VLDB 2026 Research / reviewers in the wild / expert
Issa Traoré
dblp:10/1711
· DBLP profile ↗
68ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0003-2987-8047ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 6 since 2021Artificial intelligence and machine learning · 10 · 2 since 2021Computer networks · 4 · 3 since 2021Software engineering, systems software and programming languages · 4 · 3 first-authorHuman-computer interaction and ubiquitous computing · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Preserving data and model privacy during inference and training
William Briguglio, Issa Traoré, Mohammad Saiful Islam Mamun, Waleed A. Yousef, Sherif Saad |
Expert Syst. Appl. | 2 |
| 2025 | Drift-RL: A Reinforcement Learning Framework for Simulating Textual Data Drift in Cybersecurity
Hadeer Ahmed, Issa Traoré, Sherif Saad, Mohammad Saiful Islam Mamun |
CRiSIS | 2 |
| 2025 | An Alternative Approach to Federated Learning for Model Security and Data PrivacyabstractFederated learning (FL) enables machine learning on data held across multiple clients without exchanging private data. However, exchanging information for model training can compromise data privacy. Further, participants may be untrustworthy and can attempt to sabotage model performance. Also, data that is not independently and identically distributed (IID) impede the convergence of FL techniques. We present a general framework for federated learning via aggregating multivariate estimated densities (FLAMED). FLAMED aggregates density estimations of clients’ data, from which it simulates training datasets to perform centralized learning, bypassing problems arising from non-IID data and contributing to addressing privacy and security concerns. FLAMED does not require a copy of the global model to be distributed to each participant during training, meaning the aggregating server can retain sole proprietorship of the global model without the use of resource-intensive homomorphic encrypti on. We compared its performance to standard FL approaches using synthetic and real datasets and evaluated its resilience to model poisoning attacks. Our results indicate that FLAMED effectively handles non-IID data in many settings while also being more secure. William Briguglio, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun, Sherif Saad |
ICISSP (1) | 3 |
| 2025 | Flow-Based Anomaly Intrusion Detection Systems Using Recurrent Neural NetworksabstractAs Internet of Things (IoT) networks continue to evolve, they face increasing security threats, and methods to achieve the security properties and requirements of these networks from the perspective of data, communication and IoT device security, are still on demand. This paper focuses on Recurrent neural network (RNN)-based methods, which provide intrusion detection systems (IDSs) with the capability of analyzing unseen and complex patterns in exchanges between IoT devices. Two flow-based optimized standalone RNNbased IDSs (called Uni-Hybrid and Bi-Hybrid RNNbased IDSs) are proposed to enhance the security of IoT networks. Through experiments using the IoTID20 dataset, the proposed models yield some marked improvements over a chosen benchmark model in terms of precision, accuracy, recall, and F1-score, highlighting the potential of RRN-based models in addressing intrusion detection in IoT networks. Hafiz Yasir Noor, Isaac Woungang, Glaucio H. S. Carvalho, Issa Traoré, Dao Thanh Hai |
WiMob | 4 |
| 2025 | A Self-adaptive Hybrid Network Anomaly Detection Engine
Amir Mohammadi Bagha, Isaac Woungang, Issa Traoré, Danda B. Rawat |
Comput. Commun. | 3 |
| 2024 | A Graph Clustering-Based Network Anomaly Detection SystemabstractConsidering the Activity and Event Network model, also known as AEN, a recent knowledge graph model adept at handling the uncertain and dynamic nature of network activities, this paper proposes an unsupervised anomaly detection system, whose technique is foster around graph clustering within the AEN framework. The goal is to recognize and adapt to normal behaviour across different varying time periods while establishing the baseline behaviours for each cluster. The effectiveness of our proposed system in identifying the anomalies resulted in a false positive rate of 0.85% and a detection rate of 81 %, assessed using the CIC 2018 IDS dataset. Amir Mohammadi Bagha, Isaac Woungang, Issa Traoré, Danda B. Rawat |
WiMob | 3 |
| 2024 | Effect of Text Augmentation and Adversarial Training on Fake News DetectionabstractThe action of spreading false information through fake news articles presents a significant danger to society because it has the ability to shape public opinion with inaccurate facts. This can lead to negative effects, such as reduced trust in institutions and the promotion of conflict, division, and even violence. In this article, a text augmentation technique is introduced as a means of generating new data from preexisting fake news datasets. This approach has the potential to enhance classifier performance by a range of 3%–11%. It can also be utilized to launch a successful attack on trained classifiers, with up to a 90% success rate. However, the success rate of these attacks decreased to less than 28% when the model was retrained with the generated adversarial examples. These results demonstrate the effectiveness of text augmentation as a viable method for detecting fake news and increasing classifier accuracy and performance, as well as its ability to be utilized to perform adversarial machine learning (ML) and improve the resilience of ML algorithms. Hadeer Ahmed, Issa Traoré, Sherif Saad, Mohammad Saiful Islam Mamun |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2024 | Federated Supervised Principal Component AnalysisabstractIn federated learning, standard machine learning (ML) techniques are modified so they can be applied to data held by separate participants without the need for exchanging said data and while preserving privacy. Other data modelling techniques, such as singular value decomposition, have been similarly federated, enabling federated principal component analysis (PCA), which is a popular preprocessing step for ML tasks. Supervised PCA improves on standard PCA by using labeled data to retain more relevant information for supervised ML problems. However, a federated version of supervised PCA does not exist in the literature. In this paper, we propose a federated version of supervised PCA and its dual and kernel variations, called FeS-PCA, dual FeS-PCA, and FeSK-PCA, respectively. We used random orthogonal matrix masking to keep FeS-PCA and dual FeS-PCA private, while FeSK-PCA was kept private using an approximation of the standard approach. We tested our proposed approaches by recreating visualization, classification, and regression experiments from the original unfederated supervised PCA paper. We further added a real-world federated dataset to test the scalability and fidelity of our approach. Our analysis and results indicate that FeS-PCA and dual FeS-PCA are faithful, lossless, and private versions of their unfederated counterparts. Furthermore, despite being an approximation, FeSK-PCA achieves nearly identical performance to standard kernel SPCA in many cases. This is in addition to the added benefit of a reduced runtime and smaller memory footprint. William Briguglio, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Bonet Detection Mechanism Using Graph Neural Network
Aleksander Maksimoski, Isaac Woungang, Issa Traoré, Sanjay K. Dhurandher |
AINA (2) | 3 |
| 2023 | Detecting BrakTooth AttacksabstractMore than 5.1 billion Bluetooth-enabled devices were shipped in the year 2022 and this trend is expected to exceed 7.1 billion by the year 2026. A large proportion of these devices are used in smart homes designed for older adults, to help them age in place. Monitoring vitals, climate control, illumination control, fall detection, incontinence detection, pill dispensing, and several other functions are successfully addressed by many of these Bluetooth-enabled devices. Therefore it becomes crucial to protect them from malicious attacks and ensure the safety and well-being of their users. Some of these devices have only Bluetooth connectivity which makes patching them challenging for older adults, as a result, most remain unpatched. The family of vulnerabilities recently found in the Bluetooth Classic (BT Classic) stack called BrakTooth, poses a genuine threat to such devices. In this study, we develop an experimental procedure to capture traffic at the Link Manager Protocol (LMP) layer of the BT Classic stack and use machine learning algorithms to detect BrakTooth-based attacks. Achyuth Nandikotkur, Issa Traoré, Mohammad Saiful Islam Mamun |
SECRYPT | 2 |
| 2023 | Classifier Calibration: With Application to Threat Scores in CybersecurityabstractThis article explores the calibration of a classifier output score in binary classification problems. A calibrator is a function that maps the arbitrary classifier score, of a testing observation, onto [0,1] to provide an estimate for the posterior probability of belonging to one of the two classes. Calibration is important for two reasons; first, it provides a meaningful score, that is the posterior probability; second, it puts the scores of different classifiers on the same scale for comparable interpretation. The article presents three main contributions: (1) Introducing multi-score calibration, when more than one classifier provides a score for a single observation. (2) Introducing the exact analogy between two scenarios: (a) designing a classifier from a set of features, and (b) designing a calibrator, to generate a single calibrated score, from a set of scores of different classifiers. Hence, we propose expanding these classifiers’ scores to higher dimensions to boost the calibrator’s performance. (3) Conducting a massive simulation study, in the order of 24,000 experiments, that incorporates different configurations, in addition to experimenting on three real datasets from the cybersecurity domain. The results show that there is no overall winner among the different calibrators and different configurations. However, general advices for practitioners include the following: the Platt’s calibrator (J. Plattet al., 1999), a version of the logistic regression that decreases bias for a small sample size, has a very stable and acceptable performance among all experiments; our suggested multi-score calibration provides better performance than single score calibration in the majority of experiments, including the two real datasets. In addition, expanding the scores can help in some experiments. Waleed A. Yousef, Issa Traoré, William Briguglio |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Intrusion Detection using a Graphical Fingerprint ModelabstractThe Activity and Event Network (AEN) graph is a new framework that allows modeling and detecting intrusions by capturing ongoing security-relevant activity and events occurring at a given organization using a large time-varying graph model. The graph is generated by processing various network security logs, such as network packets, system logs, and intrusion detection alerts. In this paper, we show how known attack methods can be captured generically using attack fingerprints based on the AEN graph. The fingerprints are constructed by identifying attack idiosyncrasies under the form of subgraphs that represent indicators of compromise (IOes), and then encoded using Property Graph Query Language (PGQL) queries. Among the many attack types, three main categories are implemented as a proof of concept in this paper: scanning, denial of service (DoS), and authentication breaches; each category contains its common variations. The experimental evaluation of the fingerprints was carried using a combination of intrusion detection datasets and yielded very encouraging results. Chenyang Nie, Paulo Gustavo Quinan, Issa Traoré, Isaac Woungang |
CCGRID | 3 |
| 2022 | Edge-Assisted Secure and Dependable Optimal Policies for the 5G Cloudified InfrastructureabstractThis paper proposes an optimal admission and placement stochastic controller that inserts security and depend-ability in the operational aspects of edge-cloud system under a 5G deployment. The proposed mechanism uses the frame-work of Semi-Markov Decision Making Process (SMDP) and seeks for an optimal policy that efficiently allocates the virtual resources to secure and run the services across the cloudified infrastructure. Driven by a new latency-oriented cost structure, the optimal controller achieves a dependable and secure operation by optimally balancing the service requests between the edge and the cloud system taking into account the service profile, the workload, and the traffic load. A structural analysis of the optimal policy reveals its implementation friendliness while a cloudnomics analysis shows that the optimal cost can be further optimized by fine tuning the parameters of the proposed cost structure. Glaucio H. S. Carvalho, Isaac Woungang, Alagan Anpalagan, Issa Traoré, Periklis Chatzimisios |
ICC | 4 |
| 2021 | Machine learning in precision medicine to preserve privacy via encryption
William Briguglio, Parisa Moghaddam, Waleed A. Yousef, Issa Traoré, Mohammad Saiful Islam Mamun |
Pattern Recognit. Lett. | 4 |
| 2021 | UN-AVOIDS: Unsupervised and Nonparametric Approach for Visualizing Outliers and Invariant Detection ScoringabstractThe visualization and detection of anomalies (outliers) are of crucial importance to many fields, particularly cybersecurity. Several approaches have been proposed in these fields, yet to the best of our knowledge, none of them has fulfilled both objectives, simultaneously or cooperatively, in one coherent framework. Moreover, the visualization methods of these approaches were introduced for explaining the output of a detection algorithm, not for data exploration that facilitates a standalone visual detection. This is our point of departure in introducing UN-AVOIDS, an unsupervised and nonparametric approach for both visualization (a human process) and detection (an algorithmic process) of outliers, that assigns invariant anomalous scores (normalized to [0,1]), rather than hard binary-decision. The main aspect of novelty of UN-AVOIDS is that it transforms data into a new space, which is introduced in this paper as neighborhood cumulative density function (NCDF), in which both visualization and detection are carried out. In this space, outliers are remarkably visually distinguishable, and therefore the anomaly scores assigned by the detection algorithm achieved a high area under the ROC curve (AUC). We assessed UN-AVOIDS on both simulated and two recently published cybersecurity datasets, and compared it to three of the most successful anomaly detection methods: LOF, IF, and FABOD. In terms of AUC, UN-AVOIDS was almost an overall winner with a margin that varied between - 0.028 and 0.125, depending on the data. The article concludes by providing a preview of new theoretical and practical avenues for UN-AVOIDS. Among them is designing a visualization aided anomaly detection (VAAD), a type of software that aids analysts by providing UN-AVOIDS’ detection algorithm (running in a back engine), NCDF visualization space (rendered to plots), along with other conventional methods of visualization in the original feature space, all of which are linked in one interactive environment. Waleed A. Yousef, Issa Traoré, William Briguglio |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | Optimal Security Risk Management Mechanism for the 5G Cloudified InfrastructureabstractThis work proposes an optimal security risk management mechanism to holistically minimize the risks of a Denial of Service (DoS) attack and Service Level Agreement (SLA) violations that might unfold at the 5G edge-cloud ecosystem. Using the Semi-Markov Decision Process framework, a cyber risk-aware controller is designed to optimally decide on the admission, placement, and migration of a service taking into consideration a user taxonomy and the service requirements. A new cost structure that balances the targeted security risks as well as the cost and the reward of a secure service provisioning is introduced to pave the way for a safe edge-cloud operation. To proactively restrict the population of untrusted users, we consider security controls in the form of a linear and an exponential cost functions and show that the former represents a more flexible and profitable pathway for a Mobile Network Operator to operate at the expense of an inflated security risk while the latter leads to the opposite outcome. Results show that the baseline mechanism might violate the SLA and expose the edge and the cloud to a DoS attack in levels that are 102, 1012, and 1014times higher than those of the proposed controller. Glaucio H. S. Carvalho, Isaac Woungang, Alagan Anpalagan, Issa Traoré |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | A RSA-Biometric Based User Authentication Scheme for Smart Homes Using Smartphones
Amir Mohammadi Bagha, Isaac Woungang, Sanjay K. Dhurandher, Issa Traoré |
AINA | 4 |
| 2020 | Hypervisor-based cloud intrusion detection through online multivariate statistical change tracking
Abdulaziz Aldribi, Issa Traoré, Belaid Moa, Onyekachi Nwamuo |
Comput. Secur. | 2 |
| 2020 | Multilayer ransomware detection using grouped registry key operations, file entropy and file signature monitoringabstractThe last few years have come with a sudden rise in ransomware attack incidents, causing significant financial losses to individuals, institutions and businesses. In reaction to these attacks, ransomware detection has become an important topic for research in recent years. Currently, there are two broad categories of ransomware detection techniques: signature-based and behaviour-based analyses. On the one hand, signature-based detection, which mainly relies on a static analysis, can easily be evaded by code-obfuscation and encryption techniques. On the other hand, current behaviour-based models, which rely mainly on a dynamic analysis, face difficulties in accurately differentiating between user-triggered encryption from ransomware-triggered encryption. In the current paper, we present an upgraded behavioural ransomware detection model that reinforces the existing feature space with a new set of features based on grouped registry key operations, introducing a monitoring model based on combined file entropy and file signature. We analyze the new feature model by exploring and comparing three different linear machine learning techniques: SVM, logistic regression and random forest. The proposed approach helps achieve improved detection accuracy and provides the ability to detect novel ransomware. Furthermore, the proposed approach helps differentiate user-triggered encryption from ransomware-triggered encryption, allowing saving as many files as possible during an attack. To conduct our study, we use a new public ransomware detection dataset collected in our lab, which consists of 666 ransomware and 103 benign binaries. Our experimental results show that our proposed approach achieves relatively high accuracy in detecting both previously seen and novel ransomware samples. Brijesh Jethva, Issa Traoré, Asem Ghaleb, Karim Ganame, Sherif Ahmed |
J. Comput. Secur. | 2 |
| 2019 | Automated Event Prioritization for Security Operation Center using Deep LearningabstractDespite their popularity, Security Operation Centers (SOCs) are facing increasing challenges and pressure due to the growing volume, velocity and variety of the IT infrastructure and security data observed on a daily basis. Due to the mixed performance of current technological solutions, e.g. IDS and SIEM, there is an over-reliance on manual analysis of the events by human security analysts. This creates huge backlogs and slow down considerably the resolution of critical security events. Obvious solutions include increasing accuracy and efficiency in the automation of crucial aspects of the SOC workflow, such as the event classification and prioritization. In the current paper, we present a new approach for SOC event classification by identifying a set of new features using graphical analysis and classifying using a deep neural network model. Experimental evaluation using real SOC event log data yields very encouraging results in terms of classification accuracy. Nitika Gupta, Issa Traoré, Paulo Magella de Faria Quinan |
IEEE BigData | 2 |
| 2019 | Secure mutual authentication and automated access control for IoT smart home using cumulative Keyed-hash chain
Issa Traoré |
J. Inf. Secur. Appl. | 2 |
| 2018 | If-transpiler: Inlining of hybrid flow-sensitive security monitor for JavaScript
Bassam Sayed, Issa Traoré, Amany Abdelhalim |
Comput. Secur. | 2 |
| 2016 | Improving vulnerability detection measurement: [test suites and software security assurance]abstractThe Software Assurance Metrics and Tool Evaluation (SAMATE) project at the National Institute of Standards and Technology (NIST) has created the Software Assurance Reference Dataset (SARD) to provide researchers and software security assurance tool developers with a set of known security flaws. As part of an empirical evaluation of a runtime monitoring framework, two test suites were executed and monitored, revealing deficiencies which led to a collaboration with the NIST SAMATE team to provide replacements. Test Suites 45 and 46 are analyzed, discussed, and updated to improve accuracy, consistency, preciseness, and automation. Empirical results show metrics such as recall, precision, and F-Measure are all impacted by invalid base assumptions regarding the test suites. Alexander M. Hoole, Issa Traoré, Aurélien Delaitre, Charles de Oliveira |
EASE | 2 |
| 2016 | Creating Decision Trees from Rules using RBDT-1abstractMost of the methods that generate decision trees for a specific problem use the examples of data instances in the decision tree–generation process. This article proposes a method calledRBDT‐1—rule‐based decision tree—for learning a decision tree from a set of decision rules that cover the data instances rather than from the data instances themselves. The goal is to create on demand a short and accurate decision tree from a stable or dynamically changing set of rules. The rules could be generated by an expert, by an inductive rule learning program that induces decision rules from the examples of decision instances such asAQ‐typerule induction programs, or extracted from a tree generated by another method, such as theID3orC4.5. In terms of tree complexity (number of nodes and leaves in the decision tree), RBDT‐1 compares favorably withAQDT‐1andAQDT‐2, which are methods that create decision trees from rules. RBDT‐1 also compares favorably with ID3 while it is as effective as C4.5 where both (ID3 and C4.5) are well‐known methods that generate decision trees from data examples. Experiments show that the classification accuracies of the decision trees produced by all methods under comparison are indistinguishable. Amany Abdelhalim, Issa Traoré, Youssef Nakkabi |
Comput. Intell. | 2 |
| 2015 | E-MAnt Net: An ACO-Based Energy Efficient Routing Protocol for Mobile Ad Hoc NetworksabstractIn mobile ad hoc networks (MANETs), nodes are mobile and have limited energy resource that can quickly deplete due to multi-hop routing activities, which may gradually lead to an un-operational network. In the past decade, the hunt for a reliable and energy-efficient MANETs routing protocol has been extensively researched. This paper proposes a novel Ant Net-based routing scheme for MANETs (so-called MAnt Net), and an its enhanced energy-aware version (so-called E-MAnt Net), for which the routing decisions are facilitated based on the nodes' residual energy. These protocols were evaluated through simulations using NS2, showing that E-MAnt Net outperforms both MAnt Net and EAODV, in terms of network residual energy, network lifetime, number of established connections, and the number of dead nodes in the network, where E-AODV is an energy-aware version of AODV. Ssowjanya Harishankar, Isaac Woungang, Sanjay K. Dhurandher, Issa Traoré, Shakira Banu Kaleel |
AINA | 4 |
| 2015 | Sharing Privacy Information in Credit Analysis EnvironmentabstractCredit analysis is used by financial companies to grant credit to customers. The analysis is expensive, bureaucratic, and requires the collection of customer personal information. However, shopping malls are selling goods in several installments and need a simple, fast, and cheap process to grant credit to their customers. One way to improve the efficiency of this process is to facilitate the sharing of private information from customers and stores. The challenge here is how to share private information without disclosing the identity of its owner. Here we propose a protocol to share information while preserving the privacy of the customer as well as the information of the commercial institution. Marcelo Luiz Brocardo, Ricardo Felipe Custódio, Carlos Roberto De Rolt, Julio Da Silva Dias, Issa Traoré |
CISIS | 5 |
| 2015 | A Game Theoretic Framework for Cloud Security Transparency
Abdulaziz Aldribi, Issa Traoré |
NSS | 2 |
| 2015 | Annotated Control Flow Graph for Metamorphic Malware DetectionabstractMetamorphism is a technique that mutates the binary code using different obfuscations and never keeps the same sequence of opcodes in the memory. This stealth technique provides the capability to a malware for evading detection by simple signature-based (such as instruction sequences, byte sequences and string signatures) anti-malware programs. In this paper, we present a new scheme named Annotated Control Flow Graph (ACFG) to efficiently detect such kinds of malware. ACFG is built by annotating CFG of a binary program and is used for graph and pattern matching to analyse and detect metamorphic malware. We also optimize the runtime of malware detection through parallelization and ACFG reduction, maintaining the same accuracy (without ACFG reduction) for malware detection. ACFG proposed in this paper: (i) captures the control flow semantics of a program; (ii) provides a faster matching of ACFGs and can handle malware with smaller CFGs, compared with other such techniques, without compromising the accuracy; (iii) contains more information and hence provides more accuracy than a CFG. Experimental evaluation of the proposed scheme using an existing dataset yields malware detection rate of 98.9% and false positive rate of 4.5%. Shahid Alam, Issa Traoré, Ibrahim Sogukpinar |
Comput. J. | 2 |
| 2015 | A framework for metamorphic malware analysis and real-time detection
Shahid Alam, R. Nigel Horspool, Issa Traoré, Ibrahim Sogukpinar |
Comput. Secur. | 3 |
| 2015 | Authorship verification of e-mail and tweet messages applied for continuous authentication
Marcelo Luiz Brocardo, Issa Traoré, Isaac Woungang |
J. Comput. Syst. Sci. | 2 |
| 2014 | Context-aware intrusion alerts verification approachabstractIntrusion detection systems (IDSs) produce a massive number of intrusion alerts. A huge number of these alerts are false positives. Investigating false positive alerts is an expensive and time consuming process, and as such represents a significant problem for intrusion analysts. This shows the needs for automated approaches to eliminate false positive alerts. In this paper, we propose a novel alert verification and false positives reduction approach. The proposed approach uses context-aware and semantic similarity to filter IDS alerts and eliminate false positives. Evaluation of the approach with an IDS dataset that contains massive number of IDS alerts yields strong performance in detecting false positive alerts. Sherif Saad, Issa Traoré, Marcelo Luiz Brocardo |
IAS | 2 |
| 2014 | MARD: A Framework for Metamorphic Malware Analysis and Real-Time DetectionabstractBecause of the financial and other gains attached with the growing malware industry, there is a need to automate the process of malware analysis and provide real-time malware detection. To hide a malware, obfuscation techniques are used. One such technique is metamorphism encoding that mutates the dynamic binary code and changes the opcode with every run to avoid detection. This makes malware difficult to detect in real-time and generally requires a behavioral signature for detection. In this paper we present a new framework called MARD for Metamorphic Malware Analysis and Real-Time Detection, to protect the end points that are often the last defense, against metamorphic malware. MARD provides: (1) automation (2) platform independence (3) optimizations for real-time performance and (4) modularity. We also present a comparison of MARD with other such recent efforts. Experimental evaluation of MARD achieves a detection rate of 99.6% and a false positive rate of 4%. Shahid Alam, R. Nigel Horspool, Issa Traoré |
AINA | 3 |
| 2014 | Toward a Framework for Continuous Authentication Using StylometryabstractContinuous Authentication (CA) consists of monitoring and checking repeatedly and unobtrusively user behavior during a computing session in order to discriminate between legitimate and impostor behaviors. Stylometry analysis, which consists of checking whether a target document was written or not by a specific individual, could potentially be used for CA. In this work, we adapt existing stylometric features and develop a new authorship verification model applicable for continuous authentication. We use existing lexical, syntactic, and application specific features, and propose new features based on n-gram analysis. We start initially with a large features set, and identify a reduced number of user-specific features by computing the information gain. In addition, our approach includes a strategy to circumvent issues regarding unbalanced dataset which is an inherent problem in stylometry analysis. We use Support Vector Machine (SVM) for classification. Experimental evaluation based on the Enron email dataset involving 76 authors yields very promising results consisting of an Equal Error Rate (EER) of 12.42% for message blocks of 500 characters. Marcelo Luiz Brocardo, Issa Traoré, Isaac Woungang |
AINA | 2 |
| 2014 | Continuous authentication using micro-messagesabstractAuthorship verification consists of checking whether a target document was written or not by a specific individual. In this paper, we study the problem of authorship verification for Continuous Authentication (CA) purposes. Different from traditional authorship verification that focuses on long texts, we tackle the use of micro-messages. Shorter authentication delay (i.e. smaller data sample) is essential to reduce the window size of the re-authentication period in CA. We explored lexical, syntactic, and application specific features. We investigated two different classification schemes: on one hand Logistic Regression (LR) and on the other hand an hybrid classifier combining Support Vector Machine (SVM) and LR. Experimental evaluation based on the Enron email dataset involving 76 authors and Twitter dataset involving 100 authors yield very promising results consisting of Equal Error Rates (EER) of 9.18% and 11.83%, respectively. Marcelo Luiz Brocardo, Issa Traoré |
PST | 2 |
| 2014 | Detection and mitigation of malicious JavaScript using information flow controlabstractJavaScript is the main language used to provide the client-side functionality of the modern web. It is used in many applications that provide high interactivity with the end-user. These applications range from mapping applications to online games. In recent years, cyber-criminals started focusing on attacking the visitors of legitimate websites and social networks rather than attacking the websites themselves. The dynamic nature of the JavaScript language and its tangled usage with other web technologies in modern web applications makes it hard to reason about its code statically. This poses the need to develop effective mechanisms for detecting and mitigating malicious JavaScript code on the client-side of the web. In this paper, we address the above challenges by developing a framework that detects and mitigates the flow of sensitive information on the client-side to illegal channels. The proposed model uses information flow control dynamically at run-time to track sensitive information and prevents its leakage. In order to realize the model, we extend the operational semantics of JavaScript to enable the control of information flow inside web browsers. Bassam Sayed, Issa Traoré, Amany Abdelhalim |
PST | 2 |
| 2014 | In-Cloud Malware Analysis and Detection: State of the ArtabstractWith the advent of Internet of Things, we are facing another wave of malware attacks, that encompass intelligent embedded devices. Because of the limited energy resources, running a complete malware detector on these devices is quite challenging. There is a need to devise new techniques to detect malware on these devices. Malware detection is one of the services that can be provided as an in-cloud service. This paper reviews current such systems, discusses there pros and cons, and recommends an improved in-cloud malware analysis and detection system. We introduce a new three layered hybrid system with a lightweight antimalware engine. These features can provide faster malware detection response time, shield the client from malware and reduce the bandwidth between the client and the cloud, compared to other such systems. The paper serves as a motivation for improving the current and developing new techniques for in-cloud malware analysis and detection system. Shahid Alam, Ibrahim Sogukpinar, Issa Traoré, Yvonne Coady |
SIN | 3 |
| 2014 | Current Trends and the Future of Metamorphic Malware DetectionabstractDynamic binary obfuscation or metamorphism is a technique where a malware never keeps the same sequence of opcodes in the memory. This stealthy mutation technique helps a malware evade detection by today's signature-based anti-malware programs. This paper analyzes the current trends, provides future directions and reasons about some of the basic characteristics of a system for providing real-time detection of metamorphic malware. Our emphasis is on the most recent advancements and the potentials available in metamorphic malware detection, so we only cover some of the major academic research efforts carried out, including and after, the year 2006. The paper not only serves as a collection of recent references and information for easy comparison and analysis, but also as a motivation for improving the current and developing new techniques for metamorphic malware detection. Shahid Alam, Issa Traoré, Ibrahim Sogukpinar |
SIN | 2 |
| 2014 | Online risk-based authentication using behavioral biometrics
Issa Traoré, Isaac Woungang, Mohammad S. Obaidat, Youssef Nakkabi, Iris Lai |
Multim. Tools Appl. | 1 |
| 2014 | Biometric Recognition Based on Free-Text Keystroke DynamicsabstractAccurate recognition of free text keystroke dynamics is challenging due to the unstructured and sparse nature of the data and its underlying variability. As a result, most of the approaches published in the literature on free text recognition, except for one recent one, have reported extremely high error rates. In this paper, we present a new approach for the free text analysis of keystrokes that combines monograph and digraph analysis, and uses a neural network to predict missing digraphs based on the relation between the monitored keystrokes. Our proposed approach achieves an accuracy level comparable to the best results obtained through related techniques in the literature, while achieving a far lower processing time. Experimental evaluation involving 53 users in a heterogeneous environment yields a false acceptance ratio (FAR) of 0.0152% and a false rejection ratio (FRR) of 4.82%, at an equal error rate (EER) of 2.46%. Our follow-up experiment, in a homogeneous environment with 17 users, yields FAR=0% and FRR=5.01%, at EER=2.13%. Ahmed A. Ahmed, Issa Traoré |
IEEE Trans. Cybern. | 2 |
| 2013 | MAIL: Malware Analysis Intermediate Language: a step towards automating and optimizing malware detectionabstractDynamic binary obfuscation or metamorphism is a technique where a malware never keeps the same sequence of opcodes in the memory. Such malware are very difficult to analyse and detect manually even with the help of tools. We need to automate the analysis and detection process of such malware. This paper introduces and presents a new language named MAIL (Malware Analysis Intermediate Language) to automate and optimize this process. MAIL also provides portability for building malware analysis and detection tools. Each MAIL statement is assigned a pattern that can be used to annotate a control flow graph for pattern matching to analyse and detect metamorphic malware. Experimental evaluation of the proposed approach using an existing dataset yields malware detection rate of 93.92% and false positive rate of 3.02%. Shahid Alam, R. Nigel Horspool, Issa Traoré |
SIN | 3 |
| 2013 | Botnet detection based on traffic behavior analysis and flow intervals
Issa Traoré, Bassam Sayed, Wei Lu 0018, Sherif Saad, Ali A. Ghorbani 0001, Daniel Garant |
Comput. Secur. | 2 |
| 2013 | Semantic aware attack scenarios reconstruction
Sherif Saad, Issa Traoré |
J. Inf. Secur. Appl. | 2 |
| 2012 | Peer to Peer Botnet Detection Based on Flow Intervals
Issa Traoré, Ali A. Ghorbani 0001, Bassam Sayed, Sherif Saad, Wei Lu 0018 |
SEC | 2 |
| 2012 | Dynamic Sample Size Detection in Learning Command Line Sequence for Continuous AuthenticationabstractContinuous authentication (CA) consists of authenticating the user repetitively throughout a session with the goal of detecting and protecting against session hijacking attacks. While the accuracy of the detector is central to the success of CA, the detection delay or length of an individual authentication period is important as well since it is a measure of the window of vulnerability of the system. However, high accuracy and small detection delay are conflicting requirements that need to be balanced for optimum detection. In this paper, we propose the use of sequential sampling technique to achieve optimum detection by trading off adequately between detection delay and accuracy in the CA process. We illustrate our approach through CA based on user command line sequence and naïve Bayes classification scheme. Experimental evaluation using the Greenberg data set yields encouraging results consisting of a false acceptance rate (FAR) of 11.78% and a false rejection rate (FRR) of 1.33%, with an average command sequence length (i.e., detection delay) of 37 commands. When using the Schonlau (SEA) data set, we obtain FAR = 4.28% and FRR = 12%. Issa Traoré, Isaac Woungang, Youssef Nakkabi, Mohammad S. Obaidat, Ahmed Awad E. Ahmed, Bijan Khalilian |
IEEE Trans. Syst. Man Cybern. Part B | 1 |
| 2011 | A semantic analysis approach to manage IDS alerts floodingabstractIn this paper we propose a new approach to manage alerts flooding in IDSs. The proposed approach uses semantic analysis and ontology engineering techniques to combine and fuse two or more raw IDS alerts into one summarized hybrid/meta-alert. Our approach applies a new method based on measuring the semantic similarity between IDS alerts attributes to identify the alerts that are suitable for aggregation and summarization. In contrast to previous works our approach ensures that the aggregated alerts will not lose any valuable information existing in the raw alerts set. The experimental results show that our approach is effective and efficient in fusing massive number of alerts compared to previous works in the area. Sherif Saad, Issa Traoré |
IAS | 2 |
| 2011 | Dynamic sample size detection in continuous authentication using sequential samplingabstractContinuous Authentication (CA) departs from the traditional static authentication scheme by requiring the authentication process to occur multiple times throughout the entire logon session. One of the main objectives of the CA process is to detect session hijacking. An important requirement about designing or operating a CA system is the need to achieve the quickest detection while maintaining rates of missed and false detections to predetermined levels. We introduce in this paper a new approach for detection based on the sequential sampling theory that allows balancing appropriately between detection promptness and accuracy in CA systems. We study and illustrate the proposed approach using an existing mouse dynamics biometrics recognition model and corresponding sample experimental data. Ahmed Awad E. Ahmed, Issa Traoré |
ACSAC | 2 |
| 2011 | Detecting P2P botnets through network behavior analysis and machine learningabstractBotnets have become one of the major threats on the Internet for serving as a vector for carrying attacks against organizations and committing cybercrimes. They are used to generate spam, carry out DDOS attacks and click-fraud, and steal sensitive information. In this paper, we propose a new approach for characterizing and detecting botnets using network traffic behaviors. Our approach focuses on detecting the bots before they launch their attack. We focus in this paper on detecting P2P bots, which represent the newest and most challenging types of botnets currently available. We study the ability of five different commonly used machine learning techniques to meet online botnet detection requirements, namely adaptability, novelty detection, and early detection. The results of our experimental evaluation based on existing datasets show that it is possible to detect effectively botnets during the botnet Command-and-Control (C&C) phase and before they launch their attacks using traffic behaviors only. However, none of the studied techniques can address all the above requirements at once. Sherif Saad, Issa Traoré, Ali A. Ghorbani 0001, Bassam Sayed, Wei Lu 0018, John Felix, Payman Hakimian |
PST | 2 |
| 2011 | Homogeneous physio-behavioral visual and mouse-based biometricabstractIn this research, we propose a novel biometric system for static user authentication that homogeneously combines mouse dynamics, visual search capability and short-term memory effect. The proposed system introduces the visual search capability, and short-term memory effect to the biometric-based security world for the first time. The use of a computer mouse for its dynamics, and as an input sensor for the other two biometrics, means no additional hardware is required than the standard mouse. Experimental evaluation showed the system effectiveness using variable or one-time passwords. All of these attributes qualify the proposed system to be effectively deployed as a static authentication mechanism. Extensive experimentation was done using 2740 sessions collected from 274 users. To measure the performance, a computational statistics model was specially designed and used; a statistical classifier based on Weighted-Sum produced an Equal Error Rate (EER) of 2.11%. Omar Hamdy, Issa Traoré |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2010 | Double Spending Protection for E-Cash Based on Risk Management
Patricia Everaere, Isabelle Simplot-Ryl, Issa Traoré |
ISC | 3 |
| 2010 | Method ontology for intelligent network forensics analysisabstractNetwork forensics is an after the fact process to investigate malicious activities conducted over computer networks by gathering useful intelligence. Recently, several machine learning techniques have been proposed to automate and develop intelligent network forensics systems. An intelligent network forensics system that reconstructs intrusion scenarios and makes attack attributions requires knowledge about intrusions signatures, evidences, impacts, and objectives. In addition, problem solving knowledge that describes how the system can use domain knowledge to analyze malicious activities is essential for the design of intelligent network forensics systems. In this paper we adapt recent researches in semantic-web, information architecture, and ontology engineering to design a method ontology for network forensics analysis. The proposed ontology represents both network forensics domain knowledge and problem solving knowledge. It can be used as a knowledge-base for developing sophisticated intelligent network forensics systems to support complex chain of reasoning. We use a real life network intrusion scenario to show how our ontology can be integrated and used in intelligent network forensics systems. Sherif Saad, Issa Traoré |
PST | 2 |
| 2010 | Improving Mouse Dynamics Biometric Performance Using Variance Reduction via Extractors With Separate FeaturesabstractThe European standard for access control imposes stringent performance requirements on commercial biometric technologies that few existing recognition systems are able to meet. In this correspondence paper, we present the first mouse dynamics biometric recognition system that fulfills this standard. The proposed system achieves notable performance improvement by developing separate models for separate feature groups involved. The improvements are achieved through the use of a fuzzy classification based on the Learning Algorithm for Multivariate Data Analysis and using a score-level fusion scheme to merge corresponding biometric scores. Evaluation of the proposed framework using mouse data from 48 users achieves a false acceptance rate of 0% and a false rejection rate of 0.36%. Youssef Nakkabi, Issa Traoré, Ahmed Awad E. Ahmed |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2009 | New Physiological Biometrics Based on Human Cognitive FactorsabstractModeling and quantifying different human factors continue to be one of the major challenges in introducing new biometric systems. For example, drivers of some of our behavior differences are still mysteries, and hence cannot be modeled.In this paper, we propose a novel biometric system; it introduces the visual search and short-term memory human factors to the world of biometrics. This homogeneous system uses only the standard mouse as an input sensor for the two biometric factors.Experimental evaluation was performed using mass enrollment of 275 participants, and Neural Network for classification. Results showed an Equal Error Rate (EER) of 3.88%. Omar Hamdy, Issa Traoré |
CISIS | 2 |
| 2009 | A New Method for Learning Decision Trees from RulesabstractMost of the methods that generate decision trees use examples of data instances in the decision tree generation process. This paper proposes a method called "RBDT-1"- rule based decision tree - for learning a decision tree from a set of decision rules that cover the data instances rather than from the data instances themselves. RBDT-1 method uses a set of declarative rules as an input for generating a decision tree. The method's goal is to create on-demand a short and accurate decision tree from a stable or dynamically changing set of rules. We conduct a comparative study of RBDT-1 with three existing decision tree methods based on different problems. The outcome of the study shows that RBDT-1 performs better than AQDT-1 and AQDT-2 which are methods that create decision trees from rules and than ID3 which generates decision trees from data examples, in terms of tree complexity number of nodes and leaves in the decision tree. Amany Abdelhalim, Issa Traoré |
ICMLA | 2 |
| 2008 | Contract-Based Security Monitors for Service Oriented Software ArchitectureabstractMonitors have been used for real-time systems to ensure proper behavior; however, most approaches do not allow for the addition of relevant fields required to identify and react to security vulnerabilities. Contracts can provide a useful mechanism for identifying and tracking vulnerabilities. Currently, contracts have been proposed for reliability and formal verification; yet, their use in security is limited. Static analysis methods are able to identify many known vulnerabilities; however, they suffer from a high rate of false-positives. The creation of a mechanism that can verify identified vulnerabilities is therefore warranted. We propose a contract-based security assertion monitoring framework (CB SAMF) for reducing the number of security vulnerabilities that are exploitable. CB SAMF will span multiple software layers and be used in an enhanced systems development life cycle (SDLC) including service-oriented analysis and design (SOAD). Alexander M. Hoole, Issa Traoré |
APSCC | 2 |
| 2008 | A Service-Oriented Framework for Quantitative Security Analysis of Software ArchitecturesabstractSoftware systems today often run in malicious environments in which attacks or intrusions are quite common. This situation has brought security concerns into the development of software systems. Generally, software services are expected not only to satisfy functional requirements but also to be resistant to malicious attacks. Software attackability is defined as the likelihood that an attack on a software system will succeed. In this paper, we present a service-oriented framework to analyze attackability of software systems. More specifically, we propose a User System Interaction Effect (USIE) model that can be used systematically to derive and analyze security concerns from service-oriented software architectures. Many aspects of the model derivation and analysis can be automated, which limit the amount of user involvement, and thereby reduce the subjectivity underlying typical security risk analysis process. The model can be used as a foundation for quantitative analysis of software services from different security perspectives. Yanguo Liu, Issa Traoré, Alexander M. Hoole |
APSCC | 2 |
| 2008 | Unsupervised anomaly detection using an evolutionary extension of k-means algorithmabstractIn this paper, we propose a new unsupervised anomaly detection framework for network intrusions. The framework consists of a new clustering algorithm named I-means and new anomalousness metrics named IP Weights. I-means is an evolutionary extension of k means algorithm that estimates automatically the number of clusters for a set of data. IP Weights allow the automatic conversion of regular packet features into a 3-dimensional numerical feature space. Online and offline evaluations show not only strong detection effectiveness, but also strong runtime efficiency, with response times falling within a few seconds ranges. Wei Lu 0018, Issa Traoré |
Int. J. Inf. Comput. Secur. | 2 |
| 2008 | Inverse Biometrics for mouse DynamicsabstractVarious techniques have been proposed in different literature to analyze biometric samples collected from individuals. However, not a lot of attention has been paid to the inverse problem, which consists of synthesizing artificial biometric samples that can be used for testing existing biometric systems or protecting them against forgeries. In this paper, we present a framework for mouse dynamics biometrics synthesis. Mouse dynamics biometric is a behavioral biometric technology, which allows user recognition based on the actions received from the mouse input device while interacting with a graphical user interface. The proposed inverse biometric model learns from random raw samples collected from real users and then creates synthetic mouse actions for fake users. The generated mouse actions have unique behavioral properties separate from the real mouse actions. This is shown through various comparisons of behavioral metrics as well as a Kolmogorov–Smirnov test. We also show through a two-fold cross-validation test that by submitting sample synthetic data to an existing mouse biometrics analysis model we achieve comparable performance results as when the model is applied to real mouse data. Akif Nazar, Issa Traoré, Ahmed Awad E. Ahmed |
Int. J. Pattern Recognit. Artif. Intell. | 2 |
| 2007 | A New Biometric Technology Based on Mouse DynamicsabstractIn this paper, we introduce a new form of behavioral biometrics based on mouse dynamics, which can be used in different security applications. We develop a technique that can be used to model the behavioral characteristics from the captured data using artificial neural networks. In addition, we present an architecture and implementation for the detector, which cover all the phases of the biometric data flow including the detection process. Experimental data illustrating the experiments conducted to evaluate the accuracy of the proposed detection technique are presented and analyzed. Specifically, three series of experiments are conducted. The main experiment, in which 22 participants are involved, reproduces real operating conditions in computing systems by giving participants an individual choice of operating environments and applications; 284 hours of raw mouse data are collected over 998 sessions, with an average of 45 sessions per user. The two other experiments, involving seven participants, provided a basis for studying the confounding factors arising from the main experiment by fixing the environment variables. In the main experiment, the performance results presented using receiver operating characteristic (ROC) curves and a confusion matrix yield at the crossover point (that is, the threshold set for an equal error rate) a false acceptance rate (FAR) of 2.4649 percent and a false rejection rate (FRR) of 2.4614 percent. Ahmed Awad E. Ahmed, Issa Traoré |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2006 | Integrated Security Verification and Validation: Case StudyabstractIn most current approaches to software security, security flaws are fixed only after they have been exploited. To increase user confidence in software products, the software industry needs more proactive and durable security solutions by addressing security requirements throughout the software system lifecycle, including requirements and design specification, testing, and maintenance phases. Appropriate security analysis techniques must be used for each of these phases. In this paper, we illustrate an integrated security analysis framework, which combines a quantitative design security analysis technique, with a static program analyzer, which tracks unsafe information flows. We illustrate the framework by presenting a case study based on medical information card Dorina Ghindici, Gilles Grimaud, Isabelle Simplot-Ryl, Yanguo Liu, Issa Traoré |
LCN | 5 |
| 2005 | A New Unsupervised Anomaly Detection Framework for Detecting Network Attacks in Real-Time
Wei Lu 0018, Issa Traoré |
CANS | 2 |
| 2005 | A Prevention Model for Algorithmic Complexity Attacks
Suraiya Khan, Issa Traoré |
DIMVA | 2 |
| 2005 | Determining the Optimal Number of Clusters Using a New Evolutionary AlgorithmabstractEstimating the optimal number of clusters for a dataset is one of the most essential issues in cluster analysis. An improper preselection for the number of clusters might easily lead to bad clustering outcome. In this paper, we propose a new evolutionary algorithm to address this issue. Specifically, the proposed evolutionary algorithm defines a new entropy-based fitness function, and three new genetic operators for splitting, merging, and removing clusters. Empirical evaluations using the synthetic dataset and an existing benchmark show that the proposed evolutionary algorithm can exactly estimate the optimal number of clusters for a set of data Wei Lu 0018, Issa Traoré |
ICTAI | 2 |
| 2005 | Detecting Computer Intrusions Using Behavioral Biometrics
Ahmed Awad E. Ahmed, Issa Traoré |
PST | 2 |
| 2004 | Detecting New Forms of Network Intrusion Using Genetic ProgrammingabstractHow to find and detect novel or unknown network attacks is one of the most important objectives in current intrusion detection systems. In this paper, a rule evolution approach based on Genetic Programming (GP) for detecting novel attacks on networks is presented and four genetic operators, namely reproduction, mutation, crossover, and dropping condition operators, are used to evolve new rules. New rules are used to detect novel or known network attacks. A training and testing dataset proposed by DARPA is used to evolve and evaluate these new rules. The proof of concept implementation shows that a rule generated by GP has a low false positive rate (FPR), a low false negative rate and a high rate of detecting unknown attacks. Moreover, the rule base composed of new rules has high detection rate with low FPR. An alternative to the DARPA evaluation approach is also investigated. Wei Lu 0018, Issa Traoré |
Comput. Intell. | 2 |
| 2004 | An integrated framework for formal development of open distributed systems
Issa Traoré, Demissie B. Aredo |
Inf. Softw. Technol. | 1 |
| 2004 | Enhancing Structured Review with Model-Based VerificationabstractWe propose a development framework that extends the scope of structured review by supplementing the structured review with model-based verification. The proposed approach uses the Unified Modeling Language (UML) as a modeling notation. We discuss a set of correctness arguments that can be used in conjunction with formal verification and validation (V&V) in order to improve the quality and dependability of systems in a cost-effective way. Formal methods can be esoteric; consequently, their large scale application is hindered. We propose a framework based on the integration of lightweight formal methods and structured reviews. Moreover, we show that structured reviews enable us to handle aspects of V&V that cannot be fully automated. To demonstrate the feasibility of our approach, we have conducted a study on a security-critical system - a patient document service (PDS) system. Issa Traoré, Demissie B. Aredo |
IEEE Trans. Software Eng. | 1 |
| 2003 | Detecting new forms of network intrusion using genetic programmingabstractHow to find and detect novel or unknown network attacks is one of the most important objectives in current intrusion detection systems. In this paper, a rule evolution approach based on genetic programming (GP) for detecting novel attacks on network is presented and four genetic operators namely reproduction, mutation, crossover and dropping condition operators are used to evolve new rules. New rules are used to detect novel or known network attacks. A training and testing dataset proposed by DARPA is used to evolve and evaluate these new rules. The proof of concept implementation shows that the rule generated by GP has a low false positive rate (FPR), a low false negative rate (FNR) and a high rate of detecting unknown attacks. Moreover, the rule base composed of new rules has high detection rate (DR) with low false alarm rate (FAR). Wei Lu 0018, Issa Traoré |
IEEE Congress on Evolutionary Computation | 2 |
| 2001 | An Integrated V&V Environment for Critical Systems Development
Issa Traoré |
RE | 1 |