VLDB 2026 Research / reviewers in the wild / expert
Ankur Chowdhary
dblp:192/7563
· DBLP profile ↗
12ranked-venue papers
4as first author
6since 2021 · last 2023
0000-0001-7131-067XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Unraveled - A semi-synthetic dataset for Advanced Persistent ThreatsabstractUnraveled is a novel cybersecurity dataset capturing Advanced Persistent Threat (APT) attacks not available in the public domain. Existing cybersecurity datasets lack coherent information about sophisticated and persistent cyber-attack features, including attack planning and deployment, stealthiness of the attacker(s), longer dorm period between attack activities, etc. Our APT attack scenario in Unraveled is implemented on a real network system established on a cloud platform to emulate an organization’s network system. The new dataset provides a comprehensive network flow and host-level log information about the normal user(s) traffic and the cyber attacks traffic. To emulate realistic network traffic scenarios, Unraveled also includes attacks at different skills reflecting a typical organization’s threat posture, and by utilizing APT attack information from one of the well-known APT attack databases, i.e., MITRE’s APT-group database. Furthermore, we design and develop an Employee Behavior Generation (EBG) model to emulate multiple normal employees’ traffic and activities during a 6-week time period based on their pre-defined business functions. Using well-known machine learning models for anomaly detection, we show that the APT attack activities in Unraveled are hardly detected, indicating the need for more effective solutions that are based on datasets representing real world APT attacks. Sowmya Myneni, Kritshekhar Jha, Abdulhakim Sabur, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Dijiang Huang |
Comput. Networks | 6 |
| 2022 | SmartDefense: A distributed deep defense against DDoS attacks with edge computing
Sowmya Myneni, Ankur Chowdhary, Dijiang Huang, Adel Alshamrani |
Comput. Networks | 2 |
| 2022 | Toward scalable graph-based security analysis for cloud networks
Abdulhakim Sabur, Ankur Chowdhary, Dijiang Huang, Adel Alshamrani |
Comput. Networks | 2 |
| 2022 | Object Oriented Policy Conflict Checking Framework in Cloud Networks (OOPC)abstractSoftware-Defined Networking (SDN) provides a programmable framework for multi-tenant cloud network management and orchestration. The end-to-end packet processing induced by virtual network functions (VNFs) like stateless firewall, load balancer, intrusion detection, and prevention system (IDPS) in a network involves the processing of network traffic through security policies matching the traffic pattern defined in security rules of individual VNF. The conflicting rules in terms of traffic match and conflicting actions can lead to a) violation of security requirements (authentication and authorization bypass) b) mission requirements - the presence of redundant rules (increased latency, reduced throughput). We present a new object-oriented policy conflict detection and resolution framework (OOPC), which analyzes the rule dependency relationships between the rules of heterogeneous virtual network functions (VNFs) and creates a VNF-Graph. The rules are analyzed using object-oriented dependencies between the address space and actions of VNF rules. OOPC utilizes a compact VNF-Graph, which leads to a reduction in search complexity when analyzing new security policies. Our security policy composition in our framework OOPC achieves 37 percent lower latency in policy graph composition than previous work. The proposed solution performs 20 percent faster security policy conflict detection on a cloud network with 60k OpenFlow rules than prior frameworks that serve a similar purpose. Ankur Chowdhary, Abdulhakim Sabur, Dijiang Huang, Myong H. Kang, James Kirby |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | SCVS: On AI and Edge Clouds Enabled Privacy-preserved Smart-city Video Surveillance ServicesabstractVideo surveillance systems are increasingly becoming common in many private and public campuses, city buildings, and facilities. They provide many useful smart campus/city monitoring and management services based on data captured from video sensors. However, the video surveillance services may also breach personally identifiable information, especially human face images being monitored; therefore, it may potentially violate the privacy of human subjects involved. To address this privacy issue, we introduced a large-scale distributed video surveillance service model, called Smart-city Video Surveillance (SCVS). SCVS is a video surveillance data collection and processing platform to identify important events, monitor, protect, and make decisions for smart campus/city applications. In this article, the specific research focus is on how to identify and anonymize human faces in a distributed edge cloud computing infrastructure. To preserve the privacy of data during video anonymization, SCVS utilizes a two-step approach: (i) parameter server-based distributed machine learning solution, which ensures that edge nodes can exchange parameters for machine learning-based training. Since the dataset is not located on a centralized location, the data privacy and ownership are protected and preserved. (ii) To improve the machine learning model’s accuracy, we presented an asynchronous training approach to protect data and model privacy for both data owners and data users, respectively. SCVS adopts an in-memory encryption approach, where edge computing nodes collect and process data in the memory of edge nodes in encrypted form. This approach can effectively prevent honest but curious attacks. The performance evaluation shows the presented privacy protection platform is efficient and effective compared to traditional centralized computing models as presented in Section 5 . Sowmya Myneni, Garima Agrawal, Yuli Deng, Ankur Chowdhary, Neha Vadnere, Dijiang Huang |
ACM Trans. Internet Things | 4 |
| 2022 | Intent-Driven Security Policy Management for Software-Defined SystemsabstractDifferent network controllers are utilized in a multi-domain software-defined systems (SDx) to manage the networking resources. However, these controllers operate using a different high-level language (intent). Thus, the admin needs to perform cross-layer translation from the user requirements to the underlying network controller format, increasing human-in-the-loop overhead. There are two primary security and management challenges involved in managing multi-domain controllers. The first challenge is how to design an SDN controller language that can effectively convert human-specified networking policies at the control plane into the network flow rules level at the data plane. The second challenge is how to reduce the complexity of network flow rules conflict checking at the data plane. To address these challenges, we present a new intent-based security policy enforcement solution called INTPOL. First, INTPOL provides a unified intent rules that abstracts the network admin from the underlying network controller’s format. Second, INTPOL develops a networking service solution to use a bounded formal model for network service compliance checking that significantly reduces the complexity of flow rules conflicts checking at the data plane level. Finally, INTPOL is expendable from a single SDN domain to multiple SDN domains and hybrid networks by applying network service function chaining (SFC) for inter-domain policy management. Ankur Chowdhary, Abdulhakim Sabur, Neha Vadnere, Dijiang Huang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Autonomous Security Analysis and Penetration TestingabstractSecurity Assessment of large networks is a challenging task. Penetration testing (pentesting) is a method of analyzing the attack surface of a network to find security vulnerabilities. Current network pentesting techniques involve a combination of automated scanning tools and manual exploitation of security issues to identify possible threats in a network. The solution scales poorly on a large network. We propose an autonomous security analysis and penetration testing framework (ASAP) that creates a map of security threats and possible attack paths in the network using attack graphs. Our framework utilizes: (i) state of the art reinforcement learning algorithm based on Deep-Q Network (DQN) to identify optimal policy for performing pentesting testing, and (ii) incorporates domain-specific transition matrix and reward modeling to capture the importance of security vulnerabilities and difficulty inherent in exploiting them. ASAP framework generates autonomous attack plans and validates them against real-world networks. The attack plans are generalizable to complex enterprise network, and the framework scales well on a large network. Our empirical evaluation shows that ASAP identifies non-intuitive attack plans on an enterprise network. The DQN planning algorithm employed scales well on a large network ~ 60 -70(s) for generating an attack plan for network with 300 hosts. Ankur Chowdhary, Dijiang Huang, Jayasurya Sevalur Mahendran, Daniel Romo, Yuli Deng, Abdulhakim Sabur |
MSN | 1 |
| 2019 | TRUFL: Distributed Trust Management Framework in SDNabstractSoftware Defined Networking (SDN) has emerged as a revolutionary paradigm to manage cloud infrastructure. SDN lacks scalable trust setup and verification mechanism between Data Plane-Control Plane elements, Control Plane elements, and Control Plane-Application Plane. Trust management schemes like Public Key Infrastructure (PKI) used currently in SDN are slow for trust establishment in a larger cloud environment. We propose a distributed trust mechanism - TRUFL to establish and verify trust in SDN. The distributed framework utilizes parallelism in trust management, in effect faster transfer rates and reduced latency compared to centralized trust management. The TRUFL framework scales well with the number of OpenFlow rules when compared to existing research works. Ankur Chowdhary, Dijiang Huang, Adel Alshamrani, Myong H. Kang, Anya Kim, Alexander Velazquez |
ICC | 1 |
| 2019 | S3: A DFW-based Scalable Security State Analysis Framework for Large-Scale Data Center Networks
Abdulhakim Sabur, Ankur Chowdhary, Dijiang Huang, Myong H. Kang, Anya Kim, Alexander Velazquez |
RAID | 2 |
| 2019 | Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud EnvironmentsabstractThe ease of programmability in Software-Defined Networking (SDN) makes it a great platform implementation of various initiatives that involve application deployment, dynamic topology changes, and decentralized network management in a multi-tenant data center environment. However, implementing security solutions in such an environment is fraught with policy conflicts and consistency issues with the hardness of this problem being affected by the distribution scheme for the SDN controllers. In this paper we present Brew, a security policy analysis framework implemented on an OpenDaylight SDN controller, that has comprehensive conflict detection and resolution modules to ensure that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free security policy implementation and preventing information leakage. We present techniques for global prioritization of flow rules in a decentralized environment, extend firewall rule conflict classification from a traditional environment to SDN flow rule conflicts by recognizing and classifying conflicts stemming from cross-layer conflicts and provide strategies for unassisted resolution of these conflicts. Alternately, if administrator input is desired to resolve conflicts, a novel visualization scheme is implemented to help the administrators view the conflicts graphically. We demonstrate the correctness, feasibility and scalability of our framework through a proof-of-concept prototype. Sandeep Pisharody, Janakarajan Natarajan, Ankur Chowdhary, Abdullah Alshalan, Dijiang Huang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | Combining Dynamic and Static Attack Information for Attack Tracing and Event CorrelationabstractMany sophisticated attacks, e.g. Advanced Persistent Threats (APTs), have emerged with a variety of different attack forms. APT employs a wide range of sophisticated reconnaissance and information-gathering tools, as well as attack tools and methods. The diversity and stealthiness of APT make it a challenging threat to current networking systems. The attackers are very skilled and try to hide in a system undetected for a long period of time with the incentive to steal and collect invaluable Current commonly used solutions (firewalls, Intrusion Detection Systems, proxies, etc.) show the limited efficiency of detecting APT. Thus, in this paper, we design a solution that is based on multi-source data combination to learn the adversarial behavior of suspicious users as well as to optimally select a proper countermeasure. Adel Alshamrani, Ankur Chowdhary, Oussama Mjihil, Sowmya Myneni, Dijiang Huang |
GLOBECOM | 2 |
| 2018 | Fault Tolerant Controller Placement in Distributed SDN EnvironmentsabstractSoftware Defined Network (SDN) facilitates a centralized networking system where a controller manages the global view of the network. The introduction of Software-Defined Networks and standards such as OpenFlow spawn several questions regarding scalability and reliability. One such question is the controller placement problem; i.e. given a topology, the problem of determining how many controllers are needed, and where they should be placed. This question has been well-studied relative to performance, but there has not been a focus on maximizing fault-tolerance. In this paper, we present a model for controller placement to account for fault-tolerance and compare our algorithm to existing algorithms. Our proposed solution was analyzed to determine where controllers should be placed on a wide range of topologies from the Internet Topology Zoo. We further evaluated the dependence of fault-tolerance over the range of available number of controllers. Adel Alshamrani, Sayantan Guha, Sandeep Pisharody, Ankur Chowdhary, Dijiang Huang |
ICC | 4 |