Alefiya Hussain

dblp:13/2327 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
1since 2021 · last 2023
0000-0002-4944-8338ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 3 first-authorSystems, architecture and hardware · 2Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Network security · 82% Systems and software security · 13% Digital forensics and information hiding · 3%
Computer networks
4 papers
Network measurement and analytics · 67% Network optimization and economics · 25% Network management and operations · 8%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Performance modeling and evaluation · 54% Distributed systems · 46%

Topics — the 14 heaviest of 18, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
denial-of-service attack
0.232009
Accurately Measuring Denial of Service in Simulation and Testbed Experiments · IEEE Trans. Dependable Secur. Comput. 2009
When is service really denied?: a user-centric dos metric · SIGMETRICS 2007
A framework for classifying denial of service attacks · SIGCOMM 2003
Network measurement and analytics › measurement infrastructure
network testbed
0.112012
Reducing allocation errors in network testbeds · Internet Measurement Conference 2012
Network optimization and economics
resource allocation
0.112012
Reducing allocation errors in network testbeds · Internet Measurement Conference 2012
Network security › attack resilience › attack mitigation
denial-of-service defense
0.112008
Testing a Collaborative DDoS Defense In a Red Team/Blue Team Exercise · IEEE Trans. Computers 2008
Systems and software security
security testing
0.112008
Testing a Collaborative DDoS Defense In a Red Team/Blue Team Exercise · IEEE Trans. Computers 2008
Network measurement and analytics › network performance measurement
quality of service measurement
0.112007
When is service really denied?: a user-centric dos metric · SIGMETRICS 2007
Network security › attack resilience › attack mitigation › denial-of-service defense
denial-of-service attack detection
0.112006
Identification of Repeated Denial of Service Attacks · INFOCOM 2006
Network security › intrusion detection and prevention
intrusion detection
0.112006
Identification of Repeated Denial of Service Attacks · INFOCOM 2006
Network security › traffic analysis
traffic classification
0.112006
Identification of Repeated Denial of Service Attacks · INFOCOM 2006
Network measurement and analytics › traffic characterization
attack traffic characterization
0.012003
A framework for classifying denial of service attacks · SIGCOMM 2003
Network security › attack modeling
attack classification
0.012003
A framework for classifying denial of service attacks · SIGCOMM 2003
Performance modeling and evaluation
benchmarking
0.012009
Accurately Measuring Denial of Service in Simulation and Testbed Experiments · IEEE Trans. Dependable Secur. Comput. 2009
Usable security › security operations › security analytics › cyber threat intelligence
attack attribution
0.012006
Identification of Repeated Denial of Service Attacks · INFOCOM 2006
Digital forensics and information hiding › digital forensics
network forensics
0.012006
Identification of Repeated Denial of Service Attacks · INFOCOM 2006

Methods — techniques the papers use, named apart from their topics

quality-of-service mapping · 0.2human user study · 0.2red team/blue team exercise · 0.2spectral analysis · 0.1packet trace analysis · 0.1semantic modeling · 0.1simulation · 0.1ramp-up analysis · 0.1controlled experiment · 0.1
YearPublicationVenuePosition
2023 Modeling Cognitive Workload in Open-Source Communities via Simulation
Alexey Tregubov, Jeremy Abramson, Christophe Hauser, Alefiya Hussain, Jim Blythe
MABS4
2017 Towards repeatability & verifiability in networking experiments: A stochastic framework
Swati Sharma 0003, Alefiya Hussain, Huzur Saran
J. Netw. Comput. Appl.2
2016 DBit: Assessing statistically significant differences in CDN performance
Zahaib Akhtar, Alefiya Hussain, Ethan Katz-Bassett, Ramesh Govindan
Comput. Networks2
2014 Enabling Collaborative Research for Security and Resiliency of Energy Cyber Physical Systems
abstract
The University of Illinois at Urbana Champaign (Illinois), Pacific Northwest National Labs (PNNL), and the University of Southern California Information Sciences Institute (USC-ISI) consortium is working toward providing tools and expertise to enable collaborative research to improve security and resiliency of cyber physical systems. In this extended abstract we discuss the challenges and the solution space. We demonstrate the feasibility of some of the proposed components through a wide-area situational awareness experiment for the power grid across the three sites.
Alefiya Hussain, Ted Faber, Bob Braden, Terry V. Benzel, Timothy M. Yardley, Jeremy Jones, David M. Nicol, William H. Sanders, Thomas W. Edgar, Thomas E. Carroll, David O. Manz, Laura Tinnel
DCOSS1
2012 Reducing allocation errors in network testbeds
abstract
Network testbeds have become widely used in computer science, both for evaluation of research technologies and for hands-on teaching. This can naturally lead to oversubscription and resource allocation failures, as limited testbed resources cannot meet the increasing demand.
Jelena Mirkovic, Alefiya Hussain
Internet Measurement Conference3
2011 A Semantic Framework for Data Analysis in Networked Systems
Arun Viswanathan, Alefiya Hussain, Jelena Mirkovic, Stephen Schwab, John Wroclawski
NSDI2
2009 Accurately Measuring Denial of Service in Simulation and Testbed Experiments
abstract
Researchers in the denial-of-service (DoS) field lack accurate, quantitative, and versatile metrics to measure service denial in simulation and testbed experiments. Without such metrics, it is impossible to measure severity of various attacks, quantify success of proposed defenses, and compare their performance. Existing DoS metrics equate service denial with slow communication, low throughput, high resource utilization, and high loss rate. These metrics are not versatile because they fail to monitor all traffic parameters that signal service degradation. They are not quantitative because they fail to specify exact ranges of parameter values that correspond to good or poor service quality. Finally, they are not accurate since they were not proven to correspond to human perception of service denial. We propose several DoS impact metrics that measure the quality of service experienced by users during an attack. Our metrics are quantitative: they map QoS requirements for several applications into measurable traffic parameters with acceptable, scientifically determined thresholds. They are versatile: they apply to a wide range of attack scenarios, which we demonstrate via testbed experiments and simulations. We also prove metrics' accuracy through testing with human users.
Jelena Mirkovic, Alefiya Hussain, Sonia Fahmy, Peter L. Reiher, Roshan K. Thomas
IEEE Trans. Dependable Secur. Comput.2
2008 Testing a Collaborative DDoS Defense In a Red Team/Blue Team Exercise
abstract
Testing security systems is challenging because a system's authors have to play the double role of attackers and defenders. Red team/blue team exercises are an invaluable mechanism for security testing. They partition researchers into two competing teams of attackers and defenders, enabling them to create challenging and realistic test scenarios. While such exercises provide valuable insight into vulnerabilities of security systems, they are very expensive and thus rarely performed. In this paper we describe a red team/blue team exercise, sponsored by DARPA's FTN program, and performed October 2002 --- May 2003. The goal of the exercise was to evaluate a collaborative DDoS defense, comprised of a distributed system, COSSACK, and a stand-alone defense, D-WARD. The role of the blue team was played by developers of the tested systems from USC/ISI and UCLA, the red team included researchers from Sandia National Laboratory, and all the coordination, experiment execution, result collection and analysis was performed by the white team from BBN Technologies. This exercise was of immense value to all involved --- it uncovered significant vulnerabilities in tested systems, pointed out desirable characteristics in DDoS defense systems (e.g., avoiding reliance on timing mechanisms), and taught us many lessons about testing of DDoS defenses.
Jelena Mirkovic, Peter L. Reiher, Christos Papadopoulos, Alefiya Hussain, Marla Shepard, Michael Berg, Robert Jung
IEEE Trans. Computers4
2007 When is service really denied?: a user-centric dos metric
abstract
Denial-of-service (DoS) research community lacks accurate metrics to evaluate an attack's impact on network services, its severity and the effectiveness of a potential defense. We propose several DoS impact metrics that measure the quality of service experienced by end users during an attack, and compare these measurements to application-specific thresholds. Our metrics are ideal for testbed experimentation, since necessary traffic parameters are extracted from packet traces gathered during an experiment.
Jelena Mirkovic, Alefiya Hussain, Brett Wilson, Sonia Fahmy, Wei-Min Yao, Peter L. Reiher, Stephen Schwab, Roshan K. Thomas
SIGMETRICS2
2006 Identification of Repeated Denial of Service Attacks
abstract
Abstract — Denial of Service attacks have become a weapon for extortion and vandalism causing damages in the millions of dollars to commercial and government sites. Legal prosecution is a powerful deterrent, but requires attribution of attacks, currently a difficult task. In this paper we propose a method to automatically fingerprint and identify repeated attack scenarios—a combination of attacking hosts and attack tool. Such fingerprints not only aid in attribution for criminal and civil prosecution of attackers, but also help justify and focus response measures. Since packet contents can be easily manipulated, we base our fingerprints on the spectral characteristics of the attack stream which are hard to forge. We validate our methodology by applying it to real attacks captured at a regional ISP and comparing the outcome with header-based classification. Finally, we conduct controlled experiments to identify and isolate factors that affect the attack fingerprint. I.
Alefiya Hussain, John S. Heidemann, Christos Papadopoulos
INFOCOM1
2004 Distinguishing between single and multi-source attacks using signal processing
Alefiya Hussain, John S. Heidemann, Christos Papadopoulos
Comput. Networks1
2003 A framework for classifying denial of service attacks
abstract
Launching a denial of service (DoS) attack is trivial, but detection and response is a painfully slow and often a manual process. Automatic classification of attacks as single- or multi-source can help focus a response, but current packet-header-based approaches are susceptible to spoofing. This paper introduces a framework for classifying DoS attacks based on header content, transient ramp-up behavior and novel techniques such as spectral analysis. Although headers are easily forged, we show that characteristics of attack ramp-up and attack spectrum are more difficult to spoof. To evaluate our framework we monitored access links of a regional ISP detecting 80 live attacks. Header analysis identified the number of attackers in 67 attacks, while the remaining 13 attacks were classified based on ramp-up and spectral analysis. We validate our results through monitoring at a second site, controlled experiments, and simulation. We use experiments and simulation to understand the underlying reasons for the characteristics observed. In addition to helping understand attack dynamics, classification mechanisms such as ours are important for the development of realistic models of DoS traffic, can be packaged as an automated tool to aid in rapid response to attacks, and can also be used to estimate the level of DoS activity on the Internet. 1.
Alefiya Hussain, John S. Heidemann, Christos Papadopoulos
SIGCOMM1