activity
20182020
most citedHotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

15 citations · 20 across the 3 of their papers we have counts for

collaborators

6 papers

cs.CR202015 cited

HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

William Blair, Andrea Mambretti, Sajjad Arshad +4

Contemporary fuzz testing techniques focus on identifying memory corruption vulnerabilities that allow adversaries to achieve either remote code execution or information disclosure…

cs.CR20194 cited

Cached and Confused: Web Cache Deception in the Wild

Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu +3

Web cache deception (WCD) is an attack proposed in 2017, where an attacker tricks a caching proxy into erroneously storing private information transmitted over the Internet and sub…

cs.CR2019

KRATOS: Multi-User Multi-Device-Aware Access Control System for the Smart Home

Amit Kumar Sikder, Leonardo Babun, Z. Berkay Celik +5

In a smart home system, multiple users have access to multiple devices, typically through a dedicated app installed on a mobile device. Traditional access control mechanisms consid…

cs.CR20191 cited

An Analysis of Malware Trends in Enterprise Networks

Abbas Acar, Long Lu, A. Selcuk Uluagac +1

We present an empirical and large-scale analysis of malware samples captured from two different enterprises from 2017 to early 2018. Particularly, we perform threat vector, social-…

cs.CR2018

Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the Web

Tobias Lauinger, Abdelberi Chaabane, Sajjad Arshad +3

Web developers routinely rely on third-party Java-Script libraries such as jQuery to enhance the functionality of their sites. However, if not properly maintained, such dependencie…

cs.CR2018

Large-Scale Analysis of Style Injection by Relative Path Overwrite

Sajjad Arshad, Seyed Ali Mirheidari, Tobias Lauinger +3

Relative Path Overwrite (RPO) is a recent technique to inject style directives into sites even when no style sink or markup injection vulnerability is present. It exploits differen…