VLDB 2026 Research / reviewers in the wild / expert
Muhammad Rizwan Asghar
dblp:82/10434
· DBLP profile ↗
51ranked-venue papers
11as first author
10since 2021 · last 2026
0000-0002-9607-376XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 5 first-author · 8 since 2021Computer networks · 16 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-authorSystems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Balancing benefits and risks: An analysis of CDN effectiveness in resisting DDos attacks and cyber threats
Qinwen Hu, Muhammad Rizwan Asghar |
Comput. Networks | 2 |
| 2025 | LAGER: Layer-wise Graph Feature Extractor for Network Intrusion DetectionabstractNetwork Intrusion Detection Systems (NIDS) are crucial for safeguarding networks against evolving cyber threats. However, evaluations of NIDS often assume offline training, supervised learning, or static concepts, which do not accurately capture the complexities of real-world scenarios. In this paper, we critically assess the performance of current NIDS and outlier detectors under a realistic threat model that uses online training, unsupervised learning, and is concept drift-prone. We find that conventional feature extractors struggle in diverse real-life environments. To overcome this, we propose LAGER, a novel feature extractor utilizing graph neural networks to extract representative features from a layer-wise graph representation of the network. Our results demonstrate that LAGER enhances the detection accuracy and adaptability to concept drifts for a wide range of NIDS and lays a solid foundation for robust network feature extraction. Dong Seong Kim 0001, Muhammad Rizwan Asghar |
DSN | 3 |
| 2025 | MTD-AD: Moving Target Defense as Adversarial DefenseabstractNetwork Intrusion Detection Systems (NIDSes) are increasingly incorporating Machine Learning (ML) and Deep Learning (DL) algorithms for detecting network intrusions. However, ML/DL algorithms are susceptible to adversarial examples, which can lead to the misclassification of input data. This vulnerability poses a significant threat to the reliability of NIDSes in security-sensitive domains. To address this concern, we propose a novel defense framework called Moving Target Defence as Adversarial Defence (MTD-AD) to protect anomaly-based NIDS models from adversarial attacks by stochastically altering the decision boundary of NIDS. Our approach capitalizes on the observation that adversarial examples reside in close proximity to the decision boundary of the model and exhibit sensitivity to slight perturbations of that boundary. We demonstrate the effectiveness of MTD-AD against practical adversarial attacks and evaluate its resilience against adaptive adversaries using an IoT intrusion detection dataset. Dong Seong Kim 0001, Muhammad Rizwan Asghar |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Towards a Cyber Resilience Quantification Framework (CRQF) for IT infrastructureabstractCyber resilience quantification is the process of evaluating and measuring an organisation’s ability to withstand, adapt to, and recover from cyber-attacks. It involves estimating IT systems, networks, and response strategies to ensure robust defence and effective recovery mechanisms in the event of a cyber-attack. Quantifying cyber resilience can be difficult due to the constantly changing components of IT infrastructure. Traditional methods like vulnerability assessments and penetration testing may not be effective. Measuring cyber resilience is essential to evaluate and strengthen an organisation’s preparedness against evolving cyber-attacks. It helps identify weaknesses, allocate resources, and ensure the uninterrupted operation of critical systems and information. There are various methods for measuring cyber resilience, such as evaluating, teaming and testing, and creating simulated models. This article proposes a cyber resilience quantification framework for IT infrastructure that utilises a simulation approach. This approach enables organisations to simulate different attack scenarios, identify vulnerabilities, and improve their cyber resilience. The comparative analysis of cyber resilience factors highlights pre-configuration’s robust planning and adaptation (61.44%), buffering supported’s initial readiness (44.53%), and network topologies’ robust planning but weak recovery and adaptation (60.04% to 77.86%), underscoring the need for comprehensive enhancements across all phases. The utilisation of the proposed factors is crucial in conducting a comprehensive evaluation of IT infrastructure in the event of a cyber-attack. Saleh Mohamed Alhidaifi, Muhammad Rizwan Asghar, Imran Shafique Ansari |
Comput. Networks | 2 |
| 2024 | NIDS-Vis: Improving the generalized adversarial robustness of network intrusion detection systemabstractNetwork Intrusion Detection Systems (NIDSes) are crucial for securing various networks from malicious attacks. Recent developments in Deep Neural Networks (DNNs) have encouraged researchers to incorporate DNNs as the underlying detection engine for NIDS. However, DNNs are susceptible to adversarial attacks, where subtle modifications to input data result in misclassification, posing a significant threat to security-sensitive domains such as NIDS. Existing efforts in adversarial defenses predominantly focus on supervised classification tasks in Computer Vision, differing substantially from the unsupervised outlier detection tasks in NIDS. To bridge this gap, we introduce a novel method of generalized adversarial robustness and present NIDS-Vis, an innovative black-box algorithm that traverses the decision boundary of DNN-based NIDSes near given inputs. Through NIDS-Vis, we can visualize the geometry of the decision boundaries and examine their impact on performance and adversarial robustness. Our experiment uncovers a tradeoff between performance and robustness, and we propose two novel training techniques, feature space partition and distributional loss function, to enhance the generalized adversarial robustness of DNN-based NIDSes without significantly compromising performance. Dong Seong Kim 0001, Muhammad Rizwan Asghar |
Comput. Secur. | 3 |
| 2022 | TIM: Secure and usable authentication for smartphones
Gi-Chul Yang, Qinwen Hu, Muhammad Rizwan Asghar |
J. Inf. Secur. Appl. | 3 |
| 2021 | A large-scale analysis of HTTPS deployments: Challenges, solutions, and recommendationsabstractHTTPS refers to an application-specific implementation that runs HyperText Transfer Protocol (HTTP) on top of Secure Socket Layer (SSL) or Transport Layer Security (TLS). HTTPS is used to provide encrypted communication and secure identification of web servers and clients, for different purposes such as online banking and e-commerce. However, many HTTPS vulnerabilities have been disclosed in recent years. Although many studies have pointed out that these vulnerabilities can lead to serious consequences, domain administrators seem to ignore them. In this study, we evaluate the HTTPS security level of Alexa’s top 1 million domains from two perspectives. First, we explore which popular sites are still affected by those well-known security issues. Our results show that less than 0.1% of HTTPS-enabled servers in the measured domains are still vulnerable to known attacks including Rivest Cipher 4 (RC4), Compression Ratio Info-Leak Mass Exploitation (CRIME), Padding Oracle On Downgraded Legacy Encryption (POODLE), Factoring RSA Export Keys (FREAK), Logjam, and Decrypting Rivest–Shamir–Adleman (RSA) using Obsolete and Weakened eNcryption (DROWN). Second, we assess the security level of the digital certificates used by each measured HTTPS domain. Our results highlight that less than 0.52% domains use the expired certificate, 0.42% HTTPS certificates contain different hostnames, and 2.59% HTTPS domains use a self-signed certificate. The domains we investigate in our study cover 5 regions (including ARIN, RIPE NCC, APNIC, LACNIC, and AFRINIC) and 61 different categories such as online shopping websites, banking websites, educational websites, and government websites. Although our results show that the problem still exists, we find that changes have been taking place when HTTPS vulnerabilities were discovered. Through this three-year study, we found that more attention has been paid to the use and configuration of HTTPS. For example, more and more domains begin to enable the HTTPS protocol to ensure a secure communication channel between users and websites. From the first measurement, we observed that many domains are still using TLS 1.0 and 1.1, SSL 2.0, and SSL 3.0 protocols to support user clients that use outdated systems. As the previous studies revealed security risks of using these protocols, in the subsequent studies, we found that the majority of domains updated their TLS protocol on time. Our 2020 results suggest that most HTTPS domains use the TLS 1.2 protocol and show that some HTTPS domains are still vulnerable to the existing known attacks. As academics and industry professionals continue to disclose attacks against HTTPS and recommend the secure configuration of HTTPS, we found that the number of vulnerable domain is gradually decreasing every year. Qinwen Hu, Muhammad Rizwan Asghar, Nevil Brownlee |
J. Comput. Secur. | 2 |
| 2021 | Collusion Defender: Preserving Subscribers' Privacy in Publish and Subscribe SystemsabstractThe Publish and Subscribe (pub/sub) system is an established paradigm to disseminate the data from publishers to subscribers in a loosely coupled manner using a network of dedicated brokers. However, sensitive data could be exposed to malicious entities if brokers get compromised or hacked; or even worse, if brokers themselves are curious to learn about the data. A viable mechanism to protect sensitive publications and subscriptions is to encrypt the data before it is disseminated through the brokers. State-of-the-art approaches allow brokers to perform encrypted matching without revealing publications and subscriptions. However, if malicious brokers collude with malicious subscribers or publishers, they can learn the interests of innocent subscribers, even when the interests are encrypted. In this article, we present a pub/sub system that ensures confidentiality of publications and subscriptions in the presence of untrusted brokers. Furthermore, our solution resists collusion attacks between untrusted brokers and malicious subscribers (or publishers). Finally, we have implemented a prototype of our solution to show its feasibility and efficiency. Shujie Cui, Sana Belguith, Pramodya De Alwis, Muhammad Rizwan Asghar, Giovanni Russello |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | e-PRNU: Encrypted Domain PRNU-Based Camera Attribution for Preserving PrivacyabstractPhoto Response Non-Uniformity (PRNU) noise-based source camera attribution is a popular digital forensic method. In this method, a camera fingerprint computed from a set of known images of the camera is matched against the extracted noise of an anonymous questionable image to find out if the camera had taken the anonymous image. The possibility of privacy leak, however, is one of the main concerns of the PRNU-based method. Using the camera fingerprint (or the extracted noise), an adversary can identify the owner of the camera by matching the fingerprint with the noise of an image (or with the fingerprint computed from a set of images) crawled from a social media account. In this article, we address this privacy concern by encrypting both the fingerprint and the noise using the Boneh-Goh-Nissim (BGN) encryption scheme, and performing the matching in encrypted domain. To overcome leakage of privacy from the content of an image that is used in the fingerprint calculation, we compute the fingerprint within a trusted environment, such as ARM TrustZone. We present e-PRNU that aims at minimizing privacy loss and allows authorized forensic experts to perform camera attribution. The security analysis shows that the proposed approach is semantically secure. Experimental results show that the run-time computational overhead is 10.26 seconds when a cluster of 64 computing nodes are used. Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Privacy-preserving Dynamic Symmetric Searchable Encryption with Controllable LeakageabstractSearchable Encryption (SE) is a technique that allows Cloud Service Providers to search over encrypted datasets without learning the content of queries and records. In recent years, many SE schemes have been proposed to protect outsourced data. However, most of them leak sensitive information, from which attackers could still infer the content of queries and records by mounting leakage-based inference attacks, such as the count attack and file-injection attack . In this work, first we define the leakage in searchable encrypted databases and analyse how the leakage is leveraged in existing leakage-based attacks. Second, we propose a Privacy-preserving Multi-cloud based dynamic symmetric SE scheme for relational Database ( P-McDb ). P-McDb has minimal leakage, which not only ensures confidentiality of queries and records but also protects the search, intersection, and size patterns. Moreover, P-McDb ensures both forward and backward privacy of the database. Thus, P-McDb could resist existing leakage-based attacks, e.g., active file/record-injection attacks. We give security definition and analysis to show how P-McDb hides the aforementioned patterns. Finally, we implemented a prototype of P-McDb and tested it using the TPC-H benchmark dataset. Our evaluation results show that users can get the required records in 2.16 s when searching over 4.1 million records. Shujie Cui, Xiangfu Song, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello |
ACM Trans. Priv. Secur. | 3 |
| 2020 | Optimizing Energy in WiFi Direct Based Multi-hop D2D NetworksabstractThe recent pandemic of COVID-19 has changed the way people socially interact with each other. A huge increase in the usage of social media applications has been observed due to quarantine strategies enforced by many governments across the globe. This has put a great burden on already overloaded cellular networks. It is believed that direct Device-to-Device (D2D) communication can offload a significant amount of traffic from cellular networks, especially during scenarios when residents in a locality aim to share information among them. WiFi Direct is one of the enabling technologies of D2D communications, having a great potential to facilitate various proximity-based applications. In this work, we propose power saving schemes that aim at minimizing energy consumption of user devices across D2D based multi-hop networks. Further, we provide an analytical model to formulate energy consumption of such a network. The simulation results demonstrate that a small modification in the network configuration, such as group size and transmit power can provide considerable energy gains. The observed energy consumption is reduced by 5 times for a throughput loss of 12%. Additionally, we measure the energy per transmitted bit for different configurations of the network. Furthermore, we analyze the behavior of the network, in terms of its energy consumption and throughput, for different file sizes. Muhammad Usman 0003, Marwa Qaraqe, Muhammad Rizwan Asghar, Imran Shafique Ansari, Fabrizio Granelli |
GLOBECOM | 3 |
| 2020 | A Case Study of a Cybersecurity Programme: Curriculum Design, Resource Management, and ReflectionsabstractCybersecurity is an area of growing international importance. In response to global shortages of Cybersecurity skills, many universities have introduced degree programmes in Cybersecurity. These programmes aim to prepare students to become Cybersecurity practitioners with advanced skills in a timely manner. Several universities offer Cybersecurity degrees, but these have been developed ad hoc, as there is currently no internationally accepted Cybersecurity curriculum. Recently, an ITiCSE working group on global perspectives on Cybersecurity education developed a competency-based framework that aims to help institutions to implement Cybersecurity programmes. In this report, we present a case study of a Cybersecurity programme at the University of Auckland. We discuss how the curriculum and resource management of this programme evolved, and we present some challenges for the design and delivery of a Cybersecurity programme in the light of this competency-based framework. Muhammad Rizwan Asghar, Andrew Luxton-Reilly |
SIGCSE | 1 |
| 2020 | Towards a Theory of Special-Purpose Program ObfuscationabstractMost recent theoretical literature on program obfuscation is based on notions like virtual black box (VBB) obfuscation and indistinguishability obfuscation (iO). These notions are very strong and are hard to satisfy. Further, they offer far more protection than is typically required in practical applications. On the other hand, the security notions introduced by software security researchers are suitable for practical designs but are not formal or precise enough to enable researchers to provide a quantitative security assurance. Hence, in this paper, we introduce a new formalism for practical program obfuscation that still allows rigorous security proofs. We believe our formalism will make it easier to analyse the security of obfuscation schemes. To show the flexibility and power of our formalism, we give a number of examples. Moreover, we explain the close relationship between our formalism and the task of providing obfuscation challenges. Muhammad Rizwan Asghar, Steven D. Galbraith, Andrea Lanzi, Giovanni Russello, Lukas Zobernig |
TrustCom | 1 |
| 2020 | RevBloc: A Blockchain-based Secure Customer Review SystemabstractCustomer reviews enable customers to share their experiences with others, which allow potential customers to know more about products and consume products with confidence. However, online product sellers and service providers could manipulate customer reviews, such as adding fake positive reviews and removing negative customer reviews, to support their business. Manipulated reviews could result in distorting the original content of customer reviews and misleading customers. State-of-the-art solutions lack a customer review system that is secure, efficient, and usable. In this paper, we propose RevBloc to provide a customer review system with a high level of security, efficiency, and usability. RevBloc is based on blockchain technology that enables customer reviews to be preserved in a distributed ledger, thus a single or subset of malicious parties cannot manipulate the reviews. To show the feasibility of our approach, we implement a proof-of-concept prototype of RevBloc and report its performance. Xiuli Fang, Muhammad Rizwan Asghar |
TrustCom | 2 |
| 2020 | Do My Emotions Influence What I Share? Analysing the Effects of Emotions on Privacy Leakage in TwitterabstractSocial media has become an integral part of modernday society. With increasingly digital societies, individuals have become more familiar and comfortable in using Online Social Networks (OSNs) for just about every aspect of their lives. This higher level of comfort leads to users spilling their emotions on OSNs and eventually their private information. In this work, we aim to investigate the relationship between users' emotions and private information in their tweets. Our research question is whether users' emotions, expressed in their tweets, affect their likelihood to reveal their own private information (privacy leakage) in subsequent tweets. In contrast to existing survey-based approaches, we use an inductive, data-driven approach to answer our research question. We use state-of-the-art techniques to classify users' emotions, and privacy scoring and employ a new technique involving BERT for binary detection of sensitive data. We use two parallel classification frameworks: one that takes the user's emotional state into account and the other for the detection of sensitive data in tweets. Consecutively, we identify individual cases of correlation between the two. We bring the two classifiers together to interpret the changes in both factors over time during a conversation between individuals. Variations were found with respect to the kinds of private information revealed in different states. Our results show that being in negative emotional states, such as sadness, anger or fear, leads to higher privacy leakage than otherwise. Manasi Mittal, Muhammad Rizwan Asghar, Arvind K. Tripathi |
TrustCom | 2 |
| 2020 | Analysing performance issues of open-source intrusion detection systems in high-speed networks
Qinwen Hu, Se-Young Yu, Muhammad Rizwan Asghar |
J. Inf. Secur. Appl. | 3 |
| 2020 | Multi-CDN: Towards Privacy in Content Delivery NetworksabstractA Content Delivery Network (CDN) is a distributed system composed of a large number of nodes that allows users to request objects from nearby nodes. CDN not only reduces end-to-end latency on the user side but also offloads Content Providers (CPs), providing resilience against Distributed Denial of Service (DDoS) attacks. However, by caching objects and processing user requests, CDN providers could infer user preferences and the popularity of objects, thus resulting in information leakage. Unfortunately, such information leakage may result in loss of user privacy and reveal business-specific information to untrusted or compromised CDN providers. State-of-the-art solutions can protect the content of sensitive objects but cannot prevent CDN providers from inferring user preferences and the popularity of objects. In this work, we present a privacy-preserving encrypted CDN system to hide not only the content of objects and user requests, but also protect user preferences and the popularity of objects from curious CDN providers. We employ encryption to protect the objects and user requests in a way that both the CDNs and CPs can perform the search operations without accessing objects and requests in cleartext. Our proposed system is based on a scalable key management approach for multi-user access, where no key regeneration and data re-encryption are needed for user revocation. We have implemented a prototype of the system and show its practical efficiency. Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Black Box Attacks on Deep Anomaly DetectorsabstractThe process of identifying the true anomalies from a given set of data instances is known as anomaly detection. It has been applied to address a diverse set of problems in multiple application domains including cybersecurity. Deep learning has recently demonstrated state-of-the-art performance on key anomaly detection applications, such as intrusion detection, Denial of Service (DoS) attack detection, security log analysis, and malware detection. Despite the great successes achieved by neural network architectures, models with very low test error have been shown to be consistently vulnerable to small, adversarially chosen perturbations of the input. The existence of evasion attacks during the test phase of machine learning algorithms represents a significant challenge to both their deployment and understanding. Aditya Kuppa, Slawomir Grzonkowski, Muhammad Rizwan Asghar, Nhien-An Le-Khac |
ARES | 3 |
| 2019 | Trust-Based DoS Mitigation Technique for Medical Implants in Wireless Body Area NetworksabstractMedical implants are an important part of Wireless Body Area Networks (WBANs) and play an important role to monitor, diagnose, and control various medical conditions. These tiny sensors are injected inside human body to measure and communicate various vital signs of a human body. Since the information transmitted by implants is very sensitive and critical in nature, both availability and confidentiality of such information are of prime importance. A possible security threat in medical implants that can breach the availability of the medical implants is a Denial of Service (DoS) attack. In this work, we propose a solution to mitigate DoS attack in the Medical Implant Communication Service (MICS) network. We propose a three-level trust model for a MICS network based on its environment and couple a threshold of maximum allowed data rate to each environment. The simulation results show that DoS attacks can be seamlessly mitigated in many MICS settings. Muhammad Usman 0003, Muhammad Rizwan Asghar, Imran Shafique Ansari, Marwa Qaraqe |
ICC | 2 |
| 2019 | Cybersecurity in industrial control systems: Issues, technologies, and challenges
Muhammad Rizwan Asghar, Qinwen Hu, Sherali Zeadally |
Comput. Networks | 1 |
| 2019 | PrivICN: Privacy-preserving content retrieval in information-centric networking
César Bernardini, Samuel Marchal, Muhammad Rizwan Asghar, Bruno Crispo |
Comput. Networks | 3 |
| 2019 | Checking certificate revocation efficiently using certificate revocation guard
Qinwen Hu, Muhammad Rizwan Asghar, Nevil Brownlee |
J. Inf. Secur. Appl. | 2 |
| 2018 | Measuring IPv6 DNS Reconnaissance Attacks and Preventing Them Using DNS GuardabstractTraditional address scanning attacks mainly rely on the naive 'brute forcing' approach, where the entire IPv4 address space is exhaustively searched by enumerating different possibilities. However, such an approach is inefficient for IPv6 due to its vast subnet size (i.e., 264). As a result, it is widely assumed that address scanning attacks are less feasible in IPv6 networks. In this paper, we evaluate new IPv6 reconnaissance techniques in real IPv6 networks and expose how to leverage the Domain Name System (DNS) for IPv6 network reconnaissance. We collected IPv6 addresses from 5 regions and 100,000 domains by exploiting DNS reverse zone and DNSSEC records. We propose a DNS Guard (DNSG) to efficiently detect DNS reconnaissance attacks in IPv6 networks. DNSG is a plug and play component that could be added to the existing infrastructure. We implement DNSG using Bro and Suricata. Our results demonstrate that DNSG could effectively block DNS reconnaissance attacks. Qinwen Hu, Muhammad Rizwan Asghar, Nevil Brownlee |
DSN | 2 |
| 2018 | An Energy Consumption Model for WiFi Direct Based D2D CommunicationsabstractWiFi direct is a variant of Infrastructure mode WiFi, which is designed to enable direct Device-to-Device (D2D) communications between proximity devices. This new technology enables various proximity-based services such as social networking, multimedia content distribution, cellular traffic offloading, Internet of Things (IoT), and mission critical communications. However, energy consumption of battery-constrained devices remains a major concern in all the aforementioned applications. In this paper, we model energy consumption of the WiFi direct protocol, starting from device discovery to actual data transmissions for intra group D2D communications. We simulate a content distribution scenario in Matlab and analyze our model for the energy consumption of the devices. We argue that the energy spent in device discovery becomes significant in the case of small data sizes. In particular, we find that smaller data sizes, such as 100KB, cause the equal amount of energy to spend in both device discovery and data transmission phases, even when the device discovery time is very small. Muhammad Usman 0003, Muhammad Rizwan Asghar, Imran Shafique Ansari, Marwa Qaraqe, Fabrizio Granelli |
GLOBECOM | 2 |
| 2018 | PRIMA: Privacy-Preserving Identity and Access Management at Internet-ScaleabstractThe management of identities on the Internet has evolved from the traditional approach (where each service provider stores and manages identities) to a federated identity management system (where identity management is delegated to a set of identity providers). On one hand, federated identity ensures usability and provides economic benefits to service providers. On the other hand, it poses serious privacy threats to users as well as service providers. The current technology, which is prevalently deployed on the Internet, allows identity providers to track the user's behavior across a broad range of services. In this work, we propose PRIMA, a universal credential-based authentication system for supporting federated identity management in a privacy-preserving manner. Basically, PRIMA does not require any interaction between service providers and identity providers during the authentication process, thus preventing identity providers to profile users' behavior. Moreover, throughout the authentication process, PRIMA provides a mechanism for controlled disclosure of the users' private information. We have conducted comprehensive evaluations of the system to show the feasibility of our approach. Our performance analysis shows that an identity provider can process 1,426 to 3,332 requests per second when the key size is varied from 1024 to 2048-bit, respectively. Muhammad Rizwan Asghar, Michael Backes 0001, Milivoj Simeonovski |
ICC | 1 |
| 2018 | Towards Blockchain-Based Scalable and Trustworthy File SharingabstractIn blockchain-based systems, malicious behaviour can be detected using auditable information in transactions managed by distributed ledgers. Besides cryptocurrency, blockchain technology has recently been used for other applications, such as file storage. However, most of existing blockchain- based file storage systems can not revoke a user efficiently when multiple users have access to the same file that is encrypted. Actually, they need to update file encryption keys and distribute new keys to remaining users, which significantly increases computation and bandwidth overheads. In this work, we propose a blockchain and proxy re-encryption based design for encrypted file sharing that brings a distributed access control and data management. By combining blockchain with proxy re-encryption, our approach not only ensures confidentiality and integrity of files, but also provides a scalable key management mechanism for file sharing among multiple users. Moreover, by storing encrypted files and related keys in a distributed way, our method can resist collusion attacks between revoked users and distributed proxies. Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello |
ICCCN | 2 |
| 2018 | Preserving Access Pattern Privacy in SGX-Assisted Encrypted SearchabstractOutsourcing sensitive data and operations to untrusted cloud providers is considered a challenging issue. To perform a search operation, even if both the data and the query are encrypted, attackers still can learn which data locations match the query and what results are returned to the user. This kind of leakage is referred to as data access pattern. Indeed, using access pattern leakage, attackers can easily infer the content of the data and the query. Oblivious RAM (ORAM), Fully Homomorphic Encryption (FHE), and secure Multi- Party Computation (MPC) offer a higher level of security but incur high computation and communication overheads. One promising practical approach to process the outsourced data efficiently and securely is leveraging trusted hardware like Intel SGX. Recently, several SGX- based solutions have been proposed in the literature. However, those solutions suffer from side channel attacks, high overheads of context switching, or limited SGX memory. In this paper, we present an SGX-assisted scheme for performing search over encrypted data. Our solution protects access pattern against side channel attacks while ensuring search efficiency. It can process large databases without requiring any long-term storage on SGX. We have implemented a prototype of the scheme and evaluated its performance using a dataset of 1 million records. The equality query and range query can be completed in 11 and 40 milliseconds, respectively. Comparing with ORAM- based solutions, such as ObliDB, our scheme is more than 10x faster. Shujie Cui, Sana Belguith, Muhammad Rizwan Asghar, Giovanni Russello |
ICCCN | 4 |
| 2018 | Global perspectives on cybersecurity educationabstractGlobal cybersecurity crises have compelled universities to address the demand for educated cybersecurity professionals. As no shared framework for cybersecurity as an academic discipline exists, growthhas been unfocused and driven by training materials, which make it harder to create a common body of knowledge. An international perspective is still harder, as different nations use different criteria to define local needs. As a result, new programs entering this space are on their own to conceptualize, design, package and market their programs, as there is no globally accepted reference model for cybersecurity to allow employers or students to understand the extent of a given cybersecurity program. Allen S. Parrish, John Impagliazzo, Rajendra K. Raj, Henrique M. Dinis Santos, Muhammad Rizwan Asghar, Audun Jøsang, Teresa Susana Mendes Pereira, Vítor J. Sá, Eliana Stavrou |
ITiCSE | 5 |
| 2018 | SECOD: SDN sEcure control and data plane algorithm for detecting and defending against DoS attacksabstractAlthough the popularity of Software-Defined Networking (SDN) is increasing, it is also vulnerable to security attacks such as Denial of Service (DoS) attacks. Since in SDN, the control plane is isolated from the data plane, DoS attackers can easily target the control plane to impair the network infrastructure in addition to the data plane to degrade the user's Quality of Service (QoS). In our previous work, we introduced SECO, an SDN Secure Controller algorithm to detect and defend SDN against DoS attacks. Simulation results showed that SECO successfully defends SDN networks from DoS attacks. In this paper, we present SDN sEcure COntrol and Data Plane (SECOD), which is an improved version of SECO. Basically, SECOD introduces new triggers to detect and prevent DoS attacks in both control and data planes. Moreover, SECOD is implemented and tested using SDN-based hardware testbed, OpenFlow-based switch, and RYU controller to capture the dynamics of realistic hardware and software. The results show that SECOD successfully detects and effectively mitigates DoS attacks on SDN networks keeping data plane performance at 99.72% compared to a network not under attack. Song Wang 0020, Sathyanarayanan Chandrasekharan, Karina Mabell Gomez, Kandeepan Sithamparanathan, Akram Al-Hourani, Muhammad Rizwan Asghar, Giovanni Russello, Paul Zanna |
NOMS | 6 |
| 2018 | Teaching Cyber Security Using Competitive Software Obfuscation and Reverse Engineering ActivitiesabstractTeaching cyber security techniques can be challenging due to the complexity associated with building secure systems. The major issue is these systems could easily be broken if proper protection techniques are not employed. This requires students to understand the offensive approaches that can be used to breach security in order to better understand how to properly defend against cyber attacks. We present a novel approach to teaching cyber security in a graduate course using an innovative assessment task that engages students in both software obfuscation and reverse engineering of obfuscated code. Students involved in the activities gain an appreciation of the challenges in defending against attacks. Our results demonstrate a positive change in the students' perception during the learning process. Muhammad Rizwan Asghar, Andrew Luxton-Reilly |
SIGCSE | 1 |
| 2018 | A marketplace for efficient and secure caching for IoT applications in 5G networksabstractAs the communication industry is progressing towards fifth generation (5G) of cellular networks, the traffic it carries is also shifting from high data rate traffic from cellular users to a mixture of high data rate and low data rate traffic from Internet of Things (IoT) applications. Moreover, the need to efficiently access Internet data is also increasing across 5G networks. Caching contents at the network edge is considered as a promising approach to reduce the delivery time. In this paper, we propose a marketplace for providing a number of caching options for a broad range of applications. In addition, we propose a security scheme to secure the caching contents with a simultaneous potential of reducing the duplicate contents from the caching server by dividing a file into smaller chunks. We model different caching scenarios in NS-3 and present the performance evaluation of our proposal in terms of latency and throughput gains for various chunk sizes. Muhammad Usman 0003, Muhammad Rizwan Asghar, Imran Shafique Ansari, Fabrizio Granelli, Qammer H. Abbasi, Khalid A. Qaraqe |
WCNC | 2 |
| 2017 | P-McDb: Privacy-Preserving Search Using Multi-Cloud Encrypted DatabasesabstractSearchable Symmetric Encryption (SSE) allows users to execute encrypted queries over encrypted databases. A large number of SSE schemes have been proposed in the literature. However, most of them leak a significant amount of information that could lead to inference attacks. In this work, we propose an SSE scheme for a Privacy-preserving Multi-cloud encrypted Database (P-McDb), which aims at preventing inference attacks. P-McDb allows users to execute SQL-like queries in an efficient sub-linear manner without leaking search, access and size patterns. We have implemented a prototype of P-McDb and show its practical efficiency. Shujie Cui, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello |
CLOUD | 2 |
| 2017 | Secure and Practical Searchable Encryption: A Position Paper
Shujie Cui, Muhammad Rizwan Asghar, Steven D. Galbraith, Giovanni Russello |
ACISP (1) | 2 |
| 2017 | A Review of Privacy and Consent Management in Healthcare: A Focus on Emerging Data SourcesabstractThe emergence of New Data Sources (NDS) in healthcare is revolutionising traditional electronic health records in terms of data availability, storage, and access. Increasingly, clinicians are using NDS to build a virtual holistic image of a patients health condition. This research is focused on a review and analysis of the current legislation and privacy rules available for healthcare professionals. NDS in this project refers to and includes patient-generated health data, consumer device data, wearable health and fitness data, and data from social media. This project reviewed legal and regulatory requirements for New Zealand, Australia, the European Union, and the United States to establish the ground reality of existing mechanisms in place concerning the use of NDS. The outcome of our research is to recommend changes and enhancements required to better prepare for the ’tsunami’ of NDS and applications in the currently evolving data-driven healthcare area and precision or personalised health initiatives such as Precision Driven Health (PDH) in New Zealand. Muhammad Rizwan Asghar, TzeHowe Lee, Mirza Mansoor Baig, Ehsan Ullah, Giovanni Russello, Gillian Dobbie |
eScience | 1 |
| 2017 | Towards Energy Efficient Multi-Hop D2D Networks Using WiFi DirectabstractWiFi Direct is a new technology that enables direct Device-to Device (D2D) communication. This technology has a great potential to enable various proximity-based applications such as multimedia content distribution, social networking, cellular traffic offloading, mission critical communications, and Internet of Things (IoT). However, in such applications, energy consumption of battery-constrained devices is a major concern. In this paper, we propose a novel power saving protocol that aims at optimizing energy consumption and throughput of user devices by controlling the WiFi Direct group size and transmit power of the devices. We model a content distribution scenario in NS-3 and present the performance evaluation. Our simulation results demonstrate that even a small modification in the network configuration can provide a considerable energy gain with a minor effect on throughput. The observed energy saving can be as high as 1000% for a throughput loss of 12%. Muhammad Usman 0003, Muhammad Rizwan Asghar, Imran Shafique Ansari, Fabrizio Granelli, Khalid A. Qaraqe |
GLOBECOM | 2 |
| 2017 | Towards bootstrapping trust in D2D using PGP and reputation mechanismabstractDevice-to-Device (D2D) communication has emerged as a new technology, which minimizes data transmission in radio access networks by leveraging direct interaction between nearby mobile devices. D2D communication has a great potential in solving the capacity bottleneck problem of cellular networks by offloading cellular traffic of proximity-based applications to D2D links. This provides several benefits including, but are not limited to, lower transfer delays, higher data rates, and better energy efficiency. However, security in D2D communication, which is equally essential for the success of D2D communication in future networks, is a less investigated topic in literature. In this paper, we propose the combination of the PGP and reputation-based model to bootstrap trust in D2D environments. Our proposal aims at minimizing any suspicious connection with selfish users. Offloading cellular traffic to trusted D2D links provides significant throughput gain over the conventional cellular network. Our results show that the capacity gain can be as high as 133%. Muhammad Usman 0003, Muhammad Rizwan Asghar, Imran Shafique Ansari, Fabrizio Granelli |
ICC | 2 |
| 2017 | Privacy-Preserving Content Delivery NetworksabstractA Content Delivery Network (CDN) is a distributed system composed of a large number of nodes that allows users to request objects from nearby nodes. CDN not only reduces the end-to-end latency on the user side but also offloads Content Providers (CPs) providing resilience against Distributed Denial of Service (DDoS) attacks. However, by caching objects and processing users' requests, CDN service providers could infer user preferences and the popularity of objects, thus resulting in information leakage. Unfortunately, such information leakage may result in compromising users' privacy and reveal business-specific information to untrusted or potentially malicious CDN providers. State-of-the-art Searchable Encryption (SE) schemescan protect the content of sensitive objects but cannot preventthe CDN providers from inferring users' preferences and thepopularity of objects. In this work, we present a privacy-preserving encrypted CDN system not only to hide the content of objects and users' requests, but also to protect users' preferences and the popularity of objects from curious CDN providers. We encrypt the objects and user requests in a way that both the CDNs and CPs can perform the search operations without accessing those objects and requests in cleartext. Our proposed system is based on a scalable key management approach for multi-user access, where no key regeneration and data re-encryption are needed for user revocation. Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello |
LCN | 2 |
| 2017 | Long White Cloud (LWC): A Practical and Privacy-Preserving Outsourced Database
Shujie Cui, Muhammad Rizwan Asghar, Giovanni Russello |
WISTP | 3 |
| 2016 | SPARER: Secure Cloud-Proof Storage for e-Health ScenariosabstractWith the surge of data breaches, practitioner ignorance and unprotected hardware, secure information management in healthcare environments is becoming a challenging problem. In the context of healthcare systems, confidentiality of patient data is of particular sensitivity. For economic reasons, cloud services are spreading, but there is still no clear solution to the problem of truly secure data storage at a remote location. To tackle this issue, we first examine if it is possible to have a secure storage of healthcare data without fully relying on trusted third-parties, and without impeding system usability on the side of the caregivers. The novelty of this approach is that it offers a standard-based deployable solution tailored for healthcare scenarios, using cloud services, but where trust is shifted from the cloud provider to the healthcare institution. This approach is unlike state-of-the-art solutions: there are secure cloud storage solutions that insist on having no knowledge of the stored data, but we discovered that they still require too much trust to manage user credentials, these credentials actually give them access to confidential data. In the paper, we present SPARER as a solution to the secure cloud storage problem and discuss the trade-offs of our approach. Moreover, we look at performance benchmarks that can hint to the feasibility and cost of using off-the-shelf cryptographic tools as building blocks in SPARER. Gabriela Gheorghe, Muhammad Rizwan Asghar, Jean Lancrenon, Sankalp Ghatpande |
ARES | 2 |
| 2016 | Privacy-preserving Data Sharing in Portable CloudsabstractCloud storage is a cheap and reliable solution for users to share data with their contacts. However, the lack of standardisation and migration tools makes it difficult for users to migrate to another Cloud Service Provider (CSP) without losing contacts, thus resulting in a vendor lock-in problem. In this work, we aim at providing a generic framework, named PortableCloud, that is flexible enough to enable users to migrate seamlessly to a different CSP keeping all their data and contacts. To preserve privacy of users, the data in the portable cloud is concealed from the CSP by employing encryption techniques. Moreover, we introduce a migration agent that assists users in automatically finding a suitable CSP that can satisfy their needs. Clemens Zeidler, Muhammad Rizwan Asghar |
CLOSER (2) | 2 |
| 2016 | PROTECTOR: Privacy-preserving information lookup in content-centric networksabstractContent-Centric Networking (CCN) is an emerging paradigm that can anticipate growing demands of content delivery in coming years. The underlying architecture of the CCN enables users to search for content based on names. On one hand, this is a privacy-friendly feature that do not require source and destination addresses. On the other hand, semantically-rich names reveal sufficient information about users' preferences. Unfortunately, a curious CCN node may learn and sell sensitive information to third-parties, thus posing serious threats to users' privacy. In this paper, we present PROTECTOR that aims at protecting content names as well as content and allows a CCN network to add new users or remove existing ones without requiring any re-encryption of stored content and names. It is scalable and efficient as it incurs very limited overhead for required cryptographic operations. Our performance analysis reports that PROTECTOR can handle 34 and over 10 million requests per second at boundary and other CCN nodes, respectively. Muhammad Rizwan Asghar, César Bernardini, Bruno Crispo |
ICC | 1 |
| 2016 | Certificate Revocation Guard (CRG): An Efficient Mechanism for Checking Certificate RevocationabstractIn the Public Key infrastructure (PKI) model, digital certificates play a vital role in securing online communication. Communicating parties exchange and validate these certificates, the validation fails if a certificate has been revoked. In this paper we propose the Certificate Revocation Guard (CRG) to efficiently check certificate revocation while minimising bandwidth, latency and storage overheads. CRG is based on OCSP, which caches the status of certificates locally. CRG could be installed on the user's machine, at the organisational proxy or even at the ISP level. Compared to a naive approach (where a client checks the revocation status of all certificates in the chain on every request), CRG decreases the bandwidth overheads and network latencies by 95%. Using CRG incurs 69% lower storage overheads compared to the CRL method. Our results demonstrate the effectiveness of our approach to improve certificate revocation. Qinwen Hu, Muhammad Rizwan Asghar, Nevil Brownlee |
LCN | 2 |
| 2016 | iGenoPri: Privacy-preserving genomic data processing with integrity and correctness proofsabstractNowadays, governmental and non-governmental health organisations and insurance companies invest in integrating an individual's genetic information to their daily practices. In this paper, we focus on an emerging area of genome analysis, called Disease Susceptibility (DS), from which an individual's susceptibility to a disease is calculated by using her genetic information. Recent work by Danezis et al. [1] presents an approach for calculating DS in a privacy-preserving manner. However, the proposed solution has two drawbacks. First, it does not provide a mechanism to check the integrity of genomic data that is used to calculate the susceptibility and more importantly the computed result. Second, it lacks a mechanism to check the correctness of the performed DS test. In this paper, we present iGenoPri that aims at addressing both problems by employing the Message Authentication Code (MAC) and verifiable computing. Fatih Turkmen, Muhammad Rizwan Asghar, Yuri Demchenko |
PST | 2 |
| 2016 | CloudEFS: Efficient and secure file system for cloud storageabstractAlthough outsourcing data to the cloud has many advantages, cloud computing introduces new privacy and security requirements on how data is stored and accessed. To ensure data confidentiality, use of encryption is a common strategy. A problem with this strategy is that for large data it becomes difficult to access and update data, and to ensure data integrity and data provenance without decrypting all the data. The problem becomes severe when it comes to accessing and modifying large files using mobile devices with limited processing and bandwidth capabilities. In this paper, we present CloudEFS, a novel storage framework to efficiently access and update large encrypted data. A new cached hash algorithm enables efficient updates of data integrity and provenance information. CloudEFS provides improved privacy by hiding not only content but also metadata such as data size, file count, file structure and file history. Clemens Zeidler, Muhammad Rizwan Asghar |
PST | 2 |
| 2016 | 3DCrypt: Privacy-preserving Pre-classification Volume Ray-casting of 3D Images in the CloudabstractWith the evolution of cloud computing, organizations are outsourcing the storage and rendering of volume (i.e., 3D data) to cloud servers. Data confidentiality at the third-party cloud provider, however, is one of the main challenges. In this paper, we address this challenge by proposing â 3DCrypt â a modified Paillier cryptosystem scheme for multi-user settings that allows cloud datacenters to render the encrypted volume. The rendering technique we consider in this work is pre-classification volume ray-casting. 3DCrypt is such that multiple users can render volumes without sharing any encryption keys. 3DCryptâs storage and computational overheads are approximately 66.3 MB and 27 seconds, respectively when rendering is performed on a 256 × 256 × 256 volume for a 256×256 image space. Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello |
SECRYPT | 2 |
| 2016 | $2DCrypt$ : Image Scaling and Cropping in Encrypted DomainsabstractThe evolution of cloud computing and a drastic increase in image size are making the outsourcing of image storage and processing an attractive business model. Although this outsourcing has many advantages, ensuring data confidentiality in the cloud is one of the main concerns. There are state-of-the-art encryption schemes for ensuring confidentiality in the cloud. However, such schemes do not allow cloud datacenters to perform operations over encrypted images. In this paper, we address this concern by proposing 2DCrypt, a modified Paillier cryptosystem-based image scaling and cropping scheme for multi-user settings that allows cloud datacenters to scale and crop an image in the encrypted domain. To anticipate a high storage overhead resulted from the naive per-pixel encryption, we propose a space-efficient tiling scheme that allows tile-level image scaling and cropping operations. Basically, instead of encrypting each pixel individually, we are able to encrypt a tile of pixels. 2DCrypt is such that multiple users can view or process the images without sharing any encryption keys-a requirement desirable for practical deployments in real organizations. Our analysis and results show that 2DCrypt is INDistinguishable under Chosen Plaintext Attack secure and incurs an acceptable overhead. When scaling a 512×512 image by a factor of two, 2DCrypt requires an image user to download approximately 5.3 times more data than the un-encrypted scaling and need to work approximately 2.3 s more for obtaining the scaled image in a plaintext. Manoranjan Mohanty, Muhammad Rizwan Asghar, Giovanni Russello |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Oblivion: Mitigating Privacy Leaks by Controlling the Discoverability of Online Information
Milivoj Simeonovski, Fabian Bendun, Muhammad Rizwan Asghar, Michael Backes 0001, Ninja Marnau, Peter Druschel |
ACNS | 3 |
| 2014 | PIDGIN: privacy-preserving interest and content sharing in opportunistic networksabstractOpportunistic networks have recently received considerable attention from both industry and researchers. These networks can be used for many applications without the need for a dedicated IT infrastructure. In the context of opportunistic networks, content sharing in particular has attracted significant attention. To support content sharing, opportunistic networks often implement a publish-subscribe system in which users may publish their own content and indicate interest in other content through subscriptions. Using a smartphone, any user can act as a broker by opportunistically forwarding both published content and interests within the network. Unfortunately, opportunistic networks are faced with serious privacy and security issues. Untrusted brokers can not only compromise the privacy of subscribers by learning their interests but also can gain unauthorised access to the disseminated content. This paper addresses the research challenges inherent to the exchange of content and interests without: (i) compromising the privacy of subscribers, and (ii) providing unauthorised access to untrusted brokers. Specifically, this paper presents an interest and content sharing solution that addresses these security challenges and preserves privacy in opportunistic networks. We demonstrate the feasibility and efficiency of the solution by implementing a prototype and analysing its performance on smart phones. Muhammad Rizwan Asghar, Ashish Gehani, Bruno Crispo, Giovanni Russello |
AsiaCCS | 1 |
| 2013 | ESPOONERBAC: Enforcing security policies in outsourced environments
Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo |
Comput. Secur. | 1 |
| 2011 | ESPOON: Enforcing Encrypted Security Policies in Outsourced EnvironmentsabstractThe enforcement of security policies in outsourced environments is still an open challenge for policy-based systems. On the one hand, taking the appropriate security decision requires access to the policies. However, if such access is allowed in an untrusted environment then confidential information might be leaked by the policies. Current solutions are based on cryptographic operations that embed security policies with the security mechanism. Therefore, the enforcement of such policies is performed by allowing the authorised parties to access the appropriate keys. We believe that such solutions are far too rigid because they strictly intertwine authorisation policies with the enforcing mechanism. In this paper, we want to address the issue of enforcing security policies in an untrusted environment while protecting the policy confidentiality. Our solution ESPOON is aiming at providing a clear separation between security policies and the enforcement mechanism. However, the enforcement mechanism should learn as less as possible about both the policies and the requester attributes. Muhammad Rizwan Asghar, Mihaela Ion, Giovanni Russello, Bruno Crispo |
ARES | 1 |
| 2011 | Poster: ESPOONERBAC: enforcing security policies in outsourced environments with encrypted RBAC
Muhammad Rizwan Asghar, Giovanni Russello, Bruno Crispo |
CCS | 1 |