Sandip Saha

dblp:255/5741 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-1207-2525ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Artificial neural network analysis of magnetohydrodynamics hybrid nanofluid flow over a convectively heated vertical cone in presence of chemical reaction effects
Susmay Nandi, Reshu Gupta, Shyam Sundar Santra, Sandip Saha
Eng. Appl. Artif. Intell.4
2023 YODA: Covert Communication Channel over Public DNS Resolvers
abstract
Enterprises are increasingly migrating to public domain name system (DNS) resolvers for reliability, cost optimizations, and, most importantly, improved security and user privacy. The integrated threat intelligence feeds at these resolvers enable easy identification and blocking of malicious exploits that use DNS queries. However, we observe that the shared local caches at these public DNS resolvers enable covert communication channels from otherwise secure enterprises accessible to any remote adversary, thus cautioning the migration to public DNS resolvers. We present YODA, a covert communication channel via public DNS resolvers that can exfiltrate sensitive information from a victim enterprise to a remote adversary. Unlike prior works, YODA overloads DNS queries for popular domains to transfer the data without revealing any identity of the adversary. Consequently, YODA cannot be blocked by domain name filtering. We demonstrate our attack on public DNS resolvers such as Google, Cloudflare, Quad9, OpenDNS, and LibreDNS. Our evaluations show that the adversary can achieve a bandwidth of 480bps with desktop devices.
Sandip Saha, Sareena Karapoola, Chester Rebeiro, V. Kamakoti 0001
DSN1
2023 Snoopy: A Webpage Fingerprinting Framework With Finite Query Model for Mass-Surveillance
abstract
Internet users are vulnerable to privacy attacks despite the use of encryption. Webpage fingerprinting, an attack that analyzes encrypted traffic, can identify the webpages visited by a user. The key challenges in performing mass-scale webpage fingerprinting arise from (i) the sheer number of combinations of user behavior and preferences to account for, and; (ii) the bound on the number of website queries imposed by the defense mechanisms (e.g., DDoS defense) deployed at the website. These constraints preclude the use of conventional data-intensive ML-based techniques. In this work, we propose Snoopy, a first-of-its-kind framework, that performs webpage fingerprinting for a large number of users visiting a website. Snoopy caters to the generalization requirements of mass-surveillance while complying with a bound on the number of website accesses (finite query model) for traffic sample collection. We show that Snoopy achieves$\approx 90\%$accuracy when evaluated on most websites, across various browsing contexts. A simple ensemble of Snoopy and an ML-based technique achieves$\approx 97\%$accuracy while adhering to the finite query model, in cases when Snoopy alone does not perform well.
Gargi Mitra, Prasanna Karthik Vairam, Sandip Saha, Nitin Chandrachoodan, V. Kamakoti 0001
IEEE Trans. Dependable Secur. Comput.3
2021 Numerical simulations of Newtonian fluid flow through a suddenly contracted rectangular channel with two different types of baffle plates
Sandip Saha, Pankaj Biswas, Sujit Nath, Lokendra Singh
Soft Comput.1