EDBT 2026 Demo / reviewers in the wild / expert
Ammar Masood
dblp:90/3947
· DBLP profile ↗
13ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-5118-0617ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-authorComputer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | IP obfuscation: a survey of methods and the introduction of transient key logic lockingabstractLogic locking is a widely adopted hardware obfuscation technique which can be further sub-categorised into static and dynamic approaches based on the nature of the employed key. Besides being susceptible to SAT and fault injection attacks, static logic locking is vulnerable to widespread compromise from a single key exposure or device breach. On the other hand, dynamic logic locking introduces complexities in resource utilisation, key management, design, and adaptability. In this work, we provide a comprehensive and up-to-date overview of existing IP Obfuscation techniques, highlighting their strengths, and potential vulnerabilities. We also propose, a hybrid logic locking technique that capitalises on the positive attributes of both static and dynamic logic locking methodologies while minimising their inherent limitations. An initial proof-of-concept implementation/simulation has been performed on the Xilinx SP605 FPGA development board. The suggested transient key logic locking scheme is applicable to all type of IPs. Arsalan Ali Malik, Neelam Nasir, Naveed Riaz, Mureed Hussain, Sajid Ali Khan, Ammar Masood |
Int. J. Inf. Comput. Secur. | 7 |
| 2025 | Plaintext restoration of light weight block ciphers using deep neural networks under the black box assumption
Mahira Najeeb, Zikra Ghulam, Zahid Pervaiz, Ammar Masood |
Neural Comput. Appl. | 4 |
| 2024 | Cross-Layer RF Distance Bounding Scheme for Passive and Semi-passive Ubiquitous Computing Systems
Fatima Mavra Khalil, Adnan Fazil, Muhammad Jawad Hussain, Ammar Masood |
Comput. Secur. | 4 |
| 2023 | Scalable and effective artificial intelligence for multivariate radar environment
Mahshan Zaheer Awan, Khurram Khan 0001, Ammar Masood |
Eng. Appl. Artif. Intell. | 3 |
| 2023 | Open source SIEM solutions for an enterpriseabstractPurpose The security of applications, systems and networks has always been the source of great concern for both enterprises and common users. Different security tools like intrusion detection system/intrusion prevention system and firewalls are available that provide preventive security to the enterprise networks. However, security information and event management (SIEM) systems use these tools in combination to collect events from diverse data sources across the network. SIEM is a proactive tool that processes the events to present a unified security view of the whole network at one location. SIEM system has, therefore, become an essential component of an enterprise network security architecture. However, from various options available, the selection of a suitable and cost-effective open source SIEM solution that can effectively meet most of the security requirements of small-to-medium-sized enterprises (SMEs) is not simple because of the lack of strong analysis. Design/methodology/approach In this work, the authors first review the security challenges faced by different SME sectors and then consider a comprehensive comparative analysis of the capabilities of well-known open source SIEM solutions. Based on this, the authors provide requirements based recommendations of open source SIEM solutions for SMEs. This paper aims to provide a valuable resource that can be referred to by SMEs for the selection of a SIEM system best suited to their organization’s security posture. Findings Security requirements of SMEs vary according to their network infrastructure; therefore, every open source SIEM solution would not be suitable for an SME. Selection of a SIEM solution from available open source solutions based upon the security requirements of an SME network is a critical task. Therefore, in this work, a meaningful insight for the selection of an appropriate SIEM solution for SMEs is provided. Originality/value Major contribution of this work is the mapping of the security requirements of the SME sectors under consideration, against the open source SIEM options to provide meaningful insight for SMEs in the selection of an appropriate solution. Aamna Tariq, Jawad Manzoor, Muhammad Ammar Aziz, Zain Ul Abideen Tariq, Ammar Masood |
Inf. Comput. Secur. | 5 |
| 2023 | RealMalSol: real-time optimized model for Android malware detection using efficient neural networks and model quantization
Maham Chaudhary, Ammar Masood |
Neural Comput. Appl. | 2 |
| 2022 | Which open-source IDS? Snort, Suricata or Zeek
Abdul Waleed, Abdul Fareed Jamali, Ammar Masood |
Comput. Networks | 3 |
| 2022 | Vulnerability analysis of Qualcomm Secure Execution Environment (QSEE)
Fatima Khalid, Ammar Masood |
Comput. Secur. | 2 |
| 2017 | Composability Verification of Multi-Service Workflows in a Policy-Driven Cloud Computing EnvironmentabstractThe emergence of cloud computing infrastructure and Semantic Web technologies has created unprecedented opportunities for composing large-scale business processes and workflow-based applications that span multiple organizational domains. A key challenge related to composition of such multi-organizational business processes and workflows is posed by the security and access control policies of the underlying organizational domains. In this paper, we propose a framework for verifying secure composability of distributed workflows in an autonomous multi-domain environment. The objective of workflow composability verification is to ensure that all the users or processes executing the designated workflow tasks conform to the time-dependent security policy specifications of all collaborating domains. A key aspect of such verification is to determine the time-dependent schedulability of distributed workflows, assumed to be invoked on a recurrent basis. We use a two-step approach for verifying secure workflow composability. In the first step, a distributed workflow is decomposed into domain-specific projected workflows and is verified for conformance with the respective domain's security and access control policy. In the second step, the cross-domain dependencies amongst the workflow tasks performed by different collaborating domains are verified. Basit Shafiq, Sameera Ghayyur, Ammar Masood, Zahid Pervaiz, Abdulrahman Almutairi, M. Farrukh Khan, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2010 | Fault coverage of Constrained Random Test Selection for access control: A formal analysis
Ammar Masood, Arif Ghafoor, Aditya P. Mathur |
J. Syst. Softw. | 1 |
| 2010 | Conformance Testing of Temporal Role-Based Access Control SystemsabstractWe propose an approach for conformance testing of implementations required to enforce access control policies specified using the Temporal Role-Based Access Control (TRBAC) model. The proposed approach uses Timed Input-Output Automata (TIOA) to model the behavior specified by a TRBAC policy. The TIOA model is transformed to a deterministic se-FSA model that captures any temporal constraint by using two special events Set and Exp. The modified W-method and integer-programming-based approach are used to construct a conformance test suite from the transformed model. The conformance test suite so generated provides complete fault coverage with respect to the proposed fault model for TRBAC specifications. Ammar Masood, Arif Ghafoor, Aditya P. Mathur |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2009 | Scalable and Effective Test Generation for Role-Based Access Control SystemsabstractConformance testing procedures for generating tests from the finite state model representation of Role-Based Access Control (RBAC) policies are proposed and evaluated. A test suite generated using one of these procedures has excellent fault detection ability but is astronomically large. Two approaches to reduce the size of the generated test suite were investigated. One is based on a set of six heuristics and the other directly generates a test suite from the finite state model using random selection of paths in the policy model. Empirical studies revealed that the second approach to test suite generation, combined with one or more heuristics, is most effective in the detection of both first-order mutation and malicious faults and generates a significantly smaller test suite than the one generated directly from the finite state models. Ammar Masood, Rafae Bhatti, Arif Ghafoor, Aditya P. Mathur |
IEEE Trans. Software Eng. | 1 |
| 2005 | Efficiently Managing Security Concerns in Component Based System DesignabstractComponent-based software development (CBSD) offers many advantages like reduced product time to market, reduced complexity and cost etc. Despite these advantages its wide scale utilization in developing security critical systems is currently hampered because of lack, of suitable design techniques to efficiently manage the complete system security concerns in the development process. The use of commercial of the shelf (COTS) components can introduce various security and reliability risks in the system. In this paper we propose a methodology for efficient management of all the system security concerns involved in the design of component based systems. Our methodology is based on formally representing the system security specifications and component capabilities. We identify the metrics for correlating both and suggest extensions to a previously proposed software development process, for selection of suitable components and integration mechanisms. The proposed solution ensures due treatment of all the security concerns for the complete system in the acquisition efforts. Ammar Masood, Sahra Sedigh Sarvestani, Arif Ghafoor |
COMPSAC (1) | 1 |