Muhammad Asim 0001

dblp:45/7278-1 · DBLP profile ↗
← Back
25ranked-venue papers
3as first author
12since 2021 · last 2027
0000-0002-2894-7891ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 3 since 2021Computer networks · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 2 since 2021Security and privacy · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2027 Lightweight and privacy-aware decentralized identity management for Industrial Internet of Things applications
abstract
Next-generation industrial networks incorporate diverse devices and technologies, including cloud- and fog-based systems and large-scale Industrial Internet of Things (IIoT) applications. These heterogeneous environments comprise thousands of sensors, actuators, controllers, and geographically distributed zones, posing significant challenges for authentication mechanisms that must scale while remaining secure and practical under real industrial conditions. Current blockchain-based decentralized identity-management systems are characterized by high transaction overhead, reliance on computationally intensive cryptographic operations, and partial dependence on trusted entities, all of which limit their scalability and practical deployment. To address these issues, in this paper, we propose a lightweight, blockchain-based identity-management solution that integrates epoch- and batch-based registration with sparse Merkle trees (SMTs). Device registrations are grouped into fixed epochs, and cryptographic costs are amortized across multiple devices to substantially reduce per-device overhead. The SMT structure generates verifiable, reusable proofs that preserve privacy while enabling efficient verification; sensitive device information is never revealed during authentication. Fog nodes act as decentralized verifiers, supporting distributed trust without continuous interaction with the blockchain. Experimental results show that the system can be practically deployed on Raspberry Pi and ESP32 devices, reliably perform identification with around 1000 total messages, and operate at the tested upper bound of 7000 devices distributed over 20 fog nodes, all while keeping the blockchain storage overhead under 5 MB.
Muhammad Asim 0001, Noshina Tariq, Ali Ismail Awad, Fahad Waheed, Saad Bukhari, Abdul Rafay, Houbing Song
Future Gener. Comput. Syst.1
2026 An efficient and reliable mechanism for Wormhole detection in RPL based IoT networks
Jawad Hassan, Muhammad Yousaf Ali Raza, Adnan Sohail, Muhammad Asim 0001, Zeeshan Pervez
Comput. Networks4
2025 Integrating system calls and position-specific scoring for enhanced anomaly detection in Internet of Things environments
abstract
Identifying attacks on Internet of Things (IoT) systems through anomaly detection is an effective approach and remains a crucial area of research. The core method involves collecting system-related data during normal operation to establish a baseline of typical behavior and then continuously monitoring for deviations from this baseline. Using system call sequences for anomaly detection is a well-established and important field. System call sequences effectively capture the behavior of a target system at a low level, allowing identification of any changes in this behavior; however, these approaches face several challenges, including high false-positive rates, the need for segmentation of long sequences, and the difficulty of detecting anomalies when the system call data comes from multiple processes. This work presents a novel anomaly-detection approach that uses a position-specific scoring mechanism to analyze the content and structural properties of system call sequences. The proposed approach addresses key challenges in this field, including fixed-length segmentation of system call sequences, predetermined anomaly-detection thresholds, the detection of anomalies in both single and multiple processes, and high false-positive rates. We extensively evaluated the proposed approach using system-call-specific public datasets (ADFA-LD and UNM) of a diverse nature. The performance of the proposed content-based, structure-based, and combined content- and structure-based anomaly-detection methods was evaluated using ten-fold cross-validation. The proposed anomaly-detection approach achieves an impressive detection rate of 1.0, along with exceptionally low false-positive rates of 0.001 and 0.017 when evaluated on the UNM and ADFA-LD datasets, respectively.
Nouman Shamim, Muhammad Asim 0001, Thar Baker, Zeeshan Pervez, Ali Ismail Awad, Albert Y. Zomaya
Comput. Secur.2
2025 Anomaly Detection in Internet of Things System Calls Using a Centroid-Based Vector-Space Model
abstract
Identifying attacks on Internet of Things (IoT) systems through anomaly detection remains a critical area of research. One common and effective strategy in this field involves monitoring system-related data during normal operation to establish a baseline of expected behavior, followed by continuous monitoring to identify deviations from this baseline. System call sequences, which provide a low-level representation of the behavior of a system, are widely regarded as a valuable resource for anomaly detection; however, challenges such as the categorical nature of system call data, inconsistencies in sequence lengths, repeating patterns, and the diversity of activities across single-and multi-process environments complicate the effectiveness of existing methods. To address these challenges, we propose a centroid-based anomaly detection approach that transforms IoT system call data into word vectors, creating a central vector to represent normal behavior. A weighted vector-space model is then used to set a threshold distance for distinguishing between normal and malicious sequences. The effectiveness of the proposed method is evaluated across three distinct datasets: the Australian Defense Force Academy Linux Dataset (ADFA-LD) and the University of New Mexico (UNM) datasets, including UNM-Sendmail and UNM-Line Printer Remote (LPR). The method surpasses existing approaches on the ADFA-LD dataset, achieving an accuracy of 99.02%, a false-positive rate (FPR) of 1.96%, and an area under the receiver operating characteristic curve (AUC) of 0.9923. For the UNM datasets, the performance metrics indicate a detection accuracy of 99.7%, an FPR of 0.28%, and an AUC of 0.9983. The average processing time was measured as 1–3 ms. The experimental results and subsequent analysis reveal promising performance, demonstrating the generalizability of the proposed method across various datasets.
Nouman Shamim, Muhammad Asim 0001, Ali Ismail Awad, Muhammad Khurram Khan
IEEE Internet Things J.2
2025 SecT: A Zero-Trust Framework for Secure Remote Access in Next-Generation Industrial Networks
abstract
Next-generation industrial networks are designed to integrate a wide range of devices, services, and applications spanning multiple technologies, such as cloud platforms, edge computing, and the Internet of Things. With the growing adoption of applications such as “Industry 4.0,” high security and low latency are becoming unavoidable requirements for these networks. Traditional virtual private networks (VPNs) generally experience performance, latency, and security issues, especially when supporting secure remote access for Industry 4.0 and ehealth applications. To address these issues, this study introduces a novel zero-trust network-access framework for next-generation industrial networks called Secure Transmission (SecT). SecT is a User Datagram Protocol (UDP)-based solution, ensuring speed and effectiveness, with role-based access control. It uses a centralized management interface that can adapt to various network environments, providing secure access to mission-critical applications and increasing operational agility. SecT aims to meet the emerging demands of modern industrial networks, offering secure access with improved performance. The results of a comparative analysis show that SecT outperforms traditional VPNs in both capability and flexibility, adapting well to new network conditions.
Muhammad Asim 0001, Noshina Tariq, Ali Ismail Awad, Fahad Waheed
IEEE J. Sel. Areas Commun.1
2025 Intelligent framework of sustainable cyber-physical services for autonomous manufacturing industries
abstract
Abstract Product Service Systems (PSSs) introduce new business models for enterprises to promote tangible products along with intangible functions or services, thereby incentivising product sustainability with profitability, economic stability and customer satisfaction. However, the unique characteristics of a PSS challenge obsolete product development processes and demand a dynamic change in the complex building blocks of the underlying design and in the development infrastructure to attain high quality services. This implies a need for radical change in the team structure and the team collaboration model, in the organizational structure, technical infrastructure and in the complex process models by taking the complete product life cycle into consideration. This paper, firstly, identifies PSS unique features that challenge the capabilities of existing frameworks to design a standard PSS. In response, new business models are proposed to address the challenges relating to actors’ involvement, technology provision, organizational needs and process workflow modelling. Secondly, these proposed business models are combined into one comprehensive collaborative PSS design and development methodology by modifying existing modelling techniques. An assessment framework based on Goal-Question-Metrics approach and McCall Quality Model is successfully used to evaluate the PSS development methodology and subsequently, the developed framework through a use-case study analysis.
Shamaila Iram, Terrence Fernando, Muhammad Asim 0001, Hafiz Muhammad Shakeel
Serv. Oriented Comput. Appl.3
2024 DivaCAN: Detecting in-vehicle intrusion attacks on a controller area network using ensemble learning
Muneeb Hassan Khan, Abdul Rehman Javed, Muhammad Asim 0001, Ali Ismail Awad
Comput. Secur.4
2022 A blockchain-based Fog-oriented lightweight framework for smart public vehicular transportation systems
Thar Baker, Muhammad Asim 0001, Hezekiah Samwini, Nauman Shamim, Mohammed M. Alani, Rajkumar Buyya
Comput. Networks2
2022 Machine learning and the Internet of Things security: Solutions and open challenges
Noshina Tariq, Muhammad Asim 0001, Thar Baker, Ahmed Al-Shamma'a
J. Parallel Distributed Comput.3
2022 Feature engineering and deep learning-based intrusion detection framework for securing edge IoT
Muneeba Nasir, Abdul Rehman Javed, Muhammad Adnan Tariq, Muhammad Asim 0001, Thar Baker
J. Supercomput.4
2021 Orchestration- and choreography-based composition of Internet of Transactional Things
Zakaria Maamar, Muhammad Asim 0001, Saoussen Cheikhrouhou, Ayesha Qamar
Serv. Oriented Comput. Appl.2
2021 Intelligent Control and Security of Fog Resources in Healthcare Systems via a Cognitive Fog Model
abstract
There have been significant advances in the field of Internet of Things (IoT) recently, which have not always considered security or data security concerns: A high degree of security is required when considering the sharing of medical data over networks. In most IoT-based systems, especially those within smart-homes and smart-cities, there is a bridging point (fog computing) between a sensor network and the Internet which often just performs basic functions such as translating between the protocols used in the Internet and sensor networks, as well as small amounts of data processing. The fog nodes can have useful knowledge and potential for constructive security and control over both the sensor network and the data transmitted over the Internet. Smart healthcare services utilise such networks of IoT systems. It is therefore vital that medical data emanating from IoT systems is highly secure, to prevent fraudulent use, whilst maintaining quality of service providing assured, verified and complete data. In this article, we examine the development of a Cognitive Fog (CF) model, for secure, smart healthcare services, that is able to make decisions such as opting-in and opting-out from running processes and invoking new processes when required, and providing security for the operational processes within the fog system. Overall, the proposed ensemble security model performed better in terms of Accuracy Rate, Detection Rate, and a lower False Positive Rate (standard intrusion detection measurements) than three base classifiers (K-NN, DBSCAN, and DT) using a standard security dataset (NSL-KDD).
Mohammed Al-Khafajiy, Safa Otoum, Thar Baker, Muhammad Asim 0001, Zakaria Maamar, Moayad Aloqaily, Mark Taylor 0005, Martin Randles
ACM Trans. Internet Techn.4
2020 Thingsourcing to Enable IoT Collaboration
abstract
This paper presents thingsourcing to enable thing collaboration in the context of IoT. Compared to crowdsourcing that refers to a crowd of persons, there is limited research in thingsourcing which deprives things from participating in complex business applications. In this paper, thingsourcing is associated with a platform that acts as an IoT marketplace where things sign-up and sign-off looking for opportunities to complete users' demands. The platform also has a set of mechanisms that allow to describe, search for, and “glue” things together. For demonstration purposes a car service center is used illustrating how things like service bays and vehicles collaborate in compliance with scripts defined in ComPOS (Composition language for Palcom Oblivious Services).
Zakaria Maamar, Khouloud Boukadi, Bamory Koné, Muhammad Asim 0001, Djamal Benslimane, Said Elnaffar
WETICE4
2020 DeepDetect: Detection of Distributed Denial of Service Attacks Using Deep Learning
abstract
Abstract At the advent of advanced wireless technology and contemporary computing paradigms, Distributed Denial of Service (DDoS) attacks on Web-based services have not only increased exponentially in number, but also in the degree of sophistication; hence the need for detecting these attacks within the ocean of communication packets is extremely important. DDoS attacks were initially projected toward the network and transport layers. Over the years, attackers have shifted their offensive strategies toward the application layer. The application layer attacks are potentially more detrimental and stealthier because of the attack traffic and the benign traffic flows being indistinguishable. The distributed nature of these attacks is difficult to combat as they may affect tangible computing resources apart from network bandwidth consumption. In addition, smart devices connected to the Internet can be infected and used as botnets to launch DDoS attacks. In this paper, we propose a novel deep neural network-based detection mechanism that uses feed-forward back-propagation for accurately discovering multiple application layer DDoS attacks. The proposed neural network architecture can identify and use the most relevant high level features of packet flows with an accuracy of 98% on the state-of-the-art dataset containing various forms of DDoS attacks.
Muhammad Asad 0006, Muhammad Asim 0001, Talha Javed, Mirza Omer Beg, Hasan Mujtaba, Sohail Abbas
Comput. J.2
2020 COMITMENT: A Fog Computing Trust Management Approach
Mohammed Al-Khafajiy, Thar Baker, Muhammad Asim 0001, Zehua Guo 0001, Rajiv Ranjan 0001, Antonella Longo, Deepak Puthal, Mark Taylor 0005
J. Parallel Distributed Comput.3
2020 A hybrid anomaly-based intrusion detection system to improve time complexity in the Internet of Energy environment
Thomas Rose 0004, Kashif Kifayat, Sohail Abbas, Muhammad Asim 0001
J. Parallel Distributed Comput.4
2020 A secure fog-based platform for SCADA-based IoT critical infrastructure
abstract
Summary The rapid proliferation of Internet of things (IoT) devices, such as smart meters and water valves, into industrial critical infrastructures and control systems has put stringent performance and scalability requirements on modern Supervisory Control and Data Acquisition (SCADA) systems. While cloud computing has enabled modern SCADA systems to cope with the increasing amount of data generated by sensors, actuators, and control devices, there has been a growing interest recently to deploy edge data centers in fog architectures to secure low‐latency and enhanced security for mission‐critical data. However, fog security and privacy for SCADA‐based IoT critical infrastructures remains an under‐researched area. To address this challenge, this contribution proposes a novel security “toolbox” to reinforce the integrity, security, and privacy of SCADA‐based IoT critical infrastructure at the fog layer. The toolbox incorporates a key feature: a cryptographic‐based access approach to the cloud services using identity‐based cryptography and signature schemes at the fog layer. We present the implementation details of a prototype for our proposed secure fog‐based platform and provide performance evaluation results to demonstrate the appropriateness of the proposed platform in a real‐world scenario. These results can pave the way toward the development of a more secure and trusted SCADA‐based IoT critical infrastructure, which is essential to counter cyber threats against next‐generation critical infrastructure and industrial control systems. The results from the experiments demonstrate a superior performance of the secure fog‐based platform, which is around 2.8 seconds when adding five virtual machines (VMs), 3.2 seconds when adding 10 VMs, and 112 seconds when adding 1000 VMs, compared to the multilevel user access control platform.
Thar Baker, Muhammad Asim 0001, Áine MacDermott, Farkhund Iqbal, Faouzi Kamoun, Babar Shah, Omar Alfandi, Mohammad Hammoudeh
Softw. Pract. Exp.2
2019 Fairness in Real-Time Energy Pricing for Smart Grid Using Unsupervised Learning
abstract
The capabilities of the Smart Grid coupled with dynamic pricing enables the Smart Grid to adaptively manage the electricity generation and distribution. Several dynamic real-time pricing schemes have been proposed in recent times but few have been successfully implemented despite their economic and environmental benefits. In particular, the current real-time pricing schemes have not been able to incentivize subscribers to respond to time-varying prices in order for the smart-grid to fully benefit from such pricing. Traditional pricing schemes failed to incorporate fairness for end-users because real-time data gathering was expensive and impractical before smart devices were incorporated into the grid. In this paper, we propose a novel dynamic pricing model, fair dynamic pricing (FDP), to maintain reliable power supply during times of peak demand. The proposed model is analyzed and evaluated using a real-time consumer load dataset from San Diego, CA, USA. We demonstrate that in periods of peak load, the burden of generating expensive electricity is placed on subscribers responsible for creating the peaks rather than being subsidized by the remaining subscribers. Our results show that FDP improves the rates of low-demand subscribers by 18.4% and charges a penalty of up to 34% to high-demand subscribers for 400 sample observations. This percentage varies with the number of subscribers in the system during an interval and real-time prices.
Hafiz Tayyeb Javed, Mirza Omer Beg, Hasan Mujtaba, Hammad Majeed, Muhammad Asim 0001
Comput. J.5
2019 A Mobile Code-driven Trust Mechanism for detecting internal attacks in sensor node-powered IoT
Noshina Tariq, Muhammad Asim 0001, Zakaria Maamar, Muhammad Zubair Farooqi, Noura Faci, Thar Baker
J. Parallel Distributed Comput.2
2019 Remote health monitoring of elderly through wearable sensors
abstract
Due to a rapidly increasing aging population and its associated challenges in health and social care, Ambient Assistive Living has become the focal point for both researchers and industry alike. The need to manage or even reduce healthcare costs while improving the quality of service is high government agendas. Although, technology has a major role to play in achieving these aspirations, any solution must be designed, implemented and validated using appropriate domain knowledge. In order to overcome these challenges, the remote real-time monitoring of a person’s health can be used to identify relapses in conditions, therefore, enabling early intervention. Thus, the development of a smart healthcare monitoring system, which is capable of observing elderly people remotely, is the focus of the research presented in this paper. The technology outlined in this paper focuses on the ability to track a person’s physiological data to detect specific disorders which can aid in Early Intervention Practices. This is achieved by accurately processing and analysing the acquired sensory data while transmitting the detection of a disorder to an appropriate career. The finding reveals that the proposed system can improve clinical decision supports while facilitating Early Intervention Practices. Our extensive simulation results indicate a superior performance of the proposed system: low latency (96% of the packets are received with less than 1 millisecond) and low packets-lost (only 2.2% of total packets are dropped). Thus, the system runs efficiently and is cost-effective in terms of data acquisition and manipulation.
Mohammed Al-Khafajiy, Thar Baker, Carl Chalmers, Muhammad Asim 0001, Hoshang Kolivand, Muhammad Fahim, Atif Waraich
Multim. Tools Appl.4
2018 Thing Federation as a Service: Foundations and Demonstration
Zakaria Maamar, Khouloud Boukadi, Emir Ugljanin, Thar Baker, Muhammad Asim 0001, Mohammed Al-Khafajiy, Djamal Benslimane, Hasna El Alaoui El Abdallaoui
MEDI5
2018 Security policy monitoring of BPMN-based service compositions
abstract
Abstract Service composition is a key concept of Service‐Oriented Architecture that allows for combining loosely coupled services that are offered and operated by different service providers. Such environments are expected to dynamically respond to changes that may occur at runtime, including changes in the environment and individual services themselves. Therefore, it is crucial to monitor these loosely coupled services throughout their lifetime. In this paper, we present a novel framework for monitoring services at runtime and ensuring that services behave as they have promised. In particular, we focus on monitoring non‐functional properties that are specified within an agreed security contract. The novelty of our work is based on the way in which monitoring information can be combined from multiple dynamic services to automate the monitoring of business processes and proactively report compliance violations. The framework enables monitoring of both atomic and composite services and provides a user friendly interface for specifying the monitoring policy. We provide an information service case study using a real composite service to demonstrate how we achieve compliance monitoring. The transformation of security policy into monitoring rules, which is done automatically, makes our framework more flexible and accurate than existing techniques.
Muhammad Asim 0001, Artsiom Yautsiukhin, Achim D. Brucker, Thar Baker, Qi Shi 0001, Brett Lempereur
J. Softw. Evol. Process.1
2017 An energy-aware service composition algorithm for multiple cloud-based IoT applications
Thar Baker, Muhammad Asim 0001, Hissam Tawfik, Bandar Aldawsari, Rajkumar Buyya
J. Netw. Comput. Appl.2
2013 Prototype for design-time secure and trustworthy service composition
abstract
Service-oriented environments provide the opportunity for services from different providers to work together, forming new composite services via composition of existing services. However, in addition to the intended outcomes, composition also introduces the potential for unexpected or emergent behaviour, resulting in new uncertainties, especially in the area of security. Funded by the European FP7 programme, our research focusses on providing a service composition platform that is secure and trustworthy. We will demonstrate the design-time prototype that show how to create service compositions, verify them against security policies and make sensible recommendations based on a user's security preferences.
Bo Zhou 0001, David Llewellyn-Jones, Qi Shi 0001, Muhammad Asim 0001, Madjid Merabti
CCNC4
2013 An event processing approach for threats monitoring of service compositions
abstract
The Future Internet will be populated by not just data and devices, but also services. Approaches in Service-Oriented Architectures are allowing new ways for users and developers to manage, control and benefit from the services that are being made available. However, this also introduces new threats for service ecosystems and with wider deployment comes a greater need to identify and tackle threats before they become attacks. In this paper we introduce a new Threat Monitoring approach based on filtering and pattern-detection of a variety of event types. The approach enables threat monitoring across multiple composite services with a capability to integrate dynamic changes from various subsystems and offers high flexibility through the use of CEP (Complex Event Processing). Appropriate events are identified in the context of Service-Oriented Architectures and the Threat Monitoring Module described and implemented as part of the Aniketos platform. This module is able to pull threat descriptions from a repository and apply appropriate detection techniques at run-time in order to identify potential problems. The approach is novel in both its flexibility and applicability. Threats can be chosen by service developers from a community-managed repository and the process extends to both the identification and prediction of threats. The solution is evaluated through a future telecommunication services case study.
Dhouha Ayed, Muhammad Asim 0001, David Llewellyn-Jones
CRiSIS2