The Experts below are selected from a list of 1248 Experts worldwide ranked by ideXlab platform
Gerhard Petrus Hancke - One of the best experts on this subject based on the ideXlab platform.
-
A Session Hijacking Attack Against a Device-Assisted Physical-Layer Key Agreement
IEEE Transactions on Industrial Informatics, 2020Co-Authors: Qiao Hu, Bianxia Du, Konstantinos Markantonakis, Gerhard Petrus HanckeAbstract:Physical-layer key agreement is used to generate a shared key between devices on demand. Such schemes utilize the characteristics of the wireless channel to generate the shared key from the device-to-device channel. As all characteristics are time-dependent and location-dependent, it is hard for eavesdroppers to get the key. However, most research works in this area use passive Attack models whereas active Attacks that aim at manipulating the channel and key are also possible. Physical-layer key agreement with User Introduced Randomness (PHYUIR) is a solution similar to the Diffie-Hellman protocol against such a kind of active Attack. The users (devices) introduce their own randomness to help to prevent active Attacks. In this paper, we analyze the possibility of launching a session Hijacking Attack on PHY-UIR to allow an Attacker to control the shared key established. The session Hijacking Attack manipulates the key agreement through a man-in-the-middle interaction and forces legitimate devices to run the PHY-UIR protocol with the Attacker. Our simulation and experiment results validate our Attack and show the high performance of our Attack on manipulating the generated key. We also propose PHY-UIR± where devices simultaneously exchange information about the established shared keys, which allows them to detect whether they have agreed to different keys with a third party.
-
A session Hijacking Attack on physical layer key generation agreement
2017 IEEE International Conference on Industrial Technology (ICIT), 2017Co-Authors: Qiao Hu, Gerhard Petrus HanckeAbstract:Physical layer key agreement is a new kind of schemes used to generate a shared key between pervasive and resource constrained devices. These schemes utilize the characteristics of the wireless channel to generate the shared key. As all characteristics are time-depend and location-depend, it is hard for eavesdroppers to get the key. But it lacks research on active Attacks which aim at manipulating the key. PHY-UIR (PHYsical layer key agreement with User Introduced Randomness) is the only paper which proposes a solution in detail to against such kind of active Attacks. In this paper, we propose a new kind of key manipulating Attack which PHY-UIR can not prevent. We call it session Hijacking Attack as the Attacker Hijacking the key agreement by injecting high power signals and force legitimate devices running PHY-UIR protocol with the Attacker. In such way, the Attacker and device generate the same key. Our simulation result validates our Attack and shows the high performance of our Attack on manipulating the generated key.
Qiao Hu - One of the best experts on this subject based on the ideXlab platform.
-
A Session Hijacking Attack Against a Device-Assisted Physical-Layer Key Agreement
IEEE Transactions on Industrial Informatics, 2020Co-Authors: Qiao Hu, Bianxia Du, Konstantinos Markantonakis, Gerhard Petrus HanckeAbstract:Physical-layer key agreement is used to generate a shared key between devices on demand. Such schemes utilize the characteristics of the wireless channel to generate the shared key from the device-to-device channel. As all characteristics are time-dependent and location-dependent, it is hard for eavesdroppers to get the key. However, most research works in this area use passive Attack models whereas active Attacks that aim at manipulating the channel and key are also possible. Physical-layer key agreement with User Introduced Randomness (PHYUIR) is a solution similar to the Diffie-Hellman protocol against such a kind of active Attack. The users (devices) introduce their own randomness to help to prevent active Attacks. In this paper, we analyze the possibility of launching a session Hijacking Attack on PHY-UIR to allow an Attacker to control the shared key established. The session Hijacking Attack manipulates the key agreement through a man-in-the-middle interaction and forces legitimate devices to run the PHY-UIR protocol with the Attacker. Our simulation and experiment results validate our Attack and show the high performance of our Attack on manipulating the generated key. We also propose PHY-UIR± where devices simultaneously exchange information about the established shared keys, which allows them to detect whether they have agreed to different keys with a third party.
-
A session Hijacking Attack on physical layer key generation agreement
2017 IEEE International Conference on Industrial Technology (ICIT), 2017Co-Authors: Qiao Hu, Gerhard Petrus HanckeAbstract:Physical layer key agreement is a new kind of schemes used to generate a shared key between pervasive and resource constrained devices. These schemes utilize the characteristics of the wireless channel to generate the shared key. As all characteristics are time-depend and location-depend, it is hard for eavesdroppers to get the key. But it lacks research on active Attacks which aim at manipulating the key. PHY-UIR (PHYsical layer key agreement with User Introduced Randomness) is the only paper which proposes a solution in detail to against such kind of active Attacks. In this paper, we propose a new kind of key manipulating Attack which PHY-UIR can not prevent. We call it session Hijacking Attack as the Attacker Hijacking the key agreement by injecting high power signals and force legitimate devices running PHY-UIR protocol with the Attacker. In such way, the Attacker and device generate the same key. Our simulation result validates our Attack and shows the high performance of our Attack on manipulating the generated key.
William Mahoney - One of the best experts on this subject based on the ideXlab platform.
-
knock knock who is there investigating data leakage from a medical internet of things Hijacking Attack
Hawaii International Conference on System Sciences, 2020Co-Authors: Talon Flynn, George Grispos, William Bradley Glisson, William MahoneyAbstract:A paper co-authored by William Gilsson originally published in Proceedings of the 53rd Hawaii International Conference on System Sciences in 2020.
Talon Flynn - One of the best experts on this subject based on the ideXlab platform.
-
knock knock who is there investigating data leakage from a medical internet of things Hijacking Attack
Hawaii International Conference on System Sciences, 2020Co-Authors: Talon Flynn, George Grispos, William Bradley Glisson, William MahoneyAbstract:A paper co-authored by William Gilsson originally published in Proceedings of the 53rd Hawaii International Conference on System Sciences in 2020.
Jiajia Liu - One of the best experts on this subject based on the ideXlab platform.
-
location Hijacking Attack in software defined space air ground integrated vehicular network
IEEE Internet of Things Journal, 2021Co-Authors: Jiadai Wang, Jiajia LiuAbstract:Internet of vehicles (IoV) is an emerging technology in automotive field, in which vehicles can communicate with other vehicles and roadside infrastructures to improve information acquisition ability as well as obtain various services to elevate the security and comfort level. To cope with the increasingly complex vehicular network, software-defined networking (SDN) architecture with advantages of centralized management and flexible control becomes a promising solution. However, in application scenarios, the security of SDN is rarely concerned. If Attackers exploit the vulnerabilities of SDN to hijack the network location of the servers or vehicles, vehicles may not be able to access the services they need timely and effectively, which will pose a great threat to the benefit of vehicle users. In light of this, we focus on location Hijacking Attack against SDN in vehicular network. We perform this Attack on five mainstream SDN controller platforms and analyse its impacts from multiple perspectives. As far as we know, this is the first study of such Attack in vehicular network. Furthermore, using the advantages of the software-defined space-air-ground integrated vehicular network and the characteristics of high altitude platform (HAP) such as wide coverage and high load capacity, we put forward the Attack recovery scheme based on deep Q-learning (DQL) to supplement existing defence mechanisms that always have counter Attacks and endow the vehicular network with a certain resilience.