Przemyslaw Szary

dblp:246/5563 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0002-7540-2333ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Identity and Access Management Architecture in the SILVANUS Project
abstract
SILVANUS is a scientific collaboration EU-funded project with the goal to mitigate the growing impact of wildfires caused by global climate change by implementing a comprehensive global fire prevention strategy. Due to the significant complexity and collaborative nature of the project which involves more than 50 parties, it is a challenge to ensure unified and governed security especially that the platform is based on heterogeneous and multi-component architecture. To ensure the security requirements are delivered, different security architecture perspectives need to be considered and one of these is identity and access management.
Pawel Rajba, Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Dawid Nastaj, Krzysztof Cabaj
ARES4
2024 Performance evaluation of Raspberry Pi 4 and STM32 Nucleo boards for security-related operations in IoT environments
abstract
At present, Internet of Things devices are revolutionizing and impacting increasingly more areas of our daily lives. However, there remain doubts related to the lack of sufficient security in the IoT ecosystem. As such devices have limitations in terms of resources such as computational power and batteries, adding security mechanisms is often perceived as an unnecessary burden, slowing the further expansion of IoT-based solutions and applications. In this study, an investigation is conducted to verify the possibility of applying security measures such as strong encryption without hindering the performance of IoT devices. This factor is especially important from the perspective of the European project SILVANUS, in which various IoT application scenarios are envisioned. Taking into account the above, in this work, an extensive experimental performance evaluation campaign is performed using the DTLS-based encryption of network traffic for two popular boards: Raspberry Pi 4 and STM32 Nucleo. The obtained results demonstrate that the utilization of strong encryption is feasible (with some limitations) on IoT devices, but the resulting performance or battery life is not a reasonable argument anymore to leave IoT ecosystems completely insecure.
Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk
Comput. Networks2
2023 Security Architecture in the SILVANUS project
abstract
SILVANUS is a new EU-funded project whose main objectives are to address the causes of wildfires in Europe. To achieve this aim, a dedicated platform for environmentally sustainable and climate-resilient forest management has been developed with the help of many state-of-the-art, modern technologies. One of the major challenges to solve when building such a heterogeneous, multi-component, multipurpose platform is to provide the necessary security architecture. It should ensure that only trusted users and devices (e.g., sensors, drones, UGVs, etc.) would be allowed to use it, and attackers or other third parties would not jeopardize its communication and assets. In this paper, we outline the main design principles, solutions, and mechanisms we have considered when building the security architecture for the SILVANUS platform. Moreover, we present the current state of development of this platform and the main challenges we have been facing.
Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk, Helen-Catherine Leligou, Marcin Przybyszewski, Rafal Kozik, Michal Choras
ARES3
2022 Performance Evaluation of DTLS Implementations on RIOT OS for Internet of Things Applications
abstract
The popularity, variety, and number of Internet of Things (IoT) devices and solutions have been increasing significantly with each passing year. This diversity of devices, and limited computational, memory, and battery resources make it difficult to apply effective security solutions. That is why dedicated mechanisms for the protection of IoT-based transmissions are developed. One of the most popular solutions is Datagram Transport Layer Security (DTLS), which allows securing datagram-based applications. In this paper, we investigate how efficient the three currently available DTLS implementations provided by the RIOT Operating System are. Based on the results obtained, interested parties can choose the DTLS module that has the best performance for the chosen IoT application.
Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk
ARES2
2020 Design and performance evaluation of reversible network covert channels
abstract
Covert channels nested within network traffic are important tools for allowing malware to act unnoticed or to stealthily exchange and exfiltrate information. Thus, understanding how to detect or mitigate their utilization is of paramount importance, especially to counteract the rise of increasingly sophisticated threats. In this perspective, the literature proposed various approaches, including distributed wardens, which can be used to collect traffic in different portions of the network and compare the samples to check for discrepancies revealing hidden communications. However, the use of some form of reversibility, i.e., being able to restore the exploited network carrier to its original form before the injection, can challenge such a detection scheme. Therefore, in this work we introduce and evaluate the performances of different techniques used to endow network covert channels with reversibility. Results indicate the feasibility of achieving reversibility but the used protocol plays a major role.
Przemyslaw Szary, Wojciech Mazurczyk, Steffen Wendzel, Luca Caviglione
ARES1
2019 Towards Reversible Storage Network Covert Channels
abstract
The use of network covert channels to improve privacy or support security threats has been widely discussed in the literature. As today, the totality of works mainly focuses on how to not disrupt the overt traffic flow and the performance of the covert channels in terms of undetectability and capacity. To not void the stealthiness of the channel, an important feature is the ability of restoring the carrier embedding the secret information into its original form. However, the development of such techniques mainly targets the domain of digital media steganography. Therefore, this paper applies the concept of reversible data hiding to storage network covert channels. To prove the effectiveness of our idea, a prototypical implementation of a channel exploiting IPv4 flows is presented along with its performance evaluation.
Wojciech Mazurczyk, Przemyslaw Szary, Steffen Wendzel, Luca Caviglione
ARES2