Savio Sciancalepore

dblp:160/0146 · DBLP profile ↗
← Back
60ranked-venue papers
16as first author
47since 2021 · last 2026
0000-0003-0974-3639ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 5 first-author · 24 since 2021Computer networks · 20 · 9 first-author · 13 since 2021Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2026 HidePrint: Protecting Device Anonymity by Obscuring Radio Fingerprints
abstract
Radio Frequency Fingerprinting (RFF) techniques allow a receiver to authenticate a transmitter by analyzing the physical layer of the radio spectrum. Although the vast majority of scientific contributions focus on improving the performance of RFF considering different parameters and scenarios, in this work, we consider RFF as an attack vector to identify a target device in the radio spectrum. We propose, implement, and evaluate HidePrint, a solution to prevent identification through RFF without affecting the quality of the communication link between the transmitter and the receiver. HidePrint hides the transmitter's fingerprint against an illegitimate eavesdropper through the injection of controlled noise into the transmitted signal. We evaluate our solution against various state-of-the-art RFF techniques, considering several adversarial models, data from real-world communication links (wired and wireless), and protocol configurations. Our results show that the injection of a Gaussian noise pattern with a normalized standard deviation of (at least) 0.02 prevents device fingerprinting in all the considered scenarios, while affecting the Signal-to-Noise Ratio (SNR) of the received signal by only 0.1 dB. Moreover, we introduce selective radio fingerprint disclosure, a new technique that allows the transmitter to disclose the radio fingerprint to only a subset of intended receivers.
Gabriele Oligeri, Savio Sciancalepore
AsiaCCS2
2026 From DePIN Hype to Operational Reality: Assessing Centralization and Usage of Commercial dVPNs
abstract
Decentralized VPNs (dVPNs) are marketed as a flagship use case of Decentralized Physical Infrastructure Networks (DePIN): a fully decentralized, censorship-resistant alternative to traditional VPNs, where users route traffic through a global pool of independently operated exit nodes. However, despite claims of decentralization and “military-grade privacy”, little is known in both the white and the gray literature about the actual commercial dVPNs architecture, their true level of decentralization, and what they are used for. To fill these gaps, in this work, we present the first data-driven, operator-centric study of commercial dVPNs. We deploy several fully functional exit nodes worldwide on two prominent dVPN platforms, Mysterium and Sentinel. Via such nodes, we collect control-plane traffic, user traffic, and publicly available metadata to assess what an honest-but-curious operator can infer about systems' architecture, effective decentralization, and real-world usage. Our findings challenge the dominant narrative. Architecturally, both investigated dVPNs rely heavily on centralized orchestrators, often hosted on a handful of Cloud providers. These components constitute clear chokepoints, making the networks more fragile, censorable, and way less decentralized than their branding suggests. From a usage perspective, traffic relayed by our nodes is dominated by mainstream, commercially oriented activities rather than by censorship evasion or privacy-motivated uses. Overall, we show that current commercial dVPNs inherit many centralized features of traditional VPNs while shifting trust and liability onto a heterogeneous, legally shaky, and largely untrusted operator base.
Bartan Oren, Maurantonio Caprolu, Savio Sciancalepore, Nicola Zannone, Roberto Di Pietro
AsiaCCS3
2026 Radio Jamming Against Device Fingerprinting in Power Line Communications
abstract
Power Line Communication (PLC) systems are facing increasing security threats as adversaries leverage low-cost Software-Defined Radios (SDRs) to launch physical-layer attacks, e.g., jamming and Radio Frequency Fingerprinting (RFF), for communication disruption and unauthorized device tracking, respectively. This paper investigates the dual role of Radio Frequency (RF) wireless jamming for PLC environments, through two distinct scenarios: (i) friendly RF jamming for privacy preservation of (cabled) PLC devices against unauthorized RFF, and (ii) adversarial RF jamming to degrade the performance of legitimate RFF-based authentication systems. We conducted various systematic experiments using nine USRP X310 SDRs connected to actual PLC couplers exchanging signals modulated according to the Binary-Phase Shift Keying modulation scheme to analyze the behavior of RFF in PLC scenarios under different RF jamming levels. Our results demonstrate, for the first time, that strategic RF jamming effectively obscures device fingerprints in cabled PLC communications while maintaining communication quality, with bit error rates remaining acceptable across most configurations. We also demonstrate that device identification accuracy degrades significantly as the jamming intensity increases. Our findings establish fundamental trade-offs between privacy protection and authentication reliability, providing insights for the design of robust PLC systems.
Maryam Al-Malki, Gabriele Oligeri, Savio Sciancalepore, Bechir Hamdaoui, Javier Hernandez Fernandez
CCNC4
2026 MeshGuard: MUD-Based Network Access Control for Large-Scale Thread-Powered IoT Networks
abstract
The IETF standard Manufacturer Usage Description (MUD) enables manufacturers to equip IoT devices with certified URLs that provide traffic profiles for those devices, helping administrators enforce network access control. However, MUD assumes devices operate on full IP stacks and therefore does not account for constrained IoT devices running Thread–the dominant low-power mesh networking standard–which lacks complete TCP/IP functionality. While prior work proposes extensions to support MUD in Thread environments, these approaches are limited to simple topologies with a single border router and do not scale to realistic deployments with multiple, heterogeneous border routers. We introduce MeshGuard, a framework enabling MUD-based access control in complex Thread networks, with any number of border routers. MeshGuard extends the Mesh Link Establishment (MLE) protocol to deliver MUD information from constrained devices to border routers regardless of network topology. Moreover, MeshGuard leverages Software-Defined Networking (SDN) to synchronize access control lists across all routers. Experiments on our proof-of-concept with real devices (nRF5340, nRF52833, Raspberry-Pi 3) demonstrate enhanced security, minimal overhead, and linear scalability compared to state-of-the-art approaches.
Dominik Roy George, Wouter van Hoof, Habib Mostafaei, Savio Sciancalepore
DSN4
2026 Explainable Efficiency: Grad-CAM Analysis of Image-Based Radio Frequency Fingerprinting
abstract
Radio Frequency Fingerprinting (RFF) is a physical (PHY) layer security technique enabling the identification of a radio transmitter without resorting to shared secrets while combining deep learning and signal processing techniques. State-of-the-art scientific contributions focus on improving identification performance in different scenarios and configurations while considering the RFF methodology as a black-box. In this work, we apply eXplainable Artificial Intelligence (XAI) techniques to expose the discriminative features allowing a neural network model to identify radio transmitters at the PHY layer. Our analysis considers image-based RFF classifiers, where received signals (in the form of IQ symbols) are processed into images, and proves that symbols contribute unequally to the identification of the transmitter. In particular, our results demonstrate that image pre-processing can be leveraged to significantly reduce the overhead of training (up to 50%) and testing (up to 70%) without affecting the classifier's final accuracy.
Ingrid Huso, Savio Sciancalepore, Gabriele Oligeri, Giuseppe Piro, Gennaro Boggia
INFOCOM2
2026 Beyond Static Signatures: Statistical Analysis of Radio Fingerprint Mutations
abstract
Radio Frequency Fingerprinting (RFF) has emerged as a promising physical-layer technique for device identification, leveraging the hardware imperfections in radio transmitters. However, the assumption that RF fingerprints are static and persistent is increasingly challenged by recent findings. In this work, we present a comprehensive statistical analysis of radio fingerprint mutations, focusing on the impact of FPGA image reloads in Software Defined Radios (SDRs) when used as both transmitters and receivers. Our results highlight that FPGA reloads cause a subset of devices to exhibit two different persistent fingerprint states, one following a memoryless (Markovian) process and the other retaining temporal dependencies. Notably, we show that proper external synchronization between transmitter and receiver eliminates these fingerprint mutations, leading us to attribute the phenomenon to residual phase and timing errors rather than inherent hardware changes. Our work exposes the necessity of accounting for fingerprint dynamics caused by internal SDR events and synchronization, highlighting the limits of current measurement methodologies and the need for new, statistically robust approaches to physical-layer device identification.
Gabriele Oligeri, Savio Sciancalepore
WISEC2
2026 Weak-jamming detection in IEEE 802.11 networks: Techniques, scenarios and mobility
abstract
State-of-the-art solutions detect jamming attacks ex-post , i.e., only when jamming has already disrupted the wireless communication link. In many scenarios, e.g., mobile networks or static deployments distributed over a large geographical area, it is often desired to detect jamming at the early stage, when it affects the communication link enough to be detected but not sufficiently to disrupt it (detection of weak jamming signals). Under such assumptions, devices can enhance situational awareness and promptly apply mitigation, e.g., moving away from the jammed area in mobile scenarios or changing communication frequency in static deployments, before jamming fully disrupts the communication link. Although some contributions recently demonstrated the feasibility of detecting low-power and weak jamming signals, they make simplistic assumptions far from real-world deployments. Given the current state of the art, no evidence exists that detection of weak jamming can be considered with real-world communication technologies. In this paper, we provide and comprehensively analyze new general-purpose strategies for detecting weak jamming signals, compatible by design with one of the most relevant communication technologies used by commercial-off-the-shelf devices, i.e., IEEE 802.11. We describe two operational modes: (i) binary classification via Convolutional Neural Networks and (ii) one-class classification via Sparse Autoencoders. We evaluate and compare the proposed approaches with the current state-of-the-art using data collected through an extensive real-world experimental campaign in three relevant environments. At the same time, we made the dataset available to the public. Our results demonstrate that detecting weak jamming signals is feasible in all considered real-world environments, and we provide an in-depth analysis that considers different techniques, scenarios, and mobility patterns.
Martijn Hanegraaf, Savio Sciancalepore, Gabriele Oligeri
Comput. Networks2
2026 Obfuscated Location Disclosure for Remote ID Enabled Drones
abstract
The Remote ID (RID) regulation recently introduced by several aviation authorities worldwide (including the US and EU) forces commercial drones to regularly (max. every second) broadcast plain-text messages on the wireless channel, providing information about the drone identifier and current location, among others. Although these regulations increase the accountability of drone operations and improve traffic management, they allow malicious users to track drones via the disclosed information, possibly leading to drone capture and severe privacy leaks. In this paper, we propose Obfuscated Location disclOsure for RID-enabled drones (OLO-RID), a solution modifying and extending the RID regulation while preserving drones' location privacy. Rather than disclosing the actual drone's location, drones equipped with OLO-RID disclose a differentially private obfuscated location. OLO-RID also extends RID messages with encrypted location information, accessible only by authorized entities and valuable to obtain the current drone's location in safety-critical use cases. We design, implement, and deploy OLO-RID on a Raspberry Pi 3 and release the code of our implementation as open-source. We also perform an extensive performance assessment of the runtime overhead of our solution in terms of processing, communication, memory, and energy consumption. We show that OLO-RID can generate RID messages on a constrained device in less than 0.16 s while also requiring a minimal energy toll on a relevant device ($0.0236\%$of energy for a DJI Mini 2). We also evaluate the utility of the proposed approach in the context of three reference use cases involving the drones' location usage, demonstrating minimal performance degradation when trading off location privacy and utility for next-generation RID-compliant drone ecosystems.
Alessandro Brighente, Mauro Conti, Matthijs Schotsman, Savio Sciancalepore
IEEE Trans. Dependable Secur. Comput.4
2025 Preventing Radio Fingerprinting through Low-Power Jamming
abstract
Radio Frequency fingerprinting enables a passive receiver to recognize and authenticate a transmitter without the need for cryptographic tools. Authentication is achieved by isolating specific features of the transmitted signal that are unique to the transmitter's hardware. Much research has focused on improving the effectiveness and efficiency of radio frequency fingerprinting to maximize its performance in various scenarios and conditions, while little research examined how to protect devices from being subject to radio fingerprinting in the wild. In this paper, we explore a novel point of view. We examine the threat posed by radio frequency fingerprinting, which facilitates the unauthorized identification of wireless devices in the field by malicious entities. We also suggest a method to sanitize the transmitted signal of its fingerprint using a low-power jammer, deployed on purpose to improve devices' anonymity on the channel while still guaranteeing the link's quality of service. Our experimental results and subsequent analysis demonstrate that a low-power jammer can effectively block a malicious eavesdropper from identifying a device without affecting the quality of the wireless link, thereby restoring the privacy of the user when accessing the radio spectrum.
Savio Sciancalepore, Gabriele Oligeri
AsiaCCS2
2025 Radio Frequency Fingerprinting: Models, Methodologies and Performance
abstract
Radio Frequency fingerprinting (RFF) is emerging as a viable alternative to authenticating radio devices, serving as a mitigation technique for spoofing and impersonation attacks on the wireless channel. RFF relies on the observation that each radio transducer features a distinctive radio fingerprint that is impractical—or even impossible—to forge by any other device.In this work, we provide an in-depth analysis of current state-of-the-art RFF approaches by comparing deep learning techniques and the associated methodologies. We consider real measurements in a controlled scenario and compare different configurations and classifiers in terms of performance and training time. Our findings show that the performance of the 11 considered classifiers is significantly biased by the methodology considered during the selection of the data for the training and testing datasets. Training and testing on different measurements or when radios are power-cycled significantly affects the accuracy of the classifier. Overall, our investigation sheds light on best practices and configurations to be considered to maximize the performance of RFF systems deployed in the wild.
Maryam Al-Malki, Savio Sciancalepore, Gabriele Oligeri
IWCMC3
2025 Device Fingerprinting in Power Line Communications
abstract
Power Line Communication (PLC) use existing electrical infrastructure for data transmission but are susceptible to security threats such as spoofing and impersonation attacks due to their open nature. This paper proposes a novel Device Fingerprinting (DF) approach for device authentication in PLC systems. The approach leverages hardware-induced imperfections in signals transmitted over power lines to identify devices based on their physical-layer characteristics. We develop a methodology that converts raw In-Phase Quadrature (IQ) samples from PLC channels into images, enabling the use of Convolutional Neural Networks for device classification. Our approach demonstrates the feasibility of CNN-based DF in PLC environments using only physical-layer information from received signals. Our experimental validation uses 8 Software Defined Radios and 2 power line couplers in real-world PLC measurements. We evaluate multiple Convolutional Neural Network (CNN) architectures and demonstrate that the PLC device fingerprint consists of two components: radio-specific and coupler-specific characteristics. The results show classification accuracy exceeding 0.9 across different configurations, establishing the viability of DF-based authentication in PLC systems without requiring additional security layers.
Javier Hernandez Fernandez, Aymen Omri, Savio Sciancalepore, Gabriele Oligeri
Ad Hoc Networks4
2025 Cyberattacks and defenses for Autonomous Navigation Systems: A systematic literature review
abstract
Autonomous Navigation Systems (ANSs) are revolutionizing transportation and logistics by enhancing operational efficiency and reshaping industry standards. However, the absence of human intervention during operational failures makes ANSs more vulnerable to cyberattacks and their consequences. Although prior research has addressed the security challenges of ANSs and proposed various defenses to prevent and mitigate cyberattacks against ANSs, we still lack a comprehensive understanding of the ANS attack surface and the effectiveness of both attacks and defenses. To address this gap, we conduct a systematic review of 125 articles on cybersecurity for ANSs, focusing on their domain, characteristics, and the attack and defense strategies studied in the literature. Our analysis reveals notable research trends, open gaps, and areas for future investigation. Security research on navigation functions remains limited, despite their central role and the risks associated with their compromise. Moreover, our analysis reveals a lack of cross-domain research, resulting in threats and defenses analyzed for one domain being overlooked in others. Finally, we identify discrepancies between attacks and defenses studied in the literature, with a disproportionate focus on defense strategies.
Jorrit Olthuis, Savio Sciancalepore, Nicola Zannone
Comput. Networks2
2025 Detection of Aerial Spoofing Attacks to LEO Satellite Systems via Deep Learning
abstract
Detecting spoofing attacks to Low-Earth-Orbit (LEO) satellite systems is a cornerstone to assessing the authenticity of the received information and guaranteeing robust service delivery in several application domains. The solutions available today for spoofing detection either rely on additional communication systems, receivers, and antennas, or require mobile deployments. Detection systems working at the Physical (PHY) layer of the satellite communication link also require time-consuming and energy-hungry training processes on all satellites of the constellation, and rely on the availability of spoofed data, which are often challenging to collect. Moreover, none of such contributions investigate the feasibility of aerial spoofing attacks launched via drones operating at various altitudes. In this paper, we first show experimentally the viability and effectiveness of spoofing attacks to LEO satellite systems using aerial attackers deployed on drones. We also propose a new spoofing detection technique, relying on pre-processing raw physical-layer signals into images and then applying anomaly detection on such images via autoencoders. We validate our solution through an extensive measurement campaign involving the deployment of an actual spoofer (Software-Defined Radio) installed on a drone and injecting rogue IRIDIUM messages while flying at different altitudes with various movement patterns. Our results demonstrate that the proposed technique can reliably detect LEO spoofing attacks launched at different altitudes, while state-of-the-art competing approaches simply fail. We also release the collected data as open source, fostering further research on satellite security.
Jos Wigchert, Savio Sciancalepore, Gabriele Oligeri
Comput. Networks2
2025 ePPTM - Enhanced Privacy-Preserving Trajectory Matching on Autonomous Vehicles
abstract
Detecting in advance spatiotemporal collisions among autonomous vehicles (AVs) is crucial for enhancing safety and reducing risks. However, comparing plain-text trajectories leaks private path information, e.g., the location of storage sites, and may reveal private users’ data. Although the literature already provides a few solutions for privacy-preserving trajectory comparison, they cannot handle sparse trajectory data, leading to increased safety risks. In this article, we propose ePPTM, an enhanced fully accurate protocol for privacy-preserving trajectory matching among AVs. ePPTM combines two main building blocks, i.e., the Incremental Capsule Matching algorithm, detecting co-location using capsules defined over trajectories at an increasing level of granularity, and privacy-preserving proximity testing, allowing comparison among trajectory identifiers by revealing only colliding elements. We describe two modes of ePPTM, i.e., the Truncated Mode and Full Mode, with the former potentially decreasing processing demands while fully preserving privacy and safety (no missed collisions). We implement a proof of concept of ePPTM, release the code open source, and test it on two testbeds involving heterogeneous devices and real sparse trajectory data. We demonstrate experimentally the perfect accuracy of ePPTM, i.e., 100% accuracy in identifying collisions, while earlier approaches simply fail. We also explore the overhead of ePPTM, showing that it is lightweight when trajectories do not collide or have only a few points in common. The overhead increases when trajectories are more similar, but can be always kept under control at the expense of a little privacy leakage.
Dominik Roy George, Savio Sciancalepore
IEEE Internet Things J.2
2024 GhostBuster: Detecting Misbehaving Remote ID-Enabled Drones
abstract
Remote ID (RID) regulations soon applicable world-wide force drones to broadcast plaintext wireless messages providing, among others, their current location. However, malicious drone operators who want to stay stealthy might disclose RID messages carrying out location spoofing attacks, i.e., report forged locations, different from the actual ones. In this paper, we investigate the feasibility of using wireless localization approaches to detect drones carrying out location spoofing attacks. To this aim, we propose GhostBuster, a modular solution for detecting misbehaving RID-enabled drones, and we evaluate its performance via an extensive experimental campaign based on open-source data from actual drone flights. Through the analysis of real data in an area of$1. 5km\times 2.5km$, we show that systems integrating multiple receivers can take advantage of multiple RID messages to verify the location reported by RID-enabled drones with a success rate of 95% up to 364 meters with 12 receivers. We also show that channel conditions play a crucial role in defining the maximum achievable spoofing detection performance.
Mart Keizer, Savio Sciancalepore, Gabriele Oligeri
CCNC2
2024 FadePrint - Satellite Spoofing Detection via Fading Fingerprinting
abstract
While various methods exist to implement message authentication in different communication layers, the physical layer offers some unique and beneficial features for this purpose. Existing solutions authenticate transmitters at the physical layer by merging deep learning with physical-layer attributes, protecting against impersonation attacks. This approach requires a lengthy and resource-intensive training phase for every new transmitter that joins the network. However, for some scenarios (e.g. satellite communications), characterizing the channel experienced by the received signal might be effective in detecting impersonation. In this work, we propose FadePrint, a solution capable of detecting satellite spoofing attacks by fingerprinting the noise-fading process associated with the satellite communication channel. The fading characteristics of a satellite link differ significantly from terrestrial links (e.g., indoor), making it possible to distinguish between the two. Unlike other systems, FadePrint does not require retraining when new transducers are added to the network. We tested FadePrint with real satellite and indoor radio measurements and proved that FadePrint can effectively discriminate between a satellite transmitter and a fake indoor one, with an accuracy higher than 0.99 for all the considered configurations.
Gabriele Oligeri, Savio Sciancalepore, Alireza Sadighian
CCNC2
2024 Radio Frequency Fingerprinting via Deep Learning: Challenges and Opportunities
abstract
Radio Frequency Fingerprinting (RFF) techniques promise to authenticate wireless devices at the physical layer based on inherent hardware imperfections introduced during manufacturing. Such RF transmitter imperfections are reflected into over-the-air signals, allowing receivers to accurately identify the RF transmitting source. Recent advances in Machine Learning, particularly in Deep Learning (DL), have improved the ability of RFF systems to extract and learn complex features that make up the device-specific fingerprint. However, integrating DL techniques with RFF and operating the system in real-world scenarios presents numerous challenges, originating from the embedded systems and the DL research domains. This paper systematically identifies and analyzes the essential considerations and challenges encountered in the creation of DL-based RFF systems across their typical development life-cycle, which include (i) data collection and preprocessing, (ii) training, and finally, (iii) deployment. Our investigation provides a comprehensive overview of the current open problems that prevent real deployment of DL-based RFF systems while also discussing promising research opportunities to enhance the overall accuracy, robustness, and privacy of these systems.
Saeif Alhazbi, Ahmed Hussain 0002, Savio Sciancalepore, Gabriele Oligeri, Panagiotis Papadimitratos
IWCMC3
2024 Watch Nearby! Privacy Analysis of the People Nearby Service of Telegram
abstract
People Nearby is a service offered by Telegram that allows a user to discover other Telegram users, based only on geographical proximity. Nearby users are reported with a rough estimate of their distance from the position of the reference user, allowing Telegram to claim location privacy. In this paper, we systematically analyze the location privacy provided by Telegram to users of the People Nearby service. Through an extensive measurement campaign run by spoofing the user's location all over the world, we reverse-engineer the algorithm adopted by People Nearby to compute distances between users. Although the service protects against precise user localization, we demonstrate that location privacy is always lower than the one declared by Telegram (500~meters). Specifically, we discover that location privacy is a function of the geographical position of the user. Indeed, the radius of the location privacy area (localization error) spans between 400~meters (close to the equator) and 128~meters (close to the poles), with a difference of up to 75% (worst case) compared to what Telegram declares. After our responsible disclosure, Telegram updated the FAQ associated with the service. Finally, we provide some solutions and countermeasures that Telegram can implement to improve location privacy. In general, the reported findings highlight the significant privacy risks associated with the use of the People Nearby service.
Maurantonio Caprolu, Savio Sciancalepore, Aleksandar Grigorov, Velyan Kolev, Gabriele Oligeri
WISEC2
2024 MAG-PUFs: Authenticating IoT devices via electromagnetic physical unclonable functions and deep learning
abstract
The challenge of authenticating Internet of Things (IoT) devices, particularly in low-cost deployments with constrained nodes that struggle with dynamic re-keying solutions, renders these devices susceptible to various attacks. This paper introduces a robust alternative mitigation strategy based on Physical-Layer Authentication (PLA), which leverages the intrinsic physical layer characteristics of IoT devices. These unique imperfections, stemming from the manufacturing process of IoT electronic integrated circuits (ICs), are difficult to replicate or falsify and vary with each function executed by the IoT device. We propose a novel lightweight authentication scheme, MAG-PUFs, that uses the unintentional Electromagnetic (EM) emissions from IoT devices as Physical Unclonable Functions (PUFs). MAG-PUFs operate by collecting these unintentional EM emissions during the execution of pre-defined reference functions by the IoT devices. The authentication is achieved by matching these emissions with profiles recorded at the time of enrollment, using state-of-the-art Deep Learning (DL) approaches such as Neural Networks (NN) and Autoencoders. Notably, MAG-PUFs offer compelling advantages: (i) it preserves privacy, as it does not require direct access to the IoT devices; and, (ii) it provides unique flexibility, permitting the selection of numerous and varied reference functions. We rigorously evaluated MAG-PUFs using 25 Arduino devices and a diverse set of 325 reference function classes. Employing a DL framework, we achieved a minimum authentication F1-Score of 0.99. Furthermore, the scheme’s efficacy in detecting impostor EM emissions was also affirmed, achieving a minimum F1-Score of 0.99. We also compared our solution to other solutions in the literature, showing its remarkable performance. Finally, we discussed code obfuscation techniques and the impact of Radio Frequency (RF) interference on the IoT authentication process.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
Comput. Secur.2
2024 ORION: Verification of drone trajectories via remote identification messages
abstract
With the widespread adoption of drones in daily life, next-generation smart cities need to establish highways, i.e., trajectories where drones can fly and operate safely. However, due to the untrusted nature of their ecosystem, drones might misbehave and take disallowed trajectories, e.g., to reduce the time to fly to a destination, reduce energy consumption, visit unauthorized areas, or disrupt operations of sensitive sites. In this paper, we address the cited problem by proposing ORION, a new framework for online drone trajectory verification. ORION requires one or more receivers distributed in a given area capable of receiving and analyzing standard Remote Identification (RID) messages emitted by operational drones. ORION compares the locations reported in such messages with the closest set of coordinates in the allowed trajectory. It raises an alarm if the distance between such locations exceeds a threshold calibrated offline. We validate the performance of ORION through data collected from both a real drone flight in Amsterdam (Netherlands) and taxi trajectories in Porto (Portugal), achieving a True Positive Ratio (correct detection of disallowed trajectories) up to 0.95 and a False Positive Ratio (incorrect detection of disallowed trajectories) up to 0.04. Our solution significantly outperforms existing approaches used for drone detection or time-series analysis. Finally, we also release the gathered data as open-source to foster future research.
Savio Sciancalepore, Filip Davidovic, Gabriele Oligeri
Future Gener. Comput. Syst.1
2024 Jamming Detection in Low-BER Mobile Indoor Scenarios via Deep Learning
abstract
The current state of the art on jamming detection relies on link-layer metrics. A few examples are the bit-error rate (BER), the packet delivery ratio, the throughput, and the signal-to-noise ratio (SNR). As a result, these techniques can only detect jamming ex-post, i.e., once the attack has already taken down the communication link. These solutions are unfit for mobile devices, e.g., drones, which might lose the connection to the remote controller, being unable to predict the attack. Our solution is rooted in the idea that a drone unknowingly flying toward a jammed area is experiencing an increasing effect of the jamming, e.g., in terms of BER and SNR. Therefore, drones might use the abovementioned phenomenon to detect jamming before the increase of the BER and the decrease of the SNR completely disrupt the communication link. Such an approach would allow drones and their pilots to make informed decisions and maintain complete control of navigation, enhancing security and safety. This article proposes Bloodhound+, a solution for jamming detection on mobile devices in low-BER regimes. Our approach analyzes raw physical-layer information (I-Q samples) acquired from the wireless channel. We assemble this information into grayscale images and use sparse autoencoders to detect image anomalies caused by jamming attacks. To test our solution against a broad set of configurations, we acquired a large data set of indoor measurements using multiple hardware, jamming strategies, and communication parameters. Our results indicate that Bloodhound+ can detect indoor jamming up to 20 m from the jamming source at the minimum available relative jamming power, with a minimum accuracy of 99.7%. Our solution is also robust to various sampling rates adopted by the jammer and to the type of signal used for jamming.
Savio Sciancalepore, Fabrice Kusters, Nada Khaled Abdelhadi, Gabriele Oligeri
IEEE Internet Things J.1
2024 Selective Authenticated Pilot Location Disclosure for Remote ID-enabled Drones
abstract
Remote Identification (RID) regulations recently promulgated worldwide are forcing commercial drones to broadcast wirelessly the location of the pilot in plaintext. However, in many real-world use cases, the plaintext availability of such information leads to privacy issues, allowing the extraction of sensitive information about the pilot and confidential details about the drone's business. To address this issue, this paper proposes SNELL, a RID-compliant solution for selective authenticated pilot location disclosure. Using SNELL, a drone can disclose RID messages providing encrypted information about the pilot's location. At the same time, thanks to the smart integration of Ciphertext-Policy Attribute-Based Encryption (CP-ABE) techniques, the data about the pilot location can be decrypted only by receivers with a set of attributes satisfying an access control policy chosen by the drone at run-time. Thanks to an extensive experimental assessment carried out on a real medium-end drone (Lumenier QAV-R) and a constrained chip (ESP32), we demonstrate that SNELL can fulfil all the requirements imposed by RID and relevant standardization authorities in terms of pilot location update time and message size while also requiring negligible energy toll on RID-compliant drones.
Pietro Tedeschi, Siva Ganesh Ganti, Savio Sciancalepore
Proc. Priv. Enhancing Technol.3
2023 ICSvertase: A Framework for Purpose-based Design and Classification of ICS Honeypots
abstract
As attacks on Industrial Control Systems (ICS) are increasing, the design and deployment of ICS honeypots is gaining momentum as a way to prevent, detect, and research them. However, ICS honeypot creators hardly explicitly consider what adversary behavior they want to capture, potentially creating honeypots that may not completely fulfill their intended purpose. At the same time, ICS honeypots are classified using the traditional interaction level scheme which is unsuitable for ICS due to its unique properties. In turn, these issues make it hard for potential users to systematically determine the suitability of an ICS honeypot for their use case. To tackle these problems, in this paper we introduce ICSvertase, a novel framework allowing for structural reasoning about ICS honeypots. ICSvertase integrates several existing components from the ATT&CK for ICS and Engage frameworks provided by MITRE and extends them with novel elements. ICSvertase provides a novel approach to helping companies and users in several real-world use cases, such as choosing the most suitable existing ICS honeypot, designing new ICS honeypots, and classifying existing ones in a more fine-grained way. To show ICSvertase’s benefits, we provide examples for these real-world use cases and compare them to their traditional counterparts.
Stash Kempinski, Shuaib Ichaarine, Savio Sciancalepore, Emmanuele Zambon
ARES3
2023 The Day-After-Tomorrow: On the Performance of Radio Fingerprinting over Time
abstract
The performance of Radio Frequency (RF) Fingerprinting (RFF) techniques is negatively impacted when the training data is not temporally close to the testing data. This can limit the practical implementation of physical-layer authentication solutions. To circumvent this problem, current solutions involve collecting training and testing datasets at close time intervals—this being detrimental to the real-life deployment of any physical-layer authentication solution. We refer to this issue as the Day-After-Tomorrow (DAT) effect, being widely attributed to the temporal variability of the wireless channel, which masks the physical-layer features of the transmitter, thus impairing the fingerprinting process.
Saeif Alhazbi, Savio Sciancalepore, Gabriele Oligeri
ACSAC2
2023 Lightweight Privacy-Preserving Proximity Discovery for Remotely-Controlled Drones
abstract
Discovering mutual proximity and avoiding collisions is one of the most critical services needed by the next generation of Unmanned Aerial Vehicles (UAVs). However, currently available solutions either rely on sharing mutual locations, neglecting the location privacy of involved parties, or are applicable for fully autonomous vehicles only—leaving unaddressed Remotely-Piloted UAVs’ safety needs. Alternatively, proximity can be discovered by adding sensing capabilities. However, in addition to the cost of the sensors, the complexity of integration, and the toll on the energy budget, the effectiveness of such solutions is usually limited by short detection ranges, making them hardly useful in high-mobility scenarios. In this paper, we propose LPPD (an acronym for Lightweight Privacy-preserving Proximity Discovery), a unique solution for privacy-preserving proximity discovery among remotely piloted UAVs based on the exchange of wireless messages. LPPD integrates two main building blocks: (i) a custom space tessellation technique based on randomized spheres; and, (ii) a lightweight cryptographic primitive for private-set intersection. Another feature enjoyed by LPPD is that it does not require online third parties. LPPD is rooted in sound theoretical results and is supported by an experimental assessment performed on a real drone. In particular, experimental results show that LPPD achieves 100% proximity discovery while taking only 39.66 milliseconds in the most lightweight configuration and draining only the 5 · 10− 6% of the UAV’s battery capacity. In addition, LPPD’s security properties are formally verified.
Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro
ACSAC2
2023 BloodHound: Early Detection and Identification of Jamming at the PHY-layer
abstract
Traditional jamming detection techniques, adopted in static networks, require the receiver (under jamming) to infer the presence of the jammer by measuring the effects of the jamming activity (packet loss and received signal strength), thus resulting only in a-posteriori analysis. However, in mobile scenarios, receivers (e.g., drones, vehicles, etc.) typically experience an increasing jamming effect while moving toward the jamming source. This phenomenon allows, in principle, an early detection of the jamming activity—being the communication not yet affected by the jamming (no packet loss). Under such an assumption, the mobile receiver can take an informed decision before losing the radio connection with the other party. To the best of our knowledge, this paper represents the first attempt toward the detection of a jammer before the radio link is fully affected by its activity. The proposed solution, namely, BloodHound, can early detect the approach to a jammer in a mobile scenario, i.e., before losing the capability of communicating, thus enhancing situational awareness and robustness. We performed an extensive measurement campaign, and we proved our solution to be able to detect the presence of a jammer with an accuracy higher than 0.99 even when the bit error rate is less than 0.01 (early detection), by varying several configuration parameters of the scenario.
Saeif Alhazbi, Savio Sciancalepore, Gabriele Oligeri
CCNC2
2023 Jamming Detection in Power Line Communications Leveraging Deep Learning Techniques
abstract
Power Line Communications (PLC) is a well-established technology that allows devices connected to the power line to communicate with each other. While the majority of research in this field is devoted to issues of availability, the topic of Denial of Service (DoS) attacks has not been sufficiently addressed. Typically, current solutions might detect a jammer when situated near the target devices, yet the equipment under jamming interference may face challenges in communicating an alarm. However, when these systems are placed at a significant distance from the jammer, the negligible impact of the jamming renders its detection hardly detectable. In this work, we propose a solution to identify the presence of a jammer in a PLC infrastructure even when deployed at a significant distance. We analyze the physical layer of the PLC link and adopt state-of-the-art Deep Learning techniques to detect jamming even at a distance where the jammer's effect is negligible, thus allowing the device to trigger an alarm. Considering a jammer featuring the same transmission power as legitimate devices, we prove that we can detect the presence of such a jammer with an overwhelming probability (higher than 0.99) even at a distance of 75 m from the source.
Aymen Omri, Javier Hernandez Fernandez, Savio Sciancalepore, Gabriele Oligeri
ISNCC4
2023 Privacy-Preserving Multi-Party Access Control for Third-Party UAV Services
abstract
Third-Party Unmanned Aerial Vehicle (UAV) Services, a.k.a. Drone-as-a-Service (DaaS), are an increasingly adopted business model, which enables possibly unskilled users, with no background knowledge, to operate drones and run automated drone-based tasks. Although these services provide significant advantages, the resources provided by drones are typically owned by multiple parties. Thus, Third-Party UAV services require adopting multi-party access control solutions. In this context, the leakage of the access control policies specified by the data owners might disclose confidential information and, thus, they should be protected as well. In this work, we propose a privacy-preserving multi-party access control solution tailored to the application scenarios of Third-Party UAV Services. Our solution advances an existing privacy-preserving multi-party access control framework based on Secure Function Evaluation to fit the distributed and heterogeneous nature of drone deployments. Through an extensive experimental evaluation, we demonstrate our solution can perform private policy evaluation on constrained devices in a reasonable time while requiring limited communication, memory, and energy overhead.
Dominik Roy George, Savio Sciancalepore, Nicola Zannone
SACMAT2
2023 A2RID - Anonymous Direct Authentication and Remote Identification of Commercial Drones
abstract
The recent worldwide introduction of RemoteID (RID) regulations forces all unmanned aircrafts (UAs), also known as drones, to broadcast in plaintext on the wireless channel their identity and real-time location, for accounting and monitoring purposes. Although improving drones’ monitoring and situational awareness, the RID rule also generates significant privacy concerns for UAs’ operators, threatened by the ease of tracking of UAs and related confidentiality and privacy concerns connected with the broadcasting of plaintext identity information. In this article, we propose anonymous direct authentication and remote identification ($A^{2}RID$), a protocol suite for$A^{2}RID$of heterogeneous commercial UAs.$A^{2}RID$integrates and adapts protocols for anonymous message signing to work in the UA domain, coping with the constraints of commercial drones and the tight real-time requirements imposed by the RID regulation. Overall, the protocols in the$A^{2}RID$suite allow a UA manufacturer to pick the configuration that best suits the capabilities and constraints of the drone, i.e., either a processing-intensive but memory-lightweight solution (namely,$CS-A^{2}RID$) or a computationally friendly but memory-hungry approach (namely,$DS-A^{2}RID$). Besides formally defining the protocols and formally proving their security in our setting, we also implement and test them on real heterogeneous hardware platforms, i.e., the Holybro X-500 and the ESPcopter, releasing open-source the produced code. For all the protocols, we demonstrated experimentally the capability of generating anonymous RemoteID messages well below the time bound of 1 s required by RID, while at the same time having quite a limited impact on the energy budget of the drone.
Eva Wisse, Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro
IEEE Internet Things J.3
2023 PPCA - Privacy-Preserving Collision Avoidance for Autonomous Unmanned Aerial Vehicles
abstract
Current collision avoidance techniques deployed on Unmanned Aerial Vehicles (UAVs) rely on short-range sensors, such as proximity sensors, cameras, and microphones. Unfortunately, their efficiency is significantly limited in several situations; for instance, when a remote UAV approaches at high velocity, or when the surrounding environment is impaired (e.g., fog, noise). In the cited cases, to avoid collisions and maintain self-separation, UAVs often rely on the indiscriminate broadcast of their location. Therefore, an adversary could easily identify the location of the UAV and attack it, e.g., by physically shutting it down, launching wireless jamming attacks, or continuing tracking its movements. To address the above-introduced threats, in this article we present PPCA, a lightweight, distributed, and privacy-preserving scheme to avoid collisions among UAVs. Our solution, based on an ingenious tessellation of the space, is accompanied by a thorough analytical model and is supported by an extensive experimental campaign performed on a real 3DR-Solo drone. The achieved results are striking: PPCA can efficiently and effectively avoid collisions among UAVs, by requiring a limited bandwidth and computational overhead (84.85% less than traditional privacy-preserving proximity testing approaches), while providing unique benefits in terms of privacy of the participating UAVs.
Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro
IEEE Trans. Dependable Secur. Comput.2
2023 PAST-AI: Physical-Layer Authentication of Satellite Transmitters via Deep Learning
abstract
Physical-layer security is regaining traction in the research community, due to the performance boost introduced by deep learning classification algorithms. This is particularly true for sender authentication in wireless communications via radio fingerprinting. However, previous research mainly focused on terrestrial wireless devices while, to the best of our knowledge, none of the previous work considered satellite transmitters. The satellite scenario is generally challenging because, among others, satellite radio transducers feature non-standard electronics (usually aged and specifically designed for harsh conditions). Moreover, the fingerprinting task is specifically difficult for Low-Earth Orbit (LEO) satellites (like the ones we focus in this paper) since they feature a low bit-rate and orbit at about 800 Km from the Earth, at a speed of around 25,000 Km/h, thus making the receiver experiencing a down-link with unique attenuation and fading characteristics. In this paper, we investigate the effectiveness and main limitations of AI-based solutions to the physical-layer authentication of LEO satellites. Our study is performed on massive real data—more than$100M$I-Q samples—collected from an extensive measurements campaign on the IRIDIUM LEO satellites constellation, lasting 589 hours. Our results show that Convolutional Neural Networks (CNN) and autoencoders (if properly calibrated) can be successfully adopted to authenticate the satellite transducers, with an accuracy spanning between 0.8 and 1, depending on prior assumptions. However, the relatively high number of I-Q samples required by the proposed methodology, coupled with the low bandwidth of satellite link, might prevent the detection of the spoofing attack under certain configuration parameters.
Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro
IEEE Trans. Inf. Forensics Secur.2
2022 Hide and Seek: Privacy-Preserving and FAA-compliant Drones Location Tracing
abstract
Due to the frequent unauthorized invasions by commercial drones to Critical Infrastructures (CIs), the US-based Federal Avionics Administration (FAA) recently published a new specification, namely RemoteID. Such a rule requires all drones to broadcast information about their identity and location, to allow for immediate invasion attribution and counter-actions. However, the enforcement of such a rule poses severe concerns on drones’ operators, especially in terms of location privacy and tracking threats. Indeed, by simply receiving wireless signals, an adversary could know the precise drone location, track it, and infer sensitive information.
Alessandro Brighente, Mauro Conti, Savio Sciancalepore
ARES3
2022 Privacy-Preserving Trajectory Matching on Autonomous Unmanned Aerial Vehicles
abstract
Autonomous Unmanned Aerial Vehicles (UAVs) are increasingly deployed nowadays, thanks to the additional features and enhanced flexibility they provide, e.g., for transportation and goods delivery. On the one hand, discovering in advance collisions occurring with other UAVs in the future could enhance the efficiency of the path planning, reducing further the delivery time and UAVs’ energy consumption. On the other hand, location and timestamps–key to detecting and avoiding collisions in advance–are sensitive and cannot be shared indiscriminately with untrusted entities.
Savio Sciancalepore, Dominik Roy George
ACSAC1
2022 Stepping out of the MUD: Contextual threat information for IoT devices with manufacturer-provided behavior profiles
abstract
Besides coming with unprecedented benefits, the Internet of Things (IoT) suffers deficits in security measures, leading to attacks increasing every year. In particular, network environments such as smart homes lack managed security capabilities to detect IoT-related attacks; IoT devices hosted therein are thus more easily targeted by threats. As such, context awareness of IoT infections is hard to achieve, preventing prompt response. In this work, we propose MUDscope, an approach to monitor malicious network activities affecting IoT systems in real-world consumer environments. We leverage the recent Manufacturer Usage Description (MUD) specification, which defines networking allow-lists for IoT devices in MUD profiles, to reflect consistent and necessarily-anomalous activities from smart things. Our approach characterizes this traffic and extracts signatures for given attacks. By analyzing attack signatures for multiple devices, we gather insights into emerging attack patterns. We evaluate our approach on both an existing dataset and a new, openly available dataset created for this research. We show that MUDscope detects several attacks targeting IoT devices with an F1-score of 95.77% and correctly identifies signatures for specific attacks with an F1-score of 87.72%.
Luca Morgese Zangrandi, Thijs van Ede, Tim M. Booij, Savio Sciancalepore, Luca Allodi, Andrea Continella
ACSAC4
2022 FRACTAL: Single-Channel Multi-factor Transaction Authentication Through a Compromised Terminal
Savio Sciancalepore, Simone Raponi, Daniele Caldarola, Roberto Di Pietro
ICICS1
2022 MAG-PUF: Magnetic Physical Unclonable Functions for Device Authentication in the IoT
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
SecureComm2
2022 MAG-PUF - Authenticating IoT Devices via Magnetic Physical Unclonable Functions
abstract
Authenticating Internet of Things (IoT) devices is still a defiant task, despite the remarkable technological advancement achieved in the last few years. The issue is especially challenging in scenarios involving low-cost constrained nodes, hardly supporting dynamic re-keying algorithms. To provide a viable general-purpose solution, we propose MAG-PUF: a novel and lightweight authentication scheme using unintentional magnetic emissions produced by IoT devices to implement Physical Unclonable Functions (PUFs). Our extensive experimental campaign, involving 25 Arduino boards and four example reference functions, unveiled an outstanding authentication accuracy of over 99%, proving the feasibility of using code-driven magnetic emissions as a lightweight, efficient, and robust PUF for IoT deployments.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
WISEC2
2022 GPS spoofing detection via crowd-sourced information for connected vehicles
abstract
Modern vehicular systems rely on the Global Positioning System (GPS) technology to provide accurate and timely services. However, the GPS has been proved to be characterized by an intrinsic insecure design, thus being subject to several security attacks. Current solutions can reliably detect GPS spoofing attacks leveraging the physical features of the received GPS signals or resorting to multiple antennas. However, these techniques cannot be deployed when the physical properties of the received signals cannot be accessed, which is the most general case for commercial GPS receivers. Alternative solutions in the literature rely on the cross-check of the received signal with information coming from additional sources. However, such proposals are typically limited to a single source, are rarely supported by experimental results, and do not provide insights on the impact of several parameters, such as detection accuracy, time, false-positives, and robustness to malicious information. To overcome the cited limitations, in this paper, we propose an innovative approach, resorting to combined crowd-sourced information from the mobile cellular infrastructure and the WiFi networks to detect GPS spoofing attacks. Our analysis leverages an extensive experimental dataset, available online for the research community, gathered by driving around a car in urban, suburban, and rural scenarios, for around 5 h and covering more than 196 km. Our solution allows for a tunable tradeoff between detection delay and false positive; for instance, we can detect an attack in approximately 6 s, when leveraging the information coming from only the WiFi, while the delay increases to 30 s when using the information from the mobile cellular network, still achieving a false positive probability strictly less than 0.01. We also show the limitations and trade-offs of our approach, in terms of minimum detection accuracy, time, and robustness to malicious information. The data adopted in this work are publicly released to allow results replicability and foster further research in the highlighted directions.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
Comput. Networks2
2022 PARFAIT: Privacy-preserving, secure, and low-delay service access in fog-enabled IoT ecosystems
abstract
Traditional fog-enabled IoT ecosystems always assume fully-trusted and secure fog nodes, offering computational capabilities and storage space closer to constrained IoT devices. However, such security-related assumptions can easily fall when considering the exposure of fog nodes’ location, the heterogeneity of device providers, and the ease of misuse and misconfigurations by end-users, to name a few. As a result, compromised fog nodes can stealthily steal sensitive information, such as the devices’ location, path, and private personal attributes. This paper presents PARFAIT, a privacy-preserving, secure, and low-delay framework for securely accessing services in fog-enabled IoT ecosystems. PARFAITguarantees low-delay authentication and authorization to local fog nodes, protecting the identity and the attributes possessed by the IoT devices. Moreover, PARFAITuses rolling ephemeral identities, providing unlinkability among access requests, thus preventing the tracking of mobile IoT devices by multiple compromised fog nodes. We performed several experimental tests on a reference proof-of-concept to show the viability of PARFAIT. Specifically, adopting an elliptic curve with a group size of 512 bits, PARFAITallows the access to a single protected resource in only 0.274 s, and such a delay rises to only 0.359 s with 10 consecutive requests (66.8% less than the quickest competing approach).
Savio Sciancalepore
Comput. Networks1
2022 Satellite-based communications security: A survey of threats, solutions, and research challenges
abstract
Satellite-based Communication (SATCOM) systems are gaining renewed momentum in Industry and Academia, thanks to innovative services introduced by leading tech companies and the promising impact they can deliver towards the global connectivity objective tackled by early 6G initiatives. On the one hand, the emergence of new manufacturing processes and radio technologies promises to reduce service costs while guaranteeing outstanding communication latency, available bandwidth, flexibility, and coverage range. On the other hand, cybersecurity techniques and solutions applied in SATCOM links should be updated to reflect the substantial advancements in attacker capabilities characterizing the last two decades. However, business urgency and opportunities are leading operators towards challenging system trade-offs, resulting in an increased attack surface and a general relaxation of the available security services. In this paper, we tackle the cited problems and present a comprehensive survey on the link-layer security threats, solutions, and challenges faced when deploying and operating SATCOM systems. Specifically, we classify the literature on security for SATCOM systems into two main branches, i.e., physical-layer security and cryptography schemes. Then, we further identify specific research domains for each of the identified branches, focusing on dedicated security issues, including, e.g., physical-layer confidentiality, anti-jamming schemes, anti-spoofing strategies, and quantum-based key distribution schemes. For each of the above domains, we highlight the most essential techniques, peculiarities, advantages, disadvantages, lessons learned, and future directions. Finally, we also identify emerging research topics whose additional investigation by Academia and Industry could further attract researchers and investors, ultimately unleashing the full potential behind ubiquitous satellite communications.
Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro
Comput. Networks2
2022 Noise2Weight: On detecting payload weight from drones acoustic emissions
abstract
The increasing popularity of autonomous and remotely-piloted drones has paved the way for several use-cases and application scenarios, including merchandise delivery, surveillance, and warfare, to cite a few. In many application scenarios, estimating with zero-touch the weight of the payload carried by a drone before it approaches could be of particular interest, e.g., to provide early tampering detection when the weight of the payload is sensitively different from the expected one. To the best of our knowledge, we are the first to investigate the possibility to remotely detect the weight of the payload carried by a commercial drone by analyzing its acoustic fingerprint. Rooted on a sound methodology and validated by an extensive experimental on-field campaign carried out on a reference 3DR Solo drone, we characterize how the differences in the thrust needed by a drone to carry different payloads affect the speed of the motors and the blades and, in turn, introduces significant variations in the resulting acoustic fingerprint. We applied the above findings to different use-cases and scenarios, characterized by different computational capabilities of the detection system. Results are striking: using the Mel-Frequency Cepstral Coefficients (MFCC) components of the audio signal and different Support Vector Machine (SVM) classifiers, we showed that it is possible to achieve a minimum classification accuracy of 98% in the detection of the specific payload class carried by the drone, using an acquisition time of only 0.25 s—performances improve when using longer time acquisitions. All the data used for our analysis have been released as open-source, to enable the community to validate our findings and use such data as a ready-to-use basis for further investigations.
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro
Future Gener. Comput. Syst.2
2022 Auth-AIS: Secure, Flexible, and Backward-Compatible Authentication of Vessels AIS Broadcasts
abstract
Automatic Identification System (AIS) is the de-facto communication standard used by vessels to broadcast identification and position information. However, being AIS communications neither encrypted nor authenticated, they can be eavesdropped and spoofed by adversaries, leading to potentially threatening scenarios. Existing solutions, including the ones conceived in the avionics domain, do not consider integration with the AIS standard, and they do not provide protection against rogue messages flooding. In this article, we propose Auth-AIS, a secure, flexible, standard-compliant, and backward-compatible authentication framework to secure AIS broadcast messages. Auth-AIS leverages existing sound cryptographic tools, including TESLA and Bloom Filters, inheriting their security properties while contextualizing them in the AIS technology. Auth-AIS is a software-only solution, that can be seamlessly integrated into existing AIS deployments, without requiring any hardware replacement. Its innovative design also provides backward-compatibility—i.e., Auth-AIS messages can be received also by AIS users not adopting Auth-AIS, while renouncing at its security guarantees. Auth-AIS can work in either two configuration modes: Deterministic Security Configuration, able to achieve low-delay authentication with a message overhead of 75 percent, or Probabilistic Security Configuration, reducing the message overhead down to 35.71 percent, while experiencing a marginal increase in the authentication delay. All these security configurations guarantee an 80 bits equivalent security level and false-positive rate less than 2--40. Note that these latter security parameters can easily be tuned to fit different security requirements. Finally, the source code of Auth-AIS in the GNURadio ecosystem has been released as open-source, to foster research activities from both Industry and Academia on secure AIS communications.
Savio Sciancalepore, Pietro Tedeschi, Ahmed Aziz, Roberto Di Pietro
IEEE Trans. Dependable Secur. Comput.1
2021 ARID: Anonymous Remote IDentification of Unmanned Aerial Vehicles
abstract
To enable enhanced accountability of Unmanned Aerial Vehicles (UAVs) operations, the US-based Federal Avionics Administration (FAA) recently published a new dedicated regulation, namely RemoteID, requiring UAV operators to broadcast messages reporting their identity and location. The enforcement of such a rule, mandatory by 2022, generated significant concerns on UAV operators, primarily because of privacy issues derived by the indiscriminate broadcast of the plain-text identity of the UAV on the wireless channel.
Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro
ACSAC2
2021 PPRQ: Privacy-Preserving MAX/MIN Range Queries in IoT Networks
abstract
Range queries are widely used in several Internet-of-Things (IoT) applications as a general strategy to improve the efficiency of the system. However, the communication patterns generated by the IoT nodes could lead to the identification of the devices satisfying the query, as well as to the disclosure of the queried data. State-of-the-art solutions to address the cited security issues rely on dedicated edge/fog nodes, whose deployment could be too expensive or challenging, especially in unattended scenarios where the installation of ad hoc locations could be difficult and mains-supply is hardly available. In this article, we propose PPRQ, a resilient, scalable, and lightweight protocol that allows privacy-preserving range queries in IoT networks. PPRQ is a probabilistic scheme that can be easily adapted to MIN, MAX, and MAX/MIN range queries, while requiring only hashing and bitwise xor operations. We show that PPRQ is robust, as it can be configured to provide over 99.9% accuracy in the query results. We also prove its resiliency against passive and active adversaries for a number of interesting and realistic scenarios. Our results are rooted in sound probability theory and supported by an extensive simulation campaign, while comparisons against state-of-the-art solutions show the flexibility and adaptability of PPRQ, especially for remote and unattended scenarios. Finally, further research directions opened up by the proposed solution are also highlighted.
Savio Sciancalepore, Roberto Di Pietro
IEEE Internet Things J.1
2021 Receivers location privacy in avionic crowdsourced networks: Issues and countermeasures
abstract
The lack of message encryption characterizing wireless avionic protocols, including Automatic Dependent Surveillance - Broadcast (ADS-B), recently favored the rise of a few communities that, gathering data collected by receivers at the ground or in space, offer advanced services, while at the same time releasing the cited data to the public. In this context, hiding the location of an ADS-B receiver could be useful for several reasons, including military and privacy aspects. Therefore, taking into account these considerations, the data provided by a few antennas in one of the most popular crowdsourcing platforms, Opensky Network, are released removing any information that could lead to their direct location identification. In this manuscript, we investigate the effectiveness of protecting location privacy in avionic crowdsourced networks. As a worst-case scenario, we demonstrate that, when a feasible number of receivers are deployed in the same area of a protected one, due to the nature of involved ADS-B data, standard time-based localization schemes can identify the location of any protected receiver. Our model, applied to real data, can identify the location of a protected receiver with an error ranging from 0.9 km to 2.6 km, depending on the target sensor—while the location uncertainty induced by the anonymization technique was expected to be of approximately 450 km. Our findings, supported by an extensive experimental campaign run over real data, apply to a variety of potentially protected receivers. Moreover, we also provide effective countermeasures to increase receivers’ location privacy. Finally, we discuss the trade-offs implied by the cited countermeasures, showing that it is possible to increase location privacy while not decreasing data utility.
Savio Sciancalepore, Saeif Alhazbi, Roberto Di Pietro
J. Netw. Comput. Appl.1
2021 SOS: Standard-Compliant and Packet Loss Tolerant Security Framework for ADS-B Communications
abstract
The Automatic Dependent Surveillance - Broadcast (ADS-B) technology, already deployed by the major avionics companies (e.g., QatarAirways and AmericanAirlines), will become mandatory on board of civil and military aircraft flying in Class A, B, and C airspaces by 2020, enabling direct airplanes communications and enhanced flights monitoring. However, ADS-B has been designed without security considerations, thus being vulnerable to a variety of attacks, including message injection and messages order manipulation attacks, that can be easily performed via widely available commercial Software Defined Radios. To address these threats, we present Securing Open Skies (SOS), a standard-compliant, backward-compatible, loss-tolerant, and bandwidth efficient security framework to secure ADS-B communications. SOS leverages the real deployment of densely distributed, participatory ADS-B sensor networks such as OpenSky Network and Flight Radar, and provides message authentication and integrity security services on a time-slot basis, without resorting to any public key cryptography mechanism. Experimental performances obtained through a realistic proof-of-concept, deployed using commercial Ettus Research X310 Software Defined Radios, demonstrate the viability and effectiveness of our solution, even in presence of uniformly at random or burst packet loss events characterizing the ADS-B frequency band. For instance, SOS allows the verification of the authenticity of ADS-B messages requiring less than 50 percent of bandwidth overhead, with a percentage of verifiable slots above 80 percent, even in an highly lossy environment, characterized by a single packet loss probability of 60 percent-the process requiring less than one second: almost one tenth of similar approaches published in the literature. Finally, a thorough comparison against state of the art solutions in the literature highlights the unique security and reliability features enjoyed by SOS, as well as its practical viability.
Savio Sciancalepore, Roberto Di Pietro
IEEE Trans. Dependable Secur. Comput.1
2021 MAGNETO: Fingerprinting USB Flash Drives via Unintentional Magnetic Emissions
abstract
Universal Serial Bus (USB) Flash Drives are nowadays one of the most convenient and diffused means to transfer files, especially when no Internet connection is available. However, USB flash drives are also one of the most common attack vectors used to gain unauthorized access to host devices. For instance, it is possible to replace a USB drive so that when the USB key is connected, it would install passwords stealing tools, root-kit software, and other disrupting malware. In such a way, an attacker can steal sensitive information via the USB-connected devices, as well as inject any kind of malicious software into the host. To thwart the above-cited raising threats, we propose MAGNETO, an efficient, non-interactive, and privacy-preserving framework to verify the authenticity of a USB flash drive, rooted in the analysis of its unintentional magnetic emissions. We show that the magnetic emissions radiated during boot operations on a specific host are unique for each device, and sufficient to uniquely fingerprint both the brand and the model of the USB flash drive, or the specific USB device, depending on the used equipment. Our investigation on 59 different USB flash drives—belonging to 17 brands, including the top brands purchased on Amazon in mid-2019—reveals a minimum classification accuracy of 98.2% in the identification of both brand and model, accompanied by a negligible time and computational overhead. MAGNETO can also identify the specific USB Flash drive, with a minimum classification accuracy of 91.2%. Overall, MAGNETO proves that unintentional magnetic emissions can be considered as a viable and reliable means to fingerprint read-only USB flash drives. Finally, future research directions in this domain are also discussed.
Omar Adel Ibrahim, Savio Sciancalepore, Gabriele Oligeri, Roberto Di Pietro
ACM Trans. Embed. Comput. Syst.2
2020 GNSS spoofing detection via opportunistic IRIDIUM signals
abstract
In this paper, we study the privately-own IRIDIUM satellite constellation, to provide a location service that is independent of the GNSS. In particular, we apply our findings to propose a new GNSS spoofing detection solution, exploiting unencrypted IRIDIUM Ring Alert (IRA) messages that are broadcast by IRIDIUM satellites.
Gabriele Oligeri, Savio Sciancalepore, Roberto Di Pietro
WISEC2
2020 BrokenStrokes: on the (in)security of wireless keyboards
abstract
Wireless devices resorting to event-triggered communications have been proved to suffer critical privacy issues, due to the intrinsic leakage associated with radio-frequency (RF) emissions.
Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro
WISEC2
2020 PiNcH: An effective, efficient, and robust solution to drone detection via network traffic analysis
Savio Sciancalepore, Omar Adel Ibrahim, Gabriele Oligeri, Roberto Di Pietro
Comput. Networks1
2020 LiKe: Lightweight Certificateless Key Agreement for Secure IoT Communications
abstract
Certificateless public-key cryptography (CL-PKC) schemes are particularly robust against the leakage of secret information stored on a trusted third party (TTP). These security features are particularly relevant for Internet of Things (IoT) domains, where the devices are typically preconfigured with secret keys, usually stored locally on the TTP for following maintenance tasks. Despite some contributions already proposed for the adoption of CL-PKC schemes in constrained IoT devices, current solutions generally require high message overhead, are computationally demanding, and place a high toll on the energy budget. To close this gap, we propose LiKe, a lightweight pairing-free certificateless key agreement protocol suitable for integration in the latest ZigBee 3.0 protocol stack and constrained IoT devices. LiKe is an authenticated key agreement protocol characterized by: 1) ephemeral cryptographic materials; 2) support for intermittent connectivity with the TTP; 3) lightweight rekeying operations; and 4) robustness against impersonation attacks, even when information stored on the TTP is leaked. LiKe has been thoroughly described, and its security properties have been proved via formal tools. Moreover, we have implemented and tested it on real IoT devices, in networks with up to 11 nodes-the source code has been released as an open source. Results are striking: on the OpenMote-b hardware platform, LiKe requires a total time of 3.259 s to establish session keys on each participating device, and at most 0.258% of the overall battery capacity, emerging as a lightweight and energy-friendly solution. Finally, comparisons with competing solutions do show the superior quality and viability of our proposal.
Pietro Tedeschi, Savio Sciancalepore, Areej Eliyan, Roberto Di Pietro
IEEE Internet Things J.2
2020 A Privacy Risk Assessment Model for Medical Big Data Based on Adaptive Neuro-Fuzzy Theory
abstract
Information leakage in the medical industry has become an urgent problem to be solved in the field of Internet security. However, due to the need for automated or semiautomated authorization management for privacy protection in the big data environment, the traditional privacy protection model cannot adapt to this complex open environment. Although some scholars have studied the risk assessment model of privacy disclosure in the medical big data environment, it is still in the initial stage of exploration. This paper analyzes the key indicators that affect medical big data security and privacy leakage, including user access behavior and trust, from the perspective of users through literature review and expert consultation. Also, based on the user’s historical access information and interaction records, the user’s access behavior and trust are quantified with the help of information entropy and probability, and a definition expression is given explicitly. Finally, the entire experimental process and specific operations are introduced in three aspects: the experimental environment, the experimental data, and the experimental process, and then, the predicted results of the model are compared with the actual output through the 10-fold cross verification with Matlab. The results prove that the model in this paper is feasible. In addition, the method in this paper is compared with the current more classical medical big data risk assessment model, and the results show that when the proportion of illegal users is less than 15%, the model in this paper is more superior in terms of accuracy and recall.
Mingyue Shi, Savio Sciancalepore
Secur. Commun. Networks5
2019 Location Privacy Issues in the OpenSky Network Crowdsourcing Platform
Savio Sciancalepore, Saeif Alhazbi, Roberto Di Pietro
SecureComm (1)1
2019 Drive me not: GPS spoofing detection via cellular network: (architectures, models, and experiments)
abstract
The Global Positioning System (GPS) has been proved to be exposed to several cybersecurity attacks, due to its intrinsic insecure design. GPS spoofing is one of the most easiest, cheap, and dreadful attacks that can be delivered: fake GPS signals can be sent to a target device and make it moving according to a pre-computed path.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
WiSec2
2019 EXCHANge: Securing IoT via channel anonymity
Savio Sciancalepore, Gabriele Oligeri, Giuseppe Piro, Gennaro Boggia, Roberto Di Pietro
Comput. Commun.1
2018 Multi-Domain Access Rights Composition in Federated IoT Platforms
Savio Sciancalepore, Giuseppe Piro, Pietro Tedeschi, Gennaro Boggia, Giuseppe Bianchi 0001
EWSN1
2018 On the Design of a Decentralized and Multiauthority Access Control Scheme in Federated and Cloud-Assisted Cyber-Physical Systems
abstract
While enabling brand new services and opportunities, the federation of vertical Internet of Things platforms presents new challenges in terms of secure and controlled access to heterogeneous resources, especially when authorization permissions must be regulated by multiple decentralized authorities. The work presented herein designs, develops, and experimentally validates a flexible and effective attribute-based access control framework, properly devised to operate in a federated and cloud-assisted cyber-physical system (CPS). Our main novelty stems in the original way we turn a policy-based encryption scheme, customarily used for accessing data, into a cyber-physical resource access control protocol. The proposed design approach is able to address several security issues characterizing the emerging use cases in this context, including the decoupling between authentication and authorization, fine-grained, offline, and time-limited authorization, protection against collusion attacks, access rights revocation, and user privacy. A security analysis and a performance evaluation executed through experimental tests clearly demonstrate the viability of the proposed approach in realistic cloud-assisted CPSs, as well as its ability to overcome the lacks affecting competitive approaches without introducing huge communication and computational requirements.
Savio Sciancalepore, Giuseppe Piro, Daniele Caldarola, Gennaro Boggia, Giuseppe Bianchi 0001
IEEE Internet Things J.1
2018 Position and Velocity Estimation of a Non-Cooperative Source From Asynchronous Packet Arrival Time Measurements
abstract
We tackle the problem of identifying the trajectory of a moving radio source from Time of Arrival (TOA) measurements collected by a set of cooperating receivers. The considered system is completely asynchronous: nodes clocks are affected by unknown time and frequency offsets, and no control is exerted over packet transmission times. In the proposed solution, the receiver clock offset terms are estimated from TOA measurements on packets originated by non-cooperative reference transmitters, possibly but not necessarily coincidental with reference receivers. Transmission time ambiguity is resolved by exploiting the redundancy associated to the reception of the same packet at multiple receivers. A distinguishing feature of the proposed solution is that it seeks to identify the parameters of the trajectory as a whole, rather than the individual points of transmission as done in traditional point-based approaches. This allows the effective exploitation of TOA measurements collected in lossy scenarios, where the generic packet is received by a smaller subset of the available receivers (at least two). For the problem at hand, we provide distinct estimators based on TOA and Time-Difference of Arrival (TDOA) and prove their equivalence. Numerical results from simulations and from a real WiFi testbed are provided to validate the effectiveness of the proposed method.
Fabio Ricciato, Savio Sciancalepore, Francesco Gringoli, Nicolò Facchi, Gennaro Boggia
IEEE Trans. Mob. Comput.2
2017 OAuth-IoT: An access control framework for the Internet of Things based on open standards
abstract
While the Internet of Things is breaking into the market, the controlled access to constrained resources still remains a blocking concern. Unfortunately, conventional solutions already accepted for both web and cloud applications cannot be directly used in this context. In fact, they generally require high computational and bandwidth capabilities (that are impossible to reach with constrained devices) and offer poor interoperability against standardized communication protocols for the Internet of Things. To solve this issue, this contribution presents a flexible authentication and authorization framework for the Internet of Things, namely OAuth-IoT. It leverages and properly harmonizes existing open-standards (including the OAuth 2.0 authorization framework, different token formats, and the protocol suite for the Internet of Things tailored by the Internet Engineering Task Force), while carefully taking into account the limited capabilities of constrained devices. Functionalities and benefits offered by OAuth-IoT are pragmatically shown by means of an experimental testbed, and further demonstrated with a very preliminary performance assessment.
Savio Sciancalepore, Giuseppe Piro, Daniele Caldarola, Gennaro Boggia, Giuseppe Bianchi 0001
ISCC1
2016 LICITUS: A lightweight and standard compatible framework for securing layer-2 communications in the IoT
abstract
With reference to the IEEE 802.15.4 standard, many solutions have been formulated to face the different facets of layer-2 security. Unfortunately, the opportunities and subtleties arising from their joint adoption has been not investigated, due to the lack of an integrating framework. To this end, hereby a novel standard compatible framework is proposed, which is able to orchestrate several layer-2 security mechanisms with a limited computational footprint. Conceived as a distributed scheme, it covers the following key features: (i) multiple security configurations in homogeneous and heterogeneous scenarios; (ii) adaption to dynamic networks; (iii) lean and scalable initialization functionalities; (iv) lightweight Key Management Protocol; and (v) resilience to several attacks. The robustness against security attacks have been evaluated through a well-known automatic cryptographic protocol verifier, namely ProVerif. Moreover, to further demonstrate its effectiveness, the proposed framework has been implemented within the emerging OpenWSN protocol stack, experimentally evaluated, and compared with respect to the ZigBee IP security architecture, which integrates the Symmetric Key - Key Establishment protocol (SKKE). Results clearly show that, although security features in constrained nodes incur not negligible computational costs (which impair latencies and energy efficiency), the proposed approach always guarantees better performances with respect to the ZigBee IP security architecture. In fact, it speeds up the configuration of security services (up to 120%), while ensuring relevant energy savings (larger than 50%).
Savio Sciancalepore, Giuseppe Piro, Elvis Vogli, Gennaro Boggia, Luigi Alfredo Grieco, Giuseppe Cavone
Comput. Networks1