Reza Curtmola

dblp:c/RezaCurtmola · DBLP profile ↗
← Back
46ranked-venue papers
6as first author
9since 2021 · last 2026
0000-0002-7586-0932ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 3 first-author · 8 since 2021Computer networks · 6 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 4Systems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Leaky Apps: Targeted Deanonymization on Mobile Phones
abstract
Targeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-targeted attacks against the inferred identities.
Robert Blacha, Yossef Oren, Reza Curtmola
CODASPY3
2026 SourceFabric: Consistent and Scalable Security Policies for Git Repositories
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Marcela S. Melara, Dennis Roellke, Reza Curtmola, Justin Cappos
EuroS&P5
2025 Rethinking Trust in Forge-Based Git Security
Aditya Sirish A Yelgundhalli, Patrick Zielinski, Reza Curtmola, Justin Cappos
NDSS3
2025 Contention-Based Side Channels Enable Faster and Stealthier Browsing History Sniffing
abstract
Web browsers are implicitly trusted to handle a large amount of private user information. One such piece of private information, a user's browsing history, is maintained by browsers and is used to provide a popular usability feature: Web links are rendered using different styles depending on whether the URLs they point to have been visited or not. Unfortunately, this feature can be abused by malicious webpages in order to extract users’ browsing history. We present new browsing history sniffing attacks through two contention-based side channels which are new in this context: Last-level CPU cache contention, and GPU execution unit contention. The attacks are robust and can be executed successfully against the popular Chrome browser. Compared to prior work which uses the rendering performance as a side channel, our work achieves an attack rate increase of up to 30x. The new attacks are stealthier, because the side channels we use do not slow down the browser's rendering rate. In addition, we revisit the existing sniffing attacks based on the rendering performance side channel, and show how their attack rate can also be increased by a significant amount. Finally, we discuss the root cause of history sniffing attacks and point out solutions.
Mojtaba Zaheri, Yossef Oren, Reza Curtmola
IEEE Trans. Dependable Secur. Comput.3
2023 Towards verifiable web-based code review systems
abstract
Although code review is an essential step for ensuring the quality of software, it is surprising that current code review systems do not have mechanisms to protect the integrity of the code review process. We uncover multiple attacks against the code review infrastructure which are easy to execute, stealthy in nature, and can have a significant impact, such as allowing malicious or buggy code to be merged and propagated to future releases. To improve this status quo, in this work we lay the foundations for securing the code review process. Towards this end, we first identify a set of key design principles necessary to secure the code review process. We then use these principles to propose SecureReview , a security mechanism that can be applied on top of a Git-based code review system to ensure the integrity of the code review process and provide verifiable guarantees that the code review process followed the intended review policy. We implement SecureReview as a Chrome browser extension for GitHub and Gerrit. Our security analysis shows that SecureReview is effective in mitigating the aforementioned attacks. An experimental evaluation shows that the SecureReview implementation only adds a slight storage overhead ( i.e., less than 0.0006 of the repository size).
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
J. Comput. Secur.3
2022 Bootstrapping Trust in Community Repository Projects
Sangat Vaidya, Santiago Torres-Arias, Justin Cappos, Reza Curtmola
SecureComm4
2022 Targeted Deanonymization via the Cache Side Channel: Attacks and Defenses
Mojtaba Zaheri, Yossef Oren, Reza Curtmola
USENIX Security Symposium3
2022 DFPS: A Distributed Mobile System for Free Parking Assignment
abstract
Cruising for vacant curbside parking spaces causes waste of time, frustration, waste of fuel, and pollution. This problem has been addressed by centralized solutions that perform parking assignments and communicate them to drivers’ smart phones. These solutions suffer, however, from two intrinsic problems: scalability, as the server has to perform intensive computation and communication with the drivers; and privacy, as the drivers have to disclose their destinations to the server. This article proposes DFPS, a distributed mobile system for free parking assignment. DFPS solves the scalability problem by using the drivers’ smart phones to cooperatively compute the parking assignments, and a centralized dispatcher to receive and distribute parking requests to the network of smart phones. The phones of the parked drivers in DFPS are structured in a K-D tree to serve parking requests in a distributed fashion. DFPS removes the computation from the dispatcher and substantially reduces its communication load. DFPS solves the privacy problem through an entropy-based cloaking technique that runs on drivers’ smart phones and conceals drivers’ destinations from the dispatcher. The evaluation demonstrates that DFPS is scalable and obtains better travel time than a centralized system, while protecting the privacy of drivers’ destinations.
Abeer Hakeem, Reza Curtmola, Xiaoning Ding, Cristian Borcea
IEEE Trans. Mob. Comput.2
2021 Leakuidator: Leaky Resource Attacks and Countermeasures
Mojtaba Zaheri, Reza Curtmola
SecureComm (2)2
2020 Towards adding verifiability to web-based Git repositories
abstract
Web-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature – the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended. In this paper, we show a range of high-impact attacks that can be executed stealthily when developers use the web UI of a Git hosting service to perform common actions such as editing files or merging branches. We then propose le-git-imate , a defense against these attacks, which enables users to protect their commits using Git’s standard commit signing mechanism. We implement le-git-imate as a Chrome browser extension. le-git-imate does not require changes on the server side and can thus be used immediately. It also preserves current workflows used in Github/GitLab and does not require the user to leave the browser, and it allows anyone to verify that the server’s actions faithfully follow the user’s requested actions. Moreover, experimental evaluation using the browser extension shows that le-git-imate has comparable performance with Git’s standard commit signature mechanism. With our solution in place, users can take advantage of GitHub/GitLab’s web-based features without sacrificing security, thus paving the way towards verifiable web-based Git repositories.
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
J. Comput. Secur.3
2020 Design and Implementation of an Overlay File System for Cloud-Assisted Mobile Apps
abstract
With cloud assistance, mobile apps can offload their resource-demanding computation tasks to the cloud. This leads to a scenario where computation tasks in the same program run concurrently on both the mobile device and the cloud. An important challenge is to ensure that the tasks are able to access and share the files on both the mobile and the cloud in a manner that is efficient, consistent, and transparent to locations. Existing distributed file systems and network file systems do not satisfy these requirements. Current systems for offloading tasks either do not support file access for offloaded tasks or do not offload tasks with file access. The paper addresses this issue by designing and implementing an application-level file system called Overlay File System (OFS). To improve efficiency, OFS maintains and buffers local copies of data sets on both the cloud and the mobile device. OFS ensures consistency and guarantees that all the reads get the latest data. It combines write-invalidate and write-update policies to effectively reduce the network traffic incurred by invalidating/updating stale data copies and to reduce the execution delay when the latest data cannot be accessed locally. To guarantee location transparency, OFS creates a unified view of the data that is location independent and is accessible as local storage. We overcome the challenges caused by the special features of mobile systems on an application-level file system, like the lack of root privilege and state loss when application is killed due to the shortage of resource and implement an easy to deploy prototype of OFS. The paper tests the OFS prototype on Android OS with a real mobile app and real mobile user traces. Extensive experiments show that OFS can effectively support consistent file accesses from computation tasks, no matter whether they are on a mobile device or offloaded to the cloud. In addition, OFS reduce both file access latency and network traffic incurred by file accesses.
Nafize R. Paiker, Jianchen Shan, Cristian Borcea, Narain H. Gehani, Reza Curtmola, Xiaoning Ding
IEEE Trans. Cloud Comput.5
2019 Auditable Compressed Storage
Iraklis Leontiadis, Reza Curtmola
ISC2
2019 Multi-destination vehicular route planning with parking and traffic constraints
abstract
This paper aims to provide an efficient solution for people in a city who drive their cars to visit several destinations, where they need to park for a while, but do not care about the visiting order. This instance of the multi-destination route planning problem is novel in terms of its constraints: the real-time traffic conditions and the real-time free parking conditions in the city. The paper proposes a novel Multi-Destination Vehicle Route Planning (MDVRP) system to optimize the travel time for all drivers. MDVRP's design has two components: a mobile app running on the drivers' smart phones that submits real-time route requests and guides the drivers toward destinations, and a server in the cloud that optimizes the routes by finding the most efficient order to visit the destinations. MDVRP uses TDTSP-FPA, an algorithm that finds the fastest route to the next destination and also assigns free curbside parking spaces that minimize the total travel time for drivers. We evaluate MDVRP using a driver trip dataset that contains real vehicular mobility traces of over two million drivers from the city of Cologne, Germany. By learning the spatio-temporal distribution of real driver destinations from this dataset, we build a novel experimental platform that simulates real, multi-destination driver trips. Extensive simulations executed over this platform demonstrate that TDTSP-FPA delivers the best performance when compared to three baseline algorithms.
Abeer Hakeem, Narain H. Gehani, Xiaoning Ding, Reza Curtmola, Cristian Borcea
MobiQuitous4
2019 Commit Signatures for Centralized Version Control Systems
Sangat Vaidya, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
SEC3
2019 in-toto: Providing farm-to-table guarantees for bits and bytes
Santiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola, Justin Cappos
USENIX Security Symposium4
2019 The Moitree middleware for distributed mobile-cloud computing
Hillol Debnath, Mohammad A. Khan, Nafize R. Paiker, Xiaoning Ding, Narain H. Gehani, Reza Curtmola, Cristian Borcea
J. Syst. Softw.6
2018 le-git-imate: Towards Verifiable Web-based Git Repositories
abstract
Web-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature - the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended.
Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos
AsiaCCS3
2018 Context-Aware File Discovery System for Distributed Mobile-Cloud Apps
abstract
Recent research has proposed middleware to enable efficient distributed apps over mobile-cloud platforms. This paper presents a Context-Aware File Discovery Service (CAFDS) that allows distributed mobile-cloud applications to find and access files of interest shared by collaborating users. CAFDS enables programmers to search for files defined by context and content features, such as location, creation time, or the presence of certain object types within an image file. CAFDS provides low-latency through a cloud-based metadata server, which uses a decision tree to locate the nearest files that satisfy the context and content features requested by applications. We implemented CAFDS in Android and Linux. Experimental results show CAFDS achieves substantially lower latency than peer-to-peer solutions that cannot leverage context information.
Nafize R. Paiker, Xiaoning Ding, Reza Curtmola, Cristian Borcea
CloudCom3
2018 Secure Storage with Replication and Transparent Deduplication
abstract
We seek to answer the following question: To what extent can we deduplicate replicated storage? To answer this question, we design ReDup, a secure storage system that provides users with strong integrity, reliability, and transparency guarantees about data that is outsourced at cloud storage providers. Users store multiple replicas of their data at different storage servers, and the data at each storage server is deduplicated across users. Remote data integrity mechanisms are used to check the integrity of replicas. We consider a strong adversarial model, in which collusions are allowed between storage servers and also between storage servers and dishonest users of the system. A cloud storage provider (CSP) could store less replicas than agreed upon by contract, unbeknownst to honest users. ReDup defends against such adversaries by making replica generation to be time consuming so that a dishonest CSP cannot generate replicas on the fly when challenged by the users.
Iraklis Leontiadis, Reza Curtmola
CODASPY2
2018 Sentio: Distributed Sensor Virtualization for Mobile Apps
abstract
This paper presents Sentio, a distributed middle-ware designed to provide mobile apps with seamless connectivity to remote sensors when the sensing code and the sensors are not physically on the same device, e.g., when the sensing code is offloaded to the cloud. Sentio presents the apps with virtual sensors that are mapped to remote physical sensors. Virtual sensors can be composed into higher-level sensors, which fuse sensing data from multiple physical sensors. Furthermore, they are mapped to the best available physical sensors when the app starts and re-mapped transparently to other physical sensors at runtime in response to context changes. Sentio was designed to work without modifications to the operating system and to provide low-latency access to remote sensors, which is beneficial to apps with real time-requirements such as mobile games. We have built a prototype of Sentio on Android. We have also developed four apps based on Sentio to understand the programming effort and evaluate the performance. The development of the apps shows that complex sensing tasks can be implemented quickly, benefiting from Sentio's high-level API. The experimental results show that Sentio achieves good real-time performance.
Hillol Debnath, Narain H. Gehani, Xiaoning Ding, Reza Curtmola, Cristian Borcea
PerCom4
2017 Remote data integrity checking with server-side repair
abstract
Distributed storage systems store data redundantly at multiple servers that are geographically spread throughout the world. This basic approach would be sufficient in handling server failure due to natural faults, because when one server fails, data from healthy servers can be used to restore the d esired redundancy level. However, in a setting where servers are untrusted and can behave maliciously, data redundancy must be used in tandem with Remote Data Checking (RDC) to ensure that the redundancy level of the storage systems is maintained over time. All previous RDC schemes for distributed systems impose a heavy burden on the data owner (client) during data maintenance: To repair data at a faulty server, the data owner needs to first download a large amount of data, re-generate the data to be stored at a new server, and then upload this data at a new healthy server. We work on a new concept, namely, server-side repair, in which the servers are responsible to repair the corruption, whereas the client acts as a lightweight repair coordinator during repair. We propose two novel RDC schemes for replication-based distributed storage systems, RDC-SR and ERDC-SR, which enable server-side repair (thus taking advantage of the premium connections available between a CSP’s data centers) and minimize the load on the client side. Although both schemes achieve a similar objective, RDC-SR assumes that the computational power of the CSP will not grow over time, whereas ERDC-SR relaxes this assumption and considers a CSP whose computational power can increase over time. Our guidelines on choosing the parameters of these schemes provide insights on their practical usage and also reveal that, whereas ERDC-SR can handle more powerful adversaries, it also imposes a minimal file size. Finally, we evaluate the performance of the two schemes. For the RDC-SR scheme, we build a prototype on the Amazon cloud and provide experimental results to support its effectiveness. Our prototype for RDC-SR built on Amazon AWS validates the practicality of this new approach. For the ERDC-SR scheme, our analytical performance analysis shows that the scheme is an order of magnitude more efficient than a simple extension of RDC-SR to defend against the stronger adversarial model.
Bo Chen 0028, Reza Curtmola
J. Comput. Secur.2
2016 An Overlay File System for cloud-assisted mobile applications
abstract
With cloud assistance, a mobile application can offload its resource-demanding computation tasks to the cloud (public cloud, cloudlet, or personal cloud, etc). This leads to a scenario where computation tasks in the same application run concurrently on both the mobile device and the cloud. These tasks need to save, read, and write files on both the mobile device and the cloud. An important challenge is to ensure that the tasks are able to access and share the files in a manner that is efficient, consistent, and transparent to locations. The paper addresses this issue by designing an application-level file system called Overlay File System (OFS). To improve efficiency, OFS maintains and buffers local copies of data sets on both the cloud and the mobile device. OFS ensures consistency and guarantees that all the reads get the latest data. It combines write-invalidate and write-update policies to effectively reduce the network traffic incurred by invalidating/updating stale data copies and to reduce the application delay when the latest data cannot be accessed locally. To guarantee location transparency, OFS creates an unified view of the data that is location independent and is accessible as local storage. Our experiments show that OFS can effectively support task offloading and efficient execution of offloaded tasks by significantly decreasing both file access latency and network traffic incurred by file accesses.
Jianchen Shan, Nafize R. Paiker, Xiaoning Ding, Narain H. Gehani, Reza Curtmola, Cristian Borcea
MSST5
2016 On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities
Santiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin Cappos
USENIX Security Symposium3
2015 Towards Server-side Repair for Erasure Coding-based Distributed Storage Systems
abstract
Erasure coding is one of the main mechanisms to add redundancy in a distributed storage system, by which a file with k data segments is encoded into a file with n coded segments such that any k coded segments can be used to recover the original k data segments. Each coded segment is stored at a storage server. Under an adversarial setting in which the storage servers can exhibit Byzantine behavior, remote data checking (RDC) can be used to ensure that the stored data remains retrievable over time. The main previous RDC scheme to offer such strong security guarantees, HAIL, has an inefficient repair procedure, which puts a high load on the data owner when repairing even one corrupt data segment.
Bo Chen 0028, Anil Kumar Ammula, Reza Curtmola
CODASPY3
2015 Collaborative Bluetooth-based location authentication on smart phones
Manoop Talasila, Reza Curtmola, Cristian Borcea
Pervasive Mob. Comput.2
2014 Auditable Version Control Systems
Bo Chen 0028, Reza Curtmola
NDSS2
2013 Towards self-repairing replication-based storage systems using untrusted clouds
abstract
Distributed storage systems store data redundantly at multiple servers which are geographically spread throughout the world. This basic approach would be sufficient in handling server failure due to natural faults, because when one server fails, data from healthy servers can be used to restore the desired redundancy level. However, in a setting where servers are untrusted and can behave maliciously, data redundancy must be used in tandem with Remote Data Checking (RDC) to ensure that the redundancy level of the storage systems is maintained over time.
Bo Chen 0028, Reza Curtmola
CODASPY2
2012 Robust dynamic remote data checking for public clouds
abstract
Remote Data Checking (RDC) allows clients to efficiently check the integrity of data stored at untrusted servers. This allows data owners to assess the risk of outsourcing data in the public cloud, making RDC a valuable tool for data auditing. Early RDC schemes have focused on static data, whereas later schemes such as DPDP support the full range of dynamic operations on the outsourced data, including insertions, modifications, and deletions. Robustness is required for both static and dynamic RDC schemes that rely on spot checking for efficiency. In this paper, we propose the first RDC schemes that provide robustness and, at the same time, support dynamic updates, while requiring small, constant, client storage.
Bo Chen 0028, Reza Curtmola
CCS2
2012 Entropy attacks and countermeasures in wireless network coding
abstract
Multihop wireless networks gain higher performance by using network coding. However, using network coding also introduces new attacks such as the well-studied pollution attacks and less-studied entropy attacks. Unlike in pollution attacks where an attacker injects polluted packets (i.e., packets that are not linear combinations of the packets sent by the source), in entropy attacks an attacker creates non-innovative packets (i.e., packets that contain information already known by the system). In both cases the result is a severe degradation of the system performance. In this paper, we identify two variants of entropy attacks (local and global) and show that while they share some characteristics with pollution attacks and selective forwarding, none of the techniques proposed to defend against such attacks are applicable to entropy attacks because the packets look legitimate and the packet forwarding is stealthy in nature. We propose and evaluate several defenses that vary in detection capabilities and overhead.
Andrew Newell, Reza Curtmola, Cristina Nita-Rotaru
WISEC2
2012 Pollution Attacks and Defenses in Wireless Interflow Network Coding Systems
abstract
We study data pollution attacks in wireless interflow network coding systems. Although several defenses for these attacks are known for intraflow network coding systems, none of them are applicable to interflow coding systems. We formulate a model for interflow network coding that encompasses all the existing systems, and use it to analyze the impact of pollution attacks. Our analysis shows that the effects of pollution attacks depend not only on the network topology, but also on the location and strategy of the attacker nodes. We propose CodeGuard, a reactive attestation-based defense mechanism that uses efficient bit-level traceback and a novel cross-examination technique to unequivocally identify attacker nodes. We analyze the security of CodeGuard and prove that it is always able to identify and isolate at least one attacker node on every occurrence of a pollution attack. We analyze the overhead of CodeGuard and show that the storage, computation, and communication overhead are practical. We experimentally demonstrate that CodeGuard is able to identify attacker nodes quickly (within 500 ms) and restore system throughput to a high level, even in the presence of many attackers, thus preserving the performance of the underlying network coding system.
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru, David K. Y. Yau
IEEE Trans. Dependable Secur. Comput.2
2011 Searchable symmetric encryption: Improved definitions and efficient constructions
abstract
Searchable symmetric encryption (SSE) allows a party to outsource the storage of his data to another party in a private manner, while maintaining the ability to selectively search over it. This problem has been the focus of active research and several security definitions and constructions have been proposed. In this paper we begin by reviewing existing notions of security and propose new and stronger security definitions. We then present two constructions that we show secure under our new definitions. Interestingly, in addition to satisfying stronger security guarantees, our constructions are more efficient than all previous constructions. Further, prior work on SSE only considered the setting where only the owner of the data is capable of submitting search queries. We consider the natural extension where an arbitrary group of parties other than the owner can submit search queries. We formally define SSE in this multi-user setting, and present an efficient construction.
Reza Curtmola, Juan A. Garay 0001, Seny Kamara, Rafail Ostrovsky
J. Comput. Secur.1
2011 Remote data checking using provable data possession
abstract
We introduce a model for provable data possession (PDP) that can be used for remote data checking: A client that has stored data at an untrusted server can verify that the server possesses the original data without retrieving it. The model generates probabilistic proofs of possession by sampling random sets of blocks from the server, which drastically reduces I/O costs. The client maintains a constant amount of metadata to verify the proof. The challenge/response protocol transmits a small, constant amount of data, which minimizes network communication. Thus, the PDP model for remote data checking is lightweight and supports large data sets in distributed storage systems. The model is also robust in that it incorporates mechanisms for mitigating arbitrary amounts of data corruption. We present two provably-secure PDP schemes that are more efficient than previous solutions. In particular, the overhead at the server is low (or even constant), as opposed to linear in the size of the data. We then propose a generic transformation that adds robustness to any remote data checking scheme based on spot checking. Experiments using our implementation verify the practicality of PDP and reveal that the performance of PDP is bounded by disk I/O and not by cryptographic computation. Finally, we conduct an in-depth experimental evaluation to study the tradeoffs in performance, security, and space overheads when adding robustness to a remote data checking scheme.
Giuseppe Ateniese, Randal C. Burns, Reza Curtmola, Joseph Herring, Lea Kissner, Zachary N. J. Peterson, Dawn Song
ACM Trans. Inf. Syst. Secur.3
2011 Practical defenses against pollution attacks in wireless network coding
abstract
Recent studies have shown that network coding can provide significant benefits to network protocols, such as increased throughput, reduced network congestion, higher reliability, and lower power consumption. The core principle of network coding is that intermediate nodes actively mix input packets to produce output packets. This mixing subjects network coding systems to a severe security threat, known as a pollution attack , where attacker nodes inject corrupted packets into the network. Corrupted packets propagate in an epidemic manner, depleting network resources and significantly decreasing throughput. Pollution attacks are particularly dangerous in wireless networks, where attackers can easily inject packets or compromise devices due to the increased network vulnerability. In this article, we address pollution attacks against network coding systems in wireless mesh networks. We demonstrate that previous solutions are impractical in wireless networks, incurring an unacceptable high degradation of throughput. We propose a lightweight scheme, DART, that uses time-based authentication in combination with random linear transformations to defend against pollution attacks. We further improve system performance and propose EDART, which enhances DART with an optimistic forwarding scheme. We also propose efficient attacker identification schemes for both DART and EDART that enable quick attacker isolation and the selection of attacker-free paths, achieving additional performance improvement. A detailed security analysis shows that the probability of a polluted packet passing our verification procedure is very low (less than 0.002% in typical settings). Performance results using the well-known MORE protocol and realistic link quality measurements from the Roofnet experimental testbed show that our schemes improve system performance over 20 times compared with previous solutions.
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru
ACM Trans. Inf. Syst. Secur.2
2011 Secure High-Throughput Multicast Routing in Wireless Mesh Networks
abstract
Recent work in multicast routing for wireless mesh networks has focused on metrics that estimate link quality to maximize throughput. Nodes must collaborate in order to compute the path metric and forward data. The assumption that all nodes are honest and behave correctly during metric computation, propagation, and aggregation, as well as during data forwarding, leads to unexpected consequences in adversarial networks where compromised nodes act maliciously. In this work, we identify novel attacks against high-throughput multicast protocols in wireless mesh networks. The attacks exploit the local estimation and global aggregation of the metric to allow attackers to attract a large amount of traffic. We show that these attacks are very effective against multicast protocols based on high-throughput metrics. We conclude that aggressive path selection is a double-edged sword: While it maximizes throughput, it also increases attack effectiveness in the absence of defense mechanisms. Our approach to defend against the identified attacks combines measurement-based detection and accusation-based reaction techniques. The solution accommodates transient network variations and is resilient against attempts to exploit the defense mechanism itself. A detailed security analysis of our defense scheme establishes bounds on the impact of attacks. We demonstrate both the attacks and our defense using ODMRP, a representative multicast protocol for wireless mesh networks, and SPP, an adaptation of the well-known ETX unicast metric to the multicast setting.
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru
IEEE Trans. Mob. Comput.2
2010 LINK: Location Verification through Immediate Neighbors Knowledge
Manoop Talasila, Reza Curtmola, Cristian Borcea
MobiQuitous2
2010 Tradeoffs between security and communication performance in wireless mesh networks
abstract
In the context of wireless mesh networks (WMNs), we ask the question whether a high level of security can be achieved while providing good communication performance. To answer this question, we examine two techniques designed and shown to improve throughput performance in WMNs: high-throughput routing and network coding. Although the advantages of using these techniques hold in a benign setting, it is not clear whether they can be preserved under an adversarial setting. We analyze these techniques and reveal a wide range of security vulnerabilities. We then investigate whether alternative schemes can be designed to be secure and still preserve most of the advantages achieved in benign settings.
Reza Curtmola, Jing Dong 0006, Cristina Nita-Rotaru
WOWMOM1
2009 Practical defenses against pollution attacks in intra-flow network coding for wireless mesh networks
abstract
Recent studies show that network coding can provide significant benefits to network protocols, such as increased throughput, reduced network congestion, higher reliability, and lower power consumption. The core principle of network coding is that intermediate nodes actively mix input packets to produce output packets. This mixing subjects network coding systems to a severe security threat, known as a \emph{pollution attack}, where attacker nodes inject corrupted packets into the network. Corrupted packets propagate in an epidemic manner, depleting network resources and significantly decreasing throughput. Pollution attacks are particularly dangerous in wireless networks, where attackers can easily inject packets or compromise devices due to the increased network vulnerability.
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru
WISEC2
2009 Secure network coding for wireless mesh networks: Threats, challenges, and directions
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru
Comput. Commun.2
2009 BSMR: Byzantine-Resilient Secure Multicast Routing in Multihop Wireless Networks
abstract
Multihop wireless networks rely on node cooperation to provide multicast services. The multihop communication offers increased coverage for such services but also makes them more vulnerable to insider (or Byzantine) attacks coming from compromised nodes that behave arbitrarily to disrupt the network. In this work, we identify vulnerabilities of on-demand multicast routing protocols for multihop wireless networks and discuss the challenges encountered in designing mechanisms to defend against them. We propose BSMR, a novel secure multicast routing protocol designed to withstand insider attacks from colluding adversaries. Our protocol is a software-based solution and does not require additional or specialized hardware. We present simulation results that demonstrate that BSMR effectively mitigates the identified attacks.
Reza Curtmola, Cristina Nita-Rotaru
IEEE Trans. Mob. Comput.1
2008 MR-PDP: Multiple-Replica Provable Data Possession
abstract
Many storage systems rely on replication to increase the availability and durability of data on untrusted storage systems. At present, such storage systems provide no strong evidence that multiple copies of the data are actually stored. Storage servers can collude to make it look like they are storing many copies of the data, whereas in reality they only store a single copy. We address this shortcoming through multiple-replica provable data possession (MR-PDP): A provably-secure scheme that allows a client that stores t replicas of a file in a storage system to verify through a challenge-response protocol that (1) each unique replica can be produced at the time of the challenge and that (2) the storage system uses t times the storage required to store a single replica. MR-PDP extends previous work on data possession proofs for a single copy of a file in a client/server storage system (Ateniese et al., 2007). Using MR-PDP to store t replicas is computationally much more efficient than using a single-replica PDP scheme to store t separate, unrelated files (e.g., by encrypting each file separately prior to storing it). Another advantage of MR-PDP is that it can generate further replicas on demand, at little expense, when some of the existing replicas fail.
Reza Curtmola, Randal C. Burns, Giuseppe Ateniese
ICDCS1
2008 On the Pitfalls of High-Throughput Multicast Metrics in Adversarial Wireless Mesh Networks
abstract
Recent work in multicast routing for wireless mesh networks has focused on metrics that estimate link quality to maximize throughput. Nodes must collaborate in order to compute the path metric and forward data. The assumption that all nodes are honest and behave correctly during metric computation, propagation, and aggregation, as well as during data forwarding, leads to unexpected consequences in adversarial networks where compromised nodes act maliciously. In this work we identify novel attacks against high-throughput multicast protocols in wireless mesh networks. The attacks exploit the local estimation and global aggregation of the metric to allow attackers to attract a large amount of traffic. We show that these attacks are very effective against multicast protocols based on high-throughput metrics. This leads us to conclude that aggressive path selection is a double-edged sword: it maximizes throughput, but in the absence of protection mechanisms it also increases attack effectiveness. Our approach to mitigate the identified attacks combines measurement-based detection and accusation- based reaction techniques. The solution also accommodates transient network variations and is resilient against attempts to exploit the defense mechanism itself. We demonstrate the attacks and our defense using ODMRP, a representative multicast protocol for wireless mesh networks, and SPP, an adaptation of the well- known ETX unicast metric to the multicast setting.
Jing Dong 0006, Reza Curtmola, Cristina Nita-Rotaru
SECON2
2008 ODSBR: An on-demand secure Byzantine resilient routing protocol for wireless ad hoc networks
abstract
Ah hoc networks offer increased coverage by using multihop communication. This architecture makes services more vulnerable to internal attacks coming from compromised nodes that behave arbitrarily to disrupt the network, also referred to as Byzantine attacks. In this work, we examine the impact of several Byzantine attacks performed by individual or colluding attackers. We propose ODSBR, the first on-demand routing protocol for ad hoc wireless networks that provides resilience to Byzantine attacks caused by individual or colluding nodes. The protocol uses an adaptive probing technique that detects a malicious link after log n faults have occurred, where n is the length of the path. Problematic links are avoided by using a route discovery mechanism that relies on a new metric that captures adversarial behavior. Our protocol never partitions the network and bounds the amount of damage caused by attackers. We demonstrate through simulations ODSBR's effectiveness in mitigating Byzantine attacks. Our analysis of the impact of these attacks versus the adversary's effort gives insights into their relative strengths, their interaction, and their importance when designing multihop wireless routing protocols.
Baruch Awerbuch, Reza Curtmola, David Holmer, Cristina Nita-Rotaru, Herbert Rubens
ACM Trans. Inf. Syst. Secur.2
2007 Provable data possession at untrusted stores
abstract
We introduce a model for provable data possession (PDP) that allows a client that has stored data at an untrusted server to verify that the server possesses the original data without retrieving it. The model generates probabilistic proofs of possession by sampling random sets of blocks from the server, which drastically reduces I/O costs. The client maintains a constant amount of metadata to verify the proof. The challenge/response protocol transmits a small, constant amount of data, which minimizes network communication. Thus, the PDP model for remote data checking supports large data sets in widely-distributed storage system.
Giuseppe Ateniese, Randal C. Burns, Reza Curtmola, Joseph Herring, Lea Kissner, Zachary N. J. Peterson, Dawn Song
CCS3
2006 Searchable symmetric encryption: improved definitions and efficient constructions
abstract
Searchable symmetric encryption (SSE) allows a party to outsource the storage of its data to another party (a server) in a private manner, while maintaining the ability to selectively search over it. This problem has been the focus of active research in recent years. In this paper we show two solutions to SSE that simultaneously enjoy the following properties:
Reza Curtmola, Juan A. Garay 0001, Seny Kamara, Rafail Ostrovsky
CCS1
2005 On the Performance and Analysis of DNS Security Extensions
Reza Curtmola, Aniello Del Sorbo, Giuseppe Ateniese
CANS1
2005 On the Survivability of Routing Protocols in Ad Hoc Wireless Networks
abstract
Survivable routing protocols are able to provide service in the presence of attacks and failures. The strongest attacks that protocols can experience are attacks where adversaries have full control of a number of authenticated nodes that behave arbitrarily to disrupt the network, also referred to as Byzantine attacks. This work examines the survivability of ad hoc wireless routing protocols in the presence of several Byzantine attacks: black holes, flood rushing, wormholes and overlay network wormholes. Traditional secure routing protocols that assume authenticated nodes can always be trusted, fail to defend against such attacks. Our protocol, ODSBR, is an on-demand wireless routing protocol able to provide correct service in the presence of failures and Byzantine attacks. We demonstrate through simulation its effectiveness in mitigating such attacks. Our analysis of the impact of these attacks versus the adversary’s effort gives insights into their relative strengths, their interaction and their importance when designing wireless routing protocols.
Baruch Awerbuch, Reza Curtmola, David Holmer, Herbert Rubens, Cristina Nita-Rotaru
SecureComm2