Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in
  • Home
  • Agenda
  • Call for Participation
  • Organizers
  • Past Summits
  • Home
  • Attend
  • Program
  • Sponsorship
  • Participate
  • About

help promote

WOOT '16 button

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Sampling Race: Bypassing Timing-Based Analog Active Sensor Spoofing Detection on Analog-Digital Systems

Hocheol Shin, Yunmok Son, Youngseok Park, Yujin Kwon, and Yongdae Kim, Korea Advanced Institute of Science and Technology (KAIST)

Sensors and actuators are essential components of cyberphysical systems. They establish the bridge between cyber systems and the real world, enabling these systems to appropriately react to external stimuli. Among the various types of sensors, active sensors are particularly well suited to remote sensing applications, and are widely adopted for many safety critical systems such as automobiles, unmanned aerial vehicles, and medical devices. However, active sensors are vulnerable to spoofing attacks, despite their critical role in such systems. They cannot adopt conventional challenge-response authentication procedures with the object of measurement, because they cannot determine the response signal in advance, and their emitted signal is transparently delivered to the attacker as well.

Recently, PyCRA, a physical challenge-response authentication scheme for active sensor spoofing detection has been proposed. Although it is claimed to be both robust and generalizable, we discovered a fundamental vulnerability that allows an attacker to circumvent detection. In this paper, we show that PyCRA can be completely bypassed, both by theoretical analysis and by real-world experiment. For the experiment, we implemented authentication mechanism of PyCRA on a real-world medical drop counter, and successfully bypassed it, with only a low-cost microcontroller and a couple of crude electrical components. This shows that there is currently no effective robust and generalizable defense scheme against active sensor spoofing attacks.

Hocheol Shin, Korea Advanced Institute of Science and Technology (KAIST)

Yunmok Son, Korea Advanced Institute of Science and Technology (KAIST)

Youngseok Park, Korea Advanced Institute of Science and Technology (KAIST)

Yujin Kwon, Korea Advanced Institute of Science and Technology (KAIST)

Yongdae Kim, Korea Advanced Institute of Science and Technology (KAIST)

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {198483,
author = {Hocheol Shin and Yunmok Son and Youngseok Park and Yujin Kwon and Yongdae Kim},
title = {Sampling Race: Bypassing {Timing-Based} Analog Active Sensor Spoofing Detection on {Analog-Digital} Systems},
booktitle = {10th USENIX Workshop on Offensive Technologies (WOOT 16)},
year = {2016},
address = {Austin, TX},
url = {https://www.usenix.org/conference/woot16/workshop-program/presentation/shin},
publisher = {USENIX Association},
month = aug
}
Download
Shin PDF
View the slides
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us