Tuomas Aura

dblp:a/TAura · DBLP profile ↗
← Back
40ranked-venue papers
12as first author
5since 2021 · last 2026
0000-0003-1648-8875ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 28 · 11 first-author · 3 since 2021Computer networks · 4Human-computer interaction and ubiquitous computing · 3Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS
abstract
Remote attestation is increasingly being composed with different protocols to provide endpoint security. Transport Layer Security (TLS) is the most widely used among those protocols, and the composition of TLS with remote attestation is known as attested TLS protocol. Such protocols are used in security-critical applications, e.g., they serve as the backbone of an emerging computing paradigm, Confidential Computing (CC). In this work, we explore the identity crisis that results from ambiguous notions of identity for attested TLS protocols in CC. We present a formal approach with a set of comprehensive security goals and a generic template for the comparison of the security strengths of attested TLS protocols. Using the approach, we discover vulnerabilities in two state-of-the-art protocols. The Confidential Computing Consortium (CCC) attestation Special Interest Group (SIG) and TLS working group have acknowledged the vulnerabilities. To mitigate the vulnerabilities, we present a formally verified solution for vulnerabilities and propose several potential solutions, which are under discussion for standardization at the Internet Engineering Task Force (IETF).
Muhammad Usama Sardar, Mariam Moustafa, Tuomas Aura
AsiaCCS3
2025 Helm-ET: Reducing Exposure to Lateral Movement in Kubernetes Artifacts
abstract
Modern cloud applications consist of containerized microservices deployed to a virtual computing environment, such as a Kubernetes cluster. Policies are needed to block unintended and potentially harmful interactions between the microservices, which attackers could exploit for discovery and lateral move-ment. However, it is challenging for cluster administrators to define strict network policies because the interactions between the components are not clearly defined. Enabling them often requires manual inspection of the declarative configuration and the source code of the applications. This paper proposes a novel approach to creating Kubernetes network policies that restricts access between microservices within a cluster. Based on the principles of modularity and information hiding, we identify service composition patterns in cloud applications and use them to create network policies. The policy generation is implemented as an open-source tool, Helm-ET, which we evaluate on 451 Helm charts across three datasets. The results show that the proposed approach can significantly reduce the internal attack surface in the Kubernetes cluster (92.71 % less allowed connections), achieving comparable results to state-of-the-art tools. However, compared to other solutions, Helm-ET is faster (<100ms vs 79 seconds) and the policies before the application deplovment,
Jacopo Bufalino, Jose Luiz Martin Navarro, Aleksi Peltonen, Tuomas Aura
CLOUD4
2024 Security Analysis of the Consumer Remote SIM Provisioning Protocol
abstract
Remote SIM provisioning (RSP) for consumer devices is the protocol specified by the GSM Association for downloading SIM profiles into a secure element in a mobile device. The process is commonly known as eSIM, and it is expected to replace removable SIM cards. The security of the protocol is critical because the profile includes the credentials with which the mobile device will authenticate to the mobile network. In this article, we present a formal security analysis of the consumer RSP protocol. We model the multi-party protocol in applied pi calculus, define formal security goals, and verify them in ProVerif. The analysis shows that the consumer RSP protocol protects against a network adversary when all the intended participants are honest. However, we also model the protocol in realistic partial compromise scenarios where the adversary controls a legitimate participant or communication channel. The security failures in the partial compromise scenarios reveal weaknesses in the protocol design. The most important observation is that the security of RSP depends unnecessarily on it being encapsulated in a TLS tunnel. Also, the lack of pre-established identifiers means that a compromised download server anywhere in the world or a compromised secure element can be used for attacks against RSP between honest participants. Additionally, the lack of reliable methods for verifying user intent can lead to serious security failures. Based on the findings, we recommend practical improvements to RSP implementations, future versions of the specification, and mobile operator processes to increase the robustness of eSIM security.
Abu Shohel Ahmed, Aleksi Peltonen, Mohit Sethi, Tuomas Aura
ACM Trans. Priv. Secur.4
2023 Analyzing Microservice Connectivity with Kubesonde
abstract
Modern cloud-based applications are composed of several microservices that interact over a network. They are complex distributed systems, to the point that developers may not even be aware of how microservices connect to each other and to the Internet. As a consequence, the security of these applications can be greatly compromised. This work explicitly targets this context by providing a methodology to assess microservice connectivity, a software tool that implements it, and findings from analyzing real cloud applications. Specifically, it introduces Kubesonde, a cloud-native software that instruments live applications running on a Kubernetes cluster to analyze microservice connectivity, with minimal impact on performance. An assessment of microservices in 200 popular cloud applications with Kubesonde revealed significant issues in terms of network isolation: more than 60% of them had discrepancies between their declared and actual connectivity, and none restricted outbound connections towards the Internet. Our analysis shows that Kubesonde offers valuable insights on the connectivity between microservices, beyond what is possible with existing tools.
Jacopo Bufalino, Mario Di Francesco, Tuomas Aura
ESEC/SIGSOFT FSE3
2023 Threat modeling framework for mobile communication systems
abstract
This paper presents a domain-specific threat-modeling framework for the cellular mobile networks. We survey known attacks against mobile communication and organize them into attack phases, tactical objectives, and techniques. The Bhadra framework aims to provide a structured way to analyze and communicate threats on a level that abstracts away the technical details but still provides meaningful insights into the adversarial behavior. Our goals are similar to existing threat modeling frameworks for enterprise information systems, but with a focus on mobile operator networks. The framework fills a gap that has existed in tools and methodology for sharing of threat intelligence within and between organizations in the telecommunications industry. The paper includes concrete case studies of applying the framework. It can also be read as a survey of attacks against mobile networks. CCS CONCEPTS Security and privacy → Security requirements; Mobile and wireless security; Networks→ Networks Mobile networks
Siddharth Prakash Rao, Hsin Yi Chen, Tuomas Aura
Comput. Secur.3
2020 XSS Vulnerabilities in Cloud-Application Add-Ons
abstract
Many cloud-application vendors open their APIs for third-party developers to easily extend the functionality of their applications. The features implemented with these APIs are called add-ons (also called add-ins or apps). This is a relatively new phenomenon, and its effects on the application security have not been widely studied. It seems likely that some of the add-ons have lower code quality than the core applications themselves and, thus, may bring in security vulnerabilities. In this work, we found that many of such add-ons are vulnerable to cross-site scripting (XSS). The attacker can take advantage of the document-sharing and messaging features of the cloud applications to send malicious input to them. The vulnerable add-ons then execute client-side JavaScript from the carefully crafted malicious input. In a major analysis effort, we systematically studied 300 add-ons for three popular application suites, namely Microsoft Office Online, G Suite and Shopify, and discovered a significant percentage of vulnerable add-ons among them. We present the results of this study, as well as analyze the add-on architectures to understand how the XSS vulnerabilities can be exploited and how the threat can be mitigated.
Thanh Bui, Siddharth Prakash Rao, Markku Antikainen, Tuomas Aura
AsiaCCS4
2020 Formal verification of misbinding attacks on secure device pairing and bootstrapping
abstract
In identity misbinding attacks against authenticated key-exchange protocols, a legitimate but compromised participant manipulates the honest parties so that the victim becomes unknowingly associated with a third party. These attacks are well known, and resistance to misbinding is considered a critical requirement for security protocols on the Internet. In the context of device pairing, on the other hand, the attack has received little attention outside the trusted-computing community. This paper points out that most device pairing protocols are vulnerable to misbinding. Device pairing protocols are characterized by lack of a-priory information, such as identifiers and cryptographic roots of trust, about the other endpoint. Therefore, the devices in pairing protocols need to be identified by the user’s physical access to them. As case studies for demonstrating the misbinding vulnerability, we use Bluetooth and protocols that register new Internet of Things (IoT) devices to authentication servers on wireless networks. We have implemented the attacks. We also show how the attacks can be found in formal models of the protocols with carefully formulated correspondence assertions. The formal analysis yields a new type of double misbinding attack. While pairing protocols have been extensively modelled and analyzed, misbinding seems to be an aspect that has not previously received sufficient attention. Finally, we discuss potential ways to mitigate the threat and its significance to security of pairing protocols.
Aleksi Peltonen, Mohit Sethi, Tuomas Aura
J. Inf. Secur. Appl.3
2019 Misbinding Attacks on Secure Device Pairing and Bootstrapping
abstract
In identity misbinding attacks against authenticated key-exchange protocols, a legitimate but compromised participant manipulates the honest parties so that the victim becomes unknowingly associated with a third party. These attacks are well known, and resistance to misbinding is considered a critical requirement for security protocols on the Internet. In the context of device pairing, on the other hand, the attack has received little attention outside the trusted-computing community. This paper points out that most device pairing protocols are vulnerable to misbinding. Device pairing protocols are characterized by lack of a-priory information, such as identifiers and cryptographic roots of trust, about the other endpoint. Therefore, the devices in pairing protocols need to be identified by the user's physical access to them. As case studies for demonstrating the misbinding vulnerability, we use Bluetooth and a protocol that registers new IoT devices to authentication servers on wireless networks. We have implemented the attacks. We also show how the attacks can be found in formal models of the protocols with carefully formulated correspondence assertions. The formal analysis yields a new type of double misbinding attack. While pairing protocols have been extensively modelled and analyzed, misbinding seems to be an aspect that has not previously received sufficient attention. Finally, we discuss potential ways to mitigate the threat and its significance to security of pairing protocols.
Mohit Sethi, Aleksi Peltonen, Tuomas Aura
AsiaCCS3
2019 Watch Your Step! Detecting Stepping Stones in Programmable Networks
abstract
Hackers hide behind compromised intermediate hosts and pose advanced persistent threats (APTs). The compromised hosts are used as stepping stones to launch real attacks, as is evident from an incident that shook the world in 2016 - Panama Papers Leak. The major attack would not go unnoticed if the compromised stepping stone, in this case an email server, could be identified in time. In this paper, we explore how today's programmable networks could be retrofitted with effective stepping stone detection mechanisms to correlate flows. We share initial results to prove that such a setup exists. Lastly, we analyze scalability issues associated with the setup and explore recent developments in network monitoring which have potential to address these issues.
Debopam Bhattacherjee, Andrei V. Gurtov, Tuomas Aura
ICC3
2018 Security Wrapper Orchestration in Cloud
abstract
We present an architecture and implementation of the security wrapper concept for the protection of virtualized network functions in a cloud environment. The security wrapper is the enclosing of a set of virtualized resources within a data plane transparent protective envelope in the network forwarding graph. The extent and capabilities of this envelope are dynamic. We present a prototype implementation of the security wrapper and analyze its behaviour in different operation scenarios. Measurements of the wrapper orchestration delays, resource overhead and data plane traffic impact indicate that the proposed mechanism can be deployed in virtualized networks with little overhead while remaining relatively transparent to the traffic traversing the security wrapper boundary.
Aapo Kalliola, Shankar Lal, Kimmo Ahola, Ian Oliver, Yoan Miché, Tuomas Aura
ARES6
2018 Application of Public Ledgers to Revocation in Distributed Access Control
Thanh Bui, Tuomas Aura
ICICS2
2018 Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the Computer
Thanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan, Tuomas Aura
USENIX Security Symposium5
2018 Automated analysis of freeware installers promoted by download portals
abstract
We present an analysis system for studying Windows application installers. The analysis system is fully automated from installer download to execution and data collection. The system emulates the behavior of a lazy user who wants to finish the installation dialogs with the default options and with as few clicks as possible. The UI automation makes use of image recognition techniques and heuristics. During the installation, the system collects data about the system modification and network access. The analysis system is scalable and can run on bare-metal hosts as well as in a data center. We use the system to analyze 792 freeware application installers obtained from popular download portals. In particular, we measure how many of them drop potentially unwanted programs (PUP) such as browser plugins or make other unwanted system modifications. We discover that most installers that download executable files over the network are vulnerable to man-in-the-middle attacks. We also find, that while popular download portals are not used for blatant malware distribution, nearly 10% of the analyzed installers come with a third-party browser or a browser extension.
Alberto Geniola, Markku Antikainen, Tuomas Aura
Comput. Secur.3
2017 SynAPTIC: Secure And Persistent connecTIvity for Containers
abstract
Cloud virtualization technology is shifting towards light-weight containers, which provide isolated environments for running cloud-based services. The emerging trends such as container-based micro-service architectures and hybrid cloud deployments result in increased traffic volumes between the micro-services, mobility of the communication endpoints, and some of the communication taking place over untrusted networks. Yet, the services are typically designed with the assumption of scalable, persistent and secure connectivity. In this paper, we present the SynAPTIC architecture, which enables secure and persistent connectivity between mobile containers, especially in the hybrid cloud and in multi-tenant cloud networks. The solution is based on the standardized Host Identity Protocol (HIP) that tenants can deploy on top of existing cloud infrastructure independently of their cloud provider. Optional cloud-provider extensions based on Software-Defined Networking (SDN) further optimize the networking architecture. Our qualitative and quantitative evaluation shows that SynAPTIC performs better than some of the existing solutions.
Alireza Ranjbar, Miika Komu, Patrik Salmela, Tuomas Aura
CCGrid4
2016 An SDN-based approach to enhance the end-to-end security: SSL/TLS case study
abstract
End-to-end encryption is becoming the norm for many applications and services. While this improves privacy of individuals and organizations, the phenomenon also raises new kinds of challenges. For instance, with the increase of devices using encryption, the volumes of outdated, exploitable encryption software also increases. This may create some distrust amongst the users against security unless its quality is enforced in some ways. Unfortunately, deploying new mechanisms at the end-points of the communication is challenging due to the sheer volume of devices, and modifying the existing services may not be feasible either. Hence, we propose a novel method for improving the quality of the secure sessions in a centralized way based on the SDN architecture. Instead of inspecting the encrypted traffic, our approach enhances the quality of secure sessions by analyzing the plaintext handshake messages exchanged between a client and server. We exploit the fact that many of today's security protocols negotiate the security parameters such as the protocol version, encryption algorithms or certificates in plaintext in a protocol handshake before establishing a secure session. By verifying the negotiated information in the handshake, our solution can improve the security level of SSL/TLS sessions. While the approach can be extended to many other protocols, we focus on the SSL/TLS protocol in this paper because of its wide-spread use. We present our implementation for the OpenDaylight controller and evaluate its overhead to SSL/TLS session establishment in terms of latency.
Alireza Ranjbar, Miika Komu, Patrik Salmela, Tuomas Aura
NOMS4
2014 Secure bootstrapping of cloud-managed ubiquitous displays
abstract
Eventually, all printed signs and bulletins will be replaced by electronic displays, which are wirelessly connected to the Internet and cloud-based services. Deploying such ubiquitous displays can be cumbersome since they need to be correctly configured and authorized to access both the Internet and the necessary services, despite the fact that they have minimal input capabilities and may be in inaccessible locations. Our goal is to enable easy and secure configuration of ubiquitous displays such as digital signage and advertisements, which are managed by cloud services and show HTML5 content. In our solution, the display shows a QR code which, when scanned by the user with a camera phone, allows automatic configuration of the wireless network along with the content to be shown. This is accomplished by a long-term trust relation configured between the cloud service and the wireless access network. We build on existing technologies and standard protocols, including RADIUS and EAP, without requiring new software to be installed on the phone or changes to the network infrastructure.
Mohit Sethi, Elena Oat, Mario Di Francesco, Tuomas Aura
UbiComp4
2014 Commitment-based device pairing with synchronized drawing
abstract
Secure device pairing is a widely studied problem. Local wireless connections such as Bluetooth and WiFi typically rely on user-entered secret keys or manually verified authentication codes. Several recent proposals replace these with contextual or location-dependent sensor inputs, which are assumed to be secret from anyone not present at the location where the pairing takes place. These protocols have to cope with a fuzzy secret, i.e. noisy secret input that differs between the devices. In this paper, we overview such protocols and propose a new variation using time-based opening of commitments. Our protocol has the advantage of treating the fuzzy secret as one piece of data rather than requiring it to be partitioned into time intervals, and being more robust against variations in input entropy than those based on error correction codes. The protocol development is motivated by the discovery of a novel human source for the fuzzy secret: synchronized drawing with two fingers of the same hand on two touch screens or surfaces. Metrics for measuring the distance between the drawings are described and evaluated. We implement a prototype of this surprisingly simple and natural pairing mechanism and show that it accurately differentiates between true positives and man-in-the-middle attackers.
Mohit Sethi, Markku Antikainen, Tuomas Aura
PerCom3
2014 Logout in single sign-on systems: Problems and solutions
Sanna Suoranta, Kamran Manzoor, Asko Tontti, Joonas Ruuskanen, Tuomas Aura
J. Inf. Secur. Appl.5
2014 Adaptive and context-aware privacy preservation exploiting user interactions in smart environments
Gautham V. Pallapa, Sajal K. Das 0001, Mario Di Francesco, Tuomas Aura
Pervasive Mob. Comput.4
2014 Denial-of-Service Attacks in Bloom-Filter-Based Forwarding
abstract
Bloom-filter-based forwarding has been suggested to solve several fundamental problems in the current Internet, such as routing-table growth, multicast scalability issues, and denial-of-service (DoS) attacks by botnets. The proposed protocols are source-routed and include the delivery tree encoded as a Bloom filter in each packet. The network nodes forward packets based on this in-packet information without consulting routing tables and without storing per-flow state. We show that these protocols have critical vulnerabilities and make several false security assumptions. In particular, we present DoS attacks against broad classes of Bloom-filter-based protocols and conclude that the protocols are not ready for deployment on open networks. The results also help us understand the limitations and design options for Bloom-filter forwarding.
Markku Antikainen, Tuomas Aura, Mikko Särelä
IEEE/ACM Trans. Netw.2
2012 Scaling Bloom filter based multicast with hierarchical tree splitting
abstract
Bloom Filter based multicast has been proposed as a source-specific multicast solution to eliminate the multicast state requirements in the routers. However, the inherent limitation, the false positives, in the Bloom filter data structure amplifies the bandwidth wastage when the multicast tree scales to a large number of receivers. In this paper, we propose an algorithm which enhances the performance of the Bloom filter based multicast. It keeps the bandwidth waste below an acceptable upper bound while scaling the multicast tree for a large number of receivers. The large multicast tree is split into multiple smaller ones which are encoded into separate Bloom filters. Our algorithm enables multicast forwarding to be efficient - with careful setting of some parameters - for a hundreds of receivers as compared to the 20-30 receivers per group in the original technique. Furthermore, our algorithm, while slightly increasing the state requirements in the multicast sources, retains the desired property of statelessness in the intermediate routers.
Sajjad Rizvi, András Zahemszky, Tuomas Aura
ICC3
2012 Strong Authentication with Mobile Phone
Sanna Suoranta, André Andrade, Tuomas Aura
ISC3
2011 Forwarding anomalies in Bloom filter-based multicast
abstract
Several recently proposed multicast protocols use in-packet Bloom filters to encode multicast trees. These mechanisms are in principle highly scalable because no per-flow state is required in the routers and because routing decisions can be made efficiently by simply checking for the presence of outbound links in the filter. Yet, the viability of previous approaches is limited by the possibility of forwarding anomalies caused by false positives inherent in Bloom filters. This paper explores such anomalies, namely (1) packets storms, (2) forwarding loops and (3) flow duplication. We propose stateless solutions that increase the robustness and the scalability of Bloom filter-based multicast protocols. In particular, we show that the parameters of the filter need to be varied to guarantee the stability of the packet forwarding, and we present a bit permutation technique that effectively prevents both accidental and maliciously created anomalies. We evaluate our solutions in the context of BloomCast, a source-specific inter-domain multicast protocol, using analytical methods and simulations.
Mikko Särelä, Christian Esteve Rothenberg, Tuomas Aura, András Zahemszky, Pekka Nikander, Jörg Ott
INFOCOM3
2011 Security Analysis of Leap-of-Faith Protocols
Viet Pham, Tuomas Aura
SecureComm2
2010 How to Share Your Favourite Search Results while Preserving Privacy and Quality
George Danezis, Tuomas Aura, Shuo Chen 0001, Emre Kiciman
Privacy Enhancing Technologies2
2009 Privacy-preserving 802.11 access-point discovery
abstract
It is usual for 802.11 WLAN clients to probe actively for access points in order to hasten AP discovery and to find "hidden" APs. These probes reveal the client's list of preferred networks, thus, present a privacy risk: an eavesdropper can infer attributes of the client based on its associations with networks. We propose an access-point discovery protocol that supports fast discovery and hidden networks while also preserving privacy. Our solution is incrementally deployable, efficient, requires only small modifications to current client and AP implementations, interoperates with current networks, and does not change the user experience. We note that our solution is faster than the standard hidden-network discovery protocol based on measurements on a prototype implementation. Copyright 2009 ACM.
Janne Lindqvist, Tuomas Aura, George Danezis, Teemu Koponen, Annu Myllyniemi, Jussi Mäki, Michael Roe
WISEC2
2008 Chattering Laptops
Tuomas Aura, Janne Lindqvist, Michael Roe, Anish Mohammed
Privacy Enhancing Technologies1
2005 Analysis of the HIP Base Exchange Protocol
Tuomas Aura, Aarthi Nagarajan, Andrei V. Gurtov
ACISP1
2005 Reducing Reauthentication Delay in Wireless Networks
abstract
When a wireless mobile user is moving across a mobile network or between co-operating networks, the network operators often want to verify the user’s access rights before granting service. The security protocol causes a delay in the network access, which may be much longer than the typical delays caused by mobility management. An alternative would be to provide so called optimistic service before the user has been authenticated or paid for the access. Thus, there is a trade-off between the security of the access control and the quality of service observed by the user. Our aim is to reduce the authentication delay and to enable optimistic access without opening a window for fraudulent access. We present a protocol for the reauthentication of a mobile node when it repeatedly connects to different access points or cooperating wireless networks. The protocol is based on credentials which the mobile receives from access points as a proof of past honest behavior and which it presents when associating with a new access point. It can be implemented with keyed one-way functions that result in low computation and communication overhead both for the mobile and for the network.
Tuomas Aura, Michael Roe
SecureComm1
2004 Effects of Mobility and Multihoming on Transport-Protocol Security
abstract
The Stream Control Transmission Protocol (SCTP) is a reliable message-based transport protocol developed by the IETF that could replace TCP in some applications. SCTP allows endpoints to have multiple IP addresses for the purposes of fault tolerance. There is on-going work to extend the SCTP multihoming functions to support dynamic addressing and endpoint mobility. This paper explains how the multihoming and mobility features can be exploited for denial-of-service attacks, connection hijacking, and packet flooding. We propose implementation guidelines for SCTP and changes to the mobility extensions that prevent most of the attacks. The same lessons apply to multihomed TCP variants and other transport-layer protocols that incorporate some flavor of dynamic addressing.
Tuomas Aura, Pekka Nikander, Gonzalo Camarillo
S&P1
2003 Cryptographically Generated Addresses (CGA)
Tuomas Aura
ISC1
2002 Security of Internet Location Management
abstract
In the Mobile IPv6 protocol, the mobile node sends binding updates to its correspondents to inform them about its current location. It is well-known that the origin of this location information must be authenticated. This paper discusses several threats created by location management that go beyond unauthentic location data. In particular, the attacker can redirect data to bomb third parties and induce unnecessary authentication. We introduce and analyze protection mechanisms with focus on ones that work for all Internet nodes and do not need a PKI or other new security infrastructure. Our threat analysis and assessment of the defense mechanisms formed the basis for the design of a secure location management protocol for Mobile IPv6. Many of the same threats should be considered when designing any location management mechanism for open networks.
Tuomas Aura, Michael Roe, Jari Arkko
ACSAC1
2000 Analyzing Single-Server Network Inhibition
abstract
Network inhibition is a denial-of-service attack where the adversary attempts to disconnect network elements by disabling a limited number of communication links or nodes. We analyze a common variation of network inhibition where the links have infinite capacity and the goal of the attacker is to deny connections from a single server to as many clients as possible. The problem is defined formally and shown to be NP complete. Nevertheless, we develop a practical technique for network-inhibition analysis based on logic programming with stable-model semantics. The analysis scales well up to moderate-size networks. The results are a step towards quantitative analysis of denial of service and they can be applied to the design of robust network topologies.
Tuomas Aura, Matt Bishop, Dean Sniegowski
CSFW1
2000 Towards Network Denial of Service Resistant Protocols
Jussipekka Leiwo, Tuomas Aura, Pekka Nikander
SEC2
2000 Using Conservation of Flow as a Security Mechanism in Network Protocols
abstract
The law of conservation of flow, which states that an input must either be absorbed or sent on as an output (possibly with modification), is an attractive tool with which to analyze network protocols for security properties. One of its uses is to detect disruptive network elements that launch denial of service attacks by absorbing or discarding packets. Its use requires several assumptions about the protocols being analyzed. We examine the WATCHERS algorithm to detect misbehaving routers. We show that it uses conservation of flow without sufficient verification of its assumptions, and can consequently be defeated. We suggest improvements to make the use of conservation of flow valid.
John R. Hughes, Tuomas Aura, Matt Bishop
S&P2
2000 A causal semantics for time Petri nets
Tuomas Aura, Johan Lilius
Theor. Comput. Sci.1
1998 Fast Access Control Decisions from Delegation Certificate Databases
Tuomas Aura
ACISP1
1998 On the Structure of Delegation Networks
abstract
In new distributed key-oriented access control systems such as SPKI, access rights are delegated by a freely formed network of certificates. The author formalizes the concept of a delegation network and presents a formal semantics for the delegation of access rights with certificates. The certificates can have multiple subjects who must co-operate to use the authority. Some fundamental properties of the system are proven, alternative techniques for authorization decisions are compared and their equivalence is shown rigorously. In particular he proves that certificate reduction is a sound and complete decision technique. He also suggests a new type of threshold certificate and proves its properties.
Tuomas Aura
CSFW1
1997 Strategies against Replay Attacks
abstract
The goal of the paper is to present a set of design principles for avoiding replay attacks in cryptographic protocols. The principles are easily applied to real protocols and they do not consume excessive computing power or communications bandwidth. In particular we describe how to type-tag messages with unique cryptographic functions, how to inexpensively implement the full information principle with hashes, and how to produce unique session keys without assuming mutual trust between the principals. The techniques do not guarantee security of protocols, but they are concrete ways for improving the robustness of the protocol design with relatively low cost.
Tuomas Aura
CSFW1
1997 Stateless connections
Tuomas Aura, Pekka Nikander
ICICS1