EDBT 2026 Demo / reviewers in the wild / expert
Patrick Tague
dblp:89/1945
· DBLP profile ↗
55ranked-venue papers
10as first author
3since 2021 · last 2024
0000-0002-7561-6112ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 6 first-authorSecurity and privacy · 22 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Utilizing Threat Partitioning for More Practical Network Anomaly DetectionabstractAnomaly-based network intrusion detection would appear on the surface to be ideal for detection of zero-day network threats. Yet in practice, their often unacceptably high false positive rates keep them on the sideline in favor of signature-based methods, which typically detect known threats. We argue that an anomaly-based network intrusion detection system should not only be specialized to a specific class of related threats, but characteristics of the threat class itself should be utilized when designing both the detection system and structuring the network data to use with the system. To this end, we take two common network threat classes, DDoS-as-a-Smokescreen (DaaSS) and SYN flood, and analyze their characteristics for structure that we can use to specialize anomaly detection. We partition these threat classes into known behavior and unknown behavior, leaving the latter open-ended. Through experimentation on multiple datasets, we show that our proposed detection system based on this threat partitioning approach is capable of detecting DaaSS attacks and zero-day SYN flood variants with very low false positive rates, even in the face of concept drift, and can do so without having to collect large amounts of benign network traffic for training. Brian Ricks, Patrick Tague, Bhavani Thuraisingham, Sriraam Natarajan |
SACMAT | 2 |
| 2022 | On the Security of Thread Networks: Experimentation with OpenThread-Enabled DevicesabstractThe Thread networking protocol is expected to be utilized by a plethora of smart home devices as one of the IP-based networking technologies that will be supported by the Matter standard that is being developed by members of the Connectivity Standards Alliance. Thread has been developed by the Thread Group as an application-agnostic protocol that builds on top of the IEEE 802.15.4 standard to enable IPv6-based low-power wireless mesh networking. However, unlike other IEEE 802.15.4-based protocols like Zigbee, the security of Thread networks has been relatively less analyzed in the literature. Given that commercial Thread devices are expected to interact with the physical world, vulnerabilities in their communication protocols could impact the physical security of end users. In this work we analyze the security of Thread networks by repurposing hardware and software tools that have been used for the security analysis of Zigbee networks. We used development boards that were flashed with OpenThread binaries to gain insight into the nature of Thread traffic and to study their susceptibility to a set of energy depletion attacks and online password guessing attacks. Lastly, we are publicly releasing our software enhancements as well as our dataset of captured Thread packets. Dimitrios-Georgios Akestoridis, Vyas Sekar, Patrick Tague |
WISEC | 3 |
| 2022 | Wireless and Mobile Security Research and Teaching in the Post-Pandemic WorldabstractThe COVID-19 pandemic disrupted many aspects of our lives at a global scale. This includes the disruption of the research and teaching we perform within the security and privacy community. As the pandemic is weaning off, the lessons learnt during the pandemic can be very valuable in the future, both for navigating pandemic-like situations, and for accommodating greater inclination towards remote work and education. In this panel, international experts with various professional backgrounds and different points of view will discuss the impact they faced over the last two years, such as halting (or starting) specific research problems due to pandemic-related restrictions, unique challenges in deploying new experiments and how they overcame them, and finding novel ways to facilitate social events like conferences and hackathons. Anindya Maiti, Ahmad-Reza Sadeghi, Gabriela F. Ciocarlie, Patrick Tague |
WISEC | 4 |
| 2020 | Zigator: analyzing the security of zigbee-enabled smart homesabstractAs the popularity of Internet-connected devices for residential use increases, it is important to ensure that they meet appropriate security goals, given that they interact with the physical world through sensors and actuators. Zigbee is a wireless communication protocol that is commonly used in smart home environments, which builds on top of the IEEE 802.15.4 standard. In this work we present a security analysis tool, called Zigator, that enables in-depth study of Zigbee networks. In particular, we study the security consequences of the design choice to disable MAC-layer security in centralized Zigbee networks. We show that valuable information can be gained from passive inspection of Zigbee traffic, including the identification of certain encrypted NWK commands, which we then use to develop selective jamming and spoofing attacks. An attacker may launch these attacks in order to force the end user to factory reset targeted devices and eventually expose the network key. We validated our attacks by setting up a testbed, using open-source tools, that incorporates commercial Zigbee devices. Finally, we publicly release the software tools that we developed and the Zigbee packets that we captured, to contribute back to the research community. Dimitrios-Georgios Akestoridis, Madhumitha Harishankar, Michael Weber 0011, Patrick Tague |
WISEC | 4 |
| 2019 | Using bluetooth low energy spoofing to dispute device details: demoabstractIn this demo, we will show the effects of multiple Bluetooth Low Energy spoofing attacks, including a novel cache poisoning attack. Bluetooth Low Energy (BLE) is often used for communication between devices, ranging from headphones to medical sensors. Our attacks target the BLE advertising mechanism to cause Denial of Service and Man-in-the-Middle conditions. BLE Peripheral Devices are discovered through an advertising process, in which the Peripheral broadcasts advertising packets to listening Central Devices. Such packets typically include the advertising address of the device, name of the device, and information about the connectability of the device. Peripheral Devices are generally assumed to have distinct advertising addresses. If a device advertises with the same address as another device, Central Devices need to decide which information is correct. We term the condition where advertisements contain contradictory information a "Disputed Advertisement". In the case where an advertisement contains optional information, there may be a condition where one of the packets contains maliciously included information, but is not contradicted by a legitimate packet. We call this condition an "Undisputed Advertisement", which is the basis for a novel attack that we call Bluestaking. The Bluestaking attack poisons advertising name cache on Central Devices with attacker-selected address-to-name mappings. Because BLE devices are not required to be named, an attacker can spoof a device and provide a name without any dispute from the victim device. This causes scanning Central Devices to cache the name indefinitely. Christopher Hensler, Patrick Tague |
WiSec | 2 |
| 2019 | Procuring Spontaneous Session-Level Resource Guarantees for Real-Time Applications: An Auction ApproachabstractReal-time multimedia applications, such as interactive gaming, live video streaming, and augmented reality, have strict latency and bitrate requirements. However, unpredictable network conditions, such as congestion and link quality, can severely degrade the quality of experience (QoE). While buffer-based mitigations cannot be applied to real-time applications due to their immediate resource needs, recent innovations in network slicing have demonstrated the feasibility of dedicating specified amounts of network resources to individual sessions in the radio access network. Encouraged by this, we propose to reserve network resources for multimedia sessions in real time according to their declared needs, thereby providing ad hoc session-level performance guarantees. Through Wi-Fi experiments and trace-driven LTE simulations, we show that such session-level resource provisioning is robust to real-time channel fluctuations and congestion externalities over the lifetime of a session. This approach, however, raises challenges: how can the network ensure that users are honest about their resource needs and optimally allocate its limited resources to users under uncertainty in future sessions' resource needs? We derive a novel multi-unit combinatorial auction (MUCA) model with a unique structure that can be exploited for fast winner determination, and yet incentivize truthful bidding, properties not simultaneously achieved in a generic MUCA but essential to making real-time session guarantees. Furthermore, since dynamic bidding in real time is challenging for end-users who are budget-constrained, we develop a reinforcement learning-based utility-maximizing strategy to distribute their budget across sessions and show that it yields high user utility. Madhumitha Harishankar, Sireesha Pilaka, Nagarjun Srinivasan, Carlee Joe-Wong, Patrick Tague |
IEEE J. Sel. Areas Commun. | 6 |
| 2018 | To Accept or Not to Accept: The Question of Supplemental Discount Offers in Mobile Data PlansabstractAs demand for Internet usage increases, Internet service providers (ISPs) have begun to explore pricing-based solutions to dampen data demand. However few explicitly consider the dual problem of monetizing idle network capacity at uncongested times. PopData is a recent initiative from Verizon that does so by offering supplemental discount offers (SDOs) at these times, in which users can pay a fixed fee in exchange for unlimited data in the next hour. This work is the first of its kind to assess the benefits and viability of SDOs by modeling user and ISP decisions as a game, considering both overall monthly decisions and hour-to-hour decisions throughout the month. We first use our monthly model to show that users are generally willing to accept some SDO offers, allowing the ISP to increase its revenue. We then show that users face a complex hourly decision problem as to which SDOs they should accept over their billing cycles, since they are unaware of their exact future needs or when future SDOs will be made. The ISP faces a similarly challenging problem in deciding when to offer SDOs so as to maximize its revenue, subject to users' decisions. We develop optimal decision criteria for users and ISPs to decide whether to make or accept SDO offers. Our analysis shows that both users and ISPs can benefit from these offers, and we verify this through numerical experiments on a one-week trace of 20 cellular data users. We find that ISPs can exploit user uncertainty in when future SDOs will be made to optimize its revenue. Madhumitha Harishankar, Nagarjun Srinivasan, Carlee Joe-Wong, Patrick Tague |
INFOCOM | 4 |
| 2018 | Lifting the Smokescreen: Detecting Underlying Anomalies During a DDoS AttackabstractWhile DDoS attacks have become an ever-growing threat in the last decade, a new variation is taking root in which the DDoS is used as a distraction or smokescreen to hide other malicious activity. This variation, which we call DDoS as a Smokescreen (DaaSS), often result in data theft and financial loss, and often are only detected because the theft is discovered independently, long after the attack has ceased. In this work, we set out to describe these attacks and present a novel approach to detect them using real-world network trace data. We present experimental results showing promise that DaaSS attacks can be detected in a manner conducive to practical deployment. Brian Ricks, Bhavani Thuraisingham, Patrick Tague |
ISI | 3 |
| 2018 | Do You Feel What I Hear? Enabling Autonomous IoT Device Pairing Using Different Sensor TypesabstractContext-based pairing solutions increase the usability of IoT device pairing by eliminating any human involvement in the pairing process. This is possible by utilizing on-board sensors (with same sensing modalities) to capture a common physical context (e.g., ambient sound via each device's microphone). However, in a smart home scenario, it is impractical to assume that all devices will share a common sensing modality. For example, a motion detector is only equipped with an infrared sensor while Amazon Echo only has microphones. In this paper, we develop a new context-based pairing mechanism called Perceptio that uses time as the common factor across differing sensor types. By focusing on the event timing, rather than the specific event sensor data, Perceptio creates event fingerprints that can be matched across a variety of IoT devices. We propose Perceptio based on the idea that devices co-located within a physically secure boundary (e.g., single family house) can observe more events in common over time, as opposed to devices outside. Devices make use of the observed contextual information to provide entropy for Perceptio's pairing protocol. We design and implement Perceptio, and evaluate its effectiveness as an autonomous secure pairing solution. Our implementation demonstrates the ability to sufficiently distinguish between legitimate devices (placed within the boundary) and attacker devices (placed outside) by imposing a threshold on fingerprint similarity. Perceptio demonstrates an average fingerprint similarity of 94.9% between legitimate devices while even a hypothetical impossibly well-performing attacker yields only 68.9% between itself and a valid device. Jun Han 0001, Albert Jin Chung, Manal Kumar Sinha, Madhumitha Harishankar, Shijia Pan, Hae Young Noh, Pei Zhang 0001, Patrick Tague |
IEEE Symposium on Security and Privacy | 8 |
| 2018 | Optimizing a MisInformation and MisBehavior (MIB) Attack Targeting Vehicle PlatoonsabstractAutonomous driving features can mitigate traffic fatalities, create more enjoyable commutes, and increase fuel efficiency. For example, collaborative adaptive cruise control (or platooning) uses sensor- based distance measurement and vehicle-to-vehicle communications to automatically control inter-vehicle spacing. This can have tremendous benefits but is also safety critical. Therefore, it is essential to understand and mitigate potential platooning vulnerabilities. In this work, we design an attack that we call the insider MisInformation and misBehavior (MIB) attack. During this attack, a malicious vehicle uses misinformation, erroneous V2V communications, and misbehavior, erratic driving, to cause predictable, dangerous, behavior. Although this attack can be applied broadly, we use it to design three optimal attacks were an attacker causes a collision without being damaged. Finally, we simulate these attacks and discuss trade-offs in there design parameters. Bruce DeBruhl, Patrick Tague |
VTC Fall | 2 |
| 2018 | Smart Home Occupant Identification via Sensor Fusion Across On-Object DevicesabstractOccupant identification proves crucial in many smart home applications such as automated home control and activity recognition. Previous solutions are limited in terms of deployment costs, identification accuracy, or usability. We propose SenseTribute , a novel occupant identification solution that makes use of existing and prevalent on-object sensors that are originally designed to monitor the status of objects to which they are attached. SenseTribute extracts richer information content from such on-object sensors and analyzes the data to accurately identify the person interacting with the objects. This approach is based on the physical phenomenon that different occupants interact with objects in different ways. Moreover, SenseTribute may not rely on users’ true identities, so the approach works even without labeled training data. However, resolution of information from a single on-object sensor may not be sufficient to differentiate occupants, which may lead to errors in identification. To overcome this problem, SenseTribute operates over a sequence of events within a user activity, leveraging recent work on activity segmentation. We evaluate SenseTribute using real-world experiments by deploying sensors on five distinct objects in a kitchen and inviting participants to interact with the objects. We demonstrate that SenseTribute can correctly identify occupants in 96% of trials without labeled training data, while per-sensor identification yields only 74% accuracy even with training data. Jun Han 0001, Shijia Pan, Manal Kumar Sinha, Hae Young Noh, Pei Zhang 0001, Patrick Tague |
ACM Trans. Sens. Networks | 6 |
| 2017 | Pitchln: eavesdropping via intelligible speech reconstruction using non-acoustic sensor fusionabstractDespite the advent of numerous Internet-of-Things (IoT) applications, recent research demonstrates potential side-channel vulnerabilities exploiting sensors which are used for event and environment monitoring. In this paper, we propose a new side-channel attack, where a network of distributed non-acoustic sensors can be exploited by an attacker to launch an eavesdropping attack by reconstructing intelligible speech signals. Specifically, we present PitchIn to demonstrate the feasibility of speech reconstruction from non-acoustic sensor data collected offline across networked devices. Unlike speech reconstruction which requires a high sampling frequency (e.g., > 5 KHz), typical applications using non-acoustic sensors do not rely on richly sampled data, presenting a challenge to the speech reconstruction attack. Hence, PitchIn leverages a distributed form of Time Interleaved Analog-Digital-Conversion (TIADC) to approximate a high sampling frequency, while maintaining low per-node sampling frequency. We demonstrate how distributed TI-ADC can be used to achieve intelligibility by processing an interleaved signal composed of different sensors across networked devices. We implement PitchIn and evaluate reconstructed speech signal intelligibility via user studies. PitchIn has word recognition accuracy as high as 79%. Though some additional work is required to improve accuracy, our results suggest that eavesdropping using a fusion of non-acoustic sensors is a real and practical threat. Jun Han 0001, Albert Jin Chung, Patrick Tague |
IPSN | 3 |
| 2017 | IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social NetworksabstractAuthorization bugs, when present in online social networks, are usually caused by missing or incorrect authorization checks and can allow attackers to bypass the online social network's protections. Unfortunately, there is no practical way to fully guarantee that an authorization bug will never be introduced-even with good engineering practices-as a web application and its data model become more complex. Unlike other web application vulnerabilities such as XSS and CSRF, there is no practical general solution to prevent missing or incorrect authorization checks. In this paper we propose Invariant Detector (IVD), a defense-in-depth system that automatically learns authorization rules from normal data manipulation patterns and distills them into likely invariants. These invariants, usually learned during the testing or pre-release stages of new features, are then used to block any requests that may attempt to exploit bugs in the social network's authorization logic. IVD acts as an additional layer of defense, working behind the scenes, complementary to privacy frameworks and testing. We have designed and implemented IVD to handle the unique challenges posed by modern online social networks. IVD is currently running at Facebook, where it infers and evaluates daily more than 200,000 invariants from a sample of roughly 500 million client requests, and checks the resulting invariants every second against millions of writes made to a graph database containing trillions of entities. Thus far IVD has detected several high impact authorization bugs and has successfully blocked attempts to exploit them before code fixes were deployed. Paul Marinescu, Chad Parry, Marjori Pomarole, Yuan Tian 0001, Patrick Tague, Ioannis Papagiannis |
IEEE Symposium on Security and Privacy | 5 |
| 2017 | SmartAuth: User-Centered Authorization for the Internet of Things
Yuan Tian 0001, Nan Zhang 0018, Yue-Hsun Lin, XiaoFeng Wang 0001, Blase Ur, Xianzheng Guo, Patrick Tague |
USENIX Security Symposium | 7 |
| 2017 | Towards continuous and passive authentication across mobile devices: an empirical studyabstractMobile devices, such as smartphones and tablets, have become prevalent given their ample functionality brought by a variety of applications. Unfortunately, these devices face security and privacy threats due to unauthorized access. Ordinary protection mechanisms such as passcode and fingerprint verification are widely employed to mitigate the threats. To achieve strong security without sacrificing usability, extensive research efforts have been devoted to continuous authentication through passive sensing and behavior modeling. Nowadays, more and more users own multiple devices. This trend presents opportunities for further optimization of authentication across devices. In this paper, we conduct an empirical study on how a behavioral model created on one device can be transferred to other devices to bootstrap continuous authentication. To pursue this goal, we collect 160 sets of usage data on multiple mobile devices and perform a proof-of-concept experiment. The results demonstrate that we can leverage the similarity between user behaviors on different devices to enable cross-device authentication and anomaly detection. Xiao Wang 0040, Tong Yu 0001, Ole J. Mengshoel, Patrick Tague |
WISEC | 4 |
| 2017 | Design Experiences in Minimalistic Flying Sensor Node Platform through SensorFlyabstractIndoor emergency response situations, such as urban fire, are characterized by dangerous constantly changing operating environments with little access to situational information for first responders. In situ information about the conditions, such as the extent and evolution of an indoor fire, can augment rescue efforts and reduce risk to emergency personnel. Static sensor networks that are pre-deployed or manually deployed have been proposed but are less practical due to need for large infrastructure, lack of adaptivity, and limited coverage. Controlled-mobility in sensor networks, that is, the capability of nodes to move as per network needs can provide the desired autonomy to overcome these limitations. In this article, we present SensorFly, a controlled-mobile aerial sensor network platform for indoor emergency response application. The miniature, low-cost sensor platform has capabilities to self deploy, achieve three-dimensional sensing, and adapt to node and network disruptions in harsh environments. We describe hardware design trade-offs, the software architecture, and the implementation that enables limited-capability nodes to collectively achieve application goals. Through the indoor fire monitoring application scenario, we validate that the platform can achieve coverage and sensing accuracy that matches or exceeds static sensor networks and provide higher adaptability and autonomy. Xinlei Chen, Aveek Purohit, Shijia Pan, Carlos Ruiz Dominguez, Jun Han 0001, Zheng Sun 0003, Frank Mokaya, Patrick Tague, Pei Zhang 0001 |
ACM Trans. Sens. Networks | 8 |
| 2016 | Swords and shields: a study of mobile game hacks and existing defenses
Yuan Tian 0001, Eric Yawei Chen, Shuo Chen 0001, Xiao Wang 0040, Patrick Tague |
ACSAC | 6 |
| 2015 | I did not smoke 100 cigarettes today!: avoiding false positives in real-world activity recognitionabstractActivity recognition (AR) systems are typically built and evaluated on a predefined set of activities. AR systems work best if the test data contains and only contains these predefined activities. In real world applications, AR systems trained in this manner generate serious false positives, for example if "smoking" is one of the activities in the training data but "lifting weights" is not. Due to the similarity of two activities, an AR system may report a user smoking 100 times a day but he actually did a bicep workout 100 times. In this work, we propose a new approach to train an AR system leveraging the large quantity of unlabeled data which reflects activities users perform in real life. The proposed mPUL (Multi-class Positive and Unlabeled Learning) approach significantly reduces the false positives. We argue that mPUL is a much more effective training method for real-world AR applications. Le T. Nguyen, Ming Zeng 0009, Patrick Tague, Joy Zhang |
UbiComp | 3 |
| 2015 | Isolation of Multiple Anonymous Attackers in Mobile Networks
Brian Ricks, Patrick Tague |
NSS | 2 |
| 2015 | Is your commute driving you crazy?: a study of misbehavior in vehicular platoonsabstractTraffic is not only a source of frustration but also a leading cause of death for people under 35 years of age. Recent research has focused on how driver assistance technologies can be used to mitigate traffic fatalities and create more enjoyable commutes. In this work, we consider cooperative adaptive cruise control (CACC) or platooning, a driver assistance technology that controls the speed of vehicles and inter-vehicle spacing. CACC equipped cars use radar to fine tune inter-vehicle spacing and dedicated short-range communication (DSRC) to collaboratively accelerate and decelerate. Platooning can reduce fuel consumption by over 5% and increases the density of cars on a highway. Previous work on platooning has focused on proving string stability, which guarantees that the error between cars does not grow with the length of a platoon, but little work has considered the impact an attacker can have on a platoon. To design safe distributed controllers and networks it is essential to understand the possible attacks that could be mounted against platoons. Bruce DeBruhl, Sean Weerakkody, Bruno Sinopoli, Patrick Tague |
WISEC | 4 |
| 2015 | A jamming approach to enhance enterprise Wi-Fi secrecy through spatial access control
Yu Seung Kim, Patrick Tague, Heejo Lee |
Wirel. Networks | 2 |
| 2014 | Energy-governed resilient networked systemsabstractConnected embedded systems in the realm of smart infrastructures comprise ubiquitous end-point devices supported by a communication infrastructure. Device, energy supply and network failures are a reality and provisioned communications could fail. Self-organization is a process where network devices cooperate with each other to restore network connectivity on detecting network connectivity failures. Self-organized networks are envisioned to be hierarchical, implying that a root device is expected to spend more energy to forward the entire network's data. This leads to battery exhaustion and therefore a single point of failure in the system. In this paper we address this problem by proposing an energy-governed resilient networking framework. Our framework enforces a policy to throttle upstream network traffic to maintain energy drain at the root device. To demonstrate the effectiveness of the proposed policy, we designed our experiment framework using Nano-RK and FireFly; a lightweight operating system and sensing platform respectively. Arjun P. Athreya, Harry Chan-Maestas, Edward Katz, Patrick Tague, Bob Iannucci |
CCNC | 4 |
| 2014 | OAuth Demystified for Mobile Application DevelopersabstractOAuth has become a highly influential protocol due to its swift and wide adoption in the industry. The initial objective of the protocol was specific: it serves the authorization needs for websites. What motivates our work is the realization that the protocol has been significantly re-purposed and re-targeted over the years: (1) all major identity providers, e.g., Facebook, Google and Microsoft, have re-purposed OAuth for user authentication; (2) developers have re-targeted OAuth to the mobile platforms, in addition to the traditional web platform. Therefore, we believe that it is necessary and timely to conduct an in-depth study to demystify OAuth for mobile application developers. Our work consists of two pillars: (1) an in-house study of the OAuth protocol documentation that aims to identify what might be ambiguous or unspecified for mobile developers; (2) a field-study of over 600 popular mobile applications that highlights how well developers fulfill the authentication and authorization goals in practice. The result is really worrisome: among the 149 applications that use OAuth, 89 of them (59.7%) were incorrectly implemented and thus vulnerable. In the paper, we pinpoint the key portions in each OAuth protocol flow that are security critical, but are confusing or unspecified for mobile application developers. We then show several representative cases to concretely explain how real implementations fell into these pitfalls. Our findings have been communicated to vendors of the vulnerable applications. Most vendors positively confirmed the issues, and some have applied fixes. We summarize lessons learned from the study, hoping to provoke further thoughts about clear guidelines for OAuth usage in mobile applications. Eric Yawei Chen, Yutong Pei, Shuo Chen 0001, Yuan Tian 0001, Robert Kotcher, Patrick Tague |
CCS | 6 |
| 2014 | IdentityLink: user-device linking through visual and RF-signal cuesabstractMobile devices have become people's indispensable companion, since they allow each individual to be constantly connected with the outside world. In order to keep connected, the devices periodically send out data, which reveal some information about the device owner. Data sent by these devices can be captured by any external observer. Since the observer can observe only the wireless data, the actual person using the device is unknown. In this work, we propose IdentityLink, an approach leveraging the captured wireless data and computer vision to infer the user-device links, i.e., inferring which device is carried by which user. Knowing the user-device links opens up new opportunities for applications such as identifying unauthorized personnel in enterprises or finding criminals by law enforcement. By conducting experiments in a realistic scenario, we demonstrate how IdentityLink can be effectively applied to real practice. Le T. Nguyen, Yu Seung Kim, Patrick Tague, Joy Zhang |
UbiComp | 3 |
| 2014 | All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing APIabstractHTML5 changes many aspects in the browser world by introducing numerous new concepts, in particular, the new HTML5 screen sharing API impacts the security implications of browsers tremendously. One of the core assumptions on which browser security is built is that there is no cross-origin feedback loop from the client to the server. However, the screen sharing API allows creating a cross-origin feedback loop. Consequently, websites will potentially be able to see all visible content from the user's screen, irrespective of its origin. This cross-origin feedback loop, when combined with human vision limitations, can introduce new vulnerabilities. An attacker can capture sensitive information from victim's screen using the new API without the consensus of the victim. We investigate the security implications of the screen sharing API and discuss how existing defenses against traditional web attacks fail during screen sharing. We show that several attacks are possible with the help of the screen sharing API: cross-site request forgery, history sniffing, and information stealing. We discuss how popular websites such as Amazon and Wells Fargo can be attacked using this API and demonstrate the consequences of the attacks such as economic losses, compromised account and information disclosure. The objective of this paper is to present the attacks using the screen sharing API, analyze the fundamental cause and motivate potential defenses to design a more secure screen sharing API. Yuan Tian 0001, Ying Chuan Liu, Amar Bhosale, Lin-Shung Huang, Patrick Tague, Collin Jackson |
IEEE Symposium on Security and Privacy | 5 |
| 2014 | PrivateDroid: Private Browsing Mode for AndroidabstractPrivate browsing mode is a privacy feature adopted by many modern computer browsers. With the increased use of mobile devices and escalating privacy concerns for mobile users, browser applications on mobile devices have also started incorporating private browsing mode. Even so, the use of private browsing mode is limited to the browser applications and cannot be applied directly on other third-party mobile applications. In this paper, we propose Private Droid, which provides a private browsing mode for third-party applications on the Android platform. First, we discuss three possible approaches of implementing mobile private browsing mode: code instrumentation, an extra sandbox, and a Linux container approach. Then, we implement Private Droid, which creates a new sandbox for every application in private mode and destroys the sandbox once the application is closed. After that, we evaluate usability, efficiency and security of the system with 25 popular Android applications. Our design considerations, implementation details, evaluation results, and challenges lay a foundation of private browsing mode on mobile platforms. Su Mon Kywe, Christopher B. Landis, Yutong Pei, Justin Satterfield, Yuan Tian 0001, Patrick Tague |
TrustCom | 6 |
| 2014 | Power napping with loud neighbors: optimal energy-constrained jamming and anti-jammingabstractThe openness of wireless communication and the recent development of software-defined radio technology, respectively, provide a low barrier and a wide range of capabilities for misbehavior, attacks, and defenses against attacks. In this work we present finite-energy jamming games, a game model that allows a jammer and sender to choose (1) whether to transmit or sleep, (2) a power level to transmit with, and (3) what channel to transmit on. We also allow the jammer to choose on how many channels it simultaneously attacks. A major addition in finite-energy jamming games is that the jammer and sender both have a limited amount of energy which is drained according to the actions a player takes. Bruce DeBruhl, Christian Kroer, Anupam Datta, Tuomas Sandholm, Patrick Tague |
WISEC | 5 |
| 2014 | Keeping up with the jammers: Observe-and-adapt algorithms for studying mutually adaptive opponents
Bruce DeBruhl, Patrick Tague |
Pervasive Mob. Comput. | 2 |
| 2013 | Designing for self-configuration and self-adaptation in the Internet of ThingsabstractThe Internet of Things (IoT) paradigm comprises a heterogenous mix of connected devices connected to the Internet. This promises a a wealth of opportunity for a large collection of distributed applications and services. However, the IoT introduces significant changes to the Internet model, largely Arjun P. Athreya, Bruce DeBruhl, Patrick Tague |
CollaborateCom | 3 |
| 2013 | Stochastic optimization of flow-jamming attacks in multichannel wireless networksabstractAn attacker can launch an efficient jamming attack to deny service to flows in wireless networks by using cross-layer knowledge of the target network. For example, flow-jamming defined in existing work incorporates network layer information into the conventional jamming attack to maximize its attack efficiency. In this paper, we redefine a discrete optimization model of flow-jamming in multichannel wireless networks and provide metrics to evaluate the attack efficiency. We then propose the use of stochastic optimization techniques for flow-jamming attacks by using three stochastic search algorithms: iterative improvement, simulated annealing, and genetic algorithm. By integrating the algorithms into a simulation based on the OPNET Modeler network simulator, we demonstrate the optimization process and provide performance comparisons of the algorithms. From our results, genetic algorithm provides the most efficient flow-jamming configuration. Yu Seung Kim, Bruce DeBruhl, Patrick Tague |
ICC | 3 |
| 2013 | MeshJam: Intelligent Jamming Attack and Defense in IEEE 802.11s Wireless Mesh NetworksabstractWireless mesh networks represent an emerging network architecture which has been actively studied and standardized for the last several years. Because of their flexible network architecture, wireless mesh networks can provide alternative paths even when wireless links are broken by node failures or routing attacks. Among a variety of mesh network protocols, we focus on the recently ratified IEEE 802.11s WLAN mesh standard. With analysis of the path selection scheme in 802.11s, we show the effect of conventional jamming on 802.11s-based wireless mesh networks via simulation. We then introduce mesh jamming, which can more efficiently attack the mesh path selection process by exploiting cross-layer knowledge and more harmfully influence on the path discovery performance compared to conventional jamming. We propose a proof-of-concept defense, bi-directional path discovery to mitigate the devastating effect of mesh jamming. Yu Seung Kim, Bruce DeBruhl, Patrick Tague |
MASS | 3 |
| 2013 | Wireless Mesh Network Simulator for Studying Cross-Layer Jamming EffectsabstractVarious wireless mesh network standards have been actively constituted for the last several years. Because of its flexible network architecture, wireless mesh network can provide alternative paths even when some of wireless links are broken by node failures or intended attacks. Among various types of mesh network, we focus on the IEEE 802.11s based on the widely used Wi-Fi networks and its resiliency to jamming attack. In this demo, we show jamming effects on wireless mesh network and the performance of the hybrid wireless mesh protocol (HWMP) defined in IEEE 802.11s and our proposed jamming defense. Yu Seung Kim, Patrick Tague |
MASS | 2 |
| 2013 | Network self-organization in the Internet of ThingsabstractThe Internet of Things is a paradigm that allows the interaction of ubiquitous devices through a network to achieve common goals. This paradigm like any man-made infrastructure is subject to disasters, outages and other adversarial conditions. Under these situations provisioned communications fail, rendering this paradigm with little or no use. Hence, network self-organization among these devices is needed to allow for communication resilience. This paper presents a survey of related work in the area of self-organization and discusses future research opportunities and challenges for self-organization in the Internet of Things. We begin this paper with a system perspective of the Internet of Things. We then identify and describe the key components of self-organization in the Internet of Things and discuss enabling technologies. Finally we discuss possible tailoring of prior work of other related applications to suit the needs of self-organization in the Internet of Things paradigm. Arjun P. Athreya, Patrick Tague |
SECON | 2 |
| 2013 | How to jam without getting caught: Analysis and empirical study of stealthy periodic jammingabstractDespite the widespread commercial use of spread spectrum technology, advanced algorithms and modern hardware capabilities still allows efficient denial-of-service attacks against wireless communication systems using jamming. Much of the recent work on jamming mitigation has focused on how to adjust the transmitter-receiver system once a jamming attack has been detected. However, characterizing the detectability of certain classes of jamming attacks remains a largely unstudied problem. We aim to narrow this gap by analyzing the effect of a class of periodic jamming attacks on the attack detection metrics of packet delivery ratio (PDR) and received signal strength (RSS). We show that a well-designed jamming signal can effectively defeat RSS-based detection while causing a significant and often devastating reduction in PDR, demonstrating that RSS-based detection is insufficient. We further evaluate our claims through implementation of a periodic jammer using a wide range of signal parameters against a transmitter-receiver pair communicating using IEEE 802.15.4, demonstrating the validity of our analytical claims. Bruce DeBruhl, Patrick Tague |
SECON | 2 |
| 2013 | ASIA: Accelerated secure in-network aggregation in vehicular sensing networksabstractVehicular Ad-Hoc Networks (VANETs) can potentially become a sensing platform. In-network aggregation, a fundamental primitive for querying sensory data, has been shown to reduce overall communication overhead at large. To secure data aggregation in VANETs, existing schemes mainly rely on digital signatures. However, generating and verifying such signatures can cause high computational overhead. More importantly, time-consuming verifications lead to the vulnerability to signature flooding attacks in which a receiver cannot timely verify all messages before their respective deadlines. In this paper, we propose ASIA as an Accelerated Secure In-network Aggregation strategy that can accelerate message verifications and significantly reduce computational overhead while retaining satisfactory security. We replace the most common tree graph with a directed acyclic graph as the aggregation structure. Resulting redundancy in information flow offers the opportunity for misbehavior detection. Meanwhile, by leveraging time asymmetry, upstream nodes in the structure can verify downstream messages through the modified light-weight TESLA scheme. We analyze the security properties of ASIA and provide evaluation results. We show that ASIA can largely accelerate message verifications and drastically reduce computational and communication overhead compared to existing schemes using the resource-consuming Elliptic Curve Digital Signature Algorithm. Xiao Wang 0040, Patrick Tague |
SECON | 2 |
| 2013 | Selfish manipulation of cooperative cellular communications via channel fabricationabstractIn today's cellular networks, user equipment (UE) have suffered from low spectral efficiency at cell-edge region due to high interference from adjacent base stations (BSs), which share the same spectral radio resources. In the recently proposed cooperative cellular networks, geographically separated multiple BSs cooperate on transmission in order to improve the UE's signal-to-interference-plus-noise-ratio (SINR) at cell-edge region. The service provider of the system dynamically assigns the cluster of BSs to achieve higher SINR for the UE while optimizing the use of system radio resources. Although it is the service provider that makes the the clustering decision for the UE, the service provider relies on the UE's input to the decision; i.e., the channel states from the adjacent BSs to the UE. In essence, the operation of the cooperative cellular netwokrs heavily relies on the trust in the UEs. In this paper, we propose a new selfish attack against the cooperative cellular networks; an adversary reprograms her UE to report fabricated channel information to cause the service provider to make a decision that benefits the adversary while wasting its system resources. We evaluate the proposed attack in a cooperative cellular network having various performance goals on the simulation-based experiments and show that the adversary can trick the service provider into expending 3.7 times more radio resources for the adversary and, accordingly, the adversary achieves up to 16 dB SINR gain. Finally, we propose a threshold-based countermeasure for the service provider to detect the attack with approximately 90% of accuracy. Shrikant Adhikarla, Min Suk Kang, Patrick Tague |
WISEC | 3 |
| 2012 | Carving secure wi-fi zones with defensive jammingabstractWith rampant deployment of wireless technologies such as WLAN, information leakage is increasingly becoming a threat for its serious adopters such as enterprises. Research on antidotes has been mainly focused on logical measures such as authentication protocols and secure channels, but an inside collaborator can readily circumvent such defenses and wirelessly divert the classified information to a conniver outside. In this paper, we propose a novel approach to the problem that forges a walled wireless coverage, a secure Wi-Fi zone in particular. Inspired by the fact that jamming as an attack is inherently difficult to defeat, we turn the table and use it as a defensive weapon to fend off the covert illegal access from outside. To validate the proposed approach, we conduct extensive outdoor experiments with the IEEE 802.11g Wi-Fi adapters. The measurements show that the forged secure zones match well with the model prediction and that the defensive jamming approach can indeed be used to protect wireless networks against information leakage. Lastly, we propose the algorithms to configure defensive jammers in arbitrary geometry. Yu Seung Kim, Patrick Tague, Heejo Lee |
AsiaCCS | 2 |
| 2012 | All your jammers belong to us - Localization of wireless sensors under jamming attackabstractAccurately determining locations of nodes in mobile wireless network is crucial for a myriad of applications. Unfortunately, most localization techniques are vulnerable to jamming attacks where the adversary attempts to disrupt communication between legitimate nodes in the network. In this paper, we propose an approach to localize a wireless node by using jamming attack as the advantage of the network. Our localization technique is divided into two steps. First, we discover the location of the jammer using power adaptation techniques. Then, we use these properties to extrapolate the locations of jammed nodes. We design a localization protocol using this technique, and demonstrate the feasibility of our mechanism by conducting indoor experiments based on IEEE 802.15.4 wireless nodes. Our result shows that for some situations our mechanism can be used to locate mobile nodes under jamming attack. Yu Seung Kim, Frank Mokaya, Eric Yawei Chen, Patrick Tague |
ICC | 4 |
| 2012 | STIR-ing the wireless medium with self-tuned, inference-based, real-time jammingabstractJamming broadcasting to intentionally interfere with wireless reception, has long been a problem for wireless systems. Recent research demonstrates numerous advances in jamming techniques that increase attack efficiency or reduce the probability an attack will be detected by choosing attack parameters based on a system's configuration. In this work, we extend the attacker's capabilities by modifying the attack parameters in response to the observed performance of the target system, effectively creating a feedback loop in our attack model. This framework allows for more intricate attack models that are tuned online allowing for closer to optimal attacks against legitimate systems. To show the feasibility of the listening and attacking framework we introduce an attack called Self-Tuned, Inference-based, Real-time jamming or STIR-jamming. This attack listens to legitimate communication traffic, infers the systems performance, and optimizes jamming parameters. We propose the two types of STIR-jamming, mSTIR-jamming and tSTIR-jamming, and implement these attacks against an IEEE 802.15.4 link as a case study. With the empirical results, we demonstrate the attack system adapting to various scenarios and finding stable solutions. Bruce DeBruhl, Yu Seung Kim, Zachary Weinberg, Patrick Tague |
MASS | 4 |
| 2012 | ShortMAC: Efficient Data-Plane Fault Localization
Xin Zhang 0003, Zongwei Zhou, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Patrick Tague |
NDSS | 6 |
| 2012 | Living with boisterous neighbors: Studying the interaction of adaptive jamming and anti-jammingabstractJamming has long been a problem in wireless communications, but with recent advances in adaptive jamming, adaptive anti-jamming, and other advanced physical layer security techniques, it is hard to understand whether we can keep the jammer at bay. In this work, we consider this problem and introduce a game-theoretic framework which gives us a tool to analyze the complex adaptive jamming and anti-jamming space. To illustrate the strengths and weaknesses in intelligent jamming and anti-jamming techniques, we present a straightforward two-player instance and analyze a number of possible jamming and anti-jamming techniques. Bruce DeBruhl, Patrick Tague |
WOWMOM | 2 |
| 2012 | S-SPAN: Secure smart posters in Android using NFCabstractSmart posters are a promising new use case for NFC-enabled mobile devices, but to date there has been a general lack of security mechanisms for NFC smart posters. We present S-SPAN - a secure smart poster system consisting of three parts: an administrative web interface for managing posters, a backend server for storing and serving data, as well as an Android application for end-users. S-SPAN enforces confidentiality and integrity of smart poster data as well as authentication/authorization of administrators and end-users, thus ensuring that only authorized users can access the content. Ram Shankar Siva Kumar, Patrick Tague |
WOWMOM | 5 |
| 2011 | Digital Filter Design for Jamming Mitigation in 802.15.4 CommunicationabstractJamming attackers can dramatically increase attack efficiency and stealth by randomly or periodically cycling the jamming transmission on and off, attacks respectively known as random and periodic jamming. In this paper, we analyze the impact of such attacks on the IEEE 802.15.4 communication protocol, commonly used in wireless sensor networking applications, and show that the cycling behavior introduces a narrow spectral component into the received signal. We propose the inclusion of a digital filter at the receiver side to effectively eliminate this spectral component, and we discuss the benefits involved in this filter design. We evaluate the impacts of random and periodic jamming with and without the proposed filter, through implementation in software defined radios. Through our evaluation, we observe over 90% reduction in packet error rate with the proposed digital filter. Bruce DeBruhl, Patrick Tague |
ICCCN | 2 |
| 2011 | Towards secure multi-path routing for wireless mobile ad-hoc networks: A cross-layer strategyabstractMulti-path routing establishes multiple paths between a source and destination node in a network. This helps in achieving reliability in mobile ad-hoc networks (MANETs). To achieve efficient, secure and reliable multi-path routing for MANETs, we propose a routing mechanism that uses cross-layer strategies. The cross-layer strategy involves incorporating feedback and information from layers below the network layer to make decisions at the network layer. We also propose a path evaluation mechanism for the paths returned by the proposed multi-path routing mechanism. Arjun P. Athreya, Patrick Tague |
SECON | 2 |
| 2011 | Jamming-aware traffic allocation for multiple-path routing using portfolio selectionabstractMultiple-path source routing protocols allow a data source node to distribute the total traffic among available paths. In this paper, we consider the problem of jamming-aware source routing in which the source node performs traffic allocation based on empirical jamming statistics at individual network nodes. We formulate this traffic allocation as a lossy network flow optimization problem using portfolio selection theory from financial statistics. We show that in multisource networks, this centralized optimization problem can be solved using a distributed algorithm based on decomposition in network utility maximization (NUM). We demonstrate the network's ability to estimate the impact of jamming and incorporate these estimates into the traffic allocation problem. Finally, we simulate the achievable throughput using our proposed traffic allocation method in several scenarios. Patrick Tague, Sidharth Nabar, James A. Ritcey, Radha Poovendran |
IEEE/ACM Trans. Netw. | 1 |
| 2010 | Improving anti-jamming capability and increasing jamming impact with mobility controlabstractThe impact of a jamming attack on wireless communication depends on a number of physical characteristics and network protocol parameters. In particular, it depends on the relative geometries of the adversarial network of jammers and the network under attack. Hence, changes in network geometry achieved through node and jammer mobility can have significant influence on the impact of a jamming attack. In this work, we investigate the use of mobility as a tool to allow both the adversarial network and the network under attack to reconfigure their geometry in an attempt to improve attack impact and protocol performance, respectively. We present a mobility control framework for use by nodes in the network under attack and by jammer in the adversarial network. We show that a number of factors can be incorporated into node and jammer mobility using the proposed framework. Patrick Tague |
MASS | 1 |
| 2009 | A coding-theoretic approach for efficient message verification over insecure channelsabstractWe address the problem of allowing authorized users, who have yet to establish a secret key, to securely and efficiently exchange key establishment messages over an insecure channel in the presence of jamming and message insertion attacks. This problem was first introduced by Strasser, Pöpper, Čapkun, and Čagalj in their recent work, leaving joint consideration of security and efficiency as an open problem. In this paper, we present three approaches based on coding theory which reduce the overall time required to verify the packets and reconstruct the original message in the presence of jamming and malicious insertion. We first present the Hashcluster scheme which reduces the total overhead included in the short packets. We next present the Merkleleaf scheme which uses erasure coding to reduce the average number of packet receptions required to reconstruct the message. We then present the Witnesscode scheme which uses one-way accumulators to individually verify packets and reduce redundancy. We demonstrate through analysis and simulation that our candidate protocols can significantly decrease the amount of time required for key establishment in comparison to existing approaches without degrading the guaranteed level of security. David Slater, Patrick Tague, Radha Poovendran, Brian J. Matt |
WISEC | 2 |
| 2009 | Evaluating the Vulnerability of Network Traffic Using Joint Security and Routing AnalysisabstractJoint analysis of security and routing protocols in wireless networks reveals vulnerabilities of secure network traffic that remain undetected when security and routing protocols are analyzed independently. We formulate a class of continuous metrics to evaluate the vulnerability of network traffic as a function of security and routing protocols used in wireless networks. We develop two complementary vulnerability definitions using set theoretic and circuit theoretic interpretations of the security of network traffic, allowing a network analyst or an adversary to determine weaknesses in the secure network. We formalize node capture attacks using the vulnerability metric as a nonlinear integer programming minimization problem and propose the GNAVE algorithm, a Greedy Node capture Approximation using Vulnerability Evaluation. We discuss the availability of security parameters to the adversary and show that unknown parameters can be estimated using probabilistic analysis. We demonstrate vulnerability evaluation using the proposed metrics and node capture attacks using the GNAVE algorithm through detailed examples and simulation. Patrick Tague, David Slater, Jason Rogers, Radha Poovendran |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2009 | Mitigation of Control Channel Jamming under Node Capture AttacksabstractAvailability of service in many wireless networks depends on the ability for network users to establish and maintain communication channels using control messages from base stations and other users. An adversary with knowledge of the underlying communication protocol can mount an efficient denial of service attack by jamming the communication channels used to exchange control messages. The use of spread spectrum techniques can deter an external adversary from such control channel jamming attacks. However, malicious colluding insiders or an adversary who captures or compromises system users is not deterred by spread spectrum, as they know the required spreading sequences. For the case of internal adversaries, we propose a framework for control channel access schemes using the random assignment of cryptographic keys to hide the location of control channels. We propose and evaluate metrics to quantify the probabilistic availability of service under control channel jamming by malicious or compromised users and show that the availability of service degrades gracefully as the number of colluding insiders or compromised users increases. We propose an algorithm called GUIDE for the identification of compromised users in the system based on the set of control channels that are jammed. We evaluate the estimation error using the GUIDE algorithm in terms of the false alarm and miss rates in the identification problem. We discuss various design trade-offs between robustness to control channel jamming and resource expenditure. Patrick Tague, Radha Poovendran |
IEEE Trans. Mob. Comput. | 1 |
| 2008 | Vulnerability of Network Traffic under Node Capture Attacks Using Circuit Theoretic AnalysisabstractWe investigate the impact of node capture attacks on the confidentiality and integrity of network traffic. We map the compromise of network traffic to the flow of current through an electric circuit and propose a metric for quantifying the vulnerability of the traffic using the circuit mapping. We compute the vulnerability metric as a function of the routing and the cryptographic protocols used to secure the network traffic. We formulate the minimum cost node capture attack problem as a nonlinear integer programming problem. Due to the NP-hardness of the minimization problem, we provide a greedy heuristic that approximates the minimum cost attack. We provide examples of node capture attacks using our vulnerability metric and show that the adversary can expend significantly less resources to compromise target traffic by exploiting information leakage from the routing and cryptographic protocols. Patrick Tague, David Slater, Jason Rogers, Radha Poovendran |
INFOCOM | 1 |
| 2008 | Throughput optimization for multipath unicast routing under probabilistic jammingabstractWe present a framework for throughput optimization for multipath unicast routing in wireless networks in the presence of probabilistic jamming. The framework introduces a statistical characterization into the maximum network flow problem to compensate for the reduction in network flow due to the loss of jammed packets. We map the problem of throughput optimization under probabilistic jamming to that of optimal investment portfolio selection, treating the network throughput as the return on financial investments and using a common portfolio selection framework from financial statistics. Based on the portfolio selection framework, we present approaches to maximize expected throughput and to minimize throughput variance. We include both a detailed example and a simulation study to illustrate the application of the throughput optimization framework. Patrick Tague, Sidharth Nabar, James A. Ritcey, David Slater, Radha Poovendran |
PIMRC | 1 |
| 2007 | Probabilistic Mitigation of Control Channel Jamming via Random Key DistributionabstractThe use of distinct, dedicated communication channels to transmit data and control traffic introduces a single point of failure for a denial of service attack, in that an adversary may be able to jam control channel traffic and prevent relevant data traffic. Hence, it is of interest to design control channel access schemes which are resilient to jamming. We map the problem of providing resilient control channel access under jamming to that of secure communication channel establishment. We propose the use of random key distribution to hide the location of control channels in time and/or frequency. We evaluate performance metrics of resilience to control channel jamming, identification of compromised users, and delay due to jamming as a function of the number of compromised users. Patrick Tague, Radha Poovendran |
PIMRC | 1 |
| 2007 | Modeling adaptive node capture attacks in multi-hop wireless networks
Patrick Tague, Radha Poovendran |
Ad Hoc Networks | 1 |
| 2007 | A canonical seed assignment model for key predistribution in wireless sensor networksabstractA promising solution for trust establishment in wireless sensor networks is the assignment of cryptographic seeds (keys, secrets, etc.) to sensor nodes prior to network deployment, known as key predistribution . In this article, we propose a canonical seed assignment model for key predistribution characterizing seed assignment in terms of the probability distribution describing the number of nodes receiving each seed and the algorithm for seed assignment. In addition, we present a sampling framework for seed assignment algorithms in the canonical model. We propose a probabilistic k -connectivity model for randomly deployed secure networks using spatial statistics and geometric random graph theory. We analyze key predistribution schemes in the canonical model in terms of network connectivity and resilience to node capture. The analytical results can be used to determine the average or worst-case connectivity or resilience to node capture for a key predistribution scheme. Furthermore, we demonstrate the design of new key predistribution schemes and the inclusion of existing schemes in the canonical model. Finally, we present a general approach to analyze the addition of nodes to an existing secure network and derive results for a well-known scheme. Patrick Tague, Radha Poovendran |
ACM Trans. Sens. Networks | 1 |
| 2006 | A general probabilistic model for improving key assignment in wireless networksabstractWe study the problem of establishing secure communication channels in resource-constrained wireless networks using key predistribution. Pairwise communication channels between nodes are secured using link keys which are established as a function of cryptographic seeds predistributed to each node. We propose a general model for seed assignment which regulates the number of nodes sharing each seed. In addition, we provide a general model for wireless network connectivity where communication is restricted by both radio range and an independent pairwise relationship. We provide probabilistic analysis for network connectivity and resilience to node capture in terms of our seed assignment and network connectivity models. Finally, we provide a numerical example demonstrating how the proposed approach reduces key wastage while maintaining resilience to node capture of prior results. Patrick Tague, Radha Poovendran |
WiOpt | 1 |