Amar A. Rasheed

dblp:198/8022 · also Amar Rasheed · DBLP profile ↗
← Back
17ranked-venue papers
9as first author
8since 2021 · last 2025
0000-0002-1929-9124ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 4 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 CANSecure: A Secure Lightweight Framework for CAN Protocol in Modern Vehicles
abstract
The increasing connectivity of modern vehicles exposes in-vehicle communication systems such as the Controller Area Network (CAN) to a range of cyber threats. Traditional CAN lacks built-in security features, making it vulnerable to spoofing, message injection, and denial-of-service (DoS) attacks. In this paper, we present CANSecure, a lightweight security framework that integrates AES-CTR encryption, HMAC-based authentication, and a rule-based intrusion detection system (IDS) tailored for resource-constrained Electronic Control Units (ECUs). The framework was evaluated using a custom-built CAN testbed with multiple Nucleo boards under various attack scenarios. Performance results of proposed scheme demonstrate 100% decryption success rates under normal conditions and effective detection of spoofing and DoS attacks, all while maintaining sub-millisecond latency averaging ( 738 μs send, 556 μs receive), suitable for real-time automotive systems. Our findings affirm the feasibility of embedding robust security mechanisms within embedded CAN networks without compromising performance.
Damilola Oladimeji, Amar A. Rasheed, Mohamed Baza, Narasimha K. Shashidhar
MSWiM2
2025 A Secure Data-Driven Algorithm Against Malicious Intrusion Signals in Mobile Communication Networks
Yongfei Yu, Mohamed Baza, Amar A. Rasheed
Mob. Networks Appl.3
2024 IoTDL2AIDS: Toward IoT-Based System Architecture Supporting Distributed LSTM Learning for Adaptive IDS on UAS
abstract
The rapid proliferation of Unmanned Aircraft Systems (UAS) introduces new threats to national security. UAS technologies have dramatically revolutionized legitimate business operations while providing powerful weaponizing systems to malicious actors and criminals. Due to their inherited wireless capabilities, they are an easy target for cyber threats. In response to this challenge, the implementation of many Intrusion Detection Systems (IDS), which support anomaly detection on UAS, have been proposed in the past. However, such systems often require offline training with heavy processing, making them unsuitable for UAS deployment. This is pertinent for drone systems that support dynamic changes in mission operational tasks. This paper presents a novel system architecture that utilizes sensing systems capabilities available on existing IoT infrastructure for supporting rapid infield adaptive models’ training and parameters estimation services for UAS. We have devised a cluster-oriented distributed training algorithm based on LSTM with mini-batch gradient descent, with hundreds of IoT platforms per cluster collaboratively performing model parameters estimation tasks. The proposed architecture is based on deploying a multilayer system that facilitates secure dissemination of power consumption behavioral patterns for the flight sensing system between the UAS layer and the IoT layer. The model was implemented and deployed on a real IoT-enabled platform based on NXP-Kinetis K64–120 MHz. Furthermore, model training and validation were performed by applying various datasets contaminated with different percentages of malicious data. Our anomaly detection model achieved high prediction accuracy with an ROC-AUC score of 0.9332. The model maintains minimal power consumption overheads and low training time during the processing of a data batch.
Amar A. Rasheed, Mohamed Baza, Gautam Srivastava 0001, Narasimha Karpoor, Cihan Varol
IEEE Trans. Netw. Serv. Manag.1
2023 A Testbed for a Controller Area Network Communication Protocol in Automobiles
abstract
Automobiles are now becoming sophisticated as they are built with several nodes interacting together for the vehicle's overall functionality. A node in a car can be the engine, the audio system, the navigation system, or the airbags, and they all exchange data within the system. The exchange of data within an automobile is made possible by an in vehicle communication protocol. Using an mbed platform, we created a testbed for an in-vehicle protocol called the Controller Area Network protocol for an automobile. Our ultimate objective for the development of this system is to create a base system that can be used for the analysis of CAN bus security threats. In this paper, we highlight the necessary hardware and steps required to create a functioning system that operates using the CAN protocol. Our system had four major nodes communicating via the in-vehicle communication protocol and we collected and analyzed the traffic generated using a sniffer compatible with the aforementioned protocol. Subsequently, we attached a protocol decoder to validate the data sent within the system.
Damilola Oladimeji, Amar A. Rasheed, Narasimha K. Shashidhar, Cihan Varol
CCNC2
2023 DPark: Decentralized Smart Private-Parking System using Blockchains
Garrett Brenner, Mohamed Baza, Amar A. Rasheed, Wassila Lalouani, Mahmoud M. Badr, Hani Alshahrani
J. Grid Comput.3
2023 Highly Reliable Robust Mining of Educational Data Features in Universities Based on Dynamic Semantic Memory Networks
Mohamed Baza, Amar A. Rasheed
Mob. Networks Appl.3
2021 A Blockchain-Based Energy Trading Scheme for Electric Vehicles
abstract
An energy-trading system is essential for the successful integration of Electric vehicles (EVs) into the smart grid. Existing systems merely focus on making optimal decisions while others depend on anonymization to achieve EVs drivers' privacy which is not enough because they can be identified from visited locations. In this paper, leveraging blockchain technology, we propose a privacy-preserving charging-station-to-vehicle (CS2V) energy trading scheme. To preserve privacy, EVs are anonymous, however, a malicious EV may abuse the anonymity to launch Sybil attacks by pretending as multiple non-exiting EVs to launch powerful attacks such as Denial of Service (DoS) by submitting multiple reservations/offers without committing to them, to prevent other EVs from charging and make the trading system unreliable. To thwart the Sybil attacks, we use a common prefix linkable anonymous authentication scheme, so that if an EV submits multiple reservations/offers at the same timeslot, the blockchain can identify such submissions. To further protect the privacy of EV drivers, we introduce an anonymous and efficient blockchain-based payment system that cannot link individual drivers to specific charging locations. Our experimental results indicate that our schemes are secure and privacy-preserving with low communication and computation overheads.
Mohamed Baza, Ramy Amer, Amar A. Rasheed, Gautam Srivastava 0001, Mohamed Mahmoud 0001, Waleed Alasmary
CCNC3
2021 On the Assessment of Robustness of Telemedicine Applications against Adversarial Machine Learning Attacks
Ibrahim Yilmaz, Mohamed Baza, Ramy Amer, Amar A. Rasheed, Fathi H. Amsaad 0001, Rasha Morsi
IEA/AIE (1)4
2020 Adaptive Group-Based Zero Knowledge Proof-Authentication Protocol in Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc networks (VANETs) are a particular subclass of mobile ad hoc networks that raise a number of security challenges, notably from the way users authenticate the network. Authentication technologies based on existing security policies and access control rules in such networks assume full trust on roadside unit (RSU) and authentication servers. The disclosure of authentication parameters enables user's traceability over the network. VANETs' trusted entities (e.g., RSU) can utilize such information to track a user traveling behavior, violating user privacy and anonymity. In this paper, we proposed a novel, light-weight, adaptive group-based zero knowledge proof-authentication protocol (AGZKP-AP) for VANETs. The proposed authentication protocol is capable of offering various levels of users' privacy settings based on the type of services available on such networks. Our scheme is based on the zero-knowledge-proof crypto approach with the support of tradeoff options. Users have the option to make critical decisions on the level of privacy and the amount of resources usage they prefer such as short system response time versus the number of private information disclosures. Furthermore, AGZKP-AP is incorporated with a distributed privilege control and revoking mechanism that render user's private information to law enforcement in case of a traffic violation.
Amar A. Rasheed, Rabi N. Mahapatra, Felix G. Hamza-Lup
IEEE Trans. Intell. Transp. Syst.1
2018 Privacy-Preserving ECG based Active Authentication (PPEA2) for IoT Devices
abstract
IoT devices have become essential in our day-to-day life starting from health monitoring to industrial control systems. While the benefits of IoT are undeniable, IoT ecosystem comes with its own set of system vulnerabilities that include malicious actors manipulating the flow of information to and from the IoT devices, which can lead to the capture of sensitive data and loss of data privacy. In this paper, we propose a Privacy-Preserving ECG based Active Authentication (PPEA2) scheme that is deployable on power-limited wearable systems (e.g. fitness tracker systems, health monitoring systems for solider in the battlefield, and large-scale health monitoring infrastructure for rapid response systems). The proposed scheme is capable of supporting active authentication of users by utilizing live stream of electrocardiogram (ECG) signal to derive unique authentication parameters. In addition to providing active authentication, we incorporated a privacy-preserving feature into the design of our system. The scheme preserves the privacy of the users ECG data features by employing a light-weight secure computation approach based on secure weighted hamming distance computation from oblivious transfer to compute a joint set between two participating entities without revealing the authentication parameters to either of them. We demonstrate the feasibility of the system, its performance and resilience against various threats in a semi-honest model.
Ghanshyam Bhutra, Amar A. Rasheed, Rabi N. Mahapatra
IPCCC2
2016 Dynamically reconfigurable AES cryptographic core for small, power limited mobile sensors
abstract
In this paper, we propose a dynamically run-time reconfigurable power aware cryptographic processor for secure autonomous encryption. The design proposes the implementation of a dynamically reconfigurable AES cryptography process on an FPGA. The proposed design encompasses a microarchitecture which is variously power, latency, and throughput optimized via hardware acceleration and partial reconfiguration by a multi-level autonomic controller and a data router to enable tradeoffs under changing operational requirements within resource constraints. The multi-level controller decides on the appropriate configuration based on varying operational workloads to characterize the effect that time-varying task parameters have on the hardware architecture, to enable a run-time tradeoff of performance and resources usage (Key length, computational efficiency, latency and throughput).
Amar A. Rasheed, M. Cotter, D. Levan, Shashi Phoha
IPCCC1
2012 The Three-Tier Security Scheme in Wireless Sensor Networks with Mobile Sinks
abstract
Mobile sinks (MSs) are vital in many wireless sensor network (WSN) applications for efficient data accumulation, localized sensor reprogramming, and for distinguishing and revoking compromised sensors. However, in sensor networks that make use of the existing key predistribution schemes for pairwise key establishment and authentication between sensor nodes and mobile sinks, the employment of mobile sinks for data collection elevates a new security challenge: in the basic probabilistic and q-composite key predistribution schemes, an attacker can easily obtain a large number of keys by capturing a small fraction of nodes, and hence, can gain control of the network by deploying a replicated mobile sink preloaded with some compromised keys. This article describes a three-tier general framework that permits the use of any pairwise key predistribution scheme as its basic component. The new framework requires two separate key pools, one for the mobile sink to access the network, and one for pairwise key establishment between the sensors. To further reduce the damages caused by stationary access node replication attacks, we have strengthened the authentication mechanism between the sensor and the stationary access node in the proposed framework. Through detailed analysis, we show that our security framework has a higher network resilience to a mobile sink replication attack as compared to the polynomial pool-based scheme.
Amar A. Rasheed, Rabi N. Mahapatra
IEEE Trans. Parallel Distributed Syst.1
2011 Key Predistribution Schemes for Establishing Pairwise Keys with a Mobile Sink in Sensor Networks
abstract
Security services such as authentication and pairwise key establishment are critical to sensor networks. They enable sensor nodes to communicate securely with each other using cryptographic techniques. In this paper, we propose two key predistribution schemes that enable a mobile sink to establish a secure data-communication link, on the fly, with any sensor nodes. The proposed schemes are based on the polynomial pool-based key predistribution scheme, the probabilistic generation key predistribution scheme, and the Q-composite scheme. The security analysis in this paper indicates that these two proposed predistribution schemes assure, with high probability and low communication overhead, that any sensor node can establish a pairwise key with the mobile sink. Comparing the two proposed key predistribution schemes with the Q-composite scheme, the probabilistic key predistribution scheme, and the polynomial pool-based scheme, our analytical results clearly show that our schemes perform better in terms of network resilience to node capture than existing schemes if used in wireless sensor networks with mobile sinks.
Amar A. Rasheed, Rabi N. Mahapatra
IEEE Trans. Parallel Distributed Syst.1
2009 Mobile sink using multiple channels to defend against wormhole attacks in wireless sensor networks
abstract
Security is a necessity for many sensor-network applications. A particularly harmful attack against sensor networks is known as the wormhole attack, where an adversary tunnels the messages received in one part of the network over a low-latency link and replays them in a different part of the same network. This article presents the threat posed by wormhole attacks to wireless sensor networks with mobile sinks. A novel technique that involves leveraging channel diversity for defense against the wormhole attack has been proposed. Through quantitative analyses, it is shown that even when 50% of a sensor node's neighbors are malicious devices, the provision of one extra available channel for communication with the mobile sink reduces the probability of a wormhole attack to almost zero.
Amar A. Rasheed, Rabi N. Mahapatra
IPCCC1
2009 A key pre-distribution scheme for heterogeneous sensor networks
abstract
Key pre-distribution techniques developed recently to establish pairwise keys between nodes with no or limited mobility. Existing schemes make use of only one key pool to establish secure links between stationary and mobile nodes, allowing an attacker to easily gain control of the network by randomly compromising a small fraction of stationary nodes. A method of preventing this type of security breach is the use of separate key pools for mobile and stationary nodes, in which small fractions of stationary nodes are randomly pre-selected to help the mobile nodes establish links with stationary nodes. Analysis shows that with 10% of stationary nodes carry a key from the mobile key pool. To recover any key from the mobile key pool and gain control of the network, an attacker would have to capture 20.8 times more stationary nodes than if a single key pool is used for both mobile and stationary nodes.
Amar A. Rasheed, Rabi N. Mahapatra
IWCMC1
2008 An Efficient Key Distribution Scheme for Establishing Pairwise Keys with a Mobile Sink in Distributed Sensor Networks
abstract
Security services such as authentication and pair-wise key establishment are critical in sensor networks. They enable sensor nodes to communicate securely with each other using cryptographic techniques. In this paper, we propose a novel key predistribution scheme that enables a mobile sink to establish a secure data communication link with any sensor nodes on the fly. The proposed scheme is based on the polynomial pool-based key pre-distribution scheme and the scheme in [7]. The security analysis in this paper indicates that for a given node density of d sensors within the communication range of the mobile sink and with certain probabilities q and p, our scheme assures, with high probability, that any sensor node can establish a pair-wise key with the mobile sink. It remains perfectly secure up to the capture of a certain fraction of sensor nodes.
Amar A. Rasheed, Rabi N. Mahapatra
IPCCC1
2008 Secure Data Collection Scheme in Wireless Sensor Network with Mobile Sink
abstract
Wireless sensor networks that use a mobile sink to collect sensor data along a predetermined path raise a new security challenge: without verifying the source of the data request message, the network will become vulnerable to attacks. We propose an efficient security scheme, which divides the sinkpsilas data collection path into grids, sensors in each grid, uses secret keying in-formation and collision-resistant hash functions to authenticate the source of beacons. Through probabilistic analysis and definitive simulation, the proposed scheme shows with 60% of the grids under wormhole attacks, the probability that a node reply to a malicious beacon is 0.1.
Amar A. Rasheed, Rabi N. Mahapatra
NCA1