VLDB 2026 Research / reviewers in the wild / expert
Yakov Mallah
dblp:246/4703
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Risk Oriented Resource Allocation in Robotic SwarmabstractThe use of swarm robotics in various military and civil tasks is gaining popularity. During a mission, swarm members require access to different resources (both data and capabilities) to effectively perform their tasks. These resources may have different levels of sensitivity, and some of them may be highly classified and must be protected. Since the risk level of each swarm member may change during the mission, the decision on how to deploy the resources among the swarm members is crucial. In this research, we present a novel framework for distributing resources among the swarm members such that: (1) each member can access the resources it needs to perform its tasks (either locally or remotely), (2) the overall risk to the resources during the mission is minimized, and (3) the resources can be redeployed during the mission in response to changes in the risk level of swarm members. We evaluated the initial resource allocation provided by the proposed framework in various use cases and showed that it outperforms a baseline resource allocation approach in terms of the mission’s risk. We also evaluated dynamic, efficient heuristics and showed that they help maintain a low mission risk after the reallocation of resources following changes in the risk level of swarm members. Yakov Mallah, Yuval Elovici, Asaf Shabtai |
PST | 1 |
| 2023 | Characterization and Detection of Cross-Router Covert ChannelsabstractIn covert channel attacks, an adversary seeks various means to influence a tangible characteristic of a system, and then makes the systems leak information by measuring this characteristic. Covert channels are, by nature, very elusive. This makes it very difficult to identify them and defend against attacks that use these channels to leak sensitive information . Thus, they are a serious threat to the security of many systems. In this paper, we present two network timing covert channel attacks, and a defense mechanism against them. The purpose of the proposed attacks is to leak sensitive information between two logically separated (or isolated) networks that are hosted by a single router – one that is connected to the Internet, and another that is isolated and contains sensitive information. The attacks build on the fact that the response time of the router for a specific type of packet sent from a device that is connected to it is usually predictable, given the network topology . By interacting with the single shared router in a specific manner, an attacker can increase the router’s packet response time. The interaction is determined based on the information to be leaked, so the receiver (a computer located on the Internet-connected network) can measure the delayed packet response times and decode the sender’s signals (which operates from the isolated network) to receive classified information. The two classes of attacks presented in this work differ in the way that the delay is caused. In the cross-router covert channel (CRCC) attack, the sender overloads the router with control-plane packets; in the Wi-Fi micro-jamming attack, the sender uses a pre-installed implant to transmit single-tone signals in the 2.4GHz frequency range, disturbing the router’s packet transmissions . We showed that both attacks can influence a wide range of router brands and Wi-Fi capable devices and evaluated the optimal settings for both attacks when using different types of packets, transmission power, and data transmission rates. Our proposed defense mechanism is based on semi-supervised machine learning and deep learning algorithms , which are both used for novelty detection in network traffic. By detecting unusual traffic, we can identify the disturbances needed to leak the information. The system can then respond by blocking the suspicious devices that are involved in the attack. We evaluated the attacks in noisy and noise-free environments, successfully detecting both attacks in both environments. All the data and code, which includes the implementation of the attacks and the defense mechanism, is published as a benefit to the research community. Oren Shvartzman, Adar Ovadya, Kfir Zvi, Omer Shwartz, Rom Ogen, Yakov Mallah, Niv Gilboa, Yossef Oren |
Comput. Secur. | 6 |