VLDB 2026 Research / reviewers in the wild / expert
Rajorshi Biswas
dblp:225/2860
· DBLP profile ↗
10ranked-venue papers
9as first author
6since 2021 · last 2025
0000-0002-3683-7051ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-author · 1 since 2021Systems, architecture and hardware · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Interpretable Multi-Modal Transformer-Based Intrusion Detection System Utilizing Log Messages and PCAP FilesabstractIntrusion detection systems (IDS) primarily rely on signature-based approaches, which can fail to detect novel or sophisticated attacks. This paper addresses the underutilized potential of leveraging a multi-modal approach that combines packet capture (PCAP) and log data for anomaly detection. To enhance detection capabilities, we propose an interpretable hybrid neural network architecture, TransIDS, that integrates a packet-based transformer with an efficient transformer-based language model for log messages. The proposed framework extracts semantic vectors from raw log messages and concatenates them with packet embeddings. An attention-based classification model then detects anomalies by determining the importance of each log message and packet for the neural network’s decision. By fusing spatial features from PCAP data with temporal features from log data, TransIDS utilizes this multi-modal data fusion to identify anomalies that might be missed by conventional systems. This approach not only leverages the strengths of two distinct transformer-based architectures but also provides a more comprehensive analysis of network traffic, leading to more effective detection of previously undetected attacks and strengthening overall network security. We use a real testbed for our experiments to validate the effectiveness of our proposed approach. Nadia Niknami, Vahid Mahzoon, Rajorshi Biswas, Slobadan Vucetic, Jie Wu 0001 |
MASS | 3 |
| 2025 | Optimal filter assignment policy against link flooding attackabstractA Link Flooding (LFA) attack is a special type of Denial-of-Service (DoS) attack in which the attacker sends out a huge number of requests to exhaust the capacity of a link on the path the traffic comes to a server. As a result, user traffic cannot reach the server. As a result, DoS and degradation of Quality-of-Service (QoS) occur. Because the attack traffic does not go to the victim, protecting the legitimate traffic alone is hard for the victim. The victim can protect its legitimate traffic by using a special type of router called filter router (FR). An FR can receive server filters and apply them to block a link incident to it. An FR probabilistically appends its own IP address to packets it forwards, and the victim uses that information to discover the traffic topology. By analyzing traffic rates and paths, the victim identifies some links that may be congested. The victim needs to select some of these possible congested links (PCLs) and send a filter to the corresponding FR so that legitimate traffic avoids congested paths. In this paper, we formulate two optimization problems for blocking the least number of PCLs so that the legitimate traffic goes through a non-congested path. We consider the scenario where every user has at least one non-congested shortest path in the first problem. We extend the first problem to a scenario where there are some users whose shortest paths are all congested. We transform the original problem to the vertex separation problem to find the links to block. We use a custom-built Java multi-threaded simulator and conduct extensive simulations to support our solutions. Rajorshi Biswas, Jie Wu 0001, Wei Chang 0001, Pouya Ostovari |
High Confid. Comput. | 1 |
| 2022 | Optimal Filter Assignment Policy Against Distributed Denial-of-Service AttackabstractA distributed denial-of-service (DDoS) attack is a cyber-attack in which attackers from different locations send out many requests to exhaust the capacity of a server. Current DDoS attack protection services filter out the DDoS attack packets in the middle of the path from the attacker to the servers. Some of the DDoS protection systems filter them out at the victim server. As a result, unnecessary attack traffic congests the network and wastes bandwidth. This can be minimized if we block them as early as possible. In this paper, we propose a DDoS attack protection system by using the filter router. The victim needs to wisely select and send filters to a subset of filter routers to minimize attack traffic and blockage of legitimate users (LUs). Many filters can easily minimize the attack traffic and blockage of LUs, but it is costly to the victim. So, we formulate two problems with different settings for selecting filter routers given a constraint on the number of filters. We propose dynamic programming solutions for both problems. Both problems consider the blockage of all attack traffic before it reaches the victim. We conduct extensive simulation to support our solutions. Rajorshi Biswas, Jie Wu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Protecting Resources Against Volumetric and Non-volumetric Network AttacksabstractCyber attacks are growing with the increase in internet usage. In a volumetric attack, the target resource is taken down with a huge amount of traffic. Distributed denial-of-service and link flooding attacks are examples of these types of attacks. In a non-volumetric attack, the attackers try to steal or get illegal authorization of some resources in a network. This type of attack can be severe even with a small amount of traffic. Non-volumetric attacks can be stopped by applying a moving target defense approach at the nodes on the attack path. An attack path is a series of steps and the attacker needs to succeed in all of those steps to gain access to the resources. In this paper, we propose an architecture to defend against both types of attacks. We formulate a problem to minimize the damage caused by the volumetric attack by using a limited number of blockage at some routers. This problem is NP-hard and we provide a greedy solution and provide an approximation ratio of it. We formulate another optimization problem to minimize the damage while securing the resources by deploying the minimum number of moving target defense methods. We provide a dynamic programming based solution to this problem. We conduct an extensive simulation to support our proposed models. Rajorshi Biswas, Jie Wu 0001 |
ICPADS | 1 |
| 2021 | Minimizing the Number of Rules to Mitigate Link Congestion in SDN-based DatacentersabstractLink congestion due to regular traffic and link flooding attacks (LFA) are two major problems in datacenters. Recent usage growth of software defined networking (SDN) in datacenters enables dynamic and convenient configuration management that makes it easy to reconfigure the network to mitigate the LFA. The reconfiguration that redirects some of the traffic can be done in two ways: the shortest alternative path and the minimum changes in rule path. The SDN switches have a limited capacity for the rules and the performance dramatically drops when the number of stored rules is higher. Besides, it takes some time to adopt the changes by the SDN switches which causes interruption in flow. In this paper, we aim at minimizing the number of rule changes while redirecting some of the traffic from the congested link. We formulate two problems to minimize the number of rule changes to redirect traffic. The first problem is the basic and it considers a congested link and a flow to direct. We provide a Dijkstra-based and a rule merging based solution to the problems. The second problem considers multiple flows and we propose flow grouping and rule merging based solutions. We conduct extensive simulations and experiments in our datacenter to support our model. Rajorshi Biswas, Jie Wu 0001 |
NAS | 1 |
| 2021 | Sampling Rate Distribution for Flow Monitoring and DDoS Detection in DatacenterabstractMonitoring all the internal flows in a datacenter is important to protect a victim against internal distributed denial-of-service (DDoS) attacks. Unused virtual machines (VMs) in a datacenter are used as monitors and flows are copied to the monitors from software defined networking (SDN) switches by adding some special rules. In such a system, a VM runs a machine learning method to detect DDoS behavior but it can only process a limited number/amount of flows. When the amount of flows is beyond the capacities of all monitor VMs, the system sub-samples each flow probabilistically. The sampling rate affects the DDoS detection rate of the monitors. Besides, the DDoS detection rates of different types of flows are different for the same sampling rate. A uniform sampling rate might not produce a good overall DDoS detection rate. Assigning different sampling rates to different flows may produce the best result. In this paper, we propose a flow grouping approach based on behavioral similarity among the VMs followed by hierarchical clustering of VMs. The sampling rate is uniform among all the flows in a group. We investigate the relationship between the sampling rate and the DDoS detection rate. Then, we formulate an optimization problem for finding an optimal sampling rate distribution and solve it using mix-integer linear programming. We conduct extensive experiments with Hadoop and Spark and present results that support the feasibility of our model. Rajorshi Biswas, Sungji Kim, Jie Wu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Optimal Filter Assignment Policy against Transit-Link Distributed Denial-of-Service AttackabstractA transit-link distributed denial-of-service (DDoS) attack is a special attack in which the attacker sends out a huge number of requests to exhaust the capacity of a link on the path the traffic comes to a server. As a result, denial-of-service and degradation of Quality-of-Service (QoS) occurs. Because the attack traffic does not go to the victim, protecting the legitimate traffic alone is hard for the victim. With the help of a special type of router called filter router (FR), the victim can protect the legitimate traffic. A FR can receive filter from servers and apply the filter to block a link incident to it. By analyzing traffic rates and paths, the victim can identify some links that may be congested. The victim needs to select some of these possible congested links and send a filter to the corresponding FR so that the legitimate traffic follows non-congested paths. In this paper, we formulate an optimization problem for selecting the minimum number of possible congested links so that the legitimate traffic goes through a non-congested path. We consider the scenario where every user has at least one non-congested shortest path. We transform the problem to the vertex separation problem to find the links to block. We build our own Java multi-threaded simulator and conduct extensive simulations. Rajorshi Biswas, Jie Wu 0001, Wei Chang 0001, Pouya Ostovari |
GLOBECOM | 1 |
| 2019 | Co-Existence of LTE-U and Wi-Fi with Direct CommunicationabstractOne of the most prominent cellular technologies, Long Term Evolution (LTE), is currently operating on some 800MHz, 2GHz, and 3.5GHz licensed bands. Wi-Fi is currently operating on 2.5GHz and 5GHz unlicensed bands. The declaration stating that 5GHz bands are unlicensed enables LTE to operate on 5GHz bands. It is challenging, however, for different wireless technologies to co-exist. The two standards, LTE-U and LTE-LAA, for LTE to coexist with Wi-Fi on the 5GHz band have evolved. The LTE-U standard is based on the duty cycle, while LTE-LAA is based on listen-before-talk (LBT). In existing LTE-U systems, the LTE base station (eNB) estimates the fair portion of Wi-Fi usage based on channel state information. The usage estimation from channel state information is not as accurate enough as well as the fair portion. In this paper, we study the fair coexistence between LTE-U and Wi-Fi in the scenario where an LTE eNB can exchange information with Wi-Fi access points (AP). The communication can be done in both wired and wireless mediums. The wired medium is ethernet point-to-point communication, and the wireless communication is done using the reserved bits in Wi-Fi packets. Both ways are applicable to the operator, who has both LTE and Wi-Fi coverage. Therefore, the Wi-Fi AP can collect information about other APs and send it to its LTE eNB. The LTE eNB can adjust its parameters according to the received information to achieve fairness. Rajorshi Biswas, Jie Wu 0001 |
ICC | 1 |
| 2019 | Mitigation of the Spectrum Sensing Data Falsifying Attack in Cognitive Radio NetworksabstractCognitive radio networks (CRNs), offering novel network architecture for utilizing spectrum, have attracted significant attention in recent years. In CRNs, secondary users (SUs) first determine the status of a channel; if it is free, they start transmitting. If the status determination is wrong, SUs may unnecessarily interfere with the licensed primary user (PU). In cooperative spectrum sensing, a SU makes a decision about the presence of the PU based on its own and other SUs' sensing results. Malicious SUs (MSUs) send false sensing results to SUs so that they make wrong decisions about the PU presence. As a result, a SU may transmit during the presence of the PU or may keep starving for the spectrum. In this paper, we propose a reputation-based mechanism for cooperative spectrum sensing which can minimize the effects of MSUs on decision making. Some of the SUs are selected as distributed fusion centers (DFCs), which are responsible for making decisions about the PU presence and inform the reporting SUs. A DFC uses weighted majority voting among the reporting SUs, where weights are determined based on reputation. The DFC updates reputations of SUs based on confidence of an election. If the majority wins by a significant margin, the confidence of the election is high. In this case, SUs that belong to the majority get high reputations. We provide extensive simulations to validate our proposed model. Rajorshi Biswas, Jie Wu 0001, Xiaojiang Du |
ICC | 1 |
| 2018 | Filter Assignment Policy Against Distributed Denial-of-Service AttackabstractA denial-of-service (DoS) attack is a cyber-attack in which the attacker sends out a huge number of requests to exhaust the capacity of a server, so that it can no longer serve incoming requests and DoS occurs. The most devastating distributed DoS attack is performed by malicious programs called bots. With the help of a special type of router called filter router, the victim can protect itself and reduce useless congestion in the network. A server can send out filters to filter routers for blocking attack traffic. The victim needs to select a subset of filter routers wisely to minimize attack traffic and blockage of legitimate users (LUs). In this paper, we formulate two problems for selecting filter routers given a constraint on the number of filters. The first problem considers the source-based filter and we provide greedy approximation solutions. The second problem considers the destination-based filter and how to minimize total amount of attack traffic and blocked LUs. We propose a dynamic programming solution for the second problem. We present simulation results comparing the proposed solutions with a naive approach. Our simulation results strengthen support for our solutions. Rajorshi Biswas, Jie Wu 0001 |
ICPADS | 1 |