EDBT 2026 Demo / reviewers in the wild / expert
Eugene H. Spafford
dblp:s/EugeneHSpafford · also Gene Spafford
· DBLP profile ↗
72ranked-venue papers
27as first author
2since 2021 · last 2026
0000-0002-5555-8330ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 50 · 21 first-author · 1 since 2021Software engineering, systems software and programming languages · 9 · 3 first-authorComputer networks · 5 · 1 first-authorSystems, architecture and hardware · 4Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Systems and software security · 57% Network security · 28% Digital forensics and information hiding · 6% | |
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 67% Debugging and program repair · 15% Software testing · 15% |
Topics — the 17 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
operating system security |
0.1 | 1 | 2008 | Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving Approach · IEEE Trans. Parallel Distributed Syst. 2008 |
Systems and software security
provenance tracking |
0.1 | 1 | 2008 | Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving Approach · IEEE Trans. Parallel Distributed Syst. 2008 |
Network security › intrusion detection and prevention › intrusion detection › intrusion detection system
host-based intrusion detection |
0.1 | 1 | 2005 | Efficient Intrusion Detection using Automaton Inlining · S&P 2005 |
Program analysis
static analysis |
0.1 | 1 | 2005 | Efficient Intrusion Detection using Automaton Inlining · S&P 2005 |
Digital forensics and information hiding
digital forensics |
0.0 | 1 | 2008 | Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving Approach · IEEE Trans. Parallel Distributed Syst. 2008 |
Network security › attack strategy
denial-of-service attack |
0.0 | 1 | 1997 | Analysis of a Denial of Service Attack on TCP · S&P 1997 |
Authentication and access control › authentication › authentication protocols
kerberos |
0.0 | 1 | 1997 | Misplaced Trust: Kerberos 4 Session Keys · NDSS 1997 |
Cryptographic protocols and secure computation › key exchange
session-key generation |
0.0 | 1 | 1997 | Misplaced Trust: Kerberos 4 Session Keys · NDSS 1997 |
Network security › attack strategy › denial-of-service attack
SYN flood |
0.0 | 1 | 1997 | Analysis of a Denial of Service Attack on TCP · S&P 1997 |
Network security › intrusion detection and prevention › intrusion detection
anomaly detection |
0.0 | 1 | 2005 | Efficient Intrusion Detection using Automaton Inlining · S&P 2005 |
Network security › intrusion detection and prevention
intrusion detection |
0.0 | 1 | 2005 | Efficient Intrusion Detection using Automaton Inlining · S&P 2005 |
Program analysis › dynamic analysis
dynamic slicing |
0.0 | 1 | 1996 | Critical Slicing for Software Fault Localization · ISSTA 1996 |
Debugging and program repair
fault localization |
0.0 | 1 | 1996 | Critical Slicing for Software Fault Localization · ISSTA 1996 |
Software testing
mutation testing |
0.0 | 1 | 1996 | Critical Slicing for Software Fault Localization · ISSTA 1996 |
Transport protocols and congestion control › TCP
TCP connection establishment |
0.0 | 1 | 1997 | Analysis of a Denial of Service Attack on TCP · S&P 1997 |
Cryptographic primitives and cryptanalysis
random number generation |
0.0 | 1 | 1997 | Misplaced Trust: Kerberos 4 Session Keys · NDSS 1997 |
Operating systems › resource management › storage management › file systems
file system monitoring |
0.0 | 1 | 1994 | The Design and Implementation of Tripwire: A File System Integrity Checker · CCS 1994 |
Methods — techniques the papers use, named apart from their topics
static analysis · 0.1automaton inlining · 0.1virtualization · 0.1process coloring · 0.1prototype implementation · 0.0performance evaluation · 0.0cryptographic hashing · 0.0mutation-based testing · 0.0dynamic program slicing · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A bibliometric retrospective of Computers & SecurityabstractEstablished in 1982, Computers & Security (COSE) was the first journal dedicated to the technical and organizational dimensions of information security. This study examines COSE’s development from 1982 to 2024 through a bibliometric retrospective based on 4,405 Scopus-indexed documents, complemented by selected Web of Science analyses. Following the SPAR-4-SLR protocol, we combine publication and citation indicators with co-citation, bibliographic coupling, and keyword co-occurrence analyses using VOSviewer and bibliometrix . The results show four phases of publication growth, with the strongest expansion after 2016. Citation patterns indicate a sustained influence in network security, intrusion detection, privacy, malware analysis, and behavioral information security, while recent clusters point to growing attention to adversarial machine learning, blockchain, and cyber-physical systems. Author, institutional, and country-level patterns also suggest a broadening contributor base, with increased participation from Asian research systems in the most recent period. The network and keyword analyses show that COSE has retained links to its foundational security themes while incorporating newer socio-technical and AI-related topics. By mapping publication performance, intellectual structure, and topical change, the study provides a longitudinal account of COSE’s role in cybersecurity research and offers evidence that may support future editorial planning, author positioning, and research-policy discussions. Mohammad Sadegh Khorshidi, José M. Merigó, Ghassan Beydoun, Willy Susilo, Eugene H. Spafford |
Comput. Secur. | 5 |
| 2021 | Creating a Concept Map for ICS Security - A Delphi StudyabstractThis Research Full Paper presents the results of a Delphi study. Industrial Control Systems (ICS) is a term used to describe highly integrated and mutually dependent systems made up of a complex network of hundreds of thousands of interconnected control systems. These systems usually incorporate different mass production and distribution elements to accomplish an industrial purpose. These highly integrated and mutually dependent systems have been deployed to manage, monitor, and control industrial infrastructure to provide essential services, such as electricity, energy, chemical, food and beverage, water, gas, oil, and traffic control systems. As these internet-connected systems and technologies continue to grow globally, the risks and threats of ICS cyberattacks' are rapidly increasing. If left susceptible to cyberattacks, any significant stoppage or interruption can cause real-world damages, considerable loss, and undesirable events. ICS security, the process of keeping these systems secure, is becoming a challenging priority for industrial organizations. A recent study conducted by the Center for Strategic International Studies (CSIS) showed that across eight countries of I.T. decisionmakers, 82 % of employers reported a cybersecurity skills shortage, and 71 % believe this talent gap poses direct and observable harm to their organization. A report by (ISC)2 found that there is a vast ICS cybersecurity workforce gap, and the cybersecurity workforce needs to grow 89% to meet industry needs in the United States and 145% to close the skills gap worldwide. The major factor driving the market is the increasing number of complex cyber-attacks on ICS systems, requiring a high demand for trained and skilled professionals in the ICS cybersecurity field. In 2016, a CSIS survey of IT employers found that only 23 % believed education curriculums were fully training students to join the cybersecurity industry. Likewise, in 2018, ISACA found that 61 % of institutes believe that fewer than half of those filling cybersecurity positions were qualified for the job. The current education curriculum lacks essential cybersecurity programs and degrees. It does not provide a strong foundation for building the role-specific knowledge necessary to meet the needs of the cybersecurity workforce. This deficiency needs to be urgently addressed through the creation of multiple, flexible programs in industrial control systems security. One of the first steps in this development is to identify the most critical knowledge, skills, and abilities necessary to become proficient in ICS security. This paper reports on a Delphi study designed to identify these foundational concepts and create a concept map based on the findings. This study used the Delphi method to develop the concept map. A selection of 25 experts in ICS security from academia, industry, and government were contacted and asked to outline a list of core knowledge areas. The researchers developed a summary of the experts' opinions. Two more rounds of input and feedback were solicited from the panel of experts. This paper describes the process and the resulting concept map describing the landscape of ICS cybersecurity. Ida Ngambeki, Eugene H. Spafford, Subia Ansari, Isslam Alhasan, Marlo Basil-Camino, Douglas Rapp |
FIE | 2 |
| 2019 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2018 | A Hypergame Analysis for ErsatzPasswords
Christopher N. Gutierrez, Mohammed H. Almeshekah, Saurabh Bagchi, Eugene H. Spafford |
SEC | 4 |
| 2018 | Reactive redundancy for data destruction protection (R2D2)
Christopher N. Gutierrez, Eugene H. Spafford, Saurabh Bagchi, Thomas Yurek |
Comput. Secur. | 2 |
| 2017 | Ghost Patches: Fake Patches for Fake Vulnerabilities
Jeffrey Avery, Eugene H. Spafford |
SEC | 2 |
| 2016 | Inhibiting and Detecting Offline Password Cracking Using ErsatzPasswords
Christopher N. Gutierrez, Mohammed H. Almeshekah, Eugene H. Spafford, Mikhail J. Atallah, Jeffrey Avery |
ACM Trans. Priv. Secur. | 3 |
| 2015 | ErsatzPasswords: Ending Password Cracking and Detecting Password LeakageabstractIn this work we present a simple, yet effective and practical, scheme to improve the security of stored password hashes, rendering their cracking detectable and insuperable at the same time. We utilize a machine-dependent function, such as a physically unclonable function (PUF) or a hardware security module (HSM) at the authentication server to prevent off-site password discovery, and a deception mechanism to alert us if such an action is attempted. Our scheme can be easily integrated with legacy systems without the need of any additional servers, changing the structure of the hashed password file or any client modifications. When using the scheme the structure of the hashed passwords file, etc/shadow or etc/master.passwd, will appear no different than in the traditional scheme.1 However, when an attacker exfiltrates the hashed passwords file and tries to crack it, the only passwords he will get are the ersatzpasswords --- the "fake passwords". When an attempt to login using these ersatzpasswords is detected an alarm will be triggered in the system. Even with an adversary who knows about the scheme, cracking cannot be launched without physical access to the authentication server. The scheme also includes a secure backup mechanism in the event of a failure of the hardware dependent function. We discuss our implementation and provide some discussion in comparison to the traditional authentication scheme. Mohammed H. Almeshekah, Christopher N. Gutierrez, Mikhail J. Atallah, Eugene H. Spafford |
ACSAC | 4 |
| 2015 | Enhancing Passwords Security Using Deceptive Covert Communication
Mohammed H. Almeshekah, Mikhail J. Atallah, Eugene H. Spafford |
SEC | 3 |
| 2014 | Planning and Integrating Deception into Computer Security DefensesabstractDeceptive techniques played a prominent role in many human conflicts throughout history. Digital conflicts are no different as the use of deception has found its way to computing since at least the 1980s. However, many computer defenses that use deception were ad-hoc attempts to incorporate deceptive elements. In this paper, we present a model that can be used to plan and integrate deception in computer security defenses. We present an overview of fundamental reasons why deception works and the essential principles involved in using such techniques. We investigate the unique advantages deception-based mechanisms bring to traditional computer security defenses. Furthermore, we show how our model can be used to incorporate deception in many part of computer systems and discuss how we can use such techniques effectively. A successful deception should present plausible alternative(s) to the truth and these should be designed to exploit specific adversaries' biases. We investigate these biases and discuss how can they be used by presenting a number of examples. Mohammed H. Almeshekah, Eugene H. Spafford |
NSPW | 2 |
| 2014 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2013 | Improved kernel security through memory layout randomizationabstractThe vast majority of hosts on the Internet, including mobile clients, are running on one of three major operating system families. Malicious operating system kernel software, such as the code introduced by a kernel rootkit, is strongly dependent on the organization of the victim operating system. Due to the lack of diversity of operating systems, attackers can craft a single kernel exploit that has the potential to infect millions of hosts. If the underlying structure of vulnerable operating system components has been changed, in an unpredictable manner, then attackers must create many unique variations of their exploit to attack vulnerable systems en masse. If enough variants of the vulnerable software exist, then mass exploitation is much more difficult to achieve. Many forms of automatic software diversification have been explored and found to be useful for preventing malware infection. Forrest et. al. make a strong case for software diversity and describe a few possible techniques including: adding or removing nonfunctional code, reordering code, and reordering memory layouts. Our techniques build on the latter. We describe two different ways to mutate an operating system kernel using memory layout randomization to resist kernel-based attacks. We introduce a new method for randomizing the stack layout of function arguments. Additionally, we refine a previous technique for record layout randomization by introducing a static analysis technique for determining the randomizability of a record. We developed prototypes of our techniques using the plugin architecture offered by GCC. To test the security benefits our techniques, we randomized multiple Linux kernels using our compiler plugins. We attacked the randomized kernels using multiple kernel rootkits. We show that by strategically selecting just a few components for randomization, our techniques prevent kernel rootkit infection. Dannie M. Stanley, Dongyan Xu, Eugene H. Spafford |
IPCCC | 3 |
| 2013 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2012 | Reverse-safe authentication protocol for secure USB memoriesabstractABSTRACT USB memory devices are both portable and easily accessible, and have thus become one of the most popular forms of external storage device. However, if a USB device is lost, stolen, or hacked, it may lead to leakage of critical information. It is a logical outcome that malicious individuals will try to steal their colleagues' USB memories. Consequently, various USB products with built‐in security functions have been developed. To our knowledge, there has been little or no security analysis and comparison of these devices. This paper explores technological and architectural approaches to secure USB memories while analyzing their vulnerabilities, especially for resistance to reverse engineering attacks on the authentication protocols and data decryption. In this analysis, we classify vulnerabilities of these devices into 12 categories to summarize the current security situations on USB memories. Additionally, we derive a more secure authentication protocol based on our analysis. It is expected for secure USB products, including USB memory devices, to be revised with enhanced authentication protocols as a result of this effort. Copyright © 2012 John Wiley & Sons, Ltd. Kyungroul Lee, Kangbin Yim, Eugene H. Spafford |
Secur. Commun. Networks | 3 |
| 2011 | Implicit Buffer Overflow Protection Using Memory SegregationabstractComputing systems continue to be plagued by malicious corruption of instructions and data. Buffer overflows, in particular, are often employed to disrupt the control flow of vulnerable processes. Existing methods of protection against these attacks operate by detecting corruption after it has taken place or by ensuring that if corruption has taken place, it cannot be used to hijack a process' control flow. These methods thus still allow the corruption of control data to occur but, rather than being subverted, the process may terminate or take some other defined error. Few methods have attempted to prevent the corruption of control data, and those that have only focused on preventing the corruption of the return address. We propose the use of multiple memory segments to support multiple stacks, heaps, bss, and data sections per process with the goal of segregating control and non-control data. By segregating these different forms of data, we can prevent the corruption of control data by overflow and address manipulation of memory allocated for non-control data. We show that the creation of these additional data segments per process can be implemented through modifications to the compiler. Brent G. Roth, Eugene H. Spafford |
ARES | 2 |
| 2011 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2011 | Security, technology, publishing, and ethics (part II)
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2011 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2011 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2011 | Editorial for 30/8
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2010 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2010 | Editorial
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2010 | Security, technology, publishing, and ethics (Part I)
Eugene H. Spafford |
Comput. Secur. | 1 |
| 2010 | Audlib: a configurable, high-fidelity application audit mechanism
Benjamin A. Kuperman, Eugene H. Spafford |
Softw. Pract. Exp. | 2 |
| 2009 | Assured Information Sharing Life CycleabstractThis paper describes our approach to assured information sharing. The research is being carried out under a MURI 9Multiuniversiyt Research Initiative) project funded by the Air Force Office of Scientific Research (AFOSR). The main objective of our project is: define, design and develop an Assured Information Sharing Lifecycle (AISL) that realizes the DoD's information sharing value chain. In this paper we describe the problem faced by the Department of Defense and our solution to developing an AISL System. Tim Finin, Anupam Joshi, Hillol Kargupta, Yelena Yesha, Joel Sachs, Elisa Bertino, Ninghui Li 0001, Chris Clifton, Eugene H. Spafford, Bhavani Thuraisingham, Murat Kantarcioglu, Alain Bensoussan 0001, Nathan Berg, Latifur Khan, Jiawei Han 0001, ChengXiang Zhai, Ravi S. Sandhu, Shouhuai Xu, Jim Massaro, Lada A. Adamic |
ISI | 9 |
| 2009 | A distributed requirements management framework for legal compliance and accountability
Travis D. Breaux, Annie I. Antón, Eugene H. Spafford |
Comput. Secur. | 3 |
| 2008 | Tracing Worm Break-In and Contaminations via Process Coloring: A Provenance-Preserving ApproachabstractTo detect and investigate self-propagating worm attacks against networked servers, the following capabilities are desirable: 1) raising timely alerts to trigger a worm investigation, 2) determining the break-in point of a worm, i.e., the vulnerable service from which the worm infiltrates the victim, and 3) identifying all contaminations inflicted by the worm during its residence in the victim. In this paper, we argue that the worm break-in provenance information has not been exploited in achieving these capabilities and thus propose process coloring, a new approach that preserves worm break-in provenance information and propagates it along operating- system-level information flows. More specifically, process coloring assigns a "color," a unique systemwide identifier, to each remotely accessible server process. The color will be either inherited by spawned child processes or diffused transitively through process actions. Process coloring achieves three new capabilities: color-based worm warning generation, break-in point identification, and log file partitioning. The virtualization-based implementation enables more tamper-resistant log collection, storage, and real-time monitoring. Beyond the overhead introduced by virtualization, process coloring only incurs very small additional system overhead. Experiments with real-world worms demonstrate the advantages of processing coloring over non-provenance-preserving tools. Xuxian Jiang, Florian P. Buchholz, Aaron Walters, Dongyan Xu, Yi-Min Wang, Eugene H. Spafford |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2007 | CuPIDS: An exploration of highly focused, co-processor-based information system protection
Paul D. Williams, Eugene H. Spafford |
Comput. Networks | 2 |
| 2007 | Automated adaptive intrusion containment in systems of interacting services
Yu-Sung Wu, Bingrui Foo, Yu-Chun Mao, Saurabh Bagchi, Eugene H. Spafford |
Comput. Networks | 5 |
| 2007 | Run-time label propagation for forensic audit data
Florian P. Buchholz, Eugene H. Spafford |
Comput. Secur. | 2 |
| 2006 | Provenance-Aware Tracing ofWorm Break-in and Contaminations: A Process Coloring ApproachabstractTo investigate the exploitation and contamination by self-propagating Internet worms, a provenance-aware tracing mechanism is highly desirable. Provenance unawareness causes difficulties in fast, accurate identification of a worm’s break-in point, and incurs significant log inspection overhead. This paper presents the design, implementation, and evaluation of process coloring, an efficient provenance-aware approach to worm break-in and contamination tracing. More specifically, process coloring assigns a "color", a unique system-wide identifier, to each remotely-accessible server or process. The color will then be either inherited by spawned child processes or diffused indirectly through process actions (e.g., read/write operations). Process coloring brings two major advantages: (1) It enables fast color-based identification of a worm’s break-in point even before detailed log analysis; (2) It naturally partitions log data based on their colors, effectively reducing the volume of log data that need to be examined for worm investigation. A tamper-resistant log collection method is developed based on the virtual machine introspection technique. Our experiments with a number of real-world worms demonstrate the advantages of processing coloring. Xuxian Jiang, Aaron Walters, Dongyan Xu, Eugene H. Spafford, Florian P. Buchholz, Yi-Min Wang |
ICDCS | 4 |
| 2006 | Some Challenges in Digital Forensics
Eugene H. Spafford |
IFIP Int. Conf. Digital Forensics | 1 |
| 2005 | Automated Digital Evidence Target Definition Using Outlier Analysis and Existing Evidence
Brian D. Carrier, Eugene H. Spafford |
DFRWS | 2 |
| 2005 | ADEPTS: Adaptive Intrusion Response Using Attack Graphs in an E-Commerce EnvironmentabstractDistributed systems with multiple interacting services, especially e-commerce systems, are suitable targets for malicious attacks because of the potential financial impact. Compared to intrusion detection, automated response has received relatively less attention. In this paper, we present the design of automated response mechanisms in an intrusion tolerant system called ADEPTS. Our focus is on enforcing containment in the system, thus localizing the intrusion and allowing the system to provide service, albeit degraded. ADEPTS uses a graph of intrusion goals, called I-GRAPH, as the underlying representation in the system. In response to alerts from an intrusion detection framework, ADEPTS executes algorithms to determine the spread of the intrusion and the appropriate responses to deploy. A feedback mechanism evaluates the success of a deployed response and uses that in guiding future choices. ADEPTS is demonstrated on a distributed e-commerce system and evaluated using a survivability metric. Bingrui Foo, Yu-Sung Wu, Yu-Chun Mao, Saurabh Bagchi, Eugene H. Spafford |
DSN | 5 |
| 2005 | Virtual Playgrounds for Worm Behavior Investigation
Xuxian Jiang, Dongyan Xu, Helen J. Wang, Eugene H. Spafford |
RAID | 4 |
| 2005 | Efficient Intrusion Detection using Automaton InliningabstractHost-based intrusion detection systems attempt to identify attacks by discovering program behaviors that deviate from expected patterns. While the idea of performing behavior validation on-the-fly and terminating errant tasks as soon as a violation is detected is appealing, existing systems exhibit serious shortcomings in terms of accuracy and/or efficiency. To gain acceptance, a number of technical advances are needed. In this paper we focus on automated, conservative, intrusion detection techniques, i.e. techniques which do not require human intervention and do not suffer from false positives. We present a static analysis algorithm for constructing a flow- and context-sensitive model of a program that allows for efficient online validation. Context-sensitivity is essential to reduce the number of impossible control-flow paths accepted by the intrusion detection system because such paths provide opportunities for attackers to evade detection. An important consideration for on-the-fly intrusion detection is to reduce the performance overhead caused by monitoring. Compared to the existing approaches, our inlined automaton model (IAM) presents a good tradeoff between accuracy and performance. On a 32K line program, the monitoring overhead is negligible. While the space requirements of a naive IAM implementation can be quite high, compaction techniques can be employed to substantially reduce that footprint. Rajeev Gopalakrishna, Eugene H. Spafford, Jan Vitek |
S&P | 2 |
| 2004 | What starisstar information security?abstractRecent events have increasingly focused public attention on issues of information privacy, computer and network security, cybercrime and cyber terrorism. Yet despite all of this attention, there is some confusion about what is actually encompassed by those terms. There are some obvious components, such as cryptography and access control. However, the list of undisputed topics is not long or well-developed, and many questions arise as to whether a typical computer science department can offer all of the topics involved. That there are only a few universities that teach a comprehensive curriculum in these topics serves to illustrate the imprecise nature of the field. Many professionals have taken to describing it as "information security" or "information assurance" to distinguish that the focus is not on computers and networks, but on the information they hold and process.This talk will present a more comprehensive view of the area than simply within the confines of CS/CE. The speaker has been teaching information security for nearly 20 years and has developed a view that spans many traditional disciplines. The talk will present some of the reasons for that breadth of view, illustrated with examples taken from the recent CRA Grand Challenges Conference on Information Security. One conclusion from this talk is that getting good information security education widely implemented may not be simple, given current constraints and traditions within academia. Eugene H. Spafford |
SIGCSE | 1 |
| 2003 | Poly2 Paradigm: A Secure Network Service ArchitectureabstractGeneral-purpose operating systems provide a rich computing environment both to the user and the attacker. The declining cost of hardware and the growing security concerns of software necessitate a revalidation of the many assumptions made in network service architectures. Enforcing sound design principles while retaining usability and flexibility is key to practical security. Poly/sup 2/ is an approach to build a hardened framework for network services from commodity hardware and software. Guided by well-known security design principles such as least common mechanism and economy of mechanism, and driven by goals such as psychological acceptability and immediate usability, Poly/sup 2/ provides a secure platform for network services. It also serves as a testbed for several security-related research areas such as intrusion detection, forensics, and high availability. This paper discusses the overall design and philosophy of Poly/sup 2/, presents an initial implementation, and outlines future work. Eric Bryant, James P. Early, Rajeev Gopalakrishna, Gregory Roth, Eugene H. Spafford, Keith Watson, Scott Yost |
ACSAC | 5 |
| 2003 | A Failure to Learn from the PastabstractOn the evening of 2 November 1988, someone "infected" the Internet with a worm program. That program exploited flaws in utility programs in systems based on BSD-derived versions of UNIX. The flaws allowed the program to break into those machines and copy itself, thus infecting those systems. This program eventually spread to thousands of machines, and disrupted normal activities and Internet connectivity for many days. It was the first major network-wide attack on computer systems, and thus was a matter of considerable interest. We provide a brief chronology of both the spread and eradication of the program, a presentation about how the program worked, and details of the aftermath. That is followed by discussion of some observations of what has happened in the years since that incident. The discussion supports the title-that the community has failed to learn from the past. Eugene H. Spafford |
ACSAC | 1 |
| 2002 | Using Internal Sensors and Embedded Detectors for Intrusion DetectionabstractWe introduce the concept of using internal sensors to perform intrusion detection in computer systems. We show its practical feasibility and discuss its characteristics, related design and implementation issues. We introduce a classification of data collection mechanisms for intrusion detection sys tems. At a conceptual level, these mechanisms are classified as direct and indirect monitoring. At a practical level, direct monitoring can be implemented using external or internal sensors. Internal sensors provide advantages with respect to reliability, completeness, timeliness and volume of data, in addition to efficiency and resistance against attacks. We introduce an architecture called ESP as a framework for building intrusion detection systems based on internal sensors. We describe in detail a prototype implementation based on the ESP architecture and introduce the concept of embedded detectors as a mechanism for localized data reduction. Our implementation shows that it is possible to build both specific (specialized for a certain intrusion) and generic (able to detect different types of intrusions) detectors. Performance testing of the ESP implementation shows the impact that embedded detectors can have on a computer system. Detection testing shows that embedded detectors have the capability of detecting a significant percentage of new attacks. Florian Kerschbaum, Eugene H. Spafford, Diego Zamboni |
J. Comput. Secur. | 2 |
| 2001 | The Hidden Meta-Requirements of Security and PrivacyabstractWhen collecting requirements for software, designers may learn of needs for specific forms of protection to be present. These needs may be translated into requirements for encryption or authentication, but what about the non-obvious aspects of security - including privacy, auditability and assurance - that are usually overlooked in the requirements capture process? When we overlook these issues, we get software that doesn't deserve our trust. In this paper, I discuss some of the aspects of security that are regularly overlooked by designers and suggest some standard questions that should be addressed in every design. Eugene H. Spafford |
RE | 1 |
| 2000 | A Network Audit System for Host-based Intrusion Detection (NASHID) in LinuxabstractRecent work has shown that conventional operating system audit trails are insufficient to detect low-level network attacks. Because audit trails are typically based upon system calls or application sources, operations in the network protocol stack go unaudited. Earlier work has determined the audit data needed to detect low-level network attacks. We describe an implementation of an audit system which collects this data and analyze the issues that guided the implementation. Finally, we report the performance impact on the system and the rate of audit data accumulation in a test network. Thomas Daniels 0001, Eugene H. Spafford |
ACSAC | 2 |
| 2000 | Network traffic tracking systems: folly in the large?abstractArticle Network traffic tracking systems: folly in the large? Share on Authors: Thomas E. Daniels Center for Education and Research in Information Assurance and Security (CERIAS), 1315 Recitation Building, Lafayette, IN Center for Education and Research in Information Assurance and Security (CERIAS), 1315 Recitation Building, Lafayette, INView Profile , Eugene H. Spafford Center for Education and Research in Information Assurance and Security (CERIAS), 1315 Recitation Building, Lafayette, IN Center for Education and Research in Information Assurance and Security (CERIAS), 1315 Recitation Building, Lafayette, INView Profile Authors Info & Claims NSPW '00: Proceedings of the 2000 workshop on New security paradigmsFebruary 2001 Pages 119–124https://doi.org/10.1145/366173.366200Online:20 February 2001Publication History 4citation467DownloadsMetricsTotal Citations4Total Downloads467Last 12 Months4Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Thomas Daniels 0001, Eugene H. Spafford |
NSPW | 2 |
| 2000 | Intrusion detection using autonomous agents
Eugene H. Spafford, Diego Zamboni |
Comput. Networks | 1 |
| 1999 | New directions for the AAFID architecture
Eugene H. Spafford, Diego Zamboni |
Recent Advances in Intrusion Detection | 1 |
| 1999 | Identification of Host Audit Data to Detect Attacks on Low-level IP VulnerabilitiesabstractConventional host-based and network-based intrusion and misuse detection systems have concentrated on detecting network-based and internal attacks, but little work has addressed host-based detection of low-level network attacks. A major reason for th Thomas Daniels 0001, Eugene H. Spafford |
J. Comput. Secur. | 2 |
| 1998 | An Architecture for Intrusion Detection Using Autonomous AgentsabstractThe intrusion detection system architectures commonly used in commercial and research systems have a number of problems that limit their configurability, scalability or efficiency. The most common shortcoming in the existing architectures is that they are built around a single monolithic entity that does most of the data collection and processing. In this paper, we review our architecture for a distributed intrusion detection system based on multiple independent entities working collectively. We call these entities autonomous agents. This approach solves some of the problems previously mentioned. We present the motivation and description of the approach, partial results obtained from an early prototype, a discussion of design and implementation issues, and directions for future work. J. S. Balasubramaniyan, J. O. Garcia-Fernandez, D. Isacoff, Eugene H. Spafford, Diego Zamboni |
ACSAC | 4 |
| 1998 | Dissemination of state information in distributed autonomous systems
Steve J. Chapin, Eugene H. Spafford |
Comput. Commun. | 2 |
| 1998 | Prototyping experiences with classical IP and ARP over signaled ATM connections
Christoph L. Schuba, Eugene H. Spafford, Berry Kercheval |
J. Syst. Softw. | 2 |
| 1997 | A Reference Model for Firewall TechnologyabstractThe paper concentrates on one particular technological aspect of providing communications security, firewall technology. Currently firewall technology is a specialized engineering solution rather than a scientifically based solution. The paper introduces a reference model that captures existing firewall technology and allows for an extension to networking technologies to which it was not applied previously. It can serve as a framework in which firewall systems can be designed and validated. The essential components of the reference model are authentication, integrity assurance, access control, audit, and their enforcement. All components are governed by a centralized security policy, and they can be deployed in a distributed fashion to achieve scaling. Christoph L. Schuba, Eugene H. Spafford |
ACSAC | 2 |
| 1997 | Failure and Fault Analysis for Software DebuggingabstractMost studies of software failures and faults have done little more than classify failures and faults collected from long-term projects. The authors propose a model to analyze failures and faults for debugging purposes. In the model, they define "failure modes" and "failure types" to identify the existence of program failures and the nature of the program failures, respectively. The goal of this research is to achieve a systematic process model to localize faults in debugging. They first examine properties of the proposed model from a theoretical point of view, then use the trityp program as a simple example to illustrate the possible usage of the model for debugging. Further study of the failure mode, a pilot experiment of applying the proposed model, and a way to employ heuristics according to different situations for fault localization are areas of future work. Richard A. DeMillo, Hsin Pan, Eugene H. Spafford |
COMPSAC | 3 |
| 1997 | Low-threat security patches and toolsabstractWe consider the problem of distributing potentially dangerous information to a number of competing parties. As a prime example, we focus on the issue of distributing security patches to software. These patches implicitly contain vulnerability information that may be abused to jeopardize the security of other systems. When a vendor supplies a binary program patch, different users may receive it at different times. The differential application times of the patch create a window of vulnerability until all users have installed the patch. An abuser might analyze the binary patch before others install it. Armed with this information, he might be able to abuse another user's machine. A related situation occurs in the deployment of security tools. However, many tools will necessarily encode vulnerability information or explicit information about security “localisms”. This information may be reverse-engineered and used against systems. We discuss several ways in which security patches and tools may be made safer. Among these are: customizing patches to apply to only one machine; disguising patches to hinder their interpretation; synchronizing patch distribution to shrink the window of vulnerability; applying patches automatically; and using cryptoprocessors with enciphered operating systems. We conclude with some observations on the utility and effectiveness of these methods Mohd A. Bashar, Ganesh Krishnan, Markus G. Kuhn, Eugene H. Spafford, Samuel S. Wagstaff Jr. |
ICSM | 4 |
| 1997 | Misplaced Trust: Kerberos 4 Session KeysabstractOne of the commonly accepted principles of software design for security is that making the source code openly available leads to better security. The presumption is that the open publication of source code will lead others to review the code for errors, however this openness is no guarantee of correctness. One of the most widely published and used pieces of security software in recent memory is the MIT implementation of the Kerberos authentication protocol. In the design of the protocol, random session keys are the basis for establishing the authenticity of service requests. Because of the way that the Kerberos Version 4 implementation selected its random keys, the secret keys could easily be guessed in a matter of seconds. This paper discusses the difficulty of generating good random numbers, the mistakes that were made in implementing Kerberos Version 4, and the breakdown of software engineering that allowed this flaw to remain unfixed for ten years. We discuss this as a particularly notable example of the need to examine security-critical code carefully, even when it is made publicly available. Bryn Dole, Steven W. Lodin, Eugene H. Spafford |
NDSS | 3 |
| 1997 | Analysis of a Denial of Service Attack on TCPabstractThe paper analyzes a network based denial of service attack for IP (Internet Protocol) based networks. It is popularly called SYN flooding. It works by an attacker sending many TCP (Transmission Control Protocol) connection requests with spoofed source addresses to a victim's machine. Each request causes the targeted host to instantiate data structures out of a limited pool of resources. Once the target host's resources are exhausted, no more incoming TCP connections can be established, thus denying further legitimate access. The paper contributes a detailed analysis of the SYN flooding attack and a discussion of existing and proposed countermeasures. Furthermore, we introduce a new solution approach, explain its design, and evaluate its performance. Our approach offers protection against SYN flooding for all hosts connected to the same local area network, independent of their operating system or networking stack implementation. It is highly portable, configurable, extensible, and requires neither special hardware, nor modifications in routers or protected end systems. Christoph L. Schuba, Ivan Krsul, Markus G. Kuhn, Eugene H. Spafford, Aurobindo Sundaram, Diego Zamboni |
S&P | 4 |
| 1997 | Authorship analysis: identifying the author of a program
Ivan Krsul, Eugene H. Spafford |
Comput. Secur. | 2 |
| 1996 | Critical Slicing for Software Fault LocalizationabstractDeveloping effective debugging strategies to guarantee the reliability of software is important. By analyzing the debugging process used by experienced programmers, we have found that four distinct tasks are consistently performed: (1) determining statements involved in program failures, (2) selecting suspicious statements that might contain faults, (3) making hypotheses about suspicious faults (variables and locations), and (4) restoring program state to a specific statement for verification. This research focuses support for the second task, reducing the search domain for faults, which we refer to as fault localization.We explored a new approach to enhancing the process of fault localization based on dynamic program slicing and mutation-based testing. In this new approach, we have developed the technique of Critical Slicing to enable debuggers to highlight suspicious statements and thus to confine the search domain to a small region. The Critical Slicing technique is partly based on "statement deletion" mutant operator of the mutation-based testing methodology. We have explored properties of Critical Slicing, such as the relationship among Critical Slicing, Dynamic Program Slicing, and Executable Static Program Slicing; the cost to construct critical slices; and the effectiveness of Critical Slicing. Results of experiments support our conjecture as to the effectiveness and feasibility of using Critical Slicing for fault localization.This paper explains our technique and summarizes some of our findings. From these, we conclude that a debugger equipped with our proposed fault localization method can reduce human interaction time significantly and aid in the debugging of complex software. Richard A. DeMillo, Hsin Pan, Eugene H. Spafford |
ISSTA | 3 |
| 1995 | Information Superhighway or Road to Ruin?abstractNo abstract available. Becky Bace, Gary Christoph, Tsutomu Shimomura, Eugene H. Spafford |
SC | 4 |
| 1994 | The Design and Implementation of Tripwire: A File System Integrity CheckerabstractAt the heart of most computer systems is a file system. The file system contains user data, executable programs, configuration and authorization information, and (usually) the base executable version of the operating system itself. The ability to monitor file systems for unauthorized or unexpected changes gives system administrators valuable data for protecting and maintaining their systems. However, in environments of many networked heterogeneous platforms with different policies and software, the task of monitoring changes becomes quite daunting. Gene H. Kim, Eugene H. Spafford |
CCS | 2 |
| 1994 | Computer Viruses as Artificial LifeabstractThere has been considerable interest in computer viruses since they first appeared in 1981, and especially in the past few years as they have reached epidemic numbers in many personal computer environments. Viruses have been written about as a security problem, as a social problem, and as a possible means of performing useful tasks in a distributed computing environment. However, only recently have some scientists begun to ask if computer viruses are not a form of artificial life—a self-replicating organism. Simply because computer viruses do not exist as organic molecules may not be sufficient reason to dismiss the classification of this form of “vandalware” as a form of life. This paper begins with a description of how computer viruses operate and their history, and of the various ways computer viruses are structured. It then examines how viruses meet properties associated with life as defined by some researchers in the area of artificial life and self-organizing systems. The paper concludes with some comments directed toward the definition of artificially “alive” systems and experimentation. Eugene H. Spafford |
Artif. Life | 1 |
| 1993 | Software forensics: Can we track code to its authors?
Eugene H. Spafford, Stephen A. Weeber |
Comput. Secur. | 1 |
| 1993 | Debugging with Dynamic Slicing and BacktrackingabstractAbstract Programmers spend considerable time debugging code. Symbolic debuggers provide some help but the task remains complex and difficult. Other than breakpoints and tracing, these tools provide little high‐level help. Programmers must perform many tasks manually that the tools could perform automatically, such as finding which statements in the program affect the value of an output variable for a given test case, and what was the value of a given variable when the control last reached a given program location. If debugging tools provided explicit support for these tasks, the debugging process could be automated to a significant extent. In this paper we present a debugging model, based on dynamic program slicing and execution backtracking techniques, that easily lends itself to automation. This model is based on experience with using these techniques to debug software. We also present a prototype debugging tool, SPYDER, that explicitly supports the proposed model, and with which we are performing further debugging research. Hiralal Agrawal, Richard A. DeMillo, Eugene H. Spafford |
Softw. Pract. Exp. | 3 |
| 1992 | A generic virus scanner for C++abstractA virus detection tool is described. It is a generic virus scanner in C++ with no inherent limitations on the file systems, file types or host architectures that can be scanned. The tool is completely general and is structured in such a way that it can be easily augmented to recognize viruses across different system platforms with varied file types. The implementation defines an abstract C++ class, VirInfo, which encapsulates virus features common to all scannable viruses. Subclasses of this abstract class may be used to define viruses that infect different machines and operating systems. The generality of the mechanism allows it to be used for other forms of scanning as well.> Sandeep Kumar 0008, Eugene H. Spafford |
ACSAC | 2 |
| 1992 | OPUS: Preventing weak password choices
Eugene H. Spafford |
Comput. Secur. | 1 |
| 1992 | Are computer hacker break-ins ethical?
Eugene H. Spafford |
J. Syst. Softw. | 1 |
| 1990 | Networking in the nineties (panel session)abstractNo abstract available. Brent Auernheimer, Vint Cerf, Susan Estrada, Russ Hobby, Craig Partridge, Eugene H. Spafford, Steven S. Wolff |
SIGCSE | 6 |
| 1990 | Methods of integrating the study of ethics into the computer science curriculum (panel session)abstractNo abstract available. Donald Gotterbarn, Deborah G. Johnson, Keith W. Miller 0001, Eugene H. Spafford |
SIGCSE | 4 |
| 1990 | Extending Mutation Testing to Find Environmental BugsabstractAbstract Environmental bugs are bugs caused by limitations of precision or capacity in the environment of a piece of software. These bugs may be difficult to activate and even more difficult to find. This paper reports on an extension to traditional mutation testing that enables testing specifically for environmental bugs involving integer arithmetic. This method is both simple and effective, and provides some insight into other possible extensions of the mutation‐testing methodology that can be used to expose environmental bugs. Eugene H. Spafford |
Softw. Pract. Exp. | 1 |