Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Abdelberi Chaabane

dblp:02/8037 · also Chaabane Abdelberi · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-authorComputer networks · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
4 papers
Internet architecture and protocols · 58% Network measurement and analytics · 42%
Network and information security
5 papers
Privacy and data protection · 39% Web and mobile security · 32% Network security · 29%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%

Topics — the 8 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Internet architecture and protocols
domain name system
0.732018
From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop · Internet Measurement Conference 2018
WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration · Internet Measurement Conference 2016
Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers · USENIX Security Symposium 2017
Internet architecture and protocols › domain name system
domain registration
0.422018
From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop · Internet Measurement Conference 2018
Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers · USENIX Security Symposium 2017
Web and mobile security › mobile security
android security
0.312017
Semi-automated discovery of server-based information oversharing vulnerabilities in Android applications · ISSTA 2017
Privacy and data protection
information leakage
0.312017
Semi-automated discovery of server-based information oversharing vulnerabilities in Android applications · ISSTA 2017
Software maintenance and evolution
software dependencies
0.312017
Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the Web · NDSS 2017
Network measurement and analytics › internet measurement
censorship measurement
0.212014
Censorship in the Wild: Analyzing Internet Filtering in Syria · Internet Measurement Conference 2014
Network security › censorship
internet censorship
0.212014
Censorship in the Wild: Analyzing Internet Filtering in Syria · Internet Measurement Conference 2014
Recommender systems
user profiling
0.012012
You are what you like! Information leakage through users' Interests · NDSS 2012

Methods — techniques the papers use, named apart from their topics

log analysis · 0.4static program analysis · 0.3dynamic analysis · 0.3
YearPublicationVenuePosition
2019 A Decade of Mal-Activity Reporting: A Retrospective Analysis of Internet Malicious Activity Blacklists
abstract
This paper focuses on reporting of Internet malicious activity (or mal-activity in short) by public blacklists with the objective of providing a systematic characterization of what has been reported over the years, and more importantly, the evolution of reported activities. Using an initial seed of 22 blacklists, covering the period from January 2007 to June 2017, we collect more than 51 million mal-activity reports involving 662K unique IP addresses worldwide. Leveraging the Wayback Machine, antivirus (AV) tool reports and several additional public datasets (e.g., BGP Route Views and Internet registries) we enrich the data with historical meta-information including geo-locations (countries), autonomous system (AS) numbers and types of mal-activity. Furthermore, we use the initially labelled dataset of ~1.57 million mal-activities (obtained from public blacklists) to train a machine learning classifier to classify the remaining unlabeled dataset of ~44 million mal-activities obtained through additional sources. We make our unique collected dataset (and scripts used) publicly available for further research. The main contributions of the paper are a novel means of report collection, with a machine learning approach to classify reported activities, characterization of the dataset and, most importantly, temporal analysis of mal-activity reporting behavior. Inspired by P2P behavior modeling, our analysis shows that some classes of mal-activities (e.g., phishing) and a small number of mal-activity sources are persistent, suggesting that either blacklist-based prevention systems are ineffective or have unreasonably long update periods. Our analysis also indicates that resources can be better utilized by focusing on heavy mal-activity contributors, which constitute the bulk of mal-activities.
Benjamin Zi Hao Zhao, Muhammad Ikram 0001, Hassan Jameel Asghar, Mohamed Ali Kâafar, Abdelberi Chaabane, Kanchana Thilakarathna
AsiaCCS5
2018 From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop
Tobias Lauinger, Ahmet Salih Buyukkayhan, Abdelberi Chaabane, William K. Robertson, Engin Kirda
Internet Measurement Conference3
2017 Semi-automated discovery of server-based information oversharing vulnerabilities in Android applications
abstract
Modern applications are often split into separate client and server tiers that communicate via message passing over the network. One well-understood threat to privacy for such applications is the leakage of sensitive user information either in transit or at the server. In response, an array of defensive techniques have been developed to identify or block unintended or malicious information leakage. However, prior work has primarily considered privacy leaks originating at the client directed at the server, while leakage in the reverse direction -- from the server to the client -- is comparatively under-studied. The question of whether and to what degree this leakage constitutes a threat remains an open question. We answer this question in the affirmative with Hush, a technique for semi-automatically identifying Server-based InFormation OvershariNg (SIFON) vulnerabilities in multi-tier applications. In particular, the technique detects SIFON vulnerabilities using a heuristic that overshared sensitive information from server-side APIs will not be displayed by the application's user interface. The technique first performs a scalable static program analysis to screen applications for potential vulnerabilities, and then attempts to confirm these candidates as true vulnerabilities with a partially-automated dynamic analysis. Our evaluation over a large corpus of Android applications demonstrates the effectiveness of the technique by discovering several previously-unknown SIFON vulnerabilities in eight applications.
William Koch, Abdelberi Chaabane, Manuel Egele, William K. Robertson, Engin Kirda
ISSTA2
2017 Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the Web
Tobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William K. Robertson, Christo Wilson, Engin Kirda
NDSS2
2017 Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers
Tobias Lauinger, Abdelberi Chaabane, Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William K. Robertson
USENIX Security Symposium2
2016 WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, William K. Robertson, Engin Kirda
Internet Measurement Conference3
2014 Censorship in the Wild: Analyzing Internet Filtering in Syria
abstract
Internet censorship is enforced by numerous governments worldwide, however, due to the lack of publicly available information, as well as the inherent risks of performing active measurements, it is often hard for the research community to investigate censorship practices in the wild. Thus, the leak of 600GB worth of logs from 7 Blue Coat SG-9000 proxies, deployed in Syria to filter Internet traffic at a country scale, represents a unique opportunity to provide a detailed snapshot of a real-world censorship ecosystem.
Abdelberi Chaabane, Terence Chen, Mathieu Cunche, Emiliano De Cristofaro, Arik Friedman, Mohamed Ali Kâafar
Internet Measurement Conference1
2014 A Closer Look at Third-Party OSN Applications: Are They Leaking Your Personal Information?
Abdelberi Chaabane, Yuan Ding 0003, Ratan Dey, Mohamed Ali Kâafar, Keith W. Ross
PAM1
2013 How Much Is Too Much? Leveraging Ads Audience Estimation to Evaluate Public Profile Uniqueness
Terence Chen, Abdelberi Chaabane, Pierre-Ugo Tournoux, Mohamed Ali Kâafar, Roksana Boreli
Privacy Enhancing Technologies2
2013 Holiday Pictures or Blockbuster Movies? Insights into Copyright Infringement in User Uploads to One-Click File Hosters
Tobias Lauinger, Kaan Onarlioglu, Abdelberi Chaabane, Engin Kirda, William K. Robertson, Mohamed Ali Kâafar
RAID3
2012 You are what you like! Information leakage through users' Interests
Abdelberi Chaabane, Gergely Ács, Mohamed Ali Kâafar
NDSS1
2010 Digging into Anonymous Traffic: A Deep Analysis of the Tor Anonymizing Network
abstract
Users' anonymity and privacy are among the major concerns of today's Internet. Anonymizing networks are then poised to become an important service to support anonymous-driven Internet communications and consequently enhance users' privacy protection. Indeed, Tor an example of anonymizing networks based on onion routing concept attracts more and more volunteers, and is now popular among dozens of thousands of Internet users. Surprisingly, very few researches shed light on such an anonymizing network. Beyond providing global statistics on the typical usage of Tor in the wild, we show that Tor is actually being is-used, as most of the observed traffic belongs to P2P applications. In particular, we quantify the BitTorrent traffic and show that the load of the latter on the Tor network is underestimated because of encrypted BitTorrent traffic (that can go unnoticed). Furthermore, this paper provides a deep analysis of both the HTTP and BitTorrent protocols giving a complete overview of their usage. We do not only report such usage in terms of traffic size and number of connections but also depict how users behave on top of Tor. We also show that Tor usage is now diverted from the onion routing concept and that Tor exit nodes are frequently used as 1-hop SOCKS proxies, through a so-called tunneling technique. We provide an efficient method allowing an exit node to detect such an abnormal usage. Finally, we report our experience in effectively crawling bridge nodes, supposedly revealed sparingly in Tor.
Abdelberi Chaabane, Pere Manils, Mohamed Ali Kâafar
NSS1