Gabriele Oligeri

dblp:74/6682 · DBLP profile ↗
← Back
50ranked-venue papers
10as first author
27since 2021 · last 2026
0000-0002-9637-0430ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 22 · 2 first-author · 9 since 2021Security and privacy · 16 · 7 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 HidePrint: Protecting Device Anonymity by Obscuring Radio Fingerprints
abstract
Radio Frequency Fingerprinting (RFF) techniques allow a receiver to authenticate a transmitter by analyzing the physical layer of the radio spectrum. Although the vast majority of scientific contributions focus on improving the performance of RFF considering different parameters and scenarios, in this work, we consider RFF as an attack vector to identify a target device in the radio spectrum. We propose, implement, and evaluate HidePrint, a solution to prevent identification through RFF without affecting the quality of the communication link between the transmitter and the receiver. HidePrint hides the transmitter's fingerprint against an illegitimate eavesdropper through the injection of controlled noise into the transmitted signal. We evaluate our solution against various state-of-the-art RFF techniques, considering several adversarial models, data from real-world communication links (wired and wireless), and protocol configurations. Our results show that the injection of a Gaussian noise pattern with a normalized standard deviation of (at least) 0.02 prevents device fingerprinting in all the considered scenarios, while affecting the Signal-to-Noise Ratio (SNR) of the received signal by only 0.1 dB. Moreover, we introduce selective radio fingerprint disclosure, a new technique that allows the transmitter to disclose the radio fingerprint to only a subset of intended receivers.
Gabriele Oligeri, Savio Sciancalepore
AsiaCCS1
2026 Radio Jamming Against Device Fingerprinting in Power Line Communications
abstract
Power Line Communication (PLC) systems are facing increasing security threats as adversaries leverage low-cost Software-Defined Radios (SDRs) to launch physical-layer attacks, e.g., jamming and Radio Frequency Fingerprinting (RFF), for communication disruption and unauthorized device tracking, respectively. This paper investigates the dual role of Radio Frequency (RF) wireless jamming for PLC environments, through two distinct scenarios: (i) friendly RF jamming for privacy preservation of (cabled) PLC devices against unauthorized RFF, and (ii) adversarial RF jamming to degrade the performance of legitimate RFF-based authentication systems. We conducted various systematic experiments using nine USRP X310 SDRs connected to actual PLC couplers exchanging signals modulated according to the Binary-Phase Shift Keying modulation scheme to analyze the behavior of RFF in PLC scenarios under different RF jamming levels. Our results demonstrate, for the first time, that strategic RF jamming effectively obscures device fingerprints in cabled PLC communications while maintaining communication quality, with bit error rates remaining acceptable across most configurations. We also demonstrate that device identification accuracy degrades significantly as the jamming intensity increases. Our findings establish fundamental trade-offs between privacy protection and authentication reliability, providing insights for the design of robust PLC systems.
Maryam Al-Malki, Gabriele Oligeri, Savio Sciancalepore, Bechir Hamdaoui, Javier Hernandez Fernandez
CCNC3
2026 Explainable Efficiency: Grad-CAM Analysis of Image-Based Radio Frequency Fingerprinting
abstract
Radio Frequency Fingerprinting (RFF) is a physical (PHY) layer security technique enabling the identification of a radio transmitter without resorting to shared secrets while combining deep learning and signal processing techniques. State-of-the-art scientific contributions focus on improving identification performance in different scenarios and configurations while considering the RFF methodology as a black-box. In this work, we apply eXplainable Artificial Intelligence (XAI) techniques to expose the discriminative features allowing a neural network model to identify radio transmitters at the PHY layer. Our analysis considers image-based RFF classifiers, where received signals (in the form of IQ symbols) are processed into images, and proves that symbols contribute unequally to the identification of the transmitter. In particular, our results demonstrate that image pre-processing can be leveraged to significantly reduce the overhead of training (up to 50%) and testing (up to 70%) without affecting the classifier's final accuracy.
Ingrid Huso, Savio Sciancalepore, Gabriele Oligeri, Giuseppe Piro, Gennaro Boggia
INFOCOM3
2026 Beyond Static Signatures: Statistical Analysis of Radio Fingerprint Mutations
abstract
Radio Frequency Fingerprinting (RFF) has emerged as a promising physical-layer technique for device identification, leveraging the hardware imperfections in radio transmitters. However, the assumption that RF fingerprints are static and persistent is increasingly challenged by recent findings. In this work, we present a comprehensive statistical analysis of radio fingerprint mutations, focusing on the impact of FPGA image reloads in Software Defined Radios (SDRs) when used as both transmitters and receivers. Our results highlight that FPGA reloads cause a subset of devices to exhibit two different persistent fingerprint states, one following a memoryless (Markovian) process and the other retaining temporal dependencies. Notably, we show that proper external synchronization between transmitter and receiver eliminates these fingerprint mutations, leading us to attribute the phenomenon to residual phase and timing errors rather than inherent hardware changes. Our work exposes the necessity of accounting for fingerprint dynamics caused by internal SDR events and synchronization, highlighting the limits of current measurement methodologies and the need for new, statistically robust approaches to physical-layer device identification.
Gabriele Oligeri, Savio Sciancalepore
WISEC1
2026 Weak-jamming detection in IEEE 802.11 networks: Techniques, scenarios and mobility
abstract
State-of-the-art solutions detect jamming attacks ex-post , i.e., only when jamming has already disrupted the wireless communication link. In many scenarios, e.g., mobile networks or static deployments distributed over a large geographical area, it is often desired to detect jamming at the early stage, when it affects the communication link enough to be detected but not sufficiently to disrupt it (detection of weak jamming signals). Under such assumptions, devices can enhance situational awareness and promptly apply mitigation, e.g., moving away from the jammed area in mobile scenarios or changing communication frequency in static deployments, before jamming fully disrupts the communication link. Although some contributions recently demonstrated the feasibility of detecting low-power and weak jamming signals, they make simplistic assumptions far from real-world deployments. Given the current state of the art, no evidence exists that detection of weak jamming can be considered with real-world communication technologies. In this paper, we provide and comprehensively analyze new general-purpose strategies for detecting weak jamming signals, compatible by design with one of the most relevant communication technologies used by commercial-off-the-shelf devices, i.e., IEEE 802.11. We describe two operational modes: (i) binary classification via Convolutional Neural Networks and (ii) one-class classification via Sparse Autoencoders. We evaluate and compare the proposed approaches with the current state-of-the-art using data collected through an extensive real-world experimental campaign in three relevant environments. At the same time, we made the dataset available to the public. Our results demonstrate that detecting weak jamming signals is feasible in all considered real-world environments, and we provide an in-depth analysis that considers different techniques, scenarios, and mobility patterns.
Martijn Hanegraaf, Savio Sciancalepore, Gabriele Oligeri
Comput. Networks3
2026 Location-based access control system for mobile devices using bluetooth low energy technology
abstract
The increasing presence of smart mobile devices in sensitive environments raises significant security and privacy concerns, particularly due to the unauthorized usage of built-in sensors such as cameras and microphones. However, space owners currently have limited means to enforce restrictions on mobile devices within their premises. To address this issue, we propose a novel location-based access control system utilizing bluetooth low energy (BLE) beacons to dynamically enforce security policies. The proposed system introduces the jumbo beacon concept, which enables fragmented transmission and reassembly of signed access control policies, overcoming BLE payload limitations. Unlike centralized enforcement models, our approach is fully decentralized, eliminating the need for a trusted central server and providing a flexible, scalable mechanism for enforcing fine-grained access policies. The system is implemented as a native security module within the Android operating system, ensuring tamper-resistant enforcement of policies while preventing unauthorized modifications. A proof-of-concept implementation demonstrates the system’s effectiveness, highlighting its real-time policy enforcement capabilities and resilience against adversarial threats. The results indicate that our approach offers a lightweight, scalable, and secure solution for enforcing location-based access control in dynamic environments.
Ahmed Khalil Abdulla, Gabriele Oligeri, Spiridon Bakiras
J. Comput. Secur.2
2025 Preventing Radio Fingerprinting through Low-Power Jamming
abstract
Radio Frequency fingerprinting enables a passive receiver to recognize and authenticate a transmitter without the need for cryptographic tools. Authentication is achieved by isolating specific features of the transmitted signal that are unique to the transmitter's hardware. Much research has focused on improving the effectiveness and efficiency of radio frequency fingerprinting to maximize its performance in various scenarios and conditions, while little research examined how to protect devices from being subject to radio fingerprinting in the wild. In this paper, we explore a novel point of view. We examine the threat posed by radio frequency fingerprinting, which facilitates the unauthorized identification of wireless devices in the field by malicious entities. We also suggest a method to sanitize the transmitted signal of its fingerprint using a low-power jammer, deployed on purpose to improve devices' anonymity on the channel while still guaranteeing the link's quality of service. Our experimental results and subsequent analysis demonstrate that a low-power jammer can effectively block a malicious eavesdropper from identifying a device without affecting the quality of the wireless link, thereby restoring the privacy of the user when accessing the radio spectrum.
Savio Sciancalepore, Gabriele Oligeri
AsiaCCS3
2025 Radio Frequency Fingerprinting: Models, Methodologies and Performance
abstract
Radio Frequency fingerprinting (RFF) is emerging as a viable alternative to authenticating radio devices, serving as a mitigation technique for spoofing and impersonation attacks on the wireless channel. RFF relies on the observation that each radio transducer features a distinctive radio fingerprint that is impractical—or even impossible—to forge by any other device.In this work, we provide an in-depth analysis of current state-of-the-art RFF approaches by comparing deep learning techniques and the associated methodologies. We consider real measurements in a controlled scenario and compare different configurations and classifiers in terms of performance and training time. Our findings show that the performance of the 11 considered classifiers is significantly biased by the methodology considered during the selection of the data for the training and testing datasets. Training and testing on different measurements or when radios are power-cycled significantly affects the accuracy of the classifier. Overall, our investigation sheds light on best practices and configurations to be considered to maximize the performance of RFF systems deployed in the wild.
Maryam Al-Malki, Savio Sciancalepore, Gabriele Oligeri
IWCMC4
2025 Device Fingerprinting in Power Line Communications
abstract
Power Line Communication (PLC) use existing electrical infrastructure for data transmission but are susceptible to security threats such as spoofing and impersonation attacks due to their open nature. This paper proposes a novel Device Fingerprinting (DF) approach for device authentication in PLC systems. The approach leverages hardware-induced imperfections in signals transmitted over power lines to identify devices based on their physical-layer characteristics. We develop a methodology that converts raw In-Phase Quadrature (IQ) samples from PLC channels into images, enabling the use of Convolutional Neural Networks for device classification. Our approach demonstrates the feasibility of CNN-based DF in PLC environments using only physical-layer information from received signals. Our experimental validation uses 8 Software Defined Radios and 2 power line couplers in real-world PLC measurements. We evaluate multiple Convolutional Neural Network (CNN) architectures and demonstrate that the PLC device fingerprint consists of two components: radio-specific and coupler-specific characteristics. The results show classification accuracy exceeding 0.9 across different configurations, establishing the viability of DF-based authentication in PLC systems without requiring additional security layers.
Javier Hernandez Fernandez, Aymen Omri, Savio Sciancalepore, Gabriele Oligeri
Ad Hoc Networks5
2025 Detection of Aerial Spoofing Attacks to LEO Satellite Systems via Deep Learning
abstract
Detecting spoofing attacks to Low-Earth-Orbit (LEO) satellite systems is a cornerstone to assessing the authenticity of the received information and guaranteeing robust service delivery in several application domains. The solutions available today for spoofing detection either rely on additional communication systems, receivers, and antennas, or require mobile deployments. Detection systems working at the Physical (PHY) layer of the satellite communication link also require time-consuming and energy-hungry training processes on all satellites of the constellation, and rely on the availability of spoofed data, which are often challenging to collect. Moreover, none of such contributions investigate the feasibility of aerial spoofing attacks launched via drones operating at various altitudes. In this paper, we first show experimentally the viability and effectiveness of spoofing attacks to LEO satellite systems using aerial attackers deployed on drones. We also propose a new spoofing detection technique, relying on pre-processing raw physical-layer signals into images and then applying anomaly detection on such images via autoencoders. We validate our solution through an extensive measurement campaign involving the deployment of an actual spoofer (Software-Defined Radio) installed on a drone and injecting rogue IRIDIUM messages while flying at different altitudes with various movement patterns. Our results demonstrate that the proposed technique can reliably detect LEO spoofing attacks launched at different altitudes, while state-of-the-art competing approaches simply fail. We also release the collected data as open source, fostering further research on satellite security.
Jos Wigchert, Savio Sciancalepore, Gabriele Oligeri
Comput. Networks3
2024 GhostBuster: Detecting Misbehaving Remote ID-Enabled Drones
abstract
Remote ID (RID) regulations soon applicable world-wide force drones to broadcast plaintext wireless messages providing, among others, their current location. However, malicious drone operators who want to stay stealthy might disclose RID messages carrying out location spoofing attacks, i.e., report forged locations, different from the actual ones. In this paper, we investigate the feasibility of using wireless localization approaches to detect drones carrying out location spoofing attacks. To this aim, we propose GhostBuster, a modular solution for detecting misbehaving RID-enabled drones, and we evaluate its performance via an extensive experimental campaign based on open-source data from actual drone flights. Through the analysis of real data in an area of$1. 5km\times 2.5km$, we show that systems integrating multiple receivers can take advantage of multiple RID messages to verify the location reported by RID-enabled drones with a success rate of 95% up to 364 meters with 12 receivers. We also show that channel conditions play a crucial role in defining the maximum achievable spoofing detection performance.
Mart Keizer, Savio Sciancalepore, Gabriele Oligeri
CCNC3
2024 FadePrint - Satellite Spoofing Detection via Fading Fingerprinting
abstract
While various methods exist to implement message authentication in different communication layers, the physical layer offers some unique and beneficial features for this purpose. Existing solutions authenticate transmitters at the physical layer by merging deep learning with physical-layer attributes, protecting against impersonation attacks. This approach requires a lengthy and resource-intensive training phase for every new transmitter that joins the network. However, for some scenarios (e.g. satellite communications), characterizing the channel experienced by the received signal might be effective in detecting impersonation. In this work, we propose FadePrint, a solution capable of detecting satellite spoofing attacks by fingerprinting the noise-fading process associated with the satellite communication channel. The fading characteristics of a satellite link differ significantly from terrestrial links (e.g., indoor), making it possible to distinguish between the two. Unlike other systems, FadePrint does not require retraining when new transducers are added to the network. We tested FadePrint with real satellite and indoor radio measurements and proved that FadePrint can effectively discriminate between a satellite transmitter and a fake indoor one, with an accuracy higher than 0.99 for all the considered configurations.
Gabriele Oligeri, Savio Sciancalepore, Alireza Sadighian
CCNC1
2024 Radio Frequency Fingerprinting via Deep Learning: Challenges and Opportunities
abstract
Radio Frequency Fingerprinting (RFF) techniques promise to authenticate wireless devices at the physical layer based on inherent hardware imperfections introduced during manufacturing. Such RF transmitter imperfections are reflected into over-the-air signals, allowing receivers to accurately identify the RF transmitting source. Recent advances in Machine Learning, particularly in Deep Learning (DL), have improved the ability of RFF systems to extract and learn complex features that make up the device-specific fingerprint. However, integrating DL techniques with RFF and operating the system in real-world scenarios presents numerous challenges, originating from the embedded systems and the DL research domains. This paper systematically identifies and analyzes the essential considerations and challenges encountered in the creation of DL-based RFF systems across their typical development life-cycle, which include (i) data collection and preprocessing, (ii) training, and finally, (iii) deployment. Our investigation provides a comprehensive overview of the current open problems that prevent real deployment of DL-based RFF systems while also discussing promising research opportunities to enhance the overall accuracy, robustness, and privacy of these systems.
Saeif Alhazbi, Ahmed Hussain 0002, Savio Sciancalepore, Gabriele Oligeri, Panagiotis Papadimitratos
IWCMC4
2024 Watch Nearby! Privacy Analysis of the People Nearby Service of Telegram
abstract
People Nearby is a service offered by Telegram that allows a user to discover other Telegram users, based only on geographical proximity. Nearby users are reported with a rough estimate of their distance from the position of the reference user, allowing Telegram to claim location privacy. In this paper, we systematically analyze the location privacy provided by Telegram to users of the People Nearby service. Through an extensive measurement campaign run by spoofing the user's location all over the world, we reverse-engineer the algorithm adopted by People Nearby to compute distances between users. Although the service protects against precise user localization, we demonstrate that location privacy is always lower than the one declared by Telegram (500~meters). Specifically, we discover that location privacy is a function of the geographical position of the user. Indeed, the radius of the location privacy area (localization error) spans between 400~meters (close to the equator) and 128~meters (close to the poles), with a difference of up to 75% (worst case) compared to what Telegram declares. After our responsible disclosure, Telegram updated the FAQ associated with the service. Finally, we provide some solutions and countermeasures that Telegram can implement to improve location privacy. In general, the reported findings highlight the significant privacy risks associated with the use of the People Nearby service.
Maurantonio Caprolu, Savio Sciancalepore, Aleksandar Grigorov, Velyan Kolev, Gabriele Oligeri
WISEC5
2024 ORION: Verification of drone trajectories via remote identification messages
abstract
With the widespread adoption of drones in daily life, next-generation smart cities need to establish highways, i.e., trajectories where drones can fly and operate safely. However, due to the untrusted nature of their ecosystem, drones might misbehave and take disallowed trajectories, e.g., to reduce the time to fly to a destination, reduce energy consumption, visit unauthorized areas, or disrupt operations of sensitive sites. In this paper, we address the cited problem by proposing ORION, a new framework for online drone trajectory verification. ORION requires one or more receivers distributed in a given area capable of receiving and analyzing standard Remote Identification (RID) messages emitted by operational drones. ORION compares the locations reported in such messages with the closest set of coordinates in the allowed trajectory. It raises an alarm if the distance between such locations exceeds a threshold calibrated offline. We validate the performance of ORION through data collected from both a real drone flight in Amsterdam (Netherlands) and taxi trajectories in Porto (Portugal), achieving a True Positive Ratio (correct detection of disallowed trajectories) up to 0.95 and a False Positive Ratio (incorrect detection of disallowed trajectories) up to 0.04. Our solution significantly outperforms existing approaches used for drone detection or time-series analysis. Finally, we also release the gathered data as open-source to foster future research.
Savio Sciancalepore, Filip Davidovic, Gabriele Oligeri
Future Gener. Comput. Syst.3
2024 Jamming Detection in Low-BER Mobile Indoor Scenarios via Deep Learning
abstract
The current state of the art on jamming detection relies on link-layer metrics. A few examples are the bit-error rate (BER), the packet delivery ratio, the throughput, and the signal-to-noise ratio (SNR). As a result, these techniques can only detect jamming ex-post, i.e., once the attack has already taken down the communication link. These solutions are unfit for mobile devices, e.g., drones, which might lose the connection to the remote controller, being unable to predict the attack. Our solution is rooted in the idea that a drone unknowingly flying toward a jammed area is experiencing an increasing effect of the jamming, e.g., in terms of BER and SNR. Therefore, drones might use the abovementioned phenomenon to detect jamming before the increase of the BER and the decrease of the SNR completely disrupt the communication link. Such an approach would allow drones and their pilots to make informed decisions and maintain complete control of navigation, enhancing security and safety. This article proposes Bloodhound+, a solution for jamming detection on mobile devices in low-BER regimes. Our approach analyzes raw physical-layer information (I-Q samples) acquired from the wireless channel. We assemble this information into grayscale images and use sparse autoencoders to detect image anomalies caused by jamming attacks. To test our solution against a broad set of configurations, we acquired a large data set of indoor measurements using multiple hardware, jamming strategies, and communication parameters. Our results indicate that Bloodhound+ can detect indoor jamming up to 20 m from the jamming source at the minimum available relative jamming power, with a minimum accuracy of 99.7%. Our solution is also robust to various sampling rates adopted by the jammer and to the type of signal used for jamming.
Savio Sciancalepore, Fabrice Kusters, Nada Khaled Abdelhadi, Gabriele Oligeri
IEEE Internet Things J.4
2023 The Day-After-Tomorrow: On the Performance of Radio Fingerprinting over Time
abstract
The performance of Radio Frequency (RF) Fingerprinting (RFF) techniques is negatively impacted when the training data is not temporally close to the testing data. This can limit the practical implementation of physical-layer authentication solutions. To circumvent this problem, current solutions involve collecting training and testing datasets at close time intervals—this being detrimental to the real-life deployment of any physical-layer authentication solution. We refer to this issue as the Day-After-Tomorrow (DAT) effect, being widely attributed to the temporal variability of the wireless channel, which masks the physical-layer features of the transmitter, thus impairing the fingerprinting process.
Saeif Alhazbi, Savio Sciancalepore, Gabriele Oligeri
ACSAC3
2023 BloodHound: Early Detection and Identification of Jamming at the PHY-layer
abstract
Traditional jamming detection techniques, adopted in static networks, require the receiver (under jamming) to infer the presence of the jammer by measuring the effects of the jamming activity (packet loss and received signal strength), thus resulting only in a-posteriori analysis. However, in mobile scenarios, receivers (e.g., drones, vehicles, etc.) typically experience an increasing jamming effect while moving toward the jamming source. This phenomenon allows, in principle, an early detection of the jamming activity—being the communication not yet affected by the jamming (no packet loss). Under such an assumption, the mobile receiver can take an informed decision before losing the radio connection with the other party. To the best of our knowledge, this paper represents the first attempt toward the detection of a jammer before the radio link is fully affected by its activity. The proposed solution, namely, BloodHound, can early detect the approach to a jammer in a mobile scenario, i.e., before losing the capability of communicating, thus enhancing situational awareness and robustness. We performed an extensive measurement campaign, and we proved our solution to be able to detect the presence of a jammer with an accuracy higher than 0.99 even when the bit error rate is less than 0.01 (early detection), by varying several configuration parameters of the scenario.
Saeif Alhazbi, Savio Sciancalepore, Gabriele Oligeri
CCNC3
2023 Jamming Detection in Power Line Communications Leveraging Deep Learning Techniques
abstract
Power Line Communications (PLC) is a well-established technology that allows devices connected to the power line to communicate with each other. While the majority of research in this field is devoted to issues of availability, the topic of Denial of Service (DoS) attacks has not been sufficiently addressed. Typically, current solutions might detect a jammer when situated near the target devices, yet the equipment under jamming interference may face challenges in communicating an alarm. However, when these systems are placed at a significant distance from the jammer, the negligible impact of the jamming renders its detection hardly detectable. In this work, we propose a solution to identify the presence of a jammer in a PLC infrastructure even when deployed at a significant distance. We analyze the physical layer of the PLC link and adopt state-of-the-art Deep Learning techniques to detect jamming even at a distance where the jammer's effect is negligible, thus allowing the device to trigger an alarm. Considering a jammer featuring the same transmission power as legitimate devices, we prove that we can detect the presence of such a jammer with an overwhelming probability (higher than 0.99) even at a distance of 75 m from the source.
Aymen Omri, Javier Hernandez Fernandez, Savio Sciancalepore, Gabriele Oligeri
ISNCC5
2023 PAST-AI: Physical-Layer Authentication of Satellite Transmitters via Deep Learning
abstract
Physical-layer security is regaining traction in the research community, due to the performance boost introduced by deep learning classification algorithms. This is particularly true for sender authentication in wireless communications via radio fingerprinting. However, previous research mainly focused on terrestrial wireless devices while, to the best of our knowledge, none of the previous work considered satellite transmitters. The satellite scenario is generally challenging because, among others, satellite radio transducers feature non-standard electronics (usually aged and specifically designed for harsh conditions). Moreover, the fingerprinting task is specifically difficult for Low-Earth Orbit (LEO) satellites (like the ones we focus in this paper) since they feature a low bit-rate and orbit at about 800 Km from the Earth, at a speed of around 25,000 Km/h, thus making the receiver experiencing a down-link with unique attenuation and fading characteristics. In this paper, we investigate the effectiveness and main limitations of AI-based solutions to the physical-layer authentication of LEO satellites. Our study is performed on massive real data—more than$100M$I-Q samples—collected from an extensive measurements campaign on the IRIDIUM LEO satellites constellation, lasting 589 hours. Our results show that Convolutional Neural Networks (CNN) and autoencoders (if properly calibrated) can be successfully adopted to authenticate the satellite transducers, with an accuracy spanning between 0.8 and 1, depending on prior assumptions. However, the relatively high number of I-Q samples required by the proposed methodology, coupled with the low bandwidth of satellite link, might prevent the detection of the spoofing attack under certain configuration parameters.
Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro
IEEE Trans. Inf. Forensics Secur.1
2022 Energy-Harvesting Based Jammer Localization: A Battery-Free Approach in Wireless Sensor Networks
abstract
Wireless enabling technologies in critical infrastructures are increasing the efficiency of communications. Most of these technologies are vulnerable to jamming attacks. Jamming attacks are among the most effective countermeasures to attack and compromise their availability. Jamming is an interfering signal that limits the intended receiver from correctly receiving the messages. Localizing a jammer deployed by the adversary in wireless sensor networks becomes difficult, if not impossible, due to the inaccessibility of the affected sensors in the network. This paper proposes an effective yet efficient jammer localization scheme where battery-free Radio-Frequency Identification (RFID) sensor tags harvest the energy from the signal emitted by a powerful jammer. We compute the distance and estimate the actual jammer location based on the power received at each energy-harvesting node. We conduct extensive simulations campaign to test and illustrate the effectiveness of the proposed scheme. Finally, we demonstrate the possibility of deploying the proposed scheme with off-shelf equipment and consuming only 0.2175 mJ,
Ahmed Hussain 0002, Pietro Tedeschi, Gabriele Oligeri, Amr Mohamed 0001, Mohsen Guizani
GLOBECOM3
2022 GPS spoofing detection via crowd-sourced information for connected vehicles
abstract
Modern vehicular systems rely on the Global Positioning System (GPS) technology to provide accurate and timely services. However, the GPS has been proved to be characterized by an intrinsic insecure design, thus being subject to several security attacks. Current solutions can reliably detect GPS spoofing attacks leveraging the physical features of the received GPS signals or resorting to multiple antennas. However, these techniques cannot be deployed when the physical properties of the received signals cannot be accessed, which is the most general case for commercial GPS receivers. Alternative solutions in the literature rely on the cross-check of the received signal with information coming from additional sources. However, such proposals are typically limited to a single source, are rarely supported by experimental results, and do not provide insights on the impact of several parameters, such as detection accuracy, time, false-positives, and robustness to malicious information. To overcome the cited limitations, in this paper, we propose an innovative approach, resorting to combined crowd-sourced information from the mobile cellular infrastructure and the WiFi networks to detect GPS spoofing attacks. Our analysis leverages an extensive experimental dataset, available online for the research community, gathered by driving around a car in urban, suburban, and rural scenarios, for around 5 h and covering more than 196 km. Our solution allows for a tunable tradeoff between detection delay and false positive; for instance, we can detect an attack in approximately 6 s, when leveraging the information coming from only the WiFi, while the delay increases to 30 s when using the information from the mobile cellular network, still achieving a false positive probability strictly less than 0.01. We also show the limitations and trade-offs of our approach, in terms of minimum detection accuracy, time, and robustness to malicious information. The data adopted in this work are publicly released to allow results replicability and foster further research in the highlighted directions.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
Comput. Networks1
2022 Sound of guns: digital forensics of gun audio samples meets artificial intelligence
abstract
Abstract Classifying a weapon based on its muzzle blast is a challenging task that has significant applications in various security and military fields. Most of the existing works rely on ad-hoc deployment of spatially diverse microphone sensors to capture multiple replicas of the same gunshot, which enables accurate detection and identification of the acoustic source. However, carefully controlled setups are difficult to obtain in scenarios such as crime scene forensics, making the aforementioned techniques inapplicable and impractical. We introduce a novel technique that requires zero knowledge about the recording setup and is completely agnostic to the relative positions of both the microphone and shooter. Our solution can identify the category, caliber, and model of the gun, reaching over 90% accuracy on a dataset composed of 3655 samples that are extracted from YouTube videos. Our results demonstrate the effectiveness and efficiency of applying Convolutional Neural Network (CNN) in gunshot classification eliminating the need for an ad-hoc setup while significantly improving the classification performance.
Simone Raponi, Gabriele Oligeri, Isra Mohamed Ali
Multim. Tools Appl.2
2022 Fake News Propagation: A Review of Epidemic Models, Datasets, and Insights
abstract
Fake news propagation is a complex phenomenon influenced by a multitude of factors whose identification and impact assessment is challenging. Although many models have been proposed in the literature, the one capturing all the properties of a real fake-news propagation phenomenon is inevitably still missing. Modern propagation models, mainly inspired by old epidemiological models, attempt to approximate the fake-news propagation phenomena by blending psychological factors, social relations, and user behavior. This work provides an in-depth analysis of the current state of fake-news propagation models supported by real-world datasets. We highlighted similarities and differences in the modeling approaches, wrapping up the main research trends. Propagation models, transitions, network topologies, and performance metrics have been identified and discussed in detail. The thorough analysis we provided in this article, coupled with the highlighted research hints, have a high potential to pave the way for future research in the area.
Simone Raponi, Zeinab Khalifa, Gabriele Oligeri, Roberto Di Pietro
ACM Trans. Web3
2021 KaFHCa: Key-establishment via Frequency Hopping Collisions
abstract
The massive deployment of IoT devices being utilized by home automation, industrial and military scenarios demands for high security and privacy standards to be achieved through innovative solutions. This paper proposes KaFHCa, a crypto-less protocol that generates shared secret keys by combining random frequency hopping collisions and source indistinguishability independently of the radio channel status. While other solutions tie the secret bit rate generation to the current radio channel conditions, thus becoming unpractical in static environments, KaFHCa guarantees almost the same secret bit rate independently of the channel conditions. KaFHCa generates shared secrets through random collisions of the transmitter and the receiver in the radio spectrum, and leverages on the fading phenomena to achieve source indistinguishability, thus preventing unauthorized eavesdroppers from inferring the key. The proposed solution is (almost) independent of the adversary position, works under the conservative assumption of channel fading (σ=8dB), and is capable of generating a secret key of 128 bits with less than 564 transmissions.
Muhammad Usman 0003, Simone Raponi, Marwa Qaraqe, Gabriele Oligeri
ICC4
2021 Cryptomining makes noise: Detecting cryptojacking via Machine Learning
abstract
Cryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area.
Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro
Comput. Commun.3
2021 MAGNETO: Fingerprinting USB Flash Drives via Unintentional Magnetic Emissions
abstract
Universal Serial Bus (USB) Flash Drives are nowadays one of the most convenient and diffused means to transfer files, especially when no Internet connection is available. However, USB flash drives are also one of the most common attack vectors used to gain unauthorized access to host devices. For instance, it is possible to replace a USB drive so that when the USB key is connected, it would install passwords stealing tools, root-kit software, and other disrupting malware. In such a way, an attacker can steal sensitive information via the USB-connected devices, as well as inject any kind of malicious software into the host. To thwart the above-cited raising threats, we propose MAGNETO, an efficient, non-interactive, and privacy-preserving framework to verify the authenticity of a USB flash drive, rooted in the analysis of its unintentional magnetic emissions. We show that the magnetic emissions radiated during boot operations on a specific host are unique for each device, and sufficient to uniquely fingerprint both the brand and the model of the USB flash drive, or the specific USB device, depending on the used equipment. Our investigation on 59 different USB flash drives—belonging to 17 brands, including the top brands purchased on Amazon in mid-2019—reveals a minimum classification accuracy of 98.2% in the identification of both brand and model, accompanied by a negligible time and computational overhead. MAGNETO can also identify the specific USB Flash drive, with a minimum classification accuracy of 91.2%. Overall, MAGNETO proves that unintentional magnetic emissions can be considered as a viable and reliable means to fingerprint read-only USB flash drives. Finally, future research directions in this domain are also discussed.
Omar Adel Ibrahim, Savio Sciancalepore, Gabriele Oligeri, Roberto Di Pietro
ACM Trans. Embed. Comput. Syst.3
2020 GNSS spoofing detection via opportunistic IRIDIUM signals
abstract
In this paper, we study the privately-own IRIDIUM satellite constellation, to provide a location service that is independent of the GNSS. In particular, we apply our findings to propose a new GNSS spoofing detection solution, exploiting unencrypted IRIDIUM Ring Alert (IRA) messages that are broadcast by IRIDIUM satellites.
Gabriele Oligeri, Savio Sciancalepore, Roberto Di Pietro
WISEC1
2020 BrokenStrokes: on the (in)security of wireless keyboards
abstract
Wireless devices resorting to event-triggered communications have been proved to suffer critical privacy issues, due to the intrinsic leakage associated with radio-frequency (RF) emissions.
Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro
WISEC1
2020 PiNcH: An effective, efficient, and robust solution to drone detection via network traffic analysis
Savio Sciancalepore, Omar Adel Ibrahim, Gabriele Oligeri, Roberto Di Pietro
Comput. Networks3
2019 Drive me not: GPS spoofing detection via cellular network: (architectures, models, and experiments)
abstract
The Global Positioning System (GPS) has been proved to be exposed to several cybersecurity attacks, due to its intrinsic insecure design. GPS spoofing is one of the most easiest, cheap, and dreadful attacks that can be delivered: fake GPS signals can be sent to a target device and make it moving according to a pre-computed path.
Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro
WiSec1
2019 EXCHANge: Securing IoT via channel anonymity
Savio Sciancalepore, Gabriele Oligeri, Giuseppe Piro, Gennaro Boggia, Roberto Di Pietro
Comput. Commun.2
2018 Your culture is in your password: An analysis of a demographically-diverse password dataset
Mashael Al Sabah, Gabriele Oligeri, Ryan Riley
Comput. Secur.2
2018 GopJam: Key-less jamming mitigation via gossiping
Roberto Di Pietro, Gabriele Oligeri
J. Netw. Comput. Appl.2
2017 Enabling broadcast communications in presence of jamming via probabilistic pairing
Roberto Di Pietro, Gabriele Oligeri
Comput. Networks2
2015 Freedom of speech: thwarting jammers via a probabilistic approach
abstract
In this paper, we introduce a lightweight, fully distributed, and probabilistic protocol---Freedom of Speech (FoS)---that assures the delivery of a message to be broadcast (to N nodes) notwithstanding the presence of a powerful jammer. FoS enjoys several features when compared to competing schemes: it requires each node to store just N symmetric pairwise keys; node joining and node eviction require just minimal intervention on the already operating nodes; and, it is highly efficient in terms of required computation and message exchange.
Roberto Di Pietro, Gabriele Oligeri
WISEC2
2015 ESC: An efficient, scalable, and crypto-less solution to secure wireless networks
Roberto Di Pietro, Gabriele Oligeri
Comput. Networks2
2015 Silence is Golden: Exploiting Jamming and Radio Silence to Communicate
abstract
Jamming techniques require only moderate resources to be deployed, while their effectiveness in disrupting communications is unprecedented. In this article, we introduce several contributions to jamming mitigation. In particular, we introduce a novel adversary model that has both (unlimited) jamming reactive capabilities as well as powerful (but limited) proactive jamming capabilities. Under this adversary model, to the best of our knowledge more powerful than any other adversary model addressed in the literature, the communication bandwidth provided by current anti-jamming solutions drops to zero. We then present Silence is Golden ( SiG ): a novel anti-jamming protocol that, introducing a tunable, asymmetric communication channel, is able to mitigate the adversary capabilities, enabling the parties to communicate. For instance, with SiG it is possible to deliver a 128-bits-long message with a probability greater than 99% in 4096 time slots despite the presence of a jammer that jams all on-the-fly communications and 74% of the silent radio spectrum—while competing proposals simply fail. Moreover, when SiG is used in a scenario in which the adversary can jam only a subset of all the available frequencies, performance experiences a boost: a 128-bits-long message is delivered within just 17 time slots for an adversary able to jam 90% of the available frequencies. We present a thorough theoretical analysis for the solution, which is supported by extensive simulation results, showing the viability of our proposal.
Roberto Di Pietro, Gabriele Oligeri
ACM Trans. Inf. Syst. Secur.2
2013 SHAKE: Single HAsh key establishment for resource constrained devices
Paolo Barsocchi, Gabriele Oligeri, Claudio Soriente
Ad Hoc Networks2
2013 COKE Crypto-Less Over-the-Air Key Establishment
abstract
In this paper, we present a novel probabilistic protocol (COKE) to allow two wireless communicating parties to commit over-the-air (OTA) on a shared secret, even in the presence of a globally eavesdropping adversary. The proposed solution leverages no crypto but just plaintext messages exchange. Indeed, the security of the solution relies on the difficulty for the adversary to correctly identify, for each one-bit transmission, the sender of that bit-not its value, which is indeed exchanged in cleartext. Due to the low requirements of COKE (essentially, the capability to send a few wireless messages), it is particularly suited for resource constrained wireless devices (e.g., WNSs, wireless embedded systems), as well as for those scenarios where just energy saving is at premium, such as smartphones.
Roberto Di Pietro, Gabriele Oligeri
IEEE Trans. Inf. Forensics Secur.2
2013 United We Stand: Intrusion Resilience in Mobile Unattended WSNs
abstract
Wireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources, and lack of tamper resistance. Once a sensor is corrupted, the adversary learns all secrets. Thereafter, most security measures become ineffective. Recovering secrecy after compromise requires either help from a trusted third party or access to a source of high-quality cryptographic randomness. Neither is available in Unattended Wireless Sensor Networks (UWSNs), where the sink visits the network periodically. Prior results have shown that sensor collaboration is an effective but expensive means of obtaining probabilistic intrusion resilience in static UWSNs. In this paper, we focus on intrusion resilience in Mobile Unattended Wireless Sensor Networks (μUWSNs), where sensors move according to some mobility models. Note that such a mobility feature could be independent from security (e.g., sensors move to improve area coverage). We define novel security metrics to evaluate intrusion resilience protocols for sensor networks. We also propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. Thorough analysis and extensive simulations support our findings.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
IEEE Trans. Mob. Comput.2
2013 LAKE: A Server-Side Authenticated Key-Establishment with Low Computational Workload
abstract
Server-side authenticated key-establishment protocols are characterized by placing a heavy workload on the server. We propose LAKE: a new protocol that enables amortizing servers’ workload peaks by moving most of the computational burden to the clients. We provide a formal analysis of the LAKE protocol under the Canetti-Krawczyk model and prove it to be secure. To the best of our knowledge, this is the most computationally efficient authenticated key-establishment ever proposed in the literature.
Kemal Bicakci, Bruno Crispo, Gabriele Oligeri
ACM Trans. Internet Techn.3
2011 Loss tolerant video streaming authentication in heterogeneous wireless networks
Gabriele Oligeri, Stefano Chessa, Gaetano Giunta
Comput. Commun.1
2011 Robust and efficient authentication of video stream broadcasting
abstract
We present a novel video stream authentication scheme which combines signature amortization by means of hash chains and an advanced watermarking technique. We propose a new hash chain construction, the Duplex Hash Chain, which allows us to achieve bit-by-bit authentication that is robust to low bit error rates. This construction is well suited for wireless broadcast communications characterized by low packet losses such as in satellite networks. Moreover, neither hardware upgrades nor specific end-user equipment are needed to enjoy the authentication services. The computation overhead experienced on the receiver only sums to two hashes per block of pictures and one digital signature verification for the whole received stream. This overhead introduces a provably negligible decrease in video quality. A thorough analysis of the proposed solution is provided in conjunction with extensive simulations.
Gabriele Oligeri, Stefano Chessa, Roberto Di Pietro, Gaetano Giunta
ACM Trans. Inf. Syst. Secur.1
2010 Intrusion-Resilience in Mobile Unattended WSNs
abstract
Wireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources and lack of tamper-resistance. Once a sensor is corrupted, the adversary learns all secrets and (even if the sensor is later released) it is very difficult for the sensor to regain security, i.e., to obtain intrusion-resilience. Existing solutions rely on the presence of an on-line trusted third party, such as a sink, or on the availability of secure hardware on sensors. Neither assumption is realistic in large-scale Unattended WSNs (UWSNs), characterized by long periods of disconnected operation and periodic visits by the sink. In such settings, a mobile adversary can gradually corrupt the entire network during the intervals between sink visits. As shown in some recent work, intrusion-resilience in UWSNs can be attained (to a degree) via cooperative self-healing techniques. In this paper, we focus on intrusion-resilience in Mobile Unattended Wireless Sensor Networks (¿UWSNs) where sensors move according to some mobility model. We argue that sensor mobility motivates a specific type of adversary and defending against it requires new security techniques. Concretely, we propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. We provide a thorough analysis of the proposed protocol and support it by extensive simulation results.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
INFOCOM2
2010 Securing Mobile Unattended WSNs against a Mobile Adversary
abstract
One important factor complicating security in Wireless Sensor Networks (WSNs) is lack of inexpensive tamper-resistant hardware in commodity sensors. Once an adversary compromises a sensor, all memory and forms of storage become exposed, along with all secrets. Thereafter, any cryptographic remedy ceases to be effective. Regaining sensor security after compromise (i.e., intrusion-resilience) is a formidable challenge. Prior approaches rely on either (1) the presence of an on-line trusted third party (sink), or (2) the availability of a True Random Number Generator (TRNG) on each sensor. Neither assumption is realistic in large-scale Unattended Wireless Sensor Networks (UWSNs) composed of low-cost commodity sensors. periodic visits by the sink. Previous work has demonstrated that sensor collaboration is an effective, yet expensive, means of attaining intrusion-resilience in UWSNs. In this paper, we explore intrusion resilience in Mobile UWSNs in the presence of a powerful mobile adversary. We show how the choice of the sensor mobility model influences intrusion resilience with respect to this adversary. We also explore self healing protocols that require only local communication. Results indicate that sensor density and neighborhood variability are the two key parameters affecting intrusion resilience. Our findings are supported by extensive analyses and simulations.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
SRDS2
2010 Quality of experience in multicast hybrid networks: avoiding bandwidth wasting with a double-stage FEC scheme
abstract
Quality of experience is becoming an important parameter for estimating the end user perceived video quality. Video coding algorithms are currently increasing the compression performances by exploiting the temporal and spatial correlations of multimedia information. Such a trend is self-defeating in hybrid networks, due to the frequent channel impairments experienced. Here, the authors present a double-stage forward error correction (FEC) scheme to reduce the channel impairments that a multimedia communication undergoes when broadcasting a video stream through an hybrid infrastructure constituted by satellite and terrestrial wireless links. The authors present a detailed statistical description of the terrestrial wireless channel and exploit it to design the parameters for tuning the algorithm. Simulations results show that this approach not only performs better than the error recovery techniques currently used in the literature, but it also experiences a significant reduction in the bandwidth overhead.
Paolo Barsocchi, Gabriele Oligeri
IET Commun.2
2009 Measurement-based frame error model for simulating outdoor Wi-Fi networks
abstract
We present a measurement-based model of the frame error process on a Wi-Fi channel in rural environments. Measures are obtained in controlled conditions, and careful statistical analysis is performed on the data, providing information which the network simulation literature is lacking. Results indicate that most network simulators use a frame loss model that can miss important transmission impairments even at a short distance, particularly when considering antenna radiation pattern anisotropy and multi-rate switching.
Paolo Barsocchi, Gabriele Oligeri, Francesco Potortì
IEEE Trans. Wirel. Commun.2
2007 Mobile Application Security for Video Streaming Authentication and Data Integrity Combining Digital Signature and Watermarking Techniques
abstract
Satellite link presents peculiar characteristics like no packet reordering and low bit error rate. In this paper we leverage these characteristics combined with watermarking techniques to propose a novel authentication algorithm for multicast video streaming. This algorithm combines a single digital signature with a hash chain pre-computed on the transmitter side; the hash chain is embedded in the video stream by means of a watermarking technique. Our proposal shows several interesting features: authentication is enforced, as well as integrity of the received multicast stream; received blocks can be authenticated on the fly; no storage is required on the receiver side, except for the amount of memory needed to store a single hash; overhead computations required on the receiver sum up to single hash per block, while a digital signature verification is amortized over the whole received stream. Finally, note that the bandwidth overhead introduced is negligible, since the applied watermarking technique introduces virtually no modifications (at least, not recognizable by humans) on the original video stream pictures.
Stefano Chessa, Roberto Di Pietro, Erina Ferro, Gaetano Giunta, Gabriele Oligeri
VTC Spring5
2007 Embedding Source Signature in Multicast Wireless Video Streams
abstract
We consider the problem of source authentication of video streams in multicast environments. We proposed a novel algorithm which combines signature amortization based on hash chains and watermarking to embed hash chains in the video stream. The algorithm exploits a novel watermarking procedure using Reed-Solomon mark encoding which ensures error-free and fast convergence mark extraction. We show that the algorithm has a negligible impact on the video stream quality and we evaluate the configuration parameters of the algorithm which ensure proper verification of the source authenticity.
Stefano Chessa, Gaetano Giunta, Gabriele Oligeri
WOWMOM3