EDBT 2026 Demo / reviewers in the wild / expert
Morteza Safaei Pour
dblp:224/0816
· DBLP profile ↗
12ranked-venue papers
7as first author
7since 2021 · last 2024
0000-0003-1176-6274ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 3 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | EV Charging Infrastructure Discovery to Contextualize Its Deployment SecurityabstractElectric Vehicle Charging Stations (EVCSs) have been shown to be susceptible to remote exploitation due to manufacturer-induced vulnerabilities, demonstrated by recent attacks on this ecosystem. What is more alarming is that compromising these high-wattage IoT systems can be leveraged to perform coordinated oscillatory load attacks against the power grid which could lead to the instability of this critical infrastructure. In this paper, we investigate a previously sidelined aspect of EVCS security. We analyze the deployment security of EVCSs and highlight operator-induced vulnerabilities rendering the ecosystem exposed to remote intrusions. We create an advanced discovery technique that leverages Web interface artifacts to dynamically discover new charging station vendors. As a result, we uncover 33,320 charging station management systems in the wild. Consequently, we study the deployment security of the charging stations and identify that 28,046 EVCSs were found to be vulnerable to eavesdropping, and around 24% of the studied EVCSs are deployed with default configurations exposing the ecosystem to a Mirai-like attack vector. Aligned with this finding, we discover that the EVCS ecosystem has been targeted by nefarious IoT malware such as Mirai and its variants. This demonstrates that further security measures should be implemented by vendors and operators to ensure the security of this vital ecosystem. Consequently, we provide a comprehensive recommendation for securing the deployment of EVCSs. Khaled Sarieddine, Mohammad Ali Sayed, Chadi Assi, Ribal Atallah, Sadegh Torabi, Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2023 | Data-Centric Machine Learning Approach for Early Ransomware Detection and AttributionabstractResearchers have proposed a wide range of ransomware detection and analysis schemes. However, most of these efforts have focused on older families targeting Windows 7/8 systems. Hence there is a critical need to develop efficient solutions to tackle the latest threats, many of which may have relatively fewer samples to analyze. This paper presents a machine learning (ML) framework for early ransomware detection and attribution. The solution pursues a data-centric approach which uses a minimalist ransomware dataset and implements static analysis using portable executable (PE) files. Results for several ML classifiers confirm strong performance in terms of accuracy and zero-day threat detection. Aldin Vehabovic, Hadi Zanddizari, Nasir Ghani, Farooq Shaikh, Elias Bou-Harb, Morteza Safaei Pour, Jorge Crichigno |
NOMS | 6 |
| 2023 | Helium-based IoT Devices: Threat Analysis and Internet-scale ExploitationsabstractWith the explosive growth of resource-constrained smart devices and the widespread deployment of Internet-of-Things (IoT) devices, there is an ever-increasing demand for low-energy and cost-effective wireless communication solutions to serve a wide variety of systems and processes. To this end, blockchain-enabled Helium devices were conceived to enable Internet services and to support third-party IoT devices. This decentralized paradigm allows individuals and entities to freely engage, monetize and deploy wireless Helium hotspots, offering Internet coverage through piggy-backing packets via their existing network and Internet infrastructure (e.g., fiber optics at home). Currently, there are close to 1M operational Helium devices deployed in 189 countries, which are owned by 425K accounts. Given this evolving paradigm, in this paper, we take a first step to explore the plausible attack vectors which could potentially impact the confidentiality, integrity, and availability of such Helium hotspots. Along this vein, we then scrutinize 2.9 TB of one-way unsolicited Internet traffic arriving at 0.5M monitored dark IP addresses to identify 869,822 darknet events pertained to 6K Helium hotspots (as infected devices and DoS victims). By further leveraging active and passive methodologies coupled with public exploitation databases, we uncover medium to critical severity vulnerabilities attributed to 62K online Helium hotspots. Veronica Rammouz, Joseph Khoury, Dorde Klisura, Morteza Safaei Pour, Mostafa Safaei Pour, Claude Fachkha, Elias Bou-Harb |
WiMob | 4 |
| 2023 | A Comprehensive Survey of Recent Internet Measurement Techniques for Cyber SecurityabstractAs the Internet has transformed into a critical infrastructure, society has become more vulnerable to its security flaws. Despite substantial efforts to address many of these vulnerabilities by industry, government, and academia, cyber security attacks continue to increase in intensity, diversity, and impact. Thus, it becomes intuitive to investigate the current cyber security threats, assess the extent to which corresponding defenses have been deployed, and evaluate the effectiveness of risk mitigation efforts. Addressing these issues in a sound manner requires large-scale empirical data to be collected and analyzed via numerous Internet measurement techniques. Although such measurements can generate comprehensive and reliable insights, doing so encompasses complex procedures involving the development of novel methodologies to ensure accuracy and completeness. Therefore, a systematic examination of recently developed Internet measurement approaches for cyber security must be conducted to enable thorough studies that employ several vantage points, correlate multiple data sources, and potentially leverage past successful techniques for more recent issues. Unfortunately, performing such an examination is challenging, as the literature is highly scattered. In large part, this is due to each research effort only focusing on a small portion of the many constituent parts of the Internet measurement domain. Moreover, to the best of our knowledge, no studies have offered an in-depth examination of this critical research domain in order to promote future advancements. To bridge these gaps, we explore all pertinent facets of utilizing Internet measurement techniques for cyber security, ranging from threats within specific application domains to threats themselves. We provide a taxonomy of cyber security-related Internet measurement studies across two dimensions. One dimension relates to the many vertical layers (and components) of the Internet ecosystem, while the other relates to internal normal functions vs. the negative impact of external parties in the Internet and physical world. A comprehensive comparison of the gathered studies is also offered in terms of measurement technique, scope, measurement size, vantage size, and the analysis approach that was leveraged. Finally, a discussion of the roadblocks to performing effective Internet measurements and possible future research directions is elaborated. Morteza Safaei Pour, Christelle Nader, Kurt Friday, Elias Bou-Harb |
Comput. Secur. | 1 |
| 2022 | A Near Real-Time Scheme for Collecting and Analyzing IoT Malware Artifacts at ScaleabstractThe chronic proliferation of Internet of Things (IoT) botnet malware activities coupled with an unprecedented rise in security vulnerabilities convene a new world of opportunities for perpetrators and unveil a new set of hurdles in deriving relevant IoT malware intelligence. Such shortfall within the IoT paradigm exacerbates the capabilities for largely identifying the prevailing IoT malware threats, the origin of the IoT attacks, as well as, the security deficit associated with the IoT paradigm. Previous work has vastly studied IoT malware activities in the wild but has not profiled at a large scale malicious activities to collect in near real-time central IoT artifacts much-needed to understand and eventually elevate the security posture of the IoT ecosystem. Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb |
ARES | 2 |
| 2022 | HoneyComb: A Darknet-Centric Proactive Deception Technique For Curating IoT Malware Forensic ArtifactsabstractConventional IoT honeypots are known to suffer from scalability and management issues, while accumulating stringent costs. Further, their passive nature hinders the wide-scale gathering of much-needed IoT malware artifacts, impeding their measurements, analysis, and ultimately their use to infer and react to IoT maliciousness at large. To this end, in this work, we introduce HoneyComb, a proactive deception technique to curate IoT malware forensics by leveraging IoT scans captured on the darknet (i.e., Internet telescope). HoneyComb is built on the premise that we can position a large darknet network (i.e., comprising of 16.7 million IPs) as a large honeypot to interact with malware-infected IoT devices at scale. Such a large vantage point is capable of offering an incomparable hefty look into the IoT cyber security posture compared to the typical, much-restricted, currently-available IoT honeypots. In essence, the inferred IoT scans from the darknet along with the existing discrepancy in the validation algorithms of IoT malware stateless scanning modules, enable HoneyComb to initiate crafted deceiving packets (i.e., TCP SYN-ACK packets) to delude and interconnect with malware-infected IoT devices in the wild. During 48 hours of empirical measurements, the proposed scheme logged 1,432,518 interactions originating from 37,323 malware-infected IoT devices worldwide. Additionally, our findings revealed intriguing insights concerning the propagation behavior of IoT malware where 11,340 infected devices delivered the malware binaries using 1,398 unique URLs, whereas 2,114 used HexString dumping to drop their binaries, while the rest reported sensitive information (e.g., credentials) to their servers. Finally, while we observe that newly emerged IoT malware such as ZHTRAP is more capable in the takeover process due to its innovative techniques and offensive competencies, we frame HoneyComb as a complementary scheme, which would aid in addressing a number of evolving IoT-centric security endeavours, including large-scale malware attribution and C&C takedowns. Morteza Safaei Pour, Joseph Khoury, Elias Bou-Harb |
NOMS | 1 |
| 2021 | Sanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet MeasurementsabstractThe Internet-of-Things (IoT) paradigm at large continues to be compromised, hindering the privacy, dependability, security, and safety of our nations. While the operational security communities (i.e., CERTS, SOCs, CSIRT, etc.) continue to develop capabilities for monitoring cyberspace, tools which are IoT-centric remain at its infancy. To this end, we address this gap by innovating an actionable Cyber Threat Intelligence (CTI) feed related to Internet-scale infected IoT devices. The feed analyzes, in near real-time, 3.6TB of daily streaming passive measurements ( ≈ 1M pps) by applying a custom-developed learning methodology to distinguish between compromised IoT devices and non-IoT nodes, in addition to labeling the type and vendor. The feed is augmented with third party information to provide contextual information. We report on the operation, analysis, and shortcomings of the feed executed during an initial deployment period. We make the CTI feed available for ingestion through a public, authenticated API and a front-end platform. Morteza Safaei Pour, Dylan Watson, Elias Bou-Harb |
DSN | 1 |
| 2020 | On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild
Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Sagar Samtani, Jorge Crichigno, Nasir Ghani |
Comput. Secur. | 1 |
| 2019 | Data-driven Curation, Learning and Analysis for Inferring Evolving IoT Botnets in the WildabstractThe insecurity of the Internet-of-Things (IoT) paradigm continues to wreak havoc in consumer and critical infrastructure realms. Several challenges impede addressing IoT security at large, including, the lack of IoT-centric data that can be collected, analyzed and correlated, due to the highly heterogeneous nature of such devices and their widespread deployments in Internet-wide environments. To this end, this paper explores macroscopic, passive empirical data to shed light on this evolving threat phenomena. This not only aims at classifying and inferring Internet-scale compromised IoT devices by solely observing such one-way network traffic, but also endeavors to uncover, track and report on orchestrated "in the wild" IoT botnets. Initially, to prepare the effective utilization of such data, a novel probabilistic model is designed and developed to cleanse such traffic from noise samples (i.e., misconfiguration traffic). Subsequently, several shallow and deep learning models are evaluated to ultimately design and develop a multi-window convolution neural network trained on active and passive measurements to accurately identify compromised IoT devices. Consequently, to infer orchestrated and unsolicited activities that have been generated by well-coordinated IoT botnets, hierarchical agglomerative clustering is deployed by scrutinizing a set of innovative and efficient network feature sets. By analyzing 3.6 TB of recent darknet traffic, the proposed approach uncovers a momentous 440,000 compromised IoT devices and generates evidence-based artifacts related to 350 IoT botnets. While some of these detected botnets refer to previously documented campaigns such as the Hide and Seek, Hajime and Fbot, other events illustrate evolving threats such as those with cryptojacking capabilities and those that are targeting industrial control system communication and control services. Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Khaled B. Shaban, Abdelkarim Erradi |
ARES | 1 |
| 2019 | Theoretic derivations of scan detection operating on darknet traffic
Morteza Safaei Pour, Elias Bou-Harb |
Comput. Commun. | 1 |
| 2018 | Assessing Internet-wide Cyber Situational Awareness of Critical SectorsabstractIn this short paper, we take a first step towards empirically assessing Internet-wide malicious activities generated from and targeted towards Internet-scale business sectors (i.e., financial, health, education, etc.) and critical infrastructure (i.e., utilities, manufacturing, government, etc.). Facilitated by an innovative and a collaborative large-scale effort, we have conducted discussions with numerous Internet entities to obtain rare and private information related to allocated IP blocks pertaining to the aforementioned sectors and critical infrastructure. To this end, we employ such information to attribute Internet-scale maliciousness to such sectors and realms, in an attempt to provide an in-depth analysis of the global cyber situational posture. We draw upon close to 16.8 TB of darknet data to infer probing activities (typically generated by malicious/infected hosts) and DDoS backscatter, from which we distill IP addresses of victims. By executing week-long measurements, we observed an alarming number of more than 11,000 probing machines and 300 DDoS attack victims hosted by critical sectors. We also generate rare insights related to the maliciousness of various business sectors, including financial, which typically do not report their hosted and targeted illicit activities for reputation-preservation purposes. While we treat the obtained results with strict confidence due to obvious sensitivity reasons, we postulate that such generated cyber threat intelligence could be shared with sector/critical infrastructure operators, backbone networks and Internet service providers to contribute to the overall threat remediation objective. Martin Husák, Nataliia Neshenko, Morteza Safaei Pour, Elias Bou-Harb, Pavel Celeda |
ARES | 3 |
| 2018 | Implications of Theoretic Derivations on Empirical Passive Measurements for Effective Cyber Threat Intelligence GenerationabstractCyber space continues to be threatened by various debilitating attacks. In this context, executing passive measurements by analyzing Internet-scale, one- way darknet traffic has proven to be an effective approach to shed the light on Internet-wide maliciousness. While typically such measurements are solely conducted from the empirical perspective on already deployed darknet IP spaces using off-the-shelf Intrusion Detection Systems (IDS), their multidimensional theoretical foundations, relations and implications continue to be obscured. In this paper, we take a first step towards comprehending the relation between attackers' behaviors, the width of the darknet vantage points, the probability of detection and the minimum detection time. We perform stochastic modeling, derivation, validation, inter-correlation and analysis of such parameters to provide numerous insightful inferences, such as the most effective IDS and the most suitable darknet IP space, given various attackers' activities in the presence of detection time/probability constraints. One of the outcomes suggests that the widely-deployed Bro IDS is ideal for inferring slow, stealthy probing activities by leveraging passive measurements. Further, the results do not recommend deploying the Snort IDS when the available darknet IP space is relatively small, which is a typical scenario when darknets are operated and employed on organizational sub-networks. We concur that the generated derivations and mathematical relations put forward a first-of-akind formal and an accurate characterization of darknet-centric notions, which possess significant implications on Internet and passive measurements. This is especially factual with the advent of evolving paradigms such as IPv6 deployments and the proliferation of highly-distributed, orchestrated, large-scale and stealthy probing botnets. Morteza Safaei Pour, Elias Bou-Harb |
ICC | 1 |