VLDB 2026 Research / reviewers in the wild / expert
Sima Bagheri
dblp:28/9863
· DBLP profile ↗
7ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0002-9798-4418ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PerfSPEC: Performance Profiling-Based Proactive Security Policy Enforcement for ContainersabstractContainer environments provide cloud native applications with scalability, flexibility, and portable support. As a popular container orchestrator, Kubernetes facilitates automatic deployment and maintenance of a large number of containerized applications. However, potential misconfigurations, vulnerabilities, or implementation flaws may empower attackers to exploit the Kubernetes cluster. Although existing solutions such as runtime security policy enforcement may prevent an attack, they can be inefficient in large scale container environments. In this paper, we propose a performance profiling-based proactive security policy enforcement solution, namely, PerfSPEC. First, we accelerate the proactivization of policies (which typically requires significant manual effort) by proposing to profile and rank existing policies according to their induced overhead. This allows us to better focus our efforts and greatly improve the overall response time (e.g., by 98% in contrast to less than 49%). Then, we address the performance limitations of existing solutions by leveraging learning-based approaches to predict future events and compute their verification results in advance. As a result, PerfSPEC achieves a viable response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) even for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Sima Bagheri, Mahmood Gholipourchoubeh, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes ClustersabstractA large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution. Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Warping the Defence Timeline: Non-Disruptive Proactive Attack Mitigation for Kubernetes ClustersabstractIn spite of being the de-facto standard of container orchestrators, Kubernetes reportedly suffers from security vulnerabilities and misconfigurations which may lead to severe security threats to the containerized environments it manages. Mitigating such threats based on alerts raised by existing security monitoring solutions (e.g., Falco) can be challenging. First, taking actions upon every alert can cause unacceptable service disruption, as many such alerts may turn out to be false positives. Second, validating each alert by administrators before taking actions may render the mitigation too late to prevent irreversible damages, e.g., denial of service. In this paper, we propose a non-disruptive proactive mitigation approach to address those limitations. Our main idea is to proactively trigger mitigation ahead of an attack to prevent irreversible damages, while designing the mitigation actions to be non-disruptive to avoid any service disruption caused by false alerts. We implement and integrate our approach with Kubernetes, and show its effectiveness and efficiency. Sima Bagheri, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi |
ICC | 1 |
| 2022 | ProSPEC: Proactive Security Policy Enforcement for ContainersabstractBy providing lightweight and portable support for cloud native applications, container environments have gained significant momentum lately. A container orchestrator such as Kubernetes can enable the automatic deployment and maintenance of a large number of containerized applications. However, due to its critical role, a container orchestrator also attracts a wide range of security threats exploiting misconfigurations or implementation flaws. Moreover, enforcing security policies at runtime against such security threats becomes far more challenging, as the large scale of container environments implies high complexity, while the high dynamicity demands a short response time. In this paper, we tackle this key security challenge to container environments through a proactive approach, namely, ProSPEC. Our approach leverages learning-based prediction to conduct the computationally intensive steps (e.g., security verification) in advance, while keeping the runtime steps (e.g., policy enforcement) lightweight. Consequently, ProSPEC can ensure a practical response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) for large container environments (up to 800 Pods). Hugo Kermabon-Bobinnec, Mahmood Gholipourchoubeh, Sima Bagheri, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001 |
CODASPY | 3 |
| 2020 | Dynamic Firewall Decomposition and Composition in the CloudabstractFirewalls filter malicious traffic and provide the network with a satisfying level of security. Thus, their performance is critical for the whole network. Rule-based firewalls are the most widely deployed among traditional ones. However, as the size of the rule list of a firewall increases, lookup latency increases significantly. One main solution to enhance the performance of a firewall is to reorder rules based on traffic characteristics to obtain the minimum number of packet matches. The optimal firewall rule ordering problem (ORO) is NP-Complete. Therefore, setting up a centralized firewall for a whole network is infeasible. Our proposed solution dynamically scales in and out firewalls across multiple administrative domains for more efficient rules optimization, filtering, and better attack response. The proposed solution, in this paper, outsources the firewall functions into micro firewalls, which are located in different places and have their configurations. Therefore, traffic is treated locally and in a distributed way. The experimental results show that our proposed solution is scalable regarding the organization's network requirements. Moreover, the central firewall is relaxed executing rules optimization algorithms in consecutive time intervals, inefficiency. Sima Bagheri, Alireza Shameli-Sendi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Software Project Estimation Using Improved Use Case PointabstractEstimating metrics, such as effort, schedule and cost, needed for a software to be created and launched into market have significant economical effects. One of the most extensively utilized method for such estimation is a technique called Use Case Points. It is based on the use case modeling which is a popular and widely used technique for capturing and describing the functional requirements of a software system. In this paper multitude number of techniques have been proposed as the basis for improving estimation of the effort, schedule, and costs of software projects. These terms are conceptually similar but utilize different parameter values and metrics. Moreover, different versions of use case points have been proposed. This method suffers some limitations such as less accuracy, failure to consider software risks, failure to consider software quality aspects, failure to consider different levels of software security, and so on. The aim of this paper is to propose a new approach for cost estimation, based on use case points method, by considering all the existing risks related to software projects. The results indicate that the new estimation approach can produce relatively accurate estimates and also declare various aspects of project risks during project estimation. Our results also provide guidance for organizations that want to develop a software project. Sima Bagheri, Alireza Shameli-Sendi |
SERA | 1 |
| 2010 | Bayesian Estimation of Optical Properties of Nearshore Estuarine Waters: A Gibbs Sampling ApproachabstractA novel approach is developed for the retrieval of inherent optical properties of coastal water, from which water-quality constituent concentrations can be obtained. The technique combines an analytical bio-optical model with statistical modeling for the formulation of posterior probability distributions of phytoplankton absorption, backscattering, and colored dissolved organic matter absorption; a Gibbs Sampler is employed for optimization. In contrast to other methods that typically provide point estimates of the unknown parameters, the proposed method estimates posterior distributions of the parameters, quantifying the uncertainty present in the problem and revealing correlation patterns. The method is tested successfully on synthetic reflectance data and real data measuredin situin the Hudson/Raritan Estuary of New York-New Jersey. Zoi-Heleni Michalopoulou, Sima Bagheri, Lisa Axe |
IEEE Trans. Geosci. Remote. Sens. | 2 |