Assel Aliyeva

dblp:241/4280 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Debugging and program repair · 48% Software testing · 24% Operating systems · 14%
Network and information security
1 paper
Web and mobile security · 44% Network security · 44% Privacy and data protection · 13%

Topics — the 7 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Debugging and program repair
record and replay
0.822019
RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019
Towards Practical Record and Replay for Mobile Applications · DAC 2019
Network security › attack strategy
man-in-the-middle attack
0.412020
Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers · SP 2020
Software testing
test execution
0.412019
RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019
Operating systems › mobile systems › mobile operating systems
android
0.112019
Towards Practical Record and Replay for Mobile Applications · DAC 2019
Program analysis
dynamic analysis
0.112019
RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019
Operating systems › mobile systems
mobile operating systems
0.112019
Towards Practical Record and Replay for Mobile Applications · DAC 2019
Program analysis › dynamic analysis
runtime instrumentation
0.112019
RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019

Methods — techniques the papers use, named apart from their topics

protocol analysis · 0.4empirical measurement · 0.4targeted runtime instrumentation · 0.4dynamic instrumentation · 0.4UI event contextualization · 0.4
YearPublicationVenuePosition
2021 Oversharing Is Not Caring: How CNAME Cloaking Can Expose Your Session Cookies
abstract
In modern web ecosystem, online businesses often leverage third-party web analytics services to gain insights into the behavior of their users. Due to the recent privacy enhancements in major browsers that restrict third-party cookie usage for tracking, these businesses were urged to disguise third-party analytics infrastructure as regular subdomains of their websites [3]. The integration technique referred to as CNAME cloaking allows the businesses to continue monitoring user activity on their websites. However, it also opens up the possibility for severe security infractions as the businesses often share their session cookies with the analytics providers, thus putting online user accounts in danger.
Assel Aliyeva, Manuel Egele
AsiaCCS1
2020 Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers
abstract
Mobile browsers have become one of the main mediators of our online activities. However, as web pages continue to increase in size and streaming media on-the-go has become commonplace, mobile data plan constraints remain a significant concern for users. As a result, data-saving features can be a differentiating factor when selecting a mobile browser. In this paper, we present a comprehensive exploration of the security and privacy threat that data-saving functionality presents to users. We conduct the first analysis of Android's data-saving browser (DSB) ecosystem across multiple dimensions, including the characteristics of the various browsers' infrastructure, their application and protocol-level behavior, and their effect on users' browsing experience. Our research unequivocally demonstrates that enabling data-saving functionality in major browsers results in significant degradation of the user's security posture by introducing severe vulnerabilities that are not otherwise present in the browser during normal operation. In summary, our experiments show that enabling data savings exposes users to (i) proxy servers running outdated software, (ii) man-in-the-middle attacks due to problematic validation of TLS certificates, (iii) weakened TLS cipher suite selection, (iv) lack of support of security headers like HSTS, and (v) a higher likelihood of being labelled as bots. While the discovered issues can be addressed, we argue that data-saving functionality presents inherent risks in an increasingly-encrypted Web, and users should be alerted of the critical savings-vs-security trade-off that they implicitly accept every time they enable such functionality.
Brian Kondracki, Assel Aliyeva, Manuel Egele, Iasonas Polakis, Nick Nikiforakis
SP2
2019 Towards Practical Record and Replay for Mobile Applications
abstract
The ability to repeat the execution of a program is a fundamental requirement in evaluating computer systems and apps. Reproducing executions of mobile apps has proven difficult under real-life scenarios due to different sources of external inputs and interactive nature of the apps. We present a new practical record/replay framework for Android, RandR, which handles multiple sources of input and provides cross-device replay capabilities through a dynamic instrumentation approach. We demonstrate the feasibility of RandR by recording and replaying a set of real-world apps.
Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele
DAC2
2019 RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation
abstract
The ability to repeat the execution of a program is a fundamental requirement in many areas of computing from computer system evaluation to software engineering. Reproducing executions of mobile apps, in particular, has proven difficult under real-life scenarios due to multiple sources of external inputs and interactive nature of the apps. Previous works that provide record/replay functionality for mobile apps are restricted to particular input sources (e.g., touchscreen events) and present deployment challenges due to intrusive modifications to the underlying software stack. Moreover, due to their reliance on record and replay of device specific events, the recorded executions cannot be reliably reproduced across different platforms. In this paper, we present a new practical approach, RandR, for record and replay of Android applications. RandR captures and replays multiple sources of input (i.e., UI and network) without requiring source code (OS or app), administrative device privileges, or any special platform support. RandR achieves these qualities by instrumenting a select set of methods at runtime within an application's own sandbox. In addition, to enable portability of recorded executions across different platforms for replay, RandR contextualizes UI events as interactions with particular UI components (e.g., a button) as opposed to relying on platform specific features (e.g., screen coordinates). We demonstrate RandR's accurate cross-platform record and replay capabilities using over 30 real-world Android apps across a variety of platforms including emulators as well as commercial off-the-shelf mobile devices deployed in real life.
Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele
ASE2