VLDB 2026 Research / reviewers in the wild / expert
Loukas Lazos
dblp:15/3615
· DBLP profile ↗
62ranked-venue papers
14as first author
9since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 40 · 11 first-author · 5 since 2021Security and privacy · 14 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Harvesting Physical-Layer Randomness in Millimeter Wave BandsabstractThe unpredictability of the wireless channel has been used as a natural source of randomness to build physical-layer security primitives for shared key generation, authentication, access control, proximity verification, and other security properties. Compared to pseudo-random generators, it has the potential to achieve information-theoretic security. In sub-6 GHz frequencies, the randomness is harvested from the small-scale fading effects of RF signal propagation in rich scattering environments. However, the RF propagation characteristics follow sparse models with clustered paths when devices operate in millimeter-wave (mmWave) bands (5G and Next-Generation networks, Wi-Fi in 60GHz). Millimeter-wave transmissions are typically directional to increase the gain and combat high signal attenuation, leading to stable and more predictable channels. In this paper, we first demonstrate that state-of-the-art methods relying on channel state information or received signal strength measurements fail to produce high randomness. Accounting for the unique features of mmWave propagation, we propose a novel randomness extraction mechanism that exploits the random timing of channel blockage to harvest random bits. Compared with the prior art in CSI-based and context-based randomness extraction, our protocol remains secure againstpassive and active Man-in-the-Middle adversaries co-located with the legitimate devices. We demonstrate the security properties of our method in a 28 GHz mmWave testbed in an indoor setting. Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Ming Li 0003, Loukas Lazos |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | ZITA: Zero-Interaction Two-Factor Authentication Using Contact Traces and In-Band Proximity VerificationabstractTwo-factor authentication (TFA) provides an additional layer of protection to commonly-occurring password breaches. However, existing TFA methods, often involve special hardware interfaces, or require human effort which is prone to errors and acts as an adoption detractor for older adults and novice technology users. To address these limitations, we propose a zero-interaction, two-factor authentication (ZITA) protocol. In ZITA, the first factor is implemented using the conventional username and password methods. The second factor is completed without any human effort provided that the user is not accessing the service from an unregistered public device and a designated secondary device is physically co-present. To automate the second factor, ZITA exploits the long-term contact between the login device and the secondary device such as a smartphone. Moreover, to thwart man-in-the-middle and co-located attacks, ZITA incorporates a proximity verification test that relies on the randomness of ambient RF signals. Compared with other zero-effort TFA protocols, ZITA remains secure against advanced threats and does not require out-of-band sensors such as microphones, speakers, or photoplethysmography (PPG) sensors. Nirnimesh Ghose, Kaustubh Gupta, Loukas Lazos, Ming Li 0003, Ziqi Xu 0006 |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Misbehavior Detection in Wi-Fi/LTE Coexistence Over Unlicensed BandsabstractWe address the problem of detecting misbehavior in the coexistence etiquette between LTE and Wi-Fi systems operating in the 5GHz U-NII unlicensed bands. We define selfish misbehavior strategies for the LTE that can yield an unfair share of the spectrum resources. Such strategies are based on manipulating the operational parameters of the LTE-LAA standard, namely the backoff mechanism, the traffic class parameters, the clear channel access (CCA) threshold, and others. Prior methods for detecting misbehavior in homogeneous settings are not applicable in a spectrum sharing scenario because the devices of one system cannot decode the transmissions of another. We develop implicit sensing techniques that can accurately estimate the operational parameters of LTE transmissions under various topological scenarios andwithout decoding.These techniques apply correlation-based signal detection to infer the required information. Our techniques are validated through experiments on a USRP testbed. We further apply a statistical inference framework for determining deviations of the LTE behavior from the coexistence etiquette. By characterizing the detection and false alarm probabilities, we show that our framework yields high detection accuracy at a very low false alarm rate. Although our methods focus on detecting misbehavior of the LTE system, they can be generalized to detect Wi-Fi misbehavior and to other coexistence scenarios. Islam Samy, Loukas Lazos, Ming Li 0003, Yong Xiao 0001, Marwan Krunz |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | PoF: Proof-of-Following for Vehicle Platoons
Ziqi Xu 0006, Jingcheng Li, Yanjun Pan 0001, Loukas Lazos, Ming Li 0003, Nirnimesh Ghose |
NDSS | 4 |
| 2022 | In-Band Secret-Free Pairing for COTS Wireless DevicesabstractMany IoT devices lack the necessary interfaces (keyboards, screens) for entering passwords or changing default ones. For these devices, bootstrapping trust can be challenging. We address the problem of device pairing in the absence of any shared secrets. Pairing is a two-phase process that requires mutual authentication between the two parties and the agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose a secret-free and in-band trust establishment protocol that achieves the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. As compared to the state-of-the-art, our protocol does not require any hardware/firmware modification to the devices, or any out-of-band channels, but can be applied to any COTS device. Furthermore, our protocol is resistant to active signal manipulations attacks that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by exploiting hard-to-forge signal propagation laws. We perform extensive theoretical analysis to verify the security of the proposed protocol. In addition, we validate our theoretical results with experiments using COTS devices and USRP radios. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Trans. Mob. Comput. | 2 |
| 2021 | On the Capacity of Latent Variable Private Information RetrievalabstractIn latent-variable private information retrieval (LV-PIR), a user wishes to retrieve one out of$K$messages (indexed by θ) without revealing any information about a sensitive latent attribute (modeled by a latent variable$S$correlated with θ). While conventional PIR protocols, which keep θ2private, also suffice for hiding S, they can be too costly in terms of the download overhead. In this paper, we characterize the capacity (equivalently, the optimal download cost) of LV-PIR as a function of the distribution PS|θ. We present a converse proof that yields a lower bound on the optimal download cost, and a matching achievable scheme. The optimal scheme, however, involves an exhaustive search over subset queries and over all messages, which can be computationally prohibitive. We further present two low-complexity, albeit sub-optimal, schemes that also outperform the conventional PIR solution. Islam Samy, Mohamed Adel Attia, Ravi Tandon, Loukas Lazos |
ISIT | 4 |
| 2021 | Man-in-the-Middle Attack Resistant Secret Key Generation via Channel RandomizationabstractPhysical-layer based key generation schemes exploit the channel reciprocity for secret key extraction, which can achieve information-theoretic secrecy against eavesdroppers. Such methods, although practical, have been shown to be vulnerable against man-in-the-middle (MitM) attacks, where an active adversary, Mallory, can influence and infer part of the secret key generated between Alice and Bob by injecting her own packet upon observing highly correlated channel/RSS measurements from Alice and Bob. As all the channels remain stable within the channel coherence time, Mallory's injected packets cause Alice and Bob to measure similar RSS, which allows Mallory to successfully predict the derived key bits. To defend against such a MitM attack, we propose to utilize a reconfigurable antenna at one of the legitimate transceivers to proactively randomize the channel state across different channel probing rounds. The randomization of the antenna mode at every probing round breaks the temporal correlation of the channels from the adversary to the legitimate devices, while preserving the reciprocity of the channel between the latter. This prevents key injection from the adversary without affecting Alice and Bob's ability to measure common randomness. We theoretically analyze the security of the protocol and conduct extensive simulations and real-world experiments to evaluate its performance. Our results show that our approach eliminates the advantage of an active MitM attack by driving down the probability of successfully guessing bits of the secret key to a random guess. Yanjun Pan 0001, Ziqi Xu 0006, Ming Li 0003, Loukas Lazos |
MobiHoc | 4 |
| 2021 | Repair Strategies for Mobile Storage SystemsabstractWe study the data reliability problem for devices forming a dynamic distributed storage system. Such systems are commonplace in traditional cloud storage applications where storage node failures and updates are frequent. We consider the application of regenerating codes for file maintenance. Such codes require lower bandwidth to regenerate lost data fragments compared to file replication or reconstruction. We investigate threshold-based repair strategies where data repair is initiated after a threshold number of data fragments have been lost. We show that at a low departure-to-repair rate regime, in which repairs are initiated after several nodes have left the system outperforms if repairs are initiated after a single node departure. This optimality is reversed when the node turnover is high. We further compare distributed and centralized repair strategies and derive the optimal repair threshold for minimizing the average repair cost per unit of time. In addition, we examine cooperative repair strategies and show performance improvements. We investigate several models for the time needed for node repair including a simple fixed time model and a more realistic model that takes into account the number of repaired nodes. Finally, an extended model where additional failures are allowed during the repair process is investigated. Gokhan Calis, Swetha Shivaramaiah, Onur Ozan Koyluoglu, Loukas Lazos |
IEEE Trans. Cloud Comput. | 4 |
| 2021 | Asymmetric Leaky Private Information RetrievalabstractInformation-theoretic formulations of the private information retrieval (PIR) problem have been investigated under a variety of scenarios. Symmetric private information retrieval (SPIR) is a variant where a user is able to privately retrieve one out of K messages from N non-colluding replicated databases without learning anything about the remaining K-1 messages. However, the goal of perfect privacy can be too taxing for certain applications. In this paper, we investigate if the information-theoretic capacity of SPIR (equivalently, the inverse of the minimum download cost) can be increased by relaxing both user and DB privacy definitions. Such relaxation is relevant in applications where privacy can be traded for communication efficiency. We introduce and investigate the Asymmetric Leaky PIR (AL-PIR) model with different privacy leakage budgets in each direction. For user privacy leakage, we bound the probability ratios between all possible realizations of DB queries by a function of a non-negative constant ϵ. For DB privacy, we bound the mutual information between the undesired messages, the queries, and the answers, by a function of a non-negative constant δ. We propose a general AL-PIR scheme that achieves an upper bound on the optimal download cost for arbitrary ϵ and δ. We show that the optimal download cost of AL-PIR is upper-bounded as D*(ϵ,δ) ≤ 1+\frac 1N-1-\frac δeϵNK-1-1. Second, we obtain an information-theoretic lower bound on the download cost as D*(ϵ,δ) ≥ 1+\frac 1Neϵ-1-\frac δ(Neϵ)K-1-1. The gap analysis between the two bounds shows that our AL-PIR scheme is optimal when ϵ = 0, i.e., under perfect user privacy and it is optimal within a maximum multiplicative gap of \frac N-e-ϵN-1 for any ϵ > 0 and δ > 0. Islam Samy, Mohamed Adel Attia, Ravi Tandon, Loukas Lazos |
IEEE Trans. Inf. Theory | 4 |
| 2020 | Energy-efficient LTE/Wi-Fi CoexistenceabstractMotivated by the shared spectrum paradigm, we address the problem of implicit coordination between coexisting wireless systems that do not share a common control plane. We consider the coexistence of LTE and Wi-Fi and study mechanisms for conserving energy when the wireless channel is occupied. In a Wi-Fi only system, the network allocation vector (NAV) included in the header of IEEE 802.11 frames advertises the duration of an imminent transmission. Nearby Wi-Fi terminals decode the frame header and transition to sleep mode to conserve energy. However, when heterogeneous systems coexist (e.g., LTE and Wi-Fi), frames that belong to other systems are not decodable. This leads to continuous channel sensing even when the channel is to be occupied for a long duration. We design two implicit mechanisms to play the role of the NAV. Our mechanisms predict the duration of an imminent LTE transmission by predicting the frame's traffic class. The prediction is based on the elapsed idle slots between successive transmissions and the transmission history. We show that our methods achieve significant energy savings without stifling transmission opportunities. Islam Samy, Loukas Lazos |
ICC | 3 |
| 2020 | Privacy-Utility Tradeoff in Dynamic Spectrum Sharing with Non-Cooperative Incumbent UsersabstractDynamic spectrum access enables opportunistic users (OUs) to access underutilized licensed bands by querying spectrum databases. However, the operational details of the incumbent users may leak to OUs during the query process. Privacy and exclusion zones have been proposed as effective countermeasures to protect the IUs' privacy, while also managing interference. In the case of multiple heterogeneous coexisting IUs, there is an inherent tradeoff between their achieved throughput, which is controlled by the received interference, and the utility provided to OUs, under a fixed privacy constraint. In this paper, we address the problem of maximizing the utility of rational IUs, defined as the weighted sum between the IUs' capacity and compensation from allowing OUs' opportunistic access while meeting the individual IUs' privacy constraints. We formulate the interaction between the heterogeneous IUs as a non-cooperative continuous game and derive the Nash equilibrium that maximizes the utility of each IU. Our simulations show that the NE solution improves the individual utilities of the IUs compared to a joint optimization approach, where the sum of the utilities is maximized while providing more fairness to the IUs. Ahmed M. Salama, Ming Li 0003, Loukas Lazos, Yong Xiao 0001, Marwan Krunz |
ICC | 3 |
| 2020 | Latent-variable Private Information RetrievalabstractIn many applications, content accessed by users (movies, videos, news articles, etc.) can leak sensitive latent attributes, such as religious and political views, sexual orientation, ethnicity, gender, and others. To prevent such information leakage, the goal of classical PIR is to hide the identity of the content/message being accessed, which subsequently also hides the latent attributes. This solution, while private, can be too costly, particularly, when perfect (information-theoretic) privacy constraints are imposed. For instance, for a single database holding K messages, privately retrieving one message is possible if and only if the user downloads the entire database of K messages. Retrieving content privately, however, may not be necessary to perfectly hide the latent attributes.Motivated by the above, we formulate and study the problem of latent-variable private information retrieval (LV-PIR), which aims at allowing the user efficiently retrieve one out of K messages (indexed by θ) without revealing any information about the latent variable (modeled by S). We focus on the practically relevant setting of a single database and show that one can significantly reduce the download cost of LV-PIR (compared to the classical PIR) based on the correlation between θ and S. We present a general scheme for LV-PIR as a function of the statistical relationship between θ and S, and also provide new results on the capacity/download cost of LV-PIR. Several open problems and new directions are also discussed. Islam Samy, Mohamed Adel Attia, Ravi Tandon, Loukas Lazos |
ISIT | 4 |
| 2020 | Misbehavior in Multi-Channel MAC ProtocolsabstractMulti-channel MAC (MMAC) protocols are designed to coordinate multi-user access to several non-overlapping frequency bands. They are primarily tasked with the efficient and fair bandwidth utilization under a variety of traffic load conditions, presuming that terminals follow the protocol specifications. However, selfish terminals can manipulate the protocol parameters to gain an unfair share of the common bandwidth. The problem of selfish MAC-layer misbehavior is well-studied for single-channel MAC protocols, but little attention has been paid when channel access is coordinated across multiple channels. In this paper, we address the problem of MAC-layer misbehavior in the multi-channel domain. We identify misbehavior strategies for popular classes of MMAC protocols (split-phase and dedicated control channel MMACs) and evaluate their impact on network throughput and fairness. We show that selfish terminals can easily isolate frequency bands for exclusive use without violating the protocol specifications. We develop corresponding detection and mitigation strategies that greatly reduce the throughput gains due to misbehavior. Yan Zhang 0019, Loukas Lazos |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Proofs of Physical Reliability for Cloud Storage SystemsabstractCloud service providers (CSPs) promise to reliably store repositories outsourced by clients. Unfortunately, once files have left the client's control, he has no means to verify their redundant storage. In this article, we develop Proof of Physical Reliability (PoPR) auditing mechanisms that prove that a CSP stores an outsourced repository across multiple physical storage nodes. A PoPR complements the existing proof-of-retrievability (PoR) and proof-of-data possession (PDP) methods that are concerned with file retrievability, but without any verification of the fault-tolerance to physical storage nodes failures. A PoPR goes beyond retrievability by verifying that a file is redundantly stored across multiple physical storage nodes according to a pre-agreed layout and can, therefore, survive node failures. The verification mechanism relies on a combination of storage integrity and timing tests on the simultaneous retrieval of a collection of file symbols from multiple storage nodes. Compared to the state-of-the-art, our approach accommodates CSPs with heterogeneous storage devices (hard disks, SSDs, etc.) and does not assume constant data processing nor network delays. Instead, it can operate under any delayvariance, because it relies only on (loose) delay bounds. We analytically prove the security of our construction and experimentally validate its success in heterogeneous storage settings. Li Li 0077, Loukas Lazos |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2019 | Optimum Priority Class Selection Under Wi-Fi/LTE CoexistenceabstractWi-Fi and LTE standards define several traffic classes to prioritize applications based on their requirements. When these technologies coexist in unlicensed bands, the class selection of one system impacts the performance of the other. In this paper, we investigate how the traffic class selection affects the delay for completing the transmission of a fixed number of bits. We develop an analytical framework which characterizes the average delay under Wi-Fi/LTE coexistence. Our framework allows us to optimize the class selection for a Wi-Fi or LTE station based on the traffic class selected by the surrounding stations and minimize the average delay. We show that operating at a high priority class does not always minimize delay. Under certain contention and class selection conditions, a low priority class reduces the collision probability while increasing the airtime once the channel is captured. This leads to a lower overall delay. We provide numerical examples that demonstrate the inherent tradeoffs between the traffic class parameters. Islam Samy, Loukas Lazos |
ICC | 2 |
| 2019 | On the Capacity of Leaky Private Information RetrievalabstractPrivate information retrieval (PIR) allows users to retrieve data from databases without revealing the identity of that data. An extensive body of works has investigated efficient schemes to achieve computational and information-theoretic privacy. The latter guarantees that no information is revealed to the databases, irrespective of their computational power. Although information-theoretic PIR (IT-PIR) provides a strong privacy guarantee, it can be too taxing for certain applications. In this paper, we initiate the study of leaky private information retrieval (L-PIR), where a bounded amount of privacy leakage is allowed and measured through a parameter ε. The classical IT-PIR formulation is obtained by setting ε = 0, and for ε > 0, we explore the opportunities offered for reducing the download cost. We derive new upper and lower bounds on the download cost of L-PIR for any arbitrary ε, any number of messages K, and for N = 2 databases. Islam Samy, Ravi Tandon, Loukas Lazos |
ISIT | 3 |
| 2018 | SFIRE: Secret-Free-in-band Trust Establishment for COTS Wireless DevicesabstractWe address the problem of trust establishment between wireless devices that do not share any prior secrets. This includes the mutual authentication and agreement to a common key that can be used to further bootstrap essential cryptographic mechanisms. We propose SFIRE, a secret-free trust establishment protocol that allows the secure pairing of commercial off-the-shelf (COTS) wireless devices with a hub. Compared to the state-of-the-art, SFIRE does not require any out-of-band channels, special hardware, or firmware modification, but can be applied to any COTS device. Moreover, SFIRE is resistant to the most advanced active signal manipulations that include recently demonstrated signal nullification at an intended receiver. These security properties are achieved in-band with the assistance of a helper device such as a smartphone and by using the RSS fluctuation patterns to build a robust “RSS authenticator”. We perform extensive experiments using COTS devices and USRP radios and verify the validity of the proposed protocol. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
INFOCOM | 2 |
| 2018 | Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation AttacksabstractIn this paper, we address the fundamental problem of securely bootstrapping a group of wireless devices to a hub, when none of the devices share prior associations (secrets) with the hub or between them. This scenario aligns with the secure deployment of body area networks, IoT, medical devices, industrial automation sensors, autonomous vehicles, and others. We develop VERSE, a physical-layer group message integrity verification primitive that effectively detects advanced wireless signal manipulations that can be used to launch man-in-the-middle (MitM) attacks over wireless. Without using shared secrets to establish authenticated channels, such attacks are notoriously difficult to thwart and can undermine the authentication and key establishment processes. VERSE exploits the existence of multiple devices to verify the integrity of the messages exchanged within the group. We then use VERSE to build a bootstrapping protocol, which securely introduces new devices to the network. Compared to the state-of-the-art, VERSE achieves in-band message integrity verification during secure pairing using only the RF modality without relying on out-of-band channels or extensive human involvement. It guarantees security even when the adversary is capable of fully controlling the wireless channel by annihilating and injecting wireless signals. We study the limits of such advanced wireless attacks and prove that the introduction of multiple legitimate devices can be leveraged to increase the security of the pairing process. We validate our claims via theoretical analysis and extensive experimentations on the USRP platform. We further discuss various implementation aspects such as the effect of time synchronization between devices and the effects of multipath and interference. Note that the elimination of shared secrets, default passwords, and public key infrastructures effectively addresses the related key management challenges when these are considered at scale. Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | LTE Misbehavior Detection in Wi-Fi/LTE Coexistence Under the LAA-LTE StandardabstractIn this paper, we consider the fair coexistence between LTE and Wi-Fi systems in unlicensed bands. We focus on the misbehavior opportunities that stem from the heterogeneity of the coexisting systems and the lack of explicit coordination mechanisms. We show that a selfishly behaving LTE can gain an unfair share of the spectrum resources through the manipulation of the parameters defined in the LAA-LTE standard, including the manipulation of the backoff mechanism of LAA, the traffic class, the clear channel assignment threshold and others. We develop a detection mechanism for the Wi-Fi system that can identify a misbehaving LTE system. Our mechanism advances the state of the art by providing an accurate monitoring method of the LTE behavior under various topological scenarios, without explicit cross-system coordination. Deviations from the expected behavior are determined by computing the statistical distance between the protocol-specified and estimated distributions of the LAA-LTE protocol parameters. We analytically characterize the detection and false alarm probabilities and show that our detector yields high detection accuracy at very low false alarm rate, for a wise choice of statistical parameters. Islam Samy, Loukas Lazos, Yong Xiao 0001, Ming Li 0003, Marwan Krunz |
WISEC | 2 |
| 2018 | Secure Physical Layer VotingabstractDistributed wireless networks often employ voting to perform critical network functions such as fault-tolerant data fusion, cooperative sensing, and reaching consensus. Voting is implemented by sending messages to a fusion center or via direct message exchange between participants. However, the delay overhead of message-based voting can be prohibitive when numerous participants have to share the wireless channel in sequence, making it impractical for time-critical applications. In this paper, we propose a fast PHY-layer voting scheme called PHYVOS, which significantly reduces the delay for collecting and tallying votes. In PHYVOS, wireless devices transmit their votes simultaneously by exploiting the subcarrier orthogonality of OFDM and without explicit messaging. Votes are realized by injecting energy to pre-assigned subcarriers. We show that PHYVOS is secure against adversaries that attempt to manipulate the voting outcome. Security is achieved without employing cryptography-based authentication and message integrity schemes. We analytically evaluate the voting robustness as a function of PHY-layer parameters. We extend PHYVOS to operate in ad hoc groups, without the assistance of a fusion center. We discuss practical implementation challenges related to multi-device frequency and time synchronization and present a prototype implementation of PHYVOS on the USRP platform. We complement the implementation with larger scale simulations. Nirnimesh Ghose, Bocan Hu, Yan Zhang 0019, Loukas Lazos |
IEEE Trans. Mob. Comput. | 4 |
| 2017 | HELP: Helper-Enabled In-Band Device Pairing Resistant Against Signal Cancellation
Nirnimesh Ghose, Loukas Lazos, Ming Li 0003 |
USENIX Security Symposium | 2 |
| 2017 | Traffic Decorrelation Techniques for Countering a Global Eavesdropper in WSNsabstractWe address the problem of preventing the inference of contextual information in event-driven wireless sensor networks (WSNs). The problem is considered under a global eavesdropper who analyzes low-level RF transmission attributes, such as the number of transmitted packets, inter-packet times, and traffic directionality, to infer event location, its occurrence time, and the sink location. We devise a general traffic analysis method for inferring contextual information by correlating transmission times with eavesdropping locations. Our analysis shows that most existing countermeasures either fail to provide adequate protection, or incur high communication and delay overheads. To mitigate the impact of eavesdropping, we propose resource-efficient traffic normalization schemes. In comparison to the state-of-the-art, our methods reduce the communication overhead by more than 50 percent, and the end-to-end delay by more than 30 percent. To do so, we partition the WSN to minimum connected dominating sets that operate in a round-robin fashion. This allows us to reduce the number of traffic sources active at a given time, while providing routing paths to any node in the WSN. We further reduce packet delay by loosely coordinating packet relaying, without revealing the traffic directionality. Alejandro Proaño, Loukas Lazos, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2017 | Multi-Channel Medium Access without Control Channels: A Full Duplex MAC DesignabstractWe address the problem of improving the throughput and security of multi-channel MAC (MMAC) protocols. We design a protocol called FD-MMAC that exploits recent advances in full duplex (FD) communications to coordinate channel access in a distributed manner. Compared with prior MMAC designs, our protocol eliminates the use of dedicated in-band or out-of-band control channels for resolving contention, discovering the resident channel of destinations, and performing load balancing. The elimination of the control channel improves spectral efficiency and mitigates denial-of-service attacks that specifically target the exchange of control information. Moreover, FD-MMAC enables the operation of multi-channel exposed terminals. To achieve these goals, we integrate an advanced suite of PHY-layer techniques, including self interference suppression, error vector magnitude and received power measurements, and signal correlation. We validate the proposed PHY-layer techniques on the NI USRP testbed. Furthermore, we theoretically analyze the throughput performance of FD-MMAC and verify our analysis via packet level simulations. Our results show that FD-MMAC achieves significantly higherthroughput compared with prior art. Finally, we analyze the resilience of FD-MMAC to reactive jamming attacks. Yan Zhang 0019, Loukas Lazos, Kai Chen 0022, Bocan Hu, Swetha Shivaramaiah |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | Threshold-Based File Maintenance Strategies for Mobile Cloud Storage SystemsabstractWe study the data reliability problem for a community of devices forming a mobile cloud storage system. We consider the application of regenerating codes for maintaining a file within a geographically-limited area. Such codes require lower bandwidth to regenerate lost data fragments compared to file replication or reconstruction. We investigate threshold-based repair strategies where data repair is initiated after a threshold number of data fragments have been lost due to node mobility. We show that at a low departure-to-repair rate regime, a lazy repair strategy in which repairs are initiated after several nodes have left the system outperforms eager repair in which repairs are initiated after a single departure. This optimality is reversed when nodes are highly mobile. We further compare distributed and centralized repair strategies and derive the optimal repair threshold for minimizing the average repair cost per unit of time, as a function of underlying code parameters. Swetha Shivaramaiah, Gokhan Calis, Onur Ozan Koyluoglu, Loukas Lazos |
GLOBECOM | 4 |
| 2016 | Swift Jamming Attack on Frequency Offset Estimation: The Achilles' Heel of OFDM SystemsabstractFrequency offset (FO) refers to the difference in the operating frequencies of two radio oscillators. Failure to compensate for the FO may lead to decoding errors, particularly in OFDM systems. To correct the FO, wireless standards append a publicly known preamble to every frame before transmission. In this paper, we demonstrate how an adversary can exploit the known preamble structure of OFDM-based wireless systems, particularly IEEE802.11a/g/n/ac, to launch a very stealth (low energy/duty cycle) reactive jamming attack against the FO estimation mechanism. In this attack, the adversary quickly detects a transmitted OFDM frame and subsequently jams a tiny part of the preamble that is used for FO estimation at the legitimate receiver. By optimizing the energy and structure of the jamming signal and accounting for frame detection timing errors and unknown channel parameters, we empirically show that the adversary can induce a bit error rate close to$0.5$, making the transmission practically irrecoverable. Such vulnerability to FO jamming exists even when the frame is shielded by efficient channel coding. We evaluate the FO estimation attack through simulations and USRP experimentation. We also propose three approaches to mitigate such an attack. Hanif Rahbari, Marwan Krunz, Loukas Lazos |
IEEE Trans. Mob. Comput. | 3 |
| 2016 | AMD: Audit-Based Misbehavior Detection in Wireless Ad Hoc NetworksabstractWe address the problem of identifying and isolating misbehaving nodes that refuse to forward packets in multi-hop ad hoc networks. We develop a comprehensive system calledAudit-based Misbehavior Detection(AMD) that effectively and efficiently isolates both continuous and selective packet droppers. The AMD system integrates reputation management, trustworthy route discovery, and identification of misbehaving nodes based on behavioral audits. Compared to previous methods, AMD evaluates node behavior on a per-packet basis, without employing energy-expensive overhearing techniques or intensive acknowledgment schemes. Moreover, AMD can detect selective dropping attacks even if end-to-end traffic is encrypted and can be applied to multi-channel networks or networks consisting of nodes with directional antennas. We show via simulations that AMD successfully avoids misbehaving nodes, even when a large portion of the network refuses to forward packets. Loukas Lazos, William Kozma |
IEEE Trans. Mob. Comput. | 2 |
| 2015 | Time-Delayed Broadcasting for Defeating Inside JammersabstractWe address the problem of jamming-resistant broadcast communications under an internal threat model. We propose a time-delayed broadcast scheme (TDBS), which implements the broadcast operation as a series of unicast transmissions distributed in frequency and time. TDBS does not rely on commonly shared secrets, or the existence of jamming-immune control channels for coordinating broadcasts. Instead, each node follows a unique pseudo-noise (PN) frequency hopping sequence. Contrary to conventional PN sequences designed for multi-access systems, the PN sequences in TDBS exhibit correlation to enable broadcast. Moreover, they are designed to limit the information leakage due to the exposure of a subset of sequences by compromised nodes. We map the problem of constructing such PN sequences to the 1-factorization problem for complete graphs. We further accommodate dynamic broadcast groups by mapping the problem of updating the assigned PN sequences to the problem of constructing rainbow paths in proper edge-colored graphs. Loukas Lazos, Marwan Krunz |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | Network anomaly detection using autonomous system flow aggregatesabstractDetecting malicious traffic streams in modern computer networks is a challenging task due to the growing traffic volume that must be analyzed. Traditional anomaly detection systems based on packet inspection face a scalability problem in terms of computational and storage capacity. One solution to this scalability problem is to analyze traffic based on IP flow aggregates. However, IP aggregates can still result in prohibitively large datasets for networks with heavy traffic loads. In this paper, we investigate whether anomaly detection is still possible when traffic is aggregated at a coarser scale. We propose a volumetric analysis methodology that aggregates traffic at the Autonomous System (AS) level. We show that our methodology reduces the number of flows to be analyzed by several orders of magnitude compared with IP flow level analysis, while still detecting traffic anomalies. Thienne M. Johnson, Loukas Lazos |
GLOBECOM | 2 |
| 2014 | Collusion-resistant query anonymization for location-based servicesabstractWe address the problem of anonymizing user queries when accessing location-based services. We design a novel location and query anonymization protocol called MAZE that preserves the user privacy without relying on trusted parties. MAZE guarantees the user's anonymity and privacy in a decentralized manner using P2P groups. Compared to prior works, MAZE enables individual user authentication for the purpose of implementing a pay-peruse or membership subscription model and is resistant to collusion of the P2P users. We extend MAZE to L-MAZE, a multi-stage protocol that is resistant to collusion of the P2P users with the LBS, at the expense of higher communication overhead. Loukas Lazos |
ICC | 2 |
| 2014 | Security vulnerability and countermeasures of frequency offset correction in 802.11a systemsabstractFrequency offset (FO) is an inherent feature of wireless communications. It results from differences in the operating frequency of different radio oscillators. Failure to compensate for the FO may lead to a decoding failure, particularly in OFDM systems. IEEE 802.11a/g systems use a globally known preamble to deal with this issue. In this paper, we demonstrate how an adversary can exploit the structure and publicity of 802.11a's frame preamble to launch a low-power reactive jamming attack against the FO estimation mechanism. In this attack, the adversary will need to quickly detect a PHY frame and subsequently distort the FO estimation mechanism, irrespective of the channel conditions. By employing a fast frame detection technique, and optimizing the energy and structure of the jamming signal, we show the feasibility of such an attack. Furthermore, we propose some mitigation techniques and evaluate one of them through simulations and USRP testbed experimentation. Hanif Rahbari, Marwan Krunz, Loukas Lazos |
INFOCOM | 3 |
| 2014 | FD-MMAC: Combating multi-channel hidden and exposed terminals using a single transceiverabstractWe address the problem of improving the throughput and delay efficiency of distributed multi-channel MAC (MMAC) protocols. We design an MMAC protocol called FD-MMAC that exploits recent advances in full-duplex (FD) communications to coordinate channel access in a distributed manner. Compared with prior MMAC designs, the FD-MMAC protocol eliminates the use of in-band or out-of-band control channels for combating the multi-channel hidden terminal problem, discovering the resident channel of destinations, and performing load balancing. Furthermore, FD-MMAC improves the spectral efficiency by enabling the operation of multi-channel exposed terminals. To achieve its goals, FD-MMAC integrates an advanced suite of PHY-layer techniques, including self interference suppression, error vector magnitude and received power measurements, and signal correlation techniques. We validate the proposed PHY-layer techniques on NI USRP devices. Further, we show via simulations that FD-MMAC achieves significantly higher throughput and lower delay compared with prior art. Yan Zhang 0019, Loukas Lazos, Kai Chen 0022, Bocan Hu, Swetha Shivaramaiah |
INFOCOM | 2 |
| 2014 | IMap: visualizing network activity over internet mapsabstractWe propose a novel visualization, IMap, which enables the detection of security threats by visualizing a large volume of dynamic network data. In IMap, the Internet topology at the Autonomous System (AS) level is represented by a canonical map (which resembles a geographic map of the world), and aggregated IP traffic activity is superimposed in the form of heat maps (intensity overlays). Specifically, IMap groups ASes as contiguous regions based on AS attributes (geo-location, type, rank, IP prefix space) and AS relationships. The area, boundary, and relative positions of these regions in the map do not reflect actual world geography, but are determined by the characteristics of the Internet's AS topology. To demonstrate the effectiveness of IMap, we showcase two case studies, a simulated DDoS attack and a real-world worm propagation attack. J. Joseph Fowler, Thienne M. Johnson, Paolo Simonetto, Carlos Acedo, Stephen G. Kobourov, Loukas Lazos |
VizSEC | 7 |
| 2013 | Countering selfish misbehavior in multi-channel MAC protocolsabstractWe address the problem of MAC-layer misbehavior in distributed multi-channel MAC protocols. We show that selfish users can manipulate the protocol parameters to gain an unfair share of the available bandwidth, while remaining undetected. We identify optimal misbehavior strategies that can lead to the isolation of a subset of frequency bands for exclusive use by the misbehaving nodes and evaluate their impact on performance and fairness. We develop corresponding detection and mitigation strategies that practically eliminate the misbehavior gains. To the best of our knowledge, this is the first attempt in characterizing the impact of misbehavior on multi-channel MAC protocols. Yan Zhang 0019, Loukas Lazos |
INFOCOM | 2 |
| 2013 | Perfect contextual information privacy in WSNs undercolluding eavesdroppersabstractWe address the problem of preserving contextual information privacy in wireless sensor networks (WSNs). We consider an adversarial network of colluding eavesdroppers that are placed at unknown locations. Eavesdroppers use communication attributes of interest such as packet sizes, inter-packet timings, and unencrypted headers to infer contextual information, including the time and location of events reported by sensors, the sink's position, and the event type. We propose a traffic normalization technique that employs a minimum backbone set of sensors to decorrelate the observable traffic patterns from the real ones. Compared to previous works, our method significantly reduces the communication overhead for normalizing traffic patterns. Alejandro Proaño, Loukas Lazos |
WISEC | 2 |
| 2013 | Welcome message from the D-SPAN 2013 chairsabstractAs the organizing committee, it is our pleasure to present the proceedings of the 4th IEEE International Workshop on Data Security and PrivAcy in wireless Networks (D-SPAN), held on June 4, 2013, in Madrid, Spain. The goal of this one-day workshop, organized in conjunction with the 14th IEEE WoWMoM 2013, is to exchange cutting-edge ideas for securing the next-generation wireless networks, systems, and applications. D-SPAN covers a wide range of security-related topics, including security and privacy of data collection, transmission, storage, publishing, and sharing in wireless networks broadly defined such as cellular and mobile ad hoc networks (MANET), vehicular ad hoc networks (VANET), cognitive and sensor networks to applying data analytics techniques to address security and privacy challenges in these networks. D-SPAN provides a forum for academic and industry researchers to present research ideas that build bridges across three communities: wireless networks, databases, and security. Guevara Noubir, Krishna Sampigethaya, Levente Buttyán, Loukas Lazos |
WOWMOM | 4 |
| 2012 | Hiding contextual information in WSNsabstractWe address the problem of preserving the confidentiality of contextual information in wireless sensor networks (WSNs). Such information includes the time and location of events observed by the WSN, the position of the sink, and possible routes to the sink. Contextual information can be extracted via traffic analysis, even when all traffic is encrypted. We consider a global threat model in which the adversary is assumed to be capable of eavesdropping on all communications. Compared to previous works, our method significantly reduces the communication overhead for hiding contextual information. In our approach, we first reduce the number of bogus traffic sources necessary for hiding traffic patterns by finding minimum connected dominating sets that cover the deployment area. We then randomize the traffic distributions observed by eavesdropping nodes. Alejandro Proaño, Loukas Lazos |
WOWMOM | 2 |
| 2012 | Graph-based criteria for spectrum-aware clustering in cognitive radio networks
Milan Bradonjic, Loukas Lazos |
Ad Hoc Networks | 2 |
| 2012 | Packet-Hiding Methods for Preventing Selective Jamming AttacksabstractThe open nature of the wireless medium leaves it vulnerable to intentional interference attacks, typically referred to as jamming. This intentional interference with wireless transmissions can be used as a launchpad for mounting Denial-of-Service attacks on wireless networks. Typically, jamming has been addressed under an external threat model. However, adversaries with internal knowledge of protocol specifications and network secrets can launch low-effort jamming attacks that are difficult to detect and counter. In this work, we address the problem of selective jamming attacks in wireless networks. In these attacks, the adversary is active only for a short period of time, selectively targeting messages of high importance. We illustrate the advantages of selective jamming in terms of network performance degradation and adversary effort by presenting two case studies; a selective attack on TCP and one on routing. We show that selective jamming attacks can be launched by performing real-time packet classification at the physical layer. To mitigate these attacks, we develop three schemes that prevent real-time packet classification by combining cryptographic primitives with physical-layer attributes. We analyze the security of our methods and evaluate their computational and communication overhead. Alejandro Proaño, Loukas Lazos |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | Thwarting Control-Channel Jamming Attacks from Inside JammersabstractCoordination of network functions in wireless networks requires frequent exchange of control messages among participating nodes. Typically, such messages are transmitted over a universally known communication channel referred to as the control channel. Due to its critical role, this channel can become a prime target of Denial-of-Service (DoS) attacks. In this paper, we address the problem of preventing control-channel DoS attacks manifested in the form of jamming. We consider a sophisticated adversary who has knowledge of the protocol specifics and of the cryptographic quantities used to secure network operations. This type of adversary cannot be prevented by antijamming techniques that rely on shared secrets, such as spread spectrum. We propose new security metrics to quantify the ability of the adversary to deny access to the control channel, and introduce a randomized distributed scheme that allows nodes to establish and maintain the control channel in the presence of the jammer. Our method is applicable to networks with static or dynamically allocated spectrum. Furthermore, we propose two algorithms for unique identification of the set of compromised nodes, one for independently acting nodes and one for colluding nodes. Detailed theoretical evaluation of the security metrics and extensive simulation results are provided to demonstrate the efficiency of our methods in mitigating jamming and identifying compromised nodes. Loukas Lazos, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2012 | Cluster-Based Control Channel Allocation in Opportunistic Cognitive Radio NetworksabstractCognitive radio networks (CRNs) involve extensive exchange of control messages, which are used to coordinate critical network functions such as distributed spectrum sensing, medium access, and routing, to name a few. Typically, control messages are broadcasted on a preassigned common control channel, which can be realized as a separate frequency band in multichannel systems, a given time slot in TDMA systems, or a frequency hopping sequence (or CDMA code) in spread spectrum systems. However, a static control channel allocation is contrary to the opportunistic access paradigm. In this paper, we address the problem of dynamically assigning the control channel in CRNs based on time- and space-varying spectrum opportunities. We propose a cluster-based architecture that allocates different channels for control at various clusters in the network. The clustering problem is formulated as a bipartite graph problem, for which we develop a class of algorithms that provide different tradeoffs between two conflicting factors: number of common channels in a cluster and the cluster size. Clusters are guaranteed to have a desirable number of common channels for control, which facilitates for graceful channel migration when primary radio (PR) activity is detected, without the need for frequent reclustering. We perform extensive simulations that verify the agility of our algorithms in adapting to spatial-temporal variations in spectrum availability. Loukas Lazos, Marwan Krunz |
IEEE Trans. Mob. Comput. | 2 |
| 2011 | Thwarting inside jamming attacks on wireless broadcast communicationsabstractWe address the problem of jamming-resistant broadcast com-munications under an internal threat model. We propose a time-delayed broadcast scheme (TDBS), which implements the broadcast operation as a series of unicast transmissions, distributed in frequency and time. TDBS does not rely on commonly shared secrets, or the existence of jamming-immune control channels for coordinating broadcasts. In-stead, each node follows a unique pseudo-noise (PN) fre-quency hopping sequence. Contrary to conventional PN se-quences designed for multi-access systems, our sequences ex-hibit high correlation to enable broadcast. Moreover, their design limits the information leakage due to the exposure of a subset of sequences by compromised nodes. We map the problem of constructing such PN sequences to the 1-factorization problem for complete graphs. Our evaluation results show that TDBS can maintain broadcast communi-cations in the presence of inside jammers. Loukas Lazos, Marwan Krunz |
WISEC | 2 |
| 2011 | Securing low-cost RFID systems: An unconditionally secure approachabstractIn this paper, we explore a new direction towards solving the identity authentication problem in RFID systems. We break the RFID authentication process into two main problems: message authentication and random number generation. For parties equipped with a good source of randomness and a secure cry ptographic primitive to authenticate messages, the literature of cryptography is rich with well-studied solutions for secure identity authentication. However, the two operations, random number generation and message authentication, can be expensive for low-cost RFID tags. In this paper, we lay down the foundations of a new direction towards solving these problems in RFID systems. We propose an unconditionally secure direction for authenticating RFID systems. We use the fact that RFID readers are computationally powerful devices to design a protocol that allows RFID readers to deliver random numbers to RFID tags in an unconditionally secure manner. Then, by taking advantage of the information-theoretic security of the transmitted messages, we develop a novel unconditionally secure message authentication code that is computed with a single multiplication operation. The goal of this work is to bring more research to the design of such unconditionally secure protocols, as opposed to the computationally secure protocols that have been proposed extensively, for the purpose of suiting the stringent computational capabilities of low-cost devices. Basel Alomair, Loukas Lazos, Radha Poovendran |
J. Comput. Secur. | 2 |
| 2010 | Selective Jamming Attacks in Wireless NetworksabstractWe address the problem of selective jamming attacks in wireless networks. In these attacks, the adversary selectively targets specific packets of "high" importance by exploiting his knowledge on the implementation details of network protocols at various layers of the protocol stack. We illustrate the impact of selective jamming on the network performance by illustrating various selective attacks against the TCP protocol. We show that such attacks can be launched by performing real-time packet classification at the physical layer. We examine the combination of cryptographic primitives with physical layer attributes for preventing real- time packet classification and neutralizing the inside knowledge of the attacker. Alejandro Proaño, Loukas Lazos |
ICC | 2 |
| 2009 | Spectrum Opportunity-Based Control Channel Assignment in Cognitive Radio NetworksabstractWe address the problem of dynamic assignment of coordination (control) channels in cognitive radio networks (CRNs) by exploiting time- and space-varying spectrum opportunities. Motivated by the inherent grouping of Cognitive Radio (CR) users according to channel availability, we propose a cluster-based architecture for control-channel assignment in a CRN. CRs are grouped in the same cluster if they roughly sense similar idle channels and are within communication range, either directly or via a cluster-head. We formulate the clustering design as a maximum edge biclique problem. A distributed cluster agreement algorithm called Spectrum-Opportunity Clustering (SOC) is proposed to solve this problem. SOC provides a desirable balance between two competing factors: the set of common idle channels within each cluster and the cluster size. A large set of common idle channels within each cluster allows graceful migration from the current control channel should primary radio (PR) activity appear on that channel. Hence, SOC provides a stable network partition with respect to local coordination, with no need for frequent re-clustering. Moreover, when re-clustering has to be performed (due to CR mobility or PR activity), CRs agree on new clusters after the broadcast of only three messages, thus incurring low communication overhead. Loukas Lazos, Marwan Krunz |
SECON | 1 |
| 2009 | Dealing with Liars: Misbehavior Identification via Rényi-Ulam Games
William Kozma, Loukas Lazos |
SecureComm | 2 |
| 2009 | REAct: resource-efficient accountability for nodemisbehavior in ad hoc networks based on random auditsabstractWireless ad hoc networks rely on multi-hop routes to transport data from source to destination. The routing function is implemented in a collaborative manner, with each node responsible for relaying traffic to the destination. However, an increasingly sophisticated pool of users with easy access to commercial wireless devices, combined with the poor physical and software security of the devices, can lead to node misconfiguration or misbehavior. A misbehaving node may refuse to forward packets in order to conserve its energy (selfishness), or simply degrade network performance (maliciousness). William Kozma, Loukas Lazos |
WISEC | 2 |
| 2009 | Mitigating control-channel jamming attacks in multi-channel ad hoc networksabstractWe address the problem of control-channel jamming attacks in multi-channel ad hoc networks. Deviating from the traditional view that sees jamming attacks as a physical-layer vulnerability, we consider a sophisticated adversary who exploits knowledge of the protocol mechanics along with cryptographic quantities extracted from compromised nodes to maximize the impact of his attack on higher-layer functions. We propose new security metrics that quantify the ability of the adversary to deny access to the control channel, and the overall delay incurred in re-establishing the control channel. We also propose a randomized distributed scheme that allows nodes to establish a new control channel using frequency hopping. Our method differs from classic frequency hopping in that no two nodes share the same hopping sequence, thus mitigating the impact of node compromise. Furthermore, a compromised node is uniquely identified through its hop sequence, leading to its isolation from any future information regarding the frequency location of the control channel. Loukas Lazos, Marwan Krunz |
WISEC | 1 |
| 2009 | Analytic evaluation of target detection in heterogeneous wireless sensor networksabstractIn this article, we address the problem of target detection in Wireless Sensor Networks (WSNs). We formulate the target detection problem as a line-set intersection problem and use integral geometry to analytically characterize the probability of target detection for both stochastic and deterministic deployments. Compared to previous work, we analyze WSNs where sensors have heterogeneous sensing capabilities. For the stochastic case, we evaluate the probability that the target is detected by at least k sensors and compute the free path until the target is first detected. For the deterministic case, we show an analogy between the target detection problem and the problem of minimizing the average symbol error probability in 2D digital modulation schemes. Motivated by this analogy, we propose a heuristic sensor placement algorithm, called DATE, that makes use of well-known signal constellations for determining good WSN constellations. We also propose a heuristic called CDATE for connected WSN constellations, that yields high target detection probability. Loukas Lazos, Radha Poovendran, James A. Ritcey |
ACM Trans. Sens. Networks | 1 |
| 2009 | Detection of mobile targets on the plane and in space using heterogeneous sensor networks
Loukas Lazos, Radha Poovendran, James A. Ritcey |
Wirel. Networks | 1 |
| 2008 | Reactive Identification of Misbehavior in Ad Hoc Networks Based on Random AuditsabstractWe address the problem of identifying misbehaving nodes that (selectively) drop packets, in order to degrade the network performance. Such nodes may agree to forward packets by participating in the route discovery process, but refuse to do so once the packets have been received. We propose a reactive approach where the source initiates an audit process if a significant performance degradation is observed. We employ a compact representation of the behavioral proof of a node by adopting Bloom filter structures and show that the misbehaving node can be identified based on random audits. Our approach provides significant energy savings compared to previously proposed methods that rely on reputation systems, or intensive acknowledgment schemes. William Kozma, Loukas Lazos |
SECON | 2 |
| 2007 | Probabilistic detection of mobile targets in heterogeneous sensor networksabstractTarget detection and field surveillance are among the most prominent applications of Sensor Networks (SN). The quality of detection achieved by a SN can be quantified by evaluating the probability of detecting a mobile target crossing a Field of Interest (FoI). In this paper, we analytically evaluate the detection probability of mobile targets when N sensors are stochastically deployed to monitor a Fol. We map the target detection problem to a line-set intersection problem and derive analytical formulas using tools from Integral Geometry and Geometric Probability. We show that the detection probability depends on the length of the perimeters of the sensing areas of the sensors and not their shape. Hence, compared to prior work, our formulation allows us to consider a heterogeneous sensing model, where each sensor can have an arbitrary sensing area. We also evaluate the mean free path until a target is first detected. Loukas Lazos, Radha Poovendran, James A. Ritcey |
IPSN | 1 |
| 2007 | Energy and bandwidth-efficient key distribution in wireless ad hoc networks: a cross-layer approach
Javier Salido, Loukas Lazos, Radha Poovendran |
IEEE/ACM Trans. Netw. | 2 |
| 2007 | Power proximity based key management for secure multicast in ad hoc networks
Loukas Lazos, Radha Poovendran |
Wirel. Networks | 1 |
| 2007 | A graph theoretic framework for preventing the wormhole attack in wireless ad hoc networks
Radha Poovendran, Loukas Lazos |
Wirel. Networks | 2 |
| 2006 | Coverage in heterogeneous sensor networksabstractIn this paper we study the problem of coverage in heterogeneous planar sensor networks. Coverage as a performance metric, quantifies the quality of monitoring provided by the sensor network. We formulate the problem of coverage as a set intersection problem arising in Integral Geometry, and derive analytical expressions for stochastic coverage. Our formulation allows us to consider a heterogeneous sensing model, where sensors need not have an identical sensing capability. In addition, our approach is applicable to scenarios where the sensing area of each sensor has arbitrary shape and sensors are deployed according to any distribution. We present analytical expressions only for convex sensing areas, however, our results can be generalized to non-convex areas. The validity of our expressions is verified by extensive simulations. Loukas Lazos, Radha Poovendran |
WiOpt | 1 |
| 2006 | HiRLoc: high-resolution robust localization for wireless sensor networksabstractIn this paper, we address the problem of robustly estimating the position of randomly deployed nodes of a wireless sensor network (WSN), in the presence of security threats. We propose a range-independent localization algorithm called high-resolution range-independent localization (HiRLoc), that allows sensors to passively determine their location with high resolution, without increasing the number of reference points, or the complexity of the hardware of each reference point. In HiRLoc, sensors determine their location based on the intersection of the areas covered by the beacons transmitted by multiple reference points. By combining the communication range constraints imposed by the physical medium with computationally efficient cryptographic primitives that secure the beacon transmissions, we show that HiRLoc is robust against known attacks on WSN, such as the wormhole attack, the Sybil attack, and compromise of network entities. Finally, our performance evaluation shows that HiRLoc leads to a significant improvement in localization accuracy compared with state-of-the-art range-independent localization schemes, while requiring fewer reference points. Loukas Lazos, Radha Poovendran |
IEEE J. Sel. Areas Commun. | 1 |
| 2006 | Stochastic coverage in heterogeneous sensor networksabstractWe study the problem of coverage in planar heterogeneous sensor networks. Coverage is a performance metric that quantifies how well a field of interest is monitored by the sensor deployment. To derive analytical expressions of coverage for heterogeneous sensor networks, we formulate the coverage problem as a set intersection problem, a problem studied in integral geometry. Compared to previous analytical results, our formulation allows us to consider a network model where sensors are deployed according to an arbitrary stochastic distribution; sensing areas of sensors need not follow the unit disk model but can have any arbitrary shape; sensors need not have an identical sensing capability. Furthermore, our formulation does not assume deployment of sensors over an infinite plane and, hence, our derivations do not suffer from the border effect problem arising in a bounded field of interest. We compare our theoretical results with the spatial Poisson approximation that is widely used in modeling coverage. By computing the Kullback-Leibler and total variation distance between the probability density functions derived via our theoretical results, the Poisson approximation, and the simulation, we show that our formulas provide a more accurate representation of the coverage in sensor networks. Finally, we provide examples of calculating network parameters such as the network size and sensing range in order to achieve a desired degree of coverage. Loukas Lazos, Radha Poovendran |
ACM Trans. Sens. Networks | 1 |
| 2005 | Rope: robust position estimation in wireless sensor networksabstractWe address the problem of secure location determination, known as secure localization, and the problem of verifying the location claim of a node, known as location verification, in wireless sensor networks (WSN). We propose a robust positioning system we call ROPE that allows sensors to determine their location without any centralized computation. In addition, ROPE provides a location verification mechanism that verifies the location claims of the sensors before data collection. We show that ROPE bounds the ability of an attacker to spoof sensors' locations, with relatively low density deployment of reference points. We confirm the robustness of ROPE against attacks analytically and via simulations. Loukas Lazos, Radha Poovendran, Srdjan Capkun |
IPSN | 1 |
| 2005 | Preventing wormhole attacks on wireless ad hoc networks: a graph theoretic approachabstractWe study the problem of characterizing the wormhole attack, an attack that can be mounted on a wide range of wireless network protocols without compromising any cryptographic quantity or network node. A wormhole, in essence, creates a communication link between an origin and a destination point that could not exist with the use of the regular communication channel. Hence, a wormhole modifies the connectivity matrix of the network, and can be described by a graph abstraction of the ad hoc network. Making use of geometric random graphs induced by the communication range constraint of the nodes, we present the necessary and sufficient conditions for detecting and defending against wormholes. Using our theory, we also present a defense mechanism based on local broadcast keys. We believe our work is the first one to present analytical calculation of the probabilities of detection. We also present simulation results to illustrate our theory. Loukas Lazos, Radha Poovendran, Catherine Meadows 0001, Paul F. Syverson, LiWu Chang |
WCNC | 1 |
| 2005 | SeRLoc: Robust localization for wireless sensor networksabstractMany distributed monitoring applications of Wireless Sensor Networks (WSNs) require the location information of a sensor node. In this article, we address the problem of enabling nodes of Wireless Sensor Networks to determine their location in an untrusted environment, known as the secure localization problem. We propose a novel range-independent localization algorithm called SeRLoc that is well suited to a resource constrained environment such as a WSN. SeRLoc is a distributed algorithm based on a two-tier network architecture that allows sensors to passively determine their location without interacting with other sensors. We show that SeRLoc is robust against known attacks on a WSNs such as the wormhole attack , the Sybil attack , and compromise of network entities and analytically compute the probability of success for each attack. We also compare the performance of SeRLoc with state-of-the-art range-independent localization schemes and show that SeRLoc has better performance. Loukas Lazos, Radha Poovendran |
ACM Trans. Sens. Networks | 1 |
| 2004 | Cross-layer design for energy-efficient secure multicast communications in ad hoc networksabstractThis paper considers the problem of secure multicast in an energy-constrained wireless environment. We present an analytical formulation of the energy expenditure associated with the communication overhead of key management and highlight its dependence on the network topology and the key distribution method. We show that the optimal solution of this formulation does not scale with multicast group size and propose a suboptimal, cross-layer, low-complexity algorithm for energy efficient key distribution. We present simulation studies that show the energy savings achieved by our scheme and compare its performance when different routing algorithms are employed. Loukas Lazos, Radha Poovendran |
ICC | 1 |
| 2003 | Energy-aware secure multicast communication in ad-hoc networks using geographic location informationabstractThe problem of securing multicast communications in an energy-constrained ad-hoc network requires the efficient management of cryptographic quantities. We show that existing efficient key distribution techniques for wired networks that rely on logical hierarchies are extremely energy inefficient. We also show that the consideration of the physical location of the members is critical for developing energy-efficient key distribution schemes. By exploiting the spatial correlation between the members of the multicast group, we construct an energy-aware key distribution scheme. We present simulation results to illustrate the improvements achieved by our proposed algorithm. Loukas Lazos, Radha Poovendran |
ICASSP (4) | 1 |