VLDB 2026 Research / reviewers in the wild / expert
Sudip Maitra
dblp:241/2446
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0002-9866-1573ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Securing Access Control in 5G and Beyond with Zero TrustabstractThe Fifth Generation (5G) specifications have set a precedent for the evolution of next-generation mobile networks. Standardized interfaces and Network Function Virtualization (NFV) technology enable network operators to break free from vendor lock-in, while delivering more customized and agile services to their customers. However, the heterogeneous and multi-vendor composition of the Next-Generation Network (NGN), as envisioned in 5G specifications, also expands the existing attack surface and complicates trust relationships. Consequently, the traditional perimeter-based security model has become inadequate for effectively ensuring trust in such a complex network environment. On the other hand, Zero Trust has emerged as a promising security model well-suited for protecting complex and large-scale networks. Unfortunately, the current access control mechanism in the 5G core network lacks key features, rendering it incompatible with Zero Trust principles. To bridge this gap, we introduce the Continual Access Monitoring (CAM) framework that enables operators to seamlessly incorporate key security metrics into the existing access control mechanism. Furthermore, CAM introduces continual access policy evaluation, a critical requirement of the Zero Trust paradigm. The CAM framework illustrates a practical strategy for integrating Zero Trust principles into the 5G service-based architecture and scales efficiently in large 5G deployments, supporting access policy monitoring for up to 6,000 network functions at an operational cost of USD 0.2 per hour on AWS. Sudip Maitra, Kenechukwu Nwodo, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001 |
CODASPY | 1 |
| 2026 | VulLens: Enhancing Software Vulnerability Detection against Evasion Attacks
Shihua Sun, Sudip Maitra, Angelos Stavrou, Haining Wang 0001 |
DSN | 3 |
| 2025 | 5G-STREAM: Service Mesh Tailored for Reliable, Efficient and Authorized Microservices in the CloudabstractExisting registration, discovery, and authorization mechanisms in the 5G core control plane present scalability and efficiency challenges. As cellular deployments scale to accommodate diverse user demands, the 5G core control plane suffers from increased inter-Virtual Network Function (VNF) communication latency, thus deteriorating the reliability of critical procedures. To address this problem, we propose 5G-STREAM (Service mesh Tailored for Reliable, Efficient, and Authorized Microservices) to optimize control plane traffic in distributed cloud environments by establishing a topology awareness of service chains across cloud hierarchies. Leveraging this awareness, 5G-STREAM dynamically configures communication pathways to reduce discovery and authorization signaling overhead, thus increasing the reliability of inter-VNF communication. We develop a prototype of 5G-STREAM and evaluate its performance. Our evaluation results show that 5G-STREAM significantly reduces the process completion time in core service chains by up to 2× inter VNF-Network Repository Function (NRF) latency per transaction, with more pronounced benefits in larger service chains. Furthermore, we show that the cost required to deploy 5G-STREAM is an additional 0.1 USD/hr on AWS for a VNF handling a sustained rate of 50,000 requests/minute. Tolga O. Atalay, Alireza Famili, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
DSN | 3 |
| 2025 | An OpenRAN Security Framework for Scalable Authentication, Authorization, and Discovery of xApps With Isolated Critical ServicesabstractThe OpenRAN initiative promotes an open Radio Access Network (RAN) and offers operators fine-grained control over the radio stack. To that end, O-RAN introduces new components to the 5G ecosystem, such as the near real-time RAN Intelligent Controller (near-RT RIC) and the accompanying extensible Applications (xApps). The introduction of these entities expands the 5G threat surface. Furthermore, with the movement from proprietary hardware to virtual environments enabled by Network Functions Virtualization (NFV), attack vectors that exploit the existing NFV attack surface pose additional threats. To deal with these threats, we propose the xApp repository function (XRF) framework for scalable authentication, authorization, and discovery of xApps. To harden the XRF microservices, we isolate them using Intel Software Guard Extensions (SGX). We benchmark the XRF modules individually and compare how different microservices behave in terms of computational overhead when deployed in virtual and hardware-based isolation sandboxes. Our evaluation shows that the XRF framework scales efficiently in a multi-threaded Kubernetes environment. The isolation of the XRF microservices introduces different amounts of processing overhead depending on the sandboxing strategy. Finally, a security analysis is conducted to show how the XRF framework addresses chosen key issues from the O-RAN and 5G standardization efforts. Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Towards Shielding 5G Control Plane FunctionsabstractNetwork Functions Virtualization (NFV) enables flexible and scalable 5G core deployment but it also introduces new attack vectors into the mobile network ecosystem, especially when network functions are deployed on public cloud infrastructure. To address this issue, Third Generation Partnership Project (3GPP) standardization body recommends isolating critical 5G core functionalities inside Hardware Mediated Execution Enclaves (HMEEs). However, the use of HMEEs can incur debilitating QoS degradation in control plane functions including Authentication and Key Agreement (AKA) protocol. In this paper, we design and implement network slices with HMEE-enforced isolation for sensitive AKA functions and characterize their performance. Our findings reveal that the use of HMEE leads to 1.2 to 1.5× increase in function execution time and 2.2 to 2.9× increase in response time for the isolated containers. While appearing very large, this overhead is a small fraction of the end-to-end session setup latency. To evaluate the feasibility of HMEE, we use a real commercial User Equipment (UE) to register with the 5G core network through the isolated AKA functions. Finally, we discuss the role of HMEEs in addressing the key issues introduced by NFV. Sudip Maitra, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001 |
DSN | 1 |
| 2023 | Securing 5G OpenRAN with a Scalable Authorization Framework for xAppsabstractThe ongoing transformation of mobile networks from proprietary physical network boxes to virtualized functions and deployment models has led to more scalable and flexible network architectures capable of adapting to specific use cases. As an enabler of this movement, the OpenRAN initiative promotes standardization allowing for a vendor-neutral radio access network with open APIs. Moreover, the O-RAN Alliance has begun specification efforts conforming to OpenRAN’s definitions. This includes the near-real-time RAN Intelligent Controller (RIC) overseeing a group of extensible applications (xApps). The use of these potentially untrusted third-party applications introduces a new attack surface to the mobile network plane with fundamental security and system design requirements that are yet to be addressed. To secure the 5G O-RAN xApp model, we introduce the xApp Repository Function (XRF) framework, which implements scalable authentication, authorization, and discovery for xApps. We first present the framework’s system design and implementation details, followed by operational benchmarks in a production-grade containerized environment. The evaluation results, centered on active processing and operation times, show that our proposed framework can scale efficiently in a multi-threaded Kubernetes microservice environment and support a large number of clients with minimal overhead. Tolga O. Atalay, Sudip Maitra, Dragoslav Stojadinovic, Angelos Stavrou, Haining Wang 0001 |
INFOCOM | 2 |