Angelos Stavrou

dblp:14/5349 · DBLP profile ↗
← Back
110ranked-venue papers
9as first author
37since 2021 · last 2026
0000-0001-9888-0592ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 68 · 6 first-author · 12 since 2021Computer networks · 27 · 3 first-author · 19 since 2021Systems, architecture and hardware · 12 · 5 since 2021Databases, data management, data science and information retrieval · 4Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Towards Securing Access Control in 5G and Beyond with Zero Trust
abstract
The Fifth Generation (5G) specifications have set a precedent for the evolution of next-generation mobile networks. Standardized interfaces and Network Function Virtualization (NFV) technology enable network operators to break free from vendor lock-in, while delivering more customized and agile services to their customers. However, the heterogeneous and multi-vendor composition of the Next-Generation Network (NGN), as envisioned in 5G specifications, also expands the existing attack surface and complicates trust relationships. Consequently, the traditional perimeter-based security model has become inadequate for effectively ensuring trust in such a complex network environment. On the other hand, Zero Trust has emerged as a promising security model well-suited for protecting complex and large-scale networks. Unfortunately, the current access control mechanism in the 5G core network lacks key features, rendering it incompatible with Zero Trust principles. To bridge this gap, we introduce the Continual Access Monitoring (CAM) framework that enables operators to seamlessly incorporate key security metrics into the existing access control mechanism. Furthermore, CAM introduces continual access policy evaluation, a critical requirement of the Zero Trust paradigm. The CAM framework illustrates a practical strategy for integrating Zero Trust principles into the 5G service-based architecture and scales efficiently in large 5G deployments, supporting access policy monitoring for up to 6,000 network functions at an operational cost of USD 0.2 per hour on AWS.
Sudip Maitra, Kenechukwu Nwodo, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
CODASPY4
2026 VulLens: Enhancing Software Vulnerability Detection against Evasion Attacks
Shihua Sun, Sudip Maitra, Angelos Stavrou, Haining Wang 0001
DSN4
2026 RAIDER: A Lightweight UAV-Based Relay Mesh and Edge VNF Framework for Tactical Connectivity
Tolga O. Atalay, Alireza Famili, Amirreza Ghafoori, Angelos Stavrou
ICC4
2026 SlicePilot: Demystifying Network Slice Placement in Heterogeneous Cloud Infrastructures
Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas
INFOCOM4
2026 5GC-Bench: A Framework for Stress-Testing and Benchmarking 5G Core VNFs
abstract
The disaggregated, cloud-native design of the 5G Core (5GC) enables flexibility and scalability but introduces significant challenges. Control-plane procedures involve complex interactions across multiple Virtual Network Functions (VNFs), while the user plane must sustain diverse and resource-intensive traffic. Existing tools often benchmark these dimensions in isolation, rely on synthetic workloads, or lack visibility into fine-grained resource usage. This paper presents 5GC-Bench, a modular framework for stress-testing the 5GC under realistic workloads. 5GC-Bench jointly emulates signaling and service traffic, supporting both VNF profiling and end-to-end service-chain analysis. By characterizing bottlenecks and resource demands, it provides actionable insights for capacity planning and performance optimization. We integrated 5GC-Bench with the OpenAirInterface (OAI) 5GC and deployed it on a real 5G testbed, demonstrating its ability to uncover resource constraints and expose cross-VNF dependencies under scenarios that mirror operational 5G deployments. To foster reproducibility and further research, we release publicly all the artifacts.
Ioannis Panitsas, Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Leandros Tassiulas
WCNC4
2025 5G-STREAM: Service Mesh Tailored for Reliable, Efficient and Authorized Microservices in the Cloud
abstract
Existing registration, discovery, and authorization mechanisms in the 5G core control plane present scalability and efficiency challenges. As cellular deployments scale to accommodate diverse user demands, the 5G core control plane suffers from increased inter-Virtual Network Function (VNF) communication latency, thus deteriorating the reliability of critical procedures. To address this problem, we propose 5G-STREAM (Service mesh Tailored for Reliable, Efficient, and Authorized Microservices) to optimize control plane traffic in distributed cloud environments by establishing a topology awareness of service chains across cloud hierarchies. Leveraging this awareness, 5G-STREAM dynamically configures communication pathways to reduce discovery and authorization signaling overhead, thus increasing the reliability of inter-VNF communication. We develop a prototype of 5G-STREAM and evaluate its performance. Our evaluation results show that 5G-STREAM significantly reduces the process completion time in core service chains by up to 2× inter VNF-Network Repository Function (NRF) latency per transaction, with more pronounced benefits in larger service chains. Furthermore, we show that the cost required to deploy 5G-STREAM is an additional 0.1 USD/hr on AWS for a VNF handling a sustained rate of 50,000 requests/minute.
Tolga O. Atalay, Alireza Famili, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
DSN5
2025 HEAL: Healthcare Robot Localization using Efficient Anchor Layout
Alireza Famili, Tolga O. Atalay, Angelos Stavrou
HealthCom3
2025 5G-MAP: Demystifying the Performance Implications of Cloud-Based 5G Core Deployments
abstract
The Fifth Generation (5G) core network is designed as a set of Virtual Network Functions (VNFs) hosted on Commercial-Off-the-Shelf (COTS) hardware. This creates a growing demand for general-purpose computing resources. Given their elastic infrastructure, cloud services like Amazon Web Services (AWS) are attractive platforms to address this need. Therefore, it is crucial to understand the Quality of Service (QoS) requirements associated with deploying the 5G core in the cloud. We developed the 5G-MAP (5G Measurement and Assessment Platform) to understand the trade-offs between different deployment strategies. Our framework facilitates detailed control and user plane performance assessments in varied deployment scenarios. We integrated 5G-MAP with the OpenAirInterface (OAI) 5G core and utilized it in a series of deployments across seven countries, leveraging eight AWS regions and eighteen edge zones. Our evaluations cover from HTTP transactions to user plane throughput and packet loss. We identify topologies that can considerably lower the 5G core service chain latencies due to a significant reduction in the number of inter-site hops. Such actionable performance improvements illustrate how operators can leverage 5G-MAP to optimize their cloud-based 5G deployments.
Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001
MobiCom4
2025 Precise Positioning for Healthcare Robotics with Retroreflective Tags in 5G Small Cell Networks
Alireza Famili, Tolga O. Atalay, Angelos Stavrou
Networking3
2025 Enhancing Secure Communication: Deep Q-Learning for Location-Based Authentication
abstract
In the evolving landscape of next-generation wireless networks, ensuring secure communications in covert military operations is paramount. This paper proposes an advanced localization-based security system utilizing passive receivers and Time Difference of Arrival (TDOA) techniques to continuously authenticate the signals of a commander in dynamic operational scenarios. Our system effectively counters physical layer spoofing attacks by distinguishing between the precise locations of a legitimate entity and potential adversaries. To that end, we derive the positioning error bound (PEB) specific to TDOA systems, emphasizing the critical impact of receiver arrangement on localization accuracy. Furthermore, we introduce a novel application of deep Q-learning for the NP-hard problem of optimal placement of receivers, addressing the challenge of spatial geometry, which significantly influences localization accuracy. Through extensive testing, we demonstrate that our proposed approach notably outperforms traditional placement methods in mitigating geometry-induced errors and enhancing overall localization precision. Ultimately, this facilitates realizing and maintaining a secure zone where users can authenticate each other through localization.
Alireza Famili, Shihua Sun, Tolga O. Atalay, Angelos Stavrou
NOMS4
2025 Leveraging Isochrons of Nonlinear Oscillators for High-Precision Localization
abstract
Precisely measuring the location of moving objects has been a long-standing research challenge. Here, we present a highly accurate 3-D positioning system named LIO: localization using isochrons in oscillators. LIO precisely measures the Time of Arrival (ToA) of incoming radio frequency (RF) signals employing a novel timing protocol. The proposed protocol measures ToA leveraging the phase shifts of limit cycle oscillators based on their isochrons’ structure. These ToA measurements are then translated into distances and are employed in LIO for high-accuracy 3-D positioning. Moreover, LIO utilizes a passive-round-trip-time (passive-RTT) protocol leveraging retro-reflective tags to address and enhance the synchronization challenge. We derive LIO’s positioning error bound (PEB) and attribute the localization error to ranging- and geometry-induced errors. While our primary objective in this work is to address the former source of error, we also provide a novel optimization framework to mitigate the geometry-induced errors by proposing optimal anchor placements. Lastly, we assess the performance of LIO by designing comprehensive simulations using real-world operational parameters for commercially available semiconductor laser oscillators. Our numerical results indicate that LIO achieves distance estimation with the accuracy of subtenth of the millimeter (mm) and overall 3-D localization with sub-1 mm accuracy. This is at least an order of magnitude better compared to the existing technologies.
Alireza Famili, Georgia Himona, Yannis Kominis, Angelos Stavrou, Vassilios Kovanis
IEEE Internet Things J.4
2025 An OpenRAN Security Framework for Scalable Authentication, Authorization, and Discovery of xApps With Isolated Critical Services
abstract
The OpenRAN initiative promotes an open Radio Access Network (RAN) and offers operators fine-grained control over the radio stack. To that end, O-RAN introduces new components to the 5G ecosystem, such as the near real-time RAN Intelligent Controller (near-RT RIC) and the accompanying extensible Applications (xApps). The introduction of these entities expands the 5G threat surface. Furthermore, with the movement from proprietary hardware to virtual environments enabled by Network Functions Virtualization (NFV), attack vectors that exploit the existing NFV attack surface pose additional threats. To deal with these threats, we propose the xApp repository function (XRF) framework for scalable authentication, authorization, and discovery of xApps. To harden the XRF microservices, we isolate them using Intel Software Guard Extensions (SGX). We benchmark the XRF modules individually and compare how different microservices behave in terms of computational overhead when deployed in virtual and hardware-based isolation sandboxes. Our evaluation shows that the XRF framework scales efficiently in a multi-threaded Kubernetes environment. The isolation of the XRF microservices introduces different amounts of processing overhead depending on the sandboxing strategy. Finally, a security analysis is conducted to show how the XRF framework addresses chosen key issues from the O-RAN and 5G standardization efforts.
Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Partner in Crime: Boosting Targeted Poisoning Attacks Against Federated Learning
Shihua Sun, Shridatt Sugrim, Angelos Stavrou, Haining Wang 0001
IEEE Trans. Inf. Forensics Secur.3
2024 ViTGuard: Attention-aware Detection against Adversarial Examples for Vision Transformer
abstract
The use of transformers for vision tasks has challenged the traditional dominant role of convolutional neural networks (CNN) in computer vision (CV). For image classification tasks, Vision Transformer (ViT) effectively establishes spatial relationships between patches within images, directing attention to important areas for accurate predictions. However, similar to CNNs, ViTs are vulnerable to adversarial attacks, which mislead the image classifier into making incorrect decisions on images with carefully designed perturbations. Moreover, adversarial patch attacks, which introduce arbitrary perturbations within a small area (usually less than 3% of pixels), pose a more serious threat to ViTs. Even worse, traditional detection methods, originally designed for CNN models, are impractical or suffer significant performance degradation when applied to ViTs, and they generally overlook patch attacks.In this paper, we propose ViTGuard as a general detection method for defending ViT models against adversarial attacks, including typical attacks where perturbations spread over the entire input (Lpnorm attacks) and patch attacks. ViTGuard uses a Masked Autoencoder (MAE) model to recover randomly masked patches from the unmasked regions, providing a flexible image reconstruction strategy. Then, threshold-based detectors leverage distinctive ViT features, including attention maps and classification (CLS) token representations, to distinguish between normal and adversarial samples. The MAE model does not involve any adversarial samples during training, ensuring the effectiveness of our detectors against unseen attacks. ViTGuard is compared with seven existing detection methods under nine attacks across three datasets with different sizes. The evaluation results show the superiority of ViTGuard over existing detectors. Finally, considering the potential detection evasion, we further demonstrate ViTGuard’s robustness against adaptive attacks for evasion.
Shihua Sun, Kenechukwu Nwodo, Shridatt Sugrim, Angelos Stavrou, Haining Wang 0001
ACSAC4
2024 Towards Shielding 5G Control Plane Functions
abstract
Network Functions Virtualization (NFV) enables flexible and scalable 5G core deployment but it also introduces new attack vectors into the mobile network ecosystem, especially when network functions are deployed on public cloud infrastructure. To address this issue, Third Generation Partnership Project (3GPP) standardization body recommends isolating critical 5G core functionalities inside Hardware Mediated Execution Enclaves (HMEEs). However, the use of HMEEs can incur debilitating QoS degradation in control plane functions including Authentication and Key Agreement (AKA) protocol. In this paper, we design and implement network slices with HMEE-enforced isolation for sensitive AKA functions and characterize their performance. Our findings reveal that the use of HMEE leads to 1.2 to 1.5× increase in function execution time and 2.2 to 2.9× increase in response time for the isolated containers. While appearing very large, this overhead is a small fraction of the end-to-end session setup latency. To evaluate the feasibility of HMEE, we use a real commercial User Equipment (UE) to register with the 5G core network through the isolated AKA functions. Finally, we discuss the role of HMEEs in addressing the key issues introduced by NFV.
Sudip Maitra, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
DSN3
2024 Stars and Towers on the Wheels: Global Perspective on Satellite Networks vs. Terrestrial 5G
abstract
In this paper, we present a comparative study of the performance of multiple terrestrial 5G networks and Starlink’s satellite service. To that end, we conduct comprehensive mobile measurements over an 860+ km route, incorporating a diverse range of terrains, speeds, and cell tower coverage. Our study focuses on two metrics: throughput and latency both locally and as perceived by global servers. This approach provides novel insights into the operational performance of terrestrial 5G and non-terrestrial networks (NTN), in particular satellite networks, in real-world driving scenarios. Our aim is to present the trade-offs between network types, geography, and infrastructure in high-mobility scenarios. Our findings suggest that terrestrial 5G networks, particularly Verizon, exhibit high peak downlink throughput. However, the satellite network (Starlink) offers a compelling case for consistent performance, particularly lower latency, across various regions and driving speeds. Moreover, Starlink performs seamlessly in rural areas, where 5G network providers offer little to no coverage. Our analysis shows that combining terrestrial 5G and satellite network service offers suitable throughput and latency for next-generation applications.
Amirreza Ghafoori, Alireza Famili, Angelos Stavrou
GLOBECOM3
2024 RAPID: Reinforcement Learning-Aided Femtocell Placement for Indoor Drone Localization
abstract
Mobile networks are swiftly advancing to accommodate the burgeoning spectrum of applications. The architecture of 5G networks integrates the principle of network slices, logically isolated end-to-end segments tailored to offer specific services. In this architectural schema, drones have emerged as a significant service category. Achieving the successful deployment of drone networks is heavily contingent upon the ability to accurately localize them in a three-dimensional (3D) setting, beyond the critical requirement for tight latency control. Transitioning from 4G to 5G, these networks are characterized by their operation at elevated frequency spectrums and more densely packed deployment configurations. Within such environments, the task of ensuring precise indoor localization poses a significant challenge, primarily due to the distinctive signal behavior at higher frequencies. To achieve this goal, we propose the RAPID framework, utilizing foundational principles from the third-generation partnership project (3GPP) to design a radio access network (RAN) that includes 5G femtocells. This architecture aims to shift positioning responsibilities from outdoor base stations (BSs) to improve indoor localization performance. Our study’s principal contribution is the demonstration of how the spatial distribution of 5G femtocells significantly influences the accuracy of drone positioning. To address the challenges inherent in femtocell deployment, we develop an innovative optimization framework coupled with a deep reinforcement learning (DRL) strategy, aimed at solving the NP-hard problem. Our findings reveal that adopting our DRL-based placement strategy significantly improves positioning accuracy compared to regular arbitrary deployment approaches.
Alireza Famili, Amin Tabrizian, Tolga O. Atalay, Angelos Stavrou
ICCCN4
2024 5G-WAVE: A Core Network Framework with Decentralized Authorization for Network Slices
abstract
5G mobile networks leverage Network Function Virtualization (NFV) to offer services in the form of network slices. Each network slice is a logically isolated fragment constructed by service chaining a set of Virtual Network Functions (VNFs). The Network Repository Function (NRF) acts as a central OpenAuthorization (OAuth) 2.0 server to secure inter-VNF communications resulting in a single point of failure. Thus, we propose 5G-WAVE, a decentralized authorization framework for the 5G core by leveraging the WAVE framework and integrating it into the OpenAirInterface (OAI) 5G core. Our design relies on Side-Car Proxies (SCPs) deployed alongside individual VNFs, allowing point-to-point authorization. Each SCP acts as a WAVE engine to create entities and attestations and verify incoming service requests. We measure the authorization latency overhead for VNF registration, 5G Authentication and Key Agreement (AKA), and data session setup and observe that WAVE verification introduces 155ms overhead to HTTP transactions for decentralizing authorization. Additionally, we evaluate the scalability of 5G-WAVE by instantiating more network slices to observe 1.4x increase in latency with 10x growth in network size. We also discuss how 5G-WAVE can significantly reduce the 5G attack surface without using OAuth 2.0 while addressing several key issues of 5G standardization.
Tolga O. Atalay, Hans-Andrew Gibbs, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
INFOCOM5
2024 Precision Tracking in Geofencing Systems using Deep Reinforcement Learning
abstract
Geofencing technologies have emerged as crucial tools in establishing virtual boundaries within both physical and digital spaces, providing a secure method to manage and supervise specified zones. They are now recognized as vital instruments for delineating and managing boundaries in a range of applications, from ensuring aviation safety in drone operations to regulating access in mixed reality environments such as the metaverse. Successful geofencing depends significantly on accurate tracking, which is essential for preserving the integrity and effectiveness of these systems. Utilizing the benefits of 5G technology, such as its broad bandwidth and widespread availability, offers a promising approach to improve geofencing performance. In this paper, we present DEFENCE: Deep Reinforcement Learning for Geofencing Enhancement, an innovative method for precise geofencing that utilizes "5G Points" within indoor 5G small cell networks, optimally placed using a deep Q-learning framework. Through the computation of the Cramér-Rao Lower Bound (CRLB), we evaluate tracking errors arising from spatial configurations and ranging inaccuracies. Our proposed deep Q-learning model tackles the NP-hard challenge of identifying the optimal placement of 5G Points to reduce errors caused by spatial geometry. We implemented an extensive testing campaign to assess the efficacy of DEFENCE. Our findings reveal that this strategic deployment enhances tracking accuracy by a factor of 100 over conventional placement methods. This breakthrough considerably bolsters geofencing systems, enhancing their defense against potential threats such as unauthorized drone incursions and security breaches within metaverse environments.
Alireza Famili, Shihua Sun, Tolga O. Atalay, Angelos Stavrou
IPCCC4
2024 FedMADE: Robust Federated Learning for Intrusion Detection in IoT Networks Using a Dynamic Aggregation Method
Shihua Sun, Kenechukwu Nwodo, Angelos Stavrou, Haining Wang 0001
ISC (2)4
2024 All in one: Improving GPS accuracy and security via crowdsourcing
Mahsa Foruhandeh, Hanchao Yang, Angelos Stavrou, Haining Wang 0001, Yaling Yang
Comput. Networks4
2024 A multiview clustering framework for detecting deceptive reviews
abstract
Online reviews, which play a key role in the ecosystem of nowadays business, have been the primary source of consumer opinions. Due to their importance, professional review writing services are employed for paid reviews and even being exploited to conduct opinion spam. Posting deceptive reviews could mislead customers, yield significant benefits or losses to service vendors, and erode confidence in the entire online purchasing ecosystem. In this paper, we ferret out deceptive reviews originated from professional review writing services. We do so even when reviewers leverage a number of pseudonymous identities to avoid the detection. To unveil the pseudonymous identities associated with deceptive reviewers, we leverage the multiview clustering method. This enables us to characterize the writing style of reviewers (deceptive vs normal) and cluster the reviewers based on their writing style. Furthermore, we explore different neural network models to model the writing style of deceptive reviews. We select the best performing neural network to generate the representation of reviews. We validate the effectiveness of the multiview clustering framework using real-world Amazon review data under different experimental scenarios. Our results show that our approach outperforms previous research. We further demonstrate its superiority through a large-scale case study based on publicly available Amazon datasets.
Yubao Zhang, Haining Wang 0001, Angelos Stavrou
J. Comput. Secur.3
2023 Demystifying 5G Traffic Patterns with an Indoor RAN Measurement Campaign
abstract
The deployment of commercial 5G network is gaining momentum while research is already moving towards more advanced features. Currently, the lack of an easy-to-construct, open-source testbed that can support commercial off-the-shelf (COTS) devices has hindered academic research. In this paper, we build an open-source over-the-air testbed leveraging advanced features of 5G radio access and core networks developed by the OpenAirInterface (OAI) project. We evaluate the quality of service (QoS) achievable using this testbed and provide visibility into the compute consumption of individual components. Additionally, we present a method to utilize WiFi devices for experimenting with 5G QoS. We collect resource consumption analytics from the 5G user plane in correlation to raw traffic patterns. Our results show that the OAI testbed sustains sub-20ms latency with up to 80Mbps throughput over a 25m range using COTS devices. Device connection remains stable while supporting different use cases such as AR/VR, online gaming, video streaming and voice over IP (VoIP). Finally, we illustrate how these popular use cases affect the CPU utilization in the user plane. This provides insight into the capabilities of existing 5G solutions by demystifying the resource needs of specific use cases. All our results can be recreated using COTS equipment.
Tolga O. Atalay, Alireza Famili, Dragoslav Stojadinovic, Angelos Stavrou
GLOBECOM4
2023 Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains
abstract
Non-Existent Domain (NXDomain) is one type of the Domain Name System (DNS) error responses, indicating that the queried domain name does not exist and cannot be resolved. Unfortunately, little research has focused on understanding why and how NXDomain responses are generated, utilized, and exploited. In this paper, we conduct the first comprehensive and systematic study on NXDomain by investigating its scale, origin, and security implications. Utilizing a large-scale passive DNS database, we identify 146,363,745,785 NXDomains queried by DNS users between 2014 and 2022. Within these 146 billion NXDomains, 91 million of them hold historic WHOIS records, of which 5.3 million are identified as malicious domains including about 2.4 million blocklisted domains, 2.8 million DGA (Domain Generation Algorithms) based domains, and 90 thousand squatting domains targeting popular domains. To gain more insights into the usage patterns and security risks of NXDomains, we register 19 carefully selected NXDomains in the DNS database, each of which received more than ten thousand DNS queries per month. We then deploy a honeypot for our registered domains and collect 5,925,311 incoming queries for 6 months, from which we discover that 5,186,858 and 505,238 queries are generated from automated processes and web crawlers, respectively. Finally, we perform extensive traffic analysis on our collected data and reveal that NXDomains can be misused for various purposes, including botnet takeover, malicious file injection, and residue trust exploitation.
Guannan Liu 0003, Lin Jin, Shuai Hao 0001, Yubao Zhang, Daiping Liu, Angelos Stavrou, Haining Wang 0001
IMC6
2023 Securing 5G OpenRAN with a Scalable Authorization Framework for xApps
abstract
The ongoing transformation of mobile networks from proprietary physical network boxes to virtualized functions and deployment models has led to more scalable and flexible network architectures capable of adapting to specific use cases. As an enabler of this movement, the OpenRAN initiative promotes standardization allowing for a vendor-neutral radio access network with open APIs. Moreover, the O-RAN Alliance has begun specification efforts conforming to OpenRAN’s definitions. This includes the near-real-time RAN Intelligent Controller (RIC) overseeing a group of extensible applications (xApps). The use of these potentially untrusted third-party applications introduces a new attack surface to the mobile network plane with fundamental security and system design requirements that are yet to be addressed. To secure the 5G O-RAN xApp model, we introduce the xApp Repository Function (XRF) framework, which implements scalable authentication, authorization, and discovery for xApps. We first present the framework’s system design and implementation details, followed by operational benchmarks in a production-grade containerized environment. The evaluation results, centered on active processing and operation times, show that our proposed framework can scale efficiently in a multi-threaded Kubernetes microservice environment and support a large number of clients with minimal overhead.
Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
INFOCOM4
2023 Vehicular Teamwork for Better Positioning
abstract
Recent developments in the autonomous vehicle industries have increased the significance of accurate positioning. Popular techniques for localization include the Global Positioning System (GPS). However, owing to the presence of obstructions, GPS signals are unavailable in dense urban environments. Moreover, in indoor environments (such as a parking garage below the ground), GPS signals are inaccessible to users. In this article, we introduce a novel technique for accurate indoor vehicular positioning. The first step in our proposed system is localization based on received signal strength (RSS) fingerprints of 5G New Radio (NR) downlink signals. Furthermore, to compensate for the high susceptibility of RSS fingerprinting techniques in varying environments, we propose a real-time collaborative localization scheme based on 5G sidelink device-to-device (D2D) communication. We develop extensive test campaigns to assess the efficacy of our proposed two-step scheme. According to test results, our proposed algorithm outperforms scenarios that rely solely on 5G RSS fingerprints.
Alireza Famili, Vladyslav Slyusar, Yun Ho Lee, Angelos Stavrou
SMC4
2023 Wi-Five: Optimal Placement of Wi-Fi Routers in 5G Networks for Indoor Drone Navigation
abstract
In the near future, unmanned aerial vehicles (UAVs) will be used to automate the logistics between organizations and their customers by relying on high accuracy localization. In this paper, we propose a framework that leverages the multi radio access technology (RAT) 5G network to solve the cellular positioning problem for such high mobility targets. For indoors, we utilize wireless fidelity (Wi-Fi) routers, denoted as Wi-Five dots, to improve positioning accuracy where the 5G signal is weaker compared with outdoor environments. These anchor points will use the 5G backhaul to report to the same location management function (LMF) as the cellular 5G access network. The primary contribution of this work is showing how the geometry of these indoor Wi-Five dots significantly affects positioning accuracy. Through a novel optimization algorithm based on the Evolutionary Algorithm (EA) class, we solve the NP-Hard problem of finding the optimal placement of Wi-Five dots for three-dimensional high-accuracy positioning of a mobile target. Our results show that the final positioning accuracy is the product of both the ranging errors and the geometric dilution of precision (GDOP). We experimentally verify that for the latter, the error stems primarily from the Z-axis estimations rather than the errors in the X − Y plane. Finally, we evaluate the results of our optimal placement to show it drastically improves positioning estimations in a three-dimensional space compared with arbitrary beacon placement.
Alireza Famili, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001
VTC2023-Spring3
2023 iDROP: Robust Localization for Indoor Navigation of Drones With Optimized Beacon Placement
abstract
Drones in many applications need the ability to fly fully or partially autonomously to accomplish their mission. To allow these fully/partially autonomous flights, first, the drone needs to be able to locate itself constantly. Then, the navigation command signal would be generated and passed on to the controller unit of the drone. In this article, we propose a localization scheme for drones called robust localization for indoor navigation of drones with optimized beacon placement (iDROP) that is specifically devised for GPS-denied environments (e.g., indoor spaces). Instead of GPS signals, iDROP relies on speaker-generated ultrasonic acoustic signals to enable a drone to estimate its location. In general, localization error is caused by two factors: the ranging error and the error induced by relative geometry between the transmitters and the receiver. iDROP mitigates these two types of errors and provides a high-precision 3-D localization scheme for drones. iDROP employs a waveform that is robust against multipath fading. Moreover, placing beacons in optimal locations reduces the localization error induced by the relative geometry between the transmitters and the receiver.
Alireza Famili, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
IEEE Internet Things J.2
2023 OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs
abstract
The pursuit of high-accuracy localization without relying on the global positioning system (GPS) has gained significant interest in recent years. The deployment of autonomous vehicles (AVs) in diverse indoor applications exemplifies a prominent domain where the demand for a robust positioning system is evident. With the advancements in 5G and beyond radio access networks (RAN), the availability of new positioning signals presents an opportunity to deliver accurate location estimates for these applications. Nevertheless, these signals encounter substantial path losses in indoor environments. Additionally, the precise localization within existing frameworks requires stringent synchronization, which is challenging to meet. In this paper, we propose OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs, a novel positioning framework that is robust against multipath and does not require strict synchronization between anchor-anchor or anchor-target entities. Specifically, OFDRA is designed to operate in scenarios where the line of sight (LOS) exists. The first design objective of OFDRA is the mitigation of ranging errors by leveraging a compact reconfigurable intelligent surface (RIS) mounted on top of AVs acting as a programmable mirror in a 5G network. The second design objective is to achieve optimal anchor placement in three-dimensional indoor spaces, thereby reducing the geometric dilution of precision (GDOP) and mitigating geometric-induced errors in the final position estimation. Our experimental verification reveals that the localization error is influenced by GDOP, encompassing both the$X-Y$plane and$Z$-axis estimations. Through optimized anchor placement, OFDRA demonstrates a seven-fold enhancement in$Z$-axis accuracy compared to the state-of-the-art, achieving a sub-1 m three-dimensional accuracy for more than 95% of cases.
Alireza Famili, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
IEEE J. Sel. Areas Commun.3
2022 Detecting and Measuring Misconfigured Manifests in Android Apps
abstract
The manifest file of an Android app is crucial for app security as it declares sensitive app configurations, such as access permissions required to access app components. Surprisingly, we noticed a number of widely-used apps (some with over 500 million downloads) containing misconfigurations in their manifest files that can result in severe security issues. This paper presents ManiScope, a tool to automatically detect misconfigurations of manifest files when given an Android APK. The key idea is to build a manifest XML Schema by extracting ManiScope constraints from the manifest documentation with novel domain-aware NLP techniques and rules, and validate manifest files against the schema to detect misconfigurations. We have implemented ManiScope, with which we have identified 609,428 (33.20%) misconfigured Android apps out of 1,853,862 apps from Google Play, and 246,658 (35.64%) misconfigured ones out of 692,106 pre-installed apps from 4,580 Samsung firmwares, respectively. Among them, 84,117 (13.80%) of misconfigured Google Play apps and 56,611 (22.95%) of misconfigured pre-installed apps have various security implications including app defrauding, message spoofing, secret data leakage, and component hijacking.
Yuqing Yang 0003, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 0002, Angelos Stavrou, Zhiqiang Lin 0001
CCS5
2022 Network-Slice-as-a-Service Deployment Cost Assessment in an End-to-End 5G Testbed
abstract
The next generation of mobile networks will support a wide range of service requirements over a shared virtual infrastructure. Network functions virtualization (NFV) enables the deployment of Radio Access Network (RAN) and core network functions as virtual network functions (VNFs) on commodity hardware instead of proprietary servers. The deployment of the 5G core will be orchestrated between mobile virtual network operators (MVNOs) and cloud infrastructure providers by middle-men Network-slice-as-a-service (NSaaS) providers that will consume Infrastructure-as-a-service (IaaS) from the latter and offer network slices to the former. In this paper, we seek to leverage an end-to-end emulated 5G deployment to offer insight into the cost implications surrounding large-scale core network deployments. Our deployment features real-life traffic patterns corresponding to practical use cases which are fitted with network slicing models. These models are implemented in a 5G testbed to gather compute resource consumption. This data is used to formulate infrastructure procurement costs for popular cloud providers. Our results show steady patterns in compute consumption across all use cases, which we use to make high scale cost projections. In the end, we are able to observe the trade-off between cost and throughput achieved by decentralizing the network slices and offloading the user plane.
Tolga O. Atalay, Dragoslav Stojadinovic, Alireza Famili, Angelos Stavrou, Haining Wang 0001
GLOBECOM4
2022 RAIL: Robust Acoustic Indoor Localization for Drones
abstract
Navigating in environments where the GPS signal is unavailable, weak, purposefully blocked, or spoofed has become crucial for a wide range of applications. A prime example is autonomous navigation for drones in indoor environments: to fly fully or partially autonomously, drones demand accurate and frequent updates of their locations. This paper proposes a Robust Acoustic Indoor Localization (RAIL) scheme for drones designed explicitly for GPS-denied environments. Instead of depending on GPS, RAIL leverages ultrasonic acoustic signals to achieve precise localization using a novel hybrid Frequency Hopping Code Division Multiple Access (FH-CDMA) technique. Contrary to previous approaches, RAIL is able to both overcome the multipath fading effect and provide precise signal separation in the receiver. Comprehensive simulations and experiments using a prototype implementation demonstrate that RAIL provides high-accuracy three-dimensional localization with an average error of less than 1.5 cm.
Alireza Famili, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
VTC Spring2
2022 Scaling Network Slices with a 5G Testbed: A Resource Consumption Study
abstract
The next generation of networks will be utilized by multiple industry verticals with different service requirements on top of a common infrastructure. Through network function virtualization (NFV), the 5G core and Radio Access Network (RAN) functions are now implemented as virtual network functions (VNFs) on commercial off-the-shelf (COTS) hardware. The use of virtualized micro-services to implement these 5G VNFs enables end-to-end logically isolated network slices on a large scale. In this paper, we seek to measure, analyze, and understand the limits of 5G micro-service virtualization when using lightweight containers to realize different network slicing models with different service guarantees. Our deployment consists of the OpenAirInterface (OAI) core and a simulated RAN in a containerized setting to create a universally deployable testbed. We perform stress tests on individual VNFs and create network slicing models applicable to real-life scenarios. Our analysis captures the increase in compute resource consumption of individual 5G VNFs during various core network procedures. Furthermore, using different network slicing models, we are able to see the progressive increase in resource consumption as the service guarantees of the slices become more demanding. The framework created using this testbed is the first to provide such analytics on lightweight virtualized 5G core VNFs with large scale end-to-end connections.
Tolga O. Atalay, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001
WCNC3
2022 Characterization of AES Implementations on Microprocessor-based IoT Devices
abstract
The increased proliferation of IoT devices and the emergence of 5G networks have necessitated increased security of data storage and communication in such connected devices. Thus, cryptography is used in IoT environments to provide secrecy and integrity to the data as well as both authentication and anonymity to the communications across the IoT network. However, IoT devices are resource-constrained devices; have limited memory, network bandwidth, power, and compute units. Since most of the existing cryptographic algorithms were designed to run on resource powerful devices (e.g., desktops or servers), many of these algorithms may not fit into resource-constrained devices. Therefore, in this work, we present a practical performance analysis of different implementations of the Advanced Encryption Standard (AES), which is the most widely used symmetric-key cryptosystem in the IoT environment. Specifically, we explore execution times, energy consumption, and memory usage of the different AES implementations across 4 different public libraries. Furthermore, our analysis is done using various modes, key sizes, plaintext sizes, and microprocessor-based IoT devices. Our results show that for the same combination of inputs and a given algorithm, different crypto library implementations give results with widely varying relative differences. As per the obtained results, the PyCryptodome library seems to be the most suitable one in terms of both execution time and energy on a resource-constrained IoT device and has the most efficient memory usage.
Sunanda Roy, Angelos Stavrou, Brian L. Mark, Kai Zeng 0001, Sai Manoj Pudukotai Dinakarrao, Khaled N. Khasawneh
WCNC2
2022 Understanding the Security Implication of Aborting Virtual Machine Live Migration
abstract
Live migration of Virtual machines (VMs) has become a regular tool for edge and cloud operators to facilitate system maintenance, fault tolerance, and load balancing, with little impact on running instances. However, the potential security risks of live migration of VMs are still obscure. In this article, we expose a new vulnerability in the existing VM live migration approaches, especially thepost-copyapproach. The entire live migration mechanism relies upon reliable TCP connectivity for the transfer of the VM state. We demonstrate that, if the host server is vulnerable to off-path TCP attacks, the loss of TCP reliability leads to VM live migration failure. We demonstrate that, by intentionally aborting the TCP connection, attackers can cause unrecoverable memory inconsistency forpost-copy, leading to a significant increase in downtime and performance degradation of the running VM. Additionally, we present detailed techniques to reset the migration connection under heavy networking traffic. We also propose effective defenses to secure the VM live migration. Our experimental results demonstrate that memory inconsistencies could be devastating to some applications, and it only takes a few minutes to reset a heavy migration connection.
Xing Gao 0001, Jidong Xiao, Haining Wang 0001, Angelos Stavrou
IEEE Trans. Cloud Comput.4
2021 CloudSkulk: A Nested Virtual Machine Based Rootkit and Its Detection
abstract
When attackers compromise a computer system and obtain root control over the victim system, retaining that control and avoiding detection become their top priority. To achieve this goal, various rootkits have been developed. However, existing rootkits are still easy to detect as long as defenders can gain control at a lower level, such as the operating system level, the hypervisor level, or the hardware level. In this paper, we present a new type of rootkit called CloudSkulk, which is a nested virtual machine (VM) based rootkit. While nested virtualization has attracted sufficient attention from the security and cloud community, to the best of our knowledge, we are the first to reveal and demonstrate how nested virtualization can be used by attackers to develop rootkits. We then, from defenders' perspective, present a novel approach to detecting CloudSkulk rootkits at the host level. Our experimental results show that the proposed approach is effective in detecting CloudSkulk rootkits.
Joseph Connelly, Taylor Roberts, Xing Gao 0001, Jidong Xiao, Haining Wang 0001, Angelos Stavrou
DSN6
2021 DEFInit: An Analysis of Exposed Android Init Routines
Yuede Ji, Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou
USENIX Security Symposium4
2020 FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware
Mohamed Elsabagh, Ryan Johnson 0002, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, Zhiqiang Lin 0001
USENIX Security Symposium3
2020 Guest Editorial Special Issue on Blockchain and Economic Knowledge Automation
abstract
Blockchain, as an emerging decentralized architecture and distributed computing paradigm underlying Bitcoin and other cryptocurrencies, has attracted intensive attention in both research and applications recently. Blockchain, especially powered by chain-coded smart contracts, has the full potential of revolutionizing increasingly centralized cyber-physical-social systems (CPSSs) for constructions and applications, and reshaping traditional knowledge automation workflows. The key advantage of blockchain technology lies in the fact that it can enable the establishment of secured, trusted, and decentralized autonomous ecosystems for various scenarios, especially for better usage of the legacy devices, infrastructure, and resources.
Yong Yuan 0003, Shou-Yang Wang, David L. Olson, James H. Lambert, Fei-Yue Wang 0001, Chunming Rong, Angelos Stavrou, Jun Jason Zhang, Qiang Tang 0005, Foteini Baldimtsi, Laurence T. Yang, Desheng Dash Wu
IEEE Trans. Syst. Man Cybern. Syst.7
2018 Dazed Droids: A Longitudinal Study of Android Inter-App Vulnerabilities
abstract
Android devices are an integral part of modern life from phone to media boxes to smart home appliances and cameras. With 38.9% of market share, Android is now the most used operating system not just in terms of mobile devices but considering all OSes. As applications' complexity and features increased, Android relied more heavily on code and data sharing among apps for faster response times and richer user experience. To achieve that, Android apps reuse functionality and data by means of inter-app message passing where each app defines the messages it expects to receive. In this paper, we analyze the proliferation of exploitable inter-app communication vulnerabilities using a rich corpus of 1) a representative sample of 32 Android devices, 2) 59 official Google Android versions, and 3) the top 18,583 apps from 2016 to 2017. This corpus covers $91$ Android builds from version 4.4 to present. To the best of our knowledge, ours is the first longitudinal study looking into the propagation of vulnerabilities across AOSP builds, between AOSP and a diverse set of devices, and across app versions over a period of 13 months. To identify inter-app vulnerabilities, we developed Daze as a swift and fully-automated framework for extracting app components and fuzzing all app interfaces. Daze needs only about three hours for full-device analysis or two minutes per app on average. We identified 14,413 vulnerabilities and quantified their exposure time and the number of versions affected. Our findings revealed that $51.7%$ of Android devices and $49%$ of the top $300$ apps on Google Play contained at least one critical inter-app vulnerability. We found that about $15%$ of fixed vulnerabilities lived for more than $100$ days before being patched, more than $20%$ of unpatched vulnerabilities have existed for at least $180$ days, and $45%$ of unpatched vulnerabilities persisted through the latest two to four consecutive app versions in our dataset.
Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou, A. Jefferson Offutt
AsiaCCS3
2018 Detecting and Characterizing Web Bot Traffic in a Large E-commerce Marketplace
Haitao Xu 0002, Zhao Li 0007, Chen Chu, Yuanmi Chen, Yifan Yang 0001, Haifeng Lu, Haining Wang 0001, Angelos Stavrou
ESORICS (2)8
2018 End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks
Shuai Hao 0001, Yubao Zhang, Haining Wang 0001, Angelos Stavrou
USENIX Security Symposium4
2018 On early detection of application-level resource exhaustion and starvation
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
J. Syst. Softw.4
2018 Towards Transparent Debugging
abstract
Traditional malware analysis relies on virtualization or emulation technology to run samples in a confined environment, and to analyze malicious activities by instrumenting code execution. However, virtual machines and emulators inevitably create artifacts in the execution environment, making these approaches vulnerable to detection or subversion. In this paper, we present MALT, a debugging framework that employs System Management Mode, a CPU mode in the x86 architecture, to transparently study armored malware. MALT does not depend on virtualization or emulation and thus is immune to threats targeting such environments. Our approach reduces the attack surface at the software level, and advances state-of-the-art debugging transparency. MALT embodies various debugging functions, including register/memory accesses, breakpoints, and seven stepping modes. Additionally, MALT restores the system to a clean state after a debugging session. We implemented a prototype of MALT on two physical machines, and we conducted experiments by testing an array of existing anti-virtualization, anti-emulation, and packing techniques against MALT. The experimental results show that our prototype remains transparent and undetected against the samples. Furthermore, debugging and restoration introduce moderate but manageable overheads on both Windows and Linux platforms.
Fengwei Zhang, Kevin Leach, Angelos Stavrou, Haining Wang 0001
IEEE Trans. Dependable Secur. Comput.3
2017 FROST: Anti-Forensics Digital-Dead-DROp Information Hiding RobuST to Detection & Data Loss with Fault tolerance
abstract
Covert operations involving clandestine dealings and communication through cryptic and hidden messages have existed since time immemorial. While these do have a negative connotation, they have had their fair share of use in situations and applications beneficial to society in general. A "Dead Drop" is one such method of espionage trade craft used to physically exchange items or information between two individuals using a secret rendezvous point. With a "Dead Drop", to maintain operational security, the exchange itself is asynchronous. Information hiding in the slack space is one modern technique that has been used extensively. Slack space is the unused space within the last block allocated to a stored file. However, hiding in slack space operates under significant constraints with little resilience and fault tolerance.
Avinash Srinivasan, Hunter Dong, Angelos Stavrou
ARES3
2017 Strict Virtual Call Integrity Checking for C++ Binaries
abstract
Modern operating systems are equipped with defenses that render legacy code injection attacks inoperable. However, attackers can bypass these defenses by crafting attacks that reuse existing code in a program's memory. One of the most common classes of attacks manipulates memory data used indirectly to execute code, such as function pointers. This is especially prevalent in C++ programs, since tables of function pointers (vtables) are used by all major compilers to support polymorphism. In this paper, we propose VCI, a binary rewriting system that secures C++ binaries against vtable attacks. VCI works directly on stripped binary files. It identifies and reconstructs various C++ semantics from the binary, and constructs a strict CFI policy by resolving and pairing virtual function calls (vcalls) with precise sets of target classes. The policy is enforced by instrumenting checks into the binary at vcall sites. Experimental results on SPEC CPU2006 and Firefox show that VCI is significantly more precise than state-of-the-art binary solutions. Testing against the ground truth from the source-based defense GCC VTV, VCI achieved greater than 60% precision in most cases, accounting for at least 48% to 99% additional reduction in the attack surface compared to the state-of-the-art binary defenses. VCI incurs a 7.79% average runtime overhead which is comparable to the state-of-the-art. In addition, we discuss how VCI defends against real-world attacks, and how it impacts advanced vtable reuse attacks such as COOP.
Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou
AsiaCCS3
2017 CCSW'17: 2017 ACM Cloud Computing Security
abstract
The use and prevalence of cloud and large-scale computing infrastructures is increasing. They are projected to be a dominant trend in computing for the foreseeable future: major cloud operators are now estimated to house millions of machines each and to host substantial (and growing) fractions of corporate and government IT and web infrastructure. CCSW is a forum for bringing together researchers and practitioners to discuss the challenges and implications of current and future trends to the security of cloud operators, tenants, and the larger Internet community. Of special interest are the security challenges from the integration of cloud infrastructures with IoT and mobile application deployments. CCSW welcomes submissions on new threats, countermeasures, and opportunities brought about by the move to cloud computing, with a preference for unconventional approaches, as well as measurement studies and case studies that shed light on the security implications of cloud infrastructure and use cases.
Ghassan Karame, Angelos Stavrou
CCS2
2017 Detecting ROP with Statistical Learning of Program Characteristics
abstract
Return-Oriented Programming (ROP) has emerged as one of the most widely used techniques to exploit software vulnerabilities. Unfortunately, existing ROP protections suffer from a number of shortcomings: they require access to source code and compiler support, focus on specific types of gadgets, depend on accurate disassembly and construction of Control Flow Graphs, or use hardware-dependent (microarchitectural) characteristics. In this paper, we propose EigenROP, a novel system to detect ROP payloads based on unsupervised statistical learning of program characteristics. We study, for the first time, the feasibility and effectiveness of using microarchitecture-independent program characteristics -- namely, memory locality, register traffic, and memory reuse distance -- for detecting ROP. We propose a novel directional statistics based algorithm to identify deviations from the expected program characteristics during execution. EigenROP works transparently to the protected program, without requiring debug information, source code or disassembly. We implemented a dynamic instrumentation prototype of EigenROP using Intel Pin and measured it against in-the-wild ROP exploits and on payloads generated by the ROP compiler ROPC. Overall, EigenROP achieved significantly higher accuracy than prior anomaly-based solutions. It detected the execution of the ROP gadget chains with 81% accuracy, 80% true positive rate, only 0.8% false positive rate, and incurred comparable overhead to similar Pin-based solutions.
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
CODASPY4
2017 Detecting Passive Cheats in Online Games via Performance-Skillfulness Inconsistency
abstract
As the most commonly used bots in first-person shooter (FPS) online games, aimbots are notoriously difficult to detect because they are completely passive and resemble excellent honest players in many aspects. In this paper, we conduct the first field measurement study to understand the status quo of aimbots and how they play in the wild. For data collection purpose, we devise a novel and generic technique called baittarget to accurately capture existing aimbots from the two most popular FPS games. Our measurement reveals that cheaters who use aimbots cannot play as skillful as excellent honest players in all aspects even though aimbots can help them to achieve very high shooting performance. To characterize the unskillful and blatant nature of cheaters, we identify seven features, of which six are novel, and these features cannot be easily mimicked by aimbots. Leveraging this set of features, we propose an accurate and robust server-side aimbot detector called AimDetect. The core of AimDetect is a cascaded classifier that detects the inconsistency between performance and skillfulness of aimbots. We evaluate the efficacy and generality of AimDetect using the real game traces. Our results show that AimDetect can capture almost all of the aimbots with very few false positives and minor overhead.
Daiping Liu, Xing Gao 0001, Mingwei Zhang 0005, Haining Wang 0001, Angelos Stavrou
DSN5
2017 E-Android: A New Energy Profiling Tool for Smartphones
abstract
As the limited battery lifetime remains a major factor restricting the applicability of a smartphone, significant research efforts have been devoted to understand the energy consumption in smartphones. Existing energy modeling methods can account energy drain in a fine-grained manner and provide well designed human-battery interfaces for users to characterize energy usage of every app in smartphones. However, in this paper, we demonstrate that there are still pitfalls in current Android energy modeling approaches, leaving collateral energy consumption unaccounted. The existence of collateral energy consumption becomes a serious energy bug. In particular, those energy bugs could be exploited to launch a new class of energy attacks, which deplete battery life and sidestep the supervision of current energy accounting. To unveil collateral energy bugs, we propose E-Android to accurately profile energy consumption of a smartphone in a comprehensive manner. E-Android monitors collateral energy related events and maintains energy consumption maps for relevant apps. We evaluate the effectiveness of E-Android under six different collateral energy attacks and two normal scenarios, and compare the results with those of Android. While Android fails to disclose collateral energy bugs, E-Android can accurately profile energy consumption and reveal the existence of energy bugs with minor overhead.
Xing Gao 0001, Dachuan Liu, Daiping Liu, Haining Wang 0001, Angelos Stavrou
ICDCS5
2017 Practical and Accurate Runtime Application Protection Against DoS Attacks
Mohamed Elsabagh, Daniel Fleck, Angelos Stavrou, Michael Kaplan, Thomas Bowen
RAID3
2017 An Empirical Investigation of Ecommerce-Reputation-Escalation-as-a-Service
abstract
In online markets, a store’s reputation is closely tied to its profitability. Sellers’ desire to quickly achieve a high reputation has fueled a profitable underground business that operates as a specialized crowdsourcing marketplace and accumulates wealth by allowing online sellers to harness human laborers to conduct fake transactions to improve their stores’ reputations. We term such an underground market a seller-reputation-escalation (SRE) market . In this article, we investigate the impact of the SRE service on reputation escalation by performing in-depth measurements of the prevalence of the SRE service, the business model and market size of SRE markets, and the characteristics of sellers and offered laborers. To this end, we have infiltrated five SRE markets and studied their operations using daily data collection over a continuous period of 2 months. We identified more than 11,000 online sellers posting at least 219,165 fake-purchase tasks on the five SRE markets. These transactions earned at least $46,438 in revenue for the five SRE markets, and the total value of merchandise involved exceeded $3,452,530. Our study demonstrates that online sellers using the SRE service can increase their stores’ reputations at least 10 times faster than legitimate ones while about 25% of them were visibly penalized. Even worse, we found a much stealthier and more hazardous service that can, within a single day, boost a seller’s reputation by such a degree that would require a legitimate seller at least a year to accomplish. Armed with our analysis of the operational characteristics of the underground economy, we offer some insights into potential mitigation strategies. Finally, we revisit the SRE ecosystem 1 year later to evaluate the latest dynamism of the SRE markets, especially the statuses of the online stores once identified to launch fake-transaction campaigns on the SRE markets. We observe that the SRE markets are not as active as they were 1 year ago and about 17% of the involved online stores become inaccessible likely because they have been forcibly shut down by the corresponding E-commerce marketplace for conducting fake transactions.
Haitao Xu 0002, Daiping Liu, Haining Wang 0001, Angelos Stavrou
ACM Trans. Web4
2016 Why Software DoS Is Hard to Fix: Denying Access in Embedded Android Platforms
Ryan Johnson 0002, Mohamed Elsabagh, Angelos Stavrou
ACNS3
2016 When a Tree Falls: Using Diversity in Ensemble Classifiers to Identify Evasion in Malware Detectors
Charles Smutz, Angelos Stavrou
NDSS2
2015 TrustLogin: Securing Password-Login on Commodity Operating Systems
abstract
With the increasing prevalence of Web 2.0 and cloud computing, password-based logins play an increasingly important role on user-end systems. We use passwords to authenticate ourselves to countless applications and services. However, login credentials can be easily stolen by attackers. In this paper, we present a framework, TrustLogin, to secure password-based logins on commodity operating systems. TrustLogin leverages System Management Mode to protect the login credentials from malware even when OS is compromised. TrustLogin does not modify any system software in either client or server and is transparent to users, applications, and servers. We conduct two study cases of the framework on legacy and secure applications, and the experimental results demonstrate that TrustLogin is able to protect login credentials from real-world keyloggers on Windows and Linux platforms. TrustLogin is robust against spoofing attacks. Moreover, the experimental results also show TrustLogin introduces a low overhead with the tested applications.
Fengwei Zhang, Kevin Leach, Haining Wang 0001, Angelos Stavrou
AsiaCCS4
2015 On the DNS Deployment of Modern Web Services
abstract
Accessing Internet services relies on the Domain Name System (DNS) for translating human-readable names to routable network addresses. At the bottom level of the DNS hierarchy, the authoritative DNS (ADNS) servers maintain the actual mapping records and answer the DNS queries. Today, the increasing use of upstream ADNS services (i.e., third-party ADNS-hosting services) and Infrastructure-as-a-Service (IaaS) clouds facilitates the establishment of web services, and has been fostering the evolution of the deployment of ADNS servers. To shed light on this trend, in this paper we present a large-scale measurement to study the ADNS deployment patterns of modern web services and examine the characteristics of different deployment styles, such as performance, life-cycle of servers, and availability. Furthermore, we focus specifically on the DNS deployment for subdomains hosted in IaaS clouds.
Shuai Hao 0001, Haining Wang 0001, Angelos Stavrou, Evgenia Smirni
ICNP3
2015 Radmin: Early Detection of Application-Level Resource Exhaustion and Starvation Attacks
Mohamed Elsabagh, Daniel Barbará, Daniel Fleck, Angelos Stavrou
RAID4
2015 Continuous Authentication on Mobile Devices Using Power Consumption, Touch Gestures and Physical Movement of Users
Rahul Murmuria, Angelos Stavrou, Daniel Barbará, Daniel Fleck
RAID2
2015 Preventing Exploits in Microsoft Office Documents Through Content Randomization
Charles Smutz, Angelos Stavrou
RAID2
2015 Privacy Risk Assessment on Online Photos
Haitao Xu 0002, Haining Wang 0001, Angelos Stavrou
RAID3
2015 Using Hardware Features for Increased Debugging Transparency
abstract
With the rapid proliferation of malware attacks on the Internet, understanding these malicious behaviors plays a critical role in crafting effective defense. Advanced malware analysis relies on virtualization or emulation technology to run samples in a confined environment, and to analyze malicious activities by instrumenting code execution. However, virtual machines and emulators inevitably create artifacts in the execution environment, making these approaches vulnerable to detection or subversion. In this paper, we present MALT, a debugging framework that employs System Management Mode, a CPU mode in the x86 architecture, to transparently study armored malware. MALT does not depend on virtualization or emulation and thus is immune to threats targeting such environments. Our approach reduces the attack surface at the software level, and advances state-of-the-art debugging transparency. MALT embodies various debugging functions, including register/memory accesses, breakpoints, and four stepping modes. We implemented a prototype of MALT on two physical machines, and we conducted experiments by testing an array of existing anti-virtualization, anti-emulation, and packing techniques against MALT. The experimental results show that our prototype remains transparent and undetected against the samples. Furthermore, our prototype of MALT introduces moderate but manageable overheads on both Windows and Linux platforms.
Fengwei Zhang, Kevin Leach, Angelos Stavrou, Haining Wang 0001, Kun Sun 0001
IEEE Symposium on Security and Privacy3
2015 E-commerce Reputation Manipulation: The Emergence of Reputation-Escalation-as-a-Service
abstract
In online markets, a store's reputation is closely tied to its profitability. Sellers' desire to quickly achieve high reputation has fueled a profitable underground business, which operates as a specialized crowdsourcing marketplace and accumulates wealth by allowing online sellers to harness human laborers to conduct fake transactions for improving their stores' reputations. We term such an underground market a seller-reputation-escalation (SRE) market. In this paper, we investigate the impact of the SRE service on reputation escalation by performing in-depth measurements of the prevalence of the SRE service, the business model and market size of SRE markets, and the characteristics of sellers and offered laborers. To this end, we have infiltrated five SRE markets and studied their operations using daily data collection over a continuous period of two months. We identified more than 11,000 online sellers posting at least 219,165 fake-purchase tasks on the five SRE markets. These transactions earned at least $46,438 in revenue for the five SRE markets, and the total value of merchandise involved exceeded $3,452,530. Our study demonstrates that online sellers using SRE service can increase their stores' reputations at least 10 times faster than legitimate ones while only 2.2% of them were detected and penalized. Even worse, we found a newly launched service that can, within a single day, boost a seller's reputation by such a degree that would require a legitimate seller at least a year to accomplish. Finally, armed with our analysis of the operational characteristics of the underground economy, we offer some insights into potential mitigation strategies.
Haitao Xu 0002, Daiping Liu, Haining Wang 0001, Angelos Stavrou
WWW4
2014 Activity Spoofing and Its Defense in Android Smartphones
Brett Cooley, Haining Wang 0001, Angelos Stavrou
ACNS3
2014 Catch Me If You Can: A Cloud-Enabled DDoS Defense
abstract
We introduce a cloud-enabled defense mechanism for Internet services against network and computational Distributed Denial-of-Service (DDoS) attacks. Our approach performs selective server replication and intelligent client re-assignment, turning victim servers into moving targets for attack isolation. We introduce a novel system architecture that leverages a "shuffling" mechanism to compute the optimal re-assignment strategy for clients on attacked servers, effectively separating benign clients from even sophisticated adversaries that persistently follow the moving targets. We introduce a family of algorithms to optimize the runtime client-to-server re-assignment plans and minimize the number of shuffles to achieve attack mitigation. The proposed shuffling-based moving target mechanism enables effective attack containment using fewer resources than attack dilution strategies using pure server expansion. Our simulations and proof-of-concept prototype using Amazon EC2 [1] demonstrate that we can successfully mitigate large-scale DDoS attacks in a small number of shuffles, each of which incurs a few seconds of user-perceived latency.
Quan Jia, Huangxin Wang, Daniel Fleck, Fei Li 0001, Angelos Stavrou, Walter Powell
DSN5
2014 Detecting Malicious Javascript in PDF through Document Instrumentation
abstract
An emerging threat vector, embedded malware inside popular document formats, has become rampant since 2008. Owed to its wide-spread use and Javascript support, PDF has been the primary vehicle for delivering embedded exploits. Unfortunately, existing defenses are limited in effectiveness, vulnerable to evasion, or computationally expensive to be employed as an on-line protection system. In this paper, we propose a context-aware approach for detection and confinement of malicious Javascript in PDF. Our approach statically extracts a set of static features and inserts context monitoring code into a document. When an instrumented document is opened, the context monitoring code inside will cooperate with our runtime monitor to detect potential infection attempts in the context of Javascript execution. Thus, our detector can identify malicious documents by using both static and runtime features. To validate the effectiveness of our approach in a real world setting, we first conduct a security analysis, showing that our system is able to remain effective in detection and be robust against evasion attempts even in the presence of sophisticated adversaries. We implement a prototype of the proposed system, and perform extensive experiments using 18623 benign PDF samples and 7370 malicious samples. Our evaluation results demonstrate that our approach can accurately detect and confine malicious Javascript in PDF with minor performance overhead.
Daiping Liu, Haining Wang 0001, Angelos Stavrou
DSN3
2014 Click Fraud Detection on the Advertiser Side
Haitao Xu 0002, Daiping Liu, Aaron Koehl, Haining Wang 0001, Angelos Stavrou
ESORICS (2)5
2014 A Framework to Secure Peripherals at Runtime
Fengwei Zhang, Haining Wang 0001, Kevin Leach, Angelos Stavrou
ESORICS (1)4
2014 transAD: An Anomaly Detection Network Intrusion Sensor for the Web
Sharath Hiremagalore, Daniel Barbará, Daniel Fleck, Walter Powell, Angelos Stavrou
ISC5
2014 A moving target DDoS defense mechanism
Huangxin Wang, Quan Jia, Daniel Fleck, Walter Powell, Fei Li 0001, Angelos Stavrou
Comput. Commun.6
2014 HyperCheck: A Hardware-AssistedIntegrity Monitor
abstract
The advent of cloud computing and inexpensive multi-core desktop architectures has led to the widespread adoption of virtualization technologies. Furthermore, security researchers embraced virtual machine monitors (VMMs) as a new mechanism to guarantee deep isolation of untrusted software components, which, coupled with their popularity, promoted VMMs as a prime target for exploitation. In this paper, we present HyperCheck, a hardware-assisted tampering detection framework designed to protect the integrity of hypervisors and operating systems. Our approach leverages System Management Mode (SMM), a CPU mode in ×86 architecture, to transparently and securely acquire and transmit the full state of a protected machine to a remote server. We have implement two prototypes based on our framework design: HyperCheck-I and HyperCheck-II, that vary in their security assumptions and OS code dependence. In our experiments, we are able to identify rootkits that target the integrity of both hypervisors and operating systems. We show that HyperCheck can defend against attacks that attempt to evade our system. In terms of performance, we measured that HyperCheck can communicate the entire static code of Xen hypervisor and CPU register states in less than 90 million CPU cycles, or 90 ms on a 1 GHz CPU.
Fengwei Zhang, Jiang Wang 0008, Kun Sun 0001, Angelos Stavrou
IEEE Trans. Dependable Secur. Comput.4
2013 PyTrigger: A System to Trigger & Extract User-Activated Malware Behavior
abstract
We introduce PyTrigger, a dynamic malware analysis system that automatically exercises a malware binary extracting its behavioral profile even when specific user activity or input is required. To accomplish this, we developed a novel user activity record and playback framework and a new behavior extraction approach. Unlike existing research, the activity recording and playback includes the context of every object in addition to traditional keyboard and mouse actions. The addition of the context makes the playback more accurate and avoids dependencies and pitfalls that come with pure mouse and keyboard replay. Moreover, playback can become more efficient by condensing common activities into a single action. After playback, PyTrigger analyzes the system trace using a combination of multiple states and behavior differencing to accurately extract the malware behavior and user triggered behavior from the complete system trace log. We present the algorithms, architecture and evaluate the PyTrigger prototype using 3994 real malware samples. Results and analysis are presented showing PyTrigger extracts additional behavior in 21% of the samples.
Daniel Fleck, Arnur G. Tokhtabayev, Alex Alarif, Angelos Stavrou, Tomas Nykodym
ARES4
2013 SPECTRE: A dependable introspection framework via System Management Mode
abstract
Virtual Machine Introspection (VMI) systems have been widely adopted for malware detection and analysis. VMI systems use hypervisor technology for system introspection and to expose malicious activity. However, recent malware can detect the presence of virtualization or corrupt the hypervisor state thus avoiding detection. We introduce SPECTRE, a hardware-assisted dependability framework that leverages System Management Mode (SMM) to inspect the state of a system. Contrary to VMI, our trusted code base is limited to BIOS and the SMM implementations. SPECTRE is capable of transparently and quickly examining all layers of running system code including a hypervisor, the OS, and user level applications. We demonstrate several use cases of SPECTRE including heap spray, heap overflow, and rootkit detection using real-world attacks on Windows and Linux platforms. In our experiments, full inspection with SPECTRE is 100 times faster than similar VMI systems because there is no performance overhead due to virtualization.
Fengwei Zhang, Kevin Leach, Kun Sun 0001, Angelos Stavrou
DSN4
2013 MOTAG: Moving Target Defense against Internet Denial of Service Attacks
abstract
Distributed Denial of Service (DDoS) attacks still pose a significant threat to critical infrastructure and Internet services alike. In this paper, we propose MOTAG, a moving target defense mechanism that secures service access for authenticated clients against flooding DDoS attacks. MOTAG employs a group of dynamic packet indirection proxies to relay data traffic between legitimate clients and the protected servers. Our design can effectively inhibit external attackers' attempts to directly bombard the network infrastructure. As a result, attackers will have to collude with malicious insiders in locating secret proxies and then initiating attacks. However, MOTAG can isolate insider attacks from innocent clients by continuously "moving" secret proxies to new network locations while shuffling client-to-proxy assignments. We develop a greedy shuffling algorithm to minimize the number of proxy re- allocations (shuffles) while maximizing attack isolation. Simulations are used to investigate MOTAG's effectiveness on protecting services of different scales against intensified DDoS attacks.
Quan Jia, Kun Sun 0001, Angelos Stavrou
ICCCN3
2013 Providing Users' Anonymity in Mobile Hybrid Networks
abstract
We present a novel hybrid communication protocol that guarantees mobile users’ anonymity against a wide-range of adversaries by exploiting the capability of handheld devices to connect to both WiFi and cellular networks. Unlike existing anonymity schemes, we consider all parties that can intercept communications between a mobile user and a server as potential privacy threats. We formally quantify the privacy exposure and the protection of our system in the presence of malicious neighboring peers, global WiFi eavesdroppers, and omniscient mobile network operators, which possibly collude to breach user’s anonymity or disrupt the communication. We also describe how a micropayment scheme that suits our mobile scenario can provide incentives for peers to collaborate in the protocol. Finally, we evaluate the network overhead and attack resiliency of our protocol using a prototype implementation deployed in Emulab and Orbit, and our probabilistic model.
Claudio A. Ardagna, Sushil Jajodia, Pierangela Samarati, Angelos Stavrou
ACM Trans. Internet Techn.4
2012 Malicious PDF detection using metadata and structural features
abstract
Owed to their versatile functionality and widespread adoption, PDF documents have become a popular avenue for user exploitation ranging from large-scale phishing attacks to targeted attacks. In this paper, we present a framework for robust detection of malicious documents through machine learning. Our approach is based on features extracted from document metadata and structure. Using real-world datasets, we demonstrate the the adequacy of these document properties for malware detection and the durability of these features across new malware variants. Our analysis shows that the Random Forests classification method, an ensemble classifier that randomly selects features for each individual classification tree, yields the best detection rates, even on previously unseen malware.
Charles Smutz, Angelos Stavrou
ACSAC2
2012 NetGator: Malware Detection Using Program Interactive Challenges
Brian Schulte, Haris Andrianakis, Kun Sun 0001, Angelos Stavrou
DIMVA4
2012 A dependability analysis of hardware-assisted polling integrity checking systems
abstract
Due to performance constraints, host intrusion detection defenses depend on event and polling-based tamper-proof mechanisms to detect security breaches. These defenses monitor the state of critical software components in an attempt to discover any deviations from a pristine or expected state. The rate and type of checks depend can be both periodic and event-based, for instance triggered by hardware events. In this paper, we demonstrate that all software and hardware-assisted defenses that analyze non-contiguous state to infer intrusions are fundamentally vulnerable to a new class of attacks, we call “evasion attacks”. We detail two categories of evasion attacks: directly-intercepting the defense triggering mechanism and indirectly inferring its periodicity. We show that evasion attacks are applicable to a wide-range of protection mechanisms and we analyze their applicability in recent state-of-the-art hardware-assisted protection mechanisms. Finally, we quantify the performance of implemented proof-of-concept prototypes for all of the attacks and suggest potential countermeasures.
Jiang Wang 0008, Kun Sun 0001, Angelos Stavrou
DSN3
2012 Implementing and Optimizing an Encryption Filesystem on Android
abstract
The recent surge in popularity of smart handheld devices, including smart-phones and tablets, has given rise to new challenges in protection of Personal Identifiable Information (PII). Indeed, modern mobile devices store PII for applications that span from email to SMS and from social media to location-based services increasing the concerns of the end user's privacy. Therefore, there is a clear need and expectation for PII data to be protected in the case of loss, theft, or capture of the portable device. In this paper, we present a novel FUSE (File system in User space) encryption file system to protect the removable and persistent storage on heterogeneous smart gadget devices running the Android platform. The proposed file system leverages NIST certified cryptographic algorithms to encrypt the data-at-rest. We present an analysis of the security and performance trade-offs in a wide-range of usage and load scenarios. Using existing known micro benchmarks in devices using encryption without any optimization, we show that encrypted operations can incur negligible overhead for read operations and up to twenty (20) times overhead for write operations for I/O-intensive programs. In addition, we quantified the database transaction performance and we observed a 50% operation time slowdown on average when using encryption. We further explore generic and device specific optimizations and gain 10% to 60% performance for different operations reducing the initial cost of encryption. Finally, we show that our approach is easy to install and configure across all Android platforms including mobile phones, tablets, and small notebooks without any user perceivable delay for most of the regular Android applications.
Rahul Murmuria, Angelos Stavrou
MDM3
2012 SecureSwitch: BIOS-Assisted Isolation and Switch between Trusted and Untrusted Commodity OSes
Kun Sun 0001, Jiang Wang 0008, Fengwei Zhang, Angelos Stavrou
NDSS4
2012 DoubleGuard: Detecting Intrusions in Multitier Web Applications
abstract
Internet services and applications have become an inextricable part of daily life, enabling communication and the management of personal information from anywhere. To accommodate this increase in application and data complexity, web services have moved to a multitiered design wherein the webserver runs the application front-end logic and data are outsourced to a database or file server. In this paper, we present DoubleGuard, an IDS system that models the network behavior of user sessions across both the front-end webserver and the back-end database. By monitoring both web and subsequent database requests, we are able to ferret out attacks that an independent IDS would not be able to identify. Furthermore, we quantify the limitations of any multitier IDS in terms of training sessions and functionality coverage. We implemented DoubleGuard using an Apache webserver with MySQL and lightweight virtualization. We then collected and processed real-world traffic over a 15-day period of system deployment in both dynamic and static web applications. Finally, using DoubleGuard, we were able to expose a wide range of attacks with 100 percent accuracy while maintaining 0 percent false positives for static web services and 0.6 percent false positives for dynamic web services.
Meixing Le, Angelos Stavrou, Brent ByungHoon Kang
IEEE Trans. Dependable Secur. Comput.2
2011 Predicting Network Response Times Using Social Information
abstract
Social networks and discussion boards have become a significant outlet where people communicate and express their opinion freely. Although the social networks themselves are usually well-provisioned, the participating users frequently point to external links to substantiate their discussions. Unfortunately, the sudden heavy traffic load imposed on the external, linked web sites causes them to become unresponsive leading to the "Flash Crowds" effect. In this paper, we quantify the prevalence of flash crowd events for a popular social discussion board (Digg). We measured the response times of 1289 unique popular websites. We were able to verify that 89% of the popular URLs suffered variations in their response times. By analyzing the content and structure of the social discussions, we were able to forecast accurately for 86% of the popular web sites within 5 minutes of their submission and 95% of the sites when more (5 hours) of social content became available. Our work indicates that we can effectively leverage social activity to forecast network events that will be otherwise infeasible to anticipate.
Sharath Hiremagalore, Angelos Stavrou, Huzefa Rangwala
ASONAM3
2011 CapMan: Capability-Based Defense against Multi-Path Denial of Service (DoS) Attacks in MANET
abstract
This paper presents a capability-based security mechanism called CapMan. Our approach is designed to prevent Denial-of-Service (DoS) attacks on wireless communications, particularly against multi-path communication in Mobile Ad-hoc Networks (MANETs). CapMan offers a mechanism for a per flow, distributed bandwidth control by all the participating nodes along multiple communication paths. By exchanging summary capability messages, each node can maintain a global view of the overall throughput of flows in the network, and then dynamically adjust local constraints to prevent potential DoS attacks against a specific node or the network. Our approach is capable of scalably curtailing sophisticated DoS attacks that target multi-path routing protocols, even in the case that both the initiator and the responder of a network flow are malicious insiders and collude to deprive the network of valuable resources. We provide a theoretical analysis of our algorithms and also evaluate the protection and overhead of our prototype using AOMDV for routing.
Quan Jia, Kun Sun 0001, Angelos Stavrou
ICCCN3
2011 Cross-Domain Collaborative Anomaly Detection: So Far Yet So Close
Nathaniel Boggs, Sharath Hiremagalore, Angelos Stavrou, Salvatore J. Stolfo
RAID3
2011 Trading Elephants for Ants: Efficient Post-attack Reconstitution
Meixing Le, Quan Jia, Angelos Stavrou, Anup K. Ghosh, Sushil Jajodia
SecureComm4
2010 Exploiting smart-phone USB connectivity for fun and profit
abstract
The Universal Serial Bus (USB) connection has become the de-facto standard for both charging and data transfers for smart phone devices including Google's Android and Apple's iPhone. To further enhance their functionality, smart phones are equipped with programmable USB hardware and open source operating systems that empower them to alter the default behavior of the end-to-end USB communications. Unfortunately, these new capabilities coupled with the inherent trust that users place on the USB physical connectivity and the lack of any protection mechanisms render USB a insecure link, prone to exploitation. To demonstrate this new avenue of exploitation, we introduce novel attack strategies that exploit the functional capabilities of the USB physical link. In addition, we detail how a sophisticated adversary who has under his control one of the connected devices can subvert the other. This includes attacks where a compromised smart phone poses as a Human Interface Device (HID) and sends keystrokes in order to control the victim host. Moreover, we explain how to boot a smart phone device into USB host mode and take over another phone using a specially crafted cable. Finally, we point out the underlying reasons behind USB exploits and propose potential defense mechanisms that would limit or even prevent such USB borne attacks.
Angelos Stavrou
ACSAC2
2010 Providing Mobile Users' Anonymity in Hybrid Networks
Claudio A. Ardagna, Sushil Jajodia, Pierangela Samarati, Angelos Stavrou
ESORICS4
2010 Traffic Analysis against Low-Latency Anonymity Networks Using Available Bandwidth Estimation
Sambuddho Chakravarty, Angelos Stavrou, Angelos D. Keromytis
ESORICS2
2010 HyperCheck: A Hardware-Assisted Integrity Monitor
Jiang Wang 0008, Angelos Stavrou, Anup K. Ghosh
RAID2
2010 Scalable Web Object Inspection and Malfease Collection
Charalampos Andrianakis, Paul Seymer, Angelos Stavrou
HotSec3
2010 On the infeasibility of modeling polymorphic shellcode - Re-thinking the role of learning in intrusion detection systems
Yingbo Song, Michael E. Locasto, Angelos Stavrou, Angelos D. Keromytis, Salvatore J. Stolfo
Mach. Learn.3
2009 Adding Trust to P2P Distribution of Paid Content
Alex Sherman, Angelos Stavrou, Jason Nieh, Angelos D. Keromytis, Clifford Stein 0001
ISC2
2009 A2M: Access-Assured Mobile Desktop Computing
Angelos Stavrou, Ricardo A. Barrato, Angelos D. Keromytis, Jason Nieh
ISC1
2009 Adaptive Anomaly Detection via Self-calibration and Dynamic Updating
Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo
RAID2
2009 Deny-by-Default Distributed Security Policy Enforcement in Mobile Ad Hoc Networks
Mansoor Alicherry, Angelos D. Keromytis, Angelos Stavrou
SecureComm3
2008 Pushback for Overlay Networks: Protecting Against Malicious Insiders
Angelos Stavrou, Michael E. Locasto, Angelos D. Keromytis
ACNS1
2008 PAR: Payment for Anonymous Routing
Elli Androulaki, Mariana Raykova 0001, Shreyas Srivatsan, Angelos Stavrou, Steven M. Bellovin
Privacy Enhancing Technologies4
2008 Casting out Demons: Sanitizing Training Data for Anomaly Sensors
abstract
The efficacy of anomaly detection (AD) sensors depends heavily on the quality of the data used to train them. Artificial or contrived training data may not provide a realistic view of the deployment environment. Most realistic data sets are dirty; that is, they contain a number of attacks or anomalous events. The size of these high-quality training data sets makes manual removal or labeling of attack data infeasible. As a result, sensors trained on this data can miss attacks and their variations. We propose extending the training phase of AD sensors (in a manner agnostic to the underlying AD algorithm) to include a sanitization phase. This phase generates multiple models conditioned on small slices of the training data. We use these "micro- models" to produce provisional labels for each training input, and we combine the micro-models in a voting scheme to determine which parts of the training data may represent attacks. Our results suggest that this phase automatically and significantly improves the quality of unlabeled training data by making it as "attack-free" and "regular" as possible in the absence of absolute ground truth. We also show how a collaborative approach that combines models from different networks or domains can further refine the sanitization process to thwart targeted training or mimicry attacks against a single site.
Gabriela F. Ciocarlie, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, Angelos D. Keromytis
SP2
2007 On the infeasibility of modeling polymorphic shellcode
abstract
Polymorphic malcode remains a troubling threat. The ability formal code to automatically transform into semantically equivalent variants frustrates attempts to rapidly construct a single, simple, easily verifiable representation. We present a quantitative analysis of the strengths and limitations of shellcode polymorphism and consider its impact on current intrusion detection practice.
Yingbo Song, Michael E. Locasto, Angelos Stavrou, Angelos D. Keromytis, Salvatore J. Stolfo
CCS3
2007 A Study of Malcode-Bearing Documents
Wei-Jen Li, Salvatore J. Stolfo, Angelos Stavrou, Elli Androulaki, Angelos D. Keromytis
DIMVA3
2007 From STEM to SEAD: Speculative Execution for Automated Defense
Michael E. Locasto, Angelos Stavrou, Gabriela F. Ciocarlie, Angelos D. Keromytis
USENIX ATC2
2006 W3Bcrypt: Encryption as a Stylesheet
Angelos Stavrou, Michael E. Locasto, Angelos D. Keromytis
ACNS1
2006 Dark application communities
Michael E. Locasto, Angelos Stavrou, Angelos D. Keromytis
NSPW2
2005 Countering DoS attacks with stateless multipath overlays
abstract
Indirection-based overlay networks (IONs) are a promising approach for countering distributed denial of service (DDoS) attacks. Such mechanisms are based on the assumption that attackers will attack a fixed and bounded set of overlay nodes causing service disruption to a small fraction of the users. In addition, attackers cannot eaves-drop on links inside the network or otherwise gain information that can help them focus their attacks on overlay nodes that are critical for specific communication flows. We develop an analytical model and a new class of attacks that considers both simple and advanced adversaries. We show that the impact of these simple attacks on IONs can severely disrupt communications. We propose a stateless spread-spectrum paradigm to create per-packet path diversity between each pair of end-nodes using a modified ION access protocol. Our system protects end-to-end communications from DoS attacks without sacrificing strong client authentication or allowing an attacker with partial connectivity information to repeatedly disrupt communications. Through analysis, we show that an Akamai-sized overlay can withstand attacks involving over 1.3M "zombie" hosts while providing uninterrupted end-to-end connectivity. By using packet replication, the system can resist attacks that render up to 40% of the nodes inoperable. Surprisingly, our experiments on PlanetLab demonstrate that in many cases end-to-end latency decreases when packet replication is used, with a worst-case increase by a factor of 2.5. Similarly, our system imposes less than 15% performance degradation in the end-to-end throughput, even when subjected to a large DDoS attack.
Angelos Stavrou, Angelos D. Keromytis
CCS1
2005 gore: Routing-Assisted Defense Against DDoS Attacks
Stephen T. Chou, Angelos Stavrou, John Ioannidis, Angelos D. Keromytis
ISC2
2005 MOVE: An End-to-End Solution to Network Denial of Service
Angelos Stavrou, Angelos D. Keromytis, Jason Nieh, Vishal Misra, Dan Rubenstein
NDSS1
2005 WebSOS: an overlay-based system for protecting web servers from denial of service attacks
Angelos Stavrou, Debra L. Cook, William G. Morein, Angelos D. Keromytis, Vishal Misra, Dan Rubenstein
Comput. Networks1
2004 A Pay-per-Use DoS Protection Mechanism for the Web
Angelos Stavrou, John Ioannidis, Angelos D. Keromytis, Vishal Misra, Dan Rubenstein
ACNS1
2004 A lightweight, robust P2P system to handle flash crowds
abstract
An Internet flash crowd (also known as hot spots) is a phenomenon that results from a sudden, unpredicted increase in an on-line object's popularity. Currently, there is no efficient means within the Internet to deliver Web objects scalably under hot spot conditions to all clients that desire the object. We present peer-to-peer (P2P) randomized overlays to obviate flash-crowd symptoms (PROOFS), a simple, lightweight, P2P approach that uses randomized overlay construction and randomized, scoped searches to locate and deliver objects efficiently under heavy demand to all users that desire them. We evaluate PROOFS' robustness in environments in which clients join and leave the P2P network, as well as in environments in which clients are not always fully cooperative. Through a mix of simulation and prototype experimentation in the Internet, we show that randomized approaches like PROOFS should effectively relieve flash crowd symptoms in dynamic, limited-participation environments.
Angelos Stavrou, Dan Rubenstein, Sambit Sahu
IEEE J. Sel. Areas Commun.1
2003 Using graphic turing tests to counter automated DDoS attacks against web servers
abstract
We present WebSOS, a novel overlay-based architecture that provides guaranteed access to a web server that is targeted by a denial of service (DoS) attack. Our approach exploits two key characteristics of the web environment: its design around a human-centric interface, and the extensibility inherent in many browsers through downloadable "applets." We guarantee access to a web server for a large number of previously unknown users, without requiring pre-existing trust relationships between users and the system.Our prototype requires no modifications to either servers or browsers, and makes use of graphical Turing tests, web proxies, and client authentication using the SSL/TLS protocol, all readily supported by modern browsers. We use the WebSOS prototype to conduct a performance evaluation over the Internet using PlanetLab, a testbed for experimentation with network overlays. We determine the end-to-end latency using both a Chord-based approach and our shortcut extension. Our evaluation shows the latency increase by a factor of 7 and 2 respectively, confirming our simulation results.
William G. Morein, Angelos Stavrou, Debra L. Cook, Angelos D. Keromytis, Vishal Misra, Dan Rubenstein
CCS2
2002 A Lightweight, Robust P2P System to Handle Flash Crowds
abstract
Internet flash crowds (a.k.a. hot spots) are a phenomenon that result from a sudden, unpredicted increase in an on-line object's popularity. Currently, there is no efficient means within the Internet to scalably deliver Web objects under hot spot conditions to all clients that desire the object. We present PROOFS: a simple, lightweight, peer-to-peer (P2P) approach that uses randomized overlay construction and randomized, scoped searches to efficiently locate and deliver objects under heavy demand to all users that desire them. We evaluate PROOFS' robustness in environments in which clients join and leave the P2P network as well as in environments in which clients are not always fully cooperative. Through a mix of simulation and prototype experimentation in the Internet, we show that randomized approaches like PROOFS should effectively relieve flash crowd symptoms in dynamic, limited-participation environments.
Angelos Stavrou, Dan Rubenstein, Sambit Sahu
ICNP1