EDBT 2026 Demo / reviewers in the wild / expert
Shamik Sural
dblp:67/3314
· DBLP profile ↗
132ranked-venue papers
10as first author
38since 2021 · last 2026
0000-0002-4315-7329ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 70 · 1 first-author · 27 since 2021Artificial intelligence and machine learning · 24 · 6 first-author · 3 since 2021Databases, data management, data science and information retrieval · 14 · 4 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 14 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 3 since 2021Systems, architecture and hardware · 6 · 1 first-authorSoftware engineering, systems software and programming languages · 6 · 5 since 2021Computer networks · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Performance Analysis of Multi-core ABAC Systems Using an M/G/m Queue Model
Hunny Chandra, Karthikeya S. M. Yelisetty, Gaurav Madkaikar, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
DBSec | 4 |
| 2026 | Integrating ABAC Into PostgreSQL: A Trusted Execution Environment Based Approach
Harshit Jain, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
DBSec | 2 |
| 2026 | Secure multi-cloud collaboration using data leakage free attribute-based access control policies
John C. John, Arobinda Gupta, Shamik Sural |
Comput. Secur. | 3 |
| 2026 | AVChain: Trusted Sharing of Autonomous Vehicle Crash Incident Data using Interoperating HyperLedger Fabric Networks and IPFSabstractAutonomous vehicles (AVs) are gaining in popularity over the years as a viable cab service apps as well as for personal use. However, incidents of crashes involving AVs continue to occur, adversely affecting their prospects for widespread acceptance by both end users and regulatory authorities. While such cases are routinely investigated, in the absence of a human to testify on what caused the crash, one has to rely solely on available data. It is therefore imperative that the data logged by AVs is accessible to the concerned parties in a trustworthy manner. In this paper, we present AVChain—a novel framework for using a permissioned blockchain like HyperLedger Fabric (HLF) to record and share AV data comprised of sensors, actuators, maps, planning algorithms and machine learning models so that the data stays immutable even in the face of cross blaming among involved parties. Since the data volume is extremely large, we appropriately compress and down sample the same before storing in a distributed file system, namely, IPFS (Inter-Planetary File System). The hashes of such IPFS data called Content Ids (CIDs) are committed to the HLF network for making them tamper proof. The HLF ledger can later be queried to obtain the CIDs, which are then further used to retrieve and un-compress the original data from IPFS. Effectiveness and usability of AVChain is demonstrated by generating AV data from CARLA, which is a widely used open source AV simulator. For sharing AV data across organizations like sensor and actuator suppliers, map service providers, machine learning model developers and law enforcement authorities, the Weaver tool has been used to make multiple HLF networks interoperate. We have also developed a web application to demonstrate the working of AVChain. Results of an extensive set of experiments establish the efficacy of our approach. Akarsh Singh, Shounak Sural, Tirthankar Sengupta, Shamik Sural |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2026 | Auditable Ledger Snapshot for Non-Repudiable Cross-Blockchain CommunicationabstractBlockchain interoperability is increasingly recognized as the centerpiece for robust interactions among decentralized services. Blockchain ledgers are generally tamper-proof and thus enforce non-repudiation for transactions recorded within the same network. However, such a guarantee does not hold for cross blockchain transactions. When disruptions occur due to malicious activities or system failures within one blockchain network, foreign networks can take advantage by denying legitimate claims or mounting fraudulent liabilities against the defenseless network. In response, this paper introduces InterSnap, a novel blockchain snapshot archival methodology, for enabling auditability of cross blockchain transactions, enforcing non-repudiation. InterSnap introduces cross-chain transaction receipts that ensure their irrefutability. Snapshots of ledger data along with these receipts are utilized as non-repudiable proof of bilateral agreements among different networks. InterSnap enhances system resilience through a distributed snapshot generation process, need-based snapshot scheduling process, and archival storage and sharing via decentralized platforms. Through a prototype implementation based on Hyperledger Fabric, we conducted experiments using on-premise machines, AWS public cloud instances, as well as a private cloud infrastructure. We establish that InterSnap can recover from malicious attacks while preserving cross chain transaction receipts. Additionally, our proposed solution demonstrates adaptability to increasing loads while securely transferring snapshot archives with minimal overhead. Tirthankar Sengupta, Bishakh Chandra Ghosh, Sandip Chakraborty 0001, Shamik Sural |
IEEE Trans. Serv. Comput. | 4 |
| 2025 | SolRPDS: A Dataset for Analyzing Rug Pulls in Solana Decentralized FinanceabstractRug pulls in Solana have caused significant damage to users interacting with Decentralized Finance (DeFi). A rug pull occurs when developers exploit users' trust and drain liquidity from token pools on Decentralized Exchanges (DEXs), leaving users with worthless tokens. Although rug pulls in Ethereum and Binance Smart Chain (BSC) have gained attention recently, analysis of rug pulls in Solana remains largely under-explored. In this paper, we introduce SolRPDS (Solana Rug Pull Dataset), the first public rug pull dataset derived from Solana's transactions. We examine approximately four years of DeFi data (2021-2024) that covers suspected and confirmed tokens exhibiting rug pull patterns. The dataset, derived from 3.69 billion transactions, consists of 62,895 suspicious liquidity pools. The data is annotated for inactivity states, which is a key indicator, and includes several detailed liquidity activities such as additions, removals, and last interaction as well as other attributes such as inactivity periods and withdrawn token amounts, to help identify suspicious behavior. Our preliminary analysis reveals clear distinctions between legitimate and fraudulent liquidity pools and we found that 22,195 tokens in the dataset exhibit rug pull patterns during the examined period. SolRPDS can support a wide range of future research on rug pulls including the development of data-driven and heuristic-based solutions for real-time rug pull detection and mitigation. Abdulrahman Alhaidari, Bhavani Kalal, Balaji Palanisamy, Shamik Sural |
CODASPY | 4 |
| 2025 | Enabling Right to be Forgotten in a Collaborative Environment Using Permissioned Blockchains
Anand Manojkumar Parikh, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
DBSec | 2 |
| 2025 | Automated Privacy Policy Analysis Using Large Language Models
Mian Yang, Vijayalakshmi Atluri, Shamik Sural, Ashish Kundu |
DBSec | 3 |
| 2025 | The Economics of Deception: Structural Patterns of Rug Pull Across DeFi Blockchains
Bhavani Kalal, Abdulrahman Alhaidari, Balaji Palanisamy, Shamik Sural |
ESORICS (4) | 4 |
| 2025 | Generation of Optimized Solidity Code for Machine Learning Models using LLMs
Sarthak Sham Nikumbh, Shamik Sural, Sandip Chakraborty 0001 |
ICBC | 2 |
| 2025 | InterAcct: Access Control for Permissioned Blockchain Interoperation
Tirthankar Sengupta, Bishakh Chandra Ghosh, Sandip Chakraborty 0001, Shamik Sural |
ICBC | 4 |
| 2025 | Heterogeneous Graph Generation: A Hierarchical Approach using Node Feature PoolingabstractHeterogeneous graphs can be used to model systems in various domains like social networks, recommendation systems and biological networks. Unlike their homogeneous counterpart, heterogeneous graphs consist of multiple types of nodes and edges, each representing different entities and relationships. Generating realistic heterogeneous graphs that capture the complex interactions among diverse entities is a difficult task, primarily because the generator has to capture both the node type distribution and the feature distribution for each node type. In this paper, we address the challenges in heterogeneous graph generation by employing a two phase hierarchical approach called HG2NP (Heterogeneous Graph Generation using Node Feature Pooling). The first phase creates a skeleton graph with node types using an existing diffusion based model. In the second phase, we employ an encoder and a sampler structure as generator to assign node type specific features to the nodes. A discriminator is used to guide the training of the generator while feature vectors are sampled from a node feature pool. We conduct extensive experiments with the well-known IMDB and DBLP datasets to show the effectiveness of our method. The need for various architectural components is established through ablation studies. Hritaban Ghosh, Changyu Chen, Arunesh Sinha, Shamik Sural |
IJCNN | 4 |
| 2025 | Extraction of Machine Enforceable ABAC Policies from Natural Language Text using LLM Knowledge DistillationabstractNatural Language Access Control Policies (NLACPs) define who can access specific information within an organization and under what conditions. While these policies are typically written in semi-formal or informal natural language, making them easily interpretable by humans, they cannot be directly enforced by access control systems. Their unstructured nature introduces ambiguities and inconsistencies, making automated extraction and translation into structured, machine-enforceable security rules a significant challenge. Mian Yang, Vijayalakshmi Atluri, Shamik Sural, Ashish Kundu |
SACMAT | 3 |
| 2025 | Performance analysis of dynamic ABAC systems using a queuing theoretic frameworkabstractA policy comprised of a set of rules forms the backbone of Attribute-based Access Control (ABAC) systems. Every incoming request is checked against such a policy and if at least one rule grants the access, it is allowed. Else, access is denied. The initial ABAC policy could be hand crafted by the security administrator or mined from a given set of authorizations using a policy engineering technique. In dynamic ABAC systems, over a period of time, additional authorizations may have to be granted or some removed as per situational changes. These changes are maintained in an auxiliary list. For access resolution, both the policy as well as the auxiliary list are considered before taking a decision. Since such a list can grow indefinitely and checking it adversely affects access resolution efficiency, periodic policy rebuilding must be done by combining the existing policy and the auxiliary list. However, regenerating the ABAC policy requires re-running computationally expensive policy mining algorithms. Further, access mediation has to be put on hold while this step is being carried out, resulting in periods of unavailability of the system. In this paper, we study the intricate problem of balancing access request resolution, accommodating dynamic authorization updates, and ABAC policy rebuilding. We employ a queuing theoretic approach where the access mediation process is modeled as an M/G/1 queue with vacation or limited service. While the server is primarily involved in resolving access requests, it occasionally goes on vacation to rebuild the ABAC policy. We study the effect of queue discipline on several performance parameters like request arrival rate, access resolution time, vacation duration and interval between vacations. Results of an extensive set of experiments provide a direction towards efficient implementation of dynamic ABAC systems. Gaurav Madkaikar, Karthikeya S. M. Yelisetty, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
Comput. Secur. | 3 |
| 2025 | Semantically Correct Policy Mining and Enforcement for Attribute Based Access ControlabstractAttribute-Based Access Control (ABAC) is increasingly becoming popular due to its dynamic, flexible, portable, and scalable nature. Under ABAC, security policies (ABAC rules) are stated in terms of the attributes of the subject, the object and the environment. A subject is granted access to an object if their respective attribute values are satisfied against a set of ABAC rules. Typically hierarchical relationships exist among the subjects as well as the objects, where more specific subjects (objects) inherit the attributes from the general ones. As such, if a subject is allowed access to a general object, that subject is allowed to access all of its sub-types. This has been the general understanding and current ABAC enforcement and policy mining approaches follow this approach. However, in this article, we argue that the general understanding of the semantics of the ABAC is not always appropriate. Indeed, under certain semantics, the specific data may be more sensitive than that of its general counterpart. In that situation, if a subject is allowed access to a general type, it should not be allowed access to its sub-type, which is contrary to the current understanding and implementation. This paper is the first attempt in the literature to distinguish these two different ABAC semantics arising from the different semantics of object attributes themselves. We present concrete examples of these two semantics and demonstrate what can go wrong - both anecdotally as well as empirically - if one ignores the underlying semantics and inappropriately uses the existing enforcement and mining algorithms. We then present how existing algorithms can be modified so that no misconfigurations arise and security is ensured. Gunjan Batra, Samir Talegaon, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
ACM Trans. Internet Techn. | 5 |
| 2024 | Towards Accurate and Stronger Local Differential Privacy for Federated Learning with Staircase Randomized ResponseabstractFederated Learning (FL), a privacy-preserving training approach, has proven to be effective, yet its vulnerability to attacks that extract information from model weights is widely recognized. To address such privacy concerns, Local Differential Privacy (LDP) has been applied to FL: perturbing the weights trained for the local model by each client. However, besides high utility loss on the randomized model weights, we identify a new inference attack to the existing LDP method, that can reconstruct the original value from the noisy values with high confidence. To mitigate these issues, in this paper, we propose the Staircase Randomized Response (SRR)-FL framework, which assigns higher probabilities to weights closer to the true weight, reducing the distance between the true and perturbed data. This minimizes the noise for maintaining the same LDP guarantee, leading to better utility. Compared to existing LDP mechanisms (e.g., Generalized Randomized Response) on the FL, SRR-FL can further provide a more accurate privacy-preserving training model, and enhance the robustness against the inference attack while ensuring the same LDP guarantee. Furthermore, we also use the parameter shuffling method for privacy amplification. The efficacy of SRR-FL has been validated on widely used datasets MNIST, Medical-MNIST and CIFAR-10, demonstrating remarkable performance. Code is available at https://github.com/matta-varun/SRR-FL. Matta Varun, Shuya Feng, Han Wang 0021, Shamik Sural, Yuan Hong 0001 |
CODASPY | 4 |
| 2024 | Incentivized Federated Learning with Local Differential Privacy Using Permissioned Blockchains
Saptarshi De Chaudhury, Likhith Reddy, Matta Varun, Tirthankar Sengupta, Sandip Chakraborty 0001, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
DBSec | 6 |
| 2024 | A Graph-Based Framework for ABAC Policy Enforcement and Analysis
Mian Yang, Vijayalakshmi Atluri, Shamik Sural, Jaideep Vaidya |
DBSec | 3 |
| 2024 | Unlocking Efficiency: Adaptive Masking for Gene Transformer ModelsabstractGene transformer models such as Nucleotide Transformer, DNABert, and LOGO are trained to learn optimal gene sequence representations by using the Masked Language Modeling (MLM) training objective over the complete Human Reference Genome. However, the typical tokenization methods employ a basic sliding window of tokens, such as k-mers, that fail to utilize gene-centric semantics. This could result in the (trivial) masking of easily predictable sequences, leading to inefficient MLM training. Time-variant training strategies are known to improve pretraining efficiency in both language and vision tasks. In this work, we focus on using curriculum masking where we systematically increase the difficulty of masked token prediction task by using a Pointwise Mutual Information-based difficulty criterion, as gene sequences lack well-defined semantic units similar to words or sentences of NLP domain. Our proposed Curriculum Masking-based Gene Masking Strategy (CM-GEMS) demonstrates superior representation learning capabilities compared to baseline masking approaches when evaluated on downstream gene sequence classification tasks. We perform extensive evaluation in both few-shot (five datasets) and full dataset settings (Genomic Understanding Evaluation benchmark consisting of 27 tasks). Our findings reveal that CM-GEMS outperforms state-of-the-art models (DNABert-2, Nucleotide transformer, DNABert) trained at 120K steps, achieving similar results in just 10K and 1K steps. We also demonstrate that Curriculum-Learned LOGO (a 2-layer DNABert-like model) can achieve nearly 90% of the state-of-the-art model performance of 120K steps. We will make the models and codes publicly available at https://github.com/roysoumya/curriculum-GeneMask. Soumyadeep Roy, Shamik Sural, Niloy Ganguly |
ECAI | 2 |
| 2024 | Queuing Theoretic Analysis of Dynamic Attribute-Based Access Control Systems
Gaurav Madkaikar, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
SEC | 2 |
| 2024 | Progress Tracking and Responding to Online Public Shaming Events on TwitterabstractOnline public shaming events on Twitter often have devastating consequences for ordinary victims. Yet, little has been explored about such events from the perspective of these victims. The research gap is starker in comparison to the related domain of corporate crisis communication, which by virtue of a prolonged interest of both the academia and the industry spanning over decades has established theories and practices for managing a crisis event. This work attempts to bridge the gap by addressing two specific questions about managing an ongoing public shaming event. First, once an event has started, can the victim estimate the progress of the event? Second, how should a victim responds—whether by tendering an apology or posting a denial, based on the current progress to restrain the shamers efficiently? We try to address these by providing a way to measure and predict the progress of an ongoing shaming event with considerable accuracy and devising a response strategy depending on the present progress. The progress is measured from the event peak making it uniform for events of different lengths and intensities. The victim’s response can be one of denial or apology. Learning from past shaming events, we recommend the best response type depending on event progress. Moreover, the entire pipeline is language-agnostic benefiting even non-English tweet shamed victims. Rajesh Basak, Shamik Sural, Soumya K. Ghosh 0001 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | Efficiently Supporting Attribute-Based Access Control in LinuxabstractLinux is a widely used multi-user operating system with applications ranging from personal desktop to commercial heavy duty web servers. It has built-in security features based on discretionary access control enforced in the form of access control lists, which can be enhanced using the Linux Security Module (LSM) Framework. LSM allows inserting security verification hooks for supporting custom security policies. However, there is no support yet for Attribute-Based Access Control (ABAC) - an access control model gaining popularity due to its dynamic nature and flexibility. In ABAC, access is granted or denied based on attributes of the subject, object and environment. In this work, we propose a method for enhancing Linux's security features by integrating ABAC for file system objects using the LSM framework. We look at various kernel and user space components and how they can be made to work together to enforce ABAC policies. Different algorithms and data structures for efficient access request resolution are also investigated. Finally, we carry out extensive performance evaluation of the ABAC-enabled Linux system and discuss its results. H. O. Sai Varshith, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | RanSAM: Randomized Search for ABAC Policy MiningabstractThis paper presents a novel approach for generating Attribute-based Access Control policies from a given Access Control Matrix (ACM). In contrast to the existing techniques for policy mining, which group the desired accesses in the ACM using certain heuristics, we pose it as a search problem in the policy space. A randomized algorithm is then used to identify the policy that best represents the given ACM. Our initial experiments show promising results. Nakul Aggarwal, Shamik Sural |
CODASPY | 2 |
| 2023 | Tool/Dataset Paper: Realistic ABAC Data Generation using Conditional Tabular GANabstractAttribute-based Access Control (ABAC) is increasingly being used in a wide variety of applications that include cloud services, IoT, smart homes, healthcare and several others. Conducting systematic and reproducible experiments with benchmark realistic datasets, however, still remains a challenge. To address this shortcoming, in this paper we introduce a method called ConGRASS (Conditional Tabular GAN for Realistic ABAC Simulation Studies) for generating large ABAC datasets. Starting with a given real world dataset of (potentially) limited size, we first train a conditional tabular generative adversarial network for learning its distribution. The trained model is used to generate realistic datasets of arbitrarily large sizes having distribution similar to the original dataset. ConGRASS has been implemented as a free to use web-based tool in which a user can choose the name of a listed real dataset along with the desired dataset size. A CSV file containing ABAC data is generated as output. Extensive evaluation shows the ability of the model to faithfully learn the statistical properties of the selected real data. When such a dataset is used in an actual problem, significant improvement in performance is achieved, proving the utility of ConGRASS. Ritwik Rai, Shamik Sural |
CODASPY | 2 |
| 2023 | Cross-chain Transfer of Snapshot Archives for Low-overhead Peer Management in Web 3.0abstractThe concept of a decentralized web has been realized with the idea of Web 3.0 through interconnecting over multiple blockchain-based networks. However, blockchain incurs significant time and space overhead. This problem can be solved using snapshots that store the blockchain’s states compactly. But, the existing snapshot mechanism used in Hyperledger Fabric is limited to siloed operations on a single blockchain only. In this paper, we contribute towards overcoming this drawback by developing a novel mechanism for peer selection, snapshot archival, and cross-blockchain sharing of the snapshot. We extend the snapshot collection mechanism in Hyperledger Fabric to implement the above idea and test it over two blockchain networks emulating a decentralized web architecture. Tirthankar Sengupta, Sandip Chakraborty 0001, Shamik Sural |
ICWS | 3 |
| 2023 | Poster: APETEEt - Secure Enforcement of ABAC Policies using Trusted Execution EnvironmentabstractWe introduce a novel framework for efficient enforcement of Attribute-Based Access Control (ABAC) policies using trusted execution environment. An ABAC policy is represented in the form of a height-balanced tree constructed and deployed in the trusted enclave. Both the policy and its enforcement are thus protected against intentional or accidental changes. The modular design of our framework enables any application to use its APIs for building secure ABAC systems. Our initial experiments show promising results. Pritkumar Godhani, Rahul Bharadhwaj, Shamik Sural |
SACMAT | 3 |
| 2023 | Guest editors' introductionabstractAdaptively Secure Attribute-Based Encryption with Outsourced Decryption" by Shamik Sural, Haibing Lu |
J. Comput. Secur. | 1 |
| 2022 | Data Leakage Free ABAC Policy Construction in Multi-Cloud CollaborationabstractWith an increase in the diversity and complexity of requirements from organizations for cloud computing, there is a growing need for integrating the services of multiple cloud providers. In such multi-cloud systems, data leakage is considered to be a major security concern, which is caused by illegitimate actions of malicious users often acting in collusion. The possibility of data leakage in such environments is characterized by the number of interoperations as well as the trustworthiness of users on the collaborating clouds. In this paper, we address the problem of secure multi-cloud collaboration from an Attribute-based Access Control (ABAC) policy management perspective. In particular, we define a problem that aims to formulate ABAC policy rules for establishing a high degree of inter-cloud accesses while eliminating potential paths for data leakage. A data leakage free ABAC policy generation algorithm is proposed that first determines the likelihood of data leakage and then attempts to maximize inter-cloud collaborations. Experimental results on several large data sets show the efficacy of the proposed approach. John C. John, Arobinda Gupta, Shamik Sural |
CLOUD | 3 |
| 2022 | Enabling Attribute-Based Access Control in Linux KernelabstractLinux has built-in security features based on discretionary access control that can be enhanced using the Linux Security Module (LSM) framework. However, so far there has been no reported work on strengthening Linux with Attribute-Based Access Control (ABAC), which is gaining in popularity in recent years due to its flexibility and dynamic nature. In this paper, a method for enabling ABAC for Linux file system objects using LSM is proposed. We report initial experimental results and also share our public repository links for integrating ABAC in any Linux installation. H. O. Sai Varshith, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
AsiaCCS | 2 |
| 2022 | Credit-based Peer-to-Peer Ride Sharing using Smart ContractsabstractExisting ride sharing services are monetary-based and are managed by centralized service providers. In this paper, we propose a decentralized non-monetary ride-sharing platform in which users interact directly with each other. Fairness is ensured through the use of credits so that a user not only enjoys rides but also offers to drive from time to time. The application is developed on the Ethereum blockchain and is designed to provide transparency and verifiability in its operations. Somay Chopra, Balaji Palanisamy, Shamik Sural |
ICBC | 3 |
| 2022 | Poster: ASQL - Attribute Based Access Control Extension for SQLabstractIn recent years, several attempts have been made to address the challenges associated with the implementation of Attribute Based Access control (ABAC). However, almost all of these look at ABAC as an application-level access control model. In this paper, we show a direction towards supporting ABAC constructs in SQL for database-level access control. Required Structured Query Language (SQL) extensions are first proposed followed by a prototype implementation for MySQL, arguably the most popular open source relational database. Our initial experiments show encouraging results. The MySQL version with ASQL support is made freely available through our GitHub repository for any interested user to download and compile for generating the enhanced instance. Proteet Paul, Shamik Sural |
SACMAT | 3 |
| 2022 | Contemporaneous Update and Enforcement of ABAC PoliciesabstractAccess control policies are dynamic in nature, and therefore require frequent updates to synchronize with the latest organizational security requirements. As these updates are handled, it is important that all user access requests be answered contemporaneously and correctly without any interruption or delay. In this paper, considering the context of Attribute Based Access Control (ABAC), we propose an approach that is capable of immediately materializing any update to the policy and ensuring that it is taken into account for any subsequent access requests. One possibility is to update the policy based on the incoming changes through ABAC policy mining techniques. However, it turns out that no existing mining approach can offer correct enforcement of policies when access requests are entertained during the updates. We provide a formal proof for this surprising result and then propose an approach called δwOP that does not suffer from this problem. Essentially, δwOP keeps track of the needed information from updates and uses this in conjunction with the existing ABAC policy rules to make access decisions. We present the complexity analysis as well as a comprehensive experimental evaluation to demonstrate the efficacy of the proposed approach for different types of changes. Samir Talegaon, Gunjan Batra, Vijayalakshmi Atluri, Shamik Sural, Jaideep Vaidya |
SACMAT | 4 |
| 2022 | Towards Supporting Attribute-Based Access Control in Hyperledger Fabric Blockchain
Amshumaan Pericherla, Proteet Paul, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
SEC | 3 |
| 2022 | A Graph Theoretic Approach for Multi-Objective Budget Constrained Capsule Wardrobe RecommendationabstractTraditionally, capsule wardrobes are manually designed by expert fashionistas through their creativity and technical prowess. The goal is to curate minimal fashion items that can be assembled into several compatible and versatile outfits. It is usually a cost and time intensive process, and hence lacks scalability. Although there are a few approaches that attempt to automate the process, they tend to ignore the price of items or shopping budget. In this article, we formulate this task as a multi-objective budget constrained capsule wardrobe recommendation ( MOBCCWR ) problem. It is modeled as a bipartite graph having two disjoint vertex sets corresponding to top-wear and bottom-wear items, respectively. An edge represents compatibility between the corresponding item pairs. The objective is to find a 1-neighbor subset of fashion items as a capsule wardrobe that jointly maximize compatibility and versatility scores by considering corresponding user-specified preference weight coefficients and an overall shopping budget as a means of achieving personalization. We study the complexity class of MOBCCWR , show that it is NP-Complete, and propose a greedy algorithm for finding a near-optimal solution in real time. We also analyze the time complexity and approximation bound for our algorithm. Experimental results show the effectiveness of the proposed approach on both real and synthetic datasets. Shubham Patil, Debopriyo Banerjee, Shamik Sural |
ACM Trans. Inf. Syst. | 3 |
| 2021 | Knowledge-Aware Neural Networks for Medical Forum Question ClassificationabstractOnline medical forums have become a predominant platform for answering health-related information needs of consumers. However, with a significant rise in the number of queries and the limited availability of experts, it is necessary to automatically classify medical queries based on a consumer's intention, so that these questions may be directed to the right set of medical experts. Here, we develop a novel medical knowledge-aware BERT-based model (MedBERT) that explicitly gives more weightage to medical concept-bearing words, and utilize domain-specific side information obtained from a popular medical knowledge base. We also contribute a multi-label dataset for the Medical Forum Question Classification (MFQC) task. MedBERT achieves state-of-the-art performance on two benchmark datasets and performs very well in low resource settings. Soumyadeep Roy, Sudip Chakraborty, Aishik Mandal, Gunjan Balde, Prakhar Sharma, Anandhavelu Natarajan, Megha Khosla, Shamik Sural, Niloy Ganguly |
CIKM | 8 |
| 2021 | Incremental Maintenance of ABAC PoliciesabstractDiscovery of Attribute Based Access Control policies through mining has been studied extensively in the literature. However, current solutions assume that the rules are to be mined from a static data set of access permissions and that this process only needs to be done once. However, in real life, access policies are dynamic in nature and may change based on the situation. Simply utilizing the current approaches would necessitate that the mining algorithm be re-executed for every update in the permissions or user/object attributes, which would be significantly inefficient. In this paper, we propose to incrementally maintain ABAC policies by only updating the rules that may be affected due to any change in the underlying access permissions or attributes. A comprehensive experimental evaluation demonstrates that the proposed incremental approach is significantly more efficient than the conventional ABAC mining. Gunjan Batra, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
CODASPY | 4 |
| 2021 | Attribute-Based Access Control for NoSQL DatabasesabstractNoSQL databases are gaining popularity in recent times for their ability to manage high volumes of unstructured data efficiently. This necessitates such databases to have strict data security mechanisms. Attribute-Based Access Control (ABAC) has been widely appreciated for its high flexibility and dynamic nature. We present an approach for integrating ABAC into NoSQL databases, specifically MongoDB, that typically only support Role-Based Access Control (RBAC). We also discuss an implementation and performance results for ABAC in MongoDB, while emphasizing that it can be extended to other NoSQL databases as well. Eeshan Gupta, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
CODASPY | 2 |
| 2021 | An Integrated Approach for Improving Brand Consistency of Web Content: Modeling, Analysis, and RecommendationabstractA consumer-dependent (business-to-consumer) organization tends to present itself as possessing a set of human qualities, which is termed the brand personality of the company. The perception is impressed upon the consumer through the content, be it in the form of advertisement, blogs, or magazines, produced by the organization. A consistent brand will generate trust and retain customers over time as they develop an affinity toward regularity and common patterns. However, maintaining a consistent messaging tone for a brand has become more challenging with the virtual explosion in the amount of content that needs to be authored and pushed to the Internet to maintain an edge in the era of digital marketing. To understand the depth of the problem, we collect around 300K web page content from around 650 companies. We develop trait-specific classification models by considering the linguistic features of the content. The classifier automatically identifies the web articles that are not consistent with the mission and vision of a company and further helps us to discover the conditions under which the consistency cannot be maintained. To address the brand inconsistency issue, we then develop a sentence ranking system that outputs the top three sentences that need to be changed for making a web article more consistent with the company’s brand personality. Soumyadeep Roy, Shamik Sural, Niyati Chhaya, Anandhavelu Natarajan, Niloy Ganguly |
ACM Trans. Web | 2 |
| 2020 | BOXREC: Recommending a Box of Preferred Outfits in Online ShoppingabstractFashionable outfits are generally created by expert fashionistas, who use their creativity and in-depth understanding of fashion to make attractive outfits. Over the past few years, automation of outfit composition has gained much attention from the research community. Most of the existing outfit recommendation systems focus on pairwise item compatibility prediction (using visual and text features) to score an outfit combination having several items, followed by recommendation of top-n outfits or a capsule wardrobe having a collection of outfits based on user’s fashion taste. However, none of these consider a user’s preference of price range for individual clothing types or an overall shopping budget for a set of items. In this article, we propose a box recommendation framework—BOXREC—which at first collects user preferences across different item types (namely, top-wear, bottom-wear, and foot-wear) including price range of each type and a maximum shopping budget for a particular shopping session. It then generates a set of preferred outfits by retrieving all types of preferred items from the database (according to user specified preferences including price ranges), creates all possible combinations of three preferred items (belonging to distinct item types), and verifies each combination using an outfit scoring framework—BOXREC-OSF. Finally, it provides a box full of fashion items, such that different combinations of the items maximize the number of outfits suitable for an occasion while satisfying maximum shopping budget. We create an extensively annotated dataset of male fashion items across various types and categories (each having associated price) and a manually annotated positive and negative formal as well as casual outfit dataset. We consider a set of recently published pairwise compatibility prediction methods as competitors of BOXREC-OSF. Empirical results show superior performance of BOXREC-OSF over the baseline methods. We found encouraging results by performing both quantitative and qualitative analysis of the recommendations produced by BOXREC. Finally, based on user feedback corresponding to the recommendations given by BOXREC, we show that disliked or unpopular items can be a part of attractive outfits. Debopriyo Banerjee, K. Sreenivasa Rao, Shamik Sural, Niloy Ganguly |
ACM Trans. Intell. Syst. Technol. | 3 |
| 2019 | ABACaaS: Attribute-Based Access Control as a ServiceabstractIn recent years, Attribute-Based Access Control (ABAC) has emerged as the desired access control model in scenarios involving sharing of resources across multiple domains. This necessitates organizations using traditional access control models to use ABAC. However, ab initio deployment of ABAC is both cost and time intensive. In this paper, we present ABACaaS - a cloud service that enables any organization to integrate ABAC into their own environment irrespective of the platform they operate in. We show both SaaS as well as PaaS instances of ABACaaS along with results on its performance. Augustee Meshram, Saptarshi Das, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
CODASPY | 3 |
| 2019 | PolTree: A Data Structure for Making Efficient Access Decisions in ABACabstractIn Attribute-Based Access Control (ABAC), a user is permitted or denied access to an object based on a set of rules (together called an ABAC Policy) specified in terms of the values of attributes of various types of entities, namely, user, object and environment. Efficient evaluation of these rules is therefore essential for ensuring decision making at on-line speed when an access request comes. Sequentially evaluating all the rules in a policy is inherently time consuming and does not scale with the size of the ABAC system or the frequency of access requests. This problem, which is quite pertinent for practical deployment of ABAC, surprisingly has not so far been addressed in the literature. In this paper, we introduce two variants of a tree data structure for representing ABAC policies, which we name as PolTree. In the binary version (B-PolTree), at each node, a decision is taken based on whether a particular attribute-value pair is satisfied or not. The n-ary version (N-PolTree), on the other hand, grows as many branches out of a given node as the total number of possible values for the attribute being checked at that node. An extensive experimental evaluation with diverse data sets shows the scalability and effectiveness of the proposed approach. Ronit Nath, Saptarshi Das, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
SACMAT | 3 |
| 2019 | Managing attribute-based access control policies in a unified framework using data warehousing and in-memory database
Mahendra Pratap Singh, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
Comput. Secur. | 2 |
| 2019 | Security analysis of ABAC under an administrative modelabstractIn the present‐day computing environment, where access control decisions are often dependent on contextual information like the location of the requesting user and the time of access request, attribute‐based access control (ABAC) has emerged as a suitable choice for expressing security policies. In an ABAC system, access decisions depend on the set of attribute values associated with the subjects, resources, and the environment in which an access request is made. In such systems, the task of managing the set of attributes associated with the entities as well as that of analysing and understanding the security implications of each attribute assignment is of paramount importance. Here, the authors first introduce a comprehensive attribute‐based administrative model, named as AMABAC ( A dministrative M odel for ABAC ), for ABAC systems and then suggest a methodology for analysing the security properties of ABAC in the presence of the administrative model. For performing analysis, the authors use μZ , a satisfiability modulo theories‐based model checking tool. The authors study the impact of the various components of ABAC and AMABAC on the time taken for security analysis. Sadhana Jha, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
IET Inf. Secur. | 2 |
| 2019 | Deploying ABAC policies using RBAC systemsabstractThe flexibility, portability and identity-less access control features of Attribute Based Access Control(ABAC) make it an attractive choice to be employed in many application domains. However, commercially viable methods for implementation of ABAC do not exist while a vast majority of organizations use Role Based Access Control (RBAC) or their temporal extensions, such as Temporal Role Based Access Control (TRBAC). In this paper, we present a solution for organizations having a RBAC/TRBAC that can deploy an ABAC policy. Essentially, we propose a method for the translation of an ABAC policy (including time constraints) into a form that can be adopted by an RBAC/TRBAC system. We experimentally demonstrate that time taken to evaluate an access request in RBAC and TRBAC systems is significantly less than that of the corresponding ABAC system. Since the cost of security management is more expensive under RBAC when compared to ABAC, we present an analysis of the different management costs and present mitigation approaches by considering various administrative operations. Gunjan Batra, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
J. Comput. Secur. | 4 |
| 2019 | Online Public Shaming on Twitter: Detection, Analysis, and MitigationabstractPublic shaming in online social networks and related online public forums like Twitter has been increasing in recent years. These events are known to have a devastating impact on the victim's social, political, and financial life. Notwithstanding its known ill effects, little has been done in popular online social media to remedy this, often by the excuse of large volume and diversity of such comments and, therefore, unfeasible number of human moderators required to achieve the task. In this paper, we automate the task of public shaming detection in Twitter from the perspective of victims and explore primarily two aspects, namely, events and shamers. Shaming tweets are categorized into six types: abusive, comparison, passing judgment, religious/ethnic, sarcasm/joke, and whataboutery, and each tweet is classified into one of these types or as nonshaming. It is observed that out of all the participating users who post comments in a particular shaming event, majority of them are likely to shame the victim. Interestingly, it is also the shamers whose follower counts increase faster than that of the nonshamers in Twitter. Finally, based on categorization and classification of shaming tweets, a web application called BlockShame has been designed and deployed for on-the-fly muting/blocking of shamers attacking a victim on the Twitter. Rajesh Basak, Shamik Sural, Niloy Ganguly, Soumya K. Ghosh 0001 |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2019 | Policy Adaptation in Hierarchical Attribute-based Access Control SystemsabstractIn Attribute-Based Access Control (ABAC), access to resources is given based on the attributes of subjects, objects, and environment. There is an imminent need for the development of efficient algorithms that enable migration to ABAC. However, existing policy mining approaches do not consider possible adaptation to the policy of a similar organization. In this article, we address the problem of automatically determining an optimal assignment of attribute values to subjects for enabling the desired accesses to be granted while minimizing the number of ABAC rules used by each subject or other appropriate metrics. We show the problem to be NP-Complete and propose a heuristic solution. Saptarshi Das, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
ACM Trans. Internet Techn. | 2 |
| 2018 | Enabling the Deployment of ABAC Policies in RBAC Systems
Gunjan Batra, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
DBSec | 4 |
| 2018 | Predicted Edit Distance Based Clustering of Gene SequencesabstractEffective mining of huge amount of DNA and RNA fragments generated by next generation sequencing (NGS) technologies is facilitated by developing efficient tools to partition these sequence fragments (reads) based on their level of similarities using edit distance. However, edit distance calculation for all pairwise sequence fragments to cluster these huge data sets is a significant performance bottleneck. In this paper we propose a predicted Edit distance based clustering to significantly lower clustering time. Existing clustering methods for sequence fragments, such as, k-mer based VSEARCH and Locality Sensitive Hash based LSH-Div achieve much reduced clustering time but at the cost of significantly lower cluster quality. We show, through extensive performance analysis, clustering based on this predicted Edit distance provides more than 99% accurate clusters while providing an order of magnitude faster clustering time than actual Edit distance based clustering. Sakti Pramanik, A. K. M. Tauhidul Islam, Shamik Sural |
ICDM | 3 |
| 2018 | One for the Road: Recommending Male Street Attire
Debopriyo Banerjee, Niloy Ganguly, Shamik Sural, K. Sreenivasa Rao |
PAKDD (3) | 3 |
| 2018 | Using Gini Impurity to Mine Attribute-based Access Control Policies with Environment AttributesabstractIn Attribute-based Access Control (ABAC) systems, utilizing environment attributes along with the subject and object attributes introduces a dynamic nature to the access decisions. The inclusion of environment attributes helps in achieving a more fine-grained access control. In this paper, we present an ABAC policy mining algorithm that considers the environment attributes and their associated values while forming the rules. Furthermore, we use gini impurity to form the rules. This helps to minimize the number of rules in the generated policy. The experimental evaluation shows that our approach is quite effective in practice. Saptarshi Das, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
SACMAT | 2 |
| 2018 | A side-channel attack on smartphones: Deciphering key taps using built-in microphonesabstractIn recent years, concerns are increasingly being expressed about the threats of side-channel attacks that exploit acoustic emanations from electronic as well as mechanical devices of daily use. With the increased level of sophistication in both hardware and applications that run on mobile phones, the number of possible ways in which their vulnerabilities can be exploited is also on the rise. In this article, we demonstrate a novel attack which uses the sound emanating from a tap made on the touchscreen of a smartphone to decipher the text being typed. The audio signal captured by the pair of microphones typically embedded in a smartphone is first processed to determine a candidate set of keys. Filters are employed to make this step robust against ambient noise. Natural language processing techniques are then used to estimate the most probable words and sentences that can be constructed from a sequence of taps. It is shown that using even off-the-shelf tools, the typed text including passwords can be guessed with reasonably high accuracy. Besides raising awareness about this potential side-channel attack, we identify the causes that allow it to succeed and suggest countermeasures. Haritabh Gupta, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
J. Comput. Secur. | 2 |
| 2018 | Towards designing robust CAPTCHAsabstractCAPTCHAs are reverse Turing tests that aim to distinguish between human and non-human online participants. CAPTCHAs enable site administrators to determine if a particular user is a legitimate human or a bot, and grant or deny them access to resources accordingly, thus preventing abuse of resources. However, given the incentive to break or circumvent CAPTCHAs, they must also evolve alongside advances in machine learning tools and techniques to continue providing security for online services. In this paper, we present the essential design criteria for building robust CAPTCHAs and thus provide a general framework for evaluating a specific CAPTCHA design. We then develop several new CAPTCHA exemplars, and analyze them from this perspective to show how design decisions impact different evaluation parameters. We also provide an overview of a new security method that can be applied to any image CAPTCHA and present the results of the evaluation of one of the most promising image based CAPTCHAs with a comprehensive user study. David Lorenzi, Emre Uzun, Jaideep Vaidya, Shamik Sural, Vijayalakshmi Atluri |
J. Comput. Secur. | 4 |
| 2018 | Specification and Verification of Separation of Duty Constraints in Attribute-Based Access ControlabstractConstraints form an important aspect of any access control system and are often regarded as one of the principle motivations behind developing different access control models. The two primary concerns related to a constraint are its specification and enforcement. Among the various types of constraints, enforcement of the Separation of Duty (SoD) constraint is considered to be the most important in commercial applications. In this paper, we introduce the problem of SoD specification, verification, and enforcement in attribute-based access control (ABAC) systems. We then demonstrate the effect of modifications in the different components of ABAC on enforcement. We also analyze the complexity of the enforcement problem and provide a methodology for solving it. Experiments on a wide range of data sets show encouraging results. Sadhana Jha, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | EditorialabstractI am very happy to report that TSC has gained an Impact Factor (IF) of 3.520 and the 5-year IF of 4.245, both of which represent significant increases from the previous years. This further speaks to the global reputation of the journal and the amazing work done by the past EICs, all the current and past EB members, and reviewers - all of whom have volunteered their precious time despite their very busy schedule to support and contribute to the growth of this journal. I hope to count on your continued engagement for the future growth of this journal. Over this past year, several esteemed EB members have completed their terms of service to TSC after serving for several years. On behalf of the Services Computing community and the TSC EAB, I would like to thank the following Associate Editors who retired from TSC EB in 2017 for their invaluable service and contributions to the journal. Overall, I am very proud of the success that TSC has achieved in 2017. This would not have been possible without the continued support of the authors, readers, reviewers, TSC EAB, TSC EB, and the staff of IEEE and IEEE Computer Society. I look forward to exploring ways to further enhance the reputation and impact of our journal. I would love to hear your suggestions and comments, and I hope to have your continued support. Paramvir Bahl, Barbara Carminati, James Caverlee, Ing-Ray Chen, Wynne Hsu, Toru Ishida 0001, Valérie Issarny, Surya Nepal, Indrakshi Ray, Kui Ren 0001, Shamik Sural, Mei-Ling Shyu |
IEEE Trans. Serv. Comput. | 11 |
| 2017 | Optimal Rule Mining for Dynamic Authorization Management in Collaborating Clouds Using Attribute-Based Access ControlabstractApplications that span across multiple clouds are often found to be vulnerable to security threats. Such highly heterogeneous environments need a fine-grained access control mechanism like Attribute-based Access Control (ABAC) for enforcing security. A first step towards successfully deploying ABAC is to define an appropriate set of access control rules that establish the desired inter-cloud accesses. This becomes more challenging when the access requirements vary with time or the users and objects are updated quite frequently. We study the problem of formulation of an optimal set of ABAC rules for granting inter-cloud accesses in a dynamic environment. The problem being NP-Hard, we propose heuristic solutions. Extensive experiments on benchmark datasets show encouraging results. John C. John, Shamik Sural, Arobinda Gupta |
CLOUD | 2 |
| 2017 | Preventing Unauthorized Data Flows
Emre Uzun, Gennaro Parlato, Vijayalakshmi Atluri, Anna Lisa Ferrara, Jaideep Vaidya, Shamik Sural, David Lorenzi |
DBSec | 6 |
| 2017 | Poster: Constrained Policy Mining in Attribute Based Access ControlabstractIn practical access control systems, it is important to enforce an upper bound on the time taken to respond to an access request. This response time is directly influenced by the size (often called the weight) of each of the underlying access control rules. We present a constrained policy mining algorithm which takes an access control matrix as input and generates a set of attribute based access control (ABAC) rules, such that the weight of each rule is not more than a specified value and the sum of weights of all the rules is minimized. Our initial experiments show encouraging results. Mayank Gautam, Sadhana Jha, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
SACMAT | 3 |
| 2017 | EmojiTCHA: Using Emotion Recognition to Tell Computers and Humans Apart
David Lorenzi, Jaideep Vaidya, Achyuta Aich, Shamik Sural, Vijayalakshmi Atluri, Joseph Calca |
SEC | 4 |
| 2017 | Attribute-based access control management for multicloud collaborationabstractSummary Security of applications has been identified as one of the major concerns in today's multicloud collaborative environment. These applications are often bounded by the constraints of the disparate cloud domains they are deployed in. A fine‐grained access control mechanism such as attribute‐based access control (ABAC) is considered to be an appropriate choice for authorization management in this context. However, identifying a suitable set of ABAC rules, often called rule mining, is a critical step in building ABAC‐based systems. We propose 2 approaches for intercloud rule formation in ABAC. In the first approach, we consider cross domain rule mining as the problem of forming a minimal set of positive authorizations only. The second approach shows the advantage of developing deny rules along with positive authorizations in reducing the total number of rules, and hence, the response time for evaluating access requests. The problem is proved to be NP‐hard. Heuristic solutions are proposed and evaluated on benchmark datasets showing encouraging results. John C. John, Shamik Sural, Arobinda Gupta |
Concurr. Comput. Pract. Exp. | 2 |
| 2017 | Migrating from RBAC to temporal RBACabstractThe last two decades have witnessed an emergence of role‐based access control (RBAC) as the de facto standard for access control. However, for organisations already having a deployed RBAC system, in many cases it may become necessary to associate a temporal dimension with the existing access control policies due to changing organisational requirements. In such cases, migration from RBAC to a temporal extension of RBAC becomes essential. Temporal RBAC (TRBAC) is one such RBAC extension. The process of creating a set of roles for implementing a TRBAC system is known as temporal role mining . Existing temporal role mining approaches typically assume that TRBAC is being deployed from scratch and do not consider it as a migration from an existing RBAC policy. In this study, the authors propose two temporal role mining approaches that enable migration from RBAC to TRBAC. These approaches make use of conventional (non‐temporal) role mining algorithms. Apart from aiding the migration process, deriving the roles in this manner allows the flexibility of minimising any desired role mining metric. They experimentally evaluate the performance of both of the proposed approaches and show that they are both efficient and effective. Barsha Mitra, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
IET Inf. Secur. | 2 |
| 2016 | Removal of Gray Rubber StampsabstractRubber stamps often overlap with original text content of a document, and hence obscure the text regions very badly. Removal of these stamp regions becomes a necessity for successful conversion of such documents into electronic format. Stamp removal from a document becomes more difficult when they are in gray scale, or text and stamp are of the same color. In this paper, we propose a technique to remove such stamps from overlapped regions by identifying stamp regions and stamp pixels. Soumyadeep Dey, Jayanta Mukhopadhyay, Shamik Sural |
DAS | 3 |
| 2016 | Deciphering Text from Touchscreen Key Taps
Haritabh Gupta, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
DBSec | 2 |
| 2016 | Authorization Management in Multi-cloud Collaboration Using Attribute-Based Access ControlabstractSecurity in multi-cloud collaborative environment requires a fine-grained access control mechanism. Attribute Based Access Control (ABAC) is considered to be a suitable choice in such situations. However, identification of a correct set of ABAC rules is a crucial step in establishing secure collaborations among multiple clouds. In this paper, we formally define cross-domain rule mining as the problem of finding a minimal set of ABAC rules that allow access to the resources of one cloud by the users of another cloud. The problem is shown to be NP-Hard and a heuristic algorithm is proposed to solve it. Experiments on an extensive set of benchmark and synthetic data show encouraging results. John C. John, Shamik Sural, Arobinda Gupta |
ISPDC | 2 |
| 2016 | Mining temporal roles using many-valued concepts
Barsha Mitra, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
Comput. Secur. | 2 |
| 2016 | Consensus-based clustering for document image segmentation
Soumyadeep Dey, Jayanta Mukhopadhyay, Shamik Sural |
Int. J. Document Anal. Recognit. | 3 |
| 2015 | Migrating from DAC to RBAC
Emre Uzun, David Lorenzi, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
DBSec | 5 |
| 2015 | Text-graphics separation to detect logo and stamp from color document images: A spectral approachabstractText and graphics separation is an important task in the field of document image processing. This work aims at detecting graphics such as logos and stamps in a scanned document image. A novel spectral filtering based text-graphics separation algorithm (SFTGS) is presented here. The property of text that it is the major source of high spatial frequency components in a document image, is exploited in this algorithm. Accordingly high frequency filtering is used to separate the text symbols. This is followed by a segmentation process for delineating residual text and the graphics. The main advantage of SFTGS is that it works in a single pass, and can discriminate graphics and text without supervised training. Subsequently, the graphics segments are further categorized into two different classes, namely logos and stamps. In this case, we assume that these are the two classes of graphical objects present in the documents. The technique is evaluated using publicly available document dataset consisting of graphics as stamps and logos. The result is compared with existing approaches reported in the literature, and it is found that the proposed method performs superior to them. An overall performance of 89.1% recall and 96.9% precision is obtained for SFTGS. Amit Vijay Nandedkar, Jayanta Mukhopadhyay, Shamik Sural |
ICDAR | 3 |
| 2015 | Managing Multi-dimensional Multi-granular Security Policies Using Data Warehousing
Mahendra Pratap Singh, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya, Ussama Yaqub |
NSS | 2 |
| 2015 | Generating Secure Images for CAPTCHAs through Noise AdditionabstractAs online automation, image processing and computer vision become increasingly powerful and sophisticated, methods to secure online assets from automated attacks (bots) are required. As traditional text based CAPTCHAs become more vulnerable to attacks, new methods for ensuring a user is human must be devised. To provide a solution to this problem, we aim to reduce some of the security shortcomings in an alternative style of CAPTCHA - more specifically, the image CAPTCHA. Introducing noise helps image CAPTCHAs thwart attacks from Reverse Image Search (RIS) engines and Computer Vision (CV) attacks while still retaining enough usability to allow humans to pass challenges. We present a secure image generation method based on noise addition that can be used for image CAPTCHAs, along with 4 different styles of image CAPTCHAs to demonstrate a fully functional image CAPTCHA challenge system. David Lorenzi, Pratik Chattopadhyay, Emre Uzun, Jaideep Vaidya, Shamik Sural, Vijayalakshmi Atluri |
SACMAT | 5 |
| 2015 | Enhancing the Security of Image CAPTCHAs Through Noise Addition
David Lorenzi, Emre Uzun, Jaideep Vaidya, Shamik Sural, Vijayalakshmi Atluri |
SEC | 4 |
| 2015 | Modelling, synthesis and characterisation of occlusion in videosabstractOcclusion is one of the most challenging problems in many video processing applications such as surveillance, gait recognition, activity recognition and so on. Attempts have been made to develop algorithms for handling occlusion and evaluate their performance on various datasets. However, these studies are subjective in nature and the datasets are hardly characterised in terms of the level of occlusion, thereby precluding any form of quantitative comparison of performance. This shows a compelling need to design an explicit, unambiguous and quantitative model, which should be able to objectively represent occlusion in a video. This study proposes an occlusion model based on the position and pose uncertainties of the moving subjects in a video. The proposed occlusion model is able to characterise the level of occlusion present in a video. It is also employed to synthetically generate occlusion for walking sequences, thus providing a direction for controlled dataset generation against which human identification algorithms can be tested. Given an input video with a subject moving without any occlusion, a particle swarm optimisation‐based parameter estimation methodology is presented that generates the desired level of occlusion. The proposed approaches have been tested on the TUM‐IITKGP and PETS2010 datasets. Finally, as an application, the occlusion model has been used to generate an occluded gait datasets and the performances of different gait recognition algorithms have been compared under varying levels of occlusion. Pratik Chattopadhyay, Shamik Sural, Jayanta Mukhopadhyay, Gerhard Rigoll |
IET Comput. Vis. | 3 |
| 2015 | Information fusion from multiple cameras for gait-based re-identification and recognitionabstractIn this study, the authors present a fully automated frontal (i.e. employing front and back views only) gait recognition approach using the depth information captured by multiple Kinect RGB‐D cameras. Limited depth sensing range restricts each of these Kinects to record only a part of a complete gait cycle of a walking subject. Hence, information from more than one Kinect is fused together to examine which features of a gait cycle can be conveniently extracted from the sequences captured independently by these cameras. To achieve this, it is imperative that the same subject be re‐identified as he moves from the field of view of one camera to another. The authors use a set of soft‐biometric features computed from the skeleton stream provided by Kinect software development kit) for doing automatic re‐identification. To enable such information fusion and also to handle missing components even after re‐identification, features are extracted at the granularity of small fractions of a gait cycle. Experiments carried out on a data set with gait videos captured by Kinects respectively from the back and front views show promising results. Pratik Chattopadhyay, Shamik Sural, Jayanta Mukhopadhyay |
IET Image Process. | 2 |
| 2015 | The generalized temporal role mining problemabstractRole mining, the process of deriving a set of roles from the available user-permission assignments, is considered to be an essential step in successful implementation of Role-Based Access Control (RBAC) systems. Traditional role mining techniques, however, are not equipped to handle temporal extensions of RBAC like the Temporal-RBAC (TRBAC) model. In this paper, we formally define the problem of finding a minimal set of roles from temporal user-permission assignments, such that in the resulting TRBAC system, users acquire either the same or a subset of the permissions originally assigned to them for the complete or partial durations of time as specified in the input. We show that the problem is NP-complete and propose a greedy algorithm for solving it. Our algorithm first derives a set of candidate roles from the temporal user-permission assignments and then selects the least possible number of roles from the candidate role set. The final output consists of a set of roles, a user-to-role assignment relation, a role-to-permission assignment relation and a role enabling base describing the time durations for which each role is enabled. Performance of the proposed approach has been evaluated on a number of synthetic as well as real-world datasets. Barsha Mitra, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
J. Comput. Secur. | 2 |
| 2015 | Frontal gait recognition from occluded scenes
Pratik Chattopadhyay, Shamik Sural, Jayanta Mukhopadhyay |
Pattern Recognit. Lett. | 2 |
| 2015 | Meeting Cardinality Constraints in Role MiningabstractRole mining is a critical step for organizations that migrate from traditional access control mechanisms to role based access control (RBAC). Additional constraints may be imposed while generating roles from a given user-permission assignment relation. In this paper we consider two such constraints which are the dual of each other. A role-usage cardinality constraint limits the maximum number of roles any user can have. Its dual, the permission-distribution cardinality constraint, limits the maximum number of roles to which a permission can belong. These two constraints impose mutually contradictory requirements on user to role and role to permission assignments. An attempt to satisfy one of the constraints may result in a violation of the other. We show that the constrained role mining problem is NP-Complete and present heuristic solutions. Two distinct frameworks are presented in this paper. In the first approach, roles are initially mined without taking the constraints into account. The user-role and role-permission assignments are then checked for constraint violation in a post-processing step, and appropriately re-assigned, if necessary. In the second approach, constraints are enforced during the process of role mining. The methods are first applied on problems that consider the two constraints individually, and then with both considered together. Both methods are evaluated over a number of real-world data sets. Pullamsetty Harika, Marreddy Nagajyothi, John C. John, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2014 | Security analysis of temporal RBAC under an administrative model
Sadhana Jha, Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
Comput. Secur. | 2 |
| 2014 | Security analysis for temporal role based access controlabstractProviding restrictive and secure access to resources is a challenging and socially important problem. Among the many formal security models, Role Based Access Control (RBAC) has become the norm in many of today's organizations for enforcing security. For every model, it is necessary to analyze and prove that the corresponding system is secure. Such analysis helps understand the implications of security policies and helps organizations gain confidence on the control they have on resources while providing access, and devise and maintain policies. In this paper, we consider security analysis for the Temporal RBAC (TRBAC), one of the extensions of RBAC. The TRBAC considered in this paper allows temporal restrictions on roles themselves, user-permission assignments (UA), permission-role assignments (PA), as well as role hierarchies (RH). Towards this end, we first propose a suitable administrative model that governs changes to temporal policies. Then we propose our security analysis strategy, that essentially decomposes the temporal security analysis problem into smaller and more manageable RBAC security analysis sub-problems for which the existing RBAC security analysis tools can be employed. We then evaluate them from a practical perspective by evaluating their performance using simulated data sets. Emre Uzun, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural, Anna Lisa Ferrara, Gennaro Parlato, P. Madhusudan |
J. Comput. Secur. | 4 |
| 2014 | Pose Depth Volume extraction from RGB-D streams for frontal gait recognition
Pratik Chattopadhyay, Shamik Sural, Jayanta Mukhopadhyay |
J. Vis. Commun. Image Represent. | 3 |
| 2014 | Frontal Gait Recognition From Incomplete Sequences Using RGB-D CameraabstractFrontal gait recognition using partial cycle information has not received significant attention to date in spite of its many potential applications. In this paper, we propose a hierarchical classification strategy that combines front and back view features captured by RGB-D (Red Green Blue - Depth) cameras. Airport security check points are considered as a typical application scenario, where two depth cameras mounted on top of a metal detector gate positioned beyond a yellow line, respectively, record front and back views of a subject as he goes through the check-in process. Due to the short distance of the surveillance zone between the yellow line and point of exit, it is often not possible to capture a full gait cycle independently from the front view or back view. An initial stage of anthropometric feature-based classification followed by motion feature extraction from the front view is used to restrict the potential set of matched subjects. A final classification is then applied on this reduced set of subjects using depth features extracted from the back view. The method is computationally efficient with a much higher rate of accuracy compared with existing gait recognition approaches. Pratik Chattopadhyay, Shamik Sural, Jayanta Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Toward Mining of Temporal Roles
Barsha Mitra, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
DBSec | 2 |
| 2013 | Analysis of TRBAC with Dynamic Temporal Role Hierarchies
Emre Uzun, Vijayalakshmi Atluri, Jaideep Vaidya, Shamik Sural |
DBSec | 4 |
| 2013 | AMTRAC: An administrative model for temporal role-based access control
Shamik Sural, Jaideep Vaidya, Vijayalakshmi Atluri |
Comput. Secur. | 2 |
| 2013 | Towards using covariance matrix pyramids as salient point descriptors in 3D point clouds
Moritz Kaiser, Xiao Xu 0001, Bogdan Kwolek, Shamik Sural, Gerhard Rigoll |
Neurocomputing | 4 |
| 2013 | Skew Correction of Document Images by Rank Analysis in Farey sequenceabstractSkew correction of a scanned document page is an important preprocessing step in document image analysis. We propose here a fast and robust skew estimation algorithm based on rank analysis in Farey sequence. Our target document class comprises two major Indian scripts with headlines, namely Devnagari and Bangla. At the beginning, straight edge segments from the edge map of the document page are detected by our algorithm using properties of digital straightness. Straight edges derived in this manner are binned by Farey ranks in correspondence with their slopes. The principal bin, identified from these bins using the strength of accumulated edge points, represents the principal direction along the direction of headlines, from which the gross skew angle is estimated. A fast refinement algorithm is then applied with a finer tuning of Farey ranks, to detect the skew up to the desired level of precision. The algorithm has been tested on a diverse set of document images, containing Bangla and Devnagari scripts. Experimental results are quite encouraging in terms of accuracy, sensitivity to non-textual objects, effectiveness in dealing with unrestricted layouts, and computational efficiency. Sanjoy Pratihar, Partha Bhowmick, Shamik Sural, Jayanta Mukhopadhyay |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2012 | Minimum user requirement in Role Based Access Control with Separation of Duty constraintsabstractConstraints, specifically Separation of Duty (SoD) constraints, constitute an essential component for specifying Role Based Access Control (RBAC) policies. While it has been shown earlier that SoD constraints can be effectively represented using a set of t - t Statically Mutually Exclusive Roles (SMER) constraints, this paper presents a method for finding minimum number of users under multiple SMER constraints. We show that one way of solving the problem is to evaluate chromatic numbers for a set of graphs. However, since exhaustive search is computationally quite expensive, we present a genetic algorithm formulation of the problem. Each chromosome is a string of positive integers within a certain range and its length equals the number of t-t SMER constraints in the system. We report our results for different values of the number of roles and the number of constraints and also for different values of t. Arindam Roy, Shamik Sural, Arun K. Majumdar |
ISDA | 2 |
| 2012 | Analyzing temporal role based access control modelsabstractToday, Role Based Access Control (RBAC) is the de facto model used for advanced access control, and is widely deployed in diverse enterprises of all sizes. Several extensions to the authorization as well as the administrative models for RBAC have been adopted in recent years. In this paper, we consider the temporal extension of RBAC (TRBAC), and develop safety analysis techniques for it. Safety analysis is essential for understanding the implications of security policies both at the stage of specification and modification. Towards this end, in this paper, we first define an administrative model for TRBAC. Our strategy for performing safety analysis is to appropriately decompose the TRBAC analysis problem into multiple subproblems similar to RBAC. Along with making the analysis simpler, this enables us to leverage and adapt existing analysis techniques developed for traditional RBAC. We have adapted and experimented with employing two state of the art analysis approaches developed for RBAC as well as tools developed for software testing. Our results show that our approach is both feasible and flexible. Emre Uzun, Vijayalakshmi Atluri, Shamik Sural, Jaideep Vaidya, Gennaro Parlato, Anna Lisa Ferrara, P. Madhusudan |
SACMAT | 3 |
| 2012 | Role Mining under Role-Usage Cardinality Constraint
John C. John, Shamik Sural, Vijayalakshmi Atluri, Jaideep Vaidya |
SEC | 2 |
| 2012 | An efficient model-guided framework for alignment of brain MR image sequencesabstractThis paper proposes a method for alignment of human brain magnetic resonance (MR) image sequences in the brain based on a 3D human brain model (triangulated mesh). The brain model is composed of four components, namely, cerebrum, cerebellum, brain stem and pituitary gland which are represented by four different colors. Synthesized image sequences (cross-sections) are extracted from the model at regular intervals for sagittal and coronal views as done in MR imaging. The cerebellums are segmented from the sequence of MR images by using the method of active contouring and their sizes are determined. The areas of the cerebellums are computed from the cross-sections using the color information. To obtain the optimal synthesized cross-section sequence corresponding to the series of MR images, an efficient dynamic programming based computational technique has been developed that uses the normalized sizes of cerebellum in both the MR image sequences and the cross-sections. Prasenjit Mondal, Jayanta Mukhopadhyay, Shamik Sural, Pinak Pani Bhattacharyya |
SMC | 3 |
| 2012 | Evaluation of segmentation techniques using region area and boundary matching information
Debi Prosad Dogra, Arun K. Majumdar, Shamik Sural |
J. Vis. Commun. Image Represent. | 3 |
| 2012 | A hierarchical method combining gait and phase of motion with spatiotemporal model for person re-identification
Shamik Sural, Jayanta Mukhopadhyay |
Pattern Recognit. Lett. | 2 |
| 2012 | Gait recognition using Pose Kinematics and Pose Energy Image
Shamik Sural, Jayanta Mukhopadhyay |
Signal Process. | 2 |
| 2011 | Security analysis of GTRBAC and its variants using model checking
Samrat Mondal, Shamik Sural, Vijayalakshmi Atluri |
Comput. Secur. | 2 |
| 2011 | A neighborhood elimination approach for block matching in motion estimation
Avishek Saha, Jayanta Mukhopadhyay, Shamik Sural |
Signal Process. Image Commun. | 3 |
| 2010 | Robust tracking of facial feature points with 3D Active Shape ModelsabstractExact 3D tracking of facial feature points is appealing for many applications in human-machine interaction. In this work a 3D Active Shape Model (ASM) that can be shifted, scaled, and rotated is used to track the points. The efficient Gauss-Newton method is applied to estimate the 3D ASM, rotation, translation, and scale parameters. If the head turns to one side, some points might be occluded but they are still considered for the estimation of the parameters. A robust error norm that reduces (or ideally cancels) the influence of occluded points is applied. With some algebraic transformations the computational cost per frame can be further reduced. The proposed algorithm is evaluated on the basis of the Airplane Behavior Corpus. Index Terms — Tracking, face recognition, minimization methods, robustness 1. Moritz Kaiser, Dejan Arsic, Shamik Sural, Gerhard Rigoll |
ICIP | 3 |
| 2010 | Toward Analyzing the Impact of Advertisement Billboards on Soccer Telecast ViewersabstractImportant soccer tournaments like the World Cup and the European Cup are broadcast to billions of people across the world. Therefore, advertising through billboards surrounding the playing arena in a soccer match is very attractive for promoting the brand image of a company. Analysis of strength and weakness of such an advertisement is helpful for the sponsors since a lot of money is spent on it and due to its potential impact on a large number of viewers at the same time. In this paper, we present a two-stage fuzzy system for analyzing the visual impact of advertisement billboards in soccer telecasts. In the first stage, visual impact of each shot is evaluated. Two parameters, namely, size and duration, of the billboards are considered in the fuzzy rules. After the shot level analysis, results are combined in the second stage to derive an overall visual impact. In both the stages, parameters of the fuzzy set membership functions are tuned using the Particle Swarm Optimization algorithm. The results have been compared against a user survey. Suprio Das, Shamik Sural, Arun K. Majumdar |
Int. J. Comput. Intell. Appl. | 2 |
| 2009 | Detection of intrusive activity in databases by combining multiple evidences and belief updateabstractAbstract — In this paper, we propose an innovative approach for database intrusion detection which combines evidences from current as well as past behavior of users. It consists of four components, namely, rule-based component, belief combination component, security sensitive history database component and Bayesian learning component. The rule-based component consists of a set of well-defined rules which give independent evidences about a transaction’s behavior. An extension of Dempster-Shafer’s theory is used to combine multiple such evidences and an initial belief is computed. First level inferences are made about the transaction depending on this initial belief. Once the transaction is found to be suspicious, belief is updated according to its similarity with malicious or genuine transaction history using Bayesian learning. Experimental evaluation shows that the proposed intrusion detection system can effectively detect intrusive attacks in databases without raising too many false alarms. Index Terms − Database security, Dempster-Shafer theory, Bayesian learning, Intrusion detection, Suspicion score Suvasini Panigrahi, Shamik Sural, Arun K. Majumdar |
CICS | 2 |
| 2009 | A Fuzzy System for Impact Analysis of Advertisement Billboards in Soccer TelecastabstractAdvertisement billboards placed along the periphery of a soccer field in popular tournaments are used to promote specific products or the brand image of a company. In this paper, we introduce a fuzzy logic based approach for estimating the visual impact of such billboards when broadcasted through the television medium. The present system estimates the persistence effect of a billboard on human mind by using a two stage fuzzy rule based system. In the first phase, a shot level analysis is carried out, which is followed by an inter shot analysis to estimate the overall impact. In both the stages, parameters of the fuzzy set membership functions are tuned using the particle swarm optimization algorithm. The system works on top of a billboard detection system and the results have been compared against a user survey. Suprio Das, Shamik Sural, Arun K. Majumdar |
ISDA | 2 |
| 2009 | Detection of Database Intrusion Using a Two-Stage Fuzzy System
Suvasini Panigrahi, Shamik Sural |
ISC | 2 |
| 2009 | Towards formal security analysis of GTRBAC using timed automataabstractAn access control system is often viewed as a state transition system. Given a set of access control policies, a general safety requirement in such a system is to determine whether a desirable property is satisfied in all the reachable states. Such an analysis calls for formal verification. While formal analysis on traditional RBAC has been done to some extent, the extensions of RBAC lack such an analysis. In this paper, we propose a formal technique to perform security analysis on the Generalized Temporal RBAC (GTRBAC) model which can be used to express a wide range of temporal constraints on different RBAC components like role, user and permission. In the proposed approach, at first the GTRBAC system is mapped to a state transition system built using timed automata. Characteristics of each role, user and permission are captured with the help of timed automata. A single global clock is used to express the various temporal constraints supported in a GTRBAC model. Next, a set of safety and liveness properties is specified using computation tree logic (CTL). Model checking based formal verification is then done to verify the properties against the model to determine if the system is secure with respect to a given set of access control policies. Both time and space analysis has been done for studying the performance of the approach under different configurations. Samrat Mondal, Shamik Sural, Vijayalakshmi Atluri |
SACMAT | 2 |
| 2009 | XML-based policy specification framework for spatiotemporal access controlabstractRole based access control (RBAC) is an established paradigm in current enterprise resource protection environment. However, with the proliferation of mobile computing, it is being frequently observed that the RBAC access decision is directly influenced by the spatiotemporal context of both the subjects and the objects in the system. Currently, there exists few models which can handle spatiotemporal security policy on top of the classical RBAC. In this paper, an XML based policy specification framework is proposed for a spatiotemporal RBAC model. The framework is built on top of a spatiotemporal RBAC model known as ESTARBAC. It incorporates different constraints such as role hierarchy, separation of duty and cardinality, along with other constraints dependent on spatiotemporal conditions. The underlying model supports spatiotemporal role and permission extents. Use of such extents allows to specify a wide variety of spatiotemporal access control policies. The framework facilitates the administration task of a large organization by providing a convenient and efficient way of managing access control policies. Samrat Mondal, Shamik Sural |
SIN | 2 |
| 2009 | Resistance Estimation for Lateral Power Arrays Through Accurate Netlist GenerationabstractEstimation of resistance of power devices has become critical for improving the efficiency of on-chip power-management circuits. In this paper, we present an efficient technique for estimation of resistance of a large lateral power-array layout along with parasitics. We extract a resistive network for metalizations utilizing the finite-element method. The method primarily benefits in terms of computational speed from reuse methodology facilitated by repetitive structure of the metal interconnect layers. Device channels are modeled by linear resistances as the power MOS operates mostly in the linear region. Since we avoid use of heuristic-based lumped models or extrapolation techniques for resistance modeling, a good level of accuracy is achieved. Suprio Das, Shamik Sural, Amit Patra |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2009 | BLAST-SSAHA Hybridization for Credit Card Fraud DetectionabstractA phenomenal growth in the number of credit card transactions, especially for online purchases, has recently led to a substantial rise in fraudulent activities. Implementation of efficient fraud detection systems has thus become imperative for all credit card issuing banks to minimize their losses. In real life, fraudulent transactions are interspersed with genuine transactions and simple pattern matching is not often sufficient to detect them accurately. Thus, there is a need for combining both anomaly detection as well as misuse detection techniques. In this paper, we propose to use two-stage sequence alignment in which a profile analyzer (PA) first determines the similarity of an incoming sequence of transactions on a given credit card with the genuine cardholder's past spending sequences. The unusual transactions traced by the profile analyzer are next passed on to a deviation analyzer (DA) for possible alignment with past fraudulent behavior. The final decision about the nature of a transaction is taken on the basis of the observations by these two analyzers. In order to achieve online response time for both PA and DA, we suggest a new approach for combining two sequence alignment algorithms BLAST and SSAHA. Amlan Kundu 0002, Suvasini Panigrahi, Shamik Sural, Arun K. Majumdar |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2008 | Security Analysis of Temporal-RBAC Using Timed AutomataabstractRole Based Access Control (RBAC) is arguably the most common access control mechanism today due to its applicability at various levels of authorization in a system. Time varying nature of access control in RBAC administered systems is often implemented through Temporal-RBAC - an extension of RBAC in the temporal domain. In this paper, we propose an initial approach towards verification of security properties of a Temporal-RBAC system. Each role is mapped to a timed automaton. A controller automaton is used to activate and deactivate various roles. Security properties are specified using Computation Tree Logic (CTL) and are verified with the help of a model checking tool named Uppaal. We have specifically considered reachability, safety and liveness properties to show the usefulness of our approach. Samrat Mondal, Shamik Sural |
IAS | 2 |
| 2008 | Spatiotemporal Connectives for Security Policy in the Presence of Location Hierarchy
Subhendu Aich, Shamik Sural, Arun K. Majumdar |
TrustBus | 2 |
| 2008 | Attack recovery from malicious transactions in distributed database systemsabstractDatabase protection mechanisms often fail to prevent occurrence of malicious transactions. In this paper, we consider the problem of database recovery from such committed malicious transactions in distributed database systems. In a database, the result of one transaction may affect the execution of some of the later transactions. This leads to damage spreading, which makes attack recovery even more complex. Traditional recovery schemes usually perform complete rollback to undo the effect of all the transactions, both malicious as well as non-malicious. We define several useful dependency relationships among transactions and present an algorithm to restore the consistency of a distributed database by negating the effect of only those transactions that are directly or transitively dependent on the malicious transactions. Anindya Chakraborty, Manoj K. Garg, Arun K. Majumdar, Shamik Sural |
Int. J. Inf. Comput. Secur. | 4 |
| 2008 | Ball detection from broadcast soccer videos using static and dynamic features
V. Pallavi, Jayanta Mukhopadhyay, Arun K. Majumdar, Shamik Sural |
J. Vis. Commun. Image Represent. | 4 |
| 2008 | Soccer video processing for the detection of advertisement billboards
Alok Watve, Shamik Sural |
Pattern Recognit. Lett. | 2 |
| 2008 | New pixel-decimation patterns for block matching in motion estimation
Avishek Saha, Jayanta Mukhopadhyay, Shamik Sural |
Signal Process. Image Commun. | 3 |
| 2008 | ANN- and PSO-Based Synthesis of On-Chip Spiral Inductors for RF ICsabstractThis paper presents an efficient layout-level synthesis approach for RF planar on-chip spiral inductors. A spiral inductor is modeled using artificial neural networks in which the layout design parameters, namely, spiral outer diameter, number of turns, width of metal traces, and metal spacing, are taken as input. Inductance, quality factor (Q), and self-resonance frequency (SRF) form the output of the neural model. Particle-swarm optimization is used to explore the layout space to achieve a given target inductance meeting the SRF and other constraints. Our synthesis approach provides multiple sets of layout parameters that help a designer in the tradeoff analysis between conflicting objectives, such as area, Q, and SRF for a target-inductance value. We present several synthesis results which show good accuracy with respect to full-wave electromagnetic (EM) simulations. Since the proposed procedure does not require an EM simulation in the synthesis loop, it substantially reduces the cycle time in RF-circuit design optimization. Sushanta K. Mandal, Shamik Sural, Amit Patra |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2008 | Credit Card Fraud Detection Using Hidden Markov ModelabstractThe Internet has taken its place beside the telephone and the television as an important part of people's lives. Consumers rely on the Internet to shop, bank and invest online. Most online shoppers use credit cards to pay for their purchases. As credit card becomes the most popular mode of payment, cases of fraud associated with it are also increasing. In this paper, we model the sequence of operations in credit card transaction processing using a Hidden Markov Model (HMM) and show how it can be used for the detection of frauds. An HMM is trained with normal behavior of cardholder. If an incoming credit card transaction is not accepted by the HMM with sufficiently high probability, it is considered to be fraudulent. We present detailed experimental results to show the effectiveness of our approach. Abhinav Srivastava, Amlan Kundu 0002, Shamik Sural, Arun K. Majumdar |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2008 | State-Based Modeling and Object Extraction From Echocardiogram VideoabstractIn this paper, we propose a hierarchical state-based model for representing an echocardiogram video. It captures the semantics of video segments from dynamic characteristics of objects present in each segment. Our objective is to provide an effective method for segmenting an echo video into view, state, and substate levels. This is motivated by the need for building efficient indexing tools to support better content management. The modeling is done using four different views, namely, short axis, long axis, apical four chamber, and apical two chamber. For view classification, an artificial neural network is trained with the histogram of a region of interest of each video frame. Object states are detected with the help of synthetic M-mode images. In contrast to traditional single M-mode, we present a novel approach named sweep M-mode for state detection. We also introduce radial M-mode for substate identification from color flow Doppler 2-D imaging. The video model described here represents the semantics of video segments using first-order predicates. Suitable operators have been defined for querying the segments. We have carried out experiments on 20 echo videos and compared the results with manual annotation done by two experts. View classification accuracy is 97.19%. Misclassification error of the state detection stage is less than 13%, which is within acceptable range since only frames at the state boundaries are found to be misclassified. Shamik Sural, Jayanta Mukhopadhyay, Arun K. Majumdar |
IEEE Trans. Inf. Technol. Biomed. | 2 |
| 2008 | Graph-Based Multiplayer Detection and Tracking in Broadcast Soccer VideosabstractIn this paper, we propose a graph-based approach for detecting and tracking multiple players in broadcast soccer videos. In the first stage, the position of the players in each frame is determined by removing the non player regions. The remaining pixels are then grouped using a region growing algorithm to identify probable player candidates. A directed weighted graph is constructed, where probable player candidates correspond to the nodes of the graph while each edge links candidates in a frame with the candidates in next two consecutive frames. Finally, dynamic programming is applied to find the trajectory of each player. Experiments with several sequences from broadcasted videos of international soccer matches indicate that the proposed approach is able to track the players reasonably well even under varied illumination and ground conditions. V. Pallavi, Jayanta Mukhopadhyay, Arun K. Majumdar, Shamik Sural |
IEEE Trans. Multim. | 4 |
| 2007 | Access Control Model for Web Services with Attribute Disclosure RestrictionabstractWeb service is a programmable interface accessible through a network. In this paper we focus on the scenario in which different organizations use Web services to collaborate, share knowledge, integrate services and for providing value added services to customers. As a test case, we consider health care application in which different hospitals can give various types of services to other hospitals. We find attribute based access control (ABAC) model to be quite suitable for access control in Web services. However, there is a need to enforce user's security policy to decide only which attributes should be disclosed so that users can reveal their attributes to service providers according to their need. We extend the ABAC model with user attribute disclosure restriction and propose a framework for defining and applying security policies Vipin Singh Mewar, Subhendu Aich, Shamik Sural |
ARES | 3 |
| 2007 | Use of Dempster-Shafer Theory and Bayesian Inferencing for Fraud Detection in Mobile Communication Networks
Suvasini Panigrahi, Amlan Kundu 0002, Shamik Sural, Arun K. Majumdar |
ACISP | 3 |
| 2007 | A Rule-Based and Game-Theoretic Approach to Online Credit Card Fraud DetectionabstractTraditional security mechanisms are often found to be inadequate for protection against attacks by authorized users or intruders posing as authorized users. This has drawn the interest of the research community towards intrusion detection techniques. We model the conflicting motives between an intruder and an intrusion detection system as a multistage game between two players, each trying to maximize its payoff. We consider the specific application of credit card fraud detection and propose a two-tiered architecture having a rule-based component in the first tier and a game-theoretic component in the second tier. Classical game theory is considered useful in many situations because it permits the formulation of strategies that are optimal, regardless of what the adversary does, negating the need for prediction of his/her behavior. However, we use it in a predictive application in the sense that we consider intruders as rational adversaries who would try to behave optimally, and the expected optimal behavior can be determined through game theory. Vishal Vatsa, Shamik Sural, Arun K. Majumdar |
Int. J. Inf. Secur. Priv. | 2 |
| 2007 | An Integrated Color and Intensity Co-occurrence Matrix
A. Vadivel 0001, Shamik Sural, Arun K. Majumdar |
Pattern Recognit. Lett. | 2 |
| 2007 | Bottom-Up Construction of Bluetooth Topology under a Traffic-Aware Scheduling SchemeabstractWe propose a Bluetooth topology construction protocol that works in conjunction with a priority-based polling scheme. A master assigns a priority to its slaves including bridges for each polling cycle and then polls them as many times as the assigned priority. The slaves can spend their idle time either in a power-saving mode or perform new node discovery. The topology construction algorithm works in a bottom-up manner in which isolated nodes join to form small piconets. These small piconets can combine to form larger piconets. Larger piconets can start sharing bridge nodes to form a scatternet. Individual piconets can also discover new nodes while participating in the master-driven polling process. The shutting down of master and slave nodes is detected for dynamic restructuring of the scatternet. The protocol can handle situations when all the Bluetooth nodes are not within radio range of each other Rajarshi Roy 0001, Mukesh Kumar 0003, Navin Kumar Sharma, Shamik Sural |
IEEE Trans. Mob. Comput. | 4 |
| 2006 | Object Tracking Using Background Subtraction and Motion Estimation in MPEG Videos
Ashwani Aggarwal, Susmit Biswas, Shamik Sural, Arun K. Majumdar |
ACCV (2) | 4 |
| 2006 | Content Based Image and Video Retrieval Using Embedded Text
Chinmaya Misra, Shamik Sural |
ACCV (2) | 2 |
| 2006 | Online Recovery of a Distributed Database from Malicious AttackabstractIn this paper, we consider the problem of recovery from committed malicious transactions in distributed databases. We define several useful dependency relations among transactions and based on them present an online recovery scheme for restoring the consistency of a database Anindya Chakraborty, Manoj K. Garg, Arun K. Majumdar, Shamik Sural |
IDEAS | 4 |
| 2006 | Weighted Intra-transactional Rule Mining for Database Intrusion Detection
Abhinav Srivastava, Shamik Sural, Arun K. Majumdar |
PAKDD | 2 |
| 2005 | A simple wide-band compact model and parameter extraction using particle swarm optimization of on-chip spiral inductors for silicon RFICsabstractWe propose a wide-band model of spiral inductor in which a resistance is incorporated in series with the overlap capacitance that estimates the underpass oxide leakage and a parallel combination of lateral substrate resistance and capacitance is introduced to model the lateral substrate coupling at high frequencies. The particle swarm optimization (PSO) algorithm is used for the extraction of the model parameters. The proposed model has been verified with the measured data of octagonal spiral inductors fabricated on a six-metal BiCMOS7 process. The model along with the PSO extraction procedure gives excellent fit when compared with the measured data over the frequency range up to 10GHz. The frequency independent elements of the model facilitate it to be integrated in a SPICE-compatible simulator. Sushanta K. Mandal, Amit Patra, Shamik Sural |
ACM Great Lakes Symposium on VLSI | 4 |
| 2004 | Dynamic Topology Construction in Bluetooth Scatternets
Rajarshi Roy 0001, Mukesh Kumar 0003, Navin Kumar Sharma, Shamik Sural |
HiPC | 4 |
| 2002 | A comparative analysis of two distance measures in color image databasesabstractThe Euclidean distance measure has been used in comparing feature vectors of images, while the cosine angle distance measure is used in document retrieval. We theoretically analyze these two distance measures based on feature vectors normalized by image size and experiment with them in the context of a color image database. We find that the cosine angle distance, in general, works equally well for image databases. We show, for a given query vector, the characteristics of feature vectors that will be favored by one measure but not by the other. We compute k-nearest neighbors for query images using both Euclidean and cosine angle distance for a small image database. The experimental data corroborate our theoretical results. Shamik Sural, Gang Qian, Sakti Pramanik |
ICIP (1) | 1 |
| 2002 | Segmentation and histogram generation using the HSV color space for image retrievalabstractWe have analyzed the properties of the HSV (hue, saturation and value) color space with emphasis on the visual perception of the variation in hue, saturation and intensity values of an image pixel. We extract pixel features by either choosing the hue or the intensity as the dominant property based on the saturation value of a pixel. The feature extraction method has been applied for both image segmentation as well as histogram generation applications - two distinct approaches to content based image retrieval (CBIR). Segmentation using this method shows better identification of objects in an image. The histogram retains a uniform color transition that enables us to do a window-based smoothing during retrieval. The results have been compared with those generated using the RGB color space. Shamik Sural, Gang Qian, Sakti Pramanik |
ICIP (2) | 1 |
| 2001 | A Genetic Algorithm for Feature Selection in a Neuro-Fuzzy OCR SystemabstractWe have worked on the development of a character recognition system in the soft computing paradigm. In this paper we present a genetic algorithm used for feature selection with a Feature Quality Index (FQI) metric. We generate feature vectors by defining fuzzy sets on Hough transform of character pattern pixels. Each feature element is multiplied by a mask vector bit before reaching the input of a multilayer perceptron (MLP). The genetic algorithm operates on the bit string represented by the mask vector to select the best set of features. The method has been tested with three benchmark data sets and the results show a fast convergence of the genetic algorithm. Shamik Sural, P. K. Das |
ICDAR | 1 |
| 2001 | Recognition of an Indian Script Using Multilayer Perceptrons and Fuzzy FeaturesabstractPresents a multi-stage character recognition system for an Indian script, namely Bengali (also called Bangla) using fuzzy features and multilayer perceptrons (MLP). The fuzzy features are extracted from the Hough transform of a character pixel pattern. We first define a number of fuzzy sets on the Hough transform accumulator cells. The fuzzy sets are then combined by t-norms to generate feature vectors from each character. A set of fuzzy linguistic vectors is next generated from these feature vectors. The MLPs used for the classification have the fuzzy features as inputs. The MLP outputs also represent the "belongingness" of an input pattern to different fuzzy character pattern classes. To improve the recognition accuracy of Bengali characters, we divide all the patterns into three distinct sets. Each set of characters is once again divided into a number of mutually exclusive character pattern classes. During recognition, the class of each pattern is first determined, followed by recognition of the actual character within that class. The recognition accuracy of the system is more than 98%. Shamik Sural, P. K. Das |
ICDAR | 1 |
| 1999 | A Two-step Algorithm and its Parallelization for the Generation of Minimum Containing Rectangles for Document Image SegmentationabstractIn document processing, segmentation is done to uniquely identify each foreground connected region of an image by specifying its minimum containing rectangle (MCR). MCR is the rectangle with minimum dimensions that completely encloses a geometric pattern. We present a two-step MCR detection algorithm and its parallelization method. The first step determines the boundary of each connected component in a document image. This reduces resource requirements and speeds up the subsequent rectangle detection step. The rectangle detection step determines MCRs of the connected components from the detected boundaries. A comparison is made between a single-step and the two-step approaches of MCR detection. Both the boundary detection and the rectangle detection steps are parallelized and implemented on transputers to reduce the total processing time. Shamik Sural, P. K. Das |
ICDAR | 1 |
| 1999 | A Two-state Markov Chain Model of Degraded Document ImagesabstractWe propose a two-state Markov chain model of degraded document images. The model generates random and burst noise to simulate isolated pixel reversal as well as blurring of a larger document region. In the random state, the probability of pixel inversion is low compared to that in the burst state. However, the model remains in the random state for a much longer period of time. Validation of the model has been done using the statistical methodology of (Kanungo et al., 1995). To estimate the parameters efficiently, we use a genetic algorithm (GA) to search through the parameter space in which the model parameter values are encoded into a concatenated bit string to form the chromosomes. We also show how the accuracy of an optical character recognition system with dictionary search varies with two derived parameters of the proposed noise model. Shamik Sural, P. K. Das |
ICDAR | 1 |
| 1999 | Fuzzy Hough transform and an MLP with fuzzy input/output for character recognition
Shamik Sural, P. K. Das |
Fuzzy Sets Syst. | 1 |
| 1999 | An MLP using Hough transform based fuzzy feature extraction for Bengali script recognition
Shamik Sural, P. K. Das |
Pattern Recognit. Lett. | 1 |
| 1997 | A document image analysis system on parallel processorsabstractThe paper presents a document image processing system implemented on a set of parallel processors. A preprocessing stage is first used to correct skew from scanned document images. The corrected image is segmented and labelled in a two-step minimum containing rectangle (MCR) detection stage. Text block filtering (TBF) is then done heuristically and the filtered blocks are submitted to a multilayer perceptron (MLP) for recognition of characters. Smoothing of the document image is done during MLP-based character recognition to reduce the preprocessing time. It also reduces the formation of merged characters, a main source of recognition errors in conventional approaches. The MLP identifies the bold words during recognition which are used for automatic indexing of documents. Data is partitioned exploiting the inherent parallelism in a document image data. Communication overhead is small compared to the computation time so that a high degree of parallelization is achieved, reducing the total execution time. Shamik Sural, P. K. Das |
HiPC | 1 |