Shuvo Bardhan

dblp:302/2115 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
11since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 11 · 5 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 5 first-author · 11 since 2021
YearPublicationVenuePosition
2026 A Risk Scoring Mechanism for External Attack Surface Management (EASM)
Shuvo Bardhan
COMPSAC2
2026 A Quantitative EPSS-Based Risk Scoring Framework for HIPAA Technical Safeguards in Mobile Healthcare Applications
Md Bajlur Rashid, Shuvo Bardhan, Tasmiah Rahman, Md Abdul Barek, Md Raihan Mia, Hansika Kolli, Naveed Ashfaque, Hossain Shahriar, Sheikh Iqbal Ahamed
COMPSAC2
2025 Vulnerability Weightage and Prioritization Model: Derived from Real Data and Community Insights
abstract
In the current cybersecurity industry, managing vulnerabilities is a critical component (i.e., to provide a robust cybersecurity defense). Traditional scoring systems like CVSS often lack real-time threat adaptability. Keeping this in mind, our research introduces an enhanced vulnerability prioritization model by integrating–(i) CVSS; (ii) EPSS; (iii) CWE; (iv) CAPEC; (v) MITRE ATT&CK mappings; and (vi) other community-driven data. Our model leverages real-time intelligence and a weighted scoring system to prioritize vulnerabilities effectively; and by doing so, it provides–(a) a dynamic and accurate assessment; (b) improves vulnerability management; and (c) strengthens the overall security posture.
Saumyajeet Das, Shuvo Bardhan
COMPSAC3
2025 Extending the Attack Graph Model: Integrating Reconnaissance Stages
abstract
Reconnaissance plays a pivotal role in most cyber attacks; and yet, it has not been integrated into the NIST Attack Graph model (i.e., the most widely adopted cyber risk estimation model). In this paper, we have integrated reconnaissance into attack graphs and by doing so, one can visualize all the attack paths including the reconnaissance stages that an attacker might take (i.e., while moving towards the goal states). In essence, this model bridges the gap between reconnaissance stages and active attack stages. Additionally, we have also provide a detailed case study for illustration.
Owais Shaikh, Shuvo Bardhan
COMPSAC3
2025 Strengthening Cyber Resilience of Small Businesses in BFSI: A CIA-Driven Strategy for Investment and Risk Management
abstract
In today’s world, the banking, financial services, and insurance (BFSI) sector relies heavily on real-time payments, automated decision-making, analytical data support operations, and so on. However, cybersecurity remains a huge concern as the number of cyber threats are growing exponentially. In order to keep the expenses in check, cybersecurity investments must be made strategically. This study suggests a CIA-driven approach to maximise security investment for small businesses in the BFSI sector by balancing availability, confidentiality, and integrity. Additionally, this framework increases operational effectiveness and reduces risk.
Rajesh Yalavaguli Seetharamarao, Shuvo Bardhan
COMPSAC3
2025 Vendor PulseGen: Generative Vendor Risk Management Platform
abstract
In today’s world, vendor risk management (VRM) requires field expertise and assessment capabilities. A general concern in VRM is ‘what to ask?’ - usually addressed in the literature using transformer-based models. We use zero-shot approaches as these don’t have specialized VRM understanding; likewise, uploading sensitive vendor information to fine-tune LLM is not possible. To solve, we utilize the non-parametric learning abilities of LLMs to generate context-based tailored questionnaires depending on the vendor metadata (i.e., publicly available). We also assign an quantitative risk score to the different risk dimensions that our model is capable of assessing which includes compliance based risks, external surface based risks; and overall risk posture (i.e., assessed by the questions asked). By integrating the structured scoring mechanism such as Question Risk Score (QRS), Compliance Risk Score (CRS), and External Surface Risk (ESR), this platform offers an efficient approach to assess the vendor risk in a quantified manner.
Swapnil Yasasvi, Nilanjan Sinhababu, Suman Kumar Chakraborty, Shuvo Bardhan
COMPSAC4
2024 A Risk Assessment based RBAC using Attack Graphs to Mitigate Insider Threat during UAQ
abstract
User Authorization Query in Role Based Access Control allows users to gain permissions without considering the possibility of an insider threat. In this paper, a solution has been proposed by introducing the notion of attack graphs, which is a standard tool for measuring the likelihood of a network being compromised. In our approach, each time a user requests for a set of permissions (i.e., on resources and/or services of the network) the likelihood of the network being compromised with respect to the user is calculated (i.e., by using attack graphs). If the likelihood falls below a preset threshold, then the requested permission will not be granted (i.e., to prevent an insider attack). In some cases, it may so happen that the permission need to be granted. For such cases, a multi-objective optimization model has also been formulated, which generates a set of non-dominated solutions (i.e., pareto solutions). These pareto solutions provide the minimal set of permissions that need to be removed, in order to allow the that particular permission to be granted to the user (i.e., without allowing the likelihood to be above the threshold).
Shuvo Bardhan
COMPSAC1
2023 Survivability Model of Networks using Attack Graphs and Markov Chains
abstract
The most difficult task that a networks administrator faces today is to save a network from an ongoing cyber attack. Modern networks have the capability of detecting ongoing cyber attacks (i.e., using Intrusion Detection Systems (Ids)). Having said that, the number of false alarms tend to be high and acting upon every alarm does not necessarily make the network effective. In this paper, the contributions are-(a) established the credibility of an alarm using poisson distribution; and (b) presented a novel survivability model using the concepts of markov chains and attack graphs. The overall objective in this paper is to help network administrators to decide on whether to terminate a computer system in order to save the network (i.e., when an alarm is raised by an Ids).
Shuvo Bardhan
COMPSAC1
2022 A Multi-Objective Approach for Security Hardening and Probabilistic Vulnerability Assessment on Attack Graphs
abstract
Assessing vulnerabilities of a network and mitigating them is a challenging task owing to the complexity and scale of the problem. Various probabilistic security metrics on attack graphs are presented in the literature to handle realistic attack scenarios involving large attack graphs. In our work, we propose a generalized path-enumeration based technique for computing attack probabilities on attack graphs that can handle repeated vulnerabilities as well as cyclic graphs. A multiplicative idempo-tency based approach is used for computation while aggregating the path probabilities. We employ the inclusion-exclusion principle to prove the soundness of our proposed technique. Also, in practice, we found that attackers retain experience and face reduced difficulty in exploiting a vulnerability in repeated attacks. In this paper, we extend the proposed probabilistic measure to incorporate such conditions leveraging possible decay functions. Our proposed metric is helpful in service management for network hardening. Network hardening is formulated as a multi-objective optimization problem that generates pareto-optimal solutions which trade off utility with vulnerability. Case studies are presented for complex attack graphs having interesting pareto-optimal solutions for service management.
Shuvo Bardhan
COMPSAC1
2022 Evaluation Framework for Netflow-based Network Anomaly Detection Systems using Synthetic Malicious Network Traffic
abstract
In this paper, we present a procedure to evaluate netflow-based network anomaly detection (NF-NAD) systems based on accuracy of detection; and mean detection time. Conventionally, different variations of benign or normal traffic have been used to evaluate NF-NAD systems. Here we showcase a methodology where the benign traffic is constant through the entirety of the experiment. To evaluate NF-NAD systems, we create different variations of synthetic malicious network traffic, including not only traditional DDoS and scanning attacks but also a series of attacks by bot from infection to exfiltration. A two-phase approach is used to measure the accuracy and learning capability of the NF-NAD system. We have created a designed experiment (having factors, levels, and design points) to showcase our methodology.
Shuvo Bardhan, Mitsuhiro Hatada
COMPSAC1
2021 Security Metric for Networks with Intrusion Detection Systems having Time Latency using Attack Graphs
abstract
Probabilistic security metrics estimate the vulnerability of a network in terms of the likelihood of an attacker reaching the goal states (of a network) by exploiting the attack graph paths. The probability computation depends upon several assumptions regarding the possible attack scenarios. In this paper, we extend the existing security metric to model networks with intrusion detection systems and their associated uncertainties and time latencies. We consider learning capabilities of attackers as well as detection systems. Estimation of risk is obtained by using the attack paths that are undetectable owing to the latency of the detection system. Thus, we define the overall vulnerability (of a network) as a function of the time window available to an attacker for repeated exploring (via learning) and exploitation of a network, before the attack is mitigated by the detection system. Finally, we consider the realistic scenario where an attacker explores and abandons various partial paths in the attack graph before the actual exploitation. A dynamic programming formulation of the vulnerability computation methodology is proposed for this scenario. The nature of these metrics are explained using a case study showing the vulnerability spectrum from the case of zero detection latency to a no detection scenario.
Shuvo Bardhan, Abdella Battou
COMPSAC1