VLDB 2026 Research / reviewers in the wild / expert
Thomas Newe
dblp:02/3447
· DBLP profile ↗
21ranked-venue papers
0as first author
10since 2021 · last 2025
0000-0002-3375-8200ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 since 2021Systems, architecture and hardware · 6 · 3 since 2021Software engineering, systems software and programming languages · 3Applied, interdisciplinary, general and emerging computing · 3Computer networks · 2 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Dynamic Anomaly Threshold based Malicious Behavior Detection in LoRa-Assisted Industrial IoTabstractSmart manufacturing, powered by Long Range (LoRa) communication-assisted Industrial Internet of Things (IIoT), offers significant benefits but also incurs security concerns due to device compromise. In addition, various application scenarios and inherent heterogeneity of IIoT devices induce significant challenges for reliable behavior detection of compromised devices. While existing work is mostly on detecting compromised devices and there exists limited work on modeling system behavior, an open question is how to model the per-device behavior in an IIoT deployment and how behavioral changes can be automatically adapted in different scenarios. This paper proposes Misbehav, a novel self-learning device behavior anomaly detection system to detect sophisticated and stealthy attacks. First, Misbehav builds the behavior model per device using events and actions, which enables us to define acceptable and permissible actions. We use an autoencoder based unsupervised approach to train the per-device behavior model and detect malicious actions. This approach guarantees that Misbehav not only detects known attacks, but is equally capable of detecting zero-day attacks. We evaluated Misbehav on a data set collected from standard heterogeneous LoRa devices. Our results show that Misbehav exhibits a significant improvement in robustness, accuracy, and latency. In particular, Misbehav improves the detection accuracy by over 88.25% under different evasion attacks and reduces the detection latency by 11.94% than the state-of-the-art solutions. Subir Halder, Amrita Ghosal, Thomas Newe, Sajal K. Das 0001 |
WoWMoM | 3 |
| 2025 | ABIDS-VEM: leveraging an equilibrium optimizer and data ramification in association with ensemble learning for anomaly-based intrusion detection systemabstractAbstract The convergence of the Internet of Things (IoT) and Industrial Internet of Things (IIoT) within the Industry 4.0 paradigm leverages software-defined networking, multi-cloud architectures, and edge/fog computing to enhance industrial processes. However, this digital transformation introduces significant cybersecurity and privacy vulnerabilities within the complex, data-intensive IoT/IIoT ecosystems. To mitigate these risks, this research proposes a novel Anomaly-based Intrusion Detection System using Voting-based Ensemble Model (ABIDS-VEM) in Industry 4.0 environments. The VEM architecture synergistically combines multiple machine learning algorithms and gradient boosting frameworks, including CatBoost (CB), XGBoost (XGB), LightGBM (LGBM), Logistic Regression (LR), and Random Forest (RF), to enhance the precision and computational efficiency of intrusion detection systems (IDS) in IoT/IIoT contexts. The proposed framework incorporates a data ramification process, in which the data is divided into multiple parts, feature selection process which is optimized through the Equilibrium Optimizer (EO) algorithm, and outlier detection utilizing the Isolation Forest (IF) method. Comprehensive empirical evaluations were conducted using three benchmark datasets: XIIoTID, NSL-KDD, and UNSW-NB15, to validate the efficacy of the proposed system. The model achieves high accuracy across datasets: 98.1476% for XIIoT-ID, an impressive accuracy of 98.9671% for NSL-KDD, and 94.1327% for UNSW-NB15 dataset. These experimental results demonstrate the potential of this approach to significantly enhance the resilience of critical industrial systems and data against evolving cyber threats, thereby supporting the continued evolution of Industry 4.0 technologies and bolstering the security posture of IoT/IIoT ecosystems. This research contributes to the ongoing efforts to secure the rapidly expanding digital industrial landscape, offering a robust solution for detecting and mitigating sophisticated cyberattacks in the increasingly interconnected and data-driven industrial environments of the future. Priyanka Verma 0001, Donna O'Shea, Thomas Newe, Nakul Mehta, Nitesh Bharot, John G. Breslin |
J. Supercomput. | 3 |
| 2024 | ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 CertificatesabstractX.509 certificates play a crucial role in establishing secure communication over the internet by enabling authentication and data integrity. Equipped with a rich feature set, the X.509 standard is defined by multiple, comprehensive ISO/IEC documents. Due to its internet-wide usage, there are different implementations in multiple programming languages leading to a large and fragmented ecosystem. This work addresses the research question “Are there user-visible and security-related differences between X.509 certificate parsers?”. Relevant libraries offering APIs for parsing X.509 certificates were investigated and an appropriate test suite was developed. From 34 libraries 6 were chosen for further analysis. The X.509 parsing modules of the chosen libraries were called with 186,576,846 different certificates from a real-world dataset and the observed error codes were investigated. This study reveals an anomaly in wolfSSL’s X.509 parsing module and that there are fundamental differences in the ecosystem. While related studies nowadays mostly focus on fuzzing techniques resulting in artificial certificates, this study confirms that available X.509 parsing modules differ largely and yield different results, even for real-world out-in-the-wild certificates. Stefan Tatschner, Sebastian N. Peters, Michael P. Heinl, Tobias Specht, Thomas Newe |
ARES | 5 |
| 2023 | A Quic(k) Security Overview: A Literature Research on Implemented Security RecommendationsabstractBuilt on top of UDP, the relatively new QUIC protocol serves as the baseline for modern web protocol stacks. Equipped with a rich feature set, the protocol is defined by a 151 pages strong IETF standard complemented by several additional documents. Enabling fast updates and feature iteration, most QUIC implementations are implemented as user space libraries leading to a large and fragmented ecosystem. This work addresses the research question, “if a complex standard with a large number of different implementations leads to an insecure ecosystem?”. The relevant RFC documents were studied and “Security Consideration” items describing conceptional problems were extracted. During the research, 13 popular production ready QUIC implementations were compared by evaluating 10 security considerations from RFC9000. While related studies mostly focused on the functional part of QUIC, this study confirms that available QUIC implementations are not yet mature enough from a security point of view. Stefan Tatschner, Sebastian N. Peters, David Emeis, John Morris, Thomas Newe |
ARES | 5 |
| 2023 | Intrusion Detection Systems for Cyber Attacks Detection in Power Line Communications NetworksabstractPower Line Communication (PLC) is categorized into wired and wireless technologies to distribute the power and transmit the data at different frequency ranges. System administration is one of the significant area in these networks to manage communication processes. Security is one of the significant concern which make networks slow and unavailable, false and altered instructions exist, malfunctioning, and abnormal behavior of systems observed. Intrusion Detection System (IDS) is one of the solution to handle security attacks and protect the systems from unauthorized access. However, the existing IDS systems have limited capabilities to handle the new attacks. This paper proposes a Machine Learning (ML) algorithm for IDS system used in PLC networks to improve the overall system performance and detect the vulnerabilities of the system. The proposed system can detect the latest assaults and protect the systems from unauthorized and malicious activities. The proposed IDS system is assessed by using a virtual environment using the latest dataset and compared with existing traditional systems. The experiment results indicated the better performance of the proposed system to handle the new assaults and protect the systems. Kashif Naseer Qureshi, Noman Arshad, Thomas Newe |
PDP | 3 |
| 2023 | Radio fingerprinting for anomaly detection using federated learning in LoRa-enabled Industrial Internet of ThingsabstractLong Range (LoRa) communications are gaining popularity in the Industrial Internet of Things (IIoT) domain due to their large coverage and high energy efficiency. However, LoRa-enabled IIoT networks are susceptible to cyberattacks mainly due to their wide transmission window and freely operated frequency band. This has led to several categories of cyberattacks. However, existing anomaly detection systems are inefficient in detecting particularly impersonation attacks due to the dense deployment, heterogeneous IIoT devices and manufacturers involved. In this work, we introduce Hawk, a distributed anomaly detection system for detecting compromised devices in LoRa-enabled IIoT. Hawk first measures a device-type specific physical layer feature, Carrier Frequency Offset (CFO) and then leverages the CFO for fingerprinting the device, and consequently detecting anomalous deviations in the device’s CFO behavior, potentially caused by adversaries. To aggregate the device-type specific CFO behavior profile efficiently, Hawk uses federated learning, a distributed machine learning approach. To the best of our knowledge, Hawk is the first to utilise a federated learning method for anomaly-based intrusion detection in LoRa-enabled IIoT. We perform extensive experiments on a real-world dataset collected using 60 LoRa devices, primarily to assess the effectiveness of Hawk against emerging new and unknown attacks. The results show that Hawk improves the detection accuracy by more than 8% compared to the state-of-the-art solutions. Additionally, Hawk reduces the storage overhead by more than 40%, and exhibits significant robustness against cyberattack. Subir Halder, Thomas Newe |
Future Gener. Comput. Syst. | 2 |
| 2022 | SmartCrypt: Secure Storing and Sharing of Time Series Data Streams in IIoTabstractTo provide ubiquitous access, scalability and sharing possibilities, the Industrial Internet of Things (IIoT) applications utilize the cloud to store collected data streams. However, secure storing and sharing of the massive and continuously generated data poses significant privacy risks, including data breaches. This paper proposes SmartCrypt, a data storing and sharing system that supports analytics over the encrypted time series data. SmartCrypt enables users to secure and fine-grain sharing of their encrypted data using a novel symmetric homomorphic encryption scheme. Simulation results show that SmartCrypt reduces query time by 17% and improves through-put by 9% over the benchmark scheme. Subir Halder, Thomas Newe |
CCNC | 2 |
| 2022 | Robust Anomaly Detection via Radio Fingerprinting in LoRa-Enabled IIoT
Subir Halder, Thomas Newe |
ISPEC | 2 |
| 2022 | Secure Time Series Data Sharing with Fine-Grained Access Control in Cloud-Enabled IIoTabstractA growing number of Industrial Internet of Things (IIoT) devices and services collect massive time series data related to production, monitoring and maintenance. To provide ubiquitous access, scalability and sharing possibilities, the IIoT applications utilize the cloud to store collected data streams. However, secure storing of the massive and continuously generated data poses significant privacy risks, including data breaches for IIoT applications. Alongside, we need to protect the utility of the data streams by allowing benign services to access and run analytics securely and selectively.This paper introduces SmartCrypt, a data storing and sharing system that supports analytics over the encrypted time series data. SmartCrypt enables users to secure and fine-grain sharing of their encrypted data. Additionally, SmartCrypt guarantees data confidentiality in the presence of unauthorized parties by allowing end-to-end encryption using a novel symmetric homomorphic encryption scheme. We perform exhaustive experiments on a real-world dataset primarily to assess the feasibility of SmartCrypt for secure storing and sharing of IIoT data streams. The results show that SmartCrypt reduces more than 17% query time, 32% range query time and improves 9% throughput over the best performed scheme in the state-of-the-art. Subir Halder, Thomas Newe |
NOMS | 2 |
| 2022 | Enabling secure time-series data sharing via homomorphic encryption in cloud-assisted IIoTabstractA growing number of Industrial Internet of Things (IIoT) devices and services collect massive time-series data related to production, monitoring and maintenance. To provide ubiquitous access, scalability and sharing possibilities, the IIoT applications utilize the cloud to store collected data streams. However, secure storing of the massive and continuously generated data poses significant privacy risks, including data breaches for IIoT applications. Alongside, we need to protect the utility of the data streams by allowing benign services to access and run analytics securely and selectively. To address this, we propose SmartCrypt, a data storing and sharing system that supports scalable analytics over the encrypted time-series data. SmartCrypt enables users to secure and fine-grain sharing of their encrypted data. Additionally, SmartCrypt guarantees data confidentiality in the presence of unauthorized parties by allowing end-to-end encryption using a novel symmetric homomorphic encryption scheme. We perform extensive experiments on a real-world dataset primarily to assess the feasibility of SmartCrypt for secure storing and sharing of IIoT data streams. The results show that SmartCrypt reduces query time by 17%, reduces range query time by 32%, improves throughput by 9% and scalability by 20% over the best performed scheme in the state-of-the-art. Subir Halder, Thomas Newe |
Future Gener. Comput. Syst. | 2 |
| 2019 | Securing future decentralised industrial IoT infrastructures: Challenges and free open source solutions
Sven Plaga, Norbert Wiedermann, Simon Duque Antón, Stefan Tatschner, Hans D. Schotten, Thomas Newe |
Future Gener. Comput. Syst. | 6 |
| 2018 | Bump in the wire (BITW) security solution for a marine ROV remote control application
Muzaffar Rao, Thomas Newe, Edin Omerdic, Admir Kaknjo, Walid Elgenaidi, Avijit Mathur, Gerard Dooly, Elfed Lewis, Daniel J. F. Toal |
J. Inf. Secur. Appl. | 2 |
| 2018 | Real-Time Video Latency Measurement between a Robot and Its Remote Control Station: Causes and MitigationabstractThis work presents a detailed study, characterization, and measurement of video latency in a real‐time video streaming application. The target application consists of an automatic control system in the form of a control station and the mini Remotely Operated Vehicle (ROV) equipped with a camera, which is controllable over local area network (LAN) and the Internet. Control signal transmission and feedback measurements to the operator usually impose real‐time constraints on the network channel. Similarly, the video stream, which is required for the normal system control and maneuvering, imposes further strict requirements on the network in terms of bandwidth and latency. Based on these requirements, controlling the system in real time through a standard Internet connection is a challenging task. The measurement of important network parameters like availability, bandwidth, and latency has become mandatory for remotely controlling the system in real time. It is necessary to establish a methodology for the measurement of video and network latency to improve the real‐time controllability and safety of the system as such measurement is not possible using existing solutions due to the following reasons: insufficient accuracy, relying on the Internet resources such as generic Network Time Protocol (NTP) servers, inability to obtain one‐way delay measurement, and many solutions only having support for web cameras. Here, an efficient, reliable, and cost‐effective methodology for the measurement of latency of a video stream over a LAN and the Internet is proposed. A dedicated stratum‐1 NTP server is used and the necessary software needed for acquiring and measuring the latency of a video stream from a generic IP camera as well as integration into the existing ROV control software was developed. Here, by using the software and dedicated clock synchronization equipment (NTP server), it was found that normal video latencies in a LAN were in the range of 488ms – 850ms, while latencies over the Internet were measured to be in the range of 558ms – 1211ms. It is important to note that the values were obtained by using a generic (off‐the‐shelf) IP camera and they represent the actual latencies which might be experienced during control over long range and across international territory borders. Admir Kaknjo, Muzaffar Rao, Edin Omerdic, Luke Robinson, Daniel J. F. Toal, Thomas Newe |
Wirel. Commun. Mob. Comput. | 6 |
| 2017 | Reconfiguration of neighbouring nodes in coastal monitoring wireless sensor networks based on leader node recommendationabstractMaritime environmental monitoring based on wireless sensor networks is a challenging area of research due to the characteristics of the water environment. Thus, there are certain designing considerations must be taken into account, for instance network architecture, remote sensor data management and security of data transmission. The system must have the ability to adjust its sensor members in the network in response to environmental changes, and the condition of sensor nodes. In terms of data security, our scheme applied number of security algorithms on the network, such as advanced encryption standard based wireless sensor networks and message digest algorithm, which is providing source travelling data via authenticated sensor nodes to end user. For the sake of network stability, this work presents new technique relaying on recommendation for node called Leader node. This node is monitoring all network members behavior and reconstruct the network topology in case of abnormal member behavior. The system has been tested in real time on Waspmote sensor platform in University of Limerick Campus. Walid Elgenaidi, Thomas Newe, Eoin O'Connell, Avijit Mathur, Daniel J. F. Toal, Gerard Dooly |
CoDIT | 2 |
| 2017 | Cluster head election and rotation for medical-based wireless sensor networksabstractWireless sensor networks (WSN) are a growing field with applications in different areas that include the Medical industry. Each application raises different concerns, challenges, and requirements. This paper looks at a Cluster in a Medical WSN, and focuses on the election of a Cluster Head (CH), its power consumption, and rotation frequency. The rotation of CH is important because it allows for a load-balanced cluster i.e. helping mitigate network energy consumption. In the implemented system, our work shows improvement in power/energy consumption compared to the related work. Avijit Mathur, Thomas Newe, Muzaffar Rao, Walid Elgenaidi, Daniel J. F. Toal |
CoDIT | 2 |
| 2017 | Trust security mechanism for maritime wireless sensor networksabstractSummary To obtain a strong security system based on wireless sensor networks (WSNs), cryptographic‐based protocols are desired. Generally, the use of strong security mechanisms demand intensive use of limited resource, particularly memory storage and energy to provide defense services against malicious attacks. Risks detection in WSNs rely upon the behavior of every single sensor node in the system, and in the case of abnormal node behavior, the system protects the travelling packets on the network via a high level of security mechanisms such as a trusted key management algorithm. In this paper, we compare existing schemes and present a new hybrid security scheme suitable for maritime coastal environment–based WSNs. This scheme tackles the issues of memory storage of encryption keys based on a trusted node configuration, called a leader node, which works as a trusted third party for both the node joining and the node revoke processes. This security mechanism is implemented and tested in real time on a Waspmote sensor testbed platform. Copyright © 2016 John Wiley & Sons, Ltd. Walid Elgenaidi, Thomas Newe, Eoin O'Connell, Gerard Dooly |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | An FPGA-based reconfigurable IPSec AH core with efficient implementation of SHA-3 for high speed IoT applicationsabstractThe need for securing data across the Internet has become a fundamental issue over the last decade. The Internet protocol security IPSec standard has been developed as one solution to the problem of end-to-end secure communications. IPSec implementation is computationally intensive and can significantly limit the performance of high-speed networks. To overcome this speed issue, hardware implementations of IPSec offer the best solution. This work presents a field programmable gate array-based reconfigurable IPSec authentication header AH core. AH is one of the two main IPSec protocols, namely, AH and encapsulating security payload, and it supports both transport and tunnel modes of operations. For the AH protocol, a newly selected cryptographic hash function called secure hash algorithm-3 SHA-3 is implemented and used in this work. SHA-3 is implemented using a unique two-phase implementation approach that combines all the steps of SHA-3. The resultant equations, after combining the SHA-3 steps, are implemented as a proposed high-speed architecture, which results in data throughput in the gigabits per second range. The AH core proposed here outperforms other published techniques and is capable of supporting IPv4 datagrams for both modes of operation transport and tunnel and also can be used to provide security services for Internet of things applications that require high data throughput speeds. Copyright © 2016 John Wiley & Sons, Ltd. Muzaffar Rao, Thomas Newe, Ian Andrew Grout, Avijit Mathur |
Secur. Commun. Networks | 2 |
| 2015 | Trust security mechanism for marine Wireless Sensor NetworksabstractTo provide a strong security service in Wireless Sensor Networks (WSNs), cryptographic mechanisms are required.Generally these security mechanisms demand intensive use of limited resource, such as memory, and energy to provide a defense against attacks.Monitoring the behavior of nodes and detecting risks according to these behaviors, and then taking decisions based on these measurements generally requires the use of a trusted Key Management scheme.In this paper we compare two existing security key management schemes that were designed for use in mobile ad hoc networks: "An overlay approach to data security in ad-hoc networks" authored by Jorg Liebeherr, Guangyu Dong, and "A hierarchical key management scheme for secure group communications in mobile ad hoc networks" authored by Nen-Chung Wang, Shian-Zhang Fang.Then a Hybrid Security Key Management Mechanism designed for use in the marine environment is proposed.This scheme focuses on reducing the memory storage of keys, using a leader node that is responsible for both the node joining and the node revoke processes.This security mechanism is implementing in real time on the Waspmote sensor platform. Walid Elgenaidi, Thomas Newe |
FedCSIS | 2 |
| 2014 | Efficient High Speed Implementation of Secure Hash Algorithm-3 on Virtex-5 FPGAabstractCryptographic hash functions have many security based applications, particularly in message authentication codes (MACs), digital signatures and data integrity. Secure Hash Algorithm-3 (SHA-3) is a new cryptographic hash algorithm that was selected on 2nd Oct '12 after a five year public contest organized by the National Institute of Standards and Technology (NIST), USA. This paper provides a unique technique for the high speed implementation of SHA-3 on Field Programmable Gate Array (FPGA). In this implementation all the five steps of SHA-3 core are logically combined in such a way that it eliminates the intermediate states between these steps. The combination of the five steps results in 25 different equations, each of 64-bit word. These 25 equations have the same structure but different set of inputs and are implemented using the proposed hardware architecture. Xilinx Look-Up-Table primitives are used for the implementation of the proposed hardware architecture. This technique provides highest throughput i.e. 17.132Gbps and TPA (throughput/area) of 13.27 on Virtex-5 FPGA published to date. Muzaffar Rao, Thomas Newe, Ian Andrew Grout |
DSD | 2 |
| 2012 | Formal Verification of a Key Agreement Protocol for Wireless Sensor NetworksabstractWireless sensor networks (WSNs) have gained much attention in both industry and research communities where they are expected to bring the interaction between humans, environment, and machines to a new level. Due to the resource constraints of sensors nodes, it is infeasible to use traditional key establishment techniques that find use in fixed communication systems. In recent years a number of group key agreement protocols have been proposed for resourcelimited wireless sensor devices. However, these protocols do not satisfy some important security properties such as mutual authentication and forward secrecy. In this paper, we propose a hybrid authenticated group key agreement protocol for WSNs. This hybrid protocol reduces the high cost public-key operations at the sensor side and replaces them with efficient symmetric-key based operations. In order to provide assurance that the proposed protocol is verifiably secure and trustworthy, a formal verification is performed on the protocol's design specification. Dehua Chen, Thomas Newe |
TrustCom | 3 |
| 1998 | Realisation of a minimum-knowledge identification and signature scheme
Tom Coffey, Thomas Newe |
Comput. Secur. | 2 |