EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Ekramul Kabir
dblp:254/6111
· DBLP profile ↗
7ranked-venue papers
0as first author
7since 2021 · last 2025
0000-0003-2044-7187ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cross-Level Security Verification for Network Functions Virtualization (NFV)abstractNetwork Functions Virtualization (NFV) is a popular solution for providing multi-tenant network services on top of existing cloud infrastructures in an agile and cost-effective manner. However, as NFV employs multiple levels of virtualization, it also introduces novel security challenges, such as cloud-level security breaches that are invisible to NFV-level tenants. Towards verifying the security of NFV across all the levels (a.k.a. cross-level security verification), existing solutions are mostly insufficient, as each such solution typically only focuses on one specific level (e.g., cloud, SDN, or SFC), and verifying every level separately would be expensive or even infeasible. In this paper, we propose an efficient and practical system,NFVGuard+, for cross-level security verification for NFV. Particularly, the efficiency ofNFVGuard+is achieved by first performing the costly security verification at one level, and then extrapolating the verification result to other levels through conducting relatively lightweight consistency checks. Additionally, the practicality ofNFVGuard+is ensured by automating the essential steps (e.g., identifying security properties, collecting verification data, and conducting verification) based on a novel Entity-Relationship (ER) model of NFV stack, integrating the approach with OpenStack/Tacker (a popular choice for an NFV deployment), and finally evaluating its effectiveness using both synthetic and real data. Alaa Oqaily, Mohammad Ekramul Kabir, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar, Makan Pourzandi, Mourad Debbabi, Sudershan Lakshmanan Thirunavukkarasu, Mengyuan Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | iCAT+: An Interactive Customizable Anonymization Tool Using Automated Translation Through Deep LearningabstractData anonymization is a viable solution for data owners to mitigate their privacy concerns. However, existing data anonymization tools are inflexible to support various privacy and utility requirements of both data owners and data users. In most cases, this limitation is due to a lack of understanding of those requirements as well as the non-customizability of the existing tools. To address this limitation, we proposeiCAT+, which is an interactive and customizable anonymization approach. More specifically, we first automate the interpretation of data owners’ and data users’ textual requirements by deploying a Convolutional Neural Network (CNN) model for Natural Language Processing (NLP). Second, we introduce the concept of theanonymization spaceto model possible combinations of per-attribute anonymization primitives based on the level of privacy and utility that each primitive provides. Third, we design an ontology model that maps the translated requirements into their appropriate anonymization primitives in the defined anonymization space corresponding to the plain data. Fourth, we evaluate the efficiency and effectiveness ofiCAT+based on both real and synthetic network data. Finally, we assess its usability through a real user study involving participants from industry and research laboratories. Our experiments show the effectiveness and efficiency of our solution (e.g., requirement translation accuracy of 99% at the data owner side and 98% at the data user side, with a computational time of around one minute for the Google cluster dataset). Momen Oqaily, Mohammad Ekramul Kabir, Suryadipta Majumdar, Yosr Jarraya, Mengyuan Zhang 0001, Makan Pourzandi, Lingyu Wang 0001, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes ClustersabstractA large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution. Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | A Tenant-based Two-stage Approach to Auditing the Integrity of Virtual Network Function Chains Hosted on Third-Party CloudsabstractThere is a growing trend of hosting chains of Virtual Network Functions (VNFs) on third-party clouds for more cost-effective deployment. However, the multi-actor nature of such a deployment may allow a mismatch to silently arise between tenant-level specifications of VNF chains and their cloud provider-level deployment. Most existing auditing approaches would face difficulties in identifying such an integrity breach. First, relying on the cloud provider may not be sufficient, since modifications made by a stealthy attacker may seem legitimate to the provider. Second, the tenant cannot directly perform the auditing due to limited access to the provider-level data. In addition, shipping such data to the tenant would incur prohibitive overhead and confidentiality concerns. In this paper, we design a tenant-based, two-stage solution where the first stage leverages tenant-level side-channel information to identify suspected integrity breaches, and then the second stage automatically identifies and anonymizes selected provider-level data for the tenant to verify the suspected breaches from the first stage. The key advantages of our solution are: (i) the first stage gives tenants more control and transparency (with the capability of identifying integrity breaches without the provider's assistance), and (ii) the second stage provides tenants higher accuracy (with the capability of rigorous verification based on provider-level data). Our solution is integrated into OpenStack/Tacker (a popular choice for NFV deployment), and its effectiveness is demonstrated via experiments (e.g., up to 90% accuracy with the first stage alone). Momen Oqaily, Suryadipta Majumdar, Lingyu Wang 0001, Mohammad Ekramul Kabir, Yosr Jarraya, A. S. M. Asadujjaman, Makan Pourzandi, Mourad Debbabi |
CODASPY | 4 |
| 2022 | 5GFIVer: Functional Integrity Verification for 5G Cloud-Native Network Functionsabstract5G networks attain a better performance along with a reduction in cost by cloudifying its network functions as Cloud+native Network Functions (CNFs). However, CNF may introduce new security concerns (e.g., data exfiltration and ransomware) due to potential code injection attacks against network functions at runtime. This will potentially result in a breach of functional integrity of these network functions. Towards verifying such functional integrity breaches of CNFs at the 5G-operator-level, existing approaches fell short, as most of them either (i) perform pre-deployment verification (i.e., verifying the CNF image before the deployment) and hence fail to verify integrity breaches occurring after the deployment, or (ii) perform post-deployment verification (i.e., verifying against attack signatures or normal behavior patterns) approaches that require provider-level data (e.g., system calls) which is usually inaccessible to 5G operators. In this paper, we propose 5GFIVer, a new operator-oriented approach for functional integrity verification of CNFs that overcomes the above-mentioned limitations. First, our approach utilizes the side-channel information such as performance metrics (which are already available at the operator level) so that no provider-level data is needed. Second, our approach implements unsupervised machine learning algorithms to detect outliers through time-series analysis of those available performance metrics, and hence no instrumentation for the data collection as well as no training data is required. Third, we leverage the correlation between multiple CNFs to improve the accuracy and minimize false positives (e.g., caused by cloud dynamics). Our experimental results under an open source 5G testbed demonstrate the effectiveness and negligible overhead of our solution. A. S. M. Asadujjaman, Mohammad Ekramul Kabir, Hinddeep Purohit, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Makan Pourzandi |
CloudCom | 2 |
| 2022 | Coordinated Charging and Discharging of Electric Vehicles: A New Class of Switching AttacksabstractIn this work, we investigate that the abundance of Electric Vehicles (EVs) can be exploited to target the stability of the power grid. Through a cyber attack that compromises a lot of available EVs and their charging infrastructure, we present a realistic coordinated switching attack that initiates inter-area oscillations between different areas of the power grid. The threat model as well as linearized state-space representation of the grid are formulated to illustrate possible consequences of the attack. Two variations of switching attack are considered, namely, switching of EV charging and discharging power into the grid. Moreover, two possible attack strategies are also considered (i) using an insider to reveal the accurate system parameters and (ii) using reconnaissance activities in the absence of the grid parameters. In the former strategy, the system equations are used to compute the required knowledge to launch the attack. However, a stealthy system identification technique, which is tailored based on Eigenvalue Realization Algorithm (ERA), is proposed in latter strategy to calculate the required data for attack execution. The two-area Kundur, 39-Bus New England, and the Australian 5-area power grids are used to demonstrate the attack strategies and their consequences. The collected results demonstrate that by manipulation of EV charging stations and launching a coordinated switching attack to those portions of load, inter-area oscillations can be initiated. Finally, to protect the grid from this anticipated attack, a Support Vector Machine (SVM) based framework is proposed to detect and eliminate this attack even before being executed. Mohsen Ghafouri, Mohammad Ekramul Kabir, Bassam Moussa, Chadi Assi |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2022 | A Data Driven Performance Analysis Approach for Enhancing the QoS of Public Charging StationsabstractThe gaining momentum of Electric Vehicles’ (EV) market is hindered mainly due to the range anxiety. Accordingly, a ubiquitous charging station (CS) network is becoming indispensable. However, due to the lack of reservations or check-in policies in EV charging, users and operators are not provided proper information regarding waiting time at public CSs. This renders users reluctant to use public CSs. In addition, this incomplete information, creates difficulties in the deployment and operation of CSs. Evidently, there is a need to improve the Quality-of-Service (QoS) such as minimizing the waiting time or blocking probability. Therefore, CS owners rely during the designing stage on some theoretical distribution for the associated parameters assumption (i.e., battery capacity, charging demand, charging time, waiting time, etc.). To alleviate this situation, instead of depending on theoretical assumptions, real CSs usage data for EV charging are analyzed to acquire data driven distributions. Moreover, since the charging rate is dependent on the State of Charge (SoC), instead of a constant charging rate, a SoC dependent charging model based on real experimental data is proposed and evaluated with real data. Finally, exploiting the acquired distributions and charging model, variations of the$M/G/k$queuing system to approximate the waiting time, reneging probability and blocking probability is implemented. A detailed simulation is placed and the findings provide a direction for CS owners in determining the capacity (i.e., number of outlets) or parking area size to enhance the QoS. Joseph Antoun, Mohammad Ekramul Kabir, Ribal Atallah, Chadi Assi |
IEEE Trans. Intell. Transp. Syst. | 2 |