Paolo Gasti

dblp:19/5268 · DBLP profile ↗
← Back
40ranked-venue papers
7as first author
1since 2021 · last 2024
0000-0001-7810-3614ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 3 first-authorComputer networks · 6 · 1 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 since 2021Artificial intelligence and machine learning · 2Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
9 papers
Biometric security · 25% Cryptographic protocols and secure computation · 21% Authentication and access control · 19%
Computer networks
2 papers
Internet architecture and protocols · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Embedded and real-time systems · 75% Cloud and datacenter computing · 25%
Human-computer interaction and pervasive computing
2 papers
Ubiquitous computing and smart environments · 72% Wearable and physiological sensing · 28%

Topics — the 26 heaviest of 27, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
continuous authentication
0.842016
HMOG: New Behavioral Biometric Features for Continuous Authentication of Smartphone Users · IEEE Trans. Inf. Forensics Secur. 2016
Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones · IEEE Trans. Inf. Forensics Secur. 2016
A multimodal data set for evaluating continuous authentication performance in smartphones · SenSys 2014
Internet architecture and protocols
information-centric networking
0.422019
Privacy-Aware Caching in Information-Centric Networking · IEEE Trans. Dependable Secur. Comput. 2019
ANDaNA: Anonymous Named Data Networking Application · NDSS 2012
Internet architecture and protocols › information-centric networking
in-network caching
0.412019
Privacy-Aware Caching in Information-Centric Networking · IEEE Trans. Dependable Secur. Comput. 2019
Cryptographic protocols and secure computation
garbled circuits
0.412019
MEG: Memory and Energy Efficient Garbled Circuit Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2019
Hardware security and side channels › side-channel attack
timing side channel
0.412019
Privacy-Aware Caching in Information-Centric Networking · IEEE Trans. Dependable Secur. Comput. 2019
Network security › traffic analysis
browsing behavior inference
0.312017
On Inferring Browsing Activity on Smartphones via USB Power Analysis Side-Channel · IEEE Trans. Inf. Forensics Secur. 2017
Hardware security and side channels › side-channel attack
power analysis
0.312017
On Inferring Browsing Activity on Smartphones via USB Power Analysis Side-Channel · IEEE Trans. Inf. Forensics Secur. 2017
Network security
anonymity networks
0.322019
ANDaNA: Anonymous Named Data Networking Application · NDSS 2012
Privacy-Aware Caching in Information-Centric Networking · IEEE Trans. Dependable Secur. Comput. 2019
Biometric security
behavioral biometrics
0.212016
HMOG: New Behavioral Biometric Features for Continuous Authentication of Smartphone Users · IEEE Trans. Inf. Forensics Secur. 2016
Biometric security › biometric authentication
behavioral biometric authentication
0.212016
Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones · IEEE Trans. Inf. Forensics Secur. 2016
Biometric security › biometric template protection
biometric key generation
0.212016
HMOG: New Behavioral Biometric Features for Continuous Authentication of Smartphone Users · IEEE Trans. Inf. Forensics Secur. 2016
Privacy and data protection
privacy-preserving computation
0.212016
Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones · IEEE Trans. Inf. Forensics Secur. 2016
Cryptographic protocols and secure computation
secure outsourcing
0.212016
Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones · IEEE Trans. Inf. Forensics Secur. 2016
Biometric security
biometric authentication
0.212015
Secure Outsourced Biometric Authentication With Performance Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2015
Cryptographic protocols and secure computation › malicious security
malicious client security
0.212015
Secure Outsourced Biometric Authentication With Performance Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2015
Biometric security › biometric authentication
privacy-preserving biometric authentication
0.212015
Secure Outsourced Biometric Authentication With Performance Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2015
Ubiquitous computing and smart environments › mobile sensing
smartphone sensing
0.212014
A multimodal data set for evaluating continuous authentication performance in smartphones · SenSys 2014
Privacy and data protection › health data privacy
genomic privacy
0.112011
Countering GATTACA: efficient and secure testing of fully-sequenced human genomes · CCS 2011
Cryptographic protocols and secure computation › secure multiparty computation
private set operations
0.112011
Countering GATTACA: efficient and secure testing of fully-sequenced human genomes · CCS 2011
Embedded and real-time systems
mobile computing
0.112019
MEG: Memory and Energy Efficient Garbled Circuit Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2019
Embedded and real-time systems › mobile devices
smartphones
0.112019
MEG: Memory and Energy Efficient Garbled Circuit Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2019
Privacy and data protection › mobile privacy
smartphone privacy
0.112017
On Inferring Browsing Activity on Smartphones via USB Power Analysis Side-Channel · IEEE Trans. Inf. Forensics Secur. 2017
Cloud and datacenter computing
secure outsourcing
0.112016
Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones · IEEE Trans. Inf. Forensics Secur. 2016
Authentication and access control › mobile authentication
smartphone authentication
0.112015
Secure Outsourced Biometric Authentication With Performance Evaluation on Smartphones · IEEE Trans. Inf. Forensics Secur. 2015
Authentication and access control
mobile authentication
0.112014
A multimodal data set for evaluating continuous authentication performance in smartphones · SenSys 2014
Medical and health informatics
genomic medicine
0.012011
Countering GATTACA: efficient and secure testing of fully-sequenced human genomes · CCS 2011

Methods — techniques the papers use, named apart from their topics

timing side channel · 0.8countermeasures · 0.8batch data transmission · 0.8manhattan distance · 0.5hamming distance · 0.5accelerometer · 0.5multithreading · 0.4multi-threading · 0.4webpage identification · 0.3power trace analysis · 0.3privacy-preserving protocols · 0.2privacy-preserving protocol · 0.2magnetometer · 0.2gyroscope · 0.2feature extraction · 0.2multimodal sensing · 0.2behavioral biometrics · 0.2private set intersection · 0.1
YearPublicationVenuePosition
2024 SMARTCOPE: Smartphone Change Of Possession Evaluation for continuous authentication
Nicholas Cariello, Seth Levine, Blair Hoplight, Paolo Gasti, Kiran S. Balagani
Pervasive Mob. Comput.5
2020 Your PIN Sounds Good! Augmentation of PIN Guessing Strategies via Audio Leakage
Matteo Cardaioli, Mauro Conti, Kiran S. Balagani, Paolo Gasti
ESORICS (1)4
2020 DISPERSE: A Decentralized Architecture for Content Replication Resilient to Node Failures
abstract
This paper introduces DISPERSE, a distributed scalable architecture for delivery of content and services that provides resilience against node failure through location-independent storage and replication of content. Current content delivery networks (CDNs) have, at least to some degree, a centralized structure thus susceptible to a single point of failure. DISPERSE addresses this limitation by implementing a fully de-centralized structure. DISPERSE is a two-layer architecture: the first layer (front-end layer) exposes services (e.g., Web, SFTP) to clients; the second layer (back-end layer) provides reliable distributed storage of content and application state. Content in DISPERSE's back-end layer is stored and exchanged as Named Data Network (NDN) content objects. This allows DISPERSE to implement fine-grained, location-independent, fully decentralized content replication mechanisms. We validate the performance of DISPERSE under two node failure scenarios. In the first scenario, content can be stored in any DISPERSE node, and all nodes are equally likely to fail. In this scenario, we use non-linear optimization techniques to determine the optimal number of content copies under availability and latency constraints. In the second scenario, different nodes fail with different probabilities, and content is stored in nodes according to its value, node failure probability, and resource availability. This scenario is addressed as an instance of the minimum cost flow problem. Our results show that DISPERSE reduces the failure of content retrieval by five orders of magnitude compared to common CDN implementations, without significantly increasing content retrieval delay. Further, numerical results show that DISPERSE improves content availability by a factor of 1.3× - 2.3× when deploying the minimum cost flow algorithm.
Santhanakrishnan Anand, Ding Ding 0004, Paolo Gasti, Mike O'Neal, Mauro Conti, Kiran S. Balagani
IEEE Trans. Netw. Serv. Manag.3
2019 PassGAN: A Deep Learning Approach for Password Guessing
Briland Hitaj, Paolo Gasti, Giuseppe Ateniese, Fernando Pérez-Cruz
ACNS2
2019 PILOT: Password and PIN information leakage from obfuscated typing videos
abstract
This paper studies leakage of user passwords and PINs based on observations of typing feedback on screens or from projectors in the form of masked characters (∗ or ∙) that indicate keystrokes. To this end, we developed an attack called Password and Pin Information Leakage from Obfuscated Typing Videos ( PILOT ). Our attack extracts inter-keystroke timing information from videos of password masking characters displayed when users type their password on a computer, or their PIN at an ATM. We conducted several experiments in various attack scenarios. Results indicate that, while in some cases leakage is minor, it is quite substantial in others. By leveraging inter-keystroke timings, PILOT recovers 8-character alphanumeric passwords in as little as 19 attempts. When guessing PINs, PILOT significantly improved on both random guessing and the attack strategy adopted in our prior work (In European Symposium on Research in Computer Security ( 2018 ) 263–280 Springer). In particular, we were able to guess about 3% of the PINs within 10 attempts. This corresponds to a 26-fold improvement compared to random guessing. Our results strongly indicate that secure password masking GUIs must consider the information leakage identified in this paper.
Kiran S. Balagani, Matteo Cardaioli, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
J. Comput. Secur.4
2019 Privacy-Aware Caching in Information-Centric Networking
abstract
Information-Centric Networking (ICN) is an emerging networking paradigm where named and routable data (content) is the focal point. Users send explicit requests (interests) which specify content by name, and the network handles routing these interests to some entity capable of satisfying them with the appropriate data response (producer). One key feature of ICN is opportunistic in-network content caching. This property facilitates efficient content distribution by reducing bandwidth consumption, lessening network congestion, and improving the content retrieval latency by users (consumers). Unfortunately, the same feature is also detrimental to privacy of content consumers and producers. Simple to implement, and difficult to detect, timing attacks can exploit ICN routers as “oracles” and allow an adversary to learn whether a nearby consumer recently requested certain content. The attack leverages a timing side channel that relies on router caches and is implemented by requesting a few packets from each piece of content being probed. Similarly, probing attacks that target content producers can be used to discover whether certain content has been recently distributed. After analyzing the scope and feasibility of such attacks, we propose and evaluate some efficient countermeasures that offer quantifiable privacy guarantees while retaining the benefits of ICN.
Gergely Ács, Mauro Conti, Paolo Gasti, Cesar Ghali, Gene Tsudik, Christopher A. Wood
IEEE Trans. Dependable Secur. Comput.3
2019 MEG: Memory and Energy Efficient Garbled Circuit Evaluation on Smartphones
abstract
Garbled circuits are general tools that allow two parties to compute any function without disclosing their respective inputs. Applications of this technique vary from distributed privacy-preserving machine learning tasks to secure outsourced authentication. Unfortunately, the energy cost of garbled circuit evaluation protocols is substantial. This limits the applicability of garbled circuits in scenarios that involve battery-operated devices, such as Internet-of-Things (IoT) devices and smartphones. In this paper, we propose MEG, a Memory- and Energy-efficient Garbled circuit evaluation mechanism. MEG utilizes batch data transmission and multi-threading to reduce memory and energy consumption. We implement MEG on an Android smartphone and compare its performance and energy consumption with state-of-the-art techniques using two garbled circuits of widely different sizes (AES-128 and 256-bit edit distance). Our results show that, compared with “plain” garbled circuit evaluation, MEG decreases memory consumption by more than 90%. When compared with current pipelined garbled circuit evaluation techniques, MEG's energy usage was 42% lower for AES-128 and 23% lower for EDT-256. Furthermore, our multi-thread implementation of MEG decreased circuit evaluation time by up to 56.7% for AES-128, and by up to 13.5% for EDT-256, compared with state-of-the-art pipelining techniques.
Qing Yang 0005, Ge Peng, Paolo Gasti, Kiran S. Balagani, Yantao Li 0001, Gang Zhou 0002
IEEE Trans. Inf. Forensics Secur.3
2018 SILK-TV: Secret Information Leakage from Keystroke Timing Videos
Kiran S. Balagani, Mauro Conti, Paolo Gasti, Martin Georgiev, Tristan Gurtler, Daniele Lain, Charissa Miller, Kendall Molas, Nikita Samarin, Eugen Saraci, Gene Tsudik, Lynn Wu
ESORICS (1)3
2018 Content-Centric and Named-Data Networking Security: The Good, The Bad and The Rest
abstract
Named Data Networking and Content-Centric Networking (NDN and CCN, respectively) are closely related networking architectures which, unlike host-centric IP, emphasize content by explicitly naming it, and by making content names addressable and routable in the network. They support in-network (router-side) content caching, thus facilitating efficient and scalable content distribution, for which IP is comparatively poorly suited. These architectures also include new network-layer security features, such as signed content. While avoiding certain security problems of today's Internet, NDN and CCN trigger some new security and privacy issues. This paper overviews the security landscape of NDN/CCN, and focuses on two main areas of concern: (1) Interest Flooding Attacks, and (2)Producer, Consumer, and Content Privacy. We argue that, despite many attempts to fix these problems, they have not been fully addressed, and discuss the challenges that inhibit comprehensive solutions.
Paolo Gasti, Gene Tsudik
LANMAN1
2018 Weak and Strong Deniable Authenticated Encryption: On their Relationship and Applications
abstract
Consider a scenario in which a whistleblower (Alice) would like to disclose confidential documents to ajournalist (Bob). Bob wants to verify that the messages he receives are really from Alice; at the same time, Alice does not want to be implicated if Bob is later compelled to (or decides to) disclose her messages, together with his secret key and any other relevant secret information. To fulfill these requirements, Alice and Bob can use a deniable authenticated encryption scheme. In this paper we formalize the notions of strong- and weak deniable authentication, and discuss the relationship between these definitions. We show that Bob can still securely authenticate messages from Alice after all his secret information is revealed to the adversary, but only when using a weakly (but not strongly) deniable scheme. We refer to this ability as post-compromise message authentication. We present two efficient encryption schemes that provide deniable authentication. Both schemes incur overhead similar to that of non-deniable schemes. As such, they are suitable not only when deniability is needed, but also as general encryption tools. We provide details of the encryption, decryption, forgery and key- generation algorithms, and formally prove that our schemes are secure with respect to confidentiality, data authentication, and strong- and weak deniable authentication.
Kasper Bonne Rasmussen, Paolo Gasti
PST2
2018 USB side-channel attack on Tor
Qing Yang 0005, Paolo Gasti, Kiran S. Balagani, Yantao Li 0001, Gang Zhou 0002
Comput. Networks2
2018 The impact of application context on privacy and performance of keystroke authentication systems
abstract
In this paper, we show that keystroke latencies used in continuous user authentication systems disclose application context, i.e., in which application user is entering text. Using keystroke data collected from 62 subjects, we show that an adversary can infer application context from keystroke latencies with 95.15% accuracy. To prevent leakage from keystroke latencies, and prevent exposure of application context, we develop privacy-preserving authentication protocols in the outsourced authentication model. Our protocols implement two popular matching algorithms designed for keystroke authentication, called Absolute (“A”) and Relative (“R”). With our protocols, the client reveals no information to the server during authentication, besides the authentication result. Our experiments show that these protocols are fast in practice: with 100 keystroke features, authentication was completed in about one second with the “A” protocol, and in 595 ms with the “R” protocol. Further, because the asymptotic cost of our protocols is linear, they can scale to a large number of features. On the other hand, by leveraging application context we were able to reduce HTER from 14.7% with application-agnostic templates, to as low as 5.8% with application-specific templates.
Kiran S. Balagani, Paolo Gasti, Aaron Elliott, Azriel Richardson, Mike O'Neal
J. Comput. Secur.2
2017 On Inferring Browsing Activity on Smartphones via USB Power Analysis Side-Channel
abstract
In this paper, we show that public USB charging stations pose a significant privacy risk to smartphone users even when no data communication is possible between the station and the user's mobile device. We present a side-channel attack that allows a charging station to identify which Webpages are loaded while the smartphone is charging. To evaluate this side-channel, we collected power traces of Alexa top 50 Websites on multiple smartphones under several conditions, including battery charging level, browser cache enabled/disabled, taps on the screen, Wi-Fi/LTE, TLS encryption enabled/disabled, time elapsed between collection of training and testing data, and location of the Website. The results of our evaluation show that the attack is highly successful: in many settings, we were able to achieve over 90% Webpage identification accuracy. On the other hand, our experiments also show that this side-channel is sensitive to some of the aforementioned conditions. For instance, when training and testing traces were collected 70 days apart, accuracies were as low as 2.2%. Although there are studies that show that power-based side-channels can predict browsing activity on laptops, this paper is unique, because it is the first to study this side-channel on smartphones, under smartphone specific constraints. Further, we demonstrate that Websites can be correctly identified within a short time span of 2 × 6 seconds, which is in contrast with prior work, which uses 15-s traces. This is important, because users typically spend less than 15 s on a Webpage.
Qing Yang 0005, Paolo Gasti, Gang Zhou 0002, Aydin Farajidavar, Kiran S. Balagani
IEEE Trans. Inf. Forensics Secur.2
2016 FLEX: A Flexible Code Authentication Framework for Delegating Mobile App Customization
abstract
Mobile code distribution relies on digital signatures to guarantee code authenticity. Unfortunately, standard signature schemes are not well suited for use in conjunction with program transformation techniques, such as aspect-oriented programming. With these techniques, code development is performed in sequence by multiple teams of programmers. This is fundamentally different from traditional single-developer/ single-user models, where users can verify end-to-end (i.e., developer-to-user) authenticity of the code using digital signatures. To address this limitation, we introduce FLEX, a flexible code authentication framework for mobile applications. FLEX allows semi-trusted intermediaries to modify mobile code without invalidating the developer's signature, as long as the modification complies with a "contract" issued by the developer. We introduce formal definitions for secure code modification, and show that our instantiation of FLEX is secure under these definitions. Although FLEX can be instantiated using any language, we design AMJ--a novel programming language that supports code annotations--and implement a FLEX prototype based on our new language.
Gabriele Costa 0001, Paolo Gasti, Alessio Merlo, Shunt-Hsi Yu
AsiaCCS2
2016 Secure, Fast, and Energy-Efficient Outsourced Authentication for Smartphones
abstract
Common smartphone authentication mechanisms (e.g., PINs, graphical passwords, and fingerprint scans) are not designed to offer security post-login. Multi-modal continuous authentication addresses this issue by frequently and unobtrusively authenticating the user via behavioral biometric signals, such as touchscreen interaction and hand movements. Because smartphones can easily fall into the hands of the adversary, it is critical that the behavioral biometric information collected and processed on these devices is secured. This can be done by offloading encrypted template information to a remote server, and then performing authentication via privacy-preserving protocols. In this paper, we demonstrate that the energy overhead of current privacy-preserving protocols for continuous authentication is unsustainable on smartphones. To reduce energy consumption, we design a technique that leverages characteristics unique to the authentication setting in order to securely outsource computation to an untrusted Cloud. Our approach is secure against a colluding smartphone and Cloud, thus making it well suited for authentication. We performed extensive experimental evaluation. With our technique, the energy requirement for running an authentication instance that computes Manhattan distance is 0.2 mWh, which corresponds to a negligible fraction of the smartphone's battery capacity. In addition, for Manhattan distance, our protocol runs in 0.72 and 2 s for 8 and 28 biometric features, respectively. We were also able to compute Hamming distance in 3.29 s, compared with 95.57 s achieved with the previous fastest outsourced computation protocol (Whitewash). These results demonstrate that ours is presently the only technique suitable for low-latency continuous authentication (e.g., with authentication scan windows of 60 s or shorter).
Paolo Gasti, Jaroslav Sedenka, Qing Yang 0005, Gang Zhou 0002, Kiran S. Balagani
IEEE Trans. Inf. Forensics Secur.1
2016 HMOG: New Behavioral Biometric Features for Continuous Authentication of Smartphone Users
abstract
We introduce hand movement, orientation, and grasp (HMOG), a set of behavioral features to continuously authenticate smartphone users. HMOG features unobtrusively capture subtle micro-movement and orientation dynamics resulting from how a user grasps, holds, and taps on the smartphone. We evaluated authentication and biometric key generation (BKG) performance of HMOG features on data collected from 100 subjects typing on a virtual keyboard. Data were collected under two conditions: 1) sitting and 2) walking. We achieved authentication equal error rates (EERs) as low as 7.16% (walking) and 10.05% (sitting) when we combined HMOG, tap, and keystroke features. We performed experiments to investigate why HMOG features perform well during walking. Our results suggest that this is due to the ability of HMOG features to capture distinctive body movements caused by walking, in addition to the hand-movement dynamics from taps. With BKG, we achieved the EERs of 15.1% using HMOG combined with taps. In comparison, BKG using tap, key hold, and swipe features had EERs between 25.7% and 34.2%. We also analyzed the energy consumption of HMOG feature extraction and computation. Our analysis shows that HMOG features extracted at a 16-Hz sensor sampling rate incurred a minor overhead of 7.9% without sacrificing authentication accuracy. Two points distinguish our work from current literature: 1) we present the results of a comprehensive evaluation of three types of features (HMOG, keystroke, and tap) and their combinations under the same experimental conditions and 2) we analyze the features from three perspectives (authentication, BKG, and energy consumption on smartphones).
Zdenka Sitova, Jaroslav Sedenka, Qing Yang 0005, Ge Peng, Gang Zhou 0002, Paolo Gasti, Kiran S. Balagani
IEEE Trans. Inf. Forensics Secur.6
2015 Violating Consumer Anonymity: Geo-Locating Nodes in Named Data Networking
Alberto Compagno, Mauro Conti, Paolo Gasti, Luigi V. Mancini, Gene Tsudik
ACNS3
2015 Secure Outsourced Biometric Authentication With Performance Evaluation on Smartphones
abstract
We design privacy-preserving protocols for scaled Manhattan and scaled Euclidean verifiers, secure against malicious clients and honest-but-curious server. We then augment our protocols with principal component analysis (PCA), which can help to improve authentication accuracy. We evaluate the performance of our protocols on an emerging application-namely, continuous authentication of smartphone users. We compare the performance of protocols secure under the malicious client model, with three protocols secure in the honest-but-curious model. We report tradeoffs between computation overhead, communication cost, and authentication accuracy. Our key observations are: 1) scaled Manhattan without PCA gives the best tradeoff between security, accuracy, and overhead and 2) with PCA, memory availability on current smartphones limits the number of features that can be used with scaled Manhattan, and prevents the scaled Euclidean protocol from running. Our extended evaluation on a laptop client shows that PCA with both scaled Manhattan and scaled Euclidean verifiers is feasible given sufficient memory.
Jaroslav Sedenka, Sathya Govindarajan, Paolo Gasti, Kiran S. Balagani
IEEE Trans. Inf. Forensics Secur.3
2014 Covert ephemeral communication in named data networking
abstract
In recent years, the growing belief that the current IP-based Internet is becoming obsolete prompted several research efforts that aim to design potential next-generation Internet architectures. Named Data Networking (NDN), an instantiation of the content-centric approach, is one such effort. In contrast with their IP counterparts, NDN routers maintain a significant amount of state information. In this paper, we investigate the use of this feature for covert ephemeral communication (CEC). CEC allows two or more parties to covertly exchange ephemeral messages, i.e., messages that become unavailable after a certain amount of time. Our techniques rely only on network-layer services. This makes our protocols robust, and stealthy communication -- difficult to detect. We show that users can build high-bandwidth CEC channels by exploiting features unique to NDN: in-network caches, routers' forwarding state and name matching rules. We assess feasibility and performance of identified CEC channels using a local setup and the official NDN testbed.
Moreno Ambrosin, Mauro Conti, Paolo Gasti, Gene Tsudik
AsiaCCS3
2014 Privacy-preserving distance computation and proximity testing on earth, done right
abstract
In recent years, the availability of GPS-enabled smartphones have made location-based services extremely popular. A multitude of applications rely on location information to provide a wide range of services. Location information is, however, extremely sensitive and can be easily abused. In this paper, we introduce the first protocols for secure computation of distance and for proximity testing over a sphere. Our secure distance protocols allow two parties, Alice and Bob, to determine their mutual distance without disclosing any additional information about their location. Through our secure proximity testing protocols, Alice only learns if Bob is in close proximity, i.e., within some arbitrary distance. An important difference between our protocols and existing techniques is that our protocols are the first not to require parties to privately negotiate a common map. Our protocols rely on three different representations of Earth, which provide different trade-offs between accuracy and performance. We show, via experiments on a prototype implementation, that our protocols are practical on resource-constrained smartphone devices. Our distance computation protocols runs in 54 to 78 ms on a commodity Android smartphone. Similarly, our proximity tests require between 1.2 s and 2.8 s on the same platform. The imprecision introduced by our protocols is very small, i.e., between 0.1% and 2% on average, depending on the distance.
Jaroslav Sedenka, Paolo Gasti
AsiaCCS2
2014 Continuous authentication with cognition-centric text production and revision features
abstract
Most continuous user authentication techniques based on typing behavior rely on the keystroke dynamics or on the linguistic style of the user. However, there is a rich spectrum of cognition-centric behavioral traits that a typist exhibits during different stages of text production (e.g., composition, translation, and revision), which to our knowledge, have not been considered for continuous authentication. We study the continuous authentication performance of 123 behavioral traits extracted from discrete cognitive units called bursts. We performed experiments on typing data collected from 486 volunteer subjects. Our findings include: (1) features from bursts delimited by pause events have significantly higher availability and authentication performance compared to bursts delimited by revision events; (2) bursts with pause durations of at least one second provide the best authentication accuracy and availability; and (3) fusing our features with traditional keystroke dynamics features reduced authentication error rates. We achieved an equal error rate between 13.37 and 4.55 percent for authentication windows as low as 30 seconds to 3.5 minutes.
Hilbert Locklear, Sathya Govindarajan, Zdenka Sitova, Adam Goodkind, David Guy Brizan, Andrew Rosenberg, Vir V. Phoha, Paolo Gasti, Kiran S. Balagani
IJCB8
2014 Privacy-preserving population-enhanced biometric key generation from free-text keystroke dynamics
abstract
Biometric key generation techniques are used to reliably generate cryptographic material from biometric signals. Existing constructions require users to perform a particular activity (e.g., type or say a password, or provide a handwritten signature), and are therefore not suitable for generating keys continuously. In this paper we present a new technique for biometric key generation from free-text keystroke dynamics. This is the first technique suitable for continuous key generation. Our approach is based on a scaled parity code for key generation (and subsequent key reconstruction), and can be augmented with the use of population data to improve security and reduce key reconstruction error. In particular, we rely on linear discriminant analysis (LDA) to obtain a better representation of discriminable biometric signals. To update the LDA matrix without disclosing user's biometric information, we design a provably secure privacy-preserving protocol (PP-LDA) based on homomorphic encryption. Our biometric key generation with PP-LDA was evaluated on a dataset of 486 users. We report equal error rate around 5% when using LDA, and below 7% without LDA.
Jaroslav Sedenka, Kiran S. Balagani, Vir V. Phoha, Paolo Gasti
IJCB4
2014 Secure Sensing over Named Data Networking
abstract
The anticipated proliferation of smart devices, the "Internet of Things" (IoT), is one of the motivations for some large-scale research efforts aiming to design a new Internet architecture. One such effort is Named-Data Networking (NDN) - a "future internet architecture" research project in the Information-Centric Networking (ICN) area that emphasizes efficient, scalable and secure data distribution through a shift from the host-based addressing of IP to data-centric addressing. Because of its focus on data distribution, NDN has been assumed to be poorly suited for other networking scenarios. We address efficient and secure sensing over NDN, motivated by the convergence of the IoT vision with traditional Building Automation Systems (BAS). We consider several sensing paradigms and demonstrate the use of NDN to securely interact with NDN-enabled sensors. In the process, we address some challenges caused by sensors' intermittent availability, power constraints and asynchronous communication patterns. Our results include concrete protocols that facilitate secure sensor-bound communication over NDN.
Jeff Burke, Paolo Gasti, Naveen Nathan, Gene Tsudik
NCA2
2014 A multimodal data set for evaluating continuous authentication performance in smartphones
abstract
Continuous authentication modalities allow a device to authenticate users transparently without interrupting them or requiring their attention. This is especially important on smartphones, which are more prone to be lost or stolen than regular computers, and carry plenty of sensitive information. There is a multitude of signals that can be harnessed for continuous authentication on mobile devices, such as touch input, accelerometer, and gyroscope, etc. However, existing public datasets include only a handful of them, limiting the ability to do experiments that involve multiple modalities. To fill this gap, we performed a large-scale user study to collect a wide spectrum of signals on smartphones. Our dataset combines more modalities than existing datasets, including movement, orientation, touch, gestures, and pausality. This dataset has been used to evaluate our new behavioral modality named Hand Movement, Orientation, and Grasp (H-MOG). This poster reports on the data collection process and outcomes, as well as preliminary authentication results.
Qing Yang 0005, Ge Peng, David T. Nguyen, Xin Qi 0001, Gang Zhou 0002, Zdenka Sitova, Paolo Gasti, Kiran S. Balagani
SenSys7
2014 EsPRESSO: Efficient privacy-preserving evaluation of sample set similarity
abstract
Electronic information is increasingly often shared among entities without complete mutual trust. To address related security and privacy issues, a few cryptographic techniques have emerged that support privacy-preserving information sharing and retrieval. One interesting open problem in this context involves two parties that need to assess the similarity of their datasets, but are reluctant to disclose their actual content. This paper presents an efficient and provably-secure construction supporting the privacy-preserving evaluation of sample set similarity, where similarity is measured as the Jaccard index. We present two protocols: the first securely computes the (Jaccard) similarity of two sets, and the second approximates it, using MinHash techniques, with lower complexities. We show that our novel protocols are attractive in many compelling applications, including document/multimedia similarity, biometric authentication and genetic tests. In the process, we demonstrate that our constructions are appreciably more efficient than prior work.
Carlo Blundo, Emiliano De Cristofaro, Paolo Gasti
J. Comput. Secur.3
2013 Privacy-Preserving Matching of Community-Contributed Content
Mishari Al Mishari, Paolo Gasti, Gene Tsudik, Ekin Oguz
ESORICS2
2013 DoS and DDoS in Named Data Networking
abstract
With the growing realization that current Internet protocols are reaching the limits of their senescence, several on-going research efforts aim to design potential next-generation Internet architectures. Although they vary in maturity and scope, in order to avoid past pitfalls, these efforts seek to treat security and privacy as fundamental requirements. Resilience to Denial-of-Service (DoS) attacks that plague today's Internet is a major issue for any new architecture and deserves full attention. In this paper, we focus on DoS in Named Data Networking (NDN) -- a specific candidate for next-generation Internet architecture designs. By naming data instead of its locations, NDN transforms data into a first-class entity and makes itself an attractive and viable approach to meet the needs for many current and emerging applications. It also incorporates some basic security features that mitigate classes of attacks that are commonly seen today. However, NDN's resilience to DoS attacks has not been analyzed to-date. This paper represents a first step towards assessment and possible mitigation of DoS in NDN. After identifying and analyzing several new types of attacks, it investigates their variations, effects and counter-measures. This paper also sheds some light on the debate about relative virtues of self-certifying, as opposed to human-readable, names in the context of content-centric networking.
Paolo Gasti, Gene Tsudik, Ersin Uzun, Lixia Zhang 0001
ICCCN1
2013 Cache Privacy in Named-Data Networking
abstract
Content-Centric Networking (CCN) is an alternative to host-centric networking exemplified by today's Internet. CCN emphasizes content distribution by making content directly addressable. Named-Data Networking (NDN) is an example of CCN being considered as a candidate next-generation Internet architecture. One key NDN feature is router-side content caching that optimizes bandwidth consumption, reduces congestion and provides fast fetching for popular content. Unfortunately, the same feature is also detrimental to privacy of both consumers and producers of content. As we show in this paper, simple and difficult-to-detect timing attacks can exploit NDN routers as "oracles" and allow the adversary to learn whether a nearby consumer recently requested certain content. Similarly, probing attacks that target adjacent content producers can be used to discover whether certain content has been recently fetched. After analyzing the scope and feasibility of such attacks, we propose and evaluate some efficient countermeasures that offer quantifiable privacy guarantees while retaining key features of NDN.
Gergely Ács, Mauro Conti, Paolo Gasti, Cesar Ghali, Gene Tsudik
ICDCS3
2013 Poseidon: Mitigating interest flooding DDoS attacks in Named Data Networking
abstract
Content-Centric Networking (CCN) is an emerging networking paradigm being considered as a possible replacement for the current IP-based host-centric Internet infrastructure. CCN focuses on content distribution, which is arguably not well served by IP. Named-Data Networking (NDN) is an example of CCN. NDN is also an active research project under the NSF Future Internet Architectures (FIA) program. FIA emphasizes security and privacy from the outset and by design. To be a viable Internet architecture, NDN must be resilient against current and emerging threats. This paper focuses on distributed denial-of-service (DDoS) attacks; in particular we address interest flooding, an attack that exploits key architectural features of NDN. We show that an adversary with limited resources can implement such attack, having a significant impact on network performance. We then introduce Poseidon: a framework for detecting and mitigating interest flooding attacks. Finally, we report on results of extensive simulations assessing proposed countermeasure.
Alberto Compagno, Mauro Conti, Paolo Gasti, Gene Tsudik
LCN3
2013 A lightweight mechanism for detection of cache pollution attacks in Named Data Networking
Mauro Conti, Paolo Gasti, Marco Teoli
Comput. Networks2
2012 Fast and Private Computation of Cardinality of Set Intersection and Union
Emiliano De Cristofaro, Paolo Gasti, Gene Tsudik
CANS2
2012 On the Security of Password Manager Database Formats
Paolo Gasti, Kasper Bonne Rasmussen
ESORICS1
2012 ANDaNA: Anonymous Named Data Networking Application
Steve DiBenedetto, Paolo Gasti, Gene Tsudik, Ersin Uzun
NDSS2
2011 Countering GATTACA: efficient and secure testing of fully-sequenced human genomes
abstract
Recent advances in DNA sequencing technologies have put ubiquitous availability of fully sequenced human genomes within reach. It is no longer hard to imagine the day when everyone will have the means to obtain and store one's own DNA sequence. Widespread and affordable availability of fully sequenced genomes immediately opens up important opportunities in a number of health-related fields. In particular, common genomic applications and tests performed in vitro today will soon be conducted computationally, using digitized genomes. New applications will be developed as genome-enabled medicine becomes increasingly preventive and personalized. However, this progress also prompts significant privacy challenges associated with potential loss, theft, or misuse of genomic data. In this paper, we begin to address genomic privacy by focusing on three important applications: Paternity Tests, Personalized Medicine, and Genetic Compatibility Tests. After carefully analyzing these applications and their privacy requirements, we propose a set of efficient techniques based on private set operations. This allows us to implement in in silico some operations that are currently performed via in vitro methods, in a secure fashion. Experimental results demonstrate that proposed techniques are both feasible and practical today.
Pierre Baldi, Roberta Baronio, Emiliano De Cristofaro, Paolo Gasti, Gene Tsudik
CCS4
2011 Secure and Efficient Protocols for Iris and Fingerprint Identification
Marina Blanton, Paolo Gasti
ESORICS2
2011 On Re-use of randomness in broadcast encryption
abstract
Broadcast encryption provides an efficient way to encrypt a message for a large number of receivers. This paper investigates whether it is possible to further improve efficiency of an existing state-of-the-art broadcast encryption scheme by reusing a some of the random choices among different encryptions, without compromising the security of the original scheme. We introduce two schemes: the first allows a transmitter to efficiently encrypt several messages to a set of users; the second scheme extends the first by allowing the transmitter to efficiently send independent messages to different groups at once. We illustrate two scenarios where our schemes provide significant advantages compared to existing solutions.
Paolo Gasti, Alessio Merlo
PST1
2010 On the Integrity of Network Coding-Based Anonymous P2P File Sharing Networks
abstract
Network coding is a class of routing algorithms offering increased throughput and improved robustness to random failures. With traditional routing, intermediate nodes in the network may only forward unmodified packets. With network coding, instead, intermediate nodes are allowed to forward linear combinations of received packets. Original data can be reconstructed after collecting sufficiently many linear combinations. Current file sharing systems offer either low overhead and high bandwidth with no privacy, or acceptable privacy at very low speed. Thanks to network coding, a general-purpose P2P network can obtain a privacy/performance tradeoff that may be considered reasonable in most real-world scenarios. In this paper we present an integrity strategy for network coding-based P2P anonymous systems, specifically designed to preserve the anonymity of peers. Our approach is significantly easier to implement than current solutions when anonymity is required. We implement the cryptographic algorithms on which our method is based and provide performance figures. We also define verification strategies which use batching for improved performances together with an efficiency analysis.
Paolo Gasti, Alessio Merlo, Giuseppe Ciaccio, Giovanni Chiola
NCA1
2010 Breaking and Fixing the Self Encryption Scheme for Data Security in Mobile Devices
abstract
Data security is one of the major challenges that prevents the wider acceptance of mobile devices, especially within business and government environments. It is non-trivial to protect private and sensitive data stored in these devices due to the limited resources and computing power, particularly when they fall in the hand of an adversary. Previously Chen and Ku proposed a lightweight data encryption and storage scheme named Self-Encryption (SE) to meet the challenge. However, our recent research revealed that there are critical weaknesses in SE. This paper presents the detailed analysis of the weaknesses of SE scheme and proposes a solution to remove the flaws in SE. Through real-world measurements on top of the iPhone platform, we verified the effectiveness of our proposal.
Paolo Gasti, Yu Chen 0002
PDP1
2009 StemCerts-2: Pairs of X.509 v3 Certificates for Greater Security, Flexibility and Convenience
abstract
We introduce the notion of StemCerts, a digital certificate scheme that allows the user to modify some fields of a digital certificate while keeping it valid. The owner can modify a StemCert in a limited and controlled fashion without interacting with the certification authority which issued it. By modifying her identity, the user can achieve "pseudonymous anonymity" - but the CA can still associate a certificate to its owner - and/or handle temporary or permanent address changes. Modifying the expiry date allows the user to transform her certificate into a set of "one time" certificates, thus alleviating the need for revocation lists. We developed two proof-of-concept implementations for this new scheme. The first one was based on Chameleon hash functions, while the second one was based on the use of two chained, standard X.509 v3 certificates. We also present experimental data collected from the prototype implementations that show how the second prototype can easily be adopted in real environments, possibly exploiting smartcard technology.
Giovanni Chiola, Paolo Gasti
CCNC2
2009 Universally Anonymous IBE Based on the Quadratic Residuosity Assumption
Giuseppe Ateniese, Paolo Gasti
CT-RSA2