Bio
Alexandros Kapravelos is an Associate Professor in the Department of Computer Science at NC State University. He received his PhD in Computer Science from University of California, Santa Barbara in 2015. His research interests span the areas of systems and software security. Currently, he studies how the web changes on the client side via browser extensions and how we can protect the browser from malicious client-side attacks. He is also interested in Internet privacy and browser fingerprinting specifically, where he is working on making Internet users less distinctive while they browse the web. He is the lead developer of Wepawet, a publicly available system that detects drive-by downloads with the use of an emulated browser, Revolver, a system that detects evasive drive-by download attempts, and Hulk, a browser extension analysis system.
Publications
- Greg Tystahl, Jonah Ghebremichael, Siddharth Muralee, Sourag Cherupattamoolayil, Antonio Bianchi, Aravind Machiry, Alexandros Kapravelos, and William Enck, Cosseter: GitHub Actions Permission Reduction Using Demand-Driven
Static Analysis, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2026.
- Hao He, Haoqin Yang, Philipp Burckhardt, Alexandros Kapravelos, Bogdan Vasilescu, and Christian Kästner, Six Million (Suspected) Fake Stars on GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware, in Proceedings of the International Conference on Software Engineering (ICSE), Apr. 2026.
- Sohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su, Anupam Das, Jason Polakis, and Alexandros Kapravelos, Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViews, in Proceedings of the Network and Distributed System Security (NDSS) Symposium, Feb. 2026.
- Ahsan Zafar, Junhua Su, Sohom Datta, Alexandros Kapravelos, and Anupam Das, Same Script, Different Behavior: Characterizing Platform-Specific Divergent JavaScript Execution, in Proceedings of the 32nd ACM Conference on Computer and Communications Security (CCS), Nov. 2025.
- Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck, Research Directions in Software Supply Chain Security, ACM Transactions on Software Engineering Methodology (TOSEM), pp. 1–38, May 2025.
[PDF] - Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, and Luca Verderame, An Empirical Study on Reproducible Packaging in Open-Source Ecosystems, in Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), Apr. 2025.
- Shaown Sarker, William Melicher, Oleksii Starov, Anupam Das, and Alexandros Kapravelos, Automated Generation of Behavioral Signatures for Malicious Web Campaigns, in Proceedings of the 27th Information Security Conference (ISC), Oct. 2024.
- Shaown Sarker, Aleksandr Nahapetyan, Anupam Das, and Alexandros Kapravelos, JSHint: Revealing API Usage to Improve Detection of Malicious JavaScript, in Proceedings of the 27th Information Security Conference (ISC), Oct. 2024.
- Nikolaos Pantelaios and Alexandros Kapravelos, FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques, in Proceedings of the USENIX Security Symposium, Aug. 2024.
- Nusrat Zahan, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2023-11: Industry Secure Supply Chain Summit. Aug-2024. arXiv:2408.16529.
[PDF] - Aleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest, Yeganeh Ladwig, Alexandros Kapravelos, and Brad Reaves, On SMS Phishing Tactics and Infrastructure, in Proceedings of the IEEE Symposium on Security and Privacy, May 2024.
- Greg Tystahl, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2024-03: Industry Secure Supply Chain Summit. May-2024. arXiv:2405.08762.
[PDF] - Elizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck, and Alexandros Kapravelos, UntrustIDE: Exploiting Weaknesses in VS Code Extensions, in Proceedings of the ISOC Network and Distributed Systems Symposium (NDSS), Feb. 2024.
- Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Brad Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, and Aravind Machiry, ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions, in Proceedings of the USENIX Security Symposium, Aug. 2023.
- William Enck, Yasemin Acar, Michel Cukier, Alexandros Kapravelos, Christian Kästner, and Laurie Williams, S3C2 Summit 2023-06: Government Secure Supply Chain Summit. Aug-2023. arXiv:2308.06850.
[PDF] - Trevor Dunlap, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2023-02: Industry Secure Supply Chain Summit. Jul-2023. arXiv:2307.16557.
[PDF] - Mindy Tran, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, and Laurie Williams, S3C2 Summit 2022-09: Industry Secure Suppy Chain Summit. Jul-2023. arXiv:2307.15642.
[PDF] - Junhua Su and Alexandros Kapravelos, Automatic Discovery of Emerging Browser Fingerprinting Techniques, in Proceedings of The Web Conference (WWW), Apr. 2023.
- Giorgos Vasiliadis, Apostolos Karampelas, Alexandros Shevtsov, Panagiotis Papadopoulos, Sotiris Ioannidis, and Alexandros Kapravelos, WRIT: Web Request Integrity and Attestation against Malicious Browser Extensions, IEEE Transactions on Dependable and Secure Computing, 2023.
- Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Brad Reaves, Alexandros Kapravelos, and Aravind Machiry, Characterizing the Security of Github CI Workflows, in Proceedings of the USENIX Security Symposium, Aug. 2022.
- Karthika Subramani, Jordan Jueckstock, Alexandros Kapravelos, and Roberto Perdisci, SoK: Workerounds - Categorizing Service Worker Attacks and Mitigations, in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), Jun. 2022.
- Dashmeet Kaur Ajmani, Igibek Koishybayev, and Alexandros Kapravelos, yoU aRe a Liar://A Unified Framework for Cross-Testing URL Parsers, in Proceedings of the IEEE SecWeb Workshop, Jun. 2022.
- Jordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos, and Ben Livshits, Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful Tracking, in Proceedings of The Web Conference (WWW), Apr. 2022.
- Seyed Ali Akhavani, Jordan Jueckstock, Junhua Su, Alexandros Kapravelos, Engin Kirda, and Long Lu, Browserprint: An Analysis of the Impact of Browser Features on Fingerprintability and Web Privacy, in Proceedings of the Information Security Conference (ISC), Nov. 2021.
- Pierre Laperdrix, Oleksii Starov, Quan Chen, Alexandros Kapravelos, and Nick Nikiforakis, Fingerprinting in Style: Detecting Browser Extensions via Injected Style Sheets, in Proceedings of the USENIX Security Symposium, Aug. 2021.
- Quan Chen, Peter Snyder, Ben Livshits, and Alexandros Kapravelos, Detecting Filter List Evasion With Event-Loop-Turn Granularity JavaScript Signatures, in Proceedings of the IEEE Symposium on Security and Privacy, May 2021.
- Penghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun, RC Johnson, Brad Wardman, Shaown Sarker, Alexandros Kapravelos, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doupé, and Gail-Joon Ahn, CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in Phishing, in Proceedings of the IEEE Symposium on Security and Privacy, May 2021.
- Jordan Jueckstock, Shaown Sarker, Peter Snyder, Aidan Beggs, Panagiotis Papadopoulos, Matteo Varvello, Ben Livshits, and Alexandros Kapravelos, Towards Realistic and Reproducible Web Crawl Measurements, in Proceedings of the The Web Conference (WWW), Apr. 2021.
- Quan Chen, Panagiotis Ilia, Michalis Polychronakis, and Alexandros Kapravelos, Cookie Swap Party: Abusing First-Party Cookies for Web Tracking, in Proceedings of the The Web Conference (WWW), Apr. 2021.
- Sung Ta Dinh, Haehyun Cho, Kyle Martin, Adam Oest, Yihui Zeng, Alexandros Kapravelos, Tiffany Bao, Ruoyu "Fish" Wang, Yan Shoshitaishvili, Adam Doupe, and Gail-Joon Ahn, Favocado: Fuzzing Binding Code of JavaScript Engines Using Semantically Correct Test Cases, in Proceedings of the Network and Distributed System Security Symposium (NDSS), Feb. 2021.
- Nikolaos Pantelaios, Nick Nikiforakis, and Alexandros Kapravelos, You’ve Changed: Detecting Malicious Browser Extensions through their Update Deltas, in Proceedings of the ACM Conference on Computer and Communications Security (CCS), Nov. 2020.
- Shaown Sarker, Jordan Jueckstock, and Alexandros Kapravelos, Hiding in Plain Site: Detecting JavaScript Obfuscation through Concealed Browser API Usage, in Proceedings of the ACM Internet Measurement Conference (IMC), Oct. 2020.
- Igibek Koishybayev and Alexandros Kapravelos, Mininode: Reducing the Attack Surface of Node.js Applications, in Proceedings of the International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Oct. 2020.
- Jordan Jueckstock and Alexandros Kapravelos, VisibleV8: In-browser Monitoring of JavaScript in the Wild, in Proceedings of the ACM Internet Measurement Conference (IMC), Oct. 2019.
- Erik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis, and Adam Doupe, Everyone is Different: Client-side Diversification for Defending Against Extension Fingerprinting, in Proceedings of the USENIX Security Symposium, Aug. 2019.
- Aidan Beggs and Alexandros Kapravelos, Wild Extensions: Discovering and Analyzing Unlisted Chrome Extensions, in Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), Jun. 2019.
- Oleksii Starov, Pierre Laperdrix, Alexandros Kapravelos, and Nick Nikiforakis, Unnecessarily Identifiable: Quantifying the fingerprintability of browser extensions due to bloat, in Proceedings of the World Wide Web Conference (WWW), May 2019.
- Alexandros Kapravelos Quan Chen, Mystique: Uncovering Information Leakage from Browser Extensions, in Proceedings of the ACM Conference on Computer and Communications Security (CCS), Toronto, Canada, Oct. 2018.
- Luca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu, Jean-Michel Picod, and Elie Bursztein, Cloak of Visibility: Detecting When Machines Browse A Different Web, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA, May 2016.
[PDF]
