Monowar Hasan

dblp:130/9116 · DBLP profile ↗
← Back
32ranked-venue papers
10as first author
21since 2021 · last 2026
0000-0002-2657-0402ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 9 · 2 first-author · 7 since 2021Computer networks · 8 · 4 first-author · 2 since 2021Systems, architecture and hardware · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Work-in-Progress: Queue Assignment and Parameter Selection in TSN Credit-Based Shapers
Tamim Ahmed, Monowar Hasan
RTAS2
2026 Weakly-Hard Real-Time Flow Scheduling in Time-Sensitive Networks
abstract
Time-Sensitive Networking (TSN) offers deterministic transmission through mechanisms such as the Time-Aware Shaper (TAS), but existing scheduling approaches assume hard real-time semantics where all packets must meet deadlines, leading to inefficiency under high utilization or overload. In contrast, numerous cyber-physical systems operate under “weakly-hard” timing models that permit bounded deadline violations. This paper introduces a design-time scheduling framework that integrates weakly-hard requirements into TSN by categorizing packets as mandatory or optional and synthesizing Gate Control Lists (GCLs) that guarantee timing constraints for all mandatory packets while maximizing admission of optional traffic. We propose both a computationally efficient heuristic algorithm (named Lazy Search) and an Integer Linear Programming (ILP) formulation for GCL construction. We further systematically analyze the trade-off between serving optional packets through a dedicated priority queue versus multiplexing them within their nominal traffic class. Through synthetic workload evaluation and hardware validation on a commodity TSN switch, we demonstrate that the proposed framework substantially improves optional packet service rates without compromising timing guarantees of mandatory packets.
Tamim Ahmed, Zain Alabedin Haj Hammadeh, Daniel Lüdtke, Monowar Hasan
RTAS4
2026 A Comparative Evaluation of Imputation Models for Agricultural Weather Networks
abstract
High-resolution weather data are essential for irrigation scheduling, frost protection, and pest and disease risk modeling. However, weather stations frequently experience multi-hour to multi-day outages, leading to substantial downtime for weather-driven decision-making. To mitigate this, stakeholders often rely on ''imputation'' models to reconstruct missing data. Despite the existence of many statistical and machine-learning models, it remains unclear which imputation methods are most suitable for operational agricultural settings. This paper evaluates twelve imputation methods---statistical models, classical machine learning algorithms, and deep neural networks---to identify the most suitable model for agricultural applications. We tested the models using data from five meteorological towers (three in Jena, Germany, and two in Sunnyside, Washington, USA). We perform a thorough performance-engineering study: in addition to accuracy, we evaluate runtime, inference throughput, peak memory usage, GPU usage, energy consumption, and monetary cost. Our findings are surprising: among all complex and advanced (neural network) models, a properly tuned Random Forest (RF) model consistently outperforms them across multiple evaluation categories (e.g., accuracy, latency, throughput, and cost). Specifically, an RF achieves competitive error with no GPU dependencies, modest memory usage, and substantially lower energy expenditure than deep learning baselines. Our research shows that classical machine learning models remain a compelling choice for scalable, cost-aware weather data imputation in agricultural decision-support systems.
Awanish Khanal, Monowar Hasan
ICPE2
2026 On Evading Randomization-Based Defense in Hierarchical Real-Time Systems
abstract
Security for real-time systems is increasingly important with the growth of connected real-time systems in safety-critical domains such as automotive, medical, and avionics. A crucial aspect of securing such systems is to understand the attacks that the current techniques cannot effectively safeguard against. Especially relevant are vulnerabilities of real-time systems arising from their rigid temporal guarantees and attacks that exploit such vulnerabilities. Randomization-based defense techniques can reduce side-channel inference, but such techniques are limited due to the strict timing bounds of real-time systems. In this article, we design and analyze NosyNeighbor , an inter-partition side-channel attack that exploits the timing guarantees of real-time systems to infer the timing parameters of a safety-critical task in a hierarchical system. Using an adaptive technique, NosyNeighbor can improve its inference over time and evade randomization-based defense. Experimental results show that NosyNeighbor can infer victim task execution with a precision of roughly 73% under normal system load, and with a recall of about 35% using multiple malicious tasks across partitions. NosyNeighbor is also effective under the common attack model with two malicious tasks in the system, with a precision of 64%.
Vijay Banerjee, Sena Hounsinou, Yanyan Zhuang, Monowar Hasan, Gedare Bloom
ACM Trans. Cyber Phys. Syst.4
2025 Weather-Driven Agricultural Decision-Making Under Imperfect Conditions
Tamim Ahmed, Monowar Hasan
SIGSPATIAL/GIS2
2025 Time-Aware Packet Forwarding in Programmable Data Planes
abstract
Networks in many safety-critical systems like avionics, automotive, and industrial plants have strict end-to-end delay requirements to be met for correct system operation. Existing software-defined real-time networks do not support data plane programmability provided by recent protocol-independent switch architectures such as P4. Our research enables time-aware flow forwarding in P4-enabled software-defined time-critical networks. In this paper, we introduce time-aware flow scheduling for P4-enabled SDN architectures. We study two scheduling policies: the first one prioritizes flows based on slack (i.e., how much time is left to reach the destination), and the second one uses finish time as a priority metric, which is determined from its data rate requirements. Both approaches were implemented and tested in the P 4 software stack. We find that the slack-based forwarding scheme performs better in retaining real-time requirements. Our publicly released scheduler implementations will assist network engineers in adapting programmable switches to safety-critical applications that demand precise timing guarantees.
Yuqun Song, Monowar Hasan
ISORC2
2025 Work-in-Progress: Real-Time Deep Neural Inference on Resource-Constrained Edge Devices
abstract
Deep neural networks (DNNs) are now central to perception and control in time-critical cyber-physical systems, yet many mid- and low-tier edge platforms (e.g., single-board computers without GPUs and most microcontrollers) cannot host full models or meet real-time constraints. Cooperative inference by offloading workload across nearby devices improves feasibility, but most existing schemes do not analyze end-to-end timing and are thus not suitable for real-time applications. This Work-in-Progress paper studies deadline-aware distributed DNN inference with an asynchronous execution semantics: a device proceeds as soon as its required partial outputs are available, without global synchronization. We develop a time-aware optimization model that minimizes response time subject to deadline constraints. We also outline our ongoing research efforts and future extensions of the proposed work.
Md Tasnim Farhan Fatin, Monowar Hasan
RTSS2
2025 Enhancing Security Through Task Migration in Software-Defined Vehicles
abstract
The growing trend of software-controlled operation, control, and development of modern vehicles has led to the emergence of the software-defined vehicle (SDV) design paradigm. SDVs contain increasing software components and, like other cyber-physical systems, are more susceptible to cyber-attacks. However, patching vulnerabilities in these systems may take time, exposing them to cyber threats. To limit the effect of an attack, one solution is tomigratecritical tasks co-located on the same electronic control unit (ECU) with a compromised component to another ECU. However, existing migration solutions, often designed for fault tolerance, introduce overhead and ignore security parameters. This paper introduces ShiftGuard,a security-aware, distributed task migration mechanismfor SDVs. We explore various design decisions that may affect the performance of ShiftGuard. We implemented and demonstrated the efficacy of ShiftGuard on an automotive platform running the controller area network (CAN) protocol and found that the end-to-end latency of the task migration decision is less than 17 ms for a system with 15 tasks hosted in 3 ECUs. We also performed extensive design-space exploration using a custom-developed simulator. Our experiments with synthetic workloads show that any task migration request has a 76%-100% success rate. Additionally, we demonstrate ShiftGuard’s scalability for large networks of up to 70 ECUs, making it highly suitable for automotive systems with SDV capabilities.
Mohammad Hamad, Zain Alabedin Haj Hammadeh, Davide Alessi, Monowar Hasan, Mert D. Pesé, Daniel Lüdtke, Sebastian Steinhorst
IEEE Internet Things J.4
2025 Optimizing Confidential Deep Learning for Real-Time Systems
abstract
Deep neural networks (DNNs) are increasingly used in time-critical, learning-enabled cyber-physical applications such as autonomous driving and robotics. Despite the growing use of various deep learning models, protecting DNN inference from adversarial threats while preserving model privacy and confidentiality remains a key concern for resource and timing-constrained autonomous cyber-physical systems. One potential solution, primarily used in general-purpose systems, is the execution of the DNN workloads within trusted enclaves available on current off-the-shelf processors. However, ensuring temporal guarantees when running DNN inference within these enclaves poses significant challenges in real-time applications due to (a) the large computational and memory demands of DNN models and (b) the overhead introduced by frequent context switches between “normal” and “trusted” execution modes. This article introduces new time-aware schemes for dynamic (EDF) and fixed-priority (RM) schedulers to preserve the confidentiality of DNN tasks by running them inside trusted enclaves. We first propose a technique that slices each DNN layer and runs them sequentially in the enclave. However, due to the extra context switch overheads of individual layer slices, we further introduce a novel layer fusion technique. Layer fusion improves real-time guarantees by grouping multiple layers of DNN workload from multiple tasks, thus allowing them to fit and run concurrently within the enclaves while maintaining timing constraints. We implemented and tested our ideas on the Raspberry Pi platform running a DNN-enabled trusted OS (OP-TEE with DarkNet-TZ) and three DNN architectures (AlexNet-squeezed, Tiny Darknet, and YOLOv3-tiny). Compared to the layer-wise partitioning approach, layer fusion can (a) schedule up to 3× more tasksets for EDF and 5× for RM and (b) reduce context switches by up to 11.12× for EDF and by up to 11.06× for RM.
Mohammad Fakhruddin Babar, Monowar Hasan
ACM Trans. Cyber Phys. Syst.2
2025 RESCUE: A Reconfigurable Scheduling Framework for Securing Multi-Core Real-Time Systems
abstract
Modern real-time systems face increasing vulnerabilities to cyber-attacks, particularly those that use multi-core chips, where safety-critical and non-safety-critical tasks execute concurrently. Existing solutions for multi-core systems often lack either determinism or cost-efficiency. This article introduces an offline analysis technique that computes all feasible schedules for real-time tasks running on multi-core platforms. Our proposed technique isolates compromised tasks while ensuring a fail-operational system and supports low-cost, reconfigurable scheduling. The analytical models presented in this article guarantee the hard real-time constraints of safety-critical tasks while allowing bounded deadline misses for some non-safety-critical tasks during an attack to enhance security. We name our scheme RESCUE. We conduct a comprehensive design-space exploration and evaluate its real-world efficacy using a UAV autopilot system case study deployed on a quad-core platform (Raspberry Pi). Results show that the proposed scheme introduces minimal recovery overhead, measured in microseconds on a Raspberry Pi, and achieves 100% coverage in reconfiguration responses to compromised tasks in synthetic test cases.
Zain Alabedin Haj Hammadeh, Monowar Hasan, Mohammad Hamad
ACM Trans. Cyber Phys. Syst.2
2024 DeepTrust^RT: Confidential Deep Neural Inference Meets Real-Time!
abstract
Deep Neural Networks (DNNs) are becoming common in "learning-enabled" time-critical applications such as autonomous driving and robotics. One approach to protect DNN inference from adversarial actions and preserve model privacy/confidentiality is to execute them within trusted enclaves available in modern processors. However, running DNN inference inside limited-capacity enclaves while ensuring timing guarantees is challenging due to (a) large size of DNN workloads and (b) extra switching between "normal" and "trusted" execution modes. This paper introduces new time-aware scheduling schemes - DeepTrust^RT - to securely execute deep neural inferences for learning-enabled real-time systems. We first propose a variant of EDF (called DeepTrust^RT-LW) that slices each DNN layer and runs them sequentially in the enclave. However, due to extra context switch overheads of individual layer slices, we further introduce a novel layer fusion technique (named DeepTrust^RT-FUSION). Our proposed scheme provides hard real-time guarantees by fusing multiple layers of DNN workload from multiple tasks; thus allowing them to fit and run concurrently within the enclaves while maintaining real-time guarantees. We implemented and tested DeepTrust^RT ideas on the Raspberry Pi platform running OP-TEE+DarkNet-TZ DNN APIs and three DNN workloads (AlexNet-squeezed, Tiny Darknet, YOLOv3-tiny). Compared to the layer-wise partitioning approach (DeepTrust^RT-LW), DeepTrust^RT-FUSION can schedule up to 3x more tasksets and reduce context switches by up to 11.12x. We further demonstrate the efficacy of DeepTrust^RT using a flight controller (ArduPilot) case study and find that DeepTrust^RT-FUSION retains real-time guarantees where DeepTrust^RT-LW becomes unschedulable.
Mohammad Fakhruddin Babar, Monowar Hasan
ECRTS2
2024 A New Covert Channel in Fixed-Priority Real-Time Multiframe Tasks
abstract
This study investigates the presence of illicit information flows in fixed-priority multiframe real-time systems. We identify an algorithmic covert channel (called FrameLeaker) that enables a low-priority task to deduce the execution patterns (frames) of a high-priority task. We show that the response time of a targeted low-priority task (receiver) can be used to extract the execution behavior of a high-priority task (sender). We further introduce a metric called "inference precision ratio" to evaluate the efficacy of the received information.
Mohammad Fakhruddin Babar, Monowar Hasan
ISORC2
2024 Securing Real-Time Systems using Schedule Reconfiguration
abstract
Modern real-time systems are susceptible to cyber-attacks. The growing adoption of multi-core platforms, where safety and non-safety critical tasks coexist, further introduces new security challenges. Existing solutions suffer from either a lack of determinism or excessive cost. This paper addresses these shortcomings and proposes an offline analysis to compute all feasible schedules for real-time tasks running on a multi-core platform, isolating compromised tasks while guaranteeing a fail-operational system and low-cost reconfigurable scheduling. Our experimental results using a UAV autopilot system on a quad-core platform (Raspberry Pi) demonstrate that the proposed scheme incurs run-time recovery overhead at the level of microseconds. Also, the reconfiguration process covers up to 100% of all possible responses for compromised tasks in the synthetic test cases.
Zain Alabedin Haj Hammadeh, Monowar Hasan, Mohammad Hamad
ISORC2
2024 Processing Natural Language on Embedded Devices: How Well Do Modern Models Perform?
abstract
Voice-controlled systems are becoming ubiquitous in many IoT-specific applications such as home/industrial automation, automotive infotainment, and healthcare. While cloud-based voice services (\eg Alexa, Siri) can leverage high-performance computing servers, some use cases (\eg robotics, automotive infotainment) may require to execute the natural language processing (NLP) tasks offline, often on resource-constrained embedded devices. Transformer-based language models such as BERT and its variants are primarily developed with compute-heavy servers in mind. Despite the great performance of BERT models across various NLP tasks, their large size and numerous parameters pose substantial obstacles to offline computation on embedded systems. Lighter replacement of such language models (\eg DistilBERT and TinyBERT) often sacrifice accuracy, particularly for complex NLP tasks. Until now, it is still unclear \ca whether the state-of-the-art language models, \viz BERT and its variants are deployable on embedded systems with a limited processor, memory, and battery power and \cb if they do, what are the "right'' set of configurations and parameters to choose for a given NLP task. This paper presents aperformance study of transformer language models under different hardware configurations and accuracy requirements and derives empirical observations about these resource/accuracy trade-offs. In particular, we study how the most commonly used BERT-based language models (\viz BERT, RoBERTa, DistilBERT, and TinyBERT) perform on embedded systems. We tested them on \textitfour off-the-shelf embedded platforms (\hardware) with 2 GB and 4 GB memory (\ie a total of \textiteight hardware configurations) and \textitfour datasets (\ie HuRIC, GoEmotion, CoNLL, WNUT17) running various NLP tasks. Our study finds that executing complex NLP tasks (such as "sentiment'' classification) on embedded systems isfeasible even without any GPUs (\eg \rpi with 2 GB of RAM). We release our implementations for community use. Our findings can help designers understand the deployability and performance of transformer language models, especially those based on BERT architectures.
Souvika Sarkar, Mohammad Fakhruddin Babar, Md. Mahadi Hassan, Monowar Hasan, Shubhra Kanti Karmaker Santu
ICPE4
2023 You Can't Always Check What You Wanted: : Selective Checking and Trusted Execution to Prevent False Actuations in Real-Time Internet-of-Things
abstract
Modern Internet-of-Things devices are vulnerable to attacks targeting outgoing actuation commands that modify their physical behaviors. We present a “selective checking” mechanism that uses game-theoretic modeling to identify the suitable subset of commands to be checked in order to deter an adversary. This mechanism is coupled with a “delay-aware” trusted execution environment to ensure that only verified actuation commands are ever sent to the physical system, thus maintaining the safety and integrity of the system. Our proposed selective checking and trusted execution (SCATE) framework is implemented on an off-the-shelf ARM platform running embedded Linux and tested on four realistic IoT-specific cyber-physical systems (a ground rover, a flight controller, a robotic arm and an automated syringe pump).
Monowar Hasan, Sibin Mohan
ISORC1
2023 System Auditing for Real-Time Systems
abstract
System auditing is an essential tool for detecting malicious events and conducting forensic analysis. Although used extensively on general-purpose systems, auditing frameworks have not been designed with consideration for the unique constraints and properties of Real-Time Systems (RTS). System auditing could provide tremendous benefits for security-critical RTS. However, a naive deployment of auditing on RTS could violate the temporal requirements of the system while also rendering auditing incomplete and ineffectual. To ensure effective auditing that meets the computational needs of recording complete audit information while adhering to the temporal requirements of the RTS, it is essential to carefully integrate auditing into the real-time (RT) schedule. This work adapts the Linux Audit framework for use in RT Linux by leveraging the common properties of such systems, such as special purpose and predictability.Ellipsis, an efficient system for auditing RTS, is devised that learns the expected benign behaviors of the system and generates succinct descriptions of the expected activity. Evaluations using varied RT applications show thatEllipsisreduces the volume of audit records generated during benign activity by up to 97.55% while recording detailed logs for suspicious activities. Empirical analyses establish that the auditing infrastructure adheres to the properties of predictability and isolation that are important to RTS. Furthermore, the schedulability of RT tasksets under audit is comprehensively analyzed to enable the safe integration of auditing in RT task schedules.
Ayoosh Bansal, Anant Kandikuppa, Monowar Hasan, Chien-Ying Chen, Adam Bates 0001, Sibin Mohan
ACM Trans. Priv. Secur.3
2022 Towards Efficient Auditing for Real-Time Systems
Ayoosh Bansal, Anant Kandikuppa, Chien-Ying Chen, Monowar Hasan, Adam Bates 0001, Sibin Mohan
ESORICS (3)4
2022 Work in Progress: Exploring Schedule-Based Side-Channels in TrustZone-Enabled Real-Time Systems
abstract
Our research demonstrates the existence of side-channel information leaks in TrustZone-enabled real-time systems. Our algorithm can infer the critical tasks’ arrival times and pinpoint when the system switches between regular and secure execution modes. By precisely obtaining such timing information, an adversary could infer the task execution patterns inside the secure system — thus putting the system’s safety, security, and integrity at risk. Considering that secure enclaves such as TrustZone are used for executing security-critical functionalities, our findings will help designers be aware of side-channel vulnerabilities and assist them in designing better, leakage-proof systems.
Mohamed Anis Aguida, Monowar Hasan
RTAS2
2022 Beyond Just Safety: Delay-aware Security Monitoring for Real-time Control Systems
abstract
Modern embedded real-time systems (RTS) are increasingly facing more security threats than the past. A simplistic straightforward integration of security mechanisms might not be able to guarantee thesafetyand predictability of such systems. In this article, we focus on integrating security mechanisms into RTS (especiallylegacyRTS). We introduceContego-C, an analytical model to integrate security tasks into RTS that will allow system designers to improve the security posture without affecting temporal and control constraints of the existing real-time control tasks. We also define ametric(named tightness of periodic monitoring) to measure the effectiveness of such integration. We demonstrate our ideas using a proof-of-concept implementation on an ARM-based rover platform and show that Contego-C can improve security without degrading control performance.
Monowar Hasan, Sibin Mohan, Rakesh Bobba, Rodolfo Pellizzoni
ACM Trans. Cyber Phys. Syst.1
2021 Safety Critical Networks using Commodity SDNs
abstract
Safety-critical networks often have stringent real-time requirements; they must also be resilient to failures. In this paper, we propose the RealFlow framework that uses commodity software-defined networks (SDNs) to realize networks with end-to-end timing guarantees, while also: (a) increasing resiliency against link/switch failures and (b) increasing network utilization. The use of SDNs in this space also improves the management capabilities of the system due to the global visibility into the network. RealFlow is implemented as a northbound SDN controller application compatible with standard OpenFlow protocols with little to no runtime overheads. We demonstrate feasibility on a real hardware testbed (Pica8 SDN switches+Raspberry Pi endhosts) and a practical avionics case study. Our evaluations show that RealFlow can accommodate 63% more network flows with safety-critical guarantees when compared to current designs and up to 18% when link resiliency (via backup paths) is also considered.
Ashish Kashinath, Monowar Hasan, Rakesh Kumar 0016, Sibin Mohan, Rakesh Bobba, Smruti Padhy
INFOCOM2
2021 Work-in-Progress: Enabling Secure Boot for Real-Time Restart-Based Cyber-Physical Systems
abstract
Several cyber-physical systems use real-time restart-based embedded systems with the Simplex architecture to provide safety guarantees against system faults. Some approaches have been developed to protect such systems from security violations too, but none of these approaches can prevent an adversary from modifying the operating system or application code to execute an attack that persists even after a reboot. In this work, we present a secure boot mechanism to restore real-time restart-based embedded systems into a secure computing environment after every restart. We analyze the delay introduced by the proposed security feature and present preliminary results to demonstrate the viability of our approach using an open-source bootloader and real-time operating system.
Sena Hounsinou, Vijay Banerjee, Chunhao Peng, Monowar Hasan, Gedare Bloom
RTSS4
2020 Period Adaptation for Continuous Security Monitoring in Multicore Real-Time Systems
abstract
We propose HYDRA-C, a design-time evaluation framework for integrating monitoring mechanisms in multicore real-time systems (RTS). Our goal is to ensure that security (or other monitoring) mechanisms execute in a "continuous" manner - i.e., as often as possible, across cores. This is to ensure that any such mechanisms run with few interruptions, if any. HYDRA-C is intended to allow designers of RTS to integrate monitoring mechanisms without perturbing existing timing properties or execution orders. We demonstrate the framework using a proofof-concept implementation with intrusion detection mechanisms as security tasks. We develop and use both, (a) a custom intrusion detection system (IDS) as well as (b) Tripwire - an open source data integrity checking tool. We compare the performance of HYDRA-C with a state-of-the-art multicore RT security integration approach and find that our method does not impact the schedulability and, on average, can detect intrusions 19.05% faster without impacting the performance of RT tasks.
Monowar Hasan, Sibin Mohan, Rodolfo Pellizzoni, Rakesh Bobba
DATE1
2019 Preserving Physical Safety Under Cyber Attacks
abstract
Physical plants that form the core of the cyber-physical systems (CPSs) often have stringent safety requirements and, recent attacks have shown that cyber intrusions can cause damage to these plant. In this paper, we demonstrate how to ensure the safety of the physical plant even when the platform is compromised. We leverage the fact that due to physical inertia, an adversary cannot destabilize the plant (even with complete control over the software) instantaneously. In fact, it often takes finite (even considerable time). This paper provides the analytical framework that utilizes this property to compute safe operational windows in run-time during which the safety of the plant is guaranteed. To ensure the correctness of the computations in runtime, we discuss two approaches to ensure the integrity of these computations in an untrusted environment: 1) full platform-wide restarts coupled with a root-of-trust timer and 2) utilizing trusted execution environment features available in hardware. We demonstrate our approach using two realistic systems-a 3 degree-of-freedom helicopter and a simulated warehouse temperature management unit and show that our system is robust against multiple emulated attacks-essentially the attackers are not able to compromise the safety of the CPS.
Fardin Abdi Taghi Abad, Chien-Ying Chen, Monowar Hasan, Songran Liu, Sibin Mohan, Marco Caccamo
IEEE Internet Things J.3
2018 A design-space exploration for allocating security tasks in multicore real-time systems
abstract
The increased capabilities of modern real-time systems (RTS) expose them to various security threats. Recently, frameworks that integrate security tasks without perturbing the real-time tasks have been proposed, but they only target single core systems. However, modern RTS are migrating towards multicore platforms. This makes the problem of integrating security mechanisms more complex, as designers now have multiple choices for where to allocate the security tasks. In this paper we propose HYDRA, a design space exploration algorithm that finds an allocation of security tasks for multicore RTS using the concept of opportunistic execution. HYDRA allows security tasks to operate with existing real-time tasks without perturbing system parameters or normal execution patterns, while still meeting the desired monitoring frequency for intrusion detection. Our evaluation uses a representative real-time control system (along with synthetic task sets for a broader exploration) to illustrate the efficacy of HYDRA.
Monowar Hasan, Sibin Mohan, Rodolfo Pellizzoni, Rakesh Bobba
DATE1
2017 Contego: An Adaptive Framework for Integrating Security Tasks in Real-Time Systems
abstract
Embedded real-time systems (RTS) are pervasive. Many modern RTS are exposed to unknown security flaws, and threats to RTS are growing in both number and sophistication. However, until recently, cyber-security considerations were an afterthought in the design of such systems. Any security mechanisms integrated into RTS must (a) co-exist with the real-time tasks in the system and (b) operate without impacting the timing and safety constraints of the control logic. We introduce Contego, an approach to integrating security tasks into RTS without affecting temporal requirements. Contego is specifically designed for legacy systems, viz., the real-time control systems in which major alterations of the system parameters for constituent tasks is not always feasible. Contego combines the concept of opportunistic execution with hierarchical scheduling to maintain compatibility with legacy systems while still providing flexibility by allowing security tasks to operate in different modes. We also define a metric to measure the effectiveness of such integration. We evaluate Contego using synthetic workloads as well as with an implementation on a realistic embedded platform (an open-source ARM CPU running real-time Linux).
Monowar Hasan, Sibin Mohan, Rodolfo Pellizzoni, Rakesh Bobba
ECRTS1
2017 End-to-End Network Delay Guarantees for Real-Time Systems Using SDN
abstract
Real-time systems (RTS) require end-to-end delay guarantees for the delivery of network packets. In this paper, we propose a framework to reduce the management and integration overheads for such real-time (RT) network flows by leveraging the capabilities of software-defined networking (SDN) - capabilities that include global visibility and management of the network. Given the specifications of flows that must meet hard real-time requirements, our framework synthesizes paths through the network. To guarantee that these flows meet both, their bandwidth and end-to-end timing requirements, our framework solves a multi-constraint optimization problem using a heuristic algorithm. We use exhaustive emulations and experiments on hardware switches to demonstrate our techniques and feasibility of our approach. As a result of this work, SDNs become “delay-aware” and thus can be adapted for use in safety-critical and other delay-sensitive applications.
Rakesh Kumar 0016, Monowar Hasan, Smruti Padhy, Konstantin Evchenko, Lavanya Piramanayagam, Sibin Mohan, Rakesh Bobba
RTSS2
2016 Exploring Opportunistic Execution for Integrating Security into Legacy Hard Real-Time Systems
abstract
Due to physical isolation as well as use of proprietary hardware and protocols, traditional real-time systems (RTS) were considered to be invulnerable to security breaches and external attacks. This assumption is being challenged by recent attacks that highlight vulnerabilities in RTS. Besides, a straightforward integration of security mechanisms might compromise the safety and predictability guarantees of such systems. In this paper, we focus on integrating security mechanisms into RTS (especially legacy RTS) and define a metric to measure the effectiveness of such integration. We combine opportunistic execution with hierarchical scheduling to maintain compatibility with legacy systems while still providing flexibility. The proposed approach is shown to increase the security posture of RTS without impacting their temporal (and hence, safety) constraints.
Monowar Hasan, Sibin Mohan, Rakesh Bobba, Rodolfo Pellizzoni
RTSS1
2015 Distributed resource allocation in D2D-enabled multi-tier cellular networks: An auction approach
abstract
Future wireless networks are expected to be highly heterogeneous with the co-existence of macrocells and small cells and they will also provide support for device-to-device (D2D) communication. In such muti-tier heterogeneous systems, centralized radio resource allocation and interference management schemes will not be scalable. In this work, we propose an auction-based distributed solution to allocate radio resources in a muti-tier heterogeneous network. We provide the bound of achievable data rate and show that the complexity of the proposed scheme is linear with the number of transmitter nodes and the available resources. The signaling issues (e.g., information exchange over control channels) for the proposed distributed solution is also discussed. Numerical results show the effectiveness of the proposed solution in comparison with an optimal centralized resource allocation scheme.
Monowar Hasan, Ekram Hossain 0001
ICC1
2015 Distributed Resource Allocation for Relay-Aided Device-to-Device Communication Under Channel Uncertainties: A Stable Matching Approach
abstract
Wireless device-to-device (D2D) communication underlaying cellular network is a promising concept to improve user experience and resource utilization. Unlike traditional D2D communication, where two mobile devices in the proximity establish a direct local link bypassing the base station, in this work, we focus on relay-aided D2D communication. Relay-aided transmission could enhance the performance of D2D communication when D2D user equipments (UEs) are far apart from each other and/or the quality of D2D link is not good enough for direct communication. Considering the uncertainties in wireless links, we model and analyze the performance of a relay-aided D2D communication network, where the relay nodes serve both the cellular and D2D users. In particular, we formulate the radio resource allocation problem in a two-hop network to guarantee the data rate of the UEs while protecting other receiving nodes from interference. Utilizing time sharing strategy, we provide a centralized solution under bounded channel uncertainty. With a view to reducing the computational burden at relay nodes, we propose a distributed solution approach using stable matching to allocate radio resources in an efficient and computationally inexpensive way. Numerical results show that the performance of the proposed method is close to the centralized optimal solution and there is a distance margin beyond which relaying of D2D traffic improves network performance.
Monowar Hasan, Ekram Hossain 0001
IEEE Trans. Commun.1
2015 Distributed Uplink Power Control for Multi-Cell Cognitive Radio Networks
abstract
We present a distributed power control algorithm to address the uplink interference management problem in cognitive radio networks where the underlaying secondary users (SUs) share the same licensed spectrum with the primary users (PUs) in multi-cell environments. Since the PUs have a higher priority of channel access compared to the SUs, minimal number of SUs should be gradually removed, subject to the constraint that all primary users are supported with their target signal-to-interference-plus-noise ratios (SINRs), which is assumed feasible. In our proposed algorithm, each primary user rigidly tracks its target-SINR by employing the conventional target-SINR tracking power control algorithm (TPC). Each transmitting SU employs the TPC as long as the total received power at the primary receiver is below a given threshold; otherwise, it decreases its transmit power in proportion to the ratio between the given threshold and the total received power at the primary receiver, which is referred to as the total received-power-temperature. We show that our proposed distributed power-update function has at least one fixed-point. We also show that our proposed algorithm not only improves the number of supported SUs but also guarantees that all primary users are supported with their (feasible) target-SINRs. Finally, we also propose an enhanced power control algorithm that achieves zero-outage for PUs and a better outage ratio for SUs. To this end, we provide a robust power control method that considers the uncertainties in channel gains.
Mehdi Rasti, Monowar Hasan, Long Bao Le, Ekram Hossain 0001
IEEE Trans. Commun.2
2014 Distributed Resource Allocation for Relay-Aided Device-to-Device Communication: A Message Passing Approach
abstract
Device-to-device (D2D) communication underlaying cellular wireless networks is a promising concept to improve user experience and resource utilization by allowing direct transmission between two cellular devices. In this paper, performance of network-assisted D2D communication is investigated where D2D traffic is carried through relay nodes. Considering a multi-user and multi-relay network, we propose a distributed solution for resource allocation with a view to maximizing network sum-rate. An optimization problem is formulated for radio resource allocation at the relays. The objective is to maximize end-to-end rate as well as satisfy the data rate requirements for cellular and D2D user equipments under total power constraint. Due to intractability of the resource allocation problem, we propose a solution approach using message passing technique where each user equipment sends and receives information messages to/from the relay node in an iterative manner with the goal of achieving an optimal allocation. Therefore, the computational effort is distributed among all the user equipments and the corresponding relay node. The convergence and optimality of the proposed scheme are proved and a possible distributed implementation of the scheme in practical LTE-Advanced networks is outlined. The numerical results show that there is a distance threshold beyond which relay-aided D2D communication significantly improves network performance with a small increase in end-to-end delay when compared to direct communication between D2D peers.
Monowar Hasan, Ekram Hossain 0001
IEEE Trans. Wirel. Commun.1
2014 Resource Allocation Under Channel Uncertainties for Relay-Aided Device-to-Device Communication Underlaying LTE-A Cellular Networks
abstract
Device-to-device (D2D) communication in cellular networks allows direct transmission between two cellular devices with local communication needs. Due to the increasing number of autonomous heterogeneous devices in future mobile networks, an efficient resource allocation scheme is required to maximize network throughput and achieve higher spectral efficiency. In this paper, performance of network-integrated D2D communication under channel uncertainties is investigated where D2D traffic is carried through relay nodes. Considering a multi-user and multi-relay network, we propose a robust distributed solution for resource allocation with a view to maximizing network sum-rate when the interference from other relay nodes and the link gains are uncertain. An optimization problem is formulated for allocating radio resources at the relays to maximize end-to-end rate as well as satisfy the quality-of-service (QoS) requirements for cellular and D2D user equipments under total power constraint. Each of the uncertain parameters is modeled by a bounded distance between its estimated and bounded values. We show that the robust problem is convex and a gradient-aided dual decomposition algorithm is applied to allocate radio resources in a distributed manner. Finally, to reduce the cost of robustness defined as the reduction of achievable sum-rate, we utilize the chance constraint approach to achieve a trade-off between robustness and optimality. The numerical results show that there is a distance threshold beyond which relay-aided D2D communication significantly improves network performance when compared to direct communication between D2D peers.
Monowar Hasan, Ekram Hossain 0001, Dong In Kim 0001
IEEE Trans. Wirel. Commun.1