Kiavash Satvat

dblp:143/1847 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
2since 2021 · last 2024
0009-0008-6770-4391ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 2 since 2021
YearPublicationVenuePosition
2024 TIPCE: A Longitudinal Threat Intelligence Platform Comprehensiveness Analysis
abstract
Threat Intelligence (TI) serves as a vital component of cybersecurity, empowering organizations to combat cyber threats proactively. While existing research primarily focuses on analyzing threat intelligence feeds from Threat Intelligence Sharing Platforms (TISPs), the extensive data available within TISPs knowledge bases remains largely unexplored. This study aims to fill this gap by proposing a novel approach to perform the first in-depth empirical study of prominent TISPs' databases. To achieve this, we propose an innovative approach to construct a ground truth dataset of Indicators of Compromise (IOCs) derived from threat reports. We implement our approach in a tool called TIPCE, which processes over 50,000 threat reports, extracting more than 182K IOCs with high accuracy. TIPCE leverages this dataset to measure and study different features of four known TISP databases, including their coverage, overlap, and timeliness. Our results provide novel longitudinal insights into TISPs, including their distinct performance per IOC type and considerable overlap between TISP databases.
Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan
CODASPY1
2021 Extractor: Extracting Attack Behavior from Threat Reports
abstract
The knowledge on attacks contained in Cyber Threat Intelligence (CTI) reports is very important to effectively identify and quickly respond to cyber threats. However, this knowledge is often embedded in large amounts of text, and therefore difficult to use effectively. To address this challenge, we propose a novel approach and tool called Extractor that allows precise automatic extraction of concise attack behaviors from CTI reports. Extractor makes no strong assumptions about the text and is capable of extracting attack behaviors as provenance graphs from unstructured text. We evaluate Extractor using real-world incident reports from various sources as well as reports of DARPA adversarial engagements that involve several attack campaigns on various OS platforms of Windows, Linux, and FreeBSD. Our evaluation results show that Extractor can extract concise provenance graphs from CTI reports and show that these graphs can successfully be used by cyber-analytics tools in threat-hunting.
Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan
EuroS&P1
2020 CREPE: A Privacy-Enhanced Crash Reporting System
abstract
Software crashes are nearly impossible to avoid. The reported crashes often contain useful information assisting developers in finding the root cause of the crash. However, crash reports may carry sensitive and private information about the users and their systems, which may be used by an attacker who has compromised the crash reporting system to violate the user's privacy and security. Besides, a single bug may trigger loads of identical reports which excessively consumes system resources and overwhelms application developers.
Kiavash Satvat, Maliheh Shirvanian, Mahshid Hosseini, Nitesh Saxena
CODASPY1
2019 CATCHA: When Cats Track Your Movements Online
Prakash Shrestha, Nitesh Saxena, Ajaya Neupane, Kiavash Satvat
ISPEC4
2019 Brain Hemorrhage: When Brainwaves Leak Sensitive Medical Conditions and Personal Information
abstract
Brain Computer Interfaces (BCI) are rapidly gaining popularity in consumer market. It is therefore important to analyze the security and privacy threats these devices may introduce to their users. In this paper, we explore how malicious access to brainwave signals may surreptitiously reveal users' privacy-sensitive medical conditions and personal information, while they are browsing the web (or interacting with an app). At a conceptual level, we investigate the potential of brainwave signals, captured during a user's normal interactions with visual stimuli (e.g., images and audio-visuals) through a website or computer, in exposing whether the user is suffering from a given medical disorder (e.g., drug abuse or autism) and to which demographics group the user belongs (e.g., young vs. elderly or male vs. female). At an empirical level, as two representative case studies into such conceptual attacks, we present a concrete brainwave privacy attack, (Brain) Hemorrhage11In the context of our work, the term “Hemorrhage” is an attack against brainwave privacy. Brain Hemorrhage is a type of alcoholic cocktail, and hence the terminology is also intended to capture one of the case studies of our work on Alcohol Use Disorder., focusing on the leakage of Alcohol Usage Disorder (AUD) and users' age group. Hemorrhage is designed using machine learning techniques to identify the users suffering from AUD and age group by analyzing the seemingly innocuous brainwave signals leaked online in response to users' viewing of simple images or watching of videos. Based on the publicly available EEG datasets on AUD and aging, our study shows that Hemorrhage can predict the presence or absence of alcohol usage disorder with the precision of 96% and the presence or absence of aging condition with 94% accuracy. We also analyze, visualize and interpret the differences in the brainwave signals corresponding to AUD and aging, which serves to justify why our attack succeeds. While the use of neuroimaging devices to diagnose medical disorders in clinical settings is a common practice in the medical field, our study constitutes one of the first steps towards exploring the malicious use of brainwave devices in compromising people's health information privacy in an online setting (otherwise protected under the HIPAA law) as well as their age privacy. Given any website can have unfettered, permission-less access to the signals captured by the current BCI devices, we believe that our work raises a serious online health privacy and age privacy issues as these devices get widely deployed.
Ajaya Neupane, Kiavash Satvat, Mahshid Hosseini, Nitesh Saxena
PST2
2018 Do Social Disorders Facilitate Social Engineering?: A Case Study of Autism and Phishing Attacks
abstract
Social engineering is a well-established and well-studied threat especially against healthy computer users. Little studied, however, is the level of vulnerability to social engineering attacks against people with medical conditions. Social disorders in particular may make people more susceptible to such attacks. In this paper, as an initial line of investigation into this understudied research line, we launch a study of phishing, a prominent social engineering attack, against people suffering from autism spectrum disorder, a unique developmental disorder characterized by hampered social skills and communication.
Ajaya Neupane, Kiavash Satvat, Nitesh Saxena, Despina Stavrinos, Haley Johnson Bishop
ACSAC2
2017 Erratum to "On the Privacy of Private Browsing - A Forensic Approach" [JISA 19/1(2014), 88-100]
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini
J. Inf. Secur. Appl.1
2014 On the privacy of private browsing - A forensic approach
Kiavash Satvat, Matthew Forshaw, Feng Hao 0001, Ehsan Toreini
J. Inf. Secur. Appl.1