Mohsen Salehi

dblp:119/6953 · DBLP profile ↗
← Back
5ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0001-6008-2093ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 AutoPatch: Automated Generation of Hotpatches for Real-Time Embedded Devices
abstract
Real-time embedded devices like medical or industrial devices are increasingly targeted by cyber-attacks. Prompt patching is crucial to mitigate the serious consequences of such attacks on these devices. Hotpatching is an approach to apply a patch to mission-critical embedded devices without rebooting them. However, existing hotpatching approaches require developers to manually write the hotpatch for target systems, which is time-consuming and error-prone. To address these issues, we propose AutoPatch, a new hotpatching technique that automatically generates functionally equivalent hotpatches via static analysis of the official patches. AutoPatch introduces a new software triggering approach that supports diverse embedded devices, and preserves the functionality of the official patch. In contrast to prior work, AutoPatch does not rely on hardware support for triggering patches, or on executing patches in specialized virtual machines. We implemented AutoPatch using the LLVM compiler, and evaluated its efficiency, effectiveness and generality using 62 real CVEs on four embedded devices with different specifications and architectures running popular RTOSes. We found that AutoPatch can fix more than 90% of CVEs, and resolve the vulnerability successfully. The results revealed an average total delay of less than 12.7 $\mu s$ for fixing the vulnerabilities, representing a performance improvement of 50% over RapidPatch, a state-of-the-art approach. Further, our memory overhead, on average, was slightly lower than theirs (23%). Finally, AutoPatch was able to generate hotpatches for all four devices without any modifications.
Mohsen Salehi, Karthik Pattabiraman
CCS1
2022 Poster AutoPatch: Automatic Hotpatching of Real-Time Embedded Devices
abstract
The number of real-time embedded devices is increasing, especially in critical places such as industrial and medical devices. These devices are the target of many security attacks; therefore, their security must be ensured, and existing vulnerabilities must be fixed immediately. Typical update approaches require rebooting or halting the devices for an unpredictable time, and are hence not applicable for real-time embedded devices such as medical devices, which must run continuously without rebooting. Hotpatching, which patches the code without rebooting the device, has been used in this context. However, existing hotpatching methods require manual effort from programmers that is error-prone and time-consuming. Further, little attention has been paid to these techniques for real-time embedded devices. This paper proposes AutoPatch, the first automatic hotpatching approach for real-time embedded devices. AutoPatch automatically analyzes the official patch to extract its semantics using predicate abstraction, and generates a semantically equivalent patch called hotpatch. Our initial results show that AutoPatch can automatically generate hotpatches correctly based on the official patches (i.e., real-world CVEs) using program analysis. We also validate that the generated hotpatch can fix the vulnerabilities without rebooting or halting the devices.
Mohsen Salehi, Karthik Pattabiraman
CCS1
2022 A One-Dimensional Probabilistic Convolutional Neural Network for Prediction of Breast Cancer Survivability
abstract
Abstract Today, machine learning plays a major role in different branches of the healthcare industry, from prognosis and diagnosis to drug development providing a significant perspective on the medical landscape for disease prevention or treatment and the improvement of human life. Recently, the use of deep neural networks in different machine learning applications has shown a great contribution to the improvement of the accuracy of predictions. In this paper, a novel application of convolutional neural networks on medical prognosis is presented. The proposed method employs a one-dimensional convolutional neural network (1D-CNN) to predict the survivability of breast cancer patients. After further examining the network architecture, a number of 8, 14 and 24 convolutional filters were considered within three layers, respectively, followed by a max-pooling layer after the second and third layers. In addition, regarding the probabilistic nature of the survivability prediction problem, an extra layer was added to the network in order to calculate the probability of the patient survivability. To train the developed 1D-CNN machine, the SEER database as the most reliable repository of cancer survivability was used to retrieve the required training set. After a pre-processing to remove unusable records, a set of 50 000 breast cancer cases including 35 features was prepared for training the machine. Based on the results obtained in this study, the developed machine could reach an accuracy of 85.84%. This accuracy is the highest level of accuracy compared to the previous prediction methods. Furthermore, the mean squared error of the calculated probability was 0.112, which is an acceptable value of error for a probability calculation machine. The output of the developed machine can be used reliably by physicians to make decision about the most appropriate treatment strategy.
Mohsen Salehi, Jafar Razmara, Shahriar Lotfi, Farnaz Mahan
Comput. J.1
2021 PLCDefender: Improving Remote Attestation Techniques for PLCs Using Physical Model
abstract
In order to guarantee the security of industrial control system (ICS) processes, the proper functioning of the programmable logic controllers (PLCs) must be ensured. In particular, cyberattacks can manipulate the PLC control logic program and cause terrible damage that jeopardize people's life when bringing the state of the critical system into an unreliable state. Unfortunately, no remote attestation technique has yet been proposed that can validate the PLC control logic program using a physics-based model that demonstrates device behavior. In this article, we propose PLCDefender, a mitigation method that combines hybrid remote attestation technique with a physics-based model to preserve the control behavior integrity of ICS. We implemented PLCDefender and evaluated its effectiveness against a wide range of attacks on a secure water treatment facility. As our evaluation shows, we can model PLC physical behavior with accuracy as high as 98%. The evaluation results show that by determining the different threshold values, PLCDefender can accurately detect a wide range of attack scenarios on PLCs.
Mohsen Salehi, Siavash Bayat Sarmadi
IEEE Internet Things J.1
2020 A Novel Data Mining on Breast Cancer Survivability Using MLP Ensemble Learners
abstract
Abstract Breast cancer survivability has always been an important and challenging issue for researchers. Different methods have been utilized mostly based on machine learning techniques for prediction of survivability among cancer patients. The most comprehensive available database of cancer incidence is SEER in the United States, which has been frequently used for different research purposes. In this paper, a new data mining has been performed on the SEER database in order to investigate the ability of machine learning techniques for survivability prediction of breast cancer patients. To this end, the data related to breast cancer incidence have been preprocessed to remove unusable records from the dataset. In sequel, two machine learning techniques were developed based on the Multi-Layer Perceptron (MLP) learner machine including MLP stacked generalization and mixture of MLP-experts to make predictions over the database. The machines have been evaluated using K-fold cross-validation technique. The evaluation of the predictors revealed an accuracy of 84.32% and 83.86% by the mixture of MLP-experts and MLP stacked generalization methods, respectively. This indicates that the predictors can be significantly used for survivability prediction suggesting time- and cost-effective treatment for breast cancer patients.
Mohsen Salehi, Jafar Razmara, Shahriar Lotfi
Comput. J.1