VLDB 2026 Research / reviewers in the wild / expert
Ahmet Aris
dblp:69/10491
· DBLP profile ↗
21ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0003-4114-5321ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 1 first-author · 8 since 2021Security and privacy · 6 · 6 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unveiling the Global Landscape of Android Security UpdatesabstractAndroid is the world's leading mobile operating system, with over three billion active devices. Detecting vulnerabilities and ensuring timely patch deployment are critical to maintaining security. The Android Open Source Project (AOSP) has enhanced the transparency of security updates through Security Patch Levels. However, challenges related to update speed and availability persist. In 2022, Google reported that half of the zero-day vulnerabilities discovered in the wild were variations of vulnerabilities that had already been patched. Recent research mainly highlights delays in update distribution, often attributing them to fragmentation and focusing primarily on flagship devices or limited time-frames. Our approach takes a device-centric perspective to investigate Android update patterns, analyzing 567K security update records from 2014 to 2024, covering 904 distinct devices from six key Original Equipment Manufacturers (OEMs) across 98 countries. Our extensive analysis revealed notable differences in update release timing across OEMs, device types, and regions. Our study also examines documented vulnerabilities and weaknesses, while assessing OEM compliance with Android security guidelines. Our study shows that$\sim$89.7% of vulnerabilities on unpatched Android devices are exploitable without user interaction and with low attack complexity. We also identified delays linked to fragmentation and OEM-specific challenges, and provide actionable insights for improvement. Haiyun Deng, Güliz Seray Tuncay, Abbas Acar, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Ransomware Over Modern Web Browsers: A Novel Strain and a New Defense MechanismabstractRansomware is an increasingly prevalent form of malware targeting end-users, governments, and businesses. As it has evolved, adversaries added new capabilities to their arsenal. We propose a next-generation browser-based ransomware, RøB , which performs its malicious actions via web technologies, File System Access API (FSA) and WebAssembly (Wasm). RøB uses this API through the victims’ browsers; hence, it does not require the victims to download and install malicious binaries. We performed extensive evaluations with three different OSs, 23 file formats, 29 distinct directories, five cloud providers, and four antivirus solutions. Our evaluations show that RøB can encrypt various types of files in the local and cloud-integrated directories, external storage devices, and network-shared folders of victims. Our experiments also reveal that popular cloud solutions, Box Individual and Apple iCloud can be severely affected by RøB . Moreover, we conducted tests with commercial antivirus software such as AVG, Avast, Kaspersky, and Malware Bytes that perform sensitive directory and suspicious behavior monitoring against ransomware. We verified that RøB can evade these antivirus software and encrypt victim files. Moreover, existing ransomware detection solutions in the literature also cannot be a remedy against RøB due to its distinct features. Therefore, in this paper, we also propose RøBguard , a new detection system for RøB -like attacks. RøBguard monitors the web applications that use the FSA API via function hooking and uses a machine learning classifier to detect RøB -like attacks. We implemented a proof of concept version of RøBguard and our evaluation results show that RøBguard can detect RøB -like browser-based ransomware attacks effectively. We also provide future research directions that should be addressed in this domain. Harun Oz, Güliz Seray Tuncay, Ahmet Aris, Abbas Acar, Leonardo Babun, A. Selcuk Uluagac |
ACM Trans. Web | 3 |
| 2024 | Exploring Jamming and Hijacking Attacks for Micro Aerial DronesabstractRecent advancements in drone technology have shown that commercial off-the-shelf Micro Aerial Drones are more effective than large-sized drones for performing flight missions in narrow environments, such as swarming, indoor navigation, and inspection of hazardous locations. Due to their deployments in many civilian and military applications, safe and reliable communication of these drones throughout the mission is critical. The Crazyflie ecosystem is one of the most popular Micro Aerial Drones and has the potential to be deployed worldwide. In this paper, we empirically investigate two interference attacks against the Crazy Real Time Protocol (CRTP) implemented within the Crazyflie drones. In particular, we explore the feasibility of experimenting two attack vectors that can disrupt an ongoing flight mission: the jamming attack, and the hijacking attack. Our experimental results demonstrate the effectiveness of such attacks in both autonomous and non-autonomous flight modes on a Crazyflie 2.1 drone. Finally, we suggest potential shielding strategies that guarantee a safe and secure flight mission. To the best of our knowledge, this is the first work investigating jamming and hijacking attacks against Micro Aerial Drones, both in autonomous and non-autonomous modes. Yassine Mekdad, Abbas Acar, Ahmet Aris, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, A. Selcuk Uluagac |
ICC | 3 |
| 2024 | 50 Shades of Support: A Device-Centric Analysis of Android Security Updates
Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac |
NDSS | 5 |
| 2024 | (In)Security of File Uploads in Node.jsabstractFile upload is a critical feature incorporated by a myriad of web applications in an effort to enable users to share and manage their files conveniently. It has been used in many useful services such as file-sharing and social media. While file upload is an essential component of web applications, the lack of rigorous checks on the file name, type, and content of the uploaded files can result in security issues, often referred to as Unrestricted File Upload (UFU). In this study, we analyze the (in)security of popular file upload libraries and real-world applications in the Node.js ecosystem. To automate our analysis, we propose and implement NodeSEC- a tool designed to analyze file upload insecurities in Node.js applications and libraries. NodeSEC generates unique payloads and thoroughly evaluates the application's file upload security against 13 distinct UFU-type attacks. Utilizing NodeSEC, we analyze the most popular file upload libraries and real-world applications in the Node.js ecosystem. Our analysis results reveal that some real-world web applications are vulnerable to UFU attacks and disclose serious security bugs in file upload libraries. As of this writing, we received 19 CVEs and two US-CERT cases for the security issues that we reported. Our findings provide strong evidence that dynamic features of Node.js applications introduce security shortcomings and that web developers should be cautious when implementing file upload features in their applications. Finally, combining our responsible disclosure experience and root cause analysis, we identified the main causes of significant security weaknesses in file uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, A. Selcuk Uluagac |
WWW | 3 |
| 2024 | A review of on-device machine learning for IoT: An energy perspective
Nazli Tekin, Ahmet Aris, Abbas Acar, A. Selcuk Uluagac, Vehbi C. Gungor |
Ad Hoc Networks | 2 |
| 2023 | Forensic Analysis of Cryptojacking in Host-Based Docker Containers Using HoneypotsabstractBlockchain-based cryptocurrencies have transformed financial transactions and created opportunities to profit from generating new coins through cryptomining. This has led to cybercriminals stealthily using their victim's computational power and resources for their own profit. Recent trends point to an increase in cryptojacking malware targeting devices with greater processing power such as host-based docker engines for faster and greater profit. In our study, we perform a forensic analysis for detecting cryptojacking (i.e., unauthorized cryptomining) in Docker containers using honeypots. Then, we present countermeasures for securing host-based Docker containers. In addition, we propose an approach for monitoring host-based Docker containers for cryptojacking detection. To the best of our knowledge, this is the first study investigating cryptojacking detection with the use of a honeypot system. Our results reveal that host resource usage and network traffic are the key indicators of possible unauthorized cryptomining in Docker containers. Javier Franco, Abbas Acar, Ahmet Aris, A. Selcuk Uluagac |
ICC | 3 |
| 2023 | RøB: Ransomware over Modern Web Browsers
Harun Oz, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun, A. Selcuk Uluagac |
USENIX Security Symposium | 2 |
| 2023 | A survey on security and privacy issues of UAVs
Yassine Mekdad, Ahmet Aris, Leonardo Babun, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, A. Selcuk Uluagac |
Comput. Networks | 2 |
| 2023 | Ivycide: Smart Intrusion Detection System Against E-IoT Driver ThreatsabstractThe rise of Internet of Things (IoT) devices has led to the proliferation of smart environments worldwide. Although commodity IoT devices are employed by ordinary end users, complex environments, such as smart buildings, government, or private offices, or conference rooms require customized and highly reliable IoT solutions. Enterprise IoT (E-IoT) connect such environments to the Internet and are professionally managed solutions usually offered by dedicated vendors As E-IoT systems require specialized training, closed-source software, and proprietary equipment to deploy. In effect, E-IoT systems present an unprecedented, under-researched, and unexplored threat vector for an attacker. In this work, we focus on E-IoT drivers, software modules used to integrate devices into E-IoT systems, as an attack mechanism. We first present PoisonIvy, a series of generalized proof-of-concept attacks used to demonstrate that an attacker can use a malicious driver to perform denial-of-service attacks, gain remote control, and abuse E-IoT system resources. To defend against E-IoT driver-based threats, we introduce Ivycide, a novel intrusion detection system used to detect unexpected E-IoT network traffic from an E-IoT system. Ivycide operates as a passive monitoring system within an E-IoT system using machine learning and signature-based classification to detect Poisonivy attacks. We evaluated the performance of Ivycide in a realistic E-IoT deployment. Our detailed evaluation results show that Ivycide achieves an average accuracy of 97% in classifying the type of Poisonivy attack and operates without modifications or operational overhead to the existing E-IoT systems. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
IEEE Internet Things J. | 3 |
| 2022 | S-Pot: A Smart Honeypot Framework with Dynamic Rule Configuration for SDNabstractEnterprise networks are becoming increasingly heterogeneous where enterprise devices and IoT devices coexist, requiring tools for effective management and security. Software Defined Networking (SDN) has emerged in response to such needs of modern networks. SDN lacks adequate security features and Intrusion Detection and Protection Systems (IDPS) have been used to protect SDN from attacks. However, they have limited knowledge of zero day attacks. Machine Learning (ML) has become a valuable tool against these limitations and improve (SDN) network security. However, the solutions that solely rely on ML can struggle to discriminate benign traffic from malicious, and suffer from false negatives. To solve these problems and improve security of SDN-based enterprise networks, we propose S-Pot, an open-source smart honeypot framework. S-Pot uses enterprise and IoT honeypots to attract attackers, learns from attacks via ML classifiers, and dynamically configures the rules of SDN. Since honeypots generally receive only malicious traffic, S-Pot can learn from the received malicious traffic and minimize the false positives of an SDN network. In addition, S-Pot can detect the new attacks using ML classifiers, thus can help to minimize the false negatives. Our performance evaluation of S-Pot in detecting attacks using various ML classifiers show that it can detect attacks with 97% accuracy using J48 algorithm. In addition, we evaluated the effectiveness of S-Pot in improving the security of an enterprise SDN testbed network. Our results demonstrate that, compared to the without S-Pot case, S-Pot can improve the security of the SDN networks by detecting attacks with better performance, greater accuracy, effectively generating rules, and dynamically configuring the network. Javier Franco, Ahmet Aris, Leonardo Babun, A. Selcuk Uluagac |
GLOBECOM | 2 |
| 2022 | Systematic Threat Analysis of Modern Unified Healthcare Communication SystemsabstractRecently, smart medical devices have become preva-lent in remote monitoring of patients and the delivery of medication. The ongoing Covid-19 pandemic situation has boosted the upward trend of the popularity of smart medical devices in the healthcare system. Simultaneously, different device manufacturers and technologies compete for a share in a smart medical device's market, which forces the integration of diverse smart medical de-vices into a common healthcare ecosystem. Hence, modern unified healthcare communication systems (UHCSs) combine ISO/IEEE 11073 and Health Level Seven (HL7) communication standards to support smart medical devices' interoperability and their communication with healthcare providers. Despite their advantages in supporting various smart medical devices and communication technologies, these standards do not provide any security and suffer from vulnerabilities. Existing studies provide stand-alone security solutions to components of UHCSs and do not cover UHCSs holistically. In this paper, we perform a systematic threat analysis of UHCSs that relies on attack-defense tree (ADTree) formalisms. Considering the attack landscape and defense ecosys-tem, we build an ADTree for UHCSs and convert the ADTree to stochastic timed automata (STA) to perform quantitative analysis. Our analysis using UPPAAL SMC shows that the Man-in-the-Middle and unauthorized remote access attacks are the most probable attacks that a malicious entity could pursue, causing mistreatment to patients. We also extract valuable information about the top threats, the likelihood of performing different individual and simultaneous attacks, and the expected cost for attackers. A. K. M. Iqtidar Newaz, Ahmet Aris, Amit Kumar Sikder, A. Selcuk Uluagac |
GLOBECOM | 2 |
| 2022 | A First Look at Code Obfuscation for WebAssemblyabstractWebAssembly (Wasm) has seen a lot of attention lately as it spreads through the mobile computing domain and becomes the new standard for performance-oriented web development. It has diversified its uses far beyond just web applications by acting as an execution environment for mobile agents, containers for IoT devices, and enabling new serverless approaches for edge computing. Within the numerous uses of Wasm, not all of them are benign. With the rise of Wasm-based cryptojacking malware, analyzing Wasm applications has been a hot topic in the literature, resulting in numerous Wasm-based cryptojacking detection systems. Many of these methods rely on static analysis, which traditionally can be circumvented through obfuscation. However, the feasibility of the obfuscation techniques for Wasm programs has never been investigated thoroughly. In this paper, we address this gap and perform the first look at code obfuscation for Wasm. We apply numerous obfuscation techniques to Wasm programs, and test their effectiveness in producing a fully obfuscated Wasm program. Particularly, we obfuscate both benign Wasm-based web applications and cryptojacking malware instances and feed them into a state-of-the-art Wasm cryptojacking detector to see if current Wasm analysis methods can be subverted with obfuscation. Our analysis shows that obfuscation can be highly effective and can cause even a state-of-the-art detector to misclassify the obfuscated Wasm samples. Shrenik Bhansali, Ahmet Aris, Abbas Acar, Harun Oz, A. Selcuk Uluagac |
WISEC | 2 |
| 2022 | Survey on Enterprise Internet-of-Things systems (E-IoT): A security perspective
Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
Ad Hoc Networks | 3 |
| 2021 | MINOS: A Lightweight Real-Time Cryptojacking Detection System
Faraz Naseem Naseem, Ahmet Aris, Leonardo Babun, Ege Tekiner, A. Selcuk Uluagac |
NDSS | 2 |
| 2021 | LightningStrike: (in)secure practices of E-IoT systems in the wildabstractThe widespread adoption of specialty smart ecosystems has changed the everyday lives of users. As a part of smart ecosystems, Enterprise Internet of Things (E-IoT) allows users to integrate and control more complex installations in comparison to off-the-shelf IoT systems. With E-IoT, users have a complete control of audio, video, scheduled events, lightning fixtures, shades, door access, and relays via available user interfaces. As such, these systems see widespread use in government or smart private offices, schools, smart buildings, professional conference rooms, hotels, smart homes, yachts, and similar professional settings. However, even with their widespread use, the security of many E-IoT systems has not been researched in the literature. Further, many E-IoT systems utilize proprietary communication protocols that rely mostly on security through obscurity, which has perhaps led many users to mistakenly assume that these systems are secure. To address this open research problem and determine if E-IoT systems are vulnerable, we focus on one of the core E-IoT components, E-IoT communication buses. Communication buses are used by E-IoT proprietary protocols to connect multiple E-IoT devices (e.g., keypads and touchscreens) and trigger pre-configured events upon user actions. In this study, we introduce LightningStrike, the implementation of four proof-of-concept attacks that demonstrate several weaknesses in E-IoT proprietary communication protocols through communication buses. With LightningStrike, we show that it is feasible for an attacker to compromise E-IoT systems using E-IoT communication buses. We demonstrate that popular E-IoT proprietary communication protocols are susceptible to Denial-of-Service, eavesdropping, impersonation, and replay attacks. As E-IoT systems control physical access, safety components, and emergency equipment, an attacker with a low level of knowledge and effort can easily exploit E-IoT vulnerabilities to impact the security and safety of users, smart systems, and smart buildings worldwide. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
WISEC | 3 |
| 2019 | The Nearest Origin-Shield (NOS): A Jitter-Free Overlay Routing Framework for Content Delivery NetworksabstractAlthough Content Delivery Networks (CDN) do their best to quickly deliver the contents, Internet Service Providers (ISP) and network conditions cause unexpected changes on the routing paths. Hence, it gets difficult for CDNs to adhere to the delay promises within the Service Level Agreements. This paper presents a jitter-free overlay routing framework for CDNs, which struggle to adapt timely content delivery to end users due to the dynamicity of the Internet. The Nearest Origin-Shield (NOS) framework which we propose in this paper overcomes this issue by creating an overlay network on top of the existing physical ISP networks and dynamically determining the fastest routes to the content sources (Origins) on this overlay network. NOS keeps track of changes in underlay network through periodically measuring the end-to-end routing paths delays via Helper Modules. Based on the underlay network delay measures and the load (i.e., CPU, disk I/O and network usage) of the overlay network entities, NOS Central Module determines the fastest routes to the Origins using our novel Delay-Aware and Jitter-Free Overlay Routing Algorithm. Hence making it possible for CDNs to provide jitter-free and timely content deliveries meanwhile ensuring the cache servers not to be overloaded. We created a new testbed for performance evaluations with real CDN servers, Origin accounts and measurements. Results show that, NOS provides shorter, more stable and jitter-free routing paths with jitter gains up to 98 % and improves the Hit ratio by 0.74%. Nima Najaflou, Ahmet Aris, Berk Canberk, Zeynep Gürkas Aydin |
ISNCC | 2 |
| 2019 | New lightweight mitigation techniques for RPL version number attacks
Ahmet Aris, Siddika Berna Örs Yalçin, Sema F. Oktug |
Ad Hoc Networks | 1 |
| 2017 | Poster: State of the Art IDS Design for IoT
Ahmet Aris, Sema F. Oktug |
EWSN | 1 |
| 2016 | RPL version number attacks: In-depth studyabstractIn this work, we study the RPL version number attacks in-depth and analyze the attack from various points of view. The unique aspects of our work can be seen in our analysis of a realistic network topology that has both static and mobile nodes with different cardinalities for which our inspiration came from the IETF routing requirement documents. We also analyze how version number attack affects the power consumption of the nodes. We incorporated a probabilistic attacking model where the attacker attacks with a probability of p (e.g., 0, 0.3, 0.5, 0.7, 1). We also provide the performance results with respect to various values of p. Ahmet Aris, Sema F. Oktug, Siddika Berna Örs Yalçin |
NOMS | 1 |
| 2011 | Architectures for Fast Modular MultiplicationabstractModular multiplication is the key ingredient needed to realize most public-key cryptographic primitives. In a modular setting, multiplications are carried in two steps: namely a usual integer arithmetic followed by a reduction step. Progress in any of these steps naturally improves the modular multiplication but it is not possible to interleave the best algorithms of these stages. In this study, we propose architectures for recently proposed method of interleaving the Karatsuba-Ofman multiplier and bipartite modular reduction on the upper most layer of Karatsuba-Ofman's recursion. We manage to come up with a high performance modular multiplication architecture by taking the advantage of a fast multiplication and a parallel reduction method. Ahmet Aris, Siddika Berna Örs Yalçin, Gökay Saldamli |
DSD | 1 |