Yaser Baseri

dblp:92/10330 · DBLP profile ↗
← Back
12ranked-venue papers
9as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 6 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Cybersecurity in the quantum era: Assessing the impact of quantum computing on infrastructure
abstract
The emergence of quantum computing presents a double-edged sword for cybersecurity. While its immense power holds promise for advancements in various fields, it also threatens to crack the foundation of current encryption methods. This analysis explores the impact of quantum computing on critical infrastructure and cloud services, meticulously evaluating potential vulnerabilities across various layers, including applications, data, runtime, middleware, operating systems, virtualization, hardware, storage, and networks. We advocate for proactive security strategies and collaboration between sectors to develop and implement quantum-resistant cryptography. This crucial shift necessitates a comprehensive approach, and the paper introduces a tailored security blueprint encompassing nine critical infrastructure components. This blueprint strengthens each area's defenses against potential quantum-induced cyber threats. Our strategic vulnerability and risk assessment equips stakeholders with the knowledge to navigate the complex quantum threat landscape. This empowers them to make informed decisions about design, implementation, and policy formulation, ultimately bolstering the resilience of critical infrastructure. In essence, this analysis not only forecasts quantum threats but also offers a sophisticated, actionable framework for fortifying infrastructure and cloud environments against the multifaceted challenges of the quantum era. This proactive approach will ensure continued data security and a thriving digital landscape in the years to come
Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001
Comput. Secur.1
2026 DNS user profiling and risk assessment: A learning approach
Yaser Baseri, Mahdi Daghmechi Firoozjaei, Somayeh Sadeghi, Ali A. Ghorbani 0001, William Belanger, Roozbeh Razavi-Far
Future Gener. Comput. Syst.1
2025 DNS Profiler: Quantifying User Browsing Risk from DNS Traffic Patterns
abstract
User profiling based on browsing behavior has traditionally been applied to improve web personalization and marketing strategies. However, leveraging browsing patterns to assess cybersecurity risks remains underexplored. In this paper, we propose a profiling framework based on domain name system (DNS) traffic analysis. Our approach models user browsing behavior using two main factors: browsing intent and domain reputation. By aggregating risk weights derived from accessed domains, we compute a personalized browsing risk score that reflects the user’s exposure to online threats. We validate the effectiveness of our framework through experiments that demonstrate its ability to differentiate users with varying levels of browsing risk. Our findings offer new insights into user-centric cybersecurity assessment using minimal yet meaningful data sources.
Mahdi Daghmechi Firoozjaei, Yaser Baseri, Qing Tan
PST2
2025 Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition
abstract
The rise of large-scale quantum computing poses a significant threat to traditional cryptographic security measures. Quantum attacks, particularly targeting the mathematical foundations of current asymmetric cryptographic algorithms, render them ineffective. Even standard symmetric key cryptography is susceptible, albeit to a lesser extent, with potential security enhancements through longer keys or extended hash function outputs. Consequently, the cryptographic solutions currently employed to safeguard data will be inadequately secure and vulnerable to emerging quantum technology threats. In response to this impending quantum menace, organizations must chart a course towards quantum-safe environments, demanding robust business continuity plans and meticulous risk management throughout the migration process. This study provides an in-depth exploration of the challenges associated with migrating from a non-quantum-safe cryptographic state to one resilient against quantum threats. We introduce a comprehensive security risk assessment framework that scrutinizes vulnerabilities across algorithmic, certificate, and protocol layers, covering the entire migration journey, including pre-migration, through-migration, and post-migration stages. Our methodology links identified vulnerabilities to the well-established STRIDE threat model, establishing precise criteria for evaluating their potential impact and likelihood throughout the migration process. Moving beyond theoretical analysis, we address vulnerabilities practically, especially within critical components like cryptographic algorithms, public key infrastructures, and network protocols. Our study not only identifies potential attacks and vulnerabilities at each layer and migration stage but also suggests possible countermeasures and alternatives to enhance system resilience, empowering organizations to construct a secure infrastructure for the quantum era. Through these efforts, we establish the foundation for enduring security in networked systems amid the challenges of the quantum era.
Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001, Aaron Chow
Comput. Secur.1
2025 Corrigendum to "Evaluation framework for quantum security risk assessment: A comprehensive strategy for quantum-safe transition" [Computers & Security, 150, 104272]
Yaser Baseri, Vikas Chouhan, Ali A. Ghorbani 0001, Aaron Chow
Comput. Secur.1
2024 Navigating quantum security risks in networked environments: A comprehensive study of quantum-safe network protocols
abstract
The emergence of quantum computing poses a formidable security challenge to network protocols traditionally safeguarded by classical cryptographic algorithms.This paper provides an exhaustive analysis of vulnerabilities introduced by quantum computing in a diverse array of widely utilized security protocols across the layers of the TCP/IP model, including TLS, IPsec, SSH, PGP, and more.Our investigation focuses on precisely identifying vulnerabilities susceptible to exploitation by quantum adversaries at various migration stages for each protocol while also assessing the associated risks and consequences for secure communication.We delve deep into the impact of quantum computing on each protocol, emphasizing potential threats posed by quantum attacks and scrutinizing the effectiveness of post-quantum cryptographic solutions.Through carefully evaluating vulnerabilities and risks that network protocols face in the post-quantum era, this study provides invaluable insights to guide the development of appropriate countermeasures.Our findings contribute to a broader comprehension of quantum computing's influence on network security and offer practical guidance for protocol designers, implementers, and policymakers in addressing the challenges stemming from the advancement of quantum computing.This comprehensive study is a crucial step towards fortifying the security of networked environments in the quantum age.
Yaser Baseri, Vikas Chouhan, Abdelhakim Hafid
Comput. Secur.1
2024 Statistical privacy protection for secure data access control in cloud
abstract
Cloud Service Providers (CSPs) allow data owners to migrate their data to resource-rich and powerful cloud servers and provide access to this data by individual users. Some of this data may be highly sensitive and important and CSPs cannot always be trusted to provide secure access. It is also important for end users to protect their identities against malicious authorities and providers, when they access services and data. Attribute-Based Encryption (ABE) is an end-to-end public key encryption mechanism, which provides secure and reliable fine-grained access control over encrypted data using defined policies and constraints. Since, in ABE, users are identified by their attributes and not by their identities, collecting and analyzing attributes may reveal their identities and violate their anonymity. Towards this end, we define a new anonymity model in the context of ABE. We analyze several existing anonymous ABE schemes and identify their vulnerabilities in user authorization and user anonymity protection. Subsequently, we propose a Privacy-Preserving Access Control Scheme (PACS), which supports multi-authority, anonymizes user identity, and is immune against users collusion attacks, authorities collusion attacks and chosen plaintext attacks. We also propose an extension of PACS, called Statistical Privacy-Preserving Access Control Scheme (SPACS), which supports statistical anonymity even if malicious authorities and providers statistically analyze the attributes. Lastly, we show that the efficiency of our scheme is comparable to other existing schemes. Our analysis show that SPACS can successfully protect against Collision Attacks and Chosen Plaintext Attacks.
Yaser Baseri, Abdelhakim Hafid, Mahdi Daghmechi Firoozjaei, Soumaya Cherkaoui, Indrakshi Ray
J. Inf. Secur. Appl.1
2024 Evaluation Framework for Electric Vehicle Security Risk Assessment
abstract
Electric Vehicles (EVs) seem promising for future transportation to solve environmental concerns and energy management problems. According to Reuters, global car makers plan to invest over half a billion in more efficient and intelligent EVs and batteries. However, there are several challenges in EV mass production, including cybersecurity. Due to the cyber-physical nature of EVs and charging stations, their security and trustworthiness are ongoing challenges. In this study, we identify gaps in the security profiling of EVs and categorize them into five components: 1) charging station security, 2) information privacy, 3) software security, 4) connected vehicle security, and 5) autonomous driving security. Our study provides a comprehensive analysis of identified vulnerabilities, threats, challenges and attacks for different EV security aspects, along with their possible surface/subsurface and countermeasures. We develop a comprehensive security risk assessment framework by first using EV security profiles and mapping identified vulnerabilities to a well-known threat model, STRIDE. Then, we classify the risk levels associated with each vulnerability by setting ground criteria for the impact and likelihood of the threats. Finally, we validate our risk assessment framework by applying the same criteria to eight real-world EV attack scenarios. As a result, researchers can adapt the proposed risk assessment framework to discover threats and assess their risks in EVs and charging station ecosystems.
Soheil Shirvani, Yaser Baseri, Ali A. Ghorbani 0001
IEEE Trans. Intell. Transp. Syst.2
2020 Differentially Private Two-Party Set Operations
abstract
Private set intersection (PSI) allows two parties to compute the intersection of their data without revealing the data they possess that is outside of the intersection. However, in many cases of joint data analysis, the intersection is also sensitive. We define differentially private set intersection and we propose new protocols using (leveled) homomorphic encryption where the result is differentially private. Our circuit-based approach has an adaptability that allows us to achieve differential privacy, as well as to compute predicates over the intersection such as cardinality. Furthermore, our protocol produces differentially private output for set intersection and set intersection cardinality that is optimal in terms of communication and computation complexity. For a client set of size$m$and a server set of size$n$, where$m$is smaller than$n$, our communication complexity is$O(m)$while previous circuit-based protocols only achieve$O(n+m)$communication complexity. In addition to our asymptotic optimizations which include new analysis for using nested cuckoo hashing for PSI, we demonstrate the practicality of our protocol through an implementation that shows the feasibility of computing the differentially private intersection for large data sets containing millions of elements.
Bailey Kacsmar, Basit Khurram, Nils Lukas, Alexander Norton, Masoumeh Shafieinejad, Zhiwei Shang, Yaser Baseri, Maryam Sepehri, Simon Oya, Florian Kerschbaum
EuroS&P7
2018 Privacy preserving fine-grained location-based access control for mobile cloud
Yaser Baseri, Abdelhakim Hafid, Soumaya Cherkaoui
Comput. Secur.1
2017 Controlling cloud data access privilege: Cryptanalysis and security enhancement
abstract
Recently, Jung et al. [1] proposed a data access privilege scheme and claimed that their scheme addresses data and identity privacy as well as multi-authority, and provides data access privilege for attribute-based encryption. In this paper, we show that this scheme, and also its former and latest versions (i.e. [2] and [3] respectively) suffer from a number of weaknesses in terms of finegrained access control, users and authorities collusion attack, user authorization, and user anonymity protection. We then propose our new scheme that overcomes these shortcomings. We also prove the security of our scheme against user collusion attacks, authority collusion attacks and chosen plaintext attacks. Lastly, we show that the efficiency of our scheme is comparable with existing related schemes.
Yaser Baseri, Abdelhakim Hafid, Mohammed Amine Togou, Soumaya Cherkaoui
PIMRC1
2016 K-anonymous location-based fine-grained access control for mobile cloud
abstract
Mobile cloud computing is a revolutionary computing paradigm for mobile application which enables storage and computation migration from mobile users to resources rich and powerful cloud servers, but emerges various privacy concerns. Attribute based encryption is a public key encryption that ensures the security of stored data in the cloud and provides fine grained access control using defined policies and constraints. Location of a device is one of the contextual policies which is used to improve data security, authenticate users and provide access to services and useful information for mobile users. However, unlike other policies and attributes used in attribute based encryption, location of mobile users are dynamic. In this paper, we investigate providing Location Based Services (LBS) for attribute based access control in mobile cloud. More specifically, we propose a multi-authority attribute based access control scheme and protect users privacy against malicious authorities. The proposed scheme uses dynamic location of a mobile user as contextual information about that user, employs coarse location as an attribute in attribute based encryption to achieve K-anonymity, and filters the returned results for more accuracy. The attribute based encryption is integrated with proxy re-encryption to outsource the computation to a cloud server with “unlimited” computational power. The proposed scheme achieves efficiency by reducing computational cost on resource-constrained mobile users.
Yaser Baseri, Abdelhakim Hafid, Soumaya Cherkaoui
CCNC1