Andrei V. Gurtov

dblp:04/6586 · DBLP profile ↗
← Back
75ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-9829-9287ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 49 · 3 first-author · 8 since 2021Security and privacy · 6 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Secure Scalable VPLS: A Lagrangian Relaxation Approach to Tunnel Relaying Optimization
abstract
Virtual Private LAN Service (VPLS) is commonly used for secure multi-point communication across geographically scattered industrial sites, simulating a unified LAN broadcast domain for Industrial IoT (IIoT)-type devices. This configuration demands a fully-connected overlay network with encrypted Host Identity Protocol (HIP)/IPsec tunnels exhibiting quadratic scalability to the number of tunnels and a significant increase in forwarding table entries. Herein, we introduce Tunnel Relay Nodes (TRNs) as selected routers that maintain full-mesh connectivity. This approach allows non-TRN routers, or Provider Equipment (PEs) acting as spoke PEs, to connect via a TRN. We explore the challenges of using TRNs in secure HIP-based VPLS (HIPLS) networks, including (i) placing reliable TRNs within provider networks and (ii) scheduling TRNs to minimize their activation/deactivation costs as well as the connection cost among PEs. We then demonstrate how (i) can be addressed in polynomial time using a modified general median problem approach. Additionally, we formulate (ii) as a Mixed Integer Linear Programming (MILP) scheduling problem and prove its NP-completeness. Furthermore, we introduce an algorithm based on Lagrangian relaxation to address the intractability in large-scale deployments. This algorithm offers fast, near-optimal solutions while simultaneously balancing solution quality and execution time. Our simulations on three real-world network topologies with real network demands show a 92% average reduction in forwarding table entries on PE. Compared to existing solutions, our method reduces the number of tunnels established by up to 95%, at the expense of a 1.39-fold increase in tunnel path length.
Mohammad Borhani, Ioannis Avgouleas, Madhusanka Liyanage, Andrei V. Gurtov
IEEE Trans. Netw.4
2025 Deep learning frameworks for cognitive radio networks: Review and open research challenges
Senthil Kumar Jagatheesaperumal, Ijaz Ahmad 0001, Marko Höyhtyä, Suleman Khan 0003, Andrei V. Gurtov
J. Netw. Comput. Appl.5
2024 Towards a federated and hybrid cloud computing environment for sustainable and effective provisioning of cyber security virtual laboratories
abstract
Cloud Computing (CC) and virtualization concepts are two advanced technologies introduced to empower distance and blended learning. Besides, they play a crucial role in equipping learners with practical skills and fostering hands-on experience to defend against cyber-attacks. Many Higher Education Institutions (HEIs) in developed countries have already embraced the promise of CC to raise educational standards. However, the pace of its adoption in developing countries has stagnated. Moreover, existing solutions in the literature are not sustainable. They either rely on on-premise infrastructure or are bound by a single cloud service provider. Consequently, they are likely prone to failures and a sudden outage. To fill this gap, this paper is a first that comprehensively addresses the above issues and introduces a federated hybrid CC system based on an extension of Apache Virtual Computing Lab (VCL). The proposed system provides an independent open-source implementation, greater configuration flexibility, and methodological improvements as compared to existing studies in the literature. In addition, it promotes the sustainability of the CC services, extensible cloud architecture, and fault tolerance. VCL is primarily focused on provisioning Virtual Laboratories (VL) for remote cybersecurity and computer networks education, with potential expansion to other domains of engineering education. In addition, this paper introduces GPT-TerminalPro, a terminal-based tool driven by OpenAI’s Generative Pretrained Transformer (GPT-3.5) that provides intelligent assistance to users while performing lab tasks. To experimentally evaluate the VCL’s performance, the standard Linux tools as well as the Apache benchmark and httperf HTTP load generators are utilized. VCL has been tested with 30 users and 61 virtual user computing environments provisioning to validate the overall performance. The results are fascinating: the provisioning time including all VCL background tasks is always less than a minute and utilizes fewer computing resources while providing a better user experience. This paper will encourage the adoption of CC in low-income countries.
Abdeslam Rehaimi, Yassine Sadqi, Yassine Maleh, Gurjot Singh Gaba, Andrei V. Gurtov
Expert Syst. Appl.5
2023 KDC Placement Problem in Secure VPLS Networks
abstract
Virtual Private LAN Service (VPLS) is a VPN technology that connects remote client sites with provider networks in a transparent manner. Session key-based HIPLS (S-HIPLS) is a VPLS architecture based on the Host Identity Protocol (HIP) that provides a secure VPLS architecture using a Key Distribution Center (KDC) to implement security mechanisms such as authentication, encryption etc. It exhibits limited scalability though. Using multiple distributed KDCs would offer numerous advantages including reduced workload per KDC, distributed key storage, and improved scalability, while simultaneously eliminating the single point of failure of S-HIPLS. It would also come with the need for optimally placing KDCs in the provider network. In this work, we formulate the KDC placement (KDCP) problem for a secure VPLS network as an Integer Linear Programming (ILP) problem. The latter is NP-hard, thereby suggesting a high computational cost for obtaining exact solutions especially for large deployments. Therefore, we motivate the use of a primal-dual algorithm to efficiently produce near-optimal solutions. Extensive evaluations on large-scale network topologies, such as the random Internet graph, demonstrate our method’s time-efficiency as well as its improved scalability and usefulness compared to both HIPLS and S-HIPLS.
Mohammad Borhani, Ioannis Avgouleas, Madhusanka Liyanage, Andrei V. Gurtov
IEEE Trans. Inf. Forensics Secur.4
2023 Dew-Cloud-Based Hierarchical Federated Learning for Intrusion Detection in IoMT
abstract
The coronavirus pandemic has overburdened medical institutions, forcing physicians to diagnose and treat their patients remotely. Moreover, COVID-19 has made humans more conscious about their health, resulting in the extensive purchase of IoT-enabled medical devices. The rapid boom in the market worth of the internet of medical things (IoMT) captured cyber attackers' attention. Like health, medical data is also sensitive and worth a lot on the dark web. Despite the fact that the patient's health details have not been protected appropriately, letting the trespassers exploit them. The system administrator is unable to fortify security measures due to the limited storage capacity and computation power of the resource-constrained network devices'. Although various supervised and unsupervised machine learning algorithms have been developed to identify anomalies, the primary undertaking is to explore the swift progressing malicious attacks before they deteriorate the wellness system's integrity. In this paper, a Dew-Cloud based model is designed to enable hierarchical federated learning (HFL). The proposed Dew-Cloud model provides a higher level of data privacy with greater availability of IoMT critical application(s). The hierarchical long-term memory (HLSTM) model is deployed at distributed Dew servers with a backend supported by cloud computing. Data pre-processing feature helps the proposed model achieve high training accuracy (99.31%) with minimum training loss (0.034). The experiment results demonstrate that the proposed HFL-HLSTM model is superior to existing schemes in terms of performance metrics such as accuracy, precision, recall, and f-score.
Gurjot Singh Gaba, Avinash Kaur, Mustapha Hedabou, Andrei V. Gurtov
IEEE J. Biomed. Health Informatics5
2022 QUIC Throughput and Fairness over Dual Connectivity
abstract
Dual Connectivity (DC) is an important lower-layer feature accelerating the transition from 4G to 5G that also is expected to play an important role in standalone 5G radio networks. However, even though the packet reordering introduced by DC can significantly impact the performance of upper-layer protocols, no prior work has studied the impact of DC on QUIC. In this paper, we present the first such performance study. Using a series of throughput and fairness experiments, we show how QUIC is affected by different DC parameters, network conditions, and whether the DC implementation aims to improve throughput or reliability. Results for two QUIC implementations (aioquic, ngtcp2) and two congestion control algorithms (NewReno, CUBIC) are presented under both static and highly time-varying network conditions Our findings provide network operators with insights and understanding into the impacts of splitting QUIC traffic in a DC environment. With reasonably selected DC parameters and increased UDP receive buffers, QUIC over DC performs similarly to TCP over DC and achieves optimal fairness under symmetric link conditions when DC is not used for packet duplication. The insights can help network operators provide modern users with better end-to-end service when deploying DC.
David Hasselquist, Christoffer Lindström, Nikita Korzhitskii, Niklas Carlsson, Andrei V. Gurtov
Comput. Networks5
2022 A user-centric privacy-preserving authentication protocol for IoT-AmI environments
abstract
Ambient Intelligence (AmI) in Internet of Things (IoT) has empowered healthcare professionals to monitor, diagnose, and treat patients remotely. Besides, the AmI-IoT has improved patient engagement and gratification as doctors’ interactions have become more comfortable and efficient. However, the benefits of the AmI-IoT-based healthcare applications are not availed entirely due to the adversarial threats. IoT networks are prone to cyber attacks due to vulnerable wireless mediums and the absentia of lightweight and robust security protocols. This paper introduces computationally-inexpensive privacy-assuring authentication protocol for AmI-IoT healthcare applications. The use of blockchain & fog computing in the protocol guarantees unforgeability, non-repudiation, transparency, low latency, and efficient bandwidth utilization. The protocol uses physically unclonable functions (PUF), biometrics, and Ethereum powered smart contracts to prevent replay, impersonation, and cloning attacks. Results prove the resource efficiency of the protocol as the smart contract incurs very minimal gas and transaction fees. The Scyther results validate the robustness of the proposed protocol against cyber-attacks. The protocol applies lightweight cryptography primitives (Hash, PUF) instead of conventional public-key cryptography and scalar multiplications. Consequently, the proposed protocol is better than centralized infrastructure-based authentication approaches.
Mehedi Masud, Gurjot Singh Gaba, Pardeep Kumar 0001, Andrei V. Gurtov
Comput. Commun.4
2021 Detection of evil flies: securing air-ground aviation communication
abstract
The aviation community is employing various air traffic control and mobile communication technologies, such as ubiquitous data links, wireless communication architectures and protocols. Recently, software-defined networking (SDN) based architectures (i.e., cockpit network communications environment testing (COMET)) have been proposed for Air-Ground communication. However, an evil can break the communication between a pilot and air traffic control, resulting in a hazardous (or life-threatening) situation up in the air or failure of ground equipment. This paper proposes an efficient evil detection and prevention mechanism (called DoEF) for the COMET architecture. The proposed DoEF utilizes a deep learning-based approach, i.e., long-short term memory (LSTM), to detect the evil flies and provide possible countermeasures. Our preliminary results show that the proposed scheme reduces the detection time and increases the detection accuracy of distributed denial of service (DDoS) attacks for the aviation network.
Suleman Khan 0003, Pardeep Kumar 0001, An Braeken, Andrei V. Gurtov
MobiCom4
2021 A Survey of Virtual Private LAN Services (VPLS): Past, Present and Future
abstract
Virtual Private LAN services (VPLS) is a Layer 2 Virtual Private Network (L2VPN) service that has gained immense popularity due to a number of its features, such as protocol independence, multipoint-to-multipoint mesh connectivity, robust security, low operational cost (in terms of optimal resource utilization), and high scalability. In addition to the traditional VPLS architectures, novel VPLS solutions have been designed leveraging new emerging paradigms, such as Software Defined Networking (SDN) and Network Function Virtualization (NFV), to keep up with the increasing demand. These emerging solutions help in enhancing scalability, strengthening security, and optimizing resource utilization. This paper aims to conduct an in-depth survey of various VPLS architectures and highlight different characteristics through insightful comparisons. Moreover, the article discusses numerous technical aspects such as security, scalability, compatibility, tunnel management, operational issues, and complexity, along with the lessons learned. Finally, the paper outlines future research directions related to VPLS. To the best of our knowledge, this paper is the first to furnish a detailed survey of VPLS.
Kuntal Gaur, Anshuman Kalla, Jyoti Grover, Mohammad Borhani, Andrei V. Gurtov, Madhusanka Liyanage
Comput. Networks5
2021 Toward Convergence of AI and IoT for Energy-Efficient Communication in Smart Homes
abstract
The convergence of artificial intelligence (AI) and the Internet of Things (IoT) promotes energy-efficient communication in smart homes. Quality-of-Service (QoS) optimization during video streaming through wireless micro medical devices (WMMDs) in smart healthcare homes is the main purpose of this research. This article contributes in four distinct ways. First, to propose a novel lazy video transmission algorithm (LVTA). Second, a novel video transmission rate control algorithm (VTRCA) is proposed. Third, a novel cloud-based video transmission framework is developed. Fourth, the relationship between buffer size and performance indicators, i.e., peak-to-mean ratio (PMR), energy (i.e., encoding and transmission), and standard deviation, is investigated while comparing LVTA, VTRCA, and baseline approaches. The experimental results demonstrate that the reduction in encoding (32% and 35.4%) and transmission (37% and 39%) energy drains, PMR (5 and 4), and standard deviation (3 and 4 dB) for VTRCA and LVTA, respectively, is greater than that obtained by baseline during video streaming through WMMD.
Ali Hassan Sodhro, Andrei V. Gurtov, Noman Zahid, Sandeep Pirbhulal, Lei Wang 0029, Muhammad Mahboob Ur Rahman, Muhammad Ali Imran 0001, Qammer H. Abbasi
IEEE Internet Things J.2
2021 Decentralized Firmware Attestation for In-Vehicle Networks
abstract
Today’s vehicles are examples of Cyber-Physical Systems (CPS) controlled by a large number of electronic control units (ECUs), which manage everything from heating to steering and braking. Due to the increasing complexity and inter-dependency of these units, it has become essential for an ECU to be able to ensure the integrity of the firmware running on other ECU’s to guarantee its own correct operation. Existing solutions for firmware attestation use a centralized approach, which means a single point of failure. In this article, we propose and investigate a decentralized firmware attestation scheme for the automotive domain. The basic idea of this scheme is that each ECU can attest to the state of those ECU’s on which it depends. Two flavors of ECU attestation, i.e., parallel and serial solution, were designed, implemented, and evaluated. The two variants were compared in terms of both detection performance (i.e., the ability to identify unauthorized firmware modifications) and timing performance. Our results show that the proposed scheme is feasible to implement and that the parallel solution showed a significant improvement in timing performance over the serial solution.
Abhimanyu Rawat, Mohammad Khodari, Mikael Asplund, Andrei V. Gurtov
ACM Trans. Cyber Phys. Syst.4
2021 Towards 5G-Enabled Self Adaptive Green and Reliable Communication in Intelligent Transportation System
abstract
Fifth generation (5G) technologies have become the center of attention in managing and monitoring high-speed transportation system effectively with the intelligent and self-adaptive sensing capabilities. Besides, the boom in portable devices has witnessed a huge breakthrough in the data driven vehicular platform. However, sensor-based Internet of Things (IoT) devices are playing the major role as edge nodes in the intelligent transportation system (ITS). Thus, due to high mobility/speed of vehicles and resource-constrained nature of edge nodes more data packets will be lost with high power drain and shorter battery life. Thus, this research significantly contributes in three ways. First, 5G-based self-adaptive green (i.e., energy efficient) algorithm is proposed. Second, a novel 5G-driven reliable algorithm is proposed. Proposed joint energy efficient and reliable approach contains four layers, i.e., application, physical, networks, and medium access control. Third, a novel joint energy efficient and reliable framework is proposed for ITS. Moreover, the energy and reliability in terms of received signal strength (RSSI) and hence packet loss ratio (PLR) optimization is performed under the constraint that all transmitted packets must utilize minimum transmission power with high reliability under particular active time slot. Experimental results reveal that the proposed approach (with Cross Layer) significantly obtains the green (55%) and reliable (41%) ITS platform unlike the Baseline (without Cross Layer) for aging society.
Ali Hassan Sodhro, Sandeep Pirbhulal, Gul Hassan Sodhro, Muhammad Muzammal, Zongwei Luo, Andrei V. Gurtov, Antônio Roberto L. de Macêdo, Lei Wang 0029, Nuno M. Garcia, Victor Hugo C. de Albuquerque
IEEE Trans. Intell. Transp. Syst.6
2021 IoT and HIP's Opportunistic Mode
abstract
Key sharing has always been a complex issue. It became even more challenging for the Internet of Things (IoT), where a trusted third party for global management rarely exists. With authentication and confidentiality lacking, things resort to a leap of faith (LoF) paradigm where it is assumed that no attacker is present during the initial configuration. In this paper we focus on the Host Identity Protocol (HIP), specifically designed to provide mobility and multihoming capabilities. Although HIP is normally based on many strict security mechanisms (e.g., DNSSEC), it also provides a better than nothing opportunistic mode, based on the LoF paradigm, which is to be used when other more trusted mechanisms are not available. In this paper, we analyze different MiTM attacks which might occur under this opportunistic mode. Taking advantage of HIP's multihoming capabilities, we propose two key spraying techniques which strengthen the opportunistic mode's security. The first technique spreads the four key-exchange messages among different networks, while the second spreads fractions of one of those messages. Evaluation of these techniques is provided, demonstrating the major benefit of our proposal.
Adel Fuchs, Ariel Stulman, Andrei V. Gurtov
IEEE Trans. Mob. Comput.3
2020 Towards Wearable Sensing Enabled Healthcare Framework for Elderly Patients
abstract
The pervasive and smart healthcare is important for elderly patients which has revolutionized the medical world and caught the attention from industry and academia with the help of portable sensor-enabled devices. Tiny size and resource-constrained nature restricts them to perform several tasks at a time. Thus, energy drain, limited battery lifetime, and high packet loss ratio (PLR) are the key challenges to be tackled carefully for ubiquitous healthcare. Energy efficiency, reliability and longer battery cycle are the vital ingredients for wearable devices to empower cost-effective and pervasive medical environment. Thus, this research work has three key contributions. First, a novel transmission power control driven energy efficient algorithm (EEA) is proposed to enhance energy, battery lifetime and reliability while monitoring the health status of elderly patients. Proposed EEA and conventional constant transmission power control (TPC) are evaluated by adopting real-time datasets of static (i.e., wheelchair sitting) and dynamic (i.e., wheelchair moving) body postures of elderly patients. Second, smart healthcare framework is proposed. Third, performance metrics such as, energy drain, battery lifetime and reliability are introduced and calculated by considering average and threshold RSSI and TPC values. Finally, it is observed through experimental analysis that the proposed EEA enhances energy efficiency with acceptable PLR than the constant TPC during data transmission.
Ali Hassan Sodhro, Mohammad S. Obaidat, Andrei V. Gurtov, Noman Zahid, Sandeep Pirbhulal, Lei Wang 0029, Kuei-Fang Hsiao
ICC3
2020 Methodology and Mobile Application for Driver Behavior Analysis and Accident Prevention
abstract
This paper presents a methodology and mobile application for driver monitoring, analysis, and recommendations based on detected unsafe driving behavior for accident prevention using a personal smartphone. For the driver behavior monitoring, the smartphone's cameras and built-in sensors (accelerometer, gyroscope, GPS, and microphone) are used. A developed methodology includes dangerous state classification, dangerous state detection, and a reference model. The methodology supports the following driver's online dangerous states: distraction and drowsiness as well as an offline dangerous state related to a high pulse rate. We implemented the system for Android smartphones and evaluated it with ten volunteers.
Alexey M. Kashevnik, Igor Lashkov, Andrei V. Gurtov
IEEE Trans. Intell. Transp. Syst.3
2019 Managing Mobile Relays for Secure E2E Connectivity of Low-Power IoT Devices
abstract
The widespread Internet of Things (IoT) ecosystems empower the deployment of various Bluetooth Low Energy (BLE) sensor nodes in many ambient assisted living (AAL) type applications. Regardless of their limitations, these low-power IoT sensor nodes need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds which will perform further processing and storing functions. The common practice is to use one or multiple dedicated gateways to assist the communication between the sensor and the cloud. This paper presents a mobile-based relay assistance solution for establishing secure end-to-end (E2E) connectivity between low-power IoT sensors and cloud servers without using a dedicated gateway. za The prototype implementation and the described security features verify the technical readiness of the proposed solution.
Pawani Porambage, Ahsan Manzoor, Madhusanka Liyanage, Andrei V. Gurtov, Mika Ylianttila
CCNC4
2019 Watch Your Step! Detecting Stepping Stones in Programmable Networks
abstract
Hackers hide behind compromised intermediate hosts and pose advanced persistent threats (APTs). The compromised hosts are used as stepping stones to launch real attacks, as is evident from an incident that shook the world in 2016 - Panama Papers Leak. The major attack would not go unnoticed if the compromised stepping stone, in this case an email server, could be identified in time. In this paper, we explore how today's programmable networks could be retrofitted with effective stepping stone detection mechanisms to correlate flows. We share initial results to prove that such a setup exists. Lastly, we analyze scalability issues associated with the setup and explore recent developments in network monitoring which have potential to address these issues.
Debopam Bhattacherjee, Andrei V. Gurtov, Tuomas Aura
ICC2
2018 DEMO: Mobile Relay Architecture for Low-Power IoT Devices
abstract
Internet of Things (IoT) devices need pervasive and secure connections to transfer the aggregated data to the central servers located in remote clouds where the collected data further processed and stored. However, most low-power IoT devices cannot transmit the collected the data directly to such servers due the limited transmission power and range. Thus, third-party devices such as smart mobile phones are used as a relay to establish the communication link between IoT devices and the cloud server. This paper demonstrates a mobile-based relay assistance solution for secure end-to-end connectivity between low-power IoT sensors and cloud servers by using Bluetooth Low Energy (BLE) technology. The prototype implementation verifies the technical readiness of the proposed solution.
Ahsan Manzoor, Pawani Porambage, Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov
WOWMOM5
2018 Cyclic ranking in single-resource peer-to-peer exchange
abstract
Peer-to-peer (P2P) sharing systems use incentives for resource exchange to encourage cooperation and ensure fairness. In bilateral strategies, such as BitTorrent Tit-for-Tat or deficit-based FairTorrent, individual decisions of peers utilize direct observations. It may result in low performance and unfair treatment. In this paper, we study a novel exchange strategy that applies Cyclic Ranking (CR). In addition to direct observations, a peer utilizes provision cycles—a shared history of effective exchanges. The PageRank algorithm runs for the locally collected cycles and computes the numerical ranks to estimate the reputation. The CR strategy incrementally augments known incentive-aware strategies. For evaluation we implement CR-BitTorrent and CR-FairTorrent variants. Our simulation model captures the dependence on network bandwidth and the number of seeders as well as selfishness and stability of the participants. The initial experiments show improved fairness and download times, compared to the original BitTorrent and FairTorrent. The performance of selfish and unstable peers decreases by as much as 50%. The CR strategy suits well in environments where direct reciprocity has shown little effect. Contrasted to existing solutions, the CR strategy rewards longevity and stability of peers.
Andrei V. Gurtov, Joakim Koskela, Dmitry G. Korzun
Peer-to-Peer Netw. Appl.1
2017 Hardening Opportunistic HIP
abstract
As mobile and multi-homed devices are becoming ubiquitous, the need for a dynamic, yet secure communication protocol is unavoidable. The Host Identity Protocol (HIP) was constructed to meet this requirement; to provide significantly more secure mobility and multi-homing capabilities. HIP opportunistic mode, which is to be used when other, more trusted mechanisms are lacking, is based on a leap of faith (LoF) paradigm. In this paper, we analyze different Man in the middle (MiTM) attacks which might occur under this LoF, and propose a set of tweaks for hardening opportunistic HIP (HOH) that strengthen opportunistic mode's security.
Adel Fuchs, Ariel Stulman, Andrei V. Gurtov
MSWiM3
2017 Software defined VPLS architectures: Opportunities and challenges
abstract
Virtual Private LAN Services (VPLS) is an Ethernet based VPN (Virtual Private Network) service which provides protocol independent and high speed multipoint-to-multipoint connectivity. In this article, we discuss the possibility to use emerging networks concepts such as Software Defined Networking (SDN) and Network Function Virtualization (NFV) to improve the performance, flexibility and adaptability of VPLS networks. SDN and NFV based VPLS (SoftVPLS) architectures offer new features such as centralized control, network programmability and abstraction to improve the performance, flexibility and automation of traffic, security and network management functions for future VPLS networks.
Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov
PIMRC3
2017 CIDOR: Content distribution and retrieval in disaster networks for public protection
abstract
Information-Centric Networking (ICN) introduces a paradigm shift from a host centric communication model for Future Internet architectures. It supports the retrieval of a particular content regardless of the physical location of the content. Emergency network in a disaster scenario or disruptive network presents a significant challenge to the ICN deployment. In this paper, we present a Content distribution and retrieval framework in disaster netwOrks for public pRotection (CIDOR) which exploits the design principle of the native CCN architecture in the native Delay Tolerant Networking (DTN) architecture. We prove the feasibility and investigate the performance of our proposed solution using extensive simulation with different classes of the DTN routing strategies in different mobility scenarios. The simulation result shows that CIDOR can reduce the content retrieval time up to 50% while the response ratio is close to 100%.
Hasan M. A. Islam, Dmitrij Lagutin, Andrey Lukyanenko, Andrei V. Gurtov, Antti Ylä-Jääski
WiMob4
2017 Secure communication channel architecture for Software Defined Mobile Networks
Madhusanka Liyanage, An Braeken, Anca Jurcut, Mika Ylianttila, Andrei V. Gurtov
Comput. Networks5
2017 Anonymous Secure Framework in Connected Smart Home Environments
abstract
The smart home is an environment, where heterogeneous electronic devices and appliances are networked together to provide smart services in a ubiquitous manner to the individuals. As the homes become smarter, more complex, and technology dependent, the need for an adequate security mechanism with minimum individual's intervention is growing. The recent serious security attacks have shown how the Internet-enabled smart homes can be turned into very dangerous spots for various ill intentions, and thus lead the privacy concerns for the individuals. For instance, an eavesdropper is able to derive the identity of a particular device/appliance via public channels that can be used to infer in the life pattern of an individual within the home area network. This paper proposes an anonymous secure framework (ASF) in connected smart home environments, using solely lightweight operations. The proposed framework in this paper provides efficient authentication and key agreement, and enables devices (identity and data) anonymity and unlinkability. One-time session key progression regularly renews the session key for the smart devices and dilutes the risk of using a compromised session key in the ASF. It is demonstrated that computation complexity of the proposed framework is low as compared with the existing schemes, while security has been significantly improved.
Pardeep Kumar 0001, An Braeken, Andrei V. Gurtov, Jari H. Iinatti, Phuong Hoai Ha
IEEE Trans. Inf. Forensics Secur.3
2017 On the Resiliency of Static Forwarding Tables
abstract
Fast reroute and other forms of immediate failover have long been used to recover from certain classes of failures without invoking the network control plane. While the set of such techniques is growing, the level of resiliency to failures that this approach can provide is not adequately understood. In this paper, we embarked upon a systematic algorithmic study of the resiliency of forwarding tables in a variety of models (i.e., deterministic/probabilistic routing, with packet-header-rewriting, with packet-duplication). Our results show that the resiliency of a routing scheme depends on the “connectivity” k of a network, i.e., the minimum number of link deletions that partition a network. We complement our theoretical result with extensive simulations. We show that resiliency to four simultaneous link failures, with limited path stretch, can be achieved without any packet modification/duplication or randomization. Furthermore, our routing schemes provide resiliency against k - 1 failures, with limited path stretch, by storing log(k) bits in the packet header, with limited packet duplication, or with randomized forwarding technique.
Marco Chiesa, Ilya Nikolaevskiy, Slobodan Mitrovic, Andrei V. Gurtov, Aleksander Madry, Michael Schapira, Scott Shenker
IEEE/ACM Trans. Netw.4
2016 Improving the tunnel management performance of secure VPLS architectures with SDN
abstract
Secure VPLS (Virtual Private LAN Services) networks are becoming attractive in many Enterprise applications. However, the tunnel establishment mechanisms of legacy VPLS architectures are static, complex and inflexible in nature. As a result, secure VPLS architectures are suffering from limitations such as the limited scalability, over utilization of network resources, high tunnel establishment delay and high operational cost. In this article, we propose a novel SDN (Software Defined Networking) based VPLS (Virtual Private LAN Services) architecture to overcome tunnel management limitations in existing secure VPLS architectures. The proposed architecture utilizes IPsec enabled OpenFlow switches as PEs (Provider Edge Equipments) and OpenFlow protocol to install flow rules in PEs. A centralized controller is used to manage the tunnel establishment functions. We also propose a novel tunnel management mechanism which can estimate the tunnel duration based on real time session characteristics. Moreover, a novel tunnel resumption mechanism is proposed to reduce the tunnel establishment delay of subsequent tunnel establishments. Finally, the performance of proposed architecture is analyzed by using a simulation model and a testbed implementation.
Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov
CCNC3
2016 On the Resiliency of Randomized Routing Against Multiple Edge Failures
abstract
We present and study the Static-Routing-Resiliency problem, motivated by routing on the Internet: Given a graph $G$, a unique destination vertex $d$, and an integer constant $c>0$, does there exist a static and destination-based routing scheme such that the correct delivery of packets from any source $s$ to the destination $d$ is guaranteed so long as (1) no more than $c$ edges fail and (2) there exists a physical path from $s$ to $d$? We embark upon a systematic exploration of this fundamental question in a variety of models (deterministic routing, randomized routing, with packet-duplication, with packet-header-rewriting) and present both positive and negative results that relate the edge-connectivity of a graph, i.e., the minimum number of edges whose deletion partitions $G$, to its resiliency.
Marco Chiesa, Andrei V. Gurtov, Aleksander Madry, Slobodan Mitrovic, Ilya Nikolaevskiy, Michael Schapira, Scott Shenker
ICALP2
2016 The quest for resilient (static) forwarding tables
abstract
Fast Reroute (FRR) and other forms of immediate failover have long been used to recover from certain classes of failures without invoking the network control plane. While the set of such techniques is growing, the level of resiliency to failures that this approach can provide is not adequately understood. We embark upon a systematic algorithmic study of the resiliency of immediate failover in a variety of models (with/without packet marking/duplication, etc.). We leverage our findings to devise new schemes for immediate failover and show, both theoretically and experimentally, that these outperform existing approaches.
Marco Chiesa, Ilya Nikolaevskiy, Slobodan Mitrovic, Aurojit Panda, Andrei V. Gurtov, Aleksander Madry, Michael Schapira, Scott Shenker
INFOCOM5
2016 Poster Abstract: An Efficient Authentication Model in Smart Grid Networks
abstract
A smart grid is envisioned as a promising platform for the next-generation power supply network, where the electricity is generated based on the demand from the consumers energy-use information. However, the security and privacy issues over insecure wireless communications are still big obstacles in the success of smart grid networks. In this paper, we present an efficient authentication model in smart grid networks. The proposed model justifies its feasibility with an early test-bed using off-the-shelf 802.15.4 low- cost sensors. Moreover, this poster reports preliminary performance evaluation results, and shows that the proposed scheme is effective and efficient than the prior works.
Pardeep Kumar 0001, Andrei V. Gurtov, Phuong Hoai Ha
IPSN2
2016 Novel secure VPN architectures for LTE backhaul networks
abstract
In this paper, we propose two secure virtual private network architectures for the long-term evolution backhaul network.They are layer 3 Internet protocol (IP) security virtual private network architectures based on Internet key exchange version 2 mobility and multihoming protocol and host identity protocol.Both architectures satisfy a complete set of 3GPP backhaul security requirements such as authentication, authorization, payload encryption, privacy protection, and IP-based attack prevention.The security analysis and simulation results verify that the proposed architectures are capable enough to protect long-term evolution backhaul traffic against various IP-based attacks.
Madhusanka Liyanage, Pardeep Kumar 0001, Mika Ylianttila, Andrei V. Gurtov
Secur. Commun. Networks4
2016 Implementation of OpenFlow based cognitive radio network architecture: SDN&R
Suneth Namal, Ijaz Ahmad 0001, Muhammad Saad Saud, Markku Jokinen, Andrei V. Gurtov
Wirel. Networks5
2015 Efficient Key Establishment for Constrained IoT Devices with Collaborative HIP-Based Approach
abstract
The Internet of Things (IoT) technologies interconnect wide ranges of network devices irrespective of their resource capabilities and local networks. The device constraints and the dynamic link creations make it challenging to use pre-shared keys for every secure end-to-end (E2E) communication scenario in IoT. Variants of Host Identity Protocol (HIP) are adopted for constructing dynamic and secure E2E connections among the heterogenous network devices with imbalanced resource profiles and less or no previous knowledge about each other. We propose a collaborative HIP solution with an efficient key establishment component for the high constrained devices in IoT, which delegates the expensive cryptographic operations to the resource rich devices in the local networks. Finally, we demonstrate the applicability of the key establishment in collaborative HIP solution for the constrained IoT devices rather than the existing HIP variants, by providing performance and security analysis.
Pawani Porambage, An Braeken, Pardeep Kumar 0001, Andrei V. Gurtov, Mika Ylianttila
GLOBECOM4
2015 Group key establishment for secure multicasting in IoT-enabled Wireless Sensor Networks
abstract
Wireless Sensor Network (WSN) is a fundamental technology of the Internet of Things (IoT). Group communications in the form of broadcasting and multicasting incur efficient message deliveries among resource-constrained sensors in IoT-enabled WSNs. Secure and efficient key management is significant to protect the authenticity, integrity, and confidentiality of multicast messages. This paper develops two group key establishment protocols for secure multicast communications among resource-constrained devices in IoT. The applicability of the two protocols are analyzed and justified by performance and security analysis.
Pawani Porambage, An Braeken, Corinna Schmitt, Andrei V. Gurtov, Mika Ylianttila, Burkhard Stiller
LCN4
2015 isBF: Scalable in-packet bloom filter based multicast
Ilya Nikolaevskiy, Andrey Lukyanenko, Tatiana Polishchuk, Valentin Polishchuk, Andrei V. Gurtov
Comput. Commun.5
2014 A novel distributed spanning tree protocol for provider provisioned VPLS networks
abstract
Spanning Tree Protocol (STP) is a widely used protocol to maintain a loop free Layer 2 (L2) switching network. On the other hand, Virtual Private LAN Service (VPLS) is a L2 Virtual Private Network (VPN) service which is becoming very popular among many industrial enterprises. In a VPLS network, VPN connections through the provider network are invisible to L2 network devices and protocols. It causes to several issues while utilizing STP in a VPLS enabled Ethernet network. In this paper, we propose a novel Distributed STP (DSTP) to maintain a loop free Ethernet network over a VPLS network. DSTP proposes to run a modified STP instance in each remote network segment and evades the transportation of STP messages through the provider network. In addition, we propose two Redundancy Identification Mechanisms (RIMs) to mitigate the impact of invisible loops in the provider network. Simulation results verify that DSTP is capable of maintaining a loop free Ethernet network over a VPLS network. Furthermore, DSTP significantly reduces the convergence time of the spanning tree and STP overhead over the provider network.
Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov
ICC3
2014 Two-phase authentication protocol for wireless sensor networks in distributed IoT applications
abstract
In the centralized Wireless Sensor Network (WSN) architecture there exists a central entity, which acquires, processes and provides information from sensor nodes. Conversely, in the WSN applications in distributed Internet of Things (IoT) architecture, sensor nodes sense data, process, exchange information and perform collaboratively with other sensor nodes and endusers. In order to maintain the trustworthy connectivity and the accessibility of distributed IoT, it is important to establish secure links for end-to-end communication with proper authentication. The authors propose an implicit certificate-based authentication mechanism for WSNs in distributed IoT applications. The developed two-phase authentication protocol allows the sensor nodes and the end-users to authenticate each other and initiate secure connections. The proposed protocol supports the resource scarcity of the sensor nodes, heterogeneity and scalability of the network. The performance and security analysis justify that the proposed scheme is viable to deploy in resource constrained WSNs.
Pawani Porambage, Corinna Schmitt, Pardeep Kumar 0001, Andrei V. Gurtov, Mika Ylianttila
WCNC4
2014 Access Point selection game for mobile wireless users
abstract
Selecting a Access Point (AP) is an important task for a mobile wireless user to achieve the best possible quality of service. We consider AP selection as a game where players make choices selfishly and try to select the closest AP based on Minimum Path-Loss (MPL) criteria. We formulate the AP selection problem as a game where players are mobile wireless users and they choose radio APs to connect to the network. We define a new parameter called Access Point Selection Parameter (APSP) based on Signal to Interference plus Noise Ratio (SINR). Each selfish user chooses an AP which maximizes its APSP value. This APSP value depends on both the distance to AP and the total number of connected users in AP. Furthermore, we extend two players game to n-players game by adopting the KP (Koutsoupias-Papadimitriou) model of parallel links. The performance of the proposed game is illustrated by using simulations.
Madhusanka Liyanage, Julia Chirkova, Andrei V. Gurtov
WoWMoM3
2014 Securing the control channel of software-defined mobile networks
abstract
Software-Defined Mobile Networks (SDMNs) are becoming popular as the next generation of telecommunication networks due to the enhanced performance, flexibility and scalability. In this paper, we study the new security challenges of the control channel of SDMNs and propose a novel secure control channel architecture based on Host Identity Protocol (HIP). IPsec tunneling and security gateways are widely used in today's mobile networks. The proposed architecture utilized these technologies to protect the control channel of SDMNs. We implement the proposed architecture in a testbed and analyze the security features. Moreover, we measure the performance penalty of security of proposed architecture and analyze its ability to protect the control channel from various IP (Internet Protocol) based attacks.
Madhusanka Liyanage, Mika Ylianttila, Andrei V. Gurtov
WoWMoM3
2014 Security for medical sensor networks in mobile health systems
abstract
Emerging Internet of Things (IoT) technologies and mobile health scenarios provide opportunities for enhancing traditional healthcare systems. Yet current development meets the challenge of sensing patient's health data with strong security guarantees in mobile and resource-constrained settings as well as in emergency situations. This paper presents a generic IoT-aware system architecture that enables security of personal mobile data and their transfer to healthcare services. Our security solutions apply the Host Identity Protocol. We validate the efficiency using a prototype implementation.
Ilya Nikolaevskiy, Dmitry G. Korzun, Andrei V. Gurtov
WoWMoM3
2014 Performance evaluation of current and emerging authentication schemes for future 3GPP network architectures
Zoltán Faigl, Jani Pellikka, László Bokor, Andrei V. Gurtov
Comput. Networks4
2014 How penalty leads to improvement: A measurement study of wireless backoff in IEEE 802.11 networks
Dmitriy Kuptsov, Boris Nechaev, Andrey Lukyanenko, Andrei V. Gurtov
Comput. Networks4
2014 Hierarchical architectures in structured peer-to-peer overlay networks
Dmitry G. Korzun, Andrei V. Gurtov
Peer-to-Peer Netw. Appl.2
2014 Securing virtual private LAN service by efficient key management
abstract
Virtual private local area network service VPLS is a layer 2 service provider-provisioned virtual private network service. Security is one of the key system requirements of a VPLS because it delivers the frames via an untrusted network. Several VPLS architectures are proposed during the recent years. However, many of them do not provide a sufficient level of security. On the other hand, the existing secure VPLS architectures are also suffering from the scalability issues, and they are infeasible to implement in large scale networks.
Madhusanka Liyanage, Andrei V. Gurtov
Secur. Commun. Networks2
2013 A scalable and secure VPLS architecture for provider provisioned networks
abstract
Virtual Private LAN Service (VPLS) is a Layer 2 Virtual Private Network (VPN) service. Internet Engineering Task Force (IETF) defined the essential system requirements of a VPLS network. Among them, Security is a key requirement as a VPLS delivers the customer data frames via untrusted public networks. However, the existing secure VPLS architectures are suffering from scalability issues and they are infeasible to implement in large scale networks. In this paper, we propose a novel VPLS architecture based on Host Identity Protocol (HIP). It includes a new session key based security mechanism which provides the scalability both in forwarding and security planes. Initial simulations verify that the proposed architecture reduces the key storage in a VPLS node, the total key storage in the network and the number of encryption per broadcast frame than other secure VPLS architectures. Additionally, our proposal provides an efficient broadcast mechanism and comparably higher degree of security features than other existing VPLS proposals.
Madhusanka Liyanage, Andrei V. Gurtov
WCNC2
2013 Lightweight authentication and key management on 802.11 with Elliptic Curve Cryptography
abstract
Wireless Local Area Networks (WLANs) have experienced a significant growth during the last decade due to ever emerging and heavy resource demanding applications. Widely used IEEE 802.11 may unexpectedly require long durations in association compared to what Voice over IP (VoIP), Video on Demand (VoD) and other real-time applications can tolerate. In this paper, we implement HIP-WPA; a novel approach of Fast Initial Authentication (FIA) which is a combination of Host Identity Protocol Diet EXchange (HIP-DEX) with some features of Wi-Fi Protected Access (WPA) technology. This approach provides the necessary IP layer elevated security mechanisms in order to face the challenges of fast authentication in WLANs. HIP-DEX introduces a radically new way of authenticating hosts by using Elliptic Curve Cryptography (ECC) only with two message exchanges and therefore improves the authentication delay by 300% compared to WPA2. Thus, this is an effective solution to be used with any type of real-time application for intra-network (Basic Service Set (BSS) transitions) and internetwork (Extended Service Set (ESS) transitions) handovers.
Suneth Namal, Konstantinos Georgantas, Andrei V. Gurtov
WCNC3
2013 Suitability analysis of existing and new authentication methods for future 3GPP Evolved Packet Core
Zoltán Faigl, László Bokor, Jani Pellikka, Andrei V. Gurtov
Comput. Networks4
2013 Cooperative security in distributed networks
Óscar García-Morchón, Dmitriy Kuptsov, Andrei V. Gurtov, Klaus Wehrle
Comput. Commun.3
2012 Mediating Multimedia Traffic with Strict Delivery Constraints
abstract
Internet multimedia traffic currently occupies more than half of the total Internet traffic and it continues to expand tremendously. Targeting to meet strict constraints imposed by the requirements of real-time multimedia applications appropriate error-correction techniques should be implemented within the data dissemination network. We propose to introduce multipurpose relay nodes called Mediators into several positions within the tree networks typical for multicasting and broadcasting scenarios. By utilizing the error-correction domain separation paradigm in combination with selective insertion of the supplementary data from parallel networks, when the corresponding content is available, the proposed mechanism reduces the total network load and improves scalability of multicast/broadcast transmission. We share our view on how the existing application frameworks could benefit from the incremental deployment of the proposed mechanism. Experimental results confirm suitability and applicability of our assumptions.
Michael Karl 0002, Tatiana Polishchuk, Thorsten Herfet, Andrei V. Gurtov
ISM4
2012 Secured VPN Models for LTE Backhaul Networks
abstract
The Long Term Evolution (LTE) architecture proposes a flat all-IP backhaul network. 3rd Generation Partnership Project (3GPP) specified new security and traffic transport requirements of new LTE backhaul network. However, existing LTE backhaul traffic architectures are incapable of achieving these security requirements. In this paper, we propose two secured Virtual Private Network (VPN) architectures for LTE backhaul. Both architectures are layer 3 Internet Protocol security (IPsec) VPNs which are built using Internet Key exchange version 2 (IKEv2) and Host Identity Protocol (HIP). They are capable of fulfilling 3GPP security requirements such as user authentication, user authorization, payload encryption, privacy protection and IP based attack prevention. We study various IP based attacks on LTE backhaul and our proposed architectures can protect the backhaul network from them.
Madhusanka Liyanage, Andrei V. Gurtov
VTC Fall2
2012 Secure and Multihomed Vehicular Femtocells
abstract
Operators must ensure seamless voice and data session continuity even when subscribers are on move. Service continuity is one of the most critical quality parameter in a cellular system. QoS during handover is always hindered by the handover latency and packet loss. Among several approaches, IP multihoming is a promising solution to achieve throughput increment and packet loss reduction. Theoretically, it can ensure no interrupt or packet loss during the handover. In this paper, we present a novel Host Identity Protocol (HIP) based secure vehicular femtocell scenario. For the evaluation, we have developed a simulation model on top of HIPSim++ framework (simulation framework for HIP) integrated into INET/OMNeT++. Finally, we investigate the feasibility to use HIP in a vehicular femtocell which is new in the context and measure the performance in terms of handover latency, packet loss and throughput to compare multihomed and singlehomed communication.
Suneth Namal, Jani Pellikka, Andrei V. Gurtov
VTC Spring3
2012 Inter Technology Load Balancing Algorithm for Evolved Packet System
abstract
In this paper, we present an advanced load balancing algorithm for Evolved Packet System utilizing different radio interfaces. By using the fact that Evolved Packet Core can support, in addition to LTE also multiple other packet data technologies, such as WLAN, we can utilize this additional dimension for benefit of load balancing for future mobile broadband networks. The main goal of the algorithm is to minimize the number of unsatisfied users in the network and thus load balancing algorithm is only active if those are present. We show a significant performance boost in network resource utilization and average data rate per user when employing the algorithm.
Marek Skowron, Suneth Namal, Jani Pellikka, Andrei V. Gurtov
VTC Fall4
2012 Lightweight host and user authentication protocol for All-IP telecom networks
abstract
Future wireless networks are moving fast towards all-IP network architectures and mobile operators are expanding their services outside traditional cellular networks becoming multi-access operators. This lays stringent requirements on access security, where implementing consistent security policies over disparate radio accesses becomes a challenge. In this paper, we introduce a novel host and user authentication protocol based on a lightweight Host Identity Diet Exchange Protocol that extends the existing 3GPP user authentication architecture and reuses the standard Authentication and Key Agreement scheme. Furthermore, quantitative evaluation of an implementation and real deployment of our proposal along with an extensive analysis of security features is presented. Our measurements and analysis show that the proposal is a feasible lightweight authentication mechanism for mobile network use and it improves the security features of the original Diet Exchange.
Jani Pellikka, Andrei V. Gurtov, Zoltán Faigl
WOWMOM2
2012 Scalable architecture for multimedia multicast Internet applications
abstract
We propose a scalable multicast architecture for potentially large overlay networks. Our techniques address suboptimality of the adaptive hybrid error correction (AHEC) scheme in the multicast scenarios. A hierarchical multi-stage multicast tree topology is constructed in order to improve performance of AHEC and guarantee QoS for the multicast clients. The multicast tree is divided into subtrees, called regions. Every region is assigned a control node, which serves the individual redundancy and retransmission requirements of the receivers within the region. Region sizes are bounded by the maximum cost per region, which defines the ability of the control nodes to serve the receivers of the assigned regions. We show that the multistage multicast architecture significantly reduces the amount of redundancy information introduced into the network and brings it closer to the Shannon bound.
Tatiana Polishchuk, Michael Karl 0002, Thorsten Herfet, Andrei V. Gurtov
WOWMOM4
2011 Secure Resolution of End-Host Identifiers for Mobile Clients
abstract
Many efforts of the network research community focus on the introduction of a new identifier to relieve the IP address from its dual role of end-host identifier and routable locator. This identifier-locator split introduces a new identifier between human readable domain names and routable IP addresses. Mapping between identifiers and locators requires additional name mapping mechanisms because their relation is not trivial. Despite its popularity and efficiency, the DNS system is not a perfect choice for performing this mapping because identifiers are not hierarchically structured and mappings are frequently updated by users. In this paper we discuss the features needed to resolve flat identifiers to locators in a secure manner. In particular, we focus on the features and the performance that identifier-locator split protocols require from a mapping system. To this end, we consider a mapping system for an identifier-locator split based mobility solution and evaluate its performance.
Samu Varjonen, Tobias Heer, Ken Rimey, Andrei V. Gurtov
GLOBECOM4
2011 DISPUTE: Distributed puzzle tussle
abstract
Distributed Denial of Service (DDoS) attack continues to be one of the main vulnerabilities of today's Internet. Client's puzzle mechanism is a well-known solution against such threat, however with badly tuned puzzle sizes it may harm the clients in the peaceful time, as well as produce additional difficulties during an attack. Here, we introduce a novel algorithm - DISPUTE - auto-tunable distributed puzzle mechanism with variable puzzle sizes. Main feature of it is that the server does not need to adjust any puzzle sizes, instead the clients during the “fight for” server resources find some form of equilibrium situation on the server side. We describe the algorithm and show the DISPUTE's performance using a simulation tool. The results suggest that regular (laptop) users, as well as light (sensor) users can successfully access a server even during a heavy DDoS attack.
Andrey Lukyanenko, Andrei V. Gurtov, Antti Ylä-Jääski
ISCC2
2011 Comparison and Analysis of Secure Mobile Architecture (SMA) and Evolved Packet System
abstract
In this paper, we analyse and compare two architectures providing an all-IP based connectivity and mobility for mobile devices over heterogeneous access technologies: Evolved Packet System (EPS) as specified by 3GPP and Secure Mobile Architecture (SMA), a standardization effort by The Open Group (TOG). We briefly present each architecture and qualitatively evaluate their advantages and disadvantages in terms of security, mobility, and support for location-based policy enforcement and security zoning. While SMA is capable of providing simultaneous multihoming, cryptographic identity-based packet tracking and ready support for location-based security zoning and policy control, EPS enables legal interception of user traffic and protection of user/host privacy by default.
Jani Pellikka, Marek Skowron, Andrei V. Gurtov
VTC Spring3
2011 CR-Chord: Improving lookup availability in the presence of malicious DHT nodes
Boris Nechaev, Dmitry G. Korzun, Andrei V. Gurtov
Comput. Networks3
2011 Survey on hierarchical routing schemes in "flat" distributed hash tables
Dmitry G. Korzun, Andrei V. Gurtov
Peer-to-Peer Netw. Appl.2
2010 Playing Defense by Offense: Equilibrium in the DoS-attack problem
abstract
We develop defenses from resource-exhausting Denial-of-Service attacks initiated by an attacker to a server. The attacker does not have a permanent identity but spoofs the IP addresses for other users. Generalizing the Defense-by-Offense approach we enable benign users to obtain low service time by re-submitting requests according to a game-theoretic strategy. The attacker that tries to overwhelm the server by a constant stream of requests cannot succeed as its requests are dropped by the server. We derive optimal strategies for the server, as well as the attacker. We show that in the equilibrium state, the server can successfully repel the attackers with selective processing of requests. Simulations using OMNeT++ support analytical results.
Andrey Lukyanenko, Vladimir V. Mazalov, Andrei V. Gurtov, I. Falko
ISCC3
2010 On application of Host Identity Protocol in wireless sensor networks
abstract
Recent advances in development of low-cost wireless sensor platforms open up opportunities for novel wireless sensor network (WSN) applications. Likewise emerge security concerns of WSNs receiving closer attention of research community. Well known security threats in WSNs range from Denial-of-Service (DoS), Replay and Sybil attacks to those targeted at violating data integrity and confidentiality. Public-key cryptography (PKC) as a countermeasure to potential attacks, although originally treated infeasible for resource-constrained sensor nodes, has shown its eligibility for WSNs in the past few years. However, different security and performance requirements, energy consumption issues, as well as varying hardware capabilities of sensor motes pose a challenge of finding the most efficient security protocol for a particular WSN application and scenario. In this paper, we propose to use the Host Identity Protocol (HIP) as the main component for building network-layer security in WSNs. Combining PKC signatures to authenticate wireless nodes, a Diffie-Hellman key exchange to create a pairwise secret key, a puzzle mechanism to protect against DoS attacks and the IPsec protocol for optional encryption of sensitive application data, HIP provides a standardized solution to many security problems of WSNs. We discuss how HIP can strengthen security of WSNs, suggest possible alternatives to its heavy components in particular WSN applications and evaluate their computational and energy costs on a Linux-based Imote2 wireless sensor platform.
Andrey Khurri, Dmitriy Kuptsov, Andrei V. Gurtov
MASS3
2010 Secure and usable P2P VoIP for mobile devices
abstract
The use of Voice over IP (VoIP) applications involves a number of security threats and usability issues, leading to possible breaches of security and privacy. With the adoption of future peer-to-peer communication systems, the challenges grow even more as we rely on untrusted peers to access the service. We are developing a peer-to-peer VoIP system which features techniques for improving the security and privacy of users in future networks. However, as the threats are seldom well understood, presenting them in a usable manner is problematic. Implemented on a mobile device, the small user interface provides additional challenges for the end user. Via interviews, a questionnaire and usability testing, we seek to improve both the usability of managing and understanding the additional security, as well as the overall user experience of the emerging application.
Joakim Koskela, Kristiina Karvonen, Theofanis Kilinkaridis, Andrei V. Gurtov
Mobile HCI4
2010 Brief announcement: distributed trust management and revocation
abstract
Fair node and network operation is a key to ensure the correct system operation. The problem arises when some nodes become compromised or faulty endangering the overall system. This is especially challenging in sensor networks because they are often deployed in hostile environments and have to endure both passive and active attacks. Therefore, a node should only communicate with trusted nodes, while non-trusted nodes should be removed from the system to prevent them from further disrupting its normal operation. To address such threats, we introduce the Efficient Cooperative Security (ECoSec) - a distributed and adaptive protocol that allows a network to control the admission and revocation of nodes in a cooperative and democratic way during two voting rounds. Whereas the contributions of the protocol to the family of cooperative security protocols are two fold. First, it introduces the use of polynomial-based votes showing that its operation, and in general, operation of cooperative security protocols, can endure up to 33% of misbehaving nodes. Second, the protocol applies correlated keying material structures to verify the node admission and node revocation voting procedures reducing the overall communication overhead.
Dmitriy Kuptsov, Andrei V. Gurtov, Óscar García-Morchón, Klaus Wehrle
PODC2
2010 A secure peer-to-peer web framework
abstract
We present the design and evaluation of a secure peer-to-peer HTTP middleware framework that enables a multitude of web applications without relying on service providers. The framework is designed to be deployed in existing network environments, allowing ordinary users to create private services without investing in network infrastructure. Compared to previous work, scalability, NAT/firewall traversal and peer mobility is achieved without the need for maintaining dedicated servers by utilizing new network protocols and re-using existing network resources.
Joakim Koskela, Andrei V. Gurtov
WOWMOM2
2009 Usable security management with host identity protocol
abstract
Host Identity Protocol (HIP) proposes a change to the Internet architecture by introducing cryptographically-secured names, called Host Identities (HIs), for hosts. Applications use HIs instead of IP addresses in transport layer connections, which allows applications to tolerate host-based mobility better. HIP provides IPsec-based, lower-layer security, but the problem is that this type of security is invisible for most applications and users. Our main contribution is the implementation and user evaluation of several security indicators which inform the user when HIP and IPsec are securing the connections of the user. We experimented with application and system level security indicators at the client-side, as well as with server-side indicators. In this paper, we present implementation experience on integrating the identity management Graphical User Interface (GUI) to HIP and results of usability tests with actual users.
Kristiina Karvonen, Miika Komu, Andrei V. Gurtov
AICCSA3
2009 Cyclic routing: Generalizing look-ahead in peer-to-peer networks
abstract
Distributed Hash Tables (DHT) provide a lookup service in peer-to-peer overlay networks. Many valuable applications have been recently built on top of several available DHTs. However, they function poorly when no direct IP connectivity is available to some nodes (e.g., located behind a NAT or firewall) or in the presence of overloaded or malicious nodes. In this paper, we propose a new method for DHT-based routing called cyclic routing. It generalizes existing single-hop look-ahead approach (also known as ldquoKnow thy neighbor's neighborrdquo) and supports multipath routing. The method provides a systematic way for collecting stable and efficient overlay paths. Cyclic routing has the same theoretical dependability and efficiency upper bounds as basic DHT routing but it is more resilient when IP connectivity is limited or when the overlay suffers from overloaded nodes.
Dmitry G. Korzun, Boris Nechaev, Andrei V. Gurtov
AICCSA3
2009 Secure multipath transport for legacy Internet applications
abstract
Multi-interface mobile devices and multihomed residential Internet connections are becoming commonplace. However, standard transport protocols TCP and SCTP are unable to take advantage of several available paths so that the application using a single transport connection would receive the aggregate
Andrei V. Gurtov, Tatiana Polishchuk
BROADNETS1
2009 Performance of Host Identity Protocol on Symbian OS
abstract
The host identity protocol (HIP) has been specified by the IETF as a new solution for secure host mobility and multihoming in the Internet. HIP uses self-certifying public- private key pairs in combination with IPsec to authenticate hosts and protect user data. While there are three open-source HIP implementations, little experience is available with running HIP on lightweight hardware such as a mobile phone. Limited computational power and battery lifetime of lightweight devices raise concerns if HIP can be used there at all. This paper describes the porting process of HIP on Linux (HIPL) and OpenHIP implementations to Symbian OS, as well as performance measurements of HIP over WLAN using Nokia E51 and N80 smartphones. We found that with 1024-bit keys, the HIP base exchange with a server varies from 1.68 to 3.31 seconds depending on whether the mobile phone is in standby or active state respectively. After analyzing HIP performance in different scenarios we make conclusions and recommendations on using IP security on lightweight hardware clients.
Andrey Khurri, Dmitriy Kuptsov, Andrei V. Gurtov
ICC3
2009 On calibrating enterprise switch measurements
abstract
The complexity of modern enterprise networks is ever-increasing, and our understanding of these important networks is not keeping pace. Our insight into intra-subnet traffic (staying within a single LAN) is particularly limited, due to the widespread use of Ethernet switches that preclude ready LAN-wide monitoring. We have recently undertaken an approach to obtaining extensive intra-subnet visibility based on tapping sets of Ethernet switch ports simultaneously. However, doing so leads to a number of measurement calibration issues that require careful consideration to address. First, one must correctly account for redundant copies of packets that appear due to switch flooding, which if not accurately identified can greatly skew subsequent analysis results. We show that a simple, natural rule one might use for doing so in fact introduces systematic errors, but an altered version of the rule performs significantly better. We then employ this revised rule to aid with calibration issues concerning the fidelity of packet timestamps and the amount of measurement loss that our collection apparatus incurred. Additionally, we develop techniques to "map" the monitored network in terms of identifying key topological components, such as subnet boundaries, which hosts were directly monitored, and the presence of "hidden" switches and hubs. Finally, we present initial analyses demonstrating that the magnitude and diversity of traffic at the subnet level is in fact striking, highlighting the importance of obtaining and correctly calibrating switch-level enterprise traces.
Boris Nechaev, Vern Paxson, Mark Allman, Andrei V. Gurtov
Internet Measurement Conference4
2009 Distributed user authentication in wireless LANs
abstract
An increasing number of mobile devices, including smartphones, use WLAN for accessing the Internet. Existing WLAN authentication mechanisms are either disruptive, such as presenting a captive web page prompting for password, or unreliable, enabling a malicious user to attack a part of operator's infrastructure. In this paper, we present a distributed authentication architecture for WLAN users providing instant network access without manual interactions. It supports terminal mobility across WLAN access points with the Host Identity Protocol (HIP), at the same time protecting the operator's infrastructure from external attacks. User data sent over a wireless link is protected by the IPsec ESP protocol. We present our architecture design and implementation experience on two OpenWrt WLAN access points, followed by measurement results of the working prototype. The system is being deployed into pilot use in the city-wide panOULU WLAN.
Dmitriy Kuptsov, Andrey Khurri, Andrei V. Gurtov
WOWMOM3
2008 Hi3: An efficient and secure networking architecture for mobile hosts
Andrei V. Gurtov, Dmitry G. Korzun, Andrey Lukyanenko, Pekka Nikander
Comput. Commun.1
2006 On scalability properties of the Hi3 control plane
Dmitry G. Korzun, Andrei V. Gurtov
Comput. Commun.2
2005 Analysis of the HIP Base Exchange Protocol
Tuomas Aura, Aarthi Nagarajan, Andrei V. Gurtov
ACISP3
2005 Traversing Middleboxes with the Host Identity Protocol
Hannes Tschofenig, Andrei V. Gurtov, Jukka Ylitalo, Aarthi Nagarajan, Murugaraj Shanmugam
ACISP2
2003 Responding to Spurious Timeouts in TCP
abstract
Delays on Internet paths, especially including wireless links, can be highly variable. On the other hand, a current trend for modern TCPs is to deploy a fine-grain retransmission timer with a lower minimum timeout value than 1 s suggested by RFC2988. Spurious TCP timeouts cause unnecessary retransmissions and congestion control back-off. The Eifel algorithm detects spurious TCP timeouts and recovers by restoring the connection state saved before the timeout. This paper presents an enhanced version of the Eifel response to spurious timeouts and illustrates its performance benefits on paths with a high delay-bandwidth product. The refinements concern the following issues (1) an efficient operation in presence of packet losses (2) appropriate restoration of congestion control, and (3) adapting the retransmit timer to avoid further spurious timeouts. In our simulations the Eifel algorithm on paths with a high delay-bandwidth product can increase throughput by up to 250% and at the same decrease the load on the network by 3%. The proposed response also shows adequate performance on heavily congested paths.
Andrei V. Gurtov, Reiner Ludwig
INFOCOM1
2001 Measured performance of GSM, HSCSD and GPRS
abstract
In this paper we present results of measurements on the performance of GSM HSCSD and GPRS data transmission. We used a measurement tool that we have developed to study the performance of various wireless links as perceived by nomadic applications using TCP. The results show that in stationary connections the throughput and response time are stable and, in general, close to the theoretical values. However, the throughput and response time vary a lot when connections are used in motion. One of the reasons is that TCP is not capable to adapt itself properly to the variability of QoS of HSCSD and GPRS, and therefore, it does a lot of unnecessary retransmissions causing performance slowdown. The performance of HSCSD is better than the performance of GPRS. Reliability is adequate in stationary connections, but in moving connections there are unwanted disconnections or long pauses in data transfer.
Jouni Korhonen, Olli Aalto, Andrei V. Gurtov, Heimo Laamanen
ICC3