EDBT 2026 Demo / reviewers in the wild / expert
Pallavi Sivakumaran
dblp:216/4321
· DBLP profile ↗
5ranked-venue papers
5as first author
3since 2021 · last 2023
0000-0002-7102-6318ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Uncovering Vulnerabilities of Bluetooth Low Energy IoT from Companion Mobile Apps with Ble-GuuideabstractIncreasingly, with embedded intelligence and control, IoT devices are being adopted faster than ever. However, the IoT landscape and its security implications are not yet fully understood. This paper seeks to shed light on this by focusing on a particular type of IoT devices, namely the ones using Bluetooth Low Energy (BLE). Our contributions are two-fold: First, we present Ble-Guuide, a framework for performing mobile app-centric security issue identification. We exploit Universally Unique Identifiers (UUIDs), which underpin data transmissions in BLE, to glean rich information regarding device functionality and the underlying security issues. We combine this with information from app descriptions and BLE libraries, to identify the corresponding security vulnerabilities in BLE devices and determine the security or privacy impact they could have depending on the device functionality. Second, we present a large-scale analysis of 17,243 free, BLE-enabled Android APKs, systematically crawled from the official Google Play store. By applying Ble-Guuide to this dataset, we uncover that more than 70% of these APKs contain at least one security vulnerability. We also obtain insights into the identified security vulnerabilities and their impact. Pallavi Sivakumaran, Chaoshun Zuo, Zhiqiang Lin 0001, Jorge Blasco Alís |
AsiaCCS | 1 |
| 2021 | argXtract: Deriving IoT Security Configurations via Automated Static Analysis of Stripped ARM Cortex-M BinariesabstractRecent high-profile attacks on the Internet of Things (IoT) have brought to the forefront the vulnerabilities in “smart” devices, and have revealed poor device configuration to be the root cause in many cases. This has resulted in IoT technologies and devices being subjected to numerous security analyses. For the most part, automated analyses have been confined to IoT hub or gateway devices, which tend to feature traditional operating systems such as Linux or VxWorks. However, most IoT peripherals, by their very nature of being resource-constrained, lacking traditional operating systems, implementing a wide variety of communication technologies, and (increasingly) featuring the ARM Cortex-M architecture, have only been the subject of smaller-scale analyses, typically confined to a certain class or brand of device. We bridge this gap with argXtract, a framework for performing automated static analysis of stripped Cortex-M binaries, to enable bulk extraction of security-relevant configuration data. Through a case study of 200+ Bluetooth Low Energy binaries targeting Nordic Semiconductor chipsets, as well as smaller studies against STMicroelectronics BlueNRG binaries and Nordic ANT binaries, argXtract has discovered widespread security and privacy issues in IoT, including minimal or no protection for data, weakened pairing mechanisms, and potential for device and user tracking. Pallavi Sivakumaran, Jorge Blasco Alís |
ACSAC | 1 |
| 2021 | Who's Accessing My Data? Application-Level Access Control for Bluetooth Low Energy
Pallavi Sivakumaran, Jorge Blasco Alís |
SecureComm (2) | 1 |
| 2019 | A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security Landscape
Pallavi Sivakumaran, Jorge Blasco Alís |
USENIX Security Symposium | 1 |
| 2018 | A Low Energy Profile: Analysing Characteristic Security on BLE PeripheralsabstractBluetooth Low Energy is a ubiquitous technology, with applications in the fitness, healthcare and smart home sectors, to name but a few. In this paper, we present an open-source Profiler for classifying the protection level of data residing on a BLE device. Preliminary results obtained by executing the tool against several devices show that some BLE devices allow unauthenticated reads and writes from third party devices. This could expose them to a number of attacks and compromise the privacy, or even the physical safety, of the device owner. Pallavi Sivakumaran, Jorge Blasco Alís |
CODASPY | 1 |