Amirreza Niakanlahiji

dblp:192/7560 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
2since 2021 · last 2023
0000-0002-7282-1575ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-authorSystems, architecture and hardware · 1
YearPublicationVenuePosition
2023 MultiRHM: Defeating multi-staged enterprise intrusion attacks through multi-dimensional and multi-parameter host identity anonymization
Jafar Haadi Jafarian, Amirreza Niakanlahiji
Comput. Secur.2
2023 Toward practical defense against traffic analysis attacks on encrypted DNS traffic
Amirreza Niakanlahiji, Soeren Orlowski, Alireza Vahid, Jafar Haadi Jafarian
Comput. Secur.1
2020 ShadowMove: A Stealthy Lateral Movement Strategy
Amirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang 0001, Bei-tseng Chu
USENIX Security Symposium1
2019 IoCMiner: Automatic Extraction of Indicators of Compromise from Twitter
abstract
In recent years, cyber attacks have consistently grown in terms of volume, sophistication, coordination, and pervasiveness. Such attacks impose billions of dollars loss to companies and government entities annually. Sharing cyber threat intelligence (CTI) about ongoing attacks can significantly improve the current situation as many cyber attackers tend to reuse or share their network infrastructure, techniques, tactics, and procedures across multiple attacks. Therefore, many security professionals devote their time and effort on hunting cyber threats and sharing such valuable information with the public through public data sharing platforms such as social media and text sharing websites. However, due to the sheer volume of information that is being shared on such platforms; finding CTI information is tantamount to looking for a needle in a haystack. In this paper, we present a new scalable framework, IoCMiner, to automatically extract CTI, in special Indicators of Compromise, from Twitter. It utilizes a combination of graph theory, machine learning, and text mining technique to achieve its goal. IoCMiner relies on a reputation model to discover credible twitterers who publish CTI, and only tracks the tweet stream of such Twitter handles. Moreover, it employs a CTI classifier to further filter out non-CTI tweets from the observed data streams. Finally, IoCs uses a set of regular expression rules to extract IoCs from the identifies tweets. Through experimentation, we show the usefulness of IoCMiner in finding fresh IoCs from Twitter. In the course of four weeks, IoCMiner identified more than 1,200 IoCs, including malicious URLs. Only 10% of the URLs were already listed in public blacklist databases at the time of extraction. The number of URLs that appeared in blacklists increased to 26% after one week.
Amirreza Niakanlahiji, Lida Safarnejad, Reginald Harper, Bei-tseng Chu
IEEE BigData1
2019 All one needs to know about fog computing and related edge computing paradigms: A complete survey
abstract
With the Internet of Things (IoT) becoming part of our daily life and our environment, we expect rapid growth in the number of connected devices. IoT is expected to connect billions of devices and humans to bring promising advantages for us. With this growth, fog computing, along with its related edge computing paradigms, such as multi-access edge computing (MEC) and cloudlet, are seen as promising solutions for handling the large volume of security-critical and time-sensitive data that is being produced by the IoT. In this paper, we first provide a tutorial on fog computing and its related computing paradigms, including their similarities and differences. Next, we provide a taxonomy of research topics in fog computing, and through a comprehensive survey, we summarize and categorize the efforts on fog computing and its related computing paradigms. Finally, we provide challenges and future directions for research in fog computing.
Ashkan Yousefpour, Caleb Fung, Krishna Kadiyala, Fatemeh Jalali, Amirreza Niakanlahiji, Jason P. Jue
J. Syst. Archit.6
2019 WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target Defense
abstract
Existing mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers. They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility. Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning. This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers. In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications. Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification. Through rigorous evaluation, we show that WebMTD has very a low performance overhead. Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead.
Amirreza Niakanlahiji, Jafar Haadi Jafarian
Secur. Commun. Networks1
2018 A Natural Language Processing Based Trend Analysis of Advanced Persistent Threat Techniques
abstract
Advanced Persistent Threats (APTs) continue to be a major security problem in today's cyberspace. Understanding APT techniques is necessary for implementing an effective defense against APT attacks. In this paper, we first present a new information retrieval system, called SECCMiner, to assist cybersecurity professionals to more efficiently obtain actionable knowledge regarding APTs from a collected set of unstructured APT reports written in a natural language. It relies on a set of natural language processing and information retrieval techniques to identify adversarial techniques and tactics in given input reports. We then used SECCMiner to conduct a systematic study of existing APT techniques based on a repository of 445 technical reports, containing more than 1.9 million words, on recent APTs. The result includes trend analysis of common APT techniques since 2008, their inter-relationship, and the latest APT techniques that may become influential in the near future (e.g., using PowerShell scripts).
Amirreza Niakanlahiji, Jinpeng Wei, Bei-tseng Chu
IEEE BigData1
2018 PhishMon: A Machine Learning Framework for Detecting Phishing Webpages
abstract
Despite numerous research efforts, phishing attacks remain prevalent and highly effective in luring unsuspecting users to reveal sensitive information, including account credentials and social security numbers. In this paper, we propose PhishMon, a new feature-rich machine learning framework to detect phishing webpages. It relies on a set of fifteen novel features that can be efficiently computed from a webpage without requiring third-party services, such as search engines, or WHOIS servers. These features capture various characteristics of legitimate web applications as well as their underlying web infrastructures. Emulation of these features is costly for phishers as it demands to spend significantly more time and effort on their underlying infrastructures and web applications; in addition to the efforts required for replicating the appearance of target websites. Through extensive evaluation on a dataset consisting of 4,800 distinct phishing and 17,500 distinct benign webpages, we show that PhishMon can distinguish unseen phishing from legitimate webpages with a very high degree of accuracy. In our experiments, PhishMon achieved 95.4% accuracy with 1.3% false positive rate on a dataset containing unique phishing instances.
Amirreza Niakanlahiji, Bei-tseng Chu, Ehab Al-Shaer
ISI1