VLDB 2026 Research / reviewers in the wild / expert
Devdatta Akhawe
dblp:12/8302
· DBLP profile ↗
17ranked-venue papers
5as first author
2since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | SoK: Hate, Harassment, and the Changing Landscape of Online AbuseabstractWe argue that existing security, privacy, and antiabuse protections fail to address the growing threat of online hate and harassment. In order for our community to understand and address this gap, we propose a taxonomy for reasoning about online hate and harassment. Our taxonomy draws on over 150 interdisciplinary research papers that cover disparate threats ranging from intimate partner violence to coordinated mobs. In the process, we identify seven classes of attacks—such as toxic content and surveillance—that each stem from different attacker capabilities and intents. We also provide longitudinal evidence from a three-year survey that hate and harassment is a pervasive, growing experience for online users, particularly for at-risk communities like young adults and people who identify as LGBTQ+. Responding to each class of hate and harassment requires a unique strategy and we highlight five such potential research directions that ultimately empower individuals, communities, and platforms to do so. Kurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh, Elie Bursztein, Sunny Consolvo, Nicola Dell, Zakir Durumeric, Patrick Gage Kelley, Deepak Kumar 0006, Damon McCoy, Sarah Meiklejohn, Thomas Ristenpart, Gianluca Stringhini |
SP | 2 |
| 2021 | Hopper: Modeling and Detecting Lateral Movement
Grant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson, Stefan Savage, Geoffrey M. Voelker, David A. Wagner 0001 |
USENIX Security Symposium | 3 |
| 2018 | Cracking ShadowCrypt: Exploring the Limitations of Secure I/O Systems in Internet BrowsersabstractAbstract An important line of privacy research is investigating the design of systems for secure input and output (I/O) within Internet browsers. These systems would allow for users’ information to be encrypted and decrypted by the browser, and the specific web applications will only have access to the users’ information in encrypted form. The state-of-the-art approach for a secure I/O system within Internet browsers is a system called ShadowCrypt created by UC Berkeley researchers [23]. This paper will explore the limitations of ShadowCrypt in order to provide a foundation for the general principles that must be followed when designing a secure I/O system within Internet browsers. First, we developed a comprehensive UI attack that cannot be mitigated with popular UI defenses, and tested the efficacy of the attack through a user study administered on Amazon Mechanical Turk. Only 1 of the 59 participants who were under attack successfully noticed the UI attack, which validates the stealthiness of the attack. Second, we present multiple attack vectors against Shadow-Crypt that do not rely upon UI deception. These attack vectors expose the privacy weaknesses of Shadow DOM—the key browser primitive leveraged by ShadowCrypt. Finally, we present a sketch of potential countermeasures that can enable the design of future secure I/O systems within Internet browsers. Michael Freyberger, Warren He, Devdatta Akhawe, Michelle L. Mazurek, Prateek Mittal |
Proc. Priv. Enhancing Technol. | 3 |
| 2016 | pASSWORD tYPOS and How to Correct Them SecurelyabstractWe provide the first treatment of typo-tolerant password authentication for arbitrary user-selected passwords. Such a system, rather than simply rejecting a login attempt with an incorrect password, tries to correct common typographical errors on behalf of the user. Limited forms of typo-tolerance have been used in some industry settings, but to date there has been no analysis of the utility and security of such schemes. We quantify the kinds and rates of typos made by users via studies conducted on Amazon Mechanical Turk and via instrumentation of the production login infrastructure at Dropbox. The instrumentation at Dropbox did not record user passwords or otherwise change authentication policy, but recorded only the frequency of observed typos. Our experiments reveal that almost 10% of login attempts fail due to a handful of simple, easily correctable typos, such as capitalization errors. We show that correcting just a few of these typos would reduce login delays for a significant fraction of users as well as enable an additional 3% of users to achieve successful login. We introduce a framework for reasoning about typo-tolerance, and investigate the seemingly inherent tension here between security and usability of passwords. We use our framework to show that there exist typo-tolerant authentication schemes that can get corrections for "free": we prove they are as secure as schemes that always reject mistyped passwords. Building off this theory, we detail a variety of practical strategies for securely implementing typo-tolerance. Rahul Chatterjee 0001, Anish Athayle, Devdatta Akhawe, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 3 |
| 2015 | ASPIRE: Iterative Specification Synthesis for Security
Kevin Zhijie Chen, Warren He, Devdatta Akhawe, Vijay D'Silva, Prateek Mittal, Dawn Song |
HotOS | 3 |
| 2014 | ShadowCrypt: Encrypted Web Applications for EveryoneabstractA number of recent research and industry proposals discussed using encrypted data in web applications. We first present a systematization of the design space of web applications and highlight the advantages and limitations of current proposals. Next, we present ShadowCrypt, a previously unexplored design point that enables encrypted input/output without trusting any part of the web applications. ShadowCrypt allows users to transparently switch to encrypted input/output for text-based web applications. ShadowCrypt runs as a browser extension, replacing input elements in a page with secure, isolated shadow inputs and encrypted text with secure, isolated cleartext. ShadowCrypt's key innovation is the use of Shadow DOM, an upcoming primitive that allows low-overhead isolation of DOM trees. Evaluation results indicate that ShadowCrypt has low overhead and of practical use today. Finally, based on our experience with ShadowCrypt, we present a study of 17 popular web applications, across different domains, and the functionality impact and security advantages of encrypting the data they handle. Warren He, Devdatta Akhawe, Sumeet Jain, Elaine Shi, Dawn Song |
CCS | 2 |
| 2014 | The Emperor's New Password Manager: Security Analysis of Web-based Password Managers
Warren He, Devdatta Akhawe, Dawn Song |
USENIX Security Symposium | 3 |
| 2013 | Data-Confined HTML5 Applications
Devdatta Akhawe, Frank Li 0001, Warren He, Prateek Saxena, Dawn Song |
ESORICS | 1 |
| 2013 | Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness
Devdatta Akhawe, Adrienne Porter Felt |
USENIX Security Symposium | 1 |
| 2013 | An Empirical Study of Vulnerability Rewards Programs
Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
USENIX Security Symposium | 2 |
| 2013 | Here's my cert, so trust me, maybe?: understanding TLS errors on the webabstractWhen browsers report TLS errors, they cannot distinguish between attacks and harmless server misconfigurations; hence they leave it to the user to decide whether continuing is safe. However, actual attacks remain rare. As a result, users quickly become used to "false positives" that deplete their attention span, making it unlikely that they will pay sufficient scrutiny when a real attack comes along. Consequently, browser vendors should aim to minimize the number of low-risk warnings they report. To guide that process, we perform a large-scale measurement study of common TLS warnings. Using a set of passive network monitors located at different sites, we identify the prevalence of warnings for a total population of about 300,000 users over a nine-month period. We identify low-risk scenarios that consume a large chunk of the user attention budget and make concrete recommendations to browser vendors that will help maintain user attention in high-risk situations. We study the impact on end users with a data set much larger in scale than the data sets used in previous TLS measurement studies. A key novelty of our approach involves the use of internal browser code instead of generic TLS libraries for analysis, providing more accurate and representative results. Devdatta Akhawe, Johanna Amann, Matthias Vallentin, Robin Sommer |
WWW | 1 |
| 2012 | Privilege Separation in HTML5 Applications
Devdatta Akhawe, Prateek Saxena, Dawn Song |
USENIX Security Symposium | 1 |
| 2012 | How to Ask for Permission
Adrienne Porter Felt, Serge Egelman, Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
HotSec | 4 |
| 2011 | A Systematic Analysis of XSS Sanitization in Web Application Frameworks
Joel Weinberger, Prateek Saxena, Devdatta Akhawe, Matthew Finifter, Richard Shin, Dawn Song |
ESORICS | 3 |
| 2011 | Do You Know Where Your Data Are? Secure Data Capsules for Deployable Data Protection
Petros Maniatis, Devdatta Akhawe, Kevin R. Fall, Elaine Shi, Dawn Song |
HotOS | 2 |
| 2010 | Towards a Formal Foundation of Web SecurityabstractWe propose a formal model of web security based on an abstraction of the web platform and use this model to analyze the security of several sample web mechanisms and applications. We identify three distinct threat models that can be used to analyze web applications, ranging from a web attacker who controls malicious web sites and clients, to stronger attackers who can control the network and/or leverage sites designed to display user-supplied content. We propose two broadly applicable security goals and study five security mechanisms. In our case studies, which include HTML5 forms, Referer validation, and a single sign-on solution, we use a SAT-based model-checking tool to find two previously known vulnerabilities and three new vulnerabilities. Our case study of a Kerberos-based single sign-on system illustrates the differences between a secure network protocol using custom client software and a similar but vulnerable web protocol that uses cookies, redirects, and embedded links instead. Devdatta Akhawe, Adam Barth, Peifung E. Lam, John C. Mitchell, Dawn Song |
CSF | 1 |
| 2010 | A Symbolic Execution Framework for JavaScriptabstractAs AJAX applications gain popularity, client-side JavaScript code is becoming increasingly complex. However, few automated vulnerability analysis tools for JavaScript exist. In this paper, we describe the first system for exploring the execution space of JavaScript code using symbolic execution. To handle JavaScript code's complex use of string operations, we design a new language of string constraints and implement a solver for it. We build an automatic end-to-end tool, Kudzu, and apply it to the problem of finding client-side code injection vulnerabilities. In experiments on 18 live web applications, Kudzu automatically discovers 2 previously unknown vulnerabilities and 9 more that were previously found only with a manually-constructed test suite. Prateek Saxena, Devdatta Akhawe, Steve Hanna, Feng Mao, Stephen McCamant, Dawn Song |
IEEE Symposium on Security and Privacy | 2 |