VLDB 2026 Research / reviewers in the wild / expert
Zahid Anwar
dblp:62/3931
· DBLP profile ↗
32ranked-venue papers
6as first author
8since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 2 since 2021Systems, architecture and hardware · 7 · 1 first-authorComputer networks · 6 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A Unified Deep Learning Diagnostic Architecture for Big Data Healthcare AnalyticsabstractHealthcare automation is evolving rapidly as can been seen in the recent popularity of e-health or digital health systems. The massive amount of health related data produced by these systems has given rise to the field of health informatics. The World Health organization (WHO) decomposes SMARThealth as Standards-based, Machine-readable, Adaptive, Requirementsbased, and Testable, and provides guidelines for digital health. Heterogeneous and big health data health that flows into the cloud requires considerations for uniformity of structure to allow for interoperability and generalizability for universal use and analysis. This research proposes a deep-learning architecture for disease diagnosis that considers Diabetes Mellitus (DM) as a case study. Three corpuses containing DM patient data are considered which are prepared and processed using extensive data warehousing techniques and labeled with ICD-10-CM diagnostic codes. Extraction of desired health data is through a unified data model for healthcare that is in compliance with HL7 FHIR v4.0 schema. Our contributions are two-fold: First, three big data cloud analytical models are proposed and validated on the unified corpora and second the maximum possible diseases specific to a single or multiple DM patients have been diagnosed with a 100% accuracy using deep multinomial/multi-label distribution learning (DMDL). Sarah Shafqat, Zahid Anwar, Qaisar Javaid, Hafiz Farooq Ahmad |
ISADS | 2 |
| 2023 | A systematic threat analysis and defense strategies for the metaverse and extended reality systems
Sara Qamar, Zahid Anwar, Mehreen Afzal |
Comput. Secur. | 2 |
| 2023 | Airborne Computing: A Toolkit for UAV-Assisted Federated Computing for Sustainable Smart CitiesabstractSmart vehicles are equipped with onboard computing units designed to run in-vehicle applications. However, due to limited computing power, the onboard units are unable to execute compute-intensive tasks and those that require near real-time processing. Therefore tasks are offloaded to nearby fog/edge devices that have more powerful processors. However, the fog devices are static, placed at fixed locations such as intersections, and have a limited communication range. Therefore, they can only facilitate vehicles in their immediate vicinity and only limited areas of the city can be covered to provide services on demand. In this article, we propose an unmanned aerial vehicle (UAV)-based computing framework design termed Skywalker to provide computing in regions where there are no static fog units thereby extending coverage. Skywalker’s contributions are threefold: 1) it allows for load-aware UAV placement and provisions a swarm of UAVs to fly to areas experiencing a gap in service where the size of the swarm is proportional to the demand; 2) it implements multiple scheduling algorithms that the UAVs swarm employs to divide up the task processing responsibility for individual UAVs within the swarm; and 3) a zone-based delivery mechanism is being proposed to facilitate the return of completed tasks, either through direct delivery or relay-based methods. The choice between these options depends on the distance covered by the requesting vehicle from the UAV swarm. The efficiency of the framework is compared with existing techniques and it is found that it can greatly extend coverage during peak traffic hours while providing low communication delay and consuming minimum energy. Kadhim Hayawi, Zahid Anwar, Asad Waqar Malik, Zouheir Trabelsi |
IEEE Internet Things J. | 2 |
| 2023 | A Novel Framework for Studying the Business Impact of Ransomware on Connected VehiclesabstractConnected vehicle technology is rapidly evolving. In the U.S., the government targets that 50% of all vehicles be electric by 2030 in order to reduce climate change. This initiative comes in the wake of an increased spate of ransomware attacks targeting transportation companies. Unlike traditional ransomware targeting computer networks, the compromise of vehicles can have disastrous consequences on businesses and ultimately the national economy as was evident in the recent Colonial pipeline attack. This research proposes a novel framework to study the spread of ransomware and its impact on connected vehicles. Our contribution is fourfold: 1) three different ransomware infection vectors are considered for connected vehicles, namely, a hotspot attack, OBD dongle attack, and malicious over-the-air updates; 2) business impact of the ransomware is analyzed on a ride-hailing service; 3) a fog computing architecture is used to reduce latency in vehicle-to-vehicle communication and vehicle to base station communication; and 4) the effectiveness of safeguard controls are studied in mitigating the ransomware spread. Our results show that ransomware can have a debilitating impact on connected vehicle businesses due to their high mobility and connectivity with attacks on average impacting earnings by 45% per hour. Asad Waqar Malik, Zahid Anwar, Anis Ur Rahman 0001 |
IEEE Internet Things J. | 2 |
| 2022 | Privacy Limits in Power-Law Bipartite Networks under Active Fingerprinting AttacksabstractThis work considers necessary conditions for privacy guarantees under active fingerprinting attacks in power-law bipartite networks. The scenario arises naturally in social network analysis, tracking user mobility in wireless networks, and forensics applications, among others. A stochastic growing network generation model — called the popularity-based model — is investigated, where the bipartite network is generated iteratively, and in each iteration vertices attract new edges based on their assigned popularity values. It is shown that using the appropriate choice of initial popularity values, the node degree distribution follows a power-law distribution with arbitrary parameter α > 2, i.e. fraction of nodes with degree d is proportional to d−α. An active fingerprinting deanonymization attack strategy called the augmented information threshold attack strategy (A-ITS) is proposed which uses the attacker’s knowledge of the node degree distribution along with the concept of information values for deanonymization. Sufficient conditions for the success of the A-ITS, based on network parameters, are derived. It is shown through simulations that the proposed attack significantly outperforms the state-of-the-art attack strategies. Mahshad Shariatnasab, Farhad Shirani Chaharsooghi, Zahid Anwar |
ISIT | 3 |
| 2022 | Spatiotemporal Clustering and Analysis of Road Accident Hotspots by Exploiting GIS Technology and Kernel Density EstimationabstractAbstract Traffic accidents are a common problem in any transportation network. Road traffic accidents are predicted to be the seventh leading cause of deaths by the year 2030. Recently research in the integration of geographical information systems (GIS) for analyzing accidents, road design and safety management has increased considerably. The perpetual use of GIS tools, lead this study to propose the identification of accident hotspots by exploiting GIS technology coupled with kernel density estimation (KDE). This paper proposes the use of KDE technique and GIS technology to automatically identify the accident hotspots using UK as the study area. Analysis shows that most of the accidents occur when there is a 30 mph speed limit, a weekend, in the evening time, during the months of October and November, on the single carriageway, where there is ‘T’ or staggered junction and on ‘A’ road class. Moreover, this study also proposed techniques to classify the accident severity that is classified as either fatal, serious or slight. The driver behavior and environmental features achieved an accuracy up to 85% on the severity classification with Bagging technique. Further, the shortcomings, limitations and recommendations for future work are also identified. Syed Saqib Ali Kazmi, Mehreen Ahmed, Rafia Mumtaz, Zahid Anwar |
Comput. J. | 4 |
| 2022 | An analysis of zero-trust architecture and its cost-effectiveness for organizational security
Zillah Adahman, Asad Waqar Malik, Zahid Anwar |
Comput. Secur. | 3 |
| 2021 | CyberPulse++: A machine learning-based security framework for detecting link flooding attacks in software defined networksabstractA new class of link flooding attacks (LFA) can cut off internet connections of target links by employing legitimate flows to congest these without being detected. LFA is especially powerful in disrupting traffic in software-defined networks if the control channel is targeted. Most of the existing solutions work by conducting a deep packet-level inspection of the physical network links. Therefore these techniques incur a significant performance overhead, are reactive, and result in damage to the network before a delayed defense is mounted. Machine learning (ML) of captured network statistics is emerging as a promising, lightweight, and proactive solution to defend against LFA. In this paper, we propose a ML-based security framework, CyberPulse++, that utilizes a pretrained ML repository to test captured network statistics in real-time to detect abnormal path performance on network links. It effectively tackles several challenges faced by network security solutions such as the practicality of large-scale network-level monitoring and collection of network status information. The framework can use a wide variety of algorithms for training the ML repository and allows the analyst a birds-eye view by generating interactive graphs to investigate an attack in its ramp-up stage. An extensive evaluation demonstrates that the framework offers limited bandwidth and computational overhead in proactively detecting and defending against LFA in real-time. Raihan Ur Rasool, Khandakar Ahmed, Zahid Anwar, Hua Wang 0002, Usman Ashraf, Wajid Rafique |
Int. J. Intell. Syst. | 3 |
| 2020 | SCERM - A novel framework for automated management of cyber threat response activities
Zahid Anwar |
Future Gener. Comput. Syst. | 2 |
| 2020 | A survey of link flooding attacks in software defined network ecosystems
Raihan Ur Rasool, Hua Wang 0002, Usman Ashraf, Khandakar Ahmed, Zahid Anwar, Wajid Rafique |
J. Netw. Comput. Appl. | 5 |
| 2019 | A machine learning-based FinTech cyber threat attribution framework using high-level indicators of compromise
Umara Noor, Zahid Anwar, Tehmina Amjad, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 2 |
| 2019 | A machine learning framework for investigating data breaches based on semantic analysis of adversary's attack patterns in threat intelligence repositories
Umara Noor, Zahid Anwar, Asad Waqar Malik, Sharifullah Khan, Shahzad Saleem |
Future Gener. Comput. Syst. | 2 |
| 2018 | A thin client friendly trusted execution framework for infrastructure-as-a-service clouds
Imran Khan 0007, Habib-ur Rehman 0002, Mohammad Hussein Fayiz Al-khatib, Zahid Anwar, Masoom Alam |
Future Gener. Comput. Syst. | 4 |
| 2018 | A Protocol for Preventing Insider Attacks in Untrusted Infrastructure-as-a-Service CloudsabstractRecent technical advances in utility computing have allowed mall and medium sized businesses to move their applications to the cloud, to benefit from features such as auto-scaling and pay-as-you-go facilities. Before clouds are widely adopted, there is a need to address privacy concerns of customer data outsourced to these platforms. In this paper, we present a practical approach for protecting the confidentiality and integrity of client data and computation from insider attacks such as cloud clients as well as from the Infrastructure-as-a-Service (IaaS) based cloud system administrator himself. We demonstrate a scenario of how the origin integrity and authenticity of health-care multimedia content processed on the cloud can be verified using digital watermarking in an isolated environment without revealing the watermark details to the cloud administrator. Finally to verify that our protocol does not compromise confidentiality and integrity of the client data and computation or degrade performance, we have tested a prototype system using two different approaches. Formal verification using ProVerif tool shows that cryptographic operations and protocol communication cannot be compromised using a realistic attacker model. Performance analysis of our implementation demonstrates that it adds negligible overhead. Imran Khan 0007, Zahid Anwar, Behzad Bordbar, Eike Ritter, Habib-ur Rehman 0002 |
IEEE Trans. Cloud Comput. | 2 |
| 2017 | IoTChecker: A data-driven framework for security analytics of Internet of Things configurations
Mujahid Mohsin, Zahid Anwar, Farhat Zaman, Ehab Al-Shaer |
Comput. Secur. | 2 |
| 2017 | Data-driven analytics for cyber-threat intelligence and information sharing
Sara Qamar, Zahid Anwar, Mohammad Ashiqur Rahman, Ehab Al-Shaer, Bei-tseng Chu |
Comput. Secur. | 2 |
| 2017 | CloudNetSim++: A GUI Based Framework for Modeling and Simulation of Data Centers in OMNeT++abstractState-of-the-art cloud simulators in use today are limited in the number of features they provide, lack real network communication models, and do not provide extensive Graphical User Interface (GUI) to support developers and researchers to extend the behavior of the cloud environment. We propose CloudNetSim++, a comprehensive packet level simulator that enables simulation of cloud environments. CloudNetSim++ can be used to evaluate a wide spectrum of cloud components, such as processing elements, storage, networking, Service Level Agreement (SLA), scheduling algorithms, fine grained energy consumption, and VM consolidation algorithms. CloudNetSim++ offers extendibility, which means that the developers and researchers can easily incorporate own algorithms for scheduling, workload consolidation, VM migration, and SLA agreement. The simulation environment of CloudNetSim++ offers a rich GUI that provides a high level view of distributed data centers connected with various network topologies. The package also includes an energy computation module that provides a fine grained analysis of energy consumed by each component. This paper shows the flexibility and effectiveness of CloudNetSim++ through experimental results demonstrated using real-world data center workloads. Moreover, to demonstrate the correctness of CloudNetSim++, we performed formal modeling, analysis, and verification using High-level Petri Nets, Satisfiability Modulo Theories (SMT), and Z3 solver. Asad Waqar Malik, Kashif Bilal, Saif Ur Rehman Malik, Zahid Anwar, Khurram Aziz, Dzmitry Kliazovich, Nasir Ghani, Samee Ullah Khan, Rajkumar Buyya |
IEEE Trans. Serv. Comput. | 4 |
| 2016 | A deliberately insecure RDF-based Semantic Web application framework for teaching SPARQL/SPARUL injection attacks and defense mechanisms
Hira Asghar, Zahid Anwar, Khalid Latif 0001 |
Comput. Secur. | 2 |
| 2016 | Cloudlet deployment in local wireless networks: Motivation, architectures, applications, and open challenges
Usman Shaukat, Ejaz Ahmed 0003, Zahid Anwar, Feng Xia 0001 |
J. Netw. Comput. Appl. | 3 |
| 2016 | A fast and scalable technique for constructing multicast routing trees with optimized quality of service using a firefly based genetic algorithm
Usman Shaukat, Zahid Anwar |
Multim. Tools Appl. | 2 |
| 2015 | Guess who is listening in to the board meeting: on the use of mobile device applications as roving spy bugsabstractAbstract Covert listening devices—a combination of a miniature radio transmitter and a microphone—have been used as key espionage instruments as early as the mid‐20th century. More recently, hackers have started exploiting inherent weaknesses in current mobile platforms allowing them to remotely convert a victim's smartphone device into a roving spy bug without his knowledge. The goal of this paper is to illustrate with the aid of an Android mobile platform application that permissions gained in a legitimate way can be used to evade the integrity and privacy of the mobile device and install malware that remains completely hidden. When the attacker makes a call to the victim's phone, he is able to listen in to the victim's surroundings transforming the mobile phone into a sophisticated covert listening device. This communication‐level attack goes undetected by current detection mechanisms. An anomaly‐based detection feature set is another contribution of this paper to mitigate the proposed attack. As more and more mobile devices are being rapidly integrated into enterprises with the increase in bring‐your‐own‐device model in many organizations, without a rigorous security screening policy, this weakness tends to facilitate corporate espionage by presumably allowing as many spy bugs in the board meeting as there are attendees with mobiles. This work provides a demonstration of a dangerous espionage attack targeting smartphones whereby an attacker can, with the aid of an Android mobile platform application, make a call to the victim's phone and listen in to the victim's surroundings transforming the mobile phone into a sophisticated covert listening device. It also proposes and evaluates a defense technique to detect and mitigate the attack where existing security mechanisms fall short. Copyright © 2015 John Wiley & Sons, Ltd. Zahid Anwar, Waqas Ahmad Khan |
Secur. Commun. Networks | 1 |
| 2015 | A survey on reversible watermarking techniques for relational databasesabstractAbstract Over the past few years, reversible watermarking techniques for relational databases have been proposed to provide protection of ownership rights, data tempering, and data integrity. Mainly, these techniques ensure original data recovery from watermarked data, whereas irreversible watermarking schemes only protect ownership rights. This characteristic of reversible watermarking has emerged as a candidate solution for the protection of ownership rights of data, intolerable to modifications such as medical data, genetic data, credit card, and bank account data. The main objective of this paper is to make an extensive survey of the state‐of‐the‐art in reversible watermarking techniques for relational databases to reflect recent research progress and to point out the key issues for future research. In order to analyze these techniques, a classification has been performed on the basis of (i) the extent of modifications introduced by the watermarking scheme in the underlying data and (ii) the robustness of the embedded watermark against malicious attacks. Copyright © 2015 John Wiley & Sons, Ltd. Saman Iftikhar, Zahid Anwar |
Secur. Commun. Networks | 3 |
| 2015 | Storage schema and ontology-independent SPARQL to HiveQL translation
Naila Karim, Khalid Latif 0001, Zahid Anwar, Sharifullah Khan, Amir Hayat |
J. Supercomput. | 3 |
| 2015 | RRW - A Robust and Reversible Watermarking Technique for Relational DataabstractAdvancement in information technology is playing an increasing role in the use of information systems comprising relational databases. These databases are used effectively in collaborative environments for information extraction; consequently, they are vulnerable to security threats concerning ownership rights and data tampering. Watermarking is advocated to enforce ownership rights over shared relational data and for providing a means for tackling data tampering. When ownership rights are enforced using watermarking, the underlying data undergoes certain modifications; as a result of which, the data quality gets compromised. Reversible watermarking is employed to ensure data quality along-with data recovery. However, such techniques are usually not robust against malicious attacks and do not provide any mechanism to selectively watermark a particular attribute by taking into account its role in knowledge discovery. Therefore, reversible watermarking is required that ensures; (i) watermark encoding and decoding by accounting for the role of all the features in knowledge discovery; and, (ii) original data recovery in the presence of active malicious attacks. In this paper, a robust and semi-blind reversible watermarking (RRW) technique for numerical relational data has been proposed that addresses the above objectives. Experimental studies prove the effectiveness of RRW against malicious attacks and show that the proposed technique outperforms existing ones. Saman Iftikhar, Zahid Anwar |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2014 | Ontology for attack detection: An intelligent approach to web application security
Zahid Anwar, Hafiz Farooq Ahmad, Khalid Latif 0001, Rana Faisal Munir |
Comput. Secur. | 2 |
| 2014 | Semantic security against web application attacks
Khalid Latif 0001, Hafiz Farooq Ahmad, Ali Hur, Zahid Anwar, Peter Charles Bloodsworth |
Inf. Sci. | 5 |
| 2011 | Design and Deployment of a Trusted Eucalyptus CloudabstractShift from traditional software models to the Internet has been steadily gaining momentum over the last 10 years. Moving business applications to the shared utility infrastructure of the cloud with its pay-as-you-go and auto scaling features has become significantly more viable for small and medium sized businesses rather then setting up their own software and hardware infrastructure. However before clouds can reach their full potential and be wholeheartedly adopted there is a need to address the concern of privacy advocates who question the weakness of the model from being able to prevent the monitoring at will, lawfully or unlawfully of the user communication and data stored by the cloud hosting provider. Eucalyptus[?] is an open source cloud computing software framework that implements the Cloud Service Model commonly known as Infrastructure as a Service (IaaS). The IaaS model allows users to run and control entire virtual machines on cloud Infrastructure. However one of the main privacy issues in cloud Infrastructure such as Eucalyptus is to ensure the integrity and confidentiality of user data and computation. In this paper we describe the design and deployment of a Trusted Eucalyptus cloud architecture based on remote attestation via Trusted Platform Modules (TPM). Trusted Eucalyptus guarantees users that their virtual machines execute only on cloud nodes, whose integrity is valid. Our experimental results show that Trusted Eucalyptus cloud is practical in terms of performance. Imran Khan 0007, Habib-ur Rehman 0002, Zahid Anwar |
IEEE CLOUD | 3 |
| 2009 | An Integer Programming Model and Heuristic Algorithm for Automatic Scheduling in Synchrotron FacilitiesabstractThis paper studies the automatic scheduling problem at the Canadian national synchrotron facility, Canadian Light Source (CLS). An automatic scheduling tool needs to be developed to replace the current manual approach for scheduling experiments on a set of beamlines - resources that generate high-intensity X-rays for use in many kinds of scientific experiments. We present an, Integer programming model for this scheduling activity by formulating it as a problem of unrelated and paralleled machines with partially overlapping capabilities. Furthermore a heuristic based approach is used that can save computation time by pruning the search space. Using realistic data sets generated using parameters made available by CLS, we compare the performance of the base line approach that uses ILOG CPLEX implementation of the Integer programming algorithm with one that uses heuristics. The results show that the heuristic approach runs faster than the base-line, but at the cost of producing a less optimal scheduling solution. An obvious advantage of the study presented in this paper is that the automatic scheduling can handle more scheduling conditions and constraints than humans are able to handle manually and can reach optimal solutions. As far as we know, this is the first attempt to propose an automatic scheduling approach for synchrotron facilities like CLS around the world. Zahid Anwar, Dan Ni, Yaofeng Xu, Yuhong Yan |
SMC | 1 |
| 2008 | Automatic security assessment of critical cyber-infrastructuresabstractThis research investigates the automation of security assessment of the static and dynamic properties of cyber infrastructures, with emphasis on the electrical power grid. We describe a network model representing the static elements of a cyber infrastructure including devices, services, network connectivity, vulnerabilities, and access controls. The dynamic elements include workflow models of the operating procedures, processes and the state of a working power grid. We introduce a toolkit that with a little manual assistance can automatically generate these models from specifications, continuously update attributes from online event aggregators, and perform security assessment. The assessment reveals whether observed anomalies about the system could indicate possible security problems and permit dynamic ranking of alternative recovery procedures to minimize the total risk. We motivate the use of the tool-chain by showing an example scenario where the recovery procedure recommended to minimize security risk depends on the current state of system as well as the network topology. Zahid Anwar, Ravinder Shankesi, Roy H. Campbell |
DSN | 1 |
| 2006 | Multiple design patterns for voice over IP (VoIP) securityabstractDesign patterns capture software solutions to specific problems that have evolved over time and reflect many iterations of work. Documenting such patterns promotes proven design and software reuse. There has been a growing amount of work documenting design patterns for security, however, little work specific to VoIP security. In 2005 NIST released a report on recommendations and best practices for securing VoIP, however it lacks the structure, terminology, and ease-of-understanding needed for both technical and non-technical audiences that is an inherent feature of design patterns. In this paper, we document three design patterns for VoIP implementations related to specific security problems: (1) secure traversal of firewalls and NATs; (2) detecting and mitigating DDoS attacks; and (3) securing against eavesdropping. With many VoIP vendors rushing products to market with overlapping functionality and requirements for interoperability, documenting design patterns is poised to become an important part of secure programming processes for VoIP Zahid Anwar, William Yurcik, Ralph E. Johnson, Munawar Hafiz, Roy H. Campbell |
IPCCC | 1 |
| 2005 | A First Step Towards Call Survivability in Cellular NetworksabstractDespite recent advancements in cellular phone network infrastructure, survivability of the calls is still an open issue. Important business calls and tele-conferences cannot benefit from mobility because landlines are preferred owing to their reliability and tolerance to failures. In this paper, we present a framework to improve call survivability by monitoring the user's location and intimating him about the possibility of loss of connectivity, interference, and room schedules that might disrupt conversation. In addition, if a call drops because of unforeseeable circumstances like battery failure or cell-phone damage then the call is switched to the nearest available device capable of streaming voice Zahid Anwar, William Yurcik, Salman Baset, Henning Schulzrinne, Roy H. Campbell |
LCN | 1 |
| 2005 | Plethora: A Framework for Converting Generic Applications to Run in a Ubiquitous EnvironmentabstractApplications designed for ubiquitous computing environments need to be coded in a specific way in order to fully realize the benefits of ubiquitous computing. Currently, applications for ubiquitous computing environments either need to be rewritten entirely to benefit from ubiquity, or special wrappers need to be written and customized for particular applications to provide limited compatibility. We argue that the real-world deployment of ubiquitous computing will be realized when users can migrate and use the applications they are familiar with in their daily lives with minimal effort. Furthermore, these applications should automatically benefit from typical ubiquitous computing features including multi-device support, runtime adaptation, environment-independence and context-awareness. In this paper we present a framework that allows us to port any generic application to the domain of ubiquitous computing without having to rewrite the code from scratch. We have experimented with the framework in our prototype ubiquitous computing platform known as active spaces. This has allowed us to explosively increase the number of applications supported by our active space. Zahid Anwar, Jalal Al-Muhtadi, William Yurcik, Roy H. Campbell |
MobiQuitous | 1 |