EDBT 2026 Demo / reviewers in the wild / expert
Masood Mansoori
dblp:119/2631
· DBLP profile ↗
13ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-6412-2053ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Cost-Effective AIR System for Browser-Based Geolocation and Cloaking Attacks
Masood Mansoori, Junaid Haseeb, Ian Welch |
AINA (5) | 1 |
| 2025 | Feature Identification and Study of Attackers' Behaviours Using Honeypots
Junaid Haseeb, Masood Mansoori, Ian Welch |
DBSec | 2 |
| 2022 | Probabilistic modelling of deception-based security framework using markov decision process
Junaid Haseeb, Saif Ur Rehman Malik, Masood Mansoori, Ian Welch |
Comput. Secur. | 3 |
| 2022 | Corrigendum to 'Probabilistic modelling of deception-based security framework using markov decision process' [Computers & Security 115 (2022)/102599]
Junaid Haseeb, Saif Ur Rehman Malik, Masood Mansoori, Ian Welch |
Comput. Secur. | 3 |
| 2022 | Autoencoder-based feature construction for IoT attacks clustering
Junaid Haseeb, Masood Mansoori, Yuichi Hirose, Harith Al-Sahaf, Ian Welch |
Future Gener. Comput. Syst. | 2 |
| 2021 | Failure Modes and Effects Analysis (FMEA) of Honeypot-Based Cybersecurity Experiment for IoTabstractFailure Modes and Effects Analysis (FMEA) is the process of identifying potential failure modes, their causes and effects associated with a product, process or system. In this paper, we discuss the application of FMEA in the design of cybersecurity experiments using a medium interaction server honeypot in an Internet of Things (IoT) environment. Through FMEA analysis, we identify the factors affecting the outcome or contributing to the potential failures of the cybersecurity experiment. We discuss the causes of failures, their effects and how to minimise or mitigate them. Junaid Haseeb, Masood Mansoori, Ian Welch |
LCN | 2 |
| 2020 | IoT Attacks: Features Identification and ClusteringabstractThe exponential growth in the Internet of Things (IoT) market has led to the proliferation of cyber threats as millions of vulnerable IoT devices are connected to the Internet each year. Security practitioners and researchers capture attacks on IoT devices using honeypots to explore the attack process, identify the types of attacks and analyse the interaction of the attackers with IoT devices. Several studies have focused on the classification of attacks on IoT devices, however, they are limited to performing manual analysis on command data by assigning skill levels to the attackers and looking at the purpose of executing specific commands. In this paper, we report our analysis of the captured attacks on IoT devices for four months using a medium-interaction server honeypot. We extract a new feature set by analysing the attacks according to the depth of interaction by the attackers, their behaviour in the attack process and the resources they utilised to perform these attacks. We apply unsupervised learning (i.e. clustering) to automatically group captured attacks and build a model to highlight the important features that contribute to understanding the relationship between various attacks grouped in the same cluster. Junaid Haseeb, Masood Mansoori, Harith Al-Sahaf, Ian Welch |
TrustCom | 2 |
| 2020 | A Measurement Study of IoT-Based Attacks Using IoT Kill ChainabstractManufacturing limitations, configuration and maintenance flaws associated with the Internet of Things (IoT) devices have resulted in an ever-expanding attack surface. Attackers exploit IoT devices to steal private information, take part in botnets, perform Denial of Service (DoS) attacks and use their resources for the mining of cryptocurrency. In this paper, we experimentally evaluate a hypothesis that attacks on IoT devices follow the generalised Cyber Kill Chain (CKC) model. We used a medium-interaction honeypot to capture and analyse more than 30,000 attacks targeting IoT devices. We classified the steps taken by the attackers using the CKC model and extended CKC to an IoT Kill Chain (IoTKC) model. The IoTKC provides details about IoT-specific attack characteristics and attackers' activities in the exploitation of IoT devices. Junaid Haseeb, Masood Mansoori, Ian Welch |
TrustCom | 2 |
| 2020 | How do they find us? A study of geolocation tracking techniques of malicious web sites
Masood Mansoori, Ian Welch |
Comput. Secur. | 1 |
| 2019 | Geolocation Tracking and Cloaking of Malicious Web SitesabstractWeb site cloaking is a process in which varying HTML content is delivered to end users based on the attributes associated with the client agent and its interaction patterns. Cloaking poses significant challenges in detection of malicious web sites. The challenge arises due to its simplicity in implementation and its effectiveness in bypassing the detection engines. A malicious web site can deliver a benign content to a requesting client on the server side and consequently bypass detection, regardless of the detection engine used by the client. We performed large-scale real-world experiments to study cloaking techniques used by malicious web sites. We focused our research on malicious web sites using geographical information associated and derived from the IP address and language preferences of a visiting client's browser. Our study validated our hypothesis that client browser's preferred language settings and geographical information of an IP address taken in isolation, change the behaviour of a malicious web site. We also measured the effects of IP geolocation and language settings on the behaviour of malicious web sites irrespective of other factors. Masood Mansoori, Ian Welch |
LCN | 1 |
| 2016 | A Machine Learning Based Web Spam Filtering ApproachabstractWeb spam has the effect of polluting search engine results and decreasing the usefulness of search engines.Web spam can be classified according to the methods used to raise the web page's ranking by subverting web search engine's algorithms used to rank search results. The main types are: content spam, link spam and cloaking spam. There has been little or no work on automatically classifying web spam by type. This paper has two contributions, (i) we propose a Dual-Margin Multi-Class Hypersphere Support Vector Machine (DMMH- SVM) classifier approach to automatically classifying web spam by type, (ii) we introduce novel cloaking-based spam features which help our classifier model to achieve high precision and recall rate, thereby reducing the false positive rates. The effectiveness of the proposed model is justified analytically. Our experimental results demonstrated that DMMH-SVM outperforms existing algorithms with novel cloaking features. Xiaoying Gao, Ian Welch, Masood Mansoori |
AINA | 4 |
| 2016 | Empirical Analysis of Impact of HTTP Referer on Malicious Website Behaviour and DeliveryabstractReferer is a HTTP header field transmitted to a webserver, which allows the webserver to identify the origin of the request and the path taken by the visiting user to reach the final resource. Although referer is an optional field within an HTTP protocol header, many webservers use the information for logging, marketing and analytical purposes. Referer has, however, been abused in web spam cloaking and search engine optimization (SEO) attacks. The latter increases a malicious website's ranking in a search engine result with the aims of delivering spam to unwitting users. In this paper, we undertake a quantitative study to determine the effects of referer information on delivery of malicious content (excluding spam) and whether different referer values, mimicking an average user will yield dissimilar results in terms of the number and type of attacks. Our study of 500,000 suspicious websites confirms that similar to web spam, referer information is a HTTP header variable used by malicious websites to distinguish regular users from automated crawlers and security tools, and is abused to deliver malicious content accordingly. Masood Mansoori, Yuichi Hirose, Ian Welch, Kim-Kwang Raymond Choo |
AINA | 1 |
| 2016 | Application of HAZOP to the Design of Cyber Security ExperimentsabstractHazard and Operability studies have been extensively used in chemical engineering and designing safety critical systems. Its rigorous analysis based on discovering deviations and hazard makes it ideal in the study of designs and experiments with confounding variables. In this paper, HAZOP methodology is applied to a case study of network security experiment to reliably measure the IP tracking behavior of malicious websites using a low interaction client honeypot. The experiment's design involves a large number of factors and components which could potentially introduce bias in the study and result in invalid analysis. We demonstrate that HAZOP can be applied to security experiments to create a proper experimental design and properly control potential bias of confounding variables. Masood Mansoori, Ian Welch, Kim-Kwang Raymond Choo, Roy A. Maxion |
AINA | 1 |