VLDB 2026 Research / reviewers in the wild / expert
Anil Somayaji
dblp:56/1202
· DBLP profile ↗
33ranked-venue papers
5as first author
2since 2021 · last 2025
0000-0003-4761-9743ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 2Systems, architecture and hardware · 2Computer networks · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Houdini: Benchmarking Container Security ConfinementabstractWhile container-based workloads are now a standard part of cloud infrastructure, container security remains a challenge. Container confinement is a particularly pressing problem, as without it, a single vulnerable application can be used to compromise entire clusters of containers. Many container confinement technologies are available, but currently there is no easy way to verify whether a given configuration provides even a basic level of protection. This paper presents Houdini, a security test suite for container confinement. While it can be used to test deployable containers, Houdini is optimized for testing and comparing container confinement technologies. This paper presents the motivation, design, implementation, and initial results of running Houdini on a set of Docker container configurations. By providing a benchmark framework by which container confinement technologies can be evaluated, we believe Houdini can help foster the development of next-generation container confinement technologies. Huzaifa Patel, David Barrera 0003, Anil Somayaji |
PST | 3 |
| 2024 | Towards Foundational Security Metrics
Nilofar Mansourzadeh, Anil Somayaji |
NSPW | 2 |
| 2020 | Towards In-Band Non-Cryptographic AuthenticationabstractRobust, secure authentication is essential in online interactions. Current best practice is to combine factors communicated using different channels; however, in some contexts multi-factor authentication may not be feasible or appropriate. Thus there is a need for authentication strategies that do not rely on classic multiple factors. While people normally rely upon multiple factors to authenticate each other, there is anecdotal evidence that such factors are not needed to authenticate close relationships, and that in fact they can recognize each other over an extremely low-bandwidth channel: texting. Nour Dabbour, Anil Somayaji |
NSPW | 2 |
| 2018 | After the BlockCLoud ApocalypseabstractIn 2038 we have lived though a decade during which the world's global computational infrastructure undermined privacy and trust in virtually every aspect of our lives. The problems were seen far in advance, but it was commonplace belief that a combination of cryptography and more distributed responsibilty in systems---'blockchains for everything, and all hail the cloud'---would together restore what had been lost in the first decades of the 21st century. As it turned out, it was these very technologies that ended up destroying the privacy and trust we had left. Mark Burgess, Anil Somayaji |
NSPW | 2 |
| 2018 | Learning over subconcepts: Strategies for 1-class classificationabstractAbstract In machine learning research and application, multiclass classification algorithms reign supreme. Their fundamental property is the reliance on the availability of data from all known categories to induce effective classifiers. Unfortunately, data from so‐called real‐world domains sometimes do not satisfy this property, and researchers use methods such as sampling to make the data more conducive for classification. However, there are scenarios in which even such explicit methods to rectify distributions fail. In such cases, 1‐class classification algorithms become the practical alternative. Unfortunately, domain complexity severely impacts their ability to produce effective classifiers. The work in this article addresses this issue and develops a strategy that allows for 1‐class classification over complex domains. In particular, we introduce the notion of learning along the lines of underlying domain concepts; an important source of complexity in domains is the presence of subconcepts, and by learning over them explicitly rather than on the entire domain as a whole, we can produce powerful 1‐class classification systems. The level of knowledge regarding these subconcepts will naturally vary by domain, and thus, we develop 3 distinct methodologies that take the amount of domain knowledge available into account. We demonstrate these over 3 real‐world domains. Shiven Sharma, Anil Somayaji, Nathalie Japkowicz |
Comput. Intell. | 2 |
| 2018 | Technological and Human Factors of Malware Attacks: A Computer Security Clinical Trial ApproachabstractThe success (or failure) of malware attacks depends upon both technological and human factors. The most security-conscious users are susceptible to unknown vulnerabilities, and even the best security mechanisms can be circumvented as a result of user actions. Although there has been significant research on the technical aspects of malware attacks and defence, there has been much less research on how users interact with both malware and current malware defences. This article describes a field study designed to examine the interactions between users, antivirus (AV) software, and malware as they occur on deployed systems. In a fashion similar to medical studies that evaluate the efficacy of a particular treatment, our experiment aimed to assess the performance of AV software and the human risk factors of malware attacks. The 4-month study involved 50 home users who agreed to use laptops that were instrumented to monitor for possible malware attacks and gather data on user behaviour. This study provided some very interesting, non-intuitive insights into the efficacy of AV software and human risk factors. AV performance was found to be lower under real-life conditions compared to tests conducted in controlled conditions. Moreover, computer expertise, volume of network usage, and peer-to-peer activity were found to be significant correlates of malware attacks. We assert that this work shows the viability and the merits of evaluating security products, techniques, and strategies to protect systems through long-term field studies with greater ecological validity than can be achieved through other means. Fanny Lalonde Lévesque, Sonia Chiasson, Anil Somayaji, José M. Fernandez 0001 |
ACM Trans. Priv. Secur. | 3 |
| 2017 | Can I believe you?: Establishing Trust in Computer Mediated IntroductionsabstractThe problem of trust is one of the more prominent security issue in online communications. This paper critically analyses and discusses the issue of trust in computer mediated introduction (CMI) where individuals are introduced for the purpose of interacting offline. One of the most popular forms of CMI today is online dating. We evaluate and compare the attempts made to solve the problem of trust in various computer mediated communications. We further specifically analyze three online dating platforms, Match.com, Plenty of Fish, and Tinder, and compare how they attempt to establish trust between potential matches. We find that existing mechanisms are not sufficient to establish meaningful trust in online dating. While we propose some potential alternative mechanisms for establishing trust in CMIs, the key contribution of this work is to identify the security challenges that arise in computer mediated introductions as a previously unrecognized class of security problems. Borke Obada-Obieh, Anil Somayaji |
NSPW | 2 |
| 2013 | A clinical study of risk factors related to malware infectionsabstractThe success of malicious software (malware) depends upon both technical and human factors. The most security conscious users are vulnerable to zero-day exploits; the best security mechanisms can be circumvented by poor user choices. While there has been significant research addressing the technical aspects of malware attack and defense, there has been much less research reporting on how human behavior interacts with both malware and current malware defenses. Fanny Lalonde Lévesque, Jude Nsiempba, José M. Fernandez 0001, Sonia Chiasson, Anil Somayaji |
CCS | 5 |
| 2013 | Towards narrative authentication: or, against boring authenticationabstractIn this paper we propose that what-you-know authentication schemes be built using narrative elements. Specifically, we propose that stories be used as the basis of memory-based user authentication, rather than use a fixed string as the secret for authentication (as is the case with text passwords and PINs). The insight here is that secure text passwords are ``boring'' and, hence, are hard to remember. Narrative is, in contrast, extremely memorable, forming the basis of much of human communication. We present a simple, implementable scheme for narrative authentication using text adventures. We then also examine other strategies for generating and testing knowledge of narrative. Anil Somayaji, David Mould, Carson Brown |
NSPW | 1 |
| 2012 | Software Diversity: Security, Entropy and Game Theory
Saran Neti, Anil Somayaji, Michael E. Locasto |
HotSec | 2 |
| 2010 | The case for in-the-lab botnet experimentation: creating and taking down a 3000-node botnetabstractBotnets constitute a serious security problem. A lot of effort has been invested towards understanding them better, while developing and learning how to deploy effective counter-measures against them. Their study via various analysis, modelling and experimental methods are integral parts of the development cycle of any such botnet mitigation schemes. It also constitutes a vital part of the process of understanding present threats and predicting future ones. Currently, the most popular of these techniques are botnet studies, where researchers interact directly with real-world botnets. This approach is less than ideal, for many reasons that we discuss this paper, including scientific validity, ethical and legal issues. Consequently, we present an alternative approach employing in the lab experiments involving at-scale emulated botnets. We discuss the advantages of such an approach over reverse engineering, analytical modelling, simulation and in-the-wild studies. Moreover, we discuss the requirements that facilities supporting them must have. We then describe an experiment which we emulated a 3000-node, fully-featured version of the Waledac botnet, complete with an emulated command and control (C&C) infrastructure. By observing the load characteristics and yield (rate of spamming) of such a botnet, we can draw interesting conclusions about its real-world operations and design decisions made by its creators. Furthermore, we conducted experiments with sybil attacks launched against it and verified their viability. However, we were able to determine that mounting such attacks is not so simple: high resource consumption can cause havoc and partially neutralise them. Finally, we were able to repeat the attacks with varying parameters, an attempt to optimise them. The merits of this experimental approach is underlined since by the fact that it would have been difficult to obtain these results by other methods. Joan Calvet, Carlton R. Davis, José M. Fernandez 0001, Jean-Yves Marion, Pier-Luc St-Onge, Wadie Guizani, Pierre-Marc Bureau, Anil Somayaji |
ACSAC | 8 |
| 2010 | A methodology for empirical analysis of permission-based security models and its application to androidabstractPermission-based security models provide controlled access to various system resources. The expressiveness of the permission set plays an important role in providing the right level of granularity in access control. In this work, we present a methodology for the empirical analysis of permission-based security models which makes novel use of the Self-Organizing Map (SOM) algorithm of Kohonen (2001). While the proposed methodology may be applicable to a wide range of architectures, we analyze 1,100 Android applications as a case study. Our methodology is of independent interest for visualization of permission-based systems beyond our present Android-specific empirical analysis. We offer some discussion identifying potential points of improvement for the Android permission model attempting to increase expressiveness where needed without increasing the total number of permissions or overall complexity. David Barrera 0003, Hilmi Günes Kayacik, Paul C. van Oorschot, Anil Somayaji |
CCS | 4 |
| 2010 | Object-level recombination of commodity applicationsabstractThis paper presents ObjRecombGA, a genetic algorithm framework for recombining related programs at the object file level. A genetic algorithm guides the selection of object files, while a robust link resolver allows working program binaries to be produced from the object files derived from two ancestor programs. Tests on compiled C programs, including a simple web browser and a well-known 3D video game, show that functional program variants can be created that exhibit key features of both ancestor programs. This work illustrates the feasibility of applying evolutionary techniques directly to commodity applications Blair Foster, Anil Somayaji |
GECCO | 2 |
| 2010 | Visual Security Policy for the Web
Terri Oda, Anil Somayaji |
HotSec | 2 |
| 2009 | Analysis of the 1999 DARPA/Lincoln Laboratory IDS evaluation data with NetADHICTabstractThe 1999 DARPA/Lincoln Laboratory IDS evaluation data has been widely used in the intrusion detection and networking community, even though it is known to have a number of artifacts. Here we show that many of these artifacts, including the lack of damaged or unusual background packets and uniform host distribution, can be easily extracted using NetADHICT, a tool we developed for understanding networks. In addition, using NetADHICT we were able to identify extreme temporal variation in the data, a characteristic that was not identified in past analyses. These results illustrate the utility of NetADHICT in characterizing network traces for experimental purposes. Carson Brown, Alex Cowperthwaite, Abdulrahman Hijazi, Anil Somayaji |
CISDA | 4 |
| 2008 | The Evolution of System-Call MonitoringabstractComputer security systems protect computers and networks from unauthorized use by external agents and insiders. The similarities between computer security and the problem of protecting a body against damage from externally and internally generated threats are compelling and were recognized as early as 1972 when the term computer virus was coined. The connection to immunology was made explicit in the mid 1990s, leading to a variety of prototypes, commercial products, attacks, and analyses. The paper reviews one thread of this active research area, focusing on system-call monitoring and its application to anomaly intrusion detection and response. The paper discusses the biological principles illustrated by the method, followed by a brief review of how system call monitoring was used in anomaly intrusion detection and the results that were obtained. Proposed attacks against the method are discussed, along with several important branches of research that have arisen since the original papers were published. These include other data modeling methods, extensions to the original system call method, and rate limiting responses. Finally, the significance of this body of work and areas of possible future investigation are outlined in the conclusion. Stephanie Forrest, Steven Hofmeyr, Anil Somayaji |
ACSAC | 3 |
| 2008 | SOMA: mutual approval for included content in web pagesabstractUnrestricted information flows are a key security weakness of current web design. Cross-site scripting, cross-site request forgery, and other attacks typically require that information be sent or retrieved from arbitrary, often malicious, web servers. In this paper we propose Same Origin Mutual Approval (SOMA), a new policy for controlling information flows that prevents common web vulnerabilities. By requiring site operators to specify approved external domains for sending or receiving information, and by requiring those external domains to also approve interactions, we prevent page content from being retrieved from malicious servers and sensitive information from being communicated to an attacker. SOMA is compatible with current web applications and is incrementally deployable, providing immediate benefits for clients and servers that implement it. SOMA has an overhead of one additional HTTP request per domain accessed and can be implemented with minimal effort by application and web browser developers. To evaluate our proposal, we have developed a Firefox SOMA add-on. Terri Oda, Glenn Wurster, Paul C. van Oorschot, Anil Somayaji |
CCS | 4 |
| 2008 | Discovering Packet Structure through Lightweight Hierarchical ClusteringabstractThe complexity of current Internet applications makes understanding network traffic a challenging task. By providing larger-scale aggregates for analysis, unsupervised clustering approaches can greatly aid in the identification of new applications, attacks, and other changes in network usage patterns. In this paper we introduce ADHIC, a new algorithm that clusters similar network traffic together without prior knowledge of protocol structures. Packet similarity is determined through comparisons of substrings within packets at distinguishing offsets. ADHIC is notable in that it 1) produces a hierarchical decomposition of network traffic in the form of a cluster-identifying decision tree, 2) needs only a small fraction of packets to generate the tree, and 3) clusters packets at wire speeds. We find that ADHIC appropriately segregates well-known protocols, clusters together traffic of the same protocol running on multiple ports, and segregates traffic from applications, such as p2p, that do not use standard ports. Potential applications include network performance analysis, real-time alerts of flash crowds or worm activity, and dynamic DoS-resistant bandwidth management. NetADHICT, our implementation of ADHIC, is available for download and is licensed under the GNU GPL license. Abdulrahman Hijazi, Hajime Inoue, Ashraf Matrawy, Paul C. van Oorschot, Anil Somayaji |
ICC | 5 |
| 2007 | NetADHICT: A Tool for Understanding Network Traffic
Hajime Inoue, Dana Jansens, Abdulrahman Hijazi, Anil Somayaji |
LISA | 4 |
| 2007 | The future of biologically-inspired security: is there anything left to learn?abstractWhile biology has inspired much of the vocabulary in computer security, biologically-inspired security remains a controversial research strategy. This panel was convened to address the issue of biologically-inspired security by raising the question of whether there is anything left to learn. The discussion at NSPW touched on many issues, ranging from the nature of evolved and intelligent systems to whether anything in security works. The final consensus, however, was that while there may be promise in biologically-inspired defenses, we need to clarify our goals and develop better evaluation methodologies if we are to see further successes in such approaches. Anil Somayaji, Michael E. Locasto, Jan Feyereisl |
NSPW | 1 |
| 2007 | Learning DFA representations of HTTP for protecting web applications
Kenneth L. Ingham, Anil Somayaji, John Burge, Stephanie Forrest |
Comput. Networks | 2 |
| 2007 | Immunology, diversity, and homeostasis: The past and future of biologically inspired computer defenses
Anil Somayaji |
Inf. Secur. Tech. Rep. | 1 |
| 2005 | Mitigating Network Denial-of-Service Through Diversity-Based Traffic Management
Ashraf Matrawy, Paul C. van Oorschot, Anil Somayaji |
ACNS | 3 |
| 2005 | Highlights from the 2005 New Security Paradigms WorkshopabstractThis panel highlights a selection of the most interesting and provocative papers from the 2005 New Security Paradigms Workshop. This workshop was held September 2005 - the URL for more information is http://www.nspw.org. The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC. Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov |
ACSAC | 9 |
| 2005 | Securing Email Archives through User ModelingabstractOnline email archives are an under-protected yet extremely sensitive information resource. Email archives can store years worth of personal and business email in an easy-to-access form, one that is much easier to compromise than messages being transmitted "on the wire." Most email archives, however, are protected by reusable passwords that are often weak and can be easily compromised. To protect such archives, we propose a novel user-specific design for an anomaly-based email archive intrusion detection system. As a first step towards building such a system, we have developed a simple probabilistic model of user email behavior that correlates email senders and a user's disposition of emails. In tests using data gathered from three months of observed user behavior and synthetic models of attacker behavior, this model exhibits a low rate of false positives (generally one false alarm every few weeks) while still detecting most attacks. These results suggest that anomaly detection is a feasible strategy for securing email archives, one that does not require changes in user authentication or access behavior. Yiru Li, Anil Somayaji |
ACSAC | 2 |
| 2005 | Towards Network Awareness
Evan Hughes, Anil Somayaji |
LISA | 2 |
| 2005 | Pass-thoughts: authenticating with our mindsabstractWe present a novel idea for user authentication that we call pass-thoughts. Recent advances in Brain-Computer Interface (BCI) technology indicate that there is potential for a new type of human-computer interaction: a user thoughts directly to a computer. The goal of a pass-thought system would be to extract as much entropy as possible from a user's brain signals upon transmitting a thought. Provided that these brain signals can be recorded and processed in an accurate and repeatable way, a pass-thought system might provide a quasi two-factor, changeable, authentication method resistant to shoulder-surfing. The potential size of the space of a pass-thought system would seem to be unbounded in theory, although in practice it will be finite due to system constraints. In this paper, we discuss the motivation and potential of pass-thought authentication, the status quo of BCI technology, and outline the design of what we believe to be a currently feasible pass-thought system. We also briefly mention the need for general exploration and open debate regarding ethical considerations for such technologies. Julie Thorpe, Paul C. van Oorschot, Anil Somayaji |
NSPW | 3 |
| 2005 | A Generic Attack on Checksumming-Based Software Tamper ResistanceabstractSelf-checking software tamper resistance mechanisms employing checksums, including advanced systems as recently proposed by Chang and Atallah (2002) and Horne et al. (2002) have been promoted as an alternative to other software integrity verification techniques. Appealing aspects include the promise of being able to verify the integrity of software independent of the external support environment, as well as the ability to automatically integrate checksumming code during program compilation or linking. In this paper we show that the rich functionality of many modern processors, including UltraSparc and x86-compatible processors, facilitates automated attacks which defeat such checksumming by self-checking programs. Glenn Wurster, Paul C. van Oorschot, Anil Somayaji |
S&P | 3 |
| 2005 | Hardware-Assisted Circumvention of Self-Hashing Software Tamper ResistanceabstractSelf-hashing has been proposed as a technique for verifying software integrity. Appealing aspects of this approach to software tamper resistance include the promise of being able to verify the integrity of software independent of the external support environment, as well as the ability to integrate code protection mechanisms automatically. In this paper, we show that the rich functionality of most modern general-purpose processors (including UltraSparc, x86, PowerPC, AMD64, Alpha, and ARM) facilitate an automated, generic attack which defeats such self-hashing. We present a general description of the attack strategy and multiple attack implementations that exploit different processor features. Each of these implementations is generic in that it can defeat self-hashing employed by any user-space program on a single platform. Together, these implementations defeat self-hashing on most modern general-purpose processors. The generality and efficiency of our attack suggests that self-hashing is not a viable strategy for high-security tamper resistance on modern computer systems. Paul C. van Oorschot, Anil Somayaji, Glenn Wurster |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2000 | Automated Response Using System-Call Delay
Anil Somayaji, Stephanie Forrest |
USENIX Security Symposium | 1 |
| 1998 | Intrusion Detection Using Sequences of System CallsabstractA method is introduced for detecting intrusions at the level of privileged processes. Evidence is given that short sequences of system calls executed by running processes are a good discriminator between normal and abnormal operating characteristics of several common UNIX programs. Normal behavior is collected in two ways: Synthetically, by exercising as many normal modes of usage of a program as possible, and in a live user environment by tracing the actual execution of the program. In the former case several types of intrusive behavior were studied; in the latter case, results were analyzed for false positives. Steven Hofmeyr, Stephanie Forrest, Anil Somayaji |
J. Comput. Secur. | 3 |
| 1997 | Principles of a computer immune systemabstractNatural immune systems provide a rich source of inspiration for computer security in the age of the Internet. Immune systems have many features that are desirable for the imperfect, uncontrolled, and open environments in which most computers currently exist. These include distributability, diversity, disposability, adaptability, autonomy, dynamic coverage, anomaly detection, multiple layers, identity via behavior, no trusted components, and imperfect detection. These principles suggest a wide variety of architectures for a computer immune system. 1 Anil Somayaji, Steven Hofmeyr, Stephanie Forrest |
NSPW | 1 |
| 1996 | A Sense of Self for Unix ProcessesabstractA method for anomaly detection is introduced in which "normal" is defined by short-range correlations in a process' system calls. Initial experiments suggest that the definition is stable during normal behaviour for standard UNIX programs. Further; it is able to detect several common intrusions involving sendmail and 1pr. This work is part of a research program aimed at building computer security systems that incorporate the mechanisms and algorithms used by natural immune systems. Stephanie Forrest, Steven Hofmeyr, Anil Somayaji, Thomas A. Longstaff |
S&P | 3 |