EDBT 2026 Demo / reviewers in the wild / expert
Wojciech Mazurczyk
dblp:91/874 · also Woiciech Mazurczyk
· DBLP profile ↗
87ranked-venue papers
18as first author
37since 2021 · last 2026
0000-0002-8509-4127ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 53 · 10 first-author · 19 since 2021Computer networks · 9 · 6 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 5 since 2021Systems, architecture and hardware · 5 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An innovative user-to-device authentication scheme using broad learning-based dynamic hint generation
Milad Taleby Ahvanooey, Wojciech Mazurczyk |
Eng. Appl. Artif. Intell. | 2 |
| 2025 | Assessing the Threat of Neural Network Enhanced Obfuscation in Malware
Adrian Brodzik, Wojciech Mazurczyk |
AINA (4) | 2 |
| 2025 | Double Proof-of-Work Scheme for the Key Transfer in the Steganographic Communication
Pawel Rajba, Wojciech Mazurczyk, Jörg Keller 0001 |
AINA (4) | 2 |
| 2025 | A novel framework for assessing determinant risk factors on cyber (dis)trust behaviors of netizens in deepfakesabstractNowadays, Generative Artificial Intelligence (GenAI) tools or trainable agents can craft synthetic media (hereafter referred to as deepfakes) in the form of realistic texts, images, videos, and audios, incorporating events or things that never occurred in real life. These GenAI tools empower marketers and malicious actors to create deepfakes, both authorized and weaponized multimedia, which allows them to include celebrities without appearing in front of cameras or creating seductive phishing scams. Although GenAI tools can reduce the cost of content construction, they enable new risky opportunities (e.g., deepfake phishing and cyberbullying) that negatively impact netizens’ learning and (dis)trust behaviors in cyberspace. To address such risks, this study proposes a Multi-Criteria-Multi-Decision-Makers (MCMDM)-based Deepfake Risk Assessment Framework (DeepFakeR-MF) to evaluate determinant factors that impact the cyber (dis)trust behaviors of netizens in deepfakes. Moreover, DeepFakeR-MF deploys a combination of a novel optimized spherical fuzzy analytic hierarchy process method and a game theory-based MCMDM approach to prioritize and recommend alternative strategies that can be taken by five management sectors (e.g., industrial enterprises, governmental organizations, media outlets, social non-profit, and educational institutes) to mitigate GenAI-associated risks. Then, we collect 100 experts’ judgments by analyzing their responses to our questionnaire and prioritize the importance of determinant factors considering their preferences. To validate the prioritized factors on the performance of DeepFakeR-MF, we conduct a sensitivity analysis applying Monte Carlo statistical modeling. Finally, our results confirm that DeepFakeR-MF provides effective strategic alternatives for policymakers, educators, media professionals, engineers, and netizens, hopefully reducing the socio-economic risks of deepfakes. Milad Taleby Ahvanooey, Wojciech Mazurczyk, Zefan Wang, Jun Zhao 0007 |
Eng. Appl. Artif. Intell. | 2 |
| 2024 | Investigating HTTP Covert Channels Through Fuzz TestingabstractModern malware increasingly deploys network covert channels to prevent detection or bypass firewalls. Unfortunately, the early discovery of protocol fields and functional behaviors of traffic that can be abused to conceal information is very challenging. In this perspective, fuzz testing could help to face the tight relationship between the used hiding scheme and the targeted protocol trait. Even if fuzzing is a well-established practice to reveal implementation issues, bugs, or unhandled behaviors, it has never been considered to assess the “susceptilibility” of protocols to covert communications. Kai Hölk, Wojciech Mazurczyk, Marco Zuppelli, Luca Caviglione |
ARES | 2 |
| 2024 | Trustworthiness and explainability of a watermarking and machine learning-based system for image modification detection to combat disinformationabstractThe widespread use of digital platforms, prioritising content based on engagement metrics and rewarding content creators accordingly, has contributed to the proliferation of disinformation and its far-reaching social and political impact. In addition, digital platforms often operate as black boxes, concealing their decision-making processes from users and prioritizing investor interests over ethical and social considerations. Consequently, this has contributed to the erosion of general trust in verification systems. To mitigate this issue, our project proposes a two-stage verification system. The first stage allows media industries to watermark their image and video content. The second stage involves implementing a machine-learning-based manipulation detection system for suspicious content. We present findings from an international user experience study, where potential online news consumers verified the authenticity of images on a prototype version of our system. In this paper, we reflect on critical issues of explainability addressed by participants in our user study and how we addressed this issue in the platform’s design. Andrea Rosales, Agnieszka Malanowska, Tanya Koohpayeh Araghi, Minoru Kuribayashi, Marcin Kowalczyk, Daniel Blanche-Tarragó, Wojciech Mazurczyk, David Megías 0001 |
ARES | 7 |
| 2024 | A Comparative Study on the Security of Kubernetes DeploymentsabstractAs the adoption of containerized environments continues to expand, ensuring the security of Kubernetes clusters has become a major concern. In this paper, we analyze the security postures of four Kubernetes clusters in distinct configurations. In more detail, we consider two popular on-premises clusters and two managed services from public cloud providers. To perform the comparative analysis, a dedicated tool is created to automate security scans of cluster workloads, aggregate data on compliance, vulnerabilities, and misconfigurations, and support flexible result analysis. Experimental evaluation focuses on resource misconfigurations, container image vulnerabilities, and security benchmark compliance. The results obtained reveal the differences resulting from distinct management and deployment models of the compared environments. Kacper Kamieniarz, Wojciech Mazurczyk |
IWCMC | 2 |
| 2024 | A Research Environment for Evaluating File-based Cryptojacking Detection TechniquesabstractWith the advent of blockchain technology, despite the introduction of many new solutions in the field of cybersecurity, new types of attacks have also appeared. One is cryptojacking, an attack that aims to take over the victim’s resources to mine cryptocurrencies and thus generate profits. Detecting cryptojacking is still challenging for modern antivirus systems, although many detection methods have been proposed in the literature, and their effectiveness ranges from $50 \%$ to nearly $\mathbf{9 5 \%}$. However, it is unclear if these techniques would still be successful if the cryptojackers behavior evolves. That is why, in this paper, a universal research environment is designed and implemented in which a configurable tool for simulating file-based cryptojacking is available. It can be easily integrated and expanded with new functionalities and is characterized by simplicity in testing various file cryptojacking detection tools. This allows other researchers to evaluate their solutions in a homogeneous experimental environment and compare the results with existing techniques. This work also demonstrates how the created setup can be used to evaluate the detection effectiveness of available antivirus systems and detection tools dedicated for this type of threat. Lukasz Pietraszek, Wojciech Mazurczyk |
IWCMC | 2 |
| 2024 | Performance evaluation of Raspberry Pi 4 and STM32 Nucleo boards for security-related operations in IoT environmentsabstractAt present, Internet of Things devices are revolutionizing and impacting increasingly more areas of our daily lives. However, there remain doubts related to the lack of sufficient security in the IoT ecosystem. As such devices have limitations in terms of resources such as computational power and batteries, adding security mechanisms is often perceived as an unnecessary burden, slowing the further expansion of IoT-based solutions and applications. In this study, an investigation is conducted to verify the possibility of applying security measures such as strong encryption without hindering the performance of IoT devices. This factor is especially important from the perspective of the European project SILVANUS, in which various IoT application scenarios are envisioned. Taking into account the above, in this work, an extensive experimental performance evaluation campaign is performed using the DTLS-based encryption of network traffic for two popular boards: Raspberry Pi 4 and STM32 Nucleo. The obtained results demonstrate that the utilization of strong encryption is feasible (with some limitations) on IoT devices, but the resulting performance or battery life is not a reasonable argument anymore to leave IoT ecosystems completely insecure. Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk |
Comput. Networks | 4 |
| 2024 | A Meta-Analysis of State-of-the-Art Automated Fake News Detection MethodsabstractRecently, various artificial intelligence (AI)-based methods have been proposed to support humans in detecting disinformation and fake news. The goal of this article is to provide a meta-analysis, and formally evaluate, compare, and benchmark various classes of fake news detection approaches. To this end, the following paper performs a comprehensive analysis of the performance-related results of different models using a range of benchmark datasets. The performed and disclosed meta-analysis compares the statistical significance of differences in a range of performance metrics, including precision,$F1$-score, recall, and balanced accuracy (BACC). The utilized approach features the$5$$\times$$2$cross-validation methodology. The models undergoing the formal evaluation constitute state-of-the-art (SOTA) solutions meeting acceptance criteria. The evaluated approaches draw from the most recent advancements in natural language processing (NLP). The outcome of this work is the formal benchmarking and meta-analysis of fake news detection methods that can be further utilized by the research community, but more importantly by the practitioners and decision-makers that counter fake news on a daily basis, e.g., in press agencies, homeland security agencies, fact-checkers, and so on. This work is the natural extension of the authors’ previous systematic analysis of fake news detection methods and authors’ own fake news detection methods based on machine learning (ML)/artificial intelligence (AI) techniques. Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras, Wojciech Mazurczyk, Krzysztof Cabaj |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2023 | Security Architecture in the SILVANUS projectabstractSILVANUS is a new EU-funded project whose main objectives are to address the causes of wildfires in Europe. To achieve this aim, a dedicated platform for environmentally sustainable and climate-resilient forest management has been developed with the help of many state-of-the-art, modern technologies. One of the major challenges to solve when building such a heterogeneous, multi-component, multipurpose platform is to provide the necessary security architecture. It should ensure that only trusted users and devices (e.g., sensors, drones, UGVs, etc.) would be allowed to use it, and attackers or other third parties would not jeopardize its communication and assets. In this paper, we outline the main design principles, solutions, and mechanisms we have considered when building the security architecture for the SILVANUS platform. Moreover, we present the current state of development of this platform and the main challenges we have been facing. Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk, Helen-Catherine Leligou, Marcin Przybyszewski, Rafal Kozik, Michal Choras |
ARES | 5 |
| 2023 | Proof-of-work based new encoding scheme for information hiding purposesabstractSteganography techniques often assume that the secret message looks randomly or is encrypted. If encryption is required, it leads to a random-looking message, but key exchange may be problematic and jeopardize covert communication. If encryption is not required, then the question arises of whether other cryptographic solutions that are “cheaper” than encryption can provide the same level of randomness. In this paper, we investigate both questions. First, we propose a proof-of-work-inspired approach to securely transfer the key with the encrypted message, avoiding a previous key exchange. Second, we introduce a scheme that uses T-functions to substitute symmetric encryption algorithms. We implement both proposed solutions, measure the entropy of the resulting messages, and apply the Kolmogorov-Smirnoff tests. The results obtained prove that both schemes are feasible. Pawel Rajba, Jörg Keller 0001, Wojciech Mazurczyk |
ARES | 3 |
| 2023 | Combating Disinformation with Holistic Architecture, Neuro-symbolic AI and NLU ModelsabstractIt is important to realize that false news is more than just a deception. Sadly, it is impossible to confirm every bit of information we come across. A normal human impulse is to accept any information that looks sufficiently convincing, relevant, or exciting. In doing so, we often do not realize that we have just contributed to the misinformation of the community to which we belong. As a result, fake news happens to be our collective error. In this paper, we propose an architecture for combating the disinformation problem using a hybrid-based approach. We demonstrate our preliminary results on the health-related fake news dataset. Rafal Kozik, Wojciech Mazurczyk, Krzysztof Cabaj, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
DSAA | 2 |
| 2023 | Malware Classification Using Open Set Recognition and HTTP Protocol Requests
Piotr Bialczak, Wojciech Mazurczyk |
ESORICS (2) | 2 |
| 2023 | Toward the mutual routing security in wide area networks: A scoping review of current threats and countermeasuresabstractThe inter-domain routing security is often based on trust, which, as seen in practice, is an insufficient approach. Due to the deficit of native security controls in the Border Gateway Protocol (BGP), many new routing security measures were proposed to prevent control-plane abuse. They must be implemented in the majority of the Internet’s Autonomous Systems. This study undertakes a scoping review of the routing security domain to provide the most up-to-date and state-of-the-art broad summary of threat classification, prevention, and mitigation. The authors determine the progress of implementing countermeasures and explain the obstacles and research directions. This paper covers the current threat landscape and the existing taxonomies of attack vectors on the routing layer. By analyzing different taxonomies, we detected overlapping incident types. Therefore, a unified and consolidated taxonomy is proposed to preserve consistency among different attack types, simultaneously giving a more detailed breakdown of incident classification. This review also contains a comprehensive comparative study of protective measures, including historical, current, and developing techniques. This study includes the efficiency of proactive (prevention) and reactive (mitigation) practices and their caveats. The authors also examine the most promising development plans for new and existing countermeasures. Global implementation efforts are focused on routing security’s safeguard mechanisms based on mutual protection, e.g., the Resource Public Key Infrastructure (RPKI) system. This determinant creates an infinite regress problem known as the chicken or the egg—the primary dilemma. The authors find that the point of critical mass is achieved but that RPKI still faces vital issues. Mikolaj Kowalski, Wojciech Mazurczyk |
Comput. Networks | 2 |
| 2023 | AFPr-AM: A novel Fuzzy-AHP based privacy risk assessment model for strategic information management of social media platformsabstractSocial Media Platforms (SMPs) have changed how we communicate, share, and obtain information. However, this also comes at a cost, as users (willingly) share their Privately Sensitive Data (PSDs), such as pictures, real-time locations, and other personal connections, on SMPs. Recently, privacy concerns have gained much attention from both academia and industry . The current literature lacks the privacy risk assessment model that can lead the management sectors (e.g., industrial, social, and governmental) to cooperate to mitigate the privacy invasion risks of users’ PSDs in SMPs. Hence, we propose a novel assessment model (hereafter referred to as AFPr-AM), suggesting alternative strategies for reducing privacy invasion risks of users’ PSDs in SMPs based on determinant criteria . First, we explore multiple factors from the literature that affect the privacy invasion risks of users’ PSDs. Then, to prioritize the importance of determinant criteria , we seek sixty experts to participate in our survey and rank these factors. Finally, we apply the fuzzy analytical hierarchy process approach for weighting the criteria based on the experts’ opinions. Moreover, we employ a cooperative game theory-based multi criteria decision making framework to assess the possibilities of players’ interactions (e.g., management sectors), considering the weighted criteria as players’ payoffs. Our extensive experiments demonstrate that the AFPr-AM model provides effective strategic alternatives to mitigate the possible invasion risks of users’ PSDs in SMPs. Milad Taleby Ahvanooey, Mark Xuefang Zhu, Shiyan Ou, Hassan Dana Mazraeh, Wojciech Mazurczyk, Kim-Kwang Raymond Choo |
Comput. Secur. | 5 |
| 2023 | STFF-SM: Steganalysis Model Based on Spatial and Temporal Feature Fusion for Speech StreamsabstractThe real-time detection of speech steganography in Voice-over-Internet-Protocol (VoIP) scenarios remains an open problem, as it requires steganalysis methods to perform for low-intensity embeddings and short-sample inputs, as well as provide rapid detection results. To address these challenges, this paper presents a novel steganalysis model based on spatial and temporal feature fusion (STFF-SM). Differing from the existing methods, we take both the integer and fractional pitch delays as input, and design subframe-stitch module to organically integrate subframe-wise integer delays and frame-wise fractional pitch delays. Further, we design a spatial fusion module based on pre-activation residual convolution to extract the pitch spatial features and gradually increase their dimensions to discover finer steganographic distortions to enhance the detection effect, where a Group-Squeeze-Weighting block is introduced to alleviate the information loss in the process of increasing the feature dimension. In addition, we design a temporal fusion module to extract pitch temporal features using the stacked LSTM, where a Gated Feed-Forward Network is introduced to learn the interaction between different feature maps while suppressing the features that are not useful for detection. We evaluated the performance of STFF-SM through comprehensive experiments and comparisons with the state-of-the-art solutions. The experimental results demonstrate that STFF-SM can well meet the needs of real-time detection of speech steganography in VoIP streams, and outperforms the existing methods in detection performance, especially with low embedding strengths and short window sizes. Hui Tian 0002, Yiqin Qiu, Wojciech Mazurczyk, Haizhou Li 0001, Zhenxing Qian |
IEEE ACM Trans. Audio Speech Lang. Process. | 3 |
| 2022 | Detection of Malicious Images in Production-Quality Scenarios with the SIMARGL ToolkitabstractAn increasing trend exploits steganography to conceal payloads in digital images, e.g., to drop malicious executables or to retrieve configuration files. Due to the very attack-specific nature of the exploited hiding mechanisms, developing general detection methods is a hard task. An effective approach concerns the creation of ad-hoc solutions to be integrated within general toolkits, also to holistically face unknown threats. Therefore, this paper discusses the integration of a tool for detecting malicious contents hidden in digital images via the Invoke-PSImage technique within the Secure Intelligent Methods for Advanced Recognition of Malware and Stegomalware framework. Since the real impact of images embedding steganographic threats and the behavior of ad-hoc solutions in realistic scenarios are still unknown territories, this work also showcases a performance evaluation conducted in a nation-wide telecommunication provider. Results demonstrated the effectiveness of the approach and also support the need of modular architectures to face the emerging wave of highly-specialized threats. Luca Caviglione, Martin Grabowski, Kai Gutberlet, Adrian Marzecki, Marco Zuppelli, Andreas Schaffhauser, Wojciech Mazurczyk |
ARES | 7 |
| 2022 | Web Page Harvesting for Automatized Large-scale Digital Images Anomaly DetectionabstractCurrently, digital media content is increasingly being used by cybercriminals for nefarious purposes. Such objects can be used, e.g., to covertly transfer malicious code to the infected host or to exfiltrate sensitive information from the secured perimeter to the attacker’s server. In this paper, we present the design and deployment of a web page harvesting platform that allows performing various types of large-scale analyses, including metadata inspection, detection of hidden data, or evaluation of compliance with the graphical standard. The platform architecture has a distributed, flexible, and modular form, making it easily extendable and efficient. In this article, we also include initial experimental results of the analyzes carried out on the content of 1,000 of the most popular websites. Marcin Kowalczyk, Agnieszka Malanowska, Wojciech Mazurczyk, Krzysztof Cabaj |
ARES | 3 |
| 2022 | Limitations of Web Cryptojacking Detection: A Practical EvaluationabstractCryptojacking is one of the new threats that emerged several years ago with the growing popularity and increasing value of cryptocurrencies. In essence, it is a malicious technique where the attacker parasites on the victim’s resources like CPU time, memory, etc. to mine cryptocurrencies for his own benefit. Cryptojacking comes in two main flavors, i.e., as a malicious script embedded into the website or as a standalone malware residing on the compromised machine. As such threats are still widespread, in this paper, we perform a practical evaluation of the existing web browser blockers against real-world web-based cryptojacking solutions. The obtained experimental results reveal that in more than 60% of cases the tested defensive solutions fail in fighting this threat or can be easily fooled with a few simple modifications. This underlines the importance of further efforts toward developing effective countermeasures. Pawel Rajba, Wojciech Mazurczyk |
ARES | 2 |
| 2022 | Performance Evaluation of DTLS Implementations on RIOT OS for Internet of Things ApplicationsabstractThe popularity, variety, and number of Internet of Things (IoT) devices and solutions have been increasing significantly with each passing year. This diversity of devices, and limited computational, memory, and battery resources make it difficult to apply effective security solutions. That is why dedicated mechanisms for the protection of IoT-based transmissions are developed. One of the most popular solutions is Datagram Transport Layer Security (DTLS), which allows securing datagram-based applications. In this paper, we investigate how efficient the three currently available DTLS implementations provided by the RIOT Operating System are. Based on the results obtained, interested parties can choose the DTLS module that has the best performance for the chosen IoT application. Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 4 |
| 2022 | Emerging topics in defending networked systems
Steffen Wendzel, Wojciech Mazurczyk, Luca Caviglione, Amir Houmansadr |
Future Gener. Comput. Syst. | 2 |
| 2022 | Towards blind detection of steganography in low-bit-rate speech streamsabstractTo prevent the abuse of low-rate speech-based steganography from threatening cyberspace security, the corresponding steganalysis approaches have been developed and received significant attention from research community. However, most existing steganalysis methods assume that steganography methods are known in advance, which in practice is impractical. That is why, in this paper, we present three blind detection schemes suitable for steganography in low-bit-rate speech streams. The first is based on mixed sample data augmentation. It randomly selects a certain proportion of steganographic samples from the sample set of each steganographic method to form a training set together with the original carrier samples for training to enhance the robustness of the model. The second relies on decision fusion where first step is to train a dedicated classification model for each steganography method and then use a majority voting mechanism in the detection stage to fuse the outputs of each model to give the final detection result. Compared to the other two steganalysis schemes, the third one design the detection model based on self-paced ensemble according to the distribution characteristics of speech samples. Its main idea is to fully train multiple base classifiers through multiple iterations as well as under-sampling processes, and organically fuse them to form a powerful ensemble classifier. In each iteration, differing from the traditional ensemble classifier solution, we put more attention to the steganographic samples at the decision boundary for the under-sampling process of the steganography set composed of multiple steganography methods, rather than randomly selecting steganographic samples. The steganographic samples at the decision boundary are searched using the classification hardness given by the ensemble classifier trained in the last iteration, which is more informative and more conducive to improve the performance of base classifiers. The experimental results show that the proposed three schemes can achieve efficient blind detection for low-bit-rate speech-based steganography, and the steganalysis scheme based on the self-paced ensemble has the best performance. Specifically, when the embedding rate is at 30%, the accuracy of the steganalysis scheme based on self-paced ensemble is more than 85%, while the accuracy of the other two steganalysis method is less than 80%. Additionally, the steganalysis scheme based on the self-paced ensemble learning even outperforms dedicated detectors for specific steganographic methods in terms of recall for steganographic sample detection. Congcong Sun 0002, Hui Tian 0002, Wojciech Mazurczyk, Chin-Chen Chang 0001, Yiqiao Cai |
Int. J. Intell. Syst. | 3 |
| 2022 | Modern Authentication Schemes in Smartphones and IoT Devices: An Empirical SurveyabstractUser authentication remains a challenging issue, despite the existence of a large number of proposed solutions, such as traditional text-based, graphical-based, biometrics-based, Web-based, and hardware-based schemes. For example, some of these schemes are not suitable for deployment in an Internet of Things (IoT) setting, partly due to the hardware and/or software constraints of IoT devices. The increasing popularity and pervasiveness of IoT equipment in a broad range of settings reinforces the importance of ensuring the security and privacy of IoT devices. Therefore, in this article, we conduct a comprehensive literature review and an empirical study to gain an in-depth understanding of the different authentication schemes as well as their vulnerabilities and deficits against various types of cyberattacks when applied in IoT-based systems. Based on the identified limitations, we recommend several mitigation strategies and discuss the practical implications of our findings. Milad Taleby Ahvanooey, Mark Xuefang Zhu, Qianmu Li, Wojciech Mazurczyk, Kim-Kwang Raymond Choo, Brij B. Gupta, Mauro Conti |
IEEE Internet Things J. | 4 |
| 2022 | CovertSYS: A systematic covert communication approach for providing secure end-to-end conversation via social networksabstractWhile encryption can prevent unauthorized access to a secret message , it does not provide undetectability of covert communications over the public network. Implementing a highly latent data exchange, especially with low eavesdropping/discovery probability, is challenging for practical scenarios, such as social and political movements in authoritarian regimes , military operations, and privacy preservation . Moreover, the current literature suffers from a low embedding capacity and monolingual applicability, limiting the amount of hiding secret data within short text messages using state-of-the-art algorithms, e.g., linguistic-based, structural-based, or coverless-based solutions. In this paper, we present a systematic covert communication technique called CovertSYS that enables a multilingual secure end-to-end conversation via messaging or social network platforms. The CovertSYS functions by encrypting a confidential message using a multi-factor authentication scheme and converting the encoded binary data into hidden Unicode symbols to be transmitted under cover of short text messages. We then conduct extensive experiments to confirm the security and validity of the proposed technique against state-of-the-art approaches. Our experimental results show that the CovertSYS provides a superior mean performance of 91.53% by improving the criteria scores: embedding capacity rate of 100%, imperceptibility rate of 76.4%, and distortion robustness rate of 98.2%. Finally, we discuss the practical implications of the proposed technique compared to the existing text steganography methods. Milad Taleby Ahvanooey, Mark Xuefang Zhu, Wojciech Mazurczyk, Qianmu Li, Max Kilger, Kim-Kwang Raymond Choo, Mauro Conti |
J. Inf. Secur. Appl. | 3 |
| 2022 | Steganalysis of adaptive multi-rate speech streams with distributed representations of codewords
Yiqin Qiu, Hui Tian 0002, Lili Tang, Wojciech Mazurczyk, Chin-Chen Chang 0001 |
J. Inf. Secur. Appl. | 4 |
| 2022 | Code Layering for the Detection of Network Covert Channels in Agentless SystemsabstractThe growing interest in agentless and serverless environments for the implementation of virtual/container network functions makes monitoring and inspection of network services challenging tasks. A major requirement concerns the agility of deploying security agents at runtime, especially to effectively address emerging and advanced attack patterns. This work investigates a framework leveraging the extended Berkeley Packet Filter to create ad-hoc security layers in virtualized architectures without the need of embedding additional agents. To prove the effectiveness of the approach, we focus on the detection of network covert channels, i.e., hidden/parasitic network conversations difficult to spot with legacy mechanisms. Experimental results demonstrate that different types of covert channels can be revealed with a good accuracy while using limited resources compared to existing cybersecurity tools (i.e., Zeek and libpcap). Marco Zuppelli, Matteo Repetto, Andreas Schaffhauser, Wojciech Mazurczyk, Luca Caviglione |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | DISSIMILAR: Towards fake news detection using information hiding, signal processing and machine learningabstractDigital media have changed the classical model of mass media that considers the transmitter of a message and a passive receiver, to a model where users of the digital media can appropriate the contents, recreate, and circulate them. In this context, online social media are a suitable circuit for the distribution of fake news and the spread of disinformation. Particularly, photo and video editing tools and recent advances in artificial intelligence allow non-professionals to easily counterfeit multimedia documents and create deep fakes. To avoid the spread of disinformation, some online social media deploy methods to filter fake content. Although this can be an effective method, its centralized approach gives an enormous power to the manager of these services. Considering the above, this paper outlines the main principles and research approach of the ongoing DISSIMILAR project, which is focused on the detection of fake news on social media platforms using information hiding techniques, in particular, digital watermarking, combined with machine learning approaches. David Megías 0001, Minoru Kuribayashi, Andrea Rosales, Wojciech Mazurczyk |
ARES | 4 |
| 2021 | Study of the Error Detection and Correction Scheme for Distributed Network Covert ChannelsabstractInformation hiding in communication networks is gaining recently increased attention from the security community. This is because such techniques are a double-edged sword that, on the one hand, can be used, e.g., to enhance the privacy of Internet users while on the other can be utilized by malware developers to enable a covert communication feature in malicious software. This means that to understand the risks that data hiding poses, it is of utmost importance to study the inner workings of potential information hiding methods and accompanying mechanisms (e.g., those that provide reliability of such communications) as well as to develop effective and efficient countermeasures. That is why, in this paper we perform a systematic experimental evaluation of the error detection and correcting scheme, which is suitable for complex network data hiding approaches, i.e., distributed network covert channels (DNCCs). The obtained results prove that the proposed solution guarantees secret communication reliability even when faced with severe networking conditions up to 20% of data corruption while maintaining a stable covert data rate. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 4 |
| 2021 | Data Hiding Using Code ObfuscationabstractDigital transformation of many companies and government administrations, now accelerated by the pandemic, provides cybercriminals an increased opportunity of incorporating various types of information hiding techniques into the malicious software and by that perform different types of attacks. By leveraging data hiding methods, attackers can, e.g., exfiltrate confidential information, enable covert transfers between the compromised victim’s machine and an attacker-operated infrastructure, or stealthily transmit additional malicious tools. Furthermore, in the digital era, any type of digital channel can be exploited for data hiding, e.g., digital images, video or audio content, text, or network traffic. That is why it is of great importance to be acquainted with the different techniques that cybercriminals can utilize to design and introduce effective countermeasures and identify/eliminate these threats when they appear. Obfuscation is a popular technique in the software development domain which makes the code illegible and which protects the implemented algorithms and business logic from unauthorized disclosure. In this paper, we investigate whether code obfuscation can be abused for information hiding purposes. The core idea of the proposed information hiding method is to replace some randomly generated strings being a part of the introduced dead code with the encoded secret message. The performed experimental evaluation and obtained results confirm that such process can be easily adopted for data hiding, thus countermeasures need to be adjusted accordingly. Pawel Rajba, Wojciech Mazurczyk |
ARES | 2 |
| 2021 | A Revised Taxonomy of Steganography Embedding PatternsabstractSteganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography. Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert |
ARES | 3 |
| 2021 | Do Dark Web and Cryptocurrencies Empower Cybercriminals?
Milad Taleby Ahvanooey, Mark Xuefang Zhu, Wojciech Mazurczyk, Max Kilger, Kim-Kwang Raymond Choo |
ICDF2C | 3 |
| 2021 | Adaptive Warden Strategy for Countering Network Covert Storage ChannelsabstractThe detection and elimination of covert channels are performed by a network node, known as a warden. Especially if faced with adaptive covert communication parties, a regular warden equipped with a static set of normalization rules is ineffective compared to a dynamic warden. However, dynamic wardens rely on periodically changing rule sets and have their own limitations, since they do not consider traffic specifics. We propose a novel adaptive warden strategy, capable of selecting active normalization rules by taking into account the characteristics of the observed network traffic. Our goal is to disturb the covert channel and provoke the covert peers to expose themselves more by increasing the number of packets required to perform a successful covert data transfer. Our evaluation revealed that the adaptive warden has better efficiency and effectiveness when compared to the dynamic warden because of its adaptive selection of normalization rules. Mehdi Chourib, Steffen Wendzel, Wojciech Mazurczyk |
LCN | 3 |
| 2021 | Code Augmentation for Detecting Covert Channels Targeting the IPv6 Flow LabelabstractInformation hiding is at the basis of a new-wave of malware able to elude common detection mechanisms or remain unnoticed for long periods. To this aim, a key approach exploits network covert channels, i.e., abusive communication paths nested within a legitimate traffic flow. The increasing diffusion of IPv6 makes it attractive for an attacker, especially for the presence of the Flow Label field, which can be manipulated to contain up to 20 secret bits per packet. Unfortunately, gathering data to implement a standalone detection mechanism or to support third-party security tools is a poorly generalizable process and often leads to scalability issues. This paper showcases how to take advantage of code augmentation features (i.e., the extended Berkeley Packet Filter) to detect covert channels targeting the IPv6 Flow Label. To prove its effectiveness, the proposed approach has been tested against Internet-wide traffic traces collected in the wild. Results indicate that it is possible to spot the channel while mitigating the memory footprint and the computational burden (e.g., the processed traffic only experience an additional delay of a few nanoseconds). Luca Caviglione, Marco Zuppelli, Wojciech Mazurczyk, Andreas Schaffhauser, Matteo Repetto |
NetSoft | 3 |
| 2021 | Inferring Flow Table State through Active Fingerprinting in SDN Environments: A Practical Approach
Marcin Gregorczyk, Wojciech Mazurczyk |
SECRYPT | 2 |
| 2021 | Kernel-level tracing for detecting stegomalware and covert channels in Linux environmentsabstractModern malware is becoming hard to spot since attackers are increasingly adopting new techniques to elude signature- and rule-based detection mechanisms. Among the others, steganography and information hiding can be used to bypass security frameworks searching for suspicious communications between processes or exfiltration attempts through covert channels. Since the array of potential carriers is very large (e.g., information can be hidden in hardware resources, various multimedia files or network flows), detecting this class of threats is a scarcely generalizable process and gathering multiple behavioral information is time-consuming, lacks scalability, and could lead to performance degradation. In this paper, we leverage the extended Berkeley Packet Filter (eBPF), which is a recent code augmentation feature provided by the Linux kernel, for programmatically tracing and monitoring the behavior of software processes in a very efficient way. To prove the flexibility of the approach, we investigate two realistic use cases implementing different attack mechanisms, i.e., two processes colluding via the alteration of the file system and hidden network communication attempts nested within IPv6 traffic flows. Our results show that even simple eBPF programs can provide useful data for the detection of anomalies, with a minimal overhead. Furthermore, the flexibility to develop and run such programs allows to extract relevant features that could be used for the creation of datasets for feeding security frameworks exploiting AI. Luca Caviglione, Wojciech Mazurczyk, Matteo Repetto, Andreas Schaffhauser, Marco Zuppelli |
Comput. Networks | 2 |
| 2021 | Comprehensive analysis of MQTT 5.0 susceptibility to network covert channelsabstractMessage Queuing Telemetry Transport (MQTT) is a publish-subscribe protocol which is currently popular in Internet of Things (IoT) applications. Recently its 5.0 version has been introduced and ensuring that it is capable of providing services in a secure manner is of great importance. It must be noted that holistic security analysis should also evaluate protocol’s susceptibility to network covert channels. That is why in this paper we present a systematic overview of potential data hiding techniques that can be applied to MQTT 5.0. We are especially focusing on network covert channels that, in order to exchange secrets, exploit characteristic features of this MQTT version. Finally, we develop proof-of-concept implementations of the chosen data hiding techniques and conduct their performance evaluation in order to assess their feasibility in practical setups. Aleksandra Mileva, Aleksandar Velinov, Laura Hartmann, Steffen Wendzel, Wojciech Mazurczyk |
Comput. Secur. | 5 |
| 2020 | Distributed packet inspection for network security purposes in software-defined networking environmentsabstract5G networks are foreseen to offer rich ubiquitous communication infrastructure with wide range of high-quality services. However, as they are formed using a mix of modern network technologies ensuring their security is crucial. Currently, Software Defined Networking is envisioned as a key technology to provide security in 5G. However, due to its centralized nature SDN-based systems may suffer from performance issues and are difficult to scale. That is why in this paper, we propose a novel distributed packet inspection method which is easy to scale, migrate and is able to utilize any existing SDN controller software. Instead of running a single instance of SDN controller process we propose to utilize multiple processes and to distribute the traffic in a fair manner across running instances. In result, such a load-balancing solution is able to run independently on multiple machines allowing for highly scalable solution. Performed experimental evaluation proves that such solution is efficient and effective. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Marcin Gregorczyk, Maciej Purski, Wojciech Mazurczyk |
ARES | 6 |
| 2020 | Network covert channels detection using data mining and hierarchical organisation of frequent sets: an initial studyabstractCurrently, malware developers are increasingly turning their attention towards various types of information hiding techniques to conceal their malicious actions on the compromised machine or the network. One group of such mechanisms are network covert channels (CCs) which utilize subtle modifications to the legitimate network traffic to carry secret data. Unfortunately, nowadays no general detection approach exists that is able to fight covert communication in an efficient and scalable manner. On the contrary, typically for a given information hiding technique a dedicated detection solution is devised. That is why, in this paper we investigate possibility to utilize data mining approach to detect network covert channels: both distributed and undistributed. Specifically, we propose to rely on the hierarchical organisation of frequent sets discovered by the data mining algorithm and use it together with an outlier detection-based traffic classifier. Initial performance results reveal that the proposed solution has potential but it needs to be further evaluated in more realistic scenarios. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 4 |
| 2020 | Exploiting minification for data hiding purposesabstractNowadays various types of data hiding techniques are used to conceal data in different types of digital content, e.g. image, video, audio, text, or even network traffic. Such methods can be utilized for nefarious purposes, for instance, for confidential data exfiltration, enabling secret communication between the infected host and attacker's server or to download additional modules of malware. From this perspective, analyzing different schemes of data hiding allows to assess the preparedness of the current defensive systems. Minification is the process of the source code manipulation while preserving its functionality. In result, the size of the source code is reduced making the transmission more efficient. In this paper we investigate whether minification of JavaScript files can be exploited for data hiding purposes. The obtained results prove that this is feasible and thus countermeasures must be adjusted to take into account such threats. Pawel Rajba, Wojciech Mazurczyk |
ARES | 2 |
| 2020 | Design and performance evaluation of reversible network covert channelsabstractCovert channels nested within network traffic are important tools for allowing malware to act unnoticed or to stealthily exchange and exfiltrate information. Thus, understanding how to detect or mitigate their utilization is of paramount importance, especially to counteract the rise of increasingly sophisticated threats. In this perspective, the literature proposed various approaches, including distributed wardens, which can be used to collect traffic in different portions of the network and compare the samples to check for discrepancies revealing hidden communications. However, the use of some form of reversibility, i.e., being able to restore the exploited network carrier to its original form before the injection, can challenge such a detection scheme. Therefore, in this work we introduce and evaluate the performances of different techniques used to endow network covert channels with reversibility. Results indicate the feasibility of achieving reversibility but the used protocol plays a major role. Przemyslaw Szary, Wojciech Mazurczyk, Steffen Wendzel, Luca Caviglione |
ARES | 2 |
| 2020 | Special issue on Advancements in 5G Networks Security
Wojciech Mazurczyk, Pascal Bisson, Roger Piqueras Jover, Koji Nakao, Krzysztof Cabaj |
Future Gener. Comput. Syst. | 1 |
| 2020 | VoIP network covert channels to enhance privacy and information sharingabstractInformation hiding is increasingly used to implement covert channels, to exfiltrate data or to perform attacks in a stealthy manner. Another important usage deals with privacy, for instance, to bypass limitations imposed by a regime, to prevent censorship or to share information in sensitive scenarios such as those dealing with cyber defense. In this perspective, the paper investigates how VoIP communications can be used as a methodology to enhance privacy. Specifically, we propose to hide traffic into VoIP conversations in order to prevent the disclosure, exposure and revelation to an attacker or blocking the ongoing exchange of information. To this aim, we exploit the voice activity detection feature available in many client interfaces to produce fake silence packets, which can be used as the carrier where to hide data. Results indicate that the proposed approach can be suitable to enforce the privacy in real use cases, especially for file transfers. As interactive services (e.g., web browsing) may experience too many delays due to the limited bandwidth, some form of optimization or content scaling may be advisable for such scenarios. Jens Saenger, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione |
Future Gener. Comput. Syst. | 2 |
| 2020 | Characterizing Anomalies in Malware-Generated HTTP TrafficabstractCurrently, we are witnessing a significant rise in various types of malware, which has an impact not only on companies, institutions, and individuals, but also on entire countries and societies. Malicious software developers try to devise increasingly sophisticated ways to perform nefarious actions. In consequence, the security community is under pressure to develop more effective defensive solutions and to continuously improve them. To accomplish this, the defenders must understand and be able to recognize the threat when it appears. That is why, in this paper, a large dataset of recent real-life malware samples was used to identify anomalies in the HTTP traffic produced by the malicious software. The authors analyzed malware-generated HTTP requests, as well as benign traffic of the popular web browsers, using 3 groups of features related to the structure of requests, header field values, and payload characteristics. It was observed that certain attributes of the HTTP traffic can serve as an indicator of malicious actions, including lack of some popular HTTP headers and their values or usage of the protocol features in an uncommon way. The findings of this paper can be conveniently incorporated into the existing detection systems and network traffic forensic tools, making it easier to spot and eliminate potential threats. Piotr Bialczak, Wojciech Mazurczyk |
Secur. Commun. Networks | 2 |
| 2020 | Secure Data Encryption Based on Quantum Walks for 5G Internet of Things ScenarioabstractFifth generation (5G) networks are the base communication technology for connecting objects in the Internet of Things (IoT) environment. 5G is being developed to provide extremely large capacity, robust integrity, high bandwidth, and low latency. With the development and innovating new techniques for 5G-IoT, it surely will drive to new enormous security and privacy challenges. Consequently, secure techniques for data transmissions will be needed as the basis for 5G-IoT technology to address these arising challenges. Therefore, various traditional security mechanisms are provided for 5G-IoT technologies and most of them are built on mathematical foundations. With the growth of quantum technologies, traditional cryptographic techniques may be compromised due to their mathematical computation based construction. Quantum walks (QWs) is a universal quantum computational model, which possesses inherent cryptographic features that can be utilized to build efficient cryptographic mechanisms. In this paper, we use the features of quantum walk to construct a new S-box method which plays a significant role in block cipher techniques for 5G-IoT technologies. As an application of the presented S-box mechanism and controlled alternate quantum walks (CAQWs) for 5G-IoT technologies a new robust video encryption mechanism is proposed. As well as to fulfill needs of encryption for varied files in 5G-IoT, we utilize the features of quantum walk to propose a novel encryption strategy for secure transmission of sensitive files in 5G-IoT paradigm. The analyses and results of the proposed cryptosystems show that it has better security properties and efficacy in terms of cryptographic performance. Ahmed A. Abd El-Latif 0001, Bassem Abd-El-Atty, Wojciech Mazurczyk, Carol J. Fung, Salvador Elías Venegas-Andraca |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | Sniffing Detection within the Network: Revisiting Existing and Proposing Novel ApproachesabstractSniffing is a crucial part of the network attack where an intruder tries to gather as much information as possible on the devices, protocols and applications residing within the targeted network in order to discover their vulnerabilities. It is typically performed using dedicated software called sniffers and it is based on passively analyzing the traffic exchanged within the network. Due to its passive nature such malicious actions are quite hard to be discovered. That is why, in this paper we first revisit existing approaches and tools known from the state-of-the-art. Then we introduce a novel detection method which is able to identify suspicious machine using specially crafted network traffic and based on its reaction is able to infer whether sniffer is running or not. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 3 |
| 2019 | Fine-tuning of Distributed Network Covert Channels Parameters and Their Impact on UndetectabilityabstractCurrently the usage of various information hiding techniques for nefarious purposes becomes a major issue. Especially when the attackers, in order to stay under the radar, utilize increasingly sophisticated ways to conceal data. One of such advanced techniques is the use of distributed network covert channels (DNCC) where the secrets are spread among a number of available covert channels and transmitted in parallel. Taking above into consideration, in this paper we investigate how the data hiding techniques forming a DNCC can be configured to achieve an improved undetectability and how this impacts the DNCC performance and its detection susceptibility. Based on the presented results it can be concluded that if the utilized steganographic techniques forming a DNCC are used in a balanced manner then this may pose difficulties from the detection perspective although this typically also means significant limitation of the overall secret data rate. Krzysztof Cabaj, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 2 |
| 2019 | Towards Reversible Storage Network Covert ChannelsabstractThe use of network covert channels to improve privacy or support security threats has been widely discussed in the literature. As today, the totality of works mainly focuses on how to not disrupt the overt traffic flow and the performance of the covert channels in terms of undetectability and capacity. To not void the stealthiness of the channel, an important feature is the ability of restoring the carrier embedding the secret information into its original form. However, the development of such techniques mainly targets the domain of digital media steganography. Therefore, this paper applies the concept of reversible data hiding to storage network covert channels. To prove the effectiveness of our idea, a prototypical implementation of a channel exploiting IPv4 flows is presented along with its performance evaluation. Wojciech Mazurczyk, Przemyslaw Szary, Steffen Wendzel, Luca Caviglione |
ARES | 1 |
| 2019 | Introducing Dead Drops to Network Steganography using ARP-Caches and SNMP-WalksabstractNetwork covert channels enable various secret data exchange scenarios among two or more secret parties via a communication network. The diversity of the existing network covert channel techniques has rapidly increased due to research during the last couple of years and most of them share the same characteristics, i.e., they require a direct communication between the participating partners. However, it is sometimes simply not possible or it can raise suspicions to communicate directly. That is why, in this paper we introduce a new concept we call "dead drop", i.e., a covert network storage which does not depend on the direct network traffic exchange between covert communication sides. Instead, the covert sender stores secret information in the ARP (Address Resolution Protocol) cache of an unaware host that is not involved in the hidden data exchange. Thus, the ARP cache is used as a covert network storage and the accumulated information can then be extracted by the covert receiver using SNMP (Simple Network Management Protocol). Tobias Schmidbauer, Steffen Wendzel, Aleksandra Mileva, Wojciech Mazurczyk |
ARES | 4 |
| 2019 | Teaching Android Mobile SecurityabstractAt present, computer science studies generally offer courses addressing mobile development and they use mobile technologies for illustrating theoretical concepts such as operating system, design patterns, and compilation because Android and iOS use a large variety of technologies for developing applications. Teaching courses on security is also becoming an important concern for academics, and the use of mobile platforms (such as Android) as supporting material is becoming a reasonable option. In this paper, we intend to bridge a gap in the literature by reversing this paradigm: Android is not only an opportunity to learn security concepts but requires strong pedagogical efforts for covering all the aspects of mobile security. Thus, we propose teaching Android mobile security through a two-dimensional approach. The first dimension addresses the cognitive process of the Bloom taxonomy, and the second dimension addresses the technical layers of the architecture of the Android operating system. We describe a set of comprehensive security laboratory courses covering various concepts, ranging from the application development perspective to a deep investigation of the Android Open Source Project and its interaction with the Linux kernel. We evaluated this approach, and our results verify that the designed security labs impart the required knowledge to the students. Jean-François Lalande, Valérie Viet Triem Tong, Pierre Graux, Guillaume Hiet, Wojciech Mazurczyk, Habiba Chaoui, Pascal Berthomé |
SIGCSE | 5 |
| 2019 | (In)Secure Android Debugging: Security analysis and lessons learned
Krzysztof Opasiak, Wojciech Mazurczyk |
Comput. Secur. | 2 |
| 2019 | Efficient quantum-based security protocols for information sharing and data protection in 5G networks
Ahmed A. Abd El-Latif 0001, Bassem Abd-El-Atty, Salvador Elías Venegas-Andraca, Wojciech Mazurczyk |
Future Gener. Comput. Syst. | 4 |
| 2019 | Countering adaptive network covert communication with dynamic wardens
Wojciech Mazurczyk, Steffen Wendzel, Mehdi Chourib, Jörg Keller 0001 |
Future Gener. Comput. Syst. | 1 |
| 2019 | Network Threats Mitigation Using Software-Defined Networking for the 5G Internet of Radio Light SystemabstractCurrently 5G communication networks are envisioned to offer in a near future a wide range of high-quality services and unfaltering user experiences. In order to achieve this, several issues including security, privacy, and trust aspects need to be solved so that the 5G networks can be widely welcomed and accepted. Considering above, in this paper, we take a step towards these requirements by proposing a dedicated SDN-based integrated security framework for the Internet of Radio Light (IoRL) system that is following 5G architecture design. In particular, we present how TCP SYN-based scanning activities and DHCP-related network threats like Denial of Service (DoS), traffic eavesdropping, etc. can be detected and mitigated using such an approach. Enclosed experimental results prove that the proposed security framework is effective and efficient and thus can be considered as a promising defensive solution. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
Secur. Commun. Networks | 3 |
| 2019 | Guest Editorial: Recent Advances in Cyber-Physical Security in Industrial Environmentsabstract“Smart” has gradually infiltrating all areas of people's daily life and the environments where we lead our life. The term of “Smart Industrial Environment” can be used to refer to each aspect of the industrial environments focused on the future, being smart vehicles, smart systems of transportation, smart devices (wearables and smartphones), smart services (such as just-in-time production pipelines adjusted to the requirements of the supply-chain), smart grids, smart factories and smart plants management utilizing information technology. It includes the inter-connection of all the smart technologies, involving every type of political and technological borders besides being a term that involves all the aspects. Zhihan Lyu, Wojciech Mazurczyk, Steffen Wendzel, Houbing Song |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | SDN-based Mitigation of Scanning Attacks for the 5G Internet of Radio Light SystemabstractCurrently 5G communication networks are gaining on importance among industry, academia, and governments worldwide as they are envisioned to offer wide range of high-quality services and unfaltering user experiences. However, certain security, privacy and trust challenges need to be addressed in order for the 5G networks to be widely welcomed and accepted. That is why in this paper, we take a step towards these requirements and we introduce a dedicated SDN-based integrated security framework for the Internet of Radio Light (IoRL) system that is following 5G architecture design. In particular, we present how TCP SYN-based scanning activities which typically comprise the first phase of the attack chain can be detected and mitigated using such an approach. Enclosed experimental results prove that the proposed security framework has potential to become an effective defensive solution. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 3 |
| 2018 | Towards Distributed Network Covert Channels Detection Using Data Mining-based ApproachabstractCurrently, due to improvements in defensive systems network covert channels are increasingly drawing attention of cybercriminals and malware developers as they can provide stealthiness of the malicious communication and thus to bypass existing security solutions. On the other hand, the utilized data hiding methods are getting increasingly sophisticated as the attackers, in order to stay under the radar, distribute the covert data among many connections, protocols, etc. That is why, the detection of such threats becomes a pressing issue. In this paper we make an initial step in this direction by presenting a data mining-based detection of such advanced threats which relies on pattern discovery technique. The obtained, initial experimental results indicate that such solution has potential and should be further investigated. Krzysztof Cabaj, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 2 |
| 2018 | Towards Utilization of Covert Channels as a Green Networking TechniqueabstractNetwork covert channels are currently typically seen as a security threat which can result in e.g. confidential data leakage or in a hidden data exchange between malicious parties. However, in this paper we want to investigate network covert channels from a less obvious angle i.e. we want to verify whether it is possible to use them as a green networking technique. Our observation is that usually covert channels utilize various redundant "resources" in network protocols e.g. unused/reserved fields that would have been transmitted anyway. Therefore, using such "resources" for legitimate transmissions can increase the total available bandwidth without sending more packets and thus offering potential energy savings. However, it must be noted that embedding and extracting processes related to data hiding consumes energy, too. That is why, in this paper we try to establish whether the potentially saved energy due to covert channels utilization exceeds the effort needed to establish and maintain covert data transmission. For this purpose, a proof-of-concept implementation has been created to experimentally measure the impact of network covert channels on resulting energy consumption. The obtained results show that the approach can be useful mostly under specific circumstances, i.e., when the total energy consumption of the network devices is already relatively high. Furthermore, the impact of different types of network covert channels on the energy consumption is examined to assess their usefulness from the green networking perspective. Daniel Geisler, Wojciech Mazurczyk, Jörg Keller 0001 |
ARES | 2 |
| 2018 | Towards Deriving Insights into Data Hiding Methods Using Pattern-based ApproachabstractIn network information hiding, hiding patterns are used to describe hiding methods and their taxonomy. In this paper, we analyze the current state of hiding patterns and we further improve their taxonomy. In order to more thoroughly characterize and understand data hiding methods applied to communication networks we propose to distinguish between sender-side and receiver-side patterns. Additionally, we show how information hiding patterns can be utilized to conveniently describe the realization of the distributed network covert channels. Wojciech Mazurczyk, Steffen Wendzel, Krzysztof Cabaj |
ARES | 1 |
| 2018 | A review of network vulnerabilities scanning tools: types, capabilities and functioningabstractThe rapid growth of the Internet in the last years has brought many advantages in the modern society in terms of communication and information sharing. Beside that, new and complex issues are emerging due to the network flexibility, openness and systems integration. The vulnerabilities of systems are the basis of these issues. Unfortunately, such vulnerabilities in the Internet can affect not only virtual environments in an isolated way but this can have serious repercussions in the real world. That is why, identifying new system vulnerability represents an important information for malicious parties. Currently, several tools (e.g. Shodan or Censys), which automatically scan the Internet, are available. They first scan the whole IPv4 public address range and ports in a distributed and random manner and then the obtained results are published on the publicly accessible websites. Such information can be later used for the benign or malicious purposes. In the latter case the main advantage for the potential attackers is that they gain reconnaissance data without even directly contacting the targeted device. Additionally, a large list of potential victims sharing the same vulnerability can be rapidly acquired. In this context, this paper aims at providing an overview of various publicly available network vulnerabilities scanning tools. In particular, first the main scanning tools are identified and classified. Then their main features are described and finally their advantages and disadvantages are highlighted. Andrea Tundis, Wojciech Mazurczyk, Max Mühlhäuser |
ARES | 2 |
| 2018 | Exploiting IP telephony with silence suppression for hidden data transfers
Sabine S. Schmidt, Wojciech Mazurczyk, Radoslaw Kulesza, Jörg Keller 0001, Luca Caviglione |
Comput. Secur. | 2 |
| 2018 | Cybersecurity: trends, issues, and challenges
Krzysztof Cabaj, Zbigniew Kotulski, Bogdan Ksiezopolski, Wojciech Mazurczyk |
EURASIP J. Inf. Secur. | 4 |
| 2018 | Emerging and Unconventional: New Attacks and Innovative Detection TechniquesabstractArt. 9672523, 1 S. Luca Caviglione, Wojciech Mazurczyk, Steffen Wendzel, Sebastian Zander |
Secur. Commun. Networks | 2 |
| 2017 | A New Data-Hiding Approach for IP Telephony Applications with Silence SuppressionabstractEven if information hiding can be used for licit purposes, it is increasingly exploited by malware to exfiltrate data or to coordinate attacks in a stealthy manner. Therefore, investigating new methods for creating covert channels is fundamental to completely assess the security of the Internet. Since the popularity of the carrier plays a major role, this paper proposes to hide data within VoIP traffic. Specifically, we exploit Voice Activity Detection (VAD), which suspends the transmission during speech pauses to reduce bandwidth requirements. To create the covert channel, our method transforms a VAD-activated VoIP stream into a non-VAD one. Then, hidden information is injected into fake RTP packets generated during silence intervals. Results indicate that steganographically modified VAD-activated VoIP streams offer a good trade-off between stealthiness and steganographic bandwidth. Sabine S. Schmidt, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione |
ARES | 2 |
| 2017 | Inter-Protocol Steganography for Real-Time Services and Its Detection Using Traffic Coloring ApproachabstractDue to improvements in defensive systems, network threats are becoming increasingly sophisticated and complex as cybercriminals are using various methods to cloak their actions. This, among others, includes the application of network steganography e.g. to hide the communication between an infected host and a malicious control server by embedding commands into innocent-looking traffic. Currently, a new subtype of such methods called inter-protocol steganography emerged. It utilizes relationships between two or more overt protocols to hide data. In this paper, we present new inter-protocol hiding techniques which are suitable for real-time services. Afterwards, we introduce and present preliminary results of a novel steganography detection approach which relies on network traffic coloring. Florian Lehner, Wojciech Mazurczyk, Jörg Keller 0001, Steffen Wendzel |
LCN | 2 |
| 2017 | Covert Channels in Personal Cloud Storage Services: The Case of DropboxabstractPersonal storage services are one of the most popular applications based on the cloud computing paradigm. Therefore, the analysis of possible privacy and security issues has been a relevant part of the research agenda. However, threats arising from the adoption of information hiding techniques have been mainly neglected. In this perspective, the paper investigates how personal cloud storage services can be used for building covert channels for stealthy exchange of information through the Internet. To have a realistic use case, we consider the Dropbox application and we present the performance evaluation of two different covert communication methods. To understand the stealthiness of our approach and propose countermeasures, we also investigate some behaviors of Dropbox in a production quality deployment. Luca Caviglione, Maciej Podolski, Wojciech Mazurczyk, Massimo Ianigro |
IEEE Trans. Ind. Informatics | 3 |
| 2016 | POSTER: An Educational Network Protocol for Covert Channel Analysis Using PatternsabstractThe utilization of information hiding is on the rise among cybercriminals, e.g. to cloak the communication of malicious software as well as by ordinary users for privacy-enhancing purposes. A recent trend is to use network traffic in form of covert channels to convey secrets. In result, security expert training is incomplete if these aspects are not covered. This paper fills this gap by providing a method for teaching covert channel analysis of network protocols. We define a sample protocol called Covert Channel Educational Analysis Protocol (CCEAP) that can be used in didactic environments. Compared to previous works we lower the barrier for understanding network covert channels by eliminating the requirement for students to understand several network protocols in advance and by focusing on so-called hiding patterns. Steffen Wendzel, Wojciech Mazurczyk |
CCS | 2 |
| 2016 | YouSkyde: information hiding for Skype video trafficabstractIn this paper a new information hiding method for Skype videoconference calls – YouSkyde – is introduced. A Skype traffic analysis revealed that introducing intentional losses into the Skype video traffic stream to provide the means for clandestine communication is the most favourable solution. A YouSkyde proof-of-concept implementation was carried out and its experimental evaluation is presented. The results obtained prove that the proposed method is feasible and offer a steganographic bandwidth as high as 0.93 kbps, while introducing negligible distortions into transmission quality and providing high undetectability. Wojciech Mazurczyk, Maciej Karas, Krzysztof Szczypiorski, Artur Janicki |
Multim. Tools Appl. | 1 |
| 2016 | Cyber CrimeabstractToday's world's societies are becoming more and more dependent on open networks such as the Internet – where commercial activities, business transactions, and government services are realized. This has led to the fast development of new cyber threats and numerous information security issues which are exploited by cyber criminals. The inability to provide trusted secure services in contemporary computer network technologies has a tremendous socio-economic impact on global enterprises as well as individuals. Moreover, the frequently occurring international frauds impose the necessity to conduct the investigation of facts spanning across multiple international borders. Such examination is often subject to different jurisdictions and legal systems. A good illustration of the previously mentioned is the Internet, which has made it easier to perpetrate traditional crimes. It has acted as an alternate avenue for the criminals to conduct their activities, and launch attacks with relative anonymity. The increased complexity of the communications and the networking infrastructure is making investigation of the crimes difficult. Traces of illegal digital activities are often buried in large volumes of data, which are hard to inspect with the aim of detecting offenses and collecting evidence. Nowadays, the digital crime scene functions like any other network, with dedicated administrators functioning as the first responders. This poses new challenges for law enforcement policies and forces the computer societies to utilize digital forensics to combat the increasing number of cybercrimes. Forensic professionals must be fully prepared in order to be able to provide court admissible evidence. To make these goals achievable, forensic techniques should keep pace with new technologies. In this special issue, we are delighted to present a selection of 14 papers, which, in our opinion, will contribute to the enhancement of knowledge in cyber crime. The collection of high-quality research papers provides a view on the latest research advances and results in the field of digital forensics and to present the development of tools and techniques which assist the investigation process of potentially illegal cyber activity. In the first paper, Cyberterrorism targeting the general public through social media, Nicholas Ayres and Leandros A. Maglaras investigate whether a mimetic malware could be a viable method of attack against a population with respect to cyberterrorism. The presented research shows that although people are, in general, aware of cyberterrorism on their current level of fear of being a potential target of attack is relatively low. However, when presented with such a threat, their level of fear increased. The obtained results prove that a targeted mimetic virus can indeed have an effect on a population and is a potential attack method for cyberterrorism. The paper emphasizes also the importance of social media as a vessel of propagation of such threat. Next, in the paper entitled Effectiveness of File-Based Deduplication in Digital Forensics Sebastian Neuner, Martin Schmiedecker, and Edgar Weippl focus on introducing improvements to the standardized forensic process to reduce the amount of storage requirement for forensic investigations by using file whitelisting and cross-device deduplication. Authors approach is shown to be particularly useful in cases where investigation relies on referenced files in the file system. In the exemplary use case authors prove that file deduplication and file whitelisting can be successfully utilized to achieve 78% size reduction compared to the full data set which means saving about 700 gigabytes of storage capacity. Jawwad Shamsi, Sherali Zeadally, Fareha Sheikh, and Angelyn Flowers in Attribution in Cyberspace: Techniques and Legal Implications argue that only a few known cybercrimes have been successfully attributed to the actual attacker. To improve this situation authors propose three-level attribution framework to indicate various attributes and guidelines through which attribution can be instigated. The proposed framework is an initial step and in order to be successful it requires strong cooperation between different stake holders, government sponsored active cyber unit, existence of cyber laws, and cooperation among international community members. Next, two papers are focused on anomaly detection. In Evolutionary-based Packets Classification for Anomaly Detection in Web Layer, Rafał Kozik, Michał Choraś, and Witold Hołubowicz propose a novel detection method for modern web applications. First, authors observe that the majority of the state of the art solutions make an assumption about the packets' content, or how the data inside the payload is serialized. Then they propose an evolutionary-based approach to unsupervised and automated packets segmentation. On the top of their approach, authors apply several variants of machine-learned classifiers and statistics to prove that the proposed algorithm can improve the effectiveness of many well-known anomaly detection methods. In the second paper entitled DWT-based Anomaly Detection Method for Cyber Security of Wireless Sensor Networks Łukasz Saganowski, Tomasz Andrysiak, Rafał Kozik, and Michał Choraś introduce a discrete wavelet transformation-based anomaly detection approach for wireless sensor networks which is especially suited for deployment in critical infrastructures for measuring and/or monitoring purposes. The main authors' contribution is that the proposed anomaly detection is integrated with an effective SNORT-based pre-processor. Then DWT-based solution is applied to 25 network traffic parameters measured in a realistic testbed and most suitable parameters are indicated. It is worth noting that several papers from this special issue are devoted to information hiding techniques, which utilization is currently a raising trend among cybercriminals. Papers focus on both: proposing new methods and detection approaches. In the first paper entitled Pitch-based steganography for Speex voice codec, Artur Janicki devises an improved version of the HideF0 steganographic algorithm which is especially suitable for IP telephony. The proposed approach relies on approximation of the pitch-related parameter (F0) in speech signal regions where the pitch is monotonic enough to be linearly approximated with a low error. It also utilizes unused fields in the headers of the voice packets. Experiments conducted on all narrowband Speex codec modes show that an improvement in quality when compared with the originally proposed algorithm has been observed. The resulting steganographic bandwidths of HideF0 turns out to be around 200 bps at the expense of a steganographic cost of between 0.5 and 0.7 MOS, depending on the Speex mode. Hui Tian, Yanpeng Wu, Chin-Chen Chang, Yongfeng Huang, Jin Liu, Tian Wang, Yonghong Chen, and Yiqiao Cai in Steganalysis of Analysis-by-synthesis Speech Exploiting Pulse-position Distribution Characteristics introduce a Support Vector Machine-based detection of low bit-rate speech which utilizes statistic characteristics of pulse positions, that is, the probability distribution of pulse positions as a long-time distribution feature, Markov transition probabilities of pulse positions according to the short-time invariance characteristic of speech signals, and finally joint probability matrices characterizing the pulse-to-pulse correlation. The proposed steganalysis method is evaluated for the G.729a speech codec and compared with the state-of-the-art methods. Obtained experimental results reveal that the proposed method's detection performance is superior when compared with the previous steganalysis algorithms. The paper, Color Images Stegananalysis Using RGB Channel Geometric Transformation Measures by Hasan Abdulrahman, Marc Chaumont, Philippe Montesinos, and Baptiste Magnier, introduces steganalysis method for color images that is based on color feature correlation and machine learning classification. This approach relies on fusing features with those obtained from color-rich models which results in improved detectability of hidden messages. Authors use two types of features, computed between color image channels – first that reflects local Euclidean transformations and second that reflects mirror transformations. They also demonstrate the efficiency of the proposed detection method on three state-of-the-art steganography algorithms. The paper, A framework of adaptive steganography resisting JPEG compression and detection by Yi Zhang, Xiangyang Luo, Chunfang Yang, Dengpan Ye, and Fenlin Liu, describes a framework of adaptive steganography resisting JPEG compression and detection which aims at solving the issue of information loss in the process of image compression while applying image steganography to mobile intelligent terminals. The proposed framework uses the relationship between discrete cosine transform coefficients to determine the domain of messages embedding. Based on this framework, authors devise an adaptive steganography algorithm and perform its evaluation. Obtained experimental results for different payloads and quality factors of JPEG compression prove that when an algorithm is based on the framework, it has both a strong JPEG compression resistant ability and detection resistant performance. In the next paper, Micro protocol engineering for unstructured carriers: On the embedding of steganographic control protocols into audio transmissions, Matthias Naumann, Steffen Wendzel, Wojciech Mazurczyk, and Jörg Keller present techniques to embed micro protocol, that is, covert channel control protocol into an unstructured carrier which is audio streaming over the network. Two types of implementing the micro protocol: static and dynamic have been demonstrated. This allowed comparing the resulting performance and to measure the impact of both designs on the overt audio signal. On the basis of obtained experimental results, a micro protocol engineering approach for unstructured carriers has been devised. Another paper that is focused on analysis of micro protocols has been authored by Jaspreet Kaur, Steffen Wendzel, Omar Eissa, Jernej Tonejc, and Michael Meier. In Covert Channel-internal Control Protocols: Attacks and Defense, an interesting analysis of micro protocols has been conducted. First authors demonstrate that some potential attacks scenarios on micro protocols exist, and that if successful, they are able to break even sophisticated covert communication. The described attacks are based on the attacker's intentional interaction with the micro protocol specifics. Then, authors propose several defense techniques to make micro protocols immune against such threats. In Perfect undetectability of network steganography, Wojciech Frączek and Krzysztof Szczypiorski introduce StegBlocks that is a general approach for constructing network steganography techniques which defines the way in which the methods work, and at the same time it allows for the creation of methods for various carriers (network protocols). The paper encloses also the definition of perfectly undetectable network steganography which is derived from a classic steganography definition, and it covers the specific features of network steganography. Using this definition, authors argue that it is possible to create a network steganography method that is undetectable for the adversary with unlimited computational power. In the next article, DAT Detectors – Uncovering TCP/IP Covert Channels by Descriptive Analytics, Felix Iglesias, Robert Annessi, and Tanja Zseby propose descriptive analytics of traffic (DAT) detectors that utilize descriptive analytics for the detection of covert channels in TCP/IP communication networks. DAT detectors are envisioned to be an extension for network intrusion detection system and are aimed to perform fast and lightweight analysis of numerous flows. They transform communication data into flexible feature vectors that represent traffic as a set of extracted calculations and estimations. The detection approach relies mostly on the combined application of autocorrelation calculations and multimodality measures built upon kernel density estimations and Pareto charts. In the last of the presented articles, An assessment of automatic speaker verification vulnerabilities to replay spoofing attacks, Artur Janicki, Federico Alegre, and Nicholas Evans compare at a high level the threat of replay attacks to those of speech synthesis and voice conversion. This comparison is performed using strictly controlled protocols and with six different Automatic Speaker Verification systems. Presented experimental results prove that low-effort replay attacks are indeed a threat to speech synthesis and voice conversion. Basing on these findings, authors also introduce and assess two replay attack countermeasures: the local binary pattern analysis of speech spectrograms and an approach based on the detection of far-fields recordings. To summarize, we believe that this Special Issue will contribute to enhancing knowledge in Information and Communication Technology security and in Cyber Crime in particular. In addition, we also hope that the presented results will stimulate further research in the important areas of information and network security. We also want to thank the Editors-in-Chief of the Security and Communication Networks journal, the researchers contributing to the special issue, and excellent reviewers for their great help and support that made this special issue possible. Wojciech Mazurczyk, Krzysztof Szczypiorski, Zoran Duric, Dengpan Ye |
Secur. Commun. Networks | 1 |
| 2016 | Trends in modern information hiding: techniques, applications, and detectionabstractAs the production, storage, and exchange of information become more extensive and important in the functioning of societies, the problem of protecting the information from unintended and undesired usage becomes more complex. In modern societies, protection of information involves many interdependent technological and policy issues related to information confidentiality, integrity, anonymity, authenticity, utility, etc. Information hiding techniques are receiving much attention today. Digital audio, video, and images are increasingly furnished with distinguishing but imperceptible marks, which may contain a hidden copyright notice or serial number or even help to prevent unauthorized copying directly. Digital watermarking and steganography may protect information, conceal secrets, or are used as core primitives in digital rights' management schemes. Alongside the previously mentioned types of digital media steganography, currently, the target of increased interest is network steganography—a part of information hiding focused on modern networks. It is a method of hiding secret data in users' normal data transmissions. Steganographic techniques arise and evolve with the development of network protocols and mechanisms and are expected to be used in secret communication or information sharing. Presently, it becomes a hot topic because of the proliferation of information networks and multimedia services in networks and social networks. The purpose of establishing applications of Information Hiding may be varied—possible uses can fall into the category of legal actions or illicit activity. Frequently, the illegal aspect is accentuated—starting from the criminal communication, through information leakage from protected systems, cyber weapon exchange, up to industrial espionage. Recently discovered malware like Hammertoss or Stegoloader utilize various information hiding techniques for botnets purposes to enable covert communication for the C and C (Command and Control) channel. This makes detection of such malware even more difficult, and it poses a serious challenge also to investigators. On the other side of the spectrum lies legitimate uses, which include circumvention of web censorship and surveillance, computer forensics (tracing and identification), and copyright protection (e.g., watermarking images). In this special issue, we are delighted to present a selection of nine papers, which, in our opinion, will contribute to the enhancement of knowledge in information hiding. The collection of high-quality research papers provides a view on the latest research advances on covert communication, steganography, and steganalysis. In the first paper, Multi-bit watermarking of high dynamic range images based on perceptual models, Emanuele Maiorana and Patrizio Campisi describe a multi-bit watermarking method dedicated to high dynamic range images. The proposed method takes advantage of various perceptual features of the human eye. The authors present the results of imperceptibility and robustness tests, using a database of 15 high dynamic range images. Also two next articles concern image processing. In MDE-based image steganography with large embedding capacity, Zhaoxia Yin and Bin Luo propose a steganographic method based on modification of direction exploitation and pixel pair matching. The algorithm is explained in detail, and a numerical example is given. The authors analyze also the quality of the conveyed covert image and evaluate security of the proposed algorithm, using two steganalysis methods. Fengyong Li, Xinpeng Zhang, Hang Cheng, and Jiang Yu in Digital image steganalysis based on local textural features and double dimensionality reduction also deal with steganalysis of image steganography. They propose a spatial steganalysis scheme based on local textural features and double dimensionality reduction. The authors demonstrate effectiveness of their method using 5000 greyscale images and three different steganographic techniques. Next three articles concern using audio signals for steganographic transmission. In the first of them, Real-time audio steganography attack based on automatic objective quality feedback, Qilin Qi, Aaron Sharp, Dongming Peng, and Hamid Sharif propose an active warden steganographic attack based on discrete spring transform with the use of an objective quality assessment. The authors show effectiveness of such an attack against two different steganographic techniques—spread spectrum-based and a time-scale modification-robust steganography. Shanyu Tang, Qing Chen, Wei Zhang, and Yongfeng Huang in Universal steganography model for low bit-rate speech codec describe a universal steganography model for low bit-rate speech codec. The proposed method is based on using perceptual evaluation of speech quality algorithm to choose a proper data hiding algorithm. The authors employ proposed approach for the Internet Speech Audio Codec and present results for the steganographic bandwidth and cost. Rennie Archibald and Dipak Ghosal in Design and performance evaluation of a covert timing channel discuss covert timing channels, in which the steganographic transmission is realized by modulating the inter-packet delay times. The authors propose a method, which minimizes overruns and underruns of an Internet Protocol phone buffer, and then evaluate its performance using Skype traffic. Pawel Laka and Lukasz Maksymiuk in Steganographic transmission in optical networks with the use of direct spread spectrum technique describe their method of steganographic transmission to be used in the physical layer of optical networks. The proposed method is based on the spread spectrum technique. The authors show results of their experiments with adjusting the spreading code length and optical power level dependencies. In the next article, On importance of steganographic cost for network steganography, an analysis of steganographic cost for network steganography is presented by Wojciech Mazurczyk, Steffen Wendzel, Ignacio Azagra Villares, and Krzysztof Szczypiorski. In this paper, the metric of steganographic cost is defined as degradation or a distortion of the carrier caused by the application of the steganographic method. The authors analyze various approaches to steganographic cost in selected single-method and multi-method steganographic techniques. In the last of the presented articles, Matrix embedding in multicast steganography: analysis in privacy, security and immediacy, Weiwei Liu, Guangjie Liu, and Yuewei Dai discuss multicast steganography, in which a single sender delivers simultaneously different secret messages to several receivers within the same cover object. The authors propose both synchronous and asynchronous multicast matrix embedding frameworks, based on Slepian–Wolf coding and overlapped multi-embedding, respectively. Privacy, security, and immediacy of the proposed solutions are also discussed. To summarize, we believe that this Special Issue will contribute to enhancing knowledge in Information and Communication Technology (ICT) security and in information hiding in particular. In addition, we also hope that the presented results will stimulate further research in the important areas of information and network security, including steganography and covert communication. We also want to thank the editor-in-chief of the Security and Communication Networks journal, the leading researchers contributing to the special issue and excellent reviewers for their great help and support that made this special issue possible. Wojciech Mazurczyk, Krzysztof Szczypiorski, Artur Janicki, Hui Tian 0002 |
Secur. Commun. Networks | 1 |
| 2016 | On importance of steganographic cost for network steganographyabstractNetwork steganography encompasses the information hiding techniques that can be applied in communication network environments and that utilize hidden data carriers for this purpose. In this paper we introduce a characteristic called steganographic cost which is an indicator for the degradation or distortion of the carrier caused by the application of the steganographic method. Based on exemplary cases for single- and multi-method steganographic cost analyses we observe that it can be an important characteristic that allows to express hidden data carrier degradation - similarly as MSE (Mean-Square Error) or PSNR (Peak Signal-to-Noise Ratio) are utilized for digital media steganography. Steganographic cost can moreover be helpful to analyse the relationships between two or more steganographic methods applied to the same hidden data carrier. Wojciech Mazurczyk, Steffen Wendzel, Ignacio Azagra Villares, Krzysztof Szczypiorski |
Secur. Commun. Networks | 1 |
| 2016 | Micro protocol engineering for unstructured carriers: on the embedding of steganographic control protocols into audio transmissionsabstractAbstract Network steganography conceals the transfer of sensitive information within unobtrusive data in computer networks. So‐called micro protocols are communication protocols placed within the payload of a network steganographic transfer. They enrich this transfer with features such as reliability, dynamic overlay routing, or performance optimization — just to mention a few. We present different design approaches for the embedding of hidden channels with micro protocols in digitized audio signals under consideration of different requirements. On the basis of experimental results, our design approaches are compared and introduced into a protocol engineering approach for micro protocols. Copyright © 2016 John Wiley & Sons, Ltd. Matthias Naumann, Steffen Wendzel, Wojciech Mazurczyk, Jörg Keller 0001 |
Secur. Commun. Networks | 3 |
| 2016 | Steganography in IEEE 802.11 OFDM symbolsabstractAbstract This paper presents a new steganographic method called wireless padding (WiPad). It is based on the insertion of hidden data into the padding of frames at the physical layer of wireless local area networks (WLANs). A performance analysis based on a Markov model, previously introduced and validated by the authors, is provided for the method in relation to the IEEE 802.11 a/g standards. Its results prove that maximum steganographic bandwidth for WiPad is as high as 1.1 Mbit/s for data frames and 0.44 Mbit/s for acknowledgment frames. To the authors' best knowledge this is the most capacious of all the known steganographic network channels. Copyright © 2011 John Wiley & Sons, Ltd. Krzysztof Szczypiorski, Wojciech Mazurczyk |
Secur. Commun. Networks | 2 |
| 2016 | Guest Editors' Introduction: Special Issue on Cyber CrimeabstractThe twelve papers in this special section focus on the topic of cybercrimes. These computer crimes reflect the evolution of criminal practices that have adapted to the world of information and communication technologies. Cybercriminality has become a curse of the modern world with the potential to affect every one nationally and/or internationally. Individuals, companies, governments and institutions may become victims as well as (involuntary) helpers of cyber criminals. The inability to provide effective cyber-security can potentially have a tremendous socio-economic impact on global enterprises as well as individuals. Wojciech Mazurczyk, Thomas Holt, Krzysztof Szczypiorski |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Seeing the Unseen: Revealing Mobile Malware Hidden Communications via Energy Consumption and Artificial IntelligenceabstractModern malware uses advanced techniques to hide from static and dynamic analysis tools. To achieve stealthiness when attacking a mobile device, an effective approach is the use of a covert channel built by two colluding applications to exchange data locally. Since this process is tightly coupled with the used hiding method, its detection is a challenging task, also worsened by the very low transmission rates. As a consequence, it is important to investigate how to reveal the presence of malicious software using general indicators, such as the energy consumed by the device. In this perspective, this paper aims to spot malware covertly exchanging data using two detection methods based on artificial intelligence tools, such as neural networks and decision trees. To verify their effectiveness, seven covert channels have been implemented and tested over a measurement framework using Android devices. Experimental results show the feasibility and effectiveness of the proposed approach to detect the hidden data exchange between colluding applications. Luca Caviglione, Mauro Gaggero, Jean-François Lalande, Wojciech Mazurczyk, Marcin Urbanski |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | On the undetectability of transcoding steganographyabstractAbstract Transcoding Steganography (TranSteg) is a fairly new IP telephony steganographic method that is characterized by a high steganographic bandwidth, low introduced distortions, and high undetectability. TranSteg utilizes compression of the overt data to free space for the secret data bits. In this paper, we focus on evaluating different possibilities for TranSteg detection. Building on the previous works, we perform a wide analysis of different steganalysis methods to assess the possibility of TranSteg detection and identify the most ‘undetectable’ pairs of voice codecs. Copyright © 2015 John Wiley & Sons, Ltd. Artur Janicki, Wojciech Mazurczyk, Krzysztof Szczypiorski |
Secur. Commun. Networks | 2 |
| 2014 | Advances in digital media security and right managementabstractDigital media security and right management is an emerging research area that has attracted the attention of many security computer professionals, law enforcement experts and practitioners. It is a multidisciplinary research area that includes multiple fields, i.e., law, computer science, networking, data mining and criminal justice. We believe that the papers enclosed in this Special Issue will contribute to the development of the digital media security field and will further stimulate research in this area. Wojciech Mazurczyk, Krzysztof Szczypiorski |
Multim. Syst. | 1 |
| 2014 | Using transcoding for hidden communication in IP telephonyabstractThe paper presents a new steganographic method for IP telephony called TranSteg ( Tran scoding Steg anography). Typically, in steganographic communication it is advised for covert data to be compressed in order to limit its size. In TranSteg it is the overt data that is compressed to make space for the steganogram. The main innovation of TranSteg is to, for a chosen voice stream, find a codec that will result in a similar voice quality but smaller voice payload size than the originally selected. Then, the voice stream is transcoded. At this step the original voice payload size is intentionally unaltered and the change of the codec is not indicated. Instead, after placing the transcoded voice payload, the remaining free space is filled with hidden data. TranSteg proof of concept implementation was designed and developed. The obtained experimental results are enclosed in this paper. They prove that the proposed method is feasible and offers a high steganographic bandwidth while introducing small voice degradation. Moreover, TranSteg detection is difficult to perform when compared with existing VoIP steganography methods. Wojciech Mazurczyk, Pawel Szaga, Krzysztof Szczypiorski |
Multim. Tools Appl. | 1 |
| 2014 | On steganography in lost audio packetsabstractABSTRACT This paper presents a new hidden data insertion procedure based on the estimated probability of the remaining time of the call for the steganographic method called lost audio packets (LACK) steganography. LACK provides hidden communication for real‐time services such as voice over IP. The analytical results presented in this paper concern the influence of LACK's hidden data insertion procedures on the quality of voice transmission and the resistance to steganalysis. The proposed hidden data insertion procedure is also compared with previous steganogram insertion approaches on the basis of estimating the remaining average call duration. Copyright © 2011 John Wiley & Sons, Ltd. Wojciech Mazurczyk, Józef Lubacz, Krzysztof Szczypiorski |
Secur. Commun. Networks | 1 |
| 2013 | Trends in modern information hiding: techniques, applications and detectionabstractAs the production, storage, and exchange of information become more extensive and important in the functioning of societies, the problem of protecting the information from unintended and undesired usage becomes more complex. In modern societies, protection of information involves many interdependent technological and policy issues related to information confidentiality, integrity, anonymity, authenticity, utility, and so on. Information hiding techniques are receiving much attention today. Digital audio, video, and images are increasingly furnished with distinguishing but imperceptible marks, which may contain a hidden copyright notice or serial number or even help to prevent unauthorized copying directly. Digital watermarking and steganography may protect information, conceal secrets, or are used as core primitives in digital rights' management schemes. Alongside the aforementioned types of digital media steganography, currently, the target of increased interest is network steganography—a part of information hiding focused on modern networks. It is a method of hiding secret data in users' normal data transmissions. Steganographic techniques arise and evolve with the development of network protocols and mechanisms and are expected to be used in secret communication or information sharing. Presently, it becomes a hot topic owing to the proliferation of information networks and multimedia services in networks and social networks. The purpose of establishing applications of information hiding may be varied—possible uses can fall into the category of legal actions or illicit activity. Frequently, the illegal aspect is accentuated—starting from criminal communication, through information leakage from protected systems and cyber weapon exchange, up to industrial espionage. Recently discovered malware such as Duqu and Alureon point to the alleged utilization of information hiding techniques in botnets for covert communication in the command-and-conquer channels, which proves that information hiding poses important challenges to investigators. On the other side of the spectrum lie legitimate uses, which include circumvention of web censorship and surveillance, computer forensics (tracing and identification), and copyright protection (e.g. watermarking images). Papers must be written in English and describe original research not published or currently under review by other journals or conferences. All relevant papers submitted will go through an external review process. Concerning the preparation of the manuscript, please refer to the “Instructions for Authors” page at the journal website, http://onlinelibrary.wiley.com/journal/10.1002/%28ISSN%291939-0122/homepage/ForAuthors.html Furthermore, the manuscript must be submitted through the online submission system: http://mc.manuscriptcentral.com/scn by selecting the corresponding track. When submitting papers, the authors should identify “Manuscript Type” as “Special Issue,” enter “Running Head” as “SCN-SI-066” and “Special Issue Title” as “Trends in modern information hiding: techniques, applications and detection.” Contributing authors might also be asked to review some of the papers submitted to this special issue. All papers will be rigorously reviewed on the basis of their quality: originality, high scientific quality, good organization and clear writing, sufficient support for assertions and conclusion, appropriate title, abstract that include important points of the paper, satisfactory English, pertinent references, and clear tables and figures. Manuscript submission: 1 March 2014 Acceptance/rejection notification: before 1 July 2014 Expected publication: 2015 Wojciech Mazurczyk, Krzysztof Szczypiorski, Hui Tian 0002 |
Secur. Commun. Networks | 1 |
| 2012 | Toward Effective and Reliable Digital ForensicsabstractDigital forensics is a recently emerged research area, and it has attracted the attention of computer professionals, law enforcement experts and practitioners. It is a multidisciplinary area that includes multiple fields, i.e. law, computer science, finance, networking, data mining and criminal justice. We believe that papers enclosed in this Special Issue will enhance knowledge in digital forensics and will stimulate further research in the important areas of information and network security. Wojciech Mazurczyk, Krzysztof Szczypiorski |
Comput. J. | 1 |
| 2012 | Hiding information in a Stream Control Transmission Protocol
Wojciech Fraczek, Wojciech Mazurczyk, Krzysztof Szczypiorski |
Comput. Commun. | 2 |
| 2012 | What are suspicious VoIP delays?
Wojciech Mazurczyk, Krzysztof Cabaj, Krzysztof Szczypiorski |
Multim. Tools Appl. | 1 |
| 2012 | Security and privacy issues for the network of the futureabstractABSTRACT The vision towards the Network of the Future cannot be separated from the fact that today's networks, and networking services are subject to sophisticated and very effective attacks. When these attacks first appeared, spoofing and distributed denial‐of‐service attacks were treated as apocalypse for networking. Now, they are considered moderate damage, whereas more sophisticated and inconspicuous attacks, such as botnets activities, might have greater and far reaching impact. As the Internet is expanding to mobile phones and ‘smart dust’ and as its social coverage is liberalized towards the realization of ubiquitous computing (with communication), the concerns on security and privacy have become deeper and the problems more challenging than ever. Re‐designing the Internet as the Network of the Future is self‐motivating for researchers, and security and privacy cannot be provided again as separate, external, add‐on, solutions. In this paper, we discuss the security and privacy challenges of the Network of the Future and try to delimit the solutions space on the basis of emerging techniques. We also review methods that help the quantification of security and privacy in an effort to provide a more systematic and quantitative treatment of the area in the future. Copyright © 2011 John Wiley & Sons, Ltd. Giannis F. Marias, João Barros, Markus Fiedler, Andreas Fischer 0001, Harald Hauff, Ralph Herkenhöner, Antonio Grillo, Alessandro Lentini, Luísa Lima, Charlott Lorentzen, Wojciech Mazurczyk, Hermann de Meer, Paulo F. Oliveira, George C. Polyzos, Enric Pujol-Gil, Krzysztof Szczypiorski, João P. Vilela, Tiago T. V. Vinhoza |
Secur. Commun. Networks | 11 |
| 2012 | Lost audio packets steganography: the first practical evaluationabstractABSTRACT This paper presents first experimental results for an Internet Protocol (IP) telephony‐based steganographic method called lost audio packets steganography (LACK). This method utilises the fact that in typical multimedia communication protocols such as Real‐time Transport Protocol, excessively delayed packets are not used for the reconstruction of transmitted data at the receiver; that is, these packets are considered useless and discarded. The results presented in this paper were obtained on the basis of a functional LACK prototype and show the method's impact on the quality of voice transmission. Achievable steganographic bandwidth for the different IP telephony codecs is also calculated. Copyright © 2012 John Wiley & Sons, Ltd. Wojciech Mazurczyk |
Secur. Commun. Networks | 1 |
| 2011 | Retransmission steganography and its detection
Wojciech Mazurczyk, Milosz Smolarczyk, Krzysztof Szczypiorski |
Soft Comput. | 1 |
| 2006 | New VoIP Traffic Security Scheme with Digital Watermarking
Wojciech Mazurczyk, Zbigniew Kotulski |
SAFECOMP | 1 |