Devashish Gosain

dblp:207/8090 · DBLP profile ↗
← Back
25ranked-venue papers
5as first author
19since 2021 · last 2026
0009-0000-1026-8332ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 4 first-author · 12 since 2021Computer networks · 9 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 "Nobody should control the end user": Exploring Privacy Perspectives of Indian Internet Users in Light of DPDPA
abstract
With the rapid increase in online interactions, concerns over data privacy and transparency of data processing practices have become more pronounced. While regulations like the GDPR have driven the widespread adoption of cookie banners in the EU, India's Digital Personal Data Protection Act (DPDPA) promises similar changes domestically, aiming to introduce a framework for data protection. However, certain clauses within the DPDPA raise concerns about potential infringements on user privacy, given the exemptions for government accountability and user consent requirements. In this study, for the first time, we explore Indian Internet users' awareness and perceptions of cookie banners, online privacy, and privacy regulations, especially in light of the newly passed DPDPA. We conducted an online anonymous survey with 428 Indian participants, which addressed: (1) users' perspectives on cookie banners, (2) their attitudes towards online privacy and privacy regulations, and (3) their acceptance of 10 contentious DPDPA clauses that favor state authorities and may enable surveillance. Our findings reveal that privacy-conscious users often lack consistent awareness of privacy mechanisms, and their concerns do not always lead to protective actions. Our thematic analysis of 143 open-ended responses shows that users' privacy and data protection concerns are rooted in skepticism towards the government, shaping their perceptions of the DPDPA and fueling demands for policy revisions. Our study highlights the need for clearer communication regarding the DPDPA, user-centric consent mechanisms, and policy refinements to enhance data privacy practices in India.
Sana Athar, Devashish Gosain, Anja Feldmann, Mannat Kaur 0001, Ha Dao
AsiaCCS2
2026 There is No War in Ba Sing Se: A Global Analysis of Content Moderation in Large Language Models
Friedemann Lipphardt, Moonis Ali, Martin Banzer, Anja Feldmann, Devashish Gosain
NDSS5
2026 Is Misinformation More Open? A Study of robots.txt Gatekeeping on the Web
Nicolas Steinacker-Olsztyn, Devashish Gosain, Ha Dao
WWW2
2026 Clicking into Exposure: Uncovering Privacy Risks of Google Click Identifier in YouTube Ads
abstract
YouTube is one of the largest video platforms on the web, with Google Ads deeply integrated into the viewing experience. While users may expect some level of tracking during ad delivery, the extent and mechanics of Google Ads tracking on YouTube, particularly the tracking behaviors triggered by user interactions with ads, remain underexplored. To address this gap, for the first time, we develop YT-AdTrack, a fully automated framework that measures tracking initiated by YouTube ads across 430 top-trending videos, three widely used browsers, and six geographic locations. In our baseline measurement campaign, YT-AdTrack strategically accepts cookie banners on YouTube, interacts with displayed ads, and subsequently accepts cookie banners on advertiser landing pages to capture downstream tracking behavior. Our findings show that every ad click consistently carries a unique Google Click Identifier, gclid, which is propagated through redirection chains and ultimately embedded in the advertiser’s landing page. We further observe that 64 (out of 76) advertisers persist this identifier as a first-party cookie, thereby transforming a short-lived click token into a durable user identifier. In addition, gclid values frequently leak across parties from advertisers, exposing them to both Google-controlled services and external third-party ad networks, which exacerbates the tracking nexus by extending well beyond standard conversion measurement. Strikingly, even when cookie banners are rejected, ad interactions remain consistently tagged: 55.4% of advertisers store gclidas a cookie, and 18.9% enable auto-tagging, which allows Googleto directly persist the identifier. This demonstrates that banner rejection does not safeguard users from gclid-based tracking. We find these behaviors to be consistent across browsers, with advertisers persisting the identifier in 76.4–84.2% of cases and Google directly storing it in over two-thirds of interactions. Similarly, across six geographic locations, gclid-based tracking persists, with advertisers storing it in 72.5–88.5% of cases and Google’s auto-tagging active in all locations. Overall, our analysis reveals that a single ad click can initiate durable cross-site tracking that persists across various banner choices, browser environments, and regional contexts.
Ha Dao, Abhishek Shinde, Sana Athar, Devashish Gosain
Proc. Priv. Enhancing Technol.4
2025 Can You Hear Me? A First Study of VoIP Censorship Techniques in Saudi Arabia and the UAE
abstract
Internet censorship is a well-explored area, typically focusing on Web censorship enacted by powerful nation-states like China and Russia. In this paper, we diverge from the norm and study the unexplored VoIP censorship prevalent in the Middle East for over a decade. We present the first research analyzing the VoIP filtering mechanics deployed nationwide. Based on extensive on-the-ground experiments, our investigation reveals novel censorship techniques for distinctly filtering VoIP traffic originating from specific apps.We meticulously analyze the VoIP traffic of nine popular apps and reveal the presence of sophisticated "middleboxes" placed within the local ISPs. These middleboxes possess the unique capability to selectively block the calling facility, leaving the rest of the apps’ features, such as texting and media sharing, completely unhindered. Unlike traditional Web filtering techniques that often require inspecting DNS and HTTP(s) traffic, our research demonstrates that the middlebox scrutinizes the STUN protocol requests and response packets to individually identify the application-specific VoIP call flow. Our analysis of widely used apps such as WhatsApp, Signal, and Facebook Messenger reveals a uniquely characterizable flow of STUN packets. We experimentally confirm that the censor exploits such fingerprints to block VoIP calls made through these apps. Furthermore, our experiments unveil additional nuances in censorship tactics. For apps like LINE, the middlebox searches for the VoIP server IP address in some selective packets. On a successful match, it drops the packets, effectively disrupting the call.In essence, our findings provide valuable insights into the intricate mechanisms of sophisticated VoIP filtering techniques, paving the way for more informed approaches to combating such censorship practices.
Friedemann Lipphardt, Anja Feldmann, Devashish Gosain
EuroS&P3
2025 Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies
abstract
In response to the ePrivacy Directive and the consent requirements introduced by the GDPR, websites began deploying consent banners to obtain user permission for data collection and processing. However, due to shared third-party services and technical loopholes, non-consensual cross-site tracking can still occur. In fact, contrary to user expectations of seemingly isolated consent, a user's decision on one website may affect tracking behavior on others. In this study, we investigate the technical and behavioral mechanisms behind these discrepancies. Specifically, we disclose a persistent tracking mechanism exploiting web cookies. These cookies, which we refer to as intractable, are initially set on websites with accepted banners, persist in the browser, and are subsequently sent to trackers before the user provides explicit consent on other websites. To meticulously analyze this covert tracking behavior, we conduct an extensive measurement study performing stateful crawls on over 20k domains from the Tranco top list, strategically accepting banners in the first half of domains and measuring intractable cookies in the second half. Our findings reveal that around 50% of websites send at least one intractable cookie, with the majority set to expire after more than 10 days. In addition, enabling the Global Privacy Control (GPC) signal initially reduces the number of intractable cookies by 30% on average, with a further 32% reduction possible on subsequent visits by rejecting the banners. Moreover, websites with Consent Management Platform (CMP) banners, on average, send 6.9 times more intractable cookies compared to those with native banners. Our research further reveals that even if users reject all other banners, they still receive a large number of intractable cookies set by websites with cookie paywalls. Additionally, our measurement on the partitioned cookies---cookies that are restricted to the top-level site and thus mitigate cross-site tracking---shows that only 1.3% of tracking cookies are marked as such, indicating their minimal impact on cross-site tracking via intractable cookies.
Ali Rasaii, Ha Dao, Anja Feldmann, Mohammadmahdi Javid, Oliver Gasser, Devashish Gosain
Proc. Priv. Enhancing Technol.6
2024 Out in the Open: On the Implementation of Mobile App Filtering in India
Devashish Gosain, Kartikey Singh, Rishi Sharma 0004, Jithin Suresh Babu, Sambuddho Chakravarty
PAM (2)1
2023 Predictable Internet Clients and In-Switch Deep Packet Inspection
abstract
Deep packet inspection (DPI) is important for network security and is currently provided by complex black-box firewalls. This raises the question: Can network administrators build their own DPI-capable filter using a standard programmable switch? The common answer is that standard switches support P4, which allows users to specify how to parse packet headers, but not packet payload fields (e.g. URL) thus DPI tasks, like URL filtering, require dedicated middleboxes. In this paper, we challenge this common answer. First, we demonstrate that clients send packets with a predictable structure, so a P4 switch can perform some DPI (enough for URL filtering). Second, we demonstrate a URL-filtering firewall completely in the data plane, with no external help from the SDN controller, firewalls, etc. and no custom logic. Our proof-of-concept, P4Wall, handles multiple protocols (HTTP, HTTPS, DNS) with high performance - orders of magnitude faster than a standard Linux (netfilter) firewall.
Sahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. Acharya
ICCCN2
2023 Thou Shalt Not Reject: Analyzing Accept-Or-Pay Cookie Banners on the Web
abstract
Privacy regulations have led to many websites showing cookie banners to their users. Usually, cookie banners present the user with the option to "accept" or "reject" cookies. Recently, a new form of paywall-like cookie banner has taken hold on the Web, giving users the option to either accept cookies (and consequently user tracking) or buy a paid subscription for a tracking-free website experience.
Ali Rasaii, Devashish Gosain, Oliver Gasser
IMC2
2023 PTPerf: On the Performance Evaluation of Tor Pluggable Transports
abstract
Tor, one of the most popular censorship circumvention systems, faces regular blocking attempts by censors. Thus, to facilitate access, it relies on "pluggable transports" (PTs) that disguise Tor's traffic and make it hard for the adversary to block Tor. However, these are not yet well studied and compared for the performance they provide to the users. Thus, we conduct a first comparative performance evaluation of a total of 12 PTs-the ones currently supported by the Tor project and those that can be integrated in the future.
Zeya Umayya, Dhruv Malik, Devashish Gosain, Piyush Kumar Sharma
IMC3
2023 DeeP4R: Deep Packet Inspection in P4 using Packet Recirculation
abstract
Software-defined networks are useful for multiple tasks, including firewalling, telemetry, and flow analysis. In particular, the P4 language makes it possible to carry out some simple packet processing tasks in the data plane, i.e., on the switch itself (without real-time support from the SDN controller or a server). However, owing to the limitations of packet parsing in P4, these tasks involve only the packet headers. In this paper, we present a novel approach that allows Deep Packet Inspection (DPI) – i.e., inspection of the packet payload – in the data plane, using P4 alone. We make use of the fact that in P4, a switch can clone and recirculate packets. One copy (clone) can be recirculated, slicing off a byte in each round, and using a finite-state machine to check if a target string has yet been seen. If the target string is found, the other copy (original packet) is discarded; if not, it is passed through. Our approach allows us to build the first application-layer firewall (URL filter) in the data plane, and to achieve essentially line-rate performance while filtering thousands of URLs, on a commodity programmable switch. It may in future also be used for other DPI tasks.
Sahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. Acharya
INFOCOM2
2023 On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by Cryptocurrencies
Piyush Kumar Sharma, Devashish Gosain, Claudia Díaz
NDSS2
2023 Exploring the Cookieverse: A Multi-Perspective Analysis of Web Cookies
Ali Rasaii, Devashish Gosain, Oliver Gasser
PAM3
2023 Cryptographic Deniability: A Multi-perspective Study of User Perceptions and Expectations
Tarun Kumar Yadav, Devashish Gosain, Kent E. Seamons
USENIX Security Symposium2
2022 Automatic Detection of Fake Key Attacks in Secure Messaging
abstract
Popular instant messaging applications such as WhatsApp and Signal provide end-to-end encryption for billions of users. These applications often rely on a centralized, application-specific server to distribute public keys and relay encrypted messages between the users. As a result, they prevent passive attacks but are vulnerable to some active attacks. A malicious or hacked server can distribute fake keys to users to perform man-in-the-middle or impersonation attacks. While typical secure messaging applications provide a manual method for users to detect these attacks, this burdens users, and studies show it is ineffective in practice. This paper presents KTACA, a completely automated approach for key verification that is oblivious to users and easy to deploy. We motivate KTACA by designing two approaches to automatic key verification. One approach uses client auditing (KTCA) and the second uses anonymous key monitoring (AKM). Both have relatively inferior security properties, leading to KTACA, which combines these approaches to provide the best of both worlds. We provide a security analysis of each defense, identifying which attacks they can automatically detect. We implement the active attacks to demonstrate they are possible, and we also create a prototype implementation of all the defenses to measure their performance and confirm their feasibility. Finally, we discuss the strengths and weaknesses of each defense, the load they impose on clients and service providers, and their deployment considerations.
Tarun Kumar Yadav, Devashish Gosain, Amir Herzberg, Daniel Zappala, Kent E. Seamons
CCS2
2021 Camoufler: Accessing The Censored Web By Utilizing Instant Messaging Channels
abstract
Free and open communication over the Internet is considered a fundamental human right, essential to prevent repressions from silencing voices of dissent. This has led to the development of various anti-censorship systems. Recent systems have relied on a common blocking resistance strategy i.e., incurring collateral damage to the censoring regimes, if they attempt to restrict such systems. However, despite being promising, systems built on such strategies pose additional challenges, viz., deployment limitations, poor QoS etc. These challenges prevent their wide scale adoption.
Piyush Kumar Sharma, Devashish Gosain, Sambuddho Chakravarty
AsiaCCS2
2021 Demo: Simple Deep Packet Inspection with P4
abstract
The P4 language allows "protocol-independent packet parsing" in network switches, and makes many operations possible in the data plane. But P4 is not built for Deep Packet Inspection – it can only "parse" well-defined packet headers, not free-form headers as seen in HTTPS etc. Thus some very important use cases, such as application-layer firewalls, are considered impossible for P4. This demonstration shows that this limitation is not strictly true: switches, that support only standard P4, are able to independently perform tasks such as blocking specific URLs (without using non-standard "extern" components, help from the SDN controller, or rerouting to a firewall). As more Internet infrastructure becomes SDN-compatible, in future, switches may perform simple application-layer firewall tasks.
Sahil Gupta, Devashish Gosain, Garegin Grigoryan, Minseok Kwon, Hrishikesh B. Acharya
ICNP2
2021 Telemetron: Measuring Network Capacity Between Off-Path Remote Hosts
abstract
This paper presents Telemetron, the first active bandwidth measurement tool that can estimate the path capacity between two remote hosts, from an off-path Measuring Machine (MM). It is possible to induce traffic flow between off-path remote hosts—sending request packets to one host, with a spoofed source IP, will cause the first host to send reply packets to the other. The challenge for MM is to measure the rate at which these packets arrive at the second machine. Our key observation is that if the second machine has a global IP-ID counter, the arrival of packets can be monitored remotely, using probes from MM. By observing the rate of increment in the global IP-ID counter, MM estimates the path capacity between remote hosts. Telemetron shows high accuracy; on average, the path capacity reported is 92.5% of the theoretical limit.
Devashish Gosain, Aishwarya Jaiswal, Hrishikesh B. Acharya, Sambuddho Chakravarty
LCN1
2021 Too Close for Comfort: Morasses of (Anti-) Censorship in the Era of CDNs
abstract
Abstract Recent research claims that “powerful” nation-states may be hegemonic over significant web traffic of “underserved” nations (e.g., Brazil and India). Such traffic may be surveilled when transiting (or ending in) these powerful nations. On the other hand, content distribution networks (CDNs) are designed to bring web content closer to end-users. Thus it is natural to ask whether CDNs have led to the localization of Internet traffic within the country’s boundary, challenging the notion of nation-state hegemony. Further, such traffic localization may inadvertently enhance a country’s ability to coerce content providers to censor (or monitor) access within its boundary. On top of that, the obvious solution, i.e., anti-censorship approaches, may sadly face a new dilemma. Traditional ones, relying on proxies, are easily discoverable. Whereas newer ones (e.g., Decoy Routing, Cache-Browser, Domain Fronting and CovertCast etc.) might not work as they require accessing web content hosted outside the censors’ boundary. We thus quantitatively analyzed the impact of web content localization on various anti-censorship systems. Such analysis requires geolocating the websites. Thus we adapted a multilateration method, Constraint Based Geolocation (CBG), with additional heuristics. We call it as Region Specific CBG (R-CBG). In more than 89% cases, R-CBG correctly classifies hosts as inside (or outside) w.r.t. a nation. Our empirical study, involving five countries, shows that the majority (61%−92%) of popular country-specific websites are hosted within a client’s own country. Further, additional heuristics classify the majority of them to be on CDNs.
Devashish Gosain, Mayank Mohindra, Sambuddho Chakravarty
Proc. Priv. Enhancing Technol.1
2020 SiegeBreaker: An SDN Based Practical Decoy Routing System
abstract
Abstract Decoy Routing (DR), a promising approach to censorship circumvention, uses routers (rather than end hosts) as proxy servers. Users of censored networks, who wish to use DR, send specially crafted packets, nominally addressed to an uncensored website. Once safely out of the censored network, the packets encounter a special router (the Decoy Router) which identifies them using a secret handshake, and proxies them to their true destination (a censored site). However, DR has implementation problems: it is infeasible to reprogram routers for the complex operations required. Existing DR solutions fall back on using commodity servers as a Decoy Router. But as servers are not efficient at routing, most web applications show poor performance when accessed over DR. A further concern is that the Decoy Router has to inspect all flows in order to identify the ones that need DR. This may itself be a breach of privacy for other users (who neither require DR nor want to be monitored). In this paper, we present a novel DR system, Siege- Breaker (SB), which solves the aforementioned problems using an SDN-based architecture. Previous proposals involve a single unit which performs all major operations (inspecting all flows, identifying the DR requests and proxying them). In contrast, SB distributes the tasks for DR among three independent modules. (1) The SDN controller identifies DR requests via a covert, privacy preserving scheme, and does not need to inspect all flows. (2) The reconfigurable SDN switch intercepts packets, and forwards them to a secret proxy efficiently. (3) The secret proxy server proxies the client’s traffic to the censored site. Our modular, lightweight design achieves performance comparable to direct TCP downloads, for both in-lab setups, and Internet based tests involving commercial SDN switches.
Piyush Kumar Sharma, Devashish Gosain, Himanshu Sagar, Chaitanya Kumar, Aneesh Dogra, Vinayak S. Naik, Hrishikesh B. Acharya, Sambuddho Chakravarty
Proc. Priv. Enhancing Technol.2
2019 CAMP: cluster aided multi-path routing protocol for wireless sensor networks
Mohit Sajwan, Devashish Gosain, Ajay K. Sharma
Wirel. Networks2
2018 Where The Light Gets In: Analyzing Web Censorship Mechanisms in India
Tarun Kumar Yadav, Akshat Sinha, Devashish Gosain, Piyush Kumar Sharma, Sambuddho Chakravarty
Internet Measurement Conference3
2017 The Devil's in The Details: Placing Decoy Routers in the Internet
abstract
Decoy Routing, the use of routers (rather than end hosts) as proxies, is a new direction in anti-censorship research. Decoy Routers (DRs), placed in Autonomous Systems, proxy traffic from users; so the adversary, e.g. a censorious government, attempts to avoid them. It is quite difficult to place DRs so the adversary cannot route around them -- for example, we need the cooperation of 850 ASes to contain China alone [1].
Devashish Gosain, Anshika Agarwal, Sambuddho Chakravarty, Hrishikesh B. Acharya
ACSAC1
2017 Few Throats to Choke: On the Current Structure of the Internet
abstract
The original design of the Internet was a resilient, distributed system, that maybe able to route around (and therefore recover from) massive disruption - up to and including nuclear war. However, network routing effects and business decisions cause traffic to often be routed through a relatively small set of Autonomous Systems (ASes). This is not merely an academic issue; it has practical implications - some of these frequently appearing ASes are hosted in censorious nations. Other than censoring their own citizens' network access, such ASes may inadvertently filter traffic for other foreign customer ASes. In this paper, we examine the extent of routing centralization in the Internet; identify the major players who control the “Internet backbone”; and point out how many of these are, in fact, under the jurisdiction of censorious countries (specifically, Russia, China, and India). Further, we show that China and India are not only the two largest nations by number of Internet users, but that many users in free and democratic countries are affected by collateral damage caused due to censorship by such countries.
Hrishikesh B. Acharya, Sambuddho Chakravarty, Devashish Gosain
LCN3
2017 Mending Wall: On the Implementation of Censorship in India
Devashish Gosain, Anshika Agarwal, Sahil Shekhawat, Hrishikesh B. Acharya, Sambuddho Chakravarty
SecureComm1