Anwar Haque

dblp:93/5670 · DBLP profile ↗
← Back
56ranked-venue papers
4as first author
27since 2021 · last 2025
0000-0002-5253-0455ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 22 · 3 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Security and privacy · 3Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Deciphering Model Decisions in Android Malware Detection with Explainable AI
abstract
From fitness tracking to banking, human life is increasingly relying on mobile devices. As usage proliferates, risks associated with getting affected by malicious apps also increase. As a result, the development of mobile malware detection systems has consistently been a priority research focus over the past few decades. Traditional signature-based malware detection became obsolete with the advent of sophisticated development techniques such as polymorphism. Recent research suggests that Machine Learning (ML) based dynamic analysis is a promising approach for mobile malware detection. However, ML models often classify benign apps as malicious and viceversa. Thus, understanding the cause for identifying a particular malware kind is crucial. This study employs Random Forest ($\mathbf{R F}$) to detect Adware and Trojan malware, explaining the models and identifying the reasons for classification.
Moinul Islam Sayed, Amreen Anbar, Sajal Saha, Anwar Haque
ISNCC4
2025 Autonomous Cyber Incident Response Using Reasoning and Action
abstract
The increasing complexity and frequency of cyber threats necessitate autonomous security solutions capable of real-time detection, reasoning, and response. This paper introduces an autonomous cyber incident response framework that integrates Reasoning and Acting (ReAct) agents with Large Language Models (LLMs) to enhance cybersecurity decision-making. The proposed system features a cloud-based testbed, real-time monitoring tools (Wazuh, Suricata), and a NATS messaging system for seamless threat detection and mitigation. The ReAct agent, powered by a fine-tuned LLM, iteratively analyzes security alerts, generates context-aware mitigation strategies, and autonomously executes response actions via integrated cybersecurity tools such as firewalls. The framework demonstrates its effectiveness in real-time cyberattack mitigation, including port scanning, botnet intrusions, and SSH brute-force attacks. By leveraging LangGraph-guided decision loops and Chain-of-Thought (CoT) reasoning, the system dynamically adapts to evolving threats while reducing reliance on human intervention. Evaluations in a simulated environment highlight the scalability of the architecture and its ability to achieve low-latency, autonomous threat mitigation. The findings highlight the potential of LLM-driven security automation in modern cyber defense strategies, paving the way for future advancements in mitigating phishing, malware, and insider threats.
Sudipto Baral, Sajal Saha, Anwar Haque
IWCMC3
2025 Overcoming data limitations in internet traffic forecasting: LSTM models with transfer learning and wavelet augmentation
abstract
Accurate internet traffic prediction in smaller ISP networks is challenged by limited data availability. This paper explores this issue using transfer learning and data augmentation techniques with two LSTM-based models, LSTMSeq2Seq and LSTMSeq2SeqAtn, initially trained on a comprehensive dataset provided by Juniper Networks, Inc. and subsequently applied to smaller datasets. The datasets represent real internet traffic telemetry, offering insights into diverse traffic patterns across different network domains. Our study found that although both models performed well in single-step predictions, multi-step forecasting was more challenging, especially regarding long-term accuracy. Empirical results demonstrated that LSTMSeq2Seq outperformed LSTMSeq2SeqAtn on smaller datasets, with improvements in forecasting accuracy by up to 36.70% in MAE and 27.66% in WAPE after applying data augmentation using Discrete Wavelet Transform. The LSTMSeq2Seq model achieved an accuracy improvement from 83% to 88% for 6-step forecasts, 82% to 88% for 9-step forecasts, and 81% to 87% for 12-step forecasts, whereas LSTMSeq2SeqAtn exhibited a more stable short-term performance but higher variability in longer forecasts. Additionally, the mean absolute percentage error (MAPE) of multi-step predictions increased over longer horizons, with LSTMSeq2Seq reaching 6.74% at 12 steps and LSTMSeq2SeqAtn at 6.77%, highlighting the challenge of long-term forecasting. Variability analysis showed that while the attention mechanism in LSTMSeq2SeqAtn improved short-term prediction consistency, it also increased uncertainty in longer forecasts, as seen in the interquartile range (IQR) rising from 0.578 at 6 steps to 1.237 at 9 steps. Outlier analysis further confirmed that LSTMSeq2Seq exhibited more stable improvements, whereas LSTMSeq2SeqAtn showed increased dispersion in forecast accuracy. These findings underscore the importance of transfer learning and data augmentation in enhancing forecasting accuracy, particularly for smaller ISP networks with limited data availability. Furthermore, our analysis highlights the trade-offs between model complexity, short-term consistency, and long-term stability in internet traffic prediction.
Sajal Saha, Anwar Haque, Greg Sidebottom
Comput. Commun.2
2024 MavSec: A safer version of MavLink
abstract
The MavLink protocol is a lightweight communication protocol used for communication between unmanned aerial vehicles (UAVs) and the ground control station (GCS). The contents of the MavLink payload might include sensitive information, including mission details and the geographical coordinates of the drone. Nonetheless, due to the lack of encryption support in the MavLink protocol, the payload can be readily obtained and modified by an attacker. This study introduces an enhanced protocol called MavLink Secure (MavSec) that provides built-in support for payload encryption. Furthermore, we have also incorporated the secure key exchange process. Then, our proposed protocol was tested with various encryption algorithms (AES, RC4, ChaCha20, PRESENT, RECTANGLE) implemented in C++. Next, we proceed to evaluate the performance metrics with peak memory usage and average delay time on two separate machines. The results of experiments indicate that ChaCha20 has better overall performance in comparison to other encryption algorithms. The integration of ChaCha20 with MavSec has resulted in enhanced levels of confidentiality, integrity, and authenticity compared to the unprotected MavLink protocol.
Chongju Mai, Anwar Haque
IWCMC2
2024 Optimizing Internet Traffic Predictions with a Novel Deep Learning EMD-KNN Framework
abstract
Internet traffic volume estimation has a significant impact on the business policies of the ISP (Internet Service Provider) industry and business successions. Forecasting the internet traffic demand helps to shed light on the future traffic trend, which is often helpful for ISPs’ decision-making in network planning activities and investments. Besides, the capability to understand future trend contributes to managing regular and long-term operations. This study aims to predict the network traffic volume demand using deep sequence methods that incorporate Empirical Mode Decomposition (EMD) based noise reduction, Empirical rule based outlier detection, and K-Nearest Neighbour (KNN) based outlier mitigation. In contrast to the former studies, the proposed model does not rely on a particular EMD decomposed component called Intrinsic Mode Function (IMF) for signal denoising. In our proposed traffic prediction model, we used an average of all IMFs components for signal denoising. Moreover, the abnormal data points are replaced by K nearest data point’s average, and the value for K has been optimized based on the KNN regressor prediction error measured in Root Mean Squared Error (RMSE). Finally, we selected the best time-lagged feature subset for our prediction model based on AutoRegressive Integrated Moving Average (ARIMA) and Akaike Information Criterion (AIC) value. Our experiments are conducted on real-world internet traffic datasets from industry, and the proposed method is compared with various statistical and traditional deep sequence baseline models. Our results show that the proposed EMD-KNN integrated prediction models outperform comparative models.
Sajal Saha, Sudipto Baral, Anwar Haque
IWCMC3
2024 DDoS Attack Prevention in Autonomous Vehicle's OTA Updates: Combining PBFT Consensus and Distributed Firewall in Hyperledger Fabric Blockchain
abstract
The advent of connected autonomous vehicles (CAVs) is bringing forth a revolutionary new era of technology transforming transportation. For traffic to be optimized and safe, efficient vehicle-to-everything collaboration and improved autonomous vehicles (AV) decision-making are crucial. It becomes essential to make decisions in real time using information from vehicle sensors, software, and traffic data. As a part of such an In-Vehicle Network (IVN), over-the-air (OTA) software update service in CAVs needs to be facilitated rapidly, reliably, and securely. However, by taking advantage of vulnerabilities, attackers may quickly target the OTA software update as part of botnets to execute distributed denial-of-service (DDoS) attacks. The enormous volume and widespread nature of these DDoS cyber-attacks make it vital for the CAV industry to work quickly on identifying and preventing these threats. This paper proposes proof-of-concept experiments with the Hyperledger Fabric (HLF) Blockchain model to detect and prevent DDoS attacks in CAVs, OTA update systems. The proposed method implements Practical Byzantine Fault Tolerance (PBFT) as the consensus mechanism and a distributed firewall to ensure the ledger is secure and tamper’ proof. The system is tested on the Amazon Elastic Compute Cloud (EC2) Blockchain (BC) platform. The results show that the proposed approach effectively prevents DDoS attacks while ensuring fast transaction execution time.
Sadia Yeasmin, Anwar Haque
IWCMC2
2024 Predicting and mitigating cyber threats through data mining and machine learning
abstract
With cyber threats evolving alongside technological progress, strengthening network resilience to combat security vulnerabilities is crucial. This research extends cyber-crime analysis with an innovative approach, utilizing data mining and machine learning to not only predict cyber incidents but also reinforce network robustness. We introduce a real-time data collection framework to provide up-to-date cyberattack data, addressing current research limitations. By analyzing collected attack data, we identified temporal correlations in attack volumes across consecutive time frames. Our predictive model, developed using advanced machine learning and deep learning techniques, forecasts the frequency of cyber-attacks within specific time windows, demonstrating over a 15% improvement in accuracy compared to conventional baseline models. The methodologies employed include the use of Recurrent Neural Networks (RNN) and Convolutional Neural Networks (CNN) for capturing complex patterns in time series data, and the integration of a sliding window technique to transform raw data into a format suitable for supervised learning. Our experiments evaluated the performance of various models, including ARIMA, Random Forest, Support Vector Regression, and K-Nearest Neighbors Regression, across multiple scenarios. Furthermore, we developed a Power BI platform for visualizing global cyber-attack trends, providing valuable insights for enhancing cybersecurity defences. Our research demonstrates that cyber incidents are not entirely random, and advanced AI tools can significantly enhance cybersecurity defences by analyzing patterns and trends from previous instances. This comprehensive approach not only improves prediction accuracy but also offers a robust framework for reducing the risk and impact of future cyber-crimes through enhanced detection and prediction capabilities.
Nusrat Samia, Sajal Saha, Anwar Haque
Comput. Commun.3
2024 ENIDS: A Deep Learning-Based Ensemble Framework for Network Intrusion Detection Systems
abstract
Rapid and widespread adoption of emerging Information Technology (IT) infrastructures and services in commercial and private endeavors opens new horizons for novel cyberattacks. Network Intrusion Detection Systems (NIDS) gained attention as an effective means of combating various cyber threats. Recent research demonstrates the potency of machine learning (ML) and deep learning (DL) approaches in the development of NIDS. In this paper, we propose a DL-based framework called the Ensemble Framework for Network Intrusion Detection System (ENIDS) to detect various types of cyberattacks, which includes dynamic data pre-processing, optimal feature selection, the handling of imbalanced data samples, and a DL-based ensemble model. Our DL-based ensemble model is comprised of two layers: the base learner and the meta-learner. The base learner is composed of three robust DL models: convolutional neural networks (CNN), long short-term memory (LSTM), and gated recurrent units (GRU), and the meta-learner is a deep neural network (DNN) model. The proposed framework experimented with two publicly available and popular network traffic datasets, namely UNSW-15 and CICIDS-2017. In the UNSW-15 and CICIDS-2017 datasets, our proposed framework detects cyberattacks with an accuracy of 90.6% and 99.6% and an F1-score of 90.5% and 99.6%, respectively. According to experimental findings, the proposed ensemble framework outperforms existing state-of-the-art approaches and demonstrates better performance than benchmark DL methods in terms of accuracy, F1-score, and execution time for training and testing.
Ibrahim Mohammed Sayem, Moinul Islam Sayed, Sajal Saha, Anwar Haque
IEEE Trans. Netw. Serv. Manag.4
2023 Transfer Learning Based Efficient Traffic Prediction with Limited Training Data
abstract
Efficient prediction of internet traffic is an essential part of Self Organizing Network (SON) for ensuring proactive management. There are many existing solutions for internet traffic prediction using machine and deep learning techniques. But designing individual predictive models for each service provider in the network is challenging due to data heterogeneity, scarcity, and abnormality. Moreover, the performance of the deep sequence model in network traffic prediction with limited training data has not been studied extensively in the current works. In this paper, we investigated and evaluated the performance of the deep transfer learning technique in traffic prediction with inadequate historical data leveraging the knowledge of our pre-trained model. First, we used a larger real-world traffic dataset for source domain prediction based on five different deep sequence models: Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM Encoder-Decoder (LSTM_En_De), LSTM_En_De with Attention layer (LSTM_En_De_Atn), and Gated Recurrent Unit (GRU). Then, two best-performing models, LSTM_En_De and LSTM_En_De_Atn, from the source domain with an accuracy of 96.06% and 96.05% are considered for the target domain prediction. Finally, four smaller traffic datasets, collected for four different sources and destination pairs, are used in the target domain to compare the performance of the standard learning and transfer learning in terms of accuracy and execution time. According to our experimental result, transfer learning helps to reduce the execution time for most cases, while the model's accuracy is improved in transfer learning with a larger training session.
Sajal Saha, Anwar Haque, Greg Sidebottom
CCNC2
2023 Out-of-Distribution Internet Traffic Prediction Generalization Using Deep Sequence Model
abstract
Efficient internet traffic prediction is very crucial for proactive network management. Unfortunately, it is a non-trivial task to design an effective prediction tool to capture the general pattern of complex, non-linear, and non-stationary real-world traffic. However, novel deep learning models have been developed for network traffic prediction, where they exhibit excellent performance. Most existing works assumed that training and testing data samples are independent and identically distributed (IID). But there is a high probability of having slightly or completely unknown data samples after model deployment, and the model should be able to predict them accurately. In this study, we show a comparative performance analysis among several deep sequence models using IID and out-of-distributed (OOD) samples. The prediction model average accuracy dropped significantly for OOD data samples compared to IID test data. Therefore, we proposed a hybrid architecture combining deep sequence models and discrete wavelet transformation (DWT), where models are trained using decomposed hierarchical components instead of original data. According to our experimental results, the hybrid model increases the prediction accuracy using IID samples by 2% compared to the standalone model. Also, the performance gap between IDD and OOD samples is reduced considerably by hybrid models, which indicates the outperformance of our proposed methodology to conventional deep learning models for both IDD and OOD test instances.
Sajal Saha, Anwar Haque
ICC2
2023 Examining Generative Adversarial Network for Smart Home DDoS Traffic Generation
abstract
Adversarial attacks have become a common place in network security. Neural network-based traffic classifiers have been regarded as effective tools against malicious attacks. However, their performance highly depends on the quality of the training dataset that is often hard to obtain. IoT-centric smart home network is vulnerable to adversarial attacks with a high cost to the individual. In this research, we perform a thorough study on the performance of the original GAN model towards generating flow-based IoT traffic in smart home DDoS attacks. Based on a unique IoT traffic dataset of smart home, we implemented four versions of the original GAN model by using four batch sizes per epoch during training. We captured synthetic IoT traffic at different epochs of the models, which results in a total of 200 IoT traffic datasets. Then, we evaluate the quality of the 200 synthetic datasets using an approach called train-on-synthetic, test-on-real (TSTR). Our study suggests that the original GAN can produce a quality IoT traffic of smart home DDoS attacks at most of the epochs but lacks in providing consistent performance across all the epochs of the GAN model. However, by using TSTR metrics, it is possible to identify the datasets of good quality to be used for real applications.
Md. Rashed Iqbal Nekvi, Sajal Saha, Yaser Al Mtawa, Anwar Haque
ISNCC4
2023 Wavelet-Based Hybrid Machine Learning Model for Out-of-distribution Internet Traffic Prediction
abstract
Internet traffic prediction is a crucial component for the proactive management of self-organizing networks (SON) to ensure better Quality of Service (QoS) and Quality of Experience (QoE). Modern machine learning techniques have shown outstanding performance in analyzing and predicting complex internet traffic, which has non-linear and non-stationary characteristics. But most existing works assumed that model training and testing data came from independent and identical distribution (IID), which is hardly valid in actual scenarios. Also, they considered synthetic traffic datasets, which do not have enough random properties like real-world traffic. As a result, the model’s prediction accuracy measured using IID data samples is inconsistent with the accuracy of out-of-distribution (OOD) data instances. In this study, we investigated several machine learning models’ performances using four actual traffic datasets whose distribution is different than each other. The best prediction accuracy using IID samples was 96.4% which significantly dropped when we used OOD samples to evaluate the same model. Therefore, we proposed a hybrid machine learning model combining discrete wavelet transformation to decompose original data into several hierarchical components before feeding them into a prediction model. We train our hybrid models using these detail components as features that improve our best performance using IID samples by 1%. Also, it considerably reduces the best accuracy gap of conventional machine learning models in predicting IID and OOD samples by 3.5%, 6.7%, and 2.1%, respectively, for three OOD test sets.
Sajal Saha, Anwar Haque
NOMS2
2023 A Real-time Vehicle-Pedestrian Collision Avoidance System Exploiting Lightweight Smartphone App
abstract
Road accidents are the leading cause of death, resulting in thousands of deaths and major financial suffering in our society. Potential collisions between automobiles and pedestrians should be detected prior to their occurrence in order to offer early warnings. In recent years, numerous solutions have been presented to avoid vehicle-pedestrian accidents. However, the majority of these systems need substantial infrastructure, which is costly, difficult to implement on a large scale and incurs heavy maintenance. We propose a collision avoidance system that utilizes smartphones and requires no additional hardware resources. Our proposed system includes a lightweight app that generates trajectories as a prediction of future locations on the user’s side and sends it to the cloud. The trajectory updates are processed on the cloud for finding potential collisions and sending alerts to the possibly colliding devices in advance. The smartphone app is power consumption-wise less expensive as it requires only location updates and does not intervene with any other sensor. The real road experiments show impressive accuracy in generating timely, relevant warnings.
Moinul Islam Sayed, Anwar Haque
VTC Fall2
2023 Analyzing the Impact of Outlier Data Points on Multi-Step Internet Traffic Prediction Using Deep Sequence Models
abstract
The task of predicting Internet traffic is challenging, particularly in multi-step forecasting due to the volatile and random nature of data. In addition, real-world traffic may contain outlier data points, so developing a prediction model that integrates anomaly detection and mitigation is necessary. This paper compares several deep sequence models, such as Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM Encoder-Decoder (LSTM_En_De), LSTM Encoder-Decoder with attention layer (LSTM_En_De_Atn), and Gated Recurrent Unit (GRU), with our proposed methodology for single-step prediction. Our proposed LSTM_En_De model, integrated with outlier detection, outperforms traditional deep sequence models in single-step prediction, reducing the deviation between actual and predicted traffic by over 11%. We also apply our methodology to multi-step forecast analysis, using multiple output strategies for forecast horizons of 3, 6, 9, and 12 steps ahead. Experimental results demonstrate the effectiveness of our proposed methodology in improving the accuracy of single-step prediction and multi-step forecasting tasks, especially when dealing with outlier data points that adversely affect model accuracy. In summary, this paper investigates the challenges of real-world Internet traffic prediction, proposes a novel prediction model integrated with anomaly detection and mitigation, and compares different deep sequence models for single-step and multi-step forecasting tasks.
Sajal Saha, Anwar Haque, Greg Sidebottom
IEEE Trans. Netw. Serv. Manag.2
2022 Towards an Optimal Feature Selection Method for AI-Based DDoS Detection System
abstract
Cyber-attacks are increasing rapidly, so developing effective intrusion detection and prevention tools for a secure and safer cyberspace is crucial. DDoS (Distributed Denial of Services) is one of the most well-known digital threats, endangering any cyber-physical system. DDoS prevents the host from serving the legitimate traffic by overflowing the host node with unwanted service requests. Nowadays, machine learning-based IDS (Intrusion Detection System) uses different Feature Selection (FS) methods to extract a feature subset from a large dataset to increase the model performance and decrease the training time. In this research work, we used the UNSW-NB15 dataset [1] to conduct a comprehensive analysis for evaluating the performance of different FS techniques in DDoS attack classification using both Machine Learning (ML) and Deep Learning (DL) models. Furthermore, an Ensemble Feature Selection (EN-FS) technique called Majority Voting (MV) has been implemented to combine the individual FS method’s output to extract an optimal feature set. Our ensemble feature selection approach significantly reduces the features from 42 to 15, which is 64% less than the original features. Lastly, an extensive experiment has been performed to estimate and compare the performance of individual, ensemble, and original feature set in both ML and DL-based DDoS detection systems. According to our analysis, the ensemble feature set-based classification model exhibits higher accuracy, lower False Positive Rate (FPR), and better execution time than the other individual feature set-based models.
Sajal Saha, Annita Tahsin Priyoti, Aakriti Sharma, Anwar Haque
CCNC4
2022 Deep Sequence Modeling for Anomalous ISP Traffic Prediction
abstract
Internet traffic in the real world is susceptible to various external and internal factors which may abruptly change the normal traffic flow. Those unexpected changes are considered outliers in traffic. However, deep sequence models have been used to predict complex IP traffic, but their comparative performance for anomalous traffic has not been studied extensively. In this paper, we investigated and evaluated the performance of different deep sequence models for anomalous traffic prediction. Several deep sequences models were implemented to predict real traffic without and with outliers and show the significance of outlier detection in real-world traffic prediction. First, two different outlier detection techniques, such as the Three-Sigma rule and Isolation Forest, were applied to identify the anomaly. Second, we adjusted those abnormal data points using the Backward Filling technique before training the model. Finally, the performance of different models was compared for abnormal and adjusted traffic. LSTM_Encoder_Decoder (LSTM_En_De) is the best prediction model in our experiment, reducing the deviation between actual and predicted traffic by more than 11% after adjusting the outliers. All other models, including Recurrent Neural Network (RNN), Long Short-Term Memory (LSTM), LSTM_En_De with Attention layer (LSTM_En_De_Atn), Gated Recurrent Unit (GRU), show better prediction after replacing the outliers and decreasing prediction error by more than 29%, 24%, 19%, and 10% respectively. Our experimental results indicate that the outliers in the data can significantly impact the quality of the prediction. Thus, outlier detection and mitigation assist the deep sequence model in learning the general trend and making better predictions.
Sajal Saha, Anwar Haque, Greg Sidebottom
ICC2
2022 Towards an Ensemble Regressor Model for ISP Traffic Prediction with Anomaly Detection and Mitigation
abstract
Prediction of network traffic behavior is significant for the effective management of modern telecommunication networks. However, the intuitive approach of predicting network traffic using administrative experience and market analysis data is inadequate for an efficient forecast framework. As a result, many different mathematical models have been studied to capture the general trend of the network traffic and predict accordingly. But the comprehensive performance analysis of varying regression models and their ensemble has not been studied before for analyzing real-world anomalous traffic. In this paper, several regression models such as Extra Gradient Boost (XGBoost), Light Gradient Boosting Machine (LightGBM), Stochastic Gradient Descent (SGD), Gradient Boosting Regressor (GBR), and CatBoost Regressor were analyzed to predict real traffic without and with outliers and show the significance of outlier detection in real-world traffic prediction. Also, we showed the outperformance of the ensemble regression model over the individual prediction model. We compared the performance of different regression models based on five different feature sets of lengths 6, 9, 12, 15, and 18. Our ensemble regression model achieved the minimum average gap of 5.04% between actual and predicted traffic with nine outlier-adjusted inputs. In general, our experimental results indicate that the outliers in the data can significantly impact the quality of the prediction. Thus, outlier detection and mitigation assist the regression model in learning the general trend and making better predictions.
Sajal Saha, Anwar Haque, Greg Sidebottom
ISNCC2
2022 Disjoint-Path Segment Routing: Network Reliability Perspective
abstract
Achieving five-nines reliability in communication networks is of paramount importance to network operators. Adopting multipath Segment Routing (SR) in networking offers several key advantages in load balancing, optimal link utilization, reducing congestion, and enhancing reliability. Equal-cost multipath (ECMP) routing falls short to effectively utilize a multipath approach because ECMP may still forward traffic through the specific paths resulting in decreased network reliability. In this paper, we propose a novel two-phase Disjoint-path SR-based reliability framework to enhance the current network reliability. This framework drives network traffic flows through disjoint paths, resulting in effective load balancing and improving network reliability to meet stringent requirements of various services. Our proposed framework includes the following: a) Phase I: Optimization phase uses Mixed-Integer Linear Programming (MILP) formulation to find the optimal multipath that minimizes the maximum utilization of a given network while transmitting traffic between two terminal nodes, and b) Phase II: This phase splits the multipath of phase I into two disjoint multipaths, namely working and backup. The proposed framework is implemented, and its validation and effectiveness are demonstrated through simulation results.
Yaser Al Mtawa, Anwar Haque, Greg Sidebottom
IWCMC2
2022 An Empirical Study on Internet Traffic Prediction Using Statistical Rolling Model
abstract
Real-world IP network traffic is susceptible to exter-nal and internal factors such as new internet service integration, traffic migration, internet application, etc. Due to these factors, the actual internet traffic is non-linear and challenging to analyze using a statistical model for future prediction. In this paper, we investigated and evaluated the performance of different statistical prediction models for real IP network traffic; and showed a significant improvement in prediction using the rolling prediction technique. Initially, a set of best hyper-parameters for the corresponding prediction model is identified by analyzing the traffic characteristics and implementing a grid search algorithm based on the minimum Akaike Information Criterion (AIC). Then, we performed a comparative performance analysis among AutoRegressive Integrated Moving Average (ARIMA), Seasonal ARIMA (SARIMA), SARIMA with eXogenous factors (SARIMAX), and Holt-Winter for single-step prediction. The seasonality of our traffic has been explicitly modeled using SARIMA, which reduces the rolling prediction Mean Average Percentage Error (MAPE) by more than 4% compared to ARIMA (incapable of handling the seasonality). We further improved traffic prediction using SARIMAX to learn different exogenous factors extracted from the original traffic, which yielded the best rolling prediction results with a MAPE of 6.83%. Finally, we applied the exponential smoothing technique to handle the variability in traffic following the Holt-Winter model, which exhibited a better prediction than ARIMA (around 1.5% less MAPE). The rolling prediction technique reduced prediction error using real Internet Service Provider (ISP) traffic data by more than 50% compared to the standard prediction method.
Sajal Saha, Anwar Haque, Greg Sidebottom
IWCMC2
2022 A Multi-Classifier for DDoS Attacks Using Stacking Ensemble Deep Neural Network
abstract
DDoS (Distributed Denial of Service) attacks have emerged as a serious menace to the security and integrity of data and information systems. The primary aim of this attack is to take down the targeted system and prevent legitimate users from accessing its services. Identifying a DDoS attack is a challenging task, and it must be performed before initiating any countermeasure. DDoS attack detection has been effectively applied in many studies using Machine Learning (ML) and Deep Learning (DL). However, many existing models are unable to recognize the distinct and dynamic behavior of DDoS attacks because they employ datasets that were produced a long time ago and lack up-to-date attack scenarios, do not include packet-based bi-directional traffic flow, and do not contain complete network traffic. In addition, most studies carried out binary classification, however, there are many types of DDoS attacks, each with its unique characteristics. Classifying DDoS attacks can be useful when thwarting the attack and taking preventive measures. This paper presents a multi-classifier model using stacking ensemble deep neural networks that identify several types of DDoS attacks to address the issues mentioned above. Our proposed hybrid model incorporates Convolution Neural Network (CNN), Long Short Term Memory (LSTM), and Gated Recurrent Unit (GRU), and we show that while evaluating models with large datasets such as CIC-DDoS2019, ensemble technique increases model performance. According to experimental results, our proposed model can reach an accuracy of 89.4%, which outperforms other similar methods.
Moinul Islam Sayed, Ibrahim Mohammed Sayem, Sajal Saha, Anwar Haque
IWCMC4
2022 Network Intrusion Detection and Comparative Analysis Using Ensemble Machine Learning and Feature Selection
abstract
Proper security solutions in the cyber world are crucial for enforcing network security by providing real-time network protection against network vulnerabilities and data exploitation. An effective intrusion detection strategy is capable of taking a holistic approach for protecting critical systems against unauthorized access or attack. In this paper, we describe a machine learning (ML) based comprehensive security solution for network intrusion detection using ensemble supervised ML framework and ensemble feature selection methods. In addition, we provide a comparative analysis of several ML models and feature selection methods. The goal of this research is to design a generic detection mechanism and achieve higher accuracy with minimal false positive rates (FPR). NSL-KDD, UNSW-NB15, and CICIDS2017 datasets are used in the experiment, and results show that our detection model can identify 99.3% of intrusions successfully with the lowest 0.5% of false alarms, which depicts better performance metrics compared to existing solutions.
Sajal Saha, Annita Tahsin Priyoti, Etee Kawna Roy, Frederick T. Sheldon, Anwar Haque, Sajjan G. Shiva
IEEE Trans. Netw. Serv. Manag.6
2021 Simple and Efficient Algorithm for Drone Path Planning
abstract
Unmanned aerial vehicles, or drones, have gained a lot of popularity due to their large number of applications in surveillance, aerial photography, 3D mapping, search and rescue operations, and shipping and delivery of goods. A critical task in the deployment of drones is the computation of effective flying paths that allow drones to reach their destinations while avoiding obstacles and minimizing the amount of energy that they need to consume. We present a novel path planning algorithm that is not only faster and uses less memory than other existing path planning algorithms, but it also produces shorter paths. All these performance metric improvements lead to a more energy efficient path planning algorithm for autonomous drones.
Fu Chi Chen, Gopi Gugan, Roberto Solis-Oba, Anwar Haque
ICC4
2021 Fault Localization in Smart Grids Using Segmentation
Jacob Hunte, Hanan Lutfiyya, Anwar Haque
ICC3
2021 Clustering-Coefficient Based Resiliency Approach for Smart Grid
abstract
Maintaining a power grid's functions is of paramount importance to grid operators as power is essential to almost all aspects of daily human activities. Grid resiliency keeps services up to the customers even upon failure incidences. A modernized power grid should balance the power load and overcome the fault state by minimizing its impact. Resiliency researchers have proposed many schemes for post-failure grid incidents. However, there is not yet an overall framework that combines both in-depth analyses of low-level topological characteristics to evaluate the existing grid resiliency and then improve it whenever required. In this paper, we present microlevel topological and resilience analysis of multiple IEEE bus systems. We propose a two-phase resilience framework for the smart power grid: the resiliency evaluation and the resiliency enhancement. While the first phase provides empirical evidence of the sufficiency of exploring a limited number of backup power lines upon an incident, the second phase employs clustering coefficient as a key indicator to enhance grid resiliency. We implement our proposed framework, validate it and show its effectiveness using the IEEE 14-bus system.
Yaser Al Mtawa, Anwar Haque
IWCMC2
2021 A Multi-Factor Authenticated Blockchain-Based OTA Update Framework for Connected Autonomous Vehicles
abstract
The Connected Autonomous Vehicles (CAVs) are embedded with dozens of electronic units and sensors heavily reliant on vehicle's software systems for their secure and reliable operations. This software system must always stay updated for providing a secure and uninterrupted service to CA V. While the automated OTA (Over-The-Air) software and firmware updates for autonomous vehicles is essential for their safe operation, the potential system failure and cybersecurity threats remain a major concern for secure OTA update. This paper introduces a blockchain-based, highly adaptable solution for keeping the CA V OTA software systems updated in real-time while offering faster processing speed and a high level of security against possible cyber-attacks. Our proposed scheme ensures that only authorized OEM (Original Equipment Manufacturer) can upload new software and updated versions in the cloud, and only the certified vehicles download and install the updates. Our framework guarantees a faster, scalable, and multi-factor authentication system for a secure real-time software update service for CA V s.
Sadia Yeasmin, Anwar Haque
VTC Fall2
2021 Efficient execution plan for egress traffic engineering
Ibrahim Shaer, Greg Sidebottom, Anwar Haque, Abdallah Shami
Comput. Networks3
2021 Migrating From Legacy to Software Defined Networks: A Network Reliability Perspective
abstract
Designing survivable communication networks to achieve carrier-grade five-nines reliability is of paramount importance for the network operators. This article addresses service reliability and its related aspects such as nodal reachability, network connectivity, and edge-disjoint routing in both traditional networks and software defined networks (SDNs). The proposed roadmap is based on two phases: Fundamental analytical phase and performance evaluation phase. In the first phase, a graph operator is defined to analyze the characteristics of the reliability metric and its associated reachability feature. This phase will focus on both the macro- and micro-level properties of reliability. In the second phase, we exploit the analysis in the former phase to get an insight into the performance evaluation of traditional and SDN-based networks against the reliability metric, and then calculate the statistical significance of the mean difference of their reliability values. Reliability under edge-disjoint paths to avoid resource competition is also investigated. Various types of topologies are utilized to test the service reliability of both architecture designs. Extensive simulation results show that SDN-based networks have comparable performance to its legacy counterpart against the operational reliability metric. Our findings not only shed light on enhancing reliability using edge-disjoint paths under link failure scenarios but also expected to benefit the operators to achieve their service level objectives while migrating from legacy to SDN-based platform.
Yaser Al Mtawa, Anwar Haque, Hanan Lutfiyya
IEEE Trans. Reliab.2
2020 Reliability-based Formation of Cloud Federations Using Game Theory
abstract
Cloud federation is one form of the cloud computing model that supports numerous types of applications through collaboration between different service providers. Cloud federation enables providers to offer more efficient services to customers by sharing their computing and storage resources. However, the reliability of cloud can be degraded if the federation is formed and executed in an unreliable fashion. In this paper, we propose a reliability-based cloud federation model. We evaluate the reliability of different service providers using our evaluation approach and then model the federation process as a hedonic coalition formation game based on a reliability-driven utility function. Our proposed federation formation algorithm enables service providers to cooperate while considering the reliability of the infrastructure and refrain from cooperating with unreliable systems. Our evaluation shows that the providers will be able to form acceptable federations through our algorithm while preserving or enhancing the reliability of their services in a reasonable amount of time.
A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine
GLOBECOM3
2020 NIMA (Network Impact Modeling and Analysis): A QoS Perspective
abstract
The mammoth Internet traffic growth puts a significant load on Internet Service Provider's (ISP) network capacity which impacts a wide range of network Quality of Service (QoS) metrics such as latency, jitter, throughput, packet loss, link utilization, load balancing, and service availability. From the ISP's perspective, understanding the possible impact of the future Internet traffic on its network QoS is critical for provisioning their network capacity in a cost-effective manner while meeting Service Level Agreement (SLA) between an operator and its customers. To achieve the above goal, one needs a mechanism that is capable of taking input from the projected future traffic, assign the forecasted traffic over the end-to-end network, and then analyses the impact on the network's QoS status. In this paper, we developed a novel network planning framework, namely Network Impact Modeling and Analysis (NIMA) that uses novel methods and techniques to alert ISP's network capacity planners on the: (a) links that are subject to high-risk in terms of congestion; (b) impact on latency, jitter, packet loss, and throughput; (c) impact on load balancing; and finally suggests an optimal routing strategy that can improve the overall network health. For simulation purposes, we used Mininet in combination with a floodlight controller for implementation. The experiments are performed on different sized mesh topologies to test the effectiveness of our proposed framework.
Tarandeep Randhawa, Anwar Haque
GLOBECOM2
2020 Multi-Objective Interdependent VM Placement Model based on Cloud Reliability Evaluation
abstract
Virtual Machine (VM) placement is considered as one of the crucial problems in Cloud Computing environments. From the perspective of Cloud Service Providers (CSPs), finding the optimal VM placement strategy is often related to optimal resource utilization, revenue maximization, and energy efficiency. However, to ensure the continuity of customer services, CSPs should also consider the reliability of deployed applications when placing VMs on their infrastructures. Existing research in this area either do not focus on the Cloud reliability evaluation aspect or do not account for the trade-off between reliability and performance in the VM placement process. In this paper, we propose a multi-objective placement model for interdependent VMs in the Cloud that considers both reliability and workload. Reliability in our model is quantitatively evaluated through a set of metrics that we propose. The model involves an Integer Linear Programming problem that aims at maximizing the reliability of the Cloud while minimizing network delay. A multi-objective genetic algorithm is then used to solve the problem heuristically. The proposed model introduces a level of flexibility and its parameters could be adjusted depending on the requirements of the infrastructure and services. The results show that our model achieves high Cloud reliability and allows to effectively control the trade-off between reliability and Quality of Service.
A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine
ICC3
2020 Multi-Component V2X Applications Placement in Edge Computing Environment
abstract
Vehicle-to-everything (V2X) services are attracting a lot of attention in the research and industry communities due to their applicability in the landscape of connected and autonomous vehicles. Such applications have stringent performance requirements in terms of complex data processing and low latency communications which are utilized to ensure road safety and improve road conditions. To address these challenges, the placement of V2X applications through leveraging of edge computing paradigm, that distributes the computing capabilities to access points in proximity to the vehicles, presents itself as a viable solution. However, the realistic implementation of the edge enabled V2X applications is hindered by the limited computational power provided at the edge and the nature of V2X applications that are composed of multiple independent V2X basic services. To address these challenges, this work targets the efficient placement of V2X basic services in a highway scenario subject to the delay constraints of V2X applications using them and the limited computational resources at the edge. To that end, this work formulates a binary integer linear programming model that minimizes the delay of V2X applications while satisfying the resource requirements of V2X basic services. To demonstrate the soundness of the approach, simulations with varying vehicle densities were conducted, and the results reported show that it can satisfy the delay requirements of V2X applications.
Ibrahim Shaer, Anwar Haque, Abdallah Shami
ICC2
2020 Optimizing Virtual Machine Migration in Multi-Clouds
abstract
Cloud computing is susceptible to failures. Allocating Virtual machine (VM) in a reliable fashion is considered as one of the crucial problems in Cloud computing environment. Most researchers choose the optimal VM allocation based on resource utilization and cost minimization. However, to protect the reputation of cloud providers, service reliability should be addressed appropriately. In this paper, we propose a Markov-based failure prediction model to anticipate the failure of Cloud servers. Our model anticipates a deteriorating server state based on historical data. Server reliability prediction is then integrated into a VM re-allocation approach in a Multi-Cloud setting to optimize fault tolerance by maximizing Cloud reliability while reducing communication delay. The optimization problem is solved optimally and heuristically using the Artificial Bee Colony (ABC) algorithm. The results show that our model enhances reliability and minimizes communication delay between the VMs following service migration.
A. B. M. Bodrul Alam, Talal Halabi, Anwar Haque, Mohammad Zulkernine
ISNCC3
2020 Towards the Development of a Novel Service Cost Modeling: An ISP Perspective
abstract
Accurate costing provides insightful information to any Internet Service Provider (ISP) for better network planning, profits, and decision making. Developing accurate cost models for communication network services has always been a challenge for ISPs / cloud operators due to the complex nature of today's advanced shared cloud and network infrastructure. Currently, developing and maintaining such cost models require significant effort and time by the network planners in an ISP. The proposed novel methodology reduces the cycle time for the development of the cost model significantly, which leads to the ISP's operational cost savings. We have considered an Internet Protocol Virtual Private Network (IPVPN) service for the study. IPVPN creates a logical virtual network by providing an encrypted and dedicated data connection. We conducted simulations to validate the accuracy and effectiveness of the proposed model. We have compared our proposed method with the existing approach and compute the performance improvement cost gap for different network sizes. To prove the operational savings, we evaluated a quantitative example concerning both methods investigated. We also experimented with a machine learning technique for the study, which provided complementary results.
Yasmeen Ali, Anwar Haque, Bassel Bitar
ISNCC2
2020 Towards Network Traffic Monitoring Using Deep Transfer Learning
abstract
Network traffic is growing at an outpaced speed globally. The modern network infrastructure makes classic network intrusion detection methods inefficient to classify an inflow of vast network traffic. This paper aims to present a modern approach towards building a network intrusion detection system (NIDS) by using various deep learning methods. To further improve our proposed scheme and make it effective in real-world settings, we use deep transfer learning techniques where we transfer the knowledge learned by our model in a source domain with plentiful computational and data resources to a target domain with sparse availability of both the resources. Our proposed method achieved 98.30% classification accuracy score in the source domain and an improved 98.43% classification accuracy score in the target domain with a boost in the classification speed using UNSW -15 dataset. This study demonstrates that deep transfer learning techniques make it possible to construct large deep learning models to perform network classification, which can be deployed in the real world target domains where they can maintain their classification performance and improve their classification speed despite the limited accessibility of resources.
Harsh Dhillon, Anwar Haque
TrustCom2
2020 Towards the Development of a Robust Path Planner for Autonomous Drones
abstract
Path planning is a major challenge surrounding the development of autonomous drones. For a practical solution, a computationally inexpensive and efficient path planning algorithm needs to be utilized to ensure the smooth operation of drones during long distance missions. Randomly Exploring Random Trees (RRT) and RRT* are sampling based path planning algorithms that have been widely used to solve high dimensional complex problems. RRT* ensures asymptotic optimality; however, it requires a long time to converge to a near optimum solution. RRT* variants have been proposed to improve the rate of convergence. Although many RRT* variants have been proposed, to the best of our knowledge, there has not been a comprehensive analysis comparing the performance of these algorithm. In this study, we perform a detailed comparison of a select group of RRT* variants with RRT and RRT* to determine its potential to be used as a path planner for autonomous drones. We review each algorithm and evaluate its performance by investigating the path cost, execution time and the number of nodes required to generate a path. Experimental results suggest that the performance of the RRT* variants is generally dependent on the type of the environment.
Gopi Gugan, Anwar Haque
VTC Spring2
2019 Towards a Customized Resiliency Framework for Smart Grid
abstract
Introducing resiliency in a legacy power grid is one of the core mandates of smart grid architecture. Resiliency in power grid enables electrical distribution companies to maintain their services to the customers in the event of a grid failure. Its main advantages appear during the fault event: balance the power load and overcome the fault state by minimizing its impact. Although researchers have proposed many schemes for post-failure events to isolate faults (under certain conditions), yet there is no overall framework to evaluate the resiliency of the existing power grid and to improve it if required to recover from fault incidents successfully. In this paper, we propose a two-phase resiliency framework for the smart power grid. The first phase aims to assess the resiliency of a power grid. This phase provides important information regarding the weaknesses and the strengths of a power grid. Phase two will process the input of phase one to increase resiliency by employing redundant grid's elements such as power lines and poles to back up/strengthen the vulnerable components. This preventive framework increases the overall grid resiliency and enables providing an efficient self-recovery policy upon any possible power failure. To achieve this goal, we utilize graph-theoretic metrics, mainly distortion metric, to implement our proposed framework. The proposed framework is implemented and its effectiveness with link failure events is demonstrated through three IEEE bus systems: 14, 30, and 118.
Yaser Al Mtawa, Anwar Haque, Hanan Lutfiyya
GLOBECOM2
2019 RADR: Routing for Autonomous Drones
abstract
Path planning is one of the major challenges surrounding the development of autonomous drones. This paper presents an approach which can be utilized by autonomous drones to successfully travel from a source point to a destination point using Dijkstra's shortest path algorithm. This approach involves processing a 2D image of the environment in order to limit the search area, converting the image into a network and then applying Dijkstra's algorithm to determine the shortest path. Tests were conducted to determine if the algorithm correctly detects a nonexistent path. Finally, we discuss future direction for this algorithm to improve its performance and applicability for drone surveillance.
Nicole Chow, Gopi Gugan, Anwar Haque
IWCMC3
2019 Evaluating QoS in SDN-Based EPC: A Comparative Analysis
abstract
Software Defined Networking (SDN) is an emerging paradigm in networking and of high interest to the mobile network operators due to its potential benefit in improving network performance. The idea of integrating SDN in mobile network architecture, such as in LTE-evolved packet core (EPC), has already been proposed by many researchers. The SDN-based EPC network offers better Quality of Service (QoS) which is critical to the successful delivery of real-time multimedia applications in the mobile operator networks. In this paper, we provide state-of-the-art work to evaluate and analyze the QoS metrics in real-time services. We conduct a comprehensive comparison between the performance of EPC and SDN-based EPC regarding latency, jitter, and packet loss. We inject active probe packets in the networks to collect statistical data about the metrics. Various levels of workload are applied to test the robustness and stability of both EPC and SDN-based EPC designs. Our results show that SDN-based EPC significantly outperforms its legacy counterpart in all three QoS metrics. To the best of our knowledge, our study is the first comparative analysis that evaluates QoS in EPC and SDN-based EPC for real-time applications.
Yaser Al Mtawa, A. Memari, Anwar Haque, Hanan Lutfiyya
IWCMC3
2019 Analysis of the Effect of QoS on Video Conferencing QoE
abstract
Network service providers tend to focus on the quality of service (QoS) they provide to their customers. This entails analysis of various QoS metrics (such as bandwidth, packet loss and jitter) in order to be able to improve their services. This is a single-dimensional approach to a problem that needs to be analyzed not only from a business improvement perspective but also from a customer satisfaction perspective. QoS metrics do not directly translate to customer experience, which is more qualitative than quantitative. Thus, it is necessary to correlate qualitative metrics that customers relate to with quantitative metrics that can be analyzed and improved upon by service providers. This is a non-trivial problem that needs deeper exploration. In this paper, we attempt to correlate video conferencing QoE (Quality of Experience) with network QoS. In order to do this, we developed a novel Docker image called Lime, to be able to automate the experiments and emulate the network environment. We performed 144 separate video conferences under predefined network handicaps (scenarios). We discovered that bandwidth is directly proportional to the perceived quality of the video implying that higher bandwidth is preferred. On the other hand, frequently fluctuating bandwidth quickly reduced the user-opinion, and also resulted in slower subsequent climb in opinion after a period of high fluctuation. This indicated that steady bandwidth is preferred over irregularly increasing bandwidth. Jitter and packet loss were found to contribute to negative user-opinion as well as low bandwidth. Conversely, increasing jitter and packet loss was mostly forgiven if the bandwidth stayed stable and high. Lime is shown to be a novel tool to fulfill requirements related to video conferencing experiments under pre-defined network scenarios.
Nanditha Rao, Amir Haghighati Maleki, Fu Chi Chen, Anwar Haque
IWCMC7
2019 Towards a Security Architecture for Protecting Connected Vehicles from Malware
abstract
Vehicles are becoming increasingly connected to the outside world. We can connect our devices to the vehicle's infotainment system and internet is being added as a functionality. Therefore, security is a major concern as the attack surface has become much larger than before. Consequently, attackers are creating malware that can infect vehicles and perform life-threatening activities. For example, a malware can compromise vehicle ECUs and cause unexpected consequences. Hence, ensuring the security of connected vehicle software and networks is extremely important to gain consumer confidence and foster the growth of this emerging market. In this paper, we propose a characterization of vehicle malware and a security architecture to protect vehicle from these malware. The architecture uses multiple computational platforms and makes use of the virtualization technique to limit the attack surface. There is a real-time operating system to control critical vehicle functionalities and multiple other operating systems for non-critical functionalities (infotainment, telematics, etc.). The security architecture also describes groups of components for the operating systems to prevent malicious activities and perform policing (monitor, detect, and control). We believe this work will help automakers guard their systems against malware and provide a clear guideline for future research.
Shahrear Iqbal, Anwar Haque, Mohammad Zulkernine
VTC Spring2
2018 CREM: A Cloud Reliability Evaluation Model
abstract
Reliability analysis of cloud is not a trivial task due to the complexity and scalability of cloud-based systems. This paper proposes a novel model for evaluating cloud reliability in an effective manner. To provide an appropriate evaluation model, this paper also outlines a classification strategy for cloud failures and considers several types of failures from different domains of cloud environment to properly evaluate the reliability. The effectiveness and applicability of the proposed evaluation model has been demonstrated through simulation results. The results show that execution stage failures have more influence on the cloud reliability than the request processing stage failures.
A. B. M. Bodrul Alam, Anwar Haque, Mohammad Zulkernine
GLOBECOM2
2018 Does Internet of Things Disrupt Residential Bandwidth Consumption?
abstract
The Internet of Things (IoT) aims to connect smart devices communicating and collaborating while providing a wide range of services. Fixed-access Internet traffic grows globally for many reasons such as increasing number of connected devices, and the number of people who utilize the Internet. IoT, video streaming, 4K technology, and virtual and augmented reality (VR/AR) are some applications and services that have the major impact on Internet traffic. Many research and industry communities believe that the Internet of things (IoT) will be the top driver of bandwidth of fixed-access Internet in the future. In this paper, we compare IoT's impact with other bandwidth drivers such as video streaming, 4K technology, and VR/AR, and we investigate whether or not IoT will have a disruptive impact on the residential bandwidth in the near future. We design our model to forecast the residential Internet bandwidth by 2021 and measure the contribution of IoT to this projection. Our model includes all possible types of households and their bandwidth consumption behaviors. Our results show that video entertainment with 4K technology along with VR/AR will be the top drivers of future bandwidth, while IoT will be of least impact among them. Our model shows that 50% of households will require ≤ 78 Mbps, and 62% of households will require <; 100 Mbps, meaning 12% of households will require between 78 and 100 Mbps. Furthermore, only 10% of households will demand more than 300 Mbps by 2021, and nearly half of them will use more than 500 Mbps.
Yaser Al Mtawa, Anwar Haque, Bassel Bitar
VTC Fall2
2008 A Distributed Defense Framework for Flooding-Based DDoS Attacks
abstract
A flooding-based distributed denial of service (DDoS) attack sends a large amount of unwanted traffic to a victim machine. Existing network-level congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. We propose a distributed framework to defend against DDoS attacks. It has three major components: detection, traceback, and traffic control. We present the traffic control component in detail in this paper. A distance-based rate limit mechanism is proposed to allow the traffic control component at the victim end request the defense systems at the source end to set up rate limits on the edge routers of the attack source ends. This rate limit mechanism efficiently reduces attack traffic from being forwarded to the victim. We evaluate the DDoS defense framework using the NS2 platform. The results demonstrate that the framework can effectively control attack traffic to sustain quality of service for legitimate traffic compared to the pushback technique.
Yonghua You, Mohammad Zulkernine, Anwar Haque
ARES3
2008 TROP: A Novel Approximate Link-State Dissemination Framework For Dynamic Survivable Routing in MPLS Networks
abstract
In this paper, a novel approximate link-state dissemination framework, called TROP, is proposed for shared backup path protection (SBPP) in multiprotocol label switching (MPLS) networks. While performing dynamic explicit survivable routing in a distributed environment, link-state dissemination may cause a nontrivial signaling overhead in the process of exploring spare resource sharing among individual backup label switched paths (LSPs). Several previously reported studies have tackled this problem by initiating a compromise between the amount of dissemination and the achievable extent of resource sharing. The paper first summarizes the previously reported schemes into a compact and general link-state dissemination framework by way of singular value decomposition (SVD). To improve the accuracy of the matrix reconstruction and to eliminate the overestimation of the sharable spare capacity along each link, a novel SVD approach based on the min-plus algebra (also called tropical semirings) is introduced. Simulation results show that the proposed schemes can achieve a lower blocking probability than that by all the other counterpart schemes while taking the same complexity of link-state dissemination. This great advantage is gained at the expense of a longer computation time for solving a linear program (LP) in each dissemination cycle at the core nodes. We also consider the stale link-state phenomena that may cause imprecision in the routing information at the ingress nodes due to the delay in the periodic/event-driven link-state update message advertisement.
János Tapolcai, Pin-Han Ho, Anwar Haque
IEEE Trans. Parallel Distributed Syst.3
2008 Spare Capacity Reprovisioning for Shared Backup Path Protection in Dynamic Generalized Multi-Protocol Label Switched Networks
abstract
Spare capacity allocation serves as one of the most critical tasks in dynamic GMPLS networks to meet the stringent network availability constraint stipulated in the SLA of each connection. In this paper, an availability-aware spare capacity reconfiguration scheme based on shared backup path protection (SBPP) is proposed, aiming to guarantee the E2E availability of each LSP. We first provide an E2E availability model for a SBPP connection that is composed of a working and a SRG-disjoint shared backup LSP pair in the presence of all possible single, and dual simultaneous failures. Partial restoration is identified to further improve the capacity efficiency, and achieve finer service differentiation. For this purpose, restoration attempt is defined as a parameter for each connection that can be manipulated at the source node when the spare capacity of each link is scheduled. Based on the developed model, a linear program (LP) is formulated to perform inter-arrival spare capacity reconfiguration along each pre-determined shared backup LSP to meet the availability constraint of each connection. Simulation is conducted to verify the derived formulation, and to demonstrate the benefits gained in terms of the spare capacity saving ratio, where the conventional SBPP scheme that achieves 100% restorability for any single failure is taken as a benchmark. We will show that the simulation results validate the proposed E2E availability model, where a significant reduction on the required redundancy can be achieved in the effort of meeting a specific availability constraint for each SBPP connection.
Pin-Han Ho, János Tapolcai, Anwar Haque
IEEE Trans. Reliab.3
2008 A New Shared Segment Protection Method for Survivable Networks with Guaranteed Recovery Time
abstract
Shared segment protection (SSP), compared with shared path protection (SPP), and shared link protection (SLP), provides an optimal protection configuration due to the ability of maximizing spare capacity sharing, and reducing the restoration time in cases of a single link failure. This paper provides a thorough study on SSP under the GMPLS-based recovery framework, where an effective survivable routing algorithm for SSP is proposed. The tradeoff between the price (i.e., cost representing the amount of resources, and the blocking probability), and the restoration time is extensively studied by simulations on three networks with highly dynamic traffic. We demonstrate that the proposed survivable routing algorithm can be a powerful solution for meeting stringent delay upper bounds for achieving high restorability of transport services. This can significantly improve the network reliability, and enable more advanced, mission critical services in the networks. The comparison among the three protection types further verifies that the proposed scheme can yield significant advantages over shared path protection, and shared link protection.
János Tapolcai, Pin-Han Ho, Dominique Verchère, Tibor Cinkler, Anwar Haque
IEEE Trans. Reliab.5
2008 Random-Forests-Based Network Intrusion Detection Systems
abstract
Prevention of security breaches completely using the existing security technologies is unrealistic. As a result, intrusion detection is an important component in network security. However, many current intrusion detection systems (IDSs) are rule-based systems, which have limitations to detect novel intrusions. Moreover, encoding rules is time-consuming and highly depends on the knowledge of known intrusions. Therefore, we propose new systematic frameworks that apply a data mining algorithm called random forests in misuse, anomaly, and hybrid-network-based IDSs. In misuse detection, patterns of intrusions are built automatically by the random forests algorithm over training data. After that, intrusions are detected by matching network activities against the patterns. In anomaly detection, novel intrusions are detected by the outlier detection mechanism of the random forests algorithm. After building the patterns of network services by the random forests algorithm, outliers related to the patterns are determined by the outlier detection algorithm. The hybrid detection system improves the detection performance by combining the advantages of the misuse and anomaly detection. We evaluate our approaches over the knowledge discovery and data mining 1999 (KDDpsila99) dataset. The experimental results demonstrate that the performance provided by the proposed misuse approach is better than the best KDDpsila99 result; compared to other reported unsupervised anomaly detection approaches, our anomaly detection approach achieves higher detection rate when the false positive rate is low; and the presented hybrid system can improve the overall performance of the aforementioned IDSs.
Mohammad Zulkernine, Anwar Haque
IEEE Trans. Syst. Man Cybern. Part C3
2007 Availability-Constrained Shared Backup Path Protection (SBPP) for GMPLS-Based Spare Capacity Reprovisioning
abstract
Shared-backup path protection (SBPP) has been widely studied in the GMPLS networks due to its efficient spare capacity sharing and flexibility in service provisioning. This paper presents a model for evaluating the end-to-end (E2E) availability of an SBPP connection by assuming that no more than two simultaneous failures could possibly occur in the network. To minimize the redundancy while meeting the E2E availability requirement, a framework of partial restoration from any unexpected failure is created. Based on the proposed availability model, a novel Linear Program (LP) formulation is introduced, which aims to perform the spare capacity allocation for SBPP connections. A new availability-aware spare capacity reprovisioning (SCR) architecture is then introduced for dynamic provisioning of SBPP connections. Extensive simulations are conducted to validate the proposed availability model and demonstrate the effectiveness of the SCR architecture.
Pin-Han Ho, Anwar Haque, Hussein T. Mouftah
ICC3
2007 Detecting Flooding-Based DDoS Attacks
abstract
A distributed denial of service (DDoS) attack is widely regarded as a major threat for the current Internet because of its ability to create a huge volume of unwanted traffic. It is hard to detect and respond to DDoS attacks due to large and complex network environments. In this paper, we introduce two distance-based DDoS detection techniques: average distance estimation and distance-based traffic separation. They detect attacks by analyzing distance values and traffic rates. The distance information of a packet can be inferred from the time- to-live (TTL) value of the IP header. In the average distance estimation DDoS detection technique, the prediction of mean distance value is used to define normality. The prediction of traffic arrival rates from different distances is used in the distance-based traffic separation DDoS detection technique. The mean absolute deviation (MAD)-based deviation model provides the legal scope to separate the normality from the abnormality for both the techniques. The results obtained from the NS2-based simulations of the proposed techniques show that the techniques can detect attacks
Yonghua You, Mohammad Zulkernine, Anwar Haque
ICC3
2007 E-NIPS: An Event-Based Network Intrusion Prediction System
Pradeep Kannadiga, Mohammad Zulkernine, Anwar Haque
ISC3
2006 A Study on Dynamic Survivable Routing with Availability Constraint for GMPLS-Based Recovery
abstract
This paper introduces a new dynamic availability-aware survivable routing scheme under the framework of generalized multi-protocol label switching (GMPLS)-based recovery, which aims to achieve the best generality for the network operation in meeting the end-to-end (E2E) availability requirement of each connection. The paper first defines the partial restorability, justifies the feasibility of equipping a connection with partial restorability under the GMPLS control plane, and highlights the approach of evaluating the E2E availability for a pair of working and partially restorative SRG (shared risk group)-disjoint shared backup label switched paths (LSPs). A compact matrix expression is developed for modeling the minimum spare capacity along each link and the cost function for solving both of the paths. Based on the developed cost function, a novel integer linear program (ILP) is formulated to dynamically determine the working and backup LSPs of the corresponding connection request with the least amount of total capacity while the E2E availability requirement of the connection is met. We demonstrate that the model is general to the traffic uniformity, connection indivisibility, and working bandwidth restorability compared with the previous studies. Simulation is conducted to verify the proposed ILP model by making a comparison with a number of legacy schemes that achieve 100% restorability in facing a specific number of simultaneous failures, such as shared path protection (SPP), 1+1 protection, and dual-failure protection. In the case study, we have seen merits in the proposed algorithm by significantly reducing the required redundancy in the effort of achieving the given availability constraint for each connection request.
Pin-Han Ho, János Tapolcai, Anwar Haque
BROADNETS3
2006 Multi-Stage Investment Decision under Contingent Demand for Networking Planning
abstract
Telecommunication companies, such as Internet and cellular service providers, are seeing rapid and uncertain growth of amount of traffic routed through their networks. It has become a challenge for these companies to make optimal decisions for equipment purchase that simultaneously satisfy the uncertain future demand while minimizing investment cost. This paper presents a decision-making framework for installing the required equipment into the networks while in the uncertain environment. The framework is based on new multi-stage stochastic programming mathematical models that capture the complexity of the individual Central Office (CO) decision-making process. The models are solved using the online NEOS server. Two examples are presented to illustrate the procedure. The optimization model also addresses the equipment pricing problem, i.e., what premium is worth paying for shorter installation times.
Miguel F. Anjos, Michael Desroches, Anwar Haque, Oleg Grodzevich, Henry Wolkowicz
GLOBECOM3
2006 Inter-Group Shared Protection (I-GSP): A Scalable Solution for Survivable WDM Networks
abstract
The past studies for survivable routing suffers from the scalability problem when the number of nodes or connection requests grows in the network. In this proposal, a novel path based shared protection framework namely Inter-Group Shared protection (I-GSP) is developed such that the traffic matrix can be divided into multiple protection groups (PGs) based on specific grouping policy. This novel scheme not only overcomes the scalability problem but also provides an upper bound on the affected working paths in case of link failure in the network. Experiment results show that I-GSP based integer linear programming model solves the networks in a reasonable amount of time for which a regular integer linear programming formulation becomes computationally intractable. For most of the cases the performance gap between the optimal solution and the proposed I-GSP ranges between (2-16)%. The proposed optimization model yields a scalable and near-optimal solution for the capacity planning in the survivable optical networks.
Anwar Haque, Pin-Han Ho
GLOBECOM1
2006 Group shared protection for spare capacity reconfiguration in optical networks
Anwar Haque, Pin-Han Ho, Raouf Boutaba
Comput. Networks1
2006 A Study on the Design of Survivable Optical Virtual Private Networks (O-VPN)
abstract
This paper tackles the resource allocation problem in wavelength division multiplexing (WDM) networks supporting virtual private networks (O-VPN), in which working, and spare capacity are allocated in the networks for satisfying a series of traffic matrices corresponding to a group of O-VPN. Based on the (M:N)nprotection architecture where multiple protection groups (PG) are supported in a single network domain, we propose two novel integer linear programming (ILP) models, namely ILP-I, and ILP-II, aiming to initiate a graceful compromise between the capacity efficiency, and computation complexity without losing the ability of addressing the quality of service (QoS) requirements in each O-VPN. ILP-I considers all the connection requests of each O-VPN in a single formulation, which may suffer from long computation time when the number of connection requests in an O-VPN is large. To trade capacity efficiency with computation complexity, ILP-II is developed such that each O-VPN can be further divided into multiple small PG based on specific grouping policies that satisfy multiple QoS requirements. With ILP-II, it is expected that all the working, and spare capacity of the O-VPN can be allocated with a polynomial time complexity provided that the size of each PG is well constrained. Experimental results show that, in terms of capacity efficiency, a significant improvement can be achieved by ILP-I compared to that by ILP-II at the expense of much more computation time. Although ILP-II is outperformed by ILP-I, it can handle the situation with an arbitrary size of O-VPN. We conclude that the proposed ILP-II model yields a scalable solution for the capacity planning in the survivable optical networks supporting O-VPN based on the (M:N)n protection architecture
Anwar Haque, Pin-Han Ho
IEEE Trans. Reliab.1
2004 Group shared protection (GSP): a scalable solution for spare capacity reconfiguration in mesh WDM networks
abstract
This paper proposes a novel framework of shared protection, namely group shared protection (GSP), in mesh wavelength division multiplexing (WDM) networks with dynamically arriving connection requests. Based on the (M:N)/sup n/ control architecture, GSP has n mutually independent protection groups, each of which contains N SRLG-disjoint working paths protected by M protection paths. Due to the SRLG-disjointedness of the working paths in each protection group, GSP not only allows the spare capacity to be totally sharable among the corresponding working paths, but also reduces the number of working paths affected due to a single link failure. Based on the framework, an integer linear program (ILP) formulation that can optimally reconfigure the spare capacity for a specific protection group whenever a working-protection path-pair joins is proposed. Two heuristics namely link-shared protection (LSP) and ring-shared protection (RSP) are introduced for further compromising the performance and the computational complexity. The proposed schemes are compared with a reported one, namely successive survivable routing (SSR). The experimental results show that LSP, RSP and SSR yield similar performance in terms of resource sharing, whereas ILP outperforms all of them by (6-16%). Due to the limited number of working paths in each protection group, ILP can handle a dynamically arriving connection request in a reasonable amount of time. Also, we find that the number of affected working paths in GSP is about half of that in SSR. We conclude that GSP provides a scalable and efficient solution for dynamic spare capacity reconfiguration following the (M:N)/sup n/ control architecture.
Anwar Haque, Pin-Han Ho, Raouf Boutaba, James Ho
GLOBECOM1