EDBT 2026 Demo / reviewers in the wild / expert
Bruno Crispo
dblp:c/BrunoCrispo
· DBLP profile ↗
123ranked-venue papers
4as first author
32since 2021 · last 2026
0000-0002-1252-8465ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 80 · 2 first-author · 22 since 2021Computer networks · 20 · 1 first-author · 7 since 2021Systems, architecture and hardware · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 4Human-computer interaction and ubiquitous computing · 4Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TAGShield: Persistent Tagging for Robust Stack Memory Error Protection
Michele Grisafi, Carlo Ramponi, Mahmoud Ammar, Silviu Vlasceanu, Bruno Crispo |
AsiaCCS | 5 |
| 2026 | RF-Vision Fusion Non-Cooperative UAV Detection and Identification for Low-Altitude Security
Yiyao Wan, Hongtao Liang, Fuhui Zhou, Bruno Crispo, Qihui Wu 0001 |
ICC | 5 |
| 2026 | Techniques and metrics for evasion attack mitigationabstractEvasion attacks pose a substantial risk to the application of Machine Learning (ML) in Cybersecurity, potentially leading to safety hazards or security breaches in large-scale deployments. Adversaries can employ evasion attacks as an initial tactic to deceive malware or network scanners using ML, thereby orchestrating traditional cyber attacks to disrupt systems availability or compromise integrity. Adversarial data designed to fool AI systems for cybersecurity can be engineered by strategically selecting, modifying, or creating test instances. This paper presents novel defender-centric techniques and metrics for mitigating evasion attacks by leveraging adversarial knowledge, exploring potential exploitation methods, and enhancing alarm detection capabilities. We first introduce two new evasion resistance metrics: adversarial failure rate ( afr ) and adversarial failure curves ( afc ). These metrics generalize previous approaches, as they can be applied to threshold classifiers, facilitating analyses for adversarial attacks comparable to those performed with Receiver Operating Characteristics (ROC) curve. Subsequently, we propose two novel evasion resistance techniques (trainset size pinning and model matrix), extending research in keyed intrusion detection and randomization. We explore the application of proposed techniques and metrics to an intrusion detection system as a pilot study using two public datasets, ‘BETH 2021’ and ‘Kyoto 2015’, which are well-established cybersecurity datasets for uncertainty and robustness benchmarking. The experimental results demonstrate that the combination of the proposed randomization techniques consistently produces remarkable improvement over other known randomization techniques. Francesco Bergadano, Sandeep Gupta 0002, Bruno Crispo |
Comput. Secur. | 3 |
| 2026 | Precise RF-Vision Fusion UAV Positioning and Identification for 6G Spectrum SecurityabstractPrecise positioning and identification of unauthorized unmanned aerial vehicles (UAVs) are of crucial importance for spectrum security and privacy protection in future intelligent networks. Although various single-modality approaches have been investigated, their performance degrades under the sensor-specific noise, resulting in suboptimal performance and robustness. To address these security challenges, we propose a multi-layer radio frequency (RF)-vision fusion framework that synergistically exploits temporal-spectral features of UAV RF signals and spatial-visual information to achieve precise and robust UAV positioning and identification. Moreover, a corresponding unified RF-Vision fusion Network (RFViNet) is designed to exploit the RF-vision cross-modal complementary and semantic synergy. Specifically, by leveraging the novel RFinformed proposal generation, RF-enhanced feature modulation, and RF-guided semantic query modules, the RFViNet effectively exploits the complementary strengths of RF and visual modalities. Furthermore, a practical RF–vision platform is developed to evaluate the performance of our method under various challenging conditions. Experimental results on the real-world dataset demonstrate that the proposed method achieves a competitive 85.8% average precision AP50, highlighting its potential for enhancing the spectrum security in future intelligent wireless networks. Yiyao Wan, Hongtao Liang, Fuhui Zhou, Bruno Crispo, Qihui Wu 0001 |
IEEE J. Sel. Areas Commun. | 5 |
| 2026 | Firmware Secure Updates Meet Formal VerificationabstractIndustrial Internet of Things (IIoT) systems require robust mechanisms for secure firmware updates. Existing approaches are often inadequate due to vendor fragmentation, network limitations, and the safety-critical nature of many IIoT applications. In this article, we address these challenges by extending the IETF SUIT (Software Updates for Internet of Things) framework to enhance the security and assurance of firmware updates. Our contributions include the integration of Software Bill of Materials (SBOM) mechanisms and a Behavioral Certification Manifest into the SUIT architecture to increase transparency and provide formal guarantees about the content of the update. The approach is validated by a prototype implementation that demonstrates its feasibility and scalability using real-world benchmarks. Alberto Tacchella, Emanuele Beozzo, Bruno Crispo, Marco Roveri |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2025 | Bridging the Interoperability Gaps Among Trusted Architectures in MCUs
Sandro Pinto 0001, Daniel Oliveira 0003, Michele Grisafi, Emanuele Beozzo, Bruno Crispo |
ICICS (2) | 6 |
| 2025 | Coordinated Enforcement of Obligations in Distributed Usage Control Systems [Work In Progress Paper]abstractAccess and usage control have evolved to include obligations, which are mandatory actions that must be fulfilled as part of authorization decisions. However, standards such as Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) specify that Policy Enforcement Points (PEPs) are responsible for enforcing obligations but leave execution aspects unspecified. They assume that obligations will be fulfilled without addressing how enforcement should be carried out. This paper introduces an enforcement framework based on structured enforcement messages to address these challenges. It defines two types of messages to coordinate enforcement execution across PEPs: Declaration and Execution Records. These records provide information about PEP capabilities, action dependencies, and fallback strategies for synchronized enforcement. Secondly, we propose a hierarchical policy model to separate concerns between the functionality of policy logic and enforcement. The model is composed of Governance, Authorization, and Enforcement Policies. Constraints flow across these three levels, allowing policy selection and execution to adapt to the authorization context and enforcement. Finally, we illustrate a high-level architecture that integrates the three policy layers with distributed enforcement logic across multiple PEPs. Hussein Joumaa, Ali Hariri, Theodosis Dimitrakos, Bruno Crispo |
SACMAT | 4 |
| 2025 | Certified Secure Updates for IoT Devices
Alberto Tacchella, Emanuele Beozzo, Bruno Crispo, Marco Roveri |
SEC (1) | 3 |
| 2025 | Evaluating a Bimodal User Verification Robustness Against Synthetic Data AttacksabstractSmartphones balance security and convenience by offering both knowledge-based (PINs, patterns) and biometric (facial, fingerprint) verification methods. However, studies have reported that PINs and patterns can be readily circumvented, while synthetically manipulated face data can easily deceive smartphone facial verification mechanisms. In this paper, we design a bimodal user verification mechanism that combines behavioral (pickup gesture) and biological (face) biometrics for user verification on smartphones. This work establishes a baseline for single-user verification scenarios on smartphones using a one-class verification model. The evaluation is performed in two stages: first, performance is assessed in both unimodal and bimodal settings using publicly available datasets; second, the robustness of the employed biological and behavioral traits is examined against four diverse attacks. Our findings emphasize the necessity of investigating diverse attack vectors, particularly fully synthetic data, to design robust user verification mechanisms. Sandeep Gupta 0002, Rajesh Kumar 0016, Kiran B. Raja, Bruno Crispo, Carsten Maple |
SECRYPT | 4 |
| 2024 | Hidden Web Caches DiscoveryabstractWeb caches play a crucial role in web performance and scalability. However, detecting cached responses is challenging when web servers do not reliably communicate the cache status through standardized headers. This paper presents a novel methodology for cache detection using timing analysis. Our approach eliminates the dependency on cache status headers, making it applicable to any web server. The methodology relies on sending paired requests using HTTP multiplexing functionality and makes heavy use of cache-busting to control the origin of the responses. By measuring the time it takes to receive responses from paired requests, we can determine if a response is cached or not. In each pair, one request is cache-busted to force retrieval from the origin server, while the other request is not and might be served from the cache, if present. A faster response time for the non-cache-busted request compared to the cache-busted one suggests the first one is coming from the cache. We implemented this approach in a tool and achieved an estimated accuracy of 89.6% compared to state-of-the-art methods based on cache status headers. Leveraging our cache detection approach, we conducted a large-scale experiment on the Tranco Top 50k websites. We identified a significant presence of hidden caches (5.8%) that do not advertise themselves through headers. Additionally, we employed our methodology to detect Web Cache Deception (WCD) vulnerabilities in these hidden caches. We discovered that 1.020 of them are susceptible to WCD vulnerabilities, potentially leaking sensitive data. Our findings demonstrate the effectiveness of our timing analysis methodology for cache discovery and highlight the importance of a tool that does not rely on cache-communicated cache status headers. Matteo Golinelli, Bruno Crispo |
RAID | 2 |
| 2024 | Obligation Management Framework for Usage ControlabstractObligations were introduced in access and usage control as a mechanism to specify mandatory actions to be fulfilled as part of authorization. In this paper, we address challenges related to obligation management in access and usage control, focusing on the Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) standards. Firstly, we provide a comprehensive analysis of Combining Algorithms (CAs) to determine their influence on the selection and ordering of obligations and identify nondeterminism. We then propose solutions to eliminate such nondeterminism enabling policy authors to explicitly specify the intended behavior. Secondly, we discuss the recurrence of obligations in usage control that occurs due to policy re-evaluations, highlighting the need to execute some obligations only once. We address this problem by introducing a parameter that enables policy authors to explicitly specify whether they intend an obligation to recur or not. Thirdly, we highlight an ambiguity in obligation applicability to lifecycle phases (e.g., ongoing) in usage control, arising from the lack of explicit associations between obligations and phases in particular cases. To address this issue, we introduce a parameter that explicitly specifies the scope of an obligation, allowing policy authors to restrict obligations to a single phase or apply them to the entire authorization. Finally, we extend the functionality of the Obligation Manager (OM) component to combine all three solutions, providing deterministic obligation management. Hussein Joumaa, Ali Hariri, Ana Petrovska, Oleksii Osliak, Theodosis Dimitrakos, Bruno Crispo |
SACMAT | 6 |
| 2024 | FLAShadow: A Flash-based Shadow Stack for Low-end Embedded SystemsabstractRuntime attacks are a rising threat to both low- and high-end systems with the spread of techniques such as Return-Oriented Programming (ROP), which aims at hijacking the control flow of vulnerable applications. Although several control flow integrity schemes have been proposed by both academia and the industry, the vast majority of them are not compatible with low-end embedded devices, especially the ones that lack hardware security features. In this article, we propose \(\sf {\textsc {FLAShadow}}\) , a secure shadow stack design and implementation for low-end embedded systems, relying on zero hardware security features. The key idea is to leverage a software-based memory isolation mechanism to establish an integrity-protected memory area on the Flash of the target device, where \(\sf {\textsc {FLAShadow}}\) can be securely maintained. \(\sf {\textsc {FLAShadow}}\) exclusively reserves a register for maintaining the integrity of the stack pointer and also depends on a minimal trusted runtime component to avoid trusting the compiler toolchain. We evaluate an open-source implementation of \(\sf {\textsc {FLAShadow}}\) for the MSP430 architecture, showing an average performance and memory overhead of 168.58% and 25.91%, respectively. While the average performance overhead is considered high, we show that it is application dependent and incurs less than 5% for some applications. Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
ACM Trans. Internet Things | 4 |
| 2023 | OAuth 2.0 Redirect URI Validation Falls Short, LiterallyabstractOAuth 2.0 requires a complex redirection trail between websites and Identity Providers (IdPs). In particular, the "redirect URI" parameter included in the popular Authorization Grant Code flow governs the callback endpoint that users are routed to, together with their security tokens. The protocol specification, therefore, includes guidelines on protecting the integrity of the redirect URI. Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Seyed Ali Mirheidari, Bruno Crispo, Engin Kirda |
ACSAC | 5 |
| 2023 | μIPS: Software-Based Intrusion Prevention for Bare-Metal Embedded Systems
Luca Degani, Majid Salehi, Fabio Martinelli, Bruno Crispo |
ESORICS (4) | 4 |
| 2023 | AppBox: A Black-Box Application Sandboxing Technique for Mobile App Management SolutionsabstractSeveral Mobile Device Management (MDM) and Mobile Application Management (MAM) services have been launched on the market. However, these services suffer from two important limitations: reduced granularity and need for app developers to include third party SDKs. We present AppBox, a novel black-box app-sandboxing solution for app customisation for stock Android devices. AppBox enables enterprises to select any app, even highly-obfuscated, from any market and perform a set of target customisations by means of fine-grained security policies. We have implemented and tested AppBox on various smartphones and Android versions. The evaluation shows that AppBox can effectively enforce fine-grained policies on a wide set of existing apps, with an acceptable overhead. Maqsood Ahmad 0001, Francesco Bergadano, Valerio Costamagna, Bruno Crispo, Giovanni Russello |
ISCC | 4 |
| 2023 | Device Behavioral Profiling for Autonomous Protection Using Deep Neural NetworksabstractDemand for autonomous protection in computing devices can not go unnoticed with an enormous increase in cyber attacks. Consequently, cybersecurity measures to continuously monitor and analyze device critical activity, identify suspicious behavior, and proactively mitigate security risks are highly desirable. In this article, a concept of behavioral profiling is described to distinguish between benign and malicious software by observing a system's internal resource usage on Windows devices. We rely on the Windows built-in event tracing mechanism to log processes' critical interactions for a given amount of time that are converted into structured data using a graph data structure. After that, we extract features from the generated graphs to analyze a process behavior using a deep neural network. Finally, we evaluate our prototype on a collected dataset that contains one thousand benign and malicious samples each and achieve an accuracy of ≈ 90%. Sandeep Gupta 0002, Bruno Crispo |
ISCC | 2 |
| 2023 | A survey of human-computer interaction (HCI) & natural habits-based behavioural biometric modalities for user recognition schemes
Sandeep Gupta 0002, Carsten Maple, Bruno Crispo, Kiran B. Raja, Artsiom Yautsiukhin, Fabio Martinelli |
Pattern Recognit. | 3 |
| 2023 | Discovery and Identification of Memory Corruption Vulnerabilities on Bare-Metal Embedded DevicesabstractMemory corruption vulnerabilities remain a prevalent threat on low-cost bare-metal devices. Fuzzing is a popular technique for automatically discovering such vulnerabilities. However, bare-metal devices lack even basic security mechanisms such as Memory Management Unit. Consequently, fuzzing approaches encounter silent memory corruptions with no visible effects, making even discovery difficult. Once discovered, it is also essential to identify the type of observed vulnerability for applying mitigation. Both discovery and identification remain open challenges in the case of fuzzing firmware binaries. This article addresses these problems by proposing an automated instrumentation technique that allows the observation of memory corruption vulnerabilities that are otherwise not observable and facilitates the automated identification of the observed vulnerability. Additionally, we surveyed state-of-the-art IoT fuzzers and analyzed their experimental methodologies. We found that existing approaches have fundamental problems that lead to incorrect or misleading results. To evaluate the effectiveness of IoT fuzzers, it is essential to determine the range and type of vulnerabilities that these fuzzers can discover. Thus, we propose the first ground-truth benchmark suite for IoT fuzzers that enables accurate and consistent evaluation of their vulnerability-finding performance. Our instrumentation framework's efficacy and efficiency in combination with state-of-the-art IoT fuzzers are assessed using the proposed benchmark. Majid Salehi, Luca Degani, Marco Roveri, Danny Hughes 0001, Bruno Crispo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Mollywood: Subtitles as an attack vectorabstractOnline subtitle repositories manage a huge amount of subtitle files for a variety of movies/TV-shows in 88 different languages and are available to the public to download and upload. Given the popularity of these repositories, we study the subtitle providers (STP) ecosystem by identifying and analyzing the involved parties. Our observations reveal that these STPs seem to be one of the most widespread and easily accessed resources to be potentially abused by attackers. Therefore, due to the features of STP ecosystem, they could be considered as a new attack vector through the subtitle files. However, all potentials of this new attack vector have not been yet exploited. Due to the rise of cryptojacking attacks substantially, this paper shows how a vulnerability present in a popular streaming platform can be exploited to perform a cryptojacking attack using the malicious subtitles delivered by STPs. Elham Arshad, Giuliano Turri, Bruno Crispo |
ISCC | 3 |
| 2022 | WiP: Metamodel for Continuous Authorisation and Usage ControlabstractAccess control has been traditionally used to protect data and privacy. Traditional access control models (e.g., ABAC, RBAC) cannot meet modern security requirements as technologies spread over heterogeneous and dynamic environments that need continuous monitoring. Modern models such as Usage Control (UCON) introduced the concept of continuous authorisation that has a lifecycle consisting of a series of phases through which the authorisation passes during its lifetime. However, such models assume a fixed lifecycle for all authorisations, so they cannot satisfy emerging technologies (e.g., smart vehicles, zero-trust, data flow), which require various and fine-grained lifecycles. Researchers have extended existing models to meet such requirements, but all solutions remain restrictive, as they are specially tailored for specific use-cases. In this paper, we propose an extensible model for continuous authorisations and usage control. The model enables its users to customise and dynamically configure the authorisation lifecycle as required by the use-case. This adds a layer of abstraction, forming a metamodel that can be instantiated into different flavours of continuous authorisation models, each addressing specific requirements. We also show that the authorisation lifecycle can be modelled as Deterministic Finite Automaton (DFA) and expressed in a structured language used by an evaluation engine to dynamically enact and manage the lifecycle. We layout the building blocks of the proposed metamodel and devise future research directions. Ali Hariri, Amjad Ibrahim, Theodosis Dimitrakos, Bruno Crispo |
SACMAT | 4 |
| 2022 | PISTIS: Trusted Computing Architecture for Low-end Embedded Systems
Michele Grisafi, Mahmoud Ammar, Marco Roveri, Bruno Crispo |
USENIX Security Symposium | 4 |
| 2022 | Web Cache Deception Escalates!
Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda, Bruno Crispo |
USENIX Security Symposium | 5 |
| 2022 | NemesisGuard: Mitigating interrupt latency side channel attacks with static binary rewritingabstractInternet of Things (IoT) is becoming integrated into nearly every aspect of our modern life. Indeed, exploitation of such devices can directly lead to physical consequences in the real world. Previous work has shown that IoT devices can be compromised by exploits in lower software layers such as the Operating System (OS). Embedded Trusted Execution Environments (TEEs) provide a small Trusted Computing Base (TCB) to protect sensitive codes and data in such devices. TEEs assume a strong threat model where even a privileged attacker (e.g. OS) cannot compromise the confidentiality and integrity of the execution. Nevertheless, it has been shown that side channel attacks make it challenging to keep secrets during application execution. Interrupt latency side channel attacks (a.k.a. Nemesis) are a novel type of timing attacks that target embedded TEEs and extract application secrets from them. Nemesis attacks exploit the CPU’s interrupt mechanism to reveal microarchitectural instruction timings from embedded TEEs. Specifically, the attacker measures the latency of a precisely timed interrupt to differentiate between secret-dependent branches. In this paper, we present NemesisGuard, the first mitigation mechanism against such side channel attacks that does not require a modified compiler or hardware and can protect COTS binaries without access to source code. NemesisGuard applies a novel static binary instrumentation technique to balance secret-dependent branches in IoT application binaries. Evaluation of NemesisGuard shows that it mitigates Nemesis side channel attacks effectively and efficiently. Majid Salehi, Gilles De Borger, Danny Hughes 0001, Bruno Crispo |
Comput. Networks | 4 |
| 2022 | Practical attacks on Login CSRF in OAuth
Elham Arshad, Michele Benolli, Bruno Crispo |
Comput. Secur. | 3 |
| 2022 | Step & turn - A novel bimodal behavioral biometric-based user verification scheme for physical access control
Sandeep Gupta 0002, Mouna Kacimi, Bruno Crispo |
Comput. Secur. | 3 |
| 2022 | RiderAuth: A cancelable touch-signature based rider authentication scheme for driverless taxis
Sandeep Gupta 0002, Kiran B. Raja, Fabio Martinelli, Bruno Crispo |
J. Inf. Secur. Appl. | 4 |
| 2022 | IDeAuth: A novel behavioral biometric-based implicit deauthentication scheme for smartphones
Sandeep Gupta 0002, Rajesh Kumar 0016, Mouna Kacimi, Bruno Crispo |
Pattern Recognit. Lett. | 4 |
| 2022 | MPI: Memory Protection for Intermittent ComputingabstractBatteryless devices harvest energy from sporadic ambient sources, enabling a wide range of long-lived, stand-alone, and environmentally-friendly sustainable applications. Software on these devices operates intermittently due to frequent power failures. Each power failure leads the device to lose its computational state that hinders the forward progress of computation and memory consistency. One solution to remedy this situation is to pair programs with checkpoints to save a snapshot of the intermediate program state to non-volatile memory before a power loss. Due to the lack of protection mechanisms in the state-of-the-art intermittent systems, checkpoints can be altered either by programmer errors or deliberately by an attacker. This situation leads to catastrophic effects since the program execution might be corrupted, and in turn, the device might malfunction. In this paper, we propose MPI, a memory protection mechanism for intermittent computing systems. In particular, MPI is a minimal intermittent-compliant trusted computing base acting as a hypervisor that fully manages and protects the underlying memory of a batteryless device. MPI enables a reliable and secure generation and restoration of checkpoints, maintaining their integrity and access control in the presence of remote software-based attacks without trusting the user program or requiring programmer intervention. Notable is that MPI neither requires hardware modifications nor depends on hardware features that might not exist in all batteryless platforms. Our experiments on a real batteryless platform show that MPI provides stronger security guarantees compared to the state-of-the-art approaches, with a comparable time and energy overhead. Michele Grisafi, Mahmoud Ammar, Kasim Sinan Yildirim, Bruno Crispo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | The Full Gamut of an Attack: An Empirical Analysis of OAuth CSRF in the Wild
Michele Benolli, Seyed Ali Mirheidari, Elham Arshad, Bruno Crispo |
DIMVA | 4 |
| 2021 | You've Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures
Tommaso Innocenti, Seyed Ali Mirheidari, Amin Kharraz, Bruno Crispo, Engin Kirda |
DIMVA | 4 |
| 2021 | SIUV: A Smart Car Identity Management and Usage Control System Based on Verifiable Credentials
Ali Hariri, Subhajit Bandopadhyay, Athanasios Rizos, Theodosis Dimitrakos, Bruno Crispo, Muttukrishnan Rajarajan |
SEC | 5 |
| 2021 | Delegated attestation: scalable remote attestation of commodity CPS by blending proofs of execution with software attestationabstractRemote Attestation (RA) is an interaction between a trusted verifier (Vrf) and one or more remote and potentially compromised devices (provers or Prv-s) that allow the former to measure the software state of the latter. RA is particularly relevant to safety-critical cyber-physical systems (CPS) where a set of low-end micro-controllers (MCUs), operate under the control of a remote and more powerful controller. In such cases, RA is an effective and relatively efficient means to detect software compromise, e.g., malware infections, on these low-end MCUs that cannot support expensive security mechanisms. Mahmoud Ammar, Bruno Crispo, Ivan Oliveira Nunes, Gene Tsudik |
WISEC | 2 |
| 2020 | Verify&Revive: Secure Detection and Recovery of Compromised Low-end Embedded DevicesabstractTiny and specialized computing platforms, so-called embedded or Internet of Things (IoT) devices, are increasingly used in safety- and privacy-critical application scenarios. A significant number of such devices offer limited or no security features, making them attractive targets for a wide variety of cyber attacks, exemplified by malware infestations. One key component in securing these devices is establishing a root of trust, which is typically attained via remote attestation (RA), a security service that aims to ascertain the current state of a remote device and detect any malicious tampering. Although several (software-based, hardware-based, and hybrid) RA approaches have been proposed to address this problem, two main issues remain, regardless of the type of RA. First, all but one of the existing RA approaches are vulnerable to Time-Of-Check Time-Of-Use (TOCTOU) attack, where a transient malware may infect the corresponding embedded device between two consecutive RA routines without being detected. Second, little attention has been devoted to efficiently and securely rescuing devices that are determined to be compromised, increasing the maintenance cost of IoT deployments, especially in industrial control systems, where (re-)deploying a new device is often a cost-sensitive operation. Mahmoud Ammar, Bruno Crispo |
ACSAC | 2 |
| 2020 | μSBS: Static Binary Sanitization of Bare-metal Embedded Devices for Fault Observability
Majid Salehi, Danny Hughes 0001, Bruno Crispo |
RAID | 3 |
| 2020 | Cached and Confused: Web Cache Deception in the Wild
Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda, William K. Robertson |
USENIX Security Symposium | 4 |
| 2020 | StaDART: Addressing the problem of dynamic code updates in the security analysis of android applications
Maqsood Ahmad 0001, Valerio Costamagna, Bruno Crispo, Francesco Bergadano, Yury Zhauniarovich |
J. Syst. Softw. | 3 |
| 2020 | WISE: A Lightweight Intelligent Swarm Attestation Scheme for the Internet of ThingsabstractThe Internet of Things (IoT) is shaped by increasing number of low-cost Internet-connected embedded devices that are becoming ubiquitous in every aspect of modern life, including safety- and privacy-critical application scenarios. Such devices offer limited or no security features, creating a large new attack surface. One key component in securing these devices is software integrity checking, which is typically attained with Remote Attestation (RA). RA is a security service that helps in detecting malware-infected IoT devices through remotely verifying their internal state by a trusted party. In the vast majority of IoT application domains, IoT devices operate in swarms or groups to achieve common tasks. Existing swarm attestation techniques are still rigid and not smart enough to address heterogeneity and adapt the different requirements of various IoT devices connected to a swarm, thus triggering the need for more efficient swarm attestation schemes. In this article, we present WISE, the first intelligent swarm attestation scheme that takes into account the various characteristics, differences, and requirements of connected devices in a swarm, aiming at minimizing the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and diverse characteristics and constraints of each device in the swarm. We show that WISE is suitable for resource-constrained embedded devices, highly efficient and scalable in static and dynamic heterogeneous IoT networks, and offers an adjustable level of security. Mahmoud Ammar, Bruno Crispo |
ACM Trans. Internet Things | 2 |
| 2019 | Detecting malicious applications using system services request behaviorabstractWidespread growth in Android malware stimulates security researchers to propose different methods for analyzing and detecting malicious behaviors in applications. Nevertheless, current solutions are ill-suited to extract the fine-grained behavior of Android applications accurately and efficiently. In this paper, we propose ServiceMonitor, a lightweight host-based detection system that dynamically detects malicious applications directly on mobile devices. ServiceMonitor reconstructs the fine-grained behavior of applications based on their interaction with system services (i.e. SMS manager, camera, wifi networking, etc). ServiceMonitor monitors the way applications request system services in order to build a statistical Markov chain model to represent what and how system services are used. Afterwards, we use this Markov chain as a feature vector to classify the application behavior into either malicious or benign using the Random Forests classification algorithm. We evaluated ServiceMonitor using a dataset of 8034 malware and 10024 benign applications and obtaining 96.7% of accuracy rate and negligible overhead and performance penalty. Majid Salehi, Morteza Amini, Bruno Crispo |
MobiQuitous | 3 |
| 2019 | A Decentralized and Scalable Model for Resource Discovery in IoT NetworkabstractThe growing number of communicating devices in the Internet of Things (IoT) network requires an efficient resource discovery scheme without relying on centralized entity that may turn into a bottleneck affecting the system efficiency. In this paper we propose a distributed model for resource discovery in IoT. The model is based on structured peer-to-peer (p2p) scheme and follows the general system trend of fog computing. It supports multi-attribute queries and utilizes a Distributed Hash Table (DHT) as an overlay to organize the discovery process in a distributed manner. A specific method for identifier generation has been introduced to ensure the privacy of objects. Additionally, an address propagation model in the system reduces the overhead in the network by allowing the local lookup instead of global lookup for pre-connected objects. Our preliminary evaluation shows that the proposed model has a lower latency comparing to the cloud based resource discovery. Mohammed B. Alshawki, Bruno Crispo, Péter Ligeti |
WiMob | 2 |
| 2019 | PrivICN: Privacy-preserving content retrieval in information-centric networking
César Bernardini, Samuel Marchal, Muhammad Rizwan Asghar, Bruno Crispo |
Comput. Networks | 4 |
| 2019 | DriverAuth: A risk-based multi-modal biometric-based driver authentication scheme for ride-sharing platforms
Sandeep Gupta 0002, Attaullah Buriro, Bruno Crispo |
Comput. Secur. | 3 |
| 2019 | AnswerAuth: A bimodal behavioral biometric-based user authentication scheme for smartphones
Attaullah Buriro, Bruno Crispo, Mauro Conti |
J. Inf. Secur. Appl. | 2 |
| 2019 | SμV - The Security MicroVisor: A Formally-Verified Software-Based Security Architecture for the Internet of ThingsabstractThe Internet of Things (IoT) is shaped by the increasing number of low-cost Internet-connected embedded devices that are becoming ubiquitous in every aspect of modern life. With their cost-sensitive design, integrating hardware-based security mechanisms into such devices is undesirable. Therefore, securing these devices is a particularly difficult challenge, especially, due to their growing popularity as attack targets, via remote malware infestations. The vast majority of such devices are bare-metal, where they execute programs in fully-accessible and unprotected memories without any operating system and even without including any form of security. This is beside the fact that IoToperating systems offer little or no protection. This paper addresses this problem through the concept of a Security MicroVisor (SμV), which provides embedded devices that lack hardware-based memory protection units with memory isolation using software virtualisation and assembly-level code verification. More specifically, our contribution is two-fold. First, we propose SμV as a software-based memory isolation technique. We then formally verify the software architecture, written in C, to prove that it is memory-safe and crash-free. Second, we propose a software-based remote attestation, as an example of a fundamental security service that can be implemented on top of SμV, to detect malware-infected devices. We first describe the design and implementation of SμV. Then, we highlight the formal verification of software architecture, and characterize the remote attestation protocol. We evaluate the SμV implementation using an 8-bit AVR microcontroller that is widely used in IoT devices. Evaluation results show that SμV provides strong security guarantees while maintaining extremely low overhead in terms of memory footprint, performance, and power consumption. Furthermore, we extend the performance evaluation also to the remote attestation scheme, illustrating its limited overhead. Mahmoud Ammar, Bruno Crispo, Bart Jacobs 0002, Danny Hughes 0001, Wilfried Daniels |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | SPEED: Secure Provable Erasure for Class-1 IoT DevicesabstractThe Internet of Things (IoT) consists of embedded devices that sense and manage our environment in a growing range of applications. Large-scale IoT systems such as smart cities require significant investment in both equipment and personnel. To maximize return on investment, IoT platforms should support multiple third-party applications and adaptation of infrastructure over time. Realizing the vision of shared IoT platforms demands strong security guarantees. That is particularly challenging considering the limited capability and resource constraints of many IoT devices. Mahmoud Ammar, Wilfried Daniels, Bruno Crispo, Danny Hughes 0001 |
CODASPY | 3 |
| 2018 | DIALERAUTH: A Motion-assisted Touch-based Smartphone User Authentication SchemeabstractThis paper introduces DIALERAUTH - a mechanism which leverages the way a smartphone user taps/enters any text-independent 10-digit number (replicating the dialing process) and the hand's micro-movements she makes while doing so. DIALERAUTH authenticates the user on the basis of timing differences in the entered 10-digit strokes. DIALERAUTH provides enhanced security by leveraging the transparent and unobservable layer based on another modality - user's hand micro-movements. Furthermore, DIALERAUTH increases the usability and acceptability by utilizing the users' familiarity with the dialing process and the flexibility of choosing any combination of 10-digit number. We implemented DIALERAUTH for both data collection and proof-of-concept real-time analysis. We collected, in total 10500 legitimate samples involving 97 users, through an extensive unsupervised field experiment, to evaluate the effectiveness of DIALERAUTH. Analysis using one-class Multilayer Perceptron (MLP) shows a True Acceptance Rate (TAR) of 85.77% in identifying the genuine users. Security analysis involving 240 adversarial attempts proved DIALERAUTH as significantly resilient against random and mimic attacks. A usability study based on System Usability Scale (SUS) reflects a positive feedback on user acceptance (SUS score = 73.29). Attaullah Buriro, Bruno Crispo, Sandeep Gupta 0002, Filippo Del Frari |
CODASPY | 2 |
| 2018 | Polyglot CerberOS: Resource Security, Interoperability and Multi-Tenancy for IoT Services on a Multilingual PlatformabstractThe Internet of Things (IoT) promises to tackle a range of environmental challenges and deliver large efficiency gains in industry by embedding computational intelligence, sensing and control in our physical environment. Multiple independent parties are increasingly seeking to leverage shared IoT infrastructure, using a similar model to the cloud, and thus require constrained IoT devices to become microservice-hosting platforms that can securely and concurrently execute their code and interoperate. This vision demands that heterogeneous services, peripherals and platforms are provided with an expanded set of security guarantees to prevent third-party services from hijacking the platform, resource-level access control and accounting, and strong isolation between running processes to prevent unauthorized access to third-party services and data. This paper introduces Polyglot CerberOS, a resource-secure operating system for multi-tenant IoT devices that is realised through a reconfigurable virtual machine which can simultaneously execute interoperable services, written in different languages. We evaluate Polyglot CerberOS on IETF Class-1 devices running both Java and C services. The results show that interoperability and strong security guarantees for multilingual services on multi-tenant commodity IoT devices are feasible, in terms of performance and memory overhead, and transparent for developers. Sven Akkermans, Bruno Crispo, Wouter Joosen, Danny Hughes 0001 |
MobiQuitous | 2 |
| 2018 | WISE: Lightweight Intelligent Swarm Attestation Scheme for IoT (The Verifier's Perspective)abstractThe growing pervasiveness of Internet of Things (IoT) expands the attack surface by connecting more and more attractive attack targets, i.e. embedded devices, to the Internet. One key component in securing these devices is software integrity checking, which typically attained with Remote Attestation (RA). RA is realized as an interactive protocol, whereby a trusted party, verifier, verifies the software integrity of a potentially compromised remote device, prover. In the vast majority of IoT applications, smart devices operate in swarms, thus triggering the need for efficient swarm attestation schemes.In this paper, we present WISE, the first intelligent swarm attestation protocol that aims to minimize the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and the diverse characteristics (and constraints) of each device in the swarm. We show that WISE is very suitable for resource-constrained embedded devices, highly efficient and scalable in heterogenous IoT networks, and offers an adjustable level of security. Mahmoud Ammar, Mahdi Washha, Bruno Crispo |
WiMob | 3 |
| 2018 | Large-Scale Analysis of Style Injection by Relative Path OverwriteabstractRelative Path Overwrite (RPO) is a recent technique to inject style directives into sites even when no style sink or markup injection vulnerability is present. It exploits differences in how browsers and web servers interpret relative paths (i.e., path confusion) to make a HTML page reference itself as a stylesheet; a simple text injection vulnerability along with browsers» leniency in parsing CSS resources results in an attacker»s ability to inject style directives that will be interpreted by the browser. Even though style injection may appear less serious a threat than script injection, it has been shown that it enables a range of attacks, including secret exfiltration. In this paper, we present the first large-scale study of the Web to measure the prevalence and significance of style injection using RPO. Our work shows that around 9% of the sites in the Alexa Top 10,000 contain at least one vulnerable page, out of which more than one third can be exploited. We analyze in detail various impediments to successful exploitation, and make recommendations for remediation. In contrast to script injection, relatively simple countermeasures exist to mitigate style injection. However, there appears to be little awareness of this attack vector as evidenced by a range of popular Content Management Systems (CMSes) that we found to be exploitable. Sajjad Arshad, Seyed Ali Mirheidari, Tobias Lauinger, Bruno Crispo, Engin Kirda, William K. Robertson |
WWW | 4 |
| 2018 | Internet of Things: A survey on the security of IoT frameworks
Mahmoud Ammar, Giovanni Russello, Bruno Crispo |
J. Inf. Secur. Appl. | 3 |
| 2017 | CerberOS: A Resource-Secure OS for Sharing IoT Devices
Sven Akkermans, Wilfried Daniels, Gowri Sankar Ramachandran, Bruno Crispo, Danny Hughes 0001 |
EWSN | 4 |
| 2017 | Analyzing Remote Server Locations for Personal Data Transfers in Mobile AppsabstractAbstract The prevalence of mobile devices and their capability to access high speed internet has transformed them into a portable pocket cloud interface. Being home to a wide range of users’ personal data, mobile devices often use cloud servers for storage and processing. The sensitivity of a user’s personal data demands adequate level of protection at the back-end servers. In this regard, the European Union Data Protection regulations (e.g., article 25.1) impose restriction on the locations of European users’ personal data transfer. The matter of concern, however, is the enforcement of such regulations. The first step in this regard is to analyze mobile apps and identify the location of servers to which personal data is transferred. To this end, we design and implement an app analysis tool, PDTLoc (Personal Data Transfer Location Analyzer), to detect violation of the mentioned regulations. We analyze 1, 498 most popular apps in the EEA using PDTLoc to investigate the data recipient server locations. We found that 16.5% (242) of these apps transfer users’ personal data to servers located at places outside Europe without being under the control of a data protection framework. Moreover, we inspect the privacy policies of the apps revealing that 51% of these apps do not provide any privacy policy while almost all of them contact the servers hosted outside Europe. Mojtaba Eskandari, Bruno Kessler, Maqsood Ahmad 0001, Anderson Santana de Oliveira, Bruno Crispo |
Proc. Priv. Enhancing Technol. | 5 |
| 2016 | PROTECTOR: Privacy-preserving information lookup in content-centric networksabstractContent-Centric Networking (CCN) is an emerging paradigm that can anticipate growing demands of content delivery in coming years. The underlying architecture of the CCN enables users to search for content based on names. On one hand, this is a privacy-friendly feature that do not require source and destination addresses. On the other hand, semantically-rich names reveal sufficient information about users' preferences. Unfortunately, a curious CCN node may learn and sell sensitive information to third-parties, thus posing serious threats to users' privacy. In this paper, we present PROTECTOR that aims at protecting content names as well as content and allows a CCN network to add new users or remove existing ones without requiring any re-encryption of stored content and names. It is scalable and efficient as it incurs very limited overhead for required cryptographic operations. Our performance analysis reports that PROTECTOR can handle 34 and over 10 million requests per second at boundary and other CCN nodes, respectively. Muhammad Rizwan Asghar, César Bernardini, Bruno Crispo |
ICC | 3 |
| 2015 | Towards Black Box Testing of Android AppsabstractMany state-of-art mobile application testing frameworks (e.g., Dynodroid [1], EvoDroid [2]) enjoy Emma [3] or other code coverage libraries to measure the coverage achieved. The underlying assumption for these frameworks is availability of the app source code. Yet, application markets and security researchers face the need to test third-party mobile applications in the absence of the source code. There exists a number of frameworks both for manual and automated test generation that address this challenge. However, these frameworks often do not provide any statistics on the code coverage achieved, or provide coarse-grained ones like a number of activities or methods covered. At the same time, given two test reports generated by different frameworks, there is no way to understand which one achieved better coverage if the reported metrics were different (or no coverage results were provided). To address these issues we designed a framework called BBOXTESTER that is able to generate code coverage reports and produce uniform coverage metrics in testing without the source code. Security researchers can automatically execute applications exploiting current state-of-art tools, and use the results of our framework to assess if the security-critical code was covered by the tests. In this paper we report on design and implementation of BBOXTESTER and assess its efficiency and effectiveness. Yury Zhauniarovich, Anton Philippov, Olga Gadyatskaya, Bruno Crispo, Fabio Massacci |
ARES | 4 |
| 2015 | StaDynA: Addressing the Problem of Dynamic Code Updates in the Security Analysis of Android ApplicationsabstractStatic analysis of Android applications can be hindered by the presence of the popular dynamic code update techniques: dynamic class loading and reflection. Recent Android malware samples do actually use these mechanisms to conceal their malicious behavior from static analyzers. These techniques defuse even the most recent static analyzers that usually operate under the "closed world" assumption (the targets of reflective calls can be resolved at analysis time; only classes reachable from the class path at analysis time are used at runtime). Our proposed solution allows existing static analyzers to remove this assumption. This is achieved by combining static and dynamic analysis of applications in order to reveal the hidden/updated behavior and extend static analysis results with this information. This paper presents design, implementation and preliminary evaluation results of our solution called StaDynA. Yury Zhauniarovich, Maqsood Ahmad 0001, Olga Gadyatskaya, Bruno Crispo, Fabio Massacci |
CODASPY | 4 |
| 2015 | Leveraging Parallel Communications for Minimizing Energy Consumption on SmartphonesabstractRecent energy measurements on smartphones have shown that parallel communications (e.g., data transfer and voice call) require less energy than their stand-alone execution. Guided by these results, we investigate the possibility of scheduling communications in pairs for minimizing the energy consumption. We define two energy optimization problems to postpone delay-tolerant services and perform them in parallel with real-time services in order to save energy. The first problem, called single delay-tolerant assignment (SDA), allows at most one delay-tolerant service to be paired with each real-time service, whereas the second problem, called multiple delay-tolerant assignment (MDA), allows multiple delay-tolerant services to be paired (in different times) with the same real-time service. For the SDA problem, we propose an optimal algorithm. For the MDA problem, which is computationally intractable, we give an approximation algorithm. We evaluate the benefits of the energy-efficient pairing strategy via simulations on synthetic traces. The MDA algorithm can save up to the 60 percent of the energy consumption using 4G network assuming an intensive smartphone usage, while the SDA algorithm saves up to the 20 percent. Mauro Conti, Bruno Crispo, Daniele Diodati, Jukka K. Nurminen, Maria Cristina Pinotti, Taavi Teemaa |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | Less is more: cipher-suite negotiation for DNSSECabstractWe propose a transport layer cipher-suite negotiation mechanism for DNSSEC standard, allowing name-servers to send responses containing only the keys and signatures that correspond to the cipher-suite option negotiated with the resolver, rather than sending all the signatures and keys (as is done currently). Amir Herzberg, Haya Schulmann, Bruno Crispo |
ACSAC | 3 |
| 2014 | PIDGIN: privacy-preserving interest and content sharing in opportunistic networksabstractOpportunistic networks have recently received considerable attention from both industry and researchers. These networks can be used for many applications without the need for a dedicated IT infrastructure. In the context of opportunistic networks, content sharing in particular has attracted significant attention. To support content sharing, opportunistic networks often implement a publish-subscribe system in which users may publish their own content and indicate interest in other content through subscriptions. Using a smartphone, any user can act as a broker by opportunistically forwarding both published content and interests within the network. Unfortunately, opportunistic networks are faced with serious privacy and security issues. Untrusted brokers can not only compromise the privacy of subscribers by learning their interests but also can gain unauthorised access to the disseminated content. This paper addresses the research challenges inherent to the exchange of content and interests without: (i) compromising the privacy of subscribers, and (ii) providing unauthorised access to untrusted brokers. Specifically, this paper presents an interest and content sharing solution that addresses these security challenges and preserves privacy in opportunistic networks. We demonstrate the feasibility and efficiency of the solution by implementing a prototype and analysing its performance on smart phones. Muhammad Rizwan Asghar, Ashish Gehani, Bruno Crispo, Giovanni Russello |
AsiaCCS | 3 |
| 2014 | VLOC: An Approach to Verify the Physical Location of a Virtual Machine In CloudabstractThe geolocation of data stored and being processed in cloud is an important issue for many organisations due to obligations that require sensitive data to reside or be processed in particular countries. In this paper we introduce an approach, named VLOC, to verify the physical location of a virtual machine on which the customer applications and data are stored. VLOC is implemented as a software which is able to estimate the geolocation of itself and notify the corresponding user if the location is unauthorised. VLOC uses a number of arbitrary web-servers as external landmarks for localisation and employs network latency measurement for distance estimation. Due to the fluctuation in the network latency, VLOC employs a machine learning technique in order to adapt itself to various network latency tolerance. Different from most of geolocation estimation approaches, VLOC is installed inside the target host (inside the cloud). VLOC does not require special hardware nor a network of trusted landmarks. The experimental results shows the accuracy of VLOC is higher than other existing approaches. Mojtaba Eskandari, Anderson Santana de Oliveira, Bruno Crispo |
CloudCom | 3 |
| 2014 | FSquaDRA: Fast Detection of Repackaged Applications
Yury Zhauniarovich, Olga Gadyatskaya, Bruno Crispo, Francesco La Spina, Ermanno Moser |
DBSec | 3 |
| 2014 | MOSES: Supporting and Enforcing Security Profiles on SmartphonesabstractSmartphones are very effective tools for increasing the productivity of business users. With their increasing computational power and storage capacity, smartphones allow end users to perform several tasks and be always updated while on the move. Companies are willing to support employee-owned smartphones because of the increase in productivity of their employees. However, security concerns about data sharing, leakage and loss have hindered the adoption of smartphones for corporate use. In this paper we present MOSES, a policy-based framework for enforcing software isolation of applications and data on the Android platform. In MOSES, it is possible to define distinct Security Profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. Profiles are not predefined or hardcoded, they can be specified and applied at any time. One of the main characteristics of MOSES is the dynamic switching from one security profile to another. We run a thorough set of experiments using our full implementation of MOSES. The results of the experiments confirm the feasibility of our proposal. Yury Zhauniarovich, Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2013 | Enabling trusted stores for androidabstractIn the Android ecosystem, the process of verifying the integrity of downloaded apps is left to the user. Different from other systems, e.g., Apple App Store, Google does not provide any certified vetting process for the Android apps. This choice has a lot of advantages but it is also the open door to possible attacks as the recent one shown by Bluebox. To address this issue, this demo presents how to enable the deployment of application certification service, we called TruStore, for the Android platform. In our approach, the TruStore client enabled on the end-user device ensures that only the applications, which have been certified by the TruStore server, are installed on the user smartphone. We envisage trusted markets (TruStore servers, which can be, e.g., corporate application markets) that guarantee security by enabling an application vetting process. The TruStore infrastructure maintains the open nature of the Android ecosystem and requires minor modifications to Android stack. Moreover, it is backward-compatible and transparent for developers, and does not change the application management process on a device. Yury Zhauniarovich, Olga Gadyatskaya, Bruno Crispo |
CCS | 3 |
| 2013 | CREPUSCOLO: A collusion resistant privacy preserving location verification systemabstractIn location-sensitive applications (e.g. location-based access control, and location-based social networks), users often benefit from being at a certain location. These benefits are incentives for users to cheat about their current location, in order to get unauthorized access to resources and services provided by location-sensitive applications. To deal with this issue, we propose CREPUSCOLO, a collusion resistant and privacy preserving location verification system. In CREPUSCOLO, we use “location-proofs” collected from co-located mobile devices, which can be endorsed by a “token” acquired from a trusted Token Provider. In fact, location-proofs endorsed by tokens provide the resiliency against collusion attacks, because this combination can prove that a certain mobile device was at a certain location at a specific time. CREPUSCOLO also protects the source location privacy by enforcing the usage of periodically changing pseudonyms. Extensive simulations show that CREPUSCOLO is effective in detecting collusion attacks even under very conservative hypothesis. For instance, with just 11 Token Providers spread over a 121 km2area characterized by a very low density of cooperating devices, 90% of collusion attacks are detected. Eyüp S. Canlar, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
CRiSIS | 3 |
| 2013 | ESPOONERBAC: Enforcing security policies in outsourced environments
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo |
Comput. Secur. | 4 |
| 2013 | Windows Mobile LiveSD Forensics
Eyüp S. Canlar, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
J. Netw. Comput. Appl. | 3 |
| 2013 | Unprivileged Black-Box Detection of User-Space KeyloggersabstractSoftware keyloggers are a fast growing class of invasive software often used to harvest confidential information. One of the main reasons for this rapid growth is the possibility for unprivileged programs running in user space to eavesdrop and record all the keystrokes typed by the users of a system. The ability to run in unprivileged mode facilitates their implementation and distribution, but, at the same time, allows one to understand and model their behavior in detail. Leveraging this characteristic, we propose a new detection technique that simulates carefully crafted keystroke sequences in input and observes the behavior of the keylogger in output to unambiguously identify it among all the running processes. We have prototyped our technique as an unprivileged application, hence matching the same ease of deployment of a keylogger executing in unprivileged mode. We have successfully evaluated the underlying technique against the most common free keyloggers. This confirms the viability of our approach in practical scenarios. We have also devised potential evasion techniques that may be adopted to circumvent our approach and proposed a heuristic to strengthen the effectiveness of our solution against more elaborated attacks. Extensive experimental results confirm that our technique is robust to both false positives and false negatives in realistic settings. Stefano Ortolani, Cristiano Giuffrida, Bruno Crispo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2013 | FM 99.9, Radio Virus: Exploiting FM Radio Broadcasts for Malware DeploymentabstractMany modern smartphones and car radios are shipped with embedded FM radio receiver chips. The number of devices with similar chips could grow very significantly if the U.S. Congress decides to make their inclusion mandatory in any portable device as suggested by organizations such as the RIAA. While the main goal of embedding these chips is to provide access to traditional FM radio stations, a side effect is the availability of a data channel, the FM Radio Data System (RDS), which connects all these devices. Different from other existing IP-based data channels among portable devices, this new one is open, broadcast in nature, and so far completely ignored by security providers. This paper illustrates for the first time how to exploit the FM RDS protocol as an attack vector to deploy malware that, when executed, gains full control of the victim's device. We show how this attack vector allows the adversary to deploy malware on different platforms. Furthermore, we have shown the infection is undetected on devices running the Android OS, since malware detection solutions are limited in their ability due to some features of the Android security model. We support our claims by implementing an attack using RDS on different devices available on the market (smartphones, car radios, and tablets) running three different versions of Android OS. We also provide suggestions on how to limit the threat posed by this new attack vector and explain what are the design choices that make Android vulnerable. However, there are no straightforward solutions. Therefore, we also wish to draw the attention of the security community towards these attacks and initiate more research into countermeasures. Earlence Fernandes, Bruno Crispo, Mauro Conti |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Hybrid Static-Runtime Information Flow and Declassification EnforcementabstractThere are different paradigms for enforcing information flow and declassification policies. These approaches can be divided into static analyzers and runtime enforcers. Each class has its own strengths and weaknesses, each being able to enforce a different set of policies. In this paper, we introduce a hybrid static-runtime enforcement mechanism that works on unannotated program code and supports information-flow control, as well as declassification policies. Our approach manages to enforce realistic policies, as shown by our three running examples, all within the context of a mobile device application, which cannot be handled separately by static or runtime approaches, and are also not covered by current access control models of mobile platforms such as Android or iOS. We also show that including an intermediate step (called preload check) makes both the static analysis system independent (in terms of security labels) and the runtime enforcer lightweight. Finally, we implement our runtime enforcer and run experiments that show that its overhead is so low that the approach can be rolled out on current mobile systems. Bruno P. S. Rocha, Mauro Conti, Sandro Etalle, Bruno Crispo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2013 | LAKE: A Server-Side Authenticated Key-Establishment with Low Computational WorkloadabstractServer-side authenticated key-establishment protocols are characterized by placing a heavy workload on the server. We propose LAKE: a new protocol that enables amortizing servers’ workload peaks by moving most of the computational burden to the clients. We provide a formal analysis of the LAKE protocol under the Canetti-Krawczyk model and prove it to be secure. To the best of our knowledge, this is the most computationally efficient authenticated key-establishment ever proposed in the literature. Kemal Bicakci, Bruno Crispo, Gabriele Oligeri |
ACM Trans. Internet Techn. | 2 |
| 2013 | Virtual private social networks and a facebook implementationabstractThe popularity of Social Networking Sites (SNS) is growing rapidly, with the largest sites serving hundreds of millions of users and their private information. The privacy settings of these SNSs do not allow the user to avoid sharing some information (e.g., name and profile picture) with all the other users. Also, no matter the privacy settings, this information is always shared with the SNS (that could sell this information or be hacked). To mitigate these threats, we recently introduced the concept of Virtual Private Social Networks (VPSNs). In this work we propose the first complete architecture and implementation of VPSNs for Facebook. In particular, we address an important problem left unexplored in our previous research—that is the automatic propagation of updated profiles to all the members of the same VPSN. Furthermore, we made an in-depth study on performance and implemented several optimization to reduce the impact of VPSN on user experience. The proposed solution is lightweight, completely distributed, does not depend on the collaboration from Facebook, does not have a central point of failure, it offers (with some limitations) the same functionality as Facebook, and apart from some simple settings, the solution is almost transparent to the user. Thorough experiments, with an extended set of parameters, we have confirmed the feasibility of the proposal and have shown a very limited time-overhead experienced by the user while browsing Facebook pages. Mauro Conti, Arbnor Hasani, Bruno Crispo |
ACM Trans. Web | 3 |
| 2012 | Memoirs of a browser: a cross-browser detection model for privacy-breaching extensionsabstractWeb browsers are undoubtedly one of the most popular user applications. This is even more evident in recent times, with Google introducing a platform where the browser is the only application provided to the user. With their modular and extensible architecture, modern browsers are also an appealing platforms for third-party software developers, who can easily publish new extensions to extend any standard web browser functionality. Extendability is a crucial feature that makes web browsers a very attractive service platform. From a security perspective, however, extensions opened up new opportunities for attacks. Most extensions do not require any special privilege to be installed, despite their ability to access all the user private data. Delegating the decision about extension's security to trusted parties is not a conclusive solution, given that privacy-breaching behavior has been found even in store-approved extensions [1]. Cristiano Giuffrida, Stefano Ortolani, Bruno Crispo |
AsiaCCS | 3 |
| 2012 | Demonstrating the effectiveness of MOSES for separation of execution modesabstractIn this paper, we describe a demo of a light virtualisation solution for Android phones. We named our solution MOSES (MOde-of-uses SEcurity Separation). MOSES is a policy-based framework for enforcing software isolation of applications and data. In MOSES, it is possible to define distinct security profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. One of the main characteristics of MOSES is the dynamic switching from one security profile to another. Each profile is associated with a context as well. Through the smartphones sensors, MOSES is able to detect changes in context and to dynamically switch to the security profile associated with the current context. Our current implementation of MOSES shows minimal overhead compared to standard Android in terms of latencies and battery consumption. Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes, Yury Zhauniarovich |
CCS | 3 |
| 2012 | Efficient run-time solving of RBAC user authorization queries: pushing the envelopeabstractThe User Authorization Query (UAQ) Problem for Role- Based Access Control (RBAC) amounts to determining a set of roles to be activated in a given session in order to achieve some permissions while satisfying a collection of authorization constraints governing the activation of roles. Techniques ranging from greedy algorithms to reduction to (variants of) the propositional satisfiability (SAT) problem have been used to tackle the UAQ problem. Unfortunately, available techniques su er two major limitations that seem to question their practical usability. On the one hand, authorization constraints over multiple sessions or histories are not considered. On the other hand, the experimental evaluations of the various techniques are not satisfactory since they do not seem to scale to larger RBAC policies. Alessandro Armando, Silvio Ranise, Fatih Turkmen, Bruno Crispo |
CODASPY | 4 |
| 2012 | MOSES: supporting operation modes on smartphonesabstractSmartphones are very effective tools for increasing the productivity of business users. With their increasing computational power and storage capacity, smartphones allow end users to perform several tasks and be always updated while on the move. As a consequence, end users require that their personal smartphones are connected to their work IT infrastructure. Companies are willing to support employee-owned smartphones because of the increase in productivity of their employees. However, smartphone security mechanisms have been discovered to offer very limited protection against malicious applications that can leak data stored on them. This poses a serious threat to sensitive corporate data. In this paper we present MOSES, a policy-based framework for enforcing software isolation of applications and data on the Android platform. In MOSES, it is possible to define distinct security profiles within a single smartphone. Each security profile is associated with a set of policies that control the access to applications and data. One of the main characteristics of MOSES is the dynamic switching from one security profile to another. Giovanni Russello, Mauro Conti, Bruno Crispo, Earlence Fernandes |
SACMAT | 3 |
| 2012 | NoisyKey: Tolerating Keyloggers via Keystrokes Hiding
Stefano Ortolani, Bruno Crispo |
HotSec | 2 |
| 2012 | Design and implementation of a confidentiality and access control solution for publish/subscribe systems
Mihaela Ion, Giovanni Russello, Bruno Crispo |
Comput. Networks | 3 |
| 2012 | CRêPE: A System for Enforcing Fine-Grained Context-Related Policies on AndroidabstractCurrent smartphone systems allow the user to use only marginally contextual information to specify the behavior of the applications: this hinders the wide adoption of this technology to its full potential. In this paper, we fill this gap by proposing CRêPE, a fine-grained Context-Related Policy Enforcement System for Android. While the concept of context-related access control is not new, this is the first work that brings this concept into the smartphone environment. In particular, in our work, a context can be defined by: the status of variables sensed by physical (low level) sensors, like time and location; additional processing on these data via software (high level) sensors; or particular interactions with the users or third parties. CRêPE allows context-related policies to be set (even at runtime) by both the user and authorized third parties locally (via an application) or remotely (via SMS, MMS, Bluetooth, and QR-code). A thorough set of experiments shows that our full implementation of CRêPE has a negligible overhead in terms of energy consumption, time, and storage, making our system ready for a production environment. Mauro Conti, Bruno Crispo, Earlence Fernandes, Yury Zhauniarovich |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | ESPOON: Enforcing Encrypted Security Policies in Outsourced EnvironmentsabstractThe enforcement of security policies in outsourced environments is still an open challenge for policy-based systems. On the one hand, taking the appropriate security decision requires access to the policies. However, if such access is allowed in an untrusted environment then confidential information might be leaked by the policies. Current solutions are based on cryptographic operations that embed security policies with the security mechanism. Therefore, the enforcement of such policies is performed by allowing the authorised parties to access the appropriate keys. We believe that such solutions are far too rigid because they strictly intertwine authorisation policies with the enforcing mechanism. In this paper, we want to address the issue of enforcing security policies in an untrusted environment while protecting the policy confidentiality. Our solution ESPOON is aiming at providing a clear separation between security policies and the enforcement mechanism. However, the enforcement mechanism should learn as less as possible about both the policies and the requester attributes. Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo |
ARES | 4 |
| 2011 | Poster: ESPOONERBAC: enforcing security policies in outsourced environments with encrypted RBAC
Muhammad Rizwan Asghar, Giovanni Russello, Bruno Crispo |
CCS | 3 |
| 2011 | Mind how you answer me!: transparently authenticating the user of a smartphone when answering or placing a callabstractIn this paper we propose a new biometric measure to authenticate the user of a smartphone: the movement the user performs when answering (or placing) a phone call. The biometric measure leverages features that are becoming commodities in new smartphones, i.e. accelerometer and orientation sensors. We argue that this new biometric measure has a unique feature. That is, it allows a transparent authentication (not requiring an additional specific interaction for this) to check that the user that is answering (or placing) a phone call is the one authorized to do that. At the same time, this biometric measure can also be used as a non transparent authentication method, e.g. the user may need to move the phone as if answering a call, in order to unlock the phone to get access to SMSs or emails. As a consequence of being a biometric measure, an adversary that spies on the movement (e.g. captures it with a camera) and tries to replicate it, will not be granted access to the phone. Mauro Conti, Irina Zachia-Zlatea, Bruno Crispo |
AsiaCCS | 3 |
| 2011 | Virtual private social networksabstractSocial Networking Sites (SNSs) are having a significant impact on the social life of many people - even beyond the millions of people that use them directly. These websites usually allow users to present a profile of themselves through a long list of very detailed information. However, even when such SNSs have advanced privacy policies, users are often not aware of their settings and, on top of that, users cannot abstain from sharing a minimum set of information (e.g. name and location). Such a small set of information has been proven to be enough to completely re-identify a user [22, 25]. Mauro Conti, Arbnor Hasani, Bruno Crispo |
CODASPY | 3 |
| 2011 | Deploy, Adjust and Readjust: Supporting Dynamic Reconfiguration of Policy Enforcement
Gabriela Gheorghe, Bruno Crispo, Roberto Carbone, Lieven Desmet, Wouter Joosen |
Middleware | 2 |
| 2011 | KLIMAX: Profiling Memory Write Patterns to Detect Keystroke-Harvesting Malware
Stefano Ortolani, Cristiano Giuffrida, Bruno Crispo |
RAID | 3 |
| 2011 | Events privacy in WSNs: A new model and its applicationabstractA novel issue resource constrained Wireless Sensor Networks (WSNs) are affected by is context privacy. Indeed, while a few solutions do exist to provide data privacy to WSNs (i.e. to protect message confidentiality), providing context privacy (e.g. preventing an adversary to locate the source of a message) is still an open research problem. This paper attacks the issue providing several contributions. First, a formal model to reason about event privacy in WSNs is introduced. This model also captures dynamic events. Second, we introduce a new realistic class of mobile events a WSN can experience. These events become the target of our privacy preserving efforts. Third, we propose a privacy enforcing solution for the above class of events: the Unobservable Handoff Trajectory (UHT) Protocol. UHT is scalable and distributed. The analysis shows that it is both effective and efficient in terms of the induced overhead. It also minimizes the delay to notify the event sources location to the base station, while preserving the intended degree of privacy. Finally, extensive simulations confirm our findings. Stefano Ortolani, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
WOWMOM | 3 |
| 2010 | A Secure and Scalable Grid-Based Content Management SystemabstractWe present in this paper a secure and scalable Grid-based content management system for the management of high-volume multimedia data in the domain of the publishing industry. This is achieved by leveraging on existing individual solutions, such as the Alfresco content management system, the SRM standard for building scalable solutions based on the Grid and the GridTrust services for building trustworthy and secure Grid systems. Our solution brings closer the use of the Grid to the enterprise community within the context of a real world use case scenario. The solution facilitates the fine-grained usage control of the storage resources and a reputation-based matching between resource policies and users' past behaviour. Benjamin Aziz, Álvaro Enrique Arenas, Giovanni Cortese, Bruno Crispo, Silvio Causetti |
ARES | 4 |
| 2010 | An implementation of event and filter confidentiality in pub/sub systems and its application to e-healthabstractThe publish/subscribe model offers a loosely-coupled communication paradigm where applications interact indirectly and asynchronously. Publisher applications generate events that are forwarded to subscriber applications by a network of brokers. Subscribers register by specifying filters that brokers match against events as part of the routing process. Brokers might be deployed on untrusted servers where malicious entities can get access to events and filters. Supporting confidentiality of events and filters in this setting is still an open challenge. First of all, it is desirable that publishers and subscribers do not share secret keys, such a requirement being against the loose-coupling of the model. Second, brokers need to route events by matching encrypted events against encrypted filters. This should be possible even with very complex filters. Existing solutions do not fully address these issues. This work describes the implementation of a novel schema that supports (i) confidentiality for events and filters; (ii) filters that express very complex constraints on events even if brokers are not able to access any information on both events and filters; (iii) and finally, does not require publishers and subscribers to share keys. We then describe an e-Health application scenario for monitoring patients with chronic diseases and show how our encryption schema can be used to provide confidentiality of the patients' personal and medical data, and control who can receive the patients' data and under which conditions. Mihaela Ion, Giovanni Russello, Bruno Crispo |
CCS | 3 |
| 2010 | Time Warp: How Time Affects Privacy in LBSs
Luciana Marconi, Roberto Di Pietro, Bruno Crispo, Mauro Conti |
ICICS | 3 |
| 2010 | Combining Enforcement Strategies in Service Oriented Architectures
Gabriela Gheorghe, Bruno Crispo, Daniel Schleicher, Tobias Anstett, Frank Leymann, Ralph Retter, Ganna Monakova |
ICSOC | 2 |
| 2010 | CRePE: Context-Related Policy Enforcement for Android
Mauro Conti, Vu Thien Nga Nguyen, Bruno Crispo |
ISC | 3 |
| 2010 | Reasoning about Relation Based Access ControlabstractRelation Based Access Control (RelBAC) is an access control model that places permissions as first class concepts. Under this model, we discuss in this paper how to formalize typical access control policies with Description Logics. Important security properties, i.e., Separation of Duties (SoD) and Chinese Wall are studied and formally represented in RelBAC. To meet the needs of automated tools for administrators, we show that RelBAC can formalize and answer queries about access control requests and administrative checks resorting to the reasoning services of the underlying Description Logic. Alessandro Artale, Bruno Crispo, Fausto Giunchiglia, Fatih Turkmen, Rui Zhang 0006 |
NSS | 2 |
| 2010 | Bait Your Hook: A Novel Detection Technique for Keyloggers
Stefano Ortolani, Cristiano Giuffrida, Bruno Crispo |
RAID | 3 |
| 2010 | Providing Confidentiality in Content-based Publish/subscribe Systems
Mihaela Ion, Giovanni Russello, Bruno Crispo |
SECRYPT | 3 |
| 2010 | Supporting Publication and Subscription Confidentiality in Pub/Sub Networks
Mihaela Ion, Giovanni Russello, Bruno Crispo |
SecureComm | 3 |
| 2009 | Towards a Theory of White-Box Security
Amir Herzberg, Haya Schulmann, Amitabh Saxena, Bruno Crispo |
SEC | 4 |
| 2009 | Efficient integration of fine-grained access control and resource brokering in grid
Pietro Mazzoleni, Bruno Crispo, Swaminathan Sivasubramanian, Elisa Bertino |
J. Supercomput. | 2 |
| 2008 | Enforcing DRM policies across applicationsabstractIn this paper we present Trishul-UCON (T-UCON), a DRM system based on the UCON_ABC model. T-UCON is designed to be capable of enforcing not only application-specific policies, as any existing software-based DRM solution does, but also DRM policies across applications. This is achieved by binding the DRM policy only to the content it protects with no relations to the application(s) which will use this content. Furthermore, to guarantee that the policy is continuously enforced, we designed T-UCON as a JVM-based middleware that mediates the usage requests of any Java application to the protected content. Each request is granted or denied according to the content policy. We illustrate the unique features of T-UCON by using typical examples of DRM policies such as the pay-per-use and the use only N times scenarios. Preliminary results on the overhead of our solution are also provided. Srijith Krishnan Nair, Andrew S. Tanenbaum, Gabriela Gheorghe, Bruno Crispo |
Digital Rights Management Workshop | 4 |
| 2008 | Floodgate: A Micropayment Incentivized P2P Content Delivery NetworkabstractAs the sale of digital content is moving more and more online, the content providers are beginning to realize that bandwidth infrastructures are not easily scalable. The emergence of peer-to-peer content delivery networks present these providers with a way to overcome this limitation. However, such networks have so far been ad-hoc in nature. One of the main reason for this has been the lack of incentives for end users to contribute their bandwidth to the network. In this paper we present the design and implementation of a peer-to-peer protocol named Floodgate that provides a micropayment based incentive for peers to contribute their bandwidth. Floodgate implements an optimistic fair exchange protocol and is designed to be resilient against targeted attacks. Performance measurements, including those conducted over the PlanetLab infrastructure, show that Floodgate's security and cryptographic overheads are low when compared against the standard BitTorrent implementation. Srijith Krishnan Nair, Erik Zentveld, Bruno Crispo, Andrew S. Tanenbaum |
ICCCN | 3 |
| 2008 | P-CDN: Extending access control capabilities of P2P systems to provide CDN servicesabstractNew important emerging business paradigms, such as ldquoservice virtualizationrdquo can be made easy and convenient by the use of P2P systems. In these paradigms, often the owners of the services are different (and independent) from the owners of the resources used to offer such services. In comparison to centralized servers, P2P systems can conveniently offer higher availability and more bandwidth as they harness the computing and network resources of thousands of hosts in a decentralized fashion. Despite these useful features and their success in the research community, P2P systems are still not very popular in the business world. The main reason for such a skepticism is their lack of proper security. In this paper, we address this issue by motivating and explaining the benefits of adding access control in P2P systems to make them more suitable and flexible as a technical platform for providing third party services. We propose an architecture augmented with access control mechanisms to enable content delivery on a P2P system. The proposed architecture is shaped according to CDN requirements. We have also tested the feasibility of our approach with a prototype implementation and the preliminary results show that our system can scale well also in the presence of very large number of policies. Fatih Turkmen, Pietro Mazzoleni, Bruno Crispo, Elisa Bertino |
ISCC | 3 |
| 2008 | An efficient weak secrecy scheme for network coding data dissemination in VANETabstractVehicular networks create a new communication paradigm that enables to exploit the movement of cars to disseminate content. If network coding is used, vehicles have much more flexibility in content sharing and the system stability and scalability are promoted also in presence of mobility. Along this line, we propose an efficient mechanism to provide secrecy of the information. Traditional approaches based on encryption decrease the cooperation willingness of intermediate nodes, which have no expectation of recovering the file. Our scheme is based on obfuscation by processing and polluting the original file so that only the intended recipients, informed of corrupted blocks, can recover the information timely. We present several alternatives to efficiently provide weak secrecy and to foster cooperation. We simulate the file distribution in a vehicular network and show that the proposed scheme enhances content distribution in term of downloading speed and it is much more efficient than the ones that use encryption. Mario Gerla, Roberto G. Cascella, Bruno Crispo, Roberto Battiti |
PIMRC | 4 |
| 2008 | XACML Policy Integration AlgorithmsabstractXACML is the OASIS standard language specifically aimed at the specification of authorization policies. While XACML fits well with the security requirements of a single enterprise (even if large and composed by multiple departments), it does not address the requirements of virtual enterprises in which several autonomous subjects collaborate by sharing their resources to provide better services to customers. In this article we highlight such limitation, and we propose an XACML extension, the policy integration algorithms, to address them. In the article we also present the implementation of a system that makes use of the policy integration algorithms to securely replicate information in a P2P-like environment. In our solution, the data replication process considers the policies specified by both the owners of the data shared and the peers sharing data storage. Pietro Mazzoleni, Bruno Crispo, Swaminathan Sivasubramanian, Elisa Bertino |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2007 | Extending the Java Virtual Machine to Enforce Fine-Grained Security Policies in Mobile DevicesabstractThe growth of the applications and services market for mobile devices is currently slowed down by the lack of a flexible and reliable security infrastructure. The development and adoption of a new generation of mobile applications depends on the end user's ability to finely manage system security and control application's behavior. The virtual execution environment for mobile software and services should support the security needs of users and applications. This paper proposes an extension to the security architecture of the java virtual machine for mobile systems, to support fine-grained policy specification and run-time enforcement. Access control decisions are based on system state, application and system history data, as well as request specific parameters. The prototype implementation is running on desktops, as emulator, and on mobile devices, proving the high level of flexibility and security, with excellent performance provided by the extended architecture. Iulia Ion, Boris Dragovic, Bruno Crispo |
ACSAC | 3 |
| 2007 | ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems
Damiano Bolzoni, Bruno Crispo, Sandro Etalle |
LISA | 2 |
| 2007 | A Hybrid PKI-IBC Based Ephemerizer System
Srijith Krishnan Nair, Muhammad Torabi Dashti, Bruno Crispo, Andrew S. Tanenbaum |
SEC | 3 |
| 2007 | Design and implementation of a secure wide-area object middleware
Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum, Arno Bakker |
Comput. Networks | 2 |
| 2006 | Security for the Mythical Air-Dropped Sensor NetworkabstractThe research area of very large scale wireless sensor networks made of low-cost sensors is gaining a lot of interest as witnessed by the large number of published papers. The security aspects of such networks are addressed as well, and in particular many security papers investigating the security aspects of such networks make important assumptions about the capabilities of low-cost sensors. Consequently, the techniques proposed in the current literature to provide security properties for this low-cost wireless sensor networks are heavily shaped by such assumptions. In this position paper, we challenge such assumptions by presenting the results of an experiment we conducted using sensors representative of low cost units. And we show that the same security properties can be better provided using techniques based on application-specific knowledge, heuristics and statistical tests. Finally, we show that one of the most highly cited application scenarios to motivate such techniques, the air-dropped sensor network, is likely to be more a myth than a realistic scenario for low-cost sensors. Chandana Gamage, Kemal Bicakci, Bruno Crispo, Andrew S. Tanenbaum |
ISCC | 3 |
| 2006 | A Platform for RFID Security and Privacy Administration (Awarded Best Paper!)
Melanie R. Rieback, Georgi Gaydadjiev, Bruno Crispo, Rutger F. H. Hofman, Andrew S. Tanenbaum |
LISA | 3 |
| 2006 | Is Your Cat Infected with a Computer Virus?abstractRFID systems as a whole are often treated with suspicion, but the input data received from individual RFID tags is implicitly trusted. RFID attacks are currently conceived as properly formatted but fake RFID data; however no one expects an RFID tag to send a SQL injection attack or a buffer overflow. This paper is meant to serve as a warning that data from RFID tags can be used to exploit back-end software systems. RFID middleware writers must therefore build appropriate checks (bounds checking, special character filtering, etc.), to prevent RFID middleware from suffering all of the well-known vulnerabilities experienced by the Internet. Furthermore, as a proof of concept, this paper presents the first self-replicating RFID virus. This virus uses RFID tags as a vector to compromise backend RFID middleware systems, via a SQL injection attack Melanie R. Rieback, Bruno Crispo, Andrew S. Tanenbaum |
PerCom | 2 |
| 2006 | XACML policy integration algorithms: not to be confused with XACML policy combination algorithms!abstractXACML is the OASIS standard language for the specification of authorization and entitlement policies. However, while XACML well addresses security requirements of a single enterprise (even if large and composed by multiple departments), it does not address the requirements of virtual enterprises built through collaboration of several autonomous subjects sharing their resources. In this paper we highlight such limitations and we propose an XACML extension, the policy integration algorithm, to address them. In the paper we also discuss in which respect the process of comparing two XACML policies differs from the process used to compare other business rules. Pietro Mazzoleni, Elisa Bertino, Bruno Crispo |
SACMAT | 3 |
| 2006 | RFID malware: Design principles and examples
Melanie R. Rieback, Patrick N. D. Simpson, Bruno Crispo, Andrew S. Tanenbaum |
Pervasive Mob. Comput. | 3 |
| 2005 | Counting Abuses Using Flexible Off-line Credentials
Kemal Bicakci, Bruno Crispo, Andrew S. Tanenbaum |
ACISP | 2 |
| 2005 | RFID Guardian: A Battery-Powered Mobile Device for RFID Privacy Management
Melanie R. Rieback, Bruno Crispo, Andrew S. Tanenbaum |
ACISP | 2 |
| 2004 | Symmetric Key Authentication Services Revisited
Bruno Crispo, Bogdan C. Popescu, Andrew S. Tanenbaum |
ACISP | 1 |
| 2004 | A DRM security architecture for home networksabstractThis paper describes a security architecture allowing digital rights management in home networks consisting of consumer electronic devices. The idea is to allow devices to establish dynamic groups, so called "Authorized Domains", where legally acquired copyrighted content can seamlessly move from device to device. This greatly improves the end-user experience, preserves "fair use" expectations, and enables the development of new business models by content providers. Key to our design is a hybrid compliance checking and group establishment protocol, based on pre-distributed symmetric keys, with minimal reliance on public key cryptographic operations. Our architecture does not require continuous network connectivity between devices, and allows for efficient and flexible key updating and revocation. Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum, Frank Kamperman |
Digital Rights Management Workshop | 2 |
| 2004 | Support for multi-level security policies in DRM architecturesabstractDigital rights management systems allow copyrighted content to be commercialized in digital format without the risk of revenue loss due to piracy. Making such systems secure is no easy task, given that content needs to be protected while accessed through electronic devices in the hands of potentially malicious end-users; in this context, intrusion tolerance becomes a very useful system property. In this paper we point out a limitation shared by all current DRM architectures, namely their weakness in reacting to possible device compromise and confining the damage caused by such a compromise. As a solution, we propose a paradigm shift - moving from the original DRM system model where all devices are equally trustworthy and have discretionary control over all protected content, to a new model where information flow is controlled through a multi-level security policy that differentiates between devices based on their tamper-resistance properties. We show that besides improved intrusion-tolerance, supporting such policies has other advantages, such as the ability to define more flexible business models for supplying content. We also show that for a given DRM architecture, the type authentication protocol used when accepting new devices in the system has a big impact on how well multi-level security policies can be supported, and that a number of protocols currently being considered are not very well suited for this job. Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum |
NSPW | 2 |
| 2004 | Security for grid-based computing systems issues and challengesabstractGrid systems were initially developed for supporting scientific computations. Today, companies, users and researchers are looking at ways to use the Grid approach to commercial uses and for applications in many different areas. Security in grid systems however has not been much addressed and yet is an important prerequisite to really make grid systems usable in a variety of commercial applications.The goal of this panel is to explore relevant security issues, with special emphasis on access control, for grid-based computing systems. The panel will discuss security requirements that are specific to grid-based systems and set these systems apart from conventional distributed systems, and outline directions for future research. Questions addressed by the panel include the following ones: Elisa Bertino, Bruno Crispo, James B. D. Joshi, Wengliang (Kevin) Du, Ravi S. Sandhu |
SACMAT | 2 |
| 2003 | Secure Data Replication over Untrusted Hosts
Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum |
HotOS | 2 |
| 2003 | A Certificate Revocation Scheme for a Large-Scale Highly Replicated Distributed SystemabstractA common way to protect objects in distributed systems is to issue authorization certificates to users, which they present to gain access. In some situations a way is needed to revoke existing certificates. Current methods, such as having a master revocation list, have been designed to work efficiently with identity certificates, and to not take into account the delegation of certificate-issuing rights required when implementing complex administrative hierarchies for large distributed applications. In this paper we present a novel mechanism for revoking authorization certificates based on clustering users and servers, and present arguments showing that it is more efficient than other methods. We also discuss a way for probabilistically auditing the use of the revocation mechanism proposed to reduce the chances of any component behaving maliciously. Bogdan C. Popescu, Bruno Crispo, Andrew S. Tanenbaum |
ISCC | 2 |
| 2002 | Individual Authentication in Multiparty Communications
Francesco Bergadano, Davide Cavagnino, Bruno Crispo |
Comput. Secur. | 3 |
| 2001 | Reasoning about Accountability within Delegation
Bruno Crispo, Giancarlo Ruffo |
ICICS | 1 |
| 2001 | Delegation Protocols for Electronic CommerceabstractMany commercial and financial activities in the real-life require reliable mechanisms to provide accountability for the transactions that has been executed. If electronic commerce aim to substitute or support similar activities in the electronic world, it has to provide the same degree of accountability. Despite this requirement being crucial, we observe that many existing security mechanisms and protocols are not designed by considering accountability as a fundamental property. We show that this is true, particularly in the case of delegation protocols. Then to address the problem, we explicitly introduce accountability in delegation by defining a new semantics and by designing a new protocol that help to eliminate this lack of accountability. Bruno Crispo |
ISCC | 1 |
| 2000 | WWW security and trusted third party services
Bruno Crispo, Peter Landrock, Václav Matyás Jr. |
Future Gener. Comput. Syst. | 1 |
| 1998 | High Dictionary Compression for Proactive Password CheckingabstractThe important problem of user password selection is addressed and a new proactive password-checking technique is presented. In a training phase, a decision tree is generated based on a given dictionary of weak passwords. Then, the decision tree is used to determine whether a user password should be accepted. Experimental results described here show that the method leads to a very high dictionary compression (up to 1000 to 1) with low error rates (of the order of 1%). A prototype implementation, called ProCheck, is made available online. We survey previous approaches to proactive password checking, and provide an in-depth comparison. Francesco Bergadano, Bruno Crispo, Giancarlo Ruffo |
ACM Trans. Inf. Syst. Secur. | 2 |
| 1997 | Proactive Password Checking with Decision TreesabstractThe important problem of user password selection is addressed and a new proactive password checking technique is presented.In a training phase, a decision tree is generated based on a given dictionary of weak passwords.Then, the decision tree is used to determine whether a user password should be accepted.Experimental results described here show that the method leads to very high dictionary compression (from 100 to 3 in the average) with low error rates (of the order of 1%).We survey previous approaches to proactive password checking, and provide an in-depth comparison. Francesco Bergadano, Bruno Crispo, Giancarlo Ruffo |
CCS | 2 |
| 1997 | Strong Authentication and Privacy with Standard BrowsersabstractA framework for secure WWW client/server communication is proposed. Strong end-to-end encryption and authentication is achieved by means of public key techniques. A particular certification infrastructure is developed that helps assign responsibilities in case of disputes. Such issues are increasin gly important in WWW applications and are not dealt with in a satisfactory way by current certification schemes. Actual communication is done with the HTTP protocol unchanged and by using standard commercial browsers, because widespread usability is a goal. Encryption and authentication is done separately based on the execution of applets running on the client machine. Francesco Bergadano, Bruno Crispo, T. Mark A. Lomas |
J. Comput. Secur. | 2 |