Skip to main content

Bump in the Ether: A framework for securing sensitive user input

Publication ,  Conference
McCune, JM; Perrig, A; Reiter, MK
Published in: USENIX 2006 Annual Technical Conference
January 1, 2006

We present Bump in the Ether (BitE), an approach for preventing user-space malware from accessing sensitive user input and providing the user with additional confidence that her input is being delivered to the expected application. Rather than preventing malware from running or detecting already-running malware, we facilitate user input that bypasses common avenues of attack. User input traverses a trusted tunnel from the input device to the application. This trusted tunnel is implemented using a trusted mobile device working in tandem with a host platform capable of attesting to its current software state. Based on a received attestation, the mobile device verifies the integrity of the host platform and application, provides a trusted display through which the user selects the application to which her inputs should be directed, and encrypts those inputs so that only the expected application can decrypt them. We describe the design and implementation of BitE, with emphasis on both usability and security issues.

Duke Scholars

Published In

USENIX 2006 Annual Technical Conference

Publication Date

January 1, 2006

Start / End Page

185 / 198
 

Citation

APA
Chicago
ICMJE
MLA
NLM
McCune, J. M., Perrig, A., & Reiter, M. K. (2006). Bump in the Ether: A framework for securing sensitive user input. In USENIX 2006 Annual Technical Conference (pp. 185–198).
McCune, J. M., A. Perrig, and M. K. Reiter. “Bump in the Ether: A framework for securing sensitive user input.” In USENIX 2006 Annual Technical Conference, 185–98, 2006.
McCune JM, Perrig A, Reiter MK. Bump in the Ether: A framework for securing sensitive user input. In: USENIX 2006 Annual Technical Conference. 2006. p. 185–98.
McCune, J. M., et al. “Bump in the Ether: A framework for securing sensitive user input.” USENIX 2006 Annual Technical Conference, 2006, pp. 185–98.
McCune JM, Perrig A, Reiter MK. Bump in the Ether: A framework for securing sensitive user input. USENIX 2006 Annual Technical Conference. 2006. p. 185–198.

Published In

USENIX 2006 Annual Technical Conference

Publication Date

January 1, 2006

Start / End Page

185 / 198