VLDB 2026 Research / reviewers in the wild / expert
A. S. M. Asadujjaman
dblp:226/6033
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-6180-3227ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Surviving zero-day attacks using spatial specialization
A. S. M. Asadujjaman, Eduardo De Lucena Falcão, Andrey Brito, Elisa Rojas |
Comput. Secur. | 1 |
| 2024 | Securing Confidential VMs in Public CloudsabstractCloud providers and CPU vendors are working together to deliver the promise of Confidential Computing through the Confidential Virtual Machine (CVM) offerings. However, the steps required to verify the authenticity of CVMs are still unclear. Technical specifications are difficult to follow, and the implementations by the cloud providers are incomplete. Currently, there is no serviceable procedure to ensure desired security properties for CVM users. In this work, our goal is to secure confidential VMs by facilitating their authenticity verification and addressing security issues arising from their incomplete implementations. To that end, firstly, we identify a set of necessary attestation properties and formulate guidelines to verify them. Secondly, we show why the current offerings are insufficient to guarantee security and what else is needed. In that regard, as Intel has released its CVM technology recently, we focus our attention on the Intel TDX CVM offerings. After analyzing and evaluating Intel TDX services from major cloud providers, we have identified the possibility of a malware injection attack and designed a solution to detect it. Through experiments, we show that our solution does not add any significant overhead. A. S. M. Asadujjaman, Davi Pontes, Eduardo De Lucena Falcão, Andrey Brito |
CloudCom | 1 |
| 2023 | A Tenant-based Two-stage Approach to Auditing the Integrity of Virtual Network Function Chains Hosted on Third-Party CloudsabstractThere is a growing trend of hosting chains of Virtual Network Functions (VNFs) on third-party clouds for more cost-effective deployment. However, the multi-actor nature of such a deployment may allow a mismatch to silently arise between tenant-level specifications of VNF chains and their cloud provider-level deployment. Most existing auditing approaches would face difficulties in identifying such an integrity breach. First, relying on the cloud provider may not be sufficient, since modifications made by a stealthy attacker may seem legitimate to the provider. Second, the tenant cannot directly perform the auditing due to limited access to the provider-level data. In addition, shipping such data to the tenant would incur prohibitive overhead and confidentiality concerns. In this paper, we design a tenant-based, two-stage solution where the first stage leverages tenant-level side-channel information to identify suspected integrity breaches, and then the second stage automatically identifies and anonymizes selected provider-level data for the tenant to verify the suspected breaches from the first stage. The key advantages of our solution are: (i) the first stage gives tenants more control and transparency (with the capability of identifying integrity breaches without the provider's assistance), and (ii) the second stage provides tenants higher accuracy (with the capability of rigorous verification based on provider-level data). Our solution is integrated into OpenStack/Tacker (a popular choice for NFV deployment), and its effectiveness is demonstrated via experiments (e.g., up to 90% accuracy with the first stage alone). Momen Oqaily, Suryadipta Majumdar, Lingyu Wang 0001, Mohammad Ekramul Kabir, Yosr Jarraya, A. S. M. Asadujjaman, Makan Pourzandi, Mourad Debbabi |
CODASPY | 6 |
| 2022 | 5GFIVer: Functional Integrity Verification for 5G Cloud-Native Network Functionsabstract5G networks attain a better performance along with a reduction in cost by cloudifying its network functions as Cloud+native Network Functions (CNFs). However, CNF may introduce new security concerns (e.g., data exfiltration and ransomware) due to potential code injection attacks against network functions at runtime. This will potentially result in a breach of functional integrity of these network functions. Towards verifying such functional integrity breaches of CNFs at the 5G-operator-level, existing approaches fell short, as most of them either (i) perform pre-deployment verification (i.e., verifying the CNF image before the deployment) and hence fail to verify integrity breaches occurring after the deployment, or (ii) perform post-deployment verification (i.e., verifying against attack signatures or normal behavior patterns) approaches that require provider-level data (e.g., system calls) which is usually inaccessible to 5G operators. In this paper, we propose 5GFIVer, a new operator-oriented approach for functional integrity verification of CNFs that overcomes the above-mentioned limitations. First, our approach utilizes the side-channel information such as performance metrics (which are already available at the operator level) so that no provider-level data is needed. Second, our approach implements unsupervised machine learning algorithms to detect outliers through time-series analysis of those available performance metrics, and hence no instrumentation for the data collection as well as no training data is required. Third, we leverage the correlation between multiple CNFs to improve the accuracy and minimize false positives (e.g., caused by cloud dynamics). Our experimental results under an open source 5G testbed demonstrate the effectiveness and negligible overhead of our solution. A. S. M. Asadujjaman, Mohammad Ekramul Kabir, Hinddeep Purohit, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Makan Pourzandi |
CloudCom | 1 |