Collin Mulliner
Dr.-Ing. (equiv Ph.D.) (Technische Universität Berlin, Germany)
M.Sc. CS (University of California Santa Barbara, USA)
B.Sc. CS (FH-Darmstadt, University of Applied Sciences, Germany)
I'm a postdoctoral researcher with the SECLAB at Northeastern University working
with William Robertson and
Engin Kirda. My research area is systems security, for details see here.
My personal weblog www.mulliner.org/blog and
Google Scholar profile.
Upcoming events
- ReCON
DIMVA (planned)
Black Hat USA (planned)
- Defcon is still on the edge
Contact
EMail: crm [AT] ccs.neu.edu
Address: Room 330, Building WVH, 360 Huntington Avenue, 02115 Boston, MA, USA
Phone: +1 (857) 264-1748 (google voice: phone + sms, blocked in the night as in GMT-4!)
My official lab page and
department page
Index
Research Interests
Cellular device and Smartphone Security, including infrastructure
Vulnerability Analysis
Offensive Security
Software Security
Mobile Payment
Near Field Communication (NFC)
Mobile Malware
Privacy
Embedded Systems and Consumer Electronics
Network and Wireless Security (GSM/3G/LTE, WiFi, Bluetooth, ...)
Operating Systems Security (strong focus on mobile device OSes)
Projects
-- Protocols
SMS (Short Message Service) Security Research
Bluetooth Security
Near Field Communication (NFC) Security
-- Operating systems and platforms
iPhone Security
Symbian OS Exploitation and Shellcode Development
Android Security
Windows Mobile
-- Mobile operator networks
Smartphone and Mobile Phone Honeypots
M2M security (probing mobile networks for M2M devices)
-- Privacy
GPRS HTTP Header Privacy
TOR DNS
TTDNSD Proxy for full DNS over TOR, now maintained by the tor project
Previous Research Labs
Publications
Peer Reviewed Papers
Conference Workshop Short Paper
Conference
- PrivExec: Private Execution as an Operating System Service Kaan Onarlioglu, Collin Mulliner, William Robertson, Engin Kirda In the Proceedings of the 34th IEEE Symposium on Security and Privacy San Francisco, CA, USA May 2013 PDF, BibTeX entry, Slides(acceptance rate 38/315=12%)
- Taming Mr Hayes: Mitigating Signaling Based Attacks on Smartphones Collin Mulliner, Steffen Liebergeld, Matthias Lange, and Jean-Pierre Seifert
In the Proceedings of the IEEE/IFIP 41st International Conference on Dependable Systems Networks (DSN)
Boston, MA, USA 25-28 June 2012 PDF, BibTeX entry, Slides (DSN/DCCS acceptance rate 27/156 = 17.3%)
*William C. Carter Award*
- SMS of Death: from analyzing to attacking mobile phones on a large scale Collin Mulliner, Nico Golde, and Jean-Pierre Seifert
In the Proceedings of the 20th USENIX Security Symposium
San Francisco, CA, USA 10-12 August 2011 PDF, BibTeX entry, Slides (acceptance rate 35/204=17.2%)
- Rise of the iBots: 0wning a telco network Collin Mulliner and Jean-Pierre Seifert
In the Proceedings of the 5th IEEE International Conference on Malicious and Unwanted Software (Malware)
Nancy, France 19-20 October, 2010 PDF, BibTeX entry, Slides
- Privacy Leaks in Mobile Phone Internet Access Collin Mulliner
In the Proceedings of the 14th International Conference on Intelligence in Next Generation Networks (ICIN)
Berlin, Germany 11-14 October, 2010 PDF, BibTeX entry, Slides *Best Paper*
- Vulnerability Analysis of MMS User Agents Collin Mulliner and Giovanni Vigna
Proceedings of the Annual Computer Security Applications Conference (ACSAC)
Miami, Florida December 2006 PDF, BibTeX entry (acceptance rate 32/135=27%)
- Using Labeling to Prevent Cross-Service Attacks Against Smart Phones
Collin Mulliner, Giovanni Vigna, David Dagon, and Wenke Lee Proceedings of the
Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA) Berlin, Germany July 2006 PDF, BibTeX entry, Slides (27% acceptance rate)
Workshop
- Read It Twice! A mass-storage-based TOCTTOU attack Collin Mulliner and Benjamin Michele In the Proceedings of the 6th USENIX Workshop on Offensive Technologies (WOOT) Bellevue, WA, USA August 2012 PDF, BibTeX entry, Slides(acceptance rate 12/30=40%)
*Best Paper*
- Injecting SMS Messages into Smart Phones for Security Analysis Collin Mulliner and Charlie Miller
In the Proceedings of the 3rd USENIX Workshop on Offensive Technologies (WOOT)
Montreal, Canada August 2009 PDF, BibTeX entry, Slides(acceptance rate 9/24=37.5%)
- Vulnerability Analysis and Attacks on NFC-enabled Mobile Phones Collin Mulliner
In the Proceedings of the 1st International Workshop on Sensor Security (IWSS) at ARES 2009
Fukuoka, Japan March 2009 PDF, BibTeX entry, Slides
Short Paper
- SMS-based One-Time Passwords: Attacks and Defense (short paper) Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, Jean-Pierre Seifert To appear In the Proceedings of the 10th Conference on Detection of Intrusions and Malware & Vulnerability
Assessment (DIMVA 2013) Berlin, Germany July 2013 PDF, BibTeX entry, Slides(acceptance rate 12/38=31.5%)
- Nomadic Honeypots: A Novel Concept for Smartphone Honeypots (short paper / position paper)
Steffen Liebergeld, Matthias Lange and Collin Mulliner
In the Proceedings of the Workshop on Mobile Security Technologies (MoST) San Francisco, CA May 2013 PDF, BibTeX entry, Slides(acceptance rate 11/22=50%)
Journal and Magazine Articles
- Persönliche Datenspuren bei der mobilen Internetnutzung Collin Mulliner
Datenschutz und Datensicherheit (DuD) Issue 3/2012, pages 180-184
Germany March 2012 Article
- Risiko Smartphone Daniel Bachfeld, Collin Mulliner
Magazin für Computertechnik | c't (Issue 20)
Germany September 2010 1, 2
Books / Chapters
- Mobile Phone Security. The Impact of the Modem. Collin Mulliner
SVH Verlag
Germany 2012
ISBN: 978-3-8381-3289-1 Amazon
- Contribution to Chapter 7. Ken Dunham, Seth Fogie, and others
Mobile Malware Attacks and Defense
USA November 2008 Amazon
- Kapitel 7. Iomega ZIP-Drive Howto Collin Mulliner
Linux HOWTOs: Die besten Loesungen der Linuxgemeinde. (Marco Budde Hrsg.)
Germany 1999 Amazon
Tech Reports
- Countering SMS Attacks: Filter Recommendations Nico Golde and Collin Mulliner
Technical Report: 2011-09 ISSN: 1436-9915
Berlin, Germany April 2011 PDF
- Smartphone Honeypots Collin Mulliner
In Proceedings of the Sixth GI SIG SIDAR Graduate Workshop on Reactive Security (SPRING) Technical Report SR-2011-01, GI FG SIDAR
Bochum, Germany 21-22 March 2011 PDF, Slides
- Smartphone Botnets Collin Mulliner
In Proceedings of the Fifth GI SIG SIDAR Graduate Workshop on Reactive Security (SPRING) Technical Report SR-2010-01, GI FG SIDAR
Bonn, Germany 7th July 2010 PDF, Slides
- Blueprinting - Remote Device Identification based on Bluetooth Fingerprinting Techniques Martin Herfurt and Collin Mulliner
21st Chaos Communication Congress (21c3)
Berlin, Germany December 2004 PDF
Posters
- Poster: Towards Detecting DMA Malware Patrick Stewin, Jean-Pierre Seifert, Collin Mulliner 18th ACM Conference on Computer and Communications Security
(CCS) Chicago, IL, USA October 17-21 2011Poster abstract PDF (acceptance rate 41/62=66.1%)
- Poster: HoneyDroid - Creating a Smart Phone Honeypot Collin Mulliner, Steffen Liebergeld, Matthias Lange IEEE Security and Privacy Oakland, CA, USA May 22-25 2011Poster abstract PDF (acceptance rate 18/34=53%)
Edited Volumes
- Patrick Stewin, Collin Mulliner (Hrsg.)
Proceedings of the Seventh GI SIG SIDAR Graduate Workshop on Reactive Security (SPRING)
Technical Report SR-2012-01, ISSN 2190-846X
Berlin, Germany July 5-6 2012PDF
Conference Talks and Presentations
2013
- Introduction to Dynamic Dalvik Instrumenation Collin Mulliner SummerCon 2013 New York City, U.S.A. June 7th, 2013PDF
2012
- Probing Mobile Operator Networks Collin Mulliner CSAW:THREADS @ NY-Poly NYC, USA November 15th, 2012PDF, project page
(invited)
- Dynamic Binary Instrumentation on Android Collin Mulliner RuxCon 2012 Melbourne, Australia October 20-21, 2012PDF
(invited)
- Dynamic Binary Instrumentation on Android Collin Mulliner BreakPoint 2012 Melbourne, Australia October 17-18, 2012PDF
(invited)
- Probing Mobile Operator Networks Collin Mulliner Black Hat USA Las Vegas, NV, USA July 25-26, 2012PDF, project page
- Binary Instrumentation on Android Collin Mulliner SummerCon 2012 New York City, U.S.A. June 8th, 2012PDF
- Probing Mobile Operator Networks Collin Mulliner CanSecWest 2012 Vancouver, Canada March 7-9, 2012PDF, project page
2011
- Hacking your NFC phone and service: the good news and the bad news Collin Mulliner The 7th Workshop on RFID security and privacy (RFIDsec11) Amherst, MA, USA June 27-28th 2011
(invited)
- Hacking NFC and NDEF Collin Mulliner NinjaCon / BSides Vienna 2011 Vienna, Austria June 18th 2011PDF, project page
- SMS-o-Death: from analyzing to attacking mobile phones on a large scale Nico Golde and Collin Mulliner CanSecWest 2011 Vancouver, Canada March 9-11 2011PDF, project page
2010
- SMS-o-Death: from analyzing to attacking mobile phones on a large scale Nico Golde and Collin Mulliner 27th Chaos Communication Congress (27c3) Berlin, Germany December 27-30 2010
- Angriff aufs Smartphone Collin Mulliner Cisco-Expo Berlin, Germany December 1-2 2010
(invited)
- Consumer Electronics Security Lab Collin Mulliner CAST Workshop - Embedded Security Darmstadt, Germany August 26th 2010
(invited)
- Random tales from a mobile phone hacker Collin Mulliner CanSecWest 2010 Vancouver, Canada March 24-26th, 2010 PDF
2009
- Fuzzing the Phone in your Phone Collin Mulliner 26th Chaos Communication Congress (26c3) Berlin, Germany December 28th 2009 PDF, project page
- Sicherheit von mobile Devices: Risiken von iPhone, Android & Co Collin Mulliner TelekomForum Mobilfunktrends 2010 Bonn, Germany September 2009
(invited)
- Smart Phone Security from the Attacker's Perspective Collin Mulliner 5th Annual Mobile Device Management and Security Forum Berlin, Germany September 2009
(invited)
- Fuzzing the Phone in your Phone Collin Mulliner SEC-T Stockholm, Sweden September 2009 project page (invited)
- Fuzzing the Phone in your Phone Collin Mulliner, Charlie Miller Black Hat USA 2009 Las Vegas, Nevada, USA July 2009 PDF, project page
- Data leaks through mobile phone web access Collin Mulliner PH-Neutral 0x7d9 Berlin, Germany May 2009 project page
2008
- Exploiting Symbian Collin Mulliner 25th Chaos Communication Congress (25c3) Berlin, Germany December 2008 PDF, project page
- Attacking NFC Mobile Phones Collin Mulliner 25th Chaos Communication Congress (25c3) Berlin, Germany December 2008 PDF, project page
- Exploiting Symbian Collin Mulliner BlackHat Japan Tokyo, Japan October 9th 2008 PDF, project page
- Data Leaks Through Mobile Phone Web Access Collin Mulliner PET-Convention 2008.2 Darmstadt, Germany September 30th 2008 project page
- NFC-basierte Handy-Bezahlsysteme Collin Mulliner CAST Workshop - SmartCards und Bezahlsysteme Darmstadt, Germany July 24th 2008
(invited)
- Attacking NFC Mobile Phones Collin Mulliner EuSecWest London, UK May 2008 PDF, project page
2007
- Advanced Attacks Against PocketPC Phones Collin Mulliner SyScan Singapore, Singapore July 2007 PDF, project page(invited)
2006
- Advanced Attacks Against PocketPC Phones Collin Mulliner 23rd Chaos Communication Congress (23c3) Berlin, Germany December 2006 PDF, project page
- Advanced Attacks Against PocketPC Phones Collin Mulliner DEFCON-14 Las Vegas N.V., U.S.A. August 2006 PDF, project page
2005
- Exploiting PocketPC Collin Mulliner WhatTheHack! The Netherlands July 2005 PDF, project page
Talks
2013
- Mobile Security Battle Royale (panel discussion) Zach Lanier, Tiago Assumpcao, Collin Mulliner, Charlie Miller, Dino Dai Zovi RSA Conference San Francisco, Ca, USA Feb. 28. 2013
2011
- NFC Phone and Service Security Collin Mulliner Digital Footprint in a Mobile Environment Workshop - at the Joint Research Center of the European Commission Ispra, Italy November 28-19. 2011
(invited)
- Smartphone Malware/Trojans Collin Mulliner LKA NRW Duesseldorf, Germany June 20. 2011
(invited)
- Random tales of a mobile phone hacker Collin Mulliner Ruhr-Universitaet Bochum Bochum, Germany June 1. 2011
(invited)
- Attacking SMS Collin Mulliner SISCTI 36 Monterrey, Mexico March 3-5 2011
(invited)
2010
- Privacy Leaks with Mobile Phone Internet Access Collin Mulliner EPFL Lausanne, Switzerland November 3rd, 2010
(invited)
- Vulnerability Analysis of SMS Implementations on Mobile and Smart Phones Collin Mulliner Columbia University New York City, New York, USA August 9th, 2010 project page
- Vulnerability Analysis of SMS Implementations on Mobile and Smart Phones Collin Mulliner Stanford University Palo Alto, CA, USA August 5th, 2010 project page(invited)
- Vulnerability Analysis of SMS Implementations on Mobile and Smart Phones Collin Mulliner Samsung R&D San Jose, CA, USA August 4th, 2010 project page
2009
- Mobile Botnets Collin Mulliner T-Labs Workshop Berlin, Germany December 14th 2009
- Fuzzing the Phone in your Phone Collin Mulliner Recurity Labs Security Symposium (RSS) Berlin, Germany October 27th 2009 project page(invited)
- Injecting SMS Messages into Smart Phones for
Security Analysis Collin Mulliner T-Labs Scientific Workshop Berlin, Germany July 2009 project page
- Exploiting Symbian Collin Mulliner Nokia Research Center Helsinki, Finland April 2009 project page(invited)
2008
- Mobile Sicherheit Collin Mulliner Intensivseminar Hacking - Angriffe und Abwehrstrategien (Fraunhofer SIT) Darmstadt, Germany September 18th 2008
- The Home InfoPanel Collin Mulliner MetaRheinMain ChaosDays 111b Darmstadt, Germany September 5-7 2008PDF(not security research related)
2007
- More Fun with Blue Radio Waves alias: iamabanana MetaRheinMain ChaosDays 110b Darmstadt, Germany September 14-16 2007PDF
2006
- Exploiting PocketPC Collin Mulliner Graduate Colloquium Department of Computer Science, California State University Channel Islands, USA March 2006 project page(invited)
Thesis
Ph.D. Thesis
- On the Impact of the Cellular Modem on the Security of Mobile Phones Collin Mulliner Ph.D. Thesis Technische Universität Berlin, Germany December 2011 PDF
Advisor: Jean-Pierre Seifert
Master Thesis
- Security of Smart Phones Collin Mulliner Master's Thesis University of California Santa Barbara, U.S.A. June 2006 PDF
Advisor: Giovanni Vigna
Bachelor Thesis
In the Media (selection)
Professional Activities
Program Committee:
- 14th International Workshop on Information Security Applications (WISA2013), 2013
- 3rd International Workshop on Trustworthy Embedded Devices (TrustED), 2013
- 7th Workshop on Offensive Technologies (WOOT), 2013
- 8th ARES Conference (ARES), 2013
- 6th Workshop on Offensive Technologies (WOOT), 2012
- 9th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2012
- 1st International Workshop on Sensor Security (IWSS) at ARES, 2009
Reviewer Conference:
- External Reviewer for Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2013
- External Reviewer for Symposium on Hardware-Oriented Security and Trust (HOST), 2013
- External Reviewer for the 34th IEEE Symposium on Security & Privacy (Okland), 2013
- External Reviewer for the 13th International Symposium on Recent Advances in Intrusion Detection (RAID), 2010
- Reviewer for the Annual Computer Security Applications Conference (ACSAC), 2006
Reviewer Journal:
- Reviewer for the International Journal of Information Security, 2012
- Reviewer for the Communications of the ACM, 2010
Misc:
Contributions
Trivia
updated:
Mon Jun 10 18:26:49 CEST 2013