EDBT 2026 Demo / reviewers in the wild / expert
Ragib Hasan
dblp:h/RagibHasan
· DBLP profile ↗
68ranked-venue papers
13as first author
22since 2021 · last 2026
0000-0001-5248-8341ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 18 · 2 first-author · 3 since 2021Security and privacy · 13 · 6 first-authorComputer networks · 9 · 8 since 2021Software engineering, systems software and programming languages · 9 · 2 first-author · 3 since 2021Systems, architecture and hardware · 6 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-authorArtificial intelligence and machine learning · 2Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RESCUE: Real-Time Sensing and Computation for Safe Evacuation in BuildingsabstractDuring a building fire, occupants need to find an escape route free from smoke and fire hazards. However, fire and smoke can block signs and hallways that become impossible to navigate, making evacuation difficult. On the other hand, rescuers often lack real-time information about people’s locations, which increases rescue time as they manually search for survivors. To resolve this, we present RESCUE – an evacuation support system that pairs smartwall based hazard sensors with a lightweight mobile interface to deliver a live floor map and an up-to-date shortest safe route to the nearest stairs in buildings. We represent the building graph, which updates in real-time from smart wall embedded sensors. When the smart wall detects fire, smoke, or gas in a corridor segment, that segment is immediately blocked and excluded from routing. The occupant’s mobile app refreshes to display the shortest, safest route to the nearest stair/exit. Responders also view a live display of occupant locations from the app, enabling them to go directly to the correct floor and corridor, rather than checking every floor. We implemented a prototype on one floor of a campus building and simulated a five-floor deployment using the measured plan. Our RESCUE system reduced time to exit versus static signage by avoiding trial and error detours. These results indicate that real-time, sensor aware, map guided guidance improves both occupant self evacuation and responder effectiveness during building emergencies. Nasim Uddin, Ragib Hasan |
CCNC | 3 |
| 2026 | LLMAC: A Global and Explainable Access Control Framework with Large Language ModelabstractToday’s business organizations need access control systems that can handle complex, changing security requirements that go beyond what traditional methods can manage. Current approaches, such as Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and Discretionary Access Control (DAC), were designed for specific purposes. They cannot effectively manage the dynamic, situation-dependent workflows that modern systems require. In this research, we introduce LLMAC, a new unified approach using Large Language Models (LLMs) to combine these different access control methods into one comprehensive, understandable system. We used an extensive synthetic dataset that represents complex real-world scenarios, including policies for ownership verification, version management, workflow processes, and dynamic role separation. Using Mistral 7B, our trained LLM model achieved outstanding results with 98.5% accuracy, significantly outperforming traditional methods (RBAC: 14.5%, ABAC: 58.5%, DAC: 27.5%) while providing clear, human readable explanations for each decision. Performance testing shows that the system can be practically deployed with reasonable response times and computing resources. Sharif Noor Zisad, Ragib Hasan |
CCNC | 2 |
| 2026 | IPBAC: Interaction Provenance-Based Access Control for Secure and Privacy-Aware SystemsabstractInteraction provenance refers to the documentation of every action and interaction within a system, including detailed metadata such as the actor’s identity, the time the action occurred, and the surrounding context of the interaction [1] . This concept is important for understanding the history and origins of data and processes, providing a transparent and traceable record of all activities within a system specially privacy-aware systems. Sharif Noor Zisad, Ragib Hasan |
CCNC | 2 |
| 2026 | Provenance-Aware Trust Framework for Autonomous Vehicles: A Generative AI-Inspired Hybrid Approach for Decentralized Information Validation
N. M. Istiak Chowdhury, Mohammad Zakaria Haider, Mohammad Ashiqur Rahman, Ragib Hasan |
COMPSAC | 4 |
| 2026 | ABCD: Active Buildings with Computing, Distributed Sensing, and Secure Edge Collaboration for Autonomous Hazard Mitigation
Nasim Uddin, Ragib Hasan |
COMPSAC | 3 |
| 2026 | LabOrchestrator: An AI Framework for End-to-End Security in Medical Research Environments
Sharif Noor Zisad, Ragib Hasan |
COMPSAC | 2 |
| 2026 | LLM Based Policy Generation for IoMT Device Access Control: A Context-Aware Approach
Boniface M. Sindala, Joshua Agberebi, Alfredo L. Guzman, Ragib Hasan |
ICC | 4 |
| 2026 | ComplianceGPT: LLM-driven Context-Aware Agent for Automated Medical Data Privacy Compliance
Sharif Noor Zisad, Ragib Hasan |
ICC | 2 |
| 2022 | X-Fidence: Post-Pandemic Wellness By Density Monitoring with Privacy PreservationabstractThere is an increasing interest in crowd monitoring as we return to normal life after the Covid-19 pandemic. Some major obstacles to implementing a monitoring system are: privacy, scalability, and accuracy. Several entities have developed their own branded safety reassurance programs using the Internet of Things and sensors during the pandemic, and many cities are planning for the post-pandemic era. However, the lack of inclusiveness and the fear of personal information leakage often limit their usage. To this end, we developed X-Fidence, a real-time density monitoring system to avoid crowds which preserves user privacy. X-Fidence anonymously tracks visitors in certain places using Bluetooth technology. The system consists of a signal receiver module, a mobile application, and a monitoring server where the citywide current occupancy data syncs automatically. The mobile application provides density data in real-time and average historic crowds information that helps to make decisions more confidently. The X-Fidence mobile app warns residents if any area experiences more visitors than maximum safe capacity. We also present our results from an experiment to measure the feasibility and accuracy of the system. Raiful Hasan, Ragib Hasan |
CCNC | 2 |
| 2022 | Smart City Technology for Disaster Management: Demonstrating the Use of Bluetooth Low Energy (BLE) Beacons for Emergency Alert DisseminationabstractAlerts and warnings are intended to educate the public and keep them safe in an emergency or natural disaster. Historically, public alerts and warnings have been delivered mainly via broadcast media and roadside signage. However, deploying these signals is time-consuming and they may not be noticed by people who need them. With the increasing use of smart devices and other technological advancements, the nation’s alerting capabilities must be upgraded to target vulnerable sub-populations more effectively. An easy-to-deploy, automatic alert/warning system with no need for a line of sight would be useful. To this end, we developed Insight – an alerting system that detects signals from Bluetooth beacons indicating danger zones [1]. It requires no Internet or communication infrastructure and thus, it is robust to communications failures during catastrophes. Here, we demonstrate the use of the Insight mobile application and the underlying ad hoc Beacon infrastructure. Raiful Hasan, Ragib Hasan, Tanveer Islam |
CCNC | 2 |
| 2022 | An Interaction Provenance-based Trust Management Scheme For Connected VehiclesabstractConnected vehicles (CVs) have facilitated the development of intelligent transportation system that supports critical safety information sharing with minimum latency. However, CVs are vulnerable to different external and internal attacks. Though cryptographic techniques can mitigate external attacks, preventing internal attacks imposes challenges due to authorized but malicious entities. Thwarting internal attacks require identifying the trustworthiness of the participating vehicles. This paper proposes a trust management framework for CVs using interaction provenance that ensures privacy, considers both in-vehicle and vehicular network security incidents, and supports flexible security policies. For this purpose, we present an interaction provenance recording and trust management protocol. Different events are extracted from interaction provenance, and trustworthiness is calculated using fuzzy policies based on the events. Mohammad Aminul Hoque, Ragib Hasan |
CCNC | 2 |
| 2022 | BenchAV: A Security Benchmarking Framework for Autonomous DrivingabstractAutonomous vehicles (AVs) are capable of making driving decisions autonomously using multiple sensors and a complex autonomous driving (AD) software. However, AVs introduce numerous unique security challenges that have the potential to create safety consequences on the road. Security mechanisms require a benchmark suite and an evaluation framework to generate comparable results. Unfortunately, AVs lack a proper benchmarking framework to evaluate the attack and defense mechanisms and quantify the safety measures. This paper introduces BenchAV – a security benchmark suite and evaluation framework for AVs to address current limitations and pressing challenges of AD security. The benchmark suite contains 12 security and performance metrics, and an evaluation framework that automates the metric collection process using Carla simulator and Robot Operating System (ROS). Mohammad Aminul Hoque, Md. Mahmud Hossain, Ragib Hasan |
CCNC | 3 |
| 2022 | A Trust Management Framework for Connected Autonomous Vehicles Using Interaction ProvenanceabstractConnected autonomous vehicles (CAVs) have fostered the development of intelligent transportation systems that support critical safety information sharing with minimum latency and making driving decisions autonomously. However, the CAV environment is vulnerable to different external and internal attacks. Authorized but malicious entities which provide wrong information impose challenges in preventing internal attacks. An essential requirement for thwarting internal attacks is to identify the trustworthiness of the vehicles. This paper exploits interaction provenance to propose a trust management framework for CAVs that considers both in-vehicle and vehicular network security incidents, supports flexible security policies and ensures privacy. The framework contains an interaction provenance recording and trust management protocol that extracts events from interaction provenance and calculates trustworthiness using fuzzy policies based on the events. Simulation results show that the framework is effective and can be integrated with the CAV stack with minimal computation and communication overhead. Mohammad Aminul Hoque, Ragib Hasan |
ICC | 2 |
| 2022 | Pedestrian safety using the Internet of Things and sensors: Issues, challenges, and open problems
Raiful Hasan, Ragib Hasan |
Future Gener. Comput. Syst. | 2 |
| 2022 | Someone to Watch Over You: Using Bluetooth Beacons for Alerting Distracted PedestriansabstractIn the United States, an estimated 7,005 (crude rate 2.13) pedestrians were killed in traffic crashes in 2020, according to the Centers for Disease Control and Prevention (CDC). This statistic is currently increasing annually and research suggests that distraction by smartphones may be a primary reason for the increasing number of pedestrian injuries and deaths. Timely interruptions may alert inattentive pedestrians and prevent fatalities. To this end, we developed StreetBit, a Bluetooth beacon-based system that warns distracted pedestrians with a visual and/or audible interruption when they approach a potentially dangerous traffic intersection while distracted by their smartphones. We posit that by using StreetBit, we can educate distracted pedestrians and elicit behavioral change to reduce or remove smartphone-based distractions when they enter and cross roadways. To demonstrate the feasibility of StreetBit, we conducted a field study with 385 participants. Results show that the system demonstrates adequate feasibility and behavior change in response to the StreetBit program. Raiful Hasan, Mohammad Aminul Hoque, Yasser Karim, Russell Griffin, David C. Schwebel, Ragib Hasan |
IEEE Internet Things J. | 6 |
| 2022 | IoTaaS: Drone-Based Internet of Things as a Service Framework for Smart CitiesabstractThe Internet of Things (IoT) offers new services in the context of smart cities through digital devices embedded with sensing, computation, and communication capabilities. The IoT devices enhance the smart city vision by employing advanced communication and computation technologies for smart city administrations. The IoT-based smart city applications require many IoT devices and gateways to be deployed at different city points. Heterogeneous sensing devices, placing smart devices in a constrained or physically inaccessible area, and large urban areas to monitor together make IoT node deployment and sensing management tasks difficult, time-consuming, and expensive. Additionally, certain tasks may require smart devices to be deployed for a very short period of time to sense and report contextual information, making it economically infeasible to purchase the devices. In this regard, we propose a drone-based IoT as a Service (IoTaaS) framework that enables the dynamic provisioning or deployment of IoT devices using drones. IoTaaS allows IoT devices and gateways to be mounted on drones and provides a distributed cloud service by placing the IoT devices in an area according to the requirements specified by a user. We also provide an economic analysis for operating such drone-based IoT services. A proof-of-concept implementation of IoTaaS for smart agriculture and air pollution monitoring applications shows that IoTaaS can reduce setup costs and increase the usage of IoT devices. Mohammad Aminul Hoque, Md. Mahmud Hossain, Shahid Al Noor, S. M. Riazul Islam, Ragib Hasan |
IEEE Internet Things J. | 5 |
| 2022 | CATComp: A Compression-Aware Authorization Protocol for Resource-Efficient Communications in IoT NetworksabstractThe Internet of Things (IoT) devices exchange certificates and authorization tokens over the IEEE 802.15.4 radio medium that supports a maximum transmission unit (MTU) of 127 bytes. However, these credentials are significantly larger than the MTU and are, therefore, sent in a large number of fragments. As IoT devices are resource constrained and battery powered, there are considerable computations and communication overheads for fragment processing both on the sender and receiver devices, which limit their ability to serve real-time requests. Moreover, the fragment processing operations increase energy consumption by CPUs and radio transceivers, which results in shorter battery life. In this article, we propose CATComp—a compression-aware authorization protocol for constrained application protocol (CoAP) and datagram transport layer security (DTLS) that enables IoT devices to exchange small-sized certificates and capability tokens over the IEEE 802.15.4 media. CATComp introduces additional messages in the CoAP and DTLS handshakes that allow communicating devices to negotiate a compression method, which devices use to reduce the credentials’ sizes before sending them over an IEEE 802.15.4 link. The decrease in the size of the security materials minimizes the total number of packet fragments, communication overheads for fragment delivery, fragment processing delays, and energy consumption. As such, devices can respond to requests faster and have longer battery life. We implement a prototype of CATComp on Contiki-enabled RE-Mote IoT devices and provide a performance analysis of CATComp. The experimental results show that communication latency and energy consumption are reduced when CATComp is integrated with CoAP and DTLS. Md. Mahmud Hossain, Golam Kayas, Yasser Karim, Ragib Hasan, Jamie Payton, S. M. Riazul Islam |
IEEE Internet Things J. | 4 |
| 2021 | Towards a Threat Model and Security Analysis of Video Conferencing SystemsabstractVideo Conferencing has emerged as a new paradigm of communication in the age of COVID-19 pandemic. This technology is allowing us to have real-time interaction during the social distancing era. Even before the current crisis, it was increasingly commonplace for organizations to adopt a video conferencing tool. As people adopt video conferencing tools and access data with potentially less secure equipment and connections, meetings are becoming a target to cyber attackers. Enforcing appropriate security and privacy settings prevents attackers from exploiting the system. To design the video conferencing system's security and privacy model, an exhaustive threat model must be adopted. Threat modeling is a process of optimizing security by identifying objectives, vulnerabilities, and defining the plan to mitigate or prevent potential threats to the system. In this paper, we use the widely accepted STRIDE threat modeling technique to identify all possible risks to video conferencing tools and suggest mitigation strategies for creating a safe and secure system. Raiful Hasan, Ragib Hasan |
CCNC | 2 |
| 2021 | InSight: A Bluetooth Beacon-based Ad-hoc Emergency Alert System for Smart CitiesabstractThe purpose of alerts and warnings is to provide necessary information to the public that will lead to their safety in emergencies. The nation's alerting capabilities need to evolve and progress with the extensive use of smartphones, and newer technologies become available, especially to be more precisely targeted to sub-populations at risk. Historically, this has been a challenge as the delivery of alerts and warning messages to the public is primarily through broadcast media and signs. However, deploying such signs takes time and may not be visible to people imminent of natural hazards. Especially for road closing, marking hazards, emergency evacuation, etc., it would be beneficial to have an easy-to-deploy and automated alert/warning system that requires no line of sight. To this end, we have developed Insight - a Bluetooth beacon-based system that uses a smartphone application to sense signals from beacons marking hazard zones. The system does not require any Internet or communication infrastructure and therefore, it is resilient to breakdowns in communications during disasters. To demonstrate the feasibility of Insight, we conducted a study in an urban university campus location. The system demonstrated adequate usability and feasibility. Raiful Hasan, Ragib Hasan, Tanveer Islam |
CCNC | 2 |
| 2021 | StreetBit: A Bluetooth Beacon-based Personal Safety Application for Distracted PedestriansabstractThe safety of distracted pedestrians presents a significant public health challenge in the United States and worldwide. An estimated 6,704 American pedestrians died and over 200,000 pedestrians were injured in traffic crashes in 2018, according to the Centers for Disease Control and Prevention (CDC) [1]. This number is increasing annually and many researchers posit that distraction by smartphones is a primary reason for the increasing number of pedestrian injuries and deaths. One strategy to prevent pedestrian injuries and death is to use intrusive interruptions that warn distracted pedestrians directly on their smartphones. To this end, we developed StreetBit, a Bluetooth beacon-based mobile application that alerts distracted pedestrians with a visual and/or audio interruption when they are distracted by their smartphones and are approaching a potentially-dangerous traffic intersection. In this paper, we present the background, architecture, and operations of the StreetBit Application. Raiful Hasan, Mohammad Aminul Hoque, Yasser Karim, Russell Griffin, David C. Schwebel, Ragib Hasan |
CCNC | 6 |
| 2021 | AVGuard: A Forensic Investigation Framework for Autonomous VehiclesabstractAutonomous vehicles (AVs) rely on on-board sensors and computation capabilities to drive on the road with limited or no human intervention. However, autonomous driving decisions can go wrong for numerous reasons, leading to accidents on the road. The AVs lack a proper forensics investigation framework, which is essential for various reasons such as resolving insurance disputes, investigating attacks, compliance with autonomous driving safety guidelines, etc. To design robust and safe AVs, identifying the actual reason behind any incident involving the AV is crucial. Hence, it is essential to collect meaningful logs from different autonomous driving modules and store them in a secure and tamper-proof way. In this paper, we propose AVGuard, a forensic investigation framework that collects and stores the autonomous driving logs. The framework can generate and verify proofs to ensure the integrity of collected logs while preventing collusion attacks among multiple dishonest parties. The stored logs can be used later by investigators to identify the exact incident. Our proof-of-concept implementation shows that the framework can be integrated with autonomous driving modules efficiently without any significant overheads. Mohammad Aminul Hoque, Ragib Hasan |
ICC | 2 |
| 2021 | P-HIP: A Lightweight and Privacy-Aware Host Identity Protocol for Internet of ThingsabstractThe host identity protocol (HIP) has emerged as the most suitable solution to uniquely identify smart devices in the mobile and distributed Internet-of-Things (IoT) systems, such as smart cities, homes, cars, and healthcare. The HIP provides authentication methods that enable secure communications between HIP peers. However, the authentication methods provided by the HIP cannot be adopted by the IoT devices with limited processing power because of the computation-intensive cryptographic operations involved in hash generation, signature validation, and session-key establishment. Moreover, IoT devices cannot utilize the HIP as is to communicate securely in the low power and lossy networks as there is a considerable communication overhead, such as packet fragmentation and reassembly, for exchanging certificates over a lossy link. Additionally, the use of static host identifiers makes IoT devices vulnerable to cyber espionage and user-targeted attacks. In this article, we propose an authentication scheme, P-HIP, that protects the identity privacy of an IoT device by enabling the device to compute and use unique host identifiers from networks to networks and sessions to sessions. To make the HIP suitable for resource-constrained IoT devices, P-HIP provides methods that unburden IoT devices from computation-intensive operations, such as modular exponentiation, involved in authentication and session-key exchange. Additionally, P-HIP minimizes the communication overheads for exchanging certificates in lossy networks. We implement a prototype of P-HIP on Contiki-enabled IoT that shows P-HIP can reduce computation costs, communication overheads, and the session-key establishment time when used by low-powered devices in a lossy network. Md. Mahmud Hossain, Ragib Hasan |
IEEE Internet Things J. | 2 |
| 2018 | Smart bracelets: Towards automating personal safety using wearable smart jewelryabstractEnsuring personal safety and detecting physical assaults are critically important issues. During an assault, victims often have no time to call for help using their mobile phones. Most panic button type emergency call devices also require actively pressing a button to contact emergency services. The requirement of active intervention by the victim (through dialing 911 or pressing a button) reduces the effectiveness of the service for ensuring personal safety. To resolve this problem, we use the notion of a smart wearable device, in the form of a smart jewelry bracelet, to automatically sense, detect, and identify physical assault. The smart bracelet uses a multitude of sensors and machine learning to detect an assault as it takes place and then proceeds to contact emergency services and take a series of protective actions. In this demo, we will demonstrate the smart jewelry bracelet and show its usability and effectiveness in providing a low-cost, practical, and usable tool for preventing physical assault and attacks, as well as helping elderly users. Jayun Patel, Ragib Hasan |
CCNC | 2 |
| 2018 | SecuPAN: A Security Scheme to Mitigate Fragmentation-Based Network Attacks in 6LoWPANabstract6LoWPAN is a widely used protocol for communication over IPV6 Low-power Wireless Personal Area Networks. Unfortunately, the 6LoWPAN packet fragmentation mechanism possesses vulnerabilities that adversaries can exploit to perform network attacks. Lack of fragment authentication, payload integrity verification, and sender IP address validation lead to fabrication, duplication, and impersonation attacks. Moreover, adversaries can abuse the poor reassembly buffer management technique of the 6LoWPAN layer to perform buffer exhaustion and selective forwarding attacks. In this paper, we propose SecuPAN - a security scheme for mitigating fragmentation-based network attacks in 6LoWPAN networks and devices. We propose a Message Authentication Code based per-fragment integrity and authenticity verification scheme to defend against fabrication and duplication attacks. We also present a mechanism for computing datagram-tag and IPv6 address cryptographically to mitigate impersonation attacks. Additionally, our reputation-based buffer management scheme protects 6LoWPAN devices from buffer reservation attacks. We provide an extensive security analysis of SecuPAN to demonstrate that SecuPAN is secure against strong adversarial scenarios. We also implemented a prototype of SecuPAN on Contiki enabled IoT devices and provided a performance analysis of our proposed scheme. Md. Mahmud Hossain, Yasser Karim, Ragib Hasan |
CODASPY | 3 |
| 2018 | SECProv: Trustworthy and Efficient Provenance Management in the CloudabstractThe black-box nature of clouds introduces a lack of trusts in clouds. Since provenance can provide a complete history of an entity, trustworthy provenance management for data, application, or workflow can make the cloud more accountable. Current research on cloud provenance mainly focuses on collecting provenance records and trusting the cloud providers in managing the provenance records. However, a dishonest cloud provider can alter the provenance records, as the records are stored within the control of the cloud provider. To solve this problem, we first propose CloProv - a provenance model to capture the complete provenance of any type of entities in the cloud. We analyze the threats on the CloProv model considering collusion among malicious users and dishonest cloud providers. Based on the threat model, we propose a secure data provenance scheme - SECProv for cloud-based, multi-user, shared data storage systems. We integrate SECProv with the object storage module of an open source cloud framework - OpenStack Swift and analyze the efficiency of the proposed scheme. Shams Zawoad, Ragib Hasan, Mohammad Kamrul Islam |
INFOCOM | 2 |
| 2018 | Aura: An incentive-driven ad-hoc IoT cloud framework for proximal mobile computation offloading
Ragib Hasan, Md. Mahmud Hossain, Rasib Khan |
Future Gener. Comput. Syst. | 1 |
| 2018 | An Internet of Things-based health prescription assistant and its security system design
Md. Mahmud Hossain, S. M. Riazul Islam, Farman Ali 0001, Kyung Sup Kwak, Ragib Hasan |
Future Gener. Comput. Syst. | 5 |
| 2017 | Malware Secrets: De-Obfuscating in the CloudabstractMalicious software, universally known as malware, is typically used to cause disruption as it tries to steal sensitive information such as passwords, credit card numbers and other pertinent information. Malware infections have increased tremendously over the last decade. Recent reports indicate that around 70% of malware infections go undetected by the antivirus software. The infections that remain undetected fall into the category of zero-day malware, which is defined as malware that is new and is essentially an undiscovered and undisclosed threat. Furthermore, its substructure or the functioning has not been understood, and no signatures have been defined to distinguish the zero-day malware from others. Moreover, an average enterprise receives 17,000 malware alerts per week, and if 70% goes undetected, then one is certain to be infected by the zero-day malware every week. Therefore, the low detection rates and increasing vulnerabilities have created an unmet need for the researchers to try and develop an algorithm that will help in timely and efficient detection of malware. Moreover, in our approach researchers used the cloud for malware detection, which is a safe, cost-effective and user-friendly environment. Arsh Arora, Thomas Stallings, Ragib Hasan, Gary Warner |
CLOUD | 3 |
| 2017 | Towards non-intrusive continuous healthcare monitoring with the Smart Hospital GownabstractContinuous monitoring and gathering of vital signs are essential for the treatment of critical care patients in the hospital. However, in most cases, the monitoring and data gathering are manual processes, with a nurse collecting the patient's temperature, pulse rate, and other information at regular time intervals. The data collection and monitoring are performed via external sensors and peripheral devices attached to the patient. This, in turn, limits the mobility of the patient for treatment and even to perform trivial actions, such as, using the rest room. To resolve this problem, we aim at creating a smart sensory and computing fabric for the hospital gown. The Smart Hospital Gown contains one or more compute units, a multitude of sensors for collecting the patient's temperature, breathing rate, sweating, pulse rate, and other vital information. The patient can simply wear the gown without requiring any additional external wires or sensors/monitors to be attached to the patient. In this demo, we will demonstrate the Smart Hospital Gown and show its user friendliness and utility in providing a better, low-cost, and continuous monitoring system for critical care patients. Maya Guru, Ragib Hasan, Rasib Khan |
CCNC | 2 |
| 2017 | DExaS: Delegated experience as a service for mobile and wearable devicesabstractMobile devices and wearables are becoming more popular everyday. Such devices are equipped with advanced hardware and software capabilities. While delegation and remote delivery of services for mobile and wearable devices are not new, such services are limited to framework specific applications, and, without a defined incentive model for cooperative service delivery. In this paper, we propose the Delegated Experience as a Service (DExaS) model for mobile and wearable devices. DExaS delivers a service-oriented approach towards accessing services and features from smart mobile and wearable devices for capability and resource limited devices. Our model provides a detailed architecture and protocol level definition for provisioning delegated services. Moreover, DExaS incorporates capability based discovery of services, including a payment based incentive model for delegating users to participate in the given framework. We have also presented a prototype delegated phone application using the DExaS framework to illustrate the practical usage and feasibility of the proposed approach. Rasib Khan, Ragib Hasan |
CCNC | 2 |
| 2017 | Unified authentication factors and fuzzy service access using interaction provenance
Ragib Hasan, Rasib Khan |
Comput. Secur. | 1 |
| 2016 | Jugo: A Generic Architecture for Composite Cloud as a ServiceabstractCloud computing has become the industry standard for rapid application deployment, scalable server support, mobile and distributed services, and it provides access to (theoretically) infinite resources. Unfortunately, researchers are still trying to converge towards cross-provider cloud computing frameworks to enable compatibility and seamless resource transition between cloud providers. Moreover, users are restricted to using the provider-specific pre-configured options of resources and services, irrespective of their current needs. At the same time, cloud services are provided as a direct service from the providers to the clients. This creates a segregated cloud market clientele, and non-negotiable pricing strategies for the cloud services. In this paper, we propose Jugo, a generic architecture for cloud composition and negotiated service delivery for cloud users. Jugo acts as a match-maker for service specifications from the users with the currently available assets from the cloud providers. The engagement of a middle-man as an opaque cloud service provider will create a better opportunity for cloud users to find cheaper deals, price-matching, and flexible resource specifications, with increased revenue and higher resource utilization for the cloud service providers. Md. Mahmud Hossain, Rasib Khan, Shahid Al Noor, Ragib Hasan |
CLOUD | 4 |
| 2016 | Litigo: A Cost-Driven Model for Opaque Cloud ServicesabstractCloud computing provides software, platform, and infrastructure as a service that helps organizations to perform several resource intensive tasks. The services offered by a cloud service provider are limited by provider-specific options in terms of the pre-specified configurations. Moreover, it is sometimes expensive to pay a fixed amount of money without any format of negotiation or price-matching deals for the cloud-based services and resources. Conversely, the negotiator-based model for opaque services has gained popularity in various markets, such as, for flights, hotels, and rentals. We posit that a similar opaque inventory for cloud-based services and resources is the next generation niche for consumer acquisition and service delivery in the cloud computing market. Such a model will facilitate the clients with flexible resource and service provisioning at reasonable prices, and will also allow a higher revenue and increase resource utilization for cloud service providers. In this paper, we propose Litigo, a cost-driven model for opaque service platforms for cloud computing. The Litigo component acts as a middle-man to deliver cloud-based services from a set of cloud service providers to the end users. We present a detailed cost model and comparison between establishing a cloud service vs. an opaque cloud service. Our empirical framework allows a Litigo service provider to analyze the profit model and creates the market niche accordingly. We performed extensive analysis using simulated model verification for Litigo. The proposed model delivers an opaque cloud as a service to clients at a reasonable price by maximizing the resource utilization and revenue of cloud service providers. Shahid Al Noor, Rasib Khan, Md. Mahmud Hossain, Ragib Hasan |
CLOUD | 4 |
| 2016 | SECAP: Towards Securing Application Provenance in the CloudabstractProvenance for an application can provide important insights about the behavior and life cycle of the application. However, currently, there are no provenance management systems which collect and preserve provenance records securely for the applications running in a virtual machine hosted on the cloud. Moreover, the black-box nature of clouds and the possibility of cloud providers being malicious can make the secure application provenance management challenging. In this paper, we analyze the threats on trustworthy application provenance in the context of clouds while considering the collusion between users and cloud providers. Based on this threat model, we present the SECure Application Provenance (SECAP) scheme, which ensures the required integrity and confidentiality properties for application provenance efficiently. We evaluate the performance of the SECAP scheme on an OpenStack-based cloud. The experimental results suggest that SECAP performs better than several other state-of-the-art secure provenance schemes in terms of time and space requirements. Shams Zawoad, Ragib Hasan |
CLOUD | 2 |
| 2016 | A Cloud You Can Wear: Towards a Mobile and Wearable Personal CloudabstractMobile and wearable devices provide the expected user experience and the ability to run complex applications using cloud based services. This makes the design of such wearable devices complex, expensive, and with major data privacy concerns. In this paper, we present the concept of a wearable cloud -- a complete yet compact and lightweight cloud which can be embedded into the clothing of a user. The wearable cloud makes the design of mobile and wearable devices simple, inexpensive, and lightweight, tapping into the resources of the wearable cloud. We introduce five wearable cloud service delivery models including a prototype implementation of the wearable cloud and a cheap touchscreen terminal device. The paper presents experimental results on the usability of the wearable cloud based on energy consumption and application performance. Ragib Hasan, Rasib Khan |
COMPSAC | 1 |
| 2016 | How Secure is the Healthcare Network from Insider Attacks? An Audit Guideline for Vulnerability AnalysisabstractThe availability of wireless interfaces with the new generation medical devices has spawned numerous opportunities in providing better healthcare support to patients. However, the weaknesses of available wireless communication channels introduce various novel attacks on the medical devices. Since the smart mobile devices, such as smartphones, tablets, laptops are also equipped with the same communication channels (WiFi/Bluetooth), attacks on medical devices can be initiated from a compromised or malware infected mobile device. Attackers can steal confidential medical records from a wireless-enabled medical device. Medical devices or communication channels can also be compromised to feed incorrect medical records to doctors or send life threatening commands to the devices. Moreover, since the compromised mobile devices are already inside the security perimeter of a healthcare network, it is very challenging to block attacks from such compromised mobile devices. In this paper, we systematically analyze the novel threats on healthcare devices and networks, which can be initiated from compromised mobile devices. We provide a detail audit guideline to evaluate the security strength of a healthcare network. Based on our proposed guideline, we evaluate the current security state of a large university healthcare facility. We also propose several mitigation strategies to mitigate some of the possible attacks. Ragib Hasan, Shams Zawoad, Shahid Al Noor, Md Munirul Haque, Darrell Burke |
COMPSAC | 1 |
| 2016 | The Story of Naive Alice: Behavioral Analysis of Susceptible Internet UsersabstractThe Internet has become an integral part of our everyday life. Unfortunately, not all of us are equally aware of the threats when we use online services. Naive users are generally less aware of security and privacy practices on the Internet and are susceptible to online predators. In this paper, we present a behavioral analysis of Internet users and their susceptibility to online malpractices. We have considered the dataset from the Global Internet User Survey for 10789 respondents to perform a security-oriented statistical analysis of correlated user behavior. We constructed logistic regression models to analyze the statistical predictability of susceptible and not-so-susceptible identity theft victims based on their behavior and knowledge of security and privacy practices. We posit that such a study can be used to assess the vulnerability of Internet users and can hence be used to leverage institutional and personal safety on the Internet by promoting online security education, threat awareness, and guided Internet-safe behavior. Rasib Khan, Ragib Hasan |
COMPSAC | 2 |
| 2016 | Chronos: Towards Securing System Time in the Cloud for Reliable Forensics InvestigationabstractIn digital forensics investigations, the system time of computing resources can provide critical information to implicate or exonerate a suspect. In clouds, alteration of the system time of a virtual machine (VM) or a cloud host machine can provide unreliable time information, which in turn can mislead an investigation in the wrong direction. In this paper, we propose Chronos to secure the system time of cloud hosts and VMs in an untrusted cloud environment. Since it is not possible to prevent a malicious user or a dishonest insider of a cloud provider from altering the system time of a VM or a host machine, we propose a tamper-evident scheme to detect this malicious behavior at the time of investigation. We integrate Chronos with an open-source cloud platform - OpenStack and evaluate the feasibility of Chronos while running 20 VMs on a single host machine. Our test results suggest that Chronos can be easily deployed in the existing cloud with very low overheads, while achieving a high degree of trustworthiness of the system time of the cloud hosts and VMs. Shams Zawoad, Ragib Hasan |
COMPSAC | 2 |
| 2016 | Towards Building Forensics Enabled Cloud Through Secure Logging-as-a-ServiceabstractCollection and analysis of various logs (e.g., process logs, network logs) are fundamental activities in computer forensics. Ensuring the security of the activity logs is therefore crucial to ensure reliable forensics investigations. However, because of the black-box nature of clouds and the volatility and co-mingling of cloud data, providing the cloud logs to investigators while preserving users' privacy and the integrity of logs is challenging. The current secure logging schemes, which consider the logger as trusted cannot be applied in clouds since there is a chance that cloud providers (logger) collude with malicious users or investigators to alter the logs. In this paper, we analyze the threats on cloud users' activity logs considering the collusion between cloud users, providers, and investigators. Based on the threat model, we propose Secure-Logging-as-a-Service ( SecLaaS), which preserves various logs generated for the activity of virtual machines running in clouds and ensures the confidentiality and integrity of such logs. Investigators or the court authority can only access these logs by the RESTful APIs provided by SecLaaS, which ensures confidentiality of logs. The integrity of the logs is ensured by hash-chain scheme and proofs of past logs published periodically by the cloud providers. In prior research, we used two accumulator schemes Bloom filter and RSA accumulator to build the proofs of past logs. In this paper, we propose a new accumulator scheme - Bloom-Tree, which performs better than the other two accumulators in terms of time and space requirement. Shams Zawoad, Ragib Hasan |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2015 | PLAG: Practical Landmark Allocation for Cloud GeolocationabstractKnowing the physical location of files in a cloud system is of a great importance for any user, as is it can affect the whole service drastically. However, pinpointing the exact coordinates for the location of a server is very challenging. Providers prefer not to share the location of their data centers with public for security reasons, and this fact also adds to the complexity of this concept. Researchers have recently developed delay based schemes for cloud data geolocation, some of which use proprietary landmarks for location verification. Unfortunately, such landmark-based schemes are often impractical due to high cost and latency. In this paper, we have developed a practical scheme for landmark allocation in cloud data geolocation. We augment existing approaches with a new landmark allocation modification to get the same or often better accuracy, while decreasing the cost considerably. Our approach improves the existing state of the art by introducing the concept of publicly distributed landmarks for all delay based geolocation techniques. Maziar Fotouhi, Abhishek Anand, Ragib Hasan |
CLOUD | 3 |
| 2015 | OCF: An Open Cloud Forensics Model for Reliable Digital ForensicsabstractThe rise of cloud computing has changed the way computing services and resources are used. However, existing digital forensics science cannot cope with the black-box nature of clouds nor with multi-tenant cloud models. Because of the fundamental characteristics of clouds, many assumptions of digital forensics are invalidated in clouds. In the digital forensics process involving clouds, the role of cloud service providers (CSP) is utterly important, a role which needs to be considered in the science of cloud forensics. In this paper, we define cloud forensics considering the role of the CSP and propose the Open Cloud Forensics (OCF) model. Based on this OCF model, we propose a cloud computing architecture and validate our proposed model using a case study, which is inspired from an actual civil lawsuit. Shams Zawoad, Ragib Hasan, Anthony Skjellum |
CLOUD | 2 |
| 2015 | D-CLOC: A Delay Tolerant Cloud Formation Using Context-Aware Mobile CrowdsourcingabstractGathering information and providing remote assistant is a common trend as it saves time and cost associated with visiting the actual location in person. The widely available mobile sensors are used in collecting information during a task processing. However, gathering information from a remote place, or an area of disaster, is not trivial, given the unavailability of appropriate infrastructure. Existing delay tolerant networking approaches address this issue but suffer from unsatisfactory performance due to the lack of sufficient user participation. We propose the Delay-tolerant Cloud Computing framework (D-CLOC), a cloud framework utilizing the contextual information of a mobile client. Our proposed architecture combines crowdsourcing and the cellular network and forms a temporal delay tolerant cloud. D-CLOC uses a bidding incentive model to ensure and promote user participation in the cloud. We provide a detailed reasoning of the security and feasibility of our model, and delineate probable approaches for solving the various security related aspects. The paper includes the design and implementation of a realistic-simulation model for D-CLOC. The simulation scenario incorporates an example face recognition task for evaluating the performance of our proposed model. Our experimental results show that D-CLOC performs quite well compared to some of the existing DTN approaches and can be deployed for solving any real life problems using crowdsourcing within a delay tolerant cloud infrastructure. Shahid Al Noor, Ragib Hasan |
CloudCom | 2 |
| 2015 | A Trustworthy Cloud Forensics Environment
Shams Zawoad, Ragib Hasan |
IFIP Int. Conf. Digital Forensics | 2 |
| 2015 | Towards an Analysis of Security Issues, Challenges, and Open Problems in the Internet of ThingsabstractThe Internet of Things (IoT) devices have become popular in diverse domains such as e-Health, e-Home, e-Commerce, and e-Trafficking, etc. With increased deployment of IoT devices in the real world, they can be, and in some cases, already are subject to malicious attacks to compromise the security and privacy of the IoT devices. While a number of researchers have explored such security challenges and open problems in IoT, there is an unfortunate lack of a systematic study of the security challenges in the IoT landscape. In this paper, we aim at bridging this gap by conducting a thorough analysis of IoT security challenges and problems. We present a detailed analysis of IoT attack surfaces, threat models, security issues, requirements, forensics, and challenges. We also provide a set of open problems in IoT security and privacy to guide the attention of researchers into solving the most critical problems. Md. Mahmud Hossain, Maziar Fotouhi, Ragib Hasan |
SERVICES | 3 |
| 2015 | High-Performance Classification of Phishing URLs Using a Multi-modal Approach with MapReduceabstractClassifying phishing websites can be expensive both computationally and financially given a large enough volume of suspect sites. A distributed cloud environment can reduce the computational time and financial cost significantly. To test this idea, we apply a multi-modal feature classification algorithm to classify phishing websites in a non-distributed and several distributed environments. A multi-modal approach combines both visual and text features for classification. The implementation extracts color feature and histogram feature from the screenshot of a phishing website and text from its html source code. Feature extraction and comparison is accomplished by applying the MapReduce framework. Implementing the multi-modal approach in a distributed environment proves to reduce the runtime as well as the financial costs. We present results that show our work is 30 times faster than existing state of the art systems in phishing website classification problem. Niju Shrestha, Rajan Kumar Kharel, Jason Britt, Ragib Hasan |
SERVICES | 4 |
| 2015 | e-ESAS: Evolution of a participatory design-based solution for breast cancer (BC) patients in rural Bangladesh
Md Munirul Haque, Ferdaus Ahmed Kawsar, Mohammad Adibuzzaman, Md. Miftah Uddin, Sheikh Iqbal Ahamed, Richard Love, Ragib Hasan, Rumana Dowla, Tahmina Ferdousy, Reza Salim |
Pers. Ubiquitous Comput. | 7 |
| 2014 | CellCloud: A Novel Cost Effective Formation of Mobile Cloud Based on Bidding IncentivesabstractCloud computing has become the dominant computing paradigm in recent years. As clouds evolved, researchers have explored the possibility of building clouds out of loosely associated mobile computing devices. However, most such efforts failed due to the lack of a proper incentive model for the mobile device owners. In this paper, we propose CellCloud - a practical mobile cloud architecture which can be easily deployed on existing cellular phone network infrastructure. It is based on a novel reputation-based economic incentive model in order to compensate the phone owners for the use of their phones as cloud computing nodes. CellCloud offers a practical model for performing cloud operations, with lower costs compared to a traditional cloud. We provide an elaborate analysis of the model with security and economic incentives as major focus. Along with a cost equation model, we discuss detailed results to prove the feasibility of our proposed model. Our simulation results show that CellCloud creates a win-win scenario for all three stakeholders (client, cloud provider, and mobile device owners) to ensure the formation of a successful mobile cloud architecture. Shahid Al Noor, Ragib Hasan, Md Munirul Haque |
IEEE CLOUD | 2 |
| 2014 | A Comparative Study on I/O Performance between Compute and Storage Optimized Instances of Amazon EC2abstractCloud computing infrastructure helps users to minimize cost by outsourcing data and computation on-demand. Due to the varying user needs in terms of computation power, storage capacity, etc., cloud providers offer various machines to choose from, to maximize the intended need. In this paper, we disprove several common conceptions regarding the performance and cost of cloud by experimenting on instances of two different families (compute and storage optimized) of the most popular cloud platform, Amazon Elastic Compute Cloud (EC2). Our analysis shows the interesting finding that, for the machines of the same configuration, storage optimized instances have lower disk read-write speed than compute optimized, which does not completely reflect the claim made by Amazon in all cases. Additionally, storage optimized instances have notable performance difference among them. We also identify that the I/O performance of same instance type varies over different time periods. Abu Awal Md Shoeb, Ragib Hasan, Md. Haque |
IEEE CLOUD | 2 |
| 2014 | CURLA: Cloud-Based Spam URL Analyzer for Very Large DatasetsabstractURL blacklisting is a widely used technique for blocking phishing websites. To prepare an effective blacklist, it is necessary to analyze possible threats and include the identified malicious sites in the blacklist. Spam emails are good source for acquiring suspected phishing websites. However, the number of URLs gathered from spam emails is quite large. Fetching and analyzing the content of this large number of websites are very expensive tasks given limited computing and storage resources. Moreover, a high percentage of URLs extracted from spam emails refer to the same website. Hence, preserving the contents of all the websites causes significant storage waste. To solve the problem of massive computing and storage resource requirements, we propose and develop CURLA - a Cloud-based spam URL Analyzer, built on top of Amazon Elastic Computer Cloud (EC2) and Amazon Simple Queue Service (SQS). CURLA allows processing large number of spam-based URLs in parallel, which reduces the cost of establishing equally capable local infrastructure. Our system builds a database of unique spam-based URLs and accumulates the content of these unique websites in a central repository, which can be later used for phishing or other counterfeit websites detection. We show the effectiveness of our proposed architecture using real-life spam-based URL data. Shams Zawoad, Ragib Hasan, Md Munirul Haque, Gary Warner |
IEEE CLOUD | 2 |
| 2014 | OTIT: towards secure provenance modeling for location proofsabstractPersonal mobile devices and location based services are gaining popularity every day. Since the location based services are often customized based on the location information, it is important to securely generate, preserve, and validate the claim of presence at a given location at a given time as well as location provenance - the history of locations for a mobile device user over a given time period. Location provenance needs to imply secure and chronological ordering of location proofs, which can be successfully verified at a later time. Otherwise, the location based services can be easily spoofed by falsified location history. In this paper, we present OTIT - a model for designing secure location provenance. We formalized the features and characteristics for the domain of secure location provenance schemes, using formal propositional logic and logical proofs. We also present several schemes, which can be used in various modes to provide secure location provenance services. Based on the characteristics defined in OTIT, we have analyzed different schemes to show their adherence to the desired features of secure location provenance. Furthermore, we present experimental results on the performance of the various schemes, in terms of time and storage, to show a comparative applicability analysis. We posit that OTIT will serve as a comprehensive benchmark framework to evaluate the models for secure location provenance. Rasib Khan, Shams Zawoad, Munirul M. Haque, Ragib Hasan |
AsiaCCS | 4 |
| 2014 | Interaction provenance model for unified authentication factors in service oriented computingabstractAuthentication is one of the most fundamental security problems. To date, various distinct authentication factors such as passwords, tokens, certificates, and biometrics have been designed for authentication. In this paper, we propose using the history or provenance of previous interactions and events as the generic platform for all authentication challenges. In this paradigm, provenance of past interactions with the authenticating principle or a third party is used to authenticate a user. We show that the interaction provenance paradigm is generic and can be used to represent existing authentication factors, yet allow the use of newer methods. We also discuss how authentication based on interactions can allow very flexible but complex authentication and access control policies that are not easily possible with current authentication models. Ragib Hasan, Rasib Khan |
CODASPY | 1 |
| 2014 | 'Who, When, and Where?' Location Proof Assertion for Mobile Devices
Rasib Khan, Shams Zawoad, Md Munirul Haque, Ragib Hasan |
DBSec | 4 |
| 2014 | Sockpuppet Detection in Wikipedia: A Corpus of Real-World Deceptive Writing for Linking Identities
Thamar Solorio, Ragib Hasan, Mainul Mizan |
LREC | 2 |
| 2014 | A trust based Information sharing model (TRUISM) in MANET in the presence of uncertaintyabstractIn the absence of centralized trusted authorities (CTA), security is one of the foremost concern in Mobile Ad-hoc Networks (MANET) as the network is open to attacks and unreliability in the presence of malicious nodes (devices). With increasing demand of interactions among nodes, trust based information sharing needs more stringent rules to ensure security in this pervasive computing scenario. In this paper, we present a novel multi-hop recommendation based trust management scheme (TRUISM). We adapt famous Dempster-Shafer theory that can efficiently combine recommendations from multiple devices in the presence of unreliable and malicious recommendations. A novel recommendation-routing protocol named ‘buffering on-the-fly’ has been introduced to reduce the number of recommendation traffic by storing trust values in intermediate nodes. TRUISM also provides a flexible behavioral model for trust computation where a node can prioritize recommendations based on its requirements. Evaluation result shows that our model not only performs well in the presence of contradictory recommendations but also ensures a faster and scalable trust based information sharing by reducing the overall packet flow in the system. Khalid Zaman Bijon, Md Munirul Haque, Ragib Hasan |
PST | 3 |
| 2013 | Sensing-enabled channels for hard-to-detect command and control of mobile devicesabstractThe proliferation of mobile computing devices has enabled immense opportunities for everyday users. At the same time, however, this has opened up new, and perhaps more severe, possibilities for attacks. In this paper, we explore a novel generation of mobile malware that exploits the rich variety of sensors available on current mobile devices. Ragib Hasan, Nitesh Saxena, Tzipora Halevi, Shams Zawoad, Dustin Rinehart |
AsiaCCS | 1 |
| 2013 | SecLaaS: secure logging-as-a-service for cloud forensicsabstractCloud computing has emerged as a popular computing paradigm in recent years. However, today's cloud computing architectures often lack support for computer forensic investigations. Analyzing various logs (e.g., process logs, network logs) plays a vital role in computer forensics. Unfortunately, collecting logs from a cloud is very hard given the black-box nature of clouds and the multi-tenant cloud models, where many users share the same processing and network resources. Researchers have proposed using log API or cloud management console to mitigate the challenges of collecting logs from cloud infrastructure. However, there has been no concrete work, which shows how to provide cloud logs to investigator while preserving users' privacy and integrity of the logs. In this paper, we introduce Secure-Logging-as-a-Service (SecLaaS), which stores virtual machines' logs and provides access to forensic investigators ensuring the confidentiality of the cloud users. Additionally, SeclaaS preserves proofs of past log and thus protects the integrity of the logs from dishonest investigators or cloud providers. Finally, we evaluate the feasibility of the scheme by implementing SecLaaS for network access logs in OpenStack -- a popular open source cloud platform. Shams Zawoad, Ragib Hasan |
AsiaCCS | 3 |
| 2013 | FAL: A Forensics Aware Language for Secure Logging
Shams Zawoad, Marjan Mernik, Ragib Hasan |
FedCSIS | 3 |
| 2012 | MANTICORE: Masking All Network Traffic via IP Concealment with OpenVPN Relaying to EC2abstractMalware and computer forensic researchers often communicate with malicious servers, either directly or indirectly, through the web browser or other ports utilized by malicious software. Communication with this form of adversary can sometimes necessitate the use of a proxy server in order to conceal the true origin of the researcher's traffic. Open source projects such as OpenVPN currently offer a structured method for establishing software based virtual private networks (VPNs) between arbitrary clients and servers. Likewise, paradigms exist which allow a user to proxy traffic from one end of a VPN to another, effectively masking the origin of traffic being sent to and from the client system. In this paper, we present MANTICORE - a system that combines ideas from VPN with the instancing functionality of a cloud computing system in order to dynamically mask and reassign the apparent IP address of a researcher's system. We also present experimental evaluation of our system on Amazon's Elastic Compute Cloud (EC2). Patrick Butler, Adam Rhodes, Ragib Hasan |
IEEE CLOUD | 3 |
| 2012 | Cloud Based Content Fetching: Using Cloud Infrastructure to Obfuscate Phishing Scam AnalysisabstractPhishing has become a crippling problem for many of today's internet users. Despite innovations in preventative measures, phishing has evolved to become very hard to detect. Determining whether a particular site is a phishing site or not is difficult, causing many inexperienced users to fall victim. Phishing site operators often actively prevent anti-phishing measures by detecting and blacklisting the IP addresses that try to probe them. In this paper, we propose using a cloud infrastructure to mask our identity from assumed phishing sites through the use of virtual machines spread across many geographic regions. Our system presents different personas and user behavior to the phishing sites by using different IP addresses and different browsing configurations. By running a 10-day probe experiment against real phishing site, we show the effectiveness of this approach in preventing detection and blocking of anti-phishing probes by the phishing site operators. Edward Ferguson, Joseph Weber, Ragib Hasan |
SERVICES | 3 |
| 2011 | Efficient audit-based compliance for relational data retentionabstractThe Sarbanes-Oxley Act inspired research on long-term high-integrity retention of business records, based on the long-term immutability guarantees that WORM storage servers offer for files. Researchers recently proposed a Log-compliant DBMS Architecture (LDA) that extends those immutability guarantees to relational tuples, using an approach that imposes a 10-20% performance penalty on TPC-C benchmark runs. \n \nIn this paper, we present the transaction log on WORM (TLOW) approach for supporting long-term immutability for relational tuples. TLOW incurs less than 1% runtime overhead on TPC-C benchmarks with Berkeley DB, which is much less than for LDA. TLOW requires no changes to the DBMS kernel, and audit time is comparable to that of LDA: 2.7% of transaction time, i.e. ten days for a yearly audit on the platform we used. We also introduce the audit helper (AH) add-on to TLOW, which decreases the cost of a yearly audit on our platform to two hours. We provide a proof of correctness for TLOW, which exposes a subtle threat. The proof also illustrates a non-obvious problem with LDA, which we show how to correct. Ragib Hasan, Marianne Winslett |
AsiaCCS | 1 |
| 2010 | Trustworthy vacuuming and litigation holds in long-term high-integrity records retentionabstractRelational databases are periodically vacuumed to remove tuples that have expired. During the discovery phase of litigation, plaintiffs ask defendants for access to information related to their case. The requested information is then subject to a litigation hold, which means that the information cannot be deleted. Vacuuming exposes a database to a new threat -- adversaries can try to thwart database auditing mechanism by masquerading an illegal tuple deletion as a vacuuming operation, and delete an unexpired tuple, or a tuple under a litigation hold. Ragib Hasan, Marianne Winslett |
EDBT | 1 |
| 2009 | Remembrance: The Unbearable Sentience of Being Digital
Ragib Hasan, Radu Sion, Marianne Winslett |
CIDR | 1 |
| 2009 | The Case of the Fake Picasso: Preventing History Forgery with Secure Provenance
Ragib Hasan, Radu Sion, Marianne Winslett |
FAST | 1 |
| 2009 | Preventing history forgery with secure provenanceabstractAs increasing amounts of valuable information are produced and persist digitally, the ability to determine the origin of data becomes important. In science, medicine, commerce, and government, data provenance tracking is essential for rights protection, regulatory compliance, management of intelligence and medical data, and authentication of information as it flows through workplace tasks. While significant research has been conducted in this area, the associated security and privacy issues have not been explored, leaving provenance information vulnerable to illicit alteration as it passes through untrusted environments. In this article, we show how to provide strong integrity and confidentiality assurances for data provenance information at the kernel, file system, or application layer. We describe Sprov, our provenance-aware system prototype that implements provenance tracking of data writes at the application layer, which makes Sprov extremely easy to deploy. We present empirical results that show that, for real-life workloads, the runtime overhead of Sprov for recording provenance with confidentiality and integrity guarantees ranges from 1% to 13%, when all file modifications are recorded, and from 12% to 16%, when all file read and modifications are tracked. Ragib Hasan, Radu Sion, Marianne Winslett |
ACM Trans. Storage | 1 |
| 2008 | Please Permit Me: Stateless Delegated Authorization in MashupsabstractMashups have emerged as a Web 2.0 phenomenon, connecting disjoint applications together to provide unified services. However, scalable access control for mashups is difficult. To enable a mashup to gather data from legacy applications and services, users must give the mashup their login names and passwords for those services. This all-or-nothing approach violates the principle of least privilege and leaves users vulnerable to misuse of their credentials by malicious mashups. In this paper, we introduce delegation permits - a stateless approach to access rights delegation in mashups - and describe our complete implementation of a permit-based authorization delegation service. Our protocol and implementation enable fine grained, flexible, and stateless access control and authorization for distributed delegated authorization in mashups, while minimizing attackers' ability to capture and exploit users' authentication credentials. Ragib Hasan, Marianne Winslett, Richard M. Conlan, Brian Slesinsky, Nandakumar Ramani |
ACSAC | 1 |
| 2008 | A component-based framework for radio-astronomical imaging software systemsabstractAbstract This paper describes a component‐based framework for radio‐astronomical imaging software systems. We consider optimal re‐use strategies for packages of disparate architectures brought together within a modern component framework. In this practical case study, the legacy codes include both procedural and object‐oriented architectures. We consider also the special requirements on scientific component middleware, with a specific focus on high‐performance computing. We present an example application in this component architecture and outline future development planned for this project. Copyright © 2007 John Wiley & Sons, Ltd. A. J. Kemball, R. M. Crutcher, Ragib Hasan |
Softw. Pract. Exp. | 3 |
| 2006 | Synergy: A Policy-Driven, Trust-Aware Information Dissemination Framework
Ragib Hasan, Marianne Winslett |
ISI | 1 |
| 2005 | Trade-Offs in Protecting Storage: A Meta-Data Comparison of Cryptographic, Backup/Versioning, Immutable/Tamper-Proof, and Redundant Storage SolutionsabstractModern storage systems are responsible for increasing amounts of data and the value of the data itself is growing in importance. Several primary storage system solutions have emerged for the protection of data: (1) secure storage through cryptography, (2) backup and versioning systems, (3) immutable and tamper-proof storage, and (4) redundant storage. Using results from published studies, we compare these four solutions against different requirements highlighting trade-offs in performance, space, attack resistance, and cost. We also present a case study of applying these solutions based on design work at NCSA. Lastly, we conclude that while different storage protection solutions may be appropriate for different requirements, some general conclusions can be made about current state-of-the-art storage protection solutions as well as directions for future research. Joseph A. Tucek, Paul Stanton, Elizabeth Haubert, Ragib Hasan, Larry Brumbaugh, William Yurcik |
MSST | 4 |