EDBT 2026 Demo / reviewers in the wild / expert
Jafar Haadi Jafarian
dblp:34/4593
· DBLP profile ↗
13ranked-venue papers
7as first author
5since 2021 · last 2024
0000-0001-8115-085XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 6 first-author · 4 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Toward enhancing web privacy on HTTPS traffic: A novel SuperLearner attack model and an efficient defense approach with adversarial examples
Masoumeh Abolfathi, Srivani Inturi, Farnoush Banaei Kashani, Jafar Haadi Jafarian |
Comput. Secur. | 4 |
| 2023 | MultiRHM: Defeating multi-staged enterprise intrusion attacks through multi-dimensional and multi-parameter host identity anonymization
Jafar Haadi Jafarian, Amirreza Niakanlahiji |
Comput. Secur. | 1 |
| 2023 | Toward practical defense against traffic analysis attacks on encrypted DNS traffic
Amirreza Niakanlahiji, Soeren Orlowski, Alireza Vahid, Jafar Haadi Jafarian |
Comput. Secur. | 4 |
| 2022 | The Dangers of Money and Corporate Power Relating to Online DisinformationabstractSocial media platforms can serve as a conduit and magnifier of disinformation, and people's willingness to believe disinformation can have a major deleterious affect on a democratic society. Additionally, the potential motivations for the spread of disinformation is not always clear, making the situation more difficult to rectify. In this paper, we will go into detail regarding the nature of disinformation campaigns, how social media platforms obfuscate the issue, where they have been spotted in the wild including a case study regarding a proposed real estate development whose developers utilized disinformation in order to attempt to subvert local democratic order. Through this, we wish to shine a light on how a social media platform can become an amplifier for disinformation either through conspiratorial content, or through the utilization of monetary resources. Matthew Michaelis, Jafar Haadi Jafarian, Ashis Kumer Biswas |
MDM | 2 |
| 2022 | A Game-Theoretically Optimal Defense Paradigm against Traffic Analysis Attacks using Multipath Routing and DeceptionabstractWhile encryption can protect network traffic against simple on-path eavesdropping attacks, it cannot prevent sophisticated traffic analysis (TA) attacks from inferring sensitive information. TA attackers utilize machine learning algorithms to learn the traffic patterns of a communication (e.g., a website visit) and then use these learned patterns to accurately identify similar communications (which website is being visited by a targeted user), even though packets are encrypted. In this paper, we propose a novel and effective defense approach to protect users' privacy against TA attacks. The proposed approach is based on two proactive defense paradigms: multipath routing and deception. The route randomization strategy distributes packets of a flow on multiple paths between a source and destination to restrict the amount of traffic that a TA adversary can collect from a flow. The deception strategy augments the randomization strategy by injecting fake packets among the real packets of a flow on different paths. Our focal research problem is to identify the optimal strategies for how real and fake packets must be distributed on multiple paths with different capacities to achieve maximum effectiveness against TA attacks. We formalize the problem as a zero-sum game and show that the water-filling distribution of real and fake packets provides an optimal defense solution. Through theoretical and experimental studies, we demonstrate that the proposed approach can significantly degrade the accuracy of the TA attacks. Unlike other defensive approaches in the literature, our approach works without manipulating the production traffic (e.g., delaying packets or padding), or requiring any real-time information about the protected traffic flows. Masoumeh Abolfathi, Ilan Shomorony, Alireza Vahid, Jafar Haadi Jafarian |
SACMAT | 4 |
| 2019 | A Novel Permutational Sampling Technique for Cooperative Network ScanningabstractRandom IP address scanning is a seminal network reconnaissance technique in discovering machines by port-scanners and for target or peer discovery by malwares. Among various random sampling techniques for scanning, cooperative or permutational scanning achieves the highest efficiency by allowing scanning agents to collaboratively ensure that every address in the target range is scanned only once, thus minimizing the overall scanning time and footprint (number of scans). Yet, no practical distributed mechanism for no-repetition sampling has been proposed in the literature, and existing approaches only strive for minimizing the repetition. In this paper, by relying on a unique property of primitive roots of prime numbers, we propose a practical distributed permutational sampling method that enables a group of agents to cooperatively scan an IPv4 address space without even a single repetition and very low execution time. Through analytical modeling and simulation, we show that our approach significantly outperforms existing scanning techniques, in reducing the scanning time and especially the scanning footprint. We also show that our approach achieves high pseudo-randomness (entropy) and robustness against brute-force guessing attacks. We also discuss potential defensive countermeasures against this approach for both fast high-rate and stealthy low-rate scanning. Jafar Haadi Jafarian, Kuntal Das |
PST | 1 |
| 2019 | WebMTD: Defeating Cross-Site Scripting Attacks Using Moving Target DefenseabstractExisting mitigation techniques for cross-site scripting attacks have not been widely adopted, primarily due to imposing impractical overheads on developers, Web servers, or Web browsers. They either enforce restrictive coding practices on developers, fail to support legacy Web applications, demand browser code modification, or fail to provide browser backward compatibility. Moving target defense (MTD) is a novel proactive class of techniques that aim to defeat attacks by imposing uncertainty in attack reconnaissance and planning. This uncertainty is achieved by frequent and random mutation (randomization) of system configuration in a manner that is not traceable (predictable) by attackers. In this paper, we present WebMTD, a proactive moving target defense mechanism that thwarts various kinds of cross-site scripting (XSS) attacks on Web applications. Relying on built-in features of modern Web browsers, WebMTD randomizes values of certain attributes of Web elements to differentiate the application code from the injected code and disallow its execution; this is done without requiring Web developer involvement or browser code modification. Through rigorous evaluation, we show that WebMTD has very a low performance overhead. Also, we argue that our technique outperforms all competing approaches due to its broad effectiveness, transparency, backward compatibility, and low overhead. Amirreza Niakanlahiji, Jafar Haadi Jafarian |
Secur. Commun. Networks | 2 |
| 2015 | Adversary-aware IP address randomization for proactive agility against sophisticated attackersabstractNetwork reconnaissance of IP addresses and ports is prerequisite to many host and network attacks. Meanwhile, static configurations of networks and hosts simplify this adversarial reconnaissance. In this paper, we present a novel proactive-adaptive defense technique that turns end-hosts into untraceable moving targets, and establishes dynamics into static systems by monitoring the adversarial behavior and reconfiguring the addresses of network hosts adaptively. This adaptability is achieved by discovering hazardous network ranges and addresses and evacuating network hosts from them quickly. Our approach maximizes adaptability by (1) using fast and accurate hypothesis testing for characterization of adversarial behavior, and (2) achieving a very fast IP randomization (i.e., update) rate through separating randomization from end-hosts and managing it via network appliances. The architecture and protocols of our approach can be transparently deployed on legacy networks, as well as software-defined networks. Our extensive analysis and evaluation show that by adaptive distortion of adversarial reconnaissance, our approach slows down the attack and increases its detectability, thus significantly raising the bar against stealthy scanning, major classes of evasive scanning and worm propagation, as well as targeted (hacking) attacks. Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
INFOCOM | 1 |
| 2015 | Towards a General Framework for Optimal Role Mining: A Constraint Satisfaction ApproachabstractRole Based Access Control (RBAC) is the most widely used advanced access control model deployed in a variety of organizations. To deploy an RBAC system, one needs to first identify a complete set of roles, including permission role assignments and role user assignments. This process, known as role engineering, has been identified as one of the costliest tasks in migrating to RBAC. Since many organizations already have some form of user permission assignments defined, it makes sense to identify roles from this existing information. This process, known as role mining, has gained significant interest in recent years and numerous role mining techniques have been developed that take into account the characteristics of the core RBAC model, as well as its various extended features and each is based on a specific optimization metric. In this paper, we propose a generic approach which transforms the role mining problem into a constraint satisfaction problem. The transformation allows us to discover the optimal RBAC state based on customized optimization metrics. We also extend the RBAC model to include more context-aware and application specific constraints. These extensions broaden the applicability of the model beyond the classic role mining to include features such as permission usage, hierarchical role mining, hybrid role engineering approaches, and temporal RBAC models. We also perform experiments to show applicability and effectiveness of the proposed approach. Jafar Haadi Jafarian, Hassan Takabi, Hakim Touati, Ehsan Hesamifard, Mohamed Shehab |
SACMAT | 1 |
| 2015 | An Effective Address Mutation Approach for Disrupting Reconnaissance AttacksabstractNetwork reconnaissance of addresses and ports is prerequisite to a vast majority of cyber attacks. Meanwhile, the static address configuration of networks and hosts simplifies adversarial reconnaissance for target discovery. Although the randomization of host addresses has been suggested as a proactive disruption mechanism against such reconnaissance, the proposed approaches do not exploit the full potentials of address randomization in provision of unpredictability and attack adaptability. Moreover, these approaches do not provide thorough analysis on effectiveness and limitations of address randomization against relevant threat models, including stealthy scanning and worms. In this paper, we present an effective address randomization technique, called random host address mutation (RHM), that turns end-hosts into untraceable moving targets. This technique achieves maximum efficacy by allowing address randomization to be highly unpredictable and fast, and adaptive to adversarial behavior, while incurring low operational and reconfiguration overhead. Our approach achieves the following objectives: (1) it achieves high uncertainty in adversary scanning by modeling address mutation randomization as a multi-level satisfiability problem; (2) it adapts the mutation scheme by fast characterization of adversarial reconnaissance patterns; (3) it achieves high mutation rate by separating mutation from end-hosts and managing it via network appliances; and (4) it preserves network integrity, manageability and performance by bounding the size of routing tables, preserving end-to-end reachability, and efficient handling of reconfiguration updates. Our extensive analyses and simulation show that the RHM distorts adversarial reconnaissance, slows down (deters) the attack, and increases its detectability. Consequently, the RHM is effective in countering a significant number of sophisticated threat models, including reconnaissance, stealthy/evasive scanning methods, and targeted attacks. We also address limitations of our approach in terms of effectiveness and applicability. Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Formal Approach for Route Agility against Persistent Attackers
Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
ESORICS | 1 |
| 2012 | Random Host Mutation for Moving Target Defense
Ehab Al-Shaer, Qi Duan, Jafar Haadi Jafarian |
SecureComm | 3 |
| 2008 | A Context-Aware Mandatory Access Control Model for Multilevel Security Environments
Jafar Haadi Jafarian, Morteza Amini, Rasool Jalili |
SAFECOMP | 1 |