VLDB 2026 Research / reviewers in the wild / expert
Mashael Al Sabah
dblp:213/7971 · also Mashael AlSabah
· DBLP profile ↗
17ranked-venue papers
7as first author
5since 2021 · last 2026
0000-0001-6764-8280ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 7 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond RTT: An Adversarially Robust Two-Tiered Approach For Residential Proxy Detection
Temoor Ali, Shehel Yoosuf, Mouna Rabhi, Mashael Al Sabah, Hao Yun |
NDSS | 4 |
| 2025 | StructTransform: A Scalable Attack Surface for Safety-Aligned Large Language Models
Shehel Yoosuf, Temoor Ali, Ahmed Lekssays, Mashael Al Sabah, Issa M. Khalil |
ESORICS (1) | 4 |
| 2023 | DeviceWatch: A Data-Driven Network Analysis Approach to Identifying Compromised Mobile Devices with Graph-InferenceabstractWe propose to identify compromised mobile devices from a network administrator’s point of view. Intuitively, inadvertent users (and thus their devices) who download apps through untrustworthy markets are often lured to install malicious apps through in-app advertisements or phishing. We thus hypothesize that devices sharing similar apps would have a similar likelihood of being compromised, resulting in an association between a compromised device and its apps. We propose to leverage such associations to identify unknown compromised devices using the guilt-by-association principle. Admittedly, such associations could be relatively weak as it is hard, if not impossible, for an app to automatically download and install other apps without explicit user initiation. We describe how we can magnify such associations by carefully choosing parameters when applying graph-based inferences. We empirically evaluate the effectiveness of our approach on real datasets provided by a major mobile service provider. Specifically, we show that our approach achieves nearly 98% AUC (area under the ROC curve) and further detects as many as 6 ~ 7 times of new compromised devices not covered by the ground truth by expanding the limited knowledge on known devices. We show that the newly detected devices indeed present undesirable behavior in terms of leaking private information and accessing risky IPs and domains. We further conduct in-depth analysis of the effectiveness of graph inferences to understand the unique structure of the associations between mobile devices and their apps, and its impact on graph inferences, based on which we propose how to choose key parameters. Euijin Choo, Mohamed Nabeel, Mashael Al Sabah, Issa M. Khalil, Ting Yu 0001, Wei Wang 0012 |
ACM Trans. Priv. Secur. | 3 |
| 2022 | Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionabstractTor~\citetor is the most widely used anonymous communication network with millions of daily users~\citetormetrics. Since Tor provides server and client anonymity, hundreds of malware binaries found in the wild rely on it to hide their presence and hinder Command & Control (C&C) takedown operations. We believe Tor is a paramount tool enabling online freedom and privacy, and blocking it to defend against such malware is infeasible for both users and organizations. In this work, we present effective traffic analysis approaches that can accurately identify Tor-based malware communication. We collect hundreds of Tor-based malware binaries, execute and examine more than 47,000 active encrypted malware connections and compare them with benign browsing traffic. In addition to traditional traffic analysis features (which work at the connection level), we propose global host-level network features to capture peculiar malware communication fingerprints across host logs. Our experiments confirm that our models are able to detect "zero-day'' malware connections with 0.7% FPR even when malware connections constitute less than 5% of Tor traces in the test set. Using multi-labeling approaches, we are able to accurately detect the malware behavior-based classes (grayware, ransomware, etc). Finally, we evaluate the robustness of our models on real-world enterprise logs and show that the classifiers can identify infected hosts even with missing features. Priyanka Dodia, Mashael Al Sabah, Omar Alrawi, Tao Wang 0012 |
CCS | 2 |
| 2022 | Content-Agnostic Detection of Phishing Domains using Certificate Transparency and Passive DNSabstractExisting phishing detection techniques mainly rely on blacklists or content-based analysis, which are not only evadable, but also exhibit considerable detection delays as they are reactive in nature. We observe through our deep dive analysis that artifacts of phishing are manifested in various sources of intelligence related to a domain even before its contents are online. In particular, we study various novel patterns and characteristics computed from viable sources of data including Certificate Transparency Logs, and passive DNS records. To compare benign and phishing domains, we construct thoroughly-verified realistic benign and phishing datasets. Our analysis shows clear differences between benign and phishing domains that can pave the way for content-agnostic approaches to predict phishing domains even before the contents of these webpages are up and running. Mashael Al Sabah, Mohamed Nabeel, Yazan Boshmaf, Euijin Choo |
RAID | 1 |
| 2020 | Investigating MMM Ponzi Scheme on BitcoinabstractCybercriminals exploit cryptocurrencies to carry out illicit activities. In this paper, we focus on Ponzi schemes that operate on Bitcoin and perform an in-depth analysis of MMM, one of the oldest and most popular Ponzi schemes. Based on 423K transactions involving 16K addresses, we show that: (1) Starting Sep 2014, the scheme goes through three phases over three years. At its peak, MMM circulated more than 150M dollars a day, after which it collapsed by the end of Jun 2016. (2) There is a high income inequality between MMM members, with the daily Gini index reaching more than 0.9. The scheme also exhibits a zero-sum investment model, in which one member's loss is another member's gain. The percentage of victims who never made any profit has grown from 0% to 41% in five months, during which the top-earning scammer has made 765K dollars in profit. (3) The scheme has a global reach with 80 different member countries but a highly-asymmetrical flow of money between them. While India and Indonesia have the largest pairwise flow in MMM, members in Indonesia have received 12x more money than they have sent to their counterparts in India. Yazan Boshmaf, Charith Elvitigala, Husam Al Jawaheri, Primal Wijesekera, Mashael Al Sabah |
AsiaCCS | 5 |
| 2020 | Deanonymizing Tor hidden service users through Bitcoin transactions analysis
Husam Al Jawaheri, Mashael Al Sabah, Yazan Boshmaf, Aiman Erbad |
Comput. Secur. | 2 |
| 2019 | Empirical Performance Evaluation of QUIC Protocol for Tor Anonymity NetworkabstractTor's anonymity network is one of the most widely used anonymity networks online, it consists of thousands of routers run by volunteers. Tor preserves the anonymity of its users by relaying the traffic through a number of routers (called onion routers) forming a circuit. The current design of Tor's transport layer suffers from a number of problems affecting the performance of the network. Several researches proposed changes in the transport design in order to eliminate the effect of these problems and improve the performance of Tor's network. In this paper. we propose "QuicTor", an improvement to the transport layer of Tor's network by using Google's protocol "QUIC" instead of TCP. QUIC was mainly developed to eliminate TCP's latency introduced from the handshaking delays and the head-of-line blocking problem. We provide an empirical evaluation of our proposed design and compare it to two other proposed designs, IMUX and PCTCP. We show that QuicTor significantly enhances the performance of Tor's network. Lamiaa Basyoni, Aiman Erbad, Mashael Al Sabah, Noora Fetais, Mohsen Guizani |
IWCMC | 3 |
| 2019 | BlockTag: Design and Applications of a Tagging System for Blockchain Analysis
Yazan Boshmaf, Husam Al Jawaheri, Mashael Al Sabah |
SEC | 3 |
| 2018 | Your culture is in your password: An analysis of a demographically-diverse password dataset
Mashael Al Sabah, Gabriele Oligeri, Ryan Riley |
Comput. Secur. | 1 |
| 2017 | PriviPK: Certificate-less and secure email communication
Mashael Al Sabah, Alin Tomescu, Ilia A. Lebedev, Dimitrios Serpanos, Srini Devadas |
Comput. Secur. | 1 |
| 2017 | Context-aware RAON middleware for opportunistic network
Gabriel Lau, Mashael Al Sabah, Muhammad Jaseemuddin, Hooman Razavi, M. Bhuiyan |
Pervasive Mob. Comput. | 2 |
| 2015 | Circuit Fingerprinting Attacks: Passive Deanonymization of Tor Hidden Services
Albert Kwon, Mashael Al Sabah, David Lazar, Marc Dacier, Srini Devadas |
USENIX Security Symposium | 2 |
| 2013 | PCTCP: per-circuit TCP-over-IPsec transport for anonymous communication overlay networksabstractRecently, there have been several research efforts to design a transport layer that meets the security requirements of anonymous communications while maximizing the network performance experienced by users. In this work, we argue that existing proposals suffer from several performance and deployment issues and we introduce PCTCP, a novel anonymous communication transport design for overlay networks that addresses the shortcomings of the previous proposals. In PCTCP, every overlay path, or circuit, is assigned a separate kernel-level TCP connection that is protected by IPsec, the standard security layer for IP. Mashael Al Sabah, Ian Goldberg 0001 |
CCS | 1 |
| 2013 | The Path Less Travelled: Overcoming Tor's Bottlenecks with Traffic Splitting
Mashael Al Sabah, Kevin S. Bauer, Tariq Elahi, Ian Goldberg 0001 |
Privacy Enhancing Technologies | 1 |
| 2012 | Enhancing Tor's performance using real-time traffic classificationabstractTor is a low-latency anonymity-preserving network that enables its users to protect their privacy online. It consists of volunteer-operated routers from all around the world that serve hundreds of thousands of users every day. Due to congestion and a low relay-to-client ratio, Tor suffers from performance issues that can potentially discourage its wider adoption, and result in an overall weaker anonymity to all users. Mashael Al Sabah, Kevin S. Bauer, Ian Goldberg 0001 |
CCS | 1 |
| 2011 | DefenestraTor: Throwing Out Windows in Tor
Mashael Al Sabah, Kevin S. Bauer, Ian Goldberg 0001, Dirk Grunwald, Damon McCoy, Stefan Savage, Geoffrey M. Voelker |
PETS | 1 |