Mehdi Akbari Gurabi

dblp:187/5893 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
2since 2021 · last 2022
0000-0002-1734-8367ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2022 SASP: a Semantic web-based Approach for management of Sharable cybersecurity Playbooks
abstract
In incident management, response and recovery actions are designed to effectively mitigate ongoing or future cyberattacks. A security playbook consists of a pipeline of instructions to document necessary response and recovery actions to deal with a specific type of incident. Since many organisations lack the resources, expertise and know-how to handle incidents, sharing playbooks across organisations could significantly improve their response capabilities against cyberattacks. However, playbooks are often organisation specific and usually not machine-readable, sharable and interoperable. In this work, we propose a semantic web-based approach to capture the knowledge of incident response and recovery steps to support sharing of playbooks based on a standardised and common vocabulary. To further demonstrate our approach, we introduce SASP, a proof-of-concept tool based on Semantic MediaWiki for playbook management. In this paper, we describe the key requirements from incident handlers to share playbooks, SASP architecture design, and its core components and functionalities. We then discuss the results of our user-centric evaluation conducted on members of different Security Operation Centres and the further potential of the solution.
Mehdi Akbari Gurabi, Avikarsha Mandal, Jan Popanda, Robert Rapp, Stefan Decker
ARES1
2021 Towards Privacy-Preserving Classification-as-a-Service for DGA Detection
abstract
Domain generation algorithm (DGA) classifiers can be used to detect and block the establishment of a connection between bots and their command-and-control server. Classification-as-a-service (CaaS) can separate the classification of domain names from the need for real-world training data, which are difficult to obtain but mandatory for well performing classifiers. However, domain names as well as trained models may contain privacy-critical information which should not be leaked to either the model provider or the data provider. Several generic frameworks for privacy-preserving machine learning (ML) have been proposed in the past that can preserve data and model privacy. Thus, it seems high time to combine state-of-the-art DGA classifiers and privacy-preservation frameworks to enable privacy-preserving CaaS, preserving both, data and model privacy for the DGA detection use case. In this work, we examine the real-world applicability of four generic frameworks for privacy-preserving ML using different state-of-the-art DGA detection models. Our results show that out-of-the-box DGA detection models are computationally infeasible for privacy-preserving inference in a real-world setting. We propose model simplifications that achieve a reduction in inference latency of up to 95%, and up to 97% in communication complexity while causing an accuracy penalty of less than 0.17%. Despite this significant improvement, real-time classification is still not feasible in a traditional two-party setting. Thus, more efficient secure multi-party computation (SMPC) or homomorphic encryption (HE) schemes are required to enable real-world feasibility of privacy-preserving CaaS for DGA detection.
Arthur Drichel, Mehdi Akbari Gurabi, Tim Amelung, Ulrike Meyer
PST2
2018 Hardware based Two-Factor User Authentication for the Internet of Things
abstract
In the distributed Internet of Things (IoT) architecture, sensors collect data from vehicles, home appliances and office equipment and other environments. Various objects contain the sensor which process data, cooperate and exchange information with other embedded devices and end users in a distributed network. It is important to provide end-to-end communication security and an authentication system to guarantee the security and reliability of the data in such a distributed system. Two-factor authentication is a solution to improve the security level of password-based authentication processes and immunized the system against many attacks. At the same time, the computational and storage overhead of an authentication method also needs to be considered in IoT scenarios. For this reason, many cryptographic schemes are designed especially for the IoT; however, we observe a lack of laboratory hardware test beds and modules, and universal authentication hardware modules. This paper proposes a design and analysis for a hardware module in the IoT which allows the use of two-factor authentication based on smart cards, while taking into consideration the limited processing power and energy reserves of nodes, as well as designing the system with scalability in mind.
Mehdi Akbari Gurabi, Omar Alfandi, Arne Bochem, Dieter Hogrefe
IWCMC1
2016 Calculating the Speed of Vehicles Using Wireless Sensor Networks
abstract
Speed measurement is an important issue for some types of Wireless Sensor Networks (WSN), especially for Vehicular Ad-hoc Networks (VANETs).However, calculating this value is error-prone and costly.This report intends to demonstrate the calculation of speed of an object without the use of any additional devices or sensor boards, only using Received Signal Strength Indication (RSSI) for localization of the vehicles and time calculation using synchronization.We implemented these methods in actual IRIS motes, and tested them.The results show that, while not perfectly accurate, our method proved to be reliable and close to the real speed.In addition, the results do not have any linear correlation in divergence of real speed and calculated speed, which means the system avoids systematic errors.
Omar Alfandi, Arne Bochem, Alberto Rivera Díaz, Mehdi Akbari Gurabi, Md. Istiak Mehedi, Dieter Hogrefe
FedCSIS4