Ahmad Samer Wazan

dblp:10/5759 · DBLP profile ↗
← Back
20ranked-venue papers
10as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 6 first-author · 6 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 The three-eyed invigilator: an AI-powered interactive rotator for enhanced online exam proctoring
Muhammad Imran Taj 0001, Ahmad Samer Wazan, Anis Bey
Neural Comput. Appl.2
2025 No Root, No Problem: Automating Linux Least Privilege and Securing Ansible Deployments
Eddie Billoir, Romain Laborde, Daniele Canavese, Yves Rütschlé, Ahmad Samer Wazan, Benzekri Abdelmalek
ESORICS (3)5
2025 Enhancing the ACME protocol to automate the management of all X.509 web certificates (Extended version)
David Cordova Morales, Ahmad Samer Wazan, David W. Chadwick, Romain Laborde, April Rains Maramara
Comput. Commun.2
2024 Enhancing Secure Deployment with Ansible: A Focus on Least Privilege and Automation for Linux
abstract
As organisations increasingly adopt Infrastructure as Code (IaC), ensuring secure deployment practices becomes paramount. Ansible is a well-known open-source and modular tool for automating IT management tasks. However, Ansible is subject to supply-chain attacks that can compromise all managed hosts. This article presents a semi-automated process that improves Ansible-based deployments to have fine-grained control on administrative privileges granted to Ansible tasks. We describe the integration of the RootAsRole framework to Ansible. Finally, we analyse the limit of the current implementation.
Eddie Billoir, Romain Laborde, Ahmad Samer Wazan, Yves Rütschlé, Benzekri Abdelmalek
ARES3
2024 Article 45 of the eIDAS Directive Unveils the need to implement the X.509 4-cornered trust model for the WebPKI
abstract
Article 45 of the new eIDAS Directive (eIDAS 2.0) has caused significant debate on the Internet as it gives European governments the power to make EU-certificated web certificates accepted without the approval of web browsers/OS, which are considered to be the current gatekeepers of the WebPKI ecosystem. This paper goes beyond the current debate between the WebPKI gatekeepers and the European Commission (EC) about the implications of Article 45. It shows how both approaches do not provide full protection to web users. We propose a better approach that Europe can follow to regulate web X.509 certificates: Rather than regulating the issuance of web X.509 certificates, the EC can play the role of a validator that recommends the acceptance of certificates at the web scale.
Ahmad Samer Wazan, Romain Laborde, Benzekri Abdelmalek, Muhammad Imran Taj 0001
ARES1
2023 Enhancing the ACME Protocol to Automate the Management of All X.509 Web Certificates
David Cordova Morales, Ahmad Samer Wazan, David W. Chadwick, Romain Laborde, April Rains Maramara, Kalil Cabral
SEC2
2022 On the Validation of Web X.509 Certificates by TLS Interception Products
abstract
The Transport Layer Security (TLS) protocol aims to provide confidentiality and integrity of data. It is based on X.509 Certificates. Our previous research showed that popular Web Browsers exhibit non-standardized behaviour with respect to the certificate validation process[1]. This article extends that work by examining their handling of OCSP Stapling. We also examine several popular HTTPS interception products, including proxies and anti-virus tools, regarding their certificate validation processes. We analyse and compare their behaviour to that described in the relative standards.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, Rémi Venant, Benzekri Abdelmalek, Eddie Billoir, Omar Alfandi
IEEE Trans. Dependable Secur. Comput.1
2021 Which Virtualization Technology is Right for My Online IT Educational Labs?
abstract
Many IT labs require virtualization technology as students need to learn several software tools and operating systems. In an online setting, students sometimes are expected to fill the role of an IT lab architect by installing, configuring, deploying lab tasks on their personal computers, and deciding the virtualization technology needed. This can be intimidating and time-consuming for many students. Further, students often use traditional virtualization technology that is neither needed nor justified costing students significant time, effort, and computing resources. Existing studies discuss virtualization technology appropriateness in the context of industrial applications. This study, however, explores potential virtualization technologies that can be utilized in an academic setting by means of case studies that reflect our experience in transforming the labs of one of our courses. This study assesses virtualization technology suitability in online academic labs in terms of networking, setup time, feasibility, storage, and performance.
Ahmad Samer Wazan, Mohammad A. Kuhail, Kadhim Hayawi, Rémi Venant
EDUCON1
2021 RootAsRole: Towards a Secure Alternative to sudo/su Commands for Home Users and SME Administrators
Ahmad Samer Wazan, David W. Chadwick, Rémi Venant, Romain Laborde, Benzekri Abdelmalek
SEC1
2020 Know Your Customer: Opening a new bank account online using UAAF
abstract
Universal Authentication and Authorization Framework is a user-centric, privacy by design and decentralized system that allows anyone to easily benefit from a reliable digital identity made of multi-purpose and multi-origin attributes. In this article, we present the implementation of this framework in the context of online banking. We demonstrate how it can facilitate enforcing Know Your Customer when opening a new bank account online by allowing users to combine verifiable identity attributes issued by different organizations.
Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant
CCNC3
2020 A User-Centric Identity Management Framework based on the W3C Verifiable Credentials and the FIDO Universal Authentication Framework
abstract
We present a user-centric and decentralized digital identity system that allows anyone to easily benefit from an enriched digital identity made of multi-purpose and multi-origin attributes. It increases usability by the elimination of user passwords. It also makes this digital identity highly trustworthy both for the user (in terms of privacy and sovereignty) and the service provider who requires highly certified information about the user being enrolled to and/or authenticated on its services. We built our system based on the Universal Authentication Framework specified by the FIDO Alliance and the data model proposed by the W3C Verifiable Credentials WG. The whole system has been implemented in a banking scenario.
Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant
CCNC3
2017 Which Security Requirements Engineering Methodology Should I Choose?: Towards a Requirements Engineering-based Evaluation Approach
abstract
Since many decades, requirements engineering domain has seen significant enhancements towards adapting the security and risk analysis concepts. In this regard, there exist numerous security requirements engineering methodologies that support elicitation and evaluation of the security requirements. However, selecting a security requirements engineering methodology (SRE) for a given context of use often depends on a set of ad hoc criteria. In this paper, we propose a methodological evaluation methodology that helps in identifying the characteristics of a good SRE methodology.
Sravani Teja Bulusu, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
ARES3
2017 TLS Connection Validation by Web Browsers: Why do Web Browsers Still Not Agree?
abstract
The TLS protocol is the primary technology used for securing web transactions. It is based on X.509 certificates that are used for binding the identity of web servers' owners to their public keys. Web browsers perform the validation of X.509 certificates on behalf of Web users. Our previous research in 2009 showed that the validation process of Web browsers is inconsistent and flawed. We showed how this situation might have a negative impact on Web users. From 2009 until now, many new X.509 related standards have been created or updated. In this paper, we performed an increased set of experiments over our 2009 study in order to highlight the improvements and/or regressions in Web browsers' behaviours.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
COMPSAC (1)1
2017 Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker
abstract
A Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the certification authority (CA), the certificate holder (or subject), and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However, we argue that the application of this model on the Internet implies that web users need to depend on almost anyone in the world in order to use PKI technology. Thus, we believe that the current TLS system is not fit for purpose and must be revisited as a whole. In response, the latest draft edition of X.509 has proposed a new trust model by adding new entity called the Trust Broker (TB). In this paper, we present an implementation approach that a Trust Broker could follow in order to give RPs trust information about a CA by assessing the quality of its issued certificates. This is related to the quality of the CA’s policies and procedures and its commitment to them. Finally, we present our Trust Broker implementation that demonstrates how RPs can make informed decisions about certificate holders in the context of the global web, without requiring large processing resources themselves.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek, Mustafa Kaiiali, Adib Habbal
Secur. Commun. Networks1
2016 Towards the Weaving of the Characteristics of Good Security Requirements
Sravani Teja Bulusu, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
CRiSIS3
2016 How Can I Trust an X.509 Certificate? An Analysis of the Existing Trust Approaches
abstract
A Public Key Infrastructure (PKI) is based on a trust model defined by the original X.509 standard and is composed of three entities: the Certification Authority, the certificate holder (subject) and the Relying Party. The CA plays the role of a trusted third party between the subject and the RP. A trust evaluation problem is raised when an RP receives a certificate from an unknown subject that is signed by an unknown CA. Different approaches have been proposed to handle this trust problem. We argue that these approaches work only in the closed deployment model where RPs are also subjects, but cannot work in the open deployment model where they are not. Our objective is to identify the deficiencies in the existing trust approaches that try to help RPs to make trust decisions about certificates in the Internet, and to introduce the new X.509 approach based on a trust broker.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
LCN1
2015 G-Cloud on Openstack: Adressing access control and regulation requirements
abstract
It is well known that e-Government applications bring several benefits to citizens in terms of efficiency, accessibility and transparency. Today, most of governments tend to propose cloud computing based e-services to their citizens. A key component in these services is the access control management issue. In this paper, we present our research works for building an access control system for the Djiboutian e-Government project that is built using Openstack framework. Specifically, we demonstrate the limitation of the integrated access control system in Openstack for the Djiboutian e-Government access control requirements and for the compliance to the related regulation. Thus, we propose to extend the existing access control system of Openstack by integrating the features of the XACML V3 to the Openstack framework.
Ibrahim Yonis Omar, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
ISNCC3
2012 The X.509 trust model needs a technical and legal expert
abstract
The X.509 trust model is based on three entities: the certification authority (CA), the certificate holder and the relying party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. It guarantees to the RP the correctness of the certificate information. This trust model is based on hypothesis that RPs have a predefined trust relation with a CA and that the trust level in CA can be determined by reading and analyzing a set of technical and legal documents. The X.509 trust model is so complex to RPs because an RP must realize this task for each and every CA chosen by the certificate holders. We introduce a new role of technical and legal expert into the X.509 trust model to help the RP make this task.
Ahmad Samer Wazan, Romain Laborde, François Barrère, Benzekri Abdelmalek
ICC1
2011 A formal model of trust for calculating the quality of X.509 certificate
abstract
Abstract The growing number of Public Key Infrastructure (PKI) and the increasing number of situations where partners of a transaction may carry certificates signed by different certification authority (CA) points out the problematic of trust between the different CAs. Several trust models, like the hierarchy model, cross‐certification model, and bridge CA model were proposed in order to establish and extend the domain of trust of relying parties (RP). However, each model has disadvantages and especially the scalability in large open networks like Internet. In this paper, we provide users with quantitative information of the confidence a relying party can have about a certificate. We call this information quality of certificate (QoCER). QoCER depends on two parameters which are the quality of procedures announced in the certificate policy (CP) and the quality of CA (QoCA) that represents the evaluation of the CA commitment to its policy. QoCA is calculated based on the recommendation of different actors (audit agency, RP, etc.). QoCER is balanced by another information that represents the confidence on QoCA calculation. We present a formal model of trust to calculate these values. Copyright © 2010 John Wiley & Sons, Ltd.
Ahmad Samer Wazan, Romain Laborde, François Barrère, Benzekri Abdelmalek
Secur. Commun. Networks1
2009 Which Web Browsers Process SSL Certificates in a Standardized Way?
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
SEC1