VLDB 2026 Research / reviewers in the wild / expert
Udaya Kiran Tupakula
dblp:76/2607 · also Uday Kiran Tupakula
· DBLP profile ↗
55ranked-venue papers
20as first author
12since 2021 · last 2025
0000-0001-5048-9797ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 3 first-author · 3 since 2021Security and privacy · 10 · 5 first-author · 2 since 2021Systems, architecture and hardware · 8 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 6 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Achieving Robustness and Dropout Fairness with Hierarchical Federated Learning in Smart Grid InfrastructuresabstractWith the recent rapid expansion of the smart grid infrastructure paving the way for greater integration of computer and network technologies within the power grid, it has become well suited for the application of machine learning techniques. However, machine learning requires vast amounts of data, which within the smart grid setting can reveal great amounts of personal details of the individuals using the grid. This work considers the application of a variant of distributed machine learning, federated learning, which enhances data privacy. We propose a Smart Grid Hierarchical Federated Learning (SGHFL) framework, which is tuned to common smart grid architectures in the real world. We demonstrate how our SGHFL framework improves client dropout and poisoning robustness, using relatively lightweight models suitable for devices with limited computational capability. We provide theoretical justification underlying our design and have evaluated our algorithms and framework with three datasets/environments of progressively increasing practicality. We have also compared our framework with relevant works. Cody Lewis, Vijay Varadharajan, Nasimul Noman, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2024 | Mitigation of Gradient Inversion Attacks in Federated Learning with Private Adaptive Optimization
Cody Lewis, Vijay Varadharajan, Nasimul Noman, Udaya Kiran Tupakula, Nan Li 0007 |
ICDCS | 4 |
| 2024 | The WMDP Benchmark: Measuring and Reducing Malicious Use with UnlearningabstractThe White House Executive Order on Artificial Intelligence highlights the risks of large language models (LLMs) empowering malicious actors in developing biological, cyber, and chemical weapons. To measure these risks, government institutions and major AI labs are developing evaluations for hazardous capabilities in LLMs. However, current evaluations are private and restricted to a narrow range of malicious use scenarios, which limits further research into reducing malicious use. To fill these gaps, we release the Weapons of Mass Destruction Proxy (WMDP) benchmark, a dataset of 3,668 multiple-choice questions that serve as a proxy measurement of hazardous knowledge in biosecurity, cybersecurity, and chemical security. To guide progress on unlearning, we develop RMU, a state-of-the-art unlearning method based on controlling model representations. RMU reduces model performance on WMDP while maintaining general capabilities in areas such as biology and computer science, suggesting that unlearning may be a concrete path towards reducing malicious use from LLMs. We release our benchmark and code publicly at https://wmdp.ai. Nathaniel Li, Alexander Pan, Anjali Gopal, Summer Yue, Daniel Berrios, Alice Gatti, Justin D. Li, Ann-Kathrin Dombrowski, Shashwat Goel, Gabriel Mukobi, Nathan Helm-Burger, Rassin Lababidi, Lennart Justen, Andrew B. Liu, Isabelle Barrass, Oliver Zhang, Xiaoyuan Zhu, Rishub Tamirisa, Bhrugu Bharathi, Ariel Herbert-Voss, Cort B. Breuer, Andy Zou, Mantas Mazeika, Zifan Wang 0001, Palash Oswal, Weiran Lin, Adam A. Hunt, Justin Tienken-Harder, Kevin Y. Shih, Kemper Talley, John Guan, Ian Steneker, David Campbell, Brad Jokubaitis, Steven Basart, Stephen Fitz, Ponnurangam Kumaraguru, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Vijay Varadharajan, Yan Shoshitaishvili, Jimmy Ba, Kevin M. Esvelt, Alexandr Wang, Dan Hendrycks |
ICML | 40 |
| 2024 | Anti-phishing: A comprehensive perspective
Gaurav Varshney, Rahul Kumawat, Vijay Varadharajan, Udaya Kiran Tupakula, Chandranshu Gupta |
Expert Syst. Appl. | 4 |
| 2024 | Techniques for Enhancing Security in Industrial Control SystemsabstractIncreasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of Information Technology (IT) systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation’s security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS by achieving real time situational awareness and dynamic policy-driven decision making across the network infrastructure. In particular, CSSA can be used for establishing secure path for end-to-end communication between devices and also deal against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. We also discuss how CSSA provides reliable paths for safety critical messages in control systems. We discuss the prototype implementation of the proposed architecture and the results obtained from our analysis. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2024 | Ensuring Fairness and Gradient Privacy in Personalized Heterogeneous Federated LearningabstractWith the increasing tension between conflicting requirements of the availability of large amounts of data for effective machine learning-based analysis, and for ensuring their privacy, the paradigm of federated learning has emerged, a distributed machine learning setting where the clients provide only the machine learning model updates to the server rather than the actual data for decision making. However, the distributed nature of federated learning raises specific challenges related to fairness in a heterogeneous setting. This motivates the focus of our article, on the heterogeneity of client devices having different computational capabilities and their impact on fairness in federated learning. Furthermore, our aim is to achieve fairness in heterogeneity while ensuring privacy. As far as we are aware there are no existing works that address all three aspects of fairness, device heterogeneity, and privacy simultaneously in federated learning. In this article, we propose a novel federated learning algorithm with personalization in the context of heterogeneous devices while maintaining compatibility with the gradient privacy preservation techniques of secure aggregation. We analyze the proposed federated learning algorithm under different environments with different datasets and show that it achieves performance close to or greater than the state-of-the-art in heterogeneous device personalized federated learning. We also provide theoretical proofs for the fairness and convergence properties of our proposed algorithm. Cody Lewis, Vijay Varadharajan, Nasimul Noman, Udaya Kiran Tupakula |
ACM Trans. Intell. Syst. Technol. | 4 |
| 2023 | A trust-aware openflow switching framework for software defined networks (SDN)abstractSoftware Defined Networks (SDN) and Network Function Virtualisation (NFV) are prime driving technologies behind 5G and Beyond 5G (B5G) communications. The network control intelligence segregation in the SDN infrastructure enables dynamic network features (such as dynamic end-to-end management of security and quality of service (QoS)) offering significantly improved network performance. Even if one assumes that the centralised SDN controller can be security hardened and hence can be trusted, a fundamental challenge in such networks is that the data plane and switching devices are susceptible to cyberattacks. A malicious adversary can compromise them during run-time making them unreliable for secure and trusted communications. Furthermore, the controller communicating with OpenFlow switching devices is unable to accurately assess the state of the switching devices, which serves as the communication base for NFVs in 5G networks. Vulnerable switching devices can put the whole 5G network infrastructure at risk. Hence, there is a clear need for the controller and the management layer to determine the trustworthiness of the switching devices at run-time. The current trend is for many such devices to deploy trusted computing functionality such as Trusted Platform Module (TPM) or Software Guard Extension (SGx) to achieve local as well as remote attestation. In this paper, we present a dynamic trust management framework for evaluating the trustworthiness of the OpenFlow switching devices deployed in the SDN based networks. We formulate device properties that need to be assessed to determine the trust status of the device. We develop a trust enhanced security architecture which can be used to evaluate the trustworthiness of devices and determine their deployment in the provision of network services. The proposed framework uses subjective logic based techniques to derive trust levels of the switching devices at run-time, which are then used by the architecture to make trust enhanced decisions on the provision of network services. A prototype implementation of the proposed architecture is described, which demonstrates how the trustworthiness of the OpenFlow devices are assessed at run-time. The paper concludes with the performance and security analysis of the implemented trust enhanced architecture services. Kallol Krishna Karmakar, Vijay Varadharajan, Michael Hitchens, Udaya Kiran Tupakula, Prajna Sariputra |
Comput. Networks | 4 |
| 2022 | Toward a Trust Aware Network Slice-Based Service Provision in Virtualized InfrastructuresabstractFuture communication networks such as 5G are expected to support end-to-end delivery of services for several vertical markets with diverging requirements. Network slicing is a key construct that is used to provide end to end logical virtual networks running on a common virtualised infrastructure, which are mutually isolated. Having different network slices operating over the same 5G infrastructure creates several challenges in security and trust. This paper addresses the fundamental issue of trust of a network slice. It presents a trust model and property-based trust attestation mechanisms, which can be used to evaluate the trust of the virtual network functions that compose the network slice. The proposed model helps to determine the trust of the virtual network functions, as well as the properties that should be satisfied by the virtual platforms (both at boot and run time), on which these network functions are deployed for them to be trusted. We present a logic-based language that defines simple rules for the specification of properties and the conditions under which these properties need to be satisfied for trusted virtualized platforms. The proposed trust model and mechanisms enable the service providers to determine the trustworthiness of the network services as well as the users to develop trustworthy applications. We have developed a trust management architecture that enables the service providers to determine the trustworthiness of the network slices providing the network services. We have implemented a prototype of the trust management architecture using the Open Source MANO Platform and presented the performance results. The results show that our trust mechanisms cause only a slight reduction in the performance of network slices over virtualized infrastructure. We have also discussed how the proposed architecture can be used to detect and mitigate the impact of malicious virtual network functions in a dynamic manner. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | Software Enabled Security Architecture and Mechanisms for Securing 5G Network ServicesabstractThe 5G network systems are evolving and have complex network infrastructures. There is a great deal of work in this area focused on meeting the stringent service requirements for the 5G networks. Within this context, security requirements play a critical role as 5G networks can support a range of services such as healthcare services, financial and critical infrastructures. 3GPP and ETSI have been developing security frameworks for 5G networks. Our work in 5G security has been focusing on the design of security architecture and mechanisms enabling dynamic establishment of secure and trusted end to end services as well as development of mechanisms to proactively detect and mitigate security attacks in virtualised network infrastructures. The focus of this paper is on the latter, namely the facilities and mechanisms, and the design of a security architecture providing facilities and mechanisms to detect and mitigate specific security attacks. We have developed a simplified version of the security architecture using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) technologies. The specific security functions developed in this architecture can be directly integrated into the 5G core network facilities enhancing its security. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
NetSoft | 2 |
| 2021 | Techniques for Securing Control Systems from AttacksabstractIncreasingly Industrial Control Systems (ICS) systems are being connected to the Internet to minimise the operational costs and provide additional flexibility. These control systems such as the ones used in power grids, manufacturing and utilities operate continually and have long lifespans measured in decades rather than years as in the case of IT systems. Such industrial control systems require uninterrupted and safe operation. However, they can be vulnerable to a variety of attacks, as successful attacks on critical control infrastructures could have devastating consequences to the safety of human lives as well as a nation's security and prosperity. Furthermore, there can be a range of attacks that can target ICS and it is not easy to secure these systems against all known attacks let alone unknown ones. In this paper, we propose a software enabled security architecture using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) that can enhance the capability to secure industrial control systems. We have designed such an SDN/NFV enabled security architecture and developed a Control System Security Application (CSSA) in SDN Controller for enhancing security in ICS against certain specific attacks namely denial of service attacks, from unpatched vulnerable control system components and securing the communication flows from the legacy devices that do not support any security functionality. In this paper, we discuss the prototype implementation of the proposed architecture and the results obtained from our analysis. Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
TrustCom | 1 |
| 2021 | Techniques for Securing 5G Network Services from attacksabstractThe 5G network systems are evolving and have complex network infrastructures. There is a great deal of work in this area focused on meeting the stringent service requirements for the 5G networks. Within this context, security requirements play a critical role as 5G networks can support a range of services such as healthcare services, financial and critical infrastructures. 3GPP and ETSI have been developing security frameworks for 5G networks. Our work in 5G security has been focusing on the design of security architecture and mechanisms enabling dynamic establishment of secure and trusted end to end services as well as development of mechanisms to proactively detect and mitigate security attacks in virtualised network infrastructures. The focus of this paper is on the latter, namely the facilities and mechanisms, and the design of a security architecture providing facilities and mechanisms to detect and mitigate specific security attacks. We have developed and implemented a simplified version of the security architecture using Software Defined Networks (SDN) and Network Function Virtualisation (NFV) technologies. The specific security functions developed in this architecture can be directly integrated into the 5G core network facilities enhancing its security. We describe the design and implementation of the security architecture and demonstrate how it can efficiently mitigate specific types of attacks. Vijay Varadharajan, Udaya Kiran Tupakula, Kallol Krishna Karmakar |
TrustCom | 2 |
| 2021 | SDN-Enabled Secure IoT ArchitectureabstractThe Internet of Things (IoT) is increasingly being used in applications ranging from precision agriculture to critical national infrastructure by deploying a large number of resource-constrained devices in hostile environments. These devices are being exploited to launch attacks in cyber systems. As a result, security has become a significant concern in the design of IoT-based applications. In this article, we present a security architecture for IoT networks by leveraging the underlying features supported by software-defined networks (SDNs). Our security architecture not only restricts network access to authenticated IoT devices but also enforces fine granular policies to secure the flows in the IoT network infrastructure. The authentication is achieved using a lightweight protocol to authenticate IoT devices. Authorization is achieved using a dynamic policy driven approach. Such an integrated security approach involving authentication of IoT devices and enables authorized flows to protect IoT networks from malicious IoT devices and attacks. We have implemented and validated our architecture using ONOS SDN Controller and Raspbian Virtual Machines, and demonstrated how the proposed security mechanisms can counteract malware packet injection, DDoS attacks using Mirai, spoofing/masquerading, and man-in-the-middle attacks. An analysis of the security and performance of the proposed security mechanisms and their applications is presented in this article. Kallol Krishna Karmakar, Vijay Varadharajan, Surya Nepal, Udaya Kiran Tupakula |
IEEE Internet Things J. | 4 |
| 2020 | Towards a Security Enhanced Virtualised Network Infrastructure for Internet of Medical Things (IoMT)abstractInternet of Medical Things (IoMT) are getting popular in the smart healthcare domain. These devices are resource-constrained and are vulnerable to attack. As the IoMTs are connected to the healthcare network infrastructure, it becomes the primary target of the adversary due to weak security and privacy measures. In this regard, this paper proposes a security architecture for smart healthcare network infrastructures. The architecture uses various security components or services that are developed and deployed as virtual network functions. This makes the security architecture ready for future network frameworks such as OpenMANO. Besides, in this security architecture, only authenticated and trusted IoMTs serve the patients along with an encryption-based communication protocol, thus creating a secure, privacy-preserving and trusted healthcare network infrastructure. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Surya Nepal, Chandra Thapa |
NetSoft | 3 |
| 2020 | Attack Detection on the Software Defined Networking SwitchesabstractSoftware Defined Networking (SDN) is disruptive networking technology which adopts a centralised framework to facilitate fine-grained network management. However security in SDN is still in its infancy and there is need for significant work to deal with different attacks in SDN. In this paper we discuss some of the possible attacks on SDN switches and propose techniques for detecting the attacks on switches. We have developed a Switch Security Application (SSA)for SDN Controller which makes use of trusted computing technology and some additional components for detecting attacks on the switches. In particular TPM attestation is used to ensure that switches are in trusted state during boot time before configuring the flow rules on the switches. The additional components are used for storing and validating messages related to the flow rule configuration of the switches. The stored information is used for generating a trusted report on the expected flow rules in the switches and using this information for validating the flow rules that are actually enforced in the switches. If there is any variation to flow rules that are enforced in the switches compared to the expected flow rules by the SSA, then, the switch is considered to be under attack and an alert is raised to the SDN Administrator. The administrator can isolate the switch from network or make use of trusted report for restoring the flow rules in the switches. We will also present a prototype implementation of our technique. Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
NetSoft | 1 |
| 2020 | Towards a Dynamic Policy Enhanced Integrated Security Architecture for SDN InfrastructureabstractEnterprise networks are increasingly moving towards Software Defined Networking, which is becoming a major trend in the networking arena. With the increased popularity of SDN, there is a greater need for security measures for protecting the enterprise networks. This paper focuses on the design and implementation of an integrated security architecture for SDN based enterprise networks. The integrated security architecture uses a policy-based approach to coordinate different security mechanisms to detect and counteract a range of security attacks in the SDN. A distinguishing characteristic of the proposed architecture is its ability to deal with dynamic changes in the security attacks as well as changes in trust associated with the network devices in the infrastructure. The adaptability of the proposed architecture to dynamic changes is achieved by having feedback between the various security components/mechanisms in the architecture and managing them using a dynamic policy framework. The paper describes the prototype implementation of the proposed architecture and presents security and performance analysis for different attack scenarios. We believe that the proposed integrated security architecture provides a significant step towards achieving a secure SDN for enterprises. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Michael Hitchens |
NOMS | 3 |
| 2020 | VMGuard: A VMI-Based Security Architecture for Intrusion Detection in Cloud EnvironmentabstractCloud security is of paramount importance in the new era of computing. Advanced malware can hide their behavior on detection of the presence of a security tool at a tenant virtual machine (TVM). Hence, TVM-layer security solutions are not reliable. In this paper, we propose a Virtual Machine Introspection (VMI) based security architecture design for fine granular monitoring of the virtual machines to detect known attacks and their variants. We have developed techniques for monitoring the TVMs at the process level and system call level to detect attacks such as those based on malicious hidden processes, attacks that disable security tools in the virtual machines and attacks that alter the behavior of legitimate applications to access sensitive data. Our architecture, VMGuard, utilizes the introspection feature at the VMM-layer to analyze system call traces of programs running on TVM. VMGuard applies the software breakpoint injection technique which is OS agnostic and can be used to trap the execution of programs. Motivated by text mining approaches, VMGuard provides `Bag of n-grams (BonG)' approach integrated with Term Frequency-Inverse Document Frequency (TF-IDF) method, to extract and select features of normal and attack traces. It then applies the Random Forest classifier to produce a generic behavior for different categories of intrusions of the monitored TVM. We have implemented a prototype and conducted a detailed analysis using University of New Mexico (UNM) datasets and a Windows malware dataset obtained from the University of California. The results obtained are promising and demonstrate the applicability of the VMGuard. We compare VMGuard with existing techniques and discuss its advantages. Preeti Mishra, Vijay Varadharajan, Emmanuel S. Pilli, Udaya Kiran Tupakula |
IEEE Trans. Cloud Comput. | 4 |
| 2020 | Counteracting Attacks From Malicious End Hosts in Software Defined NetworksabstractThis paper proposes security techniques for counteracting attacks from malicious end hosts in a software defined networking (SDN) environment. This paper describes the design of a security architecture, which comprises a security management application running in the SDN controller for specifying and evaluating security policies, and security components in the switches for enforcing these security policies on network flows. Our proposed security solution helps to detect the attacking end hosts even before the flow requests from the malicious end hosts are forwarded to the SDN controller. Furthermore, if the end hosts become malicious after the interactions with the SDN controller and generate attacks in the data plane, then our architecture has mechanisms to address these attacks that occur after the establishment of routes by the SDN controller. The domain wide network visibility of the SDN controller enables our security architecture to achieve dynamic management of the security policies. The enforcement of security policies in the data plane is tailored to the functionality available in the network switches, making the proposed security solution practical. We describe the implementation of the proposed security architecture and analyze its security and performance characteristics. We also discuss the advantages of the proposed security architecture over existing solutions. Vijay Varadharajan, Udaya Kiran Tupakula |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | Access Control Based Dynamic Path Establishment for Securing Flows from the User Devices with Different Security Clearance
Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
AINA | 1 |
| 2019 | SDN Enabled Secure IoT Architecture
Kallol Krishna Karmakar, Vijay Varadharajan, Surya Nepal, Udaya Kiran Tupakula |
IM | 4 |
| 2019 | A Policy-Based Security Architecture for Software-Defined NetworksabstractAs networks expand in size and complexity, they pose greater administrative and management challenges. Software-defined networks (SDNs) offer a promising approach to meeting some of these challenges. In this paper, we propose a policy-driven security architecture for securing end-to-end services across multiple SDN domains. We develop a language-based approach to design security policies that are relevant for securing SDN services and communications. We describe the policy language and its use in specifying security policies to control the flow of information in a multi-domain SDN. We demonstrate the specification of fine-grained security policies based on a variety of attributes, such as parameters associated with users and devices/switches, context information, such as location and routing information, and services accessed in SDN as well as security attributes associated with the switches and controllers in different domains. An important feature of our architecture is its ability to specify path- and flow-based security policies that are significant for securing end-to-end services in SDNs. We describe the design and the implementation of our proposed policy-based security architecture and demonstrate its use in scenarios involving both intra- and inter-domain communications with multiple SDN controllers. We analyze the performance characteristics of our architecture as well as discuss how our architecture is able to counteract various security attacks. The dynamic security policy-based approach and the distribution of corresponding security capabilities intelligently as a service layer that enables flow-based security enforcement and protection of multitude of network devices against attacks are important contributions of this paper. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula, Michael Hitchens |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Towards QoS and Security in Software-Driven Heterogeneous Autonomous NetworksabstractAutonomous Networks has a potential to solve complex and critical management issues in large scale multi- technological networks. Further, the novel paradigms, i.e., Software-Defined Networks (SDN) and Network Function Vir- tualization (NFV) offer unique and attractive solutions for Autonomous Networks or Systems (AS). However, despite of these attractive features, we observed two critical issues in this interlinked multi-technology domain. Firstly, the network externality and nodes heterogeneity seriously effected the flow specific Quality of Service (QoS). Secondly, it influenced se- curity adoption in an network of interconnected nodes. We observed that QoS and security both are non-negligible and inter-dependent factors. This motivates us to investigate solution towards a) alleviating the SDN network heterogeneity at control layer, and b) to strengthen the network security after alleviating the heterogeneity. In this research effort, we have attempted to alleviate the first issue. Firstly, significant and reasonable examples have been cited to motivate researchers to study QoS and security hand-to-hand. Secondly, a theoretical high level frame work has been proposed with the aim to transform the N heterogeneous controllers to n homogeneous controller groups. Following this, we have demonstrated that our approximation method to transform heterogeneous systems to homogeneous groups works well even at high degree of heterogeneity in the network. We have shown our theoretical analysis results using Matlab. Following this, we have shown the Proof of Concept (PoC) of our approach in SDN-NFV ecosystem using Mininet. This early analysis will help researchers to address heterogeneity and security in more effective ways. Keshav Sood, Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Shui Yu 0001 |
GLOBECOM | 4 |
| 2018 | Securing Services in Networked Cloud InfrastructuresabstractIn this paper, we propose techniques and architecture for securing services that are hosted in a multi-tenant networked cloud infrastructures. Our architecture is based on trusted virtual domains and takes into account both security policies of the tenant domains as well as specific security policies of the virtual machines in the tenant domains. We describe techniques for detecting a range of attacks such as attacks between the virtual machines within a trusted virtual domain, attacks between the virtual machines in different domains, malicious insider attacks and attacks against specific services such as DNS, database and web servers within a domain. We address security policies for trusted virtual domain management such as secure addition and deletion of a virtual machine and the revocation of privileges associated with a virtual machine in a domain. We also discuss forensic analysis of attacks and fine granular detection of malicious entities and mechanisms for restoration of services. Furthermore the proposed architecture provides mechanisms for enhancing the assurance of communications between the virtual machines in different domains. Finally, we present the implementation of our security architecture using Xen and illustrate how our architecture is able to secure services in networked cloud infrastructures. Vijay Varadharajan, Udaya Kiran Tupakula |
IEEE Trans. Cloud Comput. | 2 |
| 2017 | Autoencoder-based feature learning for cyber security applicationsabstractThis paper presents a novel feature learning model for cyber security tasks. We propose to use Auto-encoders (AEs), as a generative model, to learn latent representation of different feature sets. We show how well the AE is capable of automatically learning a reasonable notion of semantic similarity among input features. Specifically, the AE accepts a feature vector, obtained from cyber security phenomena, and extracts a code vector that captures the semantic similarity between the feature vectors. This similarity is embedded in an abstract latent representation. Because the AE is trained in an unsupervised fashion, the main part of this success comes from appropriate original feature set that is used in this paper. It can also provide more discriminative features in contrast to other feature engineering approaches. Furthermore, the scheme can reduce the dimensionality of the features thereby signicantly minimising the memory requirements. We selected two different cyber security tasks: networkbased anomaly intrusion detection and Malware classication. We have analysed the proposed scheme with various classifiers using publicly available datasets for network anomaly intrusion detection and malware classifications. Several appropriate evaluation metrics show improvement compared to prior results. Mahmood Yousefi-Azar, Vijay Varadharajan, Leonard G. C. Hamey, Udaya Kiran Tupakula |
IJCNN | 4 |
| 2017 | Securing communication in multiple Autonomous System domains with Software Defined NetworkingabstractIn this paper we proposed policy based security architecture for securing the communication in multiple Autonomous System (AS) domains with Software Defined Networks (SDN). We will present a high level overview of the architecture and detail discussion on some of the important components for securing the communication in multiple AS domains. A key component of the security architecture is the specification of security policies that are to be enforced on the SDN communications whether they are intra or inter-domain. We will present example scenarios to demonstrate the operation of the security architecture to enable end-to-end secure communication within a single AS domain and for multiple AS domains. We have justified the model using ONOS controller. Vijay Varadharajan, Kallol Krishna Karmakar, Udaya Kiran Tupakula |
IM | 3 |
| 2017 | SDN-based Dynamic Policy Specification and Enforcement for Provisioning SECaaS in Cloud
Udaya Kiran Tupakula, Vijay Varadharajan, Kallol Krishna Karmakar |
WISE (2) | 1 |
| 2017 | VAED: VMI-assisted evasion detection approach for infrastructure as a service cloudabstractSummary Cloud computing provides on demand provisioning of resources mostly offered as Infrastructure as a Service. The flexibility in services has opened doors for attackers. Research has been performed to detect various malware in the last few years. However, modern malware are advanced enough to detect the presence of virtualization environment, security analyzer, or even the hypervisor by observing the virtualization‐specific information such as virtual processor features, timing features, etc. The malware exhibit evasive nature and can fool existing security solutions by performing modern antidetection tactics. In this paper, we propose an approach named as VMI‐assisted evasion detection (VAED), deployed at virtual machine monitor, to detect the evasion‐based malware attacks. The VAED is based on learning the program semantic of evasive malware. It uses system call dependency graph approach generated using Markov Chain principle and keeps track of system call ordering with transition probability distribution between each pair system calls. It uses software break point injection technique to extract the system call traces of evasive malware samples, which is free from any modification in hardware‐specific values. Hence, it is secure from evasion attempts. The VAED is validated over evasive samples collected from the University of California on request, and results seem to be promising. Preeti Mishra, Emmanuel S. Pilli, Vijay Varadharajan, Udaya Kiran Tupakula |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | Intrusion detection techniques in cloud environment: A survey
Preeti Mishra, Emmanuel S. Pilli, Vijay Varadharajan, Udaya Kiran Tupakula |
J. Netw. Comput. Appl. | 4 |
| 2017 | On the Design and Implementation of an Integrated Security Architecture for Cloud with Improved ResilienceabstractIn this paper, we propose an integrated security architecture which combines policy based access control with intrusion detection techniques and trusted computing technologies for securing distributed applications running on virtualised systems. Our security architecture incorporates access control security policies for secure interactions between applications and virtual machines in different physical virtualized servers. It provides intrusion detection and trusted attestation techniques to detect and counteract dynamic attacks in an efficient manner. We demonstrate how this integrated security architecture is used to secure the life cycle of virtual machines including dynamic hosting and allocation of resources as well as migration of virtual machines across different physical servers. We discuss the implementation of the developed architecture and show how the architecture can counteract attack scenarios involving malicious users exploiting vulnerabilities to achieve privilege escalation and then using the compromised machines to generate further attacks. The feedback between the various security components of our security architecture plays a critical role in detecting sophisticated, dynamically changing attacks, thereby increasing the resilience of the overall secure system. Vijay Varadharajan, Udaya Kiran Tupakula |
IEEE Trans. Cloud Comput. | 2 |
| 2016 | On the Design and Implementation of a Security Architecture for End to End Services in Software Defined NetworksabstractIn this paper, we propose a policy driven security architecture for securing end to end services across multiple autonomous domain based SDN environment. We develop a language based approach to designing a range of security policies that are relevant for SDN services and communications. The design of a security architecture that enables secure routing of packets based on the specified security policies in the SDN Controller is described. Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula |
LCN | 3 |
| 2015 | Trust Enhanced Security for Tenant Transactions in the Cloud EnvironmentabstractCloud computing technologies are receiving a great deal of attention. Although there are several benefits with the cloud, attackers can also make use of the cloud infrastructure for hosting malicious services and generating different types of attacks. In this paper, we propose trust enhanced security techniques for securing tenant transactions in the cloud. Our model takes advantage of the features of trusted computing technology to enhance the design and enforcement of security policies and mechanisms in a cloud environment. Furthermore, the cloud service provider monitors the ongoing tenant transactions for different types of attacks and terminates the malicious transactions. Hence, our model can be used to enhance the security of tenant transactions in cloud. Udaya Kiran Tupakula, Vijay Varadharajan |
Comput. J. | 1 |
| 2015 | Securing wireless mobile nodes from distributed denial-of-service attacksabstractSummary The current mobile devices have become smart and are increasingly being used for conducting business and personal activities. Also, there is increasing number of attacks targeting such mobile devices. The term mobile botnet refers to group of mobile devices that are compromised and controlled by the attacker that can be used for generating distributed denial‐of‐service attacks. The security protocols that have been proposed for wireless and mobile networks have several weaknesses that can be exploited by the attacker to obtain unauthorized access and generate attacks. Also, there is growing number of malicious applications that are aimed to compromise smartphones and using them for generating different types of attacks. In this paper, we propose techniques to counteract distributed denial‐of‐service attacks on wireless mobile devices. We describe the operation and architectural components of our model. We will show that our model is able to efficiently deal with the attacks by dropping the attack traffic before it targets the victim mobile node, can prevent the attack traffic at the upstream nodes, and also deal with the attack cases that involve mobility of the attacking and victim nodes. Copyright © 2014 John Wiley & Sons, Ltd. Vijay Varadharajan, Udaya Kiran Tupakula |
Concurr. Comput. Pract. Exp. | 2 |
| 2014 | Trust Enhanced Cloud Security for Healthcare ServicesabstractToday, healthcare service providers are increasingly making use of the cloud for hosting their services. Although such services are regulated by policies such as HIPAA and healthcare service providers follow best practises to minimise attacks, the attackers can easily exploit such services. Hence there is need for securing such critical services. In this paper we propose trust enhanced cloud security model for healthcare services. Udaya Kiran Tupakula, Vijay Varadharajan |
TrustCom | 1 |
| 2014 | Counteracting security attacks in virtual machines in the cloud using property based attestation
Vijay Varadharajan, Udaya Kiran Tupakula |
J. Netw. Comput. Appl. | 2 |
| 2014 | Antivirus security: naked during updatesabstractThe security of modern computer systems heavily depends on security tools, especially on antivirus software solutions. In the anti-malware research community, development of techniques for evading detection by antivirus software is an active research area. This has led to malware that can bypass or subvert antivirus software. The common strategies deployed include the use of obfuscated code and staged malware whose first instance (usually installer such as dropper and downloader) is not detected by the antivirus software. Increasingly, most of the modern malware are staged ones in order for them to be not detected by antivirus solutions at the early stage of intrusion. The installers then determine the method for further intrusion including antivirus bypassing techniques. Some malware target boot and/or shutdown time when antivirus software may be inactive so that they can perform their malicious activities. However, there can be another time frame where antivirus solutions may be inactive, namely, during the time of update. All antivirus software share a unique characteristic that they must be updated at a very high frequency to provide up-to-date protection of their system. In this paper, we suggest a novel attack vector that targets antivirus updates and show practical examples of how a system and antivirus software itself can be compromised during the update of antivirus software. Local privilege escalation using this vulnerability is also described. We have investigated this design vulnerability with several of the major antivirus software products such as Avira, AVG, McAfee, Microsoft, and Symantec and found that they are vulnerable to this new attack vector. The paper also discusses possible solutions that can be used to mitigate the attack in the existing versions of the antivirus software as well as in the future ones. Copyright © 2013 John Wiley & Sons, Ltd. Byungho Min, Vijay Varadharajan, Udaya Kiran Tupakula, Michael Hitchens |
Softw. Pract. Exp. | 3 |
| 2014 | Security as a Service Model for Cloud EnvironmentabstractCloud computing is becoming increasingly important for provision of services and storage of data in the Internet. However there are several significant challenges in securing cloud infrastructures from different types of attacks. The focus of this paper is on the security services that a cloud provider can offer as part of its infrastructure to its customers (tenants) to counteract these attacks. Our main contribution is a security architecture that provides a flexible security as a service model that a cloud provider can offer to its tenants and customers of its tenants. Our security as a service model while offering a baseline security to the provider to protect its own cloud infrastructure also provides flexibility to tenants to have additional security functionalities that suit their security requirements. The paper describes the design of the security architecture and discusses how different types of attacks are counteracted by the proposed architecture. We have implemented the security architecture and the paper discusses analysis and performance evaluation results. Vijay Varadharajan, Udaya Kiran Tupakula |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2013 | On the Security of Tenant Transactions in the CloudabstractCloud computing technologies are receiving a great deal of attention. Although there are several benefits with the cloud, the attackers can also use the cloud infrastructure for hosting malicious services and generating different types of attacks. In this paper we propose techniques for securing tenant transactions in the cloud. Vijay Varadharajan, Udaya Kiran Tupakula |
CloudCom (1) | 2 |
| 2013 | Integrated Security Architecture for Virtual Machines
Vijay Varadharajan, Udaya Kiran Tupakula |
SecureComm | 2 |
| 2012 | Intrusion detection techniques for virtual domainsabstractA virtual domain enables grouping of related virtual machines running on separate physical machine into a single network domain with a unified security policy. Since the virtual machines can be running different operating systems and applications, the attacker can exploit even a single vulnerability in any of the operating system or applications in a single virtual machine to attack other machines in the virtual domain. There is a need to develop intrusion detection techniques to deal with different types of attacks in virtual domains. In this paper we consider the design choices for attack detection and propose intrusion detection architecture to deal with attacks in virtual domains. Our architecture takes into account the specific features of the virtual machine as well as security policies of the virtual domains to deal with different types of attacks in virtual machines. We have described the operation of the proposed system architecture in detail. Finally we present how our model can efficiently deal with different types of attacks and performance analysis of our model. Udaya Kiran Tupakula, Vijay Varadharajan, Dipankar Dutta |
HiPC | 1 |
| 2012 | Distributed service control technique for detecting security attacksabstractWe propose Distributed Service Control (DSC) technique for securing critical services. One of the main aims of DSC is to deal with the attacks by minimising the attack surface between two hosts. In our model, light weight security policies are enforced at the client machines to ensure that the client can access the services using legitimate traffic only. This will minimise the number of attacks that can be generated by the malicious client machine on the server. We will show that our model can increase the availability of the critical services. Our model can also be used as an early detection technique for the outbreak of worms. Udaya Kiran Tupakula, Vijay Varadharajan |
NOMS | 1 |
| 2012 | TREASURE: Trust Enhanced Security for Cloud EnvironmentsabstractToday, cloud computing is one of the popular technologies. In addition to this, most of the hardware that is being shipped today is equipped with the TPM which can be used for realization of trusted platforms. Recently several TPM attestation techniques such as binary attestation and property based attestation techniques have been proposed but there are some fundamental issues that need to be addressed for using these techniques in practice. In this paper we consider an architecture where different services are hosted on the cloud infrastructure by multiple cloud customers (tenants). Then we consider an attacker model that is specific to the cloud and some of the challenges with the current TPM based attestation techniques. We will also propose a novel trust enhanced security model for cloud which overcomes the challenges with the current TPM based attestation techniques and efficiently deals with the attacks in the cloud. In our model, the cloud service provider is used as the Certification Authority (CA) for the tenant virtual machines. The CA only certifies the basic security properties which are the assurance on the traffic originating from the tenant virtual machine and validation of the tenant virtual machine transactions. The components of the CA monitor the interactions of the tenant virtual machine for the certified properties. Since the tenant virtual machines are running on the cloud service provider infrastructure, it is aware of the dynamic changes to the tenant virtual machine. The CA can terminate the ongoing transactions and/or dynamically isolate the tenant virtual machine if there is a variation in the behaviour of the tenant virtual machine from the certified properties. Hence our model can be used to address the challenges with the current TPM based attestation techniques and efficiently deal with the attacks in the cloud. We will present implementation of our model on Xen and how it deals with the attacks in different attack case scenarios. We will also show that our model is beneficial for the cloud service providers, tenants and tenant customers. Vijay Varadharajan, Udaya Kiran Tupakula |
TrustCom | 2 |
| 2012 | Dynamic State-Based Security Architecture for Detecting Security Attacks in Virtual MachinesabstractCurrent Internet environment is vulnerable to a range of different types of attacks, and furthermore, new types of attacks are being discovered on a daily basis. In this paper, we address the design of comprehensive intrusion detection for virtual-machine-based systems. We propose a novel security architecture using a virtual machine monitor-based intrusion detection system called Virtual machine Intrusion deteCTOR (VICTOR), which takes into account the specific characteristics of operating system and applications running in each virtual machine at a fine granular level to detect attacks. The components of our architecture are designed to deal with different types of malicious behaviour. The entity validation component is used for capturing information of the operating system and applications running in the virtual machines, secure logging and detection of attacks that are generated with spoofed source address. The intrusion detection engine component is used for the detection of known attacks and suspicious behaviour of the entities by monitoring the incoming and outgoing traffic of virtual machines. The dynamic analyser is used for detection and validation of hidden processes, detection of zero-day attacks and fine granular isolation of malicious process that is generating the attack traffic. After a zero-day attack is detected, interactive virtual machine technique is used to determine whether the zero-day attack exhibits polymorphic or metamorphic behaviour and develop attack signatures to deal with the attack. We have analysed our architecture with different types of attacks such as hidden processes and attacks such as Slammer. In this paper, we illustrate the operation of our system architecture by considering Slammer worm attack in detail. Udaya Kiran Tupakula, Vijay Varadharajan |
Comput. J. | 1 |
| 2011 | Techniques for Analysing PDF MalwareabstractToday, PDF is one of the widely used applications for sharing documents. Some of the important factors for the popular use of the PDF application are due to its platform independency and rich digital offerings such as ability to include multimedia files, direct URL access and HTTP communication. However its wider acceptance among the user community has also attracted the attackers to develop and spread malware using PDF files. Most of the existing security tools are not equipped to deal with the attacks related to PDF. In this paper we present different techniques that can be used by an attacker to generate PDF attacks. Then we propose portable document scanner (PDSCAN) which can detect the attacks by analyzing the suspicious objects and the scripts that are embedded in the documents. PDSCAN makes use of dynamic and static analysis techniques to deal with the malware. Finally we present detail analysis of a malicious PDF file in Virtual Box environment. Caglar Ulucenk, Vijay Varadharajan, Venkatesan Balakrishnan, Udaya Kiran Tupakula |
APSEC | 4 |
| 2011 | Intrusion Detection Techniques for Infrastructure as a Service CloudabstractToday, cloud computing is one of the increasingly popular technology where the customer can use the resources of the cloud services providers to perform their tasks and only pay for the resources they use. The customer virtual machines in the cloud are vulnerable to different types of attacks. In this paper we propose techniques for securing customer virtual machines from different types of attacks in the Infrastructure as a Service cloud and describe how this can be achieved in practice. Our model enables to differentiate attack traffic originating from each virtual machine even if multiple virtual machines on a VMM are sharing a single IP address. Udaya Kiran Tupakula, Vijay Varadharajan, Naveen Akku |
DASC | 1 |
| 2011 | Security Techniques for Beyond 3G Wireless Mobile NetworksabstractSignificant developments in the recent times have led to an increasing use of mobile devices such as smart phones in accessing Internet services and applications over wireless networks. In this paper, we propose a security architecture for counteracting denial of service attacks in Beyond 3G (B3G) network architecture with mobile nodes. We describe the system architecture and discuss the different cases of attack scenarios involving the mobility of the attacking and victim nodes. Our proposed solution takes into account practical issues such as limited resources of the mobile nodes. It has distinct advantages such as monitoring of the traffic to the victim node and the attack traffic being dropped before reaching the victim, the ability to trace back the attacking node and prevent the attack at the home agent or foreign agent that is closer to the attacking node, and the ability to deal with dynamic changes in attack traffic patterns. We also present an analysis of our proposed architecture as well as simulation results. Udaya Kiran Tupakula, Vijay Varadharajan, Sunil Kumar Vuppala |
EUC | 1 |
| 2011 | Security Architecture for Virtual Machines
Udaya Kiran Tupakula, Vijay Varadharajan, Abhishek Bichhawat |
ICA3PP (1) | 1 |
| 2011 | On the design of Virtual machine Intrusion detection systemabstractIn this paper we propose comprehensive security architecture called VICTOR to deal with different types of attacks on virtual machines. Our model takes into account the specific characteristics of operating system and applications running in each virtual machine (VM) at a fine granular level to deal with the attacks. Our architecture has several components such as entity validation, intrusion detection engine and dynamic analyzer. The entity validation component is used in the detection of attack traffic with spoofed source address, secure logging, and capturing information of the operating system and applications running in the virtual machines. The intrusion detection engine component is used for detection of known attacks and suspicious behaviour by monitoring the incoming and outgoing traffic of virtual machines. The dynamic analyzer is used for detection and validation of suspicious processes, detection of zero day attacks and fine granular isolation of malicious process or application that is generating the attack traffic. Udaya Kiran Tupakula, Vijay Varadharajan |
Integrated Network Management | 1 |
| 2011 | Security techniques for zero day attacksabstractWe propose security architecture to detect and prevent zero day attacks and techniques to deal with the polymorphic and metamorphic behaviour of the attacks. The components of our architecture are designed to deal with different types of malicious behaviour. The entity validation component is used for capturing information of the operating system and applications running in the virtual machines, secure logging and detection of attacks that are generated with spoofed source address. The intrusion detection engine component is used for detection of known attacks and suspicious behaviour of the entities by monitoring the incoming and outgoing traffic of virtual machines. The dynamic analyzer is used for detection and validation of hidden processes, detection of zero day attacks and fine granular isolation of malicious process that is generating the attack traffic. After a zero day attack is detected, interactive VM technique is used to determine if the zero day attack exhibits polymorphic or metamorphic behaviour and develop attack signatures to deal with the attacks efficiently. Udaya Kiran Tupakula, Vijay Varadharajan |
IWCMC | 1 |
| 2011 | Counteracting DDoS attacks in WLANabstractThe security protocols for WLAN such as WEP have fundamental weakness which can be exploited by the attacker to obtain unauthorized access to the wireless networks and generate attacks. In this paper, we propose a security architecture for counteracting denial of service attacks in wireless based network architecture with mobile nodes. We describe the system model and discuss the different cases of attack scenarios involving the mobility of the attacking and victim nodes. We describe how mobile IP protocol in conjunction with our model can be used to deal efficiently with the attacks on mobile nodes. Udaya Kiran Tupakula, Vijay Varadharajan, Sunil Kumar Vuppala |
SIN | 1 |
| 2011 | TVLAN: Trusted and Virtualised Local Area NetworksabstractToday most of the desktops, laptops are being shipped with the TPM and Virtualisation technology is widely being deployed. On the other hand, we are witnessing an increasing number of zero day attacks. Our analysis confirms that Local Area Networks are highly vulnerable to such attacks since there is free communication between the hosts in the LAN. A single compromised host can severely degrade the services in the traditional LAN and it is extremely difficult task for the security administrator to determine the compromised host that is generating attack traffic. In this paper we propose techniques to enhance the security in traditional LAN by making use of the trusted computing and virtualisation technologies. Often virtualisation is considered as a technology which enables to run multiple computers on a single server. We will show that virtualisation technology has significant benefits even if a single virtual machine is hosted on each VMM. Our model enables the security administrator to enforce security policies on the traffic that can be placed on the LAN medium. Hence our model efficiently deals with the attack at the VMM that is hosting the compromised virtual machine. The security can be enhanced furthermore by using the TPM technology to secure the virtualized local area networks. We will also present detail analysis of different cases scenarios on how the proposed model can enhance the security of the local area networks. There are several advantages with our model. Emerging attacks such as Conficker remain dormant in our proposed architecture in order to avoid detection. Hence our model can transform the highly vulnerable traditional LANs into trust enhanced and secure virtualized local area networks. Udaya Kiran Tupakula, Vijay Varadharajan |
TrustCom | 1 |
| 2010 | Detecting Security Attacks in Trusted Virtual DomainsabstractA trusted virtual domain (TVD) enables grouping of related virtual machines running on separate physical machine into a single network domain with a unified security policy. Since the virtual machines can be running different operating systems and applications, the attacker can generate attacks in the TVD by exploiting a single vulnerability in any of the operating systems or applications. Our aim in this paper is to consider the design choices and develop an intrusion detection architecture that would enable efficient detection and prevention of different types of attacks in such a TVD based distributed environments. The proposed architecture can capture the knowledge of the operating systems and applications at fine granular level and isolate the malicious entities that are generating the attack traffic. Our model takes into account the security policies that are specific to the virtual machine as well as security policies of the trusted virtual domains to deal with the attacks efficiently. Udaya Kiran Tupakula, Vijay Varadharajan |
EUC | 1 |
| 2009 | SBAC: Service Based Access ControlabstractIn this paper we propose a dynamically invoked service based access control (SBAC) model to efficiently deal with the distributed denial of service (DDoS) attacks. The main idea of the SBAC is based on the observation that if the routers have information about the services that are running on the end host and can identify the upper layer traffic from the IP packet payload, then it becomes easy to differentiate between legitimate and attack traffic for that particular victim server. To minimise the overhead on the routers, the SBAC model is invoked during the attack times only and the victimpsilas traffic is processed separately. The boundary routers in SBAC model validate each incoming packet to the victim on a per server basis. Only the packets that are considered to be accessing the legitimate services are passed and the remaining packets are dropped. Hence, at this stage the victimpsilas network is immune to any dynamic changes in attack pattern if the attack packets are not accessing the legitimate services at the victim end. The packets that are considered to be accessing legitimate services of the victim machine/network are marked with a unique ID and destined to the victim. If any of the received packets are found to be malicious, the unique ID enables the victim to identify service specific attack signature for each ingress SBAC router and prevent the attack traffic at that particular router. We will also discuss how the SBAC model deals with attacks on the infrastructure of the autonomous system. Udaya Kiran Tupakula, Vijay Varadharajan, Sunil Kumar Vuppala |
ICECCS | 1 |
| 2008 | Subjective logic based trust model for mobile ad hoc networksabstractIn last five years, several trust models have been proposed to enhance the security of Mobile Ad hoc Networks (MANET). Nevertheless, these trust models fail to express the notion of ignorance during the establishment of trust relationships between mobile nodes. Furthermore, they lack a well-defined approach to defend against the issues resulting from recommendations. In this paper, we propose a novel subjective logic based trust model that enables mobile nodes to explicitly represent and manage ignorance as uncertainty during the establishment of trust relationships with other nodes. Our model defines additional operators to subjective logic in order to address the ignorance introduced between mobile nodes (which have already established trust relationships) as a result of mobility-induced separation. Second, we demonstrate on how mobile nodes formulate their opinions for other nodes based on the evidence collected from the benign and malicious behaviors of those nodes. We then describe on how mobile nodes establish trust relationships with other nodes using the opinions held for those nodes. Depending on the policies defined, these relationships are then used by our model to enhance the security of mobile communications. Third, we propose a novel approach to communicate recommendations by which no explicit packets or additional headers are disseminated as recommendations. This allows our model to defend against recommendation related issues such as free-riding, honest-elicitation, and recommender's bias. Finally, we demonstrate the performance of our model through NS2 simulations. Venkatesan Balakrishnan, Vijay Varadharajan, Udaya Kiran Tupakula |
SecureComm | 3 |
| 2006 | Fellowship: Defense against Flooding and Packet Drop Attacks in MANETabstractIn this paper, we propose an obligation-based model called fellowship to mitigate the flooding and packet drop attacks. We also explain how the fellowship model identifies and penalizes both the malicious and selfish nodes respectively in mobile ad hoc networks (MANET). The main advantages of our model are: it unifies the framework to defend both flooding and packet drop attacks, it identifies and expels the malicious and selfish nodes that fail to contribute their resources, and rejoins the repenting malicious and selfish nodes into the network. In addition, our technique does not rely on any centralized authority or tamper-proof hardware Venkatesan Balakrishnan, Vijay Varadharajan, Udaya Kiran Tupakula |
NOMS | 3 |
| 2004 | Counteracting TCP SYN DDoS attacks using automated modelabstractWe propose modifications to the automated model to counteract TCP SYN distributed denial of service (DDoS) attacks nearest to the attacking source and also discuss the prototype implementation of our technique. It should be noted that we do not solve the TCP SYN problem, but we enable the victim to differentiate between the traffic originating from good and bad network domains, trace the router that is nearest to the attacking source with a single packet, even if the source address of the packet is spoofed, and prevent the attack traffic at the router which is nearest to the attacking source. Since our model is invoked only during attack times, it has much less overhead, and the main advantage of this technique is that the victim can provide better service for traffic originating from good network domains and completely eliminate or provide limited service for the traffic originating from the bad network domain. Udaya Kiran Tupakula, Vijay Varadharajan, Ashok Kumar Gajam |
GLOBECOM | 1 |
| 2003 | A Controller Agent Model to Counteract DoS Attacks in Multiple Domains
Udaya Kiran Tupakula, Vijay Varadharajan |
Integrated Network Management | 1 |