Pasika Ranaweera

dblp:255/2990 · also Pasika Sashmal Ranaweera · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
11since 2021 · last 2025
0000-0002-4484-2002ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 2 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Collaborative Sensing, Communication and Computing for UAV-assisted Space-Air Networks
abstract
We propose a collaborative optimization framework for integrated sensing, communication, and computing (ISCC) in the unmanned aerial vehicle (UAV)-assisted space-air networks. This framework employs an UAV for data sensing and relay, providing wireless access to terrestrial sensing devices (TSDs), while a LEO satellite serves as an offloading edge computing server in space. Acknowledging the temporal criticality of tasks within the designated service area, we classify the service area with different priorities, with the UAV prioritizing service delivery to high-priority regions. Based on sensing satisfaction and service duration, we formulate a multi-objective problem with the goal of maximizing the total satisfaction while minimizing the service duration. We propose a PPO-based deep reinforcement learning (DRL) algorithm to find the optimal solutions. To address long-term dependencies in sequential data, we embed a long short-term memory (LSTM) module into the DRL algorithm. Compared to the baseline algorithms, the proposed algorithm achieves improvements in accumulated rewards of approximately 4.1%, 14.5%, and 21.2%, respectively.
Pasika Ranaweera, Madhusanka Liyanage, Zheng Chang 0001
GLOBECOM2
2025 Optimizing Security in Dynamic Service Migration Scenarios of Multi-Access Edge Computing
abstract
Security mechanisms and Service Level Guarantees (SLGs) often operate in tension within communication systems, where stronger security protocols introduce overhead, processing delays, and encryption-related latency that can hinder the ability to meet predefined SLGs. This challenge is particularly critical in Multi-Access Edge Computing (MEC), where service migration across edge nodes can significantly impact system performance. Ensuring the security of migrating services while maintaining low-latency communication is vital to preserving service continuity and avoiding disruptions. In this paper, we introduce a novel security framework for MEC-enabled gNodeBs that supports secure and seamless service migration. Central to our framework is an adaptive security optimization model that dynamically adjusts the security level of the migration channel based on real-time bandwidth utilization. This approach maintains the continuity of service without compromising the available bandwidth, thereby upholding the required SLGs while minimizing the impact of security-related overhead.
Pasika Ranaweera, Indika A. M. Balapuwaduge, Anca Jurcut, Engin Zeydan, Madhusanka Liyanage
VTC2025-Fall1
2025 A Secure Authentication Protocol for IoT-WLAN Using EAP Framework
abstract
The plethora of Internet of Things (IoT) devices and their diversified requirements have opted to design security mechanisms that cover all major security requirements. Wireless Local Area Networks (WLANs) is the most common network domains where IoT devices are launched, particularly because of its easy availability. Security, in other words authentication however, remains to be a major constriction for IoT-WLAN deployments. Though there are IoT based authentication protocols prevailing, such protocols are either prone to threats such as perfect forward secrecy violations, insider with database access attack, traceability attack, stolen device attack, ephemeral secret leakage, or they consume excessive computational and communication resources that result in an unprecedented burden for the IoT system. This paper presents an Extensible Authentication Protocol (EAP) based mechanism for IoT devices deployed in a WLAN that addresses the above security issues and achieves cost-effectiveness. Validation follows an informal and formal approaches (using GNY and BAN logic, and Scyther verification tool) for the proposed protocol, demonstrating its robustness. Our performance analysis shows that the proposed protocol is lightweight and more secure in contrast to the state-of-the-art solutions. In addition, performance of the proposed protocol subjected to unknown attacks is investigated, which deduces that the proposed protocol has less overhead under unknown attacks than its competitors. A prototype of the protocol has been developed to demonstrate its feasibility and accuracy.
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, Pasika Ranaweera, Madhusanka Liyanage, Neeraj Kumar 0001
IEEE Trans. Dependable Secur. Comput.4
2024 Spect-NFT: Non-Fungible Tokens for Dynamic Spectrum Management
abstract
Dynamic Spectrum Sharing (DSS) is a pivotal technology for optimizing spectrum utilization and fostering efficient sharing among diverse users. However, existing DSS approaches face significant challenges related to security and privacy vulnerabilities, leading to fraudulent practices within spectrum marketplaces. In this paper, we introduce Spect-NFT, a novel framework leveraging Non Fungible Tokens (NFTs) to address these limitations and enhance the spectrum-sharing ecosystem’s efficiency and revenue. Spect-NFT employs NFTs to authenticate ownership of spectrum bands, mitigating fraudulent activities and improving trust among participants. Additionally, Spect-NFT introduces digital Permission Tokens (PTs) to facilitate seamless spectrum sharing between primary users (PUs) and secondary users (SUs) enabling the sharing of a single NFT among multiple owners. We present a methodology for converting spectrum licenses into NFTs and demonstrate the feasibility of our approach using the Ethereum Blockchain. Our proof of concept solution showcases Spect-NFT’s tamperresistant characteristics and its potential to revolutionize DSS paradigms.
Lavan Perera, Pasika Ranaweera, Shen Wang 0006, Madhusanka Liyanage
GLOBECOM2
2024 AI on the Defensive and Offensive: Securing Multi-Environment Networks from AI Agents
abstract
The role of artificial intelligence (AI) in cybersecu-rity has grown due to increasing threats from malicious actors. It aids in threat detection, behavioral analysis, malware detection, phishing identification, and enhancing security measures. However, AI can also be weaponized for cyberattacks, as malicious actors use AI-based tools for sophisticated and adaptable assaults on security systems. This study contributes to cybersecurity by defending against AI-based threats. Machine learning models were trained on diverse, complex datasets to counter sophisticated AI-based attacks in multi-environments (M-En). We have utilized auto-encoders to generate our M-En dataset by combining two benchmark datasets: UNSW-NB15 and IoTID-20, that represent traditional IP-based and IoT-based traffic, respectively. Three generative models (CTGAN, CopulaGAN, and TVAE) produced AI-based traffic, leading to a dataset comprising traditional and AI-generated traffic. Machine learning and deep learning models were deployed on this M-En dataset. The ensemble Extra Trees classifier achieved the highest accuracy score of 0.983 for binary classification and 0.968 for multiclass problems. Our proposed approach demonstrates its effectiveness in countering AI-based traffic as well as traditional network traffic within the M-En networks.
Furqan Rustam, Pasika Ranaweera, Anca Jurcut
ICC2
2024 A Novel Authentication Protocol for 5G gNodeBs in Service Migration Scenarios of MEC
abstract
Edge computing paradigms were an expedient innovation for elevating the contemporary standards of mobile and Internet networks. As specified in Multi-Access Edge Computing (MEC) standardization, edge computing serviceable infrastructures are running on virtualization technologies to provide dynamic and flexible service instances. Since the inception and operation of the services are executing at the edge level gNodeBs ($gNB$s), migration of services between$gNB$s is an imminent occurrence in edge computing that is contriving challenges to its feasible deployment. Security and service level latency requirements are vital parameters for such service migration operations conducted through$gNB$to$gNB$(g2g) connecting channels. In this paper, our focus is to ensure identity verification among the parties involved in a service migration through authentication and to secure the migrating content through a robust g2g channel establishment. Our proposed authentication protocol was designed in accordance with the MEC architectural standardization. We have verified the proposed protocol employing four different formal verification techniques: Scyther and AVISPA verification tools, GNY and ROR logical approaches. Further, we have developed the proposed protocol in a test-bed environment emulating the MEC system with an integrated 5 G Core network.
Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut
IEEE Trans. Dependable Secur. Comput.1
2023 Blockchain for the metaverse: A Review
abstract
Since Facebook officially changed its name to Meta in Oct. 2021, the metaverse has become a new norm of social networks and three-dimensional (3D) virtual worlds. The metaverse aims to bring 3D immersive and personalized experiences to users by leveraging many pertinent technologies. Despite great attention and benefits, a natural question in the metaverse is how to secure its users' digital content and data. In this regard, blockchain is a promising solution owing to its distinct features of decentralization, immutability, and transparency. To better understand the role of blockchain in the metaverse, we aim to provide an extensive survey on the applications of blockchain for the metaverse. We first present a preliminary to blockchain and the metaverse and highlight the motivations behind the use of blockchain for the metaverse. Next, we extensively discuss blockchain-based methods for the metaverse from technical perspectives, such as data acquisition, data storage, data sharing, data interoperability, and data privacy preservation. For each perspective, we first discuss the technical challenges of the metaverse and then highlight how blockchain can help. Moreover, we investigate the impact of blockchain on key-enabling technologies in the metaverse, including Internet-of-Things, digital twins, multi-sensory and immersive applications, artificial intelligence, and big data. We also present some major projects to showcase the role of blockchain in metaverse applications and services. Finally, we present some promising directions to drive further research innovations and developments toward the use of blockchain in the metaverse in the future.
Thien Huynh-The, G. Thippa Reddy, Weizheng Wang 0001, Gokul Yenduri, Pasika Ranaweera, Quoc-Viet Pham, Daniel B. da Costa 0001, Madhusanka Liyanage
Future Gener. Comput. Syst.5
2023 Open RAN security: Challenges and opportunities
abstract
Open RAN (ORAN, O-RAN) represents a novel industry-level standard for RAN (Radio Access Network), which defines interfaces that support inter-operation between vendors’ equipment and offer network flexibility at a lower cost. Open RAN integrates the benefits and advancements of network softwarization and Artificial Intelligence to enhance the operation of RAN devices and operations. Open RAN offers new possibilities so different stakeholders can develop the RAN solution in this open ecosystem. However, the benefits of Open RAN bring new security and privacy challenges. As Open RAN offers an entirely different RAN configuration than what exists today, it could lead to severe security and privacy issues if mismanaged, and stakeholders are understandably taking a cautious approach towards the security of Open RAN deployment. In particular, this paper analyzes the security and privacy risks and challenges associated with Open RAN architecture. Then, it discusses possible security and privacy solutions to secure Open RAN architecture and presents relevant security standardization efforts relevant to Open RAN security. Finally, we discuss how Open RAN can be used to deploy more advanced security and privacy solutions in 5G and beyond RAN.
Madhusanka Liyanage, An Braeken, Shahriar Shahabuddin, Pasika Ranaweera
J. Netw. Comput. Appl.4
2022 A Novel Request Handler Algorithm for Multi-access Edge Computing Platforms in 5G
abstract
Multi-access Edge Computing (MEC) is envisaging a storage and processing infrastructure at the edge of the mobile network to guarantee ultra-low latency and higher bandwidths for the provisioning services emanated by Internet of Things (IoT) devices. To achieve these dynamic requirements, MEC is adopting virtualization technologies that form a cost effective automated infrastructure ideal for 5G and beyond networks. Orchestration is the paramount task of such virtual platforms to manage and control the virtual entities autonomously. Service request handling is one such key orchestration function that handles the incoming requests to the orchestrator in case of a service initiation. However, existing service request handling procedures in MEC are still in a trivial stage. Thus, this paper proposes an advanced service request handling strategy for MEC orchestrator which can consider several factors such as service priority levels, feasibility, and resource availability. The performance of the proposed strategy is analyzed in a simulated environment and its feasibility is demonstrated using a prototype MEC infrastructure.
Gayan Dilanka, Lakshan Viranga, Rajitha Pamudith, Tharindu D. Gamage, Pasika Ranaweera, Indika A. M. Balapuwaduge, Madhusanka Liyanage
CCNC5
2022 Service Migration Authentication Protocol for MEC
abstract
Multi-Access Edge Computing (MEC) is a novel edge computing paradigm that enhances the access level capacity of mobile networks by shifting the serviceable Data center infrastructure proximate to the end devices. With this proximate placement and service provisioning, migration of a service from one edge enabled gNodeB (gNB) to another is intrinsic to maintain the service continuity. Since such services are migrated through the channel shared between the gNBs, proper security measures should be inhibited by the communication protocol to prevent any unauthorized interception. Further, each gNB should ensure the legitimacy of the migrating gNBs to avoid any impersonation attempts. As this is an area that lacks focus in current research trends, this paper introduces MEC Service Migration Authentication Protocol (MEC-SMAP), a protocol that take place prior to the migration initiation, and specifically defined for MEC. The proposed protocol ensures the secure transfer of session key generation parameters to form a secure channel while ensuring perfect forward secrecy. It introduces an identity verification mechanism through a trusted third party service. We have validated the proposed protocol through formal analysis using GNY logic and Scyther tool. Further, a prototype virtualized MEC environment was created to evaluate its feasibility and the impact of the employed security mechanisms.
Pasika Ranaweera, Awaneesh Kumar Yadav, Madhusanka Liyanage, Anca Jurcut
GLOBECOM1
2022 MEC-RHA: Demonstration of Novel Service Request Handling Algorithm for MEC
abstract
Multi-Access Edge Computing (MEC) is a cloud computing evolution that delivers end-user services at the mobile network’s edge. As a result, MEC guarantees that users will benefit from ultra-low latency and increased bandwidth when using the services. The orchestration process is the holistic management and control of the edge computing platforms. Handling of service requests forwarded by the MEC subscribers is an inceptive function that requires the intervention of the orchestrator. This paper demonstrates how an advanced service request handler algorithm (MEC-RHA) works on MEC orchestration, considering factors of service priority levels, feasibility, and resource availability when launching a service; while an optimal MEC server selection process is formed based on those factors.
Gayan Dilanka, Lakshan Viranga, Rajitha Pamudith, Tharindu D. Gamage, Pasika Ranaweera, Indika A. M. Balapuwaduge, Madhusanka Liyanage
NOMS5
2020 Dynamic Orchestration of Security Services at Fog Nodes for 5G IoT
abstract
Fog Computing is one of the edge computing paradigms that envisages being the proximate processing and storage infrastructure for a multitude of IoT appliances. With its dynamic deployability as a medium level cloud service, fog nodes are enabling heterogeneous service provisioning infrastructure that features scalability, interoperability, and adaptability. Out of the various 5G based services possible with the fog computing platforms, security services are imperative but minimally investigated direct live. Thus, in this research, we are focused on launching security services in a fog node with an architecture capable of provisioning on-demand service requests. As the fog nodes are constrained on resources, our intention is to integrate light-weight virtualization technology such as Docker for forming the service provisioning infrastructure. We managed to launch multiple security instances configured to be Intrusion Detection and Prevention Systems (IDPSs) on the fog infrastructure emulated via a Raspberry Pi-4 device. This environment was tested with multiple network flows to validate its feasibility. In our proposed architecture, orchestration strategies performed by the security orchestrator were stated as guidelines for achieving pragmatic, dynamic orchestration with fog in IoT deployments. The results of this research guarantee the possibility of developing an ambient security service model that facilitates IoT devices with enhanced security.
Vashish N. Imrith, Pasika Ranaweera, Rameshwar A. Jugurnauth, Madhusanka Liyanage
ICC2
2020 Security as a Service Platform Leveraging Multi-Access Edge Computing Infrastructure Provisions
abstract
The mobile service platform envisaged by emerging IoT and 5G is guaranteeing gigabit-level bandwidth, ultra-low latency and ultra-high storage capacity for their subscribers. In spite of the variety of applications plausible with the envisaged technologies, security is a demanding objective that should be applied beyond the design stages. Thus, Security as a Service (SECaaS) is an initiative for a service model that enable mobile and IoT consumers with diverse security functions such as Intrusion Detection and Prevention (IDPaaS), Authentication (AaaS), and Secure Transmission Channel (STCaaS) as a Service. A well-equipped edge computing infrastructure is intrinsic to achieve this goal. The emerging Multi-Access Edge Computing (MEC) paradigm standardized by the ETSI is excelling among other edge computing flavours due to its well-defined structure and protocols. Thus, in our directive, we intend to utilize MEC as the edge computing platform to launch the SECaaS functions. Though, the actual development of a MEC infrastructure is highly dependent on the integration of virtualization technologies to enable dynamic creation, the deployment, and the detachment of virtualized entities that should feature interoperability to cater the heterogeneous IoT devices and services. To that extent, this work is proposing a security service architecture that offers these SECaaS services. Further, we validate our proposed architecture through the development of a virtualized infrastructure that integrates lightweight and hypervisor-based virtualization technologies. Our experiments prove the plausibility of launching multiple security instances on the developed prototype edge platform.
Pasika Ranaweera, Vashish N. Imrith, Madhusanka Liyanage, Anca Jurcut
ICC1