Division of Computer and Network Systems (CNS)

group_project

Visible to the public SaTC: CORE: Small: Socio-Technical Strategies for Enhancing Privacy in Photo Sharing

With the rise of digital photography and social networking, people are capturing and sharing photos on social media at an unprecedented rate. Such sharing may lead to privacy concerns for the people captured in such photos, e.g., in the context of embarrassing photos that go "viral" and are shared widely. At worst, online photo sharing can result in cyber-bullying that can greatly affect the subjects of such photos.

group_project

Visible to the public SaTC: CORE: Small: Collaborative: Leveraging community oversight to enhance collective efficacy for privacy and security

This research concerns how groups of people can cooperate to protect their privacy. The researchers will study how people can help one another to manage their digital privacy and security. Offline, people support each other informally to make privacy and security decisions, by sharing stories or exchanging advice, but technology designs for privacy do not reflect these social processes.

group_project

Visible to the public SaTC: CORE: Small: Collaborative: Defending Against Authorship Attribution Attacks

Authorship attribution techniques identify the author of an unsigned document such as an e-mail, memo, or social media post by analyzing candidate authors' writing styles for tell-tale "fingerprints" such as distinctive words and sentence structure. Everyone leaves these fingerprints in their writing. This creates a problem for people who have a need to remain anonymous, people including whistleblowers and journalists working in states hostile to their work.

group_project

Visible to the public SaTC: CORE: Small: Collaborative: Techniques for Enhancing the Security and Trust of FPGAs-Based Systems

Secret keys that are stored and used within physical devices can be extracted by adversaries. The attacks involve measuring the power consumption or electromagnetic radiation emanating from the chip as it carries out encryption, and then analyzing them to deduce the secret key. This project investigates techniques that self-mutate the hardware at runtime as a means of significantly reducing and ideally eliminating signal information leveraged by the adversary.

group_project

Visible to the public SaTC: CORE: Small: Super-Human Cryptanalysis for Scalable Side-Channel Analysis

The project takes the rapidly evolving advances in deep learning and applies them in the context of side-channel analysis (SCA). Finding SCA leakages on real devices can be a tedious process, resulting devices ranging from wearables to embedded Internet of Things (IoT) devices entering the marketplace without proper protection. This project explores ways to automate side-channel security analysis using deep learning techniques. To protect devices against SCA, the project also explores a novel approach to countermeasure design by applying the concept of adversarial learning.

group_project

Visible to the public SaTC: CORE: Small: Collaborative: Fine Grained Protection for Scalable Single-Use Services

opular Internet servers and web sites may serve thousands of users simultaneously. To handle this volume of activity, these servers share resources, such as processors, memory, and hard disk space. These shared resources provide an avenue for an attacker to affect other users connected to the server if the attacker successfully exploits a vulnerability in the server. This research project aims to eliminate this risk by creating an individual, customized server instance for each user that runs within an isolated single-use container.

group_project

Visible to the public SaTC: CORE: Small: Practical methods for detecting access permission vulnerabilities caused by sysadmin's configuration errors

As data center systems become ever so complex, it has been ever so daunting for system administrators to configure various permission correctly without accidentally opening up permissions for unintended users (and also malicious users) and resulting in catastrophic security disasters.

group_project

Visible to the public SaTC: CORE: Small: Collaborative: Fine Grained Protection for Scalable Single-Use Services

Popular Internet servers and web sites may serve thousands of users simultaneously. To handle this volume of activity, these servers share resources, such as processors, memory, and hard disk space. These shared resources provide an avenue for an attacker to affect other users connected to the server if the attacker successfully exploits a vulnerability in the server. This research project aims to eliminate this risk by creating an individual, customized server instance for each user that runs within an isolated single-use container.

group_project

Visible to the public SaTC: CORE: Small: Multivariate Public Key Cryptosystems - Candidates for the Next Generation Post-Quantum Standards

Public-key cryptosystems, a revolutionary breakthrough in cryptography, are indispensable for our modern communication network. The Internet, as well as other communication systems, rely principally on public-key cryptosystems that depend for security on the difficulty of certain number-theoretic problems such as integer factorization or the "discrete log problem." However, it is now known that a quantum computer could efficiently solve these problems, thus rendering all public-key cryptosystems based on such assumptions impotent if a large-scale quantum computer can be built.

group_project

Visible to the public SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors

This project will develop new open-source processor architectures with advanced security features. The security features will be added to existing open-source processors to help protect the confidentiality and integrity of data and to protect against side-channel attacks. Beyond the design, the project will also provide new methodology to verify the proposed security feature, to provide assurance that the processor hardware itself is provably secure.