Andriy Panchenko 0001

dblp:82/5164-1 · DBLP profile ↗
← Back
30ranked-venue papers
9as first author
8since 2021 · last 2025
0009-0004-2563-4234ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 6 first-author · 5 since 2021Computer networks · 7 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Poster: Characterization of Dominant and Specific Network Patterns in Industrial Control Systems
abstract
The increasing digitization and interconnection of Industrial Control Systems (ICS) to the Internet render them susceptible to cyber attacks. Thus, a major line of research focuses on the design of reactive security solutions in the form of industrial intrusion detection systems, which aim to detect anomalies in a normal system operation. However, a crucial prerequisite for the accurate detection and localization of anomalies is the identification of typical traffic patterns that are exclusive to characterize the normal ICS behavior. Unlike previous work focusing on complex and protocol-dependent models, for characterizing ICS network traffic, in this work we propose simple, easy deployable, and effective rules for determining whether ICS network traffic, unlike traditional IT networks, remains stable over time. The main advantage of our rules is that they can be used to estimate the time required to identify the most dominant ICS traffic patterns in a given ICS. We show the efficacy of our rules by analyzing multiple ICS datasets with different industrial network protocols.
Asya Mitseva, Marco Lewandowsky, Andriy Panchenko 0001
NCA3
2024 Reviewing War: Unconventional User Reviews as a Side Channel to Circumvent Information Controls
abstract
During the first days of the 2022 Russian invasion of Ukraine, Russia's media regulator blocked access to many global social media platforms and news sites, including Twitter, Facebook, and the BBC. To bypass the information controls set by Russian authorities, pro-Ukrainian groups explored unconventional ways to reach out to the Russian population, such as posting war-related content in the user reviews of Russian businesses available on Google Maps or Tripadvisor. This paper provides a first analysis of this new phenomenon by analyzing the unconventional strategies used to avoid state censorship in the Russian Federation during the conflict. Specifically, we analyze reviews posted on these platforms from the beginning of the war to September 2022. We measure the channeling of war-related messages through user reviews on Tripadvisor and Google Maps. Our analysis of the content posted on these services reveals that users leveraged these platforms to seek and exchange humanitarian and travel advice, but also to disseminate disinformation and polarized messages. Finally, we analyze the response of platforms in terms of content moderation and their impact.
José Miguel Moreno, Sergio Pastrana, Jens Helge Reelfs, Pelayo Vallina, Savvas Zannettou, Andriy Panchenko 0001, Georgios Smaragdakis, Oliver Hohlfeld, Narseo Vallina-Rodriguez, Juan Tapiador
ICWSM6
2024 Stop, Don't Click Here Anymore: Boosting Website Fingerprinting By Considering Sets of Subpages
Asya Mitseva, Andriy Panchenko 0001
USENIX Security Symposium2
2023 Design Rationale for Symbiotically Secure Key Management Systems in IoT and Beyond
abstract
The overwhelmingly widespread use of Internet of Things (IoT) in different application domains brought not only benefits, but, alas, security concerns as a result of the increased attack surface and vectors. One of the most critical mechanisms in IoT infrastructure is key management. This paper reflects on the problems and challenges of existing key management systems, starting with the discussion of a recent real-world attack. We identify and elaborate on the drawbacks of security primitives based purely on physical variations and - after highlighting the problems of such systems - continue on to deduce an effective and cost-efficient key management solution for IoT systems extending the symbiotic security approach in a previous work. The symbiotic architecture combines software, firmware, and hardware resources for secure IoT while avoiding the traditional scheme of static key storage and generating entropy for key material on-the-fly via a combination of a Physical Unclonable Function (PUF) and pseudo-random bits pre-populated in firmware.
Witali Bartsch, Prosanta Gope, Elif Bilge Kavun, Owen Millwood, Andriy Panchenko 0001, Aryan Mohammadi Pasikhani, Ilia Polian
ICISSP5
2023 Security and performance implications of BGP rerouting-resistant guard selection algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Andriy Panchenko 0001
Comput. Secur.3
2021 POSTER: How Dangerous is My Click? Boosting Website Fingerprinting By Considering Sequences of Webpages
abstract
Website fingerprinting (WFP) is a special case of traffic analysis, where a passive attacker infers information about the content of encrypted and anonymized connections by observing patterns of data flows. Although modern WFP attacks pose a serious threat to online privacy of users, including Tor users, they usually aim to detect single pages only. By ignoring the browsing behavior of users, the attacker excludes valuable information: users visit multiple pages of a single website consecutively, e.g., by following links. In this paper, we propose two novel methods that can take advantage of the consecutive visits of multiple pages to detect websites. We show that two up to three clicks within a site allow attackers to boost the accuracy by more than 20% and to dramatically increase the threat to users' privacy. We argue that WFP defenses have to consider this new dimension of the attack surface.
Asya Mitseva, Jan Pennekamp, Johannes Lohmöller, Torsten Ziemann, Carl Hoerchner, Klaus Wehrle, Andriy Panchenko 0001
CCS7
2021 WhisperChord: Scalable and Secure Node Discovery for Overlay Networks
abstract
Node discovery is a fundamental service for any overlay network, including anonymization networks. Although anonymization and node discovery are two disjoint services, the node discovery has a direct impact on the anonymization. Centralized methods require a trusted third party, limit the network scalability, and are vulnerable to intersection (statistical disclosure) attacks. Therefore, several distributed node discovery methods were proposed to meet the security requirements of anonymization networks through additional structures within Distributed Hash Tables (DHTs). However, they require a high management overhead, a strict cooperation between nodes, and are susceptible to active and passive attacks.We propose WhisperChord—an alternative distributed node discovery approach, which incorporates gossiping into structured overlays. WhisperChord is based on a Chord DHT and neither creates any additional structures within the DHT nor requires any trusted third party. Via simulations, we show that our method provides superior protection against active attacks than prior methods and can effectively thwart information leakages.
Andriy Panchenko 0001, Asya Mitseva, Sara Knabe
LCN1
2021 GuardedGossip: Secure and Anonymous Node Discovery in Untrustworthy Networks
Andriy Panchenko 0001, Asya Mitseva, Torsten Ziemann, Till Hering
SecureComm (1)1
2020 TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic Splitting
abstract
Website fingerprinting (WFP) aims to infer information about the content of encrypted and anonymized connections by observing patterns of data flows based on the size and direction of packets. By collecting traffic traces at a malicious Tor entry node --- one of the weakest adversaries in the attacker model of Tor --- a passive eavesdropper can leverage the captured meta-data to reveal the websites visited by a Tor user. As recently shown, WFP is significantly more effective and realistic than assumed. Concurrently, former WFP defenses are either infeasible for deployment in real-world settings or defend against specific WFP attacks only.
Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
CCS9
2020 Out-of-the-box Multipath TCP as a Tor Transport Protocol: Performance and Privacy Implications
abstract
The transport design of Tor - the most popular anonymization network - has been identified as a key factor responsible for its performance unfairness. In Tor, traffic from multiple users is multiplexed in a single TCP connection between two relays. While this has positive effects on privacy, it negatively influences performance and is characterized by unfairness as TCP congestion control gives all the multiplexed Tor traffic as little of the available bandwidth as it gives to every single TCP connection that competes for the same resource. To counter this, we propose to use multipath TCP (MPTCP). It allows for better resource utilization and increases throughput of the Tor traffic to a fairer extent. Our evaluation in realworld settings shows that using out-of-the-box MPTCP leads to 15% performance gain. We analyze the privacy implications of MPTCP in Tor settings and discuss potential threats and mitigation strategies.
Wladimir De la Cadena, Daniel Kaiser 0001, Andriy Panchenko 0001, Thomas Engel 0001
NCA3
2020 Security and Performance Implications of BGP Rerouting-Resistant Guard Selection Algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Thomas Engel 0001, Andriy Panchenko 0001
SEC4
2019 POSTER: Traffic Splitting to Counter Website Fingerprinting
abstract
Website fingerprinting (WFP) is a special type of traffic analysis, which aims to infer the websites visited by a user. Recent studies have shown that WFP targeting Tor users is notably more effective than previously expected. Concurrently, state-of-the-art defenses have been proven to be less effective. In response, we present a novel WFP defense that splits traffic over multiple entry nodes to limit the data a single malicious entry can use. Here, we explore several traffic-splitting strategies to distribute user traffic. We establish that our weighted random strategy dramatically reduces the accuracy from nearly 95% to less than 35% for four state-of-the-art WFP attacks without adding any artificial delays or dummy traffic.
Wladimir De la Cadena, Asya Mitseva, Jan Pennekamp, Jens Hiller, Fabian Lanze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
CCS8
2019 Analysis of Multi-path Onion Routing-Based Anonymization Networks
Wladimir De la Cadena, Daniel Kaiser 0001, Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001
DBSec4
2019 Tailoring Onion Routing to the Internet of Things: Security and Privacy in Untrusted Environments
abstract
An increasing number of IoT scenarios involve mobile, resource-constrained IoT devices that rely on untrusted networks for Internet connectivity. In such environments, attackers can derive sensitive private information of IoT device owners, e.g., daily routines or secret supply chain procedures, when sniffing on IoT communication and linking IoT devices and owner. Furthermore, untrusted networks do not provide IoT devices with any protection against attacks from the Internet. Anonymous communication using onion routing provides a well-proven mechanism to keep the relationship between communication partners secret and (optionally) protect against network attacks. However, the application of onion routing is challenged by protocol incompatibilities and demanding cryptographic processing on constrained IoT devices, rendering its use infeasible. To close this gap, we tailor onion routing to the IoT by bridging protocol incompatibilities and offloading expensive cryptographic processing to a router or web server of the IoT device owner. Thus, we realize resource-conserving access control and end-to-end security for IoT devices. To prove applicability, we deploy onion routing for the IoT within the well-established Tor network enabling IoT devices to leverage its resources to achieve the same grade of anonymity as readily available to traditional devices.
Jens Hiller, Jan Pennekamp, Markus Dahlmanns, Martin Henze, Andriy Panchenko 0001, Klaus Wehrle
ICNP5
2019 Multipathing Traffic to Reduce Entry Node Exposure in Onion Routing
abstract
Users of an onion routing network, such as Tor, depend on its anonymity properties. However, especially malicious entry nodes, which know the client's identity, can also observe the whole communication on their link to the client and, thus, conduct several de-anonymization attacks. To limit this exposure and to impede corresponding attacks, we propose to multipath traffic between the client and the middle node to reduce the information an attacker can obtain at a single vantage point. To facilitate the deployment, only clients and selected middle nodes need to implement our approach, which works transparently for the remaining legacy nodes. Furthermore, we let clients control the splitting strategy to prevent any external manipulation.
Jan Pennekamp, Jens Hiller, Sebastian Reuter, Wladimir De la Cadena, Asya Mitseva, Martin Henze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001
ICNP9
2018 The state of affairs in BGP security: A survey of attacks and defenses
abstract
The Border Gateway Protocol (BGP) is the de facto standard interdomain routing protocol. Despite its critical role on the Internet, it does not provide any security guarantees. In response to this, a large amount of research has proposed a wide variety BGP security extensions and detection-recovery systems in recent decades. Nevertheless, BGP remains vulnerable to many types of attack. In this work, we conduct an up-to-date review of fundamental BGP threats and present a methodology for evaluation of existing BGP security proposals. Based on this, we introduce a comprehensive and up-to-date survey of proposals intended to make BGP secure and methods for detection and mitigation of routing instabilities. Last but not least, we identify gaps in research, and pinpoint open issues and unsolved challenges.
Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001
Comput. Commun.2
2016 POSTER: Fingerprinting Tor Hidden Services
abstract
The website fingerprinting attack aims to infer the content of encrypted and anonymized connections by analyzing patterns from the communication such as packet sizes, their order, and direction. Although recent study has shown that no existing fingerprinting method scales in Tor when applied in realistic settings, this does not consider the case of Tor hidden services. In this work, we propose a two-phase fingerprinting approach applied in the scope of Tor hidden services and explore its scalability. We show that the success of the only previously proposed fingerprinting attack against hidden services strongly depends on the Tor version used; i.e., it may be applicable to less than 1.5% of connections to hidden services due to its requirement for control of the first anonymization node. In contrast, in our method, the attacker needs merely to be somewhere on the link between the client and the first anonymization node and the attack can be mounted for any connection to a hidden service.
Asya Mitseva, Andriy Panchenko 0001, Fabian Lanze, Martin Henze, Klaus Wehrle, Thomas Engel 0001
CCS2
2016 Website Fingerprinting at Internet Scale
Andriy Panchenko 0001, Fabian Lanze, Jan Pennekamp, Thomas Engel 0001, Andreas Zinnen, Martin Henze, Klaus Wehrle
NDSS1
2015 Hacker's toolbox: Detecting software-based 802.11 evil twin access points
abstract
The usage of public Wi-Fi hotspots has become a common routine in our everyday life. They are ubiquitous and offer fast and budget-friendly connectivity for various client devices. However, they are exposed to a severe security threat: since 802.11 identifiers (SSID, BSSID) can be easily faked, an attacker can setup an evil twin, i.e., an access point (AP) that users are unable to distinguish from a legitimate one. Once a user connects to the evil twin, he inadvertently creates a playground for various attacks such as collection of sensitive data (e.g., credit card information, passwords) or man-in-the-middle attacks even on encrypted traffic. It is particularly alarming that this security flaw has led to the development of several tools that are freely available, easy to use and allow mounting the attack from commodity client devices such as laptops, smartphones or tablets without attracting attention. In this paper we provide a detailed overview of tools that have been developed (or can be misused) to set up evil twin APs. We inspect them thoroughly in order to identify characteristics that allow them to be distinguished from legitimate hardware-based access points. Our analysis has discovered three methods for detecting software-based APs. These exploit accuracy flaws due to emulation of hardware behavior or peculiarities of the client Wi-Fi hardware they operate on. Our evaluation with 60 hardware APs and a variety of tools on different platforms reveals enormous potential for reliable detection. Furthermore, our methods can be performed on typical client hardware within a short period of time without even connecting to a potentially untrustworthy access point.
Fabian Lanze, Andriy Panchenko 0001, Ignacio Ponce-Alcaide, Thomas Engel 0001
CCNC2
2014 Letting the puss in boots sweat: detecting fake access points using dependency of clock skews on temperature
abstract
The only available IEEE 802.11 network identifiers (i.e., the network name and the MAC address) can be easily spoofed. Consequently, an attacker is able to fake a real hotspot and attract its traffic. By this means, the attacker can intercept, collect, or change users' traffic (often even if it is encrypted). In this paper, we describe an efficient method for detecting the replacement of access points (APs) by passive remote physical device fingerprinting. The main feature of our fingerprinting approach is the clock skew - an unavoidable phenomenon that causes clocks to run at minuscule yet remotely observable different speeds - which is extracted from information contained in beacon frames. We are the first to achieve a high discriminability of devices by completely eliminating the fingerprinters' influence and considering the clock skew's dependency on temperature. Finally, we develop a method for reliable detection of the presence of AP impostors that works without explicit temperature information. Compared to the best state-of-the-art approach, our method improves detection accuracy from about 30% to 90% without generating any traffic and requires less than one minute to collect a sufficient number of observations. Our approach yields a strong feature for passive remote physical device fingerprinting in wireless networks.
Fabian Lanze, Andriy Panchenko 0001, Benjamin Braatz, Thomas Engel 0001
AsiaCCS2
2012 Clock skew based remote device fingerprinting demystified
abstract
Commonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew - an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for passive fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification.
Fabian Lanze, Andriy Panchenko 0001, Benjamin Braatz, Andreas Zinnen
GLOBECOM2
2012 Improving performance and anonymity in the Tor network
abstract
Anonymous communication aims to hide the relationship between communicating parties on the Internet. It is the technical basis for achieving privacy and overcoming censorship. Presently there are only a few systems that are of practical relevance for providing anonymity. One of the most widespread and well researched is Tor which is based on onion routing. Usage of Tor, however, often leads to long delays which are not tolerated by end-users. This, in return, discourages many of them from using the system and lowers the protection for the remaining ones. In this paper we analyze the bottlenecks in the Tor network and propose new methods of path selection that better utilize available capacities in the heterogeneous network and allow performance-improved onion routing. Our methods are based on the combination of remotely measured current load of the nodes and an estimation of their maximum capacity. We evaluate the proposed methods in a Tor network running in PlanetLab where we tried as far as possible to recreate real-world conditions. Finally, we present a practical approach to empirically analyze the strength of anonymity that different methods of path selection provide in comparison to each other. We show the risk of the currently used method for path selection in Tor and provide a countermeasure to protect against this risk by effectively detecting nodes that lie about their capacity.
Andriy Panchenko 0001, Fabian Lanze, Thomas Engel 0001
IPCCC1
2011 Lightweight Hidden Services
abstract
Hidden services (HS) are mechanisms designed to provide network services while preserving anonymity for the identity of the server. Besides protecting the identity of the server, hidden services help to resist censorship, are resistant against distributed DoS attacks, and allow server functionality even if the service provider does not own a public IP address. Currently, only the Tor network offers this feature in full functionality. However, the HS concept in Tor is complex and provides poor performance. According to recent studies, average contact time for a hidden service is 24s which is far beyond what an average user is willing to wait. In this paper we introduce a novel approach for hidden services that achieves similar functionality as HS in Tor but does so in a simple and lightweight way with the goal to improve performance and usability. Additionally, contrary to Tor, in our approach clients are not required to install any specific software for accessing hidden services. This increases usability of our approach. Simplicity makes our approach easier to understand for normal users, eases protocol reviews, and increases chances of having several implementations of the protocol available. Moreover, simpler solutions are easier to analyze and they are naturally less prone to implementation failures rather than complex protocols. In this paper, we describe our approach and provide performance as well as anonymity analysis of resulting properties of the protocol.
Andriy Panchenko 0001, Otto Spaniol, André Egners, Thomas Engel 0001
TrustCom1
2009 NISAN: network information service for anonymization networks
abstract
Network information distribution is a fundamental service for any anonymization network. Even though anonymization and information distribution about the network are two orthogonal issues, the design of the distribution service has a direct impact on the anonymization. Requiring each node to know about all other nodes in the network (as in Tor and AN.ON -- the most popular anonymization networks) limits scalability and offers a playground for intersection attacks. The distributed designs existing so far fail to meet security requirements and have therefore not been accepted in real networks.
Andriy Panchenko 0001, Stefan Richter 0001, Arne Rache
CCS1
2009 Interconnected Tool-assistance for Development of Agent-oriented Software Systems
Karl-Heinz Krempels, Andriy Panchenko 0001, Janno von Stülpnagel, Christoph Terwelp
KEOD2
2009 SHALON: Lightweight Anonymization Based on Open Standards
abstract
In this paper, we introduce a novel lightweight anonymization technique called Shalon. It is based on onion routing, aims to reduce complexity, and delivers high bandwidth. We have, compared to the widely known approach Tor, slightly reduced the level of security in favor for greatly increased performance. The most significant advantage compared to other approaches is that Shalon is fully based on standardized protocols, which makes our approach highly efficient and easy to deploy. It also makes Shalon easier to understand for normal users, eases protocol reviews, and increases the chance of having several implementations of Shalon available. In this work, we provide a description of the design and implementation of Shalon, a performance and anonymity analysis, and a discussion on the scalability properties.
Andriy Panchenko 0001, Benedikt Westermann, Lexi Pimenidis, Christer Andersson
ICCCN1
2008 Performance Analysis of Anonymous Communication Channels Provided by Tor
abstract
Providing anonymity for end-users on the Internet is a very challenging and difficult task. There are currently only a few systems that are of practical relevance for the provision of low-latency anonymity. One of the most important to mention is the Tor network that is based on onion routing. Practical usage of the system often leads to delays which are not tolerated by the average end-user. This, in return, discourages many of them from the use of such systems and hence indirectly lowers the protection of remaining users due to a smaller user base. In this paper we show to which extend overloaded nodes and links, as well as geographical diversity of nodes have an influence on the general performance of Tor communication channels. After that, we propose new methods of path selection for performance-improved onion routing which are based on actively measured latencies and estimated available capacities using passive observations of link- wise throughput.
Andriy Panchenko 0001, Lexi Pimenidis, Johannes Renner
ARES1
2008 Self-certified Sybil-free pseudonyms
abstract
Accurate and trusted identifiers are a centerpiece for any security architecture. Protecting against Sybil attacks in a privacy-friendly manner is a non-trivial problem in wireless infrastructureless networks, such as mobile ad hoc networks. In this paper, we introduce self-certified Sybil-free pseudonyms as a means to provide privacy-friendly Sybil-freeness without requiring continuous online availability of a trusted third party. These pseudonyms are self-certified and computed by the users themselves from their cryptographic long term identities. Contrary to identity certificates, we preserve location privacy and improve protection against some notorious attacks on anonymous communication systems.
Leonardo A. Martucci, Markulf Kohlweiss, Christer Andersson, Andriy Panchenko 0001
WISEC4
2008 A Self-certified and Sybil-Free Framework for Secure Digital Identity Domain Buildup
Christer Andersson, Markulf Kohlweiss, Leonardo A. Martucci, Andriy Panchenko 0001
WISTP4
2007 Using Trust to Resist Censorship in the Presence of Collusion
Andriy Panchenko 0001, Lexi Pimenidis
SEC1