Showing posts with label IEEE. Show all posts
Showing posts with label IEEE. Show all posts

Thursday, May 22, 2014

IEEE Security and Privacy Symposium 2014: Another Challenging Year, Another Compelling IEEE SSP, and Another Significant Contribution from CMU CyLab


Giovanni Domenico Tiepolo - Procession of the Trojan Horse in Troy (1773)
Another challenging year in cyber security and privacy means another compelling IEEE Security and Privacy Symposium, and another compelling IEEE Security and Privacy Symposium means another significant contribution from Carnegie Mellon University CyLab.

This year, three hundred and thirty three papers were submitted. After a rigorous review process (which included ninety nine "intensive discussions," one thousand two hundred eighteen reviews and a rebuttal phase), forty four papers were selected to be published as part of the Symposium.

Of these forty four worthy contributions, four were singled out for IEEE Security and Privacy Symposium 2014 Best Papers Awards:

Best Paper
 
Secure Multiparty Computations on BitCoin by Marcin Andrychowicz, Stefan Dziembowski, Daniel Malinowski, and Łukasz Mazurek (University of Warsaw)

Best Practical Paper
 
Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations by Chad Brubaker and Suman Jana (University of Texas at Austin), Baishakhi Ray (University Of California Davis), and Sarfraz Khurshid and Vitaly Shmatikov (University of Texas at Austin)

Best Student Papers

Framing Signals — A Return to Portable Shellcode by Erik Bosman and Herbert Bos (Vrije Universiteit Amsterdam)

Bootstrapping Privacy Compliance in Big Data Systems by Shayak Sen (Carnegie Mellon University), Saikat Guha (Microsoft Research, India), Anupam Datta (Carnegie Mellon University), Sriram Rajamani (Microsoft Research, India), Janice Tsai (Microsoft Research, Redmond), and Jeannette Wing (Microsoft Research)

CMU CyLab researcher Shayak Sen presented the award winning paper co-authored by members of the CyLab and Microsoft Research teams:

In this paper, we demonstrate a collection of techniques to transition to automated privacy compliance compliance checking in big data systems. To this end we designed the LEGALEASE language, instantiated for stating privacy policies as a form of restrictions on information flows, and the GROK data inventory that maps low level data types in code to highlevel policy concepts. We show that LEGALEASE is usable by non-technical privacy champions through a user study. We show that LEGALEASE is expressive enough to capture real-world privacy policies with purpose, role, and storage restrictions with some limited temporal properties, in particular that of Bing and Google. To build the GROK data flow grap we leveraged past work in program analysis and data flow analysis. We demonstrate how to bootstrap labeling the graph with LEGALEASE policy datatypes at massive scale. We note that the structure of the graph allows a small number of annotations to cover a large fraction of the graph. We report on our experiences and learnings from operating the system for over a year in Bing. -- Shayak Sen (Carnegie Mellon University), Saikat Guha (Microsoft Research, India), Anupam Datta (Carnegie Mellon University), Sriram Rajamani (Microsoft Research, India), Janice Tsai (Microsoft Research, Redmond), and Jeannette Wing (Microsoft Research), Bootstrapping Privacy Compliance in Big Data Systems, IEEE Security and Privacy Symposium 2014, Best Student Paper (1 of 2)

But, of course, the Bootstrapping Privacy Compliance paper was not the only CyLab contribution to the Symposium program, e.g., CMU CyLab researcher Zongwei Zhou spoke on Dancing with Giants; Wimpy Kernels for On-Demand Isolation I/O, a paper co-authored with Miao Yu and Virgil Gligor:

Trustworthy applications are unlikely to survive in the marketplace without the ability to use a variety of basic services securely, such as on-demand isolated I/O channels to peripheral devices. This paper presents a security architecture based on a wimpy kernel that provides these services without bloating the underlying trusted computing base. It also presents a concrete implementation of the wimpy kernel for a major I/O subsystem, namely USB subsystem, and a variety of device drivers. Experimental measurements show that the desired minimality and efficiency goals for the trusted base are achieved. -- Zongwei Zhou, Miao Yu, Virgil Gligor, Dancing with Giants; Wimpy Kernels for On-Demand Isolation I/O, IEEE Security and Privacy Symposium 2014

Other CMU papers selected and presented at IEEE SSP 2014 included:

All Your Screens Are Belong to Us; Attacks Exploiting the HTML5 Screen Sharing API, Analyzing Forged SSL Certificates in the Wild by Lin-Shung Huang, Yuan Tian, Patrick Tague and others, CMU SV and Facebook

Analyzing Forged SSL Certificates in the Wild by Lin-Shung Huang, Alrex Rice, Erling Ellingsen, Collin Jackson

Stopping A Rapid Tornado with A Puff by Jose Lopes and Nuno Neves of CMU Portugal
CyLab's contribution to IEEE SPP 2014 also included several papers from two CMU CyLab alumni and alumna.

There were three papers co-authored by CMU CyLab alumnus XiaoFeng Wang of Indiana University (Bloomington): Hunting the Red Fox Online: Understanding and dectection of Mass Redirect-Script Injections, Upgrading Your Android, Elevating My Malware - Privilege Escalation Through Mobile OS updating, and Perils of Fragmentation: Security Hazards in Android Device Driven Customizations.

Also CMU CyLab alumnus Bryan Parno of Microsoft Research and a CMU CyLab alumna Elaine Shi of University of Maryland (College Park) were among the co-authors of PermaCoin: Repurposing Bitcoin Work for Data Preservation, and Shi co-authored a second paper, Automating Efficient RAM-Model Secure Computation.

CyLab's efforts were also apparent on the organizational level at IEEE SSP 2014:

Adrian Perrig of ETH Zürich, formerly CyLab's Research Director, now a CyLab Distinguished Fellow, served as one of the Symposium's three program chairs.

Three CyLab researchers served as Session Chairs, Lujo Bauer for Systems Security, Virgil Gligor (CyLab Director) for Attacks 3 and Anupam Datta for Secure Computation and Storage.

Also, CMU CyLab alum Bryan Parno served as a Session Chair for Privacy and Anonymity.

And, looking ahead to next year, Lujo Bauer will be one of the Symposium program chairs. 2015 will likely be another challenging year in cyber security and privacy, which will mean another compelling IEEE Security and Privacy Symposium, with another significant contribution from Carnegie Mellon University CyLab.

Related Posts

CyLab's Strong Presence Continues at Annual IEEE Symposium on Security and Privacy (2013)

CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

A Report on 2012 IEEE Symposium on Privacy and Security

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium



Thursday, May 23, 2013

CyLab's Strong Presence Continues at Annual IEEE Symposium on Security and Privacy

Min Suk Kang with fellow CyLab grad student, after presenting The Crossfire Attack at
34th Annual IEEE Security & Privacy Symposium (May 2013, San Francisco).
The 34th annual IEEE Security and Privacy Symposium was held May 19-22 2013, in downtown San Francisco. Once again, as in recent years, Carnegie Mellon University CyLab researchers made a significant contribution to both its content and its tone.

CyLab Distinguished Fellow Adrian Perrig served as one of the three Program Chairs, along with Wenke Lee of Georgia Tech and Michael Backes of Saarland University.

Also, four of the thirteen Session Chairs were current or former CyLab researchers: current faculty members Lujo Bauer and Anupam Datta, and former faculty members Jon McCune, now with Google, and Bryan Parno, now with Microsoft Research.

Two CyLab papers were among the thirty-eight presented: The Crossfire Attack authored by Min Suk Kang, Soo Bum Lee and Virgil D. Gligor of CyLab, and Design, Implementation and Verification of an eXtensible and Modular Hypervisor Framework authored by CyLab researchers Amit Vasudevan, Limin Jia, James Newsome and Anupam Datta, along with Sagar Chaki of the Software Engineering Institute (SEI) at Carnegie Mellon University) and Jonathan M. McCune of Google (a former CyLab researcher, as mentioned above).

Furthermore, the Best Paper Award went to Bryan Parno for Pinocchio: Nearly Practical Verifiable Computation, co-authored with Craig Gentry and Mariana Raykova of IBM Research and Jon Howell, also of Microsoft Research. Before he went to Microsoft, Parno did his PhD at Carnegie Mellon University CyLab under the supervision of Adrian Perrig, and his dissertation won the 2010 ACM Doctoral Dissertation Award.

Here are excerpts from the two CyLab papers presented, with links to the full texts:

In this paper, we present the Crossfire attack. This attack can effectively cut off the Internet connections of a targeted enterprise (e.g., a university campus, a military base, a set of energy distribution stations); it can also disable up to 53% of the total number of Internet connections of some US states, and up to about 33% of all the connections of the West Coast of the US. The attack has the hallmarks of Internet terrorism3: it is low cost using legitimate-looking means (e.g., low-intensity, protocol conforming traffic); its locus cannot be anticipated and it cannot be detected until substantial, persistent damage is done; and most importantly, it is indirect: the immediate target of the attack (i.e., selected Internet links) is not necessarily the intended victim (i.e., an end-point enterprise, state, region, or small country). The low cost of the attack (viz., Section IV), would also enable a perpetrator to blackmail the victim. The Crossfire Attack , Min Suk Kang, Soo Bum Lee and Virgil D. Gligor (Carnegie Mellon University CyLab)

We propose an eXtensible and Modular HypervisorFramework (XMHF) which strives to be a comprehensible and flexible platform for building hypervisor applications (“hypapps”). XMHF is based on a design methodology that enables automated verification of hypervisor memory integrity. In particular, the automated verification was performed on the actual source code of XMHF – consisting of 5208 lines of C code – using the CBMC model checker. We believe that XMHF provides a good starting point for research and development on hypervisors with rigorous and “designed-in” security guarantees. Given XMHF’s features and performance characteristics, we believe that it can significantly enhance (security-oriented) hypervisor research and development. Design, Implementation and Verification of an eXtensible and Modular Hypervisor Framework, Amit Vasudevan, Limin Jia, James Newsome and Anupam Datta (Carnegie Mellon University CyLab), Sagar Chaki (SEI, Carnegie Mellon University) and Jonathan M. McCune (Google)

Some Related Posts
 
CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium

CyLab Researchers Virgil Gligor and David Brumley Receive Honors

CyLab researcher Bryan Parno wins ACM 2010 Doctoral Dissertation Award

Parno, McCune and Perrig Author Book on Bootstrapping Trust in Modern Computing

-- Richard Power




Saturday, May 26, 2012

CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

CyLab's Zongwei Zhou talks on Building Verifiable Trusted Path on Commodity X86 Computers




CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

The 33rd annual IEEE Symposium on Security and Privacy held at the St. Francis hotel in downtown San Francisco (May 20-May 23, 2012), is one of the respected venues in the field, and once again, numerous papers presented by Carnegie Mellon University CyLab researcher and several sessions chaired by CyLab faculty made for a powerful presence.

Seven papers authored or co-authored by CyLab researchers were presented in the course of the three-day program. In addition to the papers presented, CyLab faculty also chaired three sessions.

Here is the CyLab 2012 IEEE Security and Privacy roster of papers and presenters, with brief excerpts from each paper:

Jiyong Jang talked on ReDeBug: Finding Unpatched Code Clones in Entire OS Distributions, a paper co-authored with Abeer Agrawal, and CyLab faculty David Brumley.

"ReDeBug was designed for scalability to entire OS distributions, the ability to handle real code, and minimizing false detection. ReDeBug found 15,546 unpatched code clones, which likely represent real vulnerabilities, by analyzing 2.1 billion lines of code on a commodity desktop. We demonstrate the practical impact of ReDeBug by confirming 145 real bugs in the latest version of Debian Squeeze packages. We believe ReDeBug can be a realistic solution for regular developers to enhance the security of their code in day-to-day development."

Michael Carl Tschantz presented Formalizing and Enforcing Purpose Restrictions of Privacy Policies, a paper co-authored with Anupam Datta and Jeannette M. Wing.

"Our work makes the following contributions: 1) The first semantic formalism of when a sequence of actions is for a purpose; 2) Empirical validation that our formalism closely corresponds to how people understand the word “purpose”; 3) An algorithm employing our formalism and its implementation for auditing; and 4) The characterization of previous policy enforcement methods in our formalism and a comparative study of their expressiveness. The first two contributions illustrate that planning can formalize purpose restrictions. The next two illustrate that our formalism may aid automated auditing and analysis."

Xin Zhang, who graduated from Carnegie Mellon University and now works for Google, delivered Secure and Scalable Fault Localization under Dynamic Traffic Patterns, co-authored with CyLab Technical Director Adrian Perrig, and by Chang Lan of Tsinghua University.

"While existing path-based FL protocols aim to identify a specific faulty link (if any), DynaFL localizes data-plane faults to a coarser-grained 1-hop neighborhood, to achieve four distinct advantages. First, DynaFL does not require any minimum duration time of paths or flows in order to detect data-plane faults as path-based FL protocols do. Thus, DynaFL can fully cope with short-lived flows which are popularly seen in modern networks. Second, in DynaFL, a source node does not need to know the exact outgoing path, unlike path-based FL protocols. Hence, DynaFL can support agile (e.g., packet-level) load balancing such as VL2 routing [20] for datacenter networks. Third, a DynaFL router only needs around 4MB per-neighbor state based on our classic Sketch implementation, while a router in a path-based FL protocol requires per-path state. Finally, a DynaFL router only maintains a single secret key shared with the AC, while a router in a path-based FL protocol needs to manage 100 to 10000 secret keys in measured ISP topologies."

Sang Kil Cha spoke on Unleashing Mayhem on Binary Code, co-authored with Thanassis Avgerinos, Alexandre Rebert and David Brumley.

"We presented MAYHEM, a tool for automatically finding exploitable bugs in binary (i.e., executable) programs in an efficient and scalable way. To this end, MAYHEM introduces a novel hybrid symbolic execution scheme that combines the benefits of existing symbolic execution techniques (both online and offline) into a single system. We also present index-based memory modeling, a technique that allows MAYHEM to discover more exploitable bugs at the binary-level. We used MAYHEM to analyze 29 applications and automatically identified and demonstrated 29 exploitable vulnerabilities."

Saranga Komanduri talked on Guess again (and again and again): Measuring password strength by simulating password-cracking algorithms, co-authored with Patrick Gage Kelley, , Michelle L. Mazurek, Richard Shay, Tim Vidas, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, and Julio Lopez.

"We introduced a new, efficient technique for evaluating password strength, which can be implemented for a variety of password-guessing algorithms and tuned using a variety of training sets to gain insight into the comparative guess resistance of different sets of passwords. Using this technique, we performed a more comprehensive password analysis than had previously been possible. We found several notable results about the comparative strength of different composition policies. Although NIST considers basic16 and comprehensive8 equivalent, we found that basic16 is superior against large numbers of guesses. Combined with a prior result that basic16 is also easier for users [46], this suggests basic16 is the better policy choice. We also found that the effectiveness of a dictionary check depends heavily on the choice of dictionary; in particular, a large blacklist created using state-of-the-art password-guessing techniques is much more effective than a standard dictionary at preventing users from choosing easily guessed passwords. Our results also reveal important information about conducting guess-resistance analysis ..."

Hsu-Chun Hsiao presented LAP: Lightweight Anonymity and Privacy, co-authored with Tiffany Hyun-Jin Kim, and Adrian Perrig, along with Akira Yamada (KDDI R&D), Sam Nelson and Marco Gruteser (Rutgers University), and Wei Ming (Tsinghua University).

"In this framework, our approach is simple yet effective: by leveraging encrypted packet-carried forwarding state, ISPs that support our protocol can efficiently forward packets towards the destination, where each encrypted ISP-hop further camouflages the source or destination address or its location. Although encrypted packet-carried forwarding state is currently not supported in IP, we design simple extensions to IP that could enable this technology. In particular, our approach is even more relevant in future network architectures, where the design can be readily incorporated. This new point in the design space of anonymity protocols could also be used in concert with other techniques, for example in conjunction with Tor to prevent one Tor node from learning its successor. Despite weaker security proper- ties than Tor, we suspect that LAP contributes a significant benefit towards providing topological anonymity, as LAP is practical to use for all communication.

Zongwei Zhou delivered Building Verifiable Trusted Path on Commodity X86 Computers, co-authored with CyLab Director Virgil Gligor, as well as James Newsome and Jonathan M. McCune.

"Building a general-purpose trusted path mechanism for commodity computers with a significant level of assurance requires substantial systems engineering, which has not been completely achieved by prior work. Specifically, it requires (1) effective countermeasures against I/O attacks enabled by inadequate I/O architectures and potentially compromised operating systems; and (2) small trusted codebases that can be integrated with commodity operating systems. The design presented in this paper shows that, in principle, trusted path can be achieved on commodity computers, and suggests that simple I/O architecture changes would simplify trusted-path design considerably."

-- Richard Power

See Also:

CyLab Research has Powerful Impact on 2010 IEEE Security and Privacy Symposium

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security and Privacy; Q and A on Cloud, Cyberwar and Internet Freedom with Dr. Peter Neumann

Five Papers Add to Impressive CyLab Presence at ACM CCS 2011

CyLab Research Presentations Impact CHI 2011

USENIX Security 2011: Another Ring on the Tree Trunk for One of Cyber Security's Worthiest Gatherings, and a Strong CyLab Presence

USENIX Security 2011: CyLab Researchers Release Study on Illicit Online Drug Trade and Attacks on Pharma Industry

A Report on 2012 IEEE Symposium on Privacy and Security

Hsu-Chun Hsiao delivers a paper on LAP: Lightweight Anonymity and Privacy


A Report on 2012 IEEE Symposium on Privacy and Security

As noted in previous CyBlog posts, IEEE's annual Symposium on Privacy and Security (a.k.a. "Oakland") is an important event in the realm of academic research on how to best strengthen cyber security and privacy. This year's Symposium lived up to expectations. (And I am not just saying that because Carnegie Mellon University CyLab's imprint was on eight different sessions. See CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop.)

Here are a few glimpses into some sessions that interested me.

Prudent Practices for Designing Malware Experiments

Christian Rossow of the Institute for Internet Security delivered a talk on "Prudent Practices for Designing Malware Experiments," a paper co-authored with Christian J. Dietrich and Norbert Pohlmann, also of Institute for Internet Security, along Chris Grier, Christian Kreibich and Vern Paxson of University of California, Berkeley and International Computer Science Institute, Berkeley, as well as Herbert Bos and Maarten van Steen, VU University Amsterdam, The Network Institute.

Rossow articulated numerous guidelines on safety, transparency, realism and correct data sets.

I have pulled out an example of one of the guidelines from each categories:

Safety: "1) Deploy and describe containment policies. Well-designed containment policies facilitate realistic experiments while mitigating the potential harm malware causes to others over time. Experiments should at a minimum employ basic containment policies such as redirecting spam and infection attempts, and identifying and suppressing DoS attacks. Authors should discuss the containment policies and their implications on the fidelity of the experiments. Ideally, authors also monitor and discuss security breaches in their containment."

Transparency: "4) Mention the system used during execution. Malware may execute differently (if at all) across various systems, software configurations and versions. Explicit description of the particular system(s) used (e.g., 'Windows XP SP3 32bit without additional software installations') renders experiments more transparent, especially as presumptions about the 'standard' OS change with time. When relevant, authors should also include version information of installed software.

Realism: "5) Consider allowing Internet access to malware. Deferring legal and ethical considerations for a moment, we argue that experiments become significantly more realistic if the malware has Internet access. Malware often requires connectivity to communicate with command-and-control (C&C) servers and thus to expose its malicious behavior. In exceptional cases where experiments in simulated Internet environments are appropriate, authors need to describe the resulting limitations.

Correct data sets: "2) Balance datasets over malware families. In unbalanced datasets, aggressively polymorphic malware families will often unduly dominate datasets filtered by sample-uniqueness (e.g., MD5 hashes). Authors should discuss if such imbalances biased their experiments, and, if so, balance the datasets to the degree possible. explicitly if they decide to blend malicious traces with benign background activity."

Detecting Hoaxes, Frauds, and Deception in Writing Style Online

Sadia Afroz of Drexel University delivered a talk on "Detecting Hoaxes, Frauds, and Deception in Writing Style Online," a paper co-authored with colleagues Michael Brennan and Rachel Greenstadt.

This fascinating paper used the compelling story from recent headlines, i.e., strange tale of Amina, the "Gay Girl in Damascus," whose blog captured the attention of the world during the early days of the Arab Spring, only to be later revealed as the work of Thomas Macmaster, a 40 year old American male.

In reporting on the research, Afroz and her colleagues, concluded:

"Stylometry is necessary to determine authenticity of a document to prevent deception, hoaxes and frauds. In this work, we show that manual counter-measures against stylometry can be detected using second-order effects. That is, while it may be impossible to detect the author of a document whose authorship has been obfuscated, the obfuscation itself is detectable using a large feature set that is content-independent. Using Information Gain Ratio, we show that the most effective features for detecting deceptive writing are function words. We analyze a long-term deception and show that regular authorship recognition is more effective than deception detection to find indication of stylistic deception in this case."

As Afroz and her colleagues also point out, such research has implications for adversarial learning in general:

"Machine learning is often used in security problems from spam detection, to intrusion detection, to malware analysis. In these situations, the adversarial nature of the problem means that the adversary can often manipulate the classifier to produce lower quality or sometimes entirely ineffective results. In the case of adversarial writing, we show that using a broader feature set causes the manipulation itself to be detectable. This approach may be useful in other areas of adversarial learning to increase accuracy by screening out adversarial inputs."

Oakrams: Searching Through Strands of Oakland's DNA

The three day event culminated in a all-star panel on "How can a Focus on 'Science' Advance Research in Cyber Security?" Moderated by Carl Landwehr, the panel members, including Alessandro Acquisti (Carnegie Mellon), Dan Boneh (Stanford), Joshua Guttman (Worcester Polytechnic Institute), Wenke Lee (Georgia Tech) and Cormac Herley (Microsoft) on whether or not the realm of cyber security as currently constituted should be or is already "science." But honestly, in spite of some sparkling insights, particularly from Acquisti and Herley, this debate has a certain dog chasing its tail futility to it. It is the kind of debate that become central after it is already too late to grasp the reality of a situation. It reminded me of a sage perspective delivered back in the 1990s, by the legendary Donn B. Parker: "Information Security, A Folk Art in Need of An Upgrade." Parker was spot-on on that, as well as on other issues.

So before the theme music to the Bill Murray film Groundhog Day once again starts to rise up in my psyche, let me turn away from the august panel and its erudite dialogue, and end this report from Oakland on a "short talk" in which Hilarie Orman (Purple Streak, Inc.) shared her "Oakrams."

I suggest there is at least as much import in them as in the debate over "cyber security" as "science."

Orman was kind enough to explain her exercise to me.

"I call them 'Oakrams' (the conference used to be called "Oakland" informally, and the software is based on an open source system call 'WordCram.' I modified WordCram so that I could control the coloring based on the word position, and so that I could reuse a word placement while changing size and color. This resulted in two sequences of images. I preprocessed the text of the papers so that for each year I had an ordered list of all non-trivial words that occurred 20 times or more. In the first sequence, for each year of the conference, I arranged the words so that the size and color intensity was proportional to word's frequency for that year. I modified WordCram to get word arrangements that were both denser and more uniform that its usual algorithms could produce. The word coloring varied uniformly over a small color range from top to bottom and left to right. Each year had slightly different range, overlapping with the previous year, and drifting from yellow through green in 1980 to the final blue through reddish yellow in 2012. The word arrays seemed endlessly interesting to me. Some words are loaded with context in the security world, and their presence or absence in an array was a source for reflection. As a small example, the word 'alice' appeared briefly in one or two years, but never rose to prominence. These arrays showed that 'system,' 'information,' and 'security' were usually the most frequent words in each year. This wasn't surprising, but I wanted to get more information about the words that had varying popularity, and I wondered if the words could point out trends in topics. That led to the next phase. The second sequence of images used only 50 words. These were the words that were the 'most popular' over the 33 years. For each year, each word had the same placement in the visual array, but the size and color varied. The size of a word was proportional to its frequency for that year. The color hue varied from red to blueish-purple, where red meant the word had not occurred in the previous 5 years, and the amount of blue represented its average frequency during the previous 5 years. As words moved in and out of popularity their size and color and opacity varied to reflect their usage. It was interesting to see how long it took for networking terms like 'message,' 'packet,' and 'node' took to get traction. I was amazed that "privacy" has rarely been a major term, despite it being part of the 'Security and Privacy' symposium's name! And, to me, it was quite significant that 'application' and "attack" have become major terms --- we used to focus on provably secure operating systems, now we try to protect individual applications against specific attacks. I'm a calligrapher and student of typography; the wordcrams are artistic objects that I enjoy, but they carry some fragments of meaning, like pieces of DNA."

-- Richard Power

See Also:

CyLab Research has Powerful Impact on 2010 IEEE Security and Privacy Symposium

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security and Privacy; Q and A on Cloud, Cyberwar and Internet Freedom with Dr. Peter Neumann

Five Papers Add to Impressive CyLab Presence at ACM CCS 2011

CyLab Research Presentations Impact CHI 2011

USENIX Security 2011: Another Ring on the Tree Trunk for One of Cyber Security's Worthiest Gatherings, and a Strong CyLab Presence

USENIX Security 2011: CyLab Researchers Release Study on Illicit Online Drug Trade and Attacks on Pharma Industry

Saturday, May 22, 2010

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

Ross Anderson and Steven Murdoch of University of Cambridge accept 2010 IEEE Symposium of Security & Privacy Best Practical Paper Award

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

By Richard Power


The 2010 IEEE Symposium on Security and Privacy, held in Oakland, California, marked the 30th anniversary of this prestigious event.

Carl Landwehr, Program Director for the National Science Foundation, Senior Research Scientist at University of Maryland Institute for Systems Research (and Editor in Chief of IEEE Security & Privacy Magazine) received two awards: IEEE Computer Society Distinguished Service Award and Computer Society Technical Committee on Security and Privacy Outstanding Community Service Award.

Jerry Saltzer, Professor Emeritus of the M.I.T. Computer Science and Artificial Intelligence Lab (CSAIL), received the National Computer Security Award. Previous recipients include Jim Anderson, Dennis Branstad, Steven Bellovin, David Clark, Robert Courtney, Dorothy Denning, Whit Diffie, Virgil Gligor, Martin Hellman, Butler Lampson, Peter Neumann, Donn Parker, Ron Rivest, Roger Schell, Mike Schroeder, Eugene Spafford, Walter Tuchman, Steve Walker, and Willis Ware.

The "Best Paper" award went to Margarita Osadchy, Benny Pinkas, Ayman Jarrous, Boaz Moskovich of Univesity of Haifa for "CiFI - A System for Secure Face Identification."

The "Best Student Paper" award went to "TaintScope: A Checksum-Aware Directed Fuzzing Tool for Automatic Software Vulnerability Detection" by Tielei Wang, Tao Wei and Wei Zou of Peking University, and Guofei Gu of Texas A & M University

The award for "Best Practical Paper," sponsored by IEEE Security and Privacy Magazine, went to Ross Anderson, Steven Murdoch, Saar Drimer and Mike Bond of the University of Cambridge for Chip and PIN is Broken. This work describes and demonstrates "a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card’s PIN, and to remain undetected even when the merchant has an online connection to the banking network. The fraudster performs a man-in-the-middle attack to trick the terminal into believing the PIN verified correctly, while telling the card that no PIN was entered at all." (For more information and the full paper, go Ross Anderson's blog, Light Blue Touchpaper, 2-11-10)

As mentioned in my previous post on this year's Symposium, there were 31 papers presented in the course of the three day event. These papers explored ten research areas, from Malware Analysis (e.g., Automated Extraction of Proprietary Gadgets from Malware Binaries) and Network Security (e.g., Round-Efficient Broadcast Authentication Protocols for Fixed Topology Class) to Systemization II (e.g., Bootstrapping Trust in Commodity Computers) and Analyzing Deployed Systems (e.g., Experimental Security Analysis of a Modern Automobile).

Such research is vital, and it is always inspiring to listen to the fruits of this worthy labor. But I confess that as I sat through session after session, I found myself drawing back to contemplate the big picture, as I have been doing in my writings and talks over the last few years. (See, for example, Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security (Cerias Security Seminar, 9-30-09) and Red Pill? Blue Pill? Ruminations on the Intersection of Inner Space and Cyber Space (CSO Magazine, 10-23-09).

As I scanned the overflowing audience, I saw Peter Neumann hunched over his laptop, and sitting in the last row. So I asked him to give me his insights on the three big pictures questions I have been mulling over.

Q: At this year's RSA conference, I was struck by one keynote speaker after another, declaring the "cloud" as the future, and exhorting everyone to hurry into the "cloud" where we will find security much easier to attain, and everything will be better. Who is "we" is hard to answer in the cloud. Who is securing who, and what else are they doing? These are real concerns. Could you talk about the cyber security and privacy implications of "Cloud computing"?

Peter Neumann: Yes, I noticed Scott Charney, Howard Schmidt, Janet Napolitano extolling the wonders of cloud computing, and so many vendors saying they had it all under control. This is sheer and utter nonsense. Having to trust untrustworthy third- and fourth-party vendors, some of whom you do not even know exist (cf. Les Lamport's definition of a Distributed System) is ridiculous, given that the infrastractures, the computer systems, and the authentication processes are not trustworthy. Confidentiality and privacy may be least of our concerns, compared with system integrity, denials of service attacks, the lack of traceability and attribution, the lack of meaningful audit trails, and so on.

Q: The term "Cyberwar" is taking on a life of its own. You and I discussed "information warfare" well over a decade ago. What would you like to say about this term "cyberwar" and what it purports to describe? Overly hyped? Something different than the issues we have been dealing with all along in the struggle to secure cyberspace? Both?

Neumann: Cyberwar is indeed an overly hyped concept. The "war" on terrorism is a bad enough metaphor, but "cyberwar" is even worse. Who is the enemy? As Pogo once said, "We have met the enemy, and he is us." We will never completely secure "cyberspace", and the "enemy" will always have many advantages. However, we could do much better than we do at present. Also, take a look at my paragraph on the misuse of "cyber" (which is a combining form, not a noun or an adjective) on my website: http://www.csl.sri.com/neumann. (I just put up a new limerick on "metrics" also.)

Q: Spaf said something to me awhile ago, that perhaps there will be no Internet readily and freely accessible ten or twenty years into the future. I used to jokingly tell people that although the proverbial "they" succeeded in burning down the library of Alexandria, the proverbial "they" won't be able to due the equivalent to the Internet ... Ha ha ... Now I wonder. For example, the battle over net neutrality could be won in the legislatures but lost in the cloud, couldn't it? Net neutrality, government censorship, the mysterious hidden workings of the cloud, do these threaten the future freedom and evolution of the internet as a global commons? And is there any hope?

Neumann: On "network neutrality," unless the lobbyists' control over Congress ceases, legislative solutions will continue to be largely misguided in this area. But even if legislation were to become sensible here, you are correct -- it could still be lost in the clouds. Is there any hope? Yes, of course, we have to retain some modicum of optimism, but it must be accompanied by a radical shift in the entire culture by which mediocre systems with short-sighted requirements and short-sighted development practices abound. Think about BP's practices in the Gulf, and the financial industry, and you have an approximation for the computer industry and practice.

In conclusion, Neummann added, "This is off the top of the head, and reflects just a few of my holistic concerns. The picture requires much greater total-system long-term thinking than is used today."

As always, Neumann's thinking is both provocative and profoundly insightful.

And as always, if industry and government choose to ignore him, they do so not only at their own peril, but at the peril of all.

Of course, the Cloud is now inevitable; after all, it has been decreed by the captains of industry. Yes, it will offer both challenges and opportunities. But we should not sell it to ourselves as a security strategy, we should not fool ourselves, it is simply another dimension of risk added to the many dimensions of risk we are already operating within.

In regard to the term "Cyberwar," my views are somewhat complex, and contradictory, I find myself promoting it in some contexts, and debunking it in others, depending upon the misconceptions that dominate the space of the discussion.

And the future of the Internet? Well, the future of the Internet as a free and open cyberspace is nothing less than the future of human civilization; not necessarily the future of the human race, but of human civilization, or perhaps more precisely anything worthy of being called a "human civilization." Therefore, it is too important to be left to industry and government, or both, at least as long as there is a revolving door between the two, and especially while all other voices are without counter-balancing influence.

Preserving a free and open Internet, and making it accessible for the private use of all humans is both a security issue and a human rights issue; and increasingly, in the 21st Century, security issues and human rights issues are becoming interdependent, and as in other arenas of human endeavor, we can no long allow commercial interests to trump security and human rights concerns.

See Also

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?

Tuesday, May 18, 2010

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium

Samuel Langhorne Clemens (a.k.a. Mark Twain) in the lab of Nikola Tesla, spring of 1894.

CyLab Research has Powerful Impact on 2010 IEEE Symposium on Security & Privacy

By Richard Power


Thirty-one papers were presented at the thirty-first annual IEEE Symposium on Security and Privacy, held in Oakland, California (5/16/10-5/19/10); of those thirty-one papers, six were authored by CyLab researchers, offering powerful testimony to the relevancy of CyLab's research and its impact on current and future trends in security and privacy in cyberspace.

TrustVisor, Efficient TCB Reduction and Attestation: Jonathan McCune (Carnegie Mellon University), Yanlin Li (Carnegie Mellon University), Ning Qu (Nvidia), Zongwei Zhou (Carnegie Mellon University), Anupam Datta (Carnegie Mellon University), Virgil Gligor (Carnegie Mellon University), Adrian Perrig (Carnegie Mellon University)

"We present TrustVisor, a special-purpose hypervisor that provides code integrity as well as data integrity and secrecy for selected portions of an application."

Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes: Haowen Chan, Adrian Perrig (Carnegie Mellon University)

"The new protocols avoid the high computation overhead of one-time signatures and multi-receiver MACs, as well as the time synchronization needed by TESLA. In terms of rounds of complexity and communication congestion, our protocols provide points in the design space that are not achievable by previously published protocols."

All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but might have been afraid to ask): Thanassis Avgerinos, Edward Schwartz, David Brumley (Carnegie Mellon University)

"The contributions of this paper are two-fold. First, we precisely describe the algorithms for dynamic taint analysis and forward symbolic execution as extensions to the run-time semantics of a general language. Second, we highlight important implementation choices, common pitfalls, and considerations when using these techniques in a security context."

A Proof-Carrying File System: Deepak Garg, Frank Pfenning (Carnegie Mellon University)

"We present the design and implementation of PCFS, a file system that adapts proof-carrying authorization to provide direct, rigorous and efficient enforcement of dynamics access policies."

Scalable Parametric Verification of Secure Systems: How to Verify Reference Monitors without Worrying about Data Structure Size: Jason Franklin (Carnegie Mellon University), Sagar Chaki (Carnegie Mellon University), Anupam Datta (Carnegie Mellon University), Arvind Seshadri (IBM Research)

"This paper develops a parametric verification technique that scales even when reference monitors and adversaries operate over unbounded, but finite data structures. Specifically, we develop a parametric guarded command language for modeling reference monitors and adversaries."

Bootstrapping Trust in Commodity Computers: Bryan Parno, Jonathan M. McCune, Adrian Perrig (Carnegie Mellon University)

"In this survey, we organize and clarify extensive research on bootstrapping trust in commodity systems. We identify inconsistencies (e.g., attacks prevented by various forms of secure and trusted boot) and commonalities (e.g., all existing attempts to capture dynamic system properties still reply in some sense on static, load-time guarantees) in previous work."

In addition to the six papers presented, two CyLab researchers (Jonathan McCune and David Brumley) chaired sessions, and a third, Collin Jackson, led a workshop.