ElMouatez Billah Karbab

dblp:191/0088 · also Elmouatez Billah Karbab, Elmouatezbillah Karbab · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
4since 2021 · last 2023
0000-0003-1293-8314ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 SwiftR: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab
Expert Syst. Appl.1
2022 Chameleon: Optimized feature selection using particle swarm optimization and ensemble methods for network anomaly detection
Aniss Chohra, Paria Shirani, ElMouatez Billah Karbab, Mourad Debbabi
Comput. Secur.3
2022 Inferring and Investigating IoT-Generated Scanning Campaigns Targeting a Large Network Telescope
abstract
The analysis of recent large-scale cyber attacks, which leveraged insecure Internet of Things (IoT) devices to perform malicious activities on the Internet, highlighted the rise of IoT-tailored malware/botnets. These malware propagate by scanning the Internet for vulnerable, exploitable IoT devices that could be utilized for further malicious activities. In this article, we devise a multi-level methodology to investigate Internet-scale reconnaissance activities generated by infected IoT devices. We leverage theShodanIoT search engine and over 6TB of passive network traffic from a large network telescope (darknet) to infer compromised IoT devices and characterize the generated scanning campaigns. The results highlight a distinctive characteristic of IoT malware/botnets, represented by the targeted ports/services over the analysis interval. Furthermore, while these ports/services are mainly associated with well-known IoT malware/botnets (e.g.,MiraiandSatori), we uncovered newly targeted ports, which indicate emerging IoT malware/botnet. Finally, by comparing two instances of analyzed IoT-generated scanning campaigns, we highlight the persistence and evolution of IoT malware/botnets (e.g.,ADB.MinerandFbot), which exploit existing, and in some cases, possibly new vulnerabilities.
Sadegh Torabi, Elias Bou-Harb, Chadi Assi, ElMouatez Billah Karbab, Amine Boukhtouta, Mourad Debbabi
IEEE Trans. Dependable Secur. Comput.4
2021 PetaDroid: Adaptive Android Malware Detection Using Deep Learning
ElMouatez Billah Karbab, Mourad Debbabi
DIMVA1
2020 Scalable and robust unsupervised Android malware fingerprinting using community-based network partitioning
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
Comput. Secur.1
2020 Scalable and robust unsupervised android malware fingerprinting using community-based network partitioning
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
Comput. Secur.1
2019 BinEye: Towards Efficient Binary Authorship Characterization Using Deep Learning
Saed Alrabaee, ElMouatez Billah Karbab, Lingyu Wang 0001, Mourad Debbabi
ESORICS (2)2
2018 ToGather: Automatic Investigation of Android Malware Cyber-Infrastructures
abstract
The popularity of Android, not only in handsets but also in IoT devices, makes it a very attractive target for malware threats, which are actually expanding at a significant rate. The state-of-the-art in malware mitigation solutions mainly focuses on the detection of malicious Android apps using dynamic and static analysis features to segregate malicious apps from benign ones. Nevertheless, there is a small coverage for the Internet/network dimension of Android malicious apps. In this paper, we present ToGather, an automatic investigation framework that takes Android malware samples as input and produces insights about the underlying malicious cyber infrastructures. ToGather leverages state-of-the-art graph theory techniques to generate actionable, relevant and granular intelligence to mitigate the threat effects induced by the malicious Internet activity of Android malware apps. We evaluate ToGather on a large dataset of real malware samples from various Android families, and the obtained results are both interesting and promising.
ElMouatez Billah Karbab, Mourad Debbabi
ARES1
2017 SONAR: Automatic Detection of Cyber Security Events over the Twitter Stream
abstract
Everyday, security experts face a growing number of security events that affecting people well-being, their information systems and sometimes the critical infrastructure. The sooner they can detect and understand these threats, the more they can mitigate and forensically investigate them. Therefore, they need to have a situation awareness of the existing security events and their possible effects. However, given the large number of events, it can be difficult for security analysts and researchers to handle this flow of information in an adequate manner and answer the following questions in near-real time: what are the current security events? How long do they last? In this paper, we will try to answer these issues by leveraging social networks that contain a massive amount of valuable information on many topics. However, because of the very high volume, extracting meaningful information can be challenging. For this reason, we propose SONAR: an automatic, self-learned framework that can detect, geolocate and categorize cyber security events in near-real time over the Twitter stream. SONAR is based on a taxonomy of cyber security events and a set of seed keywords describing type of events that we want to follow in order to start detecting events. Using these seed keywords, it automatically discovers new relevant keywords such as malware names to enhance the range of detection while staying in the same domain. Using a custom taxonomy describing all type of cyber threats, we demonstrate the capabilities of SONAR on a dataset of approximately 47.8 million tweets related to cyber security in the last 9 months. SONAR could efficiently and effectively detect, categorize and monitor cyber security related events before getting on the security news, and it could automatically discover new security terminologies with their event. Additionally, SONAR is highly scalable and customizable by design; therefore we could adapt SONAR framework for virtually any type of events that experts are interested in.
Quentin Le Sceller, ElMouatez Billah Karbab, Mourad Debbabi, Farkhund Iqbal
ARES2
2016 Cypider: building community-based cyber-defense infrastructure for android malware detection
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
ACSAC1
2013 Ubiquitous sensor network management: The least interference beaconing model
abstract
Network management is revisited in the emerging ubiquitous sensor networks (USNs) that form the Internet-of-the-Things (IoT) with the objective of evaluating the impact of traffic engineering on energy efficiency and assessing if routing simplicity translates into scalability. USN management is formulated as a local optimization problem minimizing the number of traffic flows transiting by a node: the nodes traffic flow interference with other nodes. The least interference beaconing algorithm (LIBA) is proposed as an algorithmic solution to the problem, and the least interference beaconing protocol (LIBP) as its protocol implementation. LIBP extends the beaconing process widely used by collection protocols with load balancing to improve the USN energy efficiency. Simulation results reveal the relative efficiency of the resulting traffic engineering scheme compared to state of the art protocols. These results show up to 30% reduction in power consumption compared to TinyOS beaconing (TOB), and up to 40% compared to collection tree protocol (CTP) while sustaining better performance in terms of scalability.
Antoine Bagula, Djamel Djenouri, ElMouatez Billah Karbab
PIMRC3