EDBT 2026 Demo / reviewers in the wild / expert
Matthew Smith 0001
dblp:88/5808-1
· DBLP profile ↗
76ranked-venue papers
8as first author
16since 2021 · last 2025
0000-0002-2724-1379ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 42 · 7 since 2021Human-computer interaction and ubiquitous computing · 20 · 12 since 2021Systems, architecture and hardware · 11 · 7 first-authorSoftware engineering, systems software and programming languages · 9 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Out of Sight, Out of Mind? Exploring Data Protection Practices for Personal Data in Usable Security & Privacy StudiesabstractAdherence to data protection measures such as pseudonymization or anonymization is critical in human subjects research because it has a direct impact on the confidentiality of participants' sensitive information, trust in research practices, and compliance with ethical and legal standards. Regulations such as the General Data Protection Regulation (GDPR) and guarantees made by researchers in informed consent forms mandate strict protocols for data security. However, compliance with these is not always straightforward. To gain qualitative insights into data protection practices in the field of Usable Security and Privacy (USP), we conducted interviews with 22 practitioners (five professors, eight researchers, nine data protection officers) and one focus group with five researchers. Overall, our results show a high awareness of ethical and legal responsibilities but highlight many practical and procedural issues. Based on these, we make concrete recommendations on how to improve the protection of personal data in research. Florin Martius, Luisa Jansen, Lukas Struck, Arthi Arumugam, Lisa Geierhaas, Anna-Marie Ortloff, Matthew Smith 0001, Christian Tiefenau |
CHI | 7 |
| 2025 | A Qualitative Study on How Usable Security and HCI Researchers Judge the Size and Importance of Odds Ratio and Cohen's d Effect SizesabstractResearchers often place a strong focus on statistical significance when reporting the results of statistical tests. However, effect sizes are reported less frequently, and interpretation in the context of the study and the research field is even rarer. These interpretations of effect sizes are, however, necessary to understand the practical importance of a result for the community. To explore how Usable Security & Privacy (USP) and HCI researchers interpret effect sizes and make judgments on practical importance, we conducted survey and interview studies with a total of 63 researchers at CHI and SOUPS 2023. Our studies focused on Cohen's d and odds ratios in two USP and one HCI scenario. We analyzed which artifacts researchers consider when judging effect size, and found misconceptions and variation between the participants, highlighting how difficult judging statistics can be. Based on our findings, we make concrete recommendations for improved reporting practices around effect sizes. Anna-Marie Ortloff, Julia Angelika Grohs, Simon Lenau, Matthew Smith 0001 |
CHI | 4 |
| 2025 | Small, Medium, Large? A Meta-Study of Effect Sizes at CHI to Aid Interpretation of Effect Sizes and Power CalculationabstractStatistical reporting, especially of effect sizes, is at the root of many methodological issues in quantitative research at CHI. Effect sizes are necessary for assessing practical relevance of results, a-priori power analysis, and meta-analyses, but currently, they are often not reported. Interpretations in the context of the study and the research field are also rare. To aid to researchers in reporting and contextualizing their effect sizes within their research field as well as choosing effect sizes for power analysis, we conducted a meta-study of quantitative CHI papers. We extracted statistics from all quantitative CHI papers published between 2019-2023 (N=1692). Based on effect sizes and the papers' CCS categories, we present effect size distributions in 12 CHI research fields. Through an additional qualitative analysis of 67 quantitative CHI'23 publications, we identify five categories of approaches that researchers take when interpreting effect size: Comparing test-specific values, assigning size labels, using a statistical or methodological reference frame, comparing different observations and interpreting for the big picture. Anna-Marie Ortloff, Florin Martius, Mischa Meier, Theo Sans-Raimbault, Lisa Geierhaas, Matthew Smith 0001 |
CHI | 6 |
| 2025 | "They are responsible for ensuring that I can continue to use the service." Investigating Users' Expectations Towards 2FA Recovery in GermanyabstractTwo-factor authentication is often recommended for increasing online security, and users often follow this by using their phones. If physical items become unavailable, there is a risk of losing access to the account due to missing authentication requirements. In such cases, users need a backup or help from the service. Previous work found no standardized approach to how services address this issue, assist users, or offer backup options. Until now, it is unclear how users handle backups and account recovery and what their expectations towards service providers are. To shed light on this, we conducted 16 interviews and a survey with 95 participants. We found that most had never considered how to access their accounts if the second factor was lost, and only a few had a backup plan. Instead, users often rely on website support, assuming that personal data will help them regain access. We give recommendations for services. Eva Tiefenau, Julia Angelika Grohs, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau |
CHI | 4 |
| 2025 | I never reuse passwords! Development and Validation of a Security and Privacy Social Desirability Scale (SP-SDS) for end users without a background in computer science
Laura Marie Abels, Matthew Smith 0001, Anna-Marie Ortloff |
SOUPS | 2 |
| 2025 | Replication: "No one can hack my mind" - 10 years later: An update and outlook on experts' and non-experts' security practices and advice
Anna-Marie Ortloff, Jenny Tang, Arthi Arumugam, Daniel Huschina, Lisa Geierhaas, Florin Martius, Luisa Jansen, Kolja von der Twer, Lilly Jungbluth, Matthew Smith 0001 |
SOUPS | 10 |
| 2025 | "Not the Right Question?" A Study on Attitudes Toward Client-Side Scanning with Security and Privacy Researchers and a U.S. Population SampleabstractFor decades, law enforcement and privacy advocates have struggled to find common ground regarding surveillance and privacy, resulting in the so-called Crypto Wars. When Apple announced it was planning to implement client-side scanning (CSS) in 2021 as a privacy-preserving compromise to detect known child sexual abuse material (CSAM), it received such intense pushback, especially from IT experts, that it dropped the plans within weeks. However, a study of the European population by ECPAT [1] and another of the German population by Geierhaas et al. [2] showed that despite concerns, the majority stated that they supported CSS for the detection of CSAM. This highlights a potential mismatch between “the majority” and “the experts.” To examine the different attitudes toward CSS further, we extend the work by Geierhaas in two ways. First, we conducted qualitative interviews with 19 IT security and privacy researchers at two major IT security conferences: the Symposium on Usable Privacy and Security (SOUPS) and the USENIX Security Symposium. In our second study, we replicated the German survey with a representative sample (age, gender, and state) from the USA. This was done both to examine possible cultural differences between Germany and the U.S. and to have a U.S. view to compare to our interview study. In this paper, we discuss key similarities and differences between the U.S. and German samples and contrast these with the researchers' views on the matter. Lisa Geierhaas, Florin Martius, Arthi Arumugam, Matthew Smith 0001 |
SP | 4 |
| 2023 | Less About Privacy: Revisiting a Survey about the German COVID-19 Contact Tracing AppabstractThe release of COVID-19 contact tracing apps was accompanied by a heated public debate with much focus on privacy concerns, e.g., possible government surveillance. Many papers studied people’s intended behavior to research potential features and uptake of the apps. Studies in Germany conducted before the app’s release, such as that by Häring et al., showed that privacy was an important factor in the intention to install the app. We conducted a follow-up study two months post-release to investigate the intention-behavior-gap, see how attitudes changed after the release, and capture reported behavior. Analyzing a quota sample (n=837) for Germany, we found that fewer participants mentioned privacy concerns post-release, whereas utility now plays a greater role. We provide further evidence that the results of intention-based studies should be handled with care when used for prediction purposes. Maximilian Häring, Eva Tiefenau, Matthew Smith 0001, Christian Tiefenau |
CHI | 3 |
| 2023 | Different Researchers, Different Results? Analyzing the Influence of Researcher Experience and Data Type During Qualitative Analysis of an Interview and Survey Study on Security AdviceabstractWhen conducting qualitative research it is necessary to decide how many researchers should be involved in coding the data: Is one enough or are more coders beneficial? To offer empirical evidence for this question, we designed a series of studies investigating qualitative coding. We replicated and extended a usable security and privacy study by Ion et al. to gather both simple survey data and complex interview data. We had a total of 65 students and seven researchers analyze different parts of this data. We analyzed the codebook creation process, similarity of outcomes, inter-rater reliability, and compared the student to the researcher outcomes. We also surveyed five years of SOUPS-PC members about their views on coding. The reviewers view on coding practices for complex and simple data are almost identical. However, our results suggest that the coding process can be different for the two types of data, with complex data benefiting more from interaction between coders. Anna-Marie Ortloff, Matthias Fassl, Alexander Ponticello, Florin Martius, Anne Mertens, Katharina Krombholz, Matthew Smith 0001 |
CHI | 7 |
| 2023 | A Usability Evaluation of AFL and libFuzzer with CS StudentsabstractIn top-tier companies and academia, fuzzing has established itself as a valuable tool for finding bugs. It is a tool created by experts for experts, and a lot of research is being invested into improving the power of fuzzing. However, the usability of fuzzing has not received much attention yet. To alleviate this, we evaluated the usability of two popular fuzzers: AFL and libFuzzer. In our fuzzing study, 47 computer science students each worked up to 20 hours in total. We found significant usability challenges for both fuzzers leading to only 17 participants who were able to finish all tasks. Even the successful participants struggled with some of the necessary steps and found them complex and confusing. While on the whole, AFL fared better than libFuzzer, both fuzzers have strengths and weaknesses and can be improved based on our results. Stephan Plöger, Mischa Meier, Matthew Smith 0001 |
CHI | 3 |
| 2023 | Evolution of Password Expiry in Companies: Measuring the Adoption of Recommendations by the German Federal Office for Information Security
Eva Tiefenau, Maximilian Häring, Matthew Smith 0001, Christian Tiefenau |
SOUPS | 3 |
| 2023 | Adventures in Recovery Land: Testing the Account Recovery of Popular Websites When the Second Factor is Lost
Eva Tiefenau, Maximilian Häring, Charlotte Theresa Mädler, Matthew Smith 0001, Christian Tiefenau |
SOUPS | 4 |
| 2023 | SoK: I Have the (Developer) Power! Sample Size Estimation for Fisher's Exact, Chi-Squared, McNemar's, Wilcoxon Rank-Sum, Wilcoxon Signed-Rank and t-tests in Developer-Centered Usable Security
Anna-Marie Ortloff, Christian Tiefenau, Matthew Smith 0001 |
SOUPS | 3 |
| 2023 | Attitudes towards Client-Side Scanning for CSAM, Terrorism, Drug Trafficking, Drug Use and Tax Evasion in GermanyabstractIn recent years, there have been a rising number of legislative efforts and proposed technical measures to weaken privacy-preserving technology, with the stated goal of countering serious crimes like child abuse. One of these proposed measures is Client-Side Scanning (CSS). CSS has been hotly debated both in the context of Apple stating their intention to deploy it in 2021 as well as EU legislation being proposed in 2022. Both sides of the argument state that they are working in the best interests of the people. To shed some light on this, we conducted a survey with a representative sample of German citizens. We investigated the general acceptance of CSS vs cloud-based scanning for different types of crimes and analyzed how trust in the German government and companies such as Google and Apple influenced our participants’ views. We found that, by and large, the majority of participants were willing to accept CSS measures to combat serious crimes such as child abuse or terrorism, but support dropped significantly for other illegal activities. However, the majority of participants who supported CSS were also worried about potential abuse, with only 20% stating that they were not concerned. These results suggest that many of our participants would be willing to have their devices scanned and accept some risks in the hope of aiding law enforcement. In our analysis, we argue that there are good reasons to not see this as a carte blanche for the introduction of CSS but as a call to action for the S&P community. More research is needed into how a population’s desire to prevent serious crime online can be achieved while mitigating the risks to privacy and society. Lisa Geierhaas, Fabian Otto, Maximilian Häring, Matthew Smith 0001 |
SP | 4 |
| 2022 | Testing Time Limits in Screener Questions for Online Surveys with ProgrammersabstractRecruiting study participants with programming skill is essential for researchers. As programming is not a common skill, recruiting programmers as participants in large numbers is challenging. Platforms like Amazon MTurk or Qualtrics offer to recruit participants with programming knowledge. As this is self-reported, participants without programming experience could still take part, either due to a misunderstanding or to obtain the study compensation. If these participants are not detected, the data quality will suffer. To tackle this, Danilova et al. [11] developed and tested screening tasks to detect non-programmers. Unfortunately, the most reliable screeners were also those that took the most time. Since screeners should take as little time as possible, we examine whether the introduction of time limits allows us to create more efficient (i.e., quicker but still reliable) screeners. Our results show that this is possible and we extend the pool of screeners and make recommendations on how to improve the process. Anastasia Danilova, Stefan Horstmann, Matthew Smith 0001, Alena Naiakshina |
ICSE | 3 |
| 2021 | Do you really code? Designing and Evaluating Screening Questions for Online Surveys with ProgrammersabstractRecruiting professional programmers in sufficient numbers for research studies can be challenging because they often cannot spare the time, or due to their geographical distribution and potentially the cost involved. Online platforms such as Clickworker or Qualtrics do provide options to recruit participants with programming skill; however, misunderstandings and fraud can be an issue. This can result in participants without programming skill taking part in studies and surveys. If these participants are not detected, they can cause detrimental noise in the survey data. In this paper, we develop screener questions that are easy and quick to answer for people with programming skill but difficult to answer correctly for those without. In order to evaluate our questionnaire for efficacy and efficiency, we recruited several batches of participants with and without programming skill and tested the questions. In our batch 42% of Clickworkers stating that they have programming skill did not meet our criteria and we would recommend filtering these from studies. We also evaluated the questions in an adversarial setting. We conclude with a set of recommended questions which researchers can use to recruit participants with programming skill from online platforms. Anastasia Danilova, Alena Naiakshina, Stefan Horstmann, Matthew Smith 0001 |
ICSE | 4 |
| 2020 | On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company DevelopersabstractEcological validity is a major concern in usable security studies with developers. Many studies are conducted with computer science (CS) students out of convenience, since recruiting professional software developers in sufficient numbers is very challenging. In a password-storage study, Naiakshina et al. (CHI'19) showed that CS students behave similarly to freelance developers recruited online. While this is a promising result for conducting developer studies with students, an open question remains: Do professional developers employed in companies behave similarly as well? To provide more insight into the ecological validity of recruiting students for security developer studies, we replicated the study of Naiakshina et al. with developers from diverse companies in Germany. We found that developers employed in companies performed better than students and freelancers in a direct comparison. However, treatment effects were found to be significant in all groups; the treatment effects on CS students also held for company developers. Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Matthew Smith 0001 |
CHI | 4 |
| 2020 | One size does not fit all: a grounded theory and online survey study of developer preferences for security warning typesabstractA wide range of tools exist to assist developers in creating secure software. Many of these tools, such as static analysis engines or security checkers included in compilers, use warnings to communicate security issues to developers. The effectiveness of these tools relies on developers heeding these warnings, and there are many ways in which these warnings could be displayed. Johnson et al. [46] conducted qualitative research and found that warning presentation and integration are main issues. We built on Johnson et al.'s work and examined what developers want from security warnings, including what form they should take and how they should integrate into their workflow and work context. To this end, we conducted a Grounded Theory study with 14 professional software developers and 12 computer science students as well as a focus group with 7 academic researchers to gather qualitative insights. To back up the theory developed from the qualitative research, we ran a quantitative survey with 50 professional software developers. Our results show that there is significant heterogeneity amongst developers and that no one warning type is preferred over all others. The context in which the warnings are shown is also highly relevant, indicating that it is likely to be beneficial if IDEs and other development tools become more flexible in their warning interactions with developers. Based on our findings, we provide concrete recommendations for both future research as well as how IDEs and other security tools can improve their interaction with developers. Anastasia Danilova, Alena Naiakshina, Matthew Smith 0001 |
ICSE | 3 |
| 2019 | A Usability Evaluation of Let's Encrypt and Certbot: Usable Security Done RightabstractThe correct configuration of HTTPS is a complex set of tasks, which many administrators have struggled with in the past. Let's Encrypt and Electronic Frontier Foundation's Certbot aim to improve the TLS ecosystem by offering free trusted certificates (Let's Encrypt) and by providing user-friendly support to configure and harden TLS (Certbot). Although adoption rates have increased, to date, there has been only a little scientific evidence of the actual usability and security benefits of this semi-automated approach. Therefore, we conducted a randomized control trial to evaluate the usability of Let's Encrypt and Certbot in comparison to the traditional certificate authority approach. We performed a within-subjects lab study with 31 participants. The study sheds light on the security and usability enhancements that Let's Encrypt and Certbot provide. We highlight how usability improvements aimed at administrators can have a large impact on security and discuss takeaways for Certbot and other security-related tasks that experts struggle with. Christian Tiefenau, Emanuel von Zezschwitz, Maximilian Häring, Katharina Krombholz, Matthew Smith 0001 |
CCS | 5 |
| 2019 | "If you want, I can store the encrypted password": A Password-Storage Field Study with Freelance DevelopersabstractIn 2017 and 2018, Naiakshina et al. (CCS'17, SOUPS'18) studied in a lab setting whether computer science students need to be told to write code that stores passwords securely. The authors' results showed that, without explicit prompting, none of the students implemented secure password storage. When asked about this oversight, a common answer was that they would have implemented secure storage - if they were creating code for a company. To shed light on this possible confusion, we conducted a mixed-methods field study with developers. We hired freelance developers online and gave them a similar password storage task followed by a questionnaire to gain additional insights into their work. From our research, we offer two contributions. First of all, we reveal that, similar to the students, freelancers do not store passwords securely unless prompted, they have misconceptions about secure password storage, and they use outdated methods. Secondly, we discuss the methodological implications of using freelancers and students in developer studies. Alena Naiakshina, Anastasia Danilova, Eva Tiefenau, Emanuel von Zezschwitz, Matthew Smith 0001 |
CHI | 5 |
| 2019 | In Encryption We Don't Trust: The Effect of End-to-End Encryption to the Masses on User PerceptionabstractWith WhatsApp's adoption of the Signal Protocol as its default, end-to-end encryption by the masses happened almost overnight. Unlike iMessage, WhatsApp notifies users that encryption is enabled, explicitly informing users about improved privacy. This rare feature gives us an opportunity to study people's understandings and perceptions of secure messaging pre-and post-mass messenger encryption (pre/post-MME). To study changes in perceptions, we compared the results of two mental models studies: one conducted in 2015 pre-MME and one in 2017 post-MME. Our primary finding is that users do not trust encryption as currently offered. When asked about encryption in the study, most stated that they had heard of encryption, but only a few understood the implications, even on a high level. Their consensus view was that no technical solution to stop skilled attackers from getting their data exists. Even with a major development, such as WhatsApp rolling out end-to-end encryption, people still do not feel well protected by their technology. Surprisingly, despite WhatsApp's end-to-end security info messages and the high media attention, the majority of the participants were not even aware of encryption. Most participants had an almost correct threat model, but don't believe that there is a technical solution to stop knowledgeable attackers to read their messages. Using technology made them feel vulnerable. Sergej Dechand, Alena Naiakshina, Anastasia Danilova, Matthew Smith 0001 |
EuroS&P | 4 |
| 2019 | "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSabstractHTTPS is one of the most important protocols used to secure communication and is, fortunately, becoming more pervasive. However, especially the long tail of websites is still not sufficiently secured. HTTPS involves different types of users, e.g., end users who are forced to make critical security decisions when faced with warnings or administrators who are required to deal with cryptographic fundamentals and complex decisions concerning compatibility. In this work, we present the first qualitative study of both end user and administrator mental models of HTTPS. We interviewed 18 end users and 12 administrators; our findings reveal misconceptions about security benefits and threat models from both groups. We identify protocol components that interfere with secure configurations and usage behavior and reveal differences between administrator and end user mental models. Our results suggest that end user mental models are more conceptual while administrator models are more protocol-based. We also found that end users often confuse encryption with authentication, significantly underestimate the security benefits of HTTPS, and ignore and distrust security indicators while administrators often do not understand the interplay of functional protocol components. Based on the different mental models, we discuss implications and provide actionable recommendations for future designs of user interfaces and protocols. Katharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith 0001, Emanuel von Zezschwitz |
IEEE Symposium on Security and Privacy | 4 |
| 2017 | Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyabstractPasswords are still a mainstay of various security systems, as well as the cause of many usability issues. For end-users, many of these issues have been studied extensively, highlighting problems and informing design decisions for better policies and motivating research into alternatives. However, end-users are not the only ones who have usability problems with passwords! Developers who are tasked with writing the code by which passwords are stored must do so securely. Yet history has shown that this complex task often fails due to human error with catastrophic results. While an end-user who selects a bad password can have dire consequences, the consequences of a developer who forgets to hash and salt a password database can lead to far larger problems. In this paper we present a first qualitative usability study with 20 computer science students to discover how developers deal with password storage and to inform research into aiding developers in the creation of secure password systems. Alena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog, Sergej Dechand, Matthew Smith 0001 |
CCS | 6 |
| 2017 | Obstacles to the Adoption of Secure Communication ToolsabstractThe computer security community has advocated widespread adoption of secure communication tools to counter mass surveillance. Several popular personal communication tools (e.g., WhatsApp, iMessage) have adopted end-to-end encryption, and many new tools (e.g., Signal, Telegram) have been launched with security as a key selling point. However it remains unclear if users understand what protection these tools offer, and if they value that protection. In this study, we interviewed 60 participants about their experience with different communication tools and their perceptions of the tools' security properties. We found that the adoption of secure communication tools is hindered by fragmented user bases and incompatible tools. Furthermore, the vast majority of participants did not understand the essential concept of end-to-end encryption, limiting their motivation to adopt secure tools. We identified a number of incorrect mental models that underpinned participants' beliefs. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Anastasia Danilova, Alena Naiakshina, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 6 |
| 2016 | SoK: Lessons Learned from Android Security Research for Appified Software PlatformsabstractAndroid security and privacy research has boomed in recent years, far outstripping investigations of other appified platforms. However, despite this attention, research efforts are fragmented and lack any coherent evaluation framework. We present a systematization of Android security and privacy research with a focus on the appification of software systems. To put Android security and privacy research into context, we compare the concept of appification with conventional operating system and software ecosystems. While appification has improved some issues (e.g., market access and usability), it has also introduced a whole range of new problems and aggravated some problems of the old ecosystems (e.g., coarse and unclear policy, poor software development practices). Some of our key findings are that contemporary research frequently stays on the beaten path instead of following unconventional and often promising new routes. Many security and privacy proposals focus entirely on the Android OS and do not take advantage of the unique features and actors of an appified ecosystem, which could be used to roll out new security mechanisms less disruptively. Our work highlights areas that have received the larger shares of attention, which attacker models were addressed, who is the target, and who has the capabilities and incentives to implement the countermeasures. We conclude with lessons learned from comparing the appified with the old world, shedding light on missed opportunities and proposing directions for future research. Yasemin Acar, Michael Backes 0001, Sven Bugiel, Sascha Fahl, Patrick D. McDaniel, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 6 |
| 2016 | Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyabstractAnalysis of malicious software is an essential task in computer security, it provides the necessary understanding to devise effective countermeasures and mitigation strategies. The level of sophistication and complexity of current malware continues to evolve significantly, as the recently discovered "Regin" malware family strikingly illustrates. This complexity makes the already tedious and time-consuming task of manual malware reverse engineering even more difficult and challenging. Decompilation can accelerate this process by enabling analysts to reason about a high-level, more abstract from of binary code. While significant advances have been made, state-of-the-art decompilers still produce very complex and unreadable code and malware analysts still frequently go back to analyzing the assembly code. In this paper, we present several semantics-preserving code transformations to make the decompiled code more readable, thus helping malware analysts understand and combat malware. We have implemented our optimizations as extensions to the academic decompiler DREAM. To evaluate our approach, we conducted the first user study to measure the quality of decompilers for malware analysis. Our study includes 6 analysis tasks based on real malware samples we obtained from independent malware experts. We evaluate three decompilers: the leading industry decompiler Hex-Rays, the state-of-the-art academic decompiler DREAM, and our usability-optimized decompiler DREAM++. The results show that our readability improvements had a significant effect on how well our participants could analyze the malware samples. DREAM++ outperforms both Hex-Rays and DREAM significantly. Using DREAM++ participants solved 3x more tasks than when using Hex-Rays and 2x more tasks than when using DREAM. Khaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 4 |
| 2016 | An Empirical Study of Textual Key-Fingerprint Representations
Sergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar, Sascha Fahl, Matthew Smith 0001 |
USENIX Security Symposium | 6 |
| 2015 | POSTER: Secure Chat for the Masses? User-centered Security to the RescueabstractIn light of recent revelations of mass state surveillance of phone and Internet communications, many solutions now claim to provide secure messaging. This includes both a broad range of new projects and several widely adopted applications that have added security features. However, despite the demand for better solutions, there is no clear winner in the race for widespread development and deployment of messaging products. Recently, the Electronic Frontier Foundation evaluated dozens of messaging tools based on security best practices, and publicized the results via the Secure Messaging Scorecard. Our goal is to expand the scorecard by evaluating messaging tools on a range of usefulness (utility and usability) attributes. Ruba Abu-Salma, M. Angela Sasse, Joseph Bonneau, Matthew Smith 0001 |
CCS | 4 |
| 2015 | VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code AuditsabstractDespite the security community's best effort, the number of serious vulnerabilities discovered in software is increasing rapidly. In theory, security audits should find and remove the vulnerabilities before the code ever gets deployed. However, due to the enormous amount of code being produced, as well as a the lack of manpower and expertise, not all code is sufficiently audited. Thus, many vulnerabilities slip into production systems. A best-practice approach is to use a code metric analysis tool, such as Flawfinder, to flag potentially dangerous code so that it can receive special attention. However, because these tools have a very high false-positive rate, the manual effort needed to find vulnerabilities remains overwhelming. In this paper, we present a new method of finding potentially dangerous code in code repositories with a significantly lower false-positive rate than comparable systems. We combine code-metric analysis with metadata gathered from code repositories to help code review teams prioritize their work. The paper makes three contributions. First, we conducted the first large-scale mapping of CVEs to GitHub commits in order to create a vulnerable commit database. Second, based on this database, we trained a SVM classifier to flag suspicious commits. Compared to Flawfinder, our approach reduces the amount of false alarms by over 99 % at the same level of recall. Finally, we present a thorough quantitative and qualitative analysis of our approach and discuss lessons learned from the results. We will share the database as a benchmark for future research and will also provide our analysis tool as a web service. Henning Perl, Sergej Dechand, Matthew Smith 0001, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, Yasemin Acar |
CCS | 3 |
| 2015 | No More Gotos: Decompilation Using Pattern-Independent Control-Flow Structuring and Semantic-Preserving Transformations
Khaled Yakdan, Sebastian Eschweiler, Elmar Gerhards-Padilla, Matthew Smith 0001 |
NDSS | 4 |
| 2015 | Where Have You Been? Using Location-Based Security Questions for Fallback Authentication
Alina Hang, Alexander De Luca, Matthew Smith 0001, Heinrich Hußmann |
SOUPS | 3 |
| 2015 | SoK: Secure MessagingabstractMotivated by recent revelations of widespread state surveillance of personal communication, many solutions now claim to offer secure and private messaging. This includes both a large number of new projects and many widely adopted tools that have added security features. The intense pressure in the past two years to deliver solutions quickly has resulted in varying threat models, incomplete objectives, dubious security claims, and a lack of broad perspective on the existing cryptographic literature on secure communication. In this paper, we evaluate and systematize current secure messaging solutions and propose an evaluation framework for their security, usability, and ease-of-adoption properties. We consider solutions from academia, but also identify innovative and promising approaches used "in-the-wild" that are not considered by the academic literature. We identify three key challenges and map the design landscape for each: trust establishment, conversation security, and transport privacy. Trust establishment approaches offering strong security and privacy features perform poorly from a usability and adoption perspective, whereas some hybrid approaches that have not been well studied in the academic literature might provide better trade-offs in practice. In contrast, once trust is established, conversation security can be achieved without any user involvement in most two-party conversations, though conversations between larger groups still lack a good solution. Finally, transport privacy appears to be the most difficult problem to solve without paying significant performance penalties. Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg 0001, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 7 |
| 2015 | To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections
Marten Oltrogge, Yasemin Acar, Sergej Dechand, Matthew Smith 0001, Sascha Fahl |
USENIX Security Symposium | 4 |
| 2014 | Why eve and mallory (also) love webmasters: a study on the root causes of SSL misconfigurationsabstractPrevious research showed that the SSL infrastructure is a fragile system: X.509 certificate validation fails for a non-trivial number of HTTPS-enabled websites resulting in SSL warning messages presented to users. Studies revealed that warning messages do not provide easy-to-understand information or are ignored by webbrowser users. SSL warning messages are a critical component in the HTTPS infrastructure and many attempts have been made to improve these warning messages. However, an important question has not received sufficient attention yet: Why do webmasters (deliberately) deploy non-validating, security-critical X.509 certificates on publicly available websites? In this paper, we conduct the first study with webmasters operating non-validating X.509 certificates to understand their motives behind deploying those certificates. We extracted the non-validating certificates from Google's webcrawler body of X.509 certificates, informed webmasters about the problem with the X.509 certificate configuration on their website and invited a random sample of the respective webmasters to participate in our study. 755 webmasters participated, allowing us insight into their motives. While one third of them admitted to having misconfigured their webserver accidentally, two thirds of them gave reasons for deliberately using a non-validating X.509 certificate. Sascha Fahl, Yasemin Acar, Henning Perl, Matthew Smith 0001 |
AsiaCCS | 4 |
| 2014 | Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful AttackersabstractMobile devices are evolving as the dominant computing platform and consequently application repositories and app markets are becoming the prevalent paradigm for deploying software. Due to their central and trusted position in the software ecosystem, coerced, hacked or malicious app markets pose a serious threat to user security. Currently, there is little that hinders a nation state adversary (NSA) or other powerful attackers from using such central and trusted points of software distribution to deploy customized (malicious) versions of apps to specific users. Due to intransparencies in the current app installation paradigm, this kind of attack is extremely hard to detect. Sascha Fahl, Sergej Dechand, Henning Perl, Felix Fischer 0001, Jaromir Smrcek, Matthew Smith 0001 |
CCS | 6 |
| 2014 | Using personal examples to improve risk communication for security & privacy decisionsabstractIT security systems often attempt to support users in taking a decision by communicating associated risks. However, a lack of efficacy as well as problems with habituation in such systems are well known issues. In this paper, we propose to leverage the rich set of personal data available on smartphones to communicate risks using personalized examples. Examples of private information that may be at risk can draw the users' attention to relevant information for a decision and also improve their response. We present two experiments that validate this approach in the context of Android app permissions. Private information that becomes accessible given certain permissions is displayed when a user wants to install an app, demonstrating the consequences this installation might have. We find that participants made more privacy-conscious choices when deciding which apps to install. Additionally, our results show that our approach causes a negative affect in participants, which makes them pay more attention. Marian Harbach, Markus Hettig, Susanne Weber, Matthew Smith 0001 |
CHI | 4 |
| 2014 | Now you see me, now you don't: protecting smartphone authentication from shoulder surfersabstractIn this paper, we present XSide, an authentication mechanism that uses the front and the back of smartphones to enter stroke-based passwords. Users can switch sides during input to minimize the risk of shoulder surfing. We performed a user study (n = 32) to explore how switching sides during authentication affects usability and security of the system. The results indicate that switching the sides increases security while authentication speed stays relatively fast (≤ 4 seconds). The paper furthermore provides insights on accuracy of eyes-free input (as used in XSide) and shows how 3D printed prototype cases can improve the back-of-device interaction experience. Alexander De Luca, Marian Harbach, Emanuel von Zezschwitz, Max-Emanuel Maurer, Bernhard Ewald Slawik, Heinrich Hußmann, Matthew Smith 0001 |
CHI | 7 |
| 2014 | Who's Afraid of Which Bad Wolf? A Survey of IT Security Risk AwarenessabstractThe perception of risk has been established as an important part of the study of human aspects of security research. Similarly, risk awareness is often considered a central precursor for the adoption of security mechanisms and how people use them and interact with them. However, the state of risk awareness in users during their everyday use of the modern Internet has not been studied in detail. While it is well known that users have a limited "budget" for security behavior and that trying to coerce them into considering additional risks does not work well, it remains unclear which risks are on users' minds and therefore already accounted for in terms of their budget. Hence, assessing which risks and which consequences users currently perceive when using information technology is an important and currently overlooked foundation to shape usability aspects of IT security mechanisms. In this paper, we present a survey of risk and consequence awareness in users, analyze how this may influence the current lack of adoption for improved security measures, and make recommendations how this situation can be alleviated. Marian Harbach, Sascha Fahl, Matthew Smith 0001 |
CSF | 3 |
| 2014 | It's a Hard Lock Life: A Field Study of Smartphone (Un)Locking Behavior and Risk Perception
Marian Harbach, Emanuel von Zezschwitz, Andreas Fichtner, Alexander De Luca, Matthew Smith 0001 |
SOUPS | 5 |
| 2014 | Privacy/performance trade-off in private search on bio-medical data
Henning Perl, Yassene Mohammed, Michael Brenner 0003, Matthew Smith 0001 |
Future Gener. Comput. Syst. | 4 |
| 2013 | Caching oblivious memory access: an extension to the HCRYPT virtual machineabstractEfficient homomorphic encryption enables the construction of an encrypted computer system. Previous work has shown how this can be achieved using only arithmetic representations of simple demultiplexer circuits. This poster extends the results by introducing a caching mechanism for oblivious memory access, by far the most time-consuming building block of a recently proposed sample machine architecture. The construction allows to significantly accelerate homomorphically encrypted machine operation while still preserving obliviousness of memory access, control unit operation and functional components. Michael Brenner 0003, Matthew Smith 0001 |
CCS | 2 |
| 2013 | Rethinking SSL development in an appified worldabstractThe Secure Sockets Layer (SSL) is widely used to secure data transfers on the Internet. Previous studies have shown that the state of non-browser SSL code is catastrophic across a large variety of desktop applications and libraries as well as a large selection of Android apps, leaving users vulnerable to Man-in-the-Middle attacks (MITMAs). To determine possible causes of SSL problems on all major appified platforms, we extended the analysis to the walled-garden ecosystem of iOS, analyzed software developer forums and conducted interviews with developers of vulnerable apps. Our results show that the root causes are not simply careless developers, but also limitations and issues of the current SSL development paradigm. Based on our findings, we derive a proposal to rethink the handling of SSL in the appified world and present a set of countermeasures to improve the handling of SSL using Android as a blueprint for other platforms. Our countermeasures prevent developers from willfully or accidentally breaking SSL certificate validation, offer support for extended features such as SSL Pinning and different SSL validation infrastructures, and protect users. We evaluated our solution against 13,500 popular Android apps and conducted developer interviews to judge the acceptance of our approach and found that our solution works well for all investigated apps and developers. Sascha Fahl, Marian Harbach, Henning Perl, Markus Koetter, Matthew Smith 0001 |
CCS | 5 |
| 2013 | On the Acceptance of Privacy-Preserving Authentication Technology: The Curious Case of National Identity Cards
Marian Harbach, Sascha Fahl, Matthias Rieger, Matthew Smith 0001 |
Privacy Enhancing Technologies | 4 |
| 2013 | Selective cloaking: Need-to-know for location-based appsabstractCurrently location privacy settings of mobile operating systems are limited to the option of enabling or disabling the use of location completely or on a per-app basis. When location use is allowed, users always reveal their location in full precision even to apps that do not need it. For instance, weather forecast apps and navigation apps both get the most exact location a device can determine. Up to now, mobile privacy research was focused on the recognition and prevention of disclosure of private data. This includes location data, but does not extend to privacy in use cases where users do want to disclose their location - but not in full detail. However, the increasing adoption of smartphones entails the increasing use of location-based services as well. Users want to use these services, but have privacy concerns. As many location-based services do not require exact locations, user privacy can be increased by only disclosing location in such detail as required for the respective service to function. To enable users to restrict the accuracy of location data that is revealed to apps, we created a location privacy framework that allows per-app location obfuscation. The framework allows easy integration of different obfuscation algorithms into the Android system. We present both on-device obfuscation and service-based obfuscation and evaluate our framework. Benjamin Henne, Christian Kater, Matthew Smith 0001, Michael Brenner 0003 |
PST | 3 |
| 2013 | On the ecological validity of a password studyabstractThe ecological validity of password studies is a complex topic and difficult to quantify. Most researchers who conduct password user studies try to address the issue in their study design. However, the methods researchers use to try to improve ecological validity vary and some methods even contradict each other. One reason for this is that the very nature of the problem of ecological validity of password studies is hard to study, due to the lack of ground truth. In this paper, we present a study on the ecological validity of password studies designed specifically to shed light on this issue. We were able to compare the behavior of 645 study participants with their real world password choices. We conducted both online and laboratory studies, under priming and non-priming conditions, to be able to evaluate the effects of these different forms of password studies. While our study is able to investigate only one specific password environment used by a limited population and thus cannot answer all questions about ecological validity, it does represent a first important step in judging the impact of ecological validity on password studies. Sascha Fahl, Marian Harbach, Yasemin Acar, Matthew Smith 0001 |
SOUPS | 4 |
| 2013 | SnapMe if you can: privacy threats of other peoples' geo-tagged media and what we can do about itabstractThe amount of media uploaded to the Web is still rapidly expanding. The ease-of-use of modern smartphones in combination with the proliferation of high-speed mobile networks facilitates a culture of spontaneous and often carefree sharing of user-generated content, especially photos and videos. An increasing number of modern devices are capable of embedding location information and other metadata into created content. However, currently there is not much user awareness of possible privacy consequences of such data. While in most cases users upload their own media consciously, the flood of media uploaded by others is so huge that it is almost impossible for users to stay aware of all media that might be relevant to them. Current social network services and photo-sharing sites mainly focus on the privacy of users' own media in terms of access control, but offer few possibilities to deal with privacy implications created by other users' actions. We conducted an online survey with 414 participants. The results show that users would like to get more information about media shared by others. Based on an analysis of prevalent sharing services like Flickr, Facebook, or Google+ and an analysis of metadata of three different sets of crawled photos, we discuss privacy implications and potentials of the emerging trend of (geo-)tagged media. Finally, we present a novel concept on how location information can actually help users to control the flood of potentially infringing or interesting media. Benjamin Henne, Christian Szongott, Matthew Smith 0001 |
WISEC | 3 |
| 2012 | Mobile Evil Twin Malnets - The Worst of Both Worlds
Christian Szongott, Benjamin Henne, Matthew Smith 0001 |
CANS | 3 |
| 2012 | Why eve and mallory love android: an analysis of android SSL (in)securityabstractMany Android apps have a legitimate need to communicate over the Internet and are then responsible for protecting potentially sensitive data during transit. This paper seeks to better understand the potential security threats posed by benign Android apps that use the SSL/TLS protocols to protect data they transmit. Since the lack of visual security indicators for SSL/TLS usage and the inadequate use of SSL/TLS can be exploited to launch Man-in-the-Middle (MITM) attacks, an analysis of 13,500 popular free apps downloaded from Google's Play Market is presented. Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith 0001, Lars Baumgärtner, Bernd Freisleben |
CCS | 4 |
| 2012 | Towards measuring warning readabilityabstractSecurity systems frequently rely on warning messages to convey important information, especially when a machine is not able to assess a situation automatically. For a long time, researchers have investigated the effects of warning messages to optimise their reception by a user. Design guidelines and best practises help the developer or interaction designer to adequately channel urgent information. In this poster, we investigate the application of readability measures to assess the difficulty of the descriptive text in warning messages. Adapting such a measure to fit the needs of warning message design allows objective feedback on the quality of a warning's descriptive text. An automated process will be able to assist software developers and designers in creating more readable and hence more understandable security warning messages. We present an initial exploration of the use of readability measures on the descriptive text of warning messages. Existing measures were evaluated on warning messages extracted from current browsers using an experimental study with 15 undergrad students. While our data did not yield conclusive results yet, we argue that readability measures can provide valuable assistance when implementing security systems. Marian Harbach, Sascha Fahl, Thomas Muders, Matthew Smith 0001 |
CCS | 4 |
| 2012 | Fast confidential search for bio-medical data using Bloom filters and Homomorphic CryptographyabstractData protection is a challenge when outsourcing medical analysis, especially if one is dealing with patient related data. While securing transfer channels is possible using encryption mechanisms, protecting the data during analyses is difficult as it usually involves processing steps on the plain data. A common use case in bioinformatics is when a scientist searches for a biological sequence of amino acids or DNA nucleotides in a library or database of sequences to identify similarities. Most such search algorithms are optimized for speed with less or no consideration for data protection. Fast algorithms are especially necessary because of the immense search space represented for instance by the genome or proteome of complex organisms. We propose a new secure exact term search algorithm based on Bloom filters. Our algorithm retains data privacy by using Obfuscated Bloom filters while maintaining the performance needed for real-life applications. The results can then be further aggregated using Homomorphic Cryptography to allow exact-match searching. The proposed system facilitates outsourcing exact term search of sensitive data to on-demand resources in a way which conforms to best practice of data protection. Henning Perl, Yassene Mohammed, Michael Brenner 0003, Matthew Smith 0001 |
eScience | 4 |
| 2012 | Towards privacy-preserving access control with hidden policies, hidden credentials and hidden decisionsabstractThe growing adoption of cloud technology in sensitive application domains, such as medicine, gives rise to new problems in maintaining the privacy of the involved parties during authorisation. In such domains, an honest but curious service provider can derive sensitive information purely from the authorisation process. In this paper, we present a detailed discussion of this rising problem including a concrete example and argue the need for the combination of hidden credentials, hidden policies and hidden decisions. We then show that mechanisms explored in previous work only cover individual aspects of this problem, but do not achieve a comprehensive solution without making restrictive assumptions on the resources, policies or subjects to be protected. As a first step towards solving this problem, we introduce an abstract foundation for using homomorphic cryptography to provide the required combination of privacy as a wrapper for other access control (AC) mechanisms. We achieve hidden policies, hidden credentials and even hidden access control decisions, so that the subject of an AC request only learns whether or not access was granted. Meanwhile, the provider of a resource learns nothing at the policy decision point and only access frequencies for individual resources at the policy enforcement point. We postulate that this is the maximum achievable level of protection in the authorisation process, without making restrictive assumptions on the resources, policies or subjects to be protected. Once homomorphic cryptography achieves satisfactory performance, our model can be used to transparently add this protection to other access control models. Marian Harbach, Sascha Fahl, Michael Brenner 0003, Thomas Muders, Matthew Smith 0001 |
PST | 5 |
| 2012 | Practical Applications of Homomorphic Encryption
Michael Brenner 0003, Henning Perl, Matthew Smith 0001 |
SECRYPT | 3 |
| 2012 | Helping Johnny 2.0 to encrypt his Facebook conversationsabstractSeveral billion Facebook messages are sent every day. While there are many solutions to email security whose usability has been extensively studied, little work has been done in the area of message security for Facebook and even less on the usability aspects in this area. To evaluate the need for such a mechanism, we conducted a screening study with 514 participants, which showed a clear desire to protect private messages on Facebook. We therefore proceeded to analyse the usability of existing approaches and extracted key design decisions for further evaluation. Based on this analysis, we conducted a laboratory study with 96 participants to analyse different usability aspects and requirements of a Facebook message encryption mechanism. Two key findings of our study are that automatic key management and key recovery capabilities are important features for such a mechanism. Following on from these studies, we designed and implemented a usable service-based encryption mechanism for Facebook conversations. In a final study with 15 participants, we analysed the usability of our solution. All participants were capable of successfully encrypting their Facebook conversations without error when using our service, and the mechanism was perceived as usable and useful. The results of our work suggest that in the context of the social web, new security/usability trade-offs can be explored to protect users more effectively. Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith 0001, Uwe Sander |
SOUPS | 4 |
| 2012 | How Practical is Homomorphically Encrypted Program Execution? An Implementation and Performance EvaluationabstractHomomorphic cryptography has received a lot of attention due to potentially ground breaking advances in cryptography. However it is also surrounded by a lot of hyperbole such as "ground breaking advances", "this will solve all Cloud computing problems" to "it is completely impractical" and "it will never work for real world problems". In previous work we showed how homomorphic encryption can be used to execute arbitrary programs in encrypted space, showing that at least in theory real world problems can be computed protected by homomorphic cryptography without losing generality. In this paper we expand our work to evaluate how practical current homomorphic cryptography based on the Smart-Vercauteren system is for executing arbitrary programs on untrusted resources. For this we present the implementation of a method to compute non-linear secret programs on an untrusted resource using encrypted circuits embedded in an encrypted virtual machine. We successively show how a processor architecture using encrypted circuits can be implemented so it can support read and write memory access, dynamic parameters and non-linear programs that render branch-decisions at runtime. The system comprises the runtime environment for program execution and an assembler to generate the encrypted machine code. We present performance evaluation of the sub-components as well as the complete system. The system represents a flexible prototype for homomorphic program execution in software and system architecture. Michael Brenner 0003, Henning Perl, Matthew Smith 0001 |
TrustCom | 3 |
| 2012 | Confidentiality as a Service - Usable Security for the CloudabstractThere is an increasing number of easy-to-use cloud services to store and share information with others. Facebook, Dropbox, iCloud, Googlemail, Amazon S3, Windows SkyDrive and similar services encourage users to entrust the companies' servers with a large variety of information: from their holiday pictures to corporate documents. However, both private and corporate users commonly fail to take account of possible privacy consequences. Even though there are approaches to provide confidentiality for the users' data in the cloud, these are not widely adopted due to both awareness and usability issues. Therefore, we propose the novel Confidentiality as a Service (CaaS) paradigm to provide usable confidentiality and integrity for the bulk of users, for whom the current security mechanisms are too complex or require too much effort. The CaaS paradigm combines data security with usability by design and integrates effortlessly into available cloud service applications and workflows. We leverage the splitting of trust between the cloud service provider and one or more CaaS providers to improve usability. CaaS focuses on unobtrusive confidentiality by hiding all cryptographic artefacts from the prevalently non-technical users. Data protection is based on symmetric encryption and invisible key-management mechanisms. We present an integration for multiple popular cloud services to demonstrate the seamless applicability of CaaS. Sascha Fahl, Marian Harbach, Thomas Muders, Matthew Smith 0001 |
TrustCom | 4 |
| 2012 | Evaluating the threat of epidemic mobile malwareabstractWhile mobile malware has played a relatively small role compared to the behemoth of desktop malware, the changes both in the capability as well as in the proliferation of the mobile devices will steadily increase the attractiveness of mobile devices as resources to be attacked. The increased usage and connectivity of mobile devices opens up a much larger set of attack vectors to compromise these devices. In this paper, we discuss how the new features of mobile devices opens up the capability to create a new generation of mobile malware which is capable of realistically spreading epidemically on a fully mobile infection vector. We present a prototype of such a mobile malware that uses these features to replicate itself and spread over a mobile device-to-device vector. Using simulations we give quantitative support for the number of mobile devices and conditions needed to for an epidemic spread of mobile malware and present infection scenarios in downtown Chicago. Our results show that the recent growth and market dominance of just a handful of mobile phone companies and the trend towards mobile operating systems monoculture has already created a viable substrate for epidemic mobile malware. Christian Szongott, Benjamin Henne, Matthew Smith 0001 |
WiMob | 3 |
| 2011 | Request/Response Aspects for Web Services
Ernst Juhnke, Dominik Seiler, Ralph Ewerth, Matthew Smith 0001, Bernd Freisleben |
CAiSE | 4 |
| 2011 | Poster: an implementation of the fully homomorphic smart-vercauteren crypto-system
Henning Perl, Michael Brenner 0003, Matthew Smith 0001 |
CCS | 3 |
| 2011 | A Smart-gentry based Software System for Secret Program Execution
Michael Brenner 0003, Jan Wiebelitz, Gabriele von Voigt, Matthew Smith 0001 |
SECRYPT | 4 |
| 2011 | Secure mobile communication via identity-based cryptography and server-aided computations
Matthew Smith 0001, Christian Schridde, Björn Agel, Bernd Freisleben |
J. Supercomput. | 1 |
| 2010 | Metabolic Flux Analysis in the CloudabstractThe MapReduce pattern popularized by Google has successfully been utilized in several scientific applications. In this paper, it is investigated whether a MapReduce approach utilizing on-demand resources from a Cloud is beneficial to perform simulation tasks in the area of Systems Biology and whether it can be seamlessly integrated into a service-oriented scientific workflow framework. In particular, an Amazon Elastic Map Reduce Cloud implementation of the 13C-MFA (Metabolix Flux Analysis) Monte Carlo bootstrap approach aimed at the integration into an existing BPEL-based scientific workflow system is presented. A comparison of a 64 node MapReduce cluster with a single node computation approach reveals a total performance gain up to a factor of 14, with a total cost for on-demand resources of $11. The most critical factor in terms of performance is I/O, i.e. our application suffers from the fact that I/O operations on many small files are expensive using Amazon S3 and the Hadoop DFS. Tolga Dalman, Tim Dörnemann, Ernst Juhnke, Michael Weitzel, Matthew Smith 0001, Wolfgang Wiechert, Katharina Nöh, Bernd Freisleben |
eScience | 5 |
| 2010 | Early defense: enabling attribute-based authorization in Grid firewallsabstractIn today's distributed computing environments, like Grids and Clouds, authentication and authorization decisions take place in the middleware or on the compute and storage resources themselves. Thus, in both cases the decision is felled within the local network of the hosting organization. This is due to several drawbacks in common firewalls. For one, most firewalls only utilize the tupel of IP addresses, port numbers and protocol parameters to decide which connection are legitimate and which are not. This offers minimal configurability, which in complex environments like the Grid or the Cloud is not sufficient for optimal fine grained decisions. Also, the inability of application level firewalls to deal with dynamically opened server ports for encrypted connections like they are in use by GridFTP require very lax firewall rules to be set, if the Grid or Cloud is to operate unhindered. Jan Wiebelitz, Michael Brenner 0003, Christopher Kunz, Matthew Smith 0001 |
HPDC | 4 |
| 2010 | Rethinking Algorithm Design and Development in Speech ProcessingabstractSpeech processing is typically based on a set of complex algorithms requiring many parameters to be specified. When parts of the speech processing chain do not behave as expected, trial and error is often the only way to investigate the reasons. In this paper, we present a research methodology to analyze unexpected algorithmic behavior by making (intermediate) results of the speech processing chain perceivable and intuitively comprehensible by humans. The workflow of the process is explicated using a real-world example leading to considerable improvements in speaker clustering. The described methodology is supported by a software toolbox available for download. Thilo Stadelmann, Matthew Smith 0001, Ralph Ewerth, Bernd Freisleben |
ICPR | 3 |
| 2010 | Efficient Distribution of Virtual Machines for Cloud ComputingabstractThe commercial success of Cloud computing and recent developments in Grid computing have brought platform virtualization technology into the field of high performance computing. Virtualization offers both more flexibility and security through custom user images and user isolation. In this paper, we deal with the problem of distributing virtual machine (VM) images to a set of distributed compute nodes in a Cross-Cloud computing environment, i.e., the connection of two or more Cloud computing sites. Ambrust et al. identified data transfer bottlenecks as one of the obstacles Cloud computing has to solve to be a commercial success. Several methods for distributing VM images are presented, and optimizations based on copy on write layers are discussed. The performance of the presented solutions and the security overhead is evaluated. Matthias Schmidt 0001, Niels Fallenbeck, Matthew Smith 0001, Bernd Freisleben |
PDP | 3 |
| 2009 | A Streaming Intrusion Detection System for Grid Computing EnvironmentsabstractIn this paper, a novel architecture for a streaming intrusion detection system for Grid computing environments is presented. Detection mechanisms based on traditional log-files or single host databases are replaced by a streaming database approach. The streaming architecture allows processing of temporal attack data across multiple sites and offers the potential for performance benefits in large scale systems, since data is processed during its natural flow and only stored as long as necessary for analysis. Two cross-site example attacks in a Grid environment and the streaming detection logic for these attacks are presented to illustrate the approach. Experimental results of a prototypical implementation are presented. Matthew Smith 0001, Fabian Schwarzer, Marian Harbach, Thomas Noll 0003, Bernd Freisleben |
HPCC | 1 |
| 2009 | TrueIP: prevention of IP spoofing attacks using identity-based cryptographyabstractIn this paper, TrueIP--a system to prevent IP spoofing using identity-based cryptography--is presented. TrueIP is based on a new identity-based signature scheme to allow verification of an IP address without relying on a certificate or a public key infrastructure. It does not require changes or restrictions to the Internet routing protocol, is incrementally deployable, and offers protection from denial-of-service attacks based on IP spoofing. Implementation issues for practical deployment are discussed. Measurements of the TrueIP computation times for signature generation and verification are presented. Furthermore, the management overhead and bandwidth consumption to achieve proof of legitimate IP address possession and verification is compared with a standard Public Key Infrastructure approach using X.509 certificates signed by a Certificate Authority. Christian Schridde, Matthew Smith 0001, Bernd Freisleben |
SIN | 2 |
| 2009 | Secure on-demand grid computing
Matthew Smith 0001, Matthias Schmidt 0001, Niels Fallenbeck, Tim Dörnemann, Christian Schridde, Bernd Freisleben |
Future Gener. Comput. Syst. | 1 |
| 2008 | Composition and Execution of Secure Workflows in WSRF-GridsabstractBPEL is the de-facto standard for business process modeling in today's enterprises and is a promising candidate for the integration of business and Grid applications. While BPEL works well for traditional web services, it has a number of drawbacks with respect to the more complex world of WSRF- based Grid computing, especially where security is concerned. In this paper, a solution that extends the BPEL security approach to encompass secure Grid application interactions is presented. The proposed approach is capable of handling both web service and Grid service resources and their corresponding security mechanisms. The BPEL language is extended by security-related settings. An implementation of a GSI-compliant BPEL engine that can also manage the lifetime of proxy certificates is presented. Tim Dörnemann, Matthew Smith 0001, Bernd Freisleben |
CCGRID | 2 |
| 2008 | Securing stateful grid servers through virtual server rotationabstractThe Grid computing paradigm is aimed at providing seamless access to different kinds of resources, such as compute clusters, data, special appliances and even people. Like most complex IT systems, Grid middleware systems exhibit a number of security problems, and there will always be attacks that are unknown and can circumvent even the best security measures and intrusion detection systems. This creates the requirement that Grid environments should be equipped with intrusion tolerance mechanisms as well as with the traditional intrusion prevention and intrusion detection mechanisms. In this paper, we present a new intrusion tolerance approach which improves the security of stateful WSRF Grid servers against stealth attacks. The proposal is based on a novel server rotation strategy utilizing paravirtualization to close attack windows for stateful service-oriented Grid headnode servers. A flexible plugin based rotation manager deals with the complex issue of stateful connections to the Grid server, and a database connector is utilized to detach service state from the rotating functional components of the Grid server. A prototypical implementation based on the Globus Toolkit 4 is presented. Matthew Smith 0001, Christian Schridde, Bernd Freisleben |
HPDC | 1 |
| 2006 | Security Issues in On-Demand Grid and Cluster Computing
Matthew Smith 0001, Michael Engel, Thomas Friese, Bernd Freisleben, Gregory A. Koenig, William Yurcik |
CCGRID | 1 |
| 2006 | Collaborative Grid Process Creation Support in an Engineering Domain
Thomas Friese, Matthew Smith 0001, Bernd Freisleben, Julian Reichwald, Thomas Barth, Manfred Grauer |
HiPC | 2 |
| 2006 | Flex-SwA: Flexible Exchange of Binary Data Based on SOAP Messages with AttachmentsabstractSOAP is the standard protocol for message exchange in Web service environments. As an XML-based protocol, SOAP is not suitable for the transmission of large amounts of binary data. This fact has been addressed by the SOAP messages with attachments specification, which regulates the transfer of a SOAP message together with an arbitrary number of binary attachments composed within a MIME multipart/related message. Although this leads to a reduction of transmission overhead, Web service communication using SOAP messages with attachments still lacks communication and processing flexibility. In this paper, we present a novel and more flexible way of handling attachments in SOAP-based Web service environments. In contrast to SOAP messages with attachments, our approach offers message forwarding without additional communication cost and demand-driven evaluation and transmission of binary data, thus providing the opportunity to save time by overlapping service execution and data transmission Steffen Heinzl, Markus Mathes, Thomas Friese, Matthew Smith 0001, Bernd Freisleben |
ICWS | 4 |
| 2006 | Runtime Integration of Reconfigurable Hardware in Service-Oriented GridsabstractIn service-oriented grid computing, great emphasis is placed on platform independence and cross-platform interoperability, at the price of a performance overhead incurred by the middleware and the high level programming languages typically utilized for developing software services. Reconfigurable hardware has been used in many areas of computing to improve the performance of applications by realizing performance critical parts in hardware. Typically, this is done in an application specific way, creating a custom solution for the project at hand for a specific reconfigurable hardware system. In this paper, we introduce a generic architecture in which grid services can be dynamically transformed and run on reconfigurable hardware in a dynamic environment in which different types of reconfigurable hardware systems are present. Three approaches - static design time integration, dynamic run time integration and transparent dynamic run time integration -are presented for integrating such on-demand "hardware services" into a service-oriented grid environment Matthew Smith 0001, B. Klose, Ralph Ewerth, Thomas Friese, Michael Engel, Bernd Freisleben |
ICWS | 1 |
| 2006 | Countering security threats in service-oriented on-demand grid computing using sandboxing and trusted computing techniques
Matthew Smith 0001, Thomas Friese, Michael Engel, Bernd Freisleben |
J. Parallel Distributed Comput. | 1 |
| 2005 | Intra-engine service security for grids based on WSRFabstractIn typical on demand grid computing scenarios, services from different organisations can potentially run in the same Web service engine on a single grid node, making intra-engine service security vital for any production system. In this paper, a solution to the problem of intra-engine inter-service security for ad hoc grid environments based on WSRF is presented. To ensure that only authorized access to grid services is possible from within other services' code, a dynamic group enabled sandboxing approach within Apache Axis is proposed to protect dynamically deployed grid services. It relies on the features provided by a hot deployment service developed for ad hoc grids. A prototypical implementation of the hot deployment service and the intra-engine service security approach based on the Globus Toolkit 4 (GT4) is used to demonstrate the feasibility of our approach. Matthew Smith 0001, Thomas Friese, Bernd Freisleben |
CCGRID | 1 |
| 2004 | Hot service deployment in an ad hoc grid environmentabstractIn this paper, we present a solution to the probl of dynamically deploying grid service factories onto computing nodes running an implentation of the Open Grid Services Infrastructure (OGSI). By providing a non-intrusive Hot Deployment Service (HDS), we extend the service-oriented grid computing paradigm, as it is defined by the Open Grid Services Architecture (OGSA), to provide a more dynamic ad hoc grid environment. Service-oriented grid middleware utilizing the HDS enables organizations or interorganizational communities to form an ad hoc grid to harness unused and scattered resources of an existing IT-infrastructure. The availability of the HDS also improves the capabilities to manage existing grid systs based on the Globus Toolkit 3, which is a vital requirent for the adoption of service-oriented grid systs in production environments. Thomas Friese, Matthew Smith 0001, Bernd Freisleben |
ICSOC | 2 |