EDBT 2026 Demo / reviewers in the wild / expert
Hossein Siadati
dblp:122/8658
· DBLP profile ↗
7ranked-venue papers
3as first author
2since 2021 · last 2024
0000-0002-5293-8450ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Assessing Perceptual Hash Algorithms for Publicly Evaluatable FrameworkabstractImage manipulation threatens data integrity and public trust, making reliable authenticity tools essential. The development of a publicly evaluatable perceptual hash framework enables various applications, including private image search resilient to image alterations. Despite the potential of such a framework, little research has systematically analyzed the performance of various perceptual hash algorithms within it. In this paper, we assess the performance of several leading perceptual hash methods, including aHash, pHash, dHash, wHash, and DCT, across five diverse image datasets and examine how cryptographic techniques impact the effectiveness of the algorithms. Integrating advanced encryption techniques with perceptual hashing in this approach is instrumental in advancing data security. It improves the security, privacy, and computational efficiency of perceptual hashing, solidifying its importance within the overall methodology. Yaser Saei, Jafar Tahmoresnezhad, Sima Jafarikhah, Hossein Siadati |
SIN | 4 |
| 2023 | Exploring the Threat of Software Supply Chain Attacks on Containerized ApplicationsabstractContainerization has become a widely adopted approach for running contemporary software services, with its ingenious layering of Free Open Source Software (FOSS) libraries and packages. The security of containers heavily relies on the integrity of their underlying dependencies, making vulnerability assessment a critical focus for security professionals. However, the landscape has evolved, and recent software supply chain attacks have illuminated a pressing need to shift the focus beyond individual vulnerabilities and delve into the overall security of their supply chain. In this paper, we embark on a data-driven analysis of container threats by examining the security characteristics of software supply chains in their open source dependencies. Leveraging a comprehensive dataset of containers from Docker Hub, our study employs Software Supply Chain metrics like the OSSF scorecard and Software Bill of Material (SBOM) tooling to compile dependency lists. The analysis delivers valuable insights to the security community, empowering them to adopt more effective measures in thwarting and mitigating software supply chain attacks, thereby enhancing the resilience of modern software services. Motahare Mounesan, Hossein Siadati, Sima Jafarikhah |
SIN | 2 |
| 2019 | Lessons Learned Developing a Visual Analytics Solution for Investigative Analysis of Scamming ActivitiesabstractThe forensic investigation of communication datasets which contain unstructured text, social network information, and metadata is a complex task that is becoming more important due to the immense amount of data being collected. Currently there are limited approaches that allow an investigator to explore the network, text and metadata in a unified manner. We developed Beagle as a forensic tool for email datasets that allows investigators to flexibly form complex queries in order to discover important information in email data. Beagle was successfully deployed at a security firm which had a large email dataset that was difficult to properly investigate. We discuss our experience developing Beagle as well as the lessons we learned applying visual analytic techniques to a difficult real-world problem. Jay Koven, Cristian Felix, Hossein Siadati, Markus Jakobsson, Enrico Bertini |
IEEE Trans. Vis. Comput. Graph. | 3 |
| 2017 | Detecting Structurally Anomalous Logins Within Enterprise NetworksabstractMany network intrusion detection systems use byte sequences to detect lateral movements that exploit remote vulnerabilities. Attackers bypass such detection by stealing valid credentials and using them to transmit from one computer to another without creating abnormal network traffic. We call this method Credential-based Lateral Movement. To detect this type of lateral movement, we develop the concept of a Network Login Structure that specifies normal logins within a given network. Our method models a network login structure by automatically extracting a collection of login patterns by using a variation of the market-basket algorithm. We then employ an anomaly detection approach to detect malicious logins that are inconsistent with the enterprise network's login structure. Evaluations show that the proposed method is able to detect malicious logins in a real setting. In a simulated attack, our system was able to detect 82% of malicious logins, with a 0.3% false positive rate. We used a real dataset of millions of logins over the course of five months within a global financial company for evaluation of this work. Hossein Siadati, Nasir Memon |
CCS | 1 |
| 2017 | Mind your SMSes: Mitigating social engineering in second factor authentication
Hossein Siadati, Toan Nguyen 0001, Payas Gupta, Markus Jakobsson, Nasir Memon |
Comput. Secur. | 1 |
| 2016 | Detecting malicious logins in enterprise networks using visualizationabstractEnterprise networks have been a frequent target of data breaches and sabotage. In a widely used method, attackers establish a foothold in the target network by compromising a single computer or account. They then move laterally between computers to access valuable resources and information located deeper inside the network. To move laterally, attackers often steal valid user credentials. This paper is based on the observation that an attackers' pattern of access characteristics of the stolen credentials in the form ofdeviates from benign patterns and can be used to detect malicious logins. In this paper, we present APT-Hunter1, a visualization tool that helps security analysts to explore login data for discovering patterns and detecting malicious logins. To evaluate the proposed system, a pilot study was conducted over an open dataset of more than one billion logins of an enterprise network, provided by Los Alamos National Lab (LANL). Using APT-Hunter, security analysts (unfamiliar with the dataset) were able to detect 349 of 749 malicious logins related to lateral movements performed by a Red Team during a penetration test conducted at LANL. APT-Hunter is currently deployed in a global financial company and helps security analysts detect account compromises. Hossein Siadati, Bahador Saket, Nasir Memon |
VizSEC | 1 |
| 2013 | Protecting sensitive web content from client-side vulnerabilities with CRYPTONSabstractWeb browsers isolate web origins, but do not provide direct abstractions to isolate sensitive data and control computation over it within the same origin. As a result, guaranteeing security of sensitive web content requires trusting all code in the browser and client-side applications to be vulnerability-free. In this paper, we propose a new abstraction, called Crypton, which supports intra-origin control over sensitive data throughout its life cycle. To securely enforce the semantics of Cryptons, we develop a standalone component called Crypton-Kernel, which extensively leverages the functionality of existing web browsers without relying on their large TCB. Our evaluation demonstrates that the Crypton abstraction supported by the Crypton-Kernel is widely applicable to popular real-world applications with millions of users, including webmail, chat, blog applications, and Alexa Top 50 websites, with low performance overhead. Xinshu Dong, Zhaofeng Chen, Hossein Siadati, Shruti Tople, Prateek Saxena, Zhenkai Liang |
CCS | 3 |