Md. Mahmud Hossain

dblp:164/3720 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
5since 2021 · last 2022
0000-0002-4102-8056ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSecurity and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2022 BenchAV: A Security Benchmarking Framework for Autonomous Driving
abstract
Autonomous vehicles (AVs) are capable of making driving decisions autonomously using multiple sensors and a complex autonomous driving (AD) software. However, AVs introduce numerous unique security challenges that have the potential to create safety consequences on the road. Security mechanisms require a benchmark suite and an evaluation framework to generate comparable results. Unfortunately, AVs lack a proper benchmarking framework to evaluate the attack and defense mechanisms and quantify the safety measures. This paper introduces BenchAV – a security benchmark suite and evaluation framework for AVs to address current limitations and pressing challenges of AD security. The benchmark suite contains 12 security and performance metrics, and an evaluation framework that automates the metric collection process using Carla simulator and Robot Operating System (ROS).
Mohammad Aminul Hoque, Md. Mahmud Hossain, Ragib Hasan
CCNC2
2022 IoTaaS: Drone-Based Internet of Things as a Service Framework for Smart Cities
abstract
The Internet of Things (IoT) offers new services in the context of smart cities through digital devices embedded with sensing, computation, and communication capabilities. The IoT devices enhance the smart city vision by employing advanced communication and computation technologies for smart city administrations. The IoT-based smart city applications require many IoT devices and gateways to be deployed at different city points. Heterogeneous sensing devices, placing smart devices in a constrained or physically inaccessible area, and large urban areas to monitor together make IoT node deployment and sensing management tasks difficult, time-consuming, and expensive. Additionally, certain tasks may require smart devices to be deployed for a very short period of time to sense and report contextual information, making it economically infeasible to purchase the devices. In this regard, we propose a drone-based IoT as a Service (IoTaaS) framework that enables the dynamic provisioning or deployment of IoT devices using drones. IoTaaS allows IoT devices and gateways to be mounted on drones and provides a distributed cloud service by placing the IoT devices in an area according to the requirements specified by a user. We also provide an economic analysis for operating such drone-based IoT services. A proof-of-concept implementation of IoTaaS for smart agriculture and air pollution monitoring applications shows that IoTaaS can reduce setup costs and increase the usage of IoT devices.
Mohammad Aminul Hoque, Md. Mahmud Hossain, Shahid Al Noor, S. M. Riazul Islam, Ragib Hasan
IEEE Internet Things J.2
2022 CATComp: A Compression-Aware Authorization Protocol for Resource-Efficient Communications in IoT Networks
abstract
The Internet of Things (IoT) devices exchange certificates and authorization tokens over the IEEE 802.15.4 radio medium that supports a maximum transmission unit (MTU) of 127 bytes. However, these credentials are significantly larger than the MTU and are, therefore, sent in a large number of fragments. As IoT devices are resource constrained and battery powered, there are considerable computations and communication overheads for fragment processing both on the sender and receiver devices, which limit their ability to serve real-time requests. Moreover, the fragment processing operations increase energy consumption by CPUs and radio transceivers, which results in shorter battery life. In this article, we propose CATComp—a compression-aware authorization protocol for constrained application protocol (CoAP) and datagram transport layer security (DTLS) that enables IoT devices to exchange small-sized certificates and capability tokens over the IEEE 802.15.4 media. CATComp introduces additional messages in the CoAP and DTLS handshakes that allow communicating devices to negotiate a compression method, which devices use to reduce the credentials’ sizes before sending them over an IEEE 802.15.4 link. The decrease in the size of the security materials minimizes the total number of packet fragments, communication overheads for fragment delivery, fragment processing delays, and energy consumption. As such, devices can respond to requests faster and have longer battery life. We implement a prototype of CATComp on Contiki-enabled RE-Mote IoT devices and provide a performance analysis of CATComp. The experimental results show that communication latency and energy consumption are reduced when CATComp is integrated with CoAP and DTLS.
Md. Mahmud Hossain, Golam Kayas, Yasser Karim, Ragib Hasan, Jamie Payton, S. M. Riazul Islam
IEEE Internet Things J.1
2021 P-HIP: A Lightweight and Privacy-Aware Host Identity Protocol for Internet of Things
abstract
The host identity protocol (HIP) has emerged as the most suitable solution to uniquely identify smart devices in the mobile and distributed Internet-of-Things (IoT) systems, such as smart cities, homes, cars, and healthcare. The HIP provides authentication methods that enable secure communications between HIP peers. However, the authentication methods provided by the HIP cannot be adopted by the IoT devices with limited processing power because of the computation-intensive cryptographic operations involved in hash generation, signature validation, and session-key establishment. Moreover, IoT devices cannot utilize the HIP as is to communicate securely in the low power and lossy networks as there is a considerable communication overhead, such as packet fragmentation and reassembly, for exchanging certificates over a lossy link. Additionally, the use of static host identifiers makes IoT devices vulnerable to cyber espionage and user-targeted attacks. In this article, we propose an authentication scheme, P-HIP, that protects the identity privacy of an IoT device by enabling the device to compute and use unique host identifiers from networks to networks and sessions to sessions. To make the HIP suitable for resource-constrained IoT devices, P-HIP provides methods that unburden IoT devices from computation-intensive operations, such as modular exponentiation, involved in authentication and session-key exchange. Additionally, P-HIP minimizes the communication overheads for exchanging certificates in lossy networks. We implement a prototype of P-HIP on Contiki-enabled IoT that shows P-HIP can reduce computation costs, communication overheads, and the session-key establishment time when used by low-powered devices in a lossy network.
Md. Mahmud Hossain, Ragib Hasan
IEEE Internet Things J.1
2021 SUPnP: Secure Access and Service Registration for UPnP-Enabled Internet of Things
abstract
The service-oriented nature of the Universal Plug-and-Play (UPnP) protocol supports the creation of flexible, open, and dynamic systems. As such, it is widely used in Internet-of-Things (IoT) deployments. However, the protocol’s service access mechanism does not consider security from the first principles and is therefore vulnerable to various attacks. In this article, we present an in-depth analysis of the service advertisement, discovery, and access methods of the UPnP protocol stack and identify security issues in an IoT network. Our analysis shows that adversaries can perform resource exhaustion, buffer overflow, reflection, and amplification attacks by exploiting the vulnerabilities of the UPnP protocol. To address these issues, we propose a capability-based security model for UPnP to ensure secure discovery, advertisement, and access of the UPnP services that considers the resource limitations of IoT devices. Our analysis shows the effectiveness of the proposed model against potential attacks, and our experimental evaluation highlights the feasibility of implementing our Secure UPnP (SUPnP) protocol in a network of IoT devices, incurring minimal network and performance overhead.
Golam Kayas, Md. Mahmud Hossain, Jamie Payton, S. M. Riazul Islam
IEEE Internet Things J.2
2018 SecuPAN: A Security Scheme to Mitigate Fragmentation-Based Network Attacks in 6LoWPAN
abstract
6LoWPAN is a widely used protocol for communication over IPV6 Low-power Wireless Personal Area Networks. Unfortunately, the 6LoWPAN packet fragmentation mechanism possesses vulnerabilities that adversaries can exploit to perform network attacks. Lack of fragment authentication, payload integrity verification, and sender IP address validation lead to fabrication, duplication, and impersonation attacks. Moreover, adversaries can abuse the poor reassembly buffer management technique of the 6LoWPAN layer to perform buffer exhaustion and selective forwarding attacks. In this paper, we propose SecuPAN - a security scheme for mitigating fragmentation-based network attacks in 6LoWPAN networks and devices. We propose a Message Authentication Code based per-fragment integrity and authenticity verification scheme to defend against fabrication and duplication attacks. We also present a mechanism for computing datagram-tag and IPv6 address cryptographically to mitigate impersonation attacks. Additionally, our reputation-based buffer management scheme protects 6LoWPAN devices from buffer reservation attacks. We provide an extensive security analysis of SecuPAN to demonstrate that SecuPAN is secure against strong adversarial scenarios. We also implemented a prototype of SecuPAN on Contiki enabled IoT devices and provided a performance analysis of our proposed scheme.
Md. Mahmud Hossain, Yasser Karim, Ragib Hasan
CODASPY1
2018 Aura: An incentive-driven ad-hoc IoT cloud framework for proximal mobile computation offloading
Ragib Hasan, Md. Mahmud Hossain, Rasib Khan
Future Gener. Comput. Syst.2
2018 An Internet of Things-based health prescription assistant and its security system design
Md. Mahmud Hossain, S. M. Riazul Islam, Farman Ali 0001, Kyung Sup Kwak, Ragib Hasan
Future Gener. Comput. Syst.1
2016 Jugo: A Generic Architecture for Composite Cloud as a Service
abstract
Cloud computing has become the industry standard for rapid application deployment, scalable server support, mobile and distributed services, and it provides access to (theoretically) infinite resources. Unfortunately, researchers are still trying to converge towards cross-provider cloud computing frameworks to enable compatibility and seamless resource transition between cloud providers. Moreover, users are restricted to using the provider-specific pre-configured options of resources and services, irrespective of their current needs. At the same time, cloud services are provided as a direct service from the providers to the clients. This creates a segregated cloud market clientele, and non-negotiable pricing strategies for the cloud services. In this paper, we propose Jugo, a generic architecture for cloud composition and negotiated service delivery for cloud users. Jugo acts as a match-maker for service specifications from the users with the currently available assets from the cloud providers. The engagement of a middle-man as an opaque cloud service provider will create a better opportunity for cloud users to find cheaper deals, price-matching, and flexible resource specifications, with increased revenue and higher resource utilization for the cloud service providers.
Md. Mahmud Hossain, Rasib Khan, Shahid Al Noor, Ragib Hasan
CLOUD1
2016 Litigo: A Cost-Driven Model for Opaque Cloud Services
abstract
Cloud computing provides software, platform, and infrastructure as a service that helps organizations to perform several resource intensive tasks. The services offered by a cloud service provider are limited by provider-specific options in terms of the pre-specified configurations. Moreover, it is sometimes expensive to pay a fixed amount of money without any format of negotiation or price-matching deals for the cloud-based services and resources. Conversely, the negotiator-based model for opaque services has gained popularity in various markets, such as, for flights, hotels, and rentals. We posit that a similar opaque inventory for cloud-based services and resources is the next generation niche for consumer acquisition and service delivery in the cloud computing market. Such a model will facilitate the clients with flexible resource and service provisioning at reasonable prices, and will also allow a higher revenue and increase resource utilization for cloud service providers. In this paper, we propose Litigo, a cost-driven model for opaque service platforms for cloud computing. The Litigo component acts as a middle-man to deliver cloud-based services from a set of cloud service providers to the end users. We present a detailed cost model and comparison between establishing a cloud service vs. an opaque cloud service. Our empirical framework allows a Litigo service provider to analyze the profit model and creates the market niche accordingly. We performed extensive analysis using simulated model verification for Litigo. The proposed model delivers an opaque cloud as a service to clients at a reasonable price by maximizing the resource utilization and revenue of cloud service providers.
Shahid Al Noor, Rasib Khan, Md. Mahmud Hossain, Ragib Hasan
CLOUD3
2015 Towards an Analysis of Security Issues, Challenges, and Open Problems in the Internet of Things
abstract
The Internet of Things (IoT) devices have become popular in diverse domains such as e-Health, e-Home, e-Commerce, and e-Trafficking, etc. With increased deployment of IoT devices in the real world, they can be, and in some cases, already are subject to malicious attacks to compromise the security and privacy of the IoT devices. While a number of researchers have explored such security challenges and open problems in IoT, there is an unfortunate lack of a systematic study of the security challenges in the IoT landscape. In this paper, we aim at bridging this gap by conducting a thorough analysis of IoT security challenges and problems. We present a detailed analysis of IoT attack surfaces, threat models, security issues, requirements, forensics, and challenges. We also provide a set of open problems in IoT security and privacy to guide the attention of researchers into solving the most critical problems.
Md. Mahmud Hossain, Maziar Fotouhi, Ragib Hasan
SERVICES1