Edgardo Barsallo

dblp:202/2519 · also Edgardo Alberto Barsallo Yi, Edgardo Barsallo Yi · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0002-0194-0163ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-author · 1 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Multi-Device Context-Sensitive Attacks Against Privacy
abstract
As the adoption of wearable and smart devices increases, their privacy and security are still a concern. These devices collect sensitive data and constantly communicate with each other, posing new privacy threats that need to be understood and addressed. In this paper, we analyze the privacy of smart devices from a multi-device perspective. The central premise of our work is that information available at each device may be non-sensitive or lightly so, but by orchestrating information from multiple connected smart devices, it is possible to infer sensitive content. To verify this, we conduct a user study to understand user perceptions towards privacy on smart devices and contrast them with their actual behavior while operating these devices. We then present an attack framework that can leverage tightly coupled and connected smart devices, such as mobile, wearable, and smart TV, to leak sensitive information inferred from individually non-sensitive data. Finally, we introduce a tool based on NLP techniques to identify potential privacy vulnerabilities on smart devices and propose an integrated solution to increase smart devices' security. This analysis helps close the gap between user's perception and reality regarding privacy risks within their smart ecosystem.
Edgardo Barsallo, Joshua David Oetting Majors, Aditya Vardhan Padala, Darren Wu, Aravind Machiry, Saurabh Bagchi
CODASPY1
2023 Security Properties of Virtual Remotes and SPOOKing their violations
abstract
As Smart TV devices become more prevalent in our lives, it becomes increasingly important to evaluate the security of these devices. In addition to a smart and connected ecosystem through apps, Smart TV devices expose a WiFi remote protocol, that provides a virtual remote capability and allows a WiFi enabled device (e.g., a Smartphone) to control the Smart TV. The WiFi remote protocol might pose certain security risks that are not present in traditional TVs. In this paper, we assess the security of WiFi remote protocols by first identifying the desired security properties so that we achieve the same level of security as in traditional TVs. Our analysis of four popular Smart TV platforms, Android TV, Amazon FireOS, Roku OS, and WebOS (for LG TVs), revealed that all these platforms violate one or more of the identified security properties. To demonstrate the impact of these flaws, we develop Spook, which uses one of the commonly violated properties of a secure WiFi remote protocol to pair an Android mobile as a software remote to an Android TV. Subsequently, we hijack the Android TV device through the device debugger, enabling complete remote control of the device. All our findings have been communicated to the corresponding vendors. Google acknowledged our findings as a security vulnerability, assigned it a CVE, and released patches to the Android TV OS to partially mitigate the attack. We argue that these patches provide a stopgap solution without ensuring that WiFi remote protocol has all the desired security properties. We design and implement a WiFi remote protocol in the Android ecosystem using ARM TrustZone. Our evaluation shows that the proposed defense satisfies all the security properties and ensures that we have the flexibility of virtual remote without compromising security.
Joshua David Oetting Majors, Edgardo Barsallo, Amiya Maji, Darren Wu, Saurabh Bagchi, Aravind Machiry
AsiaCCS2
2022 ORION and the Three Rights: Sizing, Bundling, and Prewarming for Serverless DAGs
Ashraf Mahgoub, Edgardo Barsallo, Karthick Shankar, Sameh Elnikety, Somali Chaterji, Saurabh Bagchi
OSDI2
2021 Hybrid Low-Power Wide-Area Mesh Network for IoT Applications
abstract
The recent advancement of the Internet of Things (IoT) enables the possibility of data collection from diverse environments using IoT devices. However, despite the rapid advancement of low-power communication technologies, the deployment of IoT networks still faces many challenges. In this article, we propose a hybrid, low-power, wide-area network (LPWAN) structure that can achieve wide-area communication coverage and low-power consumption on IoT devices by utilizing both sub-GHz long-range radio and 2.4-GHz short-range radio. Specifically, we constructed a low-power mesh network with LoRa, a physical-layer standard that can provide long-range (kilometers) point-to-point communication using custom time-division multiple access (TDMA). Furthermore, we extended the capabilities of the mesh network by enabling ANT, an ultralow-power, short-range communication protocol to satisfy data collection in dense device deployments. Third, we demonstrate the performance of the hybrid network with two real-world deployments at the Purdue University campus and at the university-owned farm. The results suggest that both networks have superior advantages in terms of cost, coverage, and power consumption vis-à-vis other IoT solutions, like LoRaWAN.
Xiaofan Jiang 0002, Heng Zhang 0016, Edgardo Barsallo, Nithin Raghunathan, Charilaos Mousoulis, Somali Chaterji, Dimitrios Peroulis, Ali Shakouri, Saurabh Bagchi
IEEE Internet Things J.3
2020 Vulcan: a state-aware fuzzing tool for wear OS ecosystem
abstract
This demo abstract introduces Vulcan, a fuzz testing tool for evaluating the robustness of wearable device by injecting intra-device and inter-device communication messages. Vulcan first builds a state-model of a wearable app by offline training then steers the app to a target state for injecting mutated messages. The target state of the app typically runs a high number of concurrent processes. By testing a set of 100 popular Wear OS apps, Vulcan was able to trigger 45 unique crashes and 18 system reboots. These system reboots are triggered by a fuzzing user-level app and we present a mitigation strategy to prevent it.
Edgardo Barsallo, Heng Zhang 0016, Amiya Kumar Maji, Saurabh Bagchi
MobiSys1
2020 Vulcan: lessons on reliability of wearables through state-aware fuzzing
abstract
As we look to use Wear OS (formerly known as Android Wear) devices for fitness and health monitoring, it is important to evaluate the reliability of its ecosystem. The goal of this paper is to understand the reliability weak spots in Wear OS ecosystem. We develop a state-aware fuzzing tool, Vulcan, without any elevated privileges, to uncover these weak spots by fuzzing Wear OS apps. We evaluate the outcomes due to these weak spots by fuzzing 100 popular apps downloaded from Google Play Store. The outcomes include causing specific apps to crash, causing the running app to become unresponsive, and causing the device to reboot. We finally propose a proof-of-concept mitigation solution to address the system reboot issue.
Edgardo Barsallo, Heng Zhang 0016, Amiya Kumar Maji, Kefan Xu, Saurabh Bagchi
MobiSys1
2019 MioStream: a peer-to-peer distributed live media streaming on the edge
Servio Palacios, Edgardo Barsallo, Bharat K. Bhargava
Multim. Tools Appl.3
2018 How Reliable is My Wearable: A Fuzz Testing-Based Study
abstract
As wearable devices like smartwatches and fitness monitors gain in popularity and are being touted for clinical purposes, it becomes important to evaluate the reliability of Android Wear OS and apps on such devices. To date there has been no study done by systematic error injection into the OS or the apps. We address this gap in this work. We develop and open source a fuzz testing tool for Android Wear apps and services, called Qui-Gon Jinn (QGJ). We perform an extensive fault injection study by mutating inter-process communication messages and UI events and direct about 1.5M such mutated events at 46 apps. These apps are divided into two categories: health/fitness and other. The results of our study show some patterns distinct from prior studies of Android. Over the years, input validation has improved and fewer NullPointerExceptions are seen, however, Android Wear apps crash from unhandled IllegalStateExceptions at a higher rate. There are occasional troubling cases of the entire device rebooting due to unprivileged mutated messages. Reassuringly the apps are quite robust to mutations of UI events with only 0.05% of them causing an app crash.
Edgardo Barsallo, Amiya Maji, Saurabh Bagchi
DSN1