EDBT 2026 Demo / reviewers in the wild / expert
Phakpoom Chinprutthiwong
dblp:183/4920
· DBLP profile ↗
10ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0002-0177-5524ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | #DM-Me: Susceptibility to Direct Messaging-Based ScamsabstractIn an emerging scam on social media platforms, cyber-miscreants are luring users into sending them a direct-message (DM) and are subsequently exploiting the messaging channel. We term this attack approach as the DM-Me scam. We report on a survey of 214 MTurk participants, in which we make the first effort to systematically study the susceptibility of users in falling victim to DM-Me scams. We find that most participants chose to send a direct message to at least one scammer, and made such choices more than half the time. This susceptibility can be attributed to the misplaced trust in scammers and the lack of negative consequences foreseen by participants in messaging accounts that they do not fully trust. Interestingly, our results also suggest that women mostly from the 31-40 age-group and who predominantly use Instagram a few times a week are less susceptible than men to financial DM-Me scams as they appear to face more discomfort in initiating a conversation with unfamiliar accounts for such services. We conclude with future research directions in mitigating the risks posed by DM-Me scammers, specifically by developing reliable indicators to aid users in assessing the trustworthiness of an account. Raj Vardhan, Alok Chandrawal, Phakpoom Chinprutthiwong, Yangyong Zhang, Guofei Gu |
AsiaCCS | 3 |
| 2023 | Do Users Really Know Alexa? Understanding Alexa Skill Security IndicatorsabstractAmazon Alexa’s booming third-party skill market has grown from 160 to 100,000 skills within three years. In this work, we make the first effort in demystifying the Alexa skill permission system by studying its security indicators. Our user study results show that most of the surveyed Alexa users did not understand the security implications of interacting with third parties via Alexa’s voice user interface (VUI). Despite the potential risks of undesired resource sharing, more than two-thirds of the surveyed Alexa users considered third-party skills safe because they think these skills are Alexa- or Amazon-owned applications. Together with other uncovered deficiencies of skill security indicator designs, our study indicates a pressing need for a paradigm shift in designing security indicators for VUI systems. Yangyong Zhang, Raj Vardhan, Phakpoom Chinprutthiwong, Guofei Gu |
AsiaCCS | 3 |
| 2023 | Automatic Synthesis of Network Security Services: A First StepabstractIn the network security life cycle, security needs are initialized by network operators and typically documented in natural languages, and later implemented and deployed in developed/acquired security appliances, typically written in a programming language by third-party developers. However, oftentimes, those security appliances/programs may not quite match the urgent and fast-evolving security needs since the whole developing/deployment procedure is very time-consuming. In this paper, we propose a novel framework, AUTOSEC, to aid network operators in building up or rapid prototyping operational network security services directly from high-level service needs as automatically as possible. AUTOSEC helps bridge the huge gap from human intents in natural language descriptions to the deliverable network security services. More specifically, AUTOSEC utilizes Natural Language Processing (NLP) techniques to infer security intents from natural language descriptions, and then performs Interactive Synthesis to assist users to validate and refine parsed intents if necessary. AUTOSEC further lever-ages Software-Defined Networking (SDN) and Network Function Virtualization (NFV) techniques to automatically compose and instantiate security services in terms of refined security intents. In the evaluation, we demonstrate the early success of AUTOSEC with security policy descriptions collected from various data sources including research papers, appliance descriptions, real-world security standards, and human-written policies. Lei Xu 0024, Yangyong Zhang, Phakpoom Chinprutthiwong, Guofei Gu |
ICCCN | 3 |
| 2022 | SWAPP: A New Programmable Playground for Web Application Security
Phakpoom Chinprutthiwong, Guofei Gu |
USENIX Security Symposium | 1 |
| 2021 | The Service Worker Hiding in Your Browser: The Next Web Attack Target?abstractIn recent years, service workers are gaining attention from both web developers and attackers due to the unique features they provide. Recent findings have shown that an attacker can register a malicious service worker to take advantage of the victim such as by turning the victim’s device into a crypto-currency miner. However, the possibility of benign service workers being leveraged is not well studied. Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Yangyong Zhang, Guofei Gu |
RAID | 1 |
| 2020 | Security Study of Service Worker Cross-Site ScriptingabstractNowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker. Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Guofei Gu |
ACSAC | 1 |
| 2019 | Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant Applications
Yangyong Zhang, Lei Xu 0024, Abner Mendoza, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Guofei Gu |
NDSS | 5 |
| 2018 | Towards Fine-grained Network Security Forensics and Diagnosis in the SDN EraabstractDiagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, ForenGuard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads. Haopei Wang, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Lei Xu 0024, Yangyong Zhang, Guofei Gu |
CCS | 3 |
| 2018 | Uncovering HTTP Header Inconsistencies and the Impact on Desktop/Mobile WebsitesabstractThe paradigm shift to a mobile-first economy has seen a drastic increase in mobile-optimized websites that in many cases are derived from their desktop counterparts. Mobile website design is often focused on performance optimization rather than security, and possibly developed by different teams of developers. This has resulted in a number of subtle but critical inconsistencies in terms of security guarantees provided on the web platform, such as protection mechanisms against common web attacks. In this work, we have conducted the first systematic measurement study of inconsistencies between mobile and desktop HTTP security response configuration in the top 70,000 websites. We show that HTTP security configuration inconsistencies between mobile and desktop versions of the same website can lead to vulnerabilities. Our study compares data snapshots collected one year apart to garner insights into the longitudinal trends of mobile versus desktop inconsistencies in websites. To complement our measurement study, we present a threat analysis that explores some possible attack scenarios that can leverage the inconsistencies found on real websites. We systematically analyze the security impact of the inconsistent implementations between the mobile and desktop versions of a website and show how it can lead to real-world exploits. We present several case studies of popular websites to show real-world impact of how these inconsistencies are leveraged to compromise security and privacy of web users. Our results show little to no improvements across our datasets, which highlight the continued pervasiveness of subtle inconsistencies affecting even some high profile websites. Abner Mendoza, Phakpoom Chinprutthiwong, Guofei Gu |
WWW | 2 |
| 2015 | Seeing the Instructor in Two Video Styles: Preferences and Patterns
Suma Bhat, Phakpoom Chinprutthiwong, Michelle Perry |
EDM | 2 |