VLDB 2026 Research / reviewers in the wild / expert
Bezawada Bruhadeshwar
dblp:64/1299 · also Bruhadeshwar Bezawada
· DBLP profile ↗
34ranked-venue papers
10as first author
7since 2021 · last 2026
0000-0002-1021-8121ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 6 first-author · 7 since 2021Computer networks · 10 · 1 first-authorSystems, architecture and hardware · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | "Room for More?": Behavior Adaptive IoT Device-type Fingerprinting
Maxwel Bar-on, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
DBSec | 2 |
| 2026 | Searchable encryption scheme for static Hamming distance range queries
Rui Li 0020, Xufei Mao, Zixing Lin, Bezawada Bruhadeshwar |
J. Inf. Secur. Appl. | 4 |
| 2025 | Jibber-Jabber!: Encoding the (Un-)Natural Language of Network Devices and Applications
Maxwel Bar-on, Kiley Krosky, Federico Larrieu, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
DBSec | 4 |
| 2025 | "Bring your own device!": Adaptive IoT Device-type Fingerprinting using Automatic Behavior Extraction [Work In Progress Paper]abstractInternet-of-Things (IoT) is playing a key role in modern society by offering enhanced functionalities and services. As IoT devices may introduce new security risks to the network, network administrators profile the behavior of IoT devices using device fingerprinting. Device fingerprinting typically involves training a machine learning model using the network behavioral data of existing devices. If a new device is added, the network becomes vulnerable to attacks until the time that the machine learning model is trained and updated to integrate the new device. Furthermore, if many devices are regularly added to the network, the cost of adapting the machine learning model can be significant. To address the challenges of security and scalability in fingerprinting, we create a collection of observed behaviors of IoT devices from existing devices and use this collection to construct a fingerprint for a new device. In our approach, we design a bi-component neural network architecture consisting of a transformer-based behavior-extractor (BE) and a fingerprinting interpreter.We perform a one-time training of the BE to extract behaviors from known devices. We use the generated BE for (a) fingerprinting existing devices and (b) adapting the existing fingerprinting model to new device data. In our experiments on 22 diverse IoT devices, we show that our model can identify newly introduced devices as well as known devices with a high identification rate. Our approach improves the time to adapt a model by a factor of 78.3× with no loss of accuracy, achieving recall over 98%. Maxwel Bar-on, Katherine Patterson, Bezawada Bruhadeshwar, Indrakshi Ray, Indrajit Ray |
SACMAT | 3 |
| 2021 | MapperDroid: Verifying app capabilities from description to permissions and API calls
Rajendra Kumar Solanki, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
Comput. Secur. | 3 |
| 2021 | Scaling & fuzzing: Personal image privacy from automated attacks in mobile cloud computing
Shweta Saharan, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
J. Inf. Secur. Appl. | 3 |
| 2021 | Directed adversarial sampling attacks on phishing detectionabstractPhishing websites trick honest users into believing that they interact with a legitimate website and capture sensitive information, such as user names, passwords, credit card numbers, and other personal information. Machine learning is a promising technique to distinguish between phishing and legitimate websites. However, machine learning approaches are susceptible to adversarial learning attacks where a phishing sample can bypass classifiers. Our experiments on publicly available datasets reveal that the phishing detection mechanisms are vulnerable to adversarial learning attacks. We investigate the robustness of machine learning-based phishing detection in the face of adversarial learning attacks. We propose a practical approach to simulate such attacks by generating adversarial samples through direct feature manipulation. To enhance the sample’s success probability, we describe a clustering approach that guides an attacker to select the best possible phishing samples that can bypass the classifier by appearing as legitimate samples. We define the notion of vulnerability level for each dataset that measures the number of features that can be manipulated and the cost for such manipulation. Further, we clustered phishing samples and showed that some clusters of samples are more likely to exhibit higher vulnerability levels than others. This helps an adversary identify the best candidates of phishing samples to generate adversarial samples at a lower cost. Our finding can be used to refine the dataset and develop better learning models to compensate for the weak samples in the training dataset. Hossein Shirazi, Bezawada Bruhadeshwar, Indrakshi Ray, Charles W. Anderson |
J. Comput. Secur. | 2 |
| 2020 | EspyDroid+: Precise reflection analysis of android apps
Jyoti Gajrani, Umang Agarwal, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur, Meenakshi Tripathi, Akka Zemmari |
Comput. Secur. | 4 |
| 2019 | AGBuilder: An AI Tool for Automated Attack Graph Building, Analysis, and Refinement
Bezawada Bruhadeshwar, Indrajit Ray, Kushagra Tiwary |
DBSec | 1 |
| 2019 | Adversarial Sampling Attacks Against Phishing Detection
Hossein Shirazi, Bezawada Bruhadeshwar, Indrakshi Ray, Charles W. Anderson |
DBSec | 2 |
| 2018 | Independent Key Distribution Protocols for Broadcast AuthenticationabstractBroadcast authentication is an important problem in several network settings such as wireless sensor networks and ad-hoc networks. We focus on the problem of independent key distribution protocols, which use efficient symmetric key signatures in distributed systems to permit (local) broadcast authentication. We focus on five types of communication graphs: (1) star, (2) acyclic, (3) planar, (4) complete bipartite, and (5) fully connected graphs. A star graph is the simplest network topology where a central node is transmitting authenticated broadcast messages to several satellite nodes. For star graphs, we show that as n, the number of satellite nodes in the star network, tends to infinity, it suffices to maintain logn+1/2loglogn + 1 keys at the center node, but logn+1/2loglogn keys do not suffice. We establish that this is the optimal lower bound on the number of keys for a star graph. Building on this result, we describe storage efficient key distribution for acyclic, planar, and complete bipartite graphs, when compared to existing key distribution schemes. We extend our scheme for fully connected graphs and show that it is sufficient to store O(c log2 N) keys per node where c<1. We perform a detailed analysis of collusion resistance of our protocols and show the trade-offs against internal and external attacks depending on the size of storage. Finally, we demonstrate the practical applicability of our protocols for wireless sensor networks. Bezawada Bruhadeshwar, Sandeep S. Kulkarni, Indrajit Ray, Indrakshi Ray, Rui Li 0020 |
SACMAT | 1 |
| 2018 | "Kn0w Thy Doma1n Name": Unbiased Phishing Detection Using Domain Name Based FeaturesabstractPhishing websites remain a persistent security threat. Thus far, machine learning approaches appear to have the best potential as defenses. But, there are two main concerns with existing machine learning approaches for phishing detection. The first is the large number of training features used and the lack of validating arguments for these feature choices. The second concern is the type of datasets used in the literature that are inadvertently biased with respect to the features based on the website URL or content. To address these concerns, we put forward the intuition that the domain name of phishing websites is the tell-tale sign of phishing and holds the key to successful phishing detection. Accordingly, we design features that model the relationships, visual as well as statistical, of the domain name to the key elements of a phishing website, which are used to snare the end-users. The main value of our feature design is that, to bypass detection, an attacker will find it very difficult to tamper with the visual content of the phishing website without arousing the suspicion of the end user. Our feature set ensures that there is minimal or no bias with respect to a dataset. Our learning model trains with only seven features and achieves a true positive rate of 98% and a classification accuracy of 97%, on sample dataset. Compared to the state-of-the-art work, our per data instance classification is 4 times faster for legitimate websites and 10 times faster for phishing websites. Importantly, we demonstrate the shortcomings of using features based on URLs as they are likely to be biased towards specific datasets. We show the robustness of our learning algorithm by testing on unknown live phishing URLs and achieve a high detection accuracy of $99.7%$. Hossein Shirazi, Bezawada Bruhadeshwar, Indrakshi Ray |
SACMAT | 2 |
| 2017 | Secure and efficient proof of ownership for deduplicated cloud storageabstractThe rapid increment in volume of outsourced data has raised an issue of data management for Cloud Storage Server. To solve this issue, Deduplication, a data compression technique was introduced which avoids duplicate data storage. However, Deduplication is vulnerable to malicious access to genuine Cloud Clients' files. An adversary can get access to file by learning small piece of knowledge about the file. In this paper, we propose secure and efficient Proof of Ownership for Deduplicated Cloud Storage. Our approach employs a technique of random matrix based challenges retrieved from the file. We evaluate security and efficiency of our approach by theoretical proofs and experimental results. Jay Dave, Parvez Faruki, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
SIN | 4 |
| 2017 | Privacy and Integrity Preserving Top-k Query Processing for Two-Tiered Sensor NetworksabstractPrivacy and integrity have been the main road block to the applications of two-tiered sensor networks. The storage nodes, which act as a middle tier between the sensors and the sink, could be compromised and allow attackers to learn sensitive data and manipulate query results. Prior schemes on secure query processing are weak, because they reveal non-negligible information, and therefore, attackers can statistically estimate the data values using domain knowledge and the history of query results. In this paper, we propose the first top-k query processing scheme that protects the privacy of sensor data and the integrity of query results. To preserve privacy, we build an index for each sensor collected data item using pseudo-random hash function and Bloom filters and transform top-k queries into top-range queries. To preserve integrity, we propose a data partition algorithm to partition each data item into an interval and attach the partition information with the data. The attached information ensures that the sink can verify the integrity of query results. We formally prove that our scheme is secure under IND-CKA security model. Our experimental results on real-life data show that our approach is accurate and practical for large network sizes. Rui Li 0020, Alex X. Liu, Sheng Xiao, Hongyue Xu, Bezawada Bruhadeshwar, Ann L. Wang |
IEEE/ACM Trans. Netw. | 5 |
| 2016 | A template approach to group key establishment in dynamic ad-hoc groupsabstractFast growing communication networks like wireless ad-hoc networks and Internet-of-things (IoT) put forth new challenges in secure communication like eavesdropping and tampering attacks. For such networks, we consider the following important problem: How to establish a shared secret group key among the nodes of a dynamically formed ad-hoc group? There are two major challenges: (a) The nodes are constrained and cannot support expensive public-key operations, especially for large groups and (b) the neighborhood of an ad-hoc node is not determined a-priori and therefore, the node needs to be able to establish a group key with any dynamic sub-set of the nodes. In this work, we describe a novel template based approach to group key establishment wherein our template is a logical shared secret distribution hierarchy built on the ad-hoc nodes prior to deployment. Our template approach ensures that any given ad-hoc node shares a distinct set of secrets with any dynamic group of nodes, regardless of the physical neighborhood, after deployment. We illustrate our approach using two instantiations of symmetric secret distribution protocols namely: sub-set and dual one-way hash chain distributions. Bezawada Bruhadeshwar, Xiaojiang Liang, Alex X. Liu, Rui Li 0020 |
ICNP | 1 |
| 2016 | Topological ordering based iterative TCAM rule compression using bi-partite graphsabstractFor fast packet classification, the de-facto industry standard is to use Ternary Content Addressable Memory (TCAM) chips where each chip stores one classifier rule and a given packet is checked against all such rules in parallel. In spite of the TCAM advantages, for a large number of rules, the TCAM deployment becomes expensive and the power consumption increases significantly. Therefore, it is desirable to reduce the number of TCAM rules while retaining the original classification semantics. In this work, we present efficient graph-based algorithms and data structures that allow us to capture the rule ordering relationships and iteratively compress the TCAM rules. Through extensive experiments, we show that our algorithm achieves 75% reduction of firewall rule sets on an average and even achieves an additional 24% compression on the output rule set of the state-of-the-art solutions. Rui Li 0020, Wenjie Li 0005, Bezawada Bruhadeshwar, Zheng Qin 0001 |
ICNP | 3 |
| 2016 | Fast and Scalable Range Query Processing With Strong Privacy Protection for Cloud ComputingabstractPrivacy has been the key road block to cloud computing as clouds may not be fully trusted. This paper is concerned with the problem of privacy-preserving range query processing on clouds. Prior schemes are weak in privacy protection as they cannot achieve index indistinguishability, and therefore allow the cloud to statistically estimate the values of data and queries using domain knowledge and history query results. In this paper, we propose the first range query processing scheme that achieves index indistinguishability under the indistinguishability against chosen keyword attack (IND-CKA). Our key idea is to organize indexing elements in a complete binary tree called PBtree, which satisfies structure indistinguishability (i.e., two sets of data items have the same PBtree structure if and only if the two sets have the same number of data items) and node indistinguishability (i.e., the values of PBtree nodes are completely random and have no statistical meaning). We prove that our scheme is secure under the widely adopted IND-CKA security model. We propose two algorithms, namely PBtree traversal width minimization and PBtree traversal depth minimization, to improve query processing efficiency. We prove that the worst-case complexity of our query processing algorithm using PBtree is O(|R|logn), where n is the total number of data items and R is the set of data items in the query result. We implemented and evaluated our scheme on a real-world dataset with 5 million items. For example, for a query whose results contain 10 data items, it takes only 0.17 ms. Rui Li 0020, Alex X. Liu, Ann L. Wang, Bezawada Bruhadeshwar |
IEEE/ACM Trans. Netw. | 4 |
| 2015 | Privacy Preserving String Matching for Cloud ComputingabstractCloud computing has become indispensable in providing highly reliable data services to users. But, there are major concerns about the privacy of the data stored on cloud servers. While encryption of data provides sufficient protection, it is challenging to support rich querying functionality, such as string matching, over the encrypted data. In this work, we present the first ever symmetric key based approach to support privacy preserving string matching in cloud computing. We describe an efficient and accurate indexing structure, the PASS tree, which can execute a string pattern query in logarithmic time complexity over a set of data items. The PASS tree provides strong privacy guarantees against attacks from a semi-honest adversary. We have comprehensively evaluated our scheme over large real-life data, such as Wikipedia and Enron documents, containing up to 100000 keywords, and show that our algorithms achieve pattern search in less than a few milliseconds with 100% accuracy. Furthermore, we also describe a relevance ranking algorithm to return the most relevant documents to the user based on the pattern query. Our ranking algorithm achieves 90%+ above precision in ranking the returned documents. Bezawada Bruhadeshwar, Alex X. Liu, Bargav Jayaraman, Ann L. Wang, Rui Li 0020 |
ICDCS | 1 |
| 2015 | Privacy-Preserving Quantification of Cross-Domain Network ReachabilityabstractNetwork reachability is an important characteristic for understanding end-to-end network behavior and helps in detecting violations of security policies across the network. While quantifying network reachability within one administrative domain is a difficult problem in itself, performing the same computation across a network spanning multiple administrative domains presents a novel challenge. The problem of quantifying network reachability across multiple administrative domains is more difficult because the privacy of security policies of individual domains is a serious concern and needs to be protected through this process. In this paper, we propose the first cross-domain privacy-preserving protocol for quantifying network reachability. Our protocol constructs equivalent representations of the Access Control List (ACL) rules and determines network reachability while preserving the privacy of the individual ACLs. This protocol can accurately determine the network reachability along a network path through different administrative domains. We have implemented and evaluated our protocol on both real and synthetic ACLs. The experimental results show that the online processing time of an ACL containing thousands of rules is less than 25 s. Given two ACLs, each containing thousands of rules, the comparison time is less than 6 s, and the total communication cost is less than 2100 kB. Fei Chen 0001, Bezawada Bruhadeshwar, Alex X. Liu |
IEEE/ACM Trans. Netw. | 2 |
| 2014 | Fast Range Query Processing with Strong Privacy Protection for Cloud ComputingabstractPrivacy has been the key road block to cloud computing as clouds may not be fully trusted. This paper concerns the problem of privacy preserving range query processing on clouds. Prior schemes are weak in privacy protection as they cannot achieve index indistinguishability, and therefore allow the cloud to statistically estimate the values of data and queries using domain knowledge and history query results. In this paper, we propose the first range query processing scheme that achieves index indistinguishability under the indistinguishability against chosen keyword attack (IND-CKA). Our key idea is to organize indexing elements in a complete binary tree called PBtree, which satisfies structure indistinguishability ( i.e. , two sets of data items have the same PBtree structure if and only if the two sets have the same number of data items) and node indistinguishability ( i.e. , the values of PBtree nodes are completely random and have no statistical meaning). We prove that our scheme is secure under the widely adopted IND-CKA security model. We propose two algorithms, namely PBtree traversal width minimization and PBtree traversal depth minimization, to improve query processing efficiency. We prove that the worse case complexity of our query processing algorithm using PBtree is O (| R | log n ), where n is the total number of data items and R is the set of data items in the query result. We implemented and evaluated our scheme on a real world data set with 5 million items. For example, for a query whose results contain ten data items, it takes only 0.17 milliseconds. Rui Li 0020, Alex X. Liu, Ann L. Wang, Bezawada Bruhadeshwar |
Proc. VLDB Endow. | 4 |
| 2013 | Cross-Domain Privacy-Preserving Cooperative Firewall OptimizationabstractFirewalls have been widely deployed on the Internet for securing private networks. A firewall checks each incoming or outgoing packet to decide whether to accept or discard the packet based on its policy. Optimizing firewall policies is crucial for improving network performance. Prior work on firewall optimization focuses on either intrafirewall or interfirewall optimization within one administrative domain where the privacy of firewall policies is not a concern. This paper explores interfirewall optimization across administrative domains for the first time. The key technical challenge is that firewall policies cannot be shared across domains because a firewall policy contains confidential information and even potential security holes, which can be exploited by attackers. In this paper, we propose the first cross-domain privacy-preserving cooperative firewall policy optimization protocol. Specifically, for any two adjacent firewalls belonging to two different administrative domains, our protocol can identify in each firewall the rules that can be removed because of the other firewall. The optimization process involves cooperative computation between the two firewalls without any party disclosing its policy to the other. We implemented our protocol and conducted extensive experiments. The results on real firewall policies show that our protocol can remove as many as 49% of the rules in a firewall, whereas the average is 19.4%. The communication cost is less than a few hundred kilobytes. Our protocol incurs no extra online packet processing overhead, and the offline processing time is less than a few hundred seconds. Fei Chen 0001, Bezawada Bruhadeshwar, Alex X. Liu |
IEEE/ACM Trans. Netw. | 2 |
| 2011 | Privacy-preserving cross-domain network reachability quantificationabstractNetwork reachability is one of the key factors for capturing end-to-end network behavior and detecting the violation of security policies. While quantifying network reachability within one administrative domain is already difficult, quantifying network reachability across multiple administrative domains is more difficult because the privacy of security policies becomes a serious concern and needs to be protected through this process. In this paper, we propose the first cross-domain privacy-preserving protocol for quantifying network reachability. Our protocol constructs equivalent representations of the Access Control List (ACL) rules and determines network reachability while preserving the privacy of the individual ACLs. This protocol can accurately determine the network reachability along a network path through different administrative domains. We have implemented and evaluated our protocol on both real and synthetic ACLs. The experimental results show that the online processing time of an ACL with thousands of rules is less than 25 seconds, the comparison time of two ACLs is less than 6 seconds, and the communication cost between two ACLs with thousands of rules is less than 2100 KB. Fei Chen 0001, Bezawada Bruhadeshwar, Alex X. Liu |
ICNP | 2 |
| 2011 | A cross-domain privacy-preserving protocol for cooperative firewall optimizationabstractFirewalls have been widely deployed on the Internet for securing private networks. A firewall checks each incoming or outgoing packet to decide whether to accept or discard the packet based on its policy. Optimizing firewall policies is crucial for improving network performance. Prior work on firewall optimization focuses on either intra-firewall or inter-firewall optimization within one administrative domain where the privacy of firewall policies is not a concern. This paper explores inter-firewall optimization across administrative domains for the first time. The key technical challenge is that firewall policies cannot be shared across domains because a firewall policy contains confidential information and even potential security holes, which can be exploited by attackers. In this paper, we propose the first cross-domain privacy-preserving cooperative firewall policy optimization protocol. Specifically, for any two adjacent firewalls belonging to two different administrative domains, our protocol can identify in each firewall the rules that can be removed because of the other firewall. The optimization process involves cooperative computation between the two firewalls without any party disclosing its policy to the other. We implemented our protocol and conducted extensive experiments. The results on real firewall policies show that our protocol can remove as many as 49% of the rules in a firewall whereas the average is 19.4%. The communication cost is less than a few hundred KBs. Our protocol incurs no extra online packet processing overhead and the offline processing time is less than a few hundred seconds. Fei Chen 0001, Bezawada Bruhadeshwar, Alex X. Liu |
INFOCOM | 2 |
| 2011 | Balancing Revocation and Storage Trade-Offs in Secure Group CommunicationabstractIn this paper, we focus on trade-offs between storage cost and rekeying cost for secure multicast. Membership in secure multicast groups is dynamic and requires multiple updates in a single time frame. We present a family of algorithms that provide a trade-off between the number of keys maintained by users and the time required for rekeying due to revocation of multiple users. We show that some well-known algorithms in the literature are members of this family. We show that algorithms in this family can be used to reduce the cost of rekeying by 43-79 percent when compared with previous solutions while keeping the number of keys manageable. We also describe a scheme to reduce the number of secrets further when revocations are periodic. Furthermore, we describe techniques to provide preferential treatment for long standing members of the group without affecting the performance of the algorithms. Using our techniques, as the group size increases, long standing members need to store smaller number of keys than short-lived members. This property is useful for adapting to the variable storage requirements of users in current day heterogeneous networks. Bezawada Bruhadeshwar, Sandeep S. Kulkarni |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | Symmetric Key Approaches to Securing BGP - A Little Bit Trust Is EnoughabstractThe Border Gateway Protocol (BGP) is the de facto interdomain routing protocol that connects autonomous systems (ASes). Despite its importance for the Internet infrastructure, BGP is vulnerable to a variety of attacks due to lack of security mechanisms in place. Many BGP security mechanisms have been proposed. However, none of them has been deployed because of either high cost or high complexity. The right trade-off between efficiency and security has been ever challenging. In this paper, we attempt to trade-off between efficiency and security by giving a little dose of trust to BGP routers. We present a new flexible threat model that assumes for any path of length h, at least one BGP router is trustworthy, where h is a parameter that can be tuned according to security requirements. Based on this threat model, we present two new symmetric key approaches to securing BGP: the centralized key distribution approach and the distributed key distribution approach. Comparing our approaches to the previous SBGP scheme, our centralized approach has a 98 percent improvement in signature verification. Our distributed approach has equivalent signature generation cost as in SBGP and an improvement of 98 percent in]signature verification. Comparing our approaches to the previous SPV scheme, our centralized approach has a 42 percent improvement in signature generation and a 96 percent improvement in signature verification. Our distributed approach has a 90 percent improvement on signature generation cost and a 95 percent improvement in signature verification cost. We also describe practical techniques for increasing the long-term security and collusion resistance of our key distribution protocols without increasing the signature generation and verification costs. By combining our approaches with previous public key approaches, it is possible to simultaneously provide an increased level of security and reduced computation cost. Bezawada Bruhadeshwar, Sandeep S. Kulkarni, Alex X. Liu |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2010 | A Fully Dynamic and Self-Stabilizing TDMA Scheme for Wireless Ad-hoc NetworksabstractOne important challenge in wireless ad hoc networks is to achieve collision free communication. Many MAC layer protocols have been proposed by considering various communication models of the ad hoc networks. One such protocol is TDMA, which provides for interference free communication while providing some bound on the packet delay. However, most proposed TDMA schemes can perform scheduling transmissions among nodes that are within transmission range. This is due to the simplistic modeling of the underlying network. Recently, more practical network models and overlay construction algorithms have been proposed that consider the interference among nodes as well. Existing TDMA protocols are unsuitable for such models as they will have to consider the interference range of the nodes as well. This requires that the TDMA protocol operate in a global perspective while working as a local-control algorithm. In this work, we describe a novel TDMA protocol that is suitable for such realistic and practical network models. We also extend the TDMA protocol to handle other difficulties such as membership changes within transmission range and interference range. Some networks also have to deal with sleeping nodes that wake up periodically. Our TDMA scheme employs a simple control phase and a data phase to handle such tasks. Some of the benefits of our solution are that no knowledge of the network parameters such as the size or an estimate of the size are used. The overhead of our scheme is also very low and (control) messages exchanged are of small size. Our solution will also be self-stabilizing which is an important property for distributed systems. To the best of our knowledge, our TDMA protocol is the first MAC layer protocol for such realistic network models. Additionally, we report some experimental results of our scheme. Bezawada Bruhadeshwar, Kishore Kothapalli, Indira Radhika Pulla |
AINA | 1 |
| 2010 | Key-update distribution in secure group communication
Sandeep S. Kulkarni, Bezawada Bruhadeshwar |
Comput. Commun. | 2 |
| 2009 | Reducing the Cost of Session Key EstablishmentabstractScenarios such as online banking, mobile payment systems, stock trading, selling merchandise, and a host of other applications that need a high level of security have moved from the research domain to real world. Moreover, the nature of clients has been changing from traditional desktops to mobile and handheld devices. Protocols like SSL, SSH are the present standard for establishing secure channels. However, the drawback in these protocols is that both the server and the client need to perform computationally expensive public-key operations for secure channel establishment. In this paper, we present simple constructions that spread the cost of secure channel establishment over several sessions. Our constructions are incrementally deployable and can operate with existing protocols such as SSL and SSH. Experimental results indicate that our constructions are practical and efficient in reducing the computational load at the server as well as the client side. Bezawada Bruhadeshwar, Kishore Kothapalli, Maddi Sree Deepya |
ARES | 1 |
| 2009 | Routing Protocol Security Using Symmetric Key Based TechniquesabstractIn this paper, we address the security of routing protocols. Internet routing protocols are subject to attacks in the control plane as well as the data plane. In the control plane, a routing protocol, e.g., BGP, OSPF, exchanges routing state updates and enables routers to compute the best paths towards various destinations. During this phase, an attacker can modify or inject malicious control messages leading to incorrect computation of routing paths. In the data plane, the routers forward the data along the paths computed in the control plane. Even if an attacker is not successful during the control phase, he can choose not to use the correct routing paths and forward data along routes that benefit him. Research shows that, attacks on the control plane can be mitigated by ensuring message integrity and, attacks on the data plane can be mitigated by ensuring route integrity. Earlier works have addressed these two problems independently with many interesting solutions. However, due to the nature of these solutions, network architects cannot deploy security at both planes without increasing the overhead on the network. In this paper, we focus on an integrated approach and propose the use of symmetric key protocols for addressing the security at both the control and data planes. We describe approaches that enable the reuse of the symmetric key protocols thereby eliminating the need for separate solutions at different planes. We used symmetric key protocols as they are efficient and scalable. Our experimental results show that our approaches are practical and can be incrementally deployed as well. Bezawada Bruhadeshwar, Kishore Kothapalli, M. Poornima, M. Divya |
ARES | 1 |
| 2008 | FormatShield: A Binary Rewriting Defense against Format String Attacks
Pankaj Kohli, Bezawada Bruhadeshwar |
ACISP | 2 |
| 2008 | Signature Generation and Detection of Malware Families
V. Sai Sathyanarayan, Pankaj Kohli, Bezawada Bruhadeshwar |
ACISP | 3 |
| 2008 | Symmetric Key Approaches to Securing BGP - A Little Bit Trust Is Enough
Bezawada Bruhadeshwar, Sandeep S. Kulkarni, Alex X. Liu |
ESORICS | 1 |
| 2005 | A Family of Collusion Resistant Protocols for Instantiating SecurityabstractIn this paper, we focus on the problem of identifying a family of collusion resistant protocols that demonstrate a tradeoff between the number of secrets that users maintain and the extent of collusion resistance. Towards this end, we define classes of collusion resistant protocols (modeled along the complexity classes in algorithmic complexity) and evaluate the membership of existing protocols as well as the protocols in the proposed family in these classes. We also show that this family contains existing protocols for instantiating security. Sandeep S. Kulkarni, Bezawada Bruhadeshwar |
ICNP | 2 |
| 2005 | Rekeying and Storage Cost for Multiple User Revocation
Sandeep S. Kulkarni, Bezawada Bruhadeshwar |
NDSS | 2 |