EDBT 2026 Demo / reviewers in the wild / expert
Nils Ole Tippenhauer
dblp:32/7125
· DBLP profile ↗
55ranked-venue papers
9as first author
20since 2021 · last 2026
0000-0001-8424-2602ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 6 first-author · 15 since 2021Computer networks · 8 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pitfalls for Security Isolation in Multi-CPU Systems
Simeon Hoffmann, Nils Ole Tippenhauer |
NDSS | 2 |
| 2025 | PreFence: A Fine-Grained and Scheduling-Aware Defense Against Prefetching-Based AttacksabstractSpeculative loading of memory, called hardware prefetching, is common in modern CPUs and may cause microarchitectural side-channel vulnerabilities. As prior work has shown, prefetching can be exploited to bypass process isolation and leak secrets. However, to this date, no effective and efficient countermeasure has been presented that secures software on affected systems. Often, disabling prefetching permanently is considered the only reasonable defense, despite the significant performance penalties this entails.In this work, we propose PreFence, a fine-grained and scheduling-aware defense against prefetching-based attacks for any platform where the prefetcher can be disabled. PreFence extends the process scheduler to be aware of security requirements of individual processes and to manage the prefetcher’s state to protect against malicious parallel processes, even on SMT-enabled platforms. This allows us to efficiently disable the prefetcher only during security-critical operations, with a single system call. Library and application developers can protect their code with minimal changes, and users can protect entire legacy applications using a wrapper program.We implement our countermeasure for an x86 64 and an ARM processor. We evaluate PreFence on two attacks from prior work and find that it reliably stops prefetch leakage with low performance overhead (less than 3%) on the vulnerable functions. In addition, we observe that PreFence causes only negligible performance impact when no security-relevant code is executed. Finally, we evaluate the performance of a real-world web-server application that uses PreFence to protect security-critical code for HTTPS handling. Compared to disabling the prefetcher permanently, we find that our countermeasure allows the application to significantly benefit from the prefetcher (running up to 15.8% (Intel) and 7.2% (ARM) faster on average), while at the same time achieving the same security. Till Schlüter, Nils Ole Tippenhauer |
EuroS&P | 2 |
| 2025 | GDMA: Fully Automated DMA Rehosting via Iterative Type Overlays
Tobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner, Daniel Klischies, Felix Buchmann, Nils Ole Tippenhauer, Thorsten Holz, Marius Muench |
USENIX Security Symposium | 7 |
| 2024 | Transparent TSN for Agnostic End-hosts via P4-based Traffic Characterization at SwitchesabstractMission-critical networks currently face a transition from legacy network protocols to advanced time-sensitive networking (TSN) standards. TSN guarantees reliable and deterministic communication using off-the-shelf Ethernet equipment. However, end-hosts must be TSN-aware and may pose security risks by arbitrarily over-allocating resources. Integrating central instances like a software-defined networking (SDN) controller into TSN networks to streamline network management presents a promising solution. This raises concerns regarding latency in communication between switches and the controller, as well as among switches themselves. To address this, we propose an approach that renders TSN transparent to end-hosts, eliminating the need for their involvement in resource reservations. We embed packet processing logic in P4-enabled TSN switches to characterize network traffic intelligently. This enables switches to allocate network resources autonomously and adjust real-time traffic handling mechanisms. Leveraging P4 storage structures introduces statefulness for traffic characterization computing within the inherently stateless P4 language. Our experiments demonstrate that our P4-enhanced switches require a minimal 0.014 MB of switch memory to distinguish between periodic and non-periodic traffic with an 80% precision while incurring a mere 0.2 ms forwarding latency per packet. Cornelia Brülhart, Nurefsan Sertbas Bülbül, Nils Ole Tippenhauer, Mathias Fischer 0001 |
LCN | 3 |
| 2024 | Enabling Physical Localization of Uncooperative Cellular DevicesabstractIn cellular networks, authorities may need to physically locate user devices to track criminals or illegal equipment. This process involves authorized agents tracing devices by monitoring uplink signals with cellular operator assistance. However, tracking uncooperative uplink signal sources remains challenging, even for operators and authorities. Three key challenges persist for fine-grained localization: i) devices must generate sufficient, consistent uplink traffic over time, ii) target devices may transmit uplink signals at very low power, and iii) signals from cellular repeaters may hinder localization of the target device. While these challenges pose significant practical obstacles to localization, they have been largely overlooked in existing research. Taekkyung Oh, Sangwook Bae, Junho Ahn, Yonghwa Lee, Tuan Dinh Hoang, Min Suk Kang, Nils Ole Tippenhauer, Yongdae Kim |
MobiCom | 7 |
| 2023 | FetchBench: Systematic Identification and Characterization of Proprietary PrefetchersabstractPrefetchers speculatively fetch memory using predictions on future memory use by applications. Different CPUs may use different prefetcher types, and two implementations of the same prefetcher can differ in details of their characteristics, leading to distinct runtime behavior. For a few implementations, security researchers showed through manual analysis how to exploit specific prefetchers to leak data. Identifying such vulnerabilities required tedious reverse-engineering, as prefetcher implementations are proprietary and undocumented. So far, no systematic study of prefetchers in common CPUs is available, preventing further security assessment. Till Schlüter, Amit Choudhari, Lorenz Hetterich, Leon Trampert, Hamed Nemati, Ahmad Ibrahim 0002, Michael Schwarz 0001, Christian Rossow, Nils Ole Tippenhauer |
CCS | 9 |
| 2023 | White-Box Concealment Attacks Against Anomaly Detectors for Cyber-Physical Systems
Alessandro Erba 0001, Nils Ole Tippenhauer |
DIMVA | 2 |
| 2023 | Get Your Cyber-Physical Tests Done! Data-Driven Vulnerability Assessment of Robotic Aerial VehiclesabstractThe rapid growth of robotic aerial vehicles (RAVs) has attracted extensive interest in numerous public and civilian applications, from flying drones to quadrotors. Security of RAV systems is posting greater challenges as RAV controller software becomes more complex and exposes a growing attack surface. Memory isolation techniques, which virtually separate the memory space and conduct hardware-based memory access control, are believed to prevent the attacker from compromising the entire system by exploiting one memory vulnerability. In this paper, we propose Ares, a new variable-level vulnerability assessment framework to explore deeper bugs from a combined cyber-physical perspective. We present a data-driven method to illustrate that, despite state-of-the-art memory isolation efforts, RAV systems are still vulnerable to physics-aware data manipulation attacks. We augment RAV control states with intermediate state variables by tracing accessible control parameters and vehicle dynamics within the same isolated memory region. With this expanded state variable space, we apply multivariate statistical analysis to investigate inter-variable quantitative data dependencies and search for vulnerable state variables. Ares utilizes a reinforcement learning-based method to show how an attacker can exploit memory bugs and parameter defects in a legitimate memory view and elaborately craft adversarial variable values to disrupt a RAV's safe operations. We demonstrate the feasibility and capability of Ares on the widely-used ArduPilot RAV framework. Our extensive empirical evaluation shows that the attacker can leverage these vulnerable state variables to achieve various RAV failures during real-time operation, and even evade existing defense solutions. Aolin Ding, Amin Hass, Nils Ole Tippenhauer, Shiqing Ma, Saman A. Zonouz |
DSN | 4 |
| 2023 | FieldFuzz: In Situ Blackbox Fuzzing of Proprietary Industrial Automation Runtimes via the NetworkabstractNetworked Programmable Logic Controllers (PLCs) are proprietary industrial devices utilized in critical infrastructure that execute control logic applications in complex proprietary runtime environments that provide standardized access to the hardware resources in the PLC. These control applications are programmed in domain-specific IEC 61131-3 languages, compiled into a proprietary binary format, and process data provided via industrial protocols. Control applications present an attack surface threatened by manipulated traffic. For example, remote code injection in a control application would directly allow to take over the PLC, threatening physical process damage and the safety of human operators. However, assessing the security of control applications is challenging due to domain-specific challenges and the limited availability of suitable methods. Network-based fuzzing is often the only way to test such devices but is inefficient without guidance from execution tracing. Andrei Bytes, Prashant Hari Narayan Rajput, Constantine Doumanidis, Michail Maniatakos, Jianying Zhou 0001, Nils Ole Tippenhauer |
RAID | 6 |
| 2023 | Time sensitive networking security: issues of precision time protocol and its implementationabstractAbstract Time Sensitive Networking (TSN) will be an integral component of industrial networking. Time synchronization in TSN is provided by the IEEE-1588, Precision Time Protocol (PTP) protocol. The standard, dating back to 2008, marginally addresses security aspects, notably not encompassing the frames designed for management purposes (Type Length Values or TLVs). In this work we show that the TLVs can be abused by an attacker to reconfigure, manipulate, or shut down time synchronization. The effects of such an attack can be serious, ranging from interruption of operations to actual unintended behavior of industrial devices, possibly resulting in physical damages or even harm to operators. The paper analyzes the root causes of this vulnerability, and provides concrete examples of attacks leveraging it to de-synchronize the clocks, showing that they can succeed with limited resources, realistically available to a malicious actor. Davide Berardi, Nils Ole Tippenhauer, Andrea Melis 0001, Marco Prandini, Franco Callegati |
Cybersecur. | 2 |
| 2022 | Identifying Near-Optimal Single-Shot Attacks on ICSs with Limited Process Knowledge
Herson Esquivel-Vargas, John H. Castellanos, Marco Caselli, Nils Ole Tippenhauer, Andreas Peter 0001 |
ACNS | 4 |
| 2022 | Assessing Model-free Anomaly Detection in Industrial Control Systems Against Generic Concealment AttacksabstractIn recent years, a number of model-free process-based anomaly detection schemes for Industrial Control Systems (ICS) were proposed. Model-free anomaly detectors are trained directly from process data and do not require process knowledge. They are validated based on a set of public data with limited attacks present. As result, the resilience of those schemes against general concealment attacks is unclear. In addition, no structured discussion on the properties verified by the detectors exists. Alessandro Erba 0001, Nils Ole Tippenhauer |
ACSAC | 2 |
| 2022 | BLURtooth: Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low EnergyabstractBluetooth is a pervasive wireless technology specified in an open standard. The standard defines Bluetooth Classic (BT) for high-throughput wireless services and Bluetooth Low Energy (BLE) very low-power ones. The standard also specifies security mechanisms, such as pairing, session establishment, and cross-transport key derivation (CTKD). CTKD enables devices to establish BT and BLE security keys by pairing just once. CTKD was introduced in 2014 with Bluetooth 4.2 to improve usability. However, the security implications of CTKD were not studied carefully. Daniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne Rasmussen, Mathias Payer |
AsiaCCS | 2 |
| 2022 | Microarchitectural Leakage Templates and Their Application to Cache-Based Side ChannelsabstractThe complexity of modern processor architectures has given rise to sophisticated interactions among their components. Such interactions may result in potential attack vectors in terms of side channels, possibly available to userland exploits to leak secret data. Exploitation and countering of such side channels requires a detailed understanding of the target component. However, such detailed information is commonly unpublished for many CPUs. Ahmad Ibrahim 0002, Hamed Nemati, Till Schlüter, Nils Ole Tippenhauer, Christian Rossow |
CCS | 4 |
| 2022 | Hiding in Plain Sight? On the Efficacy of Power Side Channel-Based Control Flow Monitoring
Zahra Aref, Nils Ole Tippenhauer, Saman A. Zonouz |
USENIX Security Symposium | 4 |
| 2022 | Smooth Transition of Vehicles' Maximum Speed for Lane Detection based on Computer VisionabstractThis paper presents a prototype electric scooter designed to detect the driving lane via computer vision and automatically set the vehicular configuration. The electric scooter can drive on the pedestrian, bicycle, or car lanes. The government enforces maximum speeds on each lane for the electric scooter. Our prototype scooter would apply those regulations securely, with the help of a computer vision component. However, the safety of such a system is still part of the concern and research is going on the security and safety aspects of such vehicular systems. The maximum speed changes while the driver is riding the vehicle at the fastest possible speed could cause a safety hazard. To prevent that, we proposed to use the logarithmic speed reduction or acceleration. The results show that such an algorithm will smooth the transition between the maximum of the vehicle. Hamid Reza Ghaeini, Nils Ole Tippenhauer |
VTC Fall | 2 |
| 2022 | HADES-IoT: A Practical and Effective Host-Based Anomaly Detection System for IoT Devices (Extended Version)abstractInternet of Things (IoT) devices have become ubiquitous, with applications in many domains, including industry, transportation, and healthcare; these devices also have many household applications. The proliferation of IoT devices has raised security and privacy concerns, however many manufacturers neglect these aspects, focusing solely on the core functionality of their products due to the short time to market and the need to reduce product costs. Consequently, vulnerable IoT devices are left unpatched, allowing attackers to exploit them for various purposes, which include compromising the device users’ privacy or recruiting the devices to an IoT botnet. We present a practical and effective host-based anomaly detection system for IoT devices (HADES-IoT) as a novel last line of defense. HADES-IoT has proactive detection capabilities that enable the execution of any malicious process to be stopped before it even starts. HADES-IoT provides tamper-proof protection and can be deployed on a wide range of Linux-based IoT devices. HADES-IoT’s main advantage is its low overhead, making it suitable for Linux-based IoT devices where state-of-the-art security solutions are infeasible due to their high-performance demands. We deployed HADES-IoT on seven IoT devices, where it demonstrated 100% effectiveness in the detection of IoT malware, including VPNFilter, IoT Reaper, and Mirai malware, while requiring only 5.5% (on average) of the available memory and consuming just negligible CPU resources. Dominik Breitenbacher, Ivan Homoliak, Yan Lin Aung, Yuval Elovici, Nils Ole Tippenhauer |
IEEE Internet Things J. | 5 |
| 2022 | Constrained Proximity Attacks on Mobile TargetsabstractProximity attacks allow an adversary to uncover the location of a victim by repeatedly issuing queries with fake location data. These attacks have been mostly studied in scenarios where victims remain static and there are no constraints that limit the actions of the attacker. In such a setting, it is not difficult for the attacker to locate a particular victim and quantifying the effort for doing so is straightforward. However, it is far more realistic to consider scenarios where potential victims present a particular mobility pattern. In this article, we consider abstract (constrained and unconstrained) attacks on services that provide location information on other users in the proximity. We derive strategies for constrained and unconstrained attackers, and show that when unconstrained they can practically achieve success with theoretically optimal effort. We then propose a simple yet effective constraint that may be employed by a proximity service (for example, running in the cloud or using a suitable two-party protocol) as a countermeasure to increase the effort for the attacker several orders of magnitude both in simulated and real-world cases. Xueou Wang, Xiaolu Hou, Ruben Rios, Nils Ole Tippenhauer, Martín Ochoa |
ACM Trans. Priv. Secur. | 4 |
| 2021 | Assessing the Use of Insecure ICS Protocols via IXP Network Traffic AnalysisabstractModern Industrial Control Systems (ICSs) allow remote communication through the Internet using industrial protocols that were not designed to work with external networks. To understand security issues related to this practice, prior work usually relies on active scans by researchers or services such as Shodan. While such scans can identify publicly open ports, they cannot identify legitimate use of insecure industrial traffic. In particular, source-based filtering in Network Address Translation or Firewalls prevent detection by active scanning, but do not ensure that insecure communication is not manipulated in transit.In this work, we compare Shodan-only analysis with largescale traffic analysis at a local Internet Exchange Point (IXP), based on sFlow sampling. This setup allows us to identify ICS endpoints actually exchanging industrial traffic over the Internet. Besides, we are able to detect scanning activities and what other type of traffic is exchanged by the systems (i.e., IT traffic). We find that Shodan only listed less than 2% of hosts that we identified as exchanging industrial traffic, and only 7% of hosts identified by Shodan actually exchange industrial traffic. Therefore, Shodan does not allow to understand the actual use of insecure industrial protocols on the Internet and the current security practices in ICS communications. We show that 75.6% of ICS hosts still rely on unencrypted communications without integrity protection, leaving those critical systems vulnerable to malicious attacks. Giovanni Barbieri, Mauro Conti, Nils Ole Tippenhauer, Federico Turrin |
ICCCN | 3 |
| 2021 | LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth Stacks
Jianliang Wu 0002, Daniele Antonioli, Mathias Payer, Nils Ole Tippenhauer, Dongyan Xu, Jing (Dave) Tian, Antonio Bianchi |
USENIX Security Symposium | 5 |
| 2020 | Constrained Concealment Attacks against Reconstruction-based Anomaly Detectors in Industrial Control SystemsabstractRecently, reconstruction-based anomaly detection was proposed as an effective technique to detect attacks in dynamic industrial control networks. Unlike classical network anomaly detectors that observe the network traffic, reconstruction-based detectors operate on the measured sensor data, leveraging physical process models learned a priori. Alessandro Erba 0001, Riccardo Taormina, Stefano Galelli, Marcello Pogliani, Michele Carminati, Stefano Zanero, Nils Ole Tippenhauer |
ACSAC | 7 |
| 2020 | BIAS: Bluetooth Impersonation AttackSabstractBluetooth (BR/EDR) is a pervasive technology for wireless communication used by billions of devices. The Bluetooth standard includes a legacy authentication procedure and a secure authentication procedure, allowing devices to authenticate to each other using a long term key. Those procedures are used during pairing and secure connection establishment to prevent impersonation attacks. In this paper, we show that the Bluetooth specification contains vulnerabilities enabling to perform impersonation attacks during secure connection establishment. Such vulnerabilities include the lack of mandatory mutual authentication, overly permissive role switching, and an authentication procedure downgrade. We describe each vulnerability in detail, and we exploit them to design, implement, and evaluate master and slave impersonation attacks on both the legacy authentication procedure and the secure authentication procedure. We refer to our attacks as Bluetooth Impersonation AttackS (BIAS).Our attacks are standard compliant, and are therefore effective against any standard compliant Bluetooth device regardless the Bluetooth version, the security mode (e.g., Secure Connections), the device manufacturer, and the implementation details. Our attacks are stealthy because the Bluetooth standard does not require to notify end users about the outcome of an authentication procedure, or the lack of mutual authentication. To confirm that the BIAS attacks are practical, we successfully conduct them against 31 Bluetooth devices (28 unique Bluetooth chips) from major hardware and software vendors, implementing all the major Bluetooth versions, including Apple, Qualcomm, Intel, Cypress, Broadcom, Samsung, and CSR. Daniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne Rasmussen |
SP | 2 |
| 2020 | Key Negotiation Downgrade Attacks on Bluetooth and Bluetooth Low EnergyabstractBluetooth (BR/EDR) and Bluetooth Low Energy (BLE) are pervasive wireless technologies specified in the Bluetooth standard. The standard includes key negotiation protocols used to generate long-term keys (during pairing) and session keys (during secure connection establishment). In this work, we demonstrate that the key negotiation protocols of Bluetooth and BLE are vulnerable to standard-compliant entropy downgrade attacks. In particular, we show how an attacker can downgrade the entropy of any Bluetooth session key to 1 byte, and of any BLE long-term key and session key to 7 bytes. Such low entropy values enable the attacker to brute-force Bluetooth long-term keys and BLE long-term and session keys, and to break all the security guarantees promised by Bluetooth and BLE. As a result of our attacks, an attacker can decrypt all the ciphertext and inject valid ciphertext in any Bluetooth and BLE network. Our key negotiation downgrade attacks are conducted remotely, do not require access to the victims’ devices, and are stealthy to the victims. As the attacks are standard-compliant, they are effective regardless of the usage of the strongest Bluetooth and BLE security modes (including Secure Connections), the Bluetooth version, and the implementation details of the devices used by the victims. We successfully attack 38 Bluetooth devices (32 unique Bluetooth chips) and 19 BLE devices from different vendors, using all the major versions of the Bluetooth standard. Finally, we present effective legacy compliant and non-legacy compliant countermeasures to mitigate our key negotiation downgrade attacks. Daniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne Rasmussen |
ACM Trans. Priv. Secur. | 2 |
| 2019 | Zero Residual Attacks on Industrial Control Systems and Stateful CountermeasuresabstractIn this paper, we discuss the practical implementation of stealthy attacks on industrial control systems. We start by reviewing the attacks proposed in prior works. Then, we offer Zero-Residual Attacks (ZeRA), which allow the attacker to launch stealthy attacks leveraging estimation of the stateful anomaly detector and matching of residuals as a fraction of actual estimation residual. To perform the zero residual attack, the attacker will require the use of two state estimators each for the physical system state and the detector system state, adding complexity that was so far not discussed. We implement ZeRA and demonstrate its efficacy. Then, we propose to use a Stateful Detector (SD) to precisely detect such stealthy attacks. We design and implement the SD detector. The obtained results from the performance evaluation demonstrate that we can detect stealthy attacks such as the ZeRA, with precision above 99%, sensitivity above 99%, and Matthews correlation coefficient above 0.98. Hamid Reza Ghaeini, Nils Ole Tippenhauer, Jianying Zhou 0001 |
ARES | 2 |
| 2019 | Hide and Seek: An Architecture for Improving Attack-Visibility in Industrial Control Systems
Jairo Alonso Giraldo, David I. Urbina, Alvaro A. Cárdenas, Nils Ole Tippenhauer |
ACNS | 4 |
| 2019 | HADES-IoT: A Practical Host-Based Anomaly Detection System for IoT DevicesabstractInternet of Things (IoT) devices have become ubiquitous and spread across many application domains including the industry, transportation, healthcare, and households. However, the proliferation of the IoT devices has raised the concerns about their security -- many manufacturers focus only on the core functionality of their products due to short time to market and low cost pressures, while neglecting security aspects. Moreover, there is no established or standardized method for measuring and ensuring the security of IoT devices. Consequently, vulnerabilities are left untreated, allowing attackers to exploit IoT devices for various purposes, such as compromising privacy, recruiting devices into a botnet, or misusing devices to perform cryptocurrency mining. In this paper, we present a practical Host-based Anomaly DEtection System for IoT (HADES-IoT) as a novel last line of defense. HADES-IoT has proactive detection capabilities, provides tamper-proof resistance, and can be deployed on a wide range of Linux-based IoT devices. The main advantage of HADES-IoT is its low performance overhead, which makes it suitable for the IoT domain, where state-of-the-art approaches cannot be applied due to their high-performance demands. We deployed HADES-IoT on seven IoT devices and demonstrated 100% effectiveness in the detection of current IoT malware such as VPNFilter and IoTReaper; while on average, requiring only 5.5% of available memory and causing only a low CPU load. Dominik Breitenbacher, Ivan Homoliak, Yan Lin Aung, Nils Ole Tippenhauer, Yuval Elovici |
AsiaCCS | 4 |
| 2019 | CPS-SPC 2019: Fifth Workshop on Cyber-Physical Systems Security and PrivaCyabstractCyber-Physical Systems (CPS) are becoming increasingly critical for the well-being of society (e.g., electricity generation and distribution, water treatment, implantable medical devices etc. ). While the convergence of computing, communications and physical control in such systems provides benefits in terms of efficiency and convenience, the attack surface resulting from this convergence poses unique security and privacy challenges. These systems represent the new frontier for cyber risk. CPS-SPC is an annual forum in its 5th edition this year, that aims to provide a focal point for the research community to begin addressing the security and privacy challenges of CPS in a comprehensive and multidisciplinary manner and, in tandem with other efforts, build a comprehensive research road map. Related Workshop Proceedings are available in the ACM DL at: https://dl.acm.org/citation.cfm?id=3338499 Nils Ole Tippenhauer, Avishai Wool |
CCS | 1 |
| 2019 | Detection of Threats to IoT Devices using Scalable VPN-forwarded HoneypotsabstractAttacks on Internet of Things (IoT) devices, exploiting inherent vulnerabilities, have intensified over the last few years. Recent large-scale attacks, such as Persirai, Hakai, etc. corroborate concerns about the security of IoT devices. In this work, we propose an approach that allows easy integration of commercial off-the-shelf IoT devices into a general honeypot architecture. Our approach projects a small number of heterogeneous IoT devices (that are physically at one location) as many (geographically distributed) devices on the Internet, using connections to commercial and private VPN services. The goal is for those devices to be discovered and exploited by attacks on the Internet, thereby revealing unknown vulnerabilities. For detection and examination of potentially malicious traffic, we devise two analysis strategies: (1) given an outbound connection from honeypot, backtrack into network traffic to detect the corresponding attack command that caused the malicious connection and use it to download malware, (2) perform live detection of unseen URLs from HTTP requests using adaptive clustering. We show that our implementation and analysis strategies are able to detect recent large-scale attacks targeting IoT devices (IoT Reaper, Hakai, etc.) with overall low cost and maintenance effort. Amit Tambe, Yan Lin Aung, Ragav Sridharan, Martín Ochoa, Nils Ole Tippenhauer, Asaf Shabtai, Yuval Elovici |
CODASPY | 5 |
| 2019 | Nearby Threats: Reversing, Analyzing, and Attacking Google's 'Nearby Connections' on Android
Daniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne Rasmussen |
NDSS | 2 |
| 2019 | PAtt: Physics-based Attestation of Control Systems
Hamid Reza Ghaeini, Raad Bahmani, Ferdinand Brasser, Luis Garcia 0001, Jianying Zhou 0001, Ahmad-Reza Sadeghi, Nils Ole Tippenhauer, Saman A. Zonouz |
RAID | 8 |
| 2019 | The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDR
Daniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne Rasmussen |
USENIX Security Symposium | 2 |
| 2018 | CPS-SPC 2018: Fourth Workshop on Cyber-Physical Systems Security and PrivaCyabstractCyber-Physical Systems (CPS) are becoming increasingly critical for the well-being of society (e.g., electricity generation and distribution, water treatment, implantable medical devices etc.). While the convergence of computing, communications and physical control in such systems provides benefits in terms of efficiency and convenience, the attack surface resulting from this convergence poses unique security and privacy challenges. These systems represent the new frontier for cyber risk. CPS-SPC is an annual forum in its 4th edition this year, that aims to provide a focal point for the research community to begin addressing the security and privacy challenges of CPS in a comprehensive and multidisciplinary manner and, in tandem with other efforts, build a comprehensive research road map. Awais Rashid, Nils Ole Tippenhauer |
CCS | 2 |
| 2018 | Location Proximity Attacks Against Mobile Targets: Analytical Bounds and Attacker Strategies
Xueou Wang, Xiaolu Hou, Ruben Rios, Per A. Hallgren, Nils Ole Tippenhauer, Martín Ochoa |
ESORICS (2) | 5 |
| 2018 | WADAC: Privacy-Preserving Anomaly Detection and Attack Classification on Wireless TrafficabstractIn this work, we address the problem of detecting application-layer attacks on nearby wireless devices. In particular, we assume that the detection scheme is limited to link-layer traffic (either because schemes such as WPA2 are used, and the key is unknown, or to preserve user privacy). Such a setting allows us to detect attacks in nearby third party networks that we are not associated with, unlike related work that relies on wireline taps to observe traffic. We propose and implement a framework consisting of an anomaly detection module (unsupervised), and an attack classification module that identifies a known set of attacks (supervised). We evaluate our prototype with experiments including a range of attacks. For example, we demonstrate that the anomaly detector detects Mirai C&C traffic by an IoT device (without training with Mirai). In addition, we detect that the Mirai infected device is attacking other devices with 96.1% accuracy. We show that our prototype can be applied to different wireless standards (such as 802.11 (WiFi) and 802.15 (Zigbee)) and detect attacks with an accuracy of 96%-99%. Ragav Sridharan, Rajib Ranjan Maiti, Nils Ole Tippenhauer |
WISEC | 3 |
| 2017 | Legacy-Compliant Data Authentication for Industrial Control System Traffic
John H. Castellanos, Daniele Antonioli, Nils Ole Tippenhauer, Martín Ochoa |
ACNS | 3 |
| 2017 | Practical Evaluation of Passive COTS Eavesdropping in 802.11b/n/ac WLAN
Daniele Antonioli, Sandra Deepthy Siby, Nils Ole Tippenhauer |
CANS | 3 |
| 2017 | Towards Formal Security Analysis of Industrial Control SystemsabstractWe discuss the use of formal modeling to discover potential attacks on Cyber-Physical systems, in particular Industrial Control Systems. We propose a general approach to achieve that goal considering physical-layer interactions, time and state discretization of the physical process and logic, and the use of suitable attacker profiles. We then apply the approach to model a real-world water treatment testbed using ASLan++ and analyze the resulting transition system using CL-AtSe, identifying four attack classes. To show that the attacks identified by our formal assessment represent valid attacks, we compare them against practical attacks on the same system found independently by six teams from industry and academia. We find that 7 out of the 8 practical attacks were also identified by our formal assessment. We discuss limitations resulting from our chosen level of abstraction, and a number of modeling shortcuts to reduce the runtime of the analysis. Marco Rocchetto, Nils Ole Tippenhauer |
AsiaCCS | 2 |
| 2017 | Link-Layer Device Type Classification on Encrypted Wireless Traffic with COTS Radios
Rajib Ranjan Maiti, Sandra Deepthy Siby, Ragav Sridharan, Nils Ole Tippenhauer |
ESORICS (2) | 4 |
| 2016 | Multi-receiver GPS spoofing detection: error models and realization
Kai Jansen, Nils Ole Tippenhauer, Christina Pöpper |
ACSAC | 2 |
| 2016 | Limiting the Impact of Stealthy Attacks on Industrial Control SystemsabstractWhile attacks on information systems have for most practical purposes binary outcomes (information was manipulated/eavesdropped, or not), attacks manipulating the sensor or control signals of Industrial Control Systems (ICS) can be tuned by the attacker to cause a continuous spectrum in damages. Attackers that want to remain undetected can attempt to hide their manipulation of the system by following closely the expected behavior of the system, while injecting just enough false information at each time step to achieve their goals. In this work, we study if attack-detection can limit the impact of such stealthy attacks. We start with a comprehensive review of related work on attack detection schemes in the security and control systems community. We then show that many of those works use detection schemes that are not limiting the impact of stealthy attacks. We propose a new metric to measure the impact of stealthy attacks and how they relate to our selection on an upper bound on false alarms. We finally show that the impact of such attacks can be mitigated in several cases by the proper combination and configuration of detection schemes. We demonstrate the effectiveness of our algorithms through simulations and experiments using real ICS testbeds and real ICS systems. David I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer, Junia Valente, Mustafa Amir Faisal, Justin Ruths, Richard Candell, Henrik Sandberg |
CCS | 4 |
| 2016 | On Attacker Models and Profiles for Cyber-Physical Systems
Marco Rocchetto, Nils Ole Tippenhauer |
ESORICS (2) | 2 |
| 2016 | CPDY: Extending the Dolev-Yao Attacker with Physical-Layer Interactions
Marco Rocchetto, Nils Ole Tippenhauer |
ICFEM | 2 |
| 2016 | Physical-layer integrity for wireless messages
Nils Ole Tippenhauer, Kasper Bonne Rasmussen, Srdjan Capkun |
Comput. Networks | 1 |
| 2016 | Advanced Security Testbed Framework for Wearable IoT DevicesabstractAnalyzing the security of Wearable Internet-of-Things (WIoT) devices is considered a complex task due to their heterogeneous nature. In addition, there is currently no mechanism that performs security testing for WIoT devices in different contexts. In this article, we propose an innovative security testbed framework targeted at wearable devices, where a set of security tests are conducted, and a dynamic analysis is performed by realistically simulating environmental conditions in which WIoT devices operate. The architectural design of the proposed testbed and a proof-of-concept, demonstrating a preliminary analysis and the detection of context-based attacks executed by smartwatch devices, are presented. Shachar Siboni, Asaf Shabtai, Nils Ole Tippenhauer, Yuval Elovici |
ACM Trans. Internet Techn. | 3 |
| 2015 | UWB rapid-bit-exchange system for distance boundingabstractDistance bounding protocols enable one device (the verifier) to securely establish an upper bound on its distance to another device (the prover). These protocols can be used for secure location verification and detection of relay attacks, even in presence of strong attackers. The rapid-bit-exchange is the core of distance bounding protocols---the verifier sends single bit challenges, which the prover is expected to answer with minimal and stable processing delay. Based on the measured round trip time of flight, the verifier calculates its upper bound to the prover. Although several aspects of distance bounding implementations have been discussed in the past, no full implementation of a wireless distance bounding system has been presented so far. Nils Ole Tippenhauer, Heinrich Luecken, Marc Kuhn, Srdjan Capkun |
WISEC | 1 |
| 2014 | Automatic Generation of Security Argument GraphsabstractGraph-based assessment formalisms have proven to be useful in the safety, dependability, and security communities to help stakeholders manage risk and maintain appropriate documentation throughout the system lifecycle. In this paper, we propose a set of methods to automatically construct security argument graphs, a graphical formalism that integrates various security-related information to argue about the security level of a system. Our approach is to generate the graph in a progressive manner by exploiting logical relationships among pieces of diverse input information. Using those emergent argument patterns as a starting point, we define a set of extension templates that can be applied iteratively to grow a security argument graph. Using a scenario from the electric power sector, we demonstrate the graph generation process and highlight its application for system security evaluation in our prototype software tool, Cyber SAGE. Nils Ole Tippenhauer, William G. Temple, An Hoa Vu, Binbin Chen 0001, David M. Nicol, Zbigniew T. Kalbarczyk, William H. Sanders |
PRDC | 1 |
| 2013 | Go with the flow: toward workflow-oriented security assessmentabstractIn this paper we advocate the use of workflow---describing how a system provides its intended functionality---as a pillar of cybersecurity analysis and propose a holistic workflow-oriented assessment framework. While workflow models are currently used in the area of performance and reliability assessment, these approaches are designed neither to assess a system in the presence of an active attacker, nor to assess security aspects such as confidentiality. On the other hand, existing security assessment methods typically focus on modeling the active attacker (e.g., attack graphs), but many rely on restrictive models that are not readily applicable to complex (e.g., cyber-physical or cyber-human) systems. Binbin Chen 0001, Zbigniew T. Kalbarczyk, David M. Nicol, William H. Sanders, Rui Tan 0001, William G. Temple, Nils Ole Tippenhauer, An Hoa Vu, David K. Y. Yau |
NSPW | 7 |
| 2013 | On Limitations of Friendly Jamming for ConfidentialityabstractWireless communication provides unique security challenges, but also enables novel ways to defend against attacks. In the past few years, a number of works discussed the use of friendly jamming to protect the confidentiality of the communicated data as well as to enable message authentication and access control. In this work, we analytically and experimentally evaluate the confidentiality that can be achieved by the use of friendly jamming, given an attacker with multiple receiving antennas. We construct a MIMO-based attack that allows the attacker to recover data protected by friendly jamming and refine the conditions for which this attack is most effective. Our attack shows that friendly jamming cannot provide strong confidentiality guarantees in all settings. We further test our attack in a setting where friendly jamming is used to protect the communication to medical implants. Nils Ole Tippenhauer, Luka Malisa, Aanjhan Ranganathan, Srdjan Capkun |
IEEE Symposium on Security and Privacy | 1 |
| 2012 | Toys communicating with LEDs: Enabling toy cars interactionabstractCommunication capabilities are becoming a popular feature for premium smart toys. However, the higher cost of such transmitters are limiting the widespread use to all consumer users. In this contribution, we demonstrate a cost-effective toy communication using LED-based visible light communication (VLC), where messages sent via VLC are i) displayed on a screen, or ii) passed from one node (like a car) to another in a multi-hop way. Nils Ole Tippenhauer, Domenico Giustiniano, Stefan Mangold |
CCNC | 1 |
| 2012 | Design and Implementation of a Terrorist Fraud Resilient Distance Bounding System
Aanjhan Ranganathan, Nils Ole Tippenhauer, Boris Skoric, Dave Singelée, Srdjan Capkun |
ESORICS | 2 |
| 2011 | On the requirements for successful GPS spoofing attacksabstractAn increasing number of wireless applications rely on GPS signals for localization, navigation, and time synchronization. However, civilian GPS signals are known to be susceptible to spoofing attacks which make GPS receivers in range believe that they reside at locations different than their real physical locations. In this paper, we investigate the requirements for successful GPS spoofing attacks on individuals and groups of victims with civilian or military GPS receivers. In particular, we are interested in identifying from which locations and with which precision the attacker needs to generate its signals in order to successfully spoof the receivers. We will show, for example, that any number of receivers can easily be spoofed to one arbitrary location; however, the attacker is restricted to only few transmission locations when spoofing a group of receivers while preserving their constellation. In addition, we investigate the practical aspects of a satellite-lock takeover, in which a victim receives spoofed signals after first being locked on to legitimate GPS signals. Using a civilian GPS signal generator, we perform a set of experiments and find the minimal precision of the attacker's spoofing signals required for covert satellite-lock takeover. Nils Ole Tippenhauer, Christina Pöpper, Kasper Bonne Rasmussen, Srdjan Capkun |
CCS | 1 |
| 2011 | Investigation of Signal and Message Manipulations on the Wireless Channel
Christina Pöpper, Nils Ole Tippenhauer, Boris Danev, Srdjan Capkun |
ESORICS | 2 |
| 2010 | Integrity Regions: Authentication through Presence in Wireless NetworksabstractDespite years of intensive research, the main deterrents of widely deploying secure communication between wireless nodes remains the cumbersome key setup process. In this paper, we address this problem and we introduce Integrity (I) regions, a novel security primitive that enables message authentication in wireless networks without the use of preestablished or precertified keys. Integrity regions are based on the verification of entity proximity through time-of-arrival ranging techniques. IRegions can be efficiently implemented with ultrasonic ranging, in spite of the fact that ultrasound ranging techniques are vulnerable to distance enlargement and reduction attacks. We further show how IRegions can be used for key establishment in mobile peer-to-peer wireless networks and we propose a novel automatic key establishment approach, largely transparent to users, by leveraging on IRegions and nodes' mobility. We analyze our proposals against a multitude of security threats and we validate our findings via extensive simulations. Srdjan Capkun, Mario Cagalj, Ghassan Karame, Nils Ole Tippenhauer |
IEEE Trans. Mob. Comput. | 4 |
| 2009 | ID-Based Secure Distance Bounding and Localization
Nils Ole Tippenhauer, Srdjan Capkun |
ESORICS | 1 |
| 2009 | Attacks on public WLAN-based positioning systemsabstractIn this work, we study the security of public WLAN-based positioning systems. Specifically, we investigate the Skyhook positioning system, available on PCs and used on a number of mobile platforms, including Apple's iPod touch and iPhone. By implementing and analyzing several kinds of attacks, we demonstrate that this system is vulnerable to location spoofing and location database manipulation. In both, the attacker can arbitrarily change the result of the localization at the victim device, by either impersonating remote infrastructure or by tampering with the service database. Our attacks can easily be replicated and we conjecture that--without appropriate countermeasures--public WLAN-based positioning should therefore be used with caution in safety-critical contexts. We further discuss several approaches for securing WLAN-based positioning systems. Nils Ole Tippenhauer, Kasper Bonne Rasmussen, Christina Pöpper, Srdjan Capkun |
MobiSys | 1 |