People / Faculty / Brad Reaves

Bio

Brad Reaves is an Associate Professor of Computer Science at North Carolina State University. His research seeks to identify, characterize, and confront the root causes of the most prominent and visible problems in computer security. He is best known for his work on cellular and telephone network security, but he also has produced key results on the security of software ecosystems, local networks, and communicating security information to humans. He is the recipient of an NSF CAREER award, the 2020 Internet Defense Prize, seven distinguished paper awards, and three patents.

Publications

  • Lorenzo Neil, Deepthi Mungara, Laurie Williams, Yasemin Acar, and Bradley Reaves, It Should Be Easy but... New Users’ Experiences and Challenges with Secret Management Tools, in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Nov. 2025, pp. 2519–2533.
    [PDF]
  • Sathvik Prasad, Aleksandr Nahapetyan, and Bradley Reaves, Characterizing Robocalls with Multiple Vantage Points, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2025.
  • Setu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara, Bradley Reaves, and Laurie Williams, AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts, in Proceedings of the International Conference on Software Engineering (ICSE), Apr. 2025.
  • Setu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara, Bradley Reaves, and Laurie Williams, AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts, in Proceedings of the IEEE/ACM International Conference on Software Engineering (ICSE), Apr. 2025, pp. 1268–1280.
    [PDF]
  • David Adei, Varun Madathil, Sathvik Prasad, Bradley Reaves, and Alessandra Scafuro, Jäger: Automated Telephone Call Traceback, in Proceedings of the ACM Conference on Computer and Communications Security, Oct. 2024.
  • Alexander J. Ross, Bradley Reaves, Yomna Nasser, Gil Cukierman, and Roger Piqueras Jover, Fixing Insecure Cellular System Information Broadcasts For Good, in International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Sep. 2024.
  • Trevor Dunlap, John Speed Meyers, Brad Reaves, and William Enck, Pairing Security Advisories with Vulnerable Functions Using Open-Source LLMs, in Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), Jul. 2024.
  • Trevor Dunlap, Elizabeth Lin, William Enck, and Bradley Reaves, VFCFinder: Pairing Security Advisories and Patches, in Proceedings of the ACM ASIA Conference on Computer and Communications Security (AsiaCCS), Jul. 2024.
  • Aleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest, Yeganeh Ladwig, Alexandros Kapravelos, and Brad Reaves, On SMS Phishing Tactics and Infrastructure, in Proceedings of the IEEE Symposium on Security and Privacy, May 2024.
  • Sathvik Prasad, Trevor Dunlap, Alexander Ross, and Bradley Reaves, Diving into Robocall Content with {SnorCall}, in 32nd USENIX Security Symposium (USENIX Security 23), Aug. 2023, pp. 427–444.
  • Siddharth Muralee, Igibek Koishybayev, Aleksandr Nahapetyan, Greg Tystahl, Brad Reaves, Antonio Bianchi, William Enck, Alexandros Kapravelos, and Aravind Machiry, ARGUS: A Framework for Staged Static Taint Analysis of GitHub Workflows and Actions, in Proceedings of the USENIX Security Symposium, Aug. 2023.
  • Trevor Dunlap, Seaver Thorn, William Enck, and Bradley Reaves, Finding Fixed Vulnerabilities with Off-the-Shelf Static Analysis, in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), Jul. 2023.
  • Iffat Anjum, Jessica Sokal, Hafiza Ramzah Rehman, Ben Weintraub, Ethan Leba, William Enck, Cristina Nitarotaru, and Bradley Reaves, MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2023.
  • Setu Kumar Basak, Jamison Cox, Bradley Reaves, and Laurie Williams, A Comparative Study of Software Secrets Reporting by Secret Detection Tools, in 2023 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), 2023, pp. 1–12.
  • Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, and Laurie A. Williams, What are the Practices for Secret Management in Software Artifacts?, in Proceedings of the IEEE Secure Development Conference (SecDev), Oct. 2022.
  • Igibek Koishybayev, Aleksandr Nahapetyan, Raima Zachariah, Siddharth Muralee, Brad Reaves, Alexandros Kapravelos, and Aravind Machiry, Characterizing the Security of Github CI Workflows, in Proceedings of the USENIX Security Symposium, Aug. 2022.
  • Iffat Anjum, Daniel Kostecki, Ethan Leba, Jessica Sokal, Rajit Bharambe, William Enck, Cristina Nita-Rotaru, and Bradley Reaves, Removing the Reliance on Perimeters for Security using Network Views, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2022. (best student paper).
  • Trevor Dunlap, William Enck, and Bradley Reaves, A Study of Application Sandbox Policies in Linux, in Proceedings of the ACM Symposium on Access Control Models and Technologies (SACMAT), Jun. 2022.
  • Lorenzo Neil, Elijah Bouma-Sims, Evan Lafontaine, Yasemin Acar, and Bradley Reaves, Investigating Web Service Account Remediation Advice, in Proceedings of the Symposium on Usable Privacy and Security (SOUPS), Aug. 2021, pp. 359–376.
  • Abida Haque, Varun Madathil, Bradley Reaves, and Alessandra Scafuro, Anonymous Device Authorization for Cellular Networks, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), Jun. 2021.
  • Matthew McNiece, Ruidan Li, and Bradley Reaves, Characterizing the Security of Endogenous and Exogenous Desktop Application Network Flows, in Proceedings of the Passive and Active Measurement Conference (PAM), Mar. 2021.
  • Elijah Bouma-Sims and Bradley Reaves, A First Look at Scams on YouTube, in Proceedings of the Workshop on Measurements, Attacks, and Defenses for the Web, Feb. 2021.
  • Sathvik Prasad, Elijah Bouma-Sims, Athishay Kiran Mylappan, and Bradley Reaves, Who’s Calling? Characterizing Robocalls through Audio and Metadata Analysis, in Proceedings of the USENIX Security Symposium, Boston, MA, Aug. 2020.
    (acceptance rate=16.3%)
  • Samin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck, and Bradley Reaves, Cardpliance: PCI DSS Compliance of Android Applications, in Proceedings of the USENIX Security Symposium, Boston, MA, Aug. 2020.
    (acceptance rate=16.3%)
  • Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Serge Egelman, Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheck, in Proceedings of the USENIX Security Symposium, Boston, MA, Aug. 2020.
    (acceptance rate=16.3%)
  • Justin Whitaker, Sathvik Prasad, Bradley Reaves, and William Enck, Thou Shalt Discuss Security: Quantifying the Impacts of Instructions to RFC Authors, in Proceedings of the Security Standardisation Research Conference, Nov. 2019.
    (acceptance rate=35%)
  • Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie, PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play, in Proceedings of the USENIX Security Symposium, Santa Clara, CA, Aug. 2019.
  • TJ OConnor, Reham Mohamed, Markus Miettinen, William Enck, Bradley Reaves, and Ahmad-Reza Sadeghi, HomeSnitch: Behavior Transparency and Control for Smart Home IoT Devices, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019.
    (acceptance rate=25.6%)
  • TJ OConnor, William Enck, and Bradley Reaves, Blinded and Confused: Uncovering Systemic Flaws in Device Telemetry for Smart-Home Internet of Things, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019.
    (acceptance rate=25.6%)
  • Sanket Goutam, William Enck, and Bradley Reaves, Hestia: Simple Least Privilege Network Policies for Smart Homes, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), May 2019. (short paper).
    (acceptance rate=32.2%)
  • Michael Meli, Matthew R. McNiece, and Bradley Reaves, How Bad Can It Git? Characterizing Secret Leakage in Public GitHub Repositories, in Proceedings of the Networked and Distributed Systems Security Symposium (NDSS), Feb. 2019.
    (acceptance rate=17.1%)
  • Reaves, Bradley, Luis Vargas, Nolen Scaife, Dave Tian, Logan Blue, Patrick Traynor, and Kevin R. B. Butler, Characterizing the Security of the SMS Ecosystem with Public Gateways, ACM Transactions on Privacy and Security (TOPS), vol. 22, no. 1, Dec. 2018.
  • Dominik Wermke, Nicolas Huaman, Yasemin Acar, Bradley Reaves, Patrick Traynor, and Sascha Fahl, A Large Scale Investigation of Obfuscation Use in Google Play, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), Dec. 2018.
    (acceptance rate=20.1%)
  • Christian Peeters, Hadi Abdullah, Nolen Scaife, Jasmine Bowers, Patrick Traynor, Bradley Reaves, and Kevin Butler, Sonar: Detecting SS7 Redirection Attacks Via Call Audio-Based Distance Bounding, in Proceedings of the 39th IEEE Symposium on Security and Privacy (S&P), May 2018.
    (acceptance rate=10.4%)
  • Bradley Reaves, Logan Blue, Hadi Abdullah, Luis Vargas, Patrick Traynor, and Tom Shrimpton, AuthentiCall: Efficient Identity and Content Authentication for Phone Calls, in Proceedings of the USENIX Security Symposium, Vancouver, BC, Canada, Aug. 2017.
    (acceptance rate=16.3%)
  • Stephan Heuser, Bradley Reaves, Praveen Kumar Pendyala, Henry Carter, Alexandra Dmitrienko, William Enck, Negar Kiyavash, Ahmad-Reza Sadeghi, and Patrick Traynor, Phonion: Practical Protection of Metadata in Telephony Networks, Proceedings on Privacy Enhancing Technologies (PoPETS), vol. 2017, no. 1, Jan. 2017.
  • Bradley Reaves, Jasmine Bowers, Sigmund Albert Gorski III, Olabode Anise, Rahul Bobhate, Raymond Cho, Hiranava Das, Sharique Hussain, Hamza Karachiwala, Nolen Scaife, Byron Wright, Kevin Butler, William Enck, and Patrick Traynor, *droid: Assessment and Evaluation of Android Application Analysis Tools, ACM Computing Surveys (CSUR), vol. 2016, no. 3, Dec. 2016.
  • Saurabh Chakradeo, Brad Reaves, Patrick Traynor, and William Enck, MAST: Triage for Market-scale Mobile Malware Analysis, in Proceedings of the ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec), Budapest, Hungary, Apr. 2013. (\bf best paper).
    [PDF] (acceptance rate=15.1%)