About

My name is Nick Nikiforakis and I am a PhD candidate at the KU Leuven university in Belgium, under the supervision of Prof. Wouter Joosen and Prof. Frank Piessens. While I am interested in all sorts of practical, hands-on security, the research that I've been mainly involved in for the last years concerns the analysis of large online ecosystems from a security and privacy perspective.

In past work, together with the help of great colleagues, I've analyzed file-hosting services, referrer-anonymizing services, remote JavaScript inclusions, online fingerprinting companies and web-hosting companies. I've also proposed some countermeasures for known attacks and less known attacks, like session hijacking, ssl stripping, weak cross-origin Flash policies and tabnabbing.

News

  • We got a paper accepted at DIMVA 2013 :)
  • Paper on the adoption of bitsquatting, accepted at WWW 2013!
  • We got a paper accepted at IEEE S&P 2013!
  • Our paper with Philippe De Ryck was accepted at ASIACCS 2013
  • We got two papers accepted at CCS 2012!
  • Our paper with Job Noorman on low-level security got accepted at NordSec 2012
  • From June 2012 till September 2012, I will be on a research visit at UCSB, under the supervision of professors Christopher Kruegel and Giovanni Vigna

History

I started my PhD in September 2009 and before that I studied for 6 years in the University of Crete where I got my Bachelor in Computer Science and then my MSc in Distributed and Parallel systems. From 2006 till 2009 I also did security-related research in the Distributed Computing Systems Lab at FORTH under the supervision of Prof. Evangelos Markatos and Dr. Sotiris Ioannidis.

Apart from my work in security, when I was still a student in Greece I developed a small, Greek carpooling website called volevei.gr (volevei stands for "it is convenient" in Greek) which I still maintain.

Publications

  1. HeapSentry: Kernel-assisted Protection against Heap Overflows,
    Nick Nikiforakis, Frank Piessens, Wouter Joosen to appear in the 10th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2013), Berlin, Germany

  2. Bitsquatting: Exploiting bit-flips for fun, or profit?,
    Nick Nikiforakis, Steven Van Acker, Wannes Meert, Lieven Desmet, Frank Piessens, Wouter Joosen to appear in the 22nd International World Wide Web Conference (WWW 2013), Rio de Janeiro, Brazil

  3. Cookieless Monster: Exploring the Ecosystem of Web-based Device Fingerprinting,
    Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna to appear in the 34th IEEE Symposium of Security and Privacy (IEEE S&P 2013), San Francisco, CA, USA

  4. TabShots: Client-side detection of tabnabbing attacks,
    Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Wouter Joosen to appear at the 8th ACM Symposium on Information, Computer and Communications Security (ASIACCS 2013), Hangzhou, China

  5. You Are What You Include: Large-scale Evaluation of Remote JavaScript Inclusions,
    Nick Nikiforakis, Luca Invernizzi, Alexandros Kapravelos, Steven Van Acker, Wouter Joosen, Christopher Kruegel, Frank Piessens and Giovanni Vigna in Proceedings of the 19th ACM Conference on Computer and Communications Security (CCS 2012), Raleigh, NC, USA

  6. FlowFox: a Web Browser with Flexible and Precise Information Flow Control,
    Willem De Groef, Dominique Devriese, Nick Nikiforakis, and Frank Piessens
    in Proceedings of the 19th ACM Conference on Computer and Communications Security (CCS 2012), Raleigh, NC, USA

  7. There is Safety in Numbers: Preventing Control-Flow Hijacking by Duplication,
    Job Noorman, Nick Nikiforakis, and Frank Piessens in Proceedings of the 17th Nordic Conference on Secure IT Systems (NordSec 2012), Karlskrona, Sweden

  8. DEMACRO: Defense against Malicious Cross-domain Requests,
    Sebastian Lekies, Nick Nikiforakis, Walter Tighzert, Frank Piessens and Martin Johns in Proceedings of the 15th International Symposium on Research In Attacks, Intrusions and Defenses (RAID 2012), Amsterdam, The Netherlands

  9. Serene: Self-Reliant Client-Side Protection against Session Fixation,
    Philippe De Ryck, Nick Nikiforakis, Lieven Desmet, Frank Piessens and Wouter Joosen in Proceedings of the 7th International Federated Conference on Distributed Computing Techniques (DAIS 2012), Stockholm, Sweden

  10. Exploring the Ecosystem of Referrer-Anonymizing Services,
    Nick Nikiforakis, Steven Van Acker, Frank Piessens and Wouter Joosen in Proceedings of the 12th Privacy Enhancing Technology Symposium (PETS 2012), Vigo, Spain

  11. Recent Developments in Low-Level Software Security,
    Pieter Agten, Nick Nikiforakis, Raoul Strackx, Willem De Groef and Frank Piessens in Proceedings of the 6th Workshop in Information Security Theory and Practice (WISTP 2012), London, UK

  12. FlashOver: Automated Discovery of Cross-site Scripting Vulnerabilities in Rich Internet Applications,
    Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Wouter Joosen and Frank Piessens in Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security (ASIACCS 2012), Seoul, South Korea

  13. HyperForce: Hypervisor-enForced Execution of Security-Critical Code,
    Francesco Gadaleta, Nick Nikiforakis, Jan Tobias Muhlberg and Wouter Joosen in Proceedings of the 27th IFIP International Information Security and Privacy Conference (IFIP SEC 2012), Heraklion, Crete, Greece

  14. RIPE: Runtime Intrusion Prevention Evaluator,
    John Wilander, Nick Nikiforakis, Yves Younan, Mariam Kamkar and Wouter Joosen in Proceedings of the 27th Annual Computer Security Applications Conference (ACSAC 2011), Orlando, US [source]

  15. Hello rootKitty: A lightweight invariance-enforcing framework,
    Francesco Gadaleta, Nick Nikiforakis, Yves Younan and Wouter Joosen in Proceedings of the 14th Information Security Conference (ISC 2011), Xi'an, China [Video Demo]

  16. Abusing Locality in Shared Web Hosting,
    Nick Nikiforakis, Wouter Joosen and Martin Johns in Proceedings of the 4th European Workshop on System Security (EuroSec 2011), Salzburg, Austria

  17. Exposing the Lack of Privacy in File Hosting Services,
    Nick Nikiforakis, Marco Balduzzi, Steven Van Acker, Wouter Joosen and Davide Balzarotti in Proceedings of the 4th USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET 2011), Boston, US

  18. SessionShield: Lightweight Protection against Session Hijacking,
    Nick Nikiforakis,Wannes Meert, Yves Younan, Martin Johns and Wouter Joosen in Proceedings of the 3rd International Symposium on Engineering Secure Software and Systems (ESSoS 2011), Madrid, Spain

  19. ValueGuard: Protection of native applications against data-only buffer overflows,
    Steven Van Acker, Nick Nikiforakis, Pieter Philippaerts, Yves Younan and Frank Piessens in Proceedings of the Sixth International Conference on Information Systems Security (ICISS 2010), Gujarat, India

  20. HProxy: Client-side detection of SSL stripping attacks,
    Nick Nikiforakis, Yves Younan and Wouter Joosen in Proceedings of the 7th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2010, Bonn, Germany

  21. Monitoring three National Research Networks for Eight Weeks: Observations and Implications,
    Demetris Antoniades, Michalis Polychronakis, Nick Nikiforakis, Evangelos P. Markatos, Yiannis Mitsos in the 6th IEEE Workshop on End-to-End Monitoring Techniques and Services (E2EMon). April 2008, Salvador, Bahia, Brazil.

  22. When Appmon met Stager,
    Nikos Nikiforakis, Demetres Antoniades, Evangelos P. Markatos, Sotiris Ioannidis, Arne Olesbo, in the 6th IEEE Workshop on End-to-End Monitoring Techniques and Services (E2EMon). April 2008, Salvador, Bahia, Brazil.

  23. Alice, what did you do last time? Fighting Phishing Using Past Activity Tests,
    Nikos Nikiforakis, Andreas Makridakis, Elias Athanasopoulos, and Evangelos P. Markatos in Proceedings of the 3rd European Conference on Computer Network Defense (EC2ND). October 2007, Heraklion, Greece.

Articles

Talks

  • Web Application Security Seminar, Dagstuhl 2012 - You are what you include: Large-scale analysis of remote JavaScript inclusions
  • BruCON 2011 - Abusing locality in Shared Web Hosting
  • OWASP Netherlands Chapter meeting July 2011 - Abusing locality in Shared Web Hosting (slides)
  • OWASP BeNeLux 2010 - On the Privacy of File Sharing Services, Invited talk
  • CONFidence 201002 - Breaking Web Applications in Shared Hosting environments (slides)
  • AthCon 2010 - Alice Shares, Eve Reads: Enumerating File Hosting Services (slides)
  • OWASP AppSecDev Research 2010 - On the privacy of file sharing services

Professional Activities

Program Commitee member:

  • 7th IEEE Workshop on Network Measurements (IEEE WNM 2013)
  • 4th International Conference on Emerging Ubiquitous Systems and Pervasive Networks (EUSPN 2013)
  • OWASP AppSec Europe 2013 - Research Track (AppSec 2013)
  • 6th European Workshop on System Security (EuroSec 2013)
  • 14th IFIP Conference on Communications and Multimedia Security (CMS 2013)
  • 5th European Workshop on System Security (EuroSec 2012)
  • 13th IFIP Conference on Communications and Multimedia Security (CMS 2012)

Contact

Email

nick.nikiforakis[at]cs.kuleuven.be

Address

Nick Nikiforakis
Dept. Computer Science
Celestijnenlaan 200A
Heverlee 3001
Belgium