VLDB 2026 Research / reviewers in the wild / expert
Rishikesh Sahay
dblp:15/9554
· DBLP profile ↗
8ranked-venue papers
6as first author
3since 2021 · last 2024
0000-0002-0380-8289ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 first-author · 1 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Comparative Analysis of Phishing Tools: Features and Countermeasures
Rishikesh Sahay, Weizhi Meng 0001, Wenjuan Li 0001 |
ISPEC | 1 |
| 2023 | A comparative risk analysis on CyberShip system with STPA-Sec, STRIDE and CORASabstractThe widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. Understanding the nature of cyber threats and their potential risks and impact is essential to improve the security and resilience of cyber systems, and to build systems that are secure by design and better prepared to detect and mitigate cyber attacks. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with each methodology and relevant differences. Moreover, STPA-Sec, which is a variant of the STPA, is widely used for safety and security analysis of cyber physical systems (CPS); CORAS offers a framework to perform cyber risk assessment in a top-down approach that aligns with STPA-Sec; and STRIDE (Spoofing, Tampering, Repudiation,Information disclosure, Denial of Service, Elevation of Privilege) considers threat at the component level as well as during the interaction that is similar to STPA-Sec. As a result of this analysis, this paper highlights the pros and cons of these methodologies, illustrates areas of special applicability, and suggests that their complementary use as threats identified through STRIDE can be used as an input to CORAS and STPA-Sec to make these methods more structured. Rishikesh Sahay, Daniel A. Sepulveda Estay, Weizhi Meng 0001, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Comput. Secur. | 1 |
| 2021 | Corrigendum to "CyberShip-IoT: A Dynamic and Adaptive SDN-Based Security Policy Enforcement Framework for Ships" [Future Gener. Comput. Syst. 100 (2019) 736-750]
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 1 |
| 2020 | A systematic review of cyber-resilience assessment frameworks
Daniel A. Sepulveda Estay, Rishikesh Sahay, Michael Bruhn Barfod, Christian Damsgaard Jensen |
Comput. Secur. | 2 |
| 2019 | CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 1 |
| 2019 | The application of Software Defined Networking on securing computer networks: A survey
Rishikesh Sahay, Weizhi Meng 0001, Christian Damsgaard Jensen |
J. Netw. Comput. Appl. | 1 |
| 2017 | ArOMA: An SDN based autonomic DDoS mitigation framework
Rishikesh Sahay, Gregory Blanc, Zonghua Zhang, Hervé Debar |
Comput. Secur. | 1 |
| 2015 | Coloring networks for attacker identification and responseabstractAbstract Network‐based attacks such as denial‐of‐service attacks are usually performed by spoofing the source IP address. Packet marking techniques are used to trace such attackers as close as possible to their source. A packet mark consists of some traceback information pertaining to a router being embedded in the IP packet header. In this work, we use the concept of star coloring to assign reusable colors (marks) to routers but at the same time limits false positives and false negatives. The proposed scheme minimizes the bit space required for marking in the IP header. We introduce the concept ofpath identifier, to identify an attack path. Thepath identifiersare used to provide an elegant solution to collect attack packets in the midst of a distributed denial‐of‐service attack and then traceback. Although identifying the attacker is crucial to institute protection measures against future attacks, it cannot mitigate the effects of an ongoing attack. We establish the use ofpath identifiers, to filter packets during an ongoing attack. We present a validation of the proposed techniques in an emulated environment using real attack traffic. Copyright © 2014 John Wiley & Sons, Ltd. Ashok Singh Sairam, Sangita Roy, Rishikesh Sahay |
Secur. Commun. Networks | 3 |