VLDB 2026 Research / reviewers in the wild / expert
Hanif Rahbari
dblp:133/3880
· DBLP profile ↗
26ranked-venue papers
6as first author
15since 2021 · last 2025
0000-0001-7670-6542ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 4 first-author · 7 since 2021Security and privacy · 9 · 2 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Low-latency RFI Nulling and Multi-User Scaling for 5G and Radio Astronomy Coexistenceabstract5G network operators are constantly under pressure from regulatory agencies who restrict the deployment of base stations (gNBs) close to incumbent services, such as radio astronomy services (RAS), to avoid interfering with them. Recent works for coexistence with RAS employ limited channel modeling approaches and use explicit out-of-band communication between the gNB and RAS. However, the strict latency requirements of 5G make explicit communications less desirable due to their overheads. Deploying gNBs close to RAS is also not yet supported. In this paper, we propose a proactive open-loop beamforming and interference nullification technique in which a gNB nullifies its downlink signal at a nearby RAS telescope while beamforming to its users (UEs). We estimate the gNB-RAS channel using raytracing on open-source terrain maps. We formulate a problem that maximizes the minimum rate for UEs under the constraint of maximum allowable interference power at the RAS and show that its time complexity scales cubically with the number of gNB antennas. Hence, we propose a heuristic solution that achieves 4 orders better latency and 100 dBW lower interference power than the max-min rate solution with similar sum rate on users. Our proposed solution consistently achieves less than -310 dBW interference power, even when the gNB-RAS distance is less than 1 km, satisfying international regulations, and is robust against moving users that vary in location and elevation. Siddharth Dongre, Tiep Minh Hoang, Hanif Rahbari, Alireza Vahid |
CCNC | 3 |
| 2025 | Locking Down Relay and Spoofing Attacks During Concurrent Connection Establishments in 802.11axabstractWireless local area networks remain vulnerable to attacks initiated during the connection establishment (CE) phase. Even the latest Wi-Fi security protocols fail to fully mitigate threats such as man in the middle, preamble spoofing, and relaying. To fortify the CE phase, this paper presents a backwardcompatible scheme, reinforced with timing constraints, that interweaves a medium access control (MAC) layer digital signature into the preamble signals at the physical (PHY) layer to counter these attacks. The approach slices the signature and embeds the slices within CE frame preambles without extending frame size, allowing one or multiple stations to concurrently verify their respective APs' transmissions in enterprise and public Wi-Fi networks. The scheme supports concurrent CEs by enabling each station to analyze the consistent patterns of PHY-layer headers to determine whether the received frames are the anticipated ones from the expected APs, achieving 100% accuracy without needing to inspect MAC layer headers. Additionally, we design and implement a fast relay attack to challenge our defense's effectiveness. We extend existing open-source tools to support IEEE 802.11ax to evaluate the effectiveness and practicality of our scheme on a testbed consisting of universal software radio peripherals (USRPs), commercial APs, and Wi-Fi devices. Our results show that the proposed relay attack detection achieves 96-100% true positive rates. Finally, end-to-end formal analyses confirm the security and correctness of the proposed solution. Naureen Hoque, Hanif Rahbari |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Deep Learning Models as Moving Targets to Counter Modulation Classification AttacksabstractMalicious entities abuse advanced modulation classification (MC) techniques to launch traffic analysis, selective jamming, evasion, and poison attacks. Recent studies show that current defenses against such attacks are static in nature and vulnerable to persistent adversaries who invest time and resources into learning the defenses, thereby being able to design and execute more sophisticated attacks to circumvent them. In this paper, we present a moving-target defense framework to support a novel modulation-masking mechanism we develop against advanced and persistent MC attacks. The modulated symbols are first masked using small perturbations to make them appear to an adversary in a state of ambiguity about the model as if they are from another modulation scheme. By deploying a pool of deep learning models and perturbation-generating techniques, our defense strategy keeps changing (moving) them as needed, making it difficult (cubic time complexity) for adversaries to keep up with the evolving defense system over time. We show that the overall system performance remains unaffected under our technique. We further demonstrate that, over time, a persistent adversary can learn and eventually circumvent our masking technique, along with other existing defenses, unless a moving target defense approach is adopted. Naureen Hoque, Hanif Rahbari |
INFOCOM | 2 |
| 2024 | When Cryptography Needs a Hand: Practical Post-Quantum Authentication for V2V Communications
Geoff Twardokus, Nina Bindel, Hanif Rahbari, Sarah McCarthy |
NDSS | 3 |
| 2024 | Fair and Secure 5G and Wi-Fi Coexistence Using Robust Implicit Channel Coordinationabstract5G and Wi-Fi systems are embracing coexistence in the unlicensed portions of the 5–7 GHz bands recently allocated by FCC to support the increasing data rate demands for the growing number of wireless users. To achieve fair and effective spectrum sharing, both 5G and Wi-Fi rely on carrier sensing for medium access. However, differences in sensing thresholds create an unfair advantage for 5G nodes, as they access the medium more aggressively and degrade the data rate and latency of Wi-Fi users. We first demonstrate how an adversary can stealthily exploit this unfairness to further reduce the spectrum occupancy of Wi-Fi nodes, effectively denying Wi-Fi services. Accordingly, in this paper, we propose a novel implicit channel coordination (ICC) approach to both mitigate starvation attacks and improve spectrum access fairness under practical considerations like noise and strong adversaries who try to circumvent our technique. In ICC, Wi-Fi access points (APs) influence 5G gNBs into choosing a precoding matrix that nearly nullifies 5G downlink signals at the APs, enabling concurrent gNB and AP transmissions while accounting for a hidden terminal problem this creates. We theoretically analyze and show that our ICC mitigates novel attacks we have identified, and experimentally demonstrate on a USRP testbed its resilience against starvation attacks. Our design outperforms prior work by achieving an overall 30% higher data rate of the 5G and Wi-Fi coexistence system, 3x improvement in spectrum access fairness, and 1.5x in system capacity, all while conforming with the latency requirements of 5G. Siddharth Dongre, Hanif Rahbari |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Countering Relay and Spoofing Attacks in the Connection Establishment Phase of Wi-Fi SystemsabstractTo establish a secure Wi-Fi connection, a station first exchanges several unprotected management frames with an access point (AP) to eventually authenticate each other and install a pairwise key. It is, therefore, possible for an adversary to spoof elements of those unprotected frames at the physical (PHY) or MAC layers, facilitating additional attacks (e.g., man-in-the-middle and starvation attacks). Despite a few ad hoc efforts, there is still no practical way to counter these attacks jointly. In this paper, we propose practical schemes to employ cryptography at the PHY layer combined with a time-bound technique to detect and mitigate such attacks in enterprise and 802.1X-based public networks. Our backward-compatible schemes embed a digital signature of the AP (or a message authentication code) in frame preamble signals and add only a negligible delay to the connection establishment process and achieve a 98.9% true positive rate in detecting an attacker who tries to relay valid preambles. Furthermore, we conduct a formal security analysis of our scheme using a model checker and a cryptographic protocol verifier and evaluate its performance in a commercial AP-and-USRP~testbed. Naureen Hoque, Hanif Rahbari |
WISEC | 2 |
| 2023 | Circumventing the Defense against Modulation Classification AttacksabstractModulation classification (MC) has a wide range of applications in spectrum sharing, management, and enforcement and can also be used by an adversary to launch traffic analysis or selective jamming. While recent modulation obfuscation techniques show promising results in mitigating MC attacks, in this paper we develop a novel convolution neural network (CNN)-based model to attack those defenses and successfully identify the true modulation scheme. Our extensive simulation and over-the-air experiments using show that our classification technique achieves around 85-99% accuracy for SNR levels 0 dB and above. Furthermore, our results demonstrate that the proposed model can effectively differentiate between obfuscated and non-obfuscated symbols, even when a transmitter switches between them as a new defense mechanism, achieving an accuracy of 95%. Naureen Hoque, Hanif Rahbari |
WISEC | 2 |
| 2023 | Adaptive Preamble Embedding With MIMO to Support User-Defined Functionalities in WLANsabstractAs the Wi-Fi technology transitions into its sixth generation (Wi-Fi 6), there is a growing consensus on the need to support security and coordination functions at the Physical (PHY) layer. In contrast to the costly approach of extending the PHY-layer header to support new functions (e.g., Spatial Reuse field in the Wi-Fi 6 frame), we propose to turn specific parts of the frame preamble into a reliable data field while maintaining its primary functions. Specifically, in this paper, we develop a scheme calledextensible preamble modulation (eP-Mod)for 802.11n/ac/ax protocols that are built on multiple-input-multiple-output (MIMO) and orthogonal frequency-division multiplexing (OFDM). For each frame,eP-Modcan embed up to 144 user bits into the 802.11ac preamble of an$8\times 8$MIMO$40\;$MHz transmission. The proposed scheme is adaptive to channel conditions and enables several promising PHY-layer services, such as PHY-layer encryption and channel/device authentication, and PHY-layer signaling. At the same time, it allows legacy (eP-Mod-unaware) devices to continue to process the received preamble as normal by guaranteeing that the proposed preamble waveforms satisfy the structural properties of a standardized preamble. Through numerical analysis, extensive simulations, and hardware experiments, we validate the practicality and reliability ofeP-Mod. Zhengguang Zhang 0001, Hanif Rahbari, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Toward Protecting 5G Sidelink Scheduling in C-V2X Against Intelligent DoS Attacksabstract5G Cellular Vehicle-to-Everything (5G C-V2X) is emerging as the globally dominant connected vehicle technology. One critical application of 5G C-V2X is the direct exchange of safety-critical messages between vehicles to prevent crashes and correspondingly reduce roadway injuries and fatalities. While current C-V2X security protocols concern only message payloads, we expose vulnerabilities in the physical-layer attributes and decentralized MAC-layer scheduling algorithm of 5G C-V2X by developing two stealthy denial-of-service (DoS) attacks to exploit them. These low-duty-cycle attacks dramatically degrade C-V2X availability, increasing the likelihood of prolonged travel times and even vehicle crashes. We further develop detection and mitigation techniques for each attack, in part by exploiting new C-V2X features of 3GPP Rel-17. We experimentally evaluate our attacks and countermeasures in a hardware testbed composed of USRPs and state-of-the-art C-V2X kits as well as through extensive network and roadway simulations, showing that within seconds of initiation our attacks can reduce a target’s packet delivery ratio by 90% or that of the C-V2X channel to under 25%. We further evaluate our machine-learning detection and low-cost mitigation techniques, showing the latter completely thwart one attack and reduce the impact of the other by 80%, providing insight towards developing a more robust 5G C-V2X. Geoff Twardokus, Hanif Rahbari |
IEEE Trans. Wirel. Commun. | 2 |
| 2022 | Implicit Channel Coordination to Tackle Starvation Attacks in 5G and Wi-Fi Coexistence SystemsabstractDue to the scarcity of spectrum bands, 5G and Wi-Fi systems are embracing coexistence in the unlicensed 5 and 6 GHz bands to support high data rate demands and growing number of users. To provide fair and effective coexistence in shared frequency bands, both technologies rely on carrier sensing. However, differences in sensing thresholds creates an unfair advantage for 5G nodes who access the shared wireless medium more aggressively and degrade the data rate and latency of Wi-Fi nodes. We show in this paper that an adversary who intends to deny service to Wi-Fi can stealthily exploit this unfairness to drastically reduce the spectrum occupancy and data rate of Wi-Fi nodes. We then propose a novel implicit channel coordination (ICC) approach to mitigate the attack and improve sharing fairness. In ICC, Wi-Fi nodes influence 5G gNB into choosing a precoding matrix that nearly nullifies downlink signals at Wi-Fi nodes. We demonstrate our starvation attack on a USRP testbed and further evaluate our proposed ICC approach using simulations. We show that ICC doubles the data rate of a Wi-Fi network subject to an active attack. Siddharth Dongre, Hanif Rahbari |
GLOBECOM | 2 |
| 2022 | Non-cooperative Learning for Robust Spectrum Sharing in Connected Vehicles with Malicious AgentsabstractMulti-agent reinforcement learning (MARL) has pre-viously been employed for efficient spectrum sharing among co-operative connected vehicles. However, we show in this paper that existing MARL models are not robust against non-cooperative or malicious agents (vehicles) whose spectrum selection strategy may cause congestion and reduce the spectrum utilization. For example, a selfish (non-cooperative) agent aims to only maximize its own spectrum utilization, irrespective of the overall system efficiency and spectrum availability to others. We investigate and analyze the MARL-based spectrum sharing problem in connected vehicles including vehicles (agents) with selfish or sabotage strategies. We then develop a theoretical framework to consider the selfish agent, and study various adversarial scenarios (including attacks with disruptive goals) via simulations. Our robust MARL approach where “robust” agents are trained to be prepared for selfish agents in testing phase achieves more resiliency in the presence of a selfish agent and even a sabotage one; achieving 6.7%~20% and 50.7% ~ 138% higher unicast throughput and broadcast delivery success rate over regular benign agents, respectively. Hanif Rahbari, Shanchieh Jay Yang, Li-Chun Wang 0001 |
GLOBECOM | 2 |
| 2022 | Vehicle-to-Nothing? Securing C-V2X Against Protocol-Aware DoS AttacksabstractVehicle-to-vehicle (V2V) communication allows vehicles to directly exchange messages, increasing their situational awareness and offering the potential to prevent hundreds of thousands vehicular crashes annually. Cellular Vehicle-to-Everything (C-V2X), with its LTE-V2X and New Radio (NR)-V2X variants in 4G/LTE- and 5G-based C-V2X, is emerging as the main V2V technology. However, despite security protocols and standards for C-V2X, we expose in this paper that its physical (PHY) and MAC layers are not resilient against intelligent, protocol-aware attacks due to the very predictable PHY-layer structure and vulnerable scheduling algorithm used in both LTE-V2X and NR-V2X. We devise two stealthy denial-of-service (DoS) exploits that dramatically degrade C-V2X availability, thereby increasing the chances of fatal vehicle collisions. We experimentally evaluate our attacks on an integrated, hybrid testbed with USRPs and state-of-the-art LTE-V2X devices as well as through extensive simulations, showing that within seconds, our attacks can reduce a target’s packet delivery ratio by 90% or degrade C-V2X channel throughput by 50%. We propose, analyze, and evaluate detection approaches as well as mitigation techniques to address the vulnerabilities we expose in the C-V2X PHY/MAC layers, providing direction towards better-secured, resilient 5G C-V2X. Geoff Twardokus, Hanif Rahbari |
INFOCOM | 2 |
| 2021 | POSTER: A Tough Nut to Crack: Attempting to Break Modulation ObfuscationabstractDespite being primarily developed for spectrum management, sharing, and enforcement in civilian and military applications, modulation classification can be exploited by an adversary to threaten user privacy (e.g., via traffic analysis), or launch jamming and spoofing attacks. Several existing works study how an adversary can still classify the user traffic despite obfuscation techniques at upper layers, but little work has been done on how an adversary can classify the "modulation scheme'' when it is obfuscated at the physical layer. In this respect, we aim to study how to break the state-of-the-art modulation obfuscation schemes by applying various machine learning (ML) methods. Our preliminary results show that common ML techniques perform poorly in correctly classifying an obfuscated modulation scheme except for the random forest method (with a score as much as twice the other techniques we consider), providing insights on why other techniques, e.g., deep learning, might be more promising for finding underlying correlations. Naureen Hoque, Hanif Rahbari |
CCS | 2 |
| 2021 | Targeted Discreditation Attack against Trust Management in Connected VehiclesabstractVehicle-to-vehicle (V2V) communication systems in the U.S. rely on IEEE 1609.2 security protocols for message authentication using digital signatures. A key requirement for trust management in such systems is the ability to detect misbehaving vehicles, e.g., when vehicles are repeatedly forging signatures. However, this creates a new attack surface where receivers cannot determine whether the causes of signature verification failures are indeed malicious attacks. In this paper, we present our novel, open-source, USRP-based testbed and utilize it to demonstrate how a stealthy reactive jammer can exploit this vulnerability. Our novel, targeted attack is highly efficient (even given the short validity period for vehicle pseudonyms) and difficult to detect. Our experimental results show that our attack can successfully discredit a victim in prominent misbehavior detection schemes with just two minutes of jamming. Finally, we discuss the capabilities and extensibility of our testbed as well as the challenges of potential attack mitigation techniques. Geoff Twardokus, Jaime Ponicki, Samantha Baker, Peter Carenzo, Hanif Rahbari, Sumita Mishra |
ICC | 5 |
| 2021 | Message sieving to mitigate smart gridlock attacks in V2VabstractGrowing deployment of vehicle-to-vehicle (V2V) communications is expected to significantly increase the volume of Basic Safety Messages (BSM) in highways and dense roads. Computational overhead of verifying the integrity of BSMs will therefore be high while current V2V equipment can process only a limited number of BSMs per second. As a result, critical BSMs carrying vital information may fail to be processed on time, creating unsafe outcomes. In this paper, we expose this vulnerability, discuss critical scenarios, develop novel attacks that exploit this vulnerability, and propose a sieving technique to mitigate these verification gridlock attacks. We show on a USRP testbed that our proposed sieving mechanism to counter sophisticated attackers who exploit this vulnerability achieves 80% accuracy at SNR greater than 6 dB, effectively mitigating the attack. Siddharth Dongre, Hanif Rahbari |
WISEC | 2 |
| 2020 | Expanding the Role of Preambles to Support User-defined Functionality in MIMO-based WLANsabstractAs the Wi-Fi technology goes through its sixth generation (Wi-Fi 6), there is a growing consensus on the need to support security and coordination functions at the Physical (PHY) layer, beyond traditional functions such as frame detection and rate adaptation. In contrast to the costly approach of extending the PHY-layer header to support new functions (e.g., Target Wake Time field in 802.11ax), we propose to turn a specific part of the frame preamble into a data field while maintaining its primary functions. Specifically, in this paper, we develop a scheme called extensible preamble modulation (ePMod) for the MIMO-based 802.11ac protocol. For each frame, eP-Mod can embed up to 20 bits into the 802.11ac preamble under 1 × 2 or 2 × 1 MIMO transmission modes to support the operations of a given PHY-layer function. The proposed scheme enables several promising PHY-layer services, such as PHY-layer encryption and channel/device authentication, PHYlayer signaling, etc. At the same time, it allows legacy (eP-Modunaware) devices to continue to process the received preamble as normal by guaranteeing that our proposed preamble waveforms satisfy the structural properties of a standardized preamble. Through numerical analysis, extensive simulations, and hardware experiments, we validate the practicality and reliability of ePMod. Zhengguang Zhang 0001, Hanif Rahbari, Marwan Krunz |
INFOCOM | 2 |
| 2019 | Lightweight Machine Learning for Efficient Frequency-Offset-Aware DemodulationabstractCarrier frequency offset (CFO) arises from the intrinsic mismatch between the oscillators of a wireless transmitter and the corresponding receiver, as well as their relative motion (i.e., Doppler effect). Despite advances in CFO estimation and tracking techniques, estimation errors are still present. Residual CFO creates a time-varying phase error, which degrades the decoder's performance by increasing the symbol error rate. The impact is particularly visible in dense constellation maps (e.g., high-order QAM modulation), often used in modern wireless systems such as 5G NR, 802.11ax, and mmWave, as well as in physical security techniques, such as modulation obfuscation (MO). In this paper, we first derive the probability distribution function for the residual CFO under Gaussian noise. Using this distribution, we compute the maximum-likelihood demodulation boundaries for OFDM signals in a non-closed form. For modulation schemes with unequal-amplitude reference constellation points (e.g., 16-QAM and higher, APSK, etc.), the “optimal” boundaries have irregular shapes, and more importantly, they depend on the time since the last CFO correction instance, e.g., reception of frame preamble. To approximate the optimal boundaries and provide a practical (real-time) demodulation scheme, we explore machine learning techniques, specifically, support vector machine (SVM). Our SVM approach exhibits better accuracy and lower complexity in the test phase than other state-of-the-art machine-learning approaches. As a case study, we apply our CFO-aware demodulation to enhance the performance of a MO technique. Our analytical results show a gain of up to 3dB over conventional demodulation schemes, which exceeds 3dB in complete system simulations. Finally, we implement our scheme on USRPs and experimentally corroborate our analytic and simulation-based findings. Peyman Siyari, Hanif Rahbari, Marwan Krunz |
IEEE J. Sel. Areas Commun. | 2 |
| 2018 | Adaptive Demodulation for Wireless Systems in the Presence of Frequency-Offset Estimation ErrorsabstractCarrier frequency offset (CFO) arises from the intrinsic mismatch between the operating frequencies of the transmitter and the receiver, as well as their relative speeds (i.e., Doppler effect). Despite advances in CFO estimation techniques, estimation errors are still present. Residual CFO creates time-varying phase error. Modern wireless systems, including WLANs, 5G cellular systems, and satellite communications, use high-order modulation schemes, which are characterized by dense constellation maps. Accounting for the phase error is critical for the demodulation performance of such schemes. In this paper, we analyze the post-estimation probability distribution of residual CFO and use it to develop a CFO-aware demodulation approach for a set of modulation schemes (e.g., QAM and APSK). For a given distribution of the residual CFO, symbols with larger amplitudes are less densely distributed on the constellation map. We explore one important application of our adaptive demodulation approach in the context of PHY-layer security, and more specifically modulation obfuscation (MO) mechanisms. In such mechanisms, the transmitter attempts to hide the modulation order of a frame's payload from eavesdroppers, which could otherwise exploit such information to breach user privacy or launch selective attacks. We go further and complement our CFO-aware demodulation scheme by optimizing the design of a low-complexity MO technique with respect to phase errors. Our results show that when combined, our CFO-aware demodulation and optimized MO techniques achieve up to 5 dB gain over conventional demodulation schemes that are not obfuscated and are oblivious to residual CFO. Hanif Rahbari, Peyman Siyari, Marwan Krunz, Jung-Min Park 0001 |
INFOCOM | 1 |
| 2017 | Exploiting Frame Preamble Waveforms to Support New Physical-Layer Functions in OFDM-Based 802.11 SystemsabstractThe frame preamble in current WiFi systems is designed to facilitate various PHY-layer functions, including frequency offset estimation and frame detection. However, this preamble is typically fixed and is never used to convey any user-specific bits. Embedding information into the preamble opens the door for several new PHY-layer applications. For example, the PHY header no longer needs to be transmitted at a known (lowest) rate if this rate can be announced earlier in the preamble. A full-duplex transmitter can use the embedded information to inform other devices of its current operation mode (e.g., transmit/receive versus transmit/sense), obviating the need for additional control packets. In security applications, a PHY-layer sender identifier can be embedded in the preamble to facilitate PHY-level encryption. However, modifying the standard preamble to embed user information may disrupt the operation of 802.11a/n/ac devices. In this paper, we propose P-modulation, a method that enables an OFDM-based 802.11 transmitter to embed up to 19 user-specific bits in the frame preamble while maintaining the highest reliability required by the system. The proposed P-modulation is also backward-compatible with legacy receivers. Our analysis and USRP-based experimental results confirm the practicality of the scheme. Our scheme further provides insights into designing time-varying preambles for future wireless systems. Hanif Rahbari, Marwan Krunz |
IEEE Trans. Wirel. Commun. | 1 |
| 2016 | Full Frame Encryption and Modulation Obfuscation Using Channel-Independent Preamble IdentifierabstractThe broadcast nature of wireless communications exposes various transmission attributes, such as the packet size, inter-packet times, and the modulation scheme. These attributes can be exploited by an adversary to launch passive (e.g., traffic analysis) or selective jamming attacks. This security problem is present even when frame headers and payloads can be encrypted. For example, by determining the modulation scheme, the attacker can estimate the data rate, and hence the payload size. In this paper, we propose Friendly CryptoJam (FCJ), a scheme that decorrelates the payload's modulation scheme from other transmission attributes by embedding information symbols into the constellation map of the highest-order modulation scheme supported by the system (a concept we refer to as indistinguishable modulation unification). Such unification is done using the least-complex trellis-coded modulation schemes, which are combined with a secret pseudo-random sequence in FCJ to conceal the rate-dependent pattern imposed by the code. It also preserves the bit error rate performance of the payload's original modulation scheme. At the same time, modulated symbols are encrypted to hide PHY-/MAC layer fields. To identify the Tx and synchronously generate the secret sequence at the Tx and Rx, an efficient identifier embedding technique based on Barker sequences is proposed, which exploits the structure of the preamble and overlays a frame-specific identifier on it. We study the implications of the scheme on PHY-layer functions through simulations and testbed experiments. Our results confirm the efficiency of FCJ in hiding the targeted attributes. Hanif Rahbari, Marwan Krunz |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Swift Jamming Attack on Frequency Offset Estimation: The Achilles' Heel of OFDM SystemsabstractFrequency offset (FO) refers to the difference in the operating frequencies of two radio oscillators. Failure to compensate for the FO may lead to decoding errors, particularly in OFDM systems. To correct the FO, wireless standards append a publicly known preamble to every frame before transmission. In this paper, we demonstrate how an adversary can exploit the known preamble structure of OFDM-based wireless systems, particularly IEEE802.11a/g/n/ac, to launch a very stealth (low energy/duty cycle) reactive jamming attack against the FO estimation mechanism. In this attack, the adversary quickly detects a transmitted OFDM frame and subsequently jams a tiny part of the preamble that is used for FO estimation at the legitimate receiver. By optimizing the energy and structure of the jamming signal and accounting for frame detection timing errors and unknown channel parameters, we empirically show that the adversary can induce a bit error rate close to$0.5$, making the transmission practically irrecoverable. Such vulnerability to FO jamming exists even when the frame is shielded by efficient channel coding. We evaluate the FO estimation attack through simulations and USRP experimentation. We also propose three approaches to mitigate such an attack. Hanif Rahbari, Marwan Krunz, Loukas Lazos |
IEEE Trans. Mob. Comput. | 1 |
| 2015 | Supporting PHY-Layer Security in Multi-Link Wireless Networks Using Friendly JammingabstractFriendly jamming is a PHY-layer technique used to secure wireless communications. Unlike previous efforts that fix the placement of the friendly jamming devices, in this paper we consider small- scale multi-link wireless networks, e.g., peer-to- peer or multihop, and jointly optimize the powers and locations of the friendly jamming devices so as to minimize the total jamming power while simultaneously achieving a given secrecy constraint. We use distributed MIMO techniques and incorporate the necessary conditions to ensure nullification of the friendly jamming signals at legitimate receivers. Two optimization strategies are explored: per-link and network-wide. Our optimization framework is based on formulating a signomial programming problem using condensation techniques to approximate the problem as a geometric program, which can then be transformed into a convex problem. We also consider the secrecy-aware routing problem for multihop networks and propose a routing metric based on the total jamming power along the path. Simulations show that our proposed schemes outperform previous schemes in terms of energy efficiency (55%-99% power saving). Moreover, our formulation ensures protecting legitimate transmissions by nullifying friendly jamming signals at legitimate receivers. Rashad Eletreby, Hanif Rahbari, Marwan Krunz |
GLOBECOM | 2 |
| 2015 | Multicast Rendezvous in Fast-Varying DSA NetworksabstractEstablishing communications between devices in a dynamic spectrum access (DSA) system requires the communicating parties to “rendezvous” before transmitting data packets. Frequency hopping (FH) is an effective rendezvous method that does not rely on a predetermined control channel. Previous FH-based rendezvous designs mainly target unicast rendezvous, and do not intrinsically support multicast rendezvous, where a group of nodes need to rendezvous simultaneously. Furthermore, these designs do not account for fast-primary user (PU) dynamics, leading to long time-to-rendezvous (TTR). In this paper, we exploit the uniform k-arbiter and Chinese Remainder Theorem quorum systems to develop three FH-based multicast rendezvous algorithms, which provide different tradeoffs between rendezvous efficiency (e.g., low TTR) and security (e.g., robustness to node compromise). Our rendezvous algorithms are tailored for asynchronous and spectrum-heterogeneous DSA systems. To account for fast PU dynamics, we develop an algorithm for adapting the proposed FH designs on the fly. This adaptation is done through efficient mechanisms for channel ordering and quorum selection. Our simulations validate the effectiveness of the proposed rendezvous algorithms, their PU detection accuracy, and their robustness to insider attacks. Mohammad Abdel-Rahman, Hanif Rahbari, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2014 | Security vulnerability and countermeasures of frequency offset correction in 802.11a systemsabstractFrequency offset (FO) is an inherent feature of wireless communications. It results from differences in the operating frequency of different radio oscillators. Failure to compensate for the FO may lead to a decoding failure, particularly in OFDM systems. IEEE 802.11a/g systems use a globally known preamble to deal with this issue. In this paper, we demonstrate how an adversary can exploit the structure and publicity of 802.11a's frame preamble to launch a low-power reactive jamming attack against the FO estimation mechanism. In this attack, the adversary will need to quickly detect a PHY frame and subsequently distort the FO estimation mechanism, irrespective of the channel conditions. By employing a fast frame detection technique, and optimizing the energy and structure of the jamming signal, we show the feasibility of such an attack. Furthermore, we propose some mitigation techniques and evaluate one of them through simulations and USRP testbed experimentation. Hanif Rahbari, Marwan Krunz, Loukas Lazos |
INFOCOM | 1 |
| 2014 | Friendly CryptoJam: a mechanism for securing physical-layer attributesabstractThe broadcast nature of wireless communications exposes various "transmission attributes," such as the packet size, the inter-packet times, and the modulation scheme. These attributes can be exploited by an adversary to launch passive or active attacks. A passive attacker threatens user's privacy and confidentiality by performing traffic analysis and classification, whereas an active attacker exploits captured attributes to launch selective jamming/dropping attacks. This so-called PHY-layer security problem is present even when the payload is encrypted. For example, by determining the modulation scheme, the attacker can estimate the data rate, and hence the payload size, and later use it to launch traffic classification or selective rate-adaptation attacks. Hanif Rahbari, Marwan Krunz |
WISEC | 1 |
| 2013 | Fast and secure rendezvous protocols for mitigating control channel DoS attacksabstractThe operation of a wireless network relies extensively on exchanging messages over a universally known channel, referred to as the control channel. The network performance can be severely degraded if a jammer launches a denial-of-service (DoS) attack on such a channel. In this paper, we design quorum-based frequency hopping (FH) algorithms that mitigate DoS attacks on the control channel of an asynchronous ad hoc network. Our algorithms can establish unicast as well as multicast communications under DoS attacks. They are fully distributed, do not incur any additional message exchange overhead, and can work in the absence of node synchronization. Furthermore, the multicast algorithms maintain the multicast group consistency. The efficiency of our algorithms is shown by analysis and simulations. Mohammad Abdel-Rahman, Hanif Rahbari, Marwan Krunz, Philippe Nain |
INFOCOM | 2 |