EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Reza Nosouhi
dblp:213/0864
· DBLP profile ↗
16ranked-venue papers
10as first author
11since 2021 · last 2024
0000-0001-6959-0975ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 8 since 2021Computer networks · 4 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Towards Availability of Strong Authentication in Remote and Disruption-Prone Operational Technology EnvironmentsabstractImplementing strong authentication methods in a network requires stable connectivity between the service providers deployed within the network (i.e., applications that users of the network need to access) and the Identity and Access Management (IAM) server located at the core segment of the network. This becomes challenging when it comes to Operational Technology (OT) systems deployed in a remote area, as they often get disconnected from the core segment of the network owing to unavoidable network disruptions. As a result, weak authentication methods and shared credential approaches are still adopted in these OT environments, exposing system vulnerabilities to increasingly sophisticated cyber threats. In this work, we propose a solution to enable highly available multi-factor authentication (MFA) services for OT environments. The proposed solution is based on Proof-of-Possession (PoP) tokens generated by an IAM server for registered users. The tokens are securely linked to user-specific parameters (e.g., physical security keys, biometrics, PIN, etc.), enabling strong user authentication (during disconnection time) through token validation. We deployed the Tamarin Prover software-based toolkit to verify security of the proposed authentication scheme. For performance evaluation, we implemented the designed solution in real-world settings. The results of our analysis and experiments confirm the efficacy of the proposed solution. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Divyans Mahansaria, Debi Prasad Pati, Praveen Gauravaram, Lei Pan 0002, Keshav Sood |
ARES | 1 |
| 2024 | The Value of Strong Identity and Access Management for ICS/OT SecurityabstractAs the integration of digital technologies with Industrial Control Systems (ICS) and Operational Technology (OT) continues to deepen, these systems increasingly become targets for sophisticated cyber attacks. These attacks not only threaten the operational integrity but also pose significant risks to national security and public safety. In this paper, we provide insights into the value of ICS/OT security solutions that are based on Identity and Access Management (IAM). Beginning with presenting an abstraction model for typical ICS/OT attacks, the paper systematically outlines the main stages of an attack and the corresponding vectors employed by adversaries. Drawing from the MITRE ATT&CK framework tailored for ICS, the paper quantifies the extent to which IAM-based mitigation approaches can strengthen defense-in-depth mechanisms against cyber threats targeting ICS/OT environments. Our findings show that there are modern attack vectors that can only be mitigated through robust IAM solutions. Moreover, we found that while advanced techniques such as firewall and gateway-based intelligent threat detection play a significant role in safeguarding I CS/OT, they are insufficient on their own to address several attack vectors in ICS/OT environments. Mohammad Reza Nosouhi, Zubair A. Baig, Robin Doss, Praveen Gauravaram, Debi Prasad Pati, Divyans Mahansaria, Keshav Sood, Lei Pan 0002 |
PST | 1 |
| 2024 | Examining usable security features and user perceptions of Physical Authentication DevicesabstractDespite the enhanced security benefits offered by Physical Authentication Devices (PADs) compared to other forms of Multi-Factor Authentication (MFA), the adoption and retention of PADs remain relatively low in comparison to other MFA methods. Evidence indicates that the limited widespread adoption and usage of PADs are primarily due to negative user perceptions concerning their usability and security features. Moreover, there's a limited understanding of how users from diverse backgrounds perceive PADs with their varying standards and features. To bridge this knowledge gap, we undertook a multiple case study with 23 users spanning varied demographic characteristics (age, gender, education, and experience with MFA) to use and test three distinct PADs. Case study participants were provided with three unique PAD devices featuring different characteristics/features and were prompted to share their experiences of installation, usage, and troubleshooting over a 2-week span via an initial questionnaire, logbook, and a final interview. The gathered data were analysed using NVIVO, a Qualitative Research Software platform, uncovering notable disparities between user groups and their predilections for specific PADs. Further discussions from our research illuminate four primary areas (Compatibility, Support, Quality and Simplicity) where usable security features impede positive user perception of PAD devices and addressing these areas is crucial for enhancing PAD adoption and retention rates. Ashish Nanda, Jongkil Jeong, Syed Wajid Ali Shah, Mohammad Reza Nosouhi, Robin Doss |
Comput. Secur. | 4 |
| 2024 | User Characteristics and Their Impact on the Perceived Usable Security of Physical Authentication DevicesabstractPhysical authentication devices (PADs) offer a higher level of security than other authentication technologies commonly used in multifactor authentication (MFA) schemes because they are much less vulnerable to attack. However, PAD uptake remains significantly lower than that for SMS and app-based approaches, accounting for only 10% of all authentication technologies currently being utilized in MFA. Prior studies indicate that the primary reason for this low adoption rate is due to negative users' perceptions and attitudes toward the usability of PADs; many of these studies often skew toward a particular set of users (e.g., young university students, etc.), often creating a bias toward what usable security entails. To address this limitation, we have formulated an original research methodology that segments users into specific groups based on their user characteristics (i.e., age, education, and experience) and examines how each group defines usability and ranks their preferences regarding certain security features. Based on a survey of 410 participants, our results indicate that there are indeed different usable security preferences for each user group, and we, therefore, provide recommendations on how existing PADs might be enhanced to support usability and improve adoption rates. Jongkil Jeong, Syed Wajid Ali Shah, Ashish Nanda, Robin Doss, Mohammad Reza Nosouhi, Jeb Webb |
IEEE Trans. Hum. Mach. Syst. | 5 |
| 2023 | UCoin: An Efficient Privacy Preserving Scheme for CryptocurrenciesabstractIn cryptocurrencies, privacy of users is preserved using pseudonymity . However, it has been shown that pseudonymity does not result in anonymity if a user's transactions are linkable. This makes cryptocurrencies vulnerable to deanonymization attacks. The current solutions proposed in the literature suffer from at least one of the following issues: (1) requiring a trusted third–party entity, (2) poor performance, and (3) incompatible with the standard structure of cryptocurrencies. In this article, we propose Unlinkable Coin (UCoin), a secure mix–based approach to address these issues. In UCoin, the link between the input (payer) and output (payee) addresses in a transaction is broken. This is done by mixing the transactions of multiple users into a single aggregated transaction in which the output addresses have been secretly shuffled. In our protocol design, we first develop HDC–net, a secure shuffling protocol that enables a group of users to anonymously publish their data. Then, we deploy the proposed HDC–net protocol in the UCoin architecture (as a mixing unit) to generate the aggregate transactions. We show that UCoin (1) does not rely on a trusted third–party, (2) can mix 50 transactions in 6.3 seconds that is 18% faster than the current solutions, and (3) is fully compatible with the architecture of cryptocurrencies. Mohammad Reza Nosouhi, Shui Yu 0001, Keshav Sood, Marthie Grobler, Raja Jurdak, Ali Dorri, Shigen Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Accurate Detection of IoT Sensor Behaviors in Legitimate, Faulty and Compromised ScenariosabstractIn smart farming sector, Internet of Things (IoT) based smart sensing systems are vulnerable to failure, malfunction, and malicious attacks. Also, sensors are deployed often in an alien and harsh environment. Here, the conditions are not well supportive which either causes the sensor to fail prematurely or gives unusual and erroneous readings, known as outliers. This effects the smart network's performance and decision-making ability in many ways. Therefore, it is important to accurately detect the IoT sensor behaviour in legitimate, faulty, and compromised or attack scenarios. To distinguish the sensor behaviour in different scenarios we have proposed a feasible approach using spatial correlation theory which is validated using Moran'sIindex tool. We have used Classification and Regression Trees (CART), Random Forest (RF), and Support Vector Machine (SVM) models to test our approach. For real-time anomaly detection we have used an edge computing technology. We have compared the proposed approach, using Forest Fire real dataset, with the three existing recent works. Our results are promising in terms of accurate detection of IoT sensor behaviours in real-time. This will assist the precision farming industry in making better decisions to securely manage IoT field network, increase productivity, and improves operational efficiency. Keshav Sood, Mohammad Reza Nosouhi, Neeraj Kumar 0001, Anuroop Gaddam, Bohao Feng, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Weak-Key Analysis for BIKE Post-Quantum Key Encapsulation MechanismabstractThe evolution of quantum computers poses a serious threat to contemporary public-key encryption (PKE) schemes. To address this impending issue, the National Institute of Standards and Technology (NIST) is currently undertaking the Post-Quantum Cryptography (PQC) standardization project intending to evaluate and subsequently standardize the suitable PQC scheme(s). One such attractive approach, called Bit Flipping Key Encapsulation (BIKE), has entered the final round of the competition. Despite having some attractive features, the IND-CCA security of BIKE depends on the average decoder failure rate (DFR), a higher value of which can facilitate a particular type of side-channel attack. Although BIKE adopts the Black-Grey-Flip (BGF) decoder that offers a negligible DFR, the effect of weak-keys on the average DFR has not been fully investigated. In this paper, we implement the BIKE scheme, and then through extensive experiments show that the weak-keys can be a potential threat to IND-CCA security of the BIKE scheme and thus need attention from the relevant research community. We also propose a key-check algorithm that can potentially supplement the BIKE mechanism and prevent users from adopting weak-keys. Mohammad Reza Nosouhi, Syed Wajid Ali Shah, Lei Pan 0002, Yevhen Zolotavkin, Ashish Nanda, Praveen Gauravaram, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Intrusion Detection Scheme With Dimensionality Reduction in Next Generation NetworksabstractDue to millions of heterogeneous physical nodes, multiple-vendor and multi-tenant domains, and technologies etc., 5G has greatly expanded the threat landscape. Particularly from the high rate of traffic and ultra-low latency requirement of applications in 5G networks, the detection of the network traffic anomalies in real-time is critical. The conventional security approaches lack compatibility with modern network designs and are not much effective in 5G settings. We propose a two-stage network traffic anomaly detection system compatible with ETSI-NFV standard 5G architecture. Our architecture consists of two modules, i.e., (a) Dimensionality Reduction to compress the sample size at the edge of 5G networks and (b) Deep Neural Network classifier (DNN) that detects traffic anomalies. We have conducted our experiments using OMNET++ and ETSI-NFV (OSM MANO) 5G orchestration real platform deployed on AWS cloud systems. We have used the UNSW-NB15 data set and have shown that at dimensionality reduction factor of 81% the detection accuracy obtained is 98%. The proposal is compared with other recent approaches to show the overall merit of the architecture. Keshav Sood, Mohammad Reza Nosouhi, Dinh Duc Nha Nguyen, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Performance Evaluation of a Novel Intrusion Detection System in Next Generation NetworksabstractThe integration of Internet of Things (IoT) with 5G simply creates additional threat landscape and any network infrastructure is more vulnerable. Severe attacks on networks potentially damage organization reputation, customers or tenants lose confidence, and impacts operational and maintenance cost. Intrusion detection systems (IDSs) are an effective approach to mitigate threats. We present a novel IDS mechanism in which the unique Radio Frequency (RF) features of IoT devices are used to create a learning model which is later used to identify the illegitimate devices in the network. Leveraging the Deep Autoencoder (DAE), the existing steady-state feature extraction is generalized. The performance evaluation is conducted using a real data set from different aspects including the mobility of the nodes. The proposed IDS is broken down into pluggable virtual network function (VNF) components and its evaluation is presented for its integration into the 5G network slicing ecosystem from the perspective of the European Telecommunications Standards Institute (ETSI) standards. A Proof of Concept (PoC) is presented using ETSI Open Source NFV Management and Orchestration (OSM-MANO) test bed, deployed on AWS cloud systems, to show how the proposed approach would fit in with a real-life MANO. Keshav Sood, Dinh Duc Nha Nguyen, Mohammad Reza Nosouhi, Neeraj Kumar 0001, Frank Jiang 0001, Morshed Chowdhury, Robin Doss |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Bushfire Risk Detection Using Internet of Things: An Application ScenarioabstractWith rising temperatures and events contributing to climate change, the world is facing extreme weather patterns. Recently, Australia was hit hard by bushfires, the most devastating fires ever faced by the country. The economic damage reported was nearly one billion Australian dollars and an estimated three billion native animals were killed or adversely affected. Given the extent and intensity of this damage, researchers are seeking effective solutions to enable the prediction of fire before it starts to increase the time available for firefighters to protect lives and assets and prepare to mitigate the fires. This motivated us to investigate an approach to address this critical problem. In this article, we propose a machine learning (ML)-based approach that detects anomalies in spatiotemporal measurements of environmental parameters (e.g., temperature, relative humidity, etc.). In the proposed approach, an ML-based model learns the normal spatiotemporal behavior of the environmental data (collected over a period of one year). This is carried out during a one-time training phase. Then, during the detection phase, any spatiotemporal pattern in the real-time data (received from the field sensors) that is different than the normal pattern will be identified by the model as anomaly which indicates a possible bushfire situation. Following this, we propose a supplementary classification model based on Moran’s I index to ensure that the detected anomalies are not due to either a sensor failure or a security attack (which are common in Internet of Things). We developed three different ML models for performance evaluation and comparison and used the Forest Fire data set to train them. The results of our experiments confirm the effectiveness of the proposed approach in the early detection of fire symptoms. Mohammad Reza Nosouhi, Keshav Sood, Neeraj Kumar 0001, Tricia Wevill, Chandra Thapa |
IEEE Internet Things J. | 1 |
| 2022 | Towards Spoofing Resistant Next Generation IoT NetworksabstractThe potential vulnerability to wireless spoofing attacks is still a critical concern for Next Generation Internet of Things (NGIoT) networks which may result in catastrophic consequences in mission–critical applications. Conventional solutions may impose additional signal processing, protocol, and latency overheads which are inappropriate for NGIoT networks designed to provide high–speed and low–latency connections for a large number of resource–constrained IoT devices. In this paper, we utilize the uniqueness of beam pattern features in mmWave–enabled devices and propose a scalable security mechanism for the detection of wireless spoofing attacks in NGIoT networks. This uniqueness is proven to exist due to the non–ideal manufacturing of antenna arrays used in mmWave–enabled devices. In our approach, when legitimate mmWave–enabled IoT devices enrol into the network, their unique beam features are learned by a learning model developed at the network server. Then, during data transmission, network base stations (gNBs)/Access Points (APs) measure the beam features from the received RF signals and send them to the network server for the detection of anomalies. We develop our learning model based on Deep Autoencoders (DAEs) that are an effective tool for anomaly detection. Fortunately, the beam feature extraction can be performed using the beam searching mechanism that is already provided in mmWave standards (5G–NR and IEEE 802.11ad). Thus, feature extraction does not introduce any signal processing overheads to the system. Moreover, the proposed mechanism imposes zero computation/communication overhead to the resource—constrained IoT nodes. In our experiments, we reached 98.6% accuracy in the detection of illegitimate devices which confirms the effectiveness of the proposed approach. Mohammad Reza Nosouhi, Keshav Sood, Marthie Grobler, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Blockchain for secure location verification
Mohammad Reza Nosouhi, Shui Yu 0001, Wanlei Zhou 0001, Marthie Grobler, Habiba Keshtiar |
J. Parallel Distributed Comput. | 1 |
| 2020 | PASPORT: A Secure and Private Location Proof Generation and Verification FrameworkabstractRecently, there has been a rapid growth in location-based systems and applications in which users submit their location information to service providers in order to gain access to a service, resource, or reward. We have seen that in these applications, dishonest users have an incentive to cheat on their location. Unfortunately, no effective protection mechanism has been adopted by service providers against these fake location submissions. This is a critical issue that causes severe consequences for these applications. Motivated by this, we propose the Privacy-Aware and Secure Proof Of pRoximiTy (PASPORT) scheme in this article to address the problem. Using PASPORT, users submit a location proof (LP) to service providers to prove that their submitted location is true. PASPORT has a decentralized architecture designed for ad hoc scenarios in which mobile users can act as witnesses and generate LPs for each other. It provides user privacy protection as well as security properties, such as unforgeability and nontransferability of LPs. Furthermore, the PASPORT scheme is resilient to prover-prover collusions and significantly reduces the success probability of Prover-Witness collusion attacks. To further make the proximity checking process private, we propose P-TREAD, a privacy-aware distance bounding protocol and integrate it into PASPORT. To validate our model, we implement a prototype of the proposed scheme on the Android platform. Extensive experiments indicate that the proposed method can efficiently protect location-based applications against fake submissions. Mohammad Reza Nosouhi, Keshav Sood, Shui Yu 0001, Marthie Grobler |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2019 | Improving Data Utility Through Game Theory in Personalized Differential Privacy
Lei Cui 0006, Youyang Qu, Mohammad Reza Nosouhi, Shui Yu 0001, Jianwei Niu 0002, Gang Xie 0001 |
J. Comput. Sci. Technol. | 3 |
| 2018 | SPARSE: Privacy-Aware and Collusion Resistant Location Proof Generation and VerificationabstractRecently, there has been an increase in the number of location-based services and applications. It is common for these applications to provide facilities or rewards for users who visit specific venues frequently. This creates the incentive for dishonest users to lie about their location and submit fake check-ins by changing their GPS data. To solve this issue, different distributed location proof schemes have been proposed to generate location proofs for mobile users. However, these schemes have some drawbacks: (1) they are vulnerable to either Prover-Prover or Prover-Witness collusions, (2) the location proof generation process is slow when users adopt a long private key, and (3) their implementation requires some hardware changes on mobile devices. To address these issues, we propose the Secure, Privacy-Aware and collusion Resistant poSition vErification (SPARSE) scheme to generate private location proofs for mobile users. SPARSE has a distributed architecture designed for ad-hoc scenarios in which mobile users generate location proofs for each other. Since we do not integrate any distance bounding protocol into SPARSE, it becomes an easy-to-implement scheme in which the location proof generation process is independent of the length of the users' private key. We provide a comprehensive security analysis and simulation which show that SPARSE provides privacy protection as well as security properties for users including integrity, unforgeability and non-transferability of the location proofs. Moreover, it achieves a highly reliable performance against collusions. Mohammad Reza Nosouhi, Shui Yu 0001, Marthie Grobler, Yong Xiang 0001, Zuqing Zhu |
GLOBECOM | 1 |
| 2017 | A Hybrid Location Privacy Protection Scheme in Big Data EnvironmentabstractLocation privacy has become a significant challenge of big data. Particularly, by the advantage of big data handling tools availability, huge location data can be managed and processed easily by an adversary to obtain user private information from Location-Based Services (LBS). So far, many methods have been proposed to preserve user location privacy for these services. Among them, dummy-based methods have various advantages in terms of implementation and low computation costs. However, they suffer from the spatiotemporal correlation issue when users submit consecutive requests. To solve this problem, a practical hybrid location privacy protection scheme is presented in this paper. The proposed method filters out the correlated fake location data (dummies) before submissions. Therefore, the adversary can not identify the user's real location. Evaluations and experiments show that our proposed filtering technique significantly improves the performance of existing dummy-based methods and enables them to effectively protect the user's location privacy in the environment of big data. Mohammad Reza Nosouhi, Vu Viet Hoang Pham, Shui Yu 0001, Yong Xiang 0001, Matthew J. Warren |
GLOBECOM | 1 |