Prof. Dr. Dogan Kesdogan Lehrstuhl für Wirtschaftsinformatik IV Universität Regensburg D - 93040 Regensburg Tel.: 0941-943-5901 Telefax: 0941-943-5902 Electronic Mail: kesdogan@ur.de REPORT on Ph.D. thesis ' On selected privacy and security issues in wireless sensor networks1 Submitted by Mr. Jiří Kůr General Evaluation Mr. Kur investigates in his Ph.D. thesis selective privacy and security issues in Wireless Sensor Networks (WSN). On the one hand the work can be characterized by an extended version of a cumulative work. Each Chapter is based on published own papers. On the other hand, all chapters have a „Ieitmotif\ i.e. cost-efficiency, privacy&security and especially intrusion detection. Thus, with this leitmotif Mr. Kur manages to build a common and strong story starting with the analysis of attacker's possibilities and the conflict between privacy and Intrusion Detection Systems (IDS). After this analysis (or as a result of this analysis) the constructive part starts with the development of privacy enhanced IDS, adaptive security architecture and improved key predistribution algorithms. The work is an important contribution to applied security&privacy research. Mr. Kur has published 12 papers (see Appendix A). It is an impressive list of international journals and magazines but also international conferences and workshops. Consequently, Mr. Kur can base his Chapters of his thesis to several high quality publications. However, due to the investigation of many aspects of the security&privacy of WSN an in-depth analysis on one aspect can not be given by the very nature of the matter. It gives more a comprehensive analysis on several selected topics that are closely related. Structure Mr. Kur subdivides his work in seven chapters. It starts and ends with the obligatory introduction and conclusion chapters. At the first glance the work is a monograph but looking closer it has also elements of a cumulative thesis. The reason for that is that Mr. Kur has investigated several aspects of WSN problem and presents it more or less in autonomous chapters. Consequently, the chapters follow mostly a classical JiH Kur:On selected privacy and security issues in wireless sensor networks 2 structure with introduction, related works and contribution parts. However, the chapters are also linked to each other. The linkage between the chapters is given by the general problem orientation with the following aspects: How to estimate and fairly compare the performance of security mechanisms, what are the fundamental contradictions between IDS and Privacy and how to bring them together. Since, many research areas have to be considered the overall structure is adequate to handle the investigated scientific problem. Content Chapter 1 represents a very short introduction into the WSN area. It introduces the general problem statement, contributions and the general structure of the thesis. Security research starts usually with the question of defining a concise attacker model. The general focus is here on global eavesdropper (passive attack) with certain malicious active actions (local active attacker). It is essential to know the concrete abilities of the attacker in this attack space. Otherwise, designing security without concise attacker model the security design could simply fail (or simply unpractical). Therefore it is important to search and explore the attackers vector space. After a general introduction (e.g. related works) Mr. Kur presents his approach to explore the abilities of the attacker, i.e. uses evolutionary algorithms to construct automated attacks. Obviously, this search can not be exhaustive since genetic algorithms are an optimization strategy to accelerate the search. However, the given reasons for using genetic algorithms are vague (solution space are between 100 to one million) and need to be better justified. In Chapter 3 he investigates the principle structure between IDS and privacy. Network privacy aims to hide the actions of a particular node and the goal of IDS is to identify all actions of a node. Hence, realizing both approaches are inherently contradictory and they have to be technically mitigated. Obviously, it is hard (even impossible) to find optimal general solutions. Mr. Kur identifies twelve problems that have to be addressed and afterwards four approaches to mitigate the problems. Clearly, to enable cooperation between the two approaches one has to investigate special aspects of techniques and has to harmonize them, e.g. probing message versus dummy message. However, if IDS is considered as the „internal" attacker then the situation changes. Nevertheless, this could be addressed by distributing sensitive data and responsibility among the sensor nodes. And this is one of the main ideas that is suggested in the work. Taken as a whole this chapter is very important since it addresses the general problem of addressing privacy and IDS. In Chapter 4 a location privacy friendly intrusion detection is presented. The work is based on the link layer security scheme SNEP. Privacy is provided by simply periodic collection of information. The IDS Problem is to detect malicious nodes that Jiří Kůr:On selected privacy and security issues in wireless sensor networks 3 modify the forwarded messages. Mr. Kur suggests a protocol where every node becomes a watchdog and controls the predecessor and the successor node. He has also implemented the sketched solution and can therefore present real measurements. The suggested IDS works well if single node or pairs of nodes are malicious. However, how about if we assume more successive nodes are malicious? Since Mr. Kur has implemented the protocol he could experiment and measure many aspects, e.g. increased traffic load, drop rate and false alarm rate. However, all these aspects are left for future work. Chapter 5 starts with an analysis of adaptive security management. The argument for dynamic adaptive security level management is to save resources. Of course the more level one has the better adjustment can be achieved. However, the management cost increases with the number of levels. After presenting the related works Mr. Kur gives a solution for a specific application scenario. In this frame he considers five attacker models that result in five security levels. He claims that the internal, active and local attacker model is the most likely to appear in reality. However, this claim is not explained. Mr. Kur presents his findings in a systematic and clear way and presents the additional cost of each level. The final subsections deal with the question of management of the levels and dynamic pseudonym changes. Chapter 6 presents two improvements of random key distribution. Mr. Kur shows here a stringent analytic approach. After presenting his extensions a mathematical analysis is given. He thereupon sketches computational results (results of network simulator) that verify the analytical results. However, I wonder why he has not compared these results directly by using the figures. Chapter 7 concludes with the obligatory open questions part. The work of Mr. Kur can be extended in many ways. He presents an analysis on several selected topics that are closely related. One can identify many further steps to investigate in each topic but this shows also how fruitful his work is. Considering the breadth of the selected topics and the purpose to give a practical general solution the work is well balanced in depth and breadth. The work is excellently written and explained. I recommend the Faculty of Informatics, Masaryk University to accept the submitted PhD thesis. My overall rating is: Sum ma cum laude (1.0). Regensburg, February 02,2014 — ^ ( — \ ' L (Prof. Dr. Dogan Kesdogan)