VLDB 2026 Research / reviewers in the wild / expert
Ernest Foo
dblp:42/3445
· DBLP profile ↗
52ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0002-3971-6415ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 3 first-author · 12 since 2021Computer networks · 4Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-agent reinforcement curriculum learning for real unmanned ground vehiclesabstractThis paper investigates the use of deep reinforcement learning (DRL) for the control of mobile robot teams within the context of navigation and task-based collaborative scenarios. We apply a DRL policy with a tailored neural network architecture as a solution to control, path planning, and higher-level guidance tasks. Our network architecture was trained using a unique multi-stage curriculum that progresses from single-agent navigation, to multi-agent pathfinding with obstacles, and finally to a complex collaborative firefighting scenario. This structured approach accelerates training convergence by systematically building sophisticated collaborative behaviours upon foundational skills, which enhances training stability and guides the agents towards learning effective and coordinated strategies The policy evaluation was conducted in both simulation and hybrid simulation-physical demonstrations utilising a real unmanned ground vehicle (UGV). The policy presented is capable of achieving multi-agent navigation tasks with a 95.83% accuracy in our testing environments, and has demonstrated emergent multi-agent behaviours. In more complex collaborative firefighting scenarios, the policy also demonstrated superior performance than baselines in reaching goals, e.g., navigating and extinguishing two fires with a 99.67% success rate, suggesting its strong potential for real-world deployment. Timothy Mead, Zhe Wang 0001, Ernest Foo, Jin Song Dong 0001, Naipeng Dong, Ryan Kok Leong Ko, Abigail M. Y. Koay, Kien Nguyen Thanh, Yue Xu 0001, Junae Kim, Stephen Bornstein |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | A structure-aware and explainable approach to website fingerprinting using graph neural networksabstractWebsite fingerprinting (WF) poses a significant threat to anonymity networks such as Tor, allowing adversaries to infer visited sites from encrypted traffic. Packet direction has emerged as a dominant feature in WF, outperforming timing and size-based features, even against Tor defences, particularly when leveraged by deep learning (DL) models, yet its resilience remains poorly understood. To investigate this behaviour, we propose a structure-aware WF method that represents each traffic trace as a graph in which nodes correspond to burst-level temporal bins and edges encode both temporal adjacency and data driven dependencies estimated through mutual information. This graph formulation organises burst-level directional information into a topology that exposes temporal continuity and dependency structure across the trace, enabling a GNN to learn request response sequencing, inter-burst interactions, chronology, and non-local dependencies. Directional features show stronger transferability because they are represented at a coarse-grained burst level. This preserves stable web interaction patterns while suppressing packet-level details that are susceptible to distortion by Tor defences, such as obfuscation, including packet-length obfuscation. In closed-world experiments, the proposed method achieves the highest average defended accuracy of 62.99%, while in open-world settings it yields superior precision–recall performance. The graph representation supports a structured examination of traffic traces, providing insights into the robustness of packet direction across defence scenarios and illustrating how graph-based modelling can strengthen systems for encrypted-traffic analysis. Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi |
Inf. Sci. | 2 |
| 2025 | LTL-based runtime verification framework for cyber-attack anomaly prediction in cyber-physical systemsabstractAn anomaly is any unexpected or abnormal behaviour, event, or data pattern within a network of physical and computational components caused by data errors, cyber-attacks, hardware failures, or other unforeseen events. Anomaly detection analyses events after they occur, while anomaly prediction forecasts them before they manifest. The increasing complexity of Cyber-Physical Systems (CPS) presents challenges in fault management and vulnerability to advanced attacks, highlighting the need for early intervention through anomaly prediction. Existing anomaly prediction methods often fail due to a lack of formal guarantees required for safety-critical applications. In this paper, we introduce our anomaly prediction framework which merges the advantages of data analytics and the derivation of Linear Temporal Logic (LTL) formulas. LTL-based runtime monitoring and checking is a well-established technique efficient for tackling challenges in real-time and promptly. The framework processes historical data, clusters them to extract predictive patterns, and forms data sequences that represent these trends. These sequences are fed into an LTL learning algorithm to produce a formula that represents the pattern. This formula functions as a security property programmed into a runtime checker to verify system correctness and predict the possibility of anomalies. We evaluated our framework using three datasets collected from a cyber-physical system testbed and the experimental findings demonstrate a minimum accuracy of 90% in predicting anomalies. Ayodeji James Akande, Ernest Foo, Qinyi Li |
Comput. Secur. | 3 |
| 2025 | A graph representation framework for encrypted network traffic classificationabstractNetwork Traffic Classification (NTC) is crucial for ensuring internet security, but encryption presents significant challenges to this task. While Machine Learning (ML) and Deep Learning (DL) methods have shown promise, issues such as limited representativeness leading to sub-optimal generalizations and performance remain prevalent. These problems become more pronounced with advanced obfuscation, network security, and privacy technologies, indicating a need for improved model robustness. To address these issues, we focus on feature extraction and representation in NTC by leveraging the expressive power of graphs to represent network traffic at various granularity levels. By modeling network traffic as interconnected graphs, we can analyze both flow-level and packet-level data. Our graph representation method for encrypted NTC effectively preserves crucial information despite encryption and obfuscation. We enhance the robustness of our approach by using cosine similarity to exploit correlations between encrypted network flows and packets, defining relationships between abstract entities. This graph structure enables the creation of structural embeddings that accurately define network traffic across different encryption levels. Our end-to-end process demonstrates significant improvements where traditional NTC methods struggle, such as in Tor classification, which employs anonymization to further obfuscate traffic. Our packet-level classification approach consistently outperforms existing methods, achieving accuracies exceeding 96%. Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi |
Comput. Secur. | 2 |
| 2025 | See the words through my eyes: The role of personal traits in abusive language detectionabstractAbusive language detection systems play a significant role in addressing cyberbullying. However, conventional detection systems primarily focus on the textual pattern of messages for their prediction, overlooking the reality that the same message can usually provoke different consequences for different users. In other words, personalised predictions are essential but currently absent. To address this limitation, this paper considers the rationality of introducing a set of psychological features to personalise abusive language detection tasks. The foundation of our work lies in the Antecedents, Behaviours, Consequences model (ABC model), asserting that an individual’s response to a trigger message is impacted not only by the trigger itself but also by their personal beliefs and attitudes. We develop a novel data preparation framework and construct a new abusive language dataset, incorporating psychological features from 505 online users. Logistic regression analysis illustrates that Irrationality and Self-down features positively correlate with the abusive class, while Rationality features exhibit a negative correlation. These results are supported by established psychological findings. Furthermore, a preliminary evaluation showed that our proposed psychological features improve a CNN-based detection system’s Macro and Weighted F1 scores by 4%–5% points when making personalised predictions. These results collectively make for an empirical case that underscores the importance of considering users’ psychological features in abusive language detection. Crucially, these findings also pave the way for developing personalised prediction systems. • Psychological features improve the detection system’s F1 scores by 4%–5% points. • Psychological theory and features are transferable to detection systems studies. • Due to a self-selection bias, online and ordinary users are substantially different. • A new abusive language dataset incorporates psychological features from 505 users. Tsungcheng Yao, Sebastian Binnewies, Ernest Foo, Masoumeh Alavi |
Expert Syst. Appl. | 3 |
| 2024 | Contextual Transformer-based Node Embedding for Vulnerability Detection using Graph LearningabstractAutomated source code vulnerability detection using code graphs has seen major improvements in recent years, however one critical, but oft-overlooked, element of this problem is producing embeddings for graph nodes. Before graph-based classifiers can be used for vulnerability detection, the nodes in the graph must first be given vector representations. Graphlearning models propagate information from these embeddings through the graph before classification, and so the initial states of these embeddings are vital for all subsequent learning. While a variety of solutions to this problem have been proposed in existing literature, this is typically not the focus of these works. We propose a novel node embedding strategy for graph-based vulnerability discovery, which takes advantage of richly-learned information about the code contained in each node. We also implement and test several existing node embedding strategies, comparing them to each other and our new strategy under a standard graph-learning architecture. We find that our strategy outperforms existing methods by 10.47-50.70%. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 3 |
| 2024 | Improved Packet-Level Synthetic Network Traffic GenerationabstractWhile using generative models to create synthetic network traffic is faster and cheaper than traditional testbeds, synthetic traffic suffers from problems with realism and structural completeness. State of the art traffic generation frameworks usually omit payloads because of the difficulties in representing their high-dimensional data, which makes the synthetic traffic unrealistic and limits its usefulness. This work proposes a two-stage process that takes advantage of the high repetition of some protocols, particularly those used by Industrial Control Systems, to selectively simplify payloads, greatly reducing the number of classes and reducing model loss and consequently the ability of the model to handle sequences of payloads. Model training loss was reduced by 47.796%, and payload class selection was improved up to 69% over state of the art approaches, allowing for more realistic synthetic network traffic with reduced memory and computation overheads. Jacob Soper, Yue Xu 0001, Ernest Foo, Zahra Jadidi, Kien Nguyen Thanh |
TrustCom | 3 |
| 2024 | Current approaches and future directions for Cyber Threat Intelligence sharing: A surveyabstractCyber Threat Intelligence (CTI) is essential knowledge concerning cyber and physical threats aimed at mitigating potential cyber attacks. The rapid evolution of Information and Communications Technology (ICT), the Internet of Things (IoT), and Industry 5.0 has spawned a multitude of sources regarding current or potential cyber threats against organizations. Consequently, CTI sharing among organizations holds considerable promise for facilitating swift responses to attacks and enabling mutual benefits through active participation. However, exchanging CTI among different organizations poses significant challenges, including legal and regulatory obligations, interoperability standards, and data reliability. The current CTI sharing landscape remains inadequately explored, hindering a comprehensive examination of organizations’ critical needs and the challenges they encounter during CTI sharing. This paper presents a comprehensive survey on CTI sharing, beginning with an exploration of CTI fundamentals and its advancements in assessing cyber and physical threats and threat actors from various perspectives. For instance, we discuss the benefits of CTI, its applications, and diverse CTI sharing architectures. Additionally, we extensively discuss a list of CTI sharing challenges and evaluate how available CTI sharing proposals address these challenges. Finally, we provide an inventory of unique future research directions to offer insightful guidelines for CTI sharing. Poopak Alaeifar, Shantanu Pal, Zahra Jadidi, Mukhtar Hussain, Ernest Foo |
J. Inf. Secur. Appl. | 5 |
| 2024 | A Provably Secure and Efficient Cryptographic-Key Update Protocol for Connected VehiclesabstractWireless broadcast transmission technology enables vehicles to communicate with other nearby vehicles and with nearby fixed equipment. Vehicles and equipment within transmission range establish a self-organizing network called Vehicular Ad-hoc Network (VANET). The communication in VANETs is vulnerable to message manipulation attacks. Thus, mechanisms should be applied to ensure both the authenticity and integrity of the data broadcast. Any cryptographic technique employed for authentication requires the use of a cryptographic key, and mechanisms to restore the system quickly when either long-term and short-term cryptographic keying material are leaked or expired. Such mechanisms must be carefully designed to satisfy both perfect-forward-secrecy and security against known-key attacks. To achieve this, there should be no direct dependencies among keying material. Unfortunately, many existing proposals for authentication are not fully effective in VANETs, since many of them do not take a key-management mechanism into consideration or they fail to satisfy the requirements for secure key-update. In this paper, we first present a case study demonstrating that dependency among keying material is an exploitable vulnerability that violates perfect-forward-secrecy, and results in known-key attacks and message forgery attacks. Secondly, we propose a new cryptographic-key update protocol that consists of two sub-protocols: a long-term-key update protocol (for updating the long-term cryptographic keying material) and a short-term-key update protocol (for session-key establishment). Our scheme is accompanied by both security and efficiency analysis: we provide a formal security proof and demonstrate efficiency by conducting extensive performance analysis. This is compared with the security and efficiency of existing schemes in public literature. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Tightly Secure Lattice Identity-Based Signature in the Quantum Random Oracle Model
Ernest Foo, Qinyi Li |
ACISP | 1 |
| 2023 | Encrypted Network Traffic Classification with Higher Order Graph Neural Network
Zulu Okonkwo, Ernest Foo, Qinyi Li, Zahra Jadidi |
ACISP | 2 |
| 2023 | A Runtime Verification Framework for Cyber-Physical Systems Based on Data Analytics and LTL Formula Learning
Ayodeji James Akande, Ernest Foo, Qinyi Li |
ICFEM | 3 |
| 2023 | Discovering a data interpreted petri net model of industrial control systems for anomaly detection
Mukhtar Hussain, Colin J. Fidge, Ernest Foo, Zahra Jadidi |
Expert Syst. Appl. | 3 |
| 2023 | ALI: Anonymous Lightweight Inter-Vehicle Broadcast Authentication With EncryptionabstractWireless broadcast transmission enables Inter-vehicle or Vehicle-to-Vehicle (V2V) communication among nearby vehicles. This communication supports latency-critical applications for improved safety and maybe optimized traffic. However, V2V communication is vulnerable to cyber attacks involving message manipulation. Mechanisms are required to ensure both authenticity and integrity of broadcast data, while maintaining drivers privacy against surveillance. Considering the limited computational resources of vehicles and the possibility of high traffic density scenarios, authentication processes should have low computational overhead. Prior research has produced multiple authentication protocol proposals based on digital signatures, hash functions, or Message Authentication Codes (MACs). To date, there is no computationally efficient secure broadcast authentication scheme tolerable by the vehicles resource-constrained On-Board Units (OBUs) for latency-critical applications in heavy traffic conditions. This paper provides a new secure, efficient, and privacy-preserving scheme proposing Anonymous Lightweight Inter-vehicle (ALI) broadcast authentication with encryption. ALI provides a high level of anonymity by combining a message authentication scheme with beacon encryption. The cryptographic overhead for V2V communication in the ALI scheme is only 149 bytes, and can handle authentication of approximately 700 broadcast messages every 100 milliseconds. This demonstrates the suitability of the ALI scheme in heavy traffic scenarios. We show the security and efficiency of our proposal by conducting security proof and performance analysis. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | A Digital Twin Runtime Verification Framework for Protecting Satellites Systems from Cyber AttacksabstractThis paper presents the conceptualisation of a framework that combines digital twins with runtime verification and applies the techniques in the context of security monitoring and verification for satellites. We focus on special considerations needed for space missions and satellites, and we discuss how digital twins in such applications can be developed and how the states of the twins should be synchronised. In particular, we present state synchronisation methods to ensure secure and efficient long-distance communication between the satellite and its digital twin on the ground. Building on top of this, we develop a runtime verification engine for the digital twin that can verify properties in multiple temporal logic languages. We end the paper with our proposal to develop a fully verified satellite digital twin system as future work. Qinyi Li, Ernest Foo, Jin Song Dong 0001, Paulo de Souza |
ICECCS | 3 |
| 2022 | SCEVD: Semantic-enhanced Code Embedding for Vulnerability DiscoveryabstractSource code vulnerability detection is a major goal in security research. In recent years, deep learning methods have been applied to this end, however the task of embedding code into vector representations as input for deep learning models has yet to be definitively solved. The use of graphs, specifically Abstract Syntax Trees and Code Property Graphs, is a promising research direction for this task, however learning from graphs grows prohibitively computationally expensive for large graphs. No close examination of intelligent ways to prune this input to only vulnerability-relevant information has yet been performed. Additionally, most existing works focus largely on structural information from graphs, often neglecting information contained within the nodes themselves. We address these gaps in the prior research by proposing SCEVD: a deep learning model for vulnerability discovery which utilises semantic information to intelligently select features in source code graphs for learning. It uses information contained within code graph nodes, as well as information about their relationships with one another to select the code graph features which are most relevant to code vulnerability. We implement SCEVD and conduct experiments using the SARD Juliet test suite, finding that we are able to improve vulnerability discovery results using this process of semantic-enhanced code graph feature selection. Joseph Gear, Yue Xu 0001, Ernest Foo, Praveen Gauravaram, Zahra Jadidi, Leonie Ruth Simpson |
TrustCom | 3 |
| 2022 | Discovering Data-Aware Mode-Switching Constraints to Monitor Mode-Switching Decisions in Supervisory ControlabstractIn a multimode industrial control system, mode switching decisions have to follow standard operating procedures which are set for the safety of the system based on the operating limitations of equipment. A rich literature can be found on monitoring multimode systems. However, that work is mainly focused on mode identification and monitoring anomalies in the process running under each mode. Instead, we present a data-driven method for monitoring the modes’ switching constraints. This article is based on state-transition matrix and decision-tree methods to discover data-driven mode switching conditions. Moreover, our approach is not limited to only threshold based condition learning. To capture data trajectory-based conditions, we adopt a functional data descriptors method. In practical experiments, we showed that our approach can discover anomalous mode-switching decisions which cannot be discovered by previous multimode process-monitoring methods. Mukhtar Hussain, Colin J. Fidge, Ernest Foo, Zahra Jadidi |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Anonymous Lattice Identity-Based Encryption with Traceable Identities
Xavier Boyen, Ernest Foo, Qinyi Li |
ACISP | 2 |
| 2021 | CCA-security from adaptive all-but-one lossy trapdoor functions
Qinyi Li, Xavier Boyen, Ernest Foo |
Theor. Comput. Sci. | 3 |
| 2021 | On the Efficiency of Pairing-Based Authentication for Connected Vehicles: Time is Not on Our Side!abstractIn the near future, intelligent vehicles will be connected via wireless communication links, forming Vehicular Ad-hoc Networks (VANETs). This has potential to improve road safety and to optimize traffic. However, if the communications are not secure, VANETs are vulnerable to cyber attacks involving message manipulation. Research on this problem has produced multiple authentication protocols based on bilinear pairings (a variant of elliptic curve cryptography). The efficiency of such authentication schemes must be addressed before they can be used in real-world deployments. Standards bodies have begun standardizing various pairing-based schemes. The IEEE 1609.2 security standard has not yet selected any pairing-based scheme, leaving the settings related to pairing-based cryptography in the vehicular environments unspecified. In this work, we investigate the efficiency of pairing-based cryptographic primitives over the Barreto-Lynn-Scott and Barreto-Naehrig pairing friendly elliptic curves recommended in the IETF and ISO standards, to determine their suitability for practical application. We implement the algorithms and evaluate the effect of cryptographic pairings using theoretical and experimental analysis of four well-known pairing-based short signature schemes, including: Boneh-Lynn-Shacham, Boneh-Boyen, Zhang-Safavi-Susilo, and Boneh-Gentry-Lynn-Shacham. We use metrics including CPU clock cycles per operation, average computation time in milliseconds, and signature/public key size in bits to estimate the cost of implementing cryptographic pairings on modern processors. We demonstrate the effect of pairing-based cryptography on authentication in vehicular networks. We investigate a high-density highway scenario and show that a crash is possible, as a result of the evaluated authentication delay. We share our findings ahead of the IEEE 1609.2 recommendations for the use of cryptographic pairings. Mir Ali Rezazadeh Baee, Leonie Ruth Simpson, Xavier Boyen, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Compact Multi-Party Confidential Transactions
Jayamine Alupotha, Xavier Boyen, Ernest Foo |
CANS | 3 |
| 2020 | An Efficient Authentication Scheme for Intra-Vehicular Controller Area NetworkabstractCommunication in modern cars is managed by a controller area network (CAN) bus protocol and its extensions for electronic control units (ECUs). The CAN bus is a preferred method for reliable real-time broadcast communication. However, unprotected CAN communications make the vehicles vulnerable to a variety of practical malicious wired/wireless attacks. In this work, we analyze the existing frame-level authentication protocol and identify weaknesses and limitations. To address this, we provide a protocol suite for entity authentication, key management, a secure message flow for remote transmission request frames and session key update to be applied for vehicle connection with external devices. We prove the security of our protocol in the random oracle model and assess its resistance against known attacks. We formally verify the security of our protocol using the Tamarin tool. Our simulation results indicate that our protocol improves efficiency. Basker Palaniswamy, Seyit Ahmet Çamtepe, Ernest Foo, Josef Pieprzyk |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Anomaly detection for industrial control systems using process mining
David Myers, Suriadi Suriadi, Kenneth Radke, Ernest Foo |
Comput. Secur. | 4 |
| 2017 | Process Control Cyber-Attacks and Labelled Datasets on S7Comm Critical Infrastructure
Nicholas R. Rodofile, Sebastian T. Sherry, Christopher Djamaludin, Kenneth Radke, Ernest Foo |
ACISP (2) | 6 |
| 2017 | Modeling for performance and security balanced trading communication systems in the cloudabstractMoving Trading Communication Systems (TCSs) services to the cloud may seem to be a cost-effective choice. However, operating cloud-based TCSs across the Internet does face a number of challenges including availability, quality of service (QoS), performance and security issues. This research examines the feasibility for creation of a usable model to enable assessment of the design and implementation of TCSs in relation to both time-critical performance and appropriate security levels as TCSs are migrated to a public cloud environment. A real-world case study of a company operating a TCS, which is recently scheduled for movement to a public cloud, is used to enable assessment of a simulation system using OPNET. The simulation results show 1) that the performance of a cloud-based TCS may be inferior to traditional circuit-switched and leased-line-based TCSs, where equivalent services requirements and costs are involved; and 2) a methodology relevant to how to best manage and control a cloud-based TCS to realize true benefit while maintaining required level of QoS, performance and overall security is possible. Aklilu Daniel Tesfamicael, Vicky Liu, Ernest Foo, William J. Caelli |
IPCCC | 3 |
| 2017 | Process Discovery for Industrial Control System Cyber Attack Detection
David Myers, Kenneth Radke, Suriadi Suriadi, Ernest Foo |
SEC | 4 |
| 2017 | Reed Solomon Codes for the Reconciliation of Wireless PHY Layer Based Secret KeysabstractThis paper proposes a key reconciliation mechanism using Reed Solomon code to improve the effectiveness of secret key generation based on Received Signal Strength (RSS) variations in a wireless channel between two communicating parties. We use a two threshold quantization algorithm which can operate as a lossless system improving the secret bit extraction rate. We present our Reed Solomon (RS) code based algorithm for reconciling the independently derived secret keys through sharing of only the syndrome bits. We evaluate our reconciliation algorithm using simulated channel measurements and real environment data gathered between an unmanned aerial vehicle (UAV) and a controller in a semi mobile environment. We show that by selecting appropriate parameters of the RS code, it is possible to generate matching keys at the transmitter and the receiver which can be used to secure the communication at wireless PHY or upper layers. Michelle Fernando, Dhammika Jayalath, Seyit Ahmet Çamtepe, Ernest Foo |
VTC Fall | 4 |
| 2016 | Finding Anomalies in SCADA Logs Using Rare Sequential Pattern Mining
Anisur Rahman, Yue Xu 0001, Kenneth Radke, Ernest Foo |
NSS | 4 |
| 2016 | Automated feature engineering for HTTP tunnel detection
Jonathan J. Davis, Ernest Foo |
Comput. Secur. | 2 |
| 2016 | Revocation and update of trust in autonomous delay tolerant networks
Chris I. Djamaludin, Ernest Foo, Seyit Ahmet Çamtepe, Peter I. Corke |
Comput. Secur. | 2 |
| 2016 | Formal modelling and analysis of DNP3 secure authentication
Raphael Amoah, Seyit Ahmet Çamtepe, Ernest Foo |
J. Netw. Comput. Appl. | 3 |
| 2016 | Securing DNP3 Broadcast Communications in SCADA SystemsabstractThe Distributed Network Protocol version 3 (DNP3) provides Secure Authentication (DNP3-SA) as the mechanism to authenticate unicast messages from a master station to its outstations in supervisory control and data acquisition systems. In large-scale systems, it may be necessary to broadcast a critical request from a master station to multiple outstations at once. The DNP3 protocol standard describes the use of broadcast communication; however, it does not specify its security. This paper is the first to present DNP3 Secure Authentication for Broadcast (DNP3-SAB), a new lightweight security scheme for broadcast mode communication. This scheme is based on hash chain and only makes use of the existing cryptographic primitives specified in DNP3-SA. The scheme integrates itself into the DNP3-SA key update process. The proposed scheme is modeled, validated, and verified using colored Petri Nets against the most common protocol attacks such as modification, injection, and replay. Performance analysis on our scheme and the existing DNP3-SA modes (NACR and AGM) shows that DNP3-SAB reduces the communication overhead significantly at the cost of an increase with a constant term in processing and storage overhead. This benefit is maintained even when DNP3-SAB is under attack. Raphael Amoah, Seyit Ahmet Çamtepe, Ernest Foo |
IEEE Trans. Ind. Informatics | 3 |
| 2014 | Security analysis of the non-aggressive challenge response of the DNP3 protocol using a CPN modelabstractDistributed Network Protocol Version 3 (DNP3) is the de-facto communication protocol for power grids. Standard-based interoperability among devices has made the protocol useful to other infrastructures such as water, sewage, oil and gas. DNP3 is designed to facilitate interaction between master stations and outstations. In this paper, we apply a formal modelling methodology called Coloured Petri Nets (CPN) to create an executable model representation of DNP3 protocol. The model facilitates the analysis of the protocol to ensure that the protocol will behave as expected. Also, we illustrate how to verify and validate the behaviour of the protocol, using the CPN model and the corresponding state space tool to determine if there are insecure states. With this approach, we were able to identify a Denial of Service (DoS) attack against the DNP3 protocol. Raphael Amoah, Suriadi Suriadi, Seyit Ahmet Çamtepe, Ernest Foo |
ICC | 4 |
| 2013 | Establishing initial trust in autonomous Delay Tolerant Networks without centralised PKI
Chris I. Djamaludin, Ernest Foo, Peter I. Corke |
Comput. Secur. | 2 |
| 2012 | Mitigating On-Off attacks in reputation-based secure data aggregation for wireless sensor networksabstractAbstract In‐network aggregation is considered as an efficient way to reduce the energy consumption in wireless sensor networks (WSNs). However, it opens doors for a compromised node to distort the integrity of the aggregated data by altering the data and disrupting transmission of the aggregation results. Thus, several secure data aggregation protocols were designed to mitigate the effect of the node compromise attack and ensure data integrity. Most protocols can detect the manipulation of the aggregation results and then reject them at the base station, which gives a single node compromise the opportunity to disrupt the limited resources in the network. Reputation‐based secure data aggregation protocols take a step further in helping to identify compromised nodes as early as possible. However, reputation‐based protocols are prone to On‐Off attacks (OOs) in which a compromised node is able to affect the aggregation results without being detected. The compromised node behaves maliciously now and then to ensure that its reputation value is within the trustable level. A solution to defeat this attack is proposed in this paper. The significance of the proposal is twofold: (i) it extends Alzaidet al.'s protocol and mitigates the effect of the OO on the aggregation results, and (ii) it considers non‐homogeneous environments, which requires distinguishing between abrupt and incipient changes. In a comparative analysis of our proposal with Alzaidet al.'s protocol, plain estimate, and reputation‐based estimate shows its superior performance in mitigating the effect of the attack. Copyright © 2011 John Wiley & Sons, Ltd. Hani Alzaid, Ernest Foo, Juan Manuel González Nieto |
Secur. Commun. Networks | 2 |
| 2010 | Mitigating Sandwich Attacks Against a Secure Key Management Scheme in Wireless Sensor Networks for PCS/SCADAabstractAlzaid et al. proposed a forward & backward secure key management scheme in wireless sensor networks for Process Control Systems (PCSs) or Supervisory Control and Data Acquisition (SCADA) systems. The scheme, however, is still vulnerable to an attack called the sandwich attack that can be launched when the adversary captures two sensor nodes at times t1and t2, and then reveals all the group keys used between times t1and t2. In this paper, a fix to the scheme is proposed in order to limit the vulnerable time duration to an arbitrarily chosen time span while keeping the forward and backward secrecy of the scheme untouched. Then, the performance analysis for our proposal, Alzaid et al.'s scheme, and Nilsson et al.'s scheme is given. Hani Alzaid, DongGook Park, Juan Manuel González Nieto, Ernest Foo |
AINA | 4 |
| 2010 | Protecting the protectors: Legal liabilities from the use of Web 2.0 for Australian disaster responseabstractThe traditional model for information dissemination in disaster response is unidirectional from official channels to the public. However recent crises in the US, such as Hurricane Katrina and the Californian Bushfires show that civilians are now turning to Web 2.0 technologies as a means of sharing disaster related information. These technologies present enormous potential benefits to disaster response authorities that cannot be overlooked. In Australia, the Victorian Bushfires Royal Commission has recently recommended that Australian disaster response authorities utilize information technologies to improve the dissemination of disaster related, bushfire information. However, whilst the use of these technologies has many positive attributes, potential legal liabilities for disaster response authorities arise. This paper identifies some potential legal liabilities arising from the use of Web 2.0 technologies in disaster response situations thereby enhancing crisis related information sharing by highlighting legal concerns that need to be addressed. Rouhshi Low, Mark Burdon, Sharon Christensen, William D. Duncan, Paul Barnes, Ernest Foo |
ISTAS | 6 |
| 2009 | Modeling and Verification of Privacy Enhancing Protocols
Suriadi Suriadi, Chun Ouyang 0001, Jason Smith 0001, Ernest Foo |
ICFEM | 4 |
| 2009 | A user-centric federated single sign-on system
Suriadi Suriadi, Ernest Foo, Audun Jøsang |
J. Netw. Comput. Appl. | 2 |
| 2008 | Strengthening SMS-Based Authentication through UsabilityabstractCurrent state-of-the art solutions for online banking authentication and identity management include methods for re-authenticating users via out-of-band channels for each transaction. SMS-based schemes belong to this category, and can provide strong authentication to protect against security attacks. Poor usability of these schemes is still a problem, which makes them vulnerable to other obvious attacks. This paper describes a method for improving the usability of typical SMS-based authentication schemes which thereby will improve their overall security. Mohammed Al Zomai, Audun Jøsang, Adrian McCullagh, Ernest Foo |
ISPA | 4 |
| 2008 | RSDA: Reputation-Based Secure Data Aggregation in Wireless Sensor NetworksabstractWireless Sensor Networks (WSNs) are a new technology that is expected to be used in the near future due to its cheap cost and data processing ability. However, securing WSNs with traditional cryptographic mechanism is insufficient because of the existing limited resources and the lack of tamper resistant hardware. In this paper, we propose a Reputation-based Secure Data Aggregation for WSNs (RSDA) that integrates aggregation functionality with the advantages provided by a reputation system to enhance the network lifetime and the accuracy of the aggregated data. We bind symmetric secret keys to geographic locations and assign these keys to sensor nodes based on their locations. RSDA therefore can resist an adversary that is capable to compromise up to W sensor nodes in total with no more than t -1 compromised nodes in any cell. Hani Alzaid, Ernest Foo, Juan Manuel González Nieto |
PDCAT | 2 |
| 2008 | A User-Centric Protocol for Conditional Anonymity Revocation
Suriadi Suriadi, Ernest Foo, Jason Smith 0001 |
TrustBus | 2 |
| 2007 | Toward Non-parallelizable Client Puzzles
Suratose Tritilanunt, Colin Boyd, Ernest Foo, Juan Manuel González Nieto |
CANS | 3 |
| 2006 | A Secure E-Tender Submission Protocol
Colin Boyd, Ernest Foo |
TrustBus | 3 |
| 2005 | Designing Secure E-Tendering Systems
Ernest Foo, Juan Manuel González Nieto, Colin Boyd |
TrustBus | 2 |
| 2004 | A Mobile Agent System Providing Offer Privacy
Matt Henricksen, Greg Maitland, Ernest Foo, Ed Dawson |
ACISP | 4 |
| 2004 | Offer Privacy in Mobile Agents Using Conditionally Anonymous Digital Signatures
Matt Henricksen, Ernest Foo, Ed Dawson |
TrustBus | 3 |
| 2000 | Passive Entities: A Strategy for Electronic Payment Design
Ernest Foo, Colin Boyd |
ACISP | 1 |
| 1999 | Efficient Electronic Cash Using Batch Signatures
Colin Boyd, Ernest Foo, Christopher J. Pavlovski |
ACISP | 2 |
| 1999 | Detachable Electronic Coins
Christopher J. Pavlovski, Colin Boyd, Ernest Foo |
ICICS | 3 |
| 1998 | Off-Line Fair Payment Protocols Using Convertible Signatures
Colin Boyd, Ernest Foo |
ASIACRYPT | 2 |
| 1997 | A taxonomy of electronic cash schemes
Ernest Foo, Colin Boyd, William J. Caelli, Ed Dawson |
SEC | 1 |