Mayank Swarnkar

dblp:177/2115 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-7351-0341ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 1 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 LeakyDroid: A lightweight method for detecting zero-day leaky Android applications using One-Class Graph Neural Networks
abstract
In the current era of mobile technology, ensuring user data security and privacy is very important, particularly with the rise of malicious Android applications that aim to leak end-user data. Moreover, the popularity of the Android OS is resulting in growing numbers of such malicious Android applications. Hackers make the apps malicious by downloading the source code of Android applications and modifying it. Static analysis techniques have traditionally been used to detect such leaky Android applications. However, these methods cannot simulate runtime behaviours, leading to false positives or negatives. Moreover, obfuscated code is also harder to analyse using this technique. On the other hand, dynamic analysis-based methods are used to overcome these issues because they capture the application’s actual behaviour during runtime. However, dynamic analysis methods have high computational complexity. To fill this gap, we propose LeakyDroid , a static but lightweight method for detecting zero-day leaky Android applications using one-class graph neural networks. LeakyDroid distinguishes between the zero-day malicious and genuine versions of Android applications based on function calls inside various class files of the installable APK files. LeakyDroid generates a control flow graph from function calls from several versions of normal APK files of the same application. The graph is trained using OCGNN, which effectively captures relationships and invocation patterns of normal APK files. While testing an unknown version of the same application’s APK, if a considerable deviation is seen from normal behaviour, the application is detected as malicious. We evaluated the performance of LeakyDroid on three applications, namely WhatsApp, Netflix, and Instagram, each with approximately 25 benign and a few malicious and leaky versions. LeakyDroid successfully detected all the malicious versions of APK with no false positives.
Neha Sharma 0007, Mayank Swarnkar, Shaan Kumar
J. Inf. Secur. Appl.2
2025 QuIDS: A Quantum Support Vector machine-based Intrusion Detection System for IoT networks
Mayank Swarnkar
J. Netw. Comput. Appl.2
2025 DLAZE: Detecting DNS Tunnels Using Lightweight and Accurate Method for Zero-Day Exploits
abstract
Domain Name System (DNS) protocol is highly targeted nowadays for creating tunnels and extracting information from the intended machines. The reason for such exploitation is that DNS is passed unchecked by most firewalls and Intrusion Detection Systems (IDSs) to maintain the network’s quality of service. Most detection methods utilize the signatures of tunneled queries and tools for DNS tunnel detection. However, the new or updated tool versions bypass these signature-based methods. Moreover, DNS generally comprises a significant portion of total network traffic with a skewed distribution of legitimate DNS traffic against DNS tunnels. Thus, checking each DNS packet against signatures is a bottleneck to the efficiency of the network. To resolve this problem, we propose DLAZE, which can efficiently detect known and unknown DNS tunnels in the network traffic without compromising the efficiency of the network. DLAZE consists of a three-layer system. The first layer utilizes our already proposed work OptiTuneD, which filters out nearly all legitimate DNS packets with linear time complexity and solves the problem of the skewed distribution of legitimate vs tunneled DNS. The remaining packets are passed to the second layer, which uses the Bidirectional Encoder Representations from Transformers (BERT) model to identify legitimate DNS packets that remained unidentified at the first layer with the quadratic time complexity. The third layer obtains only unknown or zero-day DNS packets that can be legitimate or tunnels, which are differentiated using the Probing method with constant time complexity. We tested DLAZE using three publicly available datasets. The experimental results show that the average recall, precision, and F1-score obtained on all three datasets are 98.74%, 97.46%, and 97.95%, respectively, with the average processing time for each DNS packet as 473.25 milliseconds.
Neha Sharma 0007, Mayank Swarnkar, Divyanshu
IEEE Trans. Netw. Serv. Manag.2
2025 LNNIDS: A Hybrid Liquid Neural Network based IDS for Known and Unknown IoT Attacks
abstract
The rapid expansion of Internet of Things (IoT) networks has introduced new cybersecurity risks, particularly due to their heterogeneous, dynamic, and resource-constrained nature. Intrusion Detection Systems (IDS) are commonly used to detect cyber threats in such environments, but traditional IDSs and many machine learning (ML) or deep learning (DL)-based methods face challenges. These include poor detection of unknown attacks, dependence on large datasets, static feature learning, and an inability to adapt to evolving traffic patterns without frequent retraining. Furthermore, while graph-based IDSs capture relational context, their high computational cost and difficulty in adapting to dynamic IoT networks hinder their scalability. To address these challenges, we propose LNNIDS , a novel IDS method that integrates spike encoding with a Hybrid Liquid Neural Network (HLLN) to capture the temporal evolution of IoT attack network traffic. To further enhance accuracy, we introduce DYNGraph , a dynamic graph-based method that performs n → 1 pattern clustering for scalable attack classification. This allows the LNNIDS to dynamically group related flow behaviors and adapt to new or unknown attacks without retraining. We evaluated LNNIDS on two public IoT datasets. This method achieved 99.50% accuracy and maintained robust performance with only 20% training data. Furthermore, we compared the LNNIDS with the seven recent state-of-the-art methods, and we found that LNNIDS outperformed them in the detection of known and unknown IoT attacks with 13.45% and 11.99% better accuracy, respectively.
Mayank Swarnkar, Manmeet Muskan
ACM Trans. Internet Techn.2
2024 OptiClass: An Optimized Classifier for Application Layer Protocols Using Bit Level Signatures
abstract
Network traffic classification has many applications, such as security monitoring, quality of service, traffic engineering, and so on. For the aforementioned applications, Deep Packet Inspection (DPI) is a popularly used technique for traffic classification because it scrutinizes the payload and provides comprehensive information for accurate analysis of network traffic. However, DPI-based methods reduce network performance because they are computationally expensive and hinder end-user privacy as they analyze the payload. To overcome these challenges, bit-level signatures are significantly used to perform network traffic classification. However, most of these methods still need to improve performance as they perform one-by-one signature matching of unknown payloads with application signatures for classification. Moreover, these methods become stagnant with the increase in application signatures. Therefore, to fill this gap, we propose OptiClass , an optimized classifier for application protocols using bit-level signatures. OptiClass performs parallel application signature matching with unknown flows, which results in faster, more accurate, and more efficient network traffic classification. OptiClass achieves twofold performance gains compared to the state-of-the-art methods. First, OptiClass generates bit-level signatures of just 32 bits for all the applications. This keeps OptiClass swift and privacy-preserving. Second, OptiClass uses a novel data structure called BiTSPLITTER for signature matching for fast and accurate classification. We evaluated the performance of OptiClass on three datasets consisting of twenty application protocols. Experimental results report that OptiClass has an average recall, precision, and F1-score of 97.36%, 97.38%, and 97.37%, respectively, and an average classification speed of 9.08 times faster than five closely related state-of-the-art methods.
Mayank Swarnkar, Neha Sharma 0007
ACM Trans. Priv. Secur.1
2024 BitIoT: A Bit Level Deep Packet Inspection Method for Identification of MQTT-Based IoT Devices in the Wild
abstract
With the growing popularity of IoT devices, the contribution of IoT network traffic on the Internet is increasing. IoT network traffic is monitored for security analysis, maintaining the Quality of Services (QoS), etc., in a smart environment. IoT traffic is highly heterogeneous because of two main reasons. First, IoT devices use a variety of communication protocols like HTTP(s), MQTT, CoAP, etc., among which MQTT is widely used due to its lightweight design. Second, many IoT devices are frequently installed and removed from a network as needed. Thus, it is important to identify unknown IoT devices in the network traffic to maintain security and QoS. Also, identification should be lightweight enough to cater to highly dynamic environments. To fill this gap, we propose BitIoT, an unsupervised and lightweight bit-level deep packet inspection method for accurately identifying MQTT-based IoT devices in the network traffic. After Identification, BitIoT generates bit-level signatures for identified IoT devices, which are further used for signature-based classification. Furthermore, we propose a novel data structure called BinMap, which performs fast and accurate signature-based classification. We tested BitIoT on two different datasets containing network traces of 29 MQTT-based IoT devices and found that BitIoT identified all the devices successfully. Moreover, the classification from the generated signatures results in an average recall rate of 99.1%.
Mayank Swarnkar
IEEE Trans. Netw. Serv. Manag.1
2023 Temporal feature aggregation with attention for insider threat detection from activity logs
Preetam Pal, Pratik Chattopadhyay, Mayank Swarnkar
Expert Syst. Appl.3
2022 IoT Network Traffic Classification Using Machine Learning Algorithms: An Experimental Analysis
abstract
Internet of Things (IoT) refers to a wide variety of embedded devices connected to the Internet, enabling them to transmit and share information in smart environments with each other. The regular monitoring of IoT network traffic generated from IoT devices is important for their proper functioning and detection of malicious activities. One such crucial activity is the classification of IoT devices in the network traffic. It enables the administrator to monitor the activities of IoT devices which can be useful for proper implementation of Quality of Service, detect malicious IoT devices, etc. In the literature, various methods are proposed for IoT traffic classification using various machine learning algorithms. However, the accuracy of these machine learning algorithms depends on the data generated from various IoT devices, features extracted from network traffic, site at which IoT is deployed, etc. Moreover, the selection of features and machine learning algorithms are manual operations that are prone to error. Therefore, it is important to study the network traffic characteristics as well as suitable machine learning algorithms for accurate and optimized IoT traffic classification. In this article, we perform an in-depth comparative analysis of various popular machine learning algorithms using different effective features extracted from IoT network traffic. We utilize a public data set having 20 days of network traces generated from 20 popular IoT devices. Network traces are first processed to extract the significant features. We then selected state-of-the-art machine learning algorithms based on the recent survey papers for the IoT traffic classification. We then comparatively evaluated the performance of those machine learning algorithms on the basis of classification accuracy, speed, training time, etc. Finally, we provided a few suggestions for selecting the machine learning algorithm for different use cases based on the obtained results.
Mayank Swarnkar, Gaurav Singal, Neeraj Kumar 0001
IEEE Internet Things J.2
2020 BitProb: Probabilistic Bit Signatures for Accurate Application Identification
abstract
Network traffic classification finds its applications in a variety of network management tasks such as quality of service, security monitoring, traffic engineering, etc. Deep Packet Inspection is one of the methods to identify applications. With the number of proprietary protocols on the rise and network protocols using bit level information for encoding, recently it has been shown that bit level signatures are effective for identifying applications. In this paper, we propose BitProb which generates probabilistic bit signatures for traffic classification. It uses the probability of a bit at a particular position being either 0 or 1 and generates a space efficient signature represented as a state transition machine. Subsequently, it uses the overall probability of an n bit binary string extracted from a network flow to identify which application generated the flow. We experiment with three datasets covering twenty protocols (text, binary and proprietary) and show that BitProb classifies network flows with high accuracy and has a minimum number of misclassifications.
Neminath Hubballi, Mayank Swarnkar, Mauro Conti
IEEE Trans. Netw. Serv. Manag.2
2018 BitCoding: Network Traffic Classification Through Encoded Bit Level Signatures
Neminath Hubballi, Mayank Swarnkar
IEEE/ACM Trans. Netw.2
2017 BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic Classification
abstract
Traffic classification has received considerable interest as many network applications use obfuscation methods to hide their identity and bypass security. Traditionally application signatures are generated using byte level content of application flows. Increasingly new data formats are used to encode the application protocols which render the byte level signatures ineffective in identifying applications. To address this issue we propose BitCoding a bit-level application signature generation using invariant bits of application flows. Unlike other works, BitCoding uses only a small number of initial bits of flows to generate signature and signature bits are encoded using run length coding to reduce size; hence it is very inexpensive in storage and is light weight for signature matching. We evaluate BitCoding using three different datasets and show that it is able to classify both text based and binary protocols with high accuracy, making it protocol type agnostic. Further we perform cross evaluation of signatures generated to understand the portability of signatures generated to other sites and conclude that it will lead to a small compromise in the detection rate.
Neminath Hubballi, Mayank Swarnkar
GLOBECOM2
2016 VoIP Profiler: Profiling Voice over IP User Communication Behavior
abstract
Understanding the user behavior in Voice over IP (VoIP) communication has twofold advantages. It helps in detecting anomalies and also helps in planning VoIP infrastructure deployment and optimization. Anomalies arise out of various attacks and misuses like flooding, malformed messages and spam messages. In this paper we propose VoIP Profiler a method for profiling the VoIP activities at user level. For profiling users we identify a set of parameters and compute statistics of these parameters for each user using VoIP traffic. Subsequently we use these parameters to classify users (and detect anomalies). We simulate an enterprise network and experiment with a large scale VoIP dataset and identify different types of users with high success rate.
Sainath Batthala, Mayank Swarnkar, Neminath Hubballi, Maitreya Natu
ARES2
2016 OCPAD: One class Naive Bayes classifier for payload based anomaly detection
Mayank Swarnkar, Neminath Hubballi
Expert Syst. Appl.1