Haider Abbas

dblp:04/7436 · DBLP profile ↗
← Back
78ranked-venue papers
8as first author
26since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 18 · 1 first-author · 6 since 2021Systems, architecture and hardware · 14 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 3 since 2021Artificial intelligence and machine learning · 10 · 5 since 2021Security and privacy · 9 · 5 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 7 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Guest Editorial:Generative Artificial Intelligence Driven Smart Healthcare
Junxin Chen 0001, Zhihan Lyu, Danda B. Rawat, Haider Abbas
IEEE J. Biomed. Health Informatics4
2024 DUDE: Decryption, Unpacking, Deobfuscation, and Endian Conversion Framework for Embedded Devices Firmware
abstract
Commercial-Off-The-Shelf (COTS) embedded devices rely on vendor-specific firmware to perform essential tasks. These firmware have been under active analysis by researchers to check security features and identify possible vendor backdoors. However, consistently unpacking newly created filesystem formats has been exceptionally challenging. To thwart attempts at unpacking, vendors frequently use encryption and obfuscation methods. On the other hand, when handling encrypted, obfuscated, big endian cramfs, or custom filesystem formats found in firmware under test, the available literature and tools are insufficient. This study introduces DUDE, an automated framework that provides novel functionalities, outperforming cutting-edge tools in the decryption, unpacking, deobfuscation, and endian conversion of firmware. For big endian compressed romfs filesystem formats, DUDE supports endian conversion. It also supports deobfuscating obfuscated signatures for successful unpacking. Moreover, decryption support for encrypted binaries from the D-Link and MOXA series has also been added, allowing for easier analysis and access to the contents of these firmware files. Additionally, the framework offers unpacking assistance by supporting the extraction of special filesystem formats commonly found in firmware samples from various vendors. A remarkable 78% (1424 out of 1814) firmware binaries from different vendors were successfully unpacked using the suggested framework. This performance surpasses the capabilities of commercially available tools combined on a single platform.
Haider Abbas, Maliha Safdar, Ahmed Hemani
IEEE Trans. Dependable Secur. Comput.1
2023 CNN-HMM Model for Real Time DGA Categorization
Aimen Mahmood, Haider Abbas, M. Faisal Amjad
SECRYPT2
2023 An Efficient and Physically Secure Privacy-Preserving Key-Agreement Protocol for Vehicular Ad-Hoc Network
abstract
The popularity of vehicles promotes the evolution of smart cities. This development makes vehicular ad-hoc network (VANET) a widely used inter-vehicular communication to obtain information about road conditions, speed, vehicle location and traffic congestion. Such a public network is vulnerable to different security threats. Overall, the security of private data in VANET is a critical task. It has been observed that various authentication protocols have been devised for VANETs. However, most of the proposed protocols are not secure and reliable because of different security threats, including denial of service, replay, forgery and impersonation attacks, etc. Furthermore, the existing protocols used extra communication overhead and computational cost, so they become infeasible for resource-constrained environments. In this article, we design a lightweight and secure privacy-preserving key agreement protocol for VANETs using the hashing technique, which provides an efficient and secure data transmission mechanism over a public communication channel. Detailed security analysis shows that the proposed protocol is secure against various attacks. To evaluate the performance of the protocol, we simulate key cryptographic operations of vehicles, a roadside unit, and a trusted party agent on Arduino, low-end and high-end devices, respectively. The experimental results show that compared with the other related protocols, the computational cost and communication overhead of our protocol are reduced on average by 8.797% and 22.06 %, respectively. Additionally, simulation results on NS3 show that our protocol consistently achieves a packet delivery ratio higher than 99.91 %. Therefore, our protocol is secure and reliable for VANET environment.
Muhammad Asad Saleem, Xiong Li 0002, Muhammad Faizan Ayub, Salman Shamshad, Fan Wu 0003, Haider Abbas
IEEE Trans. Intell. Transp. Syst.6
2022 An Ensemble Based Deep Learning Framework to Detect and Deceive XSS and SQL Injection Attacks
Waleed Bin Shahid, Baber Aslam, Haider Abbas, Hammad Afzal, Imran Rashid
ACIIDS (1)3
2022 Keynote Speaker 5: Cyber Security Threat Landscape in the Context of Industry 4.0
abstract
Industry 4.0 is revolutionizing the ways in which industries function. Big data, industrial control systems, supervisory control, and data acquisition systems, smart machines, robotics, internet of things (IoT) etc., all fall under the umbrella of Industry 4.0. With the fourth industrial revolution comes new operational risks for smart manufacturers, connected devices, and digital supply networks. With increasing digital transformation and interconnected nature of industry 4.0, cyberattacks can have significantly greater effects than ever before while the manufacturers may not be prepared for the potential risks. Without the strong cybersecurity practices in place, industries can be subject to industrial property theft, production sabotage, industrial espionage etc. To address the cyber risks adequately in the era of industry 4.0, it is crucial to make the cyber security strategies secure and resilient and integrate them fully in the organizational strategies from the beginning. This talk will discuss different types of attacks smart industries can be targeted for. The talk will also recommend some techniques and cyber security practices that the manufacturing industries must adopt to protect themselves against such attacks.
Haider Abbas
SIN1
2022 A framework to predict early news popularity using deep temporal propagation patterns
Ramsha Saeed, Haider Abbas, Sara Asif, Saddaf Rubab, Malik Muhammad Zaki Murtaza Khan, Naima Iltaf, Shynar Mussiraliyeva
Expert Syst. Appl.2
2022 CACS: A Context-Aware and Anonymous Communication Framework for an Enterprise Network Using SDN
abstract
The emergence of software-defined networking (SDN) has revolutionized the management of an enterprise network. The SDN-based design provides flexibility in network management, which spans over multiple applications, e.g., routing, switching, forwarding, and controlling. It reduces the reliance on vendor-specific devices and middlebox solutions, such as firewalls, intrusion detection systems (IDSs), intrusion prevention systems (IPSs), etc. Furthermore, due to the integration of different technologies, privacy is one of the core issues faced by the enterprise. Host anonymity is one of the techniques to safeguard against privacy attacks; however, the existing anonymization solutions provide better anonymity, but at the cost of higher latency and are most suited for Internet traffic. To tackle this issue in an enterprise network, we propose an SDN-based communication framework using enterprise integration patterns (EIPs) that offers anonymous communication in an enterprise environment. Host anonymity is achieved by replacing the real IP address with the spoofed IP address during the transmission of data packets inside the network. Unlike the traditional networks, SDN can modify the header fields of packets as they traverse in the network from the source to the destination. In addition to the host anonymity, this framework also provides context-aware communication by leveraging the SDN global visibility characteristic, where application services are discoverable on the network without disclosing the addresses of the application servers. Moreover, context-aware services enable network traffic to be routed based on the application-layer services rather than the network-layer information. In the end, evaluation of the proposed framework is carried out with respect to the performance of anonymous communication, computational complexity, and security of the complete proposed framework. In addition, we also highlighted that the proposed framework is more suitable for heterogeneous network environments such as Internet of Things-based solutions.
Bilal Rauf, Haider Abbas, Ahmad Muqeem Sheri, Mian Muhammad Waseem Iqbal, Yawar Abbas Bangash, Mahmoud Daneshmand, M. Faisal Amjad
IEEE Internet Things J.2
2022 A deep learning assisted personalized deception system for countering web application attacks
Waleed Bin Shahid, Baber Aslam, Haider Abbas, Hammad Afzal, Saad Bin Khalid
J. Inf. Secur. Appl.3
2022 An enhanced deep learning based framework for web attacks detection, mitigation and attacker profiling
Waleed Bin Shahid, Baber Aslam, Haider Abbas, Saad Bin Khalid, Hammad Afzal
J. Netw. Comput. Appl.3
2022 Forensic analysis of image deletion applications
Maheen Fatima, Haider Abbas, Mian Muhammad Waseem Iqbal, Narmeen Shafqat
Multim. Tools Appl.2
2022 ENCVIDC: an innovative approach for encoded video content classification
Faiqa Amjad, Fawad Khan, Shahzaib Tahir, Tahreem Yaqoob, Haider Abbas
Neural Comput. Appl.5
2022 Enriching Conventional Ensemble Learner with Deep Contextual Semantics to Detect Fake News in Urdu
abstract
Increased connectivity has contributed greatly in facilitating rapid access to information and reliable communication. However, the uncontrolled information dissemination has also resulted in the spread of fake news. Fake news might be spread by a group of people or organizations to serve ulterior motives such as political or financial gains or to damage a country’s public image. Given the importance of timely detection of fake news, the research area has intrigued researchers from all over the world. Most of the work for detecting fake news focuses on the English language. However, automated detection of fake news is important irrespective of the language used for spreading false information. Recognizing the importance of boosting research on fake news detection for low resource languages, this work proposes a novel semantically enriched technique to effectively detect fake news in Urdu—a low resource language. A model based on deep contextual semantics learned from the convolutional neural network is proposed. The features learned from the convolutional neural network are combined with other n-gram-based features and are fed to a conventional majority voting ensemble classifier fitted with three base learners: Adaptive Boosting, Gradient Boosting, and Multi-Layer Perceptron. Experiments are performed with different models, and results show that enriching the traditional ensemble learner with deep contextual semantics along with other standard features shows the best results and outperforms the state-of-the-art Urdu fake news detection model.
Ramsha Saeed, Hammad Afzal, Haider Abbas, Maheen Fatima
ACM Trans. Asian Low Resour. Lang. Inf. Process.3
2021 Is Blockchain Overrated?
abstract
Blockchain technology, after the advent of Bitcoin in 2009, gradually attained significant attention in academia and industry. Its influence grew further from cryptocurrencies and the financial sector in a couple of years. Soon many new use cases of blockchain in various areas such as supply chain management, healthcare, voting, intellectual property right management, food safety, real estate, internet of things etc. were proposed in liter-ature. Enthralled by the hype, many enterprises chose to pursue blockchain-based initiatives for their business processes. However after a period of over-excitement, now blockchain is viewed with concern because a large number of the earlier blockchain-based projects, especially those not related to finance, have not been productive. Foregoing in view, this article presents a concise review of blockchain technology, highlights its prospective impact within realistic boundaries and proposes a model to assess its feasibility to use cases before implementation, in order to embrace it prudently.
Asif Raza Kazmi, Mehreen Afzal, Haider Abbas, Shahzaib Tahir, Abdul Rauf 0002
EUC3
2021 A Framework to Optimize Deep Learning based Web Attack Detection Using Attacker Categorization
abstract
The outstanding usage of web applications across the globe has enabled people to access desired information online with a few clicks. This has also enabled skilled attackers to compromise the availability, integrity and confidentiality of the data and information available on these websites. This paper proposes a framework for detecting and obstructing a large number of web attacks and scanning probes based on features of an HTTP (Hyper Text Transfer Protocol) request packet and also caters for POST HTTP data. We first trained four traditional machine learning models i.e. Decision Tree, Support Vector Machine (SVM), Naive Bayesian and Linear Regression by using a well-known publicly available dataset. It was found out that Decision Tree outperforms the rest in terms of performance and accuracy. Finally, a Convolutional Neural Network (CNN) based deep learning approach was implemented and tested on a well-known publicly available dataset. It results in optimal performance and an accuracy of 99.94%. The deep learning approach was enhanced by the introduction of a User Categorization Feature which uses cookies to categorise malicious attackers.
Waleed Bin Shahid, Haider Abbas, Baber Aslam, Hammad Afzal, Saad Bin Khalid
EUC2
2021 A Systematic Evaluation of Android Anti-Malware Tools for Detection of Contemporary Malware
abstract
Android has become ubiquitous by taking more than 86 % of the market share. This rapid expansion has brought a slew of new threats, including privacy breaches, data thefts, and cyberespionage. As today's malware are highly sophisticated and capable to evade even state-of-the-art malware detection tools using obfuscation and repacking techniques. However, existing surveys possess challenges for researchers as they classify tools based on analysis methodology such as static and dynamic analysis. They do not cover accuracy rate, false-positive rate, effectiveness, performance evaluation, and additional features such as secure backup and spam blocking. Therefore, to check the strength of existing anti-malware tools, we present an in-depth study of Android anti-malware tools built over the last decade. This research classifies anti-malware tools, according to their analysis methodology along with their protection capabilities, performance, accuracy rate, usability, and ability to classify malware families. Based on our thorough studies, shortcomings are discussed and research gaps have been identified.
Muhammad Zia, M. Faisal Amjad, Haider Abbas, Anique Azhar, Ahsan Yasin, Hasan Iesar
EUC3
2021 A Malware Evasion Technique for Auditing Android Anti-Malware Solutions
abstract
In the past few years, Android security is enhanced \nand state-of-the-art anti-malware tools have been introduced \nto counter Android malware. These tools use both static and \ndynamic analysis techniques to detect malicious applications. \nDespite these, the attack surface against Android phones has \nrisen exponentially and malware detection tools are failed to \ncounter sophisticated threats. Therefore, it is a need to audit \nand evaluate Anti Malware Solutions (AMTs). In our research, \nwe have analyzed various Android malware evasion techniques, \nalong with their pros and cons. Moreover, we conducted a detailed \ncomparison of existing anti-malware tools and measured their \nefficacy against the discussed evasion techniques. Finally, a more \nsophisticated anti-malware evasion technique is proposed that \nuses exhaustive obfuscation and remote code execution to audit \nstatic and dynamic detection capabilities of AMTs. The proposed \ntechnique is practically validated and results prove that it evades \nall known anti-malware solutions. This technique can be utilized \nby anti-malware solution providers for making their products \nmore resilient and powerful.
Samrah Mirza, Haider Abbas, Waleed Bin Shahid, Narmeen Shafqat, Maria Grazia Fugini, Muhammad Zia
WETICE2
2021 AdS: An adaptive spectrum sensing technique for survivability under jamming attack in Cognitive Radio Networks
M. Faisal Amjad, Hammad Afzal, Haider Abbas, Abdul B. Subhani
Comput. Commun.3
2021 Applications of artificial intelligence in COVID-19 pandemic: A comprehensive review
Muhammad Taqi Mehran, Zeeshan Ul Haq, Salman Raza Naqvi, Mehreen Ihsan, Haider Abbas
Expert Syst. Appl.7
2021 Textual analysis of traitor-based dataset through semi supervised machine learning
Faisal Janjua, Asif Masood, Haider Abbas, Imran Rashid, Malik Muhammad Zaki Murtaza Khan
Future Gener. Comput. Syst.3
2021 Cryptographic Framework for Role Control Remedy: A Secure Role Engineering mechanism for Single Authority Organizations
Aqsa Rashid, Asif Masood, Haider Abbas
Future Gener. Comput. Syst.3
2021 Robust, Secure, and Adaptive Trust-Oriented Service Selection in IoT-Based Smart Buildings
abstract
Internet of Things (IoT) has become an integral part of a smart community that connects computing devices, smart objects, and mechanical and digital machines, having unique identifiers, to communicate with each, without human intervention. This smart connectivity within a building assists the users in real time to provide an enormous range of connected applications and facilitate the optimized use of multiple resources. These smart building applications can make our lives more comfortable and provide a more sustainable, healthy, and safe workplace. A key challenge for IoT toward smart buildings is to ensure that the service has been taken from a trustworthy service provider. It requires a reliable, robust, and adaptive context-oriented trust mechanism that conforms to the specific requirements of the end users. To enhance the security of smart buildings in IoT, this research proposes an adaptive context-based trust evaluation system for smart building (CTES-SB) applications. The trust score for service is calculated based on the client's previous interaction and recommendation from context-similar clients. Using CTES-SB, the client selects the best service provider based on the previous and current trust scores for the next interaction. The model also helps to filter out malicious nodes through an indirect trust calculation process. This process dynamically assigns weights based on direct interactions and trustworthy recommendations for detecting and avoiding malicious interactions. We have demonstrated the effectiveness of CTES-SB by simulating multiple smart building scenarios under malicious attacks. The proposed architecture of CTES-SB has been experimentally evaluated to benchmark its performance for best service selection and resiliency against malicious nodes. The CTES-SB is proved to be efficient by having a comparison with the state-of-the-art algorithms. The comparison is in terms of filtering the malicious nodes from the network and the result shows that the trust converges quickly toward the ground-truth value.
Ayesha Altaf, Haider Abbas, Faiza Iqbal, Malik Muhammad Zaki Murtaza Khan, Mahmoud Daneshmand
IEEE Internet Things J.2
2021 ALAM: Anonymous Lightweight Authentication Mechanism for SDN-Enabled Smart Homes
abstract
The smart connected devices are the first choice of cybercriminals for spreading spy wares and different security attacks. The current security standards and protocols for Internet of Things (IoT) have failed in providing security to these devices. In addition, IoT market giants are producing nonsecure smart products in order to grab the open market. Furthermore, low resources of IoT devices, limits the traditional host-based protection solutions like anti-virus, IDS, IPS, etc. To overcome the resource constraintness and security barriers of smart devices, a network-level security architecture based on lightweight cryptographic parameters is required. Software-defined networking (SDN) is a new networking paradigm to overcome the control, management, and security issues in traditional networking. The SDN controller handles all the computation and complexities at the network level, rather than smart devices. In this research, we first present a new privacy-preserving security architecture for SDN-based smart homes. Subsequently, an anonymous lightweight authentication mechanism (ALAM) is designed based on the proposed security architecture core foundations. Furthermore, the security characteristics of the proposed protocol are formally analyzed using Burrows-Abadi-Needham (BAN) logic and ProVerif, followed by informal security analysis. Finally, performance evaluation and comparative analysis of the scheme is carried out.
Mian Muhammad Waseem Iqbal, Haider Abbas, Jiafu Wan, Bilal Rauf, Yawar Abbas Bangash, Imran Rashid
IEEE Internet Things J.2
2021 Enterprise Integration Patterns in SDN: A Reliable, Fault-Tolerant Communication Framework
abstract
In today's era, large data centers are drawn toward the two popular technologies, i.e., enterprise integration patterns (EIP) and software defined networking (SDN). The former is the combination of design patterns which integrates the new and existing business applications in an enterprise environment, whereas the latter is a rapidly evolving networking paradigm that has reshaped the large enterprise network management by introducing the programmable planes and centralized control. The promising features of EIP, i.e., asynchronous communication, reliability and that of SDN, namely, robustness, network programmability, agility, and global visibility can be merged in order to cope with growing network demands and security. In this article, we propose a communication framework that incorporates both EIP and SDN in an enterprise environment. The architecture of the propose communication framework consists of adaptive virtual local area network (VLAN) module to install and delete VLANs reactively using EIP. Furthermore, to enable communication between applications from different networks in an enterprise environment, this framework also contains a packet forwarding module where hosts IP addresses are concealed from each other. In the end, we demonstrate through simulations that how the proposed integrated design can be helpful in improving the security, efficiency, and reliability aspects of the enterprise network. As proof of concept, we also discuss the deployment of our proposed framework in IoT-based Smart Cities, which is the extension of EIP on a large scale.
Bilal Rauf, Haider Abbas, Ahmad Muqeem Sheri, Mian Muhammad Waseem Iqbal, Abdul Waheed Khan
IEEE Internet Things J.2
2021 Mitigating service-oriented attacks using context-based trust for smart cities in IoT networks
Ayesha Altaf, Haider Abbas, Faiza Iqbal, Malik Muhammad Zaki Murtaza Khan, Abdul Rauf 0002, Tehsin Kanwal
J. Syst. Archit.2
2021 User-Oriented Virtual Mobile Network Resource Management for Vehicle Communications
abstract
Currently, advanced communications and networks greatly enhance user experiences and have a major impact on all aspects of people's lifestyles in terms of work, society, and the economy. However improving competitiveness and sustainable vehicle network services, such as higher user experience, considerable resource utilization and effective personalized services, is a great challenge. Addressing these issues, this paper proposes a virtual network resource management based on user behavior to further optimize the existing vehicle communications. In particular, ensemble learning is implemented in the proposed scheme to predict the user's voice call duration and traffic usage for supporting user-centric mobile services optimization. Sufficient experiments show that the proposed scheme can significantly improve the quality of services and experiences and that it provides a novel idea for optimizing vehicle networks.
Huimin Lu 0001, Yin Zhang 0002, Yujie Li 0001, Haider Abbas
IEEE Trans. Intell. Transp. Syst.5
2020 Deceiving Eavesdroppers by Real Time Persistent Spoofing of Android Users' Location Coordinates for Privacy Enhancement
abstract
Location-based services have exponentially escalated in the past few decades. They appear to be very practical, however, the location of user is constantly being tracked, hoarded, and monitored by tech giants without user knowledge and consent. Google keeps an eye on every motion of its users, irrespective of their security settings. For this study, various Android smartphones were carried through different places for one week without the availability of internet and location services. Later, thorough network traffic analysis revealed that the archived data collected by Google apps and services, contained location data as well. This data is transferred to Google as soon as the internet connection becomes available. Moreover, a detailed performance analysis of existing fake GPS location applications was conducted that revealed a plethora of weaknesses in their performance and none of them aimed to secure users' real location coordinates. In this paper, we present an interesting solution to obfuscate Android users' real location coordinates, even in off-line mode, thereby, guaranteeing location privacy.
Anum Arshad, Haider Abbas, Waleed Bin Shahid, Anique Azhar
WETICE2
2020 DST-HRS: A topic driven hybrid recommender system based on deep semantics
Zafran Khan, Naima Iltaf, Hammad Afzal, Haider Abbas
Comput. Commun.4
2020 Multi-task reading for intelligent legal services
Yujie Li 0001, Jinyang Du, Haider Abbas, Yin Zhang 0002
Future Gener. Comput. Syst.4
2020 On the efficiency of software implementations of lightweight block ciphers from the perspective of programming languages
Abdur Rehman Raza, Khawir Mahmood, M. Faisal Amjad, Haider Abbas, Mehreen Afzal
Future Gener. Comput. Syst.4
2020 Special issue: Cognitive Internet of Things assisted by cloud computing and big data
Yin Zhang 0002, Haider Abbas
Future Gener. Comput. Syst.2
2020 Enriching Non-negative Matrix Factorization with Contextual Embeddings for Recommender Systems
Zafran Khan, Naima Iltaf, Hammad Afzal, Haider Abbas
Neurocomputing4
2020 An In-Depth Analysis of IoT Security Requirements, Challenges, and Their Countermeasures via Software-Defined Security
abstract
Internet of Things (IoT) is transforming everyone's life by providing features, such as controlling and monitoring of the connected smart objects. IoT applications range over a broad spectrum of services including smart cities, homes, cars, manufacturing, e-healthcare, smart control system, transportation, wearables, farming, and much more. The adoption of these devices is growing exponentially, that has resulted in generation of a substantial amount of data for processing and analyzing. Thus, besides bringing ease to the human lives, these devices are susceptible to different threats and security challenges, which do not only worry the users for adopting it in sensitive environments, such as e-health, smart home, etc., but also pose hazards for the advancement of IoT in coming days. This article thoroughly reviews the threats, security requirements, challenges, and the attack vectors pertinent to IoT networks. Based on the gap analysis, a novel paradigm that combines a network-based deployment of IoT architecture through software-defined networking (SDN) is proposed. This article presents an overview of the SDN along with a thorough discussion on SDN-based IoT deployment models, i.e., centralized and decentralized. We further elaborated SDN-based IoT security solutions to present a comprehensive overview of the software-defined security (SDSec) technology. Furthermore, based on the literature, core issues are highlighted that are the main hurdles in unifying all IoT stakeholders on one platform and few findings that emphases on a network-based security solution for IoT paradigm. Finally, some future research directions of SDN-based IoT security technologies are discussed.
Mian Muhammad Waseem Iqbal, Haider Abbas, Mahmoud Daneshmand, Bilal Rauf, Yawar Abbas Bangash
IEEE Internet Things J.2
2020 AdDroid: Rule-Based Machine Learning Framework for Android Malware Analysis
Anam Mehtab, Waleed Bin Shahid, Tahreem Yaqoob, M. Faisal Amjad, Haider Abbas, Hammad Afzal, Malik Najmus Saqib
Mob. Networks Appl.5
2020 Auto-MeDiSine: an auto-tunable medical decision support engine using an automated class outlier detection method and AutoMLP
Maham Jahangir, Hammad Afzal, Mehreen Ahmed, Khawar Khurshid, M. Faisal Amjad, Raheel Nawaz, Haider Abbas
Neural Comput. Appl.7
2020 Cognitive computing for intelligent application and service
Yin Zhang 0002, Haider Abbas, Yujie Li 0001
Neural Comput. Appl.2
2020 Integrated Security, Safety, and Privacy Risk Assessment Framework for Medical Devices
abstract
The substantial improvements and innovations in communication networks and bio-medical technologies have led to the adoption of networked medical devices due to which the attack surface has increased profoundly. Numerous devices in practice were designed and developed years ago without security measures. In such a scenario, the role of regulatory bodies has become evident. The Food and Drug Administration (FDA) validates and approves devices before commercialization. In contrast, the European Union (EU) follows a decentralized approach and Notified Bodies (NB) for assuring high standards, safety and quality of medical devices being marketed in Europe. Once the device has gone through stringent regulations including good manufacturing practices, Quality Management System (QMS), labeling, clinical tests, performance standards, adequate storage and packaging practices, a declaration of conformity will be granted, which is a legal binding document stating that the device is conformant with applicable European requirements and can be marketed in Europe. However, such regulations lack a systematic methodology to determine unified security, safety and privacy risk that eventually influence the health of patients. To cover these gaps, this research proposes Integrated Safety, Security, and Privacy (ISSP) Risk Assessment Framework to determine the risk level of the device and required security controls. It is, then applied to a case scenario of an infusion pump and further evaluated by comparing it with current standards and practices. The comparison shows that the framework provides a unified approach to consider different types of risks associated with devices.
Tahreem Yaqoob, Haider Abbas, Narmeen Shafqat
IEEE J. Biomed. Health Informatics2
2019 Context Based Trust Formation Using Direct User-Experience in the Internet of Things(IoT)
abstract
The Internet of Things (IoT) is converting the real world into cyber network. Security becomes a challenging task in IoT. For that reason, trust is used as an essential security measure in IoT devices. Trust Management System (TMS) is designed to mitigate the risks of uncertainty between the communicating parties. Direct interactions with servers based on the user experiences in various contexts can be considered as a solution for trust formation. The aim of this paper is to develop a context based trust management system that uses direct experiences of users while being connected with servers in various contexts. The technique is based on the Naïve Bayesian classification method. The context based direct user experiences are filtered, classified and then used as a trust formation procedure to formulate and update trust with the passage of time. The proposed protocol has been evaluated using web services datasets and results show that trust formation considering contextual information provides a promising solution.
Ayesha Altaf, Haider Abbas, Faiza Iqbal
CloudCom2
2019 Security Safety and Trust Management (SSTM' 19)
abstract
The following topics are dealt with: security of data; cloud computing; business data processing; Internet of Things; data analysis; groupware; information retrieval; Internet; natural language processing; data protection.
Haider Abbas, Farrukh Aslam Khan, Kashif Kifayat, Asif Masood, Imran Rashid, Fawad Khan
WETICE1
2019 A Deep Learning Framework to Predict Rating for Cold Start Item Using Item Metadata
abstract
Recommender systems improve browsing experience of users for large amount of items by assisting selection and classification of items utilizing item metadata. The performance of recommender system usually deteriorates when implicit data is used with limited user interaction history also regarded as cold start (CS) problem. This paper proposes a model to address cold start problem using content based technique where user or item metadata is used to break this ice barrier. The proposed method utilizes the feature extraction techniques (such as term frequencyInverse document frequency(TF-IDF)) and word embedding technique (Word2Vec). These content features are then used to predict the ratings for CS items by constructing user profiles using stacked auto-encoder. Experiments performed on largest real world dataset provided by Movielens 20M shows that proposed model outperforms the state-of-the-art approaches in CS item scenario.
Fahad Anwar, Naima Iltaf, Hammad Afzal, Haider Abbas
WETICE4
2019 iBike: Intelligent public bicycle services assisted by data analytics
Yin Zhang 0002, Haoyu Wen, Feier Qiu, Zie Wang, Haider Abbas
Future Gener. Comput. Syst.5
2019 A complex event processing framework for an adaptive language learning system
Yin Zhang 0002, Haider Abbas, Tiong-Thye Goh
Future Gener. Comput. Syst.4
2019 AndroKit: A toolkit for forensics analysis of web browsers on android platform
Muhammad Asim Rehmat, M. Faisal Amjad, Mian Muhammad Waseem Iqbal, Hammad Afzal, Haider Abbas, Yin Zhang 0002
Future Gener. Comput. Syst.5
2019 Framework for Calculating Return on Security Investment (ROSI) for Security-Oriented Organizations
Tahreem Yaqoob, Azka Arshad, Haider Abbas, M. Faisal Amjad, Narmeen Shafqat
Future Gener. Comput. Syst.3
2019 Trust models of internet of smart things: A survey, open issues, and future directions
Ayesha Altaf, Haider Abbas, Faiza Iqbal, Abdelouahid Derhab
J. Netw. Comput. Appl.2
2019 Blockchain's adoption in IoT: The challenges, and a way forward
Imran Makhdoom, Mehran Abolhasan, Haider Abbas, Wei Ni 0001
J. Netw. Comput. Appl.3
2019 A hybrid-adaptive neuro-fuzzy inference system for multi-objective regression test suites optimization
Zeeshan Anwar, Hammad Afzal, Nazia Bibi, Haider Abbas, Athar Mohsin, Omar Arif
Neural Comput. Appl.4
2019 Fog computing in internet of things: Practical applications and future directions
Rida Zojaj Naeem, Saman Bashir, M. Faisal Amjad, Haider Abbas, Hammad Afzal
Peer-to-Peer Netw. Appl.4
2018 Enhancing E-Healthcare Privacy Preservation Framework through L-Diversity
abstract
Healthcare industry is continuously evolving as new technologies are being integrated in the existing healthcare infrastructure. Privacy preservation provides one of the key role from security perspective in an electronic healthcare data security. Due to continuously emerging threats, a comprehensive security framework that should provide strong patient anonymity level (considering both patient's identity and patient's data), anonymized data searching and successful correlation of PHR for medical research is difficult to formulize. In this paper, some previous security frameworks were analyzed and their flaws were identified. Also it proposed an enhancement to the existing solutions based on a careful analysis of their shortcomings.
Adeel Shah, Haider Abbas, Mian Muhammad Waseem Iqbal, Rabia Latif
IWCMC2
2018 Ease or Privacy? A Comprehensive Analysis of Android Embedded Adware
abstract
With hundreds of millions of Android phone users in around 190 countries, the global smartphone market has witnessed extraordinary and explosive growth, which is escorted with the vast number of its applications. It has an open source code platform that encourages app developers to develop Android applications and introduce them free-of-cost in the market. Applications are considered as the heart of Android phone that drive innovation, leisure, ease of availability and compatibility with the mobile devices. Embedded adware or mobile advertising is rapidly finding its ways into android applications in the form of banner ads, rich media or interstitial ads.. This paper aims to highlight risk of privacy leakage of end users by introducing an attack model and exploring attacks caused by in-application advertisements. It also presents theoretical framework by quantitative analytic approach to figure out the impact of embedded adware on Android user's privacy.
Anum Javaid, Imran Rashid, Haider Abbas, Maria Grazia Fugini
WETICE3
2018 Correlation power analysis of modes of encryption in AES and its countermeasures
Shah Fahd, Mehreen Afzal, Haider Abbas, Mian Muhammad Waseem Iqbal, Salman Waheed
Future Gener. Comput. Syst.3
2018 A unified framework for automated inspection of handheld safety critical devices in production assemblies
Muhammad Asim Rehmat, Muhammad Shahbaz 0002, Asad Raza, Haider Abbas
Future Gener. Comput. Syst.4
2018 Countering cyber threats for industrial applications: An automated approach for malware evasion detection and analysis
Muzzamil Noor, Haider Abbas, Waleed Bin Shahid
J. Netw. Comput. Appl.2
2018 Information Diffusion Model Based on Social Big Data
Xiao Ma 0002, Yin Zhang 0002, Haider Abbas, Han Yu 0004
Mob. Networks Appl.4
2018 CrossRec: Cross-Domain Recommendations Based on Social Big Data and Cognitive Computing
Yin Zhang 0002, Xiao Ma 0002, Shaohua Wan 0001, Haider Abbas, Mohsen Guizani
Mob. Networks Appl.4
2018 Malicious insiders attack in IoT based Multi-Cloud e-Healthcare environment: A Systematic Literature Review
Afsheen Ahmed, Rabia Latif, Seemab Latif, Haider Abbas, Farrukh Aslam Khan
Multim. Tools Appl.4
2018 Forensic investigation to detect forgeries in ASF files of contemporary IP cameras
Rashid Masood Khan, Mian Muhammad Waseem Iqbal, M. Faisal Amjad, Haider Abbas, Hammad Afzal, Abdul Rauf 0002, Maruf Pasha
J. Supercomput.4
2018 Mobile Intelligence Assisted by Data Analytics and Cognitive Computing
Yin Zhang 0002, Huimin Lu 0001, Haider Abbas
Wirel. Commun. Mob. Comput.3
2017 Feasibility analysis for deploying national healthcare information system (NHIS) for Pakistan
abstract
Lack of healthcare infrastructure has caused millions of deaths in developing countries. People in such countries generally suffer from infectious diseases and are denied treatment at appropriate time or not warned about emerging epidemics. This mainly happens because of poor establishment of public health services, lack of access to health statistics and nonexistence of precise medical data. The deployment of e-health and specifically Electronic Health Record (EHR) system may help in upgrading and boosting healthcare in developing countries like Pakistan. This paper studies and compares different approaches taken by a group of countries from North America, Europe, Western Asia and Africa for developing and implementing a national EHR in the public health system. The foremost challenges highlighted in this paper are of integration, interoperability, trainings, awareness, standardization, funds, and legal framework, which would help in developing a National EHR system in Pakistan. A National Healthcare Information System (NHIS) is proposed for health sector of Pakistan. The proposed system will be capable of efficient storage, management and sharing of electronic health information of patients in Pakistan. NHIS will also help in conducting surveys and analysis of health statistics for future health planning.
Tahreem Yaqoob, Faiza Mir, Haider Abbas, Waleed Bin Shahid, Narmeen Shafqat, M. Faisal Amjad
Healthcom3
2017 Security, Safety and Trust Management (SSTM '17)
abstract
The goal of SSTM'17 was to attract young researchers, Ph.D. students, practitioners, and industry experts to bring contributions in the area of Security, Safety and Trust Management, especially in the developments of computing, management and programming models, technologies, framework and middleware.
Haider Abbas, Eugenio Orlandi, Farrukh Aslam Khan, Oliver Popov, Asif Masood
WETICE1
2017 A detection and prevention system against collaborative attacks in Mobile Ad hoc Networks
Farrukh Aslam Khan, Muhammad Imran 0005, Haider Abbas, Muhammad Hanif Durad
Future Gener. Comput. Syst.3
2017 Arrhythmia classification using Mahalanobis distance based improved Fuzzy C-Means clustering for mobile health monitoring systems
Nur Al Hasan Haldar, Farrukh Aslam Khan, Aftab Ali, Haider Abbas
Neurocomputing4
2017 Fuzziness based semi-supervised learning approach for intrusion detection system
Rana Aamir Raza, Xizhao Wang, Joshua Zhexue Huang, Haider Abbas, Yu-Lin He
Inf. Sci.4
2017 A Manufacturing Big Data Solution for Active Preventive Maintenance
abstract
Industry 4.0 has become more popular due to recent developments in cyber-physical systems, big data, cloud computing, and industrial wireless networks. Intelligent manufacturing has produced a revolutionary change, and evolving applications, such as product lifecycle management, are becoming a reality. In this paper, we propose and implement a manufacturing big data solution for active preventive maintenance in manufacturing environments. First, we provide the system architecture that is used for active preventive maintenance. Then, we analyze the method used for collection of manufacturing big data according to the data characteristics. Subsequently, we perform data processing in the cloud, including the cloud layer architecture, the real-time active maintenance mechanism, and the offline prediction and analysis method. Finally, we analyze a prototype platform and implement experiments to compare the traditionally used method with the proposed active preventive maintenance method. The manufacturing big data method used for active preventive maintenance has the potential to accelerate implementation of Industry 4.0.
Jiafu Wan, Shenglong Tang, Di Li 0001, Shiyong Wang, Chengliang Liu 0001, Haider Abbas, Athanasios V. Vasilakos
IEEE Trans. Ind. Informatics6
2016 Survey on cybersecurity issues in wireless mesh networks based eHealthcare
abstract
Information and Communication Technologies (ICT) based applications for Ambient Assisted Living (AAL) help elderly or individual people living home alone. AAL system reliability is mostly based on the recent emerging class of network that is known as wireless mesh network (WiMesh). In WiMesh the information security is the most difficult problem to tackle because the medium is open to cyber-attacks. Moreover, when we talk about AAL where the complete personal information is digitized and stored, the need for implementation and maintenance of strict security measures is essential. In this article, we present a critical literature survey on communication security issues in e-health care environments. We highlight and explore the representative state of the art security prototypes for eHealthcare environments and also provide the details of their security characteristics. In addition, we discuss in detail the challenges and opportunities of these systems.
Kashif Saleem, Khan Zeb, Abdelouahid Derhab, Haider Abbas, Jalal Al-Muhtadi, Mehmet A. Orgun, Amjad Gawanmeh
HealthCom4
2016 Guest editorial: Secure cloud computing for mobile health services
Haider Abbas, Sudip Misra, Yuh-Shyan Chen
Peer-to-Peer Netw. Appl.1
2016 Identifying an OpenID anti-phishing scheme for cyberspace
abstract
Abstract OpenID is widely being used for user centric identity management in many Web applications. OpenID provides Web users with the ability to manage their identities through third party identity providers while remaining independent of the subject that actually uses the identities to authenticate individuals. Starting from the early stages of its inception, OpenID has received a large amount of acceptance and use in the current Web community because of its flexibility and ease of use. However, in addition to its benefits and flexibilities, OpenID faces its own share of vulnerabilities and threats, which have made its future and large‐scale use in cyberspace questionable. OpenID Phishing is one such attack that has received much attention and that requires a comprehensive solution. This paper aims at identifying and discussing a solution to OpenID Phishing by proposing a user authentication scheme that allows OpenID providers to identify a user using publicly known entities. The research will help in next‐generation cyber security innovations by reducing the authentication dependency on user credentials, that is, login name/password. The authentication scheme is also validated through detailed descriptions of use cases and prototype implementation. Copyright © 2014 John Wiley & Sons, Ltd.
Haider Abbas, Moeen Qaemi Mahmoodzadeh, Farrukh Aslam Khan, Maruf Pasha
Secur. Commun. Networks1
2016 A framework for cloud forensics evidence collection and analysis using security information and event management
abstract
A primary feature of cloud computing is the provision of a variety of transparent services with efficient resource utilization. However, there are concerns with cloud computing in terms of the user's data privacy and security, especially in evidence collection for forensics analysis, because the tangible resources and hardware are out of reach for users who own the data. This paper presents a framework using security information and event management SIEM, to address the issue of efficient evidence collection for crime investigation, such as that for cloud forensics, with respect to the cloud service provider. Indeed, evidence could be shared with cloud users when required. SIEM can be considered as a major player in terms of evidence collection in a virtualized environment. The proposed mechanism using SIEM focuses on passive attacks and provides a solution from the cloud administrator or service provider's point of view. The proposed framework can help in performing detailed cloud forensics in terms of efficient evidence building for crime investigations. Copyright © 2016 John Wiley & Sons, Ltd.
Haider Abbas, Yunchuan Sun, Anam Sajid, Maruf Pasha
Secur. Commun. Networks2
2015 Feasibility analysis for incorporating/deploying SIEM for forensics evidence collection in cloud environment
abstract
Cloud computing is the emerging field nowadays and it has truly revolutionized the domain of Information Technology. This domain is very large and not easy to handle especially when it comes to the forensic in a cloud environment that is considered a very cumbersome process. This paper presents a feasibility analysis of performing digital forensics via SIEM (Security Information and Event Management) system in cloud environment. The research work mainly focuses on passive attacks while some active attacks are also covered and the forensics analysis is done while considering the service provider end. The preliminary analysis presented in this paper will provide a comprehensive overview of the various artifacts that may be considered for performing an in-depth forensic analysis in cloud environment using Security Information and Event Management System.
Haider Abbas, Mian Muhammad Waseem Iqbal
ICIS2
2015 Security concerns of cloud-based healthcare systems: A perspective of moving from single-cloud to a multi-cloud infrastructure
abstract
Cloud computing has appeared to be state of the art in the world of Information Technology especially in healthcare systems due to its innovative computing deployment model as a source of utility for users. However, many healthcare organizations are disinclined to adapt cloud computing due to security shortcoming associated with its infrastructure and many of them are still unaddressed. To provide a promising security to cloud computing infrastructure is a key issue, as users have a tendency to store their sensitive and classified medical data with cloud service providers which include the both trusted and un-trusted parties of cloud service providers. This paper addresses the distinguishing features of cloud such as, rapid elasticity, pooling of resources, on-demand services to users, multi-tenancy, third-party rule and its security requirements. Then, it presents the analysis of security concerns of cloud computing for healthcare systems in terms of availability, trust, confidentiality, compliance, integrity and audit. Furthermore, single-cloud is far more vulnerable to failure of service unavailability and malicious insiders and due to this reason it is less popular in healthcare, as medical healthcare systems are concerned about its security. From this notion of security concern an advanced model has emerged; “multi-cloud” also known to be “cloud-of-clouds”. This paper also provides an insight of security in single-cloud and multi-cloud and possible security recommendations for healthcare systems, as it has been observed that single-cloud has received more focus from researchers in terms of security vulnerabilities than a multi-cloud environment.
Haider Ali Khan Khattak, Haider Abbas, Ayesha Naeem, Kashif Saleem, Mian Muhammad Waseem Iqbal
HealthCom2
2014 Dynamically Changing Service Level Agreements (SLAs) Management in Cloud Computing
Waleed Halboob, Haider Abbas, Kamel Haouam, Asif Yaseen
ICIC (2)2
2014 Analyzing Feasibility for Deploying Very Fast Decision Tree for DDoS Attack Detection in Cloud-Assisted WBAN
Rabia Latif, Haider Abbas, Saïd Assar, Seemab Latif
ICIC (1)2
2013 Secure SMS Based Automatic Device Pairing Approach for Mobile Phones
Shoohira Aftab, Amna Khalid, Asad Raza, Haider Abbas
ICIC (2)4
2013 A framework for preservation of cloud users' data privacy using dynamic reconstruction of metadata
Adeela Waqar, Asad Raza, Haider Abbas, Muhammad Khurram Khan
J. Netw. Comput. Appl.3
2011 User Privacy Issues in Eucalyptus: A Private Cloud Computing Environment
abstract
The highly scalable nature of Cloud Computing enables its users to utilize distributed computational resources and access large amounts of data using different interfaces. Cloud entities including cloud users, service providers and business partners share the available resources at different levels of technological operations. However, the Cloud Computing framework is inherently susceptible to a great number of security threats due to the amalgamation of different computing technologies that make it a complex architecture. Among all the potential threats, those targeting the users' data are significantly important and must be thwarted in precedence to facilitate effective cloud functionality. This paper focuses on the potential threats to users' cloud resident data and metadata and suggests possible solutions to prevent these threats. We have used UEC (Ubuntu Enterprise Cloud) Eucalyptus, which is a popular open source cloud computing software, widely used by the research community. In this work, we have simulated some of the potential attacks to users' data and metadata stored in Eucalyptus database files in order to provide the intended reader with the requisite information to be able to anticipate the grave consequences of violation of cloud users' data privacy.
Adeela Waqar, Asad Raza, Haider Abbas
TrustCom3
2011 Addressing Dynamic Issues in Information Security Management
abstract
Purpose The purpose of this paper is to address three main problems resulting from uncertainty in information security management: dynamically changing security requirements of an organization; externalities caused by a security system; and obsolete evaluation of security concerns. Design/methodology/approach In order to address these critical concerns, a framework based on options reasoning borrowed from corporate finance is proposed and adapted to evaluation of security architecture and decision making for handling these issues at organizational level. The adaptation as a methodology is demonstrated by a large case study validating its efficacy. Findings The paper shows through three examples that it is possible to have a coherent methodology, building on options theory to deal with uncertainty issues in information security at an organizational level. Practical implications To validate the efficacy of the methodology proposed in this paper, it was applied to the Spridnings‐och Hämtningssystem (SHS: dissemination and retrieval system) system. The paper introduces the methodology, presents its application to the SHS system in detail and compares it to the current practice. Originality/value This research is relevant to information security management in organizations, particularly issues on changing requirements and evaluation in uncertain circumstances created by progress in technology.
Haider Abbas, Christer Magnusson, Louise Yngström, Ahmed Hemani
Inf. Manag. Comput. Secur.1
2009 Adaptability infrastructure for bridging IT security evaluation and options theory
abstract
The constantly rising threats in IT infrastructure raise many concerns for an organization, altering security requirements according to dynamically changing environment, need of midcourse decision management and deliberate evaluation of security measures are most striking. Common Criteria for IT security evaluation has long been considered to be victimized by uncertain IT infrastructure and considered resource hungry, complex and time consuming process. Considering this aspect we have continued our research quest for analyzing the opportunities to empower IT security evaluation process using Real Options thinking. The focus of our research is not only the applicability of real options analysis in IT security evaluation but also observing its implications in various domains including IT security investments and risk management. We find it motivating and worth doing to use an established method from corporate finance i.e. real options and utilize its rule of thumb technique as a road map to counter uncertainty issues for evaluation of IT products. We believe employing options theory in security evaluation will provide the intended benefits. i.e. i) manage dynamically changing security requirements ii) accelerating evaluation process iii) midcourse decision management. Having all the capabilities of effective uncertainty management, options theory follows work procedures based on mathematical calculations quite different from information security work processes. In this paper, we will address the diversities between the work processes of security evaluation and real options analysis. We present an adaptability infrastructure to bridge the gap and make them coherent with each other. This liaison will transform real options concepts into a compatible mode that provides grounds to target IT security evaluation and common criteria issues. We will address ESAM system as an example for illustrations and applicability of the concepts.
Haider Abbas, Louise Yngström, Ahmed Hemani
SIN1
2002 Fabric fault classification using neural trees
abstract
In this paper, the problem of textile quality control is addressed. The basic objective is to classify the most important defects in woven fabrics. The algorithm adopted here is composed of three stages. The first stage is a preprocessing phase where defects are detected and localized. Since every detected defect has its different shape and size, all defects are normalized to a predetermined size. In the second stage, a set of features are calculated for each defect using the Haralick et al (1973) spatial features. During the third and last stage, those features are then used to train a competitive neural tree (CNeT) (Behnke and Karayiannis, 1998) designed to learn in a supervised manner the class associated with each set of features. The network can be then used to test and classify new defects. The approach is experimented with a set of images of fault free and defected textiles and output results are analyzed.
Mohamed Abdulhady, Haider Abbas, Salwa M. Nassar
SMC2