EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Mannan
dblp:m/MohammadMannan
· DBLP profile ↗
59ranked-venue papers
9as first author
19since 2021 · last 2026
0000-0002-9630-5858ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 52 · 8 first-author · 16 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bullseye: Detecting Prototype Pollution in NPM Packages with Proof of Concept Exploits
Tariq Houis, Shaoqi Jiang, Mohammad Mannan, Amr M. Youssef |
NDSS | 3 |
| 2026 | Panoptes: Detecting Out-of-Sight Privacy Exposure in AndroidabstractAndroid apps frequently collect and transmit sensitive user information, even when not actively engaged by users. While existing research has extensively explored privacy concerns related to foreground app usage, the risks associated with apps operating out-of-sight, when they are minimized or closed, remain largely unexplored. We design and implement Panoptes, a dynamic analysis tool that detects and attributes data exposure in Android out-of-sight app operations at scale. By systematically triggering and monitoring background works, we conduct the first large-scale measurement of what data apps collect and how they expose sensitive information without user interaction, and attribute the execution of background works to the criteria that trigger them. We evaluated 15,456 popular apps from AndroidRank and found that 13,068/15,456 (84.5%) apps establish network connections while not visible on the device. Of these, 7534/13,068 (57.7%) continue their activity regardless of whether the app is visibly open, closed, or even if it has never been opened. Our findings also uncovered undocumented features that enable apps to collect data even when they are apparently closed. This study sheds light on the hidden privacy risks in Android, and highlights the need for developing more robust techniques to mitigate surreptitious data exfiltration through invisible activities. Sajjad Pourali, Mohammad Mannan |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Poster: Detecting Ransomware Attacks by Analyzing Replicated Block Snapshots Using Neural NetworksabstractCloud antivirus solutions address limitations of host-based malware detection such as extensive resource consumption. However, they remain vulnerable to sophisticated polymorphic and privileged malware. Also, existing solutions are not suitable to defend against destructive ransomware attacks. We propose an enhancement to existing cloud antivirus solutions that enables deep learning-based block snapshot analysis to detect evasive and privileged ransomware in virtualized environment without requiring any hardware support. Preliminary results validate the proposed approach. Seok Min Hong, Beom Heyn Kim, Mohammad Mannan |
CCS | 3 |
| 2024 | TEE-Receipt: A TEE-Based Non-repudiation Framework for Web Applications
Mahmoud Hofny, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
SecureComm (2) | 3 |
| 2024 | Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS Galaxy
Sajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
USENIX Security Symposium | 4 |
| 2024 | Security Weaknesses in IoT Management PlatformsabstractA diverse set of Internet of Things (IoT) devices are becoming an integrated part of daily lives, and playing an increasingly vital role in various industry, enterprise and agricultural settings. The current IoT ecosystem relies on several IoT management platforms to manage and operate a large number of IoT devices, their data, and their connectivity. Considering their key role, these platforms must be properly secured against cyber attacks. In this work, we first explore the core operations/features of leading platforms to design a framework to perform a systematic security evaluation of these platforms. Subsequently, we use our framework to analyze a representative set of 52 IoT management platforms, including 42 web-hosted and ten locally deployable platforms. We discover a number of high-severity unauthorized access vulnerabilities in 9/52 evaluated IoT management platforms, which could be abused to perform attacks, such as remote IoT SIM deactivation, IoT SIM overcharging, and IoT device data forgery. More seriously, we also uncover instances of broken authentication in 13/52 platforms, including complete account takeover on 8/52 platforms along with remote code execution on 2/52 platforms. In effect, 17/52 platforms were affected by vulnerabilities that could lead to platform-wide attacks. Overall, vulnerabilities were uncovered in 33 platforms, out of which 28 platforms responded to our responsible disclosure. We were also assigned 11 common vulnerabilities and exposures and awarded bounty for our findings. Bhaskar Tejaswi, Mohammad Mannan, Amr M. Youssef |
IEEE Internet Things J. | 2 |
| 2024 | On Detecting and Measuring Exploitable JavaScript Functions in Real-world ApplicationsabstractJavaScript is often rated as the most popular programming language for the development of both client-side and server-side applications. Because of its popularity, JavaScript has become a frequent target for attackers who exploit vulnerabilities in the source code to take control over the application. To address these JavaScript security issues, such vulnerabilities must be identified first. Existing studies in vulnerable code detection in JavaScript mostly consider package-level vulnerability tracking and measurements. However, such package-level analysis is largely imprecise, as real-world services that include a vulnerable package may not use the vulnerable functions in the package. Moreover, even the inclusion of a vulnerable function may not lead to a security problem if the function cannot be triggered with exploitable inputs. In this article, we develop a vulnerability detection framework that uses vulnerable pattern recognition and textual similarity methods to detect vulnerable functions in real-world JavaScript projects, combined with a static multi-file taint analysis mechanism to further assess the impact of the vulnerabilities on the whole project (i.e., whether the vulnerability can be exploited in a given project). We compose a comprehensive dataset of 1,360 verified vulnerable JavaScript functions using the Snyk vulnerability database and the VulnCode-DB project. From this ground-truth dataset, we build our vulnerable patterns for two common vulnerability types: prototype pollution and Regular Expression Denial of Service (ReDoS). With our framework, we analyze 9,205,654 functions (from 3,000 NPM packages, 1,892 websites and 557 Chrome Web extensions), and detect 117,601 prototype pollution and 7,333 ReDoS vulnerabilities. By further processing all 5,839 findings from NPM packages with our taint analyzer, we verify the exploitability of 290 zero-day cases across 134 NPM packages. In addition, we conduct an in-depth contextual analysis of the findings in 17 popular/critical projects and study the practical security exposure of 20 functions. With our semi-automated vulnerability reporting functionality, we disclosed all verified findings to project owners. We also obtained 25 published CVEs for our findings, 19 of them rated as “Critical” severity and six rated as “High” severity. Additionally, we obtained 169 CVEs that are currently “Reserved” (as of Apr. 2023). As evident from the results, our approach can shift JavaScript vulnerability detection from the coarse package/library level to the function level and thus improve the accuracy of detection and aid timely patching. Maryna Kluban, Mohammad Mannan, Amr M. Youssef |
ACM Trans. Priv. Secur. | 2 |
| 2023 | All Your IoT Devices Are Belong to Us: Security Weaknesses in IoT Management PlatformsabstractIoT devices have become an integral part of our day to day activities, and are also being deployed to fulfil a number of industrial, enterprise and agricultural use cases. To efficiently manage and operate these devices, the IoT ecosystem relies on several IoT management platforms. Given the security-sensitive nature of the operations performed by these platforms, analyzing them for security vulnerabilities is critical to protect the ecosystem from potential cyber threats. In this work, by exploring the core functionalities offered by leading platforms, we first design a security evaluation framework. Subsequently, we use our framework to analyze 42 IoT management platforms. Our analysis uncovers a number of high severity unauthorized access vulnerabilities in 9/42 platforms, which could lead to attacks such as remote SIM deactivation, IoT SIM overcharging and device data forgery. Furthermore, we find broken authentication in 11/42 platforms, including complete account takeover on 7/42 platforms, along with remote code execution on one of the platforms. Overall, on 11/42 platforms, we find vulnerabilities that could lead to platform-wide attacks, that affect all users and all devices connected to those platforms. Bhaskar Tejaswi, Mohammad Mannan, Amr M. Youssef |
CODASPY | 2 |
| 2023 | Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The WeChat CaseabstractSuper-apps such as WeChat and Baidu host millions of mini-apps, which are very popular among users and developers because of the mini-apps’ convenience, lightweight, ease of sharing, and not requiring explicit installation. Such ecosystems involve several entities, such as the super-app and mini-app clients, the super-app backend server, the mini-app developer server, and other hosting platforms and services used by the mini-app developer. To support various user-level functionalities, these components must authenticate each other, which differs from regular user authentication to the super-app platform. In this paper, we explore the mini-app to super-app authentication problem caused by insecure development practices. This type of authentication allows the mini-app code to access super-app services on the developer’s behalf. Supraja Baskaran, Lianying Zhao, Mohammad Mannan, Amr M. Youssef |
RAID | 3 |
| 2023 | "My Privacy for their Security": Employees' Privacy Perspectives and Expectations when using Enterprise Security Software
Jonah Stegman, Patrick J. Trottier, Caroline Hillier, Hassan Khan 0002, Mohammad Mannan |
USENIX Security Symposium | 5 |
| 2023 | All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsabstractSoftware as a Service (SaaS) e-commerce platforms for merchants allow individual business owners to set up their online stores almost instantly. Prior work has shown that the checkout flows and payment integration of some e-commerce applications are vulnerable to logic bugs with serious financial consequences, e.g., allowing “shopping for free”. Apart from checkout and payment integration, vulnerabilities in other e-commerce operations have remained largely unexplored, even though they can have far more serious consequences, e.g., enabling “store takeover”. In this work, we design and implement a security evaluation framework to uncover security vulnerabilities in e-commerce operations beyond checkout/payment integration. We use this framework to analyze 32 representative e-commerce platforms, including web services of 24 commercial SaaS platforms and 15 associated Android apps, and 8 open source platforms; these platforms host over 10 million stores as approximated through Google dorks. We uncover several new vulnerabilities with serious consequences, e.g., allowing an attacker to take over all stores under a platform, and listing illegal products at a victim’s store—in addition to “shopping for free” bugs, without exploiting the checkout/payment process. We found 12 platforms vulnerable to store takeover (affecting 41000+ stores) and 6 platforms vulnerable to shopping for free (affecting 19000+ stores, approximated via Google dorks on Oct. 8, 2022). We have responsibly disclosed the vulnerabilities to all affected parties, and requested four CVEs (three assigned, and one is pending review). Rohan Pagey, Mohammad Mannan, Amr M. Youssef |
WWW | 2 |
| 2022 | On Measuring Vulnerable JavaScript Functions in the WildabstractJavaScript is often rated as the most popular programming language for the development of both client-side and server-side applications, and is currently used in almost all websites. Because of its popularity, JavaScript has become a frequent target for attackers, who exploit vulnerabilities in the source code to take control over the application. To address these JavaScript security issues, such vulnerabilities must be identified first. Existing work mostly deals with package-level vulnerability tracking and measurements. However this approach is limited to detecting usage of already known vulnerabilities. In this paper we develop a vulnerability detection framework that uses vulnerable pattern recognition and textual similarity methods to detect vulnerable functions in real-world projects. We build our framework with the help of a comprehensive dataset of 1,360 verified vulnerable JavaScript functions that we compose based on Snyk vulnerability database and the VulnCode-DB project. Using our framework, we identify 11,148 vulnerable functions in three environments: NPM packages, Chrome web extensions and popular websites. In addition,we conduct an in-depth contextual analysis of the findings in several popular/critical projects and confirm the security exposure of 15 cases. As evident from the results, our approach can shift JavaScript vulnerability detection from the coarse package/library level to function level, and thus improve accuracy of detection and aid timely patching. Maryna Kluban, Mohammad Mannan, Amr M. Youssef |
AsiaCCS | 2 |
| 2022 | Hidden in Plain Sight: Exploring Encrypted Channels in Android AppsabstractAs privacy features in Android operating system improve, privacy-invasive apps may gradually shift their focus to non-standard and covert channels for leaking private user/device information. Such leaks also remain largely undetected by state-of-the-art privacy analysis tools, which are very effective in uncovering privacy exposures via regular HTTP and HTTPS channels. In this study, we design and implement, ThirdEye, to significantly extend the visibility of current privacy analysis tools, in terms of the exposures that happen across various non-standard and covert channels, i.e., via any protocol over TCP/UDP (beyond HTTP/S), and using multi-layer custom encryption over HTTP/S and non-HTTP protocols. Besides network exposures, we also consider covert channels via storage media that also leverage custom encryption layers. Using ThirdEye, we analyzed 12,598 top-apps in various categories from Androidrank, and found that 2887/12,598 (22.92%) apps used custom encryption/decryption for network transmission and storing content in shared device storage, and 2465/2887 (85.38%) of those apps sent device information (e.g., advertising ID, list of installed apps) over the network that can fingerprint users. Besides, 299 apps transmitted insecure encrypted content over HTTP/non-HTTP protocols; 22 apps that used authentication tokens over HTTPS, happen to expose them over insecure (albeit custom encrypted) HTTP/non-HTTP channels. We found non-standard and covert channels with multiple levels of obfuscation (e.g., encrypted data over HTTPS, encryption at nested levels), and the use of vulnerable keys and cryptographic algorithms. Our findings can provide valuable insights into the evolving field of non-standard and covert channels, and help spur new countermeasures against such privacy leakage and security issues. Sajjad Pourali, Nayanamana Samarasinghe, Mohammad Mannan |
CCS | 3 |
| 2022 | SAUSAGE: Security Analysis of Unix domain Socket usAGE in AndroidabstractThe Android operating system is currently the most popular mobile operating system in the world. Android is based on Linux and therefore inherits its features including its Inter-Process Communication (IPC) mechanisms. These mechanisms are used by processes to communicate with one another and are extensively used in Android. While Android-specific IPC mechanisms have been studied extensively, Unix domain sockets have not been examined comprehensively, despite playing a crucial role in the IPC of highly privileged system daemons. In this paper, we propose Sausage, an efficient novel static analysis framework to study the security properties of these sockets. Sausage considers access control policies implemented in the Android security model, as well as authentication checks implemented by the daemon binaries. It is a fully static analysis framework, specifically designed to analyze Unix domain socket usage in Android system daemons, at scale. We use this framework to analyze 200 Android images across eight popular smartphone vendors spanning Android versions 7–9. As a result, we uncover multiple access control misconfigurations and insecure authentication checks. Our notable findings include a permission bypass in highly privileged Qualcomm system daemons and an unprotected socket that allows an untrusted app to set the scheduling priority of other processes running on the system, despite the implementation of mandatory SELinux policies. Ultimately, the results of our analysis are worrisome; all vendors except the Android Open Source Project (AOSP) have access control issues, allowing an untrusted app to communicate to highly privileged daemons through Unix domain sockets introduced by hardware manufacturer or vendor customization. Mounir Elgharabawy, Blas Kojusner, Mohammad Mannan, Kevin R. B. Butler, Byron Williams, Amr M. Youssef |
EuroS&P | 3 |
| 2022 | Silver Surfers on the Tech Wave: Privacy Analysis of Android Apps for the Elderly
Pranay Kapoor, Rohan Pagey, Mohammad Mannan, Amr M. Youssef |
SecureComm | 3 |
| 2022 | Et tu, Brute? Privacy Analysis of Government Websites and Mobile AppsabstractPast privacy measurement studies on web tracking focused on high-ranked commercial websites, as user tracking is extensively used for monetization on those sites. Conversely, governments across the globe now offer services online, which unlike commercial sites, are funded by public money, and do not generally make it to the top million website lists. As such, web tracking on those services has not been comprehensively studied, even though these services deal with privacy and security-sensitive user data, and used by a significant number of users. In this paper, we perform privacy and security measurements on government websites and Android apps: 150,244 unique websites (from 206 countries) and 1166 Android apps (from 71 countries). We found numerous commercial trackers on these services—e.g., 17% of government websites and 37% of government Android apps host Google trackers; 13% of government sites contain YouTube cookies with an expiry date in the year of 9999. 27% of government Android apps leak sensitive information (e.g., user/device identifiers, passwords, API keys) to third parties, or any network attacker (when sent over HTTP). We also found 304 government sites and 40 apps are flagged by VirusTotal as malicious. We hope our findings to help improve privacy and security of online government services, given that governments are now apparently taking Internet privacy/security seriously and imposing strict regulations on commercial sites. Nayanamana Samarasinghe, Aashish Adhikari, Mohammad Mannan, Amr M. Youssef |
WWW | 3 |
| 2022 | Blindfold: Keeping private keys in PKIs and CDNs out of sight
Hisham S. Galal, Mohammad Mannan, Amr M. Youssef |
Comput. Secur. | 2 |
| 2021 | Horus: A Security Assessment Framework for Android Crypto Wallets
Md Shahab Uddin, Mohammad Mannan, Amr M. Youssef |
SecureComm (2) | 2 |
| 2021 | On cloaking behaviors of malicious websites
Nayanamana Samarasinghe, Mohammad Mannan |
Comput. Secur. | 2 |
| 2020 | Betrayed by the Guardian: Security and Privacy Risks of Parental Control SolutionsabstractFor parents of young children and adolescents, the digital age has introduced many new challenges, including excessive screen time, inappropriate online content, cyber predators, and cyberbullying. To address these challenges, many parents rely on numerous parental control solutions on different platforms, including parental control network devices (e.g., WiFi routers) and software applications on mobile devices and laptops. While these parental control solutions may help digital parenting, they may also introduce serious security and privacy risks to children and parents, due to their elevated privileges and having access to a significant amount of privacy-sensitive data. In this paper, we present an experimental framework for systematically evaluating security and privacy issues in parental control software and hardware solutions. Using the developed framework, we provide the first comprehensive study of parental control tools on multiple platforms including network devices, Windows applications, Chrome extensions and Android apps. Our analysis uncovers pervasive security and privacy issues that can lead to leakage of private information, and/or allow an adversary to fully control the parental control solution, and thereby may directly aid cyberbullying and cyber predators. Suzan Ali, Mounir Elgharabawy, Quentin Duchaussoy, Mohammad Mannan, Amr M. Youssef |
ACSAC | 4 |
| 2020 | Reboot-Oriented IoT: Life Cycle Management in Trusted Execution Environment for Disposable IoT devicesabstractMany IoT devices are geographically distributed without human administrators, which are maintained by a remote server to enforce security updates, ideally through machine-to-machine (M2M) management. However, malware often terminates the remote control mechanism immediately after compromise and hijacks the device completely. The compromised device has no way to recover and becomes part of a botnet. Even if the IoT device remains uncompromised, it is required to update due to recall or other reasons. In addition, the device is desired to be automatically disposable after the expiration of its service, software, or device hardware to prevent being cyber debris. Kuniyasu Suzaki, Akira Tsukamoto, Mohammad Mannan |
ACSAC | 4 |
| 2020 | ByPass: Reconsidering the Usability of Password Managers
Elizabeth Stobert, Tina Safaie, Heather Molyneaux, Mohammad Mannan, Amr M. Youssef |
SecureComm (1) | 4 |
| 2020 | LURK: Server-Controlled TLS DelegationabstractThe following topics are dealt with: security of data; data privacy; learning (artificial intelligence); telecommunication security; Internet; cryptography; mobile computing; computer network security; authorisation; Internet of Things. Ioana Boureanu, Daniel Migault, Stere Preda, Hyame Assem Alameddine, Sanjay Mishra, Frederic Fieau, Mohammad Mannan |
TrustCom | 7 |
| 2020 | Chaperone: Real-time Locking and Loss Prevention for Smartphones
Jiayi Chen 0001, Urs Hengartner, Hassan Khan 0002, Mohammad Mannan |
USENIX Security Symposium | 4 |
| 2019 | AppVeto: mobile application self-defense through resource access vetoabstractModern mobile operating systems such as Android and Apple iOS allow apps to access various system resources, with or without explicit user permission. Running multiple concurrent apps is also commonly supported, although the OS generally maintains strict separation between apps. However, an app can still get access to another app's private information, such as the user input, through numerous side-channels, mostly enabled by having access to permissioned or permission-less (sometimes even unrelated) resources, e.g., inferring keystroke and swipe gestures from a victim app via the accelerometer or gyroscope. Current mobile OSes do not empower an app to defend itself from such implicit interference from other apps; few exceptions exist such as blocking screenshot captures in Android. We propose a general mechanism for apps to defend themselves from any unwanted implicit or explicit interference from other concurrently running apps. Our AppVeto solution enables an app to easily configure its requirements for a safe environment; a foreground app can request the OS to disallow access---i.e., to enable veto powers---to selected side-channel-prone resources to all other running apps for a certain (short) duration, e.g., no access to the accelerometer during password input. In a sense, we enable a finer-grained access control policy than the current runtime permission model, and delegate the responsibility of the resource access decision (for vetoing) from users to app developers. We implement AppVeto on Android using the Xposed framework, without changing Android APIs. Furthermore, we show that AppVeto imposes negligible overhead, while being effective against several well-known side-channel attacks. Tousif Osman, Mohammad Mannan, Urs Hengartner, Amr M. Youssef |
ACSAC | 2 |
| 2019 | DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable FunctionsabstractThe Universal Serial Bus (USB) supports a diverse and wide-ranging set of device types. To enable ease of use, USB devices are automatically detected and classified by common operating systems, without any authentication. This trust-by-default design principle can be easily exploited, and led to numerous attacks in the past (e.g., Stuxnet, BadUSB, BadAndroid), specifically targeting high-value organizations. Administrators' efforts to prevent these attacks may also be threatened by unscrupulous users who may insert any USB device, or malicious users (inside attackers) who may try to circumvent OS/kernel-enforced protection mechanisms (e.g., via OS replacement). The root causes of USB attacks appear to be the lack of robust authentication of individual USB devices and inadequate tamper-proofing of the solution mechanism itself. We propose DeviceVeil to address these limitations. To authenticate individual USB devices, we utilize the tamper-proof feature of Physical Unclonable Functions (PUFs); PUFs extract unique features from physical characteristics of an integrated circuit (IC) at a reasonable cost (less than 1 USD). To make our authentication mechanism robust, we implement it as a small hypervisor, and protect it by a novel combination of security technologies available in commodity PCs, e.g., Trusted Platform Module (TPM), customized secure boot, and virtualization support. The OS disk image with all user data is encrypted by a key sealed in TPM and can be decrypted by the hypervisor only. Customized secure boot allows the loading of the legitimate hypervisor and OS kernel only. The hypervisor enables pre-OS authentication to protect the trust-by-default OS from USB attacks. The chain of trust continues from power-on to the insertion of a USB device and disallows all illegitimate USB devices. DeviceVeil's PUF authentication takes about 1.7 seconds during device insertion. Kuniyasu Suzaki, Yohei Hori, Kazukuni Kobara, Mohammad Mannan |
DSN | 4 |
| 2019 | TEE-aided Write Protection Against Privileged Data Tampering
Lianying Zhao, Mohammad Mannan |
NDSS | 2 |
| 2019 | On the null relationship between personality types and passwordsabstractWe performed a preliminary investigation of the relationship between the Big-five personality traits and the strength of selected and created online security passwords. Five-hundred and ten participants were recruited through MTurk and asked a) to complete a Big-five personality inventory, b) to select from a list of available passwords the one they felt was most secure, and c) to create unique, secure passwords for their own online protection. The security strength of participants' selected/created passwords was rated via Zxcvbn, and evaluated on a variety of additional security-based criteria (e.g., password length, inclusion of special characters). In all cases results failed to identify significant relationship between the strength of the selected/chosen password and any Big-five personality traits (when employing appropriately stringent control for multiple corrections). These null results suggest that other factors beyond an individual's personality may hold greater influence over the strength of selected/created online passwords. We present detailed observations and findings from our experiment, discuss potential considerations for contradictions, and suggest possibilities for future research into the password/personality relationship, including the potential use of enhanced password strength meters and tailored security nudges. Amit Maraj, Miguel Vargas Martin, Matthew Shane, Mohammad Mannan |
PST | 4 |
| 2019 | Another look at TLS ecosystems in networked devices vs. Web servers
Nayanamana Samarasinghe, Mohammad Mannan |
Comput. Secur. | 2 |
| 2019 | Towards a global perspective on web tracking
Nayanamana Samarasinghe, Mohammad Mannan |
Comput. Secur. | 2 |
| 2019 | Playing With Danger: A Taxonomy and Evaluation of Threats to Smart ToysabstractSmart toys have captured an increasing share of the toy market, and are growing ubiquitous in households with children. Smart toys are a subset of Internet of Things (IoT) devices, containing sensors, actuators, and/or artificial intelligence capabilities. They frequently have Internet connectivity, directly or indirectly through companion apps, and collect information about their users and environments. Recent studies have found security flaws in many smart toys that have led to serious privacy leaks, or allowed tracking a child's physical location. Some well-publicized discoveries of this nature have prompted actions from governments around the world to ban some of these toys. Compared to other IoT devices, smart toys pose unique risks because of their easily vulnerable user base, and this paper is intended to define these risks and assess a subset of toys against them. We provide a classification of threats specific to smart toys in order to unite and complement existing adhoc analyses, and help comprehensive evaluation of other smart toys. Our vulnerability taxonomy addresses the potential security and privacy flaws that can lead to leakage of private information or allow an adversary to control the toy to lure, harm, or distress a child. Using this taxonomy, we perform a thorough experimental analysis of eleven smart toys and their companion apps. Our systematic analysis has uncovered that several current toys still expose children to multiple threats for attackers with physical, nearby, or remote access to the toy. Sharon Shasha, Moustafa Mahmoud, Mohammad Mannan, Amr M. Youssef |
IEEE Internet Things J. | 3 |
| 2018 | Keys in the Clouds: Auditable Multi-device Access to Cryptographic CredentialsabstractPersonal cryptographic keys are the foundation of many secure services, but storing these keys securely is a challenge, especially if they are used from multiple devices. Storing keys in a centralized location, like an Internet-accessible server, raises serious security concerns (e.g. server compromise). Hardware-based Trusted Execution Environments (TEEs) are a well-known solution for protecting sensitive data in untrusted environments, and are now becoming available on commodity server platforms. Arseny Kurnikov, Andrew Paverd, Mohammad Mannan, N. Asokan |
ARES | 3 |
| 2018 | To Intercept or Not to Intercept: Analyzing TLS Interception in Network AppliancesabstractMany enterprise-grade network appliances host a TLS proxy to facilitate interception of TLS-protected traffic for various purposes, including malware scanning, phishing detection, and preventing data exfiltration. When deployed, the TLS proxy acts as the security validating client for external TLS web servers, on behalf of the original requesting client; on the other hand, the proxy acts as the web server to the client. Consequently, TLS proxies must maintain a reliable level of security, at least, at the same level as modern web browsers and properly configured TLS servers. Failure to do so increases the attack surface of all the proxied clients served the network appliance. We develop a framework for testing TLS inspecting appliances, combining and extending tests from existing work on client-end and network-based interception. Utilizing this framework, we analyze six representative network appliances, and uncover several security issues regarding TLS version and certificate parameters mapping, CA trusted stores, private keys, and certificate validation tests. For instance, we found that two appliances perform no certificate validation at all, exposing their end-clients to trivial Man-in-the-Middle attacks. The remaining appliances that perform certificate validation, still do not follow current best practices, and thus making them vulnerable against certain attacks. We also found that all the tested appliances deceive the requesting clients, by offering TLS parameters that are different from the proxy-to-server TLS parameters, such as the TLS versions, hashing algorithms, and RSA key sizes. We hope that this work bring focus on the risks and vulnerabilities of using TLS proxies that are being widely deployed in many enterprise and government environments, potentially affecting all their users and systems. Louis Waked, Mohammad Mannan, Amr M. Youssef |
AsiaCCS | 2 |
| 2018 | On Understanding Permission Usage Contextuality in Android Apps
Md Zakir Hossen, Mohammad Mannan |
DBSec | 2 |
| 2018 | SafeKeeper: Protecting Web Passwords using Trusted Execution EnvironmentsabstractPasswords are by far the most widely-used mechanism for authenticating users on the web, out-performing all competing solutions in terms of deployability (e.g. cost and compatibility). However, two critical security concerns are phishing and theft of password databases. These are exacerbated by users» tendency to reuse passwords across different services. Current solutions typically address only one of the two concerns, and do not protect passwords against rogue servers. Furthermore, they do not provide any verifiable evidence of their (server-side) adoption to users, and they face deployability challenges in terms of ease-of-use for end users, and/or costs for service providers. We present SafeKeeper, a novel and comprehensive solution to ensure secrecy of passwords in web authentication systems. Unlike previous approaches, SafeKeeper protects users» passwords against very strong adversaries, including external phishers as well as corrupted (rogue) servers. It is relatively inexpensive to deploy as it (i) uses widely available hardware-based trusted execution environments like Intel SGX, (ii) requires only minimal changes for integration into popular web platforms like WordPress, and (iii) imposes negligible performance overhead. We discuss several challenges in designing and implementing such a system, and how we overcome them. Via an 86-participant user study, systematic analysis and experiments, we show the usability, security and deployability of SafeKeeper, which is available as open-source. Klaudia Krawiecka, Arseny Kurnikov, Andrew Paverd, Mohammad Mannan, N. Asokan |
WWW | 4 |
| 2016 | Sixth Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM 2016)abstractMobile security and privacy issues are receiving significant attention from the research community. The SPSM workshop was created to provide a venue for researchers and practitioners interested in such issues to get together and exchange ideas. Following the success of the previous editions, we present the sixth edition of the workshop. It brings together the expertise of an international program committee, comprising of 22 mobile security experts from the academia and the industry. The workshop received 31 submissions (regular and short papers combined) from a diverge set of authors located in 19 countries. Long Lu, Mohammad Mannan |
CCS | 2 |
| 2016 | Hypnoguard: Protecting Secrets across Sleep-wake CyclesabstractAttackers can get physical control of a computer in sleep (S3/suspend-to-RAM), if it is lost, stolen, or the owner is being coerced. High-value memory-resident secrets, including disk encryption keys, and private signature/encryption keys for PGP, may be extracted (e.g., via cold-boot or DMA attacks), by physically accessing such a computer. Our goal is to alleviate threats of extracting secrets from a computer in sleep, without relying on an Internet-facing service. We propose Hypnoguard to protect all memory-resident OS/user data across S3 suspensions, by first performing an in-place full memory encryption before entering sleep, and then restoring the plaintext content at wakeup-time through an environment-bound, password-based authentication process. The memory encryption key is effectively "sealed" in a Trusted Platform Module (TPM) chip with the measurement of the execution environment supported by CPU's trusted execution mode (e.g., Intel TXT, AMD-V/SVM). Password guessing within Hypnoguard may cause the memory content to be permanently inaccessible, while guessing without Hypnoguard is equivalent to brute-forcing a high-entropy key (due to TPM protection). We achieved full memory encryption/decryption in less than a second on a mainstream computer (Intel i7-4771 CPU with 8GB RAM, taking advantage of multi-core processing and AES-NI), an apparently acceptable delay for sleep-wake transitions. To the best of our knowledge, Hypnoguard provides the first wakeup-time secure environment for authentication and key unlocking, without requiring per-application changes. Lianying Zhao, Mohammad Mannan |
CCS | 2 |
| 2016 | Killed by Proxy: Analyzing Client-end TLS Interception Software
Xavier de Carné de Carnavalet, Mohammad Mannan |
NDSS | 2 |
| 2016 | An evaluation of recent secure deduplication proposals
Vladimir Rabotka, Mohammad Mannan |
J. Inf. Secur. Appl. | 2 |
| 2016 | Deceptive Deletion Triggers Under CoercionabstractFor users in possession of password-protected encrypted data in persistent storage (i.e., “data at rest”), an obvious problem is that the password may be extracted by an adversary through dictionary attacks, or by coercing the user. Traditional full disk encryption (FDE) or plausibly deniable encryption cannot adequately address such situations. Therefore, making data verifiably inaccessible in a stealthy and quick fashion may be the preferred choice, specifically for users, such as government/corporate agents, journalists, and human rights activists with highly confidential secrets, when caught and interrogated in a hostile territory. Using secure storage on a trusted platform module (TPM) and modern CPU's trusted execution mode (e.g., Intel TXT), we design Gracewipe to enable secure and verifiable deletion of encryption keys through a special deletion password. When coerced, a user can fake compliance and enter the deletion password; and then, the user can prove to the adversary that Gracewipe has been executed and the real key is no longer available (through a TPM quote), hoping for a favorable situation (e.g., end of torture). To unlock the target encryption key, the adversary can only guess passwords through the valid Gracewipe environment with a high-risk of triggering deletion of the real key. Based on our two primary Gracewipe prototypes (i.e., software-based FDE with TrueCrypt and hardware-based FDE with self-encrypting drive), we also design and implement an extended family of unlocking schemes for triggering deletion, to achieve better plausibility, security and usability. We incur between 2-2.5 seconds delay during boot, and no performance penalty at run-time. Lianying Zhao, Mohammad Mannan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Gracewipe: Secure and Verifiable Deletion under Coercion
Lianying Zhao, Mohammad Mannan |
NDSS | 2 |
| 2015 | Peace vs. Privacy: Leveraging Conflicting Jurisdictions for Email SecurityabstractWe introduce the paradigm of security through hostility: cloud-based service providers in conflicting jurisdictions are assumed to be non-cooperating, and are used for transmitting encrypted content and corresponding keys through separate but accessible channels among end-users from both jurisdictions. Such separation between content and key can enable effortless user-to-user encrypted communication without any user-managed keys. As an example use-case of this paradigm, we consider encrypted email, which is complicated by the requirement of balancing security and ease-of-use needs. For example, users cannot be expected to manage long-term keys (e.g., PGP key-pair), or understand crypto primitives. We design CherAmi by leveraging existing relationships between a sender and a receiver on an online social networking (OSN) site, and assuming users can use OSN and email providers that are hosted from hostile/non-cooperating jurisdictions. CherAmi can provide integrity, authentication and confidentiality guarantees for selected messages among OSN friends. A confidentiality-protected email is encrypted by a randomly-generated key, and the key is privately shared with the receiver via the OSN site. Our implementation consists of a Thunderbird add-on and a Twitter app; the add-on is available at: https://madiba.encs.concordia.ca/software.html. CherAmi is a client-end solution and does not require changes to email or OSN servers. In this paper, the focus of our discussion includes: the paradigm of security through hostility, and the design, implementation and security analysis of the proposed encrypted email solution. We acknowledge that a user study will be required to validate usability-related features of CherAmi. Mohammad Mannan, Arash Shahkar, Atieh Saberi Pirouz, Vladimir Rabotka |
NSPW | 1 |
| 2015 | A Large-Scale Evaluation of High-Impact Password Strength MetersabstractPasswords are ubiquitous in our daily digital lives. They protect various types of assets ranging from a simple account on an online newspaper website to our health information on government websites. However, due to the inherent value they protect, attackers have developed insights into cracking/guessing passwords both offline and online. In many cases, users are forced to choose stronger passwords to comply with password policies; such policies are known to alienate users and do not significantly improve password quality. Another solution is to put in place proactive password-strength meters/checkers to give feedback to users while they create new passwords. Millions of users are now exposed to these meters on highly popular web services that use user-chosen passwords for authentication. More recently, these meters are also being built into popular password managers, which protect several user secrets including passwords. Recent studies have found evidence that some meters actually guide users to choose better passwords—which is a rare bit of good news in password research. However, these meters are mostly based on ad hoc design. At least, as we found, most vendors do not provide any explanation for their design choices, sometimes making them appear as a black box. We analyze password meters deployed in selected popular websites and password managers. We document obfuscated source-available meters, infer the algorithm behind the closed-source ones, and measure the strength labels assigned to common passwords from several password dictionaries. From this empirical analysis with millions of passwords, we shed light on how the server end of some web service meters functions and provide examples of highly inconsistent strength outcomes for the same password in different meters, along with examples of many weak passwords being labeled as strong or even excellent . These weaknesses and inconsistencies may confuse users in choosing a stronger password, and thus may weaken the purpose of these meters. On the other hand, we believe these findings may help improve existing meters and possibly make them an effective tool in the long run. Xavier de Carné de Carnavalet, Mohammad Mannan |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2014 | Challenges and implications of verifiable builds for security-critical open-source softwareabstractThe majority of computer users download compiled software and run it directly on their machine. Apparently, this is also true for open-sourced software -- most users would not compile the available source, and implicitly trust that the available binaries have been compiled from the published source code (i.e., no backdoor has been inserted in the binary). To verify that the official binaries indeed correspond to the released source, one can compile the source of a given application, and then compare the locally generated binaries with the developer-provided official ones. However, such simple verification is non-trivial to achieve in practice, as modern compilers, and more generally, toolchains used in software packaging, have not been designed with verifiability in mind. Rather, the output of compilers is often dependent on parameters that can be strongly tied to the building environment. In this paper, we analyze a widely-used encryption tool, TrueCrypt, to verify its official binary with the corresponding source. We first manually replicate a close match to the official binaries of sixteen most recent versions of TrueCrypt for Windows up to v7.1a, and then explain the remaining differences that can solely be attributed to non-determinism in the build process. Our analysis provides the missing guarantee on official binaries that they are indeed backdoor-free, and makes audits on TrueCrypt's source code more meaningful. Also, we uncover several sources of non-determinism in TrueCrypt's compilation process; these findings may help create future verifiable build processes. Xavier de Carné de Carnavalet, Mohammad Mannan |
ACSAC | 2 |
| 2014 | Detection of malicious payload distribution channels in DNSabstractBotmasters are known to use different protocols to hide their activities. Throughout the past few years, several protocols have been abused, and recently Domain Name System (DNS) also became a target of such malicious activities. In this paper, we study the use of DNS as a malicious payload distribution channel. We present a system to analyze the resource record activities of domain names and build DNS zone profiles to detect payload distribution channels. Our work is based on an extensive analysis of malware datasets for one year, and a near real-time feed of passive DNS traffic. The experimental results reveal a few previously unreported long-running hidden domains used by the Morto worm for distributing malicious payloads. Our experiments on passive DNS traffic indicate that our system can detect these channels regardless of the payload format. A. Mert Kara, Hamad Binsalleeh, Mohammad Mannan, Amr M. Youssef, Mourad Debbabi |
ICC | 3 |
| 2014 | From Very Weak to Very Strong: Analyzing Password-Strength Meters
Xavier de Carné de Carnavalet, Mohammad Mannan |
NDSS | 2 |
| 2014 | Mobiflage: Deniable Storage Encryptionfor Mobile DevicesabstractData confidentiality can be effectively preserved through encryption. In certain situations, this is inadequate, as users may be coerced into disclosing their decryption keys. Steganographic techniques and deniable encryption algorithms have been devised to hide the very existence of encrypted data. We examine the feasibility and efficacy of deniable encryption for mobile devices. To address obstacles that can compromise plausibly deniable encryption (PDE) in a mobile environment, we design a system called Mobiflage. Mobiflage enables PDE on mobile devices by hiding encrypted volumes within random data in a devices free storage space. We leverage lessons learned from deniable encryption in the desktop environment, and design new countermeasures for threats specific to mobile systems. We provide two implementations for the Android OS, to assess the feasibility and performance of Mobiflage on different hardware profiles. MF-SD is designed for use on devices with FAT32 removable SD cards. Our MF-MTP variant supports devices that instead share a single internal partition for both apps and user accessible data. MF-MTP leverages certain Ext4 file system mechanisms and uses an adjusted data-block allocator. These new techniques for soring hidden volumes in Ext4 file systems can also be applied to other file systems to enable deniable encryption for desktop OSes and other mobile platforms. Adam Skillen, Mohammad Mannan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | On Implementing Deniable Storage Encryption for Mobile Devices
Adam Skillen, Mohammad Mannan |
NDSS | 2 |
| 2013 | Explicit authentication response considered harmfulabstractAutomated online password guessing attacks are facilitated by the fact that most user authentication techniques provide a yes/no answer as the result of an authentication attempt. These attacks are somewhat restricted by Automated Turing Tests (ATTs, e.g., captcha challenges) that attempt to mandate human assistance. ATTs are not very difficult for legitimate users, but always pose an inconvenience. Several current ATT implementations are also found to be vulnerable to improved image processing algorithms. ATTs can be made more complex for automated software, but that is limited by the trade-off between user-friendliness and effectiveness of ATTs. As attackers gain control of large-scale botnets, relay the challenge to legitimate users at compromised websites, or even have ready access to cheap, sweat-shop human solvers for defeating ATTs, online guessing attacks are becoming a greater security risk. Using deception techniques (as in honeypots), we propose the user-verifiable authentication scheme (Uvauth) that tolerates, instead of detecting or counteracting, guessing attacks. Uvauth provides access to all authentication attempts; the correct password enables access to a legitimate session with valid user data, and all incorrect passwords lead to fake sessions. Legitimate users are expected to learn the authentication outcome implicitly from the presented user data, and are relieved from answering ATTs; the authentication result never leaves the server and thus remains (directly) inaccessible to attackers. In addition, we suggest using adapted distorted images and pre-registered images/text as a complement to convey an authentication response, especially for accounts that do not host much personal data. Lianying Zhao, Mohammad Mannan |
NSPW | 2 |
| 2012 | Revisiting Defenses against Large-Scale Online Password Guessing AttacksabstractBrute force and dictionary attacks on password-only remote login services are now widespread and ever increasing. Enabling convenient login for legitimate users while preventing such attacks is a difficult problem. Automated Turing Tests (ATTs) continue to be an effective, easy-to-deploy approach to identify automated malicious login attempts with reasonable cost of inconvenience to users. In this paper, we discuss the inadequacy of existing and proposed login protocols designed to address large-scale online dictionary attacks (e.g., from a botnet of hundreds of thousands of nodes). We propose a new Password Guessing Resistant Protocol (PGRP), derived upon revisiting prior proposals designed to restrict such attacks. While PGRP limits the total number of login attempts from unknown remote hosts to as low as a single attempt per username, legitimate users in most cases (e.g., when attempts are made from known, frequently-used machines) can make several failed login attempts before being challenged with an ATT. We analyze the performance of PGRP with two real-world data sets and find it more promising than existing proposals. Mansour Alsaleh, Mohammad Mannan, Paul C. van Oorschot |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | Unicorn: two-factor attestation for data securityabstractMalware and phishing are two major threats for users seeking to perform security-sensitive tasks using computers today. To mitigate these threats, we introduce Unicorn, which combines the phishing protection of standard security tokens and malware protection of trusted computing hardware. The Unicorn security token holds user authentication credentials, but only releases them if it can verify an attestation that the user's computer is free of malware. In this way, the user is released from having to remember passwords, as well as having to decide when it is safe to use them. The user's computer is further verified by either a TPM or a remote server to produce a two-factor attestation scheme. We have implemented a Unicorn prototype using commodity software and hardware, and two Unicorn example applications (termed as uApps, short for Unicorn Applications), to secure access to both remote data services and encrypted local data. Each uApp consists of a small, hardened and immutable OS image, and a single application. Our Unicorn prototype co-exists with a regular user OS, and significantly reduces the time to switch between the secure environment and general purpose environment using a novel mechanism that removes the BIOS from the switch time. Mohammad Mannan, Beom Heyn Kim, Afshar Ganjali, David Lie |
CCS | 1 |
| 2011 | Leveraging personal devices for stronger password authentication from untrusted computersabstractInternet authentication for popular end-user transactions, such as online banking and e-commerce, continues to be dominated by passwords entered through end-user PCs. Most users continue to prefer (typically untrusted) PCs over smaller personal devices for actual transactions, due to usability features related to keyboard and screen size. However, most such transactions and their underlying protocols are vulnerable to attacks including keylogging, phishing and pharming. We propose Mobile Password Authentication (MP-Auth) to counter such attacks, which cryptographically separates a user's long-term secret input from the client PC, and offers transaction integrity. The PC continues to be used for most of the interaction but has access only to temporary secrets, while the user's long-term secret is input through an independent personal device, e.g., a cellphone which makes it available to the PC only after encryption under the intended far-end recipient's public key. MP-Auth expects users to input passwords only to a personal device, and be vigilant while confirming transactions from the device. To facilitate a comparison to MP-Auth, we also provide a comprehensive survey of web authentication techniques that use an additional factor of authentication; this survey may be of independent interest. Mohammad Mannan, Paul C. van Oorschot |
J. Comput. Secur. | 1 |
| 2011 | User Study, Analysis, and Usable Security of Passwords Based on Digital ObjectsabstractDespite all efforts, password schemes intended to deploy or encourage the use of strong passwords have largely failed. As an alternative to enable users to create, maintain, and use high-quality passwords willingly, we propose Object-based Password (ObPwd), leveraging the universe of personal or personally meaningful digital content that many users now own or have access to. ObPwd converts user-selected digital objects to high-entropy text passwords. Memorization of exact passwords is replaced by remembering password objects. We present the design details, variants, and usability and security analysis of ObPwd, and report on the results of a hybrid in-lab/at-home user study on 32 participants. The results suggest the scheme has good usability, with excellent memorability, acceptable login times, and very positive user perception, achieved while providing strong security for the threat context explored. We believe this work lays the foundation for a promising password selection paradigm. Robert Biddle, Mohammad Mannan, Paul C. van Oorschot, Tara Whalen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2009 | Reducing threats from flawed security APIs: The banking PIN case
Mohammad Mannan, Paul C. van Oorschot |
Comput. Secur. | 1 |
| 2008 | Localization of credential information to address increasingly inevitable data breachesabstractLarge-scale data breaches exposing sensitive personal information are becoming commonplace. For numerous reasons, conventional personal (identification) information leaks from databases that store online and/or on-site user transaction data. Collected ID numbers and supporting personal information enable malicious parties to commit large-scale identity fraud. Gates and Slonim (NSPW 2003) proposed the owner-controlled information paradigm to address privacy violations of personal information where users are expected to maintain all their information using a personal device. Rubin and Wright (FC 2001), Molloy et al. (FC 2007), and others explored the use of one-time numbers to address credit card fraud (mostly for online use). However, several other types of ID number are at least as sensitive as credit card numbers. Our fundamental assumption is that collected personal information will eventually be breached. To combat identity fraud under this new environmental attack paradigm, we introduce a more general approach involving localized or customized ID numbers for both card-present and card-not-present transactions. We also explore four variants of the general idea to spark more discussion and further research in this area. Mohammad Mannan, Paul C. van Oorschot |
NSPW | 1 |
| 2008 | Digital Objects as Passwords
Mohammad Mannan, Paul C. van Oorschot |
HotSec | 1 |
| 2008 | Privacy-enhanced sharing of personal content on the webabstractPublishing personal content on the web is gaining increased popularity with dramatic growth in social networking websites, and availability of cheap personal domain names and hosting services. Although the Internet enables easy publishing of any content intended to be generally accessible, restricting personal content to a selected group of contacts is more difficult. Social networking websites partially enable users to restrict access to a selected group of users of the same network by explicitly creating a "friends' list." While this limited restriction supports users' privacy on those (few) selected websites, personal websites must still largely be protected manually by sharing passwords or obscure links. Our focus is the general problem of privacy-enabled web content sharing from any user-chosen web server. By leveraging the existing "circle of trust" in popular Instant Messaging (IM) networks, we propose a scheme called IM-based Privacy-Enhanced Content Sharing (IMPECS) for personal web content sharing. IMPECS enables a publishing user's personal data to be accessible only to her IM contacts. A user can put her personal web page on any web server she wants (vs. being restricted to a specific social networking website), and maintain privacy of her content without requiring site-specific passwords. Our prototype of IMPECS required only minor modifications to an IM server, and PHP scripts on a web server. The general idea behind IMPECS extends beyond IM and IM circles of trust; any equivalent scheme, (ideally) containing pre-arranged groups, could similarly be leveraged. Mohammad Mannan, Paul C. van Oorschot |
WWW | 1 |
| 2007 | Security and usability: the gap in real-world online bankingabstractOnline banking is one of the most sensitive tasks performed by general Internet users. Most traditional banks now offer online banking services, and strongly encourage customers to do online banking with 'peace of mind.' Although banks heavily advertise an apparent '100% online security guarantee,' typically the fine print makes this conditional on users fulfilling certain security requirements. We examine some of these requirements as set by major Canadian banks, in terms of security and usability. We opened personal checking accounts at the five largest Canadian banks, and one online-only bank. We found that many security requirements are too difficult for regular users to follow, and believe that some marketing-related messages about safety and security actually mislead users. We are also interested in what kind of computer systems people really use for online banking, and whether users satisfy common online banking requirements. Our survey of 123 technically advanced users from a university environment strongly supports our view of an emerging gap between banks' expectations (or at least what their written customer policy agreements imply) and users' actions related to security requirements of online banking. Our participants, being more security-aware than the general population, arguably makes our results best-case regarding what can be expected from regular users. Yet most participants failed to satisfy common security requirements, implying most online banking customers do not (or cannot) follow banks' stated end-user security requirements and guidelines. The survey also sheds light on the security settings of systems used for sensitive online transactions. This work is intended to spur a discussion on real-world system security and user responsibilities, in a scenario where everyday users are heavily encouraged to perform critical tasks over the Internet, despite the continuing absence of appropriate tools to do so. Mohammad Mannan, Paul C. van Oorschot |
NSPW | 1 |
| 2004 | Secure Public Instant Messaging
Mohammad Mannan, Paul C. van Oorschot |
PST | 1 |