SearcharxivSearch

arXiv subjects

Robert Hines

Publications and source records attributed to Robert Hines.

6 recordsLinked to original sources

Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils

Software supply chain frameworks, such as the US NIST Secure Software Development Framework (SSDF), detail what tasks software development organizations are recommended or mandated to adopt to reduce security risk. However, to further reduce the risk of similar attacks occurring, software organizations benefit from knowing what tasks mitigate attack techniques the attackers are currently using to address specific threats, prioritize tasks, and close mitigation gaps. The goal of this study is to aid software organizations in reducing the risk of software supply chain attacks by systematically synthesizing how framework tasks mitigate the attack techniques used in the SolarWinds, Log4j, and XZ Utils attacks. We qualitatively analyzed 106 Cyber Threat Intelligence (CTI) reports of the 3 attacks to gather the attack techniques. We then systematically constructed a mapping between attack techniques and the 73 tasks enumerated in 10 software supply chain frameworks. Afterward, we established and ranked priority tasks that mitigate attack techniques. The three mitigation tasks with the highest scores are role-based access control, system monitoring, and boundary protection. Additionally, three mitigation tasks were missing from all ten frameworks, including sustainable open-source software and environmental scanning tools. Thus, software products would still be vulnerable to software supply chain attacks even if organizations adopted all recommended tasks.

cs.SE

Public-key encryption from a trapdoor one-way embedding of $SL_2(\mathbb{N}$)

We obfuscate words of a given length in a free monoid on two generators with a simple factorization algorithm (namely $SL_2(\mathbb{N})$) to create a public-key encryption scheme. We provide a reference implementation in Python and suggested parameters. The security analysis is between weak and non-existent, left to future work.

cs.CR

An infinite product on the Teichmüller space of the once-punctured torus

We prove the identity $$ \prod_γ\left(\frac{e^{l(γ)}+1}{e^{l(γ)}-1}\right)^{2h}=\exp\left(\frac{l_1+l_2+l_3}{2}\right), $$ (or $$ \prod_γ\left(\frac{t(γ)^2}{t(γ)^2-4}\right)^h=\frac{t_1+\sqrt{t_1^2-4}}{2}\cdot\frac{t_2+\sqrt{t_2^2-4}}{2}\cdot\frac{t_3+\sqrt{t_3^2-4}}{2} $$ in trace coordinates), where the product is over all simple closed geodesics on the once-punctured torus, $l(γ)=2\operatorname{arccosh}(t(γ)/2)$ is the length of the geodesic, and $l_i$ ($t_i$) are the lengths (traces) of any triple of simple geodesics $\{γ_i\}$ intersecting at a single point. The exponent $h=h(γ;\{γ_i\})$ is a positive integer "height" which increases as we move away from the chosen triple $\{γ_i\}$ in its orbit under $SL_2(\mathbb{Z})$ (see Figure 1 for the "definition by picture"). For comparison, a short proof of McShane's identity $$ \sum_γ\frac{1}{1+e^{l(γ)}}=\frac{1}{2}=\sum_γ\frac{1-\sqrt{1-4/t(γ)^2}}{2} $$ in the same spirit is given in an appendix. Both proofs are elementary and proceed by "integrating" around the chosen triple $\{γ_i\}$ in its Teichmüller orbit.

math.GT

Examples of badly approximable vectors over number fields

We consider approximation of vectors $\mathbf{z}\in F\otimes\mathbb{R}\cong\mathbb{R}^r\times\mathbb{C}^s$ by elements of a number field $F$ and construct examples of badly approximable vectors. These examples come from compact subspaces of $SL_2(\mathcal{O}_F)\backslash SL_2(F\otimes\mathbb{R})$ naturally associated to (totally indefinite, anisotropic) $F$-rational binary quadratic and Hermitian forms, a generalization of the well-known fact that quadratic irrationals are badly approximable over $\mathbb{Q}$.

math.NT

Badly approximable numbers over imaginary quadratic fields

We recall the notion of nearest integer continued fractions over the Euclidean imaginary quadratic fields $K$ and characterize the "badly approximable" numbers, ($z$ such that there is a $C(z)>0$ with $|z-p/q|\geq C/|q|^2$ for all $p/q\in K$), by boundedness of the partial quotients in the continued fraction expansion of $z$. Applying this algorithm to "tagged" indefinite integral binary Hermitian forms demonstrates the existence of entire circles in $\mathbb{C}$ whose points are badly approximable over $K$, with effective constants. By other methods (the Dani correspondence), we prove the existence of circles of badly approximable numbers over any imaginary quadratic field, with loss of effectivity. Among these badly approximable numbers are algebraic numbers of every even degree over $\mathbb{Q}$, which we characterize. All of the examples we consider are associated with cocompact Fuchsian subgroups of the Bianchi groups $SL_2(\mathcal{O})$, where $\mathcal{O}$ is the ring of integers in an imaginary quadratic field.

math.NT

The Dynamics of Super-Apollonian Continued Fractions

We examine a pair of dynamical systems on the plane induced by a pair of spanning trees in the Cayley graph of the Super-Apollonian group of Graham, Lagarias, Mallows, Wilks and Yan. The dynamical systems compute Gaussian rational approximations to complex numbers and are "reflective" versions of the complex continued fractions of A. L. Schmidt. They also describe a reduction algorithm for Lorentz quadruples, in analogy to work of Romik on Pythagorean triples. For these dynamical systems, we produce an invertible extension and an invariant measure, which we conjecture is ergodic. We consider some statistics of the related continued fraction expansions, and we also examine the restriction of these systems to the real line, which gives a reflective version of the usual continued fraction algorithm. Finally, we briefly consider an alternate setup corresponding to a tree of Lorentz quadruples ordered by arithmetic complexity.

math.NT