Merve Sahin

dblp:168/5167 · DBLP profile ↗
← Back
6ranked-venue papers
6as first author
3since 2021 · last 2024
0009-0009-4798-0601ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 6 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2024 Towards Understanding and Improving Security-Relevant Web Application Logging
abstract
Logging of security-relevant events is crucial in software development to gain visibility into the application's runtime, and to detect suspicious and malicious behavior. Various security guidelines (such as ISO 27002, CCM) mandate the software products to log certain security-relevant events for forensics purposes. In addition, security community (such as the OWASP Foundation) has come up with similar logging recommendations. On the other hand, the lack of sufficient and proper logging practices has been common in the software industry: In fact, "insufficient logging and monitoring" has been part of the OWASP Top 10 web application security risks for many years.
Merve Sahin, Noemi Daniele
AsiaCCS1
2022 An Approach to Generate Realistic HTTP Parameters for Application Layer Deception
Merve Sahin, Cédric Hébert, Rocío Cabrera Lozoya
ACNS1
2021 Understanding and Detecting International Revenue Share Fraud
Merve Sahin, Aurélien Francillon
NDSS1
2017 SoK: Fraud in Telephony Networks
abstract
Telephone networks first appeared more than a hundred years ago, long before transistors were invented. They, therefore, form the oldest large scale network that has grown to touch over 7 billion people. Telephony is now merging many complex technologies and because numerous services enabled by these technologies can be monetized, telephony attracts a lot of fraud. In 2015, a telecom fraud association study estimated that the loss of revenue due to global telecom fraud was worth 38 billion US dollars per year. Because of the convergence of telephony with the Internet, fraud in telephony networks can also have a negative impact on security of online services. However, there is little academic work on this topic, in part because of the complexity of such networks and their closed nature. This paper aims to systematically explore fraud in telephony networks. Our taxonomy differentiates the root causes, the vulnerabilities, the exploitation techniques, the fraud types and finally the way fraud benefits fraudsters. We present an overview of each of these and use CAller NAMe (CNAM) revenue share fraud as a concrete example to illustrate how our taxonomy helps in better understanding this fraud and to mitigate it.
Merve Sahin, Aurélien Francillon, Payas Gupta, Mustaque Ahamad
EuroS&P1
2017 Using chatbots against voice spam: Analyzing Lenny's effectiveness
Merve Sahin, Marc Relieu, Aurélien Francillon
SOUPS1
2016 Over-The-Top Bypass: Study of a Recent Telephony Fraud
abstract
In this paper, we study the Over-The-Top (OTT) bypass fraud, a recent form of interconnect telecom fraud. In OTT bypass, a normal phone call is diverted over IP to a voice chat application on a smartphone, instead of being terminated over the normal telecom infrastructure. This rerouting (or hijack) is performed by an international transit operator in coordination with the OTT service provider, but without explicit authorization from the caller, callee and their operators. By doing so, they collect a large share of the call charge and induce a significant loss of revenue to the bypassed operators. Moreover, this practice degrades the quality of service without providing any benefits for the users.
Merve Sahin, Aurélien Francillon
CCS1