VLDB 2026 Research / reviewers in the wild / expert
Abhijeet Srivastava
dblp:220/2108
· DBLP profile ↗
3ranked-venue papers
0as first author
2since 2021 · last 2023
0000-0003-4490-0046ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | AutoSpill: Credential Leakage from Mobile Password ManagersabstractPassword managers (PMs) are becoming increasingly popular on mobile devices, especially on small-screen devices, mainly due to the convenience of automatically filling credentials into login forms. Modern mobile OSes advocate for system-wide autofill frameworks to support autofilling on browsers as well as other apps. Mobile OSes also empower apps to directly render web content within WebView controls without redirecting users to the main browser. \par We present a novel technique, called AutoSpill, to leak users' saved credentials during an autofill operation on a webpage loaded into an app's WebView. AutoSpill conveniently dodges the secure autofill process. The majority of popular Android PMs considered in our experiments were found vulnerable to AutoSpill; even when the app hosting the WebView is not actively participating in the leak. Android intermediates in the autofill process because of its app sandboxing. Hence, the responsibility for any credential leakage is often stranded between PMs and the Android system. We investigate the root causes of AutoSpill and propose countermeasures to fundamentally fix AutoSpill for both the parties. We responsibly disclosed our findings to the affected PMs and Android security team. Ankit Gangwal, Abhijeet Srivastava |
CODASPY | 3 |
| 2022 | BLEWhisperer: Exploiting BLE Advertisements for Data Exfiltration
Ankit Gangwal, Riccardo Spolaor, Abhijeet Srivastava |
ESORICS (1) | 4 |
| 2018 | Testing Cloud Applications under Cloud-Uncertainty Performance EffectsabstractThe paradigm shift of deploying applications to the cloud has introduced both opportunities and challenges. Although clouds use elasticity to scale resource usage at runtime to help meet an application's performance requirements, developers are still challenged by unpredictable performance, little control of execution environment, and differences among cloud service providers, all while being charged for their cloud usages. Application performance stability is particularly affected by multi-tenancy in which the hardware is shared among varying applications and virtual machines. Developers porting their applications need to meet performance requirements, but testing on the cloud under the effects of performance uncertainty is difficult and expensive, due to high cloud usage costs. This paper presents a first approach to testing an application with typical inputs for how its performance will be affected by performance uncertainty, without incurring undue costs of brute force testing in the cloud. We specify cloud uncertainty testing criteria, design a test-based strategy to characterize the black box cloud's performance distributions using these testing criteria, and support execution of tests to characterize the resource usage and cloud baseline performance of the application to be deployed. Importantly, we developed a smart test oracle that estimates the application's performance with certain confidence levels using the above characterization test results and determines whether it will meet its performance requirements. We evaluated our testing approach on both the Chameleon cloud and Amazon web services; results indicate that this testing strategy shows promise as a cost-effective approach to test for performance effects of cloud uncertainty when porting an application to the cloud. Wei Wang 0054, Ningjing Tian, Sunzhou Huang, Sen He 0002, Abhijeet Srivastava, Mary Lou Soffa, Lori L. Pollock |
ICST | 5 |