EDBT 2026 Demo / reviewers in the wild / expert
Hamid Reza Shahriari
dblp:60/566
· DBLP profile ↗
20ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0002-2749-6355ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure and verifiable task matching in trustless crowdsourcing platforms
Mahdi Nikooghadam, Hamid Reza Shahriari |
Pervasive Mob. Comput. | 2 |
| 2025 | Protecting metadata privacy in blockchain-based EHR systems: A group addressing structure
Saeid Tousi Saeidi, Hamid Reza Shahriari, Mahdi Nikooghadam |
J. Inf. Secur. Appl. | 2 |
| 2025 | Lightweight secure key establishment to create a secure channel between entities in a crowdsourcing environment
Mahdi Nikooghadam, Hamid Reza Shahriari |
Pervasive Mob. Comput. | 2 |
| 2025 | Verifiable and secure data sharing in crowdsourcing-based healthcare
Mahdi Nikooghadam, Hamid Reza Shahriari |
J. Supercomput. | 2 |
| 2024 | Improving Agents Trust in Service-Oriented Environment Based on Entropy Structure and Information Ethics PrinciplesabstractRecently, information ethics has been developed as a new perspective into ethics based on informational and computational considerations. As distrust is an essentially ethical problem in informational environments, it is plausible to think of solutions for trust-related problems in the field of information ethics. This article proposes an entropy-based trust model inspired by entropy structure and information ethics principles as a solution to trust problems in service-oriented environments. The system is capable of maintaining a robust awareness of the trustworthiness of agents. Whereas most trust models are developed as problem-specific solutions, the system proposed here is directly derived from a higher order ethical/informational philosophy that makes it better fit with many problems in an informational environment. The experimental results demonstrate that the performance of the proposed system is promising in terms of trust calculation accuracy and detection of deceptive behavior as well as the adaptation speed to environmental changes. Amir Khoshkbarchi, Hamid Reza Shahriari |
Int. J. Hum. Comput. Interact. | 2 |
| 2024 | CryptojackingTrap: An Evasion Resilient Nature-Inspired Algorithm to Detect Cryptojacking MalwareabstractThe high profitability of mining cryptocurrencies mining, a computationally intensive activity, forms a fertile ecosystem that is enticing not only legitimate investors but also cyber attackers who invest their illicit computational resources in this area. Cryptojacking refers to the surreptitious exploitation of a victim’s computing resources to mine cryptocurrencies on behalf of the cyber-criminal. This malicious behavior is observed in executable files and browser executable codes, including JavaScript and Assembly modules, downloaded from websites to victims’ machines and executed. Although there are numerous botnet detection techniques to stop this malicious activity, attackers can circumvent these protections using a variety of techniques. In this paper, CryptojackingTrap is presented as a novel cryptojacking detection solution designed to resist most malware defense methods. The CryptojackingTrap is armed with a debugger and extensible cryptocurrency listeners and its algorithm is based on the execution of cryptocurrency hash functions: an indispensable behavior of all cryptojacking executors. This algorithm becomes aware of this specific hash execution by correlating the memory access traces of suspicious executables with publicly available cryptocurrency P2P network data. With the advantage of this assembly-level investigation and a natureinspired approach to triggering the detection alarm, CryptojackingTrap provides an accurate, evasion-proof technique for detecting cryptojacking. After experimental evaluation, the false negative and false positive rates are zero, and in addition, the false positive rate is mathematically calculated as 10−20. CryptojackingTrap has an open, extensible architecture and is available to the open-source community. Atefeh Zareh Chahoki, Hamid Reza Shahriari, Marco Roveri |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | REACH: Robust Efficient Authentication for Crowdsensing-based Healthcare
Mahdi Nikooghadam, Haleh Amintoosi, Hamid Reza Shahriari |
J. Supercomput. | 3 |
| 2023 | HAKECC: Highly efficient authentication and key agreement scheme based on ECDH for RFID in IOT environment
Mahdi Nikooghadam, Hamid Reza Shahriari, Saeid Tousi Saeidi |
J. Inf. Secur. Appl. | 2 |
| 2021 | Neural software vulnerability analysis using rich intermediate graph representations of programs
Seyed Mohammad Ghaffarian, Hamid Reza Shahriari |
Inf. Sci. | 2 |
| 2020 | ANOVUL: Detection of logic vulnerabilities in annotated programs via data and control flow analysisabstractLogic vulnerabilities are largely dependent on the expected functions of web applications. Their appearance depends on both application logic and related security policy which may change based on modifications in business requirements. Accordingly, there are no specific and common patterns for logic vulnerabilities moreover, a security policy is required for their detection. In this study, a vulnerability detection method is proposed to detect logic vulnerabilities via analysing the program source code. Security checks enforce some constraints in the application so that the application behaves according to the logic intended by the programmer. The main goal is to find the vulnerabilities caused by bypassing some security checks. In this method, known as annotation‐based vulnerability detection approach (ANOVUL), control and data flows are analysed to detect the application logic vulnerabilities. To analyse the flows of the program, access control and authenticity labelling are used. To evaluate ANOVUL, the authors have collected a data set. This comprises of PHP applications with reported logic vulnerabilities that have common vulnerabilities and exposures (CVE) identifiers. Based on the results, a 73% detection rate was achieved in the data set. The proposed method can detect logic vulnerabilities that are not detectable using conventional methods. Mahmoud Ghorbanzadeh, Hamid Reza Shahriari |
IET Inf. Secur. | 2 |
| 2020 | Detecting application logic vulnerabilities via finding incompatibility between application design and implementationabstractLogic vulnerabilities are due to defects in the application logic implementation such that the application logic is not the logic that was expected. Indeed, such vulnerabilities pattern depends on the design and business logic of the application. There are no specific and common patterns for application logic vulnerabilities in commercial applications. In this study, a method named FINAD is introduced to detect application logic vulnerabilities using an activity flow graph (AFG) to find the incompatibilities of an implemented application with its design. In this work, the AFG, consisting of the activity diagram (AD) and control flow graph (CFG), is presented for the first time. Investigation of different common types of application logic vulnerabilities indicated that the majority of such vulnerabilities could be detected through conducting a static analysis on an AFG. The FINAD method is independent of the language and can be used for vulnerability detection for any programming language, provided that the AD is available, and the CFG of the program can be created. Implementation of FINAD for PHP language showed its effectiveness in detecting known logic vulnerabilities in CVE vulnerability database. Mahmoud Ghorbanzadeh, Hamid Reza Shahriari |
IET Softw. | 2 |
| 2019 | Athena: A framework to automatically generate security test oracle via extracting policies from source code and intended software behaviour
Hossein Homaei, Hamid Reza Shahriari |
Inf. Softw. Technol. | 2 |
| 2018 | OPEXA: analyser assistant for detecting over-privileged extensionsabstractWeb browsers are enticing attack vectors because they provide an interface to the Internet. Extensions add capabilities to the browsers, and therefore are attractive to attackers. These capabilities are obtained through extension privileges. Some of these privileges are necessary for extensions to perform their claimed functionalities. However, an extension may have some unrequired privileges. Over‐privileged extensions may be misused to compromise systems. The authors propose an Over‐Privileged EXtension Analyser (OPEXA), to assist security experts in detecting suspicious extensions. OPEXA predicts the intended privileges of extensions based on their descriptions, which are stated by developers in natural language. They utilise this method because real users decide whether to install extensions based on descriptions. They use a supervised machine learning method to train a multi‐label classifier that predicts the desired privileges. The extension is assumed to be suspicious if there exists at least one privilege in the extension that is not considered necessary by OPEXA. They evaluate their method on two datasets that consist of real extensions developed in new and old architectures of Firefox. According to the results, they can detect all of over‐privileged extensions in these datasets. Their approach can minimise security expert's workload by automating the extension checking process. Mina Sadat Khazaei, Hossein Homaei, Hamid Reza Shahriari |
IET Inf. Secur. | 3 |
| 2011 | An Enhanced Method for Computation of Similarity between the Contexts in Trust Evaluation Using Weighted OntologyabstractIn the context-aware trust evaluation, most of the times ontology trees are employed to represent the relation among contexts. Then, the similarity between two contexts is computed according to the contexts' distance in their ontology tree. Therefore, the performance of these methods is dependent on the tree's structure and how balanced the ontology tree is constructed, which is a limitation for them. In an unbalanced ontology tree, one branch of a node is split generally while the other branch is split in more details. As a result, this unbalanced ontology tree negatively affects all computations of the mentioned methods. To overcome this limitation, we presented a weighted ontology tree, which is balanced and independent of the tree's structure. In the proposed tree, each edge is labeled with the similarity distance between its corresponding nodes. To achieve this, we used an approach, which is based on the WorldNet English lexical reference system. Finally, the similarity between two arbitrary contexts in their weighted ontology tree is computed according to their weighted similarity distance in the tree. Having the contexts similarities, trust value for a new context is computed based on the previously experienced contexts. Mohammad Amin Morid, Amin Omidvar, Hamid Reza Shahriari |
TrustCom | 3 |
| 2011 | Compositional Approach to Quantify the Vulnerability of Computer SystemsabstractAlthough analyzing complex systems could be a complicated process, current approaches to quantify system security or vulnerability usually consider the whole system as a single component. In this paper, we propose a new compositional method to evaluate the vulnerability measure of complex systems. By the word composition we mean that the vulnerability measure of a complex system can be computed using pre-calculated vulnerability measures of its components. We define compatible systems to demonstrate which components could combine. Moreover, choice, sequential, parallel and synchronized parallel composition methods are defined and the measurement of the vulnerability in each case is presented. Our method uses a state machine to model the system. The model considers unauthorized states and attacker capabilities. Furthermore, both the probability of attack and delay time to reach the target state are used to quantify vulnerability. The proposed approach would be useful to analyze complex systems which may have complicated models. This approach reduces the state space and complexity of computation. On the other hand, if a component is replaced by another one, the vulnerability measures of other components do not change. Thus, these quantities are reused in new computation. Therefore, the calculation of the vulnerability measure for a new system is simplified. Hossein Homaei, Hamid Reza Shahriari |
Comput. J. | 2 |
| 2010 | Privacy Protection of Grid Service Requesters through Distributed Attribute Based Access Control Model
Ali Esmaeeli, Hamid Reza Shahriari |
GPC | 2 |
| 2007 | Vulnerability Take Grant (VTG): An efficient approach to analyze network vulnerabilities
Hamid Reza Shahriari, Rasool Jalili |
Comput. Secur. | 1 |
| 2006 | RT-UNNID: A practical solution to real-time network-based intrusion detection using unsupervised neural networks
Morteza Amini, Rasool Jalili, Hamid Reza Shahriari |
Comput. Secur. | 3 |
| 2005 | Network Vulnerability Analysis Through Vulnerability Take-Grant Model (VTG)
Hamid Reza Shahriari, Reza Sadoddin, Rasool Jalili, Reza Zakeri, Ali Reza Omidian |
ICICS | 1 |
| 2005 | Detection of Distributed Denial of Service Attacks Using Statistical Pre-processor and Unsupervised Neural Networks
Rasool Jalili, Fatemeh Imani-Mehr, Morteza Amini, Hamid Reza Shahriari |
ISPEC | 4 |