VLDB 2026 Research / reviewers in the wild / expert
Mehran Bagheri
dblp:78/2355
· DBLP profile ↗
6ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0001-9976-805XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Machine learning-enabled hybrid intrusion detection system with host data transformation and an advanced two-stage classifierabstractNetwork Intrusion Detection Systems (NIDS) have been extensively investigated by monitoring real network traffic and analyzing suspicious activities. However, there are limitations in detecting specific types of attacks with NIDS, such as Advanced Persistent Threats (APT). Additionally, NIDS is restricted in observing complete traffic information due to encrypted traffic or a lack of authority. To address these limitations, a Host-based Intrusion Detection system (HIDS) evaluates resources in the host, including logs, files, and folders, to identify APT attacks that routinely inject malicious files into victimized nodes. In this study, a hybrid network intrusion detection system that combines NIDS and HIDS is proposed to improve intrusion detection performance. The host data undergoes a Language Processing (NLP)-based Bidirectional Encoder Representations from Transformers (BERT) model from textual representation to a numerical one in order to process host data in a similar way to the network flow data through machine learning models. The feature flattening technique is applied to flatten two-dimensional host-based features that is provided by BERT into one-dimensional vectors so that host-based and network flow-based features can be processed by advanced Machine Learning (ML) models. In order to enhance HIDS effectiveness, a two-stage collaborative classifier is utilized, which applies two tiers of machine learning algorithms, binary and multi-class classifiers, to detect network intrusions. Once a binary classifier is used to detect benign samples to reduce the complexity of the original problem, the attack data are classified by a multi-class supervised learner to identify attack types. Hence, the overall performance of the two-stage collaborative model outperforms the baseline classifier, XGBoost. The proposed method is shown to generalize across two well-known datasets, CICIDS 2018 and NDSec-1. The performance of XGBoost, which represents conventional ML, is evaluated. Combining host and network features enhances attack detection performance (macro average F1 score) by 8.1% under the CICIDS 2018 dataset and 3.7% under the NDSec-1 dataset. Meanwhile, the two-stage collaborative classifier improves detection performance for most single classes, especially for DoS-LOIC-UDP and DoS-SlowHTTPTest, with improvements of 30.7% and 84.3%, respectively, when compared with the traditional ML models. Murat Simsek, Burak Kantarci, Mehran Bagheri, Petar Djukic |
Comput. Networks | 4 |
| 2023 | Knowledge-Based Zero-Touch Security under Host and Network Flow Features MergerabstractIncorporating machine learning algorithms with Intrusion Detection System (IDS) can detect network intrusions without human intervention and aims for Zero Touch Networks (ZTN). In this research, an automatic network-based features and host-based features integrated intrusion detection scheme is presented to improve the performance of network attack detection under the SCVIC-CIDS-2021 dataset which is derived from the integration of network packets and host logs of the CSE-CIC-IDS2018 dataset. Auto-encoder (AE) and Gated Recurrent Unit (GRU) are utilized for feature derivation to overcome the dimensionality mismatch between network-based and host-based features. The knowledge-based Prior Knowledge Input (PKI) model is used to combine unsupervised extra knowledge with a pre-trained supervised model for the final classification results. The results of the experiment reveal that the integration of network-based and host-based features is effective and the PKI model improves the performance of the original ML classification algorithm as well. Under the test set, the maximum achievable macro average F1-score reaches up to 97.08% which points out approximately 9% improvement compared to the best baseline performance. Yu Shen 0001, Murat Simsek, Burak Kantarci, Hussein T. Mouftah, Mehran Bagheri, Petar Djukic |
ICC | 5 |
| 2022 | Collaborative Feature Maps of Networks and Hosts for AI-driven Intrusion DetectionabstractIntrusion Detection Systems (IDS) are critical secu-rity mechanisms that protect against a wide variety of network threats and malicious behaviors on networks or hosts. As both Network-based IDS (NIDS) or Host-based IDS (HIDS) have been widely investigated, this paper aims to present a Combined Intrusion Detection System (CIDS) that integrates network and host data in order to improve IDS performance. Due to the scarcity of datasets that include both network packet and host data, we present a novel CIDS dataset formation framework that can handle log files from a variety of operating systems and align log entities with network flows. A new CIDS dataset named SCVIC-CIDS-2021 is derived from the meta-data from the well-known benchmark dataset, CIC-IDS-2018 by utilizing the proposed framework. Furthermore, a transformer-based deep learning model named CIDS-Net is proposed that can take network flow and host features as inputs and outperform baseline models that rely on network flow features only. Experimental results to evaluate the proposed CIDS-Net under the SCVIC-CIDS-2021 dataset support the hypothesis for the benefits of combining host and flow features as the proposed CIDS- N et can improve the macro F1 score of baseline solutions by 6.36 % (up to 99.89%). Jinxin Liu 0001, Murat Simsek, Burak Kantarci, Mehran Bagheri, Petar Djukic |
GLOBECOM | 4 |
| 2022 | Prior Knowledge based Advanced Persistent Threats Detection for IoT in a Realistic BenchmarkabstractThe number of Internet of Things (IoT) devices being deployed into networks is growing at a phenomenal pace, which makes IoT networks more vulnerable in the wireless medium. Advanced Persistent Threat (APT) is malicious to most of the network facilities and the available attack data for training the machine learning-based Intrusion Detection System (IDS) is limited when compared to the normal traffic. Therefore, it is quite challenging to enhance the detection performance in order to mitigate the influence of APT. Therefore, Prior Knowledge Input (PKI) models are proposed and tested using the SCVIC-APT-2021 dataset. To obtain prior knowledge, the proposed PKI model pre-classifies the original dataset with unsupervised clustering method. Then, the obtained prior knowledge is incorporated into the supervised model to decrease training complexity and assist the supervised model in determining the optimal mapping between the raw data and true labels. The experimental findings indicate that the PKI model outperforms the supervised baseline, with the best macro average F1-score of 81.37%, which is 10.47% higher than the baseline. Yu Shen 0001, Murat Simsek, Burak Kantarci, Hussein T. Mouftah, Mehran Bagheri, Petar Djukic |
GLOBECOM | 5 |
| 1993 | An STS-N byte-interleaving multiplexer/scrambler and demultiplexer/descrambler architecture and its experimental OC-48 implementationabstractThe authors present a byte-interleaving architecture for generating higher-order signals in the synchronous optical network (SONET) digital hierarchy and report on the implementation and system performance results of an experimental 2.488 Gbit/s SONET STS-3c to STS-48 (OC-48) byte multiplexer/scrambler and STS-48 (OC-48) to STS-3c byte demultiplexer/descrambler. The proper operation of the byte multiplexer and demultiplexer has been verified in an OC-48 experiment with a bit error rate (BER) of less than 10/sup -14/. It is shown that the byte-interleaving architecture leads to a simple and modular implementation of higher-rate interfaces (such as OC-192 at 9.95 Gbit/s) using state-of-the-art technologies.> Mehran Bagheri, Dennis T. Kong, Wayne S. Holden, Fernando C. Irizarry, Derek D. Mahoney |
IEEE/ACM Trans. Netw. | 1 |
| 1991 | Silicon Bipolar Integrated Circuits for Multi-GB/s Optical Communication SystemsabstractThe authors discuss several important circuits for fiber-optic transmission, implemented in an advanced silicon bipolar integrated circuit technology. Specifically, the authors discuss the design considerations and measured performance of a 2:1 multiplexer, front end receiver, limiting amplifier, and decision circuit IC. Also discussed are three hybrid circuit modules: a 2:1 multiplexer, 1:2 demultiplexer, and parallel processing decision circuit. These ICs and hybrid circuit modules operate at multi-Gb/s data rates. The performance of these ICs indicates that advanced silicon bipolar integrated circuits with their high speed, functionality and low cost potential could play an important role in alleviating the electronic bottleneck in future multigigabit optical communication systems.> Klaus Runge, Winston I. Way, Mehran Bagheri, James L. Gimlett, D. Clawin, Nim Cheung 0001, Daniel J. Millicker, Detlef Daniel, C. Snapp |
IEEE J. Sel. Areas Commun. | 3 |