VLDB 2026 Research / reviewers in the wild / expert
Vik Vanderlinden
dblp:365/9520
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0002-6142-8057ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Time and Time Again: Leveraging TCP Timestamps to Improve Remote Timing Attacks
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
NDSS | 1 |
| 2025 | LANShield: Analysing and Protecting Local Network Access on Mobile DevicesabstractHome and workplace networks typically safeguard against external threats but allow internal devices to communicate freely with each other. As a result, malicious code on an internal device can collect sensitive data about other devices or directly attack them. In this paper, we study mobile apps as potential sources of local network attacks, analyse their behaviour, design new defences, and evaluate and bypass existing mitigations. We first focus on Android, where apps with only the Internet permission can access all devices in the Local Area Network (LAN), meaning malicious apps can extract private LAN data, manipulate discovery protocols to obtain a Machine-in-the-Middle (MitM) position, and directly attack devices. To defend against such mobile-based attacks, we define an access model to securely differentiate between LAN and global Internet access. We implement this model on Android by creating LANShield: an app that refines Android's permission model, and can monitor and block LAN access of apps using a virtual network interface. We use LANShield to manually perform tests of 399 Android apps and find, among other observations, that 89 apps unexpectedly access the LAN, and 93 apps scan the network. In contrast to Android, iOS already separates the local and global Internet, but does so based on a proprietary LAN access model. We compare this access model to ours, and present multiple bypasses for an app to circumvent Apple's local network permission. Finally, we reported all our findings to affected vendors, and hope our work will motivate the adoption of stronger permission models on mobile devices. Angelos Beitis, Jeroen Robben, Alexander Matern, Nian Xue, Yongle Chen, Vik Vanderlinden, Mathy Vanhoef |
Proc. Priv. Enhancing Technol. | 8 |
| 2023 | Time Will Tell: Exploiting Timing Leaks Using HTTP Response Headers
Vik Vanderlinden, Tom van Goethem, Mathy Vanhoef |
ESORICS (2) | 1 |