Ashraf Matrawy

dblp:11/2732 · DBLP profile ↗
← Back
45ranked-venue papers
6as first author
17since 2021 · last 2026
0000-0001-9220-4630ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 27 · 3 first-author · 13 since 2021Security and privacy · 8 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Exploratory TEID-Based Defence against Flooding Attacks in 5G Slicing
Adam Ali Husseinat, Ashraf Matrawy
ICC2
2026 A novel perturb-ability score to mitigate evasion adversarial attacks on flow-based ML-NIDS
abstract
• Proposes PS to quantify flow-based NIDS features susceptibility to attacks. • PS-guided defenses achieve 0% attack success rate with high detection accuracy. • Universal protection independent of attack types and ML models without overhead. • Validated across UNSW-NB15, CSE-CIC-IDS2018 and MCFP datasets. As network security threats evolve, safeguarding flow-based Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS) from evasion adversarial attacks is crucial. This paper introduces the notion of feature perturb-ability and presents a novel Perturb-ability Score (PS) , which quantifies how susceptible NIDS features are to manipulation in the problem-space by an attacker. PS thereby identifies features structurally resistant to evasion attacks in flow-based ML-NIDS due to the semantics of network traffic fields, as these features are constrained by domain-specific limitations and correlations. Consequently, attempts to manipulate such features would likely either compromise the attack’s malicious functionality, render the traffic invalid for processing, or potentially both outcomes simultaneously. We introduce and demonstrate the effectiveness of our PS-enabled defenses, PS-guided feature selection and PS-guided feature masking, in enhancing flow-based NIDS resilience. Experimental results across various ML-based NIDS models and public datasets show that discarding or masking highly manipulatable features (high-PS features) can maintain solid detection performance while significantly reducing vulnerability to evasion adversarial attacks. Our findings confirm that PS effectively identifies flow-based NIDS features susceptible to problem-space perturbations. This novel approach leverages problem-space NIDS domain constraints as lightweight universal defense mechanisms against evasion adversarial attacks targeting flow-based ML-NIDS.
Mohamed elShehaby, Ashraf Matrawy
J. Inf. Secur. Appl.2
2025 A Study of XR Traffic Characteristics Under Flooding Attacks on 5G Slicing
abstract
Network slicing (NS) plays a crucial role in 5G networks; it enables the delivery of heterogeneous services and uses cases such as voice communication, video streaming, and Extended Reality (XR), and it also partitions the physical network into several logical networks, known as network slices, to cater the vertical industries via sharing the physical infrastructure. However, infrastructure and functional sharing present security and privacy challenges. In this work, we examine the characteristics of XR traffic across several 5G slicing configurations in the presence of attacks, including ping flood, User Datagram Protocol (UDP) flood, and registration flood attacks. The primary contribution of our research is the analysis of the impact of these different attacks on the XR traffic using different slice configurations. The results indicate the effects of the different attacks on XR traffic in terms of reducing the traffic throughput (Mbps) and the changes in the XR traffic characteristics in the different slice configurations. Also, the isolation of the Virtual Network Functions (VNFs) in the user plane provides better performance in the presence of these attacks.
Adam Ali Husseinat, AbdulAziz AbdulGhaffar, Ashraf Matrawy
ICC3
2025 Trimming the Fat: Introducing QUIC Thin-Apps for the Internet of Things
abstract
QUIC, a general-purpose transport protocol, is receiving growing interest in the context of the Internet of Things (IoT), as researchers have mapped various IoT applications over to QUIC transport. In this paper, we aim to show that since QUIC is so feature-rich on its own, uper-layer complexities of traditional protocols can be greatly reduced or even eliminated. A technology's simplicity and resource frugality are critical for IoT devices. To exemplify this, we have designed a publish-subscribe 'thin-app' for IoT, relying almost entirely on QUIC's specification. We achieved comparable functionality to MQTT, doing away with the need for much of its control messaging. Furthermore, experimentation with our solution against MQTTv5 shows significant reductions in signaling overhead while maintaining comparable CPU and memory utilization.
Darius Saif, Ashraf Matrawy
ICC2
2025 Adaptive Continuous Adversarial Training (ACAT) to Enhance ML-NIDS Robustness
abstract
In this paper, we extend our previously proposed Adaptive Continuous Adversarial Training (ACAT) method beyond the problem-space of SPAM filters to encompass the featurespace of Machine Learning (ML)-based Network Intrusion Detection Systems (NIDS). ACAT continuously improves model robustness by incorporating adversarial samples detected from the ML-NIDS input network traffic into the training process. Problem-space evasion attacks rely on inverse-feature mapping, where modifications to real-world objects result in targeted perturbations within the feature vector after feature extraction. Therefore, protecting ML systems against feature-space attacks inherently provides defense against both feature-space and problem-space evasion attacks. Our results demonstrate that ACAT significantly reduces adversarial sample detection time compared to traditional techniques. Moreover, the performance of the ML-based NIDS under attack improved dramatically, with accuracy increasing from 50.92 % to over 99 % after only three retraining sessions.
Mohamed elShehaby, Aditya Kotha, Ashraf Matrawy
ICC3
2025 Interaction-Aware Trust Management Scheme for IoT Systems With Machine-Learning-Based Attack Detection
abstract
The recent Internet of Things (IoT) adoption has revolutionized various applications while introducing significant security and privacy challenges. Traditional security solutions are unsuitable for IoT systems due to their dynamicity, heterogeneity, and resource constraints. Trust-based solutions are emerging as promising alternatives due to their ability to track the dynamic behavior in IoT systems. However, existing trust management schemes are implemented at the device level, raising several challenges, including device modification, that compromises certification and scalability, increased network overhead, and higher device resource utilization. To address these challenges, this article proposes a novel trust management scheme that shifts its implementation to a higher layer in the IoT system, specifically to the IoT access layer (e.g., gateway). The proposed scheme establishes trust based on typical device interactions with the gateway without requiring additional information from the device. It relies on objective attributes spanning communication, security, and advanced dimensions to compute the trust value of an IoT device. Additionally, an artificial neural network (ANN) is integrated to determine if the device acts maliciously or behaves normally. Simulation results demonstrate a notable improvement in the detection rate, primarily due to incorporating the proposed ANN, compared to the threshold-based approaches in the literature. Overall, the improvements highlight the significant advantage of the proposed scheme’s robustness.
Ali Farhat, AbdelRahman Eldosouky, Mohamed Ibnkahla, Ashraf Matrawy
IEEE Internet Things J.4
2025 A Datagram Extension to DNS Over QUIC: Proven Resource Conservation in Internet of Things
abstract
In this paper, we investigate the Domain Name System (DNS) over QUIC (DoQ) and propose a non-disruptive extension, which can greatly reduce DoQ’s resource consumption. This extension can benefit all DNS clients – especially Internet of Things (IoT) devices. This is important because even resource-constrained IoT devices can generate dozens of DNS requests every hour. DNS is a crucial service that correlates IP addresses and domain names. It is traditionally sent as plain-text, favoring low-latency results over security and privacy. The repercussion of this can be eavesdropping and information leakage about IoT devices. To address these concerns, the newest and most promising solution is DoQ. QUIC offers features similar to TCP and TLS while also supporting early data delivery and stream multiplexing. DoQ’s specification requires that DNS exchanges occur over independent streams in a long-lived QUIC connection. Our hypothesis is that due to DNS’s typically high transaction volume, managing QUIC streams may be overly resource intensive for IoT devices. Therefore, we have designed and implemented a data delivery mode for DoQ using QUIC datagrams, which we believe to be more preferable than stream-based delivery. To test our theory, we analyzed the memory, CPU, signaling, power, and time of each DoQ delivery mode in a setup generating real queries and network traffic. Our novel datagram-based delivery mode proved to be decisively more resource-friendly with little compromise in terms of functionality or performance. Furthermore, our paper is the first to investigate multiple queries over DoQ, to our knowledge.
Darius Saif, Ashraf Matrawy
IEEE Internet Things J.2
2025 Cybersecurity Challenge Analysis of Work-From-Anywhere (WFA) and Recommendations Guided by a User Study
abstract
Many organizations were forced to quickly transition to the work-from-anywhere (WFA) model as a necessity to continue with their operations and remain in business despite the restrictions imposed during the COVID-19 pandemic. Many decisions were made in a rush, and cybersecurity decency tools were not in place to support this transition. In this article, we first attempt to uncover some challenges and implications related to the cybersecurity of the WFA model. Second, we conducted an online user study to investigate the readiness and cybersecurity awareness of employers and their employees who shifted to work remotely from anywhere. The user study questionnaire addressed different resilience perspectives of individuals and organizations. The collected data includes 45 responses from remotely working employees of different organizational types: Universities, government, private, and nonprofit organizations. Despite the importance of security training and guidelines, it was surprising that many participants had not received them. A robust communication strategy is necessary to ensure that employees are informed and updated on security incidents that the organization encounters. In addition, there is an increased need to pay attention to the security-related attributes of employees, such as their behavior, awareness, and compliance. Finally, we outlined best practice recommendations and mitigation tips guided by the study results to help individuals and organizations resist cybercrime and fraud and mitigate WFA-related cybersecurity risks.
Mohammed Mahyoub, Ashraf Matrawy, Kamal Isleem, Olakunle Ibitoye
IEEE Trans. Hum. Mach. Syst.2
2024 Temporal Partitioned Federated Learning for IoT Intrusion Detection Systems
abstract
Machine learning-based intrusion detection systems (IDSs) serve as a defense-in-depth layer for Internet of Things (IoT) networks by detecting potential intrusions within IoT traffic. However, resource-constrained IoT devices impose sig-nificant challenges in developing effective IDSs. Recently, fed-erated learning (FL) has emerged as a promising solution for training detection models on distributed IoT devices without compromising resource limitations resulting in the introduction of FL-based IDSs. To this end, this paper introduces a novel approach to enhance the effectiveness of current FL-based IoT IDSs while utilizing the same resources. The proposed system partitions the FL rounds between IoT device groups, allowing each group to update the FL detection model during its time partition. Hence, by implementing this temporal partitioning, multiple detection models are updated within one FL round using the same IoT resources. The main design goals of the proposed approach are to improve detection accuracy and convergence time compared to the traditional approach. For this purpose, the proposed approach is evaluated and compared to the traditional approach using five intrusion scenarios on IoT traffic obtained from the Edge-IIoTset dataset. The results demonstrate that the proposed temporal partitioned FL-based IoT IDS outperforms the traditional system by achieving higher detection accuracy and faster convergence time. Furthermore, the proposed approach achieves the required detection accuracy in fewer FL rounds, which can, in principle, save more IoT resources.
Mohannad Abu Issa, Mohamed Ibnkahla, Ashraf Matrawy, AbdelRahman Eldosouky
WCNC3
2024 An Experimental Investigation of Tuning QUIC-Based Publish-Subscribe Architectures in IoT
abstract
There has been growing interest in using the QUIC transport protocol for the Internet of Things (IoT). In lossy and high-latency networks, QUIC outperforms TCP and TLS. Since IoT greatly differs from traditional networks in terms of architecture and resources, IoT specific parameter tuning has proven to be of significance. While RFC 9006 offers a guideline for tuning TCP within IoT, we have not found an equivalent for QUIC. This article is the first of our knowledge to contribute empirically based insights toward tuning QUIC for IoT. We improved our pure HTTP/3 publish–subscribe architecture and rigorously benchmarked it against an alternative: MQTT-over-QUIC. To investigate the impact of transport-layer parameters, we ran both applications on Raspberry Pi Zero hardware. Eight metrics were collected while emulating different network conditions and message payloads. We enumerate the points we experimentally identified (notably, relating to authentication, MAX_STREAM messages, and timers) and elaborate on how they can be tuned to improve resource consumption and performance. Our application offered lower latency than MQTT-over-QUIC with slightly higher resource consumption, making it preferable for reliable time-sensitive dissemination of information.
Darius Saif, Ashraf Matrawy
IEEE Internet Things J.2
2023 IoT Trust Establishment Through System Level Interactions and Communication Attributes
abstract
The integration of Internet of Things (loT)-based solutions in various applications introduced several challenges in security and privacy. Due to the nature of loT systems, traditional security solutions are not suitable for solving these challenges. Researchers introduced trust management as a viable solution due to its ability to track the dynamic behavior of loT devices. Compared to traditional security solutions, trust does not require an extensive amount of resources. Several loT trust solutions rely on distributed models that increase network overhead and consume additional energy. To this end, this work proposes a trust management scheme for loT systems that can be implemented at the access layer of loT systems. The proposed scheme establishes trust for loT devices through device-system interaction and communication attributes without requiring any additional information or modifications to the device. The trust value is computed using the trust attributes over a specific window size of interactions and using a forget factor. Simulation results show the ability of the proposed scheme to track the behavior of loT devices. Results also show that the proposed scheme maintains high performance in detecting persistent attacks compared to existing schemes from the literature, while improving the detection rate of ON-OFF attacks by 15%.
Ali Farhat, AbdelRahman Eldosouky, Mohamed Ibnkahla, Ashraf Matrawy
GLOBECOM4
2022 A Formal Analysis of the Efficacy of Rebooting as a Countermeasure Against IoT Botnets
abstract
The Mirai botnet revolutionized the idea of IoT botnets by infecting numerous vulnerable IoT devices in 2016, leading to the rise of many Mirai variants and imitators that plague the current IoT ecosystem. Studying the botnet infection process can greatly aid us in understanding IoT botnet capabilities and the efficacy of currently available countermeasures. However, analyzing IoT botnets is difficult due to their massive scale and the numerous existing heterogeneous IoT devices that can be targeted for infection. In this paper, we model and simulate the dynamic behavior of a Mirai-like botnet infrastructure and various IoT device categories as a network of timed automata in UPPAAL-SMC. To determine the feasibility of rebooting as a countermeasure against botnets, we examine the effectiveness of rebooting on various IoT device networks. The resulting analysis provides a solid understanding of the efficacy and feasibility of rebooting on active and dormant botnet propagation processes.
Alvi Jawad, Luke Newton, Ashraf Matrawy, Jason Jaskolka
ICC3
2022 Differentially private self-normalizing neural networks for adversarial robustness in federated learning
Olakunle Ibitoye, M. Omair Shafiq, Ashraf Matrawy
Comput. Secur.3
2022 Securing RPL Using Network Coding: The Chained Secure Mode (CSM)
abstract
Considered the preferred routing protocol for many Internet of Things (IoT) networks, the routing protocol for low-power and lossy networks (RPL) incorporates three security modes to protect the integrity and confidentiality of the routing process: 1) the unsecured mode (UM); 2) preinstalled secure mode (PSM); and 3) the authenticated secure mode (ASM). Both PSM and ASM were originally designed to protect against external routing attacks, in addition to some replay attacks (through an optional replay protection mechanism). However, recent research showed that RPL, even when it operates in PSM, is still vulnerable to many routing attacks, both internal and external. In this article, a novel secure mode for RPL, the chained secure mode (CSM), is proposed using the concept of intraflow network coding (NC). The CSM is designed to enhance RPL’s resiliency and mitigation capability against replay attacks. In addition, CSM allows the integration with external security measures such as intrusion detection systems (IDSs). An evaluation of the proposed CSM, from a security and performance point of view, was conducted and compared against RPL in UM and PSM (with and without the optional replay protection) under several routing attacks: the neighbor attack (NA), wormhole (WH), and CloneID attack (CA), using average packet delivery rate (PDR), end-to-end (E2E) latency, and power consumption as metrics. It showed that CSM has better performance and more enhanced security than both the UM and PSM with the replay protection while mitigating both the NA and WH attacks and significantly reducing the effect of the CA in the investigated scenarios.
Ahmed Raoof, Chung-Horng Lung, Ashraf Matrawy
IEEE Internet Things J.3
2021 An Early Benchmark of Quality of Experience Between HTTP/2 and HTTP/3 using Lighthouse
abstract
Google’s QUIC (GQUIC) is an emerging transport protocol designed to reduce HTTP latency. Deployed across its platforms and positioned as an alternative to TCP+TLS, GQUIC is feature rich: offering reliable data transmission and secure communication. It addresses TCP+TLS’s (i) Head of Line Blocking (HoLB), (ii) excessive round-trip times on connection establishment, and (iii) entrenchment. Efforts by the IETF are in progress to standardize the next generation of HTTP’s (HTTP/3, or H3) delivery, with their own variant of QUIC. While perfor-mance benchmarks have been conducted between GQUIC and HTTP/2-over-TCP (H2), few analyses, to our knowledge, have taken place between H2 and H3. In addition, past studies rely on Page Load Time as their main, if not only, metric. The purpose of this article is to benchmark the latest draft specification of H3 and dig into a user’s Quality of Experience (QoE) by using Lighthouse: an open-source (and metric diverse) auditing tool. Our findings show that, for one of H3’s early implementations, H3 is mostly worse but achieves a higher average throughput.
Darius Saif, Chung-Horng Lung, Ashraf Matrawy
ICC3
2021 Evaluating Resilience of Encrypted Traffic Classification against Adversarial Evasion Attacks
abstract
Machine learning and deep learning algorithms can be used to classify encrypted Internet traffic. Classification of encrypted traffic can become more challenging in the presence of adversarial attacks that target the learning algorithms. In this paper, we focus on investigating the effectiveness of different evasion attacks and see how resilient machine and deep learning algorithms are. Namely, we test C4.5 Decision Tree, K-Nearest Neighbor (KNN), Artificial Neural Network (ANN), Convolutional Neural Networks (CNN) and Recurrent Neural Networks (RNN). In most of our experimental results, deep learning shows better resilience against the adversarial samples in comparison to machine learning. Whereas, the impact of the attack varies depending on the type of attack.
Ramy Maarouf, Danish Sattar, Ashraf Matrawy
ISCC3
2021 Consolidating Policy Chains Using One Pass Packet Steering in Software Defined Data Centers
abstract
In this paper, we address the problem of service function chaining in a network and present a solution that tackles this problem in Software Defined Data Centers. Service function chaining can broadly be categorized into middlebox placement in a network and packet steering through middleboxes. We address packet steering in this paper. In particular, we present a One Pass Packet Steering (OPPS) approach for use in multi-subscriber environments. We show algorithms and proof of concept implementation using emulation. We examine how OPPS can benefit from Software Defined Data Center architecture to overcome challenges that occur in simple linear networks. Our results show how OPPS can utilize a lesser number of middleboxes and achieve the same hop counts as a reference model which has been described in previous work as ideal, without violating the subscriber's policy chain.
Julian Chukwu, Ashraf Matrawy, Dimitrios Makrakis
IEEE Trans. Cloud Comput.2
2020 Investigating Resistance of Deep Learning-based IDS against Adversaries using min-max Optimization
abstract
With the growth of adversarial attacks against machine learning models, several concerns have emerged about potential vulnerabilities in designing deep neural network-based intrusion detection systems (IDS). In this paper, we study the resilience of deep learning-based intrusion detection systems against adversarial attacks. We apply the min-max (or saddle-point) approach to train intrusion detection systems against adversarial attack samples in UNSW-NB 15 dataset. We have the max approach for generating adversarial samples that achieves maximum loss and attack deep neural networks. On the other side, we utilize the existing min approach [1] [2] as a defense strategy to optimize intrusion detection systems that minimize the loss of the incorporated adversarial samples during the adversarial training. We study and measure the effectiveness of the adversarial attack methods as well as the resistance of the adversarially trained models against such attacks. We find that the adversarial attack methods that were designed in binary domains can be used in continuous domains and exhibit different misclassification levels. We finally show that principal component analysis (PCA) based feature reduction can boost the robustness in intrusion detection system (IDS) using a deep neural network (DNN).
Rana Abou Khamis, M. Omair Shafiq, Ashraf Matrawy
ICC3
2020 Towards a Decentralized Access Control System for IoT Platforms based on Blockchain Technology
abstract
The Internet of Things (IoT) technologies are transforming traditional businesses into digital-based platforms allowing for more service innovation, performance efficiency and customer satisfaction. Novel services enable users to utilize their personal devices (eg. mobile phones or laptops) to access the IoT platform, process data, and control the IoT infrastructure. However, these services impose critical user authentication and access control requirements. In this paper, we propose a decentralized user authentication and access control system for the IoT platforms via a permissioned blockchain network. We define an authorization sensitivity factor to provide clients with specific access control privileges and we consider an ehealth system as a use case example to demonstrate our solution. The proposed system is implemented using Ethereum platform. Besides, we investigate a threat model that considers an insider Distributed Denial of Service (DDoS) attack. The proposed defense mechanism utilizes a modifier function in the smart contract and keeps a real-time record of legitimate users to restrict function calls. The results illustrate the benefits of the defense mechanism in terms of the system response time.
Dana Haj Hussein, Ragunath Anbarasu, Ashraf Matrawy, Mohamed Ibnkahla
ISNCC3
2020 Evaluation of Adversarial Training on Different Types of Neural Networks in Deep Learning-based IDSs
abstract
Network security applications, including Intrusion Detection Systems (IDS) of deep neural networks (DNN), are increasing rapidly to make detection task of anomaly activities more accurate and robust. With the rapid increase of using DNN and the volume of data traveling through systems, different growing types of adversarial attacks to defeat DNN create a severe challenge. In this paper, we focus on investigating the effectiveness of different evasion attacks and how to train a resilience deep learning-based IDS using different Neural networks, e.g., Artificial Neural Network (ANN), Convolutional Neural Networks (CNN) and Recurrent Neural Networks (RNN). We use the min-max formulation to formulate the problem of training robust intrusion detection systems against adversarial samples using two benchmark datasets. Our experiments on different deep learning algorithms and different benchmark datasets demonstrate that defense using adversarial training based min-max formulation increases the robustness of the network under the assumption of our threat model and five state-of-the-art adversarial attacks.
Rana Abou Khamis, Ashraf Matrawy
ISNCC2
2020 Proactive and Dynamic Slice Allocation in Sliced 5G Core Networks
abstract
Malicious co-residency in virtualized networks poses a real threat. The next-generation mobile networks heavily rely on virtualized infrastructure, and network slicing has emerged as a key enabler to support different virtualized services and applications in the 5G network. However, allocating network slices efficiently while providing a minimum guaranteed level of service, as well as providing defense against the threat of malicious co-residency in a mobile core network, is challenging. To address these questions, in our previous work, we proposed an optimization model to allocate slices. It provided a static and manual allocation of slices. In this work, we analyze the defense against the malicious co-residency using our optimization-based allocation, and we extend our work to dynamically allocate slices. We propose a dynamic slice allocation framework for the 5G core network. The proposed framework provides user-interaction to request slices and any required services that need to run on a slice(s). It can accept a single or multiple allocation requests, and it dynamically allocates them. Additionally, the framework allocates slices in a balanced fashion across available resources. We compare our framework with the First Come First Serve and First Available allocation scheme.
Danish Sattar, Ashraf Matrawy
ISNCC2
2020 Introducing Network Coding to RPL: The Chained Secure Mode (CSM)
abstract
The current standard of Routing Protocol for Low Power and Lossy Networks (RPL) incorporates three modes of security: the Unsecured Mode (UM), Preinstalled Secure Mode (PSM), and the Authenticated Secure Mode (ASM). While the PSM and ASM are intended to protect against external routing attacks and some replay attacks (through an optional replay protection mechanism), recent research showed that RPL in PSM is still vulnerable to many routing attacks, both internal and external. In this paper, we propose a novel secure mode for RPL, the Chained Secure Mode (CSM), based on the concept of intra-flow Network Coding. The main goal of CSM is to enhance RPL's resilience against replay attacks, with the ability to mitigate some of them. The security and performance of a proof-of-concept prototype of CSM were evaluated and compared against RPL in UM and PSM (with and without the optional replay protection) in the presence of Neighbor attack as an example. It showed that CSM has better performance and more enhanced security compared to both the UM and PSM with the replay protection. On the other hand, it showed a need for a proper recovery mechanism for the case of losing a control message.
Ahmed Raoof, Chung-Horng Lung, Ashraf Matrawy
NCA3
2020 Enhancing Routing Security in IoT: Performance Evaluation of RPL's Secure Mode Under Attacks
abstract
As the routing protocol for low power and lossy networks (RPL)s became the standard for routing in the Internet-of-Things (IoT) networks, many researchers had investigated the security aspects of this protocol. However, no work (to the best of our knowledge) has investigated the use of the security mechanisms included in RPL's standard, mainly because there was no implementation for these features in any Internet of Things (IoT) operating systems yet. A partial implementation of RPL's security mechanisms was presented recently for the Contiki operating system (by Perazzo et al.), which provided us with an opportunity to examine RPL's security mechanisms. In this article, we investigate the effects and challenges of using RPL's security mechanisms under common routing attacks. First, a comparison of RPL's performance, with and without its security mechanisms, under four routing attacks [Blackhole, Selective-Forward (SF), Neighbor, and Wormhole (WH) attacks] is conducted using several metrics (e.g., average data packet delivery rate, average data packet latency, average power consumption, etc.). This comparison is performed using two commonly used radio duty-cycle protocols. Second, and based on the observations from this comparison, we propose two techniques that could reduce the effects of such attacks, without having added security mechanisms for RPL. An evaluation of these techniques shows improved performance of RPL under the investigated attacks, except for the WH.
Ahmed Raoof, Ashraf Matrawy, Chung-Horng Lung
IEEE Internet Things J.2
2019 Analyzing Adversarial Attacks against Deep Learning for Intrusion Detection in IoT Networks
abstract
Adversarial attacks have been widely studied in the field of computer vision but their impact on network security applications remains an area of open research. As IoT, 5G and AI continue to converge to realize the promise of the fourth industrial revolution (Industry 4.0), security incidents and events on IoT networks have increased. Deep learning techniques are being applied to detect and mitigate many of such security threats against IoT networks. Feed- forward Neural Networks (FNN) have been widely used for classifying intrusion attacks in IoT networks. In this paper, we consider a variant of the FNN known as the Self-normalizing Neural Network (SNN) and compare its performance with the FNN for classifying intrusion attacks in an IoT network. Our analysis is performed using the BoT- IoT dataset from the Cyber Range Lab of the center of UNSW Canberra Cyber. In our experimental results, the FNN outperforms the SNN for intrusion detection in IoT networks based on multiple performance metrics such as accuracy, precision, and recall as well as multi-classification metrics such as Cohen Cappa’s score. However, when tested for adversarial robustness, the SNN demonstrates better resilience against the adversarial samples from the IoT dataset, presenting a promising future in the quest for safer and more secure deep learning in IoT networks.
Olakunle Ibitoye, M. Omair Shafiq, Ashraf Matrawy
GLOBECOM3
2019 Secure Routing in IoT: Evaluation of RPL's Secure Mode under Attacks
abstract
As the Routing Protocol for Low Power and Lossy Networks (RPL) became the standard for routing in the Internet of Things (IoT) networks, many researchers had investigated the security aspects of this protocol. However, no work (to the best of our knowledge) has investigated the use of the security mechanisms included in the protocol's standard, due to the fact that there was no implementation for these features in any IoT operating system yet. A partial implementation of RPL's security mechanisms was presented recently for Contiki operating system (by Perazzo et al.), which provided us with the opportunity to examine RPL's security mechanisms. In this paper, we investigate the effects and challenges of using RPL's security mechanisms under common routing attacks. First, a comparison of RPL's performance, with and without its security mechanisms, under three routing attacks (Blackhole, Selective-Forward, and Neighbor attacks) is conducted using several metrics (e.g., average data packet delivery rate, average data packet delay, average power consumption... etc.) Based on the observations from this comparison, we come up with few suggestions that could reduce the effects of such attacks, without having added security mechanisms for RPL.
Ahmed Raoof, Ashraf Matrawy, Chung-Horng Lung
GLOBECOM2
2018 A Discussion on Security Education in Academia
abstract
This panel will explore how security topics are integrated into academic programs and future directions for improvements. It will address how early in time security should be introduced in programs like computer science and software engineering; and identify the critical takeaways that each graduating student should learn. We will try to separate out the important, practical concepts from the purely academic ones. We will also consider how well security programs translate to industry-focused needs: do students emerge with an understanding that is both deep and broad enough to be useful? In general, we will try to identify the pitfalls of current security education and how we can move forward as an academic community, in tandem with industry and government.
Kevin R. B. Butler, Robert K. Cunningham, Paul C. van Oorschot, Reihaneh Safavi-Naini, Ashraf Matrawy, Jeremy Clark
CCS5
2018 SDN-VSA: Modeling and Analysis of SDN Control Applications Using Vector Spaces
abstract
Unlike traditional networks which are statically configured, SDN control applications are dynamic and are becoming more heterogeneous and complex. There is a great need for a framework to learn about the behavior of the various SDN applications. To the best of our knowledge, current network modeling frameworks were not designed to incorporate the application logic into their models, and thus can not be appropriately used to model SDN applications. In this paper, we suggest the possibility of leveraging the impact which control applications assert on the network information base to learn about the behavior of such applications. Based on this, we propose SDN- VSA, a framework that models SDN control applications as a set of affine transformations in some Vector Space. Finally, we present an analytical formulation for such framework, and discuss a use-case for the framework in analyzing flow-steering in SDN service chains.
Mohamed Aslan, Ashraf Matrawy
ICC2
2018 Economic and Energy Considerations for Resource Augmentation in Mobile Cloud Computing
abstract
In earlier works [1], [2], we proposed to utilize a centralized broker-node to perform task scheduling for the resource augmentation of a large number of mobile devices. The task scheduler model focused on energy optimization was proposed for the centralized task scheduling problem. In this paper, the model extends the optimization process by including an economic element to it. Thus, we propose an energy and monetary cost-aware mathematical task scheduler model. Compared to the previous model, this model, can allow mobile devices to offload multiple tasks to cloud resources. The results in this paper are more thorough and more aspects of task offloading have been analysed. For instance, the model is evaluated under two different resource augmentation environments for mobile cloud computing: a local private cloud and public clouds. More precisely, the task scheduling problem is optimally solved to minimize: (i) the total energy consumption when applied to a local private cloud, and (ii) the total energy consumption and monetary cost when applied to public clouds. Our proposed model at the centralized broker-node finds optimal solutions for task assignment problem, and provides a significant reduction in the total costs compared with the task assignment by the centralized scheduler without optimization.
Manjinder Nir, Ashraf Matrawy, Marc St-Hilaire
IEEE Trans. Cloud Comput.2
2017 Accurate Manipulation of Delay-based Internet Geolocation
abstract
Delay-based Internet geolocation techniques are repeatedly positioned as well suited for security-sensitive applications, e.g., location-based access control, and credit-card verification. We present new strategies enabling adversaries to accurately control the forged location. Evaluation showed that using the new strategies, adversaries could misrepresent their true locations by over 15000km, and in some cases within 100km of an intended geographic location. This work significantly improves the adversary's control in misrepresenting its location, directly refuting the appropriateness of current techniques for security-sensitive applications. We finally discuss countermeasures to mitigate such strategies.
AbdelRahman Abdou, Ashraf Matrawy, Paul C. van Oorschot
AsiaCCS2
2017 The effect of buffer management strategies on 6LoWPAN's response to buffer reservation attacks
abstract
The 6L0WPAN adaptation layer is widely used in many Internet of Things (IoT) and vehicular networking applications. The current IoT framework [1], which introduced 6LoWPAN to the TCP/IP model, does not specif the implementation for managing its received-fragments buffer. This paper looks into the effect of current implementations of buffer management strategies at 6LoWPAN's response in case of fragmentation-based, buffer reservation Denial of Service (DoS) attacks. The Packet Drop Rate (PDR) is used to analyze how successful the attacker is for each management technique. Our investigation uses different defence strategies, which include our implementation of the Split Buffer mechanism [2] and a modified version of this mechanism that we devise in this paper as well. In particular, we introduce dynamic calculation for the average time between consecutive fragments and the use of a list of previously dropped packets tags. NS3 is used to simulate all the implementations. Our results show that using a “slotted” buffer would enhance 6LoWPAN's response against these attacks. The simulations also provide an in-depth look at using scoring systems to manage buffer cleanups.
Ahmed Raoof, Ashraf Matrawy
ICC2
2017 An empirical model of packet processing delay of the Open vSwitch
abstract
Network virtualization offers flexibility by decoupling virtual network from the underlying physical network. Software-Defined Network (SDN) could utilize the virtual network. For example, in Software-Defined Networks, the entire network can be run on commodity hardware and operating systems that use virtual elements. However, this could present new challenges of data plane performance. In this paper, we present an empirical model of the packet processing delay of a widely used OpenFlow virtual switch, the Open vSwitch. In the empirical model, we analyze the effect of varying Random Access Memory (RAM) and network parameters on the performance of the Open vSwitch. Our empirical model captures the non-network processing delays, which could be used in enhancing the network modeling and simulation.
Danish Sattar, Ashraf Matrawy
ICNP2
2017 A survey on forensic event reconstruction systems
abstract
Security related incidents such as unauthorised system access, data tampering and theft have been noticeably rising. Tools such as firewalls, intrusion detection systems and anti-virus software strive to prevent these incidents. Since these tools only prevent an attack, once an illegal intrusion occurs, they cease to provide useful information beyond this point. Consequently, system administrators are interested in identifying the vulnerability in order to: 1) avoid future exploitation; 2) recover corrupted data; 3) present the attacker to law enforcement where possible. As such, forensic event reconstruction systems are used to provide the administrators with possible information. We present a survey on the current approaches towards forensic event reconstruction systems proposed over the past few years. Technical details are discussed, as well as analysis to their effectiveness, advantages and limitations. The presented tools are compared and assessed based on the primary principles that a forensic technique is expected to follow.
Abes Dabir, AbdelRahman Abdou, Ashraf Matrawy
Int. J. Inf. Comput. Secur.3
2017 CPV: Delay-Based Location Verification for the Internet
abstract
The number of location-aware services over the Internet continues growing. Some of these require the client's geographic location for security-sensitive applications. Examples include location-aware authentication, location-aware access policies, fraud prevention, complying with media licensing, and regulating online gambling/voting. An adversary can evade existing geolocation techniques, e.g., by faking GPS coordinates or employing a non-local IP address through proxy and virtual private networks. We devise Client Presence Verification (CPV), a delay-based verification technique designed to verify an assertion about a device's presence inside a prescribed geographic region. CPV does not identify devices by their IP addresses. Rather, the device's location is corroborated in a novel way by leveraging geometric properties of triangles, which prevents an adversary from manipulating measured delays. To achieve high accuracy, CPV mitigates Internet path asymmetry using a novel method to deduce one-way application-layer delays to/from the client's participating device, and mines these delays for evidence supporting/refuting the asserted location. We evaluate CPV through detailed experiments on PlanetLab, exploring various factors that affect its efficacy, including the granularity of the verified location, and the verification time. Results highlight the potential of CPV for practical adoption.
AbdelRahman Abdou, Ashraf Matrawy, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.2
2014 Optimizing Energy Consumption in Broker-Assisted Cyber Foraging Systems
abstract
In this paper, we present our work in the area of Cyber Foraging (CF), which enables mobile devices to offload heavy computations to resourceful computing nodes. The main focus of the paper is to minimize the total energy consumption across all the mobile devices in a large Cyber Foraging System (CFS). We use a centralized architecture where a broker node handles the task scheduling. We model the task scheduling problem for this centralized architecture and optimally solve the problem to minimize the total energy consumption, which is equivalent to maximizing the total energy saving across all mobile devices. Simulation results show that using a centralized broker able to optimally offload tasks can provide a significant reduction in energy consumption.
Manjinder Nir, Ashraf Matrawy, Marc St-Hilaire
AINA2
2011 A New Perspective on Providing Cloud Computing Security - A Position Paper
Ashraf Matrawy, Clifford Liem, Michael J. Wiener, Yuan Xiang Gu, Andrew Wajs
CLOSER1
2009 Design and Analysis of a Hierarchical IP Traceback System
abstract
In this paper, we present the detailed design and analysis of our solution to the IP traceback problem. We adopt (at the AS level) a path signature generation method which was proposed at the router level to primarily provide a means of filtering attack traffic. Our solution assumes a secure routing infrastructure to exchange authenticated messages in order to learn path signatures. We envision the local adoption of a separate, yet complementary, traditional traceback system at each AS. This solution is hierarchical in the sense that it works at the autonomous system (AS) level first then once a small list of possible source ASes is identified, those ASes are queried and traceback is performed within each AS to prune the list down to the actual source. Using simulation results we demonstrate that our solution is practical since it reduces - as a first step - the search space from the entire router space of the Internet to an AS-list that is only a very small fraction of all possible ASes. This combination is more scalable than doing a flat IP traceback on the entire router space of the Internet. We go on to propose a means of using more than 16 bits of the IP fragmentation fields which are traditionally used by various IP traceback systems. We present results based on using various sizes for the marking field, as well as varying number of total marks and different sizes for each mark.
Abes Dabir, Ashraf Matrawy
ICC2
2009 A Behaviour Study of Network-Aware Stealthy Worms
abstract
This paper examines the general behaviour of stealthy worms. In particular, we focus on worms that are designed based on network awareness. We study the case where a worm, instead of aiming to spread as fast as possible and penetrate intrusion detection systems (IDS), aims to avoid IDS and spread with the minimum number of detections. We compare different scanning strategies for this worm, including different combinations of hitlist and random scanning, and how they affect the number of infections and the rate of detected infection attempts. We compare the network-aware worm's behavior to that of the Code Red II worm. Simulations show that scanning worms can generate many fewer detections using localized scanning while maintaining its capability to infect.
Craig Smith, Ashraf Matrawy
ICC2
2008 Discovering Packet Structure through Lightweight Hierarchical Clustering
abstract
The complexity of current Internet applications makes understanding network traffic a challenging task. By providing larger-scale aggregates for analysis, unsupervised clustering approaches can greatly aid in the identification of new applications, attacks, and other changes in network usage patterns. In this paper we introduce ADHIC, a new algorithm that clusters similar network traffic together without prior knowledge of protocol structures. Packet similarity is determined through comparisons of substrings within packets at distinguishing offsets. ADHIC is notable in that it 1) produces a hierarchical decomposition of network traffic in the form of a cluster-identifying decision tree, 2) needs only a small fraction of packets to generate the tree, and 3) clusters packets at wire speeds. We find that ADHIC appropriately segregates well-known protocols, clusters together traffic of the same protocol running on multiple ports, and segregates traffic from applications, such as p2p, that do not use standard ports. Potential applications include network performance analysis, real-time alerts of flash crowds or worm activity, and dynamic DoS-resistant bandwidth management. NetADHICT, our implementation of ADHIC, is available for download and is licensed under the GNU GPL license.
Abdulrahman Hijazi, Hajime Inoue, Ashraf Matrawy, Paul C. van Oorschot, Anil Somayaji
ICC3
2005 Mitigating Network Denial-of-Service Through Diversity-Based Traffic Management
Ashraf Matrawy, Paul C. van Oorschot, Anil Somayaji
ACNS1
2005 Optimization of resilient packet ring networks scheduling for MPEG-4 video streaming
abstract
Resilient packet ring (RPR) is an emerging standard for the construction of local and metropolitan area networks. The priority queue (PQ) algorithm, which is recommended as the scheduling scheme for RPR always gives priority to the transit buffer. Using this scheduling scheme in single transit buffer RPR, the high priority traffic, such as video packets waiting to access the ring at congested node in the transmit buffer will suffer large delays and unsteady delay jitters. In this paper, we propose a new scheduling scheme for RPR to improve the quality of service for video traffic transmission. The proposed scheduling scheme alternately selects packets from the single transit buffer and the high priority transmit buffer using deficit round-robin (DRR) algorithm. If there is no packet in the above two buffers, low priority transmit buffer is then served. We investigate the system performance for transmission of MPEG-4 encoded bitstream as high priority traffic in an RPR network in scenario that all traffic is forwarded to a common node. We report end-to-end delay and delay jitter for I, P and B frames of several encoded video streams. Simulation results show certain improvement on overall delay and delay jitter performance for all types of video frames, especially for I frames which are the most important frames for video reconstruction.
Ashraf Matrawy, Ioannis Lambadaris, Mohsen Ashourian
ICC2
2005 A real-time video multicast architecture for assured forwarding services
abstract
This paper presents our work on developing an architecture for multicasting real-time MPEG4 over IP networks that provide service differentiation. In particular, this work is targeted at assured forwarding (AF) style services. This work is an attempt to find a simple solution to the problem of multicast congestion control of real-time traffic by exploiting the service differentiation capabilities of AF networks. Our architecture assumes loss differentiation in the network and assumes the network's ability to provide explicit congestion notification messages to the sender. We do not consider policing/shaping at the edge routers. Rather, we consider a more general case where packet marking and flow control are provided at the senders. For this network model, we built an end-to-end architecture and developed a rate-adaptation algorithm that can operate in both unicast and multicast applications with a minor modification. The simulation results show how the rate-adaptation algorithm accommodates different receivers with different networking capabilities and provides receivers with different levels of quality by taking advantage of the queue management capabilities of the AF service. We test how the architecture scales to a large number of receivers, how multiple multicast sessions interact, and how it interacts with TCP.
Ashraf Matrawy, Ioannis Lambadaris
IEEE Trans. Multim.1
2004 Current Trends and Advances in Information Assurance Metrics
Nabil Seddigh, Peter Pieda, Ashraf Matrawy, Biswajit Nandy, Ioannis Lambadaris, Adam Hatfield
PST3
2003 Real-time transport for assured forwarding: an architecture for both unicast and multicast applications
abstract
This paper presents a summary of our work on developing an architecture for transporting real-time traffic (MPEG4 video in this paper) in IP networks that provide service differentiation. We target our architecture at assured forwarding (AF) style services. This architecture assumes loss differentiation in the network and the network's ability to provide ECN messages to the sender. We did not consider policing/shaping at the edge routers. Rather we considered a more general case where marking and flow control are provided at the senders. For this network model, we developed a rate adaptation algorithm that can operate in both unicast and multicast applications with a minor modification. The simulation results presented in this paper represent the multicast case. The results show how the rate adaptation algorithm accommodates different receivers with different networking capabilities and provides them with different qualities by taking advantage of the queue management capabilities of the AF service. We also show the results of testing this architecture with different AF queuing mechanisms, namely RIO and WRED.
Ashraf Matrawy, Ioannis Lambadaris
ICC1
2002 Multicasting of adaptively-encoded MPEG4 over QoS-aware IP networks
abstract
We propose a novel architecture for multicasting adaptively-encoded layered MPEG4 over a QoS-aware IP network. We require such a network to (1) support priority dropping of packets in time of congestion; (2) provide congestion notification to the multicast sender. For the first requirement, we use RED's extension for service differentiation. It recognizes the priority of packets and drops lower priority packets first. We couple RED (random early detection) with our proposal for the second requirement which is the adoption of backward explicit congestion notification (BECN). BECN provides early congestion notification at the IP layer level to the video sender. BECN detects upcoming congestion based on size of the RED queue in the routers. The MPEG4 adaptive-encoder can change the sending rate and divide the video packets into lower priority packets and high priority packets. Based on BECN messages from the routers, a simple flow controller at the sender sets the rate for the adaptive MPEG4 encoder and also sets the ratio of the high priority and low priority packets within the video stream. We use a TES model for generating the MPEG4 traffic that is based on real video traces. Simulation results show that combining priority dropping, MPEG4 adaptive encoding and multicast BECN: (1) improves bandwidth utilization; (2) reduces the time to react to congestion and hence improves the received video quality; (3) maintains graceful degradation in quality with congestion and provides minimum quality even if congestion persists.
Ashraf Matrawy, Ioannis Lambadaris
ICC1
2001 On layered video fairness on IP networks
abstract
In this paper, we present a study of layered video fairness on IP networks. Our study is based on simulation. We investigate some issues that have direct impact on fair allocation of bandwidth between layered video and TCP, in particular: (a) congestion control mechanisms employed by layered video transfer protocols; for this part we studied the interaction of RLM with TCP; (b) the effect of the distribution of video traffic across layers in layered multicast video; (c) the effect of VBR video on fairness to TCP. We show that fairness is affected by all the above factors. We also show that fairness of layered video comes at the expense of instability of the video quality and poor link utilization. We conclude by discussing the performance of layered video protocols in general and recommendations on the design of video transfer systems on IP networks.
Ashraf Matrawy, Ioannis Lambadaris
GLOBECOM1