Kai Zeng

CR
h-index44
6papers
180citations
Novelty39%
AI Score22

6 Papers

5.2CRAug 9, 2020
Consumer UAV Cybersecurity Vulnerability Assessment Using Fuzzing Tests

David Rudo, Kai Zeng

Unmanned Aerial Vehicles (UAVs) are remote-controlled vehicles capable of flight and are present in a variety of environments from military operations to domestic enjoyment. These vehicles are great assets, but just as their pilot can control them remotely, cyberattacks can be executed in a similar manner. Cyber attacks on UAVs can bring a plethora of issues to physical and virtual systems. Such malfunctions are capable of giving an attacker the ability to steal data, incapacitate the UAV, or hijack the UAV. To mitigate such attacks, it is necessary to identify and patch vulnerabilities that may be maliciously exploited. In this paper, a new UAV vulnerability is explored with related UAV security practices identified for possible exploitation using large streams of data sent at specific ports. The more in-depth model involves strings of data involving FTP-specific keywords sent to the UAV's FTP port in the form of a fuzzing test and launching thousands of packets at other ports on the UAV as well. During these tests, virtual and physical systems are monitored extensively to identify specific patterns and vulnerabilities. This model is applied to a Parrot Bebop 2, which accurately portrays a UAV that had their network compromised by an attacker and portrays many lower-end UAV models for domestic use. During testings, the Parrot Bebop 2 is monitored for degradation in GPS performance, video speed, the UAV's reactivity to the pilot, motor function, and the accuracy of the UAV's sensor data. All these points of monitoring give a comprehensive view of the UAV's reaction to each individual test. In this paper, countermeasures to combat the exploitation of this vulnerability will be discussed as well as possible attacks that can branch from the fuzzing tests.

4.3SPAug 27, 2019
Physical Layer Key Generation in 5G Wireless Networks

Long Jiao, Ning Wang, Pu Wang et al.

The bloom of the fifth generation (5G) communication and beyond serves as a catalyst for physical layer key generation techniques. In 5G communications systems, many challenges in traditional physical layer key generation schemes, such as co-located eavesdroppers, the high bit disagreement ratio, and high temporal correlation, could be overcome. This paper lists the key-enabler techniques in 5G wireless networks, which offer opportunities to address existing issues in physical layer key generation. We survey the existing key generation methods and introduce possible solutions for the existing issues. The new solutions include applying the high signal directionality in beamforming to resist co-located eavesdroppers, utilizing the sparsity of millimeter wave (mmWave) channel to achieve a low bit disagreement ratio under low signal-to-noise-ratio (SNR), and exploiting hybrid precoding to reduce the temporal correlation among measured samples. Finally, the future trends of physical layer key generation in 5G and beyond communications are discussed.

10.9CRMay 15, 2019
Machine Learning-Based Delay-Aware UAV Detection and Operation Mode Identification over Encrypted Wi-Fi Traffic

Amir Alipour-Fanid, Monireh Dabaghchian, Ning Wang et al.

The consumer UAV (unmanned aerial vehicle) market has grown significantly over the past few years. Despite its huge potential in spurring economic growth by supporting various applications, the increase of consumer UAVs poses potential risks to public security and personal privacy. To minimize the risks, efficiently detecting and identifying invading UAVs is in urgent need for both invasion detection and forensics purposes. Given the fact that consumer UAVs are usually used in a civilian environment, existing physical detection methods (such as radar, vision, and sound) may become ineffective in many scenarios. Aiming to complement the existing physical detection mechanisms, we propose a machine learning-based framework for fast UAV identification over encrypted Wi-Fi traffic. It is motivated by the observation that many consumer UAVs use Wi-Fi links for control and video streaming. The proposed framework extracts features derived only from packet size and inter-arrival time of encrypted Wi-Fi traffic, and can efficiently detect UAVs and identify their operation modes. In order to reduce the online identification time, our framework adopts a re-weighted $\ell_1$-norm regularization, which considers the number of samples and computation cost of different features. This framework jointly optimizes feature selection and prediction performance in a unified objective function. To tackle the packet inter-arrival time uncertainty when optimizing the trade-off between the detection accuracy and delay, we utilize Maximum Likelihood Estimation (MLE) method to estimate the packet inter-arrival time. We collect a large number of real-world Wi-Fi data traffic of eight types of consumer UAVs and conduct extensive evaluation on the performance of our proposed method.

1.2NIDec 26, 2017
Who is Smarter? Intelligence Measure of Learning-based Cognitive Radios

Monireh Dabaghchian, Amir Alipour-Fanid, Songsong Liu et al.

Cognitive radio (CR) is considered as a key enabling technology for dynamic spectrum access to improve spectrum efficiency. Although the CR concept was invented with the core idea of realizing cognition, the research on measuring CR cognitive capabilities and intelligence is largely open. Deriving the intelligence measure of CR not only can lead to the development of new CR technologies, but also makes it possible to better configure the networks by integrating CRs with different cognitive capabilities. In this paper, for the first time, we propose a data-driven methodology to quantitatively measure the intelligence factors of the CR with learning capabilities. The basic idea of our methodology is to run various tests on the CR in different spectrum environments under different settings and obtain various performance data on different metrics. Then we apply factor analysis on the performance data to identify and quantize the intelligence factors and cognitive capabilities of the CR. More specifically, we present a case study consisting of 144 different types of CRs. The CRs are different in terms of learning-based dynamic spectrum access strategies, number of sensors, sensing accuracy, processing speed, and algorithmic complexity. Five intelligence factors are identified for the CRs through our data analysis.We show that these factors comply well with the nature of the tested CRs, which validates the proposed intelligence measure methodology.

2.3SPOct 23, 2017
Platoon Stability and Safety Analysis of Cooperative Adaptive Cruise Control under Wireless Rician Fading Channels and Jamming Attacks

Amir Alipour-Fanid, Monireh Dabaghchian, Kai Zeng

Cooperative Adaptive Cruise Control (CACC) is considered as a key enabling technology to automatically regulate the inter-vehicle distances in a vehicle platoon to improve traffic efficiency while maintaining safety. Although the wireless communication and physical processes in the existing CACC systems are integrated in one control framework, the coupling between wireless communication reliability and system states is not well modeled. Furthermore, the research on the impact of jamming attacks on the system stability and safety is largely open. In this paper, we conduct a comprehensive analysis on the stability and safety of the platoon under the wireless Rician fading channel model and jamming attacks. The effect of Rician fading and jamming on the communication reliability is incorporated in the modeling of string dynamics such that it captures its state dependency. Time-domain definition of string stability is utilized to delineate the impact of Rician fading and jamming on the CACC system's functionality and string stability. Attacker's possible locations at which it can destabilize the string is further studied based on the proposed model. From the safety perspective, reachable states (i.e., inter-vehicle distances) of the CACC system under unreliable wireless fading channels and jamming attacks is studied. Safety verification is investigated by examining the inter-vehicle distance trajectories. We propose a methodology to compute the upper and lower bounds of the trajectories of inter-vehicle distances between the lead vehicle and its follower. We conduct extensive simulations to evaluate the system stability and safety under jamming attacks in different scenarios. We identify that channel fading can degrade the performance of the CACC system, and the platoon's safety is highly sensitive to jamming attacks.

4.3NISep 28, 2017
Online Learning with Randomized Feedback Graphs for Optimal PUE Attacks in Cognitive Radio Networks

Monireh Dabaghchian, Amir Alipour-Fanid, Kai Zeng et al.

In a cognitive radio network, a secondary user learns the spectrum environment and dynamically accesses the channel where the primary user is inactive. At the same time, a primary user emulation (PUE) attacker can send falsified primary user signals and prevent the secondary user from utilizing the available channel. The best attacking strategies that an attacker can apply have not been well studied. In this paper, for the first time, we study optimal PUE attack strategies by formulating an online learning problem where the attacker needs to dynamically decide the attacking channel in each time slot based on its attacking experience. The challenge in our problem is that since the PUE attack happens in the spectrum sensing phase, the attacker cannot observe the reward on the attacked channel. To address this challenge, we utilize the attacker's observation capability. We propose online learning-based attacking strategies based on the attacker's observation capabilities. Through our analysis, we show that with no observation within the attacking slot, the attacker loses on the regret order, and with the observation of at least one channel, there is a significant improvement on the attacking performance. Observation of multiple channels does not give additional benefit to the attacker (only a constant scaling) though it gives insight on the number of observations required to achieve the minimum constant factor. Our proposed algorithms are optimal in the sense that their regret upper bounds match their corresponding regret lower-bounds. We show consistency between simulation and analytical results under various system parameters.