Skip to main content
arXiv is now an independent nonprofit! Learn more

Showing 1–8 of 8 results for author: Farhang, S

Searching in archive cs. Search in all archives.
.
  1. arXiv:2410.01157  [pdf, other

    cs.LG

    A Deep Learning Approach for Imbalanced Tabular Data in Advertiser Prospecting: A Case of Direct Mail Prospecting

    Authors: Sadegh Farhang, William Hayes, Nick Murphy, Jonathan Neddenriep, Nicholas Tyris

    Abstract: Acquiring new customers is a vital process for growing businesses. Prospecting is the process of identifying and marketing to potential customers using methods ranging from online digital advertising, linear television, out of home, and direct mail. Despite the rapid growth in digital advertising (particularly social and search), research shows that direct mail remains one of the most effective wa… ▽ More

    Submitted 1 October, 2024; originally announced October 2024.

    Comments: Third KDD Workshop on End-to-End Customer Journey Optimization

  2. arXiv:2002.09629  [pdf, other

    cs.CR

    An Empirical Study of Android Security Bulletins in Different Vendors

    Authors: Sadegh Farhang, Mehmet Bahadir Kirdan, Aron Laszka, Jens Grossklags

    Abstract: Mobile devices encroach on almost every part of our lives, including work and leisure, and contain a wealth of personal and sensitive information. It is, therefore, imperative that these devices uphold high security standards. A key aspect is the security of the underlying operating system. In particular, Android plays a critical role due to being the most dominant platform in the mobile ecosystem… ▽ More

    Submitted 22 February, 2020; originally announced February 2020.

  3. arXiv:1905.09352  [pdf, other

    cs.CR

    Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities

    Authors: Sadegh Farhang, Mehmet Bahadir Kirdan, Aron Laszka, Jens Grossklags

    Abstract: In this paper, we perform a comprehensive study of 2,470 patched Android vulnerabilities that we collect from different data sources such as Android security bulletins, CVEDetails, Qualcomm Code Aurora, AOSP Git repository, and Linux Patchwork. In our data analysis, we focus on determining the affected layers, OS versions, severity levels, and common weakness enumerations (CWE) associated with the… ▽ More

    Submitted 22 May, 2019; originally announced May 2019.

    Comments: The 2019 Workshop on the Economics of Information Security (WEIS 2019)

  4. arXiv:1712.08222  [pdf, other

    cs.CR

    An Economic Study of the Effect of Android Platform Fragmentation on Security Updates

    Authors: Sadegh Farhang, Aron Laszka, Jens Grossklags

    Abstract: Vendors in the Android ecosystem typically customize their devices by modifying Android Open Source Project (AOSP) code, adding in-house developed proprietary software, and pre-installing third-party applications. However, research has documented how various security problems are associated with this customization process. We develop a model of the Android ecosystem utilizing the concepts of gam… ▽ More

    Submitted 21 December, 2017; originally announced December 2017.

    Comments: 22nd International Conference on Financial Cryptography and Data Security (FC 2018)

  5. arXiv:1709.04030  [pdf, other

    cs.CR cs.GT

    Enemy At the Gateways: A Game Theoretic Approach to Proxy Distribution

    Authors: Milad Nasr, Sadegh Farhang, Amir Houmansadr, Jens Grossklags

    Abstract: A core technique used by popular proxy-based circumvention systems like Tor, Psiphon, and Lantern is to secretly share the IP addresses of circumvention proxies with the censored clients for them to be able to use such systems. For instance, such secretly shared proxies are known as bridges in Tor. However, a key challenge to this mechanism is the insider attack problem: censoring agents can imper… ▽ More

    Submitted 12 September, 2017; originally announced September 2017.

  6. arXiv:1707.06247  [pdf, ps, other

    cs.CR

    On the Economics of Ransomware

    Authors: Aron Laszka, Sadegh Farhang, Jens Grossklags

    Abstract: While recognized as a theoretical and practical concept for over 20 years, only now ransomware has taken centerstage as one of the most prevalent cybercrimes. Various reports demonstrate the enormous burden placed on companies, which have to grapple with the ongoing attack waves. At the same time, our strategic understanding of the threat and the adversarial interaction between organizations and c… ▽ More

    Submitted 21 August, 2017; v1 submitted 19 July, 2017; originally announced July 2017.

    Comments: 8th Conference on Decision and Game Theory for Security (GameSec 2017)

  7. arXiv:1706.00302  [pdf, other

    cs.CR

    When to Invest in Security? Empirical Evidence and a Game-Theoretic Approach for Time-Based Security

    Authors: Sadegh Farhang, Jens Grossklags

    Abstract: Games of timing aim to determine the optimal defense against a strategic attacker who has the technical capability to breach a system in a stealthy fashion. Key questions arising are when the attack takes place, and when a defensive move should be initiated to reset the system resource to a known safe state. In our work, we study a more complex scenario called Time-Based Security in which we com… ▽ More

    Submitted 6 June, 2017; v1 submitted 1 June, 2017; originally announced June 2017.

    Comments: Workshop on the Economics of Information Security (WEIS 2017)

  8. Flip the Cloud: Cyber-Physical Signaling Games in the Presence of Advanced Persistent Threats

    Authors: Jeffrey Pawlick, Sadegh Farhang, Quanyan Zhu

    Abstract: Access to the cloud has the potential to provide scalable and cost effective enhancements of physical devices through the use of advanced computational processes run on apparently limitless cyber infrastructure. On the other hand, cyber-physical systems and cloud-controlled devices are subject to numerous design challenges; among them is that of security. In particular, recent advances in adversar… ▽ More

    Submitted 14 September, 2015; v1 submitted 2 July, 2015; originally announced July 2015.

    Comments: To be presented at the 2015 Conference on Decision and Game Theory for Security (GameSec 2015)