VLDB 2026 Research / reviewers in the wild / expert
Anca Jurcut
dblp:15/2870 · also Anca D. Jurcut, Anca Delia Jurcut
· DBLP profile ↗
45ranked-venue papers
5as first author
35since 2021 · last 2026
0000-0002-2705-1823ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 1 first-author · 16 since 2021Security and privacy · 11 · 4 first-author · 7 since 2021Systems, architecture and hardware · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Let's get QUIC Securing IP-based Industrial Protocols by ProxyingabstractIndustrial protocols have historically been optimized for functionality and performance without considering the embedding of solid security features. Smart grids constitute a clear example, as these critical infrastructures rely heavily on power system protocols for automation. However, increasing interconnection requirements have brought novel security challenges that are difficult to mitigate with isolation and legacy lightweight security approaches. Although new industrial protocol extensions address security issues, it could be infeasible to incorporate them into already deployed infrastructures. This work proposes a proxy-based solution designed for an existing SSH3 embodiment built on top of the QUIC protocol, offering standalone proxy mechanisms that are independent of established protocols. To accomplish this, we developed a reverse socket proxy implementation for SSH3. Then, we evaluated the latency overhead of our solution to assess its practicality in industrial environments. Our results have shown that, leveraging our QUIC-based proxy solution, we can achieve average latency improvements ranging between 16% and 40%. David de Hoz, Ioannis Zografopoulos, Anca Jurcut |
CCNC | 3 |
| 2026 | Secure Distributed Overtaking and Lane Change Maneuvers for Cooperative AVsabstractAutonomous overtaking requires secure and low-latency coordination among connected vehicles. We present a deterministic, policy-driven framework on Hyperledger Fabric for a cooperative maneuver where the object vehicle keeps its lane while the leading vehicle temporarily moves into an adjacent gap. A smart contract enforces a parametric safety inequality derived from passing sight distance, combining relative speeds, visibility, reaction time and safety margins into a Boolean decision. Using Hyperledger Caliper, we benchmark the framework under realistic workloads and block-cutting configurations. With tuned parameters, the network achieves >250 transactions/s with maximum latency < 1s, satisfying human reaction time constraints. The best trade-off is obtained at BatchTimeout=0.25s and MaxMessageCount=100. Compared with prior blockchain–AV schemes, our design achieves lower latency and competitive throughput while preserving auditable, on-chain safety decisions. Eranda Harshanath Jayatunga, Anupa De Silva, Anca Jurcut, Nima Afraz |
CCNC | 3 |
| 2026 | Coordinated Resource Management for Energy-Efficient DNN Inference on Heterogeneous Edge Devices
Yuening Wang, Juan Fang 0004, Ran Zhai, Qi Ming, Anca Jurcut |
Euro-Par (2) | 6 |
| 2026 | A simulation-based unified framework for real-time malicious traffic detection in multi-environment networksabstractA multi-environment (M-En) network, integrating various network architectures, faces significant challenges in detecting malicious traffic due to diverse protocols and traffic patterns. Developing separate security frameworks for each network type increases management overhead, limits scalability, and raises costs. Another issue in this domain is the limited deployment-oriented validation of malicious traffic detection systems (MTDS), which restricts their effectiveness in protecting M-En networks under live conditions. To address these challenges, this study proposes a unified simulation-based, deployment-feasible, transfer learning-based MTDS for M-En networks, with a focus on both IoT and traditional IP-based infrastructures. In our client-server simulation setup on Ubuntu, the client captures traffic at the central gateway and forwards it to the server for analysis, where flagged malicious packets are discarded at the gateway following batch-level analysis. A representative M-En feasibility dataset is generated using partial least squares (PLS) canonical analysis by merging two benchmark datasets, IoT23 (IoT malware traffic) and CICDDoS2019 (traditional IP-based DDoS traffic). An RNN-LSTM-based transfer learning model is employed for feature extraction from this M-En dataset, and various machine learning algorithms are trained and evaluated in both offline and deployment-oriented simulation settings. Logistic Regression emerges as the best-performing model, achieving a mean accuracy of 0.98 in offline testing and 0.71 during simulation-based gateway evaluation, along with the lowest computational time (averaging 0.521 seconds offline and 0.59 seconds per batch during simulated deployment) and minimal memory and CPU usage. Furqan Rustam, Anca Jurcut |
Comput. Networks | 2 |
| 2026 | A privacy-preserving information sharing scheme in online social networks
Yehong Luo, Nafei Zhu, Jingsha He, Anca Jurcut, Yuzi Yi, Xiangjun Ma, Juan Fang 0004 |
J. Inf. Secur. Appl. | 4 |
| 2026 | MLRan: A behavioural dataset for ransomware analysis and detectionabstractRansomware remains a critical threat to cybersecurity, yet publicly available datasets for training machine learning-based ransomware detection models are scarce and often have limited sample size, diversity, and reproducibility. In this paper, we introduce MLRan, a behavioural ransomware dataset, comprising over 4800 samples across 64 ransomware families and a balanced set of goodware samples. The samples span from 2006 to 2024 and encompass the four major types of ransomware: locker, crypto, ransomware-as-a-service, and modern variants. We also propose guidelines (GUIDE-MLRan), inspired by previous work, for constructing high-quality behavioural ransomware datasets, which informed the curation of our dataset. We evaluated the ransomware detection performance of several machine learning (ML) models using MLRan. For this purpose, we performed feature selection by conducting mutual information filtering to reduce the initial 6.4 million features to 24,162, followed by recursive feature elimination, yielding 483 highly informative features. The ML models achieved an accuracy, precision and recall of up to 98.7%, 98.9%, 98.5%, respectively. Using SHAP and LIME, we identified critical indicators of malicious behaviour, including registry tampering, strings, and API misuse. The dataset and source code for feature extraction, selection, ML training, and evaluation are available publicly to support replicability and encourage future research, which can be found at https://github.com/faithfulco/mlran . Faithful Chiagoziem Onwuegbuche, Sunday Olaoluwa Adelodun, Anca Jurcut, Liliana Pasquale |
J. Netw. Comput. Appl. | 3 |
| 2025 | Few-Shot Retrieval-Augmented LLMs for Anomaly Detection in Network Traffic
Furqan Rustam, Islam Obaidat, Davide Di Monda, Anca Jurcut |
CANS | 4 |
| 2025 | Rapid Few-Shot Learning for Resilient Multi-Domain Intrusion DetectionabstractModern networking infrastructures—composed of heterogeneous architectures and configurations, i.e. domains—introduce complexity that significantly amplifies the potential attack surface. Machine and deep learning-based Network Intrusion Detection Systems (NIDS), though promising, (i) require extensive labeled datasets and (ii) must undergo complete re-training when adapting to novel network domains, making them impractical in dynamic multi-domain environments. To address these challenges, we propose MD-RFS, a Few-Shot Learning NIDS based on the Rethinking Few-Shot approach, specifically designed for multiple network domains. MD-RFS employs a 2-step learning procedure that quickly adapts from a source domain to a target domain using only a limited number of labeled traffic data, while crucially preserving its detection capabilities on the original source domain. An extensive experimental evaluation—spanning three heterogeneous domains (viz. traditional IP, IoT, and SDN), each represented by a recent and publicly-available dataset—demonstrates the efficacy of MD-RFS. In ideal conditions, MD-RFS maintains near upper-bound detection performance on the source domain while having good adaptation performance. In a realistic few-shot scenarios, MD-RFS achieves adaptation results comparable to the best baseline competitor, yet significantly reduces adaptation time by 2 orders of magnitude. These findings are further validated through visual explainability analysis. The implementation is publicly available to foster reproducibility and further research. Davide Di Monda, Furquan Rustam, Anca Jurcut, Antonio Pescapè |
GLOBECOM | 3 |
| 2025 | One Model to Catch Them All: Autoencoder-Based Anomaly Detection in Next-Generation NetworksabstractAnomaly detection is crucial for ensuring the security and reliability of next-generation heterogeneous networks, which integrate a variety of devices (e.g., IoT and traditional devices). Autoencoder (AE)-based approaches have shown promise in identifying network anomalies by modeling benign traffic and detecting deviations. However, existing AE methods, mostly evaluated in homogeneous environments, struggle to generalize in next-generation multi-environment (M-En) networks (comprising both IoT and traditional devices) due to diverse traffic patterns. This generalization issue is evidenced through an initial ablation study, where AE models trained solely on a single traffic type (e.g., IoT-only) fail to detect anomalies effectively in M-En networks. To address this limitation, a Residual Autoencoder (RD-AE) specifically designed for anomaly detection in next-generation M-En networks is presented. RD-AE is trained on a combined actual benign dataset containing both IoT and traditional traffic, allowing it to accurately identify abnormal (malicious) deviations in M-En networks. An attention-based BiLSTM classifier subsequently categorizes these detected anomalies, differentiating between malicious IoT and traditional traffic to support targeted defensive measures. A human-in-the-loop continuous learning mechanism is integrated into the classifier, ensuring adaptability to emerging threats. A realistic testbed is used to generate M-En traffic and evaluate the proposed framework in real time. Experimental results show that RD-AE achieves up to 97.4% accuracy in detecting previously unseen attack scenarios. Islam Obaidat, Furqan Rustam, Anca Jurcut |
GLOBECOM | 3 |
| 2025 | Optimizing Security in Dynamic Service Migration Scenarios of Multi-Access Edge ComputingabstractSecurity mechanisms and Service Level Guarantees (SLGs) often operate in tension within communication systems, where stronger security protocols introduce overhead, processing delays, and encryption-related latency that can hinder the ability to meet predefined SLGs. This challenge is particularly critical in Multi-Access Edge Computing (MEC), where service migration across edge nodes can significantly impact system performance. Ensuring the security of migrating services while maintaining low-latency communication is vital to preserving service continuity and avoiding disruptions. In this paper, we introduce a novel security framework for MEC-enabled gNodeBs that supports secure and seamless service migration. Central to our framework is an adaptive security optimization model that dynamically adjusts the security level of the migration channel based on real-time bandwidth utilization. This approach maintains the continuity of service without compromising the available bandwidth, thereby upholding the required SLGs while minimizing the impact of security-related overhead. Pasika Ranaweera, Indika A. M. Balapuwaduge, Anca Jurcut, Engin Zeydan, Madhusanka Liyanage |
VTC2025-Fall | 3 |
| 2025 | SG-VAE: Explainable Semi-Generative Model for Attack Detection in IoT Healthcare SystemsabstractThe integration of Internet of Things (IoT) technologies in healthcare has revolutionized patient monitoring and medical data collection, but it has also introduced new vulnerabilities to cyberattacks. Ensuring the security of these connected medical devices is essential to maintain patient safety and system reliability. In this study, we propose a lightweight semi-generative deep learning framework based on a Variational Autoencoder (SG-VAE) for detecting attacks in IoT-based healthcare systems. The model compresses high-dimensional network traffic into a latent representation using the VAE encoder and employs a classification head to detect potential cyber threats directly from the latent space. Unlike conventional generative models focused on input reconstruction, our SG-VAE leverages the generative structure purely for efficient and effective classification, resulting in a high-throughput, real-time system in resource-constrained environments. To enhance transparency and interpretability, we integrate two eXplainable AI (XAI) techniques, SHAP and LIME, to provide insights into model decisions, helping stakeholders understand which features influence predictions most. Experimental results on a publicly available IoT-based ICU healthcare security dataset demonstrate that our model achieves near-perfect accuracy, 1.00, and high throughput, 54,286 samples/second, making it both highly effective and practical for deployment in real-world healthcare systems. All code required to reproduce the experiments is publicly available on Dropbox11https://rb.gy/5y3kuh. Komal Ghafoor, Furquan Rustam, Anca Jurcut, Devis Bianchini |
WiMob | 3 |
| 2025 | Lightweight Fine-Tuning of LLMS for Explainable Intrusion Detection in SDNabstractCybersecurity concerns are rising with the rapid adoption of technology as cybercriminals grow more active. Protecting complex networks like Software-Defined Networking (SDN) is increasingly challenging because its centralized architecture introduces vulnerabilities that traditional security systems struggle to handle. This paper investigates the application of large language models (LLMs) for intrusion detection in SDN environments. Our proposed approach fine-tunes three LLMs, GPT_NEO, Phi-2, and Llama2-7b, through Quantized Low-Rank Adaptation (QLoRA), enabling efficient 4-bit quantization and reduced memory usage. Structured network features are transformed into natural language prompts for binary classification of benign and malicious traffic. Experimental results show that all models achieve high accuracy, with Llama2-7b and Phi-2 reaching high scores across multiple data scales. CodeCarbon tracking highlights the environmental trade-offs, with Llama27b consuming the most energy and Phi-2 being the most efficient. Our proposed framework for Phi-2 and GPT_NEO achieves a 1.00 accuracy score with the lowest$\text{CO}_{2}$emission of 0.173 when compared with the baselines. Further, we explore explainability challenges for our LLM models, noting the limitations of token-level interpretability tools in handling dense textual embeddings. Suvajit Lodh, Islam Obaidat, Furqan Rustam, Anca Jurcut |
WiMob | 4 |
| 2025 | Adaptive security framework for multi-environment networks using ensemble data drift detection and incremental deep learning
Furqan Rustam, Anca Jurcut |
J. Inf. Secur. Appl. | 2 |
| 2025 | Deep Learning-Driven Cyber Attack Detection Framework in DC Shipboard Microgrids System for Enhancing Maritime Transportation SecurityabstractEnhancing cybersecurity in DC shipboard microgrid (SMG) systems is crucial for maintaining the resilience of energy operation in maritime transportation systems (MTS). However, increasing cyber threats pose significant challenges to deploying resilient technologies in intelligent DC SMGs. These intricate cyber-physical systems, comprising power electronics, distributed generation units, sensors, and monitoring technologies, are managed remotely, making them vulnerable to attacks that jeopardize their stability and security. Existing solutions often require additional support due to low detection and high false alarm rates, primarily from manual analysis. To address these issues, this study presents a sophisticated deep learning-driven cyber-attack detection and identification model designed to effectively enhance the security of DC SMGs in MTS. The proposed framework leverages Long Short-Term Memory (LSTM) with variational autoencoder (VAE) architectures for deep feature extraction (DFE) under attack scenarios. VAE schemes automatically uncover hidden patterns within the DC SMG network, and their outputs are utilized by deep learning (DL) schemes for accurate attack detection. The proposed model incorporates a deep artificial neural network (ANN)-based encoder-decoder scheme to identify attacks in DC SMGs, contributing to an efficient operation. Additionally, DL-based LSTM-VAE and ANN are meticulously designed with appropriate hyperparameters to counter cyber threats. The data-driven DL method achieved the testing accuracy of 99.81%, outperforming various state-of-the-art (SOTA) DL and machine learning (ML) methods. Extensive testing scenarios have been conducted to demonstrate the performance and robustness of the proposed DL methods under different levels of attacks, ensuring their efficacy in enhancing the cybersecurity of DC shipboard microgrids. Zulfiqar Ali 0006, Tahir Hussain, Chun-Lien Su, Irfan Khan 0001, Anca Jurcut, Shao-Hang Tsao, Cho-Han Hu, Mahmoud Elsisi |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | AI on the Defensive and Offensive: Securing Multi-Environment Networks from AI AgentsabstractThe role of artificial intelligence (AI) in cybersecu-rity has grown due to increasing threats from malicious actors. It aids in threat detection, behavioral analysis, malware detection, phishing identification, and enhancing security measures. However, AI can also be weaponized for cyberattacks, as malicious actors use AI-based tools for sophisticated and adaptable assaults on security systems. This study contributes to cybersecurity by defending against AI-based threats. Machine learning models were trained on diverse, complex datasets to counter sophisticated AI-based attacks in multi-environments (M-En). We have utilized auto-encoders to generate our M-En dataset by combining two benchmark datasets: UNSW-NB15 and IoTID-20, that represent traditional IP-based and IoT-based traffic, respectively. Three generative models (CTGAN, CopulaGAN, and TVAE) produced AI-based traffic, leading to a dataset comprising traditional and AI-generated traffic. Machine learning and deep learning models were deployed on this M-En dataset. The ensemble Extra Trees classifier achieved the highest accuracy score of 0.983 for binary classification and 0.968 for multiclass problems. Our proposed approach demonstrates its effectiveness in countering AI-based traffic as well as traditional network traffic within the M-En networks. Furqan Rustam, Pasika Ranaweera, Anca Jurcut |
ICC | 3 |
| 2024 | Enhancing In-Vehicle Network Security Against AI-Generated Cyberattacks Using Machine LearningabstractCybersecurity poses a growing threat to technology infrastructure, especially raising concerns for automobile technology. Modern vehicles, reliant on connectivity, face a critical challenge in safeguarding their in-vehicle networks from cyber-attacks. Although the Controller Area Network is a standard for in-vehicle networks, its lack of security features exposes vehicles to vulnerabilities. Especially, the use of AI for offensive purposes further intensifies the threat to automotive technology infrastructure to protect it from cyber-attacks. This study proposes an approach to enhance in-vehicle network security, employing machine learning algorithms to protect against both AI-based generated attacks and traditional attacks. The Conditional Tabular Generative Adversarial Network (CTGAN) is utilized to generate in-vehicle network traffic, which is then combined with benchmark in-vehicle network traffic to create a complex and diverse scenario. The Random Forest model achieved a significant accuracy score for both benchmark in-vehicle network traffic and AI-based traffic, with scores of 0.93 and 0.89, respectively. Rahman Shafique, Furqan Rustam, Gyu Sang Choi, Anca Jurcut |
WCNC | 4 |
| 2024 | FAMTDS: A novel MFO-based fully automated malicious traffic detection system for multi-environment networksabstractMulti-environment networks, such as those in smart homes, handle both IoT and traditional IP-based traffic. Weak security protocols in IoT devices and the diverse traffic flow make these networks vulnerable to security breaches. This study delves into this pressing challenge and presents a pioneering solution—FAMTDS (Fully Automated Malicious Traffic Detection System)—designed explicitly for multi-environment networks. FAMTDS addresses the critical need for robust security measures by intelligently analyzing the amalgamation of IoT and IP-based traffic. FAMTDS comprises three pivotal stages: innovative multi-environment dataset creation, optimization of machine learning model hyperparameters, and holistic system optimization. For the multi-environment dataset, we amalgamate two prominent open-source datasets, UNSW-NB-15 and IoTID-20. Initially, crucial features are extracted from both datasets using an extra trees classifier. Subsequently, an equal number of features is generated by employing a neural network to harmonize these datasets. The resulting multi-environment dataset encompasses 19 distinct attack types, a comprehensive inclusion unprecedented in prior research on malicious traffic detection. This dataset exhibits diversity owing to its varied traffic samples, addressing a crucial gap in existing studies. To accommodate this diversity, machine learning models are deployed with fine-tuned hyperparameters. The Mouth Flame Optimizer streamlines feature extraction, feature generation, and hyperparameter tuning, automating the optimization process. FAMTDS demonstrates exceptional performance, achieving an accuracy score of 0.85 for the multi-environment dataset. We also integrated the CICDDOS2019 dataset with IoTID-20 in our multi-environment dataset, achieving a notable accuracy of 0.82 against recent attacks, thus enhancing our approach’s validation. To further validate the generalizability of our proposed approach, we applied it to zero-day attack prediction. Our method demonstrated an accuracy of 0.84 for zero-day attacks, indicating its effectiveness in detecting newly emerging threats in multi-environment networks. Furqan Rustam, Wajdi Aljedaani, Mahmoud Said Elsayed, Anca Jurcut |
Comput. Networks | 4 |
| 2024 | Malicious traffic detection in multi-environment networks using novel S-DATE and PSO-D-SEM approachesabstractThe rapid advancement of network architectures, protocols, and tools poses significant challenges to network security, especially due to the use of AI-based tools by cybercriminals. It is crucial to develop a versatile malicious traffic detection system capable of identifying attacks across diverse traffic types. This paper presents an enhanced system for detecting malicious traffic in multi-environment (M-En) networks, including IoT, SDN, and traditional IP-based traffic. Existing techniques often under-utilize diversity in network traffic, limiting their effectiveness. To address this, we propose a comprehensive approach that combines the power of Synthetic Data Augmentation TEchnique (S-DATE) and Particle Swarm Optimizer (PSO)-based Diverse-Self Ensemble Model (D-SEM). Our approach proposes the M-En dataset, a combination of three different network architectures datasets including InSDN, UNSWNB-15, and IoTID-20 that accurately represent real-world scenarios. S-DATE is then employed to address imbalanced data distribution in novel generated M-En dataset, enabling better model convergence and enhancing the detection rate of normal and abnormal traffic. Additionally, we introduce PSO-D-SEM, a novel ensemble model that leverages the diversity provided by PSO to handle the complexity of M-En networks. The PSO-D-SEM combines individual models trained on a subset of the M-En dataset, resulting in improved overall performance. The experimental results demonstrate the superiority of our enhanced system, achieving a significant accuracy score of 0.989. Further, we also deploy a statistical T-test to demonstrate the significance of the proposed PSO-D-SEM approach in comparison with state-of-the-art methods. Furqan Rustam, Anca Jurcut |
Comput. Secur. | 2 |
| 2024 | Fake news detection using enhanced features through text to image transformation with customized modelsabstractWith the large use of social media, the dissemination of intentionally altered and falsified information has become easy, thus posing negative effects on society. Detecting fake content is a non-trivial task as fake news has unique characteristics and challenges. Additionally, the wide use of artificial intelligence (AI) for fake content generation makes the detection of fake content further complicated. Fake news presents engineered content, making it difficult for traditional approaches to comprehend. Existing fake news detection approaches face four problems: lack of robustness, adaptability, limited or no use of auxiliary information, and inability to handle diversity. Fake content diversity introduces the models’ complexities and degrades their performance. Similarly, the accuracy of fake news detection approaches remains low for practical systems. This study focuses on detecting fake news by using an AI-based approach to obtain high accuracy and robustness by using the concept of text transformation into images. It transforms the text into a standard image format which enriches the feature space and boosts the performance of machine learning models. Extensive experiments using two different datasets involving binary and multi-class classification reveal that the proposed approach outperforms existing solutions by yielding superior accuracy. The use of AI approaches helps obtain higher accuracy of 99.70% and 92% for fake news detection using ISOT and LIAR datasets, respectively. Furqan Rustam, Wajdi Aljedaani, Anca Jurcut, Sultan Alfarhood, Mejdl S. Safran, Imran Ashraf 0003 |
Discov. Comput. | 3 |
| 2024 | An Evolutionary Game Theory-Based Cooperation Framework for Countering Privacy Inference AttacksabstractPrivacy inference poses a significant threat to users of online social networks (OSNs). To deal with this issue, a number of privacy-enhancing technologies have been proposed with the goal of achieving a balance between the protection of privacy and the utility of data. Previous studies, however, failed to take into consideration the impact of the interdependency of privacy (IoP), which dictates that privacy decisions made by some users may affect the privacy of some other users. The implication of IoP is that too much privacy may be disclosed when multiple individuals share data with the same data accessor because privacy conflicts resulting from independent privacy decisions would make it possible for adversaries to infer the privacy of the target user. Ideally, cooperation that preserves privacy should allow OSN users to respect each other’s privacy specifications so as to resolve such privacy conflicts caused by independent privacy decisions of individuals. To facilitate the design, we propose a privacy-preserving cooperation framework based on the evolutionary game theory to facilitate such cooperation. Based on the framework, the dynamics of user strategies regarding whether to participate in the cooperation are analyzed and an evolutionary stable state is derived to serve as the basis for incentivizing users to participate in cooperative privacy protection. Experiments based on real OSN data show that the proposed cooperation framework is effective in modeling the behaviors of users and that the proposed incentive allocation method can incentivize users to participate in the cooperation. The proposed cooperation framework can not only helps lower the threat to user privacy resulting from privacy inference by data accessors but also allows OSN service providers to design effective privacy protection policies. Yuzi Yi, Nafei Zhu, Jingsha He, Anca Jurcut, Xiangjun Ma, Yehong Luo |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | A Novel Authentication Protocol for 5G gNodeBs in Service Migration Scenarios of MECabstractEdge computing paradigms were an expedient innovation for elevating the contemporary standards of mobile and Internet networks. As specified in Multi-Access Edge Computing (MEC) standardization, edge computing serviceable infrastructures are running on virtualization technologies to provide dynamic and flexible service instances. Since the inception and operation of the services are executing at the edge level gNodeBs ($gNB$s), migration of services between$gNB$s is an imminent occurrence in edge computing that is contriving challenges to its feasible deployment. Security and service level latency requirements are vital parameters for such service migration operations conducted through$gNB$to$gNB$(g2g) connecting channels. In this paper, our focus is to ensure identity verification among the parties involved in a service migration through authentication and to secure the migrating content through a robust g2g channel establishment. Our proposed authentication protocol was designed in accordance with the MEC architectural standardization. We have verified the proposed protocol employing four different formal verification techniques: Scyther and AVISPA verification tools, GNY and ROR logical approaches. Further, we have developed the proposed protocol in a test-bed environment emulating the MEC system with an integrated 5 G Core network. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Securing Multi-Environment Networks using Versatile Synthetic Data Augmentation Technique and Machine Learning AlgorithmsabstractThe emergence of new network architectures, protocols, and tools has made it easier for cybercriminals to launch attacks using AI-based tools, presenting challenges in network security. To protect such systems, a versatile malicious traffic detection system is required that can identify attacks regardless of the type of traffic coming toward the network. In this paper, a system is proposed that can singly analyze multi-environment traffic (IoT and traditional IP-based) to detect malicious activity. The existing techniques for managing Multi-Environment traffic are inefficient due to the absence of AI utilization. To overcome these issues, the proposed approach generates a novel multienvironment traffic dataset by merging existing network datasets containing both traditional IP-based traffic and IoT network traffic. Synthetic Data Augmentation TEchnique (S-DATE) is also proposed to overcome the problem of imbalanced data distribution in the new multi-environment dataset. The results show that the utilization of S-DATE results in faster machine learning model convergence and an improvement in the detection rate of normal and abnormal traffic. The proposed approach achieves an impressive overall detection rate of 0.991 and is statistically significant compared to other state-of-the-art approaches. Furqan Rustam, Anca Jurcut, Wajdi Aljedaani, Imran Ashraf 0003 |
PST | 2 |
| 2023 | Blockchain-based privacy-preserving authentication protocol for UAV networks
Muhammad Arslan Akram, Hira Ahmad, Adnan Noor Mian, Anca Jurcut, Saru Kumari |
Comput. Networks | 4 |
| 2023 | A privacy-dependent condition-based privacy-preserving information sharing scheme in online social networks
Yuzi Yi, Nafei Zhu, Jingsha He, Anca Jurcut, Xiangjun Ma, Yehong Luo |
Comput. Commun. | 4 |
| 2023 | An Optimized Privacy Information Exchange Schema for Explainable AI Empowered WiMAX-based IoT networks
Premkumar Chithaluru, Jagjit Singh Dhatterwal, Ali Hassan Sodhro, Marwan Ali Albahar, Anca Jurcut, Ahmed Alkhayyat 0001 |
Future Gener. Comput. Syst. | 6 |
| 2023 | Novel Online Network Intrusion Detection System for Industrial IoT Based on OI-SVDD and AS-ELMabstractThe Industrial Internet of Things (IIoT) should be equipped with computational resources to detect network intrusions, types of attacks, and update their models automatically in real time. The most challenging aspect of machine learning (ML)-based network intrusion detection system (NIDS) design to secure IIoT is the continuous need for up-to-date definitions of attack data records. Moreover, the approaches employed by cyber attackers are in a dynamic state with changing trends and techniques. Hence, conventional signature-based NIDS are not suitable since they cannot update obsolete detection models. Anomaly-based NIDS that contains an online learning technique is adopted in our proposed method. Since IIoTs face resource-constrained problems, such as low memory, low computing capacity, and limited energy supply, it is very challenging to implement the exiting general-purpose anomaly-based NIDS. This article proposes a lightweight NIDS based on an online incremental support vector data description (OI-SVDD) anomaly detection system on the IIoT devices and an adaptive sequential extreme learning machine (AS-ELM) on the multiaccess edge computing (MEC) server. Additionally, we utilize the MEC server, which provides computational resources to execute the AS-ELM model at the network’s edge. To avoid data saturation in the proposed model, we apply data filtering using the rate of convergence (ROC). We evaluated the proposed NIDS through experiments using two data sets, such as UNSW-NB15 (public data set) and our self-generated data set. Our results show that the proposed OI-SVDD and AS-ELM perform effectively and detect network intrusion in a realistic IIoT environment. Eric Gyamfi, Anca Jurcut |
IEEE Internet Things J. | 2 |
| 2023 | Malware detection using image representation of malware data and transfer learning
Furqan Rustam, Imran Ashraf 0003, Anca Jurcut, Ali Kashif Bashir, Yousaf Bin Zikria |
J. Parallel Distributed Comput. | 3 |
| 2023 | Methodology for Detecting Cyber Intrusions in e-Learning Systems during COVID-19 Pandemic
Ivan Cvitic, Dragan Perakovic, Marko Perisa, Anca Jurcut |
Mob. Networks Appl. | 4 |
| 2023 | Correction to: Methodology for Detecting Cyber Intrusions in e-Learning Systems during COVID-19 Pandemic
Ivan Cvitic, Dragan Perakovic, Marko Perisa, Anca Jurcut |
Mob. Networks Appl. | 4 |
| 2023 | An Adaptive Network Security System for IoT-Enabled Maritime TransportationabstractWith the rapid growth of the Internet of Things (IoT) applications in Maritime Transportation Systems (MTS), cyber-attacks and challenges in data safety have also increased extensively. Meanwhile, the IoT devices are resource-constrained and cannot implement the existing security systems, making them susceptible to various types of debilitating cyber-attacks. The dynamics in the attack processes in IoT-enabled MTS networks keep changing, which makes a traditional offline or batch ML-based attack detection systems intractable to apply. This paper provides a novel approach of using an adaptive incremental passive-aggressive machine learning (AI-PAML) method to create a network attack detection system (NADS) to protect the IoT devices in an MTS environment. In this paper, we propose an NADS that utilizes a multi-access edge computing (MEC) platform to provide computational resources to execute the proposed model at a network end. Since online learning models face data saturation problems, we present an improved approximate linear dependence and a modified hybrid forgetting mechanism to filter the inefficient data and keep the detection model up-to-date. The proposed data filtering ensures that the model does not experience a rapid increase in unwarranted data, which affects the model's attack detection rate. A Markov transition probability is applied to control the MEC selection and data offloading process by the IoT devices. The performance of the NADS is verified using selected benchmark datasets and a realistic IoT environment. Experimental results demonstrate that AI-PAML achieves remarkable performance in the NADS design for an MTS environment. Eric Gyamfi, James Adu Ansere, Mohsin Kamal, Muhammad Tariq 0001, Anca Jurcut |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Service Migration Authentication Protocol for MECabstractMulti-Access Edge Computing (MEC) is a novel edge computing paradigm that enhances the access level capacity of mobile networks by shifting the serviceable Data center infrastructure proximate to the end devices. With this proximate placement and service provisioning, migration of a service from one edge enabled gNodeB (gNB) to another is intrinsic to maintain the service continuity. Since such services are migrated through the channel shared between the gNBs, proper security measures should be inhibited by the communication protocol to prevent any unauthorized interception. Further, each gNB should ensure the legitimacy of the migrating gNBs to avoid any impersonation attempts. As this is an area that lacks focus in current research trends, this paper introduces MEC Service Migration Authentication Protocol (MEC-SMAP), a protocol that take place prior to the migration initiation, and specifically defined for MEC. The proposed protocol ensures the secure transfer of session key generation parameters to form a secure channel while ensuring perfect forward secrecy. It introduces an identity verification mechanism through a trusted third party service. We have validated the proposed protocol through formal analysis using GNY logic and Scyther tool. Further, a prototype virtualized MEC environment was created to evaluate its feasibility and the impact of the employed security mechanisms. Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut |
GLOBECOM | 4 |
| 2022 | A comparative study on online machine learning techniques for network traffic streams analysisabstractModern networks generate a massive amount of traffic data streams. Analyzing this data is essential for various purposes, such as network resources management and cyber-security analysis. There is an urgent need for data analytic methods that can perform network data processing in an online manner based on the arrival of new data. Online machine learning (OL) techniques promise to support such type of data analytics. In this paper, we investigate and compare the OL techniques that facilitate data stream analytics in the networking domain. We also investigate the importance of traffic data analytics and highlight the advantages of online learning in this regard, as well as the challenges associated with OL-based network traffic stream analysis, e.g., concept drift and the imbalanced classes. We review the data stream processing tools and frameworks that can be used to process such data online or on-the-fly along with their pros and cons, and their integrability with de facto data processing frameworks. To explore the performance of OL techniques, we conduct an empirical evaluation on the performance of different ensemble- and tree-based algorithms for network traffic classification. Finally, the open issues and the future directions in analyzing traffic data streams are presented. This technical study presents valuable insights and outlook for the network research community when dealing with the requirements and purposes of online data streams analytics and learning in the networking domain. Amin Shahraki, Mahmoud Abbasi, Amirhosein Taherkordi, Anca Jurcut |
Comput. Networks | 4 |
| 2022 | Toward pragmatic modeling of privacy information propagation in online social networks
Yuzi Yi, Nafei Zhu, Jingsha He, Anca Jurcut, Bin Zhao 0005 |
Comput. Networks | 4 |
| 2021 | A Hybrid CNN-LSTM Based Approach for Anomaly Detection Systems in SDNsabstractSoftware-Defined Networking (SDN) is a promising technology for the future Internet. However, the SDN paradigm introduces new attack vectors that do not exist in the conventional distributed networks. This paper develops a hybrid Intrusion Detection System (IDS) by combining the Convolutional Neural Network (CNN) and Long Short-Term Memory Network (LSTM). The proposed model is capable of capturing the spatial and temporal features of the network traffic. Two regularization techniques i.e., L2 Regularization () and dropout method are used to overcome with the overfitting problem. The proposed method improves the intrusion detection performance of zero-day attacks. The InSDN dataset — the most recent dataset for SDN networks is used to test and evaluate the performance of the proposed model. The results indicate that integrating the CNN with LSTM improves the intrusion detection performance and achieves an accuracy of 96.32%. The estimated accuracy is higher than the accuracy of each individual model. In addition, it is established that the regularization techniques improves the performance of the CNN algorithms in detecting new intrusions when compared to the standard CNN. The findings of this study facilitates the development of robust IDS systems for SDN environment. Mahmoud Abdallah, Nhien-An Le-Khac, Hamed Z. Jahromi, Anca Jurcut |
ARES | 4 |
| 2021 | A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization techniqueabstractSoftware-defined networking (SDN) is a new networking paradigm that separates the controller from the network devices i.e. routers and switches. The centralized architecture of the SDN facilitates the overall network management and addresses the requirement of current data centers. While there are high benefits offered by the SDN architecture, the risk of new attacks is a critical problem and can prevent the wide adoption of SDNs. The SDN controller is a crucial element, and it is an attractive target for the intruders. In case the attacker successfully accessed the SDN controller, it can route the traffic based on its own requirements, causing severe damage to the entire network. The network intrusion detection systems (NIDSs) are important tools to detect and secure the network environment from malicious activities and anomalous attacks. Deep Learning (DL) has recently shown desirable results in a variety of problems, such as text, speech, and image applications, etc. While several related works deployed DL for NIDSs, most of these approaches ignore the influence of the overfitting problem during the implementation of DL algorithms. As a result, it can impact the robustness of the anomaly detection system and lead to poor model performance for zero-day attacks. In this work, we propose a new hybrid DL approach based on the convolutional neural network (CNN) to classify the flow traffic into normal or attack classes. A new regularizer method, namely SD-Reg, which is based on the standard deviation of the weight matrix, has been used to address the problem of overfitting and to improve the capability of NIDSs in detection of unseen intrusion events. The evaluation results indicate that the SD-Reg outperforms the previous regularizer methods. In addition, the proposed hybrid technique gives a higher performance in all the evaluation metrics compared to the single DL models. Several datasets, including the InSDN – the most recent dataset for SDN – are used to train and evaluate the performance of all techniques. Furthermore, we suggest a lightweight NIDS by training the CNN-based models using a less number of features without causing a significant drop in the model performance. Mahmoud Said Elsayed, Nhien-An Le-Khac, Marwan Ali Albahar, Anca Jurcut |
J. Netw. Comput. Appl. | 4 |
| 2020 | Security as a Service Platform Leveraging Multi-Access Edge Computing Infrastructure ProvisionsabstractThe mobile service platform envisaged by emerging IoT and 5G is guaranteeing gigabit-level bandwidth, ultra-low latency and ultra-high storage capacity for their subscribers. In spite of the variety of applications plausible with the envisaged technologies, security is a demanding objective that should be applied beyond the design stages. Thus, Security as a Service (SECaaS) is an initiative for a service model that enable mobile and IoT consumers with diverse security functions such as Intrusion Detection and Prevention (IDPaaS), Authentication (AaaS), and Secure Transmission Channel (STCaaS) as a Service. A well-equipped edge computing infrastructure is intrinsic to achieve this goal. The emerging Multi-Access Edge Computing (MEC) paradigm standardized by the ETSI is excelling among other edge computing flavours due to its well-defined structure and protocols. Thus, in our directive, we intend to utilize MEC as the edge computing platform to launch the SECaaS functions. Though, the actual development of a MEC infrastructure is highly dependent on the integration of virtualization technologies to enable dynamic creation, the deployment, and the detachment of virtualized entities that should feature interoperability to cater the heterogeneous IoT devices and services. To that extent, this work is proposing a security service architecture that offers these SECaaS services. Further, we validate our proposed architecture through the development of a virtualized infrastructure that integrates lightweight and hypervisor-based virtualization technologies. Our experiments prove the plausibility of launching multiple security instances on the developed prototype edge platform. Pasika Ranaweera, Vashish N. Imrith, Madhusanka Liyanage, Anca Jurcut |
ICC | 4 |
| 2020 | Detecting Abnormal Traffic in Large-Scale NetworksabstractWith the rapid technological advancements, organizations need to rapidly scale up their information technology (IT) infrastructure viz. hardware, software, and services, at a low cost. However, the dynamic growth in the network services and applications creates security vulnerabilities and new risks that can be exploited by various attacks. For example, User to Root (U2R) and Remote to Local (R2L) attack categories can cause a significant damage and paralyze the entire network system. Such attacks are not easy to detect due to the high degree of similarity to normal traffic. While network anomaly detection systems are being widely used to classify and detect malicious traffic, there are many challenges to discover and identify the minority attacks in imbalanced datasets. In this paper, we provide a detailed and systematic analysis of the existing Machine Learning (ML) approaches that can tackle most of these attacks. Furthermore, we propose a Deep Learning (DL) based framework using Long Short Term Memory (LSTM) autoencoder that can accurately detect malicious traffics in network traffic. We perform our experiments in a publicly available dataset of Intrusion Detection Systems (IDSs). We obtain a significant improvement in attack detection, as compared to other benchmarking methods. Hence, our method provides great confidence in securing these networks from malicious traffic. Mahmoud Said Elsayed, Nhien-An Le-Khac, Soumyabrata Dev, Anca Jurcut |
ISNCC | 4 |
| 2020 | DDoSNet: A Deep-Learning Model for Detecting Network AttacksabstractSoftware-Defined Networking (SDN) is an emerging paradigm, which evolved in recent years to address the weaknesses in traditional networks. The significant feature of the SDN, which is achieved by disassociating the control plane from the data plane, facilitates network management and allows the network to be efficiently programmable. However, the new architecture can be susceptible to several attacks that lead to resource exhaustion and prevent the SDN controller from supporting legitimate users. One of these attacks, which nowadays is growing significantly, is the Distributed Denial of Service (DDoS) attack. DDoS attack has a high impact on crashing the network resources, making the target servers unable to support the valid users. The current methods deploy Machine Learning (ML) for intrusion detection against DDoS attacks in the SDN network using the standard datasets. However, these methods suffer several drawbacks, and the used datasets do not contain the most recent attack patterns - hence, lacking in attack diversity. In this paper, we propose DDoSNet, an intrusion detection system against DDoS attacks in SDN environments. Our method is based on Deep Learning (DL) technique, combining the Recurrent Neural Network (RNN) with autoencoder. We evaluate our model using the newly released dataset CICDDoS2019, which contains a comprehensive variety of DDoS attacks and addresses the gaps of the existing current datasets. We obtain a significant improvement in attack detection, as compared to other benchmarking methods. Hence, our model provides great confidence in securing these networks. Mahmoud Said Elsayed, Nhien-An Le-Khac, Soumyabrata Dev, Anca Jurcut |
WoWMoM | 4 |
| 2019 | A Novel Security Protocol Attack Detection Logic with Unique Fault Discovery Capability for Freshness Attacks and Interleaving Session AttacksabstractThis paper introduces a new logic-based technique for detecting security protocol weaknesses that are exploitable by freshness and interleaving session attacks. This technique is realised as a special purpose logic to be used throughout the protocol design stage, where a draft of the protocol is subjected to formal analysis prior to its publication or deployment. For any detected failures the analysis also reveals their cause, facilitating design corrections. The proposed Attack Detection Logic is introduced and its details, including the language, predicates, axioms, rules, semantics as well as soundness and completeness are presented. The effectiveness of the logic is evaluated in a case study, where it is demonstrated how to use the Attack Detection Logic as part of the design process of security protocols. Further, the logic is applied to a range of security protocols, including protocols with known weaknesses and protocols that are known to be secure. The logic's ability to detect various attacks is established by demonstrating that for protocols with known weaknesses, at least one detection rule is activated and no detection rule is activated for protocols without weaknesses. This case study confirms the logic's ability to detect design weaknesses exploitable by freshness and interleaving session attacks. Anca Jurcut, Tom Coffey, Reiner Dojen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | On the security verification of a short message service protocolabstractShort Message Service (SMS) is a text messaging service component of smart phones, web, or mobile communication systems which requires a high level of security to provide user authentication and data confidentiality. To provide such security features, a high security communication protocol for SMS, called Message Security Communication Protocol (MSCP) was proposed. In this paper, MSCP is formally analyzed using an automated logic-based verification tool with attack detection capabilities. The performed formal verification reveals that the proposed protocol is susceptible to parallel session and denial-of-service (DoS) attacks. The reasoning why these attacks are possible is detailed and an amended protocol is proposed to counter the identified attacks. Formal verification of the amended protocol provides confidence regarding the correctness and effectiveness of the proposed modifications. Anca Jurcut, Madhusanka Liyanage, Cornelia Györödi, Jingsha He |
WCNC | 1 |
| 2017 | Secure communication channel architecture for Software Defined Mobile Networks
Madhusanka Liyanage, An Braeken, Anca Jurcut, Mika Ylianttila, Andrei V. Gurtov |
Comput. Networks | 3 |
| 2014 | Design requirements to counter parallel session attacks in security protocolsabstractThis work is concerned with the possible exploitation of weaknesses in security protocols by attackers using parallel session attacks and discovering ways of eliminating these weaknesses. A new analysis is presented on the reasons why security protocols, with certain weaknesses in their design, are vulnerable to parallel session attacks. Building on this analysis a new set of design requirements is proposed, whose aim is to eliminate these vulnerabilities. The proposed set of design requirements is evaluated by applying them to a range of security protocols with known weaknesses as well as protocols known to be free of these weaknesses. The results of the evaluation indicate that the set of design requirements are effective as: protocols with known weaknesses violate some of the rules, while protocols without weaknesses do not violate any of the rules. Anca Jurcut, Tom Coffey, Reiner Dojen |
PST | 1 |
| 2014 | Design guidelines for security protocols to prevent replay & parallel session attacks
Anca Jurcut, Tom Coffey, Reiner Dojen |
Comput. Secur. | 1 |
| 2012 | Symmetry in Security Protocol Cryptographic Messages - A Serious Weakness Exploitable by Parallel Session AttacksabstractThis paper is concerned with detection and prevention of weaknesses in the design of security protocols. These weaknesses can be exploited by an attacker mounting attacks that compromise the security of the protocol. A novel theory defining weaknesses caused by the symmetry of cryptographic messages in protocols is introduced. This theory incorporates new rules describing the cases when the symmetry of messages has a structural weakness that is exploitable by parallel session attacks. Further, the rationale behind the Symmetry rules is presented and the structures of detected generic attacks for each rule are provided. Additionally, the Symmetry rules are applied to a protocol that is vulnerable to a parallel session attack. It is demonstrated that the proposed theory successfully detects the weaknesses caused by the symmetry of protocol messages, which lead to parallel session attacks. Anca Jurcut, Tom Coffey, Reiner Dojen |
ARES | 1 |
| 2008 | Determining a parallel session attack on a key distribution protocol using a model checkerabstractThe use of security protocols to protect sensitive information is critical. However, flaws in the design of security protocols can make them ineffective. This paper discusses various attacks against security protocols that exploit weaknesses in their design and a key-distribution protocol is analysed using a model checker. The analysis reveals weaknesses in the protocol, which can be exploited in a parallel session attack that allows an attacker to impersonate a legitimate principal. Correction to the protocol are proposed and a formal analysis of the fix is presented. The results of this analysis provide confidence in the correctness and effectiveness of the proposed corrected protocol. Vladimir Pasca, Anca Jurcut, Reiner Dojen, Tom Coffey |
MoMM | 2 |