EDBT 2026 Demo / reviewers in the wild / expert
Rahat Masood
dblp:80/10811
· DBLP profile ↗
24ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0001-5935-0062ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 3 first-author · 5 since 2021Computer networks · 6 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 3Artificial intelligence and machine learning · 2Databases, data management, data science and information retrieval · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Taxonomy-Driven Case Study of Australian Web Resources Against Technology-Facilitated Abuse
Dipankar Srirag, Xiaolin Cen, Rahat Masood, Aditya Joshi 0001 |
ACISP (2) | 3 |
| 2026 | TBTrackerX: Fantastic Trigger Bots and Where to Find Malicious Campaigns on X
Mohd Majid Akhtar, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
NDSS | 2 |
| 2026 | Device Type Classification Using WiFi Probe Requests: From Signals to InsightsabstractWiFi devices are ubiquitous in modern environments, from smartphones and laptops to IoT sensors and AR/VR headsets. Identifying device types/models within these populations enables crowd analysis, network optimization, and detection of unusual devices. Current identification methods struggle with MAC address randomization, require large training datasets, and perform poorly in real-world deployments. This paper introduces a device identification method based on Information Element (IE) attributes extracted from WiFi probe requests. We evaluate the approach using probe requests captured in the 2.4 GHz band. Evaluation across 70+ device types yields 99% precision, 98% recall, and 99% F1 score, exceeding deep learning approaches (92% F1 score) under similar training conditions. Our approach maintains accuracy despite MAC randomization and requires minimal training data. We demonstrate practical applicability through an operational dashboard tested in real-world scenarios for urban planning and network management. Case studies across diverse environments confirm the effectiveness of the method for operational use. Niruth Bogahawatta, Yasiru Senarath Karunanayaka, Suranga Seneviratne, Kanchana Thilakarathna, Rahat Masood, Salil S. Kanhere, Aruna Seneviratne, Albert Y. Zomaya |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | Empirical Analysis of DNS Abuse Cases within Australian DomainabstractThe Domain Name System (DNS) translates human-readable domain names into machine-readable IP addresses. This critical internet infrastructure faces increasing exploitation through various malicious activities collectively known as DNS abuse. While DNS abuse has been extensively researched globally, the unique patterns and vulnerabilities within the Australian domain space remain understudied. This paper provides a comprehensive empirical analysis of DNS abuse within Australian domain names. Our thorough data collection and analysis allow us to characterize the specific nature of abuse trends within the Australian domain space. We document how malicious actors strategically employ methods to evade detection systems, and highlight the concentration of abuse among specific domain registrations. These research findings provide stakeholders with actionable, data-driven insights, emphasizing the necessity of industry-specific defensive measures and tailored state-level threat mitigation strategies. We have laid the foundation for building a more refined, risk-based Australian digital infrastructure security system. Minghao Cai, Sushmita Ruj, Rahat Masood, Salil S. Kanhere |
LCN | 3 |
| 2024 | Privacy Preserving Release of Mobile Sensor DataabstractSensors embedded in mobile smart devices can monitor users’ activity with high accuracy to provide a variety of services to end-users ranging from precise geolocation, health monitoring, and handwritten word recognition. However, this involves the risk of accessing and potentially disclosing sensitive information of individuals to the apps that may lead to privacy breaches. In this paper, we aim to minimize privacy leakages that may lead to user identification on mobile devices through user tracking and distinguishability while preserving the functionality of apps and services. We propose a privacy-preserving mechanism that effectively handles the sensor data fluctuations (e.g., inconsistent sensor readings while walking, sitting, and running at different times) by formulating the data as time-series modeling and forecasting. The proposed mechanism uses correlated noise-series against noise filtering attacks from an adversary, which aims to filter out the noise from the perturbed data to re-identify the original data. Unlike existing solutions, our mechanism keeps running in isolation without the interaction of a user or a service provider. We perform rigorous experiments on three benchmark datasets and show that our proposed mechanism limits user tracking and distinguishability threats to a significant extent compared to the original data while maintaining a reasonable level of utility of functionalities. In general, we show that our obfuscation mechanism reduces the user trackability threat by 60% across all the datasets while maintaining the utility loss below 0.3 Mean Absolute Error (MAE). More specifically, we observe that 80% of users achieve a 100% untrackability rate in the Swipes dataset across all noise scales. In the handwriting dataset, distinguishability is 17% for 60% of the users. Overall, our mechanism provides a utility error (MAE) of only 0.12 for 60% of users, and this increases to 0.2 for 100% users when correction thresholds are altered. Rahat Masood, Wing Yan Cheng, Dinusha Vatsalan, Deepak Mishra 0001, Hassan Jameel Asghar, Mohamed Ali Kâafar |
ARES | 1 |
| 2024 | SoK: False Information, Bots and Malicious Campaigns: Demystifying Elements of Social Media ManipulationsabstractThe rapid spread of false information and persistent manipulation attacks on online social networks (OSNs), often for political, ideological, or financial gain, has affected the openness of OSNs. While researchers from various disciplines have investigated different manipulation-triggering elements of OSNs (such as understanding information diffusion on OSNs or detecting automated behavior of accounts), these works have not been consolidated to present a comprehensive overview of the interconnections among these elements. Notably, user psychology, the prevalence of bots, and their tactics concerning false information detection have been overlooked in previous research. Mohd Majid Akhtar, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
AsiaCCS | 2 |
| 2024 | Passive Identification of WiFi Devices At-Scale: A Data-Driven ApproachabstractWiFi has emerged as the standard method for local connectivity across various devices, including smart assistants, IoT devices, smart TVs, and AR/VR devices. Identifying WiFi devices in neighborhoods has implications for law enforcement, urban planning, and socio-economic analysis. This paper introduces a novel approach to constructing WiFi device-type signatures using Information Element attributes from wildcard WiFi probe requests. Our method accurately identifies device types even when dealing with randomized MAC addresses and requires minimal training data, thus addressing limitations of existing machine learning and deep learning approaches. We evaluate our approach using a dataset of 51,726 probe requests across 50 device types, achieving an average F1 score of 99%, precision of 99%, and recall of 98% in device-type identification. Importantly, our method outperforms deep learning methods with significantly less training data, achieving a 92% F1 score with only one training sample per device type. Niruth Bogahawatta, Yasiru Senarath Karunanayaka, Suranga Seneviratne, Kanchana Thilakarathna, Rahat Masood, Salil S. Kanhere, Aruna Seneviratne |
LCN | 5 |
| 2024 | Evaluating Web-Based Privacy Controls: A User Study on Expectations and PreferencesabstractIn response to growing privacy concerns, many websites have implemented privacy controls that aim to enhance user autonomy and compliance with data protection regulations. While existing literature has evaluated individual privacy controls such as cookie consent interfaces, less attention has been given to how combining multiple privacy controls in realistic online environments affects the overall user experience. We conducted an online user study with 75 participants to explore the usability of privacy controls offered by websites across four widely used categories. Participants were asked to interact with website prototypes that differed in terms of where and how the privacy control variants were presented, then answer a survey about their experience. Our findings revealed the usability impact of design parameters on privacy controls and highlighted how user expectations vary across different demographics and website categories. We provide design recommendations that combine informative elements (privacy notices and policies) with actionable elements (privacy nudges and settings) to enhance the usability of website privacy controls for users. Yuemeng Yin, Rahat Masood, Suranga Seneviratne, Aruna Seneviratne |
TrustCom | 2 |
| 2024 | Single-Sensor Sparse Adversarial Perturbation Attacks Against Behavioral BiometricsabstractIn Internet of Things (IoT) deployments, sensing applications have emerged as critical tools. They combine data streams from heterogeneous, untrusted sensors to provide valuable insights or make automated decisions. This paper shows that such systems can be easily manipulated by only compromising a single sensor and perturbing the data from specific time slots rather than entire data streams in grey-box and black-box settings -attack scenarios not considered in traditional machine learning literature. Drawing from two datasets related to behavioural biometrics of smart headsets, we demonstrate that by altering just 6.2% of the data, an attacker can significantly reduce the system’s accuracy—achieving drops of 85% in grey-box scenarios and 74.5% in black-box settings. Next, we show that while adversarial training can mitigate such attacks, an attacker can overcome such defences by increasing the perturbation only in specific time steps. To this end, we propose a two-step defence where we detect more significant perturbations in IoT sensor readings using anomaly detection and mitigate more minor perturbations through adversarial training. Overall, our proposed method can limit the accuracy drop to a maximum of 9.59% across all magnitudes of perturbations, thus protecting against adversarial attacks on multi-sensor systems. Ravin Gunawardena, Sandani Jayawardena, Suranga Seneviratne, Rahat Masood, Salil S. Kanhere |
IEEE Internet Things J. | 4 |
| 2024 | A Comprehensive Threat Modelling Analysis for Distributed Energy ResourcesabstractThe exponential rise in popularity of distributed energy resources (DERs) is attributed to their numerous benefits within the power sector. However, the risks that new DERs pose to the power grid have not yet been closely assessed, exposing a gap in the literature. This article addresses this gap by presenting a comprehensive threat model of the DER architecture, combining the MITRE ATT&CK catalogue for industrial control systems (ICS), and the IDDIL/ATC threat model, to create a hybrid approach. Our first contribution is to propose criteria derived from seven metrics to evaluate and compare the efficacy and usability of threat modelling frameworks for DER systems, allowing more informed framework selection. Our second contribution is to develop a comprehensive hybrid threat modelling approach based on IDDIL/ATC and MITRE ATT&CK and organise attack paths chronologically using the cyber kill chain methodology to categorise attacker techniques. Our third contribution is to perform a comprehensive DER architecture system decomposition, elaborating assets, trust levels, entry points, data, protocols, and entity relations to identify the threat landscape. Our final contribution is to apply the proposed approach to the distribution system operator (DSO), mapping potential attacker techniques and illustrating a ransomware attack chain on the DSO's Energy Management System, with proposed mitigations. Neel Bhaskar, Jawad Ahmed, Rahat Masood, Stephen Kerr, Sanjay K. Jha |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2023 | Towards Automatic Annotation and Detection of Fake NewsabstractAutomated accounts or bots on Online Social Networks (OSNs) play a significant role in disseminating information, including false news, which may instigate cyber propaganda. The existing research on fake news detection does not account for the existence of bots. Also, they only focus on identifying fake news in “the articles shared in posts” rather than the post’s (textual) content and use manually labeled limited datasets. In this research, we overcome the challenge of data scarcity by proposing an automated approach for labeling data using verified fact-checked statements on OSNs such as Twitter. Moreover, we analyze the presence and impact of bots and show that bots change their behavior over time. Our experiments focus on COVID-19, collect 10.22 million COVID-19-re1ated tweets, and use our annotation model to build an extensive ground truth dataset for classification purposes. We evaluated our automatic annotation model on two existing COVID-19-re1ated misinformation datasets and achieved a ~ 2% increase in precision compared to the existing annotation models. In addition, our best classification model achieves 83% precision, 96% recall, and a ~ 4% false positive rate on our annotated dataset, outperforming existing techniques. Mohd Majid Akhtar, Ishan Karunanayake, Bibhas Sharma, Rahat Masood, Muhammad Ikram 0001, Salil S. Kanhere |
LCN | 4 |
| 2020 | Security Apps under the Looking Glass: An Empirical Analysis of Android Security AppsabstractThird-party security apps are an integral part of the Android app ecosystem. Many users install them as an extra layer of protection for their devices. By installing security apps, the smartphone users place a significant amount of trust on them allowing access to many smartphone resources that contain personal information such as the storage, text messages, email, and browser history. As such, it is essential to understand the mobile security apps ecosystem. In this paper, we present the first empirical study of Android security apps. We analyse 100 Android security apps from multiple aspects and offer insights to their operations and behaviours. Our results show that 20% of the security apps resell the data they collect to third parties; in some cases, even without the user consent. Also, we show that around 50% of the security apps fail to identify known malware. Weixian Yao, Yexuan Li, Weiye Lin, Tianhui Hu, Imran Chowdhury, Rahat Masood, Suranga Seneviratne |
LCN | 6 |
| 2020 | Measuring and Analysing the Chain of Implicit Trust: A Study of Third-party Resources LoadingabstractThe web is a tangled mass of interconnected services, whereby websites import a range of external resources from various third-party domains. The latter can also load further resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This article performs a large-scale study of dependency chains in the web to find that around 50% of first-party websites render content that they do not directly load. Although the majority (84.91%) of websites have short dependency chains (below three levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third parties are classified as suspicious—although seemingly small, this limited set of suspicious third parties have remarkable reach into the wider ecosystem. We find that 73% of websites under-study load resources from suspicious third parties, and 24.8% of first-party webpages contain at least three third parties classified as suspicious in their dependency chain. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript codes downloading malware. Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi |
ACM Trans. Priv. Secur. | 2 |
| 2019 | The Chain of Implicit Trust: An Analysis of the Web Third-party Resources LoadingabstractThe Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi |
WWW | 2 |
| 2018 | Incognito: A Method for Obfuscating Web DataabstractUsers leave a trail of their personal data, interests, and intents while surfing or sharing information on the Web. Web data could therefore reveal some private/sensitive information about users based on inference analysis. The possible identification of information corresponding to a single individual by an inference attack holds true even if the user identifiers are encoded or removed in the Web data. Several works have been done on improving privacy of Web data through obfuscation methods~\citeHow09,Dom09,Sha05,Che14. However, these methods are neither comprehensive, generic to be applicable to any Web data, nor effective against adversarial attacks. To this end, we propose a privacy-aware obfuscation method for Web data addressing these identified drawbacks of existing methods. We use probabilistic methods to predict privacy risk of Web data that incorporates all key privacy aspects, which are uniqueness, uniformity, and linkability of Web data. The Web data with high predicted risk are then obfuscated by our method to minimize the privacy risk using semantically similar data. Our method is resistant against adversary who has knowledge about the datasets and model learned risk probabilities using differential privacy-based noise addition. Experimental study conducted on two real Web datasets validates the significance and efficacy of our method. Our results indicate that the average privacy risk reaches to 100% with a minimum of 10 sensitive Web entries, while at most 0% privacy risk could be attained with our obfuscation method at the cost of average utility loss of 64.3%. Rahat Masood, Dinusha Vatsalan, Muhammad Ikram 0001, Mohamed Ali Kâafar |
WWW | 1 |
| 2018 | Touch and You're Trapp(ck)ed: Quantifying the Uniqueness of Touch Gestures for TrackingabstractAbstract We argue that touch-based gestures on touch-screen devices enable the threat of a form of persistent and ubiquitous tracking which we call touch-based tracking. Touch-based tracking goes beyond the tracking of virtual identities and has the potential for cross-device tracking as well as identifying multiple users using the same device. We demonstrate the likelihood of touch-based tracking by focusing on touch gestures widely used to interact with touch devices such as swipes and taps.. Our objective is to quantify and measure the information carried by touch-based gestures which may lead to tracking users. For this purpose, we develop an information theoretic method that measures the amount of information about users leaked by gestures when modelled as feature vectors. Our methodology allows us to evaluate the information leaked by individual features of gestures, samples of gestures, as well as samples of combinations of gestures. Through our purpose-built app, called TouchTrack, we gather gesture samples from 89 users, and demonstrate that touch gestures contain sufficient information to uniquely identify and track users. Our results show that writing samples (on a touch pad) can reveal 73.7% of information (when measured in bits), and left swipes can reveal up to 68.6% of information. Combining different combinations of gestures results in higher uniqueness, with the combination of keystrokes, swipes and writing revealing up to 98.5% of information about users. We further show that, through our methodology, we can correctly re-identify returning users with a success rate of more than 90%. Rahat Masood, Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Mohamed Ali Kâafar |
Proc. Priv. Enhancing Technol. | 1 |
| 2017 | POSTER: TouchTrack: How Unique are your Touch Gestures?abstractThis paper studies a privacy threat induced by the collection and monitoring of a user's touch gestures on touchscreen devices. The threat is a new form of persistent tracking which we refer to as "touch-based tracking". It goes beyond tracking of virtual identities and has the potential for cross-device tracking as well as identifying multiple users using the same device. To demonstrate the likelihood of touch-based tracking, we propose an information theoretic method that quantifies the amount of information revealed by individual features of gestures, samples of gestures as well as samples of gesture combinations, when modelled as feature vectors. We have also developed a purpose-built app, named "TouchTrack" that collects data from users and informs them on how unique they are when interacting with their touch devices. Our results from 89 different users indicate that writing samples and left swipes can reveal 73.7% and 68.6% of user information, respectively. Combining different combinations of gestures results in higher uniqueness, with the combination of keystrokes, swipes and writing revealing up to 98.5% of information about users. We correctly re-identify returning users with a success rate of more than 90%. Rahat Masood, Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Mohamed Ali Kâafar |
CCS | 1 |
| 2016 | DB-SECaaS: a cloud-based protection system for document-oriented NoSQL databasesabstractThe trend of cloud databases is leaning towards Not Only SQL (NoSQL) databases as they provide better support for scalable storage and quick retrieval of exponentially voluminous data. One of the more prominent types of NoSQL databases is document-based storage, which is being increasingly used in the dynamic cloud paradigm. However, there are inherent security issues in cloud, including remote data residency along with the non-existent control of owners over their own data. In addition to that, the inherent security features of most document-based NoSQL databases lack granular access control and robust confidentiality mechanisms. There is also a distinct lack of a comprehensive solution that effectively caters to all the security requirements of a document-oriented database in cloud. In order to overcome these issues, we propose a database security-as-a-service (DB-SECaaS) system over document-oriented database hosted in cloud, which provides authentication, fine-grained authorization, and encryption of the database objects, while ensuring that access to the data is granted only to authorized users on a need-to-know basis. The paper shows that the DB-SECaaS system strongly enhances the security of document-oriented databases on cloud, and it is thus expected to facilitate the industry to reap the benefits of NoSQL without worrying over security issues. In order to certify the abovementioned security enhancements, provided by DB-SECaaS, the paper also provides a formal analysis of DB-SECaaS using the Scyther model checker. As a proof of concept, the core functionalities of the protocol, i.e., authorization, authentication, and encryption, are formally modeled in Scyther to formally verify that the proposed framework mitigates privacy and security concerns. Yumna Ghazi, Rahat Masood, Abid Rauf, Muhammad Awais Shibli, Osman Hassan |
EURASIP J. Inf. Secur. | 2 |
| 2015 | Realization of FGAC model using XACML policy specificationabstractFGAC model has been adopted by enterprise applications, for the protection of their databases. Most of these deployments are not only limited in purpose but are dependent upon various other factors including query modification algorithms and software development languages. These factors have not only limited their applicability for distributed computing environments but have also affected their widespread adoption and acceptance. Moreover, due to the absence of standard FGAC profile specification, existing FGAC authorization techniques become unsuitable for advance applications such as Web 2.0 and cannot be deployed across various platforms, thus fall short of flexibility and customizability. As a result, there is an increasing demand for standard based FGAC specification that could be easily fit into majority of computing environments. In this paper, we bring forth a policy specification (profile) for FGAC model. Our proposed specification is not restricted to database applications only; rather it is generic and flexible enough to be applied on every type of application. It explicates the ways in which organizations would be able to implement standard based fine-grained access control for nearly every application. We present the case-study - a realization of FGAC model based on the proposed policy specification followed by a complete dryrun of policy evaluation procedure. Muhammad Awais Shibli, Rahat Masood, Umme Habiba |
SNPD | 2 |
| 2015 | Taxonomy for Trust Models in Cloud ComputingabstractEstablishment of trust between Cloud consumers and service providers is a challenging issue, which is a major reason why organizations are reluctant to adopt the Cloud paradigm. In order to resolve this issue, various trust models have been proposed for the Cloud domain; however, none of these models are widely accepted by the industry because they only cover a few aspects of trust establishment, and do not support all the essential features. Several problems exist in the Cloud trust models, but lack of standardization and interoperability are the primary concerns. Similarly, there is no such generic and comprehensive trust model that can establish trust on all the layers of Cloud services, namely software, platform and infrastructure. Moreover, existing trust models have their limitations in terms of providing essential functionality and security features for trust evaluation. In order to provide reliable trust establishment in the Cloud environment, there is an indispensable need to carry out research and gather knowledge about the functional and non-functional features offered by the existing Cloud trust models. Comprehensive research about trust models would further help the Cloud consumers in the selection of an appropriate model, according to their security and functional requirements. In this paper, we have performed in-depth analysis of the existing trust models in the Cloud, considering the essential functional and non-functional aspects to accurately evaluate the trust of the Cloud providers. We present panoramic taxonomies covering state of the art features, which are considered critical for trust models to effectively establish and evaluate the trust between Cloud consumers and providers. Furthermore, we have applied the proposed taxonomies as assessment criteria for the analysis of various trust models in the Cloud domain. In order to effectively demonstrate the realization and use of proposed taxonomies in real life scenarios, we have presented an extensive case study about the Health Information Exchange System. Ayesha Kanwal, Rahat Masood, Muhammad Awais Shibli, Rafia Mumtaz |
Comput. J. | 2 |
| 2015 | Cloud authorization: exploring techniques and approach towards effective access control framework
Rahat Masood, Muhammad Awais Shibli, Yumna Ghazi, Ayesha Kanwal, Arshad Ali 0001 |
Frontiers Comput. Sci. | 1 |
| 2013 | Assessment Criteria for Cloud Identity Management SystemsabstractCloud computing offers many benefits to the IT industry by making available the services and resources that helps them to proliferate or decrease their organizational resources automatically on demand. On the other hand, organizations are still uncertain about the security and privacy of their sensitive information (for instance the identity credentials) in the multitenant environment of the Cloud. Many security systems have been devised for the protection of resources in Cloud environments. Identity Management Systems, in this regard, play a vital role in ensuring effective user authentication, provisioning, de-provisioning and access control decisions. Many Cloud IDMSs have been proposed until now claiming to offer flexibility, agility and robustness. However, no comparative analysis of such Cloud based IDMSs has been performed so far, as to the best of our knowledge there exists no specific criteria against which one can evaluate an IDMS on Cloud. This paper proposes an assessment criterion for the evaluation of Cloud based IDMSs, comprising of potential security features that are positively imminent for the assessment of Cloud based IDMSs. Furthermore, analysis of Cloud IDMSs is presented based on the proposed assessment criteria. Potential research directions in the area of Cloud identity management and security are also discussed. Umme Habiba, Abdul Ghafoor Abbasi, Rahat Masood, Muhammad Awais Shibli |
PRDC | 3 |
| 2013 | Securing the virtual machine images in cloud computingabstractThe convergence of virtualization with Cloud computing has brought many benefits to organizations including ease of deployment, reduced costs and high availability of resources over internet. Extensive research has been carried out to increase the security of Cloud virtualization environment. However, addressing the security concerns of disk images used by virtual machines is still an open challenge. Compromising the disk images can result in loss of data integrity and confidentiality. This paper proposes a novel security scheme "Encrypted Virtual Disk Images in Cloud (EVDIC)" for the protection of stored disk images in Cloud by encryption. EVDIC also includes the security of key management and key exchange process. We integrate EVDIC with OpenStack, which is an open source Cloud platform largely used around the world. Muhammad Kazim 0001, Rahat Masood, Muhammad Awais Shibli |
SIN | 2 |
| 2012 | Comparative Analysis of Access Control Systems on CloudabstractCloud computing, a relatively new concept and has gained an immense attention of research community in the past few years. R&D organizations and industry are investing a lot in cloud based research and applications. Similarly on theconsumers' side organizations are moving their business on cloud to provide flexibility and conceive ever increasing computational power requirements. In spite of significant advantages, and its demand, different stakeholders are still reluctant to migrate to cloud. A major hindrance is the absence of reliable and comprehensive access control mechanism for cloud resources. We have analyzed existing cloud based access control systems and evaluated those using NIST defined access control systems evaluation criteria. Based on our analysis we have proposed future research direction in the domain of access control systems for cloud based environments, which will eventually pave the way towards cloud adoption. Um-e-Ghazia, Rahat Masood, Muhammad Awais Shibli |
SNPD | 2 |