Vir V. Phoha

dblp:18/5695 · also Vir Virander Phoha · DBLP profile ↗
← Back
47ranked-venue papers
5as first author
10since 2021 · last 2024
0000-0002-5390-8253ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 3 since 2021Artificial intelligence and machine learning · 15 · 3 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 11 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 since 2021Databases, data management, data science and information retrieval · 5 · 2 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2024 Decoding Hostility from Conversations Through Speech and Text Integration
abstract
Hostility is a complex trait with emotional, cognitive, and behavioral components. Hostility identification in conversational or transactional scenarios can benefit healthcare systems by, for example, predicting cardiovascular disease risks. While conventional hostility assessment relies on interviews, training proficient interviewers and mitigating biases pose significant challenges. In response, this study introduces the GMGF-MIL method to pioneer automatic multi-modal hostility detection in a structured interview. This approach utilizes recurrent neural networks to capture conversational context while integrating a graph neural network-based technique to merge acoustic and textual data. Furthermore, attention-based multiple-instance learning pooling is employed to aggregate utterance-level information. Notably, this is the first paper to introduce a novel multi-modal automated conversational hostility assessment approach, filling a notable gap in existing resources. Our evaluations showcase the efficacy of the GMGF-MIL method, achieving an accuracy of 78% in distinguishing between high- and low-hostile individuals.
Jingyu Xin, Brooks Gump, Stephen Maisto, Randall Jorgensen, Tej Bhatia, Vir V. Phoha, Asif Salekin
ACII6
2024 DSTER: A Dual-Stream Transformer-based Emotion Recognition Model through Keystrokes Dynamics
abstract
Emotion Recognition is a critical research area for enhancing human-computer interaction. Keystroke dynamics, a behavioral biometric capturing typing patterns, offers a non-intrusive, user-friendly method for recognizing emotions. We propose a Dual-Stream Transformer-based Emotion Recognition (DSTER) model, which leverages keystroke dynamics to determine emotional states. The DSTER model features a dual-stream architecture that separately extracts temporal-over-channel and channel-over-temporal information. Each stream employs multi-head self-attention mechanisms, Long-Short Term Memory (LSTM), and Convolutional Neural Network (CNN) layers, along with dense vector embeddings of keycode data, to improve the extraction of temporal and contextual information from typing sequences. To the best of our knowledge, the DSTER model is the first to integrate transformer architecture with keystroke dynamics for emotion recognition. Our experiments on a widely-used fixed-text dataset demonstrate that the DSTER model significantly outperforms the three most recent baseline models, achieving average F1 scores up to 0.989 and an average accuracy increase of up to 66.04%. Unlike the significant performance variations reported in baseline models, the DSTER model maintains consistent and robust performance across all five tested emotional states. Further analysis shows that the model performs better with longer window lengths and greater overlaps.
Frank Sicong Chen, Shruti Rao, Brijesh Tiwari, Vir V. Phoha
IJCB4
2023 Learn-to-Respond: Sequence-Predictive Recovery from Sensor Attacks in Cyber-Physical Systems
abstract
While many research efforts on Cyber-Physical System (CPS) security are devoted to attack detection, how to respond to the detected attacks receives little attention. Attack response is essential since serious consequences can be caused if CPS continues to act on the compromised data by the attacks. In this work, we aim at the response to sensor attacks and adapt machine learning techniques to recover CPSs from such attacks. There are, however, several major challenges. i) Cumulative error. Recovery needs to estimate the current state of a physical system (e.g., the speed of a vehicle) in order to know if the system has been driven to a certain state. However, the estimation error accumulates over time in presence of compromised sensors. ii) Timely response. A fast response is needed since slow recovery not only comes with large estimation errors but also may be too late to avoid irreparable consequences. To address these challenges, we propose a novel learning-based solution, named sequence-predictive recovery (or SeqRec). To reduce the estimation error, SeqRec designs the first sequence-to-sequence (Seq2Seq) model to uncover the temporal and spatial dependencies among sensors and control demands, and then uses the model to estimate system states using the trustworthy data logged in history. To achieve an adequate and fast recovery, SeqRec designs the second Seq2Seq model that considers both the current time step using the remaining intact sensors and the future time steps based on a given target state, and embeds the model into a novel recovery control algorithm to drive a physical system back to that state. Experimental results demonstrate that SeqRec can effectively and efficiently recover CPSs from sensor attacks.
Lin Zhang 0039, Vir V. Phoha, Fanxin Kong
RTSS3
2022 Gaitpoint: A Gait Recognition Network Based on Point Cloud Analysis
abstract
We propose a novel gait recognition method that combines convolutional features with features of human pose key points obtained by a point cloud analysis model. Currently, most state-of-the-art works on gait recognition rely on only images and are purely based on convolutional neural networks. Most of these methods are very sensitive to small variations in the appearance of a walking person. For instance, if a person wears a coat or carries a bag, the accuracy of these methods may drop significantly. To address this problem, we propose to treat a sequence of human key points as a point cloud and combine human key point features and convolution feature map for final prediction. The experimental results show the promise of this approach, which outperforms three state-oft-he-art baselines in all walking scenarios, including the ones involving heavy clothing or carried items.
Jiajing Chen, Huantao Ren, Frank Sicong Chen, Senem Velipasalar, Vir V. Phoha
ICIP5
2022 "This is Fake! Shared it by Mistake": Assessing the Intent of Fake News Spreaders
abstract
Individuals can be misled by fake news and spread it unintentionally without knowing it is false. This phenomenon has been frequently observed but has not been investigated. Our aim in this work is to assess the intent of fake news spreaders. To distinguish between intentional versus unintentional spreading, we study the psychological explanations of unintentional spreading. With this foundation, we then propose an influence graph, using which we assess the intent of fake news spreaders. Our extensive experiments show that the assessed intent can help significantly differentiate between intentional and unintentional fake news spreaders. Furthermore, the estimated intent can significantly improve the current techniques that detect fake news. To our best knowledge, this is the first work to model individuals’ intent in fake news spreading.
Xinyi Zhou 0001, Kai Shu, Vir V. Phoha, Huan Liu 0001, Reza Zafarani
WWW3
2022 Graph-Based Identification and Authentication: A Stochastic Kronecker Approach
abstract
A large body of research has focused on analyzing large networks and graphs. However, network and graph data is often anonymized for reasons such as protecting data privacy. Under such circumstances, it is difficult to verify the source of network data, which leads to questions such as: Given an anonymized graph, can we identify the network from which it is collected? Or, if one claims the graph is sampled from a certain network, can we verify this claim? The intuitive approach is to check for subgraph isomophism. However, subgraph isomophism is NP-complete; hence, infeasible for most large networks. Inspired by biometrics studies, we address these challenges by formulating two new problems:network identificationandnetwork authentication. To tackle these problems, similar to research on human fingerprints, we introduce two versions of anetwork identity: (1) embedding-based identity and (2) distribution-based identity. We demonstrate the effectiveness of these network identities using extensive experiments on real-world networks. Using these identities, we propose two approaches for network identification. One method uses supervised learning and can achieve an identification accuracy of 84.4 percent, and the other, which is easier to implement, relies on distances between identities and achieves an accuracy rate of 70.8 percent. For network authentication, we propose two methods to build a network authentication system. The first is a supervised learner and yields a low false accept rate and the other method, allows one to control the false reject rate with a reasonable false accept rate across networks. We demonstrate that network authentication can also be used for biometrics, authenticating users based on their touch data on phones and tablets. Our study can help identify or verify the source of network data, validate network-based research, and be used for network-based biometrics.
Shengmin Jin, Vir V. Phoha, Reza Zafarani
IEEE Trans. Knowl. Data Eng.2
2021 Adversarial Activity Detection Using Keystroke Acoustics
Amin Fallahi, Vir V. Phoha
ESORICS (1)2
2021 Press @$@$ to Login: Strong Wearable Second Factor Authentication via Short Memorywise Effortless Typing Gestures
abstract
The use of wearable devices (e.g., smartwatches) in two factor authentication (2FA) is fast emerging, as wearables promise better usability compared to smartphones. Still, the current deployments of wearable 2FA have significant usability and security issues. Specifically, one-time PIN-based wearable 2FA (PIN-2FA) requires noticeable user effort to open the app and copy random PINs from the wearable to the login terminal's (desktop/laptop) browser. An alternative approach, based on one-tap approvals via push notifications (Tap-2FA), relies upon user decision making to thwart attacks and is prone to skip-through. Both approaches are also vulnerable to traditional phishing attacks. To address this security-usability tension, we introduce a fundamentally different design of wearable 2FA, called SG-2FA, involving wrist-movement “seamless gestures” captured near transparently by the second factor wearable device while the user types a very short special sequence on the browser during the login process. The typing of the special sequence creates a wrist gesture that when identified correctly uniquely associates the login attempt with the device's owner. The special sequence can be fixed (e.g., “${@}{\$}{@}{\$}$”), does not need to be a secret, and does not need to be memorized (could be simply displayed on the browser). This design improves usability over PIN-2FA since only this short sequence has to be typed as part of the login process (no interaction with or diversion of attention to the wearable and copying of random PINs is needed). It also greatly improves security compared to Tap-2FA since the attacker can not succeed in login unless the user's wrist is undergoing the exact same gesture at the exact same time. Moreover, the approach is phishing-resistant and privacy-preserving (unlike behavioral biometrics). Our results show that SG-2FA incurs only minimal errors in both benign and adversarial settings based on appropriate parameterizations.
Prakash Shrestha, Nitesh Saxena, Diksha Shukla, Vir V. Phoha
EuroS&P4
2021 Effectiveness of symmetric rejection for a secure and user convenient multistage biometric system
Md. Shafaeat Hossain, Kiran S. Balagani, Vir V. Phoha
Pattern Anal. Appl.3
2021 Enhancing performance and user convenience of multi-biometric verification systems
Md. Shafaeat Hossain, Vir V. Phoha
Pattern Anal. Appl.2
2020 Discriminative Power of Typing Features on Desktops, Tablets, and Phones for User Identification
abstract
Research in Keystroke-Dynamics (KD) has customarily focused on temporal features without considering context to generate user templates that are used in authentication. Additionally, work on KD in hand-held devices such as smart-phones and tablets have shown that these features alone do not perform satisfactorily for authentication. In this work, we analyze the discriminatory power of the most-used conventional features found in the literature, propose a set of context-sensitive or word-specific features, and analyze the discriminatory power of proposed features using their classification results. To perform these tasks, we use the keystroke data consisting of over 650K keystrokes, collected from 20 unique users during different activities on desktops, tablets, and phones, over a span of two months. On an average, each user made 12.5K, 9K, and 10K keystrokes on desktop, tablet, and phone, respectively. We find that the conventional features are not highly discriminatory on desktops and are only marginally better on hand-held devices for user identification. By using information of the context, a subset (derived after analysis) of our proposed word-specific features offers superior discrimination among users on all devices. We find that a majority of the classifiers, built using these features, perform user identification well with accuracies in the range of 90% to 97%, average precision and recall values of 0.914 and 0.901, respectively, on balanced test samples in 10-fold cross validation. We also find that proposed features work best on hand-held devices. This work calls for a shift from using conventional KD features to a set of context-sensitive or word-specific KD features that take advantage of known information such as context.
Amith K. Belman, Vir V. Phoha
ACM Trans. Priv. Secur.2
2019 Network Identification and Authentication
abstract
Research on networks is commonly performed using anonymized network data for various reasons such as protecting data privacy. Under such circumstances, it is difficult to verify the source of network data, which leads to questions such as: Given an anonymized graph, can we identify the network from which it is collected? Or if one claims the graph is sampled from a certain network, can we verify it? The intuitive approach is to check for subgraph isomorphism. However, subgraph isomorphism is NP-complete; hence, infeasible for most large networks. Inspired by biometrics studies, we address these challenges by formulating two new problems: network identification and network authentication. To tackle these problems, similar to research on human fingerprints, we introduce two versions of a network identity: (1) embedding-based identity and (2) distribution-based identity. We demonstrate the effectiveness of these network identities on various real-world networks. Using these identities, we propose two approaches for network identification. One method uses supervised learning and can achieve an identification accuracy rate of 94.7%, and the other, which is easier to implement, relies on distances between identities and achieves an accuracy rate of 85.5%. For network authentication, we propose two methods to build a network authentication system. The first is a supervised learner and provides a low false accept rate and the other method allows one to control the false reject rate with a reasonable false accept rate across networks. Our study can help identify or verify the source of network data, validate network-based research, and be used for network-based biometrics.
Shengmin Jin, Vir V. Phoha, Reza Zafarani
ICDM2
2019 Stealing Passwords by Observing Hands Movement
abstract
The use of mobile phones in public places opens up the possibilities of remote side channel attacks on these devices. We present a video-based side channel attack to decipher passwords on mobile devices. Our method uses short video clips ranging from 5 to 10 s each, which can be taken unobtrusively from a distance and do not require the keyboard or the screen of the phone to be visible. By relating the spatiotemporal movements of the user's hand during typing and an anchor point on any visible part of the phone, we predict the typed password with high accuracy. The results on a dataset of 375 short videos of password entry process on a Samsung Galaxy S4 phone show an exponential reduction in the search space compared to a random guess. For each key-press corresponding to a character in the passwords, our method was able to reduce the search space to an average of 2-3 keys compared to ~30 keys if one has to guess the key randomly. Thus, this paper reaffirms threats to smartphone users' conventional login in public places and highlights the threats in scenarios such as hiding the screen that otherwise gives the impression of being safe to the users.
Diksha Shukla, Vir V. Phoha
IEEE Trans. Inf. Forensics Secur.2
2017 Continuous user authentication via unlabeled phone movement patterns
abstract
In this paper, we propose a novel continuous authentication system for smartphone users. The proposed system entirely relies on unlabeled phone movement patterns collected through smartphone accelerometer. The data was collected in a completely unconstrained environment over five to twelve days. The contexts of phone usage were identified using k-means clustering. Multiple profiles, one for each context, were created for every user. Five machine learning algorithms were employed for classification of genuine and impostors. The performance of the system was evaluated over a diverse population of 57 users. The mean equal error rates achieved by Logistic Regression, Neural Network, kNN, SVM, and Random Forest were 13.7%, 13.5%, 12.1%, 10.7%, and 5.6% respectively. A series of statistical tests were conducted to compare the performance of the classifiers. The suitability of the proposed system for different types of users was also investigated using the failure to enroll policy.
Rajesh Kumar 0016, Partha Pratim Kundu, Diksha Shukla, Vir V. Phoha
IJCB4
2016 Toward Robotic Robbery on the Touch Screen
abstract
Despite the tremendous amount of research fronting the use of touch gestures as a mechanism of continuous authentication on smart phones, very little research has been conducted to evaluate how these systems could behave if attacked by sophisticated adversaries. In this article, we present two Lego-driven robotic attacks on touch-based authentication: a population statistics--driven attack and a user-tailored attack. The population statistics--driven attack is based on patterns gleaned from a large population of users, whereas the user-tailored attack is launched based on samples stolen from the victim. Both attacks are launched by a Lego robot that is trained on how to swipe on the touch screen. Using seven verification algorithms and a large dataset of users, we show that the attacks cause the system’s mean false acceptance rate (FAR) to increase by up to fivefold relative to the mean FAR seen under the standard zero-effort impostor attack. The article demonstrates the threat that robots pose to touch-based authentication and provides compelling evidence as to why the zero-effort attack should cease to be used as the benchmark for touch-based authentication systems.
Abdul Serwadda, Vir V. Phoha, Rajesh Kumar 0016, Diksha Shukla
ACM Trans. Inf. Syst. Secur.2
2015 When Mice devour the Elephants: A DDoS attack against size-based scheduling schemes in the internet
Abdul Serwadda, Vir V. Phoha
Comput. Secur.2
2015 Utilizing linguistically enhanced keystroke dynamics to predict typist cognition and demographics
David Guy Brizan, Adam Goodkind, Patrick Koch, Kiran S. Balagani, Vir V. Phoha, Andrew Rosenberg
Int. J. Hum. Comput. Stud.5
2014 Topology-dependent performance of attack graph reconstruction in PPM-based IP traceback
abstract
A variety of schemes based on the technique of Probabilistic Packet Marking (PPM) have been proposed to identify Distributed Denial of Service (DDoS) attack traffic sources by IP traceback. These PPM-based schemes provide a way to reconstruct the attack graph - the network path taken by the attack traffic - hence identifying its sources. Despite the large amount of research in this area, the influence of the underlying topology on the performance of PPM-based schemes remains an open issue. In this paper, we identify three network-dependent factors that affect different PPM-based schemes uniquely giving rise to a variation in and discrepancy between scheme performance from one network to another. Using simulation, we also show the collective effect of these factors on the performance of selected schemes in an extensive set of 60 Internet-like networks. We find that scheme performance is dependent on the network on which it is implemented. We show how each of these factors contributes to a discrepancy in scheme performance in large scale networks. This discrepancy is exhibited independent of similarities or differences in the underlying models of the networks.
Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha
CCNC3
2014 Beware, Your Hands Reveal Your Secrets!
abstract
Research on attacks which exploit video-based side-channels to decode text typed on a smartphone has traditionally assumed that the adversary is able to leverage some information from the screen display (say, a reflection of the screen or a low resolution video of the content typed on the screen). This paper introduces a new breed of side-channel attack on the PIN entry process on a smartphone which entirely relies on the spatio-temporal dynamics of the hands during typing to decode the typed text. Implemented on a dataset of 200 videos of the PIN entry process on an HTC One phone, we show, that the attack breaks an average of over 50% of the PINs on the first attempt and an average of over 85% of the PINs in ten attempts. Because the attack can be conducted in such a way not to raise suspicion (i.e., since the adversary does not have to direct the camera at the screen), we believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information. As users conduct more and more of their computing transactions on mobile devices in the open, the paper calls for the community to take a closer look at the risks posed by the now ubiquitous camera-enabled devices.
Diksha Shukla, Rajesh Kumar 0016, Abdul Serwadda, Vir V. Phoha
CCS4
2014 Continuous authentication with cognition-centric text production and revision features
abstract
Most continuous user authentication techniques based on typing behavior rely on the keystroke dynamics or on the linguistic style of the user. However, there is a rich spectrum of cognition-centric behavioral traits that a typist exhibits during different stages of text production (e.g., composition, translation, and revision), which to our knowledge, have not been considered for continuous authentication. We study the continuous authentication performance of 123 behavioral traits extracted from discrete cognitive units called bursts. We performed experiments on typing data collected from 486 volunteer subjects. Our findings include: (1) features from bursts delimited by pause events have significantly higher availability and authentication performance compared to bursts delimited by revision events; (2) bursts with pause durations of at least one second provide the best authentication accuracy and availability; and (3) fusing our features with traditional keystroke dynamics features reduced authentication error rates. We achieved an equal error rate between 13.37 and 4.55 percent for authentication windows as low as 30 seconds to 3.5 minutes.
Hilbert Locklear, Sathya Govindarajan, Zdenka Sitova, Adam Goodkind, David Guy Brizan, Andrew Rosenberg, Vir V. Phoha, Paolo Gasti, Kiran S. Balagani
IJCB7
2014 Privacy-preserving population-enhanced biometric key generation from free-text keystroke dynamics
abstract
Biometric key generation techniques are used to reliably generate cryptographic material from biometric signals. Existing constructions require users to perform a particular activity (e.g., type or say a password, or provide a handwritten signature), and are therefore not suitable for generating keys continuously. In this paper we present a new technique for biometric key generation from free-text keystroke dynamics. This is the first technique suitable for continuous key generation. Our approach is based on a scaled parity code for key generation (and subsequent key reconstruction), and can be augmented with the use of population data to improve security and reduce key reconstruction error. In particular, we rely on linear discriminant analysis (LDA) to obtain a better representation of discriminable biometric signals. To update the LDA matrix without disclosing user's biometric information, we design a provably secure privacy-preserving protocol (PP-LDA) based on homomorphic encryption. Our biometric key generation with PP-LDA was evaluated on a dataset of 486 users. We report equal error rate around 5% when using LDA, and below 7% without LDA.
Jaroslav Sedenka, Kiran S. Balagani, Vir V. Phoha, Paolo Gasti
IJCB3
2014 Using network motifs to investigate the influence of network topology on PPM-based IP traceback schemes
Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha
Comput. Networks3
2014 Modeling online social network users' profile attribute disclosure behavior from a game theoretic perspective
Jundong Chen 0001, Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha
Comput. Commun.4
2014 A Non-Interactive Dual Channel Continuous Traffic Authentication Protocol
abstract
We introduce a non-interactive dual-channel protocol for continuous traffic authentication and analyze its security properties. We realize the proposed protocol by facilitating dual channels at the keyboard with the assistance of a lightweight hardware module. The proposed protocol does not require users' explicit engagement in the authentication process. Empirical results show that, for a 30-day period, the maximum false reject rate for all legitimate requests on a day is 6% (with a 30 day daily average of 2.4%) and the false accept rate on any given day is 0%. The daily maximum false reject rate of the user requests falls to 0% if the users are forced to engage explicitly in the protocol operation for a maximum of 1.2% of users' non-typed requests.
David Irakiza, Md. Enamul Karim, Vir V. Phoha
IEEE Trans. Inf. Forensics Secur.3
2013 When kids' toys breach mobile phone security
abstract
Touch-based verification --- the use of touch gestures (e.g., swiping, zooming, etc.) to authenticate users of touch screen devices --- has recently been widely evaluated for its potential to serve as a second layer of defense to the PIN lock mechanism. In all performance evaluations of touch-based authentication systems however, researchers have assumed naive (zero-effort) forgeries in which the attacker makes no effort to mimic a given gesture pattern.
Abdul Serwadda, Vir V. Phoha
CCS2
2013 Modeling privacy settings of an online social network from a game-theoretical perspective
abstract
Users of online social networks are often required to adjust their privacy settings because of frequent changes in the users’ connections as well as occasional changes in the social network’s privacy policy. In this paper, we specifically model the user’s behavior in the disclosure of user attribute
Jundong Chen 0001, Matthias R. Brust, Ankunda R. Kiremire, Vir V. Phoha
CollaborateCom4
2013 A Non-interactive Dual-channel Authentication Protocol for Assuring Pseudo-confidentiality
David Irakiza, Md. Enamul Karim, Vir V. Phoha
NDSS3
2013 Snoop-Forge-Replay Attacks on Continuous Verification With Keystrokes
abstract
We present a new attack called the snoop-forge-replay attack on keystroke-based continuous verification systems. The snoop-forge-replay is a sample-level forgery attack and is not specific to any particular keystroke-based continuous verification method or system. It can be launched with easily available keyloggers and APIs for keystroke synthesis. Our results from 2640 experiments show that: 1) the snoop-forge-replay attacks achieve alarmingly high error rates compared to zero-effort impostor attacks, which have been the de facto standard for evaluating keystroke-based continuous verification systems; 2) four state-of-the-art verification methods, three types of keystroke latencies, and 11 matching-pair settings (-a key parameter in continuous verification with keystrokes) that we examined in this paper were susceptible to the attack; 3) the attack is effective even when as low as 20 to 100 keystrokes were snooped to create forgeries. In light of our results, we question the security offered by current keystroke-based continuous verification systems. Additionally, in our experiments, we harnessed virtualization technology to generate thousands of keystroke forgeries within a short time span. We point out that virtualization setup such as the one used in our experiments can also be exploited by an attacker to scale and speedup the attack.
Khandaker Abir Rahman, Kiran S. Balagani, Vir V. Phoha
IEEE Trans. Inf. Forensics Secur.3
2013 Using Mussel-Inspired Self-Organization and Account Proxies to Obfuscate Workload Ownership and Placement in Clouds
abstract
Recent research has provided evidence indicating how a malicious user could perform coresidence profiling and public-to-private IP mapping to target and exploit customers which share physical resources. The attacks rely on two steps: resource placement on the target's physical machine and extraction. Our proposed solution, in part inspired by mussel self-organization, relies on user account and workload clustering to mitigate coresidence profiling. Users with similar preferences and workload characteristics are mapped to the same cluster. To obfuscate the public-to-private IP map, each cluster is managed and accessed by an account proxy. Each proxy uses one public IP address, which is shared by all clustered users when accessing their instances, and maintains the mapping to private IP addresses. We describe a set of capabilities and attack paths an attacker needs to execute for targeted coresidence, and present arguments to show how our approach disrupts the critical steps in the attack path for most cases. We then perform a risk assessment to determine the likelihood an individual user will be victimized, given that a successful nondirected exploit has occurred. Our results suggest that while possible, this event is highly unlikely.
Justin L. Rice, Vir V. Phoha
IEEE Trans. Inf. Forensics Secur.2
2013 Examining a Large Keystroke Biometrics Dataset for Statistical-Attack Openings
abstract
Research on keystroke-based authentication has traditionally assumed human impostors who generate forgeries by physically typing on the keyboard. With bots now well understood to have the capacity to originate precisely timed keystroke sequences, this model of attack is likely to underestimate the threat facing a keystroke-based system in practice. In this work, we investigate how a keystroke-based authentication system would perform if it were subjected to synthetic attacks designed to mimic the typical user. To implement the attacks, we perform a rigorous statistical analysis on keystroke biometrics data collected over a 2-year period from more than 3000 users, and then use the observed statistical traits to design and launch algorithmic attacks against three state-of-the-art password-based keystroke verification systems.
Abdul Serwadda, Vir V. Phoha
ACM Trans. Inf. Syst. Secur.2
2012 Dynamical System Theory for the Detection of Anomalous Behavior in Computer Programs
abstract
Code injection is a common approach which is utilized to exploit applications. We introduce some of the well-established techniques and formalisms of dynamical system theory into analysis of program behavior via system calls to detect code injections into an applications execution space. We accept a program as a blackbox dynamical system whose internals are not known, but whose output we can observe. The blackbox system observable in our model is the system calls the program makes. The collected system calls are treated as signals which are used to reconstruct the system’s phase space. Then, by using the well-established techniques from dynamical system theory, we quantify the amount of complexity of the system’s (program’s) behavior. The change in the behavior of a compromised system is detected as anomalous behavior compared with the baseline established from a clean program. We test the proposed approach against DARPA-98 dataset and a real-world exploit and present code injection experiments to show the applicability of our approach.
Nitin Kanaskar, Remzi Seker, Jiang Bian 0001, Vir V. Phoha
IEEE Trans. Syst. Man Cybern. Part C4
2011 Web Farm-inspired Computational Cluster in the Cloud
abstract
In this paper, we introduce a web farm-inspired framework for dynamic and concurrent computational processing in the cloud. We compare and contrast this with the Hadoop-cloud framework, discuss the main problems associated with our approach, and give suggestions on ways to overcome said challenges. To implement the web-inspired framework, we use Node.js - a lightweight, single threaded, server-side framework which uses asynchronous callbacks to allow non-dependent operations (parallel-like sections) to execute while waiting for I/O events such as "fetching a file" or "writing a file to disk." We perform experiments to reveal two preliminary results that showcase the framework's functionality and scalability. One, for non-blocking operations, worker nodes which use Node.js servers are significantly faster than those which use traditional servers. In particular, a single Node.js is (on average) 2.11 times faster than one Ruby We brick server, and is (on average) 1.88 times faster than two Ruby We brick servers. Two, we find that increasing the number of worker nodes improves overall performance for blocking computational operations. As the number of worker nodes increase, the total execution time decreases exponentially and the number of requests per second increases linearly.
Justin L. Rice, Vir V. Phoha, Patrice Cappelaere, Dan Mandl
CloudCom2
2011 On the discriminability of keystroke feature vectors used in fixed text keystroke authentication
Kiran S. Balagani, Vir V. Phoha, Asok Ray, Shashi Phoha
Pattern Recognit. Lett.2
2010 Size-based scheduling: a recipe for DDOS?
abstract
Internet traffic measurements have shown that the majority of the Internet's flows are short, while a small percentage of the largest flows are responsible for most of the bytes. To exploit this property for performance improvement in routers and Web servers, several studies have proposed size-based schedulings to offer preferential treatment to the shortest flows. In this work, we present analytical and simulation results which confirm that size-based scheduling will ease the task of launching DDOS attacks on the Internet.
Abdul Serwadda, Vir V. Phoha, Idris A. Rai
CCS2
2010 On the Feature Selection Criterion Based on an Approximation of Multidimensional Mutual Information
abstract
We derive the feature selection criterion presented in [CHECK END OF SENTENCE] and [CHECK END OF SENTENCE] from the multidimensional mutual information between features and the class. Our derivation: 1) specifies and validates the lower-order dependency assumptions of the criterion and 2) mathematically justifies the utility of the criterion by relating it to Bayes classification error.
Kiran S. Balagani, Vir V. Phoha
IEEE Trans. Pattern Anal. Mach. Intell.2
2010 On Guo and Nixon's Criterion for Feature Subset Selection: Assumptions, Implications, and Alternative Options
abstract
Guo and Nixon proposed a feature selection method based on maximizingI(x;Y), the multidimensional mutual information between feature vectorxand class variableY. Because computingI(x;Y) can be difficult in practice, Guo and Nixon proposed an approximation ofI(x;Y) as the criterion for feature selection. We show that Guo and Nixon's criterion originates from approximating the joint probability distributions inI(x;Y) by second-order product distributions. We remark on the limitations of the approximation and discuss computationally attractive alternatives to computeI(x;Y) .
Kiran S. Balagani, Vir V. Phoha, S. Sitharama Iyengar, N. Balakrishnan 0001
IEEE Trans. Syst. Man Cybern. Part A2
2009 Multi-hop scheduling and local data link aggregation dependant Qos in modeling and simulation of power-aware wireless sensor networks
abstract
In this study of wireless sensor networks (WSN) protocols, the application Qos, system, and protocol performance metrics are measured for a large scalable wireless deployment using a typical wireless radio and an energy model. As there are many different types of WSN algorithms, we have categorized it into pro-active, re-active, and query driven information processing. A typical Qos is based on the useful lifetime of sensor nodes, after which reliability of the sensor data cannot be guaranteed and typically, a threshold such as a percentage of the sensor drains out of energy or a minimum through-put of real-time data from the sensor network is expected, which is used to compare the Qos of the routing algorithm. The results from lifetime based Qos, measured in simulation seconds, for the implemented protocols show that with varying sampled data sources for a BE Qos multi-hop deployment and varying percentage of cluster heads in a time- synchronized deployment, the lifetime is based on network size and protocol invariant. However, low sensing ranges result in dense networks, and therefore, it becomes necessary to achieve an efficient medium-access protocol subjected to power constraints. Scalability of sensor network applications are based on energy energy-harvesting techniques in which the various layers of the network inter-operate and extend the system network lifetime, the battery residual power per node, and the application reliability in terms of cross-layer energy savings. In this study, we have extended the lifetime metrics from a constant metrics into a break down of how much percentage of time is spent for Tx, Rx, and Idle tasks, respectively. This helps one to highlight the cross-layer energy dissipation per node and how the performance of an algorithm differs in terms of duty-cycling. Furthermore, we have shown that the energy savings due owing to the distributed algorithms in a large sensor network will not be practical without a complimentary lower-layer MAC. We show have demonstrated that the Qos is very much related to the ambient conditions, namely, are the Rx and Idle modes. From these preliminary results, we have added a new category of WSN protocols which are based ion the renewable energy resources, namely, the Fusion Ambient Renewable Measuring Sensors (FARMS). The study of sensor FARMS -harvesting applications allows one to measure the impact on Idle, Sleep, and renewable energy cycles as well as their unique deployment (density) needs, as all the sensor are not active(Rx) at all times. We have also shown that the efficiency of cross-layer Qos performance of routing algorithms with MAC losses has a long tail which is similarly observed in Power Law. In this sensor network model we like to show the complexity of clustering, messaging and data rate in terms of O(√(N) log N), O(N) and O(log2N) where N is the number of nodes.
Vasanth Iyer, S. Sitharama Iyengar, Garimella Rama Murthy, Bertrand Hochet, Vir V. Phoha, M. B. Srinivas
IWCMC5
2007 On the Relationship Between Dependence Tree Classification Error and Bayes Error Rate
abstract
Wong and Poon [1] showed that Chow and Liu's tree dependence approximation can be derived by minimizing an upper bound of the Bayes error rate. Wong and Poon's result was obtained by expanding the conditional entropy H(w|X). We derive the correct expansion of H(w|X) and present its implication.
Kiran S. Balagani, Vir V. Phoha
IEEE Trans. Pattern Anal. Mach. Intell.2
2007 K-Means+ID3: A Novel Method for Supervised Anomaly Detection by Cascading K-Means Clustering and ID3 Decision Tree Learning Methods
abstract
In this paper, we present "k-means+ID3", a method to cascade k-means clustering and the ID3 decision tree learning methods for classifying anomalous and normal activities in a computer network, an active electronic circuit, and a mechanical mass-beam system. The k-means clustering method first partitions the training instances into k clusters using Euclidean distance similarity. On each cluster, representing a density region of normal or anomaly instances, we build an ID3 decision tree. The decision tree on each cluster refines the decision boundaries by learning the subgroups within the cluster. To obtain a final decision on classification, the decisions of the k-means and ID3 methods are combined using two rules: 1) the nearest-neighbor rule and 2) the nearest-consensus rule. We perform experiments on three data sets: 1) network anomaly data (NAD), 2) Duffing equation data (DED), and 3) mechanical system data (MSD), which contain measurements from three distinct application domains of computer networks, an electronic circuit implementing a forced Duffing equation, and a mechanical system, respectively. Results show that the detection accuracy of the k-means+ID3 method is as high as 96.24 percent at a false-positive-rate of 0.03 percent on NAD; the total accuracy is as high as 80.01 percent on MSD and 79.9 percent on DED
Shekhar R. Gaddam, Vir V. Phoha, Kiran S. Balagani
IEEE Trans. Knowl. Data Eng.2
2005 A parallel decision tree-based method for user authentication based on keystroke patterns
abstract
We propose a Monte Carlo approach to attain sufficient training data, a splitting method to improve effectiveness, and a system composed of parallel decision trees (DTs) to authenticate users based on keystroke patterns. For each user, approximately 19 times as much simulated data was generated to complement the 387 vectors of raw data. The training set, including raw and simulated data, is split into four subsets. For each subset, wavelet transforms are performed to obtain a total of eight training subsets for each user. Eight DTs are thus trained using the eight subsets. A parallel DT is constructed for each user, which contains all eight DTs with a criterion for its output that it authenticates the user if at least three DTs do so; otherwise it rejects the user. Training and testing data were collected from 43 users who typed the exact same string of length 37 nine consecutive times to provide data for training purposes. The users typed the same string at various times over a period from November through December 2002 to provide test data. The average false reject rate was 9.62% and the average false accept rate was 0.88%.
Yong Sheng, Vir V. Phoha, S. M. Rovnyak
IEEE Trans. Syst. Man Cybern. Part B2
2004 Supervisory Control of Software Systems
abstract
We present a new paradigm to control software systems based on the supervisory control theory (SCT). Our method uses the SCT to model the execution of a software application by restricting the actions of the OS with little or no modifications in the underlying OS. Our approach can be generalized to any software application as the interactions of the application with the OS are modeled at a process level as a deterministic finite state automaton (DFSA) termed as a "plant." A "supervisor" that controls the plant is a DFSA synthesized from a set of control specifications. The supervisor operates synchronously with the plant to restrict the language accepted by the plant to satisfy the control specifications. Using the above method of control to mitigate faults, as a proof-of-concept, we implement two supervisors under the Redhat Linux 7.2 OS to mitigate overflow and segmentation faults in five different programs. We quantify the performance of the unsupervised and supervised plant by using a language measure and give methods to compute the measure using state transition cost matrix and characteristic vector.
Vir V. Phoha, Amit U. Nadgar, Asok Ray, Shashi Phoha
IEEE Trans. Computers1
2002 An Adaptive Web Cache Access Predictor Using Neural Network
Ben Choi 0002, Vir V. Phoha
IEA/AIE3
2001 Web user clustering from access log using belief function
Yunjuan Xie, Vir V. Phoha
K-CAP2
2001 An interactive dynamic model for integrating knowledge management methods and knowledge sharing technology in a traditional classroom
abstract
This paper reports an interactive dynamic model using Continuous Knowledge Management methods and Knowledge Sharing technology to integrate the acquisition of skills and relevant information (knowledge level) into diverse, individualized, concurrent learning processes in a traditional classroom setting. As opposed to a passive introduction of technology to facilitate the traditional learning processes a Web based active learning and continuous evaluation process was created which integrates objective scientific knowledge relating to course content, subjective knowledge obtained through personal interactions and empirical knowledge collected during the learning process. Knowledge Management, an emerging area of Artificial Intelligence, encompasses identifying, mapping, and managing intellectual assets to generate new knowledge for competitive advantage and for sharing of technology. The Web-based model of knowledge management discussed here allows a diverse group of learners to progressively interact and participate in the learning process, providing non-threatening self-evaluation and just-in-time individualized feedback to the learners and efficient tracking and supervision tools to the instructor. CS1003, a required general education class provides an ideal application of this model as the course draws from a diverse body of students ranging from history to math majors and from freshmen to seniors. The instructional design of this course using the interactive dynamics of Knowledge Management includes (i) provision of course archives and relevant static information as a passive repository, (ii) Web Discussion Forums, electronic chats and email communication for active learning and continuous interaction, (iii) an intelligent self-evaluation and grade reporting system for non-threatening self-testing and what-if analysis of performance, and (iv) a dynamic student feedback system including individualized supervision and anonymous feedback. Application of this instructional process enhanced the goals of the course from mere computer literacy to what the 1999 NRC Report calls Fluency in Information Technology (FIT). Three kinds of knowledge requirements are identified for FIT: (1) Contemporary skills, (2) Foundational concepts, and (3) Intellectual capabilities. This model is broadly applicable to extend the benefits of traditional classroom instruction to focus diverse intellectual abilities and interests in a collaborative learning process. Formal and informal evaluation support this claim, demonstrating that the transition from purely traditional teaching to a high degree of technology fluency can be painless, efficient and effective in preparing the students for a technology intensive information age.
Vir V. Phoha
SIGCSE1
1996 Image recovery and segmentation using competitive learning in a layered network
abstract
In this study, we have used the principle of competitive learning to develop an iterative algorithm for image recovery and segmentation. Within the framework of Markov random fields (MRFs), the image recovery problem is transformed to the problem of minimization of an energy function; A local update rule for each pixel point is then developed in a stepwise fashion and is shown to be a gradient descent rule for an associated global energy function. The relationship of the update rule to Kohonen's update rule is shown. Quantitative measures of edge preservation and edge enhancement for synthetic images are introduced. As compared to recently published results using mean field approximation, our algorithm shows consistently better performance in edge preservation and comparable performance in enhancing within the boundaries. These results are based on simulation experiments on a set of synthetic images corrupted by Gaussian noise and on a set of real images.
Vir V. Phoha, William J. B. Oldham
IEEE Trans. Neural Networks1
1996 Corrections to "Image Recovery and Segmentation Using Competitive Learning in a Layered Network
Vir V. Phoha, William J. B. Oldham
IEEE Trans. Neural Networks1
1995 Decision support and executive information systems : by Paul Gray (editor) (1994; Pages 469; Prentice Hall, Englewood Cliffs, NJ 07632, USA; ISBN 0-13-235789-5)
Vir V. Phoha
Decis. Support Syst.1