VLDB 2026 Research / reviewers in the wild / expert
Shreyas Srinivasa
dblp:172/6486
· DBLP profile ↗
5ranked-venue papers
3as first author
3since 2021 · last 2024
0000-0002-5720-5504ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Securing PUFs via a Predictive Adversarial Machine Learning System by Modeling of AttackersabstractThe widespread adoption of Internet-of-Things (IoT) devices is elevating the security expectations of many application domains. Meanwhile, numerosity, hardware and software heterogeneity, and low cost of IoT devices makes meeting such expectations challenging. A key security function that IoT devices must possess is identity and the capability to authenticate themselves. However, traditional authentication mechanisms rely on hash-based cryptography, requiring complex hardware and computational resources. To mitigate this problem, the Physical Unclonable Function (PUF) has been proposed as a lightweight source of device-specific entropy that can be used for identifying IoT devices. However, a major challenge to this approach is protecting PUFs against Machine Learning (ML)-based modeling attacks, where an attacker can clone an authentic PUF after collecting enough training data from the communication protocol, e.g., as a passive eavesdropper. In this paper, we propose a Predictive Adversarial System (PAS) that aims to prevent ML modeling attacks by predicting the capabilities of an attacker in a PUF system. We analyze the best approaches to implement our system and evaluate their performance in terms of the modeling capacity that a passive attacker exhibits. Our experiments show that the proposed approach can increase the training data required for a successful modeling attack over one million samples, without increasing the security overhead of resource-constrained PUF-enabled IoT devices. Mieszko Ferens, Edlira Dushku, Shreyas Srinivasa, Sokol Kosta |
ACSAC | 3 |
| 2022 | Interaction matters: a comprehensive analysis and a dataset of hybrid IoT/OT honeypotsabstractThe Internet of things (IoT) and critical infrastructure utilizing operational technology (OT) protocols are nowadays a common attack target and/or attack surface used to further propagate malicious actions. Deception techniques such as honeypots have been proposed for both IoT and OT but they either lack an extensive evaluation or are subject to fingerprinting attacks. In this paper, we extend and evaluate RIoTPot, a hybrid-interaction honeypot, by exposing it to attacks on the Internet and perform a longitudinal study with multiple evaluation parameters for three months. Furthermore, we publish the aforementioned study in the form of a dataset that is available to researchers upon request. We leverage RIoTPot’s hybrid-interaction model to deploy it in three interaction variants with six protocols deployed on both cloud and self-hosted infrastructure to study and compare the attacks gathered. At a glance, we receive 10.87 million attack events originating from 22,518 unique IP addresses that involve brute-force, poisoning, multistage and other attacks. Moreover, we fingerprint the attacker IP addresses to identify the type of devices who participate in the attacks. Lastly, our results indicate that the honeypot interaction levels have an important role in attracting specific attacks and scanning probes. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
ACSAC | 1 |
| 2021 | Open for hire: attack trends and misconfiguration pitfalls of IoT devicesabstractMirai and its variants have demonstrated the ease and devastating effects of exploiting vulnerable Internet of Things (IoT) devices. In many cases, the exploitation vector is not sophisticated; rather, adversaries exploit misconfigured devices (e.g. unauthenticated protocol settings or weak/default passwords). Our work aims at unveiling the state of IoT devices along with an exploration of the current attack landscape. In this paper, we perform an Internet-level IPv4 scan to unveil 1.8 million misconfigured IoT devices that may be exploited to perform large-scale attacks. These results are filtered to exclude a total of 8,192 devices that we identify as honeypots during our scan. To study current attack trends, we deploy six state-of-art IoT honeypots for a period of 1 month. We gather a total of 200, 209 attacks and investigate how adversaries leverage misconfigured IoT devices. In particular, we study different attack types, including denial of service, multistage attacks and attacks from infected online hosts. Furthermore, we analyze data from a /8 network telescope covering a total of 81 billion requests towards IoT protocols (e.g. CoAP, UPnP). Combining knowledge from the aforementioned experiments, we identify 11, 118 IP addresses (that are part of the detected misconfigured IoT devices) that attacked our honeypot setup and the network telescope. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
Internet Measurement Conference | 1 |
| 2020 | Towards systematic honeytoken fingerprintingabstractWith the continuous rise in the numbers and sophistication of cyber-attacks, defenders are moving towards more proactive lines of defense. Deception methods such as honeypots and moving target defense paradigms, are nowadays utilized in a multitude of ways. A honeytoken is an umbrella term that describes honeypot-like entities/resources that can be inserted into a network or system. The moment an adversary interacts with a honeytoken, an alert is raised. Similar to honeypots, the value of honeytokens lies in their indistinguishability; if an attacker can detect them, e.g. via a fingerprinting tool, they can easily evade them. In this paper, we propose and discuss honeytoken fingerprinting methods. To the best of our knowledge, this is the first paper to examine honeytoken-specific fingerprinting. Furthermore, we showcase a proof of concept that is able to successfully detect a number of honeytoken types. Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis |
SIN | 1 |
| 2016 | Multi-stage attack detection and signature generation with ICS honeypotsabstractNew attack surfaces are emerging with the rise of Industrial Control System (ICS) devices exposed on the Internet. ICS devices must be protected in a holistic and efficient manner; especially when these are supporting critical infrastructure. Taking this issue into account, cyber-security research is recently being focused on providing early detection and warning mechanisms for ICSs. In this paper we present a novel honeypot capable of detecting multi-stage attacks targeting ICS networks. Upon detecting a multi-stage attack, our honeypot can generate signatures so that misuse Intrusion Detection Systems (IDSs) can subsequently thwart attacks of the same type. Our experimental results indicate that our honeypot and the signatures it generates provide good detection accuracy and that the Bro IDS can successfully use the signatures to prevent future attacks. Emmanouil Vasilomanolakis, Shreyas Srinivasa, Carlos Garcia Cordero, Max Mühlhäuser |
NOMS | 2 |