EDBT 2026 Demo / reviewers in the wild / expert
Thomas Engel 0001
dblp:e/ThomasEngel
· DBLP profile ↗
117ranked-venue papers
0as first author
17since 2021 · last 2024
0000-0002-7374-3927ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 39 · 4 since 2021Security and privacy · 19 · 2 since 2021Human-computer interaction and ubiquitous computing · 10Artificial intelligence and machine learning · 6 · 2 since 2021Systems, architecture and hardware · 6Applied, interdisciplinary, general and emerging computing · 6 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Why Privacy-Preserving Protocols Are Sometimes Not Enough: A Case Study of the Brisbane Toll Collection InfrastructureabstractThe use of Electronic Toll Collection (ETC) systems is on the rise, as these systems have a significant impact on reducing operational costs. Toll service providers (TSPs) access various information, including drivers' IDs and monthly toll fees, to bill drivers. While this is legitimate, such information could be misused for other purposes violating drivers' privacy, most prominent, to infer drivers' movement patterns. To this end, privacy-preserving ETC (PPETC) schemes have been designed to minimize the amount of information leaked while still allowing drivers to be charged. We demonstrate that merely applying such PPETC schemes to current ETC infrastructures may not ensure privacy. This is due to the (inevitable) minimal information leakage, such as monthly toll fees, which can potentially result in a privacy breach when combined with additional background information, such as road maps and statistical data. To show this, we provide a counterexample using the case study of Brisbane's ETC system. We present two attacks: the first, being a variant of the presence disclosure attack, tries to disclose the toll stations visited by a driver during a billing period as well as the frequency of visits. The second, being a stronger attack, aims to discover cycles of toll stations (e.g., the ones passed during a commute from home to work and back) and their frequencies. We evaluate the success rates of our attacks using real parameters and statistics from Brisbane's ETC system. In one scenario, the success rate of our toll station disclosure attack can be as high as 94%. This scenario affects about 61% of drivers. In the same scenario, our cycle disclosure attack can achieve a success rate of 51%. It is remarkable that these high success rates can be achieved by only using minimal information as input, which is, e.g., available to a driver's payment service provider or bank, and by following very simple attack strategies without exploiting optimizations. As a further contribution, we analyze how the choice of various parameters, such as the set of toll rates, the number of toll stations, and the billing period length, impact a driver's privacy level regarding our attacks. Amirhossein Adavoudi Jolfaei, Andy Rupp, Stefan Schiffner, Thomas Engel 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Multi-Process Federated Learning With Stacking for Securing 6G-V2X Network Slicing at Cross-BordersabstractBeing part of the 6G ecosystem vision, Connected and Automated Vehicles (CAVs) will enjoy sophisticated tailored services offering road safety and entertainment for users. As one of the 6G cornerstones, Network Slicing (NS) allows the creation of various customized 6G-V2X (Vehicle-to-Everything) use cases on the same physical infrastructure. However, 6G-NS advances can open up breaches to cyber-attacks aiming to break 6G-V2X Network slices to inflict maximum damage on CAVs and their users. Crossing borders, where CAVs leave their V2X-NS (V2X Network Slice) in the Home Mobile Network Operator (H-MNO) toward a similar V2X-NS in the Visited MNO (V-MNO), is an attractive opportunity to exploit by attackers. Detecting and mitigating attacks, in this case, becomes a priority, confronted by NS requirements and MNOs not ready to share their private data. To this end, this paper proposes a 3GPP-compliant privacy preservation collaborative learning scheme for 6G-NS security, focusing on V2X-NS cross-border areas. Our scheme leverages multi-process Federated Learning (FL) architecture to build efficient V2X-NS security-related models while preserving 6G V2X-NS isolation. In addition, it uses differential privacy-enabled stacking to build up attack detection knowledge at the V2X-NSs and MNOs levels while ensuring privacy preservation. We conducted an experimental study on the 5G-NIDD dataset, which is one of the most realistic publicly available 5G datasets. Our results demonstrate that multi-process FL with stacking can deliver high accuracy while ensuring isolation between 6G-V2X-NSs and privacy preservation between H-MNO and V-MNO. Abdelwahab Boualouache, Amirhossein Adavoudi Jolfaei, Thomas Engel 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | Reinforcement Learning-Based Security Orchestration for 5G-V2X Network Slicing at Cross-BordersabstractAs part of the 5G, Connected and Automated Vehicles (CAVs) will benefit from Network Slicing (NS) in several tailored 5G- Vehicle-to-Everything (V2X) services running on the same physical infrastructure. However, the use of 5G- NS may also increase the risk of cyber-attacks that could compromise 5G-V2X network slices (5G-V2X-NSs) and cause significant harm to CAV's passengers. This risk is particularly high at cross-borders, where CAVs move from their Home Mobile Network Operator (H-MNO) to a Visited MNO (V-MNO), with similar 5G-V2X-NSs in place. Therefore, deploying security services to neutralize 5G- V2X NS threats in this scenario is mandatory. However, if H-MNO and V-MNO act independently, deploying these security services could be inefficient and may result in increased memory, processing, and network resource consumption. Thus, MNOs should collaborate to orchestrate their security services to neutralize 5G-V2X NS attacks and optimize their costs efficiently. In this context, this paper proposes a novel approach to enhance the security of 5G-V2X NS at cross-borders using Reinforcement Learning (RL) based security orchestration. Specifically, we trained and deployed an RL agent interacting with both H-MNO and V-MNO. The RL agent efficiently deploys security services to effectively remove threats, optimize resource utilization, and minimize the impact on 5G-V2X-NSs. The performance results show that the RL-based security orchestration neutralizes threats with an average success rate of almost 100%. Additionally, resource consumption is minimal at less than 8 %, and the acceptable impact on 5G- V2X - NSs is negligible, averaging less than 12 %. Abdelwahab Boualouache, Abdelaziz Amara Korba, Sidi-Mohammed Senouci, Yacine Ghamri-Doudane, Thomas Engel 0001 |
GLOBECOM | 5 |
| 2023 | Evaluation of PTP Security Controls on gPTPabstractIn recent years, the scientific community has been focusing on deterministic Ethernet, which has helped drive the adoption of Time-Sensitive Networking (TSN) standards. Precision Time Protocol (PTP), specified in IEEE1588 [1], is a TSN standard that enables network devices to be synchronized with a degree of precision that is noticeably higher than other Ethernet synchronization protocols [2]. Generic Precision Time Protocol (gPTP) [3], a profile of PTP, is designed to have low latency and jitter, which makes it suitable for industrial applications. However, like PTP, gPTP does not have any built-in security measures. In this work, we assess the efficacy of additional security mechanisms that were suggested for inclusion in IEEE 1588 (PTP) 2019 [1]. The analysis consists of implementing these security mechanisms on a physical gPTP-capable testbed and evaluating them on several high-risk attacks against gPTP [4]. Mahdi Fotouhi, Alessio Buscemi, Florian Jomrich, Christian Köbel, Thomas Engel 0001 |
ISCC | 5 |
| 2023 | An Intrusion Detection System Against Rogue Master Attacks on gPTPabstractDue to the promise of deterministic Ethernet networking, Time Sensitive Network (TSN) standards are gaining popularity in the vehicle on-board networks sector. Among these, Generalized Precision Time Protocol (gPTP) allows network devices to be synchronized with a greater degree of precision than other synchronization protocols, such as Network Time Protocol (NTP). However, gPTP was developed without security measures, making it susceptible to a variety of attacks. Adding security controls is the initial step in securing the protocol. However, due to current gPTP design limitations, this countermeasure is insufficient to protect against all types of threats. In this paper, we present a novel supervised Machine Learning (ML)-based pipeline for the detection of high-risk rogue master attacks. Alessio Buscemi, Manasvi Ponaka, Mahdi Fotouhi, Florian Jomrich, Christian Köbel, Thomas Engel 0001 |
VTC2023-Spring | 6 |
| 2023 | Examining the Hydra: Simultaneously Shared Links in Tor and the Effects on its PerformanceabstractTor is a popular privacy-enhancing technology that allows anonymous communication using onion routing. However, such technologies are only helpful if used; therefore, performance is an important aspect. One of the main performance bottlenecks of Tor is the cross-circuit interference (CCI) problem. Tor multiplexes multiple circuits over a single Transport Layer Security (TLS) 1.2 connection if they share a path segment (link). Therefore, they have the same congestion window, which can yield unfair bandwidth allocation. However, there has been little work in understanding this problem in more depth. This paper investigates the number of simultaneously shared links in the current Tor network, which are the root cause of CCI. We developed a novel shared links simulator called SALSA to investigate this problem. Our results show that 3.7 % of active links are shared, and the involving Onion Routers (ORs) have the most common bandwidth capabilities. Additionally, we show that the internal circuits and exit policy influence the CCI problem. Furthermore, we model the number of shared links when the demand grows further and show that the number of shared links can go up to 16 %. Finally, we run Shadow simulations with a 25 % down-scaled Tor network and show that a network without shared links is faster. Sebastian Pahl, Florian Adamsky, Daniel Kaiser 0001, Thomas Engel 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | A Survey on Privacy-Preserving Electronic Toll Collection Schemes for Intelligent Transportation SystemsabstractAs part of Intelligent Transportation Systems (ITS), Electronic toll collection (ETC) is a type of toll collection system (TCS) which is getting more and more popular as it can not only help to finance the government’s road infrastructure but also it can play a crucial role in pollution reduction and congestion management. As most of the traditional ETC schemes (ETCS) require identifying their users, they enable location tracking. This violates user privacy and poses challenges regarding the compliance of such systems with privacy regulations such as the EU General Data Protection Regulation (GDPR). So far, several privacy-preserving ETC schemes have been proposed. To the best of our knowledge, this is the first survey that systematically reviews and compares various characteristics of these schemes, including components, technologies, security properties, privacy properties, and attacks on ETCS. This survey first categorizes the ETCS based on two technologies, GNSS and DSRC. Then under these categories, the schemes are classified based on whether they provide formal proof of security and support security analysis. We also demonstrate which schemes specifically are/are not resistant to collusion and physical attacks. Then, based on these classifications, several limitations and shortcomings in privacy-preserving ETCS are revealed. Finally, we identify several directions for future research. Amirhossein Adavoudi Jolfaei, Abdelwahab Boualouache, Andy Rupp, Stefan Schiffner, Thomas Engel 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | k-Pareto Optimality-Based Sorting with Maximization of ChoiceabstractTopological sorting is an important technique in numerous practical applications, such as information retrieval, recommender systems, optimization, etc. In this paper, we introduce a problem of generalized topological sorting with maximization of choice, that is, of choosing a subset of items of a predefined size that contains the maximum number of equally preferable options (items) with respect to a dominance relation. We formulate this problem in a very abstract form and prove that sorting by k-Pareto optimality yields a valid solution. Next, we show that the proposed theory can be useful in practice. We apply it during the selection step of genetic optimization and demonstrate that the resulting algorithm outperforms existing state-of-the-art approaches such as NSGA-II and NSGA-III. We also demonstrate that the provided general formulation allows discovering interesting relationships and applying the developed theory to different applications. Jean Ruppert, Marharyta Aleksandrova, Thomas Engel 0001 |
AISTATS | 3 |
| 2022 | Towards Normalizing The Design Phase of Data Preprocessing Pipelines For IoT DataabstractWe introduce a set of tools that normalize, regulate, unify and structure the notion, practices and design of data preprocessing. The design tools enhance the reproducibility of data preprocessing plans and pipelines and help achieve quality assurance while reducing the complexity of the phase. There is a synergy between the proposed design toolset and the enablers of Internet of Things Applications (IoT) as the former provide preprocessing pipelines that effectively address the challenges of distributed edge systems including limited resources and data privacy, biases and ownership. Our empirical results highlight the impact of the proposed toolset in not only obtaining quality data but also improving prediction accuracy and reducing the consumption of resources (e.g., energy) within an IoT context. Amal Tawakuli, Thomas Engel 0001 |
IEEE Big Data | 2 |
| 2022 | On Frame Fingerprinting and Controller Area Networks Security in Connected VehiclesabstractModern connected vehicles are equipped with a large number of sensors, which enable a wide range of services that can improve overall traffic safety and efficiency. However, remote access to connected vehicles also introduces new security issues affecting both inter and intra-vehicle communications. In fact, existing intra-vehicle communication systems, such as Controller Area Network (CAN), lack security features, such as encryption and secure authentication for Electronic Control Units (ECUs). Instead, Original Equipment Manufacturers (OEMs) seek security through obscurity by keeping secret the proprietary format with which they encode the information. Recently, it has been shown that the reuse of CAN frame IDs can be exploited to perform CAN bus reverse engineering without physical access to the vehicle, thus raising further security concerns in a connected environment. This work investigates whether anonymizing the frames of each newly released vehicle is sufficient to prevent CAN bus reverse engineering based on frame ID matching. The results show that, by adopting Machine Learning techniques, anonymized CAN frames can still be fingerprinted and identified in an unknown vehicle with an accuracy of up to 80 %. Alessio Buscemi, Ion Turcanu, German Castignani, Thomas Engel 0001 |
CCNC | 4 |
| 2022 | Transforming IoT Data Preprocessing: A Holistic, Normalized and Distributed ApproachabstractData preprocessing is an integral part of Artificial Intelligence (AI) pipelines. It transforms raw data into input data that fulfill algorithmic criteria and improve prediction accuracy. As the adoption of Internet of Things (IoT) gains more momentum, the data volume generated from the edge is exponentially increasing that far exceeds any expansion of infrastructure. Social responsibilities and regulations (e.g., GDPR) must also be adhered when handling IoT data. In addition, we are currently witnessing a shift towards distributing AI to the edge. The aforementioned reasons render the distribution of data preprocessing to the edge an urgent requirement. In this paper, we introduce a modern data preprocessing framework that consists of two main parts. Part1 is a design tool that reduces the complexity and costs of the data preprocessing phase for AI via generalization and normalization. The design tool is a standard template that maps specific techniques into abstract categories and highlights dependencies between them. In addition, it presents a holistic notion of data preprocessing that is not limited to data cleaning. The second part is an IoT tool that adopts the edge-cloud collaboration model to progressively improve the quality of the data. It includes a synchronization mechanism that ensures adaptation to changes in data characteristics and a coordination mechanism that ensures correct and complete execution of preprocessing plans between the cloud and the edge. The paper includes an empirical analysis of the framework using a developed prototype and an automotive use-case. Our results demonstrate reductions in resource consumption (e.g., energy, bandwidth) while maintaining the value and integrity of the data. Amal Tawakuli, Daniel Kaiser 0001, Thomas Engel 0001 |
SenSys | 3 |
| 2022 | Federated Learning-based Inter-slice Attack Detection for 5G-V2X Sliced NetworksabstractAs a leading enabler of 5G, Network Slicing (NS) aims at creating multiple virtual networks on the same shared and programmable physical infrastructure. Integrated with 5GVehicle-to-Everything (V2X) technology, NS enables various isolated 5G-V2X networks with different requirements such as autonomous driving and platooning. This combination has generated new attack surfaces against Connected and Automated Vehicles (CAVs), leading them to road hazards and putting users’ lives in danger. More specifically, such attacks can either intra-slice targeting the internal service within each V2X Network Slice (V2X-NS) or inter-slice targeting the cross V2X-NSs and breaking the isolation between them. However, detecting such attacks is challenging, especially inter-slice V2X attacks where security mechanisms should maintain privacy preservation and NS isolation. To this end, this paper addresses detecting inter-slice V2X attacks. To do so, we leverage both Virtual Security as a Service (VSaS) concept and Deep learning (DL) together with Federated learning (FL) to deploy a set of DL-empowered security Virtual Network Functions (sVNFs) over V2X-NSs. Our privacy preservation scheme is hierarchical and supports FL-based collaborative learning. It also integrates a game-theory-based mechanism to motivate FL clients (CAVs) to provide high-quality DL local models. We train, validate, and test our scheme using a publicly available dataset. The results show our scheme’s accuracy and efficiency in detecting inter-slice V2X attacks. Abdelwahab Boualouache, Thomas Engel 0001 |
VTC Fall | 2 |
| 2022 | Deep Learning-based Intra-slice Attack Detection for 5G-V2X Sliced NetworksabstractConnected and Automated Vehicles (CAVs) represent one of the main verticals of 5G to provide road safety, road traffic efficiency, and user convenience. As a key enabler of 5G, Network Slicing (NS) aims to create Vehicle-to-Everything (V2X) network slices with different network requirements on a shared and programmable physical infrastructure. However, NS has generated new network threats that might target CAVs leading to road hazards. More specifically, such attacks may target either the inner functioning of each V2X-NS (intra-slice) or break the NS isolation. In this paper, we aim to deal with the raised question of how to detect intra-slice V2X attacks. To do so, we leverage both Virtual Security as a Service (VSaS) concept and deep learning (DL) to deploy a set of DL-empowered security Virtual Network Functions (sVNFs) within V2X-NSs. These sVNFs are in charge of detecting such attacks, thanks to a DL model that we also build in this work. The proposed DL model is trained, validated, and tested using a publicly available dataset. The results show the efficiency and accuracy of our scheme to detect intra-slice V2X attacks. Abdelwahab Boualouache, Taki Eddine Toufik Djaidja, Sidi-Mohammed Senouci, Yacine Ghamri-Doudane, Bouziane Brik, Thomas Engel 0001 |
VTC Spring | 6 |
| 2022 | The Impact of Distributed Data Preprocessing on Automotive Data StreamsabstractVehicles have transformed into sophisticated computing machines that not only serve the objective of transportation from point A to point B but serve other objectives including improved experience, safer journey, automated and more efficient and sustainable transportation. With such sophistication comes complex applications and enormous volumes of data generated from diverse types of vehicle sensors and components. Automotive data is not sedentary but moves from the edge (the vehicle) to the cloud (e.g., infrastructure of the vehicle manufacturers, national highway agencies, insurance companies, etc.). The exponential increase in data volume and variety generated in modern vehicles far exceeds the rate of infrastructure scaling and expansion. To mitigate this challenge, the computational and storage capacities of vehicle components can be leveraged to perform in-vehicle operations on the data to either prepare and transform (preprocess) the data or extract information from (process) the data. This paper focuses on distributing data preprocessing to the vehicle and highlights the benefits and impact of the distribution including on the consumption of resources (e.g., energy). Amal Tawakuli, Thomas Engel 0001 |
VTC Fall | 2 |
| 2022 | MQTT-MFA: A Message Filter Aggregator to Support Massive IoT Traffic Over SatelliteabstractOne of the main application scenario that the upcoming 5G systems are expected to support is Internet of Things (IoT) traffic backhauling. With the exponential increase of devices, it follows the critical challenge of handling the huge data volume that they produce. Terrestrial networks may not be sufficient for that, or not always available. Satellites then come into play, and they can provide the ubiquitous coverage targeted by 5G. On the other side, aggregation can be an efficient strategy to reduce the amount of traffic, and use network resources in an efficient manner. Building on that, in this work, we consider a hybrid IoT-satellite network architecture for collecting message queuing telemetry transport (MQTT) traffic. We design an advanced filter, namely, MQTT message filter aggregator (MQTT-MFA), that performs MQTT topics aggregation in close proximity of MQTT Publishers before data are sent over the satellite link. The developed MQTT-MFA implementation leverages on MQTT bridge, and it is compliant with Mosquitto, an open-source MQTT broker. Extensive simulation results have demonstrated that MQTT-MFA requires only 10% of the TCP/IP overhead generated in a baseline architecture (where the bridge is not set up) and 1/4 number of bytes to transmit the same amount of information, when compression of the data payload is also enabled. Ridha Soua, Maria Rita Palattella, André Stemper, Thomas Engel 0001 |
IEEE Internet Things J. | 4 |
| 2021 | A Near-Field-based TPMS Solution for Heavy Commercial Vehicle EnvironementabstractThis paper proposes a Near-Field Communication (NFC) based solution for Tire pressure monitoring system (TPMS) in heavy commercial vehicles instead of the high frequency Far-Field communication used in conventional TPMS. We simulate the application environment represented by the tire and wheel combination, and the proposed system transmitter to evaluate the signal propagation using finite element method (FEM) analysis; incorporating highly detailed models of the transmitter and the wheel and tire combination. The simulation demonstrates the adverse effect of the application environment on the signal propagation, and shows the merit of using NF-based communication compared to conventional state of the art TPMS solutions. Ahmad Rida Tawakuli, Ridha Soua, Thomas Engel 0001 |
VTC Fall | 3 |
| 2021 | Evaluation of TPMS Signal Propagation in a Heavy Commercial Vehicle EnvironementabstractThis paper aims to evaluate the performance of the state-of-the-art Tire Pressure Monitoring System (TPMS) in a heavy commercial vehicle environment. We adopt a novel qualitative approach to determine the radio frequency (RF) signal propagation characteristics of high frequency antennas used in a state of the art TPMS solution [1]. We outline the effect of both the tire and wheel on the RF signal and system function, and compare it to the propagation in a free space. The paper quantifies the antenna RF propagation using finite element method (FEM) and using realistic models of the sensor, the wheel and the commercial tire. The adverse effect of the heavy vehicle environment on the signal propagation is described. Finally, the paper questions the feasibility of conventional TPMS in commercial vehicle, and calls for novel communication technologies to enable future use case such as smart tires. Ahmad Rida Tawakuli, Ridha Soua, Thomas Engel 0001 |
VTC Fall | 3 |
| 2020 | Synchronized Preprocessing of Sensor DataabstractSensor data whether collected for machine learning, deep learning or other applications must be preprocessed to fit input requirements or improve performance and accuracy. Data preparation is an expensive, resource consuming and complex phase often performed centrally on raw data for a specific application. The dataflow between the edge and the cloud can be enhanced in terms of efficiency, reliability and lineage by preprocessing the datasets closer to their data sources. We propose a dedicated data preprocessing framework that distributes preprocessing tasks between a cloud stage and two edge stages to create a dataflow with progressively improving quality. The framework handles heterogenous data and dynamic preprocessing plans simultaneously targeting diverse applications and use cases from different domains. Each stage autonomously executes sensor specific preprocessing plans in parallel while synchronizing the progressive execution and dynamic updates of the preprocessing plans with the other stages. Our approach minimizes the workload on central infrastructures and reduces the resources used for transferring raw data from the edge. We also demonstrate that preprocessing data can be sensor specific rather than application specific and thus can be performed prior to knowing a specific application. Amal Tawakuli, Daniel Kaiser 0001, Thomas Engel 0001 |
IEEE BigData | 3 |
| 2020 | TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingabstractWebsite fingerprinting (WFP) aims to infer information about the content of encrypted and anonymized connections by observing patterns of data flows based on the size and direction of packets. By collecting traffic traces at a malicious Tor entry node --- one of the weakest adversaries in the attacker model of Tor --- a passive eavesdropper can leverage the captured meta-data to reveal the websites visited by a Tor user. As recently shown, WFP is significantly more effective and realistic than assumed. Concurrently, former WFP defenses are either infeasible for deployment in real-world settings or defend against specific WFP attacks only. Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
CCS | 7 |
| 2020 | Toward an SDN-based Data Collection Scheme for Vehicular Fog ComputingabstractWith the integration of fog networks and vehicular networks, Vehicular Fog Computing (VFC) is a promising paradigm to the efficient collection of data for improving safety, mobility, and driver experience during journeys. To this end, we exploit the Software-Defined Networking (SDN) paradigm to propose a fully-programmable, self-configurable, and context-aware data collection scheme for VFC. This scheme leverages a stochastic model to dynamically estimate the number of fog stations to be deployed. Our simulation results demonstrate that our proposed scheme provides lower latency and higher resiliency compared to classical data collection schemes. Abdelwahab Boualouache, Ridha Soua, Thomas Engel 0001 |
ICC | 3 |
| 2020 | Enhancing CoAP Group Communication to Support mMTC Over Satellite NetworksabstractGiven that several services can benefit from the adoption of a group communication model, the IETF has specifically standardized the usage of CoAP group communication. However, CoAP responses are still sent in unicast from each single CoAP server to the CoAP client, which results in a substantial traffic load. Such problem becomes more severe in integrated IoT-Satellite networks given the limited bandwidth of the satellite return channel and the large number of IoT devices in a massive MTC (mMTC) scenario. To reduce network traffic overhead in group communication and improve the network responsiveness, this paper proposes an aggregation scheme for the CoAP group communication in combination with Observer pattern and proxying. Results obtained by using the openSAND emulator and CoAPthon library corroborate the merit of our optimization in terms of overhead reduction and delay. Ridha Soua, Maria Rita Palattella, André Stemper, Thomas Engel 0001 |
ICC | 4 |
| 2020 | Out-of-the-box Multipath TCP as a Tor Transport Protocol: Performance and Privacy ImplicationsabstractThe transport design of Tor - the most popular anonymization network - has been identified as a key factor responsible for its performance unfairness. In Tor, traffic from multiple users is multiplexed in a single TCP connection between two relays. While this has positive effects on privacy, it negatively influences performance and is characterized by unfairness as TCP congestion control gives all the multiplexed Tor traffic as little of the available bandwidth as it gives to every single TCP connection that competes for the same resource. To counter this, we propose to use multipath TCP (MPTCP). It allows for better resource utilization and increases throughput of the Tor traffic to a fairer extent. Our evaluation in realworld settings shows that using out-of-the-box MPTCP leads to 15% performance gain. We analyze the privacy implications of MPTCP in Tor settings and discuss potential threats and mitigation strategies. Wladimir De la Cadena, Daniel Kaiser 0001, Andriy Panchenko 0001, Thomas Engel 0001 |
NCA | 4 |
| 2020 | Security and Performance Implications of BGP Rerouting-Resistant Guard Selection Algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Thomas Engel 0001, Andriy Panchenko 0001 |
SEC | 3 |
| 2020 | SDN-based Misbehavior Detection System for Vehicular NetworksabstractVehicular networks are vulnerable to a variety of internal attacks. Misbehavior Detection Systems (MDS) are preferred over the cryptography solutions to detect such attacks. However, the existing misbehavior detection systems are static and do not adapt to the context of vehicles. To this end, we exploit the Software-Defined Networking (SDN) paradigm to propose a context-aware MDS. Based on the context, our proposed system can tune security parameters to provide accurate detection with low false positives. Our system is Sybil attack-resistant and compliant with vehicular privacy standards. The simulation results show that, under different contexts, our system provides a high detection ratio and low false positives compared to a static MDS. Abdelwahab Boualouache, Ridha Soua, Thomas Engel 0001 |
VTC Spring | 3 |
| 2020 | How Road and Mobile Networks Correlate: Estimating Urban Traffic Using HandoversabstractWe propose a novel way of linking mobile network signaling data to the state of the underlying urban road network. We show how a predictive model of traffic flows can be created from mobile network signaling data. To achieve this, we estimate the vehicular density inside specific areas using a polynomial function of the inner and exiting mobile phone handovers performed by the base stations covering those areas. We can then use the aggregated handovers as flow proxies alongside the density proxy to directly estimate an average velocity within an area. We evaluate the model in a simulation study of Luxembourg city and generalize our findings using a real-world data set extracted from the LTE network of a Luxembourg operator. By predicting the real traffic states as measured through floating car data, we achieve a mean absolute percentage error of 11.12%. Furthermore, in our study case, the approximations of the network macroscopic fundamental diagrams (MFD) of road network partitions can be generated. The analyzed data exhibit low variance with respect to a quadratic concave flow-density function, which is inline with the previous theoretical results on MFDs and are similar when estimated from simulation and real data. These results indicate that mobile signaling data can potentially be used to approximate MFDs of the underlying road network and contribute to better estimate road traffic states in urban congested networks. Thierry Derrmann, Raphaël Frank, Francesco Viti, Thomas Engel 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2019 | POSTER: Traffic Splitting to Counter Website FingerprintingabstractWebsite fingerprinting (WFP) is a special type of traffic analysis, which aims to infer the websites visited by a user. Recent studies have shown that WFP targeting Tor users is notably more effective than previously expected. Concurrently, state-of-the-art defenses have been proven to be less effective. In response, we present a novel WFP defense that splits traffic over multiple entry nodes to limit the data a single malicious entry can use. Here, we explore several traffic-splitting strategies to distribute user traffic. We establish that our weighted random strategy dramatically reduces the accuracy from nearly 95% to less than 35% for four state-of-the-art WFP attacks without adding any artificial delays or dummy traffic. Wladimir De la Cadena, Asya Mitseva, Jan Pennekamp, Jens Hiller, Fabian Lanze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
CCS | 6 |
| 2019 | Analysis of Multi-path Onion Routing-Based Anonymization Networks
Wladimir De la Cadena, Daniel Kaiser 0001, Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001 |
DBSec | 5 |
| 2019 | Multipathing Traffic to Reduce Entry Node Exposure in Onion RoutingabstractUsers of an onion routing network, such as Tor, depend on its anonymity properties. However, especially malicious entry nodes, which know the client's identity, can also observe the whole communication on their link to the client and, thus, conduct several de-anonymization attacks. To limit this exposure and to impede corresponding attacks, we propose to multipath traffic between the client and the middle node to reduce the information an attacker can obtain at a single vantage point. To facilitate the deployment, only clients and selected middle nodes need to implement our approach, which works transparently for the remaining legacy nodes. Furthermore, we let clients control the splitting strategy to prevent any external manipulation. Jan Pennekamp, Jens Hiller, Sebastian Reuter, Wladimir De la Cadena, Asya Mitseva, Martin Henze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
ICNP | 7 |
| 2019 | VPGA: An SDN-based Location Privacy Zones Placement Scheme for Vehicular NetworksabstractMaking personal data anonymous is crucial to ensure the adoption of connected vehicles. One of the privacysensitive information is location, which once revealed can be used by adversaries to track drivers during their journey. Vehicular Location Privacy Zones (VLPZs) is a promising approach to ensure unlinkability. These logical zones can be easily deployed over roadside infrastructures (RIs) such as gas station or electric charging stations. However, the placement optimization problem of VLPZs is NP-hard and thus an efficient allocation of VLPZs to these RIs is needed to avoid their overload and the degradation of the QoS provided within theses RIs. This work considers the optimal placement of the VLPZs and proposes a geneticbased algorithm in a software defined vehicular network to ensure minimized trajectory cost of involved vehicles and hence less consumption of their pseudonyms. The analytical evaluation shows that the proposed approach is cost-efficient and ensures shorter response time. Abdelwahab Boualouache, Ridha Soua, Thomas Engel 0001 |
IPCCC | 3 |
| 2019 | Multi-Flow Congestion-Aware Routing in Software-Defined Vehicular Networksabstract5G-enabled vehicular networks will soon allow their users to exchange safety and non-safety related information over heterogeneous communication interfaces. Routing vehicular data flows over multi-hop Vehicle-to-Vehicle (V2V) communications is one of the hardest challenges in vehicular networking, and it has been tackled in literature by using distributed algorithms. The distributed approach has shown significant inefficiencies in such dynamic vehicular scenarios, mainly due to poor network congestion control. To overcome the complexity of the envisioned architecture, and the inefficiency of distributed routing algorithms, we hereby propose to leverage the coordination capabilities of Software-Defined Networking (SDN) to determine optimal V2V multi-hop paths and to offload traffic from the Vehicle-to-Infrastructure-to-Vehicle (V2I2V) to the V2V communications, using both cellular and Wi-Fi technologies. In order to achieve this goal, we propose Multi-Flow Congestion-Aware Routing (MFCAR), a centralized routing algorithm that relies on graph theory to choose short and uncongested V2V paths. Realistic simulations prove that MFCAR outperforms well- established centralized routing algorithms (e.g. Dijkstra's) in terms of Packet Delivery Ratio (PDR), goodput and average packet delay, up to a five-fold performance gain. Antonio Di Maio, Maria Rita Palattella, Thomas Engel 0001 |
VTC Fall | 3 |
| 2019 | Experimental Evaluation of Floating Car Data Collection Protocols in Vehicular NetworksabstractThe main objectives of the Intelligent Transportation Systems (ITS) vision is to improve road safety, traffic management, and mobility by enabling cooperative communication among participants. This vision requires the knowledge of the current state of the road traffic, which can be obtained by collecting Floating Car Data (FCD) information using Dedicated Short-Range Communication (DSRC) based on the IEEE 802.11p standard. Most of the existing FCD collection protocols have been evaluated via simulations and mathematical models, while the real-world implications have not been thoroughly investigated. This paper presents an open-source implementation of two state-of-the-art FCD collection algorithms, namely BASELINE and DISCOVER. These algorithms are implemented in an open-source vehicular prototyping platform and validated in a real-world experimental setup. Ion Turcanu, Florian Adamsky, Thomas Engel 0001 |
VTC Fall | 3 |
| 2019 | IoT Device Fingerprinting: Machine Learning based Encrypted Traffic AnalysisabstractEven in the face of strong encryption, the spectacular Internet of Things (IoT) penetration across sectors such as e-health, energy, transportation, and entertainment is expanding the attack surface, which can seriously harm users' privacy. We demonstrate in this paper that an attacker is able to disclose sensitive information about the IoT device, such as its type, by identifying specific patterns in IoT traffic. To perform the fingerprint attack, we train machine-learning algorithms based on selected features extracted from the encrypted IoT traffic. Extensive simulations involving the baseline approach show that we achieve not only a significant mean accuracy improvement of 18.5% and but also a speedup of 18.39 times for finding the best estimators. Obtained results should spur the attention of policymakers and IoT vendors to secure the IoT devices they bring to market. Nizar Msadek, Ridha Soua, Thomas Engel 0001 |
WCNC | 3 |
| 2019 | SDN-based Pseudonym-Changing Strategy for Privacy Preservation in Vehicular NetworksabstractThe pseudonym-changing approach is the de-facto location privacy solution proposed by security standards to ensure that drivers are not tracked during their journey. Several Pseudonym Changing Strategies (PCSs) have been proposed to synchronize Pseudonym Changing Processes (PCPs) between connected vehicles. However, most of the existing strategies are static, rigid and do not adapt to the vehicles' context. In this paper, we exploit the Software Defined Network (SDN) paradigm to propose a context-aware pseudonym changing strategy (SDN-PCS) where SDN controllers orchestrate the dynamic update of the security parameters of the PCS. Simulation results demonstrate that SDN-PCS strategy outperforms typical static PCSs to perform efficient PCPs and protect the location privacy of vehicular network users. Abdelwahab Boualouache, Ridha Soua, Thomas Engel 0001 |
WiMob | 3 |
| 2018 | Non-intrusive Distracted Driving Detection based on Driving Sensing Dataabstractpeer reviewed Sasan Jafarnejad, German Castignani, Thomas Engel 0001 |
VEHITS | 3 |
| 2018 | WLAN Device Fingerprinting using Channel State Information (CSI)abstractpeer reviewed Florian Adamsky, Tatiana Retunskaia, Stefan Schiffner, Christian Köbel, Thomas Engel 0001 |
WISEC | 5 |
| 2018 | The state of affairs in BGP security: A survey of attacks and defensesabstractThe Border Gateway Protocol (BGP) is the de facto standard interdomain routing protocol. Despite its critical role on the Internet, it does not provide any security guarantees. In response to this, a large amount of research has proposed a wide variety BGP security extensions and detection-recovery systems in recent decades. Nevertheless, BGP remains vulnerable to many types of attack. In this work, we conduct an up-to-date review of fundamental BGP threats and present a methodology for evaluation of existing BGP security proposals. Based on this, we introduce a comprehensive and up-to-date survey of proposals intended to make BGP secure and methods for detection and mitigation of routing instabilities. Last but not least, we identify gaps in research, and pinpoint open issues and unsolved challenges. Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001 |
Comput. Commun. | 3 |
| 2018 | A Multi-Pronged Approach to Adaptive and Context Aware Content Dissemination in VANETs
João M. G. Duarte, Eirini Kalogeiton, Ridha Soua, Gaetano Manzo, Maria Rita Palattella, Antonio Di Maio, Torsten Braun, Thomas Engel 0001, Leandro A. Villas, Gianluca Rizzo |
Mob. Networks Appl. | 8 |
| 2017 | What We Can Learn from Pilots for Handovers and (De)Skilling in Semi-Autonomous Driving: An Interview StudyabstractIn aviation, pilots interact with autopilots almost on a daily basis. With semi-autonomous vehicles, this is not yet the case. In our work, we aimed at finding out what we can learn from pilots' current experiences for the domain of autonomous driving and what implications can be derived. We conducted three in-depth interviews with pilots to investigate how pilots currently handle handover situations to and from the autopilot, which information is relevant for this transition to be successful, how pilots react in critical situations, how handovers are trained, and how flying and handover skills are maintained. We compare the gained insights with the domain of autonomous driving and reflect on implications for handovers and (de)skilling. Our findings suggest that the AUI community can learn from aviation in areas such as situation awareness, transparency of system status, the need for a primary drive display, calibrated (dis)trust, and driver training. Sandra Trösterer, Alexander Meschtscherjakov, Alexander G. Mirnig, Artur Lupp, Magdalena Gärtner, Fintan McGee, Rod McCall, Manfred Tscheligi, Thomas Engel 0001 |
AutomotiveUI | 9 |
| 2017 | A centralized approach for setting floating content parameters in VANETsabstractFloating Content (FC) has recently been proposed as an attractive application for mobile networks, such as VANETs, to operate opportunistic and distributed content sharing over a given geographic area, namely Anchor Zone (AZ). FC performances are tightly dependent on the AZ size, which in literature is classically chosen by the node that generates the floating message. In the present work, we propose a method to improve FC performances by optimizing the AZ size with the support of a Software Defined Network (SDN) controller, which collects mobility information, such as speed and position, of the vehicles in its coverage range. Antonio Di Maio, Ridha Soua, Maria Rita Palattella, Thomas Engel 0001, Gianluca Rizzo |
CCNC | 4 |
| 2017 | Smartphone-Based Adaptive Driving Maneuver Detection: A Large-Scale Evaluation StudyabstractThe proliferation of connected mobile devices together with advances in their sensing capacity has enabled a new distributed telematics platform. In particular, smartphones can be used as driving sensors to identify individual driver behavior and risky maneuvers. However, in order to estimate driver behavior with smartphones, the system must deal with different vehicle characteristics. This is the main limitation of existing sensing platforms, which are principally based on fixed thresholds for different sensing parameters. In this paper, we propose an adaptive driving maneuver detection mechanism that iteratively builds a statistical model of the driver, vehicle, and smartphone combination using a multivariate normal model. By means of experimentation over a test track and public roads, we first explore the capacity of different sensor input combinations to detect risky driving maneuvers, and we propose a training mechanism that adapts the profiling model to the vehicle, driver, and road topology. A large-scale evaluation study is conducted, showing that the model for maneuver detection and scoring is able to adapt to different drivers, vehicles, and road conditions. German Castignani, Thierry Derrmann, Raphaël Frank, Thomas Engel 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2016 | Content and Context Aware Strategies for QoS Support in VANETsabstractThe surging interest in autonomous coordinateddriving and in proactive safety services, exploiting the wealth ofsensing and computing resources which are gradually permeatingthe urban and vehicular environments, is making provisioning ofhigh levels of QoS in vehicular networks an urgent issue. At thesame time, the spreading model of a smart car, with a wealthof infotainment applications, calls for architectures for vehicularcommunications capable of supporting traffic with a diverse setof performance requirements. So far efforts have been revolvedtowards enabling a single specific QoS level. But the issues of howto support traffic with tight QoS requirements (no packet loss, and delays inferior to 1ms), and of designing a system capable atthe same time of efficiently sustaining such traffic together withtraffic from infotainment applications, are still open. In this paper we present the approach taken in the SNFCONTACT project in order to tackle these issues. The goal ofthe project is to investigate how an architecture for vehicularcommunications which integrates content-centric networking, software-defined networking as well as context aware floatingcontent schemes can properly support the very diverse set ofapplication and services currently envisioned for the vehicularenvironment. Gianluca Rizzo, Maria Rita Palattella, Torsten Braun, Thomas Engel 0001 |
AINA | 4 |
| 2016 | Towards A Taxonomy of Autonomous Vehicle Handover SituationsabstractThis paper proposes a taxonomy of autonomous vehicle handover situations with a particular emphasis on situational awareness. It focuses on a number of research challenges such as: legal responsibility, the situational awareness level of the driver and the vehicle, the knowledge the vehicle must have of the driver's driving skills as well as the in-vehicle context. The taxonomy acts as a starting point for researchers and practitioners to frame the discussion on this complex problem. Rod McCall, Fintan McGee, Alexander Meschtscherjakov, Nicolas Louveton, Thomas Engel 0001 |
AutomotiveUI | 5 |
| 2016 | You Never Forget How to Drive: Driver Skilling and Deskilling in the Advent of Autonomous VehiclesabstractIn the scope of autonomous driving, the question arises if the increased use of automated systems will have an impact on driver's skills in handling the car in the long term. In order to gain more insights on the issue of driver deskilling and how it relates to driving experience and time intervals of non-driving, we conducted an online survey (n=703) considering three driver groups. We found that initial skilling is more of an issue than deskilling after long periods of driving inactivity, i.e., while once learned driving skills seem to remain stable after longer periods of non-driving, they are much more influenced by driving experience in terms of annual mileage and frequency of use. Applied to the autonomous context, this means that drivers must be trained to a high enough skill level or require sufficient manual driving experience, in order to be able to react properly when driving themselves. Sandra Trösterer, Magdalena Gärtner, Alexander G. Mirnig, Alexander Meschtscherjakov, Rod McCall, Nicolas Louveton, Manfred Tscheligi, Thomas Engel 0001 |
AutomotiveUI | 8 |
| 2016 | POSTER: Fingerprinting Tor Hidden ServicesabstractThe website fingerprinting attack aims to infer the content of encrypted and anonymized connections by analyzing patterns from the communication such as packet sizes, their order, and direction. Although recent study has shown that no existing fingerprinting method scales in Tor when applied in realistic settings, this does not consider the case of Tor hidden services. In this work, we propose a two-phase fingerprinting approach applied in the scope of Tor hidden services and explore its scalability. We show that the success of the only previously proposed fingerprinting attack against hidden services strongly depends on the Tor version used; i.e., it may be applicable to less than 1.5% of connections to hidden services due to its requirement for control of the first anonymization node. In contrast, in our method, the attacker needs merely to be somewhere on the link between the client and the first anonymization node and the attack can be mounted for any connection to a hidden service. Asya Mitseva, Andriy Panchenko 0001, Fabian Lanze, Martin Henze, Klaus Wehrle, Thomas Engel 0001 |
CCS | 6 |
| 2016 | Heat is in the eye of the beholder: Towards better authenticating on smartglassesabstractSmart and wearable devices are trendy electronic objects that have become increasingly popular in recent years. Those devices are, by definition, tightly connected with the user's personal activities. Authentication is therefore a critical feature for both identifying users and personalizing the services on the device. In particular, the emergence of smartglasses changed the way we thought a wearable could assist users in their daily activities. As designed by commercial providers, smartglasses are sold with a very specific set of interactions capabilities. These capabilities have a strong impact on how comfortably or safely users may authenticate to their smartglasses. For this reason, we investigate in this paper the different authentication methods available for smartphones and we comparatively position the smartglasses in the design space of authentication methods. We propose a new approach based on touch input on an arbitrary surface using thermal camera input. This approach aims to circumvent the lack of touch surface provided by smartglasses, while maintaining an acceptable level of security. Gabriela Gheorghe, Nicolas Louveton, Benoît Martin, Benjamin Viraize, Louis Mougin, Sébastien Faye, Thomas Engel 0001 |
HSI | 7 |
| 2016 | Not a tile out of place: Toward creating context-dependent user interfaces on smartglassesabstractDespite the rapid pace of gadgets released on the market, research in the area of usable interfaces for wearables is lagging behind. Smartglasses are new wearables that embed diverse sensors but also have small displays, and this makes it hard for the wearer to visualize real-time data. To bridge this gap, the contribution of this paper is threefold. First, we propose a data representation model to combine applications and services that match user activities and contexts. Second, we present an approach of showing relevant services to the user based on `tiles' (such as those in recent Microsoft Windows interfaces) while considering the device constraints. Finally, we suggest that combining those two aspects can open the way to personalized services for the end user, creating new ways of interacting with applications and devices. Isabelle Pecci, Benoît Martin, Imed Kacem, Imed Maamria, Sébastien Faye, Nicolas Louveton, Gabriela Gheorghe, Thomas Engel 0001 |
HSI | 8 |
| 2016 | Website Fingerprinting at Internet Scale
Andriy Panchenko 0001, Fabian Lanze, Jan Pennekamp, Thomas Engel 0001, Andreas Zinnen, Martin Henze, Klaus Wehrle |
NDSS | 4 |
| 2016 | Human Mobility Profiling Using Privacy-Friendly Wi-Fi and Activity Traces: Demo AbstractabstractHuman mobility is one of the key topics to be considered in the networks of the future, both by industrial and research communities that are already focused on multidisciplinary applications and user-centric systems. If the rapid proliferation of networks and high-tech miniature sensors makes this reality possible, the ever-growing complexity of the metrics and parameters governing such systems raises serious issues in terms of privacy, security and computing capability. In this demonstration, we show a new system, able to estimate a user's mobility profile based on anonymized and lightweight smartphone data. In particular, this system is composed of (1) a web analytics platform, able to analyze multimodal sensing traces and improve our understanding of complex mobility patterns, and (2) a smartphone application, able to show a user's profile generated locally in the form of a spider graph. In particular, this application uses anonymized and privacy-friendly data and methods, obtained thanks to the combination of Wi-Fi traces, activity detection and graph theory, made available independent of any personal information. A video showing the different interfaces to be presented is available online. Sébastien Faye, Ibrahim Tahirou, Thomas Engel 0001 |
SenSys | 3 |
| 2016 | Bluetooth Low Energy performance and robustness analysis for Inter-Vehicular Communications
Walter Bronzi, Raphaël Frank, German Castignani, Thomas Engel 0001 |
Ad Hoc Networks | 4 |
| 2016 | Internet of Things in the 5G Era: Enablers, Architecture, and Business ModelsabstractThe IoT paradigm holds the promise to revolutionize the way we live and work by means of a wealth of new services, based on seamless interactions between a large amount of heterogeneous devices. After decades of conceptual inception of the IoT, in recent years a large variety of communication technologies has gradually emerged, reflecting a large diversity of application domains and of communication requirements. Such heterogeneity and fragmentation of the connectivity landscape is currently hampering the full realization of the IoT vision, by posing several complex integration challenges. In this context, the advent of 5G cellular systems, with the availability of a connectivity technology, which is at once truly ubiquitous, reliable, scalable, and cost-efficient, is considered as a potentially key driver for the yet-to emerge global IoT. In the present paper, we analyze in detail the potential of 5G technologies for the IoT, by considering both the technological and standardization aspects. We review the present-day IoT connectivity landscape, as well as the main 5G enablers for the IoT. Last but not least, we illustrate the massive business shifts that a tight link between IoT and 5G may cause in the operator and vendors ecosystem. Maria Rita Palattella, Mischa Dohler, Luigi Alfredo Grieco, Gianluca Rizzo, Johan Torsner, Thomas Engel 0001, Latif Ladid |
IEEE J. Sel. Areas Commun. | 6 |
| 2015 | Hacker's toolbox: Detecting software-based 802.11 evil twin access pointsabstractThe usage of public Wi-Fi hotspots has become a common routine in our everyday life. They are ubiquitous and offer fast and budget-friendly connectivity for various client devices. However, they are exposed to a severe security threat: since 802.11 identifiers (SSID, BSSID) can be easily faked, an attacker can setup an evil twin, i.e., an access point (AP) that users are unable to distinguish from a legitimate one. Once a user connects to the evil twin, he inadvertently creates a playground for various attacks such as collection of sensitive data (e.g., credit card information, passwords) or man-in-the-middle attacks even on encrypted traffic. It is particularly alarming that this security flaw has led to the development of several tools that are freely available, easy to use and allow mounting the attack from commodity client devices such as laptops, smartphones or tablets without attracting attention. In this paper we provide a detailed overview of tools that have been developed (or can be misused) to set up evil twin APs. We inspect them thoroughly in order to identify characteristics that allow them to be distinguished from legitimate hardware-based access points. Our analysis has discovered three methods for detecting software-based APs. These exploit accuracy flaws due to emulation of hardware behavior or peculiarities of the client Wi-Fi hardware they operate on. Our evaluation with 60 hardware APs and a variety of tools on different platforms reveals enormous potential for reliable detection. Furthermore, our methods can be performed on typical client hardware within a short period of time without even connecting to a potentially untrustworthy access point. Fabian Lanze, Andriy Panchenko 0001, Ignacio Ponce-Alcaide, Thomas Engel 0001 |
CCNC | 4 |
| 2015 | Comparison of active proximity radars for the wearable devicesabstractTwo methods of object position and movement estimation in relation to the user of smart glasses were investigated. An active infrared and ultrasonic methods of the obstacle detection were presented and compared. Application of these methods depend on active transducers type (physical medium used), geometry and surface properties of detected objects and their movement direction and speed. In the article properties of both detectors were compared and applicability of both methods in mobile, battery operated environment such as eGlasses platform were compared. Adam Bujnowski, Krzysztof Czuszynski, Jacek Ruminski, Jerzy Wtorek, Rod McCall, Andrei Popleteev, Nicolas Louveton, Thomas Engel 0001 |
HSI | 8 |
| 2015 | Text entry on smart glassesabstractThis paper presents a comparative pilot usability study of Dasher and an on-screen keyboard on a head-mounted display. Interaction logging data was captured along with subjective responses (via the SUS questionnaire). The results indicate that there is a strong need to develop text entry systems for smart glasses rather to simply adopt those that are already available. However, both approaches are useful when there is a need to enter private or sensitive data. Rod McCall, Benoît Martin, Andrei Popleteev, Nicolas Louveton, Thomas Engel 0001 |
HSI | 5 |
| 2015 | Network troubleshooting with SDN-RADARabstractDespite increasing deployment of software-defined networks (SDN), little is yet known about how to actually manage such kind of networks. When service degradation (generically termed here “trouble”) happens, the first step is to localise under-performing network paths (“troubleshooting”). SDN-RADAR gives a novel approach to ease large network troubleshooting by leveraging SDN features and incorporating distributed monitoring of network traffic. The demo shows how the SDN-RADAR tool can help network administrators understand which is the most likely faulty network link. Tigran Avanesov, Gabriela Gheorghe, Maria Rita Palattella, Miroslaw Kantor, Ciprian P. Popoviciu, Thomas Engel 0001 |
IM | 6 |
| 2015 | SDN-RADAR: Network troubleshooting combining user experience and SDN capabilitiesabstractSoftware-defined deployments are growing into data center and enterprise network infrastructures. The typical promises of software-defined networks (SDN) are improved time for market, decreased risk and operational costs for services, flexibility and unified management. However, little is known and shared about how to actually manage an SDN network, especially in localising underperforming network paths (what we call “troubleshooting”). We describe a novel approach to ease large network troubleshooting by leveraging SDN features and incorporating distributed monitoring of network traffic. We suggest SDN-RADAR, a tool that can help network administrators understand which is the most likely faulty network link. To the best of our knowledge this is the first troubleshooting solution that combines user-side performance measurements with network data extracted from the SDN controller. Gabriela Gheorghe, Tigran Avanesov, Maria Rita Palattella, Thomas Engel 0001, Ciprian P. Popoviciu |
NetSoft | 4 |
| 2015 | Model synchronization based on triple graph grammars: correctness, completeness and invertibility
Frank Hermann 0001, Hartmut Ehrig, Fernando Orejas, Krzysztof Czarnecki 0001, Zinovy Diskin, Yingfei Xiong 0001, Susann Gottmann, Thomas Engel 0001 |
Softw. Syst. Model. | 8 |
| 2014 | Letting the puss in boots sweat: detecting fake access points using dependency of clock skews on temperatureabstractThe only available IEEE 802.11 network identifiers (i.e., the network name and the MAC address) can be easily spoofed. Consequently, an attacker is able to fake a real hotspot and attract its traffic. By this means, the attacker can intercept, collect, or change users' traffic (often even if it is encrypted). In this paper, we describe an efficient method for detecting the replacement of access points (APs) by passive remote physical device fingerprinting. The main feature of our fingerprinting approach is the clock skew - an unavoidable phenomenon that causes clocks to run at minuscule yet remotely observable different speeds - which is extracted from information contained in beacon frames. We are the first to achieve a high discriminability of devices by completely eliminating the fingerprinters' influence and considering the clock skew's dependency on temperature. Finally, we develop a method for reliable detection of the presence of AP impostors that works without explicit temperature information. Compared to the best state-of-the-art approach, our method improves detection accuracy from about 30% to 90% without generating any traffic and requires less than one minute to collect a sufficient number of observations. Our approach yields a strong feature for passive remote physical device fingerprinting in wireless networks. Fabian Lanze, Andriy Panchenko 0001, Benjamin Braatz, Thomas Engel 0001 |
AsiaCCS | 4 |
| 2014 | Implications and detection of DoS attacks in OpenFlow-based networksabstractIn this paper, we address the potential of centralised network monitoring based on Software-Defined Networking with OpenFlow. Due to the vulnerability of the flow table, which can store only a limited number of entries, we discuss and show the implications for a DoS attack on a testbed consisting of OpenFlow enabled network devices. Such an attack can be detected by analysing variations in the logical topology, using techniques from information theory that can run as a network service on the network controller. Stefan Hommes, Radu State, Thomas Engel 0001 |
GLOBECOM | 3 |
| 2014 | Using opcode-sequences to detect malicious Android applicationsabstractRecently, the Android platform has seen its number of malicious applications increased sharply. Motivated by the easy application submission process and the number of alternative market places for distributing Android applications, rogue authors are developing constantly new malicious programs. While current anti-virus software mainly relies on signature detection, the issue of alternative malware detection has to be addressed. In this paper, we present a feature based detection mechanism relying on opcode-sequences combined with machine learning techniques. We assess our tool on both a reference dataset known as Genome Project as well as on a wider sample of 40,000 applications retrieved from the Google Play Store. Quentin Jérôme, Kevin Allix, Radu State, Thomas Engel 0001 |
ICC | 4 |
| 2014 | A Cooperative Advanced Driver Assistance System to mitigate vehicular traffic shock wavesabstractWe address the problem of shock wave formation in uncoordinated highway traffic. First, we identify the combination of heavy traffic and small traffic perturbations or unexpected driver actions as the main causes of highway traffic jams. Then we introduce a novel distributed communication protocol that enables us to eliminate upstream shock wave formation even with low system penetration rates. Based on traffic information ahead, we propose a Cooperative Advanced Driver Assistance System (CADAS) that recommends non-intuitive velocity reductions in order to redistribute traffic more uniformly thereby eliminating traffic peaks. Simulation results show that CADAS significantly increases the average velocity and therewith reduces the overall travel time and avoids unnecessary slowdowns. Markus Forster, Raphaël Frank, Mario Gerla, Thomas Engel 0001 |
INFOCOM | 4 |
| 2014 | Tracking spoofed locations in crowdsourced vehicular applicationsabstractPosition information is essential for many vehicular applications like traffic information and route planning but also for enabling vital network routing services. However, the accuracy of the latter is highly dependent of a precise location service which might be altered by attackers forging falsified position data. In this paper, we propose a new method for tracking and removing location spoofing anomalies in large scale position based services assuming neither control of the communication infrastructure or additional hardware nor software at the client side. Our system uses aggregation of location information to compute relevant stability metrics which may reveal anomalous events. Lautaro Dolberg, Jérôme François, Thomas Engel 0001 |
NOMS | 3 |
| 2014 | RAMSES: Revealing Android Malware Through String Extraction and Selection
Lautaro Dolberg, Quentin Jérôme, Jérôme François, Radu State, Thomas Engel 0001 |
SecureComm (1) | 5 |
| 2014 | PhishStorm: Detecting Phishing With Streaming AnalyticsabstractDespite the growth of prevention techniques, phishing remains an important threat since the principal countermeasures in use are still based on reactive URL blacklisting. This technique is inefficient due to the short lifetime of phishing Web sites, making recent approaches relying on real-time or proactive phishing URL detection techniques more appropriate. In this paper, we introduce PhishStorm, an automated phishing detection system that can analyze in real time any URL in order to identify potential phishing sites. PhishStorm can interface with any email server or HTTP proxy. We argue that phishing URLs usually have few relationships between the part of the URL that must be registered (low-level domain) and the remaining part of the URL (upper-level domain, path, query). We show in this paper that experimental evidence supports this observation and can be used to detect phishing sites. For this purpose, we define the new concept of intra-URL relatedness and evaluate it using features extracted from words that compose a URL based on query data from Google and Yahoo search engines. These features are then used in machine-learning-based classification to detect phishing URLs from a real dataset. Our technique is assessed on 96 018 phishing and legitimate URLs that result in a correct classification rate of 94.91% with only 1.44% false positives. An extension for a URL phishingness rating system exhibiting high confidence rate ( $>$ 99%) is proposed. We discuss in this paper efficient implementation patterns that allow real-time analytics using Big Data architectures such as STORM and advanced data structures based on the Bloom filter. Samuel Marchal, Jérôme François, Radu State, Thomas Engel 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2013 | Driver diaries: a multimodal mobility behaviour logging methodologyabstractThe Driver Diaries are a mobility behaviour logging methodology, consisting of an online survey, a mobile application and focus group interviews. They are used to collect data about mobility behaviour, routines and motivations of commuters in Luxembourg. The paper focuses on design and development of the Driver Diaries and it explores the use of the application as a requirements capture and an integral element of an infotainment application that can change the standard routine driving behaviour of mobility participants in order to reduce traffic congestion. Martin Kracheel, Rod McCall, Vincent Koenig, Thomas Engel 0001 |
AutomotiveUI | 4 |
| 2013 | Assessing in-vehicle information systems application in the car: a versatile tool and unified testing platformabstractIn this paper we present the DriveLab IVIS testing platform which allows for the same experiments to be conducted both under simulator and real car conditions. Other key aspects of DriveLab is that it is highly modular (therefore allowing the exchange or integration of different components) and that it supports more than one driver. For example we show that the same IVIS devices and scenario can be used with two different 3D engines. The paper provides a technical overview and a brief example of use. Nicolas Louveton, Rod McCall, Tigran Avanesov, Vincent Koenig, Thomas Engel 0001 |
AutomotiveUI | 5 |
| 2013 | Automated source code extension for debugging of OpenFlow based networksabstractSoftware-Defined Networks using OpenFlow have to provide a reliable way to to detect network faults in operational environments. Since the functionality of such networks is mainly based on the installed software, tools are required in order to determine software bugs. Moreover, network debugging might be necessary in order to detect faults that occurred on the network devices. To determine such activities, existing controller programs must be extended with the relevant functionality. In this paper we propose a framework that can modify controller programs transparently by using graph transformation, making possible online fault management through logging of network parameters in a NoSQL database. Latter acts as a storage system for flow entries and respective parameters, that can be leveraged to detect network anomalies or to perform forensic analysis. Stefan Hommes, Frank Hermann 0001, Radu State, Thomas Engel 0001 |
CNSM | 4 |
| 2013 | An evaluation study of driver profiling fuzzy algorithms using smartphonesabstractProfiling driving behavior has become a relevant aspect in fleet management, automotive insurance and eco-driving. Detecting inefficient or aggressive drivers can help reducing fleet degradation, insurance policy cost and fuel consumption. In this paper, we present a Fuzzy-Logic based driver scoring mechanism that uses smartphone sensing data, including accelerometers and GPS. In order to evaluate the proposed mechanism, we have collected traces from a testbed consisting in 20 vehicles equipped with an Android sensing application we have developed to this end. The results show that the proposed sensing variables using smartphones can be merged to provide each driver with a single score. German Castignani, Raphaël Frank, Thomas Engel 0001 |
ICNP | 3 |
| 2013 | Improving traffic in urban environments applying the Wardrop equilibriumabstractOver the last few years vehicular traffic density has continuously increased and it is likely that the traffic demand will further increase in the future. In many metropolitan areas the road infrastructure is no longer able to handle the peak traffic demand and the existing road network cannot be easily extended. The best way to improve the traffic situation is to optimise the resources available in the transportation network and to coordinate the traffic demand. The approach that we propose in this paper makes use of a collaborative traffic coordination protocol which collects real-time Floating Car Data (FCD) directly from participating vehicles and suggests dynamic routes in order to minimize travel delay. Information such as speed, position and direction is sent to one or more Traffic Coordination Points (TCPs) where it is aggregated to obtain a global picture of the traffic conditions in real-time. Based on this data, we continuously compute the route that minimizes the travel time to a given destination by applying Wardrop's first principle of equilibrium. Our results show that, by coordinating the vehicles, we are able to better distribute the overall traffic demand throughout the transportation network, reducing the average travel times and accommodating more vehicles. Lara Codeca, Raphaël Frank, Thomas Engel 0001 |
ICNP | 3 |
| 2013 | A semantic firewall for Content-Centric Networking
David Goergen, Thibault Cholez, Jérôme François, Thomas Engel 0001 |
IM | 4 |
| 2013 | A key management scheme for Content Centric Networking
Sarmad Ullah Khan, Thibault Cholez, Thomas Engel 0001, Luciano Lavagno |
IM | 3 |
| 2013 | ASMATRA: Ranking ASs providing transit service to malware hosters
Cynthia Wagner, Jérôme François, Radu State, Alexandre Dulaunoy, Thomas Engel 0001, Gilles Massen |
IM | 5 |
| 2013 | LuxTraffic: A collaborative traffic sensing systemabstractThe following paper provides a complete overview of LuxTraffic, an online system for collaborative traffic sensing in Luxembourg. LuxTraffic has been created to gather, analyze and archive anonymous user generated traffic data by taking advantage of the communication capabilities and the built-in GPS receiver of smartphone devices. We motivate the necessity and benefits of such a system, reveal the core functionalities as well as the technical details behind its realization. Next, we continue with a statistical evaluation about the system usage. We conclude by discussing the the pros and cons of such a system and propose future works. Aleksandrina Kovacheva, Raphaël Frank, Thomas Engel 0001 |
LANMAN | 3 |
| 2013 | Multi-dimensional aggregation for DNS monitoringabstractDNS is an essential service in the Internet as it allows to translate human language based domain names into IP addresses. DNS traffic reflects the user activities and behaviors. It is thus a helpful source of information in the context of large scale network monitoring. In particular, passive DNS monitoring garnered much interest for the security perspectives by highlighting the services the machines want to access. In this paper, we propose a new method for assessing the dynamics of the match between DNS names and IP subnetworks using an efficient aggregating scheme combined with relevant steadiness metrics. The evaluation relies on real data collected over several months and is able to detect anomalies related to malicious domains. Lautaro Dolberg, Jérôme François, Thomas Engel 0001 |
LCN | 3 |
| 2013 | Path Extension Analysis of Peer-to-Peer Communications in Small 6LoWPAN/RPL Sensor NetworksabstractResearchers and manufacturers are currently putting a lot of efforts to design, improve and deploy the Internet of Things, involving a significant number of constrained and low cost embedded devices deployed in large scales with low power consumption, low bandwidth and limited communication range. For instance we can easily build a network composed by multiple sensors distributed in a building in order to monitor temperature in different offices. This kind of architecture is generally centralized as all sensors are mainly programmed to periodically transmit their data to the sink. The specific IPv6 Routing Protocol for Low-power and Lossy Networks (RPL) had been designed in order to enable such communications. Support for point-to-point traffic is also available. In fact new applications may also consider peer-to-peer communications between any nodes of the network. In that case, RPL is not optimal as data packets are forwarded in respect with longer paths with larger metrics. In this paper we propose to study the effectiveness of RPL compared to a shortest path algorithm such like the Dijkstra's algorithm. We suggest to analyze peer-to-peer communications inside random wireless sensor network topologies with size limited to 250 nodes, corresponding to a reasonable cluster size. We have built a particular simulation environment named Network Analysis and Routing eVALuation (NARVAL). This toolbox permits to generate random topologies in order to study the impact of routing algorithms on the effectiveness of communication protocols. In our work, we first generated many random network topologies where we selected a sink node. We built the Destination Oriented Directed Acyclic Graph (DODAG) from the chosen sink in respect with the RPL algorithm. We finally performed all paths between each couple of two distinct sensor nodes and compared them to the corresponding shortest paths obtained by the Dijkstra's algorithm. This approach permits to retrieve some statistics on the path extension between RPL and the Dijkstra's algorithm. We also analyzed the impact of the sink position and the network size on this path extension. Foued Melakessou, Thomas Engel 0001 |
MASCOTS | 2 |
| 2013 | Predictable Mobile Routing for Spacecraft NetworksabstractIn predictable mobile networks, network nodes move in a predictable way and therefore have dynamically changing but predictable connectivity. We have developed a model that formalizes predictable dynamic topologies as sequences of static snapshots. We use this model to design and evaluate a predictable mobile-routing protocol based on link-state routing, whose performance is superior to its static and ad hoc counterparts. Our routing protocol accounts for occurrences of additional, unpredictable changes, as well as their interaction with predictable changes. We evaluate our protocol using simulations based on randomly generated topologies and spacecraft-network scenarios. In both cases, we show that our protocol outperforms traditional routing protocols and is well suited for routing in next-generation space networks. Daniel Fischer 0006, David A. Basin, Knut Eckstein, Thomas Engel 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2012 | Improving highway traffic through partial velocity synchronizationabstractIn this paper we address the problem of uncoordinated highway traffic. We first identify the main causes of the capacity drop, namely high traffic demand and inadequate driver reaction. In the past, traffic and user behavior have been accurately described by cellular automata (CA) models. In this paper we extend the CA model to deal with highway traffic fluctuations and jams. Specifically, the model incorporates the communication layer between vehicles. The model thus enables us to study the impact of inter-vehicular communications and in particular the delivery of critical and timely upstream traffic information on driver reaction. Based on the newly-available traffic metrics, we propose an Advanced Driver Assistance System (ADAS) that suggests non-intuitive speed reduction in order to avoid the formation of so-called phantom jams. The results show that using such a system considerably increases the overall traffic flow, reduces travel time and avoids unnecessary slow-downs. Markus Forster, Raphaël Frank, Mario Gerla, Thomas Engel 0001 |
GLOBECOM | 4 |
| 2012 | An arbitrary mobility model of Mini-Sinks using controlled data collection for reducing congestion appearance in wireless sensor networksabstractThis paper addresses the appearance of congestion in Wireless Sensor Networks (WSNs) using mobile Mini-Sinks (MSs). Several mobile MSs are moving according to an arbitrary mobility model inside the sensor field for collecting data within their coverage areas based on the controlled Energy Conserving Routing Protocol (ECRP) and forwarding it towards the single main sink. ECRP, based on route diversity, is implemented in MSs and sensors. Thus, a set of multiple paths between MSs and sensors is generated to distribute the global traffic, so as to partially reduce the appearance of congestion over the entire network. Simulations were performed in order to validate the performance of our model. We compare the results obtained with those for a single static sink and mobile sink, and show that our approach achieves better network performances in terms of packet delivery ratio, throughput, end-to-end delay, network lifetime, residual energy, energy and multiple paths overhead. David Fotue, Houda Labiod, Thomas Engel 0001 |
IPCCC | 3 |
| 2012 | Improving performance and anonymity in the Tor networkabstractAnonymous communication aims to hide the relationship between communicating parties on the Internet. It is the technical basis for achieving privacy and overcoming censorship. Presently there are only a few systems that are of practical relevance for providing anonymity. One of the most widespread and well researched is Tor which is based on onion routing. Usage of Tor, however, often leads to long delays which are not tolerated by end-users. This, in return, discourages many of them from using the system and lowers the protection for the remaining ones. In this paper we analyze the bottlenecks in the Tor network and propose new methods of path selection that better utilize available capacities in the heterogeneous network and allow performance-improved onion routing. Our methods are based on the combination of remotely measured current load of the nodes and an estimation of their maximum capacity. We evaluate the proposed methods in a Tor network running in PlanetLab where we tried as far as possible to recreate real-world conditions. Finally, we present a practical approach to empirically analyze the strength of anonymity that different methods of path selection provide in comparison to each other. We show the risk of the currently used method for path selection in Tor and provide a countermeasure to protect against this risk by effectively detecting nodes that lie about their capacity. Andriy Panchenko 0001, Fabian Lanze, Thomas Engel 0001 |
IPCCC | 3 |
| 2012 | Efficient Multidimensional Aggregation for Large Scale Monitoring
Lautaro Dolberg, Jérôme François, Thomas Engel 0001 |
LISA | 3 |
| 2012 | Performance Evaluation of Hybrid Channel Assignment for Wireless Sensor NetworksabstractData transmission in Wireless Sensor Networks (WSNs) is physically constrained by interference, throughput, latency and many other physical phenomena. We propose a distributed hybrid algorithm to perform the selection of communication channels in such a way that overall throughput, latency, energy and overhead are improved. A tree structure is built out from the sink, in order to elect sensors with the highest degree of connectivity as parents, and sensors with the lowest degree of connectivity as leaves. A set of parents and leaves are assigned to a single fixed channel. Specific sensors, called mediators, are assigned to several orthogonal channels. So, they can switch dynamically to the static channels of parents for collecting the data. This allows the data to be efficiently propagated in parallel on multiple channels from parent to mediator to parent towards the sink. We compare the results obtained with those for single and multiple channels by taking sink throughput, broadcast latency, energy consumption and routing overhead as performance criteria. We show that our method provides better results. David Fotue, Houda Labiod, Thomas Engel 0001 |
MSN | 3 |
| 2012 | Detecting Stealthy Backdoors with Association Rule Mining
Stefan Hommes, Radu State, Thomas Engel 0001 |
Networking (2) | 3 |
| 2012 | Semantic Exploration of DNS
Samuel Marchal, Jérôme François, Cynthia Wagner, Thomas Engel 0001 |
Networking (1) | 4 |
| 2012 | SAFEM: Scalable analysis of flows with entropic measures and SVMabstractThis paper describes a new approach for the detection of large-scale anomalies or malicious events in Netflow records. This approach allows Internet operators, to whom botnets and spam are major threats, to detect large-scale distributed attacks. The prototype SAFEM (Scalable Analysis of Flows with Entropic Measures) uses spatial-temporal Netflow record aggregation and applies entropic measures to traffic. The aggregation scheme highly reduces data storage leading to the viability of using such an approach in an Internet Service Provider network. Jérôme François, Cynthia Wagner, Radu State, Thomas Engel 0001 |
NOMS | 4 |
| 2012 | A distance-based method to detect anomalous attributes in log filesabstractDealing with large volumes of logs is like the proverbial needle in the haystack problem. Finding relevant events that might be associated with an incident, or real time analysis of operational logs is extremely difficult when the underlying data volume is huge and when no explicit misuse model exists. While domain-specific knowledge and human expertise may be useful in analysing log data, automated approaches for detecting anomalies and track incidents are the only viable solutions when confronted with large volumes of data. In this paper we address the issue of automated log analysis and consider more specifically the case of ISP-provided firewall logs. We leverage approaches derived from statistical process control and information theory in order to track potential incidents and detect suspicious network activity. Stefan Hommes, Radu State, Thomas Engel 0001 |
NOMS | 3 |
| 2012 | DNSSM: A large scale passive DNS security monitoring frameworkabstractWe present a monitoring approach and the supporting software architecture for passive DNS traffic. Monitoring DNS traffic can reveal essential network and system level activity profiles. Worm infected and botnet participating hosts can be identified and malicious backdoor communications can be detected. Any passive DNS monitoring solution needs to address several challenges that range from architectural approaches for dealing with large volumes of data up to specific Data Mining approaches for this purpose. We describe a framework that leverages state of the art distributed processing facilities with clustering techniques in order to detect anomalies in both online and offline DNS traffic. This framework entitled DNSSM is implemented and operational on several networks. We validate the framework against two large trace sets. Samuel Marchal, Jérôme François, Cynthia Wagner, Radu State, Alexandre Dulaunoy, Thomas Engel 0001, Olivier Festor |
NOMS | 6 |
| 2012 | SDBF: Smart DNS brute-forcerabstractThe structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches. Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001, Gérard Wagener, Alexandre Dulaunoy |
NOMS | 4 |
| 2012 | Controlled data collection of Mini-Sinks for maximizing packet delivery ratio and throughput using multiple paths in Wireless Sensor NetworksabstractWe propose a new approach based on the use of many data collectors, which we designate Mini-Sinks (MSs), instead of a single sink in order to improve Wireless Sensor Network (WSN) performances. One or more MSs are mobile and move according to an arbitrary mobility model inside the sensor field in order to maintain a fully-connected network topology, collecting data based on the controlled Energy Conserving Routing Protocol (ECRP) within their coverage areas and forwarding it towards the single main sink. ECRP, based on route diversity, is implemented in MSs and sensors in order to optimize the transmission cost of the forwarding scheme. A set of multiple paths between MSs and sensors is generated to distribute the global traffic over the entire network. Simulations were performed in order to validate the performance of our new approach. We compare the results obtained with those for a single static sink and mobile sink, and show that our approach can achieve better results in terms of packet delivery ratio, throughput, end-to-end delay and multiple paths overhead. David Fotue, Houda Labiod, Thomas Engel 0001 |
PIMRC | 3 |
| 2012 | Proactive Discovery of Phishing Related Domain Names
Samuel Marchal, Jérôme François, Radu State, Thomas Engel 0001 |
RAID | 4 |
| 2012 | Breaking Tor anonymity with game theory and data miningabstractSUMMARY Attacking anonymous communication networks is very tempting, and many types of attacks have already been observed. In the case for Tor, a widely used anonymous overlay network is considered. Despite the deployment of several protection mechanisms, an attack originated by just one rogue exit node is proposed. The attack is composed of two elements. The first is an active tag injection scheme. The malicious exit node injects image tags into all HTTP replies, which will be cached for upcoming requests and allow different users to be distinguished. The second element is an inference attack that leverages a semi‐supervised learning algorithm to reconstruct browsing sessions. Captured traffic flows are clustered into sessions, such that one session is most probably associated to a specific user. The clustering algorithm uses HTTP headers and logical dependencies encountered in a browsing session. A prototype has been implemented and its performance evaluated on the Tor network. The article also describes several countermeasures and advanced attacks, modeled in a game theoretical framework, and their effectiveness assessed with reference to the Nash equilibrium. Copyright © 2011 John Wiley & Sons, Ltd. Cynthia Wagner, Gérard Wagener, Radu State, Alexandre Dulaunoy, Thomas Engel 0001 |
Concurr. Comput. Pract. Exp. | 5 |
| 2012 | Energy-efficient high-performance parallel and distributed computing
Samee Ullah Khan, Pascal Bouvry, Thomas Engel 0001 |
J. Supercomput. | 3 |
| 2011 | Detection of abnormal behaviour in a surveillance environment using control chartsabstractThis paper introduces a new approach to unsupervised detection of abnormal sequences of images in video surveillance data. We leverage an online object detection method and statistical process control techniques in order to identify suspicious sequences of events. Our method assumes a training phase in which the spatial distribution of objects is learned, followed by a chart-based tracking process. We evaluate the performance of our method on a standard dataset and have implemented a publicly available open-source prototype. Stefan Hommes, Radu State, Andreas Zinnen, Thomas Engel 0001 |
AVSS | 4 |
| 2011 | Towards Economic Energy Trading in Cloud EnvironmentsabstractEspecially in times of heavy loads, cloud providers often have to outsource tasks to external clouds to fulfill service level agreements. Nevertheless, a cloud provider maximizes the company's benefit while running as many jobs as possible on the own hardware without going below a specific workload of the running processors. Since cloud providers will have to estimate the required energy in advance due to energy trading, they should aim for estimating maturely the optimal number of necessary processors for a future date and time. This paper presents a method for anticipating the optimal number of active processors and corresponding energy. In particular, this work analyzes the potential of Gaussian processes to estimate future jobs by considering statistical data. Based on the job number estimate, a second Gaussian process approximates the optimal number of processors for a future date allowing for economical energy trading. Finally, the paper optimizes the computing resources in clouds by applying earliest deadline first strategy. Andreas Zinnen, Thomas Engel 0001 |
CloudCom | 2 |
| 2011 | Enforcing security with behavioral fingerprinting
Jérôme François, Radu State, Thomas Engel 0001, Olivier Festor |
CNSM | 3 |
| 2011 | Adaptive and self-configurable honeypotsabstractHoneypot evangelists propagate the message that honeypots are particularly useful for learning from attackers. However, by looking at current honeypots, most of them are statically configured and managed, which requires a priori knowledge about attackers. In this paper we propose a high-interaction honeypot capable of learning from attackers and capable of dynamically changing its behavior using a variant of reinforcement learning. It can strategically block the execution of programs, lure the attacker by substituting programs and insult attackers with the intent of revealing the attacker's nature and ethnic background. We also investigated the fact that attackers could learn to defeat the honeypot and discovered that attacker and honeypot interests sometimes diverge. Gérard Wagener, Radu State, Thomas Engel 0001, Alexandre Dulaunoy |
Integrated Network Management | 3 |
| 2011 | BotTrack: Tracking Botnets Using NetFlow and PageRank
Jérôme François, Shaonan Wang, Radu State, Thomas Engel 0001 |
Networking (1) | 4 |
| 2011 | Machine Learning Approach for IP-Flow Record Anomaly Detection
Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001 |
Networking (1) | 4 |
| 2011 | DANAK: Finding the odd!abstractWith the growth of network connectivity and network sizes, the interest in traffic classification respectively attack and anomaly detection in network monitoring and security related activities have become very strong. In this paper, a new tool called DANAK has been developed for the detection of anomalies in Netflow records by referring to spatial and temporal information aggregation in combination with Machine Learning techniques. Spatially aggregated Netflow records are fed in a new designed kernel function in order to analyze Netflow records on context and quantitative information. To strengthen the analysis of large volumes of Netflow records, Phase Space Embedding and Machine Learning are applied. The proposed method has been validated by extensive experimentation on real data sets, including numerous attack strategies of different roots. Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001 |
NSS | 4 |
| 2011 | Lightweight Hidden ServicesabstractHidden services (HS) are mechanisms designed to provide network services while preserving anonymity for the identity of the server. Besides protecting the identity of the server, hidden services help to resist censorship, are resistant against distributed DoS attacks, and allow server functionality even if the service provider does not own a public IP address. Currently, only the Tor network offers this feature in full functionality. However, the HS concept in Tor is complex and provides poor performance. According to recent studies, average contact time for a hidden service is 24s which is far beyond what an average user is willing to wait. In this paper we introduce a novel approach for hidden services that achieves similar functionality as HS in Tor but does so in a simple and lightweight way with the goal to improve performance and usability. Additionally, contrary to Tor, in our approach clients are not required to install any specific software for accessing hidden services. This increases usability of our approach. Simplicity makes our approach easier to understand for normal users, eases protocol reviews, and increases chances of having several implementations of the protocol available. Moreover, simpler solutions are easier to analyze and they are naturally less prone to implementation failures rather than complex protocols. In this paper, we describe our approach and provide performance as well as anonymity analysis of resulting properties of the protocol. Andriy Panchenko 0001, Otto Spaniol, André Egners, Thomas Engel 0001 |
TrustCom | 4 |
| 2011 | A Distributed Hybrid Channel Selection and Routing Technique for Wireless Sensor NetworksabstractIn this paper, we propose Well-Connected Dominating Set Channel Assignment (WCDS-CA), a distributed hybrid algorithm that uses a well-connected dominating set to perform a selection of communication channels in wireless sensor networks in such a way that the number of channels used and interference among sensor nodes remains minimal. Since the network topology allows each sensor node to be equipped with several radio interfaces, a set of parents and leaves are statically assigned to a single fixed channel. The routers are assigned to several orthogonal channels using the corresponding radio interfaces in such a way that they can switch dynamically to the static channels of parent nodes in order to minimize network interference. The tree based on Breadth-First Search is built out from the sink, with the result that the shortest between each sensor and the sink is established. This allows the data to be efficiently propagated from parent to router to parent towards the sink in order to reduce the number of individual transmissions. We compare the results obtained with those for a single channel by taking the common links used by each node on each channel and packets transmitted as performance criteria, and show that our proposal gives better results in dense wireless sensor networks. David Fotue, Foued Melakessou, Houda Labiod, Thomas Engel 0001 |
VTC Fall | 4 |
| 2010 | Game theory driven monitoring of spatial-aggregated IP-Flow recordsabstractAn important problem in current operational environments is the large quantity of monitoring data that has to be processed online. This paper introduces a new metric that leverages spatially and temporally aggregated IP-flow related information. The metric is based on a new kernel function that captures both IP address space distribution as well as volume related traffic information. We assess several attacks and counter attack methods with respect to a sound game-theoretical model in order to identify the best Nash Equilibrium driven defensive and offensive strategies. Cynthia Wagner, Gérard Wagener, Radu State, Thomas Engel 0001, Alexandre Dulaunoy |
CNSM | 4 |
| 2010 | RiskRank: Security risk ranking for IP flow recordsabstractThis paper considers the monitoring of large volumes of IP flow records, typically encountered on large ISP backbone/edge routers. The approach described in our paper aims to detect relevant flow records, where relevancy is related to overall traffic activity and associated applications. The core contribution of the paper consists in a dependency graph that leverages relationships between hosts, as well as flow-specific risk modeling. The risk model is constructed using well-known link analysis algorithms and application-specific signatures. Shaonan Wang, Radu State, Mohamed Ourdane, Thomas Engel 0001 |
CNSM | 4 |
| 2010 | FlowRank: ranking NetFlow recordsabstractThis paper describes a new approach to identify relevant flow records in large scale flow dataset. We propose a method that leverages the well known page rank algorithm in order to extract the most relevant flows. We introduce a dependency relation that uses a simple and efficient causal relationship. The strength of this dependency is determined by time related information. We have tested our method on datasets coming from our campus network. Shaonan Wang, Radu State, Mohamed Ourdane, Thomas Engel 0001 |
IWCMC | 4 |
| 2010 | Design of New Aggregation Techniques for Wireless Sensor NetworksabstractThis paper compares different alternative aggregation techniques for Wireless Sensor Networks Optimization based on tree construction. The main idea is to efficiently elect parent nodes responsible of data aggregation according to their connectivity degree. Thus, the quantity of data transmitted on the network remains minimal during the transfer from all sensors towards the sink. Simulations have shown that our new approach provides a better performance than existing techniques such as BFS, DFS and flooding, especially in terms of quantity of data packets transmitted from all sensor towards the sink. David Fotue, Foued Melakessou, Thomas Engel 0001, Houda Labiod |
MASCOTS | 3 |
| 2010 | Breaking Tor Anonymity with Game Theory and Data MiningabstractAttacking anonymous communication networks is very tempting and many attacks have already been observed. We consider the case of Tor, a widely-used anonymous overlay network. Despite the deployment of several protection mechanisms, we propose an attack originated from only one rogue exit node. Our attack is composed of two elements. The first is an active tag injection scheme. The malicious exit node injects image tags into all HTTP replies, which will be cached for upcoming requests and allows different users to be distinguished. The second element is an inference attack that leverages a semi-supervised learning algorithm to reconstruct browsing sessions. Captured traffic flows are clustered into sessions, such that one session is most probably associated to a specific user. The clustering algorithm uses HTTP headers and logical dependencies encountered in a browsing session. We have implemented a prototype and evaluated its performance on the Tor network. The article also describes several counter-measures and advanced attacks, modeled in a game-theoretical framework and their relevancy assessed with reference to the Nash equilibrium. Cynthia Wagner, Gérard Wagener, Radu State, Thomas Engel 0001, Alexandre Dulaunoy |
NSS | 4 |
| 2010 | PeekKernelFlows: peeking into IP flowsabstractThis paper introduces a new method for getting insights into IP related data flows based on a simple visualization technique that leverages kernel functions defined over spatial and temporal aggregated IP flows. This approach was implemented in a visualization tool called PeekKernelFlows. This tool simplifies the identification of anomalous patterns over a time period. An intuitive adapting image allows network operators to detect attacks. We validated our method on a real use-case scenario, where we inspected traffic of a high-interaction honeypot. Cynthia Wagner, Gérard Wagener, Radu State, Alexandre Dulaunoy, Thomas Engel 0001 |
VizSEC | 5 |
| 2009 | Collusion Detection for Grid ComputingabstractA common technique for result verification in grid computing is to delegate a computation redundantly to different workers and apply majority voting to the returned results. However, the technique is sensitive to "collusion" where a majority of malicious workers collectively returns the same incorrect result. In this paper, we propose a mechanism that identifies groups of colluding workers. The mechanism is based on the fact that colluders can succeed in a vote only when they hold the majority. This information allows us to build clusters of workers that voted similarly in the past, and so detect collusion. We find that the more strongly workers collude, the better they can be identified. Eugen Staab, Thomas Engel 0001 |
CCGRID | 2 |
| 2009 | Defensive configuration with game theoryabstractThis paper proposes a new model, based on mainstream game theory for the optimal configuration of services. We consider the case of reliable realtime P2P communications and show how the configuration of security mechanisms can be configured using game theoretical concepts, in which the defendant is played by the management plane having to face adversaries which play the attacker role. Our main contribution lies in proposing a risk assessment framework and deriving optimal strategies - in terms of Nash equilibrium - for both the attacker and the defendant. We consider the specific service of communications in autonomic networks and we show how the optimal configuration can be determined within the proposed framework. Sheila Becker, Radu State, Thomas Engel 0001 |
Integrated Network Management | 3 |
| 2009 | Runtime Monitoring and Dynamic Reconfiguration for Intrusion Detection Systems
Martin Rehák, Eugen Staab, Volker Fusenig, Michal Pechoucek, Martin Grill, Jan Stiborek, Karel Bartos, Thomas Engel 0001 |
RAID | 8 |
| 2009 | Self Adaptive High Interaction Honeypots Driven by Game Theory
Gérard Wagener, Radu State, Alexandre Dulaunoy, Thomas Engel 0001 |
SSS | 4 |
| 2008 | Trust-Aided Acquisition Of Unverifiable InformationabstractWe propose a mechanism for the acquisition of information from potentially unreliable sources. Our mechanism addresses the case where the acquired information cannot be verified. The idea is to intersperse questions (“challenges”) for which the correct answers are known. By evaluating the answers to these challenges, probabilistic conclusions about the correctness of the unverifiable information can be drawn. Less challenges need to be used if an information provider has shown to be trustworthy. Our approach can resist collusion and shows great promise for various application scenarios such as grid-computing or peer-to-peer networks. Eugen Staab, Volker Fusenig, Thomas Engel 0001 |
ECAI | 3 |
| 2008 | Security Extensions for Space-Link CommunicationabstractIn recent times, the importance of information security in civilian space communication systems has increased significantly among space agencies. Those systems often require a high degree of flexibility, interoperability and scalability. Therefore the usage of traditional, physical layer based security solutions is not a desirable option for the agencies. In this paper, we investigate the application of security services to the CCSDS Packet TM/TC space communication protocol stack and propose a transparent and open solution that provides an optimal trade-off between security, interoperability and technical implementation feasibility. We take into consideration the special restrictions that are superimposed by the space environment and existing legacy systems. Daniel Fischer 0006, Mario Merri, Thomas Engel 0001 |
ICCCN | 3 |
| 2008 | Topology dynamics and routing for predictable mobile networksabstractPredictable mobile networks are dynamic in terms of the mobility and connectivity of the network nodes. However, in contrast to mobile ad-hoc networks, their dynamics are mostly predictable, as the name suggests. Currently, no adequate topology model exists for such networks. Moreover, routing protocols based on either static or mobile ad-hoc topology models do not exploit this predictability and thus are too inefficient for use in some application areas. We present a model that formalizes predictable dynamic topologies as sequences of static snapshots. We use this model to design and prove the correctness of a protocol based on link-state routing, whose performance is superior to its static and ad-hoc counterparts. Our routing protocol accounts for occurrences of additional, unpredictable changes, as well as their interaction with predictable changes. As an application area, we focus on routing in spacecraft networks and explain the suitability of our protocol for this application domain. Daniel Fischer 0006, David A. Basin, Thomas Engel 0001 |
ICNP | 3 |
| 2008 | Unlinkable CommunicationabstractIn this paper we present a protocol for unlinkable communication, i.e. where an attacker cannot map the sender and receiver node of a communication. Existing anonymity protocols either do not guarantee unlinkability (e.g. Tor and Mix networks), or produce huge overhead -- the dining cryptographers network causes quadratic number of messages. Our protocol needs only a linear number of messages while it still guarantees unlinkability. We introduce a measure of unlinkability and show that our protocol offers the highest possible degree of unlinkability. We show how to use the protocol in practice by adapting it to Internet and ad hoc communication. Volker Fusenig, Eugen Staab, Ulrich K. Sorger, Thomas Engel 0001 |
PST | 4 |
| 2007 | Formalizing Excusableness of Failures in Multi-Agent Systems
Eugen Staab, Thomas Engel 0001 |
PRIMA | 2 |
| 2006 | Bandwidth Consumption for Providing Fair Internet Access in Wireless Mesh NetworksabstractThe contribution of this work is to examine the performance of WMNs concerning bandwidth. Here, we provide a lower bound for bandwidth utilization in mesh networks. We analyze how much bandwidth may be provided to all mesh nodes if they communicate over one wireless communication channel and use the same gateway to the Internet. Even in such a scenario where devices compete on the access to the wireless channel it is possible to operate without bandwidth loss and share this bandwidth uniformly over the set of mesh nodes. This is achievable by optimizing spatial reuse. Here, this is achieved by scheduling channel access using time slots. Of course, this is not possible for every network topology. We measure the fraction of topologies that may operate with a uniformly shared maximum bandwidth Thomas Scherer, Thomas Engel 0001 |
SECON | 2 |
| 2000 | Implementation of an Enterprise-Level Groupware System Based on J2EE Platform and WebDAV ProtocolabstractAccording to our definition, the enterprise-level groupware system (EGS) is the Web-based groupware that focuses specifically on addressing some crucial cooperation requirements put forward by Business-to-Business and Business-to Consumer electronic commerce. In this paper, we propose a new approach for constructing EGSs, in which a latest IETF specification: WebDAV is adopted in order to fully unlease the Web's potential in supporting cooperation activities, and at the same time, an enterprise-level platform: J2EE is adopted in order to ensure some enterprise-level features of the system, e.g., scalability, availability, extensibility and security. We then introduce a prototype EGS implementation called "Cooperative Workbench", which is developed in our institute. This prototype has partly proven the advantages of this new approach and its promising application prospects in the future EGSs. Changtao Qu, Thomas Engel 0001, Christoph Meinel |
EDOC | 2 |
| 2000 | Proposal for a combination of compression and encryption
Lutz Vorwerk, Thomas Engel 0001, Christoph Meinel |
VCIP | 2 |