VLDB 2026 Research / reviewers in the wild / expert
Simin Nadjm-Tehrani
dblp:n/SiminNadjmTehrani
· DBLP profile ↗
61ranked-venue papers
3as first author
17since 2021 · last 2026
0000-0002-1485-0802ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 8 since 2021Software engineering, systems software and programming languages · 11 · 3 since 2021Computer networks · 8 · 1 first-author · 1 since 2021Systems, architecture and hardware · 7Artificial intelligence and machine learning · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3Theory of computation · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | JKA-HT: A Provably Secure Replay-Resilient Authentication Protocol for IoDabstractThe Internet of Drones (IoD) enables coordinated UAV communication for critical applications such as disaster response, military operations, and smart agriculture. As IoD networks scale and integrate with next-generation wireless systems (e.g., 6G), securing communication between resource-constrained drones becomes essential, particularly against replay attacks that can compromise safety and mission integrity. We present JKA-HT, a lightweight authentication and key agreement protocol offering robust, time-independent replay protection and comprehensive formal security guarantees. Building on the Julia Key Agreement (JKA), JKA-HT introduces HASHTAG, a novel cryptographic tagging mechanism that achieves replay resilience without relying on synchronized clocks or special hardware. We formally verify JKA-HT in the TAMARIN prover under the Dolev-Yao threat model, proving mutual authentication, forward/backward secrecy, Key Compromise Impersonation (KCI) resistance, and replay protection. JKA-HT is the first IoD authentication protocol to achieve all these properties with formal proofs, making it well-suited for deployment in adversarial, resource-constrained environments. Navya Sivaraman, Niklas Carlsson, Simin Nadjm-Tehrani |
CCNC | 3 |
| 2026 | Improving SIEM Rules Using Transformer-Based Rule Evasion Detection and Attribution
Erik Nordström, Hannes Widéen, Valency Oscar Colaco, Simin Nadjm-Tehrani |
DBSec | 4 |
| 2026 | Feature attribution in 5G intrusion detection: A statistical vs. logic-based comparisonabstractWith the rise of fifth-generation (5G) networks in critical applications, it is urgent to move from detection of malicious activity to systems capable of providing a reliable verdict suitable for mitigation. In this regard, understanding and interpreting machine learning (ML) models’ security alerts is crucial for enabling actionable incident response orchestration. Explainable Artificial Intelligence (XAI) techniques are expected to enhance trust by providing insights into why alerts are raised. Under the umbrella of XAI, interpretability of outcomes is crucially dependent on understanding the influence of specific inputs, referred to as feature attribution. A dominant approach to feature attribution statistically associates feature sets that can be correlated to a given alert. This paper investigates its merits against the backdrop of criticism from recent literature, in comparison with feature attribution based on logic. We extensively study two methods, SHAP and VoTE-XAI, as representatives of each feature attribution approach by analyzing their interpretations of alerts generated by an XGBoost model across three 5G-relevant datasets (5G-NIDD, MSA, and PFCP) covering multiple attack scenarios. We identify three metrics for assessing explanations: sparsity, how concise they are; stability, how consistent they are across samples from the same attack type; and efficiency, how fast an explanation is generated. Our results reveal that logic-based attributions are consistently more sparse and stable across alerts. More importantly, we found a significant divergence between features selected by SHAP and VoTE-XAI. However, none of the top-ranked features selected by SHAP were missed by VoTE-XAI. Finally, we analyze the efficiency of both methods, discussing their suitability for real-time security monitoring even in high-dimensional 5G environments (478 features). Federica Uccello, Simin Nadjm-Tehrani |
J. Inf. Secur. Appl. | 2 |
| 2026 | Finding Minimum-Cost Explanations for Predictions Made by Tree EnsemblesabstractABSTRACT The ability to reliably explain why a machine learning model arrives at a particular prediction is crucial when used as decision support by human operators of critical systems. The provided explanations must be provably correct, and preferably without redundant information, called minimal explanations. In this paper, we aim at finding explanations for predictions made by tree ensembles that are not only minimal, but also minimum with respect to a cost function. To this end, we first present a highly efficient oracle that can determine the correctness of explanations, surpassing the runtime performance of current state‐of‐the‐art alternatives by several orders of magnitude. Secondly, we adapt an algorithm called MARCO from the optimization field (calling the adaptation m‐MARCO) to compute a single minimum explanation per prediction, and demonstrate an overall speedup factor of 2.7 compared to a state‐of‐the‐art algorithm based on minimum hitting sets (MHS), and a speedup factor of 27 compared to the standard MARCO algorithm which enumerates all minimal explanations. Finally, we study the obtained explanations from a range of use cases, leading to further insights into their characteristics. In particular, we observe that in several cases, there are more than 500,000 minimal explanations to choose from for a single prediction. In these cases, we see that only a small portion of the minimal explanations are also minimum, and that the minimum explanations are significantly less verbose, hence motivating the aim of this work. John Törnblom, Emil Karlsson, Simin Nadjm-Tehrani |
Softw. Pract. Exp. | 3 |
| 2025 | Dependency-Based Evolution Planning of a Multi-version Microservice RAN Application
Emma Witt, Simin Nadjm-Tehrani |
MoMM | 2 |
| 2025 | Topology-Aware Prioritized Patching for EV Charging Infrastructure Vulnerabilities
Roland Plaka, Mikael Asplund, Simin Nadjm-Tehrani |
VEHITS | 3 |
| 2025 | Energy Metrics for Edge Microservice Request Placement StrategiesabstractMicroservices are a way of splitting the logic of an application into small blocks that can be run on different computing units and used by other applications. It has been successful for cloud applications and is now increasingly used for edge applications. This new architecture brings many benefits but it makes deciding where a given service request should be executed (i.e. its placement) more complex as every small block needed for the request has to be placed. Klervie Toczé, Simin Nadjm-Tehrani |
ICPE | 2 |
| 2024 | Penetrating the Power Grid: Realistic Adversarial Attacks on Smart Grid Intrusion Detection Systems
Nelson Makau Mutua, Simin Nadjm-Tehrani, Petr Matousek |
CRITIS | 2 |
| 2024 | Formal Analysis of Julia Key Agreement Protocol
Navya Sivaraman, Simin Nadjm-Tehrani, Thomas Johansson 0001 |
ICICS (2) | 2 |
| 2024 | Fast Evasion Detection & Alert Management in Tree-Ensemble-Based Intrusion Detection SystemsabstractIntrusion Detection Systems (IDSs) can help bolster cyber resilience in high-risk systems by promptly detecting anomalies and thwarting security threats which could have catastrophic consequences. While Machine Learning (ML) techniques like Tree Ensembles are well suited for tasks like detecting anomalies, the widespread adoption of these techniques in IDSs faces barriers due to the threat of evasion attacks. Moreover, ML-based IDSs are susceptible to producing a high rate of false positive alerts during detection, causing alert fatigue. To alleviate these problems, we present a method that uses counterexample regions to detect evasion attacks in tree-ensemble-based IDSs. We generate these counterexample regions by defining a modified mapping checker in VoTE, a fast & scalable formal verification tool specialized for tree ensembles. Our method also provides quaternary annotations, empowering security managers with nuanced insights to better handle alerts in the triage queue. Our approach does not require training a separate model and displays good detection performance (≥98 %) in both adversarial & non-adversarial scenarios in four real-world case studies when compared to several approaches in the literature. The prototype system we implement based on our method called Iceman has a very low prediction latency, making it 5-115x faster than the current state-of-the-art in evasion detection for tree ensembles. Finally, empirical evaluations show that Iceman can correctly re-annotate the samples in the presence of evasion attacks for alert management purposes with an accuracy of more than 98 % . Valency Oscar Colaco, Simin Nadjm-Tehrani |
ICTAI | 2 |
| 2024 | NetGAP: A graph grammar approach for concept design of networked platforms with extra-functional requirementsabstractDuring the concept design of complex networked systems, concept developers have to ensure that the choice of hardware modules and the topology of the target platform will provide adequate resources to support the needs of the application. For example, future-generation aerospace systems need to consider multiple requirements, with many trade-offs, foreseeing rapid technological change and a long period for realization and service. For that purpose, we introduce NetGAP, an automated 3-phase approach to synthesize network topologies and support the exploration and concept design of networked systems with multiple requirements including dependability, security, and performance. NetGAP represents the possible interconnections between hardware modules using a graph grammar and uses a Monte Carlo Tree Search optimization to generate candidate topologies from the grammar while aiming to satisfy the requirements. We apply the proposed approach to a synthetic version of a realistic avionics application use case. It includes 99 processes and 660 messages. The experiment shows the merits of the solution to support the early-stage exploration of alternative candidate topologies. The method vividly characterizes the topology-related trade-offs between requirements stemming from security, fault tolerance, timeliness, and the “cost” of adding new modules or links. We also create a scaled-up version of the problem (267 processes, 1887 messages) to illustrate scalability. Finally, we discuss the flexibility of using the approach when changes in the application and its requirements occur. Rodrigo S. de Moraes, Simin Nadjm-Tehrani |
Eng. Appl. Artif. Intell. | 2 |
| 2023 | Mapping and Analysis of Common Vulnerabilities in Popular Web Servers
Matyas Barocsai, Johan Can, Martin Karresand, Simin Nadjm-Tehrani |
critis | 4 |
| 2023 | Vulnerability Analysis of an Electric Vehicle Charging Ecosystem
Roland Plaka, Mikael Asplund, Simin Nadjm-Tehrani |
critis | 3 |
| 2023 | 5G Handover: When Forward Security Breaksabstract5G mobility management is dependent on a couple of complex protocols for managing handovers, based on the available network interfaces (such as Xn and N2). In our work, we focus on the 5G Xn handover procedure, as defined by the 3GPP standard. In Xn handovers, the source base station hands the user equipment (UE) over to a target base station through two different mechanisms: horizontal or vertical key derivation. To ascertain the security of these complex protocols, recent works have formally described the protocols and proved some security properties. In this work, we formulate a new property, forward security, which ensures the secrecy of future handovers following a session key exchange in one handover. Using a formal model and the Tamarin prover, we show that forward security breaks in the 5G Xn handover in presence of an untrusted base station. We also propose a solution to mitigate this counter-example with a small modification of the 3GPP Xn handover procedures based on the p erceived source base station state. Navya Sivaraman, Simin Nadjm-Tehrani |
SECRYPT | 2 |
| 2023 | VioLinn: Proximity-aware Edge Placementwith Dynamic and Elastic Resource ProvisioningabstractDeciding where to handle services and tasks, as well as provisioning an adequate amount of computing resources for this handling, is a main challenge of edge computing systems. Moreover, latency-sensitive services constrain the type and location of edge devices that can provide the needed resources. When available resources are scarce there is a possibility that some resource allocation requests are denied. In this work, we propose the VioLinn system to tackle the joint problems of task placement, service placement, and edge device provisioning. Dealing with latency-sensitive services is achieved through proximity-aware algorithms that ensure the tasks are handled close to the end-user. Moreover, the concept of spare edge device is introduced to handle sudden load variations in time and space without having to continuously overprovision. Several spare device selection algorithms are proposed with different cost/performance tradeoffs. Evaluations are performed both in a Kubernetes-based testbed and using simulations and show the benefit of using spare devices for handling localized load spikes with higher quality of service (QoS) and lower computing resource usage. The study of the different algorithms shows that it is possible to achieve this increase in QoS with different tradeoffs against cost and performance. Klervie Toczé, Ali J. Fahs, Guillaume Pierre, Simin Nadjm-Tehrani |
ACM Trans. Internet Things | 4 |
| 2021 | Abstraction models for verifying resource adequacy of IMA systems at concept levelabstractComplex cyber-physical systems can be difficult to analyze for resource adequacy (e.g., bandwidth and buffer size) at the concept development stage since relevant models are hard to create. During this period, details about the functions to be executed or the platforms in the architecture are partially unknown. This is especially true for Integrated Modular Avionics (IMA) systems, for which life-cycles span over several decades, with potential changes to functionality in the future. This work aims to identify abstractions for representing data exchanges among functions realized in networked IMA systems and investigates how these can be represented in formal models and analyzed with exact guarantees. Timed automata (TA) are a relevant choice for modeling since communication resource adequacy is directly related to potential network delays. We explore two alternatives in modeling with TA, a direct one representing every process using a TA template, and a more abstract one representing every computation device with a TA template. While the first approach represents process-to-process data exchanges, the modified approach reduces the state space by representing all processes currently allocated to a single computing element to obtain scalability gains. Both approaches are flexible since the templates presented can be instantiated to represent different types of network topologies and communication patterns. The instantiated TA models are used to illustrate an use case and analyzed with the UPPAAL model checker to verify that a given platform instance supports the desired system functions in terms of network bandwidth and buffer size adequacy, thereby messages reaching their final destination with freshness guarantees. Both abstraction levels are shown to be suitable for verifying the intended properties, but the more abstract one demonstrates a 67% improvement in verification time and a 66% reduction in state space during verification. The more abstract approach is also applied to a real-world example from an earlier publication, with a much larger state space and a more complex structure, to illustrate the ability to reuse the approach in multiple use cases. Rodrigo S. de Moraes, Simin Nadjm-Tehrani |
Sci. Comput. Program. | 2 |
| 2021 | On Generating Network Traffic Datasets with Synthetic Attacks for Intrusion DetectionabstractMost research in the field of network intrusion detection heavily relies on datasets. Datasets in this field, however, are scarce and difficult to reproduce. To compare, evaluate, and test related work, researchers usually need the same datasets or at least datasets with similar characteristics as the ones used in related work. In this work, we present concepts and the Intrusion Detection Dataset Toolkit (ID2T) to alleviate the problem of reproducing datasets with desired characteristics to enable an accurate replication of scientific results. Intrusion Detection Dataset Toolkit (ID2T) facilitates the creation of labeled datasets by injecting synthetic attacks into background traffic. The injected synthetic attacks created by ID2T blend with the background traffic by mimicking the background traffic’s properties. This article has three core contributions. First, we present a comprehensive survey on intrusion detection datasets. In the survey, we propose a classification to group the negative qualities found in the datasets. Second, the architecture of ID2T is revised, improved, and expanded in comparison to previous work. The architectural changes enable ID2T to inject recent and advanced attacks, such as the EternalBlue exploit or a peer-to-peer botnet. ID2T’s functionality provides a set of tests, known as TIDED, that helps identify potential defects in the background traffic into which attacks are injected. Third, we illustrate how ID2T is used in different use-case scenarios to replicate scientific results with the help of reproducible datasets. ID2T is open source software and is made available to the community to expand its arsenal of attacks and capabilities. Carlos Garcia Cordero, Emmanouil Vasilomanolakis, Aidmar Wainakh, Max Mühlhäuser, Simin Nadjm-Tehrani |
ACM Trans. Priv. Secur. | 5 |
| 2020 | Permissioned blockchains and distributed databases: A performance studyabstractSummary Blockchains are increasingly studied in the context of new applications. Permissioned blockchains promise to deal with the issue of complete removal of trust, a notion that is currently the hallmark of the developed society. Before the idea is adopted in contexts where resource efficiency and fast operation is a requirement, one could legitimately ask the question: can permissioned blockchains match the performance of traditional large‐scale databases? This paper compares two popular frameworks, Hyperledger Fabric and Apache Cassandra, as representatives of permissioned blockchains and distributed databases, respectively. We compare their latency for varying workloads and network sizes. The results show that, for small systems, blockchains can start to compete with traditional databases, but also that the difference in consistency models and differences in setup can have a large impact on the resulting performance. Sara Bergman, Mikael Asplund, Simin Nadjm-Tehrani |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | Formal verification of input-output mappings of tree ensembles
John Törnblom, Simin Nadjm-Tehrani |
Sci. Comput. Program. | 2 |
| 2019 | ORCH: Distributed Orchestration Framework using Mobile Edge DevicesabstractIn the emerging edge computing architecture, several types of devices have computational resources available. In order to make efficient use of those resources, deciding on which device a task should execute is of great importance.Existing works on task placement in edge computing focus on a resource supply side consisting of stationary devices only. In this paper, we consider the addition of mobile edge devices. We explore how mobile and stationary edge devices can augment the original task placement problem with a second placement problem: the placement of the mobile edge devices.We propose the ORCH framework in order to solve the joint problem in a distributed manner and evaluate it in the context of a spatially-changing load. Our implementation of the combined task and edge placement algorithms shows a normalized 83% delay-sensitive task completion rate compared to a perfect edge placement strategy. Klervie Toczé, Simin Nadjm-Tehrani |
ICFEC | 2 |
| 2019 | Timing Patterns and Correlations in Spontaneous SCADA Traffic for Anomaly Detection
Chih-Yuan Lin, Simin Nadjm-Tehrani |
RAID | 2 |
| 2019 | A STAMP-based ontology approach to support safety and security analyses
Daniel Patrick Pereira, Celso M. Hirata, Simin Nadjm-Tehrani |
J. Inf. Secur. Appl. | 3 |
| 2018 | RICS-el: Building a National Testbed for Research and Training on SCADA Security (Short Paper)
Magnus Almgren, Peter Andersson, Gunnar Björkman, Mathias Ekstedt, Jonas Hallberg, Simin Nadjm-Tehrani, Erik Westring |
CRITIS | 6 |
| 2018 | Fault and timing analysis in critical multi-core systems: A survey with an avionics perspectiveabstractWith more functionality added to future safety-critical avionics systems, new platforms are required to offer the computational capacity needed. Multi-core processors offer a potential that is promising, but they also suffer from two issues that are only recently being addressed in the safety-critical contexts: lack of methods for assuring timing determinism, and higher sensitivity to permanent and transient faults due to shrinking transistor sizes. This paper reviews major contributions that assess the impact of fault tolerance on worst-case execution time of processes running on a multi-core platform. We consider the classic approach for analyzing the impact of faults in such systems, namely fault injection. The review therefore explores the area in which timing effects are studied when fault injection methods are used. We conclude that there are few works that address the intricate timing effects that appear when inter-core interferences due to simultaneous accesses of shared resources are combined with fault tolerance techniques. We assess the applicability of the methods to currently available multi-core processors used in avionics. Dark spots on the research map of the integration problem of hardware reliability and timing predictability for multi-core avionics systems are identified. Andreas Löfwenmark, Simin Nadjm-Tehrani |
J. Syst. Archit. | 2 |
| 2018 | A Taxonomy for Management and Optimization of Multiple Resources in Edge ComputingabstractEdge computing is promoted to meet increasing performance needs of data‐driven services using computational and storage resources close to the end devices at the edge of the current network. To achieve higher performance in this new paradigm, one has to consider how to combine the efficiency of resource usage at all three layers of architecture: end devices, edge devices, and the cloud. While cloud capacity is elastically extendable, end devices and edge devices are to various degrees resource‐constrained. Hence, an efficient resource management is essential to make edge computing a reality. In this work, we first present terminology and architectures to characterize current works within the field of edge computing. Then, we review a wide range of recent articles and categorize relevant aspects in terms of 4 perspectives: resource type, resource management objective, resource location, and resource use. This taxonomy and the ensuing analysis are used to identify some gaps in the existing research. Among several research gaps, we found that research is less prevalent on data, storage, and energy as a resource and less extensive towards the estimation, discovery, and sharing objectives. As for resource types, the most well‐studied resources are computation and communication resources. Our analysis shows that resource management at the edge requires a deeper understanding of how methods applied at different levels and geared towards different resource types interact. Specifically, the impact of mobility and collaboration schemes requiring incentives are expected to be different in edge architectures compared to the classic cloud solutions. Finally, we find that fewer works are dedicated to the study of nonfunctional properties or to quantifying the footprint of resource management techniques, including edge‐specific means of migrating data and services. Klervie Toczé, Simin Nadjm-Tehrani |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | Timing-Based Anomaly Detection in SCADA Networks
Chih-Yuan Lin, Simin Nadjm-Tehrani, Mikael Asplund |
CRITIS | 2 |
| 2017 | Schedulability and Memory Interference Analysis of Multicore Preemptive Real-time SystemsabstractToday's embedded systems demand increasing computing power to accommodate the ever-growing software functionality. Automotive and avionic systems aim to leverage the high performance capabilities of multicore platforms, but are faced with challenges with respect to temporal predictability. Multicore designers have achieved much progress on improvement of memory-dependent performance in caching systems and shared memories in general. However, having applications running simultaneously and requesting the access to the shared memories concurrently leads to interference. The performance unpredictability resulting from interference at any shared memory level may lead to violation of the timing properties in safety-critical real-time systems. In this paper, we introduce a formal analysis framework for the schedulability and memory interference of multicore systems with shared caches and DRAM. We build a multicore system model with a fine grained application behavior given in terms of periodic preemptible tasks, described with explicit read and write access numbers for shared caches and DRAM. We also provide a method to analyze and recommend candidates for task-to-core reallocation with the goal to find schedulable configurations if a given system is not schedulable. Our model-based framework is realized using Uppaal and has been used to analyze a case study. Abdeldjalil Boudjadar, Simin Nadjm-Tehrani |
ICPE | 2 |
| 2016 | Performance-aware scheduling of multicore time-critical systemsabstractDespite attractiveness of multicore processors for embedded systems, the potential performance gains need to be studied in the context of real-time task scheduling and memory interference. This paper explores performance-aware schedula-bility of multicore systems by evaluating the performance when changing scheduling policies (as design parameters). The modelbased framework we build enables analyzing the performance of multicore time-critical systems using processor-centric and memory-centric scheduling policies. The system architecture we consider consists of a set of cores with a local cache and sharing the cache level L2 and main memory (DRAM). The metrics we use to compare the performance achieved by different configurations of a system are: 1) utilization of the cores; and 2) the maximum delay per access request to shared cache and DRAM. Our framework, realized using UPPAAL, can be viewed as an engineering tool to be used during design stages to identify the scheduling policies that provide better performance for a given system while maintaining system schedulability. As a proof of concept, we analyze and compare 2 different cases studies. Abdeldjalil Boudjadar, Jin Hyun Kim, Simin Nadjm-Tehrani |
MEMOCODE | 3 |
| 2015 | Experience report: Memory accesses for avionic applications and operating systems on a multi-core platformabstractThe deployment of multi-core platforms in safety-critical avionic applications is hampered by the lack of means to ensure predictability when processes running on different cores can create interference effects, affecting worst-case execution time, due to shared memory accesses. One way to restrict these interferences is to allocate a budget for different processes prior to run-time and to monitor the adherence to this budget during run-time. While earlier works in adopting this approach seem promising, they focus on application level (user mode) accesses to shared memory and not the operating system accesses. In this paper we construct experiments for studying a multi-core platform running an ARINC 653 compliant operating system, and measure the impact of both application processes and operating system (supervisor mode) activities. In particular, as opposed to earlier works that considered networking applications, we select four avionic processes that exhibit different memory access patterns, namely, a navigation process, a matrix multiplication process, a math library process and an image processing one. The benchmarking on a set of avionic-relevant application processes shows that (a) the potential interference by the operating system cannot be neglected when allocating budgets that are to be monitored at run-time, and (b) the bounds for the allowed number of memory accesses should not always be based on the maximum measured count during profiling, which would lead to overly pessimistic budgets. Andreas Löfwenmark, Simin Nadjm-Tehrani |
ISSRE | 2 |
| 2015 | Quantifying Risks to Data Assets Using Formal Metrics in Embedded System Design
Maria Vasilevskaya, Simin Nadjm-Tehrani |
SAFECOMP | 2 |
| 2014 | Model-Based Security Risk Analysis for Networked Embedded Systems
Maria Vasilevskaya, Simin Nadjm-Tehrani |
CRITIS | 2 |
| 2014 | Cooperative proxies: Optimally trading energy and quality of service in mobile devicesabstractThis work studies the energy and quality of service (QoS) trade-off in the context of mobile devices with two communication interfaces (a high energy and a low energy interface). We propose an optimisation scheme during underload scenarios where proxy groups are dynamically formed exploiting both interfaces. The scheme integrates a reward mechanism that compensates a proxy while carrying other group members’ traffic, and deals with churn (joining and leaving of nodes) in a cell area. For traffic flows that approximate knowledge about current services we show that the scheme can achieve energy savings of 60% for all mobile nodes as whole. We also demonstrate the impact on disruption-sensitive flows as a function of the traffic mix, and that the use of rewards for selection of proxies is a fair mechanism in the long term. Aruna Prem Bianzino, Mikael Asplund, Ekhiotz Jon Vergara, Simin Nadjm-Tehrani |
Comput. Networks | 4 |
| 2014 | Integrating security mechanisms into embedded systems by domain-specific modellingabstractABSTRACT Embedded devices are crucial enablers of the Internet of Things and become increasingly common in our daily life. They store, manipulate and transmit sensitive information and, therefore, must be protected against security threats. Due to the security and also resource constraint concerns, designing secure networked embedded systems is a difficult task. Model‐based development (MBD) is promoted to address complexity and ease the design of software intensive systems. We leverage MBD and domain‐specific modelling to characterise common issues related to security and embedded systems that are specific to a given application domain. Security‐specific knowledge relevant for a certain application domain is represented in the form of an adapted information security ontology. Further, the elements of the ontology are associated with security building blocks modelled with the MBD method SPACE. The selection of relevant security building blocks is based on (i) assets automatically elicited from the functional models, (ii) domain security knowledge captured by the security expert and (iii) the platform adopted by the embedded system engineer. A tool is developed to support the steps supporting this methodology and help to bridge between the security and embedded systems domains. We illustrate our approach with a case study from the smart metering domain. © 2013 The Authors. Security and Communication Networks published by John Wiley & Sons, Ltd. Maria Vasilevskaya, Linda Ariani Gunawan, Simin Nadjm-Tehrani, Peter Herrmann |
Secur. Commun. Networks | 3 |
| 2013 | Kernel level energy-efficient 3G background traffic shaper for android smartphonesabstractReducing the energy consumption of wireless devices is paramount to a wide spread adoption of mobile applications. Cellular communication imposes high energy consumption on the mobile devices due to the radio resource allocation, which differs from other networks such as WiFi. Most applications are unaware of the energy consumption characteristics of third generation cellular communication (3G). This makes the background small data transfers of undisciplined applications an energy burden due to inefficient utilisation of resources. While several approaches exist to reduce the energy consumption of this best-effort background traffic by means of traffic shaping, we find that they are mostly evaluated with simulations and the actual energy overhead for the traffic shaper itself has not been studied. In order to cover this gap, our work realises an existing energy saving algorithm as a Kernel Level Shaper (KLS) within the Android platform, and measures its energy footprint. The total energy savings of our implementation range from 8% to 58% for emulated real background traffic, that is categorised as best-effort traffic. We further show the implications of running the KLS during live operation of applications as an exploratory study. Ekhiotz Jon Vergara, Joseba Sanjuan, Simin Nadjm-Tehrani |
IWCMC | 3 |
| 2013 | Exploiting resource heterogeneity in delay-tolerant networksabstractABSTRACT Routing in delay and disruption‐tolerant networks (DTNs) relies on intermediary nodes, called custodians, to deliver messages to destination. However, nodes usually differ significantly in terms of available resources: energy, buffer space and bandwidth. Routing algorithms need to make the most efficient use of custodian resources while also making sure those in limited supply are not exhausted. This paper proposes a distributed scheme for calculating resources available in node vicinity as a tool to support meaningful routing decisions. A generic model is developed first and is then applied to individual network assets. The model is based on a sparse network, where resources are potentially not uniformly distributed. It uses recent encounters to estimate resource availability in node vicinity. It is shown that a store‐carry‐forward scheme may benefit from accessing vicinity resource estimates. This knowledge allows nodes to implement meaningful custodian election and queue management strategies, approached here from a holistic perspective. It is demonstrated that routing protocols not only use up fewer resources overall but also consume resources preferentially from nodes with higher resource levels, sparing nodes with limited supplies. As a result, disparities in available resources across the node population are significantly reduced, and nodes are less likely to leave the network as a consequence of resource depletion. Copyright © 2012 John Wiley & Sons, Ltd. Gabriel Sandulescu, Péter Schaffer, Simin Nadjm-Tehrani |
Wirel. Commun. Mob. Comput. | 3 |
| 2012 | Embedded Cyber-Physical Anomaly Detection in Smart Meters
Massimiliano Raciti, Simin Nadjm-Tehrani |
CRITIS | 2 |
| 2012 | Surviving Attacks in Challenged NetworksabstractIn the event of a disaster, telecommunication infrastructures can be severely damaged or overloaded. Hastily formed networks can provide communication services in an ad hoc manner. These networks are challenging due to the chaotic context where intermittent connection is the norm and the identity and number of participants cannot be assumed. In such environments malicious actors may try to disrupt the communications to create more chaos for their own benefit. This paper proposes a general security framework for monitoring and reacting to disruptive attacks. It includes a collection of functions to detect anomalies, diagnose them, and perform mitigation. The measures are deployed in each node in a fully distributed fashion, but their collective impact is a significant resilience to attacks, so that the actors can disseminate information under adverse conditions. The approach has been evaluated in the context of a simulated disaster area network with a manycast dissemination protocol, Random Walk Gossip, with a store-and-forward mechanism. A challenging threat model where adversaries may attempt to reduce message dissemination or drain network resources without spending much of their own energy has been adopted. Jordi Cucurull-Juan, Mikael Asplund, Simin Nadjm-Tehrani, Tiziano Santoro |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2010 | Anomaly Detection and Mitigation for Disaster Area Networks
Jordi Cucurull-Juan, Mikael Asplund, Simin Nadjm-Tehrani |
RAID | 3 |
| 2009 | A Partition-Tolerant Manycast Algorithm for Disaster Area NetworksabstractInformation dissemination in disaster scenarios requires timely and energy-efficient communication in intermittently connected networks. When the existing infrastructure is damaged or overloaded, we suggest the use of a manycast algorithm that runs over a wireless mobile ad hoc network, and overcomes partitions using a store-and-forward mechanism. This paper presents a random walk gossip protocol that uses an efficient data structure to keep track of already informed nodes with minimal signaling. Avoiding unnecessary transmissions also makes it less prone to overloads. Experimental evaluation shows higher delivery ratio, lower latency, and lower overhead compared to a recently published algorithm. Mikael Asplund, Simin Nadjm-Tehrani |
SRDS | 2 |
| 2009 | Middleware extensions that trade consistency for availabilityabstractAbstract Replicated distributed object systems are deployed to provide timely and reliable services to actors at distributed locations. This paper treats applications in which data updates are dependent on satisfaction of integrity constraints over multiple objects. Network partitions, caused by occasional link failures, overload or attacks create problems in keeping both consistency and availability in such networks. We propose a means of achieving higher availability by providing partition‐awareness in middleware. The general approach has been illustrated by implementing a number of CORBA extensions that trade consistency for availability during network partitions. This paper contains a thorough experimental evaluation that presents the gains and costs of our approach. The experiments clearly illustrate the benefit of our protocols in terms of significantly higher availability and the number of performed operations. Copyright © 2009 John Wiley & Sons, Ltd. Mikael Asplund, Simin Nadjm-Tehrani, Klemen Zagar |
Concurr. Comput. Pract. Exp. | 2 |
| 2008 | Emerging Information Infrastructures: Cooperation in Disasters
Mikael Asplund, Simin Nadjm-Tehrani, Johan Sigholm |
CRITIS | 2 |
| 2008 | Tool Support for Incremental Failure Mode and Effects Analysis of Component-Based SystemsabstractFailure mode and effects analysis (FMEA) is a well-known technique widely used for safety assessment in the area of safety-critical systems. However, FMEA is traditionally done manually which makes it both time-consuming and costly, specially for large and complex systems. Also, small modifications in the design may result in a complete revision of the initial FMEA. This paper presents a tool support for automated incremental component-based FMEA of SW and HW. It is based on component safety interfaces and a formal compositional safety analysis method. This tool support enables engineers to focus on more important steps in the safety assessment process. Also, during system upgrades, the tool incrementally registers the changes and identifies possible effects in the FMEA which enables the use of earlier safety analysis results. Finally, this formal approach based on design models of the components and the system always creates FMEAs which are consistent with the system design. Jonas Elmqvist, Simin Nadjm-Tehrani |
DATE | 2 |
| 2008 | A Bidding Algorithm for Optimized Utility-Based Resource Allocation in Ad Hoc NetworksabstractThis article proposes a scheme for bandwidth allocation in wireless ad hoc networks. The quality of service (QoS) levels for each end-to-end flow are expressed using resource-utility functions, and our algorithms aim to maximize aggregated utility. The shared channel is modeled as bandwidth resources defined by maximal cliques of mutual interfering links. We propose an entirely novel resource allocation algorithm that employs auction mechanisms where flows are bidding for resources. The bids depend both on the flow's utility function and the intrinsically derived shadow prices. Then we combine it with a utility-aware on-demand shortest path routing algorithm where shadow prices are used as a natural distance metric. We also show that the problem can be formulated as a linear programming problem. Thus we can compare the performance of our scheme to the centralized optimal LP solution, registering results very close to the optimum. We isolate the performance of the price-based routing and show its advantages in hotspot scenarios, and also propose an asynchronous version that is more feasible for ad hoc environments. Experimental results of a comparison with the state-of-the-art approach based on Kelly's utility maximization framework show that our approach exhibits superior performance for networks with both increased mobility or increased allocation period. Calin Curescu, Simin Nadjm-Tehrani |
IEEE Trans. Mob. Comput. | 2 |
| 2007 | Measuring Availability in Optimistic Partition-Tolerant Systems with Data ConstraintsabstractReplicated systems that run over partitionable environments, can exhibit increased availability if isolated partitions are allowed to optimistically continue their execution independently. This availability gain is traded against consistency, since several replicas of the same objects could be updated separately. Once partitioning terminates, divergences in the replicated state needs to be reconciled. One way to reconcile the state consists of letting the application manually solve inconsistencies. However, there are several situations where automatic reconciliation of the replicated state is meaningful. We have implemented replication and automatic reconciliation protocols that can be used as building blocks in a partition-tolerant middleware. The novelty of the protocols is the continuous service of the application even during the reconciliation process. A prototype system is experimentally evaluated to illustrate the increased availability despite network partitions. Mikael Asplund, Simin Nadjm-Tehrani, Stefan Beyer, Pablo Galdámez |
DSN | 2 |
| 2007 | Adaptive real-time anomaly detection with incremental clustering
Kalle Burbeck, Simin Nadjm-Tehrani |
Inf. Secur. Tech. Rep. | 2 |
| 2006 | Comparative study of price-based resource allocation algorithms for ad hoc networksabstractAs mobile ad hoc networks provide a wide range of possibly critical services, providing quality of service guarantees becomes an essential element. Yet there is a limited understanding of the performance characteristics of different resource allocation algorithms. In particular, there is little work that comparatively studies different algorithms in the same traffic environment. Therefore we study two algorithms, ad hoc-TARA and an algorithm based on the gradient projection method, for optimised bandwidth allocation in ad hoc networks under overload situations. The focus is on convergence properties and performance measured in terms of accumulated utility. The simulation results show that the gradient projection algorithm converges to an optimal solution even in large, dynamic networks, but that in such dynamic environments the convergence time can significantly influence the overall performance. In comparison, the near-optimal algorithm ad hoc-TARA, which quickly adapts to changes in the state of the network, can exhibit superior performance. Further we illustrate how different parameter settings influence the performance of the algorithms. We conclude that finding an optimal allocation comes at a high price in the rapidly changing environments of ad hoc networks and that near-optimal allocation can be an ample alternative. Marcel Lüthi, Simin Nadjm-Tehrani, Calin Curescu |
IPDPS | 2 |
| 2005 | Optimal Choice of Checkpointing Interval for High AvailabilityabstractSupporting high availability by checkpointing and switching to a backup upon failure of a primary has a cost. Trade-off studies help system architects to decide whether higher availability at the cost of higher response time is to strive for. The decision leads to configuring a fault-tolerant server for best performance. This paper provides a mathematical model employing queuing theory that helps to compute the optimal checkpointing interval for a primary-backup replicated server. The optimization criterion is system availability. The model guides towards the checkpointing interval that is short enough to give low failover time, but long enough to utilize most of the system resources for servicing client requests. The novelty of the work is the detailed modelling of service times, wait times for earlier calls in the queue, and priority of checkpointing calls over client calls within the queues. Studies on the model in Mathematica and validation of a modelling assumption through simulations are included. Diana Szentiványi, Simin Nadjm-Tehrani, John M. Noble |
PRDC | 2 |
| 2005 | Utility-based Adaptive Resource Allocation in Hybrid Wireless NetworksabstractService availability in wireless networks is highly dependent on efficient resource allocation and guaranteed quality of service (QoS) amid overloads and failures. This paper addresses optimal bandwidth allocation in a hybrid network (cellular and ad hoc), where added reach through an ad hoc overlay is combined with the stability and essential services of a cellular network. The paper builds on a near optimal approach in which resource-utility functions are used as a means of adaptive delivery of QoS, user differentiation, and maximisation of system level utility. It distinguishes between non-adaptive, semi-adaptive, and fully adaptive applications. First, the global cellular bandwidth allocation (in the presence of multiple routes through ad hoc relays) is cast in terms of a linear programming problem. Second, a heuristic algorithm that has far lower computational overhead and accrues at worse 12% less than the utility of the optimal solution is presented. Both algorithms are implemented within a model of a hybrid network on top of the J-Sim simulation environment. Comparative studies are made to show effective load balancing and crash tolerance in the presence of a high traffic overload Calin Curescu, Simin Nadjm-Tehrani, Bing Cao 0001, Teresa A. Dahlberg |
QSHINE | 2 |
| 2005 | Safety Interfaces for Component-Based Systems
Jonas Elmqvist, Simin Nadjm-Tehrani, Marius Minea |
SAFECOMP | 2 |
| 2005 | Price/utility-based optimized resource allocation in wireless ad hoc networksabstractAbstract — This paper proposes a scheme for bandwidth allocation in wireless ad hoc networks. The Quality of Service (QoS) levels for each end-to-end flow are expressed using resource-utility functions, and our algorithms aim to maximise the aggregated utility of the flows. The scheme differentiates between applications with flexible resource requirements and rigid (real-time) requirements. As an abstract notion of resource, we use maximal cliques of mutual interfering links. Using concave piece-wise linear utility functions we present a linear programming (LP) formulation of the problem that can serve as an optimal though unrealistic solution. Then we replace this centralised approach with a distributed low complexity solution. A key concept, borrowed from the dual of the optimal allocation problem, is the shadow price of a resource. The contributions of the paper are twofold: (1) a distributed algorithm that allocates the bandwidth based on bids that are calculated using the shadow price of the resources and the flow’s utility function, (2) a utility-aware on-demand ”shortest ” path routing algorithm in which the shadow prices are used a natural distance metric. We compare the performance of the distributed allocation scheme with the centralised, optimal linear programming solution. We also compare with a non-utility-based QoS allocation scheme, that uses hop-based shortest path routing followed by highest possible bandwidth accommodation of the flow. I. Calin Curescu, Simin Nadjm-Tehrani |
SECON | 2 |
| 2005 | Formal verification of fault tolerance in safety-critical reconfigurable modules
Jerker Hammarberg, Simin Nadjm-Tehrani |
Int. J. Softw. Tools Technol. Transf. | 2 |
| 2005 | Time-Aware Utility-Based Resource Allocation in Wireless NetworksabstractThis paper presents a time-aware admission control and resource allocation scheme in wireless networks in the context of a future generation cellular network. The quality levels (and their respective utility) of different connections are specified using discrete resource-utility (R-U) functions. The scheme uses these R-U functions for allocating and reallocating bandwidth to connections, aiming to maximize the accumulated utility of the system. However, different applications react differently to resource reallocations. Therefore, at each allocation time point, the following factors are taken into account: the age of the connection, a disconnection (drop) penalty, and the sensitiveness to reallocation frequency. The evaluation of our approach shows a superior performance compared to a recent adaptive bandwidth allocation scheme (RBBS). In addition, we have studied the overhead that performing a reallocation imposes on the infrastructure. To minimize this overhead, we present an algorithm that efficiently reduces the number of reallocations while remaining within a given utility bound. Calin Curescu, Simin Nadjm-Tehrani |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2004 | Scale-up and performance studies of three agent platformsabstractWith maturing technology agents are now a viable choice for distributed computing, also for systems with requirements on dependability and scalability. Agent platforms provide common services to applications developed as agents. Given the abundance of available platforms it is not easy to select an agent platform given a set of applications requirements. Evaluations of relevant properties of agent platforms are therefore needed, but unfortunately few up-to-date evaluations exist. In this paper we introduce and evaluate the three recent agent platforms JADE, Tryllian and SAP. Focus of the evaluation is the important properties of performance, security and scalability. We conclude that all platforms perform very well, but that platform architecture heavily influences the performance. Kalle Burbeck, Daniel Garpe, Simin Nadjm-Tehrani |
IPCCC | 3 |
| 2004 | Aspects for Improvement of Performance in Fault-Tolerant SoftwareabstractWe describe the use of aspect-oriented programming to improve performance of fault-tolerant (FT) servers built with middleware support. Its contribution is to shift method call logging from middleware to application level in primary-backup replication. The novelty consists in no burden being placed on application writers, except for a simple component description aiding automatic generation of aspect code. The approach is illustrated by describing how synchronization aspects are weaved in an application, and modifications of an FT-CORBA platform to avoid middleware level logging. Evaluation is performed using a telecom application enriched with aspects, running on top of the aspect-supporting platform. We compare overheads with earlier results from runs on the base-line platform. Experiments show a drop of around 40% of original overheads. This is due to methods starting execution before previous ones end, in contrast to ordering enforced at middleware level where methods are executed sequentially, not adapting to application knowledge. Diana Szentiványi, Simin Nadjm-Tehrani |
PRDC | 2 |
| 2004 | Raising motivation in real-time laboratories: the soccer scenarioabstractReal-time systems is a topic that one cannot overlook in an engineer's education. However, teaching real-time systems in an undergraduate syllabus is a challenging experience due to conflicting constraints placed on such a course. In this paper we present a new setup for laboratories in the real-time systems course that successfully meets the constraints of mass education, stable environment management, short time span for the labs, and still enables deep involvement of students in the central topic of resource allocation with high motivation. Mehdi Amirijoo, Aleksandra Tesanovic, Simin Nadjm-Tehrani |
SIGCSE | 3 |
| 2003 | Time-Aware Utility-Based QoS OptimisationabstractThis paper presents a time-aware admission control and resource allocation scheme in the context of a future generation mobile network. The quality levels (and their respective utility) of the different connections are specified using discrete resource-utility (R-U) functions. The scheme uses these R-U functions for allocating and reallocating bandwidth to connections, aiming to maximize the accumulated utility of the system. However, different applications react differently to resource reallocations Therefore at each allocation timepoint we take into account the following factors: the age of the connection, a drop (disconnection) penalty and the sensitiveness to reallocation frequency. Finally, we show the superior performance of our approach compared to a recent adaptive bandwidth allocation scheme. Calin Curescu, Simin Nadjm-Tehrani |
ECRTS | 2 |
| 2002 | Mid-term course evaluations with muddy cardsabstractNo abstract available. Christoph W. Kessler, Simin Nadjm-Tehrani |
ITiCSE | 2 |
| 2002 | Adaptive load control algorithms for 3rd generation mobile networksabstractIn this paper we present strategies to deal with inherent load uncertainties in future generation mobile networks. We address the interplay between user differentiation and resource allocation, and specifically the problem of CPU load control in a radio network controller (RNC).The algorithms we present distinguish between two types of uncertainty: the resource needs for arriving requests and the variation over time with respect to user service policies. We use feedback mechanisms inspired by automatic control techniques for the first type, and policy-dependent deterministic algorithms for the second type. We test alternative strategies in overload situations. One approach combines feedback control with a pool allocation mechanism, and a second is based on a rejection-ratio-minimising algorithm together with a state estimator.A simulation environment and traffic models for users with voice, mail, SMS and web browsing sessions were built for the purpose of evaluation of the above strategies. Our load control architectures were tested in comparison with an existing algorithm based on the leaky bucket principle. The studies show a superior behaviour with respect to load control in presence of relative user priorities, and minimal rejection criteria. Moreover, our architecture can be tuned to future developments with respect to user differentiation policy. Simin Nadjm-Tehrani, Kayvan Najarian, Calin Curescu, Tomas Lingvall, Teresa A. Dahlberg |
MSWiM | 1 |
| 2001 | Real-time lab excercises: a teacher's dilemmaabstractThis paper describes our design of real-time systems laboratories in an integrated theme of study which includes automatic control. The theme appears at the end of the third year of a 4,5 year master of engineering programme, which adopts Problem-Based Learning (PBL) as a main pedagogical method. We describe the rationale behind our choice of application area, the lab environment, and the operating system used. The paper concludes by giving some qualitative evaluations as well as some quantitative measures based on limited data. Erik Herzog, Peter Loborg, Simin Nadjm-Tehrani |
SIGCSE | 3 |
| 1999 | Formal Verification of Dynamic Properties in an Aerospace Application
Simin Nadjm-Tehrani, Jan-Erik Strömberg |
Formal Methods Syst. Des. | 1 |
| 1995 | Proving Dynamic Properties in an Aerospace ApplicationabstractWe give an exposition to an ongoing research effort in cooperation with aerospace industries in Sweden. We report on an application of formal verification techniques on a landing gear system. This system consists of actuating hydromechanic and electromechanic hardware, and of controlling software components. We emphasize the need for modelling techniques and languages covering the whole spectrum from informal engineering documents, to hybrid mathematical models. In this modelling process we give as much weight to the physical environment as to the controlling software. We show the application of two verification methods for proving safety and timeliness properties of the closed loop system; first, using the proof system of extended duration calculus, and second by symbolic model checking. Simin Nadjm-Tehrani, Jan-Erik Strömberg |
RTSS | 1 |