AbdelRahman Eldosouky

dblp:176/5828 · also Abdel Rahman Eldosouky · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
4since 2021 · last 2025
0000-0001-9136-6734ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2025 Interaction-Aware Trust Management Scheme for IoT Systems With Machine-Learning-Based Attack Detection
abstract
The recent Internet of Things (IoT) adoption has revolutionized various applications while introducing significant security and privacy challenges. Traditional security solutions are unsuitable for IoT systems due to their dynamicity, heterogeneity, and resource constraints. Trust-based solutions are emerging as promising alternatives due to their ability to track the dynamic behavior in IoT systems. However, existing trust management schemes are implemented at the device level, raising several challenges, including device modification, that compromises certification and scalability, increased network overhead, and higher device resource utilization. To address these challenges, this article proposes a novel trust management scheme that shifts its implementation to a higher layer in the IoT system, specifically to the IoT access layer (e.g., gateway). The proposed scheme establishes trust based on typical device interactions with the gateway without requiring additional information from the device. It relies on objective attributes spanning communication, security, and advanced dimensions to compute the trust value of an IoT device. Additionally, an artificial neural network (ANN) is integrated to determine if the device acts maliciously or behaves normally. Simulation results demonstrate a notable improvement in the detection rate, primarily due to incorporating the proposed ANN, compared to the threshold-based approaches in the literature. Overall, the improvements highlight the significant advantage of the proposed scheme’s robustness.
Ali Farhat, AbdelRahman Eldosouky, Mohamed Ibnkahla, Ashraf Matrawy
IEEE Internet Things J.2
2024 Temporal Partitioned Federated Learning for IoT Intrusion Detection Systems
abstract
Machine learning-based intrusion detection systems (IDSs) serve as a defense-in-depth layer for Internet of Things (IoT) networks by detecting potential intrusions within IoT traffic. However, resource-constrained IoT devices impose sig-nificant challenges in developing effective IDSs. Recently, fed-erated learning (FL) has emerged as a promising solution for training detection models on distributed IoT devices without compromising resource limitations resulting in the introduction of FL-based IDSs. To this end, this paper introduces a novel approach to enhance the effectiveness of current FL-based IoT IDSs while utilizing the same resources. The proposed system partitions the FL rounds between IoT device groups, allowing each group to update the FL detection model during its time partition. Hence, by implementing this temporal partitioning, multiple detection models are updated within one FL round using the same IoT resources. The main design goals of the proposed approach are to improve detection accuracy and convergence time compared to the traditional approach. For this purpose, the proposed approach is evaluated and compared to the traditional approach using five intrusion scenarios on IoT traffic obtained from the Edge-IIoTset dataset. The results demonstrate that the proposed temporal partitioned FL-based IoT IDS outperforms the traditional system by achieving higher detection accuracy and faster convergence time. Furthermore, the proposed approach achieves the required detection accuracy in fewer FL rounds, which can, in principle, save more IoT resources.
Mohannad Abu Issa, Mohamed Ibnkahla, Ashraf Matrawy, AbdelRahman Eldosouky
WCNC4
2023 IoT Trust Establishment Through System Level Interactions and Communication Attributes
abstract
The integration of Internet of Things (loT)-based solutions in various applications introduced several challenges in security and privacy. Due to the nature of loT systems, traditional security solutions are not suitable for solving these challenges. Researchers introduced trust management as a viable solution due to its ability to track the dynamic behavior of loT devices. Compared to traditional security solutions, trust does not require an extensive amount of resources. Several loT trust solutions rely on distributed models that increase network overhead and consume additional energy. To this end, this work proposes a trust management scheme for loT systems that can be implemented at the access layer of loT systems. The proposed scheme establishes trust for loT devices through device-system interaction and communication attributes without requiring any additional information or modifications to the device. The trust value is computed using the trust attributes over a specific window size of interactions and using a forget factor. Simulation results show the ability of the proposed scheme to track the behavior of loT devices. Results also show that the proposed scheme maintains high performance in detecting persistent attacks compared to existing schemes from the literature, while improving the detection rate of ON-OFF attacks by 15%.
Ali Farhat, AbdelRahman Eldosouky, Mohamed Ibnkahla, Ashraf Matrawy
GLOBECOM2
2021 Interdependence-Aware Game-Theoretic Framework for Secure Intelligent Transportation Systems
abstract
The operation of future intelligent transportation systems (ITSs), communications infrastructure (CI), and power grids (PGs) will be highly interdependent. In particular, autonomous connected vehicles require CI resources to operate, and, thus, communication failures can result in nonoptimality in the ITS flow in terms of traffic jams and fuel consumption. Similarly, CI components, e.g., base stations (BSs) can be impacted by failures in the electric grid that is powering them. Thus, malicious attacks on the PG can lead to failures in both the CI and the ITSs. To this end, in this article, the security of an ITS against indirect attacks carried out through the PG is studied in an interdependent PG-CI-ITS scenario. In the considered scenario, an attacker can induce nonoptimality in the ITS or disrupt a particular set of streets by attacking the PG components while remaining stealthy from the ITS administrators. To defend against such attacks, the administrator of the interdependent critical infrastructure can allocate backup power sources (BPSs) at every BS to compensate for the power loss caused by the attacker. However, due to budget limitations, the administrator must consider the importance of each BS in light of the PG risk of failure, while allocating the BPSs. In this regard, a rigorous analytical framework is proposed to model the interdependencies between the ITS, CI, and PG. Next, a one-to-one relationship between the PG components and ITS streets is derived in order to capture the effect of the PG components’ failure on the optimality of the traffic flow in the streets. Moreover, the problem of BPS allocation is formulated using a Stackelberg game framework and the Stackelberg equilibrium (SE) of the game is characterized. Simulation results show that the derived SE outperforms any other BPS allocation strategy and can be scalable in linear time with respect to the size of the interdependent infrastructure.
Aidin Ferdowsi, AbdelRahman Eldosouky, Walid Saad 0001
IEEE Internet Things J.2
2020 Drones in Distress: A Game-Theoretic Countermeasure for Protecting UAVs Against GPS Spoofing
abstract
One prominent security threat that targets unmanned aerial vehicles (UAVs) is the capture via global positioning system (GPS) spoofing in which an attacker manipulates a UAV's GPS signals in order to capture it. Given the anticipated widespread deployment of UAVs for various purposes, it is imperative to develop new security solutions against such attacks. In this article, a mathematical framework is introduced for analyzing and mitigating the effects of GPS spoofing attacks on UAVs. In particular, system dynamics are used to model the optimal routes that the UAVs will adopt to reach their destinations. The GPS spoofer's effect on each UAV's route is also captured by the model. To this end, the spoofer's optimal imposed locations on the UAVs, are analytically derived; allowing the UAVs to predict their traveling routes under attack. Then, a countermeasure mechanism is developed to mitigate the effect of the GPS spoofing attack. The countermeasure is built on the premise of cooperative localization, in which a UAV can determine its location using nearby UAVs instead of the possibly compromised GPS locations. To better utilize the proposed defense mechanism, a dynamic Stackelberg game is formulated to model the interactions between a GPS spoofer and a drone operator. In particular, the drone operator acts as the leader that determines its optimal strategy in light of the spoofer's expected response strategy. The equilibrium strategies of the game are then analytically characterized and studied through a novel proposed algorithm. The simulation results show that, when combined with the Stackelberg strategies, the proposed defense mechanism will outperform baseline strategy selection techniques in terms of reducing the possibility of UAV capture.
AbdelRahman Eldosouky, Aidin Ferdowsi, Walid Saad 0001
IEEE Internet Things J.1
2016 Single controller stochastic games for optimized moving target defense
abstract
Moving target defense (MTD) techniques that enable a system to randomize its configuration to thwart prospective attacks are an effective security solution for tomorrow's wireless networks. However, there is a lack of analytical techniques that enable one to quantify the benefits and tradeoffs of MTDs. In this paper, a novel approach for implementing MTD techniques that can be used to randomize cryptographic techniques and keys in wireless networks is proposed. In particular, the problem is formulated as a stochastic game in which a base station (BS), acting as a defender seeks to strategically change its cryptographic techniques and keys in an effort to deter an attacker that is trying to eavesdrop on the data. The game is shown to exhibit a single-controller property in which only one player, the defender, controls the state of the game. For this game, the existence and properties of the Nash equilibrium are studied, in the presence of a defense cost for using MTD. Then, a practical algorithm for deriving the equilibrium MTD strategies is derived. Simulation results show that the proposed game-theoretic MTD framework can significantly improve the overall utility of the defender, while enabling effective randomization over cryptographic techniques.
AbdelRahman Eldosouky, Walid Saad 0001, Dusit Niyato
ICC1
2015 Contract-Theoretic Resource Allocation for Critical Infrastructure Protection
abstract
Critical infrastructure protection (CIP) is envisioned to be one of the most challenging security problems in the coming decade. One key challenge in CIP is the ability to allocate resources, either personnel or cyber, to critical infrastructures with different vulnerability and criticality levels. In this work, a contract- theoretic approach is proposed to solve the problem of resource allocation in critical infrastructure with asymmetric information. A control center (CC) is used to design contracts and offer them to infrastructures' owners. A contract can be seen as an agreement between the CC and infrastructures using which the CC allocates resources and gets rewards in return. Contracts are designed in a way to maximize the CC's benefit and motivate each infrastructure to accept a contract and obtain proper resources for its protection. Infrastructures are defined by both vulnerability levels and criticality levels which are unknown to the CC. Therefore, each infrastructure can claim that it is the most vulnerable or critical to gain more resources. A novel mechanism is developed to handle such an asymmetric information while providing the optimal contract that motivates each infrastructure to reveal its actual type. The necessary and sufficient conditions for such resource allocation contracts under asymmetric information are derived. Simulation results show that the proposed contract-theoretic approach maximizes the CC's utility while ensuring that no infrastructure has an incentive to ask for another contract, despite the lack of exact information at the CC.
AbdelRahman Eldosouky, Walid Saad 0001, Charles A. Kamhoua, Kevin A. Kwiat
GLOBECOM1