Vinay Sachidananda

dblp:45/2519 · DBLP profile ↗
← Back
16ranked-venue papers
3as first author
10since 2021 · last 2025
0000-0001-9582-1538ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 3 first-author · 8 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Enmob: Unveil the Behavior with Multi-flow Analysis of Encrypted App Traffic
abstract
Abstract In the contemporary digital landscape, mobile applications have become the predominant conduit for internet connectivity and daily tasks. Simultaneously, the advent of application encryption technology has safeguarded users’ privacy. However, this encryption, while fortifying privacy, introduces challenges to security by hindering the effective management of network applications within encrypted data streams. Conventional detection methods for encrypted application traffic, relying heavily on statistical metrics like payload, packet size, and distribution, are constrained to single traffic flows, often yielding results of limited specificity. To address this limitation, our paper introduces an innovative approach that elucidates the multi-flow nature of application behavior traffic and provides context to encrypted application traffic. This method offers a more nuanced and comprehensive perspective for understanding and representing network traffic, even when encrypted. The efficacy of our approach was evaluated using a substantial volume of real network traffic data. Results indicate that our method achieves an average accuracy of 0.958 in identifying application behavior traffic and 0.955 in classifying application traffic. These outcomes signify a substantial enhancement over single network flow-based detection methods, demonstrating a notable 5.3% improvement.
Mengmeng Ge 0003, Likun Liu, Xiangzhan Yu, Vinay Sachidananda, Xiaofei Xie, Yang Liu 0003
Cybersecur.5
2025 PRIORITI: scoring and categorization-based threat prioritization
Rajendra Patil 0001, Sivaanandh Muneeswaran, Vinay Sachidananda, Hongyi Peng, Gurusamy Mohan
J. Supercomput.3
2023 ThreatLand: Extracting Intelligence from Audit Logs via NLP methods
abstract
Threat intelligence and hunting using various logs has evolved into a crucial component of remaining aware of the ever-changing threat landscape. Given the critical need to extract useful intelligence from logs, existing techniques either focus exclusively on isolated records, ignoring correlation and the overall threat scenario, or require significant effort to filter and correlate threat records. Additionally, searching for and matching threat behaviors in logs often involves non-trivial human query construction, impeding fast threat hunting. To address this gap, we present ThreatLand, a system that extracts highlevel intelligence and structured threat patterns from audit logs automatically. ThreatLand is composed of three components (1) A lightweight and accurate NLP pipeline that extracts structured meta-data from alert descriptions and generates a heterogeneous graph that depicts the entire threat scenario. (2) A query execution engine that is both fast and efficient, based on a graphical database. (3) A graphical user interface (GUI) that offers various sorts of interactivity to aid intelligence exploration.We have evaluated the ThreatLand over the dataset containing 9240 real-time EDR alerts collected for the threat events over an enterprise setup in the lab. As a result, ThreatLand presents high-level insights from the alert logs and extracts the valuable threat patterns.
Vinay Sachidananda, Rajendra Patil 0001, Hongyi Peng, Yang Liu 0003, Kwok-Yan Lam
PST1
2023 Do NoT Open (DOT): A Unified Generic and Specialized Models for Detecting Malicious Email Attachments
abstract
In this paper, we propose – DOT – a hybrid analysis approach designed for the detection and classification of malicious files. We have developed both a unified single model and specialized models tailored to various file extensions. Our solutions leverage byte-level content analysis to identify malicious elements within documents, along with n-gram analysis. The uniqueness of DOT lies in its ability to significantly reduce computational overhead. We achieve this by employing Rolling Encoder Hashing, which shortens bytecode sequences, making them compatible with state-of-the-art sequence models like Recurrent Neural Networks (RNNs). Additionally, we have created a static analysis-based generic model capable of working with a variety of file types, including.doc,.docx,.xls,.xlsx,.pdf, and more. This model can be efficiently deployed in real-world scenarios. Furthermore, we have developed specialized models for different file types, which are enhanced versions of the generic architecture, streamlining complex maintenance procedures. Another key innovation and novelty of DOT lies in exactly locating the portion of content in the byte code that could contain malicious code, to help security analysts make the binary code analysis more efficient.We conducted extensive experiments using a dataset recently made available by sources like VirusShare, Contagio, and others, specifically intended for academic research. Our dataset comprises a substantial collection of over 156,000 documents, encompassing both malicious and benign files of the most hazardous types observed in recent years. Our findings reveal impressive results, with a unified single model achieving a 91.43% accuracy in distinguishing between benign and malicious documents. Furthermore, specialized models tailored to specific file types exhibit even higher accuracy rates: 96.13% for.doc files, 97.85% for.docx files, 92.62% for.xls files, 97.02% for.xlsx files, and 94.11% for.pdf files, respectively and with a very low false positive rate.
Vinay Sachidananda, Sivaanandh Muneeswaran, Yang Liu 0003, Kwok-Yan Lam
TrustCom1
2023 E-Audit: Distinguishing and investigating suspicious events for APTs attack detection
Rajendra Patil 0001, Sivaanandh Muneeswaran, Vinay Sachidananda, Gurusamy Mohan
J. Syst. Archit.3
2022 Peekaboo: Hide and Seek with Malware Through Lightweight Multi-feature Based Lenient Hybrid Approach
Mingchang Liu, Vinay Sachidananda, Hongyi Peng, Rajendra Patil 0001, Sivaanandh Muneeswaran, Gurusamy Mohan
ICICS2
2022 ODDITY: An Ensemble Framework Leverages Contrastive Representation Learning for Superior Anomaly Detection
Hongyi Peng, Vinay Sachidananda, Teng Joon Lim, Rajendra Patil 0001, Mingchang Liu, Sivaanandh Muneeswaran, Gurusamy Mohan
ICICS2
2022 LOG-OFF: A Novel Behavior Based Authentication Compromise Detection Approach
abstract
Password-based authentication system has been praised for its user-friendly, cost-effective, and easily deployable features. It is arguably the most commonly used security mechanism for various resources, services, and applications. On the other hand, it has well-known security flaws, including vulnerability to guessing attacks. Present state-of-the-art approaches have high overheads, as well as difficulties and unreliability during training, resulting in a poor user experience and a high false positive rate. As a result, a lightweight authentication compromise detection model that can make accurate detection with a low false positive rate is required.In this paper we propose – LOG-OFF – a behavior-based authentication compromise detection model. LOG-OFF is a lightweight model that can be deployed efficiently in practice because it does not include a labeled dataset. Based on the assumption that the behavioral pattern of a specific user does not suddenly change, we study the real-world authentication traffic data. The dataset contains more than 4 million records. We use two features to model the user behaviors, i.e., consecutive failures and login time, and develop a novel approach. LOG-OFF learns from the historical user behaviors to construct user profiles and makes probabilistic predictions of future login attempts for authentication compromise detection. LOG-OFF has a low false positive rate and latency, making it suitable for real-world deployment. In addition, it can also evolve with time and make more accurate detection as more data is being collected.
Mingchang Liu, Vinay Sachidananda, Hongyi Peng, Rajendra Patil 0001, Sivaanandh Muneeswaran, Gurusamy Mohan
PST2
2022 Hiatus: Unsupervised Generative Approach for Detection of DoS and DDoS Attacks
Sivaanandh Muneeswaran, Vinay Sachidananda, Rajendra Patil 0001, Hongyi Peng, Mingchang Liu, Gurusamy Mohan
SecureComm2
2022 MARK: Fill in the blanks through a JointGAN based data augmentation for network anomaly detection
Rajendra Patil 0001, Vinay Sachidananda, Hongyi Peng, Akshay Sachdeva, Gurusamy Mohan
Comput. Secur.2
2020 A novel approach for detecting vulnerable IoT devices connected behind a home NAT
abstract
Telecommunication service providers (telcos) are exposed to cyber-attacks executed by compromised IoT devices connected to their customers’ networks. Such attacks might have severe effects on the attack target, as well as the telcos themselves. To mitigate those risks, we propose a machine learning-based method that can detect specific vulnerable IoT device models connected behind a domestic NAT, thereby identifying home networks that pose a risk to the telcos infrastructure and service availability. To evaluate our method, we collected a large quantity of network traffic data from various commercial IoT devices in our lab and compared several classification algorithms. We found that (a) the LGBM algorithm produces excellent detection results, and (b) our flow-based method is robust and can handle situations for which existing methods used to identify devices behind a NAT are unable to fully address, e.g., encrypted, non-TCP or non-DNS traffic. To promote future research in this domain we share our novel labeled benchmark dataset.
Yair Meidan, Vinay Sachidananda, Hongyi Peng, Racheli Sagron, Yuval Elovici, Asaf Shabtai
Comput. Secur.2
2019 SoftAuthZ: A Context-Aware, Behavior-Based Authorization Framework for Home IoT
abstract
The smart home is one of the most prominent applications in the paradigm of the Internet of Things (IoT). While, it has added a level of comfort and convenience to our everyday life, at the same time, it brings a unique security challenge of mitigating insider threats, posed by legitimate users. Such threats primarily arise due to sharing of IoT devices and the presence of complex social and trust relationships among the users. The state-of-the-art home IoT platforms manage access control by deploying various multifactor authentication mechanisms. Nevertheless, such hard-security measures are inadequate to thwart insider threats, and there is a growing need to integrate user behavior and environmental contexts to make intelligent authorization decisions. In this article, we propose a novel context-sensitive and behavior-based security framework, calledSoftAuthZ, that incorporates soft-security mechanisms, such as belief, confidence, etc., to support authorization decisions. Our framework integrates multiple IoT environment-specific attributes, such as environmental context, nature of the device, requested capabilities (actions), users’ trust levels concerning the home environment, and variability in device access requests into a linear regression model, and computes confidence related to access requests. Such confidence scores can be used by the home IoT platform to make authorization decisions. Extensive analysis and simulation-based performance evaluation validate the efficacy of our framework, demonstrating that it can classify users based on their device usages, and also achieve higher rates of successful authorization.
Nirnay Ghosh, Saket Chandra, Vinay Sachidananda, Yuval Elovici
IEEE Internet Things J.3
2019 Security Testbed for Internet-of-Things Devices
abstract
The Internet of Things (IoT) is a global ecosystem of information and communication technologies aimed at connecting any type of object (thing), at any time, and in any place, to each other and to the Internet. One of the major problems associated with the IoT is the heterogeneous nature of such deployments; this heterogeneity poses many challenges, particularly, in the areas of security and privacy. Specifically, security testing and analysis of IoT devices is considered a very complex task, as different security testing methodologies, including software and hardware security testing approaches, are needed. In this paper, we propose an innovative security testbed framework targeted at IoT devices. The security testbed is aimed at testing all types of IoT devices, with different software/hardware configurations, by performing standard and advanced security testing. Advanced analysis processes based on machine learning algorithms are employed in the testbed in order to monitor the overall operation of the IoT device under test. The architectural design of the proposed security testbed along with a detailed description of the testbed implementation is discussed. The testbed operation is demonstrated on different IoT devices using several specific IoT testing scenarios. The results obtained demonstrate that the testbed is effective at detecting vulnerabilities and compromised IoT devices.
Shachar Siboni, Vinay Sachidananda, Yair Meidan, Michael Bohadana, Yael Mathov, Suhas Bhairav, Asaf Shabtai, Yuval Elovici
IEEE Trans. Reliab.2
2018 SMuF: State Machine Based Mutational Fuzzing Framework for Internet of Things
Neeraj Karamchandani, Vinay Sachidananda, Suhas Setikere, Jianying Zhou 0001, Yuval Elovici
CRITIS2
2018 Out of Kilter: Holistic Exploitation of Denial of Service in Internet of Things
Suhas Setikere, Vinay Sachidananda, Yuval Elovici
SecureComm (1)2
2016 POSTER: Towards Exposing Internet of Things: A Roadmap
abstract
Considering the exponential increase of Internet of Things (IoT) devices there is also unforeseen vulnerabilities associated with these IoT devices. One of the major problems in the IoT is the security testing and analysis due to the heterogeneous nature of deployments. Currently, there is no mechanism that performs security testing for IoT devices in different contexts. In addition, there is a missing framework to be able to adapt and tune accordingly with various security testing perspectives. In this paper, we propose an innovative security testbed targeted at IoT devices and also briefly introduce Adaptable and Tunable Framework (ATF) for testing IoT devices.
Vinay Sachidananda, Jinghui Toh, Shachar Siboni, Asaf Shabtai, Yuval Elovici
CCS1