Laurent Njilla

dblp:194/3916 · also Laurent L. Njilla, Laurent Yamen Njilla · DBLP profile ↗
← Back
46ranked-venue papers
1as first author
16since 2021 · last 2026
0000-0001-8902-7418ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 6 since 2021Systems, architecture and hardware · 10 · 2 since 2021Security and privacy · 8 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 GAN-AIIPot: GAN-Based Cyber Deception for Probing Attacks on IoT Devices
abstract
The Internet of Things (IoT) is an emerging technology that has transformed the global network by interconnecting internet-enabled devices, people, intelligent things, and valuable data, leading to significant advancements in various domains. As IoT devices become more interwoven into our daily lives, the security of these devices is a huge concern. Many IoT devices are connected to the internet, making them open to security threats. Researchers have been exploring new methods for detecting and mitigating cyberattacks on IoT devices. One promising approach is the use of Generative Adversarial Networks (GANs) for cyber deception. Cyber deception is a cybersecurity technique used to mislead attackers and hackers from their intended targets. GANs have shown promise in the field of cybersecurity for creating realistic synthetic data to test the security of systems. In the case of probing attacks on IoT devices, GAN-based cyber deception can be used to create fake devices/information that can mimic real IoT devices and deceive attackers into thinking that they have successfully compromised a target. This paper proposes a novel GAN-based cyber deception technique called GAN-AIIPot, which is designed for probe attacks on IoT devices. GAN-AIIPot is an extended version of AIIPot that adds a GAN model on top of the Bidirectional Encoder Representations from the Transformers (BERT) model used in AIIPot. We evaluate our approach using a publicly available IoT dataset and show that GAN-AIIPot captures more sophisticated attacks and improves session length with attackers, showing the effectiveness of the deception technique compared to the existing honeypots. We believe that such a solution can enhance the security of IoT devices and protect them from malicious actors.
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
IEEE Trans. Netw. Serv. Manag.3
2025 Multi-domain deception for enhanced security in automotive networks
Priva Chassem Kamdem, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Comput. Secur.3
2025 Arpotcam: augmented reality-driven honeypot for enhancing security in IoT surveillance systems
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Vis. Comput.3
2024 A Decentralized Smart Grid Communication Framework Using SDN-Enabled Blockchain
abstract
The smart grid revolution has brought numerous benefits to the energy sector, such as improved efficiency, increased renewable energy integration, and enhanced grid management. The reliance on digital communication within smart grid systems has introduced new security challenges that must be addressed to ensure reliable and secure operation. The existing communication infrastructure often lacks the necessary security measures to protect against cyber threats, which leads to potential vulnerabilities and privacy breaches. This paper presents a novel approach to enhancing smart grid communication by integrating Software-Defined Networking (SDN) and Blockchain technology. Therefore, the proposed work aims to address the specific communication needs of smart grids, which require secure and real-time data exchange between various grid components, including power generation units, substations, distribution networks, and end consumers. The proposed framework provides data integrity, communication and network security, and controller privacy.
Uttam Ghosh, Laurent Njilla, Sachin Shetty, Charles A. Kamhoua
CCNC2
2024 FLAS: A Federated Learning Framework for Adaptive Security in Edge-Driven UAV Networks
abstract
Unmanned Aerial Vehicle (UAV) networks have emerged as a transformative technology with applications ranging from surveillance to disaster response. These networks rely on a decentralized architecture where UAVs communicate with each other and with ground stations. But because UAV networks are naturally weak, especially at the edges, strong security measures are needed to keep private data safe and make sure operations run smoothly. The dynamic and distributed nature of UAV networks poses unique security concerns, including data breaches, unauthorized access, and tampering. To address the security challenges prevalent in UAV networks, we propose a Federated Learning-based Adaptive Security (FLAS) Framework using fully homomorphic encryption (FHE). In the FLAS framework, federated learning (FL) allows UAVs to share knowledge while preserving data privacy to defend against security threats. Its integration ensures that collaborative learning occurs in edge-driven UAV environments without exposing raw data. FHE enables secure computations on encrypted data. The proposed FLAS approach ensures that security measures evolve dynamically to counter emerging threats. Our proposed method not only enhances the security posture of UAV networks but also optimizes resource utilization by distributing the learning process across the network's edge.
Uttam Ghosh, Laurent Njilla, Debashis Das, Eugene Levin
ICC2
2024 Adaptive learning-based hybrid recommender system for deception in Internet of Thing
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Comput. Networks3
2023 SHATTER: Control and Defense-Aware Attack Analytics for Activity-Driven Smart Home Systems
abstract
Modern smart home control systems utilize realtime occupancy and activity monitoring to ensure control efficiency, occupants' comfort, and optimal energy consumption. Moreover, adopting machine learning-based anomaly detection models (ADMs) enhances security and reliability. However, sufficient system knowledge allows adversaries/attackers to alter sensor measurements through stealthy false data injection (FDI) attacks. Although ADMs limit attack scopes, the availability of information like occupants' location, conducted activities, and alteration capability of smart appliances increase the attack surface. Therefore, performing an attack space analysis of modern home control systems is crucial to design robust defense solutions. However, state-of-the-art analyzers do not consider contemporary control and defense solutions and generate trivial attack vectors. To address this, we propose a control and defense-aware novel attack analysis framework for a modern smart home control system, efficiently extracting ADM rules. We verify and validate our framework using a state-of-the-art dataset and a prototype testbed.
Nur Imtiazul Haque, Maurice Ngouen, Mohammad Ashiqur Rahman, A. Selcuk Uluagac, Laurent Njilla
DSN5
2023 AIIPot: Adaptive Intelligent-Interaction Honeypot for IoT Devices
abstract
The proliferation of the Internet of Things (IoT) has raised concerns about the security of connected devices. There is a need to develop suitable and cost-efficient methods to identify vulnerabilities in IoT devices to address them before attackers seize opportunities to compromise them. The deception technique is a prominent approach to improving the security posture of IoT systems. Honeypot is a popular deception technique that mimics interaction in real fashion and encourages unauthorised users (attackers) to launch attacks. Due to the large number and the heterogeneity of IoT devices, manually crafting the low and high-interaction honeypots is not affordable. This has forced researchers to seek innovative ways to build honeypots for IoT devices. In this paper, we propose a honeypot for IoT devices that uses machine learning techniques to learn and interact with attackers automatically. The evaluation of the proposed model indicates that our system can improve the session length with attackers and capture more attacks on the IoT network.
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
PIMRC3
2022 A Survey of Blockchain-Based Electronic Voting Mechanisms in Sensor Networks
abstract
Electronic voting technology has the ability to accelerate the counting of ballots, reduce the cost of voting, and offer convenience for remote voters. Meanwhile, the efficiency of voting can be improved. Immutability, verifiability, and distribution are the main features blockchain can provide. Building an electronic voting system based on the blockchain can help to mitigate the security issues such as single-point failure and data manipulation. However, some blockchain systems are not feasible in the environment of sensor networks. In this paper, we propose a comparative analysis of blockchain-based electronic voting systems from the perspective of blockchain type, cryptography techniques, counting method, and security requirements. We also identify a possible new direction for the design of blockchain-based electronic voting systems for the reference of future research.
Tieming Geng, Laurent Njilla, Chin-Tser Huang
SenSys2
2022 Smarkchain: An Amendable and Correctable Blockchain Based on Smart Markers
abstract
Immutability is an important property of blockchain which ensures integrity and prevents forgery modification of previous transactions. However, immutability also prohibits the possibility of amending outdated codes and correcting typography or fraudulent data, both of which are common needs in many use cases. Therefore, a tradeoff that keeps the integrity guarantee but lifts the strict limitation of immutability is necessary to allow the practical applications of blockchain in areas other than cryptocurrencies. In this paper, we propose a novel scheme called Smarkchain, which will enhance blockchain technology with the features of amendment and correction by incorporating smart markers, an approach which enables multiway branching and merging in blockchain. Smarkchain has the unique advantages of allowing multiple consecutive blocks to be amended or corrected at one time, allowing multiple amendments or corrections over the same blocks, and not needing to modify existing blocks. Evaluation results of a prototype implementation show that our approach is practical.
Chin-Tser Huang, Laurent Njilla, Tieming Geng
TrustCom2
2022 Secure machine learning against adversarial samples at test time
abstract
Abstract Deep neural networks (DNNs) are widely used to handle many difficult tasks, such as image classification and malware detection, and achieve outstanding performance. However, recent studies on adversarial examples, which have maliciously undetectable perturbations added to their original samples that are indistinguishable by human eyes but mislead the machine learning approaches, show that machine learning models are vulnerable to security attacks. Though various adversarial retraining techniques have been developed in the past few years, none of them is scalable. In this paper, we propose a new iterative adversarial retraining approach to robustify the model and to reduce the effectiveness of adversarial inputs on DNN models. The proposed method retrains the model with both Gaussian noise augmentation and adversarial generation techniques for better generalization. Furthermore, the ensemble model is utilized during the testing phase in order to increase the robust test accuracy. The results from our extensive experiments demonstrate that the proposed approach increases the robustness of the DNN model against various adversarial attacks, specifically, fast gradient sign attack, Carlini and Wagner (C&W) attack, Projected Gradient Descent (PGD) attack, and DeepFool attack. To be precise, the robust classifier obtained by our proposed approach can maintain a performance accuracy of 99% on average on the standard test set. Moreover, we empirically evaluate the runtime of two of the most effective adversarial attacks, i.e., C&W attack and BIM attack, to find that the C&W attack can utilize GPU for faster adversarial example generation than the BIM attack can. For this reason, we further develop a parallel implementation of the proposed approach. This parallel implementation makes the proposed approach scalable for large datasets and complex models.
Laurent Njilla, Kaiqi Xiong
EURASIP J. Inf. Secur.2
2022 Adversarial Attacks and Defenses Toward AI-Assisted UAV Infrastructure Inspection
abstract
Unmanned aerial vehicles (UAVs) have been widely adopted to assist infrastructure inspection tasks, since they have shown their potential to benefit the inspection in terms of efficiency, cost, and safety. To improve the effectiveness of the inspection, there has been a growing focus of recent research in integrating AI techniques into UAV infrastructure inspection and has achieved promising results. However, no prior work has studied whether such integration will also introduce new security concerns, especially considering the existence of potential vulnerabilities in underlying AI models toward adversarial inputs. In this article, we perform the first study to fill this critical gap by identifying and validating the security vulnerabilities of AI models in the context of UAV infrastructure inspection with a focus on bridge infrastructure. To understand the security property of AI-assisted UAV bridge inspection, we design a two-stage approach for the construction of effective adversarial inputs, with which we successfully validate the existence of security vulnerability using dynamic analysis. Spatial constraints, physical limits, and dynamic environmental changes are taken into consideration in our analysis to make it practical in the physical world. Our evaluation results on a real-world data set show that our constructed adversarial inputs can mislead the UAV to miss detecting a significant amount of risk-prone regions by exploiting the identified vulnerability. Based on such an observation, this article also discusses the defenses based on adversarial training to improve the robustness of AI-assisted UAV bridge inspection, which has been demonstrated to be effective according to our experimental evaluation results.
Ashok Raja, Laurent Njilla
IEEE Internet Things J.2
2022 Blockchain-based automated and robust cyber security management
Songlin He, Eric Ficke, Mir Mehedi Ahsan Pritom, Huashan Chen, Qiang Tang 0005, Qian Chen 0019, Marcus Pendleton, Laurent Njilla, Shouhuai Xu
J. Parallel Distributed Comput.8
2021 Blur the Eyes of UAV: Effective Attacks on UAV-based Infrastructure Inspection
abstract
Unmanned aerial vehicles (UAVs) are increasingly leveraged to perform infrastructure inspection tasks, especially with the support of rapidly evolving AI algorithms and hardware in recent years. While the integration of UAV and AI techniques enhances the efficiency and effectiveness of infrastructure inspection, it also raises security concerns due to the potential vulnerabilities existing in the underlying AI models. In this paper, we propose to investigate and discover these vulnerabilities with the case study on bridge inspection. In particular, we designed a two-stage approach that can construct effective adversarial perturbations that make the UAV miss the detection of risk-prone regions during the inspection. Spatial constraints, physical limits, as well as dynamic environmental changes are taken into consideration in our approach to make it practical in the physical world. We evaluate our approach using the COCO-Bridge dataset. Our experimental results demonstrate the effectiveness of our approach in both white-box attack and black-box attack settings.
Ashok Raja, Laurent Njilla
ICTAI2
2021 Collaborative Trajectory Optimization for Outage-aware Cellular-Enabled UAVs
abstract
Cellular-enabled unmanned aerial vehicles (UAVs) require almost continuous cellular network connectivity to fulfill their missions successfully. However, the area (e.g., rural) they fly over may have partial coverage, making the path planning of such UAV missions a challenging task. Recently a tolerable outage duration is taken into account for such UAVs, and the trajectory optimization under this outage duration is studied. However, these existing studies consider only a single UAV and focus on optimization of each UAV's own path separately even in multi-UAV scenarios. In this paper, we study the trajectory optimization problem for cellular-enabled UAVs by taking into account the collaboration among UAVs. That is, for a given set of UAVs, each with a mission to fly from a starting point to an ending point, we aim to optimize the total mission completion time for all UAVs such that none of them has a connection outage more than a threshold. We let UAVs collaborate and provide connectivity as relays to each other to solve their outage problem and shorten their trajectories. We first model and solve this problem using nonlinear programming after discretization of the problem. Since it takes longer to solve the problem with such an approach, we then provide a graph-based approximate solution that runs fast. Numerical results show that the proposed approximate solution provides close to optimal results and performs better than state-of-the-art solutions that consider each UAV separately without collaboration among UAVs.
Amirahmad Chapnevis, Ismail Güvenç, Laurent Njilla, Eyuphan Bulut
VTC Spring3
2021 Low-Latency Privacy-Preserving Outsourcing of Deep Neural Network Inference
abstract
Efficiently supporting inference tasks of deep neural network (DNN) on the resource-constrained Internet-of-Things (IoT) devices has been an outstanding challenge for emerging smart systems. To mitigate the burden on IoT devices, one prevalent solution is to outsource DNN inference tasks to the public cloud. However, this type of “cloud-backed” solutions can cause privacy breach since the outsourced data may contain sensitive information. For privacy protection, the research community has resorted to advanced cryptographic primitives to support DNN inference over encrypted data. Nevertheless, these attempts are limited by the real-time performance due to the heavy IoT computational overhead brought by cryptographic primitives. In this article, we proposed an edge computing-assisted framework to boost the efficiency of DNN inference tasks on IoT devices, which also protects the privacy of IoT data to be outsourced. In our framework, the most time-consuming DNN layers are outsourced to edge computing devices. The IoT device only processes compute-efficient layers and fast encryption/decryption. Thorough security analysis and numerical analysis are carried out to show the security and efficiency of the proposed framework. Our analysis results indicate a 99%+ outsourcing rate of DNN operations for IoT devices. Experiments on AlexNet show that our scheme can speed up DNN inference for 40.6× with a 96.2% energy saving for IoT devices.
Yifan Tian, Laurent Njilla, Shucheng Yu
IEEE Internet Things J.2
2020 Fusion of Named Data Networking and Blockchain for Resilient Internet-of-Battlefield-Things
abstract
Named Data Network's (NDN) data-centric approach makes it a suitable solution in a networking scenario where there are connectivity issues as a result of the dynamism of the network. Coupling of this ability with the blockchain's well-documented immutable trustworthy-distributed ledger feature, the union of blockchain and NDN in an Internet-of-Battlefield-Things (IoBT) setting could prove to be the ideal alliance that would guarantee data exchanged in an IoBT environment is trusted and less susceptible to cyber-attacks and packet losses. Various blockchain technologies, however, require that each node has a ledger that stores information or transactions in a chain of blocks. This poses an issue as nodes in an IoBT setting have varying computing and storage resources. Moreover, most of the nodes in the IoT/IoBT network are plagued with limited resources. As such, there needs to be an approach that ensures that the limited resources of these nodes are efficiently utilized. In this paper, we investigate an approach that merges blockchain and NDN to efficiently utilize the resources of these resource-constrained nodes by only storing relevant information on each node's ledger. Furthermore, we propose a sharding technique called an Interest Group and introduce a novel consensus mechanism called Proof of Common Interest. Performance of the proposed approach is evaluated using numerical results.
Ronald Doku, Danda B. Rawat, Moses Garuba, Laurent Njilla
CCNC4
2020 CyVi: Visualization of Cyber-Attack and Defense Effects in Geographically Referenced Networks
abstract
The assumption that technology makes the world a better place translates to naive optimism with every successful cyber-attack. Research has seen an uptake in cyber-security visualization to complement weaknesses in traditional cyber-defense systems. However, due to the onerous task of positively handling cyber-attack “attribution”, only a few of these solutions scale geographical referenced networks. Many real-world systems can be expressed as networks consisting of nodes connected by edges, thus this paper explores connectivity modeled in a geographically referenced network, to visualize cyber-attack effects on the technical space (i.e., computing assets). The paper also demonstrates effects of defense strategies handling illegal connections.
Eric Muhati, Danda B. Rawat, Moses Garuba, Laurent Njilla
CCNC4
2020 Robust Machine Learning against Adversarial Samples at Test Time
abstract
Though the performance of deep learning is remarkable, recent works have shown that deep learning models are vulnerable to adversarial samples that are close to their original samples to human eyes but misclassified by Deep Neural Network (DNN). This is a serious problem as many deep learning models are used in physical infrastructures and critical application domains such as medical diagnosis, self-driving cars, malware detection, as well as digital assistants like Google Assistant, Alexa, and Siri. Many researchers have attempted to secure neural networks through techniques such as defensive distillation and adversarial retraining. Nevertheless, many of these techniques are ineffective to new or slightly strong adversarial attacks such as the Carlini and Wagner (C&W)'s attack. In this paper, we propose a robust adversarial retraining method to iteratively retrain a given model so that it can not only detect the adversarial examples but also maintain the prediction accuracy for the normal dataset. Our experimental results show that the prediction accuracy on the MNIST test set is maintained while the accuracies under FGSM, C&W, and DeepFool attacks increase from 29% to 91%, 7% to 70%, and 29% to 91%, respectively.
Laurent Njilla, Kaiqi Xiong
ICC2
2020 A Bayesian Game Theoretic Approach for Inspecting Web-Based Malvertising
abstract
Web-based advertising systems have been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply various redirection and evasion techniques. Meanwhile, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under resource and time constraints. Moreover, the ad network is disadvantaged because it has incomplete information about whether it is facing a benign or malicious advertiser. In this paper, we aim to apply the Bayesian game model by designing two games to formulate the problem of inspecting the Web-based maladvertising. The first game has two types of Advertisers, namely Malicious and Benign, and one type of Defender; the second game has two types of Attackers, Advanced and Simple, in terms of their capability of redirection and evasion, and one type of Defender. We define their strategies and payoff functions, and compute their Bayesian Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and we derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE Trans. Dependable Secur. Comput.5
2020 Look-Aside at Your Own Risk: Privacy Implications of DNSSEC Look-Aside Validation
abstract
The Domain Name System Security Extension (DNSSEC) leverages public-key cryptography to provide data integrity, source authentication, and denial of existence for DNS responses. To complement DNSSEC operations, DNSSEC Look-aside Validation (DLV) is designed for alternative off-path validation. Although DNS privacy attracts a lot of attention, the privacy implications of DLV are not fully investigated and understood. In this paper, we take a first in-depth look into DLV, highlighting its lax specifications and privacy implications. By performing extensive experiments over datasets of domain names under comprehensive experimental settings, our findings firmly confirm the privacy leakages caused by DLV. We discover that a large number of domains that should not be sent to DLV servers are being leaked. We explore the root causes, including the lax specifications of DLV. We also propose two approaches to fix the privacy leakages. Our approaches require trivial modifications to the existing DNS standards, and we demonstrate their cost in terms of latency and communication.
David Mohaisen, Zhongshu Gu, Kui Ren 0001, Zhenhua Li 0001, Charles A. Kamhoua, Laurent Njilla, DaeHun Nyang
IEEE Trans. Dependable Secur. Comput.6
2020 Applying Chaos Theory for Runtime Hardware Trojan Monitoring and Detection
abstract
Hardware Trojans (HTs) pose a serious threat to the security of Integrated Circuits (ICs). Detecting HTs in an IC is an important but difficult problem due to the wide spectrum of HTs and their stealthy nature. While researchers have been working on enhancing traditional IC tests and developing new methods to try to detect Trojans, there is still a possibility a Trojan will avoid detection during test time and be activated once the chip is in use. A runtime Trojan detection system could monitor an IC during its operational life time and provide a last-line of defense. However, most runtime approaches are infeasible due to the overhead introduced by additional hardware, or computational complexity, or both. In this paper, we propose a hardware-based runtime detection model that overcomes the aforementioned constraints. It applies chaos theory, which has been shown to be effective in several other domains, to characterize dynamic data in a reconstructed phase space, which helps us describe, analyze, and interpret power consumption data (whether chaotic or not). The proposed chaos based approach does not make any assumption on the statistical distribution of power consumption, this makes our model applicable for runtime use given the fact that power consumption is very dynamic as well as heavily application and data dependent. Hardware overhead, which is the main challenge for runtime approaches, is reduced by taking advantage of available thermal sensors present in most modern ICs. For real world implementation, thermal sensor noise cancelation is considered in our proposed model. Our simulation results for detecting Trojans on publicly available Trojan benchmarks demonstrate that the proposed model outperforms the current runtime Trojan detection approaches in terms of detection rate, computational complexity, and implementation feasibility. Approved for Public Release; Distribution Unlimited: 88ABW-2016-4308; Dated 31 AUG 2016.
Luke Kwiat, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla
IEEE Trans. Dependable Secur. Comput.5
2020 PCBChain: Lightweight Reconfigurable Blockchain Primitives for Secure IoT Applications
abstract
In the era of ubiquitous intelligence, the Internet of Things (IoT) holds the promise as a breakthrough technology to enable diverse applications that benefit societal problems. Yet interconnecting myriad heterogeneous IoT devices across various application domains remain a security challenge. Decentralized technology has recently emerged as a powerful primitive in building distributed applications to facilitate secure transactions between mutually distrustful parties in a trustworthy manner. Unfortunately, these decentralized protocols demand computing resources and power far beyond the reach of resource-constrained IoT devices, preventing the full adoption of distributed consensus platform in the IoT setting. In this article, we address the key bottleneck to enable blockchain in resource-constrained IoT devices. We propose a lightweight implementation of proof-of-work (PoW) mining with reconfigurable hardware primitives. By replacing the hash and cryptographic functions in classic blockchain protocol with secure and efficient hardware implementations, our proposed solution can significantly reduce hardware resources and power overheads of PoW mining, while improving the transaction speed of large-scale IoT systems. Finally, we demonstrate the algorithm by proposing an antispoofing solution for GPS navigation among lightweight IoT devices. As a replacement for position computation, a mining process generates the expected coordinates with the correct initial value and function configuration.
Wei Yan 0005, Ning Zhang 0017, Laurent Njilla, Xuan Zhang 0001
IEEE Trans. Very Large Scale Integr. Syst.3
2019 Game Theoretic-Based Approaches for Cybersecurity-Aware Virtual Machine Placement in Public Cloud Clusters
abstract
Allocating several Virtual Machines (VMs) onto a single server helps to increase cloud computing resource utilization and to reduce its operating expense. However, multiplexing VMs with different security levels on a single server gives rise to major VM-to-VM cybersecurity interdependency risks. In this paper, we address the problem of the static VM allocation with cybersecurity loss awareness by modeling it as a two-player zero-sum game between an attacker and a provider. We first obtain optimal solutions by employing the mathematical programming approach. We then seek to find the optimal solutions by quickly identifying the equilibrium allocation strategies in our formulated zero-sum game. We mean by "equilibrium" that none of the provider nor the attacker has any incentive to deviate from one's chosen strategy. Specifically, we study the characteristics of the game model, based on which, to develop effective and efficient allocation algorithms. Simulation results show that our proposed cybersecurity-aware consolidation algorithms can significantly outperform the commonly used multi-dimensional bin packing approaches for large-scale cloud data centers.
Soamar Homsi, Gang Quan, Wujie Wen, Gustavo A. Chaparro-Baquero, Laurent Njilla
CCGRID5
2019 Edge-Assisted Learning for Real-Time UAV Imagery via Predictive Offloading
abstract
Real-time decision making with unmanned aerial vehicles (UAVs) imagery is desired in many applications. Deep learning (DL) is a promising enabler for such applications thanks to its recent advancements. However, direct execution of DL models on UAVs, especially small and micro ones, would not only introduce severe delay but also significantly shorten the flight time of UAVs due to the high energy consumption. Realtime transmission of UAV images to ground edge devices for deep analysis can mitigate the computational complexity but may introduce severe interference to ground devices, in addition unpredictable delays due to the dynamic network conditions. To minimize real-time image transmission, this paper designs a new offloading prediction algorithm which first estimates nearfuture need for DL of each UAV and transmit images only when necessary. Holistic resource allocation is made at the edge based on the offloading likelihood analysis of multiple UAVs as well as available resources. Experimental results on real UAV video clips show that our design can save 92% of the communication costs with less than 4% false positive rate.
Zhuosheng Zhang 0003, Laurent Njilla, Shucheng Yu
GLOBECOM2
2019 Modeling Stepping Stone Attacks with Constraints in Cyber Infrastructure
abstract
Most cyber attacks involve an attacker launching a multi-stage attack by exploiting a sequence of hosts. This multistage attack generates a chain of "stepping stones" from the origin to target. The choice of stepping stones is a function of the degree of exploitability, the impact, attacker's capability, masking origin location, and intent. In this paper, we model and analyze scenarios wherein an attacker employs multiple strategies to choose stepping stones. The problem is modeled as an Adjacency Quadratic Shortest Path using dynamic vulnerability graphs with multi-agent dynamic system approach. Using this approach, the shortest stepping stone attack with maximum node degree and the shortest stepping stone attack with maximum impact are modeled and analyzed.
Marco A. Gamarra, Sachin Shetty, David M. Nicol, Laurent Njilla, Oscar R. González
GLOBECOM4
2019 BlockTrail: A Scalable Multichain Solution for Blockchain-Based Audit Trails
abstract
Blockchain-based audit trails provide a consensus-driven and tamper-proof trail of system events that are helpful in creating provenance in enterprise solutions. However, taking into account the transaction bulk generated by these applications and the throughput limitations of existing blockchains, a single ledger for record keeping can be inefficient and costly. To that end, we see an imperative need for a new blockchain design that is capable of addressing current challenges, without compromising security and provenance. Hence, we propose BlockTrail, a scalable and efficient blockchain solution for auditing applications. BlockTrail fragments the legacy blockchain systems into layers of co-dependent hierarchies, thereby reducing the time and space complexity, and increasing the throughput. BlockTrail is prototyped on "Practical Byzantine Fault Tolerance" (PBFT) protocol with a custom-built blockchain. Experiments with BlockTrail show that compared to the conventional schemes, BlockTrail is more efficient, and has less storage footprint.
Ashar Ahmad, Muhammad Saad 0001, Laurent Njilla, Charles A. Kamhoua, Mostafa A. Bassiouni, David Mohaisen
ICC3
2019 Dual Redundant Cyber-Attack Tolerant Control Systems Strategy for Cyber-Physical Systems
abstract
In this paper, a cyber-attack tolerant control strategy for embedded controllers in a cyber-physical system is presented. A dual redundant control architecture that combines two identical controllers that are switched periodically between active and restart modes is proposed. The strategy is addressed to mitigate the impact due to corruption of the controller software by an adversary. We analyze the impact of the resetting and restarting the controller software and performance of switching process. The minimum requirements in the control design, for effective mitigation of cyber-attacks to the control software, that implies a "fast" switching period is provided. The simulation results demonstrate the effectiveness of the proposed strategy when the time to fully reset and restart the controller is faster than the time taken by adversary to compromise the controller. The results also provide insights into the stability and safety regions and the factors that determine the effectiveness of the proposed strategy.
Marco A. Gamarra, Sachin Shetty, Oscar R. González, Laurent Njilla, Marcus Pendleton, Charles A. Kamhoua
ICC4
2019 Triad-NVM: persistency for integrity-protected and encrypted non-volatile memories
abstract
Non-Volatile Memory is here and provides an attractive fabric for main memory. Unlike DRAM, non-volatile main memory (NVMM) retains data after power loss. This allows memory to host data persistently across crashes and reboots, but opens up opportunities for attackers to snoop and/or tamper with data between boot episodes. While memory encryption and integrity verification have been well studied for DRAM systems, new challenges surface for NVMM if we want to simultaneously preserve security guarantees, data recovery across crashes/reboots, good persistence performance, and fast recovery.
Amro Awad, Mao Ye 0008, Yan Solihin, Laurent Njilla, Kazi Abu Zubair
ISCA4
2019 Quantifying location privacy in permissioned blockchain-based internet of things (IoT)
abstract
Recently, blockchain has received much attention from the mobility-centric Internet of Things (IoT). It is deemed the key to ensuring the built-in integrity of information and security of immutability by design in the peer-to-peer network (P2P) of mobile devices. In a permissioned blockchain, the authority of the system has control over the identities of its users. Such information can allow an ill-intentioned authority to map identities with their spatiotemporal data, which undermines the location privacy of a mobile user. In this paper, we study the location privacy preservation problem in the context of permissioned blockchain-based IoT systems under three conditions. First, the authority of the blockchain holds the public and private key distribution task in the system. Second, there exists a spatiotemporal correlation between consecutive location-based transactions. Third, users communicate with each other through short-range communication technologies such that it constitutes a proof of location (PoL) on their actual locations. We show that, in a permissioned blockchain with an authority and a presence of a PoL, existing approaches cannot be applied using a plug-and-play approach to protect location privacy. In this context, we propose BlockPriv, an obfuscation technique that quantifies, both theoretically and experimentally, the relationship between privacy and utility in order to dynamically protect the privacy of sensitive locations in the permissioned blockchain.
Abdur Rahman Bin Shahid, Niki Pissinou, Laurent Njilla, Sheila Alemany, Ahmed Imteaj, Kia Makki, Edwin Aguilar
MobiQuitous3
2019 Online Cyber Deception System Using Partially Observable Monte-Carlo Planning Framework
Md Ali Reza Al Amin, Sachin Shetty, Laurent Njilla, Deepak K. Tosh, Charles A. Kamhoua
SecureComm (2)3
2019 LightChain: On the Lightweight Blockchain for the Internet-of-Things
abstract
The Internet of Things (IoT) and the blockchain are justly regarded as the technology for the future. The blockchain is a Distributed Ledger Technology (DLT) solution which has enormous potential as can be seen in the numerous avenues it has been deployed. Simplistically, it is a decentralized database which can revolutionize the current centralized world we live. IoT is the interconnection of devices with mostly bounded resources. IoT applications are also distributed in nature thereby making it inevitable that the paths of the blockchain and IoT will cross in the future. Blockchain's DLT will eventually play a crucial role in how IoT devices will communicate. The Proof of Work (PoW) mechanism was the original consensus technique introduced in the first blockchain based application (Bitcoin). PoW guaranteed consensus in the network by verifying transactions. However, the PoW had deficiencies. The solving of the PoW puzzle is computationally expensive which has become an impediment in the potential marriage of IoT and blockchain. This predicament arises as IoT devices are plagued with limited resources. In this work, we address this issue by presenting an approach where IoT devices can combine their resources to solve PoW puzzles that they might not have been able to solve on their own. This would ensure a successful merger between the blockchain and the IoT.
Ronald Doku, Danda B. Rawat, Moses Garuba, Laurent Njilla
SMARTCOMP4
2019 Thwarting Security Threats From Malicious FPGA Tools With Novel FPGA-Oriented Moving Target Defense
abstract
The increasing usage and popularity of the field-programmable gate array (FPGA) systems bring in security concerns. Existing countermeasures are mostly based on the assumption that the computer-aided design (CAD) tools for FPGA configuration are trusted. Unfortunately, this assumption does not always hold. In this paper, we investigate the potential security threats originated from the untrusted CAD tools. Furthermore, we exploit the principle of moving target defense (MTD) to propose an FPGA-oriented MTD (FOMTD) method. The three defense lines in the FOMTD generate uncertainties, from the attacker's point of view, to thwart hardware Trojan insertion attacks. The theoretical upper bound of the hardware Trojan hit rate for each defense line is provided in this paper. Experimental results show that the proposed defense line 2 and defense line 3 reduce the Trojan hit rate by up to 40% and 91%, respectively, for the scenario where the malicious CAD tool can insert Trojans in the occupied FPGA slices. The proposed gate replacement technique in the defense line 3 further improves the attack resilience and obtains 88% reduction on the Trojan hit rate. Compared to the static redundancy-based Trojan detection method, the proposed method achieves better resilience against Trojan insertions and consumes 50% less dynamic power.
Laurent Njilla, Charles A. Kamhoua, Qiaoyan Yu
IEEE Trans. Very Large Scale Integr. Syst.2
2018 ChainFS: Blockchain-Secured Cloud Storage
abstract
This work presents ChainFS, a middleware system that secures cloud storage services using a minimally trusted Blockchain. ChainFS hardens the cloud-storage security against forking attacks. The ChainFS middleware exposes a file-system interface to end users. Internally, ChainFS stores data files in the cloud and exports minimal and necessary functionalities to the Blockchain for key distribution and file operation logging. We implement the ChainFS system on Ethereum and S3FS and closely integrate it with FUSE clients and Amazon S3 cloud storage. We measure the system performance and demonstrate low overhead.
Yuzhe Tang, Qiwu Zou, Ju Chen, Kai Li 0017, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE CLOUD7
2018 CloudPoS: A Proof-of-Stake Consensus Design for Blockchain Integrated Cloud
abstract
Maintaining data provenance in cloud in a tamper-resistant manner that cannot be breached by malicious parties is a necessity from the current security standpoint. Blockchain technology has emerged as a secure solution to store and share information by offering an immutable distributed ledger service. Its effectiveness hinges on the infrastructure supporting the distributed ledger and consensus protocol that governs the validity of entries in the Blockchain. Hence, Blockchain can be a potential candidate to implement data provenance; however, traditional cryptocurrency-based consensus models become a bottleneck in the cloud environment. Therefore, in this paper, we propose a Blockchain based data provenance architecture (BlockCloud) that incorporates a proof-of-stake (PoS)-based consensus protocol (CloudPoS) for securely recording the data operations occurring in cloud environment. The critical operational phases of the protocol are discussed in depth, which leverages the cloud users' cyber infrastructure resources. A cloud-based testbed environment is created using a local cluster of physical machines managed by Xen hypervisor. Resource elasticity is enabled using Kubernetes setup that interacts with the dockerized containers, which emulate as peers in the Blockchain network. We then evaluate the effectiveness of the protocol in a simulated environment and conduct performance tests of the proposed consensus.
Deepak K. Tosh, Sachin Shetty, Peter Foytik, Charles A. Kamhoua, Laurent Njilla
IEEE CLOUD5
2018 QOI: Assessing Participation in Threat Information Sharing
abstract
We introduce the notion of Quality of Indicator (QoI) to assess the level of contribution by participants in threat intelligence sharing. We exemplify QoI by metrics of the correctness, relevance, utility, and uniqueness of indicators. We build a system that extrapolates the metrics using a machine learning process over a reference set of indicators. We compared these results against a model that only considers the volume of information as a metric for contribution, and unveiled various observations, including the ability to spot low-quality contributions that are synonymous to free-riding.
Jeman Park 0001, Hisham Alasmary, Omar Al-Ibrahim, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla, David Mohaisen
ICASSP6
2018 Analysis of Stepping Stone Attacks in Dynamic Vulnerability Graphs
abstract
Vulnerability graphs have been employed as an effective tool for analyzing exploitability and impact of chain of exploits in networked environments. The attack graphs are created by a chain of "stepping stones" from the attacker origin to the desired target. The stepping stones not only provide the intermediate steps to reach the target, but also make it difficulty to identify the attacker's true location. In this paper, we model and analyze stepping stones in dynamic vulnerability graphs. Most analysis based on attack graph assume that the graph edges and weights remain constant during the attacker's attempt to propagate through the network. We propose a biased min- consensus technique for dynamic graphs with switching topology as a distributed technique to determine the attach paths with more probable stepping-stones in dynamic vulnerability graphs. We use min-plus algebra to determine necessary and sufficient convergence conditions. A necessary condition for convergence to the shortest path in the switching topology case is provided.
Marco A. Gamarra, Sachin Shetty, David M. Nicol, Oscar Gonazlez, Charles A. Kamhoua, Laurent Njilla
ICC6
2018 Enabling Cooperative IoT Security via Software Defined Networks (SDN)
abstract
Internet of Things (IoT) is becoming an increasingly attractive target for cybercriminals. We observe that many attacks to IoTs are launched in a collusive way, such as brute-force hacking usernames and passwords, to target at a particular victim. However, most of the time our defending mechanisms to such kind of attacks are carried out individually and independently, which leads to ineffective and weak defense. To this end, we propose to leverage Software Defined Networks (SDN) to enable cooperative security for legacy IP-based IoT devices. SDN decouples control plane and data plane, and can help bridge the knowledge divided between the application and network layers. In this paper, we discuss the IoT security problems and challenges, and present an SDN-based architecture to enable IoT security in a cooperative manner. Furthermore, we implemented a platform that can quickly share the attacking information with peer controllers and block the attacks. We carried out our experiments in both virtual and physical SDN environments with OpenFlow switches. Our evaluation results show that both environments can scale well to handle attacks, but hardware implementation is much more efficient than a virtual one.
Garegin Grigoryan, Yaoqing Liu, Laurent Njilla, Charles A. Kamhoua, Kevin A. Kwiat
ICC3
2018 A Generic Paradigm for Blockchain Design
abstract
Cryptocurrencies have recently gained huge popularity. It is desirable to come up with effective approaches to constructing better blockchain protocols. In this paper, inspired by the 2-hop design by Duong et al (ePrint 2016/716), we put forth a generic paradigm for blockchain design, called n-hop blockchain. It includes one main chain, which is supported by (n -- 1) supporting chains; hence, the main chain can achieve better security performance. In our paradigm, we show that our n-hop design can be easily extended to (n + 1)-hop design. To demonstrate the power of our paradigm, we showcase two instantiations: 2-hop blockchain variant, a combination of proof-of-stake and proof-of-work, and 3-hop blockchain variant, which is extended from 2-hop blockchain variant by adding Byzantine fault tolerance blockchain in 3rd hop.
Phuc Thai, Laurent Njilla, Tuyet Duong, Lei Fan 0002, Hong-Sheng Zhou
MobiQuitous2
2017 ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and Availability
abstract
Cloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications.
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
CCGrid6
2017 Security Implications of Blockchain Cloud with Analysis of Block Withholding Attack
abstract
The blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations.
Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
CCGrid6
2017 Estimation of Safe Sensor Measurements of Autonomous System Under Attack
abstract
The introduction of automation in cyber-physical systems (CPS) has raised major safety and security concerns. One attack vector is the sensing unit whose measurements can be manipulated by an adversary through attacks such as denial of service and delay injection. To secure an autonomous CPS from such attacks, we use a challenge response authentication (CRA) technique for detection of attack in active sensors data and estimate safe measurements using the recursive least square algorithm. For demonstrating effectiveness of our proposed approach, a car-follower model is considered where the follower vehicle's radar sensor measurements are manipulated in an attempt to cause a collision.
Raj Gautam Dutta, Xiaolong Guo 0001, Teng Zhang 0002, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla, Yier Jin
DAC6
2017 Automatic Generation of Hardware Sandboxes for Trojan Mitigation in Systems on Chip (Abstract Only)
Christophe Bobda, Taylor J. L. Whitaker, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
FPGA5
2017 A game theoretic approach for inspecting web-based malvertising
abstract
Web-based advertising system has become a convenient and efficient channel for advertisers to deliver ads to targeted Internet users. Unfortunately, this system has been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply a variety of evasion techniques such as fingerprinting the execution environment, redirecting to compromised IP addresses, and malware polymorphism. On the other hand, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under the constraints of resource and time. In this paper, we aim to apply game theory to formulate the problem of inspecting the malware inserted by the malvertisers into the Web-based advertising system. We design a normal form game between the malvertiser and the ad network, define their strategies and payoff functions, and compute their pure-strategy and mixed-strategy Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
ICC5
2017 Approach to detect non-adversarial overlapping collusion in crowdsourcing
abstract
Crowdsourcing services have become one of the most common ways organizations can gather ideas for new products and services from large crowds of consumers by offering monetary rewards depending on the tasks. However, this monetary reward has begun to attract malicious crowds of users who wish to complete the task with minimal effort through collaboration. For instance, a task based on reviews of a product can be degraded when malicious users copy each other with minimal edits of the review, giving a misrepresentation of the true quality of the product. More specifically, we investigate the case where different malicious crowd sizes cooperate on different tasks, known as overlapping groups. Such sophisticated and hard to detect malicious crowds provide unfair evaluations and misleading results to the crowdsourcers. To overcome this type of attack, we propose two methods to point out such groups with high accuracy. The first method detects similar reviews by including a new proposed similarity between review texts and show the results outperform the vectorial similarity measures used in prior works. The second method is based on community detection on networks and exploits the semantic similarity of the reviews. The experiments were conducted on reviews from Ott dataset on Amazon Mechanical Turk.
Georges A. Kamhoua, Niki Pissinou, S. Sitharama Iyengar, Jonathan Beltran, Jerry Miller, Charles A. Kamhoua, Laurent Njilla
IPCCC7
2015 Dynamics of data delivery in mobile ad-hoc networks: A bargaining game approach
abstract
In this paper, we address the problem of dynamic packet forwarding with a set of wireless autonomous ad hoc network nodes, where each node acting in a selfish manner tries to use the resources of other nodes. We model the dynamic packet forwarding problem as a modified Rubinstein-Ståhl bargaining game. In our model, a mobile node (player) negotiates with the other mobile node to obtain an agreeable and respectable sharing rule of packet forwarding based on its own resource available, such that a node should not agree to forward packets without the energy or storage capacity to do so. We investigate and solve this bargaining by finding the Subgame Perfect Nash Equilibrium (SPNE) strategies of the game. We consider finite horizon of the bargaining game and examine its SPNE. The solution obtained from bargaining ensures that a mobile device always finds a peer to help forward packets in order to keep the network at flow. Extensive simulations using OMNET++ simulation frameworks are conducted to evaluate how the level of participation of each mobile node impact the network overall performance. Simulation results show that our proposed bargaining game scheme performs better than other resource shared algorithms, namely the technique for order preference by similarity to ideal solution (TOPSIS) and the bargaining game based access network selection for heterogeneous network.
Laurent Njilla, Niki Pissinou
CISDA1