Barsha Mitra

dblp:58/10753 · DBLP profile ↗
← Back
18ranked-venue papers
4as first author
12since 2021 · last 2025
0000-0003-0688-5383ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 4 first-author · 8 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Securing Multi-Domain Systems: Intelligent ABAC Policy Learning for Cross-Domain Access Control
abstract
Ensuring secure, dynamic, and fine-grained access control across independently managed domains is a major challenge in modern multi-domain environments. An access control mechanism designed for multi-domain systems needs to account for the unique characteristics of such systems, like a distributed environment, a dynamic nature, and cross-domain collaboration. This paper proposes an intelligent framework for mining Attribute-Based Access Control (ABAC) policies using a supervised learning technique for multi-domain systems. In the proposed architecture, each domain employs its own Policy Decision Engine (PDE) to evaluate access requests originating either from within the same domain or from a remote domain. For each domain, the ABAC policy is derived by training a supervised machine learning model using the access logs of that domain. Our proposed method enables the different domains to retain their autonomy by allowing them to make access decisions based on their own independent policies. We evaluate the performance of our approach on two access control datasets in terms of accuracy, precision, recall, and F1 score. Moreover, we compare our method with an existing clustering-based policy mining technique. Our proposed method significantly outperforms the existing approach in terms of the accuracy of access decision-making. This implies that our proposed framework exhibits strong generalization across domains, supporting scalable and decentralized ABAC policy learning, thereby enabling secure and interoperable access control in complex, multi-domain environments.
Asmita Biswas, Barsha Mitra, Iqbal Gondal, Qiang Fu 0011
PST2
2025 Enhancing Access Control in Distributed Systems Through Intelligent ABAC Policy Mining
Sudhir Kumar Bai, Jason Aaron Goveas, Barsha Mitra
SECRYPT3
2024 Knowledge Empowered Deep Reinforcement Learning to Prioritize Alerts Generated by Intrusion Detection Systems
Lalitha Chavali, Paresh Saxena, Barsha Mitra
AINA (4)3
2024 SINTTRA: Sliding Window Based Temporally Aware Network Traffic Analyzer for IoT Device Fingerprinting
abstract
In recent years, the growing demand for connected technologies has lead to an exponential surge in the number of IoT devices worldwide. This has resulted in the IoT ecosystems been relentlessly targeted by cyber criminals with the sole aim of compromising the IoT devices. Such compromised devices exhibit abnormal behavior that are manifested in the corresponding network traffic patterns. Anomalous network traffic behavior can be detected with the help of IoT device fingerprinting. Device fingerprinting involves analysis of the network traffic patterns of the IoT devices to create a unique digital blueprint of each of the devices. Such blueprints help to distinguish between normal and abnormal device behaviors, thereby providing indications of possible device compromise and also to detect the presence of a new device. In this paper, we propose an IoT device fingerprinting strategy that uses a sliding window based approach to analyze the characteristics of the network traffic generated by the IoT devices. Our fingerprinting strategy performs packet-level network traffic analysis. However, instead of considering the individual network packets, the proposed sliding window based method aggregates a fixed number of packets to create the device fingerprints. Moreover, the method ensures overlap between successive windows while aggregating the packets to retain the temporal relationships among the different packets of a single IoT device. We name our strategy as SINTTRA, Sliding wINdow based Temporally aware neTwork tRaffic Analyzer. SINTTRA uses supervised machine learning for categorizing the different IoT devices. We have evaluated the efficacy of SINTTRA on network traffic traces collected from our own IoT testbed setup as well as the open-source UNSW IoT dataset. We have also compared the performance of SINTTRA with the flow-based network traffic analysis for device fingerprinting. For both datasets, SINTTRA performs better than the flow-based approach by a margin of 2% to 10% in terms of accuracy, precision, recall and F1-score.
Vibhum Raj Tripathi, Srikant Tangirala, Divakarla Venkata Sasanka, Dheeraj Reddy, Chinmay S. Dalal, Barsha Mitra
IS6
2024 Malware Analysis Using Transformer Based Models: An Empirical Study
Divyateja Pasupuleti, P. Nischith, Sarvesh Sutaone, Soumil Ray, Soumyadeep Dey, Barsha Mitra
SECRYPT7
2024 Off-policy actor-critic deep reinforcement learning methods for alert prioritization in intrusion detection systems
Lalitha Chavali, Abhinav Krishnan, Paresh Saxena, Barsha Mitra, Aneesh Sreevallabh Chivukula
Comput. Secur.4
2023 Analyzing Image Based Strategies for Android Malware Detection and Classification: An Empirical Exploration
Chirag Jaju, Dhairya Agrawal, Rishi Poddar, Shubh Badjate, Sidharth Anand, Barsha Mitra, Soumyadeep Dey
SECRYPT6
2023 Context-Aware Behavioral Fingerprinting of IoT Devices via Network Traffic Analysis
Arjun Prasad, Kevin Kanichery Biju, Soumya Somani, Barsha Mitra
SECRYPT4
2022 PAMMELA: Policy Administration Methodology using Machine Learning
abstract
In recent years, Attribute-Based Access Control (ABAC) has become quite popular and effective for enforcing access control in dynamic and collaborative environments. Implementation of ABAC requires the creation of a set of attribute-based rules which cumulatively form a policy. Designing an ABAC policy ab initio demands a substantial amount of effort from the system administrator. Moreover, organizational changes may necessitate the inclusion of new rules in an already deployed policy. In such a case, re-mining the entire ABAC policy requires a considerable amount of time and administrative effort. Instead, it is better to incrementally augment the policy. In this paper, we propose PAMMELA, a Policy Administration Methodology using Machine Learning to assist system administrators in creating new ABAC policies as well as augmenting existing policies. PAMMELA can generate a new policy for an organization by learning the rules of a policy currently enforced in a similar organization. For policy augmentation, new rules are inferred based on the knowledge gathered from the existing rules. A detailed experimental evaluation shows that the proposed approach is both efficient and effective.
Varun Gumma, Barsha Mitra, Soumyadeep Dey, Pratik Shashikantbhai Patel, Sourabh Suman, Saptarshi Das, Jaideep Vaidya
SECRYPT2
2022 A holistic framework for prediction of routing attacks in IoT-LLNs
Rashmi Sahay, Barsha Mitra
J. Supercomput.3
2021 Enforcing Cardinality Constraint in Temporal RBAC
Sohail Rajdev, Barsha Mitra
SECRYPT2
2021 A novel Network Partitioning Attack against Routing Protocol in Internet of Things
Rashmi Sahay, Barsha Mitra
Ad Hoc Networks3
2020 A Feedforward Neural Network based Model to Predict Sub-optimal Path Attack in IoT-LLNs
abstract
The Internet of Things achieves its vision to connect all physical devices to the Internet through the Low power and Lossy Networks (LLNs). The LLNs comprise constrained devices like sensors, actuators and RFIDs. Since the IoT environment involves large scale deployment of sensor networks, routing becomes an essential requirement. IPv6 Routing Protocol over Low Power and Lossy Network (RPL) is the most popular routing protocol suggested by the Internet Engineering Task Force (IETF) for the IoT-LLN environment. RPL facilitates communication among the sensor nodes in the IoT-LLNs by organizing them in the form of a Destination Oriented Directed Acyclic Graph (DODAG). The term destination-oriented is derived from the fact that data traffic from all the sensor nodes is destined towards the sink (root) node, which acts as a bridge between the LLNs and the intended IoT application. According to RPL, a node chooses its parent from a set of neighboring nodes based on the rank value advertised by them. The rank of any node is a numeric value which is estimated through an objective function and reflects the path quality offered by a parent node to the sink node. Lesser the rank value, the higher is the path quality in terms of the objective function. In a sub-optimal path attack, a malicious node intentionally chooses a sub-optimal path to the sink node by selecting a parent node with a higher rank value. Since the motive of the attacker node is always to select an inferior parent node, the attack is named as the Worst Parent Attack. In this paper, we analyze the impact of the Worst Parent Attack on the overall performance of the IoT-LLNs. Following the analysis, we propose a mechanism based on the Feedforward Neural Network to predict the worst parent attack in RPL supported IoT-LLNs and to identify the source of the attack.
Rashmi Sahay, Barsha Mitra
CCGRID3
2018 Efficient Framework for Detection of Version Number Attack in Internet of Things
Rashmi Sahay, Barsha Mitra, Ipsit Sahoo
ISDA (2)3
2017 Migrating from RBAC to temporal RBAC
abstract
The last two decades have witnessed an emergence of role‐based access control (RBAC) as the de facto standard for access control. However, for organisations already having a deployed RBAC system, in many cases it may become necessary to associate a temporal dimension with the existing access control policies due to changing organisational requirements. In such cases, migration from RBAC to a temporal extension of RBAC becomes essential. Temporal RBAC (TRBAC) is one such RBAC extension. The process of creating a set of roles for implementing a TRBAC system is known as temporal role mining . Existing temporal role mining approaches typically assume that TRBAC is being deployed from scratch and do not consider it as a migration from an existing RBAC policy. In this study, the authors propose two temporal role mining approaches that enable migration from RBAC to TRBAC. These approaches make use of conventional (non‐temporal) role mining algorithms. Apart from aiding the migration process, deriving the roles in this manner allows the flexibility of minimising any desired role mining metric. They experimentally evaluate the performance of both of the proposed approaches and show that they are both efficient and effective.
Barsha Mitra, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri
IET Inf. Secur.1
2016 Mining temporal roles using many-valued concepts
Barsha Mitra, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri
Comput. Secur.1
2015 The generalized temporal role mining problem
abstract
Role mining, the process of deriving a set of roles from the available user-permission assignments, is considered to be an essential step in successful implementation of Role-Based Access Control (RBAC) systems. Traditional role mining techniques, however, are not equipped to handle temporal extensions of RBAC like the Temporal-RBAC (TRBAC) model. In this paper, we formally define the problem of finding a minimal set of roles from temporal user-permission assignments, such that in the resulting TRBAC system, users acquire either the same or a subset of the permissions originally assigned to them for the complete or partial durations of time as specified in the input. We show that the problem is NP-complete and propose a greedy algorithm for solving it. Our algorithm first derives a set of candidate roles from the temporal user-permission assignments and then selects the least possible number of roles from the candidate role set. The final output consists of a set of roles, a user-to-role assignment relation, a role-to-permission assignment relation and a role enabling base describing the time durations for which each role is enabled. Performance of the proposed approach has been evaluated on a number of synthetic as well as real-world datasets.
Barsha Mitra, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya
J. Comput. Secur.1
2013 Toward Mining of Temporal Roles
Barsha Mitra, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya
DBSec1