VLDB 2026 Research / reviewers in the wild / expert
Ariel Stulman
dblp:26/6706
· DBLP profile ↗
15ranked-venue papers
0as first author
7since 2021 · last 2025
0000-0003-1191-007XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Achieving manet protection without the use of superfluous fictitious nodes
Nadav Schweitzer, Liad Cohen, Tirza Hirst, Amit Dvir, Ariel Stulman |
Comput. Commun. | 5 |
| 2024 | SPRINKLER: A Multi-RPL Man-in-the-Middle Identification Scheme in IoT NetworksabstractCyber-threat protection is one of the most challenging research branches of Internet-of-Things (iot). With the exponential increase of tiny connected devices, the battle between friend and foe intensifies. Unfortunately,iotdevices offer very limited security features, laying themselves wide open to new attacks, inhibiting the expected global adoption ofiottechnologies. Moreover, existing prevention and mitigation techniques and intrusion detection systems handle attack anomalies rather than the attack itself while using a significant amount of the network resources.rpl, the de-facto routing protocol foriot, proposes minimal security features that cannot handle internal attacks. Hence, in this paper, we proposesprinkler, which identifies the specificthingthat is under attack by an adversarial Man-in-The-Middle.sprinkleruses the multi-instance feature ofrplto identify the adversary. The proposed solution adheres to two basic principles: it only uses pre-existing standard routing protocols and does not rely on a centralized or trusted third-party node such as a certificate authority. All information must be gleaned by each node using only primitives that already exist in the underlying communication protocol, which excludes any training dataset. Simulations show thatsprinkleradds minimal maintenance and energy expenditure while pinpointing deterministically the attacker in the network. In particular,sprinklerhas a message delivery rate and detection rate of 100%. Aviram Zilberman, Amit Dvir, Ariel Stulman |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Identifying a Malicious Node in a UAV NetworkabstractWith the emergence of new and exciting wireless technologies and capabilities, Unmanned Aerial Vehicles (UAVs) and the services they allow, stand to be a major influencer in our daily lives. Unfortunately, they are also prone to a plethora of security issues. Existing studies propose both prevention and identification schemes for various routing attacks. They do not, however, preclude future malicious attempts. Hence, in this work we identify the specific UAV that is compromising the network, with the specific purpose of flushing it out. The proposed solution combines secret sharing and cheating identification schemes with multi-path routing protocols, to deterministically pinpoint the compromised node that is cheating the UAV flock. It assures a quiet identification of the adversary creating new opportunities for its attack, even when facing a sophisticated adversary that selectively modifies data messages or re-routes them in within the network. We took special care to allow for applicability in existing networks by adhering to two basic principles: only using pre-existing standard routing protocols and not relying on a centralized or trusted third party node such as a base station. All information must be gleaned by each node using only primitives which already exist in the underlying communication protocols. We provide a rigorous mathematical proof of the cost bounds, and run simulations to prove feasibility. Moreover, the simulations show a 100% detection rate and message delivery rate. The communication overhead varies, on average, between$0.4\cdot 10^{6}-0.8\cdot 10^{6}$bytes, depending on various parameters such as the network size and the reception rate of network nodes. The time required varies between 0.2–0.4 seconds, depending mainly on the network size. Aviram Zilberman, Ariel Stulman, Amit Dvir |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Persuasive: A node isolation attack variant for OLSR-based MANETs and its mitigation
Nadav Schweitzer, Liad Cohen, Amit Dvir, Ariel Stulman |
Ad Hoc Networks | 4 |
| 2023 | Network wormhole attacks without a traditional wormhole
Nadav Schweitzer, Amit Dvir, Ariel Stulman |
Ad Hoc Networks | 3 |
| 2022 | Word embedding dimensionality reduction using dynamic variance thresholding (DyVaT)
Avraham Treistman, Dror Mughaz, Ariel Stulman, Amit Dvir |
Expert Syst. Appl. | 3 |
| 2021 | IoT and HIP's Opportunistic ModeabstractKey sharing has always been a complex issue. It became even more challenging for the Internet of Things (IoT), where a trusted third party for global management rarely exists. With authentication and confidentiality lacking, things resort to a leap of faith (LoF) paradigm where it is assumed that no attacker is present during the initial configuration. In this paper we focus on the Host Identity Protocol (HIP), specifically designed to provide mobility and multihoming capabilities. Although HIP is normally based on many strict security mechanisms (e.g., DNSSEC), it also provides a better than nothing opportunistic mode, based on the LoF paradigm, which is to be used when other more trusted mechanisms are not available. In this paper, we analyze different MiTM attacks which might occur under this opportunistic mode. Taking advantage of HIP's multihoming capabilities, we propose two key spraying techniques which strengthen the opportunistic mode's security. The first technique spreads the four key-exchange messages among different networks, while the second spreads fractions of one of those messages. Evaluation of these techniques is provided, demonstrating the major benefit of our proposal. Adel Fuchs, Ariel Stulman, Andrei V. Gurtov |
IEEE Trans. Mob. Comput. | 2 |
| 2020 | Effectiveness of DCFM on different mobility modelsabstractSimulation based network protocol testing requires that one model reality correctly. Mis-modelling can render results invalid. Hence, one must determine the context in which a solution is to be implemented for the results to be meaningful. In this work, we investigate whether the security augmentation technique DCFM (denial contradictions with fictitious nodes) for OLSR based mobile ad-hoc networks (MANET) is valid for multiple contexts. We accomplish this by running the node isolation attack and DCFM defense on a variety of mobility models, comparing the results. We show that for most models the technique performs well, while for a specific scenario (e.g. street based) it fails. Additionally we describe the infrastructure that was built to support the street based simulations. Nadav Schweitzer, Ariel Stulman |
WINCOM | 2 |
| 2019 | Network bottlenecks in OLSR based ad-hoc networks
Nadav Schweitzer, Ariel Stulman, Tirza Hirst, Roy David Margalit, Asaf Shabtai |
Ad Hoc Networks | 2 |
| 2017 | Hardening Opportunistic HIPabstractAs mobile and multi-homed devices are becoming ubiquitous, the need for a dynamic, yet secure communication protocol is unavoidable. The Host Identity Protocol (HIP) was constructed to meet this requirement; to provide significantly more secure mobility and multi-homing capabilities. HIP opportunistic mode, which is to be used when other, more trusted mechanisms are lacking, is based on a leap of faith (LoF) paradigm. In this paper, we analyze different Man in the middle (MiTM) attacks which might occur under this LoF, and propose a set of tweaks for hardening opportunistic HIP (HOH) that strengthen opportunistic mode's security. Adel Fuchs, Ariel Stulman, Andrei V. Gurtov |
MSWiM | 2 |
| 2017 | Authorization Enforcement DetectionabstractOne of the many aspects of website security is the question of authorization breach. It is an attack in which un-authorized entities are allowed access to restricted space. As the complexity of website code increases, the human capability of handling authorization rules and semantics decreases accordingly. In this project, we demonstrate an automated authorization enforcement detection (AED) tool which allows website administrators to check if they have authorization vulnerabilities on their sites. Ehood Porat, Shmuel Tikochinski, Ariel Stulman |
SACMAT | 3 |
| 2017 | Contradiction Based Gray-Hole Attack Minimization for Ad-Hoc NetworksabstractAlthough quite popular for the protection for ad-hoc networks (MANETs, IoT, VANETs, etc.), detection & mitigation techniques only function after the attack has commenced. Prevention, however, attempts at thwarting an attack before it is executed. Both techniques can be realized either by the collective collaboration of network nodes (i.e., adding security messages to protocols) or by internal deduction of attack state. In this paper, we propose a method for minimizing the gray-hole DoS attack. Our solution assumes no explicit node collaboration, with each node using only internal knowledge gained by routine routing information. The technique was evaluated using five different threat models (different attacker capabilities), allowing for a better understanding of the attack surface and its prevention. Our simulation results show a decrease of up to 51 percent in previously dropped packet, greatly minimizing gray-hole attack effectiveness. Nadav Schweitzer, Ariel Stulman, Roy David Margalit, Asaf Shabtai |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | Neighbor Contamination to Achieve Complete Bottleneck ControlabstractBlack-holes, gray-holes and, wormholes, are devastating to the correct operation of any network. These attacks (among others) are based on the premise that packets will travel through compromised nodes, and methods exist to coax routing into these traps. Detection of these attacks are mainly centered around finding the subversion in action. In networks, bottleneck nodes -- those that sit on many potential routes between sender and receiver -- are an optimal location for compromise. Finding naturally occurring path bottlenecks, however, does not entitle network subversion, and as such are more difficult to detect. The dynamic nature of mobile ad-hoc networks (manets) causes ubiquitous routing algorithms to be even more susceptible to this class of attacks. Finding perceived bottlenecks in an olsr based manet, is able to capture between 50%-75% of data. In this paper we propose a method of subtly expanding perceived bottlenecks into complete bottlenecks, raising capture rate up to 99%; albeit, at high cost. We further tune the method to reduce cost, and measure the corresponding capture rate. Nadav Schweitzer, Ariel Stulman, Asaf Shabtai |
MSWiM | 2 |
| 2016 | Mitigating Denial of Service Attacks in OLSR Protocol Using Fictitious NodesabstractWith the main focus of research in routing protocols for Mobile Ad-Hoc Networks (MANET) geared towards routing efficiency, the resulting protocols tend to be vulnerable to various attacks. Over the years, emphasis has also been placed on improving the security of these networks. Different solutions have been proposed for different types of attacks, however, these solutions often compromise routing efficiency or network overload. One major DOS attack against the Optimized Link State Routing protocol (OLSR) known as the node isolation attack occurs when topological knowledge of the network is exploited by an attacker who is able to isolate the victim from the rest of the network and subsequently deny communication services to the victim. In this paper, we suggest a novel solution to defend the OLSR protocol from node isolation attack by employing the same tactics used by the attack itself. Through extensive experimentation, we demonstrate that 1) the proposed protection prevents more than 95 percent of attacks, and 2) the overhead required drastically decreases as the network size increases until it is non-discernable. Last, we suggest that this type of solution can be extended to other similar DOS attacks on OLSR. Nadav Schweitzer, Ariel Stulman, Asaf Shabtai, Roy David Margalit |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Virtual Mobile Ad-hoc NetworksabstractUbiquitous use of MANETs (Mobile Ad-hoc Networks) is greatly hindered by the technological cap on broadcast distances. In this work we propose a method of extending the cover area of a MANETs by taking advantage of pre-existing mesh networks among routers. This is done in a transparent manner, so participating ad-hoc nodes are oblivious to this mechanism. They see both ad-hoc networks as one, effectively creating a large virtual network. We implemented a proof-ofconcept that uses a MANET client application over the Android operating system for providing voice calls between smartphones. Jonathan Lahav, Ariel Stulman |
MASS | 2 |