EDBT 2026 Demo / reviewers in the wild / expert
Bharat K. Bhargava
dblp:b/BKBhargava · also Bharat Kumar Bhargava
· DBLP profile ↗
190ranked-venue papers
36as first author
26since 2021 · last 2026
0000-0003-3803-8672ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 48 · 18 first-authorSecurity and privacy · 43 · 4 first-author · 14 since 2021Software engineering, systems software and programming languages · 24 · 4 first-author · 2 since 2021Computer networks · 23 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 18 · 7 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 17 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 15 · 4 first-author · 2 since 2021Systems, architecture and hardware · 13 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 4Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Big Data Analytics-Envisioned Quantum-Safe Lattice-Based Three-Party Authenticated Key Agreement Protocol for Cloud IoT-Enabled Healthcare ApplicationsabstractCloud-based Internet of Things (IoT)-enabled smart healthcare plays a vital role in modern society, yet security and privacy challenges remain unavoidable. The authenticated key agreement (AKA) process, which serves as the foundation of secure communication, is widely recognized as a key solution to these challenges. However, many existing AKA methods in the literature either involve high communication and computational costs or fail to withstand quantum attacks. Post-quantum cryptography (PQC) introduces a new class of cryptographic algorithms designed to resist future quantum computer threats. In this article, we present a quantum-secure, lattice-based three-party AKA scheme for smart IoT healthcare applications, leveraging the computationally complex Ring-Learning With Errors (Ring-LWE) problem. Our approach integrates secure big-data analytics with blockchain technology by utilizing authentication procedures for secure data aggregation before storing it in the blockchain. A comprehensive security evaluation including formal and informal analysis, demonstrates the scheme's strong resilience against both classical and quantum attacks. Additionally, experimental results confirm that the proposed scheme is well-suited for real-time smart healthcare applications. Prithwi Bagchi, Aakash Roy, Mohammad Wazid, Ashok Kumar Das, Bharat K. Bhargava, Youngho Park 0005 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | VLMS: Verifiable Lattice-Based Encryption With Multi-Keyword Search in Cloud Storage
Na Wang 0003, Wen Zhou 0021, Jingjing Wang 0001, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | QPCASIN: A Quantum-Defended Privacy-Aware Preemptive Handover-Enabled Continuous Authentication in Space Information NetworksabstractThe Space Information Network (SIN) plays a crucial role in terrestrial communication, delivering time-bound services from ground stations to users. It relies on moving low-orbit earth (LEO) satellites for uninterrupted coverage. However, untrustworthy connectivity poses several security challenges during handover services for users maintained by the satellites. While traditional cryptographic techniques provide a degree of security, the advent of quantum computing exposes significant vulnerabilities. This work proposes a quantum-safe and continuous authentication mechanism with handover provision. The proposed authentication protocol uses post-quantum primitives of the Frodo key encapsulation mechanism, currently an approved mechanism under ISO/IEC 18033-2. It ensures privacy and ensures users’ anonymity. The security of the proposed protocol is analyzed using the quantum random oracle (QROM) model. Formal verification confirms its safety for practical adoption as a post-quantum candidate. Further, the performance evaluation shows an authentication delay and energy consumption of the proposed protocol within practical limits, making it a suitable candidate for privacy-preserved post-quantum adoption for SIN. Basker Palaniswamy, Arijit Karati, Ting-Yu Chen 0001, Ashok Kumar Das, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | ReTrial: Robust Encrypted Malicious Traffic Detection via Discriminative Relation Incorporation and Misleading Relation CorrectionabstractEncryption techniques greatly ensure the confidentiality and integrity of network communications. However, they also allow attackers to conceal malicious activities within encrypted traffic, posing severe cybersecurity challenges. Current detection methods primarily rely on statistics and correlation analysis. However, both statistical features and inter-entity relations can be easily obfuscated. Moreover, issues with low-quality data and fixed feature sets limit the generalizability and adaptability to defend against various evasion techniques. Robustifying encrypted malicious traffic detection in adverse conditions is still an open problem. In this paper, we propose ReTrial, a robust encrypted malicious traffic detection system via discriminative relation incorporation and misleading relation correction. The key motivations behind ReTrialare to accurately leverage the rich relations among flows for contextual analysis, and correct misleading ones for robust threat detection. Specifically, we construct a relational multigraph and develop a tailored Graph Attention Network (GAT) to selectively incorporate contextual information. Then we retrieve multi-order neighborhood similarity graphs as observations for adaptive relation correction. Following an iterative scheme, both detector performance and graph topology mutually optimize. To validate the robustness of ReTrial, we simulate various adverse conditions by randomly dropping packets and greedily injecting perturbation edges. The experimental results show that ReTrialis competitive in ideal condition. Under adverse conditions, though the performances of other state-of-the-art methods degrade significantly, ReTrialconsistently exhibits superior performance with a maximum reduction of only 5.88% in F1, highlighting its robustness in threat detection. Jianjin Zhao, Qi Li 0057, Zewei Han, Junsong Fu 0001, Guoshun Nan, Meng Shen 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Quantitative Evaluation of Extensive Vulnerability Set Using Cost Benefit AnalysisabstractThe significant expansion in network size to support new paradigms such as cloud computing, IoT (Internet of Things), etc. together with the exponential increase in vulnerabilities has challenged the existing security mechanisms greatly. These challenges have opened many avenues for research in network security. However, while attack graphs play an important role in analyzing vulnerabilities, analyzing large attack graphs itself is a major issue. Therefore, it is necessary to extract only the critical part of the attack graph. Although technologies have been developed for attack path characterization, there is a lack of hybrid technology that can differentiate between similar behavior attack paths. We have proposed a cost-based path characterization technique that takes the attack node's vulnerability complexity into account and significantly reduces the number of vulnerabilities that need to be patched to avoid the major segment of attack graph. Moreover, we have used a real network prototype to validate the performance of the proposed scheme. The proposed scheme works well in cases where some vulnerabilities have similar risk scores. To the best of our knowledge, this is the first time that a cost-effective approach for attack path analysis has been proposed. Urvashi Bansal, Geeta Sikka, Lalit Kumar Awasthi, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | A Framework of High-Speed Network Protocol Fuzzing Based on Shared MemoryabstractIn recent years, security test of network protocols based on fuzzing has been attracting more and more attentions. This is very challenging compared with the stateless software fuzzing and most early network protocol fuzzers are of low speed and poor test effect. Since the first greybox and stateful fuzzer named AFLNET was proposed, several new schemes have been designed to improve its performance from different aspects. During the research, a great challenge is how to greatly improve the fuzzing efficiency. Based on the basic analysis in SNPSFuzzer, this paper provides a more thorough analysis about the time consumption in a fuzzing iteration for 13 network protocols and then we design a High-speed Network Protocol Fuzzer named HNPFuzzer. In HNPFuzzer, the test cases and response messages between the client and server are transmitted through the shared memory, guided by a precise synchronizer, rather than the socket interfaces. This greatly shorten the period of an iteration. Moreover, we design a persistent mode attempting to fuzz the service instances in the memory more than one time based on analyzing the side effect information. This mode further improves the speed of fuzzing. Experiment results illustrate that our scheme can improve the fuzzing throughput by about 39.66 times in average and triggers a large number of crashes including 2 new vulnerabilities which cannot discovered by existing fuzzers. Note that, the existing network protocol fuzzing schemes proposed in different directions do not compete with each other and on the contrary, they can collaborate with each other to improve the overall fuzzing effect and efficiency. Consequently, more existing tools can be integrated into our framework to get better network protocol fuzzing effect. Junsong Fu 0001, Shuai Xiong, Na Wang 0003, Ruiping Ren, Ang Zhou, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Malware Speaks! Deep Learning Based Assembly Code Processing for Detecting Evasive CryptojackingabstractThe increasing prevalence of blockchain-based cryptocurrencies as a payment instrument in the past decade and the rewards earned by the cryptominers has resulted in a new class of cyber attacks,cryptojacking, which involves unauthorized mining of cryptocurrencies on someone's system. Spotting cryptojacking is difficult in many cases, since the relevant software tries to disguise its presence to evade detection, by mimicking benign software such as compression applications by performing similar bitwise, cryptographic, and encryption operations. In this paper, we propose the processing of assembly code—a fundamental and platform-independent programming language—as a natural language using deep learning for profiling applications, which we callDeepCodeProfiler (DeCode Pro). Our proposed solution leverages the immutable step of any cyber attack: the deployment of instructions in system memory to carry out the attack. Through extensive experimentation with different neural network architectures in the profiling stage, we show that DeCode Pro is highly effective in the detection of evasive cryptojacking attacks and achieves low false positive and false negative rates. We also show that the model achieves high classification accuracy even with limited training data, which can considerably reduce the computing resources required for training and retraining the deep learning model. Ganapathy Mani, Myeongsu Kim, Bharat K. Bhargava, Pelin Angin, Ayça Deniz, Vikram Pasumarti |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic AlgorithmabstractAlthough Tor is designed to provide anonymity, website fingerprinting (WF) attacks have posed significant threats to user privacy. In response, various defense approaches have been developed. Randomization and regularization-based defenses are criticized to be inefficient due to their bandwidth-consuming nature. Some adversarial learning-based defenses are impractical because the generation of perturbation depends on the complete traffic traces. Other adversarial learning-based defenses have weaknesses of lacking adaptability because their perturbations are input-agnostic. To overcome these shortcomings, we propose RUDOLF, an efficient and adaptive WF defense based on the soft actor-critic (SAC) algorithm of reinforcement learning (RL). We train the agent that can incrementally output perturbations synchronously following each burst of real-time traffic. Different from previous defenses, RUDOLF’s perturbation does not depend on the integrity of the traffic and concerns the actual real-time traffic, which ensures the practicality of implementation and adaptability. Besides, we take advantage of the exploratory characteristics of the SAC algorithm to obtain the optimal policy of adding perturbations that can efficiently balance defense effects and bandwidth consumption. Experiments on synthetic datasets show that with less than 30% bandwidth overhead (BWO), RUDOLF can reduce the average attack accuracy to around 15%–20%, which is superior to previous works. We also have implemented RUDOLF as a Tor pluggable transport. The performance in the real Tor network shows that RUDOLF can reduce the average accuracy of WF classifier to around 24% with about 25% BWO and almost no time delay. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | EMERSK -Explainable Multimodal Emotion Recognition With Situational KnowledgeabstractAutomatic emotion recognition has recently gained significant attention due to the growing popularity of deep learning algorithms. One of the primary challenges in emotion recognition is effectively utilizing the various cues (modalities) available in the data. Another challenge is providing a proper explanation of the outcome of the learning. To address these challenges, we present Explainable Multimodal Emotion Recognition with Situational Knowledge (EMERSK), a generalized and modular system for human emotion recognition and explanation using visual information. Our system can handle multiple modalities, including facial expressions, posture, and gait, in a flexible and modular manner. The network consists of different modules that can be added or removed depending on the available data. We utilize a two-stream network architecture with convolutional neural networks (CNNs) and encoder-decoder style attention mechanisms to extract deep features from face images. Similarly, CNNs and recurrent neural networks (RNNs) with Long Short-term Memory (LSTM) are employed to extract features from posture and gait data. We also incorporate deep features from the background as contextual information for the learning process. The deep features from each module are fused using an early fusion network. Furthermore, we leverage situational knowledge derived from the location type and adjective-noun pair (ANP) extracted from the scene, as well as the spatio-temporal average distribution of emotions, to generate explanations. Ablation studies demonstrate that each sub-network can independently perform emotion recognition, and combining them in a multimodal approach significantly improves overall recognition performance. Extensive experiments conducted on various benchmark datasets, including GroupWalk, validate the superior performance of our approach compared to other state-of-the-art methods. Mijanur Rahaman Palash, Bharat K. Bhargava |
IEEE Trans. Multim. | 2 |
| 2023 | Machine Learning Based Resilience Testing of an Address Randomization Cyber DefenseabstractMoving target defenses (MTDs) are widely used as an active defense strategy for thwarting cyberattacks on cyber-physical systems by increasing diversity of software and network paths. Recently, machine Learning (ML) and deep Learning (DL) models have been demonstrated to defeat some of the cyber defenses by learning attack detection patterns and defense strategies. It raises concerns about the susceptibility of MTD to ML and DL methods. In this article, we analyze the effectiveness of ML and DL models when it comes to deciphering MTD methods and ultimately evade MTD-based protections in real-time systems. Specifically, we consider a MTD algorithm that periodically randomizes address assignments within the MIL-STD-1553 protocol—a military standard serial data bus. Two ML and DL-based tasks are performed on MIL-STD-1553 protocol to measure the effectiveness of the learning models in deciphering the MTD algorithm: 1) determining whether there is an address assignments change i.e., whether the given system employs a MTD protocol and if it does 2) predicting the future address assignments. The supervised learning models (random forest and k-nearest neighbors) effectively detected the address assignment changes and classified whether the given system is equipped with a specified MTD protocol. On the other hand, the unsupervised learning model (K-means) was significantly less effective. The DL model (long short-term memory) was able to predict the future addresses with varied effectiveness based on MTD algorithm's settings. Ganapathy Mani, Marina Haliem, Bharat K. Bhargava, Indu Manickam, Kevin Kochpatcharin, Myeongsu Kim, Eric D. Vugrin, Weichao Wang, Pelin Angin, Meng Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | AGAPECert: An Auditable, Generalized, Automated, Privacy-Enabling Certification Framework With Oblivious Smart ContractsabstractThis paper introduces AGAPECert, an Auditable, Generalized, Automated, Privacy-Enabling, Certification framework capable of performing auditable computation on private data and reporting real-time aggregate certification status without disclosing underlying private data. AGAPECert utilizes a novel mix of trusted execution environments, blockchain technologies, and a real-time graph-based API standard to provide automated, oblivious, and auditable certification. Our technique allows a privacy-conscious data owner to run pre-approvedOblivious Smart Contractcode in their own environment on their own private data to produce Private Automated Certifications. These certifications are verifiable, purely functional transformations of the available data, enabling a third party to trust that the private data must have the necessary properties to produce the resulting certification. Recently, a multitude of solutions for certification and traceability in supply chains have been proposed. These often suffer from significant privacy issues because they tend to take a ”shared, replicated database” approach: every node in the network has access to a copy of all relevant data and contract code to guarantee the integrity and reach consensus, even in the presence of malicious nodes. In these contexts of certifications that require global coordination, AGAPECert can include a blockchain to guarantee ordering of events, while keeping a core privacy model where private data is not shared outside of the data owner's own platform. AGAPECert contributes an open-source certification framework that can be adopted in any regulated environment to keep sensitive data private while enabling a trusted automated workflow. Servio Palacios, Aaron Ault, James V. Krogmeier, Bharat K. Bhargava, Christopher G. Brinton |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Hunting for Insider Threats Using LSTM-Based Anomaly DetectionabstractInsider threats are one of the most difficult problems to solve, given the privileges and information available to insiders to launch different types of attacks. Current security systems can record and analyze sequences from a deluge of log data, potentially becoming a tool to detect insider threats. The issue is that insiders mix the sequence of attack steps with valid actions, reducing the capacity of security systems to programmatically detect the attacks. To address this shortcoming, we introduce LADOHD, an anomaly detection framework based on Long-Short Term Memory (LSTM) models, which learns the expected event patterns in a computer system to identify attack sequences even when attacks span for a long time. The applicability of the framework is demonstrated on a dataset of 38.9 million events collected from a commercial network of 30 computers over twenty days and where a 4-day long insider threat attack occurs. Results show that LADOHD outperforms the anomaly detection system used to protect the commercial network with a True Positive Rate of 97.29% and a False Positive Rate of 0.38%. Experiments also show that LSTMs have higher prediction precision in variable-length sequences than methods like Hidden Markov Models, a crucial requirement in sequence-analysis-based anomaly detection techniques. Miguel Villarreal-Vasquez, Gaspar Modelo-Howard, Simant Dube, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | An Attack to One-Tap Authentication Services in Cellular NetworksabstractThe One-Tap Authentication (OTAuth) based on the cellular network is a password-less login service provided by Mobile Network Operator (MNO) through the unique communication gateway access technique. The service allows app users to quickly sign up or log in with their mobile phone numbers without entering a password. Due to its convenience, OTAuth has been widely used by various apps. However, some studies have elaborated that OTAuth services are of great drawbacks from the perspective of mobile security and identified several flawed designs, which make the MNO cannot distinguish malicious apps from normal ones and cause impersonation attacks. In this paper, we further analyze OTAuth services from the perspective of 4G and 5G cellular networks and focus on two important procedures in which the cellular network plays an important role in OTAuth services. Not surprisingly, we discover a new fundamental design flaw in determining whether the runtime environment supports OTAuth services. Moreover, we propose a mature attack paradigm by exploiting this flaw, which allows an attacker to login or register one app as a victim. To evaluate the impact of the attack, we have examined 100/90/100 Android/iOS/HarmonyOS apps for OTAuth services of 3 main-stream MNOs in China. The experimental results show that our proposed attack is applicable to almost all the apps that support OTAuth services, and affects more apps than the attacks that have been reported before. Finally, we propose several counter-measures to defend against the attack. Note that, for security’s sake, we have already reported our findings to authorized parties and received their confirmations. Baojiang Cui, Junsong Fu 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Lightweight and Secure Data Transmission Scheme Against Malicious Nodes in Heterogeneous Wireless Sensor NetworksabstractWith the continuous development of sensor technology, more and more users hope to monitor and collect information in a certain area safely and efficiently by deploying heterogeneous wireless sensor networks (HWSNs). However, nodes in HWSNs have limited capabilities, which leads to many security challenges. Existing data transmission schemes in HWSNs take measures to resist these security threats, which aggravate the node computation overhead and increase the network energy consumption. This paper proposes a Lightweight and Secure Data Transmission (LSDT) scheme against malicious nodes in heterogeneous wireless sensor networks. Firstly, considering node capabilities limitations in HWSNs, we design a lightweight secret sharing scheme based on XOR operation, which maps data to multiple shares and makes it convenient to transmit shares separately to the sink node via multiple paths. While guaranteeing data security, this scheme can greatly reduce the computation overhead of nodes compared with traditional secret sharing schemes. Further, during the delivery of shares, the network may be attacked by malicious nodes, causing the interruption of message transmission. Therefore, we design a malicious node detection and feedback mechanism, which can quickly respond to malicious node attacks and update the reputation degree of malicious nodes. Finally, we propose a routing selection scheme based on reference path which comprehensively considers the energy and reputation degree of heterogeneous nodes. It makes message transmission bypass malicious nodes while achieving network energy load balance, significantly extending the network lifetime. The security analysis proves that our scheme guarantees the security of data transmission. Theoretical analysis and experiments show that our scheme has significant advantages over the existing HWSNs data transmission schemes in terms of network lifetime extension and malicious node resistance. Na Wang 0003, Shancheng Zhang, Jiawen Qiao, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Secure and Distributed IoT Data Storage in Clouds Based on Secret Sharing and Collaborative BlockchainabstractWith the rapid development of 5G/6G, most Internet of Things (IoT) devices will embrace wireless connection in the near future. A public concern is how to securely organize, store and retrieve data generated from IoT devices. Many cloud-based IoT data storage schemes have been proposed recently. However, for an untrusted or vulnerable cloud server, the stored IoT data can be easily accessed, modified and even destroyed given that the IoT data are stored in total centralization. Moreover, the servers in a cloud are generally homogeneous and thus vulnerable to attacks. For improvements, we design a novel framework for secure and efficient IoT data storage based on secret sharing and a collaborative blockchain. First, an ultra-lightweight secret sharing algorithm is designed to map original messages generated by IoT devices to a set of shorter message shares. Second, all the shares of IoT messages are separately delivered to different clouds for storage. To guarantee the security of shares, the delivery is notarized on a proposed blockchain. Specifically, both hash values of the shares and their information of location are embedded in blocks which are then chained to form a blockchain. Third, we create a balanced index structure about the shares for each cloud storage node based on the information in the blockchain, and we also propose a depth-first data search algorithm to improve IoT data retrieval efficiency. Theoretical analysis and simulation results illustrate that our scheme can store and retrieve the IoT data securely and efficiently. Na Wang 0003, Junsong Fu 0001, Shancheng Zhang, Jiawen Qiao, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE/ACM Trans. Netw. | 7 |
| 2022 | Information theoretic approach to detect collusion in multi-agent gamesabstractCollusion in a competitive multi-agent game occurs when two or more agents co-operate covertly to the disadvantage of others. Most competitive multi-agent games do not allow players to share information and explicitly prohibit collusion. In this paper, we present a novel way of detecting collusion using a domain-independent information-theoretic approach. Specifically, we show that the use of mutual information between actions of the agents provides a good indication of collusive behavior. Our experiments show that our method can detect varying levels of collusion in repeated simultaneous games like iterated Rock Paper Scissors. We further extend the detection to partially observable sequential games like poker and show the effectiveness of our methodology. Trevor Bonjour, Vaneet Aggarwal, Bharat K. Bhargava |
UAI | 3 |
| 2022 | 1174: futuristic trends and innovations in multimedia systems using big data, IoT and cloud technologies (FTIMS)
Pradeep Kumar Singh 0001, Bharat K. Bhargava, Wei-Chiang Hong, Pelin Angin |
Multim. Tools Appl. | 2 |
| 2022 | Bio-Inspired Formal Model for Space/Time Virtual Machine Randomization and DiversificationabstractStudies on resiliency against system attacks have contributed well established defensive techniques, sound protocols and paradigms in distributed systems’ literature. One of this contribution is credited to redundancy and replication techniques which is proven to be a double–edged–sword, by increasing the number of nodes inherently increases the system's attack-vector – the set of ways an attacker can compromise a system. To remedy this issue, system randomization and diversification has been considered as an effective defensive strategy, referred to as a Moving Target Defense (MTD). In this article, we introduce a bio-inspired formal model for space/time system randomization/diversification and a quantification scheme for virtual machines (VMs) in a cloud computing environment. We show the practicality of the model with a MTD framework(Mayflies)integrated into the cloud management software stack(OpenStack)and illustrate with realistic VM attacks and proactive defense use cases. Noor Ahmed 0001, Bharat K. Bhargava |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | AdaPool: A Diurnal-Adaptive Fleet Management Framework Using Model-Free Deep Reinforcement Learning and Change Point DetectionabstractThis paper introduces an adaptive model-free deep reinforcement approach that can recognize and adapt to the diurnal patterns in the ride-sharing environment with car-pooling. Deep Reinforcement Learning (RL) suffers from catastrophic forgetting due to being agnostic to the timescale of changes in the distribution of experiences. Although RL algorithms are guaranteed to converge to optimal policies in Markov decision processes (MDPs), this only holds in the presence of static environments. However, this assumption is very restrictive. In many real-world problems like ride-sharing, traffic control, etc., we are dealing with highly dynamic environments, where RL methods yield only sub-optimal decisions. To mitigate this problem in highly dynamic environments, we (1) adopt an online Dirichlet change point detection (ODCP) algorithm to detect the changes in the distribution of experiences, (2) develop a Deep Q Network (DQN) agent that is capable of recognizing diurnal patterns and making informed dispatching decisions according to the changes in the underlying environment. Rather than fixing patterns by time of week, the proposed approach automatically detects that the MDP has changed, and uses the results of the new model. In addition to the adaptation logic in dispatching, this paper also proposes a dynamic, demand aware vehicle-passenger matching and route planning framework that dynamically generates optimal routes for each vehicle based on online demand, vehicle capacities, and locations. Evaluation on New York City Taxi public dataset shows the effectiveness of our approach in improving the fleet utilization, where less than 50% of the fleet are utilized to serve the demand of up to 90% of the requests, while maximizing profits and minimizing idle times. Marina Haliem, Vaneet Aggarwal, Bharat K. Bhargava |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | PassGoodPool: Joint Passengers and Goods Fleet Management With Reinforcement Learning Aided Pricing, Matching, and Route PlanningabstractThe ubiquitous growth of mobility-on-demand services for passenger and goods delivery has brought various challenges and opportunities within the realm of transportation systems. As a result, intelligent transportation systems are being developed to maximize operational profitability, user convenience, and environmental sustainability. The growth of last mile deliveries alongside ridesharing calls for an efficient and cohesive system that transports both passengers and goods. Existing methods address this using static routing methods considering neither the demands of requests nor the transfer of goods between vehicles during route planning. In this paper, we present a dynamic and demand aware fleet management framework for combined goods and passenger transportation that is capable of (1) Involving both passengers and drivers in the decision-making process by allowing drivers to negotiate to a mutually suitable price, and passengers to accept/reject, (2) Matching of goods to vehicles, and the multi-hop transfer of goods, (3) Dynamically generating optimal routes for each vehicle considering demand along their paths, based on the insertion cost which then determines the matching, (4) Dispatching idle vehicles to areas of anticipated high passenger and goods demand using Deep Reinforcement Learning (RL), (5) Allowing for distributed inference at each vehicle while collectively optimizing fleet objectives. Our proposed model is deployable independently within each vehicle as this minimizes computational costs associated with the growth of distributed systems and democratizes decision-making to each individual. Simulations on a variety of vehicle types, goods, and passenger utility functions show the effectiveness of our approach as compared to other methods that do not consider combined load transportation or dynamic multi-hop route planning. Our proposed method showed improvements over the next best baseline in various aspects including a 15% increase in fleet utilization and a 20% increase in average vehicle profits. Kaushik Manchella, Marina Haliem, Vaneet Aggarwal, Bharat K. Bhargava |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Defending Trace-Back Attack in 3D Wireless Internet of ThingsabstractWith the development of 5G, it is unsurprising that most of the smart devices in the Internet of Things (IoT) will be wirelessly connected with each other in the near future. This kind of lightweight, scalable and green network architecture will be well-received. In a wide variety of IoT application scenarios, sensor nodes deployed in a local space, such as a multistory building, automatically form a distributed 3D wireless IoT and it can be employed to collect and analyze environmental information. Source-location privacy protection is of great importance in these networks and however, most existing schemes focus on only planar distributed networks which are not suitable for the 3D networks. In this paper, we consider a novel trace-back attack for 3D wireless IoT and then design a source-location privacy protection scheme, named DMR-3D, to defend this kind of novel attacks. In DMR-3D, the source node first selects a set of virtual locations to indirectly choose a set of agent nodes based on the cold start sphere structure and the ellipsoid communication pipeline. Then, a sophisticated mechanism is designed based on both the connected graph and Multiple Delaunay Triangulation (MDT) structure of the network to deliver packets from the source node to the destination node via these agent nodes in a relay manner. Analysis and simulation results illustrate that the proposed scheme can effectively protect source-location privacy with a moderate increment of path stretch, time delay and data transmission amount. Junsong Fu 0001, Na Wang 0003, Leyao Nie, Baojiang Cui, Bharat K. Bhargava |
IEEE/ACM Trans. Netw. | 5 |
| 2022 | A Practical Framework for Secure Document Retrieval in Encrypted Cloud File SystemsabstractWith the development of cloud computing, more and more data owners are motivated to outsource their documents to the cloud and share them with the authorized data users securely and flexibly. To protect data privacy, the documents are generally encrypted before being outsourced to the cloud and hence their searchability decreases. Though many privacy-preserving document search schemes have been proposed, they cannot reach a proper balance among functionality, flexibility, security and efficiency. In this paper, a new encrypted document retrieval system is designed and a proxy server is integrated into the system to alleviate data owner's workload and improve the whole system's security level. In this process, we consider a more practical and stronger threat model in which the cloud server can collude with a small number of data users. To support multiple document search patterns, we construct two AVL trees for the filenames and authors, and a Hierarchical Retrieval Features tree (HRF tree) for the document vectors. A depth-first search algorithm is designed for the HRF tree and the Enhanced Asymmetric Scalar-Product-Preserving Encryption (Enhanced ASPE) algorithm is utilized to encrypt the HRF tree. All the three index trees are linked with each other to efficiently support the search requests with multiple parameters. Theoretical analysis and simulation results illustrate the security and efficiency of the proposed framework. Junsong Fu 0001, Na Wang 0003, Baojiang Cui, Bharat K. Bhargava |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2022 | RL-ABE: A Revocable Lattice Attribute Based Encryption Scheme Based on R-LWE Problem in Cloud StorageabstractIn this article, we propose a revocable lattice-based CP-ABE (Ciphertext-Policy Attribute-Based Encryption) scheme (RL-ABE), which is suitable to be applied in the cloud storage. The RL-ABE scheme can resist quantum algorithm attack and ensure fine-grained access control to the users’ rights in achieving shared data. In addition, our scheme can realize attribute revocation, which can expediently renew users’ attributes to grant or revoke their access rights. Then, we formally prove the security of our scheme based on the hardness of Ring Learning with Error problem(R-LWE) to resist quantum algorithm attack, and prove our scheme can solve security threatens to withstand collusion attacks. Finally, the performance analysis shows the high efficiency of our scheme compared with other related schemes. Bharat K. Bhargava |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | Detection of Message Injection Attacks Onto the CAN Bus Using Similarities of Successive Messages-Sequence GraphsabstractThe smart features of modern cars are enabled by a number of Electronic Control Units (ECUs) components that communicate through an in-vehicle network, known as Controller Area Network (CAN) bus. The fundamental challenge is the security of the communication link where an attacker can inject messages (e.g., increase the speed) that may impact the safety of the driver. Most of existing practical IDS solutions rely on the knowledge of the identity of the ECUs, which is proprietary information. This paper proposes a message injection attack detection solution that is independent of the IDs of the ECUs. First, we represent the sequencing of the messages in a given time-interval as a direct graph and compute the similarities of the successive graphs using the cosine similarity and Pearson correlation. Then, we apply threshold, change point detection, and Long Short-Term Memory (LSTM)-Recurrent Neural Network (RNN) to detect and predict malicious message injections into the CAN bus. The evaluation of the methods using a dataset collected from a moving vehicle under malicious RPM and speed reading message injections show a detection accuracy of 97.32% and detection speed of 2.5 milliseconds when using a threshold method. The performance metrics makes the IDS suitable for real-time control mechanisms for vehicle resiliency to cyber-attacks. Mubark Jedh, Lotfi Ben Othmane, Noor Ahmed 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | A Distributed Model-Free Ride-Sharing Approach for Joint Matching, Pricing, and Dispatching Using Deep Reinforcement LearningabstractSignificant development of ride-sharing services presents a plethora of opportunities to transform urban mobility by providing personalized and convenient transportation while ensuring the efficiency of large-scale ride pooling. However, a core problem for such services is route planning for each driver to fulfill the dynamically arriving requests while satisfying given constraints. Current models are mostly limited to static routes with only two rides per vehicle (optimally) or three (with heuristics) (Alonso-Moraet al., 2017), at least in the initial allocation while not ascertaining that opposite-direction rides are not grouped together. In this paper, we present a dynamic, demand aware, and pricing-based vehicle-passenger matching and route planning framework that (1) dynamically generates optimal routes for each vehicle based on online demand, pricing associated with each ride, vehicle capacities and locations. This matching algorithm starts greedily and optimizes over time using an insertion operation, (2) involves drivers in the decision-making process by allowing them to propose a different price based on the expected reward for a particular ride as well as the destination locations for future rides, which is influenced by supply-and-demand computed by the Deep Q-network. (3) allows customers to accept or reject rides based on their set of preferences with respect to pricing and delay windows, vehicle type and carpooling preferences. These (1-3) in tandem with each other enforce grouping rides with the most route-intersections together. (4) Based on demand prediction, our approach re-balances idle vehicles by dispatching them to the areas of anticipated high demand using deep Reinforcement Learning (RL). Our framework is validated using millions of trips extracted from the New York City Taxi public dataset; however, we consider different vehicle types and designed customer utility functions to validate the setup and study different settings. Experimental results show the effectiveness of our approach in real-time and large scale settings. Marina Haliem, Ganapathy Mani, Vaneet Aggarwal, Bharat K. Bhargava |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | Identity-Preserving Public Integrity Checking with Dynamic Groups for Cloud StorageabstractDespite a variety of security threats, cloud storage is on the increase especially when a group of users need to store and share data. Identity-privacy and user dynamic operation are of growing concern in public integrity checking (PIC) scheme. In this paper, we develop an identity-preserving public integrity checking scheme with dynamic groups (IPIC-DG) for cloud storage. Firstly, our IPIC-DG scheme can realize the whole anonymity. On the one hand, no one except the group manager can discover the real identity of users. On the other hand, even the manager, who issues user's secret key, is not capable of forging signatures on behalf of others. Secondly, we propose an anonymous public integrity verification protocol which not only supports integrity checking without retrieving whole data from the cloud, but also protects the signer's identity during the whole process. We utilize group signature to construct a homomorphic authenticator on each file block to guarantee the anonymous remote data integrity checking. Thirdly, our scheme supports a way of dynamic user operation that greatly improves the efficiency and feasibility of user revocation. At last, we formally prove our IPIC-DG scheme is IND-CCA security. Experimental results show that our work performs well in practical application. Aoting Hu, Bharat K. Bhargava |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | From Byzantine Fault-Tolerance to Fault-Avoidance: An Architectural Transformation to Attack and Failure ResiliencyabstractWe present Byzantine Fault-Avoidance (BFA), a fault-resilient architecture designed for Byzantine Fault Tolerant (BFT) systems to withstand against attacks and failures. BFA allows replicas to short live on a given computing platform, i.e., hardware, hypervisors and OS, to thwart successful and in-progress attacks while simultaneously preserving the correctness condition of BFT properties; safety and liveness. BFA combines the cloud management software stack of OpenStack (nova) and the Software Defined Network (SDN) implementation (neutron) to control the replicas susceptibility window of attack in order to avoid Byzantine faults. The proposed fault-avoidance scheme illustrates the defensive security solutions enabled by the underlying cloud computing fabric are far superior than the ones implemented at the application/protocol level. Preliminary results of widely studied BFT system (BFT-SMaRT) deployed in a cloud infrastructure (OpenStack-Kilo) indicate that BFA achieves desired BFT reliability properties and throughput over contested environments. Noor Ahmed 0001, Bharat K. Bhargava |
IEEE Trans. Cloud Comput. | 2 |
| 2020 | Source-Location Privacy Protection Based on Anonymity Cloud in Wireless Sensor NetworksabstractAn adversary can deploy parasitic sensor nodes into wireless sensor networks to collect radio traffic distributions and trace back messages to their source nodes. Then, he can locate the monitored targets around the source nodes with a high probability. In this paper, a Source-location privacy Protection scheme based on Anonymity Cloud (SPAC) is proposed. We first design a light-weight (t, n)-threshold message sharing scheme and map the original message to a set of message shares which are shorter in length and can be processed and delivered with minimal energy consumption. Based on the shares, the source node constructs an anonymity cloud with an irregular shape around itself to protect its location privacy. Specifically, an anonymity cloud is a set of active nodes with similar radio actions and they are statistically indistinguishable from each other. The size of the cloud is controlled by the preset number of hops that the shares can walk in the cloud. At the border of the cloud, the fake source nodes independently send the shares to the sink node through proper routing algorithms. At last, the original message can be recovered by the sink node once at least t shares are received. The simulation results demonstrate that the SPAC can strongly protect the source-location privacy in an efficient manner. Moreover, the message sharing mechanism of SPAC increases the confidentiality of network data and it also brings high tolerance for the failures of sensor nodes to the data transmission process. Na Wang 0003, Junsong Fu 0001, Jian Li 0035, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Safe and Efficient UAV Navigation Near an AirportabstractMuch recent effort has been devoted to employing Unmanned Aerial Vehicles (UAVs) to implement airport-related tasks. However, a critical issue, collision avoidance, must be fully considered in this scenario. Herein, we study the efficient UAV navigation problem considering the safety issue near an airport. In detail, we first define the safe separation between the UAV and airplanes according to related aviation regulations. Thereafter, an effective tree-based scheme for navigating the UAV has been proposed to cope with the extra uncertainties induced by keeping the safe separation. An analytical derivation of the UAV's flying time is conducted to determine the optimal battery life. Extensive simulation is conducted to verify our proposed navigation scheme and the analytical derivation. Yan Pan 0003, Bharat K. Bhargava, Zebu Ning, Nikola Slavov, ShiNing Li, Jianhang Liu, Shoaling Xu, Ting Zhu 0001 |
ICC | 2 |
| 2019 | MioStream: a peer-to-peer distributed live media streaming on the edge
Servio Palacios, Edgardo Barsallo, Bharat K. Bhargava |
Multim. Tools Appl. | 4 |
| 2019 | Big Data Analytics for Cyber Securityabstracte era of Internet of ings with billions of connected devices has created an ever larger surface for cyber attackers to exploit, which has resulted in the need for fast and accurate detection of those attacks.e developments in mobile computing, communications, and mass storage architectures in the past decade have brought about the phenomenon of big data, which involves unprecedented amounts of valuable data generated in various forms at a high speed.e ability to process these massive amounts of data in real time using big data analytics tools brings along many bene ts that could be utilized in cyber threat analysis systems.By making use of big data collected from networks, computers, sensors, and cloud systems, cyber threat analysts and intrusion detection/prevention systems can discover useful information in real time.is information can help detect system vulnerabilities and attacks that are becoming prevalent and develop security solutions accordingly.Big data analytics will be a must-have component of any e ective cyber security solution due to the need of fast processing of the high-velocity, high-volume data from various sources to discover anomalies and/or attack patterns as fast as possible to limit the vulnerability of the systems and increase their resilience.Even though many big data analytics tools have been developed in the past few years, their usage in the eld of cyber security warrants new approaches considering many aspects including (a) uni ed data representation, (b) zero-day attack detection, (c) data sharing across threat detection systems, (d) real time analysis, (e) sampling and dimensionality reduction, (f ) resource-constrained data processing, and (g) time series analysis for anomaly detection.is special issue has attracted original contributions that utilize and build big data analytics solutions for cyber Pelin Angin, Bharat K. Bhargava, Rohit Ranchal |
Secur. Commun. Networks | 2 |
| 2019 | A Blockchain-Enabled Trustless Crowd-Intelligence Ecosystem on Mobile Edge ComputingabstractCrowd intelligence tries to gather, process, infer, and ascertain massive useful information by utilizing the intelligence of crowds or distributed computers, which has great potential in Industrial Internet of Things. A crowd-intelligence ecosystem involves three stakeholders, namely the platform, workers (e.g., individuals, sensors, or processors), and task publisher. The stakeholders have no mutual trust but interest conflict, which means bad cooperation of them. Due to lack of trust, transferring raw data (e.g., pictures or video clips) between publisher and workers requires the remote platform center to serve as a relay node, which implies network congestion. First, we use a reward-penalty model to align the incentives of stakeholders. Then the predefined rules are implemented using blockchain smart contract on many edge servers (ES) of the mobile edge computing network, which together function as a trustless hybrid human-machine crowd-intelligence platform. As ES are near to workers and publisher, network congestion can be effectively improved. Further, we proved the existence of the only one strong Nash equilibrium, which can maximize the interests of involved ES and make the ecosystem bigger. Theoretical analysis and experiments validate the proposed method, respectively. Jinliang Xu, Shangguang Wang, Bharat K. Bhargava, Fangchun Yang |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | EPICS: A Framework for Enforcing Security Policies in Composite Web ServicesabstractWith advances in cloud computing and the emergence of service marketplaces, the popularity of composite services marks a paradigm shift from single-domain monolithic systems to cross-domain distributed services, which raises important privacy and security concerns. Access control becomes a challenge in such systems because authentication, authorization and data disclosure may take place across endpoints that are not known to clients. The clients lack options for specifying policies to control the sharing of their data and have to rely on service providers which offer limited selection of security and privacy preferences. This lack of awareness and loss of control over data sharing increases threats to a client's data and diminishes trust in these systems. We propose EPICS, an efficient and effective solution for enforcing security policies in composite Web services that protects data privacy throughout the service interaction lifecycle. The solution ensures that the data are distributed along with the client policies that dictate data access and an execution monitor that controls data disclosure. It empowers data owners with control of data disclosure decisions during interactions with remote services and reduces the risk of unauthorized access. The paper presents the design, implementation, and evaluation of the EPICS framework. Rohit Ranchal, Bharat K. Bhargava, Pelin Angin, Lotfi Ben Othmane |
IEEE Trans. Serv. Comput. | 2 |
| 2018 | (WIP) Blockhub: Blockchain-Based Software Development System for Untrusted EnvironmentsabstractTo ensure integrity, trust, immutability and authenticity of software and information (cyber data, user data and attack event data) in a collaborative environment, research is needed for cross-domain data communication, global software collaboration, sharing, access auditing and accountability. Blockchain technology can significantly automate the software export auditing and tracking processes. It allows to track and control what data or software components are shared between entities across multiple security domains. Our blockchain-based solution relies on role-based and attribute-based access control and prevents unauthorized data accesses. It guarantees integrity of provenance data on who updated what software module and when. Furthermore, our solution detects data leakages, made behind the scene by authorized blockchain network participants, to unauthorized entities. Our approach is used for data forensics/provenance, when the identity of those entities who have accessed/ updated/ transferred the sensitive cyber data or sensitive software is determined. All the transactions in the global collaborative software development environment are recorded in the blockchain public ledger and can be verified any time in the future. Transactions can not be repudiated by invokers. We also propose modified transaction validation procedure to improve performance and to protect permissioned IBM Hyperledger-based blockchains from DoS attacks, caused by bursts of invalid transactions. Denis A. Ulybyshev, Miguel Villarreal-Vasquez, Bharat K. Bhargava, Ganapathy Mani, Steve Seaberg, Paul Conoval, Jason Kobes |
IEEE CLOUD | 3 |
| 2018 | A self-protecting agents based model for high-performance mobile-cloud computing
Pelin Angin, Bharat K. Bhargava, Rohit Ranchal |
Comput. Secur. | 2 |
| 2018 | Source-location privacy full protection in wireless sensor networks
Na Wang 0003, Junsong Fu 0001, Jiwen Zeng, Bharat K. Bhargava |
Inf. Sci. | 4 |
| 2018 | Efficient Retrieval Over Documents Encrypted by Attributes in Cloud ComputingabstractSecure document storage and retrieval is one of the hottest research directions in cloud computing. Though many searchable encryption schemes have been proposed, few of them support efficient retrieval over the documents which are encrypted based on their attributes. In this paper, a hierarchical attribute-based encryption scheme is first designed for a document collection. A set of documents can be encrypted together if they share an integrated access structure. Compared with the ciphertext-policy attribute-based encryption schemes, both the ciphertext storage space and time costs of encryption/decryption are saved. Then, an index structure named attribute-based retrieval features (ARF) tree is constructed for the document collection based on the TF-IDF model and the documents' attributes. A depth-first search algorithm for the ARF tree is designed to improve the search efficiency which can be further improved by parallel computing. Except for the document collections, our scheme can be also applied to other datasets by modifying the ARF tree slightly. A thorough analysis and a series of experiments are performed to illustrate the security and efficiency of the proposed scheme. Na Wang 0003, Junsong Fu 0001, Bharat K. Bhargava, Jiwen Zeng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Secure Data Storage and Searching for Industrial IoT by Integrating Fog Computing and Cloud ComputingabstractWith the fast development of industrial Internet of things (IIoT), a large amount of data is being generated continuously by different sources. Storing all the raw data in the IIoT devices locally is unwise considering that the end devices' energy and storage spaces are strictly limited. In addition, the devices are unreliable and vulnerable to many threats because the networks may be deployed in remote and unattended areas. In this paper, we discuss the emerging challenges in the aspects of data processing, secure data storage, efficient data retrieval and dynamic data collection in IIoT. Then, we design a flexible and economical framework to solve the problems above by integrating the fog computing and cloud computing. Based on the time latency requirements, the collected data are processed and stored by the edge server or the cloud server. Specifically, all the raw data are first preprocessed by the edge server and then the time-sensitive data (e.g., control information) are used and stored locally. The non-time-sensitive data (e.g., monitored data) are transmitted to the cloud server to support data retrieval and mining in the future. A series of experiments and simulation are conducted to evaluate the performance of our scheme. The results illustrate that the proposed framework can greatly improve the efficiency and security of data storage and retrieval in IIoT. Junsong Fu 0001, Yun Liu 0001, Han-Chieh Chao, Bharat K. Bhargava, Zhenjiang Zhang |
IEEE Trans. Ind. Informatics | 4 |
| 2017 | End-to-End Policy Monitoring and Enforcement for Service-Oriented ArchitectureabstractA service-oriented architecture (SOA)-based application is composed of a number of distributed and loosely-coupled services which are interconnected to accomplish a more complex functionality. The main security challenge in SOA is that we cannot trust the participating services in a service composition to behave as expected all the time. Moreover, the chain of all services involved in an end-to-end invocation may not be visible to the clients. As a result, any violation of the client's policies could remain undetected. To address these challenges in SOA, we propose the following contributions. First, we propose a new end-to-end security architecture for SOA based on a dynamic composite trust model. To maintain the dynamic trust, we designed a trusted-third party service called trust manager component, which collects and processes feedbacks from the actual execution of services. Second, we developed an end-to-end inter-service policy monitoring and enforcement framework (PME framework), which is able to dynamically intercept the interactions between services at runtime and react to the potentially malicious activities according to the client's policies. Third, we design an intra-service policy monitoring and enforcement framework based on taint analysis mechanism to monitor the flow of information within services and detect and prevent information disclosure attacks. These two frameworks together can provide an end-to-end visibility and security in SOA. Finally, we have extensively studied the correctness and performance of the proposed security frameworks based on a realistic SOA case study in a cloud environment. All experimental studies validate that the practicality and effectiveness of the presented solutions. Mehdi Azarmi, Bharat K. Bhargava |
CLOUD | 2 |
| 2017 | An End-to-End Dynamic Trust Framework for Service-Oriented ArchitectureabstractService-oriented architecture (SOA) is an architectural paradigm that advocates composition of loosely-coupled services in order to construct more complex applications. The agility and complexity of modern web services on one hand and the arbitrary interconnections among them on the other hand, make it difficult to maintain a sustainable trustworthiness in long-running SOA-based applications. Moreover, the chain of participating services in a specific SOA invocation may not be visible to the service consumers, which leads to a lack of accountability. To address these challenges in SOA, we propose the following contributions. First, we design a new dynamic and flexible trust model based on graph abstraction that uses multiple trust strategies to calculate trust across SOA. This trust model keeps track of three trust metrics: individual service trust, session trust, and composite trust. We further design a trust engine component that implements the proposed trust model and that continuously maintains the quantitative end-to-end trust based on processing actual execution of services. Second, to prove the practicality and usefulness of the proposed framework, we have implemented an adaptive and secure service composition engine (ASSC) which takes advantage of an efficient algorithm to generate service compositions with near-optimal trustworthiness under predefined QoS constraints. Finally, we have developed a tool that is able to automatically deploy SOA testbeds from arbitrary directed acyclic graphs (created in the GUI). This tool enables the researcher to study the dynamics of new trust algorithms and strategies under different scenarios (e.g., arbitrary SOA topologies and attacks). We have extensively studied the effectiveness and performance of the proposed solutions using testbeds in the Amazon EC2 cloud. Mehdi Azarmi, Bharat K. Bhargava |
CLOUD | 2 |
| 2017 | A Monitoring Approach for Policy Enforcement in Cloud ServicesabstractWhen clients interact with a cloud-based service, they expect certain levels of quality of service guarantees. These are expressed as security and privacy policies, interaction authorization policies, and service performance policies among others. The main security challenge in a cloud-based service environment, typically modeled using service-oriented architecture (SOA), is that it is difficult to trust all services in a service composition. In addition, the details of the services involved in an end-to-end service invocation chain are usually not exposed to the clients. The complexity of the SOA services and multi-tenancy in the cloud environment leads to a large attack surface. In this paper we propose a novel approach for end-to-end security and privacy in cloud-based service orchestrations, which uses a service activity monitor to audit activities of services in a domain. The service monitor intercepts interactions between a client and services, as well as among services, and provides a pluggable interface for different modules to analyze service interactions and make dynamic decisions based on security policies defined over the service domain. Experiments with a real-world service composition scenario demonstrate that the overhead of monitoring is acceptable for real-time operation of Web services. Ruchith Fernando, Rohit Ranchal, Bharat K. Bhargava, Pelin Angin |
CLOUD | 3 |
| 2017 | Privacy-Preserving Data Dissemination in Untrusted CloudabstractB2B (business-to-business) systems often use service-oriented architecture (SOA) with decomposed business services. These services can interact and share data among each other. Service might use a cloud – hosted database, such as a non - relational encrypted key – value store. However, the cloud platform hosting the database can be untrusted. Data owner needs to be sure that each service can access only those segments of a shared database for which the service is authorized. Furthermore, data requests can come from a service also hosted by untrusted cloud. Hence, there is a need for designing a cloud enterprise framework that can ensure privacy-preserving data dissemination in SOA and accurately detect data leakages. We design and prototype a solution that ensures privacy – preserving dissemination of data. The solution is based on (a) role-based access control, (b) cryptographic capabilities of client's browser, (c) authentication method, (d) subject's trust level. The prototype enables privacy – preserving dissemination of Electronic Health Records (EHRs) hosted in an untrusted cloud. Denis A. Ulybyshev, Bharat K. Bhargava, Miguel Villarreal-Vasquez, Aala Oqab Alsalem, Donald Steiner, Leon Li, Jason Kobes, Harry Halpin, Rohit Ranchal |
CLOUD | 2 |
| 2017 | An MTD-Based Self-Adaptive Resilience Approach for Cloud SystemsabstractAdvances in cloud computing have made it a feasible and cost-effective solution to improve the resiliency of enterprise systems. However, the replication approach taken by cloud computing to provide resiliency leads to an increase in the number of ways an attacker can exploit or penetrate the systems. This calls for designing cloud systems that can accurately detect anomalies and dynamically adapt themselves to keep performing mission-critical functions even under attacks and failures. In this paper, we propose a self-adaptive resiliency approach for cloud enterprise systems that employs a live monitoring and moving target defense based approach to automatically detect deviations from normal behavior and reconfigure critical cloud processes through software-defined networking to mitigate attacks and reduce system downtime. The proposed solution is promising to present a unified framework for resilient cloud systems. Miguel Villarreal-Vasquez, Bharat K. Bhargava, Pelin Angin, Noor Ahmed 0001, Daniel Goodwin, Kory Brin, Jason Kobes |
CLOUD | 2 |
| 2017 | RaaS and Hierarchical Aggregation RevisitedabstractConsumer ratings are widely used in online marketplaces-helping vendors in assessing the quality of offerings and consumers in discovery and purchase decisions. To build trust in a marketplace, which has a direct impact on sales, an accurate assessment of ratings is essential in determining the quality of offerings. This paper proposes novel extensions to consumer Rating as a Service (RaaS)-a rating management service providing consumer rating functionality to a marketplace using hierarchical aggregation, which is a rating aggregation mechanism using hierarchical relationships of components to evaluate composite offerings. Contributions include the optimization of RaaS design for Web-scale, the integration of consumer credibility in hierarchical aggregation, and the application of hierarchical aggregation to existing independent atomic offerings. Various experiments are conducted to demonstrate the practicality of RaaS and correctness of hierarchical aggregation using real ratings from Amazon.com. Rohit Ranchal, Sidak Pal Singh, Pelin Angin, Ajay Mohindra, Hui Lei 0001, Bharat K. Bhargava |
ICWS | 6 |
| 2017 | On the Security of Data Access Control for Multiauthority Cloud Storage SystemsabstractData access control has becoming a challenging issue in cloud storage systems. Some techniques have been proposed to achieve the secure data access control in a semitrusted cloud storage system. Recently, K. Yang et al. proposed a basic data access control scheme for multiauthority cloud storage system (DAC-MACS) and an extensive data access control scheme (EDAC-MACS). They claimed that the DAC-MACS could achieve efficient decryption and immediate revocation and the EDAC-MACS could also achieve these goals even though nonrevoked users reveal their Key Update Keys to the revoked user. However, through our cryptanalysis, the revocation security of both schemes cannot be guaranteed. In this paper, we first give two attacks on the two schemes. By the first attack, the revoked user can eavesdrop to obtain other users' Key Update Keys to update its Secret Key, and then it can obtain proper Token to decrypt any secret information as a nonrevoked user. In addition, by the second attack, the revoked user can intercept Ciphertext Update Key to retrieve its ability to decrypt any secret information as a nonrevoked user. Secondly, we propose a new extensive DAC-MACS scheme (NEDAC-MACS) to withstand the above two attacks so as to guarantee more secure attribute revocation. Then, formal cryptanalysis of NEDAC-MACS is presented to prove the security goals of the scheme. Finally, the performance comparison among NEDAC-MACS and related schemes is given to demonstrate that the performance of NEDAC-MACS is superior to that of DACC, and relatively same as that of DAC-MACS. Xianglong Wu, Bharat K. Bhargava |
IEEE Trans. Serv. Comput. | 3 |
| 2016 | Consumer Oriented Privacy Preserving Access Control for Electronic Health Records in the CloudabstractThis paper addresses privacy issues in managing electronic health records by a third party cloud based service. Compared to traditional authentication-authorization mechanisms, the proposed approach minimizes the leakage of identity information of involved participants through unlinkability. Furthermore, it gives the ability to health record owners for making access control decisions. This solution employs an identity management scheme that enhances consumer privacy by preventing consumer profiling based on the credentials used to satisfy the service provider policies. The paper proposes a set of mechanisms to allow authenticated unlinkable access to electronic health records, while giving the record owners ability to make access control decisions. The security evaluation for accessing data in the cloud is detailed, and the implementation of the system is evaluated in this paper. Ruchith Fernando, Rohit Ranchal, Byungchan An, Lotfi Ben Othmane, Bharat K. Bhargava |
CLOUD | 5 |
| 2016 | Disruption-resilient Publish and SubscribeabstractPublish and Subscribe (pub/sub) dissemination paradigm has emerged as a popular means of disseminating selective time-sensitive information. Through the use of event service or broker, published information is filtered to disseminate only to the subscribers interested in that information. Once a broker is compromised, information can be delivered unfiltered, dropped, delayed, perhaps colluding among the brokers in virtualized cloud platforms. Such disruptive behavior is known as Byzantine faults. We present a Disruption–Resilient Publish and Subscribe (DRPaS) system designed to withstand faults through continuously refreshing the virtual instances of the broker. DRPaS combines advances in cloud management software stack (i.e., OpenStack nova and neutron) to control the broker’s susceptibility window of disruption. Preliminary experimental results show that the defensive security solutions enabled by the underlying cloud computing fabric is simpler and more effective than the ones implemented at the application/protocol level to withstand disruptions. Noor Ahmed 0001, Bharat K. Bhargava |
CLOSER (1) | 2 |
| 2016 | Privacy Preserving Access Control in Service-Oriented ArchitectureabstractService-oriented Architecture (SOA) comprises a number of loosely-coupled independent services, which collaborate, interact and share data to accomplish incoming requests. A service invocation can involve multiple services, where each service accesses, processes and shares the client's data. These interactions may share data with unauthorized services and violate client's privacy. The client has no means of identifying if a violation occurred because it has no control over the service invocations beyond its trust domain. Such interactions introduce new security challenges which are not present in traditional systems. This paper proposes a data-centric approach for privacy preserving access control in SOA. Benefits of the proposed approach include the ability to dynamically define access polices by the clients and control data access at the time of each service interaction. A realistic healthcare scenario is used to evaluate the implementation of the proposed solution which validates its viability. Rohit Ranchal, Bharat K. Bhargava, Ruchith Fernando, Hui Lei 0001, Zhongjun Jin |
ICWS | 2 |
| 2016 | Tamper-resistant autonomous agents-based mobile-cloud computingabstractThe rise of the mobile-cloud computing paradigm has enabled mobile devices with limited processing power and battery life to achieve complex tasks in real-time. While mobile-cloud computing is promising to overcome limitations of mobile devices for real-time computing needs, the reliance of existing models on strong assumptions such as the availability of a full clone of the application code and non-standard system environments in the cloud makes it harder to manage the performance of mobile-cloud computing based applications. Furthermore, offloading mobile computation to the cloud entails security risks associated with sending data and code to an untrusted platform and perfect security is hard to achieve due to the extra computational overhead introduced by complex mechanisms. In this paper, we present a dynamic computation-offloading model for mobile-cloud computing, based on autonomous agent-based application partitions. We propose a dynamic tamper-resistance approach for managing the security of offloaded computation, by augmenting agents with self-protection capability using a low-overhead introspection and integrity-preserving communication mechanism. Experiments with a real-world mobile application demonstrates the effectiveness of the approach for high-performance, tamper-resistant mobile-cloud computing. Pelin Angin, Bharat K. Bhargava, Rohit Ranchal |
NOMS | 2 |
| 2016 | SDSS-MAC: Secure data sharing scheme in multi-authority cloud storage systems
Xianglong Wu, Bharat K. Bhargava |
Comput. Secur. | 3 |
| 2015 | A Self-Cloning Agents Based Model for High-Performance Mobile-Cloud ComputingabstractThe rise of the mobile-cloud computing paradigm in recent years has enabled mobile devices with processing power and battery life limitations to achieve complex tasks in real-time. While mobile-cloud computing is promising to overcome the limitations of mobile devices for real-time computing, the lack of frameworks compatible with standard technologies and techniques for dynamic performance estimation and program component relocation makes it harder to adopt mobile-cloud computing at large. Most of the available frameworks rely on strong assumptions such as the availability of a full clone of the application code and negligible execution time in the cloud. In this paper, we present a dynamic computation offloading model for mobile-cloud computing, based on autonomous agents. Our approach does not impose any requirements on the cloud platform other than providing isolated execution containers, and it alleviates the management burden of offloaded code by the mobile platform using stateful, autonomous application partitions. We also investigate the effects of different cloud runtime environment conditions on the performance of mobile-cloud computing, and present a simple and low-overhead dynamic make span estimation model integrated into autonomous agents to enhance them with self-performance evaluation in addition to self-cloning capabilities. The proposed performance profiling model is used in conjunction with a cloud resource optimization scheme to ensure optimal performance. Experiments with two mobile applications demonstrate the effectiveness of the proposed approach for high-performance mobile-cloud computing. Pelin Angin, Bharat K. Bhargava, Zhongjun Jin |
CLOUD | 2 |
| 2015 | Towards Dynamic QoS Monitoring in Service Oriented Architectures
Norman Ahmed, Bharat K. Bhargava |
CLOSER | 2 |
| 2015 | Hierarchical Aggregation of Consumer Ratings for Service EcosystemabstractWith the wide availability of products and services through popular e-commerce platforms and dozens of similar offerings to choose from, there is a need to accurately assess and evaluate the quality of offerings. Several studies have shown that consumer feedback is an important source of information. This paper presents: (a) consumer Rating as a Service (RaaS) -- a building block service that can be used to add the consumer feedback lifecycle feature in the development of e-commerce platforms, (b) an approach to evaluate the quality of composite offerings based on the aggregation of consumer ratings using the composition structure and component relationships. Benefits of the proposed service include reduced development effort, shorter delivery time and a fine-grained aggregation of consumer ratings for composite offerings even with limited ratings. Rohit Ranchal, Ajay Mohindra, Nianjun Zhou, Shubir Kapoor, Bharat K. Bhargava |
ICWS | 5 |
| 2015 | Incorporating attacker capabilities in risk estimation and mitigation
Lotfi Ben Othmane, Rohit Ranchal, Ruchith Fernando, Bharat K. Bhargava, Eric Bodden |
Comput. Secur. | 4 |
| 2015 | A Computational Dynamic Trust Model for User AuthorizationabstractDevelopment of authorization mechanisms for secure information access by a large community of users in an open environment is an important problem in the ever-growing Internet world. In this paper we propose a computational dynamic trust model for user authorization, rooted in findings from social science. Unlike most existing computational trust models, this model distinguishes trusting belief in integrity from that in competence in different contexts and accounts for subjectivity in the evaluation of a particular trustee by different trusters. Simulation studies were conducted to compare the performance of the proposed integrity belief model with other trust models from the literature for different user behavior patterns. Experiments show that the proposed model achieves higher performance than other models especially in predicting the behavior of unstable users. Yuhui Zhong, Bharat K. Bhargava, Yi Lu 0013, Pelin Angin |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | Using Assurance Cases to Develop Iteratively Security Features Using ScrumabstractA security feature is a customer-valued capability of software for mitigating a set of security threats. Incremental development of security features, using the Scrum method, often leads to developing ineffective features in addressing the threats they target due to factors such as incomplete security tests. This paper proposes the use of security assurance cases to maintain a global view of the security claims as the feature is being developed iteratively and a process that enables the incremental development of security features while ensuring the security requirements of the feature are fulfilled. Lotfi Ben Othmane, Pelin Angin, Bharat K. Bhargava |
ARES | 3 |
| 2014 | A simulation study of ad hoc networking of UAVs with opportunistic resource utilization networks
Leszek Lilien, Lotfi Ben Othmane, Pelin Angin, Andrew DeCarlo, Raed M. Salih, Bharat K. Bhargava |
J. Netw. Comput. Appl. | 6 |
| 2014 | Extending the Agile Development Process to Develop Acceptably Secure SoftwareabstractThe agile software development approach makes developing secure software challenging. Existing approaches for extending the agile development process, which enables incremental and iterative software development, fall short of providing a method for efficiently ensuring the security of the software increments produced at the end of each iteration. This article (a) proposes a method for security reassurance of software increments and demonstrates it through a simple case study, (b) integrates security engineering activities into the agile software development process and uses the security reassurance method to ensure producing acceptably secure-by the business owner-software increments at the end of each iteration, and (c) discusses the compliance of the proposed method with the agile values and its ability to produce secure software increments. Lotfi Ben Othmane, Pelin Angin, Harold Weffers, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2013 | Analysis of End-to-End SOA Security Protocols with Mobile DevicesabstractService Oriented Architecture (SOA) is an architectural style that provides agility to align technical solutions to a modular business Web Services (WS) that are well decoupled from their consumers. This agility is extended to the Cloud model. To achieve a high level of security and a degree of decoupling, SOA encourages the use of standardized transport schemes such as SOAP/HTTP(s) with WS family of standards specifications (commonly referred to as WS-* (WS-star)) to ease the interoperability complexity and security concerns in enterprise networks, which have medium/high bandwidth and reliable/wired networks. However, these protocol standards are ill suited for mobile devices due to their limited computational capabilities, low bandwidth, and intermittent connectivity. In this paper, we present an analysis of WS-* standards, classifying and discussing their inter-dependencies to provide a basis for determining the limitation of mobile device use in SOA and for establishing an architectural consideration baseline for selecting appropriate security mechanisms. Norman Ahmed, Mark Linderman, Rose F. Gamble, Bharat K. Bhargava |
MDM (2) | 4 |
| 2013 | Protecting PLM Data Throughout Their Lifecycle
Rohit Ranchal, Bharat K. Bhargava |
QSHINE | 2 |
| 2013 | A Case for Societal Digital Security Culture
Lotfi Ben Othmane, Harold Weffers, Rohit Ranchal, Pelin Angin, Bharat K. Bhargava, Mohd Murtadha Mohamad |
SEC | 5 |
| 2013 | A Survey of Computation Offloading for Mobile Systems
Karthik Kumar, Jibang Liu, Yung-Hsiang Lu, Bharat K. Bhargava |
Mob. Networks Appl. | 4 |
| 2013 | Editorial for Special Issue on "New Technologies and Applications for Wireless Communications & Mobile Cloud Computing"
Taeshik Shon, Athanasios V. Vasilakos, Bharat K. Bhargava, Ivan Stojmenovic, Hai Jin 0001, Albert Y. Zomaya |
Mob. Networks Appl. | 3 |
| 2013 | Immunizing mobile ad hoc networks against collaborative attacks using cooperative immune modelabstractABSTRACT In this paper, a security problem of cooperative immunization against collaborative attacks such as blackhole attacks and wormhole attacks, in the mobile ad hoc networks such as the Worldwide Interoperability for Microwave Access (WiMAX) networks, was discussed. Because of the vulnerabilities of the protocol suites, collaborative attacks in the mobile ad hoc networks can cause more damages than individual attacks. In human immune system, nonselfs (i.e., viruses, bacteria and cancers etc.) can attack human body in a collaborative way and cause diseases in the human body. With the inspiration from the human immune system, a tri‐tier cooperative immune model was built to detect and eliminate the collaborative attacks (i.e., nonselfs) in the mobile ad hoc networks. ARM‐based Network Simulator (NS2) tests and probability analysis were utilized in the prototype for immune model to analyze and detect the attacks. Experimental results demonstrate the validation and effectiveness of the model proposed by minimizing the collaborative attacks and immunizing the mobile ad hoc networks. Copyright © 2012 John Wiley & Sons, Ltd. Bharat K. Bhargava |
Secur. Commun. Networks | 2 |
| 2013 | SORT: A Self-ORganizing Trust Model for Peer-to-Peer SystemsabstractOpen nature of peer-to-peer systems exposes them to malicious activity. Building trust relationships among peers can mitigate attacks of malicious peers. This paper presents distributed algorithms that enable a peer to reason about trustworthiness of other peers based on past interactions and recommendations. Peers create their own trust network in their proximity by using local information available and do not try to learn global trust information. Two contexts of trust, service, and recommendation contexts, are defined to measure trustworthiness in providing services and giving recommendations. Interactions and recommendations are evaluated based on importance, recentness, and peer satisfaction parameters. Additionally, recommender's trustworthiness and confidence about a recommendation are considered while evaluating recommendations. Simulation experiments on a file sharing application show that the proposed model can mitigate attacks on 16 different malicious behavior models. In the experiments, good peers were able to form trust relationships in their proximity and isolate malicious peers. Ahmet Burak Can, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | An End-to-End Security Auditing Approach for Service Oriented ArchitecturesabstractService-Oriented Architecture (SOA) is becoming a major paradigm for distributed application development in the recent explosion of Internet services and cloud computing. However, SOA introduces new security challenges not present in the single-hop client-server architectures due to the involvement of multiple service providers in a service request. The interactions of independent service domains in SOA could violate service policies or SLAs. In addition, users in SOA systems have no control on what happens in the chain of service invocations. Although the establishment of trust across all involved partners is required as a prerequisite to ensure secure interactions, still a new end-to-end security auditing mechanism is needed to verify the actual service invocations and its conformance to the expected service orchestration. In this paper, we provide an efficient solution for end-to-end security auditing in SOA. The proposed security architecture introduces two new components called taint analysis and trust broker in addition to taking advantages of WS-Security and WS-Trust standards. The interaction of these components maintains session auditing and dynamic trust among services. This solution is transparent to the services, which allows auditing of legacy services without modification. Moreover, we have implemented a prototype of the proposed approach and verified its effectiveness in a LAN setting and the Amazon EC2 cloud computing infrastructure. Mehdi Azarmi, Bharat K. Bhargava, Pelin Angin, Rohit Ranchal, Norman Ahmed, Asher Sinclair, Mark Linderman, Lotfi Ben Othmane |
SRDS | 2 |
| 2012 | Private Anonymous MessagingabstractMessaging systems where a user maintains a set of contacts and broadcasts messages to them is very common. We address the problem of a contact obtaining a message that it missed, from other contacts of the user while maintaining anonymity of all parties involved. We identify a set of requirements in addressing this problem and propose a modification to the hierarchical identity based encryption scheme proposed by Boneh et. al. We briefly present an implementation of the proposed cryptographic primitives as a proof of concept. Ruchith Fernando, Bharat K. Bhargava, Mark Linderman |
SRDS | 2 |
| 2012 | Extending Attack Graph-Based Security Metrics and Aggregating Their ApplicationabstractThe attack graph is an abstraction that reveals the ways an attacker can leverage vulnerabilities in a network to violate a security policy. When used with attack graph-based security metrics, the attack graph may be used to quantitatively assess security-relevant aspects of a network. The Shortest Path metric, the Number of Paths metric, and the Mean of Path Lengths metric are three attack graph-based security metrics that can extract security-relevant information. However, one's usage of these metrics can lead to misleading results. The Shortest Path metric and the Mean of Path Lengths metric fail to adequately account for the number of ways an attacker may violate a security policy. The Number of Paths metric fails to adequately account for the attack effort associated with the attack paths. To overcome these shortcomings, we propose a complimentary suite of attack graph-based security metrics and specify an algorithm for combining the usage of these metrics. We present simulated results that suggest that our approach reaches a conclusion about which of two attack graphs correspond to a network that is most secure in many instances. Nwokedi C. Idika, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | A Kolmogorov Complexity Approach for Measuring Attack Path Complexity
Nwokedi C. Idika, Bharat K. Bhargava |
SEC | 2 |
| 2011 | Local geometric algorithm for hole boundary detection in sensor networksabstractAbstract We present a hole boundary detection algorithm for sensor network which identifies the geographical boundary of voids in the network assuming the relative geographic information of only 2‐hop neighbors. We formalize the fuzzy notion of a hole by relating it to the graph theoretic concept of a chordless cycle enclosing a face in an arrangement of lines. Furthermore, the algorithm for detecting such topological holes is distributed, O(k) per node computation (fork2‐hop neighbors) and requires synchronization between nodes that are no more than 2‐hops away. The algorithm takes a local best‐effort approach and does not verify if the nodes indeed form a closed polygonal loop. We believe that this local effort is sufficient based on theoretical observations and experiments. In the simulation tests we conducted, this was hardly a restriction in correctly identifying the simple, closed polygonal loops. We discuss the security implications of the hole detection framework in the context of sensor networks. Copyright © 2011 John Wiley & Sons, Ltd. Amit Shirsat, Bharat K. Bhargava |
Secur. Commun. Networks | 2 |
| 2010 | A Mobile-Cloud Collaborative Traffic Lights Detector for Blind NavigationabstractContext-awareness is a critical aspect of safe navigation especially for the blind and visually impaired in unfamiliar environments. Existing mobile devices for context-aware navigation fall short in many cases due to their dependence on specific infrastructure requirements as well as having limited access to resources that could provide a wealth of contextual clues. In this paper, we propose a mobile-cloud collaborative approach for context-aware navigation by exploiting the computational power of resources made available by Cloud Computing providers as well as the wealth of location-specific resources available on the Internet. We propose an extensible system architecture that minimizes reliance on infrastructure, thus allowing for wide usability. We present a traffic light detector that we developed as an initial application component of the proposed system. We present preliminary results of experiments performed to test the appropriateness for the real-time nature of the application. Pelin Angin, Bharat K. Bhargava, Abdelsalam Helal |
Mobile Data Management | 2 |
| 2010 | An Entity-Centric Approach for Privacy and Identity Management in Cloud ComputingabstractEntities (e.g., users, services) have to authenticate themselves to service providers (SPs) in order to use their services. An entity provides personally identifiable information (PII) that uniquely identifies it to an SP. In the traditional application-centric Identity Management (IDM) model, each application keeps trace of identities of the entities that use it. In cloud computing, entities may have multiple accounts associated with different SPs, or one SP. Sharing PIIs of the same entity across services along with associated attributes can lead to mapping of PIIs to the entity. We propose an entity-centric approach for IDM in the cloud. The approach is based on: (1) active bundles-each including a payload of PII, privacy policies and a virtual machine that enforces the policies and uses a set of protection mechanisms to protect themselves, (2) anonymous identification to mediate interactions between the entity and cloud services using entity's privacy policies. The main characteristics of the approach are: it is independent of third party, gives minimum information to the SP and provides ability to use identity data on untrusted hosts. Pelin Angin, Bharat K. Bhargava, Rohit Ranchal, Noopur Singh, Mark Linderman, Lotfi Ben Othmane, Leszek Lilien |
SRDS | 2 |
| 2010 | Protection of Identity Information in Cloud Computing without Trusted Third PartyabstractCloud computing allows the use of Internet-based services to support business processes and rental of IT-services on a utility-like basis. It offers a concentration of resources but also poses risks for data privacy. A single breach can cause significant loss. The heterogeneity of “users” represents a danger of multiple, collaborative threats. In cloud computing, entities may have multiple accounts associated with a single or multiple service providers (SPs). Sharing sensitive identity information (that is, Personally Identifiable information or PII) along with associated attributes of the same entity across services can lead to mapping of the identities to the entity, tantamount to privacy loss. Identity management (IDM) is one of the core components in cloud privacy and security and can help alleviate some of the problems associated with cloud computing. Available solutions use trusted third party (TTP) in identifying entities to SPs. The solution providers do not recommend the usage of their solutions on untrusted hosts. We propose an approach for IDM, which is independent of TTP and has the ability to use identity data on untrusted hosts. The approach is based on the use of predicates over encrypted data and multi-party computing for negotiating a use of a cloud service. It uses active bundle-which is a middleware agent that includes PII data, privacy policies, a virtual machine that enforces the policies, and has a set of protection mechanisms to protect itself. An active bundle interacts on behalf of a user to authenticate to cloud services using user's privacy policies. Rohit Ranchal, Bharat K. Bhargava, Lotfi Ben Othmane, Leszek Lilien, Anya Kim, Myong H. Kang, Mark Linderman |
SRDS | 2 |
| 2009 | Adaptive Voice Spam Control with User Behavior AnalysisabstractSpit (Spam over Internet Telephony), known as unsolicited bulk calls sent via VoIP networks, is a major problem that undermines the usability of VoIP. Countermeasures against spit face challenges in identifying and filtering spit in real time. A user behavior based on three parameters (interaction,historical, and social ratio) is used to design an anti-spit technique. The rationale for the technique is that voice spammers behave significantly different from legitimate callers because of their revenue-driven motivations. The scheme uses adaptive training to determine filtering accuracy and estimates the legitimacy of the caller. The ideas can be implemented at the router level for detecting and achieving voice spam control. Compared to existing spit defending techniques, it is simple, fast and effective. Experiments are reported and measure the accuracy based on call intensity, call density, and the size of training data. The proposed scheme inapplicable for detecting and filtering both machine initiated and human-initiated spam calls, better protects VoIP calls against Sybil attacks and spammer behavior changes. Xiao Su 0006, Bharat K. Bhargava |
HPCC | 3 |
| 2009 | Detection and filtering Spam over Internet Telephony - a user-behavior-aware intermediate-network-based approachabstractVoIP applications have gained popularity due to largely reduced cost and wider range of advanced services, as compared to traditional telephone networks. However, SPIT (spam over Internet telephony), known as unsolicited bulk calls sent via VoIP networks, is becoming a major problem that would undermine the usability of VoIP. Unlike detection and filtering of e-mail spam, countermeasures against SPIT face great challenges on how to identify and filter SPIT in real time. In this paper, a user-behavior-aware anti-SPIT technique implemented at the router level for detecting and filtering SPIT is proposed. The rationale for the technique is that voice spammers behave significantly different from legitimate callers because of their revenue-driven motivations. The technique defines and combines three features developed from user behavior analyses to detect and filter spam calls. Compared to existing SPIT defending techniques, it is simple, fast and effective. Other advantages of our approach are that it is applicable for detecting and filtering both machine-initiated and human-initiated spam calls, better protects VoIP calls against sybil attacks and spammer behavior changes. Xiao Su 0006, Bharat K. Bhargava |
ICME | 3 |
| 2009 | The Effects of Threading, Infection Time, and Multiple-Attacker Collaboration on Malware PropagationabstractSelf-propagating malware spreads over the network quickly and automatically. Malware propagation should be modeled accurately for fast detection and defense. State-of-the-art malware propagation models fail to consider a number of issues. First, the malware can scan a host for multiple vulnerabilities on multiple ports. Second, the vulnerability scanning can be done by multiple threads concurrently. Third, the exploitation of vulnerabilities and the infection of vulnerable hosts cannot be done instantly. Fourth, the malware propagation can start from multiple places in the network rather than a single release point. Finally, the malware copies can collaborate with each other to cause much more damage. Little was done to understand the effects of multi-port scanning, multi-threading, infection time, multiple starting points, and collaboration (MMIMC) on malware propagation. This research quantitatively measures the effects of MMIMC on infected hosts. We employ the Fibonacci number sequence (FNS)to model the effects of infection time. We derive the shift property, which illustrates that different malware initialization scan be represented by shifting their propagations on the time axis. We prove the linear property, which shows that the effects of multiple-attacker collaboration can be represented by linear combinations of individual attacks. Experimental results show that the above issues significantly affect malware propagation and verify our analysis. Yu Zhang 0188, Bharat K. Bhargava, Philipp Hurni |
SRDS | 2 |
| 2009 | Collaborative attacks in WiMAX networksabstractAbstract In this paper, we discuss security problems, with a focus on collaborative attacks, in the Worldwide Interoperability for Microwave Access (WiMAX) scenario. The WiMAX protocol suite, which includes but is not limited to DOCSIS, DES, and AES, consists of a large number of protocols. We present briefly the WiMAX standard and its vulnerabilities. We pinpoint the problems with individual protocols in the WiMAX protocol suite, and discuss collaborative attacks on WiMAX systems. We present several typical WiMAX attack scenarios, including: bringing a large number of attackers to increase their computation power and break WiMAX protocols; assembling a sufficient number of attackers to influence the decision‐making of core machines, which includes routing attacks and Sybil attacks; and exploiting implementations that do not conform to the WiMAX specification completely, causing interoperability problems among various protocols, including the ones in typical WiMAX/WiFi/LAN deployment scenarios. We present theoretical models and practical solutions to profile, model, and analyze collaborative attacks in WiMAX. We employ attack graphs to do vulnerability analysis. Experimental results verify our models and validate our analysis. Copyright © 2009 John Wiley & Sons, Ltd. Bharat K. Bhargava, Yu Zhang 0188, Nwokedi C. Idika, Leszek Lilien, Mehdi Azarmi |
Secur. Commun. Networks | 1 |
| 2009 | Self-Learning Disk SchedulingabstractPerformance of disk I/O schedulers is affected by many factors, such as workloads, file systems, and disk systems. Disk scheduling performance can be improved by tuning scheduler parameters, such as the length of read timers. Scheduler performance tuning is mostly done manually. To automate this process, we propose four self-learning disk scheduling schemes: change-sensing Round-Robin, feedback learning, per-request learning, and two-layer learning. experiments show that the novel two-layer learning scheme performs best. It integrates the workload-level and request-level learning algorithms. It employs feedback learning techniques to analyze workloads, change scheduling policy, and tune scheduling parameters automatically. We discuss schemes to choose features for workload learning, divide and recognize workloads, generate training data, and integrate machine learning algorithms into the two-layer learning scheme. We conducted experiments to compare the accuracy, performance, and overhead of five machine learning algorithms: decision tree, logistic regression, naive Bayes, neural network, and support vector machine algorithms. Experiments with real-world and synthetic workloads show that self-learning disk scheduling can adapt to a wide variety of workloads, file systems, disk systems, and user preferences. It outperforms existing disk schedulers by as much as 15.8% while consuming less than 3%-5% of CPU time. Yu Zhang 0188, Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2008 | Multi-hop Cross-Layer Design in Wireless Sensor Networks: A Case StudyabstractCross-layer design has been proposed as a promising paradigm to tackle various problems of wireless communication systems. Recent research has led to a variety of protocols that rely on intensive interaction between different layers of the classical layered OSI protocol architecture. These protocols involve different layers and introduce new ideas how layers shall communicate and interact. In existing cross-layer approaches, the violation of the OSI architecture typically consists in passing information between different adjacent or non-adjacent layers of one single station's protocol stack to solve an optimization problem and exploiting the dependencies between the layers. This paper proposes to go a step further and to consider cross-layer information exchange across different layers of multiple stations involved in multi-hop communication systems. It outlines possible application scenarios of this approach, and trades off between advantages and disadvantages of the proposed \emph {multi-hop cross-layer design}. It examines an application scheme in a scenario of a wireless sensor network environment operating with a recent energy-efficient power saving protocol. Philipp Hurni, Torsten Braun, Bharat K. Bhargava, Yu Zhang 0188 |
WiMob | 3 |
| 2008 | A role-based access in a hierarchical sensor network architecture to provide multilevel security
Biswajit Panja, Sanjay Madria, Bharat K. Bhargava |
Comput. Commun. | 3 |
| 2008 | Invisible watermarking based on creation and robust insertion-extraction of image adaptive watermarksabstractThis article presents a novel invisible robust watermarking scheme for embedding and extracting a digital watermark in an image. The novelty lies in determining a perceptually important subimage in the host image. Invisible insertion of the watermark is performed in the most significant region of the host image such that tampering of that portion with an intention to remove or destroy will degrade the esthetic quality and value of the image. One feature of the algorithm is that this subimage is used as a region of interest for the watermarking process and eliminates the chance of watermark removal. Another feature of the algorithm is the creation of a compound watermark using the input user watermark (logo) and attributes of the host image. This facilitates the homogeneous fusion of a watermark with the cover image, preserves the quality of the host image, and allows robust insertion-extraction. Watermark creation consists of two distinct phases. During the first phase, a statistical image is synthesized from a perceptually important subimage of the image. A compound watermark is created by embedding a watermark (logo) into the statistical synthetic image by using a visible watermarking technique. This compound watermark is invisibly embedded into the important block of the host image. The authentication process involves extraction of the perceptive logo as well statistical testing for two-layer evidence. Results of the experimentation using standard benchmarks demonstrates the robustness and efficacy of the proposed watermarking approach. Ownership proof could be established under various hostile attacks. Saraju P. Mohanty, Bharat K. Bhargava |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2007 | Indexing Noncrashing Failures: A Dynamic Program Slicing-Based ApproachabstractRecent software systems usually feature an automated failure reporting component, with which a huge number of failures are collected from software end-users. With a proper support of failure indexing, which identifies failures due to the same fault, the collected failure data can help developers prioritize failure diagnosis, among other utilities of the failure data. Since crashing failures can be effectively indexed by program crashing venues, current practice has seen great success in prioritizing crashing failures. A recent study of bug characteristics indicates that as excellent memory checking tools are widely adopted, semantic bugs and the resulting noncrashing failures have become dominant. Unfortunately, the problem of how to index non-crashing failures has not been seriously studied before. In previous study, two techniques have been proposed to index noncrashing failures, and they are T-Proximity and R-Proximity. However, as T-Proximity indexes failures by the profile of the entire execution, it is generally not effective because most information in the profile is fault-irrelevant. On the other hand, although R-Proximity is more effective than T-Proximity, it relies on a sufficient number of correct executions that may not be available in practice. In this paper, we propose a dynamic slicing-based approach, which does not require any correct executions, and is comparably effective as R-Proximity. A detailed case study with gzip is reported, which clearly strates the advantages of the proposed approach. Chao Liu 0001, Xiangyu Zhang 0001, Yu Zhang 0188, Jiawei Han 0001, Bharat K. Bhargava |
ICSM | 5 |
| 2007 | On the Design of Perceptual MPEG-Video Encryption AlgorithmsabstractIn this paper, some existing perceptual encryption algorithms of MPEG videos are reviewed and some problems, especially security defects of two recently proposed MPEG-video perceptual encryption schemes, are pointed out. Then, a simpler and more effective design is suggested, which selectively encrypts fixed-length codewords in MPEG-video bit streams under the control of three perceptibility factors. The proposed design is actually an encryption configuration that can work with any stream cipher or block cipher. Compared with the previously-proposed schemes, the new design provides more useful features, such as strict size-preservation, on-the-fly encryption and multiple perceptibility, which make it possible to support more applications with different requirements. In addition, four different measures are suggested to provide better security against known/chosen-plaintext attacks. Shujun Li 0001, Guanrong Chen, Albert Cheung, Bharat K. Bhargava, Kwok-Tung Lo |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2006 | Performance evaluation of multiple-rate mobile ad hoc networks
Gang Ding, Xiaoxin Wu 0001, Bharat K. Bhargava |
Perform. Evaluation | 3 |
| 2006 | Tree-Based Data Broadcast in IEEE 802.15.4 and ZigBee NetworksabstractThis paper studies efficient and simple data broadcast in IEEE 802.15.4-based ad hoc networks (e.g., ZigBee). Since finding the minimum number of rebroadcast nodes in general ad hoc networks is NP-hard, current broadcast protocols either employ heuristic algorithms or assume extra knowledge such as position or two-hop neighbor table. However, the ZigBee network is characterized as low data rate and low cost. It cannot provide position or two-hop neighbor information, but it still requires an efficient broadcast algorithm that can reduce the number of rebroadcast nodes with limited computation complexity and storage space. To this end, this paper proposes self-pruning and forward node selection algorithms that exploit the hierarchical address space in ZigBee networks. Only one-hop neighbor information is needed; a partial list of two-hop neighbors is derived without exchanging messages between neighboring nodes. The ZigBee forward node selection algorithm finds the minimum rebroadcast nodes set with polynomial computation time and memory space. Using the proposed localized algorithms, it is proven that the entire network is covered. Simulations are conducted to evaluate the performance improvement in terms of the number of rebroadcast nodes, number of duplicated receivings, coverage time, and communication overhead. Gang Ding, Zafer Sahinoglu, Philip V. Orlik, Jinyun Zhang, Bharat K. Bhargava |
IEEE Trans. Mob. Comput. | 5 |
| 2006 | A scheme for privacy-preserving data disseminationabstractAn adequate level of trust must be established between prospective partners before an interaction can begin. In asymmetric trust relationships, one of the interacting partners is stronger. The weaker partner can gain a higher level of trust by disclosing private information. Dissemination of sensitive data owned by the weaker partner starts at this moment. The stronger partner can propagate data to others, who may then choose to spread data further. The proposed scheme for privacy-preserving data dissemination enables control of data by their owner (such as a weaker partner). It relies on the ideas of bundling sensitive data with metadata, an apoptosis of endangered bundles, and an adaptive evaporation of bundles in suspect environments. Possible applications include interactions among patients and healthcare providers, customers and businesses, researchers, and suppliers of their raw data. They will contribute to providing privacy guarantees, which are indispensable for the realization of the promise of pervasive computing Leszek Lilien, Bharat K. Bhargava |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2006 | Trust-based privacy preservation for peer-to-peer data sharingabstractPrivacy preservation in a peer-to-peer (P2P) system tries to hide the association between the identity of a participant and the data that it is interested in. This paper proposes a trust-based privacy-preservation method for P2P data sharing. It adopts the trust relation between a peer and its collaborators (buddies). The buddy works as a proxy to send the request and acquire the data. This provides a shield under which the identity of the requester and the accessed data cannot be linked. A privacy measuring method is presented to evaluate the proposed mechanism. Dynamic trust assessment and the enhancement to supplier's privacy are discussed Yi Lu 0013, Weichao Wang, Bharat K. Bhargava, Dongyan Xu |
IEEE Trans. Syst. Man Cybern. Part A | 3 |
| 2006 | A crossing-tier location update/paging scheme in hierarchical cellular networksabstractLocation update/paging strategies have been widely studied in the traditional single-tier cellular networks. We propose and evaluate a novel crossing-tier location update/paging scheme that can be used in a hierarchical macrocell/microcell cellular network. Location update is proceeded only in the macrocell tier, where a location area (LA) is made up by larger macrocells. A mobile user will stay in such a LA for longer time. Therefore, the cost on location update can be reduced due to the decreased frequency of location update. To reduce the paging delay, the paged mobile user will be searched in the macrocell tier only when the paging load is not high. Otherwise, it will be searched in the microcell tier, where a sequential searching method is applied. The operation for the scheme is simple, as the macrocell/microcell cellular network has the advantage because a mobile user can receive a signal from both a microcell and the overlaid macrocell. Analytical models have been built for cost and delay evaluation. Numerical results show that, at relatively low cost, the crossing-tier scheme also achieves low paging delay. Xiaoxin Wu 0001, Biswanath Mukherjee, Bharat K. Bhargava |
IEEE Trans. Wirel. Commun. | 3 |
| 2006 | Defending against wormhole attacks in mobile ad hoc networksabstractAbstract In ad hoc networks, malicious nodes can deploy wormhole attacks to fabricate a false scenario on the proximity relationship among mobile nodes. A classification of the attacks according to the format of the wormholes is proposed. This forms a basis to identify the detection capability of various approaches. An analysis shows that earlier approaches focus on the prevention of wormholes among neighbors that trust each other. As a more generic approach, we present an end‐to‐end scheme that can detect wormholes on a multi‐hop route. Only the trust between the source and the destination is assumed. The mechanism uses geographic information to detect anomalies in neighbor relations and node movements. To reduce the computation and storage overhead, we present a scheme called cell‐based open tunnel avoidance (COTA) to manage the information. COTA requires a constant space for every node on the path and the computation overhead increases linearly to the number of detection packets. We prove that the savings do not deteriorate the detection capability. Various schemes to control communication overhead are studied. The simulation and experiments on real devices show that the proposed mechanism can be combined with existent routing protocols to defend against wormhole attacks. Copyright © 2006 John Wiley & Sons, Ltd. Weichao Wang, Bharat K. Bhargava, Yi Lu 0013, Xiaoxin Wu 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2005 | Reliable broadcast in ZigBee networksabstractDue to scarce resources, such as transmission power, storage space and communication bandwidth, current broadcast approaches for general ad hoc networks can not be applied to IEEE 802.15.4 based ad hoc networks (e.g., ZigBee networks). This paper proposes a forward node selection algorithm that significantly reduces broadcast redundancy. The algorithm exploits the hierarchical address space in ZigBee networks. Only one-hop neighbor information is needed: a partial list of two-hop neighbors is derived at a node without exchanging messages between neighboring nodes. The complexity of the proposed algorithm is polynomial in terms of both computation time and memory space. The localized algorithm provides an optimal and feasible solution of selecting the minimum number of rebroadcast nodes in ZigBee networks, which is an NP-hard problem for general ad hoc networks. The proposed algorithm is extended to deal with packet loss during data transmission. A ZigBee rebroadcast algorithm is also proposed to further reduce the number of rebroadcast nodes and cover the whole network faster by assigning a non-random rebroadcast timer determined by the number of neighbors to be covered, distance and link quality. Simulations are conducted to evaluate the broadcast redundancy, coverage time, and coverage ratio. Gang Ding, Zafer Sahinoglu, Bharat K. Bhargava, Philip V. Orlik, Jinyun Zhang |
SECON | 3 |
| 2005 | Multimedia data transmission and control using active networks
Bharat K. Bhargava, Sheng-Yih Wang, Maleq Khan, Ahsan Habib 0001 |
Comput. Commun. | 1 |
| 2005 | Counteracting shill bidding in online english auctionabstractThe popularity of online auctions and the associated frauds have led to many auction sites preferring English auction over other auction mechanisms. The ease of adopting multiple fake identities over the Internet nourishes shill bidding by fraudulent sellers in English auction. In this paper, we derive an equilibrium bidding strategy to counteract shill bidding in an online English auction. An algorithm based on this strategy is developed. We conduct experiments to evaluate the strategy in a simulated eBay like auction environment. Five popular bidding strategies are compared with the proposed one. In the simulation, bidders compete to buy a product in the presence of a shill. Each bidder is randomly assigned a bidding strategy. She draws her valuation from a uniform distribution. The experiments show hat the average expected utility of agents with proposed strategy is the highest when the auction continues for a longer duration. Bharat K. Bhargava, Mamata Jenamani, Yuhui Zhong |
Int. J. Cooperative Inf. Syst. | 1 |
| 2005 | CollectCast: A peer-to-peer service for media streaming
Mohamed Hefeeda, Ahsan Habib 0001, Dongyan Xu, Bharat K. Bhargava, Boyan Botev |
Multim. Syst. | 4 |
| 2005 | A Tree-Based Forward Digest Protocol to Verify Data Integrity in Distributed Media StreamingabstractWe design a tree-based forward digest protocol (TFDP) to verify data integrity in distributed media streaming for content distribution. Several challenges arise, including the timing constraint of streaming sessions, the involvement of multiple senders, and the untrustworthiness of these senders. A comprehensive comparison is presented on the performance of existing protocols and TFDP, with respect to communication and computation overhead. Both simulation and Internet-based experimental results are presented to demonstrate the effectiveness of TFDP. Ahsan Habib 0001, Dongyan Xu, Mikhail J. Atallah, Bharat K. Bhargava, John C.-I. Chuang |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2005 | AO2P: Ad Hoc On-Demand Position-Based Private Routing ProtocolabstractPrivacy is needed in ad hoc networks. An ad hoc on-demand position-based private routing algorithm, called AO2P, is proposed for communication anonymity. Only the position of the destination is exposed in the network for route discovery. To discover routes with the limited routing information, a receiver contention scheme is designed for determining the next hop. Pseudo identifiers are used for data packet delivery after a route is established. Real identities (IDs) for the source nodes, the destination nodes, and the forwarding nodes in the end-to-end connections are kept private. Anonymity for a destination relies on the difficulty of matching a geographic position to a real node ID. This can be enforced by the use of secure position service systems. Node mobility enhances destination anonymity by making the match of a node ID with a position momentary. To further improve destination privacy, R-AO2P is proposed. In this protocol, the position of a reference point, instead of the position of the destination, is used for route discovery. Analytical models are developed for evaluating the delay in route discovery and the probability of route discovery failure. A simulator based on ns-2 is developed for evaluating network throughput. Analysis and simulation results show that, while AO2P preserves communication privacy in ad hoc networks, its routing performance is comparable with other position-based routing algorithms. Xiaoxin Wu 0001, Bharat K. Bhargava |
IEEE Trans. Mob. Comput. | 2 |
| 2004 | Anonymizing Web Services through a Club Mechanism with Economic IncentivesabstractPreserving privacy during Web transactions is a major concern for individuals and organizations. One of the solutions proposed in the literature is to maintain anonymity through group cooperation during Web transactions. The lack of understanding of incentives for encouraging group cooperation is a major drawback in such systems. We propose an anonymizing club mechanism, and sequential economic strategy for trusted collaboration. We model the individual transactions as a Prisoners' Dilemma, where two players either cooperate or defect while maintaining each other's anonymity. The activities of the participants over a series of transactions can be modeled as a sequential repeated game. We determine conditions to ensure cooperation among the participants in the sequential repeated game, even if defecting is a dominant strategy in each individual Prisoners' Dilemma game. Our results show that by adopting an appropriate initiation fee and adequate fine for malicious behavior, both enforced through a trusted central authority, we can sustain cooperation in the proposed anonymizing club mechanism. Mamata Jenamani, Leszek Lilien, Bharat K. Bhargava |
ICWS | 3 |
| 2004 | Edge-to-edge measurement-based distributed network monitoring
Ahsan Habib 0001, Maleq Khan, Bharat K. Bhargava |
Comput. Networks | 3 |
| 2004 | A hybrid architecture for cost-effective on-demand media streaming
Mohamed Hefeeda, Bharat K. Bhargava, David K. Y. Yau |
Comput. Networks | 2 |
| 2004 | Integrating Heterogeneous Wireless Technologies: A Cellular Aided Mobile Ad Hoc Network (CAMA)
Bharat K. Bhargava, Xiaoxin Wu 0001, Yi Lu 0013, Weichao Wang |
Mob. Networks Appl. | 1 |
| 2004 | MPEG Video Encryption Algorithms
Bharat K. Bhargava, Changgui Shi, Sheng-Yih Wang |
Multim. Tools Appl. | 1 |
| 2003 | Fraud Formalization and Detection
Bharat K. Bhargava, Yuhui Zhong, Yunhua Lu |
DaWaK | 1 |
| 2003 | GnuStream: a P2P media streaming system prototypeabstractWe present the design and prototype of GnuStream, a peer- to-peer (P2P) and receiver-driven media streaming system. GnuStream is built on top of Gnutella, and it integrates dynamic peer location and streaming capacity aggregation. Each GnuStream streaming session is controlled by the receiver peer and involves a dynamic set of peer senders instead of one fixed sender. The receiver aggregates streaming bandwidth from the multiple senders, achieving load distribution and fast reaction to sender capacity and on/off-line status changes. The effectiveness of GnuStream is demonstrated by our experiments with its prototype, which serves as the basis for real-world development and evaluation of resilient P2P media streaming services. Xuxian Jiang, Dongyan Xu, Bharat K. Bhargava |
ICME | 4 |
| 2003 | PROMISE: peer-to-peer media streaming using CollectCastabstractWe present the design, implementation, and evaluation of PROMISE, a novel peer-to-peer media streaming system encompassing the key functions of peer lookup, peer-based aggregated streaming, and dynamic adaptations to network and peer conditions. Particularly, PROMISE is based on a new application level P2P service called CollectCast. CollectCast performs three main functions: (1) inferring and leveraging the underlying network topology and performance information for the selection of senders; (2) monitoring the status of peers and connections and reacting to peer/connection failure or degradation with low overhead; (3) dynamically switching active senders and standby senders, so that the collective network performance out of the active senders remains satisfactory. Based on both real-world measurement and simulation, we evaluate the performance of PROMISE, and discuss lessons learned from our experience with respect to the practicality and further optimization of PROMISE. Mohamed Hefeeda, Ahsan Habib 0001, Boyan Botev, Dongyan Xu, Bharat K. Bhargava |
ACM Multimedia | 5 |
| 2003 | Detecting Service Violations and DoS Attacks
Ahsan Habib 0001, Mohamed Hefeeda, Bharat K. Bhargava |
NDSS | 3 |
| 2003 | Study of Distance Vector Routing Protocols for Mobile Ad Hoc NetworksabstractWe investigate the performance issues of destination-sequenced distance vector (DSDV) and ad-hoc on-demand distance vector (AODV) routing protocols for mobile ad hoc networks. Four performance metrics are measured by varying the maximum speed of mobile hosts, the number of connections, and the network size. The correlation between network topology change and mobility is investigated by using linear regression analysis. The simulation results indicate that AODV outperforms DSDV in less stressful situations, while DSDV is more scalable with respect to the network size. It is observed that network congestion is the dominant reason for packet drop for both protocols. We propose a new routing protocol, congestion-aware distance vector (CADV), to address the congestion issues. CADV outperforms AODV in delivery ratio by about 5%, while introduces less protocol load. The result demonstrates that integrating congestion avoidance mechanisms with proactive routing protocols is a promising way to improve performance. Yi Lu 0013, Weichao Wang, Yuhui Zhong, Bharat K. Bhargava |
PerCom | 4 |
| 2003 | On Security Study of Two Distance Vector Routing Protocols or Mobile Ad Hoc NetworksabstractThis paper compares the security properties of ad hoc on-demand distance vector (AODV) and destination sequence distance vector (DSDV) protocols, especially the difference caused by on-demand and proactive route queries. The on-demand route query enables the malicious host to conduct real time attacks on AODV. The communication overhead of attacks on DSDV is independent of the attack methods and the width of attack targets. A single false route propagates slower in AODV than in DSDV. The detection of false destination sequence in AODV heavily depends on the mobility of hosts. False distance vector and false destination sequence attacks are studied by simulation. The delivery ratio, communication overhead, and the propagation of false routes are measured by varying the traffic load and the maximum speed of host movement. The anomalous patterns of sequence numbers detected by destination hosts can be applied to detect the false destination sequence attacks. Weichao Wang, Yi Lu 0013, Bharat K. Bhargava |
PerCom | 3 |
| 2003 | On detecting service violations and bandwidth theft in QoS network domains
Ahsan Habib 0001, Sonia Fahmy, Srinivas R. Avasarala, Venkatesh Prabhakar, Bharat K. Bhargava |
Comput. Commun. | 5 |
| 2002 | PartJoin: An Efficient Storage and Query Execution for Data Warehouses
Ladjel Bellatreche, Michel Schneider, Mukesh K. Mohania, Bharat K. Bhargava |
DaWaK | 4 |
| 2002 | Authorization Based on Evidence and Trust
Bharat K. Bhargava, Yuhui Zhong |
DaWaK | 1 |
| 2002 | An Algorithm for Building User-Role Profiles in a Trust Environment
Evimaria Terzi, Yuhui Zhong, Bharat K. Bhargava, Pankaj, Sanjay Madria |
DaWaK | 3 |
| 2002 | A round trip time and time-out aware traffic conditioner for differentiated services networksabstractTCP connection throughput is inversely proportional to the connection round trip time (RTT). To mitigate TCP bias to short RTT connections, a differentiated services traffic conditioner can ensure connections with long RTTs do not starve when connections with short RTTs get all extra resources after achieving the target rates. Current proposals for RTT-aware conditioners work well for a small number of connections when most TCP connections are in the congestion avoidance phase. If there is a large number of TCP connections, however, connections time-out and go to slow start. We show that current RTT-aware conditioners over-protect long RTT flows and starve short RTT flows in this case. We design and evaluate a conditioner based on RTT as well as the retransmission time-out (RTO). The proposed RTT-RTO aware traffic conditioner works well for realistic situations with a large number of connections. Simulation results in a variety of situations confirm that the conditioner mitigates RTT bias. Ahsan Habib 0001, Bharat K. Bhargava, Sonia Fahmy |
ICC | 2 |
| 2002 | On Peer-to-Peer Media StreamingabstractIn this paper, we study a peer-to-peer media streaming system with the following characteristics: (1) its streaming capacity grows dynamically; (2) peers do not exhibit server-like behavior; (3) peers are heterogeneous in their bandwidth contribution; and (4) each streaming session may involve multiple supplying peers. Based on these characteristics, we investigate two problems: (1) how to assign media data to multiple supplying peers in one streaming session and (2) how to quickly amplify the system's total streaming capacity. Our solution to the first problem is an optimal media data assignment algorithm OTS/sub p2p/, which results in minimum buffering delay in the consequent streaming session. Our solution to the second problem is a distributed differentiated admission control protocol DAC/sub p2p/. By differentiating between requesting peers with different outbound bandwidth, DAC/sub p2p/ achieves fast system capacity amplification; benefits all requesting peers in admission rate, waiting time, and buffering delay; and creates an incentive for peers to offer their truly available out-bound bandwidth. Dongyan Xu, Mohamed Hefeeda, Susanne E. Hambrusch, Bharat K. Bhargava |
ICDCS | 4 |
| 2002 | Virtual Routers: A Tool for Emulating IP RoutersabstractSetting up experimental networks of a sufficient size is a crucial element for the development of communication services. Unfortunately, the required equipment, like routers and hosts, is expensive and its availability is limited. On the other hand, simulations often lack interoperability to real systems and scalability, which limits the scope and the validity of their results. Therefore, an intermediate approach between these two alternatives that allows for setting up testbeds on a cluster of computers is needed. This paper presents an intermediate approach based on the emulation of IP routers and evaluates the concept. In a first set of experiments the impact of various parameters on the packet delay was investigated, while further experiments compare the performance of differentiated services run on the network emulator with the results obtained by the well known network simulator ns. Florian Baumgartner, Torsten Braun, Bharat K. Bhargava |
LCN | 3 |
| 2002 | Mobile data and transaction management
Sanjay Madria, Mukesh K. Mohania, Sourav S. Bhowmick, Bharat K. Bhargava |
Inf. Sci. | 4 |
| 2002 | Performance evaluation of linear hash structure model in a nested transaction environment
Malik Ayed Tubaishat, Sanjay Madria, Bharat K. Bhargava |
J. Syst. Softw. | 3 |
| 2002 | Guest Editorial: Quality of Service in Multimedia Networks
Bharat K. Bhargava |
Multim. Tools Appl. | 1 |
| 2002 | Heterogeneous CPU Services Using Differentiated Admission Control
David K. Y. Yau, Bharat K. Bhargava |
Multim. Tools Appl. | 2 |
| 2001 | Design and evaluation of an adaptive traffic conditioner for differentiated services networksabstractWe design and evaluate an adaptive traffic conditioner to improve application performance over the differentiated services assured forwarding behavior. The conditioner is adaptive because the marking algorithm changes based upon the current number of flows traversing through an edge router. If there are a small number of flows, the conditioner maintains and uses state information to intelligently protect critical TCP packets. On the other hand, if there are many flows going through the edge router, the conditioner only uses flow characteristics as indicated in the TCP packet headers to mark without requiring per flow state. Simulation results indicate that this adaptive conditioner improves throughput of data extensive applications like large FTP transfers, and achieves low packet delays and response times for Telnet and WWW traffic. Ahsan Habib 0001, Sonia Fahmy, Bharat K. Bhargava |
ICCCN | 3 |
| 2001 | Applying Fault-Tolerance Principles to Security ResearchabstractThere has been much focus on building secure distributed systems. The CERIAS center has been established at Purdue along with 14 other such centers in USA. We note that many of the ideas, concepts, algorithms being proposed in security have many common threads with reliability. We need to apply the science and engineering of reliability research to the research in security and vice versa. We briefly give some examples to illustrate the ideas. To increase reliability in distributed systems, the use of quorums allows the transactions to read and write replicas even if some replicas have failed or are unavailable. So the systems manage the replicas so that a forum can be formed in the presence of failures. To make systems secure against unauthorized access, one can use the reverse strategy of making it difficult to form quorums. All accesses require permission from a group of authorities who could coordinate to deny a yes majority vote. Anjali Bhargava, Bharat K. Bhargava |
SRDS | 2 |
| 2001 | A Transaction Model to Improve Data Availability in Mobile Computing
Sanjay Madria, Bharat K. Bhargava |
Distributed Parallel Databases | 2 |
| 2001 | Formalization and Proof of Correctness of the Crash Recovery Algorithm for an Open and Safe Nested Transaction ModelabstractIn this paper, we present, formalize and prove the correctness of recovery algorithm for our open and safe nested transaction model using I/O automaton model. Our nested transaction model uses the notion of a recovery point subtransaction in the nested transaction tree. It introduces a prewrite operation before each write operation to increase the potential concurrency. Our transaction model is termed as "open and safe" as prewrites allow early reads (before database writes on disk) without cascading aborts. The systems restart and buffer management operations are modelled as nested transactions to exploit possible concurrency during restart. Each non-access transaction, object, and the scheduler is modeled as I/O automaton. Each of these automata is specified with the help of some pre-and post-conditions. These pre-and post-conditions capture the operational semantics and the behavior of each automaton during recovery operations. Our proof technique makes use of assertional reasoning and provide many interesting invariant, thus gives a better understanding of our recovery algorithm. Sanjay Madria, S. N. Maheshwari, B. Chandra 0001, Bharat K. Bhargava |
Int. J. Cooperative Inf. Syst. | 4 |
| 2001 | Global Scheduling for Flexible Transactions in Heterogeneous Distributed Database SystemsabstractA heterogeneous distributed database environment integrates a set of autonomous database systems to provide global database functions. A flexible transaction approach has been proposed for the heterogeneous distributed database environments. In such an environment, flexible transactions can increase the failure resilience of global transactions by allowing alternate (but in some sense equivalent) executions to be attempted when a local database system fails or some subtransactions of the global transaction abort. We study the impact of compensation, retry, and switching to alternative executions on global concurrency control for the execution of flexible transactions. We propose a new concurrency control criterion for the execution of flexible and local transactions, termed F-serializability, in the error-prone heterogeneous distributed database environments. We then present a scheduling protocol that ensures F-serializability on global schedules. We also demonstrate that this scheduler avoids unnecessary aborts and compensation. Aidong Zhang 0001, Marian H. Nodine, Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2000 | Security in Data Warehousing
Bharat K. Bhargava |
DaWaK | 1 |
| 2000 | An adaptable constrained locking protocol for high data contention environments: correctness and performance
Shalab Goel, Bharat K. Bhargava, Sanjay Madria |
Inf. Softw. Technol. | 2 |
| 2000 | Multi-level transaction model for semantic concurrency control in linear hash structures
Sanjay Madria, Malik Ayed Tubaishat, Bharat K. Bhargava |
Inf. Softw. Technol. | 3 |
| 2000 | An open and safe nested transaction model: concurrency and recovery
Sanjay Madria, S. N. Maheshwari, B. Chandra 0001, Bharat K. Bhargava |
J. Syst. Softw. | 4 |
| 2000 | Guest Editorial: Digital Libraries and Multimedia
Bharat K. Bhargava |
Multim. Tools Appl. | 1 |
| 2000 | A Communication Framework for Digital Libraries
Bharat K. Bhargava, Melliyal Annamalai |
Multim. Tools Appl. | 1 |
| 2000 | Design and Analysis of an Integrated Checkpointing Recovery Scheme for Distributed ApplicationsabstractAn integrated checkpointing and recovery scheme which exploits the low latency and high coverage characteristics of a concurrent error detection scheme is presented. Message dependency, which is the main source of multistep rollback in distributed systems, is minimized by using a new message validation technique derived from the notion of concurrent error detection. The concept of a new global state matrix is introduced to track error checking and message dependency in a distributed system and assist in the recovery. The analytical model, algorithms and data structures to support an easy implementation of the new scheme are presented. The completeness and correctness of the algorithms are proved. A number of scenarios and illustrations that give the details of the analytical model are presented. The benefits of the integrated checkpointing scheme are quantified by means of simulation using an object-oriented test framework. Bina Ramamurthy, Shambhu J. Upadhyaya, Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2000 | Editorial
Sanjay Madria, Mukesh K. Mohania, Bharat K. Bhargava |
World Wide Web | 3 |
| 1999 | An Adaptable Constrained Locking Protocol for High Data Contention EnvironmentsabstractMultiversions of data are used in database systems to increase concurrency and to provide efficient recovery. Data versions improve the concurrency by allowing the concurrent execution of non-conflicting read-write lock requests on different versions of data in an arbitrary fashion. A transaction that accesses a data item version which is later diagnosed to lead to an incorrect execution, is aborted. This act is reminiscent of the validation phase in the optimistic concurrency control schemes. Various performance studies suggest that these schemes perform poorly in high data contention environments where the excessive transaction aborts result due to the failed validation. We propose an adaptable constrained two-version two-phase locking (C2V2PL) scheme in which these non-conflicting requests are allowed only in a constrained manner. C2V2PL schemes assume that a lock request failing to satisfy the specific constraints will lead to an incorrect execution and hence, must be either rejected or blocked. This eliminates the need for a separate validation phase. When the contention for data among the concurrent transactions is high, the C2V2PL scheduler in aggressive state rejects such lock requests. The deadlock free nature of C2V2PL scheduler adapts to the low data contention environments by accepting the lock requests that have failed the specific constraints but contrary to the assumption, will not lead to an incorrect execution. Thus improving the performance due to reduced transaction aborts in this conservative state. Shalab Goel, Bharat K. Bhargava, Sanjay Madria |
DASFAA | 2 |
| 1999 | Experiments in Adaptable and Secure Multimedia Database Systems (Invited Paper)
Bharat K. Bhargava, Shunge Li |
DEXA | 1 |
| 1999 | Design and Implementation of Linear Hash Algorithm in a Nested Transaction Environment
Sanjay Madria, Malik Ayed Tubaishat, Bharat K. Bhargava |
DEXA | 3 |
| 1999 | Concurrency Control in Database SystemsabstractIdeas that are used in the design, development, and performance of concurrency control mechanisms have been summarized. The locking, time-stamp, optimistic-based mechanisms are included. The ideas of validation in the optimistic approach are presented in some detail. The degree of concurrency and classes of serializability for various algorithms have been presented. Questions that relate arrival rate of transactions with degree of concurrency and performance have been briefly presented. Finally, several useful ideas for increasing concurrency have been summarized. They include flexible transactions, adaptability, prewrites, multidimensional time stamps, and relaxation of two-phase locking. Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1999 | Data Consistency in Intermittently Connected Distributed SystemsabstractMobile computing introduces a new form of distributed computation in which communication is most often intermittent, low-bandwidth, or expensive, thus providing only weak connectivity. We present a replication scheme tailored for such environments. Bounded inconsistency is defined by allowing controlled deviation among copies located at weakly connected sites. A dual database interface is proposed that in addition to read and write operations with the usual semantics supports weak read and write operations. In contrast to the usual read and write operations that read consistent values and perform permanent updates, weak operations access only local and potentially inconsistent copies and perform updates that are only conditionally committed. Exploiting weak operations supports disconnected operation since mobile clients can employ them to continue to operate even while disconnected. The extended database interface coupled with bounded inconsistency offers a flexible mechanism for adapting replica consistency to the networking conditions by appropriately balancing the use of weak and normal operations. Adjusting the degree of divergence among copies provides additional support for adaptivity. We present transaction-oriented correctness criteria for the proposed schemes, introduce corresponding serializability-based methods, and outline protocols for their implementation. Then, some practical examples of their applicability are provided. The performance of the scheme is evaluated for a range of networking conditions and varying percentages of weak transactions by using an analytical model developed for this purpose. Evaggelia Pitoura, Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1998 | On the Correctness of a Transaction Model for Mobile Computing
Sanjay Madria, Bharat K. Bhargava |
DEXA | 2 |
| 1998 | A Transaction Model for Mobile ComputingabstractWe introduce a prewrite operation before a write operation in a mobile transaction to improve data availability. A prewrite operation does not update the state of a data object but only makes visible the value that the data object will have after the commit of the transaction. Once the transaction has read all the values and declares all the prewrites, it can precommit at a mobile host. The remaining transaction's execution is shifted to the stationary host. Writes on a database consume both time and resources at the stationary host and are therefore delayed. A pre-committed transaction's prewrite values are made visible both at mobile and stationary hosts before the final commit of the transaction. This increases data availability during frequent disconnection common in mobile computing. Since the expensive part of the transaction execution is shifted to the stationary host, it reduces the computing expenses at the mobile host. Sanjay Madria, Bharat K. Bhargava |
IDEAS | 2 |
| 1998 | A Fast MPEG Video Encryption AlgorithmabstractMultimedia data secmity is important for multimedia commerce.Previous cryptography studies have focused on text data.The encryption algorithms devdoped to secure text data may not be suitable to multimedia applications becattse of large data sizes and real time constraint.For multimedia applications, light weight encryption algorithms are attractive.We present a novel MPEG Video Encryption Algorithm, called VEA The basic idea of VEA is to use a secret key randomly changing the sign bits of all of the DCT coefficients of MPEG video.VEA'S encryption effects are achieved by the IDCT during MPEG video decompression processing.VEA adds minimum overhead to MPEG codecj one Mm&e XOR operation to each none zero DCT coefficient.A software implementation of VEA is fast enough to meet the real time requirement of MPEG video applications.Our experimental results show that VEA achieves satisfying results.We believe that it can be used to secure video-on-demand, tideo conferencing and video email applications. Changgui Shi, Bharat K. Bhargava |
ACM Multimedia | 2 |
| 1998 | Design and Analysis of a Hardware-Assisted Checkpointing and Recovery Scheme for Distributed ApplicationsabstractA checkpointing and recovery scheme which exploits the low latency and high coverage characteristics of a hardware error detection scheme is presented. Message dependency which is the main source of multi-step rollback in distributed systems is minimized by using a new message validation technique derived from hardware-assisted error detection. The main contribution of this paper is the development of an analytical model to establish the completeness and correctness of the new scheme. A novel concept of global state matrix is defined to keep track of the global state in a distributed system and assist in recovery. An illustration is given to show the distinction between conventional and the new recovery schemes. Bina Ramamurthy, Shambhu J. Upadhyaya, Bharat K. Bhargava |
SRDS | 3 |
| 1998 | An Efficient MPEG Video Encryption AlgorithmabstractMultimedia data security is important for multimedia commerce. Previous cryptography studies have focused on text data. The encryption algorithms developed to secure text data may not be suitable to multimedia applications because of large data sizes and real time constraints. For multimedia applications, light weight encryption algorithms are attractive. We present an efficient MPEG video encryption algorithm. This algorithm uses a secret key randomly changing the sign bits of encoded differential values of DC coefficients of I pictures and the sign bits of encoded differential values of motion vectors of B and P pictures. The encryption effects are achieved by the IDCT during MPEG video decompression processing. This algorithm adds very small overhead to MPEG codec. A software implementation is fast enough to meet the real time requirement of MPEG video applications. Experimental results show that this algorithm achieves satisfying results. We believe that it can be used to secure video-on-demand, video conferencing and video email applications. Changgui Shi, Bharat K. Bhargava |
SRDS | 2 |
| 1998 | A Fragmentation Scheme for Multimedia Traffic in Active NetworksabstractMultimedia data are usually very large. Fragmentation of multimedia data units is inevitable when they are transmitted through networks. Active networks are becoming popular, and active technologies are being applied to various interesting problems. When applying active technologies to multimedia data, however, the problem of fragmenting large packets still exists. Furthermore, new issues emerge when active capsules are fragmented. In this paper, we propose a new fragmentation scheme which addresses the unique needs of active networks and which utilizes the special properties of active networks. We propose an algorithm to fragment the data at the transport layer, which can minimize the overhead. Preliminary experimental results show that the scheme works well under realistic scenarios, with an overhead of less than 5%. Sheng-Yih Wang, Bharat K. Bhargava |
SRDS | 2 |
| 1997 | System Defined Prewrites for Increasing Concurrency in Databases
Sanjay Madria, Bharat K. Bhargava |
ADBIS | 2 |
| 1997 | Active Gateway: A Facility for Video Conferencing Traffic ControlabstractThe paper describes the authors' work of applying active network technology to videoconferencing (VC) research. They present the architecture and features of an application-level facility, called active gateway, for videoconferencing traffic and quality of service (QoS) control. It is shown through experiments that this facility enables more control functions that are not seen in conventional videoconferencing tools. Shunge Li, Bharat K. Bhargava |
COMPSAC | 2 |
| 1997 | Multi-pass Transmission Policy: An Effective Method of Transmitting Large Multimedia Objects in the Wide-Area NetworkabstractMultimedia objects such as audio, video and images are usually very large in size and often used in time critical applications. The traditional method of transmitting these large objects over a WAN is to use TCP because of the high loss rate of IP datagrams over a WAN. We propose a method called multi pass transmission policy (MpTP). The basic idea of MpTP consists of three things: sending small packets, selective retransmission requested by the receiver, and multi pass transmission. MpTP function by sending small packets and packets not received on the first pass are retransmitted on the second pass and so on till the required reliability is reached. We have conducted experiments on both MpTP and TCP, as well as proposing a formal model of MpTP to analyze the MpTP approach. Sheng-Yih Wang, Bharat K. Bhargava |
COMPSAC | 2 |
| 1997 | Crash Recovery in an Open and Safe Nested Transaction Model
Sanjay Madria, S. N. Maheshwari, B. Chandra 0001, Bharat K. Bhargava |
DEXA | 4 |
| 1997 | On Relaxing Serializability by Constraining Transaction Readsets
Evaggelia Pitoura, Aidong Zhang 0001, Bharat K. Bhargava |
Inf. Syst. | 3 |
| 1996 | A Colour-Based Technique for Measuring Visible Loss for Use in Image Data Communication
Melliyal Annamalai, Aurobindo Sundaram, Bharat K. Bhargava |
DEXA | 3 |
| 1995 | Communication Costs in Digital Library Databases
Bharat K. Bhargava, Melliyal Annamalai |
DEXA | 1 |
| 1995 | A Layered Architecture for Supporting Objects in a Relational System: A Performance Study
Bharat K. Bhargava, Shalab Goel |
DEXA | 1 |
| 1995 | Maintaining Consistency of Data in Mobile Distributed EnvironmentsabstractTo deal with the frequent, foreseeable and variable disconnections that occur in a mobile environment, we introduce a flexible, two-level consistency model. Semantically related or closely located data are grouped together to form a cluster. While all data inside a cluster are mutually consistent, degrees of inconsistency are allowed among data at different clusters. To take advantage of the predictability of disconnections, and to accommodate mobility, the cluster configuration is dynamic. We allow transactions to exhibit certain degrees of tolerance for inconsistencies by introducing strict and weak operations. Weak operations are operations that can be executed under weaker consistency requirements. We define correctness criteria for schedules that involve weak operations and compare them with traditional serializability criteria. Finally, we argue that our model is appropriate for a variety of other environments including very large databases and multidatabases. Evaggelia Pitoura, Bharat K. Bhargava |
ICDCS | 2 |
| 1995 | A View-Based Approach to Relaxing Global Serializability in a Multidatabase System (Abstract)abstractNo abstract available. Evaggelia Pitoura, Aidong Zhang 0001, Bharat K. Bhargava |
PODC | 3 |
| 1994 | Re-Evaluating Indexing Schemes for Nested ObjectsabstractPerformance is a major issue in the acceptance of object-oriented database management systems (OODBMS). The nested index and path index schemes have been criticized for their heavy costs and poor handling of update operations. This paper re-evaluates three index schemes (nested index, path index, and multi-index) applicable to queries on nested attributes. Among these, we found that a multi-index scheme is best supported in the object-oriented or extended relational DBMS environment. Multi-index schemes not only provide a better balance between retrieval and update costs than do the nested or path indices, but they also scale well for update when the number of indices increases. In this paper, we propose a multi-index design that reuses the single-table index structures already present in a DBMS. Our performance study extends previous models by permitting attributes to be multi-valued as well as single-valued. We also suggest that a combination of nested index and multi-index schemes offers a feasible solution to the support of queries on nested objects. Yin-he Jiang, Xiangning Liu, Bharat K. Bhargava |
CIKM | 3 |
| 1994 | Building Information Systems for Mobile EnvironmentsabstractIt is expected that in the near future, tens of millions of users will have access to distributed information systems through wireless connections. The technical characteristics of the wireless medium and the resulting mobility of both data resources and data consumers raise new challenging questions regarding the development of information systems appropriate for mobile environments. In this paper, we report on the development of such a system. First, we describe the general architecture of the information system and the main considerations of our design. Then, based on these considerations, we present our system support for maintaining the consistency of replicated data and for providing transaction schemas that account for the frequent but predictable disconnections, the mobility, and the vulnerability of the wireless environment. Evaggelia Pitoura, Bharat K. Bhargava |
CIKM | 2 |
| 1994 | Ensuring Relaxed Atomicity for Flexible Transactions in Multidatabase SystemsabstractGlobal transaction management requires cooperation from local sites to ensure the consistent and reliable execution of global transactions in a distributed database system. In a heterogeneous distributed database (or multidatabase) environment, various local sites make conflicting assertions of autonomy over the execution of global transactions. A flexible transaction model for the specification of global transactions makes it possible to deal robustly with these conflicting requirements. This paper presents an approach that preserves the semi-atomicity (a weaker form of atomicity) of flexible transactions, allowing local sites to autonomously maintain serializability and recoverability. We offer a fundamental characterization of the flexible transaction model and precisely define the semi-atomicity. We investigate the commit dependencies among the subtransactions of a flexible transaction. These dependencies are used to control the commitment order of the subtransactions. We next identify those restrictions that must be placed upon a flexible transaction to ensure the maintenance of its semi-atomicity. As atomicity is a restrictive criterion, semi-atomicity enhances the class of executable global transactions. Aidong Zhang 0001, Marian H. Nodine, Bharat K. Bhargava, Omran A. Bukhres |
SIGMOD Conference | 3 |
| 1994 | Multiple-Query Optimization at Algorithm-Level
Myong H. Kang, Henry G. Dietz, Bharat K. Bhargava |
Data Knowl. Eng. | 3 |
| 1993 | Efficient Availability Mechanisms in Distributed Databases SystemsabstractThe resiliency of distributed database systems can be realized through a collection of integrated faulttolerance mechanisms.These include clata replication techniques, failure detection, failure isolation through reconfiguration and adaptability, and non-blocking atomic commitment.Collectively, these mechanism enhance the availability and operability of the syste]n in the presence of various types of site and communication failures.In this paper, we focus on mechanisms for data replication, failure detection, and reconfiguration.We present the implementation details of each of these mechanisms along with their integration within the RAID system developed at Purdue.Data replication is implemented through the partial replication of data relations, and through the use of a library of replication control methods.An on-line replication control server (RC) provides highly available database operations through the adaptable use of these methods.Failuredetection isirriplementedvi aa reliable surveillance facility that rnonitorsthe changes in system connectivity.Such failures include site and communication failures as well as network partition.Repairs andnetwork merges are also detected by this facility, thus leading to the automatic initiation of recovery.We wilI show how failure isolation is achieved through data and server reconfiguration and by the adaptable use of replication methods. Bharat K. Bhargava, Abdelsalam Helal |
CIKM | 1 |
| 1993 | Performance Study on Supporting Objects in O-Raid Distributed Database SystemsabstractO-Raid [1, 2] uses a layered approach to provide support for objects on top of a distributed relational database system called RAID [3], It reuses the replication controller of RAID to allow replication of simple objects as well as replication of composite objects. In this paper, we first describe the experiments conducted on O-Raid that measure the overheads incurred in supporting objects through a layered implementation, and the overheads involved in replicating objects. The overheads are low (e.g. 4ms for an insert query involving objects). We present experiments that evaluate three replication strategies for composite objects, namely, full replication, selective replication and no replication in a two-site and a four-site O-Raid system. For composite object experiments, the selective replication strategy demonstrated the flexibility of tuning replication of member objects based on the patterns of access. The experimentation is performed in different networking environments (LANs and WANs) to further evaluate the replication schemes. The results indicate that selective replication scheme has greater benefits in WAN than in LAN. Jagannathan Srinivasan, Yin-he Jiang, Yongguang Zhang, Bharat K. Bhargava |
Int. J. Cooperative Inf. Syst. | 4 |
| 1991 | Experiences with Super, a Database Visual Environment
Annamaria Auddino, Eric Amiel, Bharat K. Bhargava |
DEXA | 3 |
| 1991 | Communication in the Raid Distributed Database System
Bharat K. Bhargava, Enrique Mafla, John Riedl |
Comput. Networks ISDN Syst. | 1 |
| 1990 | Supporting queries in the O-Raid object-oriented database systemabstractThe authors present the query language SQL++ used in the O-Raid object-oriented database system. SQL++ is an extension to the relational query language SQL that adds object-oriented capabilities. It supports object-oriented database capabilities such as subobject referencing, method invocation, navigational queries, and 'implicit joins' while maintaining the relational capabilities and closure property of SQL. SQL++ also has an application program interface that solves the 'impedance mismatch' problem for C++ application programs, allowing them to store and retrieve objects in the database without the need to translate from one data format to another.> James G. Mullen, Jagannathan Srinivasan, Prasun Dewan, Bharat K. Bhargava |
COMPSAC | 4 |
| 1990 | Experimental Evaluation of Concurrency Checkpointing and Rollback-Recovery AlgorithmsabstractThe performance of two distributed checkpointing and recovery algorithms, the synchronous checkpointing algorithm (SA) and the independent checkpointing algorithm (ICA), is evaluated. The performance is based on a detailed implementation of algorithms published earlier in the C language. A benchmark that simulates a variety of application requirements and considers variations in the number of processes running on one or more machines, size of processes to be checkpointed, size of control messages, and frequency of message exchanges for normal processing is used to conduct the experiments. Measurements are made for the elapsed time and the CPU time to run a single instance of the checkpoint or rollback. The experiments are repeated for various combinations of concurrent checkpoint and rollback executions. The messages needed for synchronization are computed. It is found that the time that a process spends in processing control messages contributes significantly to the elapsed time in both algorithms. Elapsed times for recovery for both algorithms are found to be comparable when the number of checkpoints is small.> Bharat K. Bhargava, Shy-Renn Lian, Pei-Jyun Leu |
ICDE | 1 |
| 1990 | Adaptility Experiments in the RAID Distributed Data Base SystemabstractA series of experiments is being conducted on the RAID distributed database system to study the performance and reliability implications of providing static and dynamic adaptability. The authors' studies of the cost of their adaptable implementation were conducted in the context of the concurrency controller and the replication controller. It is shown that adaptable implementations can be provided at costs comparable to those of special-purpose implementations. The experimentation with dynamic adaptability focuses on concurrency control. It is shown that dynamic adaptability can result in performance benefits and that system reconfiguration can be accomplished dynamically with less cost than stopping the system, performing reconfiguration, and then restarting the system. The authors' examination of the costs of providing greater data availability includes studying the replication control and atomicity control subsystems of RAID. The cost associated with increasing availability in an adaptable scheme of replication control and commit protocols is demonstrated.> Bharat K. Bhargava, Abdelsalam Helal, Karl Friesen, John Riedl |
SRDS | 1 |
| 1990 | Adaptable Recovery Using Dynamic Quorum Assignments
Bharat K. Bhargava, Shirley Browne |
VLDB | 1 |
| 1989 | A model for concurrent checkpointing and recovery using transactionsabstractConcurrent checkpointing and recovery using a concurrent transaction processing model which consists of four types of atomic operation and five types of conflict is developed. Each checkpoint/rollback transaction is executed by multiple processes in the system. They can be executed concurrently. It is shown that the consistency of recovery lines and rollback lines established by checkpoint transactions and rollback transactions can be achieved by enforcing serializability on the corresponding transactions. There are two advantages in using a transaction model for concurrent checkpointing and recovery: (1) it is easier to find algorithms to solve a transaction processing problem; and (2) based on this model, related issues of the two corresponding problems can be thought of uniformly. This model clarifies the concepts of concurrent checkpointing and recovery, and brings more ideas for designing algorithms.> Pei-Jyun Leu, Bharat K. Bhargava |
ICDCS | 2 |
| 1989 | Implementation and Measurements of Efficient Communication Facilities for Distributed Database SystemsabstractExperimentation with several methods of providing efficient communication facilities for distributed database systems is described. These studies give insight into the delays incurred by applications running on distributed systems. Five different mechanisms for local interprocess communications (two variations with message queues, named pipes, shared memory, and UDP sockets) have been implemented, compared, and analyzed. The most efficient of these is three times as fast as UDP for 1000-byte messages. Kernel-level software multicast and hardware multicast have also been implemented and their performance analyzed. The results show the significant advantage of using these techniques instead of using multiple sends and receives at the user level. The design of a facility that allows the dynamic addition of user-level protocols such as two-phase commit, clock synchronization, etc. to an operating system kernel is presented. The facility is based on a simple stack-based language that provides the functionality and security required.> Bharat K. Bhargava, Enrique Mafla, John Riedl, Bradley Sauder |
ICDE | 1 |
| 1989 | SETH: A Quorum-Based Database System for Experimentation with FailuresabstractThe behavior and performance of replica control protocols (RCP) that deal with network partitions is investigated using a quorum-based replicated database system called Seth. Seth is designed to be used as a transaction processing system, as well as a flexible experimentation tool. Seth's experimentation domain includes failures (site/link failure/repair rates), transactions (arrival rate, size, type, read/write ratio), quorum assignment, communications (communication protocols, network type, topology, number of sites), and transaction protocols (quorum-based RCPs, distributed commitment, concurrency control). The design and implementation of Seth are discussed, and two experiments are presented. The first studies the behavior of the quorum consensus protocol against different transition loads. The second experiment shows how expensive quorum-based replication is in terms of network traffic.> Abdelsalam Helal, Jagannathan Srinivasan, Bharat K. Bhargava |
ICDE | 3 |
| 1989 | A Model for Adaptable Systems for Transaction ProcessingabstractAdaptability is an essential tool for managing escalating software costs and to build high-reliability, high-performance systems. Algorithmic adaptability, which supports techniques for switching between classes of schedulers in distributed transaction systems, is modeled. RAID, an experimental system implemented to support experimentation in adaptability, is discussed. Adaptability features in RAID, including algorithmic adaptability, fault tolerance, and implementation techniques for an adaptable server-based design, are modeled.> Bharat K. Bhargava, John Riedl |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1989 | The Raid Distributed Database SystemabstractRaid, a robust and adaptable distributed database system for transaction processing, is described. Raid is a message-passing system, with server processes on each site. The servers manage concurrent processing, consistent replicated copies during site failures and atomic distributed commitment. A high-level, layered communications package provides a clean, location-independent interface between servers. The latest design of the communications package delivers messages via shared memory in a high-performance configuration in which several servers are linked into a single process. Raid provides the infrastructure to experimentally investigate various methods for supporting reliable distributed transaction processing. Measurements on transaction processing time and server CPU time are presented. Data and conclusions of experiments in three categories are also presented: communications software, consistent replicated copy control during site failures, and concurrent distributed checkpointing. A software tool for the evaluation of transaction processing algorithms in an operating system kernel is proposed.> Bharat K. Bhargava, John Riedl |
IEEE Trans. Software Eng. | 1 |
| 1988 | A Generic Algorithm for Transaction Processing During Network Partitioning
Bharat K. Bhargava, Shirley Browne |
FSTTCS | 1 |
| 1988 | An Experimental Analysis of Replicated Copy Control During Site Failure and RecoveryabstractThe authors examine the effect of failures on the consistency of replicated copies, measure the rate at which inconsistency can be removed, and measure the overheads associated with replicated copy control. They have extended the prototype system RAID to utilize the ideas of session numbers, nominal session vectors, fail-locks, and control transactions for replicated copy control. The authors discuss the results of three experiments. In the first experiment the authors measured the overhead for fail-locks maintenance, the overhead for copier transactions. In the second experiment they observed the effects of site failure on data availability. In the last experiment they examined the maintenance of consistency of replicated copies during site failure and recovery.> Bharat K. Bhargava, Paul Noll, Donna Sabo |
ICDE | 1 |
| 1988 | A Model for Adaptable Systems for Transaction ProcessingabstractA model is presented for an adaptable system that allows online switching of classes of algorithms for database transaction processing. The basic idea is to identify conditions on the state of processing that will maintain consistency during the switch from one class to another. The classes of concurrency control algorithms and the formalism of history for transaction processing and serializability have been used to develop this research. In addition to the formalism, the precise conditions for switching digraph-serializable (DSR) algorithms have been given. This research is being applied to switching network partition protocols (conservative to optimistic), commit protocols, recovery block software, and has led towards the design of an adaptable and reconfigurable distributed database system. An experimental system called RAID has been implemented to test these ideas; it has been noted that adaptability provides for varying performance requirements and deals with failures of sites, transactions, and other components of the system.> Bharat K. Bhargava, John Riedl |
ICDE | 1 |
| 1988 | Concurrent Robust Checkpointing and Recovery in Distributed SystemsabstractA checkpoint/rollback algorithm is presented for multiple processes in a distributed system that uses message passing for communication. Each process in the system can initiate the algorithm autonomously. If only one instance of the algorithm is being executed, the algorithm will force the minimal number of additional processes other than the initiator to make checkpoints (or roll back). The contributions of this research are as follows: (1) the concurrent execution of the algorithm for different global checkpointing instances and rollback instances initiated by several processes is allowed. Deadlocks or livelocks among different global checkpointing instances and rollback instances will not occur; (2) the algorithm is resilient to multiple process failures, and handles network partitioning in a pessimistic way, and (3) the algorithm does not require that messages be received in the order in which they are sent.> Pei-Jyun Leu, Bharat K. Bhargava |
ICDE | 2 |
| 1988 | Independent Checkpointing and Concurrent Rollback for Recovery in Distributed Systems - An Optimistic ApproachabstractA checkpoint algorithm is presented that benefits from the research in concurrency control, commit, and site recovery algorithms in transaction processing. In the authors' approach a number of checkpointing processes, a number of rollback processes, and computations on operational processes can proceed concurrently while tolerating the failure of an arbitrary number of processes. Each process takes checkpoints independently. During recovery after a failure, a process invokes a two-phase rollback algorithm. It collects information about relevant message exchanges in the system in the first phase and uses it in the second phase to determine both the set of processes that must roll back and the set of checkpoints up to which rollback must occur. Concurrent rollbacks are completed in the order of the priorities of the recovering processes. The proposed solution is optimistic in the sense that it does well if failures are infrequent by minimizing overhead during normal processing.> Bharat K. Bhargava, Shy-Renn Lian |
SRDS | 1 |
| 1988 | Implementation of RAIDabstractRAID is a robust and adaptable distributed system for transaction processing. It is a message-passing system, with server processes on each site. A high-level, layered communications package provides a clean, location independent interface between servers. RAID processes concurrent updates and retrievals on multiple sites. The servers manage concurrent processing, consistent replicated copies during site failures or network partitionings, and atomic distributed commitment. The latest version of the communications package is able to deliver messages in a high-performance configuration in which several servers are linked into a single process. RAID provides the infrastructure to investigate experimentally various methods for supporting reliable distributed-transaction processing. Experiments on handling site failure with partial replication, checkpointing, and alternative communications methods have been performed. Measurements on various aspects of RAID transaction processing performance are presented.> Bharat K. Bhargava, John Riedl |
SRDS | 1 |
| 1988 | A Dynamic majority determination algorithm for reconfiguration of network partitions
Bharat K. Bhargava, Peter Lei Ng |
Inf. Sci. | 1 |
| 1988 | Clarification of Two Phase Locking in Concurrent Transaction ProcessingabstractThe authors propose a formal definition of the two-phase locking class derived from the semantic description of the two-phase locking protocol, and prove that this definition is equivalent to that given by C.H. Papadimitriou (1979). They present: (1) a precise definition of the two phase locking; (2) a clarification of the occurrence and the order of all events such as lock points, unlock points, read operations, and write operations of conflicting transactions; and (3) by relaxing some conditions in the given definition, the derivation of a new class called restricted-non-two-phase locking (RN2PL), which is a superset of the class two-phase locking (2PL) but a subset of the class D-serializable (DSR) given by Papadimitriou.> Pei-Jyun Leu, Bharat K. Bhargava |
IEEE Trans. Software Eng. | 2 |
| 1987 | Multidimensional Timestamp Protocols for Concurrency ControlabstractWe propose multidimensional timestamp protocols for concurrency control in database systems where each transaction is assigned a timestamp vector containing multiple elements. The timestamp vectors for two transactions can be equal if timestamp elements are assigned the same values. The serializability order among the transactions is determined by a topological sort of the corresponding timestamp vectors. The timestamp in our protocols is assigned dynamically and is not just based on the starting/finishing time as in conservative and optimistic timestamp methods. The concurrency control can be enforced based on more precise dependency information derived dynamically from the operations of the transactions. Several classes of logs have been identified based on the degree of concurrency or the number of logs accepted by a concurrency controller. The class recognized by our protocols is within D-serializable (DSR), and is different from all previously known classes such as two phase locking (2PL), strictly serializable (SSR), timestamp ordering (TO), which have been defined in literature. The protocols have been analyzed to study the complexity of recognition of logs. We briefly discuss the implementation of the concurrency control algorithm for the new class, and give a timestamp vector processing mechanism. The extension of the protocols for nested transaction and distributed database models has also been included. Pei-Jyun Leu, Bharat K. Bhargava |
IEEE Trans. Software Eng. | 2 |
| 1986 | Site Recovery in Replicated Distributed Database Systems
Bharat K. Bhargava, Zuwang Ruan |
ICDCS | 1 |
| 1986 | Multidimensional Timestamp Protocols for Concurrency ControlabstractWe propose multidimensional timestamp protocols where each transaction has a timestamp vector of multiple elements. The timestamp vectors need not be distinct but do define a partial order. The serializability order among the transactions is determined by any topological sort of their timestamp vectors. The timestamp in our protocols is constructed dynamically, not just based on the starting/finishing time as in conservative and optimistic timestamp methods, and thus the concurrency control can be enforced based on more precise dependency information derived from the operations of the transactions. Several classes of logs have been identified based on the degree of concurrency which represents the number of logs accepted by a concurrency controller [12]. The class for our protocols is different from any previously known classes such as two phase locking (2PL), D-serializable (DSR), strictly serializable (SSR), timestamp ordering (TO), which have been defined in [5, 9, 12, 13]. If the dimension of the timestamp vector is one, then our protocols recognize the class timestamp ordering (TO). We will briefly discuss the implementation of the concurrency control algorithm for the new class. Pei-Jyun Leu, Bharat K. Bhargava |
ICDE | 2 |
| 1985 | Reliability in Distributed Database Systems (Panel)abstractarticle Reliability in distributed database systems (panel discussion) Share on Chairman: Bharat Bhargava Department of Computer Sciences, Purdue University, W Lafayette, Indiana Department of Computer Sciences, Purdue University, W Lafayette, IndianaView Profile Authors Info & Claims ACM SIGMOD RecordVolume 14Issue 4May 1985 pp 420–422https://doi.org/10.1145/971699.318992Online:01 May 1985Publication History 0citation263DownloadsMetricsTotal Citations0Total Downloads263Last 12 Months5Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Bharat K. Bhargava |
SIGMOD Conference | 1 |
| 1985 | Database Integrity Block Construct: Concepts and Design IssuesabstractWhen a crash occurs in a transaction processing system, the database can enter an unacceptable state. To continue the processing, the recovery system has three tasks: 1) verification of the database state for acceptability, 2) restoration of an acceptable database state, and 3) restoration of an acceptable history of transaction processing. Unfortunately these tasks are not trivial and the computational complexity of the algorithms for most of them is either NP-complete or NP-hard. In this paper we discuss the concepts and design issues of a construct called database integrity block (DIB). The implementation of this construct allows for efficient verification of the database state by employing a set of integrity assertions and restoration of transaction history by utilizing any database restoration technique such as audit trail or differential file. This paper presents approximation algorithms for minimizing the costs of evaluation of integrity assertions by modeling the problem as the directed traveling salesman problem, and presents a methodology to compare the costs of audit trail and differential file techniques for database restoration. The applicability of integrity verification research to the problem of multiple-query optimization is also included. Leszek Lilien, Bharat K. Bhargava |
IEEE Trans. Software Eng. | 2 |
| 1984 | Performance evaluation of reliability control algorithms for distributed database systems
Bharat K. Bhargava |
J. Syst. Softw. | 1 |
| 1984 | A Scheme for Batch Verification of Integrity Assertions in a Database SystemabstractA database management system can ensure the semantic integrity of a database via an integrity control subsystem. A technique for implementation of such a subsystem is proposed. After a database is updated by transactions, its integrity must be verified by evaluation of a set of semantic integrity assertions. For evaluation of an integrity assertion a number of database pages need to be transferred from the secondary storage to the fast memory. Since certain pages may be required for evaluation of different integrity assertions, the order of the evaluation of the integrity assertions determines the total number of pages fetched from the secondary storage. Hence, the schedule for the evaluation determines the cost of the database verification process. We show that the search for an optimal schedule is an NP-hard problem. Four approximation algorithms that find suboptimal schedules are proposed. They are based on the utilization of intersections among sets of pages required for the evaluation of different integrity assertions. The theoretical worst case behaviors of these algorithms are studied. Finally, the algorithms are compared via a simulation study to a naive, random order verification approach. The methods proposed for minimizing the costs of the batch integrity verification also apply to other problems that can be abstracted to the directed traveling salesman optimization problem. For example, the methods are applicable to multiple to multiple-query optimization and to concurrency control via the predicate locks. Leszek Lilien, Bharat K. Bhargava |
IEEE Trans. Software Eng. | 2 |
| 1983 | Cost Analysis of Selected Database Restoration Techniques
Bharat K. Bhargava, Leszek Lilien |
ER | 1 |
| 1983 | Analysis of the Majority Consensus Concurrency Control Algorithm for Correctness and Performance Using the Event Ordering Approach
Cecil T. Hua, Bharat K. Bhargava |
INFOCOM | 2 |
| 1983 | A Causal Model for Analyzing Distributed Concurrency Control AlgorithmsabstractAn event order based model for specifying and analyzing concurrency control algorithms for distributed database systems has been presented. An expanded notion of history that includes the database access events as well as synchronization events is used to study the correctness, degree of concurrency, and other aspects of the algorithms such as deadlocks and reliability. The algorithms are mapped into serializable classes that have been defined based on the order of synchronization events such as lock points, commit point, arrival of a transaction, etc,. Bharat K. Bhargava, Cecil T. Hua |
IEEE Trans. Software Eng. | 1 |
| 1982 | Performance Evaluation of the Optimistic Approach to Distributed Database Systems and Its Comparison to Locking
Bharat K. Bhargava |
ICDCS | 1 |
| 1982 | Classes of Serializable Histories and Synchronization Algorithms in Distributed Database Systems
Cecil T. Hua, Bharat K. Bhargava |
ICDCS | 2 |
| 1982 | Guest Editorial: Reliability Issues in Distributed SystemsabstractTO provide continuity of operations in automated systems, we need to develop techniques that can make them reliable. Many systems such as used in space programs, air traffic control, nuclear plant monitors, ballistic missile defense, etc., demand robust operation. In the past, research efforts have focused on the design and implementation of distributed systems used in such applications. We foresee a need of research effort in the investigation of algorithms and system structures that make error/failure detection, reconfiguration, recovery, and restart of a system feasible with the least amount of interruptions. Bharat K. Bhargava |
IEEE Trans. Software Eng. | 1 |
| 1973 | Tree Systems for Syntactic Pattern RecognitionabstractAn approach of representing patterns by trees rather than by strings is described. A review of tree systems that include tree grammars, transformations, and mappings on trees and tree automata is briefly presented. The tree system is then applied to the problem of syntactic pattern recognition. Tree grammars are used for pattern description, and tree automata are used for classification. Illustrative examples include the application of the tree system to the classification of bubble chamber events and some English characters. King-Sun Fu, Bharat K. Bhargava |
IEEE Trans. Computers | 2 |