VLDB 2026 Research / reviewers in the wild / expert
Robin Doss
dblp:44/6790 · also R. Chellappa Doss, Robin Chellappa Doss, Robin Ram Mohan Doss
· DBLP profile ↗
99ranked-venue papers
9as first author
61since 2021 · last 2026
0000-0001-6143-6850ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 1 first-author · 26 since 2021Computer networks · 34 · 6 first-author · 18 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 5 since 2021Systems, architecture and hardware · 6 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Developing a Decolonial Mindset for Indigenising Computing EducationabstractThe underrepresentation of First Peoples in CE reflects colonial legacies embedded in curricula, pedagogies, and digital infrastructures. This paper introduces the Decolonial Mindset Stack (DMS), a seven-layer framework for educator transformation: Recognition, Reflection, Reframing, Reembedding, Reciprocity, Reclamation, and Resurgence. Grounded in Freirean critical pedagogy and Indigenous methodologies, the DMS aligns with relational lenses of ''About Me,'' ''Between Us,'' and ''By Us.'' It fosters self-reflexivity, relational accountability, and Indigenous sovereignty in CE, reframing underrepresentation as systemic exclusion. The DMS provides both theoretical grounding and pathways for practice, positioning indigenisation not as an endpoint but as a sustained ethical commitment to transformative justice and the co-creation of CE with First Peoples. Jianhua Li 0002, Yin Paradies, Trina Myers, Robin Doss, Armita Zarnegar, Jack Reis |
SIGCSE (1) | 4 |
| 2026 | A review of indirect authentication in LEO satellite networks: Three decades of progressabstractLow Earth Orbit (LEO) satellite networks have become the main differentiator in achieving global connectivity, augmenting terrestrial networks through wider coverage, lower latency, and native integration with 5G/6G, the Internet of Things (IoT), and edge services. However, the expansion of LEO constellations introduces substantial security challenges, mainly ensuring robust authentication under dynamic, resource and bandwidth constrained conditions. In many practical architectures, authentication is performed indirectly, with satellites forwarding verification material to ground infrastructure rather than authenticating autonomously. Despite its prevalence, indirect authentication in LEO networks lacks a dedicated, up-to-date survey and a consistent way to compare designs. This paper reviews 69 indirect authentication protocols published between 1996 and 2024 and introduces a role-based taxonomy that distinguishes relay-based schemes from schemes where satellites provide limited assistance prior to ground-based verification. Each protocol is analysed in terms of architecture, cryptographic approach, security properties, validation practices, and efficiency trade-offs. Emerging directions are also synthesised, including blockchain-based designs, quantum security, physical-layer authentication, and Zero Trust-inspired approaches. The survey consolidates fragmented terminology, clarifies design choices and trade-offs, and highlights open research problems toward scalable authentication for future LEO constellations that reflect operational realities. Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Ad Hoc Networks | 3 |
| 2026 | Early detection and mitigation of cache-based attacks in IoT-NDNabstractNamed Data Networking (NDN) has been identified as a key paradigm for enhancing data-centric communication, particularly in the Internet of Things (IoT) to address the scalability issues in existing solutions. Caching in NDN is a crucial mechanism for improving network performance by reducing latency and conserving bandwidth. However, it also introduces significant security challenges, making the system vulnerable to attacks like Cache Pollution Attacks and Side-Channel Timing Attacks, which can undermine data integrity and lead to denial-of-service scenarios. Traditional caching strategies, such as the Least Recently Used policy, predominantly rely on data usage frequency and often overlook critical factors including content popularity and data freshness. This oversight leaves the cache susceptible to exploitation, as it cannot effectively distinguish between valuable content and malicious requests. This paper proposes a cache management mechanism that integrates metrics such as content popularity and data freshness, facilitating early detection and mitigation of malicious activities while maximizing cache efficiency. Our results demonstrate a 96% success rate in early detection and mitigation, significantly improving the security and reliability of the IoT-NDN ecosystem. Sai Gautam Mandapati, Chathurika Ranaweera 0001, Robin Doss |
Comput. Secur. | 3 |
| 2026 | Mitigating malware prevalence in networks with arbitrary topologies: a Flip-It cyber game approach integrated with epidemic modelingabstractCyber threats have evolved in complexity, aiming at a wide range of sectors using advanced methods and tools. This evolving threat landscape challenges existing cybersecurity frameworks, many of which lack the adaptability to counteract the complex tactics of sophisticated adversaries. Developing robust cyber defense strategies requires simulating dynamic interactions between attackers and defenders across high, moderate, and low-impact scenarios. The Flip-It cyber game serves as an intelligent framework for simulating these interactions, enabling the analysis of adaptive strategies in cybersecurity. This paper aims to address the problem of mitigating malware prevalence in full consideration of attack/defense capabilities in arbitrary network topologies. This paper proposes a sophisticated discrete-time epidemic model to characterize security state transitions over time for all three scenarios within the Flip-It game framework. On this basis, the original problem is modeled as a closed-loop control problem to seek the optimal containment strategy. Deep Reinforcement Learning (DRL) is then used to tackle the problem, generating efficient defense strategies that are well-adapted to changing cybersecurity environments. Numerical simulations based on small-world networks, scale-free networks, and router networks are then carried out to generate corresponding strategies. Additionally, we have evaluated the performance of the proposed method against the State-Of-The-Art (SOTA) in terms of attack/defense objective function, control actions, number of devices under the control of the attacker and defender, stability, execution time, and scalability. This comprehensive approach integrates epidemiological modeling, game theory, and advanced machine learning to effectively tackle the complexities of contemporary cybersecurity threats. • Mitigates malware across low, medium, and high-impact cyberattacks. • Integrates the Flip-It game for attacker-defender dynamic interactions. • Employs DRL to enable adaptive and optimized defense strategies. • Evaluates defense evolution across diverse network topologies. Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Robin Doss, Kon Mouzakis, Rajesh Vasa, Helge Janicke, Ahmed Ibrahim 0002, Ahmed Mohsin, Iqbal H. Sarker, Kristen Moore, Seyit Ahmet Çamtepe, Diksha Goel |
Inf. Sci. | 4 |
| 2026 | Privacy-Preserving Automated Deep Learning for Secure Inference ServiceabstractAutomated deep learning (AutoDL) aims to automatically discover optimal architectures of deep neural networks (DNNs) for secure inference without the studies for time-consuming and error-prone manual design. Privacy concerns have increasingly motivated the studies for privacy-preserving AutoDL (PrivAutoDL), where DNN architectures are searched directly on encrypted data without revealing the client's confidential inputs and well-trained DNN architectures. However, existing studies encounter problems in achieving a balance between provable security and efficiency while avoiding significant degradation of model utility. To tackle these problems, we design a privacy-preserving AutoDL scheme, named 2PCAutoDL, utilizing a two-party (two non-colluding cloud servers) computation model. Based on the two-server model, efficient and secure computation protocols are customized layer by layer to protect DNN models associated with client's data. In particular, we reduce the computational overhead of secure DNN: our optimized protocols achieve$1.34\times \sim 2.05\times$speedup for linear layers and$1.33 \times \sim 45 \times$speedup for non-linear layers, compared to a range of existing secure implementations in the literature. Moreover, our fresh alternative to approximate Softmax avoids the drawbacks of approximating exponential operation and yields slightly higher accuracy under appropriate configurations. The security of 2PCAutoDL is formally analyzed under the semi-honest adversary model. Extensive experiments demonstrate that the searched models from 2PCAutoDL improve the inference accuracy by 0.6% on MNIST and by 0.5% on CIFAR-10 when compared to state-of-the-art (SOTA) PrivAutoDL. Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Xiaoning Liu 0002, Robin Doss |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | Mitigating Insider-Facilitated Advanced Persistent Threat: A Three-Player Differential Game ApproachabstractAdvanced Persistent Threat (APT) presents a significant challenge to the cybersecurity of contemporary organizations. This challenge is further exacerbated when APT actors collaborate with malicious insiders. The involvement of the insider transforms a bilateral adversarial scenario into a triadic strategic interaction, introducing additional layers of complexity in modeling and defense planning. Effective defense against insider-facilitated APT necessitates a comprehensive treatment of two critical aspects: (i) the dynamic strategic interactions among the three players—the defender, the insider, and the APT actor—and (ii) the impact of these interactions on the evolving state of the intranet. However, both dimensions are insufficiently addressed in existing research. To bridge this gap, we first develop an expected state evolution model that captures the real-time influence of the dynamic strategies of the players on the expected compromise state of the intranet. Building upon this, we formulate a three-player differential game model that explicitly incorporates the dynamic interactions of all participants. The associated optimality system is derived and numerically solved using a proposed iterative algorithm. The proposed algorithm achieves a 27.5% improvement in the organization’s expected payoff compared to baseline permissible strategies. Subsequently, we analyze key properties of the proposed framework and empirically evaluate the cost-effectiveness of the resulting defense strategy. To the best of our knowledge, this work represents the first application of three-player differential game theory in the domain of cybersecurity, offering a novel approach to defending against insider-facilitated APT. Lu-Xing Yang, Xiaofan Yang 0001, Gang Li 0009, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | sf SEBioID: Secure and Efficient Biometric Identification with Two-Party Computation
Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss, Jianying Zhou 0001 |
ACNS (3) | 6 |
| 2025 | Implementing A Dynamic and Context-Aware Trust Evaluation Model for Zero Trust Architecture (ZTA): A Fuzzy Logic ApproachabstractEmerging technologies such as the Internet of Things, cloud computing, and big data have rendered traditional perimeter-based security solutions inadequate against today’s sophisticated cyber-attacks. Zero Trust Architecture (ZTA), in contrast to traditional architectures, enforces strict access control and verification for every access request Continuous trust evaluation is the core of this security architecture, where no network entity is implicitly trusted, regardless of its location. This research proposes a dynamic and context-aware trust evaluation model that employs fuzzy logic to calculate the trust score within ZTA. The model incorporates real-time contextual data, such as location, time, duration of connection, and usage, along with the user’s previous trust score, to provide a more accurate and responsive trust evaluation. A ZTA testbed was implemented to generate data and evaluate the model. The results show that the model is highly responsive to behavioral changes, achieving a precision of 98.7%, a recall rate of 99.7%, and an F1-Score of 99.1%. Furthermore, the model demonstrated good performance with a variety of concurrent connections, indicating its scalability potential in real-time security applications. Sanaz Amanlou, Robin Doss |
IWCMC | 2 |
| 2025 | Poster: BlockFL-Med: Blockchain-Enabled and Lightweight Federated Learning for Smart Medical SpacesabstractWe propose a blockchain-enabled lightweight federated learning (BlockFL-Med) framework tailored for smart medical spaces, e.g., the Internet of Medical Things (IoMT), addressing key challenges, e.g., privacy preservation, trust management, and scalability. The framework ensures the privacy of sensitive patient data by employing federated learning, where only model updates are shared instead of raw data. To enhance trust, the framework integrates blockchain technology, creating a decentralized and tamper-proof network that verifies client contributions and mitigates risks from malicious participants. Experimental results demonstrate the scalability and efficiency issues by optimizing communication costs, e.g., transmitting lightweight kilobyte-sized model updates instead of larger megabyte-sized models, making it well-suited for heterogeneous and resource-constrained IoMT environments. Shantanu Pal, Saifur Rahman 0002, Robin Doss, Chandan K. Karmakar |
MobiCom | 3 |
| 2025 | Integrating Threat Analysis and Formal Verification for Secure OTA UpdatesabstractThe automotive industry increasingly relies on Over-the-Air (OTA) updates to deliver essential security patches to vehicles. However, this dependence may introduce significant cy-bersecurity vulnerabilities, particularly concerning the integrity and privacy of updates. This paper presents an integrated framework that combines threat modeling and formal verification by employing an identical system model across all stages. The process begins with applying the ThreatGet tool to identify potential threats in the OTA update process, which directly guide the formulation of formal security requirements expressed as Computation Tree Logic (CTL) properties. The same high-level model encompassing a Cloud Server (CS), Telematics Control Unit (TCU), Central Gateway Unit (CGU), Advanced Driver Assistance System (ADAS) module, and an attacker module is consistently used for both threat modeling and encoding in the NuSMV model checker. This unified approach ensures that identified threats translate seamlessly into verifiable properties. Experimental threat analysis and verification results demonstrate the effectiveness of our integrated approach in uncovering OTA update vulnerabilities properties. Sheraz Mazhar, Abdur Rakib, Robin Doss, Adnan Anwar, Frank Jiang 0001 |
PRDC | 3 |
| 2025 | Enhancing Physical Security in Smart Environments with Ambient IntelligenceabstractSmart environments are increasingly equipped with interconnected digital systems to manage access and physical security. However, traditional authentication methods, typically restricted to static checkpoints, fail to provide persistent assurance once entry is granted, leaving facilities vulnerable to credential misuse, tailgating, and unauthorised movement. This paper presents the Continuous Authentication Platform (CAP), a modular, multi-modal framework developed within the RAAISE project to enable continuous and context-aware verification across dynamic facility zones. CAP integrates heterogeneous off-the-shelf sensors, including NFC, RFID, biometric, motion, and WiFi positioning units, which collectively support persistent user tracking and real-time access enforcement. The platform’s architecture couples distributed sensing and edge processing with a centralised intelligence layer for event correlation and policy-driven decision-making. A live testbed deployment at Deakin University was used to evaluate CAP’s performance under realistic operational conditions. Results from functional trials demonstrate CAP’s ability to detect credential misuse, prevent tailgating, and maintain authentication continuity with sub-second responsiveness. These findings underscore CAP’s potential as a scalable, privacy-aligned foundation for next-generation smart facility security systems. Ashish Nanda, Robin Doss, Fokke Heikamp, Abhi Kumar, Haftu Tasew Reda, Adnan Anwar, Zubair A. Baig, Praveen Gauravaram, Debi Prasad Pati, Salil S. Kanhere, Mohan Baruwal Chhetri |
TrustCom | 2 |
| 2025 | CAMP in the Odyssey: Provably Robust Reinforcement Learning with Certified Radius Maximization
Derui Wang, Kristen Moore, Diksha Goel, Minjune Kim, Gang Li 0009, Yang Li 0182, Robin Doss, Minhui Xue 0001, Bo Li 0026, Seyit Ahmet Çamtepe, Liming Zhu 0001 |
USENIX Security Symposium | 7 |
| 2025 | Zero trust-based authentication for Inter-Satellite Links in NextGen Low Earth Orbit networksabstractNext Generation (NextGen) Low Earth Orbit satellite networks are rapidly expanding to support global communication and 6G technology transition. This growth exposes networks to new security challenges due to wide coverage in hostile areas and increased access points in space and on Earth. Traditional static authentication methods prove inadequate in this dynamic environment. We address these challenges by developing a Zero Trust Authentication Protocol for Inter-Satellite Link (ISL) communication. Our protocol implements a novel verification process that leverages orbital signals to authenticate ISLs. This approach ensures secure data access and transmission exclusively among verified satellites, mitigating threats from eavesdropping, signal spoofing, impersonation, and replay attacks. To optimize security and resource efficiency, we integrate Hyperelliptic Curve Cryptography (HECC) into our protocol. We validate our approach through MATLAB and Systems Tool Kit (STK) simulations, complemented by BAN Logic and Scyther analyses. Our findings demonstrate that our protocol enhances the security framework of NextGen LEO networks without compromising their performance or operational capabilities. Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Ad Hoc Networks | 3 |
| 2025 | RAD-IoMT: Robust adversarial defence mechanisms for IoMT medical image analysisabstractThe Internet of Medical Things (IoMT) represents a significant technological advancement with exceptional capabilities across various domains, particularly in healthcare. IoMT integrates medical devices, software applications, and healthcare systems, enabling seamless communication and data exchange over the Internet. As deep learning (DL) continues to evolve, applications within IoMT are increasingly dominant. However, these DL applications face new reliability challenges, particularly due to the security threat posed by adversarial attacks. These attacks introduce subtle and often imperceptible perturbations that can lead to significantly erroneous predictions by classifiers. To address these reliability concerns, we propose a novel security mechanism using an attack detector specifically designed to counter adversarial attacks within IoMT environments. This approach leverages a transformer model to enhance resistance against such attacks. We validate our method through experiments using datasets for skin cancer, retina damage, and chest X-rays, testing against both white-box attacks (e.g., Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD)) and black-box attacks (e.g., Additive Gaussian Noise (AGN) and Additive Uniform Noise (AUN)). Our proposed attack detector exhibited F1 and accuracy 0.91 and 0.94. Following the successful application of our attack detector, the disease classification model achieved an average F1 and accuracy of 0.97 and 0.98 compared to the attack model performance (F1 and accuracy of 0.64 and 0.60, respectively) across the three datasets. Saifur Rahman 0002, Shantanu Pal, Amir Mohammad Fallah, Robin Doss, Chandan K. Karmakar |
Ad Hoc Networks | 4 |
| 2025 | Securing ICS networks: SDN-based Automated Traffic Control and MTD Defensive Framework against DDoS attacksabstractIndustrial Control Systems (ICS) are increasingly targeted by distributed denial-of-service (DDoS) attacks, posing significant risks to system availability and reliability. This research proposes a novel defensive framework for ICS networks based on Software-Defined Networking (SDN). The main objectives are to enhance resilience against DDoS attacks and maintain critical system functions. Our framework combines automated traffic control (ATC) to filter and bypass malicious traffic dynamically, and Moving Target Defense (MTD) techniques such as proactive IP shuffling and network redundancy to protect critical nodes. Experimental results show that the proposed approach effectively reduces CPU load, improves round-trip time (RTT), and lowers packet drop rate (PDR) during DDoS scenarios. These findings demonstrate that integrating SDN-based ATC and MTD strategies can significantly strengthen ICS security and ensure system availability, providing a robust solution for critical infrastructure protection. Xingsheng Qin, Robin Doss, Frank Jiang 0001, Xingguo Qin, Biyue Long |
Comput. Commun. | 2 |
| 2025 | RansoGuard: A RNN-based framework leveraging pre-attack sensitive APIs for early ransomware detectionabstractRansomware has emerged as a significant security threat in cyberspace, inflicting severe economic losses and privacy breaches on individual users and organizations. Ransomware typically encrypts critical user files and demands a ransom for decryption. Traditional signature-based defense methods effectively identify known ransomware but perform poorly when confronting unknown zero-day attacks. Addressing this challenge, a ransomware detection framework called ‘RansoGuard’ is proposed. This framework aims to achieve timely identification and defense against ransomware by capturing and analyzing the sensitive Application Programming Interface (API) call behavior exhibited before the encryption attack is launched. A real-world ransomware sample dataset was constructed. The dynamic behavioral data during the pre-attack stage was analyzed, and natural language processing techniques were used to represent and extract key features from API call sequences. A Recurrent Neural Network (RNN) classifier was trained on these features to distinguish ransomware from benign software. Experimental results demonstrate that the RansoGuard framework exhibits outstanding early ransomware detection performance across different datasets, achieving a recall of 96.18% and an accuracy of 94.26%. Furthermore, it exhibits robustness in effectively countering zero-day attacks. Mingcan Cen, Frank Jiang 0001, Robin Doss |
Comput. Secur. | 3 |
| 2025 | Quantum-Powered Extended Visibility for Zero-Trust-Based Ransomware Detection in Smart GridsabstractTechnological evolution in the Industrial Internet of Things (IIoT) domain has fostered smart grid systems’ operation, performance, connectivity, and delivery with higher efficiency. However, it has also exposed the platform to a broader surface for attackers. Current information technology (IT)-centric solutions for detecting, preventing, and mitigating attacks have limitations, especially in comprehensively monitoring industrial control operational technology (OT) and communication systems. The rise of sophisticated cyberattacks, such as targeted ransomware, demand more robust security measures, leading to the emergence of zero trust (ZT) deployment as a response to these threats. This article proposes a new framework for implementing ZT comprising both IT and OT in smart grid infrastructures, with multiple security mechanisms and robust system coverage. We present an EigenGame algorithm for integrating diverse data sources into a rich-context format and an enhanced approach to quantum reinforcement learning for reliable malicious behavior detection in IIoT-enabled smart grids. The framework was evaluated using five sets of data from the X-IIoTID dataset, demonstrating its good performance in verifying any behavior inside the system and identifying any malicious behavior related ransomware attacks. Muna Al-Hawawreh, Omar Shindi, Zubair A. Baig, Mamoun Alazab, Adnan Anwar, Robin Doss |
IEEE Internet Things J. | 6 |
| 2025 | Toward Decentralized Operationalization of Zero Trust Architecture for Next Generation NetworksabstractNext-generation networks demand security that evolves as fast as threats do. Our pioneering decentralized Zero Trust Architecture (dZTA), proposed in this paper, redefines protection for IoT and remote collaboration, merging Zero Trust’s ironclad access controls with blockchain’s transparency and federated learning’s privacy-first analytics. Unlike traditional models, dZTA enforces security at every layer: a distributed policy engine eliminates single points of failure, cross-network analytics optimize WiFi-8, satellite, and 6G performance under real-world stressors, and anti-leakage protocols safeguard IoT ecosystems. Rigorous real-world simulations confirm dZTA’s dual triumph—uncompromising security and seamless efficiency— proving its readiness to secure tomorrow’s hyperconnected world. Shiva Raj Pokhrel, Gang Li 0009, Robin Doss, Surya Nepal |
IEEE J. Sel. Areas Commun. | 3 |
| 2025 | MedShield: A Fast Cryptographic Framework for Private Multi-Service Medical DiagnosisabstractThe substantial progress in privacy-preserving machine learning (PPML) facilitates outsourced medical computer-aided diagnosis (MedCADx) services. However, existing PPML frameworks primarily concentrate on enhancing the efficiency of prediction services, without exploration into diverse medical services such as medical segmentation. In this paper, we proposeMedShield, a pioneering cryptographic framework for diverse MedCADx services (i.e., multi-service, including medical imaging prediction and segmentation). Based on a client-server (two-party) setting,MedShieldefficiently protects medical records and neural network models without fully outsourcing. To execute multi-service securely and efficiently, our technical contributions include: 1) optimizing computational complexity of matrix multiplications for linear layers at the expense of free additions/subtractions; 2) introducing a secure most significant bit protocol with crypto-friendly activations to enhance the efficiency of non-linear layers; 3) presenting a novel layer for upscaling low-resolution feature maps to support multi-service scenarios in practical MedCADx. We conduct a rigorous security analysis and extensive evaluations on benchmarks (MNIST and CIFAR-10) and real medical records (breast cancer, liver disease, COVID-19, and bladder cancer) for various services. Experimental results demonstrate thatMedShieldachieves up to$2.4\times$,$4.3\times$, and$2\times$speed up for MNIST, CIFAR-10, and medical datasets, respectively, compared with prior work when conducting prediction services. For segmentation services,MedShieldpreserves the precision of the unprotected version, showing a$1.23\%$accuracy improvement. Fuyi Wang, Jinzhi Ouyang, Xiaoning Liu 0002, Lei Pan 0002, Leo Yu Zhang, Robin Doss |
IEEE Trans. Serv. Comput. | 6 |
| 2024 | Towards Availability of Strong Authentication in Remote and Disruption-Prone Operational Technology EnvironmentsabstractImplementing strong authentication methods in a network requires stable connectivity between the service providers deployed within the network (i.e., applications that users of the network need to access) and the Identity and Access Management (IAM) server located at the core segment of the network. This becomes challenging when it comes to Operational Technology (OT) systems deployed in a remote area, as they often get disconnected from the core segment of the network owing to unavoidable network disruptions. As a result, weak authentication methods and shared credential approaches are still adopted in these OT environments, exposing system vulnerabilities to increasingly sophisticated cyber threats. In this work, we propose a solution to enable highly available multi-factor authentication (MFA) services for OT environments. The proposed solution is based on Proof-of-Possession (PoP) tokens generated by an IAM server for registered users. The tokens are securely linked to user-specific parameters (e.g., physical security keys, biometrics, PIN, etc.), enabling strong user authentication (during disconnection time) through token validation. We deployed the Tamarin Prover software-based toolkit to verify security of the proposed authentication scheme. For performance evaluation, we implemented the designed solution in real-world settings. The results of our analysis and experiments confirm the efficacy of the proposed solution. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Divyans Mahansaria, Debi Prasad Pati, Praveen Gauravaram, Lei Pan 0002, Keshav Sood |
ARES | 3 |
| 2024 | POSTER: Addressing the Privacy by Use Challenges in Verifiable Credential based Digital WalletsabstractThe concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity. However, the inability of users to make optimal decisions in relation to the use of VC results in privacy risks. To address this gap in VC technology, we present game-theoretic models for optimising the privacy of users and simultaneously ensuring minimum disclosure of PII in line with privacy safeguards around CDR and GDPR expectations around anonymity and unlinkability and demonstrate these properties through a digital credential wallet (DCW). The developed technology will deliver a novel DCW which embeds decision-making ability to quantify, benchmark and recommend the optimal usage of credentials that are held within the DCW. Jongkil Jeong, Lu-Xing Yang, Robin Doss, Praveen Gauravaram, Zoe Wang, Mohamed Almorsy, Ashish Nanda, Keerthivasan Viswanathan |
AsiaCCS | 3 |
| 2024 | TrustMIS: Trust-Enhanced Inference Framework for Medical Image SegmentationabstractRecent advancements in privacy-preserving deep learning (PPDL) enable artificial intelligence-assisted (AI-assisted) medical image diagnostics with privacy guarantees, addressing increasing concerns about data and model privacy. However, intensive studies are restricted to shallow and narrow neural networks (NNs) for simple service (e.g., disease prediction), leaving a gap in exploring diverse inferences. This paper proposes TrustMIS, a trust-enhanced inference framework for fast and private medical image segmentation (MIS) and prediction services. Based on two-party computation, TrustMIS introduces lightweight additive secret-sharing tools to safeguard medical records and NNs. Complementing existing PPDL schemes, we present a series of secure two-party interactive protocols for linear layers. Specifically, we optimize the secure matrix multiplication by reducing the number of expensive multiplication operations with the help of free-computation addition operations to enhance efficiency (bringing 1.15× ∼2.64× savings in both time and communication costs). Furthermore, we customize a fresh secure transposed convolutional protocol for MIS-oriented NNs. A thorough theoretical analysis is provided to prove TrustMIS’s correctness and security. We conduct experimental evaluations over two benchmark and four real-world medical datasets and compare them to state-of-the-art studies. The results demonstrate TrustMIS’s superiority in efficiency and accuracy, improved by 1.1× ∼ 54.4× speedup in secure disease prediction, and 5.56% ↑ ∼ 11.7% ↑ accuracy in secure MIS. Fuyi Wang, Jinzhi Ouyang, Lei Pan 0002, Leo Yu Zhang, Xiaoning Liu 0002, Robin Doss |
ECAI | 7 |
| 2024 | User perceptions of algorithmic persuasion in OTT platforms: A scoping reviewabstractData-driven algorithms are used in over-the-top streaming applications to provide users with a personalised viewing experience. Users and policy makers are concerned about the deliberate use of these algorithms to influence beliefs, attitudes and behaviours i.e. algorithmic persuasion. However, there has been more focus on improving recommendation accuracy and user-focused research in this area is limited. This scoping review seeks to map existing studies on user perceptions of algorithmic persuasion in OTT streaming platforms. By examining available evidence, the study assesses the extent of existing knowledge and potential gaps. Three databases were searched for studies published in English between 2007 and 2024. Included studies were qualitative studies containing direct quotations from participants where they described their perceptions and experiences of algorithmic persuasion in OTT streaming platforms. 12 studies were identified for the final review. User quotations were coded and analysed to extract themes relevant to the research question. Negative perceptions were centered around loss of autonomy, problematic viewing behaviour, lack of content diversity and lack of control over persuasive elements. Users have an awareness of how their behaviour affects recommendations and they acknowledge the conveniences afforded by algorithmic curation. However, they are also concerned about data collected by platforms. Findings reveal a need for platforms to address user concerns about their privacy, autonomy and need for control. Results also indicate that there is a need for more in-depth studies to further understanding of user interactions with persuasive algorithms in streaming platforms. Ronald Svondo Nyathi, Sophie McKenzie, Jianhua Li 0002, Radhika Gorur, Robin Doss |
ISTAS | 5 |
| 2024 | The Value of Strong Identity and Access Management for ICS/OT SecurityabstractAs the integration of digital technologies with Industrial Control Systems (ICS) and Operational Technology (OT) continues to deepen, these systems increasingly become targets for sophisticated cyber attacks. These attacks not only threaten the operational integrity but also pose significant risks to national security and public safety. In this paper, we provide insights into the value of ICS/OT security solutions that are based on Identity and Access Management (IAM). Beginning with presenting an abstraction model for typical ICS/OT attacks, the paper systematically outlines the main stages of an attack and the corresponding vectors employed by adversaries. Drawing from the MITRE ATT&CK framework tailored for ICS, the paper quantifies the extent to which IAM-based mitigation approaches can strengthen defense-in-depth mechanisms against cyber threats targeting ICS/OT environments. Our findings show that there are modern attack vectors that can only be mitigated through robust IAM solutions. Moreover, we found that while advanced techniques such as firewall and gateway-based intelligent threat detection play a significant role in safeguarding I CS/OT, they are insufficient on their own to address several attack vectors in ICS/OT environments. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Praveen Gauravaram, Debi Prasad Pati, Divyans Mahansaria, Keshav Sood, Lei Pan 0002 |
PST | 3 |
| 2024 | Ransomware early detection: A surveyabstractIn recent years, ransomware attacks have exploded globally, and it has become one of the most significant cyber threats to digital infrastructure. Such attacks have been targeting ranging from individuals to critical infrastructure or large organizations such as large commercial companies, energy facilities, medical centers and government departments. Ransomware attackers use sophisticated encryption techniques to hijack victims’ files in exchange for a large ransom to release encrypted data. Sophisticated encryption techniques make it almost impossible for victims to recover data without the secret key in the event of such an attack. To protect systems from ransomware threats, malicious activities had better be detected earlier, preferably before they engage in the harmful behavior. Numerous studies have focused on ransomware threats and attempted to provide detection and prevention solutions for ransomware attacks, but none of the surveys explored the early detection of ransomware and highlighted challenges and issues with existing solutions. This survey fills this gap and provides a state-of-the-art overview of research on the ransomware early detections. Moreover, we investigate the latest ransomware surveys and give an overview of the categories of ransomware from different perspectives, the evolution and attack process of ransomware, and provide datasets used for ransomware detection. Finally, the possible future research directions are discussed. Mingcan Cen, Frank Jiang 0001, Xingsheng Qin, Qinghong Jiang, Robin Doss |
Comput. Networks | 5 |
| 2024 | Provably secure optimal homomorphic signcryption for satellite-based internet of things
Kerry Anne Farrea, Zubair A. Baig, Robin Doss, Dongxi Liu |
Comput. Networks | 3 |
| 2024 | CGAN-based cyber deception framework against reconnaissance attacks in ICSabstractIn recent years, Industrial Control Systems (ICSs) have faced increasing vulnerability to cyber attacks due to their integration with the Internet. Despite efforts to enhance cybersecurity, reconnaissance attacks remain a significant threat, prompting the need for innovative defensive strategies. This paper introduces a novel approach to strengthen the defensive capabilities of ICS networks against reconnaissance attacks using machine learning-driven cyber deception techniques. Leveraging Conditional Generative Adversarial Networks (CGANs), the proposed framework dynamically generates defensive network topologies to network shuffling and implement deception strategies, prioritizing system availability. Extensive simulations demonstrate the superior efficacy of the proposed framework in enhancing cybersecurity while minimizing computational overhead. By effectively mitigating reconnaissance attacks, this solution reinforces the resilience of ICS networks, safeguarding critical industrial infrastructure from evolving cyber threats. These findings underscore the significance of adopting machine learning-based cyber deception as a pragmatic security measure for protecting ICS networks in real-world industrial contexts. Xingsheng Qin, Frank Jiang 0001, Xingguo Qin, Lina Ge, Meiqu Lu, Robin Doss |
Comput. Networks | 6 |
| 2024 | Zero-Ran Sniff: A zero-day ransomware early detection method based on zero-shot learningabstractRansomware attacks, which blackmail victims into paying a ransom by locking their devices or encrypting their files, have become one of the major threats to network security. Conventional anti-ransomware tools often fail to detect zero-day ransomware attacks due to the inability to obtain zero-day ransomware signatures in advance to train detection models. In addition, zero-day ransomware attacks often use sophisticated encryption techniques to launch attacks on new vulnerabilities, and these encryption attacks cause irreversible damage to victims' digital files even if they choose to pay a ransom. It is therefore urgent and important to identify unknown ransomware attacks as early as possible, i.e. before the stage of encryption. To this end, this paper proposes Zero-Ran Sniff (ZRS), an early zero-day ransomware detection method based on zero-shot learning, which can detect zero-day ransomware attacks in the early stage. ZRS leverages the portable executable header (PE header) feature from executable files to identify ransomware. It comprises two stages: an auto-encoding network-based core attribute learning (AE-CAL) stage and a self-attentive mechanism-based convolutional neural network inference Stage (SA-CNN-IS). During the AE-CAL stage, the core features of known and unknown classes of ransomware are extracted using self-encoding networks, and the SA-CNN-IS phase identifies ransomware. To the best of our knowledge, we are the first to explore the use of zero-shot learning for zero-day ransomware early detection. Experimental results demonstrate that the proposed ZRS outperforms traditional machine learning methods. Compared to previous zero-day detection work, ZRS achieves a recall of 98.47% and an accuracy of 96.31% Mingcan Cen, Xizhen Deng, Frank Jiang 0001, Robin Doss |
Comput. Secur. | 4 |
| 2024 | Examining usable security features and user perceptions of Physical Authentication DevicesabstractDespite the enhanced security benefits offered by Physical Authentication Devices (PADs) compared to other forms of Multi-Factor Authentication (MFA), the adoption and retention of PADs remain relatively low in comparison to other MFA methods. Evidence indicates that the limited widespread adoption and usage of PADs are primarily due to negative user perceptions concerning their usability and security features. Moreover, there's a limited understanding of how users from diverse backgrounds perceive PADs with their varying standards and features. To bridge this knowledge gap, we undertook a multiple case study with 23 users spanning varied demographic characteristics (age, gender, education, and experience with MFA) to use and test three distinct PADs. Case study participants were provided with three unique PAD devices featuring different characteristics/features and were prompted to share their experiences of installation, usage, and troubleshooting over a 2-week span via an initial questionnaire, logbook, and a final interview. The gathered data were analysed using NVIVO, a Qualitative Research Software platform, uncovering notable disparities between user groups and their predilections for specific PADs. Further discussions from our research illuminate four primary areas (Compatibility, Support, Quality and Simplicity) where usable security features impede positive user perception of PAD devices and addressing these areas is crucial for enhancing PAD adoption and retention rates. Ashish Nanda, Jongkil Jeong, Syed Wajid Ali Shah, Mohammad Reza Nosouhi, Robin Doss |
Comput. Secur. | 5 |
| 2024 | A hybrid cyber defense framework for reconnaissance attack in industrial control systemsabstractThe convergence of information technology (IT) and operation technology (OT) has made Industrial Control Systems (ICS) a popular target for cyberattacks in recent years. Unlike traditional networks, enhancing availability is the ICS network's top priority rather than confidentiality in the CIA scheme. We propose a bio-inspired adaptive defense framework based on dissimilar redundancy, diversity, and adaptive defense strategies to achieve this aim. The proposed mechanism mixed optimal network shuffling and cyber deception techniques to maximise the time attackers spend on the decoys. Besides, to provide an extra layer of protection for system availability, we introduce dual heterogeneous subnets in the proposed framework that could be regenerated once compromised. We evaluate the performance of the proposed defense framework in a typical industrial manufacturing network using an SDN-based platform and test the defense framework in various scenarios. Compared with previous research, the simulation shows a considerable improvement in defense performance in the adaptive defense mode. Xingsheng Qin, Frank Jiang 0001, Chengzu Dong, Robin Doss |
Comput. Secur. | 4 |
| 2024 | User Characteristics and Their Impact on the Perceived Usable Security of Physical Authentication DevicesabstractPhysical authentication devices (PADs) offer a higher level of security than other authentication technologies commonly used in multifactor authentication (MFA) schemes because they are much less vulnerable to attack. However, PAD uptake remains significantly lower than that for SMS and app-based approaches, accounting for only 10% of all authentication technologies currently being utilized in MFA. Prior studies indicate that the primary reason for this low adoption rate is due to negative users' perceptions and attitudes toward the usability of PADs; many of these studies often skew toward a particular set of users (e.g., young university students, etc.), often creating a bias toward what usable security entails. To address this limitation, we have formulated an original research methodology that segments users into specific groups based on their user characteristics (i.e., age, education, and experience) and examines how each group defines usability and ranks their preferences regarding certain security features. Based on a survey of 410 participants, our results indicate that there are indeed different usable security preferences for each user group, and we, therefore, provide recommendations on how existing PADs might be enhanced to support usability and improve adoption rates. Jongkil Jeong, Syed Wajid Ali Shah, Ashish Nanda, Robin Doss, Mohammad Reza Nosouhi, Jeb Webb |
IEEE Trans. Hum. Mach. Syst. | 4 |
| 2023 | Misbehaviour Detection for Smart Grids using a Privacy-centric and Computationally Efficient Federated Learning ApproachabstractFederated Learning (FL)-based Intrusion Detection Systems (IDSs) have recently surfaced as viable privacy-preserving solution to decentralized grid zones. However, conventional synchronous FL methods face technical challenges including the lack of consideration of communication delays and straggler nodes. To level the playing field, we propose a novel power system misbehaviour detection framework that leverages semi-asynchronous federated learning and dynamic aggregation. Specifically, our framework introduces an adaptive learning rate mechanism in the semi-asynchronous FL setting, allowing for efficient model updates and mitigating the impact of stragglers on the training process. Experiments conducted on publicly available Mississippi State University and Oak Ridge National Laboratory Power System Attack (MSU-ORNL PSA) Dataset demonstrate that our adaptive learning semi-asynchronous FL framework achieves superior attack detection rate while safeguarding data confidentiality and minimizing the negative effects of practical world communication latency and straggler nodes. Furthermore, our proposed method shows a significant 40% improvement in training time compared to conventional synchronous FL methods, showcasing the effectiveness and efficiency of our recommended approach. Muhammad Akbar Husnoo, Adnan Anwar, Nasser Hosseinzadeh, Robin Doss, Biplab Sikdar 0001 |
GLOBECOM | 4 |
| 2023 | Enhancing Security in Industrial IoT: A Taxonomy-driven Approach to Risk AssessmentabstractThe Industrial Internet of Things (IIoT) embodies the emerging fourth revolution, which strongly focuses on Machine-to-Machine (M2M) communications, big data, and predictive analytics. One of the major challenges associated with this deployment is physical and cyber security, as new emerging devices and technology have paved the way for new threat vectors, and current security measures have a limited endpoint focus and are inadequate to accommodate the broad scale of these emerged complex and distributed IIoT systems. To create secure and safe IoT systems, a comprehensive risk assessment that can span the entire physical and cyber stack of IIoT systems is needed. In this article, we investigate the current risk assessment frameworks, discuss their strengths and challenges, and show that current frameworks do not sufficiently work for IIoT deployments. We subsequently present a novel security taxonomy to supplement and address existing assessment frameworks' challenges. We validate this proposed taxonomy with extensive recent research literature. Muna Al-Hawawreh, Robin Doss |
TrustCom | 2 |
| 2023 | Hybrid cyber defense strategies using Honey-X: A survey
Xingsheng Qin, Frank Jiang 0001, Mingcan Cen, Robin Doss |
Comput. Networks | 4 |
| 2023 | False data injection threats in active distribution systems: A comprehensive survey
Muhammad Akbar Husnoo, Adnan Anwar, Nasser Hosseinzadeh, Shama Naz Islam, Abdun Naser Mahmood, Robin Doss |
Future Gener. Comput. Syst. | 6 |
| 2023 | Weak-Key Analysis for BIKE Post-Quantum Key Encapsulation MechanismabstractThe evolution of quantum computers poses a serious threat to contemporary public-key encryption (PKE) schemes. To address this impending issue, the National Institute of Standards and Technology (NIST) is currently undertaking the Post-Quantum Cryptography (PQC) standardization project intending to evaluate and subsequently standardize the suitable PQC scheme(s). One such attractive approach, called Bit Flipping Key Encapsulation (BIKE), has entered the final round of the competition. Despite having some attractive features, the IND-CCA security of BIKE depends on the average decoder failure rate (DFR), a higher value of which can facilitate a particular type of side-channel attack. Although BIKE adopts the Black-Grey-Flip (BGF) decoder that offers a negligible DFR, the effect of weak-keys on the average DFR has not been fully investigated. In this paper, we implement the BIKE scheme, and then through extensive experiments show that the weak-keys can be a potential threat to IND-CCA security of the BIKE scheme and thus need attention from the relevant research community. We also propose a key-check algorithm that can potentially supplement the BIKE mechanism and prevent users from adopting weak-keys. Mohammad Reza Nosouhi, Syed Wajid Ali Shah, Lei Pan 0002, Yevhen Zolotavkin, Ashish Nanda, Praveen Gauravaram, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Intrusion Detection Scheme With Dimensionality Reduction in Next Generation NetworksabstractDue to millions of heterogeneous physical nodes, multiple-vendor and multi-tenant domains, and technologies etc., 5G has greatly expanded the threat landscape. Particularly from the high rate of traffic and ultra-low latency requirement of applications in 5G networks, the detection of the network traffic anomalies in real-time is critical. The conventional security approaches lack compatibility with modern network designs and are not much effective in 5G settings. We propose a two-stage network traffic anomaly detection system compatible with ETSI-NFV standard 5G architecture. Our architecture consists of two modules, i.e., (a) Dimensionality Reduction to compress the sample size at the edge of 5G networks and (b) Deep Neural Network classifier (DNN) that detects traffic anomalies. We have conducted our experiments using OMNET++ and ETSI-NFV (OSM MANO) 5G orchestration real platform deployed on AWS cloud systems. We have used the UNSW-NB15 data set and have shown that at dimensionality reduction factor of 81% the detection accuracy obtained is 98%. The proposal is compared with other recent approaches to show the overall merit of the architecture. Keshav Sood, Mohammad Reza Nosouhi, Dinh Duc Nha Nguyen, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Performance Evaluation of a Novel Intrusion Detection System in Next Generation NetworksabstractThe integration of Internet of Things (IoT) with 5G simply creates additional threat landscape and any network infrastructure is more vulnerable. Severe attacks on networks potentially damage organization reputation, customers or tenants lose confidence, and impacts operational and maintenance cost. Intrusion detection systems (IDSs) are an effective approach to mitigate threats. We present a novel IDS mechanism in which the unique Radio Frequency (RF) features of IoT devices are used to create a learning model which is later used to identify the illegitimate devices in the network. Leveraging the Deep Autoencoder (DAE), the existing steady-state feature extraction is generalized. The performance evaluation is conducted using a real data set from different aspects including the mobility of the nodes. The proposed IDS is broken down into pluggable virtual network function (VNF) components and its evaluation is presented for its integration into the 5G network slicing ecosystem from the perspective of the European Telecommunications Standards Institute (ETSI) standards. A Proof of Concept (PoC) is presented using ETSI Open Source NFV Management and Orchestration (OSM-MANO) test bed, deployed on AWS cloud systems, to show how the proposed approach would fit in with a real-life MANO. Keshav Sood, Dinh Duc Nha Nguyen, Mohammad Reza Nosouhi, Neeraj Kumar 0001, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2022 | Cyber Attack Detection in IoT Networks with Small Samples: Implementation And Analysis
Venkata Abhishek Kanthuru, Sutharshan Rajasegarar, Punit Rathore, Robin Doss, Lei Pan 0002, Biplob R. Ray, Morshed Chowdhury, Chandrasekaran Srimathi, M. A. Saleem Durai |
ADMA (1) | 4 |
| 2022 | A Compressed Sensing Based Image Compression-Encryption Coding Scheme without Auxiliary Information TransmissionabstractFacing the explosive growth of image data, how to realize low-cost compression coding and how to protect the confidentiality of image data have become two important research topics. In this work, a novel image coding scheme is proposed, which combines compression and encryption under the framework of compressed sensing (CS). Firstly, the signal is sampled using CS, then normalized and quantified. Next, according to the statistical characteristic of the measurements, the partially quantized measurements are selected for single-valued diffusion, and at the same time the auxiliary information, including the energy information and the quantization parameters, are automatically embedded. In contrast to other existing schemes, our scheme simultaneously achieves two security objectives: one is avoiding energy leakage in CS-based cryptosystem; the other is resisting Chosen Plaintext Attack (CPA). Furthermore, without transmitting the auxiliary information, the receiver can perform decryption correctly. Experimental results and analysis also demonstrate the effectiveness and security of the proposed scheme. Di Xiao 0001, Yong Xiang 0001, Robin Doss |
ICC | 4 |
| 2022 | A Generic Enhancer for Backdoor Attacks on Deep Neural Networks
Bilal Hussain Abbasi, Leo Yu Zhang, Shang Gao 0003, Antonio Robles-Kelly, Robin Doss |
ICONIP (7) | 6 |
| 2022 | Towards Privacy-Preserving Neural Architecture SearchabstractMachine learning promotes the continuous development of signal processing in various fields, including network traffic monitoring, EEG classification, face identification, and many more. However, massive user data collected for training deep learning models raises privacy concerns and increases the difficulty of manually adjusting the network structure. To address these issues, we propose a privacy-preserving neural architecture search (PP-NAS) framework based on secure multi-party computation to protect users' data and the model's parameters/hyper-parameters. PP-NAS outsources the NAS task to two non-colluding cloud servers for making full advantage of mixed protocols design. Complement to the existing PP machine learning frameworks, we redesign the secure ReLU and Max-pooling garbled circuits for significantly better efficiency (3 ~ 436 times speed-up). We develop a new alternative to approximate the Softmax function over secret shares, which bypasses the limitation of approximating exponential operations in Softmax while improving accuracy. Extensive analyses and experiments demonstrate PP-NAS's superiority in security, efficiency, and accuracy. Fuyi Wang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss |
ISCC | 5 |
| 2022 | The First International Workshop on Cryptographic Security and Information Hiding Technology for IoT System (CSIHTIS 2022): PrefaceabstractThis Special Collection aims at seeking original articles with novel perspectives and solutions to address the cryptographic security and information hiding technology for Cloud or Fog-based IoT system. We expect this Special Collection can provide scientists, researchers, and industrial practitioners with a chance to publish original manuscripts that demonstrate and explore current advances in all aspects of security, privacy, trust and covert communication issue for Cloud or Fog computing/architecture IoT system. Xiaoliang Wang 0002, Frank Jiang 0001, Robin Doss |
MSN | 3 |
| 2022 | Forward Traceability for Product Authenticity Using Ethereum Smart Contracts
Fokke Heikamp, Lei Pan 0002, Rolando Trujillo-Rasua, Sushmita Ruj, Robin Doss |
NSS | 5 |
| 2022 | A Differential Privacy Mechanism for Deceiving Cyber Attacks in IoT Networks
Guizhen Yang, Mengmeng Ge 0001, Shang Gao 0003, Xuequan Lu, Leo Yu Zhang, Robin Doss |
NSS | 6 |
| 2022 | A Bytecode-based Approach for Smart Contract ClassificationabstractWith the development of blockchain technologies, the number of smart contracts deployed on blockchain platforms is growing exponentially, which makes it difficult for users to find desired services by manual screening. The automatic classification of smart contracts can provide blockchain users with keyword-based contract searching and helps to manage smart contracts effectively. Current research on smart contract classification focuses on Natural Language Processing (NLP) solutions which are based on contract source code. However, more than 94% of smart contracts are not open-source, so the application scenarios of NLP methods are very limited. Meanwhile, NLP models are vulnerable to adversarial attacks. This paper proposes a classification model based on features from contract bytecode instead of source code to solve these problems. We also use feature selection and ensemble learning to optimize the model. Our experimental studies on over 11K real-world Ethereum smart contracts show that our model can classify smart contracts without source code and has better performance than baseline models. Our model also has good resistance to adversarial attacks compared with NLP-based models. In addition, our analysis reveals that account features used in many smart contract classification models have little effect on classification and can be excluded. Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Longxiang Gao, Keshav Sood, Robin Doss |
SANER | 6 |
| 2022 | Traceability in supply chains: A Cyber security analysis
Naeem Firdous Syed, Syed Wajid Ali Shah, Rolando Trujillo-Rasua, Robin Doss |
Comput. Secur. | 4 |
| 2022 | Towards Spoofing Resistant Next Generation IoT NetworksabstractThe potential vulnerability to wireless spoofing attacks is still a critical concern for Next Generation Internet of Things (NGIoT) networks which may result in catastrophic consequences in mission–critical applications. Conventional solutions may impose additional signal processing, protocol, and latency overheads which are inappropriate for NGIoT networks designed to provide high–speed and low–latency connections for a large number of resource–constrained IoT devices. In this paper, we utilize the uniqueness of beam pattern features in mmWave–enabled devices and propose a scalable security mechanism for the detection of wireless spoofing attacks in NGIoT networks. This uniqueness is proven to exist due to the non–ideal manufacturing of antenna arrays used in mmWave–enabled devices. In our approach, when legitimate mmWave–enabled IoT devices enrol into the network, their unique beam features are learned by a learning model developed at the network server. Then, during data transmission, network base stations (gNBs)/Access Points (APs) measure the beam features from the received RF signals and send them to the network server for the detection of anomalies. We develop our learning model based on Deep Autoencoders (DAEs) that are an effective tool for anomaly detection. Fortunately, the beam feature extraction can be performed using the beam searching mechanism that is already provided in mmWave standards (5G–NR and IEEE 802.11ad). Thus, feature extraction does not introduce any signal processing overheads to the system. Moreover, the proposed mechanism imposes zero computation/communication overhead to the resource—constrained IoT nodes. In our experiments, we reached 98.6% accuracy in the detection of illegitimate devices which confirms the effectiveness of the proposed approach. Mohammad Reza Nosouhi, Keshav Sood, Marthie Grobler, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Improving Unlinkability of Attribute-based Authentication through Game TheoryabstractThis article first formalizes the problem of unlinkable attribute-based authentication in the system where each user possesses multiple assertions and uses them interchangeably. Currently, there are no recommendations for optimal usage of assertions in such authentication systems. To mitigate this issue, we use conditional entropy to measure the uncertainty for a Relying Party who attempts to link observed assertions with user labels. Conditional entropy is the function of usage statistics for all assertions in the system. Personaldecisionsmade by the users about the usage of assertions contribute to these statistics. This collective effect from all the users impacts the unlinkability of authentication and must be studied using game theory. We specify several instances of the game where context information that is provided to the users differs. Through game theory and based on conditional entropy, we demonstrate how each user optimizes usage for the personal set of assertions. In the experiment, we substantiate the advantage of the proposed rational decision-making approaches: Unlinkability that we obtain under Nash equilibrium is higher than in the system where users authenticate using their assertions at random. We finally propose an algorithm that calculates equilibrium and assists users with the selection of assertions. This manifests that described techniques can be executed in realistic settings. This does not require modification of existing authentication protocols and can be implemented in platform-independent identity agents. As a use case, we describe how our technique can be used in Digital Credential Wallets: We suggest that unlinkability of authentication can be improved for Verifiable Credentials. Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Maksym Slavnenko, Robin Doss |
ACM Trans. Priv. Secur. | 5 |
| 2021 | Digital Twin for Cybersecurity: Towards Enhancing Cyber Resilience
Rajiv Faleiro, Lei Pan 0002, Shiva Raj Pokhrel, Robin Doss |
BROADNETS | 4 |
| 2021 | Identifying DNS Exfiltration based on Lexical Attributes of Query NameabstractSensitive and personal information theft is one of the biggest threats faces by enterprise networks. DNS is frequently used by sophisticated attackers to exfiltrate data over DNS queries, or facilitate command and control communications for malware in networks (i.e., tunneling). Commercial firewalls and intrusion detection systems (IDSs) seemingly have some capabilities to detect evolving attack vectors, but they are expensive and inflexible hardware solutions, yet incapable of offering advanced security features at high throughput. This paper develops and evaluates novel deep neural network-based DNS exfiltration using 1 Million benign domains and 1 Million DNS exfiltrated domains. We then compare its performance with state-of-the-art methods that show our deep learning-based framework outperforms with an accuracy of more than 99.9%. Iram Jawad, Jawad Ahmed, Muhammad Imran Razzak, Robin Doss |
IJCNN | 4 |
| 2021 | Federated Learning with Extreme Label Skew: A Data Extension ApproachabstractThe real-world data sets often leveraged by Federated Learning (FL) applications are mostly non-independent and non-identically distributed (non-IID). This usually results from the diverse nature of the participating clients and their individual data-gathering contexts. An effective FL algorithm must incorporate the capability to produce a joint model that generalizes and captures these diverse patterns. In this work, we show how using some wild external data samples as placeholders for missing classes on client devices can alleviate the learning difficulty often posed by inbalance data distributions. Our exploration showed that this strategy enhances learning and can significantly boost test accuracy, particularly in extreme label skew scenarios. We recorded over 25% reduction in test error rate for the pathological non-IID partitions of the CIFAR10 data set. Our results are similar to those obtainable through bound-expanding strategies such as direct data sharing among clients. But unlike these techniques, our approach rules out the risk of exposing client's private data. Saheed A. Tijani, Xingjun Ma, Frank Jiang 0001, Robin Doss |
IJCNN | 5 |
| 2021 | Systematic evaluation of abnormal detection methods on gas well sensor dataabstractNatural gas, as a kind of clean energy, has attracted significant attention in the global market. However, how to ensure the safety and high efficiency in natural gas production becomes a hot research problem in the gas industry. The real-time abnormal status detection of the natural gas well empowers the decision-maker to prevent potentially catastrophic damage and correct unexpected situations. In this paper, we systematically evaluate the 9 state-of-the-art machine learning methods to detect such anomalous status on large sensor data collected from 4 natural gas wells. In addition, we have identified the most important features that can improve anomaly detection performance. The challenges and potential research directions have been discussed. This is the first work to investigate different types of anomaly detection methods on natural gas well sensor data. Our research results provide valuable insights for developing specific anomaly detection systems in the natural gas industry. Xichen Tang, Ye Zhu 0002, Robin Doss |
ISCC | 4 |
| 2021 | Evaluating the Current State of Application Programming Interfaces for Verifiable CredentialsabstractOne of the challenges to the adoption of the decentralised approach to digital ID is a lack of consensus and standardisation of how different stakeholders within the ecosystem can inter-operate. As a means to address this issue, we examine the use of standard application programming interfaces (API) to integrate decentralised digital identification systems to preexisting ones. We first examine the current literature and solutions to (a) assess the attributes necessary to compare and contrast APIs, and (b) create a list of API providers within the decentralised digital ID marketplace, (c) compare the API providers against the attributes established. Based on an API Usability and Adoption framework as our lens, we assessed 19 service providers of APIs against their use cases. We identified that whilst the APIs are maturing, the APIs remain inconsistent and poorly adopted. A clear standard API could assist in better adoption. The guidance provided can inform organisations implementing digital identity and VCs along their adoption journey Nikesh Lalchandani, Frank Jiang 0001, Jongkil Jeong, Yevhen Zolotavkin, Robin Doss |
PST | 5 |
| 2021 | Enhancing Privacy Through DMMA: Decision-Making Method for AuthenticationabstractAttribute-Based Authentication (ABA) is becoming more prevalent in everyday interactions. In this paper, we propose the Decision-Making Method for Authentication (DMMA) to address the privacy concerns in ABA. The need for DMMA is supported through multiple observations. First, in practice, the indistinguishability of crypto-proof-based assertions (that are posessed by different users) fails with non-zero probability. This explains why cryptographic means alone are insufficient to provide a substantial level of unlinkability in ABA systems with n users. Second, each user in ABA possesses multiple credentials: they can be used interchangeably to get access to the service(s) which is provided by a relying party (RP). DMMA addresses the challenge of interchangeable usage. As an initial step, we synthesized the criterion of unlinkability: it is based on the definitions of international standard ISO 27551 as well as the information theoretic measure of conditional entropy. We then use that criterion to formalize the task of authentication as a non-cooperative coordination game. In this game, players (targets of the attack) maximize their utilities by using their assertions interchangeably. The experiment demonstrates that a number of equilibria with substantially higher unlinkability can be achieved. Unlinkability vary depending on: i) the information (and its trustworthiness) about the moves of the other players in the game; ii) the statistical distribution of user attributes. DMMA demonstrates how users may be provided recommendations over the optimal selection of assertions for ABA. These recommendations can have a practical impact if DMMA is implemented as a feature within Digital Credential Wallets (DCWs). Maksym Slavnenko, Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Robin Doss |
TrustCom | 5 |
| 2021 | EEG-based emotion recognition via capsule network with channel-wise attention and LSTM models
Lina Deng, Xiaoliang Wang 0002, Frank Jiang 0001, Robin Doss |
CCF Trans. Pervasive Comput. Interact. | 4 |
| 2021 | Secure and privacy-preserving structure in opportunistic networks
Samaneh Rashidibajgan, Thomas Hupperich, Robin Doss, Anna Förster |
Comput. Secur. | 3 |
| 2021 | LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA)
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss |
Comput. Secur. | 6 |
| 2021 | Multipath TCP Meets Transfer Learning: A Novel Edge-Based Learning for Industrial IoTabstractWe consider a fifth-generation (5G)-empowered future Industrial IoT (IIoT) networking problem where IIoT machines are capable of communicating and sharing their data networking knowledge gained (and experiences) with other neighboring devices/tools. For such an IIoT setting, deep-learning (DL)-based communication protocols are known to be highly efficient but having a computationally complex training procedure in terms of both time/space and volume of data sets. One solution for such training is to be completed offline for each equipment and machines of IIoT before deployment. A better approach would be to replicate the model from the expert existing machine and implant it into new machines. Such training for the transfer of knowledge can be done by manufacturers using high computational power, even for large-scale DL models. After sufficient training and the desired level of accuracy, the trained machines can be deployed in the smart factory equipment to perform life-long collaborative learning. We design a novel distributed transfer learning (TL) framework to maximize multipath communication networking performance for Industry 4.0 environment. To conduct seamless sharing of knowledge gain by the multipath TCP (MPTCP) agents and tackle retraining issues of DL-based approaches, we investigate TL for MPTCP from the IIoT networking perspective. With relevant insights from transfer and collaborative learning, we develop a distributed TL-MPTCP framework to accelerate the learning efficiency and enhance the performance of newly deployed machines. Our approach is validated with numerical and emulated NS-3 experiments in comparison with the state-of-the-art schemes. Shiva Raj Pokhrel, Lei Pan 0002, Neeraj Kumar 0001, Robin Doss, Hai Le Vu 0001 |
IEEE Internet Things J. | 4 |
| 2021 | SolGuard: Preventing external call issues in smart contract-based multi-agent robotic systems
Purathani Praitheeshan, Lei Pan 0002, James Xi Zheng, Alireza Jolfaei, Robin Doss |
Inf. Sci. | 5 |
| 2021 | Data congestion in VANETs: research directions and new trends through a bibliometric analysis
Tarandeep Kaur Bhatia, Ramkumar Ketti Ramachandran, Robin Doss, Lei Pan 0002 |
J. Supercomput. | 3 |
| 2020 | Towards Decentralized IoT Updates Delivery Leveraging Blockchain and Zero-Knowledge ProofsabstractInternet of Things (IoT) devices are being deployed in huge numbers around the world, and often present serious vulnerabilities. Accordingly, delivering regular software updates is critical to secure IoT devices. Manufactures face two predominant challenges in providing software updates to IoT devices: 1) scalability of the current client-server model and 2) integrity of the distributed updates - exacerbated due to the devices' computing power and lightweight cryptographic primitives. Motivated by these limitations, we propose CrowdPatching, a blockchain-based decentralized protocol, allowing manufacturers to delegate the delivery of software updates to self-interested distributors in exchange for cryptocurrency. Manufacturers announce updates by deploying a smart contract (SC), which in turn will issue cryptocurrency payments to any distributor who provides an unforgeable proof-of-delivery. The latter is provided by IoT devices authorizing the SC to issue payment to a distributor when the required conditions are met. These conditions include the requirement for a distributor to generate a zero-knowledge proof, generated with a novel proving system called zk-SNARKs. Compared with related work, CrowdPatching protocol offers three main advantages. First, the number of distributors can scale indefinitely by enabling the addition of new distributors at any time after the initial distribution by manufacturers (i.e., redistribution among the distributor network). The latter is not possible in existing protocols and is not account for. Secondly, we leverage the recent common integration of gateway or Hub in IoT deployments in our protocol to make CrowdPatching feasible even for the more constraint IoT devices. Thirdly, the trustworthiness of distributors is considered in our protocol, rewarding the honest distributors' engagements. We provide both informal and formal security analysis of CrowdPatching using Tamarin Prover. Edoardo Puggioni, Arash Shaghaghi, Robin Doss, Salil S. Kanhere |
NCA | 3 |
| 2020 | Security Evaluation of Smart Contract-Based On-chain Ethereum Wallets
Purathani Praitheeshan, Lei Pan 0002, Robin Doss |
NSS | 3 |
| 2020 | A Feedback-Driven Lightweight Reputation Scheme for IoVabstractMost applications of Internet of Vehicles (IoVs) rely on collaboration between nodes. Therefore, false information flow in-between these nodes poses the challenging trust issue in rapidly moving IoV nodes. To resolve this issue, a number of mechanisms have been proposed in the literature for the detection of false information and establishment of trust in IoVs, most of which employ reputation scores as one of the important factors. However, it is critical to have a robust and consistent scheme that is suitable to aggregate a reputation score for each node based on the accuracy of the shared information. Such a mechanism has therefore been proposed in this paper. The proposed system utilises the results of any false message detection method to generate and share feedback in the network, this feedback is then collected and filtered to remove potentially malicious feedback in order to produce a dynamic reputation score for each node. The reputation system has been experimentally validated and proved to have high accuracy in the detection of malicious nodes sending false information and is robust or negligibly affected in the presence of spurious feedback. Rohan Dahiya, Frank Jiang 0001, Robin Doss |
TrustCom | 3 |
| 2020 | Opportunistic Tracking in Cyber-Physical SystemsabstractCyber-Physical Systems raise a new dimension of security concerns as they open up the opportunity for attackers to affect a real-world environment. These systems are often applied in specific environments with special requirements and a common issue is to keep track of movements in a mobile system, e.g., involving autonomous robots, drones or sensory I/O devices. In Opportunistic Networks, nodes are usually mobile, forwarding messages from one device to another, not relying on external infrastructure like WiFi. Due to compact and convenient wearability, the nodes of an OppNet might be used to detect the absence and presence of devices or even people in an area where classical networks may not be reliable enough. In this paper, we combine opportunistic network technology with cyber-physical systems and propose a reliable routing algorithm for nodes tracking. Our real-world setup implements hardware sensor tags to evaluate the algorithm in a state-of-the-art environment. Efficiency and performance are compared with established algorithms i. e., Epidemic and Prophet, in terms of latency, network overhead, as well as message delivery probability, and to evaluate the algorithm's scalability, we simulate the tracking in a huge environment. Samaneh Rashidibajgan, Thomas Hupperich, Robin Doss, Lei Pan 0002 |
TrustCom | 3 |
| 2020 | Avoiding Geographic Regions in TorabstractIn this note, the further improvements to prior work in the area of geographical avoidance within the Tor network have been conducted, that aims to improve the security and performance of such systems. First, we propose a new approach to a prior method where the round-trip time from client to entry is directly measured rather than estimated. Secondly, we introduce a new system where we are able to extrapolate data collected from a comparatively small number of Tor circuits and apply it to other unmeasured connections. A dynamic threshold has been identified to partially compensate for inaccuracy and shifts up or down depending on the length of the circuit. The experimental results quantitively validate the effectiveness and efficiency of the new proposed system. The testbed produced in this work may prove useful to future research in the areas of traffic analysis, the Tor network, and geographical avoidance on the Internet. Matthew J. Ryan, Morshed U. Chowdhury, Frank Jiang 0001, Robin Doss |
TrustCom | 4 |
| 2020 | Towards a Lightweight Continuous Authentication Protocol for Device-to-Device CommunicationabstractContinuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely researched human user characteristics-based CA mechanisms cannot be extended to continuously authenticate Internet of Things (IoT) devices. The challenges are exacerbated with the increased adoption of device-to-device (d2d) communication in critical infrastructures. Existing d2d authentication protocols proposed in the literature are either prone to subversion or are computationally infeasible to be deployed on constrained IoT devices. In view of these challenges, we propose a novel, lightweight and secure CA protocol that leverages communication channel properties and a tunable mathematical function to generate dynamically changing session keys. Our preliminary informal protocol analysis suggests that the proposed protocol is resistant to known attack vectors and thus has strong potential for deployment in securing critical and resource-constrained d2d communication. Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss |
TrustCom | 6 |
| 2020 | Secure attribute-based search in RFID-based inventory control systems
Robin Doss, Rolando Trujillo-Rasua, Selwyn Piramuthu |
Decis. Support Syst. | 1 |
| 2019 | Privacy-preserving history-based routing in Opportunistic Networks
Samaneh Rashidibajgan, Robin Doss |
Comput. Secur. | 2 |
| 2018 | Packet integrity defense mechanism in OppNets
Asma'a Ahmad, Robin Doss, Majeed Alajeely, Sarab F. Al Rubeaai, Dua'a Ahmad |
Comput. Secur. | 2 |
| 2018 | A malicious threat detection model for cloud assisted internet of things (CoT) based industrial control system (ICS) networks using deep belief network
Md. Shamsul Huda, Md. Suruz Miah, John Yearwood, Sultan Alyahya, Hmood Al-Dossari 0001, Robin Doss |
J. Parallel Distributed Comput. | 6 |
| 2017 | A secure search protocol for low cost passive RFID tags
Saravanan Sundaresan, Robin Doss, Selwyn Piramuthu, Wanlei Zhou 0001 |
Comput. Networks | 2 |
| 2017 | Defense against packet collusion attacks in opportunistic networks
Majeed Alajeely, Robin Doss, Asma'a Ahmad, Vicky H. Mak-Hau |
Comput. Secur. | 2 |
| 2017 | On sensor-based solutions for simultaneous presence of multiple RFID tags
Selwyn Piramuthu, Robin Doss |
Decis. Support Syst. | 2 |
| 2017 | Special issue on Underwater Acoustic Sensor Networks: Emerging trends and current perspectives
Sabu M. Thampi, Jaime Lloret Mauri, Robin Doss |
J. Netw. Comput. Appl. | 3 |
| 2016 | RFID ownership transfer protocol based on cloud
Tianjie Cao, Xiuqing Chen, Robin Doss, Jingxuan Zhai, Lucas J. Wise |
Comput. Networks | 3 |
| 2015 | Catabolism attack and Anabolism defense: A novel attack and traceback mechanism in Opportunistic Networks
Majeed Alajeely, Robin Doss, Asma'a Ahmad, Vicky H. Mak-Hau |
Comput. Commun. | 2 |
| 2015 | Secure ownership transfer for multi-tag multi-owner passive RFID environment with individual-owner-privacy
Saravanan Sundaresan, Robin Doss, Wanlei Zhou 0001, Selwyn Piramuthu |
Comput. Commun. | 2 |
| 2015 | Zero Knowledge Grouping Proof Protocol for RFID EPC C1G2 TagsabstractIn this paper, we propose a novel zero knowledge grouping proof protocol for RFID Systems. Over the years, several protocols have been proposed in this area but they are either found to be vulnerable to certain attacks or do not comply with the EPC Class 1 Gen 2 (C1G2) standard because they use hash functions or other complex encryption schemes. Also, the unique design requirements of grouping proofs have not been fully addressed by many. Our protocol addresses these important security and design gaps in grouping proofs. We present a novel approach based on pseudo random squares and quadratic residuosity to realize a zero knowledge system. Tag operations are limited to functions such as modulo (MOD), exclusive-or (XOR) and 128 bit Pseudo Random Number Generators (PRNG). These can be easily implemented on passive tags and hence achieves compliance with the EPC Global standard while meeting the security requirements. Saravanan Sundaresan, Robin Doss, Wanlei Zhou 0001 |
IEEE Trans. Computers | 2 |
| 2015 | Secure Tag Search in RFID Systems Using Mobile ReadersabstractOne of the important features of an RFID system is its ability to search for a particular tag among a group of tags. In order to ensure privacy and security of the tags, the search has to be conducted in a secure fashion. To our knowledge not much work has been done in this secure search area of RFID. The minimal work that has been done do not comply with the EPC C1G2 (Class-1 Gen-2) standard since most of them use expensive hash operations or sophisticated encryption schemes that cannot be implemented in the low-cost passive tags that are highly resource constrained. Our work aims to fill this gap by proposing a protocol that is based on simple XOR encryption and 128 bit pseudo random number generators (PRNG), operations that can be easily implemented on low-cost passive tags. Thus, our protocol enables large scale implementations and achieves EPC C1G2 compliance while meeting the security requirements. The protocol provides additional protection by hiding the pseudo-random number during all transmissions using a blind-factor. Saravanan Sundaresan, Robin Doss, Selwyn Piramuthu, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | A Robust Grouping Proof Protocol for RFID EPC C1G2 TagsabstractSeveral grouping proof protocols for RFID systems have been proposed over the years but they are either found to be vulnerable to certain attacks or do not comply with the EPC class-1 gen-2 (C1G2) standard because they use hash functions or other complex encryption schemes. Among other requirements, synchronization of keys, simultaneity, dependence, detecting illegitimate tags, eliminating unwanted tag processing, and denial-of-proof attacks have not been fully addressed by many. Our protocol addresses these important gaps by taking a holistic approach to grouping proofs and provides forward security, which is an open research issue. The protocol is based on simple (XOR) encryption and 128-bit pseudorandom number generators, operations that can be easily implemented on low-cost passive tags. Thus, our protocol enables large-scale implementations and achieves EPC C1G2 compliance while meeting the security requirements. Saravanan Sundaresan, Robin Doss, Selwyn Piramuthu, Wanlei Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Secure ownership transfer in multi-tag/multi-owner passive RFID systemsabstractIn this paper we propose a secure ownership transfer protocol for a multi-tag and multi-owner RFID environment. Most of the existing work in this area do not comply with the EPC Global Class-1 Gen-2 (C1G2) standard since they use expensive hash operations or sophisticated encryption schemes that cannot be implemented on low-cost passive tags that are highly resource constrained. Our work aims to fill this gap by proposing a protocol based on simple XOR and 128-bit Pseudo Random Number Generators (PRNG), operations that can be easily implemented on low-cost passive RFID tags. The protocol thus achieves EPC C1G2 compliance while meeting the security requirements. Also, our protocol provides additional protection using a blind-factor to prevent tracking attacks. Saravanan Sundaresan, Robin Doss, Wanlei Zhou 0001 |
GLOBECOM | 2 |
| 2013 | A general cloud firewall framework with dynamic resource allocationabstractCloud is becoming a dominant computing platform. However, we see few work on how to protect cloud data centers. As a cloud usually hosts many different type of applications, the traditional packet level firewall mechanism is not suitable for cloud platforms in case of complex attacks. It is necessary to perform anomaly detection at the event level. Moreover, protecting objects are more diverse than the traditional firewall. Motivated by this, we propose a general framework of cloud firewall, which features event level detection chain with dynamic resource allocation. We establish a mathematical model for the proposed framework. Moreover, a linear resource investment function is proposed for economical dynamical resource allocation for cloud firewalls. A few conclusions have been extracted for the reference of cloud service providers and designers. Shui Yu 0001, Robin Doss, Wanlei Zhou 0001, Song Guo 0001 |
ICC | 2 |
| 2013 | Offline grouping proof protocol for RFID systemsabstractSeveral grouping proof protocols have been proposed over the years but they are either found to be vulnerable to certain attacks or do not comply with EPC Class-1 Gen-2 (C1G2) standard because they use hash functions or other complex encryption schemes. Also, synchronization of keys, forward security, proving simultaneity, creating dependence, detecting illegitimate tags, eliminating unwanted tag processing and denial-of-proof (DoP) attacks have not been fully addressed by many. Our protocol addresses these important gaps and is based on Quadratic Residues property where the tags are only required to use XOR, 128-bit Pseudo Random Number Generators (PRNG) and Modulo (MOD) operations which can be easily implemented on low-cost passive tags and hence achieves EPC C1G2 compliance. Saravanan Sundaresan, Robin Doss, Wanlei Zhou 0001 |
WiMob | 2 |
| 2013 | A practical quadratic residues based scheme for authentication and privacy in mobile RFID systems
Robin Doss, Saravanan Sundaresan, Wanlei Zhou 0001 |
Ad Hoc Networks | 1 |
| 2013 | Secure RFID Tag Ownership Transfer Based on Quadratic ResiduesabstractIn this paper, we propose a novel approach to secure ownership transfer in RFID systems based on the quadratic residue property. We present two secure ownership transfer schemes—the closed loop and open loop schemes. An important property of our schemes is that ownership transfer is guaranteed to be atomic. Further, both our schemes are suited to the computational constraints of EPC Class-1 Gen-2 passive RFID tags as they only use operations that such passive RFID tags are capable of. We provide a detailed security analysis to show that our schemes achieve strong privacy and satisfy the required security properties of tag anonymity, tag location privacy, forward secrecy, and forward untraceability. We also show that the schemes are resistant to replay (both passive and algebraic), desynchronization, and server impersonation attacks. Performance comparisons demonstrate that our schemes are practical and can be implemented on low-cost passive RFID tags. Robin Doss, Wanlei Zhou 0001, Shui Yu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2012 | A secure search protocol based on Quadratic Residues for EPC Class-1 Gen-2 UHF RFID tagsabstractRadio Frequency Identification (RFID) is a technological revolution that is expected to soon replace barcode systems. One of the important features of an RFID system is its ability to search for a particular tag among a group of tags. This task is quite common where RFID systems play a vital role. To our knowledge not much work has been done in this secure search area of RFID. Also, most of the existing work do not comply with the C1G2 standards. Our work aims to fill that gap by proposing a protocol based on Quadratic Residues property that does not use the expensive hash functions or any complex encryption schemes but achieves total compliance with industry standards while meeting the security requirements. Saravanan Sundaresan, Robin Doss, Wanlei Zhou 0001 |
PIMRC | 2 |
| 2012 | A minimum disclosure approach to authentication and privacy in RFID systems
Robin Doss, Wanlei Zhou 0001, Saravanan Sundaresan, Shui Yu 0001, Longxiang Gao |
Comput. Networks | 1 |
| 2011 | Prevention of Information Harvesting in a Cloud Services Environment
Lynn Margaret Batten, Jemal H. Abawajy, Robin Doss |
CLOSER | 3 |
| 2011 | Traceback of DDoS Attacks Using Entropy VariationsabstractDistributed Denial-of-Service (DDoS) attacks are a critical threat to the Internet. However, the memoryless feature of the Internet routing mechanisms makes it extremely hard to trace back to the source of these attacks. As a result, there is no effective and efficient method to deal with this issue so far. In this paper, we propose a novel traceback method for DDoS attacks that is based on entropy variations between normal and DDoS attack traffic, which is fundamentally different from commonly used packet marking techniques. In comparison to the existing DDoS traceback methods, the proposed strategy possesses a number of advantages - it is memory nonintensive, efficiently scalable, robust against packet pollution, and independent of attack traffic patterns. The results of extensive experimental and simulation studies are presented to demonstrate the effectiveness and efficiency of the proposed method. Our experiments show that accurate traceback is possible within 20 seconds (approximately) in a large-scale attack network with thousands of zombies. Shui Yu 0001, Wanlei Zhou 0001, Robin Doss, Weijia Jia 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2010 | Information discovery in mission-critical wireless sensor networks
Robin Doss, Gang Li 0009, Vicky H. Mak-Hau, Menik Tissera |
Comput. Networks | 1 |
| 2009 | Lightweight Authentication for Recovery in Wireless Sensor NetworksabstractWireless sensor networks (WSNs) suffer from a wide range of security attacks due to their limited processing and energy capabilities. Their use in numerous mission critical applications, however, requires that fast recovery from such attacks be achieved. Much research has been completed on detection of security attacks, while very little attention has been paid to recovery from an attack. In this paper, we propose a novel, lightweight authentication protocol that can secure network and node recovery operations such as re-clustering and reprogramming. Our protocol is based on hash functions and we compare the performance of two well-known lightweight hash functions, SHA-1 and Rabin. We demonstrate that our authentication protocol can be implemented efficiently on a sensor network test-bed with TelosB motes. Further, our experimental results show that our protocol is efficient both in terms of computational overhead and execution times which makes it suitable for low resourced sensor devices. Lynn Margaret Batten, Robin Doss |
MSN | 3 |
| 2009 | Improving the QoS for information discovery in autonomic wireless sensor networks
Robin Doss, Gang Li 0009, Vicky H. Mak-Hau, Shui Yu 0001, Morshed U. Chowdhury |
Pervasive Mob. Comput. | 1 |
| 2008 | Exploiting Affinity Propagation for Energy-Efficient Information Discovery in Sensor NetworksabstractWireless sensor networks (WSN) are attractive for information gathering in large-scale data rich environments. Emerging WSN applications require dissemination of information to interested clients within the network requiring support for differing traffic patterns. Further, in-network query processing capabilities are required for autonomic information discovery. In this paper, we formulate the information discovery problem as a load-balancing problem, with the combined aim being to maximize network lifetime and minimize query processing delay. We propose novel methods for data dissemination, information discovery and data aggregation that are designed to provide significant QoS benefits. We make use of affinity propagation to group "similar" sensors and have developed efficient mechanisms that can resolve both ALL-type and ANY-type queries in-network with improved energy-efficiency and query resolution time. Simulation results prove the proposed method(s) of information discovery offer significant QoS benefits for ALL-type and ANY-type queries in comparison to previous approaches. Robin Doss, Gang Li 0009 |
GLOBECOM | 1 |
| 2008 | A Transformation Model for Heterogeneous ServersabstractOne of the characteristics of the current Web services is that many clients request the same or similar service from a group of replicated servers, e.g. music or movie downloading in peer-to-peer networks. Most of the time, servers are heterogeneous ones in terms of service rate. Much of research has been done in the homogeneous environment. However, there is has been little done on the heterogeneous scenario. It is important and urgent that we have models for heterogeneous server groups for the current Internet applications design and analysis. In this paper, we deploy an approximation method to transform heterogeneous systems into a group of homogeneous system. As a result, the previous results of homogeneous studies can be applied in heterogeneous cases. In order to test the approximation ratio of the proposed model to real applications, we conducted simulations to obtain the degree of similarity. We use two common strategies: random selection algorithm and Firs-Come-First-Serve (FCFS) algorithm to test the approximation ratio of the proposed model. The simulations indicate that the approximation model works well. Shui Yu 0001, Robin Doss, Theerasak Thapngam, David Qian |
HPCC | 2 |
| 2007 | Geographic Routing with Cooperative Relaying and Leapfrogging in Wireless Sensor NetworksabstractA novel geographic routing protocol for multi-hop wireless sensor networks is presented. It exploits the broadcast nature of the wireless channel to enable on-demand cooperative relaying and leapfrogging for circumventing weak radio links. In order to achieve energy efficiency, a metric is introduced for next-hop selection that takes into account information on the residual battery energy, the geographical position of the sensor nodes, and the channel quality of the involved radio links when available. Performance results show that the completely decentralized protocol offers significant benefits by reducing the number of (re)transmissions required to reach the destination. This translates into network-wide energy savings that extend the network lifetime. Pedro Coronel, Robin Doss, Wolfgang Schott |
GLOBECOM | 2 |
| 2006 | Lease Based Addressing for Event-Driven Wireless Sensor NetworksabstractSensor Networks have applications in diverse fields. They can be deployed for habitat modeling, temperature monitoring and industrial sensing. They also find applications in battlefield awareness and emergency (first) response situations. While unique addressing is not a requirement of many data collecting applications of wireless sensor networks it is vital for the success of applications such as emergency response. Data that cannot be associated with a specific node becomes useless in such situations. In this work we propose an addressing mechanism for event-driven wireless sensor networks. The proposed scheme eliminates the need for network wide Duplicate Address Detection (DAD) and enables reuse of addresses. Robin Doss, Deddy Chandra, Lei Pan 0002, Wanlei Zhou 0001, Morshed U. Chowdhury |
ISCC | 1 |
| 2005 | Route maintenance using mobility prediction for mobile ad hoc networksabstractNext generation networks (3G & beyond) will support real-time multimedia applications through traditional wide-area networking concepts as well as hot-spot (WLAN) and ad hoc networking concepts. In order to fulfill the vision of next generation networks a method of maintaining a real-time flow despite frequent topology changes and irregularity in user movement is required. Mobility prediction has been identified as having applications in the areas of link availability estimation and pro-active routing in ad hoc networks. In this work we present the mobility prediction based algorithm for route maintenance in mobile ad hoc networks. Simulation study of the algorithm proves it to offer significant benefits to dynamic source routing (DSR). B. Hansolt Sathyaraj, Robin Doss |
MASS | 2 |
| 2003 | A comparative study of mobility prediction in fixed wireless networks and mobile ad hoc networksabstractIn this paper we have introduced a mobility prediction scheme that proposes the use of a new sector-based tracking of mobile users, with a sector-numbering scheme to predict user movements. The proposed scheme is applicable for both the fixed network and the ad hoc networking structures. Our study shows that accurate prediction is possible with reduced area of tracking for both types of networks. Robin Doss, Andrew Jennings, Nirmala Shenoy |
ICC | 1 |