Sahil Gupta

dblp:137/6623 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
5since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 3 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2024 Adaptive highly secure and imperceptible video steganography for medical images via deep convolutional neural network
abstract
The risk of medical data theft has increased due to technological developments in communication. Steganography is frequently used for covert communication; however, existing steganography algorithms have poor imperceptibility, lesser embedding capacity, and lower extraction accuracy. The proposed model extracts the keyframe followed by data hiding and extraction using a convolutional neural network (CNN). The CNN model incorporates preparation, hidden and reveal networks that extract the low and high-dimensional features from the keyframe and secret image via convolution, and pooling operations. All three networks are trained collectively to minimise the loss function value. The computed value of peak signal to noise ratio (PSNR) between the keyframe and container frame is 32.7 decibels (dB), whereas an embedding capacity of 100% demonstrates the higher imperceptibility and embedding capacity of the proposed model than other state of art methods. The normalize correlation value (NC) of 0.996 on the receiver side indicates better robustness against attacks.
Sahil Gupta, Naresh Kumar Garg
Int. J. Inf. Comput. Secur.1
2023 Predictable Internet Clients and In-Switch Deep Packet Inspection
abstract
Deep packet inspection (DPI) is important for network security and is currently provided by complex black-box firewalls. This raises the question: Can network administrators build their own DPI-capable filter using a standard programmable switch? The common answer is that standard switches support P4, which allows users to specify how to parse packet headers, but not packet payload fields (e.g. URL) thus DPI tasks, like URL filtering, require dedicated middleboxes. In this paper, we challenge this common answer. First, we demonstrate that clients send packets with a predictable structure, so a P4 switch can perform some DPI (enough for URL filtering). Second, we demonstrate a URL-filtering firewall completely in the data plane, with no external help from the SDN controller, firewalls, etc. and no custom logic. Our proof-of-concept, P4Wall, handles multiple protocols (HTTP, HTTPS, DNS) with high performance - orders of magnitude faster than a standard Linux (netfilter) firewall.
Sahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. Acharya
ICCCN1
2023 DeeP4R: Deep Packet Inspection in P4 using Packet Recirculation
abstract
Software-defined networks are useful for multiple tasks, including firewalling, telemetry, and flow analysis. In particular, the P4 language makes it possible to carry out some simple packet processing tasks in the data plane, i.e., on the switch itself (without real-time support from the SDN controller or a server). However, owing to the limitations of packet parsing in P4, these tasks involve only the packet headers. In this paper, we present a novel approach that allows Deep Packet Inspection (DPI) – i.e., inspection of the packet payload – in the data plane, using P4 alone. We make use of the fact that in P4, a switch can clone and recirculate packets. One copy (clone) can be recirculated, slicing off a byte in each round, and using a finite-state machine to check if a target string has yet been seen. If the target string is found, the other copy (original packet) is discarded; if not, it is passed through. Our approach allows us to build the first application-layer firewall (URL filter) in the data plane, and to achieve essentially line-rate performance while filtering thousands of URLs, on a commodity programmable switch. It may in future also be used for other DPI tasks.
Sahil Gupta, Devashish Gosain, Minseok Kwon, Hrishikesh B. Acharya
INFOCOM1
2023 Data hiding in the optimal keyframes using circular shifting and mutation operations for improvement in imperceptibility
Sahil Gupta, Naresh Kumar Garg
Int. J. Inf. Comput. Secur.1
2021 Demo: Simple Deep Packet Inspection with P4
abstract
The P4 language allows "protocol-independent packet parsing" in network switches, and makes many operations possible in the data plane. But P4 is not built for Deep Packet Inspection – it can only "parse" well-defined packet headers, not free-form headers as seen in HTTPS etc. Thus some very important use cases, such as application-layer firewalls, are considered impossible for P4. This demonstration shows that this limitation is not strictly true: switches, that support only standard P4, are able to independently perform tasks such as blocking specific URLs (without using non-standard "extern" components, help from the SDN controller, or rerouting to a firewall). As more Internet infrastructure becomes SDN-compatible, in future, switches may perform simple application-layer firewall tasks.
Sahil Gupta, Devashish Gosain, Garegin Grigoryan, Minseok Kwon, Hrishikesh B. Acharya
ICNP1
2019 Proof-Carrying Network Code
abstract
Computer networks often serve as the first line of defense against malicious attacks. Although there are a growing number of tools for defining and enforcing security policies in software-defined networks (SDNs), most assume a single point of control and are unable to handle the challenges that arise in networks with multiple administrative domains. For example, consumers may want want to allow their home IoT networks to be configured by device vendors, which raises security and privacy concerns. In this paper we propose a framework called Proof-Carrying Network Code (PCNC) for specifying and enforcing security in SDNs with interacting administrative domains. Like Proof-Carrying Authorization (PCA), PCNC provides methods for managing authorization domains, and like Proof-Carrying Code (PCC), PCNC provides methods for enforcing behavioral properties of network programs. We develop theoretical foundations for PCNC and evaluate it in simulated and real network settings, including a case study that considers security in IoT networks for home health monitoring.
Christian Skalka, John H. Ring, David Darais, Minseok Kwon, Sahil Gupta, Kyle Diller, Steffen Smolka, Nate Foster
CCS5
2019 FADU-EV an automated framework for pre-release emotive analysis of theatrical trailers
Jaiteg Singh, Gaurav Goyal, Sahil Gupta
Multim. Tools Appl.3
2013 Trust-based Security Protocol against blackhole attacks in opportunistic networks
abstract
Opportunistic networks (Oppnets) are a kind of wireless networks that provide the opportunity to have social interaction and obtain data that can be used for message passing decision. The increase observed in the number of people with PDAs and other handset devices equipped with wireless technologies makes the forwarding paradigm and Oppnets scenarios more interesting and challenging. The main challenge in Oppnets is to take efficient routing decisions on securing the delivery of messages to the destination. Cooperation and trust between nodes in the network saves them from malicious attacks. The trust of a node is a basic value that symbolizes the magnitude of its social responsibility in the network, which include helping groups of nodes in message delivery, saving these nodes from malicious attacks, just to name a few. This paper focuses on blackhole attack against the PRoPHET routing protocol for Oppnets. A Trust-based Security Protocol (TSP) is proposed to secure Oppnets against blackhole attacks. Simulation results are provided to support the effectiveness of our proposed TSP approach, in the sense that considerable control is observed in the number of dropped packets, number of messages captured bythe malicious nodes (so-called malicious count) and overhead ratio.
Sahil Gupta, Sanjay K. Dhurandher, Isaac Woungang, Arun Kumar 0013, Mohammad S. Obaidat
WiMob1