EDBT 2026 Demo / reviewers in the wild / expert
Siraj Ahmed Shaikh
dblp:s/SirajAShaikh · also Siraj A. Shaikh
· DBLP profile ↗
21ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-0726-3319ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 5 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A quantitative methodology for systemic impact assessment of cyber threats in connected vehiclesabstractThe increasing integration of digital technologies in connected vehicles introduces cybersecurity risks that extend beyond individual vehicles, with the potential to disrupt entire transportation systems. Current practice (e.g., ISO/SAE 21434 TARA) focuses on threat identification and qualitative impact ratings at the vehicle boundary, with limited systemic quantification. This study presents a systematic, simulation-based methodology for quantifying the systemic operational and safety impacts of cyber threats on connected vehicles, evaluating cascading effects across the transport network. Three representative scenarios are examined: (I) telematics-induced sudden braking causing a cascading collision, (II) remote disabling on a motorway (M25) segment, and (III) a compromised Roadside Unit (RSU) spoofing Variable Speed Limit (VSL) and phantom lane closure messages to connected and automated vehicles (CAVs). The results highlight the potential for cascading safety incidents and systemic operational degradation, as evidenced by the defined systemic operational and safety vectors, factors that are insufficiently addressed in the current scope of the ISO/SAE 21434 standard, which primarily focuses on individual vehicle-level threats. The findings underscore the need to incorporate systemic evaluation into existing frameworks to enhance cyber resilience across connected vehicle ecosystems. The framework complements ISO/SAE 21434 by supplying quantitative, reproducible evidence for the impact rating step at a systemic scale, reducing assessor subjectivity and supporting policy and operations, enabling more data-driven evaluations of systemic cyber risks. Don Nalin Dharshana Jayaratne, Abdur Rakib, Muhamad Azfar Ramli, Rakhi Manohar Mepparambath, Siraj Ahmed Shaikh, Nguyen Hoang Nga |
Comput. Secur. | 6 |
| 2025 | WOLVES: Window of Opportunity attack feasibility likelihood value estimation through a simulation-based approachabstractThe Road Vehicles Cybersecurity Engineering Standard, ISO/SAE 21434, provides a framework for road vehicle Threat Analysis and Risk Assessment (TARA). The TARA framework must include Connected Vehicles (CVs) and their connectivity with external interfaces. However, assessing cyber-attack feasibility on CVs is a significant challenge, as traditionally, qualitative and subjective expert opinions are the norm. Additionally, there is a need for historical data on security-related incidents and dynamically evolving interconnected vehicle-to-everything (V2X) entities for feasibility assessment, which is not readily available. To address this problem, this paper presents, to the best of our knowledge, the first simulation-based TARA framework designed to characterise, quantify, and assess the Window of Opportunity (WO) for attackers—a metric that indicates the likelihood of an attack. A case study involving Bluetooth, with one attacker and one target, is modelled to demonstrate the proposed framework WOLVES’s applicability. Two scenarios have been investigated using different motorway roads in the UK. The primary outcome is the WOLVES framework, which employs a data-driven approach using both prior and likelihood information to estimate the probability of a successful cyber attack on a given technology in CVs. The findings from this research could assist threat analysts, decision-makers, and planners involved in CV risk assessment by enhancing the modelling of attack feasibility for cybersecurity threats in dynamic scenarios and developing appropriate mitigation strategies. Suraj Harsha Kamtam, Abdur Rakib, Muhamad Azfar Ramli, Rakhi Manohar Mepparambath, Siraj Ahmed Shaikh, Nguyen Hoang Nga |
Comput. Secur. | 6 |
| 2025 | Predicting Next Useful Location with Context-Awareness: The State-of-the-ArtabstractPredicting the future location of mobile objects reinforces location-aware services with proactive intelligence and helps businesses and decision-makers with better planning and near real-time scheduling in different applications such as traffic congestion control, location-aware advertisements and monitoring public health and well-being. Recent developments in smartphone and location sensors technology and the prevalence of using location-based social networks alongside the improvements in AI and machine learning techniques provide an excellent opportunity to exploit massive amounts of historical and real-time contextual information to recognise mobility patterns and achieve more accurate and intelligent predictions. This unique survey provides a comprehensive overview of the next useful location prediction problem with context-awareness and the related studies. First, we explain the concepts of context and context-awareness and define the next location prediction problem. Then we analyse more than 30 studies in this field concerning the prediction method, the challenges addressed, the datasets and metrics used for training and evaluating the model and the types of context incorporated. Finally, we discuss the advantages and disadvantages of different approaches, focusing on the usefulness of the predicted location and identifying the open challenges and future work on this subject. Alireza Nezhadettehad, Arkady B. Zaslavsky, Abdur Rakib, Siraj Ahmed Shaikh, Seng W. Loke, Guang-Li Huang, Alireza Hassani |
ACM Trans. Intell. Syst. Technol. | 4 |
| 2024 | TOMSAC - Methodology for trade-off management between automotive safety and cyber securityabstractSafety and security interdependencies have been of interest for researchers for several decades. However, in practice, they are not given the necessary consideration yet due to various reasons, such as lack of understanding and reluctance to change current practices. This research is aimed at advancing the state of the art in this area by developing a practical, easy to adapt and to use methodology for managing interdependencies and trade-offs throughout the development lifetime of cyber physical systems. The methodology is named TOMSAC, short for Trade-Off Management between Safety And Cyber security. Giedre Sabaliauskaite, Jeremy W. Bryans, Hesamaldin Jadidbonab, Siraj Ahmed Shaikh, Paul Wooderson |
Comput. Secur. | 5 |
| 2023 | A formal framework for security testing of automotive over-the-air update systemsabstractModern vehicles are comparable to desktop computers due to the increase in connectivity. This fact also extends to potential cyber-attacks. A solution for preventing and mitigating cyber attacks is Over-The-Air (OTA) updates. This solution has also been used for both desktops and mobile phones. The current de facto OTA security system for vehicles is Uptane, which is developed to solve the unique issues vehicles face. The Uptane system needs to have a secure method of updating; otherwise, attackers will exploit it. To this end, we have developed a comprehensive and model-based security testing approach by translating Uptane and our attack model into formal models in Communicating Sequential Processes (CSP). These are combined and verified to generate an exhaustive list of test cases to see to which attacks Uptane may be susceptible. Security testing is then conducted based on these generated test cases, on a test-bed running an implementation of Uptane. The security testing result enables us to validate the security design of Uptane and some vulnerabilities to which it is subject. Rhys Kirk, Nguyen Hoang Nga, Jeremy W. Bryans, Siraj Ahmed Shaikh, Charles Wartnaby |
J. Log. Algebraic Methods Program. | 4 |
| 2022 | Safety, Stability and Environmental Impact of FDI Attacks on Vehicular PlatoonsabstractVehicular platooning is a promising technology for improving road safety, increasing vehicle efficiency, and reducing traffic congestion by enabling high-speed vehicles to travel in close formation with minimum inter-vehicular distance. However, a False Data Injection (FDI) attack can destabilise and break up vehicular platoons in several different ways. First, an attacker can inject false leave or split messages leading to a breakup of the vehicular platoon. Another way is by sending fake beacons or tampering information (such as speed, acceleration, distance, location etc) in a beacon. Upon receiving this false data, the platoon will destabilise as the members receives tampered information from the attacker. In this paper, we studied the impact of FDI attacks on the vehicular platoon by modifying significant information in a beacon. We carried out a simulation-based study, where a FDI attacker is modelled in Plexe simulator to attack a platoon. We considered two scenarios for an FDI attack, i.e., the attacker can be present both inside and outside of the platoon. Further, two flavours of FDI attacks are implemented, i.e., (1) Constant FDI: where, the attacker is launching FDI attack constantly throughout it’s journey, and (2) Intelligent On-Off FDI: where the attacker is performing FDI for short period of time and then hides his identity by performing legitimate communication with platoon members. We studied the impact of FDI attacks on vehicular platoons from three significant aspects: environmental (CO2emissions), safety (distance), and stability (speed). Our study showed that FDI attacks can have drastic impact on the vehicular platoons. Sean Joe Taylor, Nguyen Hoang Nga, Siraj Ahmed Shaikh |
NOMS | 4 |
| 2022 | Drivers and barriers for secure hardware adoption across ecosystem stakeholdersabstractAbstract The decisions involved in choosing technology components for systems are poorly understood. This is especially so where the choices pertain to system security and countering the threat of cybersecurity attack. Although common in some commercial products, secure hardware chips provide security functions such as authentication, secure execution and integrity validation on system start, and are increasingly deemed to have a role in devices across sectors, such as IoT devices, autonomous vehicle systems and critical infrastructure components. To understand the decisions and opinions regarding the adoption of secure hardware, we conducted 23 semi-structured interviews with senior decision-makers from companies spanning a range of sectors, sizes and supply-chain roles. Our results consider the business propositional drivers, barriers and economic factors that influence the adoption decisions. Understanding these would help those seeking to influence the adoption process, whether as a business decision, or as a trade or national strategy. Andrew Tomlinson, Simon Edward Parkin, Siraj Ahmed Shaikh |
J. Cybersecur. | 3 |
| 2019 | A Template-Based Method for the Generation of Attack Trees
Jeremy W. Bryans, Lin Shen Liew, Nguyen Hoang Nga, Giedre Sabaliauskaite, Siraj Ahmed Shaikh, Fengjun Zhou |
WISTP | 5 |
| 2018 | Building an automotive security assurance case using systematic security evaluations
Madeline Cheah, Siraj Ahmed Shaikh, Jeremy W. Bryans, Paul Wooderson |
Comput. Secur. | 2 |
| 2017 | Software Model Checking: A Promising Approach to Verify Mobile App Security: A Position PaperabstractIn this position paper we advocate software model checking as a technique suitable for security analysis of mobile apps. Our recommendation is based on promising results that we achieved on analysing app collusion in the context of the Android operating system. Broadly speaking, app collusion is when, in performing a threat, several apps are working together, i.e., they exchange information which they could not obtain on their own. In this context, we developed the K-Android tool, which provides an encoding of the Android/Smali code semantics within the K framework. K-Android allows for software model checking of Android APK files. Though our experience so far is limited to collusion, we believe the approach to be applicable to further security properties as well as other mobile operating systems. Irina Mariuca Asavoae, Nguyen Hoang Nga, Markus Roggenbach, Siraj Ahmed Shaikh |
FTfJP@ECOOP | 4 |
| 2017 | Towards a Testbed for Automotive CybersecurityabstractModern automotive platforms are cyber-physical in nature and increasingly connected. Cybersecurity testing of such platforms is expensive and carries safety concerns, making it challenging to perform tests for vulnerabilities and refine test methodologies. We propose a testbed, built over a Controller Area Network (CAN) simulator, and validate it against a real-world demonstration of a weakness in a test vehicle using aftermarket On Board Diagnostic (OBD) scanners (dongles). Daniel S. Fowler, Madeline Cheah, Siraj Ahmed Shaikh, Jeremy W. Bryans |
ICST | 3 |
| 2017 | Formalising Systematic Security Evaluations Using Attack Trees for Automotive Applications
Madeline Cheah, Nguyen Hoang Nga, Jeremy W. Bryans, Siraj Ahmed Shaikh |
WISTP | 4 |
| 2016 | Combining Third Party Components Securely in Automotive Systems
Madeline Cheah, Siraj Ahmed Shaikh, Jeremy W. Bryans, Nguyen Hoang Nga |
WISTP | 2 |
| 2015 | Towards an Early Warning System for Network Attacks Using Bayesian InferenceabstractThe Internet has become the most vulnerable part of critical civil infrastructures. Proactive measures such as early warnings are required to reduce the risk of disasters that can be created using it. With the continuous growth in scale, complexity and variety of networked systems the quality of data is continuously decreasing. This paper investigates the ability to employ Bayesian inference for network scenario analysis with low quality data to produce early warnings. Theoretical account of the approach and experimental results using a real world attack scenario and a real network traffic capture is presented. Harsha K. Kalutarage, Chonho Lee, Siraj Ahmed Shaikh, Bu-Sung Lee |
CSCloud | 3 |
| 2014 | Selected contributions from the Open Source Software Certification (OpenCert) workshops
Luís Soares Barbosa, Siraj Ahmed Shaikh |
Sci. Comput. Program. | 2 |
| 2013 | Tracing Sources of Anonymous Slow Suspicious Activities
Harsha K. Kalutarage, Siraj Ahmed Shaikh, Qin Zhou 0004, Anne E. James |
NSS | 2 |
| 2011 | Who's your best friend?: targeted privacy attacks In location-sharing social networksabstractThis paper presents a study that aims to answer two important questions related to targeted location-sharing privacy attacks: (1) given a group of users and their social graph, is it possible to predict which among them is likely to reveal most about their whereabouts, and (2) given a user, is it possible to predict which among her friends knows most about her whereabouts. To answer these questions we analyse the privacy policies of users of a real-time location sharing application, in which users actively shared their location with their contacts. The results show that users who are central to their network are more likely to reveal most about their whereabouts. Furthermore, we show that the friend most likely to know the whereabouts of a specific individual is the one with most common contacts and/or greatest number of contacts. Vassilis Kostakos, Jayant Venkatanathan, Bernardo Reynolds, Norman M. Sadeh, Eran Toch, Siraj Ahmed Shaikh, Simon L. Jones |
UbiComp | 6 |
| 2011 | A Formal Approach to Analysing Knowledge Transfer Processes in Developing Countries
Jin Tong, Siraj Ahmed Shaikh, Anne E. James |
SEFM | 2 |
| 2010 | Optimising IDS Sensor PlacementabstractIn large network environments multiple intrusion detection sensors are needed to adequately monitor network traffic. However, deploying and managing additional sensors on a large network can be a demanding task, and organizations have to balance their desire for detecting intrusions throughout their network with financial and staffing limitations. This paper investigates how intrusion detection system (IDS) sensors should best be placed on a network when there are several competing evaluation criteria. This is a computationally difficult problem and we show how Multi-Objective Genetic Algorithms provide an excellent means of searching for optimal placements. Hao Chen 0032, John A. Clark, Siraj Ahmed Shaikh, Howard Chivers, Philip Nobles |
ARES | 3 |
| 2010 | Characteristic trade-offs in designing large-scale biometric-based identity management systems
Siraj Ahmed Shaikh, Joseph R. Rabaiotti |
J. Netw. Comput. Appl. | 1 |
| 2009 | Specifying authentication using signal events in CSP
Siraj Ahmed Shaikh, Vicky J. Bush, Steve A. Schneider |
Comput. Secur. | 1 |