ACM Home Page
      Please provide us with feedback. Feedback
 
Conference on Computer and Communications Security archive
Proceedings of the 14th ACM conference on Computer and communications security
2007,  Alexandria, Virginia, USA    October 28 - 31, 2007
Additional Information:full citation, abstract
Paper Acceptance Rate:55.00 of 302.00 submissions, 18%  view statistics
General Chairs  
Peng Ning NC State University, USA
Program Chairs  
Sabrina De Capitani di Vimercati University of Milan, Italy
Paul Syverson Naval Research Laboratory, USA
Front matter
PdfPdf
(title page, copyright, welcome, contents, organization, reviewers, sponsors)

Back matter
PdfPdf
(author index)
 
Table of Contents
  Assurance and evaluation: what next?
Steven B. Lipner
Pages: 1 - 1
Full text available: PdfPdf(350 KB)
Additional Information:full citation, abstract, index terms
 
 
SESSION: Web applications security
    An analysis of browser domain-isolation bugs and a light-weight transparent defense mechanism
Shuo Chen, David Ross, Yi-Min Wang
Pages: 2 - 11
Full text available: PdfPdf(421 KB)
    CANDID: preventing sql injection attacks using dynamic candidate evaluations
Sruthi Bandhakavi, Prithvi Bisht, P. Madhusudan, V. N. Venkatakrishnan
Pages: 12 - 24
Full text available: PdfPdf(426 KB)
    Multi-module vulnerability analysis of web-based applications
Davide Balzarotti, Marco Cova, Viktoria V. Felmetsger, Giovanni Vigna
Pages: 25 - 35
Full text available: PdfPdf(319 KB)
 
 
SESSION: Authentication and passwords
    Do background images improve "draw a secret" graphical passwords?
Paul Dunphy, Jeff Yan
Pages: 36 - 47
Full text available: PdfPdf(782 KB)
    Beamauth: two-factor web authentication with a bookmark
Ben Adida
Pages: 48 - 57
Full text available: PdfPdf(295 KB)
    Dynamic pharming attacks and locked same-origin policies for web browsers
Chris Karlof, Umesh Shankar, J. D. Tygar, David Wagner
Pages: 58 - 71
Full text available: PdfPdf(504 KB)
 
 
SESSION: Anonymity
    Blacklistable anonymous credentials: blocking misbehaving users without ttps
Patrick P. Tsang, Man Ho Au, Apu Kapadia, Sean W. Smith
Pages: 72 - 81
Full text available: PdfPdf(468 KB)
    How much anonymity does network latency leak?
Nicholas Hopper, Eugene Y. Vasserman, Eric Chan-Tin
Pages: 82 - 91
Full text available: PdfPdf(714 KB)
    Denial of service or denial of security?
Nikita Borisov, George Danezis, Prateek Mittal, Parisa Tabriz
Pages: 92 - 102
Full text available: PdfPdf(393 KB)
 
 
SESSION: Operating systems and malware
    Automated detection of persistent kernel control-flow attacks
Nick L. Petroni, Jr., Michael Hicks
Pages: 103 - 115
Full text available: PdfPdf(312 KB)
    Panorama: capturing system-wide information flow for malware detection and analysis
Heng Yin, Dawn Song, Manuel Egele, Christopher Kruegel, Engin Kirda
Pages: 116 - 127
Full text available: PdfPdf(295 KB)
    Stealthy malware detection through vmm-based "out-of-the-box" semantic view reconstruction
Xuxian Jiang, Xinyuan Wang, Dongyan Xu
Pages: 128 - 138
Full text available: PdfPdf(1.23 MB)
 
 
SESSION: Traffic analysis and location privacy
    Shunting: a hardware/software architecture for flexible, high-performance network intrusion prevention
Jose M. Gonzalez, Vern Paxson, Nicholas Weaver
Pages: 139 - 149
Full text available: PdfPdf(579 KB)
    Highly efficient techniques for network forensics
Miroslav Ponec, Paul Giura, Hervé Brönnimann, Joel Wein
Pages: 150 - 160
Full text available: PdfPdf(615 KB)
    Preserving privacy in gps traces via uncertainty-aware path cloaking
Baik Hoh, Marco Gruteser, Hui Xiong, Ansaf Alrabady
Pages: 161 - 171
Full text available: PdfPdf(2.98 MB)
 
 
SESSION: Cryptography
    Robust computational secret sharing and a unified account of classical secret-sharing goals
Phillip Rogaway, Mihir Bellare
Pages: 172 - 184
Full text available: PdfPdf(333 KB)
    Chosen-ciphertext secure proxy re-encryption
Ran Canetti, Susan Hohenberger
Pages: 185 - 194
Full text available: PdfPdf(329 KB)
    Attribute-based encryption with non-monotonic access structures
Rafail Ostrovsky, Amit Sahai, Brent Waters
Pages: 195 - 203
Full text available: PdfPdf(217 KB)
 
 
SESSION: Network security
    Optimal security hardening using multi-objective optimization on attack tree models of networks
Rinku Dewri, Nayot Poolsappasit, Indrajit Ray, Darrell Whitley
Pages: 204 - 213
Full text available: PdfPdf(770 KB)
    On the accuracy of decentralized virtual coordinate systems in adversarial networks
David John Zage, Cristina Nita-Rotaru
Pages: 214 - 224
Full text available: PdfPdf(876 KB)
    Analyzing the vulnerability of superpeer networks against attack
Bivas Mitra, Fernando Peruani, Sujoy Ghose, Niloy Ganguly
Pages: 225 - 234
Full text available: PdfPdf(560 KB)
    Towards automated provisioning of secure virtualized networks
Serdar Cabuk, Chris I. Dalton, HariGovind Ramasamy, Matthias Schunter
Pages: 235 - 245
Full text available: PdfPdf(326 KB)
 
 
SESSION: Election systems and applied cryptography
    Split-ballot voting: everlasting privacy with distributed trust
Tal Moran, Moni Naor
Pages: 246 - 255
Full text available: PdfPdf(415 KB)
    An independent audit framework for software dependent voting systems
Sujata Garera, Aviel D. Rubin
Pages: 256 - 265
Full text available: PdfPdf(2.23 MB)
    Forward-secure signatures in untrusted update environments: efficient and generic constructions
Benoît Libert, Jean-Jacques Quisquater, Moti Yung
Pages: 266 - 275
Full text available: PdfPdf(301 KB)
    Ordered multisignatures and identity-based sequential aggregate signatures, with applications to secure routing
Alexandra Boldyreva, Craig Gentry, Adam O'Neill, Dae Hyun Yum
Pages: 276 - 285
Full text available: PdfPdf(343 KB)
 
 
SESSION: Side and covert channels detection
    An information-theoretic model for adaptive side-channel attacks
Boris Köpf, David Basin
Pages: 286 - 296
Full text available: PdfPdf(507 KB)
    Covert channels in privacy-preserving identification systems
Daniel V. Bailey, Dan Boneh, Eu-Jin Goh, Ari Juels
Pages: 297 - 306
Full text available: PdfPdf(282 KB)
    Detecting covert timing channels: an entropy-based approach
Steven Gianvecchio, Haining Wang
Pages: 307 - 316
Full text available: PdfPdf(256 KB)
 
 
SESSION: Protocols and spam filters
    Polyglot: automatic extraction of protocol message format using dynamic binary analysis
Juan Caballero, Heng Yin, Zhenkai Liang, Dawn Song
Pages: 317 - 329
Full text available: PdfPdf(448 KB)
    Harvesting verifiable challenges from oblivious online sources
J. Alex Halderman, Brent Waters
Pages: 330 - 341
Full text available: PdfPdf(599 KB)
    Filtering spam with behavioral blacklisting
Anirudh Ramachandran, Nick Feamster, Santosh Vempala
Pages: 342 - 351
Full text available: PdfPdf(438 KB)
 
 
SESSION: Internet security
    ConceptDoppler: a weather tracker for internet censorship

Pages: 352 - 365
Full text available: PdfPdf(1.06 MB)
Additional Information:full citation, cited by
    Asirra: a CAPTCHA that exploits interest-aligned manual image categorization

Pages: 366 - 374
Full text available: PdfPdf(816 KB)
Additional Information:full citation, cited by
    An inquiry into the nature and causes of the wealth of internet miscreants

Pages: 375 - 388
Full text available: PdfPdf(455 KB)
Additional Information:full citation, cited by
 
 
SESSION: Key management
    Hardware-rooted trust for secure key management and transient trust
Jeffrey S. Dwoskin, Ruby B. Lee
Pages: 389 - 400
Full text available: PdfPdf(521 KB)
    Robust key generation from signal envelopes in wireless networks
Babak Azimi-Sadjadi, Aggelos Kiayias, Alejandra Mercado, Bulent Yener
Pages: 401 - 410
Full text available: PdfPdf(513 KB)
    Robust group key agreement using short broadcasts
Stanisław Jarecki, Jihye Kim, Gene Tsudik
Pages: 411 - 420
Full text available: PdfPdf(664 KB)
 
 
SESSION: Policies
    Protecting browsers from dns rebinding attacks
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, Dan Boneh
Pages: 421 - 431
Full text available: PdfPdf(1.32 MB)
    Alpaca: extensible authorization for distributed services
Chris Lesniewski-Laas, Bryan Ford, Jacob Strauss, Robert Morris, M. Frans Kaashoek
Pages: 432 - 444
Full text available: PdfPdf(407 KB)
    Efficient policy analysis for administrative role based access control
Scott D. Stoller, Ping Yang, C R. Ramakrishnan, Mikhail I. Gofman
Pages: 445 - 455
Full text available: PdfPdf(402 KB)
 
 
SESSION: Cryptography and cryptoanalysis
    Provably secure ciphertext policy ABE
Ling Cheung, Calvin Newport
Pages: 456 - 465
Full text available: PdfPdf(347 KB)
    Security under key-dependent inputs
Shai Halevi, Hugo Krawczyk
Pages: 466 - 475
Full text available: PdfPdf(384 KB)
    Cryptanalysis of the windows random number generator
Leo Dorrendorf, Zvi Gutterman, Benny Pinkas
Pages: 476 - 485
Full text available: PdfPdf(238 KB)
 
 
SESSION: Data privacy
    Secure two-party k-means clustering
Paul Bunn, Rafail Ostrovsky
Pages: 486 - 497
Full text available: PdfPdf(464 KB)
    Privacy-preserving remote diagnostics
Justin Brickell, Donald E. Porter, Vitaly Shmatikov, Emmett Witchel
Pages: 498 - 507
Full text available: PdfPdf(702 KB)
    Automaton segmentation: a new approach to preserve privacy in xml information brokering
Fengjun Li, Bo Luo, Peng Liu, Dongwon Lee, Chao-Hsien Chu
Pages: 508 - 518
Full text available: PdfPdf(657 KB)
    Privacy preserving error resilient dna searching through oblivious automata
Juan Ramón Troncoso-Pastoriza, Stefan Katzenbeisser, Mehmet Celik
Pages: 519 - 528
Full text available: PdfPdf(492 KB)
 
 
SESSION: Software security
    Predicting vulnerable software components
Stephan Neuhaus, Thomas Zimmermann, Christian Holler, Andreas Zeller
Pages: 529 - 540
Full text available: PdfPdf(2.29 MB)
    On the infeasibility of modeling polymorphic shellcode
Yingbo Song, Michael E. Locasto, Angelos Stavrou, Angelos D. Keromytis, Salvatore J. Stolfo
Pages: 541 - 551
Full text available: PdfPdf(544 KB)
    The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86)
Hovav Shacham
Pages: 552 - 561
Full text available: PdfPdf(484 KB)
    Memsherlock: an automated debugger for unknown memory corruption vulnerabilities
Emre C. Sezer, Peng Ning, Chongkyung Kil, Jun Xu
Pages: 562 - 572
Full text available: PdfPdf(381 KB)
 
 
SESSION: Data disclosure
    Information disclosure under realistic assumptions: privacy versus optimality
Lei Zhang, Sushil Jajodia, Alexander Brodsky
Pages: 573 - 583
Full text available: PdfPdf(404 KB)
    Pors: proofs of retrievability for large files
Ari Juels, Burton S. Kaliski, Jr.
Pages: 584 - 597
Full text available: PdfPdf(483 KB)
    Provable data possession at untrusted stores
Giuseppe Ateniese, Randal Burns, Reza Curtmola, Joseph Herring, Lea Kissner, Zachary Peterson, Dawn Song
Pages: 598 - 609
Full text available: PdfPdf(646 KB)