Charles A. Kamhoua

dblp:45/9386 · DBLP profile ↗
← Back
92ranked-venue papers
5as first author
31since 2021 · last 2026
0000-0003-2169-5975ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 39 · 3 first-author · 18 since 2021Security and privacy · 15 · 1 first-author · 4 since 2021Systems, architecture and hardware · 11 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 1 first-authorArtificial intelligence and machine learning · 5 · 2 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Theory of computation · 1
YearPublicationVenuePosition
2026 Deepfake detection using a distinctive eye signature and the entropy heat map of the image texture
Elisabeth Tchaptchet, Elie Fute Tagne, Alain B. Djimeli-Tsajio, Jaime C. Acosta, Danda B. Rawat, Charles A. Kamhoua
Multim. Tools Appl.6
2026 A probabilistic attack graph-based model for coordinated attacks in sensor-defended networks
Romaric Mofouet, Arnold Kouam, Jie Fu 0002, Charles A. Kamhoua, Gabriel Deugoue
J. Supercomput.5
2026 Decoy Allocation Against Lateral Movement: A Network Centrality Game Approach
Willie Kouam, Yezekael Hayel, Gabriel Deugoue, Charles A. Kamhoua
IEEE Trans. Netw. Serv. Manag.4
2026 GAN-AIIPot: GAN-Based Cyber Deception for Probing Attacks on IoT Devices
abstract
The Internet of Things (IoT) is an emerging technology that has transformed the global network by interconnecting internet-enabled devices, people, intelligent things, and valuable data, leading to significant advancements in various domains. As IoT devices become more interwoven into our daily lives, the security of these devices is a huge concern. Many IoT devices are connected to the internet, making them open to security threats. Researchers have been exploring new methods for detecting and mitigating cyberattacks on IoT devices. One promising approach is the use of Generative Adversarial Networks (GANs) for cyber deception. Cyber deception is a cybersecurity technique used to mislead attackers and hackers from their intended targets. GANs have shown promise in the field of cybersecurity for creating realistic synthetic data to test the security of systems. In the case of probing attacks on IoT devices, GAN-based cyber deception can be used to create fake devices/information that can mimic real IoT devices and deceive attackers into thinking that they have successfully compromised a target. This paper proposes a novel GAN-based cyber deception technique called GAN-AIIPot, which is designed for probe attacks on IoT devices. GAN-AIIPot is an extended version of AIIPot that adds a GAN model on top of the Bidirectional Encoder Representations from the Transformers (BERT) model used in AIIPot. We evaluate our approach using a publicly available IoT dataset and show that GAN-AIIPot captures more sophisticated attacks and improves session length with attackers, showing the effectiveness of the deception technique compared to the existing honeypots. We believe that such a solution can enhance the security of IoT devices and protect them from malicious actors.
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
IEEE Trans. Netw. Serv. Manag.5
2025 Prospect Theoretic Hypothesis Testing-based Cyber Deception
abstract
In this paper, we present a novel hypothesis testing framework to model and analyze an attacker’s decision-making during the reconnaissance phase, and subsequently leverage the framework to characterize optimal deception strategies that can be used to defeat the attacker’s reconnaissance efforts. Our developed model and analytical approaches are well capable of diligently addressing the information-centric nature of the involved attack-defense processes while adapting with the defender’s and attacker’s cognitive biases (irrationalities). Employing the developed hypothesis testing framework, we first characterize a cognitively biased attacker’s optimal prospect theoretic decision rule that enables it to best exploit the information that it acquires during reconnaissance. Leveraging such understanding, we design optimal information falsification strategies that can be employed by a cognitively biased defender to strategically deceive the attacker during its reconnaissance phase under varied considerations. Several numerical results have been presented that provide important insights into the developed strategies.
Swastik Brahma, Baocheng Geng, Charles A. Kamhoua
MASS4
2025 Multi-domain deception for enhanced security in automotive networks
Priva Chassem Kamdem, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Comput. Secur.5
2025 Defending Internet of Things Against Energy Depletion Attack Using Bayesian Game
abstract
Due to their limited resources, Internet of Things (IoT) networks are vulnerable to attacks like aggressive denial-of-service (DoS) attacks aimed at draining device energy. IoT devices often have non-rechargeable or hard-to-recharge batteries, especially when deployed in hostile areas, making them prime targets for energy depletion attacks such as barrage attacks. To mitigate these threats, security systems must implement lightweight measures. This paper proposes a new game theory-based mechanism to defend IoT devices against energy depletion. Game theory effectively models the adversarial interactions between attackers and defenders. Our approach uses a dynamic game with incomplete information to derive optimal detection, defense, and attack strategies, establishing a Perfect Bayesian Nash Equilibrium (PBNE) to protect IoT device energy under constant attack. This dynamic game involves repeated interactions where at least one player lacks complete information about the other. The proposed model offers a high-performance solution for conserving IoT device energy. Simulation results demonstrate its effectiveness, showing that it can save, on average, 95.19% of the energy expended in receiving packets during an attack and can deter attackers. This approach ensures the sustainability of IoT networks against persistent energy depletion attacks.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Charles A. Kamhoua
IEEE Internet Things J.5
2025 Arpotcam: augmented reality-driven honeypot for enhancing security in IoT surveillance systems
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Vis. Comput.5
2024 A Decentralized Smart Grid Communication Framework Using SDN-Enabled Blockchain
abstract
The smart grid revolution has brought numerous benefits to the energy sector, such as improved efficiency, increased renewable energy integration, and enhanced grid management. The reliance on digital communication within smart grid systems has introduced new security challenges that must be addressed to ensure reliable and secure operation. The existing communication infrastructure often lacks the necessary security measures to protect against cyber threats, which leads to potential vulnerabilities and privacy breaches. This paper presents a novel approach to enhancing smart grid communication by integrating Software-Defined Networking (SDN) and Blockchain technology. Therefore, the proposed work aims to address the specific communication needs of smart grids, which require secure and real-time data exchange between various grid components, including power generation units, substations, distribution networks, and end consumers. The proposed framework provides data integrity, communication and network security, and controller privacy.
Uttam Ghosh, Laurent Njilla, Sachin Shetty, Charles A. Kamhoua
CCNC4
2024 Mitigating Energy Attacks in Wireless Sensor Networks Using Deception: A Game Theoretic Approach
abstract
Wireless Sensor Networks (WSNs) consist of devices communicating information wirelessly from a monitored field. Sensors are designed with limited energy resources pushing application designers to optimize energy consumption. It is common practice in WSNs to organize nodes in clusters with a device (designed as a cluster head) with superior energy resources. However, this clustered architecture exposes vulnerabilities, particularly to energy depletion attacks targeting the cluster head. Energy depletion attacks pose a significant threat to sensor node survival. To overcome such attacks, we propose a cyber deception defense mechanism based on game theory to model the actions between the attacker agent and the cluster head agent and hence, extract optimal strategies during conflicting interactions between the agents. In this paper, we propose using a game with incomplete information to find the Nash equilibrium point. Cyber deception, particularly the integration of a honeypot system, is employed to enhance the solution’s effectiveness in optimizing cluster head energy in the face of potential attacks. The proposed solution demonstrates its effectiveness in mitigating attacks of varying intensity against the cluster head.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Charles A. Kamhoua, Chakchai So-In
GLOBECOM5
2024 A pipeline approach for privacy preservation against poisoning attacks in a Mobile Edge Computing environment
Joelle Kabdjou, Elie Fute Tagne, Danda B. Rawat, Jaime C. Acosta, Charles A. Kamhoua
Ad Hoc Networks5
2024 Adaptive learning-based hybrid recommender system for deception in Internet of Thing
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
Comput. Networks5
2024 Countering ARP spoofing attacks in software-defined networks using a game-theoretic approach
Fabrice Mvah, Vianney Kengne Tchendji, Clémentin Tayou Djamégni, Ahmed H. Anwar, Deepak K. Tosh, Charles A. Kamhoua
Comput. Secur.6
2024 TriAssetRank: Ranking Vulnerabilities, Exploits, and Privileges for Countermeasures Prioritization
abstract
Network defence practices have no standardized mechanism for determining the priority of threat events. Prioritization of cyber vulnerabilities intends to make network administrators focus on the most critical points within the system to mitigate potential damages produced by attackers. More likely, in managing vulnerabilities, current approaches always focus on the common vulnerability exposures (CVE), which are not the only existing vulnerabilities in a network. Also, while the Common Vulnerability Scoring System (CVSS) effectively scores individual vulnerabilities, it fails to consider the relationships between them but considers each vulnerability in isolation. Existing research, such as the ‘AssetRank’ algorithm, has made progress in exploring these relationships. Building on this foundation, in this paper we propose TriAssetRank, a tripartite ranking algorithm that evaluates three key elements within a logical attack graph: vulnerabilities, privileges, and potential attack exploits. Since each node type has its unique characteristics and potential impact on the system’s security, we rank them in concert, taking into account the dependencies between nodes in the attack graph. The proposed ranking scheme computes a numerical value for each node based on its type, which is a clear indication of how valuable it is to a potential attacker. Several tests on various model networks have empirically validated the effectiveness of the algorithm, which enables organizations to prioritize countermeasures by identifying the most critical vulnerabilities, exploits, and privilege escalation risks, allowing efficient allocation of resources to mitigate high-impact threats and reduce overall risk exposure effectively.
Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Wilson Ejuh Geh, Frederica Free-Nelson, Sachin Shetty, Charles A. Kamhoua
IEEE Trans. Inf. Forensics Secur.6
2024 Optimizing Effectiveness and Defense of Drone Surveillance Missions via Honey Drones
abstract
This work aims to develop a surveillance mission system using unmanned aerial vehicles (UAVs) or drones when Denial-of-Service (DoS) attacks are present to disrupt normal operations for mission systems. In particular, we introduce the concept of cyber deception using honey drones (HDs) to protect the mission system from DoS attacks. HDs exhibit fake vulnerabilities and employ stronger signal strengths to lure DoS attacks, unlike the legitimate drones called mission drones (MDs) deployed for mission execution. This research formulates an optimization problem to identify an optimal set of signal strengths of HDs and MDs to best prevent the system from DoS attacks while maximizing mission performance under the resource constraints of UAVs. To solve this optimization problem, we leverage deep reinforcement learning (DRL) to achieve these multiple objectives of the mission system concerning system security and performance. Particularly, for efficient and effective parallel processing in DRL, we utilize a DRL algorithm called the Asynchronous Advantage Actor-Critic (A3C) algorithm to model attack-defense interactions. We employ a physical engine-based simulation testbed to consider realistic scenarios and demonstrate valid findings from the realistic testbed. The extensive experiments proved that our HD-based approach could achieve up to a 32% increase in mission completion, a 20% reduction in energy consumption, and a 62% decrease in attack success rates compared to existing defense strategies.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
ACM Trans. Internet Techn.5
2023 Cyber Resilience Measurement Through Logical Attack Graph Analysis
abstract
To improve resilience, it is crucial to quantify or measure it. Measurement techniques usually base their measure on critical functionality, which is unfortunately not mission-centric. Also, methods of measurement over time can not tackle the fact that a system may have different consecutive missions at different intervals of time. We propose a method to measure the cyber-resilience of any complex network by analyzing how the business process varies against adversity effort. Both efforts of the attacker and the impact on the business process are obtained by leveraging the vulnerabilities CVSS score of attack paths extracted from a generated attack graph. We finally obtain a numerical value for cyber resilience by calculating the area under the curve of business process against attacker effort. Experimentation shows that the proposed framework suits the absorption, recovery, and adaptation abilities of cyber resilience. This also helps designers to analyze which type of vulnerabilities leads to the worst resilience case, thereby making critical decisions to improve cyber resilience.
Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Frederica Free-Nelson, Sachin Shetty, Wilson Ejuh Geh, Charles A. Kamhoua
ICC6
2023 Mitigating Energy Depletion Attack In Wireless Sensor Network Using Signaling Game
abstract
Nowadays, with the evolution of technology, sensor networks have experienced a real boom. Due to their constitutions, sensors suffer from low security and are therefore susceptible to different types of attacks. Wireless sensor networks (WSNs) deployed in hostile environments suffer particularly from energetic attacks, i.e. attacks aimed at shortening the life cycle of sensors. Sensors have limited energy resources; replacing or recharging nodes in hostile environments is difficult. Attacks that cause a drain on the energy level are the most common attacks in a hostile environment and can lead to the death of sensors such as sleep denial attacks. In this paper, we design a game model using a signaling game within clusters that enables both detection and defense against attackers. In this paper, we identify and impose penalties on nodes that practice sleep deprivation torture in WSNs. The simulations showed that the model is able to force the attacker to behave normally in a WSN.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Frederica Free-Nelson, Charles A. Kamhoua
ICC6
2023 Deception in Drone Surveillance Missions: Strategic vs. Learning Approaches
abstract
Unmanned Aerial Vehicles (UAVs) have been used for surveillance operations, search and rescue missions, and delivery services. Given their importance and versatility, they naturally become targets for cyberattacks. Denial-of-Service (DoS) attacks are commonly considered to exhaust their resources or crash UAVs (or drones). This work proposes a unique proactive defense using honey drones (HD) for UAVs during surveillance operations. These HDs use lightweight virtual machines to lure and redirect potential DoS attacks. Both the choice of target by the attacker and the HD's deceptive tactics are influenced by the strength of the radio signal. However, a critical trade-off exists in that stronger signals can deplete battery life, while weaker signals can negatively affect the connectivity of a drone fleet network. To address this, we formulate an optimization problem to select the best strategies for an attacker or defender in selecting their signal strength level. We propose a novel HD-based defense to identify the optimal setting using deep reinforcement learning (DRL) or game theory and compare their performance with that of non-HD-based methods, such as Intrusion Detection Systems and ContainerDrone. Our experiments demonstrate the unique benefits and superior efficacy of each HD-based defense across various attack scenarios.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
MobiHoc5
2023 AIIPot: Adaptive Intelligent-Interaction Honeypot for IoT Devices
abstract
The proliferation of the Internet of Things (IoT) has raised concerns about the security of connected devices. There is a need to develop suitable and cost-efficient methods to identify vulnerabilities in IoT devices to address them before attackers seize opportunities to compromise them. The deception technique is a prominent approach to improving the security posture of IoT systems. Honeypot is a popular deception technique that mimics interaction in real fashion and encourages unauthorised users (attackers) to launch attacks. Due to the large number and the heterogeneity of IoT devices, manually crafting the low and high-interaction honeypots is not affordable. This has forced researchers to seek innovative ways to build honeypots for IoT devices. In this paper, we propose a honeypot for IoT devices that uses machine learning techniques to learn and interact with attackers automatically. The evaluation of the proposed model indicates that our system can improve the session length with attackers and capture more attacks on the IoT network.
Volviane Saphir Mfogo, Alain B. Zemkoho, Laurent Njilla, Marcellin Nkenlifack, Charles A. Kamhoua
PIMRC5
2023 Optimal Honeypot Allocation using Core Attack Graph in Cyber Deception Games
abstract
Honeypots appear today as a defense strategy to trap intelligent cyber attackers who can detect traditional security measures. The scalability of existing algorithms for solving some classes of game theory is very limited due to large-scale networks. This paper opens the door to a new approach to allocate honeypots in the network, to increase attackers’ costs, during the lateral movement of the APT attack. We use the core attack graph that can show the main routes an attacker can take toward the goal. This allows the defender to use a limited number of honeypots focusing its efforts only on critical nodes over the main attacker routes. The effectiveness and scalability of the proposed approach are evaluated over different network topologies, a varying number of honeypots, network size, and density. Numerical results show that the defender reward over the core attack graph is quite similar to that obtained on the original attack graph while significantly reducing the defender’s actions and computation time.
Achile Leonel Nguemkam, Ahmed H. Anwar, Vianney Kengne Tchendji, Deepak K. Tosh, Charles A. Kamhoua
PIMRC5
2023 Resisting Multiple Advanced Persistent Threats via Hypergame-Theoretic Defensive Deception
abstract
Existing defensive deception (DD) approaches apply game theory, assuming that an attacker and defender play the same, full game with all possible strategies. However, in deceptive settings, players may have different beliefs about the game itself. Such structural uncertainty is not naturally handled in traditional game theory. In this work, we formulate an attackdefense hypergame where multiple advanced persistent threat (APT) attackers and a single defender play a repeated game with different perceptions. The hypergame model systematically evaluates how various DD strategies can defend proactively against APT attacks. We present an adaptive method to select an optimal defense strategy using hypergame theory for strategic defense as well as machine learning for adaptive defense. We conducted in-depth experiments to analyze the performance of the eight schemes including ours, baselines, and existing counterparts. We found the DD strategies showed their highest advantages when the hypergame and machine learning are considered in terms of reduced false positives and negatives of the NIDS, system lifetime, and players’ perceived uncertainties and utilities. We also analyze the Hyper Nash Equilibrium of given hypergames and discuss the key findings and insights behind them.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.5
2022 Cyber Deception using Honeypot Allocation and Diversity: A Game Theoretic Approach
abstract
Cyber deception has become the core of advanced enterprise-level defense systems. It is also being used for early detection by many experts. In this paper, we propose a novel approach for cyber deception using honeypot allocation and software diversity to enhance network security. The network defender chooses where to place the honeypots given a limited budget of resources. Also, we consider an interesting tradeoff between the level of software diversity to be implemented in the network and the operational cost incurred due to using different types of honeypots. To this end, we formulate a game-theoretic approach to characterize the honeypot allocation policy that protects the most valuable resources of the network. Moreover, we develop a game model between the two players to investigate the diversity tradeoff. Our results show that careful honeypot allocation is critical to protect high-value nodes and validate the proposed software-diversity approach.
Ahmed H. Anwar, Charles A. Kamhoua
CCNC2
2022 Honeypot-Based Cyber Deception Against Malicious Reconnaissance via Hypergame Theory
abstract
Malicious reconnaissance is a critical step for attackers to collect sufficient network knowledge and choose valuable targets for intrusion. Defensive deception (DD) is an essential strategy against threats by misleading attackers' observations and beliefs. Honeypots are widely used for cyber deception that aims to confuse attackers and waste their resources and efforts. Defenders may use low-interaction honeypots or high-interaction honeypots. In this paper, we consider a hybrid honeypot system that balances the use of the two levels of honeypot complexity, where high-interaction honeypots are more capable of deceiving skilled attackers than low-interaction honeypots. We present a two-player hypergame model that characterizes how a defender should deploy low and high-interaction honeypots to defend the network against malicious reconnaissance activities. We model the tradeoff of each player and characterize their best strategies within a hypergame framework that considers the imperfect knowledge of each player toward their opponent. Finally, our numerical results validate the effectiveness of the proposed honeypot system.
Ahmed H. Anwar, Zelin Wan, Jin-Hee Cho, Charles A. Kamhoua, Munindar P. Singh
GLOBECOM5
2022 MAVIPER: Learning Decision Tree Policies for Interpretable Multi-agent Reinforcement Learning
Stephanie Milani, Zhicheng Zhang 0003, Nicholay Topin, Zheyuan Shi, Charles A. Kamhoua, Evangelos E. Papalexakis, Fei Fang 0001
ECML/PKDD (4)5
2022 Game-Theoretic Modeling of Cyber Deception Against Epidemic Botnets in Internet of Things
abstract
Practically, a botnet is spread over the Internet of Things (IoT) to ensure an attacker the control of a large number of devices. In this context, in which IoT users react to protect their devices against the threat, a zero-sum one-sided partially observable stochastic game (OS-POSG) model is proposed in which a defender strategically places honeypots in the IoT network in order to deceive attacker’s actions and mitigate the botnet propagation. No player (attacker and defender) observes the opponent’s action but, realistically, the attacker—who is the maximizer—has a perfect knowledge of the state of the network while the defender—who is the minimizer—only is informed of the decisions of IoT users. The objective is to find an optimal deception strategy for the defender that better limits from above the proportion of infected IoT devices. We show in numerous simulations the impact of the partial observation and of the strategic defender’s action on the particular metrics which are the maximum proportion of infected IoT devices during the botnet propagation and the time to botnet extinction in the IoT network.
Olivier Tsemogne, Yezekael Hayel, Charles A. Kamhoua, Gabriel Deugoue
IEEE Internet Things J.3
2022 Forecasting network events to estimate attack risk: Integration of wavelet transform and vector auto regression with exogenous variables
Soo-Yeon Ji, Bong-Keun Jeong, Charles A. Kamhoua, Nandi Leslie, Dong Hyun Jeong
J. Netw. Comput. Appl.3
2022 Honeypot Allocation for Cyber Deception Under Uncertainty
abstract
Cyber deception aims to misrepresent the state of the network to mislead the attackers, falsify their reconnaissance conclusions, and deflect them away from their goals. Honeypots serve as decoy devices inside networks that can capture adversaries for monitoring purposes. We propose a two-phase deception approach based on honeypot allocation. In the first phase, we develop a proactive deceptive honeypot allocation policy, the second phase proposes a reactive deception approach that dynamically allocates honeypots according to IDS updates. Considering a practical scenario, the defender partially monitors the adversary’s activities. To this end, we develop our deception approach using a combination of game-theoretic and reinforcement learning models. We cast the problem of reactive deception as a partially observable Markov decision process (POMDP) based on a game-theoretic dynamic model to accommodate the imperfect monitoring of the actions taken by the attacker. We solve this combined partially observable game model using Monte-Carlo tree search to overcome the game model complexity. We give a game-theoretic analysis to explain the attack-defense policies at equilibrium. Finally, we present numerical results to validate the effectiveness of the proposed deception approach.
Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie, Christopher Kiekintveld
IEEE Trans. Netw. Serv. Manag.2
2022 Foureye: Defensive Deception Against Advanced Persistent Threats via Hypergame Theory
abstract
Defensive deception techniques have emerged as a promising proactive defense mechanism to mislead an attacker and thereby achieve attack failure. However, most game-theoretic defensive deception approaches have assumed that players maintain consistent views under uncertainty. They do not consider players’ possible, subjective beliefs formed due to asymmetric information given to them. In this work, we formulate a hypergame between an attacker and a defender where they can interpret the same game differently and accordingly choose their best strategy based on their respective beliefs. This gives a chance for defensive deception strategies to manipulate an attacker’s belief, which is the key to the attacker’s decision-making. We consider advanced persistent threat (APT) attacks, which perform multiple attacks in the stages of the cyber kill chain (CKC) where both the attacker and the defender aim to select optimal strategies based on their beliefs. Through extensive simulation experiments, we demonstrated how effectively the defender can leverage defensive deception techniques while dealing with multi-staged APT attacks in a hypergame in which the imperfect information is reflected based on perceived uncertainty, cost, and expected utilities of both the attacker and defender, the system lifetime (i.e., mean time to security failure), and improved false-positive rates of intrusion detection.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.5
2021 Lightweight On-Demand Honeypot Deployment for Cyber Deception
Jaime C. Acosta, Anjon Basak, Christopher Kiekintveld, Charles A. Kamhoua
ICDF2C4
2021 Pareto GAN: Extending the Representational Power of GANs to Heavy-Tailed Distributions
abstract
Generative adversarial networks (GANs) are often billed as "universal distribution learners", but precisely what distributions they can represent and learn is still an open question. Heavy-tailed distributions are prevalent in many different domains such as financial risk-assessment, physics, and epidemiology. We observe that existing GAN architectures do a poor job of matching the asymptotic behavior of heavy-tailed distributions, a problem that we show stems from their construction. Additionally, common loss functions produce unstable or near-zero gradients when faced with the infinite moments and large distances between outlier points characteristic of heavy-tailed distributions. We address these problems with the Pareto GAN. A Pareto GAN leverages extreme value theory and the functional properties of neural networks to learn a distribution that matches the asymptotic behavior of the marginal distributions of the features. We identify issues with standard loss functions and propose the use of alternative metric spaces that enable stable and efficient learning. Finally, we evaluate our proposed approach on a variety of heavy-tailed datasets.
Todd Huster, Jeremy E. J. Cohen, Zinan Lin 0001, Kevin S. Chan, Charles A. Kamhoua, Nandi Leslie, C. Jason Chiang, Vyas Sekar
ICML5
2021 Deep Learning for Cyber Deception in Wireless Networks
abstract
Wireless communications networks are an integral part of intelligent systems that enhance the automation of various activities and operations embarked by humans. For example, the development of intelligent devices imbued with sensors leverages emerging technologies such as machine learning (ML) and artificial intelligence (AI), which have proven to enhance military operations through communication, control, intelligence gathering, and situational awareness. However, growing concerns in cybersecurity imply that attackers are always seeking to take advantage of the widened attack surface to launch adversarial attacks which compromise the activities of legitimate users. To address this challenge, we leverage on deep learning (DL) and the principle of cyber-deception to propose a method for defending wireless networks from the activities of jammers. Specifically, we use DL to regulate the power allocated to users and the channel they use to communicate, thereby luring jammers into attacking designated channels that are considered to guarantee maximum damage when attacked. Furthermore, by directing its energy towards the attack on a specific channel, other channels are freed up for actual transmission, ensuring secure communication. Through simulations and experiments carried out, we conclude that this approach enhances security in wireless communication systems.
Felix O. Olowononi, Ahmed H. Anwar, Danda B. Rawat, Jaime C. Acosta, Charles A. Kamhoua
MSN5
2020 Integrating Mission-Centric Impact Assessment to Operational Resiliency in Cyber-Physical Systems
abstract
Developing mission-centric impact assessment techniques to address cyber resiliency in the cyber-physical systems (CPSs) requires integrating system inter-dependencies to the risk and resilience analysis process. Generally, network administrators utilize attack graphs to estimate possible consequences in a networked environment. Attack graphs lack to incorporate the operations-specific dependencies. Localizing the dependencies among operational missions, tasks, and the hosting devices in a large-scale CPS is also challenging. In this work, we offer a graphical modeling technique to integrate the mission-centric impact assessment of cyberattacks by relating the effect to the operational resiliency by utilizing a combination of the logical attack graph and mission impact propagation graph. We propose formal techniques to compute cyberattacks' impact on the operational mission and offer an optimization process to minimize the same, having budgetary restrictions. We also relate the effect to the system functional operability. We illustrate our modeling techniques using a SCADA (supervisory control and data acquisition) case study for the cyber-physical power systems. We believe our proposed method would help evaluate and minimize the impact of cyber attacks on CPS's operational missions and, thus, enhance cyber resiliency.
Md Ariful Haque, Sachin Shetty, Charles A. Kamhoua, Kimberly Gold
GLOBECOM3
2020 Software Diversity for Cyber Deception
abstract
In this paper, we propose a cyber deception approach using software diversity in a honeynet. Honeypot allocation is used as an active cyber deception technique to increase the uncertainty of adversaries and hide the true state of the network. Moreover, software diversity limits the ability of attackers to discover honeypots. Specifically, this paper introduces a diversity-based honeypot allocation approach for network security formulated in a game-theoretic framework. We consider a two-player zero-sum game between the network defender and the adversary. To validate our findings, we measured the potential benefits of diversity on network security and calculated the optimum diversifying strategy in Nash equilibrium using different honeypot types.
Aliou Badra Sarr, Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie, Jaime C. Acosta
GLOBECOM3
2020 Mitigation of Jamming Attacks via Deception
abstract
This paper considers the problem of mitigating jamming attacks by aiming to deceive the jammer. Specifically, in the presence of a jammer, to defend a transmitter-receiver pair sending (real) information, the paper proposes the novel technique of sending fake information over a second transmitter-receiver pair in order to deceive the jammer into investing some of its jamming power budget for jamming the channel carrying fake information. The paper develops a leader-follower model where the jammer (acting as the follower) adopts it's jamming strategy after sensing the communication activities on the channels carrying the real and fake information, while the system (acting as the leader) adopts its power allocation strategy prior to the jammer. The paper characterizes the optimal power allocation strategy of the system considering the jammer to be non-strategic in nature, as well as characterizes the Subgame Perfect Nash Equilibrium (SPNE) strategy of the leader-follower game considering both the system and the jammer to be strategic entities. Extensive simulation results are provided to gain insights into the deception strategies developed in the paper.
Satyaki Nan, Swastik Brahma, Charles A. Kamhoua, Nandi Leslie
PIMRC3
2020 Modeling Mission Impact of Cyber Attacks on Energy Delivery Systems
Md Ariful Haque, Sachin Shetty, Charles A. Kamhoua, Kimberly Gold
SecureComm (2)3
2020 A Bayesian Game Theoretic Approach for Inspecting Web-Based Malvertising
abstract
Web-based advertising systems have been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply various redirection and evasion techniques. Meanwhile, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under resource and time constraints. Moreover, the ad network is disadvantaged because it has incomplete information about whether it is facing a benign or malicious advertiser. In this paper, we aim to apply the Bayesian game model by designing two games to formulate the problem of inspecting the Web-based maladvertising. The first game has two types of Advertisers, namely Malicious and Benign, and one type of Defender; the second game has two types of Attackers, Advanced and Simple, in terms of their capability of redirection and evasion, and one type of Defender. We define their strategies and payoff functions, and compute their Bayesian Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and we derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE Trans. Dependable Secur. Comput.3
2020 Look-Aside at Your Own Risk: Privacy Implications of DNSSEC Look-Aside Validation
abstract
The Domain Name System Security Extension (DNSSEC) leverages public-key cryptography to provide data integrity, source authentication, and denial of existence for DNS responses. To complement DNSSEC operations, DNSSEC Look-aside Validation (DLV) is designed for alternative off-path validation. Although DNS privacy attracts a lot of attention, the privacy implications of DLV are not fully investigated and understood. In this paper, we take a first in-depth look into DLV, highlighting its lax specifications and privacy implications. By performing extensive experiments over datasets of domain names under comprehensive experimental settings, our findings firmly confirm the privacy leakages caused by DLV. We discover that a large number of domains that should not be sent to DLV servers are being leaked. We explore the root causes, including the lax specifications of DLV. We also propose two approaches to fix the privacy leakages. Our approaches require trivial modifications to the existing DNS standards, and we demonstrate their cost in terms of latency and communication.
David Mohaisen, Zhongshu Gu, Kui Ren 0001, Zhenhua Li 0001, Charles A. Kamhoua, Laurent Njilla, DaeHun Nyang
IEEE Trans. Dependable Secur. Comput.5
2020 Applying Chaos Theory for Runtime Hardware Trojan Monitoring and Detection
abstract
Hardware Trojans (HTs) pose a serious threat to the security of Integrated Circuits (ICs). Detecting HTs in an IC is an important but difficult problem due to the wide spectrum of HTs and their stealthy nature. While researchers have been working on enhancing traditional IC tests and developing new methods to try to detect Trojans, there is still a possibility a Trojan will avoid detection during test time and be activated once the chip is in use. A runtime Trojan detection system could monitor an IC during its operational life time and provide a last-line of defense. However, most runtime approaches are infeasible due to the overhead introduced by additional hardware, or computational complexity, or both. In this paper, we propose a hardware-based runtime detection model that overcomes the aforementioned constraints. It applies chaos theory, which has been shown to be effective in several other domains, to characterize dynamic data in a reconstructed phase space, which helps us describe, analyze, and interpret power consumption data (whether chaotic or not). The proposed chaos based approach does not make any assumption on the statistical distribution of power consumption, this makes our model applicable for runtime use given the fact that power consumption is very dynamic as well as heavily application and data dependent. Hardware overhead, which is the main challenge for runtime approaches, is reduced by taking advantage of available thermal sensors present in most modern ICs. For real world implementation, thermal sensor noise cancelation is considered in our proposed model. Our simulation results for detecting Trojans on publicly available Trojan benchmarks demonstrate that the proposed model outperforms the current runtime Trojan detection approaches in terms of detection rate, computational complexity, and implementation feasibility. Approved for Public Release; Distribution Unlimited: 88ABW-2016-4308; Dated 31 AUG 2016.
Luke Kwiat, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla
IEEE Trans. Dependable Secur. Comput.4
2019 Behavioral Cyber Deception: A Game and Prospect Theoretic Approach
abstract
This paper aims to characterize deception based attack-defense strategies when a system and an attacker is behavioral in nature under strategic considerations. The paper uses Prospect Theory to model the behavioral nature of the system and the attacker, and Game Theory to model the strategic interactions between them. The paper first considers the availability of multiple computing devices that can be used to deceive a behavioral attacker into attacking a device being unused by a behavioral system and characterizes the Nash Equilibrium (NE) based attack-defense strategy in such a scenario under cost considerations. The paper then considers the problem of protecting a target device that is accessible via a tree network and proposes the idea of deceptive routing to mislead a behavioral attacker towards a fake target present in the network. The NE based attack-defense strategies in the context of the proposed deceptive routing technique is also characterized. Numerical results provide insights into the strategic deception techniques presented in this paper.
Satyaki Nan, Swastik Brahma, Charles A. Kamhoua, Nandi Leslie
GLOBECOM3
2019 BlockTrail: A Scalable Multichain Solution for Blockchain-Based Audit Trails
abstract
Blockchain-based audit trails provide a consensus-driven and tamper-proof trail of system events that are helpful in creating provenance in enterprise solutions. However, taking into account the transaction bulk generated by these applications and the throughput limitations of existing blockchains, a single ledger for record keeping can be inefficient and costly. To that end, we see an imperative need for a new blockchain design that is capable of addressing current challenges, without compromising security and provenance. Hence, we propose BlockTrail, a scalable and efficient blockchain solution for auditing applications. BlockTrail fragments the legacy blockchain systems into layers of co-dependent hierarchies, thereby reducing the time and space complexity, and increasing the throughput. BlockTrail is prototyped on "Practical Byzantine Fault Tolerance" (PBFT) protocol with a custom-built blockchain. Experiments with BlockTrail show that compared to the conventional schemes, BlockTrail is more efficient, and has less storage footprint.
Ashar Ahmad, Muhammad Saad 0001, Laurent Njilla, Charles A. Kamhoua, Mostafa A. Bassiouni, David Mohaisen
ICC4
2019 Dual Redundant Cyber-Attack Tolerant Control Systems Strategy for Cyber-Physical Systems
abstract
In this paper, a cyber-attack tolerant control strategy for embedded controllers in a cyber-physical system is presented. A dual redundant control architecture that combines two identical controllers that are switched periodically between active and restart modes is proposed. The strategy is addressed to mitigate the impact due to corruption of the controller software by an adversary. We analyze the impact of the resetting and restarting the controller software and performance of switching process. The minimum requirements in the control design, for effective mitigation of cyber-attacks to the control software, that implies a "fast" switching period is provided. The simulation results demonstrate the effectiveness of the proposed strategy when the time to fully reset and restart the controller is faster than the time taken by adversary to compromise the controller. The results also provide insights into the stability and safety regions and the factors that determine the effectiveness of the proposed strategy.
Marco A. Gamarra, Sachin Shetty, Oscar R. González, Laurent Njilla, Marcus Pendleton, Charles A. Kamhoua
ICC6
2019 Compact Representation of Value Function in Partially Observable Stochastic Games
abstract
Value methods for solving stochastic games with partial observability model the uncertainty of the players as a probability distribution over possible states, where the dimension of the belief space is the number of states. For many practical problems, there are exponentially many states which causes scalability problems. We propose an abstraction technique that addresses this curse of dimensionality by projecting the high-dimensional beliefs onto characteristic vectors of significantly lower dimension (e.g., marginal probabilities). Our main contributions are (1) a novel compact representation of the uncertainty in partially observable stochastic games and (2) a novel algorithm using this representation that is based on existing state-of-the-art algorithms for solving stochastic games with partial observability. Experimental evaluation confirms that the new algorithm using the compact representation dramatically increases scalability compared to the state of the art.
Karel Horák 0002, Branislav Bosanský, Christopher Kiekintveld, Charles A. Kamhoua
IJCAI4
2019 A Deep Recurrent Neural Network Based Predictive Control Framework for Reliable Distributed Stream Data Processing
abstract
In this paper, we present design, implementation and evaluation of a novel predictive control framework to enable reliable distributed stream data processing, which features a Deep Recurrent Neural Network (DRNN) model for performance prediction, and dynamic grouping for flexible control. Specifically, we present a novel DRNN model, which makes accurate performance prediction with careful consideration for interference of co-located worker processes, according to multilevel runtime statistics. Moreover, we design a new grouping method, dynamic grouping, which can distribute/re-distribute data tuples to downstream tasks according to any given split ratio on the fly. So it can be used to re-direct data tuples to bypass misbehaving workers. We implemented the proposed framework based on a widely used Distributed Stream Data Processing System (DSDPS), Storm. For validation and performance evaluation, we developed two representative stream data processing applications: Windowed URL Count and Continuous Queries. Extensive experimental results show: 1) The proposed DRNN model outperforms widely used baseline solutions, ARIMA and SVR, in terms of prediction accuracy; 2) dynamic grouping works as expected; and 3) the proposed framework enhances reliability by offering minor performance degradation with misbehaving workers.
Jielong Xu, Jian Tang 0008, Chengxiang Yin 0001, Kevin A. Kwiat, Charles A. Kamhoua
IPDPS6
2019 A game-theoretic framework for dynamic cyber deception in internet of battlefield things
abstract
Cyber deception techniques are crucial to protect networks in battlefield settings and combat malicious cyber attacks. Cyber deception can effectively disrupt the surveillance process outcome of an adversary. In this paper, we propose a novel approach for cyber deception to protect important nodes and trap the adversary. We present a sequential approach of honeypot placement to defend and protect the network vital nodes. We formulate a stochastic game to study the dynamic interactions between the network administrator and the attacker. The defender makes strategic decisions about where to place honeypots to introduce new vulnerabilities to the network. The attacker's goal is to develop an attack strategy to compromise the nodes of the network by exploiting a set of known vulnerabilities. To consider a practical threat model, we assume that the attacker can only observe a noisy version of the network state. To this end, both players solve a partially observable stochastic game (POSG). Finally, we present a discussion on existing techniques to solve the formulated game and possible approaches to reduce the game complexity as part of our ongoing and future research.
Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie
MobiQuitous2
2019 Online Cyber Deception System Using Partially Observable Monte-Carlo Planning Framework
Md Ali Reza Al Amin, Sachin Shetty, Laurent Njilla, Deepak K. Tosh, Charles A. Kamhoua
SecureComm (2)5
2019 Optimizing honeypot strategies against dynamic lateral movement using partially observable stochastic games
Karel Horák 0002, Branislav Bosanský, Petr Tomásek, Christopher Kiekintveld, Charles A. Kamhoua
Comput. Secur.5
2019 Transfer learning for detecting unknown network attacks
abstract
Network attacks are serious concerns in today’s increasingly interconnected society. Recent studies have applied conventional machine learning to network attack detection by learning the patterns of the network behaviors and training a classification model. These models usually require large labeled datasets; however, the rapid pace and unpredictability of cyber attacks make this labeling impossible in real time. To address these problems, we proposed utilizing transfer learning for detecting new and unseen attacks by transferring the knowledge of the known attacks. In our previous work, we have proposed a transfer learning-enabled framework and approach, called HeTL, which can find the common latent subspace of two different attacks and learn an optimized representation, which was invariant to attack behaviors’ changes. However, HeTL relied on manual pre-settings of hyper-parameters such as relativeness between the source and target attacks. In this paper, we extended this study by proposing a clustering-enhanced transfer learning approach, called CeHTL, which can automatically find the relation between the new attack and known attack. We evaluated these approaches by stimulating scenarios where the testing dataset contains different attack types or subtypes from the training set. We chose several conventional classification models such as decision trees, random forests, KNN, and other novel transfer learning approaches as strong baselines. Results showed that proposed HeTL and CeHTL improved the performance remarkably. CeHTL performed best, demonstrating the effectiveness of transfer learning in detecting new network attacks.
Juan Zhao 0003, Sachin Shetty, Jan Wei Pan, Charles A. Kamhoua, Kevin A. Kwiat
EURASIP J. Inf. Secur.4
2019 Fast Approximate Score Computation on Large-Scale Distributed Data for Learning Multinomial Bayesian Networks
abstract
In this article, we focus on the problem of learning a Bayesian network over distributed data stored in a commodity cluster. Specifically, we address the challenge of computing the scoring function over distributed data in an efficient and scalable manner, which is a fundamental task during learning. While exact score computation can be done using the MapReduce-style computation, our goal is to compute approximate scores much faster with probabilistic error bounds and in a scalable manner. We propose a novel approach, which is designed to achieve the following: (a) decentralized score computation using the principle of gossiping; (b) lower resource consumption via a probabilistic approach for maintaining scores using the properties of a Markov chain; and (c) effective distribution of tasks during score computation (on large datasets) by synergistically combining well-known hashing techniques. We conduct theoretical analysis of our approach in terms of convergence speed of the statistics required for score computation, and memory and network bandwidth consumption. We also discuss how our approach is capable of efficiently recomputing scores when new data are available. We conducted a comprehensive evaluation of our approach and compared with the MapReduce-style computation using datasets of different characteristics on a 16-node cluster. When the MapReduce-style computation provided exact statistics for score computation, it was nearly 10 times slower than our approach. Although it ran faster on randomly sampled datasets than on the entire datasets, it performed worse than our approach in terms of accuracy. Our approach achieved high accuracy (below 6% average relative error) in estimating the statistics for approximate score computation on all the tested datasets. In conclusion, it provides a feasible tradeoff between computation time and accuracy for fast approximate score computation on large-scale distributed data.
Anas Katib, Praveen Rao 0001, Kobus Barnard, Charles A. Kamhoua
ACM Trans. Knowl. Discov. Data4
2019 Thwarting Security Threats From Malicious FPGA Tools With Novel FPGA-Oriented Moving Target Defense
abstract
The increasing usage and popularity of the field-programmable gate array (FPGA) systems bring in security concerns. Existing countermeasures are mostly based on the assumption that the computer-aided design (CAD) tools for FPGA configuration are trusted. Unfortunately, this assumption does not always hold. In this paper, we investigate the potential security threats originated from the untrusted CAD tools. Furthermore, we exploit the principle of moving target defense (MTD) to propose an FPGA-oriented MTD (FOMTD) method. The three defense lines in the FOMTD generate uncertainties, from the attacker's point of view, to thwart hardware Trojan insertion attacks. The theoretical upper bound of the hardware Trojan hit rate for each defense line is provided in this paper. Experimental results show that the proposed defense line 2 and defense line 3 reduce the Trojan hit rate by up to 40% and 91%, respectively, for the scenario where the malicious CAD tool can insert Trojans in the occupied FPGA slices. The proposed gate replacement technique in the defense line 3 further improves the attack resilience and obtains 88% reduction on the Trojan hit rate. Compared to the static redundancy-based Trojan detection method, the proposed method achieves better resilience against Trojan insertions and consumes 50% less dynamic power.
Laurent Njilla, Charles A. Kamhoua, Qiaoyan Yu
IEEE Trans. Very Large Scale Integr. Syst.3
2018 ChainFS: Blockchain-Secured Cloud Storage
abstract
This work presents ChainFS, a middleware system that secures cloud storage services using a minimally trusted Blockchain. ChainFS hardens the cloud-storage security against forking attacks. The ChainFS middleware exposes a file-system interface to end users. Internally, ChainFS stores data files in the cloud and exports minimal and necessary functionalities to the Blockchain for key distribution and file operation logging. We implement the ChainFS system on Ethereum and S3FS and closely integrate it with FUSE clients and Amazon S3 cloud storage. We measure the system performance and demonstrate low overhead.
Yuzhe Tang, Qiwu Zou, Ju Chen, Kai Li 0017, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
IEEE CLOUD5
2018 CloudPoS: A Proof-of-Stake Consensus Design for Blockchain Integrated Cloud
abstract
Maintaining data provenance in cloud in a tamper-resistant manner that cannot be breached by malicious parties is a necessity from the current security standpoint. Blockchain technology has emerged as a secure solution to store and share information by offering an immutable distributed ledger service. Its effectiveness hinges on the infrastructure supporting the distributed ledger and consensus protocol that governs the validity of entries in the Blockchain. Hence, Blockchain can be a potential candidate to implement data provenance; however, traditional cryptocurrency-based consensus models become a bottleneck in the cloud environment. Therefore, in this paper, we propose a Blockchain based data provenance architecture (BlockCloud) that incorporates a proof-of-stake (PoS)-based consensus protocol (CloudPoS) for securely recording the data operations occurring in cloud environment. The critical operational phases of the protocol are discussed in depth, which leverages the cloud users' cyber infrastructure resources. A cloud-based testbed environment is created using a local cluster of physical machines managed by Xen hypervisor. Resource elasticity is enabled using Kubernetes setup that interacts with the dockerized containers, which emulate as peers in the Blockchain network. We then evaluate the effectiveness of the protocol in a simulated environment and conduct performance tests of the proposed consensus.
Deepak K. Tosh, Sachin Shetty, Peter Foytik, Charles A. Kamhoua, Laurent Njilla
IEEE CLOUD4
2018 QOI: Assessing Participation in Threat Information Sharing
abstract
We introduce the notion of Quality of Indicator (QoI) to assess the level of contribution by participants in threat intelligence sharing. We exemplify QoI by metrics of the correctness, relevance, utility, and uniqueness of indicators. We build a system that extrapolates the metrics using a machine learning process over a reference set of indicators. We compared these results against a model that only considers the volume of information as a metric for contribution, and unveiled various observations, including the ability to spot low-quality contributions that are synonymous to free-riding.
Jeman Park 0001, Hisham Alasmary, Omar Al-Ibrahim, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla, David Mohaisen
ICASSP4
2018 Analysis of Stepping Stone Attacks in Dynamic Vulnerability Graphs
abstract
Vulnerability graphs have been employed as an effective tool for analyzing exploitability and impact of chain of exploits in networked environments. The attack graphs are created by a chain of "stepping stones" from the attacker origin to the desired target. The stepping stones not only provide the intermediate steps to reach the target, but also make it difficulty to identify the attacker's true location. In this paper, we model and analyze stepping stones in dynamic vulnerability graphs. Most analysis based on attack graph assume that the graph edges and weights remain constant during the attacker's attempt to propagate through the network. We propose a biased min- consensus technique for dynamic graphs with switching topology as a distributed technique to determine the attach paths with more probable stepping-stones in dynamic vulnerability graphs. We use min-plus algebra to determine necessary and sufficient convergence conditions. A necessary condition for convergence to the shortest path in the switching topology case is provided.
Marco A. Gamarra, Sachin Shetty, David M. Nicol, Oscar Gonazlez, Charles A. Kamhoua, Laurent Njilla
ICC5
2018 Enabling Cooperative IoT Security via Software Defined Networks (SDN)
abstract
Internet of Things (IoT) is becoming an increasingly attractive target for cybercriminals. We observe that many attacks to IoTs are launched in a collusive way, such as brute-force hacking usernames and passwords, to target at a particular victim. However, most of the time our defending mechanisms to such kind of attacks are carried out individually and independently, which leads to ineffective and weak defense. To this end, we propose to leverage Software Defined Networks (SDN) to enable cooperative security for legacy IP-based IoT devices. SDN decouples control plane and data plane, and can help bridge the knowledge divided between the application and network layers. In this paper, we discuss the IoT security problems and challenges, and present an SDN-based architecture to enable IoT security in a cooperative manner. Furthermore, we implemented a platform that can quickly share the attacking information with peer controllers and block the attacks. We carried out our experiments in both virtual and physical SDN environments with OpenFlow switches. Our evaluation results show that both environments can scale well to handle attacks, but hardware implementation is much more efficient than a virtual one.
Garegin Grigoryan, Yaoqing Liu, Laurent Njilla, Charles A. Kamhoua, Kevin A. Kwiat
ICC4
2018 Game Theoretic Characterization of Collusive Behavior Among Attackers
abstract
Recent observations have shown that most of the attacks are fruits of collaboration among attackers. In this work we have developed a coalition formation game to model the collusive behavior among attackers. The novelty of this work is that we are the first to investigate the coalition formation dynamics among attackers with different efficiency. Most of the related works have modeled the attacker as a single entity. We define a new parameter called friction to represent the unwillingness of an attacker to collude. We have shown that the proportion of attackers in the Maximum Average Payoff Coalition (MAPC) decreases with efficiency. We have also shown that as the friction increases, size and heterogeneity of MAPC decrease. We show, using text analysis on a hacker web forum chat data, that the hacker collaboration network shows a strong small-world characteristics. We identify the leaders in these coalitions. The cluster compositions of the hacker collaboration network agree with our model. We also develop method to estimate the friction parameters for the attackers to decide optimal coalition to join. As this model provides insight into coalition formation among attackers, e.g., leaders, composition, and homogeneity, this model will be helpful to develop better defender strategies.
Abhishek Roy 0005, Charles A. Kamhoua, Prasant Mohapatra
INFOCOM2
2018 Establishing evolutionary game models for CYBer security information EXchange (CYBEX)
Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat
J. Comput. Syst. Sci.3
2018 GPU-Accelerated High-Throughput Online Stream Data Processing
abstract
The Single Instruction Multiple Data (SIMD) architecture of Graphic Processing Units (GPUs) makes them perfect for parallel processing of big data. In this paper, we present the design, implementation and evaluation of G-Storm, a GPU-enabled parallel system based on Storm, which harnesses the massively parallel computing power of GPUs for high-throughput online stream data processing. G-Storm has the following desirable features: 1) G-Storm is designed to be a general data processing platform as Storm, which can handle various applications and data types. 2) G-Storm exposes GPUs to Storm applications while preserving its easy-to-use programming model. 3) G-Storm achieves high-throughput and low-overhead data processing with GPUs. 4) G-Storm accelerates data processing further by enabling Direct Data Transfer (DDT), between two executors that process data at a common GPU. We implemented G-Storm based on Storm 0.9.2 and tested it using three different applications, including continuous query, matrix multiplication and image resizing. Extensive experimental results show that 1) Compared to Storm, G-Storm achieves over 7χ improvement on throughput for continuous query, while maintaining reasonable average tuple processing time. It also leads to 2.3χ and 1.3χ throughput improvements on the other two applications, respectively. 2) DDT significantly reduces data processing time.
Zhenhua Chen 0006, Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Charles A. Kamhoua, Chonggang Wang
IEEE Trans. Big Data5
2018 On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic Approach
abstract
Security is one of the top considerations in hardware designs for Internet-of-Things (IoT), where embedded cryptosystems are extensively used. Traditionally, random dynamic voltage scaling technology has been shown to be very effective in improving the resistance of cryptosystems against side-channel attacks. However, in this paper we demonstrate that the resistance can be undermined by providing lower off-chip power supply voltage. In order to address this issue, we then further propose to monitor the off-chip power supply voltage, and trigger an alarm to protect valued information once the power supply voltage is lower than the expected voltage (threshold voltage). However, considering both maintenance cost of IoT devices and the environment noise on power supply voltage, we first formulated this problem as a nonzero sum game model, and the attacker and the circuit supplier (defender) are the players of this game. The analysis of the Nash equilibria in this game show interesting guideline to the defender about the choice of threshold voltage, which is based on parameters of cryptosystem including the value of information, denial-of-service cost in IoT, etc.
Hui Geng, Kevin A. Kwiat, Charles A. Kamhoua, Yiyu Shi 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2018 Combating Data Leakage Trojans in Commercial and ASIC Applications With Time-Division Multiplexing and Random Encoding
Travis E. Schulze, Daryl G. Beetner, Yiyu Shi 0001, Kevin A. Kwiat, Charles A. Kamhoua
IEEE Trans. Very Large Scale Integr. Syst.5
2017 An SDN Based Framework for Guaranteeing Security and Performance in Information-Centric Cloud Networks
abstract
Cloud data centers are critical infrastructures to deliver cloud services. Although security and performance of cloud data centers have been well studied in the past, their networking aspects are overlooked. Current network infrastructures in cloud data centers limit the ability of cloud provider to offer guaranteed cloud network resources to users. In order to ensure security and performance requirements as defined in the service level agreement (SLA) between cloud user and provider, cloud providers need the ability to provision network resources dynamically and on the fly. The main challenge for cloud provider in utilizing network resource can be addressed by provisioning virtual networks that support information centric services by separating the control plane from the cloud infrastructure. In this paper, we propose an sdn based information centric cloud framework to provision network resources in order to support elastic demands of cloud applications depending on SLA requirements. The framework decouples the control plane and data plane wherein the conceptually centralized control plane controls and manages the fully distributed data plane. It computes the path to ensure security and performance of the network. We report initial experiment on average round-trip delay between consumers and producers.
Uttam Ghosh, Pushpita Chatterjee, Deepak K. Tosh, Sachin Shetty, Kaiqi Xiong, Charles A. Kamhoua
CLOUD6
2017 Cloud Standards in Comparison: Are New Security Frameworks Improving Cloud Security?
abstract
The increasing relevance of information assurance in cloud computing has forced governments and stakeholders to turn their attention to Information Technology (IT) security certifications and standards. The introduction of new frameworks such as FedRAMP in the US and C5 in Germany is aimed to raise the level of protection against threats and vulnerabilities unique to cloud computing. However, our in-depth and systematic analyses reveals that these new standards do not bring a radical change in the realm of certifications. Results also shows that the newly developed standards share much of their basis with older, more consolidated standards such as the ISO/IEC 27001 and hence the need for determining the added value. In this study, we provide an overview of ISO/IEC 27001, C5, and FedRAMP while examining their completeness and adequacy in addressing current threats to cloud assurance. We question the level of protection they offer by comparing these three certifications alongside each other. We identify weaknesses in the three frameworks and highlight necessary improvements to meet the security requirements indispensable in relation to the current threat landscape.
Carlo Di Giulio, Read Sprabery, Charles A. Kamhoua, Kevin A. Kwiat, Roy H. Campbell, Masooda N. Bashir
CLOUD3
2017 Man in the Cloud (MITC) Defender: SGX-Based User Credential Protection for Synchronization Applications in Cloud Computing Platform
abstract
In cloud environment, client user credential protection is a critical security capability that is target of adversarial attacks, especially, in cloud file synchronization applications. Among the various adversarial attacks, MITC (Man in the Cloud) attack on commercial cloud storage applications has emerged as a critical threat because it is easy to launch and hard to detect. In this paper, we propose MITC Defender, a hardware-based defense system capable of protecting client user credentials using Intel Software Guard Extensions (SGX) and preventing against four different types of MITC attack in cloud environment. By adopting Intel SGX security features such as sealing and attestation, MITC Defender can securely seal user credentials locally and easily unseal user credentials, when verifications are needed, in a Trusted Execution Environment (TEE). We implement MITC Defender on an open source platform OpenSGX and evaluate the performance and potential overhead. Our evaluation results show that MITC Defender is effective on defense against MITC attack and other security threats with a low cost.
Xueping Liang, Sachin Shetty, Lingchen Zhang, Charles A. Kamhoua, Kevin A. Kwiat
CLOUD4
2017 IT Security and Privacy Standards in Comparison: Improving FedRAMP Authorization for Cloud Service Providers
abstract
To demonstrate compliance with privacy and security principles, information technology (IT) service providers often rely on security standards and certifications. However, the appearance of new service models such as cloud computing has brought new threats to information assurance, weakening the protection that existing standards can provide. In this study, we analyze four highly regarded IT security standards used to assess, improve, and demonstrate information systems assurance and cloud security. ISO/IEC 27001, SOC 2, C5, and FedRAMP are standards adopted worldwide and constantly updated and improved since the first release of ISO in 2005. We examine their adequacy in addressing current threats to cloud security, and provide an overview of the evolution over the years of their ability to cope with threats and vulnerabilities. By comparing the standards alongside each other, we investigate their complementarity, their redundancies, and the level of protection they offer to information stored in cloud systems. We unveil vulnerabilities left unaddressed in the four frameworks, thus questioning the necessity of multiple standards to assess cloud assurance. We suggest necessary improvements to meet the security requirements made indispensable by the current threat landscape.
Carlo Di Giulio, Charles A. Kamhoua, Roy H. Campbell, Read Sprabery, Kevin A. Kwiat, Masooda N. Bashir
CCGrid2
2017 ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and Availability
abstract
Cloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications.
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
CCGrid4
2017 Security Implications of Blockchain Cloud with Analysis of Block Withholding Attack
abstract
The blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations.
Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
CCGrid4
2017 Estimation of Safe Sensor Measurements of Autonomous System Under Attack
abstract
The introduction of automation in cyber-physical systems (CPS) has raised major safety and security concerns. One attack vector is the sensing unit whose measurements can be manipulated by an adversary through attacks such as denial of service and delay injection. To secure an autonomous CPS from such attacks, we use a challenge response authentication (CRA) technique for detection of attack in active sensors data and estimate safe measurements using the recursive least square algorithm. For demonstrating effectiveness of our proposed approach, a car-follower model is considered where the follower vehicle's radar sensor measurements are manipulated in an attempt to cause a collision.
Raj Gautam Dutta, Xiaolong Guo 0001, Teng Zhang 0002, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla, Yier Jin
DAC5
2017 Automatic Generation of Hardware Sandboxes for Trojan Mitigation in Systems on Chip (Abstract Only)
Christophe Bobda, Taylor J. L. Whitaker, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
FPGA3
2017 A game theoretic approach for inspecting web-based malvertising
abstract
Web-based advertising system has become a convenient and efficient channel for advertisers to deliver ads to targeted Internet users. Unfortunately, this system has been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply a variety of evasion techniques such as fingerprinting the execution environment, redirecting to compromised IP addresses, and malware polymorphism. On the other hand, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under the constraints of resource and time. In this paper, we aim to apply game theory to formulate the problem of inspecting the malware inserted by the malvertisers into the Web-based advertising system. We design a normal form game between the malvertiser and the ad network, define their strategies and payoff functions, and compute their pure-strategy and mixed-strategy Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy.
Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla
ICC3
2017 Electric grid power flow model camouflage against topology leaking attacks
abstract
The power flow model for DC power grids has been used theoretically to launch false data injection attacks (FDIAs) against state estimation. We recognize FDIAs are just one possible attack using the power flow model and that the grid topology information within the model implies its discovery may also facilitate topology-based attacks. We show attackers can derive the power flow model, and thus the topology also. Indeed, with incomplete data, attackers can accurately reconstruct regions of the model, or topology, all that is necessary to launch an attack. We also illustrate how to cause such attackers to derive instead a convincing fake model by camouflaging the real model. Consequently, no sensitive information will leak, so attacks based on this fake model will be ineffective, rather alerting grid administrators to the attacker's efforts. Using five test cases included in the MATLAB power flow analysis tool MATPOWER, ranging from 9 to 300 buses, an average 67.0% of the topology may be derived with a 69.1% model accuracy. Lastly, we find reconstructions of small portions of the model sufficient for performing FDIAs with 75% success, and that camouflage prevents 93% of them in all but the 9-bus case.
Ian D. Markwood, Yao Liu 0007, Kevin A. Kwiat, Charles A. Kamhoua
INFOCOM4
2017 Approach to detect non-adversarial overlapping collusion in crowdsourcing
abstract
Crowdsourcing services have become one of the most common ways organizations can gather ideas for new products and services from large crowds of consumers by offering monetary rewards depending on the tasks. However, this monetary reward has begun to attract malicious crowds of users who wish to complete the task with minimal effort through collaboration. For instance, a task based on reviews of a product can be degraded when malicious users copy each other with minimal edits of the review, giving a misrepresentation of the true quality of the product. More specifically, we investigate the case where different malicious crowd sizes cooperate on different tasks, known as overlapping groups. Such sophisticated and hard to detect malicious crowds provide unfair evaluations and misleading results to the crowdsourcers. To overcome this type of attack, we propose two methods to point out such groups with high accuracy. The first method detects similar reviews by including a new proposed similarity between review texts and show the results outperform the vectorial similarity measures used in prior works. The second method is based on community detection on networks and exploits the semantic similarity of the reviews. The experiments were conducted on reviews from Ott dataset on Amazon Mechanical Turk.
Georges A. Kamhoua, Niki Pissinou, S. Sitharama Iyengar, Jonathan Beltran, Jerry Miller, Charles A. Kamhoua, Laurent Njilla
IPCCC6
2017 Reputation Routing in MANETs
abstract
In this work we present a trust computation method, Direct Trust Computation, and utilize it to design a Reputation Routing Model (RRM) for MANETs. We utilize this routing framework to mitigate the effect of blackhole attacks in OLSR without altering the original protocol or increasing its overhead. Our solution can isolate bad nodes in the network and select the most trusted path to route packets. We evaluate the performance of our model by emulating network scenarios on Common Open Research Emulator (CORE) for static as well as dynamic topologies. From our findings, it is observed that RRM substantially outperforms the original OLSR protocol in terms of packet delivery rates in presence of a malicious node, unless the mobility rate is quite high. RRM is therefore useful in mitigating the effect of blackhole attacks in MANETs, particularly in low mobility scenarios.
Prateek K. Singh, Koushik Kar, Charles A. Kamhoua
VTC Fall3
2016 Quick Eviction of Virtual Machines through Proactive Snapshots
abstract
Live migration of Virtual Machines (VMs) is a key technique to quickly migrate workloads in response to events such as impending failure or load changes. Despite extensive research, state-of-the-art live migration approaches take a long time to migrate a VM, which in turn negatively impacts the application performance during migration. We present, Quick Eviction, a new approach to significantly speed up the eviction of a VM from the source host with low impact on VM's performance during migration. Before migration, Quick Eviction regularly snapshots the VM's memory to a destination or a failover node. During the actual migration, Quick Eviction has to transfer only a small amount of dirtied memory resulting in a very short time to completely evict the VM out of the source. Our experimental results show that Quick Eviction in the KVM/QEMU platform significantly reduces the eviction time.
Dinuni K. Fernando, Hardik Bagdi, Yaohui Hu, Ping Yang 0002, Kartik Gopalan, Charles A. Kamhoua, Kevin A. Kwiat
CLUSTER6
2015 Security-Aware Virtual Machine Allocation in the Cloud: A Game Theoretic Approach
abstract
With the growth of cloud computing, many businesses, both small and large, are opting to use cloud services compelled by a great cost savings potential. This is especially true of public cloud computing which allows for quick, dynamic scalability without many overhead or long-term commitments. However, one of the largest dissuasions from using cloud services comes from the inherent and unknown danger of a shared platform such as the hyper visor. An attacker can attack a virtual machine (VM) and then go on to compromise the hyper visor. If successful, then all virtual machines on that hyper visor can become compromised. This is the problem of negative externalities, where the security of one player affects the security of another. This work shows that there are multiple Nash equilibria for the public cloud security game. It also demonstrates that we can allow the players' Nash equilibrium profile to not be dependent on the probability that the hyper visor is compromised, reducing the factor externality plays in calculating the equilibrium. Finally, by using our allocation method, the negative externality imposed onto other players can be brought to a minimum compared to other common VM allocation methods.
Luke Kwiat, Charles A. Kamhoua, Kevin A. Kwiat, Jian Tang 0008, Andrew P. Martin
CLOUD2
2015 G-Storm: GPU-enabled high-throughput online data processing in Storm
abstract
The Single Instruction Multiple Data (SIMD) architecture of Graphic Processing Units (GPUs) makes them perfect for parallel processing of big data. In this paper, we present the design, implementation and evaluation of G-Storm, a GPU-enabled parallel system based on Storm, which harnesses the massively parallel computing power of GPUs for high-throughput online stream data processing. G-Storm has the following desirable features: 1) G-Storm is designed to be a general data processing platform as Storm, which can handle various applications and data types. 2) G-Storm exposes GPUs to Storm applications while preserving its easy-to-use programming model. 3) G-Storm achieves high-throughput and low-overhead data processing with GPUs. We implemented G-Storm based on Storm 0.9.2 and tested it using two different applications: continuous query and matrix multiplication. Extensive experimental results show that compared to Storm, G-Storm achieves over 7x improvement on throughput for continuous query, while maintaining reasonable average tuple processing time. It also leads to 2.3x throughput improvement for the matrix multiplication application.
Zhenhua Chen 0006, Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Charles A. Kamhoua
IEEE BigData5
2015 On the use of design diversity in fault tolerant and secure systems: A qualitative analysis
abstract
The design and development of modern critical systems, including cyber-physical systems, is experiencing a greater reliance on the outsourcing of systems parts and the use of third-party components and tools. These issues pose new risks and threats that affect dependability in general, and security in particular. Not only the chances are higher for system designs to be faulty, yet they can be maliciously altered. In addition, the extension of monocultures, comprising networks of interconnected systems featuring similar platforms and computing resources, facilitates the spreading and gravity of attacks. Even correctly designed systems can have side behaviors leading to vulnerabilities that are exploitable by attackers. Design diversity, although proposed and used for long time, can help palliate these emerging challenges. This paper explores and analyzes design diversity from a qualitative perspective, with respect to its fault tolerance and performance properties. The paper describes core concepts of design diversity such as non-diversity and diversity points, and provides quality measurements that help gaining a better understanding of how design diversity can impact the development of fault tolerant and secure systems.
Kevin A. Kwiat, Charles A. Kamhoua
CISDA3
2015 Applying chaos theory for runtime Hardware Trojan detection
abstract
Hardware Trojans (HTs) are posing a serious threat to the security of Integrated Circuits (ICs). Detecting HT in an IC is an important but hard problem due to the wide spectrum of HTs and their stealthy nature. In this paper, we propose a runtime Trojan detection approach by applying chaos theory to analyze the nonlinear dynamic characteristics of power consumption of an IC. The observed power dissipation series is embedded into a higher dimensional phase space. Such an embedding transforms the observed data to a new processing space, which provides precise information about the dynamics involved. The feature model is then built in this newly reconstructed phase space. The overhead, which is the main challenge for runtime approaches, is reduced by taking advantage of available thermal sensors in most modern ICs. The proposed model has been tested for publicly-available Trojan benchmarks and simulation results show that the proposed scheme outperforms the state-of-the-art method using temperature tracking in terms of detection rate and computational complexity. More importantly, the proposed model does not make any assumptions about the statistical distribution of power trace and no Trojan-active data is needed, which makes it appropriate for runtime use.
Kevin A. Kwiat, Charles A. Kamhoua
CISDA3
2015 Cyber-Threats Information Sharing in Cloud Computing: A Game Theoretic Approach
abstract
Cybersecurity is among the highest priorities in industries, academia and governments. Cyber-threats information sharing among different organizations has the potential to maximize vulnerabilities discovery at a minimum cost. Cyber-threats information sharing has several advantages. First, it diminishes the chance that an attacker exploits the same vulnerability to launch multiple attacks in different organizations. Second, it reduces the likelihood an attacker can compromise an organization and collect data that will help him launch an attack on other organizations. Cyberspace has numerous interconnections and critical infrastructure owners are dependent on each other's service. This well-known problem of cyber interdependency is aggravated in a public cloud computing platform. The collaborative effort of organizations in developing a countermeasure for a cyber-breach reduces each firm's cost of investment in cyber defense. Despite its multiple advantages, there are costs and risks associated with cyber-threats information sharing. When a firm shares its vulnerabilities with others there is a risk that these vulnerabilities are leaked to the public (or to attackers) resulting in loss of reputation, market share and revenue. Therefore, in this strategic environment the firms committed to share cyber-threats information might not truthfully share information due to their own self-interests. Moreover, some firms acting selfishly may rationally limit their cybersecurity investment and rely on information shared by others to protect themselves. This can result in under investment in cybersecurity if all participants adopt the same strategy. This paper will use game theory to investigate when multiple self-interested firms can invest in vulnerability discovery and share their cyber-threat information. We will apply our algorithm to a public cloud computing platform as one of the fastest growing segments of the cyberspace.
Charles A. Kamhoua, Andrew P. Martin, Deepak K. Tosh, Kevin A. Kwiat, Chad Heitzenrater, Shamik Sengupta
CSCloud1
2015 Game Theoretic Modeling to Enforce Security Information Sharing among Firms
abstract
Robust CYBersecurity information EXchange (CYBEX) infrastructure is envisioned to protect the firms from future cyber attacks via collaborative threat intelligence sharing, which might be difficult to achieve via sole effort. The executive order from the U. S. federal government clearly encourages the firms to share their cybersecurity breach and patch related information among other federal and private firms for strengthening their as well as nation's security infrastructure. In this paper, we present a game theoretic framework to investigate the economic benefits of cyber-threat information sharing and analyze the impacts and consequences of not participating in the game of information exchange. We model the information exchange framework as distributed non-cooperative game among the firms and investigate the implications of information sharing and security investments. The proposed incentive model ensures and self-enforces the firms to share their breach information truthfully for maximization of its gross utility. Theoretical analysis of the incentive framework has been conducted to find the conditions under which firms' net benefit for sharing security information and investment can be maximized. Numerical results verify that the proposed model promotes such sharing, which helps to relieve their total security technology investment too.
Deepak K. Tosh, Shamik Sengupta, Sankar Mukhopadhyay, Charles A. Kamhoua, Kevin A. Kwiat
CSCloud4
2015 Contract-Theoretic Resource Allocation for Critical Infrastructure Protection
abstract
Critical infrastructure protection (CIP) is envisioned to be one of the most challenging security problems in the coming decade. One key challenge in CIP is the ability to allocate resources, either personnel or cyber, to critical infrastructures with different vulnerability and criticality levels. In this work, a contract- theoretic approach is proposed to solve the problem of resource allocation in critical infrastructure with asymmetric information. A control center (CC) is used to design contracts and offer them to infrastructures' owners. A contract can be seen as an agreement between the CC and infrastructures using which the CC allocates resources and gets rewards in return. Contracts are designed in a way to maximize the CC's benefit and motivate each infrastructure to accept a contract and obtain proper resources for its protection. Infrastructures are defined by both vulnerability levels and criticality levels which are unknown to the CC. Therefore, each infrastructure can claim that it is the most vulnerable or critical to gain more resources. A novel mechanism is developed to handle such an asymmetric information while providing the optimal contract that motivates each infrastructure to reveal its actual type. The necessary and sufficient conditions for such resource allocation contracts under asymmetric information are derived. Simulation results show that the proposed contract-theoretic approach maximizes the CC's utility while ensuring that no infrastructure has an incentive to ask for another contract, despite the lack of exact information at the CC.
AbdelRahman Eldosouky, Walid Saad 0001, Charles A. Kamhoua, Kevin A. Kwiat
GLOBECOM3
2015 NAPF: Percolation driven probabilistic flooding for interference limited cognitive radio networks
abstract
In this paper, we argue that the traditional techniques for flooding and probabilistic flooding are not applicable to cognitive radio networks under the SINR regime. We identify the causes that i) degrade node outreach even with increasing deployment density under the SINR model and ii) lead to duplicate transmissions under the Boolean model. Further performance degradation occurs due to the additional constraints imposed by the primary users in such networks. To increase node outreach in interference-limited cognitive radio networks, we propose a modified version of probabilistic flooding that uses lower message overhead without compromising network connectivity. This is achieved by having just enough number of neighbors of a node to rebroadcast to others. The subset of neighbors that are selected to broadcast is decided on the number of neighbor a nodes has, their spatial orientation with respect to each other, and the interference they might cause. Identification of such subsets reduce duplicate retransmissions which in turn reduces interference. We use a localized clustering technique in conjunction with the concept of critical density from percolation theory such that each node decides its own rebroadcasting probability in a distributed manner. Through simulations, we compare the proposed technique with flooding and probabilistic flooding. Results validated that, the proposed technique reduces number of rebroadcasts and increases node outreach both under SINR and Boolean models.1
Osama Abbas Al Tameemi, Mainak Chatterjee, Kevin A. Kwiat, Charles A. Kamhoua
ICC4
2015 An evolutionary game-theoretic framework for cyber-threat information sharing
abstract
The initiative to protect against future cyber crimes requires a collaborative effort from all types of agencies spanning industry, academia, federal institutions, and military agencies. Therefore, a Cybersecurity Information Exchange (CYBEX) framework is required to facilitate breach/patch related information sharing among the participants (firms) to combat cyber attacks. In this paper, we formulate a non-cooperative cybersecurity information sharing game that can guide: (i) the firms (players)1to independently decide whether to “participate in CYBEX and share” or not; (ii) the CYBEX framework to utilize the participation cost dynamically as incentive (to attract firms toward self-enforced sharing) and as a charge (to increase revenue). We analyze the game from an evolutionary game-theoretic strategy and determine the conditions under which the players' self-enforced evolutionary stability can be achieved. We present a distributed learning heuristic to attain the evolutionary stable strategy (ESS) under various conditions. We also show how CYBEX can wisely vary its pricing for participation to increase sharing as well as its own revenue, eventually evolving toward a win-win situation.
Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat, Andrew P. Martin
ICC3
2015 Cost-Efficient Virtual Server Provisioning and Selection in distributed Data Centers
abstract
In this paper, we study a Virtual Server Provisioning and Selection (VSPS) problem in distributed Data Centers (DCs) with the objective of minimizing the total operational cost while meeting the service response time requirement.We aim to develop general algorithms for the VSPS problem without assuming a particular queueing model for service processing in each DC. First, we present a Mixed Integer Linear Programming (MILP) formulation. Then we present a 3-step optimization framework, under which we develop a polynomial-time ln(N)-approximation algorithm (where N is the number of clients) along with a post-optimization procedure for performance improvement. We also show this problem is NP-hard to approximate and is not possible to obtain a better approximation ratio unless NP has TIME(nO(log log n)) deterministic time algorithms. In addition, we present an effective heuristic algorithm that jointly obtains the VS provisioning and selection solutions. Extensive simulation results are presented to justify effectiveness of the proposed algorithms.
Jielong Xu, Jian Tang 0008, Brendan Mumey, Weiyi Zhang 0001, Kevin A. Kwiat, Charles A. Kamhoua
ICC6
2015 Bayesian inference based decision reliability under imperfect monitoring
abstract
Reliability of a cooperative decision mechanism is critical for the proper and accurate functioning of a networked decision system. However, adversaries may choose to compromise the inputs from different sets of components that comprise the system. Often times, the monitoring mechanisms fail to accurately detect compromised inputs; hence cannot categorize all inputs into polarized decisions: compromised or not compromised. In this paper, we propose a Bayesian inference model based on multinomial evidence to quantify reliability for a cooperative decision process as a function of beliefs associated with observations from the imperfect monitoring mechanism. We propose two reliability models: an optimistic one for a normal system and a conservative one for a mission critical system. We also provide an entropy measure that reflects the certainty or uncertainty on the calculated reliability of the decision process. Through simulation, we show how the reliability and its corresponding entropy changes as the accuracy of the underlying monitoring mechanism improves1.
Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat, Charles A. Kamhoua
IM4
2015 Multi-level VM replication based survivability for mission-critical cloud computing
abstract
The elasticity and economics of cloud computing offer significant benefits to mission-critical applications which are increasingly complex and resource demanding. Cloud systems also provide powerful tools such as virtual machine (VM) based replication for defending mission-critical applications. However, cloud-based mission-critical computing raises serious challenges to mission assurance. VM-based consolidation brings different applications to the same set of physical resources, increasing the risk of one user compromising the mission of another. The mission-critical application in a VM lacks the visibility and control to detect and stop outside malicious attacks, whereas the support for security isolation from existing cloud systems is also limited. The objective of the research presented in this paper is to address these challenges and improve the survivability of mission-critical applications through the novel use of VM replication. Specifically, this paper presents a new multi-level VM replication approach which uses different types of VM clones to provide a variety of protections to mission-critical applications, and improve the survivability of the applications under accidental faults and malicious attacks. In this approach, full VM clones are employed to provide tolerance of attacks, decoy clones are created to divert attacks, and honeypot clones are used to analyze attacks. The paper also presents the prototypes of the proposed approach implemented for the widely used OpenStack-based private cloud systems and Amazon-EC2-based public cloud systems.
Francois D'Ugard, Kevin A. Kwiat, Charles A. Kamhoua
IM4
2014 Game Theoretic Modeling of Security and Interdependency in a Public Cloud
abstract
As cloud computing thrives, many small organizations are joining a public cloud to take advantage of its multiple benefits. Cloud computing is cost efficient, i.e., cloud user can reduce spending on technology infrastructure and have easy access to their information without up-front or long-term commitment of resources. Moreover, a cloud user can dynamically grow and shrink the resources provisioned to an application on demand. Despite those benefits, cyber security concern is the main reason many large organizations with sensitive information such as the Department of Defense have been reluctant to join a public cloud. This is because different public cloud users share a common platform such as the hypervisor. A common platform intensifies the well-known problem of cyber security interdependency. In fact, an attacker can compromise a virtual machine (VM) to launch an attack on the hypervisor which if compromised can instantly yield the compromising of all the VMs running on top of that hypervisor. Therefore, a user that does not invest in cyber security imposes a negative externality on others. This research uses the mathematical framework of game theory to analyze the cause and effect of interdependency in a public cloud platform. This work shows that there are multiple possible Nash equilibria of the public cloud security game. However, the players use a specific Nash equilibrium profile depending on the probability that the hypervisor is compromised given a successful attack on a user and the total expense required to invest in security. Finally, there is no Nash equilibrium in which all the users in a public cloud will fully invest in security.
Charles A. Kamhoua, Luke Kwiat, Kevin A. Kwiat, Joon S. Park
IEEE CLOUD1
2014 Trusted Online Social Network (OSN) services with optimal data management
Joon S. Park, Kevin A. Kwiat, Charles A. Kamhoua, Sookyung Kim
Comput. Secur.3
2013 Game theoretic attack analysis in online social network (OSN) services
abstract
In the social media era, the ever-increasing utility of Online Social Networks (OSN) services provide a variety of benefits to users, organizations, and service providers. However, OSN services also introduce new threats and privacy issues regarding the data they are dealing with. For instance, in a reliable OSN service, a user should be able to set up his desired level of information sharing and securely manage sensitive data. Currently, few approaches exist that can model OSNs for the purpose, let alone model the effects that attackers can have on these networks. In this work a novel OSN modeling approach is presented to fill the gap. This model is based on an innovative game theoretical approach and it is analyzed both from a theoretical and simulation-oriented view. The game theoretic model is implemented in order to analyze several attack scenarios. As the results show, there are several scenarios where OSN services are very vulnerable and hence more protection mechanisms should be provided in order to secure the data contained across these networks.
Joon S. Park, Charles A. Kamhoua, Kevin A. Kwiat
ASONAM3
2013 Modeling cooperative, selfish and malicious behaviors for Trajectory Privacy Preservation using Bayesian game theory
abstract
As new mobile Wireless Sensor Networks (mWSNs) for location-aware applications are emerging, trajectory privacy invasion is becoming an indispensable issue. Many promising techniques are under development. Considering the decentralized network architecture, most of Trajectory Privacy Preservation (TPP) techniques rely on the cooperation from peer nodes, cluster headers, or a third party. However, only a few works have addressed the issue of selfish behaviors in such cooperation required techniques. Nevertheless, the problem of facing selfish and compromised nodes in the noncooperative and hostile environment is rarely touched. In this paper, we apply Bayesian game theory to model cooperative, selfish and malicious behaviors of autonomous mobile nodes in decentralized mWSNs. We formulate and analyze the TPP game among peer nodes in both strategic and dynamic forms. The equilibrium strategies for users to evaluate the degree of trust in participating in in-network TPP activities are provided and analyzed in theoretical and simulation results.
Niki Pissinou, Sitthapon Pumpichet, Charles A. Kamhoua, Kevin A. Kwiat
LCN4
2012 Optimal State Management of Data Sharing in Online Social Network (OSN) Services
abstract
Although Online Social Network (OSN) services offer users a variety of benefits, they also bring new threats and privacy issues to the community. In this paper, we first define the data types in OSN services and the states of shared data with respect to Optimal, Under-shared, Over-shared, and Hybrid states. We also identify the facilitating, detracting, and preventive parameters that are responsible for the state transition of the data. We address that, in a reliable OSN service, a user should be able to set up his or her desired level of information sharing with a certain group of other users. However, it is not always clear to the ordinary users how to decide how much information they should reveal to others. Therefore, we propose an approach for helping OSN users determine their optimum levels of information sharing, taking into consideration the payoffs (potential Reward or Cost) based on the Markov decision process (MDP).
Joon S. Park, Sookyung Kim, Charles A. Kamhoua, Kevin A. Kwiat
TrustCom3
2011 Game Theoretic Modeling and Evolution of Trust in Autonomous Multi-Hop Networks: Application to Network Security and Privacy
abstract
Future applications will require autonomous devices to be interconnected to form a network. Such networks will not have a central manager; each node will manage itself and will be free to decide participation in any network function. As with traditional networks, these networks need to be secured to authenticate the nodes, prevent misuse, detect anomalies and protect user privacy. Network security and privacy protection without a central manager will be challenging. Several security mechanisms and privacy protections will require the cooperation of several nodes to defend the network from malicious attacks. We particularly investigate when for each node it is cost-effective to freely participate in the security mechanism or protect its privacy depending if that node believes or trusts that all other nodes or at least a minimum number of other nodes will do the same. In this case, each node will be involved in a trust dilemma that we will model using the mathematical framework of game theory and evolutionary game theory. The well known stag hunt game will be our basic game model. This paper will clearly present the interconnection between cooperation, trust, privacy and security in a network.
Charles A. Kamhoua, Niki Pissinou, Kia Makki
ICC1
2010 Belief-free equilibrium of packet forwarding game in ad hoc networks under imperfect monitoring
abstract
Future applications will require autonomous devices to be interconnected and form ad hoc networks. In such networks, cooperation will be the first problem to solve at all layers of the protocol stack. This paper deals with one of the basic functions of a network, namely packet forwarding. We model packet forwarding as a stochastic game in which each node monitors the behavior of its neighbors. We consider the realistic scenario when the monitoring technology used by the nodes is imperfect. In reality, there can be inconsistencies between the true action of a node and the observations of its neighbors. Therefore, in an ad hoc network, each node receives only noisy private information about the past play of its neighbors. We develop a simple one period memory strategy that constrains self-interested nodes to cooperate under noise. We use a belief-free approach. A belief-free approach delivers a tremendous computational advantage because nodes' belief about the neighbors' private history does not need to be computed. We support our results by mathematical proofs and simulations.
Charles A. Kamhoua, Niki Pissinou, Alan Busovaca, Kia Makki
IPCCC1
2010 Mitigating selfish misbehavior in multi-hop networks using stochastic game theory
abstract
Cooperation is a critical issue in autonomous multi-hop networks due to their lack of infrastructure. Each node in the network is at the same time a terminal and a router. As such, cooperation often involves forwarding packets from other nodes, which is not in the best interest of the individual node, due to the cost involved. In this paper, we propose Punish Only n Times (PONT): A distributed algorithm based on stochastic game theory that can force intelligent selfish autonomous nodes to cooperate without a contract in a multi-hop network.
Charles A. Kamhoua, Niki Pissinou
LCN1