EDBT 2026 Demo / reviewers in the wild / expert
Siddharth Prakash Rao
dblp:155/9775
· DBLP profile ↗
6ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-8656-1877ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From See to Shield: ML-Assisted Fine-Grained Access Control for Visual Data: Data/Toolset Paper
Mete Harun Akcay, Buse G. A. Tekgul, Siddharth Prakash Rao, Alexandros Bakas |
CODASPY | 3 |
| 2023 | Authenticating Mobile Users to Public Internet Commodity Services Using SIM TechnologyabstractThe traditional use of the Subscriber Identity Module (SIM), which resides in a mobile device, is to authenticate a user to cellular mobile networks. However, we believe that the cryptographic capabilities of SIM are not fully utilized for authenticating a user to other types of services. To address this concern, we introduce a novel SIM-based solution to authenticate users to Commodity Services (CS) on the public Internet. We present SIM-Based Authentication (SIMBA), a protocol that comprises registration, key establishment, authentication, and revocation. Our solution consists of a variant of the Remote SIM Provisioning (RSP) protocol that can be run between a commodity service, users, and a Mobile Network Operator (MNO). Furthermore, we introduce the concept of asub-profile for CS that can reside inside an operating SIM profile of an MNO. Unlike the SIM profiles defined in the RSP, our solution can have multiple active sub-profiles that allow users to simultaneously log in to different commodity services without swapping between profiles. We formally define a threat model and present an analysis to prove the protocol's security guarantees. SIMBA offers several benefits to mobile end-users, CS providers, and MNOs. In this realm, we believe that our work contributes to the ongoing research on novel authentication methods. Siddharth Prakash Rao, Alexandros Bakas |
WISEC | 1 |
| 2023 | Threat modeling framework for mobile communication systemsabstractThis paper presents a domain-specific threat-modeling framework for the cellular mobile networks. We survey known attacks against mobile communication and organize them into attack phases, tactical objectives, and techniques. The Bhadra framework aims to provide a structured way to analyze and communicate threats on a level that abstracts away the technical details but still provides meaningful insights into the adversarial behavior. Our goals are similar to existing threat modeling frameworks for enterprise information systems, but with a focus on mobile operator networks. The framework fills a gap that has existed in tools and methodology for sharing of threat intelligence within and between organizations in the telecommunications industry. The paper includes concrete case studies of applying the framework. It can also be read as a survey of attacks against mobile networks. CCS CONCEPTS Security and privacy → Security requirements; Mobile and wireless security; Networks→ Networks Mobile networks Siddharth Prakash Rao, Hsin Yi Chen, Tuomas Aura |
Comput. Secur. | 1 |
| 2021 | On Adoptability and Use Case Exploration of Threat Modeling for Mobile Communication SystemsabstractAs the attack surface and the number of security incidents in mobile communication networks increase, a common language for threat intelligence gathering and sharing among different parties becomes essential. We addressed this by developing the Bhadra framework [4], a domain-specific conceptual framework that captures adversarial behaviors in end-to-end communication over the mobile networks in our previous work. Nevertheless, the acceptance or adoptability of the framework by the mobile communications industry is still unclear. In this work, we built a threat modeling tool as a companion for Bhadra and conduct a user study with industry experts to evaluate the framework's usefulness and explore its potential use cases besides threat modeling and sharing. Our preliminary results indicate that the mobile communication industry would benefit from a threat modeling framework with a companion tool and its use cases, making it a potential candidate to integrate within work processes. Hsin Yi Chen, Siddharth Prakash Rao |
CCS | 2 |
| 2020 | XSS Vulnerabilities in Cloud-Application Add-OnsabstractMany cloud-application vendors open their APIs for third-party developers to easily extend the functionality of their applications. The features implemented with these APIs are called add-ons (also called add-ins or apps). This is a relatively new phenomenon, and its effects on the application security have not been widely studied. It seems likely that some of the add-ons have lower code quality than the core applications themselves and, thus, may bring in security vulnerabilities. In this work, we found that many of such add-ons are vulnerable to cross-site scripting (XSS). The attacker can take advantage of the document-sharing and messaging features of the cloud applications to send malicious input to them. The vulnerable add-ons then execute client-side JavaScript from the carefully crafted malicious input. In a major analysis effort, we systematically studied 300 add-ons for three popular application suites, namely Microsoft Office Online, G Suite and Shopify, and discovered a significant percentage of vulnerable add-ons among them. We present the results of this study, as well as analyze the add-on architectures to understand how the XSS vulnerabilities can be exploited and how the threat can be mitigated. Thanh Bui, Siddharth Prakash Rao, Markku Antikainen, Tuomas Aura |
AsiaCCS | 2 |
| 2018 | Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the Computer
Thanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan, Tuomas Aura |
USENIX Security Symposium | 2 |