A. S. M. Kayes

dblp:116/7137 · DBLP profile ↗
← Back
35ranked-venue papers
11as first author
18since 2021 · last 2026
0000-0002-2421-2214ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 1 first-author · 8 since 2021Security and privacy · 9 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 5 · 4 first-author · 1 since 2021Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A systematic literature survey of machine learning approaches to cyber data breach detection: Current research issues and future directions
abstract
Although several machine learning driven solutions are deemed to be effective at detecting data breaches, the recent proliferation in data breach incidents resulting from cyber attacks on computer networks demands an updated, thorough analysis of Machine Learning (ML) based data breach countermeasures to identify research gaps and guide future studies. In view of this, this study employs a systematic approach and draws insight from 89 research articles to classify machine learning based data breach countermeasures using eight criteria namely learning tasks, learning classifiers, datasets, feature engineering methods, multimodal approaches, pre-training approaches and performance. In classifying the studies, we: (a) propose a taxonomy of feature extraction and representation to classify studies using ten sub-criteria, (b) classify multimodal machine learning approaches used in the studies into three fusion sub-criteria: namely early fusion, intermediate fusion and late fusion, (c) show a comparison of studies based on pre-training techniques employed such as pre-text objective, learning model and data used in pre-training, (d) classify the datasets used in the study evaluation into two categories: real dataset and simulated dataset and (e) evaluate studies by detection performance and effectiveness against data breaches on unknown and obfuscated network traffic. To aid the literature identification, we analyse forty recent incidents and obtain prevalent cyber attack vectors of data breaches, which we present as the general workflow for data breaches due to cyber attacks. Finally, we highlight the research issues associated with existing ML-based data breach countermeasures and recommend future research directions.
Paul Ntim Yeboah, A. S. M. Kayes, Wenny Rahayu, Eric Pardede, Syed Mahbub
Comput. Networks2
2026 A framework for phishing and web attack detection using ensemble features of self-supervised pre-trained models
abstract
Cyber-attacks on industrial applications, specifically, phishing and web attacks are the most common data breach vectors and, as such, have attracted significant research attention. To mitigate these types of attacks, many countermeasures based on machine learning (ML) have been proposed. Although ML-based countermeasures are reported to yield satisfactory detection performance on phishing and web attacks, they often require massive amounts of manually labelled email and web request data to build these countermeasures. The manual generation of labels, however, can be laborious, error-prone and infeasible to scale. To cope with the evolution of web attacks and phishing emails, methods which exploit the vast volumes of unlabelled email texts and web request data should be adopted. Recent studies have primarily employed sequential models such as BERT, to learn semantic contextual features from unlabelled email and HTTP request text. In this study, we take a step further by extracting complementary features from unlabelled email and web request data represented in two-dimensional structures. Our method applies computer vision-based transformations to these structured representations and employing a self-supervise learning approach, we pre-train a convolutional neural network model to recognise these transformations, enabling the model to learn syntactic structural features from unlabelled data. We then adopt concatenation as our ensemble strategy to combine contextual and syntactic features, yielding robust representation of email and HTTP request text, which we leverage in a downstream fully connected neural network model for phishing and web attack detection. Extensive experiments conducted on three phishing datasets including Nazario, Enron and Subhadeep’s email corpus, as well as the benchmark SR-BH web attack dataset show that, the proposed method outperforms baseline sequential models developed in this work, which rely solely on contextual representations for detecting phishing and web attacks.
Paul Ntim Yeboah, A. S. M. Kayes, Wenny Rahayu, Eric Pardede, Syed Mahbub
J. Netw. Comput. Appl.2
2025 PRIV-HFL: Privacy-Preserving and Robust Federated Learning for Heterogeneous Clients Against Data Reconstruction Attacks
abstract
Federated Learning (FL) is a machine learning paradigm that allows multiple local clients to collaboratively train a global model by sharing their model parameters instead of private data, thereby mitigating privacy leakage. However, recent studies have shown that gradient-based Data Reconstruction Attack (DRA) can still expose private information by exploiting model parameters from local clients. Existing privacy-preserving FL strategies provide some defense against these attacks, but at the cost of significantly reduced model accuracy. Moreover, the issue of client heterogeneity, particularly in Non-Identical and Independent Distributions (Non-IID) clients, further exacerbates these FL methods, resulting in drifted global models, slower convergence, and decreased performance. This study aims to address the two main challenges of FL: Non-IID data and client privacy through DRA. To this end, it leverages the lagrangian duality approach and incorporates a generator model to enable Knowledge Distillation (KD) among clients. By facilitating improved local model performance through inter-client knowledge transfer, the proposed method aims to simultaneously address the practical challenges commonly encountered by FL systems. Our study demonstrates a remarkable improvement in model accuracy, with KD boosting it by up to $15 \%$ on CIFAR-10 and MNIST classification tasks in Non-IID client settings. Furthermore, we propose an aggregation algorithm that inherently preserves client data privacy during the training phase, offering resilience against DRA.
Mohammadreza Najafi, Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu
RAID4
2025 Securing cross-domain data access with decentralized attribute-based access control
abstract
In attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare.
Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari
Ad Hoc Networks4
2025 Social network botnet attack mitigation model for cloud
abstract
Online Social Network (OSN) botnet attacks pose a growing threat to the cloud environment and reduce the services’ availability and reliability for users by launching distributed denial of service (DDoS) attacks on crucial servers in the cloud. These attacks involve the deployment of sophisticated botnets that exploit the interconnected nature of social networks to identify targets, exploit vulnerabilities, and launch attacks. The prevalence and impact of these botnet-driven attacks have recently been studied. Although the detection of these botnet attacks is still a challenging process, it remains crucial to gain a comprehensive understanding of and evaluate the best defense strategies against botnet attacks. This evaluation can be further utilized to formulate effective defense plans to mitigate the impact of such botnet attacks. In this paper, we first investigate the properties of OSN botnet attack stages that eventually lead to launching DDoS attacks toward a cloud system. Then, we formalize a defensive model using a sequential game model to analyze both the attacker’s and defenders’ best equilibrium strategies for the proposed botnet attack scenario. Moreover, we formulate optimal strategies for the defender against various attack strategies. Our experiments reveal the best defense strategies against various attack rates to maintain cloud functionality. Finally, we discuss possible countermeasures for these OSN botnet threats.
Hooman Alavizadeh, Ahmad Salehi S., A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon
Comput. Networks3
2025 Physical layer security techniques for grant-free massive Machine-Type Communications in 5G and beyond: A survey, challenges, and future directions
abstract
The future of smart cities, industrial automation, and connected vehicles is heavily reliant on advanced communication technologies. These technologies, particularly massive Machine-Type Communication (mMTC), are the backbone of the many connected devices required for these applications. Grant -free access in 5G and beyond, while enhancing transmission efficiency by eliminating the need for permission requests, also introduces significant security risks. These risks, such as unauthorised access, data interception, and interference due to the absence of centralised control, are of paramount importance. Physical layer security (PLS) techniques, with their ability to exploit the unique properties of wireless channels to bolster communication security, offer a promising solution. This paper provides a comprehensive review of PLS techniques for securing grant-free mMTC, comparing different approaches and exploring the challenges of their integration. Our findings lay the groundwork for future research and the practical implementation of advanced security solutions in grant-free mMTC, a development that will also enhance the security of advanced 5G and 6G networks.
Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes
Comput. Networks4
2025 A comprehensive literature review of cyber threats and vulnerabilities in IoT-driven satellite networks: Research challenges and future directions
abstract
Satellite communications play an increasingly important role in a number of different industries with the rise of the Internet of Things (IoT). IoT-driven satellite (‘IoT-Satellite’ in short) networks have a number of vulnerabilities that can make them targets of common cyber attacks such as jamming and spoofing. These attacks can potentially be highly disruptive to the services they support. This paper presents a comprehensive survey of cyber threats and vulnerabilities with a focus on application areas in IoT-Satellite networks. Cyber threats include spoofing, jamming, malware and denial-of-service (DoS) attacks. Vulnerabilities in IoT-Driven satellite include deficits in encryption, access control and vulnerabilities in commercial off-the-shelf (COTS) parts. Subsequently, proposed in-depth solutions are also discussed in this paper. Proposed solutions include zero-trust security, software-defined networking, dynamic and context-based access control, blockchain and artificial intelligence (AI) approaches. While there are limited surveys specifically addressing IoT-driven satellite networks, we identify relevant studies and compare them with our work. Based on these findings we describe open research issues and potential future areas of research. The study suggests that further research is needed to develop a security framework for IoT-driven satellite networks, addressing prevalent cyber attacks and mitigating strategies.
Tatyana Stojnic, A. S. M. Kayes, Wenny Rahayu, Mohammad Jabed Morshed Chowdhury
Comput. Networks2
2025 Robust Multiuser Physical Layer Security for Grant-Free mMTC in Beyond 5G/6G Networks
abstract
Industry 5.0 introduces human-machine collaboration and resilient automation, demanding secure, low-latency connectivity for ultra-dense Industrial IoT (IIoT). Grant-free massive machine-type communications (mMTC) supports such connectivity but faces challenges including dense multiuser access, passive eavesdropping, and imperfect channel state information (CSI), which undermine physical layer security (PLS). This paper proposes a robust and low-complexity multiuser PLS scheme tailored for grant-free mMTC under CSI uncertainty. The scheme leverages dynamic user clustering based on spatial correlation and real-time interference to enable scalable, interference-aware beamforming. Furthermore, a joint optimisation of receive beamforming and adaptive artificial noise injection is performed, and enhanced by a regularised minimum mean square error (MMSE) framework to mitigate bounded CSI errors. Simulation results show that the scheme consistently outperforms existing benchmarks across secrecy capacity, bit error rate, and secrecy outage probability under different channel models, together with analyses of SOP sensitivity to CSI error and scalability to dense users/eavesdroppers, confirms its robustness, efficiency, and applicability to large-scale, secure IIoT communications in beyond 5G/6G networks aligned with Industry 5.0 requirements.
Uchenna P. Enwereonye, Ahmad Salehi S., Hooman Alavizadeh, A. S. M. Kayes
IEEE Internet Things J.4
2025 Safeguarding Individuals and Organizations From Privacy Breaches: A Comprehensive Review of Problem Domains, Solution Strategies, and Prospective Research Directions
abstract
Privacy breaches have become increasingly prevalent, exposing individuals to significant risks. These breaches can have far-reaching consequences, including identity theft and life-threatening situations. Several studies have analyzed data and privacy breaches and presented detection or prevention techniques to combat these breaches. However, because the number and type of breaches have significantly increased, these studies have become less relevant or outdated. Previous research on data and privacy breaches compared the techniques and results of various studies. However, none comprehensively analyzed the type of information and the level and severity of compromise that occurred after such breaches. In this survey, we examine the fundamental concepts of privacy and security and define the security incidents and data/privacy breaches. We propose a set of criteria to evaluate the published studies on privacy breaches. We thoroughly investigate the problem domains and security-related concerns considering six recent breach cases in Australia, elucidating the critical challenges and issues associated with privacy breaches. We comprehensively review and outline the trends and severity of security incidents and data/privacy breaches from 2020 to 2024. Additionally, we review the current state-of-the-art countermeasures to safeguard against these breaches. Finally, we identify an open research direction to develop an artificial intelligence (AI)-powered security framework. This framework aims to analyze cyber threats, characterize attackers’ behaviors, distinguish between legitimate and illegitimate privacy policies, and restrict access to individuals’ information. Overall, this survey will help organizations to reassess and update their security and privacy measures.
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Ahmad Salehi S., Hooman Alavizadeh
IEEE Internet Things J.1
2025 Approximation-based energy-efficient cyber-secured image classification framework
abstract
Approximation-based energy-efficient cyber-secured image classification framework
Mohamed Abdur Rahman 0004, Salma Sultana Tunny, A. S. M. Kayes, Peng Cheng 0002, Aminul Huq, M. S. Rana 0001, Md. Rashidul Islam, Animesh Sarkar Tusher
Signal Process. Image Commun.3
2024 IoTPredictor: A security framework for predicting IoT device behaviours and detecting malicious devices against cyber attacks
Rudri Kalaria, A. S. M. Kayes, Wenny Rahayu, Eric Pardede, Ahmad Salehi S.
Comput. Secur.2
2023 Applying staged event-driven access control to combat ransomware
abstract
The advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware.
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.2
2022 Spam Email Categorization with NLP and Using Federated Deep Learning
Ikram Ul Haq, Paul Black, Iqbal Gondal, Joarder Kamruzzaman, Paul A. Watters, A. S. M. Kayes
ADMA (2)6
2022 A deep learning model for mining and detecting causally related events in tweets
abstract
Abstract Nowadays, public gatherings and social events are an integral part of a modern city life. To run such events seamlessly, it requires real time mining and monitoring of causally related events so that the management can make informed decisions and take appropriate actions. The automatic detection of event causality from short text such as tweets could be useful for event management in this context. However, detecting event causality from tweets is a challenging task. Tweets are short, unstructured, and often written in highly informal language which lacks enough contextual information to detect causality. The existing approaches apply different techniques including hand‐crafted linguistic rules and machine learning models. However, none of the approaches tackle the issue related to the lack of contextual information. In this paper, we detect event causality in tweets by applying a context word extension technique and a deep causal event detection model. The context word extension technique is driven by background knowledge extracted from one million news articles. Our model achieves 79.35% recall and 67.28% f1‐score, which are 17.39% and 2.33% improvements to the state‐of‐the‐art approach.
Humayun Kayesh, Md. Saiful Islam 0003, Junhu Wang, A. S. M. Kayes, Paul A. Watters
Concurr. Comput. Pract. Exp.4
2021 A Secure Mutual authentication approach to fog computing environment
Rudri Kalaria, A. S. M. Kayes, Wenny Rahayu, Eric Pardede
Comput. Secur.2
2021 Dynamic user-centric access control for detection of ransomware attacks
Timothy R. McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, Paul A. Watters
Comput. Secur.2
2021 Enforcing situation-aware access control to build malware-resilient file systems
Timothy R. McIntosh, Paul A. Watters, A. S. M. Kayes, Alex Ng, Yi-Ping Phoebe Chen
Future Gener. Comput. Syst.3
2021 Detection of Harassment Type of Cyberbullying: A Dictionary of Approach Words and Its Impact
abstract
The purpose of this paper is to analyse the effects of predatory approach words in the detection of cyberbullying and to propose a mechanism of generating a dictionary of such approach words. The research incorporates analysis of chat logs from convicted felons, to generate a dictionary of sexual approach words. By analysing data across multiple social networks, the study demonstrates the usefulness of such a dictionary of approach words in detection of online predatory behaviour through machine learning algorithms. It also shows the difference between the nature of contents across specific social network platforms. The proposed solution to detect cyberbullying and the domain of approach words are scalable to fit real-life social media, which can have a positive impact on the overall health of online social networks. Different types of cyberbullying have different characteristics. However, existing cyberbullying detection works are not targeted towards any of these specific types. This research is tailored to focus on sexual harassment type of cyberbullying and proposes a novel dictionary of approach words. Since cyberbullying is a growing threat to the mental health and intellectual development of adolescents in the society, models targeted towards the detection of specific type of online bullying or predation should be encouraged among social network researchers.
Syed Mahbub, Eric Pardede, A. S. M. Kayes
Secur. Commun. Networks3
2020 Answering Binary Causal Questions: A Transfer Learning Based Approach
abstract
Causal question answering is a task of answering causality related questions. The questions are referred to as binary causal questions when the questions e.g., "Could X cause Y?" can be answered by yes/no answers. Answer to the previous question is yes if X is a cause of Y, and otherwise no. The binary causal question answering systems can be used to validate causal relationships, which can be particularly useful for decision making. For example, it could be useful for the tourism authorities to know the answer to the question "Could growing social tension cause reduction in tourism?". We aim to automatically answer such binary causal questions by developing a machine learning model. However, training a machine learning model to detect causal relationships is challenging due to the lack of large and high quality labeled datasets. In this paper, we propose a transfer learning-based approach which fine-tunes pretrained transformer based language models on a small dataset of cause-effect pairs to detect causality and answer binary causal questions. The proposed approach achieves performance comparable to a number of benchmark approaches on five benchmark test datasets extracted by human experts conditioned on the same small training dataset.
Humayun Kayesh, Md. Saiful Islam 0003, Junhu Wang, Shikha Anirban, A. S. M. Kayes, Paul A. Watters
IJCNN5
2020 A Framework for Measuring IoT Data Quality Based on Freshness Metrics
abstract
Over the last decade, the proliferation of the Internet of Things (IoT) has produced an overwhelming flow of continuous streaming data. A massive amount of IoT data will be generated in the future. Therefore, it is necessary to create more sophisticated frameworks to measure IoT data quality, considering relevant attributes such as the freshness, reliability and trustworthiness of IoT data. Existing data freshness models and frameworks mostly depend on the timestamp. However, the frequency of IoT data (e.g., data generated by sensors which is measured per millisecond or minute) needs to be considered, that is, IoT data can change frequently. We introduce a new model for measuring IoT data freshness. In our model, we define unreliable IoT data and discard them while considering fresh data. We introduce a formal approach to IoT data freshness including the underlying concepts and definitions. Using this formal approach, we propose an algorithm for the numerical calculation of the freshness attributes. We conduct several sets of experiments and demonstrate the feasibility of the proposed framework by quantifying the performance of the freshness measurement algorithm. We also demonstrate the capability of the framework to capture freshly generated IoT data through a software prototype and several case studies. Finally, we provide a roadmap for future research considering other IoT data quality attributes, such as reliability and trustworthiness.
Fatma Mohammed, A. S. M. Kayes, Eric Pardede, Wenny Rahayu
TrustCom2
2020 CalBehav: A Machine Learning-Based Personalized Calendar Behavioral Model Using Time-Series Smartphone Data
abstract
Abstract The electronic calendar is a valuable resource nowadays for managing our daily life appointments or schedules, also known as events, ranging from professional to highly personal. Researchers have studied various types of calendar events to predict smartphone user behavior for incoming mobile communications. However, these studies typically do not take into account behavioral variations between individuals. In the real world, smartphone users can differ widely from each other in how they respond to incoming communications during their scheduled events. Moreover, an individual user may respond the incoming communications differently in different contexts subject to what type of event is scheduled in her personal calendar. Thus, a static calendar-based behavioral model for individual smartphone users does not necessarily reflect their behavior to the incoming communications. In this paper, we present a machine learning based context-aware model that is personalized and dynamically identifies individual’s dominant behavior for their scheduled events using logged time-series smartphone data, and shortly name as ‘CalBehav’. The experimental results based on real datasets from calendar and phone logs, show that this data-driven personalized model is more effective for intelligently managing the incoming mobile communications compared to existing calendar-based approaches.
Iqbal H. Sarker, Alan W. Colman, Jun Han 0004, A. S. M. Kayes, Paul A. Watters
Comput. J.4
2020 Achieving security scalability and flexibility using Fog-Based Context-Aware Access Control
A. S. M. Kayes, Wenny Rahayu, Paul A. Watters, Mamoun Alazab, Tharam S. Dillon, Elizabeth Chang 0001
Future Gener. Comput. Syst.1
2020 ABC-RuleMiner: User behavioral rule-based machine learning method for context-aware intelligent services
Iqbal H. Sarker, A. S. M. Kayes
J. Netw. Comput. Appl.2
2019 ISDI: A New Window-Based Framework for Integrating IoT Streaming Data from Multiple Sources
Doan Quang Tu, A. S. M. Kayes, Wenny Rahayu, Kinh Nguyen
AINA2
2019 Trust Modeling for Blockchain-Based Wearable Data Market
abstract
Wearable devices continuously produce physiological data that can provide individuals critical information about their daily routine or fitness level in combination with their smartphones without requiring manual calculations or maintaining log-books. Real-time participant-generated data can enable large scale observational studies of health conditions, provide better insights into medical conditions of individuals and streamline clinical trial processes in medical research. However, privacy is a major concern for health data and there can be a lack of trust among different parties in the health data collection process. In addition, individuals often do not have sufficient control over the sharing of their data from the wearable devices. The lack of control, trust and privacy are key barriers to research participants being prepared to share their personal data from wearable devices. In this work, we propose a trust model to overcome the trust deficit among different parties. Then, we present a reference system architecture, rooted on the developed trust model, that provides incentive for individuals to securely share their health data through a data marketplace. By encouraging individuals to share their real-time health data, researchers will have access to large data sets at low cost.
Mohammad Jabed Morshed Chowdhury, Md Sadek Ferdous, Kamanashis Biswas, Niaz Chowdhury, A. S. M. Kayes, Paul A. Watters, Alex Ng
CloudCom5
2019 A Policy Model and Framework for Context-Aware Access Control to Information Resources†
abstract
In today’s dynamic ICT environments, the ability to control users’ access to information resources and services has become ever important. On the one hand, it should provide flexibility to adapt to the users’ changing needs, while on the other hand, it should not be compromised. The user is often faced with different contexts and environments that may change the user’s information needs. To allow for this, it is essential to incorporate the dynamically changing context information into the access control policies to reflect different contexts and environments through the use of a new context-aware access control (CAAC) approach with both dynamic associations of user-role and role-permission capabilities. Our proposed CAAC framework differs from the existing access control frameworks in that it supports context-sensitive access control to information resources and dynamically re-evaluates the access control decisions when there are dynamic changes to the context. It uses the dynamic context information to specify the user-role and role-permission assignment policies. We first present a formal policy model for our framework, specifying CAAC policies. Using this model, we then introduce a policy ontology for modeling CAAC policies and a policy enforcement architecture which supports access to resources according to the dynamically changing context information. In addition, we demonstrate the feasibility of our framework by considering (i) the completeness, correctness and consistency of the ontology concepts through application to healthcare scenarios and (ii) the performance and usability testing of the framework when using desktop and mobile-based prototypes.
A. S. M. Kayes, Jun Han 0004, Wenny Rahayu, Tharam S. Dillon, Md. Saiful Islam 0003, Alan W. Colman
Comput. J.1
2019 Context-aware access control with imprecise context characterization for cloud-based data resources
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Elizabeth Chang 0001, Jun Han 0004
Future Gener. Comput. Syst.1
2018 An Ontology-Based Approach to Dynamic Contextual Role for Pervasive Access Control
abstract
In role-based access control, roles are mostly organized in static hierarchies and users are authorized to play such roles in order to exercise the organizational functions. However, some of these roles cannot be organized in the same way in static hierarchies as the authorizations granted to such roles are strictly related to the dynamically changing contextual conditions (e.g., health profile information). Users need to satisfy these conditions in order to exercise the functions of such dynamic contextual roles. While several research works have been done in dynamic activation of static roles, no extensive research has been undertaken in the area of dynamic specification of contextual roles. This article makes a significant research contribution to the dynamic contextual role modeling and activation. We introduce both formal and ontology-based approaches in order to model the dynamic contextual roles and specify the context-aware access control policies by activating such dynamic roles at runtime. These contextual roles are equally important because of the demands of large-scale (pervasive) environments to control context-sensitive access to resources at different granularity levels with low processing overheads. We develop a software prototype to demonstrate the feasibility of our proposal and provide a walkthrough of the whole mechanism. Experimental results demonstrate the satisfactory performance of our proposed approach compared to our previous approach.
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon
AINA1
2018 Dynamic Transitions of States for Context-Sensitive Access Control Decision
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Syed Mahbub, Eric Pardede, Elizabeth Chang 0001
WISE (1)1
2015 OntCAAC: An Ontology-Based Approach to Context-Aware Access Control for Software Services
abstract
In modern communication environments, the ability to provide access control to information resources and software services in a context-aware manner is crucial. By leveraging the dynamically changing context information, we can achieve context-specific control over access to such resources and services, better satisfying the security and privacy requirements of the stakeholders. Existing access control approaches are highly domain-specific and they control access to services depending on the specific types of context information (e.g. location and time). One of the key limitations of the existing approaches is the lack of systematic capture and use of context information in making context-aware access control decisions. Therefore, new access control approaches are required for such dynamic and context-aware environments. Existing approaches define context as the state/situation of the entities. To achieve context-aware access control, in this paper we not only consider the states of the entities but also consider the states of the relationships between entities. We introduce a generic framework, OntCAAC (Ontology-based Context-Aware Access Control), that adopts semantic technologies in modelling dynamic contexts and corresponding access control policies. It includes a context model specific to access control, capturing the relevant context information. The context model also incorporates the ability to infer high-level implicit context information according to operator-defined rules. Using the context model, the policy model of the OntCAAC framework provides support for specifying and enforcing context-aware access control policies. We have developed a prototype implementation of the framework and have demonstrated its use in making context-aware access control decisions through two case studies from different domains. Experimental results show the feasibility of our approach and quantify the performance overhead of providing context-aware access control for software services.
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
Comput. J.1
2015 An ontological framework for situation-aware access control of software services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
Inf. Syst.1
2014 PO-SAAC: A Purpose-Oriented Situation-Aware Access Control Framework for Software Services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
CAiSE1
2014 A Survey on Mining Program-Graph Features for Malware Analysis
Md. Saiful Islam 0003, Md. Rafiqul Islam 0001, A. S. M. Kayes, Chengfei Liu, Irfan Altas
SecureComm (2)3
2013 An Ontology-Based Approach to Context-Aware Access Control for Software Services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
WISE (1)1
2012 ICAF: A Context-Aware Framework for Access Control
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
ACISP1