VLDB 2026 Research / reviewers in the wild / expert
Vincent Lenders
dblp:75/5939
· DBLP profile ↗
87ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0002-2289-3722ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 43 · 15 since 2021Computer networks · 32 · 7 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lightweight Internet Bandwidth Allocation and Isolation with Fractional Fair Shares
Marc Wyss, Yih-Chun Hu, Vincent Lenders, Roland Meier, Adrian Perrig |
NDSS | 3 |
| 2025 | Universal Spoofing of Real-World Aircraft Multilaterationabstractpeer reviewed Oliver Senn, Giorgio Tresoldi, Daniel Moser, Vincent Lenders, Martin Strohmeier |
WISEC | 4 |
| 2024 | HydroLab: A Versatile Hydroelectric Power Lab for Security Research and Education
Sebastian Obermeier 0001, Giorgio Tresoldi, Bernhard Tellenbach, Vincent Lenders |
SECRYPT | 4 |
| 2024 | Wireless Signal Injection Attacks on VSAT Satellite Modems
Robin Bisping, Johannes Willbold, Martin Strohmeier, Vincent Lenders |
USENIX Security Symposium | 4 |
| 2024 | RECORD: A RECeption-Only Region Determination Attack on LEO Satellite Users
Eric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. Schmitt |
USENIX Security Symposium | 3 |
| 2024 | On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)
Giacomo Longo, Martin Strohmeier, Enrico Russo 0001, Alessio Merlo, Vincent Lenders |
USENIX Security Symposium | 5 |
| 2024 | VSAsTer: Uncovering Inherent Security Issues in Current VSAT System PracticesabstractRecent geopolitical events have exposed our critical dependence on the wireless infrastructure used to facilitate worldwide communication. State-sponsored groups are actively attacking and exploiting space-based communication networks, causing outages and serious economic damage. Despite initial research findings pointing out a lack of security, such networks enjoy growing adoption and are still placed at the heart of today's communication infrastructure, ranging form the transportation sector over oil rigs to consumer internet. Worryingly, the command and control networks that support this satellite-based communication have received little attention from the security community so far. Johannes Willbold, Moritz Schloegel, Robin Bisping, Martin Strohmeier, Thorsten Holz, Vincent Lenders |
WISEC | 6 |
| 2024 | SkyPos: Real-World Evaluation of Self-Positioning With Aircraft Signals for IoT DevicesabstractPositioning based on aircraft signals has been proposed as an alternative to satellite-based positioning systems (e.g. GPS). However, so far, no deployment of this technique exists, and the real-world performance remains unclear. This paper contributes at better understanding the performance tradeoffs under realistic conditions. We implement SkyPos, a localization system for GPS-denied areas or location integrity that opportunistically uses the large availability of aircraft signals to self-localize receivers. We analyze SkyPos with data collected from hundreds of sensors and thousands of aircraft around Europe. Our results show that we can achieve median accuracy down to 10m in seconds, enabling almost real-time positioning or location verification using aircraft signals at scale. Yago Lizarribar 0001, Domenico Giustiniano, Gérôme Bovet, Vincent Lenders |
IEEE J. Sel. Areas Commun. | 4 |
| 2023 | FABRID: Flexible Attestation-Based Routing for Inter-Domain Networks
Cyrill Krähenbühl, Marc Wyss, David A. Basin, Vincent Lenders, Adrian Perrig, Martin Strohmeier |
USENIX Security Symposium | 4 |
| 2022 | On the Security of the FLARM Collision Warning SystemabstractIn the past decade, the vulnerability of aircraft communications against low-resourced attackers has received significant attention both in the information security community and from aviation industry and regulators. Until now, research on attacks against such communications technologies has focused on larger aircraft, neglecting the technologies used in light aircraft and unmanned aerial vehicles (UAV). As such lighter aircraft make up a large and growing majority of both airspace users and casualties, this is a glaring oversight from a security and safety perspective. Boya Wang, Giorgio Tresoldi, Martin Strohmeier, Vincent Lenders |
AsiaCCS | 4 |
| 2022 | High Data Throughput Exfiltration Through Video Cable Emanations
Llorenç Romá Álvarez, Daniel Moser, Vincent Lenders |
CRITIS | 3 |
| 2022 | FPGA-to-CPU Undervolting AttacksabstractFPGAs are proving useful and attractive for many applications, thanks to their hardware reconfigurability, low power, and high-degree of parallelism. As a result, modern embedded systems are often based on systems-on-chip (SoCs), where CPUs and FPGAs share the same die. In this paper, we demonstrate the first undervolting attack in which the FPGA acts as an aggressor while the CPU, residing on the same SoC, is the victim. We show that an adversary can use the FPGA fabric to create a significant supply voltage drop which, in turn, faults the software computation performed by the CPU. Additionally, we show that an attacker can, with an even higher success rate, execute a denial-of-service attack, without any modification of the underlying hardware or the power distribution network. Our work exposes a new electrical-level attack surface, created by tight integration of CPUs and FPGAs in modern SoCs, and incites future research on countermeasures. Dina Mahmoud, Samah Hussein, Vincent Lenders, Mirjana Stojilovic |
DATE | 3 |
| 2022 | ditto: WAN Traffic Obfuscation at Line Rate
Roland Meier, Vincent Lenders, Laurent Vanbever |
NDSS | 2 |
| 2022 | Aggregate-based congestion control for pulse-wave DDoS defenseabstractPulse-wave DDoS attacks are a new type of volumetric attack formed by short, high-rate traffic pulses. Such attacks target the Achilles' heel of state-of-the-art DDoS defenses: their reaction time. By continuously adapting their attack vectors, pulse-wave attacks manage to render existing defenses ineffective. Albert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent Vanbever |
SIGCOMM | 3 |
| 2022 | An Experimental Study of GPS Spoofing and Takeover Attacks on UAVs
Harshad Sathaye, Martin Strohmeier, Vincent Lenders, Aanjhan Ranganathan |
USENIX Security Symposium | 3 |
| 2021 | Studying Neutrality in Cyber-Space: a Comparative Geographical Analysis of Honeypot Responses
Martin Strohmeier, James Pavur, Ivan Martinovic, Vincent Lenders |
CRITIS | 4 |
| 2021 | QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary Orbit
James Pavur, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
NDSS | 3 |
| 2021 | Orbit-based authentication using TDOA signatures in satellite networksabstractGiven the nature of satellites orbiting the Earth on a fixed trajectory, in principle, it is interesting to investigate how this invariant can be exploited for security purposes. In particular, satellite orbit information can be retrieved from public databases. Using time difference of arrival (TDOA) measurements from multiple receivers, we can check this orbit information against a corresponding TDOA-based signature of the satellite. In that sense, we propose an orbit-based authentication scheme for down-link satellite communications in this paper. To investigate the properties and fundamentals of our novel TDOA signature scheme we study two satellite systems at different altitudes: Iridium and Starlink. Eric Jedermann, Martin Strohmeier, Matthias Schäfer 0002, Jens B. Schmitt, Vincent Lenders |
WISEC | 5 |
| 2021 | Classi-Fly: Inferring Aircraft Categories from Open DataabstractIn recent years, air traffic communication data has become easy to access, enabling novel research in many fields. Exploiting this new data source, a wide range of applications have emerged, from weather forecasting to stock market prediction, or the collection of intelligence about military and government movements. Typically, these applications require knowledge about the metadata of the aircraft, specifically its operator and the aircraft category. armasuisse Science + Technology, the R&D agency for the Swiss Armed Forces, has been developing Classi-Fly, a novel approach to obtain metadata about aircraft based on their movement patterns. We validate Classi-Fly using several hundred thousand flights collected through open source means, in conjunction with ground truth from publicly available aircraft registries containing more than 2 million aircraft. We show that we can obtain the correct aircraft category with an accuracy of greater than 88%. In cases, where no metadata is available, this approach can be used to create the data necessary for applications working with air traffic communication. Finally, we show that it is feasible to automatically detect particular sensitive aircraft such as police and surveillance aircraft using this method. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
ACM Trans. Intell. Syst. Technol. | 3 |
| 2021 | Event Detection on Microposts: A Comparison of Four ApproachesabstractMicroblogging services such as Twitter are important, up-to-date, and live sources of information on a multitude of topics and events. An increasing number of systems use such services to detect and analyze events in real-time as they unfold. In this context, we recently proposed ArmaTweet-a system developed in collaboration among armasuisse and the Universities of Oxford and Fribourg to support semantic event detection on Twitter streams. Our experiments have shown that ArmaTweet is successful at detecting many complex events that cannot be detected by simple keyword-based search methods alone. Building up on this work, we explore in this paper several approaches for event detection on microposts. In particular, we describe and compare four different approaches based on keyword search (Plain-Seed-Query), information retrieval (Temporal Query Expansion), Word2Vec word embeddings (Embedding), and semantic retrieval (ArmaTweet). We provide an extensive empirical evaluation of these techniques using a benchmark dataset of about 200 million tweets on six event categories that we collected. While the performance of individual systems varies depending on the event category, our results show that ArmaTweet outperforms the other approaches on five out of six categories, and that a combined approach offers highest recall without adversely affecting precision of event detection. Akansha Bhardwaj, Albert Blarer, Philippe Cudré-Mauroux, Vincent Lenders, Boris Motik, Axel Tanner, Alberto Tonon |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2020 | SkySense: terrestrial and aerial spectrum use analysed using lightweight sensing technology with weather balloonsabstractGiven the availability of lightweight radio and processing technology, it becomes feasible to imagine spectrum sensing systems using weather balloons. Such balloons navigate the airspace up to 40 km, and can provide a bird's eye and clear view of terrestrial, as well as aerial spectrum use. In this paper, we present SkySense, which is an extension of the Electrosense sensing framework with mobile GPS-located sensors and local data logging. In addition, we present 6 different sensing campaigns, targeting multiple terrestrial or aerial technologies such as ADS-B, AIS or LTE. For instance, for ADS-B, we can clearly conclude that the number of airplanes that are detected is the same for each balloon altitude, but the message reception rate decreases strongly with altitude because of collisions. For each sensing campaign, the dataset is described, and some example spectrum analysis results are presented. In addition, we analyse and quantify important trends visible when sensing from the sky, such as temperature and hardware variations, increased ambient interference levels, as well as hardware limitations of the lightweight system. A key challenge is the automatic gain control and dynamic range of the system, as a radio navigating over 30km, sees a very wide range of possible signal levels. All data is publicly available through the Electrosense framework, to encourage the spectrum sensing community to further analyse the data or motivate further measurement campaigns using weather balloons. Brecht Reynders, Franco Minucci, Erma Perenda, Hazem Sallouha, Roberto Calvo-Palomino, Yago Lizarribar 0001, Markus Fuchs, Matthias Schäfer 0002, Markus Engel, Bertold Van den Bergh, Sofie Pollin, Domenico Giustiniano, Gérôme Bovet, Vincent Lenders |
MobiSys | 14 |
| 2020 | A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic Systems
Matthew Smith 0006, Martin Strohmeier, Jon Harman, Vincent Lenders, Ivan Martinovic |
NDSS | 4 |
| 2020 | A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsabstractVery Small Aperture Terminals (VSAT) have revolutionized maritime operations. However, the security dimensions of maritime VSAT services are not well understood. Historically, high equipment costs have acted as a barrier to entry for both researchers and attackers. In this paper we demonstrate a substantial change in threat model, proving practical attacks against maritime VSAT networks with less than $400 of widely-available television equipment. This is achieved through GSExtract, a purpose-built forensic tool which enables the extraction of IP traffic from highly corrupted VSAT data streams.The implications of this threat are assessed experimentally through the analysis of more than 1.3 TB of real-world maritime VSAT recordings encompassing 26 million square kilometers of coverage area. The underlying network platform employed in these systems is representative of more than 60% of the global maritime VSAT services market. We find that sensitive data belonging to some of the world's largest maritime companies is regularly leaked over VSAT ship-to-shore communications. This threat is contextualized through illustrative case studies ranging from the interception and alteration of navigational charts to theft of passport and credit card details. Beyond this, we demonstrate the ability to arbitrarily intercept and modify TCP sessions under certain network configurations, enabling man-in-the-middle and denial of service attacks against ships at sea. The paper concludes with a brief discussion of the unique requirements and challenges for encryption in VSAT environments. James Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
SP | 4 |
| 2020 | Electrosense+: Crowdsourcing radio spectrum decoding using IoT receivers
Roberto Calvo-Palomino, Héctor Cordobés, Markus Engel, Markus Fuchs, Pratiksha Jain, Marc Liechti, Sreeraj Rajendran, Matthias Schäfer 0002, Bertold Van den Bergh, Sofie Pollin, Domenico Giustiniano, Vincent Lenders |
Comput. Networks | 12 |
| 2019 | 28 Blinks Later: Tackling Practical Challenges of Eye Movement BiometricsabstractIn this work we address three overlooked practical challenges of continuous authentication systems based on eye movement biometrics: (i) changes in lighting conditions, (ii) task dependent features and the (iii) need for an accurate calibration phase. We collect eye movement data from 22 participants. To measure the effect of the three challenges, we collect data while varying the experimental conditions: users perform four different tasks, lighting conditions change over the course of the session and we collect data related to both accurate (user-specific) and inaccurate (generic) calibrations. To address changing lighting conditions, we identify the two main sources of light, i.e., screen brightness and ambient light, and we propose a pupil diameter correction mechanism based on these. We find that such mechanism can accurately adjust for the pupil shrinking or expanding in relation to the varying amount of light reaching the eye. To account for inaccurate calibrations, we augment the previously known feature set with new features based on binocular tracking, where the left and the right eye are tracked separately. We show that these features can be extremely distinctive even when using a generic calibration. We further apply a cross-task mapping function based on population data which systematically accounts for the dependency of features to tasks (e.g., reading a text and browsing a website lead to different eye movement dynamics). Using these enhancements, even while relaxing assumptions about the experimental conditions, we show that our system achieves significantly lower error rates compared to previous work. For intra-task authentication, without user-specific calibration and in variable screen brightness and ambient lighting, we achieve an equal error rate of 3.93% with only two minutes of training data. For the same setup but with constant screen brightness (e.g., as for a reading task) we can achieve equal error rates as low as of 1.88%. Simon Eberz, Giulio Lovisotto, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
CCS | 4 |
| 2019 | (Self) Driving Under the Influence: Intoxicating Adversarial Network InputsabstractTraditional network control planes can be slow and require manual tinkering from operators to change their behavior. There is thus great interest in a faster, data-driven approach that uses signals from real-time traffic instead. However, the promise of fast and automatic reaction to data comes with new risks: malicious inputs designed towards negative outcomes for the network, service providers, users, and operators. Roland Meier, Thomas Holterbach, Stephan Keck, Matthias Stähli, Vincent Lenders, Ankit Singla, Laurent Vanbever |
HotNets | 5 |
| 2019 | Collaborative wideband signal decoding using non-coherent receiversabstractIn recent years we are experiencing an important growth of interest for sensing the electromagnetic spectrum and making its access more agile. Emerging initiatives use low-cost receivers in large deployments for sensing the radio spectrum or collecting air-traffic signals at large scale. One of the major drawbacks of low-cost spectrum receivers is their limited sampling rate, which does not allow to decode wideband signals. In order to circumvent the hardware limitations of single receivers, we envision a scenario where non-coherent receivers sample the signal collaboratively to cover a larger bandwidth than the one of the single receiver and then, enable the signal reconstruction and decoding in the backend. We present a methodology to enable the signal reconstruction in the backend by multiplexing in frequency a certain number of noncoherent receivers in order to cover a signal bandwidth that would not otherwise be possible using a single receiver. We propose a method that does not use the knowledge of the modulation scheme, and has been designed to be transparent to the subsequent decoding process. As such, it is equivalent to the reception of the signal by a high-end receiver. We demonstrate and evaluate our approach with two non-coherent receivers which collaboratively sample an aviation signal of almost twice the bandwidth of each receiver. The experimental results show that, using two non-coherent receivers, our method is able to reconstruct and decode correctly more than 80% of data. Roberto Calvo-Palomino, Héctor Cordobés, Fabio Ricciato, Domenico Giustiniano, Vincent Lenders |
IPSN | 5 |
| 2019 | Digital radio signal cancellation attacks: an experimental evaluationabstractAttacker models are the cornerstone of any security assessment. As attacker's capabilities evolve over time, it is key to re-evaluate periodically if attacker models that were deemed unrealistic in the past might not pose a possible threat today. In this work, we evaluate the threat of wireless radio signal cancellation attacks in the face of recent advancements in software-defined radio attacker capabilities. Unlike classical radio interference or jamming attacker models which add noise to the legitimate communication, signal cancellation attacks aim at interfering destructively with the legitimate signal in order to remove those signals from the spectrum. While signal cancellation attacks were deemed unrealistic in the analogue domain, we analyse the system requirements to perform such attacks digitally using SDRs and evaluate the feasibility to launch such attacks against wireless communication systems such as GPS. Our evaluation reveals that signal cancellation attacks that manage to attenuate up to 40 dB of the signal at the receiver are feasible over the air. We further show that even complex CDMA signals such as GPS can be attenuated by 30 dB, even below a receiver's noise floor. These results indicate that digital signal cancellation attacks - especially against systems like GPS - should not be considered impossible per se, but deserve consideration when assessing the threat of attacks on wireless communication systems. Daniel Moser, Vincent Lenders, Srdjan Capkun |
WiSec | 2 |
| 2019 | Secrets in the sky: on privacy and infrastructure security in DVB-S satellite broadbandabstractDemands for ubiquitous global connectivity have sparked a satellite broadband renaissance. Secure satellite broadband is vital to ensuring that this growth does not beget unanticipated harm. Motivated by this need, this paper presents an experimental security analysis of satellite broadband signals using the Digital Video Broadcasting for Satellite (DVB-S) protocol. This analysis comprises 14 geostationary platforms encompassing over 100 million square kilometers of combined coverage area. James Pavur, Daniel Moser, Vincent Lenders, Ivan Martinovic |
WiSec | 3 |
| 2018 | The Real First Class? Inferring Confidential Corporate Mergers and Government Relations from Air Traffic CommunicationabstractThis paper exploits publicly available aircraft meta data in conjunction with unfiltered air traffic communication gathered from a global collaborative sensor network to study the privacy impact of large-scale aircraft tracking on governments and public corporations. First, we use movement data of 542 verified aircraft used by 113 different governments to identify events and relationships in the real world. We develop a spatio-temporal clustering method which returns 47 public and 18 non-public meetings attended by dedicated government aircraft over the course of 18 months. Additionally, we illustrate the ease of analyzing the long-term behavior and relationships of aviation users through the example of foreign governments visiting Europe. Secondly, we exploit the same types of data to predict potential merger and acquisition (M&A) activities by 36 corporations listed on the US and European stock markets. We identify seven M&A cases, in all of which the buyer has used corporate aircraft to visit the target prior to the official announcement, on average 61 days before. Finally, we analyze five existing technical and non-technical mitigation options available to the individual stakeholders. We quantify their popularity and effectiveness, finding that despite their current widespread use, they are ineffective against the presented exploits. Consequently, we argue that regulatory and technical changes are required to be able to protect the privacy of non-commercial aviation users in the future. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
EuroS&P | 3 |
| 2018 | Demo: Electrosense - spectrum sensing with increased frequency range
Franco Minucci, Sreeraj Rajendran, Bertold Van den Bergh, Sofie Pollin, Domenico Giustiniano, Héctor Cordobés, Roberto Calvo-Palomino, Markus Fuchs, Vincent Lenders |
EWSN | 9 |
| 2018 | Nanosecond-precision time-of-arrival estimation for aircraft signals with low-cost SDR receiversabstractPrecise Time-of-Arrival (TOA) estimations of aircraft and drone signals are important for a wide set of applications including aircraft/drone tracking, air traffic data verification, or self-localization. Our focus in this work is on TOA estimation methods that can run on low-cost software-defined radio (SDR) receivers, as widely deployed in Mode S / ADS-B crowdsourced sensor networks such as the OpenSky Network. We evaluate experimentally classical TOA estimation methods which are based on a cross-correlation with a reconstructed message template and find that these methods are not optimal for such signals. We propose two alternative methods that provide superior results for real-world Mode S / ADS-B signals captured with low-cost SDR receivers. The best method achieves a standard deviation error of 1.5 ns. Roberto Calvo-Palomino, Fabio Ricciato, Blaz Repas, Domenico Giustiniano, Vincent Lenders |
IPSN | 5 |
| 2018 | Data fusion for hybrid and autonomous time-of-flight positioningabstractExisting mobile devices such as smartphones rely on a multi-radio access technology (RAT) architecture to provide pervasive location information in various environmental contexts as the user is moving. Yet, existing architectures consider the different localization technologies as monolithic entities and choose the final navigation position from the RAT that is expected to provide the highest accuracy. In contrast, we propose to fuse timing range measurements of diverse radio technologies in order to circumvent the limitations of the individual radio access technologies. We take a first step in this direction and propose to fuse timing measurements of satellite navigation systems and WiFi networks. We introduce different novel methods such as a data fuser, an estimator of WiFi ToF distance and a geometrical-statistical approach to best fuse the set of ranges in presence of a rich set of measurements. Experimental results show that our solution allows the mobile device to efficiently position itself in diverse challenging scenarios. Aymen Fakhreddine, Domenico Giustiniano, Vincent Lenders |
IPSN | 3 |
| 2018 | Monitoring meteorological parameters with crowdsourced air traffic control dataabstractUp-to-date meteorological information about upper air conditions is crucial for accurate weather modeling and forecasting. Existing techniques to sense meteorological parameters in the atmosphere are costly and provide only limited temporal and spatial sensing resolutions. In this paper, we propose crowdsourcing air traffic control data as a new cost-efficient method to achieve a high temporal and spatial resolution, and large coverage. Our solution leverages Secondary Surveillance Radar Mode S and ADS-B transponder signals that are continuously transmitted by aircraft for air traffic control purposes. It builds on signals captured by the OpenSky Network, a global-scale sensor network crowdsourcing 15+ billions of transponder messages per day from aircraft up to an altitude of 13 km. Based on the decoded data, we infer meteorological conditions such as air temperature, wind speed, wind direction and atmospheric pressure. Our evaluation demonstrates that our approach is effective at estimating these parameters with high resolutions along the tracks of more than 50 percent of all aircraft monitored by the OpenSky Network. Our method delivers estimations for temperature with 0.11°C, wind speed with 0.09 m/s, wind direction with 1.00°, and air pressure with 0.10 hPa average deviation, making those measurements suitable for the assimilation in numerical weather models. Roman Trüb, Daniel Moser, Matthias Schäfer 0002, Rui Pinheiro, Vincent Lenders |
IPSN | 5 |
| 2018 | When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across ContextsabstractAttacks on behavioral biometrics have become increasingly popular. Most research has been focused on presenting a previously obtained feature vector to the biometric sensor, often by the attacker training themselves to change their behavior to match that of the victim. However, obtaining the victim's biometric information may not be easy, especially when the user's template on the authentication device is adequately secured. As such, if the authentication device is inaccessible, the attacker may have to obtain data elsewhere. In this paper, we present an analytic framework that enables us to measure how easily features can be predicted based on data gathered in a different context (e.g., different sensor, performed task or environment). This framework is used to assess how resilient individual features or entire biometrics are against such cross-context attacks. In order to be able to compare existing biometrics with regard to this property, we perform a user study to gather biometric data from 30 participants and five biometrics (ECG, eye movements, mouse movements, touchscreen dynamics and gait) in a variety of contexts. We make this dataset publicly available online. Our results show that many attack scenarios are viable in practice as features are easily predicted from a variety of contexts. All biometrics include features that are particularly predictable (e.g., amplitude features for ECG or curvature for mouse movements). Overall, we observe that cross-context attacks on eye movements, mouse movements and touchscreen inputs are comparatively easy while ECG and gait exhibit much more chaotic cross-context changes. Simon Eberz, Giulio Lovisotto, Andrea Patanè, Marta Z. Kwiatkowska, Vincent Lenders, Ivan Martinovic |
IEEE Symposium on Security and Privacy | 5 |
| 2018 | Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksabstractThe aviation industry's increasing reliance on GPS to facilitate navigation and air traffic monitoring opens new attack vectors with the purpose of hijacking UAVs or interfering with air safety. We propose Crowd-GPS-Sec to detect and localize GPS spoofing attacks on moving airborne targets such as UAVs or commercial airliners. Unlike previous attempts to secure GPS, Crowd-GPS-Sec neither requires any updates of the GPS infrastructure nor of the airborne GPS receivers, which are both unlikely to happen in the near future. In contrast, Crowd-GPS-Sec leverages crowdsourcing to monitor the air traffic from GPS-derived position advertisements that aircraft periodically broadcast for air traffic control purposes. Spoofing attacks are detected and localized by an independent infrastructure on the ground which continuously analyzes the contents and the times of arrival of these advertisements. We evaluate our system with real-world data from a crowdsourced air traffic monitoring sensor network and by simulations. We show that Crowd-GPS-Sec is able to globally detect GPS spoofing attacks in less than two seconds and to localize the attacker up to an accuracy of 150 meters after 15 minutes of monitoring time. Kai Jansen, Matthias Schäfer 0002, Daniel Moser, Vincent Lenders, Christina Pöpper, Jens B. Schmitt |
IEEE Symposium on Security and Privacy | 4 |
| 2018 | NetHide: Secure and Practical Network Topology Obfuscation
Roland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever, Martin T. Vechev |
USENIX Security Symposium | 3 |
| 2018 | Interference Suppression in Bandwidth Hopping Spread Spectrum CommunicationsabstractBandwidth hopping spread spectrum (BHSS) has recently been proposed as a spectrum-efficient technique to combat jamming. In BHSS, the transmitter is randomly hopping the signal bandwidth in order to make it unpredictable to an attacker. When the signal bandwidth is unpredictable, the attacker cannot match its interference bandwidth to the signal bandwidth of the transmitter, and the receiver can filter out the interference power (or parts of it) prior demodulation, and thus increase decoding performance. The main challenge in BHSS is that the bandwidth must be hopping very rapidly at the symbol level in order to prevent a reactive jammer from following the hopping pattern by simple tracking techniques. Existing receiver filtering techniques as proposed in prior work require a long time to estimate the filter parameters and are thus unable to suppress the interference from the jammer when the bandwidth is hopping at the symbol level. In this paper, we propose a new filtering approach adapted for BHSS which is able to suppress arbitrary jamming interference even when the signal bandwidth is hopping after every symbol. Our approach is based on a filter bank which applies different filters in parallel and dynamically selects the best filter for every symbol according to the soft-state output of the demodulator. We evaluate the improvement of our method over classical filtering techniques in experiments using software-defined radios. Our results show a gain in interference suppression above 30 dB with respect to state-of-the-art solutions. We further implement frequency hopping for a BHSS system, and demonstrate the superiority of a system combining hopping in bandwidth, code and frequency against jamming attacks. Domenico Giustiniano, Markus Schalch, Marc Liechti, Vincent Lenders |
WISEC | 4 |
| 2018 | Undermining Privacy in the Aircraft Communications Addressing and Reporting System (ACARS)abstractAbstract Despite the Aircraft Communications, Addressing and Reporting System (ACARS) being widely deployed for over twenty years, little scrutiny has been applied to it outside of the aviation community. Whilst originally utilized by commercial airlines to track their flights and provide automated timekeeping on crew, today it serves as a multi-purpose air-ground data link for many aviation stakeholders including private jet owners, state actors and military. Such a change has caused ACARS to be used far beyond its original mandate; to date no work has been undertaken to assess the extent of this especially with regard to privacy and the various stakeholder groups which use it. In this paper, we present an analysis of ACARS usage by privacy sensitive actors-military, government and business. We conduct this using data from the VHF (both traditional ACARS, and VDL mode 2) and satellite communications subnetworks. Based on more than two million ACARS messages collected over the course of 16 months, we demonstrate that current ACARS usage systematically breaches location privacy for all examined aviation stakeholder groups, explaining the types of messages used to cause this problem.We illustrate the challenges with three case studies-one for each stakeholder group-to show how much privacy sensitive information can be constructed with a handful of ACARS messages. We contextualize our findings with opinions on the issue of privacy in ACARS from 40 aviation industry professionals. From this, we explore recommendations for how to address these issues, including use of encryption and policy measures. Matthew Smith 0006, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
Proc. Priv. Enhancing Technol. | 4 |
| 2017 | Evaluating Behavioral Biometrics for Continuous Authentication: Challenges and MetricsabstractIn recent years, behavioral biometrics have become a popular approach to support continuous authentication systems. Most generally, a continuous authentication system can make two types of errors: false rejects and false accepts. Based on this, the most commonly reported metrics to evaluate systems are the False Reject Rate (FRR) and False Accept Rate (FAR). However, most papers only report the mean of these measures with little attention paid to their distribution. This is problematic as systematic errors allow attackers to perpetually escape detection while random errors are less severe. Using 16 biometric datasets we show that these systematic errors are very common in the wild. We show that some biometrics (such as eye movements) are particularly prone to systematic errors, while others (such as touchscreen inputs) show more even error distributions. Our results also show that the inclusion of some distinctive features lowers average error rates but significantly increases the prevalence of systematic errors. As such, blind optimization of the mean EER (through feature engineering or selection) can sometimes lead to lower security. Following this result we propose the Gini Coefficient (GC) as an additional metric to accurately capture different error distributions. We demonstrate the usefulness of this measure both to compare different systems and to guide researchers during feature selection. In addition to the selection of features and classifiers, some non- functional machine learning methodologies also affect error rates. The most notable examples of this are the selection of training data and the attacker model used to develop the negative class. 13 out of the 25 papers we analyzed either include imposter data in the negative class or randomly sample training data from the entire dataset, with a further 6 not giving any information on the methodology used. Using real-world data we show that both of these decisions lead to significant underestimation of error rates by 63% and 81%, respectively. This is an alarming result, as it suggests that researchers are either unaware of the magnitude of these effects or might even be purposefully attempting to over-optimize their EER without actually improving the system. Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
AsiaCCS | 3 |
| 2017 | Localization of Spoofing Devices using a Large-scale Air Traffic Surveillance SystemabstractSystems relying on satellite positioning techniques such as GPS can be targeted by spoofing attacks, where attackers try to inject fake positioning information. With the growing spread of flying drones and their usage of GPS for localization, these systems become interesting targets of attacks with the purpose of hijacking or to distract air safety surveillance. The most recent development in air traffic surveillance is the automatic dependent surveillance -- broadcast (ADS-B). Aircraft periodically broadcast their location, speed, or environmental measurements via ADS-B. The open research project OpenSky Network collects ADS-B reports and makes them available for research purposes. This poster presents a concept to detect and localize spoofing devices by utilizing the information provided by a large-scale air traffic surveillance system. We utilize ADS-B reports collected by the OpenSky Network and provide first results on the effectiveness of localizing spoofing sources. Kai Jansen, Matthias Schäfer 0002, Vincent Lenders, Christina Pöpper, Jens B. Schmitt |
AsiaCCS | 3 |
| 2017 | Unsupervised Detection of APT C&C Channels using Web Request Graphs
Pavlos Lamprakis, Ruggiero Dargenio, David Gugelmann, Vincent Lenders, Markus Happe, Laurent Vanbever |
DIMVA | 4 |
| 2017 | Quantifying Web Adblocker Privacy
Arthur Gervais, Alexandros Filios, Vincent Lenders, Srdjan Capkun |
ESORICS (2) | 3 |
| 2017 | ArmaTweet: Detecting Events by Semantic Tweet Analysis
Alberto Tonon, Philippe Cudré-Mauroux, Albert Blarer, Vincent Lenders, Boris Motik |
ESWC (2) | 4 |
| 2017 | Crowdsourcing spectrum data decodingabstractCrowdsourced signal monitoring systems are gaining attention for capturing the wireless spectrum at large geographical scale. Yet, most of the current systems are still limited to simple power spectrum measurements reported by each sensor. Our objective is to enhance such systems with signal decoding capabilities performed in the backend while retaining the original vision of a low-cost and crowdsourced setup. We propose a distributed system architecture for collaborative radio signal monitoring and decoding that builds on $12 low-cost radio frequency (RF) frontends and embedded boards and that takes into consideration the limited network bandwidth from the sensors to the backend. We present a distributed time multiplexing mechanism to sample the spectrum in a coordinated fashion that exploits the similarity of the radio signal received by more than one RF frontend in the same radio coverage. We address the strict time synchronization required among sensors to reconstruct the signal from the samples they receive when in the same radio coverage. We study and implement techniques to identify and overcome errors in the timing information in the presence of noise sources and decode the data in the backend. We provide an evaluation based on simulations and on real signals transmitted by Long-Term Evolution (LTE) base stations. Our results show that we can reliably reconstruct and decode radio signals received by low-cost crowdsourced sensors. Roberto Calvo-Palomino, Domenico Giustiniano, Vincent Lenders, Aymen Fakhreddine |
INFOCOM | 3 |
| 2017 | On Perception and Reality in Wireless Air Traffic Communication SecurityabstractMore than a dozen wireless technologies are used by air traffic communication systems during different flight phases. From a conceptual perspective, all of them are insecure, as security was never part of their design. Recent contributions from academic and hacking communities have exploited this inherent vulnerability to demonstrate attacks on some of these technologies. However, not all of these contributions have resonated widely within aviation circles. At the same time, the security community lacks certain aviation domain knowledge, preventing aviation authorities from giving credence to their findings. In this survey, we aim to reconcile the view of the security community and the perspective of aviation professionals concerning the safety of air traffic communication technologies. To achieve this, we first provide a systematization of the applications of wireless technologies upon which civil aviation relies. Based on these applications, we comprehensively analyze vulnerabilities and existing attacks. We further survey the existing research on countermeasures and categorize it into approaches that are applicable in the short term and research of secure new technologies deployable in the long term. Since not all of the required aviation knowledge is codified in academic publications, we additionally examine the existing aviation standards and survey 242 international aviation experts. Besides their domain knowledge, we also analyze the awareness of members of the aviation community concerning the security of wireless systems and collect their expert opinions on the potential impact of concrete attack scenarios using these technologies. Martin Strohmeier, Matthias Schäfer 0002, Rui Pinheiro, Vincent Lenders, Ivan Martinovic |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2017 | Filtering Noisy 802.11 Time-of-Flight Ranging Measurements From Commoditized WiFi RadiosabstractTime-of-flight (ToF) echo techniques have been recently suggested for ranging mobile devices over WiFi radios. However, these techniques have yielded only moderate accuracy in indoor environments because WiFi ToF measurements suffer from extensive device-related noise which makes it challenging to differentiate between direct path from non-direct path signal components when estimating the ranges. Existing multipath mitigation techniques tend to fail at identifying the direct path when the device-related Gaussian noise is in the same order of magnitude, or larger than the multipath noise. In order to address this challenge, we propose a new method for filtering ranging measurements that is better suited for the inherent large noise as found in WiFi radios. Our technique combines statistical learning and robust statistics in a single filter. The filter is lightweight in the sense that it does not require specialized hardware, the intervention of the user, or cumbersome on-site manual calibration. This makes our method particularly suitable for indoor localization in large-scale deployments using existing legacy WiFi infrastructures. We evaluate our technique for indoor mobile tracking scenarios in multipath environments and, through extensive evaluations across four different testbeds covering areas up to 1000m2, the filter is able to achieve a median 2-D positioning error between 2 and 3.4 m. Maurizio Rea, Aymen Fakhreddine, Domenico Giustiniano, Vincent Lenders |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | Quantifying Location Privacy Leakage from Transaction Prices
Arthur Gervais, Hubert Ritzdorf, Mario Lucic, Vincent Lenders, Srdjan Capkun |
ESORICS (2) | 4 |
| 2016 | Investigation of multi-device location spoofing attacks on air traffic control and possible countermeasuresabstractMultilateration techniques have been proposed to verify the integrity of unprotected location claims in wireless localization systems. A common assumption is that the adversary is equipped with only a single device from which it transmits location spoofing signals. In this paper, we consider a more advanced model where the attacker is equipped with multiple devices and performs a geographically distributed coordinated attack on the multilateration system. The feasibility of a distributed multi-device attack is demonstrated experimentally with a self-developed attack implementation based on multiple COTS software-defined radio (SDR) devices. We launch an attack against the OpenSky Network, an air traffic surveillance system that implements a time-difference-of-arrival (TDoA) multi-lateration method for aircraft localization based on ADS-B signals. Our experiments show that the timing errors for distributed spoofed signals are indistinguishable from the multilateration errors of legitimate aircraft signals, indicating that the threat of multi-device spoofing attacks is real in this and other similar systems. In the second part of this work, we investigate physical-layer features that could be used to detect multi-device attacks. We show that the frequency offset and transient phase noise of the attacker's radio devices can be exploited to discriminate between a received signal that has been transmitted by a single (legitimate) transponder or by multiple (malicious) spoofing sources. Based on that, we devise a multi-device spoofing detection system that achieves zero false positives and a false negative rate below 1%. Daniel Moser, Patrick Leu, Vincent Lenders, Aanjhan Ranganathan, Fabio Ricciato, Srdjan Capkun |
MobiCom | 3 |
| 2016 | Evaluation of self-positioning algorithms for time-of-flight based localizationabstractSelf-localization systems based on the Time-of-Flight (ToF) of radio signals are highly susceptible to noise and their performance therefore heavily rely on the design and parametrization of robust algorithms. In this work, we study the noise sources of GPS and WiFi ToF ranging techniques and compare the performance of different self-positioning algorithms at a mobile node using those ranges. Our results show that the localization error varies greatly depending on the ranging technology, algorithm selection, and appropriate tuning of the algorithms. We characterize the localization error using real-world measurements and different parameter settings to provide guidance for the design of robust location estimators in realistic settings. Aymen Fakhreddine, Domenico Giustiniano, Vincent Lenders |
WiOpt | 3 |
| 2016 | Secure Motion Verification using the Doppler EffectabstractFuture transportation systems highly rely on the integrity of spatial information provided by their means of transportation such as vehicles and planes. In critical applications (e.g. collision avoidance), tampering with this data can result in life-threatening situations. It is therefore essential for the safety of these systems to securely verify this information. While there is a considerable body of work on the secure verification of locations, movement of nodes has only received little attention in the literature. This paper proposes a new method to securely verify spatial movement of a mobile sender in all dimensions, i.e., position, speed, and direction. Our scheme uses Doppler shift measurements from different locations to verify a prover's motion. We provide formal proof for the security of the scheme and demonstrate its applicability to air traffic communications. Our results indicate that it is possible to reliably verify the motion of aircraft in currently operational systems with an equal error rate of zero. Matthias Schäfer 0002, Patrick Leu, Vincent Lenders, Jens B. Schmitt |
WISEC | 3 |
| 2016 | Looks Like Eve: Exposing Insider Threats Using Eye Movement BiometricsabstractWe introduce a novel biometric based on distinctive eye movement patterns. The biometric consists of 20 features that allow us to reliably distinguish users based on differences in these patterns. We leverage this distinguishing power along with the ability to gauge the users’ task familiarity, that is, level of knowledge, to address insider threats. In a controlled experiment, we test how both time and task familiarity influence eye movements and feature stability, and how different subsets of features affect the classifier performance. These feature subsets can be used to tailor the eye movement biometric to different authentication methods and threat models. Our results show that eye movement biometrics support reliable and stable continuous authentication of users. We investigate different approaches in which an attacker could attempt to use inside knowledge to mimic the legitimate user. Our results show that while this advance knowledge is measurable, it does not increase the likelihood of successful impersonation. In order to determine the time stability of our features, we repeat the experiment twice within 2 weeks. The results indicate that we can reliably authenticate users over the entire period. We show that lower sampling rates provided by low-cost hardware pose a challenge, but that reliable authentication is possible even at the rate of 50Hz commonly available with consumer-level devices. In a second set of experiments, we evaluate how our authentication system performs across a variety of real-world tasks, including reading, writing, and web browsing. We discuss the advantages and limitations of our approach in detail and give practical insights on the use of this biometric in a real-world environment. Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
ACM Trans. Priv. Secur. | 3 |
| 2015 | Jamming mitigation by randomized bandwidth hoppingabstractWe present bandwidth hopping spread spectrum (BHSS), a novel technique to improve the jamming resistance of wireless communications. In BHSS, the bandwidth of a signal is hopped rapidly in a manner that is unpredictable to the jammer. We show in this work that by combining bandwidth hopping at the transmitter with adaptive filtering at the receiver, BHSS is able to improve the jamming resistance of the communication beyond the processing gain of conventional spread spectrum techniques such as DSSS and FHSS without an increase in RF spectrum requirements. We have designed and implemented a BHSS transmitter and receiver system on off-the-shelf software-defined radios. Our experimental results with different hopping patterns show that BHSS is able to boost the power advantage of spread spectrum communication by 8 to 20 dB for jammers of fixed bandwidth. When both transmitter and jammer hop randomly, the average power advantage we achieve with our system is 11.4 dB. Marc Liechti, Vincent Lenders, Domenico Giustiniano |
CoNEXT | 2 |
| 2015 | Intrusion Detection for Airborne Communication Using PHY-Layer Information
Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
DIMVA | 2 |
| 2015 | A low-cost sensor platform for large-scale wideband spectrum monitoringabstractToday's radio frequency (RF) spectrum measurements are mainly performed by governmental agencies which drive around using bulky and expensive specialized hardware. This approach does not scale well, providing us with only a poor situational awareness of the actual RF spectrum usage around us. We have developed a wideband spectrum monitoring sensor for remote operation that builds upon portable and low-cost commercial off-the-shelf (COTS) hardware components with a total cost per sensor device below $100. This results in a stunning cost reduction factor of 50 to 500 comparing to professional equipment. Our sensor platform adopts the software-defined radio paradigm and performs all signal processing steps on the CPU and GPU of a low-cost single-board computer. We address the challenges of large frequency errors and long scanning times due to the hardware constraints by proposing new correction and optimization methods, providing a satisfactory level of accuracy in indoor and outdoor environments. Our remote sensing platform is envisioned to be used at larger scale for various applications such as dynamic spectrum access in cognitive radios, detecting regions with elevated electro-smog, or for policy enforcement in the electromagnetic space. Roberto Calvo-Palomino, Damian Pfammatter, Domenico Giustiniano, Vincent Lenders |
IPSN | 4 |
| 2015 | A software-defined sensor architecture for large-scale wideband spectrum monitoringabstractToday's spectrum measurements are mainly performed by governmental agencies which drive around using expensive specialized hardware. The idea of crowdsourcing spectrum monitoring has recently gained attention as an alternative way to capture the usage of wide portions of the wireless spectrum at larger geographical and time scales. To support this vision, we develop a flexible software-defined sensor architecture that enables distributed data collection in real-time over the Internet. Our sensor design builds upon low-cost commercial off-the-shelf (COTS) hardware components with a total cost per sensor device below $100. The low-cost nature of our sensor platform makes the sensing approach particularly suitable for large-scale deployments but imposes technical challenges regarding performance and quality. To circumvent the limits of our solution, we have implemented and evaluated different sensing strategies and noise reduction techniques. Our results suggest that our sensor architecture may be useful in application areas such as dynamic spectrum access in cognitive radios, detecting regions with elevated electro-smog, or simply to gain an understanding of the spectrum usage for advanced signal intelligence such as anomaly detection or policy enforcement. Damian Pfammatter, Domenico Giustiniano, Vincent Lenders |
IPSN | 3 |
| 2015 | Towards understanding upstream Web trafficabstractWhile downstream Web traffic has been studied in detail, upstream Web traffic has not received much attention yet. We argue that upstream traffic deserves the same or even higher attention since data flows towards Web servers generally entail privacy-relevant user information. Our aim is to understand where to and how much data users send to Web services. To this end, we examine HTTP(S) requests of two 24 hour traces recorded at a gateway of a campus network. As HTTP is highly repetitive, we introduce a scalable approach to remove redundant parts from upstream Web traffic, yielding an approximation of actual information flow. We identify thirteen classes of Web services covering up to 95% of all outgoing HTTP information. Our methodology further allows to quantify and compare the share of information different Web service classes receive. We find that advertisement and analytics services receive two times more information during Web browsing than all first party Web services together. David Gugelmann, Bernhard Ager, Vincent Lenders, Markus Happe |
IWCMC | 3 |
| 2015 | Deep Inspection of the Noise in WiFi Time-of-Flight Echo TechniquesabstractTime-of-flight (ToF) echo techniques have been proposed to estimate the distance between a local and a target station using regular WiFi radio devices. As of today, there is little understanding of the noise sources from ToF measurements. We conduct extensive experimental tests based on a customized WiFi echo technique implementation residing in the core of the 802.11 MAC processor and a high-resolution signal analysis of the WiFi traffic captured with a wideband oscilloscope. We discern the root of the error components in WiFi echo technique measurements and statistically characterize the offset noise added by the target station. Our measurements provide key insights to model the sources of noise and guidance for the design of robust distance estimators. Domenico Giustiniano, Theodoros Bourchas, Maciej Bednarek, Vincent Lenders |
MSWiM | 4 |
| 2015 | Preventing Lunchtime Attacks: Fighting Insider Threats With Eye Movement Biometrics
Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
NDSS | 3 |
| 2015 | Secure Track VerificationabstractWe propose a new approach for securely verifying sequences of location claims from mobile nodes. The key idea is to exploit the inherent mobility of the nodes in order to constrain the degree of freedom of an attacker when spoofing consecutive location updates along a claimed track. We show that in the absence of noise, our approach is able to securely verify any 2-D track with a minimum of three verifiers or any 3-D track with four verifiers. Our approach is lightweight in the sense that it considerably relaxes the system requirements compared to previous secure location verification schemes which are all agnostic to mobility. As opposed to previous schemes, our track verification solution is at the same time (i) passive, (ii) does not require any time synchronization among the verifiers, (iii) does not need to keep the location of the verifiers secret, (iv) nor does it require specialized hardware. This makes our solution particularly suitable for large-scale deployments. We have evaluated our solution in a realistic air traffic monitoring scenario using real-world data. Our results show that 25 position claims on a track are sufficient to detect spoofing attacks with a false positive rate of 1.4% and a false negative rate of 1.2%. For tracks with more than 40 claims, the false positive and false negative rates drop to zero. Matthias Schäfer 0002, Vincent Lenders, Jens B. Schmitt |
IEEE Symposium on Security and Privacy | 2 |
| 2015 | Security by mobility in location and track verificationabstractThis poster presents the idea of exploiting mobility to improve the security in location and track verification. Unlike traditional approaches which require tight time synchronization or two-way communication, mobility can be used to derive lightweight verification schemes. By ensuring independent movement of the verifiers, our scheme can provide security guarantees even if the verifiers' positions are known to the attacker. We also give an outlook on more general opportunities for mobility-aided security. Matthias Schäfer 0002, Daniel S. Berger, Vincent Lenders, Jens B. Schmitt |
WISEC | 3 |
| 2015 | An Automated Approach for Complementing Ad Blockers' BlacklistsabstractAbstract Privacy in the Web has become a major concern resulting in the popular use of various tools for blocking tracking services. Most of these tools rely on manually maintained blacklists, which need to be kept up-to-date to protect Web users’ privacy efficiently. It is challenging to keep pace with today’s quickly evolving advertisement and analytics landscape. In order to support blacklist maintainers with this task, we identify a set of Web traffic features for identifying privacyintrusive services. Based on these features, we develop an automatic approach that learns the properties of advertisement and analytics services listed by existing blacklists and proposes new services for inclusion on blacklists. We evaluate our technique on real traffic traces of a campus network and find in the order of 200 new privacy-intrusive Web services that are not listed by the most popular Firefox plug-in Adblock Plus. The proposed Web traffic features are easy to derive, allowing a distributed implementation of our approach. David Gugelmann, Markus Happe, Bernhard Ager, Vincent Lenders |
Proc. Priv. Enhancing Technol. | 4 |
| 2014 | Quantifying Web-Search PrivacyabstractWeb search queries reveal extensive information about users' personal lives to the search engines and Internet eavesdroppers. Obfuscating search queries through adding dummy queries is a practical and user-centric protection mechanism to hide users' search intentions and interests. Despite few such obfuscation methods and tools, there is no generic quantitative methodology for evaluating users' web-search privacy. In this paper, we provide such a methodology. We formalize adversary's background knowledge and attacks, the users' privacy objectives, and the algorithms to evaluate effectiveness of query obfuscation mechanisms. We build upon machine-learning algorithms to learn the linkability between user queries. This encompasses the adversary's knowledge about the obfuscation mechanism and the users' web-search behavior. Then, we quantify privacy of users with respect to linkage attacks. Our generic attack can run against users for which the adversary does not have any background knowledge, as well as for the cases where some prior queries from the target users are already observed. We quantify privacy at the query level (the link between user's queries) and the semantic level (user's topics of interest). We design a generic tool that can be used for evaluating generic obfuscation mechanisms, and users with different web search behavior. To illustrate our approach in practice, we analyze and compare privacy of users for two example obfuscation mechanisms on a set of real web-search logs. Arthur Gervais, Reza Shokri, Adish Singla, Srdjan Capkun, Vincent Lenders |
CCS | 5 |
| 2014 | Filtering Noisy 802.11 Time-of-Flight Ranging MeasurementsabstractTime-of-Flight (ToF) echo techniques have been proposed as a way to estimate the range between regular Wi-Fi stations. Recent works either did not address practical questions for deployability, or made evaluations in basic setups, or used advanced 802.11 hardware designs. We build an approach solely deployed using ToF measurements and relying on software access point (AP) upgrades of simple commercial off-the-shelf 802.11 chipsets. Our solution filters noisy measurements collected by WiFi chipsets of six dollars each, it has been tested across different and heterogeneous setups and testbeds, and has the potential to enable ToF ranging in every Wi-Fi chipsets. Andreas Marcaletti, Maurizio Rea, Domenico Giustiniano, Vincent Lenders, Aymen Fakhreddine |
CoNEXT | 4 |
| 2014 | Bringing up OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 3 |
| 2014 | Demonstration abstract: OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 3 |
| 2014 | Poster abstract: practical limits of wifi time-of-flight echo techniques
Theodoros Bourchas, Maciej Bednarek, Domenico Giustiniano, Vincent Lenders |
IPSN | 4 |
| 2014 | Detection of Reactive Jamming in DSSS-based Wireless CommunicationsabstractReactive jammers have been shown to be a serious threat for wireless communication. Despite this, it is difficult to detect their presence reliably. We propose a novel method to detect such sophisticated jammers in direct sequence spread spectrum (DSSS) wireless communication systems. The key idea is to extract statistics from the jamming-free symbols of the DSSS synchronizer to discern jammed packets from those lost due to bad channel conditions. Our contribution is twofold. First, we experimentally evaluate new empirical models utilizing the preamble symbols of IEEE 802.15.4 packets, thus enabling the accurate prediction of the packet delivery ratio (PDR). We show that the chip error rate-based metric is superior to metrics used in the literature, offering an accurate and reactive indicator of the true PDR. Our second contribution is the design and evaluation of a detection technique relying on this metric to detect reactive jammers. We build a software-defined radio testbed and show that our technique enables the error-free detection of reactive jammers that jam all packets on links with a PDR above 0.3. To the best of our knowledge, our detector is the first to detect reactive jamming attacks targeting the physical layer header of DSSS packets, and does not require any modifications of the wireless communication system. Michael Spuhler, Domenico Giustiniano, Vincent Lenders, Matthias Wilhelm 0001, Jens B. Schmitt |
IEEE Trans. Wirel. Commun. | 3 |
| 2014 | On the Reception of Concurrent Transmissions in Wireless Sensor NetworksabstractNumerous studies have shown that concurrent transmissions can help boost wireless network performance despite the possibility of packet collisions. However, while these works provide empirical evidence that concurrent transmissions may be received reliably, existing signal capture models only partially explain the root causes of this phenomenon. We present a comprehensive mathematical model for MSK-modulated signals that makes the reasons explicit and thus provides fundamental insights into the key parameters governing the successful reception of colliding transmissions. A major contribution is the closed-form derivation of the receiver bit decision variable for an arbitrary number of colliding signals and constellations of power ratios, time offsets, and carrier phase offsets. We systematically explore the factors for successful packet delivery under concurrent transmissions across the whole parameter space of the model. We confirm the capture threshold behavior observed in previous studies but also reveal new insights relevant to the design of optimal protocols. We identify capture zones depending not only on the signal power ratio but also on time and phase offsets. Matthias Wilhelm 0001, Vincent Lenders, Jens B. Schmitt |
IEEE Trans. Wirel. Commun. | 2 |
| 2013 | Experimental Analysis of Attacks on Next Generation Air Traffic Communication
Matthias Schäfer 0002, Vincent Lenders, Ivan Martinovic |
ACNS | 2 |
| 2013 | Horizon extender: long-term preservation of data leakage evidence in web trafficabstractThis paper presents Horizon Extender, a system for long-term preservation of data leakage evidence in enterprise networks. In contrast to classical network intrusion detection systems that keep only packet records of suspicious traffic (black-listing), Horizon Extender reduces the total size of captured network traces by filtering out all records that do not reveal potential evidence about leaked data (white-listing). Horizon Extender has been designed to exploit the inherent redundancy and adherence to protocol specification of general Web traffic. We show in a real-life network including more than 1000 active hosts that Horizon Extender is able to reduce the total HTTP volume by 99.8%, or the outgoing volume by 90.9% to 93.9%, while preserving sufficient evidence to recover retrospectively time, end point identity, and content of information leaked over the HTTP communication channel. David Gugelmann, Dominik Schatzmann, Vincent Lenders |
AsiaCCS | 3 |
| 2013 | BLITZ: Wireless Link Quality Estimation in the Dark
Michael Spuhler, Vincent Lenders, Domenico Giustiniano |
EWSN | 2 |
| 2013 | Detection of reactive jamming in DSSS-based wireless networksabstractWe propose a novel approach to detect reactive jammers in direct sequence spread spectrum (DSSS) wireless networks. The key idea is to use the chip error rate of the first few jamming-free symbols at the DSSS demodulator during the signal synchronization phase of regular packet reception to estimate the probability of successful packet delivery. If the estimated probability is significantly higher than the actual packet delivery ratio, we declare jamming. As a proof of concept, we implement a prototype in a network of three USRP software-defined radios (transmitter, receiver, and jammer) and evaluate the feasibility, responsiveness, and accuracy of our approach in a controlled lab environment. Our experiments with IEEE 802.15.4 DSSS-based communication show that for links with a jamming-free packet delivery probability above 0.5, the false positive and negative detection rates remain below 5%. Domenico Giustiniano, Vincent Lenders, Jens B. Schmitt, Michael Spuhler, Matthias Wilhelm 0001 |
WISEC | 2 |
| 2012 | Fast and accurate packet delivery estimation based on DSSS chip errorsabstractFast and accurate link quality estimation is an important feature for wireless protocols such as routing, rate switching or handover. Existing signal strength based estimators tend to be fast but inaccurate while packet statistic based approaches are more accurate but require longer estimation times. We propose a new link quality estimation approach based on chip errors in symbols for direct sequence spread spectrum transceivers. The new link quality estimator is evaluated experimentally with software defined radios on IEEE 802.15.4 for different link conditions, including multi-path and mobile scenarios. We show that our chip error based link quality estimator performs more accurately than received signal strength based estimators and much faster than the packet statistic based estimators with comparable accuracy. With our approach, only a single packet, or even a fraction of a packet (e.g., only a few symbols), is necessary to obtain similar performance as state-of-the-art approaches that require at least 10 packets. Pirmin Heinzer, Vincent Lenders, Franck Legendre |
INFOCOM | 2 |
| 2011 | WiFire: a firewall for wireless networksabstractFirewalls are extremely effective at enforcing security policies in wired networks. Perhaps surprisingly, firewalls are entirely nonexistent in the wireless domain. Yet, the need to selectively control and block radio communication is particularly high in a broadcast environment since any node may receive and send packets. In this demo, we present WiFire, a system that brings the firewall concept to wireless networks. First, WiFire detects and analyzes packets during their transmission, checking their content against a set of rules. It then relies on reactive jamming techniques to selectively block undesired communication. We show the feasibility and performance of WiFire, which is implemented on the USRP2 software-defined radio platform, in several scenarios with IEEE 802.15.4 radios. WiFire is able to classify and effectively block undesired communication without interfering with desired communication. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders |
SIGCOMM | 4 |
| 2011 | Short paper: reactive jamming in wireless networks: how realistic is the threat?abstractIn this work, we take on the role of a wireless adversary and investigate one of its most powerful tools---radio frequency jamming. Although different jammer designs are discussed in the literature, reactive jamming, i.e., targeting only packets that are already on the air, is generally recognized as a stepping stone in implementing optimal jamming strategies. The reason is that, while destroying only selected packets, the adversary minimizes its risk of being detected. One might hope for reactive jamming to be too challenging or uneconomical for an attacker to conceive and implement due to its strict real-time requirements. Yet, in this work we disillusion from such hopes as we demonstrate that flexible and reliable software-defined reactive jamming is feasible by designing and implementing a reactive jammer against IEEE 802.15.4 networks. First, we identify the causes of loss at the physical layer of 802.15.4 and show how to achieve the best performance for reactive jamming. Then, we apply these insights to our USRP2-based reactive jamming prototype, enabling a classification of transmissions in real-time, and reliable and selective jamming. The prototype achieves a reaction time in the order of microseconds, a high precision (such as targeting individual symbols), and a 97.6% jamming rate in realistic indoor scenarios for a single reactive jammer, and over 99.9% for two concurrent jammers. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders |
WISEC | 4 |
| 2009 | Repeatable and Realistic Experimentation in Mobile Wireless NetworksabstractExperimenting with mobile and wireless networks is challenging because testbeds lack repeatability and existing simulation models are unrealistic for real-world settings. We present practical models for the physical and MAC layer behavior in mobile wireless networks in order to address this challenge. Our models use measurements of a real network rather than abstract radio propagation and mobility models as the basis for accuracy in complex environments. We develop an adaptive measurement technique in order to maximize the accuracy of our models in dynamic environments. The models then predict the packet delivery, deferring, and collision probability in the same network for an arbitrary set of transmitters. This allows to explore the performance of different network and higher layer protocols in simulation or emulation under identical and realistic conditions. We evaluate the accuracy of our models empirically by comparing them to benchmark measurements. We find that our models are effective at reproducing mobile scenarios in various environments. Across many experiments in realistic environments, we are able to reproduce link delivery probabilities with RMS error below 12 percent, and the simulated throughput of data flows in the presence of interfering transmitters with an error that is below 10 percent. Vincent Lenders, Margaret Martonosi |
IEEE Trans. Mob. Comput. | 1 |
| 2008 | The limits of theory: Pragmatic challenges in mobile ad hoc systemsabstractThe development of mobile ad hoc systems have considerably emphasized the need for a better understanding of the factors that influence the systemspsila performance, i.e., mobility patterns, radio propagation, traffic characteristics and their interrelations. Depending on the context where the system is being used-whether at work, at home, or in some means of transportation-there will be various applications that provide benefit of using the system. These different applications in turn generate traffic with very heterogeneous characteristics. In addition, the radio propagation depends on the surrounding environment and the density of communicating nodes in the system and in other systems that compete for radio resources; hence the available data rates in the system are hard to ascertain. The uncertainty regarding both the traffic and the available data rates make it hard to evaluate the performance of the system. This uncertainty is due to the lack of deployed systems. We hence believe that research in mobile ad hoc networks has to couple theory and practice in a continuous feedback loop with experimentations running full-fledged applications. We show how this methodology has proved to be beneficial in order to overcome challenges and to determine main issues for future research in the context of our PodNet project. It has also allowed us to revisit assumptions and scepticism surrounding the feasibility of mobile ad hoc networks. PodNet is an architecture, instantiated in a prototype, that is dedicated to cooperative content distribution. It enables exchange of podcasts (for any kind of multimedia content) amongst mobile devices in a peer-to-peer fashion using IEEE 802.11 in ad hoc mode. PodNet has clear advantages over traditional content distribution approaches (e.g., newspapers, 3G) in terms of public availability, practicability, capacity, resilience to failures, and jamming. Franck Legendre, Martin May, Vincent Lenders, Gunnar Karlsson |
PIMRC | 3 |
| 2008 | Link-Diversity Routing: A Robust Routing Paradigm for Mobile Ad Hoc NetworksabstractWe present link-diversity routing, a routing paradigm that achieves high path resilience in mobile ad hoc networks. Link-diversity routing chooses each hop of a packet's route, so that the choice reflects the amount of outgoing links towards the destination at the intermediate hops. This choice maximizes the opportunities to make progress at every hop in the presence of unpredictable link failures caused by mobility or fading effects. As a result, link diversity routing takes paths which are less prone to fail due to individual link failures than traditional routing. We develop a loop-free and distributed link-diversity routing algorithm. The algorithm is based on an analogy from the heat theory which consists of routing packets along the steepest gradient of a temperature field. We perform simulations of our algorithm with a DSDV-based implementation. Our simulations show that link-diversity routing increases the end-to-end packet delivery ratio to a factor of up to four without any additional protocol overhead compared to the traditional minimum hop- count based DSDV. Vincent Lenders, Rainer Baumann |
WCNC | 1 |
| 2008 | Density-based anycast: a robust routing strategy for wireless ad hoc networks
Vincent Lenders, Martin May, Bernhard Plattner |
IEEE/ACM Trans. Netw. | 1 |
| 2007 | Routing Packets into Wireless Mesh Networks
Rainer Baumann, Simon Heimlicher, Vincent Lenders, Martin May |
WiMob | 3 |
| 2007 | HEAT: Scalable Routing in Wireless Mesh Networks Using Temperature FieldsabstractExisting unicast routing protocols are not suited well for wireless mesh networks as in such networks, most traffic flows between a large number of mobile nodes and a few access points with Internet connectivity. In this paper, we propose HEAT, an anycast routing protocol for this type of communication that is designed to scale to the network size and to be robust to node mobility. HEAT relies on a temperature field to route data packets towards the Internet gateways, as follows. Every node is assigned a temperature value, and packets are routed along increasing temperature values until they reach any of the Internet gateways, which are modeled as heat sources. Our major contribution is a distributed protocol to establish such temperature fields. The distinguishing feature of our protocol is that it does not require flooding of control messages. Rather, every node in the network determines its temperature considering only the temperature of its direct neighbors, which renders our protocol particularly scalable to the network size. We analyze our approach and compare its performance with OLSR through simulations with Glomosim. We use realistic mobility patterns extracted from geographical data of large Swiss cities. Our results clearly show the benefit of HEAT versus OLSR in terms of scalability to the number of nodes and robustness to node mobility. The packet delivery ratio with HEAT is more than two times higher than OLSR in large mobile scenarios and we conclude that HEAT is a suitable routing protocol for city-wide wireless mesh networks. Rainer Baumann, Simon Heimlicher, Vincent Lenders, Martin May |
WOWMOM | 3 |
| 2006 | Density-Based vs. Proximity-Based Anycast Routing for Mobile NetworksabstractExisting anycast routing protocols solely route packets to the closest group member. In this paper, we introduce density-based anycast routing, a new anycast routing strategy particularly suitable for unstable networks. Instead of routing packets merely on proximity information to the closest member, density-based anycast routing considers the number of available anycast group members for its routing decision. To evaluate the benefits of densitybased routing, we present a unified model to analyze pure proximitybased, pure density-based, as well as combined routing strategies. With an extensive simulation study, we then evaluate these strategies in multiple mobile scenarios. The two main results are that (i) density-based routing increases the probability of successful packet delivery when the network is unstable; and (ii) for particular mobile scenarios, density-based routing finds even shorter routes compared to traditional proximity-based routing. Finally, we discuss implementation issues and propose a solution to dynamically adapt the protocol’s parameter settings. I. Vincent Lenders, Martin May, Bernhard Plattner |
INFOCOM | 1 |
| 2006 | Measurements from an 802.11b Mobile Ad Hoc NetworkabstractThis paper analyzes the characteristics of a multi-hop 802.11b mobile ad hoc network. We present data gathered from a mobile network of 20 devices carried by test users over 5 days in an indoor environment. The data is analyzed with regard to (i) the number of reachable devices, (ii) the node degree, (iii) the average path length, (iv) the link lifetime, (v) and the route lifetime. Despite the relatively high node density and low node mobility in our setup, we observe frequent network partitioning and considerably high path lengths (as large as 7 hops). However, the usability of these long paths is questionable as their lifetime is short. We believe that our measurements are representative for typical indoor environments and that the results can and should be used for evaluating networking protocols as well as to validate existing or to derive new mobility models Vincent Lenders, Jörg Wagner 0001, Martin May |
WOWMOM | 1 |
| 2005 | Towards a new communication paradigm for mobile ad hoc networksabstractIn mobile ad hoc networks, we envision a network where mobile users obtain services from close-by instances. The architecture of today's Internet was designed for fixed users that obtain services from stationary servers and is not well suited for such scenarios. The reason is that (i) the architecture combines identity and location in an IP address and thus forces mobile elements to change their identity when moving over subnet boundaries; and that (ii) the layered architecture implies a separation of service discovery/selection and routing, which is inflexible and also leads to protocol overhead. In this paper, we revise the existing Internet architecture and propose a novel architecture that is better suited for mobile ad hoc networks. There, clients bind to location-independent service identifiers and send packets that are routed to any instance of the desired service in proximity. The routing mechanism is based on the concept of (electrical) fields with which packets are forwarded towards a region with a high density of service nodes. As a result, this architecture increases the probability of successful packet delivery and leads to a robust routing substrate even in very unstable network conditions Vincent Lenders, Martin May, Bernhard Plattner |
MASS | 1 |
| 2005 | Service Discovery in Mobile Ad Hoc Networks: A Field Theoretic ApproachabstractService discovery in mobile ad hoc networks is challenging because of the absence of any central intelligence in the network. Traditional solutions, as used in the Internet, are hence not well suited for mobile ad hoc networks. We present a novel decentralized service discovery mechanism for ad hoc networks. The basic idea is to distribute information about available services to the network neighborhood. We achieve this by using the analogy of an electrostatic field. A service is modeled by a (positive) point charge, and service request packets are seen as (negative) test charges which are attracted by the service instances. We map the physical model to a mobile ad hoc network in a way where each network element calculates a potential value and routes service requests towards the neighbor with the highest potential, hence towards a service instance. Our approach allows for differentiation of service instances based on their capacity. We define the required protocols and methods which we implemented in a network simulator. Using extensive simulations, we evaluate the performance and robustness of the mechanisms. The results indicate good performance and convergence, even in highly mobile environments. We believe that this technique can, and should, be further exploited, e.g., as a routing protocol in mobile networks. Vincent Lenders, Martin May, Bernhard Plattner |
WOWMOM | 1 |
| 2005 | Service discovery in mobile ad hoc networks: A field theoretic approach
Vincent Lenders, Martin May, Bernhard Plattner |
Pervasive Mob. Comput. | 1 |