Marie Vasek

dblp:145/2831 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
9since 2021 · last 2025
0009-0009-4045-9493ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-author · 5 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Fishing for Smishing: Understanding SMS Phishing Infrastructure and Strategies by Mining Public User Reports
abstract
Recently, there has been a worldwide surge in SMS phishing, aka smishing. However, the lack of open-access updated datasets makes it challenging for researchers to study this global issue. Mobile network operators and government agencies provide users special SMS spam reporting services. Though, these services are regional and users are largely unaware. So, users often turn to public forums such as Twitter or Reddit to report and discuss smishing. This paper presents a novel methodological approach to collect an updated smishing dataset and measure the infrastructure, targets, and strategies employed by attackers to lure victims. We programmatically collect users' smishing reports from five public forums, collating over 64.5k smishing image attachments and reports, which include 28.6k sender IDs and 25.9k URLs criminals abuse to conduct smishing campaigns across 66 languages. We unveil the exploited infrastructure ranging from mobile network operators to domains. We categorize smishing texts into seven scam types and explain lures criminals use to deceive victims into providing sensitive/financial information. Through a case study using real time measurements on a random sample of Twitter posts, we showcase how to uncover Android malware spread via smishing. We suggest effective mitigation approaches to curb this widespread cybercrime.
Sharad Agarwal, Antonis Papasavva, Guillermo Suarez-Tangil, Marie Vasek
IMC4
2025 Card-Not-Present Fraud resulting from Smishing Attacks: An Experimental Study
abstract
Smishing or SMS phishing is a recent update to email-based phishing. This modern scam hinges upon the trust that users have in their bank or online service to steal users’ personal details. While recent work examines these texts and the URLs sent, no work has empirically determined what happens after scammers obtain this credit card information. Card-not-present (CNP) fraud—where stolen card details are used to make purchases online without physical access to the card—has become a growing concern. While some investigate this indirectly using forum posts, the unavailability of credit card transaction data makes it tricky to study empirically. As smishing continues to rise, so does CNP fraud, resulting in more losses borne by consumers. To this end, we perform a proof-of-concept experiment towards understanding how criminals abuse stolen credit card details brought in from smishing. We collaborate with a mobile network operator and a financial institution to access live smishing URLs and test credit cards. We provide test credit cards to twelve different smishing URLs and observe 36 authorization attempts across 17 different online merchants. We analyze the ISO transaction messages to uncover scammers’ transaction patterns and their cash-out mechanisms. Our insights into scammer behavior could help stakeholders develop effective mitigations to tackle CNP fraud towards eliminating the profitability of smishing.
Sharad Agarwal, Marie Vasek
NSPW2
2025 SoK: A Privacy Framework for Security Research Using Social Media Data
abstract
The use of social media data in research is common, spanning fields from computer science to social science, from human-computer interaction to law and criminology. However, social media data often contains personal and sensitive information. While prior work discusses the ethics of research using social media data, focusing on ethics broadly can be insufficient to unravel granular privacy risks and possible mitigations. Focusing on research papers that use social media data to study security-related topics, we systematically analyze 601 papers across 16 years, covering a wide array of academic disciplines. Our findings highlight a lack of transparency in reporting - only 35% of papers mention any considerations of data anonymization, availability, and storage. Applying Solove's taxonomy to classify the identified privacy risks in the social media setting, we observe that Solove's taxonomy was prescient in capturing aggregation risk, but the volume, timeliness, and micro details of data, combined with modern data science, yield risks beyond what was considered 20 years ago. We present the implications of our findings for various stakeholders: researchers, ethics boards, and publishing venues. While there are already signs of improvement, we posit that some small behavioral changes from the academic community may make a big difference in user privacy.
Kyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran, Marilyne Ordekian, Enrico Mariconti, Yixin Zou, Marie Vasek
SP8
2025 'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom
Sharad Agarwal, Emma Harvey, Enrico Mariconti, Guillermo Suarez-Tangil, Marie Vasek
USENIX Security Symposium5
2025 "Edit: I'm sorry for being offensive, this is getting downvoted and I feel terrible": Implicit Social Norms as Governance in Identity-Based Communities
abstract
Community norms are important in regulating online identity-based communities as they help shape both online and offline discourse. Yet, not all expressions of identity are treated equally as acceptable forms of speech and expression of identity differ among communities. We used mixed-methods to understand how implicit norms within a set of non-binary communities are reinforced and shaped through influence within these communities. We analyzed approximately 2 million Reddit posts and comments to measure the effect of scores, replies, and self-disclosures, on user editing behaviors, which we use as means to observe norm regulation. We find self-disclosures and the number of replies a post receives is positively associated with editing behaviors, while the influence of scores on the likelihood of a message being edited is highly dependent on whether the message is a post or comment. Our qualitative analysis of posts, comments, and threads finds community norms are created, contested, and reinforced through the interactions between community and individual-level understanding of what it means to be non-binary. We propose a model for implicit norms as governance in identity-based communities, and discuss how platform designers can better use implicit norms to support governance in identity-based communities.
Kyle Beadle, Mark Warner, Marie Vasek
Proc. ACM Hum. Comput. Interact.3
2024 Investigating Wrench Attacks: Physical Attacks Targeting Cryptocurrency Users
Marilyne Ordekian, Gilberto Atondo Siu, Alice Hutchings, Marie Vasek
AFT4
2024 Poster: A Comprehensive Categorization of SMS Scams
abstract
SMS scams have surged over the recent years. However, little empirical research has been done to understand this rising threat due to the lack of an updated dataset. In the UK, mobile network operators run a firewall to block illicit messages. To this end, we collaborate with a major UK mobile network operator, which provides us with 3.58m SMS messages flagged by their firewall. These messages originated from over 42k unique sender IDs and were sent to 2.23m mobile numbers between December 2023 and February 2024. This is the first research to examine the current threats in the SMS ecosystem and categorize illicit SMS messages into eight sectors, including spam. We present the distribution of SMS messages successfully blocked by the mobile network operator's firewall and those that successfully evade detection.
Sharad Agarwal, Emma Harvey, Marie Vasek
IMC3
2023 Short Paper: DeFi Deception - Uncovering the Prevalence of Rugpulls in Cryptocurrency Projects
Sharad Agarwal, Gilberto Atondo Siu, Marilyne Ordekian, Alice Hutchings, Enrico Mariconti, Marie Vasek
FC (1)6
2021 An examination of the cryptocurrency pump-and-dump ecosystem
J. T. Hamrick, Farhang Rouhi, Arghya Mukherjee, Amir Feder, Neil Gandal, Tyler Moore 0001, Marie Vasek
Inf. Process. Manag.7
2016 Hacking Is Not Random: A Case-Control Study of Webserver-Compromise Risk
abstract
We describe a case-control study to identify risk factors that are associated with higher rates of webserver compromise. We inspect a random sample of around 200,000 webservers and automatically identify attributes hypothesized to affect the susceptibility to compromise, notably content management system (CMS) and webserver type. We then cross-list this information with data on webservers hacked to serve phishing pages or redirect to unlicensed online pharmacies. We find that webservers running WordPress and Joomla are more likely to be hacked than those not running any CMS, and that servers running Apache and Nginx are more likely to be hacked than those running Microsoft IIS. We also identify several WordPress plugins and Joomla extensions that associated with compromise. Furthermore, using a series of logistic regressions, we find that a CMS's market share is positively correlated with website compromise. Surprisingly, we find that webservers running outdated software are less likely to be compromised than those running up-to date software. We present evidence that this is true for core WordPress software (the most popular CMS platform) and many associated plugins. Finally, we examine what happens to webservers following compromise. We find that under 5 percent of hacked WordPress websites are subsequently updated, but those that do are recompromised about half as often as those that do not update.
Marie Vasek, John Wadleigh, Tyler Moore 0001
IEEE Trans. Dependable Secur. Comput.1