EDBT 2026 Demo / reviewers in the wild / expert
Niels Provos
dblp:90/6745
· DBLP profile ↗
20ranked-venue papers
8as first author
0since 2021 · last 2016
0009-0006-8446-3978ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 7 first-authorComputer networks · 3Systems, architecture and hardware · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
16 papers |
Malware analysis · 41% Systems and software security · 20% Web and mobile security · 17% | |
| Computer networks
3 papers |
Network measurement and analytics · 83% Internet architecture and protocols · 17% |
Topics — the 23 heaviest of 29, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis
pay-per-install |
0.2 | 1 | 2016 | Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software · USENIX Security Symposium 2016 |
Malware analysis
malware defense |
0.2 | 1 | 2013 | CAMP: Content-Agnostic Malware Protection · NDSS 2013 |
Systems and software security › exploitation › injection attacks
code injection attack |
0.1 | 1 | 2011 | SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks · USENIX Security Symposium 2011 |
Network security › protocol security
DNS security |
0.1 | 1 | 2008 | Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority · NDSS 2008 |
Web and mobile security
web attacks |
0.1 | 1 | 2008 | All Your iFRAMEs Point to Us · USENIX Security Symposium 2008 |
Network security
malware propagation |
0.1 | 1 | 2016 | Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software · USENIX Security Symposium 2016 |
Digital forensics and information hiding
steganography |
0.1 | 2 | 2002 | Detecting Steganographic Content on the Internet · NDSS 2002 Defending Against Statistical Steganalysis · USENIX Security Symposium 2001 |
Web and mobile security
browser security |
0.1 | 1 | 2015 | Trends and Lessons from Three Years Fighting Malicious Extensions · USENIX Security Symposium 2015 |
Network measurement and analytics
traffic analysis |
0.1 | 1 | 2005 | Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic · Internet Measurement Conference 2005 |
Network security › traffic analysis
network telescope analysis |
0.1 | 1 | 2005 | Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic · Internet Measurement Conference 2005 |
Systems and software security
vulnerability discovery |
0.0 | 1 | 2013 | CAMP: Content-Agnostic Malware Protection · NDSS 2013 |
Network security › cyber deception
honeypot |
0.0 | 1 | 2004 | A Virtual Honeypot Framework · USENIX Security Symposium 2004 |
Systems and software security › platform security
host security |
0.0 | 1 | 2003 | Improving Host Security with System Call Policies · USENIX Security Symposium 2003 |
Systems and software security › exploitation mitigation
privilege escalation prevention |
0.0 | 1 | 2003 | Preventing Privilege Escalation · USENIX Security Symposium 2003 |
Digital forensics and information hiding › digital forensics
forensic analysis |
0.0 | 1 | 2011 | SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks · USENIX Security Symposium 2011 |
Digital forensics and information hiding
steganalysis |
0.0 | 1 | 2002 | Detecting Steganographic Content on the Internet · NDSS 2002 |
Systems and software security
memory protection |
0.0 | 1 | 2000 | Encrypting Virtual Memory · USENIX Security Symposium 2000 |
Internet architecture and protocols › domain name system
DNS resolution |
0.0 | 1 | 2008 | Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority · NDSS 2008 |
Malware analysis › web-based malware
drive-by downloads |
0.0 | 1 | 2008 | All Your iFRAMEs Point to Us · USENIX Security Symposium 2008 |
Operating systems › system security › operating system security
access control |
0.0 | 2 | 2003 | Preventing Privilege Escalation · USENIX Security Symposium 2003 Improving Host Security with System Call Policies · USENIX Security Symposium 2003 |
Network security › intrusion detection and prevention
intrusion detection |
0.0 | 1 | 2004 | A Virtual Honeypot Framework · USENIX Security Symposium 2004 |
Digital forensics and information hiding
information hiding |
0.0 | 1 | 2001 | Defending Against Statistical Steganalysis · USENIX Security Symposium 2001 |
Memory systems › memory management
virtual memory |
0.0 | 1 | 2000 | Encrypting Virtual Memory · USENIX Security Symposium 2000 |
Methods — techniques the papers use, named apart from their topics
revenue chain analysis · 0.4measurement pipeline · 0.4measurement study · 0.4machine learning · 0.2natural language processing · 0.2data reduction · 0.1encryption · 0.1statistical detection · 0.0statistical steganalysis · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software
Kurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod, Cait Phillips, Marc-André Decoste, Chris Sharp, Fabio Tirelo, Ali Tofigh, Marc-Antoine Courteau, Lucas Ballard, Robert Shield, Nav Jagpal, Moheeb Abu Rajab, Panayiotis Mavrommatis, Niels Provos, Elie Bursztein, Damon McCoy |
USENIX Security Symposium | 16 |
| 2015 | Ad Injection at Scale: Assessing Deceptive Advertisement ModificationsabstractToday, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Google -- tens of millions of users around the globe. Injected ads arrive on a client's machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved. Kurt Thomas, Elie Bursztein, Chris Grier, Grant Ho, Nav Jagpal, Alexandros Kapravelos, Damon McCoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab |
IEEE Symposium on Security and Privacy | 11 |
| 2015 | Trends and Lessons from Three Years Fighting Malicious Extensions
Nav Jagpal, Eric Dingle, Jean-Philippe Gravel, Panayiotis Mavrommatis, Niels Provos, Moheeb Abu Rajab, Kurt Thomas |
USENIX Security Symposium | 5 |
| 2013 | CAMP: Content-Agnostic Malware Protection
Moheeb Abu Rajab, Lucas Ballard, Noe Lutz, Panayiotis Mavrommatis, Niels Provos |
NDSS | 5 |
| 2012 | Manufacturing compromise: the emergence of exploit-as-a-serviceabstractWe investigate the emergence of the exploit-as-a-service model for driveby browser compromise. In this regime, attackers pay for an exploit kit or service to do the "dirty work" of exploiting a victim's browser, decoupling the complexities of browser and plugin vulnerabilities from the challenges of generating traffic to a website under the attacker's control. Upon a successful exploit, these kits load and execute a binary provided by the attacker, effectively transferring control of a victim's machine to the attacker. Chris Grier, Lucas Ballard, Juan Caballero, Neha Chachra, Christian Dietrich 0005, Kirill Levchenko, Panayiotis Mavrommatis, Damon McCoy, Antonio Nappa, Andreas Pitsillidis, Niels Provos, M. Zubair Rafique, Moheeb Abu Rajab, Christian Rossow, Kurt Thomas, Vern Paxson, Stefan Savage, Geoffrey M. Voelker |
CCS | 11 |
| 2011 | SHELLOS: Enabling Fast Detection and Forensic Analysis of Code Injection Attacks
Kevin Z. Snow, Srinivas Krishnan, Fabian Monrose, Niels Provos |
USENIX Security Symposium | 4 |
| 2010 | Peeking Through the Cloud: Client Density Estimation via DNS Cache ProbingabstractReliable network demographics are quickly becoming a much sought-after digital commodity. However, as the need for more refined Internet demographics has grown, so too has the tension between privacy and utility. Unfortunately, current techniques lean too much in favor of functional requirements over protecting the privacy of users. For example, the most prominent proposals for measuring the relative popularity of a Web site depend on the deployment of client-side measurement agents that are generally perceived as infringing on users’ privacy, thereby limiting their wide-scale adoption. Moreover, the client-side nature of these techniques also makes them susceptible to various manipulation tactics that undermine the integrity of their results. In this article, we propose a new estimation technique that uses DNS cache probing to infer the density of clients accessing a given service. Compared to earlier techniques, our scheme is less invasive as it does not reveal user-specific traits, and is more robust against manipulation. We demonstrate the flexibility of our approach through two important security applications. First, we illustrate how our scheme can be used as a lightweight technique for measuring and verifying the relative popularity rank of different Web sites. Second, using data from several hundred botnets, we apply our technique to indirectly measure the infected population of this increasing Internet phenomenon. Moheeb Abu Rajab, Fabian Monrose, Niels Provos |
ACM Trans. Internet Techn. | 3 |
| 2008 | Peeking Through the Cloud: DNS-Based Estimation and Its Applications
Moheeb Abu Rajab, Fabian Monrose, Andreas Terzis, Niels Provos |
ACNS | 4 |
| 2008 | Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority
David Dagon, Niels Provos, Christopher P. Lee 0001, Wenke Lee |
NDSS | 2 |
| 2008 | All Your iFRAMEs Point to Us
Niels Provos, Panayiotis Mavrommatis, Moheeb Abu Rajab, Fabian Monrose |
USENIX Security Symposium | 1 |
| 2008 | To Catch a Predator: A Natural Language Approach for Eliciting Malicious Payloads
Sam Small, Joshua Mason, Fabian Monrose, Niels Provos, Adam Stubblefield |
USENIX Security Symposium | 4 |
| 2006 | Flow-Cookies: Using Bandwidth Amplification to Defend Against DDoS Flooding AttacksabstractThis paper describes flow-cookies which defend against DDoS flooding attacks using bandwidth amplification. "Flow-cookies" is a mechanism in which a Website can reliably send filtering requests to a cooperating node in the network, leveraging its protection bandwidth. In this approach, a third party provider installs a flow-cookies enabled middlebox called the cookie box, in the network at a high bandwidth link. All traffic to or from the protected Web server must traverse the cookie box. The cookie box guarantees that all packets that pass between it and the server belong to a legitimate TCP flow with a valid sender. This implementation is able to operate at gigabit speeds including per-packet IP filtering of millions of addresses. This approach is also very effective against high volume SYN flooding attacks Martín Casado, Aditya Akella, Niels Provos |
IWQoS | 4 |
| 2005 | Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic
Michael D. Bailey, Evan Cooke, Farnam Jahanian, Niels Provos, Karl Rosaen, David Watson 0001 |
Internet Measurement Conference | 4 |
| 2004 | A Virtual Honeypot Framework
Niels Provos |
USENIX Security Symposium | 1 |
| 2003 | Improving Host Security with System Call Policies
Niels Provos |
USENIX Security Symposium | 1 |
| 2003 | Preventing Privilege Escalation
Niels Provos, Markus Friedl, Peter Honeyman |
USENIX Security Symposium | 1 |
| 2002 | Detecting Steganographic Content on the Internet
Niels Provos, Peter Honeyman |
NDSS | 1 |
| 2001 | ScanSSH: Scanning the Internet for SSH Servers
Niels Provos, Peter Honeyman |
LISA | 1 |
| 2001 | Defending Against Statistical Steganalysis
Niels Provos |
USENIX Security Symposium | 1 |
| 2000 | Encrypting Virtual Memory
Niels Provos |
USENIX Security Symposium | 1 |