VLDB 2026 Research / reviewers in the wild / expert
Rida Khatoun
dblp:18/2789
· DBLP profile ↗
35ranked-venue papers
0as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 7 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Trust-based attack detection model for connected cars using a Subjective Logic based framework
Ahmad Ismail, Ahmad Fadlallah, Francesca Bassi, Rida Khatoun |
IWCMC | 4 |
| 2025 | Analyzing the Persuasive Strategies of Influencers and News Media on Social MediaabstractSocial media platforms have become arenas for political discourse, where political influencers and news media organizations actively employ rhetorical strategies to shape public opinion. However, how these strategies differ between actors and adapt to audience expectations remains underexplored. This study investigates the nature of digital persuasion and its impact on the audience engagement in political discourse on the X platform (formerly Twitter). Specifically we analyze how persuasive strategies employed by political influencers and news media accounts differ during a U.S. election event, and how types of persuasion correlate with the engagement the audiences. Our approach encompasses an analysis of the Aristotles persuasion framework that consists of three appeals: Ethos (credibility), Pathos (emotion appeal), and logos (logic and reasoning), along with sentiment, and social network analysis. The findings identify that political influencers tend to employ a hybrid strategy that combines ethos and logos to maximize user engagement and exhibit high linguistic homophily with their ego networks. In contrast, news media accounts predominantly rely on ethos-driven appeals and show limited rhetorical alignment with their audiences. These insights highlight how rhetorical adaptation and audience alignment differ between influencers and institutional actors, offering a new lens for understanding digital political communication. Omran Berjawi, Rida Khatoun, Giuseppe Fenza |
AICCSA | 2 |
| 2025 | Securing Cooperative Vehicular Platooning with a Set of Reinforced ChecksabstractInternational audience Farah-Emma Braiteh, Francesca Bassi, Rida Khatoun |
IWCMC | 3 |
| 2025 | Digital Persuasion: Understanding the Impact of Online Influencers on Public Opinion
Omran Berjawi, Rida Khatoun, Giuseppe Fenza |
PERSUASIVE | 2 |
| 2025 | Exposing Go's Hidden Bugs: A Novel Concolic FrameworkabstractThe widespread adoption of the Go programming language [1] in infrastructure backends and blockchain projects has heightened the need for improved security measures. Established techniques such as unit testing, static analysis, and program fuzzing provide foundational protection mechanisms. Although symbolic execution tools have made significant contributions, opportunities remain to address the complexities of Go’s runtime and concurrency model. In this work, we present Zorya, a novel methodology leveraging concrete and symbolic (concolic) execution to evaluate Go programs comprehensively. By systematically exploring execution paths to uncover vulnerabilities beyond conventional testing, symbolic execution offers distinct advantages, and coupling it with concrete execution mitigates the path explosion problem. Our solution employs Ghidra’s PCode [2] as an intermediate representation (IR). This implementation detects runtime panics in the TinyGo compiler [3] and supports both generic and custom invariants. Furthermore, $\mathbf{P}$ Code’s generic IR nature enables analysis of programs written in other languages such as $\mathbf{C}$. Future enhancements may include intelligent classification of concolic execution logs to identify vulnerability patterns. Karolina Gorna, Nicolas Iooss, Yannick Seurin, Rida Khatoun |
SERA | 4 |
| 2025 | Secure Group Key Dissemination Protocol in Cooperative Vehicular PlatooningabstractCooperative vehicular platoons improve road safety and reduce congestion through synchronized maneuvers enabled by Vehicle-to-Vehicle (V2V) communication. Vehicles are authenticated using certificates from the Cooperative Intelligent Transport Systems (C-ITS) Public Key Infrastructure (PKI). Short-term certificates, serving as vehicle identifiers, change over time and distance, which may lead to legitimate members being misidentified as attackers in the platoon, resulting in false positives. Additionally, sensitive data, such as platoon IDs, must be protected from impersonation attacks by external vehicles. To address these challenges, we propose a secure group key-based authentication framework that uses post-quantum cryptography and Shamir's Secret Sharing for key exchange. This ensures accurate member authentication and protection of platoon data. Security analysis using the Scyther tool along with simulations using PLEXE simulator demonstrate the protocol's effectiveness in securing platoon operations against cyber threats. Farah-Emma Braiteh, Francesca Bassi, Rida Khatoun |
WiMob | 3 |
| 2025 | Tracking Vehicles in Cooperative Intelligent Transportation Systems: Attacks, Defense Solutions, and Future DirectionsabstractThe Cooperative Intelligent Transportation System (C-ITS) is vital in enhancing road safety, improving traffic efficiency, and increasing user comfort for pedestrians and drivers. However, as vehicle communications evolve, security threats that aim to undermine critical security services, such as data confidentiality, integrity, and privacy, have become crucial issues that must be addressed. Privacy, the freedom from interference or intrusion, is also considered one of the most significant challenges in computer networks and connected vehicles. Privacy in C-ITS can be protected by preventing both the collection of personal information and the tracking of vehicles by malicious users. Tracking is often achieved through the periodic transmission of Cooperative Awareness Messages (CAMs), which contain spatio-temporal information such as position and speed. We investigate key tracking-related critical issues in intelligent connected vehicles. We highlight current security challenges and attacks that lead to the unauthorized tracking of connected cars. We discuss various defense solutions proposed in the literature to address these challenges. We classify these solutions into two groups: general (addressing eavesdropping, Sybil, etc.) and pseudonym change (addressing correlation, swap, silent periods, and mix-zones). Finally, we explore robust future strategies to prevent tracking attacks on the C-ITS. Fadlallah Chbib, Sherali Zeadally, Ahmad Fadlallah, Rida Khatoun, Ali El Attar |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | How Does Distributed Denial of Service Affect the Connected Cars Environment?abstractDistributed Denial-of-Service (DDoS) attacks are among the most insidious cyberattacks targeting any networking system. In the Internet domain, these attacks have demonstrated the capability of bringing down most systems for extended periods. In recent years, researchers have been exploring and simulating DDoS attacks against connected car systems. However, these simulated attacks have primarily employed messages from the Internet domain rather than leveraging the messages exchanged between connected vehicles. This paper presents a novel study that investigates the impact of DDoS attacks employing Cooperative Awareness Messages (CAMs), which serve as fundamental safety messages for establishing awareness in the connected car environment. The results obtained reveal that our attack exerts a significant, silent, and stealthy impact on connected cars. While the system remains operational, the quality of the services it provides (e.g., data collection and vehicle cooperation) is severely compromised. This highlights the vulnerability of connected cars to these attacks and underscores the need for robust mitigation strategies. Ayoub Wehby, Sherali Zeadally, Rida Khatoun, Mohammed Lamine Bouchouia, Ahmad Fadlallah |
CoDIT | 3 |
| 2024 | DNS flooding attack detection scheme through Machine LearningabstractDomain Name System (DNS) servers are considered registers that enable internet devices to quickly look up specific web servers and access web pages. DNS flooding is a type of distributed denial of service (DDoS) attack in which an attacker overwhelms DNS servers with a huge number of resolution requests. Such an attack can prevent DNS servers from responding to legitimate traffic. In this paper, we propose a new approach that relies on monitoring and analyzing incoming DNS requests to identify flooding attacks against DNS servers. The detection is carried out using a Machine Learning-based Intrusion Detection System at the entry point of networks. We analyze the performance of different machine learning methods (decision tree, random forest, XGBoost, SVM, K-nearest neighbors, logistic regression, and Multi-Layer Perceptron) for detecting DNS flooding attacks. The evaluation was conducted in the context of emulated attacks. The obtained results reveal that all six methods exhibit the capability to effectively detect DNS attacks, even when dealing with low attack rates. This highlights the robustness of these methods and their potential to maintain high accuracy levels in identifying DNS attack patterns. Ali El Attar, Rida Khatoun, Fadlallah Chbib, Ahmad Fadlallah, Ahmed Serhrouchni |
IWCMC | 2 |
| 2024 | Shielding the Connected Cars: A Dataset-Powered Defense Against DDoSabstractThe connected car is no longer a theoretical concept and is now in the application phase. This puts a burden on the infrastructure of the connected cars since it is at the heart of this technology. The research is now focused on how to protect this infrastructure against the well-known serious attacks, among which is the Distributed Denial of Service (DDoS) attack. The messages exchanged between the cars and the infrastructure are secured by digital certificates, this protects the network from external attacks only. Therefore, there is a need for an extra layer of security that protects the system from insider attacks in the form of an Intrusion Detection System (IDS). While researchers have made efforts to simulate such an attack in a near-realistic setup, the work still lacks its true representation. To contribute to this research gap, we present in this paper the generation of a publicly available dataset representing a DDoS attack simulated using Cooperative Awareness Messages in a well-known vehicular traffic simulation to be used to develop an IDS. The data collection is done on the Road Side Unit reflecting real data collection. Also, we propose an ensemble learning-driven approach as a potential framework for creating connected cars Vehicle-to-Everything IDS. Where we delve into the propositions of its deployment and the architecture of it. The obtained results show a Matthews correlation coefficient of 98% by the proposed models countering the attacks. Ayoub Wehby, Rida Khatoun, Ahmad Fadlallah |
WINCOM | 2 |
| 2023 | Comparison of Data Cleansing Methods for Network DDoS Attacks MitigationabstractA Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming it with a flood of requests from multiple compromised internet-connected devices, such as distributed servers, personal computers, and Internet of Things devices. One of the methods used to defend against DDoS attacks is traffic redirection to a Scrubbing Center (SC) for further inspection and mitigation. In this research, we present a novel scrubbing method that employs machine learning models to detect DDoS attacks. We propose using three machine learning algorithms, Random Forest, Support Vector Machine (SVM), and eXtreme Gradient Boosting (XGBoost), and combine them with three feature selection techniques, Analysis of Variance (ANOVA), Principal Component Analysis (PCA), and Kendall's Rank Correlation. Our results indicate that a combination of Kendall's Rank Correlation as a feature selector with SVM, XGBoost, and Random Forest models achieved a high F1 score. Adonis Jamal, Ali El Attar, Fadlallah Chbib, Rida Khatoun |
CoDIT | 4 |
| 2023 | Lightweight TLS 1.3 Handshake for C-ITS SystemsabstractCooperative Intelligent Transport Systems (C-ITS) Deployment Platform is considered the newest version of vehicular communication systems, which enables the cooperation between two or more ITS sub-systems to provide enhanced services. With the expanded communication range and system complexity, ensuring the credibility of access nodes and protecting users from being monitored has become a difficult problem in network security, especially the services provided by remote servers like navigation. Transport Layer Security (TLS) is widely used for user authentication and encrypted data transmission in all networks. However, although the TLS handshake complexity is significantly reduced in TLS 1.3 the transmission of a full certificate chain during the handshake is still costly, especially for high-mobility vehicles. In this paper, we propose an optional extension named Certificate Get to reduce the TLS handshake overhead in C-ITS. Specifically, with our proposed extension, the revisiting client transmits a hash value of the certificate chain corresponding to a certain server in the ClientHello message, which can reduce the transmission payload of the certificate chain from an average of 4874 bytes to 68 bytes. Simulation results show that our proposed scheme achieves a significant performance gain by greatly reducing the certificate transmission delay by 50% for both TLS 1.3 and TLS 1.2. Danylo Goncharskyi, Sung Yong Kim, Pengwenlong Gu, Ahmed Serhrouchni, Rida Khatoun, Farid Naït-Abdesselam |
ICC | 5 |
| 2023 | Enabling Programmable Deterministic Communications in 6GabstractEmerging applications and technologies such as vehicle-to-everything (V2X), edge-computing, and artificial intelligence have emphasized the demand for low-latency and deterministic communication. Although the 5G network has taken several efforts to fulfill this demand, such as with 5G-Time-Sensitive Networking (TSN) integration and DetNet, these efforts must be significantly expanded in 6G to fully achieve end-to-end deterministic communication. In this paper, we explore the problem of programmable deterministic communication in the new architecture of 6G. To deal with this problem, we rely on TSN, which has been proven to be a promising solution for deterministic communication. We take V2X as a use case, then investigate the two greatest challenges of this use case: low-latency communication and programmable network management for deterministic communication. To deal with these challenges, we introduce two solutions: (i) TSN low-latency scheduling supported by Multi-Agent Deep Reinforcement Learning, and (ii) programmable network management supported by SDN and joint cloud-infrastructure control. For each solution, detailed architecture and functionality design are presented. We show their high feasibility, applicability, and potentialities through comprehensive definitions, detailed explanations and in-depth qualitative analysis. Minh-Thuyen Thi, Siwar Ben Hadj Said, Adrien Roberty, Fadlallah Chbib, Rida Khatoun, Leonardo Linguaglossa |
MobiHoc | 5 |
| 2023 | Dynamic logic-based attack graph for risk assessment in complex computer systems
Antoine Boudermine, Rida Khatoun, Jean-Henri Choyer |
Comput. Networks | 2 |
| 2023 | Detecting DDoS attacks using adversarial neural network
Ali Mustapha, Rida Khatoun, Sherali Zeadally, Fadlallah Chbib, Ahmad Fadlallah, Walid Fahs, Ali El Attar |
Comput. Secur. | 2 |
| 2022 | A machine learning based approach for the detection of sybil attacks in C-ITSabstractThe intrusion detection systems are vital for the sustainability of Cooperative Intelligent Transportation Systems (C-ITS) and the detection of sybil attacks are particularly challenging. In this work, we propose a novel approach for the detection of sybil attacks in C-ITS environments. We provide an evaluation of our approach using extensive simulations that rely on real traces, showing our detection approach's effectiveness. Badis Hammi, Yacine Mohamed Idir, Rida Khatoun |
APNOMS | 3 |
| 2022 | Delay Measurement of 0-RTT Transport Layer Security (TLS) Handshake ProtocolabstractTransport Layer Security (TLS) 1.3 was normalised in 2018, in which an efficient 0-rtt handshake protocol was proposed. For future 5G networks, the 0-RTT handshake will be a more suitable choice for both secrecy and efficiency. However, 4 years after it was proposed, the 0-rtt handshake protocol is still not widely accepted by network service providers due to concerns about its ability to resist replay attacks. In order to address this issue, many solutions have be proposed in the past few year but all of them will increase the complexity and overhead of the 0-RTT protocol. In this paper, we focus on testing whether the 0-RTT handshake protocol is supported by service providers, and testing its performance in a real network environment to verify whether it can withstand continuous optimization in terms of security. Test results show that with 0-RTT, the server received the first application data up to 37 time faster than the 1-RTT and up to 83 time faster than 2-RTT. However, at the client side, the performance of 0-RTT protocol is virtually the same as 1-RTT, as predicted. Danylo Goncharskyi, Sung Yong Kim, Ahmed Serhrouchni, Pengwenlong Gu, Rida Khatoun, Joel Hachem |
CoDIT | 5 |
| 2022 | TLS Early Data Resistance to Replay Attacks in Wireless Internet of ThingsabstractTransport Layer Security (TLS) is widely used for user authentication and encrypted data transmission in all kinds of networks. In its newly published version, TLS 1.3, a 0- RTT handshake protocol is proposed for session resumptions in low delay networks, which makes it possible to secure the data transmission and protect users from being monitored in wireless Internet of Things (IoTs). However, the 0-RTT TLS handshake protocol is vulnerable to the replay attack. In this paper, we propose a Time-Based One-Time Password (TOTP) empowered TLS encryption algorithm to resist replay attacks during the handshake process, in which we propose to integrate the TOTP into the encryption process of the EarlyData. It can significantly improve the forward secrecy of the 0-RTT handshake protocol and its capacity to resist the replay attack. On the other hand, we make no changes to the interaction process of the standardized 0- RTT handshake protocol to guarantee the compatibility of our proposed scheme, which makes our proposed scheme suitable for large area wireless IoTs. Simulation results show that under the premise of choosing an appropriate TOTP update rate, our proposed scheme can effectively resist replay attacks while ensuring the processing efficiency of the system. Sung Yong Kim, Danylo Goncharskyi, Pengwenlong Gu, Ahmed Serhrouchni, Rida Khatoun, Farid Naït-Abdesselam, Jean-Jacques Grund |
GLOBECOM | 5 |
| 2022 | Survey on smart homes: Vulnerabilities, risks, and countermeasures
Badis Hammi, Sherali Zeadally, Rida Khatoun, Jamel Nebhen |
Comput. Secur. | 3 |
| 2022 | Is it Really Easy to Detect Sybil Attacks in C-ITS Environments: A Position PaperabstractIn the context of current smart cities, Cooperative Intelligent Transportation Systems (C-ITS) represent one of the main use case scenarios that aim to improve peoples’ daily lives. Thus, during the last few years, numerous standards have been adopted to regulate such networks. Within a C-ITS, a large number of messages are exchanged continuously in order to ensure that the different applications operate efficiently. However, these networks can be the target of numerous attacks. The sybil attack is among the most dangerous ones. In a sybil attack, an attacker creates multiple identities and then disguises as several fake stations in order to interfere with the normal operations of the system or profit from provided services. We analyze recently proposed sybil detection approaches regarding their compliance with the current C-ITS standards as well as their evaluation methods. We provide several recommendations such as network and attack models as well as an urban and highway datasets that can be considered in future research in sybil attack detection. Badis Hammi, Yacine Mohamed Idir, Sherali Zeadally, Rida Khatoun, Jamel Nebhen |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2021 | Scaling A Blockchain System For 5G-based Vehicular Networks Using Heuristic Shardingabstract5G communications are expected to expand both capacity and flexibility in future vehicular networks. However, due to the wide coverage range of 5G-based networks, massive device access in the 5G era will pose great challenges in access control and terminal management. In order to address the scalability issue in large-scale 5G-based vehicular networks, we propose in this paper the use of two heuristic sharding schemes which are based on the Determinantal Point Process (DPP) with different complexities. Specifically, in the proposed algorithms, both location and wireless channel condition of a base station (BS) are jointly considered respectively as diversity and quality parameters in the DPP. Both of them can effectively control the size of each shard, ensure the shards are evenly distributed and allow in-shard cooperation among the BSs. The communication robustness is then greatly improved due to the efficient in-shard cooperation and the system guarantees stable throughput even in scenarios where transactions volume changes dynamically. While compared to benchmark schemes, the simulation results of the proposed protocol and algorithms show significant performance gains in terms of coverage and load balancing. Pengwenlong Gu, Dingjie Zhong, Cunqing Hua, Farid Naït-Abdesselam, Ahmed Serhrouchni, Rida Khatoun |
GLOBECOM | 6 |
| 2020 | A secure multipath reactive protocol for routing in IoT and HANETs
Badis Hammi, Sherali Zeadally, Houda Labiod, Rida Khatoun, Youcef Begriche, Lyes Khoukhi |
Ad Hoc Networks | 4 |
| 2020 | Control Channel Anti-Jamming in Vehicular Networks via Cooperative Relay BeamformingabstractIn vehicular networks, radio-frequency (RF) jamming attacks are considered a major threat to the availability of control channel (CCH). In particular, vehicles may not be able to receive control messages from roadside units (RSUs) due to persistent interference in the CCH, which may claim human lives and result in significant economic losses. In this article, a cooperative anti-jamming beamforming scheme is proposed to address the CCH jamming problems in vehicular networks. This scheme utilizes spatial diversity provided by the multiantenna RSU and relay vehicles to improve the transmission reliability of downlink control messages. In addition, to address the additive effects of the jamming signals and the intergroup interference, the relay selection problem and the beamformer design problem are jointly considered, which is modeled as a mixed-integer nonlinear programming (MINLP) problem. Then, we address this challenging problem by relaxing it into a series of convex subproblems via the semi-definite relaxation (SDR) and convex-concave process (CCP) methods, and then propose to solve these convex subproblems iteratively. The simulation results show that our proposed method convergences rapidly, and compared to the benchmark schemes, significant performance gains can be observed. Pengwenlong Gu, Cunqing Hua, Wenchao Xu 0001, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni |
IEEE Internet Things J. | 4 |
| 2018 | Perils of using CQIC in LTE network and a quick fix with delayed ACKabstractIn this poster, we revisit the CQIC congestion control and adapt the implementation from 3G/QUIC semantic to LTE/TCP. We identify the reason for performance degradation of End-to-End (E2E) high data rate connection-oriented download in LTE Acknowledgement Mode (AM, which is turned on by default) and further recommend to turn on the Delayed Acknowledgement (DelAck) feature for TCP-CQIC, or more generally, for all the high speed E2E connections in LTE-AM mode. Finally, an NS3 simulation of TCP-CQIC and TCP-CQIC-DelAck with TCP Cubic and Westwood as a bench mark is made. Zhenzhe Zhong, Isabelle Hamchaoui, Rida Khatoun |
CCNC | 3 |
| 2018 | CDBE: A cooperative way to improve end-to-end congestion control in mobile networkabstractThe advancing MAC/PHY technique and architecture in the mobile network allows the DownLink (DL) capacity in radio access network (RAN) to vary from Kilo-Byte per-second level up to Giga-byte per-second level in a glimpse. The existing TCP congestion control algorithms (CCA) were not designed for such dramatic variability. In this paper, we proposed an improvement for end-to-end congestion control, called Client Driven Bandwidth Estimation (CDBE), which allows TCP clients to cooperate with its CDBE. The cooperation can enhance the down-stream (DS) performance of the connections, even in the mobile network. The CDBE client can measure the available bandwidth (BW) on the bottleneck and inform the server of the BW estimation (BWE) result. Unlike existing mobile cross-layer congestion control proposals, the proposed algorithm on TCP client does not directly invoke information from UE MAC/PHY layer module but implicitly reflect the varying cellular BW when the mobile last hop is the bottleneck of the network. The CDBE TCP server uses the received BWE value to calculate its pacing rate and congestion window, and it further calibrates the result according to the variation of down-stream delay (DSDL). The state transition in the server can react rapidly to eNB BW and queue variation. Sets of NS3 system simulation in a LTE network is conducted with BBR and CQIC as the baseline. The result shows that the proposed algorithm can improve the end-to-end throughput and good-put while keeping the DS delay at a low level. Zhenzhe Zhong, Isabelle Hamchaoui, Alexandre Ferrieux, Rida Khatoun, Ahmed Serhrouchni |
WiMob | 4 |
| 2018 | Cooperative relay beamforming for control channel jamming in vehicular networksabstractRadio Frequency (RF) jamming attacks constitute a major threat to the availability of control channel communications in the vehicular networks. In particular, the victim vehicles may fail to receive the safety related messages from the Road Side Unit (RSU) due to persistent jamming attacks, which can possibly cause tremendous economic loss and claim human lives. In this paper, we propose a cooperative anti-jamming beamforming scheme for the control channel jamming problem in vehicular networks, which takes advantage of the multi-antenna and spatial diversity provided by the RSU and relay vehicles to improve the transmission reliability of the victim vehicles. The anti-jamming beamformer design problem is formulated as a Mixed-integer Nonlinear Programming (MINLP) problem, which is intractable in general. We address this challenging problem by reformulating it as a sequence of convex sub-problems using the semi-definite relaxation (SDR) and convex-concave procedure (CCP) methods. Simulation results are provided to investigate the convergence of the proposed scheme, and significant performance gain can be observed comparing with other benchmark schemes. Pengwenlong Gu, Cunqing Hua, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni |
WiOpt | 3 |
| 2017 | Cooperative Anti-Jamming Relaying for Control Channel Jamming in Vehicular NetworksabstractRadio Frequency (RF) jamming attacks represent a major threat to the availability of services in vehicular networks. In particular, if the control channel is under persistent jamming attacks, the vehicles within the jamming area cannot receive the safety related messages from the road side unit (RSU), which can possibly cause tremendous economic loss and claim human lives. In this paper, we propose to adopt the cooperative relaying technique to address this problem, whereby the neighbouring vehicles outside of the jamming area serve as the relay nodes to forward the received control channel signal to the victim vehicles through the jamming- free service channel. To investigate the performance of this cooperative relaying scheme, we analyse the outage probability at the victims under different jamming scenarios based on Poisson point process (PPP) model. Simulation results are provided to validate the theoretical results and show the effectiveness of the cooperative anti-jamming relay scheme under different conditions. Pengwenlong Gu, Cunqing Hua, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni |
GLOBECOM | 3 |
| 2017 | Support Vector Machine (SVM) Based Sybil Attack Detection in Vehicular NetworksabstractVehicular networks have been drawing special atten- tion in recent years, due to its importance in enhancing driving experience and improving road safety in future smart city. In past few years, several security services, based on cryptography, PKI and pseudonymous, have been standardized by IEEE and ETSI. However, vehicular networks are still vulnerable to various attacks, especially Sybil attack. In this paper, a Support Vector Machine (SVM) based Sybil attack detection method is proposed. We present three SVM kernel functions based classifiers to distinguish the malicious nodes from benign ones via evaluating the variance in their Driving Pattern Matrices (DPMs). The effectiveness of our proposed solution is evaluated through extensive simulations based on SUMO simulator and MATLAB. The results show that the proposed detection method can achieve a high detection rate with low error rate even under a dynamic traffic environment. Pengwenlong Gu, Rida Khatoun, Youcef Begriche, Ahmed Serhrouchni |
WCNC | 2 |
| 2017 | A stochastic approach for packet dropping attacks detection in mobile Ad hoc networks
Mohammad Rmayti, Rida Khatoun, Youcef Begriche, Lyes Khoukhi, Dominique Gaïti |
Comput. Networks | 2 |
| 2015 | A collaborative approach for a source based detection of botcloudsabstractSince the last years, cloud computing is playing an important role in providing high quality of IT services. However, beyond a legitimate usage, the numerous advantages it presents are now exploited by attackers, and botnets supporting DDoS attacks are among the greatest beneficiaries of this malicious use. In this paper, we present an original approach that enables a collaborative egress detection of DDoS attacks leveraged by a botcloud. We provide an early evaluation of our approach using simulations that rely on real workload traces, showing our detection system effectiveness and low overhead, as well as its support for incremental deployment in real cloud infrastructures. Badis Hammi, Guillaume Doyen, Rida Khatoun |
IM | 3 |
| 2014 | Trimming Approach of Robust Clustering for Smartphone Behavioral AnalysisabstractNowadays, smart phones get increasingly popular which also attracted hackers. With the increasing capabilities of such phones, more and more malicious softwares targeting these devices have been developed. Malwares can seriously damage an infected device within seconds. In this paper, we propose to use the trimming approaches for automatic clustering (trimmed k-means, Tclust) of smartphone's applications. They aim to identify homogenous groups of applications exhibiting similar behavior and allow to handle a proportion of contaminating data to guarantee the robustness of clustering. Then, a clustering-based detection technique is applied to compute an anomaly score for each application, leading to discover the most dangerous among them. Initial experiments results prove the efficiency and the accuracy of the used clustering methods in detecting abnormal smartphone's applications and that with a low false alerts rate. Ali El Attar, Rida Khatoun, Marc Lemercier |
EUC | 2 |
| 2014 | Clustering-based anomaly detection for smartphone applicationsabstractNowadays, Smartphones have been widely used due to their capabilities in communication and multimedia processing. Smartphones provide access to a tremendous amount of sensitive information related to business, such as customer contacts, financial data, and Intranet networks. Hence, the Internet of the future will be mobile Internet. However, threat of malicious software has become an important factor in the smartphones security. In this paper, a new behavior-based malware detection framework using three clustering methods (PAM, DBSCAN and t-distribution) is proposed. Experimental results show that the approach has high detection rate and low rate of false positive and false negative. Ali El Attar, Rida Khatoun, Marc Lemercier |
NOMS | 2 |
| 2014 | Understanding botclouds from a system perspective: A principal component analysisabstractCloud computing is gaining ground and becoming one of the fast growing segments of the IT industry. However, if its numerous advantages are mainly used to support a legitimate activity, it is now exploited for a use it was not meant for: malicious users leverage its power and fast provisioning to turn it into an attack support. Botnets supporting DDoS attacks are among the greatest beneficiaries of this malicious use since they can be setup on demand and at very large scale without requiring a long dissemination phase nor an expensive deployment costs. For cloud service providers, preventing their infrastructure from being turned into an Attack as a Service delivery model is very challenging since it requires detecting threats at the source, in a highly dynamic and heterogeneous environment. In this paper, we present the result of an experiment campaign we performed in order to understand the operational behavior of a botcloud used for a DDoS attack. The originality of our work resides in the consideration of system metrics that, while never considered for state-of-the-art botnets detection, can be leveraged in the context of a cloud to enable a source based detection. Our study considers both attacks based on TCP-flood and UDP-storm and for each of them, we provide statistical results based on a principal component analysis, that highlight the recognizable behavior of a botcloud as compared to other legitimate workloads. Badis Hammi, Guillaume Doyen, Rida Khatoun |
NOMS | 3 |
| 2014 | Robust clustering methods for detecting smartphone's abnormal behaviorabstractSmartphones have become increasingly popular, and, nowadays, thanks to the use of 3G networks, the need for connectivity in a business environment is significant. Smartphones provide access to a tremendous amount of sensitive information related to business, such as customer contacts, financial data and Intranet networks. If any of this information were to fall into the hands of hackers, it would be devastating for the company. In this paper, we propose a cluster-based approach to detecting abnormal behaviour in smartphone applications. First we carry out various robust clustering techniques that help to identify and regroup applications that exhibit similar behaviour. The clustering results are then used to define a cluster-based outlier factor for each application, which in turn identifies the top n malware applications. Initial results of the experiments prove the efficiency and accuracy of cluster-based approaches in detecting abnormal smartphone applications and those with a low false-alert rate. Ali El Attar, Rida Khatoun, Babiga Birregah, Marc Lemercier |
WCNC | 2 |
| 2011 | Content pollution quantification in large P2P networks : A measurement study on KADabstractContent pollution is one of the major issues affecting P2P file sharing networks. However, since early studies on FastTrack and Overnet, no recent investigation has reported its impact on current P2P networks. In this paper, we present a method and the supporting architecture to quantify the pollution of contents in the KAD network. We first collect information on many popular files shared in this network. Then, we propose a new way to detect content pollution by analyzing all filenames linked to a content with a metric based on the Tversky index and which gives very low error rates. By analyzing a large number of popular files, we show that 2/3 of the contents are polluted, one part by index poisoning but the majority by a new, more dangerous, form of pollution that we call index falsification. Guillaume Montassier, Thibault Cholez, Guillaume Doyen, Rida Khatoun, Isabelle Chrisment, Olivier Festor |
Peer-to-Peer Computing | 4 |