Asya Mitseva

dblp:140/7588 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
6since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 4 since 2021Computer networks · 3 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Poster: Characterization of Dominant and Specific Network Patterns in Industrial Control Systems
abstract
The increasing digitization and interconnection of Industrial Control Systems (ICS) to the Internet render them susceptible to cyber attacks. Thus, a major line of research focuses on the design of reactive security solutions in the form of industrial intrusion detection systems, which aim to detect anomalies in a normal system operation. However, a crucial prerequisite for the accurate detection and localization of anomalies is the identification of typical traffic patterns that are exclusive to characterize the normal ICS behavior. Unlike previous work focusing on complex and protocol-dependent models, for characterizing ICS network traffic, in this work we propose simple, easy deployable, and effective rules for determining whether ICS network traffic, unlike traditional IT networks, remains stable over time. The main advantage of our rules is that they can be used to estimate the time required to identify the most dominant ICS traffic patterns in a given ICS. We show the efficacy of our rules by analyzing multiple ICS datasets with different industrial network protocols.
Asya Mitseva, Marco Lewandowsky, Andriy Panchenko 0001
NCA1
2024 Stop, Don't Click Here Anymore: Boosting Website Fingerprinting By Considering Sets of Subpages
Asya Mitseva, Andriy Panchenko 0001
USENIX Security Symposium1
2023 Security and performance implications of BGP rerouting-resistant guard selection algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Andriy Panchenko 0001
Comput. Secur.1
2021 POSTER: How Dangerous is My Click? Boosting Website Fingerprinting By Considering Sequences of Webpages
abstract
Website fingerprinting (WFP) is a special case of traffic analysis, where a passive attacker infers information about the content of encrypted and anonymized connections by observing patterns of data flows. Although modern WFP attacks pose a serious threat to online privacy of users, including Tor users, they usually aim to detect single pages only. By ignoring the browsing behavior of users, the attacker excludes valuable information: users visit multiple pages of a single website consecutively, e.g., by following links. In this paper, we propose two novel methods that can take advantage of the consecutive visits of multiple pages to detect websites. We show that two up to three clicks within a site allow attackers to boost the accuracy by more than 20% and to dramatically increase the threat to users' privacy. We argue that WFP defenses have to consider this new dimension of the attack surface.
Asya Mitseva, Jan Pennekamp, Johannes Lohmöller, Torsten Ziemann, Carl Hoerchner, Klaus Wehrle, Andriy Panchenko 0001
CCS1
2021 WhisperChord: Scalable and Secure Node Discovery for Overlay Networks
abstract
Node discovery is a fundamental service for any overlay network, including anonymization networks. Although anonymization and node discovery are two disjoint services, the node discovery has a direct impact on the anonymization. Centralized methods require a trusted third party, limit the network scalability, and are vulnerable to intersection (statistical disclosure) attacks. Therefore, several distributed node discovery methods were proposed to meet the security requirements of anonymization networks through additional structures within Distributed Hash Tables (DHTs). However, they require a high management overhead, a strict cooperation between nodes, and are susceptible to active and passive attacks.We propose WhisperChord—an alternative distributed node discovery approach, which incorporates gossiping into structured overlays. WhisperChord is based on a Chord DHT and neither creates any additional structures within the DHT nor requires any trusted third party. Via simulations, we show that our method provides superior protection against active attacks than prior methods and can effectively thwart information leakages.
Andriy Panchenko 0001, Asya Mitseva, Sara Knabe
LCN2
2021 GuardedGossip: Secure and Anonymous Node Discovery in Untrustworthy Networks
Andriy Panchenko 0001, Asya Mitseva, Torsten Ziemann, Till Hering
SecureComm (1)2
2020 TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting
abstract
Website fingerprinting (WFP) aims to infer information about the content of encrypted and anonymized connections by observing patterns of data flows based on the size and direction of packets. By collecting traffic traces at a malicious Tor entry node --- one of the weakest adversaries in the attacker model of Tor --- a passive eavesdropper can leverage the captured meta-data to reveal the websites visited by a Tor user. As recently shown, WFP is significantly more effective and realistic than assumed. Concurrently, former WFP defenses are either infeasible for deployment in real-world settings or defend against specific WFP attacks only.
Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
CCS2
2020 Security and Performance Implications of BGP Rerouting-Resistant Guard Selection Algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Thomas Engel 0001, Andriy Panchenko 0001
SEC1
2019 POSTER: Traffic Splitting to Counter Website Fingerprinting
abstract
Website fingerprinting (WFP) is a special type of traffic analysis, which aims to infer the websites visited by a user. Recent studies have shown that WFP targeting Tor users is notably more effective than previously expected. Concurrently, state-of-the-art defenses have been proven to be less effective. In response, we present a novel WFP defense that splits traffic over multiple entry nodes to limit the data a single malicious entry can use. Here, we explore several traffic-splitting strategies to distribute user traffic. We establish that our weighted random strategy dramatically reduces the accuracy from nearly 95% to less than 35% for four state-of-the-art WFP attacks without adding any artificial delays or dummy traffic.
Wladimir De la Cadena, Asya Mitseva, Jan Pennekamp, Jens Hiller, Fabian Lanze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
CCS2
2019 Analysis of Multi-path Onion Routing-Based Anonymization Networks
Wladimir De la Cadena, Daniel Kaiser 0001, Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001
DBSec3
2019 Multipathing Traffic to Reduce Entry Node Exposure in Onion Routing
abstract
Users of an onion routing network, such as Tor, depend on its anonymity properties. However, especially malicious entry nodes, which know the client's identity, can also observe the whole communication on their link to the client and, thus, conduct several de-anonymization attacks. To limit this exposure and to impede corresponding attacks, we propose to multipath traffic between the client and the middle node to reduce the information an attacker can obtain at a single vantage point. To facilitate the deployment, only clients and selected middle nodes need to implement our approach, which works transparently for the remaining legacy nodes. Furthermore, we let clients control the splitting strategy to prevent any external manipulation.
Jan Pennekamp, Jens Hiller, Sebastian Reuter, Wladimir De la Cadena, Asya Mitseva, Martin Henze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
ICNP5
2018 The state of affairs in BGP security: A survey of attacks and defenses
abstract
The Border Gateway Protocol (BGP) is the de facto standard interdomain routing protocol. Despite its critical role on the Internet, it does not provide any security guarantees. In response to this, a large amount of research has proposed a wide variety BGP security extensions and detection-recovery systems in recent decades. Nevertheless, BGP remains vulnerable to many types of attack. In this work, we conduct an up-to-date review of fundamental BGP threats and present a methodology for evaluation of existing BGP security proposals. Based on this, we introduce a comprehensive and up-to-date survey of proposals intended to make BGP secure and methods for detection and mitigation of routing instabilities. Last but not least, we identify gaps in research, and pinpoint open issues and unsolved challenges.
Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001
Comput. Commun.1
2016 POSTER: Fingerprinting Tor Hidden Services
abstract
The website fingerprinting attack aims to infer the content of encrypted and anonymized connections by analyzing patterns from the communication such as packet sizes, their order, and direction. Although recent study has shown that no existing fingerprinting method scales in Tor when applied in realistic settings, this does not consider the case of Tor hidden services. In this work, we propose a two-phase fingerprinting approach applied in the scope of Tor hidden services and explore its scalability. We show that the success of the only previously proposed fingerprinting attack against hidden services strongly depends on the Tor version used; i.e., it may be applicable to less than 1.5% of connections to hidden services due to its requirement for control of the first anonymization node. In contrast, in our method, the attacker needs merely to be somewhere on the link between the client and the first anonymization node and the attack can be mounted for any connection to a hidden service.
Asya Mitseva, Andriy Panchenko 0001, Fabian Lanze, Martin Henze, Klaus Wehrle, Thomas Engel 0001
CCS1