EDBT 2026 Demo / reviewers in the wild / expert
Kevin A. Kwiat
dblp:86/3876
· DBLP profile ↗
88ranked-venue papers
6as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 33 · 1 first-authorSecurity and privacy · 18 · 2 first-authorSystems, architecture and hardware · 17 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 10Human-computer interaction and ubiquitous computing · 4Artificial intelligence and machine learning · 3Software engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
8 papers |
Hardware security and side channels · 52% Cyber-physical and IoT security · 26% Malware analysis · 14% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Cloud and datacenter computing · 39% Electronic design automation · 34% Integrated circuit design · 17% | |
| Theoretical computer science
2 papers |
Algorithmic game theory and mechanism design · 100% | |
| Computer networks
5 papers |
Network optimization and economics · 43% Internet of things and sensor networks · 24% Wireless networking · 14% |
Topics — the 30 heaviest of 36, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels
hardware trojan |
0.4 | 1 | 2020 | Applying Chaos Theory for Runtime Hardware Trojan Monitoring and Detection · IEEE Trans. Dependable Secur. Comput. 2020 |
Electronic design automation › hardware verification and test › hardware verification
hardware trojan detection |
0.4 | 1 | 2020 | Applying Chaos Theory for Runtime Hardware Trojan Monitoring and Detection · IEEE Trans. Dependable Secur. Comput. 2020 |
Algorithmic game theory and mechanism design › incomplete information
bayesian game |
0.4 | 1 | 2020 | A Bayesian Game Theoretic Approach for Inspecting Web-Based Malvertising · IEEE Trans. Dependable Secur. Comput. 2020 |
Algorithmic game theory and mechanism design
security games |
0.4 | 1 | 2020 | A Bayesian Game Theoretic Approach for Inspecting Web-Based Malvertising · IEEE Trans. Dependable Secur. Comput. 2020 |
Hardware security and side channels › side-channel attack
power analysis |
0.3 | 1 | 2018 | On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic Approach · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2018 |
Hardware security and side channels
side-channel attack |
0.3 | 1 | 2018 | On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic Approach · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2018 |
Hardware security and side channels
side-channel resistance |
0.3 | 1 | 2018 | On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic Approach · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2018 |
Cyber-physical and IoT security › deception attacks
false data injection attack |
0.3 | 1 | 2017 | Electric grid power flow model camouflage against topology leaking attacks · INFOCOM 2017 |
Hardware security and side channels › hardware trojan
hardware trojan countermeasure |
0.3 | 1 | 2017 | Automatic Generation of Hardware Sandboxes for Trojan Mitigation in Systems on Chip (Abstract Only) · FPGA 2017 |
Cyber-physical and IoT security › cyber-physical attack detection
sensor attack detection |
0.3 | 1 | 2017 | Estimation of Safe Sensor Measurements of Autonomous System Under Attack · DAC 2017 |
Cyber-physical and IoT security
smart grid security |
0.3 | 1 | 2017 | Electric grid power flow model camouflage against topology leaking attacks · INFOCOM 2017 |
Cloud and datacenter computing › datacenter architecture
virtualized datacenter |
0.2 | 1 | 2013 | Enhancing Survivability in Virtualized Data Centers: A Service-Aware Approach · IEEE J. Sel. Areas Commun. 2013 |
Cloud and datacenter computing › virtualization › virtual machine management
virtual machine placement |
0.2 | 1 | 2013 | Enhancing Survivability in Virtualized Data Centers: A Service-Aware Approach · IEEE J. Sel. Areas Commun. 2013 |
Integrated circuit design
low-power circuit design |
0.1 | 1 | 2020 | Applying Chaos Theory for Runtime Hardware Trojan Monitoring and Detection · IEEE Trans. Dependable Secur. Comput. 2020 |
Wireless networking › cooperative networks
cooperation enforcement |
0.1 | 1 | 2011 | Cooperation in Wireless Networks with Unreliable Channels · IEEE Trans. Commun. 2011 |
Network optimization and economics › game theory
game-theoretic networking |
0.1 | 1 | 2011 | Cooperation in Wireless Networks with Unreliable Channels · IEEE Trans. Commun. 2011 |
Network optimization and economics
game theory |
0.1 | 1 | 2011 | Cooperation in Wireless Networks with Unreliable Channels · IEEE Trans. Commun. 2011 |
Network optimization and economics › game theory › equilibrium analysis
nash equilibrium |
0.1 | 1 | 2011 | Cooperation in Wireless Networks with Unreliable Channels · IEEE Trans. Commun. 2011 |
Cellular and mobile networks
power control |
0.1 | 1 | 2010 | A Game Theoretic Framework for Power Control in Wireless Sensor Networks · IEEE Trans. Computers 2010 |
Internet of things and sensor networks
wireless sensor network |
0.1 | 1 | 2010 | A Game Theoretic Framework for Power Control in Wireless Sensor Networks · IEEE Trans. Computers 2010 |
Internet of things and sensor networks › iot security
iot device security |
0.1 | 1 | 2018 | On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic Approach · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2018 |
Energy systems and smart grids › power system monitoring
state estimation |
0.1 | 1 | 2017 | Electric grid power flow model camouflage against topology leaking attacks · INFOCOM 2017 |
Embedded and real-time systems
cyber-physical system platforms |
0.1 | 1 | 2017 | Estimation of Safe Sensor Measurements of Autonomous System Under Attack · DAC 2017 |
Integrated circuit design
system-on-chip |
0.1 | 1 | 2017 | Automatic Generation of Hardware Sandboxes for Trojan Mitigation in Systems on Chip (Abstract Only) · FPGA 2017 |
Distributed systems
fault tolerance |
0.0 | 1 | 2013 | Enhancing Survivability in Virtualized Data Centers: A Service-Aware Approach · IEEE J. Sel. Areas Commun. 2013 |
Network security › intrusion detection and prevention
intrusion detection |
0.0 | 1 | 2004 | An Effective Architecture and Algorithm for Detecting Worms with Various Scan · NDSS 2004 |
Network security › intrusion detection and prevention › intrusion detection › malicious traffic detection
worm detection |
0.0 | 1 | 2004 | An Effective Architecture and Algorithm for Detecting Worms with Various Scan · NDSS 2004 |
Malware analysis › malware propagation modeling
worm propagation modeling |
0.0 | 1 | 2003 | Modeling the Spread of Active Worms · INFOCOM 2003 |
Routing and switching
packet forwarding |
0.0 | 1 | 2011 | Cooperation in Wireless Networks with Unreliable Channels · IEEE Trans. Commun. 2011 |
Algorithmic game theory and mechanism design › solution concepts in games › equilibrium concepts
nash equilibrium |
0.0 | 1 | 2010 | A Game Theoretic Framework for Power Control in Wireless Sensor Networks · IEEE Trans. Computers 2010 |
Methods — techniques the papers use, named apart from their topics
game theory · 0.9phase space reconstruction · 0.9nash equilibrium · 0.9chaos theory · 0.9bayesian game · 0.9nash equilibrium analysis · 0.7recursive least squares · 0.6power flow analysis · 0.6hardware sandbox generation · 0.6challenge-response authentication · 0.6simulation · 0.3distributed power control algorithm · 0.2distortion metric · 0.2optimization · 0.2heuristic algorithm · 0.2state machine strategy · 0.1non-cooperative game theory · 0.1evolutionary game theory · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | A Bayesian Game Theoretic Approach for Inspecting Web-Based MalvertisingabstractWeb-based advertising systems have been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply various redirection and evasion techniques. Meanwhile, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under resource and time constraints. Moreover, the ad network is disadvantaged because it has incomplete information about whether it is facing a benign or malicious advertiser. In this paper, we aim to apply the Bayesian game model by designing two games to formulate the problem of inspecting the Web-based maladvertising. The first game has two types of Advertisers, namely Malicious and Benign, and one type of Defender; the second game has two types of Attackers, Advanced and Simple, in terms of their capability of redirection and evasion, and one type of Defender. We define their strategies and payoff functions, and compute their Bayesian Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and we derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy. Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Applying Chaos Theory for Runtime Hardware Trojan Monitoring and DetectionabstractHardware Trojans (HTs) pose a serious threat to the security of Integrated Circuits (ICs). Detecting HTs in an IC is an important but difficult problem due to the wide spectrum of HTs and their stealthy nature. While researchers have been working on enhancing traditional IC tests and developing new methods to try to detect Trojans, there is still a possibility a Trojan will avoid detection during test time and be activated once the chip is in use. A runtime Trojan detection system could monitor an IC during its operational life time and provide a last-line of defense. However, most runtime approaches are infeasible due to the overhead introduced by additional hardware, or computational complexity, or both. In this paper, we propose a hardware-based runtime detection model that overcomes the aforementioned constraints. It applies chaos theory, which has been shown to be effective in several other domains, to characterize dynamic data in a reconstructed phase space, which helps us describe, analyze, and interpret power consumption data (whether chaotic or not). The proposed chaos based approach does not make any assumption on the statistical distribution of power consumption, this makes our model applicable for runtime use given the fact that power consumption is very dynamic as well as heavily application and data dependent. Hardware overhead, which is the main challenge for runtime approaches, is reduced by taking advantage of available thermal sensors present in most modern ICs. For real world implementation, thermal sensor noise cancelation is considered in our proposed model. Our simulation results for detecting Trojans on publicly available Trojan benchmarks demonstrate that the proposed model outperforms the current runtime Trojan detection approaches in terms of detection rate, computational complexity, and implementation feasibility. Approved for Public Release; Distribution Unlimited: 88ABW-2016-4308; Dated 31 AUG 2016. Luke Kwiat, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | A Deep Recurrent Neural Network Based Predictive Control Framework for Reliable Distributed Stream Data ProcessingabstractIn this paper, we present design, implementation and evaluation of a novel predictive control framework to enable reliable distributed stream data processing, which features a Deep Recurrent Neural Network (DRNN) model for performance prediction, and dynamic grouping for flexible control. Specifically, we present a novel DRNN model, which makes accurate performance prediction with careful consideration for interference of co-located worker processes, according to multilevel runtime statistics. Moreover, we design a new grouping method, dynamic grouping, which can distribute/re-distribute data tuples to downstream tasks according to any given split ratio on the fly. So it can be used to re-direct data tuples to bypass misbehaving workers. We implemented the proposed framework based on a widely used Distributed Stream Data Processing System (DSDPS), Storm. For validation and performance evaluation, we developed two representative stream data processing applications: Windowed URL Count and Continuous Queries. Extensive experimental results show: 1) The proposed DRNN model outperforms widely used baseline solutions, ARIMA and SVR, in terms of prediction accuracy; 2) dynamic grouping works as expected; and 3) the proposed framework enhances reliability by offering minor performance degradation with misbehaving workers. Jielong Xu, Jian Tang 0008, Chengxiang Yin 0001, Kevin A. Kwiat, Charles A. Kamhoua |
IPDPS | 5 |
| 2019 | Transfer learning for detecting unknown network attacksabstractNetwork attacks are serious concerns in today’s increasingly interconnected society. Recent studies have applied conventional machine learning to network attack detection by learning the patterns of the network behaviors and training a classification model. These models usually require large labeled datasets; however, the rapid pace and unpredictability of cyber attacks make this labeling impossible in real time. To address these problems, we proposed utilizing transfer learning for detecting new and unseen attacks by transferring the knowledge of the known attacks. In our previous work, we have proposed a transfer learning-enabled framework and approach, called HeTL, which can find the common latent subspace of two different attacks and learn an optimized representation, which was invariant to attack behaviors’ changes. However, HeTL relied on manual pre-settings of hyper-parameters such as relativeness between the source and target attacks. In this paper, we extended this study by proposing a clustering-enhanced transfer learning approach, called CeHTL, which can automatically find the relation between the new attack and known attack. We evaluated these approaches by stimulating scenarios where the testing dataset contains different attack types or subtypes from the training set. We chose several conventional classification models such as decision trees, random forests, KNN, and other novel transfer learning approaches as strong baselines. Results showed that proposed HeTL and CeHTL improved the performance remarkably. CeHTL performed best, demonstrating the effectiveness of transfer learning in detecting new network attacks. Juan Zhao 0003, Sachin Shetty, Jan Wei Pan, Charles A. Kamhoua, Kevin A. Kwiat |
EURASIP J. Inf. Secur. | 5 |
| 2018 | ChainFS: Blockchain-Secured Cloud StorageabstractThis work presents ChainFS, a middleware system that secures cloud storage services using a minimally trusted Blockchain. ChainFS hardens the cloud-storage security against forking attacks. The ChainFS middleware exposes a file-system interface to end users. Internally, ChainFS stores data files in the cloud and exports minimal and necessary functionalities to the Blockchain for key distribution and file operation logging. We implement the ChainFS system on Ethereum and S3FS and closely integrate it with FUSE clients and Amazon S3 cloud storage. We measure the system performance and demonstrate low overhead. Yuzhe Tang, Qiwu Zou, Ju Chen, Kai Li 0017, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
IEEE CLOUD | 6 |
| 2018 | QOI: Assessing Participation in Threat Information SharingabstractWe introduce the notion of Quality of Indicator (QoI) to assess the level of contribution by participants in threat intelligence sharing. We exemplify QoI by metrics of the correctness, relevance, utility, and uniqueness of indicators. We build a system that extrapolates the metrics using a machine learning process over a reference set of indicators. We compared these results against a model that only considers the volume of information as a metric for contribution, and unveiled various observations, including the ability to spot low-quality contributions that are synonymous to free-riding. Jeman Park 0001, Hisham Alasmary, Omar Al-Ibrahim, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla, David Mohaisen |
ICASSP | 5 |
| 2018 | Enabling Cooperative IoT Security via Software Defined Networks (SDN)abstractInternet of Things (IoT) is becoming an increasingly attractive target for cybercriminals. We observe that many attacks to IoTs are launched in a collusive way, such as brute-force hacking usernames and passwords, to target at a particular victim. However, most of the time our defending mechanisms to such kind of attacks are carried out individually and independently, which leads to ineffective and weak defense. To this end, we propose to leverage Software Defined Networks (SDN) to enable cooperative security for legacy IP-based IoT devices. SDN decouples control plane and data plane, and can help bridge the knowledge divided between the application and network layers. In this paper, we discuss the IoT security problems and challenges, and present an SDN-based architecture to enable IoT security in a cooperative manner. Furthermore, we implemented a platform that can quickly share the attacking information with peer controllers and block the attacks. We carried out our experiments in both virtual and physical SDN environments with OpenFlow switches. Our evaluation results show that both environments can scale well to handle attacks, but hardware implementation is much more efficient than a virtual one. Garegin Grigoryan, Yaoqing Liu, Laurent Njilla, Charles A. Kamhoua, Kevin A. Kwiat |
ICC | 5 |
| 2018 | Establishing evolutionary game models for CYBer security information EXchange (CYBEX)
Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat |
J. Comput. Syst. Sci. | 4 |
| 2018 | GPU-Accelerated High-Throughput Online Stream Data ProcessingabstractThe Single Instruction Multiple Data (SIMD) architecture of Graphic Processing Units (GPUs) makes them perfect for parallel processing of big data. In this paper, we present the design, implementation and evaluation of G-Storm, a GPU-enabled parallel system based on Storm, which harnesses the massively parallel computing power of GPUs for high-throughput online stream data processing. G-Storm has the following desirable features: 1) G-Storm is designed to be a general data processing platform as Storm, which can handle various applications and data types. 2) G-Storm exposes GPUs to Storm applications while preserving its easy-to-use programming model. 3) G-Storm achieves high-throughput and low-overhead data processing with GPUs. 4) G-Storm accelerates data processing further by enabling Direct Data Transfer (DDT), between two executors that process data at a common GPU. We implemented G-Storm based on Storm 0.9.2 and tested it using three different applications, including continuous query, matrix multiplication and image resizing. Extensive experimental results show that 1) Compared to Storm, G-Storm achieves over 7χ improvement on throughput for continuous query, while maintaining reasonable average tuple processing time. It also leads to 2.3χ and 1.3χ throughput improvements on the other two applications, respectively. 2) DDT significantly reduces data processing time. Zhenhua Chen 0006, Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Charles A. Kamhoua, Chonggang Wang |
IEEE Trans. Big Data | 4 |
| 2018 | On Random Dynamic Voltage Scaling for Internet-of-Things: A Game-Theoretic ApproachabstractSecurity is one of the top considerations in hardware designs for Internet-of-Things (IoT), where embedded cryptosystems are extensively used. Traditionally, random dynamic voltage scaling technology has been shown to be very effective in improving the resistance of cryptosystems against side-channel attacks. However, in this paper we demonstrate that the resistance can be undermined by providing lower off-chip power supply voltage. In order to address this issue, we then further propose to monitor the off-chip power supply voltage, and trigger an alarm to protect valued information once the power supply voltage is lower than the expected voltage (threshold voltage). However, considering both maintenance cost of IoT devices and the environment noise on power supply voltage, we first formulated this problem as a nonzero sum game model, and the attacker and the circuit supplier (defender) are the players of this game. The analysis of the Nash equilibria in this game show interesting guideline to the defender about the choice of threshold voltage, which is based on parameters of cryptosystem including the value of information, denial-of-service cost in IoT, etc. Hui Geng, Kevin A. Kwiat, Charles A. Kamhoua, Yiyu Shi 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2018 | Combating Data Leakage Trojans in Commercial and ASIC Applications With Time-Division Multiplexing and Random Encoding
Travis E. Schulze, Daryl G. Beetner, Yiyu Shi 0001, Kevin A. Kwiat, Charles A. Kamhoua |
IEEE Trans. Very Large Scale Integr. Syst. | 4 |
| 2017 | Cloud Standards in Comparison: Are New Security Frameworks Improving Cloud Security?abstractThe increasing relevance of information assurance in cloud computing has forced governments and stakeholders to turn their attention to Information Technology (IT) security certifications and standards. The introduction of new frameworks such as FedRAMP in the US and C5 in Germany is aimed to raise the level of protection against threats and vulnerabilities unique to cloud computing. However, our in-depth and systematic analyses reveals that these new standards do not bring a radical change in the realm of certifications. Results also shows that the newly developed standards share much of their basis with older, more consolidated standards such as the ISO/IEC 27001 and hence the need for determining the added value. In this study, we provide an overview of ISO/IEC 27001, C5, and FedRAMP while examining their completeness and adequacy in addressing current threats to cloud assurance. We question the level of protection they offer by comparing these three certifications alongside each other. We identify weaknesses in the three frameworks and highlight necessary improvements to meet the security requirements indispensable in relation to the current threat landscape. Carlo Di Giulio, Read Sprabery, Charles A. Kamhoua, Kevin A. Kwiat, Roy H. Campbell, Masooda N. Bashir |
CLOUD | 4 |
| 2017 | Man in the Cloud (MITC) Defender: SGX-Based User Credential Protection for Synchronization Applications in Cloud Computing PlatformabstractIn cloud environment, client user credential protection is a critical security capability that is target of adversarial attacks, especially, in cloud file synchronization applications. Among the various adversarial attacks, MITC (Man in the Cloud) attack on commercial cloud storage applications has emerged as a critical threat because it is easy to launch and hard to detect. In this paper, we propose MITC Defender, a hardware-based defense system capable of protecting client user credentials using Intel Software Guard Extensions (SGX) and preventing against four different types of MITC attack in cloud environment. By adopting Intel SGX security features such as sealing and attestation, MITC Defender can securely seal user credentials locally and easily unseal user credentials, when verifications are needed, in a Trusted Execution Environment (TEE). We implement MITC Defender on an open source platform OpenSGX and evaluate the performance and potential overhead. Our evaluation results show that MITC Defender is effective on defense against MITC attack and other security threats with a low cost. Xueping Liang, Sachin Shetty, Lingchen Zhang, Charles A. Kamhoua, Kevin A. Kwiat |
CLOUD | 5 |
| 2017 | IT Security and Privacy Standards in Comparison: Improving FedRAMP Authorization for Cloud Service ProvidersabstractTo demonstrate compliance with privacy and security principles, information technology (IT) service providers often rely on security standards and certifications. However, the appearance of new service models such as cloud computing has brought new threats to information assurance, weakening the protection that existing standards can provide. In this study, we analyze four highly regarded IT security standards used to assess, improve, and demonstrate information systems assurance and cloud security. ISO/IEC 27001, SOC 2, C5, and FedRAMP are standards adopted worldwide and constantly updated and improved since the first release of ISO in 2005. We examine their adequacy in addressing current threats to cloud security, and provide an overview of the evolution over the years of their ability to cope with threats and vulnerabilities. By comparing the standards alongside each other, we investigate their complementarity, their redundancies, and the level of protection they offer to information stored in cloud systems. We unveil vulnerabilities left unaddressed in the four frameworks, thus questioning the necessity of multiple standards to assess cloud assurance. We suggest necessary improvements to meet the security requirements made indispensable by the current threat landscape. Carlo Di Giulio, Charles A. Kamhoua, Roy H. Campbell, Read Sprabery, Kevin A. Kwiat, Masooda N. Bashir |
CCGrid | 5 |
| 2017 | ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and AvailabilityabstractCloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 5 |
| 2017 | Security Implications of Blockchain Cloud with Analysis of Block Withholding AttackabstractThe blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations. Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 5 |
| 2017 | Estimation of Safe Sensor Measurements of Autonomous System Under AttackabstractThe introduction of automation in cyber-physical systems (CPS) has raised major safety and security concerns. One attack vector is the sensing unit whose measurements can be manipulated by an adversary through attacks such as denial of service and delay injection. To secure an autonomous CPS from such attacks, we use a challenge response authentication (CRA) technique for detection of attack in active sensors data and estimate safe measurements using the recursive least square algorithm. For demonstrating effectiveness of our proposed approach, a car-follower model is considered where the follower vehicle's radar sensor measurements are manipulated in an attempt to cause a collision. Raj Gautam Dutta, Xiaolong Guo 0001, Teng Zhang 0002, Kevin A. Kwiat, Charles A. Kamhoua, Laurent Njilla, Yier Jin |
DAC | 4 |
| 2017 | Automatic Generation of Hardware Sandboxes for Trojan Mitigation in Systems on Chip (Abstract Only)
Christophe Bobda, Taylor J. L. Whitaker, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
FPGA | 4 |
| 2017 | A game theoretic approach for inspecting web-based malvertisingabstractWeb-based advertising system has become a convenient and efficient channel for advertisers to deliver ads to targeted Internet users. Unfortunately, this system has been exploited by cybercriminals to disseminate malware to an enormous number of end-users and their vulnerable machines. To protect their malicious ads and malware from detection by the ad network, malvertisers apply a variety of evasion techniques such as fingerprinting the execution environment, redirecting to compromised IP addresses, and malware polymorphism. On the other hand, the ad network can also apply inspection techniques to spoil the malvertiser's tricks and expose the malware. However, both the malvertiser and the ad network are under the constraints of resource and time. In this paper, we aim to apply game theory to formulate the problem of inspecting the malware inserted by the malvertisers into the Web-based advertising system. We design a normal form game between the malvertiser and the ad network, define their strategies and payoff functions, and compute their pure-strategy and mixed-strategy Nash equilibria. We use numeric simulation to evaluate our game theoretic models, and derive several insights from the results that can serve as guidelines for the ad network to decide its best inspection strategy. Chin-Tser Huang, Muhammad N. Sakib, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
ICC | 4 |
| 2017 | Electric grid power flow model camouflage against topology leaking attacksabstractThe power flow model for DC power grids has been used theoretically to launch false data injection attacks (FDIAs) against state estimation. We recognize FDIAs are just one possible attack using the power flow model and that the grid topology information within the model implies its discovery may also facilitate topology-based attacks. We show attackers can derive the power flow model, and thus the topology also. Indeed, with incomplete data, attackers can accurately reconstruct regions of the model, or topology, all that is necessary to launch an attack. We also illustrate how to cause such attackers to derive instead a convincing fake model by camouflaging the real model. Consequently, no sensitive information will leak, so attacks based on this fake model will be ineffective, rather alerting grid administrators to the attacker's efforts. Using five test cases included in the MATLAB power flow analysis tool MATPOWER, ranging from 9 to 300 buses, an average 67.0% of the topology may be derived with a 69.1% model accuracy. Lastly, we find reconstructions of small portions of the model sufficient for performing FDIAs with 75% success, and that camouflage prevents 93% of them in all but the 9-bus case. Ian D. Markwood, Yao Liu 0007, Kevin A. Kwiat, Charles A. Kamhoua |
INFOCOM | 3 |
| 2016 | Quick Eviction of Virtual Machines through Proactive SnapshotsabstractLive migration of Virtual Machines (VMs) is a key technique to quickly migrate workloads in response to events such as impending failure or load changes. Despite extensive research, state-of-the-art live migration approaches take a long time to migrate a VM, which in turn negatively impacts the application performance during migration. We present, Quick Eviction, a new approach to significantly speed up the eviction of a VM from the source host with low impact on VM's performance during migration. Before migration, Quick Eviction regularly snapshots the VM's memory to a destination or a failover node. During the actual migration, Quick Eviction has to transfer only a small amount of dirtied memory resulting in a very short time to completely evict the VM out of the source. Our experimental results show that Quick Eviction in the KVM/QEMU platform significantly reduces the eviction time. Dinuni K. Fernando, Hardik Bagdi, Yaohui Hu, Ping Yang 0002, Kartik Gopalan, Charles A. Kamhoua, Kevin A. Kwiat |
CLUSTER | 7 |
| 2015 | Security-Aware Virtual Machine Allocation in the Cloud: A Game Theoretic ApproachabstractWith the growth of cloud computing, many businesses, both small and large, are opting to use cloud services compelled by a great cost savings potential. This is especially true of public cloud computing which allows for quick, dynamic scalability without many overhead or long-term commitments. However, one of the largest dissuasions from using cloud services comes from the inherent and unknown danger of a shared platform such as the hyper visor. An attacker can attack a virtual machine (VM) and then go on to compromise the hyper visor. If successful, then all virtual machines on that hyper visor can become compromised. This is the problem of negative externalities, where the security of one player affects the security of another. This work shows that there are multiple Nash equilibria for the public cloud security game. It also demonstrates that we can allow the players' Nash equilibrium profile to not be dependent on the probability that the hyper visor is compromised, reducing the factor externality plays in calculating the equilibrium. Finally, by using our allocation method, the negative externality imposed onto other players can be brought to a minimum compared to other common VM allocation methods. Luke Kwiat, Charles A. Kamhoua, Kevin A. Kwiat, Jian Tang 0008, Andrew P. Martin |
CLOUD | 3 |
| 2015 | G-Storm: GPU-enabled high-throughput online data processing in StormabstractThe Single Instruction Multiple Data (SIMD) architecture of Graphic Processing Units (GPUs) makes them perfect for parallel processing of big data. In this paper, we present the design, implementation and evaluation of G-Storm, a GPU-enabled parallel system based on Storm, which harnesses the massively parallel computing power of GPUs for high-throughput online stream data processing. G-Storm has the following desirable features: 1) G-Storm is designed to be a general data processing platform as Storm, which can handle various applications and data types. 2) G-Storm exposes GPUs to Storm applications while preserving its easy-to-use programming model. 3) G-Storm achieves high-throughput and low-overhead data processing with GPUs. We implemented G-Storm based on Storm 0.9.2 and tested it using two different applications: continuous query and matrix multiplication. Extensive experimental results show that compared to Storm, G-Storm achieves over 7x improvement on throughput for continuous query, while maintaining reasonable average tuple processing time. It also leads to 2.3x throughput improvement for the matrix multiplication application. Zhenhua Chen 0006, Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Charles A. Kamhoua |
IEEE BigData | 4 |
| 2015 | On the use of design diversity in fault tolerant and secure systems: A qualitative analysisabstractThe design and development of modern critical systems, including cyber-physical systems, is experiencing a greater reliance on the outsourcing of systems parts and the use of third-party components and tools. These issues pose new risks and threats that affect dependability in general, and security in particular. Not only the chances are higher for system designs to be faulty, yet they can be maliciously altered. In addition, the extension of monocultures, comprising networks of interconnected systems featuring similar platforms and computing resources, facilitates the spreading and gravity of attacks. Even correctly designed systems can have side behaviors leading to vulnerabilities that are exploitable by attackers. Design diversity, although proposed and used for long time, can help palliate these emerging challenges. This paper explores and analyzes design diversity from a qualitative perspective, with respect to its fault tolerance and performance properties. The paper describes core concepts of design diversity such as non-diversity and diversity points, and provides quality measurements that help gaining a better understanding of how design diversity can impact the development of fault tolerant and secure systems. Kevin A. Kwiat, Charles A. Kamhoua |
CISDA | 2 |
| 2015 | Applying chaos theory for runtime Hardware Trojan detectionabstractHardware Trojans (HTs) are posing a serious threat to the security of Integrated Circuits (ICs). Detecting HT in an IC is an important but hard problem due to the wide spectrum of HTs and their stealthy nature. In this paper, we propose a runtime Trojan detection approach by applying chaos theory to analyze the nonlinear dynamic characteristics of power consumption of an IC. The observed power dissipation series is embedded into a higher dimensional phase space. Such an embedding transforms the observed data to a new processing space, which provides precise information about the dynamics involved. The feature model is then built in this newly reconstructed phase space. The overhead, which is the main challenge for runtime approaches, is reduced by taking advantage of available thermal sensors in most modern ICs. The proposed model has been tested for publicly-available Trojan benchmarks and simulation results show that the proposed scheme outperforms the state-of-the-art method using temperature tracking in terms of detection rate and computational complexity. More importantly, the proposed model does not make any assumptions about the statistical distribution of power trace and no Trojan-active data is needed, which makes it appropriate for runtime use. Kevin A. Kwiat, Charles A. Kamhoua |
CISDA | 2 |
| 2015 | Cyber-Threats Information Sharing in Cloud Computing: A Game Theoretic ApproachabstractCybersecurity is among the highest priorities in industries, academia and governments. Cyber-threats information sharing among different organizations has the potential to maximize vulnerabilities discovery at a minimum cost. Cyber-threats information sharing has several advantages. First, it diminishes the chance that an attacker exploits the same vulnerability to launch multiple attacks in different organizations. Second, it reduces the likelihood an attacker can compromise an organization and collect data that will help him launch an attack on other organizations. Cyberspace has numerous interconnections and critical infrastructure owners are dependent on each other's service. This well-known problem of cyber interdependency is aggravated in a public cloud computing platform. The collaborative effort of organizations in developing a countermeasure for a cyber-breach reduces each firm's cost of investment in cyber defense. Despite its multiple advantages, there are costs and risks associated with cyber-threats information sharing. When a firm shares its vulnerabilities with others there is a risk that these vulnerabilities are leaked to the public (or to attackers) resulting in loss of reputation, market share and revenue. Therefore, in this strategic environment the firms committed to share cyber-threats information might not truthfully share information due to their own self-interests. Moreover, some firms acting selfishly may rationally limit their cybersecurity investment and rely on information shared by others to protect themselves. This can result in under investment in cybersecurity if all participants adopt the same strategy. This paper will use game theory to investigate when multiple self-interested firms can invest in vulnerability discovery and share their cyber-threat information. We will apply our algorithm to a public cloud computing platform as one of the fastest growing segments of the cyberspace. Charles A. Kamhoua, Andrew P. Martin, Deepak K. Tosh, Kevin A. Kwiat, Chad Heitzenrater, Shamik Sengupta |
CSCloud | 4 |
| 2015 | Game Theoretic Modeling to Enforce Security Information Sharing among FirmsabstractRobust CYBersecurity information EXchange (CYBEX) infrastructure is envisioned to protect the firms from future cyber attacks via collaborative threat intelligence sharing, which might be difficult to achieve via sole effort. The executive order from the U. S. federal government clearly encourages the firms to share their cybersecurity breach and patch related information among other federal and private firms for strengthening their as well as nation's security infrastructure. In this paper, we present a game theoretic framework to investigate the economic benefits of cyber-threat information sharing and analyze the impacts and consequences of not participating in the game of information exchange. We model the information exchange framework as distributed non-cooperative game among the firms and investigate the implications of information sharing and security investments. The proposed incentive model ensures and self-enforces the firms to share their breach information truthfully for maximization of its gross utility. Theoretical analysis of the incentive framework has been conducted to find the conditions under which firms' net benefit for sharing security information and investment can be maximized. Numerical results verify that the proposed model promotes such sharing, which helps to relieve their total security technology investment too. Deepak K. Tosh, Shamik Sengupta, Sankar Mukhopadhyay, Charles A. Kamhoua, Kevin A. Kwiat |
CSCloud | 5 |
| 2015 | Contract-Theoretic Resource Allocation for Critical Infrastructure ProtectionabstractCritical infrastructure protection (CIP) is envisioned to be one of the most challenging security problems in the coming decade. One key challenge in CIP is the ability to allocate resources, either personnel or cyber, to critical infrastructures with different vulnerability and criticality levels. In this work, a contract- theoretic approach is proposed to solve the problem of resource allocation in critical infrastructure with asymmetric information. A control center (CC) is used to design contracts and offer them to infrastructures' owners. A contract can be seen as an agreement between the CC and infrastructures using which the CC allocates resources and gets rewards in return. Contracts are designed in a way to maximize the CC's benefit and motivate each infrastructure to accept a contract and obtain proper resources for its protection. Infrastructures are defined by both vulnerability levels and criticality levels which are unknown to the CC. Therefore, each infrastructure can claim that it is the most vulnerable or critical to gain more resources. A novel mechanism is developed to handle such an asymmetric information while providing the optimal contract that motivates each infrastructure to reveal its actual type. The necessary and sufficient conditions for such resource allocation contracts under asymmetric information are derived. Simulation results show that the proposed contract-theoretic approach maximizes the CC's utility while ensuring that no infrastructure has an incentive to ask for another contract, despite the lack of exact information at the CC. AbdelRahman Eldosouky, Walid Saad 0001, Charles A. Kamhoua, Kevin A. Kwiat |
GLOBECOM | 4 |
| 2015 | NAPF: Percolation driven probabilistic flooding for interference limited cognitive radio networksabstractIn this paper, we argue that the traditional techniques for flooding and probabilistic flooding are not applicable to cognitive radio networks under the SINR regime. We identify the causes that i) degrade node outreach even with increasing deployment density under the SINR model and ii) lead to duplicate transmissions under the Boolean model. Further performance degradation occurs due to the additional constraints imposed by the primary users in such networks. To increase node outreach in interference-limited cognitive radio networks, we propose a modified version of probabilistic flooding that uses lower message overhead without compromising network connectivity. This is achieved by having just enough number of neighbors of a node to rebroadcast to others. The subset of neighbors that are selected to broadcast is decided on the number of neighbor a nodes has, their spatial orientation with respect to each other, and the interference they might cause. Identification of such subsets reduce duplicate retransmissions which in turn reduces interference. We use a localized clustering technique in conjunction with the concept of critical density from percolation theory such that each node decides its own rebroadcasting probability in a distributed manner. Through simulations, we compare the proposed technique with flooding and probabilistic flooding. Results validated that, the proposed technique reduces number of rebroadcasts and increases node outreach both under SINR and Boolean models.1 Osama Abbas Al Tameemi, Mainak Chatterjee, Kevin A. Kwiat, Charles A. Kamhoua |
ICC | 3 |
| 2015 | An evolutionary game-theoretic framework for cyber-threat information sharingabstractThe initiative to protect against future cyber crimes requires a collaborative effort from all types of agencies spanning industry, academia, federal institutions, and military agencies. Therefore, a Cybersecurity Information Exchange (CYBEX) framework is required to facilitate breach/patch related information sharing among the participants (firms) to combat cyber attacks. In this paper, we formulate a non-cooperative cybersecurity information sharing game that can guide: (i) the firms (players)1to independently decide whether to “participate in CYBEX and share” or not; (ii) the CYBEX framework to utilize the participation cost dynamically as incentive (to attract firms toward self-enforced sharing) and as a charge (to increase revenue). We analyze the game from an evolutionary game-theoretic strategy and determine the conditions under which the players' self-enforced evolutionary stability can be achieved. We present a distributed learning heuristic to attain the evolutionary stable strategy (ESS) under various conditions. We also show how CYBEX can wisely vary its pricing for participation to increase sharing as well as its own revenue, eventually evolving toward a win-win situation. Deepak K. Tosh, Shamik Sengupta, Charles A. Kamhoua, Kevin A. Kwiat, Andrew P. Martin |
ICC | 4 |
| 2015 | Cost-Efficient Virtual Server Provisioning and Selection in distributed Data CentersabstractIn this paper, we study a Virtual Server Provisioning and Selection (VSPS) problem in distributed Data Centers (DCs) with the objective of minimizing the total operational cost while meeting the service response time requirement.We aim to develop general algorithms for the VSPS problem without assuming a particular queueing model for service processing in each DC. First, we present a Mixed Integer Linear Programming (MILP) formulation. Then we present a 3-step optimization framework, under which we develop a polynomial-time ln(N)-approximation algorithm (where N is the number of clients) along with a post-optimization procedure for performance improvement. We also show this problem is NP-hard to approximate and is not possible to obtain a better approximation ratio unless NP has TIME(nO(log log n)) deterministic time algorithms. In addition, we present an effective heuristic algorithm that jointly obtains the VS provisioning and selection solutions. Extensive simulation results are presented to justify effectiveness of the proposed algorithms. Jielong Xu, Jian Tang 0008, Brendan Mumey, Weiyi Zhang 0001, Kevin A. Kwiat, Charles A. Kamhoua |
ICC | 5 |
| 2015 | Bayesian inference based decision reliability under imperfect monitoringabstractReliability of a cooperative decision mechanism is critical for the proper and accurate functioning of a networked decision system. However, adversaries may choose to compromise the inputs from different sets of components that comprise the system. Often times, the monitoring mechanisms fail to accurately detect compromised inputs; hence cannot categorize all inputs into polarized decisions: compromised or not compromised. In this paper, we propose a Bayesian inference model based on multinomial evidence to quantify reliability for a cooperative decision process as a function of beliefs associated with observations from the imperfect monitoring mechanism. We propose two reliability models: an optimistic one for a normal system and a conservative one for a mission critical system. We also provide an entropy measure that reflects the certainty or uncertainty on the calculated reliability of the decision process. Through simulation, we show how the reliability and its corresponding entropy changes as the accuracy of the underlying monitoring mechanism improves1. Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat, Charles A. Kamhoua |
IM | 3 |
| 2015 | Multi-level VM replication based survivability for mission-critical cloud computingabstractThe elasticity and economics of cloud computing offer significant benefits to mission-critical applications which are increasingly complex and resource demanding. Cloud systems also provide powerful tools such as virtual machine (VM) based replication for defending mission-critical applications. However, cloud-based mission-critical computing raises serious challenges to mission assurance. VM-based consolidation brings different applications to the same set of physical resources, increasing the risk of one user compromising the mission of another. The mission-critical application in a VM lacks the visibility and control to detect and stop outside malicious attacks, whereas the support for security isolation from existing cloud systems is also limited. The objective of the research presented in this paper is to address these challenges and improve the survivability of mission-critical applications through the novel use of VM replication. Specifically, this paper presents a new multi-level VM replication approach which uses different types of VM clones to provide a variety of protections to mission-critical applications, and improve the survivability of the applications under accidental faults and malicious attacks. In this approach, full VM clones are employed to provide tolerance of attacks, decoy clones are created to divert attacks, and honeypot clones are used to analyze attacks. The paper also presents the prototypes of the proposed approach implemented for the widely used OpenStack-based private cloud systems and Amazon-EC2-based public cloud systems. Francois D'Ugard, Kevin A. Kwiat, Charles A. Kamhoua |
IM | 3 |
| 2015 | Vector quantization based QoS evaluation in cognitive radio networks
Osama Abbas Al Tameemi, Mainak Chatterjee, Kevin A. Kwiat |
Wirel. Networks | 3 |
| 2014 | Game Theoretic Modeling of Security and Interdependency in a Public CloudabstractAs cloud computing thrives, many small organizations are joining a public cloud to take advantage of its multiple benefits. Cloud computing is cost efficient, i.e., cloud user can reduce spending on technology infrastructure and have easy access to their information without up-front or long-term commitment of resources. Moreover, a cloud user can dynamically grow and shrink the resources provisioned to an application on demand. Despite those benefits, cyber security concern is the main reason many large organizations with sensitive information such as the Department of Defense have been reluctant to join a public cloud. This is because different public cloud users share a common platform such as the hypervisor. A common platform intensifies the well-known problem of cyber security interdependency. In fact, an attacker can compromise a virtual machine (VM) to launch an attack on the hypervisor which if compromised can instantly yield the compromising of all the VMs running on top of that hypervisor. Therefore, a user that does not invest in cyber security imposes a negative externality on others. This research uses the mathematical framework of game theory to analyze the cause and effect of interdependency in a public cloud platform. This work shows that there are multiple possible Nash equilibria of the public cloud security game. However, the players use a specific Nash equilibrium profile depending on the probability that the hypervisor is compromised given a successful attack on a user and the total expense required to invest in security. Finally, there is no Nash equilibrium in which all the users in a public cloud will fully invest in security. Charles A. Kamhoua, Luke Kwiat, Kevin A. Kwiat, Joon S. Park |
IEEE CLOUD | 3 |
| 2014 | A game theoretic approach to detect and co-exist with malicious nodes in wireless networks
Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
Comput. Networks | 3 |
| 2014 | Trusted Online Social Network (OSN) services with optimal data management
Joon S. Park, Kevin A. Kwiat, Charles A. Kamhoua, Sookyung Kim |
Comput. Secur. | 2 |
| 2014 | Improving System Reliability Against Rational Attacks Under Given ResourcesabstractSystem reliability has always been a challenging issue for many systems. In order to achieve high reliability, redundancy and voting schemes are often used to tolerate unintentional component failures. For unintentional failures caused by, for instance, normal wear-outs, hardware failures, or software bugs, etc., adding more redundancies often improves a system's reliability. However, when attack-caused failures exist, the number of redundant components and the number of participating voting entities may not be positively proportional to system reliability. In this paper, we study system reliability and system defense strategies when the system is under rational attacks. In particular, we analyze how defense and attack strategies may impact system reliability when both the defender and attacker are given a fixed amount of resources that can only be used for adding camouflaging components or enhancing existing components' cyber protection by defenders, or selecting a subset of components to attack by attackers, respectively. We also present an algorithm to decide the optimal defense strategy in fighting against rational attacks. Li Wang 0011, Shangping Ren, Bogdan Korel, Kevin A. Kwiat, Eric Salerno |
IEEE Trans. Syst. Man Cybern. Syst. | 4 |
| 2013 | Game theoretic attack analysis in online social network (OSN) servicesabstractIn the social media era, the ever-increasing utility of Online Social Networks (OSN) services provide a variety of benefits to users, organizations, and service providers. However, OSN services also introduce new threats and privacy issues regarding the data they are dealing with. For instance, in a reliable OSN service, a user should be able to set up his desired level of information sharing and securely manage sensitive data. Currently, few approaches exist that can model OSNs for the purpose, let alone model the effects that attackers can have on these networks. In this work a novel OSN modeling approach is presented to fill the gap. This model is based on an innovative game theoretical approach and it is analyzed both from a theoretical and simulation-oriented view. The game theoretic model is implemented in order to analyze several attack scenarios. As the results show, there are several scenarios where OSN services are very vulnerable and hence more protection mechanisms should be provided in order to secure the data contained across these networks. Joon S. Park, Charles A. Kamhoua, Kevin A. Kwiat |
ASONAM | 4 |
| 2013 | Pricing-based routing in cognitive radio networksabstractIn this paper, we propose a pricing-based routing algorithm in a distributed cognitive radio network. The routing of packets is viewed as a market-based phenomenon where bandwidth is traded between transmitters and receivers. We propose a pricing model using which a seller determines the selling price. We also find the interference that a seller is exposed to since it determines the achievable bit-rate for the bandwidth being sold. As for the buyer, we calculate the bandwidth required from different sellers considering the respective signal to noise ratio. The seller with the minimum price is selected as the next hop relay. Thus, the total price to be paid by a source node is the sum of the prices paid at each hop in the route. Through simulation experiments, we validate the proposed scheme and show the prices for various routes1. Enas F. Khairullah, Mainak Chatterjee, Kevin A. Kwiat |
GLOBECOM | 3 |
| 2013 | Utilizing misleading information for cooperative spectrum sensing in cognitive radio networksabstractIn cognitive radio networks, the radios continuously scan the radio spectrum and create a spectrum usage report. Due to channel uncertainty, there are inaccuracies in these reports. Oftentimes, the radios share and fuse the observed data in order to increase the accuracy of the spectrum usage. However, malicious nodes tend to send false information (i.e., attack) in order to mislead the construction of the spectrum usage report. In this paper, we use a trust model to evaluate the trustworthiness of every node and use the trust values to effectively fuse the information from all nodes. A node compares the information sent by a neighboring node with the predicted information. Based on the ratio of matches (or mismatches), the neighboring node is assigned a trust value. Then, we propose a log-weighted metric utilizing trust values to distinguish malicious nodes from others. Subsequently, we propose threshold based Selective Inversion (SI) fusion and Complete Inversion (CI) fusion to effectively combine not only the information sent by honest nodes but also utilize misleading information sent by malicious nodes. We also propose a combination of the two inversion schemes. We compare the performance of the inversion based fusion schemes with blind and trust-based fusions. Results reveal better performance for inversion based fusion schemes for various intensities of attack. We also conduct simulations to evaluate the optimal thresholds that are used for invoking the inversion based fusion schemes. Shameek Bhattacharjee, Saptarshi Debroy, Mainak Chatterjee, Kevin A. Kwiat |
ICC | 4 |
| 2013 | Modeling cooperative, selfish and malicious behaviors for Trajectory Privacy Preservation using Bayesian game theoryabstractAs new mobile Wireless Sensor Networks (mWSNs) for location-aware applications are emerging, trajectory privacy invasion is becoming an indispensable issue. Many promising techniques are under development. Considering the decentralized network architecture, most of Trajectory Privacy Preservation (TPP) techniques rely on the cooperation from peer nodes, cluster headers, or a third party. However, only a few works have addressed the issue of selfish behaviors in such cooperation required techniques. Nevertheless, the problem of facing selfish and compromised nodes in the noncooperative and hostile environment is rarely touched. In this paper, we apply Bayesian game theory to model cooperative, selfish and malicious behaviors of autonomous mobile nodes in decentralized mWSNs. We formulate and analyze the TPP game among peer nodes in both strategic and dynamic forms. The equilibrium strategies for users to evaluate the degree of trust in participating in in-network TPP activities are provided and analyzed in theoretical and simulation results. Niki Pissinou, Sitthapon Pumpichet, Charles A. Kamhoua, Kevin A. Kwiat |
LCN | 5 |
| 2013 | Enhancing Survivability in Virtualized Data Centers: A Service-Aware ApproachabstractIn this paper, we propose a service-aware approach to enhance survivability in virtualized data centers. The idea is to create and maintain a Survivable Virtual Infrastructure (SVI) for each service or tenant, which includes Virtual Machines (VMs) hosting the corresponding application and their backup VMs. A fundamental problem is to determine how to map each SVI to a data center network with minimum operational costs while satisfying each VM's resource requirements and bandwidth demands between VMs before and after failures. This problem can be naturally divided into two subproblems: VM Placement (VMP) and Virtual Link Mapping (VLM). We first present a general optimization framework. Then we propose an efficient algorithm for VMP, and a polynomial-time optimal algorithm for VLM, which can be used as subroutines in the framework. We also present an effective heuristic algorithm that jointly solves two subproblems. It has been shown by extensive simulation results based on the real VM workload traces collected from Syracuse University's green data center that compared to the First Fit Decreasing (FFD) and shortest path routing based baseline algorithm, the proposed algorithms significantly reduce the reserved bandwidth, and yield comparable results in terms of the number of active servers. \begin{keywords}Cloud Computing, Data Center, Service-aware, Survivability, Virtual Machine Management. \end{keywords} Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Weiyi Zhang 0001, Guoliang Xue |
IEEE J. Sel. Areas Commun. | 3 |
| 2013 | Collaborative jamming and collaborative defense in cognitive radio networks
Wenjing Wang 0006, Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat |
Pervasive Mob. Comput. | 4 |
| 2013 | Component survivability at runtime for mission-critical distributed systems
Joon S. Park, Pratheep Chandramohan, Avinash T. Suresh, Joseph Giordano, Kevin A. Kwiat |
J. Supercomput. | 5 |
| 2012 | Survivable Virtual Infrastructure Mapping in Virtualized Data CentersabstractIn a virtualized data center, survivability can be enhanced by creating redundant Virtual Machines (VMs) as backup for VMs such that after VM or server failures, affected services can be quickly switched over to backup VMs. To enable flexible and efficient resource management, we propose to use a service-aware approach in which multiple correlated VMs and their backups are grouped together to form a Survivable Virtual Infrastructure (SVI) for a service or a tenant. A fundamental problem in such a system is to determine how to map each SVI to a physical data center network such that operational costs are minimized subject to the constraints that each VM's resource requirements are met and bandwidth demands between VMs can be guaranteed before and after failures. This problem can be naturally divided into two sub-problems: VM Placement(VMP) and Virtual Link Mapping (VLM). We present a general optimization framework for this mapping problem. Then we present an efficient algorithm for the VMP sub problem as well as a polynomial-time algorithm that optimally solves the VLM sub problem, which can be used as subroutines in the framework. We also present an effective heuristic algorithm that jointly solves the two sub problems. It has been shown by extensive simulation results based on the real VM data traces collected from the green data center at Syracuse University that compared with the First Fit Descending (FFD) and single shortest path based baseline algorithm, both our VMP+VLM algorithm and joint algorithm significantly reduce the reserved bandwidth, and yield comparable results in terms of the number of active servers. Jielong Xu, Jian Tang 0008, Kevin A. Kwiat, Weiyi Zhang 0001, Guoliang Xue |
IEEE CLOUD | 3 |
| 2012 | Hierarchical adaptive QoS control for voting-based data collection in hostile scenarios
Mohammad Rabby, Kaliappa Nadar Ravindran, Kevin A. Kwiat |
CNSM | 3 |
| 2012 | Optimal content delivery in DSA networks: A path auction based frameworkabstractIn this paper, we address the problem of Optimal Content Delivery (OCD) in Dynamic Spectrum Access (DSA) networks, where the source of a flow sends data traffic to the destination in exchange for some monetary benefit, such as a subscription fee. Also, each intermediate secondary node incurs a cost for routing traffic. We propose a path auction based content delivery mechanism in which each secondary node announces its cost (considered as private information) to the auction mechanism. Based on the announced costs, the optimal flow rate between the end nodes is determined, a multi-path route is chosen and payments are made to the nodes that route traffic, such that the profit of the source node is maximized in sending data to the destination. Furthermore, the auction mechanism is strategy-proof, i.e., it can induce the intermediate nodes to truthfully declare their costs. We provide polynomial time algorithms for implementing our auction based content delivery mechanism in DSA networks. Swastik Brahma, Pramod K. Varshney, Mainak Chatterjee, Kevin A. Kwiat |
ICC | 4 |
| 2012 | Optimal State Management of Data Sharing in Online Social Network (OSN) ServicesabstractAlthough Online Social Network (OSN) services offer users a variety of benefits, they also bring new threats and privacy issues to the community. In this paper, we first define the data types in OSN services and the states of shared data with respect to Optimal, Under-shared, Over-shared, and Hybrid states. We also identify the facilitating, detracting, and preventive parameters that are responsible for the state transition of the data. We address that, in a reliable OSN service, a user should be able to set up his or her desired level of information sharing with a certain group of other users. However, it is not always clear to the ordinary users how to decide how much information they should reveal to others. Therefore, we propose an approach for helping OSN users determine their optimum levels of information sharing, taking into consideration the payoffs (potential Reward or Cost) based on the Markov decision process (MDP). Joon S. Park, Sookyung Kim, Charles A. Kamhoua, Kevin A. Kwiat |
TrustCom | 4 |
| 2012 | An effective use of spectrum usage estimation for IEEE 802.22 networksabstractIEEE 802.22 networks consist of base stations and consumer premise equipments (CPEs) where the base station in each cell opportunistically accesses and allocates (uplink and downlink) channels to all the CPEs in its cell. Information on white space (unused primary channels) availability is reported by the CPEs to the base stations. Thus, a base station's effectiveness to allocate channels are based on its ability to gauge the spectrum usage at various locations. In this paper, we propose a channel usage estimation framework where a base station uses the spectrum reports from other neighboring base stations to estimate the spectrum usage scenario at any arbitrary location within its cell. Our estimation framework is based on Shepard's interpolation technique for irregular points. We propose a channel allocation scheme that minimizes interference among CPEs and maximizes white space utilization. Through simulation experiments, we demonstrate the accuracy of the estimation technique, utilization of the available spectrum, and efficiency of allocation scheme. We also show that our scheme achieves very low false positives and no false negatives. Finally, we show that the optimal number of base stations that need to be consulted is in accordance with Shepard's bounds1. Saptarshi Debroy, Shameek Bhattacharjee, Mainak Chatterjee, Kevin A. Kwiat |
WCNC | 4 |
| 2012 | Traffic management in wireless sensor networks: Decoupling congestion control and fairness
Swastik Brahma, Mainak Chatterjee, Kevin A. Kwiat, Pramod K. Varshney |
Comput. Commun. | 3 |
| 2011 | Optimal Voting Strategy Against Rational AttackersabstractVoting algorithms are often used to improve a system's reliability through fault tolerance. However, when both the reliability of individual voters and the existence of rational attackers are taken into consideration, the number of voters that participate in an actual voting process determines the fault-and-attack tolerance performance of voting algorithms. In this paper, we are to find an optimal voting strategy (i.e., the optimal number of participating voters) against rational attackers whose goal is to defect the system by strategically compromising individual voters across the system. We model the problem of deciding the number of participating voters against rational attackers as a two-person zero-sum game problem and provide solutions based on the results from this well-known game problem. A set of experiments are performed to illustrate the voting strategy's performance in the presences of rational attackers. Li Wang 0011, Zheng Li 0006, Shangping Ren, Kevin A. Kwiat |
CRiSIS | 4 |
| 2011 | Trust based fusion over noisy channels through anomaly detection in cognitive radio networksabstractByzantine attacks have been identified as one of the key vulnerabilities in cognitive radio networks, where malicious nodes advertise false spectrum occupancy data in a cooperative environment. In such cases, the resultant fused data is very different from the actual scenario. Thus, there is a need to identify the malicious nodes or at least find the trustworthiness of nodes such that the data sent by malicious nodes could be filtered out. The process is complicated by presence of noise in the channel which makes it harder to distinguish anomalies caused by malicious activity and those caused due to unreliable noisy channels. Shameek Bhattacharjee, Saptarshi Debroy, Mainak Chatterjee, Kevin A. Kwiat |
SIN | 4 |
| 2011 | Improving operation time bounded mission critical systems' attack-survivability through controlled source-code transformationabstractMission critical systems often operate for limit time durations. For these systems, we subscribe to the notion that provisioning of security can be based on the expected duration of a system's mission. In this paper, we present a simple and safe K-variant approach to improve time-based mission critical systems' attack-survivability and provide formal analysis about K-variant system's attack survivability under M memory-based attack attempts. Our theoretical analysis supported by extensive simulations and a case study provide good evidences that the proposed approach may be in improving system's attack-survivability. Bogdan Korel, Shangping Ren, Kevin A. Kwiat, Arnaud Auguste, Alban Vignaux |
SIN | 3 |
| 2011 | Fault tolerance for fight-through: a basis for strategic survivalabstractConcepts from the domain of fault-tolerant computing cannot be merely adopted for cyber defense; instead they have to be adapted. Kevin A. Kwiat |
SIN | 1 |
| 2011 | Collaborative jamming and collaborative defense in Cognitive Radio NetworksabstractCognitive Radio Network (CRN) is one of the prominent communication technologies that is touted to drive the next generations of digital communications. In this paper, we address the vulnerabilities in such networks and analyze a common form of the Denial-of-Service attack, i.e., collaborative jamming. In particular, we model and analyze the channel availability when different jamming and defending schemes are employed by the attackers and legitimate users. Cooperative defense strategy is proposed to exploit the temporal and spatial diversity for the legitimate secondary users. Illustrative results show how to improve the resiliency in CRN against jamming attacks. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
WOWMOM | 3 |
| 2011 | A dynamic reconfigurable routing framework for wireless sensor networks
Mukundan Venkataraman, Mainak Chatterjee, Kevin A. Kwiat |
Ad Hoc Networks | 3 |
| 2011 | Cooperation in Wireless Networks with Unreliable ChannelsabstractIn a distributed wireless system, multiple network nodes behave cooperatively towards a common goal. An important challenge in such a scenario is to attain mutual cooperation. This paper provides a non-cooperative game theoretic solution to enforce cooperation in wireless networks in the presence of channel noise. We focus on one-hop information exchange and model the packet forwarding process as a hidden action game with imperfect private monitoring. We propose a state machine based strategy to reach Nash Equilibrium. The equilibrium is proved to be a sequential one with carefully designed system parameters. Furthermore, we extend our discussion to a general wireless network scenario by considering how cooperation can prevail over collusion using evolutionary game theory. The simulation results are provided to back our analysis. In particular, network throughput performance is measured with respect to parameters like channel loss probability, route hop count, and mobility. Results suggest that the performance due to our proposed strategy is in close agreement with that of unconditionally cooperative nodes. Simulation results also reveal how the convergence of cooperation enforcement is affected by initial population share and channel unreliability. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
IEEE Trans. Commun. | 3 |
| 2010 | Attacker Detection Game in Wireless Networks with Channel UncertaintyabstractIdentification and isolation of attackers in a distributed system is a challenging problem. This problem is even more aggravated in a wireless network because the unreliable channel makes the actions of the users (nodes) hidden from each other. Therefore, legitimate users can only construct a belief about a potential attacker through monitoring and observation. In this paper, we use game theory to study the interactions between regular and attacker nodes in a wireless network. We model the attacker node detection process as a Bayesian game with imperfect information and show that a mixed strategy perfect Bayesian Nash Equilibrium is attainable. Further, we show how an attacker node can construct a nested belief system to predict the belief held by a regular node. By employing the nested belief system, a Markov Perfect Bayes-Nash Equilibrium is reached and the equilibrium postpones the detection of the attacker node. Simulation results and their discussions are provided to illustrate the properties of the derived equilibria. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
ICC | 3 |
| 2010 | A Multi-step Simulation Approach toward Secure Fault Tolerant System EvaluationabstractAs new techniques of fault tolerance and security emerge, so does the need for suitable tools to evaluate them. Generally, the security of a system can be estimated and verified via logical test cases, but the performance overhead of security algorithms on a system needs to be numerically analyzed. The diversity in security methods and design of fault tolerant systems make it impossible for researchers to come up with a standard, affordable and openly available simulation tool, evaluation framework or an experimental test-bed. Therefore, researchers choose from a wide range of available modeling-based, implementation-based or simulation-based approaches in order to evaluate their designs. All of these approaches have certain merits and several drawbacks. For instance, development of a system prototype provides a more accurate system analysis but unlike simulation, it is not highly scalable. This paper presents a multi-step, simulation-based performance evaluation methodology for secure fault tolerant systems. We use a divide-and-conquer approach to model the entire secure system in a way that allows the use of different analytical tools at different levels of granularity. This evaluation procedure tries to strike a balance between the efficiency, effort, cost and accuracy of a system's performance analysis. We demonstrate this approach in a step-by-step manner by analyzing the performance of a secure and fault tolerant system using a JAVA implementation in conjunction with the ARENA simulation. Ruchika Mehresh, Shambhu J. Upadhyaya, Kevin A. Kwiat |
SRDS | 3 |
| 2010 | A Game Theoretic Framework for Power Control in Wireless Sensor NetworksabstractIn infrastructure-less sensor networks, efficient usage of energy is very critical because of the limited energy available to the sensor nodes. Among various phenomena that consume energy, radio communication is by far the most demanding one. One of the effective ways to limit unnecessary energy loss is to control the power at which the nodes transmit signals. In this paper, we apply game theory to solve the power control problem in a CDMA-based distributed sensor network. We formulate a noncooperative game under incomplete information and study the existence of Nash equilibrium. With the help of this equilibrium, we devise a distributed algorithm for optimal power control and prove that the system is power stable only if the nodes comply with certain transmit power thresholds. We show that even in a noncooperative scenario, it is in the best interest of the nodes to comply with these thresholds. The power level at which a node should transmit, to maximize its utility, is evaluated. Moreover, we compare the utilities when the nodes are allowed to transmit with discrete and continuous power levels; the performance with discrete levels is upper bounded by the continuous case. We define a distortion metric that gives a quantitative measure of the goodness of having finite power levels and also find those levels that minimize the distortion. Numerical results demonstrate that the proposed algorithm achieves the best possible payoff/utility for the sensor nodes even by consuming less power. Shamik Sengupta, Mainak Chatterjee, Kevin A. Kwiat |
IEEE Trans. Computers | 3 |
| 2009 | Cooperation in Ad Hoc Networks with Noisy ChannelsabstractAn underlying assumption of multi-hop data communication in ad hoc networks is that the nodes forward each others' packets. An important challenge in such scenario is to attain mutual cooperation. This paper provides a game theoretic solution to enforce cooperation in ad hoc network in the presence of channel noise. We focus on the packet forwarding process and model it as a hidden action game with imperfect private monitoring. We propose a state machine based strategy to reach Nash Equilibrium. The equilibrium is proved to be a sequential equilibrium with carefully designed system parameters. Furthermore, we extend our discussion to a general ad hoc network scenario by refining the strategy profiles to handle multi-hop packet forwarding. The simulation results illustrate the efficiency of the proposed forwarding strategies. In addition, network throughput performance is measured with respect to parameters like channel loss probability, route hop count and mobility. Results suggest that the performance due to our proposed strategy is in close agreement with that of unconditionally cooperative nodes. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
SECON | 3 |
| 2009 | Dynamic spectrum access in cognitive radio based tactical networksabstractIn this paper, we investigate how cognitive radio (CR) enabled devices can self-organize to form a tactical mesh network and operate on non-dedicated (secondary) spectrum. Each node in the network constantly senses the environment and maintains an up-to-date spectrum usage report. This report is used by a central controller (CC) to initialize the network formation. Then the other CR nodes gradually join the mesh network in a repeated, distributed manner. We provide the detailed steps for the mesh creation and also propose some refinements. We also compute the spectral efficiency that is achieved through our algorithm. Through simulation experiments, we study the effectiveness of the proposed schemes on mesh initialization latency, control signaling, collision rate during network initialization, and spectrum utilization. Shamik Sengupta, Mainak Chatterjee, Kevin A. Kwiat |
WCNC | 3 |
| 2009 | Traffic based dynamic routing for wireless sensor networksabstractNumerous routing protocols have been proposed for wireless sensor networks, each of which is highly optimized for a certain class of traffic, like real time, reliable sense and disseminate, network reprogramming, energy efficiency and so on. However, a typical deployment demands an arbitrary communication pattern that generates multiple traffic types simultaneously. Arguably, no single routing protocol can completely cater to a deployment's various flavors. In this paper, we propose a dynamic routing framework that can replace the traditional routing layer with a collection of routing decisions. We allow application packets to carry a two-bit preamble that uniquely describes the nature of communication sought for. The framework dynamically wires the appropriate routing component from a set of well-defined suite. We conduct extensive simulation experiments that generates a concurrent mix of different traffic types - each having its own, and often conflicting, communication demands. For such an application, we show that we could meet each traffic types demands for reliability, delay, path distribution, link losses and congestion losses. We also show that service differentiation can indeed be met successfully, and practical deployments can be an imminent reality. Mukundan Venkataraman, Mainak Chatterjee, Kevin A. Kwiat |
WCNC | 3 |
| 2009 | User-input driven QoS management in ad hoc networks
Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
Comput. Commun. | 3 |
| 2008 | Adaptive Voting Algorithms for Reliable Dissemintation of Data in Sensor NetworksabstractA real-time data collection system in sensor network settings requires dealing with failures in the network and in the external environment: such as data corruptions by malicious devices and message timeliness violations in the network. Functional replication is employed to deal with such failures, with voting among the replica devices to move a correct data to the end-user. The goal of our paper is to develop a voting system that dynamically adapts its internal mechanisms to deal with various types of failures. The paper presents the design issues, with considerations of protocol correctness and performance. A goal is to reduce the message overhead - and hence the power drain on wireless connected sensor devices. Kaliappa Nadar Ravindran, Kevin A. Kwiat, Ali Sabbir |
ARES | 3 |
| 2008 | A Non-Intrusive Approach to Enhance Legacy Embedded Control Systems with Cyber Protection FeaturesabstractUnlike general purpose systems, distributed and embedded control systems, such as power grid control systems and water treatment systems, etc., generally have a 24x7 availability requirement. Hence, upgrading or adding new cyber protection features into these systems in order to sustain them when faults caused by cyber attacks occur, is often difficult to achieve and inhibits the evolution of these systems into a cyber environment. In this paper, we present a solution for extending the capabilities of existing systems while simultaneously maintaining the stability of the current systems. An externalized survivability management scheme based on the observe-reason-modify paradigm is applied, which decomposes the cyber attack protection process into three orthogonal subtasks: observation, evaluation and protection. This architecture provides greater flexibility and has an evolvability attribute - it can utilize emerging techniques; yet requires either minimal modifications or even no modifications whatsoever to the controlled infrastructures. The approach itself is general and can be applied to a broad class of observable systems. Shangping Ren, Kevin A. Kwiat |
ARES | 2 |
| 2008 | Enforcing cooperation in ad hoc networks with unreliable channelabstractAn inherent assumption for packet forwarding in ad hoc networks is that the nodes will cooperate i.e., nodes can rely in each other. Thus, it is extremely important that cooperation is induced and achieved in the network. In this paper, we use game theory to analyze the necessary and sufficient conditions to enforce cooperation enforced, especially when a node cannot perfectly monitor other nodespsila behaviors. We analyze a credit exchange method under a general unreliable channel and show that the packet forwarding probability can be adjusted through proper design of incentives, which in turn can be used to attain the desired Nash Equilibrium. We extend our discussion to repeated games and take several well-known strategy profiles and derive the conditions under which the cooperation can lead to a subgame perfect Nash equilibrium. In particular, we show how the unreliable channel can affect the conditions and how a reputation based strategy leads to subgame perfection even under imperfect monitoring. We further investigate collusion resistance and cooperation coalition formation using evolutionary game theory. Mathematical proofs show the existence of an upper bound on the population share of the non-cooperative nodes for an evolutionarily non-stable strategy that enforces full cooperation. This bound is shown to depend on the nodespsila belief on the continuity of the game. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
MASS | 3 |
| 2007 | Take Intelligent Risk and Optimize Decision Based on Time, Available Resources and Risk Tolerance LimitsabstractIn real-time environment, data usually has a lifespan associated with it. The semantics and the importance of the data depend on the time when data is utilized. Hence, the process of getting a consensus data from a group of replicated units must not take longer time than the lifespan of the data. However, in real environment, every unit, faulty or non-faulty, may encounter delays when processing and sending their data which inevitably increases the time of acquiring a consensus. The latency for obtaining a valid data hence depends not only on the time when individual replicas make their votes, but also on the accuracy and credibility of the votes. Thus, a new metric, i.e. a credibility function, needs to be taken into account when evaluating expected time and deciding upon data replications. This paper presents analytical solutions for the expected time when dependable data can be obtained under different voting schemes. We show that if not all replicas are truthful, increasing replication does not reduce the time for obtaining valid results. When different types of resources are used to ensure the quality of the data, we show that the allocation of the resource plays an important role in satisfying both data availability and consistency constraints. We further demonstrate that when point-based constraints may be intrinsically impossible to satisfy, a more general interval-based constraint can be used to obtain statistical solutions Yue Yu 0002, Shangping Ren, Kevin A. Kwiat |
IEEE Real-Time and Embedded Technology and Applications Symposium | 3 |
| 2007 | An Economic Approach to Hierarchical Routing in Resource Rationed Ad Hoc NetworksabstractIn this paper, we focus on the problem of routing in resource rationed ad hoc networks. We exemplify the concept of resource rationing in a military scenario where the allocated resources are rationed to prolong the mission. By modeling the network as a directed weighted graph, we propose an economic approach to address the routing issue, namely HR3. Our approach begins with a hierarchical bidding process, through which nodes in the network bid for virtual currency. The winning bids use the granted virtual currency to pay the intermediate nodes for packet forwarding. After successful delivery, nodes get rewards. We study the truthfulness of HR3with rational nodes and propose security extension to identify and isolate the malicious nodes. Through simulations on ns-2, HR3shows performance gains in data throughput and energy consumption. Wenjing Wang 0006, Mainak Chatterjee, Kevin A. Kwiat |
WOWMOM | 3 |
| 2007 | The role of roles in supporting reconfigurability and fault localizations for open distributed and embedded systemsabstractOne of the main characteristics of open distributed embedded systems is that the involved entities are often very dynamic—different individual entities may join or leave the systems frequently. Therefore, systems built of these dynamic entities must be runtime reconfigurable. In addition, large classes of open embedded systems often have high availability and dependability requirements. However, the openness makes these requirements more difficult to achieve and the system more vulnerable to attacks. This article presents a coordination model, the Actor, Role and Coordinator (ARC) model, that aims to support reconfigurability and fault localization for open distributed embedded software systems. In particular, the actor model is used to model concurrent embedded entities, while the system's reconfigurability and dependability requirements are encapsulated within coordination objects: roles and coordinators, and are achieved through coordination among the actors. Roles, as a key thrust in the ARC model not only represent an abstraction for a set of behaviors shared by a group of actors so that reconfiguration within the roles becomes transparent to entities outside the roles, but also assume coordination responsibilities among the member actors. The article also argues from both analytical and empirical perspectives that with the support of the role, faults can be localized within actors, and actor level reconfiguration becomes transparent to the system. Shangping Ren, Yue Yu 0002, Nianen Chen, Jeffrey J. P. Tsai, Kevin A. Kwiat |
ACM Trans. Auton. Adapt. Syst. | 5 |
| 2006 | Bringing the economic model to the human-computer interfaceabstractAn examination of network control suggests that a simple abstraction at the human-computer interface suffices as the mechanism for the purpose of prioritizing and tailoring traffic. This mechanism for Quality of Service (QoS) adaptation is understandable to human users because it follows a simple rationale based on the notion of ration. As an instance of an economic model for network control, this mechanism at the user interface is proposed for implementation within a military setting of network-centric warfare. Kevin A. Kwiat |
CCNC | 1 |
| 2006 | Engineering of Replica Voting Protocols for Energy-Efficiency in Data DeliveryabstractThis paper describes the engineering of replica voting protocols for energy-efficiency in data delivery. The protocols employ 2-phase voting among replica processes to move a correct data from the external environment to the end-user(s) in a secure real-time application setting. The replicas may be wireless computation nodes deployed in a power-constrained environment. The cross-layer optimization techniques is employed to reduce the amount of network message exchanges and device processing cycles expended for data delivery to the user. This optimization can in turn reduce the battery energy consumption of wireless devices that participate in the voting protocol. Cross-layer design of a replica-based voting protocol is considered for deployment over IEEE- 802.11 networks. Furthermore, though the paper focused on replica voting as the application, the optimization techniques are useful in other application domains Kaliappa Nadar Ravindran, Ali Sabbir, Kevin A. Kwiat |
WOWMOM | 4 |
| 2006 | Effective worm detection for various scan techniquesabstractIn recent years, the threats and damages caused by active worms have become more and more serious. In order to reduce the loss caused by fast-spreading active worms, an effective detection mechanism to quickly detect worms is desired. In this paper, we first explore various scan strategies used by worms on finding vulnerable hosts. We show that targeted worms spread much faster than random scan worms. We then present a generic worm detection architecture to monitor malicious worm activities. We propose and evaluate our detection mechanism called Victim Number Based Algorithm. We show that our detection algorithm is effective and able to detect worm events before 2% of vulnerable hosts are infected for most scenarios. Furthermore, in order to reduce false alarms, we propose an integrated approach using multiple parameters as indicators to detect worm events. The results suggest that our integrated approach can differentiate worm attacks from DDoS attacks and benign scans. Jianhong Xia, Sarma Vangala, Lixin Gao 0001, Kevin A. Kwiat |
J. Comput. Secur. | 5 |
| 2005 | Timed Publish-Subscribe Coomunication for Distributed Embedded SystemsabstractIn a distributed embedded system, data items may be moved from one set of functional modules to another through a common buffer that is interposed between them over a network. Here, the computation modules disseminating data should agree on what data items are written into the remote buffer, to coordinate their actions on the external environment. Furthermore, a timely effect of these actions requires enforcing deadlines on the processing of data from the remote buffer. To meet these requirements, we provide a publish-subscribe style programming structure that enables a shared view of the processing on data in the buffer by various computation modules over prescribed time intervals. Our structure allows an explicit application-level control of the asynchrony and timing of information flow between various modules. Its use is illustrated with a case study of a target tracking application. In general, our programming structure can be useful in a variety of embedded software systems such as shared e-desks and collaborative Web services. Kaliappa Nadar Ravindran, Ali Sabbir, Kevin A. Kwiat |
DS-RT | 3 |
| 2005 | Energy-Efficient Replica Voting Mechanisms for Secure Real-Time Embedded SystemsabstractThe paper employs majority voting among replica processes to move correct data from the environment to the end-user entity in a secure real-time application setting. The replicas may be wireless computation nodes deployed in a power-constrained environment, and the data may be quite large in size with nonnumeric and non-exact contents (e.g., imaging devices in a geographic terrain). The voting protocol is made energy-efficient by reducing the amount of data processing and network-level message exchanges required in delivering data to the user. Our optimization takes into account: (i) processing cycles expended in comparing data; (ii) amount of replica data movement required; (iii) number of control messages generated. We consider two types of voting protocol: a 'centralized' scheme where replica data are collected at a secure power-abundant site to carry out the data comparisons for voting; a 'decentralized' scheme where each replica compares its locally computed data with a candidate data to send its consent/dissent message to a central vote collating site. The paper develops a performance model that considers the (i)-(iii) tradeoffs to determine the energy consumption levels in the centralized and decentralized voting schemes. Our model allows the voting apparatus to select an energy-optimal scheme, given the timeliness parameters and the network and processing bandwidths. Kevin A. Kwiat, Kaliappa Nadar Ravindran, Patrick Hurley |
WOWMOM | 1 |
| 2004 | Energy-efficient placement/activation algorithms for authorization servers in sensor networkabstractSensor networks are resource constrained environments and not physically secured. Sensor nodes may be physically captured and reverse engineered by the attacker. The goal of our research is to design energy-efficient distributed authorization servers (DAS) resilient to logical attack (hacking) and physical attack. We propose to organize our DAS as a layered directed acyclic graph (DAG). Any request to a sensor must be routed through and authorized by every layer of the DAG. Similar concepts have been investigated by other researchers. Our research adds a structural component to the existing research. A common method for achieving longer life for a sensor network is to deploy redundant nodes and activate only a subset of nodes at one point of time. To the best of our knowledge, nobody addressed the problem of choosing the nodes to be activated. In This work we designed a set of algorithms to choose the set of nodes for forming the DAS between the command and control centers (CCCs) and sensors collecting data. Our algorithms maximize the time required to compromise the security as well reduces the energy requirement for authorization and communication. Sibabrata Ray, Kevin A. Kwiat |
ISCC | 2 |
| 2004 | An Effective Architecture and Algorithm for Detecting Worms with Various Scan
Sarma Vangala, Lixin Gao 0001, Kevin A. Kwiat |
NDSS | 4 |
| 2003 | 'Timed atomic write': a programming primitive for distributed embedded systemsabstractIn a distributed embedded system, one or more data items may be moved from one functional module to another through a common buffer that is interposed between them over a network. Here, the computation modules generating and/or disseminating data should agree on what data items are written into the remote buffer, to coordinate their actions on the external environment. Furthermore, a timely effect of these actions requires enforcing deadlines on the processing of data from the remote buffer. We encouch the functionalities of reaching agreement on the data processed through a shared buffer and meeting the time deadlines associated with this data in an abstract programming primitive: 'timed atomic write'. The primitive has a rich semantics in that it enables a consistent view of the processing on data in the buffer by various computation modules over prescribed time intervals. The primitive allows an explicit application-level control of the asynchrony and timing of information flow between various modules. The paper describes the structure and semantics of the 'atomic write' primitive, and illustrates its use in a 'sensor data fusion' application. Kaliappa Nadar Ravindran, Ali Sabbir, Kevin A. Kwiat |
GLOBECOM | 3 |
| 2003 | Modeling the Spread of Active WormsabstractActive worms spread in an automated fashion and can flood the Internet in a very short time. Modeling the spread of active worms can help us understand how active worms spread, and how we can monitor and defend against the propagation of worms effectively. In this paper, we present a mathematical model, referred to as the Analytical Active Worm Propagation (AAWP) model, which characterizes the propagation of worms that employ random scanning. We compare our model with the Epidemiological model and Weaver's simulator. Our results show that our model can characterize the spread of worms effectively. Taking the Code Red v2 worm as an example, we give a quantitative analysis for monitoring, detecting and defending against worms. Furthermore, we extend our AAWP model to understand the spread of worms that employ local subnet scanning. To the best of our knowledge, there is no model for the spread of a worm that employs the localized scanning strategy and we believe that this is the first attempt on understanding local subnet scanning quantitatively. Zesheng Chen 0001, Lixin Gao 0001, Kevin A. Kwiat |
INFOCOM | 3 |
| 2001 | Can Reliability and Security be Joined Reliably and Securely?abstractThe combined topics of reliability and security are briefly traced in relation to the past and present endeavors of the Air Force Research Laboratory's Information Directorate. It is concluded that in the realm of information assurance, system features created to tolerate benign failures and to respond to attack must be stressed and tested beforehand and their effectiveness predicted, otherwise they might inadvertently magnify the attacker's power. With the explosive growth of distributed and mobile systems and the need for information assurance to address the accompanying vulnerabilities, one history lesson comes to mind: although ancient Rome was not built in a day, it did not take very long for it to fall once the barbarians took hold. Kevin A. Kwiat |
SRDS | 1 |
| 2001 | An Analytical Framework for Reasoning about IntrusionsabstractLocal and wide area network information assurance analysts need current and precise knowledge about their system activities in order to address the challenges of critical infrastructure protection. In particular, the analyst needs to know in real-time that an intrusion has occurred so that an active response and recovery thread can be created rapidly. Existing intrusion detection solutions are basically after-the-fact, thereby offering very little in terms of damage confinement and restoration of service. Quick recovery is only possible if the assessment scheme has low latency and it occurs in real-time. The objective of the paper is to develop a reasoning framework to aid in the real-time detection and assessment task that is based on a novel idea of encapsulation of owner's intent. The theoretical framework developed here will help resolve dubious circumstances that may arise while inferring the premises of operations (encapsulated from owner's intent) by way of examining the observed conclusions resulting from the actual operations of the owner. This reasoning is significant in view of the fact that intrusion signaling is not a binary decision unlike error detection in traditional fault tolerance. Our reasoning framework has been developed by leveraging the concepts of cost analysis and pricing under uncertainty found in economics and finance. Our main result is the modeling of user activity on a computing system as a martingale and the subsequent quantification of the cost of performing a job to enable decision making. Shambhu J. Upadhyaya, Ramkumar Chinchani, Kevin A. Kwiat |
SRDS | 3 |
| 1996 | Software Fault Tolerance Using Dynamically Reconfigurable FPGAsabstractAn emerging class of Field-Programmable Gate Arrays (FPGAs) permits partial reconfiguration of the device without disturbing the rest of the array-even while the device is operating. Dynamic device reconfiguration allows novel approaches to the migration of algorithms from software to hardware. New simulation tools are required in order to fully exploit the FPGA's versatility. We demonstrate how FPGA cells can be programmed and reprogrammed to provide a virtual FPGA that is much larger than the physical FPGA. In the context of dependable computing, our FPGA-based approach shows promise of significant performance gains over traditional software-intensive approaches. We apply this capability to the enhancement of software fault tolerance. Kevin A. Kwiat, Warren H. Debany Jr., Salim Hariri |
Great Lakes Symposium on VLSI | 1 |
| 1995 | Modeling a versatile FPGA for prototyping adaptive systemsabstractCurrently, the Computer-Aided Engineering (CAE) environments for designing Field-Programmable Gate Arrays (FPGAs) do not support the simulation of FPGA reprogrammability, hence prototyping of adaptive systems relies upon using the actual FPGAs. The FPGA architecture baselined an this paper, similar to a commercially-available FPGA as architecture, supports partial reconfiguration without disturbing the rest of the array. In this paper, we describe a modeling strategy for obtaining VHDL descriptions of versatile FPGAs so their dynamic behavior can be exhibited in advance of device procurement. An adaptive system using a versatile FPGA may also be prototyped with an emulation system whose FPGAs are architecturally different from the one requiring emulation. VHDL structural descriptions of the prototype's FPGA demonstrate the feasibility of transferring the model to the emulation system. We show how the generation of both the model and the simulation input capture the FPGA's full versatility. Kevin A. Kwiat, Warren H. Debany Jr., Salim Hariri |
RSP | 1 |
| 1992 | Empirical bounds on fault coverage loss due to LFSR aliasingabstractLinear-feedback shift registers (LFSRs) are often used to compact test responses. Prior analyses, based on statistically-independent error models, have predicted that aliasing probability 'converges' to 2/sup -k/ for LFSR polynomials of degree k, and that primitive polynomials perform better than nonprimitive polynomials. This paper presents the first statistical results based on full fault simulation that confirm these predictions. However, the average aliasing probability is not by itself a useful measure of the loss of fault detection information; the authors introduce an upper confidence limit (UCL) for the loss of fault coverage. The 'ideal' UCL is shown to match closely the empirically-derived UCL.> Warren H. Debany Jr., Mark Gorniak, Daniel Daskiewich, Anthony R. Macera, Kevin A. Kwiat, Heather B. Dussault |
VTS | 5 |
| 1992 | Effective concurrent test for a parallel-input multiplier using modulo 3abstractExperiments were performed to determine the effectiveness of modulo 3 checking for a class of two's complement, parallel-input multipliers. A full gate-level simulation of stuck-at faults was performed. The probability of aliasing for a 12*12-bit multiplier was found to be only 5.196%. The assumption that bit errors are statistically-independent yields a much greater probability of aliasing.> Warren H. Debany Jr., Anthony R. Macera, Daniel Daskiewich, Mark Gorniak, Kevin A. Kwiat, Heather B. Dussault |
VTS | 5 |
| 1991 | Design verification using logic testsabstractDesign verification is the process of assuring that a design is error-free. Empirical design verification involves the running of test cases against the design. To be effective, 'sufficient' testing must be performed. But to be cost-effective as well, testing must be terminated when that point is reached. There is a lack of quantifiable metrics to guide the development of tests for digital logic design verification. The authors report on the results of experiments that indicate that fault simulation, which parallels the well-known mutation testing approach used in software design verification, can be used to grade the coverage of test cases used for hardware design verification.> Warren H. Debany Jr., Mark Gorniak, Anthony R. Macera, Kevin A. Kwiat, Heather B. Dussault, Daniel Daskiewich |
RSP | 4 |
| 1988 | Defining a Standard for Fault Simulator EvaluationabstractAn acceptable standard is developed for relating fault simulator results from different simulators. Each simulator should verify the good circuit and evaluate the effectiveness of the generated test patterns (fault coverage). A hypothetical standard set of characteristics are proposed and each of the simulators are redefined in terms of the standard. These recommendations for evaluating these fault simulators and relating them to the standard include: the use of the same circuit topology (structure) and same ordered test vectors. However, the use of fault classes as a basis for evaluating the fault coverage is the major result of this effort.> Sami A. Al-Arian, Kevin A. Kwiat |
ITC | 2 |