VLDB 2026 Research / reviewers in the wild / expert
Deepak K. Tosh
dblp:118/7021
· DBLP profile ↗
30ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0001-8492-1066ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 3 since 2021Computer networks · 8 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Design of a Unified Monitoring Tool for Detecting Anomalies in High Performance Computing SystemsabstractWith increased demand in various cyberinfrastructure, researchers are leveraging High Performance Computing (HPC) systems to simulate complex environments for system and cybersecurity experimentation. This paper presents ongoing work towards designing a novel unified monitoring framework that collects both system-level and network-level metrics from containerized networking system orchestrated in a public cloud environment, to support anomaly detection in HPC systems. The framework captures system-level metrics using Lightweight Distributed Metric Service (LDMS), further hardware performance data through Performance Application Programming Interface (PAPI), and network flow features using tcpdump. This paper mainly focuses on the design of the framework and a case study associated with the effectiveness of some of the collected metrics. Arin Rahman, Shirley V. Moore, Deepak K. Tosh |
CCNC | 3 |
| 2026 | Cost-Aware Cyber-Threat Mitigation Framework for Critical Infrastructure EnvironmentabstractCritical infrastructure systems continue to face growing threats against industrial communication protocols and embedded hardware. Despite increasing pressure to improve cybersecurity, operational constraints, limited budgets, and complex environments make it difficult for organizations to prioritize and implement effective mitigation strategies. Traditional risk models rely on static scoring systems, such as CVSS, which fail to capture the evolving nature of threats and the costs of deploying controls. Although some recent models, such as SecScore, address time-dependent risk, they often overlook the economic impact of mitigation efforts. This paper presents SecOptICS, a time-aware, risk-informed, and cost-sensitive cybersecurity investment model for ICS environments. The model accounts for the probability of exploit code development for a vulnerability over time, the frequency of threats, and the financial cost and effectiveness of security controls. SecOptICS introduces a utility-based framework that enables organizations to dynamically assess and prioritize both vulnerabilities and mitigation strategies. Through ICS-specific case studies using CVE data, we demonstrate how SecOptICS supports more strategic resource allocation by quantifying residual risk and identifying the optimal time to deploy controls. Our results show that SecOptICS offers a practical and adaptable approach to cybersecurity decision making in resource-constrained industrial environments. Arin Rahman, Deepak K. Tosh |
CCNC | 2 |
| 2025 | Network Anomaly Detection in Distributed Edge Computing InfrastructureabstractAs networks continue to grow in complexity and scale, detecting anomalies has become increasingly challenging, particularly in diverse and geographically dispersed environments. Traditional approaches often struggle with managing the computational burden associated with analyzing large-scale network traffic to identify anomalies. This paper introduces a distributed edge computing framework that integrates federated learning with Apache Spark and Kubernetes to address these challenges. We hypothesize that our approach, which enables collaborative model training across distributed nodes, significantly enhances the detection accuracy of network anomalies across different network types. We show that by leveraging distributed computing and containerization technologies, our framework not only improves scalability and fault tolerance but also achieves superior detection performance compared to state-of-the-art methods. Extensive experiments on the UNSW-NB15 and ROAD datasets validate the effectiveness of our approach, demonstrating statistically significant improvements in detection accuracy and training efficiency over baseline models, as confirmed by MannWhitney U and Kolmogorov-Smirnov tests$(p<0.05)$. William Marfo, Enrique A. Rico, Deepak K. Tosh, Shirley V. Moore |
CCNC | 3 |
| 2025 | Efficient Client Selection in Federated LearningabstractFederated Learning (FL) enables decentralized machine learning while preserving data privacy. This paper proposes a novel client selection framework that integrates differential privacy and fault tolerance. The adaptive client selection adjusts the number of clients based on performance and system constraints, with noise added to protect privacy. Evaluated on the UNSW-NB15 and ROAD datasets for network anomaly detection, the method improves accuracy by 7% and reduces training time by 25 % compared to baselines. Fault tolerance enhances robustness with minimal performance trade-offs.1 William Marfo, Deepak K. Tosh, Shirley V. Moore |
CCNC | 2 |
| 2025 | Detecting Masquerade Attacks in Controller Area Networks Using Graph Machine LearningabstractModern vehicles rely on a myriad of electronic control units (ECUs) interconnected via controller area networks (CANs) for critical operations. Despite their ubiquitous use and reliability, CANs are susceptible to sophisticated cyberattacks, particularly masquerade attacks, which inject false data that mimic legitimate messages at the expected frequency. These attacks pose severe risks such as unintended acceleration, brake deactivation, and rogue steering. Traditional intrusion detection systems (IDS) often struggle to detect these subtle intrusions due to their seamless integration into normal traffic. This paper introduces a novel framework for detecting masquerade attacks in the CAN bus using graph machine learning (ML). We hypothesize that the integration of shallow graph embeddings with time series features derived from CAN frames enhances the detection of masquerade attacks. We show that by representing CAN bus frames as message sequence graphs (MSGs) and enriching each node with contextual statistical attributes from time series, we can enhance detection capabilities across various attack patterns compared to using graph-based features only. Our method ensures a comprehensive and dynamic analysis of CAN frame interactions, improving robustness and efficiency. Extensive experiments on the ROAD dataset validate the effectiveness of our approach, demonstrating statistically significant improvements in the detection rates of masquerade attacks compared to a baseline that uses graph-based features only as confirmed by Mann-Whitney U and Kolmogorov-Smirnov tests (p< 0.05). William Marfo, Pablo Moriano, Deepak K. Tosh, Shirley V. Moore |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Countering ARP spoofing attacks in software-defined networks using a game-theoretic approach
Fabrice Mvah, Vianney Kengne Tchendji, Clémentin Tayou Djamégni, Ahmed H. Anwar, Deepak K. Tosh, Charles A. Kamhoua |
Comput. Secur. | 5 |
| 2023 | Optimal Honeypot Allocation using Core Attack Graph in Cyber Deception GamesabstractHoneypots appear today as a defense strategy to trap intelligent cyber attackers who can detect traditional security measures. The scalability of existing algorithms for solving some classes of game theory is very limited due to large-scale networks. This paper opens the door to a new approach to allocate honeypots in the network, to increase attackers’ costs, during the lateral movement of the APT attack. We use the core attack graph that can show the main routes an attacker can take toward the goal. This allows the defender to use a limited number of honeypots focusing its efforts only on critical nodes over the main attacker routes. The effectiveness and scalability of the proposed approach are evaluated over different network topologies, a varying number of honeypots, network size, and density. Numerical results show that the defender reward over the core attack graph is quite similar to that obtained on the original attack graph while significantly reducing the defender’s actions and computation time. Achile Leonel Nguemkam, Ahmed H. Anwar, Vianney Kengne Tchendji, Deepak K. Tosh, Charles A. Kamhoua |
PIMRC | 4 |
| 2022 | Edge-Based Optimal Routing in SDN-Enabled Industrial Internet of ThingsabstractThe efficiency of communication between devices in any network depends on the network architecture and the routing algorithms. This efficiency vastly affects the productivity of the Internet of Things (IoT) nodes when utilized in an industrial environment. The conundrum of using the conventional network architecture in an industry/factory connected by IoT devices has paved the way for the development of software-defined networking (SDN). Traditional network architectures lack network programmability and hinder the testing and performance evaluation of new communication protocols. The use of vendor-specific hardware is a major hindrance to create a network where the control is centralized for the deployment of different policies over the network. This article aims to find an optimal path for efficient communication between the nodes present in a programmable Industrial IoT (IIoT) network. A programmable IIoT network is created and end-user routing algorithms are designed to find the optimal path for communication. We integrate an SDN framework with IIoT nodes for the creation of a centralized programmable network architecture and deploy custom routing algorithms over it for evaluation. To further reduce the communication latency, we incorporate edge computing servers (ECSs) in the network. Three routing algorithms: 1)$K$-means-based optimal path algorithm; 2) cluster-based optimal path algorithm; and 3) minimum interval-based optimal path algorithm, that can be deployed over an SDN are proposed in this article. Experimental results reveal that the proposed algorithms are more efficient than the existing algorithms. Prasad Ramesh Desai, S. Mini 0001, Deepak K. Tosh |
IEEE Internet Things J. | 3 |
| 2021 | Robust Authentication and Data Flow Integrity for P2P SCADA InfrastructuresabstractThe Emergence of Industry 4.0 (I4.0) is pushing toward the modernization of Supervisory Control and Data Acquisition (SCADA) systems. Enabling such highly flexible architecture that meets the need of I4.0 remains challenging. Moreover, significant automation in critical infrastructures need robust security, in terms of strong authentication and data integrity assurance, without constraining the performance requirements. Thus, it is essential to design an I4.0 compliant hybrid SCADA that has the capability to adopt decentralized communications for new-generation devices. This paper presents an SRAM-based PUF Authentication, Integrity, and Non-repudiation Peer-to-Peer (SPAIN-P2P) protocol that meets the security requirements of modern SCADA. The SPAIN-P2P ensures data flow protection by integrating lightweight cryptographic algorithms and Physical Unclonable Functions in P2P-based SCADA network. The implementation and the promising performance results of the proposed SPAIN-P2P protocol reveal its suitability and adaptability for integrating in next generation SCADA environments. Abel O. Gomez Rivera, Evan M. White, Deepak K. Tosh |
LCN | 3 |
| 2021 | Tikiri - Towards a lightweight blockchain for IoT
Eranga Bandara, Deepak K. Tosh, Peter Foytik, Sachin Shetty, Nalin Ranasinghe, Kasun De Zoysa |
Future Gener. Comput. Syst. | 2 |
| 2021 | Leveraging Intel SGX to enable trusted and privacy preserving membership service in distributed ledgers
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
Int. J. Inf. Comput. Secur. | 3 |
| 2021 | Introduction to the Special Issue on Decentralized Blockchain Applications and Infrastructures for Next Generation Cyber-Physical Systemsabstractintroduction Introduction to the Special Issue on Decentralized Blockchain Applications and Infrastructures for Next Generation Cyber-Physical Systems Share on Editors: Kim Kwang Raymond Choo University of Texas at San Antonio University of Texas at San AntonioView Profile , Uttam Ghosh Vanderbilt University Vanderbilt UniversityView Profile , Deepak Tosh University of Texas El Paso University of Texas El PasoView Profile , Reza M. Parizi Kennesaw State University Kennesaw State UniversityView Profile , Ali Dehghantanha University of Guelph University of GuelphView Profile Authors Info & Claims ACM Transactions on Internet TechnologyVolume 21Issue 2June 2021 Article No.: 38epp 1–3https://doi.org/10.1145/3464768Online:15 June 2021Publication History 0citation68DownloadsMetricsTotal Citations0Total Downloads68Last 12 Months68Last 6 weeks5 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Kim-Kwang Raymond Choo, Uttam Ghosh, Deepak K. Tosh, Reza M. Parizi, Ali Dehghantanha |
ACM Trans. Internet Techn. | 3 |
| 2020 | Quality-driven Energy Optimization in Internet of ThingsabstractAs a consequence of limited internal battery capacity and needless expenditure of electrical energy in commercial and residential deployments of Internet of Things (IoT) in recent years, there has been a rise in the impetus given to energy saving and optimization. In this paper, we propose a technique to solve the energy optimization problem for an IoT deployment that detects critical events like elderly fall detection, fire detection, intruder detection, etc. This technique aims to achieve an optimal set of configurations for a given IoT deployment such that the total energy consumption is minimum, and the deployment satisfies the required threshold accuracy expected from the deployment. Researchers have addressed this issue using algorithms mostly based on the Greedy Heuristic approach to reduce energy consumption by considering the dynamic nature of configurations of IoT devices. We propose Dynamic multiple-choice knapsack (DMCKP) algorithm that produces a better solution. The results of the proposed approach are compared with the existing algorithms to demonstrate the superiority of the proposed algorithm. Vineet Naique Dhaimodker, Rahul Desai, S. Mini 0001, Deepak K. Tosh |
ICCCN | 4 |
| 2020 | Quantitative Risk Modeling and Analysis for Large-Scale Cyber-Physical SystemsabstractThreats of cyber attacks are very real today and greatly impact everything including the public health sector, economics, electric grids, internet of things (IoT), and national security. The number of new evolving threats and reported vulnerabilities has severely increased in the last few years [1]. Perpetually refined cyber-attacks have set data, organizational assets, organizations, and individuals at considerable risk. Protecting sophisticated networks and interdependent systems, or reducing the impact of cyber-attacks has become a major challenge, where today's effective countermeasures can be completely ineffective tomorrow. The various risk assessment frameworks and methodologies are either high-level, missing risk metrics values, not suitable for all kinds of networks, or publicly not available. To address this issue, we present a quantitative risk assessment model, that helps to model the organizational security posture, evaluates the security controls in place, and provides an understanding of the associated risks. We further provide a detailed explanation of the formulations and evaluate the proposed model on an industrial scenario. Adeel A. Malik, Deepak K. Tosh |
ICCCN | 2 |
| 2020 | Privacy Preserving Path Planning in an Adversarial ZoneabstractUsing Unmanned Aerial Vehicles (UAVs) for package delivery is an emerging technology. This technology facilitates delivery by providing safety, speed, road flexibility, reducing road congestion, etc. However, as the UAVs' path can be monitored by the public, such delivery could pose serious privacy issues. This is due to the fact that an attacker can monitor UAVs' path toward a destination and passively infer sensitive information about the users or even actively interfere in a package delivery system. To address this problem, in this paper, we study the challenges of preserving the privacy of a UAV's destination in an adversarial zone. We propose a set of path planning algorithms to protect the UAV's destination from a curious adversary. Our model does not rely on security by obscurity, which means that we assume the path planning algorithm is known to the public including adversary. Iman Vakilinia, Mohammad Jafari 0001, Deepak K. Tosh, Shahin Vakilinia |
ISNCC | 3 |
| 2019 | Non-Intrusive Deployment of Blockchain in Establishing Cyber-Infrastructure for Smart CityabstractInternet-of-Things has emerged to develop smart communities so that real time sensing and decision can improve operational efficiency and quality of lives. However, establishing such infrastructure can be exceptionally intricate due to the vast variety of devices and the implemented technologies. Also, it poses several unique challenges, such as heterogeneity of the infrastructure, type, and scale of deployment, security, privacy, and inter-operability. One primary concern in a smart city environment is the capabilities of typically end-IoT devices which are vulnerable to security threats and prone to confidentiality and integrity breach of data. Blockchain can potentially address these security challenges due to the distributed ledger's inherent properties. In this paper, we propose a decentralized architecture using the Blockchain to provide a secure and resilient smart city infrastructure that can run the ledger service over a distributed network. We consider a permissioned Blockchain, Hyperledger Sawtooth, and to automate and to overcome the infrastructural challenges concerning the smart city deployment, and we provide a systematic methodology that automates the deployment process and saves a significant amount of time. We simulate and deploy a Blockchain-integrated smart city environment using the proposed seamless deployment strategy using our automation module. With the proposed deployment scheme, we improve the Blockchain-based infrastructure development time by 82% compared to the traditional deployment approach. Adeel A. Malik, Deepak K. Tosh, Uttam Ghosh |
SECON | 2 |
| 2019 | An Improved Communications in Cyber Physical System Architecture, Protocols and ApplicationsabstractIn recent trends, Cyber-Physical Systems (CPS) and Internet of Things interpret an evolution of computerized integration connectivity. The specific research challenges in CPS as security, privacy, data analytics, participate sensing, smart decision making. In addition, The challenges in Wireless Sensor Network (WSN) includes secure architecture, energy efficient protocols and quality of services. In this paper, we present an architectures of CPS and its protocols and applications. We propose software related mobile sensing paradigm namely Mobile Sensor Information Agent (MSIA). It works as plug-in based for CPS middleware and scalable applications in mobile devices. The working principle MSIA is acts intermediary device and gathers data from a various external sensors and its upload to cloud on demand. CPS needs tight integration between cyber world and man-made physical world to achieve stability, security, reliability, robustness, and efficiency in the system. Emerging software-defined networking (SDN) can be integrated as the communication infrastructure with CPS infrastructure to accomplish such system. Thus we propose a possible SDN-based CPS framework to improve the performance of the system. Madhan E. S., Uttam Ghosh, Deepak K. Tosh, Mandal K., E. Murali, Soumalya Ghosh |
SECON | 3 |
| 2019 | Online Cyber Deception System Using Partially Observable Monte-Carlo Planning Framework
Md Ali Reza Al Amin, Sachin Shetty, Laurent Njilla, Deepak K. Tosh, Charles A. Kamhoua |
SecureComm (2) | 4 |
| 2018 | CloudPoS: A Proof-of-Stake Consensus Design for Blockchain Integrated CloudabstractMaintaining data provenance in cloud in a tamper-resistant manner that cannot be breached by malicious parties is a necessity from the current security standpoint. Blockchain technology has emerged as a secure solution to store and share information by offering an immutable distributed ledger service. Its effectiveness hinges on the infrastructure supporting the distributed ledger and consensus protocol that governs the validity of entries in the Blockchain. Hence, Blockchain can be a potential candidate to implement data provenance; however, traditional cryptocurrency-based consensus models become a bottleneck in the cloud environment. Therefore, in this paper, we propose a Blockchain based data provenance architecture (BlockCloud) that incorporates a proof-of-stake (PoS)-based consensus protocol (CloudPoS) for securely recording the data operations occurring in cloud environment. The critical operational phases of the protocol are discussed in depth, which leverages the cloud users' cyber infrastructure resources. A cloud-based testbed environment is created using a local cluster of physical machines managed by Xen hypervisor. Resource elasticity is enabled using Kubernetes setup that interacts with the dockerized containers, which emulate as peers in the Blockchain network. We then evaluate the effectiveness of the protocol in a simulated environment and conduct performance tests of the proposed consensus. Deepak K. Tosh, Sachin Shetty, Peter Foytik, Charles A. Kamhoua, Laurent Njilla |
IEEE CLOUD | 1 |
| 2018 | Towards a Reliable and Accountable Cyber Supply Chain in Energy Delivery System Using Blockchain
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Yafei Ji, Danyi Li |
SecureComm (2) | 3 |
| 2018 | A Reliable Data Provenance and Privacy Preservation Architecture for Business-Driven Cyber-Physical Systems Using BlockchainabstractCyber-physical systems (CPS) including power systems, transportation, industrial control systems, etc. support both advanced control and communications among system components. Frequent data operations could introduce random failures and malicious attacks or even bring down the whole system. The dependency on a central authority increases the risk of single point of failure. To establish an immutable data provenance scheme for CPS, the authors adopt blockchain and propose a decentralized architecture to assure data integrity. In business-driven CPS, end users are required to share their personal information with multiple third parties. To prevent data leakage and preserve user privacy, the authors isolate and feed different information retrieval requests using tokens specifically generated for each type of request. Providing both traceability of data operations, and unlinkability of end user activities, a robust blockchain-based CPS is prototyped. Evaluation indicates the architecture is capable of assured data provenance validation and user privacy preservation at a low overhead. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Juan Zhao 0003, Danyi Li, Jihong Liu |
Int. J. Inf. Secur. Priv. | 3 |
| 2018 | Establishing evolutionary game models for CYBer security information EXchange (CYBEX)
Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat |
J. Comput. Syst. Sci. | 1 |
| 2017 | An SDN Based Framework for Guaranteeing Security and Performance in Information-Centric Cloud NetworksabstractCloud data centers are critical infrastructures to deliver cloud services. Although security and performance of cloud data centers have been well studied in the past, their networking aspects are overlooked. Current network infrastructures in cloud data centers limit the ability of cloud provider to offer guaranteed cloud network resources to users. In order to ensure security and performance requirements as defined in the service level agreement (SLA) between cloud user and provider, cloud providers need the ability to provision network resources dynamically and on the fly. The main challenge for cloud provider in utilizing network resource can be addressed by provisioning virtual networks that support information centric services by separating the control plane from the cloud infrastructure. In this paper, we propose an sdn based information centric cloud framework to provision network resources in order to support elastic demands of cloud applications depending on SLA requirements. The framework decouples the control plane and data plane wherein the conceptually centralized control plane controls and manages the fully distributed data plane. It computes the path to ensure security and performance of the network. We report initial experiment on average round-trip delay between consumers and producers. Uttam Ghosh, Pushpita Chatterjee, Deepak K. Tosh, Sachin Shetty, Kaiqi Xiong, Charles A. Kamhoua |
CLOUD | 3 |
| 2017 | ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and AvailabilityabstractCloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 3 |
| 2017 | Security Implications of Blockchain Cloud with Analysis of Block Withholding AttackabstractThe blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations. Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 1 |
| 2017 | Towards a Trusted and Privacy Preserving Membership Service in Distributed Ledger Using Intel Software Guard Extensions
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
ICICS | 3 |
| 2015 | Cyber-Threats Information Sharing in Cloud Computing: A Game Theoretic ApproachabstractCybersecurity is among the highest priorities in industries, academia and governments. Cyber-threats information sharing among different organizations has the potential to maximize vulnerabilities discovery at a minimum cost. Cyber-threats information sharing has several advantages. First, it diminishes the chance that an attacker exploits the same vulnerability to launch multiple attacks in different organizations. Second, it reduces the likelihood an attacker can compromise an organization and collect data that will help him launch an attack on other organizations. Cyberspace has numerous interconnections and critical infrastructure owners are dependent on each other's service. This well-known problem of cyber interdependency is aggravated in a public cloud computing platform. The collaborative effort of organizations in developing a countermeasure for a cyber-breach reduces each firm's cost of investment in cyber defense. Despite its multiple advantages, there are costs and risks associated with cyber-threats information sharing. When a firm shares its vulnerabilities with others there is a risk that these vulnerabilities are leaked to the public (or to attackers) resulting in loss of reputation, market share and revenue. Therefore, in this strategic environment the firms committed to share cyber-threats information might not truthfully share information due to their own self-interests. Moreover, some firms acting selfishly may rationally limit their cybersecurity investment and rely on information shared by others to protect themselves. This can result in under investment in cybersecurity if all participants adopt the same strategy. This paper will use game theory to investigate when multiple self-interested firms can invest in vulnerability discovery and share their cyber-threat information. We will apply our algorithm to a public cloud computing platform as one of the fastest growing segments of the cyberspace. Charles A. Kamhoua, Andrew P. Martin, Deepak K. Tosh, Kevin A. Kwiat, Chad Heitzenrater, Shamik Sengupta |
CSCloud | 3 |
| 2015 | Game Theoretic Modeling to Enforce Security Information Sharing among FirmsabstractRobust CYBersecurity information EXchange (CYBEX) infrastructure is envisioned to protect the firms from future cyber attacks via collaborative threat intelligence sharing, which might be difficult to achieve via sole effort. The executive order from the U. S. federal government clearly encourages the firms to share their cybersecurity breach and patch related information among other federal and private firms for strengthening their as well as nation's security infrastructure. In this paper, we present a game theoretic framework to investigate the economic benefits of cyber-threat information sharing and analyze the impacts and consequences of not participating in the game of information exchange. We model the information exchange framework as distributed non-cooperative game among the firms and investigate the implications of information sharing and security investments. The proposed incentive model ensures and self-enforces the firms to share their breach information truthfully for maximization of its gross utility. Theoretical analysis of the incentive framework has been conducted to find the conditions under which firms' net benefit for sharing security information and investment can be maximized. Numerical results verify that the proposed model promotes such sharing, which helps to relieve their total security technology investment too. Deepak K. Tosh, Shamik Sengupta, Sankar Mukhopadhyay, Charles A. Kamhoua, Kevin A. Kwiat |
CSCloud | 1 |
| 2015 | An evolutionary game-theoretic framework for cyber-threat information sharingabstractThe initiative to protect against future cyber crimes requires a collaborative effort from all types of agencies spanning industry, academia, federal institutions, and military agencies. Therefore, a Cybersecurity Information Exchange (CYBEX) framework is required to facilitate breach/patch related information sharing among the participants (firms) to combat cyber attacks. In this paper, we formulate a non-cooperative cybersecurity information sharing game that can guide: (i) the firms (players)1to independently decide whether to “participate in CYBEX and share” or not; (ii) the CYBEX framework to utilize the participation cost dynamically as incentive (to attract firms toward self-enforced sharing) and as a charge (to increase revenue). We analyze the game from an evolutionary game-theoretic strategy and determine the conditions under which the players' self-enforced evolutionary stability can be achieved. We present a distributed learning heuristic to attain the evolutionary stable strategy (ESS) under various conditions. We also show how CYBEX can wisely vary its pricing for participation to increase sharing as well as its own revenue, eventually evolving toward a win-win situation. Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat, Andrew P. Martin |
ICC | 1 |
| 2013 | Self-Coexistence in Cognitive Radio Networks Using Multi-Stage Perception LearningabstractIn this paper, we study the self-coexistence problem among competitive Cognitive Radio (CR) networks in an uncoordinated distributed wireless environment of homogeneous and heterogeneous bands. This problem can be correlated with famous optimal foraging theory, where the humming birds forage to explore islands in search of food sources to survive. The behavior of learning from observations leads them to find island of optimal resources. The proposed perception based learning mechanism for homogeneous spectra, helps the CR networks to strategize their choice of actions on the basis of rewards gathered from the accessed spectrum bands and successfully grab a clear chunk of spectrum. However, in heterogeneous bands scenario, the CR networks inadvertently choose the best suitable band greedily which lead them to collision. We incorporate a regret minimization technique with the proposed learning mechanism to resolve the contention among them and maximize system performance. Experimental results conclude that the networks could achieve the objective of finding a free spectrum with maximized system utility using the proposed heuristic within limited number of interactions. Deepak K. Tosh, Shamik Sengupta |
VTC Fall | 1 |