Keyvan Ansari

dblp:143/1045 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0002-9969-7682ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Simulated Study of IoT ALPs Over Legacy TCP/UDP Versus QUIC and SCTP for V2I Communications
abstract
Vehicle-to-infrastructure (V2I) communication, a subset of Vehicle-to-everything (V2X), plays a critical role in enhancing road safety and traffic efficiency. While DSRC and C-V2X technologies have standardised physical layer communication, the upper layers remain flexible and open to diverse implementations. Existing IoT application layer protocols (ALPs), built on legacy TCP and UDP transport protocols, may exhibit suboptimal performance in dynamic V2I environments. This study evaluates six ALPs, i.e., AMQP, CoAP, DDS, MQTT, WebSocket (WS), and XMPP, across twenty protocol combinations, including modern QUIC and SCTP transport protocols. Using a simulation framework that integrates Omnet++, SUMO, Veins, and OpenStreetMap data, we assess key performance metrics: latency, packet delivery ratio, throughput, inter-arrival time, and connection establishment time. Our results indicate that while most protocol combinations perform adequately under low node densities (e.g., fewer than 100 nodes), network congestion leads to performance degradation. Nevertheless, CoAP over QUIC/UDP and WS over QUIC emerge as promising candidates for disseminating awareness messages across diverse V2I communication scenarios within the context and test limits.
Danladi Suleman, Rania Shibl, Mingzhong Wang, Keyvan Ansari
IEEE Trans. Intell. Transp. Syst.4
2025 Ransomware Encryption Detection: Adaptive File System Analysis Against Evasive Encryption Tactics
Arash Mahboubi, Hamed Aboutorab, Seyit Ahmet Çamtepe, Hang Thanh Bui, Khanh Luong, Keyvan Ansari, Shenlu Wang, Bazara I. A. Barry
ACISP (3)6
2025 Multi-Stage Payload Execution with Fragmented Double-Layer Encoding
abstract
This study provides a comprehensive examination of AtomBombing, a stealthy fileless code injection technique that leverages the Windows Global Atom Table for covert payload storage and execution. Unlike traditional injection strategies that rely on memory manipulation or file-based artifacts, AtomBombing avoids direct memory writes and operates entirely through legitimate Windows APIs, making it exceptionally evasive against modern endpoint detection and response tools. Through our proof-of-concept (PoCs) implementations, we demonstrate how adversaries could exploit atom-based payload fragmentation, double layer encoding, and time-based triggers to execute malicious tasks while minimizing forensic visibility. Building on those PoCs, we introduce ABOMB-FOD, a $\mathbf{1. 2 ~ M B}$ multistage loader that survives reboots, bypasses user account controls, and still fits comfortably within the Atom Table capacity limits ($\leq$ 65,535 entries $+\mathbf{2 5 5} \mathbf{B} \approx \mathbf{1 6} \mathbf{~ M B}$). The AtomBombing Process Orchestrator illustrates the ability to securely store encrypted payloads and orchestrate parallel execution using PowerShell, while the Atom Table Backdoor showcases persistent command-and-control behavior activated under specific system conditions. Our findings underscore the inadequacy of current security solutions in monitoring Atom Table interactions, i.e., critical API functions remain largely overlooked in behavioral analysis, despite their potential for stealthy data injection. Consistent with this blind spot, our evaluation confirms that standard defenses, including Windows Defender with cloud protection enabled, fail to detect or flag AtomBombing activity, even when ABOMBFOD or other payloads are executing and network interactions are in progress. We note that a straightforward heuristic, such as flagging any process that issues more than a certain number of GlobalAddAtomW invocations (e.g., 500) within a short time window (e.g., one minute) and stores high-entropy data, can be effective in identifying candidates for further investigation.
Arash Mahboubi, Keyvan Ansari, Seyit Ahmet Çamtepe
AICCSA2
2024 A Lightweight Detection of Sequential Patterns in File System Events During Ransomware Attacks
Arash Mahboubi, Hang Thanh Bui, Hamed Aboutorab, Khanh Luong, Seyit Ahmet Çamtepe, Keyvan Ansari
WISE (5)6
2024 Shared file protection against unauthorised encryption using a Buffer-Based Signature Verification Method
abstract
Understanding the attributes of critical data and implementing suitable security measures help organisations bolster their data-protection strategies and diminish the potential impacts of ransomware incidents. Unauthorised extraction and acquisition of data are the principal objectives of most cyber invasions. We underscore the severity of this issue using a recent attack by the Clop ransomware group, which exploited the MOVEit Transfer vulnerability and bypassed network-detection mechanisms to exfiltrate data via a Command and Control server. As a countermeasure, we propose a method called Buffer-Based Signature Verification (BBSV). This approach involves embedding 32-byte tags into files prior to their storage in the cloud, thus offering enhanced data protection. The BBSV method can be integrated into software like MOVEit Secure Managed File Transfer, thereby thwarting attempts by ransomware to exfiltrate data. Empirically tested using a BBSV prototype, our approach was able to successfully halt the encryption process for 80 ransomware instances from 70 ransomware families. BBSV not only stops the encryption but also prevents data exfiltration when data are moved or written from the original location by adversaries. We further develop a hypothetical exploit scenario in which an adversary manages to bypass the BBSV, illicitly transmits data to a Command and Control server, and then removes files from the original location. We construct an extended state space, in which each state represents a tuple that integrates user authentication and system components at the filesystem level.
Arash Mahboubi, Seyit Ahmet Çamtepe, Keyvan Ansari, Marcin Piotr Pawlowski, Pawel Morawiecki, Hamed Aboutorab, Josef Pieprzyk, Jaroslaw Duda 0001
J. Inf. Secur. Appl.3
2020 Cooperative Position Prediction: Beyond Vehicle-to-Vehicle Relative Positioning
abstract
Reliable and accurate relative position prediction techniques are vital to the integrity of cooperative intelligent transportation systems (C-ITS) because most C-ITS safety applications should constantly access a (relative-) localization mechanism that satisfies not only a certain (relative-) position accuracy range but also a minimal computational complexity. A global navigation satellite system (GNSS) coupled with dedicated short-range communications (DSRC) links is a candidate for the localization system required for vehicular relative positioning. The vehicle-to-vehicle (V2V) exchange of safety-related data such as raw GNSS measurements, as accurate and frequent as possible, via DSRC links allows the vehicular localization mechanism to maintain real-time relative positioning (RRP) vectors. However, V2V DSRC safety messages may include inaccurate positioning data or may fast become outdated, and/or DSRC links may occasionally fail due to various adverse scenarios including network overheads that drop the bandwidth of vehicular ad-hoc networks. Hence, each DSRC-enabled vehicle may not necessarily know the latest positioning data of neighboring vehicles. This calls upon reliable and accurate relative position prediction mechanisms to cover the DSRC-related deficiencies of relative positioning. This paper, at first, studies the benefits of a terrestrial communications system complementing DSRC-based V2V RRP and then considers position prediction techniques suitable for V2V RRP and examines a few existing solutions and makes a detailed comparison based on a set of required positioning performance parameters for vehicle safety application.
Keyvan Ansari
IEEE Trans. Intell. Transp. Syst.1
2018 Cloud Computing on Cooperative Cars (C4S): An Architecture to Support Navigation-as-a-Service
abstract
This paper offers a cloud computing architecture supporting Navigation-as-a-Service (NAVaaS) for Cooperative Intelligent Transportation Systems (C-ITS) to ensure interoperability among C-ITS users, i.e., users of single-and multi-Global Navigation Satellite Systems (GNSS) receivers. The proposed architecture, namely, Cloud Computing on Cooperative Cars (C4S) is a tailored design for connected vehicles using Dedicated Short-Range Communications (DSRC) or cellular connections. C4S is a scalable Everything-as-a-Service (XaaS) architecture using Mobile Cloud Computing (MCC) for sharing resources, platforms, software, data and communications as services. These shared infrastructure, platform, software and communications services are distributed across clusters over a network of servers and clients complementing Vehicular Ad-hoc Networks (VANETs). C4S sits above the VANET layer of C-ITS to improve transportation in terms of safety, reliability, productivity and resilience, and environmental protection. To this end, C4S establishes itself over two levels of MCC: (1) DSRC-based local fogs and (2) the Internet-based remote cloud. This architecture made an array of novel cloud-based navigation services possible that supports VANETs. The mechanism, capacity and applications of NAVaaS are verified through a describing function model and a series of experimental studies.
Keyvan Ansari
IEEE CLOUD1
2015 A Runtime Integrity Monitoring Framework for Real-Time Relative Positioning Systems Based on GPS and DSRC
abstract
This paper provides a three-layered framework to monitor the positioning performance requirements of real-time relative positioning (RRP) systems of the Cooperative Intelligent Transport Systems that support cooperative collision warning (CCW) applications. These applications exploit state data of surrounding vehicles obtained solely from the Global Positioning System (GPS) and dedicated short-range communications (DSRC) units without using other sensors. To this end, this paper argues the need for the GPS/DSRC-based RRP systems to have an autonomous monitoring mechanism, since the operation of CCW applications is meant to augment safety on roads. The advantages of autonomous integrity monitoring are essential and integral to any safety-of-life system. The autonomous integrity monitoring framework proposed necessitates the RRP systems to detect/predict the unavailability of their subsystems and of the integrity monitoring module itself and, if available, to account for effects of data link delays and breakages of DSRC links, as well as of faulty measurement sources of GPS and/or integrated augmentation positioning systems, before the information used for safety warnings/alarms becomes unavailable, unreliable, inaccurate, or misleading. Hence, a monitoring framework using a tight integration and correlation approach is proposed for instantaneous reliability assessment of the RRP systems. Ultimately, using the proposed framework, the RRP systems will provide timely alerts to users when the RRP solutions cannot be trusted or used for the intended operation.
Keyvan Ansari, Yanming Feng, Maolin Tang
IEEE Trans. Intell. Transp. Syst.1
2013 Vehicle-to-Vehicle Real-Time Relative Positioning Using 5.9 GHz DSRC Media
abstract
Vehicular accidents are one of the deadliest safety hazards and accordingly an immense concern of individuals and governments. Although, a wide range of active autonomous safety systems, such as advanced driving assistance and lane keeping support, are introduced to facilitate safer driving experience, these stand-alone systems have limited capabilities in providing safety. Therefore, cooperative vehicular systems were proposed to fulfill more safety requirements. Most of cooperative vehicle-to-vehicle safety applications require relative positioning accuracy of decimeter with an update rate of at least 10 Hz. These requirements cannot be met via direct navigation or differential positioning techniques. This paper studies a cooperative vehicle platform that aims to facilitate real-time relative positioning (RRP) among adjacent vehicles. The developed system is capable of exchanging both GPS position solutions and raw observations using RTCM-104 format over vehicular dedicated short range communication (DSRC) links. Real-time kinematic (RTK) positioning technique is integrated into the system to enable RRP to be served as an embedded real-time warning system. The 5.9 GHz DSRC technology is adopted as the communication channel among road-side units (RSUs) and on-board units (OBUs) to distribute GPS corrections data received from a nearby reference station via the Internet using cellular technologies, by means of RSUs, as well as to exchange the vehicular real-time GPS raw observation data. Ultimately, each receiving vehicle calculates relative positions of its neighbors to attain a RRP map. A series of real-world data collection experiments was conducted to explore the synergies of both DSRC and positioning systems. The results demonstrate a significant enhancement in precision and availability of relative positioning at mobile vehicles.
Keyvan Ansari, Lei Wang 0045, Yanming Feng
VTC Fall1