Sadegh Torabi

dblp:117/5054 · DBLP profile ↗
← Back
17ranked-venue papers
4as first author
15since 2021 · last 2025
0000-0003-2811-3536ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 4 first-author · 8 since 2021Computer networks · 6 · 6 since 2021Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Dynamic trigger-based attacks against next-generation IoT malware family classifiers
Yefei Zhang, Sadegh Torabi, Jun Yan 0007, Chadi Assi
Comput. Secur.2
2025 A Data-Driven Study of IoT Malware Classification Models: Insights Into Temporal, Architectural, and Spatial Inconsistency Challenges
abstract
To combat the growing IoT malware threat, many studies propose ML-based classification solutions, but the lack of comprehensive evaluations limits insights for developing new solutions and selecting models. Given this necessity, this work evaluates IoT malware classification models under three key challenges: temporal, architectural, and spatial inconsistencies between development and deployment datasets, which can be regarded as variables characterizing the dataset, and the challenges arise from the variable values inconsistency between the two stages. To improve the conclusions’ comprehensiveness, effectiveness, and generalizability, the evaluation is organized hierarchically across three levels based on model generation, sample variation, and inconsistency assumptions. Given the complexity of the model development pipeline, our evaluation treats each model individually and aims to conclude impacts across all models. The analysis reveals that temporal and architectural inconsistencies significantly degrade model performance, with architectural inconsistency having a greater impact, despite cross-architecture designs. Temporal inconsistency effects vary with temporal value differences, while spatial inconsistency has minimal impact, even with substantial spatial variation. Furthermore, we use one-way ANOVA to identify features contributing to family distinguishability, temporal stability, and architectural generalizability that benefit future solution design. Meanwhile, we studied a specific example to study the model performance degradation under architectural inconsistency. Finally, we summarize the lessons learned and outline potential research directions to address these challenges.
Yefei Zhang, Sadegh Torabi, Jun Yan 0007, Chadi Assi
IEEE Internet Things J.2
2025 Internet-Wide Analysis, Characterization, and Family Attribution of IoT Malware: A Comprehensive Longitudinal Study
abstract
This study presents a large-scale empirical analysis of real-life Internet-of-Things (IoT) malware by conducting a comprehensive analysis of 160,000 malicious executables detected by specialized IoT honeypots over five years. Our findings contribute to improving the knowledge of IoT malware characteristics and inter-relationships, which in return, contribute towards strengthening cybersecurity measures for IoT threat detection/mitigation. To achieve these goals, we leverage various malware analysis techniques to extract useful information from the executable files. Our analysis demonstrate that in contrast to non-IoT malware, we were able to extract unsolicited IP addresses and command strings from the majority of the analyzed IoT malware binaries using off-the-shelf de-obfuscation techniques/tools. Additionally, by correlating the extracted information and performing consequent similarity analysis using NLP-based features, we were able to reveal closely related samples with shared implementation across the adversarial infrastructure. Thus, contributing to labeling previously unseen/unknown IoT malware samples while uncovering emerging, possibly new variants. Finally, given such findings, we discuss the applications of a real-time IoT honeypot, which enables capturing real-time commands from malware-infected IoT devices while enabling timely and effective IoT-malware detection, analysis, labeling, and mitigation.
Sadegh Torabi, Dorde Klisura, Joseph Khoury, Elias Bou-Harb, Chadi Assi, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.1
2024 Uncovering Covert Attacks on EV Charging Infrastructure: How OCPP Backend Vulnerabilities Could Compromise Your System
abstract
The Electric Vehicle (EV) charging infrastructure has been rapidly expanding to keep up with the increased demands of EV consumers. This government-backed infrastructure expansion resulted in the rushed integration of a significant number of insecure EV Charging Stations (EVCS), which are vulnerable to cyber-attacks. Motivated by the uncovered vulnerabilities in different components of the EV charging infrastructure, in this paper, we study the security of the EVCS Cloud Management System (CMS). Specifically, we focus on the (in)security of the Open Charge Point Protocol (OCPP) backend communication with the EVCS. We verified the prevalence of such security weaknesses by discovering 6 zero-day vulnerabilities in each of the 16 representative live EV charging management systems. Our findings highlight the insecurity of the OCPP backend, which is widely deployed on existing EVCSs in the wild. Indeed, we discuss various attack scenarios that lead to man-in-the-middle, denial of service, firmware theft, and data poisoning, to name a few. We also leverage the developed testbed to demonstrate the feasibility of launching switching attacks against the power grid using compromised EVCSs. Finally, we contribute to the security of the EV charging ecosystem by also recommending countermeasures to mitigate/prevent future cyber-attacks.
Khaled Sarieddine, Mohammad Ali Sayed, Sadegh Torabi, Ribal Atallah, Danial Jafarigiv, Chadi Assi, Mourad Debbabi
AsiaCCS3
2024 Securing IoT Malware Classifiers: Dynamic Trigger-Based Attack and Mitigation
abstract
The evolution of IoT malware has ignited interest in the creation of malware family classification models. Nonetheless, these models encounter security concerns stemming from issues related to their interpretability and vulnerabilities exposed within the training pipeline. Recent research highlighted the limitations of learning-based malware classifiers, which are susceptible to backdoor attacks due to relying on human-engineered features to simplify the mapping from features to binary perturbations. In contrast, our study aligns with the current trajectory of the malware classification field, where we emphasize the detection of backdoor attacks targeted at models employing features extracted from within the model itself. To thoroughly assess model vulner-abilities, we have devised a dynamic trigger generation method based on sample features, which we refer to as “BENIGN”. This approach is used to contaminate and launch attacks on the model while also implementing a tailored training process to achieve specific attack objectives. Through experiments, we analyze the impact of variables involved in its training procedures on the attack stability and success rates. Last, we evaluate mitigation methods and emphasize the challenges and adaptability needed to defend against these attack strategies.
Yefei Zhang, Jun Yan 0007, Sadegh Torabi, Chadi Assi
ICC3
2024 A Hybrid System Call Profiling Approach for Container Protection
abstract
Over-privileged Linux containers might put the underlying OS at risk by permitting pointless system calls that could be exploited as entry points to the kernel. However, finding such security profiles is a difficult task as it demands examining the implementation/operation of containers in the absence of knowledge regarding its required system calls. In this article, we propose a hybrid approach to limit the system call usage during the execution of containers. Specifically, given an application container, we maintain an initial fine-grained whitelist by dynamic tracking to control the run-time security along with a complementary whitelist extracted via static analysis to maintain container's functionality while addressing the coverage limitation of dynamic analysis. Our method automatically analyzes the container behavior to identify three execution phases and dynamically enforce the corresponding fine-grained system call whitelists. The invoked system call will be compared with both whitelists to decide if it should be killed to guarantee the container security or logged for further analysis. Our evaluation results with 193 Docker images demonstrate the effectiveness of our approach in significantly reducing the required system calls during the applications' life-cycle. Furthermore, we discuss the reduced attack surface and demonstrate the efficiency of our approach through empirical analysis results.
Yunlong Xing, Xinda Wang 0001, Sadegh Torabi, Lingguang Lei, Kun Sun 0001
IEEE Trans. Dependable Secur. Comput.3
2024 EV Charging Infrastructure Discovery to Contextualize Its Deployment Security
abstract
Electric Vehicle Charging Stations (EVCSs) have been shown to be susceptible to remote exploitation due to manufacturer-induced vulnerabilities, demonstrated by recent attacks on this ecosystem. What is more alarming is that compromising these high-wattage IoT systems can be leveraged to perform coordinated oscillatory load attacks against the power grid which could lead to the instability of this critical infrastructure. In this paper, we investigate a previously sidelined aspect of EVCS security. We analyze the deployment security of EVCSs and highlight operator-induced vulnerabilities rendering the ecosystem exposed to remote intrusions. We create an advanced discovery technique that leverages Web interface artifacts to dynamically discover new charging station vendors. As a result, we uncover 33,320 charging station management systems in the wild. Consequently, we study the deployment security of the charging stations and identify that 28,046 EVCSs were found to be vulnerable to eavesdropping, and around 24% of the studied EVCSs are deployed with default configurations exposing the ecosystem to a Mirai-like attack vector. Aligned with this finding, we discover that the EVCS ecosystem has been targeted by nefarious IoT malware such as Mirai and its variants. This demonstrates that further security measures should be implemented by vendors and operators to ensure the security of this vital ecosystem. Consequently, we provide a comprehensive recommendation for securing the deployment of EVCSs.
Khaled Sarieddine, Mohammad Ali Sayed, Chadi Assi, Ribal Atallah, Sadegh Torabi, Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb
IEEE Trans. Netw. Serv. Manag.5
2023 RPM: Ransomware Prevention and Mitigation Using Operating Systems' Sensing Tactics
abstract
Ransomware, an extortion type of malware, continues to create havoc targeting critical infrastructure and organizations at large, causing an estimated $20 Billion in direct and collateral damages in 2022. While significant efforts from both academia and industry are being pledged to address this debilitating and disrupting phenomena, the ransomware pandemic continues to expand rapidly in frequency, spread and stealthiness. To this end, in this work, we propose RPM, a Ransomware Prevention and Mitigation scheme. RPM is rooted in the proactive analysis of operating systems' API artifacts through the exploitation of a neat observation related to ransomware behavior, namely, activities generated prior to the actual execution of the malicious payloads. RPM employs OS-centric process hooking tactics to develop an offensive approach leveraging such sensing activities. To demonstrate the effectiveness of RPM, we empirically evaluated it using 100 of the most prominent ransomware samples. The results demonstrate very motivating accuracy metrics with low system footprint, asserting the rationale of the proposed scheme. We posture RPM as a strong step towards proactive mitigation, which aims at complimenting ongoing ransomware thwarting efforts.
Ricardo Misael Ayala Molina, Elias Bou-Harb, Sadegh Torabi, Chadi Assi
ICC3
2023 ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management Systems
Tony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha, Chadi Assi
NDSS2
2023 Investigating the Security of EV Charging Mobile Applications as an Attack Surface
abstract
The adoption rate of EVs has witnessed a significant increase in recent years driven by multiple factors, chief among which is the increased flexibility and ease of access to charging infrastructure. To improve user experience and increase system flexibility, mobile applications have been incorporated into the EV charging ecosystem. EV charging mobile applications allow consumers to remotely trigger actions on charging stations and use functionalities such as start/stop charging sessions, pay for usage, and locate charging stations, to name a few. In this article, we study the security posture of the EV charging ecosystem against a new type of remote that exploits vulnerabilities in the EV charging mobile applications as an attack surface. We leverage a combination of static and dynamic analysis techniques to analyze the security of widely used EV charging mobile applications. Our analysis was performed on 31 of the most widely used mobile applications including their interactions with various components such as cloud management systems. The attack scenarios that exploit these vulnerabilities were verified on a real-time co-simulation test bed. Our discoveries indicate the lack of user/vehicle verification and improper authorization for critical functions, which allow adversaries to remotely hijack charging sessions and launch attacks against the connected critical infrastructure. The attacks were demonstrated using the EVCS mobile applications showing the feasibility and the applicability of our attacks. Indeed, we discuss specific remote attack scenarios and their impact on EV users. More importantly, our analysis results demonstrate the feasibility of leveraging existing vulnerabilities across various EV charging mobile applications to perform wide-scale coordinated remote charging/discharging attacks against the connected critical infrastructure (e.g., power grid), with significant economical and operational implications. Finally, we propose countermeasures to secure the infrastructure and impede adversaries from performing reconnaissance and launching remote attacks using compromised accounts.
Khaled Sarieddine, Mohammad Ali Sayed, Sadegh Torabi, Ribal Atallah, Chadi Assi
ACM Trans. Cyber Phys. Syst.3
2022 EVOLIoT: A Self-Supervised Contrastive Learning Framework for Detecting and Characterizing Evolving IoT Malware Variants
abstract
Recent years have witnessed the emergence of new and more sophisticated malware targeting the Internet of Things. Moreover, the public release of the source code of popular malware families such as Mirai has spawned diverse variants, making it harder to disambiguate their ownership, lineage, and correct label. Such a rapidly evolving landscape makes it also harder to deploy and generalize effective learning models against retired, updated, and/or new threat campaigns. In this paper, we present EVOLIoT, a novel approach aiming at combating "concept drift" and the limitations of inter-family IoT malware classification by detecting drifting IoT malware families and understanding their diverse evolutionary trajectories. We introduce a robust and effective contrastive method that learns and compares semantically meaningful representations of IoT malware binaries and codes without the need for expensive target labels. We find that the evolution of IoT binaries can be used as an augmentation strategy to learn effective representations to contrast (dis)similar variant pairs. We discuss the impact and findings of our analysis and present several evaluation studies to highlight the tangled relationships of IoT malware, as well as the efficiency of our contrastively learned feature vectors in preserving semantics and reducing out-of-vocabulary size in cross-architecture IoT malware binaries.
Mirabelle Dib, Sadegh Torabi, Elias Bou-Harb, Nizar Bouguila, Chadi Assi
AsiaCCS2
2022 Power jacking your station: In-depth security analysis of electric vehicle charging station management systems
Tony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha, Chadi Assi
Comput. Secur.2
2022 Inferring and Investigating IoT-Generated Scanning Campaigns Targeting a Large Network Telescope
abstract
The analysis of recent large-scale cyber attacks, which leveraged insecure Internet of Things (IoT) devices to perform malicious activities on the Internet, highlighted the rise of IoT-tailored malware/botnets. These malware propagate by scanning the Internet for vulnerable, exploitable IoT devices that could be utilized for further malicious activities. In this article, we devise a multi-level methodology to investigate Internet-scale reconnaissance activities generated by infected IoT devices. We leverage theShodanIoT search engine and over 6TB of passive network traffic from a large network telescope (darknet) to infer compromised IoT devices and characterize the generated scanning campaigns. The results highlight a distinctive characteristic of IoT malware/botnets, represented by the targeted ports/services over the analysis interval. Furthermore, while these ports/services are mainly associated with well-known IoT malware/botnets (e.g.,MiraiandSatori), we uncovered newly targeted ports, which indicate emerging IoT malware/botnet. Finally, by comparing two instances of analyzed IoT-generated scanning campaigns, we highlight the persistence and evolution of IoT malware/botnets (e.g.,ADB.MinerandFbot), which exploit existing, and in some cases, possibly new vulnerabilities.
Sadegh Torabi, Elias Bou-Harb, Chadi Assi, ElMouatez Billah Karbab, Amine Boukhtouta, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.1
2022 On Ransomware Family Attribution Using Pre-Attack Paranoia Activities
abstract
Ransomware attacks are among the most disruptive cyber threats, causing significant financial losses while impacting productivity, accessibility, and reputation. Despite their end goals (encryption/locking), ransomware are often designed to evade detection by executing a series of pre-attack API calls, namely “paranoia” activities, for determining a suitable execution environment. In this work, we present a first-of-a-kind effort to utilize such paranoia activities for characterizing ransomware distinguishable behaviors. To this end, we draw-upon more than 3K samples from recent/prominent ransomware families to fingerprint their uniquely leveraged paranoia activities. Specifically, by leveraging techniques rooted in Natural Language Processing (NLP) such as Occurrence of Words (OoW), we model ransomware-generated evasion API calls while tailoring various machine and deep learning algorithms to perform ransomware classification. The thoroughly conducted evaluations demonstrate the effectiveness of the implemented approach, with the Random Forest (RF) and OoW techniques producing an optimal classification accuracy (94.92%). The insights/findings from this work not only shed light on contemporary ransomware-specific evasion methods, but also (i) indicates that such tactics could be employed effectively as features for ransomware family attribution while (ii) laying the foundation for implementing proactive and portable countermeasures for further ransomware attack detection/mitigation by solely utilizing ransomware-generated paranoia activities.
Ricardo Misael Ayala Molina, Sadegh Torabi, Khaled Sarieddine, Elias Bou-Harb, Nizar Bouguila, Chadi Assi
IEEE Trans. Netw. Serv. Manag.2
2021 A Multi-Dimensional Deep Learning Framework for IoT Malware Classification and Family Attribution
abstract
The emergence of Internet of Things malware, which leverages exploited IoT devices to perform large-scale cyber attacks (e.g., Mirai botnet), is considered as a major threat to the Internet ecosystem. To mitigate such threat, there is an utmost need for effective IoT malware classification and family attribution, which provide essential steps towards initiating attack mitigation/prevention countermeasures. In this paper, motivated by the lack of sophisticated malware obfuscation in the implementation of IoT malware, we utilize features extracted from strings- and image-based representations of the executable binaries to propose a novel multi-dimensional classification approach using Deep Learning (DL) architectures. To this end, we analyze more than 70,000 recently detected IoT malware samples. Our in-depth experiments with four prominent IoT malware families highlight the significant accuracy of the approach (99.78%), which outperforms conventional single-level classifiers. Additionally, we utilize our IoT-tailored approach for labeling newly detected “unknown” malware samples, which were mainly attributed to a few predominant families. Finally, this work contributes to the security of future networks (e.g., 5G) through the implementation of effective tools/techniques for timely IoT malware classification, and attack mitigation.
Mirabelle Dib, Sadegh Torabi, Elias Bou-Harb, Chadi Assi
IEEE Trans. Netw. Serv. Manag.2
2018 Inferring, Characterizing, and Investigating Internet-Scale Malicious IoT Device Activities: A Network Telescope Perspective
abstract
Recent attacks have highlighted the insecurity of the Internet of Things (IoT) paradigm by demonstrating the impacts of leveraging Internet-scale compromised IoT devices. In this paper, we address the lack of IoT-specific empirical data by drawing upon more than 5TB of passive measurements. We devise data-driven methodologies to infer compromised IoT devices and those targeted by denial of service attacks. We perform large-scale characterization analysis of their traffic, as well as explore a public threat repository and an in-house malware database, to underlie their malicious activities. The results expose a significant 26 thousand compromised IoT devices "in the wild," with 40% being active in critical infrastructure. More importantly, we uncover new, previously unreported malware variants that specifically target IoT devices. Our empirical results render a first attempt to highlight the large-scale insecurity of the IoT paradigm, while alarming about the rise of new generations of IoT-centric malware-orchestrated botnets.
Sadegh Torabi, Elias Bou-Harb, Chadi Assi, Mario Galluscio, Amine Boukhtouta, Mourad Debbabi
DSN1
2016 Sharing Health Information on Facebook: Practices, Preferences, and Risk Perceptions of North American Users
Sadegh Torabi, Konstantin Beznosov
SOUPS1