EDBT 2026 Demo / reviewers in the wild / expert
Philip D. Huff
dblp:88/7086 · also Philip Dale Huff
· DBLP profile ↗
7ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0003-0869-2147ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Assessing and Prioritizing Ransomware Risk Based on Historical Victim DataabstractWe present an approach to identifying which ransomware adversaries are most likely to target specific entities, thereby assisting these entities in formulating better protection strategies. Ransomware poses a formidable cybersecurity threat characterized by profit-driven motives, a complex underlying economy supporting criminal syndicates, and the overt nature of its attacks. This type of malware has consistently ranked among the most prevalent, with a rapid escalation in activity observed. Recent estimates indicate that approximately two-thirds of organizations experienced ransomware attacks in 2023 [ 1 ]. A central tactic in ransomware campaigns is publicizing attacks to coerce victims into paying ransoms. Our study utilizes public disclosures from ransomware victims to predict the likelihood of an entity being targeted by a specific ransomware variant. We employ a Large Language Model (LLM) architecture that uses a unique chain-of-thought, multi-shot prompt methodology to define adversary SKRAM (Skills, Knowledge, Resources, Authorities, and Motivation) profiles from ransomware bulletins, threat reports, and news items. This analysis is enriched with publicly available victim data and is further enhanced by a heuristic for generating synthetic data that reflects victim profiles. Our work culminates in the development of a machine learning model that assists organizations in prioritizing ransomware threats and formulating defenses based on the tactics, techniques, and procedures (TTP) of the most likely attackers. Spencer Massengale, Philip D. Huff |
SecureComm (4) | 2 |
| 2024 | CFE: Secure Filtered Words in End-to-End Encrypted Messaging SystemabstractWe introduce a new lightweight Symmetric Threshold Predicate Encryption (STPE) scheme, which expands the definition of Predicate Encryption. In STPE, the recipient’s private key evaluates only k predicates instead of all predicates on the sender’s encrypted data. The recipient can decrypt the data if at least k predicates are satisfied. As a new building block, we design a Content-Filtered Encryption (CFE) scheme based on STPE, which allows the sender to encrypt the message with the extracted words and the recipient to generate a filter with abusive words. The recipient can decrypt the message if the evaluation of extracted words and abusive words does not intersect more than a threshold k, where k is a flexible limit of sensitive words the recipient can accept. Otherwise, the recipient can refuse to read the message. It is essential for the recipient to generate a filter of abusive words beforehand; the incoming encrypted message will be delivered only if it bypasses this filter. Therefore, our proposed scheme enables secure filtering of words in the end-to-end encryption messaging protocol, which achieves selective security and efficiency for all communication devices. We prove that our STPE and CFE schemes are secure under the selected security assumptions. Furthermore, by utilizing the Pseudo-Random Function and XOR gate, our construction achieves lightweight computation, which benefits from the primitives of symmetric crypto mechanisms. We experimented on multiple devices, such as PCs and mobile devices. Additionally, our work demonstrates the feasibility across heterogeneous devices. Tran Viet Xuan Phuong, Albert Baker, Philip D. Huff, Jan P. Springer, Tho Thi Ngoc Le |
TrustCom | 3 |
| 2023 | Cyber Arena: An Open-Source Solution for Scalable Cybersecurity Labs in the CloudabstractNumerous institutions are developing cybersecurity education and training programs to supply the considerable global demand for cybersecurity professionals. However, these institutions face barriers in building realistic laboratory environments, commonly referred to as cyber ranges, needed for hands-on skills development. Cybersecurity labs differ from traditional computing labs in both size and complexity. They often require multiple distinct components to represent network configurations, adversarial computing, and defense mechanisms. Philip D. Huff, Sandra Leiterman, Jan P. Springer |
SIGCSE (1) | 1 |
| 2021 | A Recommender System for Tracking VulnerabilitiesabstractMitigating vulnerabilities in software requires first identifying the vulnerabilities with an organization’s software assets. This seemingly trivial task involves maintaining vendor product vulnerability notification for a kludge of hardware and software packages from innumerable software publishers, coding projects, and third-party package managers. On the other hand, software vulnerability databases are often consistently reported and categorized in clean, standard formats and neatly tied to a common software product enumerator (i.e., CPE). Currently it is a heavy workload for cybersecurity analysts at organizations to match their hardware and software package inventory to target CPEs. This hinders organizations from getting notifications for new vulnerabilities, and identifying applicable vulnerabilities. In this paper, we present a recommender system to automatically identify a minimal candidate set of CPEs for software names to improve vulnerability identification and alerting accuracy. The recommender system uses a pipeline of natural language processing, fuzzy matching, and machine learning to significantly reduce the human effort needed for software product vulnerability matching. Philip D. Huff, Kylie McClanahan, Thao Le 0004 |
ARES | 1 |
| 2021 | Towards Automated Assessment of Vulnerability Exposures in Security Operations
Philip D. Huff |
SecureComm (1) | 1 |
| 2021 | A Distributed Ledger for Non-attributable Cyber Threat Intelligence Exchange
Philip D. Huff |
SecureComm (1) | 1 |
| 2008 | Improving the Efficiency of Capture-Resistant Biometric Authentication Based on Set IntersectionabstractTraditional biometric authentication systems store biometric reference templates in cleartext on an authentication server, making them vulnerable to theft. Fuzzy extractors allow an authentication server to store biometric verification data that are resistant to capture. It is hard to recover the reference templates from these biometric verification data, thus increasing the privacy of the reference templates. In this paper, we improve the efficiency of a set intersection-based fuzzy extractor in two ways. First, we speed up the computation of verifying a biometric sample under some parameter combinations through integrating a Reed-Solomon decoding algorithm. Second, we propose a new function to improve the storage efficiency of the fuzzy extractor. A prototype implementation is developed to validate our improvements and it shows that our first improvement could speed up computation as many as 2.29 times 106times. Xunhua Wang, Philip D. Huff, Brett C. Tjaden |
ACSAC | 2 |