Leila Rashidi

dblp:243/0932 · DBLP profile ↗
← Back
7ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0002-8284-9002ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-authorSecurity and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2024 A Graph Learning-Based Approach for Lateral Movement Detection
abstract
Lateral movement, a crucial phase in the Advanced Persistent Threat (APT) life cycle, refers to a strategy employed by adversaries to traverse horizontally within a network. The aim is to gain access to various systems or resources, thereby expanding their control and potential access to valuable targets. Detecting these attacks becomes challenging for conventional detection systems due to various factors, including the complexity of pathways, the mimicking of legitimate user behavior by attackers, and limited network visibility. To address these challenges, advanced detection techniques are required to effectively and dynamically analyze multiple features within the interconnected structure of the network. This paper introduces an innovative approach to detect malicious lateral movement paths by leveraging authentication events and graph learning techniques. The proposed method involves constructing a heterogeneous graph, and employing DeepWalk for node embedding. By combining node embedding features with the temporal information of authentication events, feature vectors are generated for each authentication request. These features are then used to train multiple machine learning-based classifiers to detect malicious lateral movement paths. Furthermore, to assess the model’s performance in a more realistic scenario, a series of additional experiments were conducted. These experiments provided further validation of the model’s robustness and its capability for forward prediction.
Mahdi Rabbani, Leila Rashidi, Ali A. Ghorbani 0001
IEEE Trans. Netw. Serv. Manag.2
2023 Securing Supply Chain: A Comprehensive Blockchain-based Framework and Risk Assessment
abstract
Cyber attacks on data, networks, and software have become a crucial problem for supply chain management due to the globalization, decentralization, and digitalization. Blockchain provides an ideal platform for business stakeholders to address issues with modern supply chains, such as traceability, interoperability, and transparency. However, adopting blockchain is challenging as it introduces risks to the supply chain.In this paper, we propose a blockchain-based framework to manage the supply chain and enable a trust-based feedback mechanism, fostering trust among supply chain stakeholders. Moreover, we perform a qualitative risk assessment for adopting blockchain in the supply chain management process, based on standards provided by the National Institute of Standards and Technology (NIST). Our assessment shows that if a threat is imminent, the risk associated with the consensus, limited fixed verification capacity, and inter-autonomous system communication is high in a blockchain-based supply chain that uses proof of authority.
Leila Rashidi, Windhya Hansinie Rankothge, Hesamodin Mohammadian, Rashid Hussain Khokhar, Brian Frei, Shawn Ellis, Lago Freitas, Ali A. Ghorbani 0001
PST1
2023 On the Performance Analysis of Epidemic Routing in Non-Sparse Delay Tolerant Networks
abstract
We study the behavior of epidemic routing in a delay tolerant network as a function of node density. Focusing on the probability of successful delivery to a destination within a deadline (PS), we show that PS experiences a phase transition as node density increases. Specifically, we prove that PS exhibits a phase transition when nodes are placed according to a Poisson process and allowed to move according to independent and identical processes with limited speed. We then propose four fluid approximations to evaluate the performance of epidemic routing in non-sparse networks. An ordinary differential equation (ODE) is proposed for supercritical networks based on approximation of the infection rate as a function of time. Other ODEs are based on the approximation of thepairwise infection rate. Two of them, one for subcritical networks and another for supercritical networks, use the pairwise infection rate as a function of the number of infected nodes. The other ODE uses pairwise infection rate as a function of time, and can be applied for both subcritical and supercritical networks achieving good accuracy. The ODE for subcritical networks is accurate when density is not close to the percolation critical density. Moreover, the ODEs that target only supercritical regime are accurate.
Leila Rashidi, Don Towsley, Arman Mohseni-Kabir, Ali Movaghar-Rahimabadi
IEEE Trans. Mob. Comput.1
2021 More than a Fair Share: Network Data Remanence Attacks against Secret Sharing-based Schemes
Leila Rashidi, Daniel Kostecki, Alexander James, Anthony Peterson, Majid Ghaderi, Samuel Jero, Cristina Nita-Rotaru, Hamed Okhravi, Reihaneh Safavi-Naini
NDSS1
2019 Scalable Performance Analysis of Epidemic Routing Considering Skewed Location Visiting Preferences
abstract
This paper investigates the performance of epidemic routing, in mobile social networks (MSNs), which makes use of the store-carry-forward paradigm for communication. Real-life mobility traces show that people have skewed location visiting preferences, with some places visited frequently and some others infrequently. In order to model epidemic routing in MSNs, we first analyze the time taken for a node to meet the first node belonging to a set of nodes restricted to move in a specific subarea. Afterwards, a monolithic stochastic reward net (SRN) is proposed to evaluate the delivery delay and the average number of transmissions under epidemic routing by considering skewed location visiting preferences. This monolithic model is not scalable enough, in terms of the number of nodes and frequently visited locations. In order to achieve higher scalability, the folding technique is applied to the monolithic SRN and an approximate folded SRN is proposed to evaluate the performance of epidemic routing. Discrete-event simulation is applied to cross-validate the proposed models. Results indicate that the monolithic model has higher accuracy in predicting the performance of epidemic routing. The approximate folded model also achieves a good accuracy and can be solved for a network with a large number of nodes/frequently visited locations. This model is more accurate than the ordinary differential equation approach.
Leila Rashidi, Amir Dalili-Yazdi, Reza Entezari-Maleki, Leonel Sousa, Ali Movaghar-Rahimabadi
MASCOTS1
2019 Hierarchical Stochastic Models for Performance, Availability, and Power Consumption Analysis of IaaS Clouds
abstract
Infrastructure as a Service (IaaS) is one of the most significant and fastest growing fields in cloud computing. To efficiently use the resources of an IaaS cloud, several important factors such as performance, availability, and power consumption need to be considered and evaluated carefully. Evaluation of these metrics is essential for cost-benefit prediction and quantification of different strategies which can be applied to cloud management. In this paper, analytical models based on Stochastic Reward Nets (SRNs) are proposed to model and evaluate an IaaS cloud system at different levels. To achieve this, an SRN is initially presented to model a group of physical machines which are controlled by a management layer. Afterwards, the SRN models presented for the groups of physical machines in the first stage are combined to capture a monolithic model representing an entire IaaS cloud. Since the monolithic model does not scale well for large cloud systems, two approximate SRN models using folding and fixed-point iteration techniques are proposed to evaluate the performance, availability, and power consumption of the IaaS cloud. The existence of a solution for the fixed-point approximate model is proved using Brouwer's fixed-point theorem. A validation of the proposed monolithic and approximate models against both an ad-hoc discrete-event simulator developed in Java and the CloudSim framework is presented. The analytic-numeric results obtained from applying the proposed models to sample cloud systems show that the errors introduced by approximate models are insignificant while an improvement of several orders of magnitude in the state space reduction of the monolithic model is obtained.
Ehsan Ataie, Reza Entezari-Maleki, Leila Rashidi, Kishor S. Trivedi, Danilo Ardagna, Ali Movaghar-Rahimabadi
IEEE Trans. Cloud Comput.3
2019 Performance Evaluation of Epidemic Content Retrieval in DTNs With Restricted Mobility
abstract
In some applicable scenarios, such as community patrolling, mobile nodes are restricted to move only in their own communities. Exploiting the meetings of the nodes within the same community and the nodes within the neighboring communities, a delay tolerant network (DTN) can provide communication between any two nodes. In this paper, two analytical models based on stochastic reward nets (SRNs) are proposed to evaluate the performance of the epidemic content retrieval in such multi-community DTNs. Performance measures computed by the proposed models are the average retrieval delay and the average number of transmissions. The monolithic SRN model proposed in the first step is not scalable, in terms of the number of communities and nodes, due to the state space explosion in the underlying Markov chain. In order to solve the scalability problem of the monolithic model, an approximate model based on the folding technique is presented which allows us to evaluate the performance of large-scale DTNs. In order to cross-validate the results obtained from the proposed models, we extend the ONE simulator to support our network model. The analytic-numeric results indicate that both models have good accuracy, and the folded model reduces the state space highly, achieving good scalability without any significant loss of accuracy.
Leila Rashidi, Reza Entezari-Maleki, Dimitris Chatzopoulos, Pan Hui 0001, Kishor S. Trivedi, Ali Movaghar-Rahimabadi
IEEE Trans. Netw. Serv. Manag.1