Roger Piqueras Jover

dblp:17/10934 · DBLP profile ↗
← Back
17ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-1420-2987ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 1 first-authorSecurity and privacy · 6 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2024 Fixing Insecure Cellular System Information Broadcasts For Good
abstract
Cellular networks are essential everywhere, and securing them is increasingly important as attacks against them become more prevalent and powerful. All cellular network generations bootstrap new radio connections with unauthenticated System Information Blocks (SIBs), which provide critical parameters needed to identify and connect to the network. Many cellular network attacks require exploiting SIBs. Authenticating these messages would eliminate whole classes of attack, from spoofed emergency alerts to fake base stations.
Alexander J. Ross, Bradley Reaves, Yomna Nasser, Gil Cukierman, Roger Piqueras Jover
RAID5
2024 ASTRA-5G: Automated Over-the-Air Security Testing and Research Architecture for 5G SA Devices
abstract
Despite the widespread deployment of 5G technologies, there exists a critical gap in security testing for 5G Standalone (SA) devices. Existing methods, largely manual and labor-intensive, are ill-equipped to fully uncover the state of security in the implementations of 5G SA protocols and standards on devices, severely limiting the ability to conduct comprehensive evaluations. To address this issue, in this work, we introduce a novel, open-source framework that automates the security testing process for 5G SA devices. By leveraging enhanced functionalities of 5G SA core and Radio Access Network (RAN) software, our framework offers a streamlined approach to generating, executing, and evaluating test cases, specifically focusing on the Non-Access Stratum layer. Our application of this framework across multiple 5G SA devices provides in-depth security insights, significantly improving testing efficiency and breadth.
Syed Khandker, Michele Guerra, Evangelos Bitsikas, Roger Piqueras Jover, Aanjhan Ranganathan, Christina Pöpper
WISEC4
2023 UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing Framework
abstract
Security flaws and vulnerabilities in cellular networks lead to severe security threats given the data-plane services that are involved, from calls to messaging and Internet access. While the 5G Standalone (SA) system is currently being deployed worldwide, practical security testing of User Equipment (UE) has only been conducted and reported publicly for 4G/LTE and earlier network generations. In this paper, we develop and present the first open-source based security testing framework for 5G SA User Equipment. To that end, we modify the functionality of open-source suites (Open5GS and srsRAN) and develop a broad set of test cases for the 5G NAS and RRC layers. We apply our testing framework in a proof-of-concept manner to 5G SA mobile phones and provide detailed insights from our experiments. While being a framework in development, the results of our experiments presented in this paper can assist other researchers in the field and have the potential to improve 5G SA security.
Evangelos Bitsikas, Syed Khandker, Ahmad Salous, Aanjhan Ranganathan, Roger Piqueras Jover, Christina Pöpper
WISEC5
2020 CSAI: Open-Source Cellular Radio Access Network Security Analysis Instrument
abstract
This paper presents our methodology and software toolbox that allows analyzing the radio access network security of laboratory and commercial 4G and future 5G cellular networks. We leverage a free open-source software suite that implements the LTE UE and eNB enabling real-time signaling using software radio peripherals. We modify the UE software processing stack to act as an LTE packet collection and examination tool. This is possible because of the openness of the 3GPP specifications. Hence, we are able to receive and decode LTE downlink messages for the purpose of analyzing potential security problems of the standard. This paper shows how to rapidly prototype LTE tools and build a software-defined radio access network (RAN) analysis instrument for research and education. Using the Cellular Security Analysis Instrument (CSAI), a researcher can analyze broadcast and paging messages of cellular networks. CSAI is also able to test networks to aid in the identification of vulnerabilities and verify functionality post-remediation. Additionally, we found that it can crash a software eNB which motivates equivalent analyses of commercial network equipment and its robustness against denial of service attacks.
Thomas Byrd, Vuk Marojevic, Roger Piqueras Jover
VTC Spring3
2020 Special issue on Advancements in 5G Networks Security
Wojciech Mazurczyk, Pascal Bisson, Roger Piqueras Jover, Koji Nakao, Krzysztof Cabaj
Future Gener. Comput. Syst.3
2015 Detecting Malicious Activity on Smartphones Using Sensor Measurements
Roger Piqueras Jover, Ilona Murynets, Jeffrey Bickford
NSS1
2015 Connection-less communication of IoT devices over LTE mobile networks
abstract
The emergence of the Internet of Things (IoT) introduces a vast ecosystem of new network-enabled objects. Although most current cellular IoT services run over 2G and 3G cellular networks, the Long Term Evolution (LTE) is expected to be one of the main platforms for the emergence of new Machine to Machine (M2M) communication systems. Cellular communication protocols were designed and optimized to handle human-originated communications. However, with the forecasted deployment of billions of M2M devices, there is a growing concern in the industry that the cellular core may be overloaded by the sharp increase in control plane signaling load. The traffic characteristics of IoT devices are very different from those of smartphones and can enhance the risk for signaling storms. A new connection-less communication protocol for IoT systems over LTE mobile networks is proposed to spare signaling exchanges at the cellular core for M2M communications. It requires no standards modification and provides an overlaying channel between connected objects and base stations. Its effectiveness is demonstrated through simulations with realistic background network load parameters extracted from real LTE traffic sniffed from a busy downtown Manhattan intersection.
Roger Piqueras Jover, Ilona Murynets
SECON1
2015 Scalability of Machine to Machine systems and the Internet of Things on LTE mobile networks
abstract
Machine to Machine (M2M) systems are actively spreading, with mobile networks rapidly evolving to provide connectivity beyond smartphones and tablets. With billions of embedded devices expected to join cellular networks over the next few years, novel applications are emerging and contributing to the Internet of Things (IoT) paradigm. The new generation of mobile networks, the Long Term Evolution (LTE), has been designed to provide enhanced capacity for a large number of mobile devices and is expected to be the main enabler of the emergence of the IoT. In this context, there is growing interest in the industry and standardization bodies on understanding the potential impact of the scalability of M2M systems on LTE networks. The highly heterogeneous traffic patterns of most M2M systems, very different from those of smartphones and other mobile devices, and the surge of M2M connected devices over the next few years, present a great challenge for the network. This paper presents the first insights and answers on the scalability of the IoT on LTE networks, determining to what extent mobile networks could be overwhelmed by the large amount of devices attempting to communicate. Based on a detailed analysis with a custom-built, standards-compliant, large-scale LTE simulation testbed, we determine the main potential congestion points and bottlenecks, and determine which types of M2M traffic present a larger challenge. To do so, the simulation testbed implements realistic statistical M2M traffic models derived from fully anonymized real LTE traces of six popular M2M systems from one of the main tier-1 operators in the United States.
Jill Jermyn, Roger Piqueras Jover, Ilona Murynets, Mikhail Istomin, Salvatore J. Stolfo
WOWMOM2
2014 Is it really you?: user identification via adaptive behavior fingerprinting
abstract
The increased popularity of mobile devices widens opportunities for a user either to lose the device or to have the device stolen and compromised. At the same time, user interaction with a mobile device generates a unique set of features such as dialed numbers, timestamps of communication activities, contacted base stations, etc. This work proposes several methods to identify the user based on her communications history. Specifically, the proposed methods detect an abnormality based on the behavior fingerprint generated by a set of features from the network for each user session. We present an implementation of such methods that use features from real SMS, and voice call records from a major tier 1 cellular operator. This can potentially trigger a rapid reaction upon an unauthorized user gaining control of a lost or stolen terminal, preventing data compromise and device misuse. The proposed solution can also detect background malicious traffic originated by, for example, a malicious application running on the mobile device. Our experiments with annonymized data from 10,000 users, representing over 14 million SMS and voice call detail records, show that the proposed methods are scalable and can continuously identify millions of mobile users while preserving data privacy, and achieving low false positives and high misuse detection rates with low storage and computation overhead.
Paul Giura, Ilona Murynets, Roger Piqueras Jover, Yevgeniy Vahlis
CODASPY3
2014 Firecycle: A scalable test bed for large-scale LTE security research
abstract
LTE (Long Term Evolution) is the latest cellular communications standard to provide advanced mobile services that go beyond traditional voice and short messaging traffic. Mobility networks are experiencing a drastic evolution with the advent of Machine to Machine (M2M) systems and the Internet of Things (IoT), which is expected to result in billions of connected devices in the near future. In parallel, the security threat landscape against communication networks has rapidly evolved over the last few years, with major Distributed Denial of Service (DDoS) attacks and the substantial spread of mobile malware. In this paper we introduce Firecycle, a new modeling and simulation platform for next-generation LTE mobility network security research. This standards compliant platform is suitable for large-scale security analysis of threats against a real LTE mobile network. It is designed with the ability to be distributed over the cloud, with an arbitrary number of virtual machines running different portions of the network, thus allowing simulation and testing of a full-scale LTE mobility network with millions of connected devices. Moreover, the mobile traffic generated by the platform is modeled from real data traffic observations from one of the major tier-1 operators in the US.
Jill Jermyn, Roger Piqueras Jover, Mikhail Istomin, Ilona Murynets
ICC2
2014 Analysis and detection of SIMbox fraud in mobility networks
abstract
Voice traffic termination fraud, often referred to as Subscriber Identity Module box (SIMbox) fraud, is a common illegal practice on mobile networks. As a result, cellular operators around the globe lose billions annually. Moreover, SIMboxes compromise the cellular network infrastructure by overloading local base stations serving these devices. This paper analyzes the fraudulent traffic from SIMboxes operating with a large number of SIM cards. It processes hundreds of millions of anonymized voice call detail records (CDRs) from one of the main cellular operators in the United States. In addition to overloading voice traffic, fraudulent SIMboxes are observed to have static physical locations and to generate disproportionately large volume of outgoing calls. Based on these observations, novel classifiers for fraudulent SIMbox detection in mobility networks are proposed. Their outputs are optimally fused to increase the detection rate. The operator's fraud department confirmed that the algorithm succeeds in detecting new fraudulent SIMboxes.
Ilona Murynets, Michael Zabarankin, Roger Piqueras Jover, Adam Panagia
INFOCOM3
2014 Enhancing the security of LTE networks against jamming attacks
abstract
The long-term evolution (LTE) is the newly adopted technology to offer enhanced capacity and coverage for current mobility networks, which experience a constant traffic increase and skyrocketing bandwidth demands. This new cellular communication system, built upon a redesigned physical layer and based on an orthogonal frequency division multiple access (OFDMA) modulation, features robust performance in challenging multipath environments and substantially improves the performance of the wireless channel in terms of bits per second per Hertz (bps/Hz). Nevertheless, as all wireless systems, LTE is vulnerable to radio jamming attacks. Such threats have security implications especially in the case of next-generation emergency response communication systems based on LTE technologies. This proof of concept paper overviews a series of new effective attacks (smart jamming) that extend the range and effectiveness of basic radio jamming. Based on these new threats, a series of new potential security research directions are introduced, aiming to enhance the resiliency of LTE networks against such attacks. A spread-spectrum modulation of the main downlink broadcast channels is combined with a scrambling of the radio resource allocation of the uplink control channels and an advanced system information message encryption scheme. Despite the challenging implementation on commercial networks, which would require inclusion of these solutions in future releases of the LTE standard, the security solutions could strongly enhance the security of LTE-based national emergency response communication systems.
Roger Piqueras Jover, Joshua Lackey, Arvind Raghavan
EURASIP J. Inf. Secur.1
2013 Anomaly detection in cellular Machine-to-Machine communications
abstract
Communication networks are rapidly evolving with connectivity reaching far beyond cell-phones, computers and tablets. Novel applications are emerging based on the widespread presence of network-enabled sensors and actuators. Machine-to-Machine (M2M) devices such as power meters, medical sensors and asset tracking appliances provide a new dimension to telecommunication services. The majority of these novel systems require low bandwidth and base their communications and control protocols on the Short Messaging Service (SMS). SMS-based attacks pose a serious threat to M2M devices and the servers/users communicating with them. Researchers have demonstrated how to remotely control embedded devices and leverage them for malicious message floods. These attacks can potentially be masked by the massive amounts of legitimate text messages traveling the airwaves daily and providing data connectivity to these connected M2M appliances. In this paper we propose two algorithms for detecting anomalous SMS activities and attacks on aggregate, cluster and individual device levels. Once these algorithms detect an anomaly they automatically determine the cause of the anomaly. Effectiveness of the algorithms has been demonstrated on real life SMS communication traffic of M2M devices connected to the network of one of the main tier-1 providers in the US.
Ilona Murynets, Roger Piqueras Jover
ICC2
2012 How an SMS-based malware infection will get throttled by the wireless link
abstract
As smart phones increase in popularity, they become an attractive target for attackers and spammers. This paper presents a new simulation model that evaluates the effects of an SMS-based malware infection in GSM and UMTS networks. It is the first known work that accounts for the wireless link of the network in modeling of malware propagation. The paper demonstrates propagation of the SMS-transmitted malware in a densely populated metropolitan area. It shows that spreading rate of cellular malware is tightly bounded by the actual network architecture and strongly diverges from the pattern seen in regular wired Internet-connected networks.
Ilona Murynets, Roger Piqueras Jover
ICC2
2012 Crime scene investigation: SMS spam data analysis
abstract
The Short Messaging Service (SMS), one of the most successful cellular services, generates millions of dollars in revenue for mobile operators. Estimates indicate that billions of text messages are traveling the airwaves daily. Nevertheless, text messaging is becoming a source of customer dissatisfaction due to the rapid surge of messaging abuse activities. Although spam is a well tackled problem in the email world, SMS spam experiences a yearly growth larger than 500%. In this paper we present, to the best of our knowledge, the first analysis of SMS spam traffic from a tier-1 cellular operator. Communication patterns of spammers are compared to those of legitimate cell-phone users and Machine to Machine (M2M) connected appliances. The results indicate that M2M systems exhibit communication profiles similar to spammers, which could mislead spam filters. Beyond the expected results, such as a large load of text messages sent out to a wide target list, other interesting findings are made. For example, the results indicate that the great majority of the spammers connect to the network with just a handful of different hardware models. We find the main geographical sources of messaging abuse in the US. We also find evidence of spammer mobility, voice and data traffic resembling the behavior of legitimate customers.
Ilona Murynets, Roger Piqueras Jover
Internet Measurement Conference2
2012 Uplink Interference Mitigation for OFDMA Femtocell Networks
abstract
Femtocell networks, consisting of a conventional macro cellular deployment and overlaying femtocells, forming a hierarchical cell structure, constitute an attractive solution to improving the macrocell capacity and coverage. However, the inter- and intra-tier interferences in such systems can significantly reduce the capacity and cause an unacceptably high level of outage. This paper treats the uplink interference problem in orthogonal frequency-division multiple-access (OFDMA)-based femtocell networks with partial cochannel deployment. We first propose an inter-tier interference mitigation strategy without the femtocell users power control by forcing the femto-interfering macrocell users to use only some dedicated subcarriers. The non-interfering macrocell users, on the other hand, can use either the dedicated subcarriers, or the shared subcarriers which are also used by the femtocell users. We then propose subcarrier allocation schemes based on the auction algorithm for macrocell users and femtocell users, respectively, to independently mitigate the intra-tier interference. The proposed interference mitigation scheme for femtocell networks offers significant performance improvement over the existing methods by substantially reducing the inter- and intra-tier inferences in the system.
Yanzan Sun, Roger Piqueras Jover, Xiaodong Wang 0001
IEEE Trans. Wirel. Commun.2
2006 Dynamic Pricing for Decentralised Rat Selection in Heterogeneous Scenarios
abstract
This paper addresses the inclusion of dynamic pricing concepts to provide CRRM solutions in heterogeneous scenarios. A RAT selection algorithm based on a dynamic pricing strategy aimed at controlling the load in the considered RATs in a decentralised way is proposed and evaluated through system level simulations. Results reveal that, by a proper variation of the RAT price, which at the end becomes transparent to the actual price paid by the users, the algorithm is able to provide better performance than when the pricing strategy is not considered.
Roger Piqueras Jover, Jordi Pérez-Romero, Oriol Sallent, Ramón Agustí
PIMRC1