EDBT 2026 Demo / reviewers in the wild / expert
Ravishankar Borgaonkar
dblp:75/7408 · also Ravishankar Bhaskarrao Borgaonkar
· DBLP profile ↗
16ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-2874-3650ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
3 papers |
Cellular and mobile networks · 100% | |
| Network and information security
2 papers |
Network security · 77% Privacy and data protection · 23% |
Topics — the 4 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cellular and mobile networks
4G/LTE |
0.2 | 1 | 2016 | Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems · NDSS 2016 |
Cellular and mobile networks › cellular network security
privacy attack |
0.2 | 1 | 2016 | Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems · NDSS 2016 |
Network security › wireless network security
mobile network security |
0.1 | 1 | 2012 | Weaponizing Femtocells: The Effect of Rogue Devices on Mobile Telecommunications · NDSS 2012 |
Privacy and data protection
anonymity and unlinkability |
0.0 | 1 | 2012 | New privacy issues in mobile telephony: fix and verification · CCS 2012 |
Methods — techniques the papers use, named apart from their topics
proverif · 0.3formal methods · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Red Teaming Your Standalone Private 5G Deployment Using GenAI
Anders Kornberg Simensen, Thomas Zinner, Ravishankar Borgaonkar |
NetSoft | 3 |
| 2025 | Cybersecurity Indicators Within a Cybersecurity Testing and Monitoring Framework
Stephen Taylor 0002, Norbert Götze, Joerg Abendroth, Jens Kuhr, Rosella Mancilla, Bernd-Ludwig Wenning, Pasindu Kuruppuarachchi, Aida Omerovic, Ravishankar Borgaonkar, Andrea Neverdal Skytterholm, Antonis Mpantis, George N. Triantafyllou, Oscar Garcia Perales, Oleh Zaritskyi |
IoTBDS | 9 |
| 2025 | AI-driven Access Control System for Smart Factory DevicesabstractThe authors of the article examined the modern challenges involved in developing an access control system for smart factories, focusing on the creation of an integrated solution for monitoring and managing the information security of the Internet of Things (loT) through the integration of diverse tools and methods within a single system. In this paper, the information system is examined through the lens of system analysis, focusing on the interactions between the subjects and objects within the system. This perspective allows for an accurate assessment of the current state of obj ects, taking into account the system's architecture and its vulnerabilities, as well as the evolution of the system state over time. The approach proposed incorporates modern tools and software solutions, including intrusion detection systems (IDS), fuzzy testing, Software Bill of Materials (SBOM), and various machine learning (ML) techniques. Oleh Zaritskyi, Dmytro Shyrokorad, Rosella Mancilla, Joerg Abendroth, Antonis Mpantis, Oscar Garcia Perales, George N. Triantafyllou, Armando Aguayo-Mendoza, Ravishankar Borgaonkar |
SMARTCOMP | 9 |
| 2023 | Software Bill of Materials in Critical InfrastructureabstractCritical infrastructure today is comprised of cyber-physical systems, and therefore also vulnerable to cyber threats. Many of these threats come from within, through malicious code in software updates or bugs that can be exploited. Further exacerbating the issue is the fact that most software suppliers in critical infrastructure are developing proprietary systems and giving out minimal information about the composition of their software products. With the US introduction of a Software Bill of Materials (SBOM) requirement in federal information systems, they are better prepared to deal with cyber incidents. This article examines regulations regarding software in critical infrastructure, and whether there is any benefit to mandating SBOMs in critical infrastructure. Lars Andreassen Jaatun, Silje Marie Sørlien, Ravishankar Borgaonkar, Stephen Taylor 0002, Martin Gilje Jaatun |
CloudCom | 3 |
| 2021 | Improving smart grid security through 5G enabled IoT and edge computingabstractAbstract This article investigates and analyzes the security aspects of 5G specifications from the perspective of IoT‐based smart grids. As the smart grid requires high‐speed and reliable communication to enable real‐time grid monitoring via Internet of Things (IoT) devices, 5G can be considered a catalyst to transform the current power grid infrastructure into a smart grid. Thus, an understanding of what 5G can bring in terms of cyber security in IoT‐based smart grids is important for design decisions and future risk analysis efforts. In this article, we explore a smart grid use case on automatic voltage control—a use case utilizing 5G as a wireless communication infrastructure with edge support. We identify the benefits 5G brings to several security aspects, and show how 5G security techniques are applicable to the smart grid, thus providing a foundation for future security analysis of 5G enabled smart grid systems. Future research should extend this work to additional smart grid use cases. Ravishankar Borgaonkar, Inger Anne Tøndel, Merkebu Z. Degefa, Martin Gilje Jaatun |
Concurr. Comput. Pract. Exp. | 1 |
| 2019 | New vulnerabilities in 4G and 5G cellular access network protocols: exposing device capabilitiesabstractCellular devices support various technical features and services for 2G, 3G, 4G and upcoming 5G networks. For example, these technical features contain physical layer throughput categories, radio protocol information, security algorithm, carrier aggregation bands and type of services such as GSM-R, Voice over LTE etc. In the cellular security standardisation context, these technical features and network services termed as device capabilities and exchanged with the network during the device registration phase. In this paper, we study device capabilities information specified for 4G and 5G devices and their role in establishing security association between the device and network. Our research results reveal that device capabilities are exchanged with the network before the authentication stage without any protection and not verified by the network. Consequently, we present three novel classes of attacks exploiting unprotected device capabilities information in 4G and upcoming 5G networks - identification attacks, bidding down attacks, and battery drain attacks against cellular devices. We implement proof-of-concept attacks using low-cost hardware and software setup to evaluate their impact against commercially available 4G devices and networks. We reported identified vulnerabilities to the relevant standardisation bodies and provide countermeasure to mitigate device capabilities attacks in 4G and upcoming 5G networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WiSec | 2 |
| 2019 | New Privacy Threat on 3G, 4G, and Upcoming 5G AKA ProtocolsabstractAbstract Mobile communications are used by more than two-thirds of the world population who expect security and privacy guarantees. The 3rd Generation Partnership Project (3GPP) responsible for the worldwide standardization of mobile communication has designed and mandated the use of the AKA protocol to protect the subscribers’ mobile services. Even though privacy was a requirement, numerous subscriber location attacks have been demonstrated against AKA, some of which have been fixed or mitigated in the enhanced AKA protocol designed for 5G. In this paper, we reveal a new privacy attack against all variants of the AKA protocol, including 5G AKA, that breaches subscriber privacy more severely than known location privacy attacks do. Our attack exploits a new logical vulnerability we uncovered that would require dedicated fixes. We demonstrate the practical feasibility of our attack using low cost and widely available setups. Finally we conduct a security analysis of the vulnerability and discuss countermeasures to remedy our attack. Ravishankar Borgaonkar, Lucca Hirschi, Shinjo Park, Altaf Shaik |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | On the Impact of Rogue Base Stations in 4G/LTE Self Organizing NetworksabstractMobile network operators choose Self Organizing Network (SON) concept as a cost-effective method to deploy LTE/4G networks and meet user expectations for high quality of service and bandwidth. The main objective of SON is to introduce automation into network management activities and reduce human intervention. SON enabled LTE networks heavily rely on the information acquired from mobile phones to provide self-configuration, self-optimization, and self-healing features. However, mobile phones can be attacked over-the-air using rogue base stations. In this paper, we carefully study SON related LTE/4G security specifications and reveal several vulnerabilities. Our key idea is to introduce a rogue eNodeB that uses legitimate mobile devices as a covert channel to launch attacks against SON enabled LTE networks. Altaf Shaik, Ravishankar Borgaonkar, Shinjo Park, Jean-Pierre Seifert |
WISEC | 2 |
| 2016 | Characterizing SEAndroid Policies in the WildabstractStarting from the 5.0 Lollipop release all Android processes must be run inside confined SEAndroid access control domains. As a result, Android device manufacturers were compelled to develop SEAndroid expertise in order to create policies for their device-specific components. In this paper we analyse SEAndroid policies from a number of 5.0 Lollipop devices on the market, and identify patterns of common problems we found. We also suggest some practical tools that can improve policy design and analysis. We implemented the first of such tools, SEAL. Elena Reshetova, Filippo Bonazzi, Thomas Nyman, Ravishankar Borgaonkar, N. Asokan |
ICISSP | 4 |
| 2016 | Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems
Altaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan, Valtteri Niemi |
NDSS | 3 |
| 2014 | What Does the Fox Say? On the Security Architecture of Firefox OSabstractWe are witnessing a shift in the design of mobile operating systems from custom architectures to web-based platforms. This paper attempts to understand the security implications of bringing the smartphone to the web. We base our work on Firefox OS as the open nature of the project offers an insight into its design, and allows for the introduction of extensions to its security architecture. This paper has the following contributions: (1) Systematizing our knowledge about the security architecture of Firefox OS, (2) Pointing out shortcomings of Firefox OS's security architecture, (3) Formulating a threat model that web-based OSes face, and (4) Outlining directions for future research in the field. Marta Piekarska, Bhargava Shastry, Ravishankar Borgaonkar |
ARES | 3 |
| 2013 | SMS-Based One-Time Passwords: Attacks and Defense - (Short Paper)
Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, Jean-Pierre Seifert |
DIMVA | 2 |
| 2012 | New privacy issues in mobile telephony: fix and verificationabstractMobile telephony equipment is daily carried by billions of subscribers everywhere they go. Avoiding linkability of subscribers by third parties, and protecting the privacy of those subscribers is one of the goals of mobile telecommunication protocols. We use formal methods to model and analyse the security properties of 3G protocols. We expose two novel threats to the user privacy in 3G telephony systems, which make it possible to trace and identify mobile telephony subscribers, and we demonstrate the feasibility of a low cost implementation of these attacks. We propose fixes to these privacy issues, which also take into account and solve other privacy attacks known from the literature. We successfully prove that our privacy-friendly fixes satisfy the desired unlinkability and anonymity properties using the automatic verification tool ProVerif. Myrto Arapinis, Loretta Ilaria Mancini, Eike Ritter, Mark Ryan 0001, Nico Golde, Kevin Redon, Ravishankar Borgaonkar |
CCS | 7 |
| 2012 | Weaponizing Femtocells: The Effect of Rogue Devices on Mobile Telecommunications
Nico Golde, Kevin Redon, Ravishankar Borgaonkar |
NDSS | 3 |
| 2011 | Security analysis of a femtocell deviceabstractMobile network operators are adapting femtocells in order to simplify their network architecture for increased coverage, performance, and greater revenue opportunities. While emerging as a new low-cost technology which assures best connectivity, it has also introduced a range of new potential security risks for the mobile network operators. In this paper, we analyze these security issues and demonstrate the weaknesses of femtocell security. We demonstrate several security flaws that allowing attackers to gain root access and to install malicious applications on the femtocell. Furthermore, we experimentally evaluate and show a wide range of possible threats to femtocell; including compromise of femtocell credentials; physical, configuration, and protocol attacks; user data and identity privacy attacks. The vulnerabilities we found suggest that commercial-available femtocells fail to fulfill 3GPP security requirements and could expose operator network elements to the attacker. Our findings and successful attacks exhibit the need for further research to bridge the gap between theoretical and practical security of femtocell devices. Ravishankar Borgaonkar, Kevin Redon, Jean-Pierre Seifert |
SIN | 1 |
| 2009 | Spam filter optimality based on signal detection theoryabstractUnsolicited bulk email, commonly known as spam, represents a significant problem on the Internet. The seriousness of the situation is reflected by the fact that approximately 97% of the total e-mail traffic currently (2009) is spam. To fight this problem, various anti-spam methods have been proposed and are implemented to filter out spam before it gets delivered to recipients, but none of these methods are entirely satisfactory. In this paper we analyze the properties of spam filters from the viewpoint of Signal Detection Theory (SDT). The Bayesian approach of Signal Detection Theory provides a basis for determining the optimality of spam filters, i.e. whether they provide positive utility to users. In the process of decision making by a spam filter various tradeoff's are considered as a function of the costs of incorrect decisions and the benefits of correct decisions. Audun Jøsang, Md Sadek Ferdous, Ravishankar Borgaonkar |
SIN | 4 |