activity
20202024
most citedInjection Attacks Reloaded: Tunnelling Malicious Payloads over DNS

10 citations · 17 across the 3 of their papers we have counts for

collaborators

6 papers

cs.CR2024

Byzantine-Secure Relying Party for Resilient RPKI

Jens Friess, Donika Mirdita, Haya Schulmann +1

To protect against prefix hijacks, Resource Public Key Infrastructure (RPKI) has been standardized. To enjoy the security guarantees of RPKI validation, networks need to install a…

cs.CR20227 cited

Stalloris: RPKI Downgrade Attack

Tomas Hlavacek, Philipp Jeitner, Donika Mirdita +2

We demonstrate the first downgrade attacks against RPKI. The key design property in RPKI that allows our attacks is the tradeoff between connectivity and security: when networks ca…

cs.CR202210 cited

Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS

Philipp Jeitner, Haya Shulman

The traditional design principle for Internet protocols indicates: "Be strict when sending and tolerant when receiving" [RFC1958], and DNS is no exception to this. The transparency…

cs.CR2021

The Master and Parasite Attack

Lukas Baumann, Elias Heftrig, Haya Shulman +1

We explore a new type of malicious script attacks: the persistent parasite attack. Persistent parasites are stealthy scripts, which persist for a long time in the browser's cache.…

cs.CR2021

Privacy Preserving and Resilient RPKI

Kris Shrishak, Haya Shulman

Resource Public Key Infrastructure (RPKI) is vital to the security of inter-domain routing. However, RPKI enables Regional Internet Registries (RIRs) to unilaterally takedown IP pr…

cs.CR2020

The Impact of DNS Insecurity on Time

Philipp Jeitner, Haya Shulman, Michael Waidner

We demonstrate the first practical off-path time shifting attacks against NTP as well as against Man-in-the-Middle (MitM) secure Chronos-enhanced NTP. Our attacks exploit the insec…