VLDB 2026 Research / reviewers in the wild / expert
Sambuddho Chakravarty
dblp:95/1983
· DBLP profile ↗
20ranked-venue papers
3as first author
10since 2021 · last 2026
0009-0005-0955-3378ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 3 first-author · 9 since 2021Computer networks · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ViNET: Connecting the Unconnected using Video over LTE
Manav Mittal, Yogesh Kaushik, Anirudh S. Kumar, Mukulika Maity, Sambuddho Chakravarty |
EuroS&P | 5 |
| 2026 | The Invisible Ink of the Android Malware World: A Longitudinal Study on the Usage of Covert Communication Channels
Zeya Umayya, Manan Aggarwal, Manan Chugh, Mann Nariya, Yogesh Kaushik, Sambuddho Chakravarty |
EuroS&P | 6 |
| 2024 | How Many Hands in the Cookie Jar? Examining Privacy Implications of Popular Apps in IndiaabstractSmartphone app usage has steeply risen in India in the past decade. But limited efforts in the past assess the privacy aspects of these smartphone apps. Many of these are used for common utilities and handle sensitive user data. Such sensitive data leaks can have a wide variety of consequences when exposed to untrusted players (e.g., repressive governments, data/content hosting companies, and other third parties). These could range from mere embar-rassment to personal targeting and surveillance. This paper presents a measurement study on the data collection and privacy considerations of some of the most popular apps on the Indian Google Play Store. We selected 24 apps, and analyzed their data collection behavior on phones as well as the security of the servers to whom they send the data. We also obfuscated the data being collected and sent to the backend servers. Interestingly, for the non-government apps we found that extensive (mostly personally identifiable information), often “unnecessary”, data collection is being performed. In other words, we observed that a lot of these apps work fine even without these pieces of sensitive information. We then classified the data collected as necessary or not necessary based on this information. Furthermore, we found that often such sensitive data may be available in plaintext to the intermediate players managing/deploying the hosting infrastructure. We also found that while the governmental services-based apps collect fewer such unnecessary data points, they often store the data on web-fronted back-end databases with little to no user authentication mechanisms enabled. We expect our study to enable better understanding among both users and app developers about the privacy implications of these data collection practices. Koustuv Kanungo, Rahul Khatoliya, Vishrut Arora, Aairah Bari, Arani Bhattacharya, Mukulika Maity, Sambuddho Chakravarty |
EuroS&P | 7 |
| 2024 | VoIP Vanguard: A Practical Front Line Defense Against VoIP Identification Attacks in Tor
S. Jithin, Reeshabh Kumar Ranjan, Shreyansh Nagpal, Mukulika Maity, Sambuddho Chakravarty |
NSS | 6 |
| 2024 | Every Sherlock Needs a Watson: Practical Semi-realtime Attack Elaboration System
Zeya Umayya, Arpit Nandi, Amartyo Roy, Sambuddho Chakravarty |
NSS | 4 |
| 2024 | Out in the Open: On the Implementation of Mobile App Filtering in India
Devashish Gosain, Kartikey Singh, Rishi Sharma 0004, Jithin Suresh Babu, Sambuddho Chakravarty |
PAM (2) | 5 |
| 2023 | Dolphin: A Cellular Voice Based Internet Shutdown Resistance SystemabstractTraditional censorship revolves around blocking access to some websites (or services) over the Internet. However, recently there has been a rise in the events of an extreme form of censorship viz., deliberate Internet shutdown, leading to complete Internet disconnection, severely impacting lives in such regions. Naturally, these shutdowns render all existing circumvention schemes unusable. Thus, we present Dolphin, a first of its kind system that can provide access to lightweight and delay tolerant Internet applications (email, tweets, news snippets, etc.) during Internet shutdowns. Dolphin uses the cellular voice channel to transmit data bits. A user in the shutdown region (who wishes to access these applications) requires a peer in non-shutdown region to send and retrieve content on its behalf. The data bits between the peers are sent by first encoding them into audio and then transmitting them over a cellular voice call. We overcome multiple challenges while designing and implementing Dolphin. E.g., the cellular voice channel is inherently lossy and unreliable. But the Internet applications need reliable transfers. Thus, in Dolphin we develop a TCP-style reliability layer to overcome the losses that works atop any underlying encoding and modulation scheme. Further, to evade eavesdroppers over the insecure voice channel, we provide end-to-end confidentiality. Also, Dolphin can function even without human intervention, by using cellular voice automation services. We experimentally show that Dolphin works for Internet applications, by testing it for sending email, tweets and accessing news snippets. All these applications take a few minutes to be accessed (e.g., a 500 character email was received in under 2 minutes). Piyush Kumar Sharma, Rishi Sharma 0004, Kartikey Singh, Mukulika Maity, Sambuddho Chakravarty |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Camoufler: Accessing The Censored Web By Utilizing Instant Messaging ChannelsabstractFree and open communication over the Internet is considered a fundamental human right, essential to prevent repressions from silencing voices of dissent. This has led to the development of various anti-censorship systems. Recent systems have relied on a common blocking resistance strategy i.e., incurring collateral damage to the censoring regimes, if they attempt to restrict such systems. However, despite being promising, systems built on such strategies pose additional challenges, viz., deployment limitations, poor QoS etc. These challenges prevent their wide scale adoption. Piyush Kumar Sharma, Devashish Gosain, Sambuddho Chakravarty |
AsiaCCS | 3 |
| 2021 | Telemetron: Measuring Network Capacity Between Off-Path Remote HostsabstractThis paper presents Telemetron, the first active bandwidth measurement tool that can estimate the path capacity between two remote hosts, from an off-path Measuring Machine (MM). It is possible to induce traffic flow between off-path remote hosts—sending request packets to one host, with a spoofed source IP, will cause the first host to send reply packets to the other. The challenge for MM is to measure the rate at which these packets arrive at the second machine. Our key observation is that if the second machine has a global IP-ID counter, the arrival of packets can be monitored remotely, using probes from MM. By observing the rate of increment in the global IP-ID counter, MM estimates the path capacity between remote hosts. Telemetron shows high accuracy; on average, the path capacity reported is 92.5% of the theoretical limit. Devashish Gosain, Aishwarya Jaiswal, Hrishikesh B. Acharya, Sambuddho Chakravarty |
LCN | 4 |
| 2021 | Too Close for Comfort: Morasses of (Anti-) Censorship in the Era of CDNsabstractAbstract Recent research claims that “powerful” nation-states may be hegemonic over significant web traffic of “underserved” nations (e.g., Brazil and India). Such traffic may be surveilled when transiting (or ending in) these powerful nations. On the other hand, content distribution networks (CDNs) are designed to bring web content closer to end-users. Thus it is natural to ask whether CDNs have led to the localization of Internet traffic within the country’s boundary, challenging the notion of nation-state hegemony. Further, such traffic localization may inadvertently enhance a country’s ability to coerce content providers to censor (or monitor) access within its boundary. On top of that, the obvious solution, i.e., anti-censorship approaches, may sadly face a new dilemma. Traditional ones, relying on proxies, are easily discoverable. Whereas newer ones (e.g., Decoy Routing, Cache-Browser, Domain Fronting and CovertCast etc.) might not work as they require accessing web content hosted outside the censors’ boundary. We thus quantitatively analyzed the impact of web content localization on various anti-censorship systems. Such analysis requires geolocating the websites. Thus we adapted a multilateration method, Constraint Based Geolocation (CBG), with additional heuristics. We call it as Region Specific CBG (R-CBG). In more than 89% cases, R-CBG correctly classifies hosts as inside (or outside) w.r.t. a nation. Our empirical study, involving five countries, shows that the majority (61%−92%) of popular country-specific websites are hosted within a client’s own country. Further, additional heuristics classify the majority of them to be on CDNs. Devashish Gosain, Mayank Mohindra, Sambuddho Chakravarty |
Proc. Priv. Enhancing Technol. | 3 |
| 2020 | The Road Not Taken: Re-thinking the Feasibility of Voice Calling Over TorabstractAnonymous VoIP calls over the Internet holds great significance for privacy-conscious users, whistle-blowers and political activists alike. Prior research deems popular anonymization systems like Tor unsuitable for providing the requisite performance guarantees that real-time applications like VoIP need. Their claims are backed by studies that may no longer be valid due to constant advancements in Tor. Moreover, we believe that these studies lacked the requisite diversity and comprehensiveness. Thus, conclusions from these studies, led them to propose novel and tailored solutions. However, no such system is available for immediate use. Additionally, operating such new systems would incur significant costs for recruiting users and volunteered relays, to provide the necessary anonymity guarantees. Piyush Kumar Sharma, Shashwat Chaudhary, Nikhil Hassija, Mukulika Maity, Sambuddho Chakravarty |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | SiegeBreaker: An SDN Based Practical Decoy Routing SystemabstractAbstract Decoy Routing (DR), a promising approach to censorship circumvention, uses routers (rather than end hosts) as proxy servers. Users of censored networks, who wish to use DR, send specially crafted packets, nominally addressed to an uncensored website. Once safely out of the censored network, the packets encounter a special router (the Decoy Router) which identifies them using a secret handshake, and proxies them to their true destination (a censored site). However, DR has implementation problems: it is infeasible to reprogram routers for the complex operations required. Existing DR solutions fall back on using commodity servers as a Decoy Router. But as servers are not efficient at routing, most web applications show poor performance when accessed over DR. A further concern is that the Decoy Router has to inspect all flows in order to identify the ones that need DR. This may itself be a breach of privacy for other users (who neither require DR nor want to be monitored). In this paper, we present a novel DR system, Siege- Breaker (SB), which solves the aforementioned problems using an SDN-based architecture. Previous proposals involve a single unit which performs all major operations (inspecting all flows, identifying the DR requests and proxying them). In contrast, SB distributes the tasks for DR among three independent modules. (1) The SDN controller identifies DR requests via a covert, privacy preserving scheme, and does not need to inspect all flows. (2) The reconfigurable SDN switch intercepts packets, and forwards them to a secret proxy efficiently. (3) The secret proxy server proxies the client’s traffic to the censored site. Our modular, lightweight design achieves performance comparable to direct TCP downloads, for both in-lab setups, and Internet based tests involving commercial SDN switches. Piyush Kumar Sharma, Devashish Gosain, Himanshu Sagar, Chaitanya Kumar, Aneesh Dogra, Vinayak S. Naik, Hrishikesh B. Acharya, Sambuddho Chakravarty |
Proc. Priv. Enhancing Technol. | 8 |
| 2018 | Where The Light Gets In: Analyzing Web Censorship Mechanisms in India
Tarun Kumar Yadav, Akshat Sinha, Devashish Gosain, Piyush Kumar Sharma, Sambuddho Chakravarty |
Internet Measurement Conference | 5 |
| 2017 | The Devil's in The Details: Placing Decoy Routers in the InternetabstractDecoy Routing, the use of routers (rather than end hosts) as proxies, is a new direction in anti-censorship research. Decoy Routers (DRs), placed in Autonomous Systems, proxy traffic from users; so the adversary, e.g. a censorious government, attempts to avoid them. It is quite difficult to place DRs so the adversary cannot route around them -- for example, we need the cooperation of 850 ASes to contain China alone [1]. Devashish Gosain, Anshika Agarwal, Sambuddho Chakravarty, Hrishikesh B. Acharya |
ACSAC | 3 |
| 2017 | Few Throats to Choke: On the Current Structure of the InternetabstractThe original design of the Internet was a resilient, distributed system, that maybe able to route around (and therefore recover from) massive disruption - up to and including nuclear war. However, network routing effects and business decisions cause traffic to often be routed through a relatively small set of Autonomous Systems (ASes). This is not merely an academic issue; it has practical implications - some of these frequently appearing ASes are hosted in censorious nations. Other than censoring their own citizens' network access, such ASes may inadvertently filter traffic for other foreign customer ASes. In this paper, we examine the extent of routing centralization in the Internet; identify the major players who control the “Internet backbone”; and point out how many of these are, in fact, under the jurisdiction of censorious countries (specifically, Russia, China, and India). Further, we show that China and India are not only the two largest nations by number of Internet users, but that many users in free and democratic countries are affected by collateral damage caused due to censorship by such countries. Hrishikesh B. Acharya, Sambuddho Chakravarty, Devashish Gosain |
LCN | 2 |
| 2017 | Mending Wall: On the Implementation of Censorship in India
Devashish Gosain, Anshika Agarwal, Sahil Shekhawat, Hrishikesh B. Acharya, Sambuddho Chakravarty |
SecureComm | 5 |
| 2014 | On the Effectiveness of Traffic Analysis against Anonymity Networks Using Flow Records
Sambuddho Chakravarty, Marco Valerio Barbera, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis |
PAM | 1 |
| 2011 | Detecting Traffic Snooping in Tor Using Decoys
Sambuddho Chakravarty, Georgios Portokalidis, Michalis Polychronakis, Angelos D. Keromytis |
RAID | 1 |
| 2010 | Traffic Analysis against Low-Latency Anonymity Networks Using Available Bandwidth Estimation
Sambuddho Chakravarty, Angelos Stavrou, Angelos D. Keromytis |
ESORICS | 1 |
| 2007 | An Experimental Study of Location Assisted Proactive HandoverabstractTraditionally, signal-to-noise ratio of a mobile determines the handoff dynamics of the mobile. But in certain cases, precise location of the mobile augmented by information services, such as IEEE 802.21 MIS, can expedite the handoff with similar performance results. We illustrate an experimental system that takes advantage of the mobile's relative location with the neighboring access point to perform proactive handoff. It keeps track of the current location of the mobile and then uses the information from the neighboring networks to help perform the proactive handoff. Proactive handover technique helps the mobile to communicate with these networks before the handover is complete thereby reducing the delay and packet loss. In some cases, location-assisted handover could prove to be more useful compared to the handover technique based on signal-noise-ratio. Ashutosh Dutta, Sambuddho Chakravarty, Kenichi Taniuchi, Victor Fajardo, Yoshihiro Ohba, David Famolari, Henning Schulzrinne |
GLOBECOM | 2 |