
The parameterized pattern matching (PPM) problem is seeking occurrences of one string in another, where both strings are given from two parameter and constant alphabet sets. In this matching paradigm, a consistent renaming of symbols from the parameter alphabet is allowed. The parameterized pattern matching is useful in problems in software engineering, computational biology, and other applications. In this paper, for the first time, we consider the problem of secure parameterized multi-pattern matching (SPMPM) that an owner of a set of patterns allows matching of his/her patterns against the text while pattern owner only learns matching results and the text owner learns nothing. In our setting, a pattern owner can find the matching locations in multiple texts in a privacy-preserving manner. The server only performs operations over encrypted values and cannot obtain any information about the text or the patterns. The proposed scheme is efficient for the pattern owner and every text owner. We prove the security of our scheme via the simulation-based paradigm.
Reverse engineering using Side Channel Attacks (SCA) have been known as a serious menace against embedded devices. The attacker could employ side channel data to retrieve some sensitive information from the device, security analysis, existence of a library in the device or execution of a special stream of codes. Side channel data could be gathered from the power consumption or electromagnetic radiations by the device. In this paper, we propose a disassembler to extract the instructions of the device under attack. A deep convolutional neural network is employed to make templates of the target to use it for real-time scenarios. Short Time Fourier Transform (STFT), and Mel-Frequency Cepstrum Coefficients (MFCC) are utilized as feature extractors. The proposed method consists of two different parts: 1) Hierarchical scenario and 2) Sole model. Atmel 8-bit AVR micro-controller is employed as the target device under attack. Our results indicate that, even with an experimental and low cost setup a vast number of instructions are detectable. The proposed method reaches 98.21% accuracy on the real code, outperforms state-of-the-art methods on the proposed dataset.
In recent years pairing-based cryptographic protocols have attracted so much attention. Meanwhile identity-based cryptography based on bilinear pairings has received particular attention. The IEEE, IETF, and ISO organizations have been working on standardization of pairing-based cryptographic schemes. The Boneh-Franklin identity-based encryption is the most well-known identity-based scheme that has been standardized. So far, various schemes have been proposed to reduce the computational cost of pairing operations. All these schemes are trying to outsource pairing operations in a secure manner. But in addition to pairing operations, there are other basic and costly operations in pairing-based cryptography and identity-based schemes, including scalar multiplication on elliptic curves. In this research, we outsource the Boneh-Franklin encryption in a more secure and efficient (in terms of computational and communication complexity) way than existing schemes. The proposed scheme is secure in the OMTUP model. Also, unlike previous schemes, we considered communication channels insecure. Moreover, compared with the trivial solution which outsources every single operation (such as pairing, scalar multiplication and modular exponentiation) as a separate subroutine, our scheme offers less complexity by seamlessly outsourcing the whole encryption scheme for the first time.
Web application firewalls (WAF) are the last line of defense in protecting web applications from application layer security threats like SQL injection and cross-site scripting. Currently, most evasion techniques from WAFs are still developed manually. In this work, we propose a solution, which automatically scans the WAFs to find payloads through which the WAFs can be bypassed. Our solution finds out rules defects, which can be further used in rule tuning for rule-based WAFs. Also, it can enrich the machine learning-based dataset for retraining. To this purpose, we provide a framework based on reinforcement learning with an environment compatible with OpenAI gym toolset standards, employed for training agents to implement WAF evasion tasks. The framework acts as an adversary and exploits a set of mutation operators to mutate the malicious payload syntactically without affecting the original semantics. We use Q-learning and proximal policy optimization algorithms with the deep neural network. Our solution is successful in evading signature-based and machine learning-based WAFs.
Fragile watermarking is the task of embedding a watermark in an image such that even small changes, called tamper, in the image can be detected or even recovered to preserve unauthorized alteration. A well-known type of spatial fragile watermarking embeds the watermark in the least significant bits of the image to measure correctness of the most significant bits. In addition, Hamming code is a coding algorithm in communication that transmits the data-bits by augmenting some check-bits to exactly detect and recover single-bit modifications. This property is used, in this paper, to detect and perfectly recover the images modified by a tamper with diameter less than a half of the diameter of the image. Based on our knowledge, this is the first time that perfect reconstruction is guaranteed in a high probable condition. To achieve this goal, the Hamming code is applied on a distributed pixel of which bits are extracted from far sufficient pixels in the image. According to the experimental results, the proposed method achieves better performance, in terms of recovering the tampered areas, in comparison to state-of-the-art.
LSB matching techniques are widely applied in the field of image steganography. In such algorithms, pixel values of each group must be changed in a way that a predefined function of the pixel group matches the secret digit. The notational system of the secret digits can be every desired number, as well as the size of the pixel groups. In order to preserve the quality of the stego image, it is desired to limit the changes in the pixel groups as much as possible. Therefore, optimum strategies must be found to match the function of the pixel group to the secret digit with the least possible imposed distortion in terms of mean square error. Having been recently found for pixel pairs, such strategies are found for the larger pixel groups by the proposed method in this paper. Among all the strategies providing the similar minimum MSE value, the one is chosen that helps to preserve the histogram of the original image. Optimum strategies found for all notational systems and pixel group sizes make the algorithm flexible for various application with different payloads, while it improves the similar techniques in terms of both MSE reduction and histogram preservation.
Simon's algorithm is one of the most widely used quantum algorithms in cryptanalysis of symmetric ciphers, which has a significant advantage over its classical counterparts. However, if the number of unwanted collisions of the target function is large or if the number of adversary's quantum superposition queries is limited, the Simon's algorithm is not able to unambiguously compute the actual period. This problem can lead to the failure of period-finding-based quantum attacks. In this paper we first show that using Simon's algorithm, one can find proper partial periods of Boolean vector functions, such that the corresponding probabilities, independent of the target function, are directly related to the number of quantum queries. Next, we examine how to use the partial period instead of actual one in quantum period-finding-based attacks. As a result, the advantage of our proposed relaxing method is twofold: It improves success probabilities of quantum period-finding-based distinguishers, provided that the adversary is limited to a specified small number of queries, in contrast to the previous ones. On the other hand, our proposed method generalizes the previous forgery attacks on modes of operation for message authentication codes.
Saturnin is a suite of lightweight symmetric algorithms which is proposed in ToSC2020 and also is a second-round NIST Lightweight competition candidate. Its aim is to provide security both in classical and post-quantum setting. In this paper, we provide a security analysis of Saturnin block cipher against integral distinguisher using bit-based division property and propose a 9-round integral characteristic, which is the first integral cryptanalysis results externally published on Saturnin. We also provide an evaluation of the tightness of the data complexity bounds for integral distinguishers given by the designers for a different number of rounds of Saturnin.
There has been a considerable growth in interest in the modeling and analyzing of signed social networks (SSNs). However, the anonymity, dispersed, and open character of these frameworks, which stimulate users' communication capacities, and contribute to the spread of low-quality information, assaults, and manipulations from malicious users. In order to improve the robustness of a network in response to anonymity and increasing users' confidence in a social network, it is critical to analyze the vulnerability for external disturbances such as a random defense attack that targets the trust-ability of the network. In this paper, we propose an approach to capture the vulnerability of the SSNs in terms of pairwise trusts and analyze the change of balance of SSNs under various changes. To analyze the vulnerability of structural balance in SSNs, the most challenge is finding that how the energy function of a network will be changed when popular nodes, especially nodes with a high-value of trust, change their signs. We also analyze the changes of energy function using a ranking method for nodes based on trust values. As a result, by changing the value of the energy function of a network the network structure is likely intended to be unbalanced.
Since the emerge of wireless body area networks (WBANs) as a new technology in telemedicine, the challenges of secure communications in these networks have been noticed, extensively. Recently, Gao et al. have designed an efficient access control protocol for WBANs and claimed that their proposal can authenticate the physician to the patient and satisfy the confidentiality of the request message sent from the physician to the patient concurrently, in a certificateless setting. Moreover, at the end of the protocol the physician and the patient establish a session key for their next secure communications. They first designed a certificateless signcryption (CL-SC) scheme and then implied it to propose their access control protocol. In this paper, we design a key replacement attack against the Gao et al.'s CL-SC scheme, in which the adversary can obtain the confidential request message sent from the physician to the patient. Moreover, based on our designed attack, the adversary can obtain the session key established by the physician for the next communications to the patient. Afterwards, we fix the scheme to be secure against our proposed attacks.
Evasion techniques are used by some Android malware to hide their malicious behavior and to hinder their execution during the dynamic analysis process. Many tools tackle such evasions by using a manually created list of API functions (as sources of evasions) to detect these evasions. As an important consequence, no matter how good the tool is, it can only guarantee to defeat these evasions and extract the real behavior of the malware if its list of evasion sources is complete. This way, if some evasion sources are missing from the list or when similar API functions are used, the dynamic analysis can be hindered. In this paper, we propose a machine learning approach to detect and categorize various evasion sources in Android malware. The proposed approach uses a manually collected training dataset to train two classifiers. The first classifier is used to detect the evasion nature of the Android API methods, while the second classifier is used to categorize the detected evasion sources into predefined categories. We applied the proposed approach to a large number of methods extracted from Android API 27. The proposed approach could detect hundreds of evasions with accuracy of 92.8% for the first classifier and 90.5% for the second classifier. The evaluation for 500 real-world samples showed that many of the evasions are detected by our approach, are not considered by the state-of-the-art dynamic analysis frameworks that are indeed used by malware samples.
Using generative models to generate unlimited number of synthetic samples is a popular replacement of database sharing. When these models are built using sensitive data, the developers should ensure that the training dataset is appropriately protected. Hence, quantifying the privacy risk of these models is important. In this paper, we focus on evaluating privacy risk of publishing generator in generative adversarial network (GAN) models. Specially, we conduct a white box membership inference attack against GAN models. The proposed attack is applicable to various kinds of GANs. We evaluate our attack accuracy with respect to various model types and training configurations. The results demonstrate superior performance of the proposed attack compared to previous attacks in white box generator access.
In IoT scenarios, computational and communication costs on the user side are important problems. In most expressive ABE schemes, there is a linear relationship between the access structure size and the number of heavy pairing operations that are used in the decryption process. This property limits the application of ABE. We propose an expressive CP-ABE with the constant number of pairings in the decryption process. The simulation shows that the proposed scheme is highly efficient in encryption and decryption processes. In addition, we use the outsourcing method in decryption to get better performance on the user side. The main burden of decryption computations is done by the cloud without revealing any information about the plaintext. We introduce a new revocation method. In this method, the users' communication channels aren't used during the revocation process. These features significantly reduce the computational and communication costs on the user side that makes the proposed scheme suitable for applications such as IoT. The proposed scheme is selectively CPA-secure in the standard model.
Nowadays, vehicular ad-hoc networks (VANETs) attract lots of attention due to their significant impact on controlling traffic and reducing road accidents. One of the major issues in VANETs is to satisfy their security requirements. Authentication and privacy preservation are the most important security requirements in VANETs. The SPACF scheme claims that efficiently meets these requirements. This scheme is software-based and does not depend heavily on tamper-proof hardware devices. A security and efficiency analysis of the SPACF scheme has been provided in this paper. Briefly, this scheme is vulnerable to replay attacks in the initial handshake phase. Moreover, the SPACF makes use of timestamps to provide freshness of message in the signing phase. It requires the strong assumption that all vehicles and road-side units are synchronized. It has been shown that the way authentication and privacy preservation are met is not efficient. To address the problems of the SPACF, a new scheme has been proposed which not only prevents replay attacks in the initial handshake and message signing phases but also is more computationally efficient than the SPACF scheme. Additionally, a security and efficiency comparison with the SPACF and two other well-known schemes depicts the advantages of our scheme over these schemes.
Steganography is a solution for covert communication and blockchain is a p2p network for data transmission, so the benefits of blockchain can be used in steganography. In this paper, we discuss the advantages of blockchain in steganography, which include the ability to embed hidden data without manual change in the original data, as well as the readiness of the blockchain platform for data transmission and storage, which eliminates the need for the Steganographer to design and implement a new platform for data transmission and storage. We have proposed two algorithms for steganography in blockchain, the first one is a high-capacity algorithm for the key and the steganography algorithm exchange and switching, and the second one is a medium-capacity algorithm for embedding hidden data. Also, by reviewing the previous three steganography schemes in blockchain, we have examined their drawback and have showed that none of them are practical schemes for steganography in blockchain. Then, we have explained the challenges of steganography in blockchain from the steganographers and steganalyzers point of view.
With the spread of information technology in human life, data protection is a critical task. On the other hand, malicious programs are developed, which can manipulate sensitive and critical data and restrict access to this data. Ransomware is an example of such a malicious program that encrypts data, restricts users’ access to the system or their data, and then request a ransom payment. Many types of research have been proposed for ransomware detection. Most of these methods attempt to identify ransomware by relying on program behavior during execution. The main weakness of these methods is that it is not clear how long the program should be monitored to show its real behavior. Therefore, sometimes, these researches cannot early detect ransomware. In this paper, a new method for ransomware detection is proposed that does not require running the program and uses the PE header of the executable files. To extract effective features from the PE header files, an image based on PE header is constructed. Then, according to the advantages of Convolutional Neural Networks in extracting features from images and classifying them, CNN is used. The proposed method achieves 93.33% accuracy. Our results indicate the usefulness and practicality method for ransomware detection.
Nowadays, with the increasing use of computers and the Internet, more people are exposed to cyber-security dangers. According to antivirus companies, malware is one of the most common threats of using the Internet. Therefore, providing a practical solution is critical. Current methods use machine learning approaches to classify malware samples automatically. Despite the success of these approaches, the accuracy and efficiency of these techniques are still inadequate, especially for multiple class classification problems and imbalanced training data sets. To mitigate this problem, we use deep learning-based algorithms for classification and generation of new malware samples. Our model is based on the opcode sequences, which are given to the model without any pre-processing. Besides, we use a novel generative adversarial network to generate new opcode sequences for oversampling minority classes. Also, we propose the model that is a combination of Convolutional Neural Network (CNN) and Long Short Term Memory (LSTM) to classify malware samples. CNN is used to consider short-term dependency between features; while, LSTM is used to consider longer-term dependence. The experiment results show our method could classify malware to their corresponding family effectively. Our model achieves 98.99% validation accuracy.
A certificateless signcryption (CL-SC) scheme is an important cryptographic primitive which provides the goals of a signature scheme (i.e. the unforgeability) and an encryption scheme (i.e. the confidentiality) both at once, in a certificateless setting. The certificateless public key cryptography (CL-PKC) setting, makes it possible to overcome the problems of the conventional public key infrastructure (i.e. the certificates management) and the ID-Based public key cryptography (i.e. the key escrow problem), concurrently. Recently, Caixue [4], Shan [16] and Ullah et al. [17] have proposed CL-SC schemes. In this paper, these schemes are analyzed. Some attacks are designed which show that Caixue's scheme is easily forgeable and Shan's scheme is forgeable against a malicious key generation center (KGC). Moreover, it is shown that Ullah et al.'s scheme has basic errors in its algorithms, as it does not even satisfy the correctness of the verification algorithm and it is not a CL-SC scheme at all.
The emergence of Internet of Things (IoT) is turning common conceptions of the current Internet into a dream of smart objects that communicate with each other. Wireless Sensor Networks (WSNs) play an important role in such an environment, since they include a wide range of applications. Researchers are already working on how WSN can be effectively integrated into the IoT environment. One part of the integration is the security aspect. In recent years, Farash et al. proposed an efficient user authentication and key agreement scheme for Heterogeneous WSN (HWSN) tailored for the IoT environment. Although their scheme is efficient, we found that this scheme is vulnerable to several cryptographic attacks. This paper first demonstrates all security weaknesses of the Farash et al.'s scheme and then proposes a secure and improved mutual authentication and key agreement scheme.
Considering the dependency between the power consumption of implemented cryptographic algorithms and the data being processed, side-channel analysis methods can reveal the secret information of these systems. It was previously thought that data acquisition of dynamic power needs physical access to these systems, but recent studies show, it is possible to gather information about power consumption from FPGAs without any physical access. High flexibilities of modern FPGAs cause that they are used for cloud accelerator in Platform as a Service (PaaS) system; however, new serious vulnerabilities emerged for these platforms. Although there are some reports about how switching activities from one region of FPGA affect other regions, details of this technique are not analyzed. In this paper, we analyzed the strength of this kind of attack and examined the impact of geometrical and electrical parameters of the victim/attacker modules on the efficiency of this attack. Experimental results and analyses show that the relational location, and the distance of victim/attacker modules, have considerable impacts on the quality of attack. Results of this analysis can help the FPGA manufacturer and IP developers to protect their systems against this serious attack.