Change Your Pa55w0rd – FragAttacks: Clarifying Some Aspects

To better protect Wi-Fi networks, the new WPA3 security protocol was created in 2018. One of its core features is that it prevents a malicious individual from rapidly trying to guess your Wi-Fi password. This means that with WPA3 you can use simpler passwords but still enjoy strong security. Unfortunately, our research uncovered design flaws in WPA3 that still allowed a malicious individual to crack the password. To fix this vulnerability, including other flaws that we discovered, we collaborated with the industry. As a result, when you now buy a new Wi-Fi device that supports WPA3, it will include our fixes.

Recently, we also discovered security issues that affect all versions of Wi-Fi. A malicious individual that is within range of a victim’s Wi-Fi network can abuse these vulnerabilities to steal user information or attack devices. Some of these security issues are present in the design of Wi-Fi, and as a result, all Wi-Fi devices are affected by them. Surprisingly, the root cause of some of these issues was already present in the first version of Wi-Fi, meaning these flaws have been part of Wi-Fi since its release in 1997! To protect users, we collaborated with the industry to prepare updates that mitigate the impact of our discovered attacks. We therefore strongly remind everyone to regularly update their devices.

You can visit https://wpa3.mathyvanhoef.com and https://fragattacks.com for more information.

Cyber Security Research in the Arab Region: A Blooming Ecosystem with Global Ambitions

Our view on cyber security research in the Arab region. Article by Christina Pöpper, Michail Maniatakos, Roberto Di Pietro. Communications of the ACM, April 2021, Vol. 64 No. 4, Pages 96-101
10.1145/3447741 Arab World Special Section: Big Trends

In a region where political tensions are recurrent, the strive for security is crucial. This applies equally to the cyberspace, where the need for cyber security is magnified by the level of digitization and technical penetration that the Arab region is experiencing. For instance, the Internet penetration ratea is generally higher than 90% and, in some cases such as Kuwait, UAE, and Qatar, approaches 100%. As such, many Arab countries have recognized that the security of cyberspace is an integral part of their economic systems and a matter of national security. This awareness has been followed by policies and actions: In the International Telecommunication Union’s (ITU) Global Cybersecurity Index,b the states of Oman, KSA, Egypt, and Qatar rank among the top-20 countries globally—with a considerable part of the Arab countries consistently ranking higher than many European countries. The strive for cyber security is a global as much as a local—and also Arab—endeavor, and the Arab region is gaining pace in cyber security research efforts and achievements. In this article, we will survey the main initiatives related to cyber security in the Arab region, report on the evolution of the cyber security posture, and point to possible Pan-Arab and international collaboration avenues in cyber security research..

Cyber security can be considered as specific to the Arab region as computing itself: Many of the threats, software and hardware developments, and industrial endeavors relating to cyber security are not exclusively tied to the region but are instead of a global character due to the nature of digitalization.

However, the political, economic, cultural, and financial contexts of Arab countries create a particular environment for facing attacks and addressing cyber security issues. The way the Arab world responds to cyber security challenges—in a broad but common understanding encompassing also trust and privacy—does not happen without tension or regional specificity: for instance, the protection of families and the respect for family life are an integral part of the Arab culture, while the strive for privacy protection is neither rooted nor strongly manifested in everyday digital life in Arab countries. Furthermore, while certain Arab countries are well known for their strong financial standing and politically stable systems—some being at the forefront of creating digital societies—others are suffering from war, instability, corruption, and poverty, which creates a heterogeneous and fragmented environment for threats and defenses on various scales.

As an example, the countries in the Gulf region share a strong dependency of their GDP on the oil and gas industry. For instance, the oil and gas sector accounts for roughly 87% of Saudi budget revenues, 60% of Qatar’s GDP, 40% of Kuwait’s GDP, and 30% for UAE’s GDP, to cite a few. Moreover, the production sites are typically concentrated in specific, narrow geographic regions, and represent a critical asset for the cited countries. For instance, on September 14, 2019, drones were used to attack the state-owned Saudi Aramco oil processing facilities at Abqaiq (Biqayq in Arabic) and Khurais in eastern Saudi Arabia, while in 2012 the Shamoon virus (aka W32.Dist-Track) was used against national oil companies including Saudi Arabia’s Saudi Aramcoc and Qatar’s RasGas.d A group named “Cutting Sword of Justice” claimed responsibility for an attack on 35,000 Saudi Aramco workstations, causing the company to spend more than a week restoring their services. Computer systems at RasGas were knocked offline by an unidentified computer virus, with some security experts attributing the damage to Shamoon. In 2017, software commonly referred to as Tritone was the first malware to attack an industrial control system directly (not the IT infrastructure, like Shamoon did) by attacking a Saudi Arabian petrochemical plant. The cited attacks had worldwide consequences, sending up the price of oil, with further cascading effects and their increasing sophistication is alarming, pointing to state-level actors.

Consequently, awareness of the importance of cyber security raised within the national governments in the Arab region. One can observe committed endeavors toward the creation of secure digital environments within Arab countries, manifested by the development of national cyber security strategies and the establishment of national cyber security agencies—at varying levels of maturity and scope (see accompanying table). National cyber security strategies exist or are in rollout for Egypt, Jordan, Lebanon, Kuwait, Qatar and the UAE, others have occurred as drafts or are in development (Saudi Arabia, Bahrain). For other Arab countries, the recognition of cyber security as a matter requiring a national strategy is gaining momentum. The endeavors have been well directed and managed, as shown by international benchmarks. For instance, ITU’s cyber security index is overall rising in many Arab countries (see accompanying figure), indicating the national strategies, capabilities, and programs in the field of cyber security are on the rise (regarding national cyber security strategies and computer emergency response teams, but also cybercrime legislation, awareness, and capacity building).

Read the full Article here

NYU Abu Dhabi Researchers Reveals the “Dragonfly Handshake” is Not a Secure Grip

The “dragonfly handshake”—a nickname for a wi-fi security protocol thought to provide strong protection from hacking—may not be as firm as previously thought. Two security researchers, Mathy Vanhoef of NYU Abu Dhabi and Eyal Ronen of Tel Aviv University, have found that the WPA-3 protocol can indeed by breached, despite claims that its method of authentication, called Simultaneous Authentication of Equals (SAE), would make passwords almost impossible to crack. The researchers, who won a Pwnie Cryptography Award in 2019 and garnered press coverage in Forbes Magazine, ZDNet, and others, identified “severe vulnerabilities in all implementations,” and revealed “side-channels that enable offline dictionary attacks.” Vanhoef, who is affiliated with the Center for Cybersecurity at NYU Abu Dhabi, and his colleague recently presented a paper on this work at the IEEE Security and Privacy Conference, one of five CCS-affiliated presentations delivered at the 2020 S&P Conference.

Researchers find that red-flagging misinformation could slow the spread of fake news on social media

A team led by researchers at NYU Tandon discover that credibility indicators flagging spurious headlines can reduce intention to share non-true news, though demographics and political affiliation influence their effectiveness

BROOKLYN, New York, Tuesday, April 28, 2020 – The dissemination of fake news on social media is a pernicious trend with dire implications for the 2020 presidential election. Indeed, research shows that public engagement with spurious news is greater than with legitimate news from mainstream sources, making social media a powerful channel for propaganda.

A new study on the spread of disinformation reveals that pairing headlines with credibility alerts from fact-checkers, the public, news media and even AI, can reduce peoples’ intention to share. However, the effectiveness of these alerts varies with political orientation and gender. The good news for truth seekers? Official fact-checking sources are overwhelmingly trusted.

The study, led by Nasir Memon, professor of computer science and engineering at the New York University Tandon School of Engineering and Sameer Patil, visiting research professor at NYU Tandon and assistant professor in the Luddy School of Informatics, Computing, and Engineering at Indiana University Bloomington, goes further, examining the effectiveness of a specific set of inaccuracy notifications designed to alert readers to news headlines that are inaccurate or untrue.

The work, “Effects of Credibility Indicators on Social Media News Sharing Intent,” published in the Proceedings of the 2020 ACM CHI Conference on Human Factors in Computing Systems, involved an online study of around 1,500 individuals to measure the effectiveness among different groups of four so-called “credibility indicators” displayed beneath headlines:

  • Fact Checkers: “Multiple fact-checking journalists dispute the credibility of this news”
  • News Media: “Major news outlets dispute the credibility of this news”
  • Public: “A majority of Americans disputes the credibility of this news”
  • AI: “Computer algorithms using AI dispute the credibility of this news”

“We wanted to discover whether social media users were less apt to share fake news when it was accompanied by one of these indicators and whether different types of credibility indicators exhibit different levels of influence on people’s sharing intent,” says Memon. “But we also wanted to measure the extent to which demographic and contextual factors like age, gender, and political affiliation impact the effectiveness of these indicators.”

Participants — over 1,500 U.S. residents  — saw a sequence of 12 true, false, or satirical news headlines. Only the false or satirical headlines included a credibility indicator below the headline in red font. For all of the headlines, respondents were asked if they would share the corresponding article with friends on social media, and why.

“Upon initial inspection, we found that political ideology and affiliation were highly correlated to responses and that the strength of individuals’ political alignments made no difference, whether Republican or Democrat,” says Memon. “The indicators impacted everyone regardless of political orientation, but the impact on Democrats was much larger compared to the other two groups.”

The most effective of the credibility indicators, by far, was Fact Checkers: Study respondents intended to share 43% fewer non-true headlines with this indicator versus 25%, 22%, and 22% for the “News Media,” “Public,” and “AI” indicators, respectively.

Effects of Political Affiliation

The team found a strong correlation between political affiliation and the propensity of each of the credibility indicators to influence intention to share. In fact, the AI credibility indicator actually induced Republicans to increase their intention to share non-true news:

  • Democrats intended to share 61% fewer non-true headlines with the Fact Checkers indicator (versus 40% for Independents and 19% for Republicans)
  • Democrats intended to share 36% fewer non-true headlines with the News Media indicator (versus 29% for Independents and 4.5% for Republicans)
  • Democrats intended to share 37% fewer non-true headlines with the Public indicator, (versus 17% for Independents and 6.7% for Republicans)
  • Democrats intended to share 40% fewer non-true headlines with the AI indicator (versus 16% for Independents)
  • Republicans intended to share 8.1% more non-true news with the AI indicator
bar graph (see caption for details)

Republicans are less likely to be influenced by credibility indicators, more inclined to share fake news on social media.

Patil says that while fact-checkers are the most effective kind of indicator, regardless of political affiliation and gender, fact-checking is a very labor-intensive. He says the team was surprised by the fact that Republicans were more inclined to share news that was flagged as not credible using the AI indicator.

“We were not expecting that, although conservatives may tend to trust more traditional means of flagging the veracity of news,” he says, adding that the team will next examine how to make the most effective credibility indicator — fact-checkers — efficient enough to handle the scale inherent in today’s news climate.

“This could include applying fact checks to only the most-needed content, which might involve applying natural language algorithms. So, it is a question, broadly speaking, of how humans and AI could co-exist,” he explains.

The team also found that males intended to share non-true headlines one and half times more than females, with the differences largest for the Public and News Media indicators.

bar graph showing how men are more likely to share fake news.

Men are less likely to be influenced by credibility indicators, more inclined to share fake news on social media. But indicators, especially those from fact-checkers, reduce intention to share fake news across the board.

Socializing was the dominant reason respondents gave for intending to share a headline, with the top-reported reason for intending to share fake stories being that they were considered funny.

“Effects of Credibility Indicators on Social Media News Sharing Intent” is available at: ACM Digital Library


About the New York University Tandon School of Engineering

The NYU Tandon School of Engineering dates to 1854, the founding date for both the New York University School of Civil Engineering and Architecture and the Brooklyn Collegiate and Polytechnic Institute (widely known as Brooklyn Poly). A January 2014 merger created a comprehensive school of education and research in engineering and applied sciences, rooted in a tradition of invention and entrepreneurship and dedicated to furthering technology in service to society. In addition to its main location in Brooklyn, NYU Tandon collaborates with other schools within NYU, one of the country’s foremost private research universities, and is closely connected to engineering programs at NYU Abu Dhabi and NYU Shanghai. It operates Future Labs focused on start-up businesses in downtown Manhattan and Brooklyn and an award-winning online graduate program. For more information, visit engineering.nyu.edu.

Leading NYU Tandon hardware security researcher named an IEEE fellow

World’s largest technical professional association honors Ramesh Karri for contributions to securing the supply chain for electronic design and manufacturing. His recent pioneering work addresses 3D printing, nano-scale biochips

BROOKLYN, New York, February 4, 2020 – New York University School of Engineering Professor Ramesh Karri has been named a fellow of the Institute of Electrical and Electronics Engineers (IEEE), the world’s largest technical professional association, for his contributions to and leadership in trustworthy electronic hardware.

Karri is a professor of electrical and computer engineering at NYU Tandon, co-founder and co-chair of the NYU Center for Cyber Security, and faculty leader for the world’s most comprehensive student-led cybersecurity games, CSAW (Cyber Security Awareness Worldwide).

Karri, who has more than 250 journal and conference publications to his credit, was recognized for his seminal work in ensuring that the global hardware supply chain is as secure as possible. Hardware security is an especially great concern in an age when chips are being manufactured at supplier foundries far from where they are designed, giving bad actors ample opportunity to install malicious “Trojan horse” circuits or to pirate intellectual property. Vulnerabilities in the chain threaten not only personal computers and smartphones but automotive systems, major utilities, the aerospace industry, nuclear facilities, and industrial equipment.

Karri is widely acknowledged for bringing the need for strong hardware security to the attention of the industry and for placing NYU Tandon at the forefront of the vital field. In 2002 he and his colleagues generated the first research on attack-resilient chip architecture, demonstrating before anyone else that integrated circuits’ test and debug ports could be used by hackers. Since then, he pioneered the technique of  microchip camouflaging, a tactic to prevent reverse engineering; delivered the first set of invited IEEE tutorials in hardware security in the U.S.,  Europe, and Latin America; presented the first research paper on split manufacturing, a means of thwarting counterfeiting by an untrusted foundry by dividing a chip’s blueprint into several components and distributing each to a different fabricator; explored the vulnerabilities in digital microfluidic biochips, which are used by researchers and medical professionals for diagnostics, DNA sequencing, and environmental monitoring; and more.

Some of his latest research involves the growing additive manufacturing (3D-printing) industry, whose use of computer-aided design (CAD) files leaves it subject to threats like viruses and piracy.

Karri is also well-known in the hardware security world for founding the Embedded Security Challenge, which is held each year as part of CSAW. Research developed during the contest has propelled the entire field of hardware trust, and several students who have participated in the challenge, which was inaugurated in 2008, have gone on to make important contributions to the field. The challenge was foundational in the establishment of a National Science Foundation-supported network called 
Trust-Hub, an open and collaborative digital clearinghouse and community-building site where researchers exchange papers, hardware platforms, source codes, and tools.

“I heartily congratulate Professor Karri on taking his well-deserved place as an IEEE fellow,” said Dean Jelena Kovačević. “The honor is indicative of the pioneering nature and importance of his research, which has helped make NYU Tandon a leader in a field exceptionally important to the security of the world’s cyber systems.”

In addition to his IEEE Fellowship, Karri is the recipient of a Humboldt Fellowship and a National Science Foundation CAREER Award. His work has been funded by the Office of Naval Research, the Defense Advanced Research Projects Agency (DARPA), the Army Research Office, the Air Force Research Laboratory, the Semiconductor Research Corporation, and companies including Boeing, Intel, Ford, and Cisco.

HAS THE WORLD’S FIRST UNHACKABLE CHIP ARRIVED?

Ozgur Sinanoglu is obsessed with computer chips — a passion born at age 10 when his father brought home a Commodore 64. Now 42 and the associate dean of engineering at New York University Abu Dhabi, Sinanoglu claims that he and his colleagues have designed an unhackable chip. Given last year’s Meltdown and Spectre — security flaws that researchers are calling catastrophic because they could affect nearly every computer chip manufactured in the past 20 years — producing a chip capable of repelling attacks would restore peace of mind to everyone from government agencies to private companies. 

Sinanoglu, director of the Design for Excellence Lab at NYU Abu Dhabi, is not the first to make the claim. Because chips combined in central processing units (CPUs) are essentially the brains of computers, savvy engineers around the world have come up with all manner of tricks to keep hackers at bay. And most designs ultimately join the ranks of “good effort, but not good enough.” In 2010, former U.S. Army computer specialist Christopher Tarnovsky hacked into Infineon’s allegedly unhackable SLE66 CL PE chip used in PCs, gaming consoles and e-cards. Granted, he used a $70,000 electron microscope, tiny conductive needles and acid to siphon off critical data, but the point was made: not unhackable.

What sets Sinanoglu apart — besides his roughly 20 issued or pending patents — are his heavyweight backers, from the National Science Foundation to the U.S. Department of Defense, which is supporting his research through its Defense Advanced Research Projects Agency (DARPA). Boasting a 15-page résumé of academic accomplishments, the Turkish engineer is most concerned with chips fabricated in foundries, or “fabs,” where designers can’t monitor the manufacturing process. When chips are fabricated at these third-party facilities, can we really trust the end result? No, Sinanoglu asserts, making it critical that we add defenses to make them resistant to theft or tampering by those seeking financial gain, so-called hacktivists or nefarious state actors.

After analyzing the myriad threats, Sinanoglu and his team added locks to their chip that are comparable to computer passwords except that they’re made up of a unique combination of binary code (0’s and 1’s). Fortheir first design, released in fall 2017, the team added logic, or processing information, to obscure the design. Only people with a special key could hack into the chip and replicate, steal or tamper with it. The NYU team issued a public invitation to hackers to hack away — a move that turned out to be premature. By October, they realized the logic they’d added gave away information about the key. Sure enough, the following April, a group from China’s Wuhan University hacked the chip.

Humbled but not disheartened, Sinanoglu set to work again. As he recounts what came next, he becomes visibly animated, his speech speeding up. The team revisited its process, posing new questions and finding stealthier paths to protecting the chip. Their conclusion? They needed to strip out all logic and leave no structural traces. Hackers could identify the chip design, but they would have no sense of its logic or functionality without the special key of 0’s and 1’s. The functionality, says Sinanoglu, is buried in the secret key.They unveiled the subtractive version of their chip in December 2018, and once again invited hackers to have at it. Since then, Sinanoglu says, no one has found the key.

As steeped as he is in cybersecurity now, Sinanoglu started on a different course. As a Ph.D. student in computer engineering at the University of California, San Diego, he was keenly interested in the environmental factors and manufacturing defects that affect chip functionality. After graduating in 2004, he took a job with Qualcomm, a huge multinational chipmaker, as a senior design and test engineer. Then, in 2006, with a new baby and wishing to be closer to his family in Turkey, he accepted an offer to teach computer science at Kuwait University. That gig ended in 2010 with a new job that would change the trajectory of Sinanoglu’s career.

Hired as a visiting assistant professor under the guidance of Ramesh Karri, a professor of electrical and computer engineering at NYU’s Tandon School of Engineering, Sinanoglu got hooked on the challenge of staying ahead of bad actors with malicious intent. “It’s a whole different game,” he says, one that requires constantly outpacing hackers’ creativity and intelligence. “It’s actually a more fun game,” he’s quick to add with a grin.

Karri says that most people in cybersecurity — himself included — are “a little more cautious”than his colleaguesabout claiming the existence of an unhackable chip. But “if anybody can make one, it’s Ozgur and JV,” he says, referring to Jeyavijayan “JV” Rajendran, an assistant professor of electrical and computer engineering at Texas A&M University who’s working closely with Sinanoglu on the DARPA project. But Dan Goldberg, founder of Castlerock Cyber Security and an information security consultant in Virginia, expresses skepticism that anything “as complex as a microprocessor or general purpose computing device” can be truly unhackable.

For starters, Goldberg worries about key discipline: Who has access to the key and what happens when that access is revoked? Could a spurned employee exact revenge? What if the key is lost?Goldberg’s approach is to design networks and systems that follow a “defense in-depth” model. “If a malicious actor gets access to one aspect of the system, they don’t immediately have access to everything,” he explains. Sinanoglu acknowledges that, for now, they can only secure their chip at the hardware layer, but when the hardware is compromised, the whole system is compromised — which is why he considers his team’s latest iteration the unhackable ideal he has been working toward for most of his life.

Sinanoglu clearly recalls the day in Izmir when his father, a petroleum engineer, presented him with that ancient 8-bit home computer. His younger brother, Yigit, who works as a product control manager in Switzerland, says Ozgur was glued to the device, and his competitive drive (nurtured by a natural aptitude for sports) pushed him to master every detail. “Whatever he was doing, he wanted to beat the other guys,” Yigit recalls. The “other guys” now in his sights are bad actors in the chip business.

Assuming his new design withstands scrutiny, Sinanoglu plans to deploy the technology more widely, making it both scalable and practical. Can this competitive computer nerd thwart the world’s hackers? The jury’s still out, but listening to him, it’s easy to believe the future of chip security is now.