VLDB 2026 Research / reviewers in the wild / expert
Shishir Nagaraja
dblp:48/2854
· DBLP profile ↗
10ranked-venue papers
7as first author
3since 2021 · last 2022
0000-0001-7272-0611ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 7 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Can You Still See Me?: Identifying Robot Operations Over End-to-End Encrypted ChannelsabstractConnected robots play a key role in automating industrial workflows. Robots can expose sensitive operational information to remote adversaries. Despite the use of end-to-end encryption, a passive adversary could fingerprint and reconstruct the entire workflows being carried out and developing a detailed understanding of how facilities operate. In this paper, we investigate whether a remote passive attacker can accurately fingerprint robot movements and reconstruct operational workflows. Using a neural network-based traffic analysis approach, we found that attackers can predict TLS-encrypted robot movements with around \textasciitilde60% accuracy, increasing to near perfect accuracy in realistic settings. Ultimately, simply adopting best cybersecurity practices is not enough to stop even weak (passive) adversaries. Ryan Shah, Chuadhry Mujeeb Ahmed, Shishir Nagaraja |
WISEC | 3 |
| 2022 | Dissecting liabilities in adversarial surgical robot failures: A national (Danish) and EU law perspectiveabstractOver the last decade, surgical robots have risen in prominence and usage. They are not merely tools, but have also become advanced instruments with network connectivity. Connectivity is necessary to accept software updates, accept instructions, and transfer sensory data, but it also exposes the robot to cyberattacks, which can damage the patient or the surgeon. These injuries are normally caused by safety failures, as seen in accidents with industrial robots, but cyberattacks are caused by security failures instead. We create a taxonomy for both types of failures in this paper specifically for surgical robots. These robots are increasingly sold and used in the European Union (EU), hence it is natural to consider how surgical robots are viewed and treated by EU law. Specifically, which rights regulators and manufacturers have under it, and which legal remedies and actions a patient or manufacturer would have in a single national legal system in the union, if injuries were to occur from a security failure caused by an adversary that cannot be unambiguously identified (attribution of cyberattacks is often hard). Given that the Medical Device Regulation (MDR) has only recently entered into force, we also offer some general considerations of the regulation. We find that the selected (Danish) national legal system can adequately deal with attacks on surgical robots, because it can on one hand efficiently compensate the patient, and at the same time protect the patient by not shying away from dealing with the problem concretely. This is because of its flexibility; secondly, a remarkable absence of distinction between safety vs security causes of failure and focusing instead on the detrimental effects, thus benefiting the patient; and third, liability can be removed from the manufacturer by withdrawing its status as party, if the patient chooses a separate public law measure to recover damages. Furthermore, we find that current EU law does consider both security and safety aspects of surgical robots, without it mentioning it through literal wording, but it also adds substantial liabilities and responsibilities to the manufacturers of surgical robots, gives the patient special rights and confers immense powers on the regulators, which can end up affecting any future lawsuits. Kaspar Rosager Ludvigsen, Shishir Nagaraja |
Comput. Law Secur. Rev. | 2 |
| 2021 | VoIPLoc: passive VoIP call provenance via acoustic side-channelsabstractWe propose VoIPLoc, a novel location fingerprinting technique and apply it to the VoIP call provenance problem. It exploits echo-location information embedded within VoIP audio to support fine-grained location inference. We found consistent statistical features induced by the echo-reflection characteristics of the location into recorded speech. These features are discernible within traces received at the VoIP destination, enabling location inference. We evaluated VoIPLoc by developing a dataset of audio traces received through VoIP channels over the Tor network. We show that recording locations can be fingerprinted and detected remotely with a low false-positive rate, even when a majority of the audio samples are unlabelled. Finally, we note that the technique is fully passive and thus undetectable, unlike prior art. VoIPLoc is robust to the impact of environmental noise and background sounds, as well as the impact of compressive codecs and network jitter. The technique is also highly scalable and offers several degrees of freedom terms of the fingerprintable space. Shishir Nagaraja, Ryan Shah |
WISEC | 1 |
| 2019 | Poster: Unified Access Control for Surgical RoboticsabstractEnsuring the accuracy of output of surgical robotics is vital, as an incision (during surgery) that is too deep could result in the death of the patient. A large contribution to the level of accuracy of components comes from its calibration. Calibration ensures the output is of high accuracy and is traceable to antecedent calibration units up to national standards. However, each of the levels in the calibration hierarchy have different security requirements (confidentiality and integrity), who may also be in conflict with each other. We propose a hybrid access control model for surgical robotics that maintains integrity and confidentiality requirements across a lattice structure and manages conflicts of interests. Ryan Shah, Shishir Nagaraja |
SACMAT | 2 |
| 2019 | Clicktok: click fraud detection using traffic analysisabstractAdvertising is a primary means for revenue generation for millions of websites and smartphone apps. Naturally, a fraction abuse ad networks to systematically defraud advertisers of their money. Modern defences have matured to overcome some forms of click fraud but measurement studies have reported that a third of clicks supplied by ad networks could be clickspam. Our work develops novel inference techniques which can isolate click fraud attacks using their fundamental properties. We propose two defences, mimicry and bait-click, which provide clickspam detection with substantially improved results over current approaches. Mimicry leverages the observation that organic clickfraud involves the reuse of legitimate click traffic, and thus isolates clickspam by detecting patterns of click reuse within ad network clickstreams. The bait-click defence leverages the vantage point of an ad network to inject a pattern of bait clicks into a user's device. Any organic clickspam generated involving the bait clicks will be subsequently recognisable by the ad network. Our experiments show that the mimicry defence detects around 81% of fake clicks in stealthy (low rate) attacks, with a false-positive rate of 110 per hundred thousand clicks. Similarly, the bait-click defence enables further improvements in detection, with rates of 95% and a reduction in false-positive rates of between 0 and 30 clicks per million - a substantial improvement over current approaches. Shishir Nagaraja, Ryan Shah |
WiSec | 1 |
| 2014 | Botyacc: Unified P2P Botnet Detection Using Behavioural Analysis and Graph Analysis
Shishir Nagaraja |
ESORICS (2) | 1 |
| 2011 | P3CA: Private Anomaly Detection Across ISP Networks
Shishir Nagaraja, Virajith Jalaparti, Matthew Caesar 0001, Nikita Borisov |
PETS | 1 |
| 2010 | The Impact of Unlinkability on Adversarial Community Detection: Effects and Countermeasures
Shishir Nagaraja |
Privacy Enhancing Technologies | 1 |
| 2010 | BotGrep: Finding P2P Bots with Structured Graph Analysis
Shishir Nagaraja, Prateek Mittal, Chi-Yao Hong, Matthew Caesar 0001, Nikita Borisov |
USENIX Security Symposium | 1 |
| 2007 | Anonymity in the Wild: Mixes on Unstructured Networks
Shishir Nagaraja |
Privacy Enhancing Technologies | 1 |