I lead research at Socket and am an Associate Professor of Computer Science at North Carolina State University. I'm also a member of the Wolfpack Security and Privacy Research (WSPR) Lab and the faculty mentor of HackPack. Together with The Order of the Overflow team we organized DEF CON CTF during 2018-2021.
Research Interests
My research interests span the areas of web security & privacy, software supply chain security, and AI security. I am in particular interested in the security and privacy problems that arise from the evolution of the web, the software supply chain and the latest advancements in AI.
News
- SecWeb 2024 Keynote
- NDSS 2024 Distinguished Paper Award
- NSF Frontier proposal funded
- IEEE S&P 2021 Best Student Paper Award
Publications
- COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis
Greg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, William Enck
Proceedings of the IEEE Symposium on Security and Privacy, 2026
[PDF] [DOI]@inproceedings{cosseter-sp26, title = {{COSSETER: GitHub Actions Permission Reduction Using Demand-Driven Static Analysis}}, author = {Tystahl, Greg and Ghebremichael, Jonah and Muralee, Siddharth and Cherupattamoolayil, Sourag and Bianchi, Antonio and Machiry, Aravind and Kapravelos, Alexandros and Enck, William}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, month = may, pages = {2628--2645}, doi = {10.1109/SP63933.2026.00067}, year = {2026} } - Towards Verifiably Safe Tool Use for LLM Agents
Aarya Doshi, Yining Hong, Congying Xu, Eunsuk Kang, Alexandros Kapravelos, Christian Kästner
Proceedings of the IEEE/ACM International Conference on Software Engineering, New Ideas and Emerging Results (ICSE-NIER), 2026
[PDF] [DOI]@inproceedings{safetooluse-icse26, title = {{Towards Verifiably Safe Tool Use for LLM Agents}}, author = {Doshi, Aarya and Hong, Yining and Xu, Congying and Kang, Eunsuk and Kapravelos, Alexandros and K{ä}stner, Christian}, booktitle = {{Proceedings of the IEEE/ACM International Conference on Software Engineering, New Ideas and Emerging Results (ICSE-NIER)}}, month = apr, pages = {201--205}, doi = {10.1145/3786582.3786839}, year = {2026} } - Six Million (Suspected) Fake Stars on GitHub: A Growing Spiral of Popularity Contests, Spam, and Malware
Hao He, Haoqin Yang, Philipp Burckhardt, Alexandros Kapravelos, Bogdan Vasilescu, Christian Kästner
Proceedings of the International Conference on Software Engineering (ICSE), 2026
[PDF] [code]@inproceedings{fakestars-icse26, title = {{Six Million (Suspected) Fake Stars on GitHub: A Growing Spiral of Popularity Contests, Spam, and Malware}}, author = {He, Hao and Yang, Haoqin and Burckhardt, Philipp and Kapravelos, Alexandros and Vasilescu, Bogdan and K{ä}stner, Christian}, booktitle = {{Proceedings of the International Conference on Software Engineering (ICSE)}}, code = {{https://github.com/hehao98/StarScout}}, month = apr, year = {2026} } - Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViews
Sohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su, Anupam Das, Jason Polakis, Alexandros Kapravelos
Proceedings of the Network and Distributed System Security Symposium (NDSS), 2026
[PDF] [code]@inproceedings{vv8webview-ndss26, title = {{Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViews}}, author = {Datta, Sohom and Diamantaris, Michalis and Zafar, Ahsan and Su, Junhua and Das, Anupam and Polakis, Jason and Kapravelos, Alexandros}, booktitle = {{Proceedings of the Network and Distributed System Security Symposium (NDSS)}}, month = feb, code = {{https://github.com/wspr-ncsu/webviewtracer}}, tag = {vv8}, year = {2026} } - Same Script, Different Behavior: Characterizing Divergent JavaScript Execution Across Different Device Platforms
Ahsan Zafar, Junhua Su, Sohom Datta, Alexandros Kapravelos, Anupam Das
Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2025
[PDF] [DOI]@inproceedings{vv8diverge-ccs25, title = {{Same Script, Different Behavior: Characterizing Divergent JavaScript Execution Across Different Device Platforms}}, author = {Zafar, Ahsan and Su, Junhua and Datta, Sohom and Kapravelos, Alexandros and Das, Anupam}, booktitle = {{Proceedings of the ACM Conference on Computer and Communications Security (CCS)}}, month = oct, pages = {1889--1903}, doi = {10.1145/3719027.3765202}, tag = {vv8}, year = {2025} } - Research Directions in Software Supply Chain Security
Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, William Enck
ACM Transactions on Software Engineering and Methodology, 2025
[PDF] [DOI]@article{tosem-directions, author = {Williams, Laurie and Benedetti, Giacomo and Hamer, Sivana and Paramitha, Ranindya and Rahman, Imranur and Tamanna, Mahzabin and Tystahl, Greg and Zahan, Nusrat and Morrison, Patrick and Acar, Yasemin and Cukier, Michel and K\"{a}stner, Christian and Kapravelos, Alexandros and Wermke, Dominik and Enck, William}, title = {Research Directions in Software Supply Chain Security}, journal = {{ACM} Transactions on Software Engineering and Methodology}, volume = {34}, number = {5}, pages = {146:1--146:38}, month = may, doi = {10.1145/3714464}, year = {2025} } - An Empirical Study on Reproducible Packaging in Open-Source Ecosystems
Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, Luca Verderame
Proceedings of the International Conference on Software Engineering (ICSE), 2025
[PDF] [DOI]@inproceedings{repro-icse25, title = {{An Empirical Study on Reproducible Packaging in Open-Source Ecosystems}}, author = {Benedetti, Giacomo and Solarin, Oreofe and Miller, Courtney and Tystahl, Greg and Enck, William and K{ä}stner, Christian and Kapravelos, Alexandros and Merlo, Alessio and Verderame, Luca}, booktitle = {{Proceedings of the International Conference on Software Engineering (ICSE)}}, month = apr, pages = {1052--1063}, doi = {10.1109/ICSE55347.2025.00136}, year = {2025} } - JSHint: Revealing API Usage to Improve Detection of Malicious JavaScript
Shaown Sarker, Kasimir Schulz, Aleksandr Nahapetyan, Anupam Das, Alexandros Kapravelos
Proceedings of the Information Security Conference (ISC), 2024
[PDF] [DOI]@inproceedings{jshint-isc24, title = {{JSHint: Revealing API Usage to Improve Detection of Malicious JavaScript}}, author = {Sarker, Shaown and Schulz, Kasimir and Nahapetyan, Aleksandr and Das, Anupam and Kapravelos, Alexandros}, booktitle = {{Proceedings of the Information Security Conference (ISC)}}, month = oct, pages = {205--225}, doi = {10.1007/978-3-031-75764-8_11}, year = {2024} } - Automated Generation of Behavioral Signatures for Malicious Web Campaigns
Shaown Sarker, William Melicher, Oleksii Starov, Anupam Das, Alexandros Kapravelos
Proceedings of the Information Security Conference (ISC), 2024
[PDF] [DOI]@inproceedings{webehavior-isc24, title = {{Automated Generation of Behavioral Signatures for Malicious Web Campaigns}}, author = {Sarker, Shaown and Melicher, William and Starov, Oleksii and Das, Anupam and Kapravelos, Alexandros}, booktitle = {{Proceedings of the Information Security Conference (ISC)}}, month = oct, pages = {226--245}, doi = {10.1007/978-3-031-75764-8_12}, year = {2024} } - FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
Nikolaos Pantelaios, Alexandros Kapravelos
Proceedings of the USENIX Security Symposium, 2024
[PDF] [code]@inproceedings{fv8-sec24, title = {{FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques}}, author = {Pantelaios, Nikolaos and Kapravelos, Alexandros}, booktitle = {{Proceedings of the USENIX Security Symposium}}, code = {{https://github.com/wspr-ncsu/FV8}}, month = aug, pages = {3747--3764}, tag = {vv8}, year = {2024} } - On SMS Phishing Tactics and Infrastructure
Aleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest, Yeganeh Ladwig, Alexandros Kapravelos, Brad Reaves
Proceedings of the IEEE Symposium on Security and Privacy, 2024
[PDF] [DOI]@inproceedings{smsphishing-sp24, title = {{On SMS Phishing Tactics and Infrastructure}}, author = {Nahapetyan, Aleksandr and Prasad, Sathvik and Childs, Kevin and Oest, Adam and Ladwig, Yeganeh and Kapravelos, Alexandros and Reaves, Brad}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, month = may, pages = {1--16}, doi = {10.1109/SP54263.2024.00169}, year = {2024} } - UntrustIDE: Exploiting Weaknesses in VS Code Extensions
Elizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck, Alexandros Kapravelos
Proceedings of the Network and Distributed System Security Symposium (NDSS), 2024
Distinguished Paper Award
[PDF]@inproceedings{untrustide-ndss24, title = {{UntrustIDE: Exploiting Weaknesses in VS Code Extensions}}, author = {Lin, Elizabeth and Koishybayev, Igibek and Dunlap, Trevor and Enck, William and Kapravelos, Alexandros}, booktitle = {{Proceedings of the Network and Distributed System Security Symposium (NDSS)}}, note = {Distinguished Paper Award}, month = feb, year = {2024} } - WRIT: Web Request Integrity and Attestation Against Malicious Browser Extensions
Giorgos Vasiliadis, Apostolos Karampelas, Alexandros Shevtsov, Panagiotis Papadopoulos, Sotiris Ioannidis, Alexandros Kapravelos
IEEE Transactions on Dependable and Secure Computing, 2024
[PDF] [DOI]@article{writ-tdsc24, title = {{WRIT: Web Request Integrity and Attestation Against Malicious Browser Extensions}}, author = {Vasiliadis, Giorgos and Karampelas, Apostolos and Shevtsov, Alexandros and Papadopoulos, Panagiotis and Ioannidis, Sotiris and Kapravelos, Alexandros}, journal = {{IEEE Transactions on Dependable and Secure Computing}}, volume = {21}, number = {4}, pages = {3082--3095}, doi = {10.1109/TDSC.2023.3322516}, year = {2024} } - ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions
Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Brad Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, Aravind Machiry
Proceedings of the USENIX Security Symposium, 2023
CSAW 2023 Applied Research Finalist
[PDF] [website] [code] [news]@inproceedings{githubreactions-usenixsec23, title = {{ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions}}, author = {Muralee, Siddharth and Koishybayev, Igibek and Nahapetyan, Aleksandr and Tystahl, Greg and Reaves, Brad and Bianchi, Antonio and Enck, William and Kapravelos, Alexandros and Machiry, Aravind}, booktitle = {{Proceedings of the USENIX Security Symposium}}, month = aug, code = {{https://github.com/purs3lab/ARGUS}}, howpublished = {/projects/argus/}, pages = {6983--7000}, note = {{CSAW 2023 Applied Research Finalist}}, news = {{https://github.blog/2023-08-09-four-tips-to-keep-your-github-actions-workflows-secure/}}, tag = {githubreactions}, year = {2023} } - Automatic Discovery of Emerging Browser Fingerprinting Techniques
Junhua Su, Alexandros Kapravelos
Proceedings of The Web Conference (WWW), 2023
[PDF] [code]@inproceedings{fptechniques-www23, title = {{Automatic Discovery of Emerging Browser Fingerprinting Techniques}}, author = {Su, Junhua and Kapravelos, Alexandros}, booktitle = {{Proceedings of The Web Conference (WWW)}}, month = apr, code = {{https://github.com/wspr-ncsu/BrowserFingerprintingAD}}, pages = {2178--2188}, tag = {vv8}, year = {2023} } - Characterizing the Security of Github CI Workflows
Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Brad Reaves, Alexandros Kapravelos, Aravind Machiry
Proceedings of the USENIX Security Symposium, 2022
[PDF] [website] [code]@inproceedings{githubactions-usenixsec22, title = {{Characterizing the Security of Github CI Workflows}}, author = {Koishybayev, Igibek and Nahapetyan, Aleksandr and Zachariah, Raima and Muralee, Siddharth and Reaves, Brad and Kapravelos, Alexandros and Machiry, Aravind}, booktitle = {{Proceedings of the USENIX Security Symposium}}, month = aug, tag = {githubactions}, code = {{https://github.com/wspr-ncsu/github-actions-security-analysis}}, howpublished = {/projects/githubactions/}, pages = {2747--2763}, year = {2022} } - yoU aRe a Liar://A Unified Framework for Cross-Testing URL Parsers
Dashmeet Kaur Ajmani, Igibek Koishybayev, Alexandros Kapravelos
Proceedings of the IEEE SecWeb Workshop, 2022
[PDF]@inproceedings{youarealiar-secweb22, title = {{yoU aRe a Liar://A Unified Framework for Cross-Testing URL Parsers}}, author = {Ajmani, Dashmeet Kaur and Koishybayev, Igibek and Kapravelos, Alexandros}, booktitle = {{Proceedings of the IEEE SecWeb Workshop}}, pages = {51-58}, month = jun, year = {2022} } - SoK: Workerounds - Categorizing Service Worker Attacks and Mitigations
Karthika Subramani, Jordan Jueckstock, Alexandros Kapravelos, Roberto Perdisci
Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), 2022
[PDF]@inproceedings{workerounds-eurosp22, title = {{SoK: Workerounds - Categorizing Service Worker Attacks and Mitigations}}, author = {Subramani, Karthika and Jueckstock, Jordan and Kapravelos, Alexandros and Perdisci, Roberto}, booktitle = {{Proceedings of the IEEE European Symposium on Security and Privacy (EuroS\&P)}}, month = jun, pages = {555-571}, year = {2022} } - Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking
Jordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos, Ben Livshits
Proceedings of The Web Conference (WWW), 2022
[PDF]@inproceedings{ephemeralstorage-www22, title = {{Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking}}, author = {Jueckstock, Jordan and Snyder, Peter and Sarker, Shaown and Kapravelos, Alexandros and Livshits, Ben}, booktitle = {{Proceedings of The Web Conference (WWW)}}, month = apr, pages = {710–720}, year = {2022} } - Browserprint: An Analysis of the Impact of Browser Features on Fingerprintability and Web Privacy
Seyed Ali Akhavani, Jordan Jueckstock, Junhua Su, Alexandros Kapravelos, Engin Kirda, Long Lu
Proceedings of the Information Security Conference (ISC), 2021
[PDF]@inproceedings{browserprint-isc21, title = {{Browserprint: An Analysis of the Impact of Browser Features on Fingerprintability and Web Privacy}}, author = {Akhavani, Seyed Ali and Jueckstock, Jordan and Su, Junhua and Kapravelos, Alexandros and Kirda, Engin and Lu, Long}, booktitle = {{Proceedings of the Information Security Conference (ISC)}}, pages = {161--176}, month = nov, tag = {vv8}, year = {2021} } - Fingerprinting in Style: Detecting Browser Extensions via Injected Style Sheets
Pierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos, Nick Nikiforakis
Proceedings of the USENIX Security Symposium, 2021
[PDF] [code]@inproceedings{css-fp-usenixsec21, title = {{Fingerprinting in Style: Detecting Browser Extensions via Injected Style Sheets}}, author = {Laperdrix, Pierre and Starov, Oleksii and Chen, Quan and Kapravelos, Alexandros and Nikiforakis, Nick}, booktitle = {{Proceedings of the USENIX Security Symposium}}, code = {https://github.com/plaperdr/fingerprinting-in-style}, month = aug, pages = {2507--2524}, year = {2021} } - Detecting Filter List Evasion With Event-Loop-Turn Granularity JavaScript Signatures
Quan Chen, Peter Snyder, Ben Livshits, Alexandros Kapravelos
Proceedings of the IEEE Symposium on Security and Privacy, 2021
[PDF] [code]@inproceedings{pg-sigs-sp20, title = {{Detecting Filter List Evasion With Event-Loop-Turn Granularity JavaScript Signatures}}, author = {Chen, Quan and Snyder, Peter and Livshits, Ben and Kapravelos, Alexandros}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, code = {{https://github.com/semantic-signatures/semantic-signatures}}, month = may, pages = {1715-1729}, year = {2021} } - CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing
Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doupe, Gail-Joon Ahn
Proceedings of the IEEE Symposium on Security and Privacy, 2021
Best Student Paper Award
[PDF]@inproceedings{crawlphish-sp21, title = {{CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing}}, author = {Zhang, Penghui and Oest, Adam and Cho, Haehyun and Sun, Zhibo and Johnson, RC and Wardman, Brad and Sarker, Shaown and Kapravelos, Alexandros and Bao, Tiffany and Wang, Ruoyu and Shoshitaishvili, Yan and Doupe, Adam and Ahn, Gail-Joon}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, note = {Best Student Paper Award}, month = may, pages = {1109-1124}, year = {2021} } - Towards Realistic and Reproducible Web Crawl Measurements
Jordan Jueckstock, Shaown Sarker, Peter Snyder, Aidan Beggs, Panagiotis Papadopoulos, Matteo Varvello, Ben Livshits, Alexandros Kapravelos
Proceedings of The Web Conference (WWW), 2021
[PDF] [code]@inproceedings{vpc-www21, title = {{Towards Realistic and Reproducible Web Crawl Measurements}}, author = {Jueckstock, Jordan and Sarker, Shaown and Snyder, Peter and Beggs, Aidan and Papadopoulos, Panagiotis and Varvello, Matteo and Livshits, Ben and Kapravelos, Alexandros}, booktitle = {{Proceedings of The Web Conference (WWW)}}, code = {{https://github.com/wspr-ncsu/reprocrawl-code-release}}, pages = {80–91}, numpages = {13}, month = apr, tag = {vv8}, year = {2021} } - Favocado: Fuzzing Binding Code of JavaScript Engines Using Semantically Correct Test Cases
Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Yihui Zeng, Alexandros Kapravelos, Tiffany Bao, Ruoyu "Fish" Wang, Yan Shoshitaishvili, Adam Doupe, Gail-Joon Ahn
Proceedings of the Network and Distributed System Security Symposium (NDSS), 2021
[PDF]@inproceedings{favocado-ndss21, title = {{Favocado: Fuzzing Binding Code of JavaScript Engines Using Semantically Correct Test Cases}}, author = {Dinh, Sung Ta and Cho, Haehyun and Martin, Kyle and Oest, Adam and Zeng, Yihui and Kapravelos, Alexandros and Bao, Tiffany and Wang, Ruoyu "Fish" and Shoshitaishvili, Yan and Doupe, Adam and Ahn, Gail-Joon}, booktitle = {{Proceedings of the Network and Distributed System Security Symposium (NDSS)}}, month = feb, year = {2021} } - You’ve Changed: Detecting Malicious Browser Extensions through their Update Deltas
Nikolaos Pantelaios, Nick Nikiforakis, Alexandros Kapravelos
Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2020
[PDF] [code]@inproceedings{extensiondeltas-CCS20, title = {{You've Changed: Detecting Malicious Browser Extensions through their Update Deltas}}, author = {Pantelaios, Nikolaos and Nikiforakis, Nick and Kapravelos, Alexandros}, booktitle = {{Proceedings of the ACM Conference on Computer and Communications Security (CCS)}}, code = {https://github.com/wspr-ncsu/extensiondeltas}, month = nov, pages = {477–491}, year = {2020} } - Hiding in Plain Site: Detecting JavaScript Obfuscation through Concealed Browser API Usage
Shaown Sarker, Jordan Jueckstock, Alexandros Kapravelos
Proceedings of the ACM Internet Measurement Conference (IMC), 2020
[PDF]@inproceedings{jsobf-imc20, title = {{Hiding in Plain Site: Detecting JavaScript Obfuscation through Concealed Browser API Usage}}, author = {Sarker, Shaown and Jueckstock, Jordan and Kapravelos, Alexandros}, booktitle = {{Proceedings of the ACM Internet Measurement Conference (IMC)}}, pages = {648–661}, month = oct, tag = {vv8}, year = {2020} } - Mininode: Reducing the Attack Surface of Node.js Applications
Igibek Koishybayev, Alexandros Kapravelos
Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 2020
[PDF] [website]@inproceedings{mininode-raid20, title = {{Mininode: Reducing the Attack Surface of Node.js Applications}}, author = {Koishybayev, Igibek and Kapravelos, Alexandros}, booktitle = {{Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID)}}, month = oct, howpublished = {/projects/mininode/}, tag = {mininode}, pages = {121--134}, year = {2020} } - VisibleV8: In-browser Monitoring of JavaScript in the Wild
Jordan Jueckstock, Alexandros Kapravelos
Proceedings of the ACM Internet Measurement Conference (IMC), 2019
[PDF] [website] [slides] [talk] [code]@inproceedings{vv8-imc19, title = {{VisibleV8: In-browser Monitoring of JavaScript in the Wild}}, author = {Jueckstock, Jordan and Kapravelos, Alexandros}, booktitle = {{Proceedings of the ACM Internet Measurement Conference (IMC)}}, pages = {393–405}, month = oct, howpublished = {/projects/vv8/}, code = {{https://github.com/wspr-ncsu/visiblev8}}, slides = {/presentations/vv8-imc19.pdf}, talk = {https://vimeo.com/showcase/6531379/video/369121825#t=3500s}, tag = {vv8}, year = {2019} } - Everyone is Different: Client-side Diversification for Defending Against Extension Fingerprinting
Erik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis, Adam Doupe
Proceedings of the USENIX Security Symposium, 2019
[PDF] [code]@inproceedings{cloakx-sec19, title = {{Everyone is Different: Client-side Diversification for Defending Against Extension Fingerprinting}}, author = {Trickel, Erik and Starov, Oleksii and Kapravelos, Alexandros and Nikiforakis, Nick and Doupe, Adam}, booktitle = {{Proceedings of the USENIX Security Symposium}}, code = {https://github.com/sefcom/cloakx}, month = aug, pages = {1679--1696}, year = {2019} } - Wild Extensions: Discovering and Analyzing Unlisted Chrome Extensions
Aidan Beggs, Alexandros Kapravelos
Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2019
[PDF]@inproceedings{wildextensions-dimva19, title = {{Wild Extensions: Discovering and Analyzing Unlisted Chrome Extensions}}, author = {Beggs, Aidan and Kapravelos, Alexandros}, booktitle = {{Proceedings of the Conference on Detection of Intrusions and Malware \& Vulnerability Assessment (DIMVA)}}, month = jun, pages = {3--22}, year = {2019} } - Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloat
Oleksii Starov, Pierre Laperdrix, Alexandros Kapravelos, Nick Nikiforakis
Proceedings of the World Wide Web Conference (WWW), 2019
[PDF]@inproceedings{extbloat-www2019, title = {{Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloat}}, author = {Starov, Oleksii and Laperdrix, Pierre and Kapravelos, Alexandros and Nikiforakis, Nick}, booktitle = {{Proceedings of the World Wide Web Conference (WWW)}}, month = may, pages = {3244–3250}, year = {2019} } - Mystique: Uncovering Information Leakage from Browser Extensions
Quan Chen, Alexandros Kapravelos
Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2018
[PDF] [website] [code]@inproceedings{mystique-CCS18, title = {Mystique: Uncovering Information Leakage from Browser Extensions}, author = {Chen, Quan and Kapravelos, Alexandros}, booktitle = {{Proceedings of the ACM Conference on Computer and Communications Security (CCS)}}, howpublished = {https://mystique.csc.ncsu.edu/}, code = {https://github.com/wspr-ncsu/mystique}, month = oct, pages = {1687–1700}, year = {2018} } - Cloak of Visibility: Detecting When Machines Browse A Different Web
Luca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu, Jean-Michel Picod, Elie Bursztein
Proceedings of the IEEE Symposium on Security and Privacy, 2016
[PDF]@inproceedings{cloaking-SP16, title = {{Cloak of Visibility: Detecting When Machines Browse A Different Web}}, author = {Invernizzi, Luca and Thomas, Kurt and Kapravelos, Alexandros and Comanescu, Oxana and Picod, Jean-Michel and Bursztein, Elie}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, month = may, pages = {743-758}, year = {2016} } - Ad Injection at Scale: Assessing Deceptive Advertisement Modifications
Kurt Thomas, Elie Bursztein, Chris Grier, Grant Go, Nav Jagpal, Alexandros Kapravelos, Damon Mccoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab
Proceedings of the IEEE Symposium on Security and Privacy, 2015
Distinguished Practical Paper Award
[PDF]@inproceedings{adinjection-SP15, title = {{Ad Injection at Scale: Assessing Deceptive Advertisement Modifications}}, author = {Thomas, Kurt and Bursztein, Elie and Grier, Chris and Go, Grant and Jagpal, Nav and Kapravelos, Alexandros and Mccoy, Damon and Nappa, Antonio and Paxson, Vern and Pearce, Paul and Provos, Niels and Abu Rajab, Moheeb}, booktitle = {{Proceedings of the IEEE Symposium on Security and Privacy}}, note = {Distinguished Practical Paper Award}, month = may, year = {2015} } - The Dark Alleys of Madison Avenue: Understanding Malicious Advertisements
Apostolis Zarras, Alexandros Kapravelos, Gianluca Stringhini, Thorsten Holz, Chris Kruegel, Giovanni Vigna
Proceedings of the Internet Measurement Conference (IMC), 2014
[PDF]@inproceedings{malvertisments-IMC14, title = {{The Dark Alleys of Madison Avenue: Understanding Malicious Advertisements}}, author = {Zarras, Apostolis and Kapravelos, Alexandros and Stringhini, Gianluca and Holz, Thorsten and Kruegel, Chris and Vigna, Giovanni}, booktitle = {{Proceedings of the Internet Measurement Conference (IMC)}}, month = nov, year = {2014} } - Hulk: Eliciting Malicious Behavior in Browser Extensions
Alexandros Kapravelos, Chris Grier, Neha Chachra, Chris Kruegel, Giovanni Vigna, Vern Paxson
Proceedings of the USENIX Security Symposium, 2014
[PDF]@inproceedings{hulk-UsenixSec14, title = {{Hulk: Eliciting Malicious Behavior in Browser Extensions}}, author = {Kapravelos, Alexandros and Grier, Chris and Chachra, Neha and Kruegel, Chris and Vigna, Giovanni and Paxson, Vern}, booktitle = {{Proceedings of the USENIX Security Symposium}}, month = aug, year = {2014}, organization = {USENIX} } - PExy: The other side of Exploit Kits
Giancarlo De Maio, Alexandros Kapravelos, Yan Shoshitaishvili, Chris Kruegel, Giovanni Vigna
Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2014
[PDF]@inproceedings{pexy-DIMVA14, title = {{PExy: The other side of Exploit Kits}}, author = {De Maio, Giancarlo and Kapravelos, Alexandros and Shoshitaishvili, Yan and Kruegel, Chris and Vigna, Giovanni}, booktitle = {{Proceedings of the Conference on Detection of Intrusions and Malware \& Vulnerability Assessment (DIMVA)}}, month = jul, year = {2014} } - Revolver: An Automated Approach to the Detection of Evasive Web-based Malware
Alexandros Kapravelos, Yan Shoshitaishvili, Marco Cova, Chris Kruegel, Giovanni Vigna
Proceedings of the USENIX Security Symposium, 2013
[PDF]@inproceedings{revolver-UsenixSec13, title = {{Revolver: An Automated Approach to the Detection of Evasive Web-based Malware}}, author = {Kapravelos, Alexandros and Shoshitaishvili, Yan and Cova, Marco and Kruegel, Chris and Vigna, Giovanni}, booktitle = {{Proceedings of the USENIX Security Symposium}}, month = aug, year = {2013} } - You Are What You Include: Large-scale Evaluation of Remote JavaScript Inclusions
Nick Nikiforakis, Luca Invernizzi, Alexandros Kapravelos, Steven Van Acker, Wouter Joosen, Chris Kruegel, Frank Piessens, Giovanni Vigna
Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2012
[PDF]@inproceedings{jsinclusions-CCS12, title = {You Are What You Include: Large-scale Evaluation of Remote JavaScript Inclusions}, author = {Nikiforakis, Nick and Invernizzi, Luca and Kapravelos, Alexandros and Van Acker, Steven and Joosen, Wouter and Kruegel, Chris and Piessens, Frank and Vigna, Giovanni}, booktitle = {{Proceedings of the ACM Conference on Computer and Communications Security (CCS)}}, month = oct, year = {2012} } - Escape from Monkey Island: Evading High-Interaction Honeyclients
Alexandros Kapravelos, Marco Cova, Chris Kruegel, Giovanni Vigna
Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2011
[PDF]@inproceedings{monkeyisland-DIMVA11, title = {{Escape from Monkey Island: Evading High-Interaction Honeyclients}}, author = {Kapravelos, Alexandros and Cova, Marco and Kruegel, Chris and Vigna, Giovanni}, booktitle = {{Proceedings of the Conference on Detection of Intrusions and Malware \& Vulnerability Assessment (DIMVA)}}, month = jul, year = {2011} } - D(e|i)aling with VoIP: Robust Prevention of Dial Attacks
Alexandros Kapravelos, Jason Polakis, Elias Athanasopoulos, Sotiris Ioannidis, Evangelos P. Markatos
Proceedings of the European Symposium on Research in Computer Security (ESORICS), 2010
[PDF]@inproceedings{dial-esorics10, title = {{D(e$\mid$i)aling with VoIP: Robust Prevention of Dial Attacks}}, author = {Kapravelos, Alexandros and Polakis, Jason and Athanasopoulos, Elias and Ioannidis, Sotiris and Markatos, Evangelos P.}, booktitle = {{Proceedings of the European Symposium on Research in Computer Security (ESORICS)}}, month = sep, year = {2010} } - FleXConf: A Flexible Conference Assistant Using Context-Aware Notification Services
Nikos Armenatzoglou, Yannis Marketakis, Lito Kriara, Elias Apostolopoulos, Vicky Papavasiliou, Dimitris Kampas, Alexandros Kapravelos, Eythimis Kartsonakis, Giorgos Linardakis, Sofia Nikitaki, Antonis Bikakis, Grigoris Antoniou
Proceedings of the IEEE Workshop on Context Aware Mobile Systems (CAMS), 2009
[PDF]@inproceedings{flexconf, author = {Armenatzoglou, Nikos and Marketakis, Yannis and Kriara, Lito and Apostolopoulos, Elias and Papavasiliou, Vicky and Kampas, Dimitris and Kapravelos, Alexandros and Kartsonakis, Eythimis and Linardakis, Giorgos and Nikitaki, Sofia and Bikakis, Antonis and Antoniou, Grigoris}, title = {FleXConf: A Flexible Conference Assistant Using Context-Aware Notification Services}, booktitle = {Proceedings of the IEEE Workshop on Context Aware Mobile Systems (CAMS)}, month = oct, year = {2009} } - Realistic Passive Packet Loss Measurement for High-Speed Networks
Ales Friedl, Sven Ubik, Alexandros Kapravelos, Michalis Polychronakis, Evangelos P. Markatos
Proceedings of the International Workshop on Traffic Monitoring and Analysis (TMA), 2009
[PDF]@inproceedings{packetloss-TMA09, title = {{Realistic Passive Packet Loss Measurement for High-Speed Networks}}, author = {Friedl, Ales and Ubik, Sven and Kapravelos, Alexandros and Polychronakis, Michalis and Markatos, Evangelos P.}, booktitle = {{Proceedings of the International Workshop on Traffic Monitoring and Analysis (TMA)}}, month = apr, year = {2009} } - Passive end-to-end packet loss estimation for grid traffic monitoring
Antonis Papadogiannakis, Alexandros Kapravelos, Michalis Polychronakis, Evangelos P. Markatos, Augusto Ciuffoletti
Proceedings of the CoreGRID Integration Workshop, 2006
[PDF]@inproceedings{lossestimation-coregrid06, title = {{Passive end-to-end packet loss estimation for grid traffic monitoring}}, author = {Papadogiannakis, Antonis and Kapravelos, Alexandros and Polychronakis, Michalis and Markatos, Evangelos P. and Ciuffoletti, Augusto}, booktitle = {{Proceedings of the CoreGRID Integration Workshop}}, month = nov, year = {2006} }
Contact
Alexandros KapravelosOffice: 2240K Engineering Building II
Address: 890 Oval Dr., Raleigh, NC 27695-8206, USA
Email: akaprav at ncsu.edu