VLDB 2026 Research / reviewers in the wild / expert
Frederica Free-Nelson
dblp:221/5255 · also Frederica F. Nelson, Frederica Nelson
· DBLP profile ↗
17ranked-venue papers
0as first author
12since 2021 · last 2026
0000-0001-8641-384XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 3 since 2021Security and privacy · 7 · 6 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MTD in depth: Multi-phased moving target defense techniques against cyber-attacks based on cyber kill chain
Minjune Kim, Jin-Hee Cho, Hyuk Lim, Tina Moghaddam, Terrence J. Moore, Frederica Free-Nelson, Dong Seong Kim 0001 |
Future Gener. Comput. Syst. | 6 |
| 2025 | Graphical security modelling for Autonomous Vehicles: A novel approach to threat analysis and defence evaluationabstractAutonomous Vehicles (AVs) integrate numerous control units , network components, and protocols to operate effectively and interact with their surroundings, such as pedestrians and other vehicles. While these technologies enhance vehicle capabilities and enrich the driving experience, they also introduce new attack surfaces, making AVs vulnerable to cyber-attacks. Such cyber-attacks can lead to severe consequences, including traffic disruption and even threats to human life. Security modelling is crucial to safeguarding AVs as it enables the simulation and analysis of an AV’s security before any potential attacks. However, the existing research on AV security modelling methods for analysing security risks and evaluating the effectiveness of security measures remains limited. In this work, we introduce a novel graphical security model and metrics to assess the security of AV systems. The proposed model utilizes initial network information to build attack graphs and attack trees at different layers of network depth. From this, various metrics are automatically calculated to analyse the security and safety of the AV network. The proposed model is designed to identify potential attack paths, analyse security and safety with precise metrics, and evaluate various defence strategies. We demonstrate the effectiveness of our framework by applying it to two AV networks and distinct AV attack scenarios, showcasing its capability to enhance the security of AVs. Nhung H. Nguyen, Mengmeng Ge 0001, Jin-Hee Cho, Terrence J. Moore, Seunghyun Yoon 0001, Hyuk Lim, Frederica Free-Nelson, Guangdong Bai, Dong Seong Kim 0001 |
Comput. Secur. | 7 |
| 2024 | TriAssetRank: Ranking Vulnerabilities, Exploits, and Privileges for Countermeasures PrioritizationabstractNetwork defence practices have no standardized mechanism for determining the priority of threat events. Prioritization of cyber vulnerabilities intends to make network administrators focus on the most critical points within the system to mitigate potential damages produced by attackers. More likely, in managing vulnerabilities, current approaches always focus on the common vulnerability exposures (CVE), which are not the only existing vulnerabilities in a network. Also, while the Common Vulnerability Scoring System (CVSS) effectively scores individual vulnerabilities, it fails to consider the relationships between them but considers each vulnerability in isolation. Existing research, such as the ‘AssetRank’ algorithm, has made progress in exploring these relationships. Building on this foundation, in this paper we propose TriAssetRank, a tripartite ranking algorithm that evaluates three key elements within a logical attack graph: vulnerabilities, privileges, and potential attack exploits. Since each node type has its unique characteristics and potential impact on the system’s security, we rank them in concert, taking into account the dependencies between nodes in the attack graph. The proposed ranking scheme computes a numerical value for each node based on its type, which is a clear indication of how valuable it is to a potential attacker. Several tests on various model networks have empirically validated the effectiveness of the algorithm, which enables organizations to prioritize countermeasures by identifying the most critical vulnerabilities, exploits, and privilege escalation risks, allowing efficient allocation of resources to mitigate high-impact threats and reduce overall risk exposure effectively. Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Wilson Ejuh Geh, Frederica Free-Nelson, Sachin Shetty, Charles A. Kamhoua |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | EVADE: Efficient Moving Target Defense for Autonomous Network Topology Shuffling Using Deep Reinforcement Learning
Qisheng Zhang, Jin-Hee Cho, Terrence J. Moore, Dong Seong Kim 0001, Hyuk Lim, Frederica Free-Nelson |
ACNS (1) | 6 |
| 2023 | Cyber Resilience Measurement Through Logical Attack Graph AnalysisabstractTo improve resilience, it is crucial to quantify or measure it. Measurement techniques usually base their measure on critical functionality, which is unfortunately not mission-centric. Also, methods of measurement over time can not tackle the fact that a system may have different consecutive missions at different intervals of time. We propose a method to measure the cyber-resilience of any complex network by analyzing how the business process varies against adversity effort. Both efforts of the attacker and the impact on the business process are obtained by leveraging the vulnerabilities CVSS score of attack paths extracted from a generated attack graph. We finally obtain a numerical value for cyber resilience by calculating the area under the curve of business process against attacker effort. Experimentation shows that the proposed framework suits the absorption, recovery, and adaptation abilities of cyber resilience. This also helps designers to analyze which type of vulnerabilities leads to the worst resilience case, thereby making critical decisions to improve cyber resilience. Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Frederica Free-Nelson, Sachin Shetty, Wilson Ejuh Geh, Charles A. Kamhoua |
ICC | 3 |
| 2023 | Mitigating Energy Depletion Attack In Wireless Sensor Network Using Signaling GameabstractNowadays, with the evolution of technology, sensor networks have experienced a real boom. Due to their constitutions, sensors suffer from low security and are therefore susceptible to different types of attacks. Wireless sensor networks (WSNs) deployed in hostile environments suffer particularly from energetic attacks, i.e. attacks aimed at shortening the life cycle of sensors. Sensors have limited energy resources; replacing or recharging nodes in hostile environments is difficult. Attacks that cause a drain on the energy level are the most common attacks in a hostile environment and can lead to the death of sensors such as sleep denial attacks. In this paper, we design a game model using a signaling game within clusters that enables both detection and defense against attackers. In this paper, we identify and impose penalties on nodes that practice sleep deprivation torture in WSNs. The simulations showed that the model is able to force the attacker to behave normally in a WSN. Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Frederica Free-Nelson, Charles A. Kamhoua |
ICC | 5 |
| 2022 | Continual Learning with Network Intrusion DatasetabstractDeep learning-based cybersecurity applications should be able to continually accumulate threat knowledge for new types of threats over time while maintaining the knowledge of threats already exposed to the application. This paper proposes episodic memory management for continual learning with network intrusion datasets. For new attacks, the number of samples may not be sufficiently large for training, and thus the memory management algorithm should retain as many samples as possible instead of random sampling in the episodic memory for continual learning. The experiment results indicated that the proposed algorithm outperforms offline learning in terms of average per-class accuracy in a continual scenario with a network intrusion dataset. Dong Seong Kim 0001, Jin-Hee Cho, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim |
IEEE Big Data | 5 |
| 2022 | Performance and Security Evaluation of a Moving Target Defense Based on a Software-Defined Networking EnvironmentabstractAs cyberattacks continuously threaten conventional defense techniques, Moving Target Defense (MTD) has emerged as a promising countermeasure to defend a system against them by dynamically changing attack surfaces of the system. MTD provides the system a state-of-art security mechanism that increases the attack cost or complexity of the system aiming for reducing vulnerabilities exposed to potential attackers. However, the notion of the proactive and dynamic systems adopting MTD services causes a substantial trade-off between system performance and security effectiveness, compared to conventional defense strategies. The MTD tactics accordingly result in performance degradation (e.g., interruptions of service availability) as one of the drawbacks caused by continuous mutations of the system configuration. Therefore, it is crucial to validate not only the security benefits against system threats but also quality-of-service (QoS) for clients when an MTD-enabled system proactively continues to mutate attack surfaces. This paper contributes to (i) developing new security metrics; (ii) measuring both the performance degradation and security effectiveness against potential real attacks (i.e., scanning, HTTP flood, dictionary, and SQL injection attack); and (iii) comparing the proposed job management strategies (i.e., drop and switch-over) from a performance and security perspective in a physical SDN testbed. Minjune Kim, Jin-Hee Cho, Hyuk Lim, Terrence J. Moore, Frederica Free-Nelson, Dong Seong Kim 0001 |
PRDC | 5 |
| 2022 | Evaluating Performance and Security of a Hybrid Moving Target Defense in SDN EnvironmentsabstractAs cyberattacks are rising, Moving Target Defense (MTD) can be a countermeasure to proactively protect a networked system against cyber-attacks. Despite the fact that MTD systems demonstrate security effectiveness against the reconnaissance of Cyber Kill Chain (CKC), a time-based MTD has a limitation when it comes to protecting a system against the next phases of CKC. In this work, we propose a novel hybrid MTD technique, its implementation and evaluation. Our hybrid MTD system is designed on a real SDN testbed and it uses an intrusion detection system (IDS) to provide an additional MTD triggering condition. This in itself presents an extra layer of system protection. Our hybrid MTD technique can enhance security in the response to multi-phased cyber-attacks. The use of the reactive MTD triggering from intrusion detection alert shows that it is effective to thwart the further phase of detected cyber-attacks. We also investigate the performance degradation due to more frequent MTD triggers.This work contributes to (1) proposing an ML-based rule classification model for predicting identified attacks which helps a decision-making process for security enhancement; (2) developing a hybrid-based MTD integrated with a Network Intrusion Detection System (NIDS) with the consideration of performance and security; and (3) assessment of the performance degradation and security effectiveness against potential real attacks (i.e., scanning, dictionary, and SQL injection attack) in a physical testbed. Minjune Kim, Jin-Hee Cho, Hyuk Lim, Terrence J. Moore, Frederica Free-Nelson, Ryan Kok Leong Ko, Dong Seong Kim 0001 |
QRS | 5 |
| 2022 | DIVERGENCE: Deep Reinforcement Learning-Based Adaptive Traffic Inspection and Moving Target Defense Countermeasure FrameworkabstractReinforcement learning (RL) is a promising approach for intelligent agents to protect a given system under highly hostile environments. RL allows the agent to adaptively make sequential defense decisions based on the perceived current state of system security aiming to achieve the maximum defense performance in terms of fast, efficient, and automated detection, threat analysis, and response to the threat. In this paper, we propose a deep reinforcement learning (DRL)-based adaptive traffic inspection and moving target defense countermeasure framework, called ‘DIVERGENCE,’ for building a secure networked system. The DIVERGENCE provides two main security services: (1) a DRL-based network traffic inspection mechanism to achieve scalable and intensive network traffic visibility for rapid threat detection; and (2) an address shuffling-based moving target defense (MTD) technique to defend against threats as a proactive intrusion prevention mechanism. Through extensive simulations and experiments, we demonstrate that the DIVERGENCE successfully caught malicious traffic flows while significantly reducing the vulnerability of the network through MTD. Sunghwan Kim 0004, Seunghyun Yoon 0001, Jin-Hee Cho, Dong Seong Kim 0001, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2021 | Repeatable Experimentation for Cybersecurity Moving Target Defense
Jaime C. Acosta, Luisana Clarke, Stephanie Medina, Monika Akbar, Mahmud Shahriar Hossain, Frederica Free-Nelson |
SecureComm (1) | 6 |
| 2021 | Supervised Authorship Segmentation of Open Source Code ProjectsabstractAbstract Source code authorship attribution can be used for many types of intelligence on binaries and executables, including forensics, but introduces a threat to the privacy of anonymous programmers. Previous work has shown how to attribute individually authored code files and code segments. In this work, we examine authorship segmentation, in which we determine authorship of arbitrary parts of a program. While previous work has performed segmentation at the textual level, we attempt to attribute subtrees of the abstract syntax tree (AST). We focus on two primary problems: identifying the primary author of an arbitrary AST subtree and identifying on which edges of the AST primary authorship changes. We demonstrate that the former is a difficult problem but the later is much easier. We also demonstrate methods by which we can leverage the easier problem to improve accuracy for the harder problem. We show that while identifying the author of subtrees is difficult overall, this is primarily due to the abundance of small subtrees: in the validation set we can attribute subtrees of at least 25 nodes with accuracy over 80% and at least 33 nodes with accuracy over 90%, while in the test set we can attribute subtrees of at least 33 nodes with accuracy of 70%. While our baseline accuracy for single AST nodes is 20.21% for the validation set and 35.66% for the test set, we present techniques by which we can increase this accuracy to 42.01% and 49.21% respectively. We further present observations about collaborative code found on GitHub that may drive further research. Edwin Dauber, Robert F. Erbacher, Gregory Shearer, Michael J. Weisman, Frederica Free-Nelson, Rachel Greenstadt |
Proc. Priv. Enhancing Technol. | 5 |
| 2020 | Dynamic Security Metrics for Software-Defined Network-based Moving Target Defense
Dilli P. Sharma, Simon Yusuf Enoch, Jin-Hee Cho, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim, Dong Seong Kim 0001 |
J. Netw. Comput. Appl. | 5 |
| 2020 | Attack Graph-Based Moving Target Defense in Software-Defined NetworksabstractMoving target defense (MTD) has emerged as a proactive defense mechanism aiming to thwart a potential attacker. The key underlying idea of MTD is to increase uncertainty and confusion for attackers by changing the attack surface (i.e., system or network configurations) that can invalidate the intelligence collected by the attackers and interrupt attack execution; ultimately leading to attack failure. Recently, the significant advance of software-defined networking (SDN) technology has enabled several complex system operations to be highly flexible and robust; particularly in terms of programmability and controllability with the help of SDN controllers. Accordingly, many security operations have utilized this capability to be optimally deployed in a complex network using the SDN functionalities. In this paper, by leveraging the advanced SDN technology, we developed an attack graph-based MTD technique that shuffles a host’s network configurations (e.g., MAC/IP/port addresses) based on its criticality, which is highly exploitable by attackers when the host is on the attack path(s). To this end, we developed a hierarchical attack graph model that provides a network’s vulnerability and network topology, which can be utilized for the MTD shuffling decisions in selecting highly exploitable hosts in a given network, and determining the frequency of shuffling the hosts’ network configurations. The MTD shuffling with a high priority on more exploitable, critical hosts contributes to providing adaptive, proactive, and affordable defense services aiming to minimize attack success probability with minimum MTD cost. We validated the out performance of the proposed MTD in attack success probability and MTD cost via both simulation and real SDN testbed experiments. Seunghyun Yoon 0001, Jin-Hee Cho, Dong Seong Kim 0001, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2019 | Random Host and Service Multiplexing for Moving Target Defense in Software-Defined NetworksabstractMoving target defense (MTD) is a proactive defense mechanism of changing the attack surface to increase an attacker's confusion and/or uncertainty, which invalidates its intelligence gained through reconnaissance and/or network scanning attacks. In this work, we propose software-defined networking (SDN)-based MTD technique using the shuffling of IP addresses and port numbers aiming to obfuscate both network and transport layers' real identities of the host and the service for defending against the network reconnaissance and scanning attacks. We call our proposed MTD technique Random Host and Service Multiplexing, namely RHSM. RHSM allows each host to use random, multiple virtual IP addresses to be dynamically and periodically shuffled. In addition, it uses short-lived, multiple virtual port numbers for an active service running on the host. Our proposed RHSM is novel in that we employ multiplexing (or de-multiplexing) to dynamically change and remap from all the virtual IPs of the host to the real IP or the virtual ports of the services to the real port, respectively. Via extensive simulation experiments, we prove how effectively and efficiently RHSM outperforms a baseline counterpart (i.e., a static network without RHSM) in terms of the attack success probability and defense cost. Dilli P. Sharma, Jin-Hee Cho, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim, Dong Seong Kim 0001 |
ICC | 4 |
| 2019 | Poster: Address Shuffling based Moving Target Defense for In-Vehicle Software-Defined NetworksabstractAs connected and autonomous vehicle technology evolves, the design of in-vehicle network architecture, which connects multiple electronic control units (ECUs) and internal sensors and supports connectivity to the outside of the vehicle, has increased significantly to meet security needs. However, the heterogeneous structure of the in-vehicle network and lack of security consideration has introduced a lack of scalability and security concerns. In this work, we propose a shuffling-based moving target defense (MTD) technique aiming to disturb network reconnaissance attacks and deployed it in the proposed software-defined networking (SDN)-based in-vehicle network architecture. To validate the proposed MTD, we compare the service availability of our proposed MTD and non-MTD counterpart in the presence of the reconnaissance-based false message injection attacks. Seunghyun Yoon 0001, Jin-Hee Cho, Dong Seong Kim 0001, Terrence J. Moore, Frederica Free-Nelson, Hyuk Lim |
MobiCom | 5 |
| 2019 | Git Blame Who?: Stylistic Authorship Attribution of Small, Incomplete Source Code FragmentsabstractAbstract Program authorship attribution has implications for the privacy of programmers who wish to contribute code anonymously. While previous work has shown that individually authored complete files can be attributed, these efforts have focused on such ideal data sets as contest submissions and student assignments. We explore the problem of authorship attribution “in the wild,” examining source code obtained from open-source version control systems, and investigate how contributions can be attributed to their authors, either on an individual or a per-account basis. In this work, we present a study of attribution of code collected from collaborative environments and identify factors which make attribution of code fragments more or less successful. For individual contributions, we show that previous methods (adapted to be applied to short code fragments) yield an accuracy of approximately 50% or 60%, depending on whether we average by sample or by author, at identifying the correct author out of a set of 104 programmers. By ensembling the classification probabilities of a sufficiently large set of samples belonging to the same author we achieve much higher accuracy for assigning the set of samples to the correct author from a known suspect set. Additionally, we propose the use of calibration curves to identify which samples are by unknown and previously unencountered authors. Edwin Dauber, Aylin Caliskan, Richard E. Harang, Gregory Shearer, Michael J. Weisman, Frederica Free-Nelson, Rachel Greenstadt |
Proc. Priv. Enhancing Technol. | 6 |