EDBT 2026 Demo / reviewers in the wild / expert
Nazari Skrupsky
dblp:65/8736
· DBLP profile ↗
4ranked-venue papers
1as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 60% Web and mobile security · 40% |
Topics — the 3 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.2 | 2 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010 |
Web and mobile security
web application vulnerability |
0.2 | 2 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010 |
Systems and software security › exploitation
exploit generation |
0.1 | 1 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 |
Methods — techniques the papers use, named apart from their topics
symbolic execution · 0.1static analysis · 0.1input validation analysis · 0.1black-box testing · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Automated detection of parameter tampering opportunities and vulnerabilities in web applicationsabstractParameter tampering attacks are dangerous to a web application whose server fails to replicate the validation of user-supplied data that is performed by the client in web forms. Malicious users who circumvent the client can capitalize on the missing server validation. In this paper, we provide a formal description of parameter tampering vulnerabilities and a high level approach for their detection. We specialize this high level approach to develop complementary detection solutions in two interesting settings: blackbox (only analyze client-side code in web forms) and whitebox (also analyze server-side code that processes submitted web forms). This paper presents interesting challenges encountered in realizing the high level approach for each setting and novel technical contributions that address these challenges. We also contrast utility, difficulties and effectiveness issues in both settings and provide a quantitative comparison of results. Our experiments with real world and open source applications demonstrate that parameter tampering vulnerabilities are prolific (total 47 in 9 applications), and their exploitation can have serious consequences including unauthorized transactions, account hijacking and financial losses. We conclude this paper with a discussion on countermeasures for parameter tampering attacks and present a detailed survey of existing defenses and their suitability. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, V. N. Venkatakrishnan |
J. Comput. Secur. | 3 |
| 2013 | TamperProof: a server-agnostic defense for parameter tampering attacks on web applicationsabstractParameter tampering attacks are dangerous to a web application whose server performs weaker data sanitization than its client. This paper presents TamperProof, a methodology and tool that offers a novel and efficient mechanism to protect Web applications from parameter tampering attacks. TamperProof is an online defense deployed in a trusted environment between the client and server and requires no access to, or knowledge of, the server side codebase, making it effective for both new and legacy applications. The paper reports on experiments that demonstrate TamperProof's power in efficiently preventing all known parameter tampering vulnerabilities on ten different applications. Nazari Skrupsky, Prithvi Bisht, Timothy L. Hinrichs, V. N. Venkatakrishnan, Lenore D. Zuck |
CODASPY | 1 |
| 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit constructionabstractParameter tampering attacks are dangerous to a web application whose server fails to replicate the validation of user-supplied data that is performed by the client. Malicious users who circumvent the client can capitalize on the missing server validation. In this paper, we describe WAPTEC, a tool that is designed to automatically identify parameter tampering vulnerabilities and generate exploits by construction to demonstrate those vulnerabilities. WAPTEC involves a new approach to whitebox analysis of the server's code. We tested WAPTEC on six open source applications and found previously unknown vulnerabilities in every single one of them. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, V. N. Venkatakrishnan |
CCS | 3 |
| 2010 | NoTamper: automatic blackbox detection of parameter tampering opportunities in web applicationsabstractWeb applications rely heavily on client-side computation to examine and validate form inputs that are supplied by a user (e.g., "credit card expiration date must be valid"). This is typically done for two reasons: to reduce burden on the server and to avoid latencies in communicating with the server. However, when a server fails to replicate the validation performed on the client, it is potentially vulnerable to attack. In this paper, we present a novel approach for automatically detecting potential server-side vulnerabilities of this kind in existing (legacy) web applications through blackbox analysis. We discuss the design and implementation of NoTamper, a tool that realizes this approach. NoTamper has been employed to discover several previously unknown vulnerabilities in a number of open-source web applications and live web sites. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz, V. N. Venkatakrishnan |
CCS | 3 |