VLDB 2026 Research / reviewers in the wild / expert
Bogdan Carbunar
dblp:20/4777
· DBLP profile ↗
74ranked-venue papers
32as first author
12since 2021 · last 2026
0000-0002-4950-9751ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 7 first-author · 7 since 2021Computer networks · 24 · 14 first-author · 1 since 2021Databases, data management, data science and information retrieval · 12 · 4 first-author · 3 since 2021Systems, architecture and hardware · 7 · 6 first-authorHuman-computer interaction and ubiquitous computing · 5 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Source-Level Disengagement: A Usable Security Defense Against Misinformation
Zaid Hakami, Yuzhou Feng, Bogdan Carbunar |
SOUPS | 3 |
| 2026 | IO-X: Detecting and Attributing Content-Duplicating Influence Operations on X (Twitter)
Ashfaq Ali Shafin, Md Nahid Siddique, Bogdan Carbunar |
WWW | 3 |
| 2025 | Duplicating Deceit: Inauthentic Behavior Among Indian Misinformation Duplicators on X/Twitter
Ashfaq Ali Shafin, Bogdan Carbunar |
ASONAM (2) | 2 |
| 2025 | Trilobyte: Plausibly Deniable Communications Through Single Player Games: Data/Toolset PaperabstractPlausibly deniable communication solutions built on services popular in Western countries may invite closer scrutiny into the activities of their users in censored countries. This paper investigates the ability of popular single-player games to provide the medium for plausibly deniable communications. We introduce Trilobyte, a system that hides data in game state generated opportunistically during regular game-playing activities, and shares data-hiding state through accounts on gaming platforms. We show that even in the presence of hypothetical censors that inspect game state, Trilobyte can hide up to 5.3 MB of data in game state saved in a one hour gaming session. We investigate the practicality of Trilobyte through surveys with 285 Chinese gamers, and by renting and purchasing thousands of gaming accounts. We find that most investigated games, including games developed in China, allow users to communicate keywords considered sensitive in China, when compressed, encrypted or hidden in game state or chat channels. Yuzhou Feng, Sandeep Kiran Pinjala, Radu Sion, Bogdan Carbunar |
CODASPY | 4 |
| 2025 | Cooperative Dynamics of Censorship, Misinformation, and Influence Operations: Insights from the Global South and U.SabstractCensorship and the distribution of false information, tools used to manipulate what users see and believe, are seemingly at opposite ends of the information access spectrum. Most previous work has examined them in isolation and within individual countries, leaving gaps in our understanding of how these information manipulation tools interact and reinforce each other across diverse societies. In this paper, we study perceptions about the interplay between censorship, false information, and influence operations, gathered through a mixed-methods study consisting of a survey (n = 384) and semi-structured interviews (n = 30) with participants who have experienced these phenomena across diverse countries in both the Global South and Global North, including Bangladesh, China, Cuba, Iran, Venezuela, and the United States. Our findings reveal perceptions of cooperation across various platforms between distinct entities working together to create information cocoons, within which censorship and false information become imperceptible to those affected. Building on study insights, we propose novel platform-level interventions to enhance transparency and help users navigate information manipulation. In addition, we introduce the concept of plausibly deniable social platforms, enabling censored users to provide credible, benign explanations for their activities, protecting them from surveillance and coercion. Zaid Hakami, Yuzhou Feng, Bogdan Carbunar |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2024 | INVISILINE: Invisible Plausibly-Deniable StorageabstractPlausibly-deniable (PD) storage systems allow users to securely hide data and plausibly deny its presence when challenged by adversaries who coerce them to provide encryption keys and passwords. However, PD systems need specialized software that renders them detectable by suspicious adversaries questioning the very use of a PD system. To address this fundamental problem, we introduce and formally define the notion of plausible invisibility, preventing adversaries from determining whether a PD system was used in the first place. We develop INVISILINE, a plausibly invisible system resilient against multi-snapshot adversaries that can access the device multiple times. To remain invisible, INVISILINE uses a data layout and encoding that is compatible with the Linux dmcrypt disk encryption subsystem, and stores hidden data in the initialization vectors used by dm-crypt to encrypt public data. INVISILINE ensures that any disk changes that result from changes to the hidden data between adversary snapshots, can be plausibly explained using changes to public data resulting from regular use of dm-crypt. In the presence of adversaries, INVISILINE enables users to access all and only the public data using only dm-crypt. INVISILINE can securely and invisibly hide 19GB on a 1TB disk with no impact on public data I/O, and an average of 4.5MB/s throughput for writing hidden data. Sandeep Kiran Pinjala, Bogdan Carbunar, Anrin Chakraborti, Radu Sion |
SP | 2 |
| 2023 | A Study of China's Censorship and Its Evasion Through the Lens of Online Gaming
Yuzhou Feng, Ruyu Zhai, Radu Sion, Bogdan Carbunar |
USENIX Security Symposium | 4 |
| 2023 | Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations
Ruben Recabarren, Bogdan Carbunar, Nestor Hernandez, Ashfaq Ali Shafin |
USENIX Security Symposium | 2 |
| 2022 | SoK: Plausibly Deniable Storage
Chen Chen 0057, Xiao Liang 0014, Bogdan Carbunar, Radu Sion |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | Toward Uncensorable, Anonymous and Private Access Over Satoshi Blockchains
Ruben Recabarren, Bogdan Carbunar |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | RacketStore: measurements of ASO deception in Google play via mobile and app usageabstractOnline app search optimization (ASO) platforms that provide bulk installs and fake reviews for paying app developers in order to fraudulently boost their search rank in app stores, were shown to employ diverse and complex strategies that successfully evade state-of-the-art detection methods. In this paper we introduce RacketStore, a platform to collect data from Android devices of participating ASO providers and regular users, on their interactions with apps which they install from the Google Play Store. We present measurements from a study of 943 installs of RacketStore on 803 unique devices controlled by ASO providers and regular users, that consists of 58,362,249 data snapshots collected from these devices, the 12,341 apps installed on them and their 110,511,637 Google Play reviews. We reveal significant differences between ASO providers and regular users in terms of the number and types of user accounts registered on their devices, the number of apps they review, and the intervals between the installation times of apps and their review times. We leverage these insights to introduce features that model the usage of apps and devices, and show that they can train supervised learning algorithms to detect paid app installs and fake reviews with an F1-measure of 99.72% (AUC above 0.99), and detect devices controlled by ASO providers with an F1-measure of 95.29% (AUC = 0.95). We discuss the costs associated with evading detection by our classifiers and also the potential for app stores to use our approach to detect ASO work with privacy. Nestor Hernandez, Ruben Recabarren, Bogdan Carbunar, Syed Ishtiaque Ahmed |
Internet Measurement Conference | 3 |
| 2021 | Towards De-Anonymization of Google Play Search Rank FraudabstractSearch rank fraud, the fraudulent promotion of products hosted on peer-review sites, is driven by expert workers recruited online, often from crowdsourcing sites. In this paper we introduce thefraud de-anonymizationproblem, that goes beyond fraud detection, to unmask the human masterminds responsible for posting search rank fraud in peer-review sites. We collect and study data from crowdsourced search rank fraud jobs, and survey the capabilities and behaviors of 58 search rank fraud workers recruited from 6 crowdsourcing sites. We collect a gold standard dataset of Google Play user accounts attributed to 23 crowdsourced workers and analyze their fraudulent behaviors in the wild. We proposeDolos, a fraud de-anonymization system that leverages traits and behaviors we extract from our studies, to attribute detected fraud to crowdsourcing site workers, thus to real identities and bank accounts. We introduce MCDense, a min-cut dense component detection algorithm to uncover groups of user accounts controlled bydifferentworkers, and use stylometry and supervised learning to attribute them to crowdsourcing site profiles.Doloscorrectly identified the owners of 95 percent of fraud worker-controlled communities, and uncovered fraud workers who promoted as many as 97.5 percent of fraud apps we collected from Google Play. When evaluated on 13,087 apps (820,760 reviews), which we monitored over more than 6 months,Dolosidentified 1,056 apps with suspicious reviewer groups. We report orthogonal evidence of their fraud, including fraud duplicates and fraud re-posts.Dolossignificantly outperformed adapted dense subgraph detection and loopy belief propagation competitors, on two new coverage scores that measure the quality of detected community partitions. Nestor Hernandez, Bogdan Carbunar, Polo Chau |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2020 | Human Distinguishable Visual Key Fingerprints
Mozhgan Azimpourkivi, Umut Topkara, Bogdan Carbunar |
USENIX Security Symposium | 3 |
| 2019 | The Art and Craft of Fraudulent App Promotion in Google PlayabstractBlack Hat App Search Optimization (ASO) in the form of fake reviews and sockpuppet accounts, is prevalent in peer-opinion sites, e.g., app stores, with negative implications on the digital and real lives of their users. To detect and filter fraud, a growing body of research has provided insights into various aspects of fraud posting activities, and made assumptions about the working procedures of the fraudsters from online data. However, such assumptions often lack empirical evidence from the actual fraud perpetrators. To address this problem, in this paper, we present results of both a qualitative study with 18 ASO workers we recruited from 5 freelancing sites, concerning activities they performed on Google Play, and a quantitative investigation with fraud-related data collected from other 39 ASO workers. We reveal findings concerning various aspects of ASO worker capabilities and behaviors, including novel insights into their working patterns, and supporting evidence for several existing assumptions. Further, we found and report participant-revealed techniques to bypass Google-imposed verifications, concrete strategies to avoid detection, and even strategies that leverage fraud detection to enhance fraud efficacy. We report a Google site vulnerability that enabled us to infer the mobile device models used to post more than 198 million reviews in Google Play, including 9,942 fake reviews. We discuss the deeper implications of our findings, including their potential use to develop the next generation fraud detection and prevention systems. Nestor Hernandez, Ruben Recabarren, Syed Ishtiaque Ahmed, Bogdan Carbunar |
CCS | 5 |
| 2019 | Tithonus: A Bitcoin Based Censorship Resilient SystemabstractAbstract Providing reliable and surreptitious communications is difficult in the presence of adaptive and resourceful state level censors. In this paper we introduce Tithonus, a framework that builds on the Bitcoin blockchain and network to provide censorship-resistant communication mechanisms. In contrast to previous approaches, we do not rely solely on the slow and expensive blockchain consensus mechanism but instead fully exploit Bitcoin’s peer-to-peer gossip protocol. We develop adaptive, fast and cost effective data communication solutions that camouflage client requests into inconspicuous Bitcoin transactions. We propose solutions to securely request and transfer content, with unobservability and censorship resistance, and free, pay-per-access and subscription based payment options. When compared to state-of-the-art Bitcoin writing solutions, Tithonus reduces the cost of transferring data to censored clients by 2 orders of magnitude and increases the goodput by 3 to 5 orders of magnitude. We show that Tithonus client initiated transactions are hard to detect, while server initiated transactions cannot be censored without creating split world problems to the Bit-coin blockchain. Ruben Recabarren, Bogdan Carbunar |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Fraud De-Anonymization for Fun and ProfitabstractThe persistence of search rank fraud in online, peer-opinion systems, made possible by crowdsourcing sites and specialized fraud workers, shows that the current approach of detecting and filtering fraud is inefficient. We introduce a fraud de-anonymization approach to disincentivize search rank fraud: attribute user accounts flagged by fraud detection algorithms in online peer-opinion systems, to the human workers in crowdsourcing sites, who control them. We model fraud de-anonymization as a maximum likelihood estimation problem, and introduce UODA, an unconstrained optimization solution. We develop a graph based deep learning approach to predict ownership of account pairs by the same fraudster and use it to build discriminative fraud de-anonymization (DDA) and pseudonymous fraudster discovery algorithms (PFD). To address the lack of ground truth fraud data and its pernicious impacts on online systems that employ fraud detection, we propose the first cheating-resistant fraud de-anonymization validation protocol, that transforms human fraud workers into ground truth, performance evaluation oracles. In a user study with 16 human fraud workers, UODA achieved a precision of 91%. On ground truth data that we collected starting from other 23 fraud workers, our co-ownership predictor significantly outperformed a state-of-the-art competitor, and enabled DDA and PFD to discover tens of new fraud workers, and attribute thousands of suspicious user accounts to existing and newly discovered fraudsters. Nestor Hernandez, Ruben Recabarren, Bogdan Carbunar |
CCS | 4 |
| 2018 | CipherLocker: Encrypted File Sharing with Ranked Search https: //cipherlocker.comabstractToday's (predominantly cloud-based) File sharing products leave users at the mercy of providers and nation-state adversaries with subpoena and National Security Letter (NSL) powers. In-transit and provider-side at-rest encryption do little to handle this.Almost-weekly breaches [7-13, 17] and NSL revelations [2] show that the problem becomes only worse with increasingly privacy-unfriendly regulation [14]. We believe it is important to provide hype-free, easy-to-use strongly-secure solutions that protect individual privacy while also defeating cloud breaches and compromises. CipherLocker provides practical, easy-to-use, client-side encrypted File sharing with integrated ranked search. All data and metadata is strongly encrypted before leaving the client. Users can securely store, share, sync, and search. The design does not allow even a compromised or compelled cloud provider to ever access user data or search queries. CipherLocker shows that highly-scalable, fast ranked search on encrypted data is possible without the deployment of expensive and often insecure server-side search-on-encrypted-data cryptography which would require 3-5 orders of magnitude more resources and cannot scale to even thousands of users, or the simplest sharing scenarios without breaking security. CipherLocker is the result of several years of work and it cannot be exhaustively detailed and analyzed in this space. This is the first of a series of papers discussing CipherLocker design, implementation and security properties. The main goal here is to briefly overview and introduce key design decisions and behaviors. Jan Kasiak, Bogdan Carbunar, Jake Christensen, Maria Lyukova, Sumeet Bajaj, Mike Boruta, Radu Sion, Viorel Popescu, Alex Sorodoc, Gabriel Stan |
CCS | 2 |
| 2018 | AbuSniff: Automatic Detection and Defenses Against Abusive Facebook Friends
Sajedul Talukder, Bogdan Carbunar |
ICWSM | 2 |
| 2017 | A Secure Mobile Authentication Alternative to BiometricsabstractBiometrics are widely used for authentication in consumer devices and business settings as they provide sufficiently strong security instant verification and convenience for users. However, biometrics are hard to keep secret, stolen biometrics pose lifelong security risks to users as they cannot be reset and re-issued, and transactions authenticated by biometrics across different systems are linkable and traceable back to the individual identity. In addition, their cost-benefit analysis does not include personal implications to users, who are least prepared for the imminent negative outcomes, and are not often given equally convenient alternative authentication options. Mozhgan Azimpourkivi, Umut Topkara, Bogdan Carbunar |
ACSAC | 3 |
| 2017 | Hardening Stratum, the Bitcoin Pool Mining ProtocolabstractAbstract Stratum, the de-facto mining communication protocol used by blockchain based cryptocurrency systems, enables miners to reliably and efficiently fetch jobs from mining pool servers. In this paper we exploit Stratum’s lack of encryption to develop passive and active attacks on Bitcoin’s mining protocol, with important implications on the privacy, security and even safety of mining equipment owners. We introduce StraTap and ISP Log attacks, that infer miner earnings if given access to miner communications, or even their logs. We develop BiteCoin, an active attack that hijacks shares submitted by miners, and their associated payouts. We build BiteCoin on WireGhost, a tool we developed to hijack and surreptitiously maintain Stratum connections. Our attacks reveal that securing Stratum through pervasive encryption is not only undesirable (due to large overheads), but also ineffective: an adversary can predict miner earnings even when given access to only packet timestamps. Instead, we devise Bedrock, a minimalistic Stratum extension that protects the privacy and security of mining participants. We introduce and leverage the mining cookie concept, a secret that each miner shares with the pool and includes in its puzzle computations, and that prevents attackers from reconstructing or hijacking the puzzles. We have implemented our attacks and collected 138MB of Stratum protocol traffic from mining equipment in the US and Venezuela. We show that Bedrock is resilient to active attacks even when an adversary breaks the crypto constructs it uses. Bedrock imposes a daily overhead of 12.03s on a single pool server that handles mining traffic from 16,000 miners. Ruben Recabarren, Bogdan Carbunar |
Proc. Priv. Enhancing Technol. | 2 |
| 2017 | A Longitudinal Study of Google PlayabstractThe difficulty of large-scale monitoring of app markets affects our understanding of their dynamics. This is particularly true for dimensions such as app update frequency, control and pricing, the impact of developer actions on app popularity, as well as coveted membership in top app lists. In this paper, we perform a detailed temporal analysis on two datasets we have collected from the Google Play Store, one consisting of 160000 apps and the other of 87223 newly released apps. We have monitored and collected data about these apps over more than six months. Our results show that a high number of these apps have not been updated over the monitoring interval. Moreover, these apps are controlled by a few developers that dominate the total number of app downloads. We observe that infrequently updated apps significantly impact the median app price. However, a changing app price does not correlate with the download count. Furthermore, we show that apps that attain higher ranks have better stability in top app lists. We show that app market analytics can help detect emerging threat vectors, and identify search rank fraud and even malware. Further, we discuss the research implications of app market analytics on improving developer and user experiences. Rahul Potharaju, Bogdan Carbunar |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2017 | Search Rank Fraud and Malware Detection in Google PlayabstractFraudulent behaviors in Google Play, the most popular Android app market, fuel search rank abuse and malware proliferation. To identify malware, previous work has focused on app executable and permission analysis. In this paper, we introduce FairPlay, a novel system that discovers and leverages traces left behind by fraudsters, to detect both malware and apps subjected to search rank fraud. FairPlay correlates review activities and uniquely combines detected review relations with linguistic and behavioral signals gleaned from Google Play app data (87 K apps, 2.9 M reviews, and 2.4M reviewers, collected over half a year), in order to identify suspicious apps. FairPlay achieves over 95 percent accuracy in classifying gold standard datasets of malware, fraudulent and legitimate apps. We show that 75 percent of the identified malware apps engage in search rank fraud. FairPlay discovers hundreds of fraudulent apps that currently evade Google Bouncer's detection technology. FairPlay also helped the discovery of more than 1,000 reviews, reported for 193 apps, that reveal a new type of “coercive” review campaign: users are harassed into writing positive reviews, and install and review other apps. Mahmudur Rahman, Bogdan Carbunar, Polo Chau |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2017 | Video Liveness for Citizen Journalism: Attacks and DefensesabstractThe impact of citizen journalism raises important video integrity and credibility issues. In this article, we introduce Vamos, the first user transparent video “liveness” verification solution based on video motion, that accommodates the full range of camera movements, and supports videos of arbitrary length. Vamos uses the agreement between video motion and camera movement to corroborate the video authenticity. Vamos can be integrated into any mobile video capture application without requiring special user training. We develop novel attacks that target liveness verification solutions. The attacks leverage both fully automated algorithms and trained human experts. We introduce the concept of video motion categories to annotate the camera and user motion characteristics of arbitrary videos. We show that the performance of Vamos depends on the video motion category. Even though Vamos uses motion as a basis for verification, we observe a surprising and seemingly counter-intuitive resilience against attacks performed on relatively “stationary” video chunks, which turn out to contain hard-to-imitate involuntary movements. We show that overall the accuracy of Vamos on the task of verifying whole length videos exceeds 93 percent against the new attacks. Mahmudur Rahman, Mozhgan Azimpourkivi, Umut Topkara, Bogdan Carbunar |
IEEE Trans. Mob. Comput. | 4 |
| 2016 | FairPlay: Fraud and Malware Detection in Google PlayabstractFraudulent behaviors in Google's Android app market fuel search rank abuse and malware proliferation. We present FairPlay, a novel system that uncovers both malware and search rank fraud apps, by picking out trails that fraudsters leave behind. To identify suspicious apps, FairPlay's PCF algorithm correlates review activities and uniquely combines detected review relations with linguistic and behavioral signals gleaned from longitudinal Google Play app data. We contribute a new longitudinal app dataset to the community, which consists of over 87K apps, 2.9M reviews, and 2.4M reviewers, collected over half a year. FairPlay achieves over 95% accuracy in classifying gold standard datasets of malware, fraudulent and legitimate apps. We show that 75% of the identified malware apps engage in search rank fraud. FairPlay discovers hundreds of fraudulent apps that currently evade Google Bouncer's detection technology, and reveals a new type of attack campaign, where users are harassed into writing positive reviews, and install and review other apps. Mahmudur Rahman, Bogdan Carbunar, Polo Chau |
SDM | 3 |
| 2016 | GeoPal: Friend Spam Detection in Social Networks Using Private Location ProofsabstractFriend spam, adversarial invitations sent to social network users, exposes victims to a suite of privacy, spear phishing and malware vulnerabilities. In this paper, we use the location history of users to detect friend spam. We posit that the user trust in friends is associated with their co-location frequency. We exploit this hypothesis to introduce GeoPal, a framework that carefully accesses the potentially sensitive location history of users to privately prove their past location claims, and to privately compute and update fuzzy co-location affinities with other users. We build GeoPal on PLP, a protocol we develop to privately collect proofs of user past locations. We confirm our hypothesis through a user study with 68 participants: 57% and 70% of the friends never met in person are not remembered and are not talked to, respectively, by the participants. In contrast, 86% of the friends met daily or weekly are either family, close or regular friends. We highlight the relevance of friend spam: 75% of the participants have at least one friend whom they do not recall. We show that GeoPal is practical: a Nexus 5 can process more thank 20K location proofs per second. Bogdan Carbunar, Mozhgan Azimpourkivi, Debra Lee Davis |
SECON | 1 |
| 2016 | Secure Management of Low Power Fitness TrackersabstractThe increasing popular interest in personal telemetry, also called the Quantified Self or “lifelogging”, has induced a popularity surge for wearable personal fitness trackers. Fitness trackers automatically collect sensor data about the user throughout the day, and integrate it into social network accounts. Solution providers have to strike a balance between many constraints, leading to a design process that often puts security in the back seat. Case in point, we reverse engineered and identified security vulnerabilities in Fitbit Ultra and Gammon Forerunner 610, two popular and representative fitness tracker products. We introduce FitBite and GarMax, tools to launch efficient attacks against Fitbit and Garmin. We devise SensCrypt, a protocol for secure data storage and communication, for use by makers of affordable and lightweight personal trackers. SensCrypt thwarts not only the attacks we introduced, but also defends against powerful JTAG Read attacks. We have built Sens.io, an Arduino Uno based tracker platform, of similar capabilities but at a fraction of the cost of current solutions. On Sens.io, SensCrypt imposes a negligible write overhead and significantly reduces the end-to-end sync overhead of Fitbit and Garmin. Mahmudur Rahman, Bogdan Carbunar, Umut Topkara |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | Movee: Video Liveness Verification for Mobile Devices Using Built-In Motion SensorsabstractThe ubiquitous and connected nature of camera-equipped mobile devices has greatly increased the value and importance of visual information they capture. Today, broadcasting videos from camera phones uploaded by unknown users is admissible on news networks, and banking customers expect to be able to deposit checks using mobile devices. In this paper, we introduce Movee, a system that addresses the fundamental question of whether the visual stream uploaded by a user has been captured live on a mobile device, and has not been tampered with by an adversary. Movee leverages the mobile device motion sensors and the intrinsic user movements during the shooting of the video. Movee exploits the observation that the movement of the scene recorded on the video stream should be related to the movement of the device simultaneously captured by the accelerometer. Contrary to existing algorithms, Movee has the unique strength of not depending on the audio track. We introduce novel attacks that focus on Movee's defenses, to fabricate acceleration data that mimics the motion observed in targeted videos. We use smartphones and wearable smart glasses to collect both genuine and attack data from 13 users. Our experiments show that Movee is able to efficiently detect human and automatically generated plagiarized videos: Movee's accuracy ranges between 68-93 percent on a smartphone, and between 76-91 percent on a Google Glass device. Mahmudur Rahman, Umut Topkara, Bogdan Carbunar |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | A Longitudinal Study of the Google App MarketabstractRecently emerged app markets provide a centralized paradigm for software distribution in smartphones. The difficulty of massively collecting app data has led to a lack a good understanding of app market dynamics. In this paper we seek to address this problem, through a detailed temporal analysis of Google Play, Google's app market. We perform the analysis on data that we collected daily from 160,000 apps, over a period of six months in 2012. We report often surprising results. For instance, at most 50% of the apps are updated in all categories, which significantly impacts the median price. The average price does not exhibit seasonal monthly trends and a changing price does not show any observable correlation with the download count. In addition, productive developers are not creating many popular apps, but a few developers control apps which dominate the total number of downloads. We discuss the research implications of such analytics on improving developer and user experiences, and detecting emerging threat vectors. Bogdan Carbunar, Rahul Potharaju |
ASONAM | 1 |
| 2015 | Liveness verifications for citizen journalism videosabstractCitizen journalism videos increasingly complement or even replace the professional news coverage through direct reporting by event witnesses. This raises questions of the integrity and credibility of such videos. We introduce Vamos, the first user transparent video "liveness" verification solution based on video motion, that can be integrated into any mobile video capture application without requiring special user training. Vamos' algorithm not only accommodates the full range of camera movements, but also supports videos of arbitrary length. We develop strong attacks both by utilizing fully automated attackers and by employing trained human experts for creating fraudulent videos to thwart mobile video verification systems. Mahmudur Rahman, Mozhgan Azimpourkivi, Umut Topkara, Bogdan Carbunar |
WISEC | 4 |
| 2014 | SensCrypt: A Secure Protocol for Managing Low Power Fitness TrackersabstractThe increasing interest in personal telemetry has induced a popularity surge for wearable personal fitness trackers. Such trackers automatically collect sensor data about the user throughout the day, and integrate it into social network accounts. Solution providers have to strike a balance between many constraints, leading to a design process that often puts security in the back seat. Case in point, we reverse engineered and identified security vulnerabilities in Fit bit Ultra and Gammon Forerunner 610, two popular and representative fitness tracker products. We introduce Fit Bite and GarMax, tools to launch efficient attacks against Fit bit and Garmin. We devise SensCrypt, a protocol for secure data storage and communication, for use by makers of affordable and lightweight personal trackers. SensCrypt thwarts not only the attacks we introduced, but also defends against powerful JTAG Read attacks. We have built Sens.io, an Arduino Uno based tracker platform, of similar capabilities but at a fraction of the cost of current solutions. On Sens.io, SensCrypt imposes a negligible write overhead and significantly reduces the end-to-end sync overhead of Fit bit and Garmin. Mahmudur Rahman, Bogdan Carbunar, Umut Topkara |
ICNP | 2 |
| 2014 | Geofit: Verifiable Fitness ChallengesabstractThe tight integration of mobile devices and apps into our daily routine impacts our approach to health. While existing solutions propose to take advantage of recent developments in mobile and sensor technologies to encourage users to lead healthier lives, we still lack a viable approach that motivates user participation. In this paper we aim to integrate fitness challenges into the daily routine of users, in order to motivate them to participate more frequently. We develop GeoFit, a mobile app that enables users to discover and add novel fitness challenges in their proximity. In addition to achievement badges, GeoFit relies on top-k lists to motivate users to become top performers. Since participation incentives may also raise cheating concerns, GeoFit leverages GPS and accelerometer sensors of the mobile device to verify the authenticity of fitness challenges performed by users. We have implemented and tested GeoFit on Android devices. Our experimental results show that the GeoFit client imposes only little overhead on the user device, while the server side can support hundreds of client interactions per second. Ian Michael Terry, Anita Wu, Sebastian Ramirez, Alex Pissinou Makki, Leonardo Bobadilla, Niki Pissinou, S. Sitharama Iyengar, Bogdan Carbunar |
MASS | 8 |
| 2014 | Turning the Tide: Curbing Deceptive Yelp BehaviorsabstractThe popularity and influence of reviews, make sites like Yelp ideal targets for malicious behaviors. We present Marco, a novel system that exploits the unique combination of social, spatial and temporal signals gleaned from Yelp, to detect venues whose ratings are impacted by fraudulent reviews. Marco increases the cost and complexity of attacks, by imposing a tradeoff on fraudsters, between their ability to impact venue ratings and their ability to remain undetected. We contribute a new dataset to the community, which consists of both ground truth and gold standard data. We show that Marco significantly outperforms state-of-the-art approaches, by achieving 94% accuracy in classifying reviews as fraudulent or genuine, and 95.8% accuracy in classifying venues as deceptive or legitimate. Marco successfully flagged 244 deceptive venues from our large dataset with 7,435 venues, 270,121 reviews and 195,417 users. Among the San Francisco car repair and moving companies that we analyzed, almost 10% exhibit fraudulent behaviors. Mahmudur Rahman, Bogdan Carbunar, Jaime Ballesteros, George Burri, Polo Chau |
SDM | 2 |
| 2014 | ${\rm PROFIL}_{R}$: Toward Preserving Privacy and Functionality in Geosocial NetworksabstractProfit is the main participation incentive for social network providers. Its reliance on user profiles, built from a wealth of voluntarily revealed personal information, exposes users to a variety of privacy vulnerabilities. In this paper, we propose to take first steps toward addressing the conflict between profit and privacy in geosocial networks. We introduce PROFILR, a framework for constructing location centric profiles (LCPs), aggregates built over the profiles of users that have visited discrete locations (i.e., venues). PROFILR endows users with strong privacy guarantees and providers with correctness assurances. In addition to a venue centric approach, we propose a decentralized solution for computing real time LCP snapshots over the profiles of colocated users. An Android implementation shows that PROFILR is efficient; the end-to-end overhead is small even under strong privacy and correctness assurances. Bogdan Carbunar, Mahmudur Rahman, Jaime Ballesteros, Naphtali Rishe, Athanasios V. Vasilakos |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Private Badges for Geosocial NetworksabstractGeosocial networks (GSNs) extend classic online social networks with the concept of location. Users can report their presence at venues through “check-ins” and, when certain check-in sequences are satisfied, users acquire special status in the form of “badges”. We first show that this innovative functionality is popular in Foursquare, a prominent GSN. Furthermore, we address the apparent tension between privacy and correctness, where users are unable to prove having satisfied badge conditions without revealing the corresponding time and location of their check-in sequences. To this end, we propose several privacy preserving protocols that enable users to prove having satisfied the conditions of several badge types. Specifically, we introduce (i) GeoBadge and T-Badge, solutions for acquiring location badges, (ii) FreqBadge, for mayorship badges, (iii) e-Badge, for proving various expertise levels and (iv) MPBadge, for accumulating multi-player badges. We show that a Google Nexus One smartphone is able to perform tens of badge proofs per minute while a provider can support hundreds of million of check-ins and badge verifications per day. Bogdan Carbunar, Radu Sion, Rahul Potharaju, Moussa Ehsan |
IEEE Trans. Mob. Comput. | 1 |
| 2014 | Errata for: A Framework for Network Aware Caching for Video on Demand SystemsabstractSome errors were introduced while preparing the final source files for the original article published in August 2013 in the 9,4 issue of TOMM. The errata are summarized here below together with attached revised pages showing the corrected elements indicated in red. The full CVoR (Corrected Version of Record) can be accessed in the ACM Digital Library, DOI=http://dx.doi.org/10.1145/2501643.2501652 —Page 8: New Figure 6(a) —Page 16: New Figures 8(a), 8(b), and 9(a) —Page 17: New Figure 10(b) —Page 18: New Figures 11 and 12; corrected text reference —Page 19: Final sentence deleted Bogdan Carbunar, Rahul Potharaju, Michael Pearce, Venu Vasudevan, Michael L. Needham |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2014 | Towards Safe Cities: A Mobile and Social Networking ApproachabstractPopulation density and natural and man-made disasters make public safety a concern of growing importance. In this paper we aim to enable the vision of smart and safe cities by exploiting mobile and social networking technologies to securely and privately extract, model and embed real-time public safety information into quotidian user experiences. We first propose novel approaches to define location- and user-based safety metrics. We evaluate the ability of existing forecasting techniques to predict future safety values. We introduce iSafe, a privacy-preserving algorithm for computing safety snapshots of co-located mobile devices as well as geosocial network users. We present implementation details of iSafe as both an Android application and a browser plugin that visualizes safety levels of visited locations and browsed geosocial venues. We evaluate iSafe using crime and census data from the Miami-Dade (FL) county as well as data we collected from Yelp, a popular geosocial network. Jaime Ballesteros, Bogdan Carbunar, Mahmudur Rahman, Naphtali Rishe, S. Sitharama Iyengar |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Seeing is not believing: visual verifications through liveness analysis using mobile devicesabstractThe visual information captured with camera-equipped mobile devices has greatly appreciated in value and importance as a result of their ubiquitous and connected nature. Today, banking customers expect to be able to deposit checks using mobile devices, and broadcasting videos from camera phones uploaded by unknown users is admissible on news networks. We present Movee, a system that addresses the fundamental question of whether the visual stream coming into a mobile app from the camera of the device can be trusted to be un-tampered with, live data, before it can be used for a variety of purposes. Mahmudur Rahman, Umut Topkara, Bogdan Carbunar |
ACSAC | 3 |
| 2013 | Toward preserving privacy and functionality in geosocial networksabstractStoring user friend lists, preferences and messages, online social networks have become a significant source of sensi-tive personal information. A recent addition to this space, geosocial networks (GSNs) such as Yelp [1] or Foursquare [2], Mahmudur Rahman, Jaime Ballesteros, Bogdan Carbunar, Naphtali Rishe, Athanasios V. Vasilakos |
MobiCom | 3 |
| 2013 | A framework for network aware caching for video on demand systemsabstractVideo on Demand (VoD) services allow users to select and locally consume remotely stored content. We investigate the use of caching to solve the scalability issues of several existing VoD providers. We propose metrics and goals that define the requirements of a caching framework for CDNs of VoD systems. Using data logs collected from Motorola equipment from Comcast VoD deployments we show that several classic caching solutions do not satisfy the proposed goals. We address this issue by developing novel techniques for predicting future values of several metrics of interest. We rely on computed predictions to define the penalty imposed on the system, both network and caching sites, when not storing individual items. We use item penalties to devise novel caching and static content placement strategies. We use the previously mentioned data logs to validate our solutions and show that they satisfy all the defined goals. Bogdan Carbunar, Rahul Potharaju, Michael Pearce, Venu Vasudevan, Michael L. Needham |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2012 | The Shy Mayor: Private Badges in GeoSocial Networks
Bogdan Carbunar, Radu Sion, Rahul Potharaju, Moussa Ehsan |
ACNS | 1 |
| 2012 | Private location centric profiles for GeoSocial networksabstractProviding input to targeted advertising, profiling social network users is an important source of revenue for geosocial networks. Since profiles contain personal information, their construction introduces a trade-off between user privacy and incentives of participation for businesses and geosocial network providers. In this paper we introduce location centric profiles (LCPs), aggregates built over the profiles of users present at a given location. We introduce ProfilR, a suite of mechanisms that construct LCPs in a private and correct manner. Our Android implementation shows that ProfilR is efficient: the end-to-end overhead is small even under strong correctness assurances. Bogdan Carbunar, Mahmudur Rahman, Naphtali Rishe, Jaime Ballesteros |
SIGSPATIAL/GIS | 1 |
| 2012 | Safe cities. A participatory sensing approachabstractSmart cities combine technology and human resources to improve the quality of life and reduce expenditures. Ensuring the safety of city residents remains one of the open problems, as standard budgetary investments fail to decrease crime levels. This work takes steps toward implementing smart, safe cities, by combining the use of personal mobile devices and social networks to make users aware of the safety of their surroundings. We propose novel metrics to define location and user based safety values. We evaluate the ability of forecasting techniques including autoregressive integrated moving average (ARIMA) and artificial neural networks (ANN) to predict future safety values. We devise iSafe, a privacy preserving algorithm for computing safety snapshots of co-located mobile device users and integrate our approach into an Android application for visualizing safety levels. We further investigate relationships between location dependent social network activity and crime levels. We evaluate our contributions using data we collected from Yelp as well as crime and census data. Jaime Ballesteros, Mahmudur Rahman, Bogdan Carbunar, Naphtali Rishe |
LCN | 3 |
| 2012 | You unlocked the Mt. Everest badge on foursquare! Countering location fraud in Geosocial NetworksabstractGeoSocial Networks (GSNs) are online social networks centered on the location information of their users. Users “check-in” their location and use it to acquire location-based special status (e.g., badges, mayorships) and receive venue dependent rewards. The strategy of rewarding user participation however makes cheating a profitable behavior. In this paper we introduce XACT, a suite of venue-oriented secure location verification mechanisms that enable venues and GSN providers to certify the locations claimed by users. We prove that XACT is correct, secure and easy to use. We validate the need for secure location verification mechanisms by collecting and analyzing data from the most popular GSNs today: 780,000 Foursquare users and 143,000 Gowalla users. Through a proof-of-concept implementation on a Revision C4 BeagleBoard embedded system we show that XACT is easy to deploy and economically viable. We analytically and empirically prove that XACT detects location cheating attacks. Bogdan Carbunar, Rahul Potharaju |
MASS | 1 |
| 2012 | Network Aware Caching for Video on Demand systemsabstractVideo on Demand (VoD) services allow users to select and locally consume remotely stored content. We investigate the use of caching to solve the scalability issues of several existing VoD providers. We propose metrics and goals that define the requirements of a caching framework for CDNs of VoD systems. Using data logs collected from Motorola equipment from Comcast VoD deployments we show that several classic caching solutions do not satisfy the proposed goals. We address this issue by developing a novel technique for predicting future values of several metrics of interest. We use these predictions to evaluate the penalty imposed on the system (network and caches) when not caching individual items. We use item penalties to propose novel caching and static placement strategies. We use the mentioned data logs to validate our solutions and show that they satisfy all the defined goals. Bogdan Carbunar, Rahul Potharaju, Michael Pearce, Venu Vasudevan |
WOWMOM | 1 |
| 2012 | Tipping Pennies? Privately Practical Anonymous MicropaymentsabstractWe design and analyze the first practical anonymous payment mechanisms for network services. We start by reporting on our experience with the implementation of a routing micropayment solution for Tor. We then propose micropayment protocols of increasingly complex requirements for networked services, such as P2P or cloud-hosted services. The solutions are efficient, with bandwidth and latency overheads of under 4% and 0.9 ms, respectively, in the ORPay implementation, provide full anonymity (for both payers and payees), and support thousands of transactions per second. Bogdan Carbunar, Radu Sion |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | Toward Private Joins on Outsourced DataabstractIn an outsourced database framework, clients place data management responsibilities with specialized service providers. Of essential concern in such frameworks is data privacy. Potential clients are reluctant to outsource sensitive data to a foreign party without strong privacy assurances beyond policy “fine prints.” In this paper, we introduce a mechanism for executing general binary JOIN operations (for predicates that satisfy certain properties) in an outsourced relational database framework with computational privacy and low overhead—the first, to the best of our knowledge. We illustrate via a set of relevant instances of JOIN predicates, including: range and equality (e.g., for geographical data), Hamming distance (e.g., for DNA matching), and semantics (i.e., in health-care scenarios—mapping antibiotics to bacteria). We experimentally evaluate the main overhead components and show they are reasonable. The initial client computation overhead for 100,000 data items is around 5 minutes and our privacy mechanisms can sustain theoretical throughputs of several million predicate evaluations per second, even for an unoptimized OpenSSL-based implementation. Bogdan Carbunar, Radu Sion |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2012 | Payments for Outsourced ComputationsabstractWith the recent advent of cloud computing, the concept of outsourcing computations, initiated by volunteer computing efforts, is being revamped. While the two paradigms differ in several dimensions, they also share challenges, stemming from the lack of trust between outsourcers and workers. In this work, we propose a unifying trust framework, where correct participation is financially rewarded: neither participant is trusted, yet outsourced computations are efficiently verified and validly remunerated. We propose three solutions for this problem, relying on an offline bank to generate and redeem payments; the bank is oblivious to interactions between outsourcers and workers. We propose several attacks that can be launched against our framework and study the effectiveness of our solutions. We implemented our most secure solution and our experiments show that it is efficient: the bank can perform hundreds of payment transactions per second and the overheads imposed on outsourcers and workers are negligible. Bogdan Carbunar, Mahesh Tripunitara |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2011 | Private geosocial networkingabstractLocation based social or geosocial networks (GSNs) have recently emerged as a natural combination of location based services with online social networks: users register their location and activities, share it with friends and achieve special status (e.g., "mayorship" badges) based on aggregate location predicates. Boasting millions of users and tens of daily check-ins, such services pose significant privacy threats: user location information may be tracked and leaked to third parties. Conversely, a solution enabling location privacy may provide cheating capabilities to users wanting to claim special location status. In this paper we introduce new mechanisms that allow users to (inter)act privately in today's geosocial networks while simultaneously ensuring honest behaviors. We show that our solutions are efficient both on the provider and the client side. Bogdan Carbunar, Radu Sion |
GIS | 1 |
| 2011 | Predictive Caching for Video on Demand CDNsabstractVideo on Demand (VoD) services provide a wide range of content options and enable subscribers to select, retrieve and locally consume desired content. In this work we propose caching solutions to improve the scalability of the content distribution networks (CDNs) of existing VoD architectures. We first investigate metrics relevant to this caching framework and subsequently define goals that should be satisfied by an efficient solution. We propose novel techniques for predicting future values of metrics of interest. We use our prediction mechanisms to define the cost imposed on the system (network and caches) by items that are not cached. We use this cost to develop novel caching and static placement strategies. We validate our solutions using log data collected from Motorola equipment from several Comcast VoD deployments. Bogdan Carbunar, Michael Pearce, Venu Vasudevan, Michael L. Needham |
GLOBECOM | 1 |
| 2011 | Conditional e-payments with transferability
Bogdan Carbunar, Larry Shi, Radu Sion |
J. Parallel Distributed Comput. | 1 |
| 2011 | Write-Once Read-Many Oblivious RAMabstractWe introduce WORM-ORAM, a first mechanism that combines Oblivious RAM (ORAM) access privacy and data confidentiality with Write-Once Read-Many (WORM) regulatory data retention guarantees. Clients can outsource their database to a server with full confidentiality and data access privacy, and, for data retention, the server ensures client access WORM semantics. In general simple confidentiality and WORM assurances are easily achievable, e.g., via an encrypted outsourced data repository with server-enforced read-only access to existing records (albeit encrypted). However, this becomes hard when also access privacy is to be ensured-when client access patterns are necessarily hidden and the server cannot enforce access control directly. WORM-ORAM overcomes this by deploying a set of zero-knowledge proofs to convince the server that all stages of the protocol are WORM-compliant. Bogdan Carbunar, Radu Sion |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Regulatory Compliant Oblivious RAM
Bogdan Carbunar, Radu Sion |
ACNS | 1 |
| 2010 | iFriendU: leveraging 3-cliques to enhance infiltration attacks in online social networksabstractOnline Social Networks (OSNs) such as Facebook have become ubiquitous in the past few years, counting hundreds of millions of people as members. OSNs allow users to form friendship relationships, join groups, communicate and share information with friends. The tremendous popularity of OSNs has naturally made them an appealing target for privacy compromising attacks. In this abstract we propose a novel attack against tightly knit OSN communities. Such (artificial) communities consist of users that know well each other and that are reluctant to accept other users as friends. Becoming a member of such a community may be only a first milestone for the attacker. Harvesting private information of members of such communities and following up with offline attacks may be the longer term benefit. Rahul Potharaju, Bogdan Carbunar, Cristina Nita-Rotaru |
CCS | 2 |
| 2010 | Fair Payments for Outsourced ComputationsabstractInitiated by volunteer computing efforts, the computation outsourcing problem can become a compelling application for networked set-top-boxes and mobile devices. In this paper we extend such environments with the ability to provide secure payments in exchange for outsourced CPU cycles. Previous contributions in wired networks have almost exclusively tackled only one side of the problem -- offering incentives for volunteer participation and preventing worker laziness. This makes sense in static environments where reputable outsourcers have little to gain from incorrectly rewarding honest participation. However, this assumption is no longer valid in ad hoc environments, where unique identities are difficult to provide and anyone can outsource computations. In this paper we propose a solution that simultaneously ensures correct remuneration for jobs completed on time and prevents worker laziness. Our solution relies on an offline bank to generate and redeem payments; the bank is oblivious to interactions between outsourcers and workers. In particular, the bank is not involved in job computation or verification. Our experiments show that the solution is efficient: the bank can perform hundreds of payment transactions per second and the overheads imposed on outsourcers and workers are negligible. Bogdan Carbunar, Mahesh Tripunitara |
SECON | 1 |
| 2010 | Query privacy in wireless sensor networksabstractExisting mechanisms for querying wireless sensor networks leak client interests to the servers performing the queries. The leaks are not only in terms of specific regions of interest but also of client access patterns. In this article we introduce the problem of preserving the privacy of clients querying a wireless sensor network owned by untrusted organizations. We first propose an efficient protocol, SPYC, that ensures full client privacy in settings where the servers providing access to the network are honest-but-curious and whose collaboration does not extend beyond well-defined administrative purposes. Furthermore, we study the same query privacy problem in a setting where servers exhibit malicious behavior or where powerful external attackers have access to sensor network traffic information. In this setting we propose two metrics for quantifying the privacy achieved by a client's query sequence. We then extend SPYC with a suite of practical algorithms, then analyze the privacy and efficiency levels they provide. Our TOSSIM simulations show that the proposed extensions are communication efficient while significantly improving client privacy levels. Bogdan Carbunar, Yang Yu 0009, Larry Shi, Michael Pearce, Venu Vasudevan |
ACM Trans. Sens. Networks | 1 |
| 2010 | Secure Synchronization of Periodic Updates in Ad Hoc NetworksabstractWe present techniques for synchronizing nodes that periodically broadcast content and presence updates to colocated nodes over an ad hoc network, where nodes may exhibit Byzantine malicious behavior. Instead of aligning duty cycles, our algorithms synchronize the periodic transmissions of nodes. This allows nodes to save battery power by switching off their network cards without missing updates from their neighbors. We propose several novel attack classes and show that they are able to disrupt synchronization even when launched by a single attacker. Finally, we devise a rating based algorithm (RBA) that rates neighbors based on the consistency of their behavior. By favoring well-behaved nodes in the synchronization process, we show that RBA quickly stabilizes the synchronization process and reduces the number of lost updates by 85 percent. Our evaluation also shows that all our algorithms are computationally efficient and, for the setup considered, extend the device lifetime by 30 percent over an always-on Wi-Fi scenario. Bogdan Carbunar, Michael Pearce, Shivajit Mohapatra, Loren J. Rittle, Venu Vasudevan, Octavian Carbunar |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2009 | Efficient access enforcement in distributed role-based access control (RBAC) deploymentsabstractWe address the distributed setting for enforcement of a centralized Role-Based Access Control (RBAC) protection state. We present a new approach for time- and space-efficient access enforcement. Underlying our approach is a data structure that we call a cascade Bloom filter. We describe our approach, provide details about the cascade Bloom filter, its associated algorithms, soundness and completeness properties for those algorithms, and provide an empirical validation for distributed access enforcement of RBAC. We demonstrate that even in low-capability devices such as WiFi network access points, we can perform thousands of access checks in a second. Mahesh Tripunitara, Bogdan Carbunar |
SACMAT | 2 |
| 2009 | A personal mobile DRM manager for smartphones
Siddharth Bhatt, Radu Sion, Bogdan Carbunar |
Comput. Secur. | 3 |
| 2009 | Efficient tag detection in RFID systems
Bogdan Carbunar, Murali Krishna Ramanathan, Mehmet Koyutürk, Suresh Jagannathan, Ananth Grama |
J. Parallel Distributed Comput. | 1 |
| 2009 | JANUS: A Framework for Scalable and Secure Routing in Hybrid Wireless NetworksabstractHybrid networks consisting of cellular and Wi-Fi networks were proposed as a high-throughput architecture for cellular services. In such networks, devices equipped with cellular and Wi-Fi network cards access Internet services through the cellular base station. The Wi-Fi interface is used to provide a better service to clients that are far away from the base station, via multihop ad hoc paths. The modified trust model of hybrid networks generates a set of new security challenges as clients rely on intermediate nodes to participate effectively in the resource reservation process and data forwarding. In this paper, we introduce JANUS, a framework for scalable, secure, and efficient routing for hybrid cellular and Wi-Fi networks. JANUS uses a scalable routing algorithm with multiple channel access, for improved network throughput. In addition, it provides protection against selfish nodes through a secure crediting protocol and protection against malicious nodes through secure route establishment and data forwarding mechanisms. We evaluate JANUS experimentally and show that its performance is 85 percent of the optimum algorithm, improving with a factor greater than 50 percent over previous work. We evaluate the security overhead of JANUS against two types of attacks: less aggressive, but sufficient for some applications, selfish attacks and purely malicious attacks. Bogdan Carbunar, Ioannis Ioannidis, Cristina Nita-Rotaru |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2008 | Conditional Payments for Computing Markets
Bogdan Carbunar, Mahesh Tripunitara |
CANS | 1 |
| 2008 | Building castles out of mud: practical access pattern privacy and correctness on untrusted storageabstractWe introduce a new practical mechanism for remote data storage with efficient access pattern privacy and correctness. A storage client can deploy this mechanism to issue encrypted reads, writes, and inserts to a potentially curious and malicious storage service provider, without revealing information or access patterns. The provider is unable to establish any correlation between successive accesses, or even to distinguish between a read and a write. Moreover, the client is provided with strong correctness assurances for its operations -- illicit provider behavior does not go undetected. We built a first practical system -- orders of magnitude faster than existing implementations -- that can execute over several queries per second on 1Tbyte+ databases with full computational privacy and correctness. Radu Sion, Bogdan Carbunar |
CCS | 3 |
| 2008 | Byzantine resilient synchronization for content and presence updates in MANETSabstractIn this paper, we present techniques for synchronizing nodes that periodically broadcast content and presence updates to co-located nodes over an ad-hoc network, where nodes may exhibit Byzantine malicious behavior. We first propose an algorithm for synchronizing the periodic transmissions of all the nodes in an attacker-free multi-hop network. This allows nodes to save battery power by switching off their network cards without missing updates from their neighbors. We then introduce a suite of spoofing attacks and show that they are able to disrupt synchronization and destabilize the network even when launched by a single attacker in large, multi-hop networks. Finally, we devise a rating based algorithm that rates neighbors based on the consistency of their behaviors. By favoring well-behaved nodes in the synchronization process, we show that we can address the issue of Byzantine malicious behavior very effectively. Our evaluation shows that the algorithms are computationally efficient and, for the setup considered, extend the device lifetime by 30% over an always-on Wi-Fi scenario. Moreover, in the presence of attacks, our rating based algorithm quickly stabilizes the synchronization process and reduces the number of lost updates by 85%. Bogdan Carbunar, Michael Pearce, Shivajit Mohapatra, Loren J. Rittle, Venu Vasudevan |
ICNP | 1 |
| 2007 | Verifiable Credit Based Transfers in Wireless Ad Hoc NetworksabstractEncouraging cooperation between users of mobile devices operating in ad hoc mode is a difficult task mostly because the scarce battery and bandwidth resources of devices suggest that selfish behavior may be most beneficial. The insecure usage of credits to reward cooperation can easily provide an incentive for cheating, thus, on the long term only leading to selfishness. In this paper we propose several secure credit based mechanisms enforcing fairness in a hybrid wireless content retrieval system operating both in cellular and ad hoc connectivity modes. Our solution consists of mechanisms for securely and privately discovering desired content on neighboring devices, simultaneously exchanging credit and content shares in a verifiable manner and for generating and expiring non-forgeable credits. We present experimental results of a partial prototype of our system implemented on MPx and E680i cellular phones and HP iPaq hx4700 PDAs, along with extensive simulation results showing that our solution significantly reduces the effectiveness of selfish behavior, making it an unattractive strategy. Bogdan Carbunar, Brett Lindsley, Michael Pearce, Venu Vasudevan |
IPDPS | 1 |
| 2007 | On the Practicality of Private Information Retrieval
Radu Sion, Bogdan Carbunar |
NDSS | 2 |
| 2007 | NS2: Networked Searchable Store with Correctness
Radu Sion, Sumeet Bajaj, Bogdan Carbunar, Stefan Katzenbeisser 0001 |
VLDB | 3 |
| 2006 | Redundancy and coverage detection in sensor networksabstractWe study the problem of detecting and eliminating redundancy in a sensor network with a view to improving energy efficiency, while preserving the network's coverage. We also examine the impact of redundancy elimination on the related problem of coverage-boundary detection. We reduce both problems to the computation of Voronoi diagrams, prove and achieve lower bounds on the solution of these problems, and present efficient distributed algorithms for computing and maintaining solutions in cases of sensor failures or insertion of new sensors. We prove the correctness and termination properties of our distributed algorithms, and analytically characterize the time complexity and traffic generated by our algorithms. Using detailed simulations, we also quantify the impact of system parameters such as sensor density, transmission range, and failure rates on network traffic. Bogdan Carbunar, Ananth Grama, Jan Vitek, Octavian Carbunar |
ACM Trans. Sens. Networks | 1 |
| 2005 | Redundant reader elimination in RFID systemsabstractAbstract — While recent technological advances have motivated large-scale deployment of RFID systems, a number of critical design issues remain unresolved. In this paper we deal with detecting redundant RFID readers (the redundant reader problem). The underlying difficulty associated with this problem arises from the lack of collision detection mechanisms, the potential inability of RFID readers to relay packets generated by other readers, and severe resource constraints on RFID tags. We prove that an optimal solution to the redundant reader problem is NP-hard and propose a randomized, distributed, and localized approximation algorithm, RRE. We provide a detailed probabilistic analysis of the accuracy and time complexity of RRE and conduct elaborate simulations to demonstrate their correctness and efficiency. I. Bogdan Carbunar, Murali Krishna Ramanathan, Mehmet Koyutürk, Christoph Hoffmann, Ananth Grama |
SECON | 1 |
| 2005 | High Throughput Routing in Hybrid Cellular and Ad-Hoc NetworksabstractWe present DST, a dynamic spanning tree based algorithm, as a routing protocol for hybrid networks. It is scalable with the network size and achieves high throughput by taking advantage of multiple channels. DST maintains a close to optimal spanning tree of the network by using distributed topology trees. DST is fully dynamic and generates only O(log n) messages per update operation. We show experimentally that DST scales well with network size, making it ideal for metropolitan environment hybrid networks. Ioannis Ioannidis, Bogdan Carbunar, Cristina Nita-Rotaru |
WOWMOM | 2 |
| 2004 | Distributed and Dynamic Voronoi Overlays for Coverage Detection and Distributed Hash Tables in Ad-Hoc Networks
Bogdan Carbunar, Ananth Grama, Jan Vitek |
ICPADS | 1 |
| 2004 | A public key algorithm for ad-hoc networksabstractSecurity is an important consideration for many applications of ad-hoc networks. While security aspects of the routing layer have been addressed extensively, there is relatively lesser work on establishing a viable public key infrastructure, which is the basis for most security protocols. We present a distributed algorithm for validating the association between the network identifier of a host and its public key without relying on a priori shared secrets or a trusted certification authority. Bogdan Carbunar, Ananth Grama, Jan Vitek |
IPCCC | 1 |
| 2004 | Scalable routing in hybrid cellular and ad-hoc networksabstractAs wireless ad-hoc networking approaches its maturity, an architecture that can support the massive deployment of such networks has not been established. Hybrid networks are a promising architecture that builds ad hoc wireless networks around the existing cellular telephony infrastructure. We present a routing protocol (DST) for hybrid networks that maintains a close to optimal spanning tree of the network with the use of distributed topology trees. DST is fully dynamic and generates only O(log n) messages per update operation. We demonstrate experimentally that the performance of DST scales excellently with the network size and activity, making it ideal for the metropolitan environment hybrid networks are expected to operate in. Ioannis Ioannidis, Bogdan Carbunar |
MASS | 2 |
| 2004 | Coverage preserving redundancy elimination in sensor networksabstractIn this paper, we study the problem of detecting and eliminating redundancy in a sensor network with a view to improving energy efficiency, while preserving the network's coverage. We also examine the impact of redundancy elimination on the related problem of coverage-boundary detection. We reduce both problems to the computation of Voronoi diagrams, prove and achieve lower bounds on the solution of these problems, and present efficient distributed algorithms for computing and maintaining solutions in cases of sensor failures or insertion of new sensors. We prove the correctness and termination properties of our distributed algorithms, and analytically characterize the time complexity and the traffic generated by our algorithms. Our simulations show that the traffic generated per sensor insertion or removal (failure) experiences a dramatic decrease with an increase in sensor density, (up to 300% when the number of sensors deployed in the same 1000 /spl times/ 1000 m/sup 2/ area increases from 150 to 800), and with an increase in radio transmission range (up to 200% when the sensor's transmission range increases from 70 m to 200 m). Bogdan Carbunar, Ananth Grama, Jan Vitek, Octavian Carbunar |
SECON | 1 |
| 2004 | Coordination and mobility in CoreLimeabstractThe choice of suitable high-level communication primitives for wide area network programming languages remains an open problem. This paper is driven by the practical consideration of providing an efficient and secure communication infrastructure for mobile agent systems. This has led us to formalise the Lime coordination middleware and propose a simplified model, which we call CoreLime, that addresses some of the main shortcomings of Lime while retaining its distinguishing feature, namely transient sharing of tuple spaces. We further discuss a prototype implementation along with security extensions. Our contribution is thus an exploration of the language design space rather than a theoretical investigation of properties of these models. Bogdan Carbunar, Marco Túlio Valente, Jan Vitek |
Math. Struct. Comput. Sci. | 1 |