Suryadipta Majumdar

dblp:175/5819 · DBLP profile ↗
← Back
38ranked-venue papers
8as first author
26since 2021 · last 2026
0000-0002-6501-4214ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 7 first-author · 20 since 2021Computer networks · 3 · 3 since 2021
YearPublicationVenuePosition
2026 NEXUS: Towards Accurate and Scalable Mapping between Vulnerabilities and Attack Techniques
Ehsan Khodayarseresht, Suryadipta Majumdar, Serguei A. Mokhov, Mourad Debbabi
NDSS2
2026 ForenThings: An Interactive Framework for Crime Scene Reconstruction in IoT Forensics
abstract
In IoT platforms, devices and sensors can interact with each other via smart apps that utilize automation settings preconfigured by users, resulting in significant amounts of potential forensic data. Existing IoT forensic approaches can pinpoint relevant data sources for specific activities in smart environments using static code analysis and instrumentation techniques. However, recent IoT platforms like SmartThings no longer run application code on their infrastructure, making access to source code impossible for existing IoT forensic solutions. To bridge this gap, this paper introduces ForenThings , an interactive framework for crime scene reconstruction in smart environments. The main idea is to convert each IoT device and smart app to a responsive agent, enabling them to participate in a forensic investigation of a security incident collaboratively. Instead of relying on static code analysis or instrumentation, ForenThings reconstructs the scene from the device and app events forwarded by the IoT platform. We develop a ForenThings prototype for the SmartThings platform and test its effectiveness for both normal scenarios and 12 real-world IoT attack scenarios. The evaluation shows that ForenThings can achieve 100% data provenance coverage in reconstructing various crime scenes in a smart environment with negligible runtime and resource overhead.
Ehsan Khodayarseresht, Sofya Smolyakova, Lianying Zhao, Armin Mansouri, Suryadipta Majumdar, Mauro Conti
ACM Trans. Internet Things5
2025 CapMan: Detecting and Mitigating Linux Capability Abuses at Runtime to Secure Privileged Containers
Alireza Moghaddas Borhan, Hugo Kermabon-Bobinnec, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar
ESORICS (3)5
2025 Identifying and Addressing User-level Security Concerns in Smart Homes Using "Smaller" LLMs
abstract
With the rapid growth of smart home IoT devices, users are increasingly exposed to various security risks, as evident from recent studies. While seeking answers to know more on those security concerns, users are mostly left with their own discretion while going through various sources, such as online blogs, and technical manuals; which may render higher complexity to the regular users to extract the necessary information from. This requirement does not go along with the common mindsets of smart home users and hence threatens the security of smart homes furthermore. In this paper, we aim to identify and address the major user-level security concerns in smart homes. Specifically, we develop a novel dataset of Q&A from public forums, capturing practical security challenges faced by smart home users. We extract major security concerns in smart homes from our dataset by leveraging the Latent Dirichlet Allocation (LDA). We fine-tune relatively “smaller” transformer models, such as T5 and Flan-T5, on this dataset to build a QA system tailored for smart home security. Unlike larger models like GPT and Gemini, which are powerful but often resource hungry, and requiring data sharing, smaller models are more feasible for deployment in resource-constrained or privacy-sensitive environments, like smart homes. The dataset is manually curated and supplemented with synthetic data to explore its potential impact on model performance. This approach significantly improves the system’s ability to deliver accurate and relevant answers, helping users address common security concerns with smart home IoT devices. Our experiments on real-world user concerns show that our work improves the performance of the base models.
Hafijul Hoque Chowdhury, Riad Ahmed Anonto, Sourov Jajodia, Suryadipta Majumdar, Md. Shohrab Hossain
PST4
2025 PerfSPEC: Performance Profiling-Based Proactive Security Policy Enforcement for Containers
abstract
Container environments provide cloud native applications with scalability, flexibility, and portable support. As a popular container orchestrator, Kubernetes facilitates automatic deployment and maintenance of a large number of containerized applications. However, potential misconfigurations, vulnerabilities, or implementation flaws may empower attackers to exploit the Kubernetes cluster. Although existing solutions such as runtime security policy enforcement may prevent an attack, they can be inefficient in large scale container environments. In this paper, we propose a performance profiling-based proactive security policy enforcement solution, namely, PerfSPEC. First, we accelerate the proactivization of policies (which typically requires significant manual effort) by proposing to profile and rank existing policies according to their induced overhead. This allows us to better focus our efforts and greatly improve the overall response time (e.g., by 98% in contrast to less than 49%). Then, we address the performance limitations of existing solutions by leveraging learning-based approaches to predict future events and compute their verification results in advance. As a result, PerfSPEC achieves a viable response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) even for large container environments (up to 800 Pods).
Hugo Kermabon-Bobinnec, Sima Bagheri, Mahmood Gholipourchoubeh, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi
IEEE Trans. Dependable Secur. Comput.4
2025 Cross-Level Security Verification for Network Functions Virtualization (NFV)
abstract
Network Functions Virtualization (NFV) is a popular solution for providing multi-tenant network services on top of existing cloud infrastructures in an agile and cost-effective manner. However, as NFV employs multiple levels of virtualization, it also introduces novel security challenges, such as cloud-level security breaches that are invisible to NFV-level tenants. Towards verifying the security of NFV across all the levels (a.k.a. cross-level security verification), existing solutions are mostly insufficient, as each such solution typically only focuses on one specific level (e.g., cloud, SDN, or SFC), and verifying every level separately would be expensive or even infeasible. In this paper, we propose an efficient and practical system,NFVGuard+, for cross-level security verification for NFV. Particularly, the efficiency ofNFVGuard+is achieved by first performing the costly security verification at one level, and then extrapolating the verification result to other levels through conducting relatively lightweight consistency checks. Additionally, the practicality ofNFVGuard+is ensured by automating the essential steps (e.g., identifying security properties, collecting verification data, and conducting verification) based on a novel Entity-Relationship (ER) model of NFV stack, integrating the approach with OpenStack/Tacker (a popular choice for an NFV deployment), and finally evaluating its effectiveness using both synthetic and real data.
Alaa Oqaily, Mohammad Ekramul Kabir, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar, Makan Pourzandi, Mourad Debbabi, Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001
IEEE Trans. Dependable Secur. Comput.5
2024 On Detecting Malicious Code Injection by Monitoring Multi-Level Container Activities
Md. Olid Hasan Bhuiyan, Shafayat H. Majumder, Suryadipta Majumdar, Md. Shohrab Hossain
CLOSER4
2024 CCSM: Building Cross-Cluster Security Models for Edge-Core Environments Involving Multiple Kubernetes Clusters
abstract
With the emergence of 5G networks and their large scale applications such as IoT and autonomous vehicles, telecom operators are increasingly offloading the computation closer to customers (i.e., on the edge). Such edge-core environments usually involve multiple Kubernetes clusters potentially owned by different providers. Confidentiality concerns could prevent those providers from sharing data freely with each other, which makes it challenging to perform common security tasks such as security verification across different clusters. In this work, we propose a solution for building cross-cluster security models to enable various security analyses, while preserving confidentiality for each cluster. We design a six-step methodology to model both the cross-cluster communication and cross-cluster event dependency, and we apply those models to different security use cases. We implement our solution based on a 5G edge-core environment that involves multiple Kubernetes clusters, and our experimental results demonstrate its efficiency (e.g., less than 8 seconds of processing time for a model with 3,600 edges and nodes) and accuracy (e.g., more than 96% for cross-cluster event prediction).
Mahmood Gholipourchoubeh, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi
CODASPY3
2024 Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall Sequences
Hugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang 0001, Suryadipta Majumdar, Makan Pourzandi
NDSS4
2024 On Continuously Verifying Device-level Functional Integrity by Monitoring Correlated Smart Home Devices
abstract
The correct functionality (can also be called as functional integrity) from a smart device is essential towards ensuring their safe and secure operations. The functional integrity of a device can be defined based on its correctness in sensing and actuating on the physical environment as well as in reporting to the users. As evident from several practical threats (e.g., event spoofing attacks, event masking attacks, sensor failure, vulnerabilities, and misconfigurations), this functional integrity of a device are often breached to cause severe security and safety impacts to their users. To make things worse, such integrity breaches might stay stealthy (due to their non-existence at the user-side) as well as be caused from both devices and apps (due to their vulnerability and misconfiguratons at both physical and cyber spaces). Existing works mainly focus on detecting specific attacks without aiming at verifying functional integrity as a security property. In this paper, we bridge this gap by proposing a continuous approach for smart homes to verify functional integrity at the device-level while monitoring correlated devices. Specifically, our main idea is to learn the correlations among various sensors and actuators in a smart environment, and continuously monitor all the correlated devices to verify functional integrity breaches against various real-world attacks, including spoofing, masking, sensor failure, and device misconfigurations/vulnerabilities. We implement our approach in the context of smart home and evaluate its effectiveness (e.g., for sensors, R2 score of 0.98, and for actuators, accuracy up to 100%) using a public dataset.
Shiva Sunar, Paria Shirani, Suryadipta Majumdar, J. David Brown
WISEC3
2024 Traditional IOCs Meet Dynamic App-Device Interactions for IoT-Specific Threat Intelligence
abstract
While enjoying widespread popularity, IoT faces numerous threats using both the traditional (e.g., common vulnerabilities and exposures (CVEs) and common weakness enumerations (CWEs)) and IoT-specific (e.g., device-application interactions) attack vectors. Therefore, gathering threat intelligence for an IoT environment is equally essential if not more (compared to many other IT environments). However, extracting threat intelligence from an IoT deployment poses several unique challenges. First, most IoT implementations are not logging threat-related information and even if they are, their logging mechanisms require significant additional effort to turn those logs to a threat intelligence. Second, there is no clear definition of Indicators of Compromise (IOCs), which are the key inputs to threat intelligence, in the context of IoT; including how to combine IoT-specific IOCs, including that are involved with the dynamic app–device interactions. In this article, we propose IoTINT, a solution to obtain IoT-specific threat intelligence while addressing the above-mentioned challenges. Specifically, our key ideas are to first enable logging in IoT devices and apps without requiring any code instrumentation (in contrast to the existing approaches), then iteratively finding dynamic interactions between the IoT devices and their apps that are defined by the automation rules and result in various security threats, and finally, combine both the app–device interactions with traditional IOCs (such as CVEs and CWEs) to build a comprehensive threat intelligence for IoT. We implement IoTINT for the Samsung SmartThings, a major smart home platform, and evaluate its performance (e.g., 100% coverage in extracting threat intelligence within 11 s for ten realistic IoT attack scenarios).
Sofya Smolyakova, Ehsan Khodayarseresht, Suryadipta Majumdar
IEEE Internet Things J.3
2024 iCAT+: An Interactive Customizable Anonymization Tool Using Automated Translation Through Deep Learning
abstract
Data anonymization is a viable solution for data owners to mitigate their privacy concerns. However, existing data anonymization tools are inflexible to support various privacy and utility requirements of both data owners and data users. In most cases, this limitation is due to a lack of understanding of those requirements as well as the non-customizability of the existing tools. To address this limitation, we proposeiCAT+, which is an interactive and customizable anonymization approach. More specifically, we first automate the interpretation of data owners’ and data users’ textual requirements by deploying a Convolutional Neural Network (CNN) model for Natural Language Processing (NLP). Second, we introduce the concept of theanonymization spaceto model possible combinations of per-attribute anonymization primitives based on the level of privacy and utility that each primitive provides. Third, we design an ontology model that maps the translated requirements into their appropriate anonymization primitives in the defined anonymization space corresponding to the plain data. Fourth, we evaluate the efficiency and effectiveness ofiCAT+based on both real and synthetic network data. Finally, we assess its usability through a real user study involving participants from industry and research laboratories. Our experiments show the effectiveness and efficiency of our solution (e.g., requirement translation accuracy of 99% at the data owner side and 98% at the data user side, with a computational time of around one minute for the Google cluster dataset).
Momen Oqaily, Mohammad Ekramul Kabir, Suryadipta Majumdar, Yosr Jarraya, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.3
2024 Caught-in-Translation (CiT): Detecting Cross-Level Inconsistency Attacks in Network Functions Virtualization (NFV)
abstract
As one of the main technology pillars of 5G networks, Network Functions Virtualization (NFV) enables agile and cost-effective deployment of network services. However, the multi-level, multi-actor design of NFV may also allow for inconsistency between the different abstraction levels to be mistakenly or intentionally introduced, as shown in recent studies. Serious security issues, such as man-in-the-middle, network sniffing, and DoS, may arise at one abstraction level without being noticed by the victims at another level. Most existing solutions are either limited to one abstraction level of NFV or reliant on direct access to lower-level data which could become inaccessible when managed by different providers. In this paper, by drawing an analogy between cross-level NFV event sequences and natural languages, we propose a Neural Machine Translation-based approach, namely,Caught-in-Translation (CiT), to detect cross-level inconsistency attacks in NFV at runtime. Specifically, we first extract event sequences from different abstraction levels of an NFV stack. We then leverage Long Short-Term Memory (LSTM) to translate the event sequences from one level to another. Finally, we apply both a similarity metric and a Siamese neural network to compare thetranslatedevent sequences with theoriginalones to detect attacks. We integrateCiTinto OpenStack/Tacker, a popular open-source NFV implementation, and evaluate its performance using both real and synthetic data. Experimental results show the benefit of leveraging NMT asCiTachieves AUC≥96.03%, which significantly outperforms traditional SVM-based anomaly detection. We also evaluateCiTin terms of its efficiency, scalability, and robustness for detecting inconsistency attacks in NFV platforms.
Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001
IEEE Trans. Dependable Secur. Comput.3
2024 ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes Clusters
abstract
A large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution.
Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi
IEEE Trans. Inf. Forensics Secur.4
2023 A Tenant-based Two-stage Approach to Auditing the Integrity of Virtual Network Function Chains Hosted on Third-Party Clouds
abstract
There is a growing trend of hosting chains of Virtual Network Functions (VNFs) on third-party clouds for more cost-effective deployment. However, the multi-actor nature of such a deployment may allow a mismatch to silently arise between tenant-level specifications of VNF chains and their cloud provider-level deployment. Most existing auditing approaches would face difficulties in identifying such an integrity breach. First, relying on the cloud provider may not be sufficient, since modifications made by a stealthy attacker may seem legitimate to the provider. Second, the tenant cannot directly perform the auditing due to limited access to the provider-level data. In addition, shipping such data to the tenant would incur prohibitive overhead and confidentiality concerns. In this paper, we design a tenant-based, two-stage solution where the first stage leverages tenant-level side-channel information to identify suspected integrity breaches, and then the second stage automatically identifies and anonymizes selected provider-level data for the tenant to verify the suspected breaches from the first stage. The key advantages of our solution are: (i) the first stage gives tenants more control and transparency (with the capability of identifying integrity breaches without the provider's assistance), and (ii) the second stage provides tenants higher accuracy (with the capability of rigorous verification based on provider-level data). Our solution is integrated into OpenStack/Tacker (a popular choice for NFV deployment), and its effectiveness is demonstrated via experiments (e.g., up to 90% accuracy with the first stage alone).
Momen Oqaily, Suryadipta Majumdar, Lingyu Wang 0001, Mohammad Ekramul Kabir, Yosr Jarraya, A. S. M. Asadujjaman, Makan Pourzandi, Mourad Debbabi
CODASPY2
2023 Evaluating the Security Posture of 5G Networks by Combining State Auditing and Event Monitoring
Md. Nazmul Hoq, Jia Wei Yao, Suryadipta Majumdar, Lingyu Wang 0001, Amine Boukhtouta, Makan Pourzandi, Mourad Debbabi
ESORICS (2)3
2023 Warping the Defence Timeline: Non-Disruptive Proactive Attack Mitigation for Kubernetes Clusters
abstract
In spite of being the de-facto standard of container orchestrators, Kubernetes reportedly suffers from security vulnerabilities and misconfigurations which may lead to severe security threats to the containerized environments it manages. Mitigating such threats based on alerts raised by existing security monitoring solutions (e.g., Falco) can be challenging. First, taking actions upon every alert can cause unacceptable service disruption, as many such alerts may turn out to be false positives. Second, validating each alert by administrators before taking actions may render the mitigation too late to prevent irreversible damages, e.g., denial of service. In this paper, we propose a non-disruptive proactive mitigation approach to address those limitations. Our main idea is to proactively trigger mitigation ahead of an attack to prevent irreversible damages, while designing the mitigation actions to be non-disruptive to avoid any service disruption caused by false alerts. We implement and integrate our approach with Kubernetes, and show its effectiveness and efficiency.
Sima Bagheri, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi
ICC3
2023 Layered Security Analysis for Container Images: Expanding Lightweight Pre-Deployment Scanning
abstract
Containerization using tools such as Docker has transformed the way applications are deployed and managed in various organizations. However, the use of containers also presents new security challenges due to the potential vulnerabilities that may be present in the container images. To address this, various vulnerability detection tools that use static analysis have been developed that focus more on OS packages, and fail to detect known package vulnerabilities. In this paper, we propose a pre-deployment methodology that detects vulnerabilities in container images targeting both the OS and application packages using a layered approach, where static tools generally fail to detect vulnerabilities in those images. Our solution offers a high degree of customizability and control over its performance in detecting vulnerabilities in images. Users can choose a specific scan profile that is tailored to their particular needs, enabling the detection of vulnerabilities that are either more common, more unique, or a balance of the two. This adaptability makes our solution more flexible and better suited to meet the specific needs of our users. We evaluate our proposed framework against 111 both official and community images collected from Docker Hub to demonstrate its effectiveness compared to other popular static analysis tools for containers.
Shafayat H. Majumder, Sourov Jajodia, Suryadipta Majumdar, Md. Shohrab Hossain
PST3
2022 5GFIVer: Functional Integrity Verification for 5G Cloud-Native Network Functions
abstract
5G networks attain a better performance along with a reduction in cost by cloudifying its network functions as Cloud+native Network Functions (CNFs). However, CNF may introduce new security concerns (e.g., data exfiltration and ransomware) due to potential code injection attacks against network functions at runtime. This will potentially result in a breach of functional integrity of these network functions. Towards verifying such functional integrity breaches of CNFs at the 5G-operator-level, existing approaches fell short, as most of them either (i) perform pre-deployment verification (i.e., verifying the CNF image before the deployment) and hence fail to verify integrity breaches occurring after the deployment, or (ii) perform post-deployment verification (i.e., verifying against attack signatures or normal behavior patterns) approaches that require provider-level data (e.g., system calls) which is usually inaccessible to 5G operators. In this paper, we propose 5GFIVer, a new operator-oriented approach for functional integrity verification of CNFs that overcomes the above-mentioned limitations. First, our approach utilizes the side-channel information such as performance metrics (which are already available at the operator level) so that no provider-level data is needed. Second, our approach implements unsupervised machine learning algorithms to detect outliers through time-series analysis of those available performance metrics, and hence no instrumentation for the data collection as well as no training data is required. Third, we leverage the correlation between multiple CNFs to improve the accuracy and minimize false positives (e.g., caused by cloud dynamics). Our experimental results under an open source 5G testbed demonstrate the effectiveness and negligible overhead of our solution.
A. S. M. Asadujjaman, Mohammad Ekramul Kabir, Hinddeep Purohit, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Makan Pourzandi
CloudCom4
2022 ProSPEC: Proactive Security Policy Enforcement for Containers
abstract
By providing lightweight and portable support for cloud native applications, container environments have gained significant momentum lately. A container orchestrator such as Kubernetes can enable the automatic deployment and maintenance of a large number of containerized applications. However, due to its critical role, a container orchestrator also attracts a wide range of security threats exploiting misconfigurations or implementation flaws. Moreover, enforcing security policies at runtime against such security threats becomes far more challenging, as the large scale of container environments implies high complexity, while the high dynamicity demands a short response time. In this paper, we tackle this key security challenge to container environments through a proactive approach, namely, ProSPEC. Our approach leverages learning-based prediction to conduct the computationally intensive steps (e.g., security verification) in advance, while keeping the runtime steps (e.g., policy enforcement) lightweight. Consequently, ProSPEC can ensure a practical response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) for large container environments (up to 800 Pods).
Hugo Kermabon-Bobinnec, Mahmood Gholipourchoubeh, Sima Bagheri, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001
CODASPY4
2022 MLFM: Machine Learning Meets Formal Method for Faster Identification of Security Breaches in Network Functions Virtualization (NFV)
Alaa Oqaily, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi, Suryadipta Majumdar
ESORICS (3)5
2022 ProSAS: Proactive Security Auditing System for Clouds
abstract
The multi-tenancy in a cloud along with its dynamic and self-service nature could cause severe security concerns, such as isolation breaches among cloud tenants. To mitigate such concerns and ensure the accountability and transparency of the cloud providers towards their tenants, verifying cloud states against a list of security policies, a.k.a.security auditing, is a promising solution. However, the existing security auditing solutions for clouds suffer from several limitations. First, the traditional auditing approach, which is retroactive in nature, can only detect violations after the fact and hence, often becomes ineffective while dealing with the dynamic nature of a cloud. Second, the existing runtime approaches can cause significant delay in the response time while dealing with the sheer size of a cloud. Finally, the current proactive approaches typically rely on prior knowledge about future changes in a cloud and also require significant manual efforts, and thus become less practical for a dynamic environment like cloud. To address those limitations, we present a novel proactive security auditing system, namely,ProSAS, which can prevent violations to security policies at runtime with a practical response time, and yet does not require prior knowledge about future changes. More specifically,ProSASfirst establishes its models (e.g., dependency relationships between cloud events, and critical events) through learning from historical data (e.g., logs); it then predicts future critical events which would likely follow a received event by leveraging the dependency relationships; afterwards, it proactively verifies the impacts of those future events, and prevents those events which can cause violations of security policies. ProSAS is integrated into OpenStack, a popular cloud management platform, and we provide a concrete guideline to port ProSAS to other popular cloud platforms, such as Google Cloud Platform, and Amazon EC2. Our experiment results using both real and synthetic data demonstrate the improvement of efficiency (i.e., reducing response time to 1,450 nanoseconds at best and 8.5 milliseconds on average for a large-scale cloud with 10,000 tenants) and level of automation (i.e., learning more than 20 new critical events spanning 100 days) in proactive security auditing by ProSAS.
Suryadipta Majumdar, Gagandeep Singh Chawla, Amir Alimohammadifar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.1
2021 Security Auditing of Internet of Things Devices in a Smart Home
Suryadipta Majumdar, Daniel Bastos, Anoop Singhal
IFIP Int. Conf. Digital Forensics1
2021 Towards an Attention-Based Accurate Intrusion Detection Approach
Arunavo Dey, Md. Shohrab Hossain, Md. Nazmul Hoq, Suryadipta Majumdar
QSHINE4
2021 VMGuard: State-Based Proactive Verification of Virtual Network Isolation With Application to NFV
abstract
Network Functions Virtualization (NFV) leverages from clouds to simplify and automate the creation and deployment of network services on the fly in a multi-tenant environment. However, clouds may also bring issues leading to tenants' concerns over possible breaches violating the isolation of their deployments. Verifying such network isolation breaches in cloud-enabled NFV environments faces unique challenges. The fine-grained and distributed network access control (e.g., per-function security group rules), which is typical to virtual cloud infrastructures, requires examining not only the events but also the states of all virtual resources using a state-based verification approach. However, verifying the state of a virtual infrastructure may become highly complex and non-scalable due to its sheer size paired with the self-serviced dynamic nature of clouds. In this article, we propose VMGuard, a state-based proactive approach for efficiently verifying large-scale virtual infrastructures in cloud and NFV against network isolation policies. Informally, our key idea is to proactively trigger the verification based on predicted events and their simulated impact upon the current state, such that we can have the best of both worlds, i.e., the efficiency of a proactive approach and the effectiveness of state-based verification. We implement and evaluate VMGuard based on OpenStack, and our experiments with both real and synthetic data demonstrate the performance and efficiency, e.g., less than five milliseconds to perform incremental verification on a dataset with more than 25, 000 VMs and less than two milliseconds with the proactive module enabled.
Gagandeep Singh Chawla, Mengyuan Zhang 0001, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.3
2021 SegGuard: Segmentation-Based Anonymization of Network Data in Clouds for Privacy-Preserving Security Auditing
abstract
Security auditing allows cloud tenants to verify the compliance of cloud infrastructure with respect to desirable security properties, e.g., whether a tenant’s virtual network is properly isolated from other tenants’ networks. However, the input to the auditing task, such as the detailed topology of the underlying cloud infrastructure, typically contains sensitive information which a cloud provider may be reluctant to hand over to a third party auditor. Additionally, auditing results intended for one tenant may inadvertently reveal private information about other tenants, e.g., another tenant’s VM is reachable due to a misconfiguration. How to anonymize both the input data and the auditing results in order to prevent such information leakage is a novel challenge that has received little attention. Directly applying most of the existing anonymization techniques to such a context would either lead to insufficient protection or render the data unsuitable for auditing. In this article, we proposeSegGuard, a novel anonymization approach that prevents cross-tenant information leakage through per-tenant encryption, and prevents information leakage to auditors through hiding real input segments among fake ones; in addition, applying property-preserving encryption in an innovative way enablesSegGuardto preserve the data utility for auditing while mitigating semantic attacks. We implementSegGuardbased on OpenStack, and evaluate its effectiveness and overhead using both synthetic and real data. Our experimental results demonstrate thatSegGuardcan reduce the information leakage to a negligible level (e.g., less than 1 percent for an adversary with 50 percent pre-knowledge) with a practical response time (e.g., 62 seconds to anonymize a cloud infrastructure with 25,000 virtual machines).
Momen Oqaily, Yosr Jarraya, Meisam Mohammady, Suryadipta Majumdar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.4
2020 NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) Stack
abstract
Network Functions Virtualization (NFV) enables agile and cost-effective deployment of multi-tenant network services on top of a cloud infrastructure. However, the multi-tenant and multilevel nature of NFV may lead to novel security challenges, such as stealthy attacks exploiting potential inconsistencies between different levels of the NFV stacks. Consequently, the security compliance of a multilevel NFV stack cannot be sufficiently established using existing solutions, which typically focus on one level. Moreover, the naive approach of separately verifying every level could be expensive or even infeasible. In this paper, we propose, NFVGuard, the first multilevel approach to the formal security verification of NFV stacks. Our key idea is to conduct the security verification at only one level, and then assure that verification result for other levels by verifying the consistency between adjacent levels. We integrate NFVGuard with OpenStack/Tacker, a popular platform for the NFV deployment, and experimentally evaluate its effectiveness.
Alaa Oqaily, Sudershan Lakshmanan Thirunavukkarasu, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
CloudCom4
2020 Proactively Extracting IoT Device Capabilities: An Application to Smart Homes
Andy Dolan, Indrakshi Ray, Suryadipta Majumdar
DBSec3
2019 Proactivizer: Transforming Existing Verification Tools into Efficient Solutions for Runtime Security Enforcement
Suryadipta Majumdar, Azadeh Tabiban, Meisam Mohammady, Alaa Oqaily, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
ESORICS (2)1
2019 Learning probabilistic dependencies among events for proactive security auditing in clouds
abstract
Security compliance auditing is a viable solution to ensure the accountability and transparency of a cloud provider to its tenants. However, the sheer size of a cloud, coupled with the high operational complexity implied by the multi-tenancy and self-service nature, can easily render existing runtime auditing techniques too expensive and non-scalable. To this end, a proactive approach, which prepares for the auditing ahead of critical events, is a promising solution to reduce the response time to a practical level. However, a key limitation of such approaches is their reliance on manual efforts to extract the dependency relationships among events, which greatly restricts their practicality. What makes things worse is the fact that, as the most important input to security auditing, the logs and configuration databases of a real world cloud platform can be unstructured and not ready to be used for efficient security auditing. In this paper, we first propose a log processing technique, which prepares raw cloud logs for different analysis purposes, and then design a learning-based proactive security auditing system, namely, [Formula: see text]. To this end, we conduct case studies on current log formats in different real-world OpenStack (a popular cloud platform) deployments, and identify major challenges in log processing. Later, we design a stand-alone log processor for clouds, which may potentially be used for various log analyses. Consequently, we leverage the log processor outputs to extract probabilistic dependencies from runtime events for the dependency models. Finally, through these dependency models, we proactively prepare for security critical events and prevent security violations resulting from those critical events. Furthermore, we integrate [Formula: see text] to OpenStack and perform extensive experiments in both simulated and real cloud environments that show a practical response time (e.g., 6 ms to audit a cloud of 100,000 VMs) and a significant improvement (e.g., about 50% faster) over existing proactive approaches. In addition, we successfully and efficiently apply our log processor outputs to other learning techniques (e.g., executing sequence pattern mining algorithms within 18 ms for 50,000 events).
Suryadipta Majumdar, Azadeh Tabiban, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
J. Comput. Secur.1
2019 ISOTOP: Auditing Virtual Networks Isolation Across Cloud Layers in OpenStack
abstract
Multi-tenancy in the cloud is a double-edged sword. While it enables cost-effective resource sharing, it increases security risks for the hosted applications. Indeed, multiplexing virtual resources belonging to different tenants on the same physical substrate may lead to critical security concerns such as cross-tenants data leakage and denial of service. Particularly, virtual networks isolation failures are among the foremost security concerns in the cloud. To remedy these, automated tools are needed to verify security mechanisms compliance with relevant security policies and standards. However, auditing virtual networks isolation is challenging due to the dynamic and layered nature of the cloud. Particularly, inconsistencies in network isolation mechanisms across cloud-stack layers, namely, the infrastructure management and the implementation layers, may lead to virtual networks isolation breaches that are undetectable at a single layer. In this article, we propose an offline automated framework for auditing consistent isolation between virtual networks in OpenStack-managed cloud spanning over overlay and layer 2 by considering both cloud layers’ views. To capture the semantics of the audited data and its relation to consistent isolation requirement, we devise a multi-layered model for data related to each cloud-stack layer’s view. Furthermore, we integrate our auditing system into OpenStack, and present our experimental results on assessing several properties related to virtual network isolation and consistency. Our results show that our approach can be successfully used to detect virtual network isolation breaches for large OpenStack-based data centers in reasonable time.
Taous Madi, Yosr Jarraya, Amir Alimohammadifar, Suryadipta Majumdar, Yushun Wang, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
ACM Trans. Priv. Secur.4
2018 Stealthy Probing-Based Verification (SPV): An Active Approach to Defending Software Defined Networks Against Topology Poisoning Attacks
Amir Alimohammadifar, Suryadipta Majumdar, Taous Madi, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
ESORICS (2)2
2018 User-Level Runtime Security Auditing for the Cloud
abstract
Cloud computing is emerging as a promising IT solution for enabling ubiquitous, convenient, and on-demand accesses to a shared pool of configurable computing resources. However, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security auditing techniques. Auditing in cloud poses many unique challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures), and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and need of runtime verification for the dynamic nature of cloud). To this end, existing runtime auditing techniques do not offer a practical response time to verify a wide-range of user-level security properties for a large cloud. In this paper, we propose a runtime security auditing framework for the cloud with special focus on the user-level including common access control and authentication mechanisms e.g., RBAC, ABAC, SSO, and we implement and evaluate the framework based on OpenStack, a widely deployed cloud management system. The main idea towards reducing the response time to a practical level is to perform the costly operations only once, which is followed by significantly more efficient incremental runtime verification. Our experimental results show that runtime security auditing in a large cloud environment is realistic under our approach (e.g., our solution performs runtime auditing of 100,000 users within 500 milliseconds).
Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
IEEE Trans. Inf. Forensics Secur.1
2017 LeaPS: Learning-Based Proactive Security Auditing for Clouds
Suryadipta Majumdar, Yosr Jarraya, Momen Oqaily, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
ESORICS (2)1
2017 TenantGuard: Scalable Runtime Verification of Cloud-Wide VM-Level Network Isolation
Yushun Wang, Taous Madi, Suryadipta Majumdar, Yosr Jarraya, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
NDSS3
2016 Auditing Security Compliance of the Virtualized Infrastructure in the Cloud: Application to OpenStack
Taous Madi, Suryadipta Majumdar, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001
CODASPY2
2016 Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack
Suryadipta Majumdar, Yosr Jarraya, Taous Madi, Amir Alimohammadifar, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
ESORICS (1)1
2015 Security Compliance Auditing of Identity and Access Management in the Cloud: Application to OpenStack
abstract
Cloud computing has seen a lot of interests and adoption lately. Nonetheless, the widespread adoption of cloud is still being hindered by the lack of transparency and accountability, which has traditionally been ensured through security compliance auditing techniques. Auditing in cloud, however, presents many new challenges in data collection and processing (e.g., data format inconsistency and lack of correlation due to the heterogeneity of cloud infrastructures) and in verification (e.g., prohibitive performance overhead due to the sheer scale of cloud infrastructures and their self-provisioning, elastic, and dynamic nature). In this paper, we propose a security compliance auditing framework for cloud, with special focus on identity and access management, and we implement and evaluate the framework based on OpenStack, one of the most popular cloud management systems. Our experimental results show that auditing with formal methods in large cloud environment is realistic (e.g., our auditing solution can handle 60 thousand users in less than one minute).
Suryadipta Majumdar, Taous Madi, Yushun Wang, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi
CloudCom1