Proceedings
"Super Nodes" in Tor: Existence and Security Implication
Chenglong Li, Yibo Xue, Yingfei Dong, Dongsheng Wang
“Mix-In-Place” Anonymous Networking Using Secure Function Evaluation
Nilesh Nipane, Italo Dacosta, Patrick Traynor
A Server- and Browser-Transparent CSRF Defense for Web 2.0 Applications
Riccardo Pelizzi, R Sekar
AdSentry: Comprehensive and Flexible Confinement of JavaScript-based Advertisements
Xinshu Dong, Minh Tran, Zhenkai Liang, Xuxian Jiang
An Empirical Study of Visual Security Cues to Prevent the SSLstripping Attack
Dongwan Shin, Rodrigo Lopes
ASIDE: IDE Support for Web Application Security
Jing Xie, Bill Chu, Heather Richter Lipford, John T. Melton
Attacks on WebView in the Android System
Tongbo Luo, Hao Hao, Wenliang Du, Yifei Wang, Heng Yin
Automated Remote Repair for Mobile Malware
Yacin Nadji, Jonathan Giffin, Patrick Traynor
BareBox: Efficient Malware Analysis on Bare-Metal
Dhilung Kirat, Giovanni Vigna, Christopher Kruegel
BLOCK: A Black-box Approach for Detection of State Violation Attacks Towards Web Applications
Xiaowei Li, Yuan Xue
deRop: Removing Return-Oriented Programming from Malware
Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao
Detecting and Resolving Privacy Conflicts for Collaborative Data Sharing in Online Social Networks
Hongxin Hu, Gail-Joon Ahn, Jan Jorgensen
Detecting Malware’s Failover C&C Strategies with SQUEEZE
Matthias Neugschwandtner, Paolo Milani Comparetti, Christian Platzer
Distilling Critical Attack Graph Surface iteratively through Minimum-Cost SAT Solving
Heqing Huang, Su Zhang, Xinming Ou, Atul Prakash, Karem Sakallah
Don't Bump, Shake on It: The Exploitation of a Popular Accelerometer-Based Smart Phone Exchange and Its Secure Replacement
Ahren Studer, Timothy Passaro, Lujo Bauer
Dynamic Sample Size Detection in Continuous Authentication using Sequential Sampling
Ahmed Awad E. Ahmed, Issa Traore
Enabling Secure VM-vTPM Migration in Private Clouds
Boris Danev, Ramya Jayaram Masti, Ghassan O. Karame , Srdjan Capkun
Exploring the Potential Benefits of Expanded Rate Limiting in Tor: Slow and Steady Wins the Race With Tortoise
W. Brad Moore, Chris Wacek, Micah Sherr
Exposing Invisible Timing-based Traffic Watermarks with BACKLIT
Xiapu Luo, Peng Zhou, Junjie Zhang, Roberto Perdisci, Wenke Lee, Rocky K. C. Chang
Facing the Facts about Image Type in Recognition-Based Graphical Passwords
Max Hlywa, Andrew Patrick, Robert Biddle
ForeCast - Skimming off the Malware Cream
Matthias Neugschwandtner, Paolo Milani Comparetti, Gregoire Jacob, Christopher Kruegel
From Prey To Hunter: Transforming Legacy Embedded Devices Into Exploitation Sensor Grids
Ang Cui, Jatin Kataria, Salvatore J. Stolfo
Hit 'em Where it Hurts: A Live Security Exercise on Cyber Situational Awareness
Adam Doupé, Manuel Egele, Benjamin Caillat, Gianluca Stringhini, Gorken Yakin, Ali Zand, Ludovico Cavedon, Giovanni Vigna
Improving Robustness of DNS to Software Vulnerabilities
Ahmed Khurshid, Firat Kiyak, Matthew Caesar
Mitigating Code-Reuse Attacks with Control-Flow Locking
Tyler Bletsch, Xuxian Jiang, Vince Freeh
Nexat: A History-Based Approach to Predict Attacker Actions
Amir Houmansadr, Ali Zand, Casey Cipriano, Giovanni Vigna, Christopher Kruegel
PhorceField: A Phish-Proof Password Ceremony
Michael Hart, Claude Castille, Manoj Harpalani, Jonathan Toohill, Rob Johnson
Private Search in the Real World
Vasilis Pappas, Mariana Raykova, Binh Vo, Steven M. Bellovin, Tal Malkin
Reliable Telemetry in White Spaces using Remote Attestation
Omid Fatemieh, Michael LeMay, Carl A. Gunter
RIPE: Runtime Intrusion Prevention Evaluator
John Wilander, Nick Nikiforakis, Yves Younan, Wouter Joosen, Miriam Kamkar
Security Through Amnesia: A Software-Based Solution to the Cold Boot Attack on Disk Encryption
Patrick Simmons
SEMAGE: A New Image-based Two-Factor CAPTCHA
Shardul Vikram, Yinan Fan, Guofei Gu
Smart Metering De-Pseudonymization
Marek Jawurek, Martin Johns, Konrad Rieck
Social Snapshots: Digital Forensics for Online Social Networks
Markus Huber, Martin Mulazzani, Gilbert Wondracek, Sebastian Schrittwieser, Edgar Weippl, Manuel Leithner
Static Detection of Malicious JavaScript-Bearing PDF Documents
Pavel Laskov, Nedim Srndic
The Socialbot Network: When Bots Socialize for Fame and Money
Yazan Boshmaf, Ildar Muslukhov, Konstantin Beznosov, Matei Ripeanu
Tracking Payment Card Data Flow Using Virtual Machine State Introspection
Jennia Hizver, Tzi-cker Chiueh
Understanding the Prevalence and Use of Alternative Plans in Malware with Network Games
Yacin Nadji, Manos Antonakakis, Roberto Perdisci, Wenke Lee
WebJail: Least-privilege Integration of Third-party Components in Web Mashups
Steven Van Acker, Philippe De Ryck, Lieven Desmet, Frank Piessens, Wouter Joosen