EDBT 2026 Demo / reviewers in the wild / expert
Andrei Costin
dblp:134/6433
· DBLP profile ↗
11ranked-venue papers
5as first author
4since 2021 · last 2023
0000-0002-2704-9715ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | HALE-IoT: Hardening Legacy Internet of Things Devices by Retrofitting Defensive Firmware Modifications and ImplantsabstractInternet of Things (IoT) devices and their firmware are notorious for their lifelong vulnerabilities. As device infection increases, vendors also fail to release patches at a competitive pace. Despite security in acrshort IoT being an active area of research, prior work has mainly focused on vulnerability detection and exploitation, threat modeling, and protocol security. However, these methods are ineffective in preventing attacks against legacy and End-Of-Life devices that are already vulnerable. Current research mainly focuses on implementing and demonstrating the potential of malicious modifications. Hardening emerges as an effective solution to provide acrshort IoT devices with an additional layer of defense. In this article, we bridge these gaps through the design of $\textit {HALE-IoT}$ , a generically applicable systematic approach to HArdening LEgacy acrshort IoT non-low-end devices by retrofitting defensive firmware modifications without access to the original source code. $\textit {HALE-IoT}$ approaches this nontrivial task via binary firmware reversing and modification while being underpinned by a semiautomated toolset that aims to keep cybersecurity of such devices in a hale state. Our focus is on both modern and, especially, legacy or obsolete acrshort IoT devices as they become increasingly prevalent. To evaluate the effectiveness and efficiency of HALE-IoT, we apply it to a wide range of acrshort IoT devices by retrofitting 395 firmware images with defensive implants containing an intrusion prevention system in the form of a Web Application Firewall (for prevention of Web-attack vectors), and an HTTPS-proxy (for latest and full end-to-end HTTPS support) using emulation. We also test our approach on four physical devices, where we show that HALE-IoT successfully runs on protected and quite constrained devices with as low as 32 MB of RAM and 8 MB of storage. Overall, in our evaluation, we achieve good performance and reliability with a remarkably accurate detection and prevention rate for attacks coming from both real CVEs and synthetic exploits. Javier Carrillo Mondéjar, Hannu Turtiainen, Andrei Costin, José Luis Martínez 0001, Guillermo Suarez-Tangil |
IEEE Internet Things J. | 3 |
| 2022 | CCTVCV: Computer Vision model/dataset supporting CCTV forensics and privacy applicationsabstractThe increased, widespread, unwarranted, and unaccountable use of Closed-Circuit TeleVision (CCTV) cameras globally has raised concerns about privacy risks for the last several decades. Recent technological advances implemented in CCTV cameras, such as Artificial Intelligence (AI)-based facial recognition and Internet of Things (IoT) connectivity, fuel further concerns among privacy advocates. Machine learning and computer vision automated solutions may prove necessary and efficient to assist CCTV forensics of various types.In this paper, we introduce and release the first and only computer vision models are compatible with Microsoft common object in context (MS COCO) and capable of accurately detecting CCTV and video surveillance cameras in street view, generic images, and video frames.Our best detectors were built using 8,387 images, which were manually reviewed and annotated to contain 10,419 CCTV camera instances, and achieved an accuracy rate of up to 98.7%. This work proves fundamental to a handful of present and future applications that we discuss, such as CCTV forensics, pro-active detection of CCTV cameras, providing CCTV-aware routing, navigation, and geolocation services, and estimating their prevalence and density globally and on geographic boundaries. Hannu Turtiainen, Andrei Costin, Timo Hämäläinen 0002, Tuomo Lahtinen, Lauri Sintonen |
TrustCom | 2 |
| 2022 | CCTV-FullyAware: toward end-to-end feasible privacy-enhancing and CCTV forensics applicationsabstractIt is estimated that over 1 billion Closed-Circuit Television (CCTV) cameras are operational worldwide. The advertised main benefits of CCTV cameras have always been the same; physical security, safety, and crime deterrence. The current scale and rate of deployment of CCTV cameras bring additional research and technical challenges for CCTV forensics as well, as for privacy enhancements.This paper presents the first end-to-end system for CCTV forensics and feasible privacy-enhancing applications such as exposure measurement, CCTV route recovery, CCTV-aware routing/navigation, and crowd-sourcing. For this, we developed and evaluated four complex and distinct modules (CCTVCV [1], OSRM-CCTV [2], BRIMA [3], CCTV-Exposure [4]), all of which are novel, unique, peer-reviewed, and can be used either separately or within an integrated end-to-end system such as CCTV-FullyAware. We release all our artefacts as open-source/open data. We hope our work will bootstrap policy-driving discussions and large-scale applications such as CCTV forensics and privacy-enhancing technologies. Hannu Turtiainen, Andrei Costin, Timo Hämäläinen 0002, Tuomo Lahtinen, Lauri Sintonen |
TrustCom | 2 |
| 2021 | Brima: Low-Overhead Browser-Only Image Annotation Tool (Preprint)abstractImage annotation and large annotated datasets are crucial parts within the Computer Vision and Artificial Intelligence fields. At the same time, it is well-known and acknowledged by the research community that the image annotation process is challenging, time-consuming and hard to scale. Therefore, the researchers and practitioners are always seeking ways to perform the annotations easier, faster, and at higher quality. Even though several widely used tools exist and the tools’ landscape evolved considerably, most of the tools still require intricate technical setups and high levels of technical savviness from its operators and crowdsource contributors.In order to address such challenges, we develop and present BRIMA – a flexible and open-source browser extension that allows BRowser-only IMage Annotation at considerably lower overheads. Once added to the browser, it instantly allows the user to annotate images easily and efficiently directly from the browser without any installation or setup on the client-side. It also features cross-browser and cross-platform functionality thus presenting itself as a neat tool for researchers within the Computer Vision, Artificial Intelligence, and privacy-related fields. Tuomo Lahtinen, Hannu Turtiainen, Andrei Costin |
ICIP | 3 |
| 2020 | ISAdetect: Usable Automated Detection of CPU Architecture and Endianness for Executable Binary Files and Object CodeabstractStatic and dynamic binary analysis techniques are actively used to reverse engineer software's behavior and to detect its vulnerabilities, even when only the binary code is available for analysis. To avoid analysis errors due to misreading op-codes for a wrong CPU architecture, these analysis tools must precisely identify the Instruction Set Architecture (ISA) of the object code under analysis. The variety of CPU architectures that modern security and reverse engineering tools must support is ever increasing due to massive proliferation of IoT devices and the diversity of firmware and malware targeting those devices. Recent studies concluded that falsely identifying the binary code's ISA caused alone about 10% of failures of IoT firmware analysis. The state of the art approaches detecting ISA for executable object code look promising, and their results demonstrate effectiveness and high-performance. However, they lack the support of publicly available datasets and toolsets, which makes the evaluation, comparison, and improvement of those techniques, datasets, and machine learning models quite challenging (if not impossible). This paper bridges multiple gaps in the field of automated and precise identification of architecture and endianness of binary files and object code. We develop from scratch the toolset and datasets that are lacking in this research space. As such, we contribute a comprehensive collection of open data, open source, and open API web-services. We also attempt experiment reconstruction and cross-validation of effectiveness, efficiency, and results of the state of the art methods. When training and testing classifiers using solely code-sections from executable binary files, all our classifiers performed equally well achieving over 98% accuracy. The results are consistent and comparable with the current state of the art, hence supports the general validity of the algorithms, features, and approaches suggested in those works. Sami Kairajärvi, Andrei Costin, Timo Hämäläinen 0002 |
CODASPY | 2 |
| 2017 | Towards Automated Classification of Firmware Images and Identification of Embedded Devices
Andrei Costin, Apostolis Zarras, Aurélien Francillon |
SEC | 1 |
| 2016 | Automated Dynamic Firmware Analysis at Scale: A Case Study on Embedded Web InterfacesabstractEmbedded devices are becoming more widespread, interconnected, and web-enabled than ever. However, recent studies showed that embedded devices are far from being secure. Moreover, many embedded systems rely on web interfaces for user interaction or administration. Web security is still difficult and therefore the web interfaces of embedded systems represent a considerable attack surface. Andrei Costin, Apostolis Zarras, Aurélien Francillon |
AsiaCCS | 1 |
| 2014 | A Large-Scale Analysis of the Security of Embedded Firmwares
Andrei Costin, Jonas Zaddach, Aurélien Francillon, Davide Balzarotti |
USENIX Security Symposium | 1 |
| 2014 | Short paper: a dangerous 'pyrotechnic composition': fireworks, embedded wireless and insecurity-by-designabstractFireworks are used around the world to salute popular events such as festivals, weddings, and public or private celebrations. Besides their entertaining effects fireworks are essentially colored explosives which are sometimes directly used as weapons. Modern fireworks systems heavily rely on `wireless pyrotechnic firing systems'. Those `embedded cyber-physical systems' (ECPS) are able to remotely control pyrotechnic composition ignition. The failure to properly secure these computer sub-systems may have disastrous, if not deadly, consequences. They rely on standardized wireless communications, off the shelf embedded hardware and custom firmware. Andrei Costin, Aurélien Francillon |
WISEC | 1 |
| 2014 | Inside the SCAM Jungle: A Closer Look at 419 Scam Email Operationsabstract419 scam (also referred to as Nigerian scam) is a popular form of fraud in which the fraudster tricks the victim into paying a certain amount of money under the promise of a future, larger payoff. Using a public dataset, in this paper, we study how these forms of scam campaigns are organized and evolve over time. In particular, we discuss the role of phone numbers as important identifiers to group messages together and depict the way scammers operate their campaigns. In fact, since the victim has to be able to contact the criminal, both email addresses and phone numbers need to be authentic and they are often unchanged and re-used for a long period of time. We also present in detail several examples of 419 scam campaigns, some of which last for several years - representing them in a graphical way and discussing their characteristics. Jelena Isacenkova, Olivier Thonnard, Andrei Costin, Aurélien Francillon, Davide Balzarotti |
EURASIP J. Inf. Secur. | 3 |
| 2013 | The role of phone numbers in understanding cyber-crime schemesabstractInternet and telephones are part of everyone's modern life. Unfortunately, several criminal activities also rely on these technologies to reach their victims. While the use and importance of the Internet has been largely studied, previous work overlooked the role that phone numbers can play in understanding online threats. In this work we aim at determining if leveraging phone numbers analysis can improve our understanding of the underground markets, illegal computer activities, or cyber-crime in general. This knowledge could then be adopted by several defensive mechanisms, including blacklists or advanced spam heuristics. Our results show that, in scam activities, phone numbers remain often more stable over time than email addresses. Using a combination of graph analysis and geographical Home Location Register (HLR) lookups, we identify recurrent cyber-criminal business models and link together scam communities that spread over different countries. Andrei Costin, Jelena Isacenkova, Marco Balduzzi, Aurélien Francillon, Davide Balzarotti |
PST | 1 |