · 0.2graph mining · 0.2concept analysis · 0.2integrity measurement · 0.2remote attestation · 0.1virtual TPM · 0.1trusted platform module · 0.1
YearPublicationVenuePosition
2016 Detecting Malicious Exploit Kits using Tree-based Similarity Searches
Teryl Taylor, Xin Hu 0001, Ting Wang 0006, Jiyong Jang, Marc Ph. Stoecklin, Fabian Monrose, Reiner Sailer
CODASPY7
2015 FCCE: Highly scalable distributed Feature Collection and Correlation Engine for low latency big data analytics
abstract
In this paper, we present the design, architecture, and implementation of a novel analysis engine, called Feature Collection and Correlation Engine (FCCE), that finds correlations across a diverse set of data types spanning over large time windows with very small latency and with minimal access to raw data. FCCE scales well to collecting, extracting, and querying features from geographically distributed large data sets. FCCE has been deployed in a large production network with over 450,000 workstations for 3 years, ingesting more than 2 billion events per day and providing low latency query responses for various analytics. We explore two security analytics use cases to demonstrate how we utilize the deployment of FCCE on large diverse data sets in the cyber security domain: 1) detecting fluxing domain names of potential botnet activity and identifying all the devices in the production network querying these names, and 2) detecting advanced persistent threat infection. Both evaluation results and our experience with real-world applications show that FCCE yields superior performance over existing approaches, and excels in the challenging cyber security domain by correlating multiple features and deriving security intelligence.
Douglas Lee Schales, Xin Hu 0001, Jiyong Jang, Reiner Sailer, Marc Ph. Stoecklin, Ting Wang 0006
ICDE4
2014 Outsourcing multi-version key-value stores with verifiable data freshness
abstract
In the age of big data, key-value data updated by intensive write streams is increasingly common, e.g., in social event streams. To serve such data in a cost-effective manner, a popular new paradigm is to outsource it to the cloud and store it in a scalable key-value store while serving a large user base. Due to the limited trust in third-party cloud infrastructures, data owners have to sign the data stream so that the data users can verify the authenticity of query results from the cloud. In this paper, we address the problem of verifiable freshness for multi-version key-value data. We propose a memory-resident digest structure that utilizes limited memory effectively and can have efficient verification performance. The proposed structure is named IncBM-Tree because it can INCrementally build a Bloom filter-embedded Merkle Tree. We have demonstrated the superior performance of verification under small memory footprints for signing, which is typical in an outsourcing scenario where data owners and users have limited resources.
Yuzhe Tang, Ling Liu 0001, Ting Wang 0006, Xin Hu 0001, Reiner Sailer, Peter R. Pietzuch
ICDE5
2014 Kaleido: Network Traffic Attribution using Multifaceted Footprinting
abstract
Network traffic attribution, namely, inferring users responsible for activities observed on network interfaces, is one fundamental yet challenging task in network security forensics. Compared with other user-system interaction records, network traces are inherently coarsegrained, context-sensitive, and detached from user ends. This paper presents Kaleido, a new network traffic attribution tool with a series of key features: a) it adopts a new class of inductive discriminant models to capture user- and context-specific patterns (“footprints”) from different aspects of network traffic; b) it applies efficient learning methods to extracting and aggregating such footprints from noisy historical traces; c) with the help of novel indexing structures, it is able to perform efficient, runtime traffic attribution over high-volume network traces. The efficacy of Kaleido is evaluated with extensive experimental studies using the real network traces collected over three months in a large enterprise network.
Ting Wang 0006, Fei Wang 0001, Reiner Sailer, Douglas Lee Schales
SDM3
2014 MUSE: asset risk scoring in enterprise network with mutually reinforced reputation propagation
abstract
Cyber security attacks are becoming ever more frequent and sophisticated. Enterprises often deploy several security protection mechanisms, such as anti-virus software, intrusion detection/prevention systems, and firewalls, to protect their critical assets against emerging threats. Unfortunately, these protection systems are typically ‘noisy’, e.g., regularly generating thousands of alerts every day. Plagued by false positives and irrelevant events, it is often neither practical nor cost-effective to analyze and respond to every single alert. The main challenges faced by enterprises are to extract important information from the plethora of alerts and to infer potential risks to their critical assets. A better understanding of risks will facilitate effective resource allocation and prioritization of further investigation. In this paper, we present MUSE, a system that analyzes a large number of alerts and derives risk scores by correlating diverse entities in an enterprise network. Instead of considering a risk as an isolated and static property pertaining only to individual users or devices, MUSE exploits a novel mutual reinforcement principle and models the dynamics of risk based on the interdependent relationship among multiple entities. We apply MUSE on real-world network traces and alerts from a large enterprise network consisting of more than 10,000 nodes and 100,000 edges. To scale up to such large graphical models, we formulate the algorithm using a distributed memory abstraction model that allows efficient in-memory parallel computations on large clusters. We implement MUSE on Apache Spark and demonstrate its efficacy in risk assessment and flexibility in incorporating a wide variety of datasets.
Xin Hu 0001, Ting Wang 0006, Marc Ph. Stoecklin, Douglas Lee Schales, Jiyong Jang, Reiner Sailer
EURASIP J. Inf. Secur.6
2013 Practical Comprehensive Bounds on Surreptitious Communication over DNS
Vern Paxson, Mihai Christodorescu, Mobin Javed, Josyula R. Rao, Reiner Sailer, Douglas Lee Schales, Marc Ph. Stoecklin, Kurt Thomas, Wietse Z. Venema, Nicholas Weaver
USENIX Security Symposium5
2010 Synthesizing Near-Optimal Malware Specifications from Suspicious Behaviors
abstract
Fueled by an emerging underground economy, malware authors are exploiting vulnerabilities at an alarming rate. To make matters worse, obfuscation tools are commonly available, and much of the malware is open source, leading to a huge number of variants. Behavior-based detection techniques are a promising solution to this growing problem. However, these detectors require precise specifications of malicious behavior that do not result in an excessive number of false alarms. In this paper, we present an automatic technique for extracting optimally discriminative specifications, which uniquely identify a class of programs. Such a discriminative specification can be used by a behavior-based malware detector. Our technique, based on graph mining and concept analysis, scales to large classes of programs due to probabilistic sampling of the specification space. Our implementation, called Holmes, can synthesize discriminative specifications that accurately distinguish between programs, sustaining an 86% detection rate on new, unknown malware, with 0 false positives, in contrast with 55% for commercial signature-based antivirus (AV) and 62-64% for behavior-based AV (commercial or research).
Matt Fredrikson, Somesh Jha, Mihai Christodorescu, Reiner Sailer, Xifeng Yan
IEEE Symposium on Security and Privacy4
2008 Trustworthy and personalized computing on public kiosks
abstract
Many people desire ubiquitous access to their personal computing environments. We present a system in which a user leverages a personal mobile device to establish trust in a public computing device, or kiosk, prior to resuming her environment on the kiosk. We have designed a protocol by which the mobile device determines the identity and integrity of all software loaded on the kiosk, in order to inform the user whether the kiosk is trustworthy. Our system exploits emerging hardware security technologies, namely the Trusted Platform Module and new support in x86 processors for establishing a dynamic root of trust. We have demonstrated the viability of our approach by implementing and evaluating our system on commodity hardware. Through a brief survey, we found that respondents are generally willing to endure a delay in exchange for an increased assurance of data privacy, and that the delay incurred by our unoptimized prototype is close to the range tolerable to the respondents. We have focused on allowing the user to personalize a kiosk by running her own virtual machine there. However, our work is generally applicable to establishing trust on public computing devices before revealing any sensitive information to those devices.
Scott Garriss, Ramón Cáceres, Stefan Berger, Reiner Sailer, Leendert van Doorn, Xiaolan Zhang 0001
MobiSys4
2007 Retrofitting the IBM POWER Hypervisor to Support Mandatory Access Control
abstract
Server virtualization more readily enables the collocation of disparate workloads on a shared physical platform. When employed on systems across a data center, the result can be a dramatic increase in server utilization and a decrease in overall power, cooling and floor space requirements. However, in an environment where workloads share the underlying platforms, achieving other desirable workload goals, such as availability and security, becomes a challenge. In particular, enforcing isolation between workloads in a large, dynamic, and virtualized data center requires strong yet easily configurable controls on the sharing of resources at the virtualization layer. Commercial hypervisors usually offer reasonable isolation of individual virtual machines (VMs). However, on hypervisor-based platforms, one cannot currently define a single policy that automatically enforces restrictions on the sharing of resources between multiple VMs or request an air gap between workloads. In this paper, we describe the design and implementation of a Hypervisor-based Mandatory Access Control (MAC) that achieves policy-driven distributed workload isolation for the IBM Power Hypervisor (PHYP). We discuss our experiences and lessons learned and examine the implications and trade-offs involved in providing MAC on a production- level, commercially-available hypervisor. Our goal is to simplify the security management of data centers through centralized security management and policy- driven distributed access control and data protection.
Enriquillo Valdez, Reiner Sailer, Ronald Perez
ACSAC2
2007 Managing the risk of covert information flows in virtual machine systems
abstract
Flexible mandatory access control (MAC) enforcement is now available for virtual machine systems. For example, the sHype MAC system for the Xen virtual machine monitor is part of the mainline Xen distribution. Such systems offer the isolation of VM systems with the flexible security of MAC enforcement. A problem is that such MAC VM systems will only be assured at modest levels (e.g., Common Criteria EAL4), so they may contain covert channels. Covert channels are often difficult to identify and harder to remove, so we propose an approach to manage possible covert leakage to enable verification of security guarantees. Typically, covert channels are outside of access control policies, but we propose an approach that includes both overt flows and covert flows to assess the possible risk of information leakage due to their combination. We define the concept of a risk flow policy that describes the authorized risks due to covert flows. In this paper, we evaluate the ability of four policy models to express risk flow policies. Further, we examine how such policies will be enforced in VM systems. We find that variants of the Chinese Wall model and Bell-LaPadula model have features necessary to express risk flow policies. Further, we find that such policies can be enforced in the context of sHype's Type Enforcement model.
Trent Jaeger, Reiner Sailer, Yogesh Sreenivasan
SACMAT2
2006 Shamon: A System for Distributed Mandatory Access Control
abstract
We define and demonstrate an approach to securing distributed computation based on a shared reference monitor (Shamon) that enforces mandatory access control (MAC) policies across a distributed set of machines. The Shamon enables local reference monitor guarantees to be attained for a set of reference monitors on these machines. We implement a prototype system on the Xen hypervisor with a trusted MAC virtual machine built on Linux 2.6 whose reference monitor design requires only 13 authorization checks, only 5 of which apply to normal processing (others are for policy setup). We show that, through our architecture, distributed computations can be protected and controlled coherently across all the machines involved in the computation
Jonathan M. McCune, Trent Jaeger, Stefan Berger, Ramón Cáceres, Reiner Sailer
ACSAC5
2006 Toward Automated Information-Flow Integrity Verification for Security-Critical Applications
Umesh Shankar, Trent Jaeger, Reiner Sailer
NDSS3
2006 PRIMA: policy-reduced integrity measurement architecture
abstract
We propose an integrity measurement approach based on information flow integrity,which we call the Policy-Reduced Integrity Measurement Architecture (PRIMA).The recent availability of secure hardware has made it practical for a system to measure its own integrity, such that it can generate an integrity proof for remote parties. Various approaches have been proposed,but most simply measure the loaded code and static data to approximate runtime system integrity.We find that these approaches suffer from two problems: (1)the load-time measurements of code alone do not accurately reflect runtime behaviors,such as the use of untrusted network data,and (2) they are ineficient,requiring all measured entities to be known and fully trusted even if they have no impact on the target application.Classical integrity models are based on information flow,so we design the PRIMA approach to enable measurement of information flow integrity and prove that it achieves these goals. We prove how a remote party can verify useful information flow integrity properties using PRIMA. A PRIMA prototype has been built based on the open-source Linux Integrity Measurement Architecture (IMA)using SELinux policies to provide the information flow.
Trent Jaeger, Reiner Sailer, Umesh Shankar
SACMAT2
2006 vTPM: Virtualizing the Trusted Platform Module
Stefan Berger, Ramón Cáceres, Kenneth A. Goldman, Ronald Perez, Reiner Sailer, Leendert van Doorn
USENIX Security Symposium5
2006 Shame on Trust in Distributed Systems
Trent Jaeger, Patrick D. McDaniel, Luke St. Clair, Ramón Cáceres, Reiner Sailer
HotSec5
2005 Building a MAC-Based Security Architecture for the Xen Open-Source Hypervisor
abstract
We present the sHype hypervisor security architecture and examine in detail its mandatory access control facilities. While existing hypervisor security approaches aiming at high assurance have been proven useful for high-security environments that prioritize security over performance and code reuse, our approach aims at commercial security where near-zero performance overhead, non-intrusive implementation, and usability are of paramount importance. sHype enforces strong isolation at the granularity of a virtual machine, thus providing a robust foundation on which higher software layers can enact finer-grained controls. We provide the rationale behind the sHype design and describe and evaluate our implementation for the Xen open-source hypervisor
Reiner Sailer, Trent Jaeger, Enriquillo Valdez, Ramón Cáceres, Ronald Perez, Stefan Berger, John Linwood Griffin, Leendert van Doorn
ACSAC1
2004 Attestation-based policy enforcement for remote access
abstract
Intranet access has become an essential function for corporate users. At the same time, corporation's security administrators have little ability to control access to corporate data once it is released to remote clients. At present, no confidentiality or integrity guarantees about the remote access clients are made, so it is possible that an attacker may have compromised a client process and is now downloading or modifying corporate data. Even though we have corporate-wide access control over remote users, the access control approach is currently insufficient to stop these malicious processes. We have designed and implemented a novel system that empowers corporations to verify client integrity properties and establish trust upon the client policy enforcement before allowing clients (remote) access to corporate Intranet services. Client integrity is measured using a Trusted Platform Module (TPM), a new security technology that is becoming broadly available on client systems, and our system uses these measurements for access policy decisions enforced upon the client's processes. We have implemented a Linux 2.6 prototype system that utilizes the TPM measurement and attestation, existing Linux network control (Netfilter), and existing corporate policy management tools in the Tivoli Access Manager to control remote client access to corporate data. This prototype illustrates that our solution integrates seamlessly into scalable corporate policy management and introduces only a minor performance overhead.
Reiner Sailer, Trent Jaeger, Xiaolan Zhang 0001, Leendert van Doorn
CCS1
2004 Resolving constraint conflicts
abstract
In this paper, we define constraint conflicts and examine properties that may aid in guiding their resolution. A constraint conflict is an inconsistency between the access control policy and the constraints specified to limit that policy. For example, a policy that permits a high integrity subject to access low integrity data is in conflict with a Biba integrity constraint. Constraint conflicts differ from typical policy conflicts in that constraints are never supposed to be violated. That is, a conflict with a constraint results in a policy compilation error, whereas policy conflicts are resolved at runtime. As we have found in the past, when constraint conflicts occur in a specification a variety of resolutions are both possible and practical. In this paper, we detail some key formal properties of constraint conflicts and show how these are useful in guiding conflict resolution. We use the SELinux example policy for Linux 2.4.19 as the source of our constraint conflicts and resolution examples. The formal properties are used to guide the selection of resolutions and provide a basis for a resolution language that we apply to resolve conflicts in the SELinux example policy.
Trent Jaeger, Reiner Sailer, Xiaolan Zhang 0001
SACMAT2
2004 Design and Implementation of a TCG-based Integrity Measurement Architecture
Reiner Sailer, Xiaolan Zhang 0001, Trent Jaeger, Leendert van Doorn
USENIX Security Symposium1
2003 Analyzing Integrity Protection in the SELinux Example Policy
Trent Jaeger, Reiner Sailer, Xiaolan Zhang 0001
USENIX Security Symposium2
2002 Authentication for Distributed Web Caches
James Giles, Reiner Sailer, Dinesh C. Verma, Suresh Chari
ESORICS2
2001 IPSECvalidate: A Tool to Validate IPSEC Configurations
Reiner Sailer, Arup Acharya, Mandis Beigi, Raymond B. Jennings III, Dinesh C. Verma
LISA1
2000 History-based Distributed Filtering - A Tagging Approach to Network-Level Access Control
abstract
Discusses a network-level access control technique that applies the non-discretionary access control model to individual data packets that are exchanged between hosts or subnets. The proposed technique examines the incoming data's integrity properties to prevent applications within a node or subnetwork from so-called subversive channels. It checks outgoing data's secrecy requirements before transmission. Security labels are used to identify data packets as members of different categories and security levels. Additional tags store context information to validate the trustworthiness of a packet's content. Labels and tags of a data packet reflect events that may be relevant to access control throughout its life. As opposed to stateful filtering, which is based on the history of a flow of packets, our approach works on the history of an individual packet. Any state information is part of the packet rather than being stored in all the nodes inspecting the packet; i.e. nodes do not need to create and maintain state information.
Reiner Sailer, Matthias Kabatnik
ACSAC1
1998 Security Services in an Open Service Environment
abstract
Emerging telecommunication services use, store or transmit sensitive personal data to form individual network services. We suggest an add-on approach to realize secure telecommunication services which saves the huge investments in the existing ISDN network infrastructure. This is done by adding trusted runtime environments that contain security functions to the existing service infrastructure. This approach aims at separating sensitive service functions from highly complex functions of public telecommunication networks. We propose an enhancement of existing network service interfaces by standardized security service interfaces to enable the provision of open security services. Separated security control functions of independent service providers, however, might not be trusted by network operators. Therefore, this contribution particularly considers gateway functions implementing access control and ancillary conditions concerning network integrity.
Reiner Sailer
ACSAC1
1998 An Evolutionary Approach to Multilaterally Secure Services in ISDN / IN
abstract
Data protection and data security become more significant since telecommunication services and innovative applications based on these services handle an increasing amount of sensitive data. Modern services, e.g. call forwarding, tele-conferencing, and voice mail services use or store personal data to implement individual services. Sensitive data include personal identities or calling numbers, location information of the communicating parties, service indicators, number translation tables, reachability information, and time and duration of communication events. Generally usable open security services interfaces are proposed, that promote security services implemented in user terminals or trusted third parties in order to satisfy currently ignored and evolving security requirements in a more flexible and scalable way. This approach will both save the huge investments in today's telecommunication infrastructure and promote open security services that are independent of the underlying network infrastructure.
Reiner Sailer
ICCCN1