VLDB 2026 Research / reviewers in the wild / expert
Chhagan Lal
dblp:98/10124
· DBLP profile ↗
44ranked-venue papers
5as first author
20since 2021 · last 2024
0000-0002-0051-1551ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 21 · 2 first-author · 9 since 2021Security and privacy · 13 · 6 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Anonymous and reliable ultralightweight RFID-enabled authentication scheme for IoT systems in cloud computing
Mohd Shariq, Mauro Conti, Karan Singh 0002, Chhagan Lal, Ashok Kumar Das, Shehzad Ashraf Chaudhry, Mehedi Masud |
Comput. Networks | 4 |
| 2024 | SYNTROPY: TCP SYN DDoS attack detection for Software Defined Network based on Rényi entropy
Vaishali A. Shirsath, Madhav Chandane, Chhagan Lal, Mauro Conti |
Comput. Networks | 3 |
| 2024 | SPARQ: SYN Protection using Acyclic Redundancy check and Quartile range on P4 switches
Vaishali A. Shirsath, Madhav Chandane, Chhagan Lal, Mauro Conti |
Comput. Commun. | 3 |
| 2024 | Explainable artificial intelligence for intrusion detection in IoT networks: A deep learning based approachabstractThe Internet of Things (IoT) is currently seeing tremendous growth due to new technologies and big data . Research in the field of IoT security is an emerging topic. IoT networks are becoming more vulnerable to new assaults as a result of the growth in devices and the production of massive data. In order to recognize the attacks, an intrusion detection system is required. In this work, we suggested a Deep Learning (DL) model for intrusion detection to categorize various attacks in the dataset. We used a filter-based approach to pick out the most important aspects and limit the number of features, and we built two different deep-learning models for intrusion detection . For model training and testing, we used two publicly accessible datasets, NSL-KDD and UNSW-NB 15. First, we applied the dataset on the Deep neural network (DNN) model and then the same dataset on Convolution Neural Network (CNN) model. For both datasets, the DL model had a better accuracy rate. Because DL models are opaque and challenging to comprehend, we applied the idea of explainable Artificial Intelligence (AI) to provide a model explanation. To increase confidence in the DNN model, we applied the explainable AI (XAI) Local Interpretable Model-agnostic Explanations (LIME ) method, and for better understanding, we also applied Shapley Additive Explanations (SHAP). Bhawana Sharma, Chhagan Lal, Satyabrata Roy |
Expert Syst. Appl. | 3 |
| 2024 | A Location-Aware and Healing Attestation Scheme for Air-Supported Internet of VehiclesabstractWith the rapid technological advancement in the Internet of Things (IoT) and Internet of Vehicles (IoV), we witness exponential growth of Connected and Autonomous Vehicles (CAVs). However, these integrations of IoV with other technologies make the IoV network and its interaction between different network components highly complex. Therefore, ensuring the correct functioning of the firmware and software running on these next-generation vehicles becomes an essential requirement. A feasible method to address the aforementioned security issues is Remote Attestation (RA). However, the advancement in the attackers’ approaches and the increased complexity, large network size, and vehicle mobility allow the attacks to bypass these security solutions, making RA less effective. In this paper, we propose LHASIoV, an attestation and healing protocol for IoV. LHASIoV has many features such as competent-wise (treats different entities of the system differently), geographical location-aware (traces forensics of security breaches and eases healing compromised vehicles), gradual healing (via slicing the healing software) of compromised vehicles, and resistance to single-point-of-failure. We provide proof-of-concept implementation and formal operational and security analysis for LHASIoV. To show its practical feasibility and effectiveness, we provide performance analysis by implementing it on the Omnetpp simulator. The simulation results show that for an IoV system that has 100 vehicles moving with a speed range of 15–25 mph, LHASIoV needed only 5.27 seconds to complete the vehicle’s attestation. For this number of vehicles and compared to the existing protocols, LHASIoV reduced the communication and storage costs on average by 54.46% and 43.92%, respectively. Mohamed A. El-Zawawy, Chhagan Lal, Mauro Conti |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Time-Restricted, Verifiable, and Efficient Query Processing Over Encrypted Data on CloudabstractOutsourcing data users’ location data to a cloud server (CS) enables them to obtain$k$nearest points of interest. However, data users’ privacy concerns hinder the wide-scale use. Several studies have achieved Secure k Nearest Neighbor (SkNN) query, but do not addresstime-restricted accessorresult privacy, and randomly partition data items which degrades efficiency. In this article, we proposeTime-restricted,verifiable, andefficientQueryProcessing (TiveQP). TiveQP has three distinguishing features. 1) Expand SkNN: data users can query$k$nearest locations open at a specific time. 2) Adopt a stronger threat model: we assume the CS is malicious and proposecomplementary set(i.e., transform proving “in” a set to proving “in” its complementary set) to allow data users to verify results without leaking unqueried data items’ information. 3) Improve efficiency: we design a space encoding technique and a pruning strategy to improve efficiency in query processing and result verification. We formally proved the security of TiveQP in the random oracle model. We conducted extensive evaluations over a Yelp dataset to show that TiveQP significantly improves over existing work, e.g., top-10NN query over 100 thousand data items only needs 10 ms to get queried results and 1.4 ms for verification. Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti |
IEEE Trans. Serv. Comput. | 5 |
| 2023 | An efficient and reliable ultralightweight RFID authentication scheme for healthcare systems
Karan Singh 0002, Mohd Shariq, Chhagan Lal, Mauro Conti, Ruhul Amin 0001, Shehzad Ashraf Chaudhry |
Comput. Commun. | 4 |
| 2023 | Eunomia: Anonymous and Secure Vehicular Digital Forensics Based on BlockchainabstractVehicular Digital Forensics (VDF) is essential to enable liability cognizance of accidents and fight against crimes. Ensuring the authority to timely gather, analyze, and trace data promotes vehicular investigations. However, adversaries crave the identity of the data provider/user, damage the evidence, violate evidence jurisdiction, and leak evidence. Therefore, protecting privacy and evidence accountability while guaranteeing access control and traceability in VDF is no easy task. To address the above-mentioned issues, we propose Eunomia: an anonymous and secure VDF scheme based on blockchain. It preserves privacy with decentralized anonymous credentials without trusted third parties. Vehicular data and evidence are uploaded by data providers to the blockchain and stored in distributed data storage. Each investigation is modeled as a finite state machine with state transitions being executed by smart contracts. Eunomia achieves fine-grained evidence access control via ciphertext-policy attribute-based encryption and Bulletproofs. A user must hold specific attributes and a temporary-and-unexpired token/warrant to retrieve data from the blockchain. Finally, a secret key is embedded into data to trace the traitor if any evidence breach happens. We use a formal analysis to demonstrate the strong privacy and security properties of Eunomia. Moreover, we build a prototype in a WiFi-based Ethereum test network to evaluate its performance. Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Mamoun Alazab, Donghui Hu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Nereus: Anonymous and Secure Ride-Hailing Service Based on Private Smart ContractsabstractSecurity and privacy issues have become a major hindrance to the broad adoption of Ride-Hailing Services (RHSs). In this article, we introduce a new collusion attack initiated by the Ride-Hailing Service Provider (RHSP) and a driver that could easily link the real riders and their anonymous requests (credentials). Besides this attack, existing work requires heavy computations to execute user matching, and it is challenging for riders to verify matching results. Meanwhile, a malicious driver may cancel an assigned ride order due to its short distance. To address these issues, we present a RHS system named Nereus to support collusion resistance, efficiency, verifiability, and accountability. First, we integrate a smart contract into a Software Guard Extensions (SGX) enclave to establish aprivate smart contractfor collusion resistance. We use a Bloom filter to achieve efficient matching. Second, we leverage privacy-preserving range query and Merkle proofs to make matching results verifiable. Meanwhile, we adopt short group signatures to provide anonymous authentication and deposit commitments to hold the runaway driver accountable. We formally state and prove the security and privacy of Nereus. We build a prototype based on Ethereum and SGX to conduct extensive performance analysis in regard to gas costs, computational costs, and communication overhead. Experimental results show that Nereus significantly improves over existing schemes in terms of computational costs. Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Fabio Martinelli, Mamoun Alazab |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Astraea: Anonymous and Secure Auditing Based on Private Smart Contracts for Donation SystemsabstractMany regions are in urgent need of facial masks for slowing down the spread of COVID-19. To fight the pandemic, people are contributing masks through donation systems. Most existing systems are built on a centralized architecture which is prone to the single point of failure and lack of transparency. Blockchain-based solutions neglect fundamental privacy concerns (donation privacy) and security attacks (collusion attack, stealing attack). Moreover, current auditing solutions are not designed to achieve donation privacy, thus not appropriate in our context. In this work, we design a decentralized, anonymous, and secure auditing frameworkAstraeabased on private smart contracts for donation systems. Specifically, we integrate a Distribute Smart Contract (DiSC) with an SGX Enclave to distribute donations, prove the integrity of donation number (intention) and donation sum while preserving donation privacy. With DiSC, we design a Donation Smart Contract to refund deposits and defend against the stealing attack the collusion attack from malicious collector and transponder. We formally define and prove the privacy and security of Astraea by using security reduction. We build a prototype of Astraea to conduct extensive performance analysis. Experimental results demonstrate that Astraea is practically efficient in terms of both computation and communication. Meng Li 0006, Yifei Chen 0005, Liehuang Zhu, Zijian Zhang 0001, Jianbing Ni, Chhagan Lal, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | EQRSRL: an energy-aware and QoS-based routing schema using reinforcement learning in IoMT
Amin Nazari, Mojtaba Kordabadi, Reza Mohammadi 0003, Chhagan Lal |
Wirel. Networks | 4 |
| 2022 | Repetitive, Oblivious, and Unlinkable SkNN Over Encrypted-and-Updated Data on Cloud
Meng Li 0006, Chhagan Lal, Mauro Conti, Mamoun Alazab |
ICICS | 4 |
| 2022 | Graph Encryption for Shortest Path Queries with k Unsorted NodesabstractShortest distance queries over large-scale graphs bring great benefits to various applications, i.e., save planning time and travelling expenses. To protect the sensitive nodes and edges in the graph, a user outsources an encrypted graph to an untrusted server without losing the query ability. However, no prior work has considered the user requirement of the shortest path with k unsorted nodes. In particular, we are concerned with how to securely find the shortest path by passing k nodes that do not have a fixed traverse order. To solve the problems, we propose Gespun (stands for Graph encryption for shortest path queries with k unordered nodes). It includes an oracle encryption scheme that is provably secure against the semi-honest server. Specifically, we compute the shortest paths and distances for all nodes locally to obtain path-distance oracles. We transform the shortest paths to a sequence of secure codes by using a pseudo-random permutation to protect the structure privacy. We encrypt the shortest distance by using additively homomorphic encryption. Second, we pack the oracles in link-list nodes and store them in an array-based dictionary after another permutation. Next, we construct a search graph to compute the shortest path while guaranteeing that the path passes the required k nodes. We formally prove that Gespun is adaptively semantically-secure in the random oracle. We implement a prototype of Gespun and evaluate its performance. Experiments results demonstrate that Gespun is efficient, e.g., a query over 6301 nodes, 20777 edges, and 5 unsorted nodes only needs 483 ms to get queried results. We believe that our research problem span new research that soon promotes a new line of graph encryption schemes. Meng Li 0006, Zijian Zhang 0001, Chaoping Fu, Chhagan Lal, Mauro Conti |
TrustCom | 5 |
| 2022 | ESRAS: An efficient and secure ultra-lightweight RFID authentication scheme for low-cost tagsabstractInternet of Things (IoT) technologies rapidly evolve and are used in many real-life applications. One of the core technologies used in various IoT applications is Radio Frequency IDentification (RFID) technology. RFID wirelessly and uniquely identifies the tagged objects without a direct line of sight. However, the research community had reported privacy and security-related concerns in RFID systems, where an adversary may tamper, eavesdrop, add, delete, or even modify the transmitted messages over an insecure communication channel. To address the issues mentioned above, we propose an Efficient, Secure, and practical ultra-lightweight RFID Authentication Scheme (ESRAS), which uses rank operation for low-cost tags. We utilize a simplistic bitwise exclusive-OR, circular left rotation, and a newly proposed ultra-lightweight rank operation to provide high security at low cost. The analysis of ESRAS concerning its security and performance shows that it effectively resists several known attacks and is relatively superior to the existing schemes regarding the computational and storage costs. Moreover, ESRAS shows more suitability for low-cost RFID tags and can be executed in a multimedia big data environment. Mohd Shariq, Karan Singh 0002, Chhagan Lal, Mauro Conti, Tayyab Ali Khan |
Comput. Networks | 3 |
| 2022 | Privacy-Preserving Navigation Supporting Similar Queries in Vehicular NetworksabstractTraffic-sensitive navigation systems in vehicular networks help drivers avoid traffic jams by providing several realtime navigation routes. However, drivers still encounter privacy concerns because their sensitive locations, i.e., their start point and endpoint, are submitted to an honest-but-curious navigation service provider (NSP). Previous privacy-preserving studies exhibit serious deficiencies under similar queries: if a driver makes several similar queries, i.e., periodically makes requests for the same start point and endpoint to the NSP, these requests will eventually reveal the areas of the two points as well as the route. In this paper, we present a novel privacy-preserving navigation scheme PiSim, which supports similar queries in navigation services. Intuitively, we transform the typical navigation approach into a traffic congestion querying approach. Instead of sending two locations to the NSP and awaiting a navigation route, drivers query the traffic congestion along the navigation route. Specifically, PiSim is characterized by extending anonymous authentication, facilitating privacy-preserving multi-keyword fuzzy search, and constructing weighted proximity graphs. Our scheme protects location privacy and route privacy, and defends against multiple requesting, spurious reporting, and collusion attacks from malicious drivers. Finally, a detailed analysis confirms the privacy and security properties of PiSim. Extensive experiments are conducted to demonstrate the feasibility, performance, and privacy protection level. Meng Li 0006, Yifei Chen 0005, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | User-Defined Privacy-Preserving Traffic Monitoring Against n-by-1 Jamming AttackabstractTraffic monitoring services collect traffic reports and respond to users’ traffic queries. However, the reports and queries may reveal the user’s identity and location. Although different anonymization techniques have been applied to protect user privacy, a new security threat arises, namely, n-by-1 jamming attack, in which an anonymous contributing driver impersonates$n$drivers and uploads$n$normal reports by using$n$reporting devices. Such an attack will mislead the traffic monitoring service provider and further degrade the service quality. Existing traffic monitoring services do not support customized queries, and private information retrieval techniques cannot be applied directly in traffic monitoring. We formally define the new attack and propose a traffic monitoring scheme TraJ to defend the attack and achieve user-defined location privacy. Specifically, we bridge anonymous contributing drivers without disclosing their speed set by using private set intersection. Each RSU collects time traffic reports and structures a weighted proximity graph to filter out malicious colluding drivers. We design a user-defined privacy-preserving query method by encoding complex road network. We leverage the uploading phase from private aggregation to collect traffic conditions and allow requesting drivers to dynamically and privately query traffic conditions. We provide a formal analysis of TraJ to prove its privacy and security properties. We also construct a prototype based on a real-world dataset and Android smartphones to demonstrate its feasibility and efficiency. A formal analysis demonstrates the privacy and security properties. Extensive experiments illustrate the performance and defense efficacy. Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab |
IEEE/ACM Trans. Netw. | 4 |
| 2021 | Internet-of-Forensic (IoF): A blockchain based digital forensics framework for IoT applicationsabstractDigital forensic in Internet-of-Thing (IoT) paradigm is critical due to its heterogeneity and lack of transparency of evidence processing. Moreover, cross-border legalization makes a hindrance in such process pertaining to the cloud forensic issues. This urges a forensic framework for IoT which provides distributed computing, decentralization, and transparency of forensic investigation of digital evidences in cross-border perspectives. To this end, we propose a framework for IoT forensics that addresses the above mentioned issues. The proposed solution called Internet-of-Forensics (IoF) considers a blockchain tailored IoT framework for digital forensics. It provides a transparent view of the investigation process that involves all the stakeholders (e.g., heterogeneous devices, and cloud service providers) in a single framework. It uses blockchain-based case chain to deal with the investigation process including chain-of-custody and evidence chain. Consensus is used for consortium to solve the problems of cross-border legalization. This is also beneficial for a transparent and ease of forensic reference. The programmable lattice-based cryptographic primitives produce reduced complexities. It shows benefits for power-aware devices and puts an add-on to the novelty of the presented idea. IoF is generic; hence, it can be used by autonomous security operation centers, cyber-forensic investigators and manually initiated evidences under chain-of-custody for man-made crimes. Security services are assured as required by the framework. IoF is experimented and compared with the other state-of-the-art frameworks. The outcomes and analysis prove the efficiency of IoF concerning complexity, time consumption, memory and CPU utilization, gas consumption, and energy analysis. Gulshan Kumar, Rahul Saha, Chhagan Lal, Mauro Conti |
Future Gener. Comput. Syst. | 3 |
| 2021 | LEChain: A blockchain-based lawful evidence management scheme for digital forensics
Meng Li 0006, Chhagan Lal, Mauro Conti, Donghui Hu |
Future Gener. Comput. Syst. | 2 |
| 2021 | Anonymous and Verifiable Reputation System for E-Commerce Platforms Based on BlockchainabstractE-commerce platforms incorporate reputation systems that allow customers to rate suppliers following financial transactions. Existing reputation systems cannot defend the centralized server against arbitrarily tampering with the supplier’s reputation. Furthermore, they do not offer reputation access across platforms. Rates are faced with privacy leakages because rating activities are correlated with privacy (e.g., identity and rating). Meanwhile, raters could be malicious and initiate multiple rating attacks and abnormal rating attacks. Determining how to address these issues have both research and practical value. In this paper, we propose a blockchain-based privacy-preserving reputation system for e-commerce platforms named RepChain; our system allows cross-platform reputation access and anonymous and private ratings. Using RepChain, all e-commerce platforms collaborate and share users’ reputations by co-constructing a consortium blockchain and modeling the rating process as a finite state machine. In particular, we facilitate one-show anonymous credentials constructed from two-move blind signatures to protect customers’ identities and resist multiple rating attacks, leverage zero-knowledge range proof to verify the correctness of ratings and defend against abnormal rating attacks, design a secure sum computation protocol among nodes to update reputations, and verify ratings via batch processing and consensus hashes. Finally, we demonstrate the security and privacy of RepChain via a formal analysis and evaluate its performance based on Ethereum test network. Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | AEGIS: Detection and Mitigation of TCP SYN Flood on SDN ControllerabstractSoftware-Defined Network (SDN) segregates the control plane and the data plane to bring about a programmable network. The controller at the control plane runs network modules and sets rules for forwarding the packets in the switches that resides at the data plane. Though advantageous in several ways, SDN can fail when the controller is saturated by a flood of TCP SYN packets. SYN flood can be created using malicious spoofing of IP or MAC addresses or flash crowd. The existing solutions to mitigate SYN flood against the controller does not adequately handle MAC spoofing based SYN flood, and these are unable to distinguish between flash crowd and malicious traffic. To overcome some limitations in existing solutions, we propose a novel mechanism called AEGIS, which detect and mitigate SYN flood against the controller in SDN. AEGIS runs in the controller, and it regularly checks if there is a performance lag in the controller due to an ongoing SYN flood. If a performance degradation is detected, then AEGIS takes it an indication of SYN flood and it identifies whether it is due to spoofed addresses or flash crowd. Once the reason is found, the appropriate mitigation procedure is triggered. We evaluate AEGIS in testbed and emulator settings, and we compare the results of the evaluation with state-of-the-art solutions. The performance evaluation of AEGIS shows that it identifies the malicious SYN at an accuracy of 97.78%. Moreover, when there is no SYN flood, AEGIS takes 0.0637s to set up a successful TCP connection, which is 53.81% less than the time taken by the state-of-the-art solution, thus, it proves that AEGIS is lightweight. Nagarathna Ravi, Mercy Shalinie Selvaraj, Chhagan Lal, Mauro Conti |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | One-Time, Oblivious, and Unlinkable Query Processing Over Encrypted Data on Cloud
Yifei Chen 0005, Meng Li 0006, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti |
ICICS | 5 |
| 2020 | NC based DAS-NDN: Network Coding for robust Dynamic Adaptive Streaming over NDN
Muhammad Hassan 0001, Mauro Conti, Chhagan Lal |
Comput. Networks | 3 |
| 2020 | Security and design requirements for software-defined VANETs
Wafa Ben Jaballah, Mauro Conti, Chhagan Lal |
Comput. Networks | 3 |
| 2020 | Context-based Co-presence detection techniques: A survey
Mauro Conti, Chhagan Lal |
Comput. Secur. | 2 |
| 2020 | LiDL: Localization with early detection of sybil and wormhole attacks in IoT Networks
Pallavi Kaliyar, Wafa Ben Jaballah, Mauro Conti, Chhagan Lal |
Comput. Secur. | 4 |
| 2020 | A robust multicast communication protocol for Low power and Lossy networks
Mauro Conti, Pallavi Kaliyar, Chhagan Lal |
J. Netw. Comput. Appl. | 3 |
| 2020 | Blockchain-Enabled Secure Energy Trading With Verifiable Fairness in Industrial Internet of ThingsabstractEnergy trading in Industrial Internet of Things (IIoT), a fundamental approach to realize Industry 4.0, plays a vital role in satisfying energy demands and optimizing system efficiency. Existing research works utilize a utility company to distribute energy to energy nodes with the help of energy brokers. Afterwards, they apply blockchain to provide transparency, immutability, and auditability of peer-to-peer (P2P) energy trading. However, their schemes are constructed on a weak security model and do not consider the cheating attack initiated by energy sellers. Such an attack refers to an energy seller refusing to transfer the negotiated energy to an energy purchaser who already paid money. In this article, we propose FeneChain, a blockchain-based energy trading scheme to supervise and manage the energy trading process toward building a secure energy trading system and improving energy quality for Industry 4.0. Specifically, we leverage anonymous authentication to protect user privacy, and we design a timed-commitments-based mechanism to guarantee the verifiable fairness during energy trading. Moreover, we utilize fine-grained access control for energy trading services. We also build a consortium blockchain among energy brokers to verify and record energy trading transactions. Finally, we formally analyze the security and privacy of FeneChain and evaluate its performance (i.e., computational costs and communication overhead) by implementing a prototype via a local Ethereum test network and Raspberry Pi. Meng Li 0006, Donghui Hu, Chhagan Lal, Mauro Conti, Zijian Zhang 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | TARE: Topology Adaptive Re-kEying scheme for secure group communication in IoT networks
Anshu S. Anand, Mauro Conti, Pallavi Kaliyar, Chhagan Lal |
Wirel. Networks | 4 |
| 2020 | Reliable and secure data transfer in IoT networks
Sarada Prasad Gochhayat, Chhagan Lal, Durga Prasad Sharma, Deepak Gupta 0002, Jose Antonio Marmolejo Saucedo, Utku Kose |
Wirel. Networks | 2 |
| 2019 | BlockAuth: BlockChain based distributed producer authentication in ICN
Mauro Conti, Muhammad Hassan 0001, Chhagan Lal |
Comput. Networks | 3 |
| 2019 | SLDP: A secure and lightweight link discovery protocol for software defined networking
Ajay Nehra, Meenakshi Tripathi, Manoj Singh Gaur, Ramesh Babu Battula, Chhagan Lal |
Comput. Networks | 5 |
| 2019 | CENSOR: Cloud-enabled secure IoT architecture over SDN paradigmabstractSummary The cyber‐security threats to low‐cost end‐user devices could severely undermine the expected deployment of Internet of Thing (IoT) solutions in a range of real‐world applications such as environment monitoring, transportation, and manufacturing. Additionally, the huge amount of data generated by these devices posses new challenges concerning tasks such as efficient information acquisition and analysis, decision making, and action implementation. In this paper, we propose CENSOR, a novel cloud‐enabled secure IoT network architecture based on SDN paradigm. We discuss the significant benefits as well as challenges that are inherent while performing integration of SDN and IoT in CENSOR. We show that the emerging software‐based networking features combined with the cloud computing solutions can significantly improve the security and communication reliability in the target IoT scenarios. In particular, to provide the adequate security measures in the network, CENSOR uses a lightweight and scalable software remote attestation scheme, which ensures the integrity of the software that is being executed by the IoT devices to achieve the application specific goals in the network. We further discuss the improvements in data communication and data overhead that can be achieved in CENSOR due to its convergence with the cloud computing (at back‐end) and fog computing services (at edge routers or front‐end). A Smart City use‐case has been considered as a target IoT scenario to analyze the feasibility and effectiveness of CENSOR concerning the communication security and the network scalability parameters. Additionally, we provide future research directions along with the recent industry initiatives that include open issues in the integration and deployment of cloud‐enabled SDN‐based IoT networks. Mauro Conti, Pallavi Kaliyar, Chhagan Lal |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Lightweight solutions to counter DDoS attacks in software defined networking
Mauro Conti, Chhagan Lal, Reza Mohammadi 0003, Umashankar Rawat |
Wirel. Networks | 2 |
| 2018 | Fair-RTT-DAS: A robust and efficient dynamic adaptive streaming over ICN
Mauro Conti, Ralph E. Droms, Muhammad Hassan 0001, Chhagan Lal |
Comput. Commun. | 4 |
| 2018 | SAFETY: Early Detection and Mitigation of TCP SYN Flood Utilizing Entropy in SDNabstractSoftware defined networking (SDN) is an emerging network paradigm which emphasizes the separation of the control plane from the data plane. This decoupling provides several advantages such as flexibility, programmability, and centralized control. However, SDN also introduces new vulnerabilities due to the required communication between data plane and control plane. Examples of threats that leverage such vulnerabilities are the control plane saturation and switch buffer overflow attacks. These attacks can be launched by flooding the TCP SYN packets from data plane (i.e., switches) to the control plane. This paper presents SAFETY, a novel solution for the early detection and mitigation of TCP SYN flooding. SAFETY harnesses the programming and wide visibility approach of SDN with entropy method to determine the randomness of the flow data. The entropy information includes destination IP and few attributes of TCP flags. To show the feasibility and effectiveness of SAFETY, we implement it as an extension module in Floodlight controller and evaluate it under different conditional scenarios. We run a thorough evaluation of our implementation through extensive emulation via Mininet. The experimental results show that when compared to the state-of-the-art, SAFETY brings a significant improvement (13%) regarding processing delay experienced by a legitimate node. Other parameters such as CPU utilization at the controller and attack detection time are also examined and shows improvement in various scenarios. Meenakshi Tripathi, Ajay Nehra, Mauro Conti, Chhagan Lal |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2018 | Enhancing QoE for video streaming in MANETs via multi-constraint routing
Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti |
Wirel. Networks | 1 |
| 2017 | REMI: A Reliable and Secure Multicast Routing Protocol for IoT NetworksabstractIn this paper, we present REMI, a reliable and secure multicast routing protocol for IoT networks. The main aim of REMI is to enable efficient communication in low-power and lossy networks such as IoT, by ensuring that a message will be received by all its intended destinations, irrespective of the network size and the presence of misbehaving nodes. REMI uses a cluster-based routing approach that triggers a faster multicast dissemination of messages within the network. We implemented REMI with Contiki, a multitasking operating system which is widely adopted by industry for deploying energy-constrained and memory-efficient wireless networks. To assess the effectiveness and efficiency of REMI, we run a thorough set of simulations. Our results show the effectiveness of our protocol over state-of-art protocols in terms of network throughput, propagation delay, and scalability at the cost of minimal overheads in terms of energy consumption and memory utilization. Mauro Conti, Pallavi Kaliyar, Chhagan Lal |
ARES | 3 |
| 2015 | JellyFish attack: Analysis, detection and countermeasure in TCP-based MANET
Vijay Laxmi, Chhagan Lal, Manoj Singh Gaur, Deepanshu Mehta |
J. Inf. Secur. Appl. | 2 |
| 2015 | Bandwidth-aware routing and admission control for efficient video streaming over MANETs
Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur, Seok-Bum Ko |
Wirel. Networks | 1 |
| 2014 | Analysis of Identity Forging Attack in MANETsabstractIn Mobile Ad-Hoc Networks (MANETs) source and destination generally needs multihops to transfer data packets. Hence the number of nodes from source to destination increases. This property has render it vulnerable to attacks. We use the identity forging property of Sybil attack to propose an attack named "Identity Forging". In this attack, an attacker impersonates fake identity to affect the performance of network by sending the control packets through the identity of fabricated node and itself remaining silent. This makes it immune to the basic detection techniques of Sybil attack where both the attacker and its fake identity work simultaneously and thus can be detected if heard together for long period. The attacker also keeps changing the fabricated identity every time the link fails. Two different variations of this attack has been presented with their analysis and their impact on the performance of MANETs. In the end a possible detection algorithm for the attack has been proposed. Nishant Garg, Kuldeep Pareek, Manoj Singh Gaur, Vijay Laxmi, Chhagan Lal |
SIN | 5 |
| 2013 | QoS-aware routing for transmission of H.264/SVC encoded video traffic over MANETsabstractEfficient and reliable video streaming over mobile ad-hoc networks (MANETs) is a challenging task due to the varying characteristics of wireless networks and video traffic. Therefore, these kinds of applications require quality-of-service (QoS) support. Although, many QoS provisioning solutions are reported in the past but none of them are tested on video traffic and also affects of mobility and variations in link quality are not addressed properly. In this paper, we proposed an efficient QoS-aware routing protocol (QARP) which uses the cross-layer communication (CLC) and session admission control (SAC) methods to provide QoS guarantees in terms of network bandwidth. In QARP, we perform QoS-aware route discovery by considering the effects of both inter-contention and intra-contention during the route discovery phase. Only data sessions for which a route with required bandwidth is discovered are admitted into the network by our SAC process. Existing periodic message structures are extended for exchange the QoS states of nodes to minimize the affect of mobility in our QoS-aware routing method. Furthermore, two methods are proposed to handle the QoS violations caused by dynamic characteristics of video traffic and network mobility during data communication. To stress the network with real time multimedia traffic, we use trace files generated from real time video files that are encoded using H.264/SVC encoder. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
APCC | 1 |
| 2013 | Video streaming over MANETs: Testing and analysis using real-time emulationabstractIn this paper, we design and deploy a Mobile Ad hoc Network (MANET) testbed that is integrated with EXata-Cyber network emulator to evaluate the performance of real-time video streaming applications. EXata-Cyber can unvaryingly connect emulated networks (virtual networks created by EXata-Cyber) to real machines. Thus, in our testbed, real machines can exchange real-life applications traffic over emulated wireless networks consisting of virtual machines. With the emulation capabilities of EXata-Cyber, our developed testbed gives an efficient, high fidelity and accommodating testing terrain for analyzing the performances and behaviors of real-life applications, machines and MANET routing protocols. We evaluate the performance of both proactive and reactive routing protocols while transmitting real-time video traffic in terms of change in network load, network mobility and video streaming bit rate. Furthermore, to provide accurate measures for perceived video quality at users end in the form of Quality-of-Experience (QoE), we evaluate and analyze metrics such as Mean Opinion Score (MOS), Signal-to-Interference and Noise Ratio (SINR) and Packet Delivery Ratio (PDR) at various layers of TCP/IP protocol stack. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
APCC | 1 |
| 2013 | Impact analysis of JellyFish attack on TCP-based mobile ad-hoc networksabstractTremendous increase has been seen in the number of application areas of mobile ad-hoc networks (MANETs) in recent years owing to the advancements in hardware of hand- held devices and wireless network deployment technologies. As a result, providing security in these kinds of networks has become central concern for researchers. In this paper, we analyze the behavior and impacts of JellyFish attack over TCP-based MANETs. We implement and evaluate three variants of JellyFish attack namely JF-reorder, JF-delay and JF-drop. JellyFish attack exploits the behavior of closed loop protocols such as TCP and performs the attacks without disobeying any rules of the protocol. Consequently, it causes ruinous effects and becomes difficult to detect due to its protocol compliance nature. This paper provides the complete simulation study of JellyFish attacks on three TCP variants known as TCP-Tahoe, TCP-SACK and TCP-NewReno. The simulations have been taken in the light of throughput, number of JF nodes and number of retransmissions. The paper contributes to the field of denial of service (DoS) attacks in MANETs by giving a comparative analysis of three TCP variants and discovers which TCP variant performs best under different variants of JellyFish attack. In addition to this, our simulation results also shed some light on the seriousness of the attacks caused by JF nodes and their effects on data communication. Vijay Laxmi, Deepanshu Mehta, Manoj Singh Gaur, Parvez Faruki, Chhagan Lal |
SIN | 5 |
| 2012 | A Node-Disjoint Multipath Routing Method Based on AODV Protocol for MANETsabstractFrequent link failures are caused in mobile ad-hoc networks due to node's mobility and use of unreliable wireless channels for data transmission. Due to this, multipath routing protocols become an important research issue. In this paper, we propose and implement a node-disjoint multipath routing method based on AODV protocol. The main goal of the proposed method is to determine all available node-disjoint routes from source to destination with minimum routing control overhead. With the proposed approach, as soon as the first route for destination is determined, the source starts data transmission. All the other backup routes, if available, are determined concurrently with the data transmission through the first route. This minimizes the initial delay caused because data transmission is started as soon as first route is discovered. We also propose three different route maintenance methods. All the proposed route maintenance methods are used with the proposed route discovery process for performance evaluation. The results obtained through various simulations show the effectiveness of our proposed methods in terms of route availability, control overhead, average end-to-end delay and packet delivery ratio. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
AINA | 1 |