Andrei Soeanu

dblp:87/2938 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
4since 2021 · last 2024
0000-0002-7315-6490ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 7 · 4 first-author · 1 since 2021Security and privacy · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 OctopusTaint: Advanced Data Flow Analysis for Detecting Taint-Based Vulnerabilities in IoT/IIoT Firmware
abstract
The widespread integration of Internet of Things (IoT) and Industrial IoT (IIoT) devices in respectively home and business environments offers both benefits and perils. While these devices, such as IP cameras and network routers improve operational efficiency with their user-friendly web interfaces, they also broaden the potential for cybersecurity vulnerabilities. Recent studies highlight the vulnerability of these devices to taint-based attacks, demonstrating that even attackers with limited permissions can gain control of a device. Current state-of-the-art solutions for mitigating these risks primarily utilize Dynamic Symbolic Execution (DSE). Although effective, DSE is computationally costly and challenging for large-scale analysis. Besides, during inspection, these approaches typically exhibit over-taint behavior by producing a large number of alerts, many of which are false positives due to ineffective handling of sanitization measures that might be in place. To overcome these limitations, we introduce OctopusTaint, an innovative static-based taint analysis approach that integrates advanced data flow analysis with backtracking techniques. OctopusTaint is distinguished by its integration of a sanitization inspection module and sophisticated post-processing filters. These features are specifically designed to minimize false positives effectively while ensuring the accurate identification of genuine security threats. OctopusTaint also excels in tracking transformed tainted inputs across NVRAM, identifying new user-defined taint source functions while addressing the challenges associated with indirect calls and aliasing. Through comparative performance evaluations, OctopusTaint demonstrates superior performance over the current state-of-the-art solutions, SaTC, EmTaint, and MangoDFA. It reports genuine extra tainted sinks in considerable less time (24% faster). Furthermore, OctopusTaint identifies 82% of tainted sinks within EmTaint 's labeled dataset while exhibiting its advanced capability in sanitization inspection. It correctly flags as sanitized 320 sinks, which were misidentified as genuine alerts by EmTaint. Furthermore, OctopusTaint uncovers additional candidates overlooked by EmTaint, leveraging its enhanced detection mechanisms for new taint sources. OctopusTaint successfully identifies 142 n -day vulnerabilities previously reported by SaTC and EmTaint, in addition to discovering dozens of potential 0-day candidates.
Abdullah Qasem, Mourad Debbabi, Andrei Soeanu
CCS3
2024 Spatial-Temporal Data-Driven Model for Load Altering Attack Detection in Smart Power Distribution Networks
abstract
The widespread deployment of information and communication technologies in smart power distribution networks (SPDNs) exposes them to cyber threats. Among different types of cyber-attacks in such ICT-based SPDNs, load-altering attacks (LAAs) against high-wattage devices have received significant attention in recent years. In this context, this article proposes a data-driven detection model tailored for identifying and localizing LAAs in SPDNs. In this pursuit, first, the graph structure of an SPDN, which is obtained from the grid topology, and node features, i.e., measurements of the load's power, are fed to a graph attention network (GAT), and the spatial correlations among the nodes are captured. Alongside, the temporal correlations are captured using a long short-term memory model trained based on the graph representation obtained from the GAT. These spatial and temporal correlations are used by prediction and reconstruction models, i.e., a fully connected neural network and an auto-encoder. Finally, based on the error of the prediction and reconstruction blocks, an attack score for each load is calculated, and the compromised loads are detected and localized. To evaluate the performance of the proposed model, a co-simulation framework, which simulates the power system and emulates the communication network using real industrial protocols, i.e., IEC 60870-5-104, has been developed. The robustness of the model's performance against noisy data and non-attack outliers is confirmed with respect to different noise levels and data outliers. Also, the developed model's superior performance over existing models is demonstrated through various LAA scenarios applied to the IEEE 33- and the 123-Bus benchmarks.
Afshin Ebtia, Dhiaa Elhak Rebbah, Mourad Debbabi, Marthe Kassouf, Mohsen Ghafouri, Arash Mohammadi 0001, Andrei Soeanu
IEEE Trans. Ind. Informatics7
2023 CPID: Insider threat detection using profiling and cyber-persona identification
Badis Racherache, Paria Shirani, Andrei Soeanu, Mourad Debbabi
Comput. Secur.3
2021 Separation linearization approach for the capacitated facility location problem under disruption
Badr Afify, Andrei Soeanu, Anjali Awasthi
Expert Syst. Appl.2
2020 Multi-depot vehicle routing problem with risk mitigation: Model and solution algorithm
Andrei Soeanu, Sujoy Ray, Jean Berger, Abdeslem Boukhtouta, Mourad Debbabi
Expert Syst. Appl.1
2019 Evolutionary learning algorithm for reliable facility location under disruption
Badr Afify, Sujoy Ray, Andrei Soeanu, Anjali Awasthi, Mourad Debbabi, Mohamad Khaled Allouche
Expert Syst. Appl.3
2016 Hierarchy aware distributed plan execution monitoring
Andrei Soeanu, Mourad Debbabi, Mohamad Khaled Allouche, Micheline Bélanger, Nicolas Léchevin
Expert Syst. Appl.1
2015 Transportation risk analysis using probabilistic model checking
Andrei Soeanu, Mourad Debbabi, Dima Alhadidi, Makram Makkawi, Mohamad Khaled Allouche, Micheline Bélanger, Nicolas Léchevin
Expert Syst. Appl.1
2014 The multi-depot split-delivery vehicle routing problem: Model and solution algorithm
Sujoy Ray, Andrei Soeanu, Jean Berger, Mourad Debbabi
Knowl. Based Syst.2
2012 A Learning Based Evolutionary Algorithm For Distributed Multi-Depot VRP
abstract
Solving multi-depot vehicle routing problem (MDVRP) in centralized setting has known scalability issues. This paper presents an innovative multi-agent and multi-round reinforcement learning procedure over adaptive elitist solutions selected from an evolving population pool, to near optimally solve MDVRP in a distributed setting. The paper contribution is threefold: First, it illustrates an effective solution finding procedure for MDVRP with limited information sharing in a realistic setup of agent’s control over depot and fleet. Second, it elaborates an agent-centric heuristic algorithm to navigate the solution space toward near-optimality based on elitist selection. In this context, a dynamic weighted probability distribution template generator is used to evolve increasingly better representative fractions of the solution population. Finally, it presents noteworthy results by applying the procedure on known MDVRP problem instances. The results are analyzed to assess solution quality.
Andrei Soeanu, Sujoy Ray, Mourad Debbabi, Jean Berger, Abdeslem Boukhtouta
KES1
2009 New aspect-oriented constructs for security hardening concerns
Azzam Mourad, Andrei Soeanu, Marc-André Laverdière, Mourad Debbabi
Comput. Secur.2