Nasser Nowdehi

dblp:148/7296 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0003-4869-6409ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2026 On the Reduction of Error Space for Model-Implemented Fault- and Attack Injection
abstract
Fault- and attack injection are techniques used to measure dependability attributes of computer systems. An important property of such techniques is their efficiency in exploring the target system's fault- or attack space. As this space is generally very large, pre-injection analysis techniques may be used to effectively explore the space. In this paper, we study two such techniques proposed in the past, namelyinject-on-readandinject-on-write. Furthermore, we propose two new techniques callederror space pruning of signalsanderror space pruning of signals and portsand evaluate their efficiency in reducing the space needed to be explored by injection experiments. These techniques were integrated into MODIFI, a fault- and attack injector targeting Simulink models. To the best of our knowledge, we are the first to evaluate these pre-injection techniques for this kind of injector. The results of our evaluation of 11 Simulink models from the automotive domain and one from the avionics domain, show that the new proposed techniques reduce the fault- and attack space needed to be explored by about 27–49%. Using MODIFI, we then performed injection experiments on two automotive models, as well as an aero engine control model, while elaborating on the results obtained.
Peter Folkesson, Behrooz Sangchoolie, Pierre Kleberger, Nasser Nowdehi, Georgios Giantamidis, Vassilios A. Tsachouridis, Stylianos Basagiannis
IEEE Trans. Dependable Secur. Comput.4
2022 On the Evaluation of Three Pre-Injection Analysis Techniques for Model-Implemented Fault- and Attack Injection
abstract
Fault- and attack injection are techniques used to measure dependability attributes of computer systems. An important property of such injectors is their efficiency that deals with the time and effort needed to explore the target system's fault- or attack space. As this space is generally very large, techniques such as pre-injection analyses are used to effectively explore the space. In this paper, we study two such techniques that have been proposed in the past, namely inject-on-read and inject-on-write. Moreover, we propose a new technique called error space pruning of signals and evaluate its efficiency in reducing the space needed to be explored by fault and attack injection experiments. We implemented and integrated these techniques into MODIFI, a model-implemented fault and attack injector, which has been effectively used in the past to evaluate Simulink models in the presence of faults and attacks. To the best of our knowledge, we are the first to integrate these pre-injection analysis techniques into an injector that injects faults and attacks into Simulink models. The results of our evaluation on 11 vehicular Simulink models show that the error space pruning of signals reduce the attack space by about 30–43%, hence allowing the attack space to be exploited by fewer number of attack injection experiments. Using MODIFI, we then performed attack injection experiments on two of these vehicular Simulink models, a comfort control model and a brake-by-wire model, while elaborating on the results obtained.
Peter Folkesson, Behrooz Sangchoolie, Pierre Kleberger, Nasser Nowdehi
PRDC4
2022 CONSERVE: A framework for the selection of techniques for monitoring containers security
abstract
Container-based virtualization is gaining popularity in different domains, as it supports continuous development and improves the efficiency and reliability of run-time environments. Different techniques are proposed for monitoring the security of containers. However, there are no guidelines supporting the selection of suitable techniques for the tasks at hand. We aim to support the selection and design of techniques for monitoring container-based virtualization environments. : First, we review the literature and identify techniques for monitoring containerized environments. Second, we classify these techniques according to a set of categories, such as technical characteristic, applicability, effectiveness, and evaluation. We further detail the pros and cons that are associated with each of the identified techniques. As a result, we present CONSERVE, a multi-dimensional decision support framework for an informed and optimal selection of a suitable set of container monitoring techniques to be implemented in different application domains. A mix of eighteen researchers and practitioners evaluated the ease of use, understandability, usefulness, efficiency, applicability, and completeness of the framework. The evaluation shows a high level of interest, and points out to potential benefits.
Rodi Jolak, Thomas Rosenstatter, Mazen Mohamad, Kim Strandberg, Behrooz Sangchoolie, Nasser Nowdehi, Riccardo Scandariato
J. Syst. Softw.6
2021 Resilient Shield: Reinforcing the Resilience of Vehicles Against Security Threats
abstract
Vehicles have become complex computer systems with multiple communication interfaces. In the future, vehicles will have even more connections to e.g., infrastructure, pedestrian smartphones, cloud, road-side-units and the Internet. External and physical interfaces, as well as internal communication buses have shown to have potential to be exploited for attack purposes. As a consequence, there is an increase in regulations which demand compliance with vehicle cyber resilience requirements. However, there is currently no clear guidance on how to comply with these regulations from a technical perspective.To address this issue, we have performed a comprehensive threat and risk analysis based on published attacks against vehicles from the past 10 years, from which we further derive necessary security and resilience techniques. The work is done using the SPMT methodology where we identify vital vehicle assets, threat actors, their motivations and objectives, and develop a comprehensive threat model. Moreover, we develop a comprehensive attack model by analyzing the identified threats and attacks. These attacks are filtered and categorized based on attack type, probability, and consequence criteria. Additionally, we perform an exhaustive mapping between asset, attack, threat actor, threat category, and required mitigation mechanism for each attack, resulting in a presentation of a secure and resilient vehicle design. Ultimately, we present the Resilient Shield a novel and imperative framework to justify and ensure security and resilience within the automotive domain.
Kim Strandberg, Thomas Rosenstatter, Rodi Jolak, Nasser Nowdehi, Tomas Olovsson
VTC Spring4
2019 A Preliminary Security Assessment of 5G V2X
abstract
Research on intelligent transport systems (ITS) for improved traffic safety and efficiency has reached a high level of maturity and first applications will hit the market in 2019. Since 2004, the wireless standard 802.11p has been developed specifically for ITS services. Since then new telecommunication standards have been devised, and the new 5G telecommunication standard is nearing completion. Due to its technological advantages such as higher speeds and reliability, it is being considered to be used for ITS services. The new radio technology "New Radio (NR)'', which is being developed as part of 5G, can complement or replace 802.11p in V2X applications. While there has been some work to compare 802.11p and 5G New Radio in terms of performance and applicability for safety-critical use cases, little work has been done to investigate the implications for security. In this paper, we provide an overview of the security requirements of known ETSI ITS use cases, and based on those use cases we compare and assess the security implications of replacing 802.11p with cellular V2X. We find that due to the use of millimeter waves, beamforming and massive MIMO, there will be an implicit improvement for confidentiality and privacy, and it may also be possible to shorten authentication procedures in certain cases. When a fully network-assisted C-V2X mode is chosen, it is also possible to outsource several of the ITS security requirements to the cellular network.
Aljoscha Lautenbach, Nasser Nowdehi, Tomas Olovsson, Romi Zaragatzky
VTC Spring2
2017 In-Vehicle CAN Message Authentication: An Evaluation Based on Industrial Criteria
abstract
Vehicles have evolved from mostly mechanical machines into devices controlled by an internal computer network consisting of more than 100 interconnected Electronic Control Units (ECUs). Moreover, modern vehicles communicate with external devices to enable new features, but these new communication facilities also expose safety-critical functions to security threats. As the most prevalent automotive bus, the Controller Area Network (CAN) bus is a prime target for attacks. Even though the computer security community has proposed several message authentication solutions to alleviate those threats, such solutions have not yet been widely adopted by the automotive industry. We have identified the most promising CAN message authentication solutions and provide a comprehensive overview of them. In order to investigate the lack of adoption of such solutions, we, together with industry experts, have identified five general requirements they must fulfill in order to be considered viable in industry. Based on those requirements, we analyze and evaluate the identified authentication solutions. We find that none of them meet all the requirements, and that backward compatibility and acceptable overhead are the biggest obstacles.
Nasser Nowdehi, Aljoscha Lautenbach, Tomas Olovsson
VTC Fall1
2014 Experiences from implementing the ETSI ITS SecuredMessage service
abstract
Cooperative intelligent transport systems supporting secure vehicle to vehicle and vehicle to infrastructure communications, is becoming a very important topic. The aim of this paper is to share our experiences from implementing the ETSI Intelligent Transport System (ITS) SecuredMessage and sign/verify services on an existing ETSI ITS communication stack (ITSC). We have followed the new ETSI TS 103 097 v1.1.1 standard when implementing the security services, and have made our best to create a robust and secure implementation. Our goal has been to identify flaws and vulnerabilities in our implementation that are caused by weaknesses or deficiencies in the standard and in its description of services. We have then performed an analysis of the protocol, its headers and created test cases used to test our implementation. Several problems were found, and we have also repeated the tests with another, supposedly very stable implementation, provided by Fraunhofer FOKUS. To our surprise, this system also showed unexpected behavior as our system. We show that these problems are the result of weaknesses and complexities in the design of the standard. We present the problems found in our implementation and show what part in the standard was causing the problems. We show that several problems in the standard, mainly due to their complexity, open up for misinterpretation leading to various types of implementation errors. We conclude the paper with proposing changes to the standard to prevent other implementations from repeating the same mistakes.
Nasser Nowdehi, Tomas Olovsson
Intelligent Vehicles Symposium1