Graph Neural Networks (GNNs)

Graph Neural Networks (GNNs) have shown great success in learning on graph-structured data, such as social networks, recommendation systems, and protein-protein interactions. In our work, we leverage the fact that circuits can be represented naturally as graphs and we employ GNNs to learn the properties of circuits. Through our graph-based learning on circuits, we are able to identify critical security vulnerabilities in the implementations of various design-for-trust solutions aimed to achieve hardware security.

Cybersecurity implications of Construction 4.0

The construction industry is shifting towards digitalization and automation (known as Construction 4.0), impacting the different phases of construction projects, from planning to design to construction and operation. This shift includes creating, editing, storing, and sharing information in digital environments and monitoring and controlling site activities by utilizing (semi)autonomous robotic systems and remote-controlled machines. Although this transformation is very exciting and promising, it also makes the construction sector a vulnerable target for cyber-attacks and raises many questions about privacy and security concerns. With the support from the CCS-AD, researchers from the S.M.A.R.T. Construction Research Group at NYUAD, led by Prof. Borja García de Soto, investigate some of the cybersecurity implications of Construction 4.0.

Change Your Pa55w0rd – FragAttacks: Clarifying Some Aspects

To better protect Wi-Fi networks, the new WPA3 security protocol was created in 2018. One of its core features is that it prevents a malicious individual from rapidly trying to guess your Wi-Fi password. This means that with WPA3 you can use simpler passwords but still enjoy strong security. Unfortunately, our research uncovered design flaws in WPA3 that still allowed a malicious individual to crack the password. To fix this vulnerability, including other flaws that we discovered, we collaborated with the industry. As a result, when you now buy a new Wi-Fi device that supports WPA3, it will include our fixes.

Recently, we also discovered security issues that affect all versions of Wi-Fi. A malicious individual that is within range of a victim’s Wi-Fi network can abuse these vulnerabilities to steal user information or attack devices. Some of these security issues are present in the design of Wi-Fi, and as a result, all Wi-Fi devices are affected by them. Surprisingly, the root cause of some of these issues was already present in the first version of Wi-Fi, meaning these flaws have been part of Wi-Fi since its release in 1997! To protect users, we collaborated with the industry to prepare updates that mitigate the impact of our discovered attacks. We therefore strongly remind everyone to regularly update their devices.

You can visit https://wpa3.mathyvanhoef.com and https://fragattacks.com for more information.

Cyber Security Research in the Arab Region: A Blooming Ecosystem with Global Ambitions

Our view on cyber security research in the Arab region. Article by Christina Pöpper, Michail Maniatakos, Roberto Di Pietro. Communications of the ACM, April 2021, Vol. 64 No. 4, Pages 96-101
10.1145/3447741 Arab World Special Section: Big Trends

In a region where political tensions are recurrent, the strive for security is crucial. This applies equally to the cyberspace, where the need for cyber security is magnified by the level of digitization and technical penetration that the Arab region is experiencing. For instance, the Internet penetration ratea is generally higher than 90% and, in some cases such as Kuwait, UAE, and Qatar, approaches 100%. As such, many Arab countries have recognized that the security of cyberspace is an integral part of their economic systems and a matter of national security. This awareness has been followed by policies and actions: In the International Telecommunication Union’s (ITU) Global Cybersecurity Index,b the states of Oman, KSA, Egypt, and Qatar rank among the top-20 countries globally—with a considerable part of the Arab countries consistently ranking higher than many European countries. The strive for cyber security is a global as much as a local—and also Arab—endeavor, and the Arab region is gaining pace in cyber security research efforts and achievements. In this article, we will survey the main initiatives related to cyber security in the Arab region, report on the evolution of the cyber security posture, and point to possible Pan-Arab and international collaboration avenues in cyber security research..

Cyber security can be considered as specific to the Arab region as computing itself: Many of the threats, software and hardware developments, and industrial endeavors relating to cyber security are not exclusively tied to the region but are instead of a global character due to the nature of digitalization.

However, the political, economic, cultural, and financial contexts of Arab countries create a particular environment for facing attacks and addressing cyber security issues. The way the Arab world responds to cyber security challenges—in a broad but common understanding encompassing also trust and privacy—does not happen without tension or regional specificity: for instance, the protection of families and the respect for family life are an integral part of the Arab culture, while the strive for privacy protection is neither rooted nor strongly manifested in everyday digital life in Arab countries. Furthermore, while certain Arab countries are well known for their strong financial standing and politically stable systems—some being at the forefront of creating digital societies—others are suffering from war, instability, corruption, and poverty, which creates a heterogeneous and fragmented environment for threats and defenses on various scales.

As an example, the countries in the Gulf region share a strong dependency of their GDP on the oil and gas industry. For instance, the oil and gas sector accounts for roughly 87% of Saudi budget revenues, 60% of Qatar’s GDP, 40% of Kuwait’s GDP, and 30% for UAE’s GDP, to cite a few. Moreover, the production sites are typically concentrated in specific, narrow geographic regions, and represent a critical asset for the cited countries. For instance, on September 14, 2019, drones were used to attack the state-owned Saudi Aramco oil processing facilities at Abqaiq (Biqayq in Arabic) and Khurais in eastern Saudi Arabia, while in 2012 the Shamoon virus (aka W32.Dist-Track) was used against national oil companies including Saudi Arabia’s Saudi Aramcoc and Qatar’s RasGas.d A group named “Cutting Sword of Justice” claimed responsibility for an attack on 35,000 Saudi Aramco workstations, causing the company to spend more than a week restoring their services. Computer systems at RasGas were knocked offline by an unidentified computer virus, with some security experts attributing the damage to Shamoon. In 2017, software commonly referred to as Tritone was the first malware to attack an industrial control system directly (not the IT infrastructure, like Shamoon did) by attacking a Saudi Arabian petrochemical plant. The cited attacks had worldwide consequences, sending up the price of oil, with further cascading effects and their increasing sophistication is alarming, pointing to state-level actors.

Consequently, awareness of the importance of cyber security raised within the national governments in the Arab region. One can observe committed endeavors toward the creation of secure digital environments within Arab countries, manifested by the development of national cyber security strategies and the establishment of national cyber security agencies—at varying levels of maturity and scope (see accompanying table). National cyber security strategies exist or are in rollout for Egypt, Jordan, Lebanon, Kuwait, Qatar and the UAE, others have occurred as drafts or are in development (Saudi Arabia, Bahrain). For other Arab countries, the recognition of cyber security as a matter requiring a national strategy is gaining momentum. The endeavors have been well directed and managed, as shown by international benchmarks. For instance, ITU’s cyber security index is overall rising in many Arab countries (see accompanying figure), indicating the national strategies, capabilities, and programs in the field of cyber security are on the rise (regarding national cyber security strategies and computer emergency response teams, but also cybercrime legislation, awareness, and capacity building).

Read the full Article here

ACM WiSec 2021

The 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks (ACM WiSec 2021) will take place as an online/virtual conference from June 28 to July 1, 2021. The event will be hosted by the Center for Cyber Security at New York University Abu Dhabi (NYUAD).

Click here for more information