EDBT 2026 Demo / reviewers in the wild / expert
Asaf Nadler
dblp:198/8291
· DBLP profile ↗
6ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0003-4397-3729ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Information Based Heavy Hitters for Real-Time DNS Data Exfiltration Detection
Yarin Ozery, Asaf Nadler, Asaf Shabtai |
NDSS | 2 |
| 2022 | On the vulnerability of anti-malware solutions to DNS attacks
Asaf Nadler, Ron Biton, Oleg Brodt, Asaf Shabtai |
Comput. Secur. | 1 |
| 2021 | MORTON: Detection of Malicious Routines in Large-Scale DNS Traffic
Yael Daihes, Hen Tzaban, Asaf Nadler, Asaf Shabtai |
ESORICS (1) | 3 |
| 2020 | Helix: DGA Domain Embeddings for Tracking and Exploring BotnetsabstractBotnets have been using domain generation algorithms (DGA) for over a decade to covertly and robustly identify the domain name of their command and control servers (C&C). Recent advancements in DGA detection has motivated botnet owners to rapidly alter the C&C domain and use adversarial techniques to evade detection. As a result, it has become increasingly difficult to track botnets in DNS traffic. In this paper, we present Helix, a method for tracking and exploring botnets. Helix uses a spatio-temporal deep neural network autoencoder to convert domains into numerical vectors (embeddings) which capture the DGA and seed used to create the domain. This is made possible by leveraging both convolutional (spatial) and recurrent (temporal) layers, and by using techniques such as attention mechanisms and highways. Furthermore, by using an autoencoder architecture, the network can be trained in an unsupervised manner (no labeling of data) which makes the system practical for real world deployments. In our evaluation, we found that Helix can track botnet campaigns, distinguish between DGA families and seeds, and can identify domains generated using the latest adversarial machine learning techniques. Helix is currently being used to track botnets in one of the world's largest Internet Service Providers (ISP), and we include some of the ISP's analysis work using our method. Lior Sidi, Yisroel Mirsky, Asaf Nadler, Yuval Elovici, Asaf Shabtai |
CIKM | 3 |
| 2019 | Detection of malicious and low throughput data exfiltration over the DNS protocol
Asaf Nadler, Avi Aminov, Asaf Shabtai |
Comput. Secur. | 1 |
| 2019 | IoTPatchPool: Incentivized delivery network of IoT software updates based on proofs-of-distribution
Oded Leiba, Ron Biton, Yechiav Yitzchak, Asaf Nadler, Davidoz Kashi, Asaf Shabtai |
Pervasive Mob. Comput. | 4 |