Arash Shaghaghi

dblp:186/7967 · DBLP profile ↗
← Back
21ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0001-6630-9519ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 8 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A secure framework for containerized IoT applications in integrated edge-cloud computing environments
abstract
The integration of edge and cloud computing combines low latency with high computational power, addressing the constraints of edge resources and high access latency inherent in cloud environments. This is essential for deploying Internet of Things (IoT) applications, which are mainly developed by Containers within these heterogeneous environments. However, the open, multi-user nature of edge computing, compounded by a lack of standardized practices, introduces substantial security challenges with severe economic implications. In response, we propose SecConEC, an economically driven framework designed to secure the deployment and execution of containerized IoT applications. We conducted systematic threat modeling using the STRIDE framework, explicitly incorporating quantitative economic risk assessment to identify and prioritize security threats based on their potential economic impacts. We particularly focus on tampering and resource hijacking threats. SecConEC implements robust yet lightweight mitigation and detection mechanisms informed by the MITRE ATT&CK framework through a Security Information and Event Management (SIEM) system. Also, SecConEC introduces a dynamic, security-aware scheduling mechanism that balances performance and security considerations, proactively mitigating economic risks associated with potential security threats. Extensive performance evaluation shows that SecConEC significantly mitigates prioritized threats, effectively securing IoT application deployment and execution in edge-cloud environments, while maintaining low service latency with a minimal performance overhead of 1.7%.
Qifan Deng, Mohammad Goudarzi, Arash Shaghaghi, Majid Sarvi, Rajkumar Buyya
Future Gener. Comput. Syst.3
2025 Nosy Layers, Noisy Fixes: Tackling DRAs in Federated Learning Systems using Explainable AI
Meghali Nandi, Arash Shaghaghi, Nazatul Haque Sultan, Gustavo Batista, Raymond K. Zhao, Sanjay K. Jha
AsiaCCS2
2025 What Lies Beneath: An Empirical Study of Silent Vulnerability Fixes in Open-Source Software
abstract
Unlike standard vulnerability disclosure, fixing vulnerabilities "silently" is another common approach in software development. While silent fixes can prevent potential targeted attacks without disclosing any details, they only offer short-term protection. Users often rely on publicly disclosed vulnerabilities to identify and eliminate vulnerabilities in their own software, particularly for open-source software (OSS). We conduct the first comprehensive empirical study in OSS to investigate potential security threats brought by silent fixes. By examining disclosed vulnerabilities and their corresponding patches in real-world OSSes, we investigated the prevalence of silent vulnerabilities and assessed the potential impacts they might cause. After analyzing 3,515 vulnerabilities, we observed that nearly 50% of the vulnerabilities, with half of them classified as high-severity, were exposed for over 30 days. Over 10% of them published exploits during the "silent" period, enabling adversaries to replicate the exploits and attack other OSS users. Due to delayed vulnerability disclosure, we even found one HIGH-severity vulnerability that was silently fixed still exists in downstream software, indicating that silent fixes may increase the risks for other OSSes, amplifying their impact throughout software supply chains.
Jialiang Dong, Xinzhang Chen, Willy Susilo, Nan Sun 0002, Arash Shaghaghi, Siqi Ma 0001
DSN5
2025 Demo: TOSense - What Did You Just Agree to?
abstract
Online services often require users to agree to lengthy and obscure Terms of Service (ToS), leading to information asymmetry and legal risks. This paper proposes TOSense—a Chrome extension that allows users to ask questions about ToS in natural language and get concise answers in real time. The system combines (i) a crawler "tos-crawl" that automatically extracts ToS content, and (ii) a lightweight large language model pipeline: MiniLM for semantic retrieval and BART-encoder for answer relevance verification. To avoid expensive manual annotation, we present a novel Question Answering Evaluation Pipeline (QEP) that generates synthetic questions and verifies the correctness of answers using clustered topic matching. Experiments on five major platforms, Apple, Google, X (formerly Twitter), Microsoft, and Netflix, show the effectiveness of TOSense (with up to 44.5% accuracy) across varying number of topic clusters. During the demonstration, we will showcase TOSense in action. Attendees will be able to experience seamless extraction, interactive question answering, and instant indexing of new sites.
Xinzhang Chen, Hassan Ali 0001, Arash Shaghaghi, Salil S. Kanhere, Sanjay K. Jha
LCN3
2025 Congested by the Past: The Dataset Lag in Network Traffic Analysis
abstract
Network traffic analysis (NTA) remains a central research area, underpinning advances in both security and performance optimization. Recent years have seen a surge of machine learning-based approaches for NTA, supported by widely used public datasets, such as ISCX-VPN, ISCX-ToR and USTCTFC. While these benchmarks provide reproducibility, many were collected prior to 2018, thus, fail to reflect contemporary protocols, such as TLS 1.3 and HTTP/3 over QUIC. By reviewing NTA studies published in 2024 and 2025 across premier venues in security, networking, and artificial intelligence, we find that 13 out of 15 studies continue to utilize datasets collected before 2018, underscoring a persistent misalignment between academic practice and today’s network traffic. This reliance on outdated datasets risks producing models that do not generalize, embed invalid assumptions, and report misleading performance. We call for the adoption and public release of up-to-date datasets and outline a research agenda that emphasizes evaluating classifiers across diverse downstream tasks using modern traffic traces.
Nimesha Wickramasinghe, Sanjay K. Jha, Gene Tsudik, Arash Shaghaghi
NCA4
2025 Enhancing Security in Third-Party Library Reuse - Comprehensive Detection of 1-day Vulnerability through Code Patch Analysis
Shangzhi Xu, Jialiang Dong, Weiting Cai, Juanru Li, Arash Shaghaghi
NDSS5
2025 SoK: Decoding the Enigma of Encrypted Network Traffic Classifiers
abstract
The adoption of modern encryption protocols such as TLS 1.3 has significantly challenged traditional network traffic classification (NTC) methods. As a consequence, researchers are increasingly turning to machine learning (ML) approaches to overcome these obstacles. This paper analyses ML-based NTC studies by developing a taxonomy of their design choices, benchmarking suites, and prevalent assumptions impacting classifier performance. Through this systematization, we demonstrate widespread reliance on outdated datasets, oversights in design choices, and the consequences of unsubstantiated assumptions. Our evaluation reveals that the majority of proposed encrypted traffic classifiers have mistakenly utilized unencrypted traffic due to the use of legacy datasets. Furthermore, by conducting 348 feature occlusion experiments on state-of-the-art classifiers, we show how oversights in NTC design choices lead to overfitting and validate or refute prevailing assumptions with empirical evidence. By highlighting lessons learned, we offer strategic insights, identify emerging research directions, and recommend best practices to support the development of real-world applicable NTC methodologies.
Nimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. Jha
SP2
2025 Hotpatching on the Fly - Mitigating Drone Incidents Arising From Incorrect Configuration
abstract
Manufacturers offer adjustable control parameters for flight control systems to accommodate diverse environments and missions. To ensure flight safety, they also develop established boundaries, i.e., range specifications for parameter values. However, even when the configuration parameters fall within the prescribed manufacturer range, they could still lead to instability or even severe incidents like crashes, which are referred to asRange Specification Bugs. Prior research has suggested shrinking the range of parameter values to protect drones from the adverse effects of such bugs. However, narrowing the range of parameters may only reduce the probability of errors and could potentially limit the drone’s adaptability. To overcome this limitation, we present an online approach that analyzes a sequence of flight states to detect any potential triggering of bugs and rectify the drone by dynamically adjusting its parameters. We implemented the rectification approach,ConFix, and applied it in current prevalent flight control systems, Ardupilot and PX4. The results demonstrated thatConFixachieved an average rectification success rate of 80%.
Ruidong Han, Juanru Li, Zhuo Ma 0001, David Lo 0001, Arash Shaghaghi, Jianfeng Ma 0001, Siqi Ma 0001
IEEE Trans. Dependable Secur. Comput.5
2024 Towards Detecting IoT Event Spoofing Attacks Using Time-Series Classification
abstract
Internet of Things (IoT) devices have grown in popularity since they can directly interact with the real world. Home automation systems automate these interactions. IoT events are crucial to these systems’ decision-making but are often unreliable. Security vulnerabilities allow attackers to impersonate events. Using statistical machine learning, IoT event fingerprints from deployed sensors have been used to detect spoofed events. Multivariate temporal data from these sensors has structural and temporal properties that statistical machine learning cannot learn. These schemes’ accuracy depends on the knowledge base; the larger, the more accurate. However, the lack of huge datasets with enough samples of each IoT event in the nascent field of IoT can be a bottleneck. In this work, we deployed advanced machine learning to detect event-spoofing assaults. The temporal nature of sensor data lets us discover important patterns with fewer events. Our rigorous investigation of a publicly available real-world dataset indicates that our time-series-based solution technique learns temporal features from sensor data faster than earlier work, even with a 100- or 500-fold smaller training sample, making it a realistic IoT solution.
Uzma Maroof, Gustavo Batista, Arash Shaghaghi, Sanjay K. Jha
LCN3
2024 Towards Threat Modelling of IoT Context-Sharing Platforms
abstract
The Internet of Things (IoT) involves complex, interconnected systems and devices that depend on contextsharing platforms for interoperability and information exchange. These platforms are, therefore, critical components of real-world IoT deployments, making their security essential to ensure the resilience and reliability of these “systems of systems.” In this paper, we take the first steps toward systematically and comprehensively addressing the security of IoT context-sharing platforms. We propose a framework for threat modelling and security analysis of a generic IoT context-sharing solution, employing the MITRE ATT&CK framework. Through an evaluation of various industry-funded projects and academic research, we identify significant security challenges in the design of IoT context-sharing platforms. Our threat modelling provides an in-depth analysis of the techniques and sub-techniques adversaries may use to exploit these systems, offering valuable insights for future research aimed at developing resilient solutions. Additionally, we have developed an open-source threat analysis tool that incorporates our detailed threat modelling, which can be used to evaluate and enhance the security of existing context-sharing platforms.
Mohammad Goudarzi, Arash Shaghaghi, Simon Finn, Burkhard Stiller, Sanjay K. Jha
NCA2
2024 Lack of Systematic Approach to Security of IoT Context Sharing Platforms
abstract
IoT context-sharing platforms are an essential component of today's interconnected IoT deployments with their security affecting the entire deployment and the critical in-frastructure adopting IoT. We report on a lack of systematic approach to the security of IoT context-sharing platforms and propose the need for a methodological and systematic alternative to evaluate the existing solutions and develop ‘secure-by-design’ solutions. We have identified the key components of a generic IoT context-sharing platform and propose using MITRE ATT&CK for threat modelling of such platforms.
Mohammad Goudarzi, Arash Shaghaghi, Simon Finn, Sanjay K. Jha
PST2
2024 Towards Weaknesses and Attack Patterns Prediction for IoT Devices
abstract
As the adoption of Internet of Things (IoT) devices continues to rise in enterprise environments, the need for effective and efficient security measures becomes increasingly critical. This paper presents a cost-efficient platform to facilitate the pre-deployment security checks of IoT devices by predicting potential weaknesses and associated attack patterns. The platform employs a Bidirectional Long Short-Term Memory (Bi-LSTM) network to analyse device-related textual data and predict weaknesses. At the same time, a Gradient Boosting Machine (GBM) model predicts likely attack patterns that could exploit these weaknesses. When evaluated on a dataset curated from the National Vulnerability Database (NVD) and publicly accessible IoT data sources, the system demonstrates high accuracy and reliability. The dataset created for this solution is publicly accessible.
Carlos A. Rivera Alvarez, Arash Shaghaghi, Gustavo Batista, Salil S. Kanhere
SIN2
2022 iRECOVer: Patch your IoT on-the-fly
Uzma Maroof, Arash Shaghaghi, Regio A. Michelin, Sanjay K. Jha
Future Gener. Comput. Syst.2
2021 Is This IoT Device Likely to Be Secure? Risk Score Prediction for IoT Devices Using Gradient Boosting Machines
Carlos A. Rivera Alvarez, Arash Shaghaghi, David D. Nguyen, Salil S. Kanhere
MobiQuitous2
2021 LCDA: Lightweight Continuous Device-to-Device Authentication for a Zero Trust Architecture (ZTA)
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss
Comput. Secur.3
2020 Towards a Distributed Defence Mechanism Against IoT-based Bots
abstract
IoT devices are the target of choice for attackers, and one of the most devastating threats involving compromised IoT devices has been their exploitation as part of botnets. Here, we propose c-Shield, as a distributed and extensible solution designed to detect and respond to IoT-based bots in an enterprise network. c-Shield passively inspects network traffic associated with IoT devices over a range of different protocols and systematically analyses the URLs extracted. Compared with the existing solutions, c-Shield is designed to be capable of detecting bots using advanced evasion techniques such as Domain Name Generation Algorithms (DGA) with a high accuracy rate.
Carlos A. Rivera Alvarez, Arash Shaghaghi, Salil S. Kanhere
LCN2
2020 Towards Decentralized IoT Updates Delivery Leveraging Blockchain and Zero-Knowledge Proofs
abstract
Internet of Things (IoT) devices are being deployed in huge numbers around the world, and often present serious vulnerabilities. Accordingly, delivering regular software updates is critical to secure IoT devices. Manufactures face two predominant challenges in providing software updates to IoT devices: 1) scalability of the current client-server model and 2) integrity of the distributed updates - exacerbated due to the devices' computing power and lightweight cryptographic primitives. Motivated by these limitations, we propose CrowdPatching, a blockchain-based decentralized protocol, allowing manufacturers to delegate the delivery of software updates to self-interested distributors in exchange for cryptocurrency. Manufacturers announce updates by deploying a smart contract (SC), which in turn will issue cryptocurrency payments to any distributor who provides an unforgeable proof-of-delivery. The latter is provided by IoT devices authorizing the SC to issue payment to a distributor when the required conditions are met. These conditions include the requirement for a distributor to generate a zero-knowledge proof, generated with a novel proving system called zk-SNARKs. Compared with related work, CrowdPatching protocol offers three main advantages. First, the number of distributors can scale indefinitely by enabling the addition of new distributors at any time after the initial distribution by manufacturers (i.e., redistribution among the distributor network). The latter is not possible in existing protocols and is not account for. Secondly, we leverage the recent common integration of gateway or Hub in IoT deployments in our protocol to make CrowdPatching feasible even for the more constraint IoT devices. Thirdly, the trustworthiness of distributors is considered in our protocol, rewarding the honest distributors' engagements. We provide both informal and formal security analysis of CrowdPatching using Tamarin Prover.
Edoardo Puggioni, Arash Shaghaghi, Robin Doss, Salil S. Kanhere
NCA2
2020 Towards a Lightweight Continuous Authentication Protocol for Device-to-Device Communication
abstract
Continuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely researched human user characteristics-based CA mechanisms cannot be extended to continuously authenticate Internet of Things (IoT) devices. The challenges are exacerbated with the increased adoption of device-to-device (d2d) communication in critical infrastructures. Existing d2d authentication protocols proposed in the literature are either prone to subversion or are computationally infeasible to be deployed on constrained IoT devices. In view of these challenges, we propose a novel, lightweight and secure CA protocol that leverages communication channel properties and a tunable mathematical function to generate dynamically changing session keys. Our preliminary informal protocol analysis suggests that the proposed protocol is resistant to known attack vectors and thus has strong potential for deployment in securing critical and resource-constrained d2d communication.
Syed Wajid Ali Shah, Naeem Firdous Syed, Arash Shaghaghi, Adnan Anwar, Zubair A. Baig, Robin Doss
TrustCom3
2018 Gargoyle: A Network-based Insider Attack Resilient Framework for Organizations
abstract
Anytime, Anywhere' data access model has become a widespread IT policy in organizations making insider attacks even more complicated to model, predict and deter. Here, we propose Gargoyle, a network-based insider attack resilient framework against the most complex insider threats within a pervasive computing context. Compared to existing solutions, Gargoyle evaluates the trustworthiness of an access request context through a new set of contextual attributes called Network Context Attribute (NCA). NCAs are extracted from the network traffic and include information such as the user's device capabilities, security-level, current and prior interactions with other devices, network connection status, and suspicious online activities. Retrieving such information from the user's device and its integrated sensors are challenging in terms of device performance overheads, sensor costs, availability, reliability and trustworthiness. To address these issues, Gargoyle leverages the capabilities of Software-Defined Network (SDN) for both policy enforcement and implementation. In fact, Gargoyle's SDN App can interact with the network controller to create a 'defence-in-depth' protection system. For instance, Gargoyle can automatically quarantine a suspicious data requestor in the enterprise network for further investigation or filter out an access request before engaging a data provider. Finally, instead of employing simplistic binary rules in access authorizations, Gargoyle incorporates Function-based Access Control (FBAC) and supports the customization of access policies into a set of functions (e.g., disabling copy, allowing print) depending on the perceived trustworthiness of the context. Our extensive evaluation results prove the practicality of Gargoyle with better performance metrics compared to existing solutions.
Arash Shaghaghi, Salil S. Kanhere, Mohamed Ali Kâafar, Elisa Bertino, Sanjay K. Jha
LCN1
2018 Gwardar: Towards Protecting a Software-Defined Network from Malicious Network Operating Systems
abstract
A Software-Defined Network (SDN) controller (aka. Network Operating System or NOS) is regarded as the brain of the network and is the single most critical element responsible to manage an SDN. Complimentary to existing solutions that aim to protect a NOS, we propose an intrusion protection system designed to protect an SDN against a controller that has been successfully compromised. Gwardar maintains a virtual replica of the data plane by intercepting the OpenFlow messages exchanged between the control and data plane. By observing the long-term flow of the packets, Gwardar learns the normal set of trajectories in the data plane for distinct packet headers. Upon detecting an unexpected packet trajectory, it starts by verifying the data plane forwarding devices by comparing the actual packet trajectories with the expected ones computed over the virtual replica. If the anomalous trajectories match the NOS instructions, Gwardar inspects the NOS itself. For this, it submits policies matching the normal set of trajectories and verifies whether the controller submits matching flow rules to the data plane and whether the network view provided to the application plane reflects the changes. Our evaluation results prove the practicality of Gwardar with a high detection accuracy in a reasonable time-frame.
Arash Shaghaghi, Salil S. Kanhere, Mohamed Ali Kâafar, Sanjay K. Jha
NCA1
2017 WedgeTail: An Intrusion Prevention System for the Data Plane of Software Defined Networks
abstract
Networks are vulnerable to disruptions caused by malicious forwarding devices. The situation is likely to worsen in Software Defined Networks (SDNs) with the incompatibility of existing solutions, use of programmable soft switches and the potential of bringing down an entire network through compromised forwarding devices. In this paper, we present WedgeTail, an Intrusion Prevention System (IPS) designed to secure the SDN data plane. WedgeTail regards forwarding devices as points within a geometric space and stores the path packets take when traversing the network as trajectories. To be efficient, it prioritizes forwarding devices before inspection using an unsupervised trajectory-based sampling mechanism. For each of the forwarding device, WedgeTail computes the expected and actual trajectories of packets and 'hunts' for any forwarding device not processing packets as expected. Compared to related work, WedgeTail is also capable of distinguishing between malicious actions such as packet drop and generation. Moreover, WedgeTail employs a radically different methodology that enables detecting threats autonomously. In fact, it has no reliance on pre-defined rules by an administrator and may be easily imported to protect SDN networks with different setups, forwarding devices, and controllers. We have evaluated WedgeTail in simulated environments, and it has been capable of detecting and responding to all implanted malicious forwarding devices within a reasonable time-frame. We report on the design, implementation, and evaluation of WedgeTail in this manuscript.
Arash Shaghaghi, Mohamed Ali Kâafar, Sanjay K. Jha
AsiaCCS1