VLDB 2026 Research / reviewers in the wild / expert
Anoop Singhal
dblp:57/1382
· DBLP profile ↗
63ranked-venue papers
7as first author
15since 2021 · last 2026
0000-0002-2602-3927ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 51 · 2 first-author · 15 since 2021Databases, data management, data science and information retrieval · 6 · 4 first-authorSystems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Lightweight Reliability: Using Soft Prompts for Hallucination Mitigation in Large Language Models
S. M. Tahmid Siddiqui, Akib Jawad Ononto, Anoop Singhal, Latifur Khan |
DBSec | 3 |
| 2025 | Hallucination Detection in Large Language Models Using Diversion Decoding
Basel Abdeen, S. M. Tahmid Siddiqui, Meah Tahmeed Ahmed, Anoop Singhal, Latifur Khan, Punya Parag Modi, Ehab Al-Shaer |
DBSec | 4 |
| 2024 | ALERT: A Framework for Efficient Extraction of Attack Techniques from Cyber Threat Intelligence Reports Using Active Learning
Fariha Ishrat Rahman, Sadaf Md. Halim, Anoop Singhal, Latifur Khan |
DBSec | 3 |
| 2024 | Analysis of neural network detectors for network attacksabstractWhile network attacks play a critical role in many advanced persistent threat (APT) campaigns, an arms race exists between the network defenders and the adversary: to make APT campaigns stealthy, the adversary is strongly motivated to evade the detection system. However, new studies have shown that neural network is likely a game-changer in the arms race: neural network could be applied to achieve accurate, signature-free, and low-false-alarm-rate detection. In this work, we investigate whether the adversary could fight back during the next phase of the arms race. In particular, noticing that none of the existing adversarial example generation methods could generate malicious packets (and sessions) that can simultaneously compromise the target machine and evade the neural network detection model, we propose a novel attack method to achieve this goal. We have designed and implemented the new attack. We have also used Address Resolution Protocol (ARP) Poisoning and Domain Name System (DNS) Cache Poisoning as the case study to demonstrate the effectiveness of the proposed attack. Qingtian Zou, Lan Zhang 0008, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 3 |
| 2024 | Heterogeneous Domain Adaptation for Multistream Classification on Cyber Threat DataabstractUnder a newly introduced setting of multistream classification, two data streams are involved, which are referred to as source and target streams. The source stream continuously generates data instances from a certain domain with labels, while the target stream does the same task without labels from another domain. Existing approaches assume that domains for both data streams are identical, which is not quite true, since data streams from different sources may contain distinct features. Indeed, they may even have different numbers of features. Furthermore, obtaining labels for every instance in a data stream is often expensive and time-consuming. Therefore, it has become an important topic to explore if classes of labeled instances from other related streams are helpful to predict the classes of unlabeled instances in a different stream. Note that domains of source and target streams may have distinct feature spaces and data distributions. Our objective is to predict class labels of data instances in the target stream by using the classifiers trained by the source stream. We propose a framework of multistream classification by using projected data from a common latent feature space, which is embedded from both source and target domains. This framework is also crucial for enterprise system defenders to detect cross-platform attacks, such as Advanced Persistent Threats (APTs). Empirical valuation and analysis on both real-world and synthetic datasets are performed to validate the effectiveness of our proposed algorithm, comparing to state-of-the-art techniques. Experimental results show that our approach significantly outperforms other existing approaches. Yifan Li 0003, Yang Gao 0027, Gbadebo Ayoade, Latifur Khan, Anoop Singhal, Bhavani Thuraisingham |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | The Design of an Ontology for ATT&CK and its Application to CybersecurityabstractThe spread of attacks in computer networks and within systems can have severe consequences for both individuals and organizations. One approach to preventing the spread of attacks is to use ontological aid, which is the use of ontologies to provide a structured representation of knowledge about the attack and its components, especially the ones who often disguise themselves to remain undetected for a long time within the system. As soon as one particular stage of such an attack is detected, it is imperative to reduce the amount of spread so that no permanent damage can be done. For this, the security analyst must boil down to technical details from a behavioral perspective so that proper defensive initiatives can be taken. We propose an ontology that will aid security analysts to find out the list of vulnerabilities to be patched so that an ongoing attack campaign can be prevented from spreading even more. Khandakar Ashrafi Akbar, Sadaf Md. Halim, Anoop Singhal, Basel Abdeen, Latifur Khan, Bhavani Thuraisingham |
CODASPY | 3 |
| 2023 | SMET: Semantic Mapping of CVE to ATT&CK and Its Application to Cybersecurity
Basel Abdeen, Ehab Al-Shaer, Anoop Singhal, Latifur Khan, Kevin W. Hamlen |
DBSec | 3 |
| 2023 | Revealing Human Attacker Behaviors Using an Adaptive Internet of Things Honeypot Ecosystem
Armin Ziaie Tabari, Xinming Ou, Anoop Singhal |
IFIP Int. Conf. Digital Forensics | 4 |
| 2023 | Tackling imbalanced data in cybersecurity with transfer learning: a case with ROP payload detectionabstractIn recent years, deep learning gained proliferating popularity in the cybersecurity application domain, since when being compared to traditional machine learning methods, it usually involves less human efforts, produces better results, and provides better generalizability. However, the imbalanced data issue is very common in cybersecurity, which can substantially deteriorate the performance of the deep learning models. This paper introduces a transfer learning based method to tackle the imbalanced data issue in cybersecurity using return-oriented programming payload detection as a case study. We achieved 0.0290 average false positive rate, 0.9705 average F1 score and 0.9521 average detection rate on 3 different target domain programs using 2 different source domain programs, with 0 benign training data sample in the target domain. The performance improvement compared to the baseline is a trade-off between false positive rate and detection rate. Using our approach, the total number of false positives is reduced by 23.16%, and as a trade-off, the number of detected malicious samples decreases by 0.68%. Anoop Singhal |
Cybersecur. | 2 |
| 2023 | Advanced Persistent Threat Detection Using Data Provenance and Metric LearningabstractAdvanced persistent threats (APT) have increased in recent times as a result of the rise in interest by nation-states and sophisticated corporations to obtain high-profile information. Typically, APT attacks are more challenging to detect since they leverage zero-day attacks and common benign tools. Furthermore, these attack campaigns are often prolonged to evade detection. We leverage an approach that uses a provenance graph to obtain execution traces of host nodes in order to detect anomalous behavior. By using the provenance graph, we extract features that are then used to train an online adaptive metric learning. Online metric learning is a deep learning method that learns a function to minimize the separation between similar classes and maximizes the separation between dis- similar instances. We compare our approach with baseline models and we show our method outperforms the baseline models by increasing detection accuracy on average by 11.3% and increases True positive rate (TPR) on average by 18.3%. We also show that our method outperforms several state-of-the-art models performances in comprehensive attack datasets in both binary and multi-class settings. Khandakar Ashrafi Akbar, Yigong Wang, Gbadebo Ayoade, Yang Gao 0027, Anoop Singhal, Latifur Khan, Bhavani Thuraisingham, Kangkook Jee |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Knowledge Mining in Cybersecurity: From Attack to Defense
Khandakar Ashrafi Akbar, Sadaf Md. Halim, Yibo Hu 0002, Anoop Singhal, Latifur Khan, Bhavani Thuraisingham |
DBSec | 4 |
| 2022 | Deep learning for detecting logic-flaw-exploiting network attacks: An end-to-end approachabstractNetwork attacks have become a major security concern for organizations worldwide. A category of network attacks that exploit the logic (security) flaws of a few widely-deployed authentication protocols has been commonly observed in recent years. Such logic-flaw-exploiting network attacks often do not have distinguishing signatures, and can thus easily evade the typical signature-based network intrusion detection systems. Recently, researchers have applied neural networks to detect network attacks with network logs. However, public network data sets have major drawbacks such as limited data sample variations and unbalanced data with respect to malicious and benign samples. In this paper, we present a new end-to-end approach based on protocol fuzzing to automatically generate high-quality network data, on which deep learning models can be trained for network attack detection. Our findings show that protocol fuzzing can generate data samples that cover real-world data, and deep learning models trained with fuzzed data can successfully detect the logic-flaw-exploiting network attacks. Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
J. Comput. Secur. | 2 |
| 2021 | Deep Learning for Detecting Network Attacks: An End-to-End Approach
Qingtian Zou, Anoop Singhal, Xiaoyan Sun 0003, Peng Liu 0005 |
DBSec | 2 |
| 2021 | Security Auditing of Internet of Things Devices in a Smart Home
Suryadipta Majumdar, Daniel Bastos, Anoop Singhal |
IFIP Int. Conf. Digital Forensics | 3 |
| 2021 | Network Attack Surface: Lifting the Concept of Attack Surface to the Network Level for Evaluating Networks' Resilience Against Zero-Day AttacksabstractThe concept of attack surface has seen many applications in various domains, e.g., software security, cloud security, mobile device security, Moving Target Defense (MTD), etc. However, in contrast to the original attack surface metric, which is formally and quantitatively defined for a software, most of the applications at higher abstraction levels, such as the network level, are limited to an intuitive and qualitative notion, losing the modeling power of the original concept. In this paper, we lift the attack surface concept to the network level as a formal security metric for evaluating the resilience of networks against zero day attacks. Specifically, we first develop novel models for aggregating the attack surface of different network resources. We then design heuristic algorithms to estimate the network attack surface while reducing the effort spent on calculating attack surface for individual resources. Finally, the proposed methods are evaluated through experiments. Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Developing A Compelling Vision for Winning the Cybersecurity Arms RaceabstractIn cybersecurity there is a continuous arms race between the attackers and the defenders. In this panel, we investigate three key questions regarding this arms race. First question is whether this arms race is winnable. Second, if the answer to the first question is in the affirmative, what steps we need to take to win this race. Third, if the answer to the first question is negative, what is the justification for this and what steps can we take to improve the state of affairs and increase the bar for the attackers significantly. Elisa Bertino, Anoop Singhal, Srivathsan Srinivasagopalan, Rakesh M. Verma |
CODASPY | 2 |
| 2020 | Forensic Analysis of Advanced Persistent Threat Attacks in Cloud Environments
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2019 | CASFinder: Detecting Common Attack Surface
Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 5 |
| 2019 | DETERMINING THE FORENSIC DATA REQUIREMENTS FOR INVESTIGATING HYPERVISOR ATTACKS
Anoop Singhal, Ramaswamy Chandramouli, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2019 | Optimizing the network diversity to improve the resilience of networks against unknown attacks
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
Comput. Commun. | 4 |
| 2019 | Mitigating the insider threat of remote administrators in clouds through maintenance task assignmentsabstractToday’s cloud providers strive to attract customers with better services and less downtime in a highly competitive market. The need for minimizing the operational cost unavoidably leads cloud providers to rely on third party remote administrators for fulfilling regular maintenance tasks. In such a scenario, the lack of trust in those third party remote administrators paired with the extra privileges granted to them to complete the maintenance tasks usually implies undesirable security threats. A dishonest remote administrator, or an attacker armed with the stolen credential of a remote administrator, can pose severe insider threats to both the cloud provider and its tenants. In this paper, we take the first step towards understanding and mitigating such insider threats of remote administrators in clouds. Specifically, we first model the maintenance task assignments and their corresponding security impact due to privilege escalation. We then mitigate such impact through optimizing the task assignments with respect to given constraints. Finally, the simulation results demonstrate the effectiveness of our solution in various scenarios. Nawaf Alhebaishi, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
J. Comput. Secur. | 4 |
| 2018 | Modeling and Mitigating the Insider Threat of Remote Administrators in Clouds
Nawaf Alhebaishi, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 4 |
| 2018 | Assessing Attack Impact on Business Processes by Interconnecting Attack Graphs and Entity Dependency Graphs
Chen Cao 0004, Lun-Pin Yuan, Anoop Singhal, Peng Liu 0005, Xiaoyan Sun 0003, Sencun Zhu |
DBSec | 3 |
| 2018 | A Layered Graphical Model for Cloud Forensic Mission Attack Impact Analysis
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2018 | Surviving unpatchable vulnerabilities through heterogeneous network hardening optionsabstractThe administrators of a mission critical network usually have to worry about non-traditional threats, e.g., how to live with known, but unpatchable vulnerabilities, and how to improve the network’s resilience against potentially unknown vulnerabilities. To this end, network hardening is a well-known preventive security solution that aims to improve network security by taking proactive actions, namely, hardening options. However, most existing network hardening approaches rely on a single hardening option, such as disabling unnecessary services, which becomes less effective when it comes to dealing with unknown and unpatchable vulnerabilities. There lacks a heterogeneous approach that can combine different hardening options in an optimal way to deal with both unknown and unpatchable vulnerabilities. In this paper, we propose such an approach by unifying multiple hardening options, such as service diversification, firewall rule modification, adding, removing, and relocating network resources, and access control, all under the same model. We then apply security metrics designed for evaluating network resilience against unknown and unpatchable vulnerabilities, and consequently derive optimal solutions to maximize security under given cost constraints. Finally, we study the effectiveness of our solution against unpatchable vulnerabilities through simulations. Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
J. Comput. Secur. | 4 |
| 2018 | Using Bayesian Networks for Probabilistic Identification of Zero-Day Attack PathsabstractEnforcing a variety of security measures (such as intrusion detection systems, and so on) can provide a certain level of protection to computer networks. However, such security practices often fall short in face of zero-day attacks. Due to the information asymmetry between attackers and defenders, detecting zero-day attacks remains a challenge. Instead of targeting individual zero-day exploits, revealing them on an attack path is a substantially more feasible strategy. Such attack paths that go through one or more zero-day exploits are called zero-day attack paths. In this paper, we propose a probabilistic approach and implement a prototype system ZePro for zero-day attack path identification. In our approach, a zero-day attack path is essentially a graph. To capture the zero-day attack, a dependency graph named object instance graph is first built as a supergraph by analyzing system calls. To further reveal the zero-day attack paths hidden in the supergraph, our system builds a Bayesian network based upon the instance graph. By taking intrusion evidence as input, the Bayesian network is able to compute the probabilities of object instances being infected. Connecting the high-probability-instances through dependency relations forms a path, which is the zero-day attack path. The experiment results demonstrate the effectiveness of ZePro for zero-day attack path identification. Xiaoyan Sun 0003, Jun Dai 0001, Peng Liu 0005, Anoop Singhal, John Yen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | SafeConfig'17: Applying the Scientific Method to Active Cyber Defense ResearchabstractThe focus of this workshop is the application of scientific practices to cyber security research. The objective of this workshop is examine the implementation of science practices in cyber defense research and understand the ramification of tradeoffs between simplifications to obtain interpretable results vs. observational studies of systems in the wild where the results can lead to ambiguous interpretations. The research papers accepted addressed a wide variety of technical questions in the cyber domain and the maturity of the work spanned the range of initial ideas and proofs of concept to mature work that is ready for operational implementation. Papers were evaluated for the reproducibility of the work as represented by the documentation of methods and testing environments. Nicholas J. Multari, Anoop Singhal, Erin Miller |
CCS | 2 |
| 2017 | Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 4 |
| 2017 | Towards Actionable Mission Impact Assessment in the Context of Cloud Computing
Xiaoyan Sun 0003, Anoop Singhal, Peng Liu 0005 |
DBSec | 2 |
| 2017 | Identifying Evidence for Cloud Forensic Analysis
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2016 | SafeConfig'16: Testing and Evaluation for Active and Resilient Cyber SystemsabstractThe premise of this year's SafeConfig Workshop is existing tools and methods for security assessments are necessary but insufficient for scientifically rigorous testing and evaluation of resilient and active cyber systems. The objective for this workshop is the exploration and discussion of scientifically sound testing regimen(s) that will continuously and dynamically probe, attack, and "test" the various resilient and active technologies. This adaptation and change in focus necessitates at the very least modification, and potentially, wholesale new developments to ensure that resilient- and agile-aware security testing is available to the research community. All testing, validation and experimentation must also be repeatable, reproducible, subject to scientific scrutiny, measurable and meaningful to both researchers and practitioners. Nicholas J. Multari, Anoop Singhal, David O. Manz |
CCS | 2 |
| 2016 | Diversifying Network Services Under Cost Constraints for Better Resilience Against Unknown Attacks
Daniel Borbor, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
DBSec | 4 |
| 2016 | A Probabilistic Network Forensic Model for Evidence Analysis
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2016 | Network Diversity: A Security Metric for Evaluating the Resilience of Networks Against Zero-Day AttacksabstractDiversity has long been regarded as a security mechanism for improving the resilience of software and networks against various attacks. More recently, diversity has found new applications in cloud computing security, moving target defense, and improving the robustness of network routing. However, most existing efforts rely on intuitive and imprecise notions of diversity, and the few existing models of diversity are mostly designed for a single system running diverse software replicas or variants. At a higher abstraction level, as a global property of the entire network, diversity and its effect on security have received limited attention. In this paper, we take the first step toward formally modeling network diversity as a security metric by designing and evaluating a series of diversity metrics. In particular, we first devise a biodiversity-inspired metric based on the effective number of distinct resources. We then propose two complementary diversity metrics, based on the least and the average attacking efforts, respectively. We provide guidelines for instantiating the proposed metrics and present a case study on estimating software diversity. Finally, we evaluate the proposed metrics through simulation. Mengyuan Zhang 0001, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | POSTER: A Logic Based Network Forensics Model for Evidence AnalysisabstractModern-day attackers tend to use sophisticated multi-stage/multi-host attack techniques and anti-forensics tools to cover their attack traces. Due to the current limitations of intrusion detection and forensic analysis tools, reconstructing attack scenarios from evidence left behind by the attackers of an enterprise system is challenging. In particular, reconstructing attack scenarios by using the information from IDS alerts and system logs that have a large number of false positives is a big challenge. In this paper, we present a model and an accompanying software tool that systematically addresses how to resolve the above problems to reconstruct the attack scenario. These problems include a large amount of data including non-relevant data and evidence destroyed by anti-forensic techniques. Our system is based on a Prolog system using known vulnerability databases and an anti-forensics database that we plan to extend to a standardized database like the NIST National Vulnerability Database (NVD). In this model, we use different methods, including mapping the evidence to system vulnerabilities, inductive reasoning and abductive reasoning to reconstruct attack scenarios. The goal of this work is to reduce the investigators' time and effort in reaching definite conclusion about how an attack occurred. Our results indicate that such a reasoning system can be useful for network forensics analysis. Anoop Singhal, Duminda Wijesekera |
CCS | 1 |
| 2015 | A Logic-Based Network Forensic Model for Evidence Analysis
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2014 | Modeling Network Diversity for Evaluating the Robustness of Networks against Zero-Day Attacks
Lingyu Wang 0001, Mengyuan Zhang 0001, Sushil Jajodia, Anoop Singhal, Massimiliano Albanese |
ESORICS (2) | 4 |
| 2014 | Inferring the Stealthy Bridges Between Enterprise Network Islands in Cloud Using Cross-Layer Bayesian Networks
Xiaoyan Sun 0003, Jun Dai 0001, Anoop Singhal, Peng Liu 0005 |
SecureComm (1) | 3 |
| 2014 | k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown VulnerabilitiesabstractBy enabling a direct comparison of different security solutions with respect to their relative effectiveness, a network security metric may provide quantifiable evidences to assist security practitioners in securing computer networks. However, research on security metrics has been hindered by difficulties in handling zero-day attacks exploiting unknown vulnerabilities. In fact, the security risk of unknown vulnerabilities has been considered as something unmeasurable due to the less predictable nature of software flaws. This causes a major difficulty to security metrics, because a more secure configuration would be of little value if it were equally susceptible to zero-day attacks. In this paper, we propose a novel security metric, k-zero day safety, to address this issue. Instead of attempting to rank unknown vulnerabilities, our metric counts how many such vulnerabilities would be required for compromising network assets; a larger count implies more security because the likelihood of having more unknown vulnerabilities available, applicable, and exploitable all at the same time will be significantly lower. We formally define the metric, analyze the complexity of computing the metric, devise heuristic algorithms for intractable cases, and finally demonstrate through case studies that applying the metric to existing network security practices may generate actionable knowledge. Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Pengsu Cheng, Steven Noel |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2013 | Creating Integrated Evidence Graphs for Network Forensics
Anoop Singhal, Duminda Wijesekera |
IFIP Int. Conf. Digital Forensics | 2 |
| 2013 | An Efficient Approach to Assessing the Risk of Zero-Day Vulnerabilities
Massimiliano Albanese, Sushil Jajodia, Anoop Singhal, Lingyu Wang 0001 |
SECRYPT | 3 |
| 2013 | A Unified Framework for Measuring a Network's Mean Time-to-CompromiseabstractMeasuring the mean time-to-compromise provides important insights for understanding a network's weaknesses and for guiding corresponding defense approaches. Most existing network security metrics only deal with the threats of known vulnerabilities and cannot handle zero day attacks with consistent semantics. In this paper, we propose a unified framework for measuring a network's mean time-to-compromise by considering both known, and zero day attacks. Specifically, we first devise models of the mean time for discovering and exploiting individual vulnerabilities. Unlike existing approaches, we replace the generic state transition model with a more vulnerability-specific graphical model. We then employ Bayesian networks to derive the overall mean time-to-compromise by aggregating the results of individual vulnerabilities. Finally, we demonstrate the framework's practical application to network hardening through case studies. William Nzoukou, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
SRDS | 4 |
| 2013 | Aggregating vulnerability metrics in enterprise networks using attack graphsabstractQuantifying security risk is an important and yet difficult task in enterprise network security management. While metrics exist for individual software vulnerabilities, there is currently no standard way of aggregating such metrics. We present a model that can be used to aggregate vulnerability metrics in an enterprise network, producing quantitative metrics that measure the likelihood breaches can occur within a given network configuration. A clear semantic model for this aggregation is an important first step toward a comprehensive network security metric model. We utilize existing work in attack graphs and apply probabilistic reasoning to produce an aggregation that has clear semantics and sound computation. We ensure that shared dependencies between attack paths have a proportional effect on the final calculation. We correctly reason over cycles, ensuring that privileges are evaluated without any self-referencing effect. We introduce additional modeling artifacts in our probabilistic graphical model to capture and account for hidden correlations among exploit steps. The paper shows that a clear semantic model for aggregation is critical in interpreting the results, calibrating the metric model, and explaining insights gained from empirical evaluation. Our approach has been rigorously evaluated using a number of network models, as well as data from production systems. John Homer, Xinming Ou, Yanhui Du, S. Raj Rajagopalan, Anoop Singhal |
J. Comput. Secur. | 7 |
| 2012 | Using Attack Graphs in Forensic ExaminationsabstractAttack graphs are used to compute potential attackpaths from a system configuration and known vulnerabilities of asystem. Attack graphs can be used to eliminate knownvulnerability sequences that can be eliminated to make attacksdifficult and help forensic examiners in identifying manypotential attack paths. After an attack happens, forensic analysis, including linking evidence with attacks, helps further understandand refine the attack scenario that was launched. Given thatthere are anti-forensic tools that can obfuscate, minimize oreliminate attack footprints, forensic analysis becomes harder. Asa solution, we propose to apply attack graph to forensic analysis. We do so by including anti-forensic capabilities into attackgraphs, so that the missing evidence can be explained by usinglonger attack paths that erase potential evidence. We show thiscapability in an explicit case study involving a database attack. Anoop Singhal, Duminda Wijesekera |
ARES | 2 |
| 2012 | Aggregating CVSS Base Scores for Semantics-Rich Network Security MetricsabstractA network security metric is desirable in evaluating the effectiveness of security solutions in distributed systems. Aggregating CVSS scores of individual vulnerabilities provides a practical approach to network security metric. However, existing approaches to aggregating CVSS scores usually cause useful semantics of individual scores to be lost in the aggregated result. In this paper, we address this issue through two novel approaches. First, instead of taking each base score as an input, our approach drills down to the underlying base metric level where dependency relationships have well-defined semantics. Second, our approach interprets and aggregates the base metrics from three different aspects in order to preserve corresponding semantics of the individual scores. Finally, we confirm the advantages of our approaches through simulation. Pengsu Cheng, Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal |
SRDS | 4 |
| 2011 | Guest Editorial: Security and Dependability in SOA and Business ProcessesabstractThe papers in this special issue focus on research on Service Oriented Architectures (SOA). Ernesto Damiani, Seth Proctor, Anoop Singhal |
IEEE Trans. Serv. Comput. | 3 |
| 2010 | k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks
Lingyu Wang 0001, Sushil Jajodia, Anoop Singhal, Steven Noel |
ESORICS | 3 |
| 2008 | Web Services Security: Techniques and Challenges (Extended Abstract)
Anoop Singhal |
DBSec | 1 |
| 2008 | An Attack Graph-Based Probabilistic Security Metric
Lingyu Wang 0001, Tania Islam, Anoop Singhal, Sushil Jajodia |
DBSec | 4 |
| 2008 | Forensic Web Services
Murat Gunestas, Duminda Wijesekera, Anoop Singhal |
IFIP Int. Conf. Digital Forensics | 3 |
| 2008 | Implementing interactive analysis of attack graphs using relational databasesabstractAn attack graph models the causal relationships between vulnerabilities. Attack graphs have important applications in protecting critical resources in networks against sophisticated multi-step intrusions. Currently, analyses of attack graphs largely depend on proprietary implementations of speciali zed algorithms. However, developing and implementing algorithms causes a delay to the availability of new analyses. The delay is usually unacceptable due to rapidly-changing needs in defending against network intrusions. An administrator may want to revise an analysis as soon as its outcome is observed. Such an interactive analysis, similar to that in decision support systems, is desirable but difficult with current approaches based on proprietary implementations of algorithms. This paper addresses the above issue through a relational approach. Specifically, we devise a relational model for representing necessary inputs, such as network configurations and domain knowledge, and we generate attack graphs from these inputs as relational views. We show that typical analyses can be supported through different type of searches in an attack graph, and these searches can be realized as relational queries. Our approach eliminates the needs for implementing algorithms, because an analysis is now simply a relational query. The interactive analysis of attack graphs becomes possible, since relational queries can be dynamically constructed and revised at run time. As a side effect, experimental results show that the mature optimization techniques in relational databases can transparently improve the performance of the analysis. Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
J. Comput. Secur. | 3 |
| 2007 | Measuring the Overall Security of Network Configurations Using Attack Graphs
Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
DBSec | 2 |
| 2006 | Interactive Analysis of Attack Graphs Using Relational Queries
Lingyu Wang 0001, Anoop Singhal, Sushil Jajodia |
DBSec | 3 |
| 2006 | Data warehousing and data mining techniques for intrusion detection systems
Anoop Singhal, Sushil Jajodia |
Distributed Parallel Databases | 1 |
| 2004 | Design of a data warehouse system for network/web servicesabstractThis paper describes the architecture and design of a data warehouse for AT&T Business Services. The main purpose of our system is to generate reports about the performance and reliability of the network. We describe the architecture of our system and discuss some open research problems in this area. Anoop Singhal |
CIKM | 1 |
| 1993 | Can OODB Technology Solve CAD Design Data Management Problems? (Panel Abstract)
Anoop Singhal |
ICDE | 1 |
| 1993 | DDB: An Object Oriented Design Data Manager for VLSI CADabstractIn this paper we present an object oriented data model for VLSI/CAD data. A design data manager (DDB) based on such a model has been implemented under the UNIX/C++ environment. It has been used by a set of diverse VLSI/CAD applications of our organization. Benchmarks have shown it to perform better as compared to commercial object oriented database systems. In conjunction with the ease of data access, the data manger served to improve software productivity and a modular program architecture for our CAD system. Anoop Singhal, Robert M. Arlein, Chi-Yuan Lo |
SIGMOD Conference | 1 |
| 1993 | HS: a hierarchical search package for CAD dataabstractAn algorithm that implicitly searches the flattened VLSI netlist data space without first constructing it is presented. In traditional methods, the entire search space of size n (e.g. the total number of instances) is constructed explicitly to allow a fast O(1) query time. The new algorithm uses circuit hierarchy to prune the search effectively. It is shown that the size of a hierarchical netlist is o(n), and a query can be executed in O(1) amortized time.> Nishit P. Parikh, Chi-Yuan Lo, Anoop Singhal, Kwok W. Wu |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 1990 | HS: A Hierarchical Search Package for CAD DataabstractA hierarchical search software package that allows an application to retrieve flattened netlist data from a hierarchical netlist database. An algorithm is presented that implicitly searches the entire VLSI CAD net list data space without first constructing it. While traditional methods construct the entire search space explicitly, which helps to achieve a fast O(1) query time but requires Omega (n) space, this method relies on the circuit hierarchy to prune the search effectively. It is shown that the hierarchical net list data space is smaller by a factor of O(n/sup epsilon /). Where O> Nishit P. Parikh, Chi-Yuan Lo, Anoop Singhal, Kwok W. Wu |
ICCAD | 3 |
| 1989 | A data model and architecture for VLSI/CAD databasesabstractA design data manager is emerging as an important component of an integrated CAD system. The authors present a semantic data model and an architecture for VLSI/CAD databases. The data model provides mechanisms to represent the design entities the relationships among them in a unified way. A key feature of the system architecture is that it exploits design hierarchy to provide high performance. A data manager based on this model has been implemented and used by a set of diverse applications. In conjunction with efficient data flow, the data manager can serve to improve software productivity.> Anoop Singhal, Nishit P. Parikh, Debaprosad Dutt, Chi-Yuan Lo |
ICCAD | 1 |
| 1987 | Performance Analysis of Resiliency Mechanisms in Distributed Datbase SystemsabstractDegradation in system performance due to component failures is an important factor that prevents a distributed database management system (DDBMS) from achieving its full potential of better availability, response time, and system throughput. Resiliency mechanisms that help to continue system operation in spite of failures introduce overhead due to the need to maintain redundant information. Earlier performance studies of DDBMS have either altogether ignored failure or studied only limited aspects of the effect of failures and performance of resiliency mechanisms. In this paper an analytical model is used to comprehensively characterize the effect of failures and resiliency mechanisms on the performance of DDBMS. Two new performance measures are introduced. The methodology is illustrated by comparatively evaluating the performance of three algorithms. Amit P. Sheth, Anoop Singhal, Ming T. Liu |
ICDE | 2 |
| 1985 | An Analysis of the Effect of Network Parameters on the Performance of Distributed Database SystemsabstractPerformance analysis studies of distributed database systems in the past have assumed that the message transmission time between any two nodes of a network is constant. They disregard the effect of communication network parameters such as network traffic, network topology, and capacity of transmission channels. In this paper, an analytical model is used to estimate the delays in transmission channels of the long haul network supporting the distributed database system. The analysis shows that the constant transmission time assumption cannot be justified in many cases, and that the response time is sensitive to the parameters mentioned above. Extensions and performance analysis in the context of interconnection networks are also discussed. Amit P. Sheth, Anoop Singhal, Ming T. Liu |
IEEE Trans. Software Eng. | 2 |
| 1984 | An Adaptive Concurrency Control Strategy for Distributed Database SystemsabstractPerformance of a Concurrency Control Algorithm (CCA) managing a distributed database system will deteriorate considerably when the configuration of the network supporting it will change due to either communication link failures or the communication delays introduced by varying load patterns. To get a good performance in spite of the changing configurations, we propose a scheme that involves breaking down the network into ‘weakly connected’ clusters. The problem to identify the clusters of a network is NP-hard. However, we present a heuristic strategy to identify the clusters of a network that works in polynomial time. Any of the present CCAs can be modified to work on a network that is partitioned into clusters by our scheme that uses (what we term as) multiple controllers. As an example, we present a Centralized Locking Algorithm with Acknowledgment using Multiple Controllers (CLAA/MC). Performance gain achieved using multiple controllers is also discussed. Amit P. Sheth, Anoop Singhal, Ming T. Liu |
ICDE | 2 |