Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Mati Ur Rehman

dblp:339/9563 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0000-3345-2482ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Network security · 95% Malware analysis · 5%
Software engineering, system software, and programming languages
1 paper
Program analysis · 50% Operating systems · 50%
Computer networks
1 paper
Network measurement and analytics · 100%

Topics — the 5 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention › intrusion detection › attack detection
advanced persistent threat detection
2.632026
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026
A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics · INFOCOM 2025
Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024
Network security › intrusion detection and prevention
intrusion detection
2.632026
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026
A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics · INFOCOM 2025
Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024
Operating systems
provenance
1.012026
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026
Program analysis
provenance analysis
1.012026
Accurate and Scalable Detection and Investigation of Cyber Persistence Threats · IEEE Trans. Dependable Secur. Comput. 2026
Network security › intrusion detection and prevention › intrusion detection › intrusion detection system › host-based intrusion detection
provenance-based intrusion detection
0.812024
Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning · SP 2024

Methods — techniques the papers use, named apart from their topics

pseudo-dependency edges · 2.0expert-guided edges · 2.0alert triage · 2.0multi-stage causal analytics · 1.7word2vec · 0.8graph representation learning · 0.8graph neural network · 0.8
YearPublicationVenuePosition
2026 RAPID: Restorative Amortized Protection for Image Diffusion
Muhammad Saad Umer, Sharjeel Sajid, Mati Ur Rehman, Maham Jahangir, Faisal Shafait
ICPR (15)3
2026 Accurate and Scalable Detection and Investigation of Cyber Persistence Threats
abstract
In Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the “persistence setup” and the subsequent “persistence execution”. By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction ofpseudo-dependency edges(pseudoedges), which effectively connect these disjoint phases using data provenance analysis, andexpert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to stateof- the-art methods.
Qi Liu 0023, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan
IEEE Trans. Dependable Secur. Comput.3
2025 A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan
INFOCOM5
2024 Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning
abstract
Recently, provenance-based Intrusion Detection Systems (IDSes) have gained popularity for their potential in detecting sophisticated Advanced Persistent Threat (APT) attacks. These IDSes employ provenance graphs created from system logs to identify potentially malicious activities. Despite their potential, they face challenges in accuracy, practicality, and scalability, particularly when dealing with large provenance graphs. We present Flash, a scalable IDS that leverages graph representation learning through Graph Neural Networks (GNNs) on data provenance graphs to overcome these limitations. Flash employs a Word2Vec-based semantic encoder to capture essential semantic attributes (e.g., process names and file paths) and the temporal ordering of events within the provenance graph. Furthermore, Flash incorporates a novel adaptation of a GNN-based contextual encoder to efficiently encode both local and global graph structures into expressive node embeddings. To learn benign node behaviors, we utilize a lightweight classifier that combines the GNN and Word2Vec embeddings. Recognizing the computational demands and slow processing times of GNN, particularly for large provenance graphs, we have developed an embedding recycling database to store the node embeddings generated during the training phase. During runtime, our lightweight classifier leverages the stored embeddings, obviating the need to regenerate GNN embeddings, thus facilitating real-time APT detection. Extensive evaluation of Flash on real-world datasets demonstrates superior detection accuracy compared to existing provenance-based IDSes. The results also illustrate Flash’s scalability, robustness against mimicry attacks, and potential for accelerating the alert verification process.
Mati Ur Rehman, Hadi Ahmadi, Wajih Ul Hassan
SP1