VLDB 2026 Research / reviewers in the wild / expert
Claude Fachkha
dblp:123/5457
· DBLP profile ↗
16ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0003-2863-4817ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 2 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Next-generation cloudlet federation for Internet of Things in healthcare: Enhancing response time and energy efficiency
Rahima Tanveer, Muhammad Ziad Nayyer, Muhammad Hasan Jamal, Imran Raza, Claude Fachkha |
Comput. Commun. | 5 |
| 2024 | Strategic Placement of Data Centers for Economic Analysis: An Online Algorithm Approach
Christine Markarian, Claude Fachkha |
DATA | 2 |
| 2023 | ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management Systems
Tony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha, Chadi Assi |
NDSS | 4 |
| 2023 | Helium-based IoT Devices: Threat Analysis and Internet-scale ExploitationsabstractWith the explosive growth of resource-constrained smart devices and the widespread deployment of Internet-of-Things (IoT) devices, there is an ever-increasing demand for low-energy and cost-effective wireless communication solutions to serve a wide variety of systems and processes. To this end, blockchain-enabled Helium devices were conceived to enable Internet services and to support third-party IoT devices. This decentralized paradigm allows individuals and entities to freely engage, monetize and deploy wireless Helium hotspots, offering Internet coverage through piggy-backing packets via their existing network and Internet infrastructure (e.g., fiber optics at home). Currently, there are close to 1M operational Helium devices deployed in 189 countries, which are owned by 425K accounts. Given this evolving paradigm, in this paper, we take a first step to explore the plausible attack vectors which could potentially impact the confidentiality, integrity, and availability of such Helium hotspots. Along this vein, we then scrutinize 2.9 TB of one-way unsolicited Internet traffic arriving at 0.5M monitored dark IP addresses to identify 869,822 darknet events pertained to 6K Helium hotspots (as infected devices and DoS victims). By further leveraging active and passive methodologies coupled with public exploitation databases, we uncover medium to critical severity vulnerabilities attributed to 62K online Helium hotspots. Veronica Rammouz, Joseph Khoury, Dorde Klisura, Morteza Safaei Pour, Mostafa Safaei Pour, Claude Fachkha, Elias Bou-Harb |
WiMob | 6 |
| 2022 | Power jacking your station: In-depth security analysis of electric vehicle charging station management systems
Tony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha, Chadi Assi |
Comput. Secur. | 4 |
| 2020 | Prevention of DDoS Attacks in IoT Networks
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha |
AINA | 4 |
| 2020 | A Big Data Fusion to Profile CPS Security Threats Against Operational TechnologyabstractInternet security measurements are fundamental techniques to detect cyber attacks and generate intelligence. However, such methods are limited in terms of relevancy, scalability, and data availability when it comes to Operational Technology (OT). Therefore, in this paper, we build cyber security capabilities to collect, detect, analyze, and visualize in near real-time cyberattacks targeting Cyber-Physical Systems (CPS). The latter is a critical component for Industry 4.0 and smart technologies. In order to achieve our tasks, we propose a big data fusion model, which correlates among two trap-based monitoring systems, namely, darknet and honeypot. With approximately hundred deployed sensors (monitors) over a six-month period, we have been able to collect several unauthorized and malicious activities originating from 226 countries. Furthermore, our investigation has revealed various scanning strategies such as CPS-focused scans, in addition to real exploits used by external sources to infiltrate our network. Finally, this study highlighted the importance of such monitoring systems and compare the efficiency among them with an aim to complement existing CPS and on-premise OT security solutions. Karl Biron, Wael Bazzaza, Khalid Yaqoob, Amjad Gawanmeh, Claude Fachkha |
WoWMoM | 5 |
| 2019 | Multi-scale Adaptive Threshold for DDoS Detection
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha |
CRiSIS | 4 |
| 2019 | Distributed Detection System Using Wavelet Decomposition and Chi-Square Test
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha |
CRiSIS | 4 |
| 2018 | On the Collaborative Inference of DDoS: An Information-theoretic Distributed ApproachabstractLiterature contributions have shown that information theoretic techniques can effectively detect various types of Distributed Denial of Service (DDoS) attacks. However, such techniques are often centralized with a limited measurement vantage point and suffer from the issue of single point of failure. Furthermore, with the flourishing of distributed and cloudbased environments, such techniques ought to adapt to such settings for scalability and performance reasons. In this paper, we address the problem of collaborative DDoS detection using information-theoretic techniques. To this end, we propose an entropy-based detection mechanism that supports collaborative agreement to identify suitable tuning network parameters for distributed DDoS inference in real-time. Empirical evaluations with real DDoS attacks demonstrate that the proposed approach is indeed capable of cooperatively inferring DDoS attacks while achieving resiliency and scalability. Fatima Ezzahra Ouerfelli, Khaled Barbaria, Elias Bou-Harb, Claude Fachkha, Belhassen Zouari |
IWCMC | 4 |
| 2017 | Internet-scale Probing of CPS: Inference, Characterization and Orchestration Analysis
Claude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir Memon, Mustaque Ahamad |
NDSS | 1 |
| 2015 | Inferring distributed reflection denial of service attacks from darknet
Claude Fachkha, Elias Bou-Harb, Mourad Debbabi |
Comput. Commun. | 1 |
| 2015 | On the inference and prediction of DDoS campaignsabstractAbstract This work proposes a distributed denial‐of‐service (DDoS) inference and forecasting model that aims at providing insights to organizations, security operators, and emergency response teams during and after a DDoS attack. Specifically, our work strives to predict, within minutes, the attacks' features, namely intensity/rate (packets/second) and size (estimated number of used compromised machines/bots). The goal is to understand the future short‐term trend of the ongoing DDoS attack in terms of those features and thus provide the capability to recognize the current as well as future similar situations and hence appropriately respond to the threat. Further, our work aims at investigating DDoS campaigns by proposing a clustering approach to infer various victims targeted by the same campaign and predicting related features. Our analysis employs real darknet data to explore the feasibility of applying the inference and forecasting models on DDoS attacks and evaluate the accuracy of the predictions. To achieve our goal, our proposed approach leverages a number of time series and fluctuation analysis techniques, statistical methods, and forecasting approaches. The extracted inferences from various DDoS case studies exhibit a promising accuracy reaching at some points less than 1% error rate. Further, our approach could lead to a better understanding of the scale, speed, and size of DDoS attacks and generates inferences that could be adopted for immediate response and mitigation. Moreover, the accumulated insights could be used for the purpose of long‐term large‐scale DDoS analysis. Copyright © 2014 John Wiley & Sons, Ltd. Claude Fachkha, Elias Bou-Harb, Mourad Debbabi |
Wirel. Commun. Mob. Comput. | 1 |
| 2014 | Inferring internet-scale infections by correlating malware and probing activitiesabstractThis paper presents a new approach to infer malware-infected machines by solely analyzing their generated probing activities. In contrary to other adopted methods, the proposed approach does not rely on symptoms of infection to detect compromised machines. This allows the inference of malware infection at very early stages of contamination. The approach aims at detecting whether the machines are infected or not as well as pinpointing the exact malware type/family, if the machines were found to be compromised. The latter insights allow network security operators of diverse organizations, Internet service providers and backbone networks to promptly detect their clients' compromised machines in addition to effectively providing them with tailored anti-malware/patch solutions. To achieve the intended goals, the proposed approach exploits the darknet Internet space and employs statistical methods to infer large-scale probing activities. Subsequently, such activities are correlated with malware samples by leveraging fuzzy hashing and entropy based techniques. The proposed approach is empirically evaluated using 60 GB of real darknet traffic and 65 thousand real malware samples. The results concur that the rationale of exploiting probing activities for worldwide early malware infection detection is indeed very promising. Further, the results demonstrate that the extracted inferences exhibit noteworthy accuracy and can generate significant cyber security insights that could be used for effective mitigation. Elias Bou-Harb, Claude Fachkha, Mourad Debbabi, Chadi Assi |
ICC | 2 |
| 2013 | Towards a Forecasting Model for Distributed Denial of Service ActivitiesabstractDistributed Denial of Service (DDoS) activities continue to dominate today's attack landscape. This work proposes a DDoS forecasting model to provide significant insights to organizations, security operators and emergency response teams during and after a targeted DDoS attack. Specifically, the work strives to predict, within minutes, the attacks' impact features, namely, intensity/rate (packets/sec) and size (estimated number of used compromised machines/bots). The goal is to understand the future short term trend of the ongoing DDoS attack in terms of those features and thus provide the capability to recognize the current as well as future similar situations and hence appropriately respond to the threat. Our analysis employs real dark net data to explore the feasibility of applying the forecasting model on targeted DDoS attacks and subsequently evaluate the accuracy of the predictions. To achieve its tasks, our proposed approach leverages a number of time series fluctuation analysis and forecasting methods. The extracted inferences from various DDoS case studies exhibit promising accuracy reaching at some points less than 1% error rate. Further, our model could lead to better understanding of the scale and speed of DDoS attacks and should generate inferences that could be adopted for immediate response and hence mitigation as well as accumulated for the purpose of long term large-scale DDoS analysis. Claude Fachkha, Elias Bou-Harb, Mourad Debbabi |
NCA | 1 |
| 2012 | Investigating the dark cyberspace: Profiling, threat-based analysis and correlationabstractAn effective approach to gather cyber threat intelligence is to collect and analyze traffic destined to unused Internet addresses known as darknets. In this paper, we elaborate on such capability by profiling darknet data. Such information could generate indicators of cyber threat activity as well as providing in-depth understanding of the nature of its traffic. Particularly, we analyze darknet packets distribution, its used transport, network and application layer protocols and pinpoint its resolved domain names. Furthermore, we identify its IP classes and destination ports as well as geo-locate its source countries. We further investigate darknet-triggered threats. The aim is to explore darknet embedded threats and categorize their severities. Finally, we contribute by exploring the inter-correlation of such threats, by applying association rule mining techniques, to build threat association rules. Specifically, we generate clusters of threats that co-occur targeting a specific victim. Such work proves that specific darknet threats are correlated. Moreover, it provides insights about threat patterns and allows the interpretation of threat scenarios. Claude Fachkha, Elias Bou-Harb, Amine Boukhtouta, Son Dinh, Farkhund Iqbal, Mourad Debbabi |
CRiSIS | 1 |