EDBT 2026 Demo / reviewers in the wild / expert
Mojtaba Zaheri
dblp:216/6671
· DBLP profile ↗
4ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0001-7713-569XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Contention-Based Side Channels Enable Faster and Stealthier Browsing History SniffingabstractWeb browsers are implicitly trusted to handle a large amount of private user information. One such piece of private information, a user's browsing history, is maintained by browsers and is used to provide a popular usability feature: Web links are rendered using different styles depending on whether the URLs they point to have been visited or not. Unfortunately, this feature can be abused by malicious webpages in order to extract users’ browsing history. We present new browsing history sniffing attacks through two contention-based side channels which are new in this context: Last-level CPU cache contention, and GPU execution unit contention. The attacks are robust and can be executed successfully against the popular Chrome browser. Compared to prior work which uses the rendering performance as a side channel, our work achieves an attack rate increase of up to 30x. The new attacks are stealthier, because the side channels we use do not slow down the browser's rendering rate. In addition, we revisit the existing sniffing attacks based on the rendering performance side channel, and show how their attack rate can also be increased by a significant amount. Finally, we discuss the root cause of history sniffing attacks and point out solutions. Mojtaba Zaheri, Yossef Oren, Reza Curtmola |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Targeted Deanonymization via the Cache Side Channel: Attacks and Defenses
Mojtaba Zaheri, Yossef Oren, Reza Curtmola |
USENIX Security Symposium | 1 |
| 2021 | Leakuidator: Leaky Resource Attacks and Countermeasures
Mojtaba Zaheri, Reza Curtmola |
SecureComm (2) | 1 |
| 2020 | SMT-based cube attack on round-reduced Simeck32/64abstractIn this study, the authors take advantage of feeding the SMT solver by extra information provided through middle state cube characteristics to introduce a new method which they call SMT‐based cube attack, and apply it to improve the success of the solver in attacking reduced‐round versions of Simeck32/64 lightweight block cipher. The key idea is to search for and utilise all found middle state characteristics of a cube at one round of attack. They first propose a new algorithm to find cubes with most number of middle state characteristics. Then, they apply these obtained cubes and their characteristics as extra information in the SMT definition of the cryptanalysis problem, to evaluate its effectiveness. Their cryptanalysis results in a full key recovery attack by 64 plaintext/ciphertext pairs on 12 rounds of the cipher in just 122.17 s. This is the first algebraic attack so far presented against the reduced‐round versions of Simeck32/64, and also with practical complexities. They also conduct the cube attack on the Simeck32/64 to compare with the SMT‐based cube attack. The results indicate that the proposed attack is more powerful than the cube attack. Mojtaba Zaheri, Babak Sadeghiyan |
IET Inf. Secur. | 1 |