Mumin Cebe

dblp:97/5901 · DBLP profile ↗
← Back
16ranked-venue papers
9as first author
5since 2021 · last 2024
0000-0003-2843-8904ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 4 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2024 CyberLlama2 - MEDICALHARM Threat Modeling Assistant
abstract
Threat Modeling, a shift-left cybersecurity activity to build security into a software design, has become a challenge for many industries, including Modern Medical Devices. With the advancement of Large Language Models (LLM), more industries are adopting this phenomenon to understand and solve domain-specific challenges. However, thus far, little research has evaluated the effectiveness of LLM in solving threat modeling challenges. To alleviate this problem, we developed a threat modeling assisted LLM to assist MEDICALHARM in identifying cybersecurity, privacy, and safety threats in the Modern Medical Device space. We developed a specialized decoder-only model, CyberLlama2, to assist threat modeling using a large set of -146k- cybersecurity instructions to fine-tune Llama2. The results show an improved performance of our proposed CyberLlama2 model over the baseline and other cybersecurity models.
Emmanuel Kwarteng, Mumin Cebe, Jamila Kwarteng
ICMLA2
2024 D-LNBot: A Scalable, Cost-Free and Covert Hybrid Botnet on Bitcoin's Lightning Network
abstract
While various covert botnets were proposed in the past, they still lack complete anonymization for their servers/botmasters or suffer from slow communication between the botmaster and the bots. In this paper, we first propose a new generation hybrid botnet that covertly and efficiently communicates over Bitcoin Lightning Network (LN), called LNBot. Exploiting various anonymity features of LN, we show the feasibility of a scalable two-layer botnet which completely anonymizes the identity of the botmaster. In the first layer, the botmaster anonymously sends the commands to the command and control (C&C) servers through regular LN payments. Specifically, LNBot allows botmaster's commands to be sent in the form of surreptitious multi-hop LN payments, where the commands are either encoded with the payments or attached to the payments to provide covert communications. In the second layer, C&C servers further relay those commands to the bots in their mini-botnets to launch any type of attacks to victim machines. We further improve on this design by introducing D-LNBot; a distributed version of LNBot that generates its C&C servers by infecting users on the Internet and forms the C&C connections by opening channels to the existing nodes on LN. In contrary to the LNBot, the whole botnet formation phase is distributed and the botmaster is never involved in the process. By utilizing Bitcoin's Testnet and the new message attachment feature of LN, we show that D-LNBot can be run for free and commands are propagated faster to all the C&C servers compared to LNBot. We presented proof-of-concept implementations for both LNBot and D-LNBot on the actual LN and extensively analyzed their delay and cost performance. Finally, we also provide and discuss a list of potential countermeasures to detect LNBot and D-LNBot activities and minimize their impacts.
Ahmet Kurt, Enes Erdin, Kemal Akkaya, A. Selcuk Uluagac, Mumin Cebe
IEEE Trans. Dependable Secur. Comput.5
2023 MEDICALHARM - A Threat Modeling designed for Modern Medical Devices
abstract
Modern Medical Devices (MMDs) are a rapidly growing field of medical technology, and recent advances have allowed them to monitor and manage patients’ health remotely. As these devices become more connected in order to enhance the delivery of patient care, the concerns surrounding security, privacy, and safety are also increasing. To effectively address these concerns, "shift-left security"-which involves addressing security risks as early as possible-is becoming increasingly important. To facilitate it, threat modeling must be implemented as the first step. While various threat modeling methodologies exist, MMDs need a tailored one that can take into account the safety of patients and the complexity of a typical Medical Device (MD), which contains multiple sensors and actuators. Therefore, we present a new threat modeling methodology -MEDICALHARM- tailored to identifying threats in MMD systems. MEDICALHARM delivers a holistic approach by combining threat and risk analysis under the same scheme. It specifically articulates safety threats along with security and privacy threats. Furthermore, it offers an algorithmic scheme to enable non-security experts (engineers and developers) to easily participate in the threat modeling process. To illustrate its benefits, we perform a threat modeling exercise using MEDICALHARM on a Deep Brain Stimulation device and provide an exhaustive threats document. We then compare the results of this exercise with another threat model scheme (STRIDE) to demonstrate MEDICALHARM’s efficiency in threat identification.
Emmanuel Kwarteng, Mumin Cebe
TrustCom2
2021 Communication-efficient certificate revocation management for Advanced Metering Infrastructure and IoT Integration
Mumin Cebe, Kemal Akkaya
Future Gener. Comput. Syst.1
2021 A scalable private Bitcoin payment channel network with privacy guarantees
Enes Erdin, Mumin Cebe, Kemal Akkaya, Eyuphan Bulut, A. Selcuk Uluagac
J. Netw. Comput. Appl.2
2020 LNBot: A Covert Hybrid Botnet on Bitcoin Lightning Network for Fun and Profit
Ahmet Kurt, Enes Erdin, Mumin Cebe, Kemal Akkaya, A. Selcuk Uluagac
ESORICS (2)3
2020 A Bitcoin payment network with reduced transaction fees and confirmation times
Enes Erdin, Mumin Cebe, Kemal Akkaya, Senay Solak, Eyuphan Bulut, A. Selcuk Uluagac
Comput. Networks2
2019 A Replay Attack-Resistant 0-RTT Key Management Scheme for Low-Bandwidth Smart Grid Communications
abstract
With the increasing digitization of different components of Smart Grid, there is an ongoing effort to design secure protocols and deploy them for different applications. A major need along with these efforts is to deal with key management for a large number of devices which are resource constrained and deployed within a very legacy communication environment. As the utilities rightly request to build the new systems on top of the legacy systems with limited investment, the research community needs to re-think the adaptation of the existing security approaches to such non-traditional environments. Assuming a legacy (i.e., 2G) radio communication infrastructure with bandwidths in the order of kilobits, the goal of this study is to enable basic security services in Smart Grid via a lightweight key management scheme. Specifically, the proposed scheme provides mutual authentication, key agreement, and key refreshment by utilizing a 0-RTT message exchange that relies neither on PKI or session resumption. It depends on dynamic hash chains to enable authentication and prevent any replay attacks. The evaluations results show that the proposed scheme out-performs other conventional approaches such as TLS and IKE and is suitable for Smart Grid legacy environments.
Mumin Cebe, Kemal Akkaya
GLOBECOM1
2019 Performance evaluation of key management schemes for wireless legacy smart grid environments: poster
abstract
With the increasing digitization of different components of Smart Grid, there is an ongoing effort to design secure protocols and deploy them for different applications. A major need along with these efforts is to deal with key management for a large number of devices. While key management can be easily addressed by transferring the existing protocols to Smart Grid domain, this is not an easy task as one needs to deal with the limitations of the current communication infrastructures and resource-constrained devices. As the utilities rightly requests to build the new systems on top of the legacy systems with limited investment, the research community needs to re-think the adaptation of the existing security approaches to such non-traditional environments. This poster aims to tackle one of these problems, namely, symmetric key management in a severely constrained wireless communication environment. Assuming a legacy radio communication infrastructure with bandwidths in the order of kilobits, the objective is to evaluate the feasibility and performance of the existing sophisticated key management protocols. We developed a realistic ns-3 environment and analyze the delay overhead via simulations.
Mumin Cebe, Kemal Akkaya
WiSec1
2019 On the overhead of using zero-knowledge proofs for electric vehicle authentication: poster
abstract
As Electric Vehicles (EVs) are becoming widely available, their secure management is crucial to fully enable their potential. For instance, for convenient charging, they may require quick authentication with the charging stations while they are on the go. As charging is frequently needed, exposing one's charging frequency to the stations may risk the exposure of privacy for the EV driver. Therefore, a mechanism is needed to hide EV information. In this paper, we propose using zero-knowledge proofs to achieve this goal. While zero-knowledge proofs can provide anonymous authentication, they require computation for generation of witnesses. Therefore, we assess the overhead of generating a witness and proof computation at the resource constrained on-board units (OBUs) which are deployed on EVs that utilize wireless communications for scheduling. The results indicate that computation overhead is minimal and can be delployed on resource contrained devices.
David Gabay, Mumin Cebe, Kemal Akkaya
WiSec2
2019 Efficient certificate revocation management schemes for IoT-based advanced metering infrastructures in smart cities
Mumin Cebe, Kemal Akkaya
Ad Hoc Networks1
2018 Efficient Public-Key Revocation Management for Secure Smart Meter Communications Using One-Way Cryptographic Accumulators
abstract
Advanced Metering Infrastructure (AMI) forms a communication network for the collection of power data from smart meters in Smart Grid. As the communication within an AMI needs to be secure, public-key cryptography can be used to reduce the overhead of key management. However, it still has certain challenges in terms of certificate revocation and management. In particular, distribution and storage of the Certificate Revocation List (CRL), which holds the revoked certificates, is a major challenge due to its overhead. To address this challenge, in this paper, we propose a novel revocation management scheme by utilizing cryptographic accumulators which not only reduces the space requirements for revocation information but also enables convenient distribution of revocation information to all smart meters. We implemented this one-way cryptographic accumulator-based revocation scheme on ns- 3 using IEEE 802.11s mesh standard as a model for AMI and demonstrated its superior performance with respect to traditional methods of CRL management through extensive simulations.
Mumin Cebe, Kemal Akkaya
ICC1
2018 A Network Coding Based Information Spreading Approach for Permissioned Blockchain in IoT Settings
abstract
Permissioned Blockchain (PBC) has become a prevalent data structure to ensure that the records are immutable and secure. However, PBC still has significant challenges before it can be realized in different applications. One of such challenges is the overhead of the communication which is required to execute the Byzantine Agreement (BA) protocol that is needed for consensus building. As such, it may not be feasible to implement PBC for resource constrained environments such as Internet-of-Things (IoT). In this paper, we assess the communication overhead of running BA in an IoT environment that consists of wireless nodes (e.g., Raspberry PIs) with meshing capabilities. As the the packet loss ratio is significant and makes BA unfeasible to scale, we propose a network coding based approach that will reduce the packet overhead and minimize the consensus completion time of the BA. Specifically, various network coding approaches are designed as a replacement to TCP protocol which relies on unicasting and acknowledgements. The evaluation on a network of Raspberry PIs demonstrates that our approach can significantly improve scalability making BA feasible for medium size IoT networks.
Mumin Cebe, Berkay Kaplan, Kemal Akkaya
MobiQuitous1
2017 Efficient Management of Certificate Revocation Lists in Smart Grid Advanced Metering Infrastructure
abstract
Advanced Metering Infrastructure (AMI) forms a communication network for the collection of power data from smart meters in Smart Grid. As the communication within an AMI needs to be secure, key management becomes an issue due to overhead and limited resources. While using public-keys eliminate some of the overhead of key management, there is still challenges regarding certificates that store and certify the public-keys. In particular, distribution and storage of certificate revocation list (CRL) is major a challenge due to cost of distribution and storage in AMI networks which typically consist of wireless multi-hop networks. Motivated by the need of keeping the CRL distribution and storage cost effective and scalable, in this paper, we present a distributed CRL management model utilizing the idea of distributed hash trees (DHTs) from peer-to-peer (P2P) networks. The basic idea is to share the burden of storage of CRLs among all the smart meters by exploiting the meshing capability of the smart meters among each other. Thus, using DHTs not only reduces the space requirements for CRLs but also makes the CRL updates more convenient. We implemented this structure on ns-3 using IEEE 802.11s mesh standard as a model for AMI and demonstrated its superior performance with respect to traditional methods of CRL management through extensive simulations.
Mumin Cebe, Kemal Akkaya
MASS1
2010 Qualitative test-cost sensitive classification
Mumin Cebe, Cigdem Demir
Pattern Recognit. Lett.1
2007 Test-Cost Sensitive Classification Based on Conditioned Loss Functions
Mumin Cebe, Cigdem Demir
ECML1