Behrouz Tork Ladani

dblp:05/3890 · DBLP profile ↗
← Back
23ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0003-2280-8839ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 6 · 2 since 2021Security and privacy · 4 · 3 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Systems, architecture and hardware · 3Computer networks · 2Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Unmasking Influence: The Power of Artificial Entities in Shaping Public Opinion on Social Networks
abstract
With the rise of social networks, powerful actors have increasingly attempted to manipulate public opinion in their favor using various methods, including the deployment of artificial accounts such as bots and trolls. The influence of these artificial entities poses substantial risks to fundamental freedoms, including thought, expression, and decision-making, while also creating significant social, political, cultural, and economic challenges for society. To mitigate this influence, it is essential to identify and analyze the factors that contribute to the effectiveness of artificial entities. Despite significant advancements in recent years in the detection, modeling, and analyzing of the effects of artificial entities, less attention has been paid to the accurate identification of the factors influencing their role in the formation of public opinion. This gap persists, particularly in the context of simultaneously considering both consensus-building and polarization-inducing stimuli. In this study, we try modeling artificial entities in social networks and conduct a series of experiments under various conditions to examine the factors that influence their success. To this end, we also introduce new criteria for assessing the formation of public opinion and the effectiveness of artificial entities, addressing the current lack of suitable metrics in this domain. The study demonstrates that attachment strategy, intelligence level, and lifespan of artificial entities play critical roles in shaping public opinions. We show that even a small presence of artificial entities can lead to consensus, underscoring the importance of their characteristics in shaping public discourse. By understanding the factors that influence the success of artificial entities in manipulating public opinion, policymakers, social network platforms, governing organizations, and individuals can effectively counteract their influences.
Hani Rabiee, Behrouz Tork Ladani, Ebrahim Sahafizadeh
IEEE Trans. Comput. Soc. Syst.2
2026 A Formal Lens on Android Permissions System: Modeling, Verification, and Exploitation Using LLMs and Model Checking
abstract
The Android Permissions System (APS) is a permission-based access control mechanism that controls the applications’ access to protected resources such as user contacts and GPS locations. The evolution of APS—as a critical component of Android—has made the user experience more convenient. However, the vulnerabilities and attacks targeting the APS indicate that its thorough security analysis is essential to ensure system security and to protect user information. Although previous works applied formal methods to verify the security of APS, its new capabilities, such as One-Time Permissions (OTPs), have not yet been studied. In this article, we present a model checking approach for security verification of APS that supports OTPs. We use Large Language Models in a Chain-of-Thought process to assist in extracting the behavior of APS from its documentation and source code to design a formal model and a set of security properties. Then we use the TLC model checker to verify the security properties against the model. We analyze the APS in both Android 6 and Android 11 and we succeed in discovering a previously known vulnerability in Android 6 as well as a new vulnerability in OTPs in Android 11 named Permanent Permission Access (PPA). We also implement an exploit code to show that PPA leads to permanent illegal access to sensitive resources. Our experiments show that the developed exploit app works on the latest versions of Android too (including Android 15). Besides, we propose the required fix to mitigate the vulnerability.
Amirhosein Sayyadabdi, Behrouz Tork Ladani, Bahman Zamani
ACM Trans. Priv. Secur.2
2024 A comprehensive framework for inter-app ICC security analysis of Android apps
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani
Autom. Softw. Eng.3
2024 A Social Network Model for Analysis of Public Opinion Formation Process
abstract
The growing popularity of social networks has amplified their capacity to form public opinions. The opinion formation process is affected by social factors and social phenomena such as spiral of silence and echo chambers. In this article, we present a directed homophilic preferential attachment (DHPA) model to capture the dynamics of social network generation and rewiring (network dynamics) and to take the variation of attitudes and characteristics of users when expressing their opinions and their desire to establish relationships with others into account (opinion dynamics). The proposed model not only integrates network dynamics and opinion dynamics but also accounts for homophily and the formation of social phenomena that create consensus or polarity. This results in more realistic outcomes compared to similar models. In addition, the model can contrast factors that drive consensus with those that drive polarization. DHPA provides necessary facilities for examining the impact of different factors on the opinion formation process. It enables us to analyze the circumstances to reach consensus and polarity. It is shown that the network generated by the proposed DHPA model appropriately conforms to real social networks. We have examined the impact of some important social factors by conducting a number of sensitivity analysis scenarios on the model, which led to interesting results.
Hani Rabiee, Behrouz Tork Ladani, Ebrahim Sahafizadeh
IEEE Trans. Comput. Soc. Syst.2
2023 Maaker: A framework for detecting and defeating evasion techniques in Android malware
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani
J. Inf. Secur. Appl.2
2023 A model-based framework for inter-app Vulnerability analysis of Android applications
abstract
Abstract Android users install various apps, such as banking apps, on their smart devices dealing with user‐sensitive information. The Android framework, via Inter‐Component Communication (ICC) mechanism, ensures that app components (inside the same app or on different apps) can communicate. The literature works have shown that this mechanism can cause security issues, such as app security policy violations, especially in the case of Inter‐App Communication (IAC). Despite the plethora of research on detecting security issues in IAC, detection techniques face fundamental ICC challenges for improving the precision of static analysis. Challenges include providing comprehensive and scalable modeling of app specification, capturing all potential ICC paths, and enabling more effective IAC analysis. To overcome such challenges, in this paper, we propose a framework called VAnDroid2, as an extension of our previous work, to address the security issues in multiple components at both intra‐ and inter‐app analysis levels. VAnDroid2, based on Model‐Driven Reverse Engineering, has extended our previous work as per following: (1) providing a comprehensive Intermediate Representation (IR) of the app which supports extracting all the ICC information from the app, (2) extracting high‐level representations of the apps and their interactions by omitting the details that are not relevant to inter‐app security analysis, and (3) enabling more effective IAC security analysis. This framework is implemented as an Eclipse‐based tool. The results of evaluating VAnDroid2 w.r.t. correctness, scalability, and run‐time performance, and comparing with state‐of‐the‐art analysis tools well indicate that VAnDroid2 is a promising framework in the field of Android inter‐app security analysis.
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani, Jacques Klein, Tegawendé F. Bissyandé
Softw. Pract. Exp.3
2022 Efficient Secure Pattern Matching With Malicious Adversaries
abstract
In a secure pattern matching scheme, a client learns only the locations where his private pattern matches a server’s private text, while server learns nothing. In this article, we propose a secure pattern matching protocol for the semi-honest setting which is then enhanced to guarantee full simulation-based security in the presence of malicious parties. The proposed protocol supports exact pattern matching, approximate pattern matching and pattern matching with wildcards. It is analytically shown that the proposed protocol is considerably more efficient in the approximate matching with at most$k$permitted mismatches while it has the same speed in the exact matching case comparing with the recent work in the literature. The achievements are also experimentally evaluated on a case of secure Desoxyribo-Nucleic Acid (DNA) search over the NCBI dataset of the United States national library of medicine. The results show efficiency of the proposed protocol and particularly confirm low computation overhead for the client.
Maryam Zarezadeh, Hamid Mala, Behrouz Tork Ladani
IEEE Trans. Dependable Secur. Comput.3
2021 Soft rumor control in social networks: Modeling and analysis
Mojgan Askarizadeh, Behrouz Tork Ladani
Eng. Appl. Artif. Intell.2
2021 MEGDroid: A model-driven event generation framework for dynamic android malware analysis
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani
Inf. Softw. Technol.2
2020 Model checking of robustness properties in trust and reputation systems
Seyed Asgary Ghasempouri, Behrouz Tork Ladani
Future Gener. Comput. Syst.2
2020 Secure parameterized pattern matching
Maryam Zarezadeh, Hamid Mala, Behrouz Tork Ladani
Inf. Sci.3
2020 A Model for Social Communication Network in Mobile Instant Messaging Systems
abstract
Mobile instant messaging (MIM) systems have provided very convenient ways for communication and information exchange in recent years. Interesting features of these applications have made them important platforms for spreading information, idea, behavior, and rumor. In contrast to traditional social networks, communication in MIM applications is not necessarily based on friendship relations. In group-based communication and broadcasting in channels that are prominent features of MIM systems, users may send messages to and receive messages from people with whom do not already have friendly relations. This kind of communication leads to the creation of special network in which not only users and their contact lists but also groups and channels are involved. Existing complex network models are not sufficiently expressive to represent this kind of communication network. In this article, we introduce the concept of social communication network (SCN) to be able to consider special structural properties of communications in MIM systems and propose a model for representing and generating the SCN in MIM systems. The proposed model covers all social communications between users, groups, and channels and exhibits the statistics observed in real-world data. We also redefine some existing properties and introduce some new properties of the MIM network that earlier models of complex networks do not capture. To evaluate the proposed model, we conduct a number of simulation experiments on the model and compare the results with a real-world graph that we have extracted from Telegram. The results show that SCN derived by the model is highly compatible with the real-world graph. The proposed model provides a useful basis for analysis and evaluation of MIM network properties.
Ebrahim Sahafizadeh, Behrouz Tork Ladani
IEEE Trans. Comput. Soc. Syst.2
2019 Modeling trust and reputation systems in hostile environments
Seyed Asgary Ghasempouri, Behrouz Tork Ladani
Future Gener. Comput. Syst.2
2019 VAnDroid: A framework for vulnerability analysis of Android applications using a model-driven reverse engineering technique
abstract
Summary Android is extensively used worldwide by mobile application developers. Android provides applications with a message passing system to communicate within and between them. Due to the risks associated with this system, it is vital to detect its unsafe operations and potential vulnerabilities. To achieve this goal, a new framework, called VAnDroid, based on Model Driven Reverse Engineering (MDRE), is presented that identifies security risks and vulnerabilities related to the Android application communication model. In the proposed framework, some security‐related information included in an Android app is automatically extracted and represented as a domain‐specific model. Then, it is used for analyzing security configurations and identifying vulnerabilities in the corresponding application. The proposed framework is implemented as an Eclipse‐based tool, which automatically identifies the Intent Spoofing and Unauthorized Intent Receipt as two attacks related to the Android application communication model. To evaluate the tool, it has been applied to several real‐world Android applications, including 20 apps from Google Play and 110 apps from the F‐Droid repository. VAnDroid is also compared with several existing analysis tools, and it is shown that it has a number of key advantages over those tools specifically regarding its high correctness, scalability, and usability in discovering vulnerabilities. The results well indicate the effectiveness and capacity of the VAnDroid as a promising approach in the field of Android security.
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani
Softw. Pract. Exp.3
2017 Information sharing vs. privacy: A game theoretic analysis
Mansooreh Ezhei, Behrouz Tork Ladani
Expert Syst. Appl.2
2016 Automated program repair using genetic programming and model checking
Zahra Zojaji, Behrouz Tork Ladani, Alireza Khalilian 0001
Appl. Intell.2
2016 Modeling and Quantitative Verification of Trust Systems Against Malicious Attackers
abstract
Nowadays, trust systems (TSs) are widely used for tackling dishonest entities in many modern environments. However, these systems are vulnerable to some kinds of attacks where attackers try to deceive the system using sequences of misleading behaviors and dishonest recommendations. A robust TS is expected to function properly even in the possibility of such attacks. To the best of our knowledge, simulation has been the main approach for evaluation of TSs so far, and there is no remarkable verification method for this aim. In this paper, a method for quantitative verification of TSs' robustness against malicious attackers is proposed. The proposed method consists of a formalism for specifying any given trust model named TS attack process that is cast into partially observable Markov decision process mathematical framework. The proposed method is capable of verifying TSs against both well-known attacks and the worst possible attack scenario. The method could also be used to help adjusting parameters of the given TS. Moreover, a quantitative robustness measure is introduced, which helps to compare the robustness of different TSs. To illustrate the applicability of the proposed method, a number of case studies for analysis and comparison of selected trust models (including Subjective Logic and REGRET) are presented.
Amir Jalaly Bidgoly, Behrouz Tork Ladani
Comput. J.2
2015 Modelling and Quantitative Verification of Reputation Systems Against Malicious Attackers
Amir Jalaly Bidgoly, Behrouz Tork Ladani
Comput. J.2
2015 Gossip-based data aggregation in hostile environments
Mousa Mousazadeh, Behrouz Tork Ladani
Comput. Commun.2
2014 DDoS attack detection in IEEE 802.16 based networks
Maryam Shojaei, Naser Movahhedinia, Behrouz Tork Ladani
Wirel. Networks3
2010 An auction method for resource allocation in computational grids
Hesam Izakian, Ajith Abraham, Behrouz Tork Ladani
Future Gener. Comput. Syst.3
2010 Anonymity and security for autonomous mobile agents
abstract
The mobile agent security against malicious hosts is one of the most important subjects in mobile agent technology. An extended requirement for an agent security in different applications is to provide it with anonymity property in such a way that the agent can travel in the network without exposing its owner identity and its itinerary. For this purpose, an agent anonymity protocol is proposed to maintain the anonymity of the agent owner and the agent itinerary. The introduced anonymous agent is also applied to disarm the host against the agent instead of using an armed agent, that is, an agent equipped with protection mechanisms. The analytical discussion demonstrated that this protocol preserves the autonomy of the agent in choosing the migration path and is also resistant against known traffic analysis attacks in mobile agent systems with plausible assumption. Moreover, it is feasible and adjustable regarding the required level of anonymity.
Fatemeh Raji, Behrouz Tork Ladani
IET Inf. Secur.2
2006 Specification and Implementation of Multi-Agent Organizations
Fatemeh Ghassemi, Naser Nematbakhsh, Behrouz Tork Ladani, Marjan Sirjani
WEBIST (1)3