Shankar Karuppayah

dblp:117/9405 · DBLP profile ↗
← Back
14ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0003-4801-6370ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 3 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Enhancing generalization of cross-domain intrusion detection: a heterogeneous deep stacked ensemble approach
abstract
Intrusion Detection Systems (IDS) are critical for safeguarding network infrastructures, yet the challenges of heterogeneous environments and diverse data distributions often hinder their effectiveness. This study introduces the Heterogeneous Deep Stacked Ensemble for IDS (HDSE-IDS), a novel framework designed to improve cross-domain generalization by integrating Gated Recurrent Units (GRU), Long Short-Term Memory (LSTM), Deep Neural Networks (DNN), and Multi-Layer Perceptron (MLP) models in a stacked ensemble architecture. Each base model is trained on a distinct dataset and frozen to preserve domain-specific decision boundaries, while a meta-learner aggregates their predictions to form the final decision layer. The study conducted comprehensive cross-domain evaluations using four benchmark NetFlow-based datasets: NFv2-UNSW-NB15, NFv2-BoT-IoT, NFv2-ToN-IoT, and NFv2-CIC-2018. The proposed HDSE-IDS framework achieved an average F1-score of 88.77%, representing up to a 30% improvement over recent state-of-the-art methods. These findings demonstrate the robustness and effectiveness of HDSE-IDS in diverse and dynamic network scenarios, contributing to the advancement of scalable, generalizable IDS solutions for modern cybersecurity challenges.
Muhammad Iqrar Amin, Menqing Shen, Mohamad Khairi Ishak, Selvakumar Manickam, Shankar Karuppayah
Connect. Sci.5
2025 PhishDebate: An LLM-Based Multi-Agent Framework for Phishing Website Detection
Wenhao Li 0007, Selvakumar Manickam, Yung-Wey Chong, Shankar Karuppayah
IEEE Big Data4
2024 Peer-to-peer botnets: exploring behavioural characteristics and machine/deep learning-based detection
abstract
Abstract The orientation of emerging technologies on the Internet is moving toward decentralisation. Botnets have always been one of the biggest threats to Internet security, and botmasters have adopted the robust concept of decentralisation to develop and improve peer-to-peer botnet tactics. This makes the botnets cleverer and more artful, although bots under the same botnet have symmetrical behaviour, which is what makes them detectable. However, the literature indicates that the last decade has lacked research that explores new behavioural characteristics that could be used to identify peer-to-peer botnets. For the abovementioned reasons, in this study, we propose new two methods to detect peer-to-peer botnets: first, we explored a new set of behavioural characteristics based on network traffic flow analyses that allow network administrators to more easily recognise a botnet’s presence, and second, we developed a new anomaly detection approach by adopting machine-learning and deep-learning techniques that have not yet been leveraged to detect peer-to-peer botnets using only the five-tuple static indicators as selected features. The experimental analyses revealed new and important behavioural characteristics that can be used to identify peer-to-peer botnets, whereas the experimental results for the detection approach showed a high detection accuracy of 99.99% with no false alarms. Graphical Abstract
Arkan Hammoodi Hasan Kabla, Achmad Husni Thamrin, Mohammed Anbar, Selvakumar Manickam, Shankar Karuppayah
EURASIP J. Inf. Secur.5
2024 Malware cyberattacks detection using a novel feature selection method based on a modified whale optimization algorithm
Riyadh Rahef Nuiaa, Esraa Saleh Alomari, Manar Bashar Mortatha Alkorani, Zaid Abdi Alkareem Alyasseri, Mazin Abed Mohammed, Rajesh Kumar Dhanaraj, Selvakumar Manickam, Seifedine Nimer Kadry, Mohammed Anbar, Shankar Karuppayah
Wirel. Networks10
2023 Binary Sight-Seeing: Accelerating Reverse Engineering via Point-of-Interest-Beacons
abstract
Reverse engineering is still a largely manual and very time-consuming process. To ease this process, beacons in the form of known instructions or code patterns are commonly used to guide reverse engineers in dissecting a binary. However, if done manually, identifying high-quality beacons can be very laborious. This paper introduces a novel method to automatically identify the so-called Points-of-Interests (POIs) in binaries. POIs are instructions that interact with data specified by the analyst known a priori, e.g., via sandbox analysis or expert knowledge. These POIs are then used as beacons to guide analysts to find interesting parts of the binary that interact with the specified data, e.g., the encryption routine. Compared to taint analysis, our approach offers simplicity while delivering a select few, yet high-quality beacons, thereby establishing clear focus points. Based on our proposed method, we implemented two types of prototypes. First, a prototype whose output can be loaded via custom plugins into IDA and Ghidra, i.e., two of the more popular reverse-engineering tools. We show the applicability of our method via the prototype by summarizing the insights of the analysis for the Locky and Wannacry ransomware as one of the potential application domains, i.e., malware reverse engineering. Second, we also introduced a prototype that monitors P2P botnets in a fully-automated manner by directly instrumenting the botnet malware without requiring manual reverse-engineering. We demonstrate the effectiveness of our prototype by applying it to the ZeroAccess, Sality, Nugache, and Kelihos botnets and summarize our findings in this paper. Using our approach, we effortlessly found the encryption function in the two analyzed ransomware. For P2P botnets, our monitoring prototype could enumerate the bots in all analyzed botnets, only relying on our POIs.
August See, Maximilian Gehring, Mathias Fischer 0001, Shankar Karuppayah
ACSAC4
2022 Processing of botnet tracking data under the GDPR
abstract
Botnet research is one of the many research areas affected by the coming into force of the General Data Protection Regulation (GDPR). This article aims to identify the most appropriate legal bases that would legitimise data processing in the context of botnet tracking and to give an overview of the practical implications for practitioners. First, we give a technical introduction to botnet tracking techniques and the types of processed data. Afterward, we argue that botnet tracking qualifies as ”processing of personal data” and falls under the material scope of the GDPR. We then present three scenarios where these botnet tracking techniques apply: botnet tracking research in the public interest, botnet tracking in the commercial interest and botnet tracking conducted by Internet service providers. For each scenario, we discuss the differing goals, identify the appropriate legal bases, and elaborate on the practical implications. This article concludes that the legal implications are very different for each of the three scenarios, highlighting the importance of carefully considering the legal bases before engaging in botnet tracking.
Leon Bock, Martin Fejrskov, Katerina Demetzou, Shankar Karuppayah, Max Mühlhäuser, Emmanouil Vasilomanolakis
Comput. Law Secur. Rev.4
2019 Poster: Challenges of Accurately Measuring Churn in P2P Botnets
abstract
Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.
Leon Bock, Shankar Karuppayah, Kory Fong, Max Mühlhäuser, Emmanouil Vasilomanolakis
CCS2
2018 Next Generation P2P Botnets: Monitoring Under Adverse Conditions
Leon Bock, Emmanouil Vasilomanolakis, Max Mühlhäuser, Shankar Karuppayah
RAID4
2017 SensorBuster: On Identifying Sensor Nodes in P2P Botnets
abstract
The ever-growing number of cyber attacks originating from botnets has made them one of the biggest threat to the Internet ecosystem. Especially P2P-based botnets like ZeroAccess and Sality require special attention as they have been proven to be very resilient against takedown attempts. To identify weaknesses and to prepare takedowns more carefully it is thus a necessity to monitor them by crawling and deploying sensor nodes. This in turn provokes botmasters to come up with monitoring countermeasures to protect their assets. Most existing anti-monitoring countermeasures focus mainly on the detection of crawlers and not on the detection of sensors deployed in a botnet. In this paper, we propose two sensor detection mechanisms called SensorRanker and SensorBuster. We evaluate these mechanisms in two real world botnets, Sality and ZeroAccess. Our results indicate that SensorRanker and SensorBuster are able to detect up to 17 sensors deployed in Sality and four within ZeroAccess.
Shankar Karuppayah, Leon Bock, Tim Grube, Selvakumar Manickam, Max Mühlhäuser, Mathias Fischer 0001
ARES1
2016 BoobyTrap: On autonomously detecting and characterizing crawlers in P2P botnets
abstract
The ever-growing number of cyber attacks from botnets has made them one of the biggest threats on the Internet. Thus, it is crucial to study and analyze botnets, to take them down. For this, an extensive monitoring is a pre-requisite for preparing a botnet takedown, e.g., via a sinkholing attack. However, every new monitoring mechanism developed for botnets is usually tackled by the botmasters by introducing novel antimonitoring countermeasures. In this paper, we anticipate these countermeasures by proposing a set of lightweight techniques for detecting the presence of crawlers in P2P botnets, called BoobyTrap. For that, we exploit botnet-specific protocol and design constraints. We evaluate the performance of our BoobyTrap mechanism on two real-world botnets: Sality and ZeroAccess. Our results indicate that we can distinguish many crawlers from benign bots. In fact, we discovered close to 10 crawler nodes within our observation period in the Sality botnet and around 120 in the ZeroAccess botnet. In addition, we also describe the observable characteristics of the detected crawlers and suggest crawler improvements for enabling monitoring in the presence of the BoobyTrap mechanism.
Shankar Karuppayah, Emmanouil Vasilomanolakis, Steffen Haas, Max Mühlhäuser, Mathias Fischer 0001
ICC1
2015 Zeus Milker: Circumventing the P2P Zeus Neighbor List Restriction Mechanism
abstract
The emerging trend of highly-resilient P2P botnets poses a huge security threat to our modern society. Carefully designed countermeasures as applied in sophisticated P2P botnets such as P2P Zeus impede botnet monitoring and successive takedown. These countermeasures reduce the accuracy of the monitored data, such that an exact reconstruction of the botnet's topology is hard to obtain efficiently. However, an accurate topology snapshot, revealing particularly the identities of all bots, is crucial to execute effective botnet takedown operations. With the goal of obtaining the required snapshot in an efficient manner, we provide a detailed description and analysis of the P2P Zeus neighbor list restriction mechanism. As our main contribution, we propose ZeusMilker, a mechanism for circumventing the existing anti-monitoring countermeasures of P2P Zeus. In contrast to existing approaches, our mechanism deterministically reveals the complete neighbor lists of bots and hence can efficiently provide a reliable topology snapshot of P2P Zeus. We evaluated ZeusMilker on a real-world dataset and found that it outperforms state-of-the-art techniques for botnet monitoring with regard to the number of queries needed to retrieve a bot's complete neighbor list. Furthermore, ZeusMilker is provably optimal in retrieving the complete neighbor list, requiring at most 2n queries for an n-elemental list. Moreover, we also evaluated how the performance of ZeusMilker is impacted by various protocol changes designed to undermine its provable performance bounds.
Shankar Karuppayah, Stefanie Roos, Christian Rossow, Max Mühlhäuser, Mathias Fischer 0001
ICDCS1
2015 A honeypot-driven cyber incident monitor: lessons learned and steps ahead
abstract
In recent years, the amount and the sophistication of cyber attacks has increased significantly. This creates a plethora of challenges from a security perspective. First, for the efficient monitoring of a network, the generated alerts need to be presented and summarized in a meaningful manner. Second, additional analytics are required to identify sophisticated and correlated attacks. In particular, the detection of correlated attacks requires collaboration between different monitoring points. Cyber incident monitors are platforms utilized for supporting the tasks of network administrators and provide an initial step towards coping with the aforementioned challenges.
Emmanouil Vasilomanolakis, Shankar Karuppayah, Panayotis Kikiras, Max Mühlhäuser
SIN2
2014 On advanced monitoring in resilient and unstructured P2P botnets
abstract
Botnets are a serious threat to Internet-based services and end users. The recent paradigm shift from centralized to more sophisticated Peer-to-Peer (P2P)-based botnets introduces new challenges for security researchers. Centralized botnets can be easily monitored, and once their command and control server is identified, easily be taken down. However, P2P-based botnets are much more resilient against such attempts. To make it worse, botnets like P2P Zeus include additional countermeasures to make monitoring and crawling more difficult for the defenders. In this paper, we discuss in detail the problems of P2P botnet monitoring. As our main contribution, we introduce the Less Invasive Crawling Algorithm (LICA) for efficiently crawling unstructured P2P botnets and utilize only local information. We compare the performance of LICA with other known crawling methods such as Depth-first and Breadth-first search. This is achieved by simulating these methods on not only a real-world botnet dataset, but also on an unstructured P2P file sharing network dataset. Our analysis results indicate that LICA significantly outperforms the other known crawling methods.
Shankar Karuppayah, Mathias Fischer 0001, Christian Rossow, Max Mühlhäuser
ICC1
2014 HosTaGe: a Mobile Honeypot for Collaborative Defense
abstract
The continuous growth of the number of cyber attacks along with the massive increase of mobile devices creates a highly heterogeneous landscape in terms of security challenges. We argue that in order for security researchers to cope with both the massive amount and the complexity of attacks, a more pro-active approach has to be taken into account. In addition, distributed attacks that are carried out by interconnected attackers require a collaborative defense. Diverging from traditional security defenses, honeypots are systems whose value lies on in being attacked and compromised. In this paper, we extend the idea of HosTaGe, i.e., a low interaction honeypot for mobile devices. Our system is specifically designed in a user-centric manner and runs out-of-the-box in the Android operating system. We present the design rational and discuss the different attack surfaces that HosTaGe is able to handle. The main contribution of this paper is the introduction of the collaborative capabilities of HosTaGe.
Emmanouil Vasilomanolakis, Shankar Karuppayah, Max Mühlhäuser, Mathias Fischer 0001
SIN2