EDBT 2026 Demo / reviewers in the wild / expert
Jelena Mirkovic
dblp:89/6100
· DBLP profile ↗
63ranked-venue papers
22as first author
14since 2021 · last 2026
0000-0001-7462-8747ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 6 first-author · 8 since 2021Computer networks · 19 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorSystems, architecture and hardware · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Data Flows in You: Benchmarking and Improving Static Data-flow Analysis on Binary ExecutablesabstractData-flow analysis is a critical component of security research. Theoretically, accurate data-flow analysis in binary executables is an undecidable problem, due to complexities of binary code. Practically, many binary analysis engines offer some data-flow analysis capability, but we lack understanding of the accuracy of these analyses, and their limitations. We address this problem by introducing a labeled benchmark data set, including 215, 072 microbenchmark test cases, mapping to 277, 072 binary executables, created specifically to evaluate data-flow analysis implementations. Additionally, we augment our benchmark set with dynamically-discovered data flows from 6 real-world executables. Using our benchmark data set, we evaluate three state of the art data-flow analysis implementations, in angr, Ghidra and Miasm and discuss their very low accuracy and reasons behind it. We further propose three model extensions to static data-flow analysis that significantly improve accuracy, achieving almost perfect recall (0.99) and increasing precision from 0.13 to 0.32 for the GCC compiler, and achieving a recall of 0.86 with a precision increase from 0.12 to 0.22 for Clang. Finally, we show that leveraging these model extensions in a vulnerability-discovery context leads to a tangible improvement in vulnerable instruction identification. Nicolaas Weideman, Sima Arasteh, Mukund Raghothaman, Jelena Mirkovic, Christophe Hauser |
AsiaCCS | 4 |
| 2025 | Navigating Social Media Privacy: Awareness, Preferences, and DiscoverabilityabstractSocial media platforms provide various privacy settings, which users can adjust to fit their privacy needs. Platforms claim that this is sufficient – users have power to accept the default settings they like, and change those they do not like. In this paper, we seek to quantify user awareness of, preferences around and ability to adjust social media privacy settings. We conduct an online survey of 541 participants across six different social media platforms: Facebook, Instagram, X, LinkedIn, TikTok, and Snapchat. We focus on nine privacy settings that are commonly available across these platforms, and evaluate participants’ preferences for privacy, awareness of the privacy settings and ability to locate them. We find that default settings are ill-aligned with user preferences – 92% of participants prefer at least one of the privacy options to be more private than the default. We further find that users are generally not aware of privacy settings, and struggle to find them. 80% of participants have never seen at least one privacy setting, and 79% of participants rated at least one setting as hard to find. We also find that the fewer privacy settings a user has seen, the harder for them to locate those settings, and the higher the level of privacy they desire. Additionally, we find that there are significant differences in privacy setting preferences and usability across different user age groups and across platforms. Older users are more conservative about their privacy, they have seen significantly fewer privacy settings, and they spend significantly more time locating them than younger users. On some platforms, like LinkedIn, users opt for higher visibility, while on others they prefer more privacy. Some platforms, like TikTok, make it significantly easier for users to locate privacy settings. Based on our findings, we provide recommendations on default values and how to improve usability of privacy settings on social media. Pithayuth Charnsethikul, Almajd Zunquti, Gale M. Lucas, Jelena Mirkovic |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | BinHunter: A Fine-Grained Graph Representation for Localizing Vulnerabilities in Binary Executables*abstractThe success of deep learning techniques in diverse fields has prompted research into their application for automatic software vulnerability discovery. The first step in the design of a deep learning based vulnerability detector fundamentally involves selecting an appropriate binary representation. A second challenge arises from the need to automatically localize the vulnerability to specific instructions, so as to allow for better detection and to enable downstream applications such as triage and patching.In this paper, we propose BinHunter, an automated tool for vulnerability discovery in binary programs. BinHunter leverages a new graph representation derived from slices of the combined control and data dependency graphs of a binary executable, and can learn code properties by propagating information through the graph edges. This representation enables graph convolutional network (GCN) learning algorithms to both detect and pinpoint the locations of vulnerabilities in binary programs.We evaluate our approach both using the Juliet test suite and a dataset consisting of historical CVEs from the Debian packages. In both evaluations, we observe that BinHunter is significantly more effective than the baselines: On the Juliet test programs, our model has 6.77%, 26.53%, 24.65% and 41.59% higher true positive rates and 19%, 47.64%, 31.47% and 39.82% lower false positive rates than our baselines respectively (Bin2vec [1], Asm2vec [10], Genius [12] and Jtrans [46]). Furthermore, our model is able to detect 17 of 21 bugs from the Debian dataset, Bin2vec detects 2 bugs, and the remaining three baselines are unable to detect any vulnerabilities at all. Sima Arasteh, Jelena Mirkovic, Mukund Raghothaman, Christophe Hauser |
ACSAC | 2 |
| 2024 | Poster: Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE)abstractTo transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community, and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs, and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities. Jelena Mirkovic, David M. Balenson, Brian Kocoloski, Geoff Lawler, Chris Tran, Joseph Barnes, Yuri Pradkin, Terry V. Benzel, Srivatsan Ravi, Ganesh Sankaran, Alba Regalado, David R. Choffnes, Daniel J. Dubois, Luis Garcia 0001 |
CCS | 1 |
| 2023 | Practical Intent-driven Routing Configuration Synthesis
Sivaramakrishnan Ramanathan, Ying Zhang 0022, Mohab Gawish, Yogesh Mundada, Zhaodong Wang, Sangki Yun, Eric Lippert, Walid Taha, Minlan Yu, Jelena Mirkovic |
NSDI | 10 |
| 2023 | Leader: Defense Against Exploit-Based Denial-of-Service Attacks on Web ApplicationsabstractExploit-based denial-of-service attacks (exDoS) are challenging to detect and mitigate. Rather than flooding the network with excessive traffic, these attacks generate low rates of application requests that exploit some vulnerability and tie up a scarce key resource. It is impractical to design defenses for each variant of exDoS attacks separately. This approach does not scale, since new vulnerabilities can be discovered in existing applications, and new applications can be deployed with yet unknown vulnerabilities. Rajat Tandon, Haoda Wang, Nicolaas Weideman, Shushan Arakelyan, Genevieve Bartlett, Christophe Hauser, Jelena Mirkovic |
RAID | 7 |
| 2023 | Defending Root DNS Servers against DDoS Using Layered Defenses (Extended)
A. S. M. Rizvi, Jelena Mirkovic, John S. Heidemann, Wes Hardaker, Robert Story |
Ad Hoc Networks | 2 |
| 2022 | Understanding DNS Query Composition at B-RootabstractThe Domain Name System (DNS) is part of critical internet infrastructure, as DNS is invoked whenever a remote server is accessed (an URL is visited, an API request is made, etc.) by any application. DNS queries are served in hierarchical manner, with most queries served locally from cached data, and a small fraction propagating to the top of the hierarchy – DNS root name servers. Our research aims to provide a comprehensive, longitudinal characterization of DNS queries received at B-Root over ten years. We sampled and analyzed a 28-billion-query large dataset from the ten annual "Day in the Life of the Internet (DITL)" experiments, from 2013 through 2022. We sought to identify and quantify unexpected DNS queries, establish longitudinal trends, and compare our findings with published results of others. We found that unexpected query traffic increased from 39.57% in 2013 to 67.91% in 2022, with 36.55% of queries being priming queries. We also observed growth and decline of Chromium-initiated, random DNS queries. Finally, we analyzed the largest DNS query senders and established that most of their traffic consists of unexpected queries. Jacob Ginesin, Jelena Mirkovic |
BDCAT | 2 |
| 2022 | Samba: Identifying Inappropriate Videos for Young Children on YouTubeabstractYouTube videos are one of the most effective platforms for disseminating creative material and ideas, and they appeal to a diverse audience. Along with adults and older children, young children are avid consumers of YouTube materials. Children often lack means to evaluate if a given content is appropriate for their age, and parents have very limited options to enforce content restrictions on YouTube. Young children can thus become exposed to inappropriate content, such as violent, scary or disturbing videos on YouTube. Previous studies demonstrated that YouTube videos can be classified into appropriate or inappropriate for young viewers using video metadata, such as video thumbnails, title, comments, etc. Metadata-based approaches achieve high accuracy, but still have significant misclassifications, due to the reliability of input features. In this paper, we propose a fusion model, called Samba, which uses both metadata and video subtitles for content classification. Using subtitles in the model helps better infer the true nature of a video improving classification accuracy. On a large-scale, comprehensive dataset of 70K videos, we show that Samba achieves 95% accuracy, outperforming other state-of-the-art classifiers by at least 7%. We also publicly release our dataset. Le Binh, Rajat Tandon, Chingis Oinar, Jeffrey Liu, Uma Durairaj, Jiani Guo, Spencer Zahabizadeh, Sanjana Ilango, Jeremy Tang, Fred Morstatter, Simon S. Woo, Jelena Mirkovic |
CIKM | 12 |
| 2022 | Xatu: boosting existing DDoS detection systems using auxiliary signalsabstractTraditional DDoS attack detection monitors volumetric traffic features to detect attack onset. To reduce false positives, such detection is often conservative---raising an alert only after a sustained period of observed anomalous behavior. However, contemporary attacks tend to be short, which combined with a long detection delay means that most of the attack still reaches and impacts the victim. We propose Xatu, a system that utilizes auxiliary signals to improve the accuracy and timeliness of existing DDoS detection systems. We explore two types of auxiliary signals, attack preparation signals and the history of prior attacks. These signals can be easily mined from existing traffic monitoring systems in many ISP networks. To leverage these auxiliary signals for attack detection, we propose a multi-timescale LSTM model, which derives both long-term and short-term patterns from diverse auxiliary signals. We then leverage survival analysis to quickly detect attacks when they occur while minimizing false positives and thus scrubbing costs. We evaluate Xatu on traffic from a large ISP, using commercial defense alert data to label prevalent attack events. Xatu would help the commercial defense scrub up to 44.1% additional anomalous traffic and would reduce its median detection delay by 9.5 minutes.1 Zhiying Xu, Sivaramakrishnan Ramanathan, Alexander M. Rush, Jelena Mirkovic, Minlan Yu |
CoNEXT | 4 |
| 2022 | AMON-SENSS: Scalable and Accurate Detection of Volumetric DDoS Attacks at ISPsabstractDistributed Denial of Service (DDoS) attacks continue to be a severe threat to the Internet, and have been evolving both in traffic volume and in sophistication. While many attack detection approaches exist, few of them provide easily interpretable and actionable network-level signatures. Further, most tools are either not scalable or are prohibitively expensive, and thus are not broadly available to network operators. We bridge this gap by proposing AMON-SENSS, an open-source system for scalable, accurate DDoS detection and signature generation in large networks. AMON-SENSS employs hash-based binning with multiple bin layers for scalability, observes traffic at multiple granularities, and deploys traffic volume and traffic asymmetry change-point detection techniques to identify attacks. It proactively devises network-level attack signatures, which can be used to filter attack traffic. We evaluate AMON-SENSS against two commercial defense systems, using 37 days of real traffic from a mid-size Internet Service Provider (ISP). We find that our proposed approach exhibits superior performance in terms of accuracy, detection time and network signature quality over commercial alternatives. AMON-SENSS is deployable today, it is free, and requires no hardware or routing changes. Rajat Tandon, Pithayuth Charnsethikul, Michael G. Kallitsis, Jelena Mirkovic |
GLOBECOM | 4 |
| 2022 | Harm-DoS: Hash Algorithm Replacement for Mitigating Denial-of-Service Vulnerabilities in Binary ExecutablesabstractPrograms and services relying on weak hash algorithms as part of their hash table implementations are vulnerable to hash-collision denial-of-service attacks. In the context of such an attack, the attacker sends a series of program inputs leading to hash collisions. In the best case, this slows down the execution and processing for all requests, and in the worst case it renders the program or service unavailable. We propose a new binary program analysis approach to automatically detect weak hash functions and patch vulnerable binary programs, by replacing the weak hash function with a secure alternative. To verify that our mitigation strategy does not break program functionality, we design and leverage multiple stages of static analysis and symbolic execution, which demonstrate that the patched code performs equivalently to the original code, but does not suffer from the same vulnerability. We analyze 105,831 real-world programs and confirm the use of 796 weak hash functions in the same number of programs. We successfully replace 759 of these in a non-disruptive manner. The entire process is automated. Among the real-world programs analyzed, we discovered, disclosed and mitigated a zero-day hash-collision vulnerability in Reddit. Nicolaas Weideman, Haoda Wang, Tyler Kann, Spencer Zahabizadeh, Wei-Cheng Wu, Rajat Tandon, Jelena Mirkovic, Christophe Hauser |
RAID | 7 |
| 2022 | I know what you did on Venmo: Discovering privacy leaks in mobile social paymentsabstractVenmo is a US-based mobile social payments platform. Each Venmo transaction requires a “payment note”, a brief memo. By default, these memos are visible to all other Venmo users. Using three data sets of Venmo transactions, which span 8 years and a total of 389 M transactions with over 22.5 M unique users, we quantify the extent of private data leaks from public transaction notes. To quantify the leaks, we develop a classification framework SENMO, that uses BERT and regular expressions to classify public transaction notes as sensitive or non-sensitive. We find that 41 M notes (10.5%) leak some sensitive information such as health condition, political orientation and drug/alcohol consumption involving 8.5 M (37.8%) users. We further find that users seek privacy by making their notes private, inconspicuous or cryptic. However, the large increase in Venmo’s user base means that the number of users whose privacy is publicly exposed has grown substantially. Finally, the privacy of a user who transacts with a group on Venmo can be reduced or eliminated through the actions of other users. We find that this happens to around half of Alcoholics Anonymous, gambling and biker gang group members. Our findings strongly suggest that public-by-default payment information puts many users at risk of unintended privacy leaks. Rajat Tandon, Pithayuth Charnsethikul, Ishank Arora, Dhiraj Murthy, Jelena Mirkovic |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Defending Web Servers Against Flash Crowd Attacks
Rajat Tandon, Abhinav Palia, Jaydeep Ramani, Brandon Paulsen, Genevieve Bartlett, Jelena Mirkovic |
ACNS (2) | 6 |
| 2020 | Quantifying the Impact of Blocklisting in the Age of Address ReuseabstractBlocklists, consisting of known malicious IP addresses, can be used as a simple method to block malicious traffic. However, blocklists can potentially lead to unjust blocking of legitimate users due to IP address reuse, where more users could be blocked than intended. IP addresses can be reused either at the same time (Network Address Translation) or over time (dynamic addressing). We propose two new techniques to identify reused addresses. We built a crawler using the BitTorrent Distributed Hash Table to detect NATed addresses and use the RIPE Atlas measurement logs to detect dynamically allocated address spaces. We then analyze 151 publicly available IPv4 blocklists to show the implications of reused addresses and find that 53-60% of blocklists contain reused addresses having about 30.6K-45.1K listings of reused addresses. We also find that reused addresses can potentially affect as many as 78 legitimate users for as many as 44 days. Sivaramakrishnan Ramanathan, Anushah Hossain, Jelena Mirkovic, Minlan Yu, Sadia Afroz 0001 |
Internet Measurement Conference | 3 |
| 2020 | BLAG: Improving the Accuracy of Blacklists
Sivaramakrishnan Ramanathan, Jelena Mirkovic, Minlan Yu |
NDSS | 2 |
| 2020 | Using Terminal Histories to Monitor Student Progress on Hands-on ExercisesabstractHands-on exercises are often used to improve student engagement and knowledge retention in systems, networking and cybersecurity classes. Even when students comprehend the concepts, they may lack the skills to complete an exercise. Teachers need effective tools to identify these problemsduring an assignment and offer targeted and timely help. Jelena Mirkovic, Aashray Aggarwal, David Weinmann, Paul Lepe, Jens Mache, Richard Weiss 0001 |
SIGCSE | 1 |
| 2019 | Grammatical Generalisation in Statistical Learning: Is it implicit and invariant across development?
Amanda Hickey, Emma Hayiou-Thomas, Jelena Mirkovic |
CogSci | 3 |
| 2019 | Measuring Student Learning On Network TestbedsabstractEngaging students in practical, hands-on exercises on testbeds improves student learning and knowledge retention. However, testbeds may also present an obstacle to learning for students who are not familiar with the environment, or who lack the necessary background to complete their assignments. Our research investigates how students learn with testbeds. We instrument a default operating system on the DeterLab testbed and monitor the students' command line input and output, as they perform homework assignments.We use this data to evaluate students' progress, to detect when a student is struggling and to identify common problems. Paul Lepe, Aashray Aggarwal, Jelena Mirkovic, Jens Mache, Richard Weiss 0001, David Weinmann |
ICNP | 3 |
| 2019 | Defending Web Servers Against Flash Crowd AttacksabstractFlash Crowd Attacks (FCAs) are DDoS attacks that flood victim services, such as Web servers, with well-formed requests, generated by numerous bots. It is hard to detect and filter such attacks because both legitimate and attack requests look identical. In our previous work [1], we proposed models of how human users interact with Web servers, and also showed in simulation that these models can detect naive FCA attacks. We significantly extend these proposed models to make them more robust, simpler, and applicable to a wider variety of FCA attacks in this paper. We implement the models in a system called FRADE, and evaluate it on three Web servers with different server applications and different content. We show that FRADE can detect both naive and sophisticated bots within seconds and successfully filters out attack traffic. Therefore, FRADE significantly raises the bar for a successful attack by requiring attackers to deploy botnets that are at least three orders of magnitude larger than the botnets today. Rajat Tandon, Abhinav Palia, Jaydeep Ramani, Brandon Paulsen, Genevieve Bartlett, Jelena Mirkovic |
ICNP | 6 |
| 2019 | Using Episodic Memory for User AuthenticationabstractPasswords are widely used for user authentication, but they are often difficult for a user to recall, easily cracked by automated programs, and heavily reused. Security questions are also used for secondary authentication. They are more memorable than passwords, because the question serves as a hint to the user, but they are very easily guessed. We propose a new authentication mechanism, called “life-experience passwords (LEPs).” Sitting somewhere between passwords and security questions, an LEP consists of several facts about a user-chosen life event—such as a trip, a graduation, a wedding, and so on. At LEP creation, the system extracts these facts from the user’s input and transforms them into questions and answers. At authentication, the system prompts the user with questions and matches the answers with the stored ones. We show that question choice and design make LEPs much more secure than security questions and passwords, while the question-answer format promotes low password reuse and high recall. Specifically, we find that: (1) LEPs are 10 9 --10 14 × stronger than an ideal, randomized, eight-character password; (2) LEPs are up to 3 × more memorable than passwords and on par with security questions; and (3) LEPs are reused half as often as passwords. While both LEPs and security questions use personal experiences for authentication, LEPs use several questions that are closely tailored to each user. This increases LEP security against guessing attacks. In our evaluation, only 0.7% of LEPs were guessed by casual friends, and 9.5% by family members or close friends—roughly half of the security question guessing rate. On the downside, LEPs take around 5 × longer to input than passwords. So, these qualities make LEPs suitable for multi-factor authentication at high-value servers, such as financial or sensitive work servers, where stronger authentication strength is needed. Simon S. Woo, Ron Artstein, Elsi Kaiser, Xiao Le, Jelena Mirkovic |
ACM Trans. Priv. Secur. | 5 |
| 2018 | SENSS Against Volumetric DDoS AttacksabstractVolumetric distributed denial-of-service (DDoS) attacks can bring any network to a halt. Because of their distributed nature and high volume, the victim often cannot handle these attacks alone and needs help from upstream ISPs. Today's Internet has no automated mechanism for victims to ask ISPs for help in attack handling and ISPs themselves do not offer such services. We propose SENSS, a security service for collaborative mitigation of volumetric DDoS attacks. SENSS enables the victim of an attack to request attack monitoring and filtering on demand, and to pay for the services rendered. Requests can be sent both to the immediate and to remote ISPs, in an automated and secure manner, and can be authenticated by these ISPs, without having prior trust with the victim. Simple and generic SENSS APIs enable victims to build custom detection and mitigation approaches against a variety of DDoS attacks. SENSS is deployable with today's infrastructure, and it has strong economic incentives both for ISPs and for the attack victims. It is also very effective in sparse deployment, offering full protection to direct customers of early adopters, and considerable protection to remote victims when deployed strategically. Deployment on the largest 1% of ISPs protects not just direct customers of these ISPs, but everyone on the Internet, from 90% of volumetric DDoS attacks. Sivaramakrishnan Ramanathan, Jelena Mirkovic, Minlan Yu, Ying Zhang 0022 |
ACSAC | 2 |
| 2018 | Leveraging Semantic Transformation to Investigate Password Habits and Their CausesabstractIt is no secret that users have difficulty choosing and remembering strong passwords, especially when asked to choose different passwords across different accounts. While research has shed light on password weaknesses and reuse, less is known about user motivations for following bad password practices. Understanding these motivations can help us design better interventions that work with the habits of users and not against them. Ameya Hanamsagar, Simon S. Woo, Chris Kanich, Jelena Mirkovic |
CHI | 4 |
| 2018 | GuidedPass: Helping Users to Create Strong and Memorable Passwords
Simon S. Woo, Jelena Mirkovic |
RAID | 2 |
| 2018 | Handling Anti-Virtual Machine Techniques in Malicious SoftwareabstractMalware analysis relies heavily on the use of virtual machines (VMs) for functionality and safety. There are subtle differences in operation between virtual and physical machines. Contemporary malware checks for these differences and changes its behavior when it detects a VM presence. These anti-VM techniques hinder malware analysis. Existing research approaches to uncover differences between VMs and physical machines use randomized testing, and thus cannot guarantee completeness. In this article, we propose a detect-and-hide approach, which systematically addresses anti-VM techniques in malware. First, we propose cardinal pill testing —a modification of red pill testing that aims to enumerate the differences between a given VM and a physical machine through carefully designed tests. Cardinal pill testing finds five times more pills by running 15 times fewer tests than red pill testing. We examine the causes of pills and find that, while the majority of them stem from the failure of VMs to follow CPU specifications, a small number stem from under-specification of certain instructions by the Intel manual. This leads to divergent implementations in different CPU and VM architectures. Cardinal pill testing successfully enumerates the differences that stem from the first cause. Finally, we propose VM Cloak —a WinDbg plug-in which hides the presence of VMs from malware. VM Cloak monitors each execute malware command, detects potential pills, and at runtime modifies the command’s outcomes to match those that a physical machine would generate. We implemented VM Cloak and verified that it successfully hides VM presence from malware. Jelena Mirkovic, Abdulla Alwabel |
ACM Trans. Priv. Secur. | 2 |
| 2017 | Commoner Privacy And A Study On Network TracesabstractDifferential privacy has emerged as a promising mechanism for privacy-safe data mining. One popular differential privacy mechanism allows researchers to pose queries over a dataset, and adds random noise to all output points to protect privacy. While differential privacy produces useful data in many scenarios, added noise may jeopardize utility for queries posed over small populations or over long-tailed datasets. Gehrke et al. proposed crowd-blending privacy, with random noise added only to those output points where fewer than k individuals (a configurable parameter) contribute to the point in the same manner. This approach has a lower privacy guarantee, but preserves more research utility than differential privacy. Xiyue Deng, Jelena Mirkovic |
ACSAC | 2 |
| 2017 | RESECT: Self-Learning Traffic Filters for IP Spoofing DefenseabstractIP spoofing has been a persistent Internet security threat for decades. While research solutions exist that can help an edge network detect spoofed and reflected traffic, the sheer volume of such traffic requires handling further upstream. Jelena Mirkovic, Erik Kline, Peter L. Reiher |
ACSAC | 1 |
| 2017 | User and Stakeholder Requirements of eHealth Support Tool Viewed In a Self-Determination Theory LensabstractThis paper presents preliminary results of an analysis of user requirements for an eHealth tool supporting chronic patients to use their personal strengths in health management. We conclude that Self-Determination Theory can be applied to view and categorize identified user requirements, and provide a framing for the analysis grounded in motivational theory. The final model will lay the foundation for our future design and implementation of gameful designs in an eHealth tool in order to enhance user engagement, motivation, and adherence. Stian Jessen, Jelena Mirkovic, Cornelia M. Ruland |
CBMS | 2 |
| 2016 | Life-experience passwords (LEPs)
Simon S. Woo, Elsi Kaiser, Ron Artstein, Jelena Mirkovic |
ACSAC | 4 |
| 2016 | Good Automatic Authentication Question GenerationabstractWe explore a novel application of Question Generation (QG) for authentication use, where questions are widely used to verify user identity for online accounts.In our approach, we prompt users to provide a few sentences about their personal life events.We transform user-provided input sentences into a set of simple fact-based authentication questions.We compared our approach with previous QG systems, and evaluation results show that our approach yielded better performance and the promise of future personalized authentication question generation. Simon S. Woo, Zuyao Li, Jelena Mirkovic |
INLG | 3 |
| 2014 | iDECIDE: A Mobile Application for Pre-Meal Insulin Dosing Using an Evidence Based Equation to Account for Patient Preferences
Akram Farhadi, Buffy Lloyd, Danielle Groat, Jelena Mirkovic, Curtiss B. Cook, María Adela Grando |
AMIA | 4 |
| 2014 | Identifying eHealth literacy demands of health information seeking tasks
Jelena Mirkovic, Maria Sims, David R. Kaufman |
AMIA | 1 |
| 2014 | SENSS: observe and control your own traffic in the internetabstractWe propose a new software-defined security service -- SENSS -- that enables a victim network to request services from remote ISPs for traffic that carries source IPs or destination IPs from this network's address space. These services range from statistics gathering, to filtering or quality of service guarantees, to route reports or modifications. The SENSS service has very simple, yet powerful, interfaces. This enables it to handle a variety of data plane and control plane attacks, while being easily implementable in today's ISP. Through extensive evaluations on realistic traffic traces and Internet topology, we show how SENSS can be used to quickly, safely and effectively mitigate a variety of large-scale attacks that are largely unhandled today. Abdulla Alwabel, Minlan Yu, Ying Zhang 0022, Jelena Mirkovic |
SIGCOMM | 4 |
| 2014 | Cardinal Pill Testing of System Virtual Machines
Abdulla Alwabel, Jelena Mirkovic |
USENIX Security Symposium | 3 |
| 2014 | Optimal application allocation on multiple public clouds
Simon S. Woo, Jelena Mirkovic |
Comput. Networks | 2 |
| 2013 | Nap-related consolidation in learning the grammar and vocabulary of a novel language
Jelena Mirkovic, M. Gareth Gaskell |
CogSci | 1 |
| 2012 | Reducing allocation errors in network testbedsabstractNetwork testbeds have become widely used in computer science, both for evaluation of research technologies and for hands-on teaching. This can naturally lead to oversubscription and resource allocation failures, as limited testbed resources cannot meet the increasing demand. Jelena Mirkovic, Alefiya Hussain |
Internet Measurement Conference | 1 |
| 2011 | Semantic Regularities in Grammatical Categories: Learning Grammatical Gender in an Artificial Language
Jelena Mirkovic, Sarah Forrest, M. Gareth Gaskell |
CogSci | 1 |
| 2011 | A Semantic Framework for Data Analysis in Networked Systems
Arun Viswanathan, Alefiya Hussain, Jelena Mirkovic, Stephen Schwab, John Wroclawski |
NSDI | 3 |
| 2011 | Comparative Evaluation of Spoofing DefensesabstractIP spoofing exacerbates many security threats, and reducing it would greatly enhance Internet security. Seven defenses that filter spoofed traffic have been proposed to date; three are designed for end-network deployment, while four assume some collaboration with core routers for packet marking or filtering. Because each defense has been evaluated in a unique setting, the following important questions remain unanswered: 1) Can end networks effectively protect themselves or is core support necessary? 2) Which defense performs best assuming sparse deployment? 3) How to select core participants to achieve best protection with fewest deployment points? This paper answers the above questions by: 1) formalizing the problem of spoofed traffic filtering and defining novel effectiveness measures, 2) observing each defense as selfish (it helps its participants) or altruistic (it helps everyone) and differentiating their performance goals, 3) defining optimal core deployment points for defenses that need core support, and 4) evaluating all defenses in a common and realistic setting. Our results offer a valuable insight into advantages and limitations of the proposed defenses, and uncover the relationship between any spoofing defense's performance and the Internet's topology. Jelena Mirkovic, Ezra Kissel |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2009 | RAD: Reflector Attack Defense Using Message Authentication CodesabstractReflector attacks are a variant of denial-of-service attacks that use unwitting, legitimate servers to flood a target. The attacker spoofs the target's address in legitimate service requests, such as TCP SYN packets. The servers, called "reflectors,'' reply to these requests, flooding the target. RAD is a novel defense against reflector attacks. It has two variants -- locally-deployed (L-RAD) and core-deployed (C-RAD). Local RAD uses message authentication codes (MACs) to mark outgoing requests at their source, so the target of a reflector attack can differentiate between replies to legitimate and spoofed requests. MACs can be validated either at the target machine or on a gateway router at the target's network. Core RAD, which is deployed at the AS level, handles larger attacks that overwhelm L-RAD. The source AS marks each packet it sends with a hash message authentication code (HMAC) and core ASes filter packets that carry incorrect HMACs. C-RAD prevents reflector attacks by filtering spoofed requests, rather than filtering reflected replies. We tested both variants using the DETER testbed by replaying backbone traces from the MAWI project archive in a congestion-responsive manner. Our tests show that local RAD is better than the no-defense case, but gets overwhelmed when the attack exceeds the target's network capacity. Core-deployed RAD successfully handles attacks of all rates. Erik Kline, Matt Beaumont-Gay, Jelena Mirkovic, Peter L. Reiher |
ACSAC | 3 |
| 2009 | Modeling Human Behavior for Defense Against Flash-Crowd AttacksabstractFlash-crowd attacks are the most vicious form of distributed denial of service (DDoS). They flood the victim with service requests generated from numerous bots. Attack requests are identical in content to those generated by legitimate, human users, and bots send at a low rate to appear non-aggressive - these features defeat many existing DDoS defenses. We propose defenses against flash-crowd attacks via human behavior modeling, which differentiate DDoS bots from human users. Current approaches to human-vs-bot differentiation, such as graphical puzzles, are insufficient and annoying to humans, whereas our defenses are highly transparent. We model three aspects of human behavior: a) request dynamics, by learning several chosen features of human interaction dynamics, and detecting bots that exhibit higher aggressiveness in one or more of these features, b) request semantics, by learning transitional probabilities of user requests, and detecting bots that generate valid but low-probability sequences, and c) ability to process visual cues, by embedding into server replies human-invisible objects, which cannot be detected by automated analysis, and flagging users that visit them as bots. We evaluate our defenses' performance on a series of Web traffic logs, interlaced with synthetically generated attacks, and conclude that they raise the bar for a successful, sustained attack to botnets whose size is larger than the size observed in 1-5% of DDoS attacks today. George C. Oikonomou, Jelena Mirkovic |
ICC | 2 |
| 2009 | Accurately Measuring Denial of Service in Simulation and Testbed ExperimentsabstractResearchers in the denial-of-service (DoS) field lack accurate, quantitative, and versatile metrics to measure service denial in simulation and testbed experiments. Without such metrics, it is impossible to measure severity of various attacks, quantify success of proposed defenses, and compare their performance. Existing DoS metrics equate service denial with slow communication, low throughput, high resource utilization, and high loss rate. These metrics are not versatile because they fail to monitor all traffic parameters that signal service degradation. They are not quantitative because they fail to specify exact ranges of parameter values that correspond to good or poor service quality. Finally, they are not accurate since they were not proven to correspond to human perception of service denial. We propose several DoS impact metrics that measure the quality of service experienced by users during an attack. Our metrics are quantitative: they map QoS requirements for several applications into measurable traffic parameters with acceptable, scientifically determined thresholds. They are versatile: they apply to a wide range of attack scenarios, which we demonstrate via testbed experiments and simulations. We also prove metrics' accuracy through testing with human users. Jelena Mirkovic, Alefiya Hussain, Sonia Fahmy, Peter L. Reiher, Roshan K. Thomas |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2008 | Fairness and Delay in MU-MIMO WLANsabstractIn this paper, single-user (SU) and multi-user (MU) transmission approaches in multiple input-multiple output (MIMO) wireless local area networks (WLANs) are compared. The impact of the transmission strategy on both short-term and long-term fairness and frame delay distribution is studied. This work is focused on the previously presented single-user-distributed coordination function (SU-DCF) and multi-user -distributed coordination function (MU-DCF), both based on the IEEE 802.11 distributed coordination function (DCF). A comparative performance analysis is given, and despite the increased system complexity, it is argued in favor of MU systems. Jelena Mirkovic |
CCNC | 1 |
| 2008 | Combining Speak-Up with DefCOM for Improved DDoS DefenseabstractThis work combines two existing defenses against distributed denial-of-service (DDoS) attacks - DefCOM and speak-up - resulting in a synergistic improvement. DefCOM defense organizes existing source-end, victim-end and core defenses into a collaborative overlay to filter DDoS floods. Source networks that do not participate in DefCOM often receive poor service and their traffic is severely rate-limited. This is because core nodes in DefCOM that perform filtering lack cheap algorithms to differentiate legitimate from attack traffic at line speed - they must conservatively assume all high-rate traffic from legacy networks to be attack. Thus, in its attempt to mitigate DDoS, DefCOM ends up denying service during attacks to legitimate hosts that reside in legacy networks. Speak-up is a recently proposed defense, which invites all clients of the DDoS victim to send additional payment traffic, with the assumption that attack machines are already sending close to their full capacity. Clients that send a lot of payment traffic are considered legitimate and whitelisted. Speak-up is relatively cheap to deploy at the clients and the DDoS victim, but since payment traffic needs to be sent continuously, this creates additional congestion at the victim, which is undesirable. We combine speak-up and DefCOM into a synergistic defense that addresses the shortcomings of the individual defenses and confirms the success of collaborative protection against DDoS attacks. Speak-up is integrated with core defenses in DefCOM and whitelists clients based on their payment traffic. Legitimate clients in legacy networks can thus be detected and served. Further, since Speak-up is implemented in the core, payment and attack traffic do not reach the victim and any undesirable congestion effects are localized to the vicinity of legacy networking. Mohit Mehta, Kanika Thapar, George C. Oikonomou, Jelena Mirkovic |
ICC | 4 |
| 2008 | Correcting congestion-based error in network telescope's observations of worm dynamicsabstractNetwork telescopes have been invaluable for collecting information about dynamics of large-scale worm events. Yet, a telescope's observation may be incomplete due to scan congestion drops, hardware limitations, filtering and presence of NATs, a worm's non-uniform scanning strategy or its short life. We investigate inaccuracies in telescope observations that arise from worm-induced congestion drops of worm scans and show that they may lead to significant underestimates of the number of infectees and their scanning rate. We propose a method to infer worm-induced congestion drops from telescope's observations and use them to accurately estimate global worm dynamics. We apply our methods to CAIDA telescope's observations of Witty worm's spread, and release corrected statistics of worm dynamics for public use. Songjie Wei, Jelena Mirkovic |
Internet Measurement Conference | 2 |
| 2008 | Theoretical Analysis of Saturation Throughput in MU-DCFabstractIn this paper, the calculation of saturation throughput for previously proposed multi-user - distributed coordination function (MU-DCF) is presented. MU-DCF is an IEEE 802.11 based protocol that supports multi-user (MU)-multiple input-multiple output (MIMO) transmissions. The analysis is for two extreme case scenarios: access point (AP) downlink in a hotspot scenario, and fully interconnected network. Special attention is payed on the statistical properties of traffic sources, since in MU-DCF networks they have strong impact on performance. In addition, the difference in performance between MU and single-user (SU) transmission strategies is evaluated, pointing out to the tradeoff between delay and throughput. Jelena Mirkovic, Bernhard Walke |
VTC Spring | 1 |
| 2008 | On Performance of MIMO Link Adaptation in the Presence of Channel UncertaintyabstractIn this paper, link level adaptation algorithms in a system applying spatial multiplexing in the presence of channel uncertainty are considered. The first part of this paper deals with the impact of accuracy of the channel knowledge on the post-processing signal-to-noise ratio (SNR) of transmitted multiple streams. This is evaluated by means of correlation coefficient between post-processing SNR values corresponding to the estimated and used channel matrix.In the second part of this paper, two link adaptation algorithms are introduced: the first algorithm adapts the modulation and coding scheme to the post-processing SNR level, whereas the second one searches for the optimum MIMO scheme (antenna selection) and does afterwards the adaptation of modulation and coding as well. Algorithmspsila performance is evaluated assuming perfect channel knowledge and in the presence of channel uncertainty. The two algorithms show different gains when the channel knowledge is accurate, but also different sensitivity to channel knowledge imperfections. Jelena Mirkovic, Bernhard Walke |
WiMob | 1 |
| 2008 | Learning the valid incoming direction of IP packets
Jun Li 0001, Jelena Mirkovic, Toby Ehrenkranz, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
Comput. Networks | 2 |
| 2008 | Testing a Collaborative DDoS Defense In a Red Team/Blue Team ExerciseabstractTesting security systems is challenging because a system's authors have to play the double role of attackers and defenders. Red team/blue team exercises are an invaluable mechanism for security testing. They partition researchers into two competing teams of attackers and defenders, enabling them to create challenging and realistic test scenarios. While such exercises provide valuable insight into vulnerabilities of security systems, they are very expensive and thus rarely performed. In this paper we describe a red team/blue team exercise, sponsored by DARPA's FTN program, and performed October 2002 --- May 2003. The goal of the exercise was to evaluate a collaborative DDoS defense, comprised of a distributed system, COSSACK, and a stand-alone defense, D-WARD. The role of the blue team was played by developers of the tested systems from USC/ISI and UCLA, the red team included researchers from Sandia National Laboratory, and all the coordination, experiment execution, result collection and analysis was performed by the white team from BBN Technologies. This exercise was of immense value to all involved --- it uncovered significant vulnerabilities in tested systems, pointed out desirable characteristics in DDoS defense systems (e.g., avoiding reliance on timing mechanisms), and taught us many lessons about testing of DDoS defenses. Jelena Mirkovic, Peter L. Reiher, Christos Papadopoulos, Alefiya Hussain, Marla Shepard, Michael Berg, Robert Jung |
IEEE Trans. Computers | 1 |
| 2007 | A MAC Protocol with Multi-User MIMO Support for Ad-Hoc WLANsabstractMultiple Input-Multiple Output (MIMO) is a wide set of multiple antenna technologies, which significantly increase the capacity of wireless networks, without additional bandwidth or increased transmission power. They are widely recognized as methods that can meet the ever growing network capacity requirements. With a MIMO physical layer (PHY), the transmission channel gains a layered structure, which gives another degree of freedom in scheduling transmissions. Additionally, support from higher layers with a cross-layer approach that provides efficient management of the channel's spatial layers, can significantly increase the networks' performance on both link and system level. Single-User-DCF (SU-DCF), a Multiple Access Control (MAC) protocol with the support for Single-User (SU)-MIMO transmissions in Ad-Hoc WLANs, has been previously presented. In this paper we extend that protocol to support Multi-User (MU) transmissions. In the new protocol - Multi-User-DCF (MU-DCF), destination stations for the frames in a MIMO frame can be different stations. We have studied and compared different transmission strategies and schedulers including the IEEE 802.1 In system, to explore the benefits of transmitting in MU mode. Jelena Mirkovic, Dee Denteneer |
PIMRC | 1 |
| 2007 | A Centralized MAC Protocol with QoS Support for Wireless LANsabstractWireless Local Area Networks (WLANs) are widely used in homes and offices, as well as in public places, mainly as the last mile of an Internet connection, but also as an interconnection between different devices. This extensive usage of WLANs, with the need of modern applications (such as Voice over IP) for high throughput and low transmission delays, impose the necessity for efficient protocols with Quality of Service (QoS) support. In previous work [6] the ability of Multi Carrier-Code Division Multiple Access (MC-CDMA) based Medium Access Control (MAC) protocols to achieve high efficiency has been demonstrated. This paper presents a MAC protocol, based on MC-CDMA that uses an Access Point (AP) to centrally control the network and provide QoS support. Extensive simulation results and a comparison with the standard IEEE 802.11e[3] prove the efficiency of the proposed protocol. Georgios Orfanos, Jelena Mirkovic, Bernhard Walke, Sunil Kumar Emmadi |
PIMRC | 2 |
| 2007 | When is service really denied?: a user-centric dos metricabstractDenial-of-service (DoS) research community lacks accurate metrics to evaluate an attack's impact on network services, its severity and the effectiveness of a potential defense. We propose several DoS impact metrics that measure the quality of service experienced by end users during an attack, and compare these measurements to application-specific thresholds. Our metrics are ideal for testbed experimentation, since necessary traffic parameters are extracted from packet traces gathered during an experiment. Jelena Mirkovic, Alefiya Hussain, Brett Wilson, Sonia Fahmy, Wei-Min Yao, Peter L. Reiher, Stephen Schwab, Roshan K. Thomas |
SIGMETRICS | 1 |
| 2007 | A MAC Protocol for MIMO Based IEEE 802.11 Wireless Local Area NetworksabstractAn increasing number of wireless devices and services imposes higher demands for wireless networks' capacity. Likewise, contemporary bandwidth requirements of each user in the network rise significantly, being a mixture of traffic types such as Web surfing, file transfer protocol (FTP), video, video-teleconference, and voice. Multiple input-multiple output (MIMO) techniques are recognized as methods that can meet these requirements, since they significantly increase the capacity of wireless networks, without additional bandwidth or transmission power. With a MIMO physical layer (PHY), the transmission channel gets a layered structure. Consequently, support from higher layers with a cross-layer approach that provides efficient management of the channel's spatial layers, can significantly increase the network's performance on both link and system level. In this paper a high capacity medium access control (MAC) protocol for MIMO support is presented. The proposed protocol is based on IEEE 802.11 standard, and provides a flexible and scalable support for multiple antenna terminals, backwards compatible with legacy stations. Jelena Mirkovic, Georgios Orfanos, Hans-Jürgen Reumerman, Dee Denteneer |
WCNC | 1 |
| 2006 | A Framework for a Collaborative DDoS DefenseabstractIncreasing use of the Internet for critical services makes flooding distributed denial-of-service (DDoS) a top security threat. A distributed nature of DDoS suggests that a distributed mechanism is necessary for a successful defense. Three main DDoS defense functionalities -- attack detection, rate limiting and traffic differentiation -- are most effective when performed at the victim-end, core and sourceend respectively. Many existing systems are successful in one aspect of defense, but none offers a comprehensive solution and none has seen a wide deployment. We propose to harvest the strengths of existing defenses by organizing them into a collaborative overlay, called DefCOM, and augmenting them with communication and collaboration functionalities. Nodes collaborate during the attack to spread alerts and protect legitimate traffic, while rate limiting the attack. DefCOM can accommodate existing defenses, provide synergistic response to attacks and naturally lead to an Internet-wide response to DDoS threat. George C. Oikonomou, Jelena Mirkovic, Peter L. Reiher, Max Robinson |
ACSAC | 2 |
| 2006 | MIMO Link Modeling for System Level SimulationsabstractMIMO (multiple input - multiple output) systems apply multiple antennas to increase signal to noise ratio (SNR), reduce interference and/or send multiple streams simultaneously over a single channel. Besides increasing the data rate of the physical layer (PHY), benefits can be achieved with cross-layer optimization approach exploiting the layered structure of the channel. In this paper we focus on MIMO schemes with multiplexing and/or diversity gain and present a link model for system level simulations. The model maps total SNR to achievable link level throughput, both per spatial subchannel and cumulative. The model can be combined with an arbitrary coding and modulation scheme and is abstract enough to be applied to any system protocol, fulfilling the given conditions about channel propagation characteristics Jelena Mirkovic, Georgios Orfanos, Hans-Jürgen Reumerman |
PIMRC | 1 |
| 2005 | D-WARD: A Source-End Defense against Flooding Denial-of-Service AttacksabstractDefenses against flooding distributed denial-of-service (DDoS) commonly respond to the attack by dropping the excess traffic, thus reducing the overload at the victim. The major challenge is the differentiation of the legitimate from the attack traffic, so that the dropping policies can be selectively applied. We propose D-WARD, a source-end DDoS defense system that achieves autonomous attack detection and surgically accurate response, thanks to its novel traffic profiling techniques, the adaptive response and the source-end deployment. Moderate traffic volumes seen near the sources, even during the attacks, enable extensive statistics gathering and profiling, facilitating high response selectiveness. D-WARD inflicts an extremely low collateral damage to the legitimate traffic, while quickly detecting and severely rate-limiting outgoing attacks. D-WARD has been extensively evaluated in a controlled testbed environment and in real network operation. Results of selected tests are presented in the paper. Jelena Mirkovic, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2004 | Performance evaluation for IEEE 802.11G hot spot coverage using sectorised antennasabstractWireless local area networks (WLANs) have a tremendous success in today short range communication. The user density is permanently increasing and the planning focus shifts from pure coverage issues towards capacity improvements. As IEEE 802.11 was originally planned for ragged coverage, cell planning issues have been neglected. Especially for hot spots they now become important. In this paper, we show the supply of an exhibition hall with IEEE 802.11 service using sectorised antennas. A capacity increase by a factor 2 compared to omnidirectional antennas shows that this proven technology also works in the decentralised area. Special problems of the IEEE 802.11 system are investigated by a performance evaluation using stochastical simulations. Arif Otyakmaz, Ulrich Fornefeld, Jelena Mirkovic, Daniel C. Schultz, Erik Weiss |
PIMRC | 3 |
| 2003 | Source-End DDoS DefenseabstractA successful source-end DDoS (distributed denial-of-service) defense enables early suppression of the attack and minimizes collateral damage. However, such an approach faces many challenges: (a) distributing the attack hinders detection; (b) defense systems must guarantee good service to legitimate traffic during the attack; and (c) deployment costs and false alarm levels must be sufficiently small and effectiveness must be high to provide deployment incentive. We discuss each of the challenges and describe one successful design of a source-end DDoS defense system-the D-WARD system. D-WARD was implemented in a Linux router. We include experimental results to illustrate D-WARD's performance. Jelena Mirkovic, Gregory Prier, Peter L. Reiher |
NCA | 1 |
| 2003 | Alliance formation for DDoS defenseabstractCurrently, there is no effective defense against large-scale distributed denial-of-service (DDoS) attacks. While numerous DDoS defense systems exist that offer excellent protection from specific attack types and scenarios, they can frequently be defeated by an attacker aware of their weaknesses. A necessary requirement for successful DDoS defense is wide deployment, but none of these systems can guarantee wide deployment simply because deployment depends more on market and social aspects than on the technical performance of the system.To successfully handle the DDoS threat we must abandon the current paradigm---the design of defense systems that operate in isolation---and shift toward a new paradigm, a distributed framework of heterogeneous systems that cooperate to achieve an effective defense. Heterogeneity is dictated by two major factors. First, the necessary requirements for a successful defense are detection, response and traffic differentiation. These requirements must be met at disjoint points in the Internet and require a disjoint set of functionalities from the defense systems. Second, heterogeneity is dictated by the current state of the DDoS defense field in which numerous systems exist that can offer similar performance and compete for market share. In this paper we show how the paradigm shift can be accomplished quickly and painlessly through the design of DefCOM, a distributed framework that enables the exchange of information and services between existing defense nodes. Jelena Mirkovic, Max Robinson, Peter L. Reiher |
NSPW | 1 |
| 2002 | Attacking DDoS at the SourceabstractDistributed denial-of-service (DDoS) attacks present an Internet-wide threat. We propose D-WARD, a DDoS defense system deployed at source-end networks that autonomously detects and stops attacks originating from these networks. Attacks are detected by the constant monitoring of two-way traffic flows between the network and the rest of the Internet and periodic comparison with normal flow models. Mismatching flows are rate-limited in proportion to their aggressiveness. D-WARD offers good service to legitimate traffic even during an attack, while effectively reducing DDoS traffic to a negligible level. A prototype of the system has been built in a Linux router. We show its effectiveness in various attack scenarios, discuss motivations for deployment, and describe associated costs. Jelena Mirkovic, Gregory Prier, Peter L. Reiher |
ICNP | 1 |
| 2002 | SAVE: Source Address Validity Enforcement ProtocolabstractForcing all IP packets to carry correct source addresses can greatly help network security, attack tracing, and network problem debugging. However, due to asymmetries in today's Internet routing, routers do not have readily available information to verify the correctness of the source address for each incoming packet. In this paper we describe a new protocol, named SAVE, that can provide routers with the information needed for source address validation. SAVE messages propagate valid source address information from the source location to all destinations, allowing each router along the way to build an incoming table that associates each incoming interface of the router with a set of valid source address blocks. This paper presents the protocol design and evaluates its correctness and performance by simulation experiments. The paper also discusses the issues of protocol security, the effectiveness of partial SAVE deployment, and the handling of unconventional forms of network routing, such as mobile IP and tunneling. Jun Li 0001, Jelena Mirkovic, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
INFOCOM | 2 |
| 2001 | A self-organizing approach to data forwarding in large-scale sensor networksabstractThe large number of networked sensors, frequent sensor failures and stringent energy constraints pose unique design challenges for data forwarding in wireless sensor networks. In this paper, we present a new approach to data forwarding in sensor networks that effectively addresses these design issues. Our approach organizes sensors into a dynamic, self-optimizing multicast tree-based forwarding hierarchy, which is data centric and robust to node failures. We demonstrate the effectiveness of our design through simulations. Jelena Mirkovic, Geetha Priya Venkataramani, Songwu Lu, Lixia Zhang 0001 |
ICC | 1 |