VLDB 2026 Research / reviewers in the wild / expert
Benjamin P. Turnbull
dblp:83/6246
· DBLP profile ↗
34ranked-venue papers
2as first author
16since 2021 · last 2026
0000-0003-0440-5032ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 2 first-author · 6 since 2021Computer networks · 9 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LGP: Layerwise Gradient Purify for Robust Federated Learning Against Poisoning AttacksabstractFederated learning (FL) has become a promising framework for collaborative model training on devices while preserving privacy. However, despite its significant potential, it faces notable cyber threats, such as poisoning attacks and codenamed Byzantine clients. These threats have the potential to significantly degrade the global model by jeopardizing the integrity of the collaborative model training process. Whilst previous research has addressed the detection and elimination of malicious gradients from Byzantine clients, it has also shown that model poisoning attacks can evade most statistical defence approaches relying on metrics such as median and distance. To address the challenge posed by poisoning attacks, we introduce a novel approach called Layerwise Gradient Purify (LGP), which aims to remove any harmful gradients before the global aggregation process. It is comprised of two closely-related stages. The first stage focuses on pruning gradients at the layer level using the Median Absolute Deviation (MAD) pruning criterion. In the second stage, statistical features are extracted from the pruned gradients layer-by-layer and then clustered into honest and malicious categories. The proposed methodology treats each layer of the model across all clients as a probability distribution, employing hierarchical clustering to differentiate between malicious and honest clusters. Moreover, we introduce a new innocent criterion for selecting honest clusters, relying on reputation scores and gradient deviations from the global model. Extensive experiments were conducted employing diverse deep learning models, including CNN, RNN, and MLP, across a spectrum of datasets, including Cifar-10, AG-News, MNIST and ToN-IoT. The experiments evaluated the resilience of state-of-the-art approaches against recently introduced attacks. The numerical results demonstrate that theLGPapproach is effective and superior. Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Zahir Tari |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | DT-BFL: Digital Twins for Blockchain-enabled Federated Learning in Internet of Things networksabstractSixth-generation (6G) wireless networks are set to transform the Internet of Things (IoT) by enabling faster, smarter, and more connected systems. These networks will bring together a wide range of devices, including cars, robots, industrial machines, and smartphones, to support edge intelligence and real-time decision-making. Federated learning (FL) supports this shift by allowing devices to collaboratively train models without sharing raw data, which helps to protect user privacy. Despite its advantages, FL faces significant security challenges, including poisoning attacks and Byzantine clients, both of which can compromise the training process and degrade the accuracy and reliability of the global model. Although existing methods can detect malicious updates, many advanced attacks still bypass statistical defenses relying on metrics such as median and distance. Thus, developing an FL system that ensures both reliable decision-making and privacy and security guarantees in IoT networks remains a significant challenge. This study introduces a Digital Twin-driven Blockchain-enabled Federated Learning (DT-BFL) framework designed for IoT networks. The framework creates a digital representation of the IoT environment to support secure and decentralized edge intelligence using blockchain and federated learning technologies. DT-BFL is built to detect and filter out potentially poisoned model updates from malicious participants. This is achieved through a new smart contract-enabled decentralized aggregation method called Local Updates Purify (LUP). LUP uses a two-stage filtering process: First, it applies Median Absolute Deviation (MAD) to initially remove outliers, then uses statistical features and clustering to separate honest from malicious updates before aggregating the global model. It also assigns a Trust Score (TS) to each participant based on how much their updates differ from the global model and then uses a genuine criterion to select honest clients by evaluating trust scores, update similarity, and deviation from the global model. Experimental results show that DT-BFL effectively defends against various poisoning attacks on datasets like MNIST, ToN-IoT, and CIFAR-10 using models such as CNN, MLP, ResNet, and DenseNet, and maintains high accuracy even when 50% of the clients are malicious. Using a permissioned blockchain further secures the system by enabling aggregation of the decentralized model and authentication of clients through smart contracts. The source code is available on https://github.com/UNSW-Canberra-2023/LUP . Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
Ad Hoc Networks | 3 |
| 2025 | BFL-SC: A blockchain-enabled federated learning framework, with smart contracts, for securing social media-integrated internet of things systems
Sara Salim, Nour Moustafa, Benjamin P. Turnbull |
Ad Hoc Networks | 3 |
| 2025 | Vulnerability defence using hybrid moving target defence in Internet of Things systemsabstractCyber threat actors are increasingly targeting networked assets and critical infrastructure, with the potential for major socioeconomic impacts. Moving target defence (MTD) is a cyber defence paradigm that creates constantly shifting attack surfaces (i.e., vulnerabilities). It intends to make it more difficult for cyber adversaries to exploit systems, thereby increasing costs and chances of detection. There is a lack of research into the efficiency of combined MTD techniques, especially regarding several types of security considerations like time, cost, and effort. This gap is particularly significant in the Internet of Things (IoT) context, where security problems arise from its heterogeneous architecture . Moreover, MTD may result in the overutilization of network and system resources to enhance cybersecurity. We present a Vulnerability Defence method to address this issue using the three-layer Temporal Hierarchical Attack Representation Model (3-layer-THARM). This approach overcomes this difficulty by evaluating the safety of aggregated network states, considering security metrics in each state and the accessibility of network nodes and edges. Using this model, we can recognize probable attack scenarios in the context of Internet of Things (IoT) systems, conduct a thorough security analysis of the IoT system using well-defined security metrics, and assess the effectiveness of various defence tactics. This feature inherently introduces an additional level of security for the system. Furthermore, this model showcases the ability to identify potential attack pathways and effectively mitigate the consequences of such attacks. Our analysis reveals a noteworthy trend: combining MTD techniques from different categories, such as shuffle and diversity, generally produces more favorable outcomes, including a lower probability of attack success, lower attack risk and higher attack cost. Mohammed Tanvir Masud, Marwa Keshk, Nour Moustafa, Benjamin P. Turnbull, Willy Susilo |
Comput. Secur. | 4 |
| 2024 | PEL: Privacy Embedded Learning in Smart Healthcare SystemsabstractThe widespread use of healthcare data for online medical diagnosis has been made possible by deep learning advancements. However, entrusting computation and storage to unreliable external medical servers introduces security and privacy concerns. As a result, developing trustworthy deep learning algorithms has attracted growing interest in defending against privacy concerns in patient data. Federated learning was developed to protect sensitive data privacy by allowing computation on the client side. Privacy leakage in the communication channel of healthcare systems, through inference, free-riding, Man-in-the-Middle, model poisoning, and gradient attacks, is still a crucial issue. To address this, we introduce an efficient Privacy Embedded Learning (PEL) method that trains machine learning models without compromising privacy. This PEL method addresses how machine learning models handle privacy issues by securing privacy at the patient end, at a medical server and in communication media. To balance privacy protection and model performance, PEL uses edge intelligence-enabled federated learning to defend Smart Healthcare Systems from privacy attacks by applying artificial noise functions and an iteration-based Conventional Neural Network (CNN) model. PEL also offers gradient encryption in federated learning to protect the derived model parameters as gradients on communication media to protect users' privacy without revealing user-sensitive information. We also integrated Federated Edge Aggregator (FEA) into the proposed PEL method to offer a lower overhead than peer mechanisms. We compare the proposed method with existing work and evaluate performance with well-known datasets: COVID-19 chest X-rays and MNIST. The performance is demonstrated by testing accuracy of about 92% and good privacy protection when safeguarding patient and healthcare provider data. Mahmuda Akter, Nour Moustafa, Benjamin P. Turnbull |
PST | 3 |
| 2024 | Experimental Demonstration of Risks and Influences of Cyber Attacks on Wireless Communication in MicrogridsabstractThe Microgrid allows for more efficient and lower-cost power provisions, and is therefore more flexible than traditional power ecosystems. However, the increasingly integrated nature of these systems into network and internet-connected IT systems also potentially makes them susceptible to cyber-attack. This paper examined different challenges related to the cyber attacks threatening wireless microgrid systems from the experimental view. Wireless communication and transmission methods are widely used for secondary control of energy re-sources. However, there are risks of cyber attacks during the communication process, such as Denial-of-Service (DoS) attacks. This paper reports the investigation of potential cyber attacks on wireless communications of microgrid systems. Furthermore, this paper evaluates the practical impacts of cybersecurity breaches targeting microgrid systems, with special attention to those in Australia. In brief, the main goal of this paper is to enhance the mitigation countermeasures for cyber attacks linked to wireless microgrid systems, thus guaranteeing reliable wireless communications within these systems. Zhibo Zhang 0002, Jiankun Hu, Hemanshu Roy Pota, Shabnam Kasra Kermanshahi, Benjamin P. Turnbull, Ernesto Damiani, Chan Yeob Yeun |
PST | 5 |
| 2024 | CNA-TCC: Campaign Network Attribute Based Thematic Campaign ClassificationabstractWith the emergence of social media and computing, many users have utilized social media platforms (SMPs) in communicating and sharing their interests and preferences. One critical challenge is that social media have been employed for propaganda and influence campaigns for various purposes, such as spreading fake news. SMPs generate vast amounts of data that demand machine learning (ML) capabilities to efficiently learn and infer influence campaigns. This study proposes an ML framework for the thematic campaign classification (TCC), assisting decision-makers in understanding the impacts of social media toward end-users and aiding the mitigation of their side effects. The proposed framework relies on a newly developed characterization that we have termed the campaign network attribute (CNA), which adopts representative network features for the effective TCC by neural networks. The proposed CNA-TCC framework was validated using Twitter and Instagram data sources. The proposed framework can achieve a classification precision in the range of 68%–90% for two campaigns. Also, it can identify a known campaign in generic social media data with a 60% precision. The empirical results indicated high-performance levels of the proposed CNA-TCC framework that can substantially reduce the search spaces for social influence campaigns on specific themes. The proposed CNA-TCC framework has the potential to be applied in real-world SMPs and to process their large-scale data, so as to effectively classify influence campaigns. Nathan Johnson, Benjamin P. Turnbull, Martin Reisslein, Nour Moustafa |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | A Blockchain-Enabled Explainable Federated Learning for Securing Internet-of-Things-Based Social Media 3.0 NetworksabstractSocial media (SM) 3.0 integrates SM platforms, such as Facebook and Twitter, with the Internet of Things (IoT), and has a great potential to change how we interact with mobile devices, online platforms, and the world around us. This integration with end users produces large-scale and heterogeneous data sources that demand machine learning (ML)-based data analytics for decision-making and to provide security against ML and data privacy attacks. The development of privacy-aware ML models within a federated learning (FL) ecosystem can empower an entire network to learn from data in a decentralized manner. In this article, we propose a differentially privacy blockchain-based explainable FL (DP-BFL) framework by harnessing the ever-evolving power of SM 3.0 networks. This framework permits any Internet empowered device to partake and contribute data to a global privacy preserved model. In this framework, participants will upload the differentially private local updates to the miners of blockchain, where the local updates will be evaluated and rewarded. The experimental results obtained from real-world datasets, namely, SM 3.0 and MNIST, demonstrated that the proposed framework could achieve high utility, enhanced privacy, and elevated efficiency. More Specifically, the experimental analysis of our proposed framework reveals the following two key properties. First, our proposed DP-BFL yields noticeable performance improvements in the applied learning models with high privacy and comparable utility levels, in terms of accuracy and f-measure metrics, to a standard FL and centralized learning approaches under the restriction of privacy preservation. Second, given a certain number of the malicious entities, DP-BFL allowed an enhanced recognition of users' preferences in the SM 3.0 dataset and precise prediction of images' class in the MNIST dataset while mitigating the impact of the malicious entities' poisoned updates. Moreover, as the proposed DP-BFL attains DP on the local model's update, it is considered the same as the standard FL-based setting, along with some kinds of privacy preservation on the uploaded model's updates. Sara Salim, Benjamin P. Turnbull, Nour Moustafa |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | RVE-PFL: Robust Variational Encoder-Based Personalized Federated Learning Against Model Inversion AttacksabstractFederated learning (FL) enables distributed joint training of machine learning (ML) models without the need to share local data. FL is, however, not immune to privacy threats such as model inversion (MI) attacks. The conventional FL paradigm often uses privacy-preserving techniques, and this could lead to a considerable loss in the model’s utility and consequently compromised by MI attackers. Seeking to address this limitation, this paper proposes a robust variational encoder-based personalised FL (RVE-PFL) approach that mitigates MI attacks, preserves model utility, and ensures data privacy. RVE-PFL comprises an innovative personalised variational encoder architecture and a trustworthy threat model-integrated FL method to autonomously preserve data privacy, and mitigate MI attacks. The proposed architecture seamlessly trains heterogeneous data at every client, while the proposed approach aggregates data at the server side and effectively discriminates against adversarial settings (i.e., MI); thus, achieving robustness and trustworthiness in real-time. RVE-PFL is evaluated on three benchmark datasets, namely: MNIST, Fashion-MNIST, and Cifar-10. The experimental results revealed that RVE-PFL achieves high accuracy level while preserving data and tuning adversarial settings. It outperforms Noising before Model Aggregation FL (NbAFL) with significant accuracy improvements of 8%, 20%, and 59% on MNIST, Fashion-MNIST, and Cifar-10, respectively. These findings reinforce the effectiveness of RVE-PFL in protecting against MI attacks while maintaining the model’s utility. The source code for RVE-PFL can be found on GitHub 1. Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | An explainable deep learning-enabled intrusion detection framework in IoT networksabstractAlthough the field of eXplainable Artificial Intelligence (XAI) has a significant interest these days, its implementation within cyber security applications still needs further investigation to understand its effectiveness in discovering attack surfaces and vectors. In cyber defence, especially anomaly-based Intrusion Detection Systems (IDS), the emerging applications of machine/deep learning models require the interpretation of the models' architecture and the explanation of models' prediction to examine how cyberattacks would occur. This paper proposes a novel explainable intrusion detection framework in the Internet of Things (IoT) networks. We have developed an IDS using a Short-Term Long Memory (LSTM) model to identify cyberattacks and explain the model's decisions. This uses a novel set of input features extracted by a novel SPIP (S: Shapley Additive exPlanations, P: Permutation Feature Importance, I: Individual Conditional Expectation, P: Partial Dependence Plot) framework to train and evaluate the LSTM model. The framework was validated using the NSL-KDD, UNSW-NB15 and TON_IoT datasets. The SPIP framework achieved high detection accuracy, processing time, and high interpretability of data features and model outputs compared with other peer techniques. The proposed framework has the potential to assist administrators and decision-makers in understanding complex attack behaviour. Marwa Keshk, Nickolaos Koroniotis, Nam Pham, Nour Moustafa, Benjamin P. Turnbull, Albert Y. Zomaya |
Inf. Sci. | 5 |
| 2023 | OQFL: An Optimized Quantum-Based Federated Learning Framework for Defending Against Adversarial Attacks in Intelligent Transportation SystemsabstractIntelligent transportation systems, especially Autonomous Vehicles (AVs), are emerging as a paradigm with the potential to change modern society. However, with this, there is a strong need to ensure the security and privacy of such systems. AV ecosystems depend on machine learning algorithms to autonomously control their operations. Given the amount of personal information AVs collect, coupled with the distributed nature of such ecosystems, there is a movement to employ federated learning algorithms to develop secure decision-making models. Although federated learning is a viable candidate for data privacy, it is vulnerable to adversarial attacks, particularly data poisoning attacks, where malicious vectors would be injected in the training phase. Additionally, hyperparameters play an important role in establishing an efficient federated learning model that can be resilient against adversarial attacks. In this paper, to address these challenges, we propose a novel Optimized Quantum-based Federated Learning (OQFL) framework to automatically adjust the hyperparameters of federated learning using various adversarial attacks in AV settings. This work is innovative in two ways: first, a quantum-behaved particle swarm optimization technique is used to update the hyperparameters of the learning rate, local and global epochs. Second, the proposed technique is utilized within a cyber defense framework to defend against adversarial attacks. The performance of the proposed framework was evaluated using two benchmark datasets: MINST and Fashion-MINST, where they include images that would be extracted from smart cameras of AVs. This framework is shown to be more resilient against various adversarial attacks compared with peer techniques. Waleed Yamany, Nour Moustafa, Benjamin P. Turnbull |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Data analytics of social media 3.0: Privacy protection perspectives for integrating social media and Internet of Things (SM-IoT) systems
Sara Salim, Benjamin P. Turnbull, Nour Moustafa |
Ad Hoc Networks | 2 |
| 2022 | Perturbation-enabled Deep Federated Learning for Preserving Internet of Things-based Social NetworksabstractFederated Learning (FL), as an emerging form of distributed machine learning (ML), can protect participants’ private data from being substantially disclosed to cyber adversaries. It has potential uses in many large-scale, data-rich environments, such as the Internet of Things (IoT), Industrial IoT, Social Media (SM), and the emerging SM 3.0. However, federated learning is susceptible to some forms of data leakage through model inversion attacks. Such attacks occur through the analysis of participants’ uploaded model updates. Model inversion attacks can reveal private data and potentially undermine some critical reasons for employing federated learning paradigms. This article proposes novel differential privacy (DP)-based deep federated learning framework. We theoretically prove that our framework can fulfill DP’s requirements under distinct privacy levels by appropriately adjusting scaled variances of Gaussian noise. We then develop a Differentially Private Data-Level Perturbation (DP-DLP) mechanism to conceal any single data point’s impact on the training phase. Experiments on real-world datasets, specifically the social media 3.0, Iris, and Human Activity Recognition (HAR) datasets, demonstrate that the proposed mechanism can offer high privacy, enhanced utility, and elevated efficiency. Consequently, it simplifies the development of various DP-based FL models with different tradeoff preferences on data utility and privacy levels. Sara Salim, Nour Moustafa, Benjamin P. Turnbull, Muhammad Imran Razzak |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2022 | Privacy-preserving big data analytics for cyber-physical systems
Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull |
Wirel. Networks | 4 |
| 2021 | A Deep Learning-based Penetration Testing Framework for Vulnerability Identification in Internet of Things EnvironmentsabstractThe Internet of Things (IoT) paradigm has displayed tremendous growth in recent years, resulting in innovations like Industry 4.0 and smart environments that provide improvements to efficiency, management of assets and facilitate intelligent decision making. However, these benefits are offset by considerable cybersecurity concerns that arise due to inherent vulnerabilities, which hinder IoT-based systems' Confidentiality, Integrity, and Availability. Security vulnerabilities can be detected through the application of penetration testing, and specifically, a subset of the information-gathering stage, known as vulnerability identification. Yet, existing penetration testing solutions can not discover zero-day vulnerabilities from IoT environments, due to the diversity of generated data, hardware constraints, and environmental complexity. Thus, it is imperative to develop effective penetration testing solutions for the detection of vulnerabilities in smart IoT environments. In this paper, we propose a deep learning-based penetration testing framework, namely Long Short-Term Memory Recurrent Neural Network-Enabled Vulnerability Identification (LSTM-EVI). We utilize this framework through a novel cybersecurity-oriented testbed, which is a smart airport-based testbed comprised of both physical and virtual elements. The framework was evaluated using this testbed and on real-time data sources. Our results revealed that the proposed framework achieves about 99% detection accuracy for scanning attacks, outperforming other four peer techniques. Nickolaos Koroniotis, Nour Moustafa, Benjamin P. Turnbull, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
TrustCom | 3 |
| 2021 | A Deep Blockchain Framework-Enabled Collaborative Intrusion Detection for Protecting IoT and Cloud NetworksabstractThere has been significant research in incorporating both blockchain and intrusion detection to improve data privacy and detect existing and emerging cyberattacks, respectively. In these approaches, learning-based ensemble models can facilitate the identification of complex malicious events and concurrently ensure data privacy. Such models can also be used to provide additional security and privacy assurances during the live migration of virtual machines (VMs) in the cloud and to protect Internet-of-Things (IoT) networks. This would allow the secure transfer of VMs between data centers or cloud providers in real time. This article proposes a deep blockchain framework (DBF) designed to offer security-based distributed intrusion detection and privacy-based blockchain with smart contracts in IoT networks. The intrusion detection method is employed by a bidirectional long short-term memory (BiLSTM) deep learning algorithm to deal with sequential network data and is assessed using the data sets of UNSW-NB15 and BoT-IoT. The privacy-based blockchain and smart contract methods are developed using the Ethereum library to provide privacy to the distributed intrusion detection engines. The DBF framework is compared with peer privacy-preserving intrusion detection techniques, and the experimental outcomes reveal that DBF outperforms the other competing models. The framework has the potential to be used as a decision support system that can assist users and cloud providers in securely migrating their data in a timely and reliable manner. Osama Al-Kadi, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 3 |
| 2020 | Privacy-Preserving Techniques for Protecting Large-Scale Data of Cyber-Physical SystemsabstractAs Cyber-Physical Systems (CPSs), such as power and gas networks, generate heterogeneous and large-scale data sources from devices and networks, they need efficient privacy-preserving techniques to protect data and systems from cyber attacks. To safeguard CPSs from potential cyber threats, it is vital to identify vulnerabilities of CPSs' components to prevent Advanced Persistent Threats (APTs) and protect their generated data using privacy-preserving techniques. This paper aims to review the current state of privacy-preserving techniques for protecting CPSs and their networks against cyber attacks. Concepts of Privacy preservation and CPSs are discussed, illustrating CPSs' components and how they could be hacked using cyber and physical hacking scenarios. Then, types of privacy preservation, including perturbation, authentication, machine learning (ML), cryptography and blockchain, are discussed to demonstrate how they would be applied to protect the original data in CPSs and their networks. Finally, we explain existing challenges, solutions and future research directions of privacy preservation in CPSs. Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull, Dinusha Vatsalan |
MSN | 4 |
| 2020 | Privacy-Encoding Models for Preserving Utility of Machine Learning Algorithms in Social MediaabstractSocial media has become a vital platform in our daily life, where users can interact with their friends and other people throughout the world. The vast data generated by these platforms is unique in its variety and sensitivity, and although it potentially has significant utility, but also the potential for misuse. Although social media providers apply some existing privacy techniques, such as encryption and anonymization, the techniques cannot achieve a solid level of data privacy while maintaining the highest level of data utility. This paper proposes new Privacy-Encoding (PE) models that contain two-levels of data privacy: 1) data perturbation-based encoding techniques, and 2) data normalization-based scaling techniques. The data perturbation-based encoding techniques involve label encoder and one-hot encoder ones, while data normalization-based scaling techniques include min-max and z-score normalization ones. The aim of the two-levels is to transform original data into perturbed data, along with balancing the high level of data utility using machine learning algorithms. To evaluate the data utility, the proposed models are applied on the adult dataset as well as a simulated social media dataset and the accuracy of the results is compared with several machine learning algorithms. The experiment results reveal that the models could achieve high privacy and utility levels in terms of variance, accuracy and f-measure metrics. Sara Salim, Nour Moustafa, Benjamin P. Turnbull |
TrustCom | 3 |
| 2020 | An Ontological Graph Identification Method for Improving Localization of IP Prefix Hijacking in Network SystemsabstractIP prefix hijacking continues to be a pervasive cyber security threat to the core internet routing infrastructure. The data security of multiple cloud-based services is also susceptible to these threats, due to the high dependency on traditional routing protocols. Although a number of hijacking detection techniques have been recently proposed, no existing system has effectively addressed the problem of detecting malicious transit Autonomous System (AS) services in any detected hijacking occurrences. The ability to locate and isolate malicious services is critical for conducting a necessary mitigation strategy at an early stage, to minimise the impact of the attack, to restore cloud services quickly. In this paper, we propose an effective real-time processing method, so-called Ontological Graph Identification (OGI), for detecting IP prefix hijacking of nodes and suspicious transit nodes caused by the hijacked nodes through ASs. The proposed method is evaluated using the two public datasets of RIPE RIS and RouteView. Experimental results revealed improved performance for the detection of malicious transit nodes compared with peer techniques. It is, therefore, shown that the proposed method has utility in automating the process of investigating nodes with suspicious activities in real network systems. Osama Al-Kadi, Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | A Privacy-Preserving-Framework-Based Blockchain and Deep Learning for Protecting Smart Power NetworksabstractModern power systems depend on cyber-physical systems to link physical devices and control technologies. A major concern in the implementation of smart power networks is to minimize the risk of data privacy violation (e.g., by adversaries using data poisoning and inference attacks). In this article, we propose a privacy-preserving framework to achieve both privacy and security in smart power networks. The framework includes two main modules: a two-level privacy module and an anomaly detection module. In the two-level privacy module, an enhanced-proof-of-work-technique-based blockchain is designed to verify data integrity and mitigate data poisoning attacks, and a variational autoencoder is simultaneously applied for transforming data into an encoded format for preventing inference attacks. In the anomaly detection module, a long short-term memory deep learning technique is used for training and validating the outputs of the two-level privacy module using two public datasets. The results highlight that the proposed framework can efficiently protect data of smart power networks and discover abnormal behaviors, in comparison to several state-of-the-art techniques. Marwa Keshk, Benjamin P. Turnbull, Nour Moustafa, Dinusha Vatsalan, Kim-Kwang Raymond Choo |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset
Nickolaos Koroniotis, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull |
Future Gener. Comput. Syst. | 4 |
| 2019 | An Ensemble Intrusion Detection Technique Based on Proposed Statistical Flow Features for Protecting Network Traffic of Internet of ThingsabstractInternet of Things (IoT) plays an increasingly significant role in our daily activities, connecting physical objects around us into digital services. In other words, IoT is the driving force behind home automation, smart cities, modern health systems, and advanced manufacturing. This also increases the likelihood of cyber threats against IoT devices and services. Attackers may attempt to exploit vulnerabilities in application protocols, including Domain Name System (DNS), Hyper Text Transfer Protocol (HTTP) and Message Queue Telemetry Transport (MQTT) that interact directly with backend database systems and client-server applications to store data of IoT services. Successful exploitation of one or more of these protocols can result in data leakage and security breaches. In this paper, an ensemble intrusion detection technique is proposed to mitigate malicious events, in particular botnet attacks against DNS, HTTP, and MQTT protocols utilized in IoT networks. New statistical flow features are generated from the protocols based on an analysis of their potential properties. Then, an AdaBoost ensemble learning method is developed using three machine learning techniques, namely decision tree, Naive Bayes (NB), and artificial neural network, to evaluate the effect of these features and detect malicious events effectively. The UNSW-NB15 and NIMS botnet datasets with simulated IoT sensors' data are used to extract the proposed features and evaluate the ensemble technique. The experimental results show that the proposed features have the potential characteristics of normal and malicious activity using the correntropy and correlation coefficient measures. Moreover, the proposed ensemble technique provides a higher detection rate and a lower false positive rate compared with each classification technique included in the framework and three other state-of-the-art techniques. Nour Moustafa, Benjamin P. Turnbull, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 2 |
| 2018 | Mission-Centric Automated Cyber Red TeamingabstractCyberspace is ubiquitous and is becoming increasingly critical to many societal, commercial, military, and national functions as it emerges as an operational space in its own right. Within this context, decision makers must achieve mission continuity when operating in cyberspace. Suneel Randhawa, Benjamin P. Turnbull, Joseph Yuen, Jonathan Dean |
ARES | 2 |
| 2018 | Volatile Memory Forensics Acquisition Efficacy: A Comparative Study Towards Analysing Firmware-Based RootkitsabstractFirmware-based malware is an emerging threat with few obvious mechanisms for detection. There have been multiple cases where the presence of firmware-based malware has been confirmed or strongly suspected, and current mitigations strategies have little or no recourse. Volatile memory forensics may be one of the few technologies that can be employed to detect the presence of modified firmware, through ROM shadowing. However, the majority of volatile memory forensic tools were not designed with this use-case in mind and may not be suited to the capture of protected memory regions. This work performs experimental analysis to determine which, if any, memory acquisition tools are able to collect evidence pertaining to firmware-based rootkits or malware. Jacob Taylor, Benjamin P. Turnbull, Gideon Creech |
ARES | 2 |
| 2017 | Generating realistic intrusion detection system dataset based on fuzzy qualitative modelingabstractPrior to deploying any intrusion detection system, it is essential to obtain a realistic evaluation of its performance. However, the major problems currently faced by the research community is the lack of availability of any realistic evaluation dataset and systematic metric for assessing the quantified quality of realism of any intrusion detection system dataset. It is difficult to access and collect data from real-world enterprise networks due to business continuity and integrity issues. In response to this, in this paper, firstly, a metric using a fuzzy logic system based on the Sugeno fuzzy inference model for evaluating the quality of the realism of existing intrusion detection system datasets is proposed. Secondly, based on the proposed metric results, a synthetically realistic next generation intrusion detection systems dataset is designed and generated, and a preliminary analysis conducted to assist in the design of future intrusion detection systems. This generated dataset consists of both normal and abnormal reflections of current network activities occurring at critical cyber infrastructure levels in various enterprises. Finally, using the proposed metric, the generated dataset is analyzed to assess the quality of its realism, with its comparison with publicly available intrusion detection system datasets for verifying its superiority. Waqas Haider, Jiankun Hu, Jill Slay, Benjamin P. Turnbull, Yi Xie 0002 |
J. Netw. Comput. Appl. | 4 |
| 2015 | Visual analytics for cyber red teamingabstractOur team is currently developing an Automated Cyber Red Teaming system that, when given a model-based capture of an organisation's network, uses automated planning techniques to generate and assess multi-stage attacks. Specific to this paper, we discuss our development of the visual analytic component of this system. Through various views that display network attacks paths at different levels of abstraction, our tool aims to enhance cyber situation awareness of human decision makers. Joseph Yuen, Benjamin P. Turnbull, Justin Hernandez |
VizSEC | 2 |
| 2010 | The 'Explore, Investigate and Correlate' (EIC) Conceptual Framework for Digital Forensics Information VisualisationabstractEstablishing effective and novel techniques that are able to represent digital evidence in an efficient and understandable manner to investigators is a significant challenge within the digital forensics domain. Current tools and techniques do not scale well with the increasing volumes of evidence required for analysis. This paper defines a high-level conceptual framework to address issues surrounding scalability and comprehension of digital evidence. The aim of the Explore, Investigate and Correlate (EIC) framework is to provide a set of streamlined processes and tasks that enable digital evidence to be presented in a manner that can be rapidly understood, easily focused and to minimize the overall workload of a forensic analyst. Grant Osborne, Benjamin P. Turnbull, Jill Slay |
ARES | 2 |
| 2009 | Enhancing Computer Forensics Investigation through Visualisation and Data ExploitationabstractThis paper focuses on establishing the need for new architectures on which to build visualisation systems that enhance computer forensic investigation of digital evidence. The issues surrounding processing of large quantities of digital evidence are established. In addition, the current state of visualisation and data analysis techniques for computer forensics are highlighted. This paper suggests need for new visualisation techniques in order to display data in familiar visual forms that facilitate efficient insight gaining into digital evidence. Visualisations techniques also require a source of processed data that contains context relevant information to present to an investigator. To this end this paper introduces the notion of data exploitation as a way to describe techniques that provide opportunistic data analysis across multiple sources of digital evidence. Data exploitation techniques provide normalisation techniques, event correlation, relationship extraction and investigative domain knowledge processing to occur across a set of evidence. This enables a visual representation of digital evidence to highlight relationships and events across many data sources, support an investigator throughout the entire data analysis process and enable an investigator to focus on the context of the current crime. Grant Osborne, Benjamin P. Turnbull |
ARES | 2 |
| 2009 | The Anatomy of Electronic Evidence - Quantitative Analysis of Police E-Crime DataabstractBy understanding the past and present, the future can be predicted. This work seeks to understand how an Australian policing agency is currently receiving and analyzing sources of electronic evidence in the investigation of criminal activity. It shows how many devices are received, what kinds of device make up each analysis job, and for investigation into which crimes. From this, trends and workloads may be understood and future investments in equipment and research direction can be decided. The outcomes of this work may also allow for strategies to maximize training to non-technical staff and highlight investigative areas that may benefit from more use of electronic evidence. Finally, charting the trends in how commonly different electronic devices are analysed may allow for better handling of crime scenes and expand what is collected for different crime types. This work seeks to understand which types of crime are making most use of electronic evidence sources, to prepare for future changes in the discipline. Benjamin P. Turnbull, Barry Blundell |
ARES | 1 |
| 2009 | Acer Aspire One Netbooks: A Forensic ChallengeabstractNetbooks, the smallest laptop devices, are ironically the largest market segment, based on sales in the last year. These are light-weight, cheap, and designed for the limited tasks that rely on the internet. Given the large user base of these devices, it is inevitable that they will be used criminally. This is an extension on the fact that all technologies are able to be used criminally and will be, as they become part of larger society. This work seeks to understand the forensic implications of the Asus Aspire One, one of the most popular Netbooks, looking at both the forensic acquisition and analysis of the device. Amrit Pal Singh, Michael K. Lavine, Benjamin P. Turnbull, Trupti Shiralkar |
COMPSAC (2) | 3 |
| 2009 | Towards a Formalization of Digital Forensics
Jill Slay, Yi-Chi Lin, Benjamin P. Turnbull, Jason Beckett, Paul Lin |
IFIP Int. Conf. Digital Forensics | 3 |
| 2008 | Improving the Analysis of Lawfully Intercepted Network Packet Data Captured for Forensic AnalysisabstractLawful interception of a suspects’ personal Internet communications can be a very effective evidence collection mechanism for use in criminal investigations. Once a lawful interception warrant has been obtained, software applications known as packet sniffers are used to capture all network packets being sent to and from a suspect’s personal computer. Existing packet sniffer and protocol analyser applications, both open-source and commercial, have limitations in their usefulness in criminal investigations. This research outlines a process and framework, the Highly Extensible Network Packet Analysis (HENPA) framework, which takes the output of a packet sniffer and processes the data to extract potential forensic evidence. Joshua Broadway, Benjamin P. Turnbull, Jill Slay |
ARES | 2 |
| 2008 | Wi-Fi Network Signals as a Source of Digital Evidence: Wireless Network Forensicsabstract802.11-based wireless networking has significantly altered the networking means and topology for cities, offices, homes and coffee shops over the last five years. A second generation of wireless devices has extended what was once a computer-to-computer protocol into the area of embedded functional devices. Accompanying this widespread usage is the presence of crime; the more popular technology, the more opportunity exists for its misuse. This work studies the 802.11-based wireless networking environment from a forensic computing perspective. It seeks to understand the current state of wireless misuse: present misuses; potential forms of misuse involving 802.11-based wireless networks; and current tools and techniques used in its identification, containment and analysis. The research highlights the lack of current tools and procedures for forensic computing investigations that are able to effectively handle the presence of wireless devices and networks, and that there are forms of misuse that may escape detection by forensic investigation teams. Benjamin P. Turnbull, Jill Slay |
ARES | 1 |
| 2008 | Extracting Evidence Using Google Desktop Search
Timothy Pavlic, Jill Slay, Benjamin P. Turnbull |
IFIP Int. Conf. Digital Forensics | 3 |