Showing posts with label stefan savage. Show all posts
Showing posts with label stefan savage. Show all posts

Friday, March 18, 2016

FBI issues PSA on cars' cybersecurity citing work by Jacobs School researchers

Last summer, computer scientists at the Jacobs School demonstrated that they could wirelessly control thousands of vehicles via a gadget that's often used by insurance companies to monitor cars. The team, led by Professor Stefan Savage, has worked to raise awareness of flaws in the cybersecurity of cars since 2010.

On March 17, the Federal Bureau of Investigation issued a public service announcement titled "Motor Vehicles Increasingly Vulnerable to Remote Exploits," which alludes to the researchers' work:
As previously reported by the media in and after July 2015, security researchers evaluating automotive cybersecurity were able to demonstrate remote exploits of motor vehicles. The analysis demonstrated the researchers could gain significant control over vehicle functions remotely by exploiting wireless communications vulnerabilities. While the identified vulnerabilities have been addressed, it is important that consumers and manufacturers are aware of the possible threats and how an attacker may seek to remotely exploit vulnerabilities in the future. Third party aftermarket devices with Internet or cellular access plugged into diagnostics ports could also introduce wireless vulnerabilities.
The PSA also says:
The FBI and NHTSA are warning the general public and manufacturers – of vehicles, vehicle components, and aftermarket devices – to maintain awareness of potential issues and cybersecurity threats related to connected vehicle technologies in modern vehicles.
The agency recommends that vehicle owners check the safercar.gov website twice a year for recalls on their cars.

Tuesday, May 12, 2015

Bitcoin experts and CSE alumna wins Chancellor's Dissertation Medal

Sarah Meiklejohn, an alumna who earned a Ph.D. in the Department of Computer Science and Engineering at the Jacobs School, has won the 2015 Chancellor's Dissertation Medal. She is now an assistant professor at University College, London.

Here is what Mihir Bellare, a professor in the department and her dissertation co-advisory had to say when outlining Meiklejohn's merits:

1. Impact: The results in Sarah’s thesis have shaped government policy. The methods in the thesis have been used to track cyber-criminals. The thesis has received significant media attention (NY Times, Washington Post, radio, TV, ...).
2. Intellectual and technical depth: The thesis introduces an innovative new experimental technique to track Bitcoins that was used not only to obtain the thesis results but is now used as a key forensic tool by law enforcement.
3. Independence: Unlike many theses, which write up group projects, this one was entirely Sarah’s work. She alone conceived the idea and methods and pushed it through from algorithms to reality.
In my 20 years of experience at UCSD, I would say that a thesis with one of the above elements is rare. To have all three in the same thesis is unique and extra-ordinary.
Read our story about Meiklejohn's work here

More media coverage of her work:

Forbes 

The Economist

Wired

MIT Technology Review

KPBS

Tuesday, February 10, 2015

Watch a Jacobs School scientist on CBS's 60 Minutes


It's not every day that you get to hack into a car driven by a celebrity news correspondent--with their permission. But that's exactly what Karl Koscher, a postdoctoral fellow in the Department of Computer Science and Engineering at the Jacobs School, got to do for an episode of CBS's 60 Minutes that aired Sunday, Feb. 8.

The show was focusing on security flaws within the Internet of Things--the effort to connect appliances, computers and other devices, including cars, in a network that would make users' lives easier.  Watch the full show here: http://www.cbsnews.com/news/darpa-dan-kaufman-internet-security-60-minutes/

Koscher was putting into practice knowledge accumulated over the years by researchers in the Systems and Networking group here at the Jacobs School and in the Security and Privacy Research Lab at the University of Washington. The team first presented a ground-breaking paper on the topic in May 2010 at the IEEE Symposium on Security and Privacy in Oakland, Calif. They summed up in a press release at the time:

Modern automobiles are becoming increasingly computerized — with many components controlled partially or entirely by computers and networked both internally and externally. This architecture is indeed the basis for significant advances in safety (e.g., anti-lock brakes), fuel efficiency, and convenience. However, increasing computerization also creates new risks that must be addressed as well. Our research mission is to help ensure that these future automotive systems can enjoy the benefits of a computerized architecture while providing strong assurances of safety, security, and privacy.

Our research consists of three complementary strands: conceptual, experimental, and developmental. We conceptually evaluate the computer security landscape for potential future automobiles in order to guide our experimental and developmental research. Weexperimentally evaluate real examples of today's technologies to create informed understandings of potential computer security risks with future automobiles, as well as understandings of the challenges for overcoming those risks. We then develop new security technologies to overcome those challenges and mitigate the associated risks.
However, the researchers were quick to point out that car owners should not panic:
 
 We believe that car owners today should not be overly concerned at this time. It requiressignificant sophistication to develop the capabilities described in our paper and we are unaware of any attackers who are even targeting automobiles at this time.

However, we do believe that our work should be read as a wake-up call. While today's car owners should not be alarmed, we believe that it is time to focus squarely on addressing potential automotive security issues to ensure that future cars — with ever more sophisticated computer control and broader wireless connectivity — will be able to offer commensurately strong security guarantees as well.
More info about the research here:  http://www.autosec.org/

Wednesday, January 7, 2015

Cybercrime? It's all about the money, Jacobs School computer scientist says

Photo: Erik Jepsen/UC San Diego Publications
It's all about the money, Stefan Savage, a computer science professor at the Jacobs School, says in the Los Angeles Times. 

“Ninety-nine percent of what you and I deal with when it comes to computer security is motivated by economics,” Savage said. “Data breaches? It’s all about the money. Spam? It’s all about the money. Malware? It’s all about the money. The problem is we are looking at this as a purely technical problem.”
 Over the years, Savage and colleagues at the Jacobs School and the International Computer Science Institute, an independent nonprofit in Berkeley, have probed the economics of cyber crime. The LA Times explains:

Throughout 2011 and 2012, he and a team of researchers posed as buyers of counterfeit goods sold on the Internet and, by tracking the flow of money in these transactions, showed that only a handful of banks were involved in these activities. Working with a Washington, D.C.-based anti-piracy organization called the International Anti-Counterfeiting Coalition (IACC), they helped create a framework whereby brandholders and credit card companies could work together to shut down the counterfeiter's financial accounts, effectively cutting off their economic lifeblood.
Full LA Times article here.

 More about Savage's work here, here  and  here.

Monday, August 11, 2014

Computer scientists in the spotlight on the Torrey Pines Mesa

Several Jacobs School computer scientists and their work are highlighted in a UT San Diego story about the history of the scientific institutions on the Torrey Pines Mesa.

Under the major science accomplishments section:

•Computer scientist Kenneth Bowles and his students modified the Pascal programming language, allowing a program to be moved around from machine to machine, a technique now widely used to build mobile applications.

 •George Varghese and Stefan Savage developed the first automated method for automatically identifying worm and virus attacks across the Internet and other high-speed networks almost as soon as the outbreaks occur. Cisco acquired the technology.
We also spotted computer scientists Ryan Kastner and Mia Minnes in the video accompanying the story:

Cybersecurity experts call for better automotive cyber safety, echoing Jacobs School research findings

A group of cybersecurity experts has announced a Five Start Automotive Cyber Safety Program at the annual Defcon conference in Las Vegas this week to prevent cars from being hacked, a threat that was first pointed out by a team of computer scientists here at UC San Diego and at the University of Washington back in 2010.

The group, called I am the Cavalry, breaks down the five stars as follows:
Safety by Design
Third Party Collaboration
Evidence Capture
Security Updates
Segmentation and Isolation

Savage and colleagues explain the threat in the video below (courtesy of Motherboard):



More on the research here

Wednesday, September 18, 2013

Star-studded line up for cybersecurity forum

PayPal. eBay. Lockheed Martin. These are some of the companies sending their tech leaders to talk about cybersecurity during a think-tank-style event at the Gordon Engineering Leadership Center Sept. 23 and 24 here at the Jacobs School.

 The featured speaker is the principal scientist for consumer security at PayPal, Markus Jakobsson, who will be speaking about the spiraling threat of online fraud and how to address is. Here is the abstract:

The Internet owes its growth and sustenance to commercial developments. However, the spectacular scalability of online fraud threatens this stability. While the human factor is a notable aspect of the problem, traditional security measures treat Internet security as a pure-bred technical challenge. Using examples relating to authentication, Nigerian scams and malware, I will show how we can improve our understanding of and defenses against online fraud by recognizing that it is a socio-technical problem.

 A number of Jacobs School faculty also will be speaking, including computer scientists Stefan Savage, Sorin Lerner, Hovav Schacham and Daniele Miccinacio. 

More info about the event here: http://bit.ly/1aWBsA6

Tuesday, September 10, 2013

Using Bitcoins to Make Illegal Purchases Online May Not Be Anonymous After All

Computer science Ph.D. student Sarah Meiklejohn (pictured) is causing a major stir in the world of cryto-currency and black market transactions. 

She’s part of a team at UC San Diego and George Mason University investigating the Bitcoin market and cybercrime.  Meiklejohn has become an expert on tracking Bitcoin transactions which, on the surface, appear to be anonymous. But the team found a way to link transactions to Bitcoin merchants and services – potentially undermining one major use of Bitcoin: funding online purchases of illegal products. 

In July, Meiklejohn
helped cybercrime expert Brian Krebs verify that users had deposited a total of two bitcoins (~$200) into a purse on the Silk Road black market to purchase heroin that would be sent to Krebs’ home. (Krebs was able to alert the police before the heroin arrived at his home.) 
More recently, a columnist at Forbes magazine asked Meiklejohn to see if she could trace an order for small amounts of marijuana from three different Bitcoin-based online black markets. Meiklejohn followed “digital breadcrumbs” on Silk Road and had little trouble tracing the drug buys back to the Forbes writer using a clustering analysis and detecting a specific point in Bitcoin’s blockchain record of transactions – linking the user to the drug buy. The Forbes columnist, Andy Greenberg, quotes Meiklejohn as saying 

There “are ways of using Bitcoin privately. But if you’re a casual Bitcoin user, you’re probably not hiding your activity very well.” 

Not surprisingly, the findings have hit paydirt on Slashdot, and Bloomberg Businessweek noted that a new paper by Meiklejohn and her colleagues “argues that the network’s increased reliance on a few large accounts makes user identities less secure.” 

That paper, “A Fistful of Bitcoins: Characterizing Payments Among Men with No Names,” will be presented at ACM Internet Measurement Conference in Barcelona Oct. 24, but an advance version is now available.

Meiklejohn’s co-authors at UC San Diego include undergraduate Marjori Pomarole, grad student Grant Jordan, Center for Networked Systems research scientist (and Jacobs SChool alum) Kirill Levchenko, former computer science postdoc Damon McCoy (now teaching at George Mason), as well as computer science professors Geoff Voelker and Stefan Savage.

Tuesday, August 20, 2013

Alum Yoshi Kohno featured on NOVA Science Now

A--very belated--kudos for alum Yoshi Kohno, who appeared in an episode of NOVA Science NOW in October 2012. We found out about the show while talking to a NOVA crew during a test at the Englekirk Structural Engineering Center this past weekend.

Before joining the faculty at the University of Washington, Kohno was a graduate student in the research group of Mihir Ballare here at the Jacobs School. During his almost two-decade long academic career, he has hacked into cars, voting machines and even chips that expert runners insert into their shoes, among other exploits. The show retells his life since childhood when he was, of course, a computer wiz interested in cryptography.

"Thanks goodness that Yoshi is on our side," his wife, Taryn, says at one point during the show.

You can watch the show here (the segment on Kohno begins around 41:00).

You can also read about his work to hack into cars' electronic components in conjunction with Stefan Savage's research group  here at the Jacobs School in this New York Times story.

A couple of Jacobs School press releases about Kohno's work: on hacking into Diebold voting machines, which led to a testimony in front of Congress; and on a free software he helped develop to track lost or stolen laptops.

 In 2007, he landed on the MIT Technology Review's prestigious list of innovators under 35