Pratik Satam

dblp:167/3515 · DBLP profile ↗
← Back
19ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0003-3139-8333ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 8 · 2 first-author · 4 since 2021Systems, architecture and hardware · 5 · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LLM-MC-Affect: LLM-Based Monte Carlo Modeling of Affective Trajectories and Latent Ambiguity for Interpersonal Dynamic Insight
abstract
Emotional coordination is a core property of human interaction that shapes how relational meaning is constructed in real time. While text-based affect inference has become increasingly feasible, prior approaches often treat sentiment as a deterministic point estimate for individual speakers, failing to capture the inherent subjectivity, latent ambiguity, and sequential coupling found in mutual exchanges. We introduce LLM-MC-Affect, a probabilistic framework that characterizes emotion not as a static label, but as a continuous latent probability distribution defined over an affective space. By leveraging stochastic LLM decoding and Monte Carlo estimation, the methodology approximates these distributions to derive high-fidelity sentiment trajectories that explicitly quantify both central affective tendencies and perceptual ambiguity. These trajectories enable a structured analysis of interpersonal coupling through sequential cross-correlation and slope-based indicators, identifying leading or lagging influences between interlocutors. To validate the interpretive capacity of this approach, we utilize teacher-student instructional dialogues as a representative case study, where our quantitative indicators successfully distill high-level interaction insights such as effective scaffolding. This work establishes a scalable and deployable pathway for understanding interpersonal dynamics, offering a generalizable solution that extends beyond education to broader social and behavioral research.
Yu-Zheng Lin, Bono Po-Jen Shih, John Paul Martin Encinas, Elizabeth Victoria Abraham Achom, Karan Himanshu Patel, Jesus Horacio Pacheco, Sicong Shao, Jyotikrishna Dass, Soheil Salehi, Pratik Satam
ACL (1)10
2026 Photogrammetry-Enabled Digital Twins for Semiconductor Education and Workforce Development
abstract
Semiconductor manufacturing is a critical and vital industry impacting all aspects of modern life centered around artificial intelligence (AI). The demand for semiconductors has skyrocketed with the emergence of the Fourth Industrial Revolution (4IR) technologies that integrate traditional manufacturing with modern technologies such as cloud computing, machine learning, and artificial intelligence. These transformations have created an ever-increasing need to manufacture semiconductors, creating a massive investment and the need for new fabrication capabilities over the next decade, presenting an enormous workforce development challenge. The complexity of the semiconductor manufacturing environment and equipment used exacerbates this challenge, making this workforce development a pressing need. Although not new, photogrammetry has proven transformative in industry and education, providing customizable visual digital twins of processes, facilities, and equipment. This paper highlights our ongoing efforts to use photogrammetry to build 3D models and level 1 Digital Twins, that will integrate into our PRISM platform. To facilitate this curriculum development effort, we aim to build experiential learning exercises in the PRISM platform, focusing on equipment setup, equipment usage, and basic debugging and problem solving, capitalizing on the PRISM platform’s ability to measure student sentiment while performing experiential learning to personalize and generate new content for their training needs using Retrieval-Augmented Generation (RAG) and generative AI. Our goal is to model different different stages of semiconductor manufacturing, namely 1) Photoresist Application, 2) Lithography, 3) Nickel Chromium Deposition, and 4) Lift-off. To achieve this goal, we are modeling Laurell Spin Coater, ABM Mask Aligner, Thermal Physical Vapor Evaporator, Ellipsometer, and a Profilometer using Photogrammetry. On integration into the PRISM platform, capitalizing on the PRISM platform’s ability to personalize training content through generative AI via student sentiment analysis for different target student groups, we aim to rapidly create semiconductor training experiential learning exercises for High School, Undergraduate, and Graduate Students, helping create a specialized semiconductor workforce to meet the current pressing semiconductor workforce needs.
John Paul Martin Encinas, Yu-Zheng Lin, Bono Po-Jen Shih, Josh Dean, Anh Minh Nguyen, Aurora Namjoshi, Ahmed Alhamadah, Shalaka Satam, Soheil Salehi, Pratik Satam
ACM Great Lakes Symposium on VLSI11
2026 LeakSEAL: Power Side-Channel Leakage Analysis and Mitigation for Secure Edge AI Learning
abstract
On-chip learning enables machine learning models to be trained or updated directly on specialized hardware rather than on external CPUs or GPUs, offering lower latency, improved energy-efficiency, enhanced privacy, and real-time adaptability for edge devices. In Spiking Neural Networks (SNNs), this capability relies on dynamic synaptic weight adaptation, but such adaptability also introduces significant security risks. In this work, we demonstrate a power side-channel attack on a quantized SNN implemented on a CW305 FPGA platform using ChipWhisperer. Our analysis identifies consistent power leakage patterns associated with neuron update operations, allowing an attacker to infer internal model attributes without direct access to the model’s weights or inputs. We further perform Correlation Power Analysis (CPA) with a Hamming Weight leakage model to recover secret synaptic weights with high confidence using as few as 1,500 power traces. These results expose critical vulnerabilities in on-chip learning systems and SNN architectures, highlight realistic threats to IoT and edge applications, and motivate mitigation strategies at the software-hardware boundary, including secure design practices, cryptographic protections, and access control mechanisms, without significantly degrading performance.
Veeramani Pugazhenthi, Md Muhtasim Alam Chowdhury, Sujan Ghimire, Harish Kumar Dharavath, Parsa Mirfasihi, Nader Sehatbakhsh, Pratik Satam, Soheil Salehi
ACM Great Lakes Symposium on VLSI7
2026 Can Agents Secure Hardware? Evaluating Agentic LLM-Driven Obfuscation for IP Protection
Sujan Ghimire, Parsa Mirfasihi, Md Muhtasim Alam Chowdhury, Veeramani Pugazhenthi, Harish Kumar Dharavath, Farshad Firouzi, Rozhin Yasaei, Pratik Satam, Soheil Salehi
VTS8
2026 Ai/ml based detection and categorization of covert communication in IPv6 network
Mohammad Wali Ur Rahman, Yu-Zheng Lin, Carter Weeks, David Ruddell, Jeff Gabriellini, Bill Hayes, Salim Hariri, Pratik Satam, Edward V. Ziegler Jr
Cybersecur.8
2025 Transformers for Secure Hardware Systems: Applications, Challenges, and Outlook
Banafsheh S. Latibari, Najmeh Nazari, Avesta Sasan, Houman Homayoun, Pratik Satam, Soheil Salehi, Hossein Sayadi
ACM Great Lakes Symposium on VLSI5
2025 HWREx: AI-enabled Hardware Weakness and Risk Exploration and Storytelling Framework with LLM-assisted Mitigation Suggestion
abstract
The growing complexity of modern computing frameworks has led to an increase in cybersecurity vulnerabilities reported to the National Vulnerability Database (NVD). Extracting meaningful trends from this vast amount of unstructured data is challenging without proper tools and methodologies. Existing approaches lack a holistic strategy for vulnerability mitigation and prediction and effective knowledge extraction from the Common Weakness Enumeration (CWE), Common Vulnerability Exposure (CVE), and Common Attack Pattern Enumeration and Classification (CAPEC) databases. We introduce the AI-enabled Hardware Weakness and Risk Exploration and Storytelling Framework with LLM-assisted Mitigation Suggestion (HWREx), designed to address hardware vulnerabilities and IoT security. Our architecture features an Ontology-driven Storytelling capability that automates ontology updates to track vulnerability patterns and evolution over time, while offering mitigation strategies. It also clarifies the complex interrelations among CVEs, CWEs, and CAPECs through interactive visual knowledge graphs. Our framework achieved accuracy rates of 62% for CWE-CWE, 83% for CWE-CVE, and 77% for CWE-CAPEC linkage predictions. These graphs are instrumental for in-depth hardware weakness analysis and enable HWREx to deliver comprehensive assessments and actionable mitigation strategies. Additionally, HWREx utilizes Generative Pre-trained Transformers (GPT) to offer tailored mitigation suggestions.
Sujan Ghimire, Yu-Zheng Lin, Muntasir Mamun, Md Muhtasim Alam Chowdhury, Farhad Alemi, Shuyu Cai, Jinduo Guo, Banafsheh S. Latibari, Setareh Rafatirad, Pratik Satam, Soheil Salehi
ACM Trans. Design Autom. Electr. Syst.12
2024 Photogrammetry for Digital Twinning Industry 4.0 (I4) Systems
abstract
The onset of Industry 4.0 is rapidly transforming the manufacturing world through the integration of cloud computing, machine learning (ML), artificial intelligence (AI), and universal network connectivity, resulting in performance optimization and increased productivity. Digital Twins (DT) are one such transformational technology that leverages software systems to replicate physical process behavior, and representing it in a digital environment. This paper aims to explore the use of photogrammetry (which is the process of reconstructing physical objects into virtual 3D models using photographs) and 3D Scanning techniques to create accurate visual representation of the ‘Physical Process', to interact with the ML/AI based behavior models. To achieve this, we have used a readily available consumer device, the iPhone 15 Pro, which features stereo vision capabilities, to capture the depth of an Industry 4.0 system. By processing these images using 3D scanning tools, we created a raw 3D model for 3D modeling and rendering software for the creation of a DT model. The paper highlights the reliability of this method by measuring the error rate in between the ground truth (measurements done manually using a tape measure) and the final 3D model created using this method. The overall mean error is 4.97 % and the overall standard deviation error is 5.54% between the ground truth measurements and their photogrammetry counterparts. The results from this work indicate that photogrammetry using consumer-grade devices can be an efficient and cost-efficient approach to creating DTs for smart manufacturing, while the approaches flexibility allows for iterative improvements of the models over time.
Ahmed Alhamadah, Muntasir Mamun, Henry Harms, Mathew Redondo, Yu-Zheng Lin, Soheil Salehi, Pratik Satam
AICCSA8
2024 Interactive Framework for Cybersecurity Education and Future Workforce Development
abstract
This research-to-practice paper presents a novel pedagogical tool for hardware cybersecurity education and workforce development. The growing importance of hardware security has made it essential for individuals and organizations to understand hardware security principles and best practices. However, the current educational curriculum falls short of fulfilling these emerging demands due to the rapidly changing hardware security landscape and limited opportunities for hands-on training. To address these challenges, we propose and have developed the Interactive Hardware and Cybersecurity (I-HaC) Educational Framework, a pedagogical educational framework that supplements existing courses by leveraging generative AI for individualized instruction related to hardware and cybersecurity, data mining, and applied Machine Learning (ML), as well as data visualization to enhance cybersecurity education and workforce development. The framework is designed to be utilized by graduate and undergraduate Electrical and Computer Engineering (ECE) and Computer Science (CS) students for a comprehensive introduction to cybersecurity exploits and countermeasures in an interactive manner with hands-on components. Using I-HaC, we have developed tailored lab components for a diverse range of students and intend to release I-HaC as open-source for the benefit of the ECE and CS education community.
Sujan Ghimire, Md Muhtasim Alam Chowdhury, Ryan Tsang, Richard C. Yarnell, Emma Heckert, Jaeden Wolf Carpenter, Yu-Zheng Lin, Muntasir Mamun, Ronald F. DeMara, Setareh Rafatirad, Pratik Satam, Soheil Salehi
FIE11
2023 Quantized Transformer Language Model Implementations on Edge Devices
abstract
Large-scale transformer-based models like the Bidi-rectional Encoder Representations from Transformers (BERT) are widely used for Natural Language Processing (NLP) applications, wherein these models are initially pre-trained with a large corpus with millions of parameters and then fine-tuned for a downstream NLP task. One of the major limitations of these large-scale models is that they cannot be deployed on resource- constrained devices due to their large model size and increased inference latency. In order to overcome these limitations, such large-scale models can be converted to an optimized FlatBuffer format, tailored for deployment on resource-constrained edge devices. Herein, we evaluate the performance of such FlatBuffer transformed MobileBERT models on three different edge devices, fine-tuned for Reputation analysis of English language tweets in the Rep Lab 2013 dataset. In addition, this study encompassed an evaluation of the deployed models, wherein their latency, performance, and resource efficiency were meticulously assessed. Our experiment results show that, compared to the original BERT large model, the converted and quantized MobileBERT models have 160x smaller footprints for a 4.1 % drop in accuracy while analyzing at least one tweet per second on edge devices. Furthermore, our study highlights the privacy-preserving aspect of TinyML systems as all data is processed locally within a serverless environment.
Mohammad Wali Ur Rahman, Murad Mehrab Abrar, Hunter Gibbons Copening, Salim Hariri, Sicong Shao, Pratik Satam, Soheil Salehi
ICMLA6
2022 A BERT-based Deep Learning Approach for Reputation Analysis in Social Media
abstract
Social media has become an essential part of the modern lifestyle, with its usage being highly prevalent. This has resulted in unprecedented amounts of data generated from users in social media, such as users' attitudes, opinions, interests, purchases, and activities across various aspects of their lives. Therefore, in a world of social media, where its power has shifted to users, actions taken by companies and public figures are subject to constantly being under scrutiny by influential global audiences. As a result, reputation management in social media has become essential as companies and public figures need to maintain their reputation to preserve their reputational capital. However, domain experts still face the challenge of lacking appropriate solutions to automate reliable online reputation analysis. To tackle this challenge, we proposed a novel reputation analysis approach based on the popular language model BERT (Bidirectional Encoder Representations from Transformers). The proposed approach was evaluated on the reputational polarity task using RepLab 2013 dataset. Compared to previous works, we achieved 5.8% improvement in accuracy, 26.9% improvement in balanced accuracy, and 21.8% improvement in terms of F-score.
Mohammad Wali Ur Rahman, Sicong Shao, Pratik Satam, Salim Hariri, Chris Padilla, Zoe Taylor, Carlos Nevarez
AICCSA3
2022 AI-based Arabic Language and Speech Tutor
abstract
In the past decade, we have observed a growing interest in using technologies such as artificial intelligence (AI), machine learning, and chatbots to provide assistance to language learners, especially in second language learning. By using AI and natural language processing (NLP) and chatbots, we can create an intelligent self-learning environment that goes beyond multiple-choice questions and/or fill in the blank exercises. In addition, NLP allows for learning to be adaptive in that it offers more than an indication that an error has occurred. It also provides a description of the error, uses linguistic analysis to isolate the source of the error, and then suggests additional drills to achieve optimal individualized learning outcomes. In this paper, we present our approach for developing an Artificial Intelligence-based Arabic Language and Speech Tutor (AI-ALST) for teaching the Moroccan Arabic dialect. The AI-ALST system is an intelligent tutor that provides analysis and assessment of students learning the Moroccan dialect at University of Arizona (UA). The AI-ALST provides a self-learned environment to practice each lesson for pronunciation training. In this paper, we present our initial experimental evaluation of the AI-ALST that is based on MFCC (Mel frequency cepstrum coefficient) feature extraction, bidirectional LSTM (Long Short-Term Memory), attention mechanism, and a cost-based strategy for dealing with class-imbalance learning. We evaluated our tutor on the word pronunciation of lesson 1 of the Moroccan Arabic dialect class. The experimental results show that the AI-ALST can effectively and successfully detect pronunciation errors and evaluate its performance by using$\boldsymbol{F}_{\mathbf{1}}$- score, accuracy, precision, and recall.
Sicong Shao, Saleem Alharir, Salim Hariri, Pratik Satam, Sonia Shiri, Abdessamad Mbarki
AICCSA4
2021 Multi-Layer Mapping of Cyberspace for Intrusion Detection
abstract
The ubiquity and vulnerability of computer applications make them ideal places for intrusion attacks that increase in intensity and complexity. Computer applications have a relationship with various networks, physical components, host devices, and users with different roles and requirements. Therefore, securing computer applications in such a complex and dynamic cyberspace is urgent and challenging. This paper attempts to tackle the challenges by proposing a Multi-Layer Abnormal Behaviors Analysis (MLABA) framework for intrusion detection associated with three layers (i.e., system, process, and network layers) in cyberspace for characterizing their normal operations and detect any abnormal behavior that might be triggered by malicious activities. The proposed technique was evaluated on several popular applications (i.e., Firefox, Opera, Chrome, and Ruby). The experimental results demonstrate the feasibility of MLABA framework that can detect the intrusion and abuse for applications.
Sicong Shao, Pratik Satam, Shalaka Satam, Khalid Al-Awady, Gregory Ditzler, Salim Hariri, Cihan Tunc
AICCSA2
2021 WIDS: An Anomaly Based Intrusion Detection System for Wi-Fi (IEEE 802.11) Protocol
abstract
Over the last few decades, the Internet has seen unprecedented growth, with over 4.57 billion active users as of July 2022, encompassing 59% of the global population. In recent years, we have seen an increase in mobile computing and the Internet of Things (IoT), allowing more users to communicate through the Internet using wireless devices. Modern Internet users use their wireless IoT devices for a wide variety of services that include cloud computing and storage, social networking, content services, online banking, shopping, to name a few. Moreover, with the omnipresence of IoT devices, wireless networks are used for services like device control, user authentication, etc. Wi-Fi is the network of choice for most of these wireless communications. Although Wi-Fi networks have improved over recent years, little has been done to secure Wi-Fi networks against attacks. In this article, we present a Wireless Intrusion Detection System (WIDS); an anomaly behavior analysis approach to detect attacks on Wi-Fi networks with high accuracy and low false alarms. In this approach, we model the normal behavior of the Wi-Fi protocol, using n-grams, and use machine learning models to classify Wi-Fi traffic flows as normal or malicious. We have extensively tested our approach on multiple datasets collected locally at the University of Arizona and AWID family of datasets. Our approach can successfully detect all attacks on Wi-Fi protocols with low false positives (0.0174) and a varying low rate of false negatives for different attacks.
Pratik Satam, Salim Hariri
IEEE Trans. Netw. Serv. Manag.1
2020 Multi-level Bluetooth Intrusion Detection System
abstract
Large scale deployment of IoT devices has made Bluetooth Protocol (IEEE 802.15.1) the wireless protocol of choice for close-range communications. Devices such as keyboards, smartwatches, headphones, computer mouse, and various wearable connecting devices use Bluetooth network for communication. Moreover, Bluetooth networks are widely used in medical devices like heart monitors, blood glucose monitors, asthma inhalers, and pulse oximeters. Also, Bluetooth has replaced cables for wire-free equipment in a surgical environment. In hospitals, devices communicate with one another, sharing sensitive and critical information over Bluetooth scatter-networks. Thus, it is imperative to secure the Bluetooth networks against attacks like Man in the Middle attack (MITM), eavesdropping attacks, and Denial of Service (DoS) attacks. This paper presents a Multi-Level Bluetooth Intrusion Detection System (ML-BIDS) to detect malicious attacks against Bluetooth devices. In the ML-IDS framework, we perform continuous device identification and authorization in Bluetooth networks following the zero-trust principle [ref]. The ML-BIDS framework includes an anomaly-based intrusion detection system (ABIDS) to detect attacks on the Bluetooth protocol. The ABIDS tracks the normal behavior of the Bluetooth protocol by comparing it with the Bluetooth protocol state machine. Bluetooth frame flows consisting of Bluetooth frames received over 10 seconds are split into n-grams to track the current state of the protocol in the state machine. We evaluated the performance of several machine learning algorithms like C4.5, Adaboost, SVM, Naive Bayes, Jrip, and Bagging to classify normal Bluetooth protocol flows from abnormal Bluetooth protocol flows. The ABIDS detects attacks on Bluetooth protocols with a precision of up to 99.6% and recall up to 99.6%. The ML-BIDS framework also performs whitelisting of the devices on the Bluetooth network to prevent unauthorized devices from connecting to the network. ML-BIDS uses a combination of the Bluetooth Address, mac address, and IP address to uniquely identify a Bluetooth device connecting to the network, and hence ensuring only authorized devices can connect to the Bluetooth network.
Shalaka Satam, Pratik Satam, Salim Hariri
AICCSA2
2018 Malicious HTML File Prediction: A Detection and Classification Perspective with Noisy Data
abstract
Cybersecurity plays a critical role in protecting sensitive information and the structural integrity of networked systems. As networked systems continue to expand in numbers as well as in complexity, so does the threat of malicious activity and the necessity for advanced cybersecurity solutions. Furthermore, both the quantity and quality of available data on malicious content as well as the fact that malicious activity continuously evolves makes automated protection systems for this type of environment particularly challenging. Not only is the data quality a concern, but the volume of the data can be quite small for some of the classes. This creates a class imbalance in the data used to train a classifier; however, many classifiers are not well equipped to deal with class imbalance. One such example is detecting malicious HMTL files from static features. Unfortunately, collecting malicious HMTL files is extremely difficult and can be quite noisy from HTML files being mislabeled. This paper evaluates a specific application that is afflicted by these modern cybersecurity challenges: detection of malicious HTML files. Previous work presented a general framework for malicious HTML file classification that we modify in this work to use a χ2feature selection technique and synthetic minority oversampling technique (SMOTE). We experiment with different classifiers (i.e., AdaBoost, Gentle-Boost, RobustBoost, RusBoost, and Random Forest) and a pure detection model (i.e., Isolation Forest). We benchmark the different classifiers using SMOTE on a real dataset that contains a limited number of malicious files (40) with respect to the normal files (7,263). It was found that the modified framework performed better than the previous framework's results. However, additional evidence was found to imply that algorithms which train on both the normal and malicious samples are likely overtraining to the malicious distribution. We demonstrate the likely overtraining by determining that a subset of the malicious files, while suspicious, did not come from a malicious source.
Samuel Hess, Pratik Satam, Gregory Ditzler, Salim Hariri
AICCSA2
2018 Bluetooth Intrusion Detection System (BIDS)
abstract
With the rapid deployment of IOT devices, Bluetooth networks, which form Personal Area Networks(PAN), have become the wireless network of choice for small range/indoor communications networks. Bluetooth is widely used to deliver audio streams (e.g.: Bluetooth headphones, Music systems in cars), connecting peripherals devices to more powerful devices (e.g.: keyboards to computers), connecting wearable technology like smart watches, heart monitors and fitness trackers. It's imperative that Bluetooth networks (like other wireless networks) are secure against cyberattacks such as Man In The Middle Attacks(MITM), Denial of Service attacks(DoS), etc. Moreover, Bluetooth is used heavily in mobile devices/ sensors, and consequently they become sensitive to battery utilization attacks; this type of attacks requires the Bluetooth devices to be secure against different battery draining attacks. As a part of this paper we present an anomaly-based intrusion detection system for Bluetooth networks; Bluetooth IDS (BIDS). The BIDS use an n-gram based approach to characterize the normal behavior of the Bluetooth protocol. Smoothing techniques like Jelinek-Mercer smoothing was used to improve the machine learning algorithm used for detecting abnormal Bluetooth operations. Machine learning algorithms like C4.5, AdaBoostMl, SVM, Naïve Bayes, RIPPER, Bagging were used to build the behavior models for the Bluetooth protocol. The developed models had high accuracy with precision up to 99.6% and recall up to 99.6%.
Pratik Satam, Shalaka Satam, Salim Hariri
AICCSA1
2016 Anomaly behavior analysis of website vulnerability and security
abstract
The world wide web has grown exponentially over the previous decade in terms of its size that is currently over a billion sties, as well as the number of users. In fact, web usage has become pervasive to touch all aspects of our life, economy and education. These rapid advances have also significantly increase the vulnerabilities of websites that are being hacked on a daily basis. According to White Hat security's “2015 Website Security Statistics Report” more than 86% of all websites have one or more critical vulnerability and the likelihood of information leakage is 56%. With no effective website security measures in place, one can expect the website security to be even more critical. The main research goal of this paper is to overcome this challenge by presenting an online anomaly behavior analysis of websites (e.g., HTML files) to detect any malicious codes or pages that have been injected by web attacks. Our anomaly analysis approach utilizes feature selection, data mining, data analytics and statistical techniques to identify accurately the webpage contents that have been compromised or can be exploited by attacks such as phishing attacks, cross site scripting attacks, html injection attacks, malware insertion attacks, just to name a few. We have validated our approach on more than 10,000 files and showed that our approach can detect malicious HTML files with a true positive rate of 99% and a false positive rate of 0.8% for abnormal files.
Pratik Satam, Douglas Kelly, Salim Hariri
AICCSA1
2015 Wireless Anomaly Detection Based on IEEE 802.11 Behavior Analysis
abstract
Wireless communication networks are pervading every aspect of our lives due to their fast, easy, and inexpensive deployment. They are becoming ubiquitous and have been widely used to transfer critical information, such as banking accounts, credit cards, e-mails, and social network credentials. The more pervasive the wireless technology is going to be, the more important its security issue will be. Whereas the current security protocols for wireless networks have addressed the privacy and confidentiality issues, there are unaddressed vulnerabilities threatening their availability and integrity (e.g., denial of service, session hijacking, and MAC address spoofing attacks). In this paper, we describe an anomaly based intrusion detection system for the IEEE 802.11 wireless networks based on behavioral analysis to detect deviations from normal behaviors that are triggered by wireless network attacks. Our anomaly behavior analysis of the 802.11 protocols is based on monitoring the n-consecutive transitions of the protocol state machine. We apply sequential machine learning techniques to model the n-transition patterns in the protocol and characterize the probabilities of these transitions being normal. We have implemented several experiments to evaluate our system performance. By cross validating the system over two different wireless channels, we have achieved a low false alarm rate (<;0.1%). We have also evaluated our approach against an attack library of known wireless attacks and has achieved more than 99% detection rate.
Hamid Reza Alipour, Youssif B. Al-Nashif, Pratik Satam, Salim Hariri
IEEE Trans. Inf. Forensics Secur.3