The Experts below are selected from a list of 102 Experts worldwide ranked by ideXlab platform

Angelos D. Keromytis - One of the best experts on this subject based on the ideXlab platform.

  • Detection and analysis of eavesdropping in anonymous communication networks
    International Journal of Information Security, 2015
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks, like Tor, partially protect the confidentiality of user Traffic by encrypting all communications within the overlay network. However, when the relayed Traffic reaches the boundaries of the network, toward its destination, the original user Traffic is inevitably exposed to the final node on the path. As a result, users transmitting sensitive data, like authentication credentials, over such networks, risk having their data intercepted and exposed, unless end-to-end encryption is used. Eavesdropping can be performed by malicious or compromised relay nodes, as well as any rogue network entity on the path toward the actual destination. Furthermore, end-to-end encryption does not assure defense against man-in-the-middle attacks. In this work, we explore the use of decoys at multiple levels for the detection of Traffic Interception by malicious nodes of proxy-based anonymous communication systems. Our approach relies on the injection of Traffic that exposes bait credentials for decoy services requiring user authentication, and URLs to seemingly sensitive decoy documents which, when opened, invoke scripts alerting about being accessed. Our aim was to entice prospective eavesdroppers to access our decoy servers and decoy documents, using the snooped credentials and URLs. We have deployed our prototype implementation in the Tor network using decoy IMAP, SMTP, and HTTP servers. During the course of over 30 months, our system has detected 18 cases of Traffic eavesdropping that involved 14 different Tor exit nodes.

  • RAID - Detecting Traffic snooping in tor using decoys
    Lecture Notes in Computer Science, 2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users' Traffic by encrypting all intra-overlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-to-end encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of ten months, our system detected ten cases of Traffic Interception that involved ten different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

  • Detecting Traffic Snooping in Anonymity Networks Using Decoys
    2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users’ Traffic by encrypting all intraoverlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-toend encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of six months, our system detected eight cases of Traffic Interception that involved eight different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

  • A Look at VoIP Vulnerabilities
    Log in, 2010
    Co-Authors: Angelos D. Keromytis
    Abstract:

    Voice over IP (VOIP) and Internet Multimedia Subsystem (IMS) technologies offer higher flexibility than traditional telephony infrastructures and the potential for lower cost through equipment consolidation and new business models. In this article, I examined the current state of affairs on VOIP/IMS security through a survey of all the 221 kown/disclosed security vulnerabilities in the Common vulnerabilities and Exposure (CVE) database and in IETF RFCs/drafts. My key finding is than the higher complexity of VOIP/IMSsystems leads to a variety of attcks vectors, many of them caused by unforeseen and unexpected components interactions. A second finding is that what people seem to worry about in VOIP (Traffic Interception and impresionation) bears no resemblance to the distribution of vulnerabilities actually disclosed. The article concludes with some practical suggestions for securing VOIP systems.

Sambuddho Chakravarty - One of the best experts on this subject based on the ideXlab platform.

  • Detection and analysis of eavesdropping in anonymous communication networks
    International Journal of Information Security, 2015
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks, like Tor, partially protect the confidentiality of user Traffic by encrypting all communications within the overlay network. However, when the relayed Traffic reaches the boundaries of the network, toward its destination, the original user Traffic is inevitably exposed to the final node on the path. As a result, users transmitting sensitive data, like authentication credentials, over such networks, risk having their data intercepted and exposed, unless end-to-end encryption is used. Eavesdropping can be performed by malicious or compromised relay nodes, as well as any rogue network entity on the path toward the actual destination. Furthermore, end-to-end encryption does not assure defense against man-in-the-middle attacks. In this work, we explore the use of decoys at multiple levels for the detection of Traffic Interception by malicious nodes of proxy-based anonymous communication systems. Our approach relies on the injection of Traffic that exposes bait credentials for decoy services requiring user authentication, and URLs to seemingly sensitive decoy documents which, when opened, invoke scripts alerting about being accessed. Our aim was to entice prospective eavesdroppers to access our decoy servers and decoy documents, using the snooped credentials and URLs. We have deployed our prototype implementation in the Tor network using decoy IMAP, SMTP, and HTTP servers. During the course of over 30 months, our system has detected 18 cases of Traffic eavesdropping that involved 14 different Tor exit nodes.

  • RAID - Detecting Traffic snooping in tor using decoys
    Lecture Notes in Computer Science, 2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users' Traffic by encrypting all intra-overlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-to-end encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of ten months, our system detected ten cases of Traffic Interception that involved ten different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

  • Detecting Traffic Snooping in Anonymity Networks Using Decoys
    2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users’ Traffic by encrypting all intraoverlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-toend encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of six months, our system detected eight cases of Traffic Interception that involved eight different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

Paul Barford - One of the best experts on this subject based on the ideXlab platform.

  • A Residential Client-side Perspective on SSL Certificates
    2019 Network Traffic Measurement and Analysis Conference (TMA), 2019
    Co-Authors: Edward Oakes, Jeffery Kline, Aaron Cahn, Keith Funkhouser, Paul Barford
    Abstract:

    SSL certificates are a core component of the public key infrastructure that underpins encrypted communication in the Internet. In this paper, we report the results of a longitudinal study of the characteristics of SSL certificate chains presented to clients during secure web (HTTPS) connection setup. Our data set consists of 23B SSL certificate chains collected from a global panel consisting of over 2M residential client machines over a period of 6 months. The data informing our analyses provide perspective on the entire chain of trust, including root certificates, across a wide distribution of client machines. We identify over 35M unique certificate chains with diverse relationships at all levels of the PKI hierarchy. We report on the characteristics of valid certificates, which make up 99.7% of the total corpus. We also examine invalid certificate chains, finding that 93% of them contain an untrusted root certificate and we find they have shorter average chain length than their valid counterparts. Finally, we examine two unintended but prevalent behaviors in our data: the deprecation of root certificates and secure Traffic Interception. Our results support aspects of prior, scan-based studies on certificate characteristics but contradict other findings, highlighting the importance of the residential client-side perspective.

  • TMA - A Residential Client-side Perspective on SSL Certificates
    2019 Network Traffic Measurement and Analysis Conference (TMA), 2019
    Co-Authors: Edward Oakes, Jeffery Kline, Aaron Cahn, Keith Funkhouser, Paul Barford
    Abstract:

    SSL certificates are a core component of the public key infrastructure that underpins encrypted communication in the Internet. In this paper, we report the results of a longitudinal study of the characteristics of SSL certificate chains presented to clients during secure web (HTTPS) connection setup. Our data set consists of 23B SSL certificate chains collected from a global panel consisting of over 2M residential client machines over a period of 6 months. The data informing our analyses provide perspective on the entire chain of trust, including root certificates, across a wide distribution of client machines. We identify over 35M unique certificate chains with diverse relationships at all levels of the PKI hierarchy. We report on the characteristics of valid certificates, which make up 99.7% of the total corpus. We also examine invalid certificate chains, finding that 93% of them contain an untrusted root certificate and we find they have shorter average chain length than their valid counterparts. Finally, we examine two unintended but prevalent behaviors in our data: the deprecation of root certificates and secure Traffic Interception. Our results support aspects of prior, scan-based studies on certificate characteristics but contradict other findings, highlighting the importance of the residential client-side perspective.

Michalis Polychronakis - One of the best experts on this subject based on the ideXlab platform.

  • Detection and analysis of eavesdropping in anonymous communication networks
    International Journal of Information Security, 2015
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks, like Tor, partially protect the confidentiality of user Traffic by encrypting all communications within the overlay network. However, when the relayed Traffic reaches the boundaries of the network, toward its destination, the original user Traffic is inevitably exposed to the final node on the path. As a result, users transmitting sensitive data, like authentication credentials, over such networks, risk having their data intercepted and exposed, unless end-to-end encryption is used. Eavesdropping can be performed by malicious or compromised relay nodes, as well as any rogue network entity on the path toward the actual destination. Furthermore, end-to-end encryption does not assure defense against man-in-the-middle attacks. In this work, we explore the use of decoys at multiple levels for the detection of Traffic Interception by malicious nodes of proxy-based anonymous communication systems. Our approach relies on the injection of Traffic that exposes bait credentials for decoy services requiring user authentication, and URLs to seemingly sensitive decoy documents which, when opened, invoke scripts alerting about being accessed. Our aim was to entice prospective eavesdroppers to access our decoy servers and decoy documents, using the snooped credentials and URLs. We have deployed our prototype implementation in the Tor network using decoy IMAP, SMTP, and HTTP servers. During the course of over 30 months, our system has detected 18 cases of Traffic eavesdropping that involved 14 different Tor exit nodes.

  • RAID - Detecting Traffic snooping in tor using decoys
    Lecture Notes in Computer Science, 2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users' Traffic by encrypting all intra-overlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-to-end encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of ten months, our system detected ten cases of Traffic Interception that involved ten different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

  • Detecting Traffic Snooping in Anonymity Networks Using Decoys
    2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users’ Traffic by encrypting all intraoverlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-toend encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of six months, our system detected eight cases of Traffic Interception that involved eight different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

Georgios Portokalidis - One of the best experts on this subject based on the ideXlab platform.

  • Detection and analysis of eavesdropping in anonymous communication networks
    International Journal of Information Security, 2015
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks, like Tor, partially protect the confidentiality of user Traffic by encrypting all communications within the overlay network. However, when the relayed Traffic reaches the boundaries of the network, toward its destination, the original user Traffic is inevitably exposed to the final node on the path. As a result, users transmitting sensitive data, like authentication credentials, over such networks, risk having their data intercepted and exposed, unless end-to-end encryption is used. Eavesdropping can be performed by malicious or compromised relay nodes, as well as any rogue network entity on the path toward the actual destination. Furthermore, end-to-end encryption does not assure defense against man-in-the-middle attacks. In this work, we explore the use of decoys at multiple levels for the detection of Traffic Interception by malicious nodes of proxy-based anonymous communication systems. Our approach relies on the injection of Traffic that exposes bait credentials for decoy services requiring user authentication, and URLs to seemingly sensitive decoy documents which, when opened, invoke scripts alerting about being accessed. Our aim was to entice prospective eavesdroppers to access our decoy servers and decoy documents, using the snooped credentials and URLs. We have deployed our prototype implementation in the Tor network using decoy IMAP, SMTP, and HTTP servers. During the course of over 30 months, our system has detected 18 cases of Traffic eavesdropping that involved 14 different Tor exit nodes.

  • RAID - Detecting Traffic snooping in tor using decoys
    Lecture Notes in Computer Science, 2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users' Traffic by encrypting all intra-overlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-to-end encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of ten months, our system detected ten cases of Traffic Interception that involved ten different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.

  • Detecting Traffic Snooping in Anonymity Networks Using Decoys
    2011
    Co-Authors: Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis
    Abstract:

    Anonymous communication networks like Tor partially protect the confidentiality of their users’ Traffic by encrypting all intraoverlay communication. However, when the relayed Traffic reaches the boundaries of the overlay network towards its actual destination, the original user Traffic is inevitably exposed. At this point, unless end-toend encryption is used, sensitive user data can be snooped by a malicious or compromised exit node, or by any other rogue network entity on the path towards the actual destination. We explore the use of decoy Traffic for the detection of Traffic Interception on anonymous proxying systems. Our approach is based on the injection of Traffic that exposes bait credentials for decoy services that require user authentication. Our aim is to entice prospective eavesdroppers to access decoy accounts on servers under our control using the intercepted credentials. We have deployed our prototype implementation in the Tor network using decoy IMAP and SMTP servers. During the course of six months, our system detected eight cases of Traffic Interception that involved eight different Tor exit nodes. We provide a detailed analysis of the detected incidents, discuss potential improvements to our system, and outline how our approach can be extended for the detection of HTTP session hijacking attacks.