VLDB 2026 Research / reviewers in the wild / expert
Padmalochan Bera
dblp:44/7556
· DBLP profile ↗
25ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0002-0044-7051ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 2 first-author · 3 since 2021Computer networks · 7 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure Blockchain-Assisted Attribute-Based Keyword Search for Collaborative E-HealthcareabstractIn the age of technological advancement, collaborative e-healthcare emerges as a transformative system eliminating traditional location and accessibility barriers in healthcare services. Here, searchable encryption (SE) plays a key role in enabling healthcare providers to outsource encrypted medical data and search services to third parties like cloud servers, thereby reducing storage and management expenses. This intermediary approach poses challenges of single-point failure, privacy breaches, and potentially untrustworthy results. State-of-the-art public key-based SE methods use a cloud-assisted architecture that doesn’t support reliable and practical searches with fine-grained permissions. Also, such systems require additional support to address potential privacy leakages and ensure data availability at the storage server. To address these concerns, we propose a blockchain-assisted efficient and secure keyword search (BESKS) scheme to enforce fine-grained keyword search privilege control while achieving practical search complexity. Our scheme employs a ciphertext-policy attribute-based keyword search mechanism where keywords are encrypted using expressive access policies to build an inverted index structure. The encrypted indexes are stored on the blockchain while encrypted medical documents are stored on InterPlanetary File System (IPFS) nodes to enhance availability and ensure the reliability and scalability of our approach. Our scheme utilizes blockchain-based smart contract for efficient, secure search operations and ensures financial fairness in fine-grained searches. Search tokens are generated based on user attributes and query keywords to facilitate private searches on-chain. To enhance the search process, our secure index enables exact match for a query keyword in constant time to ensure expensive authorization operations are performed only once. Theoretical analysis suggests that our BESKS is more efficient and secure than state-of-the-art schemes. Prototype implementation results on the Ethereum blockchain network further validate its feasibility for real-world applications, demonstrating the scheme’s practical applicability in collaborative e-healthcare systems. Kasturi Routray, Abhiram Manikonda, Padmalochan Bera |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2026 | DDoSBlocker: A Protocol-Independent and Lightweight Defense Mechanism against Multi-Layer DDoS Attacks in SDNabstractSoftware-Defined Networking (SDN) leverages centralized control to enhance network flexibility, programmability, and resource management. However, this centralization also makes it susceptible to Distributed Denial of Service (DDoS) attacks. In this attack, both compromised hosts and malicious third-party applications flood the controller with fake requests, causing network disruptions and potential failures. Existing literature lacks a comprehensive solution that effectively addresses both compromised host-based and application-layer DDoS attacks. Additionally, there is no mitigation mechanism capable of blocking malicious traffic directly at its source. To address this limitation, we propose DDoSBlocker which is a protocol-independent and lightweight DDoS defense mechanism against multi-layer DDoS attacks in SDN. It consists of three essential modules. The first module identifies the source points of compromised hosts responsible for DDoS attacks by leveraging time-based mapping technique integrated with machine learning technique. The second module detects malicious third-party applications by analyzing their application IDs using a machine learning approach with six novel features. Finally, the last module implements a mitigation strategy that effectively blocks malicious traffic at its source, ensuring minimal impact on legitimate network operations. DDoSBlocker is deployed in the Floodlight controller, and its effectiveness is assessed across multiple network scenarios. Our experimental results demonstrate that DDoSBlocker successfully detects and mitigates various types of DDoS attacks while achieving a 25–53% reduction in False Positive Rate (FPR) compared to existing approaches. Mitali Sinha, Padmalochan Bera, Manoranjan Satpathy |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2026 | Dynamic attribute-based encryption for secure data sharing in cloud applications
Kasturi Routray, Padmalochan Bera |
Future Gener. Comput. Syst. | 2 |
| 2025 | DDoSBlocker: Enhancing SDN security with time-based address mapping and AI-driven approach
Mitali Sinha, Padmalochan Bera, Manoranjan Satpathy, Kshira Sagar Sahoo, Joel J. P. C. Rodrigues |
Comput. Networks | 2 |
| 2025 | HalfFedLearn: A secure federated learning with local data partitioning and homomorphic encryption
Rojalini Tripathy, Jigyasa Meshram, Padmalochan Bera |
Future Gener. Comput. Syst. | 3 |
| 2024 | Interpretative Attention Networks for Structural Component Recognition
Abhishek Uniyal, Bappaditya Mandal, Niladri B. Puhan, Padmalochan Bera |
ICPR (16) | 4 |
| 2024 | Efficient and Secure Cloud Data Sharing Using CP-ABE Supporting Dynamic AttributesabstractCiphertext-Policy Attribute-Based Encryption (CP-ABE) is a cryptographic primitive that provides confidentiality and fine-grained access control for data sharing in untrusted cloud environments. It allows data owners to set access policies based on attributes, ensuring only users who meet the criteria can decrypt and access the data. However, existing CP-ABE systems are inherently designed for static attributes and lack efficient support for dynamic user attributes, often necessitating frequent key updates and complex revocation processes. To address these challenges, we propose an enhanced CP-ABE cryptosystem that allows for the dynamic generation of additional key components, which can be efficiently integrated with the user's existing key. The user private key is assigned attribute-level expiration tags, facilitating instant revocation. Additionally, our scheme facilitates the secure offloading of partial decryption of ciphertext to the cloud server using a transformed private key, thus reducing the computational overhead on resource-constrained user devices. Our proposed cryptosystem provides a secure and scalable approach for managing dynamic attributes in cloud environments with rapidly evolving access requirements. Kasturi Routray, Padmalochan Bera |
MobiCom | 2 |
| 2024 | Multi-Client Searchable Encryption with Granular Access Control for Cloud-Assisted IoTabstractCloud-assisted Internet of Things (CIoT) enhances data accessibility and operational efficiency but encounters various security and privacy challenges. Today, CIoT applications generate large amounts of data in a multi-client accessible environment involving periodic addition of data. These systems require efficient searchable encryption to securely share data with authorized users, enable private keyword searches, and support frequent updates to outsourced data, thus maintaining data integrity and user privacy. Existing symmetric searchable encryption (SSE) schemes enable efficient searches for large datasets but are limited in providing multi-user data sharing. In contrast, attribute-based searchable encryption (ABSE) schemes offer fine-grained access control in collaborative scenarios but suffer from high search latency. In this paper, we present a hybrid searchable encryption scheme that enables secure keyword search with sublinear search efficiency and supports periodic dynamic addition of files in multi-client IoT environments. By providing privacy-preserving keyword searches with forward privacy and keyword-level access control, our approach effectively enhances security and performance for cloud-assisted IoT. Kasturi Routray, Satyansh Shukla, Padmalochan Bera |
MobiCom | 3 |
| 2023 | Federated reinforcement learning based intrusion detection system using dynamic attention mechanism
Sreekanth Vadigi, Kamalakanta Sethi, Dinesh Mohanty, Shom Prasad Das, Padmalochan Bera |
J. Inf. Secur. Appl. | 5 |
| 2023 | A Security Enforcement Framework for SDN Controller Using Game Theoretic ApproachabstractSoftware-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention. Madhukrishna Priyadarsini, Padmalochan Bera, Sajal K. Das 0001, Mohammad Ashiqur Rahman |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Software defined networking architecture, traffic management, security, and placement: A survey
Madhukrishna Priyadarsini, Padmalochan Bera |
Comput. Networks | 2 |
| 2021 | Attention based multi-agent intrusion detection systems using reinforcement learning
Kamalakanta Sethi, Venu Madhav Yatam, Padmalochan Bera |
J. Inf. Secur. Appl. | 4 |
| 2020 | Practical traceable multi-authority CP-ABE with outsourcing decryption and access policy updation
Kamalakanta Sethi, Ankit Pradhan, Padmalochan Bera |
J. Inf. Secur. Appl. | 3 |
| 2019 | Distributed Multi-authority Attribute-Based Encryption Using Cellular Automata
Ankit Pradhan, Kamalakanta Sethi, Shrohan Mohapatra, Padmalochan Bera |
CANS | 4 |
| 2019 | An adaptive load balancing scheme for software-defined network controllers
Madhukrishna Priyadarsini, Joy Chandra Mukherjee, Padmalochan Bera, A. H. M. Jakaria, Mohammad Ashiqur Rahman |
Comput. Networks | 3 |
| 2018 | Risk based Security Enforcement in Software Defined Network
Bata Krishna Tripathy, Debi Prasad Das, Swagat Kumar Jena, Padmalochan Bera |
Comput. Secur. | 4 |
| 2017 | Formal Modelling and Verification of Requirements of Adaptive Routing Protocol for Mobile Ad-Hoc NetworkabstractA group of mobile nodes with limited capabilities sparsed in different clusters forms the backbone of Mobile Ad-Hoc Networks (MANET). In such situations, the requirements (mobility, performance, security, trust and timing constraints) vary with change in context, time, and geographic location of deployment. This leads to various performance and security challenges which necessitates a trade-off between them on the application of routing protocols in a specific context. The focus of our research is towards developing an adaptive and secure routing protocol for Mobile Ad-Hoc Networks, which dynamically configures the routing functions using varying contextual features with secure and real-time processing of traffic. In this paper, we propose a formal framework for modelling and verification of requirement constraints to be used in designing adaptive routing protocols for MANET. We formally represent the network topology, behaviour, and functionalities of the network in SMT-LIB language. In addition, our framework verifies various functional, security, and Quality-of-Service (QoS) constraints. The verification engine is built using the Yices SMT Solver. The efficacy of the proposed requirement models is demonstrated with experimental results. Bata Krishna Tripathy, Ashray Sudhir, Padmalochan Bera, Mohammad Ashiqur Rahman |
COMPSAC (1) | 3 |
| 2017 | Integration of role based access control with homomorphic cryptosystem for secure and controlled access of data in cloudabstractRecent advances in cloud technology facilitates data owners having limited resources to outsource their data and computations to remote servers in Cloud. To protect against unauthorized information access, sensitive data are encrypted before outsourcing. However, traditional cryptosystems need decrypting ciphertext for outsourced computations that may violate data security as well may introduce higher computational complexity. Homomorphic encryption is a solution that allows performing computations directly on ciphertext. On the otherhand, it is evident that the computations on data may vary from users to users depending on the requirements. So, it is not always feasible to allow all computations to different users on the whole ciphertext stored in cloud. In this paper, we proposed a framework for integration of role based access control (RBAC) mechanism with homomorphic cryptosystem for secure and controlled access of data in cloud. Our proposed framework is developed based on trust and role hierarchy with multi-granular operational access rights to heterogeneous stakeholders or users. Kamalakanta Sethi, Anish Chopra, Padmalochan Bera, Bata Krishna Tripathy |
SIN | 3 |
| 2017 | A novel malware analysis for malware detection and classification using machine learning algorithmsabstractNowadays, Malware has become a serious threat to the digitization of the world due to the emergence of various new and complex malware every day. Due to this, the traditional signature-based methods for detection of malware effectively becomes an obsolete method. The efficiency of the machine learning model in context to the detection of malware files has been proved by different researches and studies. In this paper, a framework has been developed to detect and classify different files (e.g exe, pdf, php, etc.) as benign and malicious using two level classifier namely, Macro (for detection of malware) and Micro (for classification of malware files as a Trojan, Spyware, Adware, etc.). Cuckoo Sandbox is used for generating static and dynamic analysis report by executing files in the virtual environment. In addition, a novel model is developed for extracting features based on static, behavioral and network analysis using analysis report generated by the Cuckoo Sandbox. Weka Framework is used to develop machine learning models by using training datasets. Kamalakanta Sethi, Shankar Kumar Chaudhary, Bata Krishna Tripathy, Padmalochan Bera |
SIN | 4 |
| 2012 | SmartAnalyzer: A noninvasive security threat analyzer for AMI smart gridabstractThe Advanced Metering Infrastructure (AMI) is the core component in smart grid that exhibits highly complex network configurations comprising of heterogeneous cyber-physical components. These components are interconnected through different communication media, protocols, and secure tunnels, and they are operated using different data delivery modes and security policies. The inherent complexity and heterogeneity in AMI significantly increase the potential of security threats due to misconfiguration or absence of defense, which may cause devastating damage to AMI. Therefore, there is a need of creating a formal model that can represent the global behavior of AMI configuration in order to verify the potential threats. In this paper, we present SmartAnalyzer, a formal security analysis tool, which offers manifold contributions: (i) formal modeling of AMI configuration including device configurations, topology, communication properties, interactions between the devices, data flows, and security properties; (ii) formal modeling of AMI invariant and user-driven constraints based on the interdependencies between AMI device configurations, security properties, and security control guidelines; (iii) verifying the AMI configuration's compliances with security constraints using Satisfiability Modulo Theory (SMT) solver; (iv) generating a comprehensive security threat report with possible remediation plan based on the verification results. The accuracy, scalability, and usability of the tool are evaluated on real smart grid environment and synthetic test networks. Mohammad Ashiqur Rahman, Padmalochan Bera, Ehab Al-Shaer |
INFOCOM | 2 |
| 2011 | Build and Test Your Own Network Configuration
Saeed Al-Haj, Padmalochan Bera, Ehab Al-Shaer |
SecureComm | 2 |
| 2011 | A WLAN security management framework based on formal spatio-temporal RBAC modelabstractAbstract In today's organizations, the large scale deployment of wireless networks has opened up new directions in network security management. The organizational security policies aim at protecting the network resources from unauthorized accesses in the wireless local area networks (WLAN). In WLAN security policy management, the standard IP‐based access control mechanisms are not sufficient due to dynamic changes in network topology and access control states. The role‐based access control (RBAC) models may be appropriate to strengthen the security perimeter over the network resources. However, formalizing the dynamic binding of the access policies to the roles, depending on various control states, is a major challenge. In this paper, we propose a WLAN security policy management framework based on a formalspatio‐temporal RBAC(STRBAC) model. The present work primarily focuses on dynamic computation of security policies based on various control states, its formal representation using STRBAC model, and security property verification of the proposed STRBAC model. The proposed policy management framework logically partitions the WLAN topology into various security policy zones. The framework includes aCentral Authentication & Role Server(CARS) which authenticates the users (nodes) and access points (AP) and also assigns appropriate roles to the users; aGlobal Policy Server(GPS) that dynamically computes the global security policy and policy configurations for different policy zones based on local user‐role and control state information; a distributed policy zone control architecture. Each policy zone consists of aPolicy Zone Controller(WPZCon) which dynamically computes the low‐level access configurations. Finally, a SAT based verification procedure has been presented for verifying the security properties of the proposed STRBAC model. Copyright © 2010 John Wiley & Sons, Ltd. Padmalochan Bera, Soumya K. Ghosh 0001, Pallab Dasgupta |
Secur. Commun. Networks | 1 |
| 2010 | A mobile IP based WLAN security management framework with reconfigurable hardware accelerationabstractThe increasing use of wireless technologies in enterprise networks demands strong security management and policy enforcement mechanisms. The conventional security management frameworks used in wired LAN do not suit in wireless domain due to dynamic topology and mobility of hosts. The enforcement of organizational security policies in wireless LAN requires appropriate access control models as well as correct distribution of access control rules in the network access points. In this paper, we propose a WLAN security management framework supported by a spatio-temporal RBAC (STRBAC) model. The concept of mobile IP has been used to ensure a fixed layer 3 address of a mobile host. Each wireless policy zone consists of a Policy Zone Controller that coordinates with a dedicated Local Role Server to extract the low level access configurations corresponding to the zone access routers. The system can be mapped into a reconfigurable hardware to exploit the parallelism in computing. We also propose a formal STRBAC model to represent the global security policies formally and a SAT based decision procedure to verify the access configurations Soumya Maity, Padmalochan Bera, Soumya K. Ghosh 0001 |
SIN | 2 |
| 2010 | Integrated security analysis framework for an enterprise network - a formal approachabstractIn a typical enterprise network, correct implementation of security policies is becoming increasingly difficult owing to complex security constraints and dynamic changes in network topology. Usually, the network security policy is defined as the collection of service access rules between various network zones. The specification of the security policy is often incomplete since all possible service access paths may not be explicitly covered. This policy is implemented in the network interfaces in a distributed fashion through sets of access control (ACL) rules. Formally verifying whether the distributed ACL implementation conforms to the security policy is a major requirement. The complexity of the problem is compounded as some combination of network services may lead to inconsistent hidden access paths. Further, failure of network link(s) may result in the formation of alternative routing paths and thus the existing security implementation may defy the policy. In this study, an integrated formal verification and fault analysis framework has been proposed which derives a correct ACL implementation with respect to given policy specification and also ensures that the implementation is fault tolerant to certain number of link failures. The verification incorporates boolean modelling of the security policies and ACL implementations and then formulates a satisfiability checking problem. Padmalochan Bera, Santosh K. Ghosh, Pallab Dasgupta |
IET Inf. Secur. | 1 |
| 2010 | Policy Based Security Analysis in Enterprise Networks: A Formal ApproachabstractIn a typical enterprise network, there are several sub-networks or network zones corresponding to different departments or sections of the organization. These zones are interconnected through set of Layer-3 network devices (or routers). The service accesses within the zones and also with the external network (e.g., Internet) are usually governed by a enterprise-wide security policy. This policy is implemented through appropriate set of access control lists (ACL rules) distributed across various network interfaces of the enterprise network. Such networks faces two major security challenges, (i) conflict free representation of the security policy, and (ii) correct implementation of the policy through distributed ACL rules. This work presents a formal verification framework to analyze the security implementations in an enterprise network with respect to the organizational security policy. It generates conflict-free policy model from the enterprise-wide security policy and then formally verifies the distributed ACL implementations with respect to the conflict-free policy model. The complexity in the verification process arises from extensive use of temporal service access rules and presence of hidden service access paths in the networks. The proposed framework incorporates formal modeling of conflict-free policy specification and distributed ACL implementation in the network and finally deploys Boolean satisfiability (SAT) based verification procedure to check the conformation between the policy and implementation models. Padmalochan Bera, Soumya K. Ghosh 0001, Pallab Dasgupta |
IEEE Trans. Netw. Serv. Manag. | 1 |