Md Masoom Rabbani

dblp:202/9003 · DBLP profile ↗
← Back
16ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0002-3518-0203ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 since 2021Computer networks · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 CarDS - Controller Area Network and Automotive Ethernet Realistic Data Set
abstract
Intrusion Detection Systems (IDSs) serve as a crucial defense mechanism against cyberattacks targeting the In-Vehicle Network (IVN) of modern, interconnected vehicles. To develop and test new IDS approaches, researchers require realistic IVN data featuring real attacks on moving vehicles. To this end, this paper presents Controller Area Network and Automotive Ethernet Realistic Data Set (CarDS), a novel dataset targeting both the Controller Area Network (CAN) and Automotive Ethernet (AE) traffic of a modern, multi-domain and multi-protocol IVN. Existing datasets are often simulated or limited to basic IVN architectures consisting of only a single CAN bus. Additionally, there are no realistic datasets for AE, despite its growing importance in high-speed in-vehicle communication. CarDS addresses these limitations by providing a labeled, time-synchronized dataset of CAN and AE traces that includes both comprehensive benign profiles and sophisticated attacks. Our traces are captured from an electric vehicle from 2020 featuring a domain-oriented architecture comprising 10 internal CAN buses and 6 AE buses. Specifically, our dataset covers 9h 07m 09s of real IVN data and features 397,383,125 CAN and 180,604,377 AE messages distributed over different scenarios in 258 traces.
Wouter Hellemans, Jannis Hamborg, Timm Lauser, Md Masoom Rabbani, Bart Preneel, Christoph Krauß, Nele Mentens
ACSAC4
2025 SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle Networks
abstract
In recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK.
Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens
EuroS&P3
2025 ITERATOR: Interruptible Remote Attestation Through Cuckoo Filters
abstract
Remote attestation (RA) is emerging as a promising security mechanism that establishes trust in IoT devices by detecting the malware presence. Typically, RA consists of computing a hash over the device’s memory and is executed as anatomicprocedure to guarantee the reliability of the attestation evidence. However, in real-world situations, such as those involving real-time systems, energy-harvesting devices, or mission-critical operations, the IoT device may not be able to complete the attestation procedure due to various factors like task scheduling, limited battery life, or higher priority tasks. In such scenarios where flexibility, adaptability, and security are paramount, enablinginterruptibilityof RA is crucial. This paper presents a novel approach called ITERATOR which leverages hash-based storage to enable interruptible RA without any additional hardware requirements. Our proposal transforms the device attestation procedure from the traditional approach of memory hash computation to a lookup operation in a hash-based storage, namely, Cuckoo filter. The ITERATOR protocol divides the device’s memory into blocks associated with a Cuckoo filter bucket. This approach allows the device to perform RA in multiple rounds, ensuring secure interruptible attestation. We perform software simulations of ITERATOR, demonstrating its high effectiveness in detecting the malware presence. Due to its interruptible design, ITERATOR cannot guarantee 100% detection in a single attestation round; however, repeated rounds make long-term evasion by malware highly unlikely. In particular, the experiments showed that the probability of evading the detection ranges between 37% and less than 1%, depending on the protocol configuration. Moreover, we validate ITERATOR’s efficiency through two hardware proof-of-concept implementations that rely on ESP32 and FPGA platforms. The FPGA implementation shows the high efficiency of the protocol, with 34.3ns to attest a single memory block.
Nicoló Sponziello, Arish Sateesan, Md Masoom Rabbani, Nele Mentens, Nicola Dragoni, Edlira Dushku
IEEE Internet Things J.3
2025 Toward a Real-Time Intrusion Detection System for Modern In-Vehicle Networks
abstract
Over the past decade, it has been demonstrated that the In-Vehicle Network (IVN) of a modern Intelligent Transportation System (ITS) is vulnerable to several cyberattacks. Given the collaborative nature of these systems, detecting (remote) cyberattacks is of utmost importance in ensuring trusted interactions. One key technique that has been explored to detect adversarial presence in IVNs are Intrusion Detection Systems (IDSs). However, many existing solutions focus on legacy architectures or are not practically feasible due to their hardware requirements or inability to operate in real-time. To this end, we propose Modular Reduced Temporal Convolutional Network (MR-TCN), an efficient IDS architecture that can effectively be accelerated on hardware to enable real-time intrusion detection in low-cost embedded platforms. Additionally, we evaluate variants of MR-TCN on a Field-Programmable Gate Array (FPGA) platform across a diverse range of IVN traffic (i.e., CAN CC, CAN FD, and Automotive Ethernet), demonstrating its suitability in real-world applications.
Wouter Hellemans, Laurens Le Jeune, Md Masoom Rabbani, Bart Preneel, Nele Mentens
IEEE Trans. Intell. Transp. Syst.3
2023 Yes we CAN!: Towards bringing security to legacy-restricted Controller Area Networks. A review
abstract
With the demand for advanced functionality such as autonomous driving, the complexity and connectivity of modern vehicles have faced an overwhelming expansion in recent years. Although the numerous interfaces pave the way for a better user experience, recent research has demonstrated that they can also serve as an attack surface for cybercriminals. Therefore, researchers have been challenged to develop a wide variety of security solutions aiming to solve specific issues.
Wouter Hellemans, Md Masoom Rabbani, Bart Preneel, Nele Mentens
CF2
2023 PROVE: Provable remote attestation for public verifiability
abstract
The expanding attack surface of Internet of Things (IoT) systems calls for innovative security approaches to verify the reliability of IoT devices. To this end, Remote Attestation (RA) serves as a key mechanism that remotely detects the presence of malware in IoT devices. Typically, RA allows a centralized trusted Verifier to retrieve reliable evidence about the software integrity of an untrusted Prover. Existing RA schemes generally rely on the assumption that the Verifier and the Prover know each other and have pre-shared cryptographic keys during the bootstrap phase. However, these assumptions are not realistic to employ over commonly used event-driven IoT networks, in which the interacting parties do not know each other and do not communicate directly. This paper proposes PROVE, a novel protocol that allows many Verifiers to attest one or more Provers without pre-shared key material and without using public-key cryptography which is often not suitable for resource-constraint IoT devices. In particular, PROVE considers a realistic IoT system where devices adopt the publish/subscribe communication paradigm. In PROVE, the subscribers act as untrusted Verifiers and attest not only the firmware integrity of the publishers that act as untrusted Provers but also the authenticity of the received data originated from these publishers. We simulate PROVE on the Contiki emulator and demonstrate the scalability of the solution. We also validate PROVE through two hardware proof-of-concept implementations: PROVE and PROVE+, which rely on different cryptographic cores. The results show that a complete execution of the protocol takes 4605 ns and 324 ns for PROVE and PROVE+, respectively.
Edlira Dushku, Md Masoom Rabbani, Jo Vliegen, An Braeken, Nele Mentens
J. Inf. Secur. Appl.2
2022 FOCUS: Frequency Based Detection of Covert Ultrasonic Signals
Wouter Hellemans, Md Masoom Rabbani, Jo Vliegen, Nele Mentens
SEC2
2021 RESERVE: Remote Attestation of Intermittent IoT devices
abstract
Internet of Things (IoT) devices have enveloped our surroundings and have been increasingly deployed in many domains. Even though the IoT has generated unprecedented opportunities, the poorly secured design of IoT devices makes them an easy target for cyber attacks. Aimed at securing IoT devices, Remote Attestation (RA) is a security technique that identifies threat presence in IoT systems. Typically, RA is an atomic procedure that requires uninterrupted connectivity to execute. However, in energy harvesting context where intermittent IoT devices go into sleep mode immediately after regular operations, the atomic property is difficult to achieve. In this paper, we propose RESERVE, a novel lightweight RA protocol designed specifically for Intermittent IoT devices. RESERVE aims to improve the security of intermittent systems by detecting malware presence during online mode and guaranteeing with some probability software legitimacy during offline mode. In particular, RESERVE ensures trustworthiness by organizing the device's software into modules, and after regular operation each device attests as many modules as fit in its energy budget.
Md Masoom Rabbani, Edlira Dushku, Jo Vliegen, An Braeken, Nicola Dragoni, Nele Mentens
SenSys1
2021 FADIA: fairness-driven collaborative remote attestation
abstract
Internet of Things (IoT) technology promises to bring new value creation opportunities across all major industrial sectors. This will yield industries to deploy more devices into their networks. A key pillar to ensure the safety and security of the running services on these devices is remote attestation. Unfortunately,existing solutions fail to cope with the recent challenges raised by large IoT networks. In particular, the heterogeneity of the devices used in the network affects the performance of a remote attestation protocol. Another challenge in these networks is their dynamic nature: More IoT devices may be added gradually over time. This poses a problem in terms of key management in remote attestation.
Mohamad Mansouri, Wafa Ben Jaballah, Melek Önen, Md Masoom Rabbani, Mauro Conti
WISEC4
2020 SHeFU: Secure Hardware-Enabled Protocol for Firmware Updates
abstract
Firmware updates are often termed as a panacea to vulnerable Internet-of-Things (IoT) networks, as firmware updates can fix the exposed bugs and prevent them from being exploited in the future. However, a secure firmware update is a challenging task as IoT devices are often employed in unattended networks. Moreover, malicious updates of firmware in any of the devices of a network, or the non-execution of an update, can create havoc. Although security mechanisms like remote attestation (RA) are quite popular to identify malicious nodes in a network, they are costly in terms of computation/memory usage and communication overhead. To overcome these issues, we propose a “Secure Hardware-enabled Protocol for Firmware Updates (SHeFU)”. The aim of the proposed protocol is two-fold: 1) we obviate the need for remote attestation, and 2) we make sure that malicious nodes are isolated from benign nodes. Assuming a restricted threat model and network constellation, SHeFU ensures secure firmware updates and prevents compromised nodes from communicating with benign nodes in a network.
Md Masoom Rabbani, Jo Vliegen, Mauro Conti, Nele Mentens
ISCAS1
2020 Attestation-enabled secure and scalable routing protocol for IoT networks
Mauro Conti, Pallavi Kaliyar, Md Masoom Rabbani, Silvio Ranise
Ad Hoc Networks3
2020 SARA: Secure Asynchronous Remote Attestation for IoT Systems
abstract
Remote attestation has emerged as a valuable security mechanism which aims to verify remotely whether or not a potentially untrusted device has been compromised. The protocols of Remote attestation are particularly important for securing Internet of Things (IoT) systems which, due to the large number of interconnected devices and limited security protections, are susceptible to a wide variety of cyber attacks. To guarantee the integrity of a software running on a single device, remote attestation is usually executed as an uninterrupted procedure: at the attestation time, a device stops the normal operation and executes the attestation of the entire device without interruption. The remote attestation protocols that aim to attest a large number of devices also follow the assumption on uninterrupted execution: when a device attests its network neighbours, each device verified in the neighborhood suspends its normal operation until the attestation protocol is completed. To avoid unnecessary suspension of the normal operation of the devices, this paper proposes a novel Secure Asynchronous Remote Attestation (SARA) protocol that releases the constraint of synchronous interaction among devices. In particular, SARA is an attestation protocol that exploits asynchronous communication capabilities among IoT devices in order to attest a distributed IoT service executed by them. SARA verifies both that each IoT device is not compromised (device trustworthiness), and that the exchanged communication data have not maliciously influence the communicating devices (legitimate operations). By tracing the execution order of each service invocation of an asynchronous distributed service, SARA allows each service to collect accurately historical data of its interactions, and transmits asynchronously such historical data to other interacting services. We have implemented and validated SARA through a realistic simulation on the Contiki emulator that demonstrates the functionality and efficiency of our protocol. The results confirm the suitability of SARA for low-end devices.
Edlira Dushku, Md Masoom Rabbani, Mauro Conti, Luigi V. Mancini, Silvio Ranise
IEEE Trans. Inf. Forensics Secur.2
2019 SACHa: Self-Attestation of Configurable Hardware
abstract
Device attestation is a procedure to verify whether an embedded device is running the intended application code. This way, protection against both physical attacks and remote attacks on the embedded software is aimed for. With the wide adoption of Field-Programmable Gate Arrays or FPGAs, hardware also became configurable, and hence susceptible to attacks (just like software). In addition, an upcoming trend for hardware-based attestation is the use of configurable FPGA hardware. Therefore, in order to attest a whole system that makes use of FPGAs, the status of both the software and the hardware needs to be verified, without the availability of a tamper-resistant hardware module.In this paper, we propose a solution in which a prover core on the FPGA performs an attestation of the entire FPGA, including a self-attestation. This way, the FPGA can be used as a tamper-resistant hardware module to perform hardware-based attestation of a processor, resulting in a protection of the entire hardware/software system against malicious code updates.
Jo Vliegen, Md Masoom Rabbani, Mauro Conti, Nele Mentens
DATE2
2019 SHeLA: Scalable Heterogeneous Layered Attestation
abstract
This article proposes a novel mechanism for swarm attestation, i.e., the remote attestation (RA) of a multitude of interconnected devices, also called a swarm of devices. Classical RA protocols work with one prover and one verifier. Swarm attestation protocols assume that the devices in the swarm act both as verifier and prover in order to attest the software integrity of all the devices to a root verifier, typically in a spanning-tree topology. We propose “scalable heterogeneous layered attestation (SHeLA),” a novel RA technique for swarms. Our approach consists of introducing an additional edge layer in between the root verifier and the swarm devices. The edge layer consists of geographically spread devices with a larger computational power and storage capacity than the swarm devices. The main challenges we address are related to the scalability of the swarm, the availability or visibility of the nodes (especially when they are mobile), the heterogeneity of the devices with respect to the wireless communication protocol and interface, and the granularity of the attestation in terms of detecting the sanity of individual swarm devices. We build a proof-of-concept network that allows us to evaluate the computational delay and the resource overhead of the edge and swarm devices, and to perform a thorough security analysis.
Md Masoom Rabbani, Jo Vliegen, Jori Winderickx, Mauro Conti, Nele Mentens
IEEE Internet Things J.1
2018 SPLIT: A Secure and Scalable RPL routing protocol for Internet of Things
abstract
Due to recent notorious security threats, like Mirai-botnet, it is challenging to perform efficient data communication and routing in low power and lossy networks (LLNs) such as Internet of Things (IoT), in which huge data collection and processing are predictable. The Routing Protocol for low power and Lossy networks (RPL) is recently standardized as a routing protocol for LLNs. However, the lack of scalability and the vulnerabilities towards various security threats still pose a significant challenge in the broader adoption of RPL in LLNs.To address these challenges, we propose SPLIT, a secure and scalable RPL routing protocol for IoT networks. SPLIT effectively uses a lightweight remote attestation technique to ensure software integrity of network nodes. To avoid additional overhead caused by attestation messages, SPLIT piggybacks attestation process on the RPL's control messages. Thus, SPLIT enjoys the low energy consumption and scalability features of RPL protocol, which are essential in resource-constrained large scale networks such as IoT. The simulation results for different IoT scenarios show the effectiveness of SPLIT compared to the state-of-the-art in presence of different types of attacks, concerning metrics such as packet delivery ratio and energy consumption.
Mauro Conti, Pallavi Kaliyar, Md Masoom Rabbani, Silvio Ranise
WiMob3
2017 Toward secure and efficient attestation for highly dynamic swarms: poster
abstract
Remote Attestation (RA) has been proven to be a powerful security service to check the legitimacy of the software configuration (e.g., running software and data) of devices. In recent years, advances in trusted computing, made possible to extend the use of RA also to embedded and Internet of Things (IoT) devices. The massive scale of IoT deployments poses scalability challenges to RA. Recently, researchers proposed efficient protocols for collective network attestation, i.e., efficient attestation of a whole network of interconnected embedded devices; however, most of these solutions are either costly, or simply unsuitable for highly dynamic networks.
Moreno Ambrosin, Mauro Conti, Riccardo Lazzeretti, Md Masoom Rabbani, Silvio Ranise
WISEC4