Browsing by Author "Ferdous, Md Sadek"
Now showing 1 - 15 of 15
- Results Per Page
- Sort Options
Item A blockchain and capability based access control for internet of things using self-sovereign identity(BRAC University, 2024-12) Amin, Md. Safinur; Khan, Abu Bakar Siddique; Ahmed, Istihad; Sajid, Tawsif Mahamud; Monir, Md. Mohtasim; Ferdous, Md SadekAccess control systems are essential tools for businesses because they guarantee the safe management of user access to resources after verification. Conventional approaches, such as Role-Based Access Control (RBAC) and Discretionary Access Control (DAC), have drawbacks such complexity brought on by "role explosion" and susceptibility to Trojan horse assaults. Moreover Attribute-Based Access Control (ABAC) has scalability challenges. As the number of attributes increases, managing and maintaining the policies associated with these attributes can become complex. Another significant drawback is, ABAC relies heavily on policies that define the rules for granting or denying access based on attributes, introducing the challenge of policy management complexity. While it provides an alternative, Attribute-Based Access Control (ABAC) has drawbacks such as “attribute explosion" when the number of attributes rises. The lightweight and dynamic properties of Internet of Things (IoT) devices provide security challenges for centralized access control systems. To ensure that only authorized entities may connect with certain IoT resources, access control becomes essential to handle issues related to single-point failure, user authentication, and privacy leaks. To mitigate the risks of centralized approaches, a technique called distributed access control is suggested. It is investigated whether integrating blockchain technology might improve security. Benefits of blockchain include its decentralized, transparent, and unchangeable nature. Nevertheless, there are drawbacks to the current blockchain-based IoT access control solutions, such as their vulnerability to Distributed Denial of Service (DDoS) assaults. To solve these problems, the suggested method integrates capability-based access management with Self-Sovereign Identity (SSI) inside a blockchain environment. By ensuring that entities only have permissions that are in line with their roles and responsibilities, this method seeks to securely manage and transfer capabilities. The creation of a prototype system highlights the feasibility and effectiveness of the suggested solution in the research. This system provides a possible remedy for the security issues raised by IoT settings and blockchain technology by demonstrating the combination of SSI and capability-based access control in a practical setting.Item A comprehensive framework for evaluating different layer 2 protocols in ethereum(BRAC University, 2025-06) Riyadh, Md. Mahadi Hassan; Saliken, Md. Safwoan; Annan, Wasima; Ghosh, Arjun; Fareeha, Eshat; Ferdous, Md SadekBlockchain technology was created with the motive to establish a decentralized, secured, and transparent system for digital transactions, reducing fraudulent behavior and aiming to stabilize the economy. However, scalability has always been regarded as a key issue that has been limiting the capacity of the system. With the widespread use of blockchain systems across the world, the demand for a high-speed transaction and lower latency in finality has increased. This is a significant barrier with the growing chain as it takes a substantial amount of time to process the transaction in Layer 1 which also adds in additional cost that makes each transaction more expensive and less user friendly. One of the leading solutions to scalability issues has been rollups that conduct transactions outside of the main chain and publish the summary of transactions in the main chain. However, rollup technology is relatively new and the protocols built on top of this are not very user-friendly. In this research, we propose and develop a Layer 2 recommendation system based on the user’s needs. The system is capable of giving users score-based feedback for different Layer 2 protocols. It can also deploy the user’s smart contract on the test networks of one or more of these Layer 2 protocols if the user wishes to do so. The system is aimed to reduce the hassle of users, promoting increased use of Layer 2 protocols. In this research, we introduce L2Easy, a Layer 2 protocol recommendation system that is customized to individual user needs. The system provides score-based evaluations of various Layer 2 protocols based on customizable criteria and offers the functionality to deploy user defined smart contracts to test networks across selected protocols. Our goal is to streamline the decision making process for users, increase the usability of the protocol, and promote a wider adoption of Layer 2 technologies.Item A privacy-preserving decentralized aggregated ride-sharing platform utilizing blockchain and differential privacy(BRAC University, 2025-10) Tasnim, Himika; Tasnim, Tahsin; Partho, Arnob Sarker; Ferdous, Md SadekRide-sharing platforms have emerged as significant components in modern urban mobility providing flexible, cost-effective, and efficient transportation solutions. With a growing user base, these platforms have access to the location data of millions of users and this data can be used in predicting traffic conditions and enhancing the overall ride-sharing experience. However, the traditional ride-sharing platforms rely solely on their own data, overlooking the broader traffic conditions shaped by multiple service providers (SPs), which highlights the need for aggregated systems to get more accurate traffic insight. However, aggregated platforms are vulnerable to critical privacy threats because of their dynamic and interconnected nature, creating a broad attack surface, hence publishing data while ensuring data privacy becomes a significant challenge here. Additionally, traditional ride-sharing platforms rely on centralized systems which are associated with the risk of single points of failure, and potential attacks from malicious participants. To address these limitations, this paper presents a decentralized and privacy-preserving aggregated ride-sharing framework that integrates Blockchain, Differential Privacy (DP), and OAuth-based access delegation. The aggregated platform provides information of all available drivers and active search requests in a specific area, gathered from multiple SPs. The use of blockchain helps to establish an immutable, verifiable, and tamper-resistant control layer for managing users’ metadata, while hashed or encrypted operational data is maintained in an off-chain database for efficiency. DP is used to share location data between SPs and aggregators in an privacy preserving, yet utility-retaining manner, while real data is exchanged only when the user selects a verified SP for booking, ensuring information sharing occurs exclusively within consent-based, OAuth-secured transactions. In this proposal, this research aim to bridge together blockchain with DP and explore it as a novel solution to provide two layers of security and privacy, paving the way for a decentralized and privacy preserving aggregated ride-sharing platform. By showing all SPs’ available drivers and nearby users, this aggregated approach enhances ride-matching efficiency and promotes a more comprehensive and accurate traffic and demand prediction system.Item A secure authentication mechanism for federated metaverses using Non-fungible Tokens (NFTs)(BRAC University, 2025-06) Hossain, Mohammed Shakib; Hawak, Khawaja Ehsun Ul; Jawad, Mutasin; Ferdous, Md SadekThe rapid growth of consumer-grade augmented reality (AR) and virtual reality (VR) devices has driven the interest in Metaverses, a type of fully immersive vir- tual world where people may communicate and conduct their businesses. However, similar to any restricted online services, the authentication of users is a crucial com- ponent to access any Metaverses. The authentication mechanism in the traditional online services has a number of issues such as password vulnerabilities, centralized control, identity fragmentation, session hijacking, scalability challenges, credential theft etc. Adopting such an authentication mechanism would introduce similar is- sues in the Metaverse domain. Moreover, there are also questions about additional security concerns in Metaverses as it is hard to control an individual’s virtual ac- tions. Hence, Blockchain create a decentralize environment that empowers users to take charge of their individual actions and identities. A smart contract that tokenize identity in the Metaverse can be executed securely within the blockchain technology. Therefore, a new authentication mechanism must be explored in order to increase the security of Metaverses. In this research, We propose a system utilizing the concept of Metaverse Federation in order to provide authentication throughout var- ious Metaverse, where multiple Metaverse will form a Circle of Trust (CoT) and the federation facilitates a secured authentication and identity management using a shared registry table for each Metaverse. This system leverages smart contracts and blockchain technology to generate Non-fungible token(NFT’s), which allow users to authenticate in various Metaverse. This enables users to navigate multiple Meta- verses with ease and a trusted identity, while complying with the specific rules and regulations of each Metaverse. we aim to explore a novel authentication mechanism tailored for Metaverses that will utilize the concept Non-fungible tokens (NFT’s) and the Metaverse Federation.Item Blockchain-Based COVID Vaccination Registration and Monitoring(Scopus, 22-12-22) Nabil, Shirajus Salekin; Pran, Md Sabbir Alam; Al Haque, Ali Abrar; Chakraborty, Narayan Ranjan; Chowdhury, Mohammad Jabed Morshed; Ferdous, Md SadekCOVID-19 has changed almost all aspects of our lives. Governments around the world have imposed lockdowns to slow down the transmissions. Fortunately, we have found the vaccine, in fact, a good number of them. However, managing the testing and vaccination process of the total population is a mammoth job. However, there are always delays or data silo problems in multi-organizational work. Therefore, streamlining this process is vital to improve efficiency and save more lives. Because of its effective data sharing mechanism among different entities with a number of security features, blockchain can be an effective tool for different applications in the health sector. Furthermore, blockchain provides a distributed system along with greater privacy, transparency, and authenticity. In this article, we have presented a blockchain-based system that seamlessly integrates testing and vaccination systems, allowing the system to be transparent. The instant verification of any tamper-proof COVID-19 test result has been developed, which will serve as “Test Certificates”. A transparent and efficient vaccination system has also been exhibited and implemented as the “Digital Vaccine Passport” (DVP) system. The infection rate-based prioritization will ensure a transparent and fair vaccination process as well as tackle the distribution issue of the limited amount of vaccine. The comparative review with other existing works is also discussed, highlighting a clear difference from the existing works. Our proposed system is distinctive on the basis of prioritization of vaccines and seamless integration of test certificates and vaccine passports, which will aid in controlling the pandemic situation. This system will also be handy in the case of tackling any future pandemics initially.Item Decentralized access control using hyperledger fabric(BRAC University, 2024-10) Hossain, Jubayer; Nabil, Mehedi Hasan; Jahin, Farhan Labib; Ferdous, Md SadekIn traditional access control systems, all the access control mechanisms are centrally managed which is seriously vulnerable. It is susceptible to a single point of failure due to its centralized architecture. As the system security breaks down due to the compromised central authority, it will be a huge risk, opening the door for data breaches, illegal access, and exploitation of private data. This research mitigates these risks by suggesting the decentralized control of access control systems using Extensible Access Control Markup Language (XACML). It is appropriate to use XACML for this task because XACML is flexible, open source, and works well in compliance with many access control models. This research focuses on decentralizing the four components of XACML: Policy Enforcement Point, Policy Decision Point, Policy Administration Point and Policy Information Point via the incorporation of Hyperledger Fabric (HF), a permissioned blockchain system. In the proposed architecture, the access control is distributed by smart contracts or chaincodes in multiple nodes of the network eliminating the single point of failure. To evaluate the feasibility of implementation, the development of the system following the proposed architecture is also done using chaincode. The results from the test evaluation show that decentralized implementation of the four XACML components with the Hyperledger Fabric eliminates single point of failure, scalability issues, and data integrity in distributed systems. The decentralization of the XACML components will help to create a secure and decentralized access control architecture. This research lays the foundation for future investigation of strategic blockchain-based decentralized access control systems.Item End-to-end encrypted peer to peer chat system with SSI(BRAC University, 2024-01) Rahat, Razin Rayan; Ahmed, Shahriar; Talukder, Abrar Awsaf; Islam, Ilmy; Chowdhury, Mahpara; Ferdous, Md SadekChat applications are among the most popular Internet applications and a huge number of people use them on a regular basis. As their use has grown, different security and privacy concerns have received attention from the users and the professionals. Many users consider what they chat with their family and friends to be extremely private and they want a certain amount of assurance that their chats are securely exchanged and are not exposed to any unauthorized parties. Towards this aim, many chat applications employ an End-to-End (E2E) Encryption mechanism. This is to safeguard the encryption keys during key exchange as these keys are crucial to ensure the security of the chat histories. Unfortunately, the existing key exchange mechanisms for E2E encryption are prone to Man-in-the-Middle (MITM) attacks. In addition, such mechanisms sometimes use a central server for exchanging keys which raises privacy and security concerns as these central servers may not be trustworthy. In this research, we would like to address these issues, by introducing a novel SSI (Self-sovereign Identity) based End-to-End Chat System which supports a Peer-to-Peer (P2P) key exchange mechanism.Item Hyperledger fabric blockchain-based medical document and prescription sharing system: Enhancing data security and traceability of the healthcare sector in Bangladesh(BRAC University, 2023-01) Abdullah, Mohammed Taher; Hasan, Ikramul; Iqbal, Shadab; Banik, Srijan; Dihan, Merazul Islam; Rabiul Alam, Md. Golam; Ferdous, Md SadekIn the current digital age, Blockchain technology has the potential to revolution ize the way sensitive medical information is handled. Blockchain’s immutable and encrypted nature makes it an ideal solution for preventing fraud and ensuring the security of essential data. This study aims to utilize an Hyperledger Fabric-based blockchain network for the authentication of individual medical prescriptions, while maintaining a ledger for each patient to reduce drug abuse and promote transparency and traceability. In Bangladesh, the analog nature of medical prescriptions makes it difficult to verify their authenticity, leading to a high rate of counterfeit prescrip tions and drug abuse. Our proposed solution utilizes a distributed ledger where records of transactions and data can be remotely stored, providing an open and tamper-proof system. In each transaction, the date and time are embedded with the digital signature of the issuer, creating a clear timeline of the transaction and greatly reducing the possibility of fraud. The current system of using hard copies for medical prescriptions is not only inconvenient for storage and sharing of infor mation but also time-consuming. Our proposed blockchain network can be used to store transaction and documentation data and easily share it with other nodes in the network, eliminating the need for paper exchange. This improves the efficiency of transactions and reduces the need for reconciling different ledgers. Our goal is to assist in the creation of a secure and authentic system for issuing and storing medical prescriptions in Bangladesh, to eliminate drug abuse. This research aims to explore the use of the Hyperledger blockchain system to make patient data more secure, while also enabling private sharing of information within the network. The Hyperledger framework, being a permissioned blockchain system, is well-suited for use cases that require privacy and security. The study will also examine the tech nical feasibility of building such a system. The outcome of this study will provide valuable insights into the potential of Hyperledger-based systems in the healthcare sector and aid in the design and implementation of similar systems in the future.Item Implementing zero trust in federated identity systems using hardware attestation and adaptive multi-factor authentication (MFA)(BRAC University, 2026-01) Islam, MD Monzurul; Zahin, Jaima; Swaccho, Aditya Das; Ahsan, Salfi; Hasan, Mahtab Uddin Al; Ferdous, Md SadekIn an era defined by dynamic cyber threats, old perimeter-style security models are becoming increasingly obsolete. Federated Identity Systems (FIS), where users au thenticate across multiple domains based on a single identity provider (IdP), offer convenience but are accompanied by significant security threats, including token theft, IdP compromise, and static session validation. At the same time, Zero Trust Architecture (ZTA) has emerged as a strong framework that applies continuous ver ification and least-privilege access regardless of user location or network trust. This research proposes a comprehensive solution for deploying the Zero Trust approach to Federated Identity Systems, which adjusts authentication needs based on real-time risk evaluations. It integrates Adaptive Multi-Factor Authentication (MFA) and hardware attestation, like TPM (Trusted Platform Module), to detect and register devices that establish trust, ensuring that compromised and untrusted devices do not enter the federation. The system designs and deploys a safe, privacy-preserving federated identity system utilizing OpenID Connect and dynamic policy verifica tion. After threat modeling, requirements analysis, and performance testing, the proposed system demonstrates increased protection against identity-based attacks and remains user-friendly and interoperable. Combining device trust, which is sup ported by hardware and adaptive authentication with contextual risk assessment, this architecture provides a comprehensive trust model that helps to mitigate threats of credential abuse, device spoofing, and token misuse. The approach increases se curity in federated environments and minimizes friction among users to provide an effective, scalable secure digital identity solution.Item Integrating single sign-on within the WebAuthn framework(BRAC University, 2026-01) Adnan, Asir; Anika, Nafisha Tabassum; Sobahan, Saima; Istiaque, A.J.M; Ferdous, Md SadekIn the world of digital identity, preserving user privacy while maintaining seamless access across platforms has become a challenge. WebAuthn, developed by World Wide Web Consortium (W3C) is mainly a web-based authentication standard. This system enhances security by enabling passwordless login through hardware-based and biometric authentication mechanisms. Another popular approach, to simplify authentication for users across the internet is Single-Sign-On (SSO) which allows a single credential to access multiple services or applications. This way users can get rid of the liability to manage multiple credentials, rather they can rely on only one credential to authenticate in a trusted manner and use that to authenticate in many other websites. Despite the potential of the SSO system, it has not been integrated with the WebAuthn framework till date. Through our research work, we have introduced a system that ensures passwordless authentication via WebAuthn and supports seamless access to service providers through SSO eliminating the requirements of repeated login. Moreover, this system empowers users with the full control over sharing their personal information by selective disclosure mechanism. Security Assertion Markup language (SAML) is used as the federated identity to exchange the authentication assertion securely between identity providers and service providers to enable seamless SSO. Thereby, introducing a new horizon of research on WebAuthn and SSO.Item Privacy-preserving healthcare data management system using blockchain technology(BRAC University, 2022-05) Arshad, Abir; Das, Devamitra; Rahman, Md.Mostafizur; Mostafi, Md.Tarik-Ul-; Biswas, Swapnil; Ferdous, Md SadekIn recent years, blockchain technology has gotten plenty of attention, with rising interest in an exceedingly type of way resembling as-Banking, Telecommunication, IoT, aid etc. Each different sector, Blockchain has additionally completed a massive task in medical aid specialties. Antecedently the standard EHR- based mostly systems were aggravated by several knowledge loss hazards, security and unchangeableness accord for the aid records, there was a niche between communications among varied brought about hospitals and what is more the reclamation of the data was thus uncomfortable. Blockchain has lessened these issues. Varied beginning points for Blockchain technology within the aid trade area unit the main target of this report. A redistributed info that is ever delayed thus far presents several benefits to the aid industry. These benefits get particularly overwhelming, once many alternative parties want access to identical data. Through a shared network infrastructure, totally different aid specialists will enter identical data. This can additionally allow the event of a brand-new category of Blockchain- grounded exercises in aid that may loosen wasted coffers and break vital useful issues with extra secured infrastructure. Either with the assistance of good contracts it’s going to be potential to alter a time- overwhelming method properly. This text describes a patient- doctor-centric construct for a redistributed aid management system that has a blockchain- based mostly on EHR and good contracts written in JavaScript. An acting epitome supported Hyperledger cloth and melodist technology has additionally been developed, guaranteeing the planned model’s security. Cyber criminals have been increasingly interested in healthcare data. Decentralization could help to lessen the annihilating effects of healthcare data. A peer-to-peer (P2P) network allows for decentralization, allowing multiple parties to store and conduct computation while keeping sensitive health data private. Blockchain technology is based on a decentralized or distributed method, which assures that its use is transparent and trustworthy. This study describes a patient-centric healthcare data management system that employs Blockchain as a storage medium to ensure anonymity. The use of cryptographic methods to safeguard patient data ensures pseudonymity. Healthcare providers are increasingly using Internet of Things (IoT)-based wearable technologies to speed up diagnosis and treatment. Hundreds of billions of sensors, devices, and vehicles have been connected to the Internet in recent years. Remote patient monitoring is one such technology that is now widely used in the treatment and care of patients. These technologies, on the other hand, pose serious privacy and security problems when it comes to data transfer and logging. These medical data security and privacy issues could cause a delay in treatment, possibly putting the patient’s life in jeopardy. We propose using a blockchain to manage and analyze healthcare large data in a secure manner. Blockchains, on the other hand, are computationally expensive, necessitate high bandwidth, and require additional computational capacity, making them unsuitable for most resource-constrained IoT devices aimed for smart cities. In this paper, we attempt to address the aforementioned concerns with blockchain and IoT devices. We offer a new framework of modified blockchain models that are ideal for IoT devices and rely on the network’s distributed nature as well as other privacy and security features. Our model’s added privacy and security features are based on advanced cryptographic primitives.Item Probabilistic security mapping of large language model integrations via stochastic Petri Nets(BRAC University, 2026) Mohammad, Zaber; Ferdous, Md Sadek; Sadeque, Farig YousufLarge Language Models (LLMs) are becoming increasingly popular for use in modern software systems. However, with increasing popularity, newly introduced security risks have emerged while integrating LLMs in a software system. These security gaps do not align with the traditional cybersecurity framework. To address it, this study specifically focuses on modeling three distinct related threats: prompt injection, context extraction, and Denial of Service (DoS) by resource exhaustion. First, the research maps these three LLM security aspects with the traditional CIA triad (Confidentiality, Integrity, Availability) and maps the system assets with corresponding justifications to show exactly what component of a system is at risk during these specific attacks. After that, the research investigates three distinct and independent threat models across the LLM architecture. First, Prompt Injection is analyzed at the input processing layer to mathematically evaluate Defensive Depth theory. Second, Data Exfiltration is evaluated during output scanning to formalize the Temporal Defense theory. Finally, a Denial of Service (DoS) attack is modeled to validate the Saturation theory. To transition from theoretical risk to measurable impact, an independent threat model is developed using Petri Net diagram to simulate these distinct stages of the LLM pipeline. Mathematical analysis is then conducted using a Continuous-Time Markov Chain (CTMC) and finite queuing theories. Specifically for the DoS evaluation, the adversarial arrival rate (λ) and system processing bottleneck (ρ) are modeled to measure the queue wait times and resource depletion. Across all three threat vectors, Monte Carlo validation is used to ensure the theoretical mathematical calculations match the simulated reality. The result provides a formalized mathematical baseline for each independent vulnerability. The findings demonstrate the exact architectural trade-offs to implement input-layer defensive depth, the temporal cost for output sanitization, and the critical threshold where system queues saturate and drop legitimate requests during a DoS attack. These insights help developer to design more resilient, optimized, and mathematically verifiable security architecture for deployed LLM applications.Item Revolutionizing microfinance: a blockchain-driven decentralized finance (DeFi) model for collateral-free loans(BRAC University, 2023) Tasin, Md. Ishmam; Hossain, Md. Rabib; Chowdhury, Nahin; Alam, S.M. Azwad-Ul-; Ferdous, Md SadekMicrofinance, providing essential banking services to low-income and unbanked individuals, faces numerous challenges such as high-interest rates, cumbersome intermediary processes, and lack of transparency. Decentralized Finance (Defi) has recently been identified as a transformative technology with the potential to ameliorate these concerns and advance microfinance. In this paper, we present a layered Decentralized Application (DApp) designed using Defi to alleviate the security issues intrinsic to conventional microfinance. Our model enables uncollateralized lending to the unbanked population, thus tackling one of the significant barriers in traditional microfinance. In addition to discussing its design and architecture, we demonstrate the DApp on the Ethereum (ETH) network that supports open-source DApps. We then propose a detailed roadmap to reduce intermediaries, lower costs, improve loan accessibility, and engender a more transparent lending environment using blockchain technology. We also examine sustainable methods for uncollateralized loans in the microfinance space, focusing on regions such as Bangladesh. This research underscores the transformative power of Defi and blockchain in reshaping the microfinance landscape.Item Tokenized property renting and trading using blockchain(BRAC University, 2022-09) Hossain, Md. Miraj; Ahmed, Kazi Sazid; Saha, Senjuti; Eshan, Kazi Tasmima; Akand, Tasmia; Ferdous, Md SadekIt is challenging for any authoritative figure to keep track of and oversee the house rental market because of the large number of landlords, arbitrary fees, misleading rental information and other issues. On the basis of Blockchain technology of encryption algorithm, this paper develops a property buy, sell and rental system. The system uses smart contracts to form all kinds of agreements, establish the relationship among users, pay and collect rent automatically on a regular basis and return the rental right when it is due. With this approach, there is no need for mediation, it is less expensive, rental information is transparent and it is easier to keep track of all the records for an authoritative figure using this system.Item Understanding the economic impact of botnets in Bangladesh: insights and strategies from attacker & victim perspectives(BRAC University, 2024-10) Reheean, Rodoshie; Sami, Golam Sarwar; Ahmed, Syeda Ifroza; Nipa, Anonna Dev; Ahmed, Md Faisal; Ferdous, Md SadekBotnets pose a significant threat to Bangladesh’s cyberspace and to its economic stability, especially in critical sectors such as finance, government and technology. This research investigates the life cycle and economic impacts of botnets in Bangladesh from multiple perspectives namely the attacker, the general public, and security experts. It explores how botnets target vulnerable systems, the methods and strategies used by attackers to propagate botnets and the financial and operational harm they pose to organizations. Data was collected through surveys targeting both attackers and victims, and also via interviews with cybersecurity professionals to identify effective detection and mitigation strategies. The research findings reveal substantial financial losses due to botnet attacks and emphasizes the need for a robust cybersecurity framework tailored for Bangladesh’s evolving digital landscape. The proposed framework aims to prevent digital casualties for the general public, minimize botnetrelated activities and economic disruptions in government institutions and financial sectors.
