EDBT 2026 Demo / reviewers in the wild / expert
Levente Buttyán
dblp:84/3267
· DBLP profile ↗
58ranked-venue papers
21as first author
5since 2021 · last 2025
0000-0003-4233-2559ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 35 · 16 first-authorSecurity and privacy · 18 · 5 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Targeted Attacks Against the TLSH Similarity Digest SchemeabstractSimilarity Digest Schemes are used in various applications (e.g. digital forensics, spam filtering, malware detection and malware clustering), which require them to be resistant against attacks aiming at generating (A) semantically similar inputs with very different similarity digest values, or (B) completely different inputs with very similar digest values. We show that TLSH, a widely used similarity digest function, is not robust enough against either kinds of attacks. More specifically, we propose automated methods to modify executable software binaries in a way that the modified binary has the exact same functionality as the original one, yet (A) its TLSH difference score from the original version becomes high, or (B) its TLSH digest becomes very similar to another arbitrary TLSH digest up to a complete digest collision. We evaluate our methods on a large data set containing malware binaries, and we also show that they can be used effectively to generate adversarial samples that evade detection by SIMBIoTA, a recently proposed similarity-based malware detection approach. Gábor Fuchs, Roland Nagy, Levente Buttyán |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A pipeline for processing large datasets of potentially malicious binaries with rate-limited access to a cloud-based malware analysis platformabstractIn this paper, we present a pipeline that we designed for cleaning and processing large datasets of potentially malicious binaries using access to a rate-limited cloud-based malware analysis platform. Our goal is to efficiently filter out and discard benign files, to extract metadata from the remaining, likely-to-be-malware samples, and to create graph-based databases containing only metadata of verified malware. The main issue that we have to solve is the limited quota for accessing online malware analysis platforms that can be used for deciding about the maliciousness of a binary and obtaining metadata from static and dynamic analysis of samples. Our pipeline solves the problem by reaching a state where every sample in the database is either confirmed malware (based on its VirusTotal report) or similar to a confirmed malware with a minimal amount of requests made to the online platform. A database in such a state is already usable in practice, while confirming the malicious nature of and extracting metadata for all the samples in it can be continued in the background. Dávid Maliga, Roland Nagy, Levente Buttyán |
MASCOTS | 3 |
| 2023 | A Practical Attack on the TLSH Similarity Digest SchemeabstractSimilarity digest schemes are used in various applications (e.g., digital forensics, spam filtering, malware clustering, and malware detection), which require them to be resistant to attacks aiming at generating semantically similar inputs that have very different similarity digest values. In this paper, we show that TLSH, a widely used similarity digest function, is not sufficiently robust against such attacks. More specifically, we propose an automated method for modifying executable files (binaries), such that the modified binary has the exact same functionality as the original one, it also remains syntactically similar to the original one, yet, the TLSH difference score between the original and the modified binaries becomes high. We evaluate our method on a large data set containing malware binaries, and we also show that it can be used effectively to generate adversarial samples that evade detection by SIMBIoTA, a recently proposed similarity-based malware detection approach. Gábor Fuchs, Roland Nagy, Levente Buttyán |
ARES | 3 |
| 2022 | SIMBIoTA-ML: Light-weight, Machine Learning-based Malware Detection for Embedded IoT Devices
Dorottya Papp, Gergely Ács, Roland Nagy, Levente Buttyán |
IoTBDS | 4 |
| 2021 | SIMBIoTA: Similarity-based Malware Detection on IoT Devices
Csongor Tamás, Dorottya Papp, Levente Buttyán |
IoTBDS | 3 |
| 2020 | Clustering IoT Malware based on Binary SimilarityabstractIn this paper, we propose to cluster malware samples based on their TLSH similarity. We apply this approach to clustering IoT malware samples as IoT botnets built from malware infected IoT devices are becoming an important trend. We study the performance of two distance-based clustering algorithms, k-medoid and OPTICS, on a large corpus of IoT malware samples when they are used with the TLSH difference metric to measure distances between samples. Our results show that neither of the two algorithms have acceptable clustering performance. Hence, we propose a new clustering algorithm, which achieves a performance superior to both k-medoid and OPTICS. Márton Bak, Dorottya Papp, Csongor Tamás, Levente Buttyán |
NOMS | 4 |
| 2019 | Towards Detecting Trigger-Based Behavior in Binaries: Uncovering the Correct Environment
Dorottya Papp, Thorsten Tarrach, Levente Buttyán |
SEFM | 3 |
| 2017 | Towards Semi-automated Detection of Trigger-based Behavior for Software Security AssuranceabstractA program exhibits trigger-based behavior if it performs undocumented, often malicious, functions when the environmental conditions and/or specific input values match some pre-specified criteria. Checking whether such hidden functions exist in the program is important for increasing trustworthiness of software. In this paper, we propose a framework to effectively detect trigger-based behavior at the source code level. Our approach is semi-automated: We use automated source code instrumentation and mixed concrete and symbolic execution to generate potentially suspicious test cases that may trigger hidden, potentially malicious functions. The test cases must be investigated by a human analyst manually to decide which of them are real triggers. While our approach is not fully automated, it greatly reduces manual work by allowing analysts to focus on a few test cases found by our automated tools. Dorottya Papp, Levente Buttyán, Zhendong Ma |
ARES | 2 |
| 2016 | Membrane: A Posteriori Detection of Malicious Code Loading by Memory Paging Analysis
Gábor Pék, Zsombor Lázár, Zoltán Várnagy, Márk Félegyházi, Levente Buttyán |
ESORICS (1) | 5 |
| 2015 | Embedded systems security: Threats, vulnerabilities, and attack taxonomyabstractEmbedded systems are the driving force for technological development in many domains such as automotive, healthcare, and industrial control in the emerging post-PC era. As more and more computational and networked devices are integrated into all aspects of our lives in a pervasive and “invisible” way, security becomes critical for the dependability of all smart or intelligent systems built upon these embedded systems. In this paper, we conduct a systematic review of the existing threats and vulnerabilities in embedded systems based on public available data. Moreover, based on the information, we derive an attack taxonomy for embedded systems. We envision that the findings in this paper provide a valuable insight of the threat landscape facing embedded systems. The knowledge can be used for a better understanding and the identification of security risks in system analysis and design. Dorottya Papp, Zhendong Ma, Levente Buttyán |
PST | 3 |
| 2014 | Towards the automated detection of unknown malware on live systemsabstractIn this paper, we propose a new system monitoring framework that can serve as an enabler for automated malware detection on live systems. Our approach takes advantage of the increased availability of hardware assisted virtualization capabilities of modern CPUs, and its basic novelty consists in launching a hypervisor layer on the live system without stopping and restarting it. This hypervisor runs at a higher privilege level than the OS itself, thus, it can be used to observe the behavior of the analyzed system in a transparent manner. For this purpose, we also propose a novel system call tracing method that is designed to be configurable in terms of transparency and granularity. Gábor Pék, Levente Buttyán |
ICC | 2 |
| 2013 | SDTP+: Securing a distributed transport protocol for WSNs using Merkle trees and Hash chainsabstractTransport protocols for Wireless Sensor Networks (WSNs) are designed to fulfill both reliability and energy efficiency requirements. Distributed Transport for Sensor Networks (DTSN) [1] is one of the most promising transport protocols designed for WSNs because of its effectiveness; however, it does not address any security issues, hence it is vulnerable to many attacks. The first secure transport protocol for WSN was the secure distributed transport protocol (SDTP) [2], which is a security extension of DTSN. Unfortunately, it turns out that the security methods provided by SDTP are not sufficient; some tricky attacks get around the protection mechanism. In this paper, we describe the security gaps in the SDTP protocol, and we introduce SDTP+for patching the weaknesses. We show that SDTP+resists attacks on reliability and energy efficiency of the protocol, and also present an overhead analysis for showing its effectiveness. Amit Dvir, Levente Buttyán, Ta Vinh Thong 0001 |
ICC | 2 |
| 2013 | Welcome message from the D-SPAN 2013 chairsabstractAs the organizing committee, it is our pleasure to present the proceedings of the 4th IEEE International Workshop on Data Security and PrivAcy in wireless Networks (D-SPAN), held on June 4, 2013, in Madrid, Spain. The goal of this one-day workshop, organized in conjunction with the 14th IEEE WoWMoM 2013, is to exchange cutting-edge ideas for securing the next-generation wireless networks, systems, and applications. D-SPAN covers a wide range of security-related topics, including security and privacy of data collection, transmission, storage, publishing, and sharing in wireless networks broadly defined such as cellular and mobile ad hoc networks (MANET), vehicular ad hoc networks (VANET), cognitive and sensor networks to applying data analytics techniques to address security and privacy challenges in these networks. D-SPAN provides a forum for academic and industry researchers to present research ideas that build bridges across three communities: wireless networks, databases, and security. Guevara Noubir, Krishna Sampigethaya, Levente Buttyán, Loukas Lazos |
WOWMOM | 3 |
| 2013 | Designing robust network topologies for wireless sensor networks in adversarial environments
Aron Laszka, Levente Buttyán, Dávid Szeszlér |
Pervasive Mob. Comput. | 2 |
| 2012 | Query Auditing for Protecting Max/Min Values of Sensitive Attributes in Statistical Databases
Ta Vinh Thong 0001, Levente Buttyán |
TrustBus | 2 |
| 2012 | Traffic analysis attacks and countermeasures in wireless body area sensor networksabstractIn this paper, we study the problem of traffic analysis attacks in wireless body area sensor networks. When these networks are used in health-care for remote patient monitoring, traffic analysis can reveal the type of medical sensors mounted on the patient, and this information may be used to infer the patient's health problems. We show that simple signal processing methods can be used effectively for performing traffic analysis attacks and identifying the sensor types in a rather weak adversary model. We then investigate possible traffic obfuscation mechanisms aiming at hiding the regular patterns in the observable wireless traffic. Among the investigated countermeasures, traffic shaping, a mechanism that introduces carefully chosen delays for message transmissions, appears to be the best choice, as it achieves close to optimal protection and incurs no overhead. Levente Buttyán, Tamás Holczer |
WOWMOM | 1 |
| 2012 | Secure and reliable clustering in wireless sensor networks: A critical survey
Péter Schaffer, Károly Farkas, Ádám Horváth, Tamás Holczer, Levente Buttyán |
Comput. Networks | 5 |
| 2011 | A Secure Distributed Transport Protocol for Wireless Sensor NetworksabstractWe propose a secure distributed transport protocol for wireless sensor networks that resists against attacks on the reliability service provided by the protocol, as well as against energy depleting attacks. Our protocol is based on the Distributed Transport for Sensor Networks (DTSN) protocol, to which we add a security extension that consists in an efficient, symmetric key based authentication scheme for control packets. Besides describing the operation of our protocol, we also provide its analysis in terms of security and overhead. Levente Buttyán, António Grilo 0001 |
ICC | 1 |
| 2011 | VeRA - Version Number and Rank Authentication in RPLabstractDesigning a routing protocol for large low-power and lossy networks (LLNs), consisting of thousands of constrained nodes and unreliable links, presents new challenges. The IPv6 Routing Protocol for Low-power and Lossy Networks (RPL), have been developed by the IETF ROLL Working Group as a preferred routing protocol to provide IPv6 routing functionality in LLNs. RPL provides path diversity by building and maintaining directed acyclic graphs (DAG) rooted at one (or more) gateway. However, an adversary that impersonates a gateway or has compromised one of the nodes close to the gateway can divert a large part of network traffic forward itself and/or exhaust the nodes' batteries. Therefore in RPL, special security care must be taken when the Destination Oriented Directed Acyclic Graph (DODAG) root is updating the Version Number by which reconstruction of the routing topology can be initiated. The same care also must be taken to prevent an internal attacker (compromised DODAG node) to publish decreased Rank value, which causes a large part of the DODAG to connect to the DODAG root via the attacker and give it the ability to eavesdrop a large part of the network traffic forward itself. Unfortunately, the currently available security services in RPL will not protect against a compromised internal node that can construct and disseminate fake messages. In this paper, a new security service is described that prevents any misbehaving node from illegitimately increasing the Version Number and compromise illegitimate decreased Rank values. Amit Dvir, Tamás Holczer, Levente Buttyán |
MASS | 3 |
| 2011 | Optimal selection of sink nodes in wireless sensor networks in adversarial environmentsabstractIn this paper, we address the problem of assigning the sink role to a subset of nodes in a wireless sensor network with a given topology such that the resulting network configuration is robust against denial-of-service type attacks such as node destruction, battery exhaustion and jamming. In order to measure robustness, we introduce new metrics based on a notion defined in [1]. We argue that our metrics are more appropriate to measure the robustness of network configurations than the widely known connectivity based metrics. We formalize the problem of selecting the sink nodes as an optimization problem aiming at minimizing the deployment budget while achieving a certain level of robustness.We propose an efficient greedy heuristic algorithm that approximates the optimal solution reasonably well. Aron Laszka, Levente Buttyán, Dávid Szeszlér |
WOWMOM | 2 |
| 2011 | Detection and Recovery from Pollution Attacks in Coding-Based Distributed Storage SchemesabstractWe address the problem of pollution attacks in coding-based distributed storage systems. In a pollution attack, the adversary maliciously alters some of the stored encoded packets, which results in the incorrect decoding of a large part of the original data upon retrieval. We propose algorithms to detect and recover from such attacks. In contrast to existing approaches to solve this problem, our approach is not based on adding cryptographic checksums or signatures to the encoded packets, and it does not introduce any additional redundancy to the system. The results of our analysis show that our proposed algorithms are suitable for practical systems, especially in wireless sensor networks. Levente Buttyán, László Czap 0002, István Vajda |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2010 | Perfectly anonymous data aggregation in wireless sensor networksabstractClustering and data aggregation in wireless sensor networks improves scalability, and helps the efficient use of scarce resources. Yet, these mechanisms also introduce some security issues; in particular, aggregator nodes become attractive targets of physical destruction and jamming attacks. In order to mitigate this problem, we propose a new private aggregator node election protocol that hides the identity of the elected aggregator nodes both from external eavesdroppers and from compromised nodes participating in the protocol. We also propose a private data aggregation protocol and a corresponding private query protocol which allows the aggregators to collect sensor readings and respond to queries of the base station, respectively, without revealing any useful information about their identity to external eavesdroppers and to compromised nodes. Levente Buttyán, Tamás Holczer |
MASS | 1 |
| 2010 | Misbehaving router detection in link-state routing for wireless mesh networksabstractIn this paper, we address the problem of detecting misbehaving routers in wireless mesh networks and avoiding them when selecting routes. We assume that link-state routing is used, and we essentially propose a reputation system, where trusted gateway nodes compute Node Trust Values for the routers, which are fed back into the system and used in the route selection procedure. The computation of the Node Trust Values is based on packet counters maintained in association with each route and reported to the gateways by the routers in a regular manner. The feedback mechanism is based on limited scope flooding. The received Node Trust Values concerning a given router are aggregated, and the aggregate trust value of the router determines the probability with which that router is kept in the topology graph used for route computation. Hence, less trusted routers are excluded from the topology graph with higher probability, while the route selection still runs on a weighted graph (where the weights are determined by the announced link qualities), and it does not need to be changed. We evaluated the performance of our solution by means of simulations. The results show that our proposed mechanism can detect misbehaving routers reliably, and thanks to the feedback and the exclusion of the accused nodes from the route selection, we can decrease the number of packets dropped due to router misbehavior considerably. At the same time, our mechanism only slightly increases the average route length. Gergely Ács, Levente Buttyán, László Dóra |
WOWMOM | 2 |
| 2010 | Barter trade improves message delivery in opportunistic networks
Levente Buttyán, László Dóra, Márk Félegyházi, István Vajda |
Ad Hoc Networks | 1 |
| 2010 | Fast certificate-based authentication scheme in multi-operator maintained wireless mesh networks
Levente Buttyán, László Dóra, Fabio Martinelli, Marinella Petrocchi |
Comput. Commun. | 1 |
| 2010 | Securing multi-operator-based QoS-aware mesh networks: requirements and design optionsabstractAbstract Wireless mesh networking allows network operators and service providers to offer nearly ubiquitous broadband access at a low cost to customers. In this paper, we focus on QoS‐aware mesh networks operated by multiple operators in a cooperative manner. In particular, we identify the general security requirements of such networks and we give an overview on the available design options for a security architecture aiming at satisfying those requirements. More specifically, we consider the problems of mesh client authentication and access control, protection of wireless communications, securing the routing, key management, and intrusion and misbehavior detection and recovery. Our aim is to structure this rich problem domain and to prepare the grounds for the design of a practically usable security architecture. Copyright © 2008 John Wiley & Sons, Ltd. Ioannis G. Askoxylakis, Boldizsár Bencsáth, Levente Buttyán, László Dóra, Vasilios A. Siris, D. Szili, István Vajda |
Wirel. Commun. Mob. Comput. | 3 |
| 2009 | Private Cluster Head Election in Wireless Sensor NetworksabstractClustering is a useful mechanism in wireless sensor networks that helps to cope with scalability problems and, if combined with in-network data aggregation, may increase the energy efficiency of the network. At the same time, by assigning a special role to the cluster head nodes, clustering makes the network more vulnerable to attacks. In particular, disabling a cluster head by physical destruction or jamming may render the entire cluster inoperable temporarily until the problem is detected and a new cluster head is elected. Hence, the cluster head nodes may be attractive targets of attacks, and one would like to make it difficult for an adversary to identify them. The adversary can try to identify the cluster head nodes in various ways, including the observation of the cluster head election process itself and the analysis of the traffic patterns after the termination of the cluster head election. In this paper, we focus on the former problem, which we call the private cluster head election problem. This problem has been neglected so far, and as a consequence, existing cluster head election protocols leak too much information making the identification of the elected cluster head nodes easy even for a passive external observer. We propose the first private cluster head election protocol for wireless sensor networks that is designed to hide the identity of the elected cluster head nodes from an adversary that can observe the execution of the protocol. Levente Buttyán, Tamás Holczer |
MASS | 1 |
| 2009 | An authentication scheme for QoS-aware multi-operator maintained wireless mesh networksabstractIn this paper, we consider QoS aware mesh networks that are maintained by multiple operators and they cooperate in the provision of networking services to the mesh clients. In order to support mobile users and seamless handover between the access points, the authentication delay has to be reduced. Many proposed fast authentication schemes rely on trust models that are not appropriate in multi-operator environment. Here, we propose two certificate based authentication schemes such that the authentication is performed locally between the access point and the mesh client. We consider both powerful and constraint mesh clients and we propose certificate sets to decrease the authentication latency. We compare our proof-of-concept implementation to current widely used authentication methods like EAP-TLS, and we conclude that our proposed authentication scheme is considerably faster in all considered scenarios. Levente Buttyán, László Dóra |
WOWMOM | 1 |
| 2009 | CORA: Correlation-based resilient aggregation in sensor networks
Levente Buttyán, Péter Schaffer, István Vajda |
Ad Hoc Networks | 1 |
| 2008 | Securing coding based distributed storage in wireless sensor networksabstractWe address the problem of pollution attacks in coding based distributed storage systems proposed for wireless sensor networks. In a pollution attack, the adversary maliciously alters some of the stored encoded packets, which results in the incorrect decoding of a large part of the original data upon retrieval. We propose algorithms to detect and recover from such attacks. In contrast to existing approaches to solve this problem, our approach is not based on adding cryptographic checksums or signatures to the encoded packets. We believe that our proposed algorithms are suitable in practical systems. Levente Buttyán, László Czap 0002, István Vajda |
MASS | 1 |
| 2007 | The Security Proof of a Link-state Routing Protocol for Wireless Sensor NetworksabstractIn this paper, we present a flexible and mathematically rigorous modeling framework for analyzing the security of sensor network routing protocols. Then, we demonstrate the usage of this framework by formally proving that INSENS (Intrusion-Tolerant Routing in Wireless Sensor Networks), which is a secure sensor network routing protocol proposed in the literature independently of our work, can be proven to be secure in our model. Gergely Ács, Levente Buttyán, István Vajda |
MASS | 2 |
| 2007 | PANEL: Position-based Aggregator Node Election in Wireless Sensor NetworksabstractIn this paper, we introduce PANEL, a position-based aggregator node election protocol for wireless sensor networks. The novelty of PANEL with respect to other aggregator node election protocols is that it supports asynchronous sensor network applications where the sensor readings are fetched by the base stations after some delay. In particular, the motivation for the design of PANEL was to support reliable and persistent data storage applications, such as TinyPEDS. PANEL ensures load balancing, and it supports intra-and inter-cluster routing allowing sensor to aggregator, aggregator to aggregator, base station to aggregator, and aggregator to base station communications. We also present simulation results showing that PANEL is very energy efficient. Levente Buttyán, Péter Schaffer |
MASS | 1 |
| 2007 | Group-Based Private AuthenticationabstractWe propose a novel authentication scheme that ensures privacy of the provers. Our scheme is based on symmetric-key cryptography, and therefore, it is well-suited to resource constrained applications in large scale environments. A typical example for such an application is an RFID system, where the provers are low-cost RFID tags, and the number of the tags can potentially be very large. We analyze the proposed scheme and show that it is superior to the well-known key-tree based approach for private authentication both in terms of privacy and efficiency. Gildas Avoine, Levente Buttyán, Tamás Holczer, István Vajda |
WOWMOM | 2 |
| 2007 | Barter-based cooperation in delay-tolerant personal wireless networksabstractIn this paper, we consider the application of delay-tolerant networks to personal wireless communications. In these networks, selfish nodes can exploit the services provided by other nodes by downloading messages that interest them, but refusing to store and distribute messages for the benefit of other nodes. We propose a mechanism to discourage selfish behavior based on the principles of barter. We develop a game-theoretic model in which we show that the proposed approach indeed stimulates cooperation of the nodes. In addition, the results show that the individually most beneficial behavior leads to the social optimum of the system. Levente Buttyán, László Dóra, Márk Félegyházi, István Vajda |
WOWMOM | 1 |
| 2007 | Guest Editorial Non-Cooperative Behavior in NetworkingabstractKeywords: NCCR-MICS ; NCCR-MICS/CL3 Reference LCA-ARTICLE-2007-012 Record created on 2007-06-06, modified on 2017-05-12 Levente Buttyán, Jean-Pierre Hubaux, Xiang-Yang Li 0001, Timothy Roughgarden, Alberto Leon-Garcia |
IEEE J. Sel. Areas Commun. | 1 |
| 2006 | Provably Secure On-Demand Source Routing in Mobile Ad Hoc NetworksabstractRouting is one of the most basic networking functions in mobile ad hoc networks. Hence, an adversary can easily paralyze the operation of the network by attacking the routing protocol. This has been realized by many researchers and several "secure” routing protocols have been proposed for ad hoc networks. However, the security of those protocols has mainly been analyzed by informal means only. In this paper, we argue that flaws in ad hoc routing protocols can be very subtle, and we advocate a more systematic way of analysis. We propose a mathematical framework in which security can be precisely defined and routing protocols for mobile ad hoc networks can be proved to be secure in a rigorous manner. Our framework is tailored for on-demand source routing protocols, but the general principles are applicable to other types of protocols too. Our approach is based on the simulation paradigm, which has already been used extensively for the analysis of key establishment protocols, but, to the best of our knowledge, it has not been applied in the context of ad hoc routing so far. We also propose a new on-demand source routing protocol, called endairA, and we demonstrate the use of our framework by proving that it is secure in our model. Gergely Ács, Levente Buttyán, István Vajda |
IEEE Trans. Mob. Comput. | 2 |
| 2006 | Mobility Helps Peer-to-Peer SecurityabstractWe propose a straightforward technique to provide peer-to-peer security in mobile networks. We show that far from being a hurdle, mobility can be exploited to set up security associations among users. We leverage on the temporary vicinity of users, during which appropriate cryptographic protocols are run. We illustrate the operation of the solution in two scenarios, both in the framework of mobile ad hoc networks. In the first scenario, we assume the presence of an offline certification authority and we show how mobility helps to set up security associations for secure routing; in this case, the security protocol runs over one-hop radio links. We further show that mobility can be used for the periodic renewal of vital security information (e.g., the distribution of hash chain/Merkle tree roots). In the second scenario, we consider fully self-organized security: Users authenticate each other by visual contact and by the activation of an appropriate secure side channel of their personal device; we show that the process can be fuelled by taking advantage of trusted acquaintances. We then show that the proposed solution is generic: It can be deployed on any mobile network and it can be implemented either with symmetric or with asymmetric cryptography. We provide a performance analysis by studying the behavior of the solution in various scenarios. Srdjan Capkun, Jean-Pierre Hubaux, Levente Buttyán |
IEEE Trans. Mob. Comput. | 3 |
| 2006 | Nash Equilibria of Packet Forwarding Strategies in Wireless Ad Hoc NetworksabstractIn self-organizing ad hoc networks, all the networking functions rely on the contribution of the participants. As a basic example, nodes have to forward packets for each other in order to enable multihop communication. In recent years, incentive mechanisms have been proposed to give nodes incentive to cooperate, especially in packet forwarding. However, the need for these mechanisms was not formally justified. In this paper, we address the problem of whether cooperation can exist without incentive mechanisms. We propose a model,based on game theory and graph theory to investigate equilibrium conditions of packet forwarding strategies. We prove theorems about the equilibrium conditions for both cooperative and noncooperative strategies. We perform simulations to estimate the probability that the conditions for a cooperative equilibrium hold in randomly generated network scenarios.. As the problem is involved, we deliberately restrict ourselves to a static configuration. We conclude that in static ad hoc networks where the relationships between the nodes are likely to be stab le-cooperation needs to be encouraged. Márk Félegyházi, Jean-Pierre Hubaux, Levente Buttyán |
IEEE Trans. Mob. Comput. | 3 |
| 2006 | Node Cooperation in Hybrid Ad Hoc NetworksabstractA hybrid ad hoc network is a structure-based network that is extended using multihop communications. Indeed, in this kind of network, the existence of a communication link between the mobile station and the base station is not required: A mobile station that has no direct connection with a base station can use other mobile stations as relays. Compared with conventional (single-hop) structure-based networks, this new generation can lead to a better use of the available spectrum and to a reduction of infrastructure costs. However, these benefits would vanish if the mobile nodes did not properly cooperate and forward packets for other nodes. In this paper, we propose a charging and rewarding scheme to encourage the most fundamental operation, namely packet forwarding. We use "MAC layering" to reduce the space overhead in the packets and a stream cipher encryption mechanism to provide "implicit. authentication" of the nodes involved in the communication. We analyze the robustness of our protocols against rational and malicious attacks. We show that-using our solution-collaboration is rational for selfish nodes. We also show that our protocols thwart rational attacks and detect malicious attacks. Naouel Ben Salem, Levente Buttyán, Jean-Pierre Hubaux, Markus Jakobsson |
IEEE Trans. Mob. Comput. | 2 |
| 2005 | A Framework for the Revocation of Unintended Digital Signatures Initiated by Malicious TerminalsabstractHuman users need trusted computers when they want to generate digital signatures. In many applications, in particular, if the users are mobile, they need to carry their trusted computers with themselves. Smart cards are easy to use, easy to carry, and relatively difficult to tamper with, but they do not have a user interface; therefore, the user still needs a terminal for authorizing the card to produce digital signatures. If the terminal is malicious, it can mislead the user and obtain a digital signature on an arbitrary document. In order to mitigate this problem, we propose a solution based on conditional signatures. More specifically, we propose a framework for the controlled revocation of unintended digital signatures. We also propose a solution with a special emphasis on privacy issues. István Zsolt Berta, Levente Buttyán, István Vajda |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2004 | Privacy Protecting Protocols for Revocable Digital Signatures
István Zsolt Berta, Levente Buttyán, István Vajda |
CARDIS | 2 |
| 2004 | A formal model of rational exchange and its application to the analysis of Syverson's protocolabstractWe propose a formal model of rational exchange and exchange protocols in general, which is based on game theory. In this model, an exchange protocol is represented as a set of strategies in a game that is played by the protocol parties and the network that they use to communicate with each other. W ithin this model, we give a formal definition for rational exchange and various other properties of exchange protocols, including fairness. In particular, rational exchange is defined in terms of a Nash equilibrium in the protocol game. We also study the relationship between rational and fair exchange, and prove that fairness implies rationality, but not vice versa. Finally, we illustrate the usage of our formal model for the analysis of existing rational exchange protocols by analyzing a protocol proposed by Syverson. We show that the protocol is rational only under the assumption that the network is reliable. Levente Buttyán, Jean-Pierre Hubaux, Srdjan Capkun |
J. Comput. Secur. | 1 |
| 2003 | PoDSy 2003: Principles of Dependable Systems
Felix C. Freiling, Klaus Kursawe, Levente Buttyán |
DSN | 3 |
| 2003 | Mobility helps security in ad hoc networksabstractContrary to the common belief that mobility makes security more di#cult to achieve, we show that node mobility can, in fact, be useful to provide security in ad hoc networks. We propose a technique in which security associations between nodes are established, when they are in the vicinity of each other, by exchanging appropriate cryptographic material. We show that this technique is generic, by explaining its application to fully self-organized ad hoc networks and to ad hoc networks placed under an (o#-line) authority. We also propose an extension of this basic mechanism, in which a security association can be established with the help of a "friend". We show that our mechanism can work in any network configuration and that the time necessary to set up the security associations is strongly influenced by several factors, including the size of the deployment area, the mobility patterns, and the number of friends; we provide a detailed investigation of this influence. Srdjan Capkun, Jean-Pierre Hubaux, Levente Buttyán |
MobiHoc | 3 |
| 2003 | A charging and rewarding scheme for packet forwarding in multi-hop cellular networksabstractIn multi-hop cellular networks, data packets have to be relayed hop by hop from a given mobile station to a base station and vice-versa. This means that the mobile stations must accept to forward information for the benefit of other stations. In this paper, we propose an incentive mechanism that is based on a charging/rewarding scheme and that makes collaboration rational for selfish nodes. We base our solution on symmetric cryptography to cope with the limited resources of the mobile stations. We provide a set of protocols and study their robustness with respect to various attacks. By leveraging on the relative stability of the routes, our solution leads to a very moderate overhead. Naouel Ben Salem, Levente Buttyán, Jean-Pierre Hubaux, Markus Jakobsson |
MobiHoc | 2 |
| 2003 | Stimulating Cooperation in Self-Organizing Mobile Ad Hoc Networks
Levente Buttyán, Jean-Pierre Hubaux |
Mob. Networks Appl. | 1 |
| 2003 | Self-Organized Public-Key Management for Mobile Ad Hoc NetworksabstractIn contrast with conventional networks, mobile ad hoc networks usually do not provide online access to trusted authorities or to centralized servers, and they exhibit frequent partitioning due to link and node failures and to node mobility. For these reasons, traditional security solutions that require online trusted authorities or certificate repositories are not well-suited for securing ad hoc networks. We propose a fully self-organized public-key management system that allows users to generate their public-private key pairs, to issue certificates, and to perform authentication regardless of the network partitions and without any centralized services. Furthermore, our approach does not require any trusted authority, not even in the system initialization phase. Srdjan Capkun, Levente Buttyán, Jean-Pierre Hubaux |
IEEE Trans. Mob. Comput. | 2 |
| 2002 | A Formal Analysis of Syverson?s Rational Exchange ProtocolabstractIn this paper, we provide a formal analysis of a rational exchange protocol proposed by Syverson. A rational exchange protocol guarantees that misbehavior cannot generate benefits, and is therefore discouraged. The analysis is performed using our formal model, which is based on game theory. In this model, rational exchange is defined in terms of a Nash equilibrium. Levente Buttyán, Jean-Pierre Hubaux, Srdjan Capkun |
CSFW | 1 |
| 2002 | Small worlds in security systems: an analysis of the PGP certificate graphabstractWe propose a new approach to securing self-organized mobile ad hoc networks. In this approach, security is achieved in a fully self-organized manner; by this we mean that the security system does not require any kind of certification authority or centralized server, even for the initialization phase. In our work, we were inspired by PGP [15] because its operation relies solely on the acquaintances between users. We show that the small-world phenomenon naturally emerges in the PGP system as a consequence of the self-organization of users. We show this by studying the PGP certificate graph properties and by quantifying its small-world characteristics. We argue that the certificate graphs of self-organized security systems will exhibit a similar small-world phenomenon, and we provide a way to model self-organized certificate graphs. The results of the PGP certificate graph analysis and graph modelling can be used to build new self-organized security systems and to test the performance of the existing proposals. In this work, we refer to such an example. Srdjan Capkun, Levente Buttyán, Jean-Pierre Hubaux |
NSPW | 2 |
| 2001 | A Payment Scheme for Broadcast Multimedia StreamsabstractStreaming multimedia data on the Internet is developing as a mainstream technology, which attracts many users by providing a new and convenient form of access to online multimedia information. While its strong business potential is obvious, many problems related to charging, copyright protection, and privacy can delay or even hinder its extensive deployment. In this paper we are concerned with the charging problem, and propose an electronic payment scheme to use for purchasing broadcast multimedia streams. Our design respects the pay-per-use principle, makes cheating uninteresting for both the user and the service provider, resists forgery and over-spending, protects sensitive payment information and user privacy, and allows the identification of misbehaving users. Levente Buttyán, Naouel Ben Salem |
ISCC | 1 |
| 2001 | The quest for security in mobile ad hoc networksabstractSo far, research on mobile ad hoc networks has been forcused primarily on routing issues. Security, on the other hand, has been given a lower priority. This paper provides an overview of security problems for mobile ad hoc networks, distinguishing the threats on basic mechanisms and on security mechanisms. It then describes our solution to protect the security mechanisms. The original features of this solution include that (i) it is fully decentralized and (ii) all nodes are assigned equivalent roles. Jean-Pierre Hubaux, Levente Buttyán, Srdjan Capkun |
MobiHoc | 2 |
| 2000 | Enforcing service availability in mobile ad-hoc WANsabstractWe address the problem of service availability in mobile ad-hoc WANs. We present a secure mechanism to stimulate end users to keep their devices turned on, to refrain from overloading the network, and to thwart tampering aimed at converting the device into a "selfish" one. Our solution is based on the application of a tamper resistant security module in each device and cryptographic protection of messages. Levente Buttyán, Jean-Pierre Hubaux |
MobiHoc | 1 |
| 2000 | Towards mobile ad-hoc WANs: terminodesabstractTerminodes are personal devices that provide functionality of both the terminals and the nodes of the network. A network of terminodes is an autonomous, fully self-organized, wireless network, independent of any infrastructure. It must be able to scale up to millions of units, without any fixed backbone or server. In this paper we present the main challenges and discuss the main technical directions. Jean-Pierre Hubaux, Jean-Yves Le Boudec, Silvia Giordano, Maher Hamdi, Ljubica Blazevic, Levente Buttyán, Milan Vojnovic |
WCNC | 6 |
| 2000 | Extensions to an authentication technique proposed for the global mobility networkabstractWe present three attacks on the authentication protocol that has been proposed for the so-called global mobility network in the October 1997 issue of the IEEE Journal on Selected Areas in Communications. We show that the attacks are feasible and propose corrections that make the protocol more robust and resistant against two of the presented attacks. The aim is to highlight some basic design principles for cryptographic protocols, the adherence to which would have prevented these attacks. Levente Buttyán, Constant Gbaguidi, Sebastian Staamann, Uwe G. Wilhelm |
IEEE Trans. Commun. | 1 |
| 1999 | Closed user groups in Internet service centres
Sebastian Staamann, Levente Buttyán, Allan Coignet, Ernesto Ruggiano, Uwe G. Wilhelm, Marc Zweiacker |
DAIS | 2 |
| 1999 | Accountable Anonymous Access to Services in Mobile Communication SystemsabstractWe introduce a model that allows anonymous yet accountable access to services in mobile communication systems. This model is based on the introduction of a new business role, called the customer care agency and a ticket based mechanism for service access. We introduce the general idea of ticket based service access, and present a categorisation of ticket types and ticket acquisition models. We analyse the role of customer care agencies and emphasise their advantages. Levente Buttyán, Jean-Pierre Hubaux |
SRDS | 1 |
| 1998 | A Simple Logic for Authentication Protocol DesignabstractThe authors describe a simple logic. The logic uses the notion of channels that are generalisations of communication links with various security properties. The abstract nature of channels enables one to treat the protocol at a higher abstraction level than do most of the known logics for authentication, and thus, one can address the higher level functional properties of the system, without having to be concerned with the problems of the actual implementation. The major advantage of the proposed logic is its suitability for the design of authentication protocols. They give a set of synthetic rules that can be used by protocol designers to construct a protocol in a systematic way. Levente Buttyán, Sebastian Staamann, Uwe G. Wilhelm |
CSFW | 1 |
| 1998 | On the Problem of Trust in Mobile Agent Systems
Uwe G. Wilhelm, Sebastian Staamann, Levente Buttyán |
NDSS | 3 |