VLDB 2026 Research / reviewers in the wild / expert
Kapil Singh
dblp:87/6804
· DBLP profile ↗
22ranked-venue papers
8as first author
3since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 6 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorComputer networks · 2Databases, data management, data science and information retrieval · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Towards Automated Regulation Analysis for Effective Privacy Compliance
Sunil Manandhar, Kapil Singh, Adwait Nadkarni |
NDSS | 2 |
| 2024 | Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election WebsitesabstractPolitical campaigns are known to collect private user data, whether for building voter profiles, engaging with volunteers, or for soliciting donations. However, as such campaigns are classified as nonprofit in the United States (U.S.), their privacy practices have not received the same level of scrutiny as those of for-profit enterprises. This paper presents the Polityzer framework to evaluate the privacy posture of political campaign websites, and uses it to analyze 2060 campaign websites active during the U.S. election of November 2020. Our analysis leads to 20 key findings that demonstrate gaps in the privacy postures of political campaigns. For instance, we find that campaigns collect extensive private data they are not required to by the Federal Election Commission (FEC), and a vast majority do not provide any form of privacy disclosure. When disclosures are provided, they are often incomplete. We also found that campaigns may be inadvertently sharing data with other campaigns through common fundraising platforms, without disclosing such sharing. Reporting the lack of privacy disclosure to the respective campaigns yields further insights into the rationale behind their security posture. Finally, we discuss ways in which our results could enable future research, inform emerging privacy regulations, and transform user behavior regarding data privacy in this critical context. Kaushal Kafle, Prianka Mandal, Kapil Singh, Benjamin Andow, Adwait Nadkarni |
SP | 3 |
| 2022 | Smart Home Privacy Policies Demystified: A Study of Availability, Content, and Coverage
Sunil Manandhar, Kaushal Kafle, Benjamin Andow, Kapil Singh, Adwait Nadkarni |
USENIX Security Symposium | 4 |
| 2020 | Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheck
Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, Serge Egelman |
USENIX Security Symposium | 6 |
| 2019 | PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play
Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, Tao Xie 0001 |
USENIX Security Symposium | 7 |
| 2019 | PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity AssetsabstractUser's digital identity information has privacy and security requirements. Privacy requirements include confidentiality of the identity information itself, anonymity of those who verify and consume a user's identity information and unlinkability of online transactions which involve a user's identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's identity information. Such privacy and security requirements, although conflicting, are critical for identity management systems enabling the exchange of users' identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security. Hasini Gunasinghe, Ashish Kundu, Elisa Bertino, Hugo Krawczyk, Suresh Chari, Kapil Singh, Dong Su |
WWW | 6 |
| 2017 | UiRef: analysis of sensitive user inputs in Android applicationsabstractMobile applications frequently request sensitive data. While prior work has focused on analyzing sensitive-data uses originating from well-defined API calls in the system, the security and privacy implications of inputs requested via application user interfaces have been widely unexplored. In this paper, our goal is to understand the broad implications of such requests in terms of the type of sensitive data being requested by applications. Benjamin Andow, Akhil Acharya, Dengfeng Li 0003, William Enck, Kapil Singh, Tao Xie 0001 |
WISEC | 5 |
| 2016 | CASE: Comprehensive Application Security Enforcement on COTS Mobile DevicesabstractWithout violating existing app security enforcement, malicious modules inside apps, such as a library or an external class, can steal private data and abuse sensitive capabilities meant for other modules inside the same apps. These so-called "module-level attacks" are quickly emerging, fueled by the pervasive use of third-party code in apps and the lack of module-level security enforcement on mobile platforms. Suwen Zhu, Long Lu, Kapil Singh |
MobiSys | 3 |
| 2016 | AppShell: Making data protection practical for lost or stolen Android devicesabstractMobile apps continue to consume increasing amounts of sensitive data, such as banking credentials and classified documents. At the same time, the number of smartphone thefts is increasing at a rapid speed. As a result, there is an imperative need to protect sensitive data on lost or stolen mobile devices. In this work, we develop a practical solution to protect sensitive data on mobile devices. Our solution enables adaptive protection by pro-actively stepping up or stepping down data security based on perceived contextual risk of the device. We realize our solution for the Android platform in the form of a system called AppShell. AppShell does not require root privilege, nor need any modification to the underlying framework, and hence is a ready-to-deploy solution. It supports both in-memory and on-disk data protection by transparently encrypting the data, and discarding the encryption key, when required, for enhanced protection. We implement a working prototype of AppShell and evaluate it against several popular Android apps. Our results show that AppShell can successfully protect sensitive data in the lost devices with a reasonable performance overhead. Xuxian Jiang, Kapil Singh, Yajin Zhou |
NOMS | 2 |
| 2015 | WebCapsule: Towards a Lightweight Forensic Engine for Web BrowsersabstractPerforming detailed forensic analysis of real-world web security incidents targeting users, such as social engineering and phishing attacks, is a notoriously challenging and time-consuming task. To reconstruct web-based attacks, forensic analysts typically rely on browser cache files and system logs. However, cache files and logs provide only sparse information often lacking adequate detail to reconstruct a precise view of the incident. To address this problem, we need an always-on and lightweight (i.e., low overhead) forensic data collection system that can be easily integrated with a variety of popular browsers, and that allows for recording enough detailed information to enable a full reconstruction of web security incidents, including phishing attacks. Christopher Neasbitt, Bo Li 0058, Roberto Perdisci, Long Lu, Kapil Singh, Kang Li 0001 |
CCS | 5 |
| 2015 | What is wrecking your data plan? A measurement study of mobile web overheadabstractThe growing popularity of smartphones and continuous user demand for a rich web experience has resulted in an exponential surge in cellular bandwidth requirements. Cellular providers have struggled to keep pace with the new requirements while users often face a monetary cost associated with the data downloaded to their device. While many modern websites have adapted to the new mobile habitat, they often take shortcuts to transition from their desktop to mobile versions, many times carrying redundant content that is never utilized. Moreover, mobile users are effectively paying for certain undesirable content, such as advertisements, in the form of their bandwidth costs. In this paper, we study the composition and complexity of modern websites, from both a mobile and desktop perspective, to identify sources of wasted bandwidth. We developed a custom crawler-based framework to perform an in-depth analysis of the top 100,000 popular sites ranked by Alexa. Our results show that 23% or more of the content size on an average website is unnecessary, unused or redundant. Our results serve as a motivation for developing optimized websites and enhancing the web infrastructure to better suit the mobile environment with emphasis on reducing bandwidth costs, while also improving performance and efficiency. Abner Mendoza, Kapil Singh, Guofei Gu |
INFOCOM | 2 |
| 2014 | CCS'14 Co-Located Workshop Summary for SPSM 2014abstractSecurity and privacy in smartphones and mobile devices is an emerging area which has received significant attention from the research community during the past few years. The SPSM workshop was created to bring together these researchers and practitioners. Following the success of the three previous editions, we present this fourth edition of the workshop which has attracted a significant number of great submissions and benefited from the expertise of an international program committee comprising of mobile security experts across the academia and the industry. Kapil Singh, Zhenkai Liang |
CCS | 1 |
| 2013 | Accurate and efficient reliability estimation techniques during ADL-driven embedded processor designabstractThe downscaling of technology features has brought the system developers an important design criteria, reliability, into prime consideration. Due to external radiation effects and temperature gradients, the CMOS device is not guaranteed anymore to function flawlessly. On the other hand, admission for errors to occur allows extending the power budget. The power-performance-reliability trade-off compounds the system design challenge, for which efficient design exploration framework is needed. In this work, we present a high-level processor design framework extended with two reliability estimation techniques. First, a simulation-based technique, which allows a generic instruction-set simulator to estimate reliability via high-level fault injection capability. Second, a novel analytical technique, which is based on the reliability model for coarse arithmetic logical operator blocks within a processor instruction. The techniques are tested with a RISC processor and several embedded application kernels. Our results show the efficiency and accuracy of these techniques against a HDL-level reliability estimation framework. Zheng Wang 0020, Kapil Singh, Chao Chen 0022, Anupam Chattopadhyay |
DATE | 2 |
| 2013 | Practical Context-Aware Permission Control for Hybrid Mobile Applications
Kapil Singh |
RAID | 1 |
| 2012 | Biometric authentication on a mobile device: a study of user effort, error and task disruptionabstractWe examine three biometric authentication modalities -- voice, face and gesture -- as well as password entry, on a mobile device, to explore the relative demands on user time, effort, error and task disruption. Our laboratory study provided observations of user actions, strategies, and reactions to the authentication methods. Face and voice biometrics conditions were faster than password entry. Speaking a PIN was the fastest for biometric sample entry, but short-term memory recall was better in the face verification condition. None of the authentication conditions were considered very usable. In conditions that combined two biometric entry methods, the time to acquire the biometric samples was shorter than if acquired separately but they were very unpopular and had high memory task error rates. These quantitative results demonstrate cognitive and motor differences between biometric authentication modalities, and inform policy decisions in selecting authentication methods. Shari Trewin, Calvin Swart, Larry Koved, Jacquelyn Martino, Kapil Singh, Shay Ben-David |
ACSAC | 5 |
| 2012 | xAccess: A unified user-centric access control framework for web applicationsabstractWith the rapid growth of Web 2.0, users are contributing more and more content on the Internet, in the form of user profiles, blogs, reviews, etc. With this increased sharing comes a pressing need for access control policies and mechanisms to protect the users' privacy. Access control has remained largely centralized and under the control of the web applications. Moreover, most web applications either provide no or very primitive and limited access control. We argue that the owner of any piece of data on the web should be able to decide how to control access to this data. This argument should hold not only for the web applications contributing data, but also for the contributing users. In other words, users should be able to choose their own access control models to control the sharing of their data independent of the underlying applications. In this work, we present a novel framework, called xAccess, for providing access control that empowers users to control how they want their data to be accessed. xAccess is analogous to the single sign-on mechanism, however, instead of providing login capability, it provides the user with a single point for defining his access control models and policies for one or multiple applications. On one hand, xAccess enables individual users to use a single unified access control across multiple web applications; and on the other hand, it allows an application to support different access control models deployed by its users with a single model abstraction. We demonstrate the viability of our design by means of a platform prototype. The usability of the platform is further evaluated by developing sample applications using the xAccess APIs. Kapil Singh |
NOMS | 1 |
| 2012 | Practical end-to-end web content integrityabstractWidespread growth of open wireless hotspots has made it easy to carry out man-in-the-middle attacks and impersonate web sites. Although HTTPS can be used to prevent such attacks, its universal adoption is hindered by its performance cost and its inability to leverage caching at intermediate servers (such as CDN servers and caching proxies) while maintaining end-to-end security. To complement HTTPS, we revive an old idea from SHTTP, a protocol that offers end-to-end web integrity without confidentiality. We name the protocol HTTPi and give it an efficient design that is easy to deploy for today's web. In particular, we tackle several previously-unidentified challenges, such as supporting progressive page loading on the client's browser, handling mixed content, and defining access control policies among HTTP, HTTPi, and HTTPS content from the same domain. Our prototyping and evaluation experience show that HTTPi incurs negligible performance overhead over HTTP, can leverage existing web infrastructure such as CDNs or caching proxies without any modifications to them, and can make many of the mixed-content problems in existing HTTPS web sites easily go away. Based on this experience, we advocate browser and web server vendors to adopt HTTPi. Kapil Singh, Helen J. Wang, Alexander Moshchuk, Collin Jackson, Wenke Lee |
WWW | 1 |
| 2010 | Evaluating Bluetooth as a Medium for Botnet Command and Control
Kapil Singh, Samrit Sangal, Nehil Jain, Patrick Traynor, Wenke Lee |
DIMVA | 1 |
| 2010 | On the Incoherencies in Web Browser Access Control PoliciesabstractWeb browsers' access control policies have evolved piecemeal in an ad-hoc fashion with the introduction of new browser features. This has resulted in numerous incoherencies. In this paper, we analyze three major access control flaws in today's browsers: (1) principal labeling is different for different resources, raising problems when resources interplay, (2) runtime changes to principal identities are handled inconsistently, and (3) browsers mismanage resources belonging to the user principal. We show that such mishandling of principals leads to many access control incoherencies, presenting hurdles for web developers to construct secure web applications. A unique contribution of this paper is to identify the compatibility cost of removing these unsafe browser features. To do this, we have built WebAnalyzer, a crawler-based framework for measuring real-world usage of browser features, and used it to study the top 100,000 popular web sites ranked by Alexa. Our methodology and results serve as a guideline for browser designers to balance security and backward compatibility. Kapil Singh, Alexander Moshchuk, Helen J. Wang, Wenke Lee |
IEEE Symposium on Security and Privacy | 1 |
| 2009 | xBook: Redesigning Privacy Control in Social Networking Platforms
Kapil Singh, Sumeer Bhola, Wenke Lee |
USENIX Security Symposium | 1 |
| 2008 | Evaluating email's feasibility for botnet command and controlabstractThe usefulness of email has been tempered by its role in the widespread distribution of spam and malicious content. Security solutions have focused on filtering out malicious payloads and weblinks from email; the potential dangers of email go past these boundaries: harmless-looking emails can carry dangerous, hidden botnet content. In this paper, we evaluate the suitability of email communication for botnet command and control. What makes email-based botnets interesting is the lack of clear detection and mitigation strategies that defenders could use to disrupt the botnet. We first demonstrate that botnet commands can remain hidden in spam due to its enormous volume. If email providers deploy specialized detection of spam-based botnets, botmasters can alternatively communicate with bots via non-spam email that cannot be safely discarded. We show the viability of such communication by means of simulations and a prototype, and we discuss the limited prospects for detection of email botnets. Kapil Singh, Abhinav Srivastava, Jonathon T. Giffin, Wenke Lee |
DSN | 1 |
| 2007 | Understanding Precision in Host Based Intrusion Detection
Monirul Islam Sharif, Kapil Singh, Jonathon T. Giffin, Wenke Lee |
RAID | 2 |