VLDB 2026 Research / reviewers in the wild / expert
Makan Pourzandi
dblp:22/3167
· DBLP profile ↗
72ranked-venue papers
2as first author
31since 2021 · last 2026
0000-0001-9775-6231ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 21 since 2021Computer networks · 11 · 7 since 2021Systems, architecture and hardware · 7 · 2 first-authorSoftware engineering, systems software and programming languages · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Context and Semantics-Aware Mapping of Unstructured Tickets to MITRE ATT&CK TTPs
Hnin Pann Phyu, Boubakr Nour, Makan Pourzandi, Chadi Assi, Mourad Debbabi |
ICC | 3 |
| 2026 | Automating Threat-Aligned Testflows Generation Using Ontology-Grounded RAG From CTI ReportsabstractThe increasing sophistication and complexity of Advanced Persistent Threats (APTs) pose significant challenges to security practitioners. To proactively protect against these threats, security practitioners rely on the generation of testflows, structured sequences of actions designed to verify whether the tactics and behaviors of an APT are present within their organization. However, manually creating such testflows is time-consuming, error-prone, and highly dependent on expert knowledge. Moreover, existing automated approaches suffer from several limitations, including validity, efficiency, and insufficient domain adaptation. To address these challenges, this paper introduces CTI-RAGFlow, to automate the generation of relevant, valid, and effective testflows from unstructured threat reports tailored to specific organizational environments. CTI-RAGFlow introduces three key contributions: (i) a dual-ontology approach, that integrates both a system ontology representing the operational environment and a cybersecurity ontology capturing adversary tactics, techniques, and procedures, improving the precision and accuracy of generated testflows; (ii) a fact-based context retrieval mechanism that combines a hypergraph structured knowledge base with a Retrieval-Augmented Generation pipeline using Large Language Models; and (iii) a fully automated testflow generation process that minimizes manual effort, reduces human error, and facilitates the generation of valid testflow. We evaluate CTI-RAGFlow against three widely used LLM models (e.g., base and fine-tuned models) using publicly available CTI reports for three well-known APTs (e.g., APT41, APT29, APT28). The results show that CTI-RAGFlow outperforms the baselines in terms of semantic relevance, coverage, validity, and effectiveness in verifying multi-stage cyberattack scenarios. Faissal Ahmadou, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Empowering 5G SBA security: Time series transformer for HTTP/2 anomaly detection
Nathalie Wehbe, Hyame Assem Alameddine, Makan Pourzandi, Chadi Assi |
Comput. Secur. | 3 |
| 2025 | PerfSPEC: Performance Profiling-Based Proactive Security Policy Enforcement for ContainersabstractContainer environments provide cloud native applications with scalability, flexibility, and portable support. As a popular container orchestrator, Kubernetes facilitates automatic deployment and maintenance of a large number of containerized applications. However, potential misconfigurations, vulnerabilities, or implementation flaws may empower attackers to exploit the Kubernetes cluster. Although existing solutions such as runtime security policy enforcement may prevent an attack, they can be inefficient in large scale container environments. In this paper, we propose a performance profiling-based proactive security policy enforcement solution, namely, PerfSPEC. First, we accelerate the proactivization of policies (which typically requires significant manual effort) by proposing to profile and rank existing policies according to their induced overhead. This allows us to better focus our efforts and greatly improve the overall response time (e.g., by 98% in contrast to less than 49%). Then, we address the performance limitations of existing solutions by leveraging learning-based approaches to predict future events and compute their verification results in advance. As a result, PerfSPEC achieves a viable response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) even for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Sima Bagheri, Mahmood Gholipourchoubeh, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Cross-Level Security Verification for Network Functions Virtualization (NFV)abstractNetwork Functions Virtualization (NFV) is a popular solution for providing multi-tenant network services on top of existing cloud infrastructures in an agile and cost-effective manner. However, as NFV employs multiple levels of virtualization, it also introduces novel security challenges, such as cloud-level security breaches that are invisible to NFV-level tenants. Towards verifying the security of NFV across all the levels (a.k.a. cross-level security verification), existing solutions are mostly insufficient, as each such solution typically only focuses on one specific level (e.g., cloud, SDN, or SFC), and verifying every level separately would be expensive or even infeasible. In this paper, we propose an efficient and practical system,NFVGuard+, for cross-level security verification for NFV. Particularly, the efficiency ofNFVGuard+is achieved by first performing the costly security verification at one level, and then extrapolating the verification result to other levels through conducting relatively lightweight consistency checks. Additionally, the practicality ofNFVGuard+is ensured by automating the essential steps (e.g., identifying security properties, collecting verification data, and conducting verification) based on a novel Entity-Relationship (ER) model of NFV stack, integrating the approach with OpenStack/Tacker (a popular choice for an NFV deployment), and finally evaluating its effectiveness using both synthetic and real data. Alaa Oqaily, Mohammad Ekramul Kabir, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar, Makan Pourzandi, Mourad Debbabi, Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | PUL-Inter-Slice Defender: An Anomaly Detection Solution for Distributed Slice Mobility AttacksabstractNetwork Slices (NSs) are virtual networks operating over a shared physical infrastructure, each designed to meet specific application requirements while maintaining consistent Quality of Service (QoS). In Fifth Generation (5G) networks, User Equipment (UE) can connect to and seamlessly switch between multiple NSs to access diverse services. However, this flexibility, known as Inter-Slice Switching (ISS), introduces a potential vulnerability that can be exploited to launch Distributed Slice Mobility (DSM) attacks, a form of Distributed Denial of Service (DDoS) attack. To secure 5G networks and their NSs against DSM attacks, we present in this work, PUL-Inter-Slice Defender; an anomaly detection solution that leverages Positive Unlabeled Learning (PUL) and incorporates a combination of Long Short-Term Memory Autoencoders and K-Means clustering. PUL-Inter-Slice Defender leverages the Third Generation Partnership Project (3GPP) key performance indicators and performance measurement counters as features for its machine learning models to detect DSM attack variants while maintaining robustness in the presence of contaminated training data. When evaluated on data collected from our 5G testbed based on the open-source free 5GC and UERANSIM, a UE/ Radio Access Network (RAN) simulator; PUL-Inter-Slice Defender achieved F1-scores exceeding 98.50% on training datasets with 10% to 40% attack contamination, consistently outperforming its counterpart Inter-Slice Defender and other PUL based solutions combining One-Class Support Vector Machine (OCSVM) with Random Forest and XGBoost. Ricardo Misael Ayala Molina, Hyame Assem Alameddine, Makan Pourzandi, Chadi Assi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Threatify: APT Threat Variant Generation Using Graph-Based Machine LearningabstractEnsuring cybersecurity in an ever-evolving threat landscape requires proactive identification and understanding of potential threats. Conventional detection and prediction solutions often fall short as they predominantly focus on known attack vectors. Advanced Persistent Threats (APTs) are becoming increasingly sophisticated and stealthy, resulting in new threat variants that are undetectable by these detection solutions. This paper introduces THREATIFY, a novel approach to predicting the most probable threat variants from existing APTs and previously seen attack campaigns. Our approach automates the generation of threat variants using graph-based machine learning based on the attack definition, past attack campaigns, and the security context between different techniques. THREATIFY leverages a security knowledge base of realistic attack scenarios and cybersecurity expertise to model, generate, and predict new forms of potential future threats by combining inter-(i.e. within the same APT attack) and intra-(i.e. between different APTs) techniques used by threat actors. It is crucial to emphasize that THREATIFY does not merely mix techniques from different APTs; rather, it constructs a logical and pragmatic kill chain based on their security context. THREATIFY is able to predict new attack steps, find relevant techniques to be substituted by, and merge APTs techniques in the current security context, and thus create previously unexplored threat variants. Our extensive experimental results demonstrate the efficacy of our approach in generating relevant and novel threat variants with a similarity score of 92%, uniqueness of 82%, validity of 95%, and reduction rate of 96%, including those that have never occurred before. Boubakr Nour, Makan Pourzandi, Mourad Debbabi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Multi-target Risk Score Aggregation for Security Evaluation of Network EnvironmentsabstractScoring computer systems/networks in terms of specific threats or concerns can enable the comparison of their security level, in a quantitative manner, to facilitate decision making, e.g., mitigation prioritization. The state-of-the-art approaches have mostly focused on scoring the security of a given target, while aggregating scores of multiple systems where each system can be a potential target remains less explored, e.g., whether network A is relatively more secure than network B. In this paper, we take advantage of the well-established attack path representation and use such paths as inter-system influences to derive a risk score of the entire network. We consider the security semantics of various forms of score aggregation, which has not been studied by prior work, and propose to use what we call pairwise path aggregation. We evaluate our approach with a typical fifth Generation (5G) core network, supplemented by evaluations for other network types. The results show that our approach is able to reflect how the overall security varies with multiple factors in common operational scenarios of IT environments. Taous Madi, Matthew Nitschke, Lianying Zhao, Makan Pourzandi |
CloudCom | 5 |
| 2024 | CCSM: Building Cross-Cluster Security Models for Edge-Core Environments Involving Multiple Kubernetes ClustersabstractWith the emergence of 5G networks and their large scale applications such as IoT and autonomous vehicles, telecom operators are increasingly offloading the computation closer to customers (i.e., on the edge). Such edge-core environments usually involve multiple Kubernetes clusters potentially owned by different providers. Confidentiality concerns could prevent those providers from sharing data freely with each other, which makes it challenging to perform common security tasks such as security verification across different clusters. In this work, we propose a solution for building cross-cluster security models to enable various security analyses, while preserving confidentiality for each cluster. We design a six-step methodology to model both the cross-cluster communication and cross-cluster event dependency, and we apply those models to different security use cases. We implement our solution based on a 5G edge-core environment that involves multiple Kubernetes clusters, and our experimental results demonstrate its efficiency (e.g., less than 8 seconds of processing time for a model with 3,600 edges and nodes) and accuracy (e.g., more than 96% for cross-cluster event prediction). Mahmood Gholipourchoubeh, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi |
CODASPY | 7 |
| 2024 | Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall Sequences
Hugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang 0001, Suryadipta Majumdar, Makan Pourzandi |
NDSS | 5 |
| 2024 | ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual Trailers
Momen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi, Mourad Debbabi |
USENIX Security Symposium | 6 |
| 2024 | iCAT+: An Interactive Customizable Anonymization Tool Using Automated Translation Through Deep LearningabstractData anonymization is a viable solution for data owners to mitigate their privacy concerns. However, existing data anonymization tools are inflexible to support various privacy and utility requirements of both data owners and data users. In most cases, this limitation is due to a lack of understanding of those requirements as well as the non-customizability of the existing tools. To address this limitation, we proposeiCAT+, which is an interactive and customizable anonymization approach. More specifically, we first automate the interpretation of data owners’ and data users’ textual requirements by deploying a Convolutional Neural Network (CNN) model for Natural Language Processing (NLP). Second, we introduce the concept of theanonymization spaceto model possible combinations of per-attribute anonymization primitives based on the level of privacy and utility that each primitive provides. Third, we design an ontology model that maps the translated requirements into their appropriate anonymization primitives in the defined anonymization space corresponding to the plain data. Fourth, we evaluate the efficiency and effectiveness ofiCAT+based on both real and synthetic network data. Finally, we assess its usability through a real user study involving participants from industry and research laboratories. Our experiments show the effectiveness and efficiency of our solution (e.g., requirement translation accuracy of 99% at the data owner side and 98% at the data user side, with a computational time of around one minute for the Google cluster dataset). Momen Oqaily, Mohammad Ekramul Kabir, Suryadipta Majumdar, Yosr Jarraya, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Caught-in-Translation (CiT): Detecting Cross-Level Inconsistency Attacks in Network Functions Virtualization (NFV)abstractAs one of the main technology pillars of 5G networks, Network Functions Virtualization (NFV) enables agile and cost-effective deployment of network services. However, the multi-level, multi-actor design of NFV may also allow for inconsistency between the different abstraction levels to be mistakenly or intentionally introduced, as shown in recent studies. Serious security issues, such as man-in-the-middle, network sniffing, and DoS, may arise at one abstraction level without being noticed by the victims at another level. Most existing solutions are either limited to one abstraction level of NFV or reliant on direct access to lower-level data which could become inaccessible when managed by different providers. In this paper, by drawing an analogy between cross-level NFV event sequences and natural languages, we propose a Neural Machine Translation-based approach, namely,Caught-in-Translation (CiT), to detect cross-level inconsistency attacks in NFV at runtime. Specifically, we first extract event sequences from different abstraction levels of an NFV stack. We then leverage Long Short-Term Memory (LSTM) to translate the event sequences from one level to another. Finally, we apply both a similarity metric and a Siamese neural network to compare thetranslatedevent sequences with theoriginalones to detect attacks. We integrateCiTinto OpenStack/Tacker, a popular open-source NFV implementation, and evaluate its performance using both real and synthetic data. Experimental results show the benefit of leveraging NMT asCiTachieves AUC≥96.03%, which significantly outperforms traditional SVM-based anomaly detection. We also evaluateCiTin terms of its efficiency, scalability, and robustness for detecting inconsistency attacks in NFV platforms. Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes ClustersabstractA large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution. Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | AUTOMA: Automated Generation of Attack Hypotheses and Their Variants for Threat Hunting Using Knowledge DiscoveryabstractThreat hunting is a proactive security defense line exercised to uncover attacks that could circumvent conventional detection mechanisms. It is based on an iterative approach to generate, inspect, and revise attack hypotheses. The quality of these hypotheses is essential to prove/refute the existence of an attack. Today, attack hypotheses are often generated manually by security analysts. The generation process requires elusive expertise, is costly, and is prone to produce a large number of irrelevant hypotheses without considering the attack variants. In this paper, we address the aforementioned challenges by designing AUTOMA, a solution that automates the generation of relevant hypotheses and their variants using knowledge discovery. AUTOMA incorporates the system telemetry in combination with a knowledge base of existing attacks, techniques, and their relationships to mine the most relevant hypotheses. In order to increase the relevance of the generated hypotheses, AUTOMA examines these hypotheses by applying matching-based similarity, success, likelihood, and criticality evaluations. These evaluations are based on the past occurrences of the techniques part of a hypothesis in the system telemetry and the knowledge base. Additionally, AUTOMA uses sequence success, sequence alignment, and hierarchical similarity approach for generating potential attack variants of a hypothesis taking into account the dynamism and stealthiness of attackers in coming up with alternative attack steps. We extensively evaluate the effectiveness and efficiency of AUTOMA using a real dataset for 284 attack campaigns distributed over 57 advanced persistent threats. The obtained results show that AUTOMA is able to generate the relevant hypothesis (top 3), with a large reduction rate (up to 99%), and fast execution time (up to 8 minutes for proposing the relevant hypothesis and 10 seconds for variants generation). Boubakr Nour, Makan Pourzandi, Rushaan Kamran Qureshi, Mourad Debbabi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A Tenant-based Two-stage Approach to Auditing the Integrity of Virtual Network Function Chains Hosted on Third-Party CloudsabstractThere is a growing trend of hosting chains of Virtual Network Functions (VNFs) on third-party clouds for more cost-effective deployment. However, the multi-actor nature of such a deployment may allow a mismatch to silently arise between tenant-level specifications of VNF chains and their cloud provider-level deployment. Most existing auditing approaches would face difficulties in identifying such an integrity breach. First, relying on the cloud provider may not be sufficient, since modifications made by a stealthy attacker may seem legitimate to the provider. Second, the tenant cannot directly perform the auditing due to limited access to the provider-level data. In addition, shipping such data to the tenant would incur prohibitive overhead and confidentiality concerns. In this paper, we design a tenant-based, two-stage solution where the first stage leverages tenant-level side-channel information to identify suspected integrity breaches, and then the second stage automatically identifies and anonymizes selected provider-level data for the tenant to verify the suspected breaches from the first stage. The key advantages of our solution are: (i) the first stage gives tenants more control and transparency (with the capability of identifying integrity breaches without the provider's assistance), and (ii) the second stage provides tenants higher accuracy (with the capability of rigorous verification based on provider-level data). Our solution is integrated into OpenStack/Tacker (a popular choice for NFV deployment), and its effectiveness is demonstrated via experiments (e.g., up to 90% accuracy with the first stage alone). Momen Oqaily, Suryadipta Majumdar, Lingyu Wang 0001, Mohammad Ekramul Kabir, Yosr Jarraya, A. S. M. Asadujjaman, Makan Pourzandi, Mourad Debbabi |
CODASPY | 7 |
| 2023 | Evaluating the Security Posture of 5G Networks by Combining State Auditing and Event Monitoring
Md. Nazmul Hoq, Jia Wei Yao, Suryadipta Majumdar, Lingyu Wang 0001, Amine Boukhtouta, Makan Pourzandi, Mourad Debbabi |
ESORICS (2) | 7 |
| 2023 | Warping the Defence Timeline: Non-Disruptive Proactive Attack Mitigation for Kubernetes ClustersabstractIn spite of being the de-facto standard of container orchestrators, Kubernetes reportedly suffers from security vulnerabilities and misconfigurations which may lead to severe security threats to the containerized environments it manages. Mitigating such threats based on alerts raised by existing security monitoring solutions (e.g., Falco) can be challenging. First, taking actions upon every alert can cause unacceptable service disruption, as many such alerts may turn out to be false positives. Second, validating each alert by administrators before taking actions may render the mitigation too late to prevent irreversible damages, e.g., denial of service. In this paper, we propose a non-disruptive proactive mitigation approach to address those limitations. Our main idea is to proactively trigger mitigation ahead of an attack to prevent irreversible damages, while designing the mitigation actions to be non-disruptive to avoid any service disruption caused by false alerts. We implement and integrate our approach with Kubernetes, and show its effectiveness and efficiency. Sima Bagheri, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
ICC | 6 |
| 2022 | 5GFIVer: Functional Integrity Verification for 5G Cloud-Native Network Functionsabstract5G networks attain a better performance along with a reduction in cost by cloudifying its network functions as Cloud+native Network Functions (CNFs). However, CNF may introduce new security concerns (e.g., data exfiltration and ransomware) due to potential code injection attacks against network functions at runtime. This will potentially result in a breach of functional integrity of these network functions. Towards verifying such functional integrity breaches of CNFs at the 5G-operator-level, existing approaches fell short, as most of them either (i) perform pre-deployment verification (i.e., verifying the CNF image before the deployment) and hence fail to verify integrity breaches occurring after the deployment, or (ii) perform post-deployment verification (i.e., verifying against attack signatures or normal behavior patterns) approaches that require provider-level data (e.g., system calls) which is usually inaccessible to 5G operators. In this paper, we propose 5GFIVer, a new operator-oriented approach for functional integrity verification of CNFs that overcomes the above-mentioned limitations. First, our approach utilizes the side-channel information such as performance metrics (which are already available at the operator level) so that no provider-level data is needed. Second, our approach implements unsupervised machine learning algorithms to detect outliers through time-series analysis of those available performance metrics, and hence no instrumentation for the data collection as well as no training data is required. Third, we leverage the correlation between multiple CNFs to improve the accuracy and minimize false positives (e.g., caused by cloud dynamics). Our experimental results under an open source 5G testbed demonstrate the effectiveness and negligible overhead of our solution. A. S. M. Asadujjaman, Mohammad Ekramul Kabir, Hinddeep Purohit, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Makan Pourzandi |
CloudCom | 7 |
| 2022 | A Hybrid Decision-making Approach to Security Metrics Aggregation in Cloud EnvironmentsabstractIn cybersecurity, being able to quantity the level of security has been a long quest so that decisions can be made toward improving security. Various metrics have been proposed and applied, which can usually be computed from collected measurements. However, only certain aspects of the target system are measured corresponding to the purpose the metrics were designed for, be it software vulnerabilities or configuration errors, thus lacking a concise and clear image of the overall security of a system for the practitioners to act on, especially when it comes to large-scale or complex systems.We argue that overall security metrics are defined by humans based on specific security goals before they can be computed. Therefore, we propose a hybrid approach to the aggregation of well-established individual security metrics by combining machine computation with human decision making. In particular, we modify the Analytic Hierarchy Process (AHP) to reach a group decision of selected “experts”, which can derive the weights of individual metrics for their aggregation. We showcase its feasibility by selecting several common metrics to measure the target systems in our testbed, and conducting an AHP survey with seventeen experts. The resulted overall security score for the target systems shows how our approach enables comparison of the overall security between those systems. By considering cloud-oriented settings, we also showcase how this approach can be applicable to today’s virtualized environments. Lianying Zhao, Makan Pourzandi, Fereydoun Farrahi Moghaddam |
CloudCom | 3 |
| 2022 | ProSPEC: Proactive Security Policy Enforcement for ContainersabstractBy providing lightweight and portable support for cloud native applications, container environments have gained significant momentum lately. A container orchestrator such as Kubernetes can enable the automatic deployment and maintenance of a large number of containerized applications. However, due to its critical role, a container orchestrator also attracts a wide range of security threats exploiting misconfigurations or implementation flaws. Moreover, enforcing security policies at runtime against such security threats becomes far more challenging, as the large scale of container environments implies high complexity, while the high dynamicity demands a short response time. In this paper, we tackle this key security challenge to container environments through a proactive approach, namely, ProSPEC. Our approach leverages learning-based prediction to conduct the computationally intensive steps (e.g., security verification) in advance, while keeping the runtime steps (e.g., policy enforcement) lightweight. Consequently, ProSPEC can ensure a practical response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Mahmood Gholipourchoubeh, Sima Bagheri, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
CODASPY | 6 |
| 2022 | MLFM: Machine Learning Meets Formal Method for Faster Identification of Security Breaches in Network Functions Virtualization (NFV)
Alaa Oqaily, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi, Suryadipta Majumdar |
ESORICS (3) | 4 |
| 2022 | ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
Azadeh Tabiban, Heyang Zhao, Yosr Jarraya, Makan Pourzandi, Mengyuan Zhang 0001, Lingyu Wang 0001 |
NDSS | 4 |
| 2022 | ProSAS: Proactive Security Auditing System for CloudsabstractThe multi-tenancy in a cloud along with its dynamic and self-service nature could cause severe security concerns, such as isolation breaches among cloud tenants. To mitigate such concerns and ensure the accountability and transparency of the cloud providers towards their tenants, verifying cloud states against a list of security policies, a.k.a.security auditing, is a promising solution. However, the existing security auditing solutions for clouds suffer from several limitations. First, the traditional auditing approach, which is retroactive in nature, can only detect violations after the fact and hence, often becomes ineffective while dealing with the dynamic nature of a cloud. Second, the existing runtime approaches can cause significant delay in the response time while dealing with the sheer size of a cloud. Finally, the current proactive approaches typically rely on prior knowledge about future changes in a cloud and also require significant manual efforts, and thus become less practical for a dynamic environment like cloud. To address those limitations, we present a novel proactive security auditing system, namely,ProSAS, which can prevent violations to security policies at runtime with a practical response time, and yet does not require prior knowledge about future changes. More specifically,ProSASfirst establishes its models (e.g., dependency relationships between cloud events, and critical events) through learning from historical data (e.g., logs); it then predicts future critical events which would likely follow a received event by leveraging the dependency relationships; afterwards, it proactively verifies the impacts of those future events, and prevents those events which can cause violations of security policies. ProSAS is integrated into OpenStack, a popular cloud management platform, and we provide a concrete guideline to port ProSAS to other popular cloud platforms, such as Google Cloud Platform, and Amazon EC2. Our experiment results using both real and synthetic data demonstrate the improvement of efficiency (i.e., reducing response time to 1,450 nanoseconds at best and 8.5 milliseconds on average for a large-scale cloud with 10,000 tenants) and level of automation (i.e., learning more than 20 new critical events spanning 100 days) in proactive security auditing by ProSAS. Suryadipta Majumdar, Gagandeep Singh Chawla, Amir Alimohammadifar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2021 | DistAppGaurd: Distributed Application Behaviour Profiling in Cloud-Based EnvironmentabstractToday, Machine Learning (ML) techniques are increasingly used to detect abnormal behaviours of industrial applications. Since many of these applications are moving to the cloud environments, classical ML approaches are facing new challenges in accurately identifying abnormal behaviours due to the highly dynamic and heterogeneous nature of the cloud. In this paper, we propose a novel framework, DistAppGaurd, for profiling simultaneously the behaviour of all microservice components of a distributed application in the cloud. The framework can therefore, detect complex attacks that are not observable by monitoring a single process or a single microservice. DistAppGaurd utilizes the system calls executed by all the processes of an application to build a graph consisting of data exchanges among different application entities (e.g., processes and files) representing the behaviour of the application. This representation is then used by our novel miroservice-aware Autoencoder model to perform anomaly detection at runtime. The efficiency and feasibility of our approach is shown by implementing several different real-world attacks, which yields high detection rates (94%-97%) at 0.01% false alarm rate. Mohammad Mahdi Ghorbani, Fereydoun Farrahi Moghaddam, Mengyuan Zhang 0001, Makan Pourzandi, Kim Khoa Nguyen, Mohamed Cheriet |
ACSAC | 4 |
| 2021 | AutoGuard: A Dual Intelligence Proactive Anomaly Detection at Application-Layer in 5G Networks
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta, Moataz Samir 0001, Chadi Assi |
ESORICS (1) | 3 |
| 2021 | Towards 5G-ready Security MetricsabstractThe fifth-generation (5G) mobile telecom network has been garnering interest in both academia and industry, with better flexibility and higher performance compared to previous generations. Along with functionality improvements, new attack vectors also made way. Network operators and regulatory organizations wish to have a more precise idea about the security posture of 5G environments. Meanwhile, various security metrics for IT environments have been around and attracted the community’s attention. However, 5G-specific factors are less taken into consideration.This paper considers such 5G-specific factors to identify potential gaps if existing security metrics are to be applied to the 5G environments. In light of the layered nature and multi-ownership, the paper proposes a new approach to the modular computation of security metrics based on cross-layer projection as a means of information sharing between layers. Finally, the proposed approach is evaluated through simulation. Lianying Zhao, Muhammad Shafayat Oshman, Mengyuan Zhang 0001, Fereydoun Farrahi Moghaddam, Shubham Chander, Makan Pourzandi |
ICC | 6 |
| 2021 | NFV security survey in 5G networks: A three-dimensional threat taxonomy
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta |
Comput. Networks | 3 |
| 2021 | VMGuard: State-Based Proactive Verification of Virtual Network Isolation With Application to NFVabstractNetwork Functions Virtualization (NFV) leverages from clouds to simplify and automate the creation and deployment of network services on the fly in a multi-tenant environment. However, clouds may also bring issues leading to tenants' concerns over possible breaches violating the isolation of their deployments. Verifying such network isolation breaches in cloud-enabled NFV environments faces unique challenges. The fine-grained and distributed network access control (e.g., per-function security group rules), which is typical to virtual cloud infrastructures, requires examining not only the events but also the states of all virtual resources using a state-based verification approach. However, verifying the state of a virtual infrastructure may become highly complex and non-scalable due to its sheer size paired with the self-serviced dynamic nature of clouds. In this article, we propose VMGuard, a state-based proactive approach for efficiently verifying large-scale virtual infrastructures in cloud and NFV against network isolation policies. Informally, our key idea is to proactively trigger the verification based on predicted events and their simulated impact upon the current state, such that we can have the best of both worlds, i.e., the efficiency of a proactive approach and the effectiveness of state-based verification. We implement and evaluate VMGuard based on OpenStack, and our experiments with both real and synthetic data demonstrate the performance and efficiency, e.g., less than five milliseconds to perform incremental verification on a dataset with more than 25, 000 VMs and less than two milliseconds with the proactive module enabled. Gagandeep Singh Chawla, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | SegGuard: Segmentation-Based Anonymization of Network Data in Clouds for Privacy-Preserving Security AuditingabstractSecurity auditing allows cloud tenants to verify the compliance of cloud infrastructure with respect to desirable security properties, e.g., whether a tenant’s virtual network is properly isolated from other tenants’ networks. However, the input to the auditing task, such as the detailed topology of the underlying cloud infrastructure, typically contains sensitive information which a cloud provider may be reluctant to hand over to a third party auditor. Additionally, auditing results intended for one tenant may inadvertently reveal private information about other tenants, e.g., another tenant’s VM is reachable due to a misconfiguration. How to anonymize both the input data and the auditing results in order to prevent such information leakage is a novel challenge that has received little attention. Directly applying most of the existing anonymization techniques to such a context would either lead to insufficient protection or render the data unsuitable for auditing. In this article, we proposeSegGuard, a novel anonymization approach that prevents cross-tenant information leakage through per-tenant encryption, and prevents information leakage to auditors through hiding real input segments among fake ones; in addition, applying property-preserving encryption in an innovative way enablesSegGuardto preserve the data utility for auditing while mitigating semantic attacks. We implementSegGuardbased on OpenStack, and evaluate its effectiveness and overhead using both synthetic and real data. Our experimental results demonstrate thatSegGuardcan reduce the information leakage to a negligible level (e.g., less than 1 percent for an adversary with 50 percent pre-knowledge) with a practical response time (e.g., 62 seconds to anonymize a cloud infrastructure with 25,000 virtual machines). Momen Oqaily, Yosr Jarraya, Meisam Mohammady, Suryadipta Majumdar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | A Multi-view Approach to Preserve Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces or require heavy data sanitization or perturbation, which may result in a significant loss of data utility. In this article, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces: Those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The experimental results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Momen Oqaily, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
ACM Trans. Priv. Secur. | 6 |
| 2020 | R2DP: A Universal and Automated Approach to Optimizing the Randomization Mechanisms of Differential Privacy for Utility Metrics with No Known Optimal DistributionsabstractDifferential privacy (DP) has emerged as a de facto standard privacy notion for a wide range of applications. Since the meaning of data utility in different applications may vastly differ, a key challenge is to find the optimal randomization mechanism, i.e., the distribution and its parameters, for a given utility metric. Existing works have identified the optimal distributions in some special cases, while leaving all other utility metrics (e.g., usefulness and graph distance) as open problems. Since existing works mostly rely on manual analysis to examine the search space of all distributions, it would be an expensive process to repeat such efforts for each utility metric. To address such deficiency, we propose a novel approach that can automatically optimize different utility metrics found in diverse applications under a common framework. Our key idea that, by regarding the variance of the injected noise itself as a random variable, a two-fold distribution may approximately cover the search space of all distributions. Therefore, we can automatically find distributions in this search space to optimize different utility metrics in a similar manner, simply by optimizing the parameters of the two-fold distribution. Specifically, we define a universal framework, namely, randomizing the randomization mechanism of differential privacy (R2DP), and we formally analyze its privacy and utility. Our experiments show that R2DP can provide better results than the baseline distribution (Laplace) for several utility metrics with no known optimal distributions, whereas our results asymptotically approach to the optimality for utility metrics having known optimal distributions. As a side benefit, the added degree of freedom introduced by the two-fold distribution allows R2DP to accommodate the preferences of both data owners and recipients. Meisam Mohammady, Shangyu Xie, Yuan Hong 0001, Mengyuan Zhang 0001, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
CCS | 6 |
| 2020 | Malchain: Virtual Application Behaviour Profiling by Aggregated Microservice Data Exchange GraphabstractIn the recent literature, Machine Learning (ML) techniques are increasingly used to detect the abnormal behaviour for different applications. Recently, these applications have moved to the cloud and virtualized environments due to the unique benefits such as deployment agility, scalability, flexibility and resiliency. However, those benefits pose a new challenge for classical ML approaches to accurately identify abnormal behaviours due to their highly dynamic and heterogeneous nature. In this paper, we propose a new approach Malchain for profiling virtual applications based on using a new concept: microservice role. The roles are used to provide a consistent view of the virtual application addressing the mentioned new challenges. The microservice data exchange graph built using this consistent view is then used to extract features providing the appropriate measures to profile the aggregated behaviour of the microservices comprising a virtual application. We show the efficiency and feasibility of our approach by implementing several different real-world attacks, and measuring high detection rates (86%-99%) for those attacks. Mohammad Mahdi Ghorbani, Fereydoun Farrahi Moghaddam, Mengyuan Zhang 0001, Makan Pourzandi, Kim Khoa Nguyen, Mohamed Cheriet |
CloudCom | 4 |
| 2020 | NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) StackabstractNetwork Functions Virtualization (NFV) enables agile and cost-effective deployment of multi-tenant network services on top of a cloud infrastructure. However, the multi-tenant and multilevel nature of NFV may lead to novel security challenges, such as stealthy attacks exploiting potential inconsistencies between different levels of the NFV stacks. Consequently, the security compliance of a multilevel NFV stack cannot be sufficiently established using existing solutions, which typically focus on one level. Moreover, the naive approach of separately verifying every level could be expensive or even infeasible. In this paper, we propose, NFVGuard, the first multilevel approach to the formal security verification of NFV stacks. Our key idea is to conduct the security verification at only one level, and then assure that verification result for other levels by verifying the consistency between adjacent levels. We integrate NFVGuard with OpenStack/Tacker, a popular platform for the NFV deployment, and experimentally evaluate its effectiveness. Alaa Oqaily, Sudershan Lakshmanan Thirunavukkarasu, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 6 |
| 2019 | Modeling NFV Deployment to Identify the Cross-Level Inconsistency VulnerabilitiesabstractBy providing network functions through software running on standard hardware, Network Functions Virtualization (NFV) brings many benefits, such as increased agility and flexibility with reduced costs, as well as additional security concerns. Although existing works have examined various security issues of NFV, such as vulnerabilities in VNF software and DoS, there has been little effort on a security issue that is intrinsic to NFV, i.e., as an NFV environment typically involves multiple abstraction levels, the inconsistency that may arise between different levels can potentially be exploited for security attacks. In this paper, we propose the first NFV deployment model to capture the deployment aspects of NFV at different abstraction levels, which is essential for an in-depth study of the inconsistencies between such levels. Based on the model and an implemented NFV testbed, we present concrete attack scenarios in which the inconsistencies are exploited to attack the network functions in a stealthy manner. Finally, we study the feasibility of detecting the inconsistencies through verification. Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001, Alaa Oqaily, Gagandeep Singh Chawla, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
CloudCom | 6 |
| 2019 | Proactivizer: Transforming Existing Verification Tools into Efficient Solutions for Runtime Security Enforcement
Suryadipta Majumdar, Azadeh Tabiban, Meisam Mohammady, Alaa Oqaily, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 6 |
| 2019 | iCAT: An Interactive Customizable Anonymization Tool
Momen Oqaily, Yosr Jarraya, Mengyuan Zhang 0001, Lingyu Wang 0001, Makan Pourzandi, Mourad Debbabi |
ESORICS (1) | 5 |
| 2019 | Learning probabilistic dependencies among events for proactive security auditing in cloudsabstractSecurity compliance auditing is a viable solution to ensure the accountability and transparency of a cloud provider to its tenants. However, the sheer size of a cloud, coupled with the high operational complexity implied by the multi-tenancy and self-service nature, can easily render existing runtime auditing techniques too expensive and non-scalable. To this end, a proactive approach, which prepares for the auditing ahead of critical events, is a promising solution to reduce the response time to a practical level. However, a key limitation of such approaches is their reliance on manual efforts to extract the dependency relationships among events, which greatly restricts their practicality. What makes things worse is the fact that, as the most important input to security auditing, the logs and configuration databases of a real world cloud platform can be unstructured and not ready to be used for efficient security auditing. In this paper, we first propose a log processing technique, which prepares raw cloud logs for different analysis purposes, and then design a learning-based proactive security auditing system, namely, [Formula: see text]. To this end, we conduct case studies on current log formats in different real-world OpenStack (a popular cloud platform) deployments, and identify major challenges in log processing. Later, we design a stand-alone log processor for clouds, which may potentially be used for various log analyses. Consequently, we leverage the log processor outputs to extract probabilistic dependencies from runtime events for the dependency models. Finally, through these dependency models, we proactively prepare for security critical events and prevent security violations resulting from those critical events. Furthermore, we integrate [Formula: see text] to OpenStack and perform extensive experiments in both simulated and real cloud environments that show a practical response time (e.g., 6 ms to audit a cloud of 100,000 VMs) and a significant improvement (e.g., about 50% faster) over existing proactive approaches. In addition, we successfully and efficiently apply our log processor outputs to other learning techniques (e.g., executing sequence pattern mining algorithms within 18 ms for 50,000 events). Suryadipta Majumdar, Azadeh Tabiban, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
J. Comput. Secur. | 6 |
| 2019 | ISOTOP: Auditing Virtual Networks Isolation Across Cloud Layers in OpenStackabstractMulti-tenancy in the cloud is a double-edged sword. While it enables cost-effective resource sharing, it increases security risks for the hosted applications. Indeed, multiplexing virtual resources belonging to different tenants on the same physical substrate may lead to critical security concerns such as cross-tenants data leakage and denial of service. Particularly, virtual networks isolation failures are among the foremost security concerns in the cloud. To remedy these, automated tools are needed to verify security mechanisms compliance with relevant security policies and standards. However, auditing virtual networks isolation is challenging due to the dynamic and layered nature of the cloud. Particularly, inconsistencies in network isolation mechanisms across cloud-stack layers, namely, the infrastructure management and the implementation layers, may lead to virtual networks isolation breaches that are undetectable at a single layer. In this article, we propose an offline automated framework for auditing consistent isolation between virtual networks in OpenStack-managed cloud spanning over overlay and layer 2 by considering both cloud layers’ views. To capture the semantics of the audited data and its relation to consistent isolation requirement, we devise a multi-layered model for data related to each cloud-stack layer’s view. Furthermore, we integrate our auditing system into OpenStack, and present our experimental results on assessing several properties related to virtual network isolation and consistency. Our results show that our approach can be successfully used to detect virtual network isolation breaches for large OpenStack-based data centers in reasonable time. Taous Madi, Yosr Jarraya, Amir Alimohammadifar, Suryadipta Majumdar, Yushun Wang, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ACM Trans. Priv. Secur. | 6 |
| 2019 | Efficient Provisioning of Security Service Function Chaining Using Network Security Defense PatternsabstractNetwork functions virtualization intertwined with software-defined networking opens up great opportunities for flexible provisioning and composition of network functions, known as network service chaining. In the cloud, this allows providers to create service chains tuned to each application type while optimizing resources' utilization. This is particularly useful to accommodate different tenants' applications with different security needs. However, considering security provisioning from the single perspective of resources optimization may lead to deployment solutions that do not comply with well-known security-related best practices and recommendations. In this paper, we propose network security defense patterns (NSDP) aimed at leveraging the best practice and know-how from the security experts and at capturing various security constraints to efficiently select compliant security functions' deployment options. The placement problem being a NP-Hard problem to solve, we also propose a scalable networking and computing resources aware optimization framework to efficiently provision different NSDPs. We further show the feasibility of implementing NSDPs in the cloud infrastructure through the integration of our approach into an open source cloud framework, namely OpenStack, in our test laboratory. The simulation results show the effectiveness of our approach in selecting an optimal placement of the security functions for large data centers with hundreds of thousands of computing nodes, while complying with the predefined security constraints and improving the scalability compared to the current placement algorithms. Alireza Shameli-Sendi, Yosr Jarraya, Makan Pourzandi, Mohamed Cheriet |
IEEE Trans. Serv. Comput. | 3 |
| 2018 | Preserving Both Privacy and Utility in Network Trace AnonymizationabstractAs network security monitoring grows more sophisticated, there is an increasing need for outsourcing such tasks to third-party analysts. However, organizations are usually reluctant to share their network traces due to privacy concerns over sensitive information, e.g., network and system configuration, which may potentially be exploited for attacks. In cases where data owners are convinced to share their network traces, the data are typically subjected to certain anonymization techniques, e.g., CryptoPAn, which replaces real IP addresses with prefix-preserving pseudonyms. However, most such techniques either are vulnerable to adversaries with prior knowledge about some network flows in the traces, or require heavy data sanitization or perturbation, both of which may result in a significant loss of data utility. In this paper, we aim to preserve both privacy and utility through shifting the trade-off from between privacy and utility to between privacy and computational cost. The key idea is for the analysts to generate and analyze multiple anonymized views of the original network traces; those views are designed to be sufficiently indistinguishable even to adversaries armed with prior knowledge, which preserves the privacy, whereas one of the views will yield true analysis results privately retrieved by the data owner, which preserves the utility. We formally analyze the privacy of our solution and experimentally evaluate it using real network traces provided by a major ISP. The results show that our approach can significantly reduce the level of information leakage (e.g., less than 1% of the information leaked by CryptoPAn) with comparable utility. Meisam Mohammady, Lingyu Wang 0001, Yuan Hong 0001, Habib Louafi, Makan Pourzandi, Mourad Debbabi |
CCS | 5 |
| 2018 | QuantiC: Distance Metrics for Evaluating Multi-Tenancy Threats in Public CloudabstractAs a cornerstone of cloud computing, multi-tenancy brings not only the benefit of resource sharing but also additional security implications. To achieve an optimal trade-off between security and resource sharing, cloud providers are obliged to evaluate the potential threats related to multi-tenancy. However, quantitative approaches for evaluating those threats are largely missing in existing works. In this paper, we propose a set of multi-level distance metrics that quantify the proximity of tenants' virtual resources inside a cloud. Those metrics are defined based on the configuration and deployment in a cloud, such that a cloud provider may apply them to evaluate the risk related to potential multi-tenancy attacks. We conduct case studies and experiments on both real and fictitious clouds. The obtained results show the effectiveness and applicability of our metrics. We further implement our metrics in OpenStack and show how they can be applied for distance auditing. Taous Madi, Mengyuan Zhang 0001, Yosr Jarraya, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 5 |
| 2018 | Fingerprinting Crowd Events in Content Delivery Networks: A Semi-supervised Methodology
Amine Boukhtouta, Makan Pourzandi, Richard Brunner, Stéphane Dault |
DBSec | 2 |
| 2018 | Stealthy Probing-Based Verification (SPV): An Active Approach to Defending Software Defined Networks Against Topology Poisoning Attacks
Amir Alimohammadifar, Suryadipta Majumdar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 5 |
| 2018 | User-Level Runtime Security Auditing for the CloudabstractCloud computing is emerging as a promising IT solution for enabling ubiquitous, convenient, and on-demand accesses to a shared pool of configurable computing resources. However, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security auditing techniques. Auditing in cloud poses many unique challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures), and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and need of runtime verification for the dynamic nature of cloud). To this end, existing runtime auditing techniques do not offer a practical response time to verify a wide-range of user-level security properties for a large cloud. In this paper, we propose a runtime security auditing framework for the cloud with special focus on the user-level including common access control and authentication mechanisms e.g., RBAC, ABAC, SSO, and we implement and evaluate the framework based on OpenStack, a widely deployed cloud management system. The main idea towards reducing the response time to a practical level is to perform the costly operations only once, which is followed by significantly more efficient incremental runtime verification. Our experimental results show that runtime security auditing in a large cloud environment is realistic under our approach (e.g., our solution performs runtime auditing of 100,000 users within 500 milliseconds). Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2017 | LeaPS: Learning-Based Proactive Security Auditing for Clouds
Suryadipta Majumdar, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 5 |
| 2017 | A Framework for Enabling Security Services Collaboration Across Multiple DomainsabstractCollaboration among Security Service Functions (SSF) is expected to become as essential to SECaaS (SECurity as a Service) systems as elasticity is to IaaS (Infrastructure as a Service). The virtualization opens new era in network security as new security appliances can be created on demand in appropriate places in the network. At the same time, the increasing size and diversity of attacks make it necessary to come up with new approaches for more efficient and more resilient security mechanisms. In this paper, we propose a new framework leveraging SDN (Software Defined Networking) and SFC (Service Function Chaining) to enhance the collaboration among different SSFs to mitigate large scale attacks. We describe a framework that allows SSFs from different domains to negotiate and dynamically control the amount of resources allocated for collaboration, in what we call a "best-effort" collaboration mode. This SSF collaboration framework creates a distributed mitigation system for handling large scale attacks in a dynamic and scalable manner. The efficiency and feasibility of this framework is experimentally assessed, showing that our approach incurs low overhead, increases the amount of traffic treated by SSFs and reduces the dropped traffic due to the lack of resources from the security mechanisms. Daniel Migault, Marcos A. Simplício Jr., Bruno M. Barros, Makan Pourzandi, Thiago R. M. Almeida, Ewerton R. Andrade, Tereza Cristina M. B. Carvalho |
ICDCS | 4 |
| 2017 | TenantGuard: Scalable Runtime Verification of Cloud-Wide VM-Level Network Isolation
Yushun Wang, Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
NDSS | 6 |
| 2016 | Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
Taous Madi, Suryadipta Majumdar, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
CODASPY | 5 |
| 2016 | Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (1) | 5 |
| 2015 | Multistage OCDO: Scalable Security Provisioning Optimization in SDN-Based CloudabstractCloud computing is increasingly changing the landscape of computing, however, one of the main issues that is refraining potential customers from adopting the cloud is the security. Network functions virtualization together with software-defined networking can be used to efficiently coordinate different network security functionality in the network. To squeeze the best out of network capabilities, there is need for algorithms for optimal placement of the security functionality in the cloud infrastructure. However, due to the large number of flows to be considered and complexity of interactions in these networks, the classical placement algorithms are not scalable. To address this issue, we elaborate an optimization framework, namely OCDO, that provides adequate and scalable network security provisioning and deployment in the cloud. Our approach is based on an innovative multistage approach that combines together decomposition and segmentation techniques to the problem of security functions placement while coping with the complexity and the scalability of such an optimization problem. We present the results of multiple scenarios to assess the efficiency and the adequacy of our framework. We also describe our prototype implementation of the framework integrated into an open source cloud framework, i.e. Open stack. Yosr Jarraya, Alireza Shameli-Sendi, Makan Pourzandi, Mohamed Cheriet |
CLOUD | 3 |
| 2015 | Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStackabstractCloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute). Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
CloudCom | 5 |
| 2015 | Optimal placement of sequentially ordered virtual security appliances in the cloudabstractTraditional enterprise network security is based on the deployment of security appliances placed on some specific locations filtering, monitoring the traffic going through them. In this perspective, security appliances are chained in specific order to perform different security functions on the traffic. In the cloud, the same approach is often adopted using virtual security appliances to protect traffic for different virtual applications with the challenge of dealing with the flexible and elastic nature of the cloud. In this paper, we investigate the problem of placing virtual security appliances within the data center in order to minimize network latency and computing costs for security functions while maintaining the required sequential order of traversing virtual security appliances. We propose a new algorithm computing the best place to deploy these virtual security appliances in the data center. We further integrated our placement algorithm in an open source cloud framework, i.e. Openstack, in our test laboratory. The preliminary results show that we are placing the virtual security appliances in the required sequential order while improving the efficiency compared to the current default placement algorithm in Openstack. Alireza Shameli-Sendi, Yosr Jarraya, Mohamed Fekih Ahmed, Makan Pourzandi, Chamseddine Talhi, Mohamed Cheriet |
IM | 4 |
| 2015 | Verification of firewall reconfiguration for virtual machines migrations in the cloud
Yosr Jarraya, Arash Eghtesadi, Sahba Sadri, Mourad Debbabi, Makan Pourzandi |
Comput. Networks | 5 |
| 2015 | Taxonomy of Distributed Denial of Service mitigation approaches for cloud computingabstractCloud computing has a central role to play in meeting today׳s business requirements. However, Distributed Denial-of-Service (DDoS) attacks can threaten the availability of cloud functionalities. In recent years, many effort has been expended to detect the various DDoS attack types. In this survey paper, our concentration is on how to mitigate these attacks. We believe that cloud computing technology can substantially change the way we respond to a DDoS attack, based on a number of new characteristics, which were introduced with the advent of this technology. We first present a new taxonomy of DDoS mitigation strategies to organize the work. Then, we go on to discuss the main features of existing DDoS mitigation strategies and explain their functionalities in the cloud environment. Afterwards, we show how the existing DDoS mechanisms fit into the network topology of the cloud. Finally, we discuss some of these DDoS mechanisms in detail, and compare their behavior in the cloud. Our objective is to show how these characteristics bring a novel perspective to existing DDoS mechanisms, and so give researchers new insights into how to mitigate DDoS attacks in the cloud computing. Alireza Shameli-Sendi, Makan Pourzandi, Mohamed Fekih Ahmed, Mohamed Cheriet |
J. Netw. Comput. Appl. | 2 |
| 2014 | A Software-Defined Scalable and Autonomous Architecture for Multi-tenancyabstractScalability for distributed Data Center Networks (DCNs) has long been a goal of the network research and industrial community. To support dynamically increasing demands from multi-tenants, the network providers have to duplicate or share virtual resources for satisfying tenants' requests. However, current Software-Defined Networking (SDN) architectures have major drawbacks including lack of scalability and cross Virtual Tenant Network (VTN) communication. They rely only on the flexibility of control plane and neglect management plane important role. SDN scalability bottleneck affects directly the network/VTN scalability. In front of the fast growing network, it is widely accepted that the network of the future will require more capabilities such as self-awareness, self-control and self-management. At the core of these challenges is providing elastic isolation for multi-tenancy and involving tenant in management and control to reach the scalability objective and reduce the complexity of management operations of large DCNs. To address these challenges, the Open virtual Network Management and Security (Open vNMS) is proposed for supporting transparent multi-tenancy while both network and VTN scalability is solved. Basing on elastic L2 isolation using SDN components' flexibility, we design an autonomic architecture to provide self-control, self-management and self-adaptive capabilities for the network. The experiment results showed that the proposed design offers negligible overhead and guarantees the network performance. Mohamed Fekih Ahmed, Chamseddine Talhi, Makan Pourzandi, Mohamed Cheriet |
IC2E | 3 |
| 2014 | Preservation of Security Configurations in the CloudabstractThe dynamic and elastic nature of cloud computing introduces new security challenges when it comes to maintaining consistent security configurations. This is emphasized by the fact that virtual machines are abruptly migrated between physical hosts, in the same or even in different data centers under different security policies. If security is not correctly enforced at the destination locations, and not properly updated in the source locations, security of the migrating virtual machine as well as the co-located machines can be compromised. In this paper, we intend to tackle this problem, specifically for intrusion detection/prevention and VPN/IPsec as main security mechanisms. More precisely, we propose a systematic verification approach to check the compliance of security configurations. To this end, we first elaborate on two properties, namely intrusion monitoring configuration preservation and VPN/IPsec protection configuration preservation. Then, we derive a set of formulas that compare security configurations before and after migration. This allows reasoning on whether the aforementioned security properties hold. To this end, we encode these formulas as constraint satisfaction problems. The obtained constraints are then submitted to a constraint solver, namely Sugar, in order to verify the properties and to pinpoint potential misconfiguration problems. Arash Eghtesadi, Yosr Jarraya, Mourad Debbabi, Makan Pourzandi |
IC2E | 4 |
| 2013 | A secure, efficient, and cost-effective distributed architecture for spam mitigation on LTE 4G mobile networksabstractABSTRACT The 4G of mobile networks will be a technology‐opportunistic and user‐centric system, combining the economical and technological advantages of various transmission technologies. As a part of its new architecture, LTE networks will implement an evolved packet core. Although this will provide various critical advantages, it will, on the other hand, expose telecom networks to serious IP‐based attacks. One often adopted solution to mitigate such attacks is based on a centralized security architecture. However, this approach requires large processing and memory resources to handle huge amounts of traffic, which, in turn, causes a significant over dimensioning problem in the centralized nodes. Hence, it may cause this approach to fail from achieving its security task. In this paper, we focus on a SPAM flooding attack, namely SMTP SPAM, and demonstrate, through simulations and discussion, its DoS impact on the Long Term Evolution (LTE) network and subsequent effects on the mobile network operator. Our main contribution involves proposing a distributed architecture on the LTE network that is secure and that mitigates attacks efficiently by solving the over dimensioning problem. It is also cost‐effective by utilizing ‘off‐the‐shelf’ low‐cost hardware in the distributed nodes. Through additional simulation and analysis, we demonstrate the feasibility and effectiveness of our approach. Copyright © 2012 John Wiley & Sons, Ltd. Elias Bou-Harb, Makan Pourzandi, Mourad Debbabi, Chadi Assi |
Secur. Commun. Networks | 2 |
| 2012 | Studying Impacts of Prefix Interception Attack by Exploring BGP AS-PATH PrependingabstractThe AS path prep ending approach in BGP is commonly used to perform inter-domain traffic engineering, such as inbound traffic load-balancing for multi-homed ASes. It artificially increases the length of the AS level path in BGP announcements by inserting its local AS number multiple times into outgoing announcements. In this work, we study how the AS path prep ending mechanism can be exploited to launch a BGP prefix interception attack. Our work is motivated by a recent routing anomaly related to AS Path prepending behavior, i.e., Facebook's traffic being redirected to Korea and China due to a shorter path with fewer prep ending ASNs. In order to measure the possible impact of the attack, we develop a simulator to quantify the damage of the attack under a diverse set of attacker/victim combinations. Our main contribution is to quantify how many ASes may be susceptible to the attack, and analyze how effective the attack may be through simulation. Furthermore, we propose an algorithm to detect the interception attack by exploiting inconsistencies via collaborative monitoring from multiple vantage points. Our evaluation shows up to 99% accuracy with 150 vantage points. Ying Zhang 0022, Makan Pourzandi |
ICDCS | 2 |
| 2012 | Formal Verification of Security Preservation for Migrating Virtual Machines in the Cloud
Yosr Jarraya, Arash Eghtesadi, Mourad Debbabi, Ying Zhang 0022, Makan Pourzandi |
SSS | 5 |
| 2011 | A Taxonomy Model for Cloud Computing Services
Nelson Mimura Gonzalez, Charles Miers, Fernando F. Redígolo, Marcos A. Simplício Jr., Tereza Cristina M. B. Carvalho, Mats Näslund, Makan Pourzandi |
CLOSER | 7 |
| 2011 | A Quantitative Analysis of Current Security Concerns and Solutions for Cloud ComputingabstractThe development of cloud computing services is speeding up the rate in which the organizations outsource their computational services or sell their idle computational resources. Even though migrating to the cloud remains a tempting trend from a financial perspective, there are several other aspects that must be taken into account by companies before they decide to do so. One of the most important aspect refers to security: while some cloud computing security issues are inherited from the solutions adopted to create such services, many new security questions that are particular to these solutions also arise, including those related to how the services are organized and which kind of service/data can be placed in the cloud. Aiming to give a better understanding of this complex scenario, in this article we identify and classify the main security concerns and solutions in cloud computing, and propose a taxonomy of security in cloud computing, giving an overview of the current status of security in this emerging technology. Nelson Mimura Gonzalez, Charles Miers, Fernando F. Redígolo, Tereza Cristina M. B. Carvalho, Marcos A. Simplício Jr., Mats Näslund, Makan Pourzandi |
CloudCom | 7 |
| 2009 | PHDabstractAs TV consumers expect a growing quantity and quality of services provided to them, and providers fear uncontrolled distribution of the digital content, one of the more promising theoretical proposals to balance these two needs are the so-called "Authorized Domains" (AD). We present in this paper a novel architecture that builds on the AD concept, but extends it to allow for a more generic, open, and flexible solution. The contributions of our work are twofold: First, we analyze and motivate which features a generic and flexible IPTV architecture should exhibit in order to enable various business models, while maintaining in all instances the above-mentioned core features. Second, we present our architecture – “Personal Home Domains” (PHD) –, which adds some key features to the original AD: it allows offline content in addition to streaming; it harmonizes the distribution inside the domain with (new) the delivery from service provider to the domain; it allows for the distribution of free or age-protected content; it emphasizes the mobility of users more than the original concept; and it allows for non-compliant devices inside the domain devices as well. Marcos A. Simplício Jr., Vlad C. Coroama, Yeda Regina Venturini, Tereza Cristina M. B. Carvalho, Mats Näslund, Makan Pourzandi |
AINA | 6 |
| 2009 | An Aspect-Oriented Approach for Software Security Hardening: from Design to ImplementationabstractSecurity is a very challenging task in software engineering. Enforcing security policies should be taken care of during the early phases of the software development life cycle to prevent security breaches in the final product. Since security is a crosscutting concern that pervades the entire software, integrating security solutions at the software design level may result in scattering and tangling security features throughout the entire design. To address this issue, we propose in this paper an aspect-oriented approach for specifying and enforcing security hardening solutions. This approach provides software designers with UML-based capabilities to perform security hardening in a clear and organized way, at the UML design level, without the need to be security experts. We also present the SHP profile, a UML-based security hardening language to describe and specify security hardening solutions at the UML design level. Finally, we explore the efficiency and the relevance of our approach by applying it to a real world case study and present the experimental results. Djedjiga Mouheb, Chamseddine Talhi, Azzam Mourad, Vitor Lima, Mourad Debbabi, Lingyu Wang 0001, Makan Pourzandi |
SoMeT | 7 |
| 2008 | Reputation based trust management using TCG in Mobile Ad-Hoc Networks (RTA)abstractThe Mobile Ad-Hoc Networks (MANET) are more and more important due to their increasing use. At the same time, the Trusted Computing Group (TCG) approach in using TPM based hardware root of trust is increasingly used in mobile devices providing a trustable source of knowledge about software composition of devices. In this paper, we develop a new approach to evaluate trust among peers in an Ad Hoc network, based on the reputation of their software composition. Segla Kpodjedo, Samuel Pierre, Makan Pourzandi |
LCN | 3 |
| 2006 | Work in Progress: RASS Framework for a Cluster-Aware SELinux
Arpan Darivemula, Chokchai Leangsuksun, Anand Tikotekar, Makan Pourzandi |
CCGRID | 4 |
| 2006 | Multiple personal security domainsabstractMobility, usability and security are major requirements for any Ad Hoc network systems, and there have been numerous papers in regards to them. However, often these requirements are addressed separately. For a valid solution, these requirements must be considered from an integrated view. In this paper, taking into account mobility and usability, we implement a framework which allows to securely share resources and services between devices in Ad-hoc networks, based on security policies defined by the owners of those devices. In addition, we extend our framework to support inter-domain sharing of services and resources. We detail our design, present the preliminary results of our prototype, and discuss the lessons learned, in particular how user experience led to several re-designs of the initial security solution. Reinaldo Matushima, Yeda Regina Venturini, Rony R. M. Sakuragui, Tereza Cristina M. B. Carvalho, Wilson Vicente Ruggiero, Mats Näslund, Makan Pourzandi |
IWCMC | 7 |
| 2005 | Feasibility study and early experimental results towards cluster survivabilityabstractThis paper propounds an investigation, a feasibility study, and performance benchmarking of vital management elements for critical enterprise and HPC infrastructure. We propose concepts of integrating high availability cluster mechanism with a secure cluster infrastructure. Our proposed architecture incorporates the distributed security infrastructure (DSI) framework, an open source project providing secure infrastructure for carrier grade clusters, and HA-OSCAR, an open source cluster framework that meets the reliability, availability, serviceability (RAS) needs. The result is a cluster infrastructure that is compliant with the reliability, availability, serviceability and security (RASS) principles. We conducted an initial feasibility study and experiment to gauge issues and the degree of success in the implementation of our proposed RASS framework. We verified the integration of HA-OSCAR release 1.0 and DSI release 0.3. Although there was a minimal performance overhead, having "RASS" in mission critical settings by far outweighs the performance impact. We plan to further our proof-of-concept architecture to suit the required needs on the production environments. Chokchai Leangsuksun, Anand Tikotekar, Makan Pourzandi, Ibrahim Haddad |
CCGRID | 3 |
| 2005 | Clusters and security: distributed security for distributed systemsabstractLarge-scale commodity clusters are used in an increasing number of domains: academic, research, and industrial environments. At the same time, these clusters are exposed to an increasing number of attacks coming from public networks. Therefore, mechanisms for efficiently and flexibly managing security have now become an essential requirement for clusters. However, despite the growing importance of cluster security, this field has been only minimally addressed by contemporary cluster administration techniques. This paper presents a high-level view of existing security challenges related to clusters and proposes a structured approach for handling security in clustered servers. The goal of this paper is to identify various necessarily-distributed security services and their related characteristics as a means of enhancing cluster security. Makan Pourzandi, David Gordon, William Yurcik, Gregory A. Koenig |
CCGRID | 1 |
| 2004 | DigSig: Runtime Authentication of Binaries at Kernel Level
Axelle Apvrille, David Gordon, Serge E. Hallyn, Makan Pourzandi, Vincent Roy |
LISA | 4 |
| 2004 | XML distributed security policy for clusters
Axelle Apvrille, Makan Pourzandi |
Comput. Secur. | 2 |
| 2002 | A New Architecture for Secure Carrier-Class ClustersabstractTraditionally the telecom industry has used clusters to meet its carrier-class requirements of high availability, reliability, and scalability, while relying on cost-effective hardware and software. Efficient cluster security is now an essential requirement and has not yet been addressed in a coherent fashion on clustered systems. This paper presents an approach for distributed security architecture that supports advanced security mechanisms for current and future security needs, targeted for carrier-class application servers running on clustered systems. Makan Pourzandi, Ibrahim Haddad, Charles Levert, Miroslaw Zakrzewski, Michel R. Dagenais |
CLUSTER | 1 |