VLDB 2026 Research / reviewers in the wild / expert
Babak Amin Azad
dblp:248/1647
· DBLP profile ↗
10ranked-venue papers
5as first author
7since 2021 · last 2023
0000-0002-1370-9305ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Role Models: Role-based Debloating for Web ApplicationsabstractThe process of debloating, i.e., removing unnecessary code and features in software, has become an attractive proposition to managing the ever-expanding attack surface of ever-growing modern applications. Researchers have shown that debloating produces significant security improvements in a variety of application domains including operating systems, libraries, compiled software, and, more recently, web applications. Even though the client/server nature of web applications allows the same backend to serve thousands of users with diverse needs, web applications have been approached monolithically by existing debloating approaches. That is, a feature can be debloated only if none of the users of a web application requires it. Similarly, everyone gets access to the same "global" features, whether they need them or not. Recognizing that different users need access to different features, in this paper we propose role-based debloating for web applications. In this approach, we focus on clustering users with similar usage behavior together and providing them with a custom debloated application that is tailored to their needs. Through a user study with 60 experienced web developers and administrators, we first establish that different users indeed use web applications differently. This data is then used by DBLTR, an automated pipeline for providing tailored debloating based on a user's true requirements. Next to debloating web applications, DBLTR includes a transparent content-delivery mechanism that routes authenticated users to their debloated copies. We demonstrate that for different web applications, DBLTR can be 30-80% more effective than the state-of-the-art in debloating in removing critical vulnerabilities. Babak Amin Azad, Nick Nikiforakis |
CODASPY | 1 |
| 2023 | AnimateDead: Debloating Web Applications Using Concolic Execution
Babak Amin Azad, Rasoul Jahanshahi, Chris Tsoukaladelis, Manuel Egele, Nick Nikiforakis |
USENIX Security Symposium | 1 |
| 2023 | Minimalist: Semi-automated Debloating of PHP Web Applications through Static Analysis
Rasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel Egele |
USENIX Security Symposium | 2 |
| 2023 | Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability ScanningabstractWeb vulnerability scanners (WVS) are an indispensable tool for penetration testers and developers of web applications, allowing them to identify and fix low-hanging vulnerabilities before they are discovered by attackers. Unfortunately, malicious actors leverage the very same tools to identify and exploit vulnerabilities in third-party websites. Existing research in the WVS space is largely concerned with how many vulnerabilities these tools can discover, as opposed to trying to identify the tools themselves when they are used illicitly. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
WWW | 2 |
| 2022 | The Droid is in the Details: Environment-aware Evasion of Android Sandboxes
Brian Kondracki, Babak Amin Azad, Najmehalsadat Miramirkhani, Nick Nikiforakis |
NDSS | 2 |
| 2021 | Catching Transparent Phish: Analyzing and Detecting MITM Phishing ToolkitsabstractFor over a decade, phishing toolkits have been helping attackers automate and streamline their phishing campaigns. Man-in-the- Middle (MITM) phishing toolkits are the latest evolution in this space, where toolkits act as malicious reverse proxy servers of online services, mirroring live content to users while extracting cre- dentials and session cookies in transit. These tools further reduce the work required by attackers, automate the harvesting of 2FA- authenticated sessions, and substantially increase the believability of phishing web pages. Brian Kondracki, Babak Amin Azad, Oleksii Starov, Nick Nikiforakis |
CCS | 2 |
| 2021 | Good Bot, Bad Bot: Characterizing Automated Browsing ActivityabstractAs the web keeps increasing in size, the number of vulnerable and poorly-managed websites increases commensurately. Attackers rely on armies of malicious bots to discover these vulnerable websites, compromising their servers, and exfiltrating sensitive user data. It is, therefore, crucial for the security of the web to understand the population and behavior of malicious bots.In this paper, we report on the design, implementation, and results of Aristaeus, a system for deploying large numbers of "honeysites", i.e., websites that exist for the sole purpose of attracting and recording bot traffic. Through a seven-month-long experiment with 100 dedicated honeysites, Aristaeus recorded 26.4 million requests sent by more than 287K unique IP addresses, with 76,396 of them belonging to clearly malicious bots. By analyzing the type of requests and payloads that these bots send, we discover that the average honeysite received more than 37K requests each month, with more than 50% of these requests attempting to brute-force credentials, fingerprint the deployed web applications, and exploit large numbers of different vulnerabilities. By comparing the declared identity of these bots with their TLS handshakes and HTTP headers, we uncover that more than 86.2% of bots are claiming to be Mozilla Firefox and Google Chrome, yet are built on simple HTTP libraries and command-line tools. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
SP | 2 |
| 2020 | Web Runner 2049: Evaluating Third-Party Anti-bot Services
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
DIMVA | 1 |
| 2020 | Short Paper - Taming the Shape Shifter: Detecting Anti-fingerprinting Browsers
Babak Amin Azad, Oleksii Starov, Pierre Laperdrix, Nick Nikiforakis |
DIMVA | 1 |
| 2019 | Less is More: Quantifying the Security Benefits of Debloating Web Applications
Babak Amin Azad, Pierre Laperdrix, Nick Nikiforakis |
USENIX Security Symposium | 1 |