<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Seminar - MMLAB Forum				            </title>
            <link>https://mmlab.snu.ac.kr/community/seminar/</link>
            <description>MMLAB Discussion Board</description>
            <language>ko-KR</language>
            <lastBuildDate>Fri, 04 Sep 2026 14:36:16 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title> HOLMES&amp;WATSON: A Robust and Lightweight HTTPS Website Fingerprinting through HTTP Version Parallelism</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-08-18-holmeswatson-a-robust-and-lightweight-https-website-fingerprinting-through-http-version-parallelism/</link>
                        <pubDate>Tue, 18 Aug 2026 00:50:31 +0000</pubDate>
                        <description><![CDATA[HOLMES &amp; WATSON: A Robust and Lightweight HTTPS Website Fingerprinting through HTTP Version Parallelism (WWW &#039;25)
 

Website Fingerprinting (WF) is a traffic analysis techni...]]></description>
                        <content:encoded><![CDATA[<div><b>HOLMES &amp; WATSON: A Robust and Lightweight HTTPS Website Fingerprinting through HTTP Version Parallelism (WWW '25)</b></div>
<div> </div>
<div><b></b></div>
<div>Website Fingerprinting (WF) is a traffic analysis technique that aims to identify websites visited by users through the analysis of encrypted traffic patterns. Existing approaches often exhibit limited robustness against network variability and concept drift, resulting in significant performance degradation under real-world HTTPS conditions. Moreover, these methods typically require large-scale training datasets and substantial computational resources, which further increases the complexity of deployment. In this paper, we propose HOLMES, a novel approach that exploits HTTP version parallelism to extract enhanced application-layer features. These features, including the number of web resources transmitting in various HTTP versions, expose up to 4.28 bits of information-surpassing 98% of previously reported features and demonstrate increased stability across varying network conditions. Complementary to this, we introduce WATSON, a lightweight classification method based on lazy learning, which substantially reduces the dependency on large training datasets. To further enhance the identification accuracy, we incorporate two fingerprint-specific distance metrics that ensure high intra-class similarity. Our experimental evaluation demonstrates that HOLMES &amp; WATSON significantly enhance both robustness and efficiency, achieving an average accuracy of 87.7% with only a single sample per website, marking an improvement of over 15% compared to state-of-the-art methods.</div>
<div id="wpfa-18177" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="MainSeminar260818_HOLMESWATSON_sykim_제출용.pptx" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1787014231-MainSeminar260818_HOLMESWATSON_sykim_.pptx" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> MainSeminar260818_HOLMESWATSON_sykim_제출용.pptx</a></div>
<div id="wpfa-18178" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1787014303-WWW-2025HolmesWatson.pdf" target="_blank" title="WWW-2025HolmesWatson.pdf"><i class="fas fa-paperclip"></i>&nbsp;WWW-2025HolmesWatson.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>sykim</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-08-18-holmeswatson-a-robust-and-lightweight-https-website-fingerprinting-through-http-version-parallelism/</guid>
                    </item>
				                    <item>
                        <title> AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-08-11-airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</link>
                        <pubDate>Tue, 11 Aug 2026 01:20:24 +0000</pubDate>
                        <description><![CDATA[Abstract
&nbsp;
To prevent malicious Wi-Fi clients from attacking other clients on the same network, vendors have introduced client isolation, a combination of mechanisms that block direct...]]></description>
                        <content:encoded><![CDATA[<p>Abstract</p>
<p>&nbsp;</p>
<p><span>To prevent malicious Wi-Fi clients from attacking other clients on the same network, vendors have introduced client isolation, a combination of mechanisms that block direct communication between clients. However, client isolation is not a standardized feature, making its security guarantees unclear. In this paper, we undertake a structured security analysis of Wi-Fi client isolation and uncover new classes of attacks that bypass this protection. We identify several root causes behind these weaknesses. First, Wi-Fi keys that protect broadcast frames are improperly managed and can be abused to bypass client isolation. Second, isolation is often only enforced at the MAC or IP layer, but not both. Third, weak synchronization of a client’s identity across the network stack allows one to bypass Wi-Fi client isolation at the network layer instead, enabling the interception of uplink and downlink traffic of other clients as well as internal backend devices. Every tested router and network was vulnerable to at least one attack. More broadly, the lack of standardization leads to inconsistent, ad hoc, and often incomplete implementations of isolation across vendors. Building on these insights, we design and evaluate end-toend attacks that enable full machine-in-the-middle capabilities in modern Wi-Fi networks. Although client isolation effectively mitigates legacy attacks like ARP spoofing, which has long been considered the only universal method for achieving machinein-the-middle positioning in local area networks, our attack introduces a general and practical alternative that restores this capability, even in the presence of client isolation.</span></p>
<p>&nbsp;</p>
<p><span>For more information, see:  </span><br /><a href="https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/" target="_blank" rel="noopener">https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</a></p>
<div id="wpfa-18164" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="Airsnitch-paper.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1786411278-Airsnitch-paper.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> Airsnitch-paper.pdf</a></div>
<div id="wpfa-18165" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260811_main_seminar_Airsnitch_v4.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1786411421-260811_main_seminar_Airsnitch_v4.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260811_main_seminar_Airsnitch_v4.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>jhoh</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-08-11-airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</guid>
                    </item>
				                    <item>
                        <title> DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing More</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-08-04-distefano-decentralized-infrastructure-for-sharing-trusted-encrypted-facts-and-nothing-more/</link>
                        <pubDate>Tue, 04 Aug 2026 00:17:27 +0000</pubDate>
                        <description><![CDATA[Abstract
We design DiStefano: an efficient, maliciously-secure framework for generating private commitments over TLS-encrypted web traffic, for verification by a designated third-party. DiS...]]></description>
                        <content:encoded><![CDATA[<p>Abstract</p>
<p>We design DiStefano: an efficient, maliciously-secure framework for generating private commitments over TLS-encrypted web traffic, for verification by a designated third-party. DiStefano provides many improvements over previous TLS commitment systems, including: a modular protocol specific to TLS 1.3, support for arbitrary verifiable claims over encrypted data, client browsing history privacy amongst pre-approved TLS servers, and various optimisations to ensure fast online performance of the TLS 1.3 session. We build a permissive open-source implementation of DiStefano integrated into the BoringSSL cryptographic library (used by Chromium-based Internet browsers). We show that DiStefano is practical in both LAN and WAN settings for committing to facts in arbitrary TLS traffic, requiring &lt; 1 s and ≤ 80 KiB to execute the complete online phase of the protocol.</p>
<div id="wpfa-18155" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="NDSS25_DiStefano.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1785802647-NDSS25_DiStefano.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> NDSS25_DiStefano.pdf</a></div>
<div id="wpfa-18156" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1785802695-NDSS25_DiStefano_CH.pdf" target="_blank" title="NDSS25_DiStefano_CH.pdf"><i class="fas fa-paperclip"></i>&nbsp;NDSS25_DiStefano_CH.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>chlee</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-08-04-distefano-decentralized-infrastructure-for-sharing-trusted-encrypted-facts-and-nothing-more/</guid>
                    </item>
				                    <item>
                        <title> Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-07-28-demystifying-the-insecurity-of-oauth-based-account-linking-in-connector-ecosystems/</link>
                        <pubDate>Tue, 28 Jul 2026 04:44:53 +0000</pubDate>
                        <description><![CDATA[Abstract
Modern productivity apps, automation platforms, and AI agents orchestrate across external tools through cloudbased “connectors”. To obtain authorized access to connector accounts, ...]]></description>
                        <content:encoded><![CDATA[<p>Abstract</p>
<p>Modern productivity apps, automation platforms, and AI agents orchestrate across external tools through cloudbased “connectors”. To obtain authorized access to connector accounts, these applications rely extensively on the OAuth 2.0 protocol. However, tracking authorization context across web origins and user-agents, while maintaining the binding to the applications' own user identities (i.e., a secure Account Linking process), pushes OAuth beyond its original client-server model assumptions. The rise of the OAuth-as-a-Service (OaaS) paradigm further complicates trust boundaries in OAuth. In this paper, we present the first comprehensive study of OAuth-based account (mis)linking in connector ecosystems. By systematizing real-world account linking architectural patterns, we show how “OAuth connections”, commonly introduced to manage account linking, can inadvertently break session integrity and security boundaries in OAuth. This enables multiple forms of connector account takeovers. We develop OASIS (OAuth Session Integrity Scanner), an analysis framework that identifies account linking implementations and detects novel Cross-user OAuth session fixation (COSF) vulnerabilities in mobile apps. Our empirical analysis discovers 40 vendors susceptible to COSF and identifies additional Cross-tenant confused deputy threats in 8 OaaS providers. We propose practical countermeasures that have since been adopted by major vendors such as Amazon Bedrock AgentCore. We lead ongoing discussions and standardization efforts to update OAuth security best practices in the IETF.</p>
<p>For more information, see:<br />paper: https://ieeexplore.ieee.org/abstract/document/11573408/<br />related talk at IETF: https://youtu.be/C72Saxe03tk?t=2700</p>
<div id="wpfa-18146" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260728_sp26-luo_jhnam.pptx" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1785213893-260728_sp26-luo_jhnam.pptx" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260728_sp26-luo_jhnam.pptx</a></div>
<div id="wpfa-18147" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1785214350-260728_sp26-luo_jhnam.pdf" target="_blank" title="260728_sp26-luo_jhnam.pdf"><i class="fas fa-paperclip"></i>&nbsp;260728_sp26-luo_jhnam.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>남재호</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-07-28-demystifying-the-insecurity-of-oauth-based-account-linking-in-connector-ecosystems/</guid>
                    </item>
				                    <item>
                        <title> ACE: A Security Architecture for LLM-Integrated App Systems</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-07-21-ace-a-security-architecture-for-llm-integrated-app-systems/</link>
                        <pubDate>Tue, 21 Jul 2026 01:35:46 +0000</pubDate>
                        <description><![CDATA[AbstractLLM-integrated app systems extend the utility of Large Language Models (LLMs) with third-party apps that are invoked by a system LLM using interleaved planning and execution phases t...]]></description>
                        <content:encoded><![CDATA[<p>Abstract<br />LLM-integrated app systems extend the utility of Large Language Models (LLMs) with third-party apps that are invoked by a system LLM using interleaved planning and execution phases to answer user queries. These systems introduce new attack vectors where malicious apps can cause integrity violation of planning or execution, availability breakdown, or privacy compromise during execution. In this work, we identify new attacks impacting the integrity of planning, as well as the integrity and availability of execution in LLM-integrated apps, and demonstrate them against IsolateGPT, a recent solution designed to mitigate attacks from malicious apps. We propose Abstract-Concrete-Execute (ACE), a new secure architecture for LLM-integrated app systems that provides security guarantees for system planning and execution. Specifically, ACE decouples planning into two phases by first creating an abstract execution plan using only trusted informa tion, and then mapping the abstract plan to a concrete plan using installed system apps. We verify that the plans generated by our system satisfy user-specified secure information flow constraints via static analysis on the structured plan output. During execution, ACE enforces data and capability barriers between apps, and ensures that the execution is conducted according to the trusted abstract plan. We show experimentally that ACE is secure against attacks from the INJECAGENT and Agent Security Bench benchmarks for indirect prompt injection, and our newly introduced attacks. We also evaluate the utility of ACE in realistic environments, using the Tool Usage suite from the LangChain benchmark. Our architecture represents a significant advancement towards hardening LLM-based systems using system security principles.</p>
<div id="wpfa-18116" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="ndss_2026_ACE.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1784597746-ndss_2026_ACE.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> ndss_2026_ACE.pdf</a></div>
<div> </div>
<div id="wpfa-18118" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1784598436-260721_ACE_NDSS_26.pptx" target="_blank" title="260721_ACE_NDSS_26.pptx"><i class="fas fa-paperclip"></i>&nbsp;260721_ACE_NDSS_26.pptx</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>jhkang</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-07-21-ace-a-security-architecture-for-llm-integrated-app-systems/</guid>
                    </item>
				                    <item>
                        <title> PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak Detection</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-07-07-pathprob-probabilistic-inference-and-path-scoring-for-enhanced-and-flexible-bgp-route-leak-detection/</link>
                        <pubDate>Mon, 06 Jul 2026 23:28:19 +0000</pubDate>
                        <description><![CDATA[AbstractThe Border Gateway Protocol (BGP) lacks inherent security, leaving the Internet vulnerable to severe threats like route leaks. Existing detection methods suffer from limitations such...]]></description>
                        <content:encoded><![CDATA[<p>Abstract<br /><br /><span>The Border Gateway Protocol (BGP) lacks inherent security, leaving the Internet vulnerable to severe threats like route leaks. Existing detection methods suffer from limitations such as rigid binary classification, high false positives, and sparse authoritative AS relationship data. To address these challenges, this paper proposes PathProb—a novel paradigm that flexibly identifies route leaks by calculating topology-aware probability distributions for AS links and computing legitimacy scores for AS paths. Our approach integrates Monte Carlo methods with an Integer Linear Programming formulation of routing policies to derive these solutions efficiently.</span><br /><span>We comprehensively evaluate PathProb using real-world BGP routing traces and route leak incidents. Results show our inference model outperforms state-of-the-art approaches with a high-confidence validation dataset. PathProb detects real-world route leaks with 98.45% recall while simultaneously reducing false positives by 4.29 ∼ 20.08 percentage points over </span><span>state-of-the-art</span><span> alternatives. Additionally, PathProb’s path legitimacy scoring enables network administrators to dynamically adjust route leak detection thresholds—tailoring security posture to their specific false alarm tolerance and security needs. Finally, PathProb offers seamless compatibility with emerging route leak mitigation mechanisms, such as Autonomous System Provider Authorization (ASPA), enabling flexible integration to enhance leak detection capabilities.</span><br /><br />논문링크: https://www.ndss-symposium.org/ndss-paper/pathprob-probabilistic-inference-and-path-scoring-for-enhanced-and-flexible-bgp-route-leak-detection/</p>
<div class="gs">
<div class="   ">
<div id=":17x" class="ii gt">
<div id=":17w" class="a3s aiL ">
<div id="avWBGd-18">
<div class="adL"> </div>
</div>
</div>
</div>
<div id="avWBGd-19" class="WhmR8e" data-hash="0"> </div>
</div>
</div>
<div id="wpfa-18097" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1783380499-260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pdf</a></div>
<div id="wpfa-18099" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1783407294-260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pptx" target="_blank" title="260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pptx"><i class="fas fa-paperclip"></i>&nbsp;260707_PathProb_Probabilistic_Inference_and_Path_Scoring_for_Enhanced_and_Flexible_BGP_Route_Leak_Detection.pptx</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>박홍근</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-07-07-pathprob-probabilistic-inference-and-path-scoring-for-enhanced-and-flexible-bgp-route-leak-detection/</guid>
                    </item>
				                    <item>
                        <title> Inside Job: Defending Kubernetes Clusters Against Network Misconfigurations</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-06-30-inside-job-defending-kubernetes-clusters-against-network-misconfigurations/</link>
                        <pubDate>Mon, 29 Jun 2026 20:40:59 +0000</pubDate>
                        <description><![CDATA[Abstract:
Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. D...]]></description>
                        <content:encoded><![CDATA[<p>Abstract:</p>
<p>Kubernetes has emerged as the de facto standard for container orchestration. Unfortunately, its increasing popularity has also made it an attractive target for malicious actors. Despite extensive research on securing Kubernetes, little attention has been paid to the impact of network configuration on the security of application deployments. This paper addresses this gap by conducting a comprehensive analysis of network misconfigurations in a Kubernetes cluster with specific reference to lateral movement. Accordingly, we carried out an extensive evaluation of 287 open-source applications belonging to six different organizations, ranging from IT companies and public entities to non-profits. As a result, we identified 634 misconfigurations, well beyond what could be found by solutions in the state of the art. We responsibly disclosed our findings to the concerned organizations and engaged in a discussion to assess their severity. As of now, misconfigurations affecting more than thirty applications have been fixed with the mitigations we proposed.</p>
<div id="wpfa-18063" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="20260630_inside-job_huko_vfin.pptx" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1782765659-20260630_inside-job_huko_vfin.pptx" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 20260630_inside-job_huko_vfin.pptx</a></div>
<div id="wpfa-18064" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="20260630_inside-job_huko_vfin.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1782765685-20260630_inside-job_huko_vfin.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 20260630_inside-job_huko_vfin.pdf</a></div>
<div id="wpfa-18065" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1782765753-Bufalino-et-al-2025-Inside-Job-Defending-Kubernetes-Clusters-Against-Network-Misconfigurations.pdf" target="_blank" title="Bufalino-et-al.-2025-Inside-Job-Defending-Kubernetes-Clusters-Against-Network-Misconfigurations.pdf"><i class="fas fa-paperclip"></i>&nbsp;Bufalino-et-al.-2025-Inside-Job-Defending-Kubernetes-Clusters-Against-Network-Misconfigurations.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>고형욱</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-06-30-inside-job-defending-kubernetes-clusters-against-network-misconfigurations/</guid>
                    </item>
				                    <item>
                        <title> CAMP: Compositional Amplification Attacks against DNS</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-06-23-camp-compositional-amplification-attacks-against-dns/</link>
                        <pubDate>Tue, 23 Jun 2026 03:40:30 +0000</pubDate>
                        <description><![CDATA[While DNS is often exploited by reflective DoS attacks, it can also be weaponized as a powerful amplifier to overload itself, as evidenced by a stream of recently discovered application-laye...]]></description>
                        <content:encoded><![CDATA[<p>While DNS is often exploited by reflective DoS attacks, it can also be weaponized as a powerful amplifier to overload itself, as evidenced by a stream of recently discovered application-layer amplification attacks. Given the importance of DNS, the question arises of what the fundamental traits are for such attacks. To answer this question, we perform a systematic investigation by establishing a taxonomy of amplification primitives intrinsic to DNS and a framework to analyze their composability. This approach leads to the discovery of a large family of compositional amplification (Camp) vulnerabilities, which can produce multiplicative effects with message amplification factors of hundreds to thousands. Our measurements with popular DNS implementations and open resolvers indicate the ubiquity and severity of Camp vulnerabilities and the serious threats they pose to the Internet’s crucial naming infrastructure.</p>
<div id="wpfa-18053" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="usenixsecurity24-duan.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1782186030-usenixsecurity24-duan.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> usenixsecurity24-duan.pdf</a></div>
<div id="wpfa-18054" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1782186133-MMLAB__23Jun2026_v10.pdf" target="_blank" title="MMLAB_메인세미나_23Jun2026_v1.0.pdf"><i class="fas fa-paperclip"></i>&nbsp;MMLAB_메인세미나_23Jun2026_v1.0.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>황은비</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-06-23-camp-compositional-amplification-attacks-against-dns/</guid>
                    </item>
				                    <item>
                        <title> Looma: A Low-Latency PQTLS Authentication Architecture for Cloud Applications</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-06-11-looma-a-low-latency-pqtls-authentication-architecture-for-cloud-applications/</link>
                        <pubDate>Tue, 09 Jun 2026 05:03:38 +0000</pubDate>
                        <description><![CDATA[안녕하세요. 메인 세미나 자료입니다.
 260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_제출용.pdf
&nbsp;260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architec...]]></description>
                        <content:encoded><![CDATA[<p>안녕하세요. 메인 세미나 자료입니다.</p>
<div id="wpfa-18013" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_제출용.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1780981418-260604__Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_제출용.pdf</a></div>
<div id="wpfa-18014" class="wpforo-attached-file"><a class="wpforo-default-attachment" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1780981450-260604__Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_.pptx" target="_blank" title="260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_제출용.pptx"><i class="fas fa-paperclip"></i>&nbsp;260604_메인세미나_Looma-A-Low-Latency-PQTLS-Authentication-Architecture-for-Cloud-Applications_제출용.pptx</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>정경헌</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-06-11-looma-a-low-latency-pqtls-authentication-architecture-for-cloud-applications/</guid>
                    </item>
				                    <item>
                        <title> A Framework to Evaluate MPIC Security using Real-World BGP Announcements</title>
                        <link>https://mmlab.snu.ac.kr/community/seminar/2026-05-21-a-framework-to-evaluate-mpic-security-using-real-world-bgp-announcements/</link>
                        <pubDate>Thu, 21 May 2026 04:53:30 +0000</pubDate>
                        <description><![CDATA[Abstract
Multiple Perspective Issuance Corroboration (MPIC) is a defense that strengthens the Domain Control Validation protocol run by Certificate Authorities (CAs) against network attacks...]]></description>
                        <content:encoded><![CDATA[<p>Abstract</p>
<p>Multiple Perspective Issuance Corroboration (MPIC) is a defense that strengthens the Domain Control Validation protocol run by Certificate Authorities (CAs) against network attacks (e.g., routing hijacks). Despite its recent adoption as a requirement by the CA/Browser Forum, the quantitative security benefits of MPIC in light of real-world routing behaviors are not well understood. We seek to address this challenge by creating a framework to test the effects of real-world BGP hijacks on millions of potential MPIC perspective deployments. Our framework launches around 1500 ethical BGP hijacks on IP prefixes we own and analyzes how potential MPIC perspectives route under these attacks. We consider over 100 global MPIC perspective locations spread across 3 major cloud providers. We find that optimal MPIC deployments can prevent certificate misissuance for over 87% of our evaluated real-world BGP hijacks. We further show that different routing behaviors by cloud providers, such as cold potato routing, have a substantial effect on MPIC's ability to limit the impact of BGP attacks. Finally, our framework computes optimized sets of MPIC perspective locations for CAs to use given their preference of cloud provider and perspective count. Our recommendations have already impacted the MPIC deployment at Google Trust Services, and have been adopted as the default recommendation by the Open MPIC project.</p>
<p>For more information, see:<br />paper: https://dl.acm.org/doi/10.1145/3730567.3764495<br />website: https://mpiclabs.org/marcopolo</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div id="wpfa-17976" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260521_imc25-birgelee_jhnam.pptx" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1779339210-260521_imc25-birgelee_jhnam.pptx" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260521_imc25-birgelee_jhnam.pptx</a></div>
<div id="wpfa-17977" class="wpforo-attached-file"><a class="wpforo-default-attachment" title="260521_imc25-birgelee_jhnam.pdf" href="//mmlab.snu.ac.kr/wp-content/uploads/wpforo/default_attachments/1779339238-260521_imc25-birgelee_jhnam.pdf" target="_blank" rel="noopener"><i class="fas fa-paperclip"></i> 260521_imc25-birgelee_jhnam.pdf</a></div>]]></content:encoded>
						                            <category domain="https://mmlab.snu.ac.kr/community/seminar/">Seminar</category>                        <dc:creator>남재호</dc:creator>
                        <guid isPermaLink="true">https://mmlab.snu.ac.kr/community/seminar/2026-05-21-a-framework-to-evaluate-mpic-security-using-real-world-bgp-announcements/</guid>
                    </item>
							        </channel>
        </rss>
		