EDBT 2026 Demo / reviewers in the wild / expert
Manoj Singh Gaur
dblp:80/7311
· DBLP profile ↗
90ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-0497-721XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 52 · 4 first-author · 5 since 2021Systems, architecture and hardware · 17 · 1 since 2021Computer networks · 11 · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PANDORA: Lightweight Adversarial Defense for Edge IoT using Uncertainty-Aware Metric Learning
Avinash Awasthi, Pritam Vediya, Hemant Miranka, Ramesh Babu Battula, Manoj Singh Gaur |
NDSS | 5 |
| 2025 | Learning to detect PII: Tabular vs. Document classification models for network traffic analysisabstractDetecting Personally Identifiable Information (PII) exfiltration from mobile network traffic is critical for preserving user privacy. Traditional approaches rely on machine learning classifiers trained on manually engineered features extracted from network packets. Deep learning offers the potential to remove the reliance on such an external feature selection process; however, its effectiveness depends significantly on how underlying packets are encoded. In this work, we investigate deep learning paradigms for PII detection with a focus on the impact of feature encoding strategies. We explore tabular modeling approaches, including both an existing architecture (FT-Transformer) and proposed modular frameworks that integrates a pretrained language model (all-MiniLM-L6-v2) for semantic feature embeddings, followed by a classifier. We also evaluate document classification modeling by applying pretrained language models such as TinyBERT directly to the raw packet content. We further demonstrate the feasibility of on-device inference by deploying trained models using ONNX and TensorFlow Lite. Finally, we recommend modeling strategies based on data size , performance , resource utilization , and generalizability , enabling model selection according to the primary requirement of the deployment scenario. Rishika Kohli, Shaifu Gupta, Manoj Singh Gaur, Soma S. Dhavala |
J. Inf. Secur. Appl. | 3 |
| 2024 | GAN-based Seed Generation for Efficient Fuzzing
Shyamili Toluchuri, Aishwarya Upadhyay, Smita Naval, Vijay Laxmi, Manoj Singh Gaur |
SECRYPT | 5 |
| 2023 | Adaptive distribution of control messages for improving bandwidth utilization in multiple NoC
Sonal Yadav, Vijay Laxmi, Hemangee K. Kapoor, Manoj Singh Gaur, Amit Kumar 0046 |
J. Supercomput. | 4 |
| 2022 | QoS-aware Mesh-based Multicast Routing Protocols in Edge Ad Hoc Networks: Concepts and ChallengesabstractMulticast communication plays a pivotal role in Edge based Mobile Ad hoc Networks (MANETs). MANETs can provide low-cost self-configuring devices for multimedia data communication that can be used in military battlefield, disaster management, connected living, and public safety networks. A Multicast communication should increase the network performance by decreasing the bandwidth consumption, battery power, and routing overhead. In recent years, a number of multicast routing protocols (MRPs) have been proposed to resolve above listed challenges. Some of them are used for dynamic establishment of reliable route for multimedia data communication. This article provides a detailed survey of the merits and demerits of the recently developed techniques. An ample study of various Quality of Service (QoS) techniques and enhancement is also presented. Later, mesh topology-based MRPs are classified according to enhancement in routing mechanism and QoS modification. This article covers the most recent, robust, and reliable QoS-aware mesh based MRPs, classified on the basis of their operational features, and pros and cons. Finally, a comparative study has been presented on the basis of their performance parameters on the proposed protocols. Gaurav Singal, Vijay Laxmi, Manoj Singh Gaur, D. Vijay Rao, Riti Kushwaha, Deepak Garg 0002, Neeraj Kumar 0001 |
ACM Trans. Internet Techn. | 3 |
| 2021 | MapperDroid: Verifying app capabilities from description to permissions and API calls
Rajendra Kumar Solanki, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
Comput. Secur. | 4 |
| 2021 | Scaling & fuzzing: Personal image privacy from automated attacks in mobile cloud computing
Shweta Saharan, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
J. Inf. Secur. Appl. | 4 |
| 2020 | Edge Preserving Image Fusion using Intensity Variation ApproachabstractIn this article, a novel edge preserving image fusion method is proposed by merging multiple images captured from different imaging sensors. The objective of this paper is to highlight the informative contents of multiple images into a single fused image. Fusion of data from multiple sensors is a difficult task as the imaging modality are different and sensors capturing the data may be affected by sensors noise. As the images captured from multiple sensors possess uncertainty within a pixel due to the multi-valued level of brightness. It is obvious that a deterministic method of fusion may not give a better results. Hence, it is required to explore the use of fuzzy sets theoretic approaches in this regard. The proposed scheme follow three stages. In the first stage of the algorithm, a resultant image is obtained by setting the maximum value between the pixel intensity of visible and infrared sub-images considered within a small spatial neighborhood. The edges of the visible image are preserved in the second stage of the algorithm using a Fuzzy edge technique. Finally the fused image is obtained by combining the obtained resultant image and the edges of the visible image. In order to evaluate the performance of the proposed method quantitatively, and qualitatively experiments were carried out on publicly available benchmark database, "TNO-database". The proposed method is compared with those of eight state-of-the-arts techniques. The experimental results of the proposed method attained state-of-the-art performance in objective assessment and visual quality assessment. Badri N. Subudhi, Veerakumar Thangaraj, Manoj Singh Gaur |
TENCON | 4 |
| 2020 | Multiple-NoC Exploration and Customization for Energy Efficient Traffic DistributionabstractMotivation. As more on-chip computation resources are available, the Networks-on-Chip (NoC) power consumption is expected to increase in the future many-core era. Many of these would have to be switched off while inactive to keep power consumption and chip temperature low. However, the NoC infrastructure must be kept alive to serve shared caches and memory accesses. A recent study shows that the proportion of NoC power consumption becomes appreciable in comparison to computation counterpart. A 32 core chip at 45nm substantially raises NoC power ( ~ 42%) among the remaining on-chip active resources (cores, shared caches, memory controllers, PCIe controllers) [1]. Therefore, low power becomes the primary objective for modern NoC designs. Sonal Yadav, Vijay Laxmi, Manoj Singh Gaur |
VLSI-SOC | 3 |
| 2020 | SPARK: Secure Pseudorandom Key-based Encryption for Deduplicated Storage
Jay Dave, Parvez Faruki, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Mauro Conti |
Comput. Commun. | 5 |
| 2020 | EspyDroid+: Precise reflection analysis of android apps
Jyoti Gajrani, Umang Agarwal, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur, Meenakshi Tripathi, Akka Zemmari |
Comput. Secur. | 5 |
| 2020 | SneakLeak+: Large-scale klepto apps analysis
Shweta Bhandari, Frédéric Herbreteau, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Partha S. Roop |
Future Gener. Comput. Syst. | 5 |
| 2020 | TRACK: An algorithm for fault-tolerant, dynamic and scalable 2D mesh network-on-chip routing reconfiguration
Anugrah Jain, Vijay Laxmi, Meenakshi Tripathi, Manoj Singh Gaur, Rimpy Bishnoi |
Integr. | 4 |
| 2020 | QuickDedup: Efficient VM deduplication in cloud computing environments
Shweta Saharan, Gaurav Somani 0001, Robin Verma, Manoj Singh Gaur, Rajkumar Buyya |
J. Parallel Distributed Comput. | 5 |
| 2019 | MAPPER: Mapping Application Description to Permissions
Rajendra Kumar Solanki, Vijay Laxmi, Manoj Singh Gaur |
CRiSIS | 3 |
| 2019 | Improving Static Power Efficiency via Placement of Network Demultiplexer over Control Plane of Router in Multi-NoCsabstractNetwork Demultiplexer (Net-Demux) is an essential hardware unit in multiple NoCs for traffic distribution between the NoC networks. This paper proposes a novel idea of the placement of Net-Demux at the control plane of switch allocator of the router to improve static power and energy efficiency as compared to conventional data plane placement at the Network Interface (NI). Sonal Yadav, Vijay Laxmi, Manoj Singh Gaur, Hemangee K. Kapoor |
DAC | 3 |
| 2019 | SLDP: A secure and lightweight link discovery protocol for software defined networking
Ajay Nehra, Meenakshi Tripathi, Manoj Singh Gaur, Ramesh Babu Battula, Chhagan Lal |
Comput. Networks | 3 |
| 2019 | ETGuard: Detecting D2D attacks using wireless Evil Twins
Vineeta Jain, Vijay Laxmi, Manoj Singh Gaur, Mohamed Mosbah 0001 |
Comput. Secur. | 3 |
| 2019 | S2DIO: an extended scalable 2D mesh network-on-chip routing reconfiguration for efficient bypass of link failures
Anugrah Jain, Vijay Laxmi, Meenakshi Tripathi, Manoj Singh Gaur, Rimpy Bishnoi |
J. Supercomput. | 4 |
| 2018 | Privacy Preserving Data Offloading Based on Transformation
Shweta Saharan, Vijay Laxmi, Manoj Singh Gaur, Akka Zemmari |
CRiSIS | 3 |
| 2018 | SWORD: Semantic aWare andrOid malwaRe Detector
Shweta Bhandari, Rekha Panihar, Smita Naval, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur |
J. Inf. Secur. Appl. | 6 |
| 2018 | Scale Inside-Out: Rapid Mitigation of Cloud DDoS AttacksabstractThe distributed denial of service (DDoS) attacks in cloud computing requires quick absorption of attack data. DDoS attack mitigation is usually achieved by dynamically scaling the cloud resources so as to quickly identify the onslaught features to combat the attack. The resource scaling comes with an additional cost which may prove to be a huge disruptive cost in the cases of longer, sophisticated, and repetitive attacks. In this work, we address an important problem, whether the resource scaling during attack, always result in rapid DDoS mitigation? For this purpose, we conduct real-time DDoS attack experiments to study the attack absorption and attack mitigation for various target services in the presence of dynamic cloud resource scaling. We found that the activities such as attack absorption which provide timely attack data input to attack analytics, are adversely compromised by the heavy resource usage generated by the attack. We show that the operating system level local resource contention, if reduced during attacks, can expedite the overall attack mitigation. The attack mitigation would otherwise not be completed by the dynamic scaling of resources alone. We conceived a novel relation which terms “Resource Utilization Factor” for each incoming request as the major component in forming the resource contention. To overcome these issues, we propose a new “Scale Inside-out” approach which during attacks, reduces the “Resource Utilization Factor” to a minimal value for quick absorption of the attack. The proposed approach sacrifices victim service resources and provides those resources to mitigation service in addition to other co-located services to ensure resource availability during the attack. Experimental evaluation shows up to 95 percent reduction in total attack downtime of the victim service in addition to considerable improvement in attack detection time, service reporting time, and downtime of co-located services. Gaurav Somani 0001, Manoj Singh Gaur, Dheeraj Sanghi, Mauro Conti, Muttukrishnan Rajarajan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Enhancing QoE for video streaming in MANETs via multi-constraint routing
Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti |
Wirel. Networks | 3 |
| 2017 | sPECTRA: A precise framEwork for analyzing CrypTographic vulneRabilities in Android appsabstractThe majority of Android applications (apps) deals with user's personal data. Users trust these apps and allow them to access all sensitive data. Cryptography, when employed in an appropriate way, can be used to prevent misuse of data. Unfortunately, cryptographic libraries also include vulnerable cryptographic services. Since Android app developers may not be cryptographic experts, this makes apps become the target of various attacks due to cryptographic vulnerabilities. In this work, we present sPECTRA: an automated framework for analyzing wide range of cryptographic vulnerabilities in Android apps at large scale. sPECTRA is more precise and accurate in comparison to state-of-the-art approaches as it reduces both false negatives and false positives. The inclusion of Intelligent UI exploration during dynamic analysis makes sPECTRA deployable to analyze apps at large scale. Moreover, sPECTRA works on apk files without the need of any source code. We evaluate sPECTRA on 7,000 apps collected from 7 most popular Android app stores. Results indicate that 90% of apps are exploitable because of cryptographic vulnerabilities. We made sPECTRA available as an open source. Jyoti Gajrani, Meenakshi Tripathi, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti, Muttukrishnan Rajarajan |
CCNC | 4 |
| 2017 | Detecting Inter-App Information Leakage PathsabstractSensitive (private) information can escape from one app to another using one of the multiple communication methods provided by Android for inter-app communication. This leakage can be malicious. In such a scenario, individual benign app, in collusion with other conspiring apps, if present, can leak the private information. In this work in progress, we present, a new model-checking based approach for inter-app collusion detection. The proposed technique takes into account simultaneous analysis of multiple apps. We are able to identify any set of conspiring apps involved in the collusion. To evaluate the efficacy of our tool, we developed Android apps that exhibit collusion through inter-app communication. Eight demonstrative sets of apps have been contributed to widely used test dataset named DroidBench. Our experiments show that proposed technique can accurately detect the presence/absence of collusion among apps. To the best of our knowledge, our proposal has improved detection capability than other techniques. Shweta Bhandari, Frédéric Herbreteau, Vijay Laxmi, Akka Zemmari, Partha S. Roop, Manoj Singh Gaur |
AsiaCCS | 6 |
| 2017 | Detection of Information Leaks via Reflection in Android AppsabstractReflection is a language feature which allows to analyze and transform the behavior of classes at the runtime. Reflection is used for software debugging and testing. Malware authors can leverage reflection to subvert the malware detection by static analyzers. Reflection initializes the class, invokes any method of class, or accesses any field of class. But, instead of utilizing usual programming language syntax, reflection passes classes/methods etc. as parameters to reflective APIs. As a consequence, these parameters can be constructed dynamically or can be encrypted by malware. These cannot be detected by state-of-the-art static tools. We propose EspyDroid, a system that combines dynamic analysis with code instrumentation for a more precise and automated detection of malware employing reflection. We evaluate EspyDroid on 28 benchmark apps employing major reflection categories. Our technique show improved results over FlowDroid via detection of additional undetected flows. These flows have potential to leak sensitive and private information of the users, through various sinks. Jyoti Gajrani, Li Li 0029, Vijay Laxmi, Meenakshi Tripathi, Manoj Singh Gaur, Mauro Conti |
AsiaCCS | 5 |
| 2017 | Unraveling Reflection Induced Sensitive Leaks in Android Apps
Jyoti Gajrani, Vijay Laxmi, Meenakshi Tripathi, Manoj Singh Gaur, Daya Ram Sharma, Akka Zemmari, Mohamed Mosbah 0001, Mauro Conti |
CRiSIS | 4 |
| 2017 | Flooding in secure wireless sensor networks: Student contributionabstractThe flooding algorithm remains one of the simplest and most effective ways to quickly disseminate information across all nodes in a Wireless Sensor Network. Though fast, this algorithm remains unsecure as the packets can be intercepted by malice agents to reveal the information. In this paper, simulations of a flooding algorithm in Sensor Networks secured by a Random Key Pre-distribution model are presented. We conducted these simulations on ns-3 over a theoretical Peer-to-peer and a standard based IEEE 802.15.4 network. This is followed by a demonstration of the robustness of the network through a random black hole attack. Jimmy Bondu, Anupal Mishra, Vijay Laxmi, Manoj Singh Gaur |
SIN | 4 |
| 2017 | Secure and efficient proof of ownership for deduplicated cloud storageabstractThe rapid increment in volume of outsourced data has raised an issue of data management for Cloud Storage Server. To solve this issue, Deduplication, a data compression technique was introduced which avoids duplicate data storage. However, Deduplication is vulnerable to malicious access to genuine Cloud Clients' files. An adversary can get access to file by learning small piece of knowledge about the file. In this paper, we propose secure and efficient Proof of Ownership for Deduplicated Cloud Storage. Our approach employs a technique of random matrix based challenges retrieved from the file. We evaluate security and efficiency of our approach by theoretical proofs and experimental results. Jay Dave, Parvez Faruki, Vijay Laxmi, Bezawada Bruhadeshwar, Manoj Singh Gaur |
SIN | 5 |
| 2017 | 'Global view' in SDN: existing implementation, vulnerabilities & threatsabstractSoftware Defined Network (SDN) provides a programmable and flexible network with separation in data and control plane. SDN has the capability to maintain a `Global View' at the cotroller which is the core of all SDN promises. A global view refers to the information about existence of switches, links between switches and attached hosts. A global view provides support for several topology aware applications such as shortest routing path, link load balancer, etc. In this research article, we examine how different controllers specifically POX, Ryu, OpenDaylight, Floodlight, Beacon, ONOS, HPEVAN discover links to achieve `Global view'. Furthermore it discusses vulnerabilities in these existing implementations. It also provides a analysis of the resulting threats namely Link Layer Discovery Protocol (LLDP) poisoning, LLDP flooding, & LLDP replay attack on these controllers. Ajay Nehra, Meenakshi Tripathi, Manoj Singh Gaur |
SIN | 3 |
| 2017 | A comprehensive and effective mechanism for DDoS detection in SDNabstractDDoS attack is one of the major concerns for network and cloud service providers, due to its substantial impact on revenue/cost and especially on their reputation. Also, network administrators are looking for solutions to manage voluminous data traffic. SDN is an emerging networking paradigm that provides a flexible network management. Hence, SDN is being widely adopted for wired, wireless, and mobile networks. Apart from a single point of failure (the controller), an attacker can target SDN at various levels by DDoS attacks. Existing solutions either focus on a particular attack type or require cumbersome alterations in SDN infrastructure. In this paper, we propose a comprehensive, yet effective and lightweight approach to detect various fundamentally different DDoS attacks in SDN. Our approach relies on sequential analysis. We employ a non-parametric change point detection technique called Cumulative Sum (CuSum). Our framework also includes an adaptive threshold scheme that adapts with the changing traffic pattern. Additionally, our framework can be tuned to suffice critical security requirements such as high detection rate and low false alarm rate. We evaluated the effectiveness of our solution using CAIDA Internet traces as well as DARPA intrusion detection evaluation dataset. Our results confirm the effectiveness of our mechanism. In particular, average false alarm rate in our experiments was under 11.64%. On average, our method is able to detect DDoS attacks within 4.15 seconds. Mauro Conti, Ankit Gangwal, Manoj Singh Gaur |
WiMob | 3 |
| 2017 | Multi-constraints link stable multicast routing protocol in MANETs
Gaurav Singal, Vijay Laxmi, Manoj Singh Gaur, Swati Todi, D. Vijay Rao, Meenakshi Tripathi, Riti Kushwaha |
Ad Hoc Networks | 3 |
| 2017 | DDoS attacks in cloud computing: Issues, taxonomy, and future directions
Gaurav Somani 0001, Manoj Singh Gaur, Dheeraj Sanghi, Mauro Conti, Rajkumar Buyya |
Comput. Commun. | 2 |
| 2017 | Android inter-app communication threats and detection techniques
Shweta Bhandari, Wafa Ben Jaballah, Vineeta Jain, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur, Mohamed Mosbah 0001, Mauro Conti |
Comput. Secur. | 6 |
| 2017 | Moralism: mobility prediction with link stability based multicast routing protocol in MANETs
Gaurav Singal, Vijay Laxmi, Manoj Singh Gaur, D. Vijay Rao |
Wirel. Networks | 3 |
| 2016 | Intersection Automata Based Model for Android Application CollusionabstractAndroid applications need to access and share user's sensitive data. To maintain user's privacy and related data security, it is essential to protect this data. Android security framework enforces permission protected model but it has been shown that applications can bypass this security model. Attacks based on such unauthorized privileges are known as Inter-Component Communication (ICC) Collusion Attacks. In this paper, we propose, a novel automaton framework that allows effective detection of intent based collusion. Our detection framework operates at the component-level. To evaluate our proposal, we developed 14 applications and took 4 applications from Google Play Store. We took all possible combinations from the set of 21 applications. We tested our approach on 210 pairs of applications derived from the set of 21 applications. Time and space complexity of our proposed approach isO(n) where n is the number of components in all the applications under analysis. The experimental results demonstrate that our technique is scalable to application sizing and more efficient as compared to other state of the art approaches. Shweta Bhandari, Vijay Laxmi, Akka Zemmari, Manoj Singh Gaur |
AINA | 4 |
| 2016 | FlowMine: Android app analysis via data flowabstractThe demeanor towards sensitive data is an important factor to differentiate malicious apps from benign apps in Android platform. In this work, we consider the data flow path from a data source to a data sink, where `source' is a non-constant data that marks the beginning of the path, and `sink' is the resource where the data reaches. To accurately identify the behavioral differences, we analyzed the data flow paths in 2800 benign apps against 15000 malicious apps. We assigned weights to each path which is the absolute difference between its use in benign and malicious samples. If a path is more used by malicious apps, then weight becomes negative otherwise positive. We assigned rankings according to the popularity of the path. If the benignity rank of a path is higher than its malignity rank, then it can be inferred that the path is more used by benign application. We cover all possible paths in an application based on context-sensitivity, flow-sensitivity, and object-sensitivity of data. We name our proposed solution FlowMine. FlowMine takes these rankings and weights as its contrivance and evaluates the behavior of any test application towards maliciousness or benignity. For evaluation purpose, we took 5000 benign and 10000 malware samples. To the best of our knowledge, FlowMine is the first approach that finds the degree of similarity of an unknown sample app with known benign and malware samples for the classification of app. Our prototype excelled and correctly classified 96% of all benign apps and 98% of all novel malware leaking sensitive data. Lovely Sinha, Shweta Bhandari, Parvez Faruki, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti |
CCNC | 4 |
| 2016 | ELBA: Efficient Layer Based Routing Algorithm in SDNabstractAdaptive streaming dynamically adapts video quality level according to the perceived device status and network conditions. It requires several representations of the same content, each encoded at different quality rates. As a representative example, H.264/SVC eliminates the requirement of redundant representations, improving the efficiency of caching and storage infrastructure. SVC video consists of a "Base Layer" and one or more of "Enhancement Layers". These layers have inter-dependencies and different QoS requirements. On another side, SDN allows forwarding tables to be adjusted dynamically, enabling us to route every individual flow differently. In this paper, we propose ELBA, an algorithm for scalable video streaming over SDN. ELBA utilizes the dynamic re-routing capability of SDN, to stream different layers of SVC coded video over possibly different suitable paths. In the proposed video streaming system, we use a novel mechanism to exchange information between the control plane and streaming servers. We have compared the performance of our approach with traditional Internet routing technique. Our evaluation results show that our proposal is not only feasible but in particular, it significantly outperforms the traditional Internet routing approach in terms of QoE. Ankit Gangwal, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti |
ICCCN | 3 |
| 2016 | DDoS attacks in cloud computing: Collateral damage to non-targets
Gaurav Somani 0001, Manoj Singh Gaur, Dheeraj Sanghi, Mauro Conti |
Comput. Networks | 2 |
| 2016 | Colluding browser extension attack on user privacy and its implication for web browsers
Anil Saini, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti |
Comput. Secur. | 2 |
| 2015 | d2-LBDR: distance-driven routing to handle permanent failures in 2D mesh NOCs
Rimpy Bishnoi, Vijay Laxmi, Manoj Singh Gaur, José Flich |
DATE | 3 |
| 2015 | DRACO: DRoid analyst combo an android malware analysis frameworkabstractAndroid being the most popular open source mobile operating system, attracts a plethora of app developers. Millions of applications are developed for Android platform with a great extent of behavioral diversities and are available on Play Store as well as on many third party app stores. Due to its open nature, in the past Android Platform has been targeted by many malware writers. The conventional way of signature-based detection methods for detecting malware on a device are no longer promising due to an exponential increase in the number of variants of the same application with different signatures. Moreover, they lack in dynamic analysis too. In this paper, we propose DRACO, which employs a two-phase detection technique that blends the synergy of both static and dynamic analysis. It has two modules, client module that is in the form an Android app and gets installed on mobile devices and a server module that runs on a server. DRACO also explains user about the features contributing to the maliciousness of analyzed app and generates scoring for that maliciousness. It does not require any root or super-user privileges. In an evaluation of 18,000 benign applications and 10,000 malware samples, DRACO performs better than several related existing approaches and detects 98.4% of the malware with few false alerts. On ten popular smartphones, the method requires an average of 6 seconds for on device analysis and 90 seconds on server analysis. Shweta Bhandari, Vijay Laxmi, Manoj Singh Gaur, Akka Zemmari, Maxim Anikeev |
SIN | 4 |
| 2015 | DynaDroid: dynamic binary instrumentation based app behavior monitoring frameworkabstractAndroid OS market share has made it a feverish target of malicious attacks. Dynamic Binary Instrumentation (DBI) based tools are gaining prominence for behavioral program inspection, feature identification and virtual machine binary code translation. DBI has an advantage of being transparent, i.e. the application under inspection is never modified. In this paper we describe DynaDroid, DBI framework developed to build behavior based binary instrumentation methodology to effectively monitor Android Package (APK) behavior. Unlike the existing behavior monitoring approaches, the proposed DynaDroid reconstructs the Dalvik level and Java level semantics at a time. The proposed dynamic behavior approach can provide base for analyzing the native calls, Dalvik instructions and also generate profile for Java based API activity. We plan to build effective instrumentation framework to detect real malware with lightweight overhead. Bharat Buddhdev, Rati Bhan, Manoj Singh Gaur, Vijay Laxmi |
SIN | 3 |
| 2015 | A robust dynamic analysis system preventing SandBox detection by Android malwareabstractDue to an increase in the number of Android malware applications and their diversity, it has become necessary for the security community to develop automated dynamic analysis systems. Static analysis has its limitations that can be overcome by dynamic analysis. Many tools based on dynamic analysis approach have been developed which employ emulated/virtualized environment for analysis. While it has been an effective technique for analysis, it can be espied and evaded by recent sophisticated malware. Malware families such as Pincer, AnserverBot, BgServ, Wroba have incorporated methods to check the presence of emulated or virtualized environment. Once the presence of the sandbox is detected, they do not execute any malicious behavior. In this paper, a robust emulated environment has been proposed and developed that is resilient against most of the detection techniques. We have compared our malware analysis tool DroidAnalyst against 12 publicly available dynamic analysis services and shown that our service is best when considering resilience against anti-emulation techniques. Incorporation of anti anti-detection techniques in the dynamic analysis that are purely based on emulation hinders the detection and evasion of emulated environment by malware. Jyoti Gajrani, Jitendra Sarswat, Meenakshi Tripathi, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti |
SIN | 5 |
| 2015 | sandFOX: secure sandboxed and isolated environment for firefox browserabstractBrowser functionalities can be widely extended by browser extensions. One of the key features that makes browser extensions so powerful is that they run with "high" privileges. As a consequence, a vulnerable or malicious extension might expose browser, and operating system (OS) resources to possible attacks such as privilege escalation, information stealing, and session hijacking. The resources are referred as browser as well as OS components accessed through browser extension such as accessing information on the web application, executing arbitrary processes, and even access files from a host file system. Anil Saini, Manoj Singh Gaur, Vijay Laxmi, Priyadarsi Nanda |
SIN | 2 |
| 2015 | DDoS/EDoS attack in cloud: affecting everyone out there!abstractDDoS attacks have become fatal attacks in recent times. There are large number of incidents which have been reported recently and caused heavy downtime and economic losses. Evolution of utility computing models like cloud computing and its adoption across enterprises is visible due to many promising features. Effects of DDoS attacks in cloud are no more similar to what they were in traditional fixed or on premise infrastructure. In addition to effects on the service, economic or sustainability effects are significant in the form of Economic Denial of Sustainability (EDoS) attacks. We argue that in a multi-tenant public cloud, multiple stakeholders are involved other than the victim server. Some of these important stakeholders are co-hosted virtual servers, physical server(s), network and, cloud service providers. We have shown through system analysis, experiments and simulations that these stakeholders are indeed affected though they are not the actual targets. Effects to other stakeholders include performance interference, web service performance, resource race, indirect EDoS, downtime and, business losses. Cloud scale simulations have revealed that overall energy consumption and no. of VM migrations are adversely affected due to DDoS/EDoS attacks. Losses to these stakeholders should be properly accounted and there is a need to devise methods to isolate these components well. Gaurav Somani 0001, Manoj Singh Gaur, Dheeraj Sanghi |
SIN | 2 |
| 2015 | Editorial: Special issue on security of information and networks
Atilla Elçi, Mehmet A. Orgun, Alexander G. Chefranov, Manoj Singh Gaur |
J. Inf. Secur. Appl. | 4 |
| 2015 | AndroSimilar: Robust signature for detecting variants of Android malware
Parvez Faruki, Vijay Laxmi, Ammar Bharmal, Manoj Singh Gaur, Vijay Ganmoor |
J. Inf. Secur. Appl. | 4 |
| 2015 | JellyFish attack: Analysis, detection and countermeasure in TCP-based MANET
Vijay Laxmi, Chhagan Lal, Manoj Singh Gaur, Deepanshu Mehta |
J. Inf. Secur. Appl. | 3 |
| 2015 | A Brief Comment on "A Complete Self-Testing and Self-Configuring NoC Infrastructure for Cost-Effective MPSoCs" [ACM Transactions on Embedded Computing Systems 12 (2013) Article 106]abstractIn the Ghiribaldi et al. [2013] paper, a complete self-testing and self configuring NoC infrastructure for cost-effective MPSoCs was presented in order to make NoC architecture tolerant to faults. To overcome the complexity involved during the complete reconfiguration of routing instances in the face of most of the usual failure patterns, Ghiribaldi et al. [2013] proposed a fast self-reconfiguration algorithm. The algorithm is based on segment-based routing implemented using Logic-Based Distributed Routing (LBDR) and claimed to have handled the most common NoC faults. The purpose of this comment is to demonstrate the inconsistency of the fast self-configuration method presented in Ghiribaldi et al. [2013]. To handle inconsistency, we present the correct set of LBDR bits and also argue that complete reconfiguration of the routing instance is mandatory to handle some fault combinations. New coverage results of the fast self-reconfiguration algorithm of Ghiribaldi et al. [2013] are also presented. Rimpy Bishnoi, Vijay Laxmi, Manoj Singh Gaur, José Flich, Francisco Triviño |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2015 | Employing Program Semantics for Malware DetectionabstractIn recent years, malware has emerged as a critical security threat. In addition, malware authors continue to embed numerous anti-detection features to evade the existing malware detection approaches. Against this advanced class of malicious programs, dynamic behavior-based malware detection approaches outperform the traditional signature-based approaches by neutralizing the effects of obfuscation and morphing techniques. The majority of dynamic behavior detectors rely on system-calls to model the infection and propagation dynamics of malware. However, these approaches do not account an important anti-detection feature of modern malware, i.e., systemcall injection attack. This attack allows the malicious binaries to inject irrelevant and independent system-calls during the program execution thus modifying the execution sequences defeating the existing system-call-based detection. To address this problem, we propose an evasion-proof solution that is not vulnerable to system-call injection attacks. Our proposed approach characterizes program semantics using asymptotic equipartition property (AEP) mainly applied in information theoretic domain. The AEP allows us to extract information-rich call sequences that are further quantified to detect the malicious binaries. Furthermore, the proposed detection model is less vulnerable to call-injection attacks as the discriminating components are not directly visible to malware authors. We run a thorough set of experiments to evaluate our solution and compare it with the existing system-call-based malware detection techniques. The results demonstrate that the proposed solution is effective in identifying real malware instances. Smita Naval, Vijay Laxmi, Muttukrishnan Rajarajan, Manoj Singh Gaur, Mauro Conti |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2015 | Bandwidth-aware routing and admission control for efficient video streaming over MANETs
Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur, Seok-Bum Ko |
Wirel. Networks | 3 |
| 2014 | Highly adaptive and congestion-aware routing for 3D NoCsabstractIn this paper, we propose a novel highly adaptive and congestion aware routing algorithm 3D meshes which is equally applicable to 2D meshes as well. The proposed algorithm allows cyclic dependencies in channel dependency graph (CDG) providing higher degree of adaptiveness. The algorithm uses congestion-aware channel selection strategy that results balanced distribution of traffic flows across the network. A packet follows non-minimal paths only when minimal paths are congested at the neighboring channels. The deadlock avoidance methodology adopted by our algorithm remains cost-efficient as it uses one extra virtual channel along each of Y and Z dimensions to achieve deadlock freedom. Manoj Kumar 0001, Vijay Laxmi, Manoj Singh Gaur, Masoud Daneshtalab, Seok-Bum Ko, Mark Zwolinski |
ACM Great Lakes Symposium on VLSI | 3 |
| 2014 | A novel non-minimal/minimal turn model for highly adaptive routing in 2D NoCsabstractNetworks-on-Chip (NoCs) are emerging as a promising communication paradigm to overcome bottleneck of traditional bus-based interconnects for current micro-architectures (MCSoC and CMP). One of the current issues in NoC routing is the use of acyclic Channel Dependency Graph (CDG) for deadlock freedom. This requirement forces certain routing turns to be prohibited, thus, reducing the degree of adaptiveness. In this paper, we propose a novel non-minimal turn model which allows cycles in CDG provided that Extended Channel Dependency Graph (ECDG) remains acyclic. The proposed turn model reduces number of restrictions on routing turns, hence able to provide path diversity through additional minimal and non-minimal routes between source and destination. Manoj Kumar 0001, Vijay Laxmi, Manoj Singh Gaur, Masoud Daneshtalab, Pankaj Kumar Srivastava, Seok-Bum Ko, Mark Zwolinski |
NOCS | 3 |
| 2014 | P-SPADE: GPU accelerated malware packer detectionabstractPacked malware imposes negative impact on the accuracy of AV scanners. It is essential for a security researcher to nullify the effects of packing tools, prior to malware detection. Numerous open and commercial packers are available to facilitate unwelcome intentions of malware authors. Thus, identification of packers becomes necessary phase prior to malware scanning. In this paper, we have proposed a GPGPU based approach for accelerating our previous signature based packer detection (SPADE) [1] method. SPADE generates packer signature by utilizing the intra-family malware alignments. It makes use of Smith-Waterman algorithm to reveal the actual relationship among the packer family samples and achieves high detection rate as compared to other packer detection tools. The use of Smith-Waterman comes with a trade off between accuracy and high computational complexity. So, we have implemented a parallel version of Smith-Waterman to improve the signature generation phase of SPADE. Our GPU based approach (O(m+n)) produces 14.89X to 49.91X speedup over CPU based implementation of SPADE preserving detection accuracy. Moreover, the proposed approach opens up new domain of applying GPUs to the existing signature based approaches for malware detection where signature database updation is done on daily basis. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, Muttukrishnan Rajarajan |
PST | 4 |
| 2014 | Platform Neutral Sandbox for Analyzing Malware and Resource Hogger Apps
Parvez Faruki, Ammar Bharmal, Manoj Singh Gaur, Vijay Laxmi, Mauro Conti |
SecureComm (1) | 4 |
| 2014 | Analysis of Identity Forging Attack in MANETsabstractIn Mobile Ad-Hoc Networks (MANETs) source and destination generally needs multihops to transfer data packets. Hence the number of nodes from source to destination increases. This property has render it vulnerable to attacks. We use the identity forging property of Sybil attack to propose an attack named "Identity Forging". In this attack, an attacker impersonates fake identity to affect the performance of network by sending the control packets through the identity of fabricated node and itself remaining silent. This makes it immune to the basic detection techniques of Sybil attack where both the attacker and its fake identity work simultaneously and thus can be detected if heard together for long period. The attacker also keeps changing the fabricated identity every time the link fails. Two different variations of this attack has been presented with their analysis and their impact on the performance of MANETs. In the end a possible detection algorithm for the attack has been proposed. Nishant Garg, Kuldeep Pareek, Manoj Singh Gaur, Vijay Laxmi, Chhagan Lal |
SIN | 3 |
| 2014 | Exploring Worm Behaviors using DTWabstractWorms are becoming a potential threat to Internet users across the globe. The financial damages due to computer worms increased significantly in past few years. Analyzing these hazardous worm attacks has become a crucial issue to be addressed. Given the fact that worm analysts would prefer to analyze classes of worms rather than individual files, their task will be significantly reduced. In this paper, we have proposed a dynamic host--based worm categorization approach to segregate worms. These groups indicate that worm samples constitute different behavior according to their infection and anti--detection vectors. Our proposed approach utilizes system--call traces and computes a distance matrix using Dynamic Time Warping (DTW) algorithm to form these groups. In conjunction to that, the proposed approach also discriminates worm and benign executables. The constructed model is further evaluated with unknown instances of real--world worms. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, Muttukrishnan Rajarajan |
SIN | 4 |
| 2014 | Evaluation of Android Anti-malware Techniques against Dalvik Bytecode ObfuscationabstractPopularity and growth of Android mobile devices has paved the way for exploiting popular apps using various Dalvik byte code transformation methods. Testing the antimalware techniques against obfuscation identifies the need of proposing effective detection methods. In this paper, we explore the resilience of anti-malware techniques against transformations for Android. The Proposed approach employs variable compression, native code wrapping and register renaming, in addition to already implemented transformations on Dalvik byte code. Evaluation results indicate low resilience of the antimalware detection engines against code obfuscation. Furthermore, we evaluate resilience of Androguard's code similarity and AndroSimilar's robust statistical feature signature against code obfuscated malware. Parvez Faruki, Ammar Bharmal, Vijay Laxmi, Manoj Singh Gaur, Mauro Conti, Muttukrishnan Rajarajan |
TrustCom | 4 |
| 2014 | A novel non-minimal turn model for highly adaptive routing in 2D NoCsabstractNetwork-on-Chip (NoC) is emerging as a promising communication paradigm to overcome bottleneck of traditional bus-based interconnects for future micro-architectures (MPSoC and CMP). One of current issue in NoC routing is the use of acyclic channel dependency graph (ACDG) for deadlock freedom prohibiting certain routing turns. Thus, ACDG reduces the degree of adaptiveness. In this paper, we propose a novel nonminimal turn model which allows cycles in channel dependency graph provided that extended channel dependency graph is acyclic. Proposed turn model reduces number of restrictions on routing turns (specially on 90-degree), hence able to provide additional minimal and non-minimal routes between source and destination. We also propose a non-minimal and congestion-aware adaptive routing algorithm based on proposed turn model to demonstrate advantages. From results, we can observe that proposed method improves the network performance by distributing the traffic load in the non-congested regions. Manoj Kumar 0001, Vijay Laxmi, Manoj Singh Gaur, Masoud Daneshtalab, Mark Zwolinski |
VLSI-SoC | 3 |
| 2014 | Detecting malicious files using non-signature-based methodsabstractMalware or malicious code intends to harm the computer systems without the knowledge of system users. Malware are unknowingly installed by naïve users while browsing the internet. Once installed, the malicious programs perform unintentional activities like: a) steal user name, password; b) install spy software to provide remote access to the attackers; c) flood spam messages; d) perform denial of service attacks, etc. With the emergence of metamorphic malware (that uses complex obfuscation techniques), signature-based detectors fail to identify new variants of malware. In this paper, we investigate non-signature techniques for malware detection and demonstrate methods of feature selection that are best suited for detection purposes. Features are produced using mnemonic n -grams and instruction opcodes (opcodes along with addressing modes). The redundant features are eliminated using class-wise document frequency , scatter criterion and principal component analysis (PCA) . The experiments are conducted on the malware dataset collected from VX Heavens and benign executables (gathered from fresh installation of Windows XP operating system and other utility software’s). The experiments also demonstrate that proposed methods that do not require signatures are effective in identifying and classifying morphed malware. P. Vinod 0001, Vijay Laxmi, Manoj Singh Gaur, Grijesh Chauhan |
Int. J. Inf. Comput. Secur. | 3 |
| 2014 | Probabilistic modeling and analysis of molecular memoryabstractThis article investigates the aspects of designing a nanocell based molecular memory. An empirical model for molecular device is developed, based on circuit behavior of nitro-substituted Oligo (Phynylene Ethynylene) molecule (OPE). This device model is subsequently used to design nanocell based 1-bit memory and verified using HSPICE. The approach is extended to train the nanocell for multibit storage capability using external voltage signals. It is observed that to successfully train a 2-bit molecular memory, the number of control signals should be approx. one-fourth of total number of nanoparticles. A computational framework is proposed to compute the probability of retrieving the stored data bits correctly, at the output terminal of the nanocell buffer. This nanocell configuration is simulated by systematically varying number of nanoparticles and molecular switches. It is observed that the probability of the existence of at least one path from input to output approaches close to unity with presence of 20 or more nanoparticles in a nanocell. During memory model validation, 1000 samples of 1-bit memory (consisting of 20 nanoparticles) were generated and verified for read and write operations. The model verification results obtained for this memory cell closely match those obtained using analytical solution of probabilistic graph model. Renu Kumawat, Vineet Sahula, Manoj Singh Gaur |
ACM J. Emerg. Technol. Comput. Syst. | 3 |
| 2014 | Exploiting convergence characteristics to tackle collusion attacks in OLSR for Security and Communication NetworksabstractCollusion attack is an attack against Optimised Link State Routing OLSR protocol in mobile ad hoc network. Two malicious nodes work together so that routes to the target victim nodes are not established in the network. Multipoint relay MPR selection process in OLSR is exploited to achieve this route denial. Packet delivery ratio for the target drops to 0% for nodes at distance of 3 hops or more. In this paper, we propose use of convergence characteristics of OLSR in designing effective, resource efficient countermeasures for packet dropping attacks such as collusion attack. We propose a detection method and countermeasure Scruple where discovery packets called ScruplePackets are injected to probe routes from target node to its three-hop neighbours. Acquired information is analysed to conclude if the node is a target of collusion attack. We also propose a novel attack-resistant method named Forced MPR Switching OLSR in which a node temporarily blacklists potential attackers on observing symptoms of the attack, thereby, forcing recomputation of its MPR set. Proposed approaches incur minimal penalty on network performance. Simulations conducted on Network Simulator 3 confirm effectiveness of the proposed method. Copyright © 2012 John Wiley & Sons, Ltd. Manoj Singh Gaur, Rajbir Kaur, Lalith Suresh 0001, Vijay Laxmi |
Secur. Commun. Networks | 1 |
| 2013 | QoS-aware routing for transmission of H.264/SVC encoded video traffic over MANETsabstractEfficient and reliable video streaming over mobile ad-hoc networks (MANETs) is a challenging task due to the varying characteristics of wireless networks and video traffic. Therefore, these kinds of applications require quality-of-service (QoS) support. Although, many QoS provisioning solutions are reported in the past but none of them are tested on video traffic and also affects of mobility and variations in link quality are not addressed properly. In this paper, we proposed an efficient QoS-aware routing protocol (QARP) which uses the cross-layer communication (CLC) and session admission control (SAC) methods to provide QoS guarantees in terms of network bandwidth. In QARP, we perform QoS-aware route discovery by considering the effects of both inter-contention and intra-contention during the route discovery phase. Only data sessions for which a route with required bandwidth is discovered are admitted into the network by our SAC process. Existing periodic message structures are extended for exchange the QoS states of nodes to minimize the affect of mobility in our QoS-aware routing method. Furthermore, two methods are proposed to handle the QoS violations caused by dynamic characteristics of video traffic and network mobility during data communication. To stress the network with real time multimedia traffic, we use trace files generated from real time video files that are encoded using H.264/SVC encoder. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
APCC | 3 |
| 2013 | Video streaming over MANETs: Testing and analysis using real-time emulationabstractIn this paper, we design and deploy a Mobile Ad hoc Network (MANET) testbed that is integrated with EXata-Cyber network emulator to evaluate the performance of real-time video streaming applications. EXata-Cyber can unvaryingly connect emulated networks (virtual networks created by EXata-Cyber) to real machines. Thus, in our testbed, real machines can exchange real-life applications traffic over emulated wireless networks consisting of virtual machines. With the emulation capabilities of EXata-Cyber, our developed testbed gives an efficient, high fidelity and accommodating testing terrain for analyzing the performances and behaviors of real-life applications, machines and MANET routing protocols. We evaluate the performance of both proactive and reactive routing protocols while transmitting real-time video traffic in terms of change in network load, network mobility and video streaming bit rate. Furthermore, to provide accurate measures for perceived video quality at users end in the form of Quality-of-Experience (QoE), we evaluate and analyze metrics such as Mean Opinion Score (MOS), Signal-to-Interference and Noise Ratio (SINR) and Packet Delivery Ratio (PDR) at various layers of TCP/IP protocol stack. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
APCC | 3 |
| 2013 | Energy Efficient Clustered Routing for Wireless Sensor NetworkabstractIn a Wireless Sensor Network (WSN) hundreds of tiny sensors with limited resources are accommodated to sense the information from the field. Transfer of gathered information from the sensing field to the base station must be done in proficiently to sustain the network longer. Clustering of sensor nodes is one way to achieve this goal. This paper introduces an Energy Efficient clustered routing protocol based on LEACH-C for WSN. In LEACH-C (Low Energy Adaptive Clustering Hierarchy-Centralized), the cluster heads are selected by the base station randomly. This paper introduces a novel cluster based routing protocol in which, the base station finds the highest energy node among the cluster and mark it as a cluster head for the current time. Thus in the proposed system the energy consumption of various nodes becomes more uniform as compared to LEACH-C. The simulation results indicate that our proposed method leads to efficient transmission of data packets with less energy and therefore increases the network longevity as compared to LEACH-C and LEACH. Meenakshi Tripathi, Ramesh Babu Battula, Manoj Singh Gaur, Vijay Laxmi |
MSN | 3 |
| 2013 | AndroSimilar: robust statistical feature signature for Android malware detectionabstractAndroid Smartphone popularity has increased malware threats forcing security researchers and AntiVirus (AV) industry to carve out smart methods to defend Smartphone against malicious apps. Robust signature based solutions to mitigate threats become necessary to protect the Smartphone and confidential user data. In this paper we present AndroSimilar, a robust approach which generates signature by extracting statistically improbable features, to detect malicious Android apps. Proposed method is effective against code obfuscation and repackaging, widely used techniques to evade AV signature and to propagate unseen variants of known malware. AndroSimilar is a syntactic foot-printing mechanism that finds regions of statistical similarity with known malware to detect those unknown, zero day samples. Syntactic file similarity of whole file is considered instead of just opcodes for faster detection compared to known fuzzy hashing approaches. Results demonstrate robust detection of variants of known malware families. Proposed approach can be refined to deploy as Smartphone AV. Parvez Faruki, Vijay Ganmoor, Vijay Laxmi, Manoj Singh Gaur, Ammar Bharmal |
SIN | 4 |
| 2013 | Insecurities within browser: issues and challengesabstractThe browser allows users to view and interact with content on the web pages. An attack on the browser provides an unauthorized access, damage or disruption of the user information within or outside the browser. An attacker can compromise Browser by exploiting structural and application level vulnerabilities within Browser. This tutorial discuss the major security issues in modern web browsers, and encompasses the solution directives to address these issues and challenges caused by Browser-based attacks. Manoj Singh Gaur, Dhiren R. Patel, Anil Saini |
SIN | 1 |
| 2013 | Impact analysis of JellyFish attack on TCP-based mobile ad-hoc networksabstractTremendous increase has been seen in the number of application areas of mobile ad-hoc networks (MANETs) in recent years owing to the advancements in hardware of hand- held devices and wireless network deployment technologies. As a result, providing security in these kinds of networks has become central concern for researchers. In this paper, we analyze the behavior and impacts of JellyFish attack over TCP-based MANETs. We implement and evaluate three variants of JellyFish attack namely JF-reorder, JF-delay and JF-drop. JellyFish attack exploits the behavior of closed loop protocols such as TCP and performs the attacks without disobeying any rules of the protocol. Consequently, it causes ruinous effects and becomes difficult to detect due to its protocol compliance nature. This paper provides the complete simulation study of JellyFish attacks on three TCP variants known as TCP-Tahoe, TCP-SACK and TCP-NewReno. The simulations have been taken in the light of throughput, number of JF nodes and number of retransmissions. The paper contributes to the field of denial of service (DoS) attacks in MANETs by giving a comparative analysis of three TCP variants and discovers which TCP variant performs best under different variants of JellyFish attack. In addition to this, our simulation results also shed some light on the seriousness of the attacks caused by JF nodes and their effects on data communication. Vijay Laxmi, Deepanshu Mehta, Manoj Singh Gaur, Parvez Faruki, Chhagan Lal |
SIN | 3 |
| 2013 | The darker side of Firefox extensionabstractA Web browser is an important component of every computer system as it provides the interface to the Internet world. The new unforeseen functionalists may be added to the web browsers in the form of extensions. These extensions enhance the core functionality of browser and provide customization to it. Although well-intentioned, extension developers are often not security experts and write vulnerable code that can introduce a security hole through which an attacker can penetrate a victim user's browser and steal the user's sensitive information. This paper makes two contributions. First, it describes the attack vectors which are used by attacker during extension based browser attacks. Second, we discuss about various vulnerable points of attack in browser extensible model which are not yet addressed by browser developers. We explain how Firefox insecure policies and Java script based extensions can be abused by an attacker for malicious purposes. This paper is supported by proof-of-concept add-ons which are developed by exploiting the weakness in Firefox add-on coding. Anil Saini, Manoj Singh Gaur, Vijay Laxmi |
SIN | 2 |
| 2013 | Near-Optimal Geometric Feature Selection for Visual speech RecognitionabstractTo improve the accuracy of visual speech recognition systems, selection of visual features is of fundamental importance. Prominent features, which are of maximum relevance for speech classification, need to be selected from a large set of extracted visual attributes. Existing methods apply feature reduction and selection techniques on image pixels constituting region-of-interest (ROI) to reduce data dimensionality. We propose application of feature selection methods on geometrical features to select the most dominant physical features. Two techniques, Minimum Redundancy Maximum Relevance (mRMR) and Correlation-based Feature Selection (CFS), have been applied on the extracted visual features. Experimental results show that recognition accuracy is not compromised when a few selected features from the complete visual feature set are used for classification, thereby reducing processing time and storage overheads considerably. Results are compared with performance of principal components obtained by application of Principal Component Analysis (PCA) on our dataset. Our set of selected features outperforms the PCA transformed data. Results show that the center and corner segments of the mouth are major contributors to visual speech recognition. Teeth pixels are shown to be a prominent visual cue. It is also seen that lip width contributes more towards visual speech recognition accuracy as compared to lip height. Preety Singh, Vijay Laxmi, Manoj Singh Gaur |
Int. J. Pattern Recognit. Artif. Intell. | 3 |
| 2012 | A Node-Disjoint Multipath Routing Method Based on AODV Protocol for MANETsabstractFrequent link failures are caused in mobile ad-hoc networks due to node's mobility and use of unreliable wireless channels for data transmission. Due to this, multipath routing protocols become an important research issue. In this paper, we propose and implement a node-disjoint multipath routing method based on AODV protocol. The main goal of the proposed method is to determine all available node-disjoint routes from source to destination with minimum routing control overhead. With the proposed approach, as soon as the first route for destination is determined, the source starts data transmission. All the other backup routes, if available, are determined concurrently with the data transmission through the first route. This minimizes the initial delay caused because data transmission is started as soon as first route is discovered. We also propose three different route maintenance methods. All the proposed route maintenance methods are used with the proposed route discovery process for performance evaluation. The results obtained through various simulations show the effectiveness of our proposed methods in terms of route availability, control overhead, average end-to-end delay and packet delivery ratio. Chhagan Lal, Vijay Laxmi, Manoj Singh Gaur |
AINA | 3 |
| 2012 | Mining control flow graph as API call-grams to detect portable executable malwareabstractPresent day malware shows stealthy and dynamic capability and avails administrative rights to control the victim computers. Malware writers depend on evasion techniques like code obfuscation, packing, compression, encryption or polymorphism to avoid detection by Anti-Virus (AV) scanners as AV primarily use syntactic signature to detect a known malware. Our approach is based on semantic aspect of PE exectable that analyses API Call-grams to detect unknown malicious code. As in--exact source code is analysed, the machine is not infected by the executable. Moreover, static analysis covers all the paths of code which is not possible with dynamic behavioural methods as latter does not gurantee the execution of sample being analysed. Modern malicious samples also detect controlled virtual and emulated environments and stop the functioning. Semantic invariant approach is important as signature of known samples are changed by code obfuscation tools. Static analysis is performed by generating an API Call graph from control flow of an executable, then mining the Call graph as API Call-gram to detect malicious files. Parvez Faruki, Vijay Laxmi, Manoj Singh Gaur, P. Vinod 0001 |
SIN | 3 |
| 2012 | Detection of incorrect position information using speed and time span verification in VANETabstractSecurity issues in Vehicular Ad-Hoc Networks (VANETs) are important because of its diverse implications in safety related and congestion avoidance applications. A critical security problem in VANET is injection of false data, i.e. an attacker propagates false information to disrupt the behavior of drivers. Most of VANET applications are time critical and depend on the reliable position information in the safety messages received from the neighboring nodes. Disseminating incorrect position information in the safety message has severe impact on the performance, reliability and security of VANET applications. In this paper, we propose a distributed solution to detect malicious nodes propagating incorrect position information. This solution is based on series of verifications such as acceptance range verification, maximum allowable speed check, maximum density check, speed consistency verification and time interval substantiation computed by fixed Road Side Units (RSUs). In this approach, each RSU performs some set of logical operations to validate the legitimacy of positions of nodes sending safety messages. We have evaluated the proposed approach in both simulated and realistic scenario. Experimental results prove the validity of the proposed detection approach. Jyoti Grover, Manoj Singh Gaur, Vijay Laxmi, Rakesh Kumar Tiwari |
SIN | 2 |
| 2012 | Detection attack analysis using partial watermark in DCT domainabstractThe paper presents a novel framework for blind watermark detection on additive watermarking in Discrete Cosine Transform (DCT) domain. Watermarks which resist any attempt by an adversary to thwart their intended purpose such as unauthorized detection, removal or embedding of watermark are called secure watermarks. If an adversary is able to detect the watermark, he may further remove it or embed his own watermark. Thus, the ownership of the data cannot be claimed. The proposed scheme applies watermark detection as an attack and analyses the robustness of the scheme in respect of attack resistance. The scheme also puts forward the type of watermark that should be chosen to sustain such attacks on images. Moreover it also shows the conditions under which the watermark is resilient to unauthorized detection of watermark. The detection scheme uses a correlation based detector for a watermark assumed to be partially known to the attacker. The DCT of watermarked image is taken and the watermarked coefficients are extracted. The correlation coefficient between the extracted coefficients of watermarked image and the partial watermark known are calculated. Experimental results show that the proposed method is secure against unauthorized watermark detection. Reena Gunjan, Vijay Laxmi, Manoj Singh Gaur |
SIN | 3 |
| 2012 | ESCAPE: entropy score analysis of packed executableabstractMalware developers hide the malicious payload of malware binary by employing various obfuscation techniques. One such technique commonly applied is packing. Packer transforms the original bytes so it is difficult to recognize the behaviour of any executable. Although the contents of a file is changed, some byte patterns may be preserved across different packed executables. Malware detectors need to apply unpacking mechanism prior to any detection or analysis to every sample under consideration. In this paper, we have proposed a method that discriminate packed binaries from the native files to minimize the processing time of AV scanners. We have used the blockwise entropy score of byte features of the executable. Experimental results show that the proposed method is capable of identifying packed and native executable which are packed using different malware packers. Smita Naval, Vijay Laxmi, Manoj Singh Gaur, P. Vinod 0001 |
SIN | 3 |
| 2012 | Lip peripheral motion for visual surveillanceabstractReal-time surveillance systems, dealing with lipreading, can benefit from a reduction in visual data to be processed. This reduces processing time and improves the efficiency of the system. These systems take features extracted from the mouth region for recognition of speech. In this paper, the lip periphery is represented by a set of boundary descriptors. Three feature selection techniques are applied to reduce the feature set. These are Minimum Redundancy Maximum Relevance, Chi-square statistic and Correlation-based Feature Selection. Feature subsets are used for speech classification and an optimal feature vector is determined on basis of recognition performance and feature vector length. The optimal feature vector shows enhanced recognition performance while achieving a 94.17% reduction in feature size. It is observed that most of the prominent boundary descriptors lie on the upper lip. Lip width emerges as an important contributor to visual speech. Preety Singh, Vijay Laxmi, Manoj Singh Gaur |
SIN | 3 |
| 2011 | Parallelizing TUNAMI-N1 Using GPGPUabstractWe present a high performance tsunami-prediction system using General Purpose Graphics Processing Units (GPGPU). It is based on TUNAMI-N1, a Numerical Analysis Model for Investigation of near-field tsunamis. It uses linear shallow water wave equations, commonly accepted approximation for tsunami propagation, taking the input from a bathymetry file containing a large data set. Due to the largeness of the data set, the model is more amenable to parallelization. The system maps the TUNAMI-N1 model into the massively parallel GPU architecture using Nvidia CUDA framework. It employs multiple kernels that contain inherently parallel portion of the model and uses the concepts of data and hybrid parallelism to fully exploit the hardware capabilities of the GPUs. Experimental results show that our system achieves a speed up of six times. Harsh Gidra, Israrul Haque, Nitin P. Kumar, M. Sargurunathan, Manoj Singh Gaur, Vijay Laxmi, Mark Zwolinski, Virendra Singh |
HPCC | 5 |
| 2011 | Position forging attacks in Vehicular Ad Hoc Networks: Implementation, impact and detectionabstractVehicular Ad Hoc Network (VANET) applications operate on the principle of periodic exchange of messages between nodes. However, a malicious node can create multiple virtual identities for transmitting fake messages using different forged positions. This creates an illusion of a non-existent event. In VANET, each vehicle periodically broadcasts its identity (ID), time and current geographic position in beacon packets. Node position and time are important factors for modeling an attack as well as for its detection. In this paper, we introduce new variants of (a) Position forging attacks and (b) Combination of position and ID forging attacks. We also propose an implementation of these attacks, their impact on the performance of VANET and description of detection methodology. In a position forging attack, an attacker broadcasts timely coordinated wrong traffic warning messages with forged positions, producing an illusion of a car accident, a traffic jam or an emergency braking. This degrades the performance of VANET in terms of channel utilization. It also has a severe impact on the performance of security algorithms. We analyze the impact of forged position information on average vehicle speed, percentage of delivered packets and number of collisions. Jyoti Grover, Manoj Singh Gaur, Vijay Laxmi |
IWCMC | 2 |
| 2011 | Detour attack in OLSRabstractIn Optimized Link State Routing (OLSR), each node collects information about the network by exchanging control messages. The information is stored or updated in various repositories maintained at each node. The information in repositories is used to further generate control messages. A node has full control over its repositories. In absence of any security mechanism, a malicious node can poison information contained in the repositories causing routing disorder attacks. In this paper, we propose a novel routing disorder attack detour attack against OLSR. In this attack, a malicious node updates its repositories with fake neighborhood information resulting in generation of incorrect control messages. The fake information forces neighboring nodes to choose the malicious node as their Multi Point Relay (MPR) node. Data packets passing through malicious node are diverted to improper routes and packets may never reach their destination. A large amount of packets sent from source to destination get dropped. In this paper, we also analyze the effects of multiple attackers on network characteristics. Manoj Singh Gaur, Vijay Laxmi, Rajbir Kaur |
SIN | 1 |
| 2011 | Acceleration of packet filtering using gpgpuabstractPacket filtering is core functionality in many academic and corporate network systems. Firewalls use a rule database to decide which packets will be allowed from one network onto another thereby implementing a security policy. With the introduction of new types of services and applications there is a growing demand for larger bandwidth and also for improved security. Both demands are in conflict since providing security partly relies on screening packet traffic, which implies a considerable overhead. In such a scenario as LAN and WAN speeds are becoming comparable, a single firewall can become a bottleneck and reduces the overall throughput of the network. A firewall with heavy load and limited processing power, which is supposed to be a first line of defence against attacks, becomes susceptible to Denial of Service (DoS) attacks. Many research groups have proposed different methods to improve efficiency and throughput to optimize firewalls. This paper presents and analyse various parallel implementations of packet filtering running on cost effective GPGPU. We describe an approach to efficiently exploit the massively parallel capabilities of the GPGPU. Manoj Singh Gaur, Vijay Laxmi, Lakshminarayanan V., Kamal Cahndra, Mark Zwolinski |
SIN | 1 |
| 2011 | A sybil attack detection approach using neighboring vehicles in VANETabstractVehicular Ad Hoc Network (VANET) is vulnerable to many security threats. One severe attack is Sybil attack, in which a malicious node forges a large number of fake identities in order to disrupt the proper functioning of VANET applications. In this paper, a distributed and robust approach is presented to defend against Sybil attack. Proposed scheme localizes the fake identities of malicious vehicles by analyzing the consistent similarity in neighborhood information of neighbors of these fake identities. Beacon packets are exchanged periodically by all the vehicles to announce their presence and get aware of neighboring nodes. Each node periodically keep a record of its neighboring nodes. In proposed approach, each node exchange groups of its neighboring nodes periodically and perform the intersection of these groups. If some nodes observe that they have similar neighbors for a significant duration of time, these similar neighbors are identified as Sybil nodes. Proposed approach is able to locate Sybil nodes quickly without the requirement of secret information exchange and special hardware support. We evaluate our proposed approach on the realistic traffic scenario. Experiment results demonstrate that detection rate increases when optimal numbers of Sybil nodes are forged by the attacker. Jyoti Grover, Manoj Singh Gaur, Vijay Laxmi, Nitesh Kumar Prajapati |
SIN | 2 |
| 2011 | C-Routing: An adaptive hierarchical NoC routing methodologyabstractDeterministic routing algorithms are easier to design and implement in NoC but these fail to adapt to congestion. Table based adaptive routing solutions are not scalable. As the number of nodes increases, the area required for routing table becomes a penalty. In this paper, we propose a new hierarchical cluster based adaptive routing called `C-Routing' in 2-D Mesh NoC. The solution reduces routing table size and provides deadlock freedom without use of virtual channels while ensuring livelock free routing. Routers in our method use intelligent routing to route information between the processing elements ensuring the correctness, deadlock freeness, and congestion handling. This method has been evaluated against other adaptive algorithms such as PROM, and Q-Routing etc. Results show that the proposed method performs better for given traffic patterns. C-routing uses adaptivity to avoid congestion by uniform distribution of traffic among the cores by sending flits over two different paths to the destination. Manas Kumar Puthal, Virendra Singh, Manoj Singh Gaur, Vijay Laxmi |
VLSI-SoC | 3 |
| 2010 | Genetic algorithm based topology generation for application specific Network-on-ChipabstractNetwork-on-Chip (NoC) has been proposed as a solution for the communication challenges of System-on-chip (SoC) design in nanoscale technologies. Application specific SoC design offers the opportunity for incorporating custom NoC architectures that are more suitable for a particular application, and do not necessarily conform to regular topologies. The aim is to generate a custom NoC that maximizes performance under the given resource constraints. The paper presents a heuristic technique based on genetic algorithm for synthesis of custom NoC architectures along with requisite routing tables with the objective to improve communication load distributions in the network subject to the resource constraints in such a way that the overall communication throughput and latency improves. Naveen Choudhary, Manoj Singh Gaur, Vijay Laxmi, Virendra Singh |
ISCAS | 2 |
| 2010 | ERA: An Efficient Routing Algorithm for Power, Throughput and Latency in Network-on-Chips
Varsha Sharma, Rekha Agarwal, Manoj Singh Gaur, Vijay Laxmi, Vineetha V. |
NPC | 3 |
| 2010 | A novel defense mechanism against sybil attacks in VANETabstractSecurity is an important concern for many Vehicular Ad hoc Network (VANET) applications. One particular serious attack, known as Sybil attack, against ad hoc networks involves an attacker illegitimately claiming multiple identities. In this paper, we present a simple security scheme, based on the difference in movement patterns of Sybil nodes and normal nodes, for detecting Sybil nodes in VANET. Our approach is distributed in nature because all nodes contribute for detection of Sybil nodes in VANET and it scales well in an expanding network. In this approach, each Road Side Unit (RSU) calculates and stores different parameter values (Received Signal Strength, distance, angle) after receiving the beacon packets from nearby vehicles. The reason for choosing the angle as one of the parameters is that it will always be different for two vehicles (not moving side-by-side), even if they have same values for distance and received signal strength (RSS) with reference to a RSU. The combination of the parameters makes our detection approach highly accurate. After a significant observation period, these RSUs exchange their records and calculate the difference of the parameters. If some nodes have same values for the parameters during this observation period, these nodes are classified as Sybil nodes. Our preliminary simulation results show 99% accuracy and approximately 0.5% error rate, lower as compared to existing techniques. Jyoti Grover, Manoj Singh Gaur, Vijay Laxmi |
SIN | 2 |
| 2010 | MEDUSA: MEtamorphic malware dynamic analysis usingsignature from APIabstractMalware detection and prevention methods are increasingly becoming necessary for computer systems connected to the Internet. The traditional signature based detection of malware fails for metamorphic malware which changes its code structurally while maintaining functionality at time of propagation. This category of malware is called metamorphic malware. In this paper we dynamically analyze the executables produced from various metamorphic generators through an emulator by tracing API calls. A signature is generated for an entire malware class (each class representing a family of viruses generated from one metamorphic generator) instead of for individual malware sample. We show that most of the metamorphic viruses of same family are detected by the same base signature. Once a base signature for a particular metamorphic generator is generated, all the metamorphic viruses created from that tool are easily detected by the proposed method. A Proximity Index between the various Metamorphic generators has been proposed to determine how similar two or more generators are. Vinod P. Nair, Harshit Jain, Yashwant K. Golecha, Manoj Singh Gaur, Vijay Laxmi |
SIN | 4 |
| 2010 | A collusion attack detection method for OLSR-based MANETS employing scruple packetsabstractCollusion Attack is an attack against Mobile Ad hoc Networks (MANETs) exploiting vulnerabilities of the Optimised Link State Routing (OLSR) protocol. In this attack, two attacker nodes work together to prevent routes to the targeted node from being established in the network. Consequences of this attack can be severe, as Packet Delivery Ratio (PDR) for the victim node drops to 0% for neighbor nodes at a distance of three-hops or more. In this paper, we propose a detection method called Scruple for this attack. In the proposed method, discovery packets called ScruplePackets are injected to probe the routes from victim node to its three-hop neighbors. Based on the acquired information, a node checks if it is a victim of some Collusion Attack. In this paper, we describe Scruple, its implementation and analysis of effectiveness of this technique through experimental simulations using network simulator ns-3. Lalith Suresh 0001, Rajbir Kaur, Manoj Singh Gaur, Vijay Laxmi |
SIN | 3 |
| 2009 | Buyer seller watermarking protocol for digital rights managementabstractIn today's digital age, e-commerce is emerging as an alternative and inexpensive solution to traditional selling of products through shops. Sale of electronic data such as software, audio/video data, books etc. poses a problem as digital data can be easily replicated, modified and distributed. Watermarks were introduced as a means to establish ownership of digital data and check unauthorized reuse and/or violation of copyrighted material. A good e-distribution system should be able to protect rights of both buyer and seller; ensure secure and confidential transactions; determine correct source of unauthorized copies. In this paper, we propose a framework for e-distribution of digital rights. This system is based on a trusted third party CA (Certification Authority) and uses PKI (public key infrastructure). Proposed system address problems of customer's check, copy detection, customers right,unbinding, non-repudiation and man in the middle attack. Vijay Laxmi, Mudassar N. Khan, Sarath S. Kumar, Manoj Singh Gaur |
SIN | 4 |
| 2009 | Static CFG analyzer for metamorphic Malware codeabstractMalware detection and prevention methods are increasingly becoming important particularly for all computer systems connected to Internet. The term 'Malware' is collectively used for viruses, worms, Trojan's etc. Malicious activities of malware is to steal, modify, leak the data to external server or consuming system resources thereby degrading the performance of system. To avoid detection, malicious code(s) generates multiple variants while they propagate. In past, researchers have addressed malware detection using Control Flow Graph (CFG). These detection methods were based on comparison of shapes of CFG's of original sample with that of variants. Vinod P. Nair, Vijay Laxmi, Manoj Singh Gaur, G. V. S. S. Phani Kumar, Yadvendra S. Chundawat |
SIN | 3 |