Anonymized Traffic
-
Scott Coulls, Charles Wright,
Angelos Keromytis, Fabian Monrose, and Michael Reiter.
Taming the Devil: Techniques of Evaluating Anonymized Network Data. In Proceedings of the 15th Annual Network and Distributed Systems Security Symposium, Feb, 2008.
-
Scott Coulls, Charles Wright, Fabian Monrose, Michael Collins and Michael Reiter.
On Web Browsing Privacy in Anonymized NetFlows. In Proceedings of the 16th USENIX Security Symposium, Boston, August, 2007. (PDF)
-
Scott Coulls, Charles Wright, Fabian Monrose, Michael Collins and Michael Reiter.
Playing Devil's Advocate: Inferring Sensitive Information from
Anonymized Traces. In Proceedings of the 14th Annual Network and
Distributed Systems Symposium (NDSS), pages 35-47, Feb, 2007.
Network Security
Current interests
include analysis of Internet-scale threats, primarily botnets. We've understaken a
number of studies to assess the prevalence of malware and various delivery mechanisms (drive-by downloads). We have
also examined the effectiveness of network telescopes for a
variety of tasks, particularly to better understand their capabilities
and limits with respect to malware detection and containment. Below
are some papers on these subjects. More to come soon ...
Malware studies:
-
Sam Small, Josh Mason, Fabian Monrose, Niels Provos and Adam Stubblefield. To Catch A Predator: A Natural Language Approach for Eliciting Protocol Interaction.
To appear in Proceedings of the 17th USENIX Security Symposium, July, 2008.
-
Niels Provos, Panayiotis Mavrommatis, Moheeb Rajab, and Fabian Monrose. All Your iFrames Point to Us.
To appear in the Proceedings of the 17th USENIX Security Symposium, July, 2008.
-
Moheeb Rajab, Jay Zarfoss, Fabian Monrose and Andreas Terzis. A Multifaceted Approach to Understanding the Botnet Phenomenon.
In proceedings of ACM SIGCOMM/USENIX Internet Measurement Conference, October, Brazil, 2006. (PDF)
More information on the architecture we used in the IMC paper is provided in Jay Zarfoss' Masters thesis on A Scalable Architecture for Persistent Botnet Tracking, Jan. 26, 2007.
-
Moheeb Rajab, Jay Zarfoss, Fabian Monrose and Andreas Terzis. My Botnet is Bigger than Yours (Maybe, Better than Yours).
In proceedings of the First USENIX Workshop on Hot Topics in Understanding Botnets, April, Boston, 2007. (PDF)
Modeling:
-
Moheeb Rajab, Fabian Monrose, Andreas Terzis and Niels Provos. Peeking Through the Cloud: DNS-based Estimation and its Applications
In proceedings the 6th Conference on Applied Cryptography and Network Security (ACNS), 2008.
-
Moheeb Rajab, Fabian Monrose and Andreas Terzis. Fast and Evasive Attacks: Highlighting the Challenges Ahead.
In proceedings of the 9th International Symposium on Recent Advances in Intrusion Detection (RAID), Sept, Germany, 2006. (PDF)
-
Moheeb Rajab, Fabian Monrose and Andreas Terzis. On the Impact of Dynamic Addressing on Malware Propagation. In Proceedings of the ACM Workshop on Recurring Malware (WORM), Washington D.C., November, 2006.(PDF)
-
Moheeb Rajab, Fabian Monrose and Andreas Terzis. On the effectiveness of Distributed Worm Monitoring.
In Proceedings of the 14th USENIX Security Symposium, pages 225-237, Baltimore, August, 2005. (PDF)
-
Moheeb Rajab, Fabian Monrose and Andreas Terzis. Worm Evolution Tracking via Timing Analysis. In ACM Workshop on Recurring Malware (WORM), pages 52-59, Washington D.C., November, 2005. (PDF)
-
Sophie Qiu, Patrick McDaniel, and Fabian Monrose. Toward
Valley-Free Inter-domain Routing. In Proceedings of the IEEE Conference on Communications, June, Scottland, 2007.
-
Sophie Qui, Fabian Monrose, Andreas Terzis, and Patrick McDaniel. Efficient Techniques for Detecting False Origin Advertisements in Inter-domain Routing. In Proceedings of the Second Workshop on Secure Network Protocols (NPSec), November 2006. (PDF)
-
Sophie Qiu, Patrick McDaniel, Fabian Monrose, and Aviel D. Rubin, Characterizing Address Use Structure and Stabillity of Origin Advertizement in Interdomain Routing. In Proceedings of IEEE Symposium on Computers and Communications (ISCC), pages 489-496, June, Italy, 2006.
(Supercedes the earlier techreport PDF)
-
Bharat Doshi, Antonio De Simone, Sam Small, Fabian Monrose and Andreas Terzis. Large-scale Dynamic Virtual Private Networks for the Global Information Grid. In Proceedings of IEEE Milcom, Atlantic City, October, 2005.
-
S. Kamara, D. Davis, L. Ballard, R. Caudy and F. Monrose. An Extensible Platform for Evaluating Security Protocols. In Proceedings of the 38th IEEE Annual Simulation Symposium (ANSS), pages 204-213, San Deigo, 2005. (PDF). SIMNET is maintained here.
Evaluation techniques for Biometric Key Generators
Revisiting the current practices in reporting biometric performance. Here, we show the impact of incorporating stronger adversarial assumptions when performing such evaluations. Come back here for some more updates soon...
-
Lucas Ballard, Fabian Monrose and Daniel Lopresti. Biometric Authentication Revisited: Understanding the
Impact of Wolves in Sheep's Clothing. In proceedings of the 15th USENIX Security Symposium,
Vancouver, Aug. 2006.(PDF)
-
Lucas Ballard, Daniel Lopresti and F. Monrose. Evaluating the Security of Handwriting Biometrics.
In proceedings of the 10th International Workshop on Frontiers in Handwriting Recognition (IWFHR06),
France, October, 2006.(PDF)
-
Daniel Lopresti, Lucas Ballard and F. Monrose. Evaluating Biometric Security (Invited Paper). In proceedings of First Korean-Japan Workshop on Pattern Recognition, Nov, 2006.
-
Lucas Ballard, Daniel Lopresti and Fabian Monrose. Forgery Quality and its Implications for Behavioral Biometric Security. In IEEE Transactions on Systems, Man, and Cybernetics (Special Edition), Volume 37, no. 5, October, 2007.
(PDF)
-
Lucas Ballard, Seny Kamara and M.K. Reiter. The Practical Subtleties of Biometric Key Generation. To Appear in Proceedings of the 17th Annual USENIX Security Symposium, 2008. This paper supercedes our earlier tech report and is part of Lucas' thesis, Robust Techniques for Evaluating Biometric Cryptographic Key Generators, March, 2008.
Graphical Passwords
We evaluated
a new graphical password scheme that exploits features of graphical
input devices such as PDAs to provide better security than
textual-based alternatives. Graphical passwords serve the same
purpose as textual passwords, with the added benefit that pictures
(e.g., line drawings) may be used in conjunction with words. A primary
motivation for using pictures as opposed to words stems from our
(well, at least some people's) remarkable ability to recall
pictures. This paper won both the best student and best overal paper
awards at the 8th USENIX Security conference.
-
Ian Jermyn, Alain Mayer, Fabian Monrose,
Michael K. Reiter, and
Aviel D. Rubin.  The
Design and Analysis of Graphical Passwords. In Proceedings of the
8th USENIX Security Symposium, August, Washington DC, 1999.
(PDF)
Some additional work on the relationship between user choice and
its implication for the available
entropy in Graphical Passwords schemes appears here:
-
Darren Davis, Fabian Monrose, and
Michael K. Reiter. On user choice in
Graphical Password Schemes. In Proceedings of the
13th USENIX Security Symposium, August, San Diego, 2004. (PDF)
Password
Hardening using Keystroke Dynamics
This project dates
way back (to when I was still a graduate student), and though I still
get regular email inquires about it, I am no longer continuing this
work (as the voice project outlined earlier continues where this left
off). In our work on keystroke dynamics, we examined a new approach to
strengthening the security of user chosen passwords. Our techniques
made use of habitual patterns in a user's typing rhythm (as she types
her password) for generating strong cryptographic keys that could be
used, for example, for file encryption, VPN access, etc. See:
-
Fabian Monrose and Aviel D. Rubin.  Authentication
via Keystroke Dynamics. In Proceedings of the Fourth ACM
Conference on Computer and Communication Security, Zurich,
Switzerland, April, 1997. (PDF).
-
Fabian Monrose, Michael K. Reiter, and Suzanne
Wetzel. Password Hardening based on Keystroke Dynamics. In
the International Journal of Information Security (PDF), 2001. A preliminary version
appears in the Proceedings of the 6th ACM Computer and
Communications Security Conference, Singapore, November, 1999. (PDF)
-
Fabian Monrose and Aviel D. Rubin. 
Keystroke Dynamics as a Biometric for Authentication. Future
Generation Computing Systems (FGCS) Journal: Security on the Web
(special issue). March 2000. (PDF).
Applied Crypto
- Darren Davis, Fabian Monrose and Mike Reiter. 
Time Scoped Searching of Encrypted Audit Logs. In Proceedings of the
6th International Conference on Information and Communications Security (ICICS), pages 532-545, October, 2004. (PDF)
. The ICICS paper is very dense (given page limitations), so interested readers are referred to Darren's Master's thesis for more information: SEALED: Searching Encrypted Audit Logs Expeditiously, May, 2004.