Shahram Shah-Heydari

dblp:52/3307 · also Shahram Heydari · DBLP profile ↗
← Back
17ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0002-6107-7728ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%
Computer networks
1 paper
Content delivery and video streaming · 77% Network optimization and economics · 23%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Content delivery and video streaming
content delivery network
0.312017
MDP modeling of resource provisioning in virtualized content-delivery networks · ICNP 2017
Cloud and datacenter computing
resource provisioning
0.312017
MDP modeling of resource provisioning in virtualized content-delivery networks · ICNP 2017
Cloud and datacenter computing
stochastic optimization
0.312017
MDP modeling of resource provisioning in virtualized content-delivery networks · ICNP 2017
Network optimization and economics
revenue maximization
0.112017
MDP modeling of resource provisioning in virtualized content-delivery networks · ICNP 2017

Methods — techniques the papers use, named apart from their topics

stochastic optimization · 0.6simulation · 0.6markov decision process · 0.6
YearPublicationVenuePosition
2024 Unknown, Atypical and Polymorphic Network Intrusion Detection: A Systematic Survey
abstract
Agile network security is paramount in our modern world which is currently dominated by Internet systems and expanding digital spaces. This rapid digital transformation has created more opportunities for cyberattackers to exploit different vulnerabilities and launch sophisticated and continuously evolving cyberattacks. Increasingly, intrusion detection systems are relying on new methods based on Machine Learning (ML) and Deep Learning (DL) techniques to detect and mitigate such cyberattacks. While such techniques normally can identify known network attack patterns with a reasonable degree of success, their ability to identify complicated atypical, polymorphic, and unknown attacks is shown to be limited. In this paper, we present a comprehensive survey of recent research for detecting unknown, atypical, and polymorphic network attacks using DL techniques. We further highlight and discuss the main challenges in this area and identify the future research directions.
Ulya Sabeel, Shahram Shah-Heydari, Khalil El-Khatib, Khalid Elgazzar
IEEE Trans. Netw. Serv. Manag.2
2023 Enterprise Application Outage Prediction Using XGBoost and LSTM
abstract
A large percentage of the global GDP is dependent on the Internet servicing millions of applications, therefore monitoring the health of these applications is critical to businesses around the world. To this date, majority of the mechanisms to support applications have all been reactive in nature; that is, reacting when an application goes down and the business has suffered financial loss. The use of Machine Learning in this space has been very limited until very recently. In this paper, we aim to employ a multi-modal model in determining the health of an application based on several tangible metrics from the infrastructure. Our results indicate that our method is able to predict the health of the application successfully.
Shahram Shah-Heydari
CNSM2
2023 Analyzing the Quality of Synthetic Adversarial Cyberattacks
abstract
Today's networked systems face significant security challenges due to sophisticated attacks. Several Machine Learning (ML) and Deep Learning (DL) models are employed to combat these diverse attacks. Adversarial attacks, which can evade detection by AI-based intrusion detection systems (IDS) through small alterations to network attack traffic, pose a significant concern. These AI-synthesized adversarial attacks must adhere to network constraints to seem plausible. In this work, we explore the validation criteria for such adversarial attacks and propose a methodology for analyzing their quality. We evaluate adversarial attack samples synthesized by state-of-the-art generative DL models such as Variational autoencoder (VAE), Conditional Variational autoencoder (CVAE), Generative Adversarial Network (GAN) and compare the performance with our CVAE-Adversarial Network (CVAE-AN) model. Results indicate the effectiveness of CVAE-AN in synthesizing realistic adversarial attacks.
Ulya Sabeel, Shahram Shah-Heydari, Khalil El-Khatib, Khalid Elgazzar
CNSM2
2021 CVAE-AN: Atypical Attack Flow Detection Using Incremental Adversarial Learning
abstract
Network Intrusion Detection Systems (NIDS) are powerful tools for identifying and deterring cybersecurity attacks nowadays. However, while these modern IDS can detect typical attacks, recent studies show their poor performances in identifying unknown or dynamically changing atypical attacks. Another issue with the training aspect of such systems is the problem of class imbalance which impedes their performance, especially for minority attack classes. This renders IDS systems vulnerable to both adversarial as well as non-AI synthesized atypical attacks when deployed in a real network. To reduce misclassification (especially for minority classes) and detect atypical attack flows, we propose a novel adversarial incremental learning approach based on a hybrid model consisting of a Conditional Variational Autoencoder (CVAE) and a Generative Adversarial Network (GAN) namely, CVAE-Adversarial Network (CVAE-AN). The binary IDS has been trained using the CICIDS2017 dataset and evaluated using multiple atypical attacks. Simulation results demonstrate that the proposed technique significantly improves the performance of the IDS against different atypical attacks and outperforms the state-of-the-art detection models as well as class balancing methods.
Ulya Sabeel, Shahram Shah-Heydari, Khalid Elgazzar, Khalil El-Khatib
GLOBECOM2
2020 Polymorphic Adversarial DDoS attack on IDS using GAN
abstract
Intrusion Detection systems are important tools in preventing malicious traffic from penetrating into networks and systems. Recently, Intrusion Detection Systems are rapidly enhancing their detection capabilities using machine learning algorithms. However, these algorithms are vulnerable to new unknown types of attacks that can evade machine learning IDS. In particular, they may be vulnerable to attacks based on Generative Adversarial Networks (GAN). GANs have been widely used in domains such as image processing, natural language processing to generate adversarial data of different types such as graphics, videos, texts, etc. We propose a model using GAN to generate adversarial DDoS attacks that can change the attack profile and can be undetected. Our simulation results indicate that by continuous changing of attack profile, defensive systems that use incremental learning will still be vulnerable to new attacks.
Ravi Chauhan, Shahram Shah-Heydari
ISNCC2
2019 QoE-Aware Real-Time Multimedia Streaming in SD-WANs
abstract
The exponential increase in bandwidth-sensitive multimedia traffic on the net has given rise to new challenges and services. There is a need to have quality management measures to serve the high needs of efficient transmission and delivery in time-constrained environments over IP networks. Quality of Experience is one of the major techniques introduced to achieve the goals of application efficiency and user satisfaction from an end-user perspective. By utilizing crowdsourcing techniques, QoE becomes more cost-efficient and easier to measure. In this paper, we propose a framework that takes real time QoE feedback and forwards it to SD-WAN controllers in order to enhance streaming routes based on realtime user quality perceptions. We analyze how QoE can be affected by different streaming protocols and which streaming protocols perform better with imposing QoS quality changes.
Ibtihal Ellawindy, Shahram Shah-Heydari
NetSoft2
2017 MDP modeling of resource provisioning in virtualized content-delivery networks
abstract
In this paper a Markov decision process (MDP) model for virtualized content delivery networks is proposed. We use stochastic optimization to assign cloud site resources to each user group. We propose how quality of experience (QoE) can be included in the modeling and optimization. We then present an optimal solution for a constraint-free version of the problem, and show the improvement in accumulated revenue when our optimization model is used. A sub-optimal algorithm is proposed that would reduce the complexity of the problem. Simulation results are presented to support merits of the proposed algorithm.
Ali A. Haghighi, Shahram Shah-Heydari, Shahram Shahbazpanahi
ICNP2
2017 An analysis of the Collection Tree Protocol (CTP) in mobile sensing environments
abstract
The Collection Tree Protocol (CTP) is widely used for data collection in wireless sensor network applications due to its simplicity and its capability to dynamically adapt to ad-hoc changes in the network even though it is designed for static networks. With the increasing deployment of mobile wireless sensor networks, the performance of this scheme in mobile scenarios becomes extremely important. The motivation in using collection style protocols in mobile sensor networks is that the sensors primarily send data to key collecting nodes, and often there is no need for the more complex Mobile and Ad hoc routing protocols that are typically used in MANETs or the formation of clusters. Our objective in this paper is to provide a detailed analysis of the shortcomings of CTP in mobile scenarios, and to propose changes to CTP to improve its performance in mobile scenarios. This is done by a comprehensive simulation study of CTP's performance in mobile sensor environments, and identify root causes for its performance degradation in mobile scenarios. We also study the impact of introducing a mix of mobile and fixed nodes in a CTP network and evaluate how their presence improves network performance. Our results show that the performance of CTP in mobile environments. We conclude with proposed changes to CTP that improve its performance in mobile scenarios.
Nadra Ben Otman, Ramiro Liscano, Shahram Shah-Heydari
PIMRC3
2016 Optimization of SDN Flow Operations in Multi-Failure Restoration Scenarios
abstract
Flexible network configuration in software-defined networks makes it possible to dynamically restore flows. To this end, network devices carry out flow operations (i.e., adding or removing flow-entries to/from the flow-tables) to re-route the disrupted flows. Current flow restoration techniques do not consider the number of operations, and hence, are inefficient in disaster scenarios. We aim to minimize the number of operations in such cases and formulate integer programs to find a path: 1) with the lowest path cost requiring up to a given number of operations; 2) requiring the fewest possible operations; and 3) with a Dijkstra-like path cost requiring minimum operations. We study the tradeoff between path cost and the number of operations and prove that the second and third problems are polynomial-time solvable. We propose optimal/suboptimal algorithms with Dijkstra-like complexity that find nearly-optimal solutions. The simulation results show that our methods reduce the number of operations up to 50%, and the best performance is achieved when the number of failed links is small.
Saeed Akhavan-Astaneh, Shahram Shah-Heydari
IEEE Trans. Netw. Serv. Manag.2
2014 Proactive risk mitigation for communication network resilience in disaster scenarios
abstract
The impact of natural disasters can be catastrophic for communication networks and may cause significant costs for service providers and subscribers. Dynamic spreading of failures in natural disasters follows a time-varying probabilistic pattern, which requires a dynamic probabilistic response to mitigate the effect of failures. In this paper we examine the preventive protection scheme as an effective dynamic probabilistic solution to address large-scale failure scenarios and provide an algorithm to adjust probabilistic decision-making parameters. The proposed scheme can be used by network operators to adjust decision parameters in a preventive protection model to decrease the number of disrupted connections in an effective way. Reducing the number of damaged connections may lead to increased network resiliency level, which is the main concern in large-scale failure scenarios caused by natural disasters.
Alireza Izaddoost, Shahram Shah-Heydari
WoWMoM2
2013 Predictive Filtering for Adjacency-Based Localization in MANET
abstract
The Network layer adjacency information in ad-hoc networks can be used for a coarse estimation of the location of mobile sensor nodes in such networks. This method may be particularly useful for collecting approximate location information for a situational awareness system without taking too much bandwidth. However, past research has shown that the accuracy of this method is limited. In this paper, we explore the use of predictive filtering methods for improving the accuracy of adjacency-based coarse localization in MANETs. Using the fact that a mobile node would have a continuous path with smooth physical transitions, we treat abrupt turns and irregular jumps in estimated nodal speeds as noise, and explore the possibility of minimizing this noise by applying predictive filtering techniques. We examine and compare moving average, Kalman filtering and finally a hybrid method, and use simulations to show that a hybrid predictive filtering method could improve the accuracy of coarse localizations significantly.
Abdullah Alshehri 0002, Shahram Shah-Heydari
DCOSS2
2012 OLSR-based coarse localization in tactical MANET situational awareness systems
abstract
This paper presents a multi-node 2-dimensional distributed technique for coarse (approximate) localization of the nodes in a tactical mobile ad-hoc network. The objective of this work is to provide coarse localization information based on layer-3 connectivity information and a few anchor nodes or landmarks, without using traditional methods such as signal strength, Time of Arrival (ToA) or distance information. We propose a localization algorithm based on a force-directed method that will allow us to estimate the approximate location of each node based on network topology information from a local OLSR database with enhancement from known landmarks as reference points. We assume the majority of nodes are not equipped with GPS and thus do not have their exact location information. A simulation based-analysis is conducted to evaluate our proposed approach. The results of this study show that the proposed approach can provide a reasonable and fast approximation of the location of the mobile node for use in situational awareness systems.
Z. M. Faizul Islam, Mitchell Romanuik, Shahram Shah-Heydari, Mazda Salmanian
ICC3
2009 Heuristic algorithms for designing self-repairing protection trees in mesh networks
Shahram Shah-Heydari, Oliver W. W. Yang
Comput. Networks1
2007 Performance study of multiple link failure restorability of shared protection trees
abstract
In this paper we examine multiple failure restorability performance of self-repairing shared trees for local link restoration in unicast mesh networks. We demonstrate how these shared hierarchical protection trees could be utilized to effectively handle multiple consecutive link failures with minimal reconfiguration. We evaluate the restorability performance using simulation of random graphs and present the results of second- and third-failure restorability as well as the required redundancy to achieve various restorability targets.
Shahram Shah-Heydari, Oliver W. W. Yang
BROADNETS1
2007 Performance study of self-repairing unicast hierarchical protection trees in mesh networks
abstract
Protection trees have been used in the past for protecting multicast and unicast traffic in networks in various scenarios. In this paper we focus on shared protection trees for link protection in unicast mesh networks. We present a heuristic algorithm that reduces the redundant capacity required for protection on shared trees, and improves the restorability of the network. We use simulation of random mesh graphs to compute the performance improvement for various network sizes.
Shahram Shah-Heydari, Oliver W. W. Yang
BROADNETS1
2004 Multiple failure analysis with restoration paths matrix
abstract
The paper studies the concept of restoration paths (RP) matrix for analysis and performance evaluation of link restoration schemes. The RP matrix provides a very useful tool for computing single, double and multiple failure analysis of network restorability. It can be constructed for any link restoration scheme, regardless of unique scheme architecture or pattern. For this reason, the RP matrix can be used to compare various link restoration schemes. We present a description of the RP matrix, provide examples of it for well-known network architectures, and compute mathematical formulas to calculate various performance parameters of the network from network topology info and the RP matrix.
Shahram Shah-Heydari, Oliver W. W. Yang
GLOBECOM1
2004 Theoretical analysis of restorability of Hamiltonian protection cycles in random mesh networks
abstract
This paper presents an analytical study of preplanned protection cycles (p-cycles) in mesh optical networks. We mathematically define and calculate the total network restorability for a Hamiltonian p-cycle in the case where the working and protection capacities of a network are fixed and uniformly distributed. The dependency of the total network restorability on various network parameters such as network size and the ratio of maximum to minimum link capacity in the network are discussed in detail. We present analytical and simulation results for random and real networks to show the remarkable accuracy of our analysis.
Shahram Shah-Heydari, Wail Mardini, Oliver W. W. Yang
ISCC1