Ryan Shah

dblp:232/3328 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
2since 2021 · last 2022
0000-0003-1348-8423ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2022 Can You Still See Me?: Identifying Robot Operations Over End-to-End Encrypted Channels
abstract
Connected robots play a key role in automating industrial workflows. Robots can expose sensitive operational information to remote adversaries. Despite the use of end-to-end encryption, a passive adversary could fingerprint and reconstruct the entire workflows being carried out and developing a detailed understanding of how facilities operate. In this paper, we investigate whether a remote passive attacker can accurately fingerprint robot movements and reconstruct operational workflows. Using a neural network-based traffic analysis approach, we found that attackers can predict TLS-encrypted robot movements with around \textasciitilde60% accuracy, increasing to near perfect accuracy in realistic settings. Ultimately, simply adopting best cybersecurity practices is not enough to stop even weak (passive) adversaries.
Ryan Shah, Chuadhry Mujeeb Ahmed, Shishir Nagaraja
WISEC1
2021 VoIPLoc: passive VoIP call provenance via acoustic side-channels
abstract
We propose VoIPLoc, a novel location fingerprinting technique and apply it to the VoIP call provenance problem. It exploits echo-location information embedded within VoIP audio to support fine-grained location inference. We found consistent statistical features induced by the echo-reflection characteristics of the location into recorded speech. These features are discernible within traces received at the VoIP destination, enabling location inference. We evaluated VoIPLoc by developing a dataset of audio traces received through VoIP channels over the Tor network. We show that recording locations can be fingerprinted and detected remotely with a low false-positive rate, even when a majority of the audio samples are unlabelled. Finally, we note that the technique is fully passive and thus undetectable, unlike prior art. VoIPLoc is robust to the impact of environmental noise and background sounds, as well as the impact of compressive codecs and network jitter. The technique is also highly scalable and offers several degrees of freedom terms of the fingerprintable space.
Shishir Nagaraja, Ryan Shah
WISEC2
2019 Poster: Unified Access Control for Surgical Robotics
abstract
Ensuring the accuracy of output of surgical robotics is vital, as an incision (during surgery) that is too deep could result in the death of the patient. A large contribution to the level of accuracy of components comes from its calibration. Calibration ensures the output is of high accuracy and is traceable to antecedent calibration units up to national standards. However, each of the levels in the calibration hierarchy have different security requirements (confidentiality and integrity), who may also be in conflict with each other. We propose a hybrid access control model for surgical robotics that maintains integrity and confidentiality requirements across a lattice structure and manages conflicts of interests.
Ryan Shah, Shishir Nagaraja
SACMAT1
2019 Clicktok: click fraud detection using traffic analysis
abstract
Advertising is a primary means for revenue generation for millions of websites and smartphone apps. Naturally, a fraction abuse ad networks to systematically defraud advertisers of their money. Modern defences have matured to overcome some forms of click fraud but measurement studies have reported that a third of clicks supplied by ad networks could be clickspam. Our work develops novel inference techniques which can isolate click fraud attacks using their fundamental properties. We propose two defences, mimicry and bait-click, which provide clickspam detection with substantially improved results over current approaches. Mimicry leverages the observation that organic clickfraud involves the reuse of legitimate click traffic, and thus isolates clickspam by detecting patterns of click reuse within ad network clickstreams. The bait-click defence leverages the vantage point of an ad network to inject a pattern of bait clicks into a user's device. Any organic clickspam generated involving the bait clicks will be subsequently recognisable by the ad network. Our experiments show that the mimicry defence detects around 81% of fake clicks in stealthy (low rate) attacks, with a false-positive rate of 110 per hundred thousand clicks. Similarly, the bait-click defence enables further improvements in detection, with rates of 95% and a reduction in false-positive rates of between 0 and 30 clicks per million - a substantial improvement over current approaches.
Shishir Nagaraja, Ryan Shah
WiSec2