VLDB 2026 Research / reviewers in the wild / expert
Neminath Hubballi
dblp:20/7949
· DBLP profile ↗
31ranked-venue papers
14as first author
13since 2021 · last 2026
0000-0001-9669-9773ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 7 first-author · 1 since 2021Computer networks · 9 · 5 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RepCache: Content Producer Reputation based Caching in Named Data NetworksabstractNamed Data Networking (NDN) caching enhances user experience, making it suitable for deployment across various applications. Due to the limited router cache, it is crucial to decide carefully which content to store. Several caching techniques have been designed to better utilize router capacity by storing popular content. However, these methods are producer agnostic. In practice, it is beneficial to cache content from those producers whose content has previously been popular, as their newly generated content is also likely to be consumed by many. This observation stems from the fact that there are a few dominant content producers on the web. To leverage the benefits of caching content from dominant producers, this paper proposes a reputation-based caching strategy (RepCache) that prioritizes content based on the producer’s reputation. RepCache estimates a producer’s reputation by considering content frequency and hop count. RepCache outperforms state-of-the-art caching techniques by leveraging producer reputation in caching decisions. Pankaj Chaudhary, Neminath Hubballi |
CCNC | 2 |
| 2025 | PeNCache: Popularity based cooperative caching in Named Data Networks
Pankaj Chaudhary, Neminath Hubballi |
Comput. Networks | 2 |
| 2024 | Mitigating Resource Depletion and Message Sequencing Attacks in SCADA Systems
Neminath Hubballi, Nisha Kumari Barsha |
AINA (3) | 1 |
| 2024 | Detecting Cyber Attacks in Smart-Grid Networks with Probability Distribution ComparisonabstractSmart-grids add ICT to grid infrastructure and hence vulnerable to security threats. In this paper, we propose flooding and bruteforce attack detection method against smart-grid infrastructure. This we achieve by modeling the Modbus communication messages as a probability distribution and subsequently, we compare a test interval with the base distribution using the Hellinger distance metric. We experiment with two publicly available datasets to show that the proposed method can detect these attacks effectively. Nisha Kumari Barsha, Neminath Hubballi |
CCNC | 2 |
| 2024 | PePC: Popularity Based Early Predictive Caching in Named Data NetworksabstractCaching technique used in Information Centric/Named Data Networks (ICN/NDN) governs the response time. Cache capacity constraints at routers have led to investigations on different caching mechanisms to improve effective caching and performance in terms of improved cache hits and response time for requested contents. However, most caching methods remain oblivious to the dynamics of cache occupancy. In this paper, we describe a new caching technique which predicts whether a new content has to be cached or not considering the current occupancy level of the cache. Our prediction based approach is inspired by the Random Early Detection (RED) method used for queue management. Similar to RED, our predictive caching algorithm bases its decision to cache a content using the average cache occupancy and also takes into account the content popularity. When the cache occupancy is low, we cache every possible content, and with the increasing cache occupancy, the decision to cache the content is decided based on the content popularity and the occupancy threshold parameters. We perform simulation based studies using discrete event simulator to assess its performance. We also compare the performance of our predictive caching method with five different popular caching methods used in Named Data Networks to show its superiority over others. Neminath Hubballi, Pankaj Chaudhary, Sameer G. Kulkarni |
CCNC | 1 |
| 2024 | Reducing the Impact of DoS Attack on Static and Dynamic SE Using a Deep Learning-Based ModelabstractDenial-of-service (DoS) attacks adversely impact the state estimation (SE) techniques used in power systems. Our contributions in this article are twofold. First, considering a longer duration DoS attack with continuous packet loss, an analysis is carried out on an IEEE 14 bus system to assess the performance of weighted least square (WLS) and cubature Kalman filter (CKF)-based hybrid SE. Second, a method to improve the performance of CKF under long-duration attacks by accurately predicting the synchrophasor measurements using convolutional neural network (CNN) and long short-term memory (LSTM) is proposed. CNN extracts relevant features/measurements from synchrophasor and RTU measurements. Using these extracted features, LSTM predicts all synchrophasor measurements. However, only the missing measurements are utilized from LSTM output in HSE during the attack. This renders the proposed method capable of dealing with attacks on any PMU channels. A comparison with the existing techniques showed improved performance of the proposed method. Purna Kukadiya, Trapti Jain, Neminath Hubballi |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | SlowTrack: detecting slow rate Denial of Service attacks against HTTP with behavioral parameters
Shaurya Sood, Neminath Hubballi |
J. Supercomput. | 2 |
| 2024 | Anomaly Detection in SCADA Systems: A State Transition ModelingabstractSmart-Grid networks use Supervisory Control and Data Acquisition (SCADA) systems to bring measurement data from sensory nodes. These measurements drive the control decisions which are safety critical operations. SCADA communications now happen over TCP/IP networks and hence are susceptible to cyber attacks. As smart-grid is a critical infrastructure, it is essential to detect these cyber attacks. In this direction, our contributions in this paper are two-fold. First, we present three broad classes of network anomalies namely single message anomaly, message sequencing anomaly, and time based anomaly. We show that several cyber attacks in smart-grid networks can be detected by identifying these three types of anomalies. Second, we describe a novel state transition machine based model for identifying these three types of anomalies and hence different cyber attacks in smart-grid networks. Our state transition based model Deterministic Counting Timed Automata (DCTA) formalizes constraints on message attributes, timing of events, and counter values associated with states to detect these anomalies. We experiment with a publicly available dataset and show that DCTA is capable of detecting various cyber attacks with 100% detection rate in the best case for most of the attacks considered. We also benchmark its performance with recent methods found in the literature. Nisha Kumari Barsha, Neminath Hubballi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | eNCache: Improving content delivery with cooperative caching in Named Data Networking
Pankaj Chaudhary, Neminath Hubballi, Sameer G. Kulkarni |
Comput. Networks | 2 |
| 2023 | Secure Socket Shell Bruteforce Attack Detection With Petri Net ModelingabstractSecure Socket Shell exposes a secure interface for login to remote users. Password based authentication mechanism used by remote users is vulnerable to bruteforcing. In this attack an adversary systematically tries many passwords. These attacks can either be generated from a single source or collectively from a set of sources. In this paper we propose a method to detect such bruteforcing attacks and subsequently classify these attempts into three types as originating from single source, single domain and distributed attacks. We develop Petri-Net based model which identifies SSH connections corresponding to failed login attempts using network flow characteristics. The model also keeps track of sources of failed login attempts using which it subsequently labels a time interval as experiencing bruteforcing or not and if the interval is experiencing bruteforcing which type of attack it is. We experiment with network traffic collected from a production level server and also generated within a testbed setup and show that our model can detect attacks and also classify them. We also experiment with stealth attack variant where attacker keeps a low profile of attacks and suggest methods to handle such attack instances. Namrata Tiwari, Neminath Hubballi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | KeyClass: Efficient keyword matching for network traffic classification
Neminath Hubballi, Pratibha Khandait |
Comput. Commun. | 1 |
| 2021 | Preventing time synchronization in NTP broadcast mode
Nikhil Tripathi, Neminath Hubballi |
Comput. Secur. | 2 |
| 2021 | mMIG: Inversion optimization in majority inverter graph with minority operations
Umar Aalam, Bodhisatwa Mazumdar, Neminath Hubballi |
Integr. | 3 |
| 2020 | POSTER: Distributed SSH Bruteforce Attack Detection with Flow Content Similarity and Login Failure ReputationabstractIn this paper we propose a method to detect distributed bruteforcing by modeling failed login attempts as a Poisson probability distribution. We use content similarity between known SSH connection and flow characteristics of failed login attempts to attribute a flow to SSH application and subsequently either as failure or success. Using the failed login count in a window time, we label window as either normal or containing bruteforce attempts. Neminath Hubballi, Namrata Tiwari, Pratibha Khandait |
AsiaCCS | 1 |
| 2020 | POSTER: Towards Automating Detection of Anomalous HTTP Requests with Joint Probability Estimation of CharactersabstractWeb applications are often exploited using different techniques like injection, buffer overflow, etc. An HTTP request carrying such malicious content will be different from a normal request. In this paper we propose to detect such anomalous HTTP requests using regular expression based signatures. These signatures are generated using character combinations specifically identified from known malicious requests. We identify certain characters which are useful for differentiating normal and anomalous requests using their frequency value comparison and subsequently select those combinations which have high chances of appearing together by estimating their joint probability values. We experiment with few sample attack types and show that proposed method can identify anomalous HTTP requests. Pratibha Khandait, Neminath Hubballi, Katrin Franke |
AsiaCCS | 2 |
| 2020 | BitProb: Probabilistic Bit Signatures for Accurate Application IdentificationabstractNetwork traffic classification finds its applications in a variety of network management tasks such as quality of service, security monitoring, traffic engineering, etc. Deep Packet Inspection is one of the methods to identify applications. With the number of proprietary protocols on the rise and network protocols using bit level information for encoding, recently it has been shown that bit level signatures are effective for identifying applications. In this paper, we propose BitProb which generates probabilistic bit signatures for traffic classification. It uses the probability of a bit at a particular position being either 0 or 1 and generates a space efficient signature represented as a state transition machine. Subsequently, it uses the overall probability of an n bit binary string extracted from a network flow to identify which application generated the flow. We experiment with three datasets covering twenty protocols (text, binary and proprietary) and show that BitProb classifies network flows with high accuracy and has a minimum number of misclassifications. Neminath Hubballi, Mayank Swarnkar, Mauro Conti |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2018 | Slow rate denial of service attacks against HTTP/2 and detection
Nikhil Tripathi, Neminath Hubballi |
Comput. Secur. | 2 |
| 2018 | BitCoding: Network Traffic Classification Through Encoded Bit Level Signatures
Neminath Hubballi, Mayank Swarnkar |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | BitCoding: Protocol Type Agnostic Robust Bit Level Signatures for Traffic ClassificationabstractTraffic classification has received considerable interest as many network applications use obfuscation methods to hide their identity and bypass security. Traditionally application signatures are generated using byte level content of application flows. Increasingly new data formats are used to encode the application protocols which render the byte level signatures ineffective in identifying applications. To address this issue we propose BitCoding a bit-level application signature generation using invariant bits of application flows. Unlike other works, BitCoding uses only a small number of initial bits of flows to generate signature and signature bits are encoded using run length coding to reduce size; hence it is very inexpensive in storage and is light weight for signature matching. We evaluate BitCoding using three different datasets and show that it is able to classify both text based and binary protocols with high accuracy, making it protocol type agnostic. Further we perform cross evaluation of signatures generated to understand the portability of signatures generated to other sites and conclude that it will lead to a small compromise in the detection rate. Neminath Hubballi, Mayank Swarnkar |
GLOBECOM | 1 |
| 2017 | A closer look into DHCP starvation attack in wireless networks
Neminath Hubballi, Nikhil Tripathi |
Comput. Secur. | 1 |
| 2017 | An event based technique for detecting spoofed IP packets
Neminath Hubballi, Nikhil Tripathi |
J. Inf. Secur. Appl. | 1 |
| 2017 | Detecting Anomalous Behavior in VoIP Systems: A Discrete Event System ModelingabstractSession initiation protocol (SIP) is an application layer protocol used for signaling purposes to manage voice over IP connections. SIP being a text-based protocol is vulnerable to a range of denial of service (DoS) attacks. These DoS attacks can render the SIP servers/SIP proxy servers unusable by depleting memory and CPU time. In this paper, we consider two types of DoS attacks, namely, flooding attacks and coordinated attacks for detection. Flooding attacks affect both stateless and stateful SIP servers while coordinated attacks affect stateful SIP servers. We model the SIP operation as discrete event system (DES) and design a new state transition machine, which we name as probabilistic counting deterministic timed automata (PCDTA) to describe the behavior of SIP operations. We also identify different types of anomalies that can occur in a DES model, which appear in the form of illegal transitions, violating timing constraints, and appear in number which is otherwise not seen. Subsequently, we map various DoS attacks in SIP to a type of anomaly in DES. PCDTA can learn probabilities of various transitions and timings delay from a set of nonmalicious training sequences. A trained PCDTA can detect anomalies, and hence various DoS attacks in SIP. We perform a thorough experiment with computer simulated SIP traffic and report the detection performance of PCDTA on various attacks generated through custom scripts. Diksha Golait, Neminath Hubballi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | VoIP Profiler: Profiling Voice over IP User Communication BehaviorabstractUnderstanding the user behavior in Voice over IP (VoIP) communication has twofold advantages. It helps in detecting anomalies and also helps in planning VoIP infrastructure deployment and optimization. Anomalies arise out of various attacks and misuses like flooding, malformed messages and spam messages. In this paper we propose VoIP Profiler a method for profiling the VoIP activities at user level. For profiling users we identify a set of parameters and compute statistics of these parameters for each user using VoIP traffic. Subsequently we use these parameters to classify users (and detect anomalies). We simulate an enterprise network and experiment with a large scale VoIP dataset and identify different types of users with high success rate. Sainath Batthala, Mayank Swarnkar, Neminath Hubballi, Maitreya Natu |
ARES | 3 |
| 2016 | Detecting Packed Executable File: Supervised or Anomaly Detection Method?abstractExecutable packing is an evasion technique used to propagate malware in the wild. Packing uses compression and/or encryption to thwart static analysis. There are universal unpackers available which can extract original binary from any type of packer, however they are computationally expensive as they are based on dynamic analysis which requires malware execution. A possible approach is to use machine learning techniques for classifying whether an executable is packed or not packed. Although supervised machine learning methods are good at learning packer specific features, these require collecting data from each packer and extracting features specific to it which may not be feasible practically. In this paper we propose a semi-supervised technique and an anomaly based detection method to identify packed executable files. We measure the distance between representative generated from a packed and non-packed binary training data and estimate the class based on its nearest distance in semi-supervised method. In anomaly detection we generate a representative cluster from known non-packed samples and find the radius of cluster and compare the distance of a test executable with that of radius to decide either it as normal or packed one. We experiment with few distance measures and report detection performance of these methods on two datasets. Neminath Hubballi, Himanshu Dogra |
ARES | 1 |
| 2016 | How Secure are Web Servers? An Empirical Study of Slow HTTP DoS Attacks and DetectionabstractSlow HTTP Denial of Service (DoS) is an application layer DoS attack in which large number of incomplete HTTP requests are sent. If number of such open connections in the server exhaust a preset threshold, server does not accept any new connections thus creating DoS. In this paper we make twofold contributions. We do an empirical study on different HTTP servers for their vulnerability against slow HTTP DoS attacks. Subsequently we propose a method to detect Slow HTTP Dos attack. The proposed detection system is an anomaly detection system which measures the Hellinger distance between two probability distributions generated in training and testing phases. In the training phase it creates a normal profile as a probability distribution comprising of complete and incomplete HTTP requests. In case of Slow HTTP attack the proportion of incomplete messages is increased in the overall traffic and detection system leverages this for detection by generating another probability distribution and finding difference between two probability distributions. We experiment by collecting data from a real web server and report the detection performance of proposed detection system. Nikhil Tripathi, Neminath Hubballi |
ARES | 2 |
| 2016 | OCPAD: One class Naive Bayes classifier for payload based anomaly detection
Mayank Swarnkar, Neminath Hubballi |
Expert Syst. Appl. | 2 |
| 2014 | False alarm minimization techniques in signature-based intrusion detection systems: A survey
Neminath Hubballi, Vinoth Suryanarayanan |
Comput. Commun. | 1 |
| 2013 | Towards reducing false alarms in network intrusion detection systems with data summarization techniqueabstractABSTRACT Anomaly based intrusion detection systems (IDSs) create a benign behavior profile of the network, and any deviation from this profile is considered as an attack. Many of the algorithms proposed in the literature for anomaly IDS fall into cluster analysis category. As networks become faster in operation, the amount of data that needs to be analyzed becomes huge. Many clustering techniques require more than one pass on the dataset; thus, when used as anomaly IDSs, these algorithms becomes computationally expensive and cannot work for such high‐speed networks. To handle voluminous data, anomaly IDS schemes have been proposed that use data summarization techniques. Data summarization techniques found in the literature suffer from false alarms due to improper clustering when used as anomaly IDS. In this paper, an anomaly IDS is proposed that is capable of handling large dataset yet minimizing false alarms. Copyright © 2012 John Wiley & Sons, Ltd. Neminath Hubballi, Santosh Biswas, Sukumar Nandi |
Secur. Commun. Networks | 1 |
| 2011 | A host based DES approach for detecting ARP spoofingabstractAddress Resolution Protocol (ARP) based attacks are caused by compromised hosts in the LAN and mainly involve spoofing with falsified IP-MAC pairs. Since ARP is a stateless protocol such attacks are possible. Neither there are signatures available for these attacks nor any significant statistical behavior change can be observed. So existing signature or anomaly intrusion detection systems are unable to detect these type of attacks. Several schemes have been proposed in the literature to circumvent these attacks, however, these techniques either make IP-MAC pairing static, modify the existing ARP, violate network layering architecture etc. In this paper a host based Discrete Event System (DES) approach is proposed for detecting ARP spoofing attacks. This approach does not require any extra constraint like static IP-MAC, changing the ARP or violation of network layering architecture. Ferdous A. Barbhuiya, Santosh Biswas, Neminath Hubballi, Sukumar Nandi |
CICS | 3 |
| 2011 | Network specific false alarm reduction in intrusion detection systemabstractABSTRACT Intrusion Detection Systems (IDSs) are used to find the security violations in computer networks. Usually IDSs produce a vast number of alarms that include a large percentage of false alarms. One of the main reason for such false alarm generation is that, in most cases IDSs are run with default set of signatures. In this paper, a scheme for network specific false alarm reduction in IDS is proposed. A threat profile of the network is created and IDS generated alarms are correlated using neural network. Experiments conducted in a test bed have successfully filtered out most of the false alarms for a range of attacks yet maintaining theDetection Rate. Copyright © 2010 John Wiley & Sons, Ltd. Neminath Hubballi, Santosh Biswas, Sukumar Nandi |
Secur. Commun. Networks | 1 |
| 2010 | Layered Higher Order N-grams for Hardening Payload Based Anomaly Intrusion DetectionabstractApplication based intrusion detection involves analysis of network packet payload data. Recently statistical methods for analyzing the payload are being used. Since behavior of every application is not same a different model is necessary for each application. Studies have revealed that higher order n-grams are good for capturing the network profile. In this paper we introduce a concept of layered version of n-gram for payload based anomaly network intrusion detection. Each layer works as an independent anomaly detection system. A packet is declared as normal after passing through all the layers. A packet is declared as anomalous if at any layer it is declared as anomalous and we stop further processing the packet. We create a set of bins and equally distribute the distinct n-grams to each bin. Each such n-gram is a 2 tulle where the first element is byte values of the n-gram and second is the frequency of gram in the entire training data. We assign an anomaly score to each bin based on the frequency of the individual gram in the bin and is termed as coverage of the bin.We evaluate the proposed scheme on normal traffic of DARLA 99 dataset mixed with a set of attacks. Experimental results shows the efficacy of the method with a false alarm rate as low as 0.001\%. Neminath Hubballi, Santosh Biswas, Sukumar Nandi |
ARES | 1 |