EDBT 2026 Demo / reviewers in the wild / expert
David Barrera 0003
dblp:91/7087-3
· DBLP profile ↗
17ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0003-2319-9916ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Workshop on Cybersecurity and Sustainability
David Barrera 0003, Maxwell Keleher, Sonia Chiasson |
COMPASS | 1 |
| 2025 | Houdini: Benchmarking Container Security ConfinementabstractWhile container-based workloads are now a standard part of cloud infrastructure, container security remains a challenge. Container confinement is a particularly pressing problem, as without it, a single vulnerable application can be used to compromise entire clusters of containers. Many container confinement technologies are available, but currently there is no easy way to verify whether a given configuration provides even a basic level of protection. This paper presents Houdini, a security test suite for container confinement. While it can be used to test deployable containers, Houdini is optimized for testing and comparing container confinement technologies. This paper presents the motivation, design, implementation, and initial results of running Houdini on a set of Docker container configurations. By providing a benchmark framework by which container confinement technologies can be evaluated, we believe Houdini can help foster the development of next-generation container confinement technologies. Huzaifa Patel, David Barrera 0003, Anil Somayaji |
PST | 2 |
| 2024 | Balancing Security and Longevity: Benefits of Modular IoT InfrastructureabstractIoT device disposal involves all of the challenges associated with disposal of non-IoT devices, and introduces the additional challenge of purging sensitive data from the IoT components. These challenges push IoT device owners to make decisions with negative environmental, security, and privacy consequences. This paper investigates the extent to which security and privacy play a role in users’ decisions to retire home IoT devices. Through an online questionnaire administered to 195 users, we seek to understand motivations and behaviours surrounding disposal of IoT devices. We find that security is not a direct motivator for owners to cease using IoT devices of all types; in many cases loss of functionality is a greater motivator to dispose of a device. We argue that a new modular security paradigm can allow both increased security for users and longer lasting devices. Maxwell Keleher, David Barrera 0003, Sonia Chiasson |
NSPW | 2 |
| 2023 | Escaping Vendor Mortality: A New Paradigm for Extending IoT Device LongevityabstractInternet of Things (IoT) devices are increasingly being treated as disposable, becoming unsupported shortly after deployment and ending up in landfills prematurely. IoT manufacturers lock devices to their ecosystems and prioritize the development of new devices over the support of legacy product lines. This paper argues that a paradigm shift is needed to increase IoT device longevity. We review the unique challenges that IoT manufacturers face in extending device lifetimes, and identify software and security updates as a key requirement for device longevity. We propose a new IoT device software stack and lifecycle that allows devices to continue safe operation even after the vendor disappears. While we recognize that the sustainable design and management of IoT devices is a complex sociotechnical problem, we hope that the ideas in this paper helps guide future discussions on this important topic. Conner Bradley, David Barrera 0003 |
NSPW | 2 |
| 2023 | Security Best Practices: A Critical Analysis Using IoT as a Case StudyabstractAcademic research has highlighted the failure of many Internet of Things (IoT) product manufacturers to follow accepted practices, while IoT security best practices have recently attracted considerable attention worldwide from industry and governments. Given current examples of security advice, confusion is evident from guidelines that conflate desired outcomes with security practices to achieve those outcomes. We explore a surprising lack of clarity, and void in the literature, on what (generically) best practice means, independent of identifying specific individual practices or highlighting failure to follow best practices. We consider categories of security advice, and analyze how they apply over the lifecycle of IoT devices. For concreteness in discussion, we use iterative inductive coding to code and systematically analyze a set of 1,013 IoT security best practices, recommendations, and guidelines collated from industrial, government, and academic sources. Among our findings, of all analyzed items, 68% fail to meet our definition of an (actionable) practice, and 73% of all actionable advice relates to the software development lifecycle phase, highlighting the critical position of manufacturers and developers. We hope that our work provides a basis for the community to better understand best practices, identify and reach consensus on specific practices, and find ways to motivate relevant stakeholders to follow them. David Barrera 0003, Christopher Bellman, Paul C. van Oorschot |
ACM Trans. Priv. Secur. | 1 |
| 2020 | SERENIoT: Distributed Network Security Policy Management and Enforcement for Smart HomesabstractSelectively allowing network traffic has emerged as a dominant approach for securing consumer IoT devices. However, determining what the allowed behavior of an IoT device should be remains an open challenge. Proposals to date have relied on manufacturers and trusted parties to provide allow lists of network traffic, but these proposals require manufacturer involvement or placing trust in an additional stakeholder. Alternatively, locally monitoring devices can allow building allow lists of observed behavior, but devices may not exhaust their functionality set during the observation period, and the behavior may change following a software update which requires re-training. This paper proposes a blockchain-based system for determining whether an IoT device is behaving like other devices of the same type. Our system, SERENIoT, overcomes the challenge of initially determining the correct behavior for a device. Nodes in the SERENIoT public blockchain submit summaries of the network behavior observed for connected IoT devices and build allow lists of behavior observed by the majority of nodes. Changes in behavior through software updates are automatically added to the allow list once the update is broadly deployed. Through a proof-of-concept implementation of SERENIoT on a small IoT network and a large-scale Amazon EC2 simulation, we evaluate the security, scalability, and performance of our system. Corentin Thomasset, David Barrera 0003 |
ACSAC | 2 |
| 2020 | Understanding Cybersecurity Practices in Emergency DepartmentsabstractEmergency departments (EDs) have unique operational requirements within hospitals. They have strong availability demands, are staffed by rotating personnel, and must provide services as quickly as possible. Modern EDs are also heavily computerized, and as such cybersecurity practices play a key role in meeting the expected operational standards. To better understand the cybersecurity challenges in EDs, we conducted a survey asking 347 ED personnel across Canada about their cybersecurity practices. The survey collected information relating to authentication and password management, use of personal devices for handling patient data, Internet connectivity on personal and hospital systems, and institutional security policies. Our results show that across multiple hospitals, deployed computer security systems fail to integrate with the requirements of staff and patients, leading to interruptions and inefficiencies. Elizabeth Stobert, David Barrera 0003, Valérie Homier, Daniel Kollek |
CHI | 2 |
| 2018 | TARANET: Traffic-Analysis Resistant Anonymity at the Network LayerabstractModern low-latency anonymity systems, no matter whether constructed as an overlay or implemented at the network layer, offer limited security guarantees against traffic analysis. On the other hand, high-latency anonymity systems offer strong security guarantees at the cost of computational overhead and long delays, which are excessive for interactive applications. We propose TARANET, an anonymity system that implements protection against traffic analysis at the network layer, and limits the incurred latency and overhead. In TARANET's setup phase, traffic analysis is thwarted by mixing. In the data transmission phase, end hosts and ASes coordinate to shape traffic into constant-rate transmission using packet splitting. Our prototype implementation shows that TARANET can forward anonymous traffic at over 50 Gbps using commodity hardware. Chen Chen 0013, Daniele Enrico Asoni, Adrian Perrig, David Barrera 0003, George Danezis, Carmela Troncoso |
EuroS&P | 4 |
| 2016 | Source Accountability with Domain-brokered PrivacyabstractIn an ideal Internet, every packet would be attributable to its sender, while host identities and transmitted content would remain private. Designing such a network is challenging because source accountability and communication privacy are typically viewed as conflicting properties. In this paper, we propose an architecture that guarantees source accountability and privacy-preserving communication by enlisting ISPs as accountability agents and privacy brokers. While ISPs can link every packet that originates from their network to their customers, customer identity remains unknown to the rest of the Internet. In our architecture, network communication is based on Ephemeral Identifiers (EphIDs)---cryptographic tokens that can be linked to a source only by the source's ISP. We demonstrate that EphIDs can be generated and processed efficiently, and we analyze the practical considerations for deployment. Taeho Lee 0003, Christos Pappas, David Barrera 0003, Pawel Szalachowski, Adrian Perrig |
CoNEXT | 3 |
| 2015 | HORNET: High-speed Onion Routing at the Network LayerabstractWe present HORNET, a system that enables high-speed end-to-end anonymous channels by leveraging next-generation network architectures. HORNET is designed as a low-latency onion routing system that operates at the network layer thus enabling a wide range of applications. Our system uses only symmetric cryptography for data forwarding yet requires no per-flow state on intermediate routers. This design enables HORNET routers implemented on off-the-shelf hardware to process anonymous traffic at over 93 Gb/s. HORNET is also highly scalable, adding minimal processing overhead per additional anonymous channel. Chen Chen 0013, Daniele Enrico Asoni, David Barrera 0003, George Danezis, Adrian Perrig |
CCS | 3 |
| 2014 | Baton: certificate agility for android's decentralized signing infrastructureabstractAndroid's trust-on-first-use application signing model associates developers with a fixed code signing certificate, but lacks a mechanism to enable transparent key updates or certificate renewals. The model allows application updates to be recognized as authorized by a party with access to the original signing key. However, changing keys or certificates requires that end users manually uninstall/reinstall apps, losing all non-backed up user data. In this paper, we show that with appropriate OS support, developers can securely and without user intervention transfer signing authority to a new signing key. Our proposal, Baton, modifies Android's app installation framework enabling key agility while preserving backwards compatibility with current apps and current Android releases. Baton is designed to work consistently with current UID sharing and signature permission requirements. We discuss technical details of the Android-specific implementation, as well as the applicability of the Baton protocol to other decentralized environments. David Barrera 0003, Daniel McCarney, Jeremy Clark, Paul C. van Oorschot |
WISEC | 1 |
| 2012 | ThinAV: truly lightweight mobile cloud-based anti-malwareabstractThis paper introduces ThinAV, an anti-malware system for Android that uses pre-existing web-based file scanning services for malware detection. The goal in developing ThinAV was to assess the feasibility of providing real-time anti-malware scanning over a wide area network where resource limitation is a factor. As a result, our research provides a necessary counterpoint to many of the big-budget, resource-intensive idealized solutions that have been suggested in the area of cloud-based security. The evaluation of ThinAV shows that it functions well over a wide area network, resulting in a system which is highly practical for providing anti-malware security on smartphones. Chris Jarabek, David Barrera 0003, John Aycock |
ACSAC | 2 |
| 2012 | Tapas: design, implementation, and usability evaluation of a password managerabstractPasswords continue to prevail on the web as the primary method for user authentication despite their well-known security and usability drawbacks. Password managers offer some improvement without requiring server-side changes. In this paper, we evaluate the security of dual-possession authentication, an authentication approach offering encrypted storage of passwords and theft-resistance without the use of a master password. We further introduce Tapas, a concrete implementation of dual-possession authentication leveraging a desktop computer and a smartphone. Tapas requires no server-side changes to websites, no master password, and protects all the stored passwords in the event either the primary or secondary device (e.g., computer or phone) is stolen. To evaluate the viability of Tapas as an alternative to traditional password managers, we perform a 30 participant user study comparing Tapas to two configurations of Firefox's built-in password manager. We found users significantly preferred Tapas. We then improve Tapas by incorporating feedback from this study, and reevaluate it with an additional 10 participants. Daniel McCarney, David Barrera 0003, Jeremy Clark, Sonia Chiasson, Paul C. van Oorschot |
ACSAC | 2 |
| 2010 | A methodology for empirical analysis of permission-based security models and its application to androidabstractPermission-based security models provide controlled access to various system resources. The expressiveness of the permission set plays an important role in providing the right level of granularity in access control. In this work, we present a methodology for the empirical analysis of permission-based security models which makes novel use of the Self-Organizing Map (SOM) algorithm of Kohonen (2001). While the proposed methodology may be applicable to a wide range of architectures, we analyze 1,100 Android applications as a case study. Our methodology is of independent interest for visualization of permission-based systems beyond our present Android-specific empirical analysis. We offer some discussion identifying potential points of improvement for the Android permission model attempting to increase expressiveness where needed without increasing the total number of permissions or overall complexity. David Barrera 0003, Hilmi Günes Kayacik, Paul C. van Oorschot, Anil Somayaji |
CCS | 1 |
| 2009 | FiGD: An Open Source Intellectual Property Violation Detector
Carson D. Brown, David Barrera 0003, Dwight Deugo |
SEKE | 2 |
| 2009 | Security visualization tools and IPv6 addressesabstractVisualization is used by security analysts to help detect patterns and trends in large volumes of network traffic data. With IPv6 slowly being deployed around the world, network intruders are beginning to adapt their tools and techniques to work over IPv6 (vs. IPv4). Many tools for visualizing network activity, while useful for detecting large scale attacks and network behavior anomalies still only support IPv4. In this paper, we explore the current state of IPv6 support in some popular security visualization tools and identify the roadblocks preventing those tools from supporting the new protocol. We propose a filtering technique that helps reduce the occlusion of IPv6 sources on graphs. We also suggest using treemaps for visually representing the vast space of remote addresses in IPv6. David Barrera 0003, Paul C. van Oorschot |
VizSEC | 1 |
| 2008 | Improving Security Visualization with Exposure Map FilteringabstractGraphical analysis of network traffic flows helps security analysts detect patterns or behaviors that would not be obvious in a text-based environment. The growing volume of network data generated and captured makes it increasingly difficult to detect increasingly sophisticated reconnaissance and stealthy network attacks. We propose a network flow filtering mechanism that leverages the exposure maps technique of Whyte et al. (2007), reducing the traffic for the visualization process according to the network services being offered. This allows focus to be limited to selected subsets of the network traffic, for example what might be categorized (correctly or otherwise) as the unexpected or potentially malicious portion. In particular, we use this technique to filter out traffic from sources that have not gained knowledge from the network in question. We evaluate the benefits of our technique on different visualizations of network flows. Our analysis shows a significant decrease in the volume of network traffic that is to be visualized, resulting in visible patterns and insights not previously apparent. Mansour Alsaleh, David Barrera 0003, Paul C. van Oorschot |
ACSAC | 2 |