@inproceedings{54435,
  abstract     = {{Web browsers are among the most important but also complex software solutions to access the web. It is therefore not surprising that web browsers are an attractive target for attackers. Especially in the last decade, security researchers and browser vendors have developed sandboxing mechanisms like security-relevant HTTP headers to tackle the problem of getting a more secure browser. Although the security community is aware of the importance of security-relevant HTTP headers, legacy applications and individual requests from different parties have led to possible insecure configurations of these headers. Even if specific security headers are configured correctly, conflicts in their functionalities may lead to unforeseen browser behaviors and vulnerabilities. Recently, the first work which analyzed duplicated headers and conflicts in headers was published by Calzavara et al. at USENIX Security [1]. The authors focused on inconsistent protections by using both, the HTTP header X-Frame-Options and the framing protection of the Content-Security-Policy. We extend their work by analyzing browser behaviors when parsing duplicated headers, conflicting directives, and values that do not conform to the defined ABNF metalanguage specification. We created an open-source testbed running over 19,800 test cases, at which nearly 300 test cases are executed in the set of 66 different browsers. Our work shows that browsers conform to the specification and behave securely. However, all tested browsers behave differently when it comes, for example, to parsing the Strict-Transport-Security header. Moreover, Chrome, Safari, and Firefox behave differently if the header contains a character, which is not allowed by the defined ABNF. This results in the protection mechanism being fully enforced, partially enforced, or not enforced and thus completely bypassable.}},
  author       = {{Siewert, Hendrik and Kretschmer, Martin and Niemietz, Marcus and Somorovsky, Juraj}},
  booktitle    = {{2022 IEEE Security and Privacy Workshops (SPW)}},
  publisher    = {{IEEE}},
  title        = {{{On the Security of Parsing Security-Relevant HTTP Headers in Modern Browsers}}},
  doi          = {{10.1109/spw54247.2022.9833880}},
  year         = {{2022}},
}

@inproceedings{25331,
  author       = {{Brinkmann, Marcus and Dresen, Christian and Merget, Robert and Poddebniak, Damian and Müller, Jens and Somorovsky, Juraj and Schwenk, Jörg and Schinzel, Sebastian}},
  booktitle    = {{30th {USENIX} Security Symposium ({USENIX} Security 21)}},
  isbn         = {{978-1-939133-24-3}},
  pages        = {{4293--4310}},
  publisher    = {{{USENIX} Association}},
  title        = {{{ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication}}},
  year         = {{2021}},
}

@inproceedings{25332,
  author       = {{Merget, Robert and Brinkmann, Marcus and Aviram, Nimrod and Somorovsky, Juraj and Mittmann, Johannes and Schwenk, Jörg}},
  booktitle    = {{30th {USENIX} Security Symposium ({USENIX} Security 21)}},
  isbn         = {{978-1-939133-24-3}},
  pages        = {{213--230}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)}}},
  year         = {{2021}},
}

@article{24143,
  author       = {{Drees, Jan Peter and Gupta, Pritha and Hüllermeier, Eyke and Jager, Tibor and Konze, Alexander and Priesterjahn, Claudia and Ramaswamy, Arunselvan and Somorovsky, Juraj}},
  journal      = {{14th ACM Workshop on Artificial Intelligence and Security}},
  title        = {{{Automated Detection of Side Channels in Cryptographic Protocols: DROWN the ROBOTs!}}},
  year         = {{2021}},
}

@inproceedings{25334,
  author       = {{Fiterau-Brostean, Paul and Jonsson, Bengt and Merget, Robert and de Ruiter, Joeri and Sagonas, Konstantinos and Somorovsky, Juraj}},
  booktitle    = {{29th {USENIX} Security Symposium ({USENIX} Security 20)}},
  isbn         = {{978-1-939133-17-5}},
  pages        = {{2523--2540}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Analysis of DTLS Implementations Using Protocol State Fuzzing}}},
  year         = {{2020}},
}

@inproceedings{25336,
  abstract     = {{OpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem.We present the first generic countermeasure against both REPLY and EFAIL-DE attacks by checking the decryption context including SMTP headers and MIME structure during decryption. The decryption context is encoded into a string DC and used as Associated Data (AD) in the AEAD encryption. Thus the proposed solution seamlessly extends the EFAIL-MG countermeasures. The decryption context changes whenever an attacker alters the email source code in a critical way, for example, if the attacker changes the MIME structure or adds a new Reply-To header. The proposed solution does not cause any interoperability problems and legacy emails can still be decrypted. We evaluate our approach by implementing the decryption contexts in Thunderbird/Enigmail and by verifying their correct functionality after the email has been transported over all major email providers, including Gmail and iCloud Mail.}},
  author       = {{Schwenk, Jörg and Brinkmann, Marcus and Poddebniak, Damian and Müller, Jens and Somorovsky, Juraj and Schinzel, Sebastian}},
  booktitle    = {{Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security}},
  isbn         = {{9781450370899}},
  keywords     = {{decryption contexts, EFAIL, OpenPGP, S/MIME, AEAD}},
  pages        = {{1647–1664}},
  publisher    = {{Association for Computing Machinery}},
  title        = {{{Mitigation of Attacks on Email End-to-End Encryption}}},
  doi          = {{10.1145/3372297.3417878}},
  year         = {{2020}},
}

@inproceedings{15908,
  author       = {{Müller, Jens and Brinkmann, Marcus and Poddebniak, Damian and Böck, Hanno and Schinzel, Sebastian and Somorovsky, Juraj and Schwenk, Jörg}},
  booktitle    = {{28th {USENIX} Security Symposium ({USENIX} Security 19)}},
  isbn         = {{978-1-939133-06-9}},
  pages        = {{1011--1028}},
  publisher    = {{{USENIX} Association}},
  title        = {{{"Johnny, you are fired!" -- Spoofing OpenPGP and S/MIME Signatures in Emails}}},
  year         = {{2019}},
}

@inproceedings{15909,
  author       = {{Merget, Robert and Somorovsky, Juraj and Aviram, Nimrod and Young, Craig and Fliegenschmidt, Janis and Schwenk, Jörg and Shavitt, Yuval}},
  booktitle    = {{28th {USENIX} Security Symposium ({USENIX} Security 19)}},
  isbn         = {{978-1-939133-06-9}},
  pages        = {{1029--1046}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Scalable Scanning and Automatic Classification of TLS Padding Oracle Vulnerabilities}}},
  year         = {{2019}},
}

@inproceedings{15910,
  author       = {{Engelbertz, Nils and Mladenov, Vladislav and Somorovsky, Juraj and Herring, David and Erinola, Nurullah and Schwenk, Jörg}},
  booktitle    = {{Open Identity Summit 2019}},
  editor       = {{Roßnagel, Heiko and Wagner, Sven and Hühnlein, Detlef}},
  pages        = {{ 95--106 }},
  publisher    = {{Gesellschaft für Informatik, Bonn}},
  title        = {{{Security Analysis of XAdES Validation in the CEF Digital Signature Services (DSS)}}},
  year         = {{2019}},
}

@inproceedings{15892,
  author       = {{Albrecht, Martin R. and Massimo, Jake and Paterson, Kenneth G. and Somorovsky, Juraj}},
  booktitle    = {{Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security}},
  isbn         = {{9781450356930}},
  title        = {{{Prime and Prejudice: Primality Testing Under Adversarial Conditions}}},
  doi          = {{10.1145/3243734.3243787}},
  year         = {{2018}},
}

@inproceedings{15893,
  author       = {{Poddebniak, Damian and Somorovsky, Juraj and Schinzel, Sebastian and Lochter, Manfred and Rosler, Paul}},
  booktitle    = {{2018 IEEE European Symposium on Security and Privacy (EuroS&P)}},
  isbn         = {{9781538642283}},
  title        = {{{Attacking Deterministic Signature Schemes Using Fault Attacks}}},
  doi          = {{10.1109/eurosp.2018.00031}},
  year         = {{2018}},
}

@inproceedings{15894,
  author       = {{Detering, Dennis and Somorovsky, Juraj and Mainka, Christian and Mladenov, Vladislav and Schwenk, Jörg}},
  booktitle    = {{Proceedings of the 1st Reversing and Offensive-oriented Trends Symposium on - ROOTS}},
  isbn         = {{9781450353212}},
  title        = {{{On The (In-)Security Of JavaScript Object Signing And Encryption}}},
  doi          = {{10.1145/3150376.3150379}},
  year         = {{2018}},
}

@inproceedings{15905,
  author       = {{Poddebniak, Damian and Dresen, Christian and Müller, Jens and Ising, Fabian and Schinzel, Sebastian and Friedberger, Simon and Somorovsky, Juraj and Schwenk, Jörg}},
  booktitle    = {{27th {USENIX} Security Symposium ({USENIX} Security 18)}},
  isbn         = {{978-1-939133-04-5}},
  pages        = {{549--566}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels}}},
  year         = {{2018}},
}

@inproceedings{15906,
  author       = {{Böck, Hanno and Somorovsky, Juraj and Young, Craig}},
  booktitle    = {{27th {USENIX} Security Symposium ({USENIX} Security 18)}},
  isbn         = {{978-1-939133-04-5}},
  pages        = {{817--849}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Return Of Bleichenbacher\textquoterights Oracle Threat (ROBOT)}}},
  year         = {{2018}},
}

@inproceedings{15914,
  author       = {{Engelbertz, Nils and Erinola, Nurullah and Herring, David and Somorovsky, Juraj and Mladenov, Vladislav and Schwenk, Jörg}},
  booktitle    = {{12th {USENIX} Workshop on Offensive Technologies ({WOOT} 18)}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Security Analysis of eIDAS -- The Cross-Country Authentication Scheme in Europe}}},
  year         = {{2018}},
}

@inproceedings{15895,
  author       = {{Muller, Jens and Mladenov, Vladislav and Somorovsky, Juraj and Schwenk, Jörg}},
  booktitle    = {{2017 IEEE Symposium on Security and Privacy (SP)}},
  isbn         = {{9781509055333}},
  title        = {{{SoK: Exploiting Network Printers}}},
  doi          = {{10.1109/sp.2017.47}},
  year         = {{2017}},
}

@inproceedings{15912,
  author       = {{Grothe, Martin and Niemann, Tobias and Somorovsky, Juraj and Schwenk, Jörg}},
  booktitle    = {{11th {USENIX} Workshop on Offensive Technologies ({WOOT} 17)}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Breaking and Fixing Gridcoin}}},
  year         = {{2017}},
}

@inproceedings{15896,
  author       = {{Somorovsky, Juraj}},
  booktitle    = {{Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS'16}},
  isbn         = {{9781450341394}},
  title        = {{{Systematic Fuzzing and Testing of TLS Libraries}}},
  doi          = {{10.1145/2976749.2978411}},
  year         = {{2016}},
}

@inproceedings{15907,
  author       = {{Aviram, Nimrod and Schinzel, Sebastian and Somorovsky, Juraj and Heninger, Nadia and Dankel, Maik and Steube, Jens and Valenta, Luke and Adrian, David and Halderman, J. Alex and Dukhovni, Viktor and Käsper, Emilia and Cohney, Shaanan and Engels, Susanne and Paar, Christof and Shavitt, Yuval}},
  booktitle    = {{25th {USENIX} Security Symposium ({USENIX} Security 16)}},
  isbn         = {{978-1-931971-32-4}},
  pages        = {{689--706}},
  publisher    = {{{USENIX} Association}},
  title        = {{{DROWN: Breaking TLS Using SSLv2}}},
  year         = {{2016}},
}

@inproceedings{15913,
  author       = {{Böck, Hanno and Zauner, Aaron and Devlin, Sean and Somorovsky, Juraj and Jovanovic, Philipp}},
  booktitle    = {{10th {USENIX} Workshop on Offensive Technologies ({WOOT} 16)}},
  publisher    = {{{USENIX} Association}},
  title        = {{{Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS}}},
  year         = {{2016}},
}

