Subhojeet Mukherjee

dblp:160/7682 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
0since 2021 · last 2020
0009-0002-2666-5898ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Usable security · 40% Cyber-physical and IoT security · 34% Systems and software security · 26%
Human-computer interaction and pervasive computing
1 paper
Design research and methods · 100%

Topics — the 5 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cyber-physical and IoT security
automotive security
0.312017
POSTER: PenJ1939: An Interactive Framework for Design and Dissemination of Exploits for Commercial Vehicles · CCS 2017
Systems and software security
exploitation
0.312017
POSTER: PenJ1939: An Interactive Framework for Design and Dissemination of Exploits for Commercial Vehicles · CCS 2017
Usable security
security user studies
0.212015
POSTER: PsychoRithm: A Framework for Studying How Human Traits Affect User Response to Security Situations · CCS 2015
Usable security
user behavior
0.212015
POSTER: PsychoRithm: A Framework for Studying How Human Traits Affect User Response to Security Situations · CCS 2015
Design research and methods › research methodology
user study methodology
0.112015
POSTER: PsychoRithm: A Framework for Studying How Human Traits Affect User Response to Security Situations · CCS 2015

Methods — techniques the papers use, named apart from their topics

real-time scenario presentation · 0.4behavioral recording · 0.4exploit scripting · 0.3
YearPublicationVenuePosition
2020 TruckSTM: Runtime Realization of Operational State Transitions for Medium and Heavy Duty Vehicles
abstract
Embedded computing devices play an integral role in the mechanical operations of modern-day vehicles. These devices exchange information containing critical vehicle parameters that reflect the current state of operations. Such information can be captured for various purposes, such as diagnostics, fleet management, and analytics. Although monitoring individual parameters can be useful for some applications, monitoring distinct combinations of parameters can reveal more complex and higher-level states that may give useful information. Existing monitoring systems either lack user configurability and control or present simple user interfaces that make it difficult to monitor and collate different parameters to observe high-level vehicle states. In this work, we present TruckSTM, a novel application that realizes user-defined states from messages seen in the embedded networks of medium and heavy duty vehicles and displays state transitions on an interactive user interface. We begin by symbolically formulating some of the in-vehicle networking concepts and formally defining the concept of operational states and state transitions. We then elaborate on the operations performed by TruckSTM in mapping network-obtained vehicle parameters to states that can be defined in standard JSON format. Finally, we evaluate TruckSTM’s asymptotic performance and present the results for the worst-case scenario and demonstrate that in a real world scenario such high level state visualization constraints of an operational truck.
Subhojeet Mukherjee, Jeffrey C. Van Etten, Namburi Rani Samyukta, Jacob Walker, Indrakshi Ray, Indrajit Ray
ACM Trans. Cyber Phys. Syst.1
2017 POSTER: PenJ1939: An Interactive Framework for Design and Dissemination of Exploits for Commercial Vehicles
abstract
Vehicle security has been receiving a lot of attention from both the black hat and white hat community of late. Research in this area has already led to the fabrication of different attacks, of which some have been shown to have potentially grave consequences. Vehicle vendors and original equipment manufacturers (OEM)s are thus presented with the additional responsibility of ensuring in-vehicular communication level security. In this poster paper, we present a framework, which allows any individual to write, test, and store exploit scripts which could then be run by any interested party on in-vehicular networks of commercial vehicles like trucks and buses.
Subhojeet Mukherjee, Noah Cain, Jacob Walker, Indrajit Ray, Indrakshi Ray
CCS1
2017 A Precedence Graph-Based Approach to Detect Message Injection Attacks in J1939 Based Networks
abstract
Vehicles now include Electronic Control Units (ECUs) that communicate with each other via broadcast networks. Cyber-security professionals have shown that such embedded communication networks can be compromised. Very recently, it has been shown that embedded devices connected to commercial vehicle networks can be manipulated to perform unintended actions by injecting spoofed messages. Such attacks can be hard to detect as they can mimic safety critical actions performed by ECUs. We present a precedence graph-based anomaly detection technique to detect malicious message injections. Our approach can detect malicious message injections and is able to distinguish them from safety critical actions like hard braking.
Subhojeet Mukherjee, Jacob Walker, Indrakshi Ray, Jeremy Daily
PST1
2015 POSTER: PsychoRithm: A Framework for Studying How Human Traits Affect User Response to Security Situations
abstract
User studies to investigate which human traits affect a user's response to cyber security related situations are typically conducted via self-reported surveys. However, it has been observed that factors such as peer perception, socially desirable responding, and responder bias etc. frequently impact the results, which then do not necessarily reflect the actual behavior of the user when subjected to real world security incidents. To mitigate such biases, we developed PsychoRithm - a software system that presents different real-world security scenarios for the subjects and records their real-time reactions to these scenarios. This paper describes the architecture of PsychoRithm, the design choices we had to make, and the challenges we faced in the design process.
Subhojeet Mukherjee, Sachini S. Weerawardhana, Chancey Dunn, Indrajit Ray, Adele E. Howe
CCS1