Cliff C. Zou

dblp:z/CliffChangchunZou · also Cliff Changchun Zou · DBLP profile ↗
← Back
63ranked-venue papers
8as first author
10since 2021 · last 2026
0000-0003-4229-6957ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 31 · 3 first-author · 6 since 2021Security and privacy · 19 · 4 first-author · 2 since 2021Systems, architecture and hardware · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Blockchain Security and Privacy: Threats, Challenges, Applications, and Tools
abstract
Blockchain technology has heralded a new era in digital innovation, revolutionizing our approach to designing and building distributed applications in the digital sphere. Blockchain technology operates as an immutable digital ledger, where each entry representing a digital transaction is indelible and cannot be altered once established. Initially designed as the fundamental framework for cryptocurrencies, blockchain has outgrown its original purpose, demonstrating significant potential in various industries and offering a variety of security and privacy features. Our study provides a thorough and current survey of blockchain applications, security, privacy concepts, primitives, and threat models. It stands out by concentrating on how blockchain technology intersects with emerging fields like IoT, EVs, FinTech, and healthcare systems in a single framework. To provide security and privacy features, blockchain systems employ different foundational notions and primitives while tackling diverse adversarial scenarios with various capabilities and goals. This study presents a fresh examination of the current state of applications, security and privacy notions and primitives, and threat models in blockchain systems. Additionally, this work highlights existing gaps in knowledge and outlines open questions, aiming to stimulate interest in further advancements in the field.
Ahod Alghuried, Mohammed Alkinoon, Manar Mohaisen, An Wang 0002, Cliff C. Zou, David Mohaisen
Distributed Ledger Technol. Res. Pract.5
2025 Data reduction for black-box adversarial attacks against deep neural networks based on side-channel attacks
Hanxun Zhou, Longyu Kang, Wei Guo 0016, Cliff C. Zou
Comput. Secur.9
2024 Inter-Flow Spatio-Temporal Correlation Analysis Based Website Fingerprinting Using Graph Neural Network
abstract
Website fingerprinting has emerged as a prominent topic in the area of network management. However, the proliferation of encrypted network traffic poses new challenges for website fingerprinting. In this paper, we analyze the behavior and correlations among the network flows generated by browsing a webpage and conclude that there exist specific spatio-temporal correlations among these network flows. Based on this finding, we propose the construction of an inter-flow spatio-temporal correlation graph (STCG) to model these correlations. In the STCG, each node represents a flow, with its features capturing the properties of the flow itself, and each edge with a weight vector represents the spatio-temporal correlation between two flows. Subsequently, we propose a graph neural network-based website fingerprinting method (STC-WF) by considering the inter-flow spatio-temporal correlations, in which the Graph Attention Network (GAT) and Self-Attention Graph Pooling (SAGPool) mechanisms are employed to acquire a comprehensive representation of the STCG. To evaluate the performance of STC-WF, we construct a real-world traffic dataset and conduct comprehensive evaluations. The experimental results demonstrate that STC-WF outperforms state-of-the-art methods in terms of accuracy and time consumption.
Xiaobin Tan, Chuang Peng, Mengxiang Li, Shuangwu Chen, Cliff C. Zou
IEEE Trans. Inf. Forensics Secur.7
2024 Hybrid-Coding Based Content Access Control for Information-Centric Networking
abstract
The rapid growth of mobile network traffic poses major challenges for current wireless networks regarding bandwidth, delay, mobility, and stability. To overcome these obstacles, a new network architecture called Information-Centric Networking (ICN) has emerged, effectively addressing these issues and enhancing content delivery efficiency. However, with the in-network content cache, anyone including unauthorized users can access the content from intermediate network nodes. In response to this challenge, this paper proposes an efficient and lightweight ICN content access control framework based on a hybrid-coding mechanism that combines two or more encoding operations, which does not impose additional complexity on ICN routers. In the proposed scheme, the content is first divided into multiple original blocks, and these original blocks are encoded into encoded blocks using hybrid-coding operations. Each authorized user can obtain private decoding information from the content provider, and decode them into original content using its private decoding information. The proposed scheme can fully utilize ICN’s in-network cache capability and defend against a wide range of attacks. Furthermore, security analysis, ndnSIM-based simulation, and real-world experiments demonstrate the scheme’s security, performance, and scalability.
Xiaobin Tan, Shunyi Wang, Liguo Ji, Xinxin Tong, Cliff C. Zou, Quan Zheng 0002, Jian Yang 0014
IEEE Trans. Wirel. Commun.5
2022 WiFi-based IoT Devices Profiling Attack based on Eavesdropping of Encrypted WiFi Traffic
abstract
Recent research has shown that in-network observers of WiFi communication (i.e., observers who have joined the WiFi network) can obtain much information regarding the types, user identities, and activities of Internet-of-Things (IoT) devices in the network. What has not been explored is the question of how much information can be inferred by an out-of-network observer who does not have access to the WiFi network. This attack scenario is more realistic and much harder to defend against, thus imposes a real threat to user privacy. In this paper, we investigate privacy leakage derived from an out-of-network traffic eavesdropper on the encrypted WiFi traffic of popular IoT devices. We instrumented a testbed of 12 popular IoT devices and evaluated multiple machine learning methods for fingerprinting and inferring what IoT devices exist in a WiFi network. By only exploiting the WiFi frame header information, we have achieved 95% accuracy in identifying the devices and often their working status. This study demonstrates that information leakage and privacy attack is a real threat for WiFi networks and IoT applications.
Mnassar Alyami, Ibrahim Alharbi, Cliff C. Zou, Yan Solihin, Karl Ackerman
CCNC3
2022 Side-Channel VoIP Profiling Attack against Customer Service Automated Phone System
abstract
In many VoIP systems, Voice Activity Detection (VAD) is often used on VoIP traffic to suppress packets of silence in order to reduce the bandwidth consumption of phone calls. Unfortunately, although VoIP traffic is fully encrypted and secured, traffic analysis of this suppression can reveal identifying information about calls made to customer service automated phone systems. Because different customer service phone systems have distinct, but fixed (pre-recorded) automated voice messages sent to customers, VAD silence suppression used in VoIP will enable an eavesdropper to profile and identify these automated voice messages. In this paper, we will use a popular enterprise VoIP system (Cisco CallManager), running the default Session Initiation Protocol (SIP) protocol, to demonstrate that an attacker can reliably use the silence suppression to profile calls to such VoIP systems. Our real-world experiments demonstrate that this side-channel profiling attack can be used to accurately identify not only what customer service phone number a customer calls, but also what following options are subsequently chosen by the caller in the phone conversation.
Roy Laurens, Edo Christianto, Bruce Caulkins, Cliff C. Zou
GLOBECOM4
2022 FUME: Fuzzing Message Queuing Telemetry Transport Brokers
abstract
Message Queuing Telemetry Transport (MQTT) is a popular communication protocol used to interconnect devices with considerable network restraints, such as those found in Internet of Things (IoT). MQTT directly impacts a large number of devices, but the software security of its server ("broker") implementations is not well studied. In this paper, we design, implement, and evaluate a novel fuzz testing model for MQTT. The fuzzer combines aspects of mutation guided fuzzing and generation guided fuzzing to rigorously exhaust the MQTT protocol and identify vulnerabilities in servers. We introduce Markov chains for mutation guided fuzzing and generation guided fuzzing that model the fuzzing engine according to a finite Bernoulli process. We implement "response feedback", a novel technique which monitors network and console activity to learn which inputs trigger new responses from the broker. In total, we found 7 major vulnerabilities across 9 different MQTT implementations, including 6 zero-day vulnerabilities and 2 CVEs. We show that when fuzzing these popular MQTT targets, our fuzzer compares favorably with other state-of-the-art fuzzing frameworks, such as BooFuzz and AFLNet.
Bryan Pearson, Yue Zhang 0025, Cliff C. Zou, Xinwen Fu
INFOCOM3
2022 MAC-Layer Traffic Shaping Defense Against WiFi Device Fingerprinting Attacks
abstract
WiFi networks are vulnerable to statistical traffic analysis attacks, even when a WiFi network is securely encrypted and the attacker is unable to join the network. Many defenses proposed in the literature are inefficient to deal with profiling attacks against WiFi-based Internet-of-Things (IoT) devices, because they burden the Internet traffic with high bandwidth overhead and pose deliberate delay on packet transmission. In this paper, we propose a new MAC-layer packet injection technique where injected dummy packets only exist within the WiFi link between IoT devices and their connected WiFi access point. This traffic shaping defense is effective against data-link device profiling attacks without adding any Internet-side overhead or time delay in legitimate traffic. We evaluated our approach on four WiFi-based IoT devices against a recent privacy attack, and showed the reduction of attack classification accuracy from the original 100% to 54%, close to random guessing..
Mnassar Alyami, Mohammed Alkhowaiter, Mansour Al Ghanim, Cliff C. Zou, Yan Solihin
ISCC4
2022 A Web Infrastructure for Certifying Multimedia News Content for Fake News Defense
abstract
In dealing with altered multimedia news content, also referred to as fake news, we present a ready-to-deploy scheme based on existing public key infrastructure as a new fake news defense paradigm. This scheme enables news organizations to certify/endorse a newsworthy multimedia news content and securely and conveniently pass this trust information to end users. A news organization can use our program to digitally sign the multimedia news content with its private key. By installing a browser extension, an end user can easily verify whether a news content has been endorsed and by which organization. It is totally up to the end user whether to trust the news or the endorsing news organization. The underlining principles of our scheme are that fake news will sooner or later be identified as fake by general population, and a news organization puts its long-term reputation on the line when endorsing a news content.
Edward L. Amoruso, Stephen P. Johnson, Raghu Nandan Avula, Cliff C. Zou
ISCC4
2022 On Security of TrustZone-M-Based IoT Systems
abstract
Internet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension designed specifically for MCUs, is an emerging hardware security technique fortifying software security of MCU-based IoT devices. This article introduces a comprehensive security framework for IoT devices using TrustZone-M-enabled MCUs, in which device security is protected in five dimensions, i.e., hardware, boot-time software, runtime software, network, and over-the-air (OTA) update. Along developing the framework, we also present the first security analysis of potential runtime software security issues in TrustZone-M-enabled MCUs. In particular, we explore the feasibility of launching stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against nonsecure callable (NSC) functions in the context of TrustZone-M. We validate these attacks using SAM L11, a microchip MCU with TrustZone-M and provide defense mechanisms in the runtime software dimension of the proposed framework. The security framework is implemented with a full-fledged secure and trustworthy air quality monitoring device using SAM L11 as its MCU.
Yue Zhang 0025, Clayton White, Brandon Keating, Bryan Pearson, Xinhui Shao, Zhen Ling 0001, Haofei Yu, Cliff C. Zou, Xinwen Fu
IEEE Internet Things J.9
2020 Ambulance Dispatch via Deep Reinforcement Learning
abstract
In this paper, we solve the ambulance dispatch problem with a reinforcement learning oriented strategy. The ambulance dispatch problem is defined as deciding which ambulance to pick up which patient. Traditional studies on ambulance dispatch mainly focus on predefined protocols and are verified on simple simulation data, which are not flexible enough when facing the dynamically changing real-world cases. In this paper, we propose an efficient ambulance dispatch method based on the reinforcement learning framework, i.e., Multi-Agent Q-Network with Experience Replay(MAQR). Specifically, we firstly reformulate the ambulance dispatch problem with a multi-agent reinforcement learning framework, and then design the state, action, and reward function correspondingly for the framework. Thirdly, we design a simulator that controls ambulance status, generates patient requests and interacts with ambulances. Finally, we design extensive experiments to demonstrate the superiority of the proposed method.
Kunpeng Liu 0001, Cliff C. Zou, Yanjie Fu
SIGSPATIAL/GIS3
2020 On Runtime Software Security of TrustZone-M Based IoT Devices
abstract
Internet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension for MCUs, is an emerging security technique fortifying MCU based IoT devices. This paper presents the first security analysis of potential software security issues in TrustZone-M enabled MCUs. We explore the stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against Non-secure Callable (NSC) functions in the context of TrustZone-M. We validate these attacks using the Microchip SAM L11 MCU, which uses the ARM Cortex-M23 processor with the TrustZone-M technology. Strategies to mitigate these software attacks are also discussed.
Yue Zhang 0025, Cliff C. Zou, Xinhui Shao, Zhen Ling 0001, Xinwen Fu
GLOBECOM3
2020 SIC2: Securing Microcontroller Based IoT Devices with Low-cost Crypto Coprocessors
abstract
In this paper, we explore the use of microcontrollers (MCUs) and crypto coprocessors to secure IoT applications, and show how developers may implement a low-cost platform that provides protects private keys against software attacks. We first demonstrate the plausibility of format string attacks on the ESP32, a popular MCU from Espressif that uses the Harvard architecture. The format string attacks can be used to remotely steal private keys hard-coded in the firmware. We then present a framework termed SIC2(Securing IoT with Crypto Coprocessors), for secure key provisioning that protects end users' private keys from both software attacks and untrustworthy manufacturers. As a proof of concept, we pair the ESP32 with the low-cost ATECC608A cryptographic coprocessor by Microchip and connect to Amazon Web Services (AWS) and Amazon Elastic Container Service (EC2) using a hardware-protected private key, which provides the security features of TLS communication including authentication, encryption and integrity. We have developed a prototype and performed extensive experiments to show that the ATECC608A crypto chip may significantly reduce the TLS handshake time by as much as 82% with the remote server, and it may lower the total energy consumption of the system by up to 70%. Our results indicate that securing IoT with crypto coprocessors is a practicable solution for low-cost MCU based IoT devices.
Bryan Pearson, Cliff C. Zou, Yue Zhang 0025, Zhen Ling 0001, Xinwen Fu
ICPADS2
2020 Efficient Off-Chain Transaction to Avoid Inaccessible Coins in Cryptocurrencies
abstract
Bitcoin and other altcoin cryptocurrencies use the Elliptic-Curve cryptography to control the ownership of coins. A user has one or more private keys to sign a transaction and send coins to others. The user locks her private keys with a password and stores them on a piece of software or a hardware wallet to protect them. A challenge in cryptocurrencies is losing access to private keys by its user, resulting in inaccessible coins. These coins are assigned to addresses which access to their private keys is impossible. Today, about 20 percent of all possible bitcoins are inaccessible and lost forever. A promising solution is the off-chain recovery transaction that aggregates all available coins to send them to an address when the private key is not accessible. Unfortunately, this recovery transaction must be regenerated after all sends and receives, and it is time-consuming to generate on hardware wallets. In this paper, we propose a new mechanism called lean recovery transaction to tackle this problem. We make a change in wallet key management to generate the recovery transaction as less frequently as possible. In our design, the wallet generates a lean recovery transaction only when needed and provides better performance, especially for micropayment. We evaluate the regular recovery transaction on two real hardware wallets and implement our proposed mechanism on a hardware wallet. We achieve a %40 percentage of less processing time for generating payment transactions with few numbers of inputs. The performance difference becomes even more significant, with a larger number of inputs.
Hossein Rezaeighaleh, Cliff C. Zou
TrustCom2
2019 New Secure Approach to Backup Cryptocurrency Wallets
abstract
Bitcoin and other cryptocurrencies have become popular and motivate more hackers to steal digital funds. Users protect their private keys using crypto wallets to keep their funds safe from hackers. While the most secure option is hardware wallet, it suffers from lack of a secure and convenient backup and recovery process. Almost all existing wallets use mnemonics to back up the private keys, and a user must write down these words on a piece of paper. This approach is not only inconvenient but also problematic since the paper could be lost or stolen, resulting in a hacker recovering the keys. In this paper, we propose a new digital scheme to securely back up a hardware wallet relying on the side-channel human visual verification enabled by display screen on a hardware wallet. Using this method, we transfer the root of private keys from one hardware wallet to another wallet securely even via an untrusted terminal, such as a smartphone. At the end of this process, the user has two hardware wallets with the same private keys while she may use one of them as the main wallet and another one as a backup wallet.
Hossein Rezaeighaleh, Cliff C. Zou
GLOBECOM2
2019 Using Disposable Domain Names to Detect Online Card Transaction Fraud
abstract
Online card transaction fraud is one of the major threats to the bottom line of E-commerce merchants. In this paper, we propose a novel method for online merchants to utilize disposable (“one-time use”) domain names to detect client IP spoofing by collecting client's DNS information during an E-commerce transaction, which in turn can help with transaction fraud detection. By inserting a dynamically generated unique hostname on the E-commerce transaction webpage, a client will issue an identifiable DNS query to the customized authoritative DNS server maintained by the online Merchant. In this way, the online Merchant is able to collect DNS configuration of the client and match it with the client's corresponding transaction in order to verify the consistency of the client's IP address. Any discrepancy can reveal proxy usage, which fraudsters commonly use to spoof their true origins. We have deployed our preliminary prototype system on a real online merchant and successfully collected clients DNS queries correlated with their web transactions; then we show some real instances of successful fraud detection using this method. We also address some concerns regarding the use of disposable domains.
Roy Laurens, Hossein Rezaeighaleh, Cliff C. Zou, Jusak Jusak
ICC3
2018 A Game Theoretic Approach to Model Cyber Attack and Defense Strategies
abstract
Most of the cybersecurity research focus on either presenting a specific vulnerability %or hacking technique, or proposing a specific defense algorithm to defend against a well-defined attack scheme. Although such cybersecurity research is important, few have paid attention to the dynamic interactions between attackers and defenders, where both sides are intelligent and will dynamically change their attack or defense strategies in order to gain the upper hand over their opponents. This 'cyberwar' phenomenon exists among most cybersecurity incidents in the real world, which warrants special research and analysis. In this paper, we propose a dynamic game theoretic framework (i.e., hyper defense) to analyze the interactions between the attacker and the defender as a non-cooperative security game. The key idea is to model attackers/defenders to have multiple levels of attack/defense strategies that are different in terms of effectiveness, strategy costs, and attack gains/damages. Each player adjusts his strategy based on the strategy's cost, potential attack gain/damage, and effectiveness in anticipating of the opponent's strategy. We study the achievable Nash equilibrium for the attacker-defender security game where the players employ an efficient strategy according to the obtained equilibrium. Furthermore, we present case studies of three different types of network attacks and put forth how our hyper defense system can successfully model them. Simulation results show that the proposed game theoretical system achieves a better performance compared to two other fixed-strategy defense systems.
Afraa Attiah, Mainak Chatterjee, Cliff C. Zou
ICC3
2018 An evolutionary routing game for energy balance in Wireless Sensor Networks
Afraa Attiah, M. Faisal Amjad, Mainak Chatterjee, Cliff C. Zou
Comput. Networks4
2018 Gateway independent user-side wi-fi Evil Twin Attack detection using virtual wireless clients
Omar Nakhila, M. Faisal Amjad, Erich Dondyk, Cliff C. Zou
Comput. Secur.4
2017 Invariant Diversity as a Proactive Fraud Detection Mechanism for Online Merchants
abstract
Online merchants face difficulties in using existing card fraud detection algorithms, so in this paper we propose a novel proactive fraud detection model using what we call invariant diversity to reveal patterns among attributes of the devices (computers or smartphones) that are used in conducting the transactions. The model generates a regression function from a diversity index of various attribute combinations, and use it to detect anomalies inherent in certain fraudulent transactions. This approach allows for proactive fraud detection using a relatively small number of unsupervised transactions and is resistant to fraudsters' device obfuscation attempt. We tested our system successfully on real online merchant transactions and it managed to find several instances of previously undetected fraudulent transactions.
Roy Laurens, Jusak Jusak, Cliff C. Zou
GLOBECOM3
2017 Exposing Vulnerabilities in Mobile Networks: A Mobile Data Consumption Attack
abstract
Smartphone carrier companies rely on mobile networks for keeping an accurate record of customer data usage for billing purposes. In this paper, we present a vulnerability that allows an attacker to force the victim's smartphone to consume data through the cellular network by starting the data download on the victim's cell phone without the victim's knowledge. The attack is based on switching the victim's smartphones from the Wi-Fi network to the cellular network while downloading a large data file. This attack has been implemented in real-life scenarios where the test's outcomes demonstrate that the attack is feasible and that mobile networks do not record customer data usage accurately.
Dean Wasil, Omar Nakhila, Salih Safa Bacanli, Cliff C. Zou, Damla Turgut
MASS4
2017 A Game Theoretic Approach for Energy-Efficient Clustering in Wireless Sensor Networks
abstract
Selection of clusterheads using energy efficient clustering algorithms in a wireless sensor network (WSN) is very crucial as it affects the lifetime and performance of the network. As clusterheads and cluster members (i.e., non-clusterhead nodes) have a different energy consumption rates, it is necessary that all nodes resort to some rational scheme such that the connectivity and proper functioning of the network is not compromised. In this paper, we propose a Cost and Payment-based clustering Algorithm (CoPA) for achieving energy efficiency in wireless sensor networks under a game theoretical framework. The analysis is based on a non-cooperative, repeated general sum game, where each node behaves selfishly in order to maximize its lifespan (payoff). We demonstrate that the correlated equilibrium is a practical solution for clusterhead selection, which provides better performance than the Nash Equilibria. Correlated equilibrium provides a balance between the fully cooperative solution and the fully non-cooperative solution in terms of implementation overhead. CoPA produces a balanced distribution of responsibilities and energy consumption between the sensor nodes as well as maximizes the minimum payoff for every node. Results show that CoPA achieves better performance in terms of network lifetime and throughput compared to other popular clustering techniques.
Afraa Attiah, Mainak Chatterjee, Cliff C. Zou
WCNC3
2016 An Evolutionary Game for Efficient Routing in Wireless Sensor Networks
abstract
One of the major challenges in a wireless sensor network (WSN) is to extend the network's lifetime by minimizing the energy consumption. One of the ways to do so is to reduce network congestion as it increases delays and introduces additional packet collisions- thus, adversely affecting network performance. In this paper, we analyze this issue in routing and take an evolutionary game theoretic approach to show how sensor nodes in a WSN could evolve their routing strategies to transmit data packets in an efficient and stable manner. We derive the equilibrium state for the routing game and prove that there is no mutant- an individual node that adopts another strategy to invade the evolutionary stable strategy (ESS). In addition, we introduce a replicator dynamic model to show the behavior of nodes with various strategies over time. The proposed equilibrium solution aims to alleviate congestion and thereby improves the network lifetime. Simulation results show that the proposed system is successful in converging strategy choices to ESS even under dynamic network conditions.
Afraa Attiah, M. Faisal Amjad, Mainak Chatterjee, Cliff C. Zou
GLOBECOM4
2016 Using Credit/Debit Card Dynamic Soft Descriptor as Fraud Prevention System for Merchant
abstract
This paper presents a novel method of using Dynamic Soft Descriptor as a fraud prevention method for Merchant (as opposed to card Issuer) in a credit/debit card transaction under Card Not Present (CNP) environment, such as online transactions. A unique identifier is embedded into the transaction descriptor, which will instantly appear in the cardholder's credit/debit card online statement. By checking his online statement, or calling his credit/debit card bank, a cardholder can obtain this identifier; and then provides the Merchant with this identifier as a proof of access to the statement. As the identifier is propagated using card association's back-end system and as only legitimate cardholder can access the card's statement, it is very unlikely that a fraudster can obtain this identifier information. Unlike other fraud prevention proposals, this proposed method is readily available and can be used right now by Merchant without the need for explicit support from card Issuer. Furthermore, it can be used starting with the very first transaction. So, it is more attractive than ordinary fraud detection method that requires significant amount of transactions. It can be readily deployed under the current card processing infrastructure, and we will show real life result at an e-commerce Merchant.
Roy Laurens, Cliff C. Zou
GLOBECOM2
2016 Coexistence in heterogeneous spectrum through distributed correlated equilibrium in cognitive radio networks
M. Faisal Amjad, Mainak Chatterjee, Cliff C. Zou
Comput. Networks3
2016 Evolutionary non-cooperative spectrum sharing game: long-term coexistence for collocated cognitive radio networks
abstract
Abstract Collocated cognitive radio networks (CRNs) employ coexistence protocols to share the spectrum when it is not being used by the licensed primary users. These protocols work under the assumption that all spectrum bands provide the same level of quality of service, which is somewhat simplistic because channel conditions as well as the licensee's usage of allocated channels can vary significantly with time and space. These circumstances dictate that some channels may be considered better than others; therefore, CRNs are expected to have a preference over the choice of available channels. Because all CRNs are assumed to be rational and select the best available channels, it can lead to an imbalance in contention for disparate channels, degraded quality of service, and an overall inefficient utilization of spectrum resource. In this paper, we analyze this situation from a game theoretic perspective and model the coexistence of CRNs with heterogeneous spectrum as an evolutionary anti‐coordination spectrum‐sharing game. We derive the evolutionarily stable strategy (ESS) of the game by proving that it cannot be invaded by a greedy strategy. We also derive the replicator dynamics of the proposed evolutionary game, a mechanism with which players can learn from their payoff outcomes of strategic interactions and modify their strategies at every stage of the game and subsequently converge to ESS. Because all CRNs approach ESS based solely upon the common knowledge payoff observations, the evolutionary game can be implemented in a distributed manner. Finally, we analyze the game from the perspective of fairness using Jain's fairness index under selfish behavior from CRNs. Copyright © 2016 John Wiley & Sons, Ltd.
M. Faisal Amjad, Mainak Chatterjee, Omar Nakhila, Cliff C. Zou
Wirel. Commun. Mob. Comput.4
2016 Towards trustworthy collaboration in spectrum sensing for ad hoc cognitive radio networks
M. Faisal Amjad, Baber Aslam, Afraa Attiah, Cliff C. Zou
Wirel. Networks4
2015 SPS: An SMS-based push service for energy saving in smartphone's idle state
abstract
Despite of all the advances in smartphone technology in recent years, smartphones still remain limited by their battery life. Unlike other power hungry components in a smartphone, the cellular data and Wi-Fi interfaces often continue to be used even when the phone is in its idle state in order to accommodate background (necessary or unnecessary) data traffic produced by some applications. In addition, bad reception has been proven to greatly increase energy consumed by the radio, which happens frequently when smartphone users are inside buildings. In this paper, we present a Short message service Push based Service (SPS) system to save unnecessary power consumption when smartphones are in idle state, especially in bad reception areas. First, SPS disables a smartphone's data interfaces whenever the phone is in idle state. Second, to preserve the real-time notification functionality required by some apps, such as new email arrivals and social media updates, when a notification is needed, a push server will deliver a wakeup text message to the phone (which does not rely on data interfaces), and then SPS enables the phone's data interfaces to connect to the corresponding server to retrieve notification data via the normal data network. Once the notification data has been retrieved, SPS will disable the data interfaces again if the phone is still in idle state. We have developed a complete SPS prototype for Android smartphones. Our experiments show that SPS consumes less energy than the current approaches. In areas with bad reception, the SPS prototype can double the battery life of a smartphone.
Erich Dondyk, Omar Nakhila, Cliff C. Zou
CCNC3
2015 User-side Wi-Fi Evil Twin Attack detection using SSL/TCP protocols
abstract
Evil Twin Attack (ETA) refers to a rogue Wi-Fi Access Point (AP) that appears to be a legitimate one but actually has been set up to eavesdrop on wireless communications [1]. Most of existing detection techniques assume that the attacker will use the same legitimate wireless network gateway to pass through victim's wireless data. These detection methods will fail if the attacker uses a different gateway, such as using his own broadband cellular connection through his own smartphone. In this paper, we present a new client-side detection method to detect such an ETA that uses a different gateway from the legitimate one. It relies on SSL/TCP connection to an arbitrary remote web server to avoid attacker's misleading message, and trying to detect the changing of gateway's public IP address by switching from one AP to another in the middle of the SSL/TCP connection. The detection method is on the client side which makes it more convenient for users to deploy and ensure their security.
Omar Nakhila, Erich Dondyk, M. Faisal Amjad, Cliff C. Zou
CCNC4
2015 Redundancy control through traffic deduplication
abstract
Statistics show that 79% of the Internet traffic is video and mostly “redundant”. Video-On-Demand in particular follows a 90/10 access pattern, where 90% of the users access the same 10% of all video content. As a result, redundant data are repeatedly transmitted over the Internet. In this paper, we propose a novel traffic deduplication technique to achieve more efficient network communication between video sources (video servers or proxy servers in a CDN) and clients. The proposed SMART (Small packet Merge-Able RouTers) overlay network employs an opportunistic traffic deduplication approach and allows each SMART router to dynamically merge independent streams of the same video content, forming a video streaming tree (VST). The merged streams are tunneled through the overlay together with TCP sessions information before eventually being de-multiplexed and delivered to the clients fully compatible with the TCP protocol. We present theoretical analysis findings on the merging strategy between the video source and clients, the efficiency of the SMART router to save traffic during a merge process, and the overall performance of implementing a SMART overlay topology between a video source and clients. Finally, we prototyped SMART in the PlanetLab environment. We illustrate that performance evaluation results are consistent with our theoretical analysis and significant bandwidth saving is achieved.
Kien A. Hua, Jason Kuhns, Vaithiyanathan Sundaram, Cliff C. Zou
INFOCOM5
2014 Click-tracking blocker: Privacy preservation by disabling search engines' click-tracking
abstract
On a search engine result page, if a user clicks on any one of those contained URL links, whether it is a search result website (called organic link), or a search related advertisement link (called sponsored link), the user's click action will be tracked by returning back to the search engine first and then redirecting to the corresponding target website. This click-tracking is conducted by all three major search engines: Google, Bing, and Yahoo (although Bing does not track clicks on organic links). Many people are not aware that their clicks are tracked by search companies; and this click-tracking imposes a big privacy threat for privacy-concerned users. After discovering that all organic and sponsored links in a search engine result page actually encode the real URLs of target websites with simple encoding techniques, we have developed a browser plug-in program called Click-Tracking Blocker that modifies all URLs on search result pages once they are retrieved by users' computers, such that search engines will no longer be able to track users' clicking behaviors on both organic links and sponsored links. Click-Tracking Blocker can be readily and easily installed by end users to protect their privacy, works for all three major search engines, and does not affect users' search experience.
Roberto Alberdeston, Erich Dondyk, Cliff C. Zou
GLOBECOM3
2014 Modeling and Analysis on the Propagation Dynamics of Modern Email Malware
abstract
Due to the critical security threats imposed by email-based malware in recent years, modeling the propagation dynamics of email malware becomes a fundamental technique for predicting its potential damages and developing effective countermeasures. Compared to earlier versions of email malware, modern email malware exhibits two new features, reinfection and self-start. Reinfection refers to the malware behavior that modern email malware sends out malware copies whenever any healthy or infected recipients open the malicious attachment. Self-start refers to the behavior that malware starts to spread whenever compromised computers restart or certain files are visited. In the literature, several models are proposed for email malware propagation, but they did not take into account the above two features and cannot accurately model the propagation dynamics of modern email malware. To address this problem, we derive a novel difference equation based analytical model by introducing a new concept of virtual infected user. The proposed model can precisely present the repetitious spreading process caused by reinfection and self-start and effectively overcome the associated computational challenges. We perform comprehensive empirical and theoretical study to validate the proposed analytical model. The results show our model greatly outperforms previous models in terms of estimation accuracy.
Sheng Wen, Wei Zhou 0044, Jun Zhang 0010, Yang Xiang 0001, Wanlei Zhou 0001, Weijia Jia 0001, Cliff C. Zou
IEEE Trans. Dependable Secur. Comput.7
2013 Transparent cross-layer solutions for throughput boost in Cognitive Radio Networks
abstract
Cognitive Radio Network (CRN) is an emerging paradigm that makes use of Dynamic Spectrum Access (DSA) to communicate opportunistically, in the un-licensed Industrial, Scientific and Medical bands or frequency bands otherwise licensed to incumbent users such as TV broadcast. The opportunistic mode of data transfer introduces network-wide quiet periods for spectrum sensing and increased packet losses due to activities by Primary Users. TCP attributes packet delays and losses to congestion in the Internet, which does not perform well in wireless networks where the medium has inherent higher error rates than wired Internet. Opportunistic mode of communication in CRNs aggravates the already error-prone wireless communication resulting in further degradation of TCP performance due to higher latency and decreased throughput. This paper presents an analysis of TCP performance in IEEE 802.22 Wireless Regional Area Network (WRAN) based on Cognitive Radio Networks and proposes two approaches to improve the networking performance. The first approach makes base station resort to local recovery of lost frames between CRN base station and its clients, while the second approach implements a modified split TCP connection in which the base station sends crafted acknowledgements back to an Internet-side host on behalf of the corresponding CRN client to boost transmission speed. To the best of our knowledge, this is the first effort to study TCP performance in IEEE 802.22 based WRANs. Simulation results show that the proposed mechanisms result in improvement in TCP performance by as much as 20 times and conserve bandwidth by reducing retransmission overheads.
M. Faisal Amjad, Baber Aslam, Cliff C. Zou
CCNC3
2013 Denial of convenience attack to smartphones using a fake Wi-Fi access point
abstract
In this paper, we present a novel denial-of-service attack targeted at popular smartphones that are used by normal users who are not technology savvy. This type of attack, which we call a denial-of-convenience attack, prevents non-technical savvy victims from utilizing data services by exploiting the connectivity management protocol of smartphones when encountered with a Wi-Fi access point. By setting up a fake Wi-Fi access point without Internet access (using a simple device such as a laptop computer), an attacker can prompt a smartphone with enabled Wi-Fi features to automatically terminate a valid mobile broadband connection and connect to this fake Wi-Fi access point. This, as a result, prevents the targeted smartphone from having any type of Internet connection unless the victim is capable of identifying the attack and manually disabling the Wi-Fi features. We demonstrate that most popular smartphones, including iPhone and Android phones, are vulnerable to denial-of-convenience attacks. To address this attack, we propose implementing a novel Internet-access validation protocol that uses the cellular network to send a secret key phrase to an Internet validation server. Then, it attempts to retrieve this secret key phrase via the newly established Wi-Fi channel to validate the Wi-Fi access point. We have fully developed and evaluated the attacks as well as the defense prototypes that run on Android phones.
Erich Dondyk, Cliff C. Zou
CCNC2
2013 DS3: A Dynamic and Smart Spectrum Sensing Technique for Cognitive Radio Networks under denial of service attack
abstract
IEEE 802.22 Cognitive Radio Networks (CRN) employ a two-stage quiet period mechanism based on a mandatory Fast Sensing and an optional Fine Sensing stage for Dynamic Spectrum Access (DSA) during every super frame. However, the two-stage spectrum sensing approach presents an opportunity to malicious users where they can launch a smart Denial of Service (DoS) attack by transmitting a very short jamming signal during the fast sensing stage and thus forcing the CRN to carry out fine sensing, thereby wasting spectrum opportunities for honest Secondary Users (SU). In this paper, we present ‘DS3’: A Dynamic and Smart Spectrum Sensing algorithm, which minimizes the effects of jamming as well as noise on the fast sensing phase of DSA. It improves system's efficiency by striking a balance between spectrum utilization by SUs and delay in the detection of Primary Users' (PU) presence on the spectrum, using a dynamic fine sensing decision algorithm with minimal overhead.
M. Faisal Amjad, Baber Aslam, Cliff C. Zou
GLOBECOM3
2013 SMM rootkit: a new breed of OS independent malware
abstract
Abstract The emergence of hardware virtualization technology has led to the development of OS independent malware such as the virtual machine‐based rootkits (VMBRs). In this paper, we draw attention to a different but related threat that exists on many commodity systems in operation today: The system management Mode based rootkit (SMBR). System Management mode (SMM) is a relatively obscure mode on Intel processors used for low‐level hardware control. It has its own private memory space and execution environment which is generally invisible to code running outside (e.g., the Operating System). Furthermore, SMM code is completely non‐preemptible, lacks any concept of privilege level, and is immune to memory protection mechanisms. These features make it a potentially attractive home for stealthy rootkits used for high‐profile targeted attacks. In this paper, we present our development of a proof of concept SMM rootkit. In it, we explore the potential of system management mode for malicious use by implementing a chipset level keylogger and a network backdoor capable of directly interacting with the network card to send logged keystrokes to a remote machine via UDP and receive remote command packets stealthily. By modifying and reflashing the BIOS, the SMM rootkit can install itself on a computer even if the computer has originally locked its SMM. The rootkit hides its memory footprint and requires no changes to the existing operating system. It is compared and contrasted with VMBRs. Finally, techniques to defend against these threats are explored. By taking an offensive perspective we hope to help security researchers better understand the depth and scope of the problems posed by an emerging class of OS independent malware. Copyright © 2009 John Wiley & Sons, Ltd.
Shawn Embleton, Sherri Sparks, Cliff C. Zou
Secur. Commun. Networks3
2013 Defense against Sybil attack in the initial deployment stage of vehicular ad hoc network based on roadside unit support
abstract
ABSTRACT In this paper, we propose two certificate mechanisms for preventing the Sybil attack in a vehicular ad hoc network (VANET): the timestamp series approach and the temporary certificate approach. We focus on an early‐stage VANET when the number of smart vehicles is only a small fraction of the vehicles on the road and the only infrastructure components available are the roadside units (RSUs). Our approach does not require a dedicated vehicular public key infrastructure to certify individual vehicles but RSUs are the only components issuing certificates. The vehicles can obtain certificates by simply driving by RSUs, without the need to pre‐register at a certificate authority. The timestamp series approach exploits the fact that because of the variance of the movement patterns of the vehicles, it is extremely rare that the two vehicles pass by a series of RSUs at exactly the same time points. The vehicles obtain a series of certificates signed by the RSUs, which certify their passing by at the RSU at a certain time point. By exploiting the spatial and temporal correlation between vehicles and RSUs, we can detect the Sybil attack by checking the similarity of timestamp series. In the temporary certificate‐based approach, an RSU issues temporary certificates valid only in a particular area for a limited time. To guarantee that each vehicle is assigned only a single certificate, at the issuance of the first certificate, it is required that the RSU physically authenticate the vehicle. When driving by the subsequent RSUs, however, the certificate can be updated in a chained manner. By guaranteeing that each vehicle is issued a single certificate in a single area, the Sybil attack is prevented. We provide mathematical analysis and simulation for the timestamp series approach. The simulation shows that it works with a small false‐positive rate in simple roadway architecture. Copyright © 2013 John Wiley & Sons, Ltd.
Baber Aslam, Damla Turgut, Cliff C. Zou
Secur. Commun. Networks4
2012 Encrypted phrase searching in the cloud
abstract
As cloud computing is increasing in popularity, it is difficult to both maintain privacy in datasets while still providing adequate retrieval and searching procedures. This paper introduces a novel approach in the field of encrypted searching that allows both encrypted phrase searches and proximity ranked multi-keyword searches to encrypted datasets on untrusted cloud. By storing encrypted keyword-location data along with specially truncated encrypted keyword indexes in a relational database, we are able to allow for a full range of search features in our encrypted searches, something that has never been accomplished before. Furthermore, our approach permits the encrypted corpus and index to both be stored on cloud data servers. We modify currently available open-source search engine software to complete a prototype and provide results from experiments on a large scale real-world dataset that has more than half a million documents.
Steven Zittrower, Cliff C. Zou
GLOBECOM2
2012 nSwitching: Virtual Machine aware relay hardware switching to improve intra-NIC Virtual Machine traffic
abstract
Recent development on Ethernet switching to provide Single Root I/O Virtualization (SR-IOV) on network interface cards (NICs) improves Ethernet throughput for Virtual Machines (VMs) and lowers CPU loads. SR-IOV creates multiple receive queues on a NIC, directly accessible by VMs for frames coming from sources external to the Ethernet port. This virtualization of Ethernet ports and the presentation of frames directly to VMs eliminates a major cause for CPU loading by reducing the interrupts for receipt of inbound frames. However, SR-IOV cannot provide switching support for two VMs on the same computer; the only existing switching option is software-based switching in the hypervisor, which limits throughput and results in high CPU utilization. New industry standards 802.1Qbg and 802.1Qbh assist Ethernet traffic between VMs, but they require costly replacement of both Ethernet NICs and the data center external physical switch infrastructure. In this paper, we propose a new design by integrating a new Ethernet switching functionality into the NIC, which is called nSwitch, to enable hardware-based switching for inter-VM traffic on a single computer that has a single or multi-socket, multi-core CPU. Compared with software-based switching in the hypervisor, this enhancement greatly reduces CPU utilization and permits efficient traffic monitoring for on-board inter-VM I/O. Furthermore, it eliminates the back-and-forth usage of external port or channel bandwidth for internal VM communications.
Jim Bardgett, Cliff C. Zou
ICC2
2012 Optimal roadside units placement in urban areas for vehicular networks
abstract
The most important component of a vehicular ad hoc network (VANET), besides VANET-enabled vehicles, is roadside units (RSUs). The effectiveness of a VANET largely depends on the density and location of these RSUs. During the initial stages of VANET, it will not be possible to deploy a large number of RSUs either due to the low market penetration of VANET-enabled vehicles or due to the deployment cost of RSUs. There is, therefore, a need to optimally place a limited number of RSUs in a given region in order to achieve maximum performance. In this paper, we present two different optimization methods for placement of a limited number of RSUs in an urban region: an analytical Binary Integer Programming (BIP) method and a novel Balloon Expansion Heuristic (BEH) method. BIP method utilizes branch and bound approach to find an optimal analytical solution whereas BEH method uses balloon expansion analogy to find an optimal or near optimal solution. Our evaluations show that both methods perform optimally or near optimally compared with the exhaustive method. Further, BEH method is more versatile and performs better than BIP method in terms of computational cost and scalability.
Baber Aslam, M. Faisal Amjad, Cliff C. Zou
ISCC3
2011 One-way-linkable blind signature security architecture for VANET
abstract
Security attributes of a Vehicular ad hoc network (VANET) include confidentiality, integrity, authentication, non-repudiation (liability), revocation and privacy. Privacy, having characteristics opposing to the rest of the attributes, makes design of a security architecture quite difficult. A commonly used solution is to have a large number of temporary certificates (i.e., pseudonyms) to achieve these security attributes. To guard against their malicious use, these pseudonyms are stored in expensive tamper-proof-devices (TPDs). Further, a large number of valid pseudonyms, at any given time, make non-repudiation and revocation quite complex and difficult to achieve. Another solution is to get pseudonyms blindly signed from a certificate server, thus eliminating the need of TPDs (given the pseudonyms are not generated in bulk). However, blind signatures provide unconditional privacy and thus require complex/multi-transaction procedures to ensure non-repudiation/revocation. We present a security architecture by revising the original Blind signature scheme. Our proposed architecture provides “one-way-link-ability” that helps to achieve all the security attributes without introducing complex/multi-transaction procedures. It does not require expensive TPDs or complex pseudonym issuance/revocation procedures and is especially suited to VANET during initial deployment phase which is characterized with intermittent connectivity. Further, non-repudiation/revocation requires cooperation between multiple entities thus ensuring privacy without a single point of failure.
Baber Aslam, Cliff C. Zou
CCNC2
2011 Optimal roadside units placement along highways
abstract
Roadside units (RSUs) are a critical component of Vehicular ad hoc network (VANET). Ideally, RSUs should be deployed pervasively to provide continuous coverage or connectivity. However, during the initial stages of VANET, it will not be possible to ensure such a pervasive RSU deployment due to the huge cost and/or the lack of market penetration of VANET enabled vehicles. Given a limited number of RSUs, in this paper, we address the issue of optimal placement of these RSUs along highways with the goal of minimizing the average time taken for a vehicle to report an event of interest to a nearby RSU. We present a so-called balloon optimization method - the optimal solution is found by using a dynamic process similar to the natural expansion of multiple balloons in a two-dimensional space where each balloon corresponds to the coverage area of one RSU. Our preliminary evaluation shows that the balloon method performs optimal or near optimal compared with the exhaustive method and it can be used for the optimal placement of RSUs along highways.
Baber Aslam, Cliff C. Zou
CCNC2
2011 Long-term reputation system for vehicular networking based on vehicle's daily commute routine
abstract
A vehicular network must ensure a trust relationship among participating “smart vehicles” (vehicles installed with wireless network devices) and roadside infrastructure in order to maximize the benefit provided by the network. In this paper, we present practical ways to provide reliable reputation scores for vehicles in a vehicular network. Because in most of the time, the majority of people drive their vehicles locally for their daily commute (to work places, schools, daycares, superstores, etc), most vehicles have their predefined constant daily trajectories. Based on this phenomenon, roadside infrastructure could rely on repeated daily observations of the same set of passing-by vehicles to build long-term reputation scores for these local “community” vehicles, in the similar way as the reputation built-up for people in a club or a church community. The proposed scheme does not require sufficient density of smart vehicles and only requires each smart vehicle has one secret and verifiable certificate. These features make it especially suitable for the initial deployment stage of vehicular network when the penetration rate of smart vehicles is very low and vehicle-based public-key infrastructure is not mature.
Baber Aslam, Cliff C. Zou
CCNC3
2011 iCAPTCHA: The Next Generation of CAPTCHA Designed to Defend against 3rd Party Human Attacks
abstract
CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) is a simple test that is easy for humans but extremely difficult for computers to solve. CAPTCHA has been widely used in commercial websites such as web-based email providers, TicketMaster, GoDaddy, and Facebook to protect their resources from attacks initiated by automatic scripts. By design, CAPTCHA is unable to distinguish between a human attacker and a legitimate human user. This leaves websites using CAPTCHA vulnerable to 3rd party human CAPTCHA attacks. In order to demonstrate the vulnerabilities in existing CAPTCHA technologies we develop a new streamlined human-based CAPTCHA attack that uses Instant Messenger infrastructure. Facing this serious human-based attack threat, we then present a new defense system called Interactive CAPTCHA (iCAPTCHA), which is the next generation of CAPTCHA technology providing the first steps toward defending against 3rd party human CAPTCHA attacks. iCAPTCHA requires a user to solve a CAPTCHA test via a series of user interactions. The multi-step back-and-forth traffic between client and server amplifies the statistical timing difference between a legitimate user and a human solver, which enables better attack detection performance. A performance and usability study of iCAPTCHA shows the proposed scheme is effective in attack detection, is easy to use, and is a viable replacement of the current text-based CAPTCHA.
Huy D. Truong, Christopher F. Turner, Cliff C. Zou
ICC3
2011 Harnessing the power of BitTorrent for distributed denial-of-service attacks
abstract
Abstract BitTorrent is a popular peer‐to‐peer (P2P) file‐sharing protocol that utilizes a central server, known as a ‘tracker’, to coordinate connections between peers in a ‘swarm’, a term used to describe a BitTorrent ad‐hocfile sharing network. The tracker of a swarm is specified by the original file distributor and trusted unconditionally by peers in the swarm. This central point of control provides an opportunity for a file distributor to deploy a modified tracker to provide peers in a swarm with malicious coordination data, directing peer connection traffic toward an arbitrary target machine on an arbitrary service port. Although such an attack does not generate huge amount of attack traffic, it would set up many connections with the victim server successfully, which could cause serious denial‐of‐service by exhausting the victim server's connection resource. In this paper, we present and demonstrate such an attack that is entirely tracker‐based, requiring no modifications to BitTorrent client software and could be deployed by an attacker right now. The results from both emulation and real‐world experiments show the applicability of this attack. Due to the skyrocketing popularity of BitTorrent and numerous large‐scale swarms existed in the Internet, BitTorrent swarms provide an intriguing platform for launching distributed denial‐of‐service (DDoS) attacks based on connection exhaustion. Copyright © 2010 John Wiley & Sons, Ltd.
Jerome Harrington, Corey Kuwanoe, Cliff C. Zou
Secur. Commun. Networks4
2010 Scene tagging: image-based CAPTCHA using image composition and object relationships
abstract
In this paper, we propose a new form of image-based CAPTCHA we term "scene tagging". It tests the ability to recognize a relationship between multiple objects in an image that is automatically generated via composition of a background image with multiple irregularly shaped object images, resulting in a large space of possible images and questions without requiring a large object database. This composition process is accompanied by a carefully designed sequence of systematic image distortions that makes it difficult for automated attacks to locate/identify objects present. Automated attacks must recognize all or most objects contained in the image in order to answer a question correctly, thus the proposed approach reduces attack success rates. An experimental study using several widely-used object recognition algorithms (PWD-based template matching, SIFT, SURF) shows that the system is resistant to these attacks with a 2% attack success rate, while a user study shows that the task required can be performed by average users with a 97% success rate.
Peter Matthews, Cliff C. Zou
AsiaCCS2
2010 PwdIP-Hash: A Lightweight Solution to Phishing and Pharming Attacks
abstract
We present a novel lightweight password-based solution that safeguards users from Phishing and Pharming attacks. The proposed authentication relies on a hashed password, which is the hash value of the user-typed password and the authentication server's IP address. The solution rests on the fact that the server connected by a client using TCP connection cannot lie about its IP address. If a user is unknowingly directed to a malicious server (by a Phishing or a Pharming attack), the password obtained by the malicious server will be the hashed-password (tied to the malicious server's IP address) and will not be usable by the attacker at the real server thus defeating Phishing/Pharming attack. The proposed solution does not increase the number of exchanged authentication messages, nor does it need hardware tokens as required by some previously proposed solutions. The solution is also safe against denial-of-service attacks since no state is maintained on server side during the authentication process. We have prototyped our design both as a web browser's plug-in and as a standalone application. A comprehensive user study was conducted. The results show that around 95% of users think the proposed solution is easy to use and manage. Further, around 79% of users have shown willingness to use the application to protect their passwords.
Baber Aslam, Cliff C. Zou
NCA3
2010 Honeypot detection in advanced botnet attacks
abstract
Botnets have become one of the major attacks in the internet today due to their illicit profitable financial gain. Meanwhile, honeypots have been successfully deployed in many computer security defence systems. Since honeypots set up by security defenders can attract botnet compromises and become spies in exposing botnet membership and botnet attacker behaviours, they are widely used by security defenders in botnet defence. Therefore, attackers constructing and maintaining botnets will be forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have a liability constraint such that they cannot allow their honeypots to participate in real attacks that could cause damage to others, while attackers do not need to follow this constraint. Attackers could detect honeypots in their botnets by checking whether compromised machines in a botnet can successfully send out unmodified malicious traffic. Based on this basic detection principle, we present honeypot detection techniques to be used in both centralised botnets and Peer-to-Peer (P2P) structured botnets. Experiments show that current standard honeypots and honeynet programs are vulnerable to the proposed honeypot detection techniques. At the end, we discuss some guidelines for defending against general honeypot-aware attacks.
Ryan Cunningham, Cliff C. Zou
Int. J. Inf. Comput. Secur.4
2010 An Advanced Hybrid Peer-to-Peer Botnet
abstract
A “botnet” consists of a network of compromised computers controlled by an attacker (“botmaster”). Recently, botnets have become the root cause of many Internet attacks. To be well prepared for future attacks, it is not enough to study how to detect and defend against the botnets that have appeared in the past. More importantly, we should study advanced botnet designs that could be developed by botmasters in the near future. In this paper, we present the design of an advanced hybrid peer-to-peer botnet. Compared with current botnets, the proposed botnet is harder to be shut down, monitored, and hijacked. It provides robust network connectivity, individualized encryption and control traffic dispersion, limited botnet exposure by each bot, and easy monitoring and recovery by its botmaster. In the end, we suggest and analyze several possible defenses against this advanced botnet.
Sherri Sparks, Cliff C. Zou
IEEE Trans. Dependable Secur. Comput.3
2009 A chipset level network backdoor: bypassing host-based firewall & IDS
abstract
Chipsets refer to a set of specialized chips on a computer's motherboard or an expansion card [12]. In this paper we present a proof of concept chipset level rootkit/network backdoor. It interacts directly with network interface card hardware based on a widely deployed Intel chipset 8255x, and we tested it successfully on two different Ethernet cards with this chipset. The network backdoor has the ability to both covertly send out packets and receive packets, without the need to disable security software installed in the compromised host in order to hide its presence. Because of its low-level position in a computer system, the backdoor is capable of bypassing virtually all commodity firewall and host-based intrusion detection software, including popular, widely deployed applications like Snort and Zone Alarm Security Suite. Such network backdoors, while complicated and hardware specific, are likely to become serious threats in high profile attacks like corporate espionage or cyber terrorist attacks. Copyright 2009 ACM.
Sherri Sparks, Shawn Embleton, Cliff C. Zou
AsiaCCS3
2009 Pervasive Internet Access by Vehicles through Satellite Receive-Only Terminals
abstract
Ubiquitous Internet connectivity is very important in present environment. A lot of research has been done to extend Internet connectivity to vehicular ad hoc networks (VANETs). The biggest challenge to achieve this goal is the requirement of pervasive fully networked roadside infrastructure. This requirement is difficult to achieve especially during the initial deployment phase of vehicular networks and also in areas with scarce roadside infrastructure (such as along highways and in rural areas). This makes solutions that are solely dependent on roadside infrastructure impracticable to be implemented. Other solutions using cellular networks or symmetric satellite communication are either expensive or do not provide sufficient bandwidth. Further satellite communication suffers heavy losses in urban area and makes its use difficult in vehicular networks. We present a solution that complements the existing ones without requiring a fully networked roadside infrastructure. The solution uses satellite receive-only terminals and very few (widely spaced) roadside units to provide pervasive Internet connectivity. The solution is cost effective, incremental and practical. It can support TCP connection even when the uplink is interrupted for long durations of time. We present several different design options with varying degrees of error handling capabilities and different overheads and delays, which can be used according to the given environment.
Baber Aslam, Cliff C. Zou
ICCCN3
2009 A Systematic Study on Peer-to-Peer Botnets
abstract
"Botnet" is a network of computers that are compromised and controlled by an attacker. Botnets are one of the most serious threats to today's Internet. Most current botnets have centralized command and control (C&C) architecture. However, peer-to-peer (P2P) structured botnets have gradually emerged as a new advanced form of botnets. Without central C&C servers, P2P botnets are more resilient to defenses and countermeasures than traditional centralized botnets. In this paper, we systematically study P2P botnets along multiple dimensions: bot candidate selection, network construction, C&C mechanisms and communication protocols, and mitigation approaches. We carefully study two defense approaches: index poisoning and sybil attack. According to the common idea shared by them, we are able to give analytical results to evaluate their performance. We also propose possible counter techniques which might be developed by attackers against index poisoning and sybil attack defenses. In addition, we obtain one interesting finding: compared to traditional centralized botnets, by using index poisoning technique, it is easier to shut down or at least effectively mitigate P2P botnets that adopt existing P2P protocols and rely on file index to disseminate commands.
Baber Aslam, Cliff C. Zou
ICCCN4
2008 SMM rootkits: a new breed of OS independent malware
abstract
The emergence of hardware virtualization technology has led to the development of OS independent malware such as the Virtual Machine based rootkits (VMBRs). In this paper, we draw attention to a different but related threat that exists on many commodity systems in operation today: The System Management Mode based rootkit (SMBR). System Management Mode (SMM) is a relatively obscure mode on Intel processors used for low-level hardware control. It has its own private memory space and execution environment which is generally invisible to code running outside (e.g., the Operating System). Furthermore, SMM code is completely non-preemptible, lacks any concept of privilege level, and is immune to memory protection mechanisms. These features make it a potentially attractive home for stealthy rootkits. In this paper, we present our development of a proof of concept SMM rootkit. In it, we explore the potential of System Management Mode for malicious use by implementing a chipset level keylogger and a network backdoor capable of directly interacting with the network card to send logged keystrokes to a remote machine via UDP. The rootkit hides its memory footprint and requires no changes to the existing Operating System. It is compared and contrasted with VMBRs. Finally, techniques to defend against these threats are explored. By taking an offensive perspective we hope to help security researchers better understand the depth and scope of the problems posed by an emerging class of OS independent malware.
Shawn Embleton, Sherri Sparks, Cliff C. Zou
SecureComm3
2007 Automated Vulnerability Analysis: Leveraging Control Flow for Evolutionary Input Crafting
abstract
We present an extension of traditional "black box" fuzz testing using a genetic algorithm based upon a dynamic Markov model fitness heuristic. This heuristic allows us to "intelligently" guide input selection based upon feedback concerning the "success" of past inputs that have been tried. Unlike many software testing tools, our implementation is strictly based upon binary code and does not require that source code be available. Our evaluation on a Windows server program shows that this approach is superior to random black box fuzzing for increasing code coverage and depth of penetration into program control flow logic. As a result, the technique may be beneficial to the development of future automated vulnerability analysis tools.
Sherri Sparks, Shawn Embleton, Ryan Cunningham, Cliff C. Zou
ACSAC4
2007 Modeling and Simulation Study of the Propagation and Defense of Internet E-mail Worms
abstract
As many people rely on e-mail communications for business and everyday life, Internet e-mail worms constitute one of the major security threats for our society. Unlike scanning worms such as Code Red or Slammer, e-mail worms spread over a logical network defined by e-mail address relationships, making traditional epidemic models invalid for modeling the propagation of e-mail worms. In addition, we show that the topological epidemic models presented by M. Boguna, et al. (2000) largely overestimate epidemic spreading speed in topological networks due to their implicit homogeneous mixing assumption. For this reason, we rely on simulations to study e-mail worm propagation in this paper. We present an e-mail worm simulation model that accounts for the behaviors of e-mail users, including e-mail checking time and the probability of opening an e-mail attachment. Our observations of e-mail lists suggest that an Internet e-mail network follows a heavy-tailed distribution in terms of node degrees, and we model it as a power-law network. To study the topological impact, we compare e-mail worm propagation on power-law topology with worm propagation on two other topologies: small-world topology and random-graph topology. The impact of the power-law topology on the spread of e-mail worms is mixed: E-mail worms spread more quickly on a power-law topology than on a small-world topology or a random-graph topology, but immunization defense is more effective on a power-law topology.
Cliff C. Zou, Don Towsley, Weibo Gong
IEEE Trans. Dependable Secur. Comput.1
2006 Honeypot-Aware Advanced Botnet Construction and Maintenance
abstract
Because "botnets" can be used for illicit financial gain, they have become quite popular in recent Internet attacks. "Honeypots" have been successfully deployed in many defense systems. Thus, attackers constructing and maintaining botnets are forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have liability constraints such that they cannot allow their honeypots to participate in real (or too many real) attacks. Based on this assumption, attackers can detect honeypots in their botnet by checking whether the compromised machines in the botnet can successfully send out unmodified malicious traffic to attackers' sensors or whether the bot controller in their botnet can successfully relay potential attack commands. In addition, we present a novel "two-stage reconnaissance" worm that can automatically construct a peer-to-peer structured botnet and detect and remove infected honeypots during its propagation stage. Finally, we discuss some guidelines for defending against the general honeypot-aware attacks
Cliff C. Zou, Ryan Cunningham
DSN1
2006 Modeling Botnet Propagation Using Time Zones
David Dagon, Cliff C. Zou, Wenke Lee
NDSS2
2006 Adaptive Defense Against Various Network Attacks
abstract
In defending against various network attacks, such as distributed denial-of-service (DDoS) attacks or worm attacks, a defense system needs to deal with various network conditions and dynamically changing attacks. Therefore, a good defense system needs to have a built-in "adaptive defense" functionality based on cost minimization-adaptively adjusting its configurations according to the network condition and attack severity in order to minimize the combined cost introduced by false positives (misidentify normal traffic as attack) and false negatives (misidentify attack traffic as normal) at any time. In this way, the adaptive defense system can generate fewer false alarms in normal situations or under light attacks with relaxed defense configurations, while protecting a network or a server more vigorously under severe attacks. In this paper, we present concrete adaptive defense system designs for defending against two major network attacks: SYN flood DDoS attack and Internet worm infection. The adaptive defense is a high-level system design that can be built on various underlying nonadaptive detection and filtering algorithms, which makes it applicable for a wide range of security defenses
Cliff C. Zou, Nick G. Duffield, Don Towsley, Weibo Gong
IEEE J. Sel. Areas Commun.1
2006 On the performance of Internet worm scanning strategies
Cliff C. Zou, Don Towsley, Weibo Gong
Perform. Evaluation1
2005 The monitoring and early detection of internet worms
abstract
After many Internet-scale worm incidents in recent years, it is clear that a simple self-propagating worm can quickly spread across the Internet and cause severe damage to our society. Facing this great security threat, we need to build an early detection system that can detect the presence of a worm in the Internet as quickly as possible in order to give people accurate early warning information and possible reaction time for counteractions. This paper first presents an Internet worm monitoring system. Then, based on the idea of "detecting the trend, not the burst" of monitored illegitimate traffic, we present a "trend detection" methodology to detect a worm at its early propagation stage by using Kalman filter estimation, which is robust to background noise in the monitored data. In addition, for uniform-scan worms such as Code Red, we can effectively predict the overall vulnerable population size, and estimate accurately how many computers are really infected in the global Internet based on the biased monitored data. For monitoring a nonuniform scan worm, especially a sequential-scan worm such as Blaster, we show that it is crucial for the address space covered by the worm monitoring system to be as distributed as possible.
Cliff C. Zou, Weibo Gong, Don Towsley, Lixin Gao 0001
IEEE/ACM Trans. Netw.1
2004 Email Worms Modeling and Defense
abstract
Email worms constitute one of the major Internet security problems. We present an email worm model that accounts for the behaviors of email users by considering email checking time and the probability of opening email attachments. Email worms spread over a logical network defined by email address relationship, which plays an important role in determining the spreading dynamics of an email worm. Our observations suggest that the node degrees of an email network are heavy-tailed distributed. We compare email worm propagation on three topologies: power law, small world and random graph topologies; and then study how the topology affects immunization defense on email worms. The impact of the power law topology on the spread of email worms is mixed: email worms spread more quickly on a power law topology than on a small world topology or a random graph topology, but immunization defense is more effective on a power law topology than on the other two.
Cliff C. Zou, Don Towsley, Weibo Gong
ICCCN1
2003 Monitoring and early warning for internet worms
abstract
After the Code Red incident in 2001 and the SQL Slammer in January 2003, it is clear that a simple self-propagating worm can quickly spread across the Internet, infects most vulnerable computers before people can take effective countermeasures. The fast spreading nature of worms calls for a worm monitoring and early warning system. In this paper, we propose effective algorithms for early detection of the presence of a worm and the corresponding monitoring system. Based on epidemic model and observation data from the monitoring system, by using the idea of "detecting the trend, not the rate" of monitored illegitimated scan traffic, we propose to use a Kalman filter to detect a worm's propagation at its early stage in real-time. In addition, we can effectively predict the overall vulnerable population size, and correct the bias in the observed number of infected hosts. Our simulation experiments for Code Red and SQL Slammer show that with observation data from a small fraction of IP addresses, we can detect the presence of a worm when it infects only 1% to 2% of the vulnerable computers on the Internet.
Cliff C. Zou, Lixin Gao 0001, Weibo Gong, Don Towsley
CCS1
2002 Code red worm propagation modeling and analysis
abstract
The Code Red worm incident of July 2001 has stimulated activities to model and analyze Internet worm propagation. In this paper we provide a careful analysis of Code Red propagation by accounting for two factors: one is the dynamic countermeasures taken by ISPs and users; the other is the slowed down worm infection rate because Code Red rampant propagation caused congestion and troubles to some routers. Based on the classical epidemic Kermack-Mckendrick model, we derive a general Internet worm model called the two-factor worm model. Simulations and numerical solutions of the two-factor worm model match the observed data of Code Red worm better than previous models do. This model leads to a better understanding and prediction of the scale and speed of Internet worm spreading.
Cliff C. Zou, Weibo Gong, Don Towsley
CCS1