Priyadarsi Nanda

dblp:92/5218 · DBLP profile ↗
← Back
79ranked-venue papers
3as first author
39since 2021 · last 2026
0000-0002-5748-155XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 20 since 2021Systems, architecture and hardware · 21 · 2 first-author · 6 since 2021Computer networks · 10 · 3 since 2021Artificial intelligence and machine learning · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 DistillVFL: A Knowledge Distillation-enhanced Vertical Federated Learning framework for scalable cross-silo collaboration
abstract
Vertical Federated Learning (VFL) is a privacy-preserving distributed learning paradigm where parties with disjoint features collaboratively train a unified Machine Learning (ML) model without leaking private data. This approach effectively addresses medical data fragmentation, allowing organizations to build unified models even when regulations like GDPR or HIPAA prevent raw data sharing. However, VFL faces a critical scalability challenge due to its static architecture. Onboarding new participants typically requires costly system-wide retraining, demanding that all original participants remain online. This bottleneck limits the growth of real-world collaborative ecosystems. To address this, we propose DistillVFL, a novel framework leveraging Knowledge Distillation for efficient client onboarding. Our approach employs a teacher–student paradigm where a pre-trained multi-party “teacher” model transfers knowledge to a new “student” client. This approach allows original clients to remain offline, eliminating re-participation requirements and additional computational costs. We evaluate DistillVFL through extensive experiments on four diverse medical datasets. The results demonstrate that student clients can achieve performance comparable to the comprehensive teacher model while drastically reducing computational overhead. DistillVFL provides a practical, scalable solution to the client onboarding problem, facilitating more dynamic and adaptable VFL collaborations.
Bashair Alrashed, Priyadarsi Nanda, Dinh Thai Hoang, Osama Mohammed Dighriri, Amani Aldahiri, Saleh Alqahtani, Raddad Faqihi, Nojood Alghamdi
Future Gener. Comput. Syst.2
2026 Towards trustworthy cybersecurity: Reclassifying insider threat detection using SHAP
abstract
Explainable artificial intelligence methods remain critical for trustworthy insider threat detection, yet existing approaches lack systematic frameworks for validating explanation quality against domain expertise. This research presents a SHAP (SHapley Additive exPlanations) based reclassification framework that integrates exact Shapley value computation with domain knowledge mapping to enhance detection accuracy whilst enabling transparent analyst oversight. The framework introduces a threat directions mapping that systematically translates feature attributions into cybersecurity interpretations, achieving high alignment with security analyst assessments across 27 behavioural indicators. Human-in-the-loop reclassification guided by automated explanation quality assessment demonstrates practical feasibility for operational deployment. Experimental evaluations with the help of 316,250 CMU CERT instances yield substantial accuracy improvements and significant false positive reduction compared to baseline classification. Statistical validation through paired t-tests confirms highly significant improvements ( p = 0 . 0023 , Cohen’s d = 0 . 368 ). A thorough comparative analysis demonstrates the strengths of our scheme: LIME (Local Interpretable Model-agnostic Explanations) provides computational efficiency for real-time response, whilst SHAP delivers mathematical rigour supporting forensic analysis and regulatory compliance. This work advances trustworthy artificial intelligence in cybersecurity through mathematically rigorous explanation frameworks enabling confident human oversight without sacrificing detection performance.
Raddad Faqihi, Priyadarsi Nanda, Manoranjan Mohanty, Saleh Alqahtani, Bashair Alrashed
Future Gener. Comput. Syst.2
2025 Multilingual Model Enhancement Framework using a Human-Centered Approach for Arabic Spam Detection
abstract
Arabic spam detection remains a critical challenge in cybersecurity, due to the complexity of language and inadequate resources compared to those available for English. This research introduces a human-centered framework for Arabic spam classification, integrating behavioral insights from phishing vulnerability studies with advanced machine learning models. Building on our previous work for student phishing awareness and behavioral patterns, we have developed customized translation workflows and enhanced state-of-the-art detection techniques through the integration of human factors. Our enhanced models demonstrate a significant improvement in classification accuracy and a reduction in false positive rates. The results indicate that incorporating human perceptual elements not only bolsters technical performance but also enhances the real-world effectiveness of Arabic spam detection systems. This approach effectively bridges the gap between technical capability and practical deployment, providing a more robust solution for Arabic-language cybersecurity applications.
Saleh Alqahtani, Priyadarsi Nanda, Qiang Wu 0001, Raddad Faqihi, Bashair Alrashed
AICCSA2
2025 Protocol-Aware Hybrid Clustering for IoT: Adaptive Reconfiguration and Secure Communication with MQTT/CoAP Integration
abstract
The fast evolution of Internet of Things (IoT) is placing increased demands on network infrastructures to be versatile and robust, especially in dynamic, heterogeneous, and resource-limited environments. Existing cluster-based and communication protocols struggle with protocol rigidity, insufficient integrated security, and limited reconfigurability. This paper proposes a novel security-aware hybrid clustering framework integrating BIRCH-DBSCAN algorithms, MQTT/CoAP switching adaptively, and AES-128 encryption with session-based key rotation for end-to-end confidentiality. By featuring a three-layer architecture designed with autonomous cluster recovery, layered verification, and a reconfiguration system upon performance, energy, and mobility changes. Evaluated and tested on ContikiNG simulation, the approach provides $43.3 \%$ latency reduction, 22.8 % energy efficiency improvement, 99.91 % delivery reliability, and zero breaches over 39 adaptive switches with just $4.2 \%$ overhead. The results attest to the platform’s strength and viability for future IoT deployments for efficient and responsive communications in changing conditions.
Osama Mohammed Dighriri, Priyadarsi Nanda, Manoranjan Mohanty, Bashair Alrashed, Ibrahim Haddadi
AICCSA2
2025 A Scalable Framework for Insider Threat Detection: Session Modelling and Class Balancing with XGBoost
abstract
Insider threats remain a persistent challenge in cybersecurity due to the deceptive nature of malicious activities conducted under legitimate user accounts. This paper presents a session-based detection framework integrating SMOTE-IPF oversampling and XGBoost classification to address temporal context limitations and class imbalance in insider threat datasets. To mitigate the extreme class imbalance characteristic of insider threat datasets, the framework integrates SMOTE-IPF, an advanced oversampling technique that maintains minority class structure while reducing overfitting. The model, trained with a GPU-accelerated XGBoost classifier, achieves notable performance improvements: $50 \%$ recall for threat instances at the F1-optimal threshold, 99.995 % accuracy for normal activity, and only four false positives. An ROC-AUC of 0.9429 and an F1score of 0.5263 demonstrate the model’s effectiveness in balancing precision and recall. These results indicate the proposed approach can enhance threat identification while maintaining operational feasibility in high-stakes security environments.
Raddad Faqihi, Priyadarsi Nanda, Manoranjan Mohanty, Saleh Alqahtani, Bashair Alrashed
AICCSA2
2025 A Novel Scheme for Recommendation Unlearning Verification (RUV) Using Non-Influential Trigger Data
abstract
Machine unlearning has garnered widespread attention, due to various reasons, including privacy-preserving, model usability, and legal regulations. It requires model providers to unlearning users' data from models upon receiving unlearning request. Recommendation systems have also been extensively researched in the field of deep learning, particularly within the context of big data environments. However, little research can be found to verify the effectiveness of unlearning approach using pure tabular data-based recommendation scenario. In this paper, we propose a recommendation unlearning verification (RUV) scheme based on non-influential trigger data, which fills this gap. Users can use the recommendation rate for selected target items to determine whether the recommendation system complies with unlearning requests. Evaluation results on real datasets confirm the efficiency and effectiveness of our proposed RUV scheme.
Xiaocui Dang, Priyadarsi Nanda, Manoranjan Mohanty, Haiyu Deng
CCNC2
2025 LIME-Enhanced Insider Threat Detection for Distributed Security Systems
Raddad Faqihi, Priyadarsi Nanda, Manoranjan Mohanty, Saleh Alqahtani, Bashair Alrashed
ICA3PP (4)2
2025 QoSmart-IoT: Secure QoS-Based Reconfiguration and Protocol Adaptation for Hybrid Clustered IoT Systems in Constrained Environments
Osama Mohammed Dighriri, Priyadarsi Nanda, Manoranjan Mohanty, Bashair Alrashed, Ibrahim Haddadi
NPC (2)2
2025 PPVFL-SplitNN: Privacy-Preserving Vertical Federated Learning with Split Neural Networks for Distributed Patient Data
Bashair Alrashed, Priyadarsi Nanda, Hoang Dinh, Amani Aldahiri, Hadeel Alhosaini, Nojood Alghamdi
SECRYPT2
2025 Secure and Hybrid Clustering for IoT Networks: An Adaptive Dynamic Reconfigurability Approach
Osama Mohammed Dighriri, Priyadarsi Nanda, Manoranjan Mohanty, Ibrahim Haddadi
SECRYPT2
2025 HiFi-XAI: A Fidelity-Aware, LLM-Powered Framework for Trustworthy Intrusion Detection
abstract
The increasing deployment of complex "black box" AI models in anomaly-based Intrusion Detection Systems (IDS) for future networks has opened up a trust gap that requires human-interpretable explanations in order for analysts to feel confident in acting on alerts. Current approaches to Explainable AI (XAI), such as SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations), do not properly address the challenges inherent in the problem domain. These techniques fundamentally fail from a fidelity standpoint due to their incorrect assumption of independence between features that results in untrustworthy explanations, which are fundamentally based on correlated network data. We address these shortcomings by proposing HiFi-XAI, which leverages a new, novel framework to provide faithful and semantically rich explanations. HiFi-XAI introduces a model-agnostic Conditional Value Attribution Explanation (CVAE), a method based on probabilistic Shapley values that models feature dependencies to ensure explanations are derived from plausible data distributions. These high-fidelity attributions are then translated into actionable, natural-language narratives by a fine-tuned Large Language Model (LLM). We validate our framework through allaware scenario feature ablation studies on the CICIDS2017 and CICIOT2023 datasets. This demonstrates that CVAE consistently identifies more impactful features than SHAP and LIME across five anomaly-based IDS models. Furthermore, we deploy the HiFi-XAI to prove its practical feasibility and test it on a resource-constrained Raspberry Pi 4. Our work presents a complete, end-to-end solution for building trust in AI-driven IDS.
Avinash Awasthi, Pritam Vediya, Hemant Miranka, Ramesh Babu Battula, Priyadarsi Nanda
TrustCom5
2025 SecuRecNet-IoT: Adaptive Secure Reconfiguration and Session-Aware Communication in IoT Edge Networks
abstract
The security of Internet of Things (IoT) edge networks is often compromised by static schedules, infrequent credential renewal, and cryptographic mechanisms that operate independently of network reconfiguration. Existing approaches rarely integrate session-awareness, adaptive clustering, Quality of Service (QoS) control, and trust-based routing with coordinated cryptographic adaptation, leaving IoT deployments vulnerable to evolving threats. To address this gap, we propose SecuRecNet-IoT, a session-aware and reconfigurable security framework that couples event-triggered AES-128 key rotation with cluster reconfiguration. In a 61-node Contiki-NG testbed, 402 key rotations across 57 adaptation events were performed, sustaining forward secrecy with only 3.2% security overhead. The framework combines Balanced Iterative Reducing and Clustering using Hierarchies (BIRCH) with Density-Based Spatial Clustering of Applications with Noise (DBSCAN) to optimise trust propagation and resource efficiency, while autonomously renewing credentials based on key aging and validity. By embedding cryptographic agility directly into the reconfiguration process. Evaluation shows that our work improves secure session concurrency, reduces latency, increases throughput, and lowers energy use, all while preserving baseline QoS and performance. These findings highlight SecuRecNet-IoT as a practical, scalable solution for next-generation IoT edge deployments requiring both strong security and high efficiency.
Osama Mohammed Dighriri, Priyadarsi Nanda, Manoranjan Mohanty, Bashair Alrashed, Ibrahim Haddadi
TrustCom2
2024 Zero Trust for Intrusion Detection System: A Systematic Literature Review
Abeer Z. Alalmaie, Nazar Waheed, Mohrah Alalyan, Priyadarsi Nanda, Wenjing Jia, Xiangjian He
ICAART (3)4
2024 Incident Response Adaptive Metrics Framework
abstract
This paper introduces a novel, multi-dimensional approach to address the evolving challenges in cybersecurity incident response. Our proposed framework uniquely integrates adaptive metrics with a layered security model, providing organisations with a dynamic and context-sensitive tool for building robust response capabilities. We present an innovative integration of proactive threat hunting, real-time threat intelligence, and AI/ML analysis within a cohesive, adaptable structure-a combination not previously explored in incident response literature. This approach not only serves as a comprehensive baseline for managing and responding to incidents but also offers a comparative measure for organisations to continuously evaluate and enhance their cybersecurity postures. Through practical implementation scenarios and future prospects analysis, we demonstrate the framework's unique ability to adapt to the rapidly changing digital landscape, addressing critical gaps in current incident response strategies.
Muntathar Abid, Priyadarsi Nanda, Manoranjan Mohanty
SIN2
2024 Enhancing Phishing Resilience in Academia: The Mediating Role of Anti-Phishing Tools on Student Awareness and Behavior
abstract
Phishing attacks are a significant threat to cybersecurity, particularly among university students who are frequent targets due to their extensive online activities and limited cybersecurity awareness. This study explores the impact of various factors, including threat susceptibility, phishing avoidance behavior, and the use of anti-phishing tools, on students' awareness of phishing attacks. Using a quantitative approach, data were collected from 715 university students worldwide through a structured questionnaire. The findings reveal that while students exhibit a moderate level of awareness about phishing attacks, their reliance on anti-phishing tools remains insufficient. The study identifies a significant positive relationship between the use of anti-phishing tools and increased phishing awareness and avoidance behaviors. Additionally, the research highlights the mediating role of anti-phishing tools in enhancing students' cybersecurity awareness. The results underscore the importance of integrating educational programs and advanced anti-phishing tools to improve students' resilience against phishing attacks. Recommendations for enhancing cybersecurity education and practices among university students are also provided.
Saleh Mansor Alqahtani, Priyadarsi Nanda
SIN2
2024 Effects of Personal Characteristics on Phishing Awareness, Anti-Phishing Tool Usage, and Phishing Avoidance Behavior: A Structural Equation Modeling Approach
abstract
Phishing attacks are among the most prevalent cyber threats, often leading to financial losses, reputational damage, and personal identity crises. This study investigates university students' behavior towards phishing attacks, focusing on the relationship between phishing Awareness and phishing avoidance behavior. Additionally, it examines the moderating effects of gender, age, and qualification on the use of anti-phishing tools, phishing avoidance behavior, and phishing Awareness. Data were collected from 715 university students through a structured questionnaire employing a quantitative approach. The results revealed a strong positive relationship between students' Awareness of phishing attacks and their phishing avoidance behavior. The mediation analysis showed that phishing awareness significantly mediates the relationship between using anti-phishing tools and phishing avoidance behavior. Furthermore, significant differences were observed in phishing Awareness, avoidance behavior, and the use of anti-phishing tools based on gender and age groups. These findings highlight the importance of tailored cybersecurity education programs considering these demographic factors to enhance students' resilience against phishing attacks. It is recommended to develop targeted cybersecurity education programs that focus on increasing phishing awareness and promoting the use of anti-phishing tools among university students, with particular emphasis on addressing demographic differences. The study's findings suggest that improving phishing awareness and tailoring interventions based on gender, age, and educational background can significantly enhance students' ability to avoid phishing attacks, strengthening cybersecurity resilience.
Saleh Mansor Alqahtani, Priyadarsi Nanda
SIN2
2024 A Zero-Trust Framework Based on Machine Learning for Industrial Internet of Things
abstract
Controlling access to data is essential in ensuring data is only accessed by authorised and trusted users. For these reasons, zero-trust frameworks have been in the centre of interest in the past few years. Zero-Trust frameworks assume that users and systems have been compromised and deal with them as untrusted entities that require multiple levels of authorisation and security attributes to be compliant in order to be considered trusted. The most common zero trust frameworks use static thresholds to grant levels of access to systems which could introduce false positives and incorrect access privileges to systems/networks. This research paper proposes a machine-learning (ML)-based zero-trust framework that utilises an anomaly detection algorithm. The output of the anomalous detection would inform the observers the trustworthiness of systems in their environments. Moreover, performance, complexity and impact of our proposed scheme is compared against a static threshold zero-trust framework.
Adel Atieh, Priyadarsi Nanda, Manoranjan Mohanty
SIN2
2024 The Bell-LaPadula (BLP) Enterprise Security Architecture Model vs Inference Attacks
abstract
Protecting information flow, data and assets is paramount to every establishment. Therefore, enterprise security architecture design is essential in achieving this protection as it directly implements enterprise security policies. Existing research revealed that researchers have made little effort to investigate inference security challenges to enterprise security architecture design and to assess how the existing security architecture models fare against inference attacks. It was also discovered that existing security architecture models are too old and susceptible to inference attacks. Hence, this research explores a novel solution for designing effective enterprise security architecture and addressing inference attacks.
Dominic Ayamga, Priyadarsi Nanda, Manoranjan Mohanty
SIN2
2024 Recommendation System Model Ownership Verification via Non-Influential Watermarking
abstract
While deep learning-based recommendation systems have achieved great success, recommendation system models are also at serious risk of intellectual property infringement. Current model watermarking research faces significant challenges in terms of fidelity, invisibility, and efficiency. Additionally, existing model watermarking techniques are predominantly applied to image data, with limited applicability to tabular data. In this paper, we introduce an innovative watermarking framework designed to safeguard the ownership of recommendation system models. Specifically, we verify recommendation system model ownership by embedding a type of backdoor watermark into the training dataset, which does not affect model performance. We have conducted experiments on several classical datasets to validate the reliability and effectiveness of our approach.
Xiaocui Dang, Priyadarsi Nanda, Haiyu Deng, Manoranjan Mohanty
SIN2
2024 Comprehensive Security of SDN Controllers in NFVI-Based 5G Network
abstract
In the present world, Software-Defined Networks (SDN) is the developing technological environment that allows integrated control and splits the control plane from the data plane. It is essential to classify the attacks in SDN-based networks to improve security. Concomitantly, SDN-related networks are vulnerable to numerous attacks especially Distributed Denial of Service (DDoS) attacks which interrupt the data transmission and network data. To resolve this issue, various traditional researchers have attempted to attain attack detection, however, there is a lack in computational cost, accuracy rate, and Packet Delivery Ratio. To overcome the limitations, the proposed hybrid model employs a system creation model for encrypting data using ELGAMAL and ECC algorithms to strengthen data security. Furthermore, the present hybrid model incorporates the wrapper-based approach Sine Cosine hybrid optimization algorithm with Modified Particle Swarm Optimization (SCMPSO) for feature selection which is intended to improve the performance of the classification. Furthermore, it utilizes the XG Boost-Light Gradient-Boosting Machine (GBM) algorithm for attack classification. Accordingly, Extreme Gradient-Boosting (XG Boost) can handle the missing data, and the ensemble nature of XG Boost with multiple Decision trees (DT) combinations makes it challenging to finalize the prediction. To overcome the limitations of the XG Boost algorithm, the proposed model uses Light GBM. Correspondingly, the present method created a dataset using the Mininet tool. The efficacy of the proposed hybrid model is calculated with several evaluation metrics to analyze the performance. The proposed method is intended to contribute to SDN-based network development and is envisioned to contribute to attack detection mechanisms.
Asad Faraz Khan, Priyadarsi Nanda
SIN2
2024 Dynamic Network Slicing and Deep Learning Based Intrusion Detection System with Virtual Load Balancing in Edge Enabled SDN/NFV Based 5G Networks
abstract
In current times, network slicing in a 5G context is a significant study field. But it might be difficult to meet network slice requests' requirements. Network slices need to share limited resources; therefore energy efficiency and security are crucial. Additionally, it is essential to establish secured network slicing for Software-Defined Network/Network Function Virtualization (SDN/NFV). As attackers have developed to become more skilled and frequently use different attacking approaches, security is a crucial problem in network slicing. We address security, ineffective network slicing, and overloading using load balancing and Deep Learning (DL) based network slicing algorithms in edge enabled SDN/NFV assisted 5G settings in this research. Here, we mainly concentrate on secure and efficient network slicing in SDN/NFV assisted 5G systems. Initially, slicing of network is performed based on UniqueNet which includes lightweight convolutional layers that reduce the processing time and increase accuracy. For authentication of users, we employ the Improved Mersenne Twister (IMT) algorithm and role-based access control is performed using Improved Deep Q Network (ImDQN) algorithm for authorization purpose. Clustering is done by using k-means clustering (KMC) algorithm. Here, Cluster Head (CH) performed intrusion detection using Enhanced Bidirectional Generative Adversarial Network (E-BiGAN) algorithm. After detected intrusions, the Kangaroo-based IDS (KIDS) jump and send the notification to all the nodes in the CH. For efficient load balancing, we perform optimal switch selection using Dove Swarm Optimization (DSO). The performance of the suggested framework is then evaluated in terms of different metrics and compared with existing approaches to prove the efficacy of the proposed system.
Asad Faraz Khan, Priyadarsi Nanda
SIN2
2024 Comparative Analysis of Intrusion Detection Schemes in Internet of Things(IoT) Based Applications
abstract
Due to massive growth in IoT devices in recent years, security of these devices is a major concern. IoT applications span across a number of fields including but not limited to smart cities, intelligent agriculture systems, and the innovative industry. Despite its benefits, cybersecurity challenges have increased significantly in IoT environments. The lack of resource capacity and sophisticated security measurement exposes IoT devices to large number of recent attacks. A strong intrusion detection system (IDS) is the best way to secure IoT devices. Various studies have shown that the current IDS fails to detect modern malware in IoT environments. Some datasets do not have complex scenarios of attack. There are limitations of current datasets, or heterogeneous data of the IoT environment, such as KDD99, NLS_KDD, and UNSW _NB15. In addition, these datasets do not include an operating system and network monitoring audits. This paper comprehensively compares five machine-learning models on the recent EDGE-IIoT dataset. We examine these machine learning methods on Binary and Multiclass class IDS and the security challenges in managing current and future attacks in an IoT environment.
Farag El Zegil, Priyadarsi Nanda, Manoranjan Mohanty, Majed Alzahrani
SIN2
2024 A Dual Defense Design Against Data Poisoning Attacks in Deep Learning-Based Recommendation Systems
abstract
Deep learning is being extensively utilized across various domains, with deep learning-based recommendation systems gaining prominence due to their exceptional performance. However, these systems are vulnerable to data poisoning attacks, where adversaries introduce carefully crafted fake user ratings to compromise the integrity of the recommendation model. We propose a dual defense to address this threat. The first line of defense, termed active defense, preemptively reduces the system’s vulnerability to poisoning attacks by incorporating crafted regularization into the loss function. This approach diminishes the attacker’s impact while preserving system performance, thereby lowering the success rate of targeted attacks. To further enhance the system’s robustness, we introduce a Generative Adversarial Network (GAN) based detection model as a passive defense strategy to accurately identify and filter out poisoned data. Empirical evaluations on three distinct datasets demonstrate that our dual defense approach significantly enhances both the proactive defense and passive detection capabilities of recommendation systems, effectively countering data poisoning attacks.
Xiaocui Dang, Priyadarsi Nanda, Manoranjan Mohanty, Haiyu Deng
TrustCom2
2024 Differential privacy model for blockchain based smart home architecture
Amjad Qashlan, Priyadarsi Nanda, Manoranjan Mohanty
Future Gener. Comput. Syst.2
2024 Reciprocal Federated Learning Framework: Balancing incentives for model and data owners
abstract
In the evolving landscape of Web 3.0, 5G/6G, and real-world applications, federated learning faces unique challenges. Traditional incentive mechanisms struggle to address the need to motivate both data owners to provide high-quality data and model experts to optimize model performance. To navigate this complex scenario, we introduce the Reciprocal Federated Learning Framework (RFLF). This innovative approach fosters a fair and dynamic reward structure that incentivizes both high-quality data contributions and optimal model development. Extensive experiments on benchmark datasets demonstrate that the RFLF significantly enhances fairness and efficiency within federated learning. These results showcase the RFLF’s potential to transform data-driven technologies, promoting both efficiency and equitable outcomes.
Priyadarsi Nanda, Christy Jie Liang
Future Gener. Comput. Syst.2
2023 Why Zero Trust Framework Adoption has Emerged During and After Covid-19 Pandemic
Abeer Z. Alalmaie, Priyadarsi Nanda, Xiangjian He, Mohrah Saad Alayan
AINA (3)2
2023 FedBlockHealth: A Synergistic Approach to Privacy and Security in IoT-Enabled Healthcare Through Federated Learning and Blockchain
abstract
The rapid adoption of Internet of Things (IoT) devices in healthcare has introduced new challenges in preserving data privacy, security and patient safety. Traditional approaches need to ensure security and privacy while maintaining computational efficiency, particularly for resource-constrained IoT devices. This paper proposes a novel hybrid approach by combining federated learning and blockchain technology to provide a secured and privacy-preserved solution for IoT-enabled healthcare applications. Our approach leverages a public-key cryptosystem that provides semantic security for local model updates, while blockchain technology ensures the integrity of these updates and enforces access control and accountability. The federated learning process enables a secure model aggregation without sharing sensitive patient data. We implement and evaluate our proposed framework using EMNIST datasets, demonstrating its effectiveness in preserving data privacy and security while maintaining computational efficiency. The results suggest that our hybrid approach can significantly enhance the development of secure and privacy-preserved IoT-enabled healthcare applications, offering a promising direction for future research in this field.
Nazar Waheed, Ateeq Ur Rehman 0001, Anushka Nehra, Mahnoor Farooq, Nargis Tariq, Mian Ahmad Jan, Fazlullah Khan, Abeer Z. Alalmaie, Priyadarsi Nanda
GLOBECOM9
2023 C-Block: A Secure and Robust Framework for Authentication Handover in 5G HetNets based on Edge-enabled SDN/NFV Environments
abstract
The fifth-generation (5G) technology is one of the enabling technologies which is composed of heterogeneous services and offers extensive network coverage. The paradigm of Software Defined Networking (SDN) is widely juxtaposed with 5G Heterogeneous Networks (HetNets) as a control mechanism. But the combination of 5G HetNets and SDN is highly exploited by cyber attackers as there is several problems exist like unauthorized user participation, handover pitfalls, ineffective data plane management, and inaccurate flow investigation. To overcome the prevailing research gaps, we have proposed a C-Block method in which Network Functions Virtualization (NFV), consortium blockchain, and edge computing technologies are infused. The proposed framework encompasses three consecutive processes namely registration and authenticated handover, flow classification, and suspicious flow investigation. Initially, users are authenticated using Advanced Encryption System (AES) symmetric cipher algorithm to reduce unauthorized user participation. Then, only authenticated users are handover using a temporary ID to the optimal base station based on several parameters. In the second process, switches are clustered using an Improved K-Means (IKM) algorithm where only trusted switches are considered. After clustering, the cluster head keeps flows hierarchically and performs flow investigation. At this phase, CH classifies the flows into three classes based on flow features using Proximal Policy optimization (PPO) algorithm. In the third process, suspicious flows are investigated by the Hybrid Deep Learning Algorithm (HDLA). Here, flows are classified into two classes based on packet features. Finally, the illegitimate flow details are generated as a report for intimating the affected region with the help of a delegator. The proposed work is simulated using Network Simulator (NS-3.26) tool. The experimentation results show that the proposed work surpasses the existing works in terms of different performance metrics.
Asad Faraz Khan, Priyadarsi Nanda
IWCMC2
2023 ZT-NIDS: Zero Trust, Network Intrusion Detection System
Abeer Z. Alalmaie, Priyadarsi Nanda, Xiangjian He
SECRYPT2
2023 Uncovering Flaws in Anti-Phishing Blacklists for Phishing Websites Using Novel Cloaking Techniques
Wenhao Li 0007, Yongqing He, Saleh Mansor Alqahtani, Priyadarsi Nanda
SECRYPT5
2023 Anomaly Detection in Smart Grid Networks Using Power Consumption Data
Hasina Rahman, Priyadarsi Nanda, Manoranjan Mohanty, Nazim Uddin Sheikh
SECRYPT2
2023 FCH, an incentive framework for data-owner dominated federated learning
Priyadarsi Nanda, Christy Jie Liang, Xiangjian He
J. Inf. Secur. Appl.2
2023 Enabling secure lightweight mobile Narrowband Internet of Things (NB-IoT) applications using blockchain
Vamshi Sunku Mohan, Sriram Sankaran, Priyadarsi Nanda, Krishnashree Achuthan
J. Netw. Comput. Appl.3
2022 Hybrid blockchain-based Authentication Handover and Flow Rule Validation for Secure Software Defined 5G HetNets
abstract
5G networks provide high data rates, high bandwidth, high coverage, and low latency compared to 4G networks. However, 5G includes some challenges such as privacy, network management, security. To overcome these issues, we propose SDN-5G HetNet (Software Defined Network-based 5G Heterogeneous network) model which addresses three issues such as handover authentication, flow rule validation, and hybrid intrusion detection and mitigation. Authentication is performed by Bio-Signature Validation Authentication mechanism for validating the users. User credentials are stored in the public blockchain for security. Handover is performed by the Dual Constraints Chaotic Radial Movement Optimization algorithm using User Entity and Access Network constraints. Flow rules are hashed and stored in the private blockchain for validation. Also, flow rules are monitored using Hidden Markov Model (HMM). Simulation is performed using NS-3.26 network simulator, which demonstrates our proposed work achieves better performance in terms of detection accuracy, handover delay, switch failure rate, packet loss rate, delay, and throughput compared to other state-of-the-art works.
Asad Faraz Khan, Priyadarsi Nanda
IWCMC2
2022 The Force of Compensation, a Multi-stage Incentive Mechanism Model for Federated Learning
Priyadarsi Nanda, Christy Jie Liang, Xiangjian He
NSS2
2022 Zero Trust-NIDS: Extended Multi-View Approach for Network Trace Anonymization and Auto-Encoder CNN for Network Intrusion Detection
abstract
As the enterprise networks are being constantly targeted by sophisticated cyber threats, Zero Trust Security has been suggested to address existing threats. Zero Trust Security models have been recently proposed for outsourcing network security monitoring to third-party analysts. Therefore, the current trends of security monitoring needs to shift to "Never Trust, Always Verify". There are no concerns about analysis accuracy, if a zero trust model is resistant against security attacks. In this paper, a modified multi-view approach is proposed to preserve privacy in network traces, emphasizing the challenges needed to be tackled. We then extend the multi-view approach for the features that are not in the known list of the analyzer and extend the partitioning methods to a more balanced approach. In addition, in order to send any data to the analyzer, we propose to use an Auto-Encoder Convolutional Neural Network, which has the ability to receive any type of input attributes for detecting intrusive behavior. Our proposed multi-view approach outperforms existing works and improves efficiency by improving indistinguishability and preserving privacy for any attributes. The proposed Intrusion Detection System also outperforms existing works by up to 1% higher accuracy without any need for feature engineering.
Abeer Z. Alalmaie, Priyadarsi Nanda, Xiangjian He
TrustCom2
2022 An Empirical Assessment of Security and Privacy Risks of Web-Based Chatbots
Nazar Waheed, Muhammad Ikram 0001, Saad Sajid Hashmi, Xiangjian He, Priyadarsi Nanda
WISE5
2021 Context-Aware Fog Computing Implementation for Industrial Internet of Things
abstract
The connectivity of devices has increased in the last decade enabling multiple innovative applications and solutions to serve industries and societies. This has solved multiple challenges and facilitated the improvement of methodologies and techniques adapted by humanity. One of the newly created paradigms that changed industries and technology is the Industrial Internet of Things (IIoT). IIoT is currently being adapted by various industries creating interactive supply chain ecosystems through the use of cloud computing. The size and distributions of these ecosystems introduced latency and Quality of Service (QoS) issues for edge devices sending data to the cloud. This research paper explores a paradigm called “Fog Computing” which aims to reduce the latency between IIoT devices and the cloud by deploying a “cloud-like” computing layer closer to the IIoT devices. In addition, a Context-Aware implementation of fog computing is proposed in this paper to provide the most optimised service to edge devices. Furthermore, this paper includes various experiments that examine the different context-awareness perspectives this paper proposes for fog computing. The results and outcomes of these experiments show reduction in latency and automated resource scaling from the use of context-awareness with fog computing over cloud computing for IIoT.
Adel Atieh, Priyadarsi Nanda, Manoranjan Mohanty
IWCMC2
2021 BuildSenSys: Reusing Building Sensing Data for Traffic Prediction With Cross-Domain Learning
abstract
With the rapid development of smart cities, smart buildings are generating a massive amount of building sensing data by the equipped sensors. Indeed, building sensing data provides a promising way to enrich a series of data-demanding and cost-expensive urban mobile applications. In this paper, as a preliminary exploration, we study how to reuse building sensing data to predict traffic volume on nearby roads. Compared with existing studies, reusing building sensing data has considerable merits of cost-efficiency and high-reliability. Nevertheless, it is non-trivial to achieve accurate prediction on such cross-domain data with two major challenges. First, relationships between building sensing data and traffic data are not unknown as prior, and the spatio-temporal complexities impose more difficulties to uncover the underlying reasons behind the above relationships. Second, it is even more daunting to accurately predict traffic volume with dynamic building-traffic correlations, which are cross-domain, non-linear, and time-varying. To address the above challenges, we design and implement BuildSenSys, a first-of-its-kind system for nearby traffic volume prediction by reusing building sensing data. Our work consists of two parts, i.e., Correlation Analysis and Cross-domain Learning. First, we conduct a comprehensive building-traffic analysis based on multi-source datasets, disclosing how and why building sensing data is correlated with nearby traffic volume. Second, we propose a novel recurrent neural network for traffic volume prediction based on cross-domain learning with two attention mechanisms. Specifically, a cross-domain attention mechanism captures the building-traffic correlations and adaptively extracts the most relevant building sensing data at each predicting step. Then, a temporal attention mechanism is employed to model the temporal dependencies of data across historical time intervals. The extensive experimental studies demonstrate that BuildSenSys outperforms all baseline methods with up to 65.3 percent accuracy improvement (e.g., 2.2 percent MAPE) in predicting nearby traffic volume. We believe that this work can open a new gate of reusing building sensing data for urban traffic sensing, thus establishing connections between smart buildings and intelligent transportation.
Xiaochen Fan, Chaocan Xiang, Chao Chen 0004, Panlong Yang, Liangyi Gong, Xudong Song, Priyadarsi Nanda, Xiangjian He
IEEE Trans. Mob. Comput.7
2020 Security and Privacy Implementation in Smart Home: Attributes Based Access Control and Smart Contracts
abstract
There has been wide range of applications involving smart home systems for user comfort and accessibility to essential commodities. Users enjoy featured home services supported by the IoT smart devices. These IoT devices are resource-constrained, incapable of securing themselves and can be easily hacked. Edge computing can provide localized computations and storage which can augment such capacity limitations for IoT devices. Furthermore, blockchain has emerged as technology with capabilities to provide secure access and authentication for IoT devices in decentralized manner. In this paper, we propose an authentication scheme which integrate attribute based access control using smart contracts with ERC-20 Token (Ethereum Request For Comments) and edge computing to construct a secure framework for IoT devices in Smart home system. The edge server provide scalability to the system by offloading heavier computation tasks to edge servers. We present system architecture and design and discuss various aspects related to testing and implementation of the smart contracts. We show that our proposed scheme is secure by thoroughly analysing its security goals with respect to confidentiality, integrity and availability. Finally, we conduct a performance evaluation to demonstrate the feasibility and efficiency of the proposed scheme.
Amjad Qashlan, Priyadarsi Nanda, Xiangjian He
TrustCom2
2020 Deep learning for intelligent traffic sensing and prediction: recent advances and future challenges
Xiaochen Fan, Chaocan Xiang, Liangyi Gong, Yuben Qu, Saeed Amirgholipour Kasmani, Priyadarsi Nanda, Xiangjian He
CCF Trans. Pervasive Comput. Interact.8
2020 Security, Trust and Privacy in Cyber (STPCyber): Future trends and challenges
Priyadarsi Nanda, Xiangjian He, Laurence T. Yang
Future Gener. Comput. Syst.1
2020 A hybrid encryption technique for Secure-GLOR: The adaptive secure routing protocol for dynamic wireless mesh networks
Ashish Nanda, Priyadarsi Nanda, Xiangjian He, Aruna Jamdagni, Deepak Puthal
Future Gener. Comput. Syst.2
2020 QASEC: A secured data communication scheme for mobile Ad-hoc networks
Muhammad Usman 0015, Mian Ahmad Jan, Xiangjian He, Priyadarsi Nanda
Future Gener. Comput. Syst.4
2020 Hybrid Tree-Rule Firewall for High Speed Data Transmission
abstract
Traditional firewalls employ listed rules in both configuration and process phases to regulate network traffic. However, configuring a firewall with listed rules may create rule conflicts, and slows down the firewall. To overcome this problem, we have proposed a Tree-rule firewall in our previous study. Although the Tree-rule firewall guarantees no conflicts within its rule set and operates faster than traditional firewalls, keeping track of the state of network connections using hashing functions incurs extra computational overhead. In order to reduce this overhead, we propose a hybrid Tree-rule firewall in this paper. This hybrid scheme takes advantages of both Tree-rule firewalls and traditional listed-rule firewalls. The GUIs of our Tree-rule firewalls are utilized to provide a means for users to create conflict-free firewall rules, which are organized in a tree structure and called 'tree rules'. These tree rules are later converted into listed rules that share the merit of being conflict-free. Finally, in decision making, the listed rules are used to verify against packet header information. The rules which have matched with most packets are moved up to the top positions by the core firewall. The mechanism applied in this hybrid scheme can significantly improve the functional speed of a firewall.
Thawatchai Chomsiri, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
IEEE Trans. Cloud Comput.3
2020 Vehicular networks with security and trust management solutions: proposed secured message exchange via blockchain technology
Nisha Malik, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu 0001
Wirel. Networks2
2019 A Novel Multi-Path Anonymous Randomized Key Distribution Scheme for Geo Distributed Networks
abstract
A major concern in distributed networks is the ability to provide acceptable levels of security. This is achieved by using encryption and authentication mechanisms that depend on encryption keys. However, given the ever-expanding nature of the network, it is difficult to keep setting up authorities that can aid the key- exchange process. This paper presents a novel solution to the challenge of exchanging keys of a large, distributed network without the need to set up additional authorities. The key-exchange scheme presented takes advantage of features such as packet anonymity, random selection and a multi- path approach for the exchange process. The paper also discusses the effectiveness of the proposed scheme against various threat scenarios.
Ashish Nanda, Priyadarsi Nanda, Mohammad S. Obaidat, Xiangjian He, Deepak Puthal
GLOBECOM2
2019 Efficient solution to the millionaires' problem based on asymmetric commutative encryption scheme
abstract
Abstract Secure multiparty computation is an important scheme in cryptography and can be applied in various real‐life problems. The first secure multiparty computation problem is the millionaires' problem, and its protocol is an important building block. Because of the less efficiency of public key encryption scheme, most existing solutions based on public key cryptography to this problem are inefficient. Thus, a solution based on the symmetric encryption scheme has been proposed. In this paper, we formally analyse the vulnerability of this solution, and propose a new scheme based on the decisional Diffie‐Hellman assumption. Our solution also uses 0‐encoding and 1‐encoding generated by our modified encoding method to reduce the computation cost. We implement the solution based on symmetric encryption scheme and our protocol. Extensive experiments are conducted to evaluate the efficiency of our solution, and the experimental results show that our solution can be much more efficient and be approximately 8000 times faster than the solution based on symmetric encryption scheme for a 32‐bit input and short‐term security. Moreover, our solution is also more efficient than the state‐of‐the‐art solution without precomputation and can also compare well with the state‐of‐the‐art protocol while the bit length of private inputs is large enough.
Meng Liu 0007, Priyadarsi Nanda, Shui Yu 0001
Comput. Intell.3
2019 Testbed evaluation of Lightweight Authentication Protocol (LAUP) for 6LoWPAN wireless sensor networks
abstract
Summary 6LoWPAN networks involving wireless sensors consist of resource starving miniature sensor nodes. Since secured authentication is one of the important considerations, the use of asymmetric key distribution scheme may not be a perfect choice. Recent research shows that Lucky Thirteen attack has compromised Datagram Transport Layer Security (DTLS) with Cipher Block Chaining (CBC) mode for key establishment. Even though EAKES6Lo and S3 K techniques for key establishment follow the symmetric key establishment method, they strongly rely on a remote server and trust anchor. Our proposed Lightweight Authentication Protocol (LAUP) used a symmetric key method with no preshared keys and comprised of four flights to establish authentication and session key distribution between sensors and Edge Router in a 6LoWPAN environment. Each flight uses freshly derived keys from existing information such as PAN ID (Personal Area Network IDentification) and device identities. We formally verified our scheme using the Scyther security protocol verification tool. We simulated and evaluated the proposed LAUP protocol using COOJA simulator and achieved less computational time and low power consumption compared to existing authentication protocols such as the EAKES6Lo and SAKES. LAUP is evaluated using real‐time testbed and achieved less computational time, which is supportive of our simulated results.
Annie Gilda Roselin, Priyadarsi Nanda, Surya Nepal, Xiangjian He
Concurr. Comput. Pract. Exp.2
2019 Editorial to the Special Issue on Recent Advances on Trust, Security and Privacy in Computing and Communications
abstract
With the rapid development and increasing complexity of computer systems and communication networks, user requirements for trust, security, and privacy are becoming more and more demanding. Therefore, there is a grand challenge that traditional security technologies and measures may not meet user requirements in open, dynamic, heterogeneous, mobile, wireless, and distributed computing environments. Thus, there is a strong need to build systems and networks in which various applications allow users to enjoy more comprehensive services while preserving trust, security, and privacy at the same time. As useful and innovative technologies, trusted computing and communications are attracting researchers with more and more attention. The scope of this special issue is broad and is representative of many important topics involving emerging technologies in the field of Trust, Security, Privacy, Forensics, and Data analytics. In addition, the articles selected through this special issue also present strong aspects on theoretical analysis, algorithms, and practical experience in their proposed schemes. The submissions to the Special Issue were significantly extended research papers from the 16th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (Trustcom 2017). This conference brings together researchers and practitioners around the world working on trusted computing and communications, with regard to trust, security, privacy, reliability, dependability, survivability, availability, and fault tolerance aspects of computer systems and networks. All the submissions for this special issue have been reviewed rigorously following the guidelines of Wiley Journal on Concurrency and Computation: Practice and Experience (CCPE). A majority of the reviewers represent expertise in their fields who provided high quality reviews for the manuscripts. The articles selected through a rigorous reviews process for this Special Issue are briefly presented in the rest of this guest editorial. The guest editors sincerely believe that this special issue on Trust, Security, and Privacy will be a great reading for the contemporary researchers worldwide. The guest editors would like to thank the editor-in-chief (EiC) Dr Geoffrey Fox of the Wiley Journal on Concurrency and Computation: Practice and Experience (CCPE) for the opportunity of this special issue. The guest editors are sincerely thankful to the many reviewers around the globe for their timely reviews without which this successful special issue would not have been possible. The guest editors thank the authors for their patience and dedication at all stages of the review process. The guest editors are also thankful to the Wiley production staffs for their help during the production of this special issue. Fault injection has been increasingly used both to attack software applications and to test system robustness. Detecting fault injection vulnerabilities has been approached with a variety of different but limited methods. Given-Wilson et al1 propose extension of a recently published general model checking–based process to detect fault injection vulnerabilities in binaries. This new extension makes the general process scalable to real-world implementations. The authors demonstrate their scheme by detecting vulnerabilities in different cryptographic implementations. Fault analysis of AEZ is based on AES using three 128-bit keys. Al Mahri et al2 analyzed AEZ 4.2 and investigated the fault issue showing all three 128-bit keys used in AEZ 4.2 can be uniquely retrieved using only three random valued single byte fault injections. Data publishing may suffer from privacy disclosures, especially, the case in transactional data such as web search and point of sales logs. Current potent privacy preserving mechanisms mainly focus on relational data. Bewong et al3 propose a new privacy metric for transactional data to prevent inference attacks. Their proposed scheme, Anony, ensures that the adversary learns no more about an intended victim than what is publicly available. In order to demonstrate the effectiveness of their scheme, the authors present empirical evaluation on three benchmark datasets. Jahan et al4 present selective read/write access to the outsourced data for clients using mobile devices supporting users from multiple domains. The authors use Ciphertext-Policy Attribute-based Encryption (CP-ABE) scheme that provides access control on encrypted outsourced data. The proposed scheme provides fine-grained read/write access to the users, accompanied with a lightweight signature scheme and computationally inexpensive user revocation mechanism suitable for resource-constrained mobile devices. Both theoretical analyses of the security protocol and experimental results measured from a real-world testbed strongly validate the proposed scheme. Yoking-proof scheme is a very useful mechanism in many IoT (Internet of Things) application areas such as health care and supply chain. However, existing yoking-proof scheme requires two or more rounds of communication to generate the yoking-proof. Sun et al5 investigate how to design the one-round yoking-proof scheme with computational efficiency. The scheme is designed with a new timestamp-based scheme for the RFID tag pair. The authors prove the security and privacy of the proposed scheme extending to more than two RFID tags along with one-round of communication to generate the yoking-proof. While Malware-based activities on recent years are slowing down, more and more sophisticated targeting malwares have been emerging. These new categories of Malwares share little or no common feature with traditional malware. Han et al6 present classifications of malicious tasks using decidable theory and prove that tasks performed by any software can be recursive and determinable. By establishing a mapping from software to task, they prove their proposition and demonstrate that presence of malwares in software is recursive. This issue would be incomplete without the article on IoT security. Secured authentication using 6LoWPAN networks is one of the important considerations among various IoT-based applications. Existing asymmetric key distribution scheme may not be a perfect choice as recent research shows that Lucky Thirteen attack has compromised Datagram Transport Layer Security (DTLS) with Cipher Block Chaining (CBC) mode for key establishment. Even though EAKES6Lo and S3 K techniques for key establishment follow the symmetric key establishment method, they strongly rely on a remote server and trust anchor. Baskaran et al7 present a Lightweight AUthentication Protocol (LAUP) using symmetric key method with no pre-shared keys between sensors and Edge Router in a 6LoWPAN environment. Their proposed scheme is formally verified using the Scyther security protocol verification tool and the protocol is implemented using COOJA simulator. Finally, the authors develop a Testbed to measure computation time and efficiency of LAUP scheme. The proposed scheme achieves less computational time and low power consumption compared to existing authentication protocols such as the EAKES6Lo and SAKES.
Priyadarsi Nanda, Deepak Puthal, Saraju P. Mohanty
Concurr. Comput. Pract. Exp.1
2019 A secure privacy preserving deduplication scheme for cloud computing
Yongkai Fan, Wei Liang 0005, Gang Tan, Priyadarsi Nanda
Future Gener. Comput. Syst.5
2019 Exploiting the Remote Server Access Support of CoAP Protocol
abstract
The constrained application protocol (CoAP) is a specially designed Web transfer protocol for use with constrained nodes and low-power networks. The widely available CoAP implementations have failed to validate the remote CoAP clients. Each CoAP client generates a random source port number when communicating with the CoAP server. However, we observe that in such implementations it is difficult to distinguish the regular packet and the malicious packet, opening a door for a potential off-path attack. The off-path attack is considered a weak attack on a constrained network and has received a less attention from the research community. However, the consequences resulting from such an attack cannot be ignored in practice. In this article, we exploit the combination of IP spoofing vulnerability and the remote server access support of CoAP is to be launch an off-path attack. The attacker injects a fake request message to change the credentials of the 6LoWPAN smart door keypad lock system. This creates a request spoofing vulnerability in CoAP, and the attacker exploits this vulnerability to gain full access to the system. Through our implementation, we demonstrated the feasibility of the attack scenario on the 6LoWPAN-CoAP network using smart door keypad lock. We proposed a machine learning (ML)-based approach to mitigate such attacks. To the best of our knowledge, we believe that this is the first article to analyze the remote CoAP server access support and request spoofing vulnerability of CoAP to launch an off-path attack and demonstrate how an ML-based approach can be deployed to prevent such attacks.
Annie Gilda Roselin, Priyadarsi Nanda, Surya Nepal, Xiangjian He, Jarod Wright
IEEE Internet Things J.2
2019 Secure authentication and load balancing of distributed edge datacenters
abstract
Edge computing is an emerging research area to incorporate cloud computing into edge network devices. An Edge datacenter, also referred to as EDC, processes data streams and user requests in real-time and is therefore used to decrease the latency and congestion in the network. EDC is usually setup as a distributed system and is accordingly placed between the cloud datacenter and the data source . These EDCs work as an intermediate layer in the fog hierarchy between IoT and Cloud datacenter. EDC’s are aided by load balancers, responsible for distributing the workload amongst multiple EDC, in order to optimize resource utilization and response time . The load balancers make sure that the workload is equally divided amongst the available EDCs to avoid over loading of some EDCs while other remain idle as this directly impacts the user response and real-time event detection . Given the fact that EDCs are deployed in remote environments, the need for secure authentication is of major importance. In this paper we propose a novel load balancing technique that enables EDC authentication as well as identification of idle EDCs for better load balancing. The proposed load balancing technique is also compared with existing approaches and proves to be more efficient in locating EDC’s with less workload. In addition to the improved efficiency, the proposed scheme also strengthens the security of the network by incorporating destination EDC authentication.
Deepak Puthal, Rajiv Ranjan 0001, Ashish Nanda, Priyadarsi Nanda, Prem Prakash Jayaraman, Albert Y. Zomaya
J. Parallel Distributed Comput.4
2018 CTOM: Collaborative Task Offloading Mechanism for Mobile Cloudlet Networks
abstract
Mobile cloud computing has emerged as a pervasive paradigm to execute computing tasks for capacity- limited mobile devices. More specifically, at the network edge, the resource-rich and trusted cloudlet system is acting as a 'data center in a box' to support compute-intensive mobile applications. The mobile cloudlets can provide in-proximity services by executing the workloads for nearby devices. Nevertheless, load balancing in mobile cloudlet network is of great importance, as it has a huge impact on task response time. Existing methods for cloudlet load balancing basically rely on the strategic placement or user cooperation. However, the above solutions require the global task load information from the whole network, which is costly in both communication and computation. To achieve more efficient and low-cost load balancing, we propose 'CTOM', a Collaborative Task Offloading Mechanism for mobile cloudlet networks. Our solution is based on the balls-and-bins theory and can balance the task load only requiring limited information. Extensive simulations and evaluation based on mobility trace demonstrate that, our CTOM outperforms the conventional random and proportional allocation schemes by reducing the task gaps among mobile cloudlets by 65% and 55% respectively. Meanwhile, CTOM's performance is close to that of the greedy algorithm but with much lower computing complexity.
Xiaochen Fan, Xiangjian He, Deepak Puthal, Shiping Chen 0001, Chaocan Xiang, Priyadarsi Nanda, Xunpeng Rao
ICC6
2018 User Relationship Classification of Facebook Messenger Mobile Data using WEKA
Amber Umair, Priyadarsi Nanda, Xiangjian He, Kim-Kwang Raymond Choo
NSS2
2018 A Sybil attack detection scheme for a forest wildfire monitoring application
Mian Ahmad Jan, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu 0001
Future Gener. Comput. Syst.2
2017 A framework for data security in cloud using collaborative intrusion detection scheme
abstract
Cloud computing offers an on demand, elastic, global network access to a shared pool of resources that can be configured on user demand. The advantages of cloud computing are lucrative for well-established organizations looking to reduce infrastructure cost overheads. However, the users are not quite confident in entrusting their data to the cloud due to security threats and risks perceived in the cloud domain. Issues involving privacy requirements for the cloud and best practices in the cloud are suggested in this paper. Although the cloud provider ensures security in the cloud yet the flow of data, storage location, data computing process and security breaches are not transparent to the cloud customer. This distrust and lack of control on data is a major hindrance for potential cloud customers in adopting the cloud models for their businesses. Intrusion Detection Systems (IDSs) are widely used to detect malicious activities. However existing solutions with IDSs involving DDoS and other non-detectable events may not be suitable in applying to the cloud due to distributed data storage and a major shift in Internet access mechanisms offered by cloud providers. Hence there is a strong need to analyze an appropriate IDS to counter DDoS attacks in the cloud. In this paper we propose a novel framework for data security in the cloud using Collaborative Intrusion Detection (CIDS) scheme. The benefits of CIDS scheme in cloud are enabling the end user to get comprehensive information in the event of a distributed attack on cloud.
Upasana T. Nagar, Priyadarsi Nanda, Xiangjian He, Zhiyuan Tan 0001
SIN2
2017 PAWN: a payload-based mutual authentication scheme for wireless sensor networks
abstract
Summary Wireless sensor networks (WSNs) consist of resource‐starving miniature sensor nodes deployed in a remote and hostile environment. These networks operate on small batteries for days, months, and even years depending on the requirements of monitored applications. The battery‐powered operation and inaccessible human terrains make it practically infeasible to recharge the nodes unless some energy‐scavenging techniques are used. These networks experience threats at various layers and, as such, are vulnerable to a wide range of attacks. The resource‐constrained nature of sensor nodes, inaccessible human terrains, and error‐prone communication links make it obligatory to design lightweight but robust and secured schemes for these networks. In view of these limitations, we aim to design an extremely lightweight payload‐based mutual authentication scheme for a cluster‐based hierarchical WSN. The proposed scheme, also known as payload‐based mutual authentication for WSNs, operates in 2 steps. First, an optimal percentage of cluster heads is elected, authenticated, and allowed to communicate with neighboring nodes. Second, each cluster head, in a role of server, authenticates the nearby nodes for cluster formation. We validate our proposed scheme using various simulation metrics that outperform the existing schemes.
Mian Ahmad Jan, Priyadarsi Nanda, Muhammad Usman 0015, Xiangjian He
Concurr. Comput. Pract. Exp.2
2016 Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm
abstract
Redundant and irrelevant features in data have caused a long-term problem in network traffic classification. These features not only slow down the process of classification but also prevent a classifier from making accurate decisions, especially when coping with big data. In this paper, we propose a mutual information based algorithm that analytically selects the optimal feature for classification. This mutual information based feature selection algorithm can handle linearly and nonlinearly dependent data features. Its effectiveness is evaluated in the cases of network intrusion detection. An Intrusion Detection System (IDS), named Least Square Support Vector Machine based IDS (LSSVM-IDS), is built using the features selected by our proposed feature selection algorithm. The performance of LSSVM-IDS is evaluated using three intrusion detection evaluation datasets, namely KDD Cup 99, NSL-KDD and Kyoto 2006+ dataset. The evaluation results show that our feature selection algorithm contributes more critical features for LSSVM-IDS to achieve better accuracy and lower computational cost compared with the state-of-the-art methods.
Mohammed A. Ambusaidi, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
IEEE Trans. Computers3
2015 sandFOX: secure sandboxed and isolated environment for firefox browser
abstract
Browser functionalities can be widely extended by browser extensions. One of the key features that makes browser extensions so powerful is that they run with "high" privileges. As a consequence, a vulnerable or malicious extension might expose browser, and operating system (OS) resources to possible attacks such as privilege escalation, information stealing, and session hijacking. The resources are referred as browser as well as OS components accessed through browser extension such as accessing information on the web application, executing arbitrary processes, and even access files from a host file system.
Anil Saini, Manoj Singh Gaur, Vijay Laxmi, Priyadarsi Nanda
SIN4
2015 Detection of Denial-of-Service Attacks Based on Computer Vision Techniques
abstract
Detection of Denial-of-Service (DoS) attacks has attracted researchers since 1990s. A variety of detection systems has been proposed to achieve this task. Unlike the existing approaches based on machine learning and statistical analysis, the proposed system treats traffic records as images and detection of DoS attacks as a computer vision problem. A multivariate correlation analysis approach is introduced to accurately depict network traffic records and to convert the records into their respective images. The images of network traffic records are used as the observed objects of our proposed DoS attack detection system, which is developed based on a widely used dissimilarity measure, namely Earth Mover's Distance (EMD). EMD takes cross-bin matching into account and provides a more accurate evaluation on the dissimilarity between distributions than some other well-known dissimilarity measures, such as Minkowski-form distance Lpand X2statistics. These unique merits facilitate our proposed system with effective detection capabilities. To evaluate the proposed EMD-based detection system, ten-fold cross-validations are conducted using KDD Cup 99 dataset and ISCX 2012 IDS Evaluation dataset. The results presented in the system evaluation section illustrate that our detection system can detect unknown DoS attacks and achieves 99.95 percent detection accuracy on KDD Cup 99 dataset and 90.12 percent detection accuracy on ISCX 2012 IDS evaluation dataset with processing capability of approximately 59,000 traffic records per second.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001, Jiankun Hu
IEEE Trans. Computers4
2014 A Novel Feature Selection Approach for Intrusion Detection Data Classification
abstract
Intrusion Detection Systems (IDSs) play a significant role in monitoring and analyzing daily activities occurring in computer systems to detect occurrences of security threats. However, the routinely produced analytical data from computer networks are usually of very huge in size. This creates a major challenge to IDSs, which need to examine all features in the data to identify intrusive patterns. The objective of this study is to analyze and select the more discriminate input features for building computationally efficient and effective schemes for an IDS. For this, a hybrid feature selection algorithm in combination with wrapper and filter selection processes is designed in this paper. Two main phases are involved in this algorithm. The upper phase conducts a preliminary search for an optimal subset of features, in which the mutual information between the input features and the output class serves as a determinant criterion. The selected set of features from the previous phase is further refined in the lower phase in a wrapper manner, in which the Least Square Support Vector Machine (LSSVM) is used to guide the selection process and retain optimized set of features. The efficiency and effectiveness of our approach is demonstrated through building an IDS and a fair comparison with other stateof-the-art detection approaches. The experimental results show that our hybrid model is promising in detection compared to the previously reported results.
Mohammed A. Ambusaidi, Xiangjian He, Zhiyuan Tan 0001, Priyadarsi Nanda, Upasana T. Nagar
TrustCom4
2014 A Stateful Mechanism for the Tree-Rule Firewall
abstract
In this paper, we propose a novel connection tracking mechanism for Tree-rule firewall which essentially organizes firewall rules in a designated Tree structure. A new firewall model based on the proposed connection tracking mechanism is then developed and extended from the basic model of Net filter's Conn Track module, which has been used by many early generation commercial and open source firewalls including IPTABLES, the most popular firewall. To reduce the consumption of memory space and processing time, our proposed model uses one node per connection instead of using two nodes as appeared in Net filter model. This can reduce memory space and processing time. In addition, we introduce an extended hash table with more hashing bits in our firewall model in order to accommodate more concurrent connections. Moreover, our model also applies sophisticated techniques (such as using static information nodes, and avoiding timer objects and memory management tasks) to improve its processing speed. Finally, we implement this model on Linux Cent OS 6.3 and evaluate its speed. The experimental results show that our model performs more efficiently in comparison with the Net filter/IPTABLES.
Thawatchai Chomsiri, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
TrustCom3
2014 A Robust Authentication Scheme for Observing Resources in the Internet of Things Environment
abstract
The Internet of Things is a vision that broadens the scope of the internet by incorporating physical objects to identify themselves to the participating entities. This innovative concept enables a physical device to represent itself in the digital world. There are a lot of speculations and future forecasts about the Internet of Things devices. However, most of them are vendor specific and lack a unified standard, which renders their seamless integration and interoperable operations. Another major concern is the lack of security features in these devices and their corresponding products. Most of them are resource-starved and unable to support computationally complex and resource consuming secure algorithms. In this paper, we have proposed a lightweight mutual authentication scheme which validates the identities of the participating devices before engaging them in communication for the resource observation. Our scheme incurs less connection overhead and provides a robust defence solution to combat various types of attacks.
Mian Ahmad Jan, Priyadarsi Nanda, Xiangjian He, Zhiyuan Tan 0001, Ren Ping Liu 0001
TrustCom2
2014 PASCCC: Priority-based application-specific congestion control clustering protocol
Mian Ahmad Jan, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu 0001
Comput. Networks2
2014 Improving cloud network security using the Tree-Rule firewall
Xiangjian He, Thawatchai Chomsiri, Priyadarsi Nanda, Zhiyuan Tan 0001
Future Gener. Comput. Syst.3
2014 A System for Denial-of-Service Attack Detection Based on Multivariate Correlation Analysis
abstract
Interconnected systems, such as Web servers, database servers, cloud computing servers and so on, are now under threads from network attackers. As one of most common and aggressive means, denial-of-service (DoS) attacks cause serious impact on these computing systems. In this paper, we present a DoS attack detection system that uses multivariate correlation analysis (MCA) for accurate network traffic characterization by extracting the geometrical correlations between network traffic features. Our MCA-based DoS attack detection system employs the principle of anomaly based detection in attack recognition. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Furthermore, a triangle-area-based technique is proposed to enhance and to speed up the process of MCA. The effectiveness of our proposed detection system is evaluated using KDD Cup 99 data set, and the influences of both non-normalized data and normalized data on the performance of the proposed detection system are examined. The results show that our system outperforms two other previously developed state-of-the-art approaches in terms of detection accuracy.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
IEEE Trans. Parallel Distributed Syst.4
2013 Routing scheme for a Wireless Sensor Network real-time locating system
abstract
This work contains a routing proposition to be used over a Wireless Sensor Network (WSN) location system based on the IEEE 802.15.4 standard. The technical solution for communication consists of an n-ary tree algorithm for routing using a 16 bit addressing scheme. It is compared to a binary routing scheme originally used on a real system which suffers from coverage, routing and addressing problem. An analysis of the coverage aspects is driven by a geometric study. It includes an analysis of a generated topology for different coverage areas and different routing topologies. The geometric analysis is validated by a simulation work. We observe that the proposed scheme outperforms the existing routing solution in terms of hop-count, delay and association process time. The work puts in evidence that the Connectivity of the network is an important parameter to be considered during the network deployment and for the routing scheme.
Hugo Cruz-Sanchez, Laurent Ciarletta, Yeqiong Song, Priyadarsi Nanda
IWCMC4
2013 RePIDS: A multi tier Real-time Payload-based Intrusion Detection System
Aruna Jamdagni, Zhiyuan Tan 0001, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
Comput. Networks4
2012 Border Gateway Protocol Anomaly Detection Using Failure Quality Control Method
abstract
Border Gateway Protocol (BGP) is the de-facto inter-domain routing protocol used across thousands of Autonomous Systems (AS) joined together in the Internet. Security has been a major issue for BGP. Nevertheless, BGP suffers from serious threats even today, like Denial of Service (DoS) attack and misconfiguration of routing information. BGP is one of the complex routing protocols and hard to configure against malicious attacks. However, it is important to detect such malicious activities in a network, which could otherwise cause problems for availability of services in the Internet. In this paper we use the Failure Quality Control (FQC), a technique to detect anomaly packets in the network for real time intrusion detection.
Muhammad Mujtaba, Priyadarsi Nanda, Xiangjian He
TrustCom2
2012 Triangle-Area-Based Multivariate Correlation Analysis for Effective Denial-of-Service Attack Detection
abstract
Cloud computing plays an important role in current converged networks. It brings convenience of accessing services and information to users regardless of location and time. However, there are some critical security issues residing in cloud computing, such as availability of services. Denial of service occurring on cloud computing has even more serious impact on the Internet. Therefore, this paper studies the techniques for detecting Denial-of-Service (DoS) attacks to network services and proposes an effective system for DoS attack detection. The proposed system applies the idea of Multivariate Correlation Analysis (MCA) to network traffic characterization and employs the principal of anomaly-based detection in attack recognition. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Furthermore, a triangle area technique is proposed to enhance and speed up the process of MCA. The effectiveness of our proposed detection system is evaluated on the KDD Cup 99 dataset, and the influence of both non-normalized and normalized data on the performance of the detection system is examined. The results presented in the system evaluation section illustrate that our DoS attack detection system outperforms two state-of-the-art approaches.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
TrustCom4
2011 Multivariate Correlation Analysis Technique Based on Euclidean Distance Map for Network Traffic Characterization
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
ICICS4
2011 Denial-of-Service Attack Detection Based on Multivariate Correlation Analysis
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
ICONIP (3)4
2011 An Integrated Model Supporting Billing and QOS in the Internet
abstract
This article develops a charging scheme that is simple and easily usable for the users and provides them with the incentives to use only the resources they need. This scheme is developed on the time-volume charging approach to show how the contributing providers can share the total charge earned by each mobile and wireless service instance in a fair way, with each provider collecting the portion of charge that corresponds to the consumption of its own resources for the service. This is also an important issue for the commercial viability of mobile services to mobile users, given that its provision spans multiple domains. Our proposed architecture is compliant to the relevant standards and can serve as a basis for applying other Internet charging schemes as well.
Hla Myint, Priyadarsi Nanda
SNPD2
2010 A Two-Tier System for Web Attack Detection Using Linear Discriminant Method
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001, Wenjing Jia, Wei-Chang Yeh 0001
ICICS4
2010 Intrusion detection using GSAD model for HTTP traffic on web services
abstract
Intrusion detection systems are widely used security tools to detect cyber-attacks and malicious activities in computer systems and networks. Hypertext Transport Protocol (HTTP) is used for new applications without much interference. In this paper, we focus on intrusion detection of HTTP traffic by applying pattern recognition techniques using our Geometrical Structure Anomaly Detection (GSAD) model. Experimental results reveal that features extracted from HTTP request using GSAD model can be used to distinguish anomalous traffic from normal traffic, and attacks carried out over HTTP traffic can be identified. We evaluate and compare our results with the results of PAYL intrusion detection systems for the test of DARPA 1999 IDS data set. The results show GSAD has high detection rates and low false positive rates.
Aruna Jamdagni, Zhiyuan Tan 0001, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu 0001
IWCMC3
2009 Web Service Locating Unit in RFID-Centric Anti-counterfeit System
abstract
The problem of piracy has disturbed people’s daily life for hundreds of years and has not been relieved until now, though many existing anti-counterfeit solutions have been applied. However, due to the emergences of Radio Frequency IDentification (RFID) technologies, there is a more reliable alternative solution to construct authentication system. On the other hand, there arises another issue of how to simplify the deployment of RFID-centric anti-counterfeit system over the Internet. In this article, we propose an approach, Web Service Locating Unit (WSLU), to achieve this goal to manage numbers of RFID-centric authentication services (relied on web services).
Zhiyuan Tan 0001, Xiangjian He, Priyadarsi Nanda
ISPA3
2007 Quality of Service in Telemedicine
abstract
Telemedicine is one of the fastest growing fields with several innovations happening in managed health-care. With Internet and its infrastructures playing important role in the success of this field, it is not advisable to run some of the critical applications like high quality audio and video involved in telemedicine without proper quality of service (QoS) built on to the network. This paper focuses on two telemedicine setups that have been implemented on different backbone technologies. The first case discusses a virtual critical care unit that is setup for communication on an asynchronous transfer mode (ATM) backbone and a possible model on how QoS for important traffic streams can be achieved in ATM. The second case discusses a minimal access operation that was remotely conducted on a patient with the help of telerobotics on a multi protocol label switching (MPLS) setup and provides a possible solution for achieving quality of service through MPLS in that scenario.
Priyadarsi Nanda, Rohan C. Fernandes
ICDS1
2000 Intra-domain Bandwidth Management in Differentiated Services Network
abstract
In absence of any link layer traffic controls or priority-queuing mechanism in LAN infrastructure (such as shared media LAN), the subnet bandwidth management based approach of managing bandwidth is limited to only the total amount of traffic load imposed by RSVP associated flows. In such cases no mechanism is available to separate RSVP flows from best effort traffic. This brings the usefulness of the subnet bandwidth manager into question. This uses a combination of integrated services of a specific link layer model based on RSVP and an IP rate-control approach for best effort traffic to manage intra-domain traffic in a differentiated services network.
Sanjay K. Jha, Mahbub Hassan, Priyadarsi Nanda
LCN3