Kübra Kalkan

dblp:53/9959 · DBLP profile ↗
← Back
19ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0003-1918-8587ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 6 first-author · 9 since 2021Security and privacy · 3
YearPublicationVenuePosition
2026 EDPoS: Energy-aware Delegated Proof of Stake for resource-constrained devices
Arda Hacifevzioglu, Kübra Kalkan
Comput. Networks2
2026 BUDACVAB: Blockchain utilized driver authentication considering various brands for VANETS
abstract
Vehicular Ad-Hoc Networks (VANETs) enable communication between vehicles and infrastructure, supporting various applications that require secure access to sensitive data. Existing authentication approaches in VANETs commonly rely on analyzing driver behavior using vehicle sensor data. However, these approaches suffer from several limitations, including high computational cost, storage constraints, and reduced performance when processing raw driving data. Furthermore, existing solutions do not support secure and interoperable mechanisms for sharing authentication data among different vehicle manufacturers. This limitation remains a critical challenge that needs to be addressed to ensure real-world applicability. This study proposes a blockchain-based authentication framework that enables secure and interoperable driver authentication across heterogeneous vehicle manufacturers. To address storage and performance challenges, Correlation-based Feature Selection (CFS) is applied to reduce the size of raw driving data before storing it on the blockchain. This approach significantly decreases storage requirements while improving system efficiency. Experimental results demonstrate that the proposed framework improves authentication performance, achieving up to 99% accuracy using the KNN algorithm, while also increasing blockchain throughput in terms of Transactions Per Second (TPS). The proposed framework provides a scalable, secure, and efficient solution for cross-manufacturer authentication in VANET environments.
Huseyin Tuncel, Kübra Kalkan
Peer Peer Netw. Appl.2
2025 DiBSeLO: Distributed IoT Blacklisting and Server Location Optimization in Rayleigh Fading Channels
abstract
In this paper, our objectives are two-fold. First, we aim to mitigate the effects of multipath fading in industrial internet of things (IIoT) networks. We propose achieving this by introducing diversity through the utilization of multiple servers. Secondly, we focus on detecting and blacklisting malicious IoT devices within the IIoT network. To accomplish this, we present a distributed blacklisting protocol that leverages machine learning (ML) anomaly detection techniques. Moreover, our protocol operates within a hashgraph network framework, for communicating and storing the blacklisted device information. The accuracy of the blacklisting protocol is improved in a distributed IoT network, since the packets lost in the fading channel are recovered due to diversity reception with multiple servers. Based on real-time packet capture data, various machine learning algorithms are used to classify IoT devices as benign or malicious and perform anomaly detection. Each server individually performs anomaly detection, and submits its results to the hashgraph network. Message queue telemetry transport (MQTT) communications are used by the IoT network, where a consensus of the MQTT servers decides in real-time whether or not to blacklist a device via the hashgraph network. Our distributed blacklisting protocol achieves higher accuracies than the DNS feature composition RF classifier used in [9] as the number of servers increases up to 5. The proposed distributed blacklisting protocol achieves 92.9% accuracy with 5 servers, outperforming that of the literature by 5%. Server placement optimization further boosts accuracy by 5.2%. Optimizing the servers’ locations based on the location of the IoT devices reduces the packet error rate in a Rayleigh fading environment. Server location optimization improves the blacklisting accuracy when compared with the scenario where servers are placed at the centers of equally split partitions of the floor plan. This approach is especially suitable for harsh IIoT, urban, and underground environments.
Ozan Tarlan, Ilgin Safak, Kübra Kalkan
PIMRC3
2025 ZETROS: A zero-trust IoT network security framework using distributed blacklisting, trust scoring and smart contracts
abstract
The purpose of Internet of Things (IoT) security is to ensure the availability, confidentiality, and integrity of IoT networks. However, due to the heterogeneity of IoT devices and the possibility of attacks of various kinds from both inside and outside the network, securing an IoT network is a difficult task. Handshake protocols are useful for achieving mutual authentication, which allows secure inclusion of devices into the network. By verifying that the information they receive is accurate and from a trusted source, mutual authentication minimizes the possibility that a malicious actor will compromise their connections. However, handshake protocols do not protect devices from attackers in the network. Use of autonomous anomaly detection and blacklisting prevents nodes with anomalous behavior from joining, re-joining, or remaining in the network. Similarly, trust scoring is another popular method that can be used to increase the resilience of the network against trust based system attacks. In view of the above, the contributions of this paper are three-fold. First, to ensure the security of the IoT network from outsider attacks in a zero-trust environment, we propose a new handshake protocol based on Physical Unclonable Functions that can be used in IoT device discovery and mutual authentication between the IoT device and the server. The proposed protocol is resilient to Man-in-the-Middle, replay and forgery attacks, as proven in our security analysis. Secondly, we propose a real-time intrusion and anomaly detection framework based on machine learning to prevent network-based attacks from insiders. Finally, we propose a trust system which utilizes feedback mechanisms based on smart contracts for managing the trust of a dynamic IoT network to increase resilience against behavioral attacks. Simulation results show that by using blacklisting, our trust management model provides greater resilience against trust-based attacks compared to similar blockchain-based trust models in the literature, and the proposed distributed IoT network security framework can secure an IoT network from both internal and external attacks, even in an environment where half of the devices in the network are compromised.
Cem Ata Baykara, Ilgin Safak, Kübra Kalkan
Comput. Networks3
2025 Differential privacy preserving based framework using blockchain for internet-of-things
Kübra Kalkan
Peer Peer Netw. Appl.2
2024 EPIoT: Enhanced privacy preservation based blockchain mechanism for internet-of-things
Kübra Kalkan
Comput. Networks2
2024 HostSec: A blockchain-based authentication framework for SDN hosts
Majd Latah, Kübra Kalkan
Peer Peer Netw. Appl.2
2023 IBAM: IPFS and Blockchain based Authentication for MQTT protocol in IoT
abstract
Decentralized systems have proven themselves as a dominant authentication and storage paradigm for IoT systems where smartwatches are integrated with MQTT messaging framework for transmitting medical data to doctors. However, the security concerns with centralized frameworks presented vital security challenges regarding data privacy and network security for healthcare systems. This paper will present an integrated framework involving a reliable and lightweight e-health data-sharing framework that combines the decentralized interplanetary file system (IPFS) and blockchain on a smartwatch platform. Particularly, this framework helps in trustworthy control mechanisms which use smart contracts to achieve authentication and storage for both subscribers and publishers. We presented a simulation using Ethereum blockchain and IPFS in a real data-sharing scenario with the MQTT protocol. Our analysis proved that our approach satisfies lightweight access control requirements since it demonstrates the low latency of the framework and optimized energy consumption with high security and data privacy levels.
Tolga Karadas, Kübra Kalkan
ISCC2
2023 SOREC: Self-organizing and resource efficient clustered blockchain network
Orkun Dogan, Kübra Kalkan
Comput. Networks2
2022 CWT-DPA: Component-wise waiting time for BC-enabled data plane authentication
Majd Latah, Kübra Kalkan
Comput. Networks2
2020 SeCaS: Secure Capability Sharing Framework for IoT Devices in a Structured P2P Network
abstract
The emergence of the internet of Things (IoT) has resulted in the possession of a continuously increasing number of highly heterogeneous connected devices by the same owner. To make full use of the potential of a personal IoT network, there must be secure and effective cooperation between them. While application platforms (e.g., Samsung SmartThings) and interoperable protocols (e.g., MQTT) exist already, the reliance on a central hub to coordinate communication introduces a single-point of failure, provokes bottleneck problems and raises privacy concerns. In this paper we propose SeCaS, a Secure Capability Sharing framework, built on top of a peer-to-peer (P2P) architecture. SeCaS addresses the problems of fault tolerance, scalability and security in resource discovery and sharing for IoT infrastructures using a structured P2P network, in order to take advantage of the self-organised and decentralised communication it provides. SeCaS brings three main contributions: (i) a capability representation that allows each device to specify what services they offer, and can be used as a common language to search for, and exchange, capabilities, resulting in flexible service discovery that can leverage the properties on a distributed hash table (DHT); (ii) a set of four protocols that provides identification of the different devices that exist in the network and authenticity of the messages that are exchanged among them; and (iii) a thorough security and complexity analysis of the proposed scheme that shows SeCaS to be both secure and scalable.
Angeliki Aktypi, Kübra Kalkan, Kasper Bonne Rasmussen
CODASPY2
2020 SUTSEC: SDN Utilized trust based secure clustering in IoT
Kübra Kalkan
Comput. Networks1
2020 TruSD: Trust framework for service discovery among IoT devices
Kübra Kalkan, Kasper Bonne Rasmussen
Comput. Networks1
2018 JESS: Joint Entropy-Based DDoS Defense Scheme in SDN
abstract
Software-defined networking (SDN) is a communication paradigm that brings cost efficiency and flexibility through software-defined functions resident on centralized controllers. Although SDN applications are introduced in a limited scope with related technologies still under development, operational SDN networks already face major security threats. Therefore, comprehensive and efficient solutions are crucial. Especially, large-scale security threats such as distributed-denial-of-service (DDoS) attacks are jeopardizing safety and availability of data and services in these systems. A DDoS attack is aimed at making resources unavailable to legitimate users via overloading systems with excessive superfluous traffic from distributed sources. In this paper, we describe and evaluate a joint entropy-based security scheme (JESS) to enhance the SDN security with the aim of a reinforced SDN architecture against DDoS attacks. In particular, our proposed model devises a statistical solution to detect and mitigate these hazards. To the best of our knowledge, JESS is the first model that utilizes joint entropy for DDoS detection and mitigation in the SDN environment. Since it relies on a statistical model, it mitigates not only known attacks but also unfamiliar types in an efficient manner.
Kübra Kalkan, Levent Altay, Gürkan Gür, Fatih Alagöz
IEEE J. Sel. Areas Commun.1
2017 SDNScore: A statistical defense mechanism against DDoS attacks in SDN environment
abstract
Software Defined Networking (SDN) is a promising solution for addressing challenges of future networks. Despite its advantages such as flexibility, simplification and low costs, it has several drawbacks that are largely induced by the centralized control paradigm. Security is one of the most significant challenges related to centralization. In that regard, Distributed Denial of Service (DDoS) attacks pose crucial security questions in software-defined networks. In SDN architecture, switches send all packets to the controller if they do not have any applicable rules in their flow tables. Basically, controller is the key place that can take initiative in decisions. However, this characteristic results in large communication overhead and delay until a DDoS attack is detected and an appropriate action is activated against attack packets. Therefore, in this work we propose a hybrid mechanism, namely SDNScore, where switches are not simply data forwarders. Instead, they can collect statistics and decide if DDoS attack is in action. Then they coordinate with the controller and act on attack packets in cooperation. SDNScore is a statistical and packet-based defense mechanism against DDoS attacks in SDN environment. Since it has a statistical scoring method, it can detect not only known but also unknown attacks entailing packets that are alike in terms of TCP and IP layer properties. In addition, it does not drop all packets in a flow which includes both attack and legal packets, but rather filters out attack packets using packet-based analysis.
Kübra Kalkan, Gürkan Gür, Fatih Alagöz
ISCC1
2016 A distributed filtering mechanism against DDoS attacks: ScoreForCore
Kübra Kalkan, Fatih Alagöz
Comput. Networks1
2014 Key distribution scheme for peer-to-peer communication in mobile underwater wireless sensor networks
Kübra Kalkan, Albert Levi
Peer-to-Peer Netw. Appl.1
2014 Privacy-Preserving Optimal Meeting Location Determination on Mobile Devices
abstract
Equipped with state-of-the-art smartphones and mobile devices, today's highly interconnected urban population is increasingly dependent on these gadgets to organize and plan their daily lives. These applications often rely on current (or preferred) locations of individual users or a group of users to provide the desired service, which jeopardizes their privacy; users do not necessarily want to reveal their current (or preferred) locations to the service provider or to other, possibly untrusted, users. In this paper, we propose privacy-preserving algorithms for determining an optimal meeting location for a group of users. We perform a thorough privacy evaluation by formally quantifying privacy-loss of the proposed approaches. In order to study the performance of our algorithms in a real deployment, we implement and test their execution efficiency on Nokia smartphones. By means of a targeted user-study, we attempt to get an insight into the privacy-awareness of users in location-based services and the usability of the proposed solutions.
Igor Bilogrevic, Murtuza Jadliwala, Vishal Joneja, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad
IEEE Trans. Inf. Forensics Secur.4
2011 Privacy in Mobile Computing for Location-Sharing-Based Services
Igor Bilogrevic, Murtuza Jadliwala, Kübra Kalkan, Jean-Pierre Hubaux, Imad Aad
PETS3