EDBT 2026 Demo / reviewers in the wild / expert
Yazan Boshmaf
dblp:90/7258
· DBLP profile ↗
19ranked-venue papers
8as first author
2since 2021 · last 2023
0000-0002-0816-6924ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 6 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Dizzy: Large-Scale Crawling and Analysis of Onion ServicesabstractWith nearly 2.5m users, onion services have become the prominent part of the darkweb. Over the last five years alone, the number of onion domains has increased 20x, reaching more than 700k unique domains in January 2022. As onion services host various types of illicit content, they have become a valuable resource for darkweb research and an integral part of e-crime investigation and threat intelligence. However, this content is largely un-indexed by today’s search engines and researchers have to rely on outdated or manually-collected datasets that are limited in scale, scope, or both. Yazan Boshmaf, Isuranga Perera, Udesh Kumarasinghe, Sajitha Liyanage, Husam Al Jawaheri |
ARES | 1 |
| 2022 | Content-Agnostic Detection of Phishing Domains using Certificate Transparency and Passive DNSabstractExisting phishing detection techniques mainly rely on blacklists or content-based analysis, which are not only evadable, but also exhibit considerable detection delays as they are reactive in nature. We observe through our deep dive analysis that artifacts of phishing are manifested in various sources of intelligence related to a domain even before its contents are online. In particular, we study various novel patterns and characteristics computed from viable sources of data including Certificate Transparency Logs, and passive DNS records. To compare benign and phishing domains, we construct thoroughly-verified realistic benign and phishing datasets. Our analysis shows clear differences between benign and phishing domains that can pave the way for content-agnostic approaches to predict phishing domains even before the contents of these webpages are up and running. Mashael Al Sabah, Mohamed Nabeel, Yazan Boshmaf, Euijin Choo |
RAID | 3 |
| 2020 | Investigating MMM Ponzi Scheme on BitcoinabstractCybercriminals exploit cryptocurrencies to carry out illicit activities. In this paper, we focus on Ponzi schemes that operate on Bitcoin and perform an in-depth analysis of MMM, one of the oldest and most popular Ponzi schemes. Based on 423K transactions involving 16K addresses, we show that: (1) Starting Sep 2014, the scheme goes through three phases over three years. At its peak, MMM circulated more than 150M dollars a day, after which it collapsed by the end of Jun 2016. (2) There is a high income inequality between MMM members, with the daily Gini index reaching more than 0.9. The scheme also exhibits a zero-sum investment model, in which one member's loss is another member's gain. The percentage of victims who never made any profit has grown from 0% to 41% in five months, during which the top-earning scammer has made 765K dollars in profit. (3) The scheme has a global reach with 80 different member countries but a highly-asymmetrical flow of money between them. While India and Indonesia have the largest pairwise flow in MMM, members in Indonesia have received 12x more money than they have sent to their counterparts in India. Yazan Boshmaf, Charith Elvitigala, Husam Al Jawaheri, Primal Wijesekera, Mashael Al Sabah |
AsiaCCS | 1 |
| 2020 | Deanonymizing Tor hidden service users through Bitcoin transactions analysis
Husam Al Jawaheri, Mashael Al Sabah, Yazan Boshmaf, Aiman Erbad |
Comput. Secur. | 3 |
| 2019 | BlockTag: Design and Applications of a Tagging System for Blockchain Analysis
Yazan Boshmaf, Husam Al Jawaheri, Mashael Al Sabah |
SEC | 1 |
| 2018 | Source Attribution of Cryptographic API Misuse in Android ApplicationsabstractRecent research suggests that 88% of Android applications that use Java cryptographic APIs make at least one mistake, which results in an insecure implementation. It is unclear, however, if these mistakes originate from code written by application or third-party library developers. Understanding the responsible party for a misuse case is important for vulnerability disclosure. In this paper, we bridge this knowledge gap and introduce source attribution to the analysis of cryptographic API misuse. We developed BinSight, a static program analyzer that supports source attribution, and we analyzed 132K Android applications collected in years 2012, 2015, and 2016. Our results suggest that third-party libraries are the main source of cryptographic API misuse. In particular, 90% of the violating applications, which contain at least one call-site to Java cryptographic API, originate from libraries. When compared to 2012, we found the use of ECB mode for symmetric ciphers has significantly decreased in 2016, for both application and third-party library code. Unlike application code, however, third-party libraries have significantly increased their reliance on static encryption keys for symmetric ciphers and static IVs for CBC mode ciphers. Finally, we found that the insecure RC4 and DES ciphers were the second and the third most used ciphers in 2016. Ildar Muslukhov, Yazan Boshmaf, Konstantin Beznosov |
AsiaCCS | 2 |
| 2016 | Harvesting the low-hanging fruits: defending against automated large-scale cyber-intrusions by focusing on the vulnerable populationabstractThe orthodox paradigm to defend against automated social-engineering attacks in large-scale socio-technical systems is reactive and victim-agnostic. Defenses generally focus on identifying the attacks/attackers (e.g., phishing emails, social-bot infiltrations, malware offered for download). To change the status quo, we propose to identify, even if imperfectly, the vulnerable user population, that is, the users that are likely to fall victim to such attacks. Once identified, information about the vulnerable population can be used in two ways. First, the vulnerable population can be influenced by the defender through several means including: education, specialized user experience, extra protection layers and watchdogs. In the same vein, information about the vulnerable population can ultimately be used to fine-tune and reprioritize defense mechanisms to offer differentiated protection, possibly at the cost of additional friction generated by the defense mechanism. Secondly, information about the user population can be used to identify an attack (or compromised users) based on differences between the general and the vulnerable population. This paper considers the implications of the proposed paradigm on existing defenses in three areas (phishing of user credentials, malware distribution and socialbot infiltration) and discusses how using knowledge of the vulnerable population can enable more robust defenses. Hassan Halawa, Konstantin Beznosov, Yazan Boshmaf, Baris Coskun, Matei Ripeanu, Elizeu Santos-Neto |
NSPW | 3 |
| 2016 | Visualization of actionable knowledge to mitigate DRDoS attacksabstractDistributed Reflective Denial of Service attacks (DRDoS) represent an ever growing security threat. These attacks are characterized by spoofed UDP traffic that is sent to genuine machines, called amplifiers, whose response to the spoofed IP, i.e. the victim machine, is amplified and could be 500 times larger in size than the originating request. In this paper, we provide a method and a tool for Internet Service Providers (ISPs) to assess and visualize the amount of traffic that enters and leaves their network in case it contains innocent amplifiers. We show that amplified traffic usually goes undetected and can consume a significant bandwidth, even when a small number of amplifiers is present. The tool also enables ISPs to simulate various rule-based mitigation strategies and estimate their impact, based on real-world data obtained from amplification honeypots. Michaël Aupetit 0001, Yury Zhauniarovich, Giorgos Vasiliadis, Marc Dacier, Yazan Boshmaf |
VizSEC | 5 |
| 2016 | Íntegro: Leveraging victim prediction for robust fake account detection in large scale OSNs
Yazan Boshmaf, Dionysios Logothetis, Georgos Siganos, Jorge Lería, José Lorenzo, Matei Ripeanu, Konstantin Beznosov, Hassan Halawa |
Comput. Secur. | 1 |
| 2016 | Decoupling data-at-rest encryption and smartphone locking with wearable devices
Ildar Muslukhov, San-Tsai Sun, Primal Wijesekera, Yazan Boshmaf, Konstantin Beznosov |
Pervasive Mob. Comput. | 4 |
| 2015 | Integro: Leveraging Victim Prediction for Robust Fake Account Detection in OSNs
Yazan Boshmaf, Dionysios Logothetis, Georgos Siganos, Jorge Lería, José Lorenzo, Matei Ripeanu, Konstantin Beznosov |
NDSS | 1 |
| 2014 | To Befriend Or Not? A Model of Friend Request Acceptance on Facebook
Hootan Rashtian, Yazan Boshmaf, Pooya Jaferian, Konstantin Beznosov |
SOUPS | 2 |
| 2013 | Graph-based Sybil detection in social and information systemsabstractSybil attacks in social and information systems have serious security implications. Out of many defence schemes, Graph-based Sybil Detection (GSD) had the greatest attention by both academia and industry. Even though many GSD algorithms exist, there is no analytical framework to reason about their design, especially as they make different assumptions about the used adversary and graph models. In this paper, we bridge this knowledge gap and present a unified framework for systematic evaluation of GSD algorithms. We used this framework to show that GSD algorithms should be designed to find local community structures around known non-Sybil identities, while incrementally tracking changes in the graph as it evolves over time. Yazan Boshmaf, Konstantin Beznosov, Matei Ripeanu |
ASONAM | 1 |
| 2013 | Know your enemy: the risk of unauthorized access in smartphones by insidersabstractSmartphones store large amounts of sensitive data, such as SMS messages, photos, or email. In this paper, we report the results of a study investigating users' concerns about unauthorized data access on their smartphones (22 interviewed and 724 surveyed subjects). We found that users are generally concerned about insiders (e.g., friends) accessing their data on smartphones. Furthermore, we present the first evidence that the insider threat is a real problem impacting smartphone users. In particular, 12% of subjects reported a negative experience with unauthorized access. We also found that younger users are at higher risk of experiencing unauthorized access. Based on our results, we propose a stronger adversarial model that incorporates the insider threat. To better reflect users' concerns and risks, a stronger adversarial model must be considered during the design and evaluation of data protection systems and authentication methods for smartphones. Ildar Muslukhov, Yazan Boshmaf, Cynthia Kuo, Jonathan Lester, Konstantin Beznosov |
Mobile HCI | 2 |
| 2013 | Design and analysis of a social botnet
Yazan Boshmaf, Ildar Muslukhov, Konstantin Beznosov, Matei Ripeanu |
Comput. Networks | 1 |
| 2013 | Adaptive Composition of Distributed Pervasive Applications in Heterogeneous EnvironmentsabstractComplex pervasive applications need to be distributed for two main reasons: due to the typical resource restrictions of mobile devices, and to use local services to interact with the immediate environment. To set up such an application, the distributed components require spontaneous composition. Since dynamics in the environment and device failures may imply the unavailability of components and devices at any time, finding, maintaining, and adapting such a composition is a nontrivial task. Moreover, the speed of such a configuration process directly influences the user since in the event of a configuration, the user has to wait. In this article, we introduce configuration algorithms for homogeneous and heterogeneous environments. We discuss a comprehensive approach to pervasive application configuration that adapts to the characteristics of the environment: It chooses the most efficient configuration method for the given environment to minimize the configuration latency. Moreover, we propose a new scheme for caching and reusing partial application configurations. This scheme reduces the configuration latency even further such that a configuration can be executed without notable disturbance of the user. Stephan Schuhmann, Klaus Herrmann 0001, Kurt Rothermel, Yazan Boshmaf |
ACM Trans. Auton. Adapt. Syst. | 4 |
| 2011 | The socialbot network: when bots socialize for fame and moneyabstractOnline Social Networks (OSNs) have become an integral part of today's Web. Politicians, celebrities, revolutionists, and others use OSNs as a podium to deliver their message to millions of active web users. Unfortunately, in the wrong hands, OSNs can be used to run astroturf campaigns to spread misinformation and propaganda. Such campaigns usually start off by infiltrating a targeted OSN on a large scale. In this paper, we evaluate how vulnerable OSNs are to a large-scale infiltration by socialbots: computer programs that control OSN accounts and mimic real users. We adopt a traditional web-based botnet design and built a Socialbot Network (SbN): a group of adaptive socialbots that are orchestrated in a command-and-control fashion. We operated such an SbN on Facebook---a 750 million user OSN---for about 8 weeks. We collected data related to users' behavior in response to a large-scale infiltration where socialbots were used to connect to a large number of Facebook users. Our results show that (1) OSNs, such as Facebook, can be infiltrated with a success rate of up to 80%, (2) depending on users' privacy settings, a successful infiltration can result in privacy breaches where even more users' data are exposed when compared to a purely public access, and (3) in practice, OSN security defenses, such as the Facebook Immune System, are not effective enough in detecting or stopping a large-scale infiltration as it occurs. Yazan Boshmaf, Ildar Muslukhov, Konstantin Beznosov, Matei Ripeanu |
ACSAC | 1 |
| 2010 | A billion keys, but few locks: the crisis of web single sign-onabstractOpenID and InfoCard are two mainstream Web single sign-on (SSO) solutions intended for Internet-scale adoption. While they are technically sound, the business model of these solutions does not provide content-hosting and service providers (CSPs) with sufficient incentives to become relying parties (RPs). In addition, the pressure from users and identity providers (IdPs) is not strong enough to drive CSPs toward adopting Web SSO. As a result, there are currently over one billion OpenID-enabled user accounts provided by major CSPs, but only a few relying parties.In this paper, we discuss the problem of Web SSO adoption for RPs and argue that solutions in this space must offer RPs sufficient business incentives and trustworthy identity services in order to succeed. We suggest future Web SSO development should investigate and fulfill RPs' business needs, identify IdP business models, and build trust frameworks. Moreover, we propose that Web SSO technology should build identity support into browsers in order to facilitate RPs' adoption. San-Tsai Sun, Yazan Boshmaf, Kirstie Hawkey, Konstantin Beznosov |
NSPW | 2 |
| 2009 | SIMD-Scan: Ultra Fast in-Memory Table Scan using on-Chip Vector Processing UnitsabstractThe availability of huge system memory, even on standard servers, generated a lot of interest in main memory database engines. In data warehouse systems, highly compressed column-oriented data structures are quite prominent. In order to scale with the data volume and the system load, many of these systems are highly distributed with a shared-nothing approach. The fundamental principle of all systems is a full table scan over one or multiple compressed columns. Recent research proposed different techniques to speedup table scans like intelligent compression or using an additional hardware such as graphic cards or FPGAs. In this paper, we show that utilizing the embedded Vector Processing Units (VPUs) found in standard superscalar processors can speed up the performance of mainmemory full table scan by factors. This is achieved without changing the hardware architecture and thereby without additional power consumption. Moreover, as on-chip VPUs directly access the system's RAM, no additional costly copy operations are needed for using the new SIMD-scan approach in standard main memory database engines. Therefore, we propose this scan approach to be used as the standard scan operator for compressed column-oriented main memory storage. We then discuss how well our solution scales with the number of processor cores; consequently, to what degree it can be applied in multi-threaded environments. To verify the feasibility of our approach, we implemented the proposed techniques on a modern Intel multi-core processor using Intel® Streaming SIMD Extensions (Intel® SSE). In addition, we integrated the new SIMD-scan approach into SAP® Netweaver® Business Warehouse Accelerator. We conclude with describing the performance benefits of using our approach for processing and scanning compressed data using VPUs in column-oriented main memory database systems. Thomas Willhalm, Nicolae Popovici, Yazan Boshmaf, Hasso Plattner, Alexander Zeier, Jan Schaffner |
Proc. VLDB Endow. | 3 |