EDBT 2026 Demo / reviewers in the wild / expert
Ivan Martinovic
dblp:87/2623
· DBLP profile ↗
102ranked-venue papers
11as first author
34since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 78 · 7 first-author · 30 since 2021Computer networks · 13 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 2Human-computer interaction and ubiquitous computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VET Your Agent: Towards Host-Independent Autonomy via Verifiable Execution TracesabstractRecent advances in large language models (LLMs) have enabled a new generation of autonomous agents that operate over sustained periods and manage sensitive resources on behalf of users. Trusted for their ability to act without direct oversight, such agents are increasingly considered in high-stakes domains including financial management, dispute resolution, and governance. Yet in practice, agents execute on infrastructure controlled by a host, who can tamper with models, inputs, or outputs, undermining any meaningful notion of autonomy. We address this gap by introducing VET (Verifiable Execution Traces), a formal framework that achieves host-independent authentication of agent outputs and takes a step toward host-independent autonomy. Central to VET is the Agent Identity Document (AID), which specifies an agent's configuration together with the proof systems required for verification. VET is compositional: it supports multiple proof mechanisms, including trusted hardware, succinct cryptographic proofs, and notarized TLS transcripts (Web Proofs). We implement VET for an API-based LLM agent and evaluate our instantiation on realistic workloads. We find that for today's black-box, secret-bearing API calls, Web Proofs appear to be the most practical choice, with overhead typically under 3$\times$ compared to direct API calls, while for public API calls, a lower-overhead TEE Proxy is often sufficient. As a case study, we deploy a verifiable trading agent that produces proofs for each decision and composes Web Proofs with a TEE Proxy. Our results demonstrate that practical, host-agnostic authentication is already possible with current technology, laying the foundation for future systems that achieve full host-independent autonomy. Artem Grigor, Christian Schröder de Witt, Simon Birnbach, Ivan Martinovic |
AsiaCCS | 4 |
| 2026 | Finding Phones Fast: Low-Latency and Scalable Monitoring of Cellular Communications in Sensitive AreasabstractThe widespread availability of cellular devices introduces new threat vectors that allow users or attackers to bypass security policies and physical barriers and bring unauthorized devices into sensitive areas. These threats can arise from user non-compliance or deliberate actions aimed at data exfiltration/infiltration via hidden devices, drones, etc. We identify a critical gap in this context: the absence of low-latency systems for high-quality and instantaneous monitoring of cellular transmissions. Such low-latency systems are crucial to allow for timely detection, decision (e.g., geofencing or localization), and disruption of unauthorized communication in sensitive areas. Operator-based monitoring systems, built for purposes such as people counting or tracking, lack real-time capability, require cooperation across multiple operators, and thus are hard to deploy. Operator-independent monitoring approaches proposed in the literature either lack low-latency capabilities or do not scale. We propose WaveTag, the first low-latency, operator-independent, and scalable system designed to monitor 5G and LTE connections across all operators prior to any user data transmission. WaveTag consists of several downlink receivers and a distributed network of uplink receivers that measure both downlink protocol information and uplink signal characteristics at multiple locations to gain a detailed spatial image of uplink signals. WaveTag then aggregates the recorded information, processes it, and provides a decision about the connection before the UE completes connection establishment. To evaluate WaveTag, we deployed it in the context of geofencing, where WaveTag was able to determine whether the signals originate from inside or outside of an area within 2.3 ms of the initial base station-to-device message, therefore enabling prompt and targeted suppression of communication before any Martin Kotuliak, Simon Erni, Jakub Polák, Marc Röschlin, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
WISEC | 6 |
| 2026 | OpenSky: How a Security Project Became Global Infrastructure
Ivan Martinovic, Martin Strohmeier |
WISEC | 1 |
| 2026 | SideDish: Low-Cost Anti-Spoofing Countermeasure for Satellite Data CommunicationsabstractSatellite systems are increasingly vulnerable to spoofing attacks at the physical layer, where adversaries use inexpensive radio equipment to interfere with and replace legitimate signals. While cryptographic countermeasures are common in other wireless systems, their adoption in new space programs is slow due to concerns about the associated implications on robustness, cost, weight, power, and the challenges of updating existing systems. In this paper we introduce SideDish, a novel anti-spoofing countermeasure that combines a secondary receiver colocated at the satellite receiver with decoded signal comparison to detect out-of-beam unauthentic interference. The system is retrofittable into existing ground station deployments, cheap by using only low-cost components, and is robust against denial of service attacks. We verify this through simulations and real-world experiments that show SideDish spatially constraints attackers by between 70-99.84% in the angular domain, even considering scattering effects of the primary antenna. Targeting SideDish to deny service is not feasible within practical constraints, requiring microsecond-order timing accuracy to overcome. Edd Salkield, Louis-Emile Ploix, Martin Strohmeier, Sebastian Köhler 0005, Simon Birnbach, Ivan Martinovic |
WISEC | 6 |
| 2026 | SatIQ: Extensible and Stable Satellite Authentication using Hardware FingerprintingabstractAs satellite systems become a greater part of critical infrastructure, they have become a significantly more appealing target for attacks. The availability of cheap off-the-shelf radio hardware has made signal spoofing and physical layer attacks more accessible than ever to a wide range of adversaries, from hobbyists to nation-state actors. Legacy systems are particularly vulnerable due to their lack of cryptographic security, and cannot be patched to support novel security measures. In this article, we use radio transmitter fingerprinting to authenticate satellite downlinks, using characteristics of the transmitter hardware expressed as impairments on the physical layer radio signal. Our SatIQ system employs a Siamese neural network and an autoencoder to extract an efficient encoding of message headers that preserves identifying information. We focus on high sample rate fingerprinting, making device fingerprints difficult to forge without similarly high sample rate transmitting hardware. We collected 10290000 messages from the Iridium satellite constellation at 25 MS/s, and demonstrate that the SatIQ model trained on this data maintains performance over time without retraining, and can be used on new transmitters with no impact on performance. We analyze the system’s robustness against weather and signal factors, and demonstrate its effectiveness under attack, achieving an Equal Error Rate of 0.072 and ROC AUC of 0.960. We conclude that our techniques are useful for building fingerprinting systems that are effective at authenticating satellite communication, maintain performance over time and across satellite replacement, and provide robustness against spoofing and replay by raising the required budget for attacks. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
ACM Trans. Priv. Secur. | 5 |
| 2025 | RingAuth: User Authentication Using a Smart Ring
Jack Sturgess, Simon Birnbach, Simon Eberz, Ivan Martinovic |
SECRYPT | 4 |
| 2025 | A Mobile Payment Scheme Using Biometric Identification with Mutual Authentication
Jack Sturgess, Ivan Martinovic |
SECRYPT | 2 |
| 2025 | GLaDoS: Location-aware Denial-of-Service of Cellular Networks
Simon Erni, Martin Kotuliak, Richard Baker 0008, Ivan Martinovic, Srdjan Capkun |
USENIX Security Symposium | 4 |
| 2025 | Current Affairs: A Security Measurement Study of CCS EV Charging Deployments
Marcell Szakály, Sebastian Köhler 0005, Ivan Martinovic |
USENIX Security Symposium | 3 |
| 2025 | SpaceJam: Protocol-aware Jamming Attacks against Space CommunicationsabstractMotivated by the growing prevalence of increasingly advanced satellite jamming attacks, we introduce and systematically analyze protocol-aware jammers: the worst-case scenario that maximally exploits the protocol to deny service whilst remaining as difficult to detect as possible. This extends existing satellite jamming and anti-jamming literature, which to date considers only conventional jamming waveforms. We find that protocol-aware jammers are significantly more effective than conventional jammers against all major standardized satellite protocols, including when anti-jamming countermeasures in the form of interleaving and adaptive coding and modulation are employed. This performance is possible since current protocols have a cyclic and predictable nature. We assess the required capabilities in terms of synchronization, and show that many of these performance gains can be realized even by completely desynchronized jammers. We experimentally evaluate protocol-aware strategies against both a hardware and software receiver. The results show that over 15dB of performance gains over Gaussian jamming are possible against all tested satellite protocols. Furthermore, we find that the attack can be optimized in simulation and deployed against the hardware receiver without performance degradation. We conclude with a discussion of countermeasures, primarily at the protocol level, to improve the availability of these systems. Edd Salkield, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 5 |
| 2024 | Assault and Battery: Evaluating the Security of Power Conversion Systems Against Electromagnetic Injection AttacksabstractMany modern devices, including critical infrastructure, depend on the reliable operation of electrical power conversion systems. The small size and versatility of switched-mode power converters has led to their widespread use. While transformer-based systems passively convert voltage, switched-mode power converters have an actively controlled feedback loop that relies on accurate sensor measurements. Previous academic work has shown that many types of sensors are vulnerable to Intentional Electromagnetic Interference (IEMI) attacks, and it has been speculated that power converters are also susceptible.In this paper, we present the first detailed and practical evaluation of IEMI attacks against switched-mode power converters as a whole by manipulating the voltage and current sensors in their feedback loops. We develop a novel multi-frequency IEMI attack technique to effectively target devices with multiple sensors. We experimentally validate our theoretical predictions by analyzing multiple AC-DC and DC-DC converters, automotive-grade current sensors, dedicated battery chargers, and a real-world electric vehicle charger. Our attack is reliably effective at overcharging and permanently damaging Li-ion cells, and causing the EV charger to output 50 V more than it reports. Marcell Szakály, Sebastian Köhler 0005, Martin Strohmeier, Ivan Martinovic |
ACSAC | 4 |
| 2024 | MC-PanDA: Mask Confidence for Panoptic Domain Adaptation
Ivan Martinovic, Josip Saric, Sinisa Segvic |
ECCV (72) | 1 |
| 2023 | Watch This Space: Securing Satellite Communication through Resilient Transmitter FingerprintingabstractDue to an increase in the availability of cheap off-the-shelf radio hardware, signal spoofing and replay attacks on satellite ground systems have become more accessible than ever. This is particularly a problem for legacy systems, many of which do not offer cryptographic security and cannot be patched to support novel security measures. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
CCS | 5 |
| 2023 | Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
NDSS | 4 |
| 2023 | BeeHIVE: Behavioral Biometric System Based on Object Interactions in Smart Environments
Klaudia Krawiecka, Simon Birnbach, Simon Eberz, Ivan Martinovic |
SECRYPT | 4 |
| 2023 | Satellite Spoofing from A to Z: On the Requirements of Satellite Downlink Overshadowing AttacksabstractSatellite communications are increasingly crucial for telecommunications, navigation, and Earth observation. However, many widely used satellites do not cryptographically secure the downlink, opening the door for radio spoofing attacks. Recent developments in software-defined radio hardware have enabled attacks on wireless systems including GNSS, which can be effectively spoofed using only cheap hardware available off the shelf. However, these conclusions do not generalize well to other satellite systems such as high data rate backhauls or satellite-to-customer connections, where the spoofing requirements are currently unknown. In this paper, we present a systematic review of spoofing attacks against satellite downlink communications systems. We establish a threat model linking attack feasibility and impact to required budget through real-world experiments and channel simulations. Our results show that nearly all evaluated satellite systems were overshadowable at a distance of 1 km in the worst case, for a budget of ~2000 USD or less. We evaluate how key challenges surrounding modulation schemes, antenna directionality, and legitimate satellite signal strength can be overcome in practice through antenna sidelobe targeting, overshadowing, and automatic gain control takeover. We also show that, surprisingly, protocols designed to be more robust against channel noise are significantly less robust against an overshadowing attacker. We conclude with a discussion of physical-layer countermeasures specifically applicable to satellite systems which can not be cryptographically upgraded. Edd Salkield, Marcell Szakály, Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 7 |
| 2022 | Common Evaluation Pitfalls in Touch-Based Authentication SystemsabstractIn this paper, we investigate common pitfalls affecting the evaluation of authentication systems based on touch dynamics. We consider different factors that lead to misrepresented performance, are incompatible with stated system and threat models or impede reproducibility and comparability with previous work. Specifically, we investigate the effects of (i) small sample sizes (both number of users and recording sessions), (ii) using different phone models in training data, (iii) selecting non-contiguous training data, (iv) inserting attacker samples in training data and (v) swipe aggregation. We perform a systematic review of 30 touch dynamics papers showing that all of them overlook at least one of these pitfalls. To quantify each pitfall's effect, we design a set of experiments and collect a new longitudinal dataset of touch dynamics from 470 users over 31 days comprised of 1,166,092 unique swipes. We make this dataset and our code available online. Our results show significant percentage-point changes in reported mean EER for several pitfalls: including attacker data (2.55%), non-contiguous training data (3.8%), phone model mixing (3.2%-5.8%). We show that, in a common evaluation setting, cumulative effects of these evaluation choices result in a combined difference of 8.9% EER. We also largely observe these effects across the entire ROC curve. Furthermore, we validate the pitfalls on four distinct classifiers - SVM, Random Forest, Neural Network, and kNN. Based on these insights, we propose a set of best practices that, if followed, will lead to more realistic and comparable reporting of results in the field. Martin Georgiev, Simon Eberz, Henry Turner, Giulio Lovisotto, Ivan Martinovic |
AsiaCCS | 5 |
| 2022 | Signal Injection Attacks against CCD Image SensorsabstractSince cameras have become a crucial part in many safety-critical systems and applications, such as autonomous vehicles and surveillance, a large body of academic and non-academic work has shown attacks against their main component --- the image sensor. However, these attacks are limited to coarse-grained and often suspicious injections because light is used as an attack vector. Furthermore, due to the nature of optical attacks, they require the line-of-sight between the adversary and the target camera. Sebastian Köhler 0005, Richard Baker 0008, Ivan Martinovic |
AsiaCCS | 3 |
| 2022 | Demo: End-to-End Wireless Disruption of CCS EV ChargingabstractThe shift from vehicles with internal combustion engines (ICE) to fully Electric Vehicles (EVs) is happening at a rapid pace. To be competitive with ICEs and ensure a smooth rollout, the charging process of EVs needs to be as fast and convenient as possible. Modern DC fast-charging standards achieve this by implementing a high-level charging communication (HLC), which enables a safe, efficient, and convenient charging experience. Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
CCS | 4 |
| 2022 | WatchAuth: User Authentication and Intent Recognition in Mobile Payments using a SmartwatchabstractIn this paper, we show that the tap gesture, performed when a user ‘taps’ a smartwatch onto an NFC-enabled terminal to make a payment, is a biometric capable of implicitly authenticating the user and simultaneously recognising intent-to-pay. The proposed system can be deployed purely in software on the watch without requiring updates to payment terminals. It is agnostic to terminal type and position and the intent recognition portion does not require any training data from the user. To validate the system, we conduct a user study (n=16) to collect wrist motion data from users as they interact with payment terminals and to collect long-term data from a subset of them ($\mathrm{n}=9$) as they perform daily activities. Based on this data, we identify optimum gesture parameters and develop authentication and intent recognition models, for which we achieve EERs of 0.08 and 0.04, respectively. Jack Sturgess, Simon Eberz, Ivo Sluganovic, Ivan Martinovic |
EuroS&P | 4 |
| 2022 | Techniques for Continuous Touch-Based Authentication
Martin Georgiev, Simon Eberz, Ivan Martinovic |
ISPEC | 3 |
| 2022 | 99% False Positives: A Qualitative Study of SOC Analysts' Perspectives on Security Alarms
Bushra A. AlAhmadi, Louise Axon, Ivan Martinovic |
USENIX Security Symposium | 3 |
| 2022 | Generating identities with mixture models for speaker anonymization
Henry Turner, Giulio Lovisotto, Ivan Martinovic |
Comput. Speech Lang. | 3 |
| 2022 | Haunted House: Physical Smart Home Event Verification in the Presence of Compromised SensorsabstractIn this article, we verify physical events using data from an ensemble of smart home sensors. This approach both protects against event sensor faults and sophisticated attackers. To validate our system’s performance, we set up a “smart home” in an office environment. We recognize 22 event types using 48 sensors over the course of two weeks. Using data from the physical sensors, we verify the event stream supplied by the event sensors to detect both masking and spoofing attacks. We consider three threat models: a zero-effort attacker, an opportunistic attacker, and a sensor-compromise attacker who can arbitrarily modify live sensor data. For spoofed events, we achieve perfect classification for 9 out of 22 events and achieve a 0% false alarm rate at a detection rate exceeding 99.9% for 15 events. For 11 events the majority of masking attacks can be detected without causing any false alarms. We also show that even a strong opportunistic attacker is inherently limited to spoofing few select events and that doing so involves lengthy waiting periods. Finally, we demonstrate the vulnerability of a single-classifier system to compromised sensor data and introduce a more secure approach based on sensor fusion. Simon Birnbach, Simon Eberz, Ivan Martinovic |
ACM Trans. Internet Things | 3 |
| 2021 | They See Me Rollin': Inherent Vulnerability of the Rolling Shutter in CMOS Image SensorsabstractIn this paper, we describe how the electronic rolling shutter in CMOS image sensors can be exploited using a bright, modulated light source (e.g., an inexpensive, off-the-shelf laser), to inject fine-grained image disruptions. We demonstrate the attack on seven different CMOS cameras, ranging from cheap IoT to semi-professional surveillance cameras, to highlight the wide applicability of the rolling shutter attack. We model the fundamental factors affecting a rolling shutter attack in an uncontrolled setting. We then perform an exhaustive evaluation of the attack’s effect on the task of object detection, investigating the effect of attack parameters. We validate our model against empirical data collected on two separate cameras, showing that by simply using information from the camera’s datasheet the adversary can accurately predict the injected distortion size and optimize their attack accordingly. We find that an adversary can hide up to 75% of objects perceived by state-of-the-art detectors by selecting appropriate attack parameters. We also investigate the stealthiness of the attack in comparison to a naïve camera blinding attack, showing that common image distortion metrics can not detect the attack presence. Therefore, we present a new, accurate and lightweight enhancement to the backbone network of an object detector to recognize rolling shutter attacks. Overall, our results indicate that rolling shutter attacks can substantially reduce the performance and reliability of vision-based intelligent systems. Sebastian Köhler 0005, Giulio Lovisotto, Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
ACSAC | 5 |
| 2021 | On Detecting Deception in Space Situational AwarenessabstractSpace Situational Awareness (SSA) data is critical to the safe piloting of satellites through an ever-growing field of orbital debris. However, measurement complexity means that most satellite operators cannot independently acquire SSA data and must rely on a handful of centralized repositories operated by major space powers. As interstate competition in orbit increases, so does the threat of attacks abusing these information-sharing relationships. This paper offers one of the first considerations of defense techniques against SSA deceptions. Building on historical precedent and real-world SSA data, we simulate an attack whereby an SSA operator seeks to disguise spy satellites as pieces of debris. We further develop and evaluate a machine-learning based anomaly detection tool which allows defenders to detect 90-98% of deception attempts with little to no in-house astrometry hardware. James Pavur, Ivan Martinovic |
AsiaCCS | 2 |
| 2021 | MalPhase: Fine-Grained Malware Detection Using Network Flow DataabstractEconomic incentives encourage malware authors to constantly develop new, increasingly complex malware to steal sensitive data or blackmail individuals and companies into paying large ransoms. In 2017, the worldwide economic impact of cyberattacks is estimated to be between 445 and 600 billion USD, or 0.8% of global GDP. Traditionally, one of the approaches used to defend against malware is network traffic analysis, which relies on network data to detect the presence of potentially malicious software. However, to keep up with increasing network speeds and amount of traffic, network analysis is generally limited to work on aggregated network data, which is traditionally challenging and yields mixed results. In this paper we present MalPhase, a system that was designed to cope with the limitations of aggregated flows. MalPhase features a multi-phase pipeline for malware detection, type and family classification. The use of an extended set of network flow features and a simultaneous multi-tier architecture facilitates a performance improvement for deep learning models, making them able to detect malicious flows (>98% F1) and categorize them to a respective malware type (>93% F1) and family (>91% F1). Furthermore, the use of robust features and denoising autoencoders allows MalPhase to perform well on samples with varying amounts of benign traffic mixed in. Finally, MalPhase detects unseen malware samples with performance comparable to that of known samples, even when interlaced with benign flows to reflect realistic network environments. Michal Piskozub, Fabio De Gaspari, Frederick Barr-Smith, Luigi V. Mancini, Ivan Martinovic |
AsiaCCS | 5 |
| 2021 | Studying Neutrality in Cyber-Space: a Comparative Geographical Analysis of Honeypot Responses
Martin Strohmeier, James Pavur, Ivan Martinovic, Vincent Lenders |
CRITIS | 3 |
| 2021 | Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic Surveillance
Kai Jansen, Liang Niu, Nian Xue, Ivan Martinovic, Christina Pöpper |
NDSS | 4 |
| 2021 | QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary Orbit
James Pavur, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
NDSS | 4 |
| 2021 | Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandabstractAs malware detection algorithms and methods become more sophisticated, malware authors adopt equally sophisticated evasion mechanisms to defeat them. Anecdotal evidence claims Living-Off-The-Land (LotL) techniques are one of the major evasion techniques used in many malware attacks. These techniques leverage binaries already present in the system to conduct malicious actions. We present the first large-scale systematic investigation of the use of these techniques by malware on Windows systems.In this paper, we analyse how common the use of these native system binaries is across several malware datasets, containing a total of 31,805,549 samples. We identify an average 9.41% prevalence. Our results show that the use of LotL techniques is prolific, particularly in Advanced Persistent Threat (APT) malware samples where the prevalence is 26.26%, over twice that of commodity malware.To illustrate the evasive potential of LotL techniques, we test the usage of LotL techniques against several fully patched Windows systems in a local sandboxed environment and show that there is a generalised detection gap in 10 of the most popular anti-virus products. Frederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor, Ivan Martinovic |
SP | 5 |
| 2021 | SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations
Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, Ivan Martinovic |
USENIX Security Symposium | 5 |
| 2021 | #PrettyFlyForAWiFi: Real-world Detection of Privacy Invasion Attacks by DronesabstractDrones are becoming increasingly popular for hobbyists and recreational use. But with this surge in popularity comes increased risk to privacy as the technology makes it easy to spy on people in otherwise-private environments, such as an individual’s home. An attacker can fly a drone over fences and walls to observe the inside of a house, without having physical access. Existing drone detection systems require specialist hardware and expensive deployment efforts, making them inaccessible to the general public. In this work, we present a drone detection system that requires minimal prior configuration and uses inexpensive commercial off-the-shelf hardware to detect drones that are carrying out privacy invasion attacks. We use a model of the attack structure to derive statistical metrics for movement and proximity that are then applied to received communications between a drone and its controller. We test our system in real-world experiments with two popular consumer drone models mounting privacy invasion attacks using a range of flight patterns. We are able both to detect the presence of a drone and to identify which phase of the privacy attack was in progress while being resistant to false positives from other mobile transmitters. For line-of-sight approaches using our kurtosis-based method, we are able to detect all drones at a distance of 6 m, with the majority of approaches detected at 25 m or farther from the target window without suffering false positives for stationary or mobile non-drone transmitters. Simon Birnbach, Richard Baker 0008, Simon Eberz, Ivan Martinovic |
ACM Trans. Priv. Secur. | 4 |
| 2021 | Classi-Fly: Inferring Aircraft Categories from Open DataabstractIn recent years, air traffic communication data has become easy to access, enabling novel research in many fields. Exploiting this new data source, a wide range of applications have emerged, from weather forecasting to stock market prediction, or the collection of intelligence about military and government movements. Typically, these applications require knowledge about the metadata of the aircraft, specifically its operator and the aircraft category. armasuisse Science + Technology, the R&D agency for the Swiss Armed Forces, has been developing Classi-Fly, a novel approach to obtain metadata about aircraft based on their movement patterns. We validate Classi-Fly using several hundred thousand flights collected through open source means, in conjunction with ground truth from publicly available aircraft registries containing more than 2 million aircraft. We show that we can obtain the correct aircraft category with an accuracy of greater than 88%. In cases, where no metadata is available, this approach can be used to create the data necessary for applications working with air traffic communication. Finally, we show that it is feasible to automatically detect particular sensitive aircraft such as police and surveillance aircraft using this method. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
ACM Trans. Intell. Syst. Technol. | 4 |
| 2020 | BOTection: Bot Detection by Building Markov Chain Models of Bots Network BehaviorabstractBotnets continue to be a threat to organizations, thus various machine learning-based botnet detectors have been proposed. However, the capability of such systems in detecting new or unseen botnets is crucial to ensure its robustness against the rapid evolution of botnets. Moreover, it prolongs the effectiveness of the system in detecting bots, avoiding frequent and time-consuming classifier re-training. We present BOTection, a privacy-preserving bot detection system that models the bot network flow behavior as a Markov Chain. The Markov Chain state transitions capture the bots' network behavior using high-level flow features as states, producing content-agnostic and encryption resilient behavioral features. These features are used to train a classifier to first detect flows produced by bots, and then identify their bot families. We evaluate our system on a dataset of over 7M malicious flows from 12 botnet families, showing its capability of detecting bots' network traffic with 99.78% F-measure and classifying it to a malware family with a 99.09% F-measure. Notably, due to the modeling of general bot network behavior by the Markov Chains, BOTection can detect traffic belonging to unseen bot families with an F-measure of 93.03% making it robust against malware evolution. Bushra A. AlAhmadi, Enrico Mariconti, Riccardo Spolaor, Gianluca Stringhini, Ivan Martinovic |
AsiaCCS | 5 |
| 2020 | Tap-Pair: Using Spatial Secrets for Single-Tap Device Pairing of Augmented Reality HeadsetsabstractAugmented Reality (AR) headsets, which allow for a realistic integration between the physical environment and virtual objects, are rapidly coming to customer and enterprise markets. This is largely because they enable a broad range of multi-user applications in which all participants experience the same augmentation of their natural surrounding. However, despite their increasing expansion, there currently exist no implemented methods for secure ad-hoc device pairing of multiple AR headsets. Given the importance of multi-user experiences for future applications of this technology, in this paper we propose two distinct ways to establish secure ad-hoc connections that rely only on typical user interactions in AR: gazing and tapping either at the location of a shared point on the wall or towards the user with whom one wants to connect. To show the feasibility and deployability of the proposed system to existing technology, we build a prototype of Tap-Pair, a system for ad-hoc pairing of AR headsets that is based on Password Authenticated Key Exchange protocols, requires only user interactions that are common in AR, and can be extended to more than two users. The experimental evaluation of the Tap-Pair prototype in a series of measurements at three different locations confirms the feasibility of our proposal, showing that the system built with currently available augmented reality headsets indeed achieves successful pairing in more than 90% of attempts, while keeping the probability of the attacker's success lower than 1e-3. Ivo Sluganovic, Mihael Liskij, Ante Derek, Ivan Martinovic |
CODASPY | 4 |
| 2020 | Biometric Backdoors: A Poisoning Attack Against Unsupervised Template UpdatingabstractIn this work, we investigate the concept of biometric backdoors: a template poisoning attack on biometric systems that allows adversaries to stealthily and effortlessly impersonate users in the long-term by exploiting the template update procedure. We show that such attacks can be carried out even by attackers with physical limitations (no digital access to the sensor) and zero knowledge of training data (they know neither decision boundaries nor user template). Based on the adversaries' own templates, they craft several intermediate samples that incrementally bridge the distance between their own template and the legitimate user's. As these adversarial samples are added to the template, the attacker is eventually accepted alongside the legitimate user. To avoid detection, we design the attack to minimize the number of rejected samples. We design our method to cope with weak assumptions for the attacker and we evaluate the effectiveness of this approach on state-of-the-art face recognition pipelines based on deep neural networks. We find that in white-box scenarios, adversaries can successfully carry out the attack in over 70 % of cases with less than ten injection attempts. Even in black-box scenarios, we find that exploiting the transferability of adversarial samples from surrogate models can lead to successful attacks in around 15 % of cases. Finally, we design a poisoning detection technique that leverages the consistent directionality of template updates in feature space to discriminate between legitimate and malicious updates. We evaluate such a countermeasure with a set of intra-user variability factors which may present the same directionality characteristics, obtaining equal error rates for the detection between 7-14% and leading to over 99% of attacks being detected after only two sample injections. We design our method to cope with weak assumptions for the attacker and we evaluate the effectiveness of this approach on state-of-the-art face recognition pipelines based on deep neural networks. We find that in white-box scenarios, adversaries can successfully carry out the attack in over 70 % of cases with less than ten injection attempts. Even in black-box scenarios, we find that exploiting the transferability of adversarial samples from surrogate models can lead to successful attacks in around 15 % of cases. Finally, we design a poisoning detection technique that leverages the consistent directionality of template updates in feature space to discriminate between legitimate and malicious updates. We evaluate such a countermeasure with a set of intra-user variability factors which may present the same directionality characteristics, obtaining equal error rates for the detection between 7-14% and leading to over 99% of attacks being detected after only two sample injections. Giulio Lovisotto, Simon Eberz, Ivan Martinovic |
EuroS&P | 3 |
| 2020 | A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic Systems
Matthew Smith 0006, Martin Strohmeier, Jon Harman, Vincent Lenders, Ivan Martinovic |
NDSS | 5 |
| 2020 | A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsabstractVery Small Aperture Terminals (VSAT) have revolutionized maritime operations. However, the security dimensions of maritime VSAT services are not well understood. Historically, high equipment costs have acted as a barrier to entry for both researchers and attackers. In this paper we demonstrate a substantial change in threat model, proving practical attacks against maritime VSAT networks with less than $400 of widely-available television equipment. This is achieved through GSExtract, a purpose-built forensic tool which enables the extraction of IP traffic from highly corrupted VSAT data streams.The implications of this threat are assessed experimentally through the analysis of more than 1.3 TB of real-world maritime VSAT recordings encompassing 26 million square kilometers of coverage area. The underlying network platform employed in these systems is representative of more than 60% of the global maritime VSAT services market. We find that sensitive data belonging to some of the world's largest maritime companies is regularly leaked over VSAT ship-to-shore communications. This threat is contextualized through illustrative case studies ranging from the interception and alteration of navigational charts to theft of passport and credit card details. Beyond this, we demonstrate the ability to arbitrarily intercept and modify TCP sessions under certain network configurations, enabling man-in-the-middle and denial of service attacks against ships at sea. The paper concludes with a brief discussion of the unique requirements and challenges for encryption in VSAT environments. James Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
SP | 5 |
| 2019 | Peeves: Physical Event Verification in Smart HomesabstractWith the rising availability of smart devices (e.g., smart thermostats, lights, locks, etc.), they are increasingly combined into "smart homes". A key component of smart homes are event sensors that report physical events (such as doors opening or the light turning on) which can be triggered automatically by the system or manually by the user. However, data from these sensors are not always trustworthy. Both faults in the event sensors and involvement of active attackers can lead to reporting of events that did not physically happen (event spoofing). This is particularly critical, as smart homes can trigger event chains (e.g., turning the radiator off when a window is opened) without involvement of the user. The goal of this paper is to verify physical events using data from an ensemble of sensors (such as accelerometers or air pressure sensors) that are commonly found in smart homes. This approach both protects against event sensor faults and sophisticated attackers. In order to validate our system's performance, we set up a "smart home" in an office environment. We recognize 22 event types using 48 sensors over the course of two weeks. Using data from the physical sensors, we verify the event stream supplied by the event sensors. We consider two threat models: a zero-effort attacker who spoofs events at arbitrary times and an opportunistic attacker who has access to a live stream of sensor data to better time their attack. We achieve perfect classification for 9 out of 22 events and achieve a 0% false alarm rate at a detection rate exceeding 99.9% for 15 events. We also show that even a strong opportunistic attacker is inherently limited to spoofing few select events and that doing so involves lengthy waiting periods. Simon Birnbach, Simon Eberz, Ivan Martinovic |
CCS | 3 |
| 2019 | 28 Blinks Later: Tackling Practical Challenges of Eye Movement BiometricsabstractIn this work we address three overlooked practical challenges of continuous authentication systems based on eye movement biometrics: (i) changes in lighting conditions, (ii) task dependent features and the (iii) need for an accurate calibration phase. We collect eye movement data from 22 participants. To measure the effect of the three challenges, we collect data while varying the experimental conditions: users perform four different tasks, lighting conditions change over the course of the session and we collect data related to both accurate (user-specific) and inaccurate (generic) calibrations. To address changing lighting conditions, we identify the two main sources of light, i.e., screen brightness and ambient light, and we propose a pupil diameter correction mechanism based on these. We find that such mechanism can accurately adjust for the pupil shrinking or expanding in relation to the varying amount of light reaching the eye. To account for inaccurate calibrations, we augment the previously known feature set with new features based on binocular tracking, where the left and the right eye are tracked separately. We show that these features can be extremely distinctive even when using a generic calibration. We further apply a cross-task mapping function based on population data which systematically accounts for the dependency of features to tasks (e.g., reading a text and browsing a website lead to different eye movement dynamics). Using these enhancements, even while relaxing assumptions about the experimental conditions, we show that our system achieves significantly lower error rates compared to previous work. For intra-task authentication, without user-specific calibration and in variable screen brightness and ambient lighting, we achieve an equal error rate of 3.93% with only two minutes of training data. For the same setup but with constant screen brightness (e.g., as for a reading task) we can achieve equal error rates as low as of 1.88%. Simon Eberz, Giulio Lovisotto, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
CCS | 5 |
| 2019 | Attacking Speaker Recognition Systems with Phoneme Morphing
Henry Turner, Giulio Lovisotto, Ivan Martinovic |
ESORICS (1) | 3 |
| 2019 | Losing the Car Keys: Wireless PHY-Layer Insecurity in EV Charging
Richard Baker 0008, Ivan Martinovic |
USENIX Security Symposium | 2 |
| 2019 | Secrets in the sky: on privacy and infrastructure security in DVB-S satellite broadbandabstractDemands for ubiquitous global connectivity have sparked a satellite broadband renaissance. Secure satellite broadband is vital to ensuring that this growth does not beget unanticipated harm. Motivated by this need, this paper presents an experimental security analysis of satellite broadband signals using the Digital Video Broadcasting for Satellite (DVB-S) protocol. This analysis comprises 14 geostationary platforms encompassing over 100 million square kilometers of combined coverage area. James Pavur, Daniel Moser, Vincent Lenders, Ivan Martinovic |
WiSec | 4 |
| 2019 | CompactFlow: A Hybrid Binary Format for Network Flow Data
Michal Piskozub, Riccardo Spolaor, Ivan Martinovic |
WISTP | 3 |
| 2019 | Analysis of Reflexive Eye Movements for Fast Replay-Resistant Biometric AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and cons-umer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person’s gaze is particularly attractive for rapid biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates or requires long authentication times. We build on the fact that some eye movements can be reflexively and predictably triggered and develop an interactive visual stimulus for elicitation of reflexive eye movements that support the extraction of reliable biometric features in a matter of seconds, without requiring any memorization or cognitive effort on the part of the user. As an important benefit, our stimulus can be made unique for every authentication attempt and thus incorporated in a challenge-response biometric authentication system. This allows us to prevent replay attacks, which are possibly the most applicable attack vectors against biometric authentication. Using a gaze tracking device, we build a prototype of our system and perform a series of systematic user experiments with 30 participants from the general public. We thoroughly analyze various system parameters and evaluate the performance and security guarantees under several different attack scenarios. The results show that our system matches or surpasses existing gaze-based authentication methods in achieved equal error rates (6.3%) while achieving significantly lower authentication times (5s). Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
ACM Trans. Priv. Secur. | 4 |
| 2018 | The Real First Class? Inferring Confidential Corporate Mergers and Government Relations from Air Traffic CommunicationabstractThis paper exploits publicly available aircraft meta data in conjunction with unfiltered air traffic communication gathered from a global collaborative sensor network to study the privacy impact of large-scale aircraft tracking on governments and public corporations. First, we use movement data of 542 verified aircraft used by 113 different governments to identify events and relationships in the real world. We develop a spatio-temporal clustering method which returns 47 public and 18 non-public meetings attended by dedicated government aircraft over the course of 18 months. Additionally, we illustrate the ease of analyzing the long-term behavior and relationships of aviation users through the example of foreign governments visiting Europe. Secondly, we exploit the same types of data to predict potential merger and acquisition (M&A) activities by 36 corporations listed on the US and European stock markets. We identify seven M&A cases, in all of which the buyer has used corporate aircraft to visit the target prior to the official announcement, on average 61 days before. Finally, we analyze five existing technical and non-technical mitigation options available to the individual stakeholders. We quantify their popularity and effectiveness, finding that despite their current widespread use, they are ineffective against the presented exploits. Consequently, we argue that regulatory and technical changes are required to be able to protect the privacy of non-commercial aviation users in the future. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
EuroS&P | 4 |
| 2018 | Get in Line: Ongoing Co-presence Verification of a Vehicle Formation Based on Driving TrajectoriesabstractIntelligent transportation systems and the advent of smart cities have created a renewed research interest in vehicular networks (VANET). These ad-hoc networks are the key technology for new collaborative approaches to increase the efficiency and safety of our roads. In effect, city-scale field trials are being conducted by major high-tech companies to explore the capabilities and limitations of vehicle-to-infrastructure and vehicle-to-vehicle communication. Initial advances have led to safety enhancing applications like the electronic emergency brake light, cooperative collision avoidance and cooperative adaptive cruise control. In IEEE standard 1609.2, security measures to guarantee the integrity and authenticity of VANET messages are specified. However, physical properties like spatial proximity and driving direction are not considered. These become notably important when vehicles make decisions that concern the safety of users for example to avoid a collision. We propose a novel approach to verify the ongoing copresence of two vehicles. Our method is based on the observation that the trajectory through a road network can be used to uniquely define a vehicle's location as well as its driving direction. Our system provides a protocol to authenticate VANET messages for a group of vehicles driving in succession and to de-authenticate vehicles that have left the formation. To demonstrate the feasibility of trajectories as proof for co-presence, we implemented a smartphone application and conducted driving experiments under real-world conditions. We analyze the road network of several major cities from different continents to show the generalizability of our approach. Additionally, we systematically evaluate the security properties of our system by performing city-scale simulations under realistic conditions. Christian Vaas, Mika Juuti, N. Asokan, Ivan Martinovic |
EuroS&P | 4 |
| 2018 | Device Pairing at the Touch of an Electrode
Marc Röschlin, Ivan Martinovic, Kasper Bonne Rasmussen |
NDSS | 2 |
| 2018 | EMPower: Detecting Malicious Power Line Networks from EM Emissions
Richard Baker 0008, Ivan Martinovic |
SEC | 2 |
| 2018 | When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across ContextsabstractAttacks on behavioral biometrics have become increasingly popular. Most research has been focused on presenting a previously obtained feature vector to the biometric sensor, often by the attacker training themselves to change their behavior to match that of the victim. However, obtaining the victim's biometric information may not be easy, especially when the user's template on the authentication device is adequately secured. As such, if the authentication device is inaccessible, the attacker may have to obtain data elsewhere. In this paper, we present an analytic framework that enables us to measure how easily features can be predicted based on data gathered in a different context (e.g., different sensor, performed task or environment). This framework is used to assess how resilient individual features or entire biometrics are against such cross-context attacks. In order to be able to compare existing biometrics with regard to this property, we perform a user study to gather biometric data from 30 participants and five biometrics (ECG, eye movements, mouse movements, touchscreen dynamics and gait) in a variety of contexts. We make this dataset publicly available online. Our results show that many attack scenarios are viable in practice as features are easily predicted from a variety of contexts. All biometrics include features that are particularly predictable (e.g., amplitude features for ECG or curvature for mouse movements). Overall, we observe that cross-context attacks on eye movements, mouse movements and touchscreen inputs are comparatively easy while ECG and gait exhibit much more chaotic cross-context changes. Simon Eberz, Giulio Lovisotto, Andrea Patanè, Marta Z. Kwiatkowska, Vincent Lenders, Ivan Martinovic |
IEEE Symposium on Security and Privacy | 6 |
| 2018 | Increasing Mix-Zone Efficacy for Pseudonym Change in VANETs using Chaff MessagesabstractVehicular ad-hoc networks (VANETs) are designed to play a key role in the development of future transportation systems. Although cooperative awareness messages provide the required situational awareness for new safety and efficiency applications, they also introduce a new attack vector to compromise privacy. The use of ephemeral credentials called pseudonyms for privacy protection was proposed while ensuring the required security properties. In order to prevent an attacker from linking old to new pseudonyms, mix-zones provide a region in which vehicles can covertly change their signing material. In this poster, we extend the idea of mix-zones to mitigate pseudonym linking attacks with a mechanism inspired by chaff-based privacy defense techniques for mix-networks. By providing chaff trajectories, our system restores the efficacy of mix-zones to compensate for a lack of vehicles available to participate in the mixing procedure. Our simulation results of a realistic traffic scenario show that a significant improvement is possible. Christian Vaas, Panagiotis Papadimitratos, Ivan Martinovic |
WISEC | 3 |
| 2018 | Undermining Privacy in the Aircraft Communications Addressing and Reporting System (ACARS)abstractAbstract Despite the Aircraft Communications, Addressing and Reporting System (ACARS) being widely deployed for over twenty years, little scrutiny has been applied to it outside of the aviation community. Whilst originally utilized by commercial airlines to track their flights and provide automated timekeeping on crew, today it serves as a multi-purpose air-ground data link for many aviation stakeholders including private jet owners, state actors and military. Such a change has caused ACARS to be used far beyond its original mandate; to date no work has been undertaken to assess the extent of this especially with regard to privacy and the various stakeholder groups which use it. In this paper, we present an analysis of ACARS usage by privacy sensitive actors-military, government and business. We conduct this using data from the VHF (both traditional ACARS, and VDL mode 2) and satellite communications subnetworks. Based on more than two million ACARS messages collected over the course of 16 months, we demonstrate that current ACARS usage systematically breaches location privacy for all examined aviation stakeholder groups, explaining the types of messages used to cause this problem.We illustrate the challenges with three case studies-one for each stakeholder group-to show how much privacy sensitive information can be constructed with a handful of ACARS messages. We contextualize our findings with opinions on the issue of privacy in ACARS from 40 aviation industry professionals. From this, we explore recommendations for how to address these issues, including use of encryption and policy measures. Matthew Smith 0006, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
Proc. Priv. Enhancing Technol. | 5 |
| 2018 | Robust Smartphone App Identification via Encrypted Network Traffic AnalysisabstractThe apps installed on a smartphone can reveal much information about a user, such as their medical conditions, sexual orientation, or religious beliefs. In addition, the presence or absence of particular apps on a smartphone can inform an adversary, who is intent on attacking the device. In this paper, we show that a passive eavesdropper can feasibly identify smartphone apps by fingerprinting the network traffic that they send. Although SSL/TLS hides the payload of packets, side-channel data, such as packet size and direction is still leaked from encrypted connections. We use machine learning techniques to identify smartphone apps from this side-channel data. In addition to merely fingerprinting and identifying smartphone apps, we investigate how app fingerprints change over time, across devices, and across different versions of apps. In addition, we introduce strategies that enable our app classification system to identify and mitigate the effect of ambiguous traffic, i.e., traffic in common among apps, such as advertisement traffic. We fully implemented a framework to fingerprint apps and ran a thorough set of experiments to assess its performance. We fingerprinted 110 of the most popular apps in the Google Play Store and were able to identify them six months later with up to 96% accuracy. Additionally, we show that app fingerprints persist to varying extents across devices and app versions. Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | HoloPair: Securing Shared Augmented Reality Using Microsoft HoloLensabstractAugmented Reality (AR) devices continuously scan their environment in order to naturally overlay virtual objects onto user's view of the physical world. In contrast to Virtual Reality, where one's environment is fully replaced with a virtual one, one of AR's "killer features" is co-located collaboration, in which multiple users interact with the same combination of virtual and real objects. Microsoft recently released HoloLens, the first consumer-ready augmented reality headset that needs no outside markers to achieve precise inside-out spatial mapping, which allows centimeter-scale hologram positioning. Ivo Sluganovic, Matej Serbec, Ante Derek, Ivan Martinovic |
ACSAC | 4 |
| 2017 | VisAuth: Authentication over a Visual Channel Using an Embedded Image
Jack Sturgess, Ivan Martinovic |
CANS | 2 |
| 2017 | Evaluating Behavioral Biometrics for Continuous Authentication: Challenges and MetricsabstractIn recent years, behavioral biometrics have become a popular approach to support continuous authentication systems. Most generally, a continuous authentication system can make two types of errors: false rejects and false accepts. Based on this, the most commonly reported metrics to evaluate systems are the False Reject Rate (FRR) and False Accept Rate (FAR). However, most papers only report the mean of these measures with little attention paid to their distribution. This is problematic as systematic errors allow attackers to perpetually escape detection while random errors are less severe. Using 16 biometric datasets we show that these systematic errors are very common in the wild. We show that some biometrics (such as eye movements) are particularly prone to systematic errors, while others (such as touchscreen inputs) show more even error distributions. Our results also show that the inclusion of some distinctive features lowers average error rates but significantly increases the prevalence of systematic errors. As such, blind optimization of the mean EER (through feature engineering or selection) can sometimes lead to lower security. Following this result we propose the Gini Coefficient (GC) as an additional metric to accurately capture different error distributions. We demonstrate the usefulness of this measure both to compare different systems and to guide researchers during feature selection. In addition to the selection of features and classifiers, some non- functional machine learning methodologies also affect error rates. The most notable examples of this are the selection of training data and the attacker model used to develop the negative class. 13 out of the 25 papers we analyzed either include imposter data in the negative class or randomly sample training data from the entire dataset, with a further 6 not giving any information on the methodology used. Using real-world data we show that both of these decisions lead to significant underestimation of error rates by 63% and 81%, respectively. This is an alarming result, as it suggests that researchers are either unaware of the magnitude of these effects or might even be purposefully attempting to over-optimize their EER without actually improving the system. Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
AsiaCCS | 4 |
| 2017 | To Update or Not to Update: Insights From a Two-Year Study of Android App EvolutionabstractAlthough there are over 1,900,000 third-party Android apps in the Google Play Store, little is understood about how their security and privacy characteristics, such as dangerous permission usage and the vulnerabilities they contain, have evolved over time. Our research is two-fold: we take quarterly snapshots of the Google Play Store over a two-year period to understand how permission usage by apps has changed; and we analyse 30,000 apps to understand how their security and privacy characteristics have changed over the same two-year period. Extrapolating our findings, we estimate that over 35,000 apps in the Google Play Store ask for additional dangerous permissions every three months. Our statistically significant observations suggest that free apps and popular apps are more likely to ask for additional dangerous permissions when they are updated. Worryingly, we discover that Android apps are not getting safer as they are updated. In many cases, app updates serve to increase the number of distinct vulnerabilities contained within apps, especially for popular apps. We conclude with recommendations to stakeholders for improving the security of the Android ecosystem. Vincent F. Taylor, Ivan Martinovic |
AsiaCCS | 2 |
| 2017 | FADEWICH: Fast Deauthentication Over the Wireless ChannelabstractBoth authentication and deauthentication are instrumental for preventing unauthorized access to computers and other resources. While there are obvious motivating factors for using strong authentication mechanisms, convincing users to deauthenticate is not straight-forward, since deauthentication is not considered mandatory. A user who leaves a logged-in workstation unattended (especially for a short time) is typically not inconvenienced in any way; in fact, the other way around - no annoying reauthentication is needed upon return. However, an unattended workstation is trivially susceptible to the well-known "lunchtime attack" by any nearby adversary who simply takes over the departed user's log-in session. At the same time, since deauthentication does not intrinsically require user secrets, it can, in principle, be made unobtrusive. To this end, this paper designs the first automatic user deauthentication system - FADEWICH - that does not rely on biometric-or behavior-based techniques (e.g., keystroke dynamics) and does not require users to carry any devices. It uses physical properties of wireless signals and the effect of human bodies on their propagation. To assess FADEWICH's feasibility and performance, extensive experiments were conducted with its prototype. Results show that it suffices to have nine inexpensive wireless sensors deployed in a shared office setting to correctly deauthenticate all users within six seconds (90% within four seconds) after they leave their workstation's vicinity. We considered two realistic scenarios where the adversary attempts to subvert FADEWICH and showed that lunchtime attacks fail. Mauro Conti, Giulio Lovisotto, Ivan Martinovic, Gene Tsudik |
ICDCS | 3 |
| 2017 | Wi-Fly?: Detecting Privacy Invasion Attacks by Consumer Drones
Simon Birnbach, Richard Baker 0008, Ivan Martinovic |
NDSS | 3 |
| 2017 | Broken Hearted: How To Attack ECG Biometrics
Simon Eberz, Nicola Paoletti, Marc Röschlin, Andrea Patanè, Marta Z. Kwiatkowska, Ivan Martinovic |
NDSS | 6 |
| 2017 | Implementing Prover-Side Proximity Verification for Strengthening Transparent AuthenticationabstractTransparent authentication schemes based on proximity verification over a wireless channel are susceptible to relay attacks. In recent literature several countermeasures have been proposed. However these come with drawbacks in terms of usability and deployability. In this demo, we show a prototype implementation of STASH, a scheme for securing transparent authentication schemes using prover-side proximity verification, presented at SECON 2017. Mika Juuti, Christian Vaas, Hans Liljestrand, Ivo Sluganovic, N. Asokan, Ivan Martinovic |
SECON | 6 |
| 2017 | STASH: Securing Transparent Authentication Schemes Using Prover-Side Proximity VerificationabstractTransparent authentication (TA) schemes are those in which a user's prover device authenticates him to a verifier without requiring explicit user interaction. By doing so, those schemes promise high usability and security simultaneously. Most TA implementations rely on the received signal strength as an indicator of the proximity of a user device (prover). However, such implicit proximity verification is not secure against an adversary who can relay messages over a larger distance. In this paper, we propose a novel approach for thwarting relay attacks on TA schemes: the prover permits access to authentication credentials only if it can confirm that it is near the verifier. We present STASH, a system for relay-resilient transparent authentication in which the prover does proximity verification by comparing its approach trajectory towards the intended verifier, with known authorized reference trajectories. Trajectories are measured using low-cost sensors commonly available on personal devices. By analyzing empirical data, collected using a STASH prototype, we demonstrate the security of STASH against a class of adversaries and its ease-of-use. STASH is efficient and can be easily integrated to complement existing TA schemes. Mika Juuti, Christian Vaas, Ivo Sluganovic, Hans Liljestrand, N. Asokan, Ivan Martinovic |
SECON | 6 |
| 2017 | There are many apps for that: quantifying the availability of privacy-preserving appsabstractThe adage "there's an app for that" holds true in modern app stores. Indeed, app stores usually go further and provide multiple apps with very similar functionality; examples range from flashlight apps to alarm clocks. We call these functionally-similar apps. When searching for these apps, users are often presented with a vast array of choices, but no distinction is made in the user interface to highlight the relative privacy risks inherent in choosing one app over another. Yet the availability of many functionally-similar apps raises the question of whether some apps are significantly less invasive than others. In this paper, we take several steps toward answering this question. We begin by enumerating 2 500 groups of functionally-similar apps in the Google Play Store. Within groups of apps, we use static analysis to understand the real-world risks coming from apps with aggressive permission usage. By leveraging an established ranking system, and combining it with real-world data from over 28 000 Android devices, we quantify the improvements that can be made if users installed apps with privacy in mind. We observe that at least 25.6% of apps contain libraries that gratuitously exploit available permissions and find that 43.5% of apps could be swapped for comparable alternatives that require fewer permissions. Permissions saved may deliver important privacy and security improvements, including preventing access to the calendar (in 24% of cases), sending text messages (12%) and recording audio (8%). This is particularly important for apps which embed third-party libraries, since library code executes with the same permissions as the app itself. Vincent F. Taylor, Alastair R. Beresford, Ivan Martinovic |
WISEC | 3 |
| 2017 | Pulse-Response: Exploring Human Body Impedance for Biometric RecognitionabstractBiometric characteristics are often used as a supplementary component in user authentication and identification schemes. Many biometric traits, both physiological and behavioral, offering a wider range of security and stability, have been explored. We propose a new physiological trait based on the human body’s electrical response to a square pulse signal, called pulse-response , and analyze how this biometric characteristic can be used to enhance security in the context of two example applications: (1) an additional authentication mechanism in PIN entry systems and (2) a means of continuous authentication on a secure terminal. The pulse-response biometric recognition is effective because each human body exhibits a unique response to a signal pulse applied at the palm of one hand and measured at the palm of the other. This identification mechanism integrates well with other established methods and could offer an additional layer of security, either on a continuous basis or at log-in time. We build a proof-of-concept prototype and perform experiments to assess the feasibility of pulse-response for biometric authentication. The results are very encouraging, achieving an equal error rate of 2% over a static dataset and 9% over a dataset with samples taken over several weeks. We also quantize resistance to attack by estimating individual worst-case probabilities for zero-effort impersonation in different experiments. Ivan Martinovic, Kasper Bonne Rasmussen, Marc Röschlin, Gene Tsudik |
ACM Trans. Priv. Secur. | 1 |
| 2017 | On Perception and Reality in Wireless Air Traffic Communication SecurityabstractMore than a dozen wireless technologies are used by air traffic communication systems during different flight phases. From a conceptual perspective, all of them are insecure, as security was never part of their design. Recent contributions from academic and hacking communities have exploited this inherent vulnerability to demonstrate attacks on some of these technologies. However, not all of these contributions have resonated widely within aviation circles. At the same time, the security community lacks certain aviation domain knowledge, preventing aviation authorities from giving credence to their findings. In this survey, we aim to reconcile the view of the security community and the perspective of aviation professionals concerning the safety of air traffic communication technologies. To achieve this, we first provide a systematization of the applications of wireless technologies upon which civil aviation relies. Based on these applications, we comprehensively analyze vulnerabilities and existing attacks. We further survey the existing research on countermeasures and categorize it into approaches that are applicable in the short term and research of secure new technologies deployable in the long term. Since not all of the required aviation knowledge is codified in academic publications, we additionally examine the existing aviation standards and survey 242 international aviation experts. Besides their domain knowledge, we also analyze the awareness of members of the aviation community concerning the security of wireless systems and collect their expert opinions on the potential impact of concrete attack scenarios using these technologies. Martin Strohmeier, Matthias Schäfer 0002, Rui Pinheiro, Vincent Lenders, Ivan Martinovic |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2016 | Using Reflexive Eye Movements for Fast Challenge-Response AuthenticationabstractEye tracking devices have recently become increasingly popular as an interface between people and consumer-grade electronic devices. Due to the fact that human eyes are fast, responsive, and carry information unique to an individual, analyzing person's gaze is particularly attractive for effortless biometric authentication. Unfortunately, previous proposals for gaze-based authentication systems either suffer from high error rates, or require long authentication times. Ivo Sluganovic, Marc Röschlin, Kasper Bonne Rasmussen, Ivan Martinovic |
CCS | 4 |
| 2016 | DEMO: Starving Permission-Hungry Android Apps Using SecuRankabstractWe demonstrate SecuRank, a tool that can be employed by Android smartphone users to replace their currently installed apps with functionally-similar ones that require less sensitive access to their device. SecuRank works by using text mining on the app store description of apps to perform groupings by functionality. Once groups of functionally-similar apps are found, SecuRank uses contextual permission usage within groups to identify those apps that are less permission-hungry. Our demonstration will showcase both the Android app version of SecuRank and the web-based version. Participants will see the effectiveness of SecuRank as a tool for finding and replacing apps with less permission-hungry alternatives. Vincent F. Taylor, Ivan Martinovic |
CCS | 2 |
| 2016 | AppScanner: Automatic Fingerprinting of Smartphone Apps from Encrypted Network TrafficabstractAutomatic fingerprinting and identification of smartphone apps is becoming a very attractive data gathering technique for adversaries, network administrators, investigators and marketing agencies. In fact, the list of apps installed on a device can be used to identify vulnerable apps for an attacker to exploit, uncover a victim's use of sensitive apps, assist network planning, and aid marketing. However, app fingerprinting is complicated by the vast number of apps available for download, the wide range of devices they may be installed on, and the use of payload encryption protocols such as HTTPS/TLS. In this paper, we present a novel methodology and a framework implementing it, called AppScanner, for the automatic fingerprinting and real-time identification of Android apps from their encrypted network traffic. To build app fingerprints, we run apps automatically on a physical device to collect their network traces. We apply various processing strategies to these network traces before extracting the features that are used to train our supervised learning algorithms. Our fingerprint generation methodology is highly scalable and does not rely on inspecting packet payloads, thus our framework works even when HTTPS/TLS is employed. We built and deployed this lightweight framework and ran a thorough set of experiments to assess its performance. We automatically profiled 110 of the most popular apps in the Google Play Store and were later able to re-identify them with more than 99% accuracy. Vincent F. Taylor, Riccardo Spolaor, Mauro Conti, Ivan Martinovic |
EuroS&P | 4 |
| 2016 | Looks Like Eve: Exposing Insider Threats Using Eye Movement BiometricsabstractWe introduce a novel biometric based on distinctive eye movement patterns. The biometric consists of 20 features that allow us to reliably distinguish users based on differences in these patterns. We leverage this distinguishing power along with the ability to gauge the users’ task familiarity, that is, level of knowledge, to address insider threats. In a controlled experiment, we test how both time and task familiarity influence eye movements and feature stability, and how different subsets of features affect the classifier performance. These feature subsets can be used to tailor the eye movement biometric to different authentication methods and threat models. Our results show that eye movement biometrics support reliable and stable continuous authentication of users. We investigate different approaches in which an attacker could attempt to use inside knowledge to mimic the legitimate user. Our results show that while this advance knowledge is measurable, it does not increase the likelihood of successful impersonation. In order to determine the time stability of our features, we repeat the experiment twice within 2 weeks. The results indicate that we can reliably authenticate users over the entire period. We show that lower sampling rates provided by low-cost hardware pose a challenge, but that reliable authentication is possible even at the rate of 50Hz commonly available with consumer-level devices. In a second set of experiments, we evaluate how our authentication system performs across a variety of real-world tasks, including reading, writing, and web browsing. We discuss the advantages and limitations of our approach in detail and give practical insights on the use of this biometric in a real-world environment. Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
ACM Trans. Priv. Secur. | 4 |
| 2016 | Friendly Jamming on Access Points: Analysis and Real-World MeasurementsabstractFrequency jamming is known as an efficient attack tool to disrupt wireless communication. This efficiency can also be exploited for the benefit of a network—an idea often referred to as friendly jamming. A prominent application case is the blocking of unauthenticated or malicious communication, such as injection attacks. In this paper, we propose access points as a natural place to implement friendly jamming functionality. We analyze this proposal using simulations, introduce an implementation on customer-grade access points, and report measurement results from the first real-world study of friendly jamming in an IEEE 802.11 campus network. We discover a fundamental tradeoff between the effectiveness of friendly jamming and the orthogonal aspect of having minimal side-effects to the campus network’s traffic. In particular, we observed what we call the power amplification phenomenon. This effect aggravates the known hidden station problem when the number of jammers increases. We also find evidence that the collaboration between jammers can enable friendly jamming, which is both effective and minimally invasive. Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt |
IEEE Trans. Wirel. Commun. | 4 |
| 2015 | Using Channel State Information for Tamper Detection in the Internet of ThingsabstractThe Internet of Things (IoT) is increasingly used for critical applications and securing the IoT has become a major concern. Among other issues it is important to ensure that tampering with IoT devices is detected. Many IoT devices use WiFi for communication and Channel State Information (CSI) based tamper detection is a valid option. Each 802.11n WiFi frame contains a preamble which allows a receiver to estimate the impact of the wireless channel, the transmitter and the receiver on the signal. The estimation result - the CSI - is used by a receiver to extract the transmitted information. However, as the CSI depends on the communication environment and the transmitter hardware, it can be used as well for security purposes. If an attacker tampers with a transmitter it will have an effect on the CSI measured at a receiver. Unfortunately not only tamper events lead to CSI fluctuations; movement of people in the communication environment has an impact too. We propose to analyse CSI values of a transmission simultaneously at multiple receivers to improve distinction of tamper and movement events. A moving person is expected to have an impact on some but not all communication links between transmitter and the receivers. A tamper event impacts on all links between transmitter and the receivers. The paper describes the necessary algorithms for the proposed tamper detection method. In particular we analyse the tamper detection capability in practical deployments with varying intensity of people movement. In our experiments the proposed system deployed in a busy office environment was capable to detect 53% of tamper events (TPR = 53%) while creating zero false alarms (FPR = 0%). Ibrahim Ethem Bagci, Utz Roedig, Ivan Martinovic, Matthias Schulz 0001, Matthias Hollick |
ACSAC | 3 |
| 2015 | Intrusion Detection for Airborne Communication Using PHY-Layer Information
Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
DIMVA | 3 |
| 2015 | Experiences in Developing and Delivering a Programme of Part-Time Education in Software and Systems SecurityabstractWe report upon our experiences in developing and delivering a programme of part-time education in Software and Systems Security at the University of Oxford. The MSc in Software and Systems Security is delivered as part of the Software Engineering Programme at Oxford - a collection of one-week intensive courses aimed at individuals who are responsible for the procurement, development, deployment and maintenance of large-scale software-based systems. We expect that our experiences will be useful to those considering a similar journey. Andrew C. Simpson, Andrew P. Martin, Cas Cremers, Ivan Flechais, Ivan Martinovic, Kasper Bonne Rasmussen |
ICSE (2) | 5 |
| 2015 | Preventing Lunchtime Attacks: Fighting Insider Threats With Eye Movement Biometrics
Simon Eberz, Kasper Bonne Rasmussen, Vincent Lenders, Ivan Martinovic |
NDSS | 4 |
| 2014 | Bringing up OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 4 |
| 2014 | Demonstration abstract: OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 4 |
| 2014 | Authentication Using Pulse-Response Biometrics
Kasper Bonne Rasmussen, Marc Röschlin, Ivan Martinovic, Gene Tsudik |
NDSS | 3 |
| 2014 | Gaining insight on friendly jamming in a real-world IEEE 802.11 networkabstractFrequency jamming is the fiercest attack tool to disrupt wireless communication and its malicious aspects have received much attention in the literature. Yet, several recent works propose to turn the table and employ so-called friendly jamming for the benefit of a wireless network. For example, recently proposed friendly jamming applications include hiding communication channels, injection attack defense, and access control. This work investigates the practical viability of friendly jamming by applying it in a real-world network. To that end, we implemented a reactive and frame-selective jammer on a consumer grade IEEE 802.11 access point. Equipped with this, we conducted a three weeks real-world study on the jammer's performance and side-effects on legitimate traffic (the cost of jamming) in a university office environment. Our results provide detailed insights on crucial factors governing the trade-off between the effectiveness of friendly jamming (we evaluated up to 13 jammers) and its cost. In particular, we observed -- what we call the power amplification phenomenon -- an effect that aggravates the known hidden station problem when the number of jammers increases. However, we also find evidence that this effect can be alleviated by collaboration between jammers, which again enables effective and minimally invasive friendly jamming. Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt |
WISEC | 4 |
| 2013 | Experimental Analysis of Attacks on Next Generation Air Traffic Communication
Matthias Schäfer 0002, Vincent Lenders, Ivan Martinovic |
ACNS | 3 |
| 2013 | Neighborhood watch: On network coding throughput and key sharingabstractNetwork coding (NC) has frequently been promoted as an approach for improving throughput in wireless networks. Existing work has mostly focused on the fundamental aspects of NC, while constraints arising in real-world network deployments have not received much attention. In particular, NC requires network nodes to overhear each other's packets, which oftentimes contradicts many security standards that attempt to provide link-layer confidentiality, e.g., by utilizing pairwise encryption keys as is the case IEEE 802.11i and ZigBee. There is an inherent trade-off between gains from NC and link-layer security: if many nodes share the secret link-layer key, NC will improve throughput, yet a leakage of the key will affect many nodes. On the other hand, having distinct secret keys will increase resilience against key compromise, but will also minimize the coding gain. We formulate this security vs. performance trade-off as an optimization problem and evaluate the effectiveness of NC under different sizes of key-sharing groups and network topologies. Our results show that increasing the key-sharing group by a single node can result in a maximum coding gain between 1.3% and 13.7%. Martin Strohmeier, Ivan Martinovic, Utz Roedig, Karim M. El Defrawy, Jens B. Schmitt |
GLOBECOM | 2 |
| 2013 | Who do you sync you are?: smartphone fingerprinting via application behaviourabstractThe overall network traffic patterns generated by today's smartphones result from the typically large and diverse set of installed applications. In addition to the traffic generated by the user, most applications generate characteristic traffic from their background activities, such as periodic update requests or server synchronisation. Although the encryption of transmitted data in 3G networks prevents an eavesdropper from analysing the content, periodic traffic patterns leak side-channel information like timing and data volume. In this work, we extract such side-channel features from network traffic generated from the most popular applications, such as Facebook, WhatsApp, Skype, Dropbox, and others, and evaluate whether they can be used to reliably identify a smartphone. By computing fingerprints from approx,6,hours of background traffic, we show that 15 minutes of monitored traffic suffice to reliably identify a smartphone based on its behavioural fingerprint with a success probability of 90%. Tim Stöber, Mario Frank 0001, Jens B. Schmitt, Ivan Martinovic |
WISEC | 4 |
| 2013 | Secure Key Generation in Sensor Networks Based on Frequency-Selective ChannelsabstractKey management in wireless sensor networks faces several unique challenges. The scale, resource limitations, and new threats such as node capture suggest the use of in-network key generation. However, the cost of such schemes is often high because their security is based on computational complexity. Recently, several research contributions justified experimentally that the wireless channel itself can be used to generate information-theoretic secure keys. By exchanging sampling messages during device movement, a bit string is derived known only to the two involved entities. Yet, movement is not the only option to generate randomness: the channel response strongly depends on the signal frequency as well. In this work, we introduce a key generation protocol based on the frequency-selectivity of multipath fading channels. The practical advantage of this approach is that it does not require device movement during key establishment. Thus the frequent case of a sensor network with static nodes is supported. We show the protocol's applicability by implementing it on MICAz motes, and evaluating its robustness and security through experiments and analysis. The error correction property of the protocol mitigates the effects of measurement errors and temporal effects, giving rise to an agreement rate of over 97 %. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt |
IEEE J. Sel. Areas Commun. | 2 |
| 2013 | Touchalytics: On the Applicability of Touchscreen Input as a Behavioral Biometric for Continuous AuthenticationabstractWe investigate whether a classifier can continuously authenticate users based on the way they interact with the touchscreen of a smart phone. We propose a set of 30 behavioral touch features that can be extracted from raw touchscreen logs and demonstrate that different users populate distinct subspaces of this feature space. In a systematic experiment designed to test how this behavioral pattern exhibits consistency over time, we collected touch data from users interacting with a smart phone using basic navigation maneuvers, i.e., up–down and left–right scrolling. We propose a classification framework that learns the touch behavior of a user during an enrollment phase and is able to accept or reject the current user by monitoring interaction with the touch screen. The classifier achieves a median equal error rate of 0% for intrasession authentication, 2%–3% for intersession authentication, and below 4% when the authentication test was carried out one week after the enrollment phase. While our experimental findings disqualify this method as a standalone authentication mechanism for long-term authentication, it could be implemented as a means to extend screen-lock time or as a part of a multimodal biometric authentication system. Mario Frank 0001, Ralf Biedert, Eugene Ma, Ivan Martinovic, Dawn Song |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2012 | A Practical Man-In-The-Middle Attack on Signal-Based Key Generation Protocols
Simon Eberz, Martin Strohmeier, Matthias Wilhelm 0001, Ivan Martinovic |
ESORICS | 4 |
| 2012 | On the Feasibility of Side-Channel Attacks with Brain-Computer Interfaces
Ivan Martinovic, Doug Davies, Mario Frank 0001, Daniele Perito, Tomas Ros, Dawn Song |
USENIX Security Symposium | 1 |
| 2011 | Pay bursts only once holds for (some) non-FIFO systemsabstractNon-FIFO processing of flows by network nodes is not a rare phenomenon. Unfortunately, the state-of-the-art analytical tool for the computation of performance bounds in packet-switched networks, network calculus, cannot deal well with non-FIFO systems. The problem lies in its conventional service curve definitions. Either the definition is too strict to allow for a concatenation and consequent beneficial end-to-end analysis, or it is too loose and results in infinite delay bounds. Hence, in this paper, we propose a new service curve definition and demonstrate its strength with respect to achieving both finite delay bounds and a concatenation of systems resulting in a favorable end-to-end delay analysis. In particular, we show that the celebrated pay bursts only once phenomenon is retained even without any assumptions on the processing order of packets. This seems to contradict previous work [15]; the reasons for this are discussed. Jens B. Schmitt, Nicos Gollan, Steffen Bondorf, Ivan Martinovic |
INFOCOM | 4 |
| 2011 | WiFire: a firewall for wireless networksabstractFirewalls are extremely effective at enforcing security policies in wired networks. Perhaps surprisingly, firewalls are entirely nonexistent in the wireless domain. Yet, the need to selectively control and block radio communication is particularly high in a broadcast environment since any node may receive and send packets. In this demo, we present WiFire, a system that brings the firewall concept to wireless networks. First, WiFire detects and analyzes packets during their transmission, checking their content against a set of rules. It then relies on reactive jamming techniques to selectively block undesired communication. We show the feasibility and performance of WiFire, which is implemented on the USRP2 software-defined radio platform, in several scenarios with IEEE 802.15.4 radios. WiFire is able to classify and effectively block undesired communication without interfering with desired communication. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders |
SIGCOMM | 2 |
| 2011 | Short paper: reactive jamming in wireless networks: how realistic is the threat?abstractIn this work, we take on the role of a wireless adversary and investigate one of its most powerful tools---radio frequency jamming. Although different jammer designs are discussed in the literature, reactive jamming, i.e., targeting only packets that are already on the air, is generally recognized as a stepping stone in implementing optimal jamming strategies. The reason is that, while destroying only selected packets, the adversary minimizes its risk of being detected. One might hope for reactive jamming to be too challenging or uneconomical for an attacker to conceive and implement due to its strict real-time requirements. Yet, in this work we disillusion from such hopes as we demonstrate that flexible and reliable software-defined reactive jamming is feasible by designing and implementing a reactive jammer against IEEE 802.15.4 networks. First, we identify the causes of loss at the physical layer of 802.15.4 and show how to achieve the best performance for reactive jamming. Then, we apply these insights to our USRP2-based reactive jamming prototype, enabling a classification of transmissions in real-time, and reliable and selective jamming. The prototype achieves a reaction time in the order of microseconds, a high precision (such as targeting individual symbols), and a 97.6% jamming rate in realistic indoor scenarios for a single reactive jammer, and over 99.9% for two concurrent jammers. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders |
WISEC | 2 |
| 2011 | Dynamic demultiplexing in network calculus - Theory and application
Hao Wang 0023, Jens B. Schmitt, Ivan Martinovic |
Perform. Evaluation | 3 |
| 2010 | A Self-adversarial Approach to Delay Analysis under Arbitrary Scheduling
Jens B. Schmitt, Hao Wang 0023, Ivan Martinovic |
ISoLA (1) | 3 |
| 2010 | AmICA - A Flexible, Compact, Easy-to-Program and Low-Power WSN Platform
Sebastian Wille, Norbert Wehn, Ivan Martinovic, Simon Kunz, Peter Göhner |
MobiQuitous | 3 |
| 2010 | Experimental design and analysis of transmission properties in an indoor wireless sensor network
Dennis Christmann, Ivan Martinovic |
WiOpt | 2 |
| 2010 | Secret keys from entangled sensor motes: implementation and analysisabstractKey management in wireless sensor networks does not only face typical, but also several new challenges. The scale, resource limitations, and new threats such as node capture and compromise necessitate the use of an on-line key generation, where secret keys are generated by the nodes themselves. However, the cost of such schemes is high since their secrecy is based on computational complexity. Recently, several research contributions justified that the wireless channel itself can be used to generate information-theoretic secure keys between two parties. By exchanging sampling messages during movement, a bit string can be derived that is only known to the involved entities. Yet, movement is not the only possibility to generate randomness. The channel response is also strongly dependent on the frequency of the transmitted signal. In our work, we introduce a protocol for key generation based on the frequency-selectivity of channel fading. The great practical advantage of this approach is that we do not rely on node movement as the source of randomness. Thus, the frequent case of a sensor network with static motes is supported. Furthermore, the error correction property of the proposed protocol mitigates the effects of measurement errors and other temporal effects, giving rise to a key agreement rate of over 97%. We show the applicability of our protocol by implementing it on MICAz motes, and evaluate its robustness and secrecy through experiments and analysis. Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt |
WISEC | 2 |
| 2009 | Jamming for good: a fresh approach to authentic communication in WSNsabstractWhile properties of wireless communications are often considered as a disadvantage from a security perspective, this work demonstrates how multipath propagation, a broadcast medium, and frequency jamming can be used as valuable security primitives. Instead of conventional message authentication by receiving, verifying, and then discarding fake data, sensor nodes are prevented from receiving fake data at all. The erratic nature of signal propagation distributes the jamming activity over the network which hinders an adversary in predicting jamming nodes and avoids selective battery-depletion attacks. By conducting real-world measurements, we justify the feasibility of such a security design and provide details on implementing it within a realistic wireless sensor network. Ivan Martinovic, Paul Pichota, Jens B. Schmitt |
WISEC | 1 |
| 2009 | Bringing law and order to IEEE 802.11 networks - A case for DiscoSec
Ivan Martinovic, Paul Pichota, Matthias Wilhelm 0001, Frank A. Zdarsky, Jens B. Schmitt |
Pervasive Mob. Comput. | 1 |
| 2009 | Chaotic communication improves authentication: protecting WSNs against injection attacksabstractAbstract In this paper, we propose a system leveraging peculiarities of the wireless medium, such as the broadcast nature of wireless communication and the unpredictability of indoor signal propagation to achieve effective protection against attacks based on the injection of fake data. Using a real‐world WSN deployment and a realistic implementation of an attacker, we analyze this protection scheme and demonstrate that neither position change, transmission power manipulation, nor complete knowledge of wireless parameters can help an attacker to successfully attack the network. As a result, this work demonstrates how the chaotic nature of radio communication, which is often considered a disadvantage in regard to security objectives, can be exploited to enhance protection and support implementation of lightweight security mechanisms. Copyright © 2009 John Wiley & Sons, Ltd. Ivan Martinovic, Nicos Gollan, Luc Cappellaro, Jens B. Schmitt |
Secur. Commun. Networks | 1 |
| 2009 | Minimizing contention through cooperation between densely deployed wireless LANs
Frank A. Zdarsky, Ivan Martinovic, Jens B. Schmitt |
Wirel. Networks | 2 |
| 2008 | Firewalling wireless sensor networks: Security by wirelessabstractNetworked sensors and actuators for purposes from production monitoring and control to home automation are in increasing demand. Until recently, the main focus laid on wired systems, although their deployment requires careful planning and expensive infrastructure that may be difficult to install or modify. Hence, solutions based on wireless sensor networks (WSNs) are gaining popularity to reduce cost and simplify installation. Clearly, one of the key issues rising from the switch to wireless communication lies in security; while an air gap is among the most effective security measures in wired networks, wireless communication is not as easy to isolate from attack. In this paper, we propose a system leveraging the peculiarities of the wireless medium, such as the broadcast nature of wireless communication and the unpredictability of indoor signal propagation to achieve effective protection against attacks based on the injection of fake data. Using a real-world WSN deployment and a realistic implementation of an attacker, we analyze this protection scheme and demonstrate that neither position change, transmission power manipulation, nor complete knowledge of wireless parameters can help an attacker to successfully attack the network. As a result, this work demonstrates how the chaotic nature of radio communication, which is often considered a disadvantage in regard to security objectives, can be used to enhance protection and support implementation of lightweight security mechanisms. Ivan Martinovic, Nicos Gollan, Jens B. Schmitt |
LCN | 1 |
| 2008 | Wireless client puzzles in IEEE 802.11 networks: security by wirelessabstractResource-depletion attacks against IEEE 802.11 access points (APs) are commonly executed by flooding APs with fake authentication requests. Such attacks may exhaust an AP's memory resources and result in denied association service, thus enabling more sophisticated impersonation attacks accomplished by rogue APs. Ivan Martinovic, Frank A. Zdarsky, Matthias Wilhelm 0001, Christian Wegmann, Jens B. Schmitt |
WISEC | 1 |
| 2008 | Design, implementation, and performance analysis of DiscoSec - Service pack for securing WLANsabstractTo improve the already tarnished reputation of WLAN security, the new IEEE 802.11i security standard provides means for an enhanced user authentication and strong data confidentiality. However, the standard focuses on securing higher-layer data, i.e., protecting IEEE 802.11 data frames. Management frames used for connection administration are left unprotected and a wide spectrum of known attacks is still applicable and even extended against the IEEE 802.11i/IEEE 802.1X protocol execution. This work describes DiscoSec, a service pack for “patching” WLANs against the most prominent vulnerabilities resulting in resource-depletion and impersonation attacks. DiscoSec provides DoS-resilient key exchange, an efficient frame authentication, and a performance-oriented implementation. By means of extensive real-world measurements the performance of DiscoSec is evaluated showing that even on very resource-limited devices the throughput is decreased by only 22% compared to the throughput without any authentication, and by 6%on more powerful hardware. To demonstrate its effectiveness, DiscoSec is available as an open-source WLAN device driver. Ivan Martinovic, Paul Pichota, Matthias Wilhelm 0001, Frank A. Zdarsky, Jens B. Schmitt |
WOWMOM | 1 |
| 2007 | Phishing in the Wireless: Implementation and Analysis
Ivan Martinovic, Frank A. Zdarsky, Adam Bachorek, Jens B. Schmitt |
SEC | 1 |