Geeta Yadav

dblp:184/1834 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0003-0085-2708ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 2 first-authorSecurity and privacy · 2 · 2 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2026 Vuln2Action: An LLM-based framework for generating vulnerability reproduction steps and mapping exploits
Geeta Yadav
J. Inf. Secur. Appl.2
2026 Vulnerabilities in Machine Learning for cybersecurity: Current trends and future research directions
abstract
Machine learning (ML) has become integral to cybersecurity applications, e.g., phishing detection, intrusion detection systems, malware analysis, and botnet identification. However, the integration of ML also exposes novel attack surfaces that can be exploited through adversarial machine learning (AML). While prior surveys have examined individual threats or defenses, they often focus narrowly on specific stages, e.g., training or testing. In contrast, in this paper, we provide the first comprehensive survey of adversarial attacks and defenses across the entire ML development life cycle within the cybersecurity domain. Using a structured methodology, we categorize vulnerabilities and countermeasures at each stage, data gathering, model training, testing, deployment, and maintenance, highlighting cross-stage interactions and emerging distributed threat models. Our study addresses key gaps in current defenses, including their limited generalizability and lack of standardized evaluation practices, and identifies promising directions, e.g., lifecycle-aware robustness, distributed resilience, and the integration of statistical with generative methods. Consolidating fragmented research into an end-to-end perspective, this study advances the understanding of AML in cybersecurity and outlines a roadmap for building more trustworthy, and resilient ML-driven security systems.
Shantanu Pal, Geeta Yadav, Zahra Jadidi, Ahsan Habib 0003, Md Palash Uddin, Chandan K. Karmakar, Sandeep K. Shukla
J. Inf. Secur. Appl.2
2025 MisConfAI: A Framework for Detecting Configuration Vulnerabilities in Complex Systems
abstract
Configuration vulnerabilities have emerged as a critical challenge in securing complex information systems. Unlike traditional software bugs, these vulnerabilities originate from insecure system settings in components such as databases, web servers, and cloud environments. Common misconfigurations such as using default credentials, enabling skip-grant-tables=1, or setting bind-address=0.0.0.0 can significantly compromise security, leading to issues like unauthorized access (CWE-287) and unintended public network exposure (CWE-284). Despite progress in automated vulnerability scanning and patch management, configuration-related issues remain inadequately addressed due to their contextual dependencies and the limitations of conventional tools in interpreting system semantics.In this work, we present MisConfAI, a transformer-driven framework for automated detection of configuration vulnerabilities. MisConfAI first models syntactic variations and lexical deviations in configuration files, then maps risky settings to known vulnerability classes (e.g., CWE) and compliance standards such as the CIS Benchmarks. We evaluate its efficacy across multiple pre-trained language models, including BERT, CodeBERT, RoBERTa, ELECTRA, and XLNet. To ensure operational fidelity, the framework is coupled with a dynamic analysis layer that provisions containerized testbeds via Docker to replicate real-world deployment environments.
Savi Juneja, Geeta Yadav
NCA2
2021 Global Monitor using SpatioTemporally Correlated Local Monitors
abstract
An exponential increase in the IIoT network leads to complex interdependencies between the network devices. These network devices are designed to perform a fixed set of tasks and log their activities as system logs. These logs act as an excellent source of information to understand a system state. The device networks are prone to sophisticated Multi-host Multistep (MhMs) attacks, which may not be detected using machine learning-based isolated system security solutions and need a large amount of attack data for training. This led to the development of Central Monitoring Systems (CMSs) that need centralized system log collection, hence suffer from latency, network bandwidth and data loss due to network congestion. It leads to the requirement for a global monitoring system to detect ongoing MhMs attacks in real-time with low false positives and low network overhead. In this direction, we propose GLoM: a global monitor using spatio-temporally correlated local monitors to detect ongoing MhMs attacks. It leverages deep learning-based algorithms to detect anomalies with high accuracy and attack graphs to map various anomalous behavior to detect MhMs attacks. GLoM is a two-stage hybrid model, where the workload is divided between Local Monitors (LM) and Global Monitor (GM). LMs use LSTM to detect the abnormal activities of a system leveraging syslogs and forward anomalous logs to the GM. At the same time, GM discovers possible vulnerabilities on the devices followed by generating Possible Attack Graphs (PAG) by mapping the prerequisites and post-conditions required to exploit a vulnerability. GM is responsible for further analysis of the anomalous logs to find whether the logs in the current window resemble to vulnerability (CVE) exploit logs using a rule-based attack pattern repository. We track all the successful CVE exploits observed using anomalous logs followed by the generation of Evidence List (EL)) for each system. The similarity index between attack-paths and EL identifies the most probable attack scenario an adversary may be following. Using LMs, network communication overhead decreased by 88% on the publicly available dataset OpenStack (Loghub). LSTM based anomaly detection shows 99% accuracy in detecting the anomalous logs with an average anomalous log prediction overhead of 0.6 msec. We achieved 98% and 97% accuracy to generate the pre-requisites and post-conditions of a vulnerability. We evaluate GLoM's efficiency to detect MhMs attacks using a case study evaluation on a local testbed.
Geeta Yadav, Kolin Paul
NCA1
2020 SmartPatch: a patch prioritization framework for SCADA chain in smart grid
abstract
Supervisory Control and Data Acquisition (SCADA) systems are the industrial control systems and operational infrastructure that can monitor and control the electricity grid. Electricity grids are increasingly transforming from the one-directional way of generating, transmitting, and distributing electricity to smart grids that are multi-directional in the way they monitor, automate, and remotely operate the power sector. SCADA systems are increasingly under cyber attacks illustrating growing vulnerabilities to the smart grids. The U.S. power industry notes the importance of SCADA chain cyber risks and the need to take proactive measures (timely patching of vulnerabilities) to mitigate the risks. However, not all vulnerabilities are always exploited by attackers; and not all vulnerabilities can be patched in resource-constrained scenarios. Therefore, the patch sequence needs to be strategic and efficient.
Geeta Yadav, Praveen Gauravaram, Arun Kumar Jindal
MobiCom1
2019 PatchRank: Ordering updates for SCADA systems
abstract
Securing SCADA is a challenging task for the research community as well as the industry. SCADA networks form the basis of industrial productivity. Industry 4.0 is likely to see more expansive use of SCADA & IIoT for enhanced productivity. These complex systems consist of numerous vulnerable subsystems. It is challenging for the timely application of patches to all the vulnerabilities, due to resource constraints and the high cost of the patch process. Usually, the more severe (attack probable) weaknesses are patched first to secure the system. Often organizations ignore the vulnerabilities in the “critical” node in favor of securing a vulnerability in an isolated subsystem. Therefore, the sequence in which patches are applied needs to be prioritized. State of the art indicates that patch prioritization is primarily an art rather than any significant methodology being followed.This paper proposes PatchRank - a patch prioritization method for the SCADA systems based on Viable System Model, Common Vulnerability Scoring System, and Game theory. PatchRank provides a ranking of vulnerable nodes/subsystems as well as a ranking of subsystem vulnerabilities, thereby allowing well-formed strategies for patch management. This paper also proposes a “Usable Secure State” to define a security assurance level. A comparative analysis of PatchRank with other benchmark algorithms, i.e., SecureRank, CVSS, and density based prioritization shows that PatchRank converges to a usable secure state faster.
Geeta Yadav, Kolin Paul
ETFA1
2019 Assessment of SCADA System Vulnerabilities
abstract
SCADA system is an essential component for automated control and monitoring in many of the Critical Infrastructures (CI). Cyber-attacks like Stuxnet, Aurora, Maroochy on SCADA systems give us clear insight about the damage a determined adversary can cause to any country's security, economy, and health-care systems. An in-depth analysis of these attacks can help in developing techniques to detect and prevent attacks. In this paper, we focus on the assessment of SCADA vulnerabilities from the widely used National Vulnerability Database (NVD) until May 2019. We analyzed the vulnerabilities based on severity, frequency, availability, integrity and confidentiality impact, and Common Weaknesses. The number of reported vulnerabilities are increasing yearly. Approximately 89% of the attacks are the network exploits severely impacting availability of these systems. About 19% of the weaknesses are due to buffer errors due to the use of insecure and legacy operating systems. We focus on finding the answer to four key questions that are required for developing new technologies for securing SCADA systems. We believe this is the first study of its kind which looks at correlating SCADA attacks with publicly available vulnerabilities. Our analysis can provide security researchers with useful insights into SCADA critical vulnerabilities and vulnerable components, which need attention. We also propose a domain-specific vulnerability scoring system for SCADA systems considering the interdependency of the various components.
Geeta Yadav, Kolin Paul
ETFA1