The Experts below are selected from a list of 300 Experts worldwide ranked by ideXlab platform
Utz Roedig - One of the best experts on this subject based on the ideXlab platform.
-
WISEC - Short paper: gathering tamper evidence in wi-fi networks based on channel state information
Proceedings of the 2014 ACM conference on Security and privacy in wireless & mobile networks - WiSec '14, 2014Co-Authors: Ibrahim Ethem Bagci, Utz Roedig, Matthias Schulz, Matthias HollickAbstract:Wireless devices are often used in application scenarios with strict security requirements. Examples are Physical Intrusion detection systems commonly used to protect factories, airports or government buildings. In such scenarios, additional security features such as tamper detection are highly desirable to complement traditional cryptographic mechanisms. In this paper we use channel state information (CSI), extracted from off-the-shelf 802.11n Wi-Fi cards, to calculate a tamper-evidence value for transmitters. This value enables detection of tampering due to device movement or replacement. We describe algorithms for tamper-evidence value computation, discuss the interpretation of this value and evaluate its effectiveness.
-
MASS - DHB-KEY: An efficient key distribution scheme for wireless sensor networks
2008 5th IEEE International Conference on Mobile Ad Hoc and Sensor Systems, 2008Co-Authors: Tony Chung, Utz RoedigAbstract:Real-world deployments of wireless sensor networks require secure communication. In many application cases it is sufficient to provide message authentication at the sink. To implement this requirement using symmetric ciphers, keys shared between each sensor node and the sink have to be established and kept fresh during network operation. This paper presents a key distribution scheme based on the well known elliptic curve Diffie-Hellman key exchange mechanism that allows us to fulfil the previously outlined requirements efficiently. The DHB-KEY scheme requires only the distribution of a single sink-initiated broadcast message to set individual keys on all sensor nodes. Thus, DHB-KEY has a low complexity and preserves scarce resources such as bandwidth and energy. In the paper we present a protocol specification based on the DHB-KEY scheme and its implementation for the well known TinyOS platform. A Physical Intrusion detection system in an office building is used to evaluate the protocol implementation. The evaluation shows that DHB-KEY is practical in real-world deployments.
Emmanouil Panaousis - One of the best experts on this subject based on the ideXlab platform.
-
Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement Learning
IEEE Transactions on Information Forensics and Security, 2021Co-Authors: Ryan Heartfield, Anatolij Bezemskij, George Loukas, Emmanouil PanaousisAbstract:The modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach’s impact is not limited to cyberspace, as it can also affect or be facilitated in Physical space, for example, via voice. In this environment, Intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home Intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home’s changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and Physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format , together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve.
-
A taxonomy and survey of cyber-Physical Intrusion detection approaches for vehicles
Ad Hoc Networks, 2019Co-Authors: George Loukas, Anatolij Bezemskij, Eirini Karapistoli, Emmanouil Panaousis, Panagiotis Sarigiannidis, Tuan VuongAbstract:With the growing threat of cyber and cyber-Physical attacks against automobiles, drones, ships, driverless pods and other vehicles, there is also a growing need for Intrusion detection approaches that can facilitate defence against such threats. Vehicles tend to have limited processing resources and are energy-constrained. So, any security provision needs to abide by these limitations. At the same time, attacks against vehicles are very rare, often making knowledge-based Intrusion detection systems less practical than behaviour-based ones, which is the reverse of what is seen in conventional computing systems. Furthermore, vehicle design and implementation can differ wildly between different types or different manufacturers, which can lead to Intrusion detection designs that are vehicle-specific. Equally importantly, vehicles are practically defined by their ability to move, autonomously or not. Movement, as well as other Physical manifestations of their operation may allow cyber security breaches to lead to Physical damage, but can also be an opportunity for detection. For example, Physical sensing can contribute to more accurate or more rapid Intrusion detection through observation and analysis of Physical manifestations of a security breach. This paper presents a classification and survey of Intrusion detection systems designed and evaluated specifically on vehicles and networks of vehicles. Its aim is to help identify existing techniques that can be adopted in the industry, along with their advantages and disadvantages, as well as to identify gaps in the literature, which are attractive and highly meaningful areas of future research.
Matthias Hollick - One of the best experts on this subject based on the ideXlab platform.
-
WISEC - Short paper: gathering tamper evidence in wi-fi networks based on channel state information
Proceedings of the 2014 ACM conference on Security and privacy in wireless & mobile networks - WiSec '14, 2014Co-Authors: Ibrahim Ethem Bagci, Utz Roedig, Matthias Schulz, Matthias HollickAbstract:Wireless devices are often used in application scenarios with strict security requirements. Examples are Physical Intrusion detection systems commonly used to protect factories, airports or government buildings. In such scenarios, additional security features such as tamper detection are highly desirable to complement traditional cryptographic mechanisms. In this paper we use channel state information (CSI), extracted from off-the-shelf 802.11n Wi-Fi cards, to calculate a tamper-evidence value for transmitters. This value enables detection of tampering due to device movement or replacement. We describe algorithms for tamper-evidence value computation, discuss the interpretation of this value and evaluate its effectiveness.
George Loukas - One of the best experts on this subject based on the ideXlab platform.
-
Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement Learning
IEEE Transactions on Information Forensics and Security, 2021Co-Authors: Ryan Heartfield, Anatolij Bezemskij, George Loukas, Emmanouil PanaousisAbstract:The modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach’s impact is not limited to cyberspace, as it can also affect or be facilitated in Physical space, for example, via voice. In this environment, Intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home Intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home’s changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and Physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format , together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve.
-
A taxonomy and survey of cyber-Physical Intrusion detection approaches for vehicles
Ad Hoc Networks, 2019Co-Authors: George Loukas, Anatolij Bezemskij, Eirini Karapistoli, Emmanouil Panaousis, Panagiotis Sarigiannidis, Tuan VuongAbstract:With the growing threat of cyber and cyber-Physical attacks against automobiles, drones, ships, driverless pods and other vehicles, there is also a growing need for Intrusion detection approaches that can facilitate defence against such threats. Vehicles tend to have limited processing resources and are energy-constrained. So, any security provision needs to abide by these limitations. At the same time, attacks against vehicles are very rare, often making knowledge-based Intrusion detection systems less practical than behaviour-based ones, which is the reverse of what is seen in conventional computing systems. Furthermore, vehicle design and implementation can differ wildly between different types or different manufacturers, which can lead to Intrusion detection designs that are vehicle-specific. Equally importantly, vehicles are practically defined by their ability to move, autonomously or not. Movement, as well as other Physical manifestations of their operation may allow cyber security breaches to lead to Physical damage, but can also be an opportunity for detection. For example, Physical sensing can contribute to more accurate or more rapid Intrusion detection through observation and analysis of Physical manifestations of a security breach. This paper presents a classification and survey of Intrusion detection systems designed and evaluated specifically on vehicles and networks of vehicles. Its aim is to help identify existing techniques that can be adopted in the industry, along with their advantages and disadvantages, as well as to identify gaps in the literature, which are attractive and highly meaningful areas of future research.
-
Cloud-Based Cyber-Physical Intrusion Detection for Vehicles Using Deep Learning
IEEE Access, 2017Co-Authors: George Loukas, Tuan Vuong, Georgia Sakellari, Yongpil Yoon, Ryan Heartfield, Diane GanAbstract:OAPA Detection of cyber attacks against vehicles is of growing interest. As vehicles typically afford limited processing resources, proposed solutions are rule-based or lightweight machine learning techniques. We argue that this limitation can be lifted with computational offloading commonly used for resource-constrained mobile devices. The increased processing resources available in this manner allow access to more advanced techniques. Using as case study a small four-wheel robotic land vehicle, we demonstrate the practicality and benefits of offloading the continuous task of Intrusion detection that is based on deep learning. This approach achieves high accuracy much more consistently than with standard machine learning techniques and is not limited to a single type of attack or the in-vehicle CAN bus as previous work. As input, it uses data captured in realtime that relate to both cyber and Physical processes, which it feeds as time series data to a neural network architecture. We use both a deep multilayer perceptron and a recurrent neural network architecture, with the latter benefitting from a long-short term memory hidden layer, which proves very useful for learning the temporal context of different attacks. We employ denial of service, command injection and malware as examples of cyber attacks that are meaningful for a robotic vehicle. The practicality of computation offloading depends on the resources afforded onboard and remotely, and the reliability of the communication means between them. Using detection latency as the criterion, we have developed a mathematical model to determine when computation offloading is beneficial given parameters related to the operation of the network and the processing demands of the deep learning model. The more reliable the network and the greater the processing demands, the greater the reduction in detection latency achieved through offloading.
-
performance evaluation of cyber Physical Intrusion detection on a robotic vehicle
Dependable Autonomic and Secure Computing, 2015Co-Authors: Tuan Phan Vuong, George Loukas, Diane GanAbstract:Intrusion detection systems designed for conventional computer systems and networks are not necessarily suitable for mobile cyber-Physical systems, such as robots, drones and automobiles. They tend to be geared towards attacks of different nature and do not take into account mobility, energy consumption and other Physical aspects that are vital to a mobile cyber-Physical system. We have developed a decision tree-based method for detecting cyber attacks on a small-scale robotic vehicle using both cyber and Physical features that can be measured by its on-board systems and processes. We evaluate it experimentally against a variety of scenarios involving denial of service, command injection and two types of malware attacks. We observe that the addition of Physical features noticeably improves the detection accuracy for two of the four attack types and reduces the detection latency for all four.
-
CIT/IUCC/DASC/PICom - Performance Evaluation of Cyber-Physical Intrusion Detection on a Robotic Vehicle
2015 IEEE International Conference on Computer and Information Technology; Ubiquitous Computing and Communications; Dependable Autonomic and Secure Co, 2015Co-Authors: Tuan Phan Vuong, George Loukas, Diane GanAbstract:Intrusion detection systems designed for conventional computer systems and networks are not necessarily suitable for mobile cyber-Physical systems, such as robots, drones and automobiles. They tend to be geared towards attacks of different nature and do not take into account mobility, energy consumption and other Physical aspects that are vital to a mobile cyber-Physical system. We have developed a decision tree-based method for detecting cyber attacks on a small-scale robotic vehicle using both cyber and Physical features that can be measured by its on-board systems and processes. We evaluate it experimentally against a variety of scenarios involving denial of service, command injection and two types of malware attacks. We observe that the addition of Physical features noticeably improves the detection accuracy for two of the four attack types and reduces the detection latency for all four.
Ryan Heartfield - One of the best experts on this subject based on the ideXlab platform.
-
Self-Configurable Cyber-Physical Intrusion Detection for Smart Homes Using Reinforcement Learning
IEEE Transactions on Information Forensics and Security, 2021Co-Authors: Ryan Heartfield, Anatolij Bezemskij, George Loukas, Emmanouil PanaousisAbstract:The modern Internet of Things (IoT)-based smart home is a challenging environment to secure: devices change, new vulnerabilities are discovered and often remain unpatched, and different users interact with their devices differently and have different cyber risk attitudes. A security breach’s impact is not limited to cyberspace, as it can also affect or be facilitated in Physical space, for example, via voice. In this environment, Intrusion detection cannot rely solely on static models that remain the same over time and are the same for all users. We present MAGPIE, the first smart home Intrusion detection system that is able to autonomously adjust the decision function of its underlying anomaly classification models to a smart home’s changing conditions (e.g., new devices, new automation rules and user interaction with them). The method achieves this goal by applying a novel probabilistic cluster-based reward mechanism to non-stationary multi-armed bandit reinforcement learning. MAGPIE rewards the sets of hyperparameters of its underlying isolation forest unsupervised anomaly classifiers based on the cluster silhouette scores of their output. Experimental evaluation in a real household shows that MAGPIE exhibits high accuracy because of two further innovations: it takes into account both cyber and Physical sources of data; and it detects human presence to utilise models that exhibit the highest accuracy in each case. MAGPIE is available in open-source format , together with its evaluation datasets, so it can benefit from future advances in unsupervised and reinforcement learning and be able to be enriched with further sources of data as smart home environments and attacks evolve.
-
Cloud-Based Cyber-Physical Intrusion Detection for Vehicles Using Deep Learning
IEEE Access, 2017Co-Authors: George Loukas, Tuan Vuong, Georgia Sakellari, Yongpil Yoon, Ryan Heartfield, Diane GanAbstract:OAPA Detection of cyber attacks against vehicles is of growing interest. As vehicles typically afford limited processing resources, proposed solutions are rule-based or lightweight machine learning techniques. We argue that this limitation can be lifted with computational offloading commonly used for resource-constrained mobile devices. The increased processing resources available in this manner allow access to more advanced techniques. Using as case study a small four-wheel robotic land vehicle, we demonstrate the practicality and benefits of offloading the continuous task of Intrusion detection that is based on deep learning. This approach achieves high accuracy much more consistently than with standard machine learning techniques and is not limited to a single type of attack or the in-vehicle CAN bus as previous work. As input, it uses data captured in realtime that relate to both cyber and Physical processes, which it feeds as time series data to a neural network architecture. We use both a deep multilayer perceptron and a recurrent neural network architecture, with the latter benefitting from a long-short term memory hidden layer, which proves very useful for learning the temporal context of different attacks. We employ denial of service, command injection and malware as examples of cyber attacks that are meaningful for a robotic vehicle. The practicality of computation offloading depends on the resources afforded onboard and remotely, and the reliability of the communication means between them. Using detection latency as the criterion, we have developed a mathematical model to determine when computation offloading is beneficial given parameters related to the operation of the network and the processing demands of the deep learning model. The more reliable the network and the greater the processing demands, the greater the reduction in detection latency achieved through offloading.