Dudu Mimran

dblp:22/4696 · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
12since 2021 · last 2026
0009-0004-9610-6156ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SecMate: Multi-agent Adaptive Cybersecurity Troubleshooting with Tri-Context Personalization
Yair Meidan, Omri Haller, Yulia Moshan, Shahaf David, Dudu Mimran, Yuval Elovici, Asaf Shabtai
DBSec5
2026 ImpReSS: Designing and Evaluating a Lightweight Implicit Recommender System in Conversational Support Agents
abstract
Large language model (LLM)-powered AI agents have transformed customer support, yet little research has addressed the integration of product recommendations into problem-solving dialogues. We introduce ImpReSS, a lightweight implicit recommender system for conversational support agents based on small language and embedding models, making it suitable for on-premise deployment where data privacy is critical. Unlike traditional conversational recommender systems (CRSs), ImpReSS does not assume purchasing intent. Instead, it identifies relevant solution product categories (SPCs) from the conversational context to assist in problem resolution. Our offline evaluation on three real-world datasets demonstrates strong performance, achieving an MRR@1 of up to 0.477 and outperforming five competing methods, including a state-of-the-art CRS. Algorithmic relevance alone is insufficient for effective adoption. A controlled user study with 144 participants shows that the perceived naturalness of recommendations depends strongly on their delivery. Conventional UI patterns such as pop-ups were rated as more appropriate than in-conversation insertions. Optimal timing varied by context, suggesting that recommendations should adapt dynamically to user needs. Thematic analysis of participant feedback further highlights a need for greater user agency, including the ability to interact with, question, and explore alternatives. We present the first comprehensive study of integrating implicitly-inferred recommendations in support dialogues. Our findings highlight the challenges of balancing accuracy with interaction design and yield empirically grounded implications for integrating recommender systems into conversational support agents.
Omri Haller, Yair Meidan, Dudu Mimran, Yuval Elovici, Asaf Shabtai
IUI3
2025 CodeCloak: A Method for Mitigating Code Leakage by LLM Code Assistants
abstract
Large language model (LLM)-based code assistants are increasingly popular among developers. These tools help improve developers’ coding efficiency and reduce errors by providing real-time suggestions based on the developer’s codebase. While beneficial, the use of these tools can inadvertently expose the developer’s proprietary code to the code assistant service provider during the development process. In this work, we propose a method aimed at mitigating the risk of code leakage when using LLM-based code assistants. CodeCloak is a novel, real-time, deep reinforcement learning agent that manipulates the prompts before sending them to the code assistant model. CodeCloak aims to achieve the following two contradictory objectives: (i) minimizing code leakage, while (ii) preserving relevant and useful suggestions for the developer. Our evaluation performed on multiple code assistant models, demonstrates CodeCloak’s effectiveness on a diverse set of code repositories of varying sizes, as well as its transferability across different models. We validate our approach through human judgment of suggestion quality and testing on complete repositories simulating real development scenarios.The source code is available at: https://github.com/AmitFinkman/CodeCloak
Amit Finkman, Avishag Shapira, Eden Bar-Kochva, Inbar Maimon, Dudu Mimran, Yuval Elovici, Asaf Shabtai
ECAI5
2025 LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI
abstract
As the number and sophistication of cyber attacks have increased, threat hunting has become a critical aspect of active security, enabling proactive detection and mitigation of threats before they cause significant harm. Open-source cyber threat intelligence (OSCTI) is a valuable resource for threat hunters, however, it often comes in unstructured formats that require further manual analysis. Previous studies aimed at automating OSCTI analysis are limited since (1) they failed to provide actionable outputs, (2) they did not take advantage of images present in OSCTI sources, and (3) they focused on on-premises environments, overlooking the growing importance of cloud environments. To address these gaps, we propose LLMCloudHunter, a novel framework that leverages large language models (LLMs) to automatically generate generic-signature detection rule candidates from textual and visual OSCTI data. We evaluated the quality of the rules generated by the proposed framework using 20 annotated real-world cloud threat reports. The results show that our framework achieved a precision of 83% and recall of 99% for the task of accurately extracting API calls made by the threat actor and a precision of 99% with a recall of 97% for IoCs. Additionally, 99.18% of the generated detection rule candidates were successfully compiled and converted into Splunk queries.
Yuval Schwartz, Lavi Ben-Shimol, Dudu Mimran, Yuval Elovici, Asaf Shabtai
WWW3
2025 Detection of compromised functions in a serverless cloud environment
Lavi Ben-Shimol, Danielle Lavi, Eitan Klevansky, Oleg Brodt, Dudu Mimran, Yuval Elovici, Asaf Shabtai
Comput. Secur.5
2025 CORAL: Container Online Risk Assessment with Logical attack graphs
David Tayouri, Omri Sgan Cohen, Inbar Maimon, Dudu Mimran, Yuval Elovici, Asaf Shabtai
Comput. Secur.4
2025 Adversarial machine learning threat analysis and remediation in Open Radio Access Network (O-RAN)
Edan Habler, Ron Biton, Dan Avraham, Eitan Klevansky, Dudu Mimran, Oleg Brodt, Heiko Lehmann, Yuval Elovici, Asaf Shabtai
J. Netw. Comput. Appl.5
2025 Observability and Incident Response in Managed Serverless Environments Using Ontology-Based Log Monitoring
abstract
In fully managed serverless environments, cloud service providers handle the underlying infrastructure, reducing application developers’ operational and maintenance efforts. However, these environments limit the use of traditional cybersecurity frameworks and tools, compromising observability and situational awareness capabilities for security tasks (e.g., risk assessment, incident response). Additionally, existing security frameworks for serverless applications often lack generalizability across architectures and require specialized expertise. In this paper, we propose a three-layer security stack for fully managed serverless applications. The first layer establishes a foundational generic ontology that models serverless application resources and their interactions using API logs. In the second layer, the ontology is leveraged via perimeterless pipeline, to map the logs into a unified application activity KG, and in the third layer, two situational awareness tools that utilize the graph-based representation are implemented: (1) an incident response dashboard that leverages the ontology to visualize and examine application activity logs in the context of cybersecurity alerts; our user study showed that this dashboard enabled participants to respond 10% more accurately and almost twice as fast than the examined baseline tool, and (2) a criticality of asset (CoA) risk assessment framework that enables efficient expert-based prioritization in cybersecurity contexts; our expert-based questionnaire demonstrated strong agreement, achieving a Kendall-W score of 0.7179.
Lavi Ben-Shimol, Edita Grolman, Aviad Elyashar, Inbar Maimon, Dudu Mimran, Oleg Brodt, Martin Strassmann, Heiko Lehmann, Yuval Elovici, Asaf Shabtai
IEEE Trans. Cloud Comput.5
2024 SMART: Serverless Module Analysis and Recognition Technique for Managed Applications
abstract
Serverless Function-as-a-Service (FaaS) environments enable developers to build and run cloud applications without the need to manage the underlying servers and computing infrastructure, allowing them to focus on implementing the application logic. Such environments contain numerous functions and dynamic resources, e.g., APIs and databases, making it challenging to gain insight and context of internal events i.e., recognize modules. Module in a serverless application is a set of functions and resources, that represents a functional unit that shares logical context. This paper presents SMART, a method for automatic analysis and recognition of modules for managed serverless applications. The proposed method creates an event-based graph by analyzing the standard serverless logs that document events involving the application’s functions and resources and utilizes well-known community detection algorithms (such as Louvain), with graph centrality metrics (such as degree centrality) to recognize the modules. SMART enables high-level visibility of the application’s structure and logical context which can facilitate security analysis and contribute to improved decision-making of incident response handlers, who typically do not have direct access to the application’s design and code, which can lead to challenges in fully understanding the system’s intricacies. We focused on the popular Amazon Web Services (AWS) Lambda serverless computing platform and evaluated the proposed method on three different demo applications (Airline Booking, VOD, and E-commerce). We compared SMART’s performance to four overlapping community detection algorithms and showed that it outperformed them in the task of module recognition, with a maximum improvement of 61% on the omega index metric compared to the Speaker-Listener Label Propagation algorithm. In addition, we demonstrate that the use of large language models (LLMs) with the knowledge gained by SMART can enrich security analysis insights.
Adi Ashkenazi, Edita Grolman, Aviad Elyashar, Dudu Mimran, Oleg Brodt, Yuval Elovici, Asaf Shabtai
CCGrid4
2024 Green Security: A Framework for Measurement and Optimization of Energy Consumption of Cybersecurity Solutions
abstract
Information and communication technology (ICT) is playing an expanding and critical role in our modern lives. Due to its proliferation, ICT has a significant impact on global energy consumption, which in turn contributes to air pollution, climate change, water pollution, etc. The proliferation of ICT has been accompanied by the emergence of cybersecurity technologies and solutions, which play an integral role in society's digitalization. Wherever there is ICT, there is a need to secure it, resulting in an increase in global cybersecurity energy consumption as well. This paper discusses the energy-related aspects of cybersecurity solutions and defines a “Green Security” taxonomy. We highlight the inefficiencies stemming from various cybersecu-rity practices, such as processing the same data repeatedly. Within this context, we analyze cybersecurity solutions in common use cases, demonstrating the inherent energy consumption inefficiencies. In addition, we propose a method of measuring the energy consumed by cybersecurity solutions and present several optimization strategies that reduce their energy consumption. We evaluate our proposed optimization strategies and demonstrate their ability to reduce energy consumption while considering the organizational risk profile and maintaining the required security level.
Sagi Brudni, Sapir Anidgar, Oleg Brodt, Dudu Mimran, Asaf Shabtai, Yuval Elovici
EuroS&P4
2024 OSSIntegrity: Collaborative open-source code integrity verification
Mor Nahum, Edita Grolman, Inbar Maimon, Dudu Mimran, Oleg Brodt, Aviad Elyashar, Yuval Elovici, Asaf Shabtai
Comput. Secur.4
2022 Security of Open Radio Access Networks
Dudu Mimran, Ron Biton, Yehonatan Kfir, Eitan Klevansky, Oleg Brodt, Heiko Lehmann, Yuval Elovici, Asaf Shabtai
Comput. Secur.1
2014 Mobile malware detection through analysis of deviations in application network behavior
Asaf Shabtai, Lena Tenenboim-Chekina, Dudu Mimran, Lior Rokach, Bracha Shapira, Yuval Elovici
Comput. Secur.3
2013 Nesto - Network selection and traffic offloading system for android mobile devices
abstract
In this paper we present Nesto, a network selection and offloading system for android based mobile devices. Nesto chooses the best connectivity solution between available heterogeneous wireless networks using network switching. The suggested framework supports several configurable policies and addresses the following requirements: battery energy saving, bandwidth maximization, an offloading strategy for cellular operators and granting the best available network QoS to current running applications (e.g. minimizing delay and jitter for voip applications). Nesto is designed to support two primary connectivity modes: a traditional single connectivity mode and a full dual mode, where both the cellular and ad-hoc WiFi networks are used simultaneously. The full dual mode allows us to extend the always best connected definition from the device level to the application level, i.e.: selecting the best network for each application. This paper presents the architecture of Nesto and the different network selection optimization models. We evaluate our solution with simulated data and with real network traffic traces. Preliminary results indicate that: (1) energy efficient policies rely on the single connectivity operation mode, but they can be controlled to improve other networking QoS measures with minimum energy overhead, (2) using the full dual operation mode improves the overall networking performances of the device, (3) the full dual operation mode enables an efficient always best connected solution at the application level, optimizing the relevant measures for each application type.
Ariel Bar, Dudu Mimran, Lena Tenenboim-Chekina, Yuval Elovici, Bracha Shapira
IWCMC2