VLDB 2026 Research / reviewers in the wild / expert
Shamik Sengupta
dblp:62/3898
· DBLP profile ↗
80ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0002-2019-8056ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 36 · 8 first-author · 5 since 2021Security and privacy · 9 · 3 since 2021Human-computer interaction and ubiquitous computing · 7 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 1 since 2021Systems, architecture and hardware · 4 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Benchmarking Machine Learning Models for IoT Malware Detection under Data Scarcity and DriftabstractThe rapid expansion of the Internet of Things (IoT) in domains such as smart cities, transportation, and industrial systems has heightened the urgency of addressing their security vulnerabilities. IoT devices often operate under limited computational resources, lack robust physical safeguards, and are deployed in heterogeneous and dynamic networks, making them prime targets for cyberattacks and malware applications. Machine learning (ML) offers a promising approach to automated malware detection and classification, but practical deployment requires models that are both effective and lightweight. The goal of this study is to investigate the effectiveness of four supervised learning models (Random Forest, LightGBM, Logistic Regression, and a Multi-Layer Perceptron) for malware detection and classification using the IoT-23 dataset. We evaluate model performance in both binary and multiclass classification tasks, assess sensitivity to training data volume, and analyze temporal robustness to simulate deployment in evolving threat landscapes. Our results show that tree-based models achieve high accuracy and generalization, even with limited training data, while performance deteriorates over time as malware diversity increases. These findings underscore the importance of adaptive, resource-efficient ML models for securing IoT systems in real-world environments. Jake Lyon, Ehsan Saeedizade, Shamik Sengupta |
CCNC | 3 |
| 2026 | Lightweight IoT Device Fingerprinting Approach using Locality-Sensitive HashingabstractThe resource constraints of Internet of Things (IoT) devices limit the use of heavy security mechanisms, which leaves them more exposed to cyberattacks. Detecting malicious devices from network traffic is therefore critical. This paper proposes a lightweight fingerprinting method based on locality-sensitive hashing (LSH) that builds device-specific signatures from combined packet headers rather than payloads, avoiding payload variability and the overhead of full packet processing. Experiments on the LSIF and IoTSentinel datasets show that combined headers reach up to 99.3% and 95.8% accuracy, respectively, outperforming payload-based methods, while reducing processing time, making it suitable for real-time processing. Roya Taheri, Ehsan Saeedizade, Shamik Sengupta |
CCNC | 3 |
| 2025 | Unveiling Bb84 Vulnerabilities: A Quantum Key Distribution Simulation LibraryabstractThe US National Security Agency (NSA) has emphasized that Quantum Key Distribution (QKD) protocols have technical limitations making them unfeasible for national security systems. However, several researchers have debated against this narrative stating their robustness. This disagreement makes it essential for more researchers and pen-testers to study QKD and determine its robustness, performance efficiency, and/or vulnerabilities. However, simulating QKD protocols often needs an in-depth domain knowledge of both cryptography and quantum physics making it difficult for security researchers to understand and cross-examine them. To alleviate the problem, this paper implements the standard BB84 QKD protocol, develops an easily reconfigurable simulator library, and showcases how it can be used to uncover the protocol's vulnerabilities. Using the simulator, we uncover and demonstrate a major vulnerability in the BB84 protocol via which persistent eavesdroppers can evade generic detection under certain probabilistic conditions and launch denial-of-service attacks. The paper also demonstrates this vulnerability in real-time via the simulator showcasing its robustness and capabilities. Ignacio Astaburuaga, Suman Rath, Shamik Sengupta |
CCNC | 3 |
| 2025 | GCAP: Cyber Attack Progression Framework for Smart Grid InfrastructuresabstractInterdisciplinary developments like the smart grid (SG) provide enhanced functionality like efficient power delivery, reliability, and safety while ensuring the smooth integration of traditional and renewable sources of power. Unfortunately, the progressive utilization of the SG and its applications makes them a prime target for cyber attacks. In this article, we propose the grid cyber attack progression (GCAP) framework for SG security. The proposed framework provides higher flexibility in how SG organizations can prepare for complex cyber attacks by incorporating behavior patterns like the adversary skipping and/or backtracking stages during attack progression, while still maintaining a sequential and hierarchical structure. Unlike contemporary frameworks, GCAP provides us with cyber attack progression from the defender’s perspective. We illustrate the advantages of the proposed framework over established frameworks for SG security, after which we evaluate the framework on multiple case studies on real-world cyber attacks on power systems. Finally, we identify defensive solutions that can be laid down in every stage of the GCAP framework to provide more security and protection for SG infrastructures. Tapadhir Das, Suman Rath, Shamik Sengupta |
IEEE Internet Things J. | 3 |
| 2025 | Identifying Homogeneous IoT Devices With Hybrid Locality-Sensitive HashingabstractInternet of Things (IoT) devices have become increasingly prevalent, and while convenient they pose security risks and must be monitored to keep networks safe. The problem of identifying IoT devices by fingerprinting their network traffic has been studied, with various approaches emerging. While achieving good results, many solutions require complex feature extraction, considerable computational overhead, and extensive domain knowledge in both networking and machine learning to select relevant features and supporting ML algorithms. In addition, many current studies work to identify heterogeneous devices in an artificially sterile (lab) environment. To improve the process we introduce FlexHash, a system that uses a combination of locality-sensitive hashing and machine learning to identify specific devices based on a generic view of their network traffic characteristics. We successfully identify both heterogeneous and homogeneous (identical) devices in an environment with both live network noise and noise generated from other (unknown) IoT devices. FlexHash is able to consume unprocessed network traffic in the form of .pcap files and produce feature vectors capable of highly accurate device identification and anomaly detection. To enhance the strength of this approach we develop our own n-gram based hashing method allowing for various parameters in the algorithm to be tuned, making it possible to accurately differentiate individual devices from among a field of identical peers as well as device genre and heterogeneous devices with a single packet of network traffic. Roya Taheri, Jay Thom, Nathan Thom, Batyr Charyyev, Emily Morgan Hand, Shamik Sengupta |
IEEE Internet Things J. | 6 |
| 2024 | Introduction to Quantum Systems and Security VulnerabilitiesabstractThe objective of this paper is to propose and establish a new area of research and increase awareness of key cybersecurity aspects relating to the manufacturing, creation, development, and maintenance of quantum systems and identify key challenges in this domain. It aims to present areas of focus of cybersecurity in the quantum field. Through research, we have established a new emerging gap in the security of quantum systems. This paper introduces the basics of quantum systems, circuits, and computers. Then, it continues to introduce the current state of quantum technologies. Finally, it introduces cybersecurity and quantum and establishes new avenues of attacks for such systems. Ignacio Astaburuaga, Shamik Sengupta |
CCNC | 2 |
| 2024 | Game Theory for Privacy-Preserving Cybersecurity Information Exchange FrameworkabstractAnalyzing the intricate dynamics of cyber threat information (CTI) sharing platforms promotes strategic data exchange, fortifying organizations with the collective strength needed to mitigate cyber threats effectively. This research aims to quantitatively assess the utility of joining a cyber threat intelligence platform. More specifically, this paper attempts to apply the principles of game theory to cyber threat intelligence platforms to uncover how the game develops over time and examine whether it is beneficial for an organization to join in the first place. The source code for the implementation discussed in this paper is available at https://gitlab.com/ignaciochg/ccnc24-game-theory-cybex. Ignacio Astaburuaga, Shamik Sengupta |
CCNC | 2 |
| 2024 | FlexHash - Hybrid Locality Sensitive Hashing for IoT Device IdentificationabstractRecent growth in the utilization of IoT has offered convenience and utility, but has also increased security risk. Many devices lack the capacity to support adequate encryption or other common means of protection, and are often designed for easy connection out-of-the-box exposing vulnerabilities related to default configurations. Managing IoT devices in a network can be difficult as MAC addresses are easily spoofed, creating a need for techniques to properly identify and monitor membership. Many of the proposed solutions for IoT device identification require complex feature extraction and engineering. In addition, little work has been done to identify individual devices from among identical peers. We propose a novel hashing algorithm, FlexHash, and show that we are able to identify identical devices with a very high degree of accuracy using only a single packet of network traffic. By applying hybrid locality sensitive hashing in combination with machine learning our approach achieves accuracy scores as high as 98% for identical devices and 99% for identifying device genre. Nathan Thom, Jay Thom, Batyr Charyyev, Emily Morgan Hand, Shamik Sengupta |
CCNC | 5 |
| 2024 | A Cybersecurity Game to Probe Human-AI TeamingabstractRecent advances in AI indicate that the future of cybersecurity workforce development lies in professionals working in Human-AI teams to defend online resources from opposing Human-AI teams of malicious attackers. However, there is little research on how human biases and attitudes affects the performance of human-AI teams in cybersecurity. To help explore this new research area, we describe a simulation game that helps students (future professionals) understand the concept of firewalls while enabling us to probe attitudes towards cybersecurity and AI, as well as trust and cooperation in HumanAI teams. Early study prototyping results indicate that students prefer an AI-teammate over a human in this simulation game setting. In addition, students seem to engage well with the game play, pointing towards this research platform’s suitability for exploring trust and cooperation in human-AI teams for game-based cybersecurity training, and to support our prior results on differing perspectives on cybersecrity risk. Rita Olla, Emily Morgan Hand, Sushil J. Louis, Ramona Houmanfar, Shamik Sengupta |
CoG | 5 |
| 2023 | UNR-IDD: Intrusion Detection Dataset using Network Port StatisticsabstractMultiple datasets have been proposed to create Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS). However, many of these datasets suffer from sub-optimal performance and inadequate tail class representation. In this paper, we propose the University of Nevada - Reno Intrusion Detection Dataset (UNR-IDD), which utilizes network port statistics for fine-grained analysis of intrusions. Evaluation results show that UNR-IDD is better than existing NIDS datasets with an Fμ, score of 94% and a minimum F-score of 86%. This is mainly because of sufficient and equal representation of various anomaly types in the UNR-IDD dataset. Tapadhir Das, Osama Abu Hamdan, Raj Mani Shukla, Shamik Sengupta, Engin Arslan |
CCNC | 4 |
| 2023 | CarVer: Setting the Standard for Face Verification with CaricaturesabstractResearch in psychology and neuroscience point to the potential of caricatures to improve human face recognition in non-ideal settings. Face verification using caricatures is the first step in using caricatures in this way, which involves verifying pairs of faces where one is veridical (realistic) and the other is a caricature. Existing biometric research in the area of caricature face verification is recent and limited by a lack of well-constructed, large-scale datasets. We show that the largest available dataset, WebCaricature, falls short of acceptable standards of image quality and representation necessary for face verification. We present a new caricature dataset, CarVer, and introduce a face verification evaluation standard to replace WebCaricature’s. We find that the CarVer dataset (F1=0.82) outperforms WebCaricature (F1=0.76) using WebCaricature’s Bounding Box alignment method. Additionally, our new alignment methods, Enlarged Bounding Box (F1=0.82) and Revised Bounding Box (F1=0.80) outperform WebCaricature’s Bounding Box (F1=0.72) and Eye Location (F1=0.74) alignment methods. Sara R. Davis, Bryson Lingenfelter, Kevin McElhinney, Shamik Sengupta, Emily Morgan Hand |
IJCB | 4 |
| 2023 | Locality Sensitive Hashing for Network Traffic FingerprintingabstractThe Internet of Things (IoT) introduced new complexities and challenges to computer networks. Due to their simple nature, these devices are more vulnerable to cyber-attacks. Thus it becomes important to identify these devices in a network for network management and detect malicious activities. Network traffic fingerprinting is an essential tool for device identification and anomaly detection, and existing approaches mainly rely on machine learning (ML). However, ML-based approaches require feature selection, hyperparameter tuning, and model retraining to achieve optimum results and be robust to concept drifts observed in a network. To overcome these challenges, in this paper we propose locality-sensitive hashing (LSH) based network traffic fingerprinting. Specifically, we explore design alternatives for the LSH function Nilsimsa and use it to fingerprint network traffic for device identification. We also compared it with ML-based traffic fingerprinting and observed that our method increases the accuracy of state-of-the-art by 12% achieving around 94% accuracy in identifying devices in a network. Nowfel Mashnoor, Jay Thom, Abdur Rouf, Shamik Sengupta, Batyr Charyyev |
LANMAN | 4 |
| 2023 | Give and Take: Federated Transfer Learning for Industrial IoT Network Intrusion DetectionabstractThe rapid growth in Internet of Things (IoT) technology has become an integral part of today’s industries forming the Industrial IoT (IIoT) initiative, where industries are leveraging IoT to improve communication and connectivity via emerging solutions like data analytics and cloud computing. Unfortunately, the rapid use of IoT has made it an attractive target for cybercriminals. Therefore, protecting these systems is of utmost importance. In this paper, we propose a federated transfer learning (FTL) approach to perform IIoT network intrusion detection. As part of the research, we also propose a combinational neural network as the centerpiece for performing FTL. The proposed technique splits IoT data between the client and server devices to generate corresponding models, and the weights of the client models are combined to update the server model. Results showcase high performance for the FTL setup between iterations on both the IIoT clients and the server. Additionally, the proposed FTL setup achieves better overall performance than contemporary machine learning algorithms at performing network intrusion detection. Lochana Telugu Rajesh, Tapadhir Das, Raj Mani Shukla, Shamik Sengupta |
TrustCom | 4 |
| 2023 | An Intelligent Privacy Preservation Scheme for EV Charging InfrastructureabstractThe electric vehicle (EV) charging ecosystem, being a distinguishable paradigm of IIoT infrastructure, consists of distributed and complex hybrid systems that demand adaptive data-driven cyber-defense mechanisms to tackle the ever-growing attack vectors of cyber-physical systems. We propose an adaptive differential privacy-based federated learning framework for building a collaborative network intrusion detection system model for EV charging stations (EVCS). We use utility optimized local differential privacy to provide data privacy to the local network traffic data of each EVCS. Moreover, we propose a reinforcement learning-based intelligent privacy allocation mechanism at the EVCS level. The main significance of the proposed mechanism is that it can make privacy provisioning adaptive to the extent of privacy breaching rate, and dynamically optimize the privacy budget and the utility to avoid human intervention such as domain knowledge experts. The experimental results confirm the efficacy of our proposed mechanism and achieves appropriate privacy provisioning accuracy to approximately 95%. Shafkat Islam, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Ohana Means Family: Malware Family Classification using Extreme Learning MachinesabstractMalwares have historically been the central threat concerning cybersecurity. With the rise in modern technologies, malwares have become more lethal due to the increasing connectivity between various computing environments. To exacerbate this increasing threat, modern day anti-virus signature matching seems to provide limited effectiveness, which makes it possible that new malware variants can evade detection when their behavior does not correlate exactly with known malware signatures on a system. There is also a wide time gap between when a new malware variant is released, and its corresponding antivirus signature is developed and made available to the public. This time gap is when these new malware variants can cause havoc on computing environments. To counteract this threat, the paper proposes a novel malware detection methodology to analyze and detect malware and classify malware by family. This is performed through time series analysis of the sequence of API calls made, using Extreme Learning Machines (ELM) and Online Sequential Extreme Learning Machines (OS-ELM). The paper further analyzes the approach by accurately detecting and predicting malware family classification using a subset of the API call sequences. Simulation results show that the proposed approach can accurately detect and classify malware families with higher accuracy and greater speed than traditional LSTM. Our experiments show ELM and OS-ELM performing with 91% accuracy within just 3 seconds of learning time in contrast to other methods. Thus, our method is superior both in terms of training time and accuracy. Aaron Walker, Raj Mani Shukla, Tapadhir Das, Shamik Sengupta |
CCNC | 4 |
| 2022 | NetDefense: A Tower Defense Cybersecurity Game for Middle and High School StudentsabstractThis Innovate Practice Full Paper presents a new game for cybersecurity learning. Cybersecurity education is critical to personal media consumption, privacy protection, and national infrastructure. We live in a world that is increasingly connected; the majority of people, particularly young people, engage with technology and social media for multiple hours per day, using the internet as a source of news, entertainment, and connection to the outside world. However, threats on the internet, including misinformation, disinformation, phishing, and multiple other cybersecurity threats grow each year. Because of this, cybersecurity is an essential skill for K-12 and all undergraduate students to learn in public schools. In this study, we asked K-12 teachers to analyze a specific game, NetDefense, designed to teach students basic cybersecurity concepts related to networking. NetDefense specifically addresses concepts within the network communications component of the core theme of computing systems from the K-12 cybersecurity standards released by cyber.org. Before and after engaging with the game, we asked teachers a series of survey questions to determine their perceptions of the game and its utility in classrooms. Findings indicate that NetDefense improved teachers’ knowledge of network concepts. Participating teachers believed that NetDefense would help students learn these concepts and that NetDefense is an appropriate tool for this type of learning. Finally, teachers believed that student motivation to learn about and use cybersecurity concepts would increase upon playing the game. We plan to improve the game using feedback from our participants, disseminate the open source, publicly available game to all interested educators for classroom and laboratory use, and gather more data on game effectiveness. William Toledo, Sushil J. Louis, Shamik Sengupta |
FIE | 3 |
| 2022 | Modeling and analyzing attacker behavior in IoT botnet using temporal convolution network (TCN)
Farhan Sadique, Shamik Sengupta |
Comput. Secur. | 2 |
| 2021 | Friend or Foe: Discerning Benign vs Malicious Software and Malware FamilyabstractMalware remains one of the gravest threats to cybersecurity, second only to social engineering or a lack of user security awareness. This is especially true for Windows systems in enterprise environments. As malware continues to evolve and frustrate legacy detection and prevention mechanisms, additional approaches are necessary to ensure security resilience. Machine learning offers many opportunities to better combat malware threats through the advantage of big datasets. Our research highlights how machine learning can be leveraged to identify malware threats with rapid results, enabling cybersecurity professionals to learn and adapt to these threats. The approach we present in this paper produces an efficient methodology to discern malware family and function through analysis of just the first 3,000 Windows system API function calls. We compare MLP, CNN, and SVM networks to determine the best performance in terms of accuracy and speed and find that MLP works the best with our dataset. Aaron Walker, Tapadhir Das, Raj Mani Shukla, Shamik Sengupta |
GLOBECOM | 4 |
| 2021 | Analysis of Attacker Behavior in Compromised Hosts During Command and ControlabstractTraditional reactive approach of blacklisting botnets fails to adapt to the rapidly evolving landscape of cyberattacks. An automated and proactive approach to detect and block botnet hosts will immensely benefit the industry. Behavioral analysis of botnet is shown to be effective against a wide variety of attack types. Current works, however, focus solely on analyzing network traffic from and to the bots. In this work we take a different approach of analyzing the chain of commands input by attackers in a compromised host. We have deployed several honeypots to simulate Linux shells and allowed attackers access to the shells to collect a large dataset of commands. We have further developed an automated mechanism to analyze these data. For the automation we have developed a system called CYbersecurity information Exchange with Privacy (CYBEX-P). Finally, we have done a sequential analysis on the dataset to show that we can successfully predict attacker behavior from the shell commands without analyzing network traffic like previous works. Farhan Sadique, Shamik Sengupta |
ICC | 2 |
| 2021 | Sharing is Caring: Optimized Threat Visualization for a Cybersecurity Data Sharing PlatformabstractCyberattacks are increasingly costing organizations billions of dollars annually. To protect against them, cybersecurity information sharing and cyberthreat visualization have become crucial research topics. Our platform, CYBersecurity information EXchange with Privacy (CYBEX-P), implements developments in both areas as an approachable collaborative security tool. CYBEX-P's threat-intelligence graph displays indicators of compromise and their crowd-reported threat levels. Intuitive and efficient data interaction is key for adoption of such a contributor-driven system and is the focus of this work. A user study was conducted with participants from cybersecurity backgrounds to test different visualization configurations. Measurements pertaining to dependent variables such as task accuracy and threat-detection time were recorded. Subsequent analysis revealed that relying on localized color to represent threat comes with serious limitations. Likewise, information density must be carefully considered. We conclude that the misuse of simple visual properties can lead to perilous reductions in accuracy and response-time and provide recommendations for avoiding these pitfalls. Adam Cassell, Tapadhir Das, Zachary Black, Farhan Sadique, James Schnebly, Sergiu M. Dascalu, Shamik Sengupta, Jeff Springer |
NCA | 7 |
| 2021 | The Devil is in the Details: Confident & Explainable Anomaly Detector for Software-Defined NetworksabstractDeployment of SDN control plane in high-end servers allow many network applications to be automated and easily managed. In this paper, we propose an SDN anomaly detection application, Confident and Explainable Anomaly Detector (CEAD), that automatically detects malicious network flows in SDN-based network architectures. The proposed application employs a set of Machine Learning (ML) classifiers to improve the confidence score of a prediction, thereby creating improved trust upon the prediction, while providing interpretability to the anomaly detector. The method utilizes the Explainable Artificial Intelligence (XAI) framework to provide interpretation to predictions to unearth network features that establish the most influence between predicted anomaly types. Results show that the proposed framework can achieve efficient anomaly detection performance, with near perfect confidence scores. Analysis with XAI highlights that byte and packet transmissions, and their robust statistics, can be significant indicators for prevalence of any attacks. Results also indicate that a subset of influential features can generally be used to decipher between normal and anomalous flow, while certain dataset features can be specifically influential in detecting specific attack types. This can lead to more efficient network resource utilization. Tapadhir Das, Raj Mani Shukla, Shamik Sengupta |
NCA | 3 |
| 2021 | Context-Aware Fine-Grained Task Scheduling at Vehicular Edges: An Extreme Reinforcement Learning based Dynamic ApproachabstractVehicular edge computing (VEC), being a novel computing paradigm, promises to provide divergent vehicular edge services, both functional (e.g., charging route prediction, emergency messages, etc.) and infotainment (e.g. video gaming applications, featured movie series, etc.), at the network edge while satisfying application-specific QoS requirements. Vehicles usually send these service requests to nearest roadside units (RSUs), which contain mobile edge servers, according to the functional requirements or the vehicle owner preferences. However, the VEC server's virtual resources may fall short compared to the unbounded amount of real-time service requests (infotainment/functional) during rush hours. This limitation entails VEC servers to fail to meet the stringent latency requirements which may create unwanted malfunction event during driving in the requested vehicles (if functional/critical service requests are delayed in processing). Moreover, the VEC environment's intrinsic properties, i.e. mobility, application-specific distinct latency requirements, traffic congestion, and uncertain task arrival rate, make the VEC task scheduling problem a non-trivial one. In this paper, we propose an extreme reinforcement learning (ERL) based context-aware VEC task scheduler that can make online adaptive scheduling decisions to meet the application-specific latency requirements for both types of tasks (i.e. functional and infotainment). The scheduler can make scheduling decisions directly from its experience without prior knowledge or the VEC environment model. Finally, we present extensive simulation results to confirm the efficacy of the proposed scheduler. Results show that the VEC server can achieve successful (by meeting QoS requirements) task completion rate of above 96% for different task arrival rates (ranging from 10 to 50 arrival/s) using the proposed scheduler. In the simulation, we also analyze the scheduling algorithm's scalability in response to the vertical expansion of the VEC server. Furthermore, we compare the performance of our proposed method with two baseline methods. Shafkat Islam, Shahriar Badsha, Shamik Sengupta |
WOWMOM | 3 |
| 2021 | ALICIA: Applied Intelligence in blockchain based VANET: Accident Validation as a Case Study
Shirshak Raja Maskey, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001 |
Inf. Process. Manag. | 3 |
| 2021 | Towards secure and practical consensus for blockchain based VANET
Sowmya Kudva, Shahriar Badsha, Shamik Sengupta, Ibrahim Khalil 0001, Albert Y. Zomaya |
Inf. Sci. | 3 |
| 2021 | A scalable blockchain based trust management in VANET routing protocol
Sowmya Kudva, Shahriar Badsha, Shamik Sengupta, Hung Manh La, Ibrahim Khalil 0001, Mohammed Atiquzzaman |
J. Parallel Distributed Comput. | 3 |
| 2020 | Game theoretic approach applied in cybersecurity information exchange frameworkabstractIn CYBersecurity information EXchange (CYBEX) framework, Cyber Threat Intelligence (CTI) is shared among multiple organizations with a view of creating situational awareness. But there is a possibility that malicious organizations coexist with regular ones in this framework, which can get hold of the threat data shared by other organizations and can use it for carrying out malicious activities. We formulate the aforementioned problem as an incomplete information game assuming that whenever CYBEX receives any information, it processes the information for anomaly detection. We find the mixed strategy Nash equilibrium probabilities and corresponding Bayesian belief updates. We simulate the game to find the best response strategies with which regular and malicious organizations can play to increase their payoffs. Based on the best response strategies of organizations, we analyze that achieving more anomaly detection rate while keeping the processing rate minimum is the best action strategy with which CYBEX can play to increase the gain of both CYBEX and regular organizations over malicious organizations. We also find the approximate average minimum processing rate and anomaly detection rate with which CYBEX can play in order to maintain the payoff of itself and regular organizations higher than the malicious ones. Ankita Thakkar, Shahriar Badsha, Shamik Sengupta |
CCNC | 3 |
| 2020 | Evolving Dynamically Reconfiguring UAV-hosted Mesh NetworksabstractWe use potential fields tuned by genetic algorithms to dynamically reconFigure unmanned aerial vehicles networks to serve user bandwidth needs. Such flying network base stations have applications in the many domains needing quick temporary networked communications capabilities such as search and rescue in remote areas and security and defense in overwatch and scouting. Starting with an initial deployment that covers an area and discovers how users are distributed across this area of interest, tuned potential fields specify subsequent movement. A genetic algorithm tunes potential field parameters to reposition UAVs to create and maintain a mesh network that maximizes user bandwidth coverage and network lifetime. Results show that our evolutionary adaptive network deployment algorithm outperforms the current state of the art by better repositioning the unmanned aerial vehicles to provide longer coverage lifetimes while serving bandwidth requirements. The parameters found by the genetic algorithm on four training scenarios with different user distributions lead to better performance than achieved by the state of the art. Furthermore, these parameters also lead to superior performance in three never before seen scenarios indicating that our algorithm finds parameter values that generalize to new scenarios with different user distributions. Rahul Dubey, Sushil J. Louis, Shamik Sengupta |
CEC | 3 |
| 2020 | Malware Family Fingerprinting Through Behavioral AnalysisabstractSignature-based malware detection is not always effective at detecting polymorphic variants of known malware. Malware signatures are devised to counter known threats, which also limits efficacy against new forms of malware. However, existing signatures do present the ability to classify malware based upon known malicious behavior which occurs on a victim computer. In this paper we present a method of classifying malware by family type through behavioral analysis, where the frequency of system function calls is used to fingerprint the actions of specific malware families. This in turn allows us to demonstrate a machine learning classifier which is capable of distinguishing malware by family affiliation with high accuracy. Aaron Walker, Shamik Sengupta |
ISI | 2 |
| 2020 | Vulnerability market as a public-good auction with privacy preservation
Iman Vakilinia, Shamik Sengupta |
Comput. Secur. | 2 |
| 2019 | Pooling Approach for Task Allocation in the Blockchain Based Decentralized Storage NetworkabstractBlockchain technology has provided a solid system to develop incentivization algorithms using the smart contract. Blockchain applies the distributed ledger to store transaction histories, and the information is stored across a network of computers instead of on a single server. This facilitates the development of a new set of applications such as distributed file storage systems where users can rent out their storage in return for a premium. The distributed file storage systems provide more privacy and security compared to the centralized storage models as there is no need to have a trusted party. New schemes have been developed for distributed file storage systems on top of the blockchain platform, however, the problem of task/service allocation in these models have not been studied before. In this paper, we study the task/service allocation in the distributed file storage systems considering the challenge of computation cost. First, we formalize the problem of task/service allocation in a decentralized storage network, and then we discuss different approaches to allocate storage tasks to storage servers in an efficient manner. Moreover, we study the benefits of the cooperation (a.k.a pooling) in the storage and retrieval markets of distributed storage networks. The evaluation results show the benefit of our proposed pooling based approach in storage and retrieval markets. Iman Vakilinia, Shahin Vakilinia, Shahriar Badsha, Engin Arslan, Shamik Sengupta |
CNSM | 5 |
| 2019 | Anomaly Detection using Supervised Learning and Multiple Statistical MethodsabstractThe presence of anomalies or outliers within time-series data can have a detrimental effect on the efficiency of automated decision-making applications. For example, in the context of vehicular traffic flow, various services reliant on traffic data may be negatively impacted by anomalies. This paper presents an automated anomaly detection method based on supervised Long-Short Term Memory (LSTM) neural network and statistical analysis. We train LSTM neural network to predict non-robust statistical properties and combine them with robust properties to determine the anomalies in time-series data. The proposed method relies on segmentation and tunable parameters for anomaly test. We measure the efficacy of our method in terms of Precision, Recall, and F-measure. The metrics approach to 100% for certain instances. We also analyzed the performance on the prevalence of anomalies and on varying specific parameters of the model. Watson Jia, Raj Mani Shukla, Shamik Sengupta |
ICMLA | 3 |
| 2019 | In-band LOS discovery using highly directional transceivers
Suman Bhunia, Mahmudur Khan 0002, Murat Yuksel, Shamik Sengupta |
Ad Hoc Networks | 4 |
| 2019 | Fair and private rewarding in a coalitional game of cybersecurity information sharingabstractCybersecurity information sharing is a key factor of cyber threat intelligence, allowing organisations to detect and prevent malicious behaviours proactively. However, stimulating organisations to participate and deterring free‐riding in such sharing is a big challenge. To this end, the sharing system should be equipped with a rewarding and participation‐fees allocation mechanisms to encourage sharing behaviour. The problem of cybersecurity information sharing as a non‐cooperative game has been studied extensively. In contrast, in this study, the authors model such a problem as a coalitional game. They investigate a rewarding and participation‐fees calculation based on profit sharing in coalitional game theory. In particular, they formulate a coalitional game between organisations and analyse the well‐known Shapley value and Nucleolus solution concepts in the cybersecurity information sharing system. Moreover, as the participation‐fees may leak sensitive information about the organisations’ cyber‐infrastructure, they study the application of differential privacy in the coalitional game theory to protect the organisation's fees while approximating the fairness. Iman Vakilinia, Shamik Sengupta |
IET Inf. Secur. | 2 |
| 2019 | Distributed allocation and dynamic reassignment of channels in UAV networks for wireless coverage
Amar Nath Patra, Paulo Alexandre Regis, Shamik Sengupta |
Pervasive Mob. Comput. | 3 |
| 2019 | A Coalitional Cyber-Insurance Framework for a Common PlatformabstractDespite the benefits of cyber-insurance, organizations are reluctant to enroll in such policies mainly because of their limitation and high price. On the other hand, insurers are confronting the adverse selection and moral hazard problems as monitoring and distinguishing insureds' cybersecurity posture are highly complicated. Considering the organizations' security interdependency and their demand for cyber-insurance, we study the design of coalitional insurance mechanisms with the goal of covering the adverse selection, moral hazard, and motivating players for cybersecurity investment and information sharing. To this end, we propose a synergistic insurance framework, where organizations collaboratively insure a common platform instead of themselves. We present three models for insuring a common platform. In the first model, organizations act as both insurer and insured to distribute the risk in the coalition. In the second model, the system provides rewards to crowdfund the insurance. Finally, in the third model, we investigate the outsourcing of a common platform insurance. Furthermore, we discuss how our proposed mechanisms for such framework satisfy the budget balanced, ex ante individual rationality, and incentive compatibility properties. We study how such a system can improve the social welfare by leveraging cyber-insurance as a motivation for organizations to cooperate on the cybersecurity investment and information sharing. Iman Vakilinia, Shamik Sengupta |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Unmanned Aerial Vehicles Positioning Scheme for First-Responders in a Dynamic Area of InterestabstractIn this paper, we explore the problem of finding the initial positions to deploy UAVs to provide service to ground personnel. In this work, we propose a greedy algorithm that finds a feasible solution that guarantees 100% coverage on any given map. We defined subareas of the map which do not need coverage as excluding zones. We considered both excluding zones and the connectivity constraints in the algorithm. By avoiding these zones and keeping all nodes connected to the network we can reduce the total number of UAVs needed to provide coverage without losing the communication capability. We show that the complexity of the algorithm is linear with respect to the input parameters. Simulation results show the behavior of our approach with different maps. We observe a convergence on the number of nodes needed when varying the input map. Paulo Alexandre Regis, Amar Nath Patra, Shamik Sengupta |
VTC Fall | 3 |
| 2018 | Distributed adaptive beam nulling to survive against jamming in 3D UAV mesh networks
Suman Bhunia, Paulo Alexandre Regis, Shamik Sengupta |
Comput. Networks | 3 |
| 2018 | Establishing evolutionary game models for CYBer security information EXchange (CYBEX)
Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat |
J. Comput. Syst. Sci. | 2 |
| 2017 | A novel software-defined network based approach for charging station allocation to plugged-in electric vehiclesabstractThis paper proposes a novel approach to integrate plugged-in electric vehicles (PEVs), electric vehicle supply equipments (EVSEs), and smart grid (SG) infrastructure using state of the art software-defined network (SDN) technology, which has a potential to provide unprecedented flexibility to smart grid communication network. We further present set-cardinality based search algorithms for assigning charging station to PEVs to reduce their average charging time. Simulation results show a considerable improvement in the average charging time of PEVs as compared to conventional minimum distance based charging station selection. Raj Mani Shukla, Shamik Sengupta |
NCA | 2 |
| 2017 | A game-theoretic and stochastic survivability mechanism against induced attacks in Cognitive Radio Networks
Saad Mneimneh, Suman Bhunia, Felisa J. Vázquez-Abad, Shamik Sengupta |
Pervasive Mob. Comput. | 4 |
| 2016 | A device-to-device service sharing middleware for heterogeneous wireless networksabstractWireless devices with diverse capabilities are ubiquitous and will continue to flourish for the next foreseeable future. With cellular connectivity, each devicd is capable to utilize more necessary services. However, in some cases (e.g., public safety and disaster recovery) cellular connectivity may become unavailable. In these situations, device-to-device (D2D) communication can contribute to maintain connectivity as well as providing other services in terms of service sharing (e.g., SMS, Internet, camera) available in individual devices. This paper describes an approach where users can share wireless services with other users in a seamless manner. We develop a smart phone application, D2DMesh, for service sharing in a D2D manner. By using D2DMesh, users can get more work done via sharing, increase the spectrum utilization, create their own private networks without a centralized infrastructure and offload network traffic to a less congested network path. Our approach is platform-independent and is entirely implemented in user space. It allows sharing of services among neighboring devices over multiple hops without any help from the device vendors. We present results from initial experiments and show the effects of various important parameters on the performance of D2D service sharing. Mostafizur Rahman, Sandeep Mathew, Murat Yuksel, Shamik Sengupta |
LANMAN | 4 |
| 2016 | Adaptive beam nulling in multihop ad hoc networks against a jammer in motion
Suman Bhunia, Vahid Behzadan, Paulo Alexandre Regis, Shamik Sengupta |
Comput. Networks | 4 |
| 2015 | Evolving defensive strategies against iterated induction attacks in cognitive radio networksabstractThis paper investigates the use of Genetic Algorithms (GAs) to evolve defensive strategies against iterated and memory enabled induction attacks in cognitive radio networks. Security problems in cognitive radio networks have been heavily studied in recent years. However, few studies have considered the effect of memory size on attack and defense strategies. We model cognitive radio network attack and defense as a zero-sum stochastic game. Our research focuses on using GAs to recognize attack patterns from different attackers and evolving defensive strategies against the attack patterns so as to maximize network utility. We assume attackers are not only able to attack high utility channels, but are also capable of attacking based on the history of high utility channel usage by the secondary user. In our simulations, different memory lengths are used by the secondary user against memory enabled attackers. Results show that the best performance strategies evolved by GAs gain more payoff, on average, than the Nash equilibrium. Against our baseline memory enabled attackers, GAs quickly and reliably found the theoretically globally optimal defensive strategy. These results indicate that GAs is a viable approach for generating strong defenses against arbitrary memory based attackers. Siming Liu 0001, Shamik Sengupta, Sushil J. Louis |
CEC | 2 |
| 2015 | Cyber-Threats Information Sharing in Cloud Computing: A Game Theoretic ApproachabstractCybersecurity is among the highest priorities in industries, academia and governments. Cyber-threats information sharing among different organizations has the potential to maximize vulnerabilities discovery at a minimum cost. Cyber-threats information sharing has several advantages. First, it diminishes the chance that an attacker exploits the same vulnerability to launch multiple attacks in different organizations. Second, it reduces the likelihood an attacker can compromise an organization and collect data that will help him launch an attack on other organizations. Cyberspace has numerous interconnections and critical infrastructure owners are dependent on each other's service. This well-known problem of cyber interdependency is aggravated in a public cloud computing platform. The collaborative effort of organizations in developing a countermeasure for a cyber-breach reduces each firm's cost of investment in cyber defense. Despite its multiple advantages, there are costs and risks associated with cyber-threats information sharing. When a firm shares its vulnerabilities with others there is a risk that these vulnerabilities are leaked to the public (or to attackers) resulting in loss of reputation, market share and revenue. Therefore, in this strategic environment the firms committed to share cyber-threats information might not truthfully share information due to their own self-interests. Moreover, some firms acting selfishly may rationally limit their cybersecurity investment and rely on information shared by others to protect themselves. This can result in under investment in cybersecurity if all participants adopt the same strategy. This paper will use game theory to investigate when multiple self-interested firms can invest in vulnerability discovery and share their cyber-threat information. We will apply our algorithm to a public cloud computing platform as one of the fastest growing segments of the cyberspace. Charles A. Kamhoua, Andrew P. Martin, Deepak K. Tosh, Kevin A. Kwiat, Chad Heitzenrater, Shamik Sengupta |
CSCloud | 6 |
| 2015 | Game Theoretic Modeling to Enforce Security Information Sharing among FirmsabstractRobust CYBersecurity information EXchange (CYBEX) infrastructure is envisioned to protect the firms from future cyber attacks via collaborative threat intelligence sharing, which might be difficult to achieve via sole effort. The executive order from the U. S. federal government clearly encourages the firms to share their cybersecurity breach and patch related information among other federal and private firms for strengthening their as well as nation's security infrastructure. In this paper, we present a game theoretic framework to investigate the economic benefits of cyber-threat information sharing and analyze the impacts and consequences of not participating in the game of information exchange. We model the information exchange framework as distributed non-cooperative game among the firms and investigate the implications of information sharing and security investments. The proposed incentive model ensures and self-enforces the firms to share their breach information truthfully for maximization of its gross utility. Theoretical analysis of the incentive framework has been conducted to find the conditions under which firms' net benefit for sharing security information and investment can be maximized. Numerical results verify that the proposed model promotes such sharing, which helps to relieve their total security technology investment too. Deepak K. Tosh, Shamik Sengupta, Sankar Mukhopadhyay, Charles A. Kamhoua, Kevin A. Kwiat |
CSCloud | 2 |
| 2015 | An evolutionary game-theoretic framework for cyber-threat information sharingabstractThe initiative to protect against future cyber crimes requires a collaborative effort from all types of agencies spanning industry, academia, federal institutions, and military agencies. Therefore, a Cybersecurity Information Exchange (CYBEX) framework is required to facilitate breach/patch related information sharing among the participants (firms) to combat cyber attacks. In this paper, we formulate a non-cooperative cybersecurity information sharing game that can guide: (i) the firms (players)1to independently decide whether to “participate in CYBEX and share” or not; (ii) the CYBEX framework to utilize the participation cost dynamically as incentive (to attract firms toward self-enforced sharing) and as a charge (to increase revenue). We analyze the game from an evolutionary game-theoretic strategy and determine the conditions under which the players' self-enforced evolutionary stability can be achieved. We present a distributed learning heuristic to attain the evolutionary stable strategy (ESS) under various conditions. We also show how CYBEX can wisely vary its pricing for participation to increase sharing as well as its own revenue, eventually evolving toward a win-win situation. Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat, Andrew P. Martin |
ICC | 2 |
| 2015 | Distributed and cheat-proof spectrum contention scheme for IEEE 802.22 WRAN networksabstractIEEE 802.22 wireless regional area networks (WRANs) are cognitive radio-based wireless networks that opportunistically access sub-900 MHz TV bands for their operations. IEEE 802.22 WRANs are continuously faced with self-coexistence problems. The adaptive on-demand spectrum contention (ODSC) protocol has been proposed as a possible solution to the problem of self-coexistence in such networks. Unfortunately, the design of ODSC protocol contains some major flaws, which makes the scheme cheat-prone and less efficient for resolution of spectrum contentions among networks. In this paper, we highlight the main problems associated with the implementation of ODSC as a spectrum contention protocol. We propose a scalable and cheat-proof scheme for spectrum contention that guarantees fairness and system efficiency. We show the performance of proposed scheme with different network topologies. Simulation results show substantial improvement in system performance via channel reuse, with significant levels of fairness in spectrum utilization. Kenneth Ezirim, Ligon Liu, Shamik Sengupta |
WCNC | 4 |
| 2015 | Performance analysis of CR-honeynet to prevent jamming attack through stochastic modeling
Suman Bhunia, Shamik Sengupta, Felisa J. Vázquez-Abad |
Pervasive Mob. Comput. | 2 |
| 2013 | Self-Coexistence in Cognitive Radio Networks Using Multi-Stage Perception LearningabstractIn this paper, we study the self-coexistence problem among competitive Cognitive Radio (CR) networks in an uncoordinated distributed wireless environment of homogeneous and heterogeneous bands. This problem can be correlated with famous optimal foraging theory, where the humming birds forage to explore islands in search of food sources to survive. The behavior of learning from observations leads them to find island of optimal resources. The proposed perception based learning mechanism for homogeneous spectra, helps the CR networks to strategize their choice of actions on the basis of rewards gathered from the accessed spectrum bands and successfully grab a clear chunk of spectrum. However, in heterogeneous bands scenario, the CR networks inadvertently choose the best suitable band greedily which lead them to collision. We incorporate a regret minimization technique with the proposed learning mechanism to resolve the contention among them and maximize system performance. Experimental results conclude that the networks could achieve the objective of finding a free spectrum with maximized system utility using the proposed heuristic within limited number of interactions. Deepak K. Tosh, Shamik Sengupta |
VTC Fall | 2 |
| 2013 | Vulnerabilities in cognitive radio networks: A survey
Shameek Bhattacharjee, Shamik Sengupta, Mainak Chatterjee |
Comput. Commun. | 2 |
| 2013 | Self-coexistence among interference-aware IEEE 802.22 networks with enhanced air-interface
Shamik Sengupta, Swastik Brahma, Mainak Chatterjee, Sai Shankar Nandagopalan |
Pervasive Mob. Comput. | 1 |
| 2013 | SpiderRadio: A Cognitive Radio Implementation Using IEEE 802.11 ComponentsabstractIn this paper, we present SpiderRadio, a software defined cognitive radio (CR) prototype for dynamic spectrum access (DSA) networking. The medium access control (MAC) layer of SpiderRadio is implemented in software on top of commodity IEEE 802.11a/b/g hardware. However, the proposed architecture and implementation are applicable to other spectrum bands as well. We also present a dynamic spectrum sensing methodology for primary incumbent detection. The proposed method is based on observing the PHY errors, received signal strength and statistical model building. For coordination among radio nodes, synchronization and fast channel switching, we present new communication protocols, design extended management frame structure and modify the hardware abstraction layer. Several fundamental tradeoffs (e.g., complexity versus network performance) to be considered during a dynamic spectrum access radio network prototype implementation are also discussed in detail. To demonstrate the practical capabilities of the proposed SpiderRadio prototype, we also present various testbed experimental measurement results. Kai Hong, Shamik Sengupta, Rajarathnam Chandramouli |
IEEE Trans. Mob. Comput. | 2 |
| 2012 | Designing a collector overlay architecture for fault diagnosis in video networks
Mukundan Venkataraman, Shamik Sengupta, Mainak Chatterjee, Raja Neogi |
Comput. Commun. | 2 |
| 2012 | MAximum SPECTrum packing: a distributed opportunistic channel acquisition mechanism in dynamic spectrum access networksabstractThe authors present a distributed channel acquisition mechanism in dynamic spectrum access (DSA) networks. A novel graph MAximum SPECTrum packing algorithm (MASPECT) is proposed for a system with N secondary networks. Each secondary network makes use only of the local topology information to resolve contentions during channel access. The proposed algorithm also adapts easily to topological changes. Most approaches to channel acquisition use either centralised graph colouring or distributed approaches that result in under utilisation of spectrum. The authors show that the proposed MASPECT algorithm results in improvements by up to one order of magnitude in the spectrum utilisation for the secondary networks and results in Jain's fairness index of about 0.9. The authors further present a modified probabilistic heuristic, PMASPECT, that improves the termination time of the algorithm by up to two orders of magnitude. The authors also study the impact of the MASPECT algorithm on each individual secondary networks in the system in the presence of primary activity. For each secondary network, the proposed algorithm results in up to two orders of magnitude of reduction in the call blocking dropping probabilities in the presence of primary activity. Santhanakrishnan Anand, Shamik Sengupta, Rajarathnam Chandramouli |
IET Commun. | 2 |
| 2012 | Primary user emulation attack in dynamic spectrum access networks: a game-theoretic approachabstractCognitive radio (CR) enabled dynamic spectrum access (DSA) networks are designed to detect and opportunistically utilise the unused or under-utilised spectrum bands. However, due to the open paradigm of CR networks and lack of proactive security protocols, the DSA networks are vulnerable to various denial-of-service threats. The authors propose a game-theoretic framework to study the primary user emulation attack (PUEA) on CR nodes. A non-cooperative dynamic multistage game between the secondary nodes and the adversaries generating the PUEA is formulated. The pure-strategy and mixed-strategy Nash equilibria for the secondary user and malicious attacker are investigated. Moreover, a novel belief updating system is proposed for the secondary user to learn the state of the primary user as the game evolves. Simulation results demonstrate that the proposed belief updating system achieves better performance than other models for the secondary user in terms of greater payoff, lower probability of missing primary user and better robustness to the inaccurate estimation of the primary user's state. Shamik Sengupta, K. P. Subbalakshmi |
IET Commun. | 2 |
| 2012 | Power Control Game in Multi-Terminal Covert Timing ChannelsabstractWe present a game theoretic power control of overlay/overt communications to maximize the goodput (effective throughput of error-free bits) of multi-terminal covert timing channels. Most approaches in the literature on covert timing channels discuss capacities of the timing channels but do not study how the overlay communication can be controlled to maximize the goodput of covert timing channels. We study the factors of the overlay communication that affect the goodput of each timing channel in a multi-terminal covert timing network. We show that the goodput of the covert timing channel can be enhanced by increasing the rate of overlay transmission and by game theoretic power control of overlay communication. We finally extend the game theoretic power control to maximize the goodput of each covert timing channel in a multi-terminal covert timing network by maximizing the asymptotic spectral efficiency of the overlay communication. Santhanakrishnan Anand, Shamik Sengupta, Kai Hong, Rajarathnam Chandramouli |
IEEE J. Sel. Areas Commun. | 2 |
| 2011 | Security Vulnerability Due to Channel Aggregation/Bonding in LTE and HSPA+ NetworkabstractWe address a unique security vulnerability in long term evolution (LTE) advanced and high speed packet access (HSPA+) wireless networks due to carrier/channel bonding. This vulnerability is shown to result in various amounts of service disruption based on the radio network parameters and the user locations. Typically, channel bonding have been perceived as a means to enhance the bandwidth and throughput for the users. However, this could also result in the loss of orthogonality between the bonded spectrum bands. We show that this leads to a security vulnerability that can be exploited by an attacker to cause service disruption. In this case, the attacker need not even operate in the same bands as the user, to be effective. We present an analysis to compare the loss in throughput caused by the vulnerability due to channel bonding in advanced LTE and HSPA+ networks. Results indicate that channel bonding is susceptible to about 70% loss of throughput in LTE networks and about 11-15% in HSPA+ networks compared to systems with no bonding. Also, users farther away from the base station suffer larger throughput degradation due to channel bonding in LTE networks, while it causes larger degradation in throughput for near users in HSPA+ networks. To the best of our knowledge, this is the first attempt to identify and analyze a significant security vulnerability in LTE and HSPA+ networks. Santhanakrishnan Anand, Kai Hong, Rajarathnam Chandramouli, Shamik Sengupta, K. P. Subbalakshmi |
GLOBECOM | 4 |
| 2011 | Using Sybil Identities for Primary User Emulation and Byzantine Attacks in DSA NetworksabstractIn this paper, we investigate a new type of denialof- service attack in dynamic spectrum access networks - Sybilenabled attack. In this attack, the attacker not only launches the primary user emulation (PUE) attacks but also creates and infiltrates multiple Sybil identities to compromise the decision making process of the secondary network via Byzantine attacks. We implement this attack in our cognitive radio testbed to show its feasibility and attack impact. We further analyze the optimal attack strategy from the perspective of the malicious attacker, i.e., the optimal allocation of Sybil interfaces for different attacks, to maximize the impact on the secondary network. The attack models are analyzed under two different scenarios: with and without a reputation system in the network fusion center. Numerical analysis and simulations are conducted to solve the optimal attack strategy and demonstrate the impact of attacks on the secondary network. Kai Hong, Shamik Sengupta, K. P. Subbalakshmi |
GLOBECOM | 3 |
| 2011 | Human Society Inspired Dynamic Spectrum Access Networks: The Effect of ParochialismabstractIn this paper, we investigate the parochialism in dynamic spectrum access networks and its effect on spectrum resource competition and self-coexistence among cognitive radio secondary users. We assume that some greedy secondary users in the network form a parochial community in private and try to maximize their own utilities without concern for the interests of other secondary users outside the community. A noncooperative game is formulated first to analyze the equilibrium strategy of secondary users without any parochial community in the network. In the scenario where there is a parochial community, we analyze the expected payoff for the insider secondary users who deviate from the Nash equilibrium and derive the optimal strategy for them. Through numerical analysis, we see how the optimal strategies for the secondary users inside the parochial community in different circumstances deviate from Nash equilibrium. Simulation results demonstrate that being a part of the parochial community, the secondary users can obtain more utility than the outsider secondary users and the system will change from an equilibrium to an unfair situation. Shamik Sengupta, K. P. Subbalakshmi |
GLOBECOM | 2 |
| 2011 | Is Channel Fragmentation/bonding in IEEE 802.22 Networks Secure?abstractWe address a unique security threat that arises due to channel fragmentation (or aggregation or bonding) in dynamic spectrum access (DSA) based IEEE 802.22 networks. Typically, channel fragmentation, aggregation and bonding have been studied in the literature as a means to enhance the spectrum utilization. However, the loss of orthogonality between the spectrum bands due to channel fragmentation, aggregation or bonding can be exploited by malicious attackers to cause a cognitive service disruption. We present an analysis of such a threat. We determine the optimal transmit powers a malicious attacker transmits on each fragment, so as to create maximum service disruption. Numerical results indicate that a malicious attacker can cause up to about 16% loss in the capacity of the system as a consequence of fragmentation. Detailed analysis is presented for channel fragmentation and can be easily applied to channel aggregation and bonding. To the best of our knowledge,this is the first analysis of such cognitive service disruption threats due to fragmentation. Santhanakrishnan Anand, Kai Hong, Shamik Sengupta, Rajarathnam Chandramouli |
ICC | 3 |
| 2011 | Spectrum Stealing via Sybil Attacks in DSA Networks: Implementation and DefenseabstractIn this paper, we investigate Sybil attacks on spectrum allocation in distributed dynamic spectrum access (DSA) networks. Using IEEE 802.11 devices as secondary nodes, we demonstrate the feasibility of mounting Sybil attacks in the cognitive radio testbed, in which the malicious node poses as multiple normal secondary nodes with different identities in order to steal more spectrum bands. We also show the impact of the attack through an example and simulation results. A defense strategy using the statistics of beacon intervals is also proposed. Through experimental results, we show the effectiveness of this defense mechanism when there is no interference from external sources as well as in the presence of interference. Kai Hong, Shamik Sengupta, K. P. Subbalakshmi |
ICC | 3 |
| 2011 | Analysis of Coordinated Denial-of-Service Attacks in IEEE 802.22 NetworksabstractThe cognitive radio enabled IEEE 802.22 wireless regional area network (WRAN) is designed to opportunistically utilize the unused or under-utilized TV bands. However, due to the open nature of cognitive radio networks and lack of proactive security protocols, the IEEE 802.22 networks are vulnerable to various denial-of-service (DoS) threats. In this paper, we study coordinated DoS attacks on IEEE 802.22 networks from the malicious users' perspective. We consider both one-stage and a multi-stage cases of the problem. In the one-stage scenario, we formulate a cooperative game among the malicious nodes and derive the optimal decision strategy for the them. In the multi-stage case, we propose a discrete-time Markov chain model for the dynamic behavior of both malicious nodes and the 802.22 secondary networks. Simulation and numerical results demonstrate that in the one-stage case, the coordinated attack achieves 10-15% improvement compared to the non-cooperative attack from the perspective of malicious nodes, and, in the multi-stage case, there exists an optimal number of malicious nodes that maximize the net payoff under the steady state. Shamik Sengupta, K. P. Subbalakshmi |
IEEE J. Sel. Areas Commun. | 2 |
| 2010 | Competitive Spectrum Trading in Dynamic Spectrum Access Markets: A Price WarabstractThe concept of dynamic spectrum access (DSA) enables the licensed spectrum to be traded in an open market where the unlicensed users can freely buy and use the available licensed spectrum bands. However, like in the other traditional commodity markets, spectrum trading is inevitably accompanied by various competitions and challenges. In this paper, we study an important business competition activity - price war in the DSA market. A non-cooperative pricing game is formulated to model the contention among multiple wireless spectrum providers for higher market share and revenues. We calculate the Pareto optimal pricing strategies for all providers and analyze the motivations behind the price war. The potential responses to the price war are in-depth discussed. Numerical results demonstrate the efficiency of the Pareto optimal strategy for the game and the impact of the price war to all participants. Shamik Sengupta, K. P. Subbalakshmi |
GLOBECOM | 2 |
| 2010 | Cross-Layer MAC Enabling Virtual Link for Multi-Hop Routing in Wireless Ad Hoc NetworksabstractEfficient routing is a fundamental issue in multi-hop wireless ad hoc networks. In this paper, we study the limitation of traditional routing structure in multi-hop wireless ad hoc networks due to (a) the layered structure of a wireless protocol stack and (b) the lack of coordination between medium access control (MAC) and routing protocols. These limitations result in long processing delays in a relay/forwarding node. In order to alleviate these issues, we propose a solution based on cross-layer MAC design, which improves the coordination between MAC and routing layers using an idea we call ``virtual link". The virtual link idea was implemented and tested in an ad hoc wireless network testbed. Experimental results show that the proposed cross-layer design significantly improves the performance in terms of reduced round trip time (RTT), reduced processing time in the intermediate relay/forwarding nodes and increased throughput compared to a legacy architecture. Kai Hong, Shamik Sengupta, Rajarathnam Chandramouli |
ICC | 2 |
| 2010 | SpiderRadio: An Incumbent Sensing Implementation for Cognitive Radio Networking Using IEEE 802.11 DevicesabstractSpectrum sensing is one of the critical features in cognitive radio based dynamic spectrum access networking. In this paper, we discuss a new spectrum sensing technique for primary incumbent detection. The proposed method is based on observing the PHY errors, received signal strength and n-moving window averaging of the observed measurement. The sensing parameters are dynamically optimized based on the operating radio environment. This sensing method is implemented in SpiderRadio, a cognitive radio testbed based on off-the-shelf IEEE 802.11 devices. Experimental results show that the proposed technique results in very low sensing delay and failure probability. Kai Hong, Shamik Sengupta, Rajarathnam Chandramouli |
ICC | 2 |
| 2010 | Coordinated Denial-of-Service Attacks in IEEE 802.22 NetworksabstractThe cognitive radio enabled IEEE 802.22 wireless regional area network (WRAN) is designed to opportunistically utilize the unused or under-utilized TV bands. However, due to the lack of proactive security protocols and proper interaction policies among the secondary networks themselves, the IEEE 802.22 networks are vulnerable to various denial-of-service (DoS) threats. In this paper, we study the impact of coordinated DoS attacks on IEEE 802.22 networks from the malicious nodes' perspective. Assuming that multiple malicious nodes will launch coordinated attacks, we formulate a cooperative game among the malicious nodes. The expression of the net payoff is derived and the optimal decision strategy for the malicious nodes is obtained numerically. Simulation results demonstrate that the coordinated attack approach can enhance as high as 10-15% more net payoff for the malicious nodes than the uncoordinated attack. Shamik Sengupta, K. P. Subbalakshmi |
ICC | 2 |
| 2010 | An Attack-Defense Game Theoretic Analysis of Multi-Band Wireless Covert Timing NetworksabstractWe discuss malicious interference based denial of service (DoS) attacks in multi-band covert timing networks using an adversarial game theoretic approach. A covert timing network operating on a set of multiple spectrum bands is considered. Each band has an associated utility which represents the critical nature of the covert data transmitted in the band. A malicious attacker wishes to cause a DoS attack by sensing and creating malicious interference on some or all of the bands. The covert timing network deploys camouflaging resources to appropriately defend the spectrum bands. A two tier game theoretic approach is proposed to model this scenario. The first tier of the game is the sensing game in which, the covert timing network determines the amount of camouflaging resources to be deployed in each band and the malicious attacker determines the optimal sensing resources to be deployed in each band. In the second tier of the game, the malicious attacker determines the optimal transmit powers on each spectral band it chooses to attack. We prove the existence of Nash equilibriums for the games. We compare the performance of our proposed game theoretic mechanism with that of other well known heuristic mechanisms and demonstrate the effectiveness of the proposed approach. Santhanakrishnan Anand, Shamik Sengupta, Rajarathnam Chandramouli |
INFOCOM | 2 |
| 2010 | A Game Theoretic Framework for Power Control in Wireless Sensor NetworksabstractIn infrastructure-less sensor networks, efficient usage of energy is very critical because of the limited energy available to the sensor nodes. Among various phenomena that consume energy, radio communication is by far the most demanding one. One of the effective ways to limit unnecessary energy loss is to control the power at which the nodes transmit signals. In this paper, we apply game theory to solve the power control problem in a CDMA-based distributed sensor network. We formulate a noncooperative game under incomplete information and study the existence of Nash equilibrium. With the help of this equilibrium, we devise a distributed algorithm for optimal power control and prove that the system is power stable only if the nodes comply with certain transmit power thresholds. We show that even in a noncooperative scenario, it is in the best interest of the nodes to comply with these thresholds. The power level at which a node should transmit, to maximize its utility, is evaluated. Moreover, we compare the utilities when the nodes are allowed to transmit with discrete and continuous power levels; the performance with discrete levels is upper bounded by the continuous case. We define a distortion metric that gives a quantitative measure of the goodness of having finite power levels and also find those levels that minimize the distortion. Numerical results demonstrate that the proposed algorithm achieves the best possible payoff/utility for the sensor nodes even by consuming less power. Shamik Sengupta, Mainak Chatterjee, Kevin A. Kwiat |
IEEE Trans. Computers | 1 |
| 2009 | A Collector Overlay Architecture for Fault Diagnosis in Access NetworksabstractTo prevent subscriber churn, network service providers of VoD, SDV and IPTV have a pressing need to pro-actively detect, isolate and fix outages within an access network. Network induced degradations prove to be detrimental for streaming applications. This typically leads to a poor quality of experience (QoE) for subscribers. By monitoring key functional points of the access network for traces of degradation, service providers can devise mechanisms to mitigate the problem. In this work we propose a hierarchy of exporters, collectors and ANCON (ANalysis and CONtrol) nodes that can semi-autonomously monitor, detect and isolate impairments within an access network. Exporters on the data plane gather and disseminate statistics for individual subnets, which are streamed onto "collector" nodes on an orthogonal plane. Collector nodes aggregate traffic from various exporters, and stream them onto the root of the tree (ANCON). With an even placement of exporters, root cause analysis can now take the granularity of loss rates or delay rates in individual segments or subnets of an access network. As an extension to our architecture, we show that the overlay can support instrumentations of quality evaluation for streaming video. As an example, we use a simple MOS model that is in part an extension of the ITU-T Erlang model to predict the quality of a video stream much before it reaches the end user. Extensive simulations are presented to justify the design choices made in the process. Mukundan Venkataraman, Shamik Sengupta, Mainak Chatterjee, Raja Neogi |
CCNC | 2 |
| 2009 | Dynamic spectrum access in cognitive radio based tactical networksabstractIn this paper, we investigate how cognitive radio (CR) enabled devices can self-organize to form a tactical mesh network and operate on non-dedicated (secondary) spectrum. Each node in the network constantly senses the environment and maintains an up-to-date spectrum usage report. This report is used by a central controller (CC) to initialize the network formation. Then the other CR nodes gradually join the mesh network in a repeated, distributed manner. We provide the detailed steps for the mesh creation and also propose some refinements. We also compute the spectral efficiency that is achieved through our algorithm. Through simulation experiments, we study the effectiveness of the proposed schemes on mesh initialization latency, control signaling, collision rate during network initialization, and spectrum utilization. Shamik Sengupta, Mainak Chatterjee, Kevin A. Kwiat |
WCNC | 1 |
| 2009 | An economic framework for dynamic spectrum access and service pricing
Shamik Sengupta, Mainak Chatterjee |
IEEE/ACM Trans. Netw. | 1 |
| 2008 | A Game Theoretic Framework for Distributed Self-Coexistence Among IEEE 802.22 NetworksabstractThe cognitive radio based IEEE 802.22 wireless regional area network (WRAN) is designed to operate in the under-utilized TV bands by detecting and avoiding primary TV transmission bands in a timely manner. Such networks, deployed by competing wireless service providers, would have to self-coexist by accessing different parts of the available spectrum in a distributed manner. Obviously, the goal of every network is to acquire a clear spectrum chunk free of interference from other IEEE 802.22 networks so as to satisfy the QoS of the services delivered to the end-users. In this paper, we study the distributed WRAN self-coexistence problem from a minority game theoretic perspective. We model the spectrum band switching game where the networks try to minimize their cost in finding a clear band. We propose a mixed strategy that the competing networks must adhere to in order to achieve the Nash equilibrium. Simulation experiments have also been conducted and results corroborate with the theoretical analysis. Shamik Sengupta, Rajarathnam Chandramouli, Swastik Brahma, Mainak Chatterjee |
GLOBECOM | 1 |
| 2008 | Designing Auction Mechanisms for Dynamic Spectrum Access
Shamik Sengupta, Mainak Chatterjee |
Mob. Networks Appl. | 1 |
| 2008 | Improving Quality of VoIP Streams over WiMaxabstractReal-time services such as VoIP are becoming popular and are major revenue earners for network service providers. These services are no longer confined to the wired domain and are being extended over wireless networks. Although some of the existing wireless technologies can support some low-bandwidth applications, the bandwidth demands of many multimedia applications exceed the capacity of these technologies. The IEEE 802.16-based WiMax promises to be one of the wireless access technologies capable of supporting very high bandwidth applications. In this paper, we exploit the rich set of flexible features offered at the medium access control (MAC) layer of WiMax for the construction and transmission of MAC protocol data units (MPDUs) for supporting multiple VoIP streams. We study the quality of VoIP calls, usually given by R-score, with respect to the delay and loss of packets. We observe that loss is more sensitive than delay; hence, we compromise the delay performance within acceptable limits in order to achieve a lower packet loss rate. Through a combination of techniques like forward error correction, automatic repeat request, MPDU aggregation, and minislot allocation, we strike a balance between the desired delay and loss. Simulation experiments are conducted to test the performance of the proposed mechanisms. We assume a three-state Markovian channel model and study the performance with and without retransmissions. We show that the feedback-based technique coupled with retransmissions, aggregation, and variable length MPDUs are effective and increase the R-score and mean opinion score by about 40 percent. Shamik Sengupta, Mainak Chatterjee, Samrat Ganguly |
IEEE Trans. Computers | 1 |
| 2007 | Enhancements to Cognitive Radio Based IEEE 802.22 Air-InterfaceabstractThe IEEE 802.22 standard for wireless regional area network is the first standard for cognitive radio that tries to harness the idle or under-utilized spectrum allocated for TV bands. Two major challenges that are faced by IEEE 802.22 are (i) the issue of self co-existence and (ii) the hidden incumbent problem. In this paper, we discuss these two challenges and provide enhancements to the existing IEEE 802.22 air-interface. We use a graph theoretic technique and propose utility graph coloring for allocating spectrum to different IEEE 802.22 base stations so that they can co-exist. The allocation is done such that objectives such as throughput maximization, proportional fairness, and complete fairness are met. We also propose the use of dynamic multiple broadcast messages that resolves the contention among various consumer premise equipments and alleviates the hidden incumbent problem. Through simulation results, we show that the proposed techniques increase the system spectrum utilization and reduce connection set-up delay. Shamik Sengupta, Swastik Brahma, Mainak Chatterjee, Sai Shankar Nandagopalan |
ICC | 1 |
| 2007 | Performance Modeling of Multi-Rate HDR and its Effect on TCP ThroughputabstractAn interesting feature of the 3G cellular networks is their ability to support multiple data rates. Though the performance of TCP over wireless networks has been well studied, there is still no clear understanding on the expected throughput of TCP over multi-rate cellular systems. In this work, we consider a multi-rate system like High Data Rate (HDR) and represent the state space using a Markov chain. We calculate the state transition probabilities assuming transitions are possible between adjacent states only. We calculate the expected data rate conditioned to the initial state both analytically and through simulations. We use an M/G/l queuing model to capture the delay and TCP throughput for each of the initial states. We also illustrate how TCP throughput is affected by parameters like velocity, bit error rate, window size, TCP loss rate, and the underlying radio link protocol. Wenjing Wang 0006, Shamik Sengupta, Mainak Chatterjee |
ICC | 2 |
| 2006 | Improving R-Score of VoIP Streams over WiMaxabstractIn this paper, we exploit the flexible features in the medium access control (MAC) layer of WiMax for construction and transmission of MAC protocol data units (MPDU) for supporting multiple VoIP streams over a WiMax link. Quality of VoIP calls, usually given by R-score, is studied with respect to delay and loss of packets. We observe that loss is more sensitive than delay, hence we trade delay for loss. We propose a combination of techniques that exploit the flexibility of the WiMax MAC layer to strike a balance between loss and delay. These techniques are forward error correction, automatic repeat request, MPDU aggregation, and minislot allocation. Simulation experiments are conducted to test the performance of the proposed mechanisms. We assume a three-state Markovian channel model and study the performance with and without retransmissions. We show that the feedback-based technique coupled with retransmissions, aggregation, and variable length MPDUs are effective and increases the R-score by about 40%. Shamik Sengupta, Mainak Chatterjee, Samrat Ganguly, Rauf Izmailov |
ICC | 1 |
| 2006 | Differential FEC and ARQ for Radio Link ProtocolsabstractTo bring TCP-based services to the mobile devices in a cellular network, it is necessary that TCP be extended over the wireless link. However, the performance of TCP severely degrades in a wireless medium. Hence, radio link protocols (RLPs) are used as an interface between TCP and the physical medium. RLPs fragment TCP segments into frames and use robust error correcting codes and fast retransmission schemes to shield the channel related losses from TCP, thus preventing TCP throughput degradation. In this paper, we show the limitations of the existing RLPs, which do not differentiate the frames generated from the same TCP segment. We claim that if selective frames are made more robust to transmission failures, then the performance of RLP and, hence, TCP can be improved. We identify such decisive frames and categorize them as crucial and noncrucial. Our claim is based on the fact that initial frames can afford a few trials of retransmissions, whereas the later ones cannot. We treat the frames differentially with respect to forward error correcting (FEC) coding and automatic repeat request (ARQ) schemes. We consider specific cases of FEC and ARQ strategies and show the qualitative difference in the performance of the RLP through analysis and simulations. The gain in the performance is more prominent when both FEC and ARQ (hybrid-ARQ) are used. The increase in TCP throughput with the proposed RLP is also demonstrated Jaideep Sarkar, Shamik Sengupta, Mainak Chatterjee, Samrat Ganguly |
IEEE Trans. Computers | 2 |
| 2005 | WRN: improving system performance in 3G networks through fixed multi-hop relay nodesabstractNon-uniform coverage and low system throughput due to location dependent fading in cellular networks is a major bottleneck in providing quality of service. Moreover, the growing number of stand-alone Wi-Fi hotspots is creating competition for 3G cellular networks. We propose an architecture which augments the existing 3G downlink technology with Wi-Fi like relay nodes leveraging benefits of both forms to improve the 3G system performance and provide uniform coverage throughout the cell. The relay nodes in the proposed WRN (Wi-Fi like relay network) architecture are equipped with a dual radio interface to communicate with the base station and other relay nodes. We compare the performance of the existing CDMA/HDR-based 3G cellular network with the proposed WRN architecture in terms of throughput and blocking probability. We demonstrate how pre-engineered deployment of relay nodes can yield better performance than random deployment of relay nodes. Simulation experiments are conducted to corroborate our analytical findings. The system throughput is not only enhanced, but the fairness among users is also maintained. Shamik Sengupta, Mainak Chatterjee, Samrat Ganguly, Rauf Izmailov |
WCNC | 1 |
| 2005 | Exploiting MAC Flexibility in WiMAX for Media StreamingabstractThe IEEE 802.16 standard (commonly known as WiMAX), which has emerged as a broadband wireless access technology, is capable of delivering very high data rates. However, providing performance guarantees to delay sensitive applications like streaming media is still a challenge. We study the media access control (MAC) layer of WiMAX and exploit its flexible features to construct MAC packet data units (MPDU) dynamically. The sizes of the MPDUs are constantly modified based on channel state information. The desired payload is obtained either by aggregation or fragmentation of the upper layer data units. The robustness of MPDUs is also made tunable by means of cyclic redundancy code bits. We consider both the scenarios - with and without feedback. We adhere to the 802.16 specifications and propose adapting the MPDU length for streaming media for better performance. Three metrics are defined: restore probability; goodput; dropping probability. Simulation experiments are conducted which show the performance enhancements of the proposed ARQ-enabled adaptive algorithm in terms of these three metrics. Shamik Sengupta, Mainak Chatterjee, Samrat Ganguly, Rauf Izmailov |
WOWMOM | 1 |