Rasool Jalili

dblp:74/5118 · DBLP profile ↗
← Back
34ranked-venue papers
1as first author
6since 2021 · last 2024
0000-0002-9853-1955ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 2Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2024 HODA: Hardness-Oriented Detection of Model Extraction Attacks
abstract
Model extraction attacks exploit the target model’s prediction API to create a surrogate model, allowing the adversary to steal or reconnoiter the functionality of the target model in the black-box setting. Several recent studies have shown that a data-limited adversaries with no or limited access to the samples from the target model’s training data distribution, can employ synthesized or semantically similar samples to conduct model extraction attacks. In this paper, we introduce the concept of hardness degree to characterize sample difficulty based on the concept of learning speed. The hardness degree of a sample depends on the epoch number at which the predicted label for that sample converges. We investigate the hardness degree of samples and demonstrate that the hardness degree histogram of a data-limited adversary’s sample sequence is differs significantly from that of benign users’ sample sequences. We propose Hardness-Oriented Detection Approach (HODA) to detect the sample sequences of model extraction attacks. Our results indicate that HODA can effectively detect model extraction attack sequences with a high success rate, using only 100 monitored samples. It outperforms all previously proposed methods for model extraction detection.
Amir Mahdi Sadeghzadeh, Amir Mohammad Sobhanian, Faezeh Dehghan, Rasool Jalili
IEEE Trans. Inf. Forensics Secur.4
2023 GraphOS: Towards Oblivious Graph Processing
abstract
We propose GraphOS, a system that allows a client that owns a graph database to outsource it to an untrusted server for storage and querying. It relies on doubly-oblivious primitives and trusted hardware to achieve a very strong privacy and efficiency notion which we call oblivious graph processing : the server learns nothing besides the number of graph vertexes and edges, and for each query its type and response size. At a technical level, GraphOS stores the graph on a doubly-oblivious data structure , so that all vertex/edge accesses are indistinguishable. For this purpose, we propose Omix++, a novel doubly-oblivious map that outperforms the previous state of the art by up to 34×, and may be of independent interest. Moreover, to avoid any leakage from CPU instruction-fetching during query evaluation, we propose algorithms for four fundamental graph queries (BFS/DFS traversal, minimum spanning tree, and single-source shortest paths) that have a fixed execution trace , i.e., the sequence of executed operations is independent of the input. By combining these techniques, we eliminate all information that a hardware adversary observing the memory access pattern within the protected enclave can infer. We benchmarked GraphOS against the best existing solution, based on oblivious relational DBMS (translating graph queries to relational operators). GraphOS is not only significantly more performant (by up to two orders of magnitude for our tested graphs) but it eliminates leakage related to the graph topology that is practically inherent when a relational DBMS is used unless all operations are "padded" to the worst case.
Javad Ghareh Chamani, Ioannis Demertzis, Dimitrios Papadopoulos 0001, Charalampos Papamanthou, Rasool Jalili
Proc. VLDB Endow.5
2023 Multi-User Dynamic Searchable Symmetric Encryption With Corrupted Participants
abstract
We study the problem of multi-user dynamic searchable symmetric encryption (DMUSSE) where a data owner stores its encrypted documents on an untrusted remote server and wishes to selectively allow multiple users to access them by issuing keyword search queries. Specifically, we consider the case where some of the users may be corrupted andcolluding with the serverto extract additional information about the dataset (beyond what they have access to). We provide the first formal security definition for the dynamic setting as well as forward and backward privacy definitions. We then propose$\mu$SE, the first provably secure DMUSSE scheme and instantiate it in two versions, one based on oblivious data structures and one based on update queues, with different performance trade-offs. Furthermore, we extend$\mu$SEto support verifiability of results. To achieve this, users need a secure digest initially computed by the data owner and changed after every update. We efficiently accommodate this, without relying on a trusted third party, by adopting a blockchain-based approach for the digests’ dissemination and deploy our schemes over the permissioned Hyperledger Fabric blockchain. We prototype both versions and experimentally evaluate their practical performance, both as stand-alone systems and running on top of Hyperledger Fabric.
Javad Ghareh Chamani, Dimitrios Papadopoulos 0001, Rasool Jalili
IEEE Trans. Dependable Secur. Comput.5
2022 RAD: A Statistical Mechanism Based on Behavioral Analysis for DDoS Attack Countermeasure
abstract
Nowadays, Distributed Denial of Service (DDoS) attacks are among the most prevailing and costly attacks across the networks which challenge a variety of services. While many defense mechanisms are presented to detect and mitigate DDoS attacks, attackers constantly explore alternative approaches for orchestrating novel DDoS attacks. Distribution of the mechanism and its deployment into different zones can improve the accuracy and coverage of DDoS attack varieties. In this paper, we propose a 3-phase DDoS attack countermeasure, named$RAD$, based on a statistical model for scoring users in order to detect DDoS attacks. In the first phase, users are classified into either suspicious or benign based on their traffic behavior, being indicated by the number of flows, packets, concurrent connections, and amount of user-generated traffic. In the second phase, we identify a potential attack state using the drop, jitter, and delay processing parameters. In the third phase, relevant policies are enforced on the suspicious class of users and its effects are assessed continuously in order to reduce false alarms.$RAD$is evaluated through the UNB CICDDoS2019 dataset and is compared with four well-known DDoS detection algorithms.$RAD$counters DDoS attacks with more than 80% precision, 99% recall, and 89% F1-Measure in CICDDoS2019.
Mosayeb Hajimaghsoodi, Rasool Jalili
IEEE Trans. Inf. Forensics Secur.2
2021 AWA: Adversarial Website Adaptation
Amir Mahdi Sadeghzadeh, Behrad Tajali, Rasool Jalili
IEEE Trans. Inf. Forensics Secur.3
2021 Adversarial Network Traffic: Towards Evaluating the Robustness of Deep-Learning-Based Network Traffic Classification
abstract
Network traffic classification is used in various applications such as network traffic management, policy enforcement, and intrusion detection systems. Although most applications encrypt their network traffic and some of them dynamically change their port numbers, Machine Learning (ML) and especially Deep Learning (DL)-based classifiers have shown impressive performance in network traffic classification. In this article, we evaluate the robustness of DL-based network traffic classifiers against Adversarial Network Traffic (ANT). ANT causes DL-based network traffic classifiers to predict incorrectly using Universal Adversarial Perturbation (UAP) generating methods. Since there is no need to buffer network traffic before sending ANT, it is generated live. We partition the input space of the DL-based network traffic classification into three categories: packet classification, flow content classification, and flow time series classification. To generate ANT, we propose three new attacks injecting UAP into network traffic. AdvPad attack injects a UAP into the content of packets to evaluate the robustness of packet classifiers. AdvPay attack injects a UAP into the payload of a dummy packet to evaluate the robustness of flow content classifiers. AdvBurst attack injects a specific number of dummy packets with crafted statistical features based on a UAP into a selected burst of a flow to evaluate the robustness of flow time series classifiers. The results indicate injecting a little UAP into network traffic, highly decreases the performance of DL-based network traffic classifiers in all categories.
Amir Mahdi Sadeghzadeh, Saeed Shiravi, Rasool Jalili
IEEE Trans. Netw. Serv. Manag.3
2020 ACoPE: An adaptive semi-supervised learning approach for complex-policy enforcement in high-bandwidth networks
Morteza Noferesti, Rasool Jalili
Comput. Networks2
2019 Inline high-bandwidth network analysis using a robust stream clustering algorithm
abstract
High‐bandwidth network analysis is challenging, resource consuming, and inaccurate due to the high volume, velocity, and variety characteristics of the network traffic. The infinite stream of incoming traffic forms a dynamic environment with unexpected changes, which requires analysing approaches to satisfy the high‐bandwidth network processing challenges such as incremental learning, inline processing, and outlier handling. This study proposes an inline high‐bandwidth network stream clustering algorithm designed to incrementally mine large amounts of continuously transmitting network traffic when some outliers can be dropped before determining the network traffic behaviour. Maintaining extended‐meta‐events as abstracting data structures over a sliding window, enriches the algorithm to address the high‐bandwidth network processing challenges. Evaluating the algorithm indicates its robustness, efficiency, and accuracy in analysing high‐bandwidth networks.
Morteza Noferesti, Rasool Jalili
IET Inf. Secur.2
2018 New Constructions for Forward and Backward Private Symmetric Searchable Encryption
abstract
We study the problem of dynamic symmetric searchable encryption. In that setting, it is crucial to minimize the information revealed to the server as a result of update operations (insertions and deletions). Two relevant privacy properties have been defined in that context: forward and backward privacy. The first makes it hard for the server to link an update operation with previous queries and has been extensively studied in the literature. The second limits what the server can learn about entries that were deleted from the database, from queries that happen after the deletion. Backward privacy was formally studied only recently (Bost et al., CCS 2017) in a work that introduced a formal definition with three variable types of leakage (Type-I to Type-III ordered from most to least secure), as well as the only existing schemes that satisfy this property. In this work, we introduce three novel constructions that improve previous results in multiple ways. The first scheme achieves Type-II backward privacy and our experimental evaluation shows it has 145-253X faster search computation times than previous constructions with the same leakage. Surprisingly, it is faster even than schemes with Type-III leakage which makes it the most efficient implementation of a forward and backward private scheme so far. The second one has search time that is asymptotically within a polylogarithmic multiplicative factor of the theoretical optimal (i.e., the result size of a search), and it achieves the strongest level of backward privacy (Type-I). All previous Type-I constructions require time that is at least linear in the total number of updates for the requested keywords, even the (arbitrarily many) previously deleted ones. Our final scheme improves upon the second one by reducing the number of roundtrips for a search at the cost of extra leakage (Type-III).
Javad Ghareh Chamani, Dimitrios Papadopoulos 0001, Charalampos Papamanthou, Rasool Jalili
CCS4
2017 HB2DS: A behavior-driven high-bandwidth network mining system
Morteza Noferesti, Rasool Jalili
J. Syst. Softw.2
2016 Access control aware data retrieval for secret sharing based database outsourcing
Mohammad Ali Hadavi, Rasool Jalili, Leila Karimi
Distributed Parallel Databases2
2016 TIRIAC: A trust-driven risk-aware access control framework for Grid environments
Sadegh Dorri Nogoorani, Rasool Jalili
Future Gener. Comput. Syst.2
2016 Uncertainty in Trust: A Risk-Aware Approach
abstract
Uncertainty and its imposed risk have significant impacts on decision-making. However, both are disregarded in many trust-based applications. In this paper, we propose a risk-aware approach to explicitly take uncertainty of trust and its effects into account. Our approach consists of a trust, a confidence, and a risk model. We do not prescribe a specific trust model, and any probabilistic trust model can be empowered by our approach. The confidence model calculates the uncertainty of the trust model in the form of a confidence interval, and is independent of the inner-workings of the trust model. This interval is used by the utility-based risk model which assesses the effects of uncertainty on trust-based decisions. We evaluated our approach by a four-state HMM-based simulated trustee, and employed the Beta, HMM and evidence-based trust models. We proposed and compared different methods for calculating confidence intervals, as well as methods for determining the risk and opportunity of a trust-based interaction. The results demonstrate how our approach should be used to improve the correctness of decision-making in trust-based applications. According to the statistical analysis of the simulation results, confidence intervals can properly represent the trust value and its uncertainty, and strongly improve trust-based decisions.
Sadegh Dorri Nogoorani, Rasool Jalili
Int. J. Uncertain. Fuzziness Knowl. Based Syst.2
2015 (t, k)-Hypergraph anonymization: an approach for secure data publishing
abstract
Abstract Privacy preservation is an important issue in data publishing. Existing approaches on privacy‐preserving data publishing rely on tabular anonymization techniques such ask‐anonymity, which do not provide appropriate results for aggregate queries. The solutions based on graph anonymization have also been proposed for relational data to hide only bipartite relations. In this paper, we propose an approach for anonymizing multirelation constraints (ternary or more) with (t,k) hypergraph anonymization in data publishing. To this end, we model constraints as undirected hypergraphs and formally cluster attribute relations as hyperedge with thet‐means‐clustering algorithm. In addition, anonymization is carried out with ak‐anonymity method in every cluster for which the parameterkcan vary in each cluster, to attain more flexibility and less information loss with respect to utility. Our experiments demonstrate that this approach offers a great trade‐off between privacy and utility. Copyright © 2014 John Wiley & Sons, Ltd.
Atefeh Asayesh, Mohammad Ali Hadavi, Rasool Jalili
Secur. Commun. Networks3
2015 On Constrained Implementation of Lattice-Based Cryptographic Primitives and Schemes on Smart Cards
abstract
Most lattice-based cryptographic schemes with a security proof suffer from large key sizes and heavy computations. This is also true for the simpler case of authentication protocols that are used on smart cards as a very-constrained computing environment. Recent progress on ideal lattices has significantly improved the efficiency and made it possible to implement practical lattice-based cryptography on constrained devices. However, to the best of our knowledge, no previous attempts have been made to implement lattice-based schemes on smart cards. In this article, we provide the results of our implementation of several state-of-the-art lattice-based authentication protocols on smart cards and a microcontroller widely used in smart cards. Our results show that only a few of the proposed lattice-based authentication protocols can be implemented using limited resources of such constrained devices; however, cutting-edge ones are suitably efficient to be used practically on smart cards. Moreover, we have implemented fast Fourier transform (FFT) and discrete Gaussian sampling with different typical parameter sets, as well as versatile lattice-based public-key encryptions. These results have noticeable points that help to design or optimize lattice-based schemes for constrained devices.
Ahmad Boorghany, Siavash Bayat Sarmadi, Rasool Jalili
ACM Trans. Embed. Comput. Syst.3
2013 An efficient and provably-secure coercion-resistant e-voting protocol
abstract
We present an efficient and provably-secure e-voting protocol, which is a variant of the JCJ e-voting protocol (Juels et al., 2010). It decreases the total number of JCJ's operations from O(n2) to O(n), where n is the number of votes or voters (whichever is the maximum). Note that since the operations under consideration are time-consuming (e.g., public-key encryption), the improvement is quite substantial. As a rough comparison, consider a nation-wide election with around ten million voters/votes. Assuming each operation takes one microsecond, and no parallelization is used, one can see a huge difference: our protocol tallies the votes in 10 seconds, while the JCJ protocol requires over 3 years to tally the votes. In order to achieve this level of efficiency, we change the ballot format and the tallying phase of the JCJ protocol. Moreover, we provide a complexity analysis and a detailed proof for coercion-resistance of our protocol.
Alireza Toroghi Haghighat, Mohammad Sadeq Dousti, Rasool Jalili
PST3
2012 Uncertainty in Probabilistic Trust Models
abstract
Computational models of trust try to transfer the concept of trust from the real to the virtual world. While such models have been widely investigated in the past decade, the uncertainty involved in trust computation has been overlooked in the literature. In this paper, uncertainty of probabilistic trust models is quantified using confidence intervals and its factors are determined through simulation. The results confirm the importance and highlight the amount of uncertainty in the Beta and HMM (Hidden Markov Model) trust models. In addition, an uncertainty-driven method is proposed which reduces the risk involved in the trust-based utility maximization according to uncertainty.
Sadegh Dorri Nogoorani, Rasool Jalili
AINA2
2012 k-Anonymity-Based Horizontal Fragmentation to Preserve Privacy in Data Outsourcing
Abbas Taheri Soodejani, Mohammad Ali Hadavi, Rasool Jalili
DBSec3
2010 Multi-level authorisation model and framework for distributed semantic-aware environments
abstract
Semantic technology is widely used in distributed computational environments to increase interoperability and machine readability of information through giving semantics to the underlying information and resources. Semantic-awareness, distribution and interoperability of new generation of distributed systems demand an authorisation model and framework that satisfies essential authorisation requirements of such environments. In this study, the authors propose an authorisation model and framework based on multi-security-domain architecture for distributed semantic-aware environments. The proposed framework is founded based on the MA(DL)2 logic, which enables policy specification and inference (based on the defined semantic relationships) in both conceptual and ground (individual) levels. Also, it enables authorities to have cooperative security management in their shared domain of resources with different administration styles.
Morteza Amini, Rasool Jalili
IET Inf. Secur.2
2009 A semantic-based access control mechanism using semantic technologies
abstract
In order to overcome the shortcomings of the recent frameworks and mechanisms for semantic-based access control, this paper presents a semantic-based, context-aware, and multi-domain enabled framework implementing a semantic-based access control mechanism for Semantic Web. The access control framework is based on the MA(DL)2 model, which takes the semantic relationships among different entities into account. The framework handles the Semantic Web context by classifying and representing it through an ontology. Considering the MA(DL)2 model, the framework assumes Semantic Web having some overlapped domains, which each contains an authority and a security agent. As a domain authority responsibility is to specify the domain policies, its agent is to enforce them. The mechanism is designed using the semantic technologies, which make it fully consistent with the environment. The paper clarifies the usability of the designed mechanism through some examples of an elections system case study.
Moussa Amir Ehsan, Morteza Amini, Rasool Jalili
SIN3
2008 Self-reconfiguration in Highly Available Pervasive Computing Systems
Hadi Hemmati, Rasool Jalili
ATC2
2008 A Semantic-Aware Ontology-Based Trust Model for Pervasive Computing Environments
Mohsen Taherian, Rasool Jalili, Morteza Amini
ATC2
2008 Trust Inference in Web-Based Social Networks Using Resistive Networks
abstract
By the immense growth of the Web-based social networks (WBSNs), the role of trust in connecting people together through WBSNs is getting more important than ever. In other words, since the probability of malicious behavior in WBSNs is increasing, it is necessary to evaluate the reliability of a person before trying to communicate with. Hence, it is desirable to find out how much a person should trust another one in a network. The approach to answer this question is usually called trust inference. In this paper, we propose a new trust inference algorithm (called RN-trust) based on the resistive networks concept. The algorithm, in addition to being simple, resolves some problems of previously proposed approaches. The analysis of the algorithm demonstrates that RN-trust calculates the trust values more accurately than previous approaches.
Mohsen Taherian, Morteza Amini, Rasool Jalili
ICIW3
2008 A Context-Aware Mandatory Access Control Model for Multilevel Security Environments
Jafar Haadi Jafarian, Morteza Amini, Rasool Jalili
SAFECOMP3
2007 Separation of Duty in Role-Based Access Control Model through Fuzzy Relations
abstract
As a security principle, separation of duty (SoD) is widely considered in computer security. In the role-based access control(RBAC) model, separation of duty constraints enforce conflict of interest policies. There are two main types of separation of duty policies in RBAC, Static SoD (SSoD) and Dynamic SoD (DSoD). In RBAC, Statically Mutually Exclusive Role (SMER) constraints are used to enforce Static Separation of Duty policies. Dynamic Separation of duty policies, like SSoD policies, are intended to limit the permissions that are available to a user. However, DSoD policies differ from SSoD policies by the context in which these limitations are imposed. A DSoD policy limits the availability of the permissions over a users permission space by placing constraints on the roles that can be activated within or across a users sessions. Like SMER, in RBAC Dynamically Mutually Exclusive Role (DMER) constraints are used to enforce DSoD policies. We investigated using of a fuzzy approach to address the issue in order to provide a more practical solution. In this paper, we propose a model to express the separation of duty policies in RBAC using the fuzzy set theory. The concept of trustworthiness, which is fuzzy in nature, is used to express this model. In comparison with non-fuzzy methods, our method is more pragmatic and more consistent with the real world. The expressiveness of our method is higher than the non- fuzzy ones. We show expression of some constraints in our method which cannot be expressed by non-fuzzy methods. Applicability of the method is shown through an example of the real world.
Hassan Takabi, Morteza Amini, Rasool Jalili
IAS3
2007 Enhancing Role-Based Access Control Model through Fuzzy Relations
abstract
Role-Based Access Control (RBAC) model is naturally suitable to organizations where users are assigned organizational roles with well-defined privileges. However, due to the large number of users in nowadays online services of organizations and enterprises, assigning users to roles is a tiresome task and maintaining user-role assignment up- to-date is costly and error-prone. Additionally, with the increasing number of users, RBAC may have problems in prohibiting cheat and changing roles of users. In order to categorize information and formulate security policies, human decision making is required which is naturally fuzzy in the real world. This leads using a fuzzy approach to address the issue in order to provide a more practical solution. In this paper, applicability of fuzzy set theory to RBAC has been investigated by identifying access control building blocks which are fuzzy in essence. An existing RBAC model is extended to allow imprecise access control policies, using the concept of trustworthiness which is fuzzy in nature. We call the extended model as Fuzzy RBAC. Applicability of the extended model has been evaluated through some case studies.
Hassan Takabi, Morteza Amini, Rasool Jalili
IAS3
2007 Trust-Based User-Role Assignment in Role-Based Access Control
abstract
Role based access control (RBAC) model is naturally suitable to organizations where users are assigned organizational roles with well-defined privileges. Nowadays, many organizations and enterprises such as banks, insurance industry and utility companies, provide online services to their very large number of users. This shows that assigning users to roles is a intolerable task and maintaining user-role assignment up-to-date is costly and error-prone. Also, with the increasing number of users, RBAC may have problems in prohibiting cheat and changing roles of users. To overcome these problems, user-role assignment decision can be made based on how much we trust him/her. In this paper, we propose a model to assign users to roles based on trustworthiness which is fuzzy in nature. The proposed model uses fuzzy relation equations to compute trust values.
Hassan Takabi, Morteza Amini, Rasool Jalili
AICCSA3
2007 A Dynamic-Reconfigurable Architecture for Protocol Stacks of Networked Systems
abstract
This paper proposes a software framework for dynamic- reconfigurable protocol stack The framework presents mechanisms and an algorithm for all required phases for reconfiguration of a running protocol component that include freezing the component in a safe state, changing the component, and state transfer to a new component. Considering that every running protocol component communicates with at least one peer component in another system, we perform the reconfiguration with respect to the peer component.
Mahdi Niamanesh, Rasool Jalili
COMPSAC (1)2
2007 Vulnerability Take Grant (VTG): An efficient approach to analyze network vulnerabilities
Hamid Reza Shahriari, Rasool Jalili
Comput. Secur.2
2006 An Architecture for a Context-aware Service Broker in Ubiquitous Computing Environments
abstract
In ubiquitous computing environments, many de- vices and agents interoperate with each other and use services provided by others. But the problem is that there may be requests that can not be fulfilled by available services. A solution to this problem is to use service brokers that compose existing services and create new value added services that can fulfill the clients' requests. In this paper, we present an architecture for a context- aware service broker that not only is able to compose services for responding to new requests, but also considers the context of its clients for providing customized and personalized outputs and behaviors.
Yasser Ganjisaffar, Hassan Abolhassani, Rasool Jalili
AICCSA3
2006 Security Enhancement for a Low Computation Cost User Authentication Scheme
Behnam Sattarzadeh, Mahdi Asadpour, Rasool Jalili
SECRYPT3
2006 RT-UNNID: A practical solution to real-time network-based intrusion detection using unsupervised neural networks
Morteza Amini, Rasool Jalili, Hamid Reza Shahriari
Comput. Secur.2
2005 Network Vulnerability Analysis Through Vulnerability Take-Grant Model (VTG)
Hamid Reza Shahriari, Reza Sadoddin, Rasool Jalili, Reza Zakeri, Ali Reza Omidian
ICICS3
2005 Detection of Distributed Denial of Service Attacks Using Statistical Pre-processor and Unsupervised Neural Networks
Rasool Jalili, Fatemeh Imani-Mehr, Morteza Amini, Hamid Reza Shahriari
ISPEC1