EDBT 2026 Demo / reviewers in the wild / expert
Luis Claramunt
dblp:267/2573 · also Luis M. Claramunt
· DBLP profile ↗
4ranked-venue papers
2as first author
3since 2021 · last 2023
0009-0002-0634-3760ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | SpaceMediator: Leveraging Authorization Policies to Prevent Spatial and Privacy Attacks in Mobile Augmented RealityabstractMobile Augmented Reality (MAR) is a portable, powerful, and suitable technology that integrates digital content, e.g., 3D virtual objects, into the physical world, which not only has been implemented for multiple intents such as shopping, entertainment, gaming, etc., but it is also expected to grow at a tremendous rate in the upcoming years. Unfortunately, the applications that implement MAR, hereby referred to as MAR-Apps, bear security issues, which have been imaged in worldwide incidents such as robberies, which has led authorities to ban MAR-Apps at specific locations. Existing problems with MAR-Apps can be classified into three categories: first, Space Invasion, which implies the intrusive modification through MAR of sensitive spaces, e.g., hospitals, memorials, etc. Second, Space Affectation, which involves the degradation of users' experience via interaction with undesirable MAR or malicious entities. Finally, MAR-Apps mishandling sensitive data leads to Privacy Leaks. Luis Claramunt, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
SACMAT | 1 |
| 2021 | Poster: Preventing Spatial and Privacy Attacks in Mobile Augmented Reality TechnologiesabstractThe growing popularity of applications featuring Mobile Augmented Reality (MAR) raises serious concerns regarding the use of such a game-changing technology inside sensitive physical spaces, e.g., memorials, hospitals, museums, etc., such that the safety and privacy of users is preserved. To address such concerns, we present our ongoing work for mediating the way MAR Content, e.g., digital objects rendered on top of a video stream, is generated, distributed, and consumed by applications. We introduce a theoretical model, a supporting framework, as well as SpaceMediator, a proof-of-concept application implementing our approach. Luis Claramunt, Larissa Pokam Epse, Carlos E. Rubio-Medrano, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 1 |
| 2021 | Poster: DyPolDroid: User-Centered Counter-Policies Against Android Permission-Abuse AttacksabstractAndroid applications are extremely popular, as they are used for banking, social media, e-commerce, etc. However, several malicious applications have recently carried out data leaks and spurious credit card charges by abusing the Android Permissions granted initially to them by unaware users in good faith. To alleviate this pressing concern, we present DyPolDroid, a dynamic, semi-automated security framework that builds upon Android Enterprise, a device-management framework for organizations, allowing for users to design and enforce custom Counter-Policies, effectively protecting against such malicious applications without requiring advanced security and/or technical expertise. Matthew Hill, Carlos E. Rubio-Medrano, Luis Claramunt, Jaejong Baek, Gail-Joon Ahn |
EuroS&P | 3 |
| 2020 | Proactive Risk Assessment for Preventing Attribute-Forgery Attacks to ABAC PoliciesabstractRecently, the use of well-defined, security-relevant pieces of runtime information, a.k.a., attributes, has emerged as a convenient paradigm for writing, enforcing, and maintaining authorization policies, allowing for extended flexibility and convenience. However, attackers may try to bypass such policies, along with their enforcement mechanisms, by maliciously forging the attributes listed on them, e.g., by compromising the attribute sources : operative systems, software modules, remote services, etc., thus gaining unintended access to protected resources as a result. In such a context, performing a proper risk assessment of authorization policies, taking into account their inner structure: rules, attributes, combining algorithms, etc., along with their corresponding sources, becomes highly convenient to overcome \emphzero-day vulnerabilities, before they can be later exploited by attackers. With this in mind, we introduce \toolname, an automated risk assessment framework for authorization policies, which, besides being inspired by well-established techniques for vulnerability analysis such as symbolic execution, also introduces the very first approach for proactively assessing risks in the context of a series of attacks based on unintended attribute manipulation via forgery. We validate our approach by resorting to a set of case studies we performed on both real-life policies originally written in the English language, as well as a set of policies obtained from the literature, which show not only the convenience of our approach for risk assessment, but also reveal that some of those policies are vulnerable to attribute-forgery attacks by just compromising one or two of their attributes. Carlos E. Rubio-Medrano, Luis Claramunt, Shaishavkumar Jogani, Gail-Joon Ahn |
SACMAT | 2 |