Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
Steven J. Murdoch
[go: Go Back, main page]

Steven J. Murdoch

Photo of Steven
J. Murdoch I am a researcher in the Security Group of the University of Cambridge, based in the Computer Laboratory, a fellow of Christ's College, and a member of the Tor project.

Some of my writings can be found on the Security Group blog: Light Blue Touchpaper.

In my spare time, I also enjoy photography. You may be interested in my photo collection.

My research interests include:

News and Updates

23 July 2008
The slides and paper for “Metrics for Security and Performance in Low-Latency Anonymity Systems”, presented at the 2008 Privacy Enhancing Technologies Symposium, are now available.

18 May 2008
The slides and paper for “Thinking Inside the Box: System-level Failures of Tamper Proofing”, presented at the 2008 IEEE Symposium on Security and Privacy, are now available.

17 April 2008
My paper, “Hardened Stateless Session Cookies”, presented at the Cambridge Protocols Workshop 2008, is now available.

19 March 2008
My paper, “Securing Network Location Awareness with Authenticated DHCP”, presented at SecureComm 2007, is now available.

26 February 2008
For more information on the BBC Newsnight coverage of our Chip & PIN story, see our background website and press release. Full details can be found in our academic paper, to be presented at the IEEE Symposium on Security and Privacy.

29 December 2007
The slides from my talk at 24C3, “Relay attacks on card payment: vulnerabilities and defences”, are now available.

17 December 2007
My article, “Shifting Borders”, published in the current issue of Index on Censorship (DOI link), is now available.

7 December 2007
My PhD thesis, “Covert channel vulnerabilities in anonymity systems”, has now been published as UCAM-CL-TR-706.


Contents

Professional activities

Program committee member on:

PET 2007

7th Workshop on Privacy Enhancing Technologies, held in Ottawa, Canada, 20–22 June 2007. See the CFP for further details (the submission deadline is 23 February 2007).

ACM CCS 2007

14th ACM Conference on Computer and Communications Security, held in Alexandria, VA, USA, 29 October–2 November 2007. See the CFP for further details (the submission deadline is 1 May 2007).

SAC 2007 (computer security track)

Computer security track of the 22nd ACM Symposium on Applied Computing, held in Seoul, Korea, 11–15 March 2007. See the CFP for further details (the submission deadline has passed).

Previous professional activities

Projects

Publication quality graphics

I am interested in improving the explanatory power and typographical quality of graphical representations of data in papers I write. To this end, I have written some functions for GNU R to produce data-rich graphs, based on ideas presented by Edward Tufte in his book, The Visual Display of Quantitative Information.

iButtons

In the course of a different research project, I have worked with Dallas iButtons. I dismantled two of them, and while these are sensors, not designed to have any significant security properties, the photos may still be of interest.

Chip and PIN

Along with colleagues from the Security Group, I have been investigating security aspects of the recent Chip and PIN deployment. Our initial comments are summarised in Chip and Spin. Since that document was published, we have been looking at issues in PIN distribution and, in particular, the tamper-evidence of laser-printed PIN mailers. Our Laser-printed PIN Mailer Vulnerability Report describes some problems we found. This document was distributed to users and manufacturers of tamper-evident mailers in November 2004 and since then they have been working to deploy improved products. As of August 2005 this report is now publicly available.

Our work on "snooping" the account number and PIN over the communication between card and terminal was featured in a program on ARD TV's Plusminus, by Sabina Wolf and on ITN news by Chris Choi. There is further information about this work on our interceptor page.

Project Dendros

I have been working on the representation of Compounds in Project Dendros and also the API through which the framework will be exposed to programmers.

Software detection of currency

Recent printers, scanners and image manipulation software identify images of currency, will not process the image and display an error message linking to www.rulesforuse.org. The detection algorithm is not disclosed, however it is possible to test sample images as to whether they are identified as currency. This webpage shows an initial analysis of the algorithm's properties, based on results from the automated generation and testing of images.

General-purpose data-representation formats and markup languages

In order to allow information to be easily exchanged a data format must exist, which facilitates sharing between different applications and different geographical locations throughout the evolution of both the data schema and software. There are a great number of existing solutions for this problem, each making different trade-offs and so resulting in radically different approaches. As a first step in exploring this area I have compiled a growing survey of general-purpose data-representation formats and markup languages.

Symbian OS programming

I have done some work on developing software for the Symbian OS, in particular on the Sony Ericsson P800. As part of that work I have written a brief "getting started" guide for developing Symbian OS applications on Windows using GCC.

Sun Ray 1

The Sun Ray 1 is a stateless thin client produced by Sun. I have briefly looked at the protocol used and produced some notes on the Sun Ray protocol.

Publications

Talks

Miscellaneous

Contact Details

email (preferred):

Steven.Murdoch at cl.cam.ac.uk
To send me encrypted email see my PGP keys page.

post:

Steven J. Murdoch
University of Cambridge
Computer Laboratory
15 JJ Thomson Avenue
Cambridge
CB3 0FD
United Kingdom

phone:

+44 1223 763566

mobile:

+44 7866 807 628

fax:

+44 1223 334678

Last modified $Date: 2008-07-23 13:32:20 +0100 (Wed, 23 Jul 2008) $


Note for search engines: My name is commonly misspelt as Steve Murdoch, Steve J. Murdoch, Stephen Murdoch, Stephen J. Murdoch, even sjm217 and sjmurdoch. I haven't seen anyone try 9803674m or murdocsj, which were my identifiers at the University of Glasgow, but in principle they might.