Ali Dehghantanha

dblp:54/8100 · also Ali Dehghan Tanha · DBLP profile ↗
← Back
61ranked-venue papers
3as first author
28since 2021 · last 2026
0000-0002-9294-7554ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 12 since 2021Systems, architecture and hardware · 15 · 3 since 2021Security and privacy · 12 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Beyond the prompt: Log-based threat detection and attribution for multi-Agent LLMs
Elnaz Rabieinejad, Fattane Zarrinkalam, Ali Dehghantanha
Inf. Process. Manag.3
2025 Uncovering the Persuasive Fingerprint of LLMs in Jailbreaking Attacks
abstract
Despite recent advances, Large Language Models (LLMs) remain vulnerable to jailbreak attacks that bypass alignment safeguards and elicit harmful outputs. While prior research has proposed various attack strategies differing in human readability and transferability, little attention has been paid to the linguistic and psychological mechanisms that may influence a model's susceptibility to such attacks. In this paper, we examine an interdisciplinary line of research that leverages foundational theories of persuasion from the social sciences to craft adversarial prompts capable of circumventing alignment constraints in LLMs. Drawing on well-established persuasive strategies, we hypothesize that LLMs, having been trained on large-scale human-generated text, may respond more compliantly to prompts with persuasive structures. Furthermore, we investigate whether LLMs themselves exhibit distinct persuasive fingerprints that emerge in their jailbreak responses. Empirical evaluations across multiple aligned LLMs reveal that persuasion-aware prompts significantly bypass safeguards, demonstrating their potential to induce jailbreak behaviors. This work underscores the importance of cross-disciplinary insight in addressing the evolving challenges of LLM safety. The code and data are available. https://github.com/CyberScienceLab/Our-Papers/tree/main/PersuasiveJailbreaking/.
Havva Alizadeh Noughabi, Julien Serbanescu, Fattane Zarrinkalam, Ali Dehghantanha
CIKM4
2025 TrollSleuth: Behavioral and Linguistic Fingerprinting of State-Sponsored Trolls
abstract
Social media has emerged as a key arena for statesponsored disinformation campaigns, where coordinated troll accounts disseminate false narratives and manipulate public discourse. While existing research has primarily focused on detecting such troll accounts, this paper introduces the novel concept of Troll Attribution, drawing on principles from cyber threat attribution. We propose TrollSleuth, a comprehensive framework for attributing troll activity to state sponsors by analyzing linguistic and behavioral fingerprints. Our method integrates four analytical modules-Social Engagement, Word Analysis, Emotion and Sentiment Analysis, and Temporal Activity and Client Utilization Analysis-to extract distinctive features from real-world Twitter data spanning four state-sponsored campaigns. The resulting model achieves a high F1-score of $\mathbf{9 5. 4 8 \%}$ in state-sponsor identification and incorporates featurebased explanations to enhance interpretability. These findings offer actionable insights for strategic intelligence, supporting the detection and deterrence of disinformation operations, informing legal and diplomatic responses, and reinforcing defenses against state-sponsored influence campaigns. The code used in this study is publicly available.11https://github.com/CyberScienceLab/Our-Papers/tree/main/TrollSleuth/
Havva Alizadeh Noughabi, Fattane Zarrinkalam, Abbas Yazdinejad, Ali Dehghantanha
PST4
2025 Symbiotic Federated Learning for Giant AI Threat Detection in 6G-IoT Infrastructures
abstract
The increasing demand for intelligent, privacy-aware, and scalable solutions at the edge of the network is accelerating the convergence of Giant AI models and Internet of Things (IoT) infrastructures in 6G environments. In this article, we propose a symbiotic threat detection framework that unifies federated learning (FL), graph neural networks (GNNs), and HE to enable decentralized anomaly detection across distributed 6G-enabled IoT ecosystems. Our approach addresses key challenges in current cloud-centric architectures, including data privacy, communication efficiency, and lack of interpretability in AI-driven threat detection. The proposed framework, SymFL-GNN, supports collaborative learning among IoT devices while retaining data locally, leveraging the PHC to ensure gradient-level encryption. To enhance interpretability, a dynamic sensor graph is constructed using self-learned embeddings and attention mechanisms, allowing the model to pinpoint anomalous behaviors and their sources. We evaluate our framework on two real-world industrial datasets (SWaT and WADI) representing cyber-physical water systems, achieving 96.3% and 96.0% accuracy, respectively, with significant improvements over existing baselines in both precision and F1 score. Our results show that SymFL-GNN effectively balances local autonomy with global intelligence, supporting the vision of symbiotic AI at the edge. The framework demonstrates how 6G-enabled IoT networks can jointly contribute to and benefit from Giant AI models, laying the foundation for secure, intelligent, and privacy-preserving distributed systems in critical infrastructure and consumer environments.
Hedyeh Nazari, Abbas Yazdinejad, Ali Dehghantanha, Fattane Zarrinkalam, Gautam Srivastava 0001
IEEE Internet Things J.3
2024 AutonomousCyber '24 - Workshop on Autonomous Cybersecurity
abstract
Autonomous cybersecurity represents a significant evolution in information security, where systems independently detect, respond to, and neutralize cyber threats without the need for human intervention. This level of autonomy is a more advanced stage in cybersecurity, enabling systems not only to execute tasks but also to interpret contexts, make decisions, and adapt strategies in realtime. The shift towards autonomy promises enhanced adaptability, faster response times, and a reduction in human error. This domain stands out for its unique blend of advanced Machine Learning (ML) systems such as Reinforcement Learning (RL)-driven and Quantum Machine Learning (QML)-based agents with cybersecurity automation techniques such as automated patch management systems, automated incident response systems to forge self-reliant cybersecurity systems. The AutonomousCyber workshop provides a venue for presenting and discussing new developments in this field.
Ali Dehghantanha, Reza M. Parizi, Gregory Epiphaniou
CCS1
2024 A GNN-Based Adversarial Internet of Things Malware Detection Framework for Critical Infrastructure: Studying Gafgyt, Mirai, and Tsunami Campaigns
abstract
Significant advancement in Deep learning (DL) has turned it into an integral part of robust approaches for addressing cybersecurity problems in both current and aging infrastructures. Control Flow Graphs (CFGs) have demonstrated their effectiveness as leading choices that result in high-performing classifiers among various data representations used by DL-based models. Recently, Graph Neural Networks (GNNs) have made breakthroughs in the graph domain, and before long, they were jointly used with CFGs to train performant malware classifiers. However, graph-based adversarial attacks have caused suspicion about the predictions these graph-based malware classifiers make, and few studies have investigated detecting such attacks. Therefore, this paper proposes a novel GNN-based adversarial detector for identifying adversarial CFGs with higher efficacy than the previous work. This adversarial detector is placed in a data pipeline before a GNN-based malware classifier. In this paper, we solve the adversarial detection problem as an anomaly detection scenario and train the adversarial detector to learn the normal data distribution. Our GNN-based adversarial detector detects 98.96% of all adversarial CFGs, which is 1.17% higher than the previous method, with a 5.95% lower False Positive Rate (FPR). In the most hazardous category of the attack, where the attacker intends to render a malicious example as a benign input, we achieve a 4.85% boost compared to the previous competitors.
Bardia Esmaeili, Amin Azmoodeh, Ali Dehghantanha, Gautam Srivastava 0001, Hadis Karimipour, Jerry Chun-Wei Lin
IEEE Internet Things J.3
2024 Hybrid Privacy Preserving Federated Learning Against Irregular Users in Next-Generation Internet of Things
Abbas Yazdinejad, Ali Dehghantanha, Gautam Srivastava 0001, Hadis Karimipour, Reza M. Parizi
J. Syst. Archit.2
2024 A Robust Privacy-Preserving Federated Learning Model Against Model Poisoning Attacks
abstract
Although federated learning offers a level of privacy by aggregating user data without direct access, it remains inherently vulnerable to various attacks, including poisoning attacks where malicious actors submit gradients that reduce model accuracy. In addressing model poisoning attacks, existing defense strategies primarily concentrate on detecting suspicious local gradients over plaintext. However, detecting non-independent and identically distributed encrypted gradients poses significant challenges for existing methods. Moreover, tackling computational complexity and communication overhead becomes crucial in privacy-preserving federated learning, particularly in the context of encrypted gradients. To address these concerns, we propose a robust privacy-preserving federated learning model resilient against model poisoning attacks without sacrificing accuracy. Our approach introduces an internal auditor that evaluates encrypted gradient similarity and distribution to differentiate between benign and malicious gradients, employing a Gaussian Mixture Model and Mahalanobis Distance for byzantine-tolerant aggregation. The proposed model utilizes Additive Homomorphic Encryption to ensure confidentiality while minimizing computational and communication overhead. Our model demonstrates superior performance in accuracy and privacy compared to existing strategies and encryption techniques, such as Fully Homomorphic Encryption and Two-Trapdoor Homomorphic Encryption. The proposed model effectively addresses the challenge of detecting maliciously encrypted non-independent and identically distributed gradients with low computational and communication overhead.
Abbas Yazdinejad, Ali Dehghantanha, Hadis Karimipour, Gautam Srivastava 0001, Reza M. Parizi
IEEE Trans. Inf. Forensics Secur.2
2023 An ensemble deep federated learning cyber-threat hunting model for Industrial Internet of Things
Amir Namavar Jahromi, Hadis Karimipour, Ali Dehghantanha
Comput. Commun.3
2023 Generative Adversarial Networks for Cyber Threat Hunting in Ethereum Blockchain
abstract
Ethereum blockchain has shown great potential in providing the next generation of the decentralized platform beyond crypto payments. Recently, it has attracted researchers and industry players to experiment with developing various Web3 applications for the Internet of Things (IoT), Defi, Metaverse, and many more. Although Ethereum provides a secure platform for developing decentralized applications, it is not immune to security risks and has been a victim of numerous cyber attacks. Adversarial attacks are a new cyber threat to systems that have been rising. Adversarial attacks can disrupt and exploit decentralized applications running on the Ethereum platform by creating fake accounts and transactions. Detecting adversarial attacks is challenging because the fake materials (e.g., accounts and transactions) as malicious payloads are similar to benign data. This article proposes a model using Generative Adversarial Networks (GAN) and Deep Recurrent Neural Networks (RNN) for cyber threat hunting in the Ethereum blockchain. Firstly, we employ GAN to generate fake transactions using genuine Ethereum transactions as the first phase of the proposed model. Then in the second phase, we utilize bi-directional Long Short-Term Memory (LSTM) to identify adversarial transactions in a hunting exercise. The results of the first phase evaluation show that the GAN can generate transactions identical to the actual Ethereum transactions with an accuracy of 82.51%. Also, the results of the second phase show 99.98% accuracy in identifying adversarial transactions.
Elnaz Rabieinejad, Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha
Distributed Ledger Technol. Res. Pract.4
2023 An optimized fuzzy deep learning model for data classification based on NSGA-II
Abbas Yazdinejad, Ali Dehghantanha, Reza M. Parizi, Gregory Epiphaniou
Neurocomputing2
2022 Federated-Learning-Based Anomaly Detection for IoT Security Attacks
abstract
The Internet of Things (IoT) is made up of billions of physical devices connected to the Internet via networks that perform tasks independently with less human intervention. Such brilliant automation of mundane tasks requires a considerable amount of user data in digital format, which, in turn, makes IoT networks an open source of personally identifiable information data for malicious attackers to steal, manipulate, and perform nefarious activities. A huge interest has been developed over the past years in applying machine learning (ML)-assisted approaches in the IoT security space. However, the assumption in many current works is that big training data are widely available and transferable to the main server because data are born at the edge and are generated continuously by IoT devices. This is to say that classic ML works on the legacy set of entire data located on a central server, which makes it the least preferred option for domains with privacy concerns on user data. To address this issue, we propose the federated-learning (FL)-based anomaly detection approach to proactively recognize intrusion in IoT networks using decentralized on-device data. Our approach uses federated training rounds on gated recurrent units (GRUs) models and keeps the data intact on local IoT devices by sharing only the learned weights with the central server of FL. Also, the approach’s ensembler part aggregates the updates from multiple sources to optimize the global ML model’s accuracy. Our experimental results demonstrate that our approach outperforms the classic/centralized machine learning (non-FL) versions in securing the privacy of user data and provides an optimal accuracy rate in attack detection.
Viraaji Mothukuri, Prachi Khare, Reza M. Parizi, Seyed Amin Pouriyeh, Ali Dehghantanha, Gautam Srivastava 0001
IEEE Internet Things J.5
2022 A Self-Tuning Cyber-Attacks' Location Identification Approach for Critical Infrastructures
abstract
The integration of the communications network and the Internet of Things in today’s critical infrastructures facilitates intelligent and online monitoring of these systems. However, although critical infrastructure’s digitalization brings tremendous advantages and opportunities for remote access and control, it significantly increases cyber-attack’s vulnerability. Therefore, efficient and proper detection and localization of cyber-attack are paramount for the critical infrastructure’s reliable and secure operation. This article proposes a deep learning-based cyber-attack detection and location identification system for critical infrastructures by constructing new representations and model the system behavior using multilayer autoencoders. The results show that the new representations capture the physical relationships among the measurements and have more discriminant power in distinguishing the location of the attack. Furthermore, the proposed method has outperformed conventional machine learning models under various cyber-attack scenarios using real-world data from the gas pipeline and water distribution supervisory control and data acquisition systems.
Abdulrahman Al-Abassi, Amir Namavar Jahromi, Hadis Karimipour, Ali Dehghantanha, Pierluigi Siano, Henry Leung 0001
IEEE Trans. Ind. Informatics4
2022 IIoT Deep Malware Threat Hunting: From Adversarial Example Detection to Adversarial Scenario Detection
abstract
Protecting widely used deep classifiers against black-box adversarial attacks is a recent research challenge in many security-related areas, including malware classification. This class of attacks relies on optimizing a sequence of highly similar queries to bypass given classifiers. In this article, we leverage this property and propose a history-based method named,stateful query analysis (SQA), which analyzes sequences of queries received by a malware classifier to detect black-box adversarial attacks on an industrial Internet of Things (IIoT). In the SQA pipeline, there are two components, namely the similarity encoder and the classifier, both based on convolutional neural networks. Unlike the state-of-the-art methods, which aim to identify individual adversarial examples, tracking the history of queries allows our method to identify adversarial scenarios and abort attacks before their completion. We optimize SQA using different combinations of hyperparameters on an advanced risc machine (ARM)-based IIoT malware dataset, widely adopted for malware threat hunting in industry 4.0. The use of a novel distance metric in calculating the loss function of the similarity encoder results in more disentangled representations and improves the performance of our method. Our evaluations demonstrate the validity of SQA via a detection rate of 93.1% over a wide range of adversarial examples.
Bardia Esmaeili, Amin Azmoodeh, Ali Dehghantanha, Hadis Karimipour, Behrouz Zolfaghari, Mohammad Hammoudeh
IEEE Trans. Ind. Informatics3
2022 Block Hunter: Federated Learning for Cyber Threat Hunting in Blockchain-Based IIoT Networks
abstract
Nowadays, blockchain-based technologies are being developed in various industries to improve data security. In the context of the Industrial Internet of Things (IIoT), a chain-based network is one of the most notable applications of blockchain technology. IIoT devices have become increasingly prevalent in our digital world, especially in support of developing smart factories. Although blockchain is a powerful tool, it is vulnerable to cyberattacks. Detecting anomalies in blockchain-based IIoT networks in smart factories is crucial in protecting networks and systems from unexpected attacks. In this article, we use federated learning to build a threat hunting framework called block hunter to automatically hunt for attacks in blockchain-based IIoT networks. Block hunter utilizes a cluster-based architecture for anomaly detection combined with several machine learning models in a federated environment. To the best of our knowledge, block hunter is the first federated threat hunting model in IIoT networks that identifies anomalous behavior while preserving privacy. Our results prove the efficiency of the block hunter in detecting anomalous activities with high accuracy and minimum required bandwidth.
Abbas Yazdinejad, Ali Dehghantanha, Reza M. Parizi, Mohammad Hammoudeh, Hadis Karimipour, Gautam Srivastava 0001
IEEE Trans. Ind. Informatics2
2021 Deep Federated Learning-Based Cyber-Attack Detection in Industrial Control Systems
abstract
Due to the differences between Information Technology (IT) and Industrial Control System (ICS) networks, current IT security solutions are not working effectively on ICS networks. Moreover, due to security and privacy issues, ICS owners usually do not share their network data with third parties to train specific machine learning-based ICS security solutions. To rectify the mentioned issues, a scalable deep federated learning-based method is presented in this paper. In the proposed method, each client trains an unsupervised deep neural network model using local data and shares its parameters with a server. The server aggregates the clients’ parameters, makes a generalized public model, and shares it with all clients. The proposed model is evaluated using a real-world ICS dataset in a water treatment system and compared with two non-federated learning-based methods. Findings show that the proposed method outperformed the other two methods with the same computational complexity as other deep neural network-based methods in the literature.
Amir Namavar Jahromi, Hadis Karimipour, Ali Dehghantanha
PST3
2021 SteelEye: An Application-Layer Attack Detection and Attribution Model in Industrial Control Systems using Semi-Deep Learning
abstract
The security of Industrial Control Systems is of high importance as they play a critical role in uninterrupted services provided by Critical Infrastructure operators. Due to a large number of devices and their geographical distribution, Industrial Control Systems need efficient automatic cyber-attack detection and attribution methods, which suggests us AI-based approaches. This paper proposes a model called SteelEye based on Semi-Deep Learning for accurate detection and attribution of cyber-attacks at the application layer in industrial control systems. The proposed model depends on Bag of Features for accurate detection of cyber-attacks and utilizes Categorical Boosting as the base predictor for attack attribution. Empirical results demonstrate that SteelEye remarkably outperforms state-of-the-art cyber-attack detection and attribution methods in terms of accuracy, precision, recall, and Fl-score.
Sanaz Nakhodchi, Behrouz Zolfaghari, Abbas Yazdinejad, Ali Dehghantanha
PST4
2021 Generative adversarial network to detect unseen Internet of Things malware
Zahra Moti, Sattar Hashemi, Hadis Karimipour, Ali Dehghantanha, Amir Namavar Jahromi, Lida Abdi, Fatemeh Alavi
Ad Hoc Networks4
2021 Federated learning for drone authentication
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Hadis Karimipour
Ad Hoc Networks3
2021 A kangaroo-based intrusion detection system on software-defined networks
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Mohammad S. Khan
Comput. Networks3
2021 A survey of machine learning techniques in adversarial image forensics
Ehsan Nowroozi, Ali Dehghantanha, Reza M. Parizi, Kim-Kwang Raymond Choo
Comput. Secur.2
2021 A survey on security and privacy of federated learning
Viraaji Mothukuri, Reza M. Parizi, Seyed Amin Pouriyeh, Yan Huang 0032, Ali Dehghantanha, Gautam Srivastava 0001
Future Gener. Comput. Syst.5
2021 A Multikernel and Metaheuristic Feature Selection Approach for IoT Malware Threat Hunting in the Edge Layer
abstract
Internet-of-Things (IoT) devices are increasingly targeted, partly due to their presence in a broad range of applications (including home and corporate environments). In this article, we propose a multikernel support vector machine (SVM) for IoT cloud-edge gateway malware hunting, using the gray wolves optimization (GWO) technique. This metaheuristic approach is used for optimum selection of features distinguishing between malicious and benign applications at the IoT cloud-edge gateway. The model is trained with the Opcode and Bytecode of IoT malware samples (i.e., the training data set comprises 271 benign and 281 malicious Cortex A9 samples) and evaluated using the K-fold cross-validation technique. We validate the robustness of the proposed model, in terms of its ability to detect previously unseen IoT malware samples. We achieve an accuracy of 99.72% on the combination of the radial basis function (RBF) and polynomial kernels. Moreover, our proposed model only requires 20 s for training in comparison to the previous deep neural network (DNN) model that requires over 80 s to be trained on the same data. Overall, the proposed multikernel SVM approach outperforms DNNs and fuzzy-based IoT malware hunting techniques, in terms of accuracy, while significantly reducing the computational cost and the training time.
Hamed Haddad Pajouh, Alireza Mohtadi, Ali Dehghantanha, Hadis Karimipour, Xiaodong Lin 0001, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2021 Toward Detection and Attribution of Cyber-Attacks in IoT-Enabled Cyber-Physical Systems
abstract
Securing Internet-of-Things (IoT)-enabled cyber-physical systems (CPS) can be challenging, as security solutions developed for general information/operational technology (IT/OT) systems may not be as effective in a CPS setting. Thus, this article presents a two-level ensemble attack detection and attribution framework designed for CPS, and more specifically in an industrial control system (ICS). At the first level, a decision tree combined with a novel ensemble deep representation-learning model is developed for detecting attacks imbalanced ICS environments. At the second level, an ensemble deep neural network is designed to facilitate attack attribution. The proposed model is evaluated using real-world data sets in gas pipeline and water treatment system. Findings demonstrate that the proposed model outperforms other competing approaches with similar computational complexity.
Amir Namavar Jahromi, Hadis Karimipour, Ali Dehghantanha, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2021 Enabling Drones in the Internet of Things With Decentralized Blockchain-Based Security
abstract
There is currently widespread use of drones and drone technology due to their rising applications that have come into fruition in the military, safety surveillance, agriculture, smart transportation, shipping, and delivery of packages in our Internet-of-Things global landscape. However, there are security-specific challenges with the authentication of drones while airborne. The current authentication approaches, in most drone-based applications, are subject to latency issues in real time with security vulnerabilities for attacks. To address such issues, we introduce a secure authentication model with low latency for drones in smart cities that looks to leverage blockchain technology. We apply a zone-based architecture in a network of drones, and use a customized decentralized consensus, known as drone-based delegated proof of stake (DDPOS), for drones among zones in a smart city that does not require reauthentication. The proposed architecture aims for positive impacts on increased security and reduced latency on the Internet of Drones (IoD). Moreover, we provide an empirical analysis of the proposed architecture compared to other peer models previously proposed for IoD to demonstrate its performance and security authentication capability. The experimental results clearly show that not only does the proposed architecture have low packet loss rate, high throughput, and low end-to-end delay in comparison to peer models but also can detect 97.5% of attacks by malicious drones while airborne.
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Hadis Karimipour, Gautam Srivastava 0001, Mohammed Aledhari
IEEE Internet Things J.3
2021 Introduction to the Special Issue on Decentralized Blockchain Applications and Infrastructures for Next Generation Cyber-Physical Systems
abstract
introduction Introduction to the Special Issue on Decentralized Blockchain Applications and Infrastructures for Next Generation Cyber-Physical Systems Share on Editors: Kim Kwang Raymond Choo University of Texas at San Antonio University of Texas at San AntonioView Profile , Uttam Ghosh Vanderbilt University Vanderbilt UniversityView Profile , Deepak Tosh University of Texas El Paso University of Texas El PasoView Profile , Reza M. Parizi Kennesaw State University Kennesaw State UniversityView Profile , Ali Dehghantanha University of Guelph University of GuelphView Profile Authors Info & Claims ACM Transactions on Internet TechnologyVolume 21Issue 2June 2021 Article No.: 38epp 1–3https://doi.org/10.1145/3464768Online:15 June 2021Publication History 0citation68DownloadsMetricsTotal Citations0Total Downloads68Last 12 Months68Last 6 weeks5 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Kim-Kwang Raymond Choo, Uttam Ghosh, Deepak K. Tosh, Reza M. Parizi, Ali Dehghantanha
ACM Trans. Internet Techn.5
2021 A Flow-based Multi-agent Data Exfiltration Detection Architecture for Ultra-low Latency Networks
abstract
Modern network infrastructures host converged applications that demand rapid elasticity of services, increased security, and ultra-fast reaction times. The Tactile Internet promises to facilitate the delivery of these services while enabling new economies of scale for high fidelity of machine-to-machine and human-to-machine interactions. Unavoidably, critical mission systems served by the Tactile Internet manifest high demands not only for high speed and reliable communications but equally, the ability to rapidly identify and mitigate threats and vulnerabilities. This article proposes a novel Multi-Agent Data Exfiltration Detector Architecture (MADEX), inspired by the mechanisms and features present in the human immune system. MADEX seeks to identify data exfiltration activities performed by evasive and stealthy malware that hides malicious traffic from an infected host in low-latency networks. Our approach uses cross-network traffic information collected by agents to effectively identify unknown illicit connections by an operating system subverted. MADEX does not require prior knowledge of the characteristics or behavior of the malicious code or a dedicated access to a knowledge repository. We tested the performance of MADEX in terms of its capacity to handle real-time data and the sensitivity of our algorithm’s classification when exposed to malicious traffic. Experimental evaluation results show that MADEX achieved 99.97% sensitivity, 98.78% accuracy, and an error rate of 1.21% when compared to its best rivals. We created a second version of MADEX, called MADEX level 2, that further improves its overall performance with a slight increase in computational complexity. We argue for the suitability of MADEX level 1 in non-critical environments, while MADEX level 2 can be used to avoid data exfiltration in critical mission systems. To the best of our knowledge, this is the first article in the literature that addresses the detection of rootkits real-time in an agnostic way using an artificial immune system approach while it satisfies strict latency requirements.
Rafael Salema Marques, Gregory Epiphaniou, Haider M. Al-Khateeb, Carsten Maple, Mohammad Hammoudeh, Paulo André Lima de Castro, Ali Dehghantanha, Kim-Kwang Raymond Choo
ACM Trans. Internet Techn.7
2021 Editorial for the Special Issue on Sustainable Cyber Forensics and Threat Intelligence
abstract
The papers in this special issue focus on sustainable cyber forensics and threat intelligence. Increasing societal reliance on interconnected digital systems, including smart grids and Internet of Things (IoT), made sustainable detection and investigation of threat actors among the highest priorities of any society. Scale and attack surface of modern networks mandate optimized deployment of limited cyber forensics and threat intelligence resources to detect and remove malicious actors in a timely manner. However, timely dealing with such a huge number of attacks is not possible without employment of artificial intelligence and machine learning techniques. When a significant amount of data is collected from or generated by different security monitoring solutions, intelligent big-data analytical techniques are necessary to mine, interpret and extract knowledge out of those data. The emerging field of cyber threat intelligence is investigating applications of artificial intelligence and machine learning techniques to perceive, reason, learn and act intelligently against advanced cyber attacks. A crucial success factor in implementation, installation and deployment of threat intelligence and cyber forensics capacities in modern networks is sustainability.
Giuseppe Bianchi 0001, Mauro Conti, Tooska Dargahi, Ali Dehghantanha
IEEE Trans. Sustain. Comput.4
2020 A Deep Recurrent Neural Network to Support Guidelines and Decision Making of Social Distancing
abstract
The recent Covid-19 pandemic instigated many changes in our way of life within the United States, and slowly but surely we are working towards mitigating the virus. Due to Covid-19, there are higher demands for models to accurately forecast the number of Covid-19 cases that factor mandated guidelines such as social-distancing. Many scholarly and corporate research entities are investigating ways to achieve this goal preemptively; Unfortunately, current models are not yet able to accurately model future Covid-19 cases that factor in various guidelines; What is lacking with these models is an understanding of crucial factors affecting spread, accuracy, availability of reported cases on a small scale, and quantifiable metrics for how social distancing and quarantine efforts mitigate the spread. Therefore, the goal of this study is to produce a mathematical model to directly aid policy decisions by comparing predicted models of various decisions and social distancing protocols. This model can be applied on top of existing models to factor in more imminent data and produce predictive curves, indicating troughs and peaks of new daily Covid-19 cases with comparatively high accuracy, which can aid in analysis. These predictive curves can, therefore, be generated using data corresponding to projected responses to proposed guidelines and compared to each other to choose the optimal solution for “flattening the curve” of the Covid19 infection rate. We use an LSTM-RNN model with ANN Regression in an attempt to predict future Covid-19 cases. Our model achieved comparable results, but further improvements could be implemented for more optimal results.
Mohammed Aledhari, Rehma Razzak, Reza M. Parizi, Ali Dehghantanha
IEEE BigData4
2020 SLPoW: Secure and Low Latency Proof of Work Protocol for Blockchain in Green IoT Networks
abstract
Traditional Internet of Things (IoT) system architectures are centralized. Data from the devices are stored on the back-end, where they are processed and analyzed, and then reconnected to IoT devices. The scalability of centralized systems is very limited especially when an abundance of devices exist on an IoT network. Network security in IoT networks is another aspect at stake that could be compromised easily due to the unavailability of security in design mechanisms in most IoT networks. Blockchain technology is a distributed ledger without any intensive management that can store all transactions which leads to large amounts of data that increases over time. Large data amounts will be more pronounced with the increasing IoT devices and blockchain use cases involving IoT. IoT devices are for the most part constrained in both energy, storage, and computation, unlikely to be able to store all blockchain data. The current implementation of blockchain is not IoT friendly. Moreover, consensus on the blockchain using Proof of Work (PoW) is infeasible due to computational constraints. In this paper, we propose a Secure and Low latency Proof of Work (SLPoW) protocol. We also bring the computation of miners onto a Field-programmable gate array (FPGA) to improve the processing speeds of computation. We consider our resulting blockchain technology using SLPoW suitable for the evolving Green IoT setting.
Abbas Yazdinejad, Gautam Srivastava 0001, Reza M. Parizi, Ali Dehghantanha, Hadis Karimipour, Somayeh Razaghi Karizno
VTC Spring4
2020 An improved two-hidden-layer extreme learning machine for malware hunting
Amir Namavar Jahromi, Sattar Hashemi, Ali Dehghantanha, Kim-Kwang Raymond Choo, Hadis Karimipour, David Ellis Newton, Reza M. Parizi
Comput. Secur.3
2020 Blockchain smart contracts formalization: Approaches and challenges to address vulnerabilities
Amritraj Singh, Reza M. Parizi, Qi Zhang 0009, Kim-Kwang Raymond Choo, Ali Dehghantanha
Comput. Secur.5
2020 P4-to-blockchain: A secure blockchain-enabled packet parser for software defined networking
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Kim-Kwang Raymond Choo
Comput. Secur.3
2020 An opcode-based technique for polymorphic Internet of Things malware detection
abstract
Summary The increasing popularity of Internet of Things (IoT) devices makes them an attractive target for malware authors. In this paper, we use sequential pattern mining technique to detect most frequent opcode sequences of malicious IoT applications. Detected maximal frequent patterns (MFP) of opcode sequences can be used to differentiate malicious from benign IoT applications. We then evaluate the suitability of MFPs as a classification feature for K nearest neighbors (KNN), support vector machines (SVM), multilayer perceptron (MLP), AdaBoost, decision tree, and random forest classifier. Specifically, we achieve an accuracy rate of 99% in the detection of unseen IoT malware. We also demonstrate the utility of our approach in detecting polymorphed IoT malware samples.
Hamid Darabian, Ali Dehghantanha, Sattar Hashemi, Sajad Homayoun, Kim-Kwang Raymond Choo
Concurr. Comput. Pract. Exp.2
2020 Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis
Hamid Darabian, Sajad Homayoun, Ali Dehghantanha, Sattar Hashemi, Hadis Karimipour, Reza M. Parizi, Kim-Kwang Raymond Choo
J. Grid Comput.3
2020 An Ensemble of Deep Recurrent Neural Networks for Detecting IoT Cyber Attacks Using Network Traffic
abstract
Internet-of-Things (IoT) devices and systems will be increasingly targeted by cybercriminals (including nation state-sponsored or affiliated threat actors) as they become an integral part of our connected society and ecosystem. However, the challenges in securing these devices and systems are compounded by the scale and diversity of deployment, the fast-paced cyber threat landscape, and many other factors. Thus, in this article, we design an approach using advanced deep learning to detect cyber attacks against IoT systems. Specifically, our approach integrates a set of long short-term memory (LSTM) modules into an ensemble of detectors. These modules are then merged using a decision tree to arrive at an aggregated output at the final stage. We evaluate the effectiveness of our approach using a real-world data set of Modbus network traffic and obtain an accuracy rate of over 99% in the detection of cyber attacks against IoT devices.
Mahdis Saharkhizan, Amin Azmoodeh, Ali Dehghantanha, Kim-Kwang Raymond Choo, Reza M. Parizi
IEEE Internet Things J.3
2020 Sidechain technologies in blockchain networks: An examination and state-of-the-art review
Amritraj Singh, Kelly Click, Reza M. Parizi, Qi Zhang 0009, Ali Dehghantanha, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.5
2020 A high-performance framework for a network programmable packet processor using P4 and FPGA
Abbas Yazdinejad, Reza M. Parizi, Ali Bohlooli, Ali Dehghantanha, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.4
2020 Cost optimization of secure routing with untrusted devices in software defined networking
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Gautam Srivastava 0001, Senthilkumar Mohan, Abedallah M. Rababah
J. Parallel Distributed Comput.3
2020 AI4SAFE-IoT: an AI-powered secure architecture for edge layer of Internet of things
Hamed Haddad Pajouh, Raouf Khayami, Ali Dehghantanha, Kim-Kwang Raymond Choo, Reza M. Parizi
Neural Comput. Appl.3
2020 A Multilabel Fuzzy Relevance Clustering System for Malware Attack Attribution in the Edge Layer of Cyber-Physical Networks
abstract
The rapid increase in the number of malicious programs has made malware forensics a daunting task and caused users’ systems to become in danger. Timely identification of malware characteristics including its origin and the malware sample family would significantly limit the potential damage of malware. This is a more profound risk in Cyber-Physical Systems (CPSs), where a malware attack may cause significant physical damage to the infrastructure. Due to limited on-device available memory and processing power in CPS devices, most of the efforts for protecting CPS networks are focused on the edge layer, where the majority of security mechanisms are deployed. Since the majority of advanced and sophisticated malware programs are combining features from different families, these malicious programs are not similar enough to any existing malware family and easily evade binary classifier detection. Therefore, in this article, we propose a novel multilabel fuzzy clustering system for malware attack attribution. Our system is deployed on the edge layer to provide insight into applicable malware threats to the CPS network. We leverage static analysis by utilizing Opcode frequencies as the feature space to classify malware families. We observed that a multilabel classifier does not classify a part of samples. We named this problem the instance coverage problem. To overcome this problem, we developed an ensemble-based multilabel fuzzy classification method to suggest the relevance of a malware instance to the stricken families. This classifier identified samples of VirusShare, RansomwareTracker, and BIG2015 with an accuracy of 94.66%, 94.26%, and 97.56%, respectively.
Mohammad Hadi Alaeiyan, Ali Dehghantanha, Tooska Dargahi, Mauro Conti, Saeed Parsa
ACM Trans. Cyber Phys. Syst.2
2020 Decentralized Authentication of Distributed Patients in Hospital Networks Using Blockchain
abstract
In any interconnected healthcare system (e.g., those that are part of a smart city), interactions between patients, medical doctors, nurses and other healthcare practitioners need to be secure and efficient. For example, all members must be authenticated and securely interconnected to minimize security and privacy breaches from within a given network. However, introducing security and privacy-preserving solutions can also incur delays in processing and other related services, potentially threatening patients lives in critical situations. A considerable number of authentication and security systems presented in the literature are centralized, and frequently need to rely on some secure and trusted third-party entity to facilitate secure communications. This, in turn, increases the time required for authentication and decreases throughput due to known overhead, for patients and inter-hospital communications. In this paper, we propose a novel decentralized authentication of patients in a distributed hospital network, by leveraging blockchain. Our notion of a healthcare setting includes patients and allied health professionals (medical doctors, nurses, technicians, etc), and the health information of patients. Findings from our in-depth simulations demonstrate the potential utility of the proposed architecture. For example, it is shown that the proposed architecture's decentralized authentication among a distributed affiliated hospital network does not require re-authentication. This improvement will have a considerable impact on increasing throughput, reducing overhead, improving response time, and decreasing energy consumption in the network. We also provide a comparative analysis of our model in relation to a base model of the network without blockchain to show the overall effectiveness of our proposed solution.
Abbas Yazdinejad, Gautam Srivastava 0001, Reza M. Parizi, Ali Dehghantanha, Kim-Kwang Raymond Choo, Mohammed Aledhari
IEEE J. Biomed. Health Informatics4
2020 Threats on the horizon: understanding security threats in the era of cyber-physical systems
abstract
Abstract Disruptive innovations of the last few decades, such as smart cities and Industry 4.0, were made possible by higher integration of physical and digital elements. In today’s pervasive cyber-physical systems, connecting more devices introduces new vulnerabilities and security threats. With increasing cybersecurity incidents, cybersecurity professionals are becoming incapable of addressing what has become the greatest threat climate than ever before. This research investigates the spectrum of risk of a cybersecurity incident taking place in the cyber-physical-enabled world using the VERIS Community Database. The findings were that the majority of known actors were from the US and Russia, most victims were from western states and geographic origin tended to reflect global affairs. The most commonly targeted asset was information, with the majority of attack modes relying on privilege abuse. The key feature observed was extensive internal security breaches, most often a result of human error. This tends to show that access in any form appears to be the source of vulnerability rather than incident specifics due to a fundamental trade-off between usability and security in the design of computer systems. This provides fundamental evidence of the need for a major reevaluation of the founding principles in cybersecurity.
Steven Walker-Roberts, Mohammad Hammoudeh, Omar Aldabbas 0001, Mehmet Emin Aydin, Ali Dehghantanha
J. Supercomput.5
2020 An Energy-Efficient SDN Controller Architecture for IoT Networks With Blockchain-Based Security
abstract
Internet of Things (IoT) is a disruptive technology in many aspects of our society, ranging from communications to financial transactions to national security (e.g., Internet of Battlefield / Military Things), and so on. There are long-standing challenges in IoT, such as security, comparability, energy consumption, and heterogeneity of devices. Security and energy aspects play important roles in data transmission across IoT and edge networks, due to limited energy and computing (e.g., processing and storage) resources of networked devices. Whether malicious or accidental, interference with data in an IoT network potentially has real-world consequences. In this article, we explore the potential of integrating blockchain and software-defined networking (SDN) in mitigating some of the challenges. Specifically, we propose a secure and energy-efficient blockchain-enabled architecture of SDN controllers for IoT networks using a cluster structure with a new routing protocol. The architecture uses public and private blockchains for Peer to Peer (P2P) communication between IoT devices and SDN controllers, which eliminates Proof-of-Work (POW), as well as using an efficient authentication method with the distributed trust, making the blockchain suitable for resource-constrained IoT devices. The experimental results indicate that the routing protocol based on the cluster structure has higher throughput, lower delay, and lower energy consumption than EESCFD, SMSN, AODV, AOMDV, and DSDV routing protocols. In other words, our proposed architecture is demonstrated to outperform classic blockchain.
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Qi Zhang 0009, Kim-Kwang Raymond Choo
IEEE Trans. Serv. Comput.3
2020 A multiview learning method for malware threat hunting: windows, IoT and android as case studies
Hamid Darabian, Ali Dehghantanha, Sattar Hashemi, Mohammad Taheri, Amin Azmoodeh, Sajad Homayoun, Kim-Kwang Raymond Choo, Reza M. Parizi
World Wide Web2
2019 Non-interactive zero knowledge proofs for the authentication of IoT devices in reduced connectivity environments
Marcus Walshe, Gregory Epiphaniou, Haider M. Al-Khateeb, Mohammad Hammoudeh, Vasilios Katos, Ali Dehghantanha
Ad Hoc Networks6
2019 A hierarchical key pre-distribution scheme for fog networks
abstract
Summary Security in fog computing is multi‐faceted, and one particular challenge is establishing a secure communication channel between fog nodes and end devices. This emphasizes the importance of designing efficient and secret key distribution scheme to facilitate fog nodes and end devices to establish secure communication channels. Existing secure key distribution schemes designed for hierarchical networks may be deployable in fog computing, but they incur high computational and communication overheads and thus consume significant memory. In this paper, we propose a novel hierarchical key pre‐distribution scheme based on “Residual Design” for fog networks. The proposed key distribution scheme is designed to minimize storage overhead and memory consumption while increasing network scalability. The scheme is also designed to be secure against node capture attacks. We also demonstrate that, in an equal‐size network, our scheme reduces node storage overhead significantly. Our research paves the way for building an efficient key management framework for secure communication within the hierarchical network of fog nodes and end devices.
Pooneh Nikkhah Bahrami, Hamid Haj Seyyed Javadi, Tooska Dargahi, Ali Dehghantanha, Kim-Kwang Raymond Choo
Concurr. Comput. Pract. Exp.4
2019 DRTHIS: Deep ransomware threat hunting and intelligence system at the fog layer
abstract
Ransomware, a malware designed to encrypt data for ransom payments, is a potential threat to fog layer nodes as such nodes typically contain considerably amount of sensitive data. The capability to efficiently hunt abnormalities relating to ransomware activities is crucial in the timely detection of ransomware. In this paper, we present our Deep Ransomware Threat Hunting and Intelligence System (DRTHIS) to distinguish ransomware from goodware and identify their families. Specifically, DRTHIS utilizes Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN), two deep learning techniques, for classification using the softmax algorithm. We then use 220 Locky, 220 Cerber and 220 TeslaCrypt ransomware samples, and 219 goodware samples, to train DRTHIS. In our evaluations, DRTHIS achieves an F-measure of 99.6% with a true positive rate of 97.2% in the classification of ransomware instances. Additionally, we demonstrate that DRTHIS is capable of detecting previously unseen ransomware samples from new ransomware families in a timely and accurate manner using ransomware from the CryptoWall, TorrentLocker and Sage families. The findings show that 99% of CryptoWall samples, 75% of TorrentLocker samples and 92% of Sage samples are correctly classified.
Sajad Homayoun, Ali Dehghantanha, Marzieh Ahmadzadeh, Sattar Hashemi, Raouf Khayami, Kim-Kwang Raymond Choo, David Ellis Newton
Future Gener. Comput. Syst.2
2019 Fuzzy pattern tree for edge malware detection and categorization in IoT
abstract
The surging pace of Internet of Things (IoT) development and its applications has resulted in significantly large amounts of data (commonly known as big data) being communicated and processed across IoT networks. While cloud computing has led to several possibilities in regard to this computational challenge, there are several security risks and concerns associated with it. Edge computing is a state-of-the-art subject in IoT that attempts to decentralize, distribute and transfer computation to IoT nodes. Furthermore, IoT nodes that perform applications are the primary target vectors which allow cybercriminals to threaten an IoT network. Hence, providing applied and robust methods to detect malicious activities by nodes is a big step to protect all of the network. In this study, we transmute the programs’ OpCodes into a vector space and employ fuzzy and fast fuzzy pattern tree methods for malware detection and categorization. We obtained a high degree of accuracy during reasonable run-times especially for the fast fuzzy pattern tree. Both utilized feature extraction and fuzzy classification, which were robust, led to more powerful edge computing malware detection and categorization method.
Ensieh Modiri Dovom, Amin Azmoodeh, Ali Dehghantanha, David Ellis Newton, Reza M. Parizi, Hadis Karimipour
J. Syst. Archit.3
2019 Special Issue on Big Data Applications in Cyber Security and Threat Intelligence - Part 1
abstract
The papers in this special section examine Big Data applications in cyber security and threat intelligence. This last decade has witnessed a tremendous rapid increase in volume, veracity, velocity and variety of data generated by different cyber security solutions and as part of cyber investigation cases. When a significant amount of data is collected from or generated by different devices and sources, intelligent big-data analytical techniques are necessary to mine, interpret and visualize such data. To mitigate existing cyber security threats, it is important for big-data analytical techniques to keep pace. Therefore, in special issue we focus on cutting-edge from both academia and industry, with a particular emphasis on novel techniques to mine, interpret and visualize big-data from a wide range of sources and can be applied in cyber security, cyber forensics and threat intelligence context.
Kim-Kwang Raymond Choo, Mauro Conti, Ali Dehghantanha
IEEE Trans. Big Data3
2019 Special Issue on Big Data Applications in Cyber Security and Threat Intelligence - Part 2
abstract
The papers in this special section focus on Big Data applications in cybersecurity and threat intelligence. The last decade has witnessed a tremendous rapid increase in volume, veracity, velocity and variety of data (also commonly referred to as the four V’s of big data in the literature1) generated by different cyber security solutions and as part of cyber investigation cases. When a significant amount of data is collected from or generated by different devices and sources, intelligent big-data analytical techniques are necessary to mine, interpret and visualize such data. To mitigate existing cyber security threats, it is important for big-data analytical techniques to keep pace. Therefore, in special issue we focus on cutting-edge from both academia and industry, with a particular emphasis on novel techniques to mine, interpret and visualize big-data from a wide range of sources and can be applied in cyber security, cyber forensics and threat intelligence context.
Kim-Kwang Raymond Choo, Mauro Conti, Ali Dehghantanha
IEEE Trans. Big Data3
2019 Robust Malware Detection for Internet of (Battlefield) Things Devices Using Deep Eigenspace Learning
abstract
Internet of Things (IoT) in military settings generally consists of a diverse range of Internet-connected devices and nodes (e.g., medical devices and wearable combat uniforms). These IoT devices and nodes are a valuable target for cyber criminals, particularly state-sponsored or nation state actors. A common attack vector is the use of malware. In this paper, we present a deep learning based method to detect Internet Of Battlefield Things (IoBT) malware via the device's Operational Code (OpCode) sequence. We transmute OpCodes into a vector space and apply a deep Eigenspace learning approach to classify malicious and benign applications. We also demonstrate the robustness of our proposed approach in malware detection and its sustainability against junk code insertion attacks. Lastly, we make available our malware sample on Github, which hopefully will benefit future research efforts (e.g., to facilitate evaluation of future malware detection approaches).
Amin Azmoodeh, Ali Dehghantanha, Kim-Kwang Raymond Choo
IEEE Trans. Sustain. Comput.2
2019 Greening Cloud-Enabled Big Data Storage Forensics: Syncany as a Case Study
abstract
The pervasive nature of cloud-enabled big data storage solutions introduces new challenges in the identification, collection, analysis, preservation, and archiving of digital evidences. Investigation of such complex platforms to locate and recover traces of criminal activities is a time-consuming process. Hence, cyber forensics researchers are moving towards streamlining the investigation process by locating and documenting residual artefacts (evidences) of forensic value of users' activities on cloud-enabled big data platforms in order to reduce the investigation time and resources involved in a real-world investigation. In this paper, we seek to determine the data remnants of forensic value from Syncany private cloud storage service, a popular storage engine for big data platforms. We demonstrate the types and the locations of the artifacts that can be forensically recovered. Findings from this research contribute to an in-depth understanding of cloud-enabled big data storage forensics, which can result in reduced time and resources spent in real-world investigations involving Syncany-based cloud platforms.
Yee-Yang Teing, Ali Dehghantanha, Kim-Kwang Raymond Choo, Zaiton Muda, Mohd Taufik Abdullah
IEEE Trans. Sustain. Comput.2
2018 CloudMe forensics: A case of big data forensic investigation
abstract
Summary The significant increase in the volume, variety, and velocity of data complicates cloud forensic efforts, and such (big) evidential data will, at some point, become too (computationally) expensive to be fully identified, collected, and analysed in a timely manner. Thus, it is important for digital forensic practitioners to have an up‐to‐date knowledge of relevant data artefacts that could be forensically recovered from the cloud product under investigation. In this paper, CloudMe, a popular cloud storage service, is studied. The types and locations of the artefacts relating to the installation and uninstallation of CloudMe client application, logging in and out, and file synchronization events from the computer desktop and mobile clients are described. Findings from this research will also help inform future development of tools and techniques (e.g., data mining techniques) for cloud‐enabled big data endpoint forensics investigation.
Yee-Yang Teing, Ali Dehghantanha, Kim-Kwang Raymond Choo
Concurr. Comput. Pract. Exp.2
2018 Internet of Things security and forensics: Challenges and opportunities
Mauro Conti, Ali Dehghantanha, Katrin Franke, Steve Watson
Future Gener. Comput. Syst.2
2018 A deep Recurrent Neural Network based approach for Internet of Things malware threat hunting
Hamed Haddad Pajouh, Ali Dehghantanha, Raouf Khayami, Kim-Kwang Raymond Choo
Future Gener. Comput. Syst.2
2018 Nonreciprocity Compensation Combined With Turbo Codes for Secret Key Generation in Vehicular Ad Hoc Social IoT Networks
abstract
The physical attributes of the dynamic vehicle-to-vehicle propagation channel can be utilized for the generation of highly random and symmetric cryptographic keys. However, in a physical-layer key agreement scheme, nonreciprocity due to inherent channel noise and hardware impairments can propagate bit disagreements. This has to be addressed prior to the symmetric key generation which is inherently important in Social Internet of Things networks, including in adversarial settings (e.g., battlefields). In this paper, we parametrically incorporate temporal variability attributes, such as 3-D scattering and scatterers' mobility. Accordingly, this is the first work to incorporate such features into the key generation process by combining nonreciprocity compensation with turbo codes (TCs). Preliminary results indicate a significant improvement when using TCs in bit mismatch rate and key generation rate in comparison to sample indexing techniques.
Gregory Epiphaniou, Petros Karadimas, Dhouha Kbaier Ben Ismail, Haider M. Al-Khateeb, Ali Dehghantanha, Kim-Kwang Raymond Choo
IEEE Internet Things J.5
2015 Cloud Storage Forensic: hubiC as a Case-Study
abstract
In today's society where we live in a world of constant connectivity, many people are now looking to cloud services in order to store their files so they can have access to them wherever they are. By using cloud services, users can access files anywhere with an internet connection. However, while cloud storage is convenient, it also presents security risks. From a forensics perspective, the increasing popularity of cloud storage platforms, makes investigation into such exploits much more difficult, especially since many platforms such as mobile devices as well as computers are able to use these services. This paper presents investigation of hubiC as one of popular cloud platforms running on Microsoft Windows 8.1. Remaining artefacts pertaining different usage of hubiC namely upload, download, installation and uninstallation on Microsoft Windows 8.1 are presented.
Ben Blakeley, Chris Cooney, Ali Dehghantanha, Rob Aspin
CloudCom3
2014 Privacy-respecting digital investigation
abstract
The forensics investigation requirements are in direct conflict with the privacy rights of those whose actions are being investigated. At the same time, once the private data is exposed it is impossible to `undo' its exposure effects should the suspect is found innocent! Moreover, it is not uncommon that during a suspect investigation, private information of other innocent parties becomes apparent to the forensics investigator. These all raise the concern for development of platforms for enforcing privacy boundaries even to authorized forensics investigators. To the best of authors' knowledge, there is no practical model for privacy-respecting digital investigation which is capable of considering different jurisdictions requirements and protecting subjects' data privacy in line with investigation warrant permissions and data-origin privacy requirements. Privacy-respecting digital forensics as an emerging cross-disciplinary research area is moving toward addressing above issues. In this paper, we first establish needed foundations and describe details of "privacy-respecting digital investigation" as a cross-disciplinary field of research. Afterwards, we review main research efforts in different research disciplines relevant to the field and elaborate existing research problems. We finalize the paper by looking at potential privacy issues during digital investigation in the light of EU, US, and APEC privacy regulations. The main contributions of this paper are first establishing essential foundations and providing detailed definition of "privacy-respecting digital investigation" as a new cross-disciplinary field of research, second a review of current state of art in different disciplines relevant to this field, third elaborating existing issues and discussing most promising solutions relevant to these disciplines, and forth is detailed discussion of potential privacy issues in different phases of digital forensics life cycle based on EU,US, and APEC privacy regulations. We hope this paper opens up a new and fruitful avenue in the study, design, and development of privacy respecting forensics investigation as an interdisciplinary field of research.
Ali Dehghantanha, Katrin Franke
PST1
2011 Investigation of bypassing malware defences and malware detections
abstract
Nowadays, malware incident is one of the most expensive damages caused by attackers. Malwares are caused different attacks, so considerations and implementations of malware defences for internal networks are important. In this papers, different techniques such as repacking, reverse engineering and hex editing for bypassing host-based Anti Virus (AV) signatures are illustrated, and the description and comparison of different channels and methods when malware might reach the host from outside the networks are demonstrated. After that, bypassing HTTP/SSL and SMTP malware defences as channels are discussed. Finally, as it is important to find and detect new and unknown malware before the malware gets in to the victims, a new malware detection technique base on honeynet systems is surveyed.
Farid Daryabar, Ali Dehghantanha, Nur Izura Udzir
IAS2
2011 Towards data centric mobile security
abstract
Recently the usage of mobile devices has increased rapidly and it will be growing even more as mobile devices functionality is at enhanced. So the security of mobile devices needs to be improved. This paper discusses various components and functions of mobile devices such as SMS, wireless and applications and describes possible vulnerabilities threatening them precisely. Malware threats are explained and their effects on mobile devices are studied. Finally, to protect all the vulnerabilities and prevent application and malware threats, data-centric security model is provided as a solution to ensure confidentiality, integrity and availability of data stored on mobile devices.
Ali Dehghantanha, Nur Izura Udzir, Ramlan Mahmod
IAS1