EDBT 2026 Demo / reviewers in the wild / expert
Rakesh Podder
dblp:370/0240
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2025
0009-0008-7394-1369ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Formal Specification and Verification of Protection in Transit (PIT) Protocol Using UPPAALabstractProtecting devices during transit is critical to prevent firmware tampering. The Protection in Transit (PIT) protocol handles this by locking firmware before shipment and allowing only authorized users to unlock and boot the device. This protocol is intended to prevent malicious users from getting access to the device firmware, but systematic verification is needed to provide assurance. Towards this end, we specify PIT using UML Sequence Diagrams and then formally verify it using UPPAAL, a model checker that can check real-time systems. We model the locking and unlocking phases, develop an algorithm to translate UML Sequence Diagrams into UPPAAL timed automata, and verify reachability, safety, and liveness properties. Formal analysis reveals flaws in the original design; we propose targeted fixes and confirm, through iterative verification, that the corrected model meets all correctness and security criteria. Takwa Rhaimi, Hamed Aghayarzadeh, Rakesh Podder, Indrakshi Ray |
PST | 3 |
| 2025 | SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity HypergraphsabstractGraph-based frameworks are often used in network hardening to help a cyber defender understand how a network can be attacked and how the best defenses can be deployed. However, incorporating network connectivity parameters in the attack graph, reasoning about the attack graph when we do not have access to complete information, providing system administrator suggestions in an understandable format, and allowing them to do what-if analysis on various scenarios and attacker motives is still missing. We fill this gap by presenting SPEAR, a formal framework with tool support for security posture evaluation and analysis that keeps human-in-the-loop. SPEAR uses the causal formalism of AI planning to model vulnerabilities and configurations in a networked system. It automatically converts network configurations and vulnerability descriptions into planning models expressed in the Planning Domain Definition Language (PDDL). SPEAR identifies a set of diverse security hardening strategies that can be presented in a manner understandable to the domain expert. These allow the administrator to explore the network hardening solution space in a systematic fashion and help evaluate the impact and compare the different solutions. Rakesh Podder, Turgay Caglar, Shadaab Kawnain Bashir, Sarath Sreedharan, Indrajit Ray, Indrakshi Ray |
SACMAT | 1 |
| 2025 | VKG2AG : Generating Automated Knowledge-Enriched Attack Graph (AG) from Vulnerability Knowledge Graph (VKG)
Md. Rakibul Hasan Talukder, Rakesh Podder, Indrajit Ray |
SECRYPT | 2 |
| 2025 | Correctness and security analysis of the protection in transit (PIT) protocol
Rakesh Podder, Mahmoud Abdelgawad, Indrakshi Ray, Indrajit Ray, Madhan B. Santharam, Stefano Righi |
J. Syst. Softw. | 1 |
| 2024 | The PIT-Cerberus Framework: Preventing Device Tampering During TransitabstractWhen a computing device, such as a server, workstation, laptop, tablet, etc. is shipped from one site to another (for example, from a vendor to a customer or from one branch location of an organization to another) it can potentially be subjected to unauthorized firmware modifications. The industry has sought to partially address this issue by focusing on securing the boot process. Secure boot provides attestation methods by a hardware root-of-trust to confirm the integrity of the device’s BIOS/UEFI firmware. However, once a device boots up, it is relatively easy for a malicious adversary to tamper with the firmware. In this paper, we address this problem by preventing a secure boot unless done by an authorized user. We extend a hardware root of trust (HRoT) processor’s ability to perform secure attestation by implementing a new functionality to securely lock and unlock the BIOS/UEFI or the BMC (Baseboard Management Controller) and implementing an authentication mechanism in the HRoT for determining authorized users. This ensures that the secure boot process won’t commence unless authorized appropriately and provides a robust mechanism for securing the device’s firmware during transit. The proposed PIT-Cerberus framework (PIT = Protection In Transit) leverages strong cryptographic techniques and has been implemented within a trusted microcontroller. We have contributed the PIT-Cerberus framework’s libraries to Project Cerberus, an open-source project that offers a security platform for server hardware. Rakesh Podder, Jack Sovereign, Indrajit Ray, Madhan B. Santharam, Stefano Righi |
QRS | 1 |