VLDB 2026 Research / reviewers in the wild / expert
Oleksii Starov
dblp:134/8950
· DBLP profile ↗
17ranked-venue papers
7as first author
4since 2021 · last 2024
0000-0002-2796-6345ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 4 first-authorComputer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Automated Generation of Behavioral Signatures for Malicious Web Campaigns
Shaown Sarker, William Melicher, Oleksii Starov, Anupam Das 0001, Alexandros Kapravelos |
ISC (2) | 3 |
| 2022 | PhishInPatterns: measuring elicited user interactions at scale on phishing websitesabstractDespite phishing attacks and detection systems being extensively studied, phishing is still on the rise and has recently reached an all-time high. Attacks are becoming increasingly sophisticated, leveraging new web design patterns to add perceived legitimacy and, at the same time, evade state-of-the-art detectors and web security crawlers. Karthika Subramani, William Melicher, Oleksii Starov, Phani Vadrevu, Roberto Perdisci |
IMC | 3 |
| 2021 | Catching Transparent Phish: Analyzing and Detecting MITM Phishing ToolkitsabstractFor over a decade, phishing toolkits have been helping attackers automate and streamline their phishing campaigns. Man-in-the- Middle (MITM) phishing toolkits are the latest evolution in this space, where toolkits act as malicious reverse proxy servers of online services, mirroring live content to users while extracting cre- dentials and session cookies in transit. These tools further reduce the work required by attackers, automate the harvesting of 2FA- authenticated sessions, and substantially increase the believability of phishing web pages. Brian Kondracki, Babak Amin Azad, Oleksii Starov, Nick Nikiforakis |
CCS | 3 |
| 2021 | Fingerprinting in Style: Detecting Browser Extensions via Injected Style Sheets
Pierre Laperdrix, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis |
USENIX Security Symposium | 2 |
| 2020 | Web Runner 2049: Evaluating Third-Party Anti-bot Services
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
DIMVA | 2 |
| 2020 | Short Paper - Taming the Shape Shifter: Detecting Anti-fingerprinting Browsers
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
DIMVA | 2 |
| 2019 | Everyone is Different: Client-side Diversification for Defending Against Extension Fingerprinting
Erik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis, Adam Doupé |
USENIX Security Symposium | 2 |
| 2019 | Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloatabstractIn this paper, we investigate to what extent the page modifications that make browser extensions fingerprintable are necessary for their operation. We characterize page modifications that are completely unnecessary for the extension's functionality as extension bloat. By analyzing 58,034 extensions from the Google Chrome store, we discovered that 5.7% of them were unnecessarily identifiable because of extension bloat. To protect users against unnecessary extension fingerprinting due to bloat, we describe the design and implementation of an in-browser mechanism that provides coarse-grained access control for extensions on all websites. The proposed mechanism and its built-in policies, does not only protect users from fingerprinting, but also offers additional protection against malicious extensions exfiltrating user data from sensitive websites. Oleksii Starov, Pierre Laperdrix, Alexandros Kapravelos, Nick Nikiforakis |
WWW | 1 |
| 2018 | Betrayed by Your Dashboard: Discovering Malicious Campaigns via Web AnalyticsabstractTo better understand the demographics of their visitors and their paths through their websites, the vast majority of modern website owners make use of third-party analytics platforms, such as, Google Analytics and ClickTale. Given that all the clients of a third-party analytics platform report to the same server, the tracking requests need to contain identifiers that allow the analytics server to differentiate between their clients. In this paper, we analyze the analytics identifiers utilized by eighteen different third-party analytics platforms and show that these identifiers enable the clustering of seemingly unrelated websites as part of a common third-party analytics account (i.e. websites whose analytics are managed by a single person or team). We focus our attention on malicious websites that also utilize third-party web analytics and show that threat analysts can utilize web analytics to both discover previously unknown malicious pages in a threat-agnostic fashion, as well as to cluster malicious websites into campaigns. We build a system for automatically identifying, isolating, and querying analytics identifiers from malicious pages and use it to discover an additional 11K live domains that use analytics associated with malicious pages. We show how our system can be used to improve the coverage of existing blacklists, discover previously unknown phishing campaigns, identify malicious binaries and Android apps, and even aid in attribution of malicious domains with protected WHOIS information. Oleksii Starov, Najmehalsadat Miramirkhani, Nick Nikiforakis |
WWW | 1 |
| 2017 | Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile BrowsersabstractMuch of recent research on mobile security has focused on malicious applications. Although mobile devices have powerful browsers that are commonly used by users and are vulnerable to at least as many attacks as their desktop counterparts, mobile web security has not received the attention that it deserves from the community. In particular, there is no longitudinal study that investigates the evolution of mobile browser vulnerabilities over the diverse set of browsers that are available out there. In this paper, we undertake the first such study, focusing on UI vulnerabilities among mobile browsers. We investigate and quantify vulnerabilities to 27 UI-related attacks---compiled from previous work and augmented with new variations of our own---across 128 browser families and 2,324 individual browser versions spanning a period of more than 5 years. In the process, we collect an extensive dataset of browser versions, old and new, from multiple sources. We also design and implement a browser-agnostic testing framework, called Hindsight, to automatically expose browsers to attacks and evaluate their vulnerabilities. We use Hindsight to conduct the tens of thousands of individual attacks that were needed for this study. We discover that 98.6% of the tested browsers are vulnerable to at least one of our attacks and that the average mobile web browser is becoming less secure with each passing year. Overall, our findings support the conclusion that mobile web security has been ignored by the community and must receive more attention. Meng Luo 0002, Oleksii Starov, Nima Honarmand, Nick Nikiforakis |
CCS | 2 |
| 2017 | Dial One for Scam: A Large-Scale Analysis of Technical Support Scams
Najmehalsadat Miramirkhani, Oleksii Starov, Nick Nikiforakis |
NDSS | 2 |
| 2017 | XHOUND: Quantifying the Fingerprintability of Browser ExtensionsabstractIn recent years, researchers have shown that unwanted web tracking is on the rise, as advertisers are trying to capitalize on users' online activity, using increasingly intrusive and sophisticated techniques. Among these, browser fingerprinting has received the most attention since it allows trackers to uniquely identify users despite the clearing of cookies and the use of a browser's private mode. In this paper, we investigate and quantify the fingerprintability of browser extensions, such as, AdBlock and Ghostery. We show that an extension's organic activity in a page's DOM can be used to infer its presence, and develop XHound, the first fully automated system for fingerprinting browser extensions. By applying XHound to the 10,000 most popular Google Chrome extensions, we find that a significant fraction of popular browser extensions are fingerprintable and could thus be used to supplement existing fingerprinting methods. Moreover, by surveying the installed extensions of 854 users, we discover that many users tend to install different sets of fingerprintable browser extensions and could thus be uniquely, or near-uniquely identifiable by extension-based fingerprinting. We use XHound's results to build a proof-of-concept extension-fingerprinting script and show that trackers can fingerprint tens of extensions in just a few seconds. Finally, we describe why the fingerprinting of extensions is more intrusive than the fingerprinting of other browser and system properties, and sketch two different approaches towards defending against extension-based fingerprinting. Oleksii Starov, Nick Nikiforakis |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | Extended Tracking Powers: Measuring the Privacy Diffusion Enabled by Browser ExtensionsabstractUsers have come to rely on browser extensions to realize features that are not implemented by browser vendors. Extensions offer users the ability to, among others, block ads, de-clutter websites, enrich pages with third-party content, and take screenshots. At the same time, because of their privileged position inside a user's browser, extensions have access to content and functionality that is not available to webpages, such as, the ability to conduct and read cross-origin requests, as well as get access to a browser's history and cookie jar. Oleksii Starov, Nick Nikiforakis |
WWW | 1 |
| 2016 | Measuring and Mitigating AS-level Adversaries Against Tor
Rishab Nithyanand, Oleksii Starov, Phillipa Gill, Adva Zair, Michael Schapira |
NDSS | 2 |
| 2016 | No Honor Among Thieves: A Large-Scale Analysis of Malicious Web ShellsabstractWeb shells are malicious scripts that attackers upload to a compromised web server in order to remotely execute arbitrary commands, maintain their access, and elevate their privileges. Despite their high prevalence in practice and heavy involvement in security breaches, web shells have never been the direct subject of any study. In contrast, web shells have been treated as malicious blackboxes that need to be detected and removed, rather than malicious pieces of software that need to be analyzed and, in detail, understood. In this paper, we report on the first comprehensive study of web shells. By utilizing different static and dynamic analysis methods, we discover and quantify the visible and invisible features offered by popular malicious shells, and we discuss how attackers can take advantage of these features. For visible features, we find the presence of password bruteforcers, SQL database clients, portscanners, and checks for the presence of security software installed on the compromised server. In terms of invisible features, we find that about half of the analyzed shells contain an authentication mechanism, but this mechanism can be bypassed in a third of the cases. Furthermore, we find that about a third of the analyzed shells perform homephoning, i.e., the shells, upon execution, surreptitiously communicate to various third parties with the intent of revealing the location of new shell installations. By setting up honeypots, we quantify the number of third-party attackers benefiting from shell installations and show how an attacker, by merely registering the appropriate domains, can completely take over all installations of specific vulnerable shells. Oleksii Starov, Johannes Dahse, Syed Sharique Ahmad, Thorsten Holz, Nick Nikiforakis |
WWW | 1 |
| 2016 | Are You Sure You Want to Contact Us? Quantifying the Leakage of PII via Website Contact FormsabstractAbstract The majority of commercial websites provide users the ability to contact them via dedicated contact pages. In these pages, users are typically requested to provide their names, email addresses, and reason for contacting the website. This effectively makes contact pages a gateway from being anonymous or pseudonymous, i.e., identified via stateful and stateless identifiers, to being eponymous. As such, the environment where users provide their personally identifiable information (PII) has to be trusted and free from intentional and unintentional information leaks. In this paper, we report on the first large-scale study of PII leakage via contact pages of the 100,000 most popular sites of the web. We develop a reliable methodology for identifying and interacting with contact forms as well as techniques that allow us to discover the leakage of PII towards thirdparties, even when that information is obfuscated. Using these methods, we witness the leakage of PII towards third-parties in a wide range of ways, including the leakage through third-party form submissions, third-party scripts that collect PII information from a first-party page, and unintended leakage through a browser’s Referer header. To recover the lost control of users over their PII, we design and develop Formlock, a browser extension that warns the user when contact forms are using PII-leaking practices, and provides the ability to comprehensively lock-down a form so that a user’s details cannot be, neither accidentally, nor intentionally, leaked to third parties Oleksii Starov, Phillipa Gill, Nick Nikiforakis |
Proc. Priv. Enhancing Technol. | 1 |
| 2013 | Cloud Testing for Mobile Software Systems - Concept and PrototypingabstractAbstract: This paper describes an approach for increasing the effectiveness of mobile software system testing. A Cloud Testing of Mobile Systems (CTOMS) framework is presented in the form of a cloud service that provides the ability to run tests on a variety of remote mobile devices. This framework is based on a heterogeneous networked system that connects operational computers, mobile devices, and databases with software applications. Our research focuses on building a concept and a prototype of CTOMS that supports testing Android mobile applications in the cloud. CTOMS allows multidirectional testing, providing the opportunities to test an application on different devices and/or operating system (OS) versions and new device models for their compatibility with the newest OS versions and the most popular applications. Another new aspect is to embed the test model, specifically the appropriate testing techniques for mobile development, within the framework. For users, this model will provide suggestions from CTOMS about the test methods, criteria, coverage, and possible test cases. These suggestions are based on available configurations, statistics, and resource constraints. 1 Oleksii Starov, Sergiy A. Vilkomir, Vyacheslav S. Kharchenko |
ICSOFT | 1 |