VLDB 2026 Research / reviewers in the wild / expert
Vir V. Phoha
dblp:18/5695 · also Vir Virander Phoha
· DBLP profile ↗
47ranked-venue papers
5as first author
10since 2021 · last 2024
0000-0002-5390-8253ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 3 since 2021Artificial intelligence and machine learning · 15 · 3 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 11 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 since 2021Databases, data management, data science and information retrieval · 5 · 2 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Decoding Hostility from Conversations Through Speech and Text IntegrationabstractHostility is a complex trait with emotional, cognitive, and behavioral components. Hostility identification in conversational or transactional scenarios can benefit healthcare systems by, for example, predicting cardiovascular disease risks. While conventional hostility assessment relies on interviews, training proficient interviewers and mitigating biases pose significant challenges. In response, this study introduces the GMGF-MIL method to pioneer automatic multi-modal hostility detection in a structured interview. This approach utilizes recurrent neural networks to capture conversational context while integrating a graph neural network-based technique to merge acoustic and textual data. Furthermore, attention-based multiple-instance learning pooling is employed to aggregate utterance-level information. Notably, this is the first paper to introduce a novel multi-modal automated conversational hostility assessment approach, filling a notable gap in existing resources. Our evaluations showcase the efficacy of the GMGF-MIL method, achieving an accuracy of 78% in distinguishing between high- and low-hostile individuals. Jingyu Xin, Brooks Gump, Stephen Maisto, Randall Jorgensen, Tej Bhatia, Vir V. Phoha, Asif Salekin |
ACII | 6 |
| 2024 | DSTER: A Dual-Stream Transformer-based Emotion Recognition Model through Keystrokes DynamicsabstractEmotion Recognition is a critical research area for enhancing human-computer interaction. Keystroke dynamics, a behavioral biometric capturing typing patterns, offers a non-intrusive, user-friendly method for recognizing emotions. We propose a Dual-Stream Transformer-based Emotion Recognition (DSTER) model, which leverages keystroke dynamics to determine emotional states. The DSTER model features a dual-stream architecture that separately extracts temporal-over-channel and channel-over-temporal information. Each stream employs multi-head self-attention mechanisms, Long-Short Term Memory (LSTM), and Convolutional Neural Network (CNN) layers, along with dense vector embeddings of keycode data, to improve the extraction of temporal and contextual information from typing sequences. To the best of our knowledge, the DSTER model is the first to integrate transformer architecture with keystroke dynamics for emotion recognition. Our experiments on a widely-used fixed-text dataset demonstrate that the DSTER model significantly outperforms the three most recent baseline models, achieving average F1 scores up to 0.989 and an average accuracy increase of up to 66.04%. Unlike the significant performance variations reported in baseline models, the DSTER model maintains consistent and robust performance across all five tested emotional states. Further analysis shows that the model performs better with longer window lengths and greater overlaps. Frank Sicong Chen, Shruti Rao, Brijesh Tiwari, Vir V. Phoha |
IJCB | 4 |
| 2023 | Learn-to-Respond: Sequence-Predictive Recovery from Sensor Attacks in Cyber-Physical SystemsabstractWhile many research efforts on Cyber-Physical System (CPS) security are devoted to attack detection, how to respond to the detected attacks receives little attention. Attack response is essential since serious consequences can be caused if CPS continues to act on the compromised data by the attacks. In this work, we aim at the response to sensor attacks and adapt machine learning techniques to recover CPSs from such attacks. There are, however, several major challenges. i) Cumulative error. Recovery needs to estimate the current state of a physical system (e.g., the speed of a vehicle) in order to know if the system has been driven to a certain state. However, the estimation error accumulates over time in presence of compromised sensors. ii) Timely response. A fast response is needed since slow recovery not only comes with large estimation errors but also may be too late to avoid irreparable consequences. To address these challenges, we propose a novel learning-based solution, named sequence-predictive recovery (or SeqRec). To reduce the estimation error, SeqRec designs the first sequence-to-sequence (Seq2Seq) model to uncover the temporal and spatial dependencies among sensors and control demands, and then uses the model to estimate system states using the trustworthy data logged in history. To achieve an adequate and fast recovery, SeqRec designs the second Seq2Seq model that considers both the current time step using the remaining intact sensors and the future time steps based on a given target state, and embeds the model into a novel recovery control algorithm to drive a physical system back to that state. Experimental results demonstrate that SeqRec can effectively and efficiently recover CPSs from sensor attacks. Lin Zhang 0039, Vir V. Phoha, Fanxin Kong |
RTSS | 3 |
| 2022 | Gaitpoint: A Gait Recognition Network Based on Point Cloud AnalysisabstractWe propose a novel gait recognition method that combines convolutional features with features of human pose key points obtained by a point cloud analysis model. Currently, most state-of-the-art works on gait recognition rely on only images and are purely based on convolutional neural networks. Most of these methods are very sensitive to small variations in the appearance of a walking person. For instance, if a person wears a coat or carries a bag, the accuracy of these methods may drop significantly. To address this problem, we propose to treat a sequence of human key points as a point cloud and combine human key point features and convolution feature map for final prediction. The experimental results show the promise of this approach, which outperforms three state-oft-he-art baselines in all walking scenarios, including the ones involving heavy clothing or carried items. Jiajing Chen, Huantao Ren, Frank Sicong Chen, Senem Velipasalar, Vir V. Phoha |
ICIP | 5 |
| 2022 | "This is Fake! Shared it by Mistake": Assessing the Intent of Fake News SpreadersabstractIndividuals can be misled by fake news and spread it unintentionally without knowing it is false. This phenomenon has been frequently observed but has not been investigated. Our aim in this work is to assess the intent of fake news spreaders. To distinguish between intentional versus unintentional spreading, we study the psychological explanations of unintentional spreading. With this foundation, we then propose an influence graph, using which we assess the intent of fake news spreaders. Our extensive experiments show that the assessed intent can help significantly differentiate between intentional and unintentional fake news spreaders. Furthermore, the estimated intent can significantly improve the current techniques that detect fake news. To our best knowledge, this is the first work to model individuals’ intent in fake news spreading. Xinyi Zhou 0001, Kai Shu, Vir V. Phoha, Huan Liu 0001, Reza Zafarani |
WWW | 3 |
| 2022 | Graph-Based Identification and Authentication: A Stochastic Kronecker ApproachabstractA large body of research has focused on analyzing large networks and graphs. However, network and graph data is often anonymized for reasons such as protecting data privacy. Under such circumstances, it is difficult to verify the source of network data, which leads to questions such as: Given an anonymized graph, can we identify the network from which it is collected? Or, if one claims the graph is sampled from a certain network, can we verify this claim? The intuitive approach is to check for subgraph isomophism. However, subgraph isomophism is NP-complete; hence, infeasible for most large networks. Inspired by biometrics studies, we address these challenges by formulating two new problems:network identificationandnetwork authentication. To tackle these problems, similar to research on human fingerprints, we introduce two versions of anetwork identity: (1) embedding-based identity and (2) distribution-based identity. We demonstrate the effectiveness of these network identities using extensive experiments on real-world networks. Using these identities, we propose two approaches for network identification. One method uses supervised learning and can achieve an identification accuracy of 84.4 percent, and the other, which is easier to implement, relies on distances between identities and achieves an accuracy rate of 70.8 percent. For network authentication, we propose two methods to build a network authentication system. The first is a supervised learner and yields a low false accept rate and the other method, allows one to control the false reject rate with a reasonable false accept rate across networks. We demonstrate that network authentication can also be used for biometrics, authenticating users based on their touch data on phones and tablets. Our study can help identify or verify the source of network data, validate network-based research, and be used for network-based biometrics. Shengmin Jin, Vir V. Phoha, Reza Zafarani |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2021 | Adversarial Activity Detection Using Keystroke Acoustics
Amin Fallahi, Vir V. Phoha |
ESORICS (1) | 2 |
| 2021 | Press @$@$ to Login: Strong Wearable Second Factor Authentication via Short Memorywise Effortless Typing GesturesabstractThe use of wearable devices (e.g., smartwatches) in two factor authentication (2FA) is fast emerging, as wearables promise better usability compared to smartphones. Still, the current deployments of wearable 2FA have significant usability and security issues. Specifically, one-time PIN-based wearable 2FA (PIN-2FA) requires noticeable user effort to open the app and copy random PINs from the wearable to the login terminal's (desktop/laptop) browser. An alternative approach, based on one-tap approvals via push notifications (Tap-2FA), relies upon user decision making to thwart attacks and is prone to skip-through. Both approaches are also vulnerable to traditional phishing attacks. To address this security-usability tension, we introduce a fundamentally different design of wearable 2FA, called SG-2FA, involving wrist-movement “seamless gestures” captured near transparently by the second factor wearable device while the user types a very short special sequence on the browser during the login process. The typing of the special sequence creates a wrist gesture that when identified correctly uniquely associates the login attempt with the device's owner. The special sequence can be fixed (e.g., “${@}{\$}{@}{\$}$”), does not need to be a secret, and does not need to be memorized (could be simply displayed on the browser). This design improves usability over PIN-2FA since only this short sequence has to be typed as part of the login process (no interaction with or diversion of attention to the wearable and copying of random PINs is needed). It also greatly improves security compared to Tap-2FA since the attacker can not succeed in login unless the user's wrist is undergoing the exact same gesture at the exact same time. Moreover, the approach is phishing-resistant and privacy-preserving (unlike behavioral biometrics). Our results show that SG-2FA incurs only minimal errors in both benign and adversarial settings based on appropriate parameterizations. Prakash Shrestha, Nitesh Saxena, Diksha Shukla, Vir V. Phoha |
EuroS&P | 4 |
| 2021 | Effectiveness of symmetric rejection for a secure and user convenient multistage biometric system
Md. Shafaeat Hossain, Kiran S. Balagani, Vir V. Phoha |
Pattern Anal. Appl. | 3 |
| 2021 | Enhancing performance and user convenience of multi-biometric verification systems
Md. Shafaeat Hossain, Vir V. Phoha |
Pattern Anal. Appl. | 2 |
| 2020 | Discriminative Power of Typing Features on Desktops, Tablets, and Phones for User IdentificationabstractResearch in Keystroke-Dynamics (KD) has customarily focused on temporal features without considering context to generate user templates that are used in authentication. Additionally, work on KD in hand-held devices such as smart-phones and tablets have shown that these features alone do not perform satisfactorily for authentication. In this work, we analyze the discriminatory power of the most-used conventional features found in the literature, propose a set of context-sensitive or word-specific features, and analyze the discriminatory power of proposed features using their classification results. To perform these tasks, we use the keystroke data consisting of over 650K keystrokes, collected from 20 unique users during different activities on desktops, tablets, and phones, over a span of two months. On an average, each user made 12.5K, 9K, and 10K keystrokes on desktop, tablet, and phone, respectively. We find that the conventional features are not highly discriminatory on desktops and are only marginally better on hand-held devices for user identification. By using information of the context, a subset (derived after analysis) of our proposed word-specific features offers superior discrimination among users on all devices. We find that a majority of the classifiers, built using these features, perform user identification well with accuracies in the range of 90% to 97%, average precision and recall values of 0.914 and 0.901, respectively, on balanced test samples in 10-fold cross validation. We also find that proposed features work best on hand-held devices. This work calls for a shift from using conventional KD features to a set of context-sensitive or word-specific KD features that take advantage of known information such as context. Amith K. Belman, Vir V. Phoha |
ACM Trans. Priv. Secur. | 2 |
| 2019 | Network Identification and AuthenticationabstractResearch on networks is commonly performed using anonymized network data for various reasons such as protecting data privacy. Under such circumstances, it is difficult to verify the source of network data, which leads to questions such as: Given an anonymized graph, can we identify the network from which it is collected? Or if one claims the graph is sampled from a certain network, can we verify it? The intuitive approach is to check for subgraph isomorphism. However, subgraph isomorphism is NP-complete; hence, infeasible for most large networks. Inspired by biometrics studies, we address these challenges by formulating two new problems: network identification and network authentication. To tackle these problems, similar to research on human fingerprints, we introduce two versions of a network identity: (1) embedding-based identity and (2) distribution-based identity. We demonstrate the effectiveness of these network identities on various real-world networks. Using these identities, we propose two approaches for network identification. One method uses supervised learning and can achieve an identification accuracy rate of 94.7%, and the other, which is easier to implement, relies on distances between identities and achieves an accuracy rate of 85.5%. For network authentication, we propose two methods to build a network authentication system. The first is a supervised learner and provides a low false accept rate and the other method allows one to control the false reject rate with a reasonable false accept rate across networks. Our study can help identify or verify the source of network data, validate network-based research, and be used for network-based biometrics. Shengmin Jin, Vir V. Phoha, Reza Zafarani |
ICDM | 2 |
| 2019 | Stealing Passwords by Observing Hands MovementabstractThe use of mobile phones in public places opens up the possibilities of remote side channel attacks on these devices. We present a video-based side channel attack to decipher passwords on mobile devices. Our method uses short video clips ranging from 5 to 10 s each, which can be taken unobtrusively from a distance and do not require the keyboard or the screen of the phone to be visible. By relating the spatiotemporal movements of the user's hand during typing and an anchor point on any visible part of the phone, we predict the typed password with high accuracy. The results on a dataset of 375 short videos of password entry process on a Samsung Galaxy S4 phone show an exponential reduction in the search space compared to a random guess. For each key-press corresponding to a character in the passwords, our method was able to reduce the search space to an average of 2-3 keys compared to ~30 keys if one has to guess the key randomly. Thus, this paper reaffirms threats to smartphone users' conventional login in public places and highlights the threats in scenarios such as hiding the screen that otherwise gives the impression of being safe to the users. Diksha Shukla, Vir V. Phoha |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Continuous user authentication via unlabeled phone movement patternsabstractIn this paper, we propose a novel continuous authentication system for smartphone users. The proposed system entirely relies on unlabeled phone movement patterns collected through smartphone accelerometer. The data was collected in a completely unconstrained environment over five to twelve days. The contexts of phone usage were identified using k-means clustering. Multiple profiles, one for each context, were created for every user. Five machine learning algorithms were employed for classification of genuine and impostors. The performance of the system was evaluated over a diverse population of 57 users. The mean equal error rates achieved by Logistic Regression, Neural Network, kNN, SVM, and Random Forest were 13.7%, 13.5%, 12.1%, 10.7%, and 5.6% respectively. A series of statistical tests were conducted to compare the performance of the classifiers. The suitability of the proposed system for different types of users was also investigated using the failure to enroll policy. Rajesh Kumar 0016, Partha Pratim Kundu, Diksha Shukla, Vir V. Phoha |
IJCB | 4 |
| 2016 | Toward Robotic Robbery on the Touch ScreenabstractDespite the tremendous amount of research fronting the use of touch gestures as a mechanism of continuous authentication on smart phones, very little research has been conducted to evaluate how these systems could behave if attacked by sophisticated adversaries. In this article, we present two Lego-driven robotic attacks on touch-based authentication: a population statistics--driven attack and a user-tailored attack. The population statistics--driven attack is based on patterns gleaned from a large population of users, whereas the user-tailored attack is launched based on samples stolen from the victim. Both attacks are launched by a Lego robot that is trained on how to swipe on the touch screen. Using seven verification algorithms and a large dataset of users, we show that the attacks cause the system’s mean false acceptance rate (FAR) to increase by up to fivefold relative to the mean FAR seen under the standard zero-effort impostor attack. The article demonstrates the threat that robots pose to touch-based authentication and provides compelling evidence as to why the zero-effort attack should cease to be used as the benchmark for touch-based authentication systems. Abdul Serwadda, Vir V. Phoha, Rajesh Kumar 0016, Diksha Shukla |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2015 | When Mice devour the Elephants: A DDoS attack against size-based scheduling schemes in the internet
Abdul Serwadda, Vir V. Phoha |
Comput. Secur. | 2 |
| 2015 | Utilizing linguistically enhanced keystroke dynamics to predict typist cognition and demographics
David Guy Brizan, Adam Goodkind, Patrick Koch, Kiran S. Balagani, Vir V. Phoha, Andrew Rosenberg |
Int. J. Hum. Comput. Stud. | 5 |
| 2014 | Topology-dependent performance of attack graph reconstruction in PPM-based IP tracebackabstractA variety of schemes based on the technique of Probabilistic Packet Marking (PPM) have been proposed to identify Distributed Denial of Service (DDoS) attack traffic sources by IP traceback. These PPM-based schemes provide a way to reconstruct the attack graph - the network path taken by the attack traffic - hence identifying its sources. Despite the large amount of research in this area, the influence of the underlying topology on the performance of PPM-based schemes remains an open issue. In this paper, we identify three network-dependent factors that affect different PPM-based schemes uniquely giving rise to a variation in and discrepancy between scheme performance from one network to another. Using simulation, we also show the collective effect of these factors on the performance of selected schemes in an extensive set of 60 Internet-like networks. We find that scheme performance is dependent on the network on which it is implemented. We show how each of these factors contributes to a discrepancy in scheme performance in large scale networks. This discrepancy is exhibited independent of similarities or differences in the underlying models of the networks. Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha |
CCNC | 3 |
| 2014 | Beware, Your Hands Reveal Your Secrets!abstractResearch on attacks which exploit video-based side-channels to decode text typed on a smartphone has traditionally assumed that the adversary is able to leverage some information from the screen display (say, a reflection of the screen or a low resolution video of the content typed on the screen). This paper introduces a new breed of side-channel attack on the PIN entry process on a smartphone which entirely relies on the spatio-temporal dynamics of the hands during typing to decode the typed text. Implemented on a dataset of 200 videos of the PIN entry process on an HTC One phone, we show, that the attack breaks an average of over 50% of the PINs on the first attempt and an average of over 85% of the PINs in ten attempts. Because the attack can be conducted in such a way not to raise suspicion (i.e., since the adversary does not have to direct the camera at the screen), we believe that it is very likely to be adopted by adversaries who seek to stealthily steal sensitive private information. As users conduct more and more of their computing transactions on mobile devices in the open, the paper calls for the community to take a closer look at the risks posed by the now ubiquitous camera-enabled devices. Diksha Shukla, Rajesh Kumar 0016, Abdul Serwadda, Vir V. Phoha |
CCS | 4 |
| 2014 | Continuous authentication with cognition-centric text production and revision featuresabstractMost continuous user authentication techniques based on typing behavior rely on the keystroke dynamics or on the linguistic style of the user. However, there is a rich spectrum of cognition-centric behavioral traits that a typist exhibits during different stages of text production (e.g., composition, translation, and revision), which to our knowledge, have not been considered for continuous authentication. We study the continuous authentication performance of 123 behavioral traits extracted from discrete cognitive units called bursts. We performed experiments on typing data collected from 486 volunteer subjects. Our findings include: (1) features from bursts delimited by pause events have significantly higher availability and authentication performance compared to bursts delimited by revision events; (2) bursts with pause durations of at least one second provide the best authentication accuracy and availability; and (3) fusing our features with traditional keystroke dynamics features reduced authentication error rates. We achieved an equal error rate between 13.37 and 4.55 percent for authentication windows as low as 30 seconds to 3.5 minutes. Hilbert Locklear, Sathya Govindarajan, Zdenka Sitova, Adam Goodkind, David Guy Brizan, Andrew Rosenberg, Vir V. Phoha, Paolo Gasti, Kiran S. Balagani |
IJCB | 7 |
| 2014 | Privacy-preserving population-enhanced biometric key generation from free-text keystroke dynamicsabstractBiometric key generation techniques are used to reliably generate cryptographic material from biometric signals. Existing constructions require users to perform a particular activity (e.g., type or say a password, or provide a handwritten signature), and are therefore not suitable for generating keys continuously. In this paper we present a new technique for biometric key generation from free-text keystroke dynamics. This is the first technique suitable for continuous key generation. Our approach is based on a scaled parity code for key generation (and subsequent key reconstruction), and can be augmented with the use of population data to improve security and reduce key reconstruction error. In particular, we rely on linear discriminant analysis (LDA) to obtain a better representation of discriminable biometric signals. To update the LDA matrix without disclosing user's biometric information, we design a provably secure privacy-preserving protocol (PP-LDA) based on homomorphic encryption. Our biometric key generation with PP-LDA was evaluated on a dataset of 486 users. We report equal error rate around 5% when using LDA, and below 7% without LDA. Jaroslav Sedenka, Kiran S. Balagani, Vir V. Phoha, Paolo Gasti |
IJCB | 3 |
| 2014 | Using network motifs to investigate the influence of network topology on PPM-based IP traceback schemes
Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha |
Comput. Networks | 3 |
| 2014 | Modeling online social network users' profile attribute disclosure behavior from a game theoretic perspective
Jundong Chen 0001, Ankunda R. Kiremire, Matthias R. Brust, Vir V. Phoha |
Comput. Commun. | 4 |
| 2014 | A Non-Interactive Dual Channel Continuous Traffic Authentication ProtocolabstractWe introduce a non-interactive dual-channel protocol for continuous traffic authentication and analyze its security properties. We realize the proposed protocol by facilitating dual channels at the keyboard with the assistance of a lightweight hardware module. The proposed protocol does not require users' explicit engagement in the authentication process. Empirical results show that, for a 30-day period, the maximum false reject rate for all legitimate requests on a day is 6% (with a 30 day daily average of 2.4%) and the false accept rate on any given day is 0%. The daily maximum false reject rate of the user requests falls to 0% if the users are forced to engage explicitly in the protocol operation for a maximum of 1.2% of users' non-typed requests. David Irakiza, Md. Enamul Karim, Vir V. Phoha |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | When kids' toys breach mobile phone securityabstractTouch-based verification --- the use of touch gestures (e.g., swiping, zooming, etc.) to authenticate users of touch screen devices --- has recently been widely evaluated for its potential to serve as a second layer of defense to the PIN lock mechanism. In all performance evaluations of touch-based authentication systems however, researchers have assumed naive (zero-effort) forgeries in which the attacker makes no effort to mimic a given gesture pattern. Abdul Serwadda, Vir V. Phoha |
CCS | 2 |
| 2013 | Modeling privacy settings of an online social network from a game-theoretical perspectiveabstractUsers of online social networks are often required to adjust their privacy settings because of frequent changes in the users’ connections as well as occasional changes in the social network’s privacy policy. In this paper, we specifically model the user’s behavior in the disclosure of user attribute Jundong Chen 0001, Matthias R. Brust, Ankunda R. Kiremire, Vir V. Phoha |
CollaborateCom | 4 |
| 2013 | A Non-interactive Dual-channel Authentication Protocol for Assuring Pseudo-confidentiality
David Irakiza, Md. Enamul Karim, Vir V. Phoha |
NDSS | 3 |
| 2013 | Snoop-Forge-Replay Attacks on Continuous Verification With KeystrokesabstractWe present a new attack called the snoop-forge-replay attack on keystroke-based continuous verification systems. The snoop-forge-replay is a sample-level forgery attack and is not specific to any particular keystroke-based continuous verification method or system. It can be launched with easily available keyloggers and APIs for keystroke synthesis. Our results from 2640 experiments show that: 1) the snoop-forge-replay attacks achieve alarmingly high error rates compared to zero-effort impostor attacks, which have been the de facto standard for evaluating keystroke-based continuous verification systems; 2) four state-of-the-art verification methods, three types of keystroke latencies, and 11 matching-pair settings (-a key parameter in continuous verification with keystrokes) that we examined in this paper were susceptible to the attack; 3) the attack is effective even when as low as 20 to 100 keystrokes were snooped to create forgeries. In light of our results, we question the security offered by current keystroke-based continuous verification systems. Additionally, in our experiments, we harnessed virtualization technology to generate thousands of keystroke forgeries within a short time span. We point out that virtualization setup such as the one used in our experiments can also be exploited by an attacker to scale and speedup the attack. Khandaker Abir Rahman, Kiran S. Balagani, Vir V. Phoha |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2013 | Using Mussel-Inspired Self-Organization and Account Proxies to Obfuscate Workload Ownership and Placement in CloudsabstractRecent research has provided evidence indicating how a malicious user could perform coresidence profiling and public-to-private IP mapping to target and exploit customers which share physical resources. The attacks rely on two steps: resource placement on the target's physical machine and extraction. Our proposed solution, in part inspired by mussel self-organization, relies on user account and workload clustering to mitigate coresidence profiling. Users with similar preferences and workload characteristics are mapped to the same cluster. To obfuscate the public-to-private IP map, each cluster is managed and accessed by an account proxy. Each proxy uses one public IP address, which is shared by all clustered users when accessing their instances, and maintains the mapping to private IP addresses. We describe a set of capabilities and attack paths an attacker needs to execute for targeted coresidence, and present arguments to show how our approach disrupts the critical steps in the attack path for most cases. We then perform a risk assessment to determine the likelihood an individual user will be victimized, given that a successful nondirected exploit has occurred. Our results suggest that while possible, this event is highly unlikely. Justin L. Rice, Vir V. Phoha |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Examining a Large Keystroke Biometrics Dataset for Statistical-Attack OpeningsabstractResearch on keystroke-based authentication has traditionally assumed human impostors who generate forgeries by physically typing on the keyboard. With bots now well understood to have the capacity to originate precisely timed keystroke sequences, this model of attack is likely to underestimate the threat facing a keystroke-based system in practice. In this work, we investigate how a keystroke-based authentication system would perform if it were subjected to synthetic attacks designed to mimic the typical user. To implement the attacks, we perform a rigorous statistical analysis on keystroke biometrics data collected over a 2-year period from more than 3000 users, and then use the observed statistical traits to design and launch algorithmic attacks against three state-of-the-art password-based keystroke verification systems. Abdul Serwadda, Vir V. Phoha |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2012 | Dynamical System Theory for the Detection of Anomalous Behavior in Computer ProgramsabstractCode injection is a common approach which is utilized to exploit applications. We introduce some of the well-established techniques and formalisms of dynamical system theory into analysis of program behavior via system calls to detect code injections into an applications execution space. We accept a program as a blackbox dynamical system whose internals are not known, but whose output we can observe. The blackbox system observable in our model is the system calls the program makes. The collected system calls are treated as signals which are used to reconstruct the system’s phase space. Then, by using the well-established techniques from dynamical system theory, we quantify the amount of complexity of the system’s (program’s) behavior. The change in the behavior of a compromised system is detected as anomalous behavior compared with the baseline established from a clean program. We test the proposed approach against DARPA-98 dataset and a real-world exploit and present code injection experiments to show the applicability of our approach. Nitin Kanaskar, Remzi Seker, Jiang Bian 0001, Vir V. Phoha |
IEEE Trans. Syst. Man Cybern. Part C | 4 |
| 2011 | Web Farm-inspired Computational Cluster in the CloudabstractIn this paper, we introduce a web farm-inspired framework for dynamic and concurrent computational processing in the cloud. We compare and contrast this with the Hadoop-cloud framework, discuss the main problems associated with our approach, and give suggestions on ways to overcome said challenges. To implement the web-inspired framework, we use Node.js - a lightweight, single threaded, server-side framework which uses asynchronous callbacks to allow non-dependent operations (parallel-like sections) to execute while waiting for I/O events such as "fetching a file" or "writing a file to disk." We perform experiments to reveal two preliminary results that showcase the framework's functionality and scalability. One, for non-blocking operations, worker nodes which use Node.js servers are significantly faster than those which use traditional servers. In particular, a single Node.js is (on average) 2.11 times faster than one Ruby We brick server, and is (on average) 1.88 times faster than two Ruby We brick servers. Two, we find that increasing the number of worker nodes improves overall performance for blocking computational operations. As the number of worker nodes increase, the total execution time decreases exponentially and the number of requests per second increases linearly. Justin L. Rice, Vir V. Phoha, Patrice Cappelaere, Dan Mandl |
CloudCom | 2 |
| 2011 | On the discriminability of keystroke feature vectors used in fixed text keystroke authentication
Kiran S. Balagani, Vir V. Phoha, Asok Ray, Shashi Phoha |
Pattern Recognit. Lett. | 2 |
| 2010 | Size-based scheduling: a recipe for DDOS?abstractInternet traffic measurements have shown that the majority of the Internet's flows are short, while a small percentage of the largest flows are responsible for most of the bytes. To exploit this property for performance improvement in routers and Web servers, several studies have proposed size-based schedulings to offer preferential treatment to the shortest flows. In this work, we present analytical and simulation results which confirm that size-based scheduling will ease the task of launching DDOS attacks on the Internet. Abdul Serwadda, Vir V. Phoha, Idris A. Rai |
CCS | 2 |
| 2010 | On the Feature Selection Criterion Based on an Approximation of Multidimensional Mutual InformationabstractWe derive the feature selection criterion presented in [CHECK END OF SENTENCE] and [CHECK END OF SENTENCE] from the multidimensional mutual information between features and the class. Our derivation: 1) specifies and validates the lower-order dependency assumptions of the criterion and 2) mathematically justifies the utility of the criterion by relating it to Bayes classification error. Kiran S. Balagani, Vir V. Phoha |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2010 | On Guo and Nixon's Criterion for Feature Subset Selection: Assumptions, Implications, and Alternative OptionsabstractGuo and Nixon proposed a feature selection method based on maximizingI(x;Y), the multidimensional mutual information between feature vectorxand class variableY. Because computingI(x;Y) can be difficult in practice, Guo and Nixon proposed an approximation ofI(x;Y) as the criterion for feature selection. We show that Guo and Nixon's criterion originates from approximating the joint probability distributions inI(x;Y) by second-order product distributions. We remark on the limitations of the approximation and discuss computationally attractive alternatives to computeI(x;Y) . Kiran S. Balagani, Vir V. Phoha, S. Sitharama Iyengar, N. Balakrishnan 0001 |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2009 | Multi-hop scheduling and local data link aggregation dependant Qos in modeling and simulation of power-aware wireless sensor networksabstractIn this study of wireless sensor networks (WSN) protocols, the application Qos, system, and protocol performance metrics are measured for a large scalable wireless deployment using a typical wireless radio and an energy model. As there are many different types of WSN algorithms, we have categorized it into pro-active, re-active, and query driven information processing. A typical Qos is based on the useful lifetime of sensor nodes, after which reliability of the sensor data cannot be guaranteed and typically, a threshold such as a percentage of the sensor drains out of energy or a minimum through-put of real-time data from the sensor network is expected, which is used to compare the Qos of the routing algorithm. The results from lifetime based Qos, measured in simulation seconds, for the implemented protocols show that with varying sampled data sources for a BE Qos multi-hop deployment and varying percentage of cluster heads in a time- synchronized deployment, the lifetime is based on network size and protocol invariant. However, low sensing ranges result in dense networks, and therefore, it becomes necessary to achieve an efficient medium-access protocol subjected to power constraints. Scalability of sensor network applications are based on energy energy-harvesting techniques in which the various layers of the network inter-operate and extend the system network lifetime, the battery residual power per node, and the application reliability in terms of cross-layer energy savings. In this study, we have extended the lifetime metrics from a constant metrics into a break down of how much percentage of time is spent for Tx, Rx, and Idle tasks, respectively. This helps one to highlight the cross-layer energy dissipation per node and how the performance of an algorithm differs in terms of duty-cycling. Furthermore, we have shown that the energy savings due owing to the distributed algorithms in a large sensor network will not be practical without a complimentary lower-layer MAC. We show have demonstrated that the Qos is very much related to the ambient conditions, namely, are the Rx and Idle modes. From these preliminary results, we have added a new category of WSN protocols which are based ion the renewable energy resources, namely, the Fusion Ambient Renewable Measuring Sensors (FARMS). The study of sensor FARMS -harvesting applications allows one to measure the impact on Idle, Sleep, and renewable energy cycles as well as their unique deployment (density) needs, as all the sensor are not active(Rx) at all times. We have also shown that the efficiency of cross-layer Qos performance of routing algorithms with MAC losses has a long tail which is similarly observed in Power Law. In this sensor network model we like to show the complexity of clustering, messaging and data rate in terms of O(√(N) log N), O(N) and O(log2N) where N is the number of nodes. Vasanth Iyer, S. Sitharama Iyengar, Garimella Rama Murthy, Bertrand Hochet, Vir V. Phoha, M. B. Srinivas |
IWCMC | 5 |
| 2007 | On the Relationship Between Dependence Tree Classification Error and Bayes Error RateabstractWong and Poon [1] showed that Chow and Liu's tree dependence approximation can be derived by minimizing an upper bound of the Bayes error rate. Wong and Poon's result was obtained by expanding the conditional entropy H(w|X). We derive the correct expansion of H(w|X) and present its implication. Kiran S. Balagani, Vir V. Phoha |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2007 | K-Means+ID3: A Novel Method for Supervised Anomaly Detection by Cascading K-Means Clustering and ID3 Decision Tree Learning MethodsabstractIn this paper, we present "k-means+ID3", a method to cascade k-means clustering and the ID3 decision tree learning methods for classifying anomalous and normal activities in a computer network, an active electronic circuit, and a mechanical mass-beam system. The k-means clustering method first partitions the training instances into k clusters using Euclidean distance similarity. On each cluster, representing a density region of normal or anomaly instances, we build an ID3 decision tree. The decision tree on each cluster refines the decision boundaries by learning the subgroups within the cluster. To obtain a final decision on classification, the decisions of the k-means and ID3 methods are combined using two rules: 1) the nearest-neighbor rule and 2) the nearest-consensus rule. We perform experiments on three data sets: 1) network anomaly data (NAD), 2) Duffing equation data (DED), and 3) mechanical system data (MSD), which contain measurements from three distinct application domains of computer networks, an electronic circuit implementing a forced Duffing equation, and a mechanical system, respectively. Results show that the detection accuracy of the k-means+ID3 method is as high as 96.24 percent at a false-positive-rate of 0.03 percent on NAD; the total accuracy is as high as 80.01 percent on MSD and 79.9 percent on DED Shekhar R. Gaddam, Vir V. Phoha, Kiran S. Balagani |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2005 | A parallel decision tree-based method for user authentication based on keystroke patternsabstractWe propose a Monte Carlo approach to attain sufficient training data, a splitting method to improve effectiveness, and a system composed of parallel decision trees (DTs) to authenticate users based on keystroke patterns. For each user, approximately 19 times as much simulated data was generated to complement the 387 vectors of raw data. The training set, including raw and simulated data, is split into four subsets. For each subset, wavelet transforms are performed to obtain a total of eight training subsets for each user. Eight DTs are thus trained using the eight subsets. A parallel DT is constructed for each user, which contains all eight DTs with a criterion for its output that it authenticates the user if at least three DTs do so; otherwise it rejects the user. Training and testing data were collected from 43 users who typed the exact same string of length 37 nine consecutive times to provide data for training purposes. The users typed the same string at various times over a period from November through December 2002 to provide test data. The average false reject rate was 9.62% and the average false accept rate was 0.88%. Yong Sheng, Vir V. Phoha, S. M. Rovnyak |
IEEE Trans. Syst. Man Cybern. Part B | 2 |
| 2004 | Supervisory Control of Software SystemsabstractWe present a new paradigm to control software systems based on the supervisory control theory (SCT). Our method uses the SCT to model the execution of a software application by restricting the actions of the OS with little or no modifications in the underlying OS. Our approach can be generalized to any software application as the interactions of the application with the OS are modeled at a process level as a deterministic finite state automaton (DFSA) termed as a "plant." A "supervisor" that controls the plant is a DFSA synthesized from a set of control specifications. The supervisor operates synchronously with the plant to restrict the language accepted by the plant to satisfy the control specifications. Using the above method of control to mitigate faults, as a proof-of-concept, we implement two supervisors under the Redhat Linux 7.2 OS to mitigate overflow and segmentation faults in five different programs. We quantify the performance of the unsupervised and supervised plant by using a language measure and give methods to compute the measure using state transition cost matrix and characteristic vector. Vir V. Phoha, Amit U. Nadgar, Asok Ray, Shashi Phoha |
IEEE Trans. Computers | 1 |
| 2002 | An Adaptive Web Cache Access Predictor Using Neural Network
Ben Choi 0002, Vir V. Phoha |
IEA/AIE | 3 |
| 2001 | Web user clustering from access log using belief function
Yunjuan Xie, Vir V. Phoha |
K-CAP | 2 |
| 2001 | An interactive dynamic model for integrating knowledge management methods and knowledge sharing technology in a traditional classroomabstractThis paper reports an interactive dynamic model using Continuous Knowledge Management methods and Knowledge Sharing technology to integrate the acquisition of skills and relevant information (knowledge level) into diverse, individualized, concurrent learning processes in a traditional classroom setting. As opposed to a passive introduction of technology to facilitate the traditional learning processes a Web based active learning and continuous evaluation process was created which integrates objective scientific knowledge relating to course content, subjective knowledge obtained through personal interactions and empirical knowledge collected during the learning process. Knowledge Management, an emerging area of Artificial Intelligence, encompasses identifying, mapping, and managing intellectual assets to generate new knowledge for competitive advantage and for sharing of technology. The Web-based model of knowledge management discussed here allows a diverse group of learners to progressively interact and participate in the learning process, providing non-threatening self-evaluation and just-in-time individualized feedback to the learners and efficient tracking and supervision tools to the instructor. CS1003, a required general education class provides an ideal application of this model as the course draws from a diverse body of students ranging from history to math majors and from freshmen to seniors. The instructional design of this course using the interactive dynamics of Knowledge Management includes (i) provision of course archives and relevant static information as a passive repository, (ii) Web Discussion Forums, electronic chats and email communication for active learning and continuous interaction, (iii) an intelligent self-evaluation and grade reporting system for non-threatening self-testing and what-if analysis of performance, and (iv) a dynamic student feedback system including individualized supervision and anonymous feedback. Application of this instructional process enhanced the goals of the course from mere computer literacy to what the 1999 NRC Report calls Fluency in Information Technology (FIT). Three kinds of knowledge requirements are identified for FIT: (1) Contemporary skills, (2) Foundational concepts, and (3) Intellectual capabilities. This model is broadly applicable to extend the benefits of traditional classroom instruction to focus diverse intellectual abilities and interests in a collaborative learning process. Formal and informal evaluation support this claim, demonstrating that the transition from purely traditional teaching to a high degree of technology fluency can be painless, efficient and effective in preparing the students for a technology intensive information age. Vir V. Phoha |
SIGCSE | 1 |
| 1996 | Image recovery and segmentation using competitive learning in a layered networkabstractIn this study, we have used the principle of competitive learning to develop an iterative algorithm for image recovery and segmentation. Within the framework of Markov random fields (MRFs), the image recovery problem is transformed to the problem of minimization of an energy function; A local update rule for each pixel point is then developed in a stepwise fashion and is shown to be a gradient descent rule for an associated global energy function. The relationship of the update rule to Kohonen's update rule is shown. Quantitative measures of edge preservation and edge enhancement for synthetic images are introduced. As compared to recently published results using mean field approximation, our algorithm shows consistently better performance in edge preservation and comparable performance in enhancing within the boundaries. These results are based on simulation experiments on a set of synthetic images corrupted by Gaussian noise and on a set of real images. Vir V. Phoha, William J. B. Oldham |
IEEE Trans. Neural Networks | 1 |
| 1996 | Corrections to "Image Recovery and Segmentation Using Competitive Learning in a Layered Network
Vir V. Phoha, William J. B. Oldham |
IEEE Trans. Neural Networks | 1 |
| 1995 | Decision support and executive information systems : by Paul Gray (editor) (1994; Pages 469; Prentice Hall, Englewood Cliffs, NJ 07632, USA; ISBN 0-13-235789-5)
Vir V. Phoha |
Decis. Support Syst. | 1 |