EDBT 2026 Demo / reviewers in the wild / expert
Iskander Sánchez-Rola
dblp:165/2039
· DBLP profile ↗
15ranked-venue papers
9as first author
8since 2021 · last 2025
0009-0005-2600-6528ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 first-author · 8 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Ctrl+Alt+Deceive: Quantifying User Exposure to Online Scams
Platon Kotzias, Michalis Pachilakis, Javier Aldana-Iuit, Juan Caballero, Iskander Sánchez-Rola, Leyla Bilge |
NDSS | 5 |
| 2025 | Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps
Johnny So, Iskander Sánchez-Rola, Nick Nikiforakis |
USENIX Security Symposium | 2 |
| 2023 | Scamdog Millionaire: Detecting E-commerce Scams in the WildabstractThe Better Business Bureau ranked online e-commerce scams as the top consumer threat for 2022. Our measurements of real consumer devices confirm that e-commerce scams receive large traffic volumes, a total of 6.3M visits during seven months. In this work, we study e-commerce scams in depth and design a detection classifier that combines novel features that target salient characteristics of e-commerce scam websites and features for detecting malicious and scam domains proposed by prior work. In addition, we specify a method for automatically creating reliable ground-truth sets that are an order of magnitude larger than that of prior work. We use this data set to evaluate the classifier and achieve a high 0.973 F1-score (Prec: 0.988, Rec: 0.959). In a best-effort comparison, we demonstrate that our classifier outperforms the F-1 score of the prior art by 11% and that our novel features offer an F1-score boost of 4.3% over the features used in the prior art. In addition, we deploy our classifier in a real-world setting, analyze over 760K e-shops visited by real users, and identify 10% of those as e-commerce scams. We demonstrate that the classifier has a low False Positive rate in real-world settings and can protect over 176K users in one week. Platon Kotzias, Kevin A. Roundy, Michalis Pachilakis, Iskander Sánchez-Rola, Leyla Bilge |
ACSAC | 4 |
| 2023 | Domain and Website Attribution beyond WHOISabstractCurrently, WHOIS is the main method for identifying which company or individual owns a domain or website. But, WHOIS usefulness is limited due to privacy protection services and data redaction. We present a novel automated approach for domain and website attribution. When WHOIS data does not reveal the owner, our approach leverages information from multiple other sources such as passive DNS, TLS certificates, and the analysis of website content. We propose a novel ranking technique to select the domain owner among multiple identified entities. Our approach identifies the domain owner with an F1 score of 0.94 compared to 0.54 for WHOIS. When applied on 3,001 tracker domains from the popular Disconnect list, it identifies needed updates to the list. It also attributes 84% of previously unattributed tracker domains. Silvia Sebastián, Raluca-Georgia Diugan, Juan Caballero, Iskander Sánchez-Rola, Leyla Bilge |
ACSAC | 4 |
| 2023 | Rods with Laser Beams: Understanding Browser Fingerprinting on Phishing Pages
Iskander Sánchez-Rola, Leyla Bilge, Davide Balzarotti, Armin Buescher, Petros Efstathopoulos |
USENIX Security Symposium | 1 |
| 2022 | SoK: Exploring Current and Future Research Directions on XS-Leaks through an Extended Formal ModelabstractA web visit typically consists of the browser rendering a dynamically generated response that is specifically tailored to the user. This generation of responses based on the currently authenticated user, whose authentication credentials are automatically included via cookies in all (including cross-site) requests, have led to a multitude of issues. Through cross-site leaks (XS-Leaks), an adversary can try to circumvent the same-origin policy and extract information about responses, which in turn can reveal potentially sensitive information about the user. As research on this class of vulnerabilities only recently gained traction, and the attacks affect many different components of the web platform, the intrinsic characteristics and underlying causes remain largely unexplored. Tom van Goethem, Gertjan Franken, Iskander Sánchez-Rola, David Dworken, Wouter Joosen |
AsiaCCS | 3 |
| 2022 | Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and RelationshipsabstractWeb pages have been steadily increasing in complexity over time, including code snippets from several distinct origins and organizations. While this may be a known phenomenon, its implications on the panorama of cookie tracking received little attention until now. Our study focuses on filling this gap, through the analysis of crawl results that are both large-scale and fine-grained, encompassing the whole set of events that lead to the creation and sharing of around 138 million cookies from crawling more than 6 million webpages. Our analysis lets us paint a highly detailed picture of the cookie ecosystem, discovering an intricate network of connections between players that reciprocally exchange information and include each other's content in web pages whose owners may not even be aware. We discover that, in most webpages, tracking cookies are set and shared by organizations at the end of complex chains that involve several middlemen. We also study the impact of cookie ghostwriting, i.e., a common practice where an entity creates cookies in the name of another party, or the webpage. We attribute and define a set of roles in the cookie ecosystem, related to cookie creation and sharing. We see that organizations can and do follow different patterns, including behaviors that previous studies could not uncover: for example, many cookie ghostwriters send cookies they create to themselves, which makes them able to perform cross-site tracking even for users that deleted third-party cookies in their browsers. While some organizations concentrate the flow of information on themselves, others behave as dispatchers, allowing other organizations to perform tracking on the pages that include their content. Iskander Sánchez-Rola, Matteo Dell'Amico, Davide Balzarotti, Pierre-Antoine Vervier, Leyla Bilge |
SP | 1 |
| 2022 | When Sally Met Trackers: Web Tracking From the Users' Perspective
Savino Dambra, Iskander Sánchez-Rola, Leyla Bilge, Davide Balzarotti |
USENIX Security Symposium | 2 |
| 2020 | Dirty Clicks: A Study of the Usability and Security Implications of Click-related Behaviors on the WebabstractWeb pages have evolved into very complex dynamic applications, which are often very opaque and difficult for non-experts to understand. At the same time, security researchers push for more transparent web applications, which can help users in taking important security-related decisions about which information to disclose, which link to visit, and which online service to trust. Iskander Sánchez-Rola, Davide Balzarotti, Christopher Krügel, Giovanni Vigna, Igor Santos |
WWW | 1 |
| 2019 | BakingTimer: privacy analysis of server-side request processing timeabstractCookies were originally introduced as a way to provide state awareness to websites, and are now one of the backbones of the current web. However, their use is not limited to store the login information or to save the current state of user browsing. In several cases, third-party cookies are deliberately used for web tracking, user analytics, and for online advertisement, with the subsequent privacy loss for the end users. Iskander Sánchez-Rola, Davide Balzarotti, Igor Santos |
ACSAC | 1 |
| 2019 | Can I Opt Out Yet?: GDPR and the Global Illusion of Cookie ControlabstractThe European Union's (EU) General Data Protection Regulation (GDPR), in effect since May 2018, enforces strict limitations on handling users' personal data, hence impacting their activity tracking on the Web. In this study, we perform an evaluation of the tracking performed in 2,000 high-traffic websites, hosted both inside and outside of the EU. We evaluate both the information presented to users and the actual tracking implemented through cookies; we find that the GDPR has impacted website behavior in a truly global way, both directly and indirectly: USA-based websites behave similarly to EU-based ones, while third-party opt-out services reduce the amount of tracking even for websites which do not put any effort in respecting the new law. On the other hand, we find that tracking remains ubiquitous. In particular, we found cookies that can identify users when visiting more than 90% of the websites in our dataset - and we also encountered a large number of websites that present deceiving information, making it it very difficult, if at all possible, for users to avoid being tracked. Iskander Sánchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, Igor Santos |
AsiaCCS | 1 |
| 2018 | Clock Around the Clock: Time-Based Device FingerprintingabstractPhysical device fingerprinting exploits hardware features to uniquely identify a machine. This technique has been used for authentication, license binding, or attackers identification, among other tasks. More recently, hardware features have also been introduced to identify web users and perform web tracking. A particular type of hardware fingerprint exploits differences in the computer internal clock signals. However, previous methods to test for these differences relied on complex experiments performed by running native code in the target machine. In this paper, we show a new way to compute a hardware finger- printing, based on timing the execution of sequences of instructions readily available in API functions. Due to its simplicity, this method can also be performed remotely by simply timing few seemingly innocuous lines of JavaScript code. We tested our approach with different functions, such as common string manipulation or widespread cryptographic routines, and found that several of them can be used as basic blocks for fingerprinting. Using this technique, we implemented a tool called CryptoFP. We tested its native implementation in a homogeneous scenario, to distinguish among a perfectly identical (both in software and hardware) set of computers. CryptoFP was able to correctly discriminate all the identical computers in this scenario and recognize the same computer also under different CPU load configurations, outperforming every other hardware fingerprinting method. We then show how CryptoFP can be implemented using a combination of the HTML5 Cryptography API and standard timing API for web device fingerprinting. In this case, we compared our method, both in the same homogeneous scenario and by performing an experiment with real-world users running heterogeneous devices, against other state-of-the-art web device fingerprinting solutions. In both cases, our approach clearly outperforms all existing methods. Iskander Sánchez-Rola, Igor Santos, Davide Balzarotti |
CCS | 1 |
| 2018 | Knockin' on Trackers' Door: Large-Scale Automatic Analysis of Web Tracking
Iskander Sánchez-Rola, Igor Santos |
DIMVA | 1 |
| 2017 | Extension Breakdown: Security Analysis of Browsers Extension Resources Control Policies
Iskander Sánchez-Rola, Igor Santos, Davide Balzarotti |
USENIX Security Symposium | 1 |
| 2017 | The Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden ServicesabstractTor is a well known and widely used darknet, known for its anonymity. However, while its protocol and relay security have already been extensively studied, to date there is no comprehensive analysis of the structure and privacy of its Web Hidden Service. Iskander Sánchez-Rola, Davide Balzarotti, Igor Santos |
WWW | 1 |