VLDB 2026 Research / reviewers in the wild / expert
Muhammad Ikram 0001
dblp:72/7208-1
· DBLP profile ↗
41ranked-venue papers
9as first author
24since 2021 · last 2026
0000-0003-2113-3390ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 3 first-author · 12 since 2021Databases, data management, data science and information retrieval · 7 · 2 first-author · 5 since 2021Computer networks · 6 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
Sajal Halder, M. Ejaz Ahmed, Muhammad Ikram 0001, Seyit Ahmet Çamtepe, Hyoungshick Kim |
AsiaCCS | 4 |
| 2026 | TBTrackerX: Fantastic Trigger Bots and Where to Find Malicious Campaigns on X
Mohd Majid Akhtar, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
NDSS | 3 |
| 2025 | CARE: Enhancing LLM Instruction Following via Dual-Agent Prompt RefinementabstractPrompt engineering is crucial for optimizing the performance of Large Language Models (LLMs), yet it remains a manual and resource-intensive process that requires multiple iterations of trial and error. Current automated prompt enhancement approaches face key challenges in preserving component relationships, managing computational requirements, and maintaining optimization traceability. This paper introduces CARE (Comprehensive Analyzer & REfiner), an LLM-based dual-agent framework that models prompt enhancement as a staged transformation pipeline with explicit validation constraints. CARE tackles three fundamental challenges: prompt decomposition with interleaved dependencies, component interference in LLM processing, and semantic drift during refinement. The framework enables reliable prompt enhancement in a single iteration through systematic component extraction and rule-based transformations. Evaluation using established benchmarks demonstrates consistent improvements across diverse LLM architectures. Nardine Basta, Benjamin Zi Hao Zhao, Muhammad Ikram 0001, Mohamed Ali Kâafar |
ECAI | 3 |
| 2025 | Deception Meets Diagnostics: Deception-based Real-Time Threat Detection in Healthcare Web SystemsabstractIncreased cloud adoption in healthcare has amplified ransomware and malware threats, accounting for $19 \%$ of global breaches in 2024. Despite this surge, the behavior of attackers exploiting healthcare systems remains under-explored in academic literature. This paper bridges that gap by deploying a scalable and stealthy deception network specifically designed for healthcare environments. The network comprises 30 real-world vulnerable healthcare web applications, mimicking domainspecific workflows across multi-cloud infrastructures, such as patient registration and billing. We leveraged ATTACK-BERT to generate semantic embeddings and applied co-regularized spectral clustering with normalized cuts to analyze multi-protocol attack traffic. Our analysis revealed nuanced attacker behaviors, including regional and protocol-specific variations, exploitation of healthcare protocols like HL7, and the use of encryption to bypass detection. A comparative sub-study further showed that attackers deliberately engage with vulnerable systems, highlighting the strategic value of deception-based defenses. By focusing on behavioral insights within healthcare-specific settings, this work lays the groundwork for integrating deception into the broader security posture of critical infrastructures. Zeeshan Zulkifl Shah, Muhammad Ikram 0001, Hassan Jameel Asghar, Mohamed Ali Kâafar |
RAID | 2 |
| 2025 | Facing the Challenge of Leveraging Untrained Humans in Malware Analysis
Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Muhammad Ikram 0001, Mohamed Ali Kâafar, Sean Lamont, Daniel Coscia |
SEC (1) | 3 |
| 2025 | On challenges of sixth-generation (6G) wireless networks: A comprehensive survey of requirements, applications, and security issuesabstractFifth-generation (5G) wireless networks are likely to offer high data rates, increased reliability, and low delay for mobile, personal, and local area networks. Along with the rapid growth of smart wireless sensing and communication technologies, data traffic has increased significantly and existing 5G networks are not able to fully support future massive data traffic for services, storage, and processing. To meet the challenges that are ahead, both research communities and industry are exploring the sixth generation (6G) Terahertz-based wireless network that is expected to be offered to industrial users in just ten years. Gaining knowledge and understanding of the different challenges and facets of 6G is crucial in meeting the requirements of future communication and addressing evolving quality of service (QoS) demands. This survey provides a comprehensive examination of specifications, requirements, applications, and enabling technologies related to 6G. It covers disruptive and innovative, integration of 6G with advanced architectures and networks such as software-defined networks (SDN), network functions virtualization (NFV), Cloud/Fog computing, and Artificial Intelligence (AI) oriented technologies. The survey also addresses privacy and security concerns and provides potential futuristic use cases such as virtual reality, smart healthcare , and Industry 5.0 . Furthermore, it identifies the current challenges and outlines future research directions to facilitate the deployment of 6G networks. Muhammad Sajjad Akbar, Muhammad Ikram 0001, Quan Z. Sheng, Subhas Mukhopadhyay |
J. Netw. Comput. Appl. | 3 |
| 2025 | Measuring, Characterizing, and Analyzing the Free Web Games EcosystemabstractWeb games, that are directly playable within web browsers, have recently garnered substantial popularity, particularly among younger demographics. The absence of a paywall for these games has raised concerns regarding the potential privacy-compromising monetization strategies. Comprehensive investigations have been carried out into domains like paid online games, multiplayer online video games, mobile gaming, and their associated privacy and security concerns, but a significant gap persists in the characterization and examination of freely accessible web games. To address these voids, our research conducts an exhaustive analysis of the web games ecosystem. We rigorously scrutinize 22 distinct web game websites with the goal of understanding player experience and addressing privacy concerns. Our methodology involves simulating player interactions across approximately 100,000 individual web games to extract insights into player behavior and privacy risks. The outcomes of our work demonstrate substantial insights into the popularity, ownership, geolocation, and game environment, including metadata diversity. It also reveals the privacy risks faced by users on these websites, encompassing various aspects, such as the presence of questionable third-party advertisements designed for revenue generation, sporadic instances of objectionable content, and the persistence of tracking mechanisms like persistent cookies. Most of all, there is also a discouraging absence of transparent privacy policy statements, a website's privacy policy statement is a legal document to protect users' rights. Also, this deficiency of clear policy information hinders users' capacity to make informed decisions about opting out and understanding the potential consequences. In short, the insights from our study highlight substantial concerns regarding prevalent privacy practices within the domain of free web game websites. Moreover, we contribute our dataset and code, which contain metadata collected from approximately 100 K web games originating from the 22 websites examined in our investigation, thereby we provide a valuable resource for further research and analysis of this less investigated genre of websites. Hina Qayyum, Muhammad Ikram 0001, Mohamed Ali Kâafar, Gareth Tyson |
IEEE Trans. Games | 2 |
| 2024 | SoK: False Information, Bots and Malicious Campaigns: Demystifying Elements of Social Media ManipulationsabstractThe rapid spread of false information and persistent manipulation attacks on online social networks (OSNs), often for political, ideological, or financial gain, has affected the openness of OSNs. While researchers from various disciplines have investigated different manipulation-triggering elements of OSNs (such as understanding information diffusion on OSNs or detecting automated behavior of accounts), these works have not been consolidated to present a comprehensive overview of the interconnections among these elements. Notably, user psychology, the prevalence of bots, and their tactics concerning false information detection have been overlooked in previous research. Mohd Majid Akhtar, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
AsiaCCS | 3 |
| 2024 | Auditing and Attributing Behaviours of Suspicious Android Health Applications
I Wayan Budi Sentana, Muhammad Ikram 0001, Mohamed Ali Kâafar |
NSS | 3 |
| 2024 | Performance Evaluation of Quantum-Secure Symmetric Key AgreementabstractQuantum-safe public key exchange protocols face significant challenges in hardware- and software-based approaches. Quantum key distribution, which relies on specialized quantum hardware, presents a significant barrier to widespread adoption due to its high cost and limited scalability. Conversely, software-based solutions using post-quantum algorithms introduce complications, such as increased resource demands and larger cipher-texts. Furthermore, the security of these post-quantum algorithms remains relatively untested, which has led to the emerging trend of hybrid deployment, combining clas-sical and quantum-resistant techniques to hedge against potential vulnerabilities. Recently, Arqit proposed a quantum-secure symmet-ric key agreement (SKA) protocol, claiming that it is lightweight and scalable [1] to address these problems. However, their proprietary solution is not available for independent analysis. To evaluate the performance and scalability of quantum-secure SKA techniques, we develop variations of the SKA protocol using open-source and accessible components in this work. To analyze quantum-secure SKA scheme, we imple-mented an SKA technique that involves a hybrid mech-anism, leveraging secret strings distributed through a combination of existing classical and quantum public key pairs during the initial key exchange. We analyze our scheme and demonstrate that it incurs minimal performance overhead, with only 99ms for purely quantum SKA and 199ms for the hybrid version, compared to the classical SKA protocol. We also show that our scheme remains robust under various network conditions, including delays, packet losses, and bandwidth variations, maintaining small and consistent overheads. We also show that this solution is scalable, with an overhead of only one second for every additional five concurrent users. This performance improves significantly with increased computational resources-achieving a 50-60% improvement when scaling from two to four CPUs. Additionally, our security evaluations confirm that the protocol provides consistent and sufficient randomness throughout the key agreement process, ensuring quantum-resistance at every stage. Amin Rois Sinung Nugroho, Muhammad Ikram 0001, Mohamed Ali Kâafar |
SIN | 2 |
| 2024 | More Than Just a Random Number Generator! Unveiling the Security and Privacy Risks of Mobile OTP Authenticator Apps
Muhammad Ikram 0001, I Wayan Budi Sentana, Hassan Jameel Asghar, Mohamed Ali Kâafar, Michal Kepkowski |
WISE (5) | 1 |
| 2024 | On Adversarial Training with Incorrect Labels
Benjamin Zi Hao Zhao, Junda Lu 0001, Xiaowei Zhou 0003, Dinusha Vatsalan, Muhammad Ikram 0001, Mohamed Ali Kâafar |
WISE (4) | 5 |
| 2024 | SPGNN-API: A Transferable Graph Neural Network for Attack Paths Identification and Autonomous MitigationabstractAttack paths are the potential chain of malicious activities an attacker performs to compromise network assets and acquire privileges through exploiting network vulnerabilities. Attack path analysis helps organizations to identify new/unknown chains of attack vectors exposing critical assets, as opposed to individual attack vectors in signature-based attack analysis. Timely identification of attack paths enables proactive mitigation of threats. Nevertheless, manual analysis of complex network configurations, vulnerabilities, and security events to identify attack paths is rarely feasible. This work proposes a novel transferable graph neural network-based model for shortest path identification. The shortest path, integrated with a novel holistic model for identifying potential network vulnerabilities interactions, is then utilized to detect network attack paths. Our framework automates the risk assessment of attack paths indicating the propensity of the paths to enable the compromise of highly-critical assets (e.g., databases). The proposed framework, named SPGNN-API, incorporates automated threat mitigation through a proactive timely tuning of the network firewall rules and Zero-Trust (ZT) policies to break critical attack paths and bolster cyber defenses. Our evaluation process is twofold; evaluating the performance of the shortest path identification and assessing the attack path detection accuracy. Our results show that SPGNN-API largely outperforms the baseline model for shortest path identification with an average accuracy$\geq95$% and successfully detects 100% of the potentially compromised assets, outperforming the attack graph baseline by 47%. Houssem Jmal, Firas Ben Hmida, Nardine Basta, Muhammad Ikram 0001, Mohamed Ali Kâafar, Andy Walker |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | An Empirical Analysis of Security and Privacy Risks in Android Cryptocurrency Wallet Apps
I Wayan Budi Sentana, Muhammad Ikram 0001, Mohamed Ali Kâafar |
ACNS | 2 |
| 2023 | Exploring the Distinctive Tweeting Patterns of Toxic Twitter UsersabstractIn the pursuit of bolstering user safety, social media platforms deploy active moderation strategies, including content removal and user suspension. These measures target users engaged in discussions marked by hate speech or toxicity, often linked to specific keywords or hashtags. Nonetheless, the increasing prevalence of toxicity indicates that certain users adeptly circumvent these measures.This study examines consistently toxic users on Twitter (rebranded as X) Rather than relying on traditional methods based on specific topics or hashtags, we employ a novel approach based on patterns of toxic tweets, yielding deeper insights into their behavior.We analyzed 38 million tweets from the timelines of 12,148 Twitter users and identified the top 1,457 users who consistently exhibit toxic behavior, relying on metrics like the Gini index and Toxicity score. By comparing their posting patterns to those of non-consistently toxic users, we have uncovered distinctive temporal patterns, including contiguous activity spans, inter-tweet intervals (referred to as “Burstiness”), and churn analysis. These findings provide strong evidence for the existence of a unique tweeting pattern associated with toxic behavior on Twitter.Crucially, our methodology transcends Twitter and can be adapted to various social media platforms, facilitating the identification of consistently toxic users based on their posting behavior. This research contributes to ongoing efforts to combat online toxicity and offers insights for refining moderation strategies in the digital realm. We are committed to open research and will provide our code and data to the research community. Hina Qayyum, Muhammad Ikram 0001, Benjamin Zi Hao Zhao, Ian D. Wood, Nicolas Kourtellis, Mohamed Ali Kâafar |
IEEE Big Data | 2 |
| 2023 | On mission Twitter Profiles: A Study of Selective Toxic BehaviorabstractThe argument for persistent social media influence campaigns, often funded by malicious entities, is gaining traction. These entities utilize instrumented profiles to disseminate divisive content and disinformation, shaping public perception. Despite ample evidence of these instrumented profiles, few identification methods exist to locate them in the wild. To evade detection and appear genuine, small clusters of instrumented profiles engage in unrelated discussions, diverting attention from their true goals [34]. This strategic thematic diversity conceals their selective polarity towards certain topics and fosters public trust [49]. This study aims to characterize profiles potentially used for influence operations, termed “on-mission profiles,” relying solely on thematic content diversity within unlabeled data. Distinguishing this work is its focus on content volume and toxicity towards specific themes. Longitudinal data from 138K Twitter (rebranded as X) profiles and 293M tweets enables profiling based on theme diversity. High thematic diversity groups predominantly produce toxic content concerning specific themes, like politics, health, and news—classifying them as “on-mission” profiles. Using the identified on-mission” profiles, we design a classifier for unseen, unlabeled data. Employing a linear SVM model, we train and test it on an 80/20% split of the most diverse profiles. The classifier achieves a flawless 100% accuracy, facilitating the discovery of previously unknown “on-mission” profiles in the wild. Hina Qayyum, Muhammad Ikram 0001, Benjamin Zi Hao Zhao, Ian D. Wood, Nicolas Kourtellis, Mohamed Ali Kâafar |
IEEE Big Data | 2 |
| 2023 | Towards Automatic Annotation and Detection of Fake NewsabstractAutomated accounts or bots on Online Social Networks (OSNs) play a significant role in disseminating information, including false news, which may instigate cyber propaganda. The existing research on fake news detection does not account for the existence of bots. Also, they only focus on identifying fake news in “the articles shared in posts” rather than the post’s (textual) content and use manually labeled limited datasets. In this research, we overcome the challenge of data scarcity by proposing an automated approach for labeling data using verified fact-checked statements on OSNs such as Twitter. Moreover, we analyze the presence and impact of bots and show that bots change their behavior over time. Our experiments focus on COVID-19, collect 10.22 million COVID-19-re1ated tweets, and use our annotation model to build an extensive ground truth dataset for classification purposes. We evaluated our automatic annotation model on two existing COVID-19-re1ated misinformation datasets and achieved a ~ 2% increase in precision compared to the existing annotation models. In addition, our best classification model achieves 83% precision, 96% recall, and a ~ 4% false positive rate on our annotated dataset, outperforming existing techniques. Mohd Majid Akhtar, Ishan Karunanayake, Bibhas Sharma, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
LCN | 5 |
| 2022 | Towards a Zero-Trust Micro-segmentation Network Security Strategy: An Evaluation FrameworkabstractMicro-segmentation is an emerging security technique that separates physical networks into isolated logical micro-segments (workloads). By tying fine-grained security policies to individual workloads, it limits the attacker’s ability to move laterally through the network, even after infiltrating the perimeter defences. While micro-segmentation is proved to be effective for shrinking enterprise networks attack surface, its impact assessment is almost absent in the literature. This research is dedicated to developing an analytical framework to characterise and quantify the effectiveness of micro-segmentation on enhancing networks security. We rely on a twofold graph-feature-based framework of the network connectivity and attack graphs to evaluate the network exposure and robustness, respectively. Tracking the variations of formulated metrics values post the deployment of micro-segmentation reveals exposure reduction and robustness improvement in the range of 60% – 90%. Nardine Basta, Muhammad Ikram 0001, Mohamed Ali Kâafar, Andy Walker |
NOMS | 2 |
| 2022 | A First Look at Android Apps' Third-Party Resources Loading
Hina Qayyum, I Wayan Budi Sentana, Giang L. D. Nguyen, Muhammad Ikram 0001, Gareth Tyson, Mohamed Ali Kâafar |
NSS | 5 |
| 2022 | An Empirical Assessment of Security and Privacy Risks of Web-Based Chatbots
Nazar Waheed, Muhammad Ikram 0001, Saad Sajid Hashmi, Xiangjian He, Priyadarsi Nanda |
WISE | 2 |
| 2021 | Longitudinal Compliance Analysis of Android Applications with Privacy Policies
Saad Sajid Hashmi, Nazar Waheed, Gioacchino Tangari, Muhammad Ikram 0001, Stephen Smith 0001 |
MobiQuitous | 4 |
| 2021 | BlockJack: Towards Improved Prevention of IP Prefix Hijacking Attacks in Inter-domain Routing via Blockchain
I Wayan Budi Sentana, Muhammad Ikram 0001, Mohamed Ali Kâafar |
SECRYPT | 2 |
| 2021 | Empirical Security and Privacy Analysis of Mobile Symptom Checking Apps on Google PlayabstractSmartphone technology has drastically improved over the past decade. These improvements have seen the creation of specialized health applications, which offer consumers a range of health-related activities such as tracking and checking symptoms of health conditions or diseases through their smartphones. We term these applications as Symptom Checking apps or simply SymptomCheckers. Due to the sensitive nature of the private data they collect, store and manage, leakage of user information could result in significant consequences. In this paper, we use a combination of techniques from both static and dynamic analysis to detect, trace and categorize security and privacy issues in 36 popular SymptomCheckers on Google Play. Our analyses reveal that SymptomCheckers request a significantly higher number of sensitive permissions and embed a higher number of third-party tracking libraries for targeted advertisements and analytics exploiting the privileged access of the SymptomCheckers in which they exist, as a mean of collecting and sharing critically sensitive data about the user and their device. We find that these are sharing the data that they collect through unencrypted plain text to the third-party advertisers and, in some cases, to malicious domains. The results reveal that the exploitation of SymptomCheckers is present in popular apps, still readily available on Google Play. I Wayan Budi Sentana, Muhammad Ikram 0001, Mohamed Ali Kâafar, Shlomo Berkovsky |
SECRYPT | 2 |
| 2021 | Analyzing security issues of android mobile health and medical applicationsabstractOBJECTIVE: We conduct a first large-scale analysis of mobile health (mHealth) apps available on Google Play with the goal of providing a comprehensive view of mHealth apps' security features and gauging the associated risks for mHealth users and their data. MATERIALS AND METHODS: We designed an app collection platform that discovered and downloaded more than 20 000 mHealth apps from the Medical and Health & Fitness categories on Google Play. We performed a suite of app code and traffic measurements to highlight a range of app security flaws: certificate security, sensitive or unnecessary permission requests, malware presence, communication security, and security-related concerns raised in user reviews. RESULTS: Compared to baseline non-mHealth apps, mHealth apps generally adopt more reliable signing mechanisms and request fewer dangerous permissions. However, significant fractions of mHealth apps expose users to serious security risks. Specifically, 1.8% of mHealth apps package suspicious codes (eg, trojans), 45.0% rely on unencrypted communication, and as much as 23.0% of personal data (eg, location information and passwords) is sent on unsecured traffic. An analysis of the app reviews reveals that mHealth app users are largely unaware of the surfaced security issues. CONCLUSION: Despite being better aligned with security best practices than non-mHealth apps, mHealth apps are still far from ensuring robust security guarantees. App users, clinicians, technology developers, and policy makers alike should be cognizant of the uncovered security issues and weigh them carefully against the benefits of mHealth apps. Gioacchino Tangari, Muhammad Ikram 0001, I Wayan Budi Sentana, Kiran Ijaz, Mohamed Ali Kâafar, Shlomo Berkovsky |
J. Am. Medical Informatics Assoc. | 2 |
| 2020 | Decentralized Control: A Case Study of Russia
Reethika Ramesh, Ram Sundara Raman, Matthew Bernhard, Victor Ongkowijaya, Leonid Evdokimov, Anne Edmundson, Steven Sprecher, Muhammad Ikram 0001, Roya Ensafi |
NDSS | 8 |
| 2020 | iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS Applications
Zhushou Tang, Minhui Xue 0001, Yuan Tian 0001, Sen Chen 0001, Muhammad Ikram 0001, Tielei Wang, Haojin Zhu |
USENIX Security Symposium | 6 |
| 2020 | Measuring and Analysing the Chain of Implicit Trust: A Study of Third-party Resources LoadingabstractThe web is a tangled mass of interconnected services, whereby websites import a range of external resources from various third-party domains. The latter can also load further resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This article performs a large-scale study of dependency chains in the web to find that around 50% of first-party websites render content that they do not directly load. Although the majority (84.91%) of websites have short dependency chains (below three levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third parties are classified as suspicious—although seemingly small, this limited set of suspicious third parties have remarkable reach into the wider ecosystem. We find that 73% of websites under-study load resources from suspicious third parties, and 24.8% of first-party webpages contain at least three third parties classified as suspicious in their dependency chain. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript codes downloading malware. Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi |
ACM Trans. Priv. Secur. | 1 |
| 2019 | A Decade of Mal-Activity Reporting: A Retrospective Analysis of Internet Malicious Activity BlacklistsabstractThis paper focuses on reporting of Internet malicious activity (or mal-activity in short) by public blacklists with the objective of providing a systematic characterization of what has been reported over the years, and more importantly, the evolution of reported activities. Using an initial seed of 22 blacklists, covering the period from January 2007 to June 2017, we collect more than 51 million mal-activity reports involving 662K unique IP addresses worldwide. Leveraging the Wayback Machine, antivirus (AV) tool reports and several additional public datasets (e.g., BGP Route Views and Internet registries) we enrich the data with historical meta-information including geo-locations (countries), autonomous system (AS) numbers and types of mal-activity. Furthermore, we use the initially labelled dataset of ~1.57 million mal-activities (obtained from public blacklists) to train a machine learning classifier to classify the remaining unlabeled dataset of ~44 million mal-activities obtained through additional sources. We make our unique collected dataset (and scripts used) publicly available for further research. The main contributions of the paper are a novel means of report collection, with a machine learning approach to classify reported activities, characterization of the dataset and, most importantly, temporal analysis of mal-activity reporting behavior. Inspired by P2P behavior modeling, our analysis shows that some classes of mal-activities (e.g., phishing) and a small number of mal-activity sources are persistent, suggesting that either blacklist-based prevention systems are ineffective or have unreasonably long update periods. Our analysis also indicates that resources can be better utilized by focusing on heavy mal-activity contributors, which constitute the bulk of mal-activities. Benjamin Zi Hao Zhao, Muhammad Ikram 0001, Hassan Jameel Asghar, Mohamed Ali Kâafar, Abdelberi Chaabane, Kanchana Thilakarathna |
AsiaCCS | 2 |
| 2019 | On optimization of ad-blocking lists for mobile devicesabstractOnline advertisements and third-party web tracking has gained much attention in recent years. Advertisers gather as much data and information about the users to provide targeted advertisement. Though this leads to a better user experience, it comes at the cost of privacy intrusive tracking. To this end, ad-blocking lists (or filter-lists, blacklists) have been introduced which prevent third-party tracking. Ad-blocking lists operate in a crowd-sourced manner, where new tracking domains (or rules) are continuously added by privacy activists and the redundant domains are discarded from the filter-list. Over time, the number of rules added outgrow the number of rules omitted, making it hard to manage the filter-lists. We empirically observe that the filter-lists mostly detect different ad and tracking domains. The filter-lists also use less than 1% of their rules on Alexa top 5,000 websites. This suggests the need to curate optimized filter-lists that provide high coverage and require less time to scan for a given domain on mobile devices. We develop an aggregated and filtered blacklist that is more than 150 times less bulky, and provides the same coverage as the union of the blacklists on Alexa top 5,000 websites. We also develop an update mechanism to incorporate new ad and tracking domains in the aggregated and filtered blacklist in a resource efficient manner. Saad Sajid Hashmi, Muhammad Ikram 0001, Stephen Smith 0001 |
MobiQuitous | 2 |
| 2019 | The Chain of Implicit Trust: An Analysis of the Web Third-party Resources LoadingabstractThe Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi |
WWW | 1 |
| 2019 | A Cartography of Web Tracking using DNS Records
Jingxiu Su, Zhenyu Li 0001, Stéphane Grumbach, Muhammad Ikram 0001, Kavé Salamatian, Gaogang Xie |
Comput. Commun. | 4 |
| 2018 | Web Tracking Cartography with DNS RecordsabstractWeb tracking plays a crucial role in the Web ecosystem. It relies on third-party tracking domains collecting user information for various applications such as advertisement and analytics. With the massive growth of the Internet, understanding tracking and its geographical roots is of strategic importance. The goal of this paper is to propose a thorough investigation of web tracking inside China taking advantage of a large dataset (1011records) containing two days of full DNS access from a major ISP providing both mobile and landline ADSL. Our results show that a power law applies on the traffic of both sites and trackers with a handful of trackers, 26, representing 90% of tracking activity. We then show that although most first-party sites accessed from China are owned by Chinese corporations, large proportion of trackers belong to US ones. This raises concerns about the analytics industry in China, and more generally shed new lights on the international data flows, the interdependency of the main actors, and the complexity of the threats for both people and states. Jingxiu Su, Zhenyu Li 0001, Stéphane Grumbach, Muhammad Ikram 0001, Kavé Salamatian, Gaogang Xie |
IPCCC | 4 |
| 2018 | Incognito: A Method for Obfuscating Web DataabstractUsers leave a trail of their personal data, interests, and intents while surfing or sharing information on the Web. Web data could therefore reveal some private/sensitive information about users based on inference analysis. The possible identification of information corresponding to a single individual by an inference attack holds true even if the user identifiers are encoded or removed in the Web data. Several works have been done on improving privacy of Web data through obfuscation methods~\citeHow09,Dom09,Sha05,Che14. However, these methods are neither comprehensive, generic to be applicable to any Web data, nor effective against adversarial attacks. To this end, we propose a privacy-aware obfuscation method for Web data addressing these identified drawbacks of existing methods. We use probabilistic methods to predict privacy risk of Web data that incorporates all key privacy aspects, which are uniqueness, uniformity, and linkability of Web data. The Web data with high predicted risk are then obfuscated by our method to minimize the privacy risk using semantically similar data. Our method is resistant against adversary who has knowledge about the datasets and model learned risk probabilities using differential privacy-based noise addition. Experimental study conducted on two real Web datasets validates the significance and efficacy of our method. Our results indicate that the average privacy risk reaches to 100% with a minimum of 10 sensitive Web entries, while at most 0% privacy risk could be attained with our obfuscation method at the cost of average utility loss of 64.3%. Rahat Masood, Dinusha Vatsalan, Muhammad Ikram 0001, Mohamed Ali Kâafar |
WWW | 3 |
| 2017 | A first look at mobile Ad-Blocking appsabstractOnline advertisers, third party trackers and analytics services are constantly tracking user activities as they access web services through their web browsers or mobile apps. While, web browser plugins disabling and blocking Ads (often associated tracking/analytics scripts), e.g. AdBlock Plus[3] have been well studied and are relatively well understood, an emerging new category of apps in the tracking mobile eco-system, referred as the mobile Ad-Blocking apps, received very little to no attention. With the recent significant increase of the number of mobile Ad-Blockers and the exponential growth of mobile Ad-Blocking apps' popularity, this paper aims to fill in the gap and study this new category of players in the mobile ad/tracking eco-system. This paper presents the first study of Android Ad-Blocking apps (or Ad-Blockers), analysing 97 Ad-Blocking mobile apps extracted from a corpus of more than 1.5 million Android apps on Google Play. While the main (declared) purpose of the apps is to block advertisements and mobile tracking services, our data analysis revealed the paradoxical presence of third-party tracking libraries and permissions to access sensitive resources on users' mobile devices, as well as the existence of embedded malware code within some mobile Ad-Blockers. We also analysed user reviews and found that even though a fraction of users raised concerns about the privacy and the actual performance of the mobile Ad-Blocking apps, most of the apps still attract a relatively high rating. Muhammad Ikram 0001, Mohamed Ali Kâafar |
NCA | 1 |
| 2017 | Towards Seamless Tracking-Free Web: Improved Detection of Trackers via One-class LearningabstractAbstract Numerous tools have been developed to aggressively block the execution of popular JavaScript programs in Web browsers. Such blocking also affects functionality of webpages and impairs user experience. As a consequence, many privacy preserving tools that have been developed to limit online tracking, often executed via JavaScript programs, may suffer from poor performance and limited uptake. A mechanism that can isolate JavaScript programs necessary for proper functioning of the website from tracking JavaScript programs would thus be useful. Through the use of a manually labelled dataset composed of 2,612 JavaScript programs, we show how current privacy preserving tools are ineffective in finding the right balance between blocking tracking JavaScript programs and allowing functional JavaScript code. To the best of our knowledge, this is the first study to assess the performance of current web privacy preserving tools in determining tracking vs. functional JavaScript programs. To improve this balance, we examine the two classes of JavaScript programs and hypothesize that tracking JavaScript programs share structural similarities that can be used to differentiate them from functional JavaScript programs. The rationale of our approach is that web developers often “borrow” and customize existing pieces of code in order to embed tracking (resp. functional) JavaScript programs into their webpages. We then propose one-class machine learning classifiers using syntactic and semantic features extracted from JavaScript programs. When trained only on samples of tracking JavaScript programs, our classifiers achieve accuracy of 99%, where the best of the privacy preserving tools achieve accuracy of 78%. The performance of our classifiers is comparable to that of traditional two-class SVM. One-class classification, where a training set of only tracking JavaScript programs is used for learning, has the advantage that it requires fewer labelled examples that can be obtained via manual inspection of public lists of well-known trackers. We further test our classifiers and several popular privacy preserving tools on a larger corpus of 4,084 websites with 135,656 JavaScript programs. The output of our best classifier on this data is between 20 to 64% different from the tools under study. We manually analyse a sample of the JavaScript programs for which our classifier is in disagreement with all other privacy preserving tools, and show that our approach is not only able to enhance user web experience by correctly classifying more functional JavaScript programs, but also discovers previously unknown tracking services. Muhammad Ikram 0001, Hassan Jameel Asghar, Mohamed Ali Kâafar, Anirban Mahanti, Balachander Krishnamurthy |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | Measuring, Characterizing, and Detecting Facebook Like FarmsabstractOnline social networks offer convenient ways to reach out to large audiences. In particular, Facebook pages are increasingly used by businesses, brands, and organizations to connect with multitudes of users worldwide. As the number of likes of a page has become a de-facto measure of its popularity and profitability, an underground market of services artificially inflating page likes (“like farms ”) has emerged alongside Facebook’s official targeted advertising platform. Nonetheless, besides a few media reports, there is little work that systematically analyzes Facebook pages’ promotion methods. Aiming to fill this gap, we present a honeypot-based comparative measurement study of page likes garnered via Facebook advertising and from popular like farms. First, we analyze likes based on demographic, temporal, and social characteristics and find that some farms seem to be operated by bots and do not really try to hide the nature of their operations, while others follow a stealthier approach, mimicking regular users’ behavior. Next, we look at fraud detection algorithms currently deployed by Facebook and show that they do not work well to detect stealthy farms that spread likes over longer timespans and like popular pages to mimic regular users. To overcome their limitations, we investigate the feasibility of timeline-based detection of like farm accounts, focusing on characterizing content generated by Facebook accounts on their timelines as an indicator of genuine versus fake social activity. We analyze a wide range of features extracted from timeline posts, which we group into two main categories: lexical and non-lexical. We find that like farm accounts tend to re-share content more often, use fewer words and poorer vocabulary, and more often generate duplicate comments and likes compared to normal users. Using relevant lexical and non-lexical features, we build a classifier to detect like farms accounts that achieves a precision higher than 99% and a 93% recall. Muhammad Ikram 0001, Lucky Onwuzurike, Shehroze Farooqi, Emiliano De Cristofaro, Arik Friedman, Guillaume Jourjon, Mohamed Ali Kâafar, Zubair Shafiq |
ACM Trans. Priv. Secur. | 1 |
| 2016 | An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps
Muhammad Ikram 0001, Narseo Vallina-Rodriguez, Suranga Seneviratne, Mohamed Ali Kâafar, Vern Paxson |
Internet Measurement Conference | 1 |
| 2009 | Route-over vs mesh-under routing in 6LoWPANabstractTransmission of IPv6 packets over Low-power Wireless Personal Area Networks (6LoWPAN) was considered nearly impractical once. The size of IPv6 packets is much larger than the packet size of the IEEE 802.15.4 data link layer. 6LoWPAN implements an adaptation layer between network and data link layers. Main purpose of the adaptation layer is to fragment and reassemble IPv6 packets. Implementation of the adaptation layer enhances the routing/forwarding decision of packets both network and adaptation layers. We can divide the routing scheme in 6LoWPAN into two categories: the mesh-under and the route-over, based on the routing decision taken on adaptation layer or network layer respectively. In this paper we perform an analytical comparison between these two schemes in terms of the packet/fragment arrival probability, the total number of transmissions and the total delay between source and destination. We also compare the selective fragment retransmission mechanism between mesh-under and route-over schemes. Aminul Haque Chowdhury, Muhammad Ikram 0001, Hyon-Soo Cha, Hassen Redwan, S. M. Saif Shams, Ki-Hyung Kim, Seung-Wha Yoo |
IWCMC | 2 |
| 2009 | A simple lightweight authentic bootstrapping protocol for IPv6-based low rate wireless personal area networks (6LoWPANs)abstractResource and power limited IPv6-based Low rate Wireless Personal Area Networks (6LoWPANs) requires energy efficient access control scheme for authentication, bootstrapping, and commissioning of prospective 6LoWPAN devices. In this paper, we propose an energy efficient lightweight mutual authentication scheme for 6LoWPANs which ensures secure network bootstrapping. The proposed scheme is independent of any key management infrastructure; keys or authentication secret data for mutual authentication is generated or transferred to 6LoWPAN device on-the-fly. Analysis of the proposed scheme have shown that the scheme is secure against various kinds of security and privacy attacks and is light-weight, adaptable, and scalable for 6LoWPANs. Muhammad Ikram 0001, Aminul Haque Chowdhury, Hyon-Soo Cha, Ki-Hyung Kim, Seung-Wha Yoo, Dong-Kyoo Kim |
IWCMC | 1 |
| 2008 | Secure and Survivable Group Communication over MANET Using CRTDH Based on a Virtual Subnet ModelabstractMobile ad hoc network (MANET) consists of a set of wireless devices such as PDAs and notebooks. In MANET there is no centralized administration as well as base station, so the network topology changes frequently. Group communication in MANET is becoming more important day by day because of increasing popularity of MANET as well as constructing subgroups to support ldquomany-to-manyrdquo communication. However, this research area has not taken much attention among researcher so far. In this paper we propose a new protocol for establishing a secure and survivable MANET group communication using virtual subnet model applying CRTDH scheme. Then, we discuss the security analysis of our protocol. Aminul Haque Chowdhury, Muhammad Ikram 0001, Ki-Hyung Kim |
APSCC | 2 |
| 2008 | A Lightweight Mutual Authentication Scheme for Mobile Radio Frequency IDentification (mRFID) SystemsabstractAdvances in wireless communication and embedded electronic systems have revolutionized everyday life via inter-networking sophisticated tiny and useful devices. Mobile RFID (mRFID) systems make it possible to get information about entities through portable devices including mobile handsets, PDAs, laptops, etc. RFID tags consist of secret information that can be accessed by an authorized mobile user via mRFID reader. Checking the authentication and authorization of RFID tags and mRFID reader is a very crucial security requirement of RFID systems. Unlike wired communication systems, wireless mRFID systems are open to security and privacy threats. In this paper, we propose mutual authentication for mRFID systems for handling security and privacy issues related to mRFID in private and enterprize zones. The proposed scheme eliminates the need of any extra key management infrastructure by assigning the keys or authentication secret data to mRFID reader on-the-fly for mutual authentication. Extensive security and performance analysis shows that the proposed scheme is secure against various kinds of security and privacy attacks and it is light-weight, adaptable, and scalable for mRFID systems. Muhammad Ikram 0001, Aminul Haque Chowdhury, Hassen Redwan, Jong-bin Koh, Ki-Hyung Kim, Dong-Kyoo Kim |
IPCCC | 1 |