Ferdous A. Barbhuiya

dblp:78/8343 · also Ferdous Ahmed Barbhuiya · DBLP profile ↗
← Back
33ranked-venue papers
4as first author
18since 2021 · last 2026
0000-0001-8247-9171ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 7 since 2021Security and privacy · 6 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 3 since 2021Systems, architecture and hardware · 4 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2026 VERGE-IDS: Variational Encoder-BiGRU Based Framework for Threat Detection in IoT Networks
Siddhant Gond, Bishal Chhetry, Rajdeep Kumar Dutta, Rakesh Matam, Ferdous A. Barbhuiya, Ashok Singh Sairam
WCNC5
2026 Advancing Industrial Honeypots: FSM and LLM Integration for Realistic ICS Protocol Emulation
abstract
Industrial control system (ICS) honeypots face significant challenges in emulating proprietary protocols, adapting to novel attacker queries, and maintaining deception effectiveness. This article presents a novel hybrid honeypot framework that integrates finite state machine (FSM)-driven protocol modeling with a retrieval-augmented generation (RAG)-enhanced large language model (LLM). The FSM ensures structured state transitions, preserving contextual coherence and scalability, while the RAG-enhanced LLM dynamically generates accurate responses to previously unseen queries, enabling real-time protocol expansion. A key innovation of this framework is its ability to learn from attacker interactions, iteratively refine responses, and autonomously expand the protocol state machine, thereby significantly enhancing protocol emulation depth. Unlike conventional honeypots or those solely based on fine-tuned LLMs, this approach leverages RAG, iterative feedback loops, fact-checking, and context-aware prompting to ensure realism while mitigating hallucinations. Experimental evaluations demonstrate that the proposed framework outperforms conventional honeypots by achieving superior protocol fidelity, increasing attacker engagement, and broadening the attack surface.
Saurabh Chamotra, Ferdous A. Barbhuiya
IEEE Trans. Ind. Informatics2
2026 SAGE: An Adaptive IoT Honeypot with FSM-Driven Protocol Emulation and GraphRAG-Powered Response Generation
abstract
Increasing security threats in Internet of Things (IoT) ecosystems necessitate advanced deception mechanisms that can engage adversaries and generate realistic interactions. Traditional IoT honeypots suffer from limited protocol emulation, static response mechanisms, and susceptibility to fingerprinting, making them ineffective against sophisticated attacks. To address these challenges, this article introduces SAGE (State-Aware Graph-Enhanced Honeypot), an adaptive IoT honeypot that integrates Finite-State Machine (FSM)-driven protocol emulation with GraphRAG-enhanced retrieval. Unlike conventional honeypots, SAGE dynamically models stateful IoT protocols, ensuring structured and realistic request-response interactions. For undefined requests, GraphRAG retrieval selects relevant protocol knowledge from knowledge graphs and integrates it with FSM-derived contextual information, enabling the Large Language Model (LLM) to generate coherent and deception-resilient responses. Additionally, a fact-checking engine and feedback mechanism refine responses, mitigating hallucinations and ensuring protocol fidelity. A key feature of SAGE is its ability to create an IoT honeypot with limited protocol knowledge while progressively evolving its emulation depth by dynamically expanding its state-response mappings based on observed adversarial interactions. Experimental evaluation demonstrates that SAGE enhances deception robustness, improves adversary engagement, and mitigates honeypot fingerprinting risks. By combining FSM-based protocol modeling, GraphRAG-enhanced retrieval, and adaptive LLM-generated responses, SAGE establishes a scalable, intelligence-driven security framework that significantly advances IoT honeypot technology.
Saurabh Chamotra, Ferdous A. Barbhuiya
ACM Trans. Internet Things2
2026 OptiFog: A Framework for Acquiring State Information and Predicting Resource Availability for Task Offloading in Cooperative Fog-Networks
abstract
The primary objective of fog computing is to minimize the reliance of IoT devices on the cloud by leveraging the resources of fog network. Typically, IoT devices offload computation tasks to fog to meet different task requirements such as latency in task execution, computation costs, etc. So, selecting such a fog node that meets task requirements is a crucial challenge. To choose an optimal fog node, access to each node's resource availability information is essential. Existing approaches often assume state availability or depend on a subset of state information to design mechanisms tailored to different task requirements. In this paper,OptiFog:a cluster-based fog computing architecture for acquiring the state information followed by optimal fog node selection and task offloading mechanism is proposed. Additionally, a continuous time Markov chain based stochastic model for predicting the resource availability on fog nodes is proposed. This model prevents the need to frequently synchronize the resource availability status of fog nodes, and allows to maintain an updated state information. Extensive simulation results show thatOptiFoglowers task execution latency considerably, and schedules almost all the tasks at the fog layer compared to the existing state-of-the-art.
Mehbub Alam, Nurzaman Ahmed, Shyamal Ghosh, Rakesh Matam, Ferdous A. Barbhuiya
IEEE Trans. Serv. Comput.5
2025 Fake Model Free-Rider Attacks in Federated Model Distillation
abstract
Federated Learning (FL) has made it possible to learn from data that would’ve otherwise not been possible due to privacy and security restrictions. FL relies on each client’s honest participation and contribution. The existence of free-rider attackers may undermine the FL process allowing the free-riders to enjoy the contributions of the honest clients without any of their own. In FL algorithms such as Federated Averaging (FedAvg), the goal of the free-rider is to obtain the global model. However, algorithms such as Federated Model Distillation (FedMD) do not have a global model. This enables clients to train models with unique architectures. Here, collaborative learning is done by sharing prediction logits on a common public dataset aggregated by a central server. In this article, we propose a free-riding attack specific to this scenario. Here, the goal of the free-rider is to steal the aggregated logits from the server. Our proposed free-rider attack exploits the model heterogeneity property of FedMD and utilizes fake models to create the prediction logits. Furthermore, we improve upon FedMD and develop a KL-divergence-based detection mechanism to defend against such fake model attacks. Our experiments show that our mechanism can remove such free-riders at the very start of the FL process. Additionally, we also provide theoretical justification for the covertness of the fake model attack and the effectiveness of our detection mechanism.
Kaushik Amar Das, Ferdous A. Barbhuiya, Kuntal Dey
SMC2
2025 VAE-BiLSTM-IDS: A Two-Phase Deep-Learning Framework for Enhanced IoT Security
abstract
The widespread adoption of Internet of Things (IoT) devices has transformed industries such as healthcare, manufacturing, and smart cities. However, these devices often possess limited resources and weak security mechanisms, making them vulnerable to cyberattacks. Traditional Intrusion Detection Systems(IDS) rely on known attack signatures and are ineffective against novel or unknown threats. Although recent machine learning (ML) approaches aim to detect anomalous activity, many continue to suffer from high false alarm rates and degraded performance under dynamic network conditions. To address these challenges, we propose a two-phase deep learning framework, VAE-BiLSTM-IDS, designed specifically for IoT networks. In the first phase, Variational Autoencoders (VAEs) learn normal traffic patterns and detect anomalies using adaptive thresholds that adjust to changing network behavior. In the second phase, a CNN-BiLSTM model leverages both spatial and temporal features to classify anomalies and identify specific attack types. Evaluated on the Edge-IIoT dataset, which contains realistic IoT traffic and zero-day attacks, our framework yields a detection accuracy of 98.89%. It significantly reduces false positives compared to state-of-the-art methods. This approach offers a robust and adaptive solution for improving IoT security.
Siddhant Gond, Bishal Chhetry, Rajdeep Kumar Dutta, Rakesh Matam, Ferdous A. Barbhuiya
TENCON5
2025 EFSM-Based Modeling of Siemens S7comm for Adaptive Cyber Deception in ICS Honeypots
abstract
Programmable Logic Controller (PLC) honeypots are essential for analyzing attacker behavior in Industrial Control Systems (ICS); however, existing solutions often rely on static responses, lack protocol fidelity, and exhibit limited adaptability—rendering them vulnerable to fingerprinting and ineffective against advanced threats. To overcome these limitations, we propose a high-fidelity honeypot architecture that models ICS protocols using an Extended Finite State Machine (EFSM) enhanced with Mealy machine semantics. Our framework captures both control and data-flow semantics and introduces response-dependent transitions to emulate realistic, context-aware PLC behavior. This design enables protocol-compliant variability, supports adaptive deception, and strengthens resistance to fingerprinting. We implement and evaluate the approach using the Siemens S7comm protocol, comparing it against leading honeypots across multiple behavioral and system-level metrics. Experimental results demonstrate substantial improvements in emulation fidelity, attacker engagement, and deception realism, establishing the proposed framework as a robust foundation for next-generation ICS honeypots.
Saurabh Chamotra, Ferdous A. Barbhuiya
TrustCom2
2024 RedgeX: Meta-Learning based Optimal Analytical Model for Programmable Edge Intelligence
abstract
In this paper, we propose RedgeX, a meta-learning based approach for generating analytical models in a distributed edge intelligence network. The approach involves training a meta-learning model on a large dataset of edge device information and performance metrics to predict the optimal analytical model for a given task and available resources. An edge controller, which has the status of all the edge devices, can then deploy the optimal model to the most suitable edge devices based on their available resources. The RedgeX improves the efficiency and effectiveness of edge intelligence systems by dynamically generating analytical models based on the specific requirements of each task and the available resources in the edge devices. The performance evaluation of the proposed scheme shows better utilization of resources, improved performance, and reduced latency in edge intelligence systems.
Mehbub Alam, Nurzaman Ahmed, Rakesh Matam, Ferdous A. Barbhuiya
WCNC4
2024 Analyzing the suitability of IEEE 802.11ah for next generation Internet of Things: A comparative study
Mehbub Alam, Nurzaman Ahmed, Rakesh Matam, Ferdous A. Barbhuiya
Ad Hoc Networks4
2023 RMA-CPABE : A multi-authority CPABE scheme with reduced ciphertext size for IoT devices
Chandan Kumar Chaudhary, Richa Sarma, Ferdous A. Barbhuiya
Future Gener. Comput. Syst.3
2023 SDN-Based Reconfigurable Edge Network Architecture for Industrial Internet of Things
abstract
Internet of Things (IoT) with edge computing capability enhances efficiency, availability, and improves latency of an industrial automation system. However, to provide dynamic services at the resource-constrained edge device, reconfiguration of services is necessary. This article proposes a programmable edge network to (re)configure different services of industrial IoT, that employs programmable layers at the edge for reconfiguring the sensor/actuator network and application services. The lowermost layer allows reconfiguring the communication-related parameters and the middle layer consists of a software-defined networking (SDN) controller that can dynamically program different modules and handles actuation decisions from the edge. An interfacing protocol between the layers is proposed to provide reliability by considering the required configuration parameters among layers. At the top layer, a priority forwarding mechanism is designed for SDN core (control loop) communication when sensor and actuator are on different edges. The proposed architecture significantly improves the actuation latency and is highly energy efficient compared to the existing state-of-the-art.
Mehbub Alam, Nurzaman Ahmed, Rakesh Matam, Mithun Mukherjee 0001, Ferdous A. Barbhuiya
IEEE Internet Things J.5
2023 A Role-Based Encryption (RBE) Scheme for Securing Outsourced Cloud Data in a Multi-Organization Context
abstract
Role-Based Encryption (RBE) is an emerging new technique that integrates role based access control (RBAC) model with encryption. RBE embeds RBAC access policies in encrypted data itself so that only users belonging to appropriate roles are able to decrypt and access the data. However, the existing RBE schemes have been focusing on the single-organization cloud storage system, where the stored data can be accessed by users of the same organization. This paper presents a novel RBE scheme with efficient user revocation for the multi-organization cloud storage system, where the data from multiple independent organizations are stored and can be accessed by the authorized users from any other organization. Additionally, an outsourced decryption mechanism is introduced which enables the users to delegate expensive cryptographic operations to the cloud, thereby reducing the overhead on the end-users. Security and performance analyses of the proposed scheme demonstrate that it is provably secure against Chosen Plaintext Attack and can be useful for practical applications due to its low computation overhead.
Nazatul Haque Sultan, Vijay Varadharajan, Ferdous A. Barbhuiya
IEEE Trans. Serv. Comput.4
2022 Mobility-aware Task Offloading in Fog-Assisted Networks
abstract
In a fog-computing assisted Internet of Things network, end-devices typically offload computation and storage-intensive tasks to fog devices. It is primarily done to meet the latency requirements of tasks, and QoS requirements of the network. In addition to providing localized computing and storage services, the fog network also needs to support end-device mobility while handling offloaded tasks, especially, to mimic the ubiquitous availability of the cloud. Most of the existing works in this direction either recommend task migration or offloading tasks by predicting the device's location. Both these approaches are shown to have their respective limitations, and, thus a mobility-aware task offloading scheme is crucial to meet end-device task requirements. In this paper, we present an approach to handle the mobility of end-devices for effectively handling offloaded tasks. The proposed mechanism is simple, effective, and is not constrained by a device's location, thereby lowering the costs associated with mobility. Especially, the proposed scheme entirely eliminates the cost induced during migration, since effective task offloading can lessen the necessity to attempt task migrations. The simulation result of the proposed scheme reduces execution latency by 44%, saves upto 68% of network usage and 62% of computational cost at the cloud compared to the state-of - the-art.
Sangeeta Kakati, Mehbub Alam, Rakesh Matam, Ferdous A. Barbhuiya, Mithun Mukherjee 0001
GLOBECOM4
2022 MAC Protocols for IEEE 802.11ah-Based Internet of Things: A Survey
abstract
The IEEE 802.11ah, also known as WiFi HaLow, is a scalable solution for medium-range communication in Internet of Things (IoT). While provisioning support for the IoT and machine-to-machine (M2M) communication, IEEE 802.11ah leverages various innovative medium access control (MAC) layer concepts, such as restricted access window (RAW), hierarchical association identification (AID), traffic indication map (TIM) segmentation, etc. This article presents a survey on various MAC protocols for IEEE 802.11ah. While discussing the essential features of IEEE 802.11ah, this survey points out various issues and limitations of such MAC protocols. Although there are some surveys available for MAC protocols of IEEE 802.11ah, they do not include a large number of schemes that have been recently proposed to solve different standardization and implementation-based issues. This article individually surveys issues and challenges in the different problem domains of the IEEE 802.11ah MAC protocol and analyzes the recently proposed solutions. Moreover, this article identifies various factors for further improvement of these protocols. Compared to other relevant surveys, this article emphasizes the issues and challenges to enable researchers to easily identify the problem domain.
Nurzaman Ahmed, Debashis De, Ferdous A. Barbhuiya, Md. Iftekhar Hussain
IEEE Internet Things J.3
2022 MACFI: A multi-authority access control scheme with efficient ciphertext and secret key size for fog-enhanced IoT
Richa Sarma, Chandan Kumar Chaudhary, Ferdous A. Barbhuiya
J. Syst. Archit.3
2022 Authorized Keyword Search over Outsourced Encrypted Data in Cloud Environment
abstract
For better data availability and accessibility while ensuring data secrecy, end-users often tend to outsource their data to the cloud servers in an encrypted form. However, this brings a major challenge to perform the search for some keywords over encrypted content without disclosing any information to unintended entities. This paper proposes a novel expressive authorized keyword search scheme relying on the concept of ciphertext-policy attribute-based encryption. The originality of the proposed scheme is multifold. First, it supports the generic and convenient multi-owner and multi-user scenario, where the encrypted data are outsourced by several data owners and searchable by multiple users. Second, the formal security analysis proves that the proposed scheme is semantically secure against chosen keyword and outsiders keyword guessing attacks. Third, an interactive protocol is introduced which avoids the need of any secure-channels between users and service provider. Fourth, due to the concept of bilinear-map accumulator, the system can efficiently revoke users and/or their attributes, and authenticate them prior to launching any expensive search operations. Fifth, conjunctive keyword search is provided thus enabling to search for multiple keywords simultaneously, with minimal cost. Sixth, the performance analysis shows that the proposed scheme outperforms closely-related works.
Nazatul Haque Sultan, Nesrine Kaaniche, Maryline Laurent, Ferdous A. Barbhuiya
IEEE Trans. Cloud Comput.4
2021 ioFog: Prediction-based Fog Computing Architecture for Offline IoT
abstract
Due to the multi-hop, long-distance, and wireless backbone connectivity, provisioning critical and diverse services face challenges such as low latency and reliability. This paper proposes ioFog, an offline fog architecture for achieving reliability and low latency in a large backbone network. Our solution uses a Markov chain-based task prediction model to offer dynamic service requirements with minimal dependency on the Internet. The proposed architecture considers a central Fog Controller (FC) to (i) provide a global status view and (ii) predict the type of tasks at the Fog Nodes for intelligent offloading decisions. The FC also has the current status of the existing fog nodes in terms of their processing and storage capabilities. Accordingly, it can schedule the possible future offline computations and task allocations. ioFog considers the requirements of individual IoT applications and enables improved fog computing decisions. As compared to the existing offline IoT solutions, ioFog reduces service time significantly and service delivery ratio up to 23%, compared to the existing relevant architectures.
Mehbub Alam, Nurzaman Ahmed, Rakesh Matam, Ferdous A. Barbhuiya
IWCMC4
2021 MOFIT: An Efficient Access Control Scheme with Attribute Merging and Outsourcing Capability for Fog-Enhanced IoT
Richa Sarma, Ferdous A. Barbhuiya
PDCAT2
2020 Handloom Design Generation Using Generative Networks
abstract
This paper proposes deep learning techniques of generating designs for clothing, focused on handloom fabric and discusses the associated challenges along with its application. The capability of generative neural network models in understanding artistic designs and synthesizing those is not yet explored well. In this work, multiple methods are employed incorporating the current state of the art generative models and style transfer algorithms to study and observe their performance for the task. The results are then evaluated through user score. This work also provides a new dataset ”Neural-Loom” for the task of the design generation.
Rajat Kanti Bhattacharjee, Meghali Nandi, Amrit Jha, Gunajit Kalita, Ferdous A. Barbhuiya
ICIP5
2020 ACS-FIT: A Secure and Efficient Access Control Scheme for Fog-enabled IoT
abstract
The explosion of data generated by IoT devices encouraged the introduction of paradigm fog computing, which facilitates computation and analysis at the edge. Alongside fog, cloud computing co-exists for facilities such as massive storage, large processing capability, etc. However, storage and computation of data at different levels increase the risk of data security, which persuades the need for a proper access control scheme. Ciphertext-policy attribute-based encryption (CP-ABE) is a well-known cryptographic mechanism that provides data confidentiality and fine-grained access control. Unfortunately, the existing CP-ABE schemes are not well suited for the cloud-fog-IoT environment as they do not provide functionalities like key-escrow resistance, attribute update, attribute revocation, user revocation, and outsourcing of expensive operations with verifiable outsourced decryption, simultaneously in a single scheme. Therefore, this paper proposes a CP-ABE scheme named ACS-FIT, which supports key-escrow resistance, attribute update, user revocation, attribute revocation, and outsourcing of expensive operations with verifiable outsourced decryption functionalities altogether. The scheme is efficient as the expensive encryption and decryption operations are outsourced to fog nodes leaving only a small and constant amount of computation for the IoT devices. Additionally, the task of attribute update and revocation is also outsourced to a third party. The cost incurred during attribute update and revocation are also efficient as only those components are updated which are associated with the affected attributes. Meanwhile, the user holds a constant size key which remains unchanged during any update. The security analysis proves that the proposed scheme is secure against Chosen-Plaintext Attack under Decisional Bilinear Diffie-Hellman assumption. The performance analysis shows that the proposed scheme is efficient and suitable for IoT devices.
Richa Sarma, Chandan Kumar Chaudhary, Ferdous A. Barbhuiya
SMC3
2020 Analysis and modelling of multi-stage attacks
abstract
Honeypots are the information system resources used for capturing and analysis of cyber attacks. Highinteraction Honeypots are capable of capturing attacks in their totality and hence are an ideal choice for capturing multi-stage cyber attacks. The term multi-stage attack is an abstraction that refers to a class of cyber attacks consisting of multiple attack stages. These attack stages are executed either by malicious codes, scripts or sometimes even inbuilt system tools. In the work presented in this paper we have proposed a framework for capturing, analysis and modelling of multi-stage cyber attacks. The objective of our work is to devise an effective mechanism for the classification of multi-stage cyber attacks. The proposed framework comprise of a network of high interaction honeypots augmented with an attack analysis engine. The analysis engine performs rule based labeling of captured honeypot data. The labeling engine labels the attack data as generic events. These events are further fused to generate attack graphs. The hence generated attack graphs are used to characterize and later classify the multi-stage cyber attacks.
Saurabh Chamotra, Ferdous A. Barbhuiya
TrustCom2
2019 Cloud Based Weather Station using IoT Devices
abstract
This paper proposes a smart system cloud based weather station. The system uses Raspberry Pi, for collecting and observing weather data. The storing and processing of the obtained weather data is done in cloud to predicting the effect of this weather change. The system is designed to effectively monitor the ambient weather conditions such as temperature, humidity, wind speed, pressure, and rainfall etc. The objective is to design a system which is low cost, requires less maintenance, and involved minimal manual intervention. The system is built using commodity hardware Raspberry Pi, various sensors and uses WiFi as a communication medium which makes the system consume very low power and low cost of building. Smaller Raspberry Pi Zero W boards are used to collect the sensor's data and send it to the base station Raspberry Pi 3 board. The Raspberry Pi 3 then further transmits the data over WiFi to the cloud database and this data is further used to train new Machine Learning model deployed in the cloud for prediction of the effect and to observe and study various weather patterns and trends. The users can access the weather data and insights remotely, and in real time through a web application that is built using the Django Framework, and is deployed in the cloud.
Palak Kapoor, Ferdous A. Barbhuiya
TENCON2
2018 ICAuth: A secure and scalable owner delegated inter-cloud authorization
Nazatul Haque Sultan, Ferdous A. Barbhuiya, Maryline Laurent
Future Gener. Comput. Syst.2
2017 A universal cloud user revocation scheme with key-escrow resistance for ciphertext-policy attribute-based access control
abstract
Cloud storage service allows its users to store and share data in a cloud environment. To secure the data from unauthorized entities while sharing, cryptographic mechanisms are used. Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is one such mechanism, which has been widely used to achieve fine-grained access control over encrypted data. However, user revocation and keyescrow, in CP-ABE, are still remaining as challenging problems. In this paper, we propose a key-escrow resistant CP-ABE based access control scheme to provide efficient user revocation. The security analysis of the scheme has been done using Information Theory Tools. The security analysis establishes that it is unconditionally secure and provides any-wise revocation capability. Moreover, comparison with the other notable works in the area shows that it outperforms them in terms of computational and communication overheads.
Nazatul Haque Sultan, Ferdous A. Barbhuiya, Nityananda Sarma
SIN2
2017 Convolutional neural networks for ocular smartphone-based biometrics
Karan Ahuja, Rahul Islam, Ferdous A. Barbhuiya, Kuntal Dey
Pattern Recognit. Lett.3
2016 ISURE: User authentication in mobile devices using ocular biometrics in visible spectrum
abstract
In this paper, we propose a supervised learning based model for ocular biometrics. Using Speeded-Up Robust Features (SURF) for detecting local features of the eye region, we create a local feature descriptor vector of each image. We cluster these feature vectors, representing an image as a normalized histogram of membership to various clusters, thereby creating a bag-of-visual-words model. We conduct a multiphase training, first performing a fast Multinomial Naïve Bayes learning, and subsequently using a pyramid-up topology to use the top k% results (based upon confidence scores) thus predicted and perform Dense SIFT for nearest neighbor matching. Contrary to traditional ocular biometric systems, our proposed approach does not rely highly accurate iris pattern segmentation, allowing less constrained image acquisition conditions such as from mobile devices. Our method identifies the individuals with an identification accuracy varying from 48.76% to 79.49%, across different lighting conditions and phone handset data sources, while testing on the given data.
Karan Ahuja, Abhishek Bose, Seema Nagar, Kuntal Dey, Ferdous A. Barbhuiya
ICIP5
2016 Eye center localization and detection using radial mapping
abstract
We propose a geometrical method, applied over eye-specific features, to improve the accuracy of the art of eye-center localization. Our solution is built upon: (a) checking radially constrained gradient vectors, (b) adding weightage to iris specific features and (c) considering bi-directional image gradients to eliminate errors due to reflection on pupil. Our system outperforms the state of the art methods, when compared collectively across multiple benchmark databases, such as BioID and FERET. Our process is lightweight, robust and significantly fast: achieving 50-60 fps for eye center localization, using a single threaded approach on a 2.4 GHz CPU with no GPU. This makes it practicable for real-life applications.
Karan Ahuja, Ruchika Banerjee, Seema Nagar, Kuntal Dey, Ferdous A. Barbhuiya
ICIP5
2016 A preliminary study of CNNs for iris and periocular verification in the visible spectrum
abstract
Ocular biometrics in the visible spectrum has emerged as an area of significant research activity. In this paper, we propose two convolution-based models for verifying a pair of periocular images containing the iris, and compare the two approaches amongst each other as well as with a baseline model. In the first approach, we perform deep learning in an unsupervised manner using a stacked convolutional architecture, using external models learned a-priori on external facial and periocular data, on top of the baseline model applied on the provided data, and apply different score fusion models. In the second approach, we again use a stacked convolution architecture; but here, we learn the feature vector in a supervised manner. We obtain an AUROC of 0.946 and 0.981, and EER of 0.092 and 0.066, for the two models respectively. We further combine the two models, and observe the combined model to deliver the best performance in case the both the images arise from the same device type, but not necessarily so otherwise, obtaining a AUROC of 0.985 and EER of 0.057. Given the significant performance our methodology yields, our system can be used in real-life applications with minimal error.
Karan Ahuja, Rahul Islam, Ferdous A. Barbhuiya, Kuntal Dey
ICPR3
2016 A Secure Re-encryption Scheme for Data Sharing in Unreliable Cloud Environment
abstract
To share encrypted data in cloud storage, data owner provides decryption keys to authorised users. When such a user is revoked, the encrypted data related to revoked user is re-encrypted and new decryption keys are re-distributed among the non-revoked users. In this paper, an efficient and secure re-encryption scheme has been proposed for data sharing in unreliable cloud environment. The scheme is built on top of Ciphertext-Policy based Attribute-Based Encryption (CP-ABE), which will provide fine-grained access control to share data. The scheme can achieve user revocation without whole ciphertexts re-encryption and key re-distributions. In addition, re-encryption is not performed until a user requests for that data, which reduces overheads. Further, it does not need any clock synchronization. Moreover, the scheme is proven to be secured under Computational Bilinear Diffie-Hellman (CBDH) assumption. A comparison with the other notable work in this area shows that the performance is better in terms of functionality, computational and communication overheads.
Nazatul Haque Sultan, Ferdous A. Barbhuiya
SERVICES2
2012 An Active Detection Mechanism for Detecting ICMP Based Attacks
abstract
In recent years, the number of attacks in computer networks are constantly increasing due to the lack of proper authentication of communicating entities in the network. TCP/IP layering architecture is prone to various threats due to the vulnerabilities in each of its layers. This mandates the requirement for a suitable detection system in the network to monitor the possible attacks. ICMP is a mandatory protocol which provides the error reporting, control and network management functionalities to the Internet Protocol (IP). Many of the attacks in the network like MiTM and DoS can be initiated with the exploitation of this essential protocols. In this paper, an active detection mechanism to identify many ICMP Error messages based attacks is proposed. The ICMP messages are verified by sending suitable probe packets to the hosts and validating their responses. The detection scheme is successfully validated in a testbed with various attack scenarios and the results show the effectiveness of the proposed technique in terms of greater accuracy in the detection rates.
Ferdous A. Barbhuiya, S. Roopa, Ritesh Ratti, Santosh Biswas, Sukumar Nandi
TrustCom1
2011 A host based DES approach for detecting ARP spoofing
abstract
Address Resolution Protocol (ARP) based attacks are caused by compromised hosts in the LAN and mainly involve spoofing with falsified IP-MAC pairs. Since ARP is a stateless protocol such attacks are possible. Neither there are signatures available for these attacks nor any significant statistical behavior change can be observed. So existing signature or anomaly intrusion detection systems are unable to detect these type of attacks. Several schemes have been proposed in the literature to circumvent these attacks, however, these techniques either make IP-MAC pairing static, modify the existing ARP, violate network layering architecture etc. In this paper a host based Discrete Event System (DES) approach is proposed for detecting ARP spoofing attacks. This approach does not require any extra constraint like static IP-MAC, changing the ARP or violation of network layering architecture.
Ferdous A. Barbhuiya, Santosh Biswas, Neminath Hubballi, Sukumar Nandi
CICS1
2011 Detection of neighbor solicitation and advertisement spoofing in IPv6 neighbor discovery protocol
abstract
With the increase in number of hosts in the Internet, there is also a rise in the demand for IP address space. To cater to this issue, IP version 6 (IPv6) succeeded IPv4. Compared to 32 bit IP address space in IPv4, IP address in IPv6 is composed of 128 bits. In IPv4, when a host wants to communicate with another host in an LAN, it needs to know the MAC address of the target host, which was possible through Address Resolution Protocol (ARP). As ARP is stateless and due to lack of authorization in ARP messages, many attacks like request spoofing, response spoofing, Man-in-the-Middle (MiTM), Denial-of- Service (DoS) etc. are possible. IPv6 uses Network Discovery Protocol (NDP) to find the MAC address. NDP is also stateless and lacks authentication of its messages by default. So NDP also suffers from many attacks similar to ARP. Although there are various attack detection and prevention mechanisms available for ARP attacks, they are not yet implemented for NDP (IPv6). In this paper we propose an attack detection mechanism for neighbor solicitation spoofing and neighbor advertisement spoofing.
Ferdous A. Barbhuiya, Santosh Biswas, Sukumar Nandi
SIN1
2011 An active DES based IDS for ARP spoofing
abstract
A network Intrusion Detection System (IDS) is a device or software that monitors network activities and raises alerts on detection of malicious behavior. State-transition based framework like Finite State Machines (FSM), extended FSM, timed FSM, Discrete Event Systems (DES) etc. are widely used in network IDSs because the framework enables formal modeling, analysis, verification etc. The attack detection capability in these IDSs is based on passive monitoring of sequence of events with the assumption that intrusions lead to change in the sequence (which needs to be detected). However, there are certain attacks like ARP spoofing, Internet Control Message Protocol (ICMP) error message based attacks etc. for which passive monitoring schemes have several limitations because in such attacks there is no change in sequence of events. IDSs with active probing are now being proposed for such attacks which involve sending of probe packets that cause difference in sequence of events under attack condition and can be then detected using passive monitoring. In this paper we propose an IDS to detect ARP spoofing attacks using active state-transition framework called “active DES”.
Ferdous A. Barbhuiya, Santosh Biswas, Sukumar Nandi
SMC1