Security Publications
│ 2012 │ 2011 │ 2010 │ 2009 │ 2008 │ 2007 │ 2006 │ 2005 │ 2004 │ 2003 │ 2002 │ 
 
     
 

2012

SensorSift: Balancing Sensor Data Privacy and Utility in Automated Face Understanding, Miro Enev, Jaeyeon Jung, Liefeng Bo, Xiaofeng Ren, and Tadayoshi Kohno, Annual Computer Security Applications Conference, December 2012.

Strengthening User Authentication through Opportunistic Cryptographic Identity Assertions, Alexei Czeskis, Michael Dietz, Dan Wallach, Tadayoshi Kohno, and Dirk Balfanz, Proceedings of the 19th ACM Conference on Computer and Communications Security, October 2012.

User Interface Toolkit Mechanisms for Securing Interface Elements, Franziska Roesner, James Fogarty, and Tadayoshi Kohno, 25th ACM Symposium on User Interface Software and Technology (UIST 2012), October 2012.

Security Risks, Low-tech User Interfaces, and Implantable Medical Devices: A Case Study with Insulin Pump Infusion Systems, Nathanael Paul and Tadayoshi Kohno, USENIX Workshop on Health Security and Privacy (HealthSec), August 2012.

Control-Alt-Hack: A Card Game for Computer Security Outreach, Education, and Fun, Tamara Denning, Tadayoshi Kohno, and Adam Shostack, University of Washington Computer Science and Engineering technical report UW-CSE-12-07-01, July 2012.

User-Driven Access Control: Rethinking Permission Granting in Modern Operating Systems, Franziska Roesner, Tadayoshi Kohno, Alex Moshchuk, Bryan Parno, Helen J. Wang, and Crispin Cowan, IEEE Symposium on Security and Privacy, May 2012.

Detecting and Defending Against Third-Party Tracking on the Web, Franziska Roesner, Tadayoshi Kohno, and David Wetherall, Networked Systems Design and Implementation (NSDI), April 2012.

 
     
 

2011

A Review of the Security of Insulin Pump Infusion Systems, Nathanael Paul, Tadayoshi Kohno, and David C. Klonoff, Journal of Diabetes Science and Technology 5(6), November 2011.

Comprehensive Experimental Analyses of Automotive Attack Surfaces, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, and Tadayoshi Kohno, 20th USENIX Security Symposium, August 2011.

New Directions for Self-destructing Data, Roxana Geambasu, Tadayoshi Kohno, Arvind Krishnamurthy, Amit Levy, Henry M. Levy, Paul Gardner, and Vinnie Moscaritolo, University of Washington Computer Science and Engineering technical report UW-CSE-11-08-01, August 2011.

Network Support for Privacy-Preserving Forensic Attribution, Mikhail Afanasyev, Tadayoshi Kohno, Justin Ma, Nick Murphy, Stefan Savage, Alex C. Snoeren, and Geoffrey M. Voelker, Communications of the ACM 54(5):78-87, May 2011.

Keypad: An Auditing File System for Theft-prone Devices, Roxana Geambasu, John P. John, Steven D. Gribble, Tadayoshi Kohno, and Henry M. Levy, European Conference on Computer Systems (EuroSys), April 2011.

Science Fiction Prototyping and Security Education: Cultivating Contextual and Societal Thinking in Computer Security Education and Beyond, Tadayoshi Kohno and Brian David Johnson, ACM Technical Symposium on Computer Science Education (SIGCSE), March 2011.

Sensor Tricorder: What does that sensor know about me?, Gabriel Maganis, Jaeyeon Jung, Tadayoshi Kohno, Anmol Sheth, and David Wetherall, 12th Workshop on Mobile Computing Systems and Application (HotMobile), March 2011.

 
     
 

2010

Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices, Tamara Denning, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno, and William H. Maisel, Proceedings of the 28th international conference on Human factors in computing systems, New York, NY, USA, 2010, pages 917-926.

Boosting the Accuracy of Differentially Private Histograms Through Consistency, Vibhor Rastogi, Michael Hay, Gerome Miklau, and Dan Suciu, VLDB, 2010.

Retaining sandbox containment despite bugs in privileged memory-safe code, Justin Cappos, Armon Dadgar, Jeff Rasley, Justin Samuel, Ivan Beschastnikh, Cosmin Barsan, Arvind Krishnamurthy, and Thomas Anderson, Proceedings of the 17th ACM conference on Computer and communications security, October 2010.

Survivable key compromise in software update systems, Justin Samuel, Nick Mathewson, Justin Cappos, and Roger Dingledine, Proceedings of the 17th ACM conference on Computer and communications security, October 2010.

Comet: An active distributed key-value store, Roxana Geambasu, Amit A. Levy, Tadayoshi Kohno, Arvind Krishnamurthy, and Henry M. Levy, USENIX Symposium on Operating Systems Design and Implementation (OSDI), October 2010.

The Limits of Automatic OS Fingerprint Generation, David W. Richardson, Steven D. Gribble, and Tadayoshi Kohno, Workshop on Artificial Intelligence and Security (AISec), October 2010.

Seeing through Obscure Glass, Qi Shan, Brian Curless, and Tadayoshi Kohno, European Conference on Computer Vision (ECCV), September 2010.

Parenting from the Pocket: Value Tensions and Technical Directions for Secure and Private Parent-Teen Mobile Safety, Alexei Czeskis, Ivayla Dermendjieva, Hussein Yapit, Alan Borning, Batya Friedman, Brian Gill, and Tadayoshi Kohno, Symposium On Usable Privacy and Security (SOUPS), July 2010.

Experimental Security Analysis of a Modern Automobile, Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, and Stefan Savage, IEEE Symposium on Security and Privacy, May 2010.

Patients, Pacemakers, and Implantable Defibrillators: Human Values and Security for Wireless Implantable Medical Devices, Tamara Denning, Alan Borning, Batya Friedman, Brian T. Gill, Tadayoshi Kohno, and William H. Maisel, Proceedings of the ACM Conference on Human Factors in Computing Systems (CHI 2010), April 2010.

Improving the Security and Privacy of Implantable Medical Devices, William H. Maisel and Tadayoshi Kohno, New England Journal of Medicine 362(13):1164-1166, April 2010.

Cryptography Engineering: Design Principles and Practical Applications, Niels Ferguson, Bruce Schneier, and Tadayoshi Kohno, Wiley Publishing, Inc., March 2010.

 
     
 

2009

Are Patched Machines Really Fixed?, Ryan W. Gardner, Matt Bishop, and Tadayoshi Kohno, IEEE Security and Privacy 7(5), 2009.

Relationship privacy: output perturbation for queries with joins, Vibhor Rastogi, Michael Hay, Gerome Miklau, and Dan Suciu, PODS, 2009.

EPC RFID Tags in Security Applications: Passport Cards, Enhanced Drivers Licenses, and Beyond, Karl Koscher, Ari Juels, Vjekoslav Brajkovic, and Tadayoshi Kohno, Proceedings of the 16th ACM Conference on Computer and Communications Security, November 2009.

Clinically Significant Magnetic Interference of Implanted Cardiac Devices by Portable Headphones, Sinjin Lee, Kevin Fu, Tadayoshi Kohno, Benjamin Ransford, and William H. Maisel, Heart Rhythm Journal 6(10), October 2009.

A Spotlight on Security and Privacy Risks with Future Household Robots: Attacks and Lessons, Tamara Denning, Cynthia Matuszek, Karl Koscher, Joshua R. Smith, and Tadayoshi Kohno, 11th International Conference on Ubiquitous Computing (Ubicomp), October 2009.

Vanish: Increasing Data Privacy with Self-Destructing Data, Roxana Geambasu, Tadayoshi Kohno, Amit A. Levy, and Henry M. Levy, 18th USENIX Security Symposium, August 2009.

Enlisting ISPs to Improve Online Privacy: IP Address Mixing by Default, Barath Raghavan, Tadayoshi Kohno, Alex C. Snoeren, and David Wetherall, Privacy Enhancing Technologies Symposium, August 2009.

Neurosecurity: Security and privacy for neural devices, Tamara Denning, Yoky Matsuoka, and Tadayoshi Kohno, Neurosurgical Focus 27, July 2009.

Provable Security Support for the Skein Hash Family, Mihir Bellare, Tadayoshi Kohno, Stefan Lucks, Niels Ferguson, Bruce Schneier, Doug Whiting, Jon Callas, and Jesse Walker, Associated Documentation to the NIST Cryptographic Hash Algorithm Competition, April 2009.

A Comprehensive Study of Frequency, Interference, and Training of Multiple Graphical Passwords, Katherine M. Everitt, Tanya Bragin, James Fogarty, and Tadayoshi Kohno, Proceedings of the ACM Conference on Human Factors in Computing Systems (CHI 2009), April 2009.

The International Criminal Tribunal for Rwanda Information Heritage Project (aka Voices of the Rwanda Tribunal): Integrity Verification Architecture, Alexei Czeskis, Karl Koscher, Max Andrews, Nell Carden Grey, Batya Friedman, and Tadayoshi Kohno, University of Washington Computer Science and Engineering technical report 09-01-02, March 2009.

 
     
 

2008

Access Control over Uncertain Data, Vibhor Rastogi, Dan Suciu, and Evan Welbourne, VLDB, 2008.

A look in the mirror: attacks on package managers, Justin Cappos, Justin Samuel, Scott Baker, and John H. Hartman, Proceedings of the 15th ACM conference on Computer and communications security, October 2008.

Privacy Oracle: A System for Finding Application Leaks with Black Box Differential Testing, Jaeyeon Jung, Anmol Sheth, Ben Greenstein, David Wetherall, Gabriel Maganis, and Tadayoshi Kohno, Proceedings of the 15th ACM Conference on Computer and Communications Security, October 2008.

RFIDs and Secret Handshakes: Defending Against Ghost-and-Leech Attacks and Unauthorized Reads with Context-Aware Communications, Alexei Czeskis, Karl Koscher, Joshua R. Smith, and Tadayoshi Kohno, Proceedings of the 15th ACM Conference on Computer and Communications Security, October 2008.

Electromagnetic Interference (EMI) of Implanted Cardiac Devices by MP3 Player Headphones, Sinjin Lee, Benjamin Ransford, Kevin Fu, Tadayoshi Kohno, and William H. Maisel, Circulation 118(18 Supplement), October 2008.

The Skein Hash Function Family, Niels Ferguson, Stefan Lucks, Bruce Schneier, Doug Whiting, Mihir Bellare, Tadayoshi Kohno, Jon Callas, and Jesse Walker, Submission to the NIST Cryptographic Hash Algorithm Competition, October 2008.

Challenges and Directions for Monitoring P2P File Sharing Networks -- or -- Why My Printer Received a DMCA Takedown Notice, Michael Piatek, Tadayoshi Kohno, and Arvind Krishnamurthy, 3rd USENIX Workshop on Hot Topics in Security (HotSec '08), July 2008.

Defeating Encrypted and Deniable File Systems: TrueCrypt v5.1a and the Case of the Tattling OS and Applications, Alexei Czeskis, David J. St.Hilaire, Karl Koscher, Steven D. Gribble, Tadayoshi Kohno, and Bruce Schneier, 3rd USENIX Workshop on Hot Topics in Security (HotSec '08), July 2008.

Absence Makes the Heart Grow Fonder: New Directions for Implantable Medical Device Security, Tamara Denning, Kevin Fu, and Tadayoshi Kohno, 3rd USENIX Workshop on Hot Topics in Security (HotSec '08), July 2008.

Shining Light in Dark Places: Understanding the Tor Network, Damon McCoy, Kevin Bauer, Dirk Grunwald, Tadayoshi Kohno, and Douglas Sicker, Privacy Enhancing Technologies Symposium, July 2008.

Privacy-Preserving Location Tracking of Lost or Stolen Devices: Cryptographic Techniques and Replacing Trusted Third Parties with DHTs, Thomas Ristenpart, Gabriel Maganis, Arvind Krishnamurthy, and Tadayoshi Kohno, 17th USENIX Security Symposium, July 2008.

Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions, Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange, John Malone-Lee, Gregory Neven, Pascal Paillier, and Haixia Shi, Journal of Cryptology 21(3):350-391, July 2008.

Improving Wireless Privacy with an Identifier-Free Link Layer Protocol, Ben Greenstein, Damon McCoy, Jeffrey Pang, Tadayoshi Kohno, Srinivasan Seshan, and David Wetherall, International Conference on Mobile Systems, Application, and Services (MobiSys), June 2008.

Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power Defenses, Daniel Halperin, Thomas S. Heydt-Benjamin, Benjamin Ransford, Shane S. Clark, Benessa Defend, Will Morgan, Kevin Fu, Tadayoshi Kohno, and William H. Maisel, IEEE Symposium on Security and Privacy, May 2008.

Detecting In-Flight Page Changes with Web Tripwires, Charles Reis, Steven D. Gribble, Tadayoshi Kohno, and Nicholas C. Weaver, USENIX Symposium on Networked Systems Design amp; Implementation, April 2008.

Security and Privacy for Implantable Medical Devices, Daniel Halperin, Thomas S. Heydt-Benjamin, Kevin Fu, Tadayoshi Kohno, and William H. Maisel, IEEE Pervasive Computing 7(1), January 2008.

 
     
 

2007

The Boundary Between Privacy and Utility in Data Publishing, Vibhor Rastogi, Dan Suciu, and Sungho Hong, VLDB, 2007.

Stork: package management for distributed VM environments, Justin Cappos, Scott Baker, Jeremy Plichta, Duy Nyugen, Jason Hardies, Matt Borgard, Jeffry Johnston, and John H. Hartman, Proceedings of the 21st conference on Large Installation System Administration Conference, 2007.

Physical Access Control for Captured RFID Data, Travis Kriplean, Evan Welbourne, Nodira Khoussainova, Vibhor Rastogi, Magda Balazinska, Gaetano Borriello, Tadayoshi Kohno, and Dan Suciu, IEEE Pervasive Computing 6(4), October 2007.

Low-Resource Routing Attacks Against Tor, Kevin Bauer, Damon McCoy, Dirk Grunwald, Tadayoshi Kohno, and Douglas Sicker, Workshop on Privacy in the Electronic Society, October 2007.

Protecting Security and Privacy, Tadayoshi Kohno, MIT Technology Review, September 2007.

Expressing Privacy Policies Using Authorization Views, Vibhor Rastogi, Evan Welbourne, Nodira Khoussainova, Travis Kriplean, Magda Balazinska, Gaetano Borriello, Tadayoshi Kohno, and Dan Suciu, Workshop on UbiComp Privacy: Technologies, Users, Policy, September 2007.

Devices That Tell On You: Privacy Trends in Consumer Ubiquitous Computing, T. Scott Saponas, Jonathan Lester, Carl Hartung, Sameer Agarwal, and Tadayoshi Kohno, 16th USENIX Security Symposium, August 2007.

Software Review and Security Analysis of the Diebold Voting Machine Software, Ryan Gardner, Alec Yasinsac, Matt Bishop, Tadayoshi Kohno, Zachary Hartley, John Kerski, David Gainey, Ryan Walega, Evan Hollander, and Michael Gerke, Report commissioned by the Florida Department of State, July 2007.

Can Ferris Bueller Still Have His Day Off? Protecting Privacy in the Wireless Era, Ben Greenstein, Ramakrishna Gummadi, Jeffrey Pang, Mike Y. Chen, Tadayoshi Kohno, Srinivasan Seshan, and David Wetherall, 11th Workshop on Hot Topics in Operating Systems, May 2007.

 
     
 

2006

Stateful public-key cryptosystems: How to encrypt with one 160-bit exponentiation, Mihir Bellare, Tadayoshi Kohno, and Victor Shoup, Proceedings of the 13th ACM Conference on Computer and Communications Security, November 2006.

Safe Manual Memory Management in Cyclone, Nikhil Swamy, Michael Hicks, Greg Morrisett, Dan Grossman, and Trevor Jim, Science of Computer Programming, Special Issue: Five perspectives on modern memory management -- Systems, hardware and theory 62(2), October 2006.

Designing voting machines for verification, Naveen Sastry, Tadayoshi Kohno, and David Wagner, 15th USENIX Security Symposium, August 2006.

Quantified Types in Imperative Languages, Dan Grossman, ACM Transactions on Programming Languages and Systems 28(3), May 2006.

Herding hash functions and the Nostradamus attack, John Kelsey and Tadayoshi Kohno, Advances in Cryptology -- EUROCRYPT, May 2006.

Tamper-evident, history-independent, subliminal-free data structures on PROM storage -or- how to store ballots on a voting machine (extended abstract), David Molnar, Tadayoshi Kohno, Naveen Sastry, and David Wagner, IEEE Symposium on Security and Privacy, May 2006.

Key regression: Enabling efficient key distribution for secure distributed storage, Kevin Fu, Seny Kamara, and Tadayoshi Kohno, ISOC Network and Distributed System Security Symposium, February 2006.

SSH transport layer encryption modes, Mihir Bellare, Tadayoshi Kohno, and Chanathip Namprempre, IETF RFC 4344, January 2006.

 
     
 

2005

Proper: privileged operations in a virtualised system environment, Steve Muir, Larry Peterson, Marc Fiuczynski, Justin Cappos, and John Hartman, Proceedings of the annual conference on USENIX Annual Technical Conference, 2005.

Preventing Format-String Attacks via Automatic and Efficient Dynamic Checking, Michael F. Ringenburg and Dan Grossman, ACM Conference on Computer and Communications Security, November 2005.

Searchable Encryption Revisited: Consistency Properties, Relation to Anonymous IBE, and Extensions, Michel Abdalla, Mihir Bellare, Dario Catalano, Eike Kiltz, Tadayoshi Kohno, Tanja Lange, John Malone-Lee, Gregory Neven, Pascal Paillier, and Haixia Shi, Advances in Cryptology -- CRYPTO, August 2005, pages 205-222.

Remote physical device fingerprinting, Tadayoshi Kohno, Andre Broido, and kc~claffy, IEEE Symposium on Security and Privacy, May 2005, pages 211-225.

Remote physical device fingerprinting, Tadayoshi Kohno, Andre Broido, and K.C. Claffy, IEEE Transactions on Dependable and Secure Computing 2(2):93-108, April 2005.

Cyclone: a Type-safe Dialect of C, Dan Grossman, Michael Hicks, Greg Morrisett, and Trevor Jim, C/C++ Users Journal 23(1), January 2005.

 
     
 

2004

Experience With Safe Manual Memory-Management in Cyclone, Michael Hicks, Greg Morrisett, Dan Grossman, and Trevor Jim, International Symposium on Memory Management, October 2004.

Attacking and repairing the WinZip encryption scheme, Tadayoshi Kohno, Proceedings of the 11th ACM Conference on Computer and Communications Security, October 2004, pages 72-81.

Analysis of an electronic voting system, Tadayoshi Kohno, Adam Stubblefield, Aviel D. Rubin, and Dan S. Wallach, IEEE Symposium on Security and Privacy, May 2004.

Hash function balance and its impact on birthday attacks, Mihir Bellare and Tadayoshi Kohno, Advances in Cryptology -- EUROCRYPT, May 2004, pages 401-418.

Breaking and provably repairing the SSH authenticated encryption scheme: A case study of the Encode-then-Encrypt-and-MAC paradigm, Mihir Bellare, Tadayoshi Kohno, and Chanathip Namprempre, ACM Transactions on Information and System Security 7(2):206-241, May 2004.

New security proofs for the 3GPP confidentiality and integrity algorithms, Tetsu Iwata and Tadayoshi Kohno, Fast Software Encryption, February 2004, pages 427-445.

CWC: A high-performance conventional authenticated encryption mode, Tadayoshi Kohno, John Viega, and Doug Whiting, Fast Software Encryption, February 2004, pages 408-426.

 
     
 

2003

A theoretical treatment of related-key attacks: RKA-PRPs, RKA-PRFs, and applications, Mihir Bellare and Tadayoshi Kohno, Advances in Cryptology -- EUROCRYPT, May 2003, pages 491-506.

Analysis of RMAC, Lars R. Knudsen and Tadayoshi Kohno, Fast Software Encryption, February 2003, pages 182-191.

Helix: Fast encryption and authentication in a single cryptographic primitive, Niels Ferguson, Doug Whiting, Bruce Schneier, John Kelsey, Stefan Lucks, and Tadayoshi Kohno, Fast Software Encryption, February 2003, pages 330-346.

Type-Safe Multithreading in Cyclone, Dan Grossman, ACM Workshop on Types in Language Design and Implementation, January 2003.

 
     
 

2002

Authenticated Encryption in SSH: Provably Fixing the SSH Binary Packet Protocol, Mihir Bellare, Tadayoshi Kohno, and Chanathip Namprempre, Proceedings of the 9th ACM Conference on Computer and Communications Security, November 2002.

Token-Based Scanning for Source Code Security Problems, John Viega, J. T. Bloch, Tadayoshi Kohno, and Gary McGraw, ACM Transactions on Information and System Security 5(3):238-261, August 2002.

Region-Based Memory Management in Cyclone, Dan Grossman, Greg Morrisett, Trevor Jim, Michael Hicks, Yanling Wang, and James Cheney, ACM Conference on Programming Language Design and Implementation, June 2002.

Cyclone: A Safe Dialect of C, Trevor Jim, Greg Morrisett, Dan Grossman, Michael Hicks, James Cheney, and Yanling Wang, USENIX Annual Technical Conference, Monterey, CA, June 2002.

Existential Types for Imperative Languages, Dan Grossman, 11th European Symposium on Programming, April 2002.