Research Projects
Stories behind my research, organized by the three barriers to observing abuse.
Hidden by Design
Abuse that hides in blind spots created the moment a feature is deployed.
PushAdMiner: Measuring the rise of (malicious) web push advertising
Ad networks turned Web Push Notifications into an ad channel that keeps reaching users after they leave a site. We built a crawler to follow that journey end to end, and found that half of these ads were malicious.
Read more →
Service Worker SoK: Workerounds: categorizing service worker attacks and mitigations
Service workers run in the background of the browser, largely out of the user's view. We systematized the attacks that abuse them, measured how well browsers mitigate them, and built a forensics engine to spot anomalous service worker behavior.
Read more →
ChatterHub: Privacy invasion via smart-home hubs
Smart-home hubs encrypt their traffic, but the timing and shape of that traffic still leak what is happening inside a home. ChatterHub infers device identities and user actions without decrypting anything.
Read more →Obscured by Complexity
Abuse that unfolds across sequences of interaction no single page or vantage point reveals.
PhishInPatterns: Measuring elicited user interactions at scale on phishing websites
Modern phishing sites spread data collection across multi-page flows and gate their payloads behind interactions that stop automated crawlers. We built a smart crawler that plays along, and studied more than 50,000 phishing sites from the user's point of view.
Read more →
C-Frame: Characterizing and measuring in-the-wild CAPTCHA attacks
CAPTCHA-solving farms sell human labor to bypass bot defenses. Rather than studying them one site at a time, C-Frame observes them from inside a solving farm, giving the first cross-organization view of the ecosystem.
Read more →
PP3D: An in-browser, vision-based defense against web behavior manipulation attacks
Scareware and similar attacks manipulate users with what they show on screen. PP3D detects these pages directly in the browser from visual and textual cues, with over 99% detection at a 1% false-positive rate and no data leaving the device.
Read more →Expensive by Convention
Challenging the assumption that measuring or defending against network abuse requires costly infrastructure.
Domain Fronting: Discovering and measuring CDNs prone to domain fronting
Domain fronting lets malware hide its real destination behind a reputable domain on a CDN. We found which CDNs allow it, using passive DNS and targeted crawling instead of paid CDN accounts or global test infrastructure.
Read more →
IXmon: Detecting and measuring in-the-wild DRDoS attacks at Internet exchange points
IXmon detects distributed reflective denial-of-service attacks using the flow statistics networks already collect. Over 21 months at a real Internet exchange, it detected more than 900 attacks against 31 victim networks.
Read more →XNET: Intelligent dynamic sampling for 100 Gbps network security monitoring
Monitoring security-relevant traffic at 100 Gbps usually needs specialized hardware. XNET uses Linux's eXpress Data Path to prioritize the traffic that matters, on commodity machines.
Read more →