EDBT 2026 Demo / reviewers in the wild / expert
Sakir Sezer
dblp:07/5312
· DBLP profile ↗
67ranked-venue papers
5as first author
10since 2021 · last 2024
0000-0003-2857-616XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 25 · 4 first-author · 5 since 2021Security and privacy · 22 · 3 since 2021Computer networks · 10 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | XANDAR: An X-by-Construction Framework for Safety, Security, and Real-Time Behavior of Embedded Software SystemsabstractThe safe and secure implementation of increasingly complex features is a major challenge in the development of autonomous and distributed embedded systems. Automated design-time procedures that guarantee the fulfillment of critical system properties are a promising approach to tackle this challenge. In the European project XANDAR, which took place from 2021 to 2023, eight partners developed an X-by-Construction (XbC) design framework to support developers in the creation of embedded software systems with certain safety, security, and real-time properties. The design framework combines a model-based toolchain with a hypervisor-based runtime architecture. It targets modern high-performance hardware, facilitates the integration of machine learning applications, and employs a library of trusted safety and security patterns to reduce the implementation and verification effort. This paper describes the concepts developed during the project, the prototypical implementation of the design framework, and its application in both an automotive and an avionics use case. Tobias Dörr, Florian Schade, Jürgen Becker 0001, Georgios Keramidas, Nikos Petrellis, Vasilios I. Kelefouras, Michail Mavropoulos, Konstantinos Antonopoulos, Christos P. Antonopoulos, Nikos S. Voros, Alexander Ahlbrecht, Wanja Zaeske, Vincent Janson, Phillip Nöldeke, Umut Durak, Christos Panagiotou, Dimitris Karadimas, Nico Adler, Clemens Reichmann, Andreas Sailer, Raphael Weber, Thomas Wilhelm 0005, Wolfgang Gabler, Katrin Weiden, Xavier Anzuela Recasens, Sakir Sezer, Fahad Siddiqui 0001, Rafiullah Khan, Kieran McLaughlin, Sena Yengec Tasdemir, Balmukund Sonigara, Henry Hui, Esther Soriano Viguer, Aridane Álvarez Suárez, Vicente Nicolau Gallego, Manuel Muñoz Alcobendas, Miguel Masmano Tello |
DATE | 26 |
| 2023 | DEV-PIM: Dynamic Execution Validation with Processing-in-MemoryabstractInstruction injections or soft errors during execution on the CPU can cause serious system vulnerabilities. During the standard program flow of the processor, the injection of unauthorized instruction or the occurrence of an error in the expected instruction are the main conditions for potentially serious such vulnerabilities. With the execution of these unauthorized instructions, adversaries could exploit SoC and execute their own malicious program or get higher-level privileges on the system. On the other hand, non-intentional errors can potentially corrupt programs causing unintended executions or the cause of program crashes. Modern trusted architectures propose solutions for unauthorized execution on SoC with additional software mechanisms or extra hardware logic on the same untrusted SoC. Nevertheless, these SoCs can still be vulnerable, as long as deployed security detection mechanisms are embedded within the same SoC’s fabric. Furthermore, validation mechanisms on the SoC increase the complexity and power consumption of the SoC. This paper presents DEV-PIM, a new, high-performance, and low-cost execution validation mechanism in SoCs with external DRAM memory. The proposed approach uses processing-in-memory (PIM) method to detect instruction injections or corrupted instructions by utilising basic computing resources on a standard DRAM device. DEV-PIM transfers instructions scheduled for execution on the CPU to the DRAM and validates them by comparing content with the trusted program record on the DRAM using PIM operations. By optimising the DRAM scheduling process validation tasks are only executed when memory access is idle. The CPU retains uninterrupted memory access and can continue its normal program flow without penalty. We evaluate DEV-PIM in an end-to-end DRAM-compatible environment and run a set of software benchmarks. On average, the proposed architecture is able to detect 98.46% of instruction injections for different validation. We also measured on average only 0.346% CPU execution overhead with DEV-PIM enabled. Alperen Bolat, Yahya Can Tugrul, Seyyid Hikmet Çelik, Sakir Sezer, Marco Ottavi, Oguz Ergin |
ETS | 4 |
| 2023 | Secure Real-Time Industrial IoT Communications in Smart Grids Using Named Data NetworkingabstractThis paper explores Named Data Networking (NDN) for secure Industrial IoT (IIoT) communications in smart grid applications. NDN is a next generation networking paradigm, which is data-centric and has the benefit of built-in security properties, such as data integrity. This work applies NDN to IEEE C37.118.2 PMU communications, as an example smart grid IIoT application, and proposes a new data-encapsulation approach for NDN for low latency data streaming. The proposed communication architecture allows sensor data streaming with a lower overhead compared to related work. Communications are demonstrated to be secured using a trust anchor which protects data integrity and provides data authentication, while supporting optional data encryption. The proposed solution represents IEEE C37.118.2 in a JSON format, which provides flexibility and facilitates application of the approach to different use cases. Henry Hui, James Grant, Kieran McLaughlin, David M. Laverty, Sakir Sezer |
INDIN | 5 |
| 2023 | Cybersecurity Engineering: Bridging the Security Gaps in Advanced Automotive Systems and ISO/SAE 21434abstractAdvanced Driver Assistance System is one of the enabling technologies for autonomous driving. It senses and analyses the vehicle surroundings, detects the presence of potential risks as well as hazards and generates advisories. These advisories assist the autonomous driving system to take corrective measures to reduce safety risks and avoid fatal road accidents. For this purpose, ADAS uses various advanced sensing and data communication technologies to gather, process and share vehicle data. Noentheless the use of these advanced connected technologies is expected to grow further in road infrastructure such as Vehicle-to-everything (V2X). In this regard, where this sharing of mix-critical data brings opportunities, if compromised, presents serious cybersecurity threats and safety risks due to the cyber-physical nature of these advanced automotive systems. Therefore, the automotive system design approach of adhering to functional safety standards (ISO 26262) alone is inadequate to protect the vehicle’s critical functions from a range of cyberattacks. To approach this challenge, the ISO/SAE 21434 standard provides a cybersecurity baseline for vehicle manufacturers to effectively manage cybersecurity risks and improve the cyber resilience of the automotive system. This paper adopts a holistic cybersecurity engineering process as a baseline and bridges the security gap by mapping the security engineering requirements of ISO/SAE 21434 to the traditional system design engineering processes including system generation and runtime phases. It also introduces an experimental automotive use case, defines the scope to establish the context, presents a comprehensive Threat Analysis and Risk Assessment and derives appropriate risk mitigation strategies. The proposed work facilitates automotive system designers to follow ISO/SAE 21434 standard guidelines by systematically identify, assess, protect and manage the cybersecurity risks across the automotive system life cycle. Fahad Siddiqui 0001, Rafiullah Khan, Sena Yengec Tasdemir, Henry Hui, Balmukund Sonigara, Sakir Sezer, Kieran McLaughlin |
VTC2023-Spring | 6 |
| 2022 | XANDAR: Exploiting the X-by-Construction Paradigm in Model-based Development of Safety-critical SystemsabstractRealizing desired properties “by construction” is a highly appealing goal in the design of safety-critical embedded systems. As verification and validation tasks in this domain are often both challenging and time-consuming, the by-construction paradigm is a promising solution to increase design productivity and reduce design errors. In the XANDAR project, partners from industry and academia develop a toolchain that will advance current development processes by employing a modelbased X-by-Construction (XbC) approach. XANDAR defines a development process, metamodel extensions, a library of safety and security patterns, and investigates many further techniques for design automation, verification, and validation. The developed toolchain will use a hypervisor-based platform, targeting future centralized, AI-capable high-performance embedded processing systems. It is co-developed and validated in both an avionics use case for situation perception and pilot assistance as well as an automotive use case for autonomous driving. Leonard Masing, Tobias Dörr, Florian Schade, Jürgen Becker 0001, Georgios Keramidas, Christos P. Antonopoulos, Michail Mavropoulos, Efstratios Tiganourias, Vasilios I. Kelefouras, Konstantinos Antonopoulos, Nikos S. Voros, Umut Durak, Alexander Ahlbrecht, Wanja Zaeske, Christos Panagiotou, Dimitris Karadimas, Nico Adler, Andreas Sailer, Raphael Weber, Thomas Wilhelm 0005, Géza Németh, Fahad Siddiqui 0001, Rafiullah Khan, Vahid Garousi, Sakir Sezer, Victor Morales |
DATE | 25 |
| 2022 | XANDAR: A holistic Cybersecurity Engineering Process for Safety-critical and Cyber-physical SystemsabstractThe integration of connected and autonomous technologies in safety-critical and cyber-physical systems offers great potential in the vital application domains of transportation, manufacturing and aerospace. These technological advancements are necessary to meet the increasing demand for intelligent services, as they open doors to new business models by analysing and sharing the generated data. However, where this sharing of mix-critical data and broader connectivity brings opportunities, it simultaneously presents serious cybersecurity and safety risks due to the cyber-physical nature of these systems. Hence, delivering these intelligent services securely, safely, and reliably to its consumers is a complex engineering and design problem. One of the ways to approach this engineering problem is to consider both system functional and non-functional properties (safety, security, reliability) and systematically integrate them across system design and operational life cycle. The XANDAR project investigates this approach and aims to develop holistic software design methods and architectures for safety-critical and cyber-physical systems that guarantee functional and non-functional properties “byconstruction”. This paper focuses on the non-functional aspects of the project and discusses the preliminary work. by presenting the core cybersecurity principles and uses them as a baseline to propose a holistic cybersecurity engineering process. The tasks of the proposed cybersecurity engineering process are also map onto relevant clauses of ISO 21434. In future, proposed work will be integrated into the XANDAR software toolchain and validated for an avionics situation perception pilot assistance and automotive autonomous driving use cases. Fahad Siddiqui 0001, Rafiullah Khan, Sakir Sezer, Kieran McLaughlin, Leonard Masing, Tobias Dörr, Florian Schade, Jürgen Becker 0001, Alexander Ahlbrecht, Wanja Zaeske, Umut Durak, Nico Adler, Andreas Sailer, Raphael Weber, Thomas Wilhelm 0005, Géza Németh, Victor Morales, Paco Gomez, Georgios Keramidas, Christos P. Antonopoulos, Michail Mavropoulos, Vasilios I. Kelefouras, Konstantinos Antonopoulos, Nikos S. Voros, Christos Panagiotou, Dimitris Karadimas |
VTC Spring | 3 |
| 2022 | MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detectionabstractRansomware is a type of advanced malware that can encrypt a user’s files or lock a computer system until a ransom has been paid. Ransomworm is a type of malware that combines the payload of ransomware with the propagation feature of a computer worm. Most host-based detection methods require the host to be infected and the payload to be executed first to be able to identify anomalies and detect the malware. By the time of infection, it might too late as some of the system’s assets would have been already encrypted or exfiltrated by the malware. On the contrary, the network-based methods can be one of the crucial means in detecting ransomworm activities when it attempts to spread to infect other networks before executing the payload. Therefore, a thorough analysis of ransomworm network traffic can be one of the essential means for early detection. This paper presents a comprehensive behavioral analysis of ransomworm network traffic, taking WannaCry, which launched a worldwide cyberattack, and NotPetya as a case study. Two sets of related features were extracted based on two independent flow levels: session-based and time-based. On top of each set, an independent classifier was built. Moreover, to improve the reliability, a multi-feature and multi-classifier network-based system, MFMCNS, has been proposed. MFMCNS employs these classifiers working in parallel on different flow levels, then it adopts a fusion rule to combine the classifiers’ decisions. The experimental results prove that MFMCNS is reliable and has high detection accuracy. Ahmad O. Almashhadani, Domhnall Carlin, Mustafa Kaiiali, Sakir Sezer |
Comput. Secur. | 4 |
| 2022 | A Model-Free Approach to Intrusion Response SystemsabstractWith the rising number of data breaches, denial of service attacks and general malicious activity facing modern computer networks, there is an increasing need to quickly and effectively respond to attacks. Intrusion Detection Systems provide an automated method of identifying malicious activity within a network however the development of an Intrusion Response System which can automatically respond to these alerts is non-trivial. Current research in IRS proposes model-based methods for identifying possible routes a malicious actor may take when attacking a network and use subjective performance values for the cost and benefit of a response, both of which can be invalidated by the increasingly dynamic nature of network topologies and system configurations. The IRS proposed in this work utilises a Model-free Reinforcement Learning approach and evaluates the Reinforcement Learning agent's performance in stopping two distinct multi-stage attack scenarios on a virtualised testbed. Experimentation demonstrates that the agent can successfully halt both attack scenarios and find responses which have minimal impact on normal network operation based on experience gained through training. A further contribution is the novel use of a virtualised environment that demonstrates Intrusion Response Reinforcement Learning performance in a more realistic environment than simulated tasks common to previous literature. Kieran Hughes, Kieran McLaughlin, Sakir Sezer |
J. Inf. Secur. Appl. | 3 |
| 2021 | XANDAR: X-by-Construction Design framework for Engineering Autonomous & Distributed Real-time Embedded Software SystemsabstractThe next generation of networked embedded systems (ES) necessitates rapid prototyping and high performance while maintaining key qualities like trustworthiness and safety. However, development of safety-critical ES suffers from complex software (SW) toolchains and engineering processes. Moreover, the current trend in autonomous systems, which relies on Machine Learning (ML) and AI applications when combined with fail-operational requirements renders the Verification and Validation (V&V) of these new systems a challenging endeavor. Prime examples are Advanced Driver-Assistance Systems (ADAS) that are prone to various safety/security vulnerabilities. The XANDAR project aims at developing a mature SW toolchain (from requirements analysis to the actual code integration on target including V&V) fulfilling the needs of industry for rapid prototyping of interoperable and autonomous ES. Starting from a model-based system architecture, XANDAR will leverage automatic model synthesis and software parallelization techniques to achieve specific non-functional requirements setting the foundation for a novel (real-time, safety-, and security)-by-Construction paradigm. Jürgen Becker 0001, Leonard Masing, Tobias Dörr, Florian Schade, Georgios Keramidas, Christos P. Antonopoulos, Michail Mavropoulos, Efstratios Tiganourias, Vasilios I. Kelefouras, Konstantinos Antonopoulos, Nikos S. Voros, Umut Durak, Alexander Ahlbrecht, Wanja Zaeske, Christos Panagiotou, Dimitris Karadimas, Nico Adler, Andreas Sailer, Raphael Weber, Thomas Wilhelm 0005, Florian Oszwald, Dominik Reinhardt, Mohamad Chamas, Adnan Bekan, Graham Smethurst, Fahad Siddiqui 0001, Rafiullah Khan, Vahid Garousi, Sakir Sezer, Victor Morales |
FPL | 29 |
| 2021 | LSTM RNN: detecting exploit kits using redirection chain sequencesabstractAbstract While consumers use the web to perform routine activities, they are under the constant threat of attack from malicious websites. Even when visiting ‘trusted’ sites, there is always a risk that site is compromised, and, hosting a malicious script. In this scenario, the injected script would typically force the victim’s browser to undergo a series of redirects before reaching an attacker-controlled domain, which, delivers the actual malware. Although these malicious redirection chains aim to frustrate detection and analysis efforts, they could be used to help identify web-based attacks. Building upon previous work, this paper presents the first known application of a Long Short-Term Memory (LSTM) network to detect Exploit Kit (EK) traffic, utilising the structure of HTTP redirects. Samples are processed as sequences, where each timestep represents a redirect and contains a unique combination of 48 features. The experiment is conducted using a ground-truth dataset of 1279 EK and 5910 benign redirection chains. Hyper-parameters are tuned via K-fold cross-validation (5f-CV), with the optimal configuration achieving an F1 score of 0.9878 against the unseen test set. Furthermore, we compare the results of isolated feature categories to assess their importance. Jonah Burgess, Philip O'Kane, Sakir Sezer, Domhnall Carlin |
Cybersecur. | 3 |
| 2020 | MaldomDetector: A system for detecting algorithmically generated domain names with machine learningabstractOne of the leading problems in cyber security at present is the unceasing emergence of sophisticated attacks, such as botnets and ransomware, that rely heavily on Command and Control (C&C) channels to conduct their malicious activities remotely. To avoid channel detection, attackers constantly try to create different covert communication techniques. One such technique is Domain Generation Algorithm (DGA), which allows malware to generate numerous domain names until it finds its corresponding C&C server. It is highly resilient to detection systems and reverse engineering, while allowing the C&C server to have several redundant domain names. This paper presents a malicious domain name detection system, MaldomDetector, which is based on machine learning. It is capable of detecting DGA-based communications and circumventing the attack before it makes any successful connection with the C&C server, using only domain name's characters. MaldomDetector uses a set of easy-to-compute and language-independent features in addition to a deterministic algorithm to detect malicious domains. The experimental results demonstrate that MaldomDetector can operate efficiently as a first alarm to detect DGA-based domains of malware families while maintaining high detection accuracy. Ahmad O. Almashhadani, Mustafa Kaiiali, Domhnall Carlin, Sakir Sezer |
Comput. Secur. | 4 |
| 2020 | DL-Droid: Deep learning based android malware detection using real devicesabstractThe Android operating system has been the most popular for smartphones and tablets since 2012. This popularity has led to a rapid raise of Android malware in recent years. The sophistication of Android malware obfuscation and detection avoidance methods have significantly improved, making many traditional malware detection methods obsolete. In this paper, we propose DL-Droid, a deep learning system to detect malicious Android applications through dynamic analysis using stateful input generation. Experiments performed with over 30,000 applications (benign and malware) on real devices are presented. Furthermore, experiments were also conducted to compare the detection performance and code coverage of the stateful input generation method with the commonly used stateless approach using the deep learning system. Our study reveals that DL-Droid can achieve up to 97.8% detection rate (with dynamic features only) and 99.6% detection rate (with dynamic + static features) respectively which outperforms traditional machine learning techniques. Furthermore, the results highlight the significance of enhanced input generation for dynamic analysis as DL-Droid with the state-based input generation is shown to outperform the existing state-of-the-art approaches. Mohammed K. Alzaylaee, Suleiman Y. Yerima, Sakir Sezer |
Comput. Secur. | 3 |
| 2019 | Enhancing Security and Privacy of Next-Generation Edge Computing TechnologiesabstractThe advent of high performance fog and edge computing and high bandwidth connectivity has brought about changes to Internet-of-Things (IoT) service architectures, allowing for greater quantities of high quality information to be extracted from their environments to be processed. However, recently introduced international regulations, along with heightened awareness among consumers, have strengthened requirements to ensure data security, with significant financial and reputational penalties for organisations who fail to protect customers' data. This paper proposes the leveraging of fog and edge computing to facilitate processing of confidential user data, to reduce the quantity and availability of raw confidential data at various levels of the IoT architecture. This ultimately reduces attack surface area, however it also increases efficiency of the architecture by distributing processing amongst nodes and transmitting only processed data. However, such an approach is vulnerable to device level attacks. To approach this issue, a proposed System Security Manager is used to continuously monitor system resources and ensure confidential data is confined only to parts of the device that require it. In event of an attack, critical data can be isolated and the system informed, to prevent data confidentiality breach. Matthew Hagan, Fahad Siddiqui 0001, Sakir Sezer |
PST | 3 |
| 2019 | A cost analysis of machine learning using dynamic runtime opcodes for malware detection
Domhnall Carlin, Philip O'Kane, Sakir Sezer |
Comput. Secur. | 3 |
| 2019 | Machine learning-based dynamic analysis of Android apps with improved code coverageabstractThis paper investigates the impact of code coverage on machine learning-based dynamic analysis of Android malware. In order to maximize the code coverage, dynamic analysis on Android typically requires the generation of events to trigger the user interface and maximize the discovery of the run-time behavioral features. The commonly used event generation approach in most existing Android dynamic analysis systems is the random-based approach implemented with the Monkey tool that comes with the Android SDK. Monkey is utilized in popular dynamic analysis platforms like AASandbox, vetDroid, MobileSandbox, TraceDroid, Andrubis, ANANAS, DynaLog, and HADM. In this paper, we propose and investigate approaches based on stateful event generation and compare their code coverage capabilities with the state-of-the-practice random-based Monkey approach. The two proposed approaches are the state-based method (implemented with DroidBot) and a hybrid approach that combines the state-based and random-based methods. We compare the three different input generation methods on real devices, in terms of their ability to log dynamic behavior features and the impact on various machine learning algorithms that utilize the behavioral features for malware detection. Experiments performed using 17,444 applications show that overall, the proposed methods provide much better code coverage which in turn leads to more accurate machine learning-based malware detection compared to the state-of- the- art approach. Suleiman Y. Yerima, Mohammed K. Alzaylaee, Sakir Sezer |
EURASIP J. Inf. Secur. | 3 |
| 2019 | DroidFusion: A Novel Multilevel Classifier Fusion Approach for Android Malware DetectionabstractAndroid malware has continued to grow in volume and complexity posing significant threats to the security of mobile devices and the services they enable. This has prompted increasing interest in employing machine learning to improve Android malware detection. In this paper, we present a novel classifier fusion approach based on a multilevel architecture that enables effective combination of machine learning algorithms for improved accuracy. The framework (called DroidFusion), generates a model by training base classifiers at a lower level and then applies a set of ranking-based algorithms on their predictive accuracies at the higher level in order to derive a final classifier. The induced multilevel DroidFusion model can then be utilized as an improved accuracy predictor for Android malware detection. We present experimental results on four separate datasets to demonstrate the effectiveness of our proposed approach. Furthermore, we demonstrate that the DroidFusion method can also effectively enable the fusion of ensemble learning algorithms for improved accuracy. Finally, we show that the prediction accuracy of DroidFusion, despite only utilizing a computational approach in the higher level, can outperform stacked generalization, a well-known classifier fusion method that employs a meta-classifier approach in its higher level. Suleiman Y. Yerima, Sakir Sezer |
IEEE Trans. Cybern. | 2 |
| 2019 | A Multimodal Deep Learning Method for Android Malware Detection Using Various FeaturesabstractWith the widespread use of smartphones, the number of malware has been increasing exponentially. Among smart devices, android devices are the most targeted devices by malware because of their high popularity. This paper proposes a novel framework for android malware detection. Our framework uses various kinds of features to reflect the properties of android applications from various aspects, and the features are refined using our existence-based or similarity-based feature extraction method for effective feature representation on malware detection. Besides, a multimodal deep learning method is proposed to be used as a malware detection model. This paper is the first study of the multimodal deep learning to be used in the android malware detection. With our detection model, it was possible to maximize the benefits of encompassing multiple feature types. To evaluate the performance, we carried out various experiments with a total of 41 260 samples. We compared the accuracy of our model with that of other deep neural network models. Furthermore, we evaluated our framework in various aspects including the efficiency in model updates, the usefulness of diverse features, and our feature representation method. In addition, we compared the performance of our framework with those of other existing methods including deep learning-based methods. TaeGuen Kim 0002, Boojoong Kang, Mina Rho, Sakir Sezer, Eul-Gyu Im |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Using Application Layer Metrics to Detect Advanced SCADA AttacksabstractCurrent state of the art intrusion detection and network monitoring systems have a tendency to focus on the ’Five-Tuple’ features (Protocol, IP src/dst and Port src/dest). As a result there is a gap in visibility of security at an application level. We propose a collection of network application layer metrics to provide a greater insight into SCADA communications. These metrics are devised from an analysis of the ICS threat landscape and the current state of the art detection systems. Our metrics are able to detect a range of adversary capabilities which goes beyond previous literature in the SCADA domain. Peter Maynard 0001, Kieran McLaughlin, Sakir Sezer |
ICISSP | 3 |
| 2018 | Detecting Cryptomining Using Dynamic AnalysisabstractWith the rise in worth and popularity of cryptocurrencies, a new opportunity for criminal gain is being exploited and with little currently offered in the way of defence. The cost of mining (i.e., earning cryptocurrency through CPU-intensive calculations that underpin the blockchain technology) can be prohibitively expensive, with hardware costs and electrical overheads previously offering a loss compared to the cryptocurrency gained. Off-loading these costs along a distributed network of machines via malware offers an instantly profitable scenario, though standard Anti-virus (AV) products offer some defences against file-based threats. However, newer fileless malicious attacks, occurring through the browser on seemingly legitimate websites, can easily evade detection and surreptitiously engage the victim machine in computationally-expensive cryptomining (cryptojacking). With no current academic literature on the dynamic opcode analysis of cryptomining, to the best of our knowledge, we present the first such experimental study. Indeed, this is the first such work presenting opcode analysis on non-executable files. Our results show that browser-based cryptomining within our dataset can be detected by dynamic opcode analysis, with accuracies of up to 100%. Further to this, our model can distinguish between cryptomining sites, weaponized benign sites, de-weaponized cryptomining sites and real world benign sites. As it is process-based, our technique offers an opportunity to rapidly detect, prevent and mitigate such attacks, a novel contribution which should encourage further future work. Domhnall Carlin, Philip O'Kane, Sakir Sezer, Jonah Burgess |
PST | 3 |
| 2018 | Peer Based Tracking using Multi-Tuple Indexing for Network Traffic Analysis and Malware DetectionabstractTraditional firewalls, Intrusion Detection Systems(IDS) and network analytics tools extensively use the `flow' connection concept, consisting of five `tuples' of source and destination IP, ports and protocol type, for classification and management of network activities. By analysing flows, information can be obtained from TCP/IP fields and packet content to give an understanding of what is being transferred within a single connection. As networks have evolved to incorporate more connections and greater bandwidth, particularly from “always on” IoT devices and video and data streaming, so too have malicious network threats, whose communication methods have increased in sophistication. As a result, the concept of the 5 tuple flow in isolation is unable to detect such threats and malicious behaviours. This is due to factors such as the length of time and data required to understand the network traffic behaviour, which cannot be accomplished by observing a single connection. To alleviate this issue, this paper proposes the use of additional, two tuple and single tuple flow types to associate multiple 5 tuple communications, with generated metadata used to profile individual connnection behaviour. This proposed approach enables advanced linking of different connections and behaviours, developing a clearer picture as to what network activities have been taking place over a prolonged period of time. To demonstrate the capability of this approach, an expert system rule set has been developed to detect the presence of a multi-peered ZeuS botnet, which communicates by making multiple connections with multiple hosts, thus undetectable to standard IDS systems observing 5 tuple flow types in isolation. Finally, as the solution is rule based, this implementation operates in realtime and does not require post-processing and analytics of other research solutions. This paper aims to demonstrate possible applications for next generation firewalls and methods to acquire additional information from network traffic. Matthew Hagan, Boojoong Kang, Kieran McLaughlin, Sakir Sezer |
PST | 4 |
| 2018 | Demonstrating Cyber-Physical Attacks and Defense for Synchrophasor Technology in Smart GridabstractSynchrophasor technology is used for real-time control and monitoring in smart grid. Previous works in literature identified critical vulnerabilities in IEEE C37.118.2 synchrophasor communication standard. To protect synchrophasor-based systems, stealthy cyber-attacks and effective defense mechanisms still need to be investigated.This paper investigates how an attacker can develop a custom tool to execute stealthy man-in-the-middle attacks against synchrophasor devices. In particular, four different types of attack capabilities have been demonstrated in a real synchrophasor-based synchronous islanding testbed in laboratory: (i) command injection attack, (ii) packet drop attack, (iii) replay attack and (iv) stealthy data manipulation attack. With deep technical understanding of the attack capabilities and potential physical impacts, this paper also develops and tests a distributed Intrusion Detection System (IDS) following NIST recommendations. The functionalities of the proposed IDS have been validated in the testbed for detecting aforementioned cyber-attacks. The paper identified that a distributed IDS with decentralized decision making capability and the ability to learn system behavior could effectively detect stealthy malicious activities and improve synchrophasor network security. Rafiullah Khan, Kieran McLaughlin, John Hastings, David M. Laverty, Sakir Sezer |
PST | 5 |
| 2017 | Deep Android Malware DetectionabstractIn this paper, we propose a novel android malware detection system that uses a deep convolutional neural network (CNN). Malware classification is performed based on static analysis of the raw opcode sequence from a disassembled program. Features indicative of malware are automatically learned by the network from the raw opcode sequence thus removing the need for hand-engineered malware features. The training pipeline of our proposed system is much simpler than existing n-gram based malware detection methods, as the network is trained end-to-end to jointly learn appropriate features and to perform classification, thus removing the need to explicitly enumerate millions of n-grams during training. The network design also allows the use of long n-gram like features, not computationally feasible with existing methods. Once trained, the network can be efficiently executed on a GPU, allowing a very large number of files to be scanned quickly. Niall McLaughlin, Jesús Martínez del Rincón, Boojoong Kang, Suleiman Y. Yerima, Paul Miller 0003, Sakir Sezer, Yeganeh Safaei, Erik Trickel, Ziming Zhao 0001, Adam Doupé, Gail-Joon Ahn |
CODASPY | 6 |
| 2017 | New sensing technique for detecting application layer DDoS attacks targeting back-end database resourcesabstractDistributed Denial of Service (DDoS) attacks targeting the application layer are becoming more prevalent due to a lack of suitable defence solutions. Existing research treats the web server environment as a black box, by only monitoring the edge network traffic; however, we believe that this approach limits the accuracy of the detection system as it does not protect the back-end database servers. In this paper we propose a new sensor located within the back-end system, which can produce additional database features. This allows for real-time insight into the actual database workload caused by each user enabling the detection of DDoS attacks targeting high database consumption resources. These resource metrics are analysed in real-time on a live website, using a decision tree classification engine. Our preliminary results show that a low rate asymmetric attack as low as 1 request every 10 seconds can be detected using these proposed features. David Beckett, Sakir Sezer, John V. McCanny |
ICC | 2 |
| 2017 | STPA-SafeSec: Safety and security analysis for cyber-physical systemsabstractCyber-physical systems tightly integrate physical processes and information and communication technologies. As today's critical infrastructures, e.g., the power grid or water distribution networks, are complex cyber-physical systems, ensuring their safety and security becomes of paramount importance. Traditional safety analysis methods, such as HAZOP, are ill-suited to assess these systems. Furthermore, cybersecurity vulnerabilities are often not considered critical, because their effects on the physical processes are not fully understood. In this work, we present STPA-SafeSec, a novel analysis methodology for both safety and security. Its results show the dependencies between cybersecurity vulnerabilities and system safety. Using this information, the most effective mitigation strategies to ensure safety and security of the system can be readily identified. We apply STPA-SafeSec to a use case in the power grid domain, and highlight its benefits. Ivo Friedberg, Kieran McLaughlin, Paul Smith 0001, David M. Laverty, Sakir Sezer |
J. Inf. Secur. Appl. | 5 |
| 2016 | Contextual Intrusion Alerts for Scada Networks - An Ontology based Approach for Intrusion Alerts Post ProcessingabstractThe complexity of modern SCADA networks and their associated cyber-attacks requires an expressive but flexible manner for representing both domain knowledge and collected intrusion alerts with the ability to integrate them for enhanced analytical capabilities and better understanding of attacks. This paper proposes an ontology-based approach for contextualized intrusion alerts in SCADA networks. In this approach, three security ontologies were developed to represent and store information on intrusion alerts, Modbus communications, and Modbus attack descriptions. This information is correlated into enriched intrusion alerts using simple ontology logic rules written in Semantic Query-Enhanced Web Rules (SQWRL). The contextualized alerts give analysts the means to better understand evolving attacks and to uncover the semantic relationships between sequences of individual attack events. The proposed system is illustrated by two use case scenarios. Abdullah Al Balushi, Kieran McLaughlin, Sakir Sezer |
ICISSP | 3 |
| 2016 | IEEE C37.118-2 Synchrophasor Communication Framework - Overview, Cyber Vulnerabilities Analysis and Performance EvaluationabstractSynchrophasors have become an important part of the modern power system and numerous applications have been developed covering wide-area monitoring, protection and control. Most applications demand continuous transmission of synchrophasor data across large geographical areas and require an efficient communication framework. IEEE C37.118-2 evolved as one of the most successful synchrophasor communication standards and is widely adopted. However, it lacks a predefined security mechanism and is highly vulnerable to cyber attacks. This paper analyzes different types of cyber attacks on IEEE C37.118-2 communication system and evaluates their possible impact on any developed synchrophasor application. Further, the paper also recommends an efficent security mechanism that can provide strong protection against cyber attacks. Although, IEEE C37.118-2 has been widely adopted, there is no clear understanding of the requirements and limitations. To this aim, the paper also presents detailed performance evaluation of IEEE C37.118-2 implementations which could help determine required resources and network characteristics before designing any synchrophasor application. Rafiullah Khan, Kieran McLaughlin, David M. Laverty, Sakir Sezer |
ICISSP | 4 |
| 2016 | Modelling Duqu 2.0 Malware using Attack Trees with Sequential ConjunctionabstractIn this paper we identify requirements for choosing a threat modelling formalisation for modelling sophisticated malware such as Duqu 2.0. We discuss the gaps in current formalisations and propose the use of Attack Trees with Sequential Conjunction when it comes to analysing complex attacks. The paper models Duqu 2.0 based on the latest information sourced from formal and informal sources. This paper provides a well structured model which can be used for future analysis of Duqu 2.0 and related attacks. Peter Maynard 0001, Kieran McLaughlin, Sakir Sezer |
ICISSP | 3 |
| 2016 | OSCIDS: An Ontology based SCADA Intrusion Detection FrameworkabstractThis paper presents the design, development, and validation of an ontology based SCADA intrusion detection system. The proposed system analyses SCADA network communications and can derive additional information based on the background knowledge and ontology models to enhance the intrusion detection data. The developed intrusion model captures network communications, cyber attacks and the context within the SCADA domain. Moreover, a set of semantic rules were constructed to detect various attacks and extract logical relationships among these attacks. The presented framework was extensively evaluated and a comparison to the state of the art is provided. Abdullah Al Balushi, Kieran McLaughlin, Sakir Sezer |
SECRYPT | 3 |
| 2016 | Spatio-Temporal Rich Model-Based Video Steganalysis on Cross Sections of Motion Vector PlanesabstractA rich model-based motion vector (MV) steganalysis benefiting from both temporal and spatial correlations of MVs is proposed in this paper. The proposed steganalysis method has a substantially superior detection accuracy than the previous methods, even the targeted ones. The improvement in detection accuracy lies in several novel approaches introduced in this paper. First, it is shown that there is a strong correlation, not only spatially but also temporally, among neighbouring MVs for longer distances. Therefore, temporal MV dependency alongside the spatial dependency is utilized for rigorous MV steganalysis. Second, unlike the filters previously used, which were heuristically designed against a specific MV steganography, a diverse set of many filters, which can capture aberrations introduced by various MV steganography methods is used. The variety and also the number of the filter kernels are substantially more than that of used in the previous ones. Besides that, filters up to fifth order are employed whereas the previous methods use at most second order filters. As a result of these, the proposed system captures various decorrelations in a wide spatio-temporal range and provides a better cover model. The proposed method is tested against the most prominent MV steganalysis and steganography methods. To the best knowledge of the authors, the experiments section has the most comprehensive tests in MV steganalysis field, including five stego and seven steganalysis methods. Test results show that the proposed method yields around 20% detection accuracy increase in low payloads and 5% in higher payloads. Kasim Tasdemir, Fatih Kurugollu, Sakir Sezer |
IEEE Trans. Image Process. | 3 |
| 2015 | Investigating cyber-physical attacks against IEC 61850 photovoltaic inverter installationsabstractCyber-attacks against Smart Grids have been found in the real world. Malware such as Havex and BlackEnergy have been found targeting industrial control systems (ICS) and researchers have shown that cyber-attacks can exploit vulnerabilities in widely used Smart Grid communication standards. This paper addresses a deep investigation of attacks against the manufacturing message specification of IEC 61850, which is expected to become one of the most widely used communication services in Smart Grids. We investigate how an attacker can build a custom tool to execute man-in-the-middle attacks, manipulate data, and affect the physical system. Attack capabilities are demonstrated based on NESCOR scenarios to make it possible to thoroughly test these scenarios in a real system. The goal is to help understand the potential for such attacks, and to aid the development and testing of cyber security solutions. An attack use-case is presented that focuses on the standard for power utility automation, IEC 61850 in the context of inverter-based distributed energy resource devices; especially photovoltaics (PV) generators. Boojoong Kang, Peter Maynard 0001, Kieran McLaughlin, Sakir Sezer, Filip Andren, Christian Seitl, Friederich Kupzog, Thomas I. Strasser |
ETFA | 4 |
| 2015 | Spatio-temporal rich model for motion vector steganalysisabstractWe propose a spatio-temporal rich model of motion vector planes as a part of a full steganalytic system against motion vector based steganography. Superior detection accuracy of the rich model over the previous methods has been lately demonstrated for digital images in both spatial and DCT domain. It has not been heretofore used for detection of motion vector steganography. We also introduced a transformation so as to extend the feature set with temporal residuals. We carried out the tests along with most recent motion vector steganalysis and steganography methods. Test results show that the proposed model delivers an outstanding performance compared to the previous methods. Kasim Tasdemir, Fatih Kurugollu, Sakir Sezer |
ICASSP | 3 |
| 2015 | High accuracy android malware detection using ensemble learningabstractWith over 50 billion downloads and more than 1.3 million apps in Google's official market, Android has continued to gain popularity among smartphone users worldwide. At the same time there has been a rise in malware targeting the platform, with more recent strains employing highly sophisticated detection avoidance techniques. As traditional signature‐based methods become less potent in detecting unknown malware, alternatives are needed for timely zero‐day discovery. Thus, this study proposes an approach that utilises ensemble learning for Android malware detection. It combines advantages of static analysis with the efficiency and performance of ensemble machine learning to improve Android malware detection accuracy. The machine learning models are built using a large repository of malware samples and benign apps from a leading antivirus vendor. Experimental results and analysis presented shows that the proposed method which uses a large feature space to leverage the power of ensemble learning is capable of 97.3–99% detection accuracy with very low false positive rates. Suleiman Y. Yerima, Sakir Sezer, Igor Muttik |
IET Inf. Secur. | 2 |
| 2014 | Optimized packet classification for Software-Defined NetworkingabstractRecent trends, such as Software-Defined Networking (SDN), introduce programmability to the network with the opportunity to dynamically route traffic based on flow descriptions. Packet header lookup is the first phase in this process. In this paper, we illustrate improved header lookup and flow rule update speeds over conventional lookup algorithms. This is achieved by performing individual packet header field searches and combining the search results. We propose that individual algorithms should be selected for packet classification based on the application requirements. Improving the network processing performance with our configurable solution will directly support the proposed capability of programmability in SDN. K. Guerra Perez, Xin Yang 0010, Sandra Scott-Hayward, Sakir Sezer |
ICC | 4 |
| 2014 | OperationCheckpoint: SDN Application ControlabstractOne of the core properties of Software Defined Networking (SDN) is the ability for third parties to develop network applications. This introduces increased potential for innovation in networking from performance-enhanced to energy-efficient designs. In SDN, the application connects with the network via the SDN controller. A specific concern relating to this communication channel is whether an application can be trusted or not. For example, what information about the network state is gathered by the application? Is this information necessary for the application to execute or is it gathered for malicious intent? In this paper we present an approach to secure the northbound interface by introducing a permissions system that ensures that controller operations are available to trusted applications only. Implementation of this permissions system with our Operation Checkpoint adds negligible overhead and illustrates successful defense against unauthorized control function access attempts. Sandra Scott-Hayward, Christopher Kane, Sakir Sezer |
ICNP | 3 |
| 2014 | Analysis of Bayesian classification-based approaches for Android malware detectionabstractMobile malware has been growing in scale and complexity spurred by the unabated uptake of smartphones worldwide. Android is fast becoming the most popular mobile platform resulting in sharp increase in malware targeting the platform. Additionally, Android malware is evolving rapidly to evade detection by traditional signature‐based scanning. Despite current detection measures in place, timely discovery of new malware is still a critical issue. This calls for novel approaches to mitigate the growing threat of zero‐day Android malware. Hence, the authors develop and analyse proactive machine‐learning approaches based on Bayesian classification aimed at uncovering unknown Android malware via static analysis. The study, which is based on a large malware sample set of majority of the existing families, demonstrates detection capabilities with high accuracy. Empirical results and comparative analysis are presented offering useful insight towards development of effective static‐analytic Bayesian classification‐based solutions for detecting unknown Android malware. Suleiman Y. Yerima, Sakir Sezer, Gavin McWilliams |
IET Inf. Secur. | 2 |
| 2013 | A New Android Malware Detection Approach Using Bayesian ClassificationabstractMobile malware has been growing in scale and complexity as smartphone usage continues to rise. Android has surpassed other mobile platforms as the most popular whilst also witnessing a dramatic increase in malware targeting the platform. A worrying trend that is emerging is the increasing sophistication of Android malware to evade detection by traditional signature-based scanners. As such, Android app marketplaces remain at risk of hosting malicious apps that could evade detection before being downloaded by unsuspecting users. Hence, in this paper we present an effective approach to alleviate this problem based on Bayesian classification models obtained from static code analysis. The models are built from a collection of code and app characteristics that provide indicators of potential malicious activities. The models are evaluated with real malware samples in the wild and results of experiments are presented to demonstrate the effectiveness of the proposed approach. Suleiman Y. Yerima, Sakir Sezer, Gavin McWilliams, Igor Muttik |
AINA | 2 |
| 2013 | NFP-6xxx - a 22nm high-performance network flow processor for 200Gb/s Software Defined Networking
Gavin Stark, Sakir Sezer |
Hot Chips Symposium | 2 |
| 2013 | SVM Training Phase Reduction Using Dataset Feature Filtering for Malware DetectionabstractN-gram analysis is an approach that investigates the structure of a program using bytes, characters, or text strings. A key issue with N-gram analysis is feature selection amidst the explosion of features that occurs when N is increased. The experiments within this paper represent programs as operational code (opcode) density histograms gained through dynamic analysis. A support vector machine is used to create a reference model, which is used to evaluate two methods of feature reduction, which are “area of intersect” and “subspace analysis using eigenvectors.” The findings show that the relationships between features are complex and simple statistics filtering approaches do not provide a viable approach. However, eigenvector subspace analysis produces a suitable filter. Philip O'Kane, Sakir Sezer, Kieran McLaughlin, Eul-Gyu Im |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2012 | ITACA: Flexible, scalable network analysisabstractReal-time analysis is vital to network security and management. Solutions are required that are scalable to modern network speeds while remaining flexible to ensure the latest analysis techniques can be implemented. This paper presents the Internet Traffic And Content Analyser (ITACA), an extendable general analysis tool that enables the implementation of plugins to perform specific tasks. Designed with a modular architecture akin to hardware, it is shown, with experiments on real network traffic, to outperform Bro and Snort IDSs in terms of throughput and scalability while offering increased flexibility for real-time analysis. John Hurley, Antonio Muñoz 0003, Sakir Sezer |
ICC | 3 |
| 2012 | Custom purpose regular expression processor architecture for network processingabstractIn this paper we introduce the architecture and system platform of a new regular expression processor for next generation security platforms for content awareness and network security processing. The paper first outlines the feature requirements of state-of-the-art network and security systems, then presents the proposed content processing system and processor architecture. Sakir Sezer, Dwayne Burns |
ISCAS | 1 |
| 2012 | Fully hardware based WFQ architecture for high-speed QoS packet scheduling
Kieran McLaughlin, Dwayne Burns, Ciaran Toal, Colm McKillen, Sakir Sezer |
Integr. | 5 |
| 2011 | Generic Low-Latency NoC Router Architecture for FPGA Computing SystemsabstractA novel cost-effective and low-latency wormhole router for packet-switched NoC designs, tailored for FPGA, is presented. This has been designed to be scalable at system level to fully exploit the characteristics and constraints of FPGA based systems, rather than custom ASIC technology. A key feature is that it achieves a low packet propagation latency of only two cycles per hop including both router pipeline delay and link traversal delay - a significant enhancement over existing FPGA designs - whilst being very competitive in terms of performance and hardware complexity. It can also be configured in various network topologies including 1-D, 2-D, and 3-D. Detailed design-space exploration has been carried for a range of scaling parameters, with the results of various design trade-offs being presented and discussed. By taking advantage of abundant build-in reconfigurable logic and routing resources, we have been able to create a new scalable on-chip FPGA based router that exhibits high dimensionality and connectivity. The architecture proposed can be easily migrated across many FPGA families to provide flexible, robust and cost-effective NoC solutions suitable for the implementation of high-performance FPGA computing systems. Ye Lu 0003, John V. McCanny, Sakir Sezer |
FPL | 3 |
| 2011 | An Approach for Unifying Rule Based Deep Packet InspectionabstractHigh performance Internet traffic inspection and layer-7 content analysis have become essential functions of high speed networks. Over the past decade several DPI systems have evolved targeting specific issues related to traffic management, user/application policing, intrusion detection/prevention, URL/malicious/unwanted content filtering. Snort, OpenDPI, Bro, L7-filter, ClamAV are a number of open-source tools based on custom DPI engines and custom rule-sets. The surging demand for higher bandwidth DPI systems capable of supporting larger rule-sets requires the use of hardware acceleration and hardware-based systems. In comparison to software based systems, the design and development of custom purpose hardware for DPI is expensive. The need for DPI solutions for a range of applications at high speed requires a unified processing platform. This paper presents the research in converting known DPI rule-sets into a meta format based on regular expressions, that can be executed by software and hardware-based processing platforms. To demonstrate this work a Snort2Regex translator has been developed to transform Snort rules into regular expressions using not only the content of the Snort rule but every relevant element that belongs to it and could increase the accuracy of the analysis. Antonio Muñoz 0003, Sakir Sezer, Dwayne Burns, Gareth Douglas |
ICC | 2 |
| 2011 | Classifying network protocols: A 'two-way' flow approachabstractThe identification and classification of network traffic and protocols is a vital step in many quality of service and security systems. Traffic classification strategies must evolve, alongside the protocols utilising the Internet, to overcome the use of ephemeral or masquerading port numbers and transport layer encryption. This research expands the concept of using machine learning on the initial statistics of flow of packets to determine its underlying protocol. Recognising the need for efficient training/retraining of a classifier and the requirement for fast classification, the authors investigate a new application of k-means clustering referred to as ‘two-way’ classification. The ‘two-way’ classification uniquely analyses a bidirectional flow as two unidirectional flows and is shown, through experiments on real network traffic, to improve classification accuracy by as much as 18% when measured against similar proposals. It achieves this accuracy while generating fewer clusters, that is, fewer comparisons are needed to classify a flow. A ‘two-way’ classification offers a new way to improve accuracy and efficiency of machine learning statistical classifiers while still maintaining the fast training times associated with the k-means. John Hurley, Emi Garcia-Palacios, Sakir Sezer |
IET Commun. | 3 |
| 2011 | Host-Based P2P Flow Identification and Use in Real-TimeabstractData identification and classification is a key task for any Internet Service Provider (ISP) or network administrator. As port fluctuation and encryption become more common in P2P applications wishing to avoid identification, new strategies must be developed to detect and classify their flows. This article introduces a method of separating P2P and standard web traffic that can be applied as part of an offline data analysis process, based on the activity of the hosts on the network. Heuristics are analyzed and a classification system proposed that focuses on classifying those “long” flows that transfer most of the bytes across a network. The accuracy of the system is then tested using real network traffic from a core Internet router showing misclassification rates as low as 0.54% of flows in some cases. We expand on this proposed strategy to investigate its relevance to real-time, early classification problems. New proposals are made and the results of real-time experiments are compared to those obtained in the offline analysis. It is shown that classification accuracies in the real-time strategy are similar to those achieved in offline analysis with a large portion of the total web and P2P flows correctly identified. John Hurley, Emi Garcia-Palacios, Sakir Sezer |
ACM Trans. Web | 3 |
| 2010 | Intelligent Sensor Information System For Public Transport - To Safely GoabstractThe Intelligent Sensor Information System (ISIS) is described. ISIS is an active CCTV approach to reducing crime and anti-social behavior on public transport systems such as buses. Key to the system is the idea of event composition, in which directly detected atomic events are combined to infer higher-level events with semantic meaning. Video analytics are described that profile the gender of passengers and track them as they move about a 3-D space. The overall system architecture is described which integrates the on-board event recognition with the control room software over a wireless network to generate a real-time alert. Data from preliminary data-gathering trial is presented. Paul Miller 0003, Weiru Liu, Chris Fowler, Huiyu Zhou 0001, Jiali Shen, Jianbing Ma, Jianguo Zhang 0001, Wei Qi Yan 0001, Kieran McLaughlin, Sakir Sezer |
AVSS | 10 |
| 2010 | Advanced Multithreading Architecture with Hardware Based SchedulingabstractFPGA based soft-processors are an attractive approach for embedded system engineering. Multithreading is proposed as the method to manage long latency events that are caused by I/O, off-chip memory and other shared resource accesses. However, most of the earlier multi-threaded soft-processors were based on conventional FPMT and CGMT architectures, which fall short for several reasons. In this paper, we propose a novel multithreading architecture for soft-processors that eliminates the thread switch penalty, while maintaining the single thread performance. Ye Lu 0003, Sakir Sezer, John V. McCanny |
FPL | 2 |
| 2010 | On the Privacy of Encrypted Skype CommunicationsabstractThe privacy of voice over IP (VoIP) systems is achieved by compressing and encrypting the sampled data. This paper investigates in detail the leakage of information from Skype, a widely used VoIP application. In this research, it has been demonstrated by using the dynamic time warping (DTW) algorithm, that sentences can be identified with an accuracy of 60%. The results can be further improved by choosing specific training data. An approach involving the Kalman filter is proposed to extract the kernel of all training signals. Benoît Dupasquier, Stefan Burschka, Kieran McLaughlin, Sakir Sezer |
GLOBECOM | 4 |
| 2010 | TLM2.0 based timing accurate modeling method for complex NoC systemsabstractScalability and efficiency of on-chip communication of emerging Multiprocessor System-on-Chip (MPSoC) are critical design considerations. Conventional bus based interconnection schemes no longer fit for MPSoC with a large number of cores. Networks-on-Chip (NoC) is widely accepted as the next generation interconnection scheme for large scale MPSoC. The increase of MPSoC complexity requires fast and accurate system-level modeling techniques for rapid modeling and verification of emerging MPSoCs. However, the existing modeling methods are limited in delivering the essentials of timing accuracy and simulation speed. This paper proposes a novel system-level Networks-on-Chip (NoC) modeling method, which is based on SystemC and TLM2.0 and capable of delivering timing accuracy close to cycle accurate modeling techniques at a significantly lower simulation cost. Experimental results are presented to demonstrate the proposed method. Ye Lu 0003, Sakir Sezer, John V. McCanny |
ISCAS | 2 |
| 2009 | Identification of P2P flows through host activityabstractWith the increasing quantity and varying nature of traffic crossing the internet, coupled with techniques such as fluctuating port numbers and transport layer encryption, the identification of individual packet flows is becoming more difficult. We introduce and investigate a new method for the detec John Hurley, Emi Garcia-Palacios, Sakir Sezer |
BROADNETS | 3 |
| 2009 | Subpixel Interpolation Architecture for Multistandard Video Motion EstimationabstractA new reconfigurable subpixel interpolation architecture for multistandard (e.g., MPEG-2, MPEG-4, H.264, and AVS) video motion estimation (ME) is presented. This exploits the mixed use of parallel and serial-input FIR filters to achieve high throughput rate and efficient silicon utilization. Silicon design studies show that this can be implemented using 34.8 × 103gates with area and performance that compares very favorably with specific fixed solutions, e.g., for the H.264 standard alone. This can support SDTV and HDTV applications when implemented in 0.18 ¿m CMOS technology, with further performance enhancements achievable at 0.13 ¿m and below. John V. McCanny, Sakir Sezer |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2009 | Design and Implementation of a Field Programmable CRC Circuit ArchitectureabstractThe design and implementation of a programmable cyclic redundancy check (CRC) computation circuit architecture, suitable for deployment in network related system-on-chips (SoCs) is presented. The architecture has been designed to be field reprogrammable so that it is fully flexible in terms of the polynomial deployed and the input port width. The circuit includes an embedded configuration controller that has a low reconfiguration time and hardware cost. The circuit has been synthesised and mapped to 130-nm UMC standard cell [application-specific integrated circuit (ASIC)] technology and is capable of supporting line speeds of 5 Gb/s. Ciaran Toal, Kieran McLaughlin, Sakir Sezer, Xin Yang 0010 |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2008 | A Scalable Packet Sorting Circuit for High-Speed WFQ Packet SchedulingabstractA novel implementation of a tag sorting circuit for a weighted fair queueing (WFQ) enabled Internet protocol (IP) packet scheduler is presented. The design consists of a search tree, matching circuitry, and a custom memory layout. It is implemented using 130-nm silicon technology and supports quality of service (QoS) on networks at line speeds of 40 Gb/s, enabling next generation IP services to be deployed. Kieran McLaughlin, Sakir Sezer, Holger Blume, Xin Yang 0010, Friederich Kupzog, Tobias G. Noll |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2007 | Reconfigurable Motion Estimation Architecture for Multi-standard Video CompressionabstractA new, reconfigurable multi-standard architecture is introduced for integer-pixel motion estimation. This has been designed to cover most of the common block-based video compression standards, including MPEG-2, MPEG-4, H.264, WMV-9 andAVS. This is based on and extends a specific variable block-size architecture that we present for H.264 applications. The architecture exhibits simpler control, high throughput and relative low hardware cost when compared with existing circuits. It can also easily handle flexible search ranges without any increase in silicon area and can be configured prior to the start of the motion estimation process for a specific standard. The computational rates achieved make the circuit suitable for high end video processing applications such as HDTV. Silicon design studies indicate that circuits based on this approach incur only a relatively small penalty in terms of power dissipation and silicon area when compared with implementations for specific standards. John V. McCanny, Sakir Sezer |
ASAP | 3 |
| 2007 | An FPGA Based Memory Efficient Shared Buffer ImplementationabstractThis paper discusses the need for new high-speed hardware architectures for future networks and in particular the need for high speed, high capacity shared buffer designs. An implementation of such a buffer using FPGA technology utilizing RLDRAM II is presented. The architecture that has been derived and implemented operated at 12.8Gbps and is scalable up to 20Gbps. Dwayne Burns, Ciaran Toal, Kieran McLaughlin, Sakir Sezer, Mike Hutton, Kevin Cackovic |
FPL | 4 |
| 2006 | Design and analysis of matching circuit architectures for a closest match lookupabstractThis paper investigates the implementation of a number of circuits used to perform a high speed closest value match lookup. The design is targeted particularly for use in a search trie, as used in various networking lookup applications, but can be applied to many other areas where such a match is required. A range of different designs have been considered and implemented on FPGA. A detailed description of the architectures investigated is followed by an analysis of the synthesis results Kieran McLaughlin, Friederich Kupzog, Holger Blume, Sakir Sezer, Tobias G. Noll, John V. McCanny |
IPDPS | 4 |
| 2006 | Investigation into programmability for layer 2 protocol frame delineation architecturesabstractThis paper presents the design and study of reconfigurable architectures for two data-link layer frame delineation techniques used for ATM and GFP. The architectures are targeted to Altera Stratix II FPGA technology and are investigated in terms of performance and area. This work addresses the potential for incorporating programmability into custom purpose architectures that could enable the same processing hardware to be used for processing multiple protocols Ciaran Toal, Sakir Sezer |
IPDPS | 2 |
| 2004 | An investigation into the design of high-performance shared buffer architectures based on FPGA technology with embedded memoryabstractThe asynchronous nature of packet based communication demands efficient management of buffer resources at network nodes. Shared buffer architectures consequently become one of the dominating constructs of modern routers and switches. This work investigates new and existing shared buffer architectures that are ideal for emerging FPGA technologies with embedded memory. Stephen O'Kane, Sakir Sezer |
FPT | 2 |
| 2004 | Architecture and implementation of a novel tag computation circuit for broadband wireless access packet schedulingabstractIn this paper we present the hardware architecture and implementation of a tag computation circuit for a credit based Self-Clocked Fair Queuing (SCFQ) scheduler specifically targeted for packet scheduling in Broadband Wireless Access (BWA) as described in the recently released IEEE 802.16 Standards. Our objective is the implementation of a configurable scheduler that is based on the principles of weighted fair queuing combined with a credit based bandwidth reallocation scheme. The implementation provides the hardware platform for a runtime configurable scheduling architecture that is able to reallocate bandwidth on the fly if particular links should suffer packet loss due to unexpected noise or channel quality degradation. The system is implemented using FPGA technology and provides extended programmability to adapt the tag computation to a range of custom scheduling schemes. The hardware architecture is parallel and pipelined enabling an aggregated throughput rate of 180 million tag computations per second. The throughput performance is ideal for BWA nodes, allowing room for relatively complex computations in QoS aware adaptive scheduling. The high-level system breakdown is described and synthesis results for Xilinx FPGA technology are presented. Sakir Sezer, Emi Garcia-Palacios, Ciaran Toal, Stephen Dawson |
ICC | 1 |
| 2004 | A Reconfigurable Tag Computation Architecture for Terabit Packet SchedulingabstractSummary form only given. We present the hardware architecture and implementation of a reconfigurable tag computation circuit for terabit packet scheduling for future QoS aware core routers. The presented implementation provides a platform for a runtime configurable scheduling architecture that is able to reallocate bandwidth on the fly. The system is implemented using FPGA technology and provides extended programmability to adapt the tag computation to a range of custom packet scheduling policies. The hardware architecture is parallel and pipelined enabling an aggregated throughput rate of 175 million tag computations per second, easily out performing current QoS router solutions. The high-level system breakdown is described and synthesis results for Altera FPGA technology are presented. Sakir Sezer, Ciaran Toal, Emi Garcia-Palacios, Victoria Stewart |
IPDPS | 1 |
| 2003 | A Pipelined SoPC Architecture for 2.5 Gbps Network ProcessingabstractThis paper presents the architecture and implementation of a 2.5 Gbps Programmable Point-to-Point-Protocol Processor (P5) on a Virtex II FPGA (field programmable gate array). A 32-bit wide pipelined processor circuit is implemented for layer 2 frame processing and a Leon processor core is embedded for higher layer PPP (point-to-point protocol) control protocol processing. An AMBA bus interface is used to interlink the Leon processor to the hardware frame processing unit and presents a standard interface allowing easy retargeting to other processor platforms. Complex memory control is implemented to enable the microprocessor to handle the extreme data rate. The high-level system breakdown is described and Virtex II synthesis results are presented. Ciaran Toal, Sakir Sezer |
FCCM | 2 |
| 2003 | Custom Tag Computation Circuit for a 10Gbps SCFQ Scheduler
Brendan McAllister, Sakir Sezer, Ciaran Toal |
FPL | 2 |
| 2003 | A 32-Bit SoPC Implementation of a P5abstractThis paper details a system on a programmable chip (SoPC) implementation of a 2.5 Gbps programmable point-to-point-protocol processor (P/sup 5/) on an FPGA. 32-bit pipelined PPP receiver and transmitter dedicated packet processor circuits are implemented. The Leon processor core is embedded in the system and provides a programmable platform for PPP control protocols including LCP's and NCP's and application specific embedded software. An AMBA bus interface is used to interlink the Leon processor to the hardware packet processing unit and presents a standard interface allowing for easy retargeting to other processor platforms. Complex memory control is implemented to enable the microprocessor to handle the extreme data rate of the P/sup 5/. The high-level system breakdown is described and synthesis results for Altera FPGA technology are presented. Ciaran Toal, Sakir Sezer |
ISCC | 2 |
| 2001 | System on a FPGA Virtual Concatenation
Sakir Sezer, Eimear Stewart, Marc Carson, Claire Greenwood |
FCCM | 1 |
| 1999 | A Virtual Hardware Handler for RTR SystemsabstractThe design of a Virtual Hardware Handler for run-time reconfiguration is presented. A windows-based system that works with the VCC Hotworks board has been implemented and results are presented. Richard H. Turner, Roger F. Woods, Sakir Sezer, Jean-Paul Heron |
FCCM | 3 |
| 1999 | Quality of service analysis of a wireless ATM network access pointabstractProviding guaranteed quality of service (QoS) in wireless asynchronous transfer mode (WATM) networks is especially challenging due to the characteristically poor quality of the transmission media. The provision and prediction of QoS, which is necessary in order to satisfy the requirements of the interconnected fixed ATM network, and the many services it must support, is directly influenced by the design of the lower protocol layers such as the ATM and MAC layers. Identification of the functional requirements of these layers for supporting QoS are described and more specifically, the QoS degradation due to buffering delays. However the dynamically changing and multi-service class nature of WATM traffic also has a major effect upon the QoS. A novel modelling approach is presented whereby a call level-cell level model allows us to study the performance of different buffering techniques in the WATM access points (APs). Emi Garcia-Palacios, Alan Marshall 0001, Sakir Sezer, David Chieng |
ICC | 3 |
| 1998 | Fast Partial Reconfiguration for FCCMsabstractThe emergence of new FPGA families such as the Xilinx 6200 FPGA family and the Atmel 40000 series has been an important development in the FPGAs for Custom Computing Machines (FCCMs). These devices have number of appealing features when compared to other technologies such as the Xilinx 4000 series SRAM technology. These can be characterised as follows: faster reconfiguration (typically m/spl mu/ s or /spl mu/s), support for partial reconfiguration, dedicated microprocessor interface. An approach for run-time reconfiguration can be achieved by considering a range of functions collectively and developing the specific circuit architectures for each so that a high degree of commonality exists between them in terms of their structure, wiring and cell function. This is done by representing the functions or algorithms using Signal Flow Graphs (SFGs) and manipulating them to produce similar graphs for different functions. This basic concept can only be exploited through the development of an efficient hardware system. This revolves around the concept of virtual hardware which is integrated within the operating system and is supported by programming languages such as C and C++. The reconfigurable designs which allow partial re-configuration, are stored within a configuration data graph. Whilst this allows the configuration data to be efficiently stored, reconfiguration state graphs are used for high speed reconfiguration. The entire software hardware system for fast partial reconfiguration is illustrated. Sakir Sezer, Roger F. Woods, Jean-Paul Heron, Alan Marshall 0001 |
FCCM | 1 |