EDBT 2026 Demo / reviewers in the wild / expert
A. Selcuk Uluagac
dblp:46/1500 · also Arif Selcuk Uluagac
· DBLP profile ↗
103ranked-venue papers
5as first author
50since 2021 · last 2026
0000-0002-9823-3464ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 41 · 4 first-author · 13 since 2021Security and privacy · 41 · 25 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 6 since 2021Systems, architecture and hardware · 5 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems
Esteban Luques, Carlo Mazzocca, Güliz Seray Tuncay, A. Selcuk Uluagac |
EuroS&P | 4 |
| 2026 | Digital Forensic AI You Can Explain: A Case Study on Video Source Camera IdentificationabstractIn recent years, artificial intelligence (AI) has significantly impacted digital forensics, yet its broader deployment remains limited due to the difficulty of explaining AI decisions. Explainable AI (XAI) presents a promising solution to increase transparency and trust, but its application in digital forensics is still underexplored. In this work, we present a practical and structured explainable digital forensics AI (xDFAI) approach tailored to the forensic task of video source camera identification (VSCI). Our method enables forensic examiners to interpret the behavior of AI models, assess whether decisions are driven by intended logic or arise from random or content-dependent artifacts, and establish the integrity and reliability of explanations. We implement and evaluate this approach on two state-of-the-art VSCI models, providing step-by-step analysis of explanation quality, spatial consistency of high-impact features, and content dependence. Our results reveal that although models achieve strong classification accuracy, their explanations lack spatial stability and are impacted by video content, raising concerns about forensic reliability. To support reproducibility and future research, we provide an open-source implementation. This work underscores the potential of XAI to improve transparency in digital forensics and highlights the challenges of interpreting and presenting results. Our study takes an important step toward the operational deployment of xDFAI in multimedia forensics. Maryna Veksler, Kemal Akkaya, A. Selcuk Uluagac |
WACV | 3 |
| 2026 | Unveiling the Global Landscape of Android Security UpdatesabstractAndroid is the world's leading mobile operating system, with over three billion active devices. Detecting vulnerabilities and ensuring timely patch deployment are critical to maintaining security. The Android Open Source Project (AOSP) has enhanced the transparency of security updates through Security Patch Levels. However, challenges related to update speed and availability persist. In 2022, Google reported that half of the zero-day vulnerabilities discovered in the wild were variations of vulnerabilities that had already been patched. Recent research mainly highlights delays in update distribution, often attributing them to fragmentation and focusing primarily on flagship devices or limited time-frames. Our approach takes a device-centric perspective to investigate Android update patterns, analyzing 567K security update records from 2014 to 2024, covering 904 distinct devices from six key Original Equipment Manufacturers (OEMs) across 98 countries. Our extensive analysis revealed notable differences in update release timing across OEMs, device types, and regions. Our study also examines documented vulnerabilities and weaknesses, while assessing OEM compliance with Android security guidelines. Our study shows that$\sim$89.7% of vulnerabilities on unpatched Android devices are exploitable without user interaction and with low attack complexity. We also identified delays linked to fragmentation and OEM-specific challenges, and provide actionable insights for improvement. Haiyun Deng, Güliz Seray Tuncay, Abbas Acar, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Compact and Selective Disclosure for Verifiable CredentialsabstractSelf-Sovereign Identity (SSI) is a novel identity model that empowers individuals with full control over their data, enabling them to choose what information to disclose, with whom, and when. This paradigm is rapidly gaining traction worldwide, supported by numerous initiatives such as the European Digital Identity (EUDI) Regulation or Singapore's National Digital Identity (NDI). For instance, by 2026, the EUDI Regulation will enable all European citizens to seamlessly access services across Europe using Verifiable Credentials (VCs). A key feature of SSI is the ability to selectively disclose only specific claims within a credential, enhancing the privacy protection of the identity owner. This paper proposes a novel mechanism designed to achieve Compact and Selective Disclosure for VCs (CSD-JWT). Our method leverages a cryptographic accumulator to encode claims within a credential into a unique, compact representation. We implemented CSD-JWT as an open-source solution and extensively evaluated its performance under various conditions. CSD-JWT provides significant memory savings, lowering usage by up to 46% compared to the state-of-the-art. It also minimizes network overhead by producing remarkably smaller Verifiable Presentations (VPs), with size reduction from 27% to 93%. Such features make CSD-JWT especially well-suited for resource-constrained devices, including hardware wallets designed for managing credentials. Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac |
ACSAC | 4 |
| 2025 | Adaptive Solutions for DeFi: Leveraging T2EMA's Dynamic Oracle Protection
Haiyun Deng, Abdulhadi Sahin, Kemal Akkaya, A. Selcuk Uluagac |
ICBC | 4 |
| 2025 | Speak Up, I'm Listening: Extracting Speech from Zero-Permission VR Sensors
Derin Cayir, Reham Mohamed Aburas, Riccardo Lazzeretti, Marco Angelini, Abbas Acar, Mauro Conti, Z. Berkay Celik, A. Selcuk Uluagac |
NDSS | 8 |
| 2025 | Enhancing Cybersecurity Education with Artificial Intelligence ContentabstractArtificial Intelligence (AI) has become a fundamental tool for cybersecurity researchers and practitioners. It is frequently used to address major security problems such as supply chain attacks, ransomware threats, and social engineering. In this context, integrating AI into cybersecurity workflows requires incorporating AI-driven approaches into the educational training of the cybersecurity workforce. This paradigm shift in academic settings will introduce the necessary skills for cybersecurity professionals to operate modern AI-based systems. Yet, the current cybersecurity curriculum still suffers from the absence of AI resources, particularly the detailed understanding of the appropriate AI mechanisms. Such absence leaves skill gaps for future professionals and practitioners in the industry. To address this, we designed an academic lecture module on AI covering both theory and practice. Then, we taught the module across six cybersecurity courses in our institution. To assess the effectiveness of integrating AI materials into cybersecurity education, we collected data by presenting two surveys before and after the lecture (concluding 81 participants per survey). Specifically, we utilized widely accepted models for unbiased analysis of our data. Our experimental results show positive AI knowledge improvement by 30% of the participants, demonstrating the beneficial impact of the lecture. Then, we observed a high similarity score between the survey responses and the lecture content, reaching 84%. Moreover, our sentiment analysis results reflect positive feedback from the participants with a positive score of 0.50. Overall, our study serves as a reference for instructional designers for developing educational curricula aiming to integrate AI into cybersecurity education. Fernando Brito, Yassine Mekdad, Monique Ross, Mark A. Finlayson, A. Selcuk Uluagac |
SIGCSE (1) | 5 |
| 2025 | Real or virtual: a video conferencing background manipulation-detection systemabstractAbstract In the past few years, the popularity and wide use of video conferencing software enjoyed exponential growth in market size. This technology enables participants in different geographic regions to have a virtual face-to-face meeting. Additionally, it allows participants to utilize virtual backgrounds to hide their real environment with privacy concerns or to reduce distractions, particularly in professional settings. In scenarios where the users should not hide their actual locations, they may mislead other participants into assuming that the displayed virtual backgrounds are real. In this paper, we propose a new publicly-available dataset of virtual and real backgrounds in video conferencing software (e.g., Zoom, Google Meet, Microsoft Teams). The presented archive was evaluated by an exhaustive series of tests and scenarios using two well-known features extraction methods: CRSPAM1372 and six co-mat. The first verification scenario considers the case where the detector is unaware of manipulated frames (i.e., the forensically-edited frames are not part of the training set). A model trained on zoom frames that were tested with Google Meet frames can detect real background images from virtual ones in video conferencing software with 99.80% detection accuracy. Furthermore, it is possible to distinguish virtual from real backgrounds in videos created for videoconferencing software at a high detection rate of approximately 99.80%. According to our conclusions, the proposed method greatly enhanced the detection accuracy and resistance against diverse adversarial conditions, making it a reliable technique for classifying actual as opposed to virtual backgrounds in video communications. Given the described dataset provided and some preliminary experiments that we performed, we expect that it will lead to more future research in this domain. Ehsan Nowroozi, Yassine Mekdad, Mauro Conti, Simone Milani, A. Selcuk Uluagac |
Multim. Tools Appl. | 5 |
| 2025 | Benchmarking Selective Disclosure Mechanisms for Verifiable Credentials: A Systematic Comparison for Security and PrivacyabstractIn a world where digitalization isreshapingevery aspect of society, digital identity has become more crucial than ever to establish trust and accountability across all entities, whether human, organizational, or machine-based. Numerous initiatives are emerging worldwide, such as the United States mobile driver’s license (mDLs) and Singapore’s National Digital Identity (NDI). In May 2024, the European Union introduced Regulation 2024/1183, establishing the European Digital Identity Framework. By 2026, this framework will provide all European citizens with a European Digital Identity Wallet (EUDIW), allowing them to access both online and offline public and private services while maintaining full control over their data. Individuals can selectively disclose only the required information to access services. However, the current EUDIW design relies on Selective Disclosure for JSON Web Token (SD-JWT), which does not fully meet the privacy requirements outlined in the regulation. This paper presents a comprehensive comparison of the main selective disclosure mechanisms. Specifically, we identify relevant threat models, formalize associated security and privacy properties, and assess the extent to which existing mechanisms satisfy these properties in mitigating the identified threats. Furthermore, we introduce an open-source benchmark that evaluates multiple selective disclosure across key performance indicators, including computational latency, bandwidth consumption, and storage requirements. Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Ransomware Over Modern Web Browsers: A Novel Strain and a New Defense MechanismabstractRansomware is an increasingly prevalent form of malware targeting end-users, governments, and businesses. As it has evolved, adversaries added new capabilities to their arsenal. We propose a next-generation browser-based ransomware, RøB , which performs its malicious actions via web technologies, File System Access API (FSA) and WebAssembly (Wasm). RøB uses this API through the victims’ browsers; hence, it does not require the victims to download and install malicious binaries. We performed extensive evaluations with three different OSs, 23 file formats, 29 distinct directories, five cloud providers, and four antivirus solutions. Our evaluations show that RøB can encrypt various types of files in the local and cloud-integrated directories, external storage devices, and network-shared folders of victims. Our experiments also reveal that popular cloud solutions, Box Individual and Apple iCloud can be severely affected by RøB . Moreover, we conducted tests with commercial antivirus software such as AVG, Avast, Kaspersky, and Malware Bytes that perform sensitive directory and suspicious behavior monitoring against ransomware. We verified that RøB can evade these antivirus software and encrypt victim files. Moreover, existing ransomware detection solutions in the literature also cannot be a remedy against RøB due to its distinct features. Therefore, in this paper, we also propose RøBguard , a new detection system for RøB -like attacks. RøBguard monitors the web applications that use the FSA API via function hooking and uses a machine learning classifier to detect RøB -like attacks. We implemented a proof of concept version of RøBguard and our evaluation results show that RøBguard can detect RøB -like browser-based ransomware attacks effectively. We also provide future research directions that should be addressed in this domain. Harun Oz, Güliz Seray Tuncay, Ahmet Aris, Abbas Acar, Leonardo Babun, A. Selcuk Uluagac |
ACM Trans. Web | 6 |
| 2024 | X-Lock: A Secure XOR-Based Fuzzy Extractor for Resource Constrained Devices
Edoardo Liberati, Alessandro Visintin, Riccardo Lazzeretti, Mauro Conti, A. Selcuk Uluagac |
ACNS (1) | 5 |
| 2024 | Catch me if you can: Covert Information Leakage from Drones using MAVLink ProtocolabstractThe number of applications of unmanned aerial vehicles (UAVs) (aka drones) is rapidly expanding. However, the wireless and broadcast nature of communications between the drones and their operators (i.e., Ground control station (GCS)) presents a risk for this channel to be exploited by outsiders. Specifically, an attacker can abuse benign communications as a cover to leak sensitive drone data secretly to nearby adversaries within the transmission range of a drone. Therefore, in this paper, we investigate the threat of information leakage through MAVLink, a drone control protocol that is widely used in the majority of drone autopilot systems and is considered a de-facto standard. We show that multiple covert channels can be created in MAVLink by exploiting its lack of security mechanisms, default broadcast messages, and redundant features. We design and implement the novel covert channels on a realistic drone testbed in practical settings and assess their feasibility. Our extensive results demonstrate that attackers can effectively exfiltrate different types of sensitive data from drones with a high throughput via MAVLink-based covert channels in the presence of an active warden at the GCS. Finally, we provide an in-depth analysis of several countermeasures for MAVLink-based covert channels to improve the protocol's security. To the best of our knowledge, this is the first work exploiting the popular MAVLink protocol for covert communications and demonstrating how it can be manipulated by the adversary for secret communications over commodity drones. Maryna Veksler, Kemal Akkaya, A. Selcuk Uluagac |
AsiaCCS | 3 |
| 2024 | Exploring Jamming and Hijacking Attacks for Micro Aerial DronesabstractRecent advancements in drone technology have shown that commercial off-the-shelf Micro Aerial Drones are more effective than large-sized drones for performing flight missions in narrow environments, such as swarming, indoor navigation, and inspection of hazardous locations. Due to their deployments in many civilian and military applications, safe and reliable communication of these drones throughout the mission is critical. The Crazyflie ecosystem is one of the most popular Micro Aerial Drones and has the potential to be deployed worldwide. In this paper, we empirically investigate two interference attacks against the Crazy Real Time Protocol (CRTP) implemented within the Crazyflie drones. In particular, we explore the feasibility of experimenting two attack vectors that can disrupt an ongoing flight mission: the jamming attack, and the hijacking attack. Our experimental results demonstrate the effectiveness of such attacks in both autonomous and non-autonomous flight modes on a Crazyflie 2.1 drone. Finally, we suggest potential shielding strategies that guarantee a safe and secure flight mission. To the best of our knowledge, this is the first work investigating jamming and hijacking attacks against Micro Aerial Drones, both in autonomous and non-autonomous modes. Yassine Mekdad, Abbas Acar, Ahmet Aris, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, A. Selcuk Uluagac |
ICC | 7 |
| 2024 | DDoS Attack Detection and Mitigation in 5G Networks using P4 and SDNabstract5G is expected to support numerous Internet of Things (IoT) devices. However, the inherent vulnerabilities and limited resources of IoT devices make them susceptible to compromise and exploitation, potentially leading to Distributed Denial of Service (DDoS) attacks on 5G infrastructure from within. While conventional Intrusion Detection Systems (IDS) can assist, 5G’s unique protocols, such as the General Packet Radio Service (GPRS) Tunneling Protocol User Plane (GTP-U), pose challenges due to the inability to analyze packet headers. Therefore, we propose using Software-Defined Networking (SDN), Machine Learning (ML), and programmable switches that utilize the Programming Protocol-independent Packet Processors (P4) language to analyze GTP traffic on the fly for DDoS attack detection. Our framework enhances the efficiency of DDoS attack detection and mitigation, as demonstrated through evaluations on an actual 5G testbed using real datasets. Compared to an alternative solution that forwards GTP packets to the SDN controller, our method significantly reduces attack detection time while enhancing throughput on the SDN switch. Diana Pineda, Kemal Akkaya, Alexander Perez-Pons, A. Selcuk Uluagac, Abdulhadi Sahin |
LCN | 4 |
| 2024 | 50 Shades of Support: A Device-Centric Analysis of Android Security Updates
Abbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz, Ahmet Aris, A. Selcuk Uluagac |
NDSS | 6 |
| 2024 | EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks
Carlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca Montanari |
USENIX Security Symposium | 3 |
| 2024 | SoK: All You Need to Know About On-Device ML Model Extraction - The Gap Between Research and Practice
Tushar Nayan, Qiming Guo, Mohammed Alduniawi, Marcus Botacin, A. Selcuk Uluagac, Ruimin Sun |
USENIX Security Symposium | 5 |
| 2024 | Dissecting Privacy Perspectives of Websites Around the World: "Aceptar Todo, Alle Akzeptieren, Accept All..."
Aysun Ogut, Berke Turanlioglu, Doruk Can Metiner, Albert Levi, Cemal Yilmaz 0001, Orçun Çetin, A. Selcuk Uluagac |
USENIX Security Symposium | 7 |
| 2024 | The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern WebabstractThe web ecosystem is a fast-paced environment. In this dynamic landscape, new security features are offered one after another to enhance the security and robustness of web applications and the operations they handle. This paper focuses on a fragile but still in-use security feature, text-based CAPTCHAs, that had been wildly used by web applications in the past to protect against automated attacks such as credential stuffing and account hijacking. The paper first investigates what it takes to develop automated scanners that can solve previously unseen text-based CAPTCHAs. We evaluated the possibility of developing and integrating a pre-trained CAPTCHA solver in the automated web scanning process without using a significantly large training dataset. We also perform an analysis of the impact of such autonomous scanners on CAPTCHA-enabled websites. Our analysis shows that solvable text-based CAPTCHAs on login, contact, and comment pages of websites are not uncommon. In particular, we identified over 3,100 text-based CAPTCHA websites in critical sectors such as finance, government, and health with hundreds of thousands of users. We showed that a web scanner with a pre-trained solver could solve more than 20% of previously unseen CAPTCHAs in just one single attempt. This result is worrisome considering the substantial potential to autonomously run the operation across thousands of websites on a daily basis with minimal training. The findings suggest that the integration of autonomous scanning with pre-training and local optimization of models can significantly increase adversaries' asymmetric power to launch their attacks cheaper and faster. Behzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi, Viet Cuong Nguyen, Sajjad Arshad, A. Selcuk Uluagac, Amin Kharraz |
WWW | 7 |
| 2024 | (In)Security of File Uploads in Node.jsabstractFile upload is a critical feature incorporated by a myriad of web applications in an effort to enable users to share and manage their files conveniently. It has been used in many useful services such as file-sharing and social media. While file upload is an essential component of web applications, the lack of rigorous checks on the file name, type, and content of the uploaded files can result in security issues, often referred to as Unrestricted File Upload (UFU). In this study, we analyze the (in)security of popular file upload libraries and real-world applications in the Node.js ecosystem. To automate our analysis, we propose and implement NodeSEC- a tool designed to analyze file upload insecurities in Node.js applications and libraries. NodeSEC generates unique payloads and thoroughly evaluates the application's file upload security against 13 distinct UFU-type attacks. Utilizing NodeSEC, we analyze the most popular file upload libraries and real-world applications in the Node.js ecosystem. Our analysis results reveal that some real-world web applications are vulnerable to UFU attacks and disclose serious security bugs in file upload libraries. As of this writing, we received 19 CVEs and two US-CERT cases for the security issues that we reported. Our findings provide strong evidence that dynamic features of Node.js applications introduce security shortcomings and that web developers should be cautious when implementing file upload features in their applications. Finally, combining our responsible disclosure experience and root cause analysis, we identified the main causes of significant security weaknesses in file uploads in Node.js. Harun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay, Amin Kharraz, A. Selcuk Uluagac |
WWW | 6 |
| 2024 | A review of on-device machine learning for IoT: An energy perspective
Nazli Tekin, Ahmet Aris, Abbas Acar, A. Selcuk Uluagac, Vehbi C. Gungor |
Ad Hoc Networks | 4 |
| 2024 | Formal threat analysis of machine learning-based control systems: A study on smart healthcare systems
Nur Imtiazul Haque, Mohammad Ashiqur Rahman, A. Selcuk Uluagac |
Comput. Secur. | 3 |
| 2024 | D-LNBot: A Scalable, Cost-Free and Covert Hybrid Botnet on Bitcoin's Lightning NetworkabstractWhile various covert botnets were proposed in the past, they still lack complete anonymization for their servers/botmasters or suffer from slow communication between the botmaster and the bots. In this paper, we first propose a new generation hybrid botnet that covertly and efficiently communicates over Bitcoin Lightning Network (LN), called LNBot. Exploiting various anonymity features of LN, we show the feasibility of a scalable two-layer botnet which completely anonymizes the identity of the botmaster. In the first layer, the botmaster anonymously sends the commands to the command and control (C&C) servers through regular LN payments. Specifically, LNBot allows botmaster's commands to be sent in the form of surreptitious multi-hop LN payments, where the commands are either encoded with the payments or attached to the payments to provide covert communications. In the second layer, C&C servers further relay those commands to the bots in their mini-botnets to launch any type of attacks to victim machines. We further improve on this design by introducing D-LNBot; a distributed version of LNBot that generates its C&C servers by infecting users on the Internet and forms the C&C connections by opening channels to the existing nodes on LN. In contrary to the LNBot, the whole botnet formation phase is distributed and the botmaster is never involved in the process. By utilizing Bitcoin's Testnet and the new message attachment feature of LN, we show that D-LNBot can be run for free and commands are propagated faster to all the C&C servers compared to LNBot. We presented proof-of-concept implementations for both LNBot and D-LNBot on the actual LN and extensively analyzed their delay and cost performance. Finally, we also provide and discuss a list of potential countermeasures to detect LNBot and D-LNBot activities and minimize their impacts. Ahmet Kurt, Enes Erdin, Kemal Akkaya, A. Selcuk Uluagac, Mumin Cebe |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Resisting Deep Learning Models Against Adversarial Attack Transferability via Feature RandomizationabstractIn the past decades, the rise of artificial intelligence has given us the capabilities to solve the most challenging problems in our day-to-day lives, such as cancer prediction and autonomous navigation. However, these applications might not be reliable if not secured against adversarial attacks. In addition, recent works demonstrated that some adversarial examples are transferable across different models. Therefore, it is crucial to avoid such transferability via robust models that resist adversarial manipulations. In this paper, we propose a feature randomization-based approach that resists eight adversarial attacks targeting deep learning models in the testing phase. Our novel approach consists of changing the training strategy in the target network classifier and selecting random feature samples. We consider the attacker with a Limited-Knowledge and Semi-Knowledge conditions to undertake the most prevalent types of adversarial attacks. We evaluate the robustness of our approach using the well-known UNSW-NB15 datasets that include realistic and synthetic attacks. Afterward, we demonstrate that our strategy outperforms the existing state-of-the-art approach, such as the Most Powerful Attack, which consists of fine-tuning the network model against specific adversarial attacks. Further, we demonstrate the practicality of our approach using the VIPPrint dataset through a comprehensive set of experiments. Finally, our experimental results show that our methodology can secure the target network and resists adversarial attack transferability by over 60%. Ehsan Nowroozi, Mohammadreza Mohammadi, Pargol Golmohammadi, Yassine Mekdad, Mauro Conti, A. Selcuk Uluagac |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | SHATTER: Control and Defense-Aware Attack Analytics for Activity-Driven Smart Home SystemsabstractModern smart home control systems utilize realtime occupancy and activity monitoring to ensure control efficiency, occupants' comfort, and optimal energy consumption. Moreover, adopting machine learning-based anomaly detection models (ADMs) enhances security and reliability. However, sufficient system knowledge allows adversaries/attackers to alter sensor measurements through stealthy false data injection (FDI) attacks. Although ADMs limit attack scopes, the availability of information like occupants' location, conducted activities, and alteration capability of smart appliances increase the attack surface. Therefore, performing an attack space analysis of modern home control systems is crucial to design robust defense solutions. However, state-of-the-art analyzers do not consider contemporary control and defense solutions and generate trivial attack vectors. To address this, we propose a control and defense-aware novel attack analysis framework for a modern smart home control system, efficiently extracting ADM rules. We verify and validate our framework using a state-of-the-art dataset and a prototype testbed. Nur Imtiazul Haque, Maurice Ngouen, Mohammad Ashiqur Rahman, A. Selcuk Uluagac, Laurent Njilla |
DSN | 4 |
| 2023 | Forensic Analysis of Cryptojacking in Host-Based Docker Containers Using HoneypotsabstractBlockchain-based cryptocurrencies have transformed financial transactions and created opportunities to profit from generating new coins through cryptomining. This has led to cybercriminals stealthily using their victim's computational power and resources for their own profit. Recent trends point to an increase in cryptojacking malware targeting devices with greater processing power such as host-based docker engines for faster and greater profit. In our study, we perform a forensic analysis for detecting cryptojacking (i.e., unauthorized cryptomining) in Docker containers using honeypots. Then, we present countermeasures for securing host-based Docker containers. In addition, we propose an approach for monitoring host-based Docker containers for cryptojacking detection. To the best of our knowledge, this is the first study investigating cryptojacking detection with the use of a honeypot system. Our results reveal that host resource usage and network traffic are the key indicators of possible unauthorized cryptomining in Docker containers. Javier Franco, Abbas Acar, Ahmet Aris, A. Selcuk Uluagac |
ICC | 4 |
| 2023 | RøB: Ransomware over Modern Web Browsers
Harun Oz, Ahmet Aris, Abbas Acar, Güliz Seray Tuncay, Leonardo Babun, A. Selcuk Uluagac |
USENIX Security Symposium | 6 |
| 2023 | A survey on security and privacy issues of UAVs
Yassine Mekdad, Ahmet Aris, Leonardo Babun, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, A. Selcuk Uluagac |
Comput. Networks | 7 |
| 2023 | Feasibility Analysis for Sybil Attacks in Shard-Based Permissionless BlockchainsabstractCommittee-based permissionless blockchain approaches overcome single leader consensus protocols’ scalability issues by partitioning the outstanding transaction set into shards and selecting multiple committees to process these transactions in parallel. However, by design, shard-based blockchain solutions are vulnerable to Sybil attacks. An adversary with enough computational/hash power can easily manipulate the consensus protocol by generating multiple valid node identifiers/IDs (i.e., multiple Sybil committee members).Despite the straightforward nature of these attacks, they have not been systematically investigated. This article fills this research gap by analyzing Sybil attacks in shard-based consensus of proof-of-work blockchain systems. Specifically, we provide a detailed analysis for Elastico, one of the prominent shard-based blockchain models. We show that the proof-of-work technique used for ID generation in the initial phase of such protocols is vulnerable to Sybil attacks when an adversary (could be a group of colluding nodes) possesses enough hash power. We analytically derive conditions for two different Sybil attacks and perform numerical simulations to validate our theoretical results under various parameters. Further, we utilize the BlockSim simulator to validate our mathematical computation, and results confirm the correctness of the analysis. Tayebeh Rajab, Alvi Ataur Khalil, Mohammad Hossein Manshaei, Mohammad Ashiqur Rahman, Mohammad Dakhilalian, Maurice Ngouen, Murtuza Jadliwala, A. Selcuk Uluagac |
Distributed Ledger Technol. Res. Pract. | 8 |
| 2023 | Ivycide: Smart Intrusion Detection System Against E-IoT Driver ThreatsabstractThe rise of Internet of Things (IoT) devices has led to the proliferation of smart environments worldwide. Although commodity IoT devices are employed by ordinary end users, complex environments, such as smart buildings, government, or private offices, or conference rooms require customized and highly reliable IoT solutions. Enterprise IoT (E-IoT) connect such environments to the Internet and are professionally managed solutions usually offered by dedicated vendors As E-IoT systems require specialized training, closed-source software, and proprietary equipment to deploy. In effect, E-IoT systems present an unprecedented, under-researched, and unexplored threat vector for an attacker. In this work, we focus on E-IoT drivers, software modules used to integrate devices into E-IoT systems, as an attack mechanism. We first present PoisonIvy, a series of generalized proof-of-concept attacks used to demonstrate that an attacker can use a malicious driver to perform denial-of-service attacks, gain remote control, and abuse E-IoT system resources. To defend against E-IoT driver-based threats, we introduce Ivycide, a novel intrusion detection system used to detect unexpected E-IoT network traffic from an E-IoT system. Ivycide operates as a passive monitoring system within an E-IoT system using machine learning and signature-based classification to detect Poisonivy attacks. We evaluated the performance of Ivycide in a realistic E-IoT deployment. Our detailed evaluation results show that Ivycide achieves an average accuracy of 97% in classifying the type of Poisonivy attack and operates without modifications or operational overhead to the existing E-IoT systems. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
IEEE Internet Things J. | 5 |
| 2022 | A Literature Review on Blockchain-enabled Security and Operation of Cyber-Physical SystemsabstractBlockchain has become a key technology in a plethora of application domains owing to its decentralized public nature. The cyber-physical systems (CPS) is one of the prominent application domains that leverage blockchain for myriad oper-ations, where the Internet of Things (IoT) is utilized for data collection. Although some of the CPS problems can be solved by simply adopting blockchain for its secure and distributed nature, others require complex considerations for overcoming blockchain-imposed limitations while maintaining the core aspect of CPS. Even though a number of studies focus on either the utilization of block chains for different CPS applications or the blockchain-enabled security of CPS, there is no comprehensive survey including both perspectives together. To fill this gap, we present a comprehensive overview of contemporary advancement in using blockchain for enhancing different CPS operations as well as improving CPS security. To the best of our knowledge, this is the first paper that presents an in-depth review of research on blockchain-enabled CPS operation and security. Alvi Ataur Khalil, Javier Franco, Imtiaz Parvez, A. Selcuk Uluagac, Hossain Shahriar, Mohammad Ashiqur Rahman |
COMPSAC | 4 |
| 2022 | S-Pot: A Smart Honeypot Framework with Dynamic Rule Configuration for SDNabstractEnterprise networks are becoming increasingly heterogeneous where enterprise devices and IoT devices coexist, requiring tools for effective management and security. Software Defined Networking (SDN) has emerged in response to such needs of modern networks. SDN lacks adequate security features and Intrusion Detection and Protection Systems (IDPS) have been used to protect SDN from attacks. However, they have limited knowledge of zero day attacks. Machine Learning (ML) has become a valuable tool against these limitations and improve (SDN) network security. However, the solutions that solely rely on ML can struggle to discriminate benign traffic from malicious, and suffer from false negatives. To solve these problems and improve security of SDN-based enterprise networks, we propose S-Pot, an open-source smart honeypot framework. S-Pot uses enterprise and IoT honeypots to attract attackers, learns from attacks via ML classifiers, and dynamically configures the rules of SDN. Since honeypots generally receive only malicious traffic, S-Pot can learn from the received malicious traffic and minimize the false positives of an SDN network. In addition, S-Pot can detect the new attacks using ML classifiers, thus can help to minimize the false negatives. Our performance evaluation of S-Pot in detecting attacks using various ML classifiers show that it can detect attacks with 97% accuracy using J48 algorithm. In addition, we evaluated the effectiveness of S-Pot in improving the security of an enterprise SDN testbed network. Our results demonstrate that, compared to the without S-Pot case, S-Pot can improve the security of the SDN networks by detecting attacks with better performance, greater accuracy, effectively generating rules, and dynamically configuring the network. Javier Franco, Ahmet Aris, Leonardo Babun, A. Selcuk Uluagac |
GLOBECOM | 4 |
| 2022 | Systematic Threat Analysis of Modern Unified Healthcare Communication SystemsabstractRecently, smart medical devices have become preva-lent in remote monitoring of patients and the delivery of medication. The ongoing Covid-19 pandemic situation has boosted the upward trend of the popularity of smart medical devices in the healthcare system. Simultaneously, different device manufacturers and technologies compete for a share in a smart medical device's market, which forces the integration of diverse smart medical de-vices into a common healthcare ecosystem. Hence, modern unified healthcare communication systems (UHCSs) combine ISO/IEEE 11073 and Health Level Seven (HL7) communication standards to support smart medical devices' interoperability and their communication with healthcare providers. Despite their advantages in supporting various smart medical devices and communication technologies, these standards do not provide any security and suffer from vulnerabilities. Existing studies provide stand-alone security solutions to components of UHCSs and do not cover UHCSs holistically. In this paper, we perform a systematic threat analysis of UHCSs that relies on attack-defense tree (ADTree) formalisms. Considering the attack landscape and defense ecosys-tem, we build an ADTree for UHCSs and convert the ADTree to stochastic timed automata (STA) to perform quantitative analysis. Our analysis using UPPAAL SMC shows that the Man-in-the-Middle and unauthorized remote access attacks are the most probable attacks that a malicious entity could pursue, causing mistreatment to patients. We also extract valuable information about the top threats, the likelihood of performing different individual and simultaneous attacks, and the expected cost for attackers. A. K. M. Iqtidar Newaz, Ahmet Aris, Amit Kumar Sikder, A. Selcuk Uluagac |
GLOBECOM | 4 |
| 2022 | The Truth Shall Set Thee Free: Enabling Practical Forensic Capabilities in Smart Environments
Leonardo Babun, Amit Kumar Sikder, Abbas Acar, A. Selcuk Uluagac |
NDSS | 4 |
| 2022 | A Lightweight IoT Cryptojacking Detection Mechanism in Heterogeneous Smart Home Networks
Ege Tekiner, Abbas Acar, A. Selcuk Uluagac |
NDSS | 3 |
| 2022 | A First Look at Code Obfuscation for WebAssemblyabstractWebAssembly (Wasm) has seen a lot of attention lately as it spreads through the mobile computing domain and becomes the new standard for performance-oriented web development. It has diversified its uses far beyond just web applications by acting as an execution environment for mobile agents, containers for IoT devices, and enabling new serverless approaches for edge computing. Within the numerous uses of Wasm, not all of them are benign. With the rise of Wasm-based cryptojacking malware, analyzing Wasm applications has been a hot topic in the literature, resulting in numerous Wasm-based cryptojacking detection systems. Many of these methods rely on static analysis, which traditionally can be circumvented through obfuscation. However, the feasibility of the obfuscation techniques for Wasm programs has never been investigated thoroughly. In this paper, we address this gap and perform the first look at code obfuscation for Wasm. We apply numerous obfuscation techniques to Wasm programs, and test their effectiveness in producing a fully obfuscated Wasm program. Particularly, we obfuscate both benign Wasm-based web applications and cryptojacking malware instances and feed them into a state-of-the-art Wasm cryptojacking detector to see if current Wasm analysis methods can be subverted with obfuscation. Our analysis shows that obfuscation can be highly effective and can cause even a state-of-the-art detector to misclassify the obfuscated Wasm samples. Shrenik Bhansali, Ahmet Aris, Abbas Acar, Harun Oz, A. Selcuk Uluagac |
WISEC | 5 |
| 2022 | Survey on Enterprise Internet-of-Things systems (E-IoT): A security perspective
Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
Ad Hoc Networks | 5 |
| 2022 | Who's Controlling My Device? Multi-User Multi-Device-Aware Access Control System for Shared Smart Home EnvironmentabstractMultiple users have access to multiple devices in a smart home system – typically through a dedicated app installed on a mobile device. Traditional access control mechanisms consider one unique, trusted user that controls access to the devices. However, multi-user multi-device smart home settings pose fundamentally different challenges to traditional single-user systems. For instance, in a multi-user environment, users have conflicting, complex, and dynamically-changing demands on multiple devices that cannot be handled by traditional access control techniques. Moreover, smart devices from different platforms/vendors can share the same home environment, making existing access control obsolete for smart home systems. To address these challenges, in this paper, we introduce Kratos+ , a novel multi-user and multi-device-aware access control mechanism that allows smart home users to flexibly specify their access control demands. Kratos+ has four main components: user interaction module, backend server, policy manager, and policy execution module. Users can easily specify their desired access control settings using the interaction module that are translated into access control policies in the back-end server. The policy manager analyzes these policies, initiates automated negotiation between users to resolve conflicting demands, and generates final policies to enforce in smart home systems. We implemented Kratos+ as a platform-independent solution and evaluated its performance on real smart home deployments featuring multi-user scenarios with a rich set of configurations (337 different policies including 231 demand conflicts and 69 restriction policies). These configurations also included five different threats associated with access control mechanisms. Our extensive evaluations show that Kratos+ is very effective in resolving conflicting access control demands with minimal overhead. We also performed an extensive user study with 72 smart home users to better understand the user’s needs before designing the system and a usability study to evaluate the efficacy of Kratos+ in a real-life smart home environment. Amit Kumar Sikder, Leonardo Babun, Z. Berkay Celik, Hidayet Aksu, Patrick D. McDaniel, Engin Kirda, A. Selcuk Uluagac |
ACM Trans. Internet Things | 7 |
| 2021 | SoK: Cryptojacking MalwareabstractEmerging blockchain and cryptocurrency-based technologies are redefining the way we conduct business in cyberspace. Today, a myriad of blockchain and cryp-tocurrency systems, applications, and technologies are widely available to companies, end-users, and even malicious actors who want to exploit the computational resources of regular users through cryptojacking malware. Especially with ready-to-use mining scripts easily provided by service providers (e.g., Coinhive) and untraceable cryptocurrencies (e.g., Monero), cryptojacking malware has become an indispensable tool for attackers. Indeed, the banking industry, major commercial websites, government and military servers (e.g., US Dept. of Defense), online video sharing platforms (e.g., Youtube), gaming platforms (e.g., Nintendo), critical infrastructure resources (e.g., routers), and even recently widely popular remote video conferencing/meeting programs (e.g., Zoom during the Covid-19 pandemic) have all been the victims of powerful cryptojacking malware campaigns. Nonetheless, existing detection methods such as browser extensions that protect users with blacklist methods or antivirus programs with different analysis methods can only provide a partial panacea to this emerging crypto-jacking issue as the attackers can easily bypass them by using obfuscation techniques or changing their domains or scripts frequently. Therefore, many studies in the literature proposed cryptojacking malware detection methods using various dynamic/behavioral features. However, the literature lacks a systemic study with a deep understanding of the emerging cryptojacking malware and a comprehensive review of studies in the literature. To fill this gap in the literature, in this SoK paper, we present a systematic overview of cryptojacking malware based on the information obtained from the combination of academic research papers, two large cryptojacking datasets of samples, and 45 major attack instances. Finally, we also present lessons learned and new research directions to help the research community in this emerging area. Ege Tekiner, Abbas Acar, A. Selcuk Uluagac, Engin Kirda, Ali Aydin Selçuk |
EuroS&P | 3 |
| 2021 | MINOS: A Lightweight Real-Time Cryptojacking Detection System
Faraz Naseem Naseem, Ahmet Aris, Leonardo Babun, Ege Tekiner, A. Selcuk Uluagac |
NDSS | 5 |
| 2021 | LightningStrike: (in)secure practices of E-IoT systems in the wildabstractThe widespread adoption of specialty smart ecosystems has changed the everyday lives of users. As a part of smart ecosystems, Enterprise Internet of Things (E-IoT) allows users to integrate and control more complex installations in comparison to off-the-shelf IoT systems. With E-IoT, users have a complete control of audio, video, scheduled events, lightning fixtures, shades, door access, and relays via available user interfaces. As such, these systems see widespread use in government or smart private offices, schools, smart buildings, professional conference rooms, hotels, smart homes, yachts, and similar professional settings. However, even with their widespread use, the security of many E-IoT systems has not been researched in the literature. Further, many E-IoT systems utilize proprietary communication protocols that rely mostly on security through obscurity, which has perhaps led many users to mistakenly assume that these systems are secure. To address this open research problem and determine if E-IoT systems are vulnerable, we focus on one of the core E-IoT components, E-IoT communication buses. Communication buses are used by E-IoT proprietary protocols to connect multiple E-IoT devices (e.g., keypads and touchscreens) and trigger pre-configured events upon user actions. In this study, we introduce LightningStrike, the implementation of four proof-of-concept attacks that demonstrate several weaknesses in E-IoT proprietary communication protocols through communication buses. With LightningStrike, we show that it is feasible for an attacker to compromise E-IoT systems using E-IoT communication buses. We demonstrate that popular E-IoT proprietary communication protocols are susceptible to Denial-of-Service, eavesdropping, impersonation, and replay attacks. As E-IoT systems control physical access, safety components, and emergency equipment, an attacker with a low level of knowledge and effort can easily exploit E-IoT vulnerabilities to impact the security and safety of users, smart systems, and smart buildings worldwide. Luis Puche Rondon, Leonardo Babun, Ahmet Aris, Kemal Akkaya, A. Selcuk Uluagac |
WISEC | 5 |
| 2021 | A survey on IoT platforms: Communication, security, and privacy perspectives
Leonardo Babun, Kyle Denney, Z. Berkay Celik, Patrick D. McDaniel, A. Selcuk Uluagac |
Comput. Networks | 5 |
| 2021 | A Survey on Security and Privacy Issues in Modern Healthcare Systems: Attacks and DefensesabstractRecent advancements in computing systems and wireless communications have made healthcare systems more efficient than before. Modern healthcare devices can monitor and manage different health conditions of patients automatically without any manual intervention from medical professionals. Additionally, the use of implantable medical devices, body area networks, and Internet of Things technologies in healthcare systems improve the overall patient monitoring and treatment process. However, these systems are complex in software and hardware, and optimizing between security, privacy, and treatment is crucial for healthcare systems because any security or privacy violation can lead to severe effects on patients’ treatments and overall health conditions. Indeed, the healthcare domain is increasingly facing security challenges and threats due to numerous design flaws and the lack of proper security measures in healthcare devices and applications. In this article, we explore various security and privacy threats to healthcare systems and discuss the consequences of these threats. We present a detailed survey of different potential attacks and discuss their impacts. Furthermore, we review the existing security measures proposed for healthcare systems and discuss their limitations. Finally, we conclude the article with future research directions toward securing healthcare systems against common vulnerabilities. A. K. M. Iqtidar Newaz, Amit Kumar Sikder, Mohammad Ashiqur Rahman, A. Selcuk Uluagac |
ACM Trans. Comput. Heal. | 4 |
| 2021 | A scalable private Bitcoin payment channel network with privacy guarantees
Enes Erdin, Mumin Cebe, Kemal Akkaya, Eyuphan Bulut, A. Selcuk Uluagac |
J. Netw. Comput. Appl. | 5 |
| 2021 | Real-time Analysis of Privacy-(un)aware IoT ApplicationsabstractAbstract Abstract: Users trust IoT apps to control and automate their smart devices. These apps necessarily have access to sensitive data to implement their functionality. However, users lack visibility into how their sensitive data is used, and often blindly trust the app developers. In this paper, we present IoTWATcH, a dynamic analysis tool that uncovers the privacy risks of IoT apps in real-time. We have designed and built IoTWATcH through a comprehensive IoT privacy survey addressing the privacy needs of users. IoTWATCH operates in four phases: (a) it provides users with an interface to specify their privacy preferences at app install time, (b) it adds extra logic to an app’s source code to collect both IoT data and their recipients at runtime, (c) it uses Natural Language Processing (NLP) techniques to construct a model that classifies IoT app data into intuitive privacy labels, and (d) it informs the users when their preferences do not match the privacy labels, exposing sensitive data leaks to users. We implemented and evaluated IoTWATcH on real IoT applications. Specifically, we analyzed 540 IoT apps to train the NLP model and evaluate its effectiveness. IoTWATcH yields an average 94.25% accuracy in classifying IoT app data into privacy labels with only 105 ms additional latency to an app’s execution. Leonardo Babun, Z. Berkay Celik, Patrick D. McDaniel, A. Selcuk Uluagac |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | CPS Device-Class Identification via Behavioral Fingerprinting: From Theory to PracticeabstractCyber-Physical Systems (CPS) utilize different devices to collect sensitive data, communicate with other systems, and monitor essential processes in critical infrastructure applications. However, in the ecosystem of CPS, unauthorized or spoofed devices may danger or compromise the performance and security of the critical infrastructure. The unauthorized and spoofed devices may include tampered pieces of software or hardware components that can negatively impact CPS operations or collect vital CPS metrics from the network. Such devices can be outsider or insider threats trying to impersonate other real CPS devices via spoofing their legitimate identifications to gain access to systems, steal information, or spread malware. Device fingerprinting techniques are promising approaches to identify unauthorized or illegitimate devices. However, current fingerprinting solutions are not suitable as they disrupt critical real-time operations in CPS due to the nature of their extensive data analysis or too much overhead on the devices' computational resources. To address these concerns, in this work, we propose STOP-AND- FRISK (S&F), a novel fingerprinting framework to identify CPS device classes and complement traditional security mechanisms in CPS. S&F is based on a secure challenge/response mechanism that analyzes the behavior of the CPS devices at both the hardware and OS/kernel levels. Specifically, the proposed novel mechanism combines system and function call tracing techniques, signal processing, and hardware performance analysis to create specific device-class signatures. Then, the signatures are correlated against known behavioral ground-truth to identify the device types. To test the efficacy of S&F extensively, we implemented a realistic testbed that included different classes of CPS devices with a variety of computing resources, architectures, and configurations. Our experimental results reveal an excellent rate on the CPS device-class identification. Finally, extensive performance analysis demonstrates that the use of S&F yields minimal overhead on the CPS devices' computing resources. Leonardo Babun, Hidayet Aksu, A. Selcuk Uluagac |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | A Lightweight Privacy-Aware Continuous Authentication Protocol-PACAabstractAs many vulnerabilities of one-time authentication systems have already been uncovered, there is a growing need and trend to adopt continuous authentication systems. Biometrics provides an excellent means for periodic verification of the authenticated users without breaking the continuity of a session. Nevertheless, as attacks to computing systems increase, biometric systems demand more user information in their operations, yielding privacy issues for users in biometric-based continuous authentication systems. However, the current state-of-the-art privacy technologies are not viable or costly for the continuous authentication systems, which require periodic real-time verification. In this article, we introduce a novel, lightweight, privacy-aware, and secure continuous authentication protocol called PACA. PACA is initiated through a password-based key exchange (PAKE) mechanism, and it continuously authenticates users based on their biometrics in a privacy-aware manner. Then, we design an actual continuous user authentication system under the proposed protocol. In this concrete system, we utilize a privacy-aware template matching technique and a wearable-assisted keystroke dynamics-based continuous authentication method. This provides privacy guarantees without relying on any trusted third party while allowing the comparison of noisy user inputs (due to biometric data) and yielding an efficient and lightweight protocol. Finally, we implement our system on an Apple smartwatch and perform experiments with real user data to evaluate the accuracy and resource consumption of our concrete system. Abbas Acar, Shoukat Ali, Koray Karabina, Cengiz Kaygusuz, Hidayet Aksu, Kemal Akkaya, A. Selcuk Uluagac |
ACM Trans. Priv. Secur. | 7 |
| 2021 | Distributed Connectivity Maintenance in Swarm of Drones During Post-Disaster Transportation ApplicationsabstractConsidering post-disaster scenarios for intelligent traffic management and damage assessment where communication infrastructure may not be available, we advocate a swarm-of-drones mesh communication architecture that can sustain in-network connectivity among drones. The connectivity sustenance requirement stems from the fact that drones may move to various locations in response to service requests but they still need to cooperate for data collection and transmissions. To address this need, we propose a fully distributed connectivity maintenance heuristic which enables the swarm to quickly adapt its formation in response to the service requests. To select the moving drone(s) that would bring minimal overhead in terms of time and moving distance, the connected dominating set (CDS) concept from graph theory is utilized. Specifically, a variation of CDS, namely E-CDS, is introduced to address the needs of 3-D mobile swarm-of-drones. We then show that E-CDS is NP-Complete and propose a new distributed heuristic to solve it. Once the E-CDS is determined in advance, drones not part of this E-CDS set are picked for movement tasks. When the movement is to cause any disconnection with the rest of the swarm, other drones are also relocated to restore the connectivity. The proposed heuristics are implemented in ns-3 network simulator as part of the existing IEEE 802.11s mesh standard and the effectiveness is tested in terms of providing undisturbed services under different conditions. The results indicate that the proposed distributed heuristic almost matches the performance of a centralized solution and suits perfectly the needs of post-disaster traffic management. Ahmet Kurt, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | A Usable and Robust Continuous Authentication Framework Using WearablesabstractOne-time login process in conventional authentication systems does not guarantee that the identified user is the actual user throughout the session. However, it is necessary to re-verify the user identity periodically throughout a login session, which is lacking in existing one-time login systems. Continuous authentication, which re-verifies the user identity without breaking the continuity of the session, can address this issue. However, existing methods for Continuous Authentication are either not reliable or not usable. In this paper, we introduce a usable and reliable Wearable-Assisted Continuous Authentication (WACA), which relies on the sensor-based keystroke dynamics and the authentication data is acquired through the built-in sensors of a wearable (e.g., smartwatch) while the user is typing. The acquired data is periodically and transparently compared with the registered profile of the initially logged-in user with one-way classifiers. With this, WACA continuously ensures that the current user is the user who logged-in initially. We implemented the WACA framework and evaluated its performance extensively on real devices with real users. The empirical evaluation of WACA reveals that WACA is feasible, and its error rate is as low as 1 percent with 30 seconds of processing time and 2-3 percent for 20 seconds. The computational overhead is minimal. Furthermore, WACA is capable of identifying insider threats with very high accuracy (99.2 percent) and also robust against powerful adversaries such as imitation and statistical attackers. We believe that this work has practical and far-reaching implications for the future of the usable authentication field. Abbas Acar, Hidayet Aksu, A. Selcuk Uluagac, Kemal Akkaya |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Identification of Wearable Devices with BluetoothabstractWith wearable devices such as smartwatches on the rise in the consumer electronics market, securing these wearables is vital. However, the current security mechanisms only focus on validating the user not the device itself. Indeed, wearables can be (1) unauthorized wearable devices with correct credentials accessing valuable systems and networks, (2) passive insiders or outsider wearable devices, or (3) information-leaking wearables devices. Fingerprinting via machine learning can provide necessary cyber threat intelligence to address all these cyber attacks. In this work, we introduce a wearable fingerprinting technique focusing on Bluetooth classic protocol, which is a common protocol used by the wearables and other IoT devices. Specifically, we propose a non-intrusive wearable device identification framework which utilizes 20 different Machine Learning (ML) algorithms in the training phase of the classification process and selects the best performing algorithm for the testing phase. Furthermore, we evaluate the performance of proposed wearable fingerprinting technique on real wearable devices, including various off-the-shelf smartwatches. Our evaluation demonstrates the feasibility of the proposed technique to provide reliable cyber threat intelligence. Specifically, our detailed accuracy results show on average 98.5 percent, 98.3 percent precision and recall for identifying wearables using the Bluetooth classic protocol. Hidayet Aksu, A. Selcuk Uluagac, Elizabeth S. Bentley |
IEEE Trans. Sustain. Comput. | 2 |
| 2020 | LNBot: A Covert Hybrid Botnet on Bitcoin Lightning Network for Fun and Profit
Ahmet Kurt, Enes Erdin, Mumin Cebe, Kemal Akkaya, A. Selcuk Uluagac |
ESORICS (2) | 5 |
| 2020 | Adversarial Attacks to Machine Learning-Based Smart Healthcare SystemsabstractThe increasing availability of healthcare data requires accurate analysis of disease diagnosis, progression, and real-time monitoring to provide improved treatments to the patients. In this context, Machine Learning (ML) models are used to extract valuable features and insights from high-dimensional and heterogeneous healthcare data to detect different diseases and patient activities in a Smart Healthcare System (SHS). However, recent researches show that ML models used in different application domains are vulnerable to adversarial attacks. In this paper, we introduce a new type of adversarial attacks to exploit the ML classifiers used in a SHS. We consider an adversary who has partial knowledge of data distribution, SHS model, and ML algorithm to perform both targeted and untargeted attacks. Employing these adversarial capabilities, we manipulate medical device readings to alter patient status (disease-affected, normal condition, activities, etc.) in the outcome of the SHS. Our attack utilizes five different adversarial ML algorithms (HopSkipJump, Fast Gradient Method, Crafting Decision Tree, Carlini & Wagner, Zeroth Order optimization) to perform different malicious activities (e.g., data poisoning, misclassify outputs, etc.) on a SHS. Moreover, based on the training and testing phase capabilities of an adversary, we perform white box and black box attacks on a SHS. We evaluate the performance of our work in different SHS settings and medical devices. Our extensive evaluation shows that our proposed adversarial attack can significantly degrade the performance of a ML-based SHS in detecting diseases and normal activities of the patients correctly, which eventually leads to erroneous treatment. A. K. M. Iqtidar Newaz, Nur Imtiazul Haque, Amit Kumar Sikder, Mohammad Ashiqur Rahman, A. Selcuk Uluagac |
GLOBECOM | 5 |
| 2020 | Z-IoT: Passive Device-class Fingerprinting of ZigBee and Z-Wave IoT DevicesabstractIn addition to traditional networking devices (e.g., gateways, firewalls), current corporate and industrial networks integrate resource-limited Internet of Things (IoT) devices like smart outlets and smart sensors. In these settings, cyber attackers can bypass traditional security solutions and spoof legitimate IoT devices to gain illegal access to the systems. Thus, IoT device-class identification is crucial to protect critical networks from unauthorized access. In this paper, we propose Z-IoT, the first fingerprinting framework used to identify IoT device classes that utilize ZigBee and Z-Wave protocols. Z-IoT monitors idle network traffic among IoT devices to implement signature-based device-class fingerprinting mechanisms. Utilizing passive packet capturing techniques and optimal selection of filtering criteria and machine learning algorithms, Z-IoT identifies different types of IoT devices while guaranteeing the anonymity of the network data. To test Z-IoT's efficacy, we implemented several testbeds, including a total of 39 commodity IoT devices that communicate over ZigBee and Z-Wave protocols. Our experimental results showed an excellent performance in identifying different classes of IoT devices with average precision and recall of over 91%. Finally, the proposed framework yields no overhead to the IoT devices or the network traffic. Leonardo Babun, Hidayet Aksu, Lucas Ryan, Kemal Akkaya, Elizabeth S. Bentley, A. Selcuk Uluagac |
ICC | 6 |
| 2020 | Peek-a-boo: i see your smart home activities, even encrypted!abstractA myriad of IoT devices such as bulbs, switches, speakers in a smart home environment allow users to easily control the physical world around them and facilitate their living styles through the sensors already embedded in these devices. Sensor data contains a lot of sensitive information about the user and devices. However, an attacker inside or near a smart home environment can potentially exploit the innate wireless medium used by these devices to exfiltrate sensitive information from the encrypted payload (i.e., sensor data) about the users and their activities, invading user privacy. With this in mind, in this work, we introduce a novel multi-stage privacy attack against user privacy in a smart environment. It is realized utilizing state-of-the-art machine-learning approaches for detecting and identifying the types of IoT devices, their states, and ongoing user activities in a cascading style by only passively sniffing the network traffic from smart home devices and sensors. The attack effectively works on both encrypted and unencrypted communications. We evaluate the efficiency of the attack with real measurements from an extensive set of popular off-the-shelf smart home IoT devices utilizing a set of diverse network protocols like WiFi, ZigBee, and BLE. Our results show that an adversary passively sniffing the traffic can achieve very high accuracy (above 90%) in identifying the state and actions of targeted smart home devices and their users. To protect against this privacy leakage, we also propose a countermeasure based on generating spoofed traffic to hide the device states and demonstrate that it provides better protection than existing solutions. Abbas Acar, Hossein Fereidooni, Tigist Abera, Amit Kumar Sikder, Markus Miettinen, Hidayet Aksu, Mauro Conti, Ahmad-Reza Sadeghi, A. Selcuk Uluagac |
WISEC | 9 |
| 2020 | Kratos: multi-user multi-device-aware access control system for the smart homeabstractIn a smart home system, multiple users have access to multiple devices, typically through a dedicated app installed on a mobile device. Traditional access control mechanisms consider one unique trusted user that controls the access to the devices. However, multi-user multi-device smart home settings pose fundamentally different challenges to traditional single-user systems. For instance, in a multi-user environment, users have conflicting, complex, and dynamically changing demands on multiple devices, which cannot be handled by traditional access control techniques. To address these challenges, in this paper, we introduce Kratos, a novel multi-user and multi-device-aware access control mechanism that allows smart home users to flexibly specify their access control demands. Kratos has three main components: user interaction module, back-end server, and policy manager. Users can specify their desired access control settings using the interaction module which are translated into access control policies in the backend server. The policy manager analyzes these policies and initiates negotiation between users to resolve conflicting demands and generates final policies. We implemented Kratos and evaluated its performance on real smart home deployments featuring multi-user scenarios with a rich set of configurations (309 different policies including 213 demand conflicts and 24 restriction policies). These configurations included five different threats associated with access control mechanisms. Our extensive evaluations show that Kratos is very effective in resolving conflicting access control demands with minimal overhead, and robust against different attacks. Amit Kumar Sikder, Leonardo Babun, Z. Berkay Celik, Abbas Acar, Hidayet Aksu, Patrick D. McDaniel, Engin Kirda, A. Selcuk Uluagac |
WISEC | 8 |
| 2020 | A Bitcoin payment network with reduced transaction fees and confirmation times
Enes Erdin, Mumin Cebe, Kemal Akkaya, Senay Solak, Eyuphan Bulut, A. Selcuk Uluagac |
Comput. Networks | 6 |
| 2020 | A System-level Behavioral Detection Framework for Compromised CPS Devices: Smart-Grid CaseabstractCyber-Physical Systems (CPS) play a significant role in our critical infrastructure networks from power-distribution to utility networks. The emerging smart-grid concept is a compelling critical CPS infrastructure that relies on two-way communications between smart devices to increase efficiency, enhance reliability, and reduce costs. However, compromised devices in the smart grid poses several security challenges. Consequences of propagating fake data or stealing sensitive smart grid information via compromised devices are costly. Hence, early behavioral detection of compromised devices is critical for protecting the smart grid’s components and data. To address these concerns, in this article, we introduce a novel and configurable system-level framework to identify compromised smart grid devices. The framework combines system and function call tracing techniques with signal processing and statistical analysis to detect compromised devices based on their behavioral characteristics. We measure the efficacy of our framework with a realistic smart grid substation testbed that includes both resource-limited and resource-rich devices. In total, using our framework, we analyze six different types of compromised device scenarios with different resources and attack payloads. To the best of our knowledge, the proposed framework is the first in detecting compromised CPS smart grid devices with system and function-level call tracing techniques. The experimental results reveal an excellent rate for the detection of compromised devices. Specifically, performance metrics include accuracy values between 95% and 99% for the different attack scenarios. Finally, the performance analysis demonstrates that the use of the proposed framework has minimal overhead on the smart grid devices’ computing resources. Leonardo Babun, Hidayet Aksu, A. Selcuk Uluagac |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2020 | A Context-Aware Framework for Detecting Sensor-Based Threats on Smart DevicesabstractSensors (e.g., light, gyroscope, and accelerometer) and sensing-enabled applications on a smart device make the applications more user-friendly and efficient. However, the current permission-based sensor management systems of smart devices only focus on certain sensors and any App can get access to other sensors by just accessing the generic sensor Application Programming Interface (API). In this way, attackers can exploit these sensors in numerous ways: they can extract or leak users' sensitive information, transfer malware, or record or steal sensitive information from other nearby devices. In this paper, we propose 6thSense, a context-aware intrusion detection system which enhances the security of smart devices by observing changes in sensor data for different tasks of users and creating a contextual model to distinguish benign and malicious behavior of sensors. 6thSense utilizes three different Machine Learning-based detection mechanisms (i.e., Markov Chain, Naive Bayes, and LMT). We implemented 6thSense on several sensor-rich Android-based smart devices (i.e., smart watch and smartphone) and collected data from typical daily activities of 100 real users. Furthermore, we evaluated the performance of 6thSense against three sensor-based threats: (1) a malicious App that can be triggered via a sensor, (2) a malicious App that can leak information via a sensor, and (3) a malicious App that can steal data using sensors. Our extensive evaluations show that the 6thSense framework is an effective and practical approach to defeat growing sensor-based threats with an accuracy above 96 percent without compromising the normal functionality of the device. Moreover, our framework reveals minimal overhead. Amit Kumar Sikder, Hidayet Aksu, A. Selcuk Uluagac |
IEEE Trans. Mob. Comput. | 3 |
| 2019 | HDMI-walk: attacking HDMI distribution networks via consumer electronic control protocolabstractThe High Definition Multimedia Interface (HDMI) is the backbone and the de-facto standard for Audio/Video interfacing between video-enabled devices. Today, almost tens of billions of HDMI devices exist in the world and are widely used to distribute A/V signals in smart homes, offices, concert halls, and sporting events making HDMI one of the most highly deployed systems in the world. An important component in HDMI is the Consumer Electronics Control (CEC) protocol, which allows for the interaction between devices within an HDMI distribution network. Nonetheless, existing network security mechanisms only protect traditional networking components, leaving CEC outside of their scope. In this work, we identify and tap into CEC protocol vulnerabilities, using them to implement realistic proof-of-work attacks on HDMI distribution networks. We study, how current insecure CEC protocol practices and carelessly implemented HDMI distributions may grant an adversary a novel attack surface for HDMI devices otherwise thought to be unreachable through traditional means. To introduce this novel attack surface, in this paper, we present HDMI-Walk, which opens a realm of remote and local CEC attacks to HDMI devices. Specifically, with HDMI-Walk, an attacker can perform malicious analysis of devices, eavesdropping, Denial of Service attacks, targeted device attacks, and even facilitate other well-known existing attacks through HDMI. With HDMI-Walk, we prove that it is feasible for an attacker to gain arbitrary control of HDMI devices. We demonstrate the implementations of both local and remote attacks with commodity HDMI devices including Smart TVs and Media Players. Our work aims to uncover vulnerabilities in a very well deployed system like HDMI distributions. The consequences of which can largely impact HDMI users as well as other systems which depend on these distributions. Finally, we discuss security mechanisms to provide impactful and comprehensive security evaluation to these real-world systems while guaranteeing deployability and providing minimal overhead, while considering the current limitations of the CEC protocol. To the best of our knowledge, this is the first work solely investigating the security of HDMI device distribution networks. Luis Puche Rondon, Leonardo Babun, Kemal Akkaya, A. Selcuk Uluagac |
ACSAC | 4 |
| 2019 | Aegis: a context-aware security framework for smart home systemsabstractOur everyday lives are expanding fast with the introduction of new Smart Home Systems (SHSs). Today, a myriad of SHS devices and applications are widely available to users and have already started to re-define our modern lives. Smart home users utilize the apps to control and automate such devices. Users can develop their own apps or easily download and install them from vendor-specific app markets. App-based SHSs offer many tangible benefits to our lives, but also unfold diverse security risks. Several attacks have already been reported for SHSs. However, current security solutions consider smart home devices and apps individually to detect malicious actions rather than the context of the SHS as a whole. The existing mechanisms cannot capture user activities and sensor-device-user interactions in a holistic fashion. To address these issues, in this paper, we introduce Aegis, a novel context-aware security framework to detect malicious behavior in a SHS. Specifically, Aegis observes the states of the connected smart home entities (sensors and devices) for different user activities and usage patterns in a SHS and builds a contextual model to differentiate between malicious and benign behavior. We evaluated the efficacy and performance of Aegis in multiple smart home settings (i.e., single bedroom, double bedroom, duplex) with real-life users performing day-to-day activities and real SHS devices. We also measured the performance of Aegis against five different malicious behaviors. Our detailed evaluation shows that Aegis can detect malicious behavior in SHS with high accuracy (over 95%) and secure the SHS regardless of the smart home layout, device configuration, installed apps, and enforced user policies. Finally, Aegis achieves minimum overhead in detecting malicious behavior in SHS, ensuring easy deployability in real-life smart environments. Amit Kumar Sikder, Leonardo Babun, Hidayet Aksu, A. Selcuk Uluagac |
ACSAC | 4 |
| 2019 | Curie: Policy-based Secure Data ExchangeabstractData sharing among partners---users, companies, organizations---is crucial for the advancement of collaborative machine learning in many domains such as healthcare, finance, and security. Sharing through secure computation and other means allow these partners to perform privacy-preserving computations on their private data in controlled ways. However, in reality, there exist complex relationships among members (partners). Politics, regulations, interest, trust, data demands and needs prevent members from sharing their complete data. Thus, there is a need for a mechanism to meet these conflicting relationships on data sharing. This paper presents, an approach to exchange data among members who have complex relationships. A novel policy language, CPL, that allows members to define the specifications of data exchange requirements is introduced. With CPL, members can easily assert who and what to exchange through their local policies and negotiate a global sharing agreement. The agreement is implemented in a distributed privacy-preserving model that guarantees sharing among members will comply with the policy as negotiated. The use of Curie is validated through an example healthcare application built on recently introduced secure multi-party computation and differential privacy frameworks, and policy and performance trade-offs are explored. Z. Berkay Celik, Abbas Acar, Hidayet Aksu, Ryan Sheatsley, Patrick D. McDaniel, A. Selcuk Uluagac |
CODASPY | 6 |
| 2019 | An Analysis of Malware Trends in Enterprise Networks
Abbas Acar, Long Lu, A. Selcuk Uluagac, Engin Kirda |
ISC | 3 |
| 2019 | A novel routing metric for IEEE 802.11s-based swarm-of-drones applicationsabstractWith the proliferation of drones in our daily lives, there is an increasing need for handling their numerous challenges. One of such challenge arises when a swarm-of-drones are deployed to accomplish a specific task which requires coordination and communication among the drones. While this swarm-of-drones is essentially a special form of mobile ad hoc networks (MANETs) which has been studied for many years, there are still some unique requirements of drone applications that necessitates re-visiting MANET approaches. These challenges stem from 3--D environments the drones are deployed in, and their specific way of mobility which adds to the wireless link management challenges among the drones. In this paper, we consider an existing routing standard that is used to enable meshing capability among Wi-Fi enabled nodes, namely IEEE 802.11s and adopt its routing capabilities for swarm-of-drones. Specifically, we propose a link quality metric called SrFTime as an improvement to existing Airtime metric which is the 802.11s default routing metric to enable better network throughput for drone applications. This new metric is designed to fit the link characteristics of drones and enable more efficient routes from drones to their gateway. The evaluations in the actual 802.11s standard indicates that our proposed metric outperforms the existing one consistently under various conditions. Oscar G. Bautista, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
MobiQuitous | 4 |
| 2019 | USB-Watch: A Dynamic Hardware-Assisted USB Threat Detection Framework
Kyle Denney, Enes Erdin, Leonardo Babun, Michael Vai, A. Selcuk Uluagac |
SecureComm (1) | 5 |
| 2019 | A digital forensics framework for smart settings: posterabstractUsers utilize IoT devices and sensors in a co-operative manner to enable the concept of a smart environment. This integration generate data with high forensic value. Nonetheless, current smart app programming platforms do not provide any digital forensics capability to identify, trace, store, and analyze the data produced in these settings. To overcome these limitations, in this poster, we present our ongoing work to introduce a novel digital forensic framework for a smart environment. Leonardo Babun, Amit Kumar Sikder, Abbas Acar, A. Selcuk Uluagac |
WiSec | 4 |
| 2019 | Dynamically detecting USB attacks in hardware: posterabstractMalicious USB devices can disguise themselves as benign devices (e.g., keyboard, mouse, etc.) to insert malicious commands on end devices. Advanced software-based detection schemes (deeper operating system level) are used to identify the malicious nature of such mimic devices. However, a powerful adversary (e.g., as rootkits or advanced persistent threats) can subvert those software-based detection schemes. To address these concerns, we present our ongoing work to dynamically detect these threats in hardware. Specifically, we utilize a novel hardware-assistance mechanism to collect unaltered USB data at the physical layer which is fed into a machine learning-based classifier to determine the true nature of the USB device. Kyle Denney, Enes Erdin, Leonardo Babun, A. Selcuk Uluagac |
WiSec | 4 |
| 2019 | Attacking HDMI distribution networks: posterabstractThe High Definition Multimedia Interface or HDMI is the core and primary standard for Audio/Video communication in various media devices. HDMI allows flexible interaction between devices within HDMI distribution networks. Existing security standards and mechanism only protect traditional networking components. A user may mistakenly believe that a device is secure and an adversary may prove them otherwise. In this ongoing work, we show that by leveraging CEC to an attackers advantage. It is feasible for an attacker to reach devices which were formerly unreachable, and gain arbitrary control of HDMI devices. Specifically, we demonstrate it is possible to execute malicious device analysis, eavesdrop, and perform targeted Denial-of-Service attacks. Luis Puche Rondon, Leonardo Babun, Kemal Akkaya, A. Selcuk Uluagac |
WiSec | 4 |
| 2019 | SDN-enabled recovery for Smart Grid teleprotection applications in post-disaster scenarios
Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
J. Netw. Comput. Appl. | 4 |
| 2018 | Assessing the overhead of authentication during SDN-enabled restoration of smart grid inter-substation communicationsabstractSince real-time and resilient recovery of link failures is crucial for power grid infrastructure to continue its services, emerging technologies such as Software Defined Networking (SDN) has started to be employed for such purposes. SDN switches can be remotely controlled to change their configurations by exploiting the wireless communication options. However, when wireless is to be used in Smart Grid communications, security and reliability become important issues due to the specific characteristics of wireless communications. This paper investigates the overhead of providing such services on wireless links when SDN is utilized. Specifically, we consider the establishment of authentication services when wireless back-up links (i.e., WiFi or LTE) are employed as a result of a reactive link failure detection mechanism. To the best of our knowledge, this work is the first to consider authentication of such an SDN-enabled Smart Grid inter-substation communication with WiFi and LTE. To be able to effectively evaluate the performance of this proposed SDN-enabled framework, we developed it in Mininet emulator. Since Mininet does not support the authentication services for WiFi or LTE, we proposed several novel extensions to Mininet by integrating it with ns-3 simulator that supports the LTE/WiFi protocol stacks. We conducted extensive experiments by considering a general application using Smart Grid Manufacturing Message Specification (MMS) standard to assess the recovery performance of the proposed secure SDN-enabled recovery system. The results show that when authentication and reliable protocols such as TCP are to be employed, the proposed framework can still meet the deadlines of 100 ms with WiFi while LTE misses only a few packets. Abdullah Aydeger, Nico Saputro, Kemal Akkaya, A. Selcuk Uluagac |
CCNC | 4 |
| 2018 | Detection of Compromised Smart Grid Devices with Machine Learning and Convolution TechniquesabstractThe smart grid concept has transformed the traditional power grid into a massive cyber- physical system that depends on advanced two-way communication infrastructure to integrate a myriad of different smart devices. While the introduction of the cyber component has made the grid much more flexible and efficient with so many smart devices, it also broadened the attack surface of the power grid. Particularly, compromised devices pose great danger to the healthy operations of the smart-grid. For instance, the attackers can control the devices to change the behaviour of the grid and can impact the measurements. In this paper, to detect such misbehaving malicious smart grid devices, we propose a machine learning and convolution-based classification framework. Our framework specifically utilizes system and library call lists at the kernel level of the operating system on both resource-limited and resource-rich smart grid devices such as RTUs, PLCs, PMUs, and IEDs. Focusing on the types and other valuable features extracted from the system calls, the framework can successfully identify malicious smart-grid devices. In order to test the efficacy of the proposed framework, we built a representative testbed conforming to the IEC-61850 protocol suite and evaluated its performance with different system calls. The proposed framework in different evaluation scenarios yields very high accuracy (avg. 91%) which reveals that the framework is effective to overcome compromised smart grid devices problem. Cengiz Kaygusuz, Leonardo Babun, Hidayet Aksu, A. Selcuk Uluagac |
ICC | 4 |
| 2018 | U-PoT: A Honeypot Framework for UPnP-Based IoT DevicesabstractThe ubiquitous nature of the IoT devices has brought serious security implications to its users. A lot of consumer IoT devices have little to no security implementation at all, thus risking user's privacy and making them target of mass cyber-attacks. Indeed, recent outbreak of Mirai botnet and its variants have already proved the lack of security on the IoT world. Hence, it is important to understand the security issues and attack vectors in the IoT domain. Though significant research has been done to secure traditional computing systems, little focus was given to the IoT realm. In this work, we reduce this gap by developing a honeypot framework for IoT devices. Specifically, we introduce U-PoT: a novel honeypot framework for capturing attacks on IoT devices that use Universal Plug and Play (UPnP) protocol. A myriad of smart home devices including smart switches, smart bulbs, surveillance cameras, smart hubs, etc. uses the UPnP protocol. Indeed, a simple search on Shodan IoT search engine lists 1,676,591 UPnP devices that are exposed to public network. The popularity and ubiquitous nature of UPnP-based IoT device necessitates a full-fledged IoT honeypot system for UPnP devices. Our novel framework automatically creates a honeypot from UPnP device description documents and is extendable to any device types or vendors that use UPnP for communication. To the best of our knowledge, this is the first work towards a flexible and configurable honeypot framework for UPnP-based IoT devices. We released U-PoT under an open source license for further research on IoT security and created a database of UPnP device descriptions. We also evaluated our framework on two emulated deices. Our experiments show that the emulated devices are able to mimic the behavior of a real IoT device and trick vendor-provided device management applications or popular IoT search engines while having minimal performance ovherhead. Muhammad A. Hakim, Hidayet Aksu, A. Selcuk Uluagac, Kemal Akkaya |
IPCCC | 3 |
| 2018 | Sensitive Information Tracking in Commodity IoT
Z. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu, Gang Tan, Patrick D. McDaniel, A. Selcuk Uluagac |
USENIX Security Symposium | 7 |
| 2018 | Drone-Assisted Multi-Purpose Roadside Units for Intelligent Transportation SystemsabstractAs drones are becoming prevalent to be deployed in various civic applications, there is a need to integrate them into efficient and secure communications with the existing infrastructure. In this paper, considering emergency scenarios for intelligent transportation applications, we design a secure hybrid communication infrastructure for mobile road-side units (RSUs) that are based on drones. The architecture tackles interoperability issues when Dedicated Short Range Communications (DSRC), wireless mesh, and LTE need to coexist for coordination. Specifically, we propose a novel tunneling protocol to integrate LTE with IEEE 802.11s mesh network. In addition, we ensure that only legitimate users can connect and control the mobile RSUs by integrating an authentication framework built on top of the recent OAuth 2.0 standard. A detailed communication protocol is proposed within the elements of the architecture from vehicles to control center for emergency operations. The proposed secure architecture is implemented in ns-3 and tested for its performance under heavy multimedia traffic. The results indicate that the proposed hybrid architecture can enable smooth multimedia traffic delivery via the mobile RSU. Nico Saputro, Kemal Akkaya, Ramazan Algin, A. Selcuk Uluagac |
VTC Fall | 4 |
| 2018 | Privacy-preserving protocols for secure and reliable data aggregation in IoT-enabled Smart Metering systems
Samet Tonyali, Kemal Akkaya, Nico Saputro, A. Selcuk Uluagac, Mehrdad Nojoumian |
Future Gener. Comput. Syst. | 4 |
| 2017 | Identifying counterfeit smart grid devices: A lightweight system level frameworkabstractThe use of counterfeit smart grid devices throughout the smart grid communication infrastructure represents a real problem. Hence, monitoring and early detection of counterfeit smart grid devices is critical for protecting smart grid's components and data. To address these concerns, in this paper, we introduce a novel system level approach to identify counterfeit smart grid devices. Specifically, our approach is a configurable framework that combines system and function call tracing techniques and statistical analysis to detect counterfeit smart grid devices based on their behavioural characteristics. Moreover, we measure the efficacy of our framework with a realistic testbed that includes both resource-limited and resource-rich counterfeit devices. In total, we analyze six different counterfeit devices in our testbed. The devices communicate via an open source version of the IEC61850 protocol suite (i.e., libiec61850). Experimental results reveal an excellent rate on the detection of smart grid counterfeit devices. Finally, the performance analysis demonstrates that the use of the proposed framework has minimal overhead on the smart grid devices' computing resources. Leonardo Babun, Hidayet Aksu, A. Selcuk Uluagac |
ICC | 3 |
| 2017 | Cybergrenade: Automated Exploitation of Local Network Machines via Single Board ComputersabstractIn this paper, we introduce a defensive cybersecurity framework called Cybergrenade automating various penetration testing tools to sequentially exploit machines connected to a single local network, all underneath a single application running on a Single-Board Computer (SBC). This takes advantage of the SBC's unique capabilities in a way that manual exploitation simply cannot match. Currently, while many SBCs are being used in research as exploitation tool-kits, the current state of automation of the processes associated with exploitation leaves much to be desired. While this paper describes the Cybergrenade Framework, it can be used as a guideline for future research automating the exploitation process. Cybergrenade allows tools such as Nmap, OpenVAS, and Metasploit tools to be automatically utilized under one framework. Our experimental evolution revealed that Cybergrenade can perform the automation of various pentesting tools under a single application with ease. Anurag Akkiraju, David Gabay, Halim Burak Yesilyurt, Hidayet Aksu, A. Selcuk Uluagac |
MASS | 5 |
| 2017 | 6thSense: A Context-aware Sensor-based Attack Detector for Smart Devices
Amit Kumar Sikder, Hidayet Aksu, A. Selcuk Uluagac |
USENIX Security Symposium | 3 |
| 2016 | A novel storage covert channel on wearable devices using status bar notificationsabstractCovert channels have been used as a means to circumvent security measures and send sensitive data undetectable to an onlooker. Many covert channels in Android systems have been documented utilizing various system resources or settings available to the entire system. Nonetheless, this paper introduces a new storage covert channel on the emerging field of wearables that sends data to other applications, or even to other nearby devices, through the use of notifications that are normally displayed on the status bar of an Android device. In this paper, we present the design of our ongoing work for this covert channel using Android-based wearable devices. Furthermore, we evaluate the performance of this covert channel using real equipment. Our evaluation demonstrates the functionality and feasibility of the proposed covert channel. Kyle Denney, A. Selcuk Uluagac, Kemal Akkaya, Shekhar Bhansali |
CCNC | 2 |
| 2016 | A reliable data aggregation mechanism with Homomorphic Encryption in Smart Grid AMI networksabstractOne of the most common methods to preserve consumers' private data is using secure in-network data aggregation. The security can be provided through the emerging fully (FHE) or partial (PHE) homomorphic encryption techniques. However, an FHE aggregation scheme generates significantly big-size data when compared to traditional encryption methods. The overhead is compounded in hierarchical networks such as Smart Grid Advanced Metering Infrastructure (AMI) as data packets are routed towards the core of the AMI networking infrastructure from the smart meters. In this paper, we first investigate the feasibility and performance of FHE aggregation in AMI networks utilizing the reliable data transport protocol, TCP. Then, we introduce the packet reassembly problem. To address this challenge, we propose a novel packet reassembly mechanism for TCP. We evaluated the effectiveness of our proposed mechanism using both PHE and FHE-based aggregation approaches in AMI in terms throughput and end-to-end delay on an 802.11s-based wireless mesh network by using the ns-3 network simulator. The results indicate significant gains in terms of delay and bandwidth usage with the proposed mechanism. Samet Tonyali, Kemal Akkaya, Nico Saputro, A. Selcuk Uluagac |
CCNC | 4 |
| 2016 | Software defined networking for resilient communications in Smart Grid active distribution networksabstractEmerging Software Defined Networking (SDN) technology provides excellent flexibility to large-scale networks in terms of control, management, security, and maintenance. In this paper, we propose an SDN-based communication infrastructure for Smart Grid distribution networks among substations. A Smart Grid communication infrastructure consists of a large number of heterogenous devices that exchange real-time information for monitoring the status of the grid. We then investigate how SDN-enabled Smart Grid infrastructure can provide resilience to active distribution substations with self-recovery. Specifically, by introducing redundant and wireless communication links that can be used during the emergencies, we show that SDN controllers can be effective for restoring the communication while providing a lot of flexibility. Furthermore, to be able to effectively evaluate the performance of the proposed work in terms of various fine-grained network metrics, we developed a Mininet-based testing framework and integrated it with ns-3 network simulator. Finally, we conducted experiments by using actual Smart Grid communication data to assess the recovery performance of the proposed SDN-based system. The results show that SDN is a viable technology for the Smart Grid communications with almost negligible delays in switching to backup wireless links during the times of link failures in reliable fashion. Abdullah Aydeger, Kemal Akkaya, Mehmet Hazar Cintuglu, A. Selcuk Uluagac, Osama Mohammed 0001 |
ICC | 4 |
| 2016 | Drones for smart cities: Issues in cybersecurity, privacy, and public safetyabstractIt is expected that drones will take a major role in the connected smart cities of the future. They will be delivering goods and merchandise, serving as mobile hot spots for broadband wireless access, and maintaining surveillance and security of smart cities. However, pervasive use of drones for future smart cities also brings together several technical and societal concerns and challenges that needs to be addressed, including in the areas of cybersecurity, privacy, and public safety. Drones, while can be used for the betterment of the society, can also be used by malicious entities to conduct physical and cyber attacks, and threaten the society. The goal of this survey paper is to review various aspects of drones in future smart cities, relating to cybersecurity, privacy, and public safety. We will also provide representative results on cyber attacks using drones. Edwin Vattapparamban, Ismail Güvenç, Ali Ihsan Yurekli, Kemal Akkaya, A. Selcuk Uluagac |
IWCMC | 5 |
| 2016 | A simple visualization and programming framework for wireless sensor networks: PROVIZ
Shruthi Ravichandran, Ramalingam K. Chandrasekar, A. Selcuk Uluagac, Raheem A. Beyah |
Ad Hoc Networks | 3 |
| 2015 | Information Leakage in Encrypted IP Video TrafficabstractVoice chat and conferencing services may be assumed to be private and secure because of strong encryption algorithms applied to the video stream. We show that information leakage is occurring in video over IP traffic, including for encrypted payloads. It is possible to detect motion and scene changes, such as a person standing up or walking past a camera streaming live video. We accomplish this through analysis of network traffic metadata including arrival time between packets, packet sizes, and video stream bandwidth. Event detection through metadata analysis is possible even when common encryption techniques are applied to the video stream such as SSL or AES. We have observed information leakage across multiple codes and cameras. Through measurements of the x264 codec, we establish a basis for detectability of events via packet timing. Our laboratory experiments confirm that this event detection is possible and repeatable with commercial video streaming software. Christopher Wampler, A. Selcuk Uluagac, Raheem A. Beyah |
GLOBECOM | 2 |
| 2015 | InterSec: An interaction system for network security applicationsabstractTraditional two-dimensional (2D) and three-dimensional (3D) visualization tools for network security applications often employ a desktop, mouse, and keyboard setup of WIMP (Windows, Icons, Menus, and a Pointer) interfaces, which use a serial set of command inputs (e.g., click, rotate, zoom). However, research has shown that multiple inputs (e.g., Microsoft Kinect [8] and multi-touch monitors) could reduce the selection time of objects, resulting in a quicker response time than its traditional counterparts. In this work, we investigate these alternative user interfaces that are “natural” to the user for multiple inputs that reduce response time as a user navigates within a complex three-dimensional (3D) visualization for network security applications. Specifically, we introduce a visualization tool called InterSec, an interaction system prototype for interacting with 3D network security visualizations. InterSec helps developers build and manage gestures that require the coordination of multiple inputs across multiple interaction technologies. To our knowledge, InterSec is the first tool that proposes a system to reduce number of interactions within 3D visualizations for network security tools. Through our evaluation of live Honeynet data and a user study, the results reveal InterSec's ability to reduce the number of interactions to aid in 3D navigation in comparison to the mouse user interface. Troy J. Nunnally, A. Selcuk Uluagac, Raheem A. Beyah |
ICC | 2 |
| 2015 | GTID: A Technique for Physical Device and Device Type FingerprintingabstractIn this paper, we introduce GTID, a technique that can actively and passively fingerprint wireless devices and their types using wire-side observations in a local network. GTID exploits information that is leaked as a result of heterogeneity in devices, which is a function of different device hardware compositions and variations in devices' clock skew. We apply statistical techniques on network traffic to create unique, reproducible device and device type signatures, and use artificial neural networks (ANNs) for classification. We demonstrate the efficacy of our technique on both an isolated testbed and a live campus network (during peak hours) using a corpus of 37 devices representing a wide range of device classes (e.g., iPads, iPhones, Google Phones, etc.) and traffic types (e.g., Skype, SCP, ICMP, etc.). Our experiments provided more than 300 GB of traffic captures which we used for ANN training and performance evaluation. In order for any fingerprinting technique to be practical, it must be able to detect previously unseen devices (i.e., devices for which no stored signature is available) and must be able to withstand various attacks. GTID is a fingerprinting technique to detect previously unseen devices and to illustrate its resilience under various attacker models. We measure the performance of GTID by considering accuracy, recall, and processing time and also illustrate how it can be used to complement existing security mechanisms (e.g., authentication systems) and to detect counterfeit devices. Sakthi Vignesh Radhakrishnan, A. Selcuk Uluagac, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | S-MATCH: Verifiable Privacy-Preserving Profile Matching for Mobile Social ServicesabstractMobile social services utilize profile matching to help users find friends with similar social attributes (e.g., interests, location, background). However, privacy concerns often hinder users from enabling this functionality. In this paper, we introduce S-MATCH, a novel framework for privacy-preserving profile matching based on property-preserving encryption (PPE). First, we illustrate that PPE should not be considered secure when directly used on social attribute data due to its key-sharing problem and information leakage problem. Then, we address the aforementioned problems of applying PPE to social network data and develop an efficient and verifiable privacy-preserving profile matching scheme. We implement both the client and server portions of S-MATCH and evaluate its performance under three real-world social network datasets. The results show that S-MATCH can achieve at least one order of magnitude better computational performance than the techniques that use homomorphic encryption. Xiaojing Liao, A. Selcuk Uluagac, Raheem A. Beyah |
DSN | 2 |
| 2014 | Efficient safety message forwarding using multi-channels in low density VANETsabstractVehicular Ad-hoc networks (VANETs) provide a way for a vehicle to deliver various types of information to users or drivers in other vehicles. Distributing a large amount of information such as multimedia messages in a single control channel makes the control channel easily congested. Transmitting multimedia messages through multi-channel to avoid this congestion becomes a feasible solution. However, low-connectivity in a low vehicle density in multi-channel poses unique challenges and can produce connection failure if this issue is not carefully addressed. In this paper, a network coding technique with divide-and-deliver is introduced to solve this unique challenge for delivering multimedia contents through multiple service channels in a low vehicle density. Through the rigorous analytical derivation and extensive simulation, we show the proposed scheme significantly improves reliability with minimum usage of the control channels in a typical VANETs environment. Jinyoun Cho, A. Selcuk Uluagac, John A. Copeland, Yusun Chang |
GLOBECOM | 2 |
| 2014 | Cryptographically-Curated File System (CCFS): Secure, inter-operable, and easily implementable Information-Centric NetworkingabstractCryptographically-Curated File System (CCFS) proposed in this work supports the adoption of Information-Centric Networking. CCFS utilizes content names that span trust boundaries, verify integrity, tolerate disruption, authenticate content, and provide non-repudiation. Irrespective of the ability to reach an authoritative host, CCFS provides secure access by binding a chain of trust into the content name itself. Curators cryptographically bind content to a name, which is a path through a series of objects that map human meaningful names to cryptographically strong content identifiers. CCFS serves as a network layer for storage systems unifying currently disparate storage technologies. The power of CCFS derives from file hashes and public keys used as a name with which to retrieve content and as a method of verifying that content. We present results from our prototype implementation. Our results show that the overhead associated with CCFS is not negligible, but also is not prohibitive. Aaron D. Goldman, A. Selcuk Uluagac, John A. Copeland |
LCN | 2 |
| 2013 | Realizing an 802.11-based covert timing channel using off-the-shelf wireless cardsabstractBy using covert channels, a malicious entity can hide messages within regular traffic and can thereby circumvent security mechanisms. This same method of obfuscation can be used by legitimate users to transmit messages over hostile networks. A promising area for covert channels is wireless networks employing carrier sense multiple access with collision avoidance (CSMA/CA) (e.g., 802.11 networks). These schemes introduce randomness in the network that provides good cover for a covert timing channel. Hence, by exploiting the random back-off in distributed coordination function (DCF) of 802.11, we realize a relatively high bandwidth covert timing channel for 802.11 networks, called Covert-DCF. As opposed to many works in the literature focusing on theory and simulations, Covert-DCF is the first fully implemented covert timing channel for 802.11 MAC using off-the-self wireless cards. In this paper, we introduce the design and implementation of Covert-DCF that is transparent to the users of the shared medium. We also evaluate the performance of Covert-DCF and provide discussions on the feasibility of this technique in a real world scenario. Sakthi Vignesh Radhakrishnan, A. Selcuk Uluagac, Raheem A. Beyah |
GLOBECOM | 2 |
| 2013 | P3D: A parallel 3D coordinate visualization for advanced network scansabstractAs network attacks increase in complexity, network administrators will continue to struggle with analyzing security data immediately and efficiently. To alleviate these challenges, researchers are looking into various visualization techniques (e.g., two-dimensional (2D) and three-dimensional (3D)) to detect, identify, and analyze malicious attacks. This paper discusses the benefits of using a stereoscopic 3D parallel visualization techniques for network scanning, in particular, when addressing occlusion-based visualization attacks intended to confuse network administrators. To our knowledge, no 2D or 3D tool exists that analyzes these attacks. Hence, we propose a novel 3D Parallel coordinate visualization tool for advanced network scans and attacks called P3D. P3D uses flow data, filtering techniques, and state-of-the art 3D technologies to help network administrators detect distributed and coordinated network scans. Compared to other 2D and 3D network security visualization tools, P3D prevents occlusion-based visualization attacks (e.g., Windshield Wiper and Port Source Confusion attacks). We validate our tool with use-cases from emulated distributed scanning attacks. Our evaluation shows P3D allows users to extract new information about scans and minimize information overload by adding an extra dimension and awareness region in the visualization. Troy J. Nunnally, Penyen Chi, Kulsoom Abdullah, A. Selcuk Uluagac, John A. Copeland, Raheem A. Beyah |
ICC | 4 |
| 2013 | Examining the characteristics and implications of sensor side channelsabstractThe nodes in wireless sensor networks (WSNs) utilize the radio frequency (RF) channel to communicate. Given that the RF channel is the primary communication channel, many researchers have developed techniques for securing that channel. However, the RF channel is not the only interface into a sensor. The sensing components, which are primarily designed to sense characteristics about the outside world, can also be used (or misused) as a communication (side) channel. In this paper, we characterize the side channels for various sensory components (i.e., light sensor, acoustic sensor, and accelerometer). While previous work has focused on the use of these side channels to improve the security and performance of a WSN, we seek to determine if the side channels have enough capacity to potentially be used for malicious activity. Specifically, we evaluate the feasibility and practicality of the side channels using today's sensor technology and illustrate that these channels have enough capacity to enable the transfer of common, well-known malware. The ultimate goal of this work is to illustrate the need for intrusion detection systems (IDSs) that not only monitor the RF channel, but also monitor the values returned by the sensory components. Venkatachalam Subramanian, A. Selcuk Uluagac, Hasan Çam, Raheem A. Beyah |
ICC | 2 |
| 2013 | NAVSEC: a recommender system for 3D network security visualizationsabstractAs network attacks increase in complexity, the ability to quickly analyze security data and mitigate the effect of these attacks becomes a difficult problem. To alleviate these challenges, researchers are looking into various two-dimensional (2D) and three-dimensional (3D) visualization tools to detect, identify, and analyze malicious attacks. These visualization tools often require advanced knowledge in networking, visualization, and information security to operate, navigate, and successfully examine malicious attacks. Novice users, deficient in the required advanced knowledge, may find navigation within these visualization tools difficult. Furthermore, expert users may be limited and costly. We discuss the use of a modern recommender system to aid in navigating within a complex 3D visualization for network security applications. We developed a visualization module called NAVSEC, a recommender system prototype for navigating in 3D network security visualization tools. NAVSEC recommends visualizations and interactions to novice users. Given visualization interaction input from a novice user and expert communities, NAVSEC is instrumental in reducing confusion for a novice user while navigating in a 3D visualization. We illustrate NAVSEC with a use-case from an emulated stealthy scanning attack disguised as a file transfer with multiple concurrent connections. We show that using NAVSEC, a novice user's visualization converges towards a visualization used to identify or detect a suspected attack by an expert user. As a result, NAVSEC can successfully guide the novice user in differentiating between complex network attacks and benign legitimate traffic with step-by-step created visualizations and suggested user interactions. Troy J. Nunnally, Kulsoom Abdullah, A. Selcuk Uluagac, John A. Copeland, Raheem A. Beyah |
VizSEC | 3 |
| 2013 | Cell-based snapshot and continuous data collection in wireless sensor networksabstractData collection is a common operation of wireless sensor networks (WSNs). The performance of data collection can be measured by its achievable network capacity. However, most existing works focus on the network capacity of unicast, multicast or/and broadcast. In this article, we study the snapshot/continuous data collection (SDC/CDC) problem under the physical interference model for randomly deployed dense WSNs. For SDC, we propose a Cell-Based Path Scheduling (CBPS) algorithm based on network partitioning. Theoretical analysis shows that its achievable network capacity is order-optimal. For CDC, a novel Segment-Based Pipeline Scheduling (SBPS) algorithm is proposed which combines the pipeline technique and the compressive data gathering technique. Theoretical analysis shows that SBPS significantly speeds up the CDC process and achieves a high network capacity. Shouling Ji, Selena He, A. Selcuk Uluagac, Raheem A. Beyah, Yingshu Li 0001 |
ACM Trans. Sens. Networks | 3 |
| 2013 | Secure SOurce-BAsed Loose Synchronization (SOBAS) for Wireless Sensor NetworksabstractWe present the Secure SOurce-BAsed Loose Synchronization (SOBAS) protocol to securely synchronize the events in the network, without the transmission of explicit synchronization control messages. In SOBAS, nodes use their local time values as a one-time dynamic key to encrypt each message. In this way, SOBAS provides an effective dynamic en-route filtering mechanism, where the malicious data is filtered from the network. With SOBAS, we are able to achieve our main goal of synchronizing events at the sink as quickly, as accurately, and as surreptitiously as possible. With loose synchronization, SOBAS reduces the number of control messages needed for a WSN to operate providing the key benefits of reduced energy consumption as well as reducing the opportunity for malicious nodes to eavesdrop, intercept, or be made aware of the presence of the network. Albeit a loose synchronization per se, SOBAS is also able to provide $(7.24 \mu)$s clock precision given today's sensor technology, which is much better than other comparable schemes (schemes that do not employ GPS devices). Also, we show that by recognizing the need for and employing loose time synchronization, necessary synchronization can be provided to the WSN application using half of the energy needed for traditional schemes. Both analytical and simulation results are presented to verify the feasibility of SOBAS as well as the energy consumption of the scheme under normal operation and attack from malicious nodes. A. Selcuk Uluagac, Raheem A. Beyah, John A. Copeland |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2012 | SIMAGE: Secure and Link-Quality Cognizant Image Distribution for wireless sensor networksabstractWireless sensor networks (WSNs) are used in a range of critical domains (e.g., health care, military, critical infrastructure) where it is necessary that the nodes be reprogrammed with a new or modified code image without removing them from the deployment area. Various protocols have been developed for the dissemination of code images between sensors in multi-hop WSNs, where these sensor nodes may have varying levels of link quality. However, the code dissemination process in these protocols is hindered by the nodes with poor link quality. This results in an increased number of retransmissions and code dissemination time. Also, in several of the techniques, the code dissemination process is not secure and can be eavesdropped or disrupted by a malicious wireless sensor node in the transmission range. In this paper, we propose a simple approach, Secure and Link-Quality Cognizant Image Distribution (SIMAGE), to enhance the existing code dissemination protocol using the available resources in the sensors. Specifically, our approach adapts to the varying link conditions via dynamic packet sizing to reduce the number of retransmissions and overall code dissemination time. Our approach also provides confidentiality and integrity to the code dissemination process by utilizing energy-efficient encryption and authentication mechanisms with RC4 and the CBC-MAC. We have evaluated SIMAGE in a network of real sensors and the results show that adjusting the packet size as a function of link quality reduces the retransmitted data by 93% and the image transmission time by 35% when compared to the existing code dissemination protocols. The trade-offs between reliability, security overhead, and overall transmission time for SIMAGE are also discussed. K. C. Ramalingam, Venkatachalam Subramanian, A. Selcuk Uluagac, Raheem A. Beyah |
GLOBECOM | 3 |
| 2012 | Di-Sec: A distributed security framework for heterogeneous Wireless Sensor NetworksabstractWireless Sensor Networks (WSNs) are deployed for monitoring in a range of critical domains (e.g., health care, military, critical infrastructure). Accordingly, these WSNs should be resilient to attacks. The current approach to defending against malicious threats is to develop and deploy a specific defense mechanism for a specific attack. However, the problem with this traditional approach to defending sensor networks is that the solution for the Jamming attack does not defend against other attacks (e.g., Sybil and Selective Forwarding). In reality, one cannot know a priori what type of attack an adversary will launch. This work addresses the challenges with the traditional approach to securing sensor networks and presents a comprehensive framework, Di-Sec, that can defend against all known and forthcoming attacks. At the heart of Di-Sec lies the monitoring core (M-Core), which is an extensible and lightweight layer that gathers statistics relevant for the defense mechanisms. The M-Core allows for the monitoring of both internal and external threats and supports the execution of multiple detection and defense mechanisms (DDMs) against different threats in parallel. Along with Di-Sec, a new user-friendly domain-specific language was developed, the M-Core Control Language (MCL). Using the MCL, a user can implement new defense mechanisms without the overhead of learning the details of the underlying software architecture (i.e., TinyOS, Di-Sec). Hence, the MCL expedites the development of sensor defense mechanisms by significantly simplifying the coding process for developers. The Di-Sec framework has been implemented and tested on real sensors to evaluate its feasibility and performance. Our evaluation of memory, communication, and sensing components shows that Di-Sec is feasible on today's resource-limited sensors and has a nominal overhead. Furthermore, we illustrate the basic functionality of Di-Sec by implementing and simultaneously executing DDMs for attacks at various layers of the communication stack (i.e., Jamming, Selective Forwarding, Sybil, and Internal attacks). Marco Valero, Sang Shin Jung, A. Selcuk Uluagac, Yingshu Li 0001, Raheem A. Beyah |
INFOCOM | 3 |
| 2012 | Plugging the leaks without unplugging your network in the midst of DisasterabstractNetwork Disaster Recovery research has examined behavior of networks after disasters with an aim to restoring normal conditions. In addition to probable loss of connectivity, a disaster scenario can also lead to security risks. However, network security has been examined extensively under normal conditions, and not under conditions that ensue after disasters. Therefore, security issues should be addressed during the period of chaos after a disaster, but before operating conditions return to normal. Furthermore, security should be assured, while still allowing access to the network to enable public communication in order to assist in disaster relief efforts. In general, the desire to help with public assistance requires opening up access to the network, while security concerns add pressure to close down or limit access to the network. In this study, we show that the objectives of availability and confidentiality, two objectives that have not previously been considered together in disaster scenarios, can be simultaneously achieved. For our study, we evaluated six wireless devices with various network configurations, including a laptop, a Kindle Fire e-reader, an Android tablet, a Google Nexus phone, an IP camera, and an Apple TV, to approximate behaviors of a communication network under a disaster scenario. Actual data leakage was tracked and observed for these devices. To the best of our knowledge this has not previously been examined in a systematic manner for post-disaster scenarios. After illustrating the data leakage of various devices, we analyze the risk associated with the various types of leakage. Moving private traffic to a VPN would free the physical network for use as a public resource. Aaron D. Goldman, A. Selcuk Uluagac, Raheem A. Beyah, John A. Copeland |
LCN | 2 |
| 2012 | 3DSVAT: A 3D Stereoscopic Vulnerability Assessment Tool for network securityabstractAs the volume of network data continues to increase and networks become more complex, the ability to accurately manage and analyze data quickly becomes a difficult problem. Many network management tools already use two-dimensional (2D) and three-dimensional (3D) visualization techniques to help support decision-making and reasoning of network anomalies and activity. However, a poor user interface combined with the massive amount of data could obfuscate important network details. As a result, administrators may fail to detect and identify malicious network behavior in a timely manner. 3D visualizations address this challenge by introducing monocular and binocular visual cues to portray depth and to increase the perceived viewing area. In this work, we explore these cues for 3D network security applications, with a particular emphasis on binocular disparity or stereoscopic 3D. Currently, no network security tool takes advantage of the enhanced depth perception provided by stereoscopic 3D technologies for vulnerability assessment. Compared to traditional 3D systems, stereoscopic 3D helps improve the perception of depth, which can, in turn reduce the number of errors and increase response times of network administrators. Thus, we introduce a stereoscopic 3D visual Framework for Rendering Enhanced 3D Stereoscopic Visualizations for Network Security (FRE3DS). Our novel framework uses state-of-the art 3D graphics rendering to assist in 3D visualizations for network security applications. Moreover, utilizing our framework, we propose a new 3D Stereoscopic Vulnerability Assessment Tool (3DSVAT). We illustrate the use of 3DSVAT to assist in rapid detection and correlation of attack vulnerabilities in a subset of a modified local area network data set using the enhanced perception of depth in a stereoscopic 3D environment. Troy J. Nunnally, A. Selcuk Uluagac, John A. Copeland, Raheem A. Beyah |
LCN | 2 |
| 2012 | The Monitoring Core: A framework for sensor security application developmentabstractWireless sensor networks (WSNs) are used for the monitoring of physical and environmental phenomena, and applicable in a range of different domains (e.g., health care, military, critical infrastructure). When using WSNs in a variety of real-world applications, security is a vital problem that should be considered by developers. As the development of security applications (SAs) for WSNs require meticulous procedures and operations, the software implementation process can be more challenging than regular applications. Hence, in an effort to facilitate the design, development and implementation of WSN security applications, we introduce the Monitoring Core (M-Core). The M-Core is a modular, lightweight, and extensible software layer that gathers necessary data including the internal and the external status of the sensor (e.g., information about ongoing communications, neighbors, and sensing), and provides relevant information for the development of new SAs. Similar to other software development tools, the M-Core was developed to facilitate the design and development of new WSN SAs on different platforms. Moreover, a new user-friendly domain-specific language, the M-Core Control Language (MCL), was developed to further facilitate the use of the M-Core and reduce the developer's coding time. With the MCL, a user can implement new SAs without the overhead of learning the details of the underlying sensor software architecture (e.g., TinyOS). The M-Core has been implemented in TinyOS-2.x and tested on real sensors (Tmote Sky and MicaZ). Using the M-Core architecture, we implemented several SAs to show that the M-Core allows easy and rapid development of security programs efficiently and effectively. Marco Valero, A. Selcuk Uluagac, S. Venkatachalam, K. C. Ramalingam, Raheem A. Beyah |
MASS | 2 |
| 2010 | Time-Based DynamiC Keying and En-Route Filtering (TICK) for Wireless Sensor NetworksabstractGiven that transmission cost is significant in a Wireless Sensor Network (WSN), sending explicit keying control messages significantly increases the amount of energy consumed by each sensing device. Thus, in this paper, we address the issue of security for WSNs from a completely novel perspective. We present a technique to secure the network, without the transmission of explicit keying messages needed to avoid stale keys. Our protocol, the TIme-Based DynamiC Keying and En-Route Filtering (TICK) protocol for WSNs secures events as they occur. As opposed to current chatty schemes that incur regular keying message overhead, nodes use their local time values as a one-time dynamic key to encrypt each message. Further, this mechanism prevents malicious nodes from injecting false packets into the network. TICK is as a worst case twice more energy efficient than existing related work. Both an analytical framework and simulation results are presented to verify the feasibility of TICK as well as the energy consumption of the scheme under normal operation and attack from malicious nodes. A. Selcuk Uluagac, Raheem A. Beyah, John A. Copeland |
GLOBECOM | 1 |
| 2010 | Analysis of Varying AS Path Lengths from the Edge of the NetworkabstractUnderstanding and analyzing the past and current behavior of the Internet will be instrumental in building tomorrow's more efficient and scalable networks (e.g., the future Internet). In this paper, we study the impact of Autonomous Systems (ASs) paths' end-to-end latency. Unfortunately, due to the diverse set of non-disclosed routing policies among ASs, packets belonging to a certain end-to- end connection may traverse different ASs, causing fluctuating AS paths. Fluctuation of AS paths has been studied in the literature directly from the core of the network. In this paper, we take a different approach to the analysis of the fluctuation, solely from the edge of the network. Specifically, from the end user's perspective, some AS paths may be optimal (or better) and some sub-optimal. Furthermore, there is not a unique definition for sub- optimality as it may be reflected with various measures (e.g., latency) depending on the application requirements and expectations. In this paper we analyze fluctuating AS path lengths (ASPLs) and investigate their impact on the end-to-end latency over the Internet at a greater scale than previous studies. This study was conducted using Scriptroute to probe various PlanetLab nodes. Our results show that all of the source nodes experienced some AS path differences and the ASPL values that the sources use greatly vary. At worst, some nodes experienced different paths over 70% of the time during our measurements. We observed that the largest difference in ASPLs on a particular connection was as high as 6 with an average of 2.5. Moreover, we present real cases where ASPL and latency values are related, inversely related, and not related at all. Finally, we provide a simple definition for suboptimality and analyze the collected data against this definition. We show that overall 82% of the fluctuating paths and 9% of all the traces between source-destination pairs faced sub-optimal AS paths. A. Selcuk Uluagac, Raheem A. Beyah, Roma Kane, John A. Copeland |
ICC | 1 |
| 2010 | VEBEK: Virtual Energy-Based Encryption and Keying for Wireless Sensor NetworksabstractDesigning cost-efficient, secure network protocols for Wireless Sensor Networks (WSNs) is a challenging problem because sensors are resource-limited wireless devices. Since the communication cost is the most dominant factor in a sensor's energy consumption, we introduce an energy-efficient Virtual Energy-Based Encryption and Keying (VEBEK) scheme for WSNs that significantly reduces the number of transmissions needed for rekeying to avoid stale keys. In addition to the goal of saving energy, minimal transmission is imperative for some military applications of WSNs where an adversary could be monitoring the wireless spectrum. VEBEK is a secure communication framework where sensed data is encoded using a scheme based on a permutation code generated via the RC4 encryption mechanism. The key to the RC4 encryption mechanism dynamically changes as a function of the residual virtual energy of the sensor. Thus, a one-time dynamic key is employed for one packet only and different keys are used for the successive packets of the stream. The intermediate nodes along the path to the sink are able to verify the authenticity and integrity of the incoming packets using a predicted value of the key generated by the sender's virtual energy, thus requiring no need for specific rekeying messages. VEBEK is able to efficiently detect and filter false data injected into the network by malicious outsiders. The VEBEK framework consists of two operational modes (VEBEK-I and VEBEK-II), each of which is optimal for different scenarios. In VEBEK-I, each node monitors its one-hop neighbors where VEBEK-II statistically monitors downstream nodes. We have evaluated VEBEK's feasibility and performance analytically and through simulations. Our results show that VEBEK, without incurring transmission overhead (increasing packet size or sending control messages for rekeying), is able to eliminate malicious data from the network in an energy-efficient manner. We also show that our framework performs better than other comparable schemes in the literature with an overall 60-100 percent improvement in energy savings without the assumption of a reliable medium access control layer. A. Selcuk Uluagac, Raheem A. Beyah, Yingshu Li 0001, John A. Copeland |
IEEE Trans. Mob. Comput. | 1 |
| 2008 | Designing Secure Protocols for Wireless Sensor Networks
A. Selcuk Uluagac, Christopher P. Lee 0001, Raheem A. Beyah, John A. Copeland |
WASA | 1 |