Abdun Naser Mahmood

dblp:68/6125 · also Abdun Mahmood · DBLP profile ↗
← Back
40ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0001-7769-3384ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 2 first-author · 4 since 2021Systems, architecture and hardware · 9 · 2 since 2021Computer networks · 6 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-authorArtificial intelligence and machine learning · 5Applied, interdisciplinary, general and emerging computing · 4Software engineering, systems software and programming languages · 2 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2025 ICS-LTU2022: A dataset for ICS vulnerabilities
abstract
Industrial control systems (ICS) are a collection of control systems and associated instrumentation for controlling and monitoring industrial processes. Critical infrastructure relies on supervisory control and data acquisition (SCADA), a subset of ICS specifically designed for monitoring and controlling industrial processes over large geographic areas. Cyberattacks like the Colonial Pipeline ransomware case have demonstrated how an adversary may compromise critical infrastructure. The Colonial Pipeline ransomware attack led to a week's pipeline shutdown, causing a gas shortage in the United States. As existing vulnerability assessment tools cannot be used in the context of ICS systems, vulnerability datasets specified for ICSs are needed to evaluate the security weaknesses. Our secondary metadata, ICS-LTU2022, consists of multiple features that can be used for vulnerability assessment and risk evaluation in industrial control systems. A description of the dataset, its characteristics, and data analysis are also presented in this paper. Vulnerability analysis was conducted based on the top 10 vulnerabilities in terms of severity, frequency by year, impact, components of the ICS, and common weaknesses. The ICS-LTU2022 vulnerabilities dataset is updated biannually. Our proposed dataset provides security researchers with the most recent ICS critical vulnerabilities.
Manar Alanazi, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
Comput. Secur.2
2024 MeMalDet: A memory analysis-based malware detection framework using deep autoencoders and stacked ensemble under temporal evaluations
abstract
Malware attacks continue to evolve, making detection challenging for traditional static and dynamic analysis techniques. On the other hand, memory analysis provides valuable behavioral insights, but prior research lacks temporal evaluations which are critical for robust detection of new malware variants over time. This paper presents MeMalDet, a novel memory analysis-based malware detection technique using deep autoencoders and stacked ensemble learning. We introduce an improved dataset with temporal attributes enabling more realistic evaluations of memory-based malware detection techniques under concept drift (temporal data split). MeMalDet extracts optimal features from memory dumps using deep autoencoders in an unsupervised manner, avoiding manual feature engineering. A stacked ensemble of supervised classifiers then performs highly accurate malware detection. Extensive experiments on our improved large-scale public dataset demonstrate MeMalDet’s ability to maintain high performance when detecting obfuscated malware under temporal splits. We achieve up to 98.82% accuracy and 98.72% F1-score in detecting previously unseen advanced obfuscated malware, significantly improving upon state-of-the-art memory analysis-based malware detection techniques. The improved dataset enables temporally robust evaluations, which is a novel contribution. MeMalDet combines the benefits of representation learning and supervised machine learning ensemble classification for effective malware detection over time using memory analysis. This research provides a new capability for identifying evasive modern malware and combating evolving real-world threats.
Pascal Maniriho, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
Comput. Secur.2
2024 A systematic literature review on Windows malware detection: Techniques, research issues, and future directions
abstract
The aim of this systematic literature review (SLR) is to provide a comprehensive overview of the current state of Windows malware detection techniques, research issues, and future directions. The SLR was conducted by analyzing scientific literature on Windows malware detection based on executable files (.EXE file format) published between 2009 and 2022. The study presents new insights into the categorization of malware detection techniques based on datasets, features, machine learning and deep learning algorithms. It identifies ten experimental biases that could impact the performance of malware detection techniques. We provide insights on performance evaluation metrics and discuss several research issues that impede the effectiveness of existing techniques. The study also provides recommendations for future research directions and is a valuable resource for researchers and practitioners working in the field of Windows malware detection.
Pascal Maniriho, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
J. Syst. Softw.2
2023 SCADA vulnerabilities and attacks: A review of the state-of-the-art and open issues
abstract
Supervisory control and data acquisition (SCADA) serves as the backbone of several critical infrastructures, including water supply systems, oil pipelines, transportation and electricity. It accomplishes essential functions, such as monitoring data from pumps, valves and transmitters. Across different generations, SCADA has undergone a significant evolution from a typically isolated environment to a highly interconnected network. Although this conversion has benefits for SCADA, such as enhanced performance efficiency and the cost reduction of heavy equipment, it has made SCADA more vulnerable to various cyber-attacks. Several SCADA security approaches are still provided by IT-based systems that are possibly not efficient enough to deflect the risks and threats originating from SCADA field operations. As a result, it is critically important to analyse cyber risks associated with the industrial SCADA system. The goal of this survey is to explore the security vulnerabilities of SCADA systems and classify the threats accordingly. In this project, we initially reviewed SCADA systems from different scopes, including architecture, vulnerabilities, attacks, intrusion detection techniques (IDS) and testbeds. We proposed taxonomies of vulnerabilities, attacks, IDS and testbeds according to predefined criteria. We concluded the survey by highlighting the research challenges and open issues for future research in the field of SCADA security.
Manar Alanazi, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
Comput. Secur.2
2023 False data injection threats in active distribution systems: A comprehensive survey
Muhammad Akbar Husnoo, Adnan Anwar, Nasser Hosseinzadeh, Shama Naz Islam, Abdun Naser Mahmood, Robin Doss
Future Gener. Comput. Syst.5
2023 API-MalDetect: Automated malware detection framework for windows based on API calls and deep learning techniques
abstract
This paper presents API-MalDetect, a new deep learning-based automated framework for detecting malware attacks in Windows systems. The framework uses an NLP-based encoder for API calls and a hybrid automatic feature extractor based on convolutional neural networks (CNNs) and bidirectional gated recurrent units (BiGRU) to extract features from raw and long sequences of API calls. The proposed framework is designed to detect unseen malware attacks and prevent performance degradation over time or across different rates of exposure to malware by reducing temporal bias and spatial bias during the training and testing. Experimental results show that API-MalDetect outperforms existing state-of-the-art malware detection techniques in terms of accuracy, precision, recall, F1-score, and AUC-ROC on different benchmark datasets of API call sequences. These results demonstrate that the ability to automatically identify unique and highly relevant patterns from raw and long sequences of API calls is effective in distinguishing malware attacks from benign activities in Windows systems using the proposed API-MalDetect framework. API-MalDetect is also able to show cybersecurity experts which API calls were most important in malware identification. Furthermore, we make our dataset available to the research community.
Pascal Maniriho, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
J. Netw. Comput. Appl.2
2023 USMD: UnSupervised Misbehaviour Detection for Multi-Sensor Data
abstract
Cyber-Physical Systems (CPSs) enable Information Technology to be integrated with Operation Technology to efficiently monitor and manage the physical processes of various critical infrastructures. Recent incidents in cyber ecosystems have shown that CPSs are becoming increasingly vulnerable to complex attacks. These incidents often lead to sensing and actuation misbehaviour by illegal manipulations of data, which can severely impact the underlying physical processes of critical infrastructures. Current research acknowledges that IT-based security measures cannot entirely protect CPSs from such threats. Moreover, they are not designed to monitor the measurement level activities of physical processes, and they fail to mitigate blended cyberattacks, especially multi-stage and zero-day ones. This article addresses these limitations by proposing a framework, named UnSupervised Misbehaviour Detection (USMD), comprising a deep neural network that learns about a system's expected behaviour from data-driven representations. USMD can identify in real-time the attacks on CPSs by using the long-short term memory and Attention method for multi-sensor data. The USMD's performance is evaluated on various known data sets (i.e., ToN_IoT, SWaT, WADI and Gas pipeline datasets). The experimental results indicate that the superior performance of USMD compared with six state-of-the-art methods, which we implemented and extensively tested. USMD achieves F-scores of 0.9699 and 0.9702 on SWaT and WADI datasets, respectively.
Abdullah Alsaedi, Zahir Tari, Md. Redowan Mahmud, Nour Moustafa, Abdun Naser Mahmood, Adnan Anwar
IEEE Trans. Dependable Secur. Comput.5
2022 A study on malicious software behaviour analysis and detection techniques: Taxonomy, current trends and challenges
Pascal Maniriho, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
Future Gener. Comput. Syst.2
2020 Sub-curve HMM: A malware detection approach based on partial analysis of API call sequences
Jakapan Suaboot, Zahir Tari, Abdun Naser Mahmood, Albert Y. Zomaya, Wei Li 0058
Comput. Secur.3
2020 Firefly-inspired stochastic resonance for spectrum sensing in CR-based IoT communications
Haftu Tasew Reda, Abdun Naser Mahmood, Abebe Abeshu Diro, Naveen K. Chilamkurti, Suresh Kallam
Neural Comput. Appl.2
2020 A Spatiotemporal Data Summarization Approach for Real-Time Operation of Smart Grid
abstract
In a smart grid distribution management system, operation, planning, forecasting and decision making relies on demand-side management functions, which require real-time smart grid data. This data has significant dollar value because it is extremely useful for efficient control and intelligent prediction of the energy consumption, and expert management of residential and commercial load. However, the huge amount of (smart grid) data generated at a very high velocity poses a number of challenges. Utility companies have a huge demand for efficient summarization techniques to mine interesting patterns and extracting useful and actionable intelligence. Research from various domains has shown that data summarization can significantly improve the scalability and efficiency of various data analytic tasks (e.g., transactional database mining, data streams mining, network monitoring). This paper proposes a summarization approach (i.e., a set of algorithms, data structures, and query mechanisms) that enables the utility company to accurately infer various energy consumption patterns in real-time by automatic monitoring of smart grid data using significantly less computational resources. The proposed summarization approach is suitable for processing spatiotemporal streams, and it can also provide answers in real-time to various smart grid applications (e.g., demand-side management, direct load control, smart pricing and Volt-VAr control). Both theoretical bound and experimental evaluation are presented in this paper, which shows that the memory required for the proposed data structure grows linearly for the first 52 weeks; but interestingly, after the first year, the memory growth is negligible. The experimental results show that the proposed approach can process around 4 million smart meter readings every second or 120 million readings every minute. The proposed approach outperforms widely commercially used Database Management Systems (DBMSs) in terms of update and query costs: it is about 200 times faster than DBMSs in terms of update time, and about 340 times faster than DBMSs in terms of query time.
Zubair Shah, Adnan Anwar, Abdun Naser Mahmood, Zahir Tari, Albert Y. Zomaya
IEEE Trans. Big Data3
2020 Microaggregation Sorting Framework for K-Anonymity Statistical Disclosure Control in Cloud Computing
abstract
In cloud computing, there have led to an increase in the capability to store and record personal data (microdata) in the cloud. In most cases, data providers have no/little control that has led to concern that the personal data may be beached. Microaggregation techniques seek to protect microdata in such a way that data can be published and mined without providing any private information that can be linked to specific individuals. An optimal microaggregation method must minimize the information loss resulting from this replacement process. The challenge is how to minimize the information loss during the microaggregation process. This paper presents a sorting framework for Statistical Disclosure Control (SDC) to protect microdata in cloud computing. It consists of two stages. In the first stage, an algorithm sorts all records in a data set in a particular way to ensure that during microaggregation very dissimilar observations are never entered into the same cluster. In the second stage a microaggregation method is used to create k-anonymous clusters while minimizing the information loss. The performance of the proposed techniques is compared against the most recent microaggregation methods. Experimental results using benchmark datasets show that the proposed algorithms perform significantly better than existing associate techniques in the literature.
Md. Enamul Kabir, Abdun Naser Mahmood, Hua Wang 0002, Abdul K. Mustafa
IEEE Trans. Cloud Comput.2
2018 Computing Hierarchical Summary from Two-Dimensional Big Data Streams
abstract
There are many application domains, where hierarchical data is inherent, but surprisingly, there are few techniques for mining patterns from such important data. Hierarchical Heavy Hitters (HHH) and multilevel and Cross-Level Association Rules (CLAR) mining are well-known hierarchical pattern mining techniques. The problem in these techniques; however, is that they focus on capturing only global patterns from data but cannot identify local contextual patterns. Another problem in these techniques is that they treat all data items in the transaction equally and do not consider the sequential nature of the relationship among items within a transaction; hence, they cannot capture the correlation semantic within the transactions of the data items. There are many applications such as clickstream mining, healthcare data mining, network monitoring, and recommender systems, which require to identify local contextual patterns and correlation semantics. In this work, we introduce a new concept, which can capture the sequential nature of the relationship between pairs of hierarchical items at multiple concept levels and can capture local contextual patterns within the context of the global patterns. We call this notion Hierarchically Correlated Heavy Hitters (HCHH). Specifically, the proposed approach finds the correlation between items corresponding to hierarchically discounted frequency counts. We have provided formal definitions of the proposed concept and developed algorithmic approaches for computing HCHH in data streams efficiently. The proposed HCHH algorithm have deterministic error guarantees, and space bounds. It requires O(η/ϵpϵs) memory, where h is a small constant, and ϵp∈ [0,1], ϵs∈ [0,1] are user defined parameters on upper bounds of estimation error. We have compared the proposed HCHH concept with existing hierarchical pattern mining approaches both theoretically as well as experimentally.
Zubair Shah, Abdun Naser Mahmood, Michael Barlow 0001, Zahir Tari, Xun Yi, Albert Y. Zomaya
IEEE Trans. Parallel Distributed Syst.2
2017 Modeling and performance evaluation of stealthy false data injection attacks on smart grid in the presence of corrupted measurements
Adnan Anwar, Abdun Naser Mahmood, Mark R. Pickering
J. Comput. Syst. Sci.2
2017 Ensuring Data Integrity of OPF Module and Energy Database by Detecting Changes in Power Flow Patterns in Smart Grids
abstract
Recent studies show that smart grid is vulnerable to cyber anomalies. In this paper, an anomaly detection method is proposed to identify the abnormal patterns in the network power flows, which results from the accidental or deliberate changes of the database. The proposed method utilizes a multivariate time series statistical forecasting technique based on vector autoregressive model. To understand the power flow behavior of the system, a multiphase optimal power flow analysis is conducted. The proposed method is validated using IEEE Power Distribution System Analysis Subcommittee recommended 34-node and 123-node test systems. Three different experiments are performed to test the effectiveness of the proposed approach. Vulnerability and computational complexity issues of this paper are also addressed elaborately. Results obtained from this analysis show that the proposed method successfully captures the network anomalies at a high detection rate allowing only a few number of false alarms.
Adnan Anwar, Abdun Naser Mahmood, Zahir Tari
IEEE Trans. Ind. Informatics2
2017 A Technique for Efficient Query Estimation over Distributed Data Streams
abstract
Distributed data stream mining in a sliding window has emerged recently, due to its applications in many domains including large Telecoms and Internet Service Providers, financial tickers, ATM and credit card operations in banks and transactions in retail chains. Many of these large-scale applications prohibit monitoring data centrally at a single location due to their massive volume of the data; therefore, data acquisition, processing, and mining tasks are often distributed to a number of processing nodes, which monitor their local streams and exchange only the summary of data either periodically or on demand. While this offer many advantages, distributed stream applications possess significant challenges including problems related to an online analysis of the recent data, communication efficiency and various estimation of various complex queries. There are few existing techniques which solve problems related to distributed sliding window data stream; however, those techniques are focused on solving only simple problems and require high space, query, and communication cost, which can be a bottleneck for many of these large scale applications. In this paper, we propose an efficient query estimation technique by constructing a small sketch of the data stream. The constructed sketch uses a deterministic sliding window model and can estimate various complex queries, for both centralized and distributed applications; including point queries (i.e., range queries and heavy hitter queries), quantiles, inner product, and self-join size queries, with deterministic guarantees on the precision. The proposed approach improves upon recent existing work for these problems, in terms of the memory and query cost in a centralized setting and in terms of communication cost and merge complexity in a distributed setting. It requires O(1/ε21 log (εN)) memory (where 0 <; ε <; 1 is a user defined parameter), can provide estimates in O(1) time, and processes each incoming record in O(1) amortized time. Detailed experimental analysis, both in centralized and distributed settings demonstrates that in practice the proposed approach uses about six times less memory, and has about eight times less query time when compared to ECM sketches. In a distributed application, the proposed technique also significantly improves (around seven times) on the communication cost between distributed sites.
Zubair Shah, Abdun Naser Mahmood, Zahir Tari, Albert Y. Zomaya
IEEE Trans. Parallel Distributed Syst.2
2016 Computing Hierarchical Summary of the Data Streams
Zubair Shah, Abdun Naser Mahmood, Michael Barlow 0001
PAKDD (2)2
2016 A survey of anomaly detection techniques in financial domain
Abdun Naser Mahmood, Md. Rafiqul Islam 0001
Future Gener. Comput. Syst.2
2016 A survey of network anomaly detection techniques
Abdun Naser Mahmood, Jiankun Hu
J. Netw. Comput. Appl.2
2015 A Data-Driven Approach to Distinguish Cyber-Attacks from Physical Faults in a Smart Grid
abstract
Recently, there has been significant increase in interest on Smart Grid security. Researchers have proposed various techniques to detect cyber-attacks using sensor data. However, there has been little work to distinguish a cyber-attack from a power system physical fault. A serious operational failure in physical power grid may occur from the mitigation strategies if fault is wrongly classified as a cyber-attack or vice-versa. In this paper, we utilize a data-driven approach to accurately differentiate the physical faults from cyber-attacks. First, we create a realistic dataset by generating different types of faults and cyber-attacks on the IEEE 30 bus benchmark test system. With extensive experiments, we observe that most of the established supervised methods perform poorly for the classification of faults and cyber-attacks specially for the practical datasets. Hence, we provide a data-driven approach where labelled data are projected in a new low-dimensional subspace using Principal Component Analysis (PCA). Next, Sequential Minimal Optimization (SMO) based Support Vectors are trained using the new projection of the original dataset. With both simulated and practical datasets, we have observed that the proposed classification method outperforms other existing popular supervised classification approaches considering the cyber-attack and fault datasets.
Adnan Anwar, Abdun Naser Mahmood, Zubair Shah
CIKM2
2015 Identification of vulnerable node clusters against false data injection attack in an AMI based Smart Grid
Adnan Anwar, Abdun Naser Mahmood, Zahir Tari
Inf. Syst.2
2015 Computing discounted multidimensional hierarchical aggregates using modified Misra Gries algorithm
Zubair Shah, Abdun Naser Mahmood, Michael Barlow 0001
Perform. Evaluation2
2014 A summarization paradigm for big data
abstract
We have developed an efficient summarization paradigm for data drawn from hierarchical domain to construct a succinct view of important large-valued regions (“heavy hitters”). It requires one pass over the data with moderate number of updates per element of the data and requires lesser amount of memory space as compared to existing approaches for approximating hierarchically discounted frequency counts of heavy hitters with provable guarantees. The proposed technique is generic that can make use of existing state-of-the-art sketch-based or count-based frequency estimation approaches. Any algorithm from both of these families can be coupled as a subroutine in the proposed framework without any substantial modifications. Experimental as well as theoretical justifications have been provided for its significance.
Zubair Shah, Abdun Naser Mahmood
IEEE BigData2
2014 Network Traffic Pattern Analysis Using Improved Information Theoretic Co-clustering Based Collective Anomaly Detection
Abdun Naser Mahmood
SecureComm (2)2
2014 False Data Injection Attack Targeting the LTC Transformers to Disrupt Smart Grid Operation
Adnan Anwar, Abdun Naser Mahmood
SecureComm (2)2
2014 Novel Iterative Min-Max Clustering to Minimize Information Loss in Statistical Disclosure Control
Abdun Naser Mahmood, Md. Enamul Kabir, Abdul K. Mustafa
SecureComm (2)1
2014 Forensic Potentials of Solid State Drives
Zubair Shah, Abdun Naser Mahmood, Jill Slay
SecureComm (2)2
2014 PPFSCADA: Privacy preserving framework for SCADA data publishing
Adil Fahad, Zahir Tari, Abdulmohsen Almalawi, Andrzej M. Goscinski, Ibrahim Khalil 0001, Abdun Naser Mahmood
Future Gener. Comput. Syst.6
2014 Predicting dependences using domain-based coupling
abstract
SUMMARY Software dependences play a vital role in programme comprehension, change impact analysis and other software maintenance activities. Traditionally, these activities are supported by source code analysis; however, the source code is sometimes inaccessible or difficult to analyse, as in hybrid systems composed of source code in multiple languages using various paradigms (e.g. object‐oriented programming and relational databases). Moreover, not all stakeholders have adequate knowledge to perform such analyses. For example, non‐technical domain experts and consultants raise most maintenance requests; however, they cannot predict the cost and impact of the requested changes without the support of the developers. We propose a novel approach to predicting software dependences by exploiting the coupling present in domain‐level information. Our approach is independent of the software implementation; hence, it can be used to approximate architectural dependences without access to the source code or the database. As such, it can be applied to hybrid systems with heterogeneous source code or legacy systems with missing source code. In addition, this approach is based solely on information visible and understandable to domain users; therefore, it can be efficiently used by domain experts without the support of software developers. We evaluate our approach with a case study on a large‐scale enterprise system, in which we demonstrate how up to 65% of the source code dependences and 77% of the database dependences are predicted solely based on domain information. Copyright © 2013 John Wiley & Sons, Ltd.
Amir Aryani, Fabrizio Perin, Mircea Lungu, Abdun Naser Mahmood, Oscar Nierstrasz
J. Softw. Evol. Process.4
2013 Software Clustering Using Automated Feature Subset Selection
Zubair Shah, Rashid Naseem, Mehmet A. Orgun, Abdun Naser Mahmood, Sara Shahzad
ADMA (2)4
2013 A Probabilistic Model to Predict the Survivability of SCADA Systems
abstract
Recent spate of cyber attacks against critical infrastructure systems, which are vital to society, have shown that in addition to be infeasible to stop every possible attack it is imperative to keep such systems running. Survivability models and tools are good to evaluate system's capacity to handling undesired events. Current survivability measurement techniques are limited, since they only use performance to model system behaviour, and do not take into account service interdependencies. This paper introduces a probabilistic model that offers a new direction in measuring survivability. The proposed model solves the issues with current models by combining the formalism of Bayesian networks with information diversity. Service interdependencies are properly taken into account and the information diversity metric is used to represent service behaviour. In addition, the model is evaluated through a simulation of a SCADA system, where the entire process to construct and to use the model is detailed.
Carlos Queiroz, Abdun Naser Mahmood, Zahir Tari
IEEE Trans. Ind. Informatics2
2012 New Multi-dimensional Sorting Based K-Anonymity Microaggregation for Statistical Disclosure Control
Abdun Naser Mahmood, Md. Enamul Kabir, Abdul K. Mustafa
SecureComm1
2011 A clustering based system for instant detection of cardiac abnormalities from compressed ECG
Fahim K. Sufi, Ibrahim Khalil 0001, Abdun Naser Mahmood
Expert Syst. Appl.3
2011 Seamless integration of dependability and security concepts in SOA: A feedback control system based framework and taxonomy
Jiankun Hu, Ibrahim Khalil 0001, Song Han 0004, Abdun Naser Mahmood
J. Netw. Comput. Appl.4
2010 Survivable SCADA Systems: An Analytical Framework Using Performance Modelling
abstract
Supervisory Control and Data Acquisition (SCADA) systems control and monitor industrial and critical infrastructure functions, such as the electricity, gas, water, waste, railway and traffic. Recently, SCADA systems have been targeted by an increasing number of attacks from the Internet due to its grow- ing connectivity to Enterprise networks. Traditional techniques and models of identifying attacks, and quantifying its impact cannot be directly applied to SCADA systems because of their limited resources and real-time operating characteristics. The paper introduces a novel framework for evaluating survivability of SCADA systems from a service-oriented perspective. The framework uses an analytical model to evaluate the status of services performance and the survivability of the overall system using queuing theory and Bayesian networks. We further discuss how to learn from historical or simulated data automatically for building the conditional probability tables and the Bayesian networks.
Carlos Queiroz, Abdun Naser Mahmood, Zahir Tari
GLOBECOM2
2010 Critical infrastructure protection: Resource efficient sampling to improve detection of less frequent patterns in network traffic
Abdun Naser Mahmood, Jiankun Hu, Zahir Tari, Christopher Leckie
J. Netw. Comput. Appl.1
2009 Building a SCADA Security Testbed
abstract
SCADA (supervisory control and data acquisition) systems control and monitor industrial and critical infrastructure functions, such as the electricity, gas, water, waste, railway and traffic. Recent attacks on SCADA systems highlight the need of a SCADA security testbed, which can be used to model real SCADA systems and study the effects of attacks on them. We propose the architecture of a modular SCADA testbed and describe our tool which mimics a SCADA network, monitors and controls real sensors and actuators using Modbus/TCP protocol. Using distributed denial of service (DDoS) scenarios we show how attackers can disrupt the operation of a SCADA system.
Carlos Queiroz, Abdun Naser Mahmood, Jiankun Hu, Zahir Tari, Xinghuo Yu 0001
NSS2
2009 Spam filtering for network traffic security on a multi-core environment
abstract
Abstract This paper presents an innovative fusion‐based multi‐classifier e‐mail classification on a ubiquitous multi‐core architecture. Many previous approaches used text‐based single classifiers to identify spam messages from a large e‐mail corpus with some amount of false positive tradeoffs. Researchers are trying to prevent false positive in their filtering methods, but so far none of the current research has claimed zero false positive results. In e‐mail classification false positive can potentially cause serious problems for the user. In this paper, we use fusion‐based multi‐classifier classification technique in a multi‐core framework. By running each classifier process in parallel within their dedicated core, we greatly improve the performance of our multi‐classifier‐based filtering system in terms of running time, false positive rate, and filtering accuracy. Our proposed architecture also provides a safeguard of user mailbox from different malicious attacks. Our experimental results show that we achieved an average of 30% speedup at an average cost of 1.4 ms. We also reduced the instances of false positives, which are one of the key challenges in a spam filtering system, and increases e‐mail classification accuracy substantially compared with single classification techniques. Copyright © 2009 John Wiley & Sons, Ltd.
Md. Rafiqul Islam 0001, Wanlei Zhou 0001, Yang Xiang 0001, Abdun Naser Mahmood
Concurr. Comput. Pract. Exp.4
2008 An Efficient Clustering Scheme to Exploit Hierarchical Data in Network Traffic Analysis
abstract
There is significant interest in the data mining and network management communities about the need to improve existing techniques for clustering multivariate network traffic flow records so that we can quickly infer underlying traffic patterns. In this paper, we investigate the use of clustering techniques to identify interesting traffic patterns from network traffic data in an efficient manner. We develop a framework to deal with mixed type attributes including numerical, categorical, and hierarchical attributes for a one-pass hierarchical clustering algorithm. We demonstrate the improved accuracy and efficiency of our approach in comparison to previous work on clustering network traffic.
Abdun Naser Mahmood, Christopher Leckie, Parampalli Udaya
IEEE Trans. Knowl. Data Eng.1
2006 Echidna: Efficient Clustering of Hierarchical Data for Network Traffic Analysis
Abdun Naser Mahmood, Christopher Leckie, Parampalli Udaya
Networking1