EDBT 2026 Demo / reviewers in the wild / expert
Keshav Sood
dblp:153/9985
· DBLP profile ↗
43ranked-venue papers
8as first author
35since 2021 · last 2026
0000-0002-2127-1438ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 23 · 6 first-author · 16 since 2021Security and privacy · 10 · 2 first-author · 10 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Resource-based online orchestration for multi-domain collaborative analysis of network encrypted trafficabstractAbstract In recent years, cloud-edge-end collaborative federated learning frameworks have been widely used in many scenarios and achieved good results. However, with the complexity of application requirements, the problems of device heterogeneity and data heterogeneity become more prominent. Traditional frameworks often face challenges such as uneven allocation of computational resources and inefficient training when dealing with these problems. To address this problem, this paper proposes a novel federated learning framework for multi-domain collaborative analysis of networked encrypted flows. First, we split the model training tasks, intelligently assign part of the model training tasks to terminal devices based on their performance, while the remaining model training tasks that require more computational resources are handed over to edge servers. Second, we introduce a resource scheduling scheme among edge servers to reasonably allocate model training tasks and fully utilize resources. Finally, high quality global models are obtained through a weight-enabled global model aggregation scheme. Experiments show that our proposed scheme can effectively address the impact of device heterogeneity and data heterogeneity in encrypted traffic identification in cross-domain networks, and improve the training efficiency and model performance of the overall system while ensuring data privacy and security. Yunhua He, Bin Wu 0011, Keshav Sood, Ke Xiao 0001, Limin Sun 0001 |
Cybersecur. | 4 |
| 2026 | Joint client selection and epoch configuration for heterogeneity-aware federated learning in resource-constrained systems
Lang Fan, Mingjun Duan, Keshav Sood |
Future Gener. Comput. Syst. | 5 |
| 2026 | Rethinking Targeted Data Poisoning in Voice Authentication: A Critique and Defense MechanismabstractRecent deep learning techniques have significantly improved voice authentication systems. However, they remain vulnerable to threats, including data poisoning and Man-in-the-Middle (MitM) attacks. This paper reevaluates the attack and defense mechanisms of “The Guardian”, examining their assumptions and modifying the proposal. We conduct experiments with real-world datasets to validate their effectiveness under realistic conditions and assess the feasibility of executing such attacks. Additionally, we introduce a defense mechanism that improves resilience after redefining a threat model grounded in operational feasibility, specifically by isolating the enrollment phase from training phase assumptions. By analyzing the current literature, we identify open challenges and suggest directions for further improving the security of voice authentication systems. Kamel Kamel, Keshav Sood, Hridoy Sankar Dutta, Sunil Aryal |
IEEE Internet Things J. | 2 |
| 2026 | Sentinel: Dynamic Knowledge Distillation for Personalized Federated Intrusion Detection in Heterogeneous IoT NetworksabstractFederated learning (FL) offers a privacy-preserving paradigm for distributed machine learning, but its application to intrusion detection systems (IDS) in IoT networks is hindered by severe class imbalance, highly non-IID data, and high communication overhead. These challenges severely degrade the performance of conventional FL methods in real-world network traffic classification. To overcome these limitations, we propose Sentinel, a personalized federated IDS (pFed-IDS) framework that incorporates a dual-model architecture on each client, consisting of a high-capacity personalized teacher and a lightweight globally shared student model. This design balances deep local adaptation with efficient global aggregation while preserving privacy and reducing communication overhead by transmitting only the compact student model. Sentinel integrates three key mechanisms to ensure robust performance: bidirectional knowledge distillation with adaptive temperature scheduling, lightweight multi-level feature alignment between teacher and student representations, and a class-balanced loss to handle highly skewed traffic. On the server side, normalized gradient aggregation with equal client weighting mitigates client drift and improves fairness across clients. Extensive experiments on the IoTID20 and 5GNIDD benchmark datasets demonstrate that Sentinel significantly outperforms state-of-the-art federated baselines under extreme data heterogeneity, while lowering communication overhead. Keshav Sood, Pachamuthu Rajalakshmi, Yong Xiang 0001 |
IEEE Internet Things J. | 2 |
| 2026 | Efficient and Unbounded Public-Key Encryption With Keyword Search Based on Arithmetic Span Programs in Cloud StorageabstractPublic-key Encryption with Keyword Search (PEKS) enables users to search encrypted data stored on an untrusted server without revealing any sensitive information. However, existing PEKS schemes are typically inefficient and lack the flexibility to support complex search policies. To address this, a novel PEKS scheme based on Arithmetic Span Programs (PEKS-ASP) is proposed in this paper. This is the first scheme to enable flexible and efficient search policies by using directed acyclic graphs. This approach enhances the efficiency of complex search queries that implement AND, OR, and NOT gates, enabling a more efficient representation of complicated search policies without redundancy in keyword usage. And our proposed PEKS-ASP scheme guarantees constant-size public parameters regardless of the number of keywords. Additionally, the proposed scheme achieves adaptive security under the matrix decisional Diffie-Hellman (MDDH) assumption, employing dual system encryption techniques. Both theoretical analysis and experimental results demonstrate that PEKS-ASP significantly improves efficiency and practicality, making it well-suited for practical applications in various cloud environments. Hu Xiong, Jun Feng 0007, Kehan Gao, Keshav Sood |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | FedAdap: An Adaptive Federated Knowledge Graph Embedding Framework for Tackling KGs Heterogeneity via Partial Model SharingabstractKnowledge Graph Embedding (KGE) is a technique used to capture structural information from Knowledge Graphs (KGs), enabling various downstream applications such as recommender system. KGE models trained on integrated KGs from multiple organizations tend to outperform those trained on a single KG, owing to the greater richness and diversity of information. Therefore, Federated Knowledge Graph Embedding (FKGE) emerges as a promising approach for privacy-preserving training of KGE models on KGs across organizations (clients). Existing FKGE framework learns a uniform global KGE model that achieves global optima by minimizing aggregated loss across clients. However, heterogeneity among KGs often leads to divergent local optima. This presents a fundamental trade-off: ensuring global optima can compromise local performance, while focusing on local optima can decrease global model utility. To overcome this, we propose Federated Local Adaptive Knowledge Graph Embedding (FedAdap) by drawing inspiration from partial federated learning. FedAdap employs a multilayer convolutional neural network, wherein its lower layers are shared across clients to learn shared information, it maps a seed KGE model into an alignment vector space representation. Its upper layers remain private, transforming the alignment vector space representation to an adaptive KGE model tailored to the local KG. Through this, FedAdap allows clients to leverage shared information while maintaining local adaptability and mitigating the impact of KGs heterogeneity. Experiments on data sets FB15k-237 and NELL-995 show that FedAdap outperforms its counterparts in link prediction tasks. Borui Cai, Yong Xiang 0001, Keshav Sood |
IJCNN | 4 |
| 2025 | A federated compositional knowledge graph embedding for communication efficiencyabstractKnowledge Graph Embedding (KGE), which automatically capture structural information from Knowledge Graphs (KGs), are essential for enhancing various downstream tasks, such as recommender systems. To further improve the effectiveness of KGE models, Federated Knowledge Graph Embedding (FKGE) has been introduced, enabling the privacy-preserving integration of KGs across multiple organizations. However, existing FKGE frameworks require aggregation of a large global KGE model (embeddings). resulting in significant communication overhead, thereby reducing the efficiency and utility of FKGE in practical scenarios. To address this challenge, we propose Federated Compositional Knowledge Graph Embedding (FedComp), which enhances communication efficiency by leveraging the compositional characteristics of KG entities. In FedComp, we design a lightweight global model that represents shareable latent features of entities. These global latent features are composed into personalized KGE models with local embedding generators on the clients, improving both local adaptability and performance. By this, FedComp can significantly reduce the number of parameters that need to be transmitted Experimental results show that FedComp outperforms state-of-the-art FKGE frameworks on link prediction accuracy, with only around 1.0% communication overhead compared to counterpart frameworks. Borui Cai, Yong Xiang 0001, Yao Zhao 0006, Md Palash Uddin, Keshav Sood |
Knowl. Based Syst. | 6 |
| 2025 | Trustworthy and Fair Federated Learning via Reputation-Based Consensus and Adaptive IncentivesabstractFederated Learning (FL) allows collaborative training of a Machine Learning (ML) model while preserving data privacy across participating clients. Most existing studies consider FL clients to be proactive and completely honest in their participation. However, in reality, clients might lack the motivation to participate, and malicious behavior among some clients could negatively impact the interests of others. For these reasons, ensuring trust and fairness among FL clients is paramount but remains challenging due to limitations in FL consensus mechanisms and incentive strategies. To address these challenges, we introduce a Trustworthy and Fair FL (TFFL) framework that develops a reputation-based consensus mechanism called Dynamic Reputation Consensus (DRC), where clients’ reputations are dynamically assessed based on subjective opinions by evaluating real-time client behavior. We also incorporate time decay and temporal discounting of TFFL interactions along with the weighted measures of clients’ data quality, performance, and reliability to accurately reflect the evolving nature of client behavior over time. By adaptively adjusting clients’ incentives based on reputations and a cooperative game theory, DRC incentivizes honest participation and discourages malicious intent. In addition, we utilize blockchain and smart contracts to provide decentralized, regularized, and secure reputation management that is resistant to tampering and non-repudiation. Theoretical analysis and empirical results on widely used datasets (MNIST, CIFAR-10, and CIFAR-100) demonstrate the effectiveness of DRC in enhancing trust and fairness, improving performance, and providing robust security in FL settings. Results further exhibit that DRC offers superior performance in local model validation, consensus decision, and convergence time compared to related research approaches across various experimental settings. Yong Xiang 0001, Md Palash Uddin, Jine Tang, Keshav Sood, Longxiang Gao |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Alleviating Data Sparsity to Enhance AI Models Robustness in IoT Network Security ContextabstractIn Internet of Things (IoT) networks, the IoT sensors collect valuable raw data required to sustain Artificial Intelligence (AI) based networks operation. AI models are data-driven as they use the data to make accurate network security, management, and operational decisions. Unfortunately, the sensors are deployed in harsh environments which affects the sensor behaviour and eventually the networks' operations. Further, IoT devices are typically vulnerable to a range of malicious events. Therefore, IoT sensor's correct operation including resilience to failure is essential for sustained operations. Naturally, the state variables of time-series data can be changed, i.e., the data streams generated in these situations can be incorrect, incomplete or missing, and sparse presenting a significant challenge for real-time decision-making ability of AI models to make explainable and intelligent management and control decisions. In this paper, we aim to alleviate this fundamental problem to predict the missing and faulty reading correctly so that the decision-making ability of the AI models should not deteriorate in the presence of incorrect, missing, and highly imbalanced data sets. We use a novel approach using fuzzy-based information decomposition to recover the missed data values. We use three data sets, and our preliminary results show that our approach effectively recovers the missed or compromised data samples and help AI models in making accurate decision. Finally, the limitations and future work of this research have been discussed. Keshav Sood, Shigang Liu, Dinh Duc Nha Nguyen, Neeraj Kumar 0001, Bohao Feng, Shui Yu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | Empirical Study of Hierarchical Intrusion Detection Systems for Unknown AttacksabstractThe attack detection models of the traditional Intrusion Detection Systems (IDSs) IDSsIntrusion Detection Systems are trained on closed-set problems which reduces the classifiers’ performance on detecting unknown attacks in the open-set problem space. Mostly adapted, one-short learning in the classifier does not allow the traditional IDS to be an open-set recognizer. The alternate continuous learning-based IDS in unknown attack detection claims ongoing suggestions from experts to retrain the model with newly identified samples. Hence, using the multi-layer hierarchical IDS (HIDS) HIDSHierarchical IDS with optimized classifier models, the unknown attacks can be classified by comparing their patterns with benign and known attacks. However, we have identified many challenges in the existing HIDS system on various datasets though it provides a solid foundation in this design category for unknown attack identification. As a result, in this paper, we designed an enhanced multi-tier IDS for zero-day attack detection with optimized heterogeneous classifiers in its major two phases like basic framework demands. We have examined the enhanced proposed hierarchical IDS on various benchmark Intrusion Detection Systems datasets such as WUSTL, CIC_IDS_2017, 5G and UNR to analyze the efficiency in unknown attacks classification. When compare to existing multi-tier IDS, the proposed IDS achieved highest detection 96.2%,87%,96.8% and 100% in 5G, WUSTL, UNR and CIC_IDS_2017 datasets for unknown attacks. The optimized model in the proposed IDS reduces the time complexity into 50% than the existing. Implementation results show the proposed enhanced IDS performs better than the existing hierarchical IDS with a high true positive rate for benign, known and unknown attack labels on various datasets. Menaka Pushpa Arthur, Ganesan Ramachandran, Keshav Sood, Pavan Kaarthik, Srivarshinee Sridhar, Morshed Chowdhury |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Cross-Domain Identity Authentication Scheme for the IIoT Identification Resolution System Based on Self-Sovereign IdentityabstractIn the Industrial Internet of Things (IIoT), the identification resolution system enhances communication and overall efficiency between isolated work islands, ensuring the trustworthiness and effectiveness of secure resource sharing across domains through cross-domain authentication. However, traditional identity authentication methods fail to empower users with control over their identity information and face challenges such as difficulty in tracking anonymous users, high computational overhead, and insufficient cross-domain trust. To address these issues, this paper proposes a cross-domain identity authentication scheme based on self-sovereign identity. The scheme leverages aggregate signature technology to enhance authentication efficiency, integrates blockchain technology and smart contracts to achieve cross-domain trust, and designs a mechanism for threshold identity tracking and revocation, as well as an attribute credential update mechanism to enable secure and efficient cross-domain authentication in the identification resolution system. The paper provides formal security definitions and proofs and evaluates the computational and storage efficiency of the scheme through theoretical analysis and experimental simulations. The results demonstrate that the proposed scheme offers significant advantages in resource-constrained scenarios within the IIoT. Yunhua He, Tingli Yuan, Bin Wu 0011, Keshav Sood, Ke Xiao 0001, Xiuzhen Cheng |
IEEE Trans. Netw. | 4 |
| 2024 | Towards Availability of Strong Authentication in Remote and Disruption-Prone Operational Technology EnvironmentsabstractImplementing strong authentication methods in a network requires stable connectivity between the service providers deployed within the network (i.e., applications that users of the network need to access) and the Identity and Access Management (IAM) server located at the core segment of the network. This becomes challenging when it comes to Operational Technology (OT) systems deployed in a remote area, as they often get disconnected from the core segment of the network owing to unavoidable network disruptions. As a result, weak authentication methods and shared credential approaches are still adopted in these OT environments, exposing system vulnerabilities to increasingly sophisticated cyber threats. In this work, we propose a solution to enable highly available multi-factor authentication (MFA) services for OT environments. The proposed solution is based on Proof-of-Possession (PoP) tokens generated by an IAM server for registered users. The tokens are securely linked to user-specific parameters (e.g., physical security keys, biometrics, PIN, etc.), enabling strong user authentication (during disconnection time) through token validation. We deployed the Tamarin Prover software-based toolkit to verify security of the proposed authentication scheme. For performance evaluation, we implemented the designed solution in real-world settings. The results of our analysis and experiments confirm the efficacy of the proposed solution. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Divyans Mahansaria, Debi Prasad Pati, Praveen Gauravaram, Lei Pan 0002, Keshav Sood |
ARES | 8 |
| 2024 | From Data Integrity to Global Model Integrity for Federated Learning: An MHT-based ApproachabstractFederated Learning (FL) is a distributed machine learning (ML) approach that enables multiple edge nodes to collaboratively train ML models by sharing model parameters, thus addressing privacy concerns. However, in highly distributed, dynamic, and volatile FL environments, the global model is vulnerable to various corruptions. For instance, edge nodes might falsely claim that the received global model is incomplete, or the channel that transmits the global model is untrustworthy. Effectively verifying the integrity of the global model poses a critical challenge. To tackle this issue, we introduce a method for verifying model integrity called Federated learning global Model Integrity Verification (FMIV). It leverages Merkle Hash Tree (MHT) to generate integrity proofs of the global model during verification. To improve security, we integrate random security codes during proof generation. FMIV is capable of verifying the global model updated by the central server and shared with untrusted edge nodes, while efficiently identifying the edge node caching the incomplete global model. Furthermore, we conduct theoretical analysis and extensive experiments to validate the performance of FMIV. Compared to the two state-of-the-art approaches, FMIV consistently exhibits a notable improvement in verification efficiency and effectiveness in detecting model corruption. Yao Zhao 0006, Y. Neil Qu, Bruce Gu, Keshav Sood, Longxiang Gao, Shui Yu 0001 |
GLOBECOM | 5 |
| 2024 | The Value of Strong Identity and Access Management for ICS/OT SecurityabstractAs the integration of digital technologies with Industrial Control Systems (ICS) and Operational Technology (OT) continues to deepen, these systems increasingly become targets for sophisticated cyber attacks. These attacks not only threaten the operational integrity but also pose significant risks to national security and public safety. In this paper, we provide insights into the value of ICS/OT security solutions that are based on Identity and Access Management (IAM). Beginning with presenting an abstraction model for typical ICS/OT attacks, the paper systematically outlines the main stages of an attack and the corresponding vectors employed by adversaries. Drawing from the MITRE ATT&CK framework tailored for ICS, the paper quantifies the extent to which IAM-based mitigation approaches can strengthen defense-in-depth mechanisms against cyber threats targeting ICS/OT environments. Our findings show that there are modern attack vectors that can only be mitigated through robust IAM solutions. Moreover, we found that while advanced techniques such as firewall and gateway-based intelligent threat detection play a significant role in safeguarding I CS/OT, they are insufficient on their own to address several attack vectors in ICS/OT environments. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Praveen Gauravaram, Debi Prasad Pati, Divyans Mahansaria, Keshav Sood, Lei Pan 0002 |
PST | 7 |
| 2024 | Design and Robust Evaluation of Next Generation Node Authentication ApproachabstractThe flexibility of 5G-NGNs makes them an ideal infrastructure for supporting mission-critical IoT applications that require low latency and high bandwidth. However, due to the rapid proliferation and the integration of IoTs with 5 G, the threat surface has considerably expanded. Hence the security of IoT devices is a big concern. Unfortunately, IoT devices have limited resources, and the traditional security approaches (authentication and intrusion detection approaches) of cryptography do not work effectively on 5G-IoT ecosystems. Motivated from this, we leverage the distinctive RF (Radio Frequency) fingerprinting signatures of IoT devices and used them to train a Deep learning model, Mahalanobis Distance theory in addition to the Chi-square distribution theory, to authenticate the IoT nodes. Under robust scenarios we have tested the approach shows detection accuracy (99.35%) as well as significant amount of reduction in model's training time as these two metrics are one of the primary key performance indicators (KPIs). In order to evaluate the effectiveness of the proposed method in real-time scenarios, we tested the proposed solution with a real RF dataset and the OSM-MANO 5 G platform. The model underwent formal verification using the Tamarin Prover tool, and the proposal was also compared with recent research works. Dinh Duc Nha Nguyen, Keshav Sood, Yong Xiang 0001, Longxiang Gao, Lianhua Chi, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Evaluating Federated Learning-Based Intrusion Detection Scheme for Next Generation NetworksabstractThe proliferation of billions of heterogeneous Internet of Things (IoT) devices at a rapid pace has resulted in a marked expansion of attack surfaces. Numerous new attacks are constantly emerging to undermine the network’s availability, data confidentiality, and systems’ integrity due to inadequate security measures and resource limitations. Intrusion detection systems (IDSs) are used as the first line of defense to identify early instances of cyber-attacks targeting critical points. However, Next-Generation Networks (NGNs) with dense connectivity pose a challenge for traditional IDS approaches, as they raise concerns about users’ data privacy. Federated learning-based IDSs (Fed-IDSs) are an emerging and promising solution, as they permit the training of machine learning models on decentralized data stored on devices without compromising privacy. However, Fed-IDSs also have some unique issues. We identified that the existing Fed-IDSs have poor performance since the datasets used for evaluation, or the data in the real world, are highly imbalanced, and classes are not uniformly distributed. Motivated by this, we developed a novel IDS to effectively address the problem of class imbalance in federated learning at both the local and global levels. Following this, we evaluated the performance of our Fed-IDS under both independent and identically distributed (IID) and non-IID data settings and observed its generalizability to detect various attacks improved greatly. Extensive experiments are conducted to illustrate the effectiveness and benefits of this proposal. Keshav Sood, Pachamuthu Rajalakshmi, Dinh Duc Nha Nguyen, Yong Xiang 0001 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Blockchained Dual-Asynchronous Federated Learning Services for Digital Twin Empowered Edge-Cloud ContinuumabstractThe booming of learning-based Artificial Intelligence (AI) enables the integration of Big Data and emerging computing architectures, which facilitate the Edge-AI-as-a-Service (EAaaS) in the edge-cloud continuum. To meet the emerging demands, such as privacy preservation and autonomy, blockchain-enabled federated learning (B-FL) is proposed, which further provides decentralized processing, data falsification avoidance, and learning model reliability. However, synchronous global aggregation, which is deployed in most existing B-FL paradigms, is dragging down the performances due to the data and computing resources heterogeneity of diverse edge devices. In addition, the restricted resources of edge devices pose further challenges in executing learning tasks and blockchain-based consensus simultaneously. To solve these issues, we propose a blockchained dual-asynchronous federated learning (BAFL-DT) service model for EAaaS in the digital twin empowered edge-cloud continuum. In BAFL-DT, federated learning services are run on local edge devices, while the global aggregation is achieved by the consensus process of digital twins implemented in the cloud. Besides, dual-asynchronous FL allows both local training and global aggregation to be performed in an asynchronous manner, which is uniquely enabled by the proposed paradigm. Extensive evaluations of real-world datasets testify to the superior performances of EAaaS by improving accuracy and efficiency. Youyang Qu, Shui Yu 0001, Longxiang Gao, Keshav Sood, Yong Xiang 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | OATGA: Optimizing Adversarial Training via Genetic Algorithm for Automatic Modulation ClassificationabstractRecently, with the explosive growth of the mobile devices, spectrum sensing for wireless devices has become an attractive research. Automatic modulation classification (AMC) is an important task in spectrum sensing and plays an important role in blind signal recognition, and deep learning has been shown to greatly improve the performance of AMC networks. However, deep learning models for AMC are considered vulnerable against adversarial attacks, resulting in unreliable sensor systems. In this paper, we study how to deal with the threats of adversarial attacks by optimizing neural networks. We propose an adversarial defense method based on genetic algorithm (GA) to optimize adversarial training. The optimizations are performed between the layers of the neural networks to obtain the weights with maximum fitness, to improve the adversarial robustness of the models. In addition, an indicator to quantitatively evaluate the adversarial robustness of the models is also proposed. We conduct experiments in the different perturbation-to-noise ratios (PNRs) to verify the effectiveness of the defensive models. The results show that the GA-optimized approach can greatly improve the classification accuracy of the models to adversarial examples, and provides a better fitting ability than the mainstream adversarial training methods. Zhida Bao, Quanjun Zhang, Chunrong Fang, Keshav Sood, Yun Lin 0005 |
GLOBECOM | 5 |
| 2023 | Machine translation-based fine-grained comments generation for solidity smart contracts
Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Keshav Sood, Longxiang Gao |
Inf. Softw. Technol. | 4 |
| 2023 | Toward IoT Node Authentication Mechanism in Next Generation NetworksabstractAlthough the next generation networks (5G-NGNs) provide a flexible infrastructure to support latency-sensitive and bandwidth-hungry mission-critical Internet of Things (IoT) applications, however, the 5G-IoT integration in NGNs has increased the threat surface. Unfortunately, IoT devices are resource constrained, and the traditional intrusion detection systems (IDS) approaches based on cryptography are not effective on 5G-IoT ecosystems. In this article, we propose an effective 5G-IoT node authentication approach that leverages unique radio frequency (RF) fingerprinting data to train the Deep learning model to detect legitimate and nonlegitimate IoT nodes. Our approach is based on Mahalanobis Distance theory and Chi-square distribution theories. The proposed approach achieves a higher detection accuracy (99.35%) as well as lower training time compared to other existing approaches which is a key benefit of our approach in NGNs. The experiments are conducted using ETSI-open source NFV management and orchestration (OSM-MANO) platform on Amazon Web Services (AWSs) cloud platform to verify how the proposed approach would fit in real-life scenarios. The method can be used as a standalone security system or as a part of multifactor authentication. Dinh Duc Nha Nguyen, Keshav Sood, Yong Xiang 0001, Longxiang Gao, Lianhua Chi, Shui Yu 0001 |
IEEE Internet Things J. | 2 |
| 2023 | SSVS-SSVD Based Desynchronization Attacks Resilient Watermarking Method for Stereo SignalsabstractMost of the audio signals in real-world applications are stereo signals. However, the previous desynchronization attacks resilient watermarking methods cannot preserve perceptual quality or achieve robustness when constrained by high embedding rates and stereo host. In this paper, based on two novel features segmental singular values summation (SSVS) and segmental singular values difference (SSVD) that are generated using discrete cosine transform (DCT) and singular value decomposition (SVD), we present a robust watermarking method for stereo signals that not only is robust to desynchronization attacks and common signal processing attacks but also has a larger embedding rate compared with the previous methods. In the proposed method, we first apply DCT and SVD on each segment of the host signal to extract the SSVS feature and the SSVD feature. Then we generate the adaptive embedding parameters and embed watermark bits via optimized embedding strategies based on these features. Due to the use of the adaptive embedding parameters and the optimized embedding strategies, the proposed method significantly increases the embedding rate without compromising the robustness and perceptual quality. Analysis results show our proposed method outperforms the state-of-the-art methods by a large margin, where the perceptual quality improvement is over 14%, and the robustness against desynchronization attacks is improved by more than 49% when the embedding rate is 70 bps. Juan Zhao 0007, Tianrui Zong, Yong Xiang 0001, Longxiang Gao, Guang Hua 0001, Keshav Sood, Yushu Zhang 0001 |
IEEE ACM Trans. Audio Speech Lang. Process. | 6 |
| 2023 | UCoin: An Efficient Privacy Preserving Scheme for CryptocurrenciesabstractIn cryptocurrencies, privacy of users is preserved using pseudonymity . However, it has been shown that pseudonymity does not result in anonymity if a user's transactions are linkable. This makes cryptocurrencies vulnerable to deanonymization attacks. The current solutions proposed in the literature suffer from at least one of the following issues: (1) requiring a trusted third–party entity, (2) poor performance, and (3) incompatible with the standard structure of cryptocurrencies. In this article, we propose Unlinkable Coin (UCoin), a secure mix–based approach to address these issues. In UCoin, the link between the input (payer) and output (payee) addresses in a transaction is broken. This is done by mixing the transactions of multiple users into a single aggregated transaction in which the output addresses have been secretly shuffled. In our protocol design, we first develop HDC–net, a secure shuffling protocol that enables a group of users to anonymously publish their data. Then, we deploy the proposed HDC–net protocol in the UCoin architecture (as a mixing unit) to generate the aggregate transactions. We show that UCoin (1) does not rely on a trusted third–party, (2) can mix 50 transactions in 6.3 seconds that is 18% faster than the current solutions, and (3) is fully compatible with the architecture of cryptocurrencies. Mohammad Reza Nosouhi, Shui Yu 0001, Keshav Sood, Marthie Grobler, Raja Jurdak, Ali Dorri, Shigen Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Accurate Detection of IoT Sensor Behaviors in Legitimate, Faulty and Compromised ScenariosabstractIn smart farming sector, Internet of Things (IoT) based smart sensing systems are vulnerable to failure, malfunction, and malicious attacks. Also, sensors are deployed often in an alien and harsh environment. Here, the conditions are not well supportive which either causes the sensor to fail prematurely or gives unusual and erroneous readings, known as outliers. This effects the smart network's performance and decision-making ability in many ways. Therefore, it is important to accurately detect the IoT sensor behaviour in legitimate, faulty, and compromised or attack scenarios. To distinguish the sensor behaviour in different scenarios we have proposed a feasible approach using spatial correlation theory which is validated using Moran'sIindex tool. We have used Classification and Regression Trees (CART), Random Forest (RF), and Support Vector Machine (SVM) models to test our approach. For real-time anomaly detection we have used an edge computing technology. We have compared the proposed approach, using Forest Fire real dataset, with the three existing recent works. Our results are promising in terms of accurate detection of IoT sensor behaviours in real-time. This will assist the precision farming industry in making better decisions to securely manage IoT field network, increase productivity, and improves operational efficiency. Keshav Sood, Mohammad Reza Nosouhi, Neeraj Kumar 0001, Anuroop Gaddam, Bohao Feng, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Intrusion Detection Scheme With Dimensionality Reduction in Next Generation NetworksabstractDue to millions of heterogeneous physical nodes, multiple-vendor and multi-tenant domains, and technologies etc., 5G has greatly expanded the threat landscape. Particularly from the high rate of traffic and ultra-low latency requirement of applications in 5G networks, the detection of the network traffic anomalies in real-time is critical. The conventional security approaches lack compatibility with modern network designs and are not much effective in 5G settings. We propose a two-stage network traffic anomaly detection system compatible with ETSI-NFV standard 5G architecture. Our architecture consists of two modules, i.e., (a) Dimensionality Reduction to compress the sample size at the edge of 5G networks and (b) Deep Neural Network classifier (DNN) that detects traffic anomalies. We have conducted our experiments using OMNET++ and ETSI-NFV (OSM MANO) 5G orchestration real platform deployed on AWS cloud systems. We have used the UNSW-NB15 data set and have shown that at dimensionality reduction factor of 81% the detection accuracy obtained is 98%. The proposal is compared with other recent approaches to show the overall merit of the architecture. Keshav Sood, Mohammad Reza Nosouhi, Dinh Duc Nha Nguyen, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Performance Evaluation of a Novel Intrusion Detection System in Next Generation NetworksabstractThe integration of Internet of Things (IoT) with 5G simply creates additional threat landscape and any network infrastructure is more vulnerable. Severe attacks on networks potentially damage organization reputation, customers or tenants lose confidence, and impacts operational and maintenance cost. Intrusion detection systems (IDSs) are an effective approach to mitigate threats. We present a novel IDS mechanism in which the unique Radio Frequency (RF) features of IoT devices are used to create a learning model which is later used to identify the illegitimate devices in the network. Leveraging the Deep Autoencoder (DAE), the existing steady-state feature extraction is generalized. The performance evaluation is conducted using a real data set from different aspects including the mobility of the nodes. The proposed IDS is broken down into pluggable virtual network function (VNF) components and its evaluation is presented for its integration into the 5G network slicing ecosystem from the perspective of the European Telecommunications Standards Institute (ETSI) standards. A Proof of Concept (PoC) is presented using ETSI Open Source NFV Management and Orchestration (OSM-MANO) test bed, deployed on AWS cloud systems, to show how the proposed approach would fit in with a real-life MANO. Keshav Sood, Dinh Duc Nha Nguyen, Mohammad Reza Nosouhi, Neeraj Kumar 0001, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Efficient Federated DRL-Based Cooperative Caching for Mobile Edge NetworksabstractEdge caching has been regarded as a promising technique for low-latency, high-rate data delivery in future networks, and there is an increasing interest to leverage Machine Learning (ML) for better content placement instead of traditional optimization-based methods due to its self-adaptive ability under complex environments. Despite many efforts on ML-based cooperative caching, there are still several key issues that need to be addressed, especially to reduce computation complexity and communication costs under the optimization of cache efficiency. To this end, in this paper, we propose an efficient cooperative caching (FDDL) framework to address the issues in mobile edge networks. Particularly, we propose a DRL-CA algorithm for cache admission, which extracts a boarder set of attributes from massive requests to improve the cache efficiency. Then, we present an lightweight eviction algorithm for fine-grained replacements of unpopular contents. Moreover, we present a Federated Learning-based parameter sharing mechanism to reduce the signaling overheads in collaborations. We implement an emulation system and evaluate the caching performance of the proposed FDDL. Emulation results show that the proposed FDDL can achieve a higher cache hit ratio and traffic offloading rate than several conventional caching policies and DRL-based caching algorithms, and effectively reduce communication costs and training time. Aleteng Tian, Bohao Feng, Huachun Zhou, Yunxue Huang, Keshav Sood, Shui Yu 0001, Hongke Zhang |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2023 | A Sparse Protocol Parsing Method for IIoT Based on BPSO-vote-HMM Hybrid ModelabstractWith the development of the Industrial Internet of Things, industrial control systems have become more open and intelligent. However, large numbers of unknown protocols exist in IIoT, threatening the security of IIoT devices and systems. Protocol reverse engineering extracts the grammar and semantics of the protocol by monitoring and analyzing the traffic trace or the execution process of instructions, without the need for protocol description. As the executable programs are mainly integrated into the IIoT devices and the communication traffic is relatively sparse, the traditional protocol analyzing method is not suitable for the IIoT environment. This paper proposes an improved sparse protocol parsing method of IIoT protocol based on the BPSO-vote-HMM hybrid model. The binary particle swarm optimization algorithm is introduced to expand the captured IIoT protocol message sequence, solving the problems of sparse samples in IIoT and the low efficiency of the GA-based data expansion model. Besides, we improve on the parameter training part to improve the efficiency and get better model parameters by dividing the training set into several sub-sets, conducting the parameter update parallel, and inputting the results into a voter to generate the final parameter of HMM, which is used in protocol field prediction. Finally, by combining the BPSO-based data expansion model and the protocol field parsing model based on vote-HMM, a hybrid analytical model is constructed to improve the analytical accuracy in a gradual evolutionary manner. Through a series of comparative experiments, the improved protocol field parsing model has better performance on IIoT protocol. Yunhua He, Yueting Wu, Jialong Shen, Ke Xiao 0001, Keshav Sood, Limin Sun 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2023 | CoSS: Leveraging Statement Semantics for Code SummarizationabstractAutomated code summarization tools allow generating descriptions for code snippets in natural language, which benefits software development and maintenance. Recent studies demonstrate that the quality of generated summaries can be improved by using additional code representations beyond token sequences. The majority of contemporary approaches mainly focus on extracting code syntactic and structural information from abstract syntax trees (ASTs). However, from the view of macro-structures, it is challenging to identify and capture semantically meaningful features due to fine-grained syntactic nodes involved in ASTs. To fill this gap, we investigate how to learn more code semantics and control flow features from the perspective of code statements. Accordingly, we propose a novel model entitled CoSS for code summarization. CoSS adopts a Transformer-based encoder and a graph attention network-based encoder to capture token-level and statement-level semantics from code token sequence and control flow graph, respectively. Then, after receiving two-level embeddings from encoders, a joint decoder with a multi-head attention mechanism predicts output sequences verbatim. Performance evaluations on Java, Python, and Solidity datasets validate that CoSS outperforms nine state-of-the-art (SOTA) neural code summarization models in effectiveness and is competitive in execution efficiency. Further, the ablation study reveals the contribution of each model component. Chaochen Shi, Borui Cai, Yao Zhao 0006, Longxiang Gao, Keshav Sood, Yong Xiang 0001 |
IEEE Trans. Software Eng. | 5 |
| 2022 | Impersonation Attack Detection in IoT NetworksabstractThe deployment of Internet of Things (IoT) networks is growing at an extraordinary speed from last decade and has expanded the interconnection of billions of nodes, providing a range of flexible communication and computing services, etc. We note that this significant expansion of the IoT surface has expanded the attack surfaces and is a danger to companies of every size from security aspects. The IoT devices are easy to compromise and therefore the attacker can easily act as an impersonator to impersonate other legitimate IoT nodes. This is known as impersonation attacks or spoofing attacks in wireless IoT networks. In this paper, we propose a new methodology to detect an impersonation attack in IoT networks. We use Mahalanobis Distance correlation theory based two-stage attack detection model to resist IoT node spoofing. The approach is evaluated on cloud platforms and is compared with the recent state-of-the-art literature. The proposal is deployed as a pluggable module in cloud networks. The key metrics of our evaluation and comparisons are accuracy with respect to the varying size of the IoT network, classification metrics, attack detection time, and CPU utilization. Dinh Duc Nha Nguyen, Keshav Sood, Yong Xiang 0001, Longxiang Gao, Lianhua Chi |
GLOBECOM | 2 |
| 2022 | Personalized Privacy-Preserving Medical Data Sharing for Blockchain-based Smart Healthcare NetworksabstractWith the growing proliferation of intelligent end devices and data analytics techniques, real momentum towards the development of smart healthcare networks (SHN) has already been evident. Multiple parties in SHNs continuously exchange medical data in order to achieve a precise diagnosis and process optimization. Privacy issue emerges since medical data are susceptible, while the combination of a series of medical data may lead to further privacy leakage. Adversaries launch unceasingly launch poisoning attacks, a dominant attack to maliciously manipulate data, severely impact the authenticity of the data transmitting over the SHNs, leading to misdiagnosing or even physical damage. In this paper, we propose a personalized differential privacy model built upon blockchain, in which the community density is exploited to customize the degree of privacy protection and inject corresponding noise data. Besides using blockchain as the underlying network architecture to defeat poisoning attacks. The proposed model can guarantee the authentication of the differentially private data, traceability of data, and single-point failure avoidance in SHN. Evaluation and extensive results using real-world data sets demonstrate the superiority of the proposed model. Youyang Qu, Shiping Chen 0001, Longxiang Gao, Lei Cui 0006, Keshav Sood, Shui Yu 0001 |
ICC | 5 |
| 2022 | A Bytecode-based Approach for Smart Contract ClassificationabstractWith the development of blockchain technologies, the number of smart contracts deployed on blockchain platforms is growing exponentially, which makes it difficult for users to find desired services by manual screening. The automatic classification of smart contracts can provide blockchain users with keyword-based contract searching and helps to manage smart contracts effectively. Current research on smart contract classification focuses on Natural Language Processing (NLP) solutions which are based on contract source code. However, more than 94% of smart contracts are not open-source, so the application scenarios of NLP methods are very limited. Meanwhile, NLP models are vulnerable to adversarial attacks. This paper proposes a classification model based on features from contract bytecode instead of source code to solve these problems. We also use feature selection and ensemble learning to optimize the model. Our experimental studies on over 11K real-world Ethereum smart contracts show that our model can classify smart contracts without source code and has better performance than baseline models. Our model also has good resistance to adversarial attacks compared with NLP-based models. In addition, our analysis reveals that account features used in many smart contract classification models have little effect on classification and can be excluded. Chaochen Shi, Yong Xiang 0001, Jiangshan Yu, Longxiang Gao, Keshav Sood, Robin Doss |
SANER | 5 |
| 2022 | Security and QoS issues in blockchain enabled next-generation smart logistic networks: A tutorialabstractThe blockchain-enabled smart logistics market is expected to grow worth USD 1620 billion and at a compound annual growth rate of 62.4%. Smart logistics ensures intelligence infrastructure, logistics automation, real-time analysis of supply chain data synchronization of the logistics process, cost transparency, unbroken shipment tracking all the way down to the transportation route, etc. In the smart logistics domain, significant advancement and growth of the Internet of Things (IoT) sensors are evident. However, the connectivity of IoT systems, including Tactile Internet, without proper safeguards creates vulnerabilities that can still be deliberately or inadvertently cause disruption. In view of this, we primarily notice two key issues. Firstly, the logistics domain can be compromised by a variety of natural or man-made activities, which eventually affect the overall network security. Secondly, there are thousands of entities in the supply chain network that use extensive machine-learning algorithms in many scenarios, and they require high-power computational resources. From these two challenges, we note that the first concern can be addressed by adding blockchain to IoT logistic networks. The second issue can be addressed using 6G. This will support 1-μs latency communications, support seamless computing at the edges of networks, and autonomously predict the best optimal location for edge computing. Motivated by this, we have highlighted motivational examples to show the necessity to integrate 6G and blockchain in smart logistic networks. Then, we have proposed a 6G and blockchain-enabled smart logistic high-level framework. We have presented the key intrinsic issues of this framework mainly from the security and resource management context. In this paper, recent state-of-the-art advances in blockchain enabled next-generation smart logistic networks are analyzed. We have also examined why 6G and not 5G would be compatible with the smart network. We have introduced five different use cases of blockchain technology in smart logistics. Later, this paper discusses some important concerns that blockchain in smart logistics might face. We have also provided potential solutions to tackle these concerns. Anjali Vaghani, Keshav Sood, Shui Yu 0001 |
Blockchain Res. Appl. | 2 |
| 2022 | Joint optimization of Service Chain Graph Design and Mapping in NFV-enabled networks
Yexiao He, Zixiang Xia, Keshav Sood, Shui Yu 0001 |
Comput. Networks | 5 |
| 2022 | Bushfire Risk Detection Using Internet of Things: An Application ScenarioabstractWith rising temperatures and events contributing to climate change, the world is facing extreme weather patterns. Recently, Australia was hit hard by bushfires, the most devastating fires ever faced by the country. The economic damage reported was nearly one billion Australian dollars and an estimated three billion native animals were killed or adversely affected. Given the extent and intensity of this damage, researchers are seeking effective solutions to enable the prediction of fire before it starts to increase the time available for firefighters to protect lives and assets and prepare to mitigate the fires. This motivated us to investigate an approach to address this critical problem. In this article, we propose a machine learning (ML)-based approach that detects anomalies in spatiotemporal measurements of environmental parameters (e.g., temperature, relative humidity, etc.). In the proposed approach, an ML-based model learns the normal spatiotemporal behavior of the environmental data (collected over a period of one year). This is carried out during a one-time training phase. Then, during the detection phase, any spatiotemporal pattern in the real-time data (received from the field sensors) that is different than the normal pattern will be identified by the model as anomaly which indicates a possible bushfire situation. Following this, we propose a supplementary classification model based on Moran’s I index to ensure that the detected anomalies are not due to either a sensor failure or a security attack (which are common in Internet of Things). We developed three different ML models for performance evaluation and comparison and used the Forest Fire data set to train them. The results of our experiments confirm the effectiveness of the proposed approach in the early detection of fire symptoms. Mohammad Reza Nosouhi, Keshav Sood, Neeraj Kumar 0001, Tricia Wevill, Chandra Thapa |
IEEE Internet Things J. | 2 |
| 2022 | Towards Spoofing Resistant Next Generation IoT NetworksabstractThe potential vulnerability to wireless spoofing attacks is still a critical concern for Next Generation Internet of Things (NGIoT) networks which may result in catastrophic consequences in mission–critical applications. Conventional solutions may impose additional signal processing, protocol, and latency overheads which are inappropriate for NGIoT networks designed to provide high–speed and low–latency connections for a large number of resource–constrained IoT devices. In this paper, we utilize the uniqueness of beam pattern features in mmWave–enabled devices and propose a scalable security mechanism for the detection of wireless spoofing attacks in NGIoT networks. This uniqueness is proven to exist due to the non–ideal manufacturing of antenna arrays used in mmWave–enabled devices. In our approach, when legitimate mmWave–enabled IoT devices enrol into the network, their unique beam features are learned by a learning model developed at the network server. Then, during data transmission, network base stations (gNBs)/Access Points (APs) measure the beam features from the received RF signals and send them to the network server for the detection of anomalies. We develop our learning model based on Deep Autoencoders (DAEs) that are an effective tool for anomaly detection. Fortunately, the beam feature extraction can be performed using the beam searching mechanism that is already provided in mmWave standards (5G–NR and IEEE 802.11ad). Thus, feature extraction does not introduce any signal processing overheads to the system. Moreover, the proposed mechanism imposes zero computation/communication overhead to the resource—constrained IoT nodes. In our experiments, we reached 98.6% accuracy in the detection of illegitimate devices which confirms the effectiveness of the proposed approach. Mohammad Reza Nosouhi, Keshav Sood, Marthie Grobler, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | A Sparse Protocol Parsing Method for IIoT Protocols Based on HMM hybrid modelabstractAs the intelligentization of Industrial Internet of Things (IIoT) broke the relatively closed and credible industrial environment, IIoT faces increasingly serious security problems. The commonly used vulnerability discovery method is protocol reverse engineering. However, it is difficult to analyze IIoT protocols with existing protocol reverse engineering approaches, as they influence the normal operation or have spare sample data. In this paper, a sparse protocol parsing method for IIoT protocols is proposed. The parsing method expands the samples of the captured IIoT protocol message sequences using a genetic algorithm (GA), which designs its fitness function based on the protocol response data to select high-quality samples. By combining the GA with the hidden Markov model (HMM) with lower algorithm complexity, a hybrid parsing model is constructed to improve accuracy in a gradual evolution way. Through comparison experiments on various IIoT protocols, our HMM hybrid model has better performance than RNN hybrid models under sparse samples. Yunhua He, Jialong Shen, Ke Xiao 0001, Keshav Sood, Chao Wang 0061, Limin Sun 0001 |
ICC | 4 |
| 2020 | Adaptive service function chaining mappings in 5G using deep Q-learning
Guanglei Li, Bohao Feng, Huachun Zhou, Keshav Sood, Shui Yu 0001 |
Comput. Commun. | 5 |
| 2020 | Alleviating Heterogeneity in SDN-IoT Networks to Maintain QoS and Enhance SecurityabstractSoftware-defined networks (SDNs) offer unique and attractive solutions to solve challenging management issues in Internet of Things (IoT)-based large-scale multi-technological networks. SDN-IoT network collaboration is innovative and attractive but expected to be extremely heterogeneous in future generation IoT systems. For example, multi-technology network, network externality, and nodes heterogeneity in SDN-IoT may seriously affect the flow or application-specific quality-of-service (QoS) requirements. Furthermore, it highly influences security adoption in a network of interconnected IoT nodes. We observe that both QoS and security are interdependent and nonnegligible factors, thus we emphasize that in order to alleviate heterogeneity it is inevitable to study both these factors hand to hand (or vice versa). With this aim, first, we discuss significant and reasonable cases to encourage researchers to study QoS and security integrally in order to alleviate heterogeneity at SDN-IoT control plane. Second, we propose a framework which successfully transforms the m heterogeneous controllers to n homogeneous controller groups. The key metric of our observation and analysis is the SDN controller's response time. Following this, to validate our approach, we use the mathematical model and a proof of concept (PoC) in a virtual SDN ecosystem is demonstrated. From performance evaluation, we observe that the proposed framework significantly alleviates heterogeneity which helps to maintain QoS and enhance security. This fundamental analysis will enable network security individuals to deal heterogeneity, QoS, and security, of SDN-IoT, in more successful and promising ways. Keshav Sood, Kallol Krishna Karmakar, Shui Yu 0001, Vijay Varadharajan, Shiva Raj Pokhrel, Yong Xiang 0001 |
IEEE Internet Things J. | 1 |
| 2020 | Reliability-aware virtual network function placement in carrier networks
Lang Fan, Keshav Sood, Yunqing Wang, Shui Yu 0001 |
J. Netw. Comput. Appl. | 3 |
| 2020 | PASPORT: A Secure and Private Location Proof Generation and Verification FrameworkabstractRecently, there has been a rapid growth in location-based systems and applications in which users submit their location information to service providers in order to gain access to a service, resource, or reward. We have seen that in these applications, dishonest users have an incentive to cheat on their location. Unfortunately, no effective protection mechanism has been adopted by service providers against these fake location submissions. This is a critical issue that causes severe consequences for these applications. Motivated by this, we propose the Privacy-Aware and Secure Proof Of pRoximiTy (PASPORT) scheme in this article to address the problem. Using PASPORT, users submit a location proof (LP) to service providers to prove that their submitted location is true. PASPORT has a decentralized architecture designed for ad hoc scenarios in which mobile users can act as witnesses and generate LPs for each other. It provides user privacy protection as well as security properties, such as unforgeability and nontransferability of LPs. Furthermore, the PASPORT scheme is resilient to prover-prover collusions and significantly reduces the success probability of Prover-Witness collusion attacks. To further make the proximity checking process private, we propose P-TREAD, a privacy-aware distance bounding protocol and integrate it into PASPORT. To validate our model, we implement a prototype of the proposed scheme on the Android platform. Extensive experiments indicate that the proposed method can efficiently protect location-based applications against fake submissions. Mohammad Reza Nosouhi, Keshav Sood, Shui Yu 0001, Marthie Grobler |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2019 | SDN-Capable IoT Last-Miles: Design ChallengesabstractWe propose to redesign SDN control in IoT lastmiles so as to extend the capability from edge routers to devices (end-node things enabled with SDN capabilities). Our approach put forward existing and new challenges that are impossible to be resolved using the seminal approaches directly. The main challenges we identify are: scalability of sensor nodes/things, maintaining the security of the system, and fulfilling the Quality of Service (QoS) requirement of all IoT applications. Firstly, we elaborate and discuss the aforementioned critical and fundamental challenges that require immediate investigations. Secondly, we propose a policy-driven framework for secure routing and conduct performance modeling and analysis. Further, in the QoS context, we have proposed an intent-based flow offloading scheme to meet the flow-specific QoS requirements. More importantly, we have developed an analysis by modeling TCP-based flows over WiFi, thus forming the required SDN-IoT network, by using mathematics as a tool for reasoning our challenges. With new insights from our analysis, the feasibility of the proposed approach is validated using factors such as path set-up time in SDN-IoT networks, SDN controller/devices throughputs, packets losses and response time of the controller. Keshav Sood, Shiva Raj Pokhrel, Kallol Krishna Karmakar, Vijay Varadharajan, Shui Yu 0001 |
GLOBECOM | 1 |
| 2018 | Towards QoS and Security in Software-Driven Heterogeneous Autonomous NetworksabstractAutonomous Networks has a potential to solve complex and critical management issues in large scale multi- technological networks. Further, the novel paradigms, i.e., Software-Defined Networks (SDN) and Network Function Vir- tualization (NFV) offer unique and attractive solutions for Autonomous Networks or Systems (AS). However, despite of these attractive features, we observed two critical issues in this interlinked multi-technology domain. Firstly, the network externality and nodes heterogeneity seriously effected the flow specific Quality of Service (QoS). Secondly, it influenced se- curity adoption in an network of interconnected nodes. We observed that QoS and security both are non-negligible and inter-dependent factors. This motivates us to investigate solution towards a) alleviating the SDN network heterogeneity at control layer, and b) to strengthen the network security after alleviating the heterogeneity. In this research effort, we have attempted to alleviate the first issue. Firstly, significant and reasonable examples have been cited to motivate researchers to study QoS and security hand-to-hand. Secondly, a theoretical high level frame work has been proposed with the aim to transform the N heterogeneous controllers to n homogeneous controller groups. Following this, we have demonstrated that our approximation method to transform heterogeneous systems to homogeneous groups works well even at high degree of heterogeneity in the network. We have shown our theoretical analysis results using Matlab. Following this, we have shown the Proof of Concept (PoC) of our approach in SDN-NFV ecosystem using Mininet. This early analysis will help researchers to address heterogeneity and security in more effective ways. Keshav Sood, Kallol Krishna Karmakar, Vijay Varadharajan, Udaya Kiran Tupakula, Shui Yu 0001 |
GLOBECOM | 1 |
| 2016 | Software-Defined Wireless Networking Opportunities and Challenges for Internet-of-Things: A ReviewabstractWith the emergence of Internet-of-Things (IoT), there is now growing interest to simplify wireless network controls. This is a very challenging task, comprising information acquisition, information analysis, decision-making, and action implementation on large scale IoT networks. Resulting in research to explore the integration of software-defined networking (SDN) and IoT for a simpler, easier, and strain less network control. SDN is a promising novel paradigm shift which has the capability to enable a simplified and robust programmable wireless network serving an array of physical objects and applications. This paper starts with the emergence of SDN and then highlights recent significant developments in the wireless and optical domains with the aim of integrating SDN and IoT. Challenges in SDN and IoT integration are also discussed from both security and scalability perspectives. Keshav Sood, Shui Yu 0001, Yong Xiang 0001 |
IEEE Internet Things J. | 1 |