Harjinder Singh Lallie 0001

dblp:39/9451-1 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0002-1558-5115ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 IDENTIFY: Intelligent device identification using device fingerprints and machine learning
abstract
The Internet of Things (IoT) consists of a rapidly growing network of heterogeneous devices that autonomously monitor, collect, and exchange data across a wide range of application domains. The rapid increase of IoT devices highlighted the importance of scalable, secure, and adaptive network management strategies for dynamic networks. A key challenge in this context is the automatic identification of devices, which is critical for detecting and mitigating malicious devices that can compromise network integrity. Accurate device identification strengthens the security of dynamic IoT environments by facilitating early detection of anomalous or adversarial traffic. Device fingerprinting offers a non-intrusive solution by leveraging protocol and traffic characteristics, without relying on vendor-specific identifiers. In this work, we propose a lightweight and efficient framework for IoT device identification based on machine learning. Our model utilises a Random Forest classifier in conjunction with a data-driven feature selection strategy that emphasises low-overhead features derived from packet headers and traffic flow statistics. The proposed approach achieves high classification performance, attaining 97.32% accuracy in identifying general device categories and 94.39% accuracy for specific device types. It also demonstrates approximately a 40% improvement in computational efficiency compared to traditional classifiers, making it well-suited for deployment in resource-constrained edge environments. We evaluate the model under various real-world conditions, including spatiotemporal traffic variations, changes in operational modes, and different sampling intervals. Comparative experiments with established classifiers—such as J48, SMO, BayesNet, and Naive Bayes—are performed using standard metrics, including precision, recall, F1-score, and inference latency. Our approach strengthens network security by automatically identifying and classifying IoT devices in dynamic, heterogeneous environments. It is lightweight, scalable, and well-suited for deployment in resource-constrained IoT scenarios. • The research focuses on using device fingerprints and machine learning techniques to efficiently identify and classify IoT devices in heterogeneous networks. • The study employs Random Forest as the primary classification algorithm, achieving an accuracy of 97.32% for classifying IoT devices and 94.39% for identifying specific device types. • By leveraging optimized feature selection techniques, the study ensures high accuracy and reduces computational overhead. • The study highlights the importance of balancing accuracy and time efficiency in IoT device identification, offering a robust model for real-world applications.
Muhammad Ajmal Azad, Harjinder Singh Lallie 0001, Hany F. Atlam
Pervasive Mob. Comput.3
2023 An empirical evaluation of the effectiveness of attack graphs and MITRE ATT&CK matrices in aiding cyber attack perception amongst decision-makers
Ana Maria Pirca, Harjinder Singh Lallie 0001
Comput. Secur.2
2021 Cyber security in the age of COVID-19: A timeline and analysis of cyber-crime and cyber-attacks during the pandemic
Harjinder Singh Lallie 0001, Lynsay A. Shepherd, Jason R. C. Nurse, Arnau Erola, Gregory Epiphaniou, Carsten Maple, Xavier J. A. Bellekens
Comput. Secur.1
2018 Evaluating practitioner cyber-security attack graph configuration preferences
Harjinder Singh Lallie 0001, Kurt Debattista, Jay Bal
Comput. Secur.1
2018 An Empirical Evaluation of the Effectiveness of Attack Graphs and Fault Trees in Cyber-Attack Perception
abstract
Perceiving and understanding cyber-attacks can be a difficult task. This problem is widely recognized and welldocumented, and more effective techniques are needed to aid cyber-attack perception. Attack modeling techniques (AMTs), such as attack graphs and fault trees, are useful visual aids that can aid cyber-attack perception; however, there is little empirical or comparative research which evaluates the effectiveness of these methods. This paper reports the results of an empirical evaluation between an adapted attack graph method and the fault tree standard to determine which of the two methods is more effective in aiding cyber-attack perception. An empirical evaluation (n = 63) was conducted through a 3 × 2 × 2 factorial design. Participants from computer-science and non-computerscience backgrounds were divided into an adapted attack graph and fault tree group and then asked to complete three tests which tested the ability to recall, comprehend, and apply the AMT. A mean assessment score (mas) was calculated for each test. The results show that the adapted attack graph method is more effective at aiding cyber-attack perception when compared with the fault tree method (p <; 0.01). Participants that have a computer science background outperformed other participants when using both methods (p <; 0.05). These results indicate that the adapted attack graph method can be an effective tool for aiding cyber-attack perception amongst experts. This paper underlines the need for further comparisons in a broader range of settings involving additional techniques, and makes several suggestions for further work.
Harjinder Singh Lallie 0001, Kurt Debattista, Jay Bal
IEEE Trans. Inf. Forensics Secur.1
2012 CONDOR: A Hybrid IDS to Offer Improved Intrusion Detection
abstract
Intrusion Detection Systems are an accepted and very useful option to monitor, and detect malicious activities. However, Intrusion Detection Systems have inherent limitations which lead to false positives and false negatives; we propose that combining signature and anomaly based IDSs should be examined. This paper contrasts signature and anomaly-based IDSs, and critiques some proposals about hybrid IDSs with signature and heuristic capabilities, before considering some of their contributions in order to include them as main features of a new hybrid IDS named CONDOR (COmbined Network intrusion Detection ORientate), which is designed to offer superior pattern analysis and anomaly detection by reducing false positive rates and administrator intervention.
David J. Day, Denys A. Flores, Harjinder Singh Lallie 0001
TrustCom3