EDBT 2026 Demo / reviewers in the wild / expert
Amin Kharraz
dblp:151/4105 · also Mohammad-Amin Kharraz
· DBLP profile ↗
16ranked-venue papers
8as first author
7since 2021 · last 2024
0000-0002-7841-3409ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 6 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Constructs of Deceit: Exploring Nuances in Modern Social Engineering Attacks
Mohammad Ali Tofighi, Behzad Ousat, Javad Zandi, Esteban Schafir, Amin Kharraz |
DIMVA | 5 |
| 2024 | The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern WebabstractThe web ecosystem is a fast-paced environment. In this dynamic landscape, new security features are offered one after another to enhance the security and robustness of web applications and the operations they handle. This paper focuses on a fragile but still in-use security feature, text-based CAPTCHAs, that had been wildly used by web applications in the past to protect against automated attacks such as credential stuffing and account hijacking. The paper first investigates what it takes to develop automated scanners that can solve previously unseen text-based CAPTCHAs. We evaluated the possibility of developing and integrating a pre-trained CAPTCHA solver in the automated web scanning process without using a significantly large training dataset. We also perform an analysis of the impact of such autonomous scanners on CAPTCHA-enabled websites. Our analysis shows that solvable text-based CAPTCHAs on login, contact, and comment pages of websites are not uncommon. In particular, we identified over 3,100 text-based CAPTCHA websites in critical sectors such as finance, government, and health with hundreds of thousands of users. We showed that a web scanner with a pre-trained solver could solve more than 20% of previously unseen CAPTCHAs in just one single attempt. This result is worrisome considering the substantial potential to autonomously run the operation across thousands of websites on a daily basis with minimal training. The findings suggest that the integration of autonomous scanning with pre-training and local optimization of models can significantly increase adversaries' asymmetric power to launch their attacks cheaper and faster. Behzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi, Viet Cuong Nguyen, Sajjad Arshad, A. Selcuk Uluagac, Amin Kharraz |
WWW | 8 |
| 2024 | (In)Security of File Uploads in Node.jsabstractFile upload is a critical feature incorporated by a myriad of web applications in an effort to enable users to share and manage their files conveniently. It has been used in many useful services such as file-sharing and social media. While file upload is an essential component of web applications, the lack of rigorous checks on the file name, type, and content of the uploaded files can result in security issues, often referred to as Unrestricted File Upload (UFU). In this study, we analyze the (in)security of popular file upload libraries and real-world applications in the Node.js ecosystem. To automate our analysis, we propose and implement NodeSEC- a tool designed to analyze file upload insecurities in Node.js applications and libraries. NodeSEC generates unique payloads and thoroughly evaluates the application's file upload security against 13 distinct UFU-type attacks. Utilizing NodeSEC, we analyze the most popular file upload libraries and real-world applications in the Node.js ecosystem. Our analysis results reveal that some real-world web applications are vulnerable to UFU attacks and disclose serious security bugs in file upload libraries. As of this writing, we received 19 CVEs and two US-CERT cases for the security issues that we reported. Our findings provide strong evidence that dynamic features of Node.js applications introduce security shortcomings and that web developers should be cautious when implementing file upload features in their applications. Finally, combining our responsible disclosure experience and root cause analysis, we identified the main causes of significant security weaknesses in file uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, A. Selcuk Uluagac |
WWW | 5 |
| 2023 | An End-to-End Analysis of Covid-Themed Scams in the WildabstractCovid19-themed attacks took the Internet by surprise in March 2020. Adversaries updated their attack strategies rapidly and started to exploit users’ attention to this unprecedented event and distribute their malicious payloads. In this work, we perform a retrospective analysis of adversarial operations over the first four months from February 15th, 2020 to June 16th, 2020. By combining a variety of measurement perspectives, we perform a three-step analysis, by (1) analyzing the composition, growth, and reachability of Covid19-themed attack pages, (2) identifying the modus operandi of attackers, and (3) assessing the actual impact on end-users. Our measurements serve as a lens into the fragile parts of the Web ecosystem during a previously unseen attack. We argue that precipitous growth of Covid19-themed attacks in just a few weeks represents adversaries’ technical and operational agility in adapting their attack strategies and also demonstrates how novice attack techniques can bypass common defense mechanisms and expose unsuspecting users to different forms of attacks. Drawing upon these analyses, we discuss what went poorly, in an effort to understand how the technical community can respond more effectively to such events in the future. Behzad Ousat, Mohammad Ali Tofighi, Amin Kharraz |
AsiaCCS | 3 |
| 2021 | You've Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures
Tommaso Innocenti, Seyed Ali Mirheidari, Amin Kharraz, Bruno Crispo, Engin Kirda |
DIMVA | 3 |
| 2021 | SCRUTINIZER: Detecting Code Reuse in Malware via Decompilation and Machine Learning
Omid Mirzaei, Roman Vasilenko, Engin Kirda, Long Lu, Amin Kharraz |
DIMVA | 5 |
| 2021 | WebSocket Adoption and the Landscape of the Real-Time WebabstractDevelopers are increasingly deploying web applications which require real-time bidirectional updates, a use case which does not naturally align with the traditional client-server architecture of the web. Many solutions have arisen to address this need over the preceding decades, including HTTP polling, Server-Sent Events, and WebSockets. This paper investigates this ecosystem and reports on the prevalence, benefits, and drawbacks of these technologies, with a particular focus on the adoption of WebSockets. We crawl the Tranco Top 1 Million websites to build a dataset for studying real-time updates in the wild. We find that HTTP Polling remains significantly more common than WebSockets, and WebSocket adoption appears to have stagnated in the past two to three years. We investigate some of the possible reasons for this decrease in the rate of adoption, and we contrast the adoption process to that of other web technologies. Our findings further suggest that even when WebSockets are employed, the prescribed best practices for securing them are often disregarded. The dataset is made available in the hopes that it may help inform the development of future real-time solutions for the web. Paul Murley, Zane Ma, Joshua Mason, Michael D. Bailey, Amin Kharraz |
WWW | 5 |
| 2019 | USBESAFE: An End-Point Solution to Protect Against USB-Based Attacks
Amin Kharraz, Brandon L. Daley, Graham Z. Baker, William K. Robertson, Engin Kirda |
RAID | 1 |
| 2019 | Outguard: Detecting In-Browser Covert Cryptocurrency Mining in the WildabstractIn-browser cryptojacking is a form of resource abuse that leverages end-users' machines to mine cryptocurrency without obtaining the users' consent. In this paper, we design, implement, and evaluate Outguard, an automated cryptojacking detection system. We construct a large ground-truth dataset, extract several features using an instrumented web browser, and ultimately select seven distinctive features that are used to build an SVM classification model. Outguardachieves a 97.9% TPR and 1.1% FPR and is reasonably tolerant to adversarial evasions. We utilized Outguardin the wild by deploying it across the Alexa Top 1M websites and found 6,302 cryptojacking sites, of which 3,600 are new detections that were absent from the training data. These cryptojacking sites paint a broad picture of the cryptojacking ecosystem, with particular emphasis on the prevalence of cryptojacking websites and the shared infrastructure that provides clues to the operators behind the cryptojacking phenomenon. Amin Kharraz, Zane Ma, Paul Murley, Charles Lever, Joshua Mason, Andrew Miller 0001, Nikita Borisov, Manos Antonakakis, Michael D. Bailey |
WWW | 1 |
| 2018 | Surveylance: Automatically Detecting Online Survey ScamsabstractOnline surveys are a popular mechanism for performing market research in exchange for monetary compensation. Unfortunately, fraudulent survey websites are similarly rising in popularity among cyber-criminals as a means for executing social engineering attacks. In addition to the sizable population of users that participate in online surveys as a secondary revenue stream, unsuspecting users who search the web for free content or access codes to commercial software can also be exposed to survey scams. This occurs through redirection to websites that ask the user to complete a survey in order to receive the promised content or a reward. In this paper, we present SURVEYLANCE, the first system that automatically identifies survey scams using machine learning techniques. Our evaluation demonstrates that SURVEYLANCE works well in practice by identifying 8,623 unique websites involved in online survey attacks. We show that SURVEYLANCE is suitable for assisting human analysts in survey scam detection at scale. Our work also provides the first systematic analysis of the survey scam ecosystem by investigating the capabilities of these services, mapping all the parties involved in the ecosystem, and quantifying the consequences to users that are exposed to these services. Our analysis reveals that a large number of survey scams are easily reachable through the Alexa top 30K websites, and expose users to a wide range of security issues including identity fraud, deceptive advertisements, potentially unwanted programs (PUPs), malicious extensions, and malware. Amin Kharraz, William K. Robertson, Engin Kirda |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | Redemption: Real-Time Protection Against Ransomware at End-Hosts
Amin Kharraz, Engin Kirda |
RAID | 1 |
| 2016 | Identifying Extension-Based Ad Injection via Fine-Grained Web Content Provenance
Sajjad Arshad, Amin Kharraz, William K. Robertson |
RAID | 2 |
| 2016 | UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware
Amin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson, Engin Kirda |
USENIX Security Symposium | 1 |
| 2015 | Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks
Amin Kharraz, William K. Robertson, Davide Balzarotti, Leyla Bilge, Engin Kirda |
DIMVA | 1 |
| 2014 | Optical Delusions: A Study of Malicious QR Codes in the WildabstractQR codes, a form of 2D barcode, allow easy interaction between mobile devices and websites or printed material by removing the burden of manually typing a URL or contact information. QR codes are increasingly popular and are likely to be adopted by malware authors and cyber-criminals as well. In fact, while a link can "look" suspicious, malicious and benign QR codes cannot be distinguished by simply looking at them. However, despite public discussions about increasing use of QR codes for malicious purposes, the prevalence of malicious QR codes and the kinds of threats they pose are still unclear. In this paper, we examine attacks on the Internet that rely on QR codes. Using a crawler, we performed a large-scale experiment by analyzing QR codes across 14 million unique web pages over a ten-month period. Our results show that QR code technology is already used by attackers, for example to distribute malware or to lead users to phishing sites. However, the relatively few malicious QR codes we found in our experiments suggest that, on a global scale, the frequency of these attacks is not alarmingly high and users are rarely exposed to the threats distributed via QR codes while surfing the web. Amin Kharraz, Engin Kirda, William K. Robertson, Davide Balzarotti, Aurélien Francillon |
DSN | 1 |
| 2012 | On-demand multicast routing protocol with efficient route discovery
Amin Kharraz, Hamid Sarbazi-Azad, Albert Y. Zomaya |
J. Netw. Comput. Appl. | 1 |