Systematizing Systematization of Knowledge

Since 2010, the IEEE Symposium on Security and Privacy (“Oakland” conference) has included papers on Systematization of Knowledge (SoK). This paper track grew out of discussions at the NSF/IARPA/NSA Workshop on the Science of Security held at the Claremont Resort in November 2008. This site collects all the Oakland SoK papers.

SoK Authors · Frequently Asked Questions
2010
Outside the Closed World: On Using Machine Learning For Network Intrusion DetectionRobin Sommer, Vern Paxson
All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but might have been afraid to ask)Thanassis Avgerinos, Edward Schwartz, David Brumley
State of the Art: Automated Black-Box Web Application Vulnerability TestingJason Bau, Elie Bursztein, Divij Gupta, John C. Mitchell
How Good are Humans at Solving CAPTCHAs? A Large Scale EvaluationElie Bursztein, Steven Bethard, John C. Mitchell, Dan Jurafsky, Céline Fabry
Bootstrapping Trust in Commodity ComputersBryan Parno, Jonathan M. McCune, Adrian Perrig
2011
Formalizing Anonymous Blacklisting SystemsRyan Henry, Ian Goldberg
Mobile Security Catching Up? - Revealing the nuts and bolts of the security of mobile devicesMichael Becher, Felix C. Freiling, Johannes Hoffmann, Thorsten Holz, Sebastian Uellenbeck, Christopher Wolf
A Formal Foundation for the Security Features of Physical FunctionsFrederik Armknecht, Roel Maes, Ahmad-Reza Sadeghi, Francois-Xavier Standaert, Christian Wachsmann
Timing- and Termination-Sensitive Secure Information Flow: Exploring a New ApproachVineeth Kashyap, Ben Wiedermann, Ben Hardekopf
2012
Prudent Practices for Designing Malware Experiments: Status Quo and OutlookChristian Rossow, Christian J. Dietrich, Chris Grier, Christian Kreibich, Vern Paxson, Norbert Pohlmann, Herbert Bos, Maarten van Steen
Dissecting Android Malware: Characterization and EvolutionYajin Zhou, Xuxian Jiang
The Psychology of Security for the Home Computer UserAdele Howe, Indrajit Ray, Mark Roberts, Malgorzata Urbanska, Zinta Byrne
Peek-a-Boo, I Still See you: Why Efficient Traffic Analysis Countermeasures FailKevin P. Dyer, Scott E. Coull, Thomas Ristenpart, Thomas Shrimpton
Third-Party Web Tracking Policy and TechnologyJonathan R. Mayer, John C. Mitchell
OB-PWS: Obfuscation-Based Private Web SearchEro Balsa, Carmela Troncoso, Claudia Diaz
The quest to replace passwords: A framework for comparative evaluation of web authentication schemesJoseph Bonneau, Cormac Herley, Paul C. van Oorschot, Frank Stajano
2013
SoK: Eternal War in MemoryLaszlo Szekeres, Mathias Payer, Tao Wei, Dawn Song
SoK: P2PWNED — Modeling and Evaluating the Resilience of Peer-to-Peer BotnetsChristian Rossow, Dennis Andriesse, Tillmann Werner, Brett Stone-Gross, Daniel Plohmann, Christian J. Dietrich, Herbert Bos
SoK: Secure Data DeletionJoel Reardon, David Basin, Srdjan Capkun
SoK: The Evolution of Sybil Defense via Social NetworksLorenzo Alvisi, Allen Clement, Alessandro Epasto, Silvio Lattanzi, Alessandro Panconesi
SoK: SSL and HTTPS: Revisiting Past Challenges and Evaluating Certificate Trust Model EnhancementsJeremy Clark, Paul C. van Oorschot
2014
SoK: Security and Privacy in Implantable Medical Devices and Body Area NetworksMichael Rushanan, Colleen Swanson, Denis Foo Kune, Aviel D. Rubin
SoK: Introspections on Trust and the Semantic GapBhushan Jain, Mirza Basim Baig, Dongli Zhang, Donald E. Porter, Radu Sion
2015
SoK: Research Perspectives and Challenges for Bitcoin and CryptocurrenciesJoseph Bonneau, Andrew Miller, Jeremy Clark, Arvind Narayanan, Joshua A. Kroll, Edward W. Felten
SoK: Secure MessagingNik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg, Matthew Smith
SoK: A comprehensive analysis of game-based ballot privacy definitionsDavid Bernhard, Véronique Cortier, David Galindo, Olivier Pereira, Bogdan Warinschi
SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time PackersXabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos Grueiro, Pablo Garcia Bringas
2016
SoK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Kruegel, Giovanni Vigna
SoK: Everyone Hates Robocalls: A Survey of Techniques against Telephone SpamHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon Ahn
SoK: Lessons Learned From Android Security Research For Appified Software PlatformsYasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl, Patrick McDaniel, Matthew Smith
SoK: Verifiability Notions for E-Voting ProtocolsVéronique Cortier, David Galindo, Ralf Kuesters, Johannes Mueller, Tomasz Truderung
SoK: Towards Grounding Censorship Circumvention in EmpiricismMichael C. Tschantz, Sadia Afroz, Anonymous, Vern Paxson
2017
SoK: Science, Security, and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van Oorschot
SoK: Cryptographically Protected Database SearchBenjamin Fuller, Mayank Varia, Arkady Yerukhimovich, Emily Shen, Ariel Hamlin, Vijay Gadepally, Richard Shay, John Darby Mitchell, Robert K. Cunningham
SoK: Exploiting Network PrintersJens Müller, Vladislav Mladenov, Juraj Somorovsky, Jörg Schwenk