Phakpoom Chinprutthiwong

dblp:183/4920 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0002-0177-5524ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2023 #DM-Me: Susceptibility to Direct Messaging-Based Scams
abstract
In an emerging scam on social media platforms, cyber-miscreants are luring users into sending them a direct-message (DM) and are subsequently exploiting the messaging channel. We term this attack approach as the DM-Me scam. We report on a survey of 214 MTurk participants, in which we make the first effort to systematically study the susceptibility of users in falling victim to DM-Me scams. We find that most participants chose to send a direct message to at least one scammer, and made such choices more than half the time. This susceptibility can be attributed to the misplaced trust in scammers and the lack of negative consequences foreseen by participants in messaging accounts that they do not fully trust. Interestingly, our results also suggest that women mostly from the 31-40 age-group and who predominantly use Instagram a few times a week are less susceptible than men to financial DM-Me scams as they appear to face more discomfort in initiating a conversation with unfamiliar accounts for such services. We conclude with future research directions in mitigating the risks posed by DM-Me scammers, specifically by developing reliable indicators to aid users in assessing the trustworthiness of an account.
Raj Vardhan, Alok Chandrawal, Phakpoom Chinprutthiwong, Yangyong Zhang, Guofei Gu
AsiaCCS3
2023 Do Users Really Know Alexa? Understanding Alexa Skill Security Indicators
abstract
Amazon Alexa’s booming third-party skill market has grown from 160 to 100,000 skills within three years. In this work, we make the first effort in demystifying the Alexa skill permission system by studying its security indicators. Our user study results show that most of the surveyed Alexa users did not understand the security implications of interacting with third parties via Alexa’s voice user interface (VUI). Despite the potential risks of undesired resource sharing, more than two-thirds of the surveyed Alexa users considered third-party skills safe because they think these skills are Alexa- or Amazon-owned applications. Together with other uncovered deficiencies of skill security indicator designs, our study indicates a pressing need for a paradigm shift in designing security indicators for VUI systems.
Yangyong Zhang, Raj Vardhan, Phakpoom Chinprutthiwong, Guofei Gu
AsiaCCS3
2023 Automatic Synthesis of Network Security Services: A First Step
abstract
In the network security life cycle, security needs are initialized by network operators and typically documented in natural languages, and later implemented and deployed in developed/acquired security appliances, typically written in a programming language by third-party developers. However, oftentimes, those security appliances/programs may not quite match the urgent and fast-evolving security needs since the whole developing/deployment procedure is very time-consuming. In this paper, we propose a novel framework, AUTOSEC, to aid network operators in building up or rapid prototyping operational network security services directly from high-level service needs as automatically as possible. AUTOSEC helps bridge the huge gap from human intents in natural language descriptions to the deliverable network security services. More specifically, AUTOSEC utilizes Natural Language Processing (NLP) techniques to infer security intents from natural language descriptions, and then performs Interactive Synthesis to assist users to validate and refine parsed intents if necessary. AUTOSEC further lever-ages Software-Defined Networking (SDN) and Network Function Virtualization (NFV) techniques to automatically compose and instantiate security services in terms of refined security intents. In the evaluation, we demonstrate the early success of AUTOSEC with security policy descriptions collected from various data sources including research papers, appliance descriptions, real-world security standards, and human-written policies.
Lei Xu 0024, Yangyong Zhang, Phakpoom Chinprutthiwong, Guofei Gu
ICCCN3
2022 SWAPP: A New Programmable Playground for Web Application Security
Phakpoom Chinprutthiwong, Guofei Gu
USENIX Security Symposium1
2021 The Service Worker Hiding in Your Browser: The Next Web Attack Target?
abstract
In recent years, service workers are gaining attention from both web developers and attackers due to the unique features they provide. Recent findings have shown that an attacker can register a malicious service worker to take advantage of the victim such as by turning the victim’s device into a crypto-currency miner. However, the possibility of benign service workers being leveraged is not well studied.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Yangyong Zhang, Guofei Gu
RAID1
2020 Security Study of Service Worker Cross-Site Scripting
abstract
Nowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Guofei Gu
ACSAC1
2019 Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant Applications
Yangyong Zhang, Lei Xu 0024, Abner Mendoza, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Guofei Gu
NDSS5
2018 Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era
abstract
Diagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, ForenGuard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads.
Haopei Wang, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Lei Xu 0024, Yangyong Zhang, Guofei Gu
CCS3
2018 Uncovering HTTP Header Inconsistencies and the Impact on Desktop/Mobile Websites
abstract
The paradigm shift to a mobile-first economy has seen a drastic increase in mobile-optimized websites that in many cases are derived from their desktop counterparts. Mobile website design is often focused on performance optimization rather than security, and possibly developed by different teams of developers. This has resulted in a number of subtle but critical inconsistencies in terms of security guarantees provided on the web platform, such as protection mechanisms against common web attacks. In this work, we have conducted the first systematic measurement study of inconsistencies between mobile and desktop HTTP security response configuration in the top 70,000 websites. We show that HTTP security configuration inconsistencies between mobile and desktop versions of the same website can lead to vulnerabilities. Our study compares data snapshots collected one year apart to garner insights into the longitudinal trends of mobile versus desktop inconsistencies in websites. To complement our measurement study, we present a threat analysis that explores some possible attack scenarios that can leverage the inconsistencies found on real websites. We systematically analyze the security impact of the inconsistent implementations between the mobile and desktop versions of a website and show how it can lead to real-world exploits. We present several case studies of popular websites to show real-world impact of how these inconsistencies are leveraged to compromise security and privacy of web users. Our results show little to no improvements across our datasets, which highlight the continued pervasiveness of subtle inconsistencies affecting even some high profile websites.
Abner Mendoza, Phakpoom Chinprutthiwong, Guofei Gu
WWW2
2015 Seeing the Instructor in Two Video Styles: Preferences and Patterns
Suma Bhat, Phakpoom Chinprutthiwong, Michelle Perry
EDM2