VLDB 2026 Research / reviewers in the wild / expert
Zarrin Tasnim Sworna
dblp:177/5780
· DBLP profile ↗
5ranked-venue papers
5as first author
4since 2021 · last 2023
0000-0003-2418-330XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Security Tools' API Recommendation Using Machine Learning
Zarrin Tasnim Sworna, Anjitha Sreekumar, Chadni Islam, Muhammad Ali Babar 0001 |
ENASE | 1 |
| 2023 | IRP2API: Automated Mapping of Cyber Security Incident Response Plan to Security Tools' APIsabstractSecurity Operation Center (SOC) uses Incident Response Plan (IRP) to respond to security incidents by orchestrating diverse security tools’ activities in a Security Orchestration, Automation and Response (SOAR) platform. SOC teams manually dig through API documentation of security tools to find the appropriate APIs to define, update and execute an IRP, which hampers effective and efficient incident response. We propose a novel framework, namely IRP2API, for automated mapping of IRP to diverse security tools’ APIs. IRP2API enables SOC teams to effectively and efficiently execute IRP tasks, whilst significantly reducing the required human effort. IRP2API is a unified framework for diverse security tools using an unsupervised transfer learning approach based on API documentation. IRP2API alleviates the requirement of expert knowledge, expensive manually labeled data and access to the code repository. IRP2API achieves suitable semantic coverage by leveraging different semantic variation enrichment methods to deal with the semantic variation of IRP and API data. To demonstrate the real world viability of IRP2API, we experimentally evaluate its effectiveness and efficiency using IRPs of a real world SOAR platform, 6 security tools and 4 transfer learning-based pre-trained embedding approaches. IRP2API achieves 91.1% Top-15 Accuracy and mean reciprocal rank@15 of 57.4 for automated IRP to API mapping, which is 41.6% and 81.6% improved compared to the best results across all non-transfer learning-based baselines. It indicates its effectiveness to support a SOC team. IRP2API requires only 0.8 sec per IRP task to map suitable API that reflects its real world applicability in time-critical SOC. Zarrin Tasnim Sworna, Muhammad Ali Babar 0001, Anjitha Sreekumar |
SANER | 1 |
| 2023 | NLP methods in host-based intrusion detection systems: A systematic review and future directionsabstractHost-based Intrusion Detection System (HIDS) is an effective last line of defense for defending against cyber security attacks after perimeter defenses (e.g., Network-based Intrusion Detection System and Firewall) have failed or been bypassed. HIDS is widely adopted in the industry as HIDS is ranked among the top two most used security tools by Security Operation Centers (SOC) of organizations. Although effective and efficient HIDS is highly desirable for industrial organizations, the evolution of increasingly complex attack patterns causes several challenges resulting in performance degradation of HIDS (e.g., high false alert rate creating alert fatigue for SOC staff). Since Natural Language Processing (NLP) methods are better suited for identifying complex attack patterns, an increasing number of HIDS are leveraging the advances in NLP that have shown effective and efficient performance in precisely detecting low footprint, zero-day attacks and predicting an attacker’s next steps. This active research trend of using NLP in HIDS demands a synthesized and comprehensive body of knowledge of NLP-based HIDS. Despite the drastically growing adoption of NLP in HIDS development, there has been relatively little effort allocated to systematically analyze and synthesize the available peer review literature to understand how NLP is used in HIDS development. The lack of a synthesized and comprehensive body of knowledge on such an important topic motivated us to conduct a Systematic Literature Review (SLR) of the papers on the end-to-end pipeline of the use of NLP in HIDS development. For the end-to-end NLP-based HIDS development pipeline, we identify, taxonomically categorize and systematically compare the state-of-the-art of NLP methods usage in HIDS, attacks detected by these NLP methods, datasets and evaluation metrics which are used to evaluate the NLP-based HIDS. We highlight the relevant prevalent practices, considerations, advantages and limitations to support the HIDS developers. We also outline the future research directions for the NLP-based HIDS development. Zarrin Tasnim Sworna, Zahra Mousavi, Muhammad Ali Babar 0001 |
J. Netw. Comput. Appl. | 1 |
| 2023 | APIRO: A Framework for Automated Security Tools API RecommendationabstractSecurity Orchestration, Automation, and Response (SOAR) platforms integrate and orchestrate a wide variety of security tools to accelerate the operational activities of Security Operation Center (SOC). Integration of security tools in a SOAR platform is mostly done manually using APIs, plugins, and scripts. SOC teams need to navigate through API calls of different security tools to find a suitable API to define or update an incident response action. Analyzing various types of API documentation with diverse API format and presentation structure involves significant challenges such as data availability, data heterogeneity, and semantic variation for automatic identification of security tool APIs specific to a particular task. Given these challenges can have negative impact on SOC team’s ability to handle security incident effectively and efficiently, we consider it important to devise suitable automated support solutions to address these challenges. We propose a novel learning-based framework for automated security tool API R ecommendation for security O rchestration, automation, and response, APIRO . To mitigate data availability constraint, APIRO enriches security tool API description by applying a wide variety of data augmentation techniques. To learn data heterogeneity of the security tools and semantic variation in API descriptions, APIRO consists of an API-specific word embedding model and a Convolutional Neural Network (CNN) model that are used for prediction of top three relevant APIs for a task. We experimentally demonstrate the effectiveness of APIRO in recommending APIs for different tasks using three security tools and 36 augmentation techniques. Our experimental results demonstrate the feasibility of APIRO for achieving 91.9% Top-1 Accuracy. Compared to the state-of-the-art baseline, APIRO is 26.93%, 23.03%, and 20.87% improved in terms of Top-1, Top-2, and Top-3 Accuracy and outperforms the baseline by 23.7% in terms of Mean Reciprocal Rank (MRR). Zarrin Tasnim Sworna, Chadni Islam, Muhammad Ali Babar 0001 |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2016 | A LUT-based matrix multiplication using neural networksabstractMatrix multiplication is a prime operation in linear algebra and scientific computations. In this paper, Artificial Neural Network-based matrix multiplication is introduced to create a completely new horizon in matrix multiplication technique, due to having non-linear, non-parametric characteristics of Neural Network. The time complexity of the proposed matrix multiplication algorithm based on neural networks is O(log n(n+n2+ n2/2 + log2n)), whereas the time complexity of the best known matrix multiplication algorithm is O(n3/p), where n is the dimension of the matrix and p is the number of processing elements. Besides, Artificial Neural Network being the powerful data-driven, self-adaptive tool, it provides the resultant matrix multiplication with a high degree of accuracy. Through supervised learning, the neural network completes multiplication through addition operation instead of multiplication in solution prediction stage, which evidently reduces required number of Look-Up Table (LUT). The proposed design achieves an improvement of 43.88% and 50.17% over the best known existing approach in terms of number of LUTs and slices required, respectively. Zarrin Tasnim Sworna, Mubin Ul Haque, Hafiz Md. Hasan Babu |
ISCAS | 1 |