EDBT 2026 Demo / reviewers in the wild / expert
Muttukrishnan Rajarajan
dblp:80/3898
· DBLP profile ↗
84ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0001-5814-9922ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 29 · 1 first-author · 6 since 2021Security and privacy · 25 · 4 since 2021Artificial intelligence and machine learning · 11 · 3 since 2021Systems, architecture and hardware · 8 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Device behavioural blueprint (DB2): A risk-aware framework for unique device behaviour profiling using microarchitectural variationsabstractThis paper introduces DB 2 , a risk-aware behavioural identity framework that derives device identity from CPU–RTC timing deviation and Performance Monitoring Unit (PMU) microarchitectural events, without relying on GPUs, radios, sensors, or dedicated hardware. The method captures oscillator-coupled timing variation and execution behaviour through a structured signal-processing pipeline, producing device-specific behavioural signatures that remain distinguishable across reboots, temperature variation, and core transitions. DB 2 structures identity assurance into three layers: closed-set identification, calibrated open-set rejection, and stability-aware risk scoring. Evaluation under a strict three-way split with reboot separation for training, calibration, and unseen testing yields a macro-F 1 of 0.957 on unseen reboots. The open-set layer rejects previously unseen devices with a mean true-positive rate of 0.990 at a calibrated event-level false-reject rate of approximately 0.08 under strict leave-one-device-out validation, with operating-point selection performed exclusively on the calibration split. A Dynamic-Aware Identification and Risk (DAIR) mechanism decomposes behavioural stability across temperature, reboot, and core factors to provide interpretable posture monitoring for enrolled devices. Under identity-claim manipulation via spoofing, Sybil, and relabelling scenarios involving cloning, targeted identities exhibit reduced identification consistency and elevated risk, while non-targeted devices remain stable under identical calibration settings. These results show that behavioural fingerprints can be derived from standard CPU, RTC, and PMU-accessible resources on edge devices, enabling device-identity and behavioural-assurance monitoring in IoT and edge environments without specialised hardware. Muthupavithran Selvam, Safwana Haque, Amit Kumar Singh 0002, Zhan Cui, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 5 |
| 2025 | Quantum Secure Biometric Authentication in Decentralised SystemsabstractBiometric authentication has become integral to digital identity systems, particularly in smart cities where it enables secure access to services across governance, transportation, and public infrastructure. Centralised architectures, though widely used, pose privacy and scalability challenges due to the aggregation of sensitive biometric data. Decentralised identity frameworks offer better data sovereignty and eliminate single points of failure but introduce new security concerns, particularly around mutual trust among distributed devices. In such environments, biometric sensors and verification agents must authenticate one another before sharing sensitive biometric data. Existing authentication schemes rely on classical public key infrastructure, which is increasingly susceptible to quantum attacks. This work addresses this gap by proposing a quantum-secure communication protocol for decentralised biometric systems, built upon an enhanced Quantum Key Distribution (QKD) system. The protocol incorporates quantum-resilient authentication at both the classical and quantum layers of QKD: post-quantum cryptography (PQC) is used to secure the classical channel, while authentication qubits verify the integrity of the quantum channel. Once trust is established, QKD generates symmetric keys for encrypting biometric data in transit. Qiskit-based simulations show a key generation rate of 15 bits/sec and 89% efficiency. This layered, quantum-resilient approach offers scalable, robust authentication for next-generation smart city infrastructures. Tooba Qasim, Vasilios A. Siris, Izak Oosthuizen, Muttukrishnan Rajarajan, Sujit Biswas |
IJCB | 4 |
| 2024 | A privacy-aware authentication and usage-controlled access protocol for IIoT decentralized data marketplaceabstractData is ubiquitous, powerful and valuable today. With vast instalments of Industrial Internet-of-Things (IIoT) infrastructure, data is in abundance albeit sitting in organizational silos. Data Marketplaces have emerged to allow monetization of data by trading it with interested buyers. While centralized marketplaces are common, they are controlled by few and are non-transparent. Decentralized data marketplaces allow the democratization of rates, trading terms and fine control to participants. However, in such a marketplace, ensuring privacy and security is crucial. Existing data exchange schemes depend on a trusted third party for key management during authentication and rely on a ‘one-time-off’ approach to authorization. This paper proposes a user-empowered, privacy-aware, authentication and usage-controlled access protocol for IIoT data marketplace. The proposed protocol leverages the concept of Self-Sovereign Identity (SSI) and is based on the standards of Decentralized Identifier (DID) and Verifiable Credential (VC). DIDs empower buyers and give them complete control over their identities. The buyers authenticate and prove claims to access data securely using VC. The proposed protocol also implements a dynamic user-revocation policy. Usage-controlled based access provides secure ongoing authorization during data exchange. A detailed performance and security analysis is provided to show its feasibility. Akanksha Dixit 0001, Bruno Bogaz Zarpelão, Max Smith-Creasey, Muttukrishnan Rajarajan |
Comput. Secur. | 4 |
| 2023 | Open Banking API Security: Anomalous Access BehaviourabstractThird-party providers pose a significant risk for financial institutions owing to the manner in which banks expose their API to the public. Such threats include inadequate authentication, malicious injections, unsecure key handling. Therefore, financial institutions must adopt a series of countermeasures to mitigate threats exposed by third-party providers, and anomaly detection is considered one such method. In this paper, we develop random forests and a linear kernel SVM to compare the accuracy of our models in predicting anomalous user access behaviour. A dataset that presents users’ access behaviour as a numerical feature, including raw API call graphs, is utilised as a case study in this paper. Our novel approach of identifying a risk score and predicting it with a deep neural network showed a high degree of accuracy when the risk scores were developed as a multi-class classification problem Dawood Behbehani, Nikos Komninos, Khalid Al-Begain, Muttukrishnan Rajarajan |
INISTA | 4 |
| 2023 | Privacy vs Utility analysis when applying Differential Privacy on Machine Learning ClassifiersabstractIn this paper, we present how Differential Privacy (DP), the recent state-of-the-art privacy-preserving technologies, plays a role with four different Machine Learning (ML) classifiers. Preserving privacy while serving utility needs is a challenge for each ML implementation. To study the effects of different DP implementations on an ML method, we do perturbation at different phases of the ML cycle, such as perturbing data at its origin (Differential Privacy Method 1 - DPM1), during the training process (DPM2) or perturbing the parameters of the ML model generated (DPM3) and see the effect of privacy preservation on ML model utility. Further, we have tested with different perturbation methods such as the Laplace, Gaussian, Analytic Gaussian, Snapping, and Staircase mechanisms for DPM1 and analysed the results to know which one works better. We tested each case considered with varying privacy budgets. We have used privacy attacks such as the Membership Inference Attack (MIA) and the Attribute Inference Attack (AIA) to see the DP’s effect in protecting data privacy. Our experiment’s results showed that perturbing at later stages of an ML method provides better utility. When considering different DPM1 mechanisms, improved Laplace and Gaussian versions work better in utility while preserving privacy. Mathuranthagaa Selvarathnam, Roshan G. Ragel, Constantino Carlos Reyes-Aldasoro, Muttukrishnan Rajarajan |
WiMob | 4 |
| 2023 | FAST DATA: A Fair, Secure, and Trusted Decentralized IIoT Data Marketplace Enabled by BlockchainabstractAs the world calls it, data is the new oil. With vast installments of Industrial Internet of Things (IIoT) infrastructure, data is produced at a rate like never before. Similarly, artificial intelligence (AI) and machine learning (ML) solutions are getting integrated to numerous services, making them “smarter.” However, the data remain fragmented in individual organizational silos inhibiting data value extraction to its full potential. Digital marketplaces are emerging to allow data owners to monetize these data. Yet concerns, such as privacy, security, and unfair payment settlement deter adoption of such platforms. In addition, the state-of-the-art platforms are under the control of large multinational corporations with no transparency between the buyer and seller in terms of payment details, listing, data discovery, and storage. In this work, a novel decentralized platform of a digital data marketplace for IoT data has been proposed. The platform leverages a decentralized data streaming network to host IoT data in a reliable and fault-tolerant manner. The platform ensures fair trading, data storage, and delivery in a privacy-preserving manner and trust metric calculation for actors in the network. In order to study the feasibility of the proposed platform, an opensource library is developed using Hyperledger Fabric and data network layer built on VerneMQ, the library is deployed on a real-time Google cloud platform. The library is tested and results are analyzed for throughput, overheads, and scalability. Akanksha Dixit 0001, Yo Rahul, Muttukrishnan Rajarajan |
IEEE Internet Things J. | 4 |
| 2023 | A Novel Image-Based Homomorphic Approach for Preserving the Privacy of Autonomous Vehicles Connected to the CloudabstractAutonomous vehicles are taking a leap forward by performing operations without human intervention through continuous monitoring of their surroundings using multiple sensors. Images gathered through vehicle mounted cameras can be large, requiring specialized storage such as cloud. However, cloud data centres can be prone to security and privacy challenges. A partial image-based, homomorphic searchable encryption scheme is proposed, which uses pixel-level encryption to identify objects within encrypted images. The scheme provides Object-Trapdoor and Trapdoor-Image indistinguishability – as the trapdoors are probabilistic. The proposed scheme is deployed on a cloud data centre and tested over a real data set. The proposed scheme reduces storage overhead by approximately 20 times, and is 33 times more efficient compared to the generic Paillier homomorphic searchable encryption scheme. Security analysis demonstrates that the scheme maintains high levels of security and privacy. Aiman Sultan, Shahzaib Tahir, Hasan Tahir, Tayyaba Anwer, Fawad Khan, Muttukrishnan Rajarajan, Omer F. Rana |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | A New Scalable and Secure Access Control Scheme Using Blockchain Technology for IoTabstractThe growth of IoT devices is so rapid that several billions of such devices would be in use in a span of four-year period. Essential security mechanisms need to be put in place to curb several security attacks prevalent in IoT. Access control is an important security mechanism that ensures legitimate and controlled access to critical and limited resources in IoT. The current access control schemes for IoT could not handle burgeoning number of IoT devices, while meeting the necessary level of security. Consequently, in this paper, we propose a new scalable and secure access control scheme for IoT. With blockchain as the root-of-trust, the proposed scheme performs access control for the IoT devices without having the resource-constrained IoT devices to be part of the blockchain network and to possess substantial amount of blockchain data. Blockchain’s tamper-proof property makes it an ideal candidate to be chosen as the root-of-trust. The scheme is secure against various security attacks prevalent in IoT. A proof-of-concept implementation for the scheme is developed and deployed in Ethereum Mainnet. The transaction costs of the different operations in the scheme are fairly below USD 3. Furthermore, scalability of the proposed scheme in different scenarios is investigated. Sivaselvan N, Vivekananda Bhat K., Muttukrishnan Rajarajan, Ashok Kumar Das |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | A Decentralized IIoT Identity Framework based on Self-Sovereign Identity using BlockchainabstractThe fundamental requirement for interaction between digital entities is a secure and privacy-preserving digital identity infrastructure. Traditional approaches rely heavily on centralized architectural components such as Certificate Authorities (CAs) and credential storage databases that have drawbacks like a single point of failure, attack prone honeypot databases and poor scalability. Self-Sovereign Identity (SSI) is a novel decentralized digital identity model that uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). In this work, we propose a novel decentralized identity framework for Industrial Internet-of-Things (IIoT) based on SSI model. The proposed framework is implemented on two blockchain platforms namely Ethereum and Hyperledger Indy to study the underlying overheads. Akanksha Dixit 0001, Max Smith-Creasey, Muttukrishnan Rajarajan |
LCN | 3 |
| 2022 | Zero-day Ransomware Attack Detection using Deep Contractive Autoencoder and Voting based Ensemble Classifier
Umme Zahoora, Muttukrishnan Rajarajan, Zahoqing Pan, Asifullah Khan |
Appl. Intell. | 2 |
| 2022 | Modelling smart grid IT-OT dependencies for DDoS impact propagation
Dilara Acarali, K. Rajesh Rao, Muttukrishnan Rajarajan, Doron Chema, Mark Ginzburg |
Comput. Secur. | 3 |
| 2021 | SIUV: A Smart Car Identity Management and Usage Control System Based on Verifiable Credentials
Ali Hariri, Subhajit Bandopadhyay, Athanasios Rizos, Theodosis Dimitrakos, Bruno Crispo, Muttukrishnan Rajarajan |
SEC | 6 |
| 2021 | Role recommender-RBAC: Optimizing user-role assignments in RBAC
K. Rajesh Rao, Ashalatha Nayak, Indranil Ghosh Ray, Yo Rahul, Muttukrishnan Rajarajan |
Comput. Commun. | 5 |
| 2021 | Scalar Product Lattice Computation for Efficient Privacy-Preserving SystemsabstractPrivacy-preserving (PP) applications allow users to perform online daily actions without leaking sensitive information. The PP scalar product (PPSP) is one of the critical algorithms in many private applications. The state-of-the-art PPSP schemes use either computationally intensive homomorphic (public-key) encryption techniques, such as the Paillier encryption to achieve strong security (i.e., 128 b) or random masking technique to achieve high efficiency for low security. In this article, lattice structures have been exploited to develop an efficient PP system. The proposed scheme is not only efficient in computation as compared to the state-of-the-art but also provides a high degree of security against quantum attacks. Rigorous security and privacy analyses of the proposed scheme have been provided along with a concrete set of parameters to achieve 128-b and 256-b security. Performance analysis shows that the scheme is at least five orders faster than the Paillier schemes and at least twice as faster than the existing randomization technique at 128-b security. Also the proposed scheme requires six-time fewer data compared to the Paillier and randomization-based schemes for communications. Yo Rahul, Safak Dogan, Xiyu Shi, Rongxing Lu, Muttukrishnan Rajarajan, Ahmet M. Kondoz |
IEEE Internet Things J. | 5 |
| 2021 | Blockchain at the Edge: Performance of Resource-Constrained IoT NetworksabstractThe proliferation of IoT in various technological realms has resulted in the massive spurt of unsecured data. The use of complex security mechanisms for securing these data is highly restricted owing to the low-power and low-resource nature of most of the IoT devices, especially at the Edge. In this article, we propose to use blockchains for extending security to such IoT implementations. We deploy a Ethereum blockchain consisting of both regular and constrained devices connecting to the blockchain through wired and wireless heterogeneous networks. We additionally implement a secure and encrypted networked clock mechanism to synchronize the non-real-time IoT Edge nodes within the blockchain. Further, we experimentally study the feasibility of such a deployment and the bottlenecks associated with it by running necessary cryptographic operations for blockchains in IoT devices. We study the effects of network latency, increase in constrained blockchain nodes, data size, Ether, and blockchain node mobility during transaction and mining of data within our deployed blockchain. This study serves as a guideline for designing secured solutions for IoT implementations under various operating conditions such as those encountered for static IoT nodes and mobile IoT devices. Sudip Misra, Anandarup Mukherjee, Arijit Roy 0002, Nishant Saurabh, Yo Rahul, Muttukrishnan Rajarajan |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2020 | Modelling DoS Attacks & Interoperability in the Smart GridabstractSmart grids perform the crucial role of delivering electricity to millions of people and driving today's industries. However, the integration of physical operational technology (OT) with IT systems introduces many security challenges. Denial-of-Service (DoS) is a well-known IT attack with a large potential for damage within the smart grid. Whilst DoS is relatively well-understood in IT networks, the unique characteristics and requirements of smart grids bring up new challenges. In this paper, we examine this relationship and propose the OT impact chain to capture possible sequences of events resulting from an IT-side DoS attack. We then apply epidemic principles to explore the same dynamics using the proposed S-A-C model. Dilara Acarali, Muttukrishnan Rajarajan, Doron Chema, Mark Ginzburg |
ICCCN | 2 |
| 2020 | Smart-Contract Enabled Decentralized Identity Management Framework for Industry 4.0abstractIndustry 4.0 heavily uses connected machine paradigm to automate, track and maintain processes. However, a major challenge in Industrial Internet-of-Things (IIoT) remains managing the burgeoning number of sensors. The centralized framework for managing these devices is raising concerns. In this work, we propose a novel proof-of-concept framework for managing identity and access management policies for IIoT. The new framework is a smart contract enabled and blockchain based decentralized life-cycle and access management system. It is backed by decentralized storage technology InterPlanatery FileSystem (IPFS). Our framework is decentralized and scalable unlike the state-of-the-art IIoT management frameworks designed for clouds which are centralized. Akanksha Dixit 0001, Waqar Asif, Muttukrishnan Rajarajan |
IECON | 3 |
| 2020 | A parallelized disjunctive query based searchable encryption scheme for big data
Shahzaib Tahir, Liutauras Steponkus, Sushmita Ruj, Muttukrishnan Rajarajan, Ali Sajjad |
Future Gener. Comput. Syst. | 4 |
| 2020 | A New Lightweight Symmetric Searchable Encryption Scheme for String IdentificationabstractIn this paper, we provide an efficient and easy-to-implement symmetric searchable encryption scheme (SSE) for string search, which takes one round of communication, O(n) times of computations over n documents. Unlike previous schemes, we use hash-chaining instead of chain of encryption operations for index generation, which makes it suitable for lightweight applications. Unlike the previous SSE schemes for string search, with our scheme, server learns nothing about the frequency and the relative positions of the words being searched except what it can learn from the history. We are the first to propose probabilistic trapdoors in SSE for string search. We provide concrete proof of non-adaptive security of our scheme against honest-but-curious server based on the definitions of [12]. We also introduce a new notion of search pattern privacy, which gives a measure of security against the leakage from trapdoor. We have shown that our scheme is secure under search pattern indistinguishability definition. We show why SSE scheme for string search cannot attain adaptive indistinguishability criteria as mentioned in [12]. We also propose modifications of our scheme so that the scheme can be used against active adversaries at the cost of more rounds of communications and memory space. We validate our scheme against two different commercial datasets (see [1], [2]). Indranil Ghosh Ray, Yo Rahul, Muttukrishnan Rajarajan |
IEEE Trans. Cloud Comput. | 3 |
| 2019 | Security in networks of unmanned aerial vehicles for surveillance with an agent-based approach inspired by the principles of blockchain
Iván García-Magariño, Raquel Lacuesta Gilaberte, Muttukrishnan Rajarajan, Jaime Lloret Mauri |
Ad Hoc Networks | 3 |
| 2019 | Fuzzy keywords enabled ranked searchable encryption scheme for a public Cloud environment
Shahzaib Tahir, Sushmita Ruj, Ali Sajjad, Muttukrishnan Rajarajan |
Comput. Commun. | 4 |
| 2019 | A novel word-independent gesture-typing continuous authentication scheme for mobile devices
Max Smith-Creasey, Muttukrishnan Rajarajan |
Comput. Secur. | 2 |
| 2019 | Modelling the Spread of Botnet Malware in IoT-Based Wireless Sensor NetworksabstractThe propagation approach of a botnet largely dictates its formation, establishing a foundation of bots for future exploitation. The chosen propagation method determines the attack surface and, consequently, the degree of network penetration, as well as the overall size and the eventual attack potency. It is therefore essential to understand propagation behaviours and influential factors in order to better secure vulnerable systems. Whilst botnet propagation is generally well studied, newer technologies like IoT have unique characteristics which are yet to be thoroughly explored. In this paper, we apply the principles of epidemic modelling to IoT networks consisting of wireless sensor nodes. We build IoT-SIS, a novel propagation model which considers the impact of IoT-specific characteristics like limited processing power, energy restrictions, and node density on the formation of a botnet. Focusing on worm-based propagation, this model is used to explore the dynamics of spread using numerical simulations and the Monte Carlo method to discuss the real-life implications of our findings. Dilara Acarali, Muttukrishnan Rajarajan, Nikos Komninos, Bruno Bogaz Zarpelão |
Secur. Commun. Networks | 2 |
| 2019 | Privacy-Preserving iVector-Based Speaker VerificationabstractThis paper introduces an efficient algorithm to develop a privacy-preserving voice verification based on iVector and linear discriminant analysis techniques. This research considers a scenario in which users enrol their voice biometric to access different services (i.e., banking). Once enrolment is completed, users can verify themselves using their voice print instead of alphanumeric passwords. Since a voice print is unique for everyone, storing it with a third-party server raises several privacy concerns. To address this challenge, this paper proposes a novel technique based on randomization to carry out voice authentication, which allows the user to enrol and verify their voice in the randomized domain. To achieve this, the iVector-based voice verification technique has been redesigned to work on the randomized domain. The proposed algorithm is validated using a well-known speech dataset. The proposed algorithm neither compromises the authentication accuracy nor adds additional complexity due to the randomization operations. Yo Rahul, Kunaraj R. Sutharsini, Indranil Ghosh Ray, Rongxing Lu, Muttukrishnan Rajarajan |
IEEE ACM Trans. Audio Speech Lang. Process. | 5 |
| 2018 | Modelling Botnet Propagation in Networks with Layered DefencesabstractBotnets are still a pertinent threat to our digital infrastructure and a central topic for study in the cyber-research community. At the start of a botnet's life, the aim of the botmaster is to achieve enough spread to make their botnet functional and as potent as possible. Therefore, propagation dynamics are a vital area to address in order to effectively defend against this type of malware. Over the years, there have been many propagation models based on the principles of disease spread but these often do not take specific network characteristics into account. In this paper, we propose the novel use of a probabilistic adaptation of the SEIR (Susceptible, Exposed, Infected, Recovered) model applied to defence-in-depth networks with heterogeneous contact rates and node impact. We test this approach through numerical simulation and discuss our findings. Dilara Acarali, Muttukrishnan Rajarajan, Nikos Komninos |
ISNCC | 2 |
| 2018 | Privacy-preserving Anonymization with Restricted Search (PARS) on Social Network Data for Criminal InvestigationsabstractSocial network platforms have become the new norm for ensuring swift dissemination of information to a large audience. This has thus made these platforms a preferred choice of communication for many criminal organizations who tend to use them for their own iniquitous gains. These organizations take cover behind the user data/identity privacy policies, such as the General Data Protection Regulation (GDPR) [2] and Safe Harbor [4], which limit the Law Enforcement Agencies (LEAs) from accessing and analysing social media data without the consent of the users. Their veil is complemented by the fact that these malicious organization can operate from any part of the world and LEAs from different countries dither in sharing intelligence information among themselves. To overcome this issue, in this paper we propose a novel Privacy-preserving Anonymization with Restricted Search (PARS) approach which will provide LEAs with the leverage they need to access and analyse social media data without compromising individual privacy. We propose a new privacy concious node grouping approach that antagonizes relational information of a social network platform and we compliment this approach with the Public-key Encryption with Keyword Search (PEKS) mechanism that will enable LEAs to perform a restrictive search among each others' dataset without violating the privacy or leakage of the entire dataset to a third party. The proposed approach is applied on a Twitter dataset comprising of 277359 users that comment, re-tweet and/or like 11528 tweets and encryption and search times are evaluated. Furthermore, the proposed approach is tested for the effect of anonymization on information entropy of the twitter dataset. Waqar Asif, Indranil Ghosh Ray, Shahzaib Tahir, Muttukrishnan Rajarajan |
SNPD | 4 |
| 2018 | Detection of Bitcoin-Based Botnets Using a One-Class Classifier
Bruno Bogaz Zarpelão, Rodrigo Sanches Miani, Muttukrishnan Rajarajan |
WISTP | 3 |
| 2018 | Increasing user controllability on device specific privacy in the Internet of Things
Waqar Asif, Muttukrishnan Rajarajan, Marios Lestas |
Comput. Commun. | 2 |
| 2018 | Scale Inside-Out: Rapid Mitigation of Cloud DDoS AttacksabstractThe distributed denial of service (DDoS) attacks in cloud computing requires quick absorption of attack data. DDoS attack mitigation is usually achieved by dynamically scaling the cloud resources so as to quickly identify the onslaught features to combat the attack. The resource scaling comes with an additional cost which may prove to be a huge disruptive cost in the cases of longer, sophisticated, and repetitive attacks. In this work, we address an important problem, whether the resource scaling during attack, always result in rapid DDoS mitigation? For this purpose, we conduct real-time DDoS attack experiments to study the attack absorption and attack mitigation for various target services in the presence of dynamic cloud resource scaling. We found that the activities such as attack absorption which provide timely attack data input to attack analytics, are adversely compromised by the heavy resource usage generated by the attack. We show that the operating system level local resource contention, if reduced during attacks, can expedite the overall attack mitigation. The attack mitigation would otherwise not be completed by the dynamic scaling of resources alone. We conceived a novel relation which terms “Resource Utilization Factor” for each incoming request as the major component in forming the resource contention. To overcome these issues, we propose a new “Scale Inside-out” approach which during attacks, reduces the “Resource Utilization Factor” to a minimal value for quick absorption of the attack. The proposed approach sacrifices victim service resources and provides those resources to mitigation service in addition to other co-located services to ensure resource availability during the attack. Experimental evaluation shows up to 95 percent reduction in total attack downtime of the victim service in addition to considerable improvement in attack detection time, service reporting time, and downtime of co-located services. Gaurav Somani 0001, Manoj Singh Gaur, Dheeraj Sanghi, Mauro Conti, Muttukrishnan Rajarajan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2017 | sPECTRA: A precise framEwork for analyzing CrypTographic vulneRabilities in Android appsabstractThe majority of Android applications (apps) deals with user's personal data. Users trust these apps and allow them to access all sensitive data. Cryptography, when employed in an appropriate way, can be used to prevent misuse of data. Unfortunately, cryptographic libraries also include vulnerable cryptographic services. Since Android app developers may not be cryptographic experts, this makes apps become the target of various attacks due to cryptographic vulnerabilities. In this work, we present sPECTRA: an automated framework for analyzing wide range of cryptographic vulnerabilities in Android apps at large scale. sPECTRA is more precise and accurate in comparison to state-of-the-art approaches as it reduces both false negatives and false positives. The inclusion of Intelligent UI exploration during dynamic analysis makes sPECTRA deployable to analyze apps at large scale. Moreover, sPECTRA works on apk files without the need of any source code. We evaluate sPECTRA on 7,000 apps collected from 7 most popular Android app stores. Results indicate that 90% of apps are exploitable because of cryptographic vulnerabilities. We made sPECTRA available as an open source. Jyoti Gajrani, Meenakshi Tripathi, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti, Muttukrishnan Rajarajan |
CCNC | 6 |
| 2017 | Privacy preserving encrypted phonetic search of speech dataabstractThis paper presents a strategy for enabling speech recognition to be performed in the cloud whilst preserving the privacy of users. The approach advocates a demarcation of responsibilities between the client and server-side components for performing the speech recognition task. On the client-side resides the acoustic model, which symbolically encodes the audio and encrypts the data before uploading to the server. The server-side then employs searchable encryption to enable the phonetic search of the speech content. Some preliminary results for speech encoding and searchable encryption are presented. Cornelius Glackin, Gérard Chollet, Nazim Dugan, Nigel Cannings, Julie A. Wall, Shahzaib Tahir, Indranil Ghosh Ray, Muttukrishnan Rajarajan |
ICASSP | 8 |
| 2017 | A CAPTCHA model based on visual psychophysics: Using the brain to distinguish between human users and automated computer bots
Seyed Mohammad RezaSaadat Beheshti, Panos Liatsis, Muttukrishnan Rajarajan |
Comput. Secur. | 3 |
| 2017 | PIndroid: A novel Android malware detection system using ensemble learning methods
Fauzia Idrees, Muttukrishnan Rajarajan, Mauro Conti, Thomas M. Chen, Yo Rahul |
Comput. Secur. | 2 |
| 2017 | Location attestation and access control for mobile devices using GeoXACML
Saritha Arunkumar, Berker Soyluoglu, Murat Sensoy, Mudhakar Srivatsa, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 5 |
| 2017 | Cloud Security Engineering: Theory, Practice and Future ResearchabstractThe eleven papers in this special issue address security and privacy concerns associated with cloud computing. This special issue is dedicated to the identification of techniques that enable security mechanisms to be engineered and implemented in cloud services and cloud systems. A key focus is on the integration of theoretical foundations with practical deployment of security strategies that make cloud systems more secure for both end users and providers – enabling end users to increase the level of trust they have in cloud service providers – and conversely for cloud service providers to provide greater guarantees to end users about the security of their services and data. Kim-Kwang Raymond Choo, Omer F. Rana, Muttukrishnan Rajarajan |
IEEE Trans. Cloud Comput. | 3 |
| 2017 | Efficient Privacy-Preserving Facial Expression ClassificationabstractThis paper proposes an efficient algorithm to perform privacy-preserving (PP) facial expression classification (FEC) in the client-server model. The server holds a database and offers the classification service to the clients. The client uses the service to classify the facial expression (FaE) of subject. It should be noted that the client and server are mutually untrusted parties and they want to perform the classification without revealing their inputs to each other. In contrast to the existing works, which rely on computationally expensive cryptographic operations, this paper proposes a lightweight algorithm based on the randomization technique. The proposed algorithm is validated using the widely used JAFFE and MUG FaE databases. Experimental results demonstrate that the proposed algorithm does not degrade the performance compared to existing works. However, it preserves the privacy of inputs while improving the computational complexity by$120$times and communication complexity by$31$percent against the existing homomorphic cryptography based approach. Yo Rahul, Muttukrishnan Rajarajan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | Smart, secure and seamless access control scheme for mobile devicesabstractSmart devices capture users' activity such as unlock failures, application usage, location and proximity of devices in and around their surrounding environment. This activity information varies between users and can be used as digital fingerprints of the users' behaviour. Traditionally, users are authenticated to access restricted data using long term static attributes such as password and roles. In this paper, in order to allow secure and seamless data access in mobile environment, we combine both the user behaviour captured by the smart device and the static attributes to develop a novel access control technique. Security and performance analyses show that the proposed scheme substantially reduces the computational complexity while enhances the security compared to the conventional schemes. Yo Rahul, Muttukrishnan Rajarajan, Raphael C.-W. Phan |
ICC | 2 |
| 2016 | A continuous user authentication scheme for mobile devicesabstractFace and touch modalities have independently been shown to yield promising results for continuous user authentication. In this study, we present a novel framework that combines these modalities. We show a stacked classifier approach can be used to improve the continuous authentication on mobile devices and address some prevalent issues with the current state-of-the-art. We use a state-of-the-art public dataset containing face and touch-gesture modalities for 50 users. Features are extracted from each modality for each user. We train a set of classifiers for user modalities to provide probability scores on a sample. The scores capture the nuances of each sample and are concatenated into a vector. This vector is used in a meta-level classifier. The scores we obtain from the meta-level classifiers show our approach performs better than previous continuous authentication approaches. We achieve an equal error rate of 3.77% for a single sample. We also show the added robustness a multi-modal approach provides if one modality is compromised. Max Smith-Creasey, Muttukrishnan Rajarajan |
PST | 2 |
| 2016 | Survey of approaches and features for the identification of HTTP-based botnet traffic
Dilara Acarali, Muttukrishnan Rajarajan, Nikos Komninos, Ian Herwono |
J. Netw. Comput. Appl. | 2 |
| 2016 | Optimization based spectral partitioning for node criticality assessment
Waqar Asif, Marios Lestas, Hassaan Khaliq Qureshi, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 4 |
| 2016 | Combined Banzhaf & Diversity Index (CBDI) for critical node detection
Waqar Asif, Hassaan Khaliq Qureshi, Muttukrishnan Rajarajan, Marios Lestas |
J. Netw. Comput. Appl. | 3 |
| 2016 | User Collusion Avoidance Scheme for Privacy-Preserving Decentralized Key-Policy Attribute-Based EncryptionabstractDecentralized attribute-based encryption (ABE) is a variant of multi-authority based ABE whereby any attribute authority (AA) can independently join and leave the system without collaborating with the existing AAs. In this paper, we propose a user collusion avoidance scheme which preserves the user's privacy when they interact with multiple authorities to obtain decryption credentials. The proposed scheme mitigates the well-known user collusion security vulnerability found in previous schemes. We show that our scheme relies on the standard complexity assumption (decisional bilienar Deffie-Hellman assumption). This is contrast to previous schemes which relies on non-standard assumption (q-decisional Diffie-Hellman inversion). Yo Rahul, Suresh Veluru 0001, Jinguang Han, Fei Li 0012, Muttukrishnan Rajarajan, Rongxing Lu |
IEEE Trans. Computers | 5 |
| 2015 | Assessing Data Breach Risk in Cloud SystemsabstractThe emerging cloud market introduces a multitude of cloud service providers, making it difficult for consumers to select providers who are likely to be a low risk from a security perspective. Recently, significant emphasis has arisen on the need to specify Service Level Agreements that address security concerns of consumers (referred to as SecSLAs) -- these are intended to clarify security support in addition to Quality of Service characteristics associated with services. It has been found that such SecSLAs are not consistent among providers, even though they offer services with similar functionality. However, measuring security service levels and the associated risk plays an important role when choosing a cloud provider. Data breaches have been identified as a high priority threat influencing the adoption of cloud computing. This paper proposes a general analysis framework which can compute risk associated with data breaches based on pre-agreed SecSLAs for different cloud providers. The framework exploits a tree based structure to identify possible attack scenarios that can lead to data breaches in the cloud and a means of assessing the use of potential mitigation strategies to reduce such breaches. Yo Rahul, Muttukrishnan Rajarajan, Omer F. Rana, Malik Shahzad Kaleem Awan, Pete Burnap, Sajal K. Das 0001 |
CloudCom | 2 |
| 2015 | Feature selection and data balancing for activity recognition in smart homesabstractActivities performed in the same location in a smart home share common features and thus become difficult to classify. We propose an activity recognition approach that identifies key features from the information obtained using the sensors deployed in multiple locations and objects. Key features increase the separability between the classes, making the approach suitable for overlapping activities. For fewer number of activity instances in a class, we apply an oversampling approach for data balancing. The classification is performed using a learning method Evidence Theoretic K-Nearest Neighbors (ET-KNN), which performs better in uncertain conditions. Evaluation of the proposed approach using three publicly available smart home datasets demonstrates better recognition performance compared to the existing methods. Labiba Gillani Fahad, Syed Fahad Tahir, Muttukrishnan Rajarajan |
ICC | 3 |
| 2015 | Hide-and-seek: Face recognition in privateabstractRecent trend towards cloud computing and outsourcing has led to the requirement for face recognition (FR) to be performed remotely by third-party servers. When outsourcing the FR, client's test image and classification result will be revealed to the servers. Within this context, we propose a novel privacy-preserving (PP) FR algorithm based on randomization. Existing PP FR algorithms are based on homomorphic encryption (HE) which requires higher computational power and communication bandwidth. Since we use randomization, the proposed algorithm outperforms the HE based algorithm in terms of computational and communication complexity. We validated our algorithm using popular ORL database. Experimental results demonstrate that accuracy of the proposed algorithm is the same as the accuracy of existing algorithms, while improving the computational efficiency by 120 times and communication complexity by 2.5 times against the existing HE based approach. Yo Rahul, Muttukrishnan Rajarajan |
ICC | 2 |
| 2015 | Anomalies Detection in Smart-Home ActivitiesabstractAnomalies are the instances of an activity class that deviate from the normal or expected sequence of events in their performance. In this paper we propose an anomaly detection approach for activities performed in a smart home. In order to detect anomalies, we exploit the information of number of events and the time duration involved in performing an activity instance. The information is obtained through a network of wireless sensors deployed at multiple objects and locations within a smart home. We apply a density based clustering algorithm on the recognized activity instances to separate the normal from the anomalous. Evaluation of the proposed approach on two publicly available smart home datasets demonstrates its effectiveness in identifying the anomalous activity instances. Labiba Gillani Fahad, Muttukrishnan Rajarajan |
ICMLA | 2 |
| 2015 | Spectral partitioning for node criticalityabstractFinding critical nodes in a network is a significant task, highly relevant to network vulnerability and security. We consider the node criticality problem as an algebraic connectivity minimization problem where the objective is to choose nodes which minimize the algebraic connectivity of the resulting network. Previous suboptimal solutions of the problem suffer from the computational complexity associated with the implementation of a maximization consensus algorithm. In this work, we use spectral partitioning concepts introduced by Fiedler, to propose a new suboptimal solution which significantly reduces the implementation complexity. Our approach, combined with recently proposed distributed Fiedler vector calculation algorithms enable each node to decide by itself whether it is a critical node. If a single node is required then the maximization algorithm is applied on a restricted set of nodes within the network. We derive a lower bound for the achievable algebraic connectivity when nodes are removed from the network and we show through simulations that our approach leads to algebraic connectivity values close to this lower bound. Similar behaviour is exhibited by other approaches at the expense, however, of a higher implementation complexity. Waqar Asif, Marios Lestas, Hassaan Khaliq Qureshi, Muttukrishnan Rajarajan |
ISCC | 4 |
| 2015 | Robust access control framework for mobile cloud computing network
Fei Li 0012, Yo Rahul, Mauro Conti, Muttukrishnan Rajarajan |
Comput. Commun. | 4 |
| 2015 | Intrusion alert prioritisation and attack detection using post-correlation analysis
Riyanat O. Shittu, Alex Healing, Robert A. Ghanea-Hercock, Robin E. Bloomfield, Muttukrishnan Rajarajan |
Comput. Secur. | 5 |
| 2015 | Reasoning with streamed uncertain information from unreliable sources
Saritha Arunkumar, Murat Sensoy, Mudhakar Srivatsa, Muttukrishnan Rajarajan |
Expert Syst. Appl. | 4 |
| 2015 | A scalable and dynamic application-level secure communication framework for inter-cloud services
Ali Sajjad, Muttukrishnan Rajarajan, Andrea Zisman, Theodosis Dimitrakos |
Future Gener. Comput. Syst. | 2 |
| 2015 | Activity recognition in smart homes with self verification of assignments
Labiba Gillani Fahad, Asifullah Khan, Muttukrishnan Rajarajan |
Neurocomputing | 3 |
| 2015 | A review paper on preserving privacy in mobile environments
Saritha Arunkumar, Mudhakar Srivatsa, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 3 |
| 2015 | Employing Program Semantics for Malware DetectionabstractIn recent years, malware has emerged as a critical security threat. In addition, malware authors continue to embed numerous anti-detection features to evade the existing malware detection approaches. Against this advanced class of malicious programs, dynamic behavior-based malware detection approaches outperform the traditional signature-based approaches by neutralizing the effects of obfuscation and morphing techniques. The majority of dynamic behavior detectors rely on system-calls to model the infection and propagation dynamics of malware. However, these approaches do not account an important anti-detection feature of modern malware, i.e., systemcall injection attack. This attack allows the malicious binaries to inject irrelevant and independent system-calls during the program execution thus modifying the execution sequences defeating the existing system-call-based detection. To address this problem, we propose an evasion-proof solution that is not vulnerable to system-call injection attacks. Our proposed approach characterizes program semantics using asymptotic equipartition property (AEP) mainly applied in information theoretic domain. The AEP allows us to extract information-rich call sequences that are further quantified to detect the malicious binaries. Furthermore, the proposed detection model is less vulnerable to call-injection attacks as the discriminating components are not directly visible to malware authors. We run a thorough set of experiments to evaluate our solution and compare it with the existing system-call-based malware detection techniques. The results demonstrate that the proposed solution is effective in identifying real malware instances. Smita Naval, Vijay Laxmi, Muttukrishnan Rajarajan, Manoj Singh Gaur, Mauro Conti |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | An Analysis of Tracking Settings in Blackberry 10 and Windows Phone 8 Smartphones
Yo Rahul, Veelasha Moonsamy, Lynn Margaret Batten, Su Shunliang, Muttukrishnan Rajarajan |
ACISP | 5 |
| 2014 | Who Is Going to Be the Next BitTorrent Peer Idol?abstractActive measurement studies show that the Peer-to-Peer (P2P) file sharing protocol Bit Torrent is highly under attack. Moreover, malicious peers can easily exploit the original seeding algorithm and therefore reduce the efficiency of this protocol. In this paper, we propose a novel seeding algorithm that requests peers to vote for their best sharing peers. Our results show that this incentive mechanism makes Bit Torrent harder to exploit without losing performance. In some situations our algorithm even outperform other seeding algorithms. The peer exchange - that comes as a side effect - reduces the dependency on a centralized tracker and increases the robustness and the efficiency. We studied the effectiveness of our approach in a real testbed comprising 32 peers. Florian Adamsky, Syed Ali Khayam, Rudolf Jäger, Muttukrishnan Rajarajan |
EUC | 4 |
| 2014 | CBDI: Combined Banzhaf & diversity index for finding critical nodesabstractCritical node discovery plays a vital role in assessing the vulnerability of a network to an abrupt change, such as an adversarial attack or human intervention. In this paper, we propose a new metric to characterize the criticality of a node in an arbitrary network which we refer to as the Combined Banzhaf & Diversity Index (CBDI). The metric utilizes a diversity index which is based on the variability of a node's attributes relative to its neighbors and the Banzhaf Power Index which characterizes the degree of participation of a node in forming shortest paths. The Banzhaf power index is inspired from the theory of voting games in game theory. We evaluate the performance of the new metric using simulations. Our results indicate that in a number of network topologies, the proposed metric outperforms other proposals which have appeared in the literature. The proposed CBDI index chooses more critical nodes which, when removed, degrade network performance to a greater extent than if critical nodes based on other criticality metrics were removed. Waqar Asif, Hassaan Khaliq Qureshi, Muttukrishnan Rajarajan, Marios Lestas |
GLOBECOM | 3 |
| 2014 | Activity Recognition in Smart Homes Using Clustering Based ClassificationabstractActivity recognition in smart homes plays an important role in healthcare by maintaining the well being of elderly and patients through remote monitoring and assisted technologies. In this paper, we propose a two level classification approach for activity recognition by utilizing the information obtained from the sensors deployed in a smart home. In order to separates the similar activities from the non similar activities, we group the homogeneous activities using the Lloyd's clustering algorithm. For the classification of non-separated activities within each cluster, we apply a computationally less expensive learning algorithm Evidence Theoretic K-Nearest Neighbor, which performs better in uncertain conditions and noisy data. The approach enables us to achieve improved recognition accuracy particularly for overlapping activities. A comparison of the proposed approach with the existing activity recognition approaches is presented on two publicly available smart home datasets. The proposed approach demonstrates better recognition rate compared to the existing methods. Labiba Gillani Fahad, Syed Fahad Tahir, Muttukrishnan Rajarajan |
ICPR | 3 |
| 2014 | LSD-ABAC: Lightweight static and dynamic attributes based access control scheme for secure data access in mobile environmentabstractTechnology advancements in smart mobile devices empower mobile users by enhancing mobility, customizability and adaptability of computing environments. Mobile devices are now intelligent enough to capture dynamic attributes such as unlock failures, application usage, location and proximity of devices in and around its surrounding environment. Different users will have different set of values for these dynamic attributes. In traditional attribute based access control, users are authenticated to access restricted data using long term static attributes such as password, roles, and physical location. In this paper, in order to allow secure data access in mobile environment, we securely combine both the dynamic and static attributes and develop novel access control technique. Security and performance analyse show that the proposed scheme substantially reduces the computational complexity while enhances the security compare to the conventional schemes. Fei Li 0012, Yo Rahul, Muttukrishnan Rajarajan |
LCN | 3 |
| 2014 | OutMet: A new metric for prioritising intrusion alerts using correlation and outlier analysisabstractIn a medium sized network, an Intrusion Detection System (IDS) could produce thousands of alerts a day many of which may be false positives. In the vast number of triggered intrusion alerts, identifying those to prioritise is highly challenging. Alert correlation and prioritisation are both viable analytical methods which are commonly used to understand and prioritise alerts. However, to the author's knowledge, very few dynamic prioritisation metrics exist. In this paper, a new prioritisation metric - OutMet, which is based on measuring the degree to which an alert belongs to anomalous behaviour is proposed. OutMet combines alert correlation and prioritisation analysis. We illustrate the effectiveness of OutMet by testing its ability to prioritise alerts generated from a 2012 red-team cyber-range experiment that was carried out as part of the BT Saturn programme. In one of the scenarios, OutMet significantly reduced the false-positives by 99.3%. Riyanat O. Shittu, Alex Healing, Robert A. Ghanea-Hercock, Robin E. Bloomfield, Muttukrishnan Rajarajan |
LCN | 5 |
| 2014 | P-SPADE: GPU accelerated malware packer detectionabstractPacked malware imposes negative impact on the accuracy of AV scanners. It is essential for a security researcher to nullify the effects of packing tools, prior to malware detection. Numerous open and commercial packers are available to facilitate unwelcome intentions of malware authors. Thus, identification of packers becomes necessary phase prior to malware scanning. In this paper, we have proposed a GPGPU based approach for accelerating our previous signature based packer detection (SPADE) [1] method. SPADE generates packer signature by utilizing the intra-family malware alignments. It makes use of Smith-Waterman algorithm to reveal the actual relationship among the packer family samples and achieves high detection rate as compared to other packer detection tools. The use of Smith-Waterman comes with a trade off between accuracy and high computational complexity. So, we have implemented a parallel version of Smith-Waterman to improve the signature generation phase of SPADE. Our GPU based approach (O(m+n)) produces 14.89X to 49.91X speedup over CPU based implementation of SPADE preserving detection accuracy. Moreover, the proposed approach opens up new domain of applying GPUs to the existing signature based approaches for malware detection where signature database updation is done on daily basis. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, Muttukrishnan Rajarajan |
PST | 5 |
| 2014 | The Uncertainty of Identity Toolset: Analysing Digital Traces for User ProfilingabstractPeople manage a spectrum of identities in cyber domains. Profiling individuals and assigning them to distinct groups or classes have potential applications in targeted services, online fraud detection, extensive social sorting, and cyber-security. This paper presents the Uncertainty of Identity Toolset, a framework for the identification and profiling of users from their social media accounts and e-mail addresses. More specifically, in this paper we discuss the design and implementation of two tools of the framework. The Twitter Geographic Profiler tool builds a map of the ethno-cultural communities of a person's friends on Twitter social media service. The E-mail Address Profiler tool identifies the probable identities of individuals from their e-mail addresses and maps their geographical distribution across the UK. To this end, this paper presents a framework for profiling the digital traces of individuals. Muhammad Adnan 0008, Antonio Lima, Luca Rossi 0004, Suresh Veluru 0001, Paul A. Longley, Mirco Musolesi, Muttukrishnan Rajarajan |
SIN | 7 |
| 2014 | Exploring Worm Behaviors using DTWabstractWorms are becoming a potential threat to Internet users across the globe. The financial damages due to computer worms increased significantly in past few years. Analyzing these hazardous worm attacks has become a crucial issue to be addressed. Given the fact that worm analysts would prefer to analyze classes of worms rather than individual files, their task will be significantly reduced. In this paper, we have proposed a dynamic host--based worm categorization approach to segregate worms. These groups indicate that worm samples constitute different behavior according to their infection and anti--detection vectors. Our proposed approach utilizes system--call traces and computes a distance matrix using Dynamic Time Warping (DTW) algorithm to form these groups. In conjunction to that, the proposed approach also discriminates worm and benign executables. The constructed model is further evaluated with unknown instances of real--world worms. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, Muttukrishnan Rajarajan |
SIN | 5 |
| 2014 | Analysing Security requirements in Cloud-based Service Level AgreementsabstractIn cloud computing, measurable services such as packet loss and memory are quantized into different levels to provide different level of services to users. Initially, there will be a service level agreement (SLA) between users and service providers (SPs) and/or SPs and infrastructure providers (IPs). However, the most crucial service required by the users and SPs in cloud computing is security and privacy. Security parameters can be used to prevent attacks and to protect data and systems. In literature, there is no comprehensive solution which quantify all the security parameters associated with the cloud computing paradigm. In this paper, for the first time, we attempt to generalize and quantify the security parameters. Yo Rahul, Pramod S. Pawar, Pete Burnap, Muttukrishnan Rajarajan, Omer F. Rana, George Spanoudakis |
SIN | 4 |
| 2014 | Evaluation of Android Anti-malware Techniques against Dalvik Bytecode ObfuscationabstractPopularity and growth of Android mobile devices has paved the way for exploiting popular apps using various Dalvik byte code transformation methods. Testing the antimalware techniques against obfuscation identifies the need of proposing effective detection methods. In this paper, we explore the resilience of anti-malware techniques against transformations for Android. The Proposed approach employs variable compression, native code wrapping and register renaming, in addition to already implemented transformations on Dalvik byte code. Evaluation results indicate low resilience of the antimalware detection engines against code obfuscation. Furthermore, we evaluate resilience of Androguard's code similarity and AndroSimilar's robust statistical feature signature against code obfuscated malware. Parvez Faruki, Ammar Bharmal, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti, Muttukrishnan Rajarajan |
TrustCom | 6 |
| 2014 | Data-centric Rogue Node Detection in VANETsabstractVehicular ad hoc networks (VANETs) are the future of vehicular technology and Traffic Information Systems. In VANETs vehicles communicate by different types of beacon messages to inform each other of their position and speed to give them a sense of traffic around them. Vehicles can also send emergency messages in case of accidents or other hazards. The very fast moving nodes have to act quickly based on these emergency messages. However, a rogue node which sends false emergency messages can wreak havoc in the network that may even result in fatalities. This paper develops and simulates a technique to detect a rogue node that is sending false emergency messages in VANETs by cooperative exchange of data without the need of any infrastructure or revocation list. Also, the proposed mechanism will make VANETs fault tolerant and resilient against injection of false data. Kamran Zaidi, Milos Milojevic, Veselin Rakocevic, Muttukrishnan Rajarajan |
TrustCom | 4 |
| 2014 | Investigating the android intents and permissions for malware detectionabstractMobile phones are mastering our day to day scheduling, entertainment, information and almost every aspect of life. With the increasing human dependence on smart phones, threats against these devices have also increased exponentially. Almost all the mobile apps are playing with the mobile user's privacy besides the targeted actions by the malicious apps. Android applications use permissions to use different features and resources of mobile device along with the intents to launch different activities. Various aspects of permission framework have been studied but sufficient attention has not been given to the intent framework. This work is first of its kind which is investigating the combined effects of permissions and intent filters to distinguish between the malware and benign apps. This paper proposes a novel approach to identify the malicious apps by analyzing the permission and intent patterns of android apps. This approach is supplemented with the machine learning algorithms for further classification of apps. Performance of proposed approach has been validated by applying the technique to the available malicious and benign samples collected from a number of sources. Fauzia Idrees, Muttukrishnan Rajarajan |
WiMob | 2 |
| 2014 | Stealing bandwidth from BitTorrent seeders
Florian Adamsky, Syed Ali Khayam, Rudolf Jäger, Muttukrishnan Rajarajan |
Comput. Secur. | 4 |
| 2014 | Privacy-Preserving Multi-Class Support Vector Machine for Outsourcing the Data Classification in CloudabstractEmerging cloud computing infrastructure replaces traditional outsourcing techniques and provides flexible services to clients at different locations via Internet. This leads to the requirement for data classification to be performed by potentially untrusted servers in the cloud. Within this context, classifier built by the server can be utilized by clients in order to classify their own data samples over the cloud. In this paper, we study a privacy-preserving (PP) data classification technique where the server is unable to learn any knowledge about clients’ input data samples while the server side classifier is also kept secret from the clients during the classification process. More specifically, to the best of our knowledge, we propose the first known client-server data classification protocol using support vector machine. The proposed protocol performs PP classification for both two-class and multi-class problems. The protocol exploits properties of Pailler homomorphic encryption and secure two-party computation. At the core of our protocol lies an efficient, novel protocol for securely obtaining the sign of Pailler encrypted numbers. Yo Rahul, Raphael C.-W. Phan, Suresh Veluru 0001, K. Cumanan, Muttukrishnan Rajarajan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2014 | Privacy-Preserving Clinical Decision Support System Using Gaussian Kernel-Based ClassificationabstractA clinical decision support system forms a critical capability to link health observations with health knowledge to influence choices by clinicians for improved healthcare. Recent trends toward remote outsourcing can be exploited to provide efficient and accurate clinical decision support in healthcare. In this scenario, clinicians can use the health knowledge located in remote servers via the Internet to diagnose their patients. However, the fact that these servers are third party and therefore potentially not fully trusted raises possible privacy concerns. In this paper, we propose a novel privacy-preserving protocol for a clinical decision support system where the patients' data always remain in an encrypted form during the diagnosis process. Hence, the server involved in the diagnosis process is not able to learn any extra knowledge about the patient's data and results. Our experimental results on popular medical datasets from UCI-database demonstrate that the accuracy of the proposed protocol is up to 97.21% and the privacy of patient data is not compromised. Yo Rahul, Suresh Veluru 0001, Raphael C.-W. Phan, Jonathon A. Chambers, Muttukrishnan Rajarajan |
IEEE J. Biomed. Health Informatics | 5 |
| 2013 | E-mail address categorization based on semantics of surnamesabstractSurname (family name) analysis is used in geography to understand population origins, migration, identity, social norms and cultural customs. Some of these are supposedly evolved over generations. Surnames exhibit good statistical properties that can be used to extract information in names data set such as automatic detection of ethnic or community groups in names. An e-mail address, often contains surname as a substring. This containment may be full or partial. An e-mail address categorization based on semantics of surnames is the objective of this paper. This is achieved in two phases. First phase deals with surname representation and clustering. Here, a vector space model is proposed where latent semantic analysis is performed. Clustering is done using the method called average-linkage method. In the second phase, an email is categorized as belonging to one of the categories (discovered in first phase). For this, substring matching is required, which is done in an efficient way by using suffix tree data structure. We perform experimental evaluation for the 500 most frequently occurring surnames in India and United Kingdom. Also, we categorize the e-mail addresses that have these surnames as substrings. Suresh Veluru 0001, Yo Rahul, Viswanath Pulabaigari, Paul A. Longley, Muttukrishnan Rajarajan |
CIDM | 5 |
| 2013 | Long term analysis of daily activities in smart home
Labiba Gillani Fahad, Muttukrishnan Rajarajan |
ESANN | 3 |
| 2013 | A survey of intrusion detection techniques in Cloud
Chirag N. Modi, Dhiren R. Patel, Bhavesh Borisaniya, Hiren Patel, Avi Patel, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 6 |
| 2013 | Editorial for Security and Privacy in Wireless Networks Special Issue
Muttukrishnan Rajarajan, Steven Furnell |
Mob. Networks Appl. | 1 |
| 2013 | Recommendations in a heterogeneous service environment
Christian Überall, Christopher Köhnen, Veselin Rakocevic, Rudolf Jäger, Erich Hoy, Muttukrishnan Rajarajan |
Multim. Tools Appl. | 6 |
| 2013 | A survey on security issues and solutions at different layers of Cloud computing
Chirag N. Modi, Dhiren R. Patel, Bhavesh Borisaniya, Avi Patel, Muttukrishnan Rajarajan |
J. Supercomput. | 5 |
| 2013 | Evaluation and improvement of CDS-based topology control for wireless sensor networks
Hassaan Khaliq Qureshi, Sajjad Rizvi, Muhammad Saleem 0001, Syed Ali Khayam, Veselin Rakocevic, Muttukrishnan Rajarajan |
Wirel. Networks | 6 |
| 2012 | A novel framework for intrusion detection in cloudabstractOne of the major security challenges in cloud computing is the detection and prevention of denial-of-service (DoS) attacks. In order to detect and prevent DoS attacks as well as other malicious activities at the network layer, we propose a framework which integrates a network intrusion detection system (NIDS) in the Cloud infrastructure. We use snort and decision tree (DT) classifier to implement this framework. It aims to detect network attacks in Cloud by monitoring network traffic, while maintaining performance and service quality. To validate our approach, we evaluate the performance and detection efficiency by using the freely available NSL-KDD and KDD experimental intrusion datasets. The results show that the proposed framework has a higher detection rate with low false positives at an affordable computational cost. Chirag N. Modi, Dhiren R. Patel, Bhavesh Borisaniya, Avi Patel, Muttukrishnan Rajarajan |
SIN | 5 |
| 2012 | A1: An energy efficient topology control algorithm for connected area coverage in wireless sensor networks
Sajjad Rizvi, Hassaan Khaliq Qureshi, Syed Ali Khayam, Veselin Rakocevic, Muttukrishnan Rajarajan |
J. Netw. Comput. Appl. | 5 |
| 2011 | Poster: Destabilizing BitTorrent's clusters to attack high bandwidth leechers
Florian Adamsky, Muttukrishnan Rajarajan, Syed Ali Khayam, Rudolf Jäger |
CCS | 3 |
| 2011 | Poly: A reliable and energy efficient topology control protocol for wireless sensor networks
Hassaan Khaliq Qureshi, Sajjad Rizvi, Muhammad Saleem 0001, Syed Ali Khayam, Veselin Rakocevic, Muttukrishnan Rajarajan |
Comput. Commun. | 6 |
| 2010 | Enhancements to Statistical Protocol IDentification (SPID) for Self-Organised QoS in LANsabstractSince most real-time audio and video applications lack of QoS support, QoS demand of such IP data streams shall be detected and applied automatically. To support QoS in LANs, especially in home environments, a system was developed, which enables self-organised QoS for unmanaged networks through host implementations in contrast to traditional solutions without network support. It supports per-link reservation and prioritisation and works without a need for application support. One part of this system is an automated traffic identification and classification system, which is subject of this paper. An efficient set of attribute meters, based on the Statistical Protocol IDentification (SPID), was investigated, enhanced and evaluated. We improved the performance, added support for UDP protocols and real-time identification. It is shown that using our implementation efficient near real-time protocol identification on per-flow basis is possible to support self-organised resource reservation. Christopher Köhnen, Christian Überall, Florian Adamsky, Veselin Rakocevic, Muttukrishnan Rajarajan, Rudolf Jäger |
ICCCN | 5 |
| 2010 | Security framework for mobile bankingabstractThe banking sector is always looking for new services delivery platforms to improve customer confidence and satisfaction. To achieve this, the banking service delivery platform must provide end-to-end security to safeguard the information exchange between the bank and the customer. With the increased penetration of mobile phones in the market place the banks are looking for mobile phones as the major revenue generating platform for the delivery of banking and financial services. Today a number of banks offer mobile banking service to their customers. However, still banks have been adopting the generic user authentication systems that was developed for the desktop environment or other complex authentication systems with a number of user intrusive activities. Therefore, the usability and adoption of the mobile banking technology has been extremely slow. This paper presents a novel authentication and authorization framework for secure mobile banking applications. The proposed protocol enables users to authenticate with the banking services with minimum user interactions but with novel advance security features. Dasun Weerasinghe, Veselin Rakocevic, Muttukrishnan Rajarajan |
MoMM | 3 |
| 2009 | Recommendation index for DVB content using Service informationabstractThis paper presents algorithms and techniques to generate recommendations for DVB content. The developed recommendation engine uses metadata which are delivered by the DVB transport stream, the Service Information. The creation of user profiles, which contains the preferences of an individual user, is described. Personalization strategies, to filter the interesting contents for each user, will be shown. Furthermore new developed and firstly presented algorithms to generate recommendations for DVB content are listed and described. A PPG (Personal Program Guide), which has been developed to visualize the recommendations is shown, too. Several tests show the usefulness of the developed recommendation scheme. Christian Überall, Muttukrishnan Rajarajan, Veselin Rakocevic, Rudolf Jäger, Christopher Köhnen |
ICME | 2 |