VLDB 2026 Research / reviewers in the wild / expert
Andrei Bytes
dblp:224/4384
· DBLP profile ↗
4ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0003-2419-9221ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | FieldFuzz: In Situ Blackbox Fuzzing of Proprietary Industrial Automation Runtimes via the NetworkabstractNetworked Programmable Logic Controllers (PLCs) are proprietary industrial devices utilized in critical infrastructure that execute control logic applications in complex proprietary runtime environments that provide standardized access to the hardware resources in the PLC. These control applications are programmed in domain-specific IEC 61131-3 languages, compiled into a proprietary binary format, and process data provided via industrial protocols. Control applications present an attack surface threatened by manipulated traffic. For example, remote code injection in a control application would directly allow to take over the PLC, threatening physical process damage and the safety of human operators. However, assessing the security of control applications is challenging due to domain-specific challenges and the limited availability of suitable methods. Network-based fuzzing is often the only way to test such devices but is inefficient without guidance from execution tracing. Andrei Bytes, Prashant Hari Narayan Rajput, Constantine Doumanidis, Michail Maniatakos, Jianying Zhou 0001, Nils Ole Tippenhauer |
RAID | 1 |
| 2021 | Countering Concurrent Login Attacks in "Just Tap" Push-based Authentication: A Redesign and Usability EvaluationsabstractIn this paper, we highlight a fundamental vulnerability associated with the widely adopted “Just Tap” push-based authentication in the face of a concurrency attack, and propose the method REPLICATE, a redesign to counter this vulnerability. In the concurrency attack, the attacker launches the login session at the same time the user initiates a session, and the user may be fooled, with high likelihood, into accepting the push notification which corresponds to the attacker's session, thinking it is their own. The attack stems from the fact that the login notification is not explicitly mapped to the login session running on the browser in the Just Tap approach. REPLICATE attempts to address this fundamental flaw by having the user approve the login attempt by replicating the information presented on the browser session over to the login notification, such as by moving a key in a particular direction, choosing a particular shape, etc. We report on the design and a systematic usability study of REPLICATE. Even without being aware of the vulnerability, in general, participants placed multiple variants of REPLICATE in competition to the Just Tap and fairly above PIN-based authentication. Jay Prakash, Clarice Chua Qing Yu, Tanvi Ravindra Thombre, Andrei Bytes, Mohammed Jubur, Nitesh Saxena, Luciënne T. M. Blessing, Jianying Zhou 0001, Tony Q. S. Quek |
EuroS&P | 4 |
| 2019 | Towards Semantic Sensitive Feature Profiling of IoT DevicesabstractBillions of Internet of Things (IoT) devices are being adopted in our daily life as personal wearables, home automation agents, medical appliances, etc. Many domains of their use nowadays rely on the privacy and security of these devices-critical infrastructure, healthcare, logistics, manufacturing. In this paper, we aim to establish a standardized framework, which does not require access to physical devices yet allows to profile security and privacy-sensitive functionality in both existing and upcoming IoT products, based on semantic analysis of discovered technical information. We develop a software tool for automatic feature profiling of IoT devices and present case studies on two real-world IoT devices-a fitness tracker, Garmin Forerunner 230, and a voice-controlled home assistant, Amazon Echo Dot second generation and further provide comparative results analysis. Andrei Bytes, Sridhar Adepu, Jianying Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2018 | ATG: An Attack Traffic Generation Tool for Security Testing of In-vehicle CAN BusabstractIn-vehicle security research is challenging because it is hard for most researchers to get a real vehicle for security evaluation. On the other hand, the existing software solutions are either very expensive or having very limited functionality. There is a high demand for a convenient tool which can generate flexible datasets for in-vehicle attack and defense evaluation. In this work, we design and develop an Attack Traffic Generation (ATG) tool for security testing of in-vehicle CAN bus. It removes the barrier for research in this area by providing an open-source software package which works with a cheap, widely available hardware configuration. ATG provides a free and functional toolkit to automotive security researchers for easy and effective interaction with real or simulated CAN bus. One of the most important features of ATG is automatic generation of attack payloads. The payloads can be preconfigured and used within multiple attack modes. ATG can inject attack packets into CAN bus and record the CAN bus traffic in real time. The replay mode enables effective evaluation of CAN bus security implementations using the pre-classified datasets. In addition, a unified data format for raw re-playable CAN sequences enables different automotive research teams to exchange datasets and preform security testing simultaneously against different vehicles and simulation hardware. Tianxiang Huang, Jianying Zhou 0001, Andrei Bytes |
ARES | 3 |