EDBT 2026 Demo / reviewers in the wild / expert
Inian Parameshwaran
dblp:160/3897
· DBLP profile ↗
3ranked-venue papers
2as first author
0since 2021 · last 2015
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 first-authorSecurity and privacy · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Web and mobile security · 64% Systems and software security · 21% Blockchain and cryptocurrency security · 16% | |
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% |
Topics — the 6 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security › web security
cross-site scripting |
0.4 | 2 | 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilities · ESEC/SIGSOFT FSE 2015 Auto-patching DOM-based XSS at scale · ESEC/SIGSOFT FSE 2015 |
Web and mobile security › javascript security
DOM-based XSS |
0.4 | 2 | 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilities · ESEC/SIGSOFT FSE 2015 Auto-patching DOM-based XSS at scale · ESEC/SIGSOFT FSE 2015 |
Systems and software security › vulnerability patching
automated patching |
0.2 | 1 | 2015 | Auto-patching DOM-based XSS at scale · ESEC/SIGSOFT FSE 2015 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
0.2 | 1 | 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilities · ESEC/SIGSOFT FSE 2015 |
Systems and software security
vulnerability discovery |
0.1 | 1 | 2015 | Auto-patching DOM-based XSS at scale · ESEC/SIGSOFT FSE 2015 |
Software testing › non-functional testing
security testing |
0.1 | 1 | 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilities · ESEC/SIGSOFT FSE 2015 |
Methods — techniques the papers use, named apart from their topics
taint analysis · 0.4source-to-source rewriting · 0.4program transformation · 0.2dynamic analysis · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2015 | On Power Splitting Games in Distributed Computation: The Case of Bitcoin Pooled MiningabstractSeveral new services incentivize clients to compete in solving large computation tasks in exchange for financial rewards. This model of competitive distributed computation enables every user connected to the Internet to participate in a game in which he splits his computational power among a set of competing pools -- the game is called a computational power splitting game. We formally model this game and show its utility in analyzing the security of pool protocols that dictate how financial rewards are shared among the members of a pool. As a case study, we analyze the Bitcoin crypto currency which attracts computing power roughly equivalent to billions of desktop machines, over 70% of which is organized into public pools. We show that existing pool reward sharing protocols are insecure in our game-theoretic analysis under an attack strategy called the "block withholding attack". This attack is a topic of debate, initially thought to be ill-incentivized in today's pool protocols: i.e., causing a net loss to the attacker, and later argued to be always profitable. Our analysis shows that the attack is always well-incentivized in the long-run, but may not be so for a short duration. This implies that existing pool protocols are insecure, and if the attack is conducted systematically, Bitcoin pools could lose millions of dollars worth in months. The equilibrium state is a mixed strategy -- that is -- in equilibrium all clients are incentivized to probabilistically attack to maximize their payoffs rather than participate honestly. As a result, the Bitcoin network is incentivized to waste a part of its resources simply to compete. Loi Luu, Ratul Saha, Inian Parameshwaran, Prateek Saxena, Aquinas Hobor |
CSF | 3 |
| 2015 | Auto-patching DOM-based XSS at scaleabstractDOM-based cross-site scripting (XSS) is a client-side code injection vulnerability that results from unsafe dynamic code generation in JavaScript applications, and has few known practical defenses. We study dynamic code evaluation practices on nearly a quarter million URLs crawled starting from the the Alexa Top 1000 websites. Of 777,082 cases of dynamic HTML/JS code generation we observe, 13.3% use unsafe string interpolation for dynamic code generation — a well-known dangerous coding practice. To remedy this, we propose a technique to generate secure patches that replace unsafe string interpolation with safer code that utilizes programmatic DOM construction techniques. Our system transparently auto-patches the vulnerable site while incurring only 5.2 − 8.07% overhead. The patching mechanism requires no access to server-side code or modification to browsers, and thus is practical as a turnkey defense. Inian Parameshwaran, Enrico Budianto, Shweta Shinde, Hung Dang, Atul Sadhu, Prateek Saxena |
ESEC/SIGSOFT FSE | 1 |
| 2015 | DexterJS: robust testing platform for DOM-based XSS vulnerabilitiesabstractDOM-based cross-site scripting (XSS) is a client-side vulnerability that pervades JavaScript applications on the web, and has few known practical defenses. In this paper, we introduce DEXTERJS, a testing platform for detecting and validating DOM-based XSS vulnerabilities on web applications. DEXTERJS leverages source-to source rewriting to carry out character-precise taint tracking when executing in the browser context—thus being able to identify vulnerable information flows in a web page. By scanning a web page, DEXTERJS produces working exploits that validate DOM-based XSS vulnerability on the page. DEXTERJS is robust, has been tested on Alexa’s top 1000 sites, and has found a total of 820 distinct zero-day DOM-XSS confirmed exploits automatically. Inian Parameshwaran, Enrico Budianto, Shweta Shinde, Hung Dang, Atul Sadhu, Prateek Saxena |
ESEC/SIGSOFT FSE | 1 |