P. Santhi Thilagam

dblp:28/6653 · DBLP profile ↗
← Back
25ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0002-8359-1330ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 2 first-author · 3 since 2021Security and privacy · 6 · 4 since 2021Databases, data management, data science and information retrieval · 6Computer networks · 3 · 1 since 2021Software engineering, systems software and programming languages · 3Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2026 POSTER: Context-Aware Behavior Modeling of RESTful Services for Identifying State-Dependent Logic Vulnerabilities
abstract
REST APIs serve as the core interface of modern distributed systems, where operations are highly interconnected and depend on one another. Many severe vulnerabilities arise from hidden dependencies across multiple API operations, making accurate dependency modeling essential for effective testing. Existing approaches rely on basic producer-consumer relationships or simple parameter matching, which introduce false dependencies, cause inefficient exploration, or miss implicit relationships.
Abinaya J, Umang Agarwal, Gupta Harsh Hemant, P. Santhi Thilagam, Sivakumar Kaliappan
AsiaCCS5
2025 Next-Generation DDoS Attacks on IoT Deployments: Targeting the Advanced Features of MQTT v5.0 Protocol
abstract
Message queuing telemetry transport (MQTT) has emerged as the widely adopted application layer protocol for IoT environments because of its lightweight header, minimal power, and bandwidth requirements. Despite its popularity, the earlier version of the protocol, MQTT v3.1.1, encounters performance issues in large-scale implementations and required an update to handle the growing requirements of modern IoT applications. In response to these concerns, MQTT v5.0 was released with several significant features designed to enhance the reliability, user experience, and performance of IoT systems. While the MQTT protocol features were intended to facilitate robust and efficient communications, adversaries could exploit these features to mount various types of attacks in IoT deployments. More specifically, the Denial-of-Service (DoS) attacks toward the MQTT protocol have recently gained a lot of attention from the research community. However, the existing works primarily focus only on exploring the possibilities of misusing the MQTT v3.1.1 protocol features to generate DoS attacks in IoT realms. In this work, we attempt to extensively investigate the advanced protocol features of MQTT v5.0 that can be exploited to launch DDoS attacks impacting the IoT paradigm. We present the first critical evaluation of Distributed DoS (DDoS) attacks on the MQTT v5.0 protocol by analyzing three significant features: 1) CONNECT properties; 2) user properties; and 3) flow control. Moreover, we systematically propose attack scenarios based on the adversary’s capabilities, thus illustrating the practicality of proposed attacks in real-world scenarios. Furthermore, we built a real-world testbed for IoT healthcare application to evaluate the severity of the identified attacks. The experimental results demonstrate the effectiveness of these attacks in impacting the availability of guaranteed IoT services to legitimate users, even in times of need. Additionally, we disclose the insightful findings of this work as takeaways and present research initiatives toward developing effective defense mechanisms for MQTT v5.0 protocol. We hope that such a discussion could pave the way for future research, contributing to MQTT v5.0 security and resiliency.
Sujitha Lakshminarayana, P. Santhi Thilagam
IEEE Internet Things J.2
2023 Multi-layer perceptron based fake news classification using knowledge base triples
Srinivasa K, P. Santhi Thilagam
Appl. Intell.2
2023 Hindi fake news detection using transformer ensembles
Amit Praseed, Jelwin Rodrigues, P. Santhi Thilagam
Eng. Appl. Artif. Intell.3
2022 HTTP request pattern based signatures for early application layer DDoS detection: A firewall agnostic approach
Amit Praseed, P. Santhi Thilagam
J. Inf. Secur. Appl.2
2021 Preserving Privacy of Co-occurring Keywords over Encrypted Data
D. V. N. Siva Kumar, P. Santhi Thilagam
DBSec2
2021 Fuzzy Request Set Modelling for Detecting Multiplexed Asymmetric DDoS Attacks on HTTP/2 servers
Amit Praseed, P. Santhi Thilagam
Expert Syst. Appl.2
2021 Modelling Behavioural Dynamics for Asymmetric Application Layer DDoS Detection
abstract
Asymmetric application layer DDoS attacks using computationally intensive HTTP requests are an extremely dangerous class of attacks capable of taking down web servers with relatively few attacking connections. These attacks consume limited network bandwidth and are similar to legitimate traffic, which makes their detection difficult. Existing detection mechanisms for these attacks use indirect representations of actual user behaviour and complex modelling techniques, which leads to a higher false positive rate (FPR) and longer detection time, which makes them unsuitable for real time use. There is a need for simple, efficient and adaptable detection mechanisms for asymmetric DDoS attacks. In this work, an attempt is made to model the actual behavioural dynamics of legitimate users using a simple annotated Probabilistic Timed Automata (PTA) along with a suspicion scoring mechanism for differentiating between legitimate and malicious users. This allows the detection mechanism to be extremely fast and have a low FPR. In addition, the model can incrementally learn from run-time traces, which makes it adaptable and reduces the FPR further. Experiments on public datasets reveal that our proposed approach has a high detection rate and low FPR and adds negligible overhead to the web server, which makes it ideal for real time use.
Amit Praseed, P. Santhi Thilagam
IEEE Trans. Inf. Forensics Secur.2
2020 Multiplexed Asymmetric Attacks: Next-Generation DDoS on HTTP/2 Servers
abstract
Distributed Denial of Service (DDoS) attacks using the HTTP protocol have started gaining popularity in recent years. A recent trend in this direction has been the use of computationally expensive requests to launch attacks. These attacks, called Asymmetric Workload attacks can bring down servers using limited resources, and are extremely difficult to detect. The introduction of HTTP/2 has been welcomed by developers because it improves user experience and efficiency. This was made possible by the ability to transport HTTP requests and their associated inline resources simultaneously by using Multiplexing and Server Push. However multiplexing has made request traffic bursty and rendered DDoS detection mechanisms based on connection limiting obsolete. Contrary to its intention, multiplexing can also be misused to launch sophisticated DDoS attacks using multiple high workload requests in a single TCP connection. However, sufficient research has not been done in this area. Existing research demonstrates that the HTTP/2 protocol allows users to launch DDoS attacks easily, but does not focus on whether an HTTP/2 server can handle DDoS attacks more efficiently or not. Also, sufficient research has not been done on the possibility of Multiplexing and Server Push being misused. In this work, we analyse the performance of an HTTP/2 server compared to an HTTP/1.1 server under an Asymmetric DDoS attack for the same load. We propose a new DDoS attack vector called a Multiplexed Asymmetric DDoS attack, which uses multiplexing in a different way than intended. We show that such an attack can bring down a server with just a few attacking clients. We also show that a Multiplexed Asymmetric Attack on a server with Server Push enabled can trigger an egress network layer flood in addition to an application layer attack.
Amit Praseed, P. Santhi Thilagam
IEEE Trans. Inf. Forensics Secur.2
2019 Crime base: Towards building a knowledge base for crime entities and their relationships from online news papers
Srinivasa K, P. Santhi Thilagam
Inf. Process. Manag.2
2019 Approaches and challenges of privacy preserving search over encrypted data
D. V. N. Siva Kumar, P. Santhi Thilagam
Inf. Syst.2
2019 Searchable encryption approaches: attacks and challenges
D. V. N. Siva Kumar, P. Santhi Thilagam
Knowl. Inf. Syst.2
2018 Discovering spammer communities in twitter
P. V. Bindu, P. Santhi Thilagam
J. Intell. Inf. Syst.3
2018 DetLogic: A black-box approach for detecting logic vulnerabilities in web applications
G. Deepa, P. Santhi Thilagam, Amit Praseed, Alwyn Roshan Pais
J. Netw. Comput. Appl.2
2016 Securing web applications from injection and logic vulnerabilities: Approaches and challenges
G. Deepa, P. Santhi Thilagam
Inf. Softw. Technol.2
2016 Mining social networks for anomalies: Methods and challenges
P. V. Bindu, P. Santhi Thilagam
J. Netw. Comput. Appl.2
2016 Securing native XML database-driven web applications from XQuery injection vulnerabilities
Nushafreen Palsetia, G. Deepa, Furqan Ahmed Khan, P. Santhi Thilagam, Alwyn Roshan Pais
J. Syst. Softw.4
2015 Dynamics of Multi-Campaign Propagation in Online Social Networks
abstract
Ever since the advent of online social networking, people have been voluntarily posting and consuming information on the web. This new method to communicate digitally provides the means to spread information considerably far in a very short span of time with minimal resources. Social networks are increasingly being used to spread misinformation online due to low-costs in organizing grassroots of these campaigns. Our goal in this paper is to determine the efficiency with which campaigns can succeed in an online social network, efficiency represents the ease with which a campaign can triumph over other competing campaigns in a network. We model the information diffusion using Multi-Campaign Independent Cascade Model, and by applying node coercion and link cutting as campaign limiting strategies we ascertain how efficiently a campaign can succeed. The efficiency measure tackles the problem of determining the survivability of campaigns, which is used to ensure success or failure of a campaign using campaign limiting strategies.
M. Thejaswi, Sriniketh Vijayaraghavan, Avinash Das, P. Santhi Thilagam
ASONAM4
2015 Dynamics of multi-campaign propagation in online social networks
abstract
Ever since the advent of online social networking, people have been voluntarily posting and consuming information on the web. This new method to communicate digitally provides the means to spread information considerably far in a very short span of time with minimal resources. Social networks are increasingly being used to spread misinformation online due to low-costs in organizing grassroots of these campaigns. Our goal in this paper is to determine the efficiency with which campaigns can succeed in an online social network, efficiency represents the ease with which a campaign can triumph over other competing campaigns in a network. We model the information diffusion using Multi-Campaign Independent Cascade Model, and by applying node coercion and link cutting as campaign limiting strategies we ascertain how efficiently a campaign can succeed. The efficiency measure tackles the problem of determining the survivability of campaigns, which is used to ensure success or failure of a campaign using campaign limiting strategies.
M. Thejaswi, Sriniketh Vijayaraghavan, Avinash Das, P. Santhi Thilagam
DSAA4
2015 Heuristics based server consolidation with residual resource defragmentation in cloud data centers
K. Sunil Rao, P. Santhi Thilagam
Future Gener. Comput. Syst.2
2014 Optimization of countour based template matching using GPGPU based hexagonal framework
abstract
This paper presents a technique to optimize contour based template matching by using General Purpose computation on Graphics Processing Units (GPGPU). Contour based template matching requires edge detection and searching for presence of a template in an entire image, real time implementation of which is not trivial. Using the proposed solution, we could achieve an implementation fast enough to process a standard video (640 × 480) in real time with sufficient accuracy.
Mayank Bhagya, Sanjay Tripathi, P. Santhi Thilagam
HIS3
2014 Reputation-based cross-layer intrusion detection system for wormhole attacks in wireless mesh networks
abstract
ABSTRACT Wireless mesh networks provide long‐distance wireless network connectivity over heterogeneous devices for greater scalability and availability. However, protecting legitimate long‐distance wireless links from wormhole attacks is an important yet challenging security issue in wireless mesh networks. In this paper, we propose a reputation‐based cross‐layer intrusion detection system to effectively detect various wormhole attacks. The proposed system analyses the behaviours of the routing paths in wireless mesh networks to correctly isolate the malicious wormhole paths from legitimate long‐distance wireless links. It usesreputationandcross‐layer parametersfor comprehensive ability to isolate the wormhole attacks in routing paths. This isolation ensures full utilisation of legitimate long‐distance wireless links in wireless mesh networks, which is not possible with the existing wormhole attack detection approaches. Experimental results show that the proposed system increases the detection rate, decreases the false alarm rate, and secures legitimate long‐distance wireless links in wireless mesh networks. Copyright © 2014 John Wiley & Sons, Ltd.
Ganesh Reddy Karri, P. Santhi Thilagam
Secur. Commun. Networks2
2012 An Empirical Study of License Violations in Open Source Projects
abstract
The use of Open Source Software (OSS) components in building applications has presented the challenge of integrating them in a way such that the licenses of the individual components do not conflict with each other and if applicable, the overall license of the application. These conflicts lead to violations, with many having far reaching legal consequences. While proprietary software firms are often plagued with the risks of not satisfying the clauses of OSS licenses, we hypothesize that a large degree of code reuse within the OSS community poses similar threats too. Through an analysis of 1423 projects, consisting of approximately 69 million non-blank lines of code from Google Code project hosting, we validate instances of code reuse between projects by comparing their licenses. Our results discover four violations, evaluated by searching for files that share similar content. Additionally, we present statistics on code reuse within the set of projects.
Arunesh Mathur, Harshal Choudhary, Priyank Vashist, William Thies, P. Santhi Thilagam
SEW5
2008 Extraction and optimization of fuzzy association rules using multi-objective genetic algorithm
P. Santhi Thilagam, V. S. Ananthanarayana
Pattern Anal. Appl.1
2007 Semantic Partition Based Association Rule Mining across Multiple Databases Using Abstraction
abstract
Association rule mining activity is both computationally and I/O intensive. A majority of ARM algorithms reported in the literature is efficient in handling high dimensional data but is single database based. Many enterprises maintain several databases independently to serve different purposes. There could be an implicit association among various parts of such data. In this paper, we investigate a mechanism to generate association rules (ARs) between the sets of values which are subsets of domains of attributes occurring in relations present in different databases. In our approach, the relevant databases, relations and attributes are identified using knowledge, multiple navigation paths are generated using data dictionary, a structure is constructed which semantically partitions the resultant relation using this navigation paths. We propose an efficient algorithm which uses this structure to generate ARs.
P. Santhi Thilagam, V. S. Ananthanarayana
ICMLA1