VLDB 2026 Research / reviewers in the wild / expert
Filipo Sharevski
dblp:154/7105
· DBLP profile ↗
32ranked-venue papers
26as first author
25since 2021 · last 2026
0000-0003-3058-7255ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 18 first-author · 17 since 2021Human-computer interaction and ubiquitous computing · 10 · 8 first-author · 10 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerabstractQR codes are widely used, but can become the vector of phishing attacks (QRishing). To support users, we systematically developed a usable secure QR code scanner, SEQR (Security Enhanced QR code scanner). We based the SEQR’s design on two systematic reviews: (i) of academic literature (2015–2025), identifying 96 papers on QRishing, and (ii) of the MITRE ATT&CK® Mobile repository, finding 36 QRishing techniques. From these two sources, we categorized 60 potential attacks, and divided them between those that SEQR addresses only at the technology level, and those where SEQR involves the users in the decision. We evaluated SEQR effectiveness in thwarting attacks in a between-subjects online study (n = 556), where SEQR achieved 93.35% correct answers, compared to 75.24% for the Apple iOS QR code scanner and 65.11% for the Samsung Android QR code scanner. We implemented SEQR as an open source Android application, available on GitHub. Mattia Mossano, Maxime Veit, Tobias Länge, Benjamin Berens, Filipo Sharevski, Melanie Volkamer |
CHI | 5 |
| 2026 | Expert-led Debunking of Health Misinformation on TikTokabstractIn this work, we empirically evaluated expert-led debunking of health misinformation on TikTok with n=420 survey and n=20 interview participants. Unlike fact-checkers, health professionals debunk misinformation non-anonymously through video-against-video formats (stitching/”duetting”), rather than using labels. We analyzed 5,161 such posts to select six misinformation and six debunking videos across three common topics – two general health, two mental health, and two nutrition – for statistical comparison. Participants exposed to debunking videos believed misinformation claims significantly less than those exposed to misinformation videos in all six conditions. Experts were seen as more credible than misinformation creators, except in one instance involving mental health. Thematic analysis showed that expert-led debunking succeeded because experts’ videos aligned with the Debunking Handbook method for effective refutation. Experts’ credibility is derived mainly from being perceived as non-typical influencers who maintain reputable TikTok personas by providing qualified medical evidence and advice. Filipo Sharevski, Jennifer Vander Loop, Amy Devine, Peter Jachim, Sanchari Das 0001 |
CHI | 1 |
| 2026 | Maybe... I Don't Really Wanna Clone: Attitudes and Anticipated Harms of (Consensual) After-Death Cloning of One's Own and Voices of Entrusted Others
Jennifer Vander Loop, Filipo Sharevski, Lucy Davies, Partha Das Chowdhury |
SOUPS | 2 |
| 2025 | How Blind and Low-Vision Users Manage Their PasswordsabstractManaging passwords securely and conveniently is still an open problem for many users. Existing research has examined users' password management strategies and identified pain points, such as security concerns, leading to insecure practices. We investigate how Blind and Low-Vision (BLV) users tackle this problem and how password managers can assist them. This paper presents the results of a qualitative interview study with N = 33 BLV participants. We found that all participants utilize password managers to some extent, which they perceive as fairly accessible. However, the adoption is mainly driven by the convenience of storing and retrieving passwords. The security advantages -- generating strong, random passwords -- were avoided mainly due to the absence of practical accessibility. Password managers do not adhere to BLV users' underlying needs for agency, which stem from experiences with inaccessible software and vendors who deprioritize accessibility issues. Underutilization of password managers leads BLV users to adopt insecure practices, such as reusing predictable passwords or resorting to 'security through obscurity' by writing important credentials in braille. We conclude our analysis by discussing the need to implement practical accessibility and usability improvements for password managers as a way of establishing trust and secure practices while maintaining BLV users' agency. Alexander Ponticello, Filipo Sharevski, Simon Anell, Katharina Krombholz |
CCS | 2 |
| 2025 | "I have never seen that for Deaf people's content: " Deaf and Hard-of-Hearing User Experiences with Misinformation, Moderation, and Debunking on Social Media in the US
Filipo Sharevski, Oliver Alonzo, Sarah Hau |
CHI | 1 |
| 2025 | User Experiences with Abortion Misinformation on TikTok: Encounters, Assessment Strategies, and Response
Filipo Sharevski, Jennifer Vander Loop, Peter Jachim, Amy Devine, Emma Pieroni |
CHI | 1 |
| 2025 | "I Don't Think TikTok Really Cares About the Truth: " Experiences of Users Who Are Low Vision or Blind with Misinformation on TikTokabstractModerating misinformation on social media is a complex task of warning users about potentially harmful content while remaining reliable, unbiased, and non-judgmental. Though this is a valid concern, it doesn't exempt platforms like TikTok from making their soft moderation interventions inaccessible for users who are low vision or blind. Through interviews with 13 low vision or blind TikTok users, we learned that this was exactly the case - the informative cues used for soft moderation were inaccessible in 93% of the cases. To address this participatory exclusion, our participants proposed redesigns for navigable informative cues through auditory means or "audio frictions" that both warn the users and provide them with contextual information on why a particular content might be misleading, false, or generally harmful. Filipo Sharevski, Aziz Zeidieh |
ICWSM | 1 |
| 2025 | "You Creep! It Really Worked!": An Empirical Study of Telephone Scams with Cloned Familiar Voices and Trusted Caller IDsabstractTelephone scams often attempt to defraud or steal the identity of individuals by eliciting a response to a pressing request for payments or submission of information such as social security numbers. These calls usually come from numbers that individuals have not encountered before, and the request is passed through as a pre-recorded message with a generic voice. But AI-enabled voice cloning and the ability to spoof Caller IDs have given scammers the opportunity to run schemes targeted individuals with a cloned familiar voice coming from trusted numbers. This paper reports the findings from an empirical study that replicates this scenario with 14 participants (7 pairs of family relatives of friends) to capture the experiences of receiving such a scam call and responses to it. The results of our thematic analysis show that the familiar voice, coming from a trusted number of a family relative or a friend, is highly persuasive towards deceiving the call receiver (i.e., callee) to indeed follow through with the scammer’s request. The callee, together with the caller or the participants who volunteered their voices for cloning, saw this scam working particularly in the context of family emergencies, as real-world reports have surfaced about children held for ransom, grandchildren under arrest, or relatives in car accidents. The callers and callees saw no immediate way to fend off these “family emergency scams” than for families and friends to work on “family/friend codewords” that are hard to be inferred by the scammers (and thus cloned). We discuss our findings towards the development of user-centered interventions that would facilitate the detection of a wide range of AI-enabled voice cloning scams, in addition to the suggested personal ways of scam detection. Filipo Sharevski, Jennifer Vander Loop, Bill Evans, Alexander Ponticello |
NSPW | 1 |
| 2025 | (Blind) Users Really Do Heed Aural Telephone Scam WarningsabstractThis paper reports on a study exploring how two groups of individuals, legally blind$(n=36)$and sighted ones$(n=36)$, react to aural telephone scam warnings in naturalistic settings. As spoofing a CallerID is trivial, communicating the context of an incoming call instead offers a better possibility to warn a receiver about a potential scam. Usually, such warnings are visual in nature and fail to cater to users with visual disabilities. To address this exclusion, we developed an aural variant of telephone scam warnings and tested them in three conditions: baseline (no warning), short warning, and contextual warning that preceded the scam's content. We tested the two most common scam scenarios: fraud (interest rate reduction) and identity theft (social security number) by coldcalling participants and recording their actions, and debriefing and obtaining consent afterward. Only two participants “pressed one” as the scam demanded, both from the legally blind group that heard the contextual warning for the social security scenario. Upon close inspection, we learned that one of them did so because of accessibility issues with their screen reader and the other did so intentionally because the warning convinced them to waste the scammer's time, so they don't scam vulnerable people. Both the legally blind and sighted participants found the contextual warnings as powerful usable security cues that, together with STIR/SHAKEN indicators like Scam Likely, would provide robust protection against any type of scam. We also discussed the potential privacy implications of the contextual warnings and collected recommendations for usably accessible implementation. Filipo Sharevski, Jennifer Vander Loop, Bill Evans, Alexander Ponticello |
SP | 1 |
| 2025 | "Helps me Take the Post With a Grain of Salt: " Soft Moderation Effects on Accuracy Perceptions and Sharing Intentions of Inauthentic Political Content on X
Filipo Sharevski, Verena Distler, Florian Alt |
USENIX Security Symposium | 1 |
| 2025 | Social Media Misinformation and Voting Intentions: Older Adults' Experiences with Manipulative NarrativesabstractOlder adults habitually encounter misinformation, yet little is known about their experiences with it. In this study, we employed a mixed-methods approach, combining a survey (n=119) with semi-structured interviews ( n =21), to investigate how older adults in America conceptualize, discern, and contextualize social media misinformation. Given the historical context of misinformation being used to influence voting outcomes, our study specifically examined this phenomenon from a voting intention perspective. Our findings reveal that 62% of participants intending to vote Democrat perceived a manipulative political purpose behind the spread of misinformation, whereas only 5% of those intending to vote Republican believed that misinformation serves a political dissent purpose. Regardless of voting intentions, most participants relied on source heuristics and fact-checking to discern truth from misinformation on social media. A major concern among participants was the biased reasoning influenced by personal values and emotions affected by misinformation. Notably, 74% of participants intending to vote Democrat were concerned that misinformation would escalate extremism in the future. In contrast, those intending to vote Republican, those undecided, or those planning to abstain expressed concerns that misinformation would further erode trust in democratic institutions, particularly in public health and free and fair elections. During our interviews, we discovered that 63% of participants intending to vote Republican mentioned that Republican or conservative voices often disseminate misinformation, even though these participants were closely aligned with this political ideology. Filipo Sharevski, Jennifer Vander Loop, Sanchari Das 0001 |
Proc. ACM Hum. Comput. Interact. | 1 |
| 2024 | Blind and Low-Vision Individuals' Detection of Audio DeepfakesabstractAudio deepfakes are a form of deception where convincing speech sentences are synthesized through machine learning means to give an impression of a human speaker. Audio deepfakes emerge as an attractive vector for targeting users that rely on audio accessibility, such as individuals who are blind or low vision. The critical reliance on speech both as a medium and an affordance puts this population at an undue risk of being deceived as they rely solely on themselves to detect whether a piece of audio is a deepfake or not. To better understand the nature of this risk considering the nuanced reliance on assistive technologies such as screen readers, we conducted a user study with n=16 blind and low vision individuals from the US. Our participants achieved an overall discernment accuracy of 59%, and clips identified as deep fakes were only actually deepfakes in 50.8% of the cases (precision). The participants that self-identified as "low vision" performed slightly better (accuracy of 61%, precision of 64%) compared to the ones that self-identified as "blind" (accuracy of 55%, precision of 56%). Our qualitative results show that the participants in the "blind" group mostly considered a combination of infliction, imperfections in the voice, and the intensity in the speech delivery as discernment factors. The participants in the "low vision" group mostly used the speaker's pitch, enunciation, emotion, and the fluency and articulation of the speaker as discernment cues. Overall, participants felt that audio deepfakes have the potential to deceive visually impaired individuals with political disinformation, impersonate their voice in authentication and smart homes, and specifically target them with voice phishing and enhanced scams. Filipo Sharevski, Aziz Zeidieh, Jennifer Vander Loop, Peter Jachim |
CCS | 1 |
| 2024 | 'Debunk-It-Yourself': Health Professionals Strategies for Responding to Misinformation on TikTok
Filipo Sharevski, Jennifer Vander Loop, Peter Jachim, Amy Devine, Sanchari Das 0001 |
NSPW | 1 |
| 2024 | Children, Parents, and Misinformation on Social MediaabstractChildren encounter misinformation on social media in a similar capacity as their parents. Unlike their parents, children are an exceptionally vulnerable population because their cognitive abilities and emotional regulation are still maturing, rendering them more susceptible to misinformation and falsehoods online. Yet, little is known about children’s experience with misinformation as well as what their parents think of the misinformation’s effect on child development. To answer these questions, we combined a qualitative survey of parents (n=87) with semi-structured interviews of both parents and children (n=12). We found that children identify misinformation as content used to trick people on social media, such as deep fakes, memes with political context, or celebrity/influencer rumors. Children revealed they ask Siri whether a social media video or post is created to trick them before they search on Google or ask their parents about its accuracy. Parents expressed discontent that their children are impressionable to misinformation, stating that the burden falls on them to help their children develop critical thinking skills for navigating falsehoods on social media. Here, the majority of parents felt that schools should also teach these skills as well as media literacy to their children. Misinformation, according to both parents and children, affects the family relationships especially with grandparents with different political views than theirs. Filipo Sharevski, Jennifer Vander Loop |
SP | 1 |
| 2024 | Assessing Suspicious Emails with Banner Warnings Among Blind and Low-Vision Users in Realistic Settings
Filipo Sharevski, Aziz Zeidieh |
USENIX Security Symposium | 1 |
| 2023 | Folk Models of Misinformation on Social Media
Filipo Sharevski, Amy Devine, Emma Pieroni, Peter Jachim |
NDSS | 1 |
| 2023 | "I Just Didn't Notice It: " Experiences with Misinformation Warnings on Social Media amongst Users Who Are Low Vision or BlindabstractDealing with misinformation on social media is a complex affair as platforms have to continuously decide whether and how to moderate falsehoods and misleading content. The options available are either hard moderation i.e., content and account removal or soft moderation i.e., substantiate false or misleading posts with misinformation warning labels. These warning labels are implemented as visual frictions with the intention to interrupt the user’s immersive experience and “nudge” them towards a better truth discernment. The choice of visual friction poses the question whether these warning labels are accessible for users who are low vision or blind. From the first accounts of 29 such users in our study, we learned that this is not the case. Excluded as such, the misinformation warning labels we tested on three platforms – Facebook, YouTube, and TikTok – did not help 72.4% of the visually impaired participants towards a better truth discernment. Our participants, therefore, provided useful and actionable recommendations for inclusive design of misinformation warnings that could meaningfully help the overall effort for curbing falsehoods and misleading statements. Filipo Sharevski, Aziz Zeidieh |
NSPW | 1 |
| 2023 | Fight Fire with Fire: Hacktivists' Take on Social Media Misinformation
Filipo Sharevski, Benjamin Kessell |
SOUPS | 1 |
| 2022 | Misinformation warnings: Twitter's soft moderation effects on COVID-19 vaccine belief echoes
Filipo Sharevski, Raniem Alsaadi, Peter Jachim, Emma Pieroni |
Comput. Secur. | 1 |
| 2022 | "Alexa, What's a Phishing Email?": Training users to spot phishing emails using a voice assistantabstractAbstract This paper reports the findings from an empirical study investigating the effectiveness of using intelligent voice assistants, Amazon Alexa in our case, to deliver a phishing training to users. Because intelligent voice assistants can hardly utilize visual cues but provide for convenient interaction with users, we developed an interaction-based phishing training focused on the principles of persuasion with examples on how to look for them in phishing emails. To test the effectiveness of this training, we conducted a between-subject study where 120 participants were randomly assigned in three groups: no training, interaction-based training with Alexa, and a facts-and-advice training and assessed a vignette of 28 emails. The results show that the participants in the interaction-based group statistically outperformed the others when detecting phishing emails that employed the following persuasion principles (and/or combinations of): authority, authority/scarcity, commitment, commitment/liking, and scarcity/liking. The paper discusses the implication of this result for future phishing training and anti-phishing efforts. Filipo Sharevski, Peter Jachim |
EURASIP J. Inf. Secur. | 1 |
| 2022 | Socially Engineering a Polarizing Discourse on Facebook through Malware-Induced MisperceptionabstractThis paper reports the findings of a study testing a novel social engineering attack called Malware-induced Misperception (MIM). The goal of the MIM attack is to induce misperception by using a man-in-the-middle malware that covertly rearranges the linguistic content of an authentic social media post, web page, or an e-mail. The MIM attack was tested in controlled settings (N=311) where the malware covertly manipulated the linguistic content of a Facebook discourse to induce misperception about the climate of opinion on a polarizing issue (freedom of speech on college campuses) by making conservative-leaning comments appear as liberal-leaning. The induced misperception was assessed in the context of the spiral-of-silence theory. The theory predicts that polarizing issues discourage commenting on social media if an individual’s opinion diverges from the perceived climate of opinion on that issue. Consistent with the theory, the results suggest that the MIM attack can socially engineer the spiral-of-silence effect by manipulating the comments in a Facebook discourse to appeal to the individual’s political ideology and gender identity.Additional Key Words and Phrases: Malware-Induced Misperception (MIM); spiral-of-silence; social engineering; Facebook, web security Filipo Sharevski, Paige Treebridge, Peter Jachim, Audrey Li, Adam Babin, Jessica Westbrook |
Int. J. Hum. Comput. Interact. | 1 |
| 2021 | Two Truths and a Lie: Exploring Soft Moderation of COVID-19 Misinformation with Amazon AlexaabstractIn this paper, we analyzed the perceived accuracy of COVID-19 vaccine Tweets when they were spoken back by a third-party Amazon Alexa skill. We mimicked the soft moderation that Twitter applies to COVID-19 misinformation content in both forms of warning covers and warning tags to investigate whether the third-party skill could affect how and when users heed these warnings. The results from a 304-participant study suggest that the spoken back warning covers may not work as intended, even when converted from text to speech. We controlled for COVID-19 vaccination hesitancy and political leanings and found that the vaccination hesitant Alexa users ignored any type of warning as long as the Tweets align with their personal beliefs. The politically independent users trusted Alexa less than their politically-laden counterparts and that helped them accurately perceiving truthful COVID-19 information. We discuss soft moderation adaptations for voice assistants to achieve the intended effect of curbing COVID-19 misinformation. Filipo Sharevski, Donald Gover |
ARES | 1 |
| 2021 | Message-of-the-Day (MOTD) Banner Language Variations as an Adaptive Honeypot Deterrent of Unauthorized AccessabstractThis study investigates the effect of a Message-of-the-Day (MOTD) system banner, written in three languages: English, Russian, and Chinese, on deterring unauthorized access to publicly accessible systems. Banners have been used in both the physical and cyberspace realms as a method of signalling to trespassers that the defending entity is aware of, and directing against, malicious activity. We created a honeypot infrastructure with three ssh servers for each language variant, and measured the attempts of unauthorized access over a course of a regular week. The results suggest that the MOTD banner written in Russian attracted at least twice as many attempts of unauthorized access as the English and Chinese MOTD banners. The Russian MOTD banner received 38% of the attempts from US IP addresses with 3.710 failed password login attempts per session and 51% of the attempts from Chinese IP addresses with 2.958 failed password login attempts per session on average. This ratio, on the English MOTD banner, was US IP addresses: 52%, 3.986 failed password login attempts and Chinese IP addresses: 27%, 2.367 failed password login attempts. On the Chinese MOTD banner this ratio was US IP addresses: 48%, 2.568 failed password login attempts and Chinese IP addresses: 27%, 2.858 failed password login attempts. We discuss the implications of these results for incorporating language variations in MOTD banners as a deterrence strategy. Filipo Sharevski, Samuel Jevitz |
ARES | 1 |
| 2021 | VoxPop: An Experimental Social Media Platform for Calibrated (Mis)information DiscourseabstractVoxPop, shortened for Vox Populi, is an experimental social media platform that neither has an absolute “truth-keeping” mission nor an uncontrolled “free-speaking” vision. Instead, it allows discourses that naturally include (mis)information to contextualize among users with the aid of UX design and data science affordances and frictions. VoxPop introduces calibration metrics, namely a Faithfulness-To-Known-Facts (FTKF) score associated with each post and a Cumulative FTKF (C-FTKF) score associated with each user, appealing to the self-regulated participation using sociocognitive signals. The goal of VoxPop is not to become an ideal platform—that is impossible; rather, to bring to attention an adaptive approach in dealing with (mis)information rooted in social calibration instead of imposing or avoiding altogether punitive moderation. Filipo Sharevski, Peter Jachim, Emma Pieroni, Nathaniel Jachim |
NSPW | 1 |
| 2021 | Meet Malexa, Alexa's malicious twin: Malware-induced misperception through intelligent voice assistants
Filipo Sharevski, Peter Jachim, Paige Treebridge, Audrey Li, Adam Babin, Christopher Adadevoh |
Int. J. Hum. Comput. Stud. | 1 |
| 2020 | To tweet or not to tweet: covertly manipulating a Twitter debate on vaccines using malware-induced misperceptionsabstractTrolling and social bots have been proven as powerful tactics for manipulating the public opinion and sowing discord among Twitter users. This effort requires substantial content fabrication and account coordination to evade Twitter's detection of nefarious platform use. In this paper we explore an alternative tactic for covert social media interference by inducing misperceptions about genuine, non-trolling content from verified users. This tactic uses a malware that covertly manipulates targeted words, hashtags, and Twitter metrics before the genuine content is presented to a targeted user in a covert man-in-the-middle fashion. Early tests of the malware found that it is capable of achieving a similar goal as trolls and social bots, that is, silencing or provoking social media users to express their opinion in polarized debates on social media. Following this, we conducted experimental tests in controlled settings (N = 315) where the malware covertly manipulated the perception in a Twitter debate on the risk of vaccines causing autism. The empirical results demonstrate that inducing misperception is an effective tactic to silence users on Twitter when debating polarizing issues like vaccines. We used the findings to propose a solution for countering the effect of the malware-induced misperception that could also be used against trolls and social bots on Twitter. Filipo Sharevski, Peter Jachim, Kevin Florek |
ARES | 1 |
| 2020 | TrollHunter [Evader]: Automated Detection [Evasion] of Twitter Trolls During the COVID-19 PandemicabstractThis paper presents TrollHunter, an automated reasoning mechanism we used to hunt for trolls on Twitter during the COVID-19 pandemic in 2020. Trolls quickly seized the opportunity to create a COVID-19 infodemic by promulgating dubious content on Twitter. To counter the COVID-19 infodemic, the TrollHunter leverages a unique linguistic analysis of a multi-dimensional set of Twitter content features to detect whether or not a tweet was meant to troll. TrollHunter achieved 98.5% accuracy, 75.4% precision and 69.8% recall over a dataset of 1.3 million tweets. Without a final resolution of the pandemic in sight, it is unlikely that the trolls will go away, although they might be forced to evade automated hunting. To explore the plausibility of this strategy, we developed and tested an adversarial machine learning mechanism called TrollHunter-Evader. TrollHunter-Evader employs a Test Time Evasion (TTE) approach in a combination with a Markov chain-based mechanism to recycle originally trolling tweets. The recycled tweets were able to achieve a remarkable 40% decrease in the TrollHunter’s ability to correctly identify trolling tweets. Because the COVID-19 infodemic could have a harmful impact on the COVID-19 pandemic, we provide an elaborate discussion about the implications of employing adversarial machine learning to evade Twitter troll hunts. Peter Jachim, Filipo Sharevski, Paige Treebridge |
NSPW | 2 |
| 2019 | Manipulation of perceived politeness in a web-based email discourse through a malicious browser extensionabstractThis paper presents a specific man-in-the-middle exploit: Ambient Tactical Deception (ATD) in online communication, realized via a malicious web browser extension. Extensions manipulate web content in unobtrusive ways as ambient intermediaries of the overall browsing experience. In our previous work, we demonstrated that it is possible to employ tactical deception by making covert changes in the text content of a web page, regardless of the source. In this work, we investigated the application of ATD in a web-based email discourse where the objective is to manipulate the interpersonal perception without the knowledge of the involved parties. We focus on web-based email text because it is asynchronous and usually revised for clarity and politeness. Previous research has demonstrated that people's perception of politeness in online communication is based on three factors: the degree of imposition, the power of the receiver over the sender, and the social distance between them. We interviewed participants about their perception of these factors to establish the plausibility of ATD for email discourse. The results indicate that by covertly altering the politeness strategy in an email, it is possible for an ATD attacker to manipulate the receiver's perception on all of the politeness factors. Our findings support the Brown and Levinson's politeness theory and Walther's hyperpersonal model of email communication. Filipo Sharevski, Paige Treebridge, Jessica Westbrook |
NSPW | 1 |
| 2018 | Leveraging Cellular Intemet-of-Things for Resilient and Robust Disaster ManagementabstractTo improve operational efficiency, disaster management missions increasingly employ smart and interconnected devices. Autonomous robots are used for remote access, drones for impact zone surveys, and wireless sensors for human presence detection. The interconnection between these devices was mainly realized using wireless protocols for local and ad-hoc access to allow quick information exchange with the first responders. For large scale disasters, however, there is a need for a wide area wireless access, resilient to communication outages to provide robust operational efficiency by interconnecting large number of smart devices. To address this need, the article discusses how the recent advancements in Cellular IoT can be leveraged in a large-scale and complex disaster management missions. The CIoT technologies are also considered in the context of minimizing the time to restore normalcy in cooperation with the existing disaster management solutions. Filipo Sharevski |
GLOBECOM | 1 |
| 2018 | Malicious User Experience Design Research for CybersecurityabstractThis paper explores the factors and theory behind the user-centered research necessary to create a successful game-like prototype, and user experience, for malicious users in a cybersecurity context. We explore what is known about successful addictive design in the fields of video games and gambling to understand the allure of breaking into a system, and the joy of thwarting the security to reach a goal or a reward of data. Based on the malicious user research, game user research, and using the GameFlow framework, we propose a novel malicious user experience design approach. Adam Trowbridge, Filipo Sharevski, Jessica Westbrook |
NSPW | 2 |
| 2018 | User-targeted Denial-of-Service Attacks in LTE Mobile NetworksabstractMobile networks are prevalent in today's world, being used in a variety of applications ranging from personal use to the work environment and other. Ensuring security for users in a mobile network is therefore increasingly important. Denial-of-service attacks or DoS proved to be the biggest threat to mobile networks in recent years. A lot of work has been done in DoS targeting the infrastructure of the mobile network. User-targeted DoS attacks have been neglected in comparison. The fourth generation of cellular networks 4G LTE is the fastest growing mobile network in terms of subscriber numbers. The security aspect of mobile networks has improved throughout the generations, however, 4G proved to still have vulnerabilities in the signaling plane that allow a malicious attacker to target a specific user. Deploying a rogue base station and forcing the targeted user to connect to it is possible. The attacker could then deny selected services of the targeted user such as voice and SMS services. In this paper, we survey the work done on user-targeted DoS attacks in LTE networks. We analyze the 3GPP LTE standard specifications that allow such attacks. We also test the response of a LTE mobile device to tweaked Attach Accept messages during an Attach Procedure. We furthermore examine the conditions that affect the attack when we have equal priority cells. We finally present a case study of how a targeted user connected to an LTE network provider could be denied SMS and voice services therefore denying 2-factor authentication. We tested the scenarios using open-source implementations of the LTE network stack and widely available Software Defined Radios. Rami Ghannam, Filipo Sharevski, Anthony Chung |
WiMob | 2 |
| 2018 | Towards 5G cellular network forensicsabstractThe fifth generation (5G) of cellular networks will bring 10 Gb/s user speeds, 1000-fold increase in system capacity, and 100 times higher connection density. In response to these requirements, the 5G networks will incorporate technologies like CUPS, NFV, network slicing, and CIoT. Each of these 5G features requires system adaptations to enable acquisition and forensic processing of cellular network evidence. This paper reviews the digital forensics mechanisms for Lawful Interception and user localization available in LTE and LTE-Advanced networks together with the associated evidence types, tools for forensic analysis, and supporting legal framework. The challenges and potential adaptations for retaining these capabilities in the future 5G networks are also discussed to outline the future research directions for cellular network forensics. Filipo Sharevski |
EURASIP J. Inf. Secur. | 1 |