Md Sadek Ferdous

dblp:63/7409 · also Mohammad Sadek Ferdous · DBLP profile ↗
← Back
25ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0002-8361-4870ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 A Secure and Trustworthy Digital Passport System Using Self-Sovereign Identity and Blockchain
Sifat Jahan Sajin, Mohammad Mahmudul Haque Siam, Abdullah Al Anan, Sunjid Ibnul Anim, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous
COMPSAC7
2026 Evaluating FIDO2: Security and Cross-Platform Adoption on Various Mobile Devices
Puyuan Sun, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous
COMPSAC4
2026 CyQured: Design, Development, and Empirical Evaluation of a Tabletop Game for Personal Cybersecurity Education
Utsho Das, Argha Saha, Md Sadek Ferdous, Md Masum, Farida Chowdhury
SOUPS3
2026 A Passwordless Authentication Mechanism for the Web Using Self-Sovereign Identity
abstract
The traditional protected web services rely on a user authentication process. The combination of an identifier (e.g., username, email address and so on) and credential (e.g., password) still remains the most widely deployed user authentication process, even though such a process is one of the major sources of security breaches. Moreover, in this traditional setting, the management and sharing of user identity information is cumbersome. The consequence of this is that users increasingly find it difficult to manage their identity data scattered across multiple sites and they have limited controls over their own identity data. In recent times, Self-sovereign Identity (SSI) has emerged as a new mechanism for managing and exchanging identity information in a more user-centric and privacy-friendly way. There are many explorations of SSI in different application domains, however, its utility for passwordless authentication for the web mostly remains unexplored. In this article, we present SSI4Web , a framework which can facilitate a passwordless authentication mechanism for the web by employing a state-of-the-art SSI technology for providing web services with much more user control and greater flexibility. We present its architecture which is based on a threat model and requirement analysis, discuss its implementation details and sketch out its use-cases along with protocol flows. In addition, we analyse its performance, evaluate its security using ProVerif , a state-of-the-art protocol verifier and discuss its advantages and limitations.
Md Sadek Ferdous, Md Yeasin Ali, Fairuz Rahaman Chowdhury, Md Masum Alam Nahid, Andrei Ionita, Wolfgang Prinz
ACM Trans. Web1
2025 Decentralized Access Control using Hyperledger Fabric
abstract
Traditional access control systems often use the extensible access control markup language (XACML), a widely adopted standard for defining and enforcing access control policies. XACML is flexible and compatible with various access control models. It comprises key components such as the Policy Decision Point (PDP), Policy Enforcement Point (PEP), Policy Administration Point (PAP), and Policy Information Point (PIP), which are centrally managed in traditional setups. However, this central management introduces vulnerabilities like Single Point of Failure (SPOF) and other security risks. This research addresses these challenges by proposing a decentralized access control architecture built on Hyperledger Fabric. The design distributes the four core components of XACML— PEP, PDP, PAP, and PIP- across multiple blockchain nodes, eliminating SPOF while enhancing scalability and data integrity. A proof of concept (PoC) implementation is developed to evaluate the system’s performance. The architecture and PoC are analyzed against predefined threats and requirements, demonstrating how the system delivers a secure, scalable, and resilient access control solution.
Jubayer Hossain, Mehedi Hasan Nabil, Farhan Labib Jahin, Md Yeasin Ali, Hossain Shahriar, Md Sadek Ferdous
COMPSAC6
2025 AuthVR: Securing Authentication Against Shoulder Surfing and Keystroke Inference Attacks using Virtual Reality
abstract
Passwords serve as the primary authentication mechanism for knowledge-based systems, facilitating user access across a diverse spectrum of applications. Although password-based authentication is commonly employed in high-security environments such as security checkpoints and central control and command systems, it remains susceptible to fraudulent activities, e.g. shoulder-surfing and inference attacks (via direct observation, eavesdropping, or recording) particularly in public or monitored spaces equipped with CCTV cameras. In this paper, we present AuthVR, a Virtual Reality (VR) enabled authentication mechanism creating an additional layer of security in such high-security environments, significantly enhancing existing systems' security. Using Design Science Research Methodology, we assess potential threats and establish the system requirements. We present the architecture, its detailed protocol flow, validate its security through a formal analysis using ProVerif and provide a thorough analysis of the proposal's probable resistance against a number of attack vectors. Additionally, a user study is conducted to evaluate the usability and practical aspects of the system showing a positive impression towards the system.
Md Yeasin Ali, Touhid Islam Udoy, Md. Ishmam Tasin, Md Masum Alam Nahid, Fairuz Rahaman Chowdhury, Farida Chowdhury, Md Sadek Ferdous
TrustCom7
2025 A Survey of Attacks on Blockchain Systems Using a Layer-based Approach
abstract
Blockchain technology is very popular nowadays as it ensures decentralization, transparency, and immutability. However, despite its inherent security features, blockchain-based systems have been frequently targeted by adversaries, raising concerns about their trustworthiness. This paper presents a comprehensive study of 24 major attacks against blockchain systems, categorized in a structured, layer-based approach. The study systematically examines the feasibility, underlying incentives, and underlying vulnerabilities exploited in these attacks. We categorize attacks across four blockchain layers, namely the Network, Consensus, Application, and Meta-Application layers, illustrating the diverse nature of security threats. Furthermore, we propose a systematic analysis that enables an in-depth evaluation of attacks, their interconnections, and cascading effects across different layers. This research intends to contribute to the development of robust security strategies that can mitigate vulnerabilities and increase confidence in decentralized systems by providing a structured technique for analyzing blockchain security concerns. Ultimately, this research underscores the critical need for continuous advancements in blockchain security mechanisms to ensure the resilience of blockchain based systems against emerging and evolving threats.
Joydip Das, Syed Ashraf Al Tasin, Md Forhad Rabbi, Md Sadek Ferdous
Comput. Networks4
2024 Secure Backup and Recovery of SSI Wallets using Solid Pod Technology
abstract
A new paradigm for digital identity management called Self-Sovereign Identity (SSI) has emerged to offer users more control over their identity data. An important component of SSI is a wallet that stores cryptographic keys and other identity data. Secure backup and recovery methods for data stored in such wallets are a crucial feature for its wide-scale adoption, however, such a feature is lacking or implemented casually in the existing SSI wallets. In this research, we propose a secure backup and storage of SSI wallets using a novel technology called Solid Pod. Solid Pod is an emerging technology that enables users to securely store data online. Towards this aim, we present the architecture, based on a threat model and requirement analysis, of the proposed approach. We also discuss its implementation details, outline a number of protocol flows highlighting different use-cases and analyse its security, advantages and limitations.
Mohammad Farhad, Gourab Saha, Md Masum Alam Nahid, Fairuz Rahaman Chowdhury, Partha Protim Paul, Mohammed Raihan Ullah, Md Sadek Ferdous
COMPSAC7
2024 Evaluating the security of CAPTCHAs utilized on Bangladeshi websites
Md. Neyamul Islam Shibbir, Hasibur Rahman, Md Sadek Ferdous, Farida Chowdhury
Comput. Secur.3
2023 BlockMeter: An Application Agnostic Performance Measurement Framework for Private Blockchain Platforms
abstract
Blockchain Technology is an emerging technology with the potential to disrupt a number of application domains. Though blockchain platforms like Bitcoin and Ethereum have seen immense success and acceptability, their nature of being public and anonymous makes them unsuitable for many enterprise-level use-cases. To address this issue, Linux Foundation has started an open-source umbrella initiative, known as theHyperledger Platforms. Under this initiative, a number of private blockchain platforms have been developed. However, the scalability and performance of these private blockchains must be examined to understand their suitability for different use cases. Recent researches and projects on performance benchmarking for private blockchain systems are specific to use cases and generally tied to a blockchain platform. In this article, we presentBlockMeter, an application-agnostic performance benchmarking framework for private blockchain platforms. BlockMeter can be utilised to measure the key performance metrics of any application deployed on top of an external private blockchain application in real-time. In this article, we present the architecture of the framework and discuss its different implementation aspects. Then, to showcase the applicability of the framework, we use BlockMeter to evaluate the two most widely used Hyperledger platforms, Hyperledger Fabric and Hyperledger Sawtooth, against a number of use-cases.
Ifteher Alom, Md Sadek Ferdous, Mohammad Jabed Morshed Chowdhury
IEEE Trans. Serv. Comput.2
2022 Blockchain-based COVID vaccination registration and monitoring
abstract
COVID-19 has changed almost all aspects of our lives. Governments around the world have imposed lockdowns to slow down the transmissions. Fortunately, we have found the vaccine, in fact, a good number of them. However, managing the testing and vaccination process of the total population is a mammoth job. However, there are always delays or data silo problems in multi-organizational work. Therefore, streamlining this process is vital to improve efficiency and save more lives. Because of its effective data sharing mechanism among different entities with a number of security features, blockchain can be an effective tool for different applications in the health sector. Furthermore, blockchain provides a distributed system along with greater privacy, transparency, and authenticity. In this article, we have presented a blockchain-based system that seamlessly integrates testing and vaccination systems, allowing the system to be transparent. The instant verification of any tamper-proof COVID-19 test result has been developed, which will serve as “Test Certificates”. A transparent and efficient vaccination system has also been exhibited and implemented as the “Digital Vaccine Passport” (DVP) system. The infection rate-based prioritization will ensure a transparent and fair vaccination process as well as tackle the distribution issue of the limited amount of vaccine. The comparative review with other existing works is also discussed, highlighting a clear difference from the existing works. Our proposed system is distinctive on the basis of prioritization of vaccines and seamless integration of test certificates and vaccine passports, which will aid in controlling the pandemic situation. This system will also be handy in the case of tackling any future pandemics initially.
Shirajus Salekin Nabil, Md. Sabbir Alam Pran, Ali Abrar Al Haque, Narayan Ranjan Chakraborty, Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous
Blockchain Res. Appl.6
2022 A Cross-Layer Trust-Based Consensus Protocol for Peer-to-Peer Energy Trading Using Fuzzy Logic
abstract
Peer-to-Peer (P2P) energy trading platforms are being actively designed, tested, and operated by engineers, power distribution companies, and prosumers. The assurance of the accountability of the conduct of different stakeholders through a robust trust management mechanism is imperative in such platforms. The usage of blockchain, as an underlying technology, can ensure numerous properties, such as immutability, transparency, and traceable execution of transactions, in addition to ensuring trust establishment among different entities of the system. Few blockchain-based decentralized energy trading platforms have been designed in the literature to build trust about the platform and among prosumers. However, none of these proposals have considered human-in-the-loop in the trust establishment process. Moreover, these solutions have considered trust only at a particular layer of the blockchain, such as at the application or consensus layer. To bridge this gap, this article presents a novel cross-layer trust-based consensus protocol that considers human-in-the-loop and employs fuzzy logic to address the issue of vagueness of trust values by offering human interpretable trust level. The experimental results demonstrate the efficiency and effectiveness of our proposed protocol in comparison to established consensus mechanisms. The analysis also shows the protocol is immune against selfish mining, 51% and Sybil attacks.
Mohammad Jabed Morshed Chowdhury, Muhammad Usman 0001, Md Sadek Ferdous, Niaz Chowdhury, Anam Ibna Harun, Umme Sumaya Jannat, Kamanashis Biswas
IEEE Internet Things J.3
2021 A survey of consensus algorithms in public blockchain systems for crypto-currencies
Md Sadek Ferdous, Mohammad Jabed Morshed Chowdhury, Mohammad Ashraful Hoque
J. Netw. Comput. Appl.1
2020 BONIK: A Blockchain Empowered Chatbot for Financial Transactions
abstract
A Chatbot is a popular platform to enable users to interact with a software or website to gather information or execute actions in an automated fashion. In recent years, chatbots are being used for executing financial transactions, however, there are a number of security issues, such as secure authentication, data integrity, system availability and transparency, that must be carefully handled for their wide-scale adoption. Recently, the blockchain technology, with a number of security advantages, has emerged as one of the foundational technologies with the potential to disrupt a number of application domains, particularly in the financial sector. In this paper, we forward the idea of integrating a chatbot with blockchain technology in the view to improve the security issues in financial chatbots. More specifically, we present BONIK, a blockchain empowered chatbot for financial transactions, and discuss its architecture and design choices. Furthermore, we explore the developed Proof-of-Concept (PoC), evaluate its performance, analyse how different security and privacy issues are mitigated using BONIK.
Md. Saiful Islam Bhuiyan, Abdur Razzak, Md Sadek Ferdous, Mohammad Jabed Morshed Chowdhury, Mohammad Ashraful Hoque, Sasu Tarkoma
TrustCom3
2020 Modelling Attacks in Blockchain Systems using Petri Nets
abstract
Blockchain technology has evolved through many changes and modifications, such as smart-contracts since its inception in 2008. The popularity of a blockchain system is due to the fact that it offers a significant security advantage over other traditional systems. However, there have been many attacks in various blockchain systems, exploiting different vulnerabilities and bugs, which caused a significant financial loss. Therefore, it is essential to understand how these attacks in blockchain occur, which vulnerabilities they exploit, and what threats they expose. Another concerning issue in this domain is the recent advancement in the quantum computing field, which imposes a significant threat to the security aspects of many existing secure systems, including blockchain, as they would invalidate many widely-used cryptographic algorithms. Thus, it is important to examine how quantum computing will affect these or other new attacks in the future. In this paper, we explore different vulnerabilities in current blockchain systems and analyse the threats that various theoretical and practical attacks in the blockchain expose. We then model those attacks using Petri nets concerning current systems and future quantum computers.
Md. Atik Shahriar, Faisal Haque Bappy, A. K. M. Fakhrul Hossain, Dayamoy Datta Saikat, Md Sadek Ferdous, Mohammad Jabed Morshed Chowdhury, Md. Zakirul Alam Bhuiyan
TrustCom5
2019 Trust Modeling for Blockchain-Based Wearable Data Market
abstract
Wearable devices continuously produce physiological data that can provide individuals critical information about their daily routine or fitness level in combination with their smartphones without requiring manual calculations or maintaining log-books. Real-time participant-generated data can enable large scale observational studies of health conditions, provide better insights into medical conditions of individuals and streamline clinical trial processes in medical research. However, privacy is a major concern for health data and there can be a lack of trust among different parties in the health data collection process. In addition, individuals often do not have sufficient control over the sharing of their data from the wearable devices. The lack of control, trust and privacy are key barriers to research participants being prepared to share their personal data from wearable devices. In this work, we propose a trust model to overcome the trust deficit among different parties. Then, we present a reference system architecture, rooted on the developed trust model, that provides incentive for individuals to securely share their health data through a data marketplace. By encouraging individuals to share their real-time health data, researchers will have access to large data sets at low cost.
Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous, Kamanashis Biswas, Niaz Chowdhury, A. S. M. Kayes, Paul A. Watters, Alex Ng
CloudCom2
2017 A Distributed Infrastructure for Democratic Cloud Federations
abstract
Cloud federation is a novel concept that has been drawing attention from research and industry. However, there is a lack of solid proposal that can be widely adopted in practice to guarantee adequate governance of federations, especially in the Public Sector contexts due to legal requirements. In this paper, we propose an innovative governance approach that ensures distributed and democratic control in cloud federations. Starting from FaaS, a recent cloud federation proposal, we propose a blockchain infrastructure for the federation registry that implements the proposed governance approach.
Andrea Margheri, Md Sadek Ferdous, Mu Yang, Vladimiro Sassone
CLOUD2
2017 Decentralised Runtime Monitoring for Access Control Systems in Cloud Federations
abstract
Cloud federation is an emergent cloud-computing paradigm where partner organisations share data and services hosted on their own cloud platforms. In this context, it is crucial to enforce access control policies that satisfy data protection and privacy requirements of partner organisations. However, due to the distributed nature of cloud federations, the access control system alone does not guarantee that its deployed components cannot be circumvented while processing access requests. In order to promote accountability and reliability of a distributed access control system, we present a decentralised runtime monitoring architecture based on blockchain technology.
Md Sadek Ferdous, Andrea Margheri, Federica Paci, Mu Yang, Vladimiro Sassone
ICDCS1
2017 Analysing privacy in visual lifelogging
abstract
The visual lifelogging activity enables a user, the lifelogger, to passively capture images from a first-person perspective and ultimately create a visual diary encoding every possible aspect of her life with unprecedented details. In recent years, it has gained popularities among different groups of users. However, the possibility of ubiquitous presence of lifelogging devices specifically in private spheres has raised serious concerns with respect to personal privacy. In this article, we have presented a thorough discussion of privacy with respect to visual lifelogging. We have re-adjusted the existing definition of lifelogging to reflect different aspects of privacy and introduced a first-ever privacy threat model identifying several threats with respect to visual lifelogging. We have also shown how the existing privacy guidelines and approaches are inadequate to mitigate the identified threats. Finally, we have outlined a set of requirements and guidelines that can be used to mitigate the identified threats while designing and developing a privacy-preserving framework for visual lifelogging.
Md Sadek Ferdous, Soumyadeb Chowdhury, Joemon M. Jose
Pervasive Mob. Comput.1
2016 Formalising Identity Management protocols
abstract
In this paper we present the formalisation of three well-known Identity Management protocols - SAML, OpenID and OAuth. The formalisation consists of two steps: formal specification using HLPSL (High-Level Protocol Specification Language) and formal verification using a state-of-the-art verification tool for security protocols called AVISPA (Automated Validation of Internet Security Protocols and Applications). The existing formalisation initiatives using AVISPA are based on SAML and OpenID, leaving OAuth entirely, even though OAuth is one of the most widely-used Internet protocols. Furthermore, the motivation of the existing initiatives was to identify any weakness. In this paper, we have taken an opposite approach as we are keen to present how to model these protocols correctly. Moreover, our formalisation is based on a model of identity and also captures the authentication mechanism; both of these are missing in the existing works.
Md Sadek Ferdous, Ron Poet
PST1
2015 "My Day in Review": Visually Summarising Noisy Lifelog Data
abstract
Lifelogging devices, which seamlessly gather various data about a user as they go about their daily life, have resulted in users amassing large collections of noisy photographs (e.g. visual duplicates, image blur), which are difficult to navigate, especially if they want to review their day in photographs. Social media websites, such as Facebook, have faced a similar information overload problem for which a number of summarization methods have been proposed (e.g. news story clustering, comment ranking etc.). In particular, Facebook's Year in Review received much user interest where the objective for the model was to identify key moments in a user's year, offering an automatic visual summary based on their uploaded content. In this paper, we follow this notion by automatically creating a review of a user's day using lifelogging images. Specifically, we address the quality issues faced by the photographs taken on lifelogging devices and attempt to create visual summaries by promoting visual and temporal-spatial diversity in the top ranks. Conducting two crowdsourced evaluations based on 9k images, we show the merits of combining time, location and visual appearance for summarization purposes.
Soumyadeb Chowdhury, Philip J. McParlane, Md Sadek Ferdous, Joemon M. Jose
ICMR3
2014 Mathematical Modelling of Identity, Identity Management and Other Related Topics
abstract
There exist disparate sets of definitions with different semantics on different topics of Identity Management which often lead to misunderstanding. A few efforts can be found compiling several related vocabularies into a single place to build up a set of definitions based on a common semantic. However, these efforts are not comprehensive and are only textual in nature. In essence, a mathematical model of identity and identity management covering all its aspects is still missing. In this paper we build up a mathematical model of different core topics covering a wide range of vocabularies related to Identity Management. At first we build up a mathematical model of Digital Identity. Then we use the model to analyse different aspects of Identity Management. Finally, we discuss three applications to illustrate the applicability of our approach. Being based on mathematical foundations, the approach can be used to build up a solid understanding on different topics of Identity Management.
Md Sadek Ferdous, Gethin Norman, Ron Poet
SIN1
2014 CAFS: A Framework for Context-Aware Federated Services
abstract
In this paper we explore two issues: Federated Identity Management and Context-Aware Services. In the last decade or so we have seen these two technologies gaining considerable popularities as they offer a number of benefits to the user and other stakeholders. However, there are a few outstanding security and privacy issues that need to be resolved to harness the full potential of such services. We believe that these problems can be reduced significantly by integrating the federated identity architecture into the context-aware services. With this aim, we have developed a framework for Context-Aware Federated Services based on the Security Assertion Markup Language (SAML) and extensible Access Control Markup Language (XACML) standards. We have illustrated the applicability of our approach by showcasing some use-cases, analysed the security, privacy and trust issues involved in the framework and the advantages it offers.
Md Sadek Ferdous, Ron Poet
TrustCom1
2013 Analysing attribute aggregation models in federated identity management
abstract
This paper presents a comparative analysis of different attribute aggregation models against a set of requirements in the settings of the Federated Identity Management (FIM). There are several attribute aggregation models currently available which allow the user to collate attributes from multiple identity providers (IdP in short) in a single service. These models impose different novel requirements which have never been analysed before and there lacks a thorough analysis of these models that will compare them side-by-side against a set of requirements. We aim to fill in these gaps in this work. We have formulated a set of trust, functional, security and privacy requirements that are needed for each model and shown the interlink between these requirements. These requirements have been used to compare the models side-by-side in tabular forms which would allow the readers to instantly identify the requirements for each model, the advantages it offers and the weaknesses it has.
Md Sadek Ferdous, Ron Poet
SIN1
2009 Spam filter optimality based on signal detection theory
abstract
Unsolicited bulk email, commonly known as spam, represents a significant problem on the Internet. The seriousness of the situation is reflected by the fact that approximately 97% of the total e-mail traffic currently (2009) is spam. To fight this problem, various anti-spam methods have been proposed and are implemented to filter out spam before it gets delivered to recipients, but none of these methods are entirely satisfactory. In this paper we analyze the properties of spam filters from the viewpoint of Signal Detection Theory (SDT). The Bayesian approach of Signal Detection Theory provides a basis for determining the optimality of spam filters, i.e. whether they provide positive utility to users. In the process of decision making by a spam filter various tradeoff's are considered as a function of the costs of incorrect decisions and the benefits of correct decisions.
Audun Jøsang, Md Sadek Ferdous, Ravishankar Borgaonkar
SIN3