VLDB 2026 Research / reviewers in the wild / expert
Aleksi Peltonen
dblp:236/5170
· DBLP profile ↗
6ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0001-5131-1659ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Helm-ET: Reducing Exposure to Lateral Movement in Kubernetes ArtifactsabstractModern cloud applications consist of containerized microservices deployed to a virtual computing environment, such as a Kubernetes cluster. Policies are needed to block unintended and potentially harmful interactions between the microservices, which attackers could exploit for discovery and lateral move-ment. However, it is challenging for cluster administrators to define strict network policies because the interactions between the components are not clearly defined. Enabling them often requires manual inspection of the declarative configuration and the source code of the applications. This paper proposes a novel approach to creating Kubernetes network policies that restricts access between microservices within a cluster. Based on the principles of modularity and information hiding, we identify service composition patterns in cloud applications and use them to create network policies. The policy generation is implemented as an open-source tool, Helm-ET, which we evaluate on 451 Helm charts across three datasets. The results show that the proposed approach can significantly reduce the internal attack surface in the Kubernetes cluster (92.71 % less allowed connections), achieving comparable results to state-of-the-art tools. However, compared to other solutions, Helm-ET is faster (<100ms vs 79 seconds) and the policies before the application deplovment, Jacopo Bufalino, Jose Luiz Martin Navarro, Aleksi Peltonen, Tuomas Aura |
CLOUD | 3 |
| 2024 | Security Analysis of the Consumer Remote SIM Provisioning ProtocolabstractRemote SIM provisioning (RSP) for consumer devices is the protocol specified by the GSM Association for downloading SIM profiles into a secure element in a mobile device. The process is commonly known as eSIM, and it is expected to replace removable SIM cards. The security of the protocol is critical because the profile includes the credentials with which the mobile device will authenticate to the mobile network. In this article, we present a formal security analysis of the consumer RSP protocol. We model the multi-party protocol in applied pi calculus, define formal security goals, and verify them in ProVerif. The analysis shows that the consumer RSP protocol protects against a network adversary when all the intended participants are honest. However, we also model the protocol in realistic partial compromise scenarios where the adversary controls a legitimate participant or communication channel. The security failures in the partial compromise scenarios reveal weaknesses in the protocol design. The most important observation is that the security of RSP depends unnecessarily on it being encapsulated in a TLS tunnel. Also, the lack of pre-established identifiers means that a compromised download server anywhere in the world or a compromised secure element can be used for attacks against RSP between honest participants. Additionally, the lack of reliable methods for verifying user intent can lead to serious security failures. Based on the findings, we recommend practical improvements to RSP implementations, future versions of the specification, and mobile operator processes to increase the robustness of eSIM security. Abu Shohel Ahmed, Aleksi Peltonen, Mohit Sethi, Tuomas Aura |
ACM Trans. Priv. Secur. | 2 |
| 2022 | Exploring How Students Solve Open-ended Assignments: A Study of SQL Injection Attempts in a Cybersecurity CourseabstractResearch into computing and learning how to program has been ongoing for decades. Commonly, this research has been focused on novice learners and the difficulties they encounter, especially during CS1. Cybersecurity is a critical aspect in computing -- as a topic in university education as well as a core skill in the industry. In this study, we investigate how students solve open-ended assignments on a cybersecurity course offered to university students after two years of CS studies. Specifically, we looked at how students perform SQL injection attacks on an web application system, and study to what extent we can characterize the process in which they come up with successful injections. Our results show that there are distinguishable strategies used by individual students who seek to hack the system, where these approaches revolve around exploration and exploitation tactics. We also find evidence of learning due to a more pronounced use of exploitation in a subsequent similar assignment. Charles Koutcheme, Artturi Tilanterä, Aleksi Peltonen, Arto Hellas, Lassi Haaranen |
ITiCSE (1) | 3 |
| 2021 | A comprehensive formal analysis of 5G handoverabstract5G has been under standardization for over a decade and will drive the world's mobile technologies in the decades to come. One of the cornerstones of the 5G standard is its security, also for devices that move frequently between networks, such as autonomous vehicles, and must therefore be handed over from one network operator to another. We present a novel, comprehensive, formal analysis of the security of the device handover protocols specified in the 5G standard. Our analysis covers both handovers within the 5G core network, as well as fallback methods for backwards compatibility with 4G/LTE. We identify four main handover protocols and formally model them in the security protocol verification tool Tamarin. Using these models, we determine for each protocol the minimal set of security assumptions required for its intended security goals to be met. Understanding these requirements is essential when designing devices and other protocols that depend on the reliability and security of network handovers. Aleksi Peltonen, Ralf Sasse, David A. Basin |
WISEC | 1 |
| 2020 | Formal verification of misbinding attacks on secure device pairing and bootstrappingabstractIn identity misbinding attacks against authenticated key-exchange protocols, a legitimate but compromised participant manipulates the honest parties so that the victim becomes unknowingly associated with a third party. These attacks are well known, and resistance to misbinding is considered a critical requirement for security protocols on the Internet. In the context of device pairing, on the other hand, the attack has received little attention outside the trusted-computing community. This paper points out that most device pairing protocols are vulnerable to misbinding. Device pairing protocols are characterized by lack of a-priory information, such as identifiers and cryptographic roots of trust, about the other endpoint. Therefore, the devices in pairing protocols need to be identified by the user’s physical access to them. As case studies for demonstrating the misbinding vulnerability, we use Bluetooth and protocols that register new Internet of Things (IoT) devices to authentication servers on wireless networks. We have implemented the attacks. We also show how the attacks can be found in formal models of the protocols with carefully formulated correspondence assertions. The formal analysis yields a new type of double misbinding attack. While pairing protocols have been extensively modelled and analyzed, misbinding seems to be an aspect that has not previously received sufficient attention. Finally, we discuss potential ways to mitigate the threat and its significance to security of pairing protocols. Aleksi Peltonen, Mohit Sethi, Tuomas Aura |
J. Inf. Secur. Appl. | 1 |
| 2019 | Misbinding Attacks on Secure Device Pairing and BootstrappingabstractIn identity misbinding attacks against authenticated key-exchange protocols, a legitimate but compromised participant manipulates the honest parties so that the victim becomes unknowingly associated with a third party. These attacks are well known, and resistance to misbinding is considered a critical requirement for security protocols on the Internet. In the context of device pairing, on the other hand, the attack has received little attention outside the trusted-computing community. This paper points out that most device pairing protocols are vulnerable to misbinding. Device pairing protocols are characterized by lack of a-priory information, such as identifiers and cryptographic roots of trust, about the other endpoint. Therefore, the devices in pairing protocols need to be identified by the user's physical access to them. As case studies for demonstrating the misbinding vulnerability, we use Bluetooth and a protocol that registers new IoT devices to authentication servers on wireless networks. We have implemented the attacks. We also show how the attacks can be found in formal models of the protocols with carefully formulated correspondence assertions. The formal analysis yields a new type of double misbinding attack. While pairing protocols have been extensively modelled and analyzed, misbinding seems to be an aspect that has not previously received sufficient attention. Finally, we discuss potential ways to mitigate the threat and its significance to security of pairing protocols. Mohit Sethi, Aleksi Peltonen, Tuomas Aura |
AsiaCCS | 2 |