Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Niels Provos

dblp:90/6745 · DBLP profile ↗
← Back
20ranked-venue papers
8as first author
0since 2021 · last 2016
0009-0006-8446-3978ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 7 first-authorComputer networks · 3Systems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
16 papers
Malware analysis · 41% Systems and software security · 20% Web and mobile security · 17%
Computer networks
3 papers
Network measurement and analytics · 83% Internet architecture and protocols · 17%

Topics — the 23 heaviest of 29, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis
pay-per-install
0.212016
Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software · USENIX Security Symposium 2016
Malware analysis
malware defense
0.212013
CAMP: Content-Agnostic Malware Protection · NDSS 2013
Systems and software security › exploitation › injection attacks
code injection attack
0.112011
SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks · USENIX Security Symposium 2011
Network security › protocol security
DNS security
0.112008
Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority · NDSS 2008
Web and mobile security
web attacks
0.112008
All Your iFRAMEs Point to Us · USENIX Security Symposium 2008
Network security
malware propagation
0.112016
Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software · USENIX Security Symposium 2016
Digital forensics and information hiding
steganography
0.122002
Detecting Steganographic Content on the Internet · NDSS 2002
Defending Against Statistical Steganalysis · USENIX Security Symposium 2001
Web and mobile security
browser security
0.112015
Trends and Lessons from Three Years Fighting Malicious Extensions · USENIX Security Symposium 2015
Network measurement and analytics
traffic analysis
0.112005
Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic · Internet Measurement Conference 2005
Network security › traffic analysis
network telescope analysis
0.112005
Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic · Internet Measurement Conference 2005
Systems and software security
vulnerability discovery
0.012013
CAMP: Content-Agnostic Malware Protection · NDSS 2013
Network security › cyber deception
honeypot
0.012004
A Virtual Honeypot Framework · USENIX Security Symposium 2004
Systems and software security › platform security
host security
0.012003
Improving Host Security with System Call Policies · USENIX Security Symposium 2003
Systems and software security › exploitation mitigation
privilege escalation prevention
0.012003
Preventing Privilege Escalation · USENIX Security Symposium 2003
Digital forensics and information hiding › digital forensics
forensic analysis
0.012011
SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks · USENIX Security Symposium 2011
Digital forensics and information hiding
steganalysis
0.012002
Detecting Steganographic Content on the Internet · NDSS 2002
Systems and software security
memory protection
0.012000
Encrypting Virtual Memory · USENIX Security Symposium 2000
Internet architecture and protocols › domain name system
DNS resolution
0.012008
Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority · NDSS 2008
Malware analysis › web-based malware
drive-by downloads
0.012008
All Your iFRAMEs Point to Us · USENIX Security Symposium 2008
Operating systems › system security › operating system security
access control
0.022003
Preventing Privilege Escalation · USENIX Security Symposium 2003
Improving Host Security with System Call Policies · USENIX Security Symposium 2003
Network security › intrusion detection and prevention
intrusion detection
0.012004
A Virtual Honeypot Framework · USENIX Security Symposium 2004
Digital forensics and information hiding
information hiding
0.012001
Defending Against Statistical Steganalysis · USENIX Security Symposium 2001
Memory systems › memory management
virtual memory
0.012000
Encrypting Virtual Memory · USENIX Security Symposium 2000

Methods — techniques the papers use, named apart from their topics

revenue chain analysis · 0.4measurement pipeline · 0.4measurement study · 0.4machine learning · 0.2natural language processing · 0.2data reduction · 0.1encryption · 0.1statistical detection · 0.0statistical steganalysis · 0.0
YearPublicationVenuePosition
2016 Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software
Kurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod, Cait Phillips, Marc-André Decoste, Chris Sharp, Fabio Tirelo, Ali Tofigh, Marc-Antoine Courteau, Lucas Ballard, Robert Shield, Nav Jagpal, Moheeb Abu Rajab, Panayiotis Mavrommatis, Niels Provos, Elie Bursztein, Damon McCoy
USENIX Security Symposium16
2015 Ad Injection at Scale: Assessing Deceptive Advertisement Modifications
abstract
Today, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Google -- tens of millions of users around the globe. Injected ads arrive on a client's machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved.
Kurt Thomas, Elie Bursztein, Chris Grier, Grant Ho, Nav Jagpal, Alexandros Kapravelos, Damon McCoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab
IEEE Symposium on Security and Privacy11
2015 Trends and Lessons from Three Years Fighting Malicious Extensions
Nav Jagpal, Eric Dingle, Jean-Philippe Gravel, Panayiotis Mavrommatis, Niels Provos, Moheeb Abu Rajab, Kurt Thomas
USENIX Security Symposium5
2013 CAMP: Content-Agnostic Malware Protection
Moheeb Abu Rajab, Lucas Ballard, Noe Lutz, Panayiotis Mavrommatis, Niels Provos
NDSS5
2012 Manufacturing compromise: the emergence of exploit-as-a-service
abstract
We investigate the emergence of the exploit-as-a-service model for driveby browser compromise. In this regime, attackers pay for an exploit kit or service to do the "dirty work" of exploiting a victim's browser, decoupling the complexities of browser and plugin vulnerabilities from the challenges of generating traffic to a website under the attacker's control. Upon a successful exploit, these kits load and execute a binary provided by the attacker, effectively transferring control of a victim's machine to the attacker.
Chris Grier, Lucas Ballard, Juan Caballero, Neha Chachra, Christian Dietrich 0005, Kirill Levchenko, Panayiotis Mavrommatis, Damon McCoy, Antonio Nappa, Andreas Pitsillidis, Niels Provos, M. Zubair Rafique, Moheeb Abu Rajab, Christian Rossow, Kurt Thomas, Vern Paxson, Stefan Savage, Geoffrey M. Voelker
CCS11
2011 SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks
Kevin Z. Snow, Srinivas Krishnan, Fabian Monrose, Niels Provos
USENIX Security Symposium4
2010 Peeking Through the Cloud: Client Density Estimation via DNS Cache Probing
abstract
Reliable network demographics are quickly becoming a much sought-after digital commodity. However, as the need for more refined Internet demographics has grown, so too has the tension between privacy and utility. Unfortunately, current techniques lean too much in favor of functional requirements over protecting the privacy of users. For example, the most prominent proposals for measuring the relative popularity of a Web site depend on the deployment of client-side measurement agents that are generally perceived as infringing on users’ privacy, thereby limiting their wide-scale adoption. Moreover, the client-side nature of these techniques also makes them susceptible to various manipulation tactics that undermine the integrity of their results. In this article, we propose a new estimation technique that uses DNS cache probing to infer the density of clients accessing a given service. Compared to earlier techniques, our scheme is less invasive as it does not reveal user-specific traits, and is more robust against manipulation. We demonstrate the flexibility of our approach through two important security applications. First, we illustrate how our scheme can be used as a lightweight technique for measuring and verifying the relative popularity rank of different Web sites. Second, using data from several hundred botnets, we apply our technique to indirectly measure the infected population of this increasing Internet phenomenon.
Moheeb Abu Rajab, Fabian Monrose, Niels Provos
ACM Trans. Internet Techn.3
2008 Peeking Through the Cloud: DNS-Based Estimation and Its Applications
Moheeb Abu Rajab, Fabian Monrose, Andreas Terzis, Niels Provos
ACNS4
2008 Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority
David Dagon, Niels Provos, Christopher P. Lee 0001, Wenke Lee
NDSS2
2008 All Your iFRAMEs Point to Us
Niels Provos, Panayiotis Mavrommatis, Moheeb Abu Rajab, Fabian Monrose
USENIX Security Symposium1
2008 To Catch a Predator: A Natural Language Approach for Eliciting Malicious Payloads
Sam Small, Joshua Mason, Fabian Monrose, Niels Provos, Adam Stubblefield
USENIX Security Symposium4
2006 Flow-Cookies: Using Bandwidth Amplification to Defend Against DDoS Flooding Attacks
abstract
This paper describes flow-cookies which defend against DDoS flooding attacks using bandwidth amplification. "Flow-cookies" is a mechanism in which a Website can reliably send filtering requests to a cooperating node in the network, leveraging its protection bandwidth. In this approach, a third party provider installs a flow-cookies enabled middlebox called the cookie box, in the network at a high bandwidth link. All traffic to or from the protected Web server must traverse the cookie box. The cookie box guarantees that all packets that pass between it and the server belong to a legitimate TCP flow with a valid sender. This implementation is able to operate at gigabit speeds including per-packet IP filtering of millions of addresses. This approach is also very effective against high volume SYN flooding attacks
Martín Casado, Aditya Akella, Niels Provos
IWQoS4
2005 Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic
Michael D. Bailey, Evan Cooke, Farnam Jahanian, Niels Provos, Karl Rosaen, David Watson 0001
Internet Measurement Conference4
2004 A Virtual Honeypot Framework
Niels Provos
USENIX Security Symposium1
2003 Improving Host Security with System Call Policies
Niels Provos
USENIX Security Symposium1
2003 Preventing Privilege Escalation
Niels Provos, Markus Friedl, Peter Honeyman
USENIX Security Symposium1
2002 Detecting Steganographic Content on the Internet
Niels Provos, Peter Honeyman
NDSS1
2001 ScanSSH: Scanning the Internet for SSH Servers
Niels Provos, Peter Honeyman
LISA1
2001 Defending Against Statistical Steganalysis
Niels Provos
USENIX Security Symposium1
2000 Encrypting Virtual Memory
Niels Provos
USENIX Security Symposium1