EDBT 2026 Demo / reviewers in the wild / expert
Shambhu J. Upadhyaya
dblp:u/ShambhuJUpadhyaya
· DBLP profile ↗
83ranked-venue papers
12as first author
3since 2021 · last 2025
0000-0002-0596-1703ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 33 · 9 first-authorSecurity and privacy · 24 · 1 first-author · 3 since 2021Computer networks · 8Artificial intelligence and machine learning · 7Databases, data management, data science and information retrieval · 6Software engineering, systems software and programming languages · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Microft: Exploring and Mitigating Cross-State Control-Flow Hijacking Attacks on ARM Cortex-M TrustZone
Zheyuan Ma, Xi Tan 0002, Lukasz Ziarek, Ning Zhang 0017, Shambhu J. Upadhyaya, Hongxin Hu, Ziming Zhao 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Apt Detection of Ransomware - An Approach to Detect Advanced Persistent Threats Using System Call InformationabstractRansomware of the Advanced Persistent Threat (APT) type are very sophisticated and often have a contingency plan of attack in case they are discovered while the attack is in progress. Due to the ever-changing trait of such APT-type ransomware, an intelligent and robust intrusion detection system (IDS) is the need of the hour and in this paper, we put forward machine learning (ML) and natural language processing (NLP) based intrusion detection systems. We utilize a commercial simulator to run different real-world ransomware attacks to create, for the first time, a dataset for APT-type ransomware research. Then, we develop multiple IDSes by training ML models like support vector machine (SVM), logistic regression (LR), gradient boosting (GB) decision trees, random forest (RF), naive Bayes classifier (NBC), and an NLP model called BERT, on this dataset. With our intelligent IDS, we could precisely distinguish the system calls of processes spawned by ransomware from legitimate system calls. We compare the different intrusion detection systems developed using the six aforementioned models. The IDS using the NLP BERT model achieves the best accuracy of 99.98%, and the IDS using the Naive Bayes Classifier achieves an accuracy of 98.55%. Furthermore, we discuss the tradeoffs of these models for designing an intelligent IDS. The advancement in cyber attacks, especially ransomware-based attacks, necessitates this upgrade in IDS which is essential for a strong defense. Rudra Prasad Baksi, Vishwas Nalka, Shambhu J. Upadhyaya |
TrustCom | 3 |
| 2022 | Game Theoretic Analysis of Ransomware: A Preliminary Study
Rudra Prasad Baksi, Shambhu J. Upadhyaya |
ICISSP | 2 |
| 2018 | Synthetic Forgery Attack against Continuous Keystroke Authentication SystemsabstractKeystroke dynamics is an effective behavioral biometric for user authentication at a computer terminal. While many promising approaches have been proposed to enhance the recognition performance and several applications have been deployed to improve the system security level, the robustness under forgery attacks has not been well studied. In this paper, we propose a new approach to launch synthetic forgery attacks against the existing keystroke authentication systems. We analyze users' typing traits and select certain type of users who are good at imitating others from a large keystroke dataset and use their data to forge a master key. The attacks are launched under both zero effort as well as nonzero effort scenarios. Our initial results indicate that in the wake of the proposed synthetic impostor attack, the recognition rate can be weakened, thus exposing a significant vulnerability of current keystroke authentication systems. Shambhu J. Upadhyaya |
ICCCN | 2 |
| 2018 | Similarity Metrics for SQL Query ClusteringabstractDatabase access logs are the starting point for many forms of database administration, from database performance tuning, to security auditing, to benchmark design, and many more. Unfortunately, query logs are also large and unwieldy, and it can be difficult for an analyst to extract broad patterns from the set of queries found therein. Clustering is a natural first step towards understanding the massive query logs. However, many clustering methods rely on the notion of pairwise similarity, which is challenging to compute for SQL queries, especially when the underlying data and database schema is unavailable. We investigate the problem of computing similarity between queries, relying only on the query structure. We conduct a rigorous evaluation of three query similarity heuristics proposed in the literature applied to query clustering on multiple query log datasets, representing different types of query workloads. To improve the accuracy of the three heuristics, we propose a generic feature engineering strategy, using classical query rewrites to standardize query structure. The proposed strategy results in a significant improvement in the performance of all three similarity heuristics. Gökhan Kul, Duc Thanh Anh Luong, Ting Xie 0002, Varun Chandola, Oliver Kennedy, Shambhu J. Upadhyaya |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2017 | You've Been Tricked! A User Study of the Effectiveness of Typosquatting TechniquesabstractThe deceitful practice of Typosquatting involves deliberately registering Internet domain names containing typographical errors that primarily target popular domain names, in an effort to redirect users to unintended destinations or steal traffic for monetary gain. Typosquatting has existed for well over two decades and continues to be a credible threat to this day. While much of the prior work has examined various typosquatting techniques and how they change over time, none have considered how effective they are in deceiving users. In this paper, we attempt to fill in this gap by conducting a user study that exposes subjects to several uniform resource locators (URLs) in an attempt to determine the effectiveness of several typosquatting techniques that are prevalent in the wild. We also attempt to determine if the security education and awareness of cybercrimes such as typosquatting will affect the behavior of Internet users. Jeffrey Spaulding, Shambhu J. Upadhyaya, David Mohaisen |
ICDCS | 2 |
| 2016 | The Landscape of Domain Name Typosquatting: Techniques and CountermeasuresabstractWith more than 294 million registered domain names as of late 2015, the domain name ecosystem has evolved to become a cornerstone for the operation of the Internet. Domain names today serve everyone, from individuals for their online presence to big brands for their business operations. Such ecosystem that facilitated legitimate business and personal uses has also fostered "creative" cases of misuse, including phishing, spam, hit and traffic stealing, online scams, among others. As a first step towards this misuse, the registration of a legitimately-looking domain is often required. For that, domain typosquatting provides a great avenue to cybercriminals to conduct their crimes. In this paper, we review the landscape of domain name typosquatting, highlighting models and advanced techniques for typosquatted domain names generation, models for their monetization, and the existing literature on countermeasures. We further highlight potential fruitful directions on technical countermeasures that are lacking in the literature. Jeffrey Spaulding, Shambhu J. Upadhyaya, David Mohaisen |
ARES | 2 |
| 2016 | Building Long Term Trust in Vehicular NetworksabstractIn vehicular networks (VN), the response time is critical, whereas, an autonomous and efficient way of preventing hazardous situations on roads plays an important role in the successful deployment of the system. Trust or reputation models often need to be integrated with inter-vehicle communication protocols in use to avoid selfish or malicious behavior by the vehicles exploiting the system. Existing trust and reputation models for VNs lack the capability of fast and accurate trust management suitable for the ephemeral association of vehicles. In this paper, we design an augmented trust model for VNs by assigning each vehicle a long term trust value. Our model eliminates the overhead of repeated bootstrapping and ensures accountability of the vehicles for incident reporting and other critical actions. The two main features of our framework, viz. a three- party authentication and privacy protocol, and a trust propagation model, both of which are crucial for a successful deployment of VNs, can also be used in any generic security application. Tamal Biswas, Ameya Sanzgiri, Shambhu J. Upadhyaya |
VTC Spring | 3 |
| 2016 | Online shopping intention in the context of data breach in online retail stores: An examination of older and younger adults
Rajarshi Chakraborty, Jaeung Lee 0003, Sharmistha Bagchi-Sen, Shambhu J. Upadhyaya, H. Raghav Rao |
Decis. Support Syst. | 4 |
| 2014 | Factors influencing online health information search: An empirical analysis of a national cancer-related survey
Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2014 | Minimum Cost Blocking Problem in Multi-Path Wireless Routing ProtocolsabstractWe present a class of Minimum Cost Blocking (MCB) problems in Wireless Mesh Networks (WMNs) with multi-path routing protocols. We establish the provable superiority of multi-path routing protocols over conventional protocols against blocking, node-isolation and network-partitioning type attacks. In our attack model, an adversary is considered successful if he is able to capture/isolate a subset of nodes such that no more than a certain amount of traffic from source nodes reaches the gateways. Two scenarios, viz. (a) low mobility for network nodes, and (b) high degree of node mobility, are evaluated. Scenario (a) is proven to be NP-hard and scenario (b) is proven to be #P-hard for the adversary to realize the goal. Further, several approximation algorithms are presented which show that even in the best case scenario it is at least exponentially hard for the adversary to optimally succeed in such blocking-type attacks. These results are verified through simulations which demonstrate the robustness of multi-path routing protocols against such attacks. To the best of our knowledge, this is the first work that theoretically evaluates the attack-resiliency and performance of multi-path protocols with network node mobility. Qi Duan, Mohit Virendra, Shambhu J. Upadhyaya, Ameya Sanzgiri |
IEEE Trans. Computers | 3 |
| 2013 | Analysis of Malware Propagation in TwitterabstractMalware propagation in social networks is a potential risk that has not been well-studied yet as there are no formal threat models for social networks. In this paper we investigate the vulnerability and cost of spreading malware via Twitter. Towards this end we present three specific attack scenarios targeted for Twitter and systematically analyze the cost of staging each of these attacks. Our analysis presents the first step for understanding the threats on the security of a class of social networks. We identify the attack related parameters and verify these parameters by testing the attack on a Net Logo based simulator. Our analysis indicates that the cost of staging attacks to infect users of Twitter is low and that the proposed attack scenarios are plausible. Further, even with a low degree of connectivity and a low probability of clicking links, Twitter and its structure can be exploited by such attacks to infect many users with malware. Ameya Sanzgiri, Andrew Hughes, Shambhu J. Upadhyaya |
SRDS | 3 |
| 2012 | Data De-duplication and Event Processing for Security Applications on an Embedded ProcessorabstractNetwork security schemes generally deploy sensors and other network devices which generate huge volumes of data, overwhelming the underlying decision making algorithms. An example is corporate networks employing intrusion detection systems where there is a deluge of alert data, confounding the computations involved in sensor information fusion and alert correlation. One way to obtain fast and real-time responses is to preprocess such data to manageable sizes. In this paper, we show that data de-duplication using computationally efficient fingerprinting algorithms can provide real-time results. We present an algorithm which utilizes Rabin Fingerprinting/hashing scheme for the purpose of data de-duplication. We have implemented this algorithm on Intel Atom, which is a powerful, energy efficient embedded processor. Our study is intended to show that the relatively low performing embedded processors are capable of providing the needed computational support if they were to handle security functions in the field. When compared to the algorithmic performance on a high end system, viz. Intel Core 2 Duo processor, the positive results obtained make a case for using the Atom processor in networked applications employing mobile devices. Harsha Nagarajaiah, Shambhu J. Upadhyaya, Vinodh Gopal |
SRDS | 2 |
| 2012 | Assessing roles of people, technology and structure in emergency management systems: a public sector perspectiveabstractEmergency management systems are a critical factor in successful mitigation of natural and man-made disasters, facilitating responder decision making in complex situations. Based on socio-technical systems, have which four components (people, technology, structure and task), this study develops a research framework of factors affecting effective emergency management. People factors include psychological factors such as responders' self-efficacy, support from family, peers and community, and training. Technology factors are task technology and information sharing. The structure factors are leadership, labour and logistics. Finally, the task factor refers to effective emergency management. This study empirically tests this framework by collecting surveys from emergency responders who participated in the 2006 Buffalo October Storm. The research results demonstrate that training and support positively affect emergency management self-efficacy which, in turn, has a positive significant relationship with effective emergency management. Task technology and information sharing also have a positive impact on effective emergency management. However, findings suggest that the structure factors do not show a significant relationship with effective emergency management. This research presents that human factors in emergency management are essential to conduct effective operations. More importantly, investing in technology to assist responders in performing their jobs during the emergency is crucial during the emergency operations. Minkyun Kim, Raj Sharman, Catherine P. Cook-Cottone, H. Raghav Rao, Shambhu J. Upadhyaya |
Behav. Inf. Technol. | 5 |
| 2010 | A Data-Centric Approach to Insider Attack Detection in Database Systems
Sunu Mathew, Michalis Petropoulos, Hung Q. Ngo 0001, Shambhu J. Upadhyaya |
RAID | 4 |
| 2010 | A Multi-step Simulation Approach toward Secure Fault Tolerant System EvaluationabstractAs new techniques of fault tolerance and security emerge, so does the need for suitable tools to evaluate them. Generally, the security of a system can be estimated and verified via logical test cases, but the performance overhead of security algorithms on a system needs to be numerically analyzed. The diversity in security methods and design of fault tolerant systems make it impossible for researchers to come up with a standard, affordable and openly available simulation tool, evaluation framework or an experimental test-bed. Therefore, researchers choose from a wide range of available modeling-based, implementation-based or simulation-based approaches in order to evaluate their designs. All of these approaches have certain merits and several drawbacks. For instance, development of a system prototype provides a more accurate system analysis but unlike simulation, it is not highly scalable. This paper presents a multi-step, simulation-based performance evaluation methodology for secure fault tolerant systems. We use a divide-and-conquer approach to model the entire secure system in a way that allows the use of different analytical tools at different levels of granularity. This evaluation procedure tries to strike a balance between the efficiency, effort, cost and accuracy of a system's performance analysis. We demonstrate this approach in a step-by-step manner by analyzing the performance of a secure and fault tolerant system using a JAVA implementation in conjunction with the ARENA simulation. Ruchika Mehresh, Shambhu J. Upadhyaya, Kevin A. Kwiat |
SRDS | 2 |
| 2010 | Secure Distance-Based Localization in the Presence of Cheating Beacon NodesabstractSecure distance-based localization in the presence of cheating beacon (or anchor) nodes is an important problem in mobile wireless ad hoc and sensor networks. Despite significant research efforts in this direction, some fundamental questions still remain unaddressed: In the presence of cheating beacon nodes, what are the necessary and sufficient conditions to guarantee a bounded error during a two-dimensional distance-based location estimation? Under these necessary and sufficient conditions, what class of localization algorithms can provide this error bound? In this paper, we attempt to answer these and other related questions by following a careful analytical approach. Specifically, we first show that when the number of cheating beacon nodes is greater than or equal to a given threshold, there do not exist any two-dimensional distance-based localization algorithms that can guarantee a bounded error. Furthermore, when the number of cheating beacons is below this threshold, we identify a class of distance-based localization algorithms that can always guarantee a bounded localization error. Finally, we outline three novel distance-based localization algorithms that belong to this class of bounded error localization algorithms. We verify their accuracy and efficiency by means of extensive simulation experiments using both simple and practical distance estimation error models. Murtuza Jadliwala, Sheng Zhong 0002, Shambhu J. Upadhyaya, Chunming Qiao, Jean-Pierre Hubaux |
IEEE Trans. Mob. Comput. | 3 |
| 2009 | Towards a theory for securing time synchronization in wireless sensor networksabstractTime synchronization in highly distributed wireless systems like sensor and ad hoc networks is extremely important in order to maintain a consistent notion of time throughout the network and to support the various timing-based applications. But, cheating behavior by the participating nodes in the network can severely jeopardize the accuracy of the associated time synchronization process. Despite recent advances in this direction, a key fundamental question still remains unanswered: Is it theoretically feasible to secure distributed time synchronization protocols, given complete (or global) time and time difference information in the network? Murtuza Jadliwala, Qi Duan, Shambhu J. Upadhyaya, Jinhui Xu 0001 |
WISEC | 3 |
| 2008 | Insider abuse comprehension through capability acquisition graphs
Sunu Mathew, Shambhu J. Upadhyaya, Duc T. Ha, Hung Q. Ngo 0001 |
FUSION | 2 |
| 2008 | Inferring Sources of Leaks in Document Management Systems
Madhusudhanan Chandrasekaran, Vidyaraman Sankaranarayanan, Shambhu J. Upadhyaya |
IFIP Int. Conf. Digital Forensics | 3 |
| 2008 | Towards a Theory of Robust Localization Against Malicious Beacon NodesabstractLocalization in the presence of malicious beacon nodes is an important problem in wireless networks. Although significant progress has been made on this problem, some fundamental theoretical questions still remain unanswered: in the presence of malicious beacon nodes, what are the necessary and sufficient conditions to guarantee a bounded error during 2-dimensional location estimation? Under these necessary and sufficient conditions, what class of localization algorithms can provide that error bound? In this paper, we try to answer these questions. Specifically, we show that, when the number of malicious beacons is greater than or equal to some threshold, there is no localization algorithm that can have a bounded error. Furthermore, when the number of malicious beacons is below that threshold, we identify a class of localization algorithms that can ensure that the localization error is bounded. We also outline two algorithms in this class, one of which is guaranteed to finish in polynomial time (in the number of beacons providing information) in the worst case, while the other is based on a heuristic and is practically efficient. For completeness, we also extend the above results to the 3-dimensional case. Experimental results demonstrate that our solution has very good localization accuracy and computational efficiency. Sheng Zhong 0002, Murtuza Jadliwala, Shambhu J. Upadhyaya, Chunming Qiao |
INFOCOM | 3 |
| 2008 | Security in grid computing: A review and synthesis
Erin Cody, Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2008 | Defect Analysis and Defect Tolerant Design of Multi-port SRAMs
Lushan Liu, Pradeep Nagaraj, Shambhu J. Upadhyaya, Ramalingam Sridhar |
J. Electron. Test. | 3 |
| 2008 | Design Considerations for High Performance RF Cores Based on Process Variation Study
Shambhu J. Upadhyaya, Nandakumar P. Venugopal, Nihal Shastry, Srinivasan Gopalakrishnan, Bharath V. Kuppuswamy, Rana Bhowmick, Prerna Mayor |
J. Electron. Test. | 1 |
| 2007 | Towards Modeling Trust Based Decisions: A Game Theoretic Approach
Vidyaraman Sankaranarayanan, Madhusudhanan Chandrasekaran, Shambhu J. Upadhyaya |
ESORICS | 3 |
| 2007 | On the Hardness of Minimum Cost Blocking Attacks on Multi-Path Wireless Routing ProtocolsabstractThis paper demonstrates the provable superiority of multi-path routing protocols over other conventional protocols in Wireless Mesh Networks (WMNs) against blocking, node- isolation and network-partitioning type-attacks. Though the underlying network model is of a WMN with mobile nodes, the results in this paper are equally applicable to other types of wireless data networks. The adversarial objective is to isolate a subset of network nodes through minimal cost optimal blocking of certain number of paths in the network (or partitioning the network). If less than a certain threshold of traffic from such node(s) reaches the routers, the adversary is successful. Two scenarios viz. (a) low mobility for network nodes, and (b) high degree of node mobility, are evaluated. Scenario (a) is proven to be NP-hard and scenario (b) is proven to be #P-hard for the adversary to achieve the goal. Further, several approximation algorithms are presented which show that even in the best case scenario it is at least exponentially hard for the adversary to optimally succeed in such blocking-type attacks. Simulations verify the results and demonstrate the robustness of multi-path protocols against such attacks. The objective of this paper is to study the performance and feasibility of multi-path wireless protocols over conventional single-path protocols from a security angle. To the best of our knowledge, this is the first paper to theoretically evaluate the attack-resiliency and performance of multi-path protocols with network node mobility. Qi Duan, Mohit Virendra, Shambhu J. Upadhyaya |
ICC | 3 |
| 2007 | Insider Threat Analysis Using Information-Centric ModelingabstractCapability acquisition graphs (CAGs) provide a powerful framework for modeling insider threats, network attacks and system vulnerabilities. However, CAG-based security modeling systems have yet to be deployed in practice. This paper demonstrates the feasibility of applying CAGs to insider threat analysis. In particular, it describes the design and operation of an information-centric, graphics-oriented tool called ICMAP. ICMAP enables an analyst without any theoretical background to apply CAGs to answer security questions about vulnerabilities and likely attack scenarios, as well as to monitor network nodes. This functionality makes the tool very useful for attack attribution and forensics. Duc T. Ha, Shambhu J. Upadhyaya, Hung Q. Ngo 0001, Suranjan Pramanik, Ramkumar Chinchani, Sunu Mathew |
IFIP Int. Conf. Digital Forensics | 2 |
| 2007 | SpyCon: Emulating User Activities to Detect Evasive SpywareabstractThe success of any spyware is determined by its ability to evade detection. Although traditional detection methodologies employing signature and anomaly based systems have had reasonable success, new class of spyware programs emerge which blend in with user activities to avoid detection. One of the latest anti-spyware technologies consists of a local agent that generates honeytokens of known parameters (e.g., network access requests) and tricks spyware into assuming it to be legitimate activity. In this paper, as a first step, we address the deficiencies of static honeytoken generation and present an attack that circumvents such detection techniques. We synthesize the attack by means of data mining algorithms like associative rule mining. Next, we present a randomized honeytoken generation mechanism to address this new class of spyware. Experimental results show that (i) static honeytokens are detected with near 100% accuracy, thereby defeating the state-of-the-art anti-spyware technique, (ii) randomized honeytoken generation mechanism is an effective anti-spyware solution. Madhusudhanan Chandrasekaran, Vidyaraman Sankaranarayanan, Shambhu J. Upadhyaya |
IPCCC | 3 |
| 2007 | Surface Transportation and Cyber-Infrastructure: An Exploratory StudyabstractUsing IT applications is essential for the productive, safe and reliable transportation service. However, there are concerns regarding the cybersecurity vulnerability of IT applications. In this study, we investigate the role of IT in the surface transportation security based on responses from mid and high level managers in transportation industries. Our survey results indicate that managers of the transportation industry think IT applications are fundamental components in the surface transportation operation and security. However, they are highly concern about cybersecurity threats on IT applications. Our research findings contribute to provide the understating of the sate of IT application on surface transportation systems and cybersecurity threats. Our research results and analysis are discussed in this paper. Sangmi Chai, Raj Sharman, Smitha Patil, Shruta Satam, H. Raghav Rao, Shambhu J. Upadhyaya |
ISI | 6 |
| 2007 | Position: the user is the enemyabstractThe Human Factor has long been recognized as the weakest link in computer systems security, yet, nothing technically significant has been done to address this problem in an attack agnostic manner. In this paper, we introduce the mantra of "The User is the Enemy" for security designers and developers alike as an underlying current towards addressing the weak human factor. We present different notions of the user and the system and argue from parallel tracks that user actions, both ignorant and non-compliant, are detrimental to the organization. We further show how the paradigm has been applied in a rather unconscious manner and contend that security mechanisms borne out of a conscious application will be more effective towards addressing this systemic problem. Our position is not meant to be a cynical attitude towards users; rather, it is meant to be the focal point of security design attitude, similar to the mantra "All user input is evil" for addressing buffer overflow attacks. Vidyaraman Sankaranarayanan, Madhusudhanan Chandrasekaran, Shambhu J. Upadhyaya |
NSPW | 3 |
| 2007 | ASFALT: A Simple Fault-Tolerant Signature-based Localization Technique for Emergency Sensor NetworksabstractWe consider the problem of robust node deployment and fault-tolerant localization in wireless sensor networks for emergency and first response applications. Signature-based localization algorithms are a popular choice for use in such applications due to the non-uniform nature of the sensor node deployment. But, random destruction/disablement of sensor nodes in such networks adversely affects the deployment strategy as well as the accuracy of the corresponding signature-based localization algorithm. In this paper, we first model the phenomenon of sensor node destruction as a non-homogeneous Poisson process and derive a robust and efficient strategy for sensor node deployment based on this model. Next, we outline a protocol, called Group Selection Protocol, that complements current signature-based algorithms by reducing localization errors even when some nodes in a group are destroyed. Finally, we propose a novel yet simple localization technique, ASFALT, that improves the efficiency of the localization process by combining the simplicity of range-based schemes with the robustness of signature-based ones. Simulation experiments are conducted to verify the performance of the proposed algorithms. Murtuza Jadliwala, Shambhu J. Upadhyaya, Manik Taneja |
SRDS | 2 |
| 2007 | Self-healing systems - survey and synthesis
Debanjan Ghosh, Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2007 | Efficiency of critical incident management systems: Instrument development and validation
Jin Ki Kim, Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2007 | Short Term and Total Life Impact analysis of email worms in computer systems
Insu Park, Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2006 | Detecting Masquerading Users in a Document Management SystemabstractA Document Management System (DMS) is a repository of digital documents that provides functionality for check-in, check-out and shared editing. In a DMS, security mechanisms like encryption of documents and enforcement of policies are implemented to protect from information leakage. These security schemes, essentially applications of Digital Rights Management technologies, while effective against external attacks, are ineffective against insider attacks. The typical insider in a DMS already has access to documents and hence, his capabilities for information leakage are much higher. In this work, we address an important, yet unexplored problem of masquerading users in a DMS, a threat for which the DMS inherently has no protection. We approach the problem by monitoring the pattern and mannerism of user actions on documents and building a profile of each user using the resulting logs. In order to illustrate our ideas, we built user profiles of 41 users working on Microsoft Word and applied two algorithms, viz., IPAM and Naïve Bayes to distinguish between them. When supplied with appropriately interpreted command sequences of a DMS, IPAM was able to distinguish between users effectively, while Naïve Bayes failed to produce any meaningful results. We recorded an average detection rate of 58% with a false positive of 14%. Vidyaraman Sankaranarayanan, Suranjan Pramanik, Shambhu J. Upadhyaya |
ICC | 3 |
| 2006 | AVARE: aggregated vulnerability assessment and response against zero-day exploitsabstractIn this paper we propose an automated approach for determining recently published vulnerabilities pertinent to the current network/system configuration using the information aggregated from different bug tracking communities. Such vulnerability assessment and indication mechanisms significantly alleviate the system administrator's burden of manual content digging for vulnerabilities in his/her own configuration context. Furthermore, we propose an extensible defense oriented representation schema (EDORS) for vulnerability representation, which is consequently used by the policy engine to generate appropriate IDS signatures. As a result, the generated signatures can be viewed as a preventive stop-gap security measure against zero-day exploits until its patch is released. In the absence of precise detection signatures, we extend our framework to perform forensic analysis on the alerts generated, by constructing Bayesian causality graphs to assess the impact and extent of the attack. The preliminary experiments carried out suggest that our approach is able to analyze the system/network for even the most recent zero-day vulnerabilities and generate their corresponding signatures with very minimal performance and administrative overhead. Madhusudhanan Chandrasekaran, Mukarram Baig, Shambhu J. Upadhyaya |
IPCCC | 3 |
| 2006 | Understanding multistage attacks by attack-track based visualization of heterogeneous event streamsabstractIn this paper, we present a method of handling the visualization of hetereogeneous event traffic that is generated by intrusion detection sensors, log files and other event sources on a computer network from the point of view of detecting multistage attack paths that are of importance. We perform aggregation and correlation of these events based on their semantic content to generate Attack Tracks that are displayed to the analyst in real-time. Our tool, called the Event Correlation for Cyber-Attack Recognition System (EC-CARS) enables the analyst to distinguish and separate an evolving multistage attack from the thousands of events generated on a network. We focus here on presenting the environment and framework for multistage attack detection using ECCARS along with screenshots that demonstrate its capabilities. Sunu Mathew, Richard Giomundo, Shambhu J. Upadhyaya, Moises Sudit, Adam Stotz |
VizSEC | 3 |
| 2006 | PHONEY: Mimicking User Response to Detect Phishing AttacksabstractPhishing scams pose a serious threat to end-users and commercial institutions alike. Email continues to be the favorite vehicle to perpetrate such scams mainly due to its widespread use combined with the ability to easily spoof them. Several approaches, both generic and specialized, have been proposed to address this problem. However, phishing techniques, growing in ingenuity as well as sophistication, render these solutions weak. In this paper we propose a novel approach to detect phishing attacks using fake responses which mimic real users, essentially, reversing the role of the victim and the adversary. Our prototype implementation called PHONEY, sits between a user's mail transfer agent (MTA) and mail user agent (MUA) and processes each arriving email for phishing attacks. Using live email data collected over a period of eight months we demonstrate data that our approach is able to detect a wider range of phishing attacks than existing schemes. Also, the performance analysis study shows that the implementation overhead introduced by our tool is very negligible. Madhusudhanan Chandrasekaran, Ramkumar Chinchani, Shambhu J. Upadhyaya |
WOWMOM | 3 |
| 2006 | Design of a wireless test control network with radio-on-chip technology for nanometer system-on-a-chipabstractThe continued push to smaller geometries, higher frequencies, and larger chip sizes rapidly resulted in an incompatibility between interconnect needs and projected interconnect performance. As stated in the 2003 International Technology Roadmap for Semiconductors (ITRS'03) report, revolutionary interconnect methodologies such as radio frequency (RF)/wireless will deliver the foreseen progress in semiconductor technology. Recent advances in silicon integrated circuit technique are making possible tiny low-cost transceivers to be integrated on chip, namely "radio-on-chip" (ROC) technology. This paper proposes the idea of using wireless radios to transmit test data and control signals to resolve the acerbated core accessibility problem. Three types of wireless test micronetworks are first presented, i.e., miniature wireless local area network (LAN), multihop wireless test control network (MTCNet), and distributed multihop MTCNet. Then, the test control overhead and system resource partitioning in on-chip wireless micronetworks are analyzed. Several challenging system design problems such as RF node placement, core clustering, and control routing are studied, and the test control resources (i.e., the on-chip RF nodes for intrachip communication) are properly distributed and system optimization is performed in terms of test control cost. A simulation study shows the feasibility and applicability of intrachip MTCNet. Danella Zhao, Shambhu J. Upadhyaya, Martin Margala |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2005 | Towards a Theory of Insider Threat AssessmentabstractInsider attacks are a well-known problem acknowledged as a threat as early as 1980s. The threat is attributed to legitimate users who abuse their privileges, and given their familiarity and proximity to the computational environment, can easily cause significant damage or losses. Due to the lack of tools and techniques, security analysts do not correctly perceive the threat, and hence consider the attacks as unpreventable. In this paper, we present a theory of insider threat assessment. First, we describe a modeling methodology which captures several aspects of insider threat, and subsequently, show threat assessment methodologies to reveal possible attack strategies of an insider. Ramkumar Chinchani, Anusha Iyer, Hung Q. Ngo 0001, Shambhu J. Upadhyaya |
DSN | 4 |
| 2005 | A new SoC test architecture with RF/wireless connectivityabstractWhen moving into the billion-transistor era, the direct or bus interconnects in conventional SoC test control models are rather restricted in not only system performance, but also signal integrity and transmission with continued scaling of the feature size. Recent advances in silicon integrated circuit technology are making possible tiny low-cost transceivers to be integrated on chip. In this paper, we propose a new distributed multihop wireless test control network based on the recent development in "radio-on-chip" technology. Under the multilevel tree structure, the system optimization is performed on control constrained resource partitioning and distribution. Several challenging system design issues, such as RF nodes placement, clustering, and routing are studied, with the integrated resource distribution and system optimization on TAM design and test scheduling. Experimental results show that the proposed algorithm can efficiently minimize the overall testing cost. Danella Zhao, Shambhu J. Upadhyaya, Martin Margala |
ETS | 2 |
| 2005 | Design Principles of Coordinated Multi-incident Emergency Response Systems
Rui Chen 0002, Raj Sharman, H. Raghav Rao, Shambhu J. Upadhyaya |
ISI | 4 |
| 2005 | Information assurance metric development framework for electronic bill presentment and payment systems using transaction and workflow analysis
G. B. Tanna, Manish Gupta 0004, H. Raghav Rao, Shambhu J. Upadhyaya |
Decis. Support Syst. | 4 |
| 2005 | Dynamically partitioned test scheduling with adaptive TAM configuration for power-constrained SoC testingabstractGiven a system-on-chip with a set of cores and a set of test resources, and the constraints on the total power consumption during test and the maximum width on the top-level test access mechanism (TAM), it is required to optimize overall testing time of the system. To solve this problem, we first generate a power-constrained test compatibility graph and then construct a set of power-constrained concurrent test sets (PCTSs) to facilitate concurrent testing. We then handle the constrained scheduling by adaptively assigning the cores in parallel to the TAMs with variable width and efficiently utilizing the TAM bandwidth such that the tests in the same PCTS have their lengths close to each other. We concurrently schedule the test sets by dynamically partitioning and allocating the tests, and consequently constructing and updating a set of dynamically partitioned PCTSs. This reduces the test cost in terms of overall test time. Simulation study shows the productivity gained by using our integrated scheduling approach. Danella Zhao, Shambhu J. Upadhyaya |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2004 | A conceptual approach to information security in financial account aggregationabstractAn important dimension of mobile computing is the ubiquitous and location-independent availability of data. Aggregation is the ability to electronically access and display personal account information from disparate sources through a single identity. The client financial data is assembled in an organized format providing meaningful summarization and analysis. The prevalent methods of aggregation pose issues in information security and assurance. Utilizing advances in Internet technology such as web services and SOAP coupled with the best of the present approaches to aggregation we can arrive at better solutions to securing the identity and data of aggregation customers. The paper puts forth conceptual solutions to address issues regarding security of user profile and identifying aggregators masquerading as users through processes such as screen scraping. Manish Agrawal, Hemant Padmanabhan, Lokesh Pandey, H. Raghav Rao, Shambhu J. Upadhyaya |
ICEC | 5 |
| 2004 | RACOON: Rapidly Generating User Command Data For Anomaly Detection From Customizable TemplatesabstractOne of the biggest obstacles faced by user command based anomaly detection techniques is the paucity of data. Gathering command data is a slow process often spanning months or years. In this paper, we propose an approach for data generation based on customizable templates, where each template represents a particular user profile. These templates can either be user-defined or created from known data sets. We have developed an automated tool called RACOON, which rapidly generates large amounts of user command data from a given template. We demonstrate that our technique can produce realistic data by showing that it passes several statistical similarity tests with real data. Our approach offers significant advantages over passive data collection in terms of being nonintrusive and enabling rapid generation of site-specific data. Finally, we report the benchmark results of some well-known algorithms against an original data set and a generated data set. Ramkumar Chinchani, Aarthie Muthukrishnan, Madhusudhanan Chandrasekaran, Shambhu J. Upadhyaya |
ACSAC | 4 |
| 2004 | Security Policies to Mitigate Insider Threat in the Document Control DomainabstractWith rapid advances in online technologies, organizations are migrating from paper based resources to digital documents to achieve high responsiveness and ease of management. These digital documents are the most important asset of an organization and are hence the chief target of insider abuse. Security policies provide the first step to prevent abuse by defining proper and improper usage of resources. Coarse grained security policies that operate on the "principle of least privilege" [J. H. Saltzer et al., (1974)] alone are not enough to address the insider threat, since the typical insider possesses a wide range of privileges to start with. In this paper, we propose a security policy that is tailored to prevent insider abuse. We define the concept of subject, object, actions, rights, context and information flow as applicable to the document control domain. Access is allowed based on the principles of "least privilege and minimum requirements", subject to certain constraints. Unlike existing techniques, the proposed policy engine considers, among other factors, the context of a document request and the information flow between such requests to identify potential malicious insiders. Enforcing these fine-grained access control policies gives us a better platform to prevent the insider abuse. Finally, for demonstration purposes, we present a framework that can be used to specify and enforce these policies on Microsoft Word documents, one of the popular document formats. Suranjan Pramanik, Vidyaraman Sankaranarayanan, Shambhu J. Upadhyaya |
ACSAC | 3 |
| 2004 | ARCHERR: Runtime Environment Driven Program Safety
Ramkumar Chinchani, Anusha Iyer, Bharat Jayaraman, Shambhu J. Upadhyaya |
ESORICS | 4 |
| 2004 | Data Mining for Intrusion Detection: Techniques, Applications and SystemsabstractAn intrusion is defined as any set of actions that compromise the integrity, confidentiality or availability of a resource. Intrusion detection is an important task for information infrastructure security. One major challenge in intrusion detection is that we have to identify the camouflaged intrusions from a huge amount of normal communication activities. Data mining is to identify valid, novel, potentially useful, and ultimately understandable patterns in massive data. It is demanding to apply data mining techniques to detect various intrusions. In the last several years, some exciting and important advances have been made in intrusion detection using data mining techniques. Research results have been published and some prototype systems have been established. Inspired by the huge demands from applications, the interactions and collaborations between the communities of security and data mining have been boosted substantially. This seminar will present an interdisciplinary survey of data mining techniques for intrusion detection so that the researchers from computer security and data mining communities can share the experiences and learn from each other. Some data mining based intrusion detection systems will also be reviewed briefly. Moreover, research challenges and problems will be discussed so that future collaborations may be stimulated. For data mining/database researchers and practitioners, the seminar will provide background knowledge and opportunities for applying data mining techniques to intrusion detection and computer security. For computer security researchers and practitioners, it provides knowledge on how data mining can benefit and enhance computer security. We will try to understand and appreciate the following technical issues. Jian Pei 0001, Shambhu J. Upadhyaya, Faisal Farooq, Venu Govindaraju |
ICDE | 2 |
| 2004 | A Framework for a Secure Federated Patient Healthcare System
Raj Sharman, Himabindu Challapalli, H. Raghav Rao, Shambhu J. Upadhyaya |
ISI | 4 |
| 2004 | Recovery schemes for mesh arrays utilizing dedicated sparesabstractIn this paper, new schemes are presented in which the spare nodes of a permanent-fault-tolerant processing array are utilized in their idling state to aid in an online transient-error recovery process. Though spares-based methods are well-known solutions to permanent-fault tolerance, the cost of these solutions and the idling spare capacity during normal operation have limited their widespread use. Manufacturers must be offered fault tolerance solutions which provide useful work at all times. We propose the enhanced utility of spares-based methods by commissioning idling spares (those spares remaining after fabrication and subsequent replacement of faulty units) to perform transient-error recovery tasks. Our scheme will commission idling spares to perform periodic on-line testing (verifying whether system is functioning correctly), and recovery point validation during normal operation. When an error occurs, the spare will perform additional testing to select recovery points. Transient-error recovery is required in harsh environments, such as high radiation, where frequent transient errors are unavoidable. In these environments, the cost of job completion can be extremely high without some form of error recovery. Successful job completion can be attained in environments frequented by error bursts by identifying reliable data through the process of periodic on-line testing. We apply our scheme to a mesh array architecture that has applications in digital signal processing. Simulations highlight the overhead of our schemes in terms of job completion time in environments burdened with frequent transient random errors and burst errors. The proposed strategies for recovery are limited to systems of regular structure. There are many applications in signal and image processing that require array processing in which the various nodes perform similar operations with different data sets. Therefore, it is not necessary to switch the application algorithms for the spares when they perform redundant computation in a staggered mode. While this is a significant feature, there is a small cost associated with presenting the same data to a node as well as a spare. With built-in hardware and reconfiguration switches in the fault tolerant arrays, we believe this cost will be insignificant. Extension of our work to more general systems requires consideration of many issues including system timing, and sub-unit communication & dependence. This is a problem for future research. Stephanie R. Goldberg, Shambhu J. Upadhyaya, W. Kent Fuchs |
IEEE Trans. Reliab. | 2 |
| 2003 | Power Constrained Test Scheduling with Dynamically Varied TAMabstractIn this paper we present a novel scheduling algorithm for testing embedded core-based SoCs. Given test conflicts, power consumption limitation and top level test access mechanism (TAM) constraint, we handle the constrained scheduling in a unique way that adaptively assigns the cores in parallel to the TAMs with variable width and concurrently executes the test sets by dynamic test partitioning, thus reducing the test cost in terms of the overall test time. Through simulation, we show that up to 30% of SoC testing time reduction can be achieved by using our scheduling approach. Danella Zhao, Shambhu J. Upadhyaya |
VTS | 2 |
| 2003 | Guest Editorial: Special Issue on Reliable Distributed SystemsabstractESIGNERS of distributed systems are concerned with developing architectures, networking, software, algorithms, and applications. While research in this direction addresses some of the fundamental issues in distributed computing, topics related to modeling and simulation of multiple processor systems, real-time operation, reliability, fault tolerance, information assurance, performance measurements, and evaluation are also critical for the successful functioning of distributed systems. The purpose of this special issue is to serve researchers, designers, and implementers of distributed systems, with emphasis on system properties such as reliability, availability, and performability. In addition to conceptual advancement, this issue is intended to recognize the efforts that are aimed toward experimentation, testbeds, development, exploratory or emerging applications, and measurements from operational systems. The theme of this special issue was made to coincide with the 19th IEEE Symposium on Reliable Distributed Systems held at Nuernberg, Germany, 2000, but the topics and submissions were not restricted to the proceedings of this symposium. We received a total of 55 submissions, of which we selected 11 regular papers. Every submission was sent to at least five referees. We received a total of 201 reviews back from 141 referees. Several papers that are not included in this special issue have been forwarded for consideration in the regular issues of this transaction. Although we wanted to have a good mix of current, successful efforts, innovative ideas on reliable designs and open problems—both conceptual and experimental, the space limitation in the special issue and the type of submissions we received may have precluded some key topics of reliable distributed systems. Yet, we believe that the special issue encompasses major properties of a reliable distributed system. The selected papers are classified into four groups: Shambhu J. Upadhyaya, Andrea Bondavalli |
IEEE Trans. Computers | 1 |
| 2002 | Time Slot Specification Based Approach to Analog Fault Diagnosis Using Built-in Current Sensors and Test Point InsertionabstractTesting and diagnosis of analog circuits continues to be a hard task for test engineers and efficient test methodologies to tackle these problems are needed. This paper proposes a novel analog test method using time slot specification (TSS) based built-in current sensors. A technique for location of a fault site and fault type, based on TSS, is presented. The proposed built-in current sense and decision module (BSDM), in association with TSS analysis, has high testability and good fault coverage, and a capability to diagnose catastrophic faults and parametric faults in analog circuits. The digital output of the BSDM can be easily combined with built-in digital test modules for mixed-signal IC testing. The general heuristics for test point placement are also described. Shambhu J. Upadhyaya, Padmanabhan Nair |
Asian Test Symposium | 1 |
| 2002 | Minimizing concurrent test time in SoC's by balancing resource usageabstractWe present a novel test scheduling algorithm for embedded core-based SoC's. Given a system integrated with a set of cores and a set of test resources, we select a test for each core from a set of alternative test sets, and schedule it in a way that evenly balances the resource usage, and ultimately reduce the test application time. Furthermore, we propose a novel approach that groups the cores and assigns higher priority to those with smaller number of alternate test sets. In addition, we also extend the algorithm to allow multiple test sets selection from a set of alternatives to facilitate testing for various fault models. Danella Zhao, Shambhu J. Upadhyaya, Martin Margala |
ACM Great Lakes Symposium on VLSI | 2 |
| 2001 | An Analytical Framework for Reasoning about IntrusionsabstractLocal and wide area network information assurance analysts need current and precise knowledge about their system activities in order to address the challenges of critical infrastructure protection. In particular, the analyst needs to know in real-time that an intrusion has occurred so that an active response and recovery thread can be created rapidly. Existing intrusion detection solutions are basically after-the-fact, thereby offering very little in terms of damage confinement and restoration of service. Quick recovery is only possible if the assessment scheme has low latency and it occurs in real-time. The objective of the paper is to develop a reasoning framework to aid in the real-time detection and assessment task that is based on a novel idea of encapsulation of owner's intent. The theoretical framework developed here will help resolve dubious circumstances that may arise while inferring the premises of operations (encapsulated from owner's intent) by way of examining the observed conclusions resulting from the actual operations of the owner. This reasoning is significant in view of the fact that intrusion signaling is not a binary decision unlike error detection in traditional fault tolerance. Our reasoning framework has been developed by leveraging the concepts of cost analysis and pricing under uncertainty found in economics and finance. Our main result is the modeling of user activity on a computing system as a martingale and the subsequent quantification of the cost of performing a job to enable decision making. Shambhu J. Upadhyaya, Ramkumar Chinchani, Kevin A. Kwiat |
SRDS | 1 |
| 2001 | Automatic generation and compaction of March tests for memory arraysabstractGiven a set of memory array faults, the problem of computing a compact March test that detects all specified memory array faults is addressed. In this paper, we propose a novel approach in which every memory array fault is modeled by a set of primitive memory faults. A primitive March test is defined for each primitive memory fault. We show that March tests that detect the specified memory array faults are composed of primitive March tests. A method to compact the March tests for the specified memory array faults is described. A set of examples to illustrate the approach is presented. Experimental results demonstrate the productivity gained using the proposed framework. Kamran Zarrineh, Shambhu J. Upadhyaya, Sreejit Chakravarty |
IEEE Trans. Very Large Scale Integr. Syst. | 2 |
| 2000 | Design and Analysis of an Integrated Checkpointing Recovery Scheme for Distributed ApplicationsabstractAn integrated checkpointing and recovery scheme which exploits the low latency and high coverage characteristics of a concurrent error detection scheme is presented. Message dependency, which is the main source of multistep rollback in distributed systems, is minimized by using a new message validation technique derived from the notion of concurrent error detection. The concept of a new global state matrix is introduced to track error checking and message dependency in a distributed system and assist in the recovery. The analytical model, algorithms and data structures to support an easy implementation of the new scheme are presented. The completeness and correctness of the algorithms are proved. A number of scenarios and illustrations that give the details of the analytical model are presented. The benefits of the integrated checkpointing scheme are quantified by means of simulation using an object-oriented test framework. Bina Ramamurthy, Shambhu J. Upadhyaya, Bharat K. Bhargava |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1999 | On Programmable Memory Built-In Self Test ArchitecturesabstractThe design and architectures of a microcode-based memory BIST and programmable FSM-based memory BIST unit are presented. The proposed microcode-based memory BIST unit is more efficient and flexible than existing architectures. Test logic overhead of the proposed programmable versus nonprogrammable memory BIST architectures is evaluated. The proposed programmable memory BIST architectures could be used to test memories in different stages of their fabrication and therefore result in lower overall memory test logic overhead. We show that the proposed microcode-based memory BIST architecture has better extendibility and flexibility while having less test logic overhead than the programmable PSM-based memory BIST architecture. Kamran Zarrineh, Shambhu J. Upadhyaya |
DATE | 2 |
| 1999 | A New Framework For Automatic Generation, Insertion and Verification of Memory Built-In Self Test UnitsabstractThe design and architecture of a memory test synthesis framework for automatic generation, insertion and verification of memory BIST units is presented. We use a building block architecture which results in full customization of memory BIST units. The flexibility and efficiency of the framework are demonstrated by showing that memory BIST units with different architecture and characteristics could be generated, functionally verified and inserted in a short time. Custom memory test algorithms could be loaded in the supported programmable BIST unit and therefore any type of memory test algorithm could be realized. Kamran Zarrineh, Shambhu J. Upadhyaya |
VTS | 2 |
| 1998 | A new framework for generating optimal March tests for memory arraysabstractGiven a set of memory array faults the problem of computing an optimal March test that detects all specified memory array faults is addressed. In this paper, we propose a novel approach in which every memory army fault is modeled by a set of primitive memory faults. A primitive March test is defined for each primitive memory fault. We show that March tests that detect the specified memory array faults are composed of primitive March tests. A method to compute the optimal March tests for the specified memory array faults is described. A set of examples to illustrate the approach is presented. Kamran Zarrineh, Shambhu J. Upadhyaya, Sreejit Chakravarty |
ITC | 2 |
| 1998 | Design and Analysis of a Hardware-Assisted Checkpointing and Recovery Scheme for Distributed ApplicationsabstractA checkpointing and recovery scheme which exploits the low latency and high coverage characteristics of a hardware error detection scheme is presented. Message dependency which is the main source of multi-step rollback in distributed systems is minimized by using a new message validation technique derived from hardware-assisted error detection. The main contribution of this paper is the development of an analytical model to establish the completeness and correctness of the new scheme. A novel concept of global state matrix is defined to keep track of the global state in a distributed system and assist in recovery. An illustration is given to show the distinction between conventional and the new recovery schemes. Bina Ramamurthy, Shambhu J. Upadhyaya, Bharat K. Bhargava |
SRDS | 2 |
| 1998 | Automatic Insertion of Scan Structures to Enhance Testability of Embedded Memories, Cores and ChipsabstractThis paper describes a technology independent test synthesis framework to enhance the testability of embedded memories, cores and chips using extended LSSD boundary scan methodology. Extended LSSD boundary scan reuses functional storage elements and therefore introduces minimal test logic overhead and delay. Automatic insertion of this DFT methodology is particularly challenging since it involves identification and reconfiguration of the functional latches and logic transformations of I/O cells. Experimental results demonstrate the productivity gained using the proposed test synthesis framework as well as the overlead induced by the proposed DFT method. Kamran Zarrineh, Shambhu J. Upadhyaya, Philip Shephard III |
VTS | 2 |
| 1998 | Component-ontological representation of function for reasoning about devices
Amruth N. Kumar, Shambhu J. Upadhyaya |
Artif. Intell. Eng. | 2 |
| 1998 | A Novel Approach to Random Pattern Testing of Sequential CircuitsabstractRandom pattern testing methods are known to result in poor fault coverage for most sequential circuits unless costly circuit modifications are made. In this paper, we propose a novel approach to improve the random pattern testability of sequential circuits. We introduce the concept of holding signals at primary inputs and scan flipflops of a partially scanned sequential circuit for a certain length of time, instead of applying a new random vector at each clock cycle. When a random vector is held at the primary inputs of the circuit under test or at the scan flip-flops, the system clock is applied and the primary outputs of the circuit are observed. Information obtained from a testability analysis or test generator is used to determine the number of clock cycles for which each random vector is to be held constant. The method is low cost and the results of our experiment on the benchmark circuits show that it is very effective in providing fault coverage close to the maximum obtainable fault coverage using random patterns with full scan. Lama Nachman, Kewal K. Saluja, Shambhu J. Upadhyaya, Robert Reuse |
IEEE Trans. Computers | 3 |
| 1997 | A Comprehensive Reconfiguration Scheme for Fault-Tolerant VLSI/WSI Array ProcessorsabstractThis paper presents an effective reconfiguration scheme consisting of detailed spare replacement, processor placement, routing, and switch programming mechanisms. A new switch programming scheme is proposed to reduce the hardware overhead of reconfiguration. A thorough yield simulation tool has been developed for accurate prediction of yield by considering the effects of defect clusters and switching network failures. This yield simulation tool can also be used to obtain the information on the performance degradation, spare replacement, processor placement, routing and the switch programming algorithm survival probability. Yung-Yuan Chen, Shambhu J. Upadhyaya, Ching-Hwa Cheng |
IEEE Trans. Computers | 2 |
| 1994 | Modeling the Reliability of a Class of Fault-Tolerant VLSI/WSI Systems Based on Multiple-Level RedundancyabstractA class of fault-tolerant Very Large Scale Integration (VLSI) and Wafer Scale Integration (WSI) schemes, called the multiple-level redundancy, which incorporates both hierarchical and element level redundancy has been proposed for the design of high yield and high reliability large area array processors. The residual redundancy left unused after successfully reconfiguring and eliminating the manufacturing defects can be used to improve the operational reliability of a system. Since existing techniques for the analysis of the effect of residual redundancy on reliability improvement are not applicable, we present a new hierarchical model to estimate the reliability of the systems designed by our approach. Our model emphasizes the effect of support circuit (interconnection) failures on system reliability, leading to more accurate analysis. We discuss two area prediction models, one based on the regular WSI process, another based on the advanced WSI process, to estimate the area-related parameters. This analysis gives an insight into the practical implementations of fault-tolerant schemes in VLSI/WSI technology. Results of a computer experiment conducted to validate our models are also discussed.> Yung-Yuan Chen, Shambhu J. Upadhyaya |
IEEE Trans. Computers | 2 |
| 1994 | Concurrent Process Monitoring with No Reference SignaturesabstractA simple, inexpensive and time/space efficient signature technique for process monitoring is presented. In this technique, a known signature function is applied to the instruction stream at compilation phase and when the accumulated signature forms an m-out-of-n code, the corresponding instructions are tagged. Error checking is done at run-time by monitoring the signatures accumulated at the tagged locations to determine whether they form m-out-of-n codes. This approach of signature checking does not require the embedding of reference signatures at compilation, thereby leading to savings in memory as well as in execution time. The m-out-of-n code approach offers high error coverage and controllable latency. The results of the experiments conducted to verify the controllability of the latency are discussed. One of the distinguishing features of the proposed scheme is the elimination of reference signatures, which are the main source of memory and time overhead in the existing techniques.> Shambhu J. Upadhyaya, Bina Ramamurthy |
IEEE Trans. Computers | 1 |
| 1993 | A parallel VLSI implementation of Viterbi algorithm for accelerated word recognitionabstractA hardware VLSI implementation of the Viterbi algorithm is presented. The Viterbi algorithm is used to solve a word recognition problem using a hidden Markov model. In order to accelerate the speed of computation for real-time word recognition, the inherent parallelism in the recursion step of the algorithm is exploited. Details of the hardware implementation and experimental results are discussed.> V. Upadhyaya, Shambhu J. Upadhyaya, Amlan Kundu 0001 |
Great Lakes Symposium on VLSI | 2 |
| 1993 | On-chip test generation for combinational circuits by LFSR modificationabstractA new on-chip test generation technique based on the built-in self test (BIST) and deterministic test generation concepts has been proposed. Given a test set, the test patterns can be regenerated on the chip and applied to the circuit under test without the use of any external test equipments. A systematic procedure for the modification of a basic linear feedback shift register (LFSR) to realize the on-chip test generation hardware is given. Since the delay introduced by the modification of the LFSR is only two gate delays, at-speed testing of circuits is feasible. Experiments are conducted and test application time and hardware overhead are compared with a known test technique under the same fault coverage conditions. It is shown that both test cost and test application time can be decreased significantly by using the proposed technique. Shambhu J. Upadhyaya, Liang-Chi Chen |
ICCAD | 1 |
| 1993 | Reliability, Reconfiguration, and Spare Allocation Issues in Binary-Tree Architectures Based on Multiple-Level RedundancyabstractThe locally redundant modular tree (LRMT) schemes offer high yield and reliability for trees of relatively few levels but are less effective for large binary trees due to the imbalance of reliability of different levels. A new multiple-level redundancy tree (MLRT) architecture that combines modular schemes with level-oriented schemes which lead to better yield and reliability is presented. The MLRT structure enhances the wafer yield to significant levels by offering separate layers of protection for random and clustered defects. Unlike most existing techniques, this technique performs a more accurate reliability analysis by taking into account both switch and link failures. A measure called the marginal switch to processing element area ratio (MSR) is introduced to precisely characterize the effect of switch complexity on the reliability of the redundant system. A systematic method for the optimal distribution of spare modules of the MLRT structure is also presented. The analyses show that the MLRT structure offers higher yield and system reliability than LRMT and subtree-oriented fault-tolerance (SOFT) structures do.> Yung-Yuan Chen, Shambhu J. Upadhyaya |
IEEE Trans. Computers | 2 |
| 1993 | Yield Analysis of Reconfigurable Array Processors Based on Multiple-Level RedundancyabstractPresents and analyzes a new multiple-level redundancy scheme based on hierarchical and element level redundancy for the enhancement of yield and reliability of large area array processors. This scheme can effectively tolerate not only the random defects/faults, but also the clustered defects/faults. The analysis presented here is general in that it takes into account the chip-kill defects occurring in the support circuit area of the array processors and is applicable to a variety of array processors. The authors derive bounds for the support circuit area which will be useful in selecting the most cost-effective redundancy scheme for a given application. The concept of subprocessing element-level redundancy is discussed and it is shown that a combination of subprocessing element-level redundancy with hierarchical redundancy offers significant yield improvements, especially for array processors with large area processing elements. The problem of optimal redundancy is also addressed.> Yung-Yuan Chen, Shambhu J. Upadhyaya |
IEEE Trans. Computers | 2 |
| 1993 | Analysis of Noncoherent Systems and an Architecture for the Computation of the System ReliabilityabstractAn efficient technique for computing the reliability of k-to-l-out-of-n systems is presented. These kinds of systems find application in communication, multiprocessor, and transportation system environments. The k-to-l-out-of-n systems are very general and readily model coherent systems such as series, parallel, and N-modular-redundancy (NMR) systems. The algorithm presented computes in quadratic time in the worst case and yields superior results compared to existing algorithms for all permissible values of k, l, and n. The scheme is shown to evaluate the reliability in linear order-time. A cellular implementation of the algorithm in hardware is presented. The basic cell consists of a simple multiplier, an adder, and some switches that can be easily implemented in VLSI using computer-aided-design (CAD) tools. Ways of obtaining optimal configurations for the k-to-l-out-of-n system are discussed.> Shambhu J. Upadhyaya |
IEEE Trans. Computers | 1 |
| 1991 | Focusing candidate generation
Amruth N. Kumar, Shambhu J. Upadhyaya |
Artif. Intell. Eng. | 2 |
| 1990 | Rollback recovery in real-time systems with dynamic constraintsabstractRollback recovery is a backward error recovery technique for recovering from transient faults in computing systems. Real-time systems employing fault tolerance and reconfiguration generally have time-dependent (dynamic) constraints. The author presents a novel rollback point insertion strategy which evaluates the rollback conditions on-line. The technique minimizes both time and space overhead associated with rollback, thereby making it applicable to real-time systems with dynamic constraints. The algorithm presented attains a near-optimum solution in terms of the time spent in saving the states of the system. Details of the simulation conducted to validate the technique are also given. The simulation study has established that the degradation in performance due to using the proposed algorithms is insignificant and the precomputation time is very small for programs that can be represented by general acyclic graphs. On the other hand, for structured programs that can be represented by a simple sequence of tasks, the computation overhead is almost zero.> Shambhu J. Upadhyaya |
COMPSAC | 1 |
| 1990 | BIST PLAs, Pass or Fail - A Case StudyabstractNumerous Built-In Self Testing (BIST) designs now exist for the testing of Programmable Logic Arrays (PLA), but their practical usefulness has not been studied. In this paper, we implement and compare several BIST designs using a common methodology of implementation. We also perform an yield analysis to characterize the yield degradation due to the BIST design methodology. Our preliminary findings of this work is that BIST approach results in considerable degradation of yield, and therefore may not be suitable as a test vehicle for PLAs. Shambhu J. Upadhyaya, John A. Thodiyil |
DAC | 1 |
| 1990 | Yield enhancement of field programmable logic arrays by inherent component redundancyabstractA complete technique that does not use any additional components for enhancing the yield of field-programmable logic arrays (FPLAs) is presented. In this approach, the inherent sparsity (absence of devices at crosspoints) of programmable logic arrays (PLAs) is utilized to mask certain types of manufacturing defects within the unprogrammed FPLAs, thus reclaiming chips which are otherwise discarded. Two categories of faults (called type 1 and type 2) are considered. Type-1 faults, which can be diagnosed a priori, are considered first. After diagnosing type 1 faults, the mask can be reconfigured around the faulty crosspoints. A streamlined bipartite matching algorithm is presented to enhance the speed of this reconfiguration. The uniqueness of the approach is that the programming of an FPLA is formulated as a graph theoretic problem for which a polynomial time solution exists. Type-2 faults in general cannot be diagnosed a priori. Therefore, a dynamic technique is presented for the repair of type-2 faults. Unused product lines of the FPLA are utilized for the repair. With a sufficient number of excess product lines, it is shown that a defective FPLA is guaranteed to be rendered usable. A probability measure for the usability of defective FPLA is obtained both with and without the implementation of this technique. Computer studies have shown that FPLAs with even a large number of defects can be successfully repaired, thereby increasing the yield.> Michael Demjanenko, Shambhu J. Upadhyaya |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 1988 | A Unified Approach to Designing Fault-Tolerant Processor Ensembles
Sreejit Chakravarty, Shambhu J. Upadhyaya |
ICPP (1) | 2 |
| 1988 | Dynamic Techniques for Yield Enhancement of Field Programmable Logic ArraysabstractTwo techniques are presented to increase the effective yield of field programmable logic arrays (FPLAs). In the first technique, a reconfiguration scheme is proposed to dynamically alter the product-term allocation of the mask PLA onto the product lines of the raw FPLA once a type-two fault is diagnosed. This technique does not require any extra product lines to obtain a usable destination FPLA. The second technique utilizes the often unused product lines within the FPLA. It is shown that once an error is detected during the programming procedure, a product line can always be desensitized from the rest of the FPLA. The intended product term is then simply reprogrammed onto one of the extra product lines.> Michael Demjanenko, Shambhu J. Upadhyaya |
ITC | 2 |
| 1988 | An experimental study to determine task size for rollback recovery systemsabstractThe effects of using a recovery cache to save the variables of a program are studied. A novel optimization model for rollback is formulated to include the effects of a recovery cache in rollback systems. The parameters of the model proposed are the maximum recovery time, the cache size, and the save and load time associated with the task size. The results are also discussed of an experimental study conducted to estimate the parameters of the programs that are critical for arriving at a suitable task size or cache size to minimize the cost of recovery.> Shambhu J. Upadhyaya, Kewal K. Saluja |
IEEE Trans. Computers | 1 |
| 1988 | A new approach to the design of built-in self-testing PLAs for high fault coverageabstractFour critical requirements are identified for the built-in self-testing of programmable logic arrays (BIST PLAs): the test set to test the PLA as well as the output response must be independent of the function of the PLA; the test pattern generator (TPG) and the response evaluator circuits must be simple to keep the extra logic overhead to a minimum; the fault coverage of the PLA must be within acceptable limits; and the speed of the test application must be high. A design that meets all of these goals is proposed. The approach is based on counting crosspoints, as opposed to the conventional parity technique. The TPG and RE circuits are simple and consist of shift registers and counters. The design requires a reorganization of the columns of the PLA on the basis of the number of crosspoints. This design provides extremely high fault coverage: the coverage for multiple faults is higher than that of any BIST design known to the authors, and the single-fault coverage is 100%. The design is simple and can easily be incorporated into existing computer-aided design systems.> Shambhu J. Upadhyaya, Kewal K. Saluja |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 1987 | BIST-PLA: A Built-in Self-Test Design of Large Programmable Logic ArraysabstractA new method for designing a Built-In Self-Test Programmable Logic Array (BIST-PLA) is presented. In the proposed design, the Test Pattern Generator and the Response Evaluator circuits are very simple. The design requires a re-arrangement of the AND (OR) planes on the basis of number of crosspoints in the product (output) lines in the PLA. Chun-Yeh Liu, Kewal K. Saluja, Shambhu J. Upadhyaya |
DAC | 3 |
| 1986 | A Wachtdog Processor Based General Rollback Technique with Multiple RetriesabstractA common assumption in the existing rollback techniques is that transients, the cause of most failures, subside very quickly, implying that a single story retry of the program from the previous rollback point is sufficient. The authors discuss a general rollback strategy withn(n≥2) retries which takes into consideration multiple transient failures as well as transients of long duration. Ways of deriving practical values ofnfor a given program are also discussed. Furthermore, the authors propose the use of a watchdog processor as an error detection tool to initiate recovery action through rollback, since the watchdog processor offers low error latency. They also discuss the merging of the watchdog processor with rollback recovery technique for enhancing the overall system reliability. Shambhu J. Upadhyaya, Kewal K. Saluja |
IEEE Trans. Software Eng. | 1 |