EDBT 2026 Demo / reviewers in the wild / expert
Amirreza Niakanlahiji
dblp:192/7560
· DBLP profile ↗
8ranked-venue papers
6as first author
2since 2021 · last 2023
0000-0002-7282-1575ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-authorSystems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | MultiRHM: Defeating multi-staged enterprise intrusion attacks through multi-dimensional and multi-parameter host identity anonymization
Jafar Haadi Jafarian, Amirreza Niakanlahiji |
Comput. Secur. | 2 |
| 2023 | Toward practical defense against traffic analysis attacks on encrypted DNS traffic
Amirreza Niakanlahiji, Soeren Orlowski, Alireza Vahid, Jafar Haadi Jafarian |
Comput. Secur. | 1 |
| 2020 | ShadowMove: A Stealthy Lateral Movement Strategy
Amirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang 0001, Bei-tseng Chu |
USENIX Security Symposium | 1 |
| 2019 | IoCMiner: Automatic Extraction of Indicators of Compromise from TwitterabstractIn recent years, cyber attacks have consistently grown in terms of volume, sophistication, coordination, and pervasiveness. Such attacks impose billions of dollars loss to companies and government entities annually. Sharing cyber threat intelligence (CTI) about ongoing attacks can significantly improve the current situation as many cyber attackers tend to reuse or share their network infrastructure, techniques, tactics, and procedures across multiple attacks. Therefore, many security professionals devote their time and effort on hunting cyber threats and sharing such valuable information with the public through public data sharing platforms such as social media and text sharing websites. However, due to the sheer volume of information that is being shared on such platforms; finding CTI information is tantamount to looking for a needle in a haystack. In this paper, we present a new scalable framework, IoCMiner, to automatically extract CTI, in special Indicators of Compromise, from Twitter. It utilizes a combination of graph theory, machine learning, and text mining technique to achieve its goal. IoCMiner relies on a reputation model to discover credible twitterers who publish CTI, and only tracks the tweet stream of such Twitter handles. Moreover, it employs a CTI classifier to further filter out non-CTI tweets from the observed data streams. Finally, IoCs uses a set of regular expression rules to extract IoCs from the identifies tweets. Through experimentation, we show the usefulness of IoCMiner in finding fresh IoCs from Twitter. In the course of four weeks, IoCMiner identified more than 1,200 IoCs, including malicious URLs. Only 10% of the URLs were already listed in public blacklist databases at the time of extraction. The number of URLs that appeared in blacklists increased to 26% after one week. Amirreza Niakanlahiji, Lida Safarnejad, Reginald Harper, Bei-tseng Chu |
IEEE BigData | 1 |
| 2019 | All one needs to know about fog computing and related edge computing paradigms: A complete surveyabstractWith the Internet of Things (IoT) becoming part of our daily life and our environment, we expect rapid growth in the number of connected devices. IoT is expected to connect billions of devices and humans to bring promising advantages for us. With this growth, fog computing, along with its related edge computing paradigms, such as multi-access edge computing (MEC) and cloudlet, are seen as promising solutions for handling the large volume of security-critical and time-sensitive data that is being produced by the IoT. In this paper, we first provide a tutorial on fog computing and its related computing paradigms, including their similarities and differences. Next, we provide a taxonomy of research topics in fog computing, and through a comprehensive survey, we summarize and categorize the efforts on fog computing and its related computing paradigms. Finally, we provide challenges and future directions for research in fog computing. Ashkan Yousefpour, Caleb Fung, Krishna Kadiyala, Fatemeh Jalali, Amirreza Niakanlahiji, Jason P. Jue |
J. Syst. Archit. | 6 |
| 2019 | WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target DefenseabstractExisting mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers. They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility. Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning. This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers. In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications. Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification. Through rigorous evaluation, we show that WebMTD has very a low performance overhead. Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead. Amirreza Niakanlahiji, Jafar Haadi Jafarian |
Secur. Commun. Networks | 1 |
| 2018 | A Natural Language Processing Based Trend Analysis of Advanced Persistent Threat TechniquesabstractAdvanced Persistent Threats (APTs) continue to be a major security problem in today's cyberspace. Understanding APT techniques is necessary for implementing an effective defense against APT attacks. In this paper, we first present a new information retrieval system, called SECCMiner, to assist cybersecurity professionals to more efficiently obtain actionable knowledge regarding APTs from a collected set of unstructured APT reports written in a natural language. It relies on a set of natural language processing and information retrieval techniques to identify adversarial techniques and tactics in given input reports. We then used SECCMiner to conduct a systematic study of existing APT techniques based on a repository of 445 technical reports, containing more than 1.9 million words, on recent APTs. The result includes trend analysis of common APT techniques since 2008, their inter-relationship, and the latest APT techniques that may become influential in the near future (e.g., using PowerShell scripts). Amirreza Niakanlahiji, Jinpeng Wei, Bei-tseng Chu |
IEEE BigData | 1 |
| 2018 | PhishMon: A Machine Learning Framework for Detecting Phishing WebpagesabstractDespite numerous research efforts, phishing attacks remain prevalent and highly effective in luring unsuspecting users to reveal sensitive information, including account credentials and social security numbers. In this paper, we propose PhishMon, a new feature-rich machine learning framework to detect phishing webpages. It relies on a set of fifteen novel features that can be efficiently computed from a webpage without requiring third-party services, such as search engines, or WHOIS servers. These features capture various characteristics of legitimate web applications as well as their underlying web infrastructures. Emulation of these features is costly for phishers as it demands to spend significantly more time and effort on their underlying infrastructures and web applications; in addition to the efforts required for replicating the appearance of target websites. Through extensive evaluation on a dataset consisting of 4,800 distinct phishing and 17,500 distinct benign webpages, we show that PhishMon can distinguish unseen phishing from legitimate webpages with a very high degree of accuracy. In our experiments, PhishMon achieved 95.4% accuracy with 1.3% false positive rate on a dataset containing unique phishing instances. Amirreza Niakanlahiji, Bei-tseng Chu, Ehab Al-Shaer |
ISI | 1 |