VLDB 2026 Research / reviewers in the wild / expert
Anand Mudgerikar
dblp:189/9270
· DBLP profile ↗
11ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0002-7148-0000ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 2 first-author · 4 since 2021Security and privacy · 4 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Kalis2.0 - A SECaaS-Based Context-Aware Self-Adaptive Intrusion Detection System for IoTabstractThe wide variety of application domains makes the Internet of Things (IoT) quite unique among other types of computer networks: IoT networks can be made of devices of different types, i.e., characterized by different hardware, functionalities, computing capabilities, and also network topology and communication protocols may drastically change from one IoT application to another. Such a heterogeneity requires ad-hoc security solutions, as security techniques that are effective in one IoT context may not be so in another context. Furthermore, IoT networks are ever-evolving by their very nature as smart devices can be easily added or removed. These factors call for the design of security tools capable of adapting themselves to the specific IoT instance, but also to the continuous network changes. In this paper we propose a context-aware, Security-as-a-Service based approach for intrusion detection whereby an IDS (i) autonomously collects information about the monitored system, (ii) chooses the best detection strategy accordingly, and (iii) modifies the detection strategy as the network evolves over time. This comprehensive approach to intrusion detection is an attempt to face the heterogeneity which characterizes the IoT in all its aspects, making it possible the design of a security tool able to be self-adaptive and context-aware, that is, effective in different and evolving IoT scenarios with little or no human intervention. Antonino Rullo, Daniele Midi, Anand Mudgerikar, Elisa Bertino |
IEEE Internet Things J. | 3 |
| 2024 | ARIoTEDef: Adversarially Robust IoT Early Defense System Based on Self-Evolution against Multi-step AttacksabstractInternet of Things (IoT) cyber threats, exemplified by jackware and crypto mining, underscore the vulnerability of IoT devices. Due to the multi-step nature of many attacks, early detection is vital for a swift response and preventing malware propagation. However, accurately detecting early-stage attacks is challenging, as attackers employ stealthy, zero-day, or adversarial machine learning to evade detection. To enhance security, we propose ARIoTEDef, an Adversarially Robust IoT Early Defense system, which identifies early-stage infections and evolves autonomously. It models multi-stage attacks based on a cyber kill chain and maintains stage-specific detectors. When anomalies in the later action stage emerge, the system retroactively analyzes event logs using an attention-based sequence-to-sequence model to identify early infections. Then, the infection detector is updated with information about the identified infections. We have evaluated ARIoTEDef against multi-stage attacks, such as the Mirai botnet. Results show that the infection detector’s average F1 score increases from 0.31 to 0.87 after one evolution round. We have also conducted an extensive analysis of ARIoTEDef against adversarial evasion attacks. Our results show that ARIoTEDef is robust and benefits from multiple rounds of evolution. Mengdie Huang, Hyunwoo Lee 0001, Ashish Kundu, Xiaofeng Chen 0001, Anand Mudgerikar, Ninghui Li 0001, Elisa Bertino |
ACM Trans. Internet Things | 5 |
| 2023 | Intelligent Security Aware Routing: Using Model-Free Reinforcement LearningabstractWith the emergence and successful deployment of software defined networks (SDN), zero-trust security architecture, and network function virtualization (NFV) in large scale modern enterprise and 5G networks, it is possible to build ‘smart’ network controllers that leverage machine learning (ML) to learn policies for optimal and secure traffic engineering. Deep Reinforcement Learning (DRL) is an effective technique for building such smart controllers because of its model-free nature and ability to learn policies dynamically through experience without requiring extensive training data. However, conventional DRL frameworks are geared to maximize functionality and do not take network security into account. To address such a gap, we propose a security-aware DRL framework, STE-SDN that learns ‘intelligent policies' for traffic engineering (routing) to both maximize functionality gain and minimize security risk. We instantiate our framework in a simulated SDN environment of 5000 nodes with different security services and three attack classes: DDoS, Web-based and Brute-Force attacks. We then analyze our framework using the CICIDS-17 dataset in terms of performance and effectiveness in mitigating security risks. We find that our RL framework reduces detection loss by 85.8% and maintains close to optimal performance for 78.8%. Anand Mudgerikar, Elisa Bertino |
ICCCN | 1 |
| 2022 | An Infection-Identifying and Self-Evolving System for IoT Early Defense from Multi-Step Attacks
Hyunwoo Lee 0001, Anand Mudgerikar, Ashish Kundu, Ninghui Li 0001, Elisa Bertino |
ESORICS (2) | 2 |
| 2021 | A Security-Constrained Reinforcement Learning Framework for Software Defined NetworksabstractReinforcement Learning (RL) is an effective technique for building ‘smart’ SDN controllers because of its model-free nature and ability to learn policies online without requiring extensive training data. However, as RL agents are geared to maximize functionality and explore the environment without constraints, security can be breached. In this paper, we propose Jarvis-SDN, a RL framework that constrains explorations by taking security into account. In Jarvis-SDN, the RL agent learns ‘intelligent policies’ which maximize functionality but not at the cost of security. Standard network flow based attack sig-natures obtained from intrusion detection system (IDS) datasets cannot be used as policies because they do not conform to the state model of the RL framework and thus have poor accuracy and high false positives. To address such issue, the security policies for constraining explorations in Jarvis-SDN are learnt in a semi-supervised manner in the form of ‘partial attack signatures’ from packet captures of IDS datasets that are then encoded in the objective function of the RL based optimization framework. These signatures are learnt using Deep Q-Networks (DQN). Our analysis shows that DQN based attack signatures perform better than classical machine learning techniques, like decision trees, random forests and deep neural networks (DNN), for common network attacks. We instantiate our framework for a SDN controller with the goal of intelligent rate control to further analyze the effectiveness of the attack signatures. Anand Mudgerikar, Elisa Bertino, Jorge Lobo 0001, Dinesh C. Verma |
ICC | 1 |
| 2020 | Jarvis: Moving Towards a Smarter Internet of ThingsabstractThe deployment of Internet of Things (IoT) combined with cyber-physical systems is resulting in complex environments comprising of various devices interacting with each other and with users through apps running on computing platforms like mobile phones, tablets, and desktops. In addition, the rapid advances in Artificial Intelligence are making those devices able to autonomously modify their behaviors through the use of techniques such as reinforcement learning (RL). It is clear however that ensuring safety and security in such environments is critical. In this paper, we introduce Jarvis, a constrained RL framework for IoT environments that determines optimal devices actions with respect to user-defined goals, such as energy optimization, while at the same time ensuring safety and security. Jarvis is scalable and context independent in that it is applicable to any IoT environment with minimum human effort. We instantiate Jarvis for a smart home environment and evaluate its performance using both simulated and real world data. In terms of safety and security, Jarvis is able to detect 100% of the 214 manually crafted security violations collected from prior work and is able to correctly filter 99.2% of the user-defined benign anomalies and malfunctions from safety violations. For measuring functionality benefits, Jarvis is evaluated using real world smart home datasets with respect to three user required functionalities: energy use minimization, energy cost minimization, and temperature optimization. Our analysis shows that Jarvis provides significant advantages over normal device behavior in terms of functionality and over general unconstrained RL frameworks in terms of safety and security. Anand Mudgerikar, Elisa Bertino |
ICDCS | 1 |
| 2019 | E-Spion: A System-Level Intrusion Detection System for IoT DevicesabstractAs the Internet of Things (IoT) grows at a rapid pace, there is a need for an effective and efficient form of security tailored for IoT devices. In this paper, we introduce E-Spion, an anomaly-based system level Intrusion Detection System (IDS) for IoT devices. E-Spion profiles IoT devices according to their 'behavior' using system level information, like running process parameters and their system calls, in an autonomous, efficient, and scalable manner. These profiles are then used to detect anomalous behaviors indicative of intrusions. E-Spion provides three layers of detection with increasing detection efficiency but at the same time higher overhead costs on the devices. We have extensively evaluated E-Spion using a comprehensive dataset of 3973 IoT malware samples in our testbed. We observe a detection efficiency ranging from 78% to 100% depending on the layers of detection employed. We provide an analysis and comparison of the different layers of E-Spion in terms of detection accuracy and overhead costs. We also analyze the behavior of the malware samples in terms of our device logs at each layer. Anand Mudgerikar, Elisa Bertino |
AsiaCCS | 1 |
| 2018 | RWGuard: A Real-Time Detection System Against Cryptographic Ransomware
Shagufta Mehnaz, Anand Mudgerikar, Elisa Bertino |
RAID | 2 |
| 2017 | Kalis - A System for Knowledge-Driven Adaptable Intrusion Detection for the Internet of ThingsabstractIn this paper, we introduce Kalis, a self-adapting, knowledge-driven expert Intrusion Detection System able to detect attacks in real time across a wide range of IoT systems. Kalis does not require changes to existing IoT software, can monitor a wide variety of protocols, has no performance impact on applications on IoT devices, and enables collaborative security scenarios. Kalis is the first comprehensive approach to intrusion detection for IoT that does not target individual protocols or applications, and adapts the detection strategy to the specific network features. Extensive evaluation shows that Kalis is effective and efficient in detecting attacks to IoT systems. Daniele Midi, Antonino Rullo, Anand Mudgerikar, Elisa Bertino |
ICDCS | 3 |
| 2017 | Heimdall: Mitigating the Internet of Insecure ThingsabstractThe Internet of Things (IoT) is built of many small smart objects continuously connected to the Internet. This makes these devices an easy target for attacks exploiting vulnerabilities at the network, application, and mobile level. With that it comes as no surprise that distributed denial of service attacks leveraging these vulnerable devices have become a new standard for effective botnets. In this paper, we propose Heimdall, a whitelist-based intrusion detection technique tailored to IoT devices. Heimdall operates on routers acting as gateways for IoT as a homogeneous defense for all devices behind the router. Our experimental results show that our defense mechanism is effective and has minimal overhead. Javid Habibi, Daniele Midi, Anand Mudgerikar, Elisa Bertino |
IEEE Internet Things J. | 3 |
| 2017 | Real-Time Digital Signatures for Time-Critical NetworksabstractThe secure and efficient operation of time-critical networks, such as vehicular networks, smart-grid, and other smart-infrastructures, is of primary importance in today's society. It is crucial to minimize the impact of security mechanisms over such networks so that the safe and reliable operations of time-critical systems are not being interfered. For instance, if the delay introduced by the crypto operations negatively affects the time available for braking a car before a collision, the car may not be able to safely stop in time. In particular, as a primary authentication mechanism, existing digital signatures introduce a significant computation and communication overhead, and therefore are unable to fully meet the real-time processing requirements of such time-critical networks. In this paper, we introduce a new suite of real-time digital signatures referred to as Structure-free and Compact Real-time Authentication (SCRA), supported by hardware acceleration, to provide delay-aware authentication in time-critical networks. SCRA is a novel signature framework that can transform any secure aggregate signature into a signer efficient signature. We instantiate SCRA framework with condensed-RSA, BGLS, and NTRU signatures. Our analytical and experimental evaluation validates the significant performance advantages of SCRA schemes over their base signatures and the state-of-the-art schemes. Moreover, we push the performance of SCRA schemes to the edge via highly optimized implementations on vehicular capable system-on-chip as well as server-grade general purpose graphics processing units. We prove that SCRA is secure (in random oracle model) and show that SCRA can offer an ideal alternative for authentication in time-critical applications. Attila A. Yavuz, Anand Mudgerikar, Ankush Singla, Ioannis Papapanagiotou, Elisa Bertino |
IEEE Trans. Inf. Forensics Secur. | 2 |