Rajib Ranjan Maiti

dblp:72/10957 · DBLP profile ↗
← Back
16ranked-venue papers
2as first author
11since 2021 · last 2025
0000-0002-5510-8217ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 2 first-author · 9 since 2021Computer networks · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 TinyAP: An Intelligent Access Point to Combat Wi-Fi Attacks Using TinyML
abstract
In the recent past, there has been a significant surge in MAC layer Wi-Fi attacks, leaving wireless local area networks (WLANs) vulnerable to different types of network intrusions. The current routers cum access point (AP) lack the necessary intelligence to prevent or combat these attacks, thereby making it imperative to rely on various network intrusion detection systems. To address this issue, we have developed an intelligent AP that can identify different MAC layer attacks and generate alerts as required. This has been achieved using lightweight machine learning (ML) models on a microcontroller, leveraging the TensorFlow-lite-micro (TFLite Micro) libraries. A framework called TinyAP has been developed, which uses the efficient neural architecture search (NAS) and the lightweight to classify Wi-FI attack at the AP level. The system consists of a Raspberry Pi 3 B+, functioning as an AP and an Arduino Nano 33 BLE Sense acting as a plugin. The Nano module executes pretrained Tiny ML (TinyML) models, where the models are prepared (i.e., searched, trained and converted) on a Desktop PC (DESKTOP-47M82UC). We employed NAS for multilevel perceptrons (MLPNAS) to generate the five best neural architecture models to deploy on the system. To test the efficacy of this innovative approach, an online data set containing 13 different Wi-Fi-labeled attacks has been used. TinyAP has achieved an average accuracy of 96.45% for all the Wi-Fi attacks and a maximum accuracy of 100% in the 2 Class (2C) classification for some of the Wi-Fi attacks like key reinstallation attack and Kr00k. Additionally, TinyAP has also shown a maximum accuracy of 95.19% in multiclass classification. The average accuracy of TinyAP shows a marginal reduction of 0.76% in 2C classification and 0.04% in multiclass classification when compared with multilayer perceptron (MLP) models. The promising result of the TinyAP is that it provides a much-needed layer of protection for networks and offers a proactive security solution at the AP level.
Anand Agrawal, Rajib Ranjan Maiti
IEEE Internet Things J.2
2025 Discovering Attack Signature and Its Travel Path using Graphical Model in CPS: A Case Study
abstract
Cyber Physical Systems (CPSs) have a larger attack surface due to the integration of unprotected sensors and actuators into cyber infrastructure and hence a significant amount of research effort is devoted to address the problems of cyber attacks on these systems. In this article, we address the problem of discovering the signatures of a broad type of cyber attacks that can be launched by a remote attacker using malware on an operational CPS. Our aim is to efficiently detect and prevent such attacks at the boundary of cyber infrastructure and before the payloads can actually cause any damage to the system. In particular, we have considered a large dataset of an operational and popular CPS testbed, called SWaT (Secure Water Treatment), where a number of such cyber attacks have been launched and the network traces, without any specific evidence of such attacks, have been made public recently so that effective security solutions can be developed. We have proposed an effective method to analyze the traffic to discover the signatures of these cyber attacks. Our method has discovered an exact set of signatures based on the packets of Common Industrial Protocol (CIP) in EtherNet/Industrial Protocol stack (ENIP/CIP) of all “sensor reading distortion” and “actuator state alteration” attacks present in SWaT.A6_Dec2019 dataset for the first time in this article. Leveraging these signatures, we have proposed an algorithm that takes as input a network trace file containing ENIP/CIP packets and a set of signatures and automatically generates as output a graphical model of the cyber infrastructure of SWaT without using any background information and the path in the model that the signatures travel. Our analysis of computational time to execute the algorithm shows that the processing of raw network trace files, a step in the algorithm, consumes a considerable amount of time. Hence, we have developed a set of rules using the signatures and deployed them in Suricata, a well-known and well-adopted rules-based network intrusion detection system, to generate effective alert logs. We found that the rules in Suricata can produce alerts with zero false positives and false negatives in the SWaT.A6_Dec2019 dataset and in three other SWaT datasets for the two types of attacks.
Praneeta Maganti, Paresh Saxena, Rajib Ranjan Maiti
ACM Trans. Cyber Phys. Syst.3
2024 POSTER: iTieProbe: Is IoT Device Provisioning secure against MAC Layer authentication-token based replay attacks?
abstract
IoT device provisioning is the process of setting up headless IoT devices with their companion mobile apps. IoT vendors and manufacturers have the flexibility of different provisioning methods, one of them being the Access Point (AP) pairing mode over Wi-Fi, and hence, they can derive existing Wi-Fi threats and add new ones. AP pairing mode provisioning shares critical information about the Wi-Fi router or sends an authentication token associated with the user's cloud account, which may lead to vulnerabilities. In this paper, we have designed and developed a vulnerability testing tool called "iTieProbe". iTieProbe captures the Wi-Fi traffic to check the provisioning of commercial IoT devices and has the capability to extract critical security parameters. Further, iTieprobe selectively crafts the captured Wi-Fi packets and replays them to test three different vulnerabilities (V1- V3): i) In V1- iTieprobe replays the Wi-Fi packets outside the lifetime of the authentication token without any manipulation, ii) In V2 - iTieprobe replays within the lifetime of the authentication token without any manipulation in the Wi-Fi packets, iii) In V3- iTieprobe meticulously crafts the selected UDP packets and then replays it within the lifetime of the authentication token. The effect of these vulnerabilities ranges from a simple denial of service by a legitimate user not being able to provision the IoT device to a more severe one, where an adversary can set up the IoT devices. We have evaluated the efficacy of iTieprobe against two commercial IoT devices, IoT Haat Smart Plug and Wipro Smart Plug, that are using Tuya-based implementations for their provisioning. We believe this work will help the vendors to improve their provisioning methods.
Anand Agrawal, Rajib Ranjan Maiti
AsiaCCS2
2024 Guarding the Wi-Fi 4-Way Handshake against Channel-based MiTM: A Case Study on KRACK Attack
abstract
In the rapidly evolving digital age, the security of wireless networks is paramount. In this paper, we present a comprehensive analysis and defense mechanism against Key Reinstallation Attacks (KRACKs) targeting the Wi-Fi Protected Access II (WPA2) protocol suite. WPA2 is vulnerable to KRACK, where an attacker replays a specific set of packets in the 4-way handshake used in WPA2 to install a Pairwise Transient Key (PTK) in both the client and Access Point (AP). We have proposed a scheme to add a channel feature in the packets that are exchanged in the 4-way handshake to guard against channel-based Man-in-The-Middle (MiTM), which is an essential pre-condition for KRACK. In particular, we propose to integrate message 1 (\emphmsg-1 ) and message 3 (\emphmsg-3 ) of handshake with the channel number that has been advertised in the beacon frames. In addition to the predefined parameters in the msg-1 and msg-3, the AP sends an authenticated channel number to the client. On receiving, the client first validates the authenticated channel number and then processes the other parameters in these two messages. This paper details the implementation and evaluation of our solution, demonstrating its effectiveness in thwarting KRACK without compromising network performance or user convenience.
Anand Agrawal, Rajib Ranjan Maiti
CODASPY2
2024 IoTFuzzSentry: Hunting Bugs In The IoT Wilderness In Operational Phase Using Payload Fuzzing
abstract
In the operational phase, an IoT device runs a light-weight server that is responsible for responding to the user queries, like accessing video and taking a snap in a IoT camera. The flaws in the implementation of certain security mechanisms in these IoT devices can lead to varying level of security threats. In this paper, we address the problems of discovering such vulnerabilities using effective fuzzing via crafted transport and upper layer protocol packets in IoT communication. We have designed and developed a mutation-based fuzzing tool, named IoTFuzzSentry, to discover certain non-trivial vulnerabilities in commercial IoT devices and demonstrate their potential exploits. We have used IoT devices, like IP cameras and Smart Plug. We have categorized the vulnerabilities into four types (IoT Credential Leakage (\mathcalV 1), Sneak IP camera live video stream (\mathcalV 2), Creep Live IoT Image (\mathcalV 3), IoT Command Injection (\mathcalV 4)) and show their exploits using three IoT devices. We have reported all these vulnerabilities to respective vendors via email. We believe that our IoTFuzzSentry has a great potential to discover such unconventional security threats and allow IoT vendors to strengthen the security of their commercialized devices.
Priyanka Rushikesh Chaudhary, N. Pranav Krishna, Rajib Ranjan Maiti
CODASPY3
2024 iTieProbe: How Vulnerable Your IoT Provisioning via Wi-Fi AP Mode or EZ Mode?
abstract
IoT provisioning is a critical phase in IoT communication, where a number of security parameters are exchanged that are used both in this phase and later. Due to the headless nature of IoT devices, the exchange of these parameters faces challenges of balancing security and convenience. Some proprietary (e.g., “SmartConfig” by Texas Instruments) and open de-facto standards (e.g., AP mode and EZ mode by Tuya Inc.) are proposed to address these challenges, leaving scopes for certain vendor-specific settings. The analysis of vulnerability and threats thereby is a challenging task due to the lack of a common model of IoT provisioning in commercial IoT devices over Wi-Fi AP mode and EZ mode. In this paper, we propose a model using a sequence diagram for such provisioning and fuse seven research questions (RQs) to discover vendor-agnostic vulnerabilities. We develop a system, called iTieProbe to resolve the RQs. We discover six non-trivial potential vulnerabilities, identified as$\mathcal {V}1$to$\mathcal {V}6$. We evaluate the efficacy of testing these six vulnerabilities using iTieProbe by applying it to nine commercial IoT devices that include seven types, like a smart plug, IoT doorbell, spy bulb, smart speaker, spy clock, smart camera, and air quality monitor. We show that using iTieProbe, among others, an attacker can find$\mathcal {V}1$- leads to access neighbor’s Wi-Fi AP - in five devices,$\mathcal {V}3$and$\mathcal {V}4$in three devices, and$\mathcal {V}5$and$\mathcal {V}6$- both lead to successful provisioning using either an expired authentication token or a valid token belonging to an attacker - in three devices. We have reported all these vulnerabilities to respective vendors via email and received acknowledgment from some of them with three registered vulnerability (CVE-2024-7408, CVE-2024-46040, CVE-2024-46041). The average runtime of iTieProbe to test a vulnerability of any individual IoT provisioning is about 48.95 seconds, which is much less than the provisioning itself (typically in the range of a few minutes). We believe that our revelation can help the vendors or the developers of these IoT devices to fix the security vulnerabilities in their implementations of the provisioning.
Anand Agrawal, Rajib Ranjan Maiti
IEEE Trans. Inf. Forensics Secur.2
2023 CheckShake: Passively Detecting Anomaly in Wi-Fi Security Handshake Using Gradient Boosting Based Ensemble Learning
abstract
Recently, a number of attacks have been demonstrated (like key reinstallation attack, called KRACK) on WPA2 protocol suite in Wi-Fi WLAN, for which a patching is often challenging. In this article, we design and implement a system, called CheckShake, to passively detect anomalies in the handshake of Wi-Fi security protocols, in particular WPA2, between a client and an AP using COTS radios. Our proposed system works without decrypting any traffic and sniffing on multiple channels in parallel. It uses a state machine model for grouping Wi-Fi handshake packets and then perform deep packet inspection to identify the symptoms of the anomaly in specific stages of a handshake session. Our implementation of CheckShake does not require any modification to the firmware of the client or the AP or the COTS devices, it only requires to be physically placed within the range of the AP and its clients. We use both the publicly available dataset and our own data set for performance analysis of CheckShake. Using gradient boosting-based supervised machine learning (ML) models, we show that an accuracy around 98.50% with no false positive can be achieved using CheckShake in open sourced data that has non-zero probability of missing packets per group of packets.
Anand Agrawal, Urbi Chatterjee, Rajib Ranjan Maiti
IEEE Trans. Dependable Secur. Comput.3
2023 Mitigating Adversarial Attacks on Data-Driven Invariant Checkers for Cyber-Physical Systems
abstract
The use ofinvariantsin developing security mechanisms has become an attractive research area because of their potential to both prevent attacks and detect attacks in Cyber-Physical Systems (CPS). In general, an invariant is a property that is expressed using design parameters along with Boolean operators and which always holds in normal operation of a system, in particular, a CPS. Invariants can be derived by analysing operational data of various design parameters in a running CPS, or by analysing the system's requirements/design documents, with both of the approaches demonstrating significant potential to detect and prevent cyber-attacks on a CPS. While data-driven invariant generation can be fully automated, design-driven invariant generation has a substantial manual intervention. In this paper, we aim to highlight the shortcomings in data-driven invariants by demonstrating a set of adversarial attacks on such invariants. We propose a solution strategy to detect such attacks by complementing them with design-driven invariants. We perform all our experiments on a real water treatment testbed. We shall demonstrate that our approach can significantly reduce false positives and achieve high accuracy in attack detection on CPSs.
Rajib Ranjan Maiti, Cheah Huei Yoong, Venkata Reddy Palleti, Arlindo Silva, Christopher M. Poskitt
IEEE Trans. Dependable Secur. Comput.1
2022 kTRACKER: Passively Tracking KRACK using ML Model
abstract
Recently, a number of attacks have been demonstrated (like key reinstallation attack, called KRACK) on WPA2 protocol suite in Wi-Fi WLAN. In this paper, we design and implement a system, called kTRACKER, to passively detect anomalies in the handshake of Wi-Fi security protocols, in particular WPA2, between a client and an access point using COTS radios. A state machine model is implemented to detect KRACK attack by passively monitoring multiple wireless channels. In particular, we perform deep packet inspection and develop a grouping algorithm to group Wi-Fi handshake packets to identify the symptoms of the KRACK in specific stages of a handshake session. Our implementation of kTRACKER does not require any modification to the firmware of the supplicant i.e., client or the authenticator i.e., access point or the COTS devices, our system just needs to be in the accessible range from clients and access points. We use a publicly available dataset for performance analysis of kTRACKER. We employ gradient boosting-based supervised machine learning models, and show that an accuracy around 93.39% and a false positive rate of 5.08% can be achieved using kTRACKER.
Anand Agrawal, Urbi Chatterjee, Rajib Ranjan Maiti
CODASPY3
2022 Demystifying Video Traffic from IoT (Spy) Camera using Undecrypted Network Traffic
abstract
Video traffic can create significant privacy and security threats to an organization or a smart home. Integration of IoT cameras has increased this problem manifold especially when there is no clear distinction among the protocols that can be used in IoT cameras and traditional video streaming or sharing applications. In this paper, we initiate a study on distinguishing video traffic in IoT cameras from that in video conferencing or sharing applications. We have used three IoT cameras, four video conferencing applications and two video sharing platforms to collect network traffic at network and above layers. We found a number of protocols like Real-time Transport Protocol, QUIC protocol, UDT protocol and TLS protocols that are used for transferring video traffic in these applications. We found that the protocols that carry IoT camera traffic have significantly different characteristics compared to that in video conferencing and sharing applications, e.g., in terms of video codec.
Priyanka Rushikesh Chaudhary, Avinash Narasimhan, Rajib Ranjan Maiti
CODASPY3
2021 Deriving invariant checkers for critical infrastructure using axiomatic design principles
abstract
Abstract Cyber-physical systems (CPSs) in critical infrastructure face serious threats of attack, motivating research into a wide variety of defence mechanisms such as those that monitor for violations ofinvariants, i.e. logical properties over sensor and actuator states that should always be true. Many approaches for identifying invariants attempt to do so automatically, typically using data logs, but these can miss valid system properties if relevant behaviours are not well-represented in the data. Furthermore, as the CPS is already built, resolving any design flaws or weak points identified through this process is costly. In this paper, we propose a systematic method for deriving invariants from an analysis of a CPSdesign, based on principles of the axiomatic design methodology from design science. Our method iteratively decomposes a high-level CPS design to identify sets of dependentdesign parameters(i.e. sensors and actuators), allowing for invariants and invariant checkers to be derived in parallel to the implementation of the system. We apply our method to the designs of two CPS testbeds, SWaT and WADI, deriving a suite of invariant checkers that are able to detect a variety of single- and multi-stage attacks without any false positives. Finally, we reflect on the strengths and weaknesses of our approach, how it can be complemented by other defence mechanisms, and how it could help engineers to identify and resolve weak points in a design before the controllers of a CPS are implemented.
Cheah Huei Yoong, Venkata Reddy Palleti, Rajib Ranjan Maiti, Arlindo Silva, Christopher M. Poskitt
Cybersecur.3
2020 LoSeRO: A Locality Sensitive Routing Protocol in Opportunistic Networks with Contact Profiles
abstract
Mobility trajectories of users contain personal information that when analyzed may reveal relevant data usable as message-sharing condition, e.g., interests in common or similar mobility patterns. In particular, leveraging on mobility patterns, in [12] we designed and presented a Geo-casting routing protocol called LoSeRO for opportunistic networks, which uses knowledge of the locations most frequently visited by a user to route messages. LoSeRO forwards messages-in a multi-casting way-to all users who have a mobility profile that intersects the packet's destination zone. LoSeRO presented a relative good performance value, however, to improve its performances, in this paper our contribution is to propose an upgraded version of our earlier proposed protocol, termed as LoSeRO v2. In particular, it upgrades the traditional working fashion of LoSeRO by extending the knowledge of the most frequented locations to those users not only directly met, i.e., two-hops away. With this purpose, through simulations, we compare the performance of LoSeRO v2, with LoSeRO and other existing routing geo-casting protocols, and we illustrate how LoSeRO v2 achieves enhanced performances comparing precision, coverage and additional metrics.
Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi
IEEE Trans. Mob. Comput.2
2018 WADAC: Privacy-Preserving Anomaly Detection and Attack Classification on Wireless Traffic
abstract
In this work, we address the problem of detecting application-layer attacks on nearby wireless devices. In particular, we assume that the detection scheme is limited to link-layer traffic (either because schemes such as WPA2 are used, and the key is unknown, or to preserve user privacy). Such a setting allows us to detect attacks in nearby third party networks that we are not associated with, unlike related work that relies on wireline taps to observe traffic. We propose and implement a framework consisting of an anomaly detection module (unsupervised), and an attack classification module that identifies a known set of attacks (supervised). We evaluate our prototype with experiments including a range of attacks. For example, we demonstrate that the anomaly detector detects Mirai C&C traffic by an IoT device (without training with Mirai). In addition, we detect that the Mirai infected device is attacking other devices with 96.1% accuracy. We show that our prototype can be applied to different wireless standards (such as 802.11 (WiFi) and 802.15 (Zigbee)) and detect attacks with an accuracy of 96%-99%.
Ragav Sridharan, Rajib Ranjan Maiti, Nils Ole Tippenhauer
WISEC2
2017 Link-Layer Device Type Classification on Encrypted Wireless Traffic with COTS Radios
Rajib Ranjan Maiti, Sandra Deepthy Siby, Ragav Sridharan, Nils Ole Tippenhauer
ESORICS (2)1
2017 Private mobility-cast for opportunistic networks
Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi
Comput. Networks2
2015 Location-Based Routing for Opportunistic Networks
abstract
We tackle the problem of locality-aware message spreading in a network composed of smart mobile devices, without resorting to any backbone communication infrastructure. The motivations for our work are two-fold. First, recent smart mobile devices are capable of capturing and storing location information (at a significant granularity) by using, e.g., GPS service and storage capacity available in the devices. Second, recent studies have shown that mobility is positively correlated with the building of new social relationships, which are relatively more likely to occur for people who have visited common places in the past [2], [4], [3]. These two factors together show the importance of building proximity based communication networks, and the need of messages spreading among a targeted set of users in a network. We assume that the participating users move in a large geographic area, and a location inside the area can be uniquely identified by any user, for example, using GPS coordinates. Each user independently builds her mobility profile, called Moby Zone, considering her own past mobility traces. The Moby Zone of a user is the set of her most visited places.
Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi
MASS2