Nilesh Chakraborty

dblp:141/0902 · DBLP profile ↗
← Back
16ranked-venue papers
11as first author
9since 2021 · last 2025
0000-0002-3825-8838ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 1 since 2021Computer networks · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2
YearPublicationVenuePosition
2025 CSA-SACS: A Framework for Comparative Security Assessment in Smart Aging Care Systems
abstract
Smart Aging Care Systems (SACS) for independent living relies on various IoT service products to support the well-being of older adults. While research in this domain emphasizes the necessity of robust security protocols to protect this vulnerable population from cyber threats, there is a critical gap in methodologies for selecting the most suitable alternatives that meet the security requirements of SACS. This research introduces a framework, called Comparative Security Assessment in SACS (CSA-SACS). CSA-SACS evaluates the security standards of service products within SACS, integrating perspectives from multiple decision-makers, such as usability engineers and security experts. To address these evaluations’ inherent uncertainty and subjectivity, fuzzy triangular numbers are used for comparative assessments. The evaluation criteria are derived from the very recent ISO/IEC 25010:2023 standard, which encompasses conflicting elements, making the Analytic Hierarchy Process (AHP) a suitable approach for prioritization and ensuring consistency in decision-making. CSA-SACS enables evaluators to prioritize security selection criteria based on SACS-specific requirements and an automated error-handling mechanism to improve the reliability of judgment aggregation.
Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine
COMPSAC1
2025 Is Your PIN Safe Against Advanced Human-Centric Shoulder Surfing?
abstract
Personal Identification Numbers (PINs) are a widely used authentication method, especially in systems with limited user input interfaces. Although numerous studies have investigated the vulnerabilities of PINs against various cyber threats, some attacks, such as basic shoulder surfing, are often mitigated by enhancing the complexity of the user-interface. This paper challenges that conventional approach by introducing an attack strategy that builds upon three basic classifiers−Decision Tree, Random Forest, and Naive Bayes. Through the examination of both four-digit and six-digit PINs, the findings reveal that even with only partial knowledge of a captured PIN sequence−due to the cognitive limitations of human adversaries−it is possible to predict the remaining digits of the PIN with a significant success rate. In some cases, this rate exceeds 50%, which is considerably higher than the 10% success rate expected from random guessing. Despite the diminished effectiveness of the proposed attack model for six-digit PINs, the results of this preliminary research are compelling enough to question the assumed ineffectiveness of Human-Centric Shoulder Surfing (HCSS).
Nilesh Chakraborty, Mohammad Zulkernine
COMPSAC1
2024 Building Secure Software for Smart Aging Care Systems: An Agile Approach
abstract
There exists a persistent challenge in sufficiently addressing software security issues and effectively integrating security procedures into the software development life cycle. Software products vulnerable to security threats can result in severe consequences, especially in sensitive domains like those providing age-related support for older adults. This work offers guidelines to address software vulnerabilities in one of such evolving and sensitive domains, namely, Smart Aging Care Systems (SACS). The existing guidelines for securing the software cannot effectively address the observed vulnerabilities in SACS because of the unique demographics of its users and special design requirements. Therefore, the primary objective of this paper is to enhance the comprehension of secure software development methods, considering best security practices or controls in general and tailoring their selection based on the unique requirements of SACS. The chosen controls are then reshaped to align with the specific needs of SACS, with implementation carried out using the agile framework, specifically Scrum. We believe that this work will aid software development organizations in significantly enhancing the security of their software products for SACS dynamically and effectively, leveraging the Scrum framework, and also inspire its implementation in other emerging domains.
Nilesh Chakraborty, Shahrear Iqbal, Mohammad Zulkernine
QRS1
2024 Gait4Auth: Enhancing Identification and Security in Gait-Based Authentication
Youssef Yamout, Shahrear Iqbal, Nilesh Chakraborty, Mohammad Zulkernine
SecureComm (4)3
2023 A hybrid machine learning approach for hypertension risk prediction
Yingru Chen, Huihui Wang 0001, Nilesh Chakraborty, Yuyan Dai
Neural Comput. Appl.5
2022 RTT-Based Rogue UAV Detection in IoV Networks
abstract
Unmanned aerial vehicles (UAVs) are being used in different emerging domains for accomplishing many critical tasks. However, due to the various constraints, such as battery life, computational resources, etc., a UAV under a mission (M-UAV) often needs assistance from an edge/cloud server that is reachable from the M-UAV’s location. A connection between an M-UAV and edge server can be established via an access point or AP. Therefore, before sharing any sensitive information with the edge server, it is essential for an M-UAV to determine the legitimacy of the selected AP. Recently, some works in this direction indicate that a rogue UAV (R-UAV) can successfully mimic a legitimate AP for intercepting the communication channel. Hence, there should be a robust detection mechanism in place for addressing such a threat scenario. In this article, considering one of the emerging domains—the Internet of Vehicle (IoV) networks, at first, we show that communication in the IoV networks can get benefit from the presence of M-UAVs. However, as the link between the M-UAV and edge server can be intercepted by an R-UAV, the adversary may access the sensitive information from the IoV networks. Followed by this, we propose atiming-basedalgorithm for identifying the presence of rogue APs (or R-UAVs) in the channel. The M-UAV executes the timing-based algorithm, and the detection methoddoes notrequire any auxiliary hardware or any modification to the network protocols for meeting the objective. Supported by an extensive evaluation study, we show that without any rigid restriction on the M-UAV’s speed (e.g., by limiting it to almost static) the proposed approach significantly enhances the detection accuracy (at least by a margin of 29.7% and 16.65%) compared to the state-of-the-art methods.
Nilesh Chakraborty, Yao Chao, Jianqiang Li 0001, Sumit Mishra, Chengwen Luo 0001, Ying He 0006, Jie Chen 0027, Yi Pan 0001
IEEE Internet Things J.1
2022 Cryptanalysis of a Honeyword System in the IoT Platform
abstract
Password is one of the most well-known authentication methods in accessing many Internet of Things (IoT) devices. The usage of passwords, however, inherits several drawbacks and emerging vulnerabilities in the IoT platform. However, many solutions have been proposed to tackle these limitations. Most of these defense strategies suffer from a lack of computational power and memory capacity and do not have immediate cover in the IoT platform. Motivated by this consideration, the goal of this article is fivefold. First, we analyze the feasibility of implementing a honeyword-based defense strategy to prevent the latest developed server-side threat on the IoT domain’s password. Second, we perform thorough cryptanalysis of a recently developed honeyword-based method to evaluate its advancement in preventing the threat and explore the best possible way to incorporate it in the IoT platform. Third, we verify that we can add a honeyword-based solution to the IoT infrastructure by ensuring specific guidelines. Fourth, we propose a generic attack model, namely,matching attackutilizing the compromised password file to perform the security check of any legacy-UI approach for meeting the all essential flatness security criterion. Last, we compare the matching attack’s performance with the corresponding one of a benchmark technological methods over the legacy-UI model and confirm that our attack has 5%–22% more vulnerable than others.
Nilesh Chakraborty, Mithun Mukherjee 0001, Jianqiang Li 0001, Mohammad Shojafar, Yi Pan 0001
IEEE Internet Things J.1
2021 On designing an unaided authentication service with threat detection and leakage control for defeating opportunistic adversaries
Nilesh Chakraborty, Samrat Mondal
Frontiers Comput. Sci.1
2021 On Designing a Lesser Obtrusive Authentication Protocol to Prevent Machine-Learning-Based Threats in Internet of Things
abstract
In the era of the Internet of Things (IoT), people access many applications through smartphones for controlling smart devices. Therefore, such a centralized node must follow a robust access control mechanism so that an intruder cannot control the connected devices. Recent reports suggest that password can be used as an authentication factor for accessing the smart setups. However, this static information can be compromised under the light of different machine learning (ML)-empowered attack mechanisms. Alarmingly, different sensors used in the IoT setup can also expose this static information to the adversaries. Password-based authentication that uses a challenge-response strategy is an effective solution for handling such threat scenarios. In this article, at first, we show that no existing usable challenge-response protocol is safe to be used in the public area network. Following this, we propose a challenge-response protocol that is more secure to use in the public domain. By using eight classifiers, we show that a learning-based threat specific to our protocol has a marginal impact on the method's security standard. The discussion in this article also suggests that the proposed protocol has usability and security advantages compared to the existing state of the art (e.g., reduces the number of interactions between the user and verifier by a factor of 0.5).
Nilesh Chakraborty, Jianqiang Li 0001, Samrat Mondal, Chengwen Luo 0001, Huihui Wang 0001, Mamoun Alazab, Fei Chen 0003, Yi Pan 0001
IEEE Internet Things J.1
2019 Learning to Rank Query Graphs for Complex Question Answering over Knowledge Graphs
Gaurav Maheshwari 0001, Priyansh Trivedi, Denis Lukovnikov, Nilesh Chakraborty, Asja Fischer, Jens Lehmann 0001
ISWC (1)4
2019 Towards identifying and preventing behavioral side channel attack on recording attack resilient unaided authentication services
Nilesh Chakraborty, S. Vijay Anand, Samrat Mondal
Comput. Secur.1
2019 Towards incorporating honeywords in n-session recording attack resilient unaided authentication services
abstract
Unaided authentication services provide the flexibility to login without being dependent on any external hardware. n‐Session recording attack resilient unaided authentication services (n‐SRRUASs) are known for setting high security standards against different client side threats. However, because of their authentication procedure, the authors have identified that these services cope poorly with handling the server side issues. Though modern days’ research heavily depends on the honeywords (or fake passwords) as a countermeasure of server side threats, they have shown that the honeywords cannot be directly applied to n‐SRRUAS. The authors’ analysis shows that the idea of incorporating the honeywords directly into an n‐SRRUAS is particularly difficult as it prevents the system from storing passwords after applying password‐based key derivation function or in the form of a hashed string. In this study, they have proposed few generic principles for incorporating the honeywords into n‐SRRUAS and show that the proposed principles are sufficient for incorporating the honeywords into any n‐SRRUAS. Furthermore, with the help of an existing n‐SRRUAS, they have shown that the proposed idea is truly implementable in practice to fill the existing gap.
Nilesh Chakraborty, Samrat Mondal
IET Inf. Secur.1
2017 Distributed Semantic Analytics Using the SANSA Stack
Jens Lehmann 0001, Gezim Sejdiu, Lorenz Bühmann, Patrick Westphal, Claus Stadler, Ivan Ermilov, Simon Bin, Nilesh Chakraborty, Muhammad Saleem 0002, Axel-Cyrille Ngonga Ngomo, Hajira Jabeen
ISWC (2)8
2017 On designing a modified-UI based honeyword generation approach for overcoming the existing limitations
Nilesh Chakraborty, Samrat Mondal
Comput. Secur.1
2016 FREME: Multilingual Semantic Enrichment with Linked Data and Language Technologies
Milan Dojchinovski, Felix Sasaki, Tatjana Gornostaja, Sebastian Hellmann 0001, Erik Mannens, Frank Salliau, Michele Osella, Phil Ritchie, Giannis Stoitsis, Kevin Koidl, Markus Ackermann 0001, Nilesh Chakraborty
LREC12
2015 Few notes towards making honeyword system more secure and usable
abstract
Traditionally the passwords are stored in hashed format. However, if the password file is compromised then by using the brute force attack there is a high chance that the original passwords can be leaked. False passwords -- also known as honeywords, are used to protect the original passwords from such leak. A good honeyword system is dependent on effective honeyword generation techniques. In this paper, the risk and limitations of some of the existing honeyword generation techniques have been identified as different notes. Three concepts -- modified tails, close number formation and caps key are introduced to address the existing issues. The experimental analysis shows that the proposed techniques with some preprocessing can protect high percentage of passwords. Finally a comparative analysis is presented to show how the proposed approaches stand with respect to the existing honeyword generation approaches.
Nilesh Chakraborty, Samrat Mondal
SIN1