VLDB 2026 Research / reviewers in the wild / expert
Assel Aliyeva
dblp:241/4280
· DBLP profile ↗
4ranked-venue papers
1as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Debugging and program repair · 48% Software testing · 24% Operating systems · 14% | |
| Network and information security
1 paper |
Web and mobile security · 44% Network security · 44% Privacy and data protection · 13% |
Topics — the 7 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Debugging and program repair
record and replay |
0.8 | 2 | 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019 Towards Practical Record and Replay for Mobile Applications · DAC 2019 |
Network security › attack strategy
man-in-the-middle attack |
0.4 | 1 | 2020 | Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers · SP 2020 |
Software testing
test execution |
0.4 | 1 | 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019 |
Operating systems › mobile systems › mobile operating systems
android |
0.1 | 1 | 2019 | Towards Practical Record and Replay for Mobile Applications · DAC 2019 |
Program analysis
dynamic analysis |
0.1 | 1 | 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019 |
Operating systems › mobile systems
mobile operating systems |
0.1 | 1 | 2019 | Towards Practical Record and Replay for Mobile Applications · DAC 2019 |
Program analysis › dynamic analysis
runtime instrumentation |
0.1 | 1 | 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime Instrumentation · ASE 2019 |
Methods — techniques the papers use, named apart from their topics
protocol analysis · 0.4empirical measurement · 0.4targeted runtime instrumentation · 0.4dynamic instrumentation · 0.4UI event contextualization · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Oversharing Is Not Caring: How CNAME Cloaking Can Expose Your Session CookiesabstractIn modern web ecosystem, online businesses often leverage third-party web analytics services to gain insights into the behavior of their users. Due to the recent privacy enhancements in major browsers that restrict third-party cookie usage for tracking, these businesses were urged to disguise third-party analytics infrastructure as regular subdomains of their websites [3]. The integration technique referred to as CNAME cloaking allows the businesses to continue monitoring user activity on their websites. However, it also opens up the possibility for severe security infractions as the businesses often share their session cookies with the analytics providers, thus putting online user accounts in danger. Assel Aliyeva, Manuel Egele |
AsiaCCS | 1 |
| 2020 | Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile BrowsersabstractMobile browsers have become one of the main mediators of our online activities. However, as web pages continue to increase in size and streaming media on-the-go has become commonplace, mobile data plan constraints remain a significant concern for users. As a result, data-saving features can be a differentiating factor when selecting a mobile browser. In this paper, we present a comprehensive exploration of the security and privacy threat that data-saving functionality presents to users. We conduct the first analysis of Android's data-saving browser (DSB) ecosystem across multiple dimensions, including the characteristics of the various browsers' infrastructure, their application and protocol-level behavior, and their effect on users' browsing experience. Our research unequivocally demonstrates that enabling data-saving functionality in major browsers results in significant degradation of the user's security posture by introducing severe vulnerabilities that are not otherwise present in the browser during normal operation. In summary, our experiments show that enabling data savings exposes users to (i) proxy servers running outdated software, (ii) man-in-the-middle attacks due to problematic validation of TLS certificates, (iii) weakened TLS cipher suite selection, (iv) lack of support of security headers like HSTS, and (v) a higher likelihood of being labelled as bots. While the discovered issues can be addressed, we argue that data-saving functionality presents inherent risks in an increasingly-encrypted Web, and users should be alerted of the critical savings-vs-security trade-off that they implicitly accept every time they enable such functionality. Brian Kondracki, Assel Aliyeva, Manuel Egele, Iasonas Polakis, Nick Nikiforakis |
SP | 2 |
| 2019 | Towards Practical Record and Replay for Mobile ApplicationsabstractThe ability to repeat the execution of a program is a fundamental requirement in evaluating computer systems and apps. Reproducing executions of mobile apps has proven difficult under real-life scenarios due to different sources of external inputs and interactive nature of the apps. We present a new practical record/replay framework for Android, RandR, which handles multiple sources of input and provides cross-device replay capabilities through a dynamic instrumentation approach. We demonstrate the feasibility of RandR by recording and replaying a set of real-world apps. Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele |
DAC | 2 |
| 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime InstrumentationabstractThe ability to repeat the execution of a program is a fundamental requirement in many areas of computing from computer system evaluation to software engineering. Reproducing executions of mobile apps, in particular, has proven difficult under real-life scenarios due to multiple sources of external inputs and interactive nature of the apps. Previous works that provide record/replay functionality for mobile apps are restricted to particular input sources (e.g., touchscreen events) and present deployment challenges due to intrusive modifications to the underlying software stack. Moreover, due to their reliance on record and replay of device specific events, the recorded executions cannot be reliably reproduced across different platforms. In this paper, we present a new practical approach, RandR, for record and replay of Android applications. RandR captures and replays multiple sources of input (i.e., UI and network) without requiring source code (OS or app), administrative device privileges, or any special platform support. RandR achieves these qualities by instrumenting a select set of methods at runtime within an application's own sandbox. In addition, to enable portability of recorded executions across different platforms for replay, RandR contextualizes UI events as interactions with particular UI components (e.g., a button) as opposed to relying on platform specific features (e.g., screen coordinates). We demonstrate RandR's accurate cross-platform record and replay capabilities using over 30 real-world Android apps across a variety of platforms including emulators as well as commercial off-the-shelf mobile devices deployed in real life. Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele |
ASE | 2 |