Pawel Rajba

dblp:145/7231 · DBLP profile ↗
← Back
8ranked-venue papers
7as first author
6since 2021 · last 2025
0000-0003-4252-5545ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 6 first-author · 5 since 2021
YearPublicationVenuePosition
2025 Double Proof-of-Work Scheme for the Key Transfer in the Steganographic Communication
Pawel Rajba, Wojciech Mazurczyk, Jörg Keller 0001
AINA (4)1
2024 How to evade modern web cryptojacking detection tools? A review of practical findings
abstract
One of the foundations of cryptocurrencies based on proof-of-work consensus is mining. This is an activity which consumes a lot of computational resources, so malicious actors introduce cryptojacking malware to exploit users computers and in result use their victim resources. Usually it operates either as an operating system process (host-based) or in a web browser (web-based). Cryptojacking emerged several years ago together with the increasing adoption and prevalence of cryptocurrencies and, as we hear regularly about attacked cloud providers or affected websites including major web content provider, the threat still requires respective attention.
Krzysztof Chmiel, Pawel Rajba
ARES2
2024 Identity and Access Management Architecture in the SILVANUS Project
abstract
SILVANUS is a scientific collaboration EU-funded project with the goal to mitigate the growing impact of wildfires caused by global climate change by implementing a comprehensive global fire prevention strategy. Due to the significant complexity and collaborative nature of the project which involves more than 50 parties, it is a challenge to ensure unified and governed security especially that the platform is based on heterogeneous and multi-component architecture. To ensure the security requirements are delivered, different security architecture perspectives need to be considered and one of these is identity and access management.
Pawel Rajba, Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Dawid Nastaj, Krzysztof Cabaj
ARES1
2023 Proof-of-work based new encoding scheme for information hiding purposes
abstract
Steganography techniques often assume that the secret message looks randomly or is encrypted. If encryption is required, it leads to a random-looking message, but key exchange may be problematic and jeopardize covert communication. If encryption is not required, then the question arises of whether other cryptographic solutions that are “cheaper” than encryption can provide the same level of randomness. In this paper, we investigate both questions. First, we propose a proof-of-work-inspired approach to securely transfer the key with the encrypted message, avoiding a previous key exchange. Second, we introduce a scheme that uses T-functions to substitute symmetric encryption algorithms. We implement both proposed solutions, measure the entropy of the resulting messages, and apply the Kolmogorov-Smirnoff tests. The results obtained prove that both schemes are feasible.
Pawel Rajba, Jörg Keller 0001, Wojciech Mazurczyk
ARES1
2022 Limitations of Web Cryptojacking Detection: A Practical Evaluation
abstract
Cryptojacking is one of the new threats that emerged several years ago with the growing popularity and increasing value of cryptocurrencies. In essence, it is a malicious technique where the attacker parasites on the victim’s resources like CPU time, memory, etc. to mine cryptocurrencies for his own benefit. Cryptojacking comes in two main flavors, i.e., as a malicious script embedded into the website or as a standalone malware residing on the compromised machine. As such threats are still widespread, in this paper, we perform a practical evaluation of the existing web browser blockers against real-world web-based cryptojacking solutions. The obtained experimental results reveal that in more than 60% of cases the tested defensive solutions fail in fighting this threat or can be easily fooled with a few simple modifications. This underlines the importance of further efforts toward developing effective countermeasures.
Pawel Rajba, Wojciech Mazurczyk
ARES1
2021 Data Hiding Using Code Obfuscation
abstract
Digital transformation of many companies and government administrations, now accelerated by the pandemic, provides cybercriminals an increased opportunity of incorporating various types of information hiding techniques into the malicious software and by that perform different types of attacks. By leveraging data hiding methods, attackers can, e.g., exfiltrate confidential information, enable covert transfers between the compromised victim’s machine and an attacker-operated infrastructure, or stealthily transmit additional malicious tools. Furthermore, in the digital era, any type of digital channel can be exploited for data hiding, e.g., digital images, video or audio content, text, or network traffic. That is why it is of great importance to be acquainted with the different techniques that cybercriminals can utilize to design and introduce effective countermeasures and identify/eliminate these threats when they appear. Obfuscation is a popular technique in the software development domain which makes the code illegible and which protects the implemented algorithms and business logic from unauthorized disclosure. In this paper, we investigate whether code obfuscation can be abused for information hiding purposes. The core idea of the proposed information hiding method is to replace some randomly generated strings being a part of the introduced dead code with the encoded secret message. The performed experimental evaluation and obtained results confirm that such process can be easily adopted for data hiding, thus countermeasures need to be adjusted accordingly.
Pawel Rajba, Wojciech Mazurczyk
ARES1
2020 Exploiting minification for data hiding purposes
abstract
Nowadays various types of data hiding techniques are used to conceal data in different types of digital content, e.g. image, video, audio, text, or even network traffic. Such methods can be utilized for nefarious purposes, for instance, for confidential data exfiltration, enabling secret communication between the infected host and attacker's server or to download additional modules of malware. From this perspective, analyzing different schemes of data hiding allows to assess the preparedness of the current defensive systems. Minification is the process of the source code manipulation while preserving its functionality. In result, the size of the source code is reduced making the transmission more efficient. In this paper we investigate whether minification of JavaScript files can be exploited for data hiding purposes. The obtained results prove that this is feasible and thus countermeasures must be adjusted to take into account such threats.
Pawel Rajba, Wojciech Mazurczyk
ARES1
2018 Challenges and mitigation approaches for getting secured applications in an enterprise company
abstract
For years many companies have paid attention to making sure infrastructure is protected adequately while making applications secured was underestimated. This approach is changing nowadays, but according to many security research companies (like WhiteHat or Gartner) a lot of vulnerabilities are still present in applications. Those vulnerabilities are on different levels like architecture or code and they have multiple sources like wrong requirements, processes, tools, unskilled developers or everything at the same time. In the paper we present the challenges that were discovered when we applied some mitigation approaches during the security journey in an enterprise company in the automotive industry.
Pawel Rajba
ARES1