Devkishen Sisodia

dblp:195/7451 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0002-2018-1406ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 4 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Building Pathways to CS: Multilingual Collaborative Programming for Migrant and ESL Middle School Students
Braeden Anthony Alonge, Noemi Corona Calvario, Cis Garcia, Priscilla Amanda Garcia, Stanley Keopilavan, Victoria Lin 0003, Valerie Ponce Lucatero, Javier Gonzalez-Sanchez, Devkishen Sisodia
SIGCSE (2)9
2024 On Explainable and Adaptable Detection of Distributed Denial-of-Service Traffic
abstract
Launched from numerous end-hosts throughout the Internet, a distributed denial-of-service (DDoS) attack can exhaust the network bandwidth or other resources of a victim, cripple its service, and make it unavailable to legitimate clients. Recently many learning-based approaches attempt to detect DDoS attacks, but their results are often hardly explainable to users and their models are seldom adaptable to new environments. In this paper, we propose a new learning-based DDoS detection approach. It detects DDoS attacks via an enhanced k-nearest neighbors (KNN) algorithm, which utilizes a k-dimensional (KD) tree to speed up the detection process, and classifies DDoS sources at a fine granularity according to each IP's risk level. Compared to previous DDoS detection approaches, this approach outputs explanatory information that enables network administrators to easily inspect detection results and make necessary interventions. Moreover, this approach is adaptable in that users do not need to retrain the detection model to have it fit with a new network environment. We evaluated this approach in both simulated environments and the real world, achieving more than 95.6% accuracy in detecting DDoS attacks at line speed. In addition, we carried out a human subject study on its explainability, demonstrating that the outputs can help people better understand the attack and make interventions precisely and promptly.
Yebo Feng, Jun Li 0001, Devkishen Sisodia, Peter L. Reiher
IEEE Trans. Dependable Secur. Comput.3
2024 A Two-Mode, Adaptive Security Framework for Smart Home Security Applications
abstract
With the growth of the Internet of Things (IoT), the number of cyber attacks on the Internet is on the rise. However, the resource-constrained nature of IoT devices and their networks makes many classical security systems ineffective or inapplicable. We introduce TWINKLE, a two-mode, adaptive security framework that allows an IoT network to be in regular mode for most of the time, which incurs a low resource consumption rate, and to switch to vigilant mode only when suspicious behavior is detected, which potentially incurs a higher overhead. Compared to the early version of this work, this article presents a more comprehensive design and architecture of TWINKLE, describes challenges and details in implementing TWINKLE, and reports evaluations of TWINKLE based on real-world IoT testbeds with more metrics. We show the efficacy of TWINKLE in two case studies where we examine two existing intrusion detection and prevention systems and transform both into new, improved systems using TWINKLE. Our evaluations show that TWINKLE is not only effective at securing resource-constrained IoT networks, but can also successfully detect and prevent attacks with a significantly lower overhead and detection latency than existing solutions.
Devkishen Sisodia, Jun Li 0001, Samuel Mergendahl, Hasan Çam
ACM Trans. Internet Things1
2023 DDoS Mitigation Dilemma Exposed: A Two-Wave Attack with Collateral Damage of Millions
Lumin Shi, Jun Li 0001, Devkishen Sisodia, Mingwei Zhang 0004, Alberto Dainotti, Peter L. Reiher
SecureComm (2)3
2023 On the Detection of Smart, Self-Propagating Internet Worms
abstract
Self-propagating worms can infect millions of computers on the Internet in just several minutes. As witnessed by the recent Mirai and WannaCry worms, worm attacks are real, destructive, and continue to persist. Although many worm detectors exist, most that we studied suffer from three drawbacks: none systematically consider countermeasures from worm authors, potentially causing low effectiveness against evasive worms; all focus on outbound worms leaving a network, leaving their efficacy against inbound worms entering a network unanswered; and many require bi-directional traffic to detect worms, making their placement on the Internet inflexible. We therefore revisit worm detection in this paper, while avoiding the aforementioned drawbacks of existing work. We describe our design of SWORD, a new worm detector that focuses on the fundamental behavior of worms. It includes two complementary modules to monitor connections from and to a protected network, with one module monitoring burst durations and the other ensuring quiescent periods. Via extensive experiments using both simulated worm traffic and a real-world Mirai worm trace, we demonstrate that SWORD is superior to existing detectors at not only detecting both classic and evasive outbound worms, but also inbound worms, especially those that are superspreading or surreptitious.
Jun Li 0001, Devkishen Sisodia, Shad Stafford
IEEE Trans. Dependable Secur. Comput.2
2022 CJ-Sniffer: Measurement and Content-Agnostic Detection of Cryptojacking Traffic
abstract
With the continuous appreciation of cryptocurrency, cryptojacking, the act by which computing resources are stolen to mine cryptocurrencies, is becoming more rampant. In this paper, we conduct a measurement study on cryptojacking network traffic and propose CryptoJacking-Sniffer (CJ-Sniffer), an easily deployable, privacy-aware approach to protecting all devices within a network against cryptojacking. Compared with existing approaches that suffer from privacy concerns or high overhead, CJ-Sniffer only needs to access anonymized, content-agnostic metadata of network traffic from the gateway of the network to efficiently detect cryptojacking traffic. In particular, while cryptojacking traffic is also cryptocurrency mining traffic, CJ-Sniffer is the first approach to distinguishing cryptojacking traffic from user-initiated cryptocurrency mining traffic, making it possible to only filter cryptojacking traffic, rather than blindly filtering all cryptocurrency mining traffic as commonly practiced. After constructing a statistical model to identify all the cryptocurrency mining traffic, CJ-Sniffer extracts variation vectors from packet intervals and utilizes a long short-term memory (LSTM) network to further identify cryptojacking traffic. We evaluated CJ-Sniffer with a packet-level cryptomining dataset. Our evaluation results demonstrate that CJ-Sniffer achieves an accuracy of over 99% with reasonable delays.
Yebo Feng, Jun Li 0001, Devkishen Sisodia
RAID3
2020 POSTER: Content-Agnostic Identification of Cryptojacking in Network Traffic
abstract
In this paper, we propose a method that detects cryptojacking activities by analyzing content-agnostic network traffic flows. Our method first distinguishes crypto-mining activities by profiling the traffic with fast Fourier transform at each time window. It then generates the variation vectors between adjacent time windows and leverages a recurrent neural network to identify the cryptojacking patterns. Compared with the existing approaches, this method is privacy-preserving and can identify both browser-based and malware-based cryptojacking activities. Additionally, this method is easy to deploy. It can monitor all the devices within a network by accessing packet headers from the gateway router.
Yebo Feng, Devkishen Sisodia, Jun Li 0001
AsiaCCS2
2020 In-Network Filtering of Distributed Denial-of-Service Traffic with Near-Optimal Rule Selection
abstract
A recent trend to mitigate large-scale distributed denial-of-service (DDoS) attacks is in-network filtering, where victims can deploy traffic-filtering rules in networks other than their own. However, given multiple constraints, such as the number of rules a victim can afford to deploy, the set of rules that DDoS defense entities allow a victim to deploy, and the amount of collateral damage to limit, the selection of rules has a large impact on the efficacy of an in-network filtering solution.
Devkishen Sisodia, Jun Li 0001, Lei Jiao 0002
AsiaCCS1
2019 On Multi-Point, In-Network Filtering of Distributed Denial-of-Service Traffic
Mingwei Zhang 0004, Lumin Shi, Devkishen Sisodia, Jun Li 0001, Peter L. Reiher
IM3
2019 Android Malware Detection via Graphlet Sampling
abstract
Android systems are widely used in mobile & wireless distributed systems. In the near future, Android is believed to dominate the mobile distributed environment. However, with the popularity of Android-based smartphones/tablets comes the rampancy of Android-based malware. In this paper, we propose a novel topological signature of Android apps based on the function call graphs (FCGs) extracted from their Android App PacKages (APKs). Specifically, by leveraging recent advances on graphlet mining, the proposed method fully captures the invocator-invocatee relationship at local neighborhoods in an FCG without exponentially inflating the state space. Using real benign app and malware samples, we demonstrate that our method, App topologiCal signature through graphleT Sampling (ACTS), can detect malware and identify malware families robustly and efficiently. More importantly, we demonstrate that, without augmenting the FCG with any semantic features such as bytecode-based vertex typing, local topological information captured by ACTS alone can achieve a high malware detection accuracy. Since ACTS only uses structural features, which are orthogonal to semantic features, it is expected that combining them would give a greater improvement in malware detection accuracy than combining non-orthogonal semantic features.
Tianchong Gao, Wei Peng 0007, Devkishen Sisodia, Tanay Kumar Saha, Feng Li 0001, Mohammad Al Hasan
IEEE Trans. Mob. Comput.3
2018 FR-WARD: Fast Retransmit as a Wary but Ample Response to Distributed Denial-of-Service Attacks from the Internet of Things
abstract
While the Internet of Things (IoT) becomes increasingly popular and ubiquitous, IoT devices often remain unprotected and can be exploited to launch large-scale distributed denial-of-service (DDoS) attacks. One could attempt to employ traditional DDoS defense solutions, but these solutions are hardly suitable in IoT environments since they seldom consider the resource constraints of IoT devices. We present FR-WARD, a system that defends against DDoS attacks launched from an IoT network. FR-WARD operates close to potential attack sources at the gateway of an IoT network and drops packets to throttle any DDoS traffic that attempts to leave the IoT network. However, in order to properly react to traffic too difficult to categorically label as good or bad, FR-WARD employs a novel response based on the fast retransmit and flow control mechanisms of the Transmission Control Protocol (TCP) which minimizes the energy consumption and network latency of benign IoT devices within the policed network. Based on our mathematical analysis, simulation, and experimental evaluation, FR-WARD not only effectively mitigates DDoS traffic, but also minimizes the number of retransmitted packets and the connection durations of benign IoT devices. In fact, FR-WARD can successfully mitigate both naive flood attacks and smarter DDoS attacks that follow TCP congestion control but still reduce overhead caused by retransmitted packets for benign IoT devices by a up to a factor of 150.
Samuel Mergendahl, Devkishen Sisodia, Jun Li 0001, Hasan Çam
ICCCN2
2018 Securing the Smart Home via a Two-Mode Security Framework
Devkishen Sisodia, Samuel Mergendahl, Jun Li 0001, Hasan Çam
SecureComm (1)1