EDBT 2026 Demo / reviewers in the wild / expert
Saad Khan 0001
dblp:125/1839-1 · also Saad Ullah Khan 0001
· DBLP profile ↗
11ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-8613-8200ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Graph-based detection of multi-step attacks using graph convolutional networksabstractMulti-step attacks, including advanced persistent threats (APT), distributed denial of service (DDoS) and botnets, are still among the most sophisticated threats that modern organisations are experiencing today. Most traditional methods of detecting these threats have difficulties identifying unknown types of events from unknown sources. In this study, we introduce a reproducible GCN-based event-log correlation framework for Multi-step attack detection. In this work, we replicated GC-PTransE for APT reasoning (Phase-1), then extended GC-PTransE into practical lightweight variants for DDoS and Botnet detection (Phase-3) using a common PyG graph interface. Our models demonstrated significant improvements over all categories of attacks. Using the CICIDS2017 (DDoS) dataset, our model achieved 98% accuracy, 100% precision, and 94% recall. With the CTU-13 (Botnet) dataset, GETrans++ achieved 98% accuracy, 100% precision, and 47% recall. The 72% APT-relevance hit rate from our Phase 1 replication demonstrates that GCN can be deployed, providing good efficiency. Finally, by using neighbourhood batching, we avoided the need to store entire graphs in memory, thereby allowing for deployments on commodity CPU/GPU architectures. Limitations of this study included the class imbalance in enterprise logs (Phase 2) and the lack of heterogeneous operational datasets, both of which were identified as areas for future study. Syed Usman Shaukat, Saad Khan 0001, Simon Parkinson |
J. Inf. Secur. Appl. | 2 |
| 2025 | A survey of deep learning for face presentation attack detectionabstractFace anti-spoofing detection (FASD) has become a crucial technology due to the alarming advancements in presentation attacks (PAs). As more novel PAs with realistic generative capabilities emerge, improved biometric security solutions are needed to address these evolving threats. In early and foundational work, FASD techniques focused mainly on handcrafted features that were unreliable due to their limited representation capacity. In the recent decade, with the advancements in deep learning and its capabilities for image processing tasks and the emergence of large datasets, improvements in the performance of detecting PAs have been achieved. However, as research progresses rapidly, there is an absence of a comprehensive analysis of detection methods to understand the strengths and weaknesses of different types of approaches. Although various approaches utilise sensors in addition to RGB cameras, in this paper, we focus specifically on RGB camera-based methods and provide a comprehensive review of deep learning-based FASDs, including generalised models developed to date. In addition, the datasets are presented, along with the evaluation protocols and metrics. • This article provides an extensive analysis of deep learning-based approaches in the spatial domain, along with a focused review of frequency domain generalisation methods. • This paper covers the application of GANs for FASD, together with semi-supervised and self-supervised learning methods. Therefore, it provides the reader with state-of-the-art methods for different application scenarios (e.g., unseen domain generalisation and unknown attack detection). • The taxonomy of deep learning-based FASD methods using RGB cameras provides readers with an overview of modern approaches. • The strengths and weaknesses of existing models have also been explored and summarised, providing an overview of their capabilities and limitations. Mohammadreza Sheikh Fathollahi, Simon Parkinson, Richard Hill, Saad Khan 0001 |
Neurocomputing | 4 |
| 2024 | Exploring perceptions of decision-makers and specialists in defensive machine learning cybersecurity applications: The need for a standardised approachabstractMachine learning (ML) utilisation has achieved a vast global impact. This is evident in the cybersecurity sector, where ML has wide-ranging applications, such as identifying and blocking threats, uncovering unusual software and user behaviour, and many others. However, the increase in successful cyberattacks demonstrates that the effectiveness of ML in cybersecurity applications can be questioned. Although the attacks may be new, ML is often adopted due to its ability to handle diverse and often unforeseen situations – a capability that is not possible using traditional rule-based security mechanisms. As both the rate of attacks and adoption of ML solutions are increasing, there is a need to determine whether ML-based security solutions are meeting the expectations of businesses and whether businesses are genuinely aware of the ML capabilities and limitations. Moreover, current literature shows a significant variation in how ML solutions are evaluated in cybersecurity applications, which might result in a poor understanding of ML capabilities. This paper explores the common perceptions and observations of decision-makers and specialists using ML for cybersecurity regarding its capabilities, implementation, evaluation, and communication. A semi-structured interview is conducted with individuals in various managerial positions to perform this investigation. The finding of this study reveals a pressing need for a standard to manifest ML capabilities. As significant variation in the understanding of Machine Learning Cyber Security (MLCS) capabilities is observed, a standard could help better communicate MLCS capabilities. It is observed that external influences heavily impact ML adoption decisions, potentially leading to misinterpretation of ML capabilities. Omar Alshaikh, Simon Parkinson, Saad Khan 0001 |
Comput. Secur. | 3 |
| 2023 | Context-based irregular activity detection in event logs for forensic investigations: An itemset mining approachabstractEvent logs are a powerful source of digital evidence as they contain detailed information about activities performed on a computer. Forensic investigation of the event logs is a challenging and time-consuming task due to their large volume and continuous generation. A significant amount of time, effort, and knowledge is required to interpret their contents, discovering irregular events that are potentially pertinent to the investigation. As the number of digital investigations increases, so too must resources available to investigators. This requires new techniques to make the process easier and faster, reducing the burden on human investigators as well as being resource efficient. In this paper, a novel solution is presented to examine event logs and automatically identify irregular activities during forensic analysis. The proposed solution utilises a rare itemset mining approach to establish relationships among event entries, based on their contents. Following on, identified event relationships are ordered based on their temporal order to represent the timeline or sequence of activity. The solution is also capable of prioritising identified activities by calculating their degree of irregularity. The empirical analysis is performed on 15 live machines, and the results are discussed in terms of accuracy and performance metrics. Saad Khan 0001, Simon Parkinson, Craig Murphy |
Expert Syst. Appl. | 1 |
| 2022 | Identifying high-risk over-entitlement in access control policies using fuzzy logicabstractAbstract Analysing access control policies is an essential process for ensuring over-prescribed permissions are identified and removed. This is a time-consuming and knowledge-intensive process, largely because there is a wealth of policy information that needs to be manually examined. Furthermore, there is no standard definition of what constitutes an over-entitled permission within an organisation’s access control policy, making it not possible to develop automated rule-based approaches. It is often the case that over-entitled permissions are subjective to an organisation’s role-based structure, where access is be divided and managed based on different employee needs. In this context, an irregular permission could be one where an employee has frequently changed roles, thus accumulating a wide-ranging set of permissions. There is no one size fits all approach to identifying permissions where an employee is receiving more permission than is necessary, and it is necessary to examine them in the context of the organisation to establish their individual risk. Risk is not a binary measure and, in this work, an approach is built using Fuzzy Logic to determine an overall risk rating, which can then be used to make a more informed decision as to whether a user is over-entitled and presenting risk to the organisation. This requires the exploratory use of establishing resource sensitivity and user trust as measures to determine a risk rating. The paper presents a generic solution, which has been implemented to perform experimental analysis on Microsoft’s New Technology File System to show how this works in practice. A simulation using expert knowledge for comparison is then performed to demonstrate how effective it is at helping the user identify potential irregular permissions. Simon Parkinson, Saad Khan 0001 |
Cybersecur. | 2 |
| 2021 | OCEAN: A Non-Conventional Parameter Free Clustering Algorithm Using Relative Densities of CategoriesabstractIn this paper, we propose a fully autonomous density-based clustering algorithm named ‘Ocean’, which is inspired by the oceanic landscape and phenomena that occur in it. Ocean is an improvement over conventional algorithms regarding both distance metric and the clustering mechanism. Ocean defines the distance between two categories as the difference in the relative densities of categories. Unlike existing approaches, Ocean neither assigns the same distance to all pairs of categories, nor assigns arbitrary weights to matches and mismatches between categories that can lead to clustering errors. Ocean uses density ratios of adjacent regions in multidimensional space to detect the edges of the clusters. Ocean is robust against clusters of identical patterns. Unlike conventional approaches, Ocean neither makes any assumption regarding the data distribution within clusters, nor requires tuning of free parameters. Empirical evaluations demonstrate improved performance of Ocean over existing approaches. Iffat Gheyas, Simon Parkinson, Saad Khan 0001 |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2019 | Creeper: a tool for detecting permission creep in file system access controlsabstractAccess control mechanisms are widely used in multi-user IT systems where it is necessary to restrict access to computing resources. This is certainly true of file systems whereby information needs to be protected against unintended access. User permissions often evolve over time, and changes are often made in an ad hoc manner and do not follow any rigorous process. This is largely due to the fact that the structure of the implemented permissions are often determined by experts during initial system configuration and documentation is rarely created. Furthermore, permissions are often not audited due to the volume of information, the requirement of expert knowledge, and the time required to perform manual analysis. This paper presents a novel, unsupervised technique whereby a statistical analysis technique is developed and applied to detect instances of permission creep. The system (herein refereed to as Creeper) has initially been developed for Microsoft systems; however, it is easily extensible and can be applied to other access control systems. Experimental analysis has demonstrated good performance and applicability on synthetic file system permissions with an average accuracy of 96%. Empirical analysis is subsequently performed on five real-world systems where an average accuracy of 98% is established. Simon Parkinson, Saad Khan 0001, James Bray, Daiyaan Shreef |
Cybersecur. | 2 |
| 2019 | Discovering and utilising expert knowledge from security event logs
Saad Khan 0001, Simon Parkinson |
J. Inf. Secur. Appl. | 1 |
| 2018 | Eliciting and utilising knowledge for security event log analysis: An association rule mining and automated planning approach
Saad Khan 0001, Simon Parkinson |
Expert Syst. Appl. | 1 |
| 2018 | Identifying irregularities in security event logs through an object-based Chi-squared test of independence
Simon Parkinson, Saad Khan 0001 |
J. Inf. Secur. Appl. | 2 |
| 2017 | Causal Connections Mining Within Security Event LogsabstractPerforming both security vulnerability assessment and configuration processes are heavily reliant on expert knowledge. This requirement often results in many systems being left insecure due to a lack of analysis expertise and access to specialist resources. It has long been known that a system's event log provides historical information depicting potential security threats, as well as recording configuration activities. In this paper, a novel technique is developed that can process security event logs on a computer that has been assessed and configured by a security professional, and autonomously establish causality amongst event log entries to learn performed configuration tasks. This extracted knowledge can then be exploited by non-professionals to plan steps that can improve the security of a previously unseen system. Saad Khan 0001, Simon Parkinson |
K-CAP | 1 |