VLDB 2026 Research / reviewers in the wild / expert
Sareena Karapoola
dblp:244/5230
· DBLP profile ↗
6ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0003-0756-678XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: HASFire - Hardware-Software Co-design for Accurate Packet Filtering at Line-Rate
Arun Krishna AMS, Surya Prasad S, Megna Premkumar, Naveen Babu Devarakonda, Athish Pranav Dharmalingam, Gnanambikai Krishnakumar, Sareena Karapoola |
AsiaCCS | 7 |
| 2025 | SUNDEW: A Case-Sensitive Detection Engine to Counter Malware DiversityabstractMalware programs are diverse, with varying objectives, functionalities, and threat levels ranging from mere pop-ups to significant financial losses. Consequently, their run-time footprints across the system differ, impacting the optimal data source (Network, Operating system (OS), Hardware) and features that are instrumental to malware detection. Further, the variations in threat levels of malware classes affect the user policies for detection. Thus, the optimal tuple of$\langle \tt data$-$\tt source$,$\tt features$,$\tt user$-$\tt policies \rangle$, determined experimentally, is different for each malware class, impacting the state-of-the-art detection solutions that are agnostic to these subtle differences. This paper presents${\sf SUNDEW}$, a framework to detect malware classes using the corresponding optimal tuple of$\langle \tt data$-$\tt source$,$\tt features$,$\tt user$-$\tt policies \rangle$.${\sf SUNDEW}$uses an ensemble of specialized predictors, each trained with a particular data source (network, OS, and hardware) and tuned for features and policies of a specific class. While the specialized ensemble with a holistic view across the system improves detection, aggregating the independent conflicting inferences from the different predictors is challenging.${\sf SUNDEW}$resolves such conflicts with a hierarchical aggregation considering the threat-level, noise in the data sources, and prior domain knowledge. We evaluate${\sf SUNDEW}$on a real-world dataset of over 10,000 malware samples from 8 classes. It achieves an F1-Score of one for most classes, with an average of 0.93, and has a limited performance overhead of 1.5%. Our experiments on a common multi-featured dataset show that${\sf SUNDEW}$is 10% more accurate, with 89% lower false positives, than prior state-of-the-art predictors. Sareena Karapoola, Nikhilesh Singh, Chester Rebeiro, V. Kamakoti 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | YODA: Covert Communication Channel over Public DNS ResolversabstractEnterprises are increasingly migrating to public domain name system (DNS) resolvers for reliability, cost optimizations, and, most importantly, improved security and user privacy. The integrated threat intelligence feeds at these resolvers enable easy identification and blocking of malicious exploits that use DNS queries. However, we observe that the shared local caches at these public DNS resolvers enable covert communication channels from otherwise secure enterprises accessible to any remote adversary, thus cautioning the migration to public DNS resolvers. We present YODA, a covert communication channel via public DNS resolvers that can exfiltrate sensitive information from a victim enterprise to a remote adversary. Unlike prior works, YODA overloads DNS queries for popular domains to transfer the data without revealing any identity of the adversary. Consequently, YODA cannot be blocked by domain name filtering. We demonstrate our attack on public DNS resolvers such as Google, Cloudflare, Quad9, OpenDNS, and LibreDNS. Our evaluations show that the adversary can achieve a bandwidth of 480bps with desktop devices. Sandip Saha, Sareena Karapoola, Chester Rebeiro, V. Kamakoti 0001 |
DSN | 2 |
| 2022 | RaDaR: A Real-Word Dataset for AI powered Run-time Detection of Cyber-AttacksabstractArtificial Intelligence techniques on malware run-time behavior have emerged as a promising tool in the arms race against sophisticated and stealthy cyber-attacks. While data of malware run-time features are critical for research and benchmark comparisons, unfortunately, there is a dearth of real-world datasets due to multiple challenges to their collection. The evasive nature of malware, its dependence on connected real-world conditions to execute, and its potential repercussions pose significant challenges for executing malware in laboratory settings. Consequently, prior open datasets rely on isolated virtual sandboxes to run malware, resulting in data that is not representative of malware behavior in the wild. Sareena Karapoola, Nikhilesh Singh, Chester Rebeiro, V. Kamakoti 0001 |
CIKM | 1 |
| 2020 | Net-Police: A network patrolling service for effective mitigation of volumetric DDoS attacks
Sareena Karapoola, Prasanna Karthik Vairam, Shankar Raman, V. Kamakoti 0001 |
Comput. Commun. | 1 |
| 2019 | Towards Identifying Early Indicators of a Malware InfectionabstractA malware goes through multiple stages in its life-cycle at the target machine before mounting its expected attack. The entire life-cycle can span anywhere from a few weeks to several months. The network communications during the initial phase could be the earliest indicators of a malware infection. While prior works have leveraged network traffic, none have focused on the temporal analysis of how early can the malware be detected. The main challenges here are the difficulty in differentiating benign-looking malware communications in the early stages of the malware life-cycle. In our quest to build an early warning system, we analyze malware communications to identify such early indicators. Sareena Karapoola, Chester Rebeiro, Unnati Parekh, V. Kamakoti 0001 |
AsiaCCS | 1 |