ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:

~ similar to 2605.31020v1· 20 results

cs.CRcs.NIRecentMay 6, 2026

Securing the Web with HSTS-Enforced

Aaron van Diepen, Adrian Zapletal, Fernando Kuipers

The paper proposes HSTS-Enforced, a new web security model that flips the default connection from HTTP to HTTPS, eliminating TLS stripping attacks while allowing sites to opt out if they genuinely req…

View →
cs.CRRecentApr 5, 2026

Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs

Yuxiang Yang, Ao Wang, Xuewei Feng, Qi Li +1 more

This paper systematically identifies and demonstrates multiple session manipulation attacks against VPN connection tracking frameworks, revealing widespread vulnerabilities in popular VPN services.

View →
cs.CRRecentApr 9, 2026

Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain

Hanzhi Liu, Chaofan Shou, Hongbo Wen, Yanju Chen +2 more

This paper systematically analyzes the threat posed by malicious third-party API routers in the LLM supply chain, finding that a significant number of routers actively perform payload injection, crede…

View →
cs.CRquant-phRecentMay 4, 2026

Observability for Post-Quantum TLS Readiness: A Multi-Surface Evidence Framework

José Luis Delgado

The paper introduces a multi-surface evidence framework to provide comprehensive observability for post-quantum TLS migration, enabling robust measurement of session behavior and endpoint capabilities…

View →
cs.CRRecentApr 15, 2026

Understanding Student Experiences with TLS Client Authentication

Abubakar Sadiq Shittu, Clay Shubert, John Sadik, Scott Ruoti

This study empirically demonstrates that even highly technical students struggle significantly with the long-term usability and security understanding of Mutual TLS (mTLS) client authentication, sugge…

View →
cs.CRRecentMay 26, 2026

The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software

Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel +1 more

This paper analyzes RPKI specifications, demonstrating that vague or conflicting requirements in dozens of RFCs cause systemic vulnerabilities in real-world implementations, leading to 61 undocumented…

View →
cs.CRRecentApr 7, 2026

Signature Placement in Post-Quantum TLS Certificate Hierarchies: An Experimental Study of ML-DSA and SLH-DSA in TLS 1.3 Authentication

José Luis Delgado Jiménez

This paper experimentally compares ML-DSA and SLH-DSA in TLS 1.3, finding that placing SLH-DSA at the server leaf significantly increases computational cost and latency, suggesting upper-layer placeme…

View →
cs.CRRecentMay 18, 2026

Operationalising Post Quantum TLS Automated Configuration Profiling and Hybrid PQC Deployment in Financial Infrastructure

Harish Balaji, Aarav Varshney, Prasanna Ravi, Sripal Jain +5 more

This paper addresses the operational challenge of adopting Post-Quantum Cryptography (PQC) in complex financial TLS environments by presenting a methodology to automatically profile and normalize cryp…

View →
cs.CRRecentMay 28, 2026

FIDEM: A Standard-Compliant Framework for Secure Binding of MUD Profiles to IoT Devices

Alessandro Lotto, Savio Sciancalepore, Alessandro Brighente, Mauro Conti

FIDEM introduces a standard-compliant framework that uses Zero-Knowledge Proofs to securely bind IoT devices to their Manufacturer Usage Description (MUD) profiles, mitigating risks associated with in…

View →
cs.CRRecentApr 17, 2026

ProcRoute: Process-Scoped Authorization of Split-Tunnel Routes

Arul Thileeban Sagayam

ProcRoute is a system that restricts internal network route access to specific, authorized applications, preventing unprivileged processes from exploiting split-tunnel VPN routes.

View →
cs.CRcs.AIRecentMay 29, 2026

A Protocol-Language Model for Network Intrusion (Without Deep Packet Inspection)

Vivek Kumar Sharma

The paper introduces PLM-NIDS, a novel intrusion detection system that models network flows as a language based solely on L3/L4 metadata, successfully detecting attacks by identifying deviations from…

View →
cs.CRcs.AIRecentMay 29, 2026

A Protocol-Language Model for Network Intrusion (Without Deep Packet Inspection)

Vivek Kumar Sharma

The paper introduces PLM-NIDS, a novel intrusion detection system that models network flows as a language based solely on L3/L4 metadata, successfully detecting attacks by identifying deviations from…

View →
cs.CRcs.DCRecentApr 27, 2026

Network Impact of Post-Quantum Certificate Chain sizes on Time to First Byte in TLS Deployments

Matthew Chou, Phuong Cao

This paper quantifies the latency impact of increasing certificate chain sizes required by Post-Quantum Cryptography (PQC) on TLS Time to First Byte (TTFB), finding that Merkle Tree Certificates (MTC)…

View →
cs.CRcs.AIcs.NIRecentApr 22, 2026

Behavioral Consistency and Transparency Analysis on Large Language Model API Gateways

Guanjie Lin, Yinxin Wan, Shichao Pei, Ting Xu +2 more

The paper introduces GateScope, a black-box framework that audits commercial LLM API gateways, revealing frequent discrepancies in model behavior, billing, and performance across real-world services.

View →
cs.CRcs.CLcs.IRRecentMay 27, 2026

A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG

Junjie Mu, Qiongxiu Li

The paper introduces 'Routing Hijacking,' a severe attack where malicious clients forge semantic profiles in Federated RAG systems to misroute target queries, and proposes a trust-aware post-routing f…

View →
cs.CRcs.NIRecentMay 7, 2026

Aquaman: A Transparent Proxy Architecture for Quantum Resilient Key Establishment

Tushin Mallick, Ashish Kundu, Ramana Kompella

The paper introduces Aquaman, a transparent-proxy architecture that enables quantum-resilient session-key establishment at the network edge, protecting clients that cannot natively support post-quantu…

View →
cs.CRRecentMay 21, 2026

A First Measurement Study on Authentication Security in Real-World Remote MCP Servers

Huijun Zhou, Xiaohan Zhang, Haozhe Zhang, Haoyang Zhang +2 more

This study provides the first measurement of authentication security in real-world remote Model Context Protocol (MCP) servers, finding pervasive and critical authentication weaknesses, particularly i…

View →
cs.CRRecentMay 5, 2026

Quantum-Resistant Networks: A Review of Primitives, Protocols and Best Practices

Elisa Bertino, Ramana Kompella, Ashish Kundu, Cristina Nita-Rotaru +2 more

This paper provides a comprehensive, system-level taxonomy for designing quantum-resistant network architectures, moving beyond simple protocol substitutions to address key distribution and management…

View →
cs.CRcs.AIRecentMay 26, 2026

Grimlock: Guarding High-Agency Systems with eBPF and Attested Channels

Qiancheng Wu, Wenhui Zhang, Gan Fang, Sheng Mao +4 more

Grimlock is an Agent Guard that enhances security for high-agency systems by enforcing identity, authorization, and scope-bound communication through eBPF and attested TLS channels, without modifying…

View →
cs.CRcs.AIcs.SERecentMay 22, 2026

Attested Tool-Server Admission: A Security Extension to the Model Context Protocol

Alfredo Metere

The paper introduces mcp-attested, a security extension to the Model Context Protocol (MCP) that allows hosts to safely admit and restrict the tools used by external, third-party tool servers.

View →