VLDB 2026 Research / reviewers in the wild / expert
Zubair A. Baig
dblp:04/4615 · also Zubair Ahmed Baig
· DBLP profile ↗
37ranked-venue papers
8as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 3 first-author · 8 since 2021Security and privacy · 11 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 6 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorSystems, architecture and hardware · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A review of indirect authentication in LEO satellite networks: Three decades of progressabstractLow Earth Orbit (LEO) satellite networks have become the main differentiator in achieving global connectivity, augmenting terrestrial networks through wider coverage, lower latency, and native integration with 5G/6G, the Internet of Things (IoT), and edge services. However, the expansion of LEO constellations introduces substantial security challenges, mainly ensuring robust authentication under dynamic, resource and bandwidth constrained conditions. In many practical architectures, authentication is performed indirectly, with satellites forwarding verification material to ground infrastructure rather than authenticating autonomously. Despite its prevalence, indirect authentication in LEO networks lacks a dedicated, up-to-date survey and a consistent way to compare designs. This paper reviews 69 indirect authentication protocols published between 1996 and 2024 and introduces a role-based taxonomy that distinguishes relay-based schemes from schemes where satellites provide limited assistance prior to ground-based verification. Each protocol is analysed in terms of architecture, cryptographic approach, security properties, validation practices, and efficiency trade-offs. Emerging directions are also synthesised, including blockchain-based designs, quantum security, physical-layer authentication, and Zero Trust-inspired approaches. The survey consolidates fragmented terminology, clarifies design choices and trade-offs, and highlights open research problems toward scalable authentication for future LEO constellations that reflect operational realities. Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Ad Hoc Networks | 2 |
| 2025 | Enhancing Physical Security in Smart Environments with Ambient IntelligenceabstractSmart environments are increasingly equipped with interconnected digital systems to manage access and physical security. However, traditional authentication methods, typically restricted to static checkpoints, fail to provide persistent assurance once entry is granted, leaving facilities vulnerable to credential misuse, tailgating, and unauthorised movement. This paper presents the Continuous Authentication Platform (CAP), a modular, multi-modal framework developed within the RAAISE project to enable continuous and context-aware verification across dynamic facility zones. CAP integrates heterogeneous off-the-shelf sensors, including NFC, RFID, biometric, motion, and WiFi positioning units, which collectively support persistent user tracking and real-time access enforcement. The platform’s architecture couples distributed sensing and edge processing with a centralised intelligence layer for event correlation and policy-driven decision-making. A live testbed deployment at Deakin University was used to evaluate CAP’s performance under realistic operational conditions. Results from functional trials demonstrate CAP’s ability to detect credential misuse, prevent tailgating, and maintain authentication continuity with sub-second responsiveness. These findings underscore CAP’s potential as a scalable, privacy-aligned foundation for next-generation smart facility security systems. Ashish Nanda, Robin Doss, Fokke Heikamp, Abhi Kumar, Haftu Tasew Reda, Adnan Anwar, Zubair A. Baig, Praveen Gauravaram, Debi Prasad Pati, Salil S. Kanhere, Mohan Baruwal Chhetri |
TrustCom | 7 |
| 2025 | Zero trust-based authentication for Inter-Satellite Links in NextGen Low Earth Orbit networksabstractNext Generation (NextGen) Low Earth Orbit satellite networks are rapidly expanding to support global communication and 6G technology transition. This growth exposes networks to new security challenges due to wide coverage in hostile areas and increased access points in space and on Earth. Traditional static authentication methods prove inadequate in this dynamic environment. We address these challenges by developing a Zero Trust Authentication Protocol for Inter-Satellite Link (ISL) communication. Our protocol implements a novel verification process that leverages orbital signals to authenticate ISLs. This approach ensures secure data access and transmission exclusively among verified satellites, mitigating threats from eavesdropping, signal spoofing, impersonation, and replay attacks. To optimize security and resource efficiency, we integrate Hyperelliptic Curve Cryptography (HECC) into our protocol. We validate our approach through MATLAB and Systems Tool Kit (STK) simulations, complemented by BAN Logic and Scyther analyses. Our findings demonstrate that our protocol enhances the security framework of NextGen LEO networks without compromising their performance or operational capabilities. Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Ad Hoc Networks | 2 |
| 2025 | Quantum-Powered Extended Visibility for Zero-Trust-Based Ransomware Detection in Smart GridsabstractTechnological evolution in the Industrial Internet of Things (IIoT) domain has fostered smart grid systems’ operation, performance, connectivity, and delivery with higher efficiency. However, it has also exposed the platform to a broader surface for attackers. Current information technology (IT)-centric solutions for detecting, preventing, and mitigating attacks have limitations, especially in comprehensively monitoring industrial control operational technology (OT) and communication systems. The rise of sophisticated cyberattacks, such as targeted ransomware, demand more robust security measures, leading to the emergence of zero trust (ZT) deployment as a response to these threats. This article proposes a new framework for implementing ZT comprising both IT and OT in smart grid infrastructures, with multiple security mechanisms and robust system coverage. We present an EigenGame algorithm for integrating diverse data sources into a rich-context format and an enhanced approach to quantum reinforcement learning for reliable malicious behavior detection in IIoT-enabled smart grids. The framework was evaluated using five sets of data from the X-IIoTID dataset, demonstrating its good performance in verifying any behavior inside the system and identifying any malicious behavior related ransomware attacks. Muna Al-Hawawreh, Omar Shindi, Zubair A. Baig, Mamoun Alazab, Adnan Anwar, Robin Doss |
IEEE Internet Things J. | 3 |
| 2025 | Robust and lightweighted mutual authentication scheme for drone swarm networksabstractDrones are being increasingly adopted across both military and commercial domains to serve remote rendering, monitoring, surveillance and service delivery operations. Drone swarms comprise multiple drones operating cohesively as a unified system to provide collective services. Each drone in a swarm must establish mutual trust with other drones to ensure authenticity in data exchange and also to prevent the compromise of a mission. Inter-drone communication links are vulnerable to cyber threats, including unauthorized access and spoofing. While most existing studies focus on authentication mechanisms for drone-to-stationary base stations, very little research work has explored inter-drone authentication protocols specifically designed for decentralized topologies. We propose a lightweight authentication scheme for inter-drone communication that leverages a dynamic challenge-response mechanism, hash-based message authentication code and authenticated encryption to facilitate mutual authentication. We validate the efficacy of the proposed protocol through extensive informal analysis based on the Dolev–Yao and the Canetti-Krawczyk threat models and through Scyther and random oracle-based formal analysis. We also compare the protocol’s performance with state-of-the-art authentication schemes to demonstrate its efficacy and efficiency. The results obtained demonstrate the supremacy of the protocol in cost-effective threat prevention for swarms of drones. Kiran Illyass, Zubair A. Baig, Naeem Firdous Syed |
J. Netw. Comput. Appl. | 2 |
| 2024 | Towards Availability of Strong Authentication in Remote and Disruption-Prone Operational Technology EnvironmentsabstractImplementing strong authentication methods in a network requires stable connectivity between the service providers deployed within the network (i.e., applications that users of the network need to access) and the Identity and Access Management (IAM) server located at the core segment of the network. This becomes challenging when it comes to Operational Technology (OT) systems deployed in a remote area, as they often get disconnected from the core segment of the network owing to unavoidable network disruptions. As a result, weak authentication methods and shared credential approaches are still adopted in these OT environments, exposing system vulnerabilities to increasingly sophisticated cyber threats. In this work, we propose a solution to enable highly available multi-factor authentication (MFA) services for OT environments. The proposed solution is based on Proof-of-Possession (PoP) tokens generated by an IAM server for registered users. The tokens are securely linked to user-specific parameters (e.g., physical security keys, biometrics, PIN, etc.), enabling strong user authentication (during disconnection time) through token validation. We deployed the Tamarin Prover software-based toolkit to verify security of the proposed authentication scheme. For performance evaluation, we implemented the designed solution in real-world settings. The results of our analysis and experiments confirm the efficacy of the proposed solution. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Divyans Mahansaria, Debi Prasad Pati, Praveen Gauravaram, Lei Pan 0002, Keshav Sood |
ARES | 2 |
| 2024 | The Value of Strong Identity and Access Management for ICS/OT SecurityabstractAs the integration of digital technologies with Industrial Control Systems (ICS) and Operational Technology (OT) continues to deepen, these systems increasingly become targets for sophisticated cyber attacks. These attacks not only threaten the operational integrity but also pose significant risks to national security and public safety. In this paper, we provide insights into the value of ICS/OT security solutions that are based on Identity and Access Management (IAM). Beginning with presenting an abstraction model for typical ICS/OT attacks, the paper systematically outlines the main stages of an attack and the corresponding vectors employed by adversaries. Drawing from the MITRE ATT&CK framework tailored for ICS, the paper quantifies the extent to which IAM-based mitigation approaches can strengthen defense-in-depth mechanisms against cyber threats targeting ICS/OT environments. Our findings show that there are modern attack vectors that can only be mitigated through robust IAM solutions. Moreover, we found that while advanced techniques such as firewall and gateway-based intelligent threat detection play a significant role in safeguarding I CS/OT, they are insufficient on their own to address several attack vectors in ICS/OT environments. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Praveen Gauravaram, Debi Prasad Pati, Divyans Mahansaria, Keshav Sood, Lei Pan 0002 |
PST | 2 |
| 2024 | Provably secure optimal homomorphic signcryption for satellite-based internet of things
Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Comput. Networks | 2 |
| 2023 | Fog-cloud based intrusion detection system using Recurrent Neural Networks and feature selection for IoT networks
Naeem Firdous Syed, Mengmeng Ge 0001, Zubair A. Baig |
Comput. Networks | 3 |
| 2023 | Cybersecurity for Industrial IoT (IIoT): Threats, countermeasures, challenges and future directions
Sri Harsha Mekala, Zubair A. Baig, Adnan Anwar, Sherali Zeadally |
Comput. Commun. | 2 |
| 2023 | Privacy for IoT: Informed consent management in Smart BuildingsabstractSmart Buildings (SBs) employ the latest IoT technologies to automate building operations and services with the objective of increasing operational efficiency, maximising occupant comfort, and minimising environmental impact. However, these smart devices – mostly cloud-based – can capture and share a variety of sensitive and private data about the occupants, exposing them to various privacy threats. Given the non-intrusive nature of these devices, individuals typically have little or no awareness of the data being collected about them. Even if they do and claim to care about their privacy, they fail to take the necessary steps to safeguard it due to the convenience offered by the IoT devices. This discrepancy between user attitude and actual behaviour is known as the ‘privacy paradox’. To address this tension between data privacy, consent and convenience, this paper proposes a novel solution for informed consent management in shared smart spaces. Our proposed Informed Consent Management Engine (ICME) (a) increases user awareness about the data being collected by the IoT devices in the SB environment, (b) provides fine-grained visibility into privacy conformance and compliance by these devices, and (c) enables informed and confident privacy decision-making, through digital nudging. This study provides a reference architecture for ICME that can be used to implement diverse end-user consent management solutions for smart buildings. A proof-of-concept prototype is also implemented to demonstrate how ICME works in a shared smart workplace. Our proposed solution is validated by conducting expert interviews with 15 highly experienced industry professionals and academic researchers to understand the strengths, limitations, and potential improvements of the proposed system. Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig |
Future Gener. Comput. Syst. | 4 |
| 2021 | Tracing Software Exploitation
Ayman Youssef, Mohamed Almorsy, Chandan K. Karmakar, Zubair A. Baig |
NSS | 4 |
| 2021 | ICME: an informed consent management engine for conformance in smart building environmentsabstractSmart buildings can reveal highly sensitive insights about their inhabitants and expose them to new privacy threats and vulnerabilities. Yet, convenience overrides privacy concerns and most people remain ignorant about this issue. We propose a novel Informed Consent Management Engine (ICME) that aims to: (a) increase users’ awareness about privacy issues and data collection practices in their smart building environments, (b) provide fine-grained visibility into privacy conformance and infringement by these devices, (c) recommend and visualise corrective user actions through ”digital nudging”, and (d) support the monitoring and management of personal data disclosure in a shared space. We present a reference architecture for ICME that can be used by software engineers to implement diverse end-user consent management solutions for smart buildings. We also provide a proof-of-concept prototype to demonstrate how the ICME approach works in a shared smart workplace. Demo: https://youtu.be/5y6CdyWAdgY Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig |
ESEC/SIGSOFT FSE | 4 |
| 2021 | Towards a deep learning-driven intrusion detection approach for Internet of Things
Mengmeng Ge 0001, Naeem Firdous Syed, Xiping Fu, Zubair A. Baig, Antonio Robles-Kelly |
Comput. Networks | 4 |
| 2021 | LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA)
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss |
Comput. Secur. | 5 |
| 2020 | Towards a Lightweight Continuous Authentication Protocol for Device-to-Device CommunicationabstractContinuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely researched human user characteristics-based CA mechanisms cannot be extended to continuously authenticate Internet of Things (IoT) devices. The challenges are exacerbated with the increased adoption of device-to-device (d2d) communication in critical infrastructures. Existing d2d authentication protocols proposed in the literature are either prone to subversion or are computationally infeasible to be deployed on constrained IoT devices. In view of these challenges, we propose a novel, lightweight and secure CA protocol that leverages communication channel properties and a tunable mathematical function to generate dynamically changing session keys. Our preliminary informal protocol analysis suggests that the proposed protocol is resistant to known attack vectors and thus has strong potential for deployment in securing critical and resource-constrained d2d communication. Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss |
TrustCom | 5 |
| 2020 | Averaged dependence estimators for DoS attack detection in IoT networks
Zubair A. Baig, Surasak Sanguanpong, Naeem Firdous Syed, Van Nhan Vo 0001, Tri Gia Nguyen, Chakchai So-In |
Future Gener. Comput. Syst. | 1 |
| 2020 | Machine learning and data analytics for the IoT
Erwin Adi, Adnan Anwar, Zubair A. Baig, Sherali Zeadally |
Neural Comput. Appl. | 3 |
| 2019 | Deep Learning-Based Intrusion Detection for IoT NetworksabstractInternet of Things (IoT) has an immense potential for a plethora of applications ranging from healthcare automation to defence networks and the power grid. The security of an IoT network is essentially paramount to the security of the underlying computing and communication infrastructure. However, due to constrained resources and limited computational capabilities, IoT networks are prone to various attacks. Thus, safeguarding the IoT network from adversarial attacks is of vital importance and can be realised through planning and deployment of effective security controls; one such control being an intrusion detection system. In this paper, we present a novel intrusion detection scheme for IoT networks that classifies traffic flow through the application of deep learning concepts. We adopt a newly published IoT dataset and generate generic features from the field information in packet level. We develop a feed-forward neural networks model for binary and multi-class classification including denial of service, distributed denial of service, reconnaissance and information theft attacks against IoT devices. Results obtained through the evaluation of the proposed scheme via the processed dataset illustrate a high classification accuracy. Mengmeng Ge 0001, Xiping Fu, Naeem Firdous Syed, Zubair A. Baig, Gideon Teo, Antonio Robles-Kelly |
PRDC | 4 |
| 2019 | Editorial: Sustainable Mobile Networks and its Applications
Pasumpon Pandian, Joy Iong-Zong Chen, Zubair A. Baig |
Mob. Networks Appl. | 3 |
| 2019 | Physical Layer Security for the Smart Grid: Vulnerabilities, Threats, and CountermeasuresabstractSmart energy systems are becoming an important component of smart cities. The wide adoption of existing computing technologies and communication standards by a smart energy system exposes it to the plethora of threats that exist in cyberspace. In this article, we investigate the vulnerabilities and threats associated with smart energy system components, including Internet of Things enabled devices, as well as relevant communication standards, and we discuss countermeasures against adversarial attacks. We found that the existing literature has reported various attacks, including modification, denial-of-service, malware, and message replay, which can cause malfunctioning of different components of a smart energy system. In addition, we propose a framework for securing the physical layer of the smart energy system. The framework is based on advanced key generation, machine learning, and physical layer security techniques, which enhance the security of smart energy systems across different applications. Shama Naz Islam, Zubair A. Baig, Sherali Zeadally |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | Internet of Things (IoT): Research, Simulators, and TestbedsabstractThe Internet of Things (IoT) vision is increasingly being realized to facilitate convenient and efficient human living. To conduct effective IoT research using the most appropriate tools and techniques, we discuss recent research trends in the IoT area along with current challenges faced by the IoT research community. Several existing and emerging IoT research areas such as lightweight energy-efficient protocol development, object cognition and intelligence, as well as the critical need for robust security and privacy mechanisms will continue to be significant fields of research for IoT. IoT research can be a challenging process spanning both virtual and physical domains through the use of simulators and testbeds to develop and validate the initial proof-of-concepts and subsequent prototypes. To support researchers in planning IoT research activities, we present a comparative analysis of existing simulation tools categorized based on the scope of coverage of the IoT architecture layers. We compare existing large-scale IoT testbeds that have been adopted by researchers for examining the physical IoT prototypes. Finally, we discuss several open challenges of current IoT simulators and testbeds that need to be addressed by the IoT research community to conduct large-scale, robust and effective IoT simulation, and prototype evaluations. Maxim Chernyshev, Zubair A. Baig, Oladayo Bello, Sherali Zeadally |
IEEE Internet Things J. | 2 |
| 2018 | Ransomware behavioural analysis on windows platforms
Nikolai Hampton, Zubair A. Baig, Sherali Zeadally |
J. Inf. Secur. Appl. | 2 |
| 2017 | Stealthy Denial of Service (DoS) attack modelling and detection for HTTP/2 services
Erwin Adi, Zubair A. Baig, Philip Hingston |
J. Netw. Comput. Appl. | 2 |
| 2016 | Timestamp Analysis for Quality Validation of Network Forensic Data
Nikolai Hampton, Zubair A. Baig |
NSS | 2 |
| 2016 | Controlled access to cloud resources for mitigating Economic Denial of Sustainability (EDoS) attacks
Zubair A. Baig, Sadiq M. Sait, Farid Binbeshr |
Comput. Networks | 1 |
| 2013 | GMDH-based networks for intelligent intrusion detection
Zubair A. Baig, Sadiq M. Sait, AbdulRahman Shaheen |
Eng. Appl. Artif. Intell. | 1 |
| 2012 | Abductive Neural Network Modeling for Hand Recognition Using Geometric Features
El-Sayed M. El-Alfy, Radwan E. Abdel-Aal, Zubair A. Baig |
ICONIP (4) | 3 |
| 2012 | Multi-agent systems for protecting critical infrastructures: A survey
Zubair A. Baig |
J. Netw. Comput. Appl. | 1 |
| 2011 | An Entropy and Volume-Based Approach for Identifying Malicious Activities in Honeynet TrafficabstractHoney nets are an increasingly popular choice deployed by organizations to lure attackers into a trap network, for collection and analysis of unauthorized network activity. A Honey net captures substantial amount of data and logs for analysis in order to identify malicious activities perpetrated by the hacker community. The analysis of this large amount of data is a challenging task. Through this paper, we propose a technique based on the entropy and volume thresholds of selected network features to efficiently analyze Honey net data, and identify malicious activities. Our technique consists of both feature-based and volume-based schemes to identify malicious activities in the Honey net traffic. Through deployment of our proposed approach, a detailed analysis of various traffic features is conducted and the most appropriate features for Honey net traffic are thereupon selected. The anomalies are identified using entropy distributions and volume distributions, along with their corresponding threshold levels. The proposed scheme proves to be effective in identifying most types of anomalies seen in Honey net traffic. Mohammed H. Sqalli, Naeem Firdous Syed, Zubair A. Baig, Farag Azzedin |
CW | 3 |
| 2011 | A selective parameter-based evolutionary technique for network intrusion detectionabstractNetwork intrusion detection has remained a field of rigorous research over the past few years. Advances in computing performance, in terms of processing power and storage, have allowed the use of resource-intensive intelligent algorithms, to detect intrusive activities, in a timely manner. Genetic Algorithms have emerged as a powerful domain-independent technique to facilitate searching of the most effective set of rules, to differentiate between normal and anomalous network traffic. The scope of research for developing cutting-edge and effective GA-based intrusion detection systems, has rapidly expanded to keep pace with variant attack types, increasingly witnessed from the adversary class. In this paper, we propose a GA-based technique for effectively identifying network intrusion attempts, and clearly differentiating these from normal network traffic. The performance of the proposed scheme is studied and analyzed on the KDD-99 intrusion benchmark data set. We performed a simulation-based analysis of the proposed scheme, with results strengthening our findings, and providing us directions for future work. Zubair A. Baig, Saad Khan 0002, Saif Ahmed, Mohammed H. Sqalli |
ISDA | 1 |
| 2011 | Pattern recognition for detecting distributed node exhaustion attacks in wireless sensor networks
Zubair A. Baig |
Comput. Commun. | 1 |
| 2010 | On the use of Unified And-Or fuzzy operator for distributed node exhaustion attack decision-making in wireless sensor networksabstractThe effect of advances in the fields of ubiquitous computing, wireless communications and embedded system design has seen a corresponding rapid improvement of wireless sensor technology. Sensor networks have emerged as a platform for deployment and sustenance of critical applications that require real-time sensing and data acquisition for decision-making purposes. A significant number of malicious attacks against the security of such networks have been identified in recent times. Considering the untrusted environments of operations of such networks, the threat of distributed attacks against constrained sensory resources i.e. sensor power, computation and communication capabilities cannot be overlooked. In this paper, we propose a fuzzy logic-based approach towards achieving demarkation in the values of specific parameters of an attack detection scheme for detecting distributed node-exhaustion attacks in wireless sensor networks. Using the Unified And-Or (UAO) aggregation operator, we model and formulate a mechanism to achieve a tradeoff between frequent attack detection and sensor node energy utilization. Simulation results prove the effectiveness of our approach in addressing the issue of computing the optimal parameter values for achieving a reasonable tradeoff between attack detection rate and sensor node energy utilization rate. Salman A. Khan, Zubair A. Baig |
FUZZ-IEEE | 2 |
| 2010 | Multi-Agent pattern recognition mechanism for detecting distributed denial of service attacksabstractDistributed denial of service (DDoS) attacks pose a significant threat to the smooth operations of today's online critical services and applications. Existing mechanisms to detect these attacks have had limited success. With the rapid growth in size and bandwidth of contemporary computer networks, an efficient and effective distributed solution is needed for detecting DDoS attacks. In this study, the authors propose a multiagent pattern recognition mechanism for detecting DDoS attacks, in adistributed fashion. Our proposed solution is very effective in detecting such attacks launched against victim servers residing inside a production network which has multiple gateways to the Internet. Using simulation, the authors show that our proposed mechanism achieves a high degree of accuracy in detecting DDoS attacks, with low false alarm rates, using a reasonable numbers of attack detection agents collaboratively operating in a typical production network. The authors also study the relationship of the number of agents participating in the attack detection process and the false alarm rate of the detection scheme. Zubair A. Baig, Khaled Salah 0001 |
IET Inf. Secur. | 1 |
| 2009 | Resiliency of open-source firewalls against remote discovery of last-matching rulesabstractIn today's networks, firewalls act as the first line of defense against unwanted and malicious traffics. Firewalls themselves can become targets of DoS attacks, thus jeopardizing their primary operation to filter traffic. Typically, packets are checked against a firewall policy consisting (in many cases) of thousands of rules. Last-matching rules are located at the bottom of the ruleset and consume the most CPU processing power of firewalls. If these rules get discovered by an attacker, the attacker can effectively launch a low-rate DoS attack that can bring the firewall to its knees. In prior work [1], we proposed and evaluated a technique to remotely discover the last matching rules of the Linux Netfilter firewall. In this paper, we examine the effectiveness of such technique on the discovery of last-matching rules in two other popular open-source network firewalls, namely Linux IPSets and FreeBSD ipfw. Khaled Salah 0001, Karim Sattar, Zubair A. Baig, Mohammed H. Sqalli, Prasad Calyam |
SIN | 3 |
| 2007 | A Simulated Evolution-Tabu search hybrid metaheuristic for routing in computer networksabstractRouting in computer networks is a nonlinear combinatorial optimization problem with numerous constraints and is classified as an NP-complete problem. There are certain important QoS metrics which affect the performance of a network. One of these metrics is the average network delay, which should be minimized. In this paper, a routing strategy based on simulated evolution algorithm to find suboptimal routing solution for computer networks while optimizing the above metric is presented. To intensify the search, a hybrid variant of the proposed algorithm has also been implemented. This variant incorporates Tabu search characteristics into the simulated evolution algorithm. Performance evaluation of the two approaches is done via simulation. Empirical results suggest that the hybrid variant performs better than the original simulated evolution algorithm. Salman A. Khan, Zubair A. Baig |
IEEE Congress on Evolutionary Computation | 2 |
| 2006 | SGSIA-in-Network Data Preprocessing for Secure Grid-Sensor IntegrationabstractWith rapid advances being made in sensor technology, wireless sensor networks (WSNs) have emerged as an essential source of data for storage and processing on highperformance computing grids. The significant amount of data generated by sensor networks requires preprocessing at the source-end, to ensure reduction in the total volume of data generated for transfer and storage in highperformance grid systems. There exists a lack of an infrastructure for optimal and efficient retrieval of sensor data through grid-sensor integration, and facilitation of efficient sensor resource sharing in environments with multiple WSNs. In this paper, we propose the Secure Grid-Sensor Integration Architecture (SGSIA), as a secure, scalable, and intelligent architecture for the integration of resourceconstrained sensor networks into the grid. Zubair A. Baig, Mohamed Baqer, Asad I. Khan |
e-Science | 1 |