Marwa Keshk

dblp:203/1362 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0001-5749-0408ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 PLLM-CS: Pre-trained Large Language Model (LLM) for cyber threat detection in satellite networks
Mohammed Hassanin, Marwa Keshk, Sara Salim, Majid Alsubaie
Ad Hoc Networks2
2025 A context-aware zero trust-based hybrid approach to IoT-based self-driving vehicles security
Izhar Ahmed Khan, Marwa Keshk, Yasir Hussain, Dechang Pi, Bentian Li, Tanzeela Kousar, Bakht Sher Ali
Ad Hoc Networks2
2025 Vulnerability defence using hybrid moving target defence in Internet of Things systems
abstract
Cyber threat actors are increasingly targeting networked assets and critical infrastructure, with the potential for major socioeconomic impacts. Moving target defence (MTD) is a cyber defence paradigm that creates constantly shifting attack surfaces (i.e., vulnerabilities). It intends to make it more difficult for cyber adversaries to exploit systems, thereby increasing costs and chances of detection. There is a lack of research into the efficiency of combined MTD techniques, especially regarding several types of security considerations like time, cost, and effort. This gap is particularly significant in the Internet of Things (IoT) context, where security problems arise from its heterogeneous architecture . Moreover, MTD may result in the overutilization of network and system resources to enhance cybersecurity. We present a Vulnerability Defence method to address this issue using the three-layer Temporal Hierarchical Attack Representation Model (3-layer-THARM). This approach overcomes this difficulty by evaluating the safety of aggregated network states, considering security metrics in each state and the accessibility of network nodes and edges. Using this model, we can recognize probable attack scenarios in the context of Internet of Things (IoT) systems, conduct a thorough security analysis of the IoT system using well-defined security metrics, and assess the effectiveness of various defence tactics. This feature inherently introduces an additional level of security for the system. Furthermore, this model showcases the ability to identify potential attack pathways and effectively mitigate the consequences of such attacks. Our analysis reveals a noteworthy trend: combining MTD techniques from different categories, such as shuffle and diversity, generally produces more favorable outcomes, including a lower probability of attack success, lower attack risk and higher attack cost.
Mohammed Tanvir Masud, Marwa Keshk, Nour Moustafa, Benjamin P. Turnbull, Willy Susilo
Comput. Secur.2
2025 Cybersecurity Solutions and Techniques for Internet of Things Integration in Combat Systems
abstract
The Internet of Things (IoT) has enabled pervasive networking and multi-modal sensing, offering various services such as remote operations and augmenting existing processes. The military setting has increasingly and notably adopted IoT technologies, such as sensor-rich drones or autonomous vehicles, which provide military personnel with enhanced situational awareness, faster decision-making capabilities, and improved operational precision. However, integrating IoT into military systems introduces new security challenges due to increased connectivity and susceptibility to vulnerabilities. Cyberattacks on military IoT systems can have severe consequences, including operational disruptions and compromises of sensitive information. This article proposes a new perspective on examining threat models in IoT-enhanced combat systems, emphasising approaches for identifying threats, conducting vulnerability assessments, and suggesting countermeasures. It delves into the characteristics and structures of IoT-enhanced combat systems, exploring technical implementations and technologies. Additionally, it outlines five significant areas of focus, including blockchain, machine learning, game theory, protocols, and algorithms, to enhance understanding of IoT-enhanced combat systems. The insights gained from this analysis can inform the development of secure and resilient military IoT systems, ultimately enhancing the safety and effectiveness of military operations.
Amirmohammad Pasdar, Nickolaos Koroniotis, Marwa Keshk, Nour Moustafa, Zahir Tari
IEEE Trans. Sustain. Comput.3
2023 An explainable deep learning-enabled intrusion detection framework in IoT networks
abstract
Although the field of eXplainable Artificial Intelligence (XAI) has a significant interest these days, its implementation within cyber security applications still needs further investigation to understand its effectiveness in discovering attack surfaces and vectors. In cyber defence, especially anomaly-based Intrusion Detection Systems (IDS), the emerging applications of machine/deep learning models require the interpretation of the models' architecture and the explanation of models' prediction to examine how cyberattacks would occur. This paper proposes a novel explainable intrusion detection framework in the Internet of Things (IoT) networks. We have developed an IDS using a Short-Term Long Memory (LSTM) model to identify cyberattacks and explain the model's decisions. This uses a novel set of input features extracted by a novel SPIP (S: Shapley Additive exPlanations, P: Permutation Feature Importance, I: Individual Conditional Expectation, P: Partial Dependence Plot) framework to train and evaluate the LSTM model. The framework was validated using the NSL-KDD, UNSW-NB15 and TON_IoT datasets. The SPIP framework achieved high detection accuracy, processing time, and high interpretability of data features and model outputs compared with other peer techniques. The proposed framework has the potential to assist administrators and decision-makers in understanding complex attack behaviour.
Marwa Keshk, Nickolaos Koroniotis, Nam Pham, Nour Moustafa, Benjamin P. Turnbull, Albert Y. Zomaya
Inf. Sci.1
2022 Enhancing IIoT networks protection: A robust security model for attack detection in Internet Industrial Control Systems
Izhar Ahmed Khan, Marwa Keshk, Dechang Pi, Nasrullah Khan, Yasir Hussain, Hatem Soliman
Ad Hoc Networks2
2022 Privacy-preserving big data analytics for cyber-physical systems
Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull
Wirel. Networks1
2021 DAD: A Distributed Anomaly Detection system using ensemble one-class statistical learning in edge networks
Nour Moustafa, Marwa Keshk, Kim-Kwang Raymond Choo, Timothy Lynar, Seyit Ahmet Çamtepe, Monica T. Whitty
Future Gener. Comput. Syst.2
2021 An Integrated Framework for Privacy-Preserving Based Anomaly Detection for Cyber-Physical Systems
abstract
Protecting Cyber-physical Systems (CPSs) is highly important for preserving sensitive information and detecting cyber threats. Developing a robust privacy-preserving anomaly detection method requires physical and network data about the systems, such as Supervisory Control and Data Acquisition (SCADA), for protecting original data and recognising cyber-attacks. In this paper, a new privacy-preserving anomaly detection framework, so-called PPAD-CPS, is proposed for protecting confidential information and discovering malicious observations in power systems and their network traffic. The framework involves two main modules. First, a data pre-processing module is suggested for filtering and transforming original data into a new format that achieves the target of privacy preservation. Second, an anomaly detection module is suggested using a Gaussian Mixture Model (GMM) and Kalman Filter (KF) for precisely estimating the posterior probabilities of legitimate and anomalous events. The performance of the PPAD-CPS framework is assessed using two public datasets, namely the Power System and UNSW-NB15 dataset. The experimental results show that the framework is more effective than four recent techniques for obtaining high privacy levels. Moreover, the framework outperforms seven peer anomaly detection techniques in terms of detection rate, false positive rate, and computational time.
Marwa Keshk, Elena Sitnikova, Nour Moustafa, Jiankun Hu, Ibrahim Khalil 0001
IEEE Trans. Sustain. Comput.1
2020 Privacy-Preserving Techniques for Protecting Large-Scale Data of Cyber-Physical Systems
abstract
As Cyber-Physical Systems (CPSs), such as power and gas networks, generate heterogeneous and large-scale data sources from devices and networks, they need efficient privacy-preserving techniques to protect data and systems from cyber attacks. To safeguard CPSs from potential cyber threats, it is vital to identify vulnerabilities of CPSs' components to prevent Advanced Persistent Threats (APTs) and protect their generated data using privacy-preserving techniques. This paper aims to review the current state of privacy-preserving techniques for protecting CPSs and their networks against cyber attacks. Concepts of Privacy preservation and CPSs are discussed, illustrating CPSs' components and how they could be hacked using cyber and physical hacking scenarios. Then, types of privacy preservation, including perturbation, authentication, machine learning (ML), cryptography and blockchain, are discussed to demonstrate how they would be applied to protect the original data in CPSs and their networks. Finally, we explain existing challenges, solutions and future research directions of privacy preservation in CPSs.
Marwa Keshk, Nour Moustafa, Elena Sitnikova, Benjamin P. Turnbull, Dinusha Vatsalan
MSN1
2020 Federated TON_IoT Windows Datasets for Evaluating AI-based Security Applications
abstract
Existing cyber security solutions have been basically developed using knowledge-based models that often cannot trigger new cyber-attack families. With the boom of Artificial Intelligence (AI), especially Deep Learning (DL) algorithms, those security solutions have been plugged-in with AI models to discover, trace, mitigate or respond to incidents of new security events. The algorithms demand a large number of heterogeneous data sources to train and validate new security systems. This paper presents the description of new datasets, the so-called ToN_IoT, which involve federated data sources collected from Telemetry datasets of IoT services, Operating system datasets of Windows and Linux, and datasets of Network traffic. The paper introduces the testbed and description of TON_IoT datasets for Windows operating systems. The testbed was implemented in three layers: edge, fog and cloud. The edge layer involves IoT and network devices, the fog layer contains virtual machines and gateways, and the cloud layer involves cloud services, such as data analytics, linked to the other two layers. These layers were dynamically managed using the platforms of software-Defined Network (SDN) and Network-Function Virtualization (NFV) using the VMware NSX and vCloud NFV platform. The Windows datasets were collected from audit traces of memories, processors, networks, processes and hard disks. The datasets would be used to evaluate various AI-based cyber security solutions, including intrusion detection, threat intelligence and hunting, privacy preservation and digital forensics. This is because the datasets have a wide range of recent normal and attack features and observations, as well as authentic ground truth events. The datasets can be publicly accessed from this link [1].
Nour Moustafa, Marwa Keshk, Essam Soliman Debie, Helge Janicke
TrustCom2
2020 FGMC-HADS: Fuzzy Gaussian mixture-based correntropy models for detecting zero-day attacks from linux systems
Waqas Haider, Nour Moustafa, Marwa Keshk, Amanda S. Fernandez, Kim-Kwang Raymond Choo
Comput. Secur.3
2020 A Privacy-Preserving-Framework-Based Blockchain and Deep Learning for Protecting Smart Power Networks
abstract
Modern power systems depend on cyber-physical systems to link physical devices and control technologies. A major concern in the implementation of smart power networks is to minimize the risk of data privacy violation (e.g., by adversaries using data poisoning and inference attacks). In this article, we propose a privacy-preserving framework to achieve both privacy and security in smart power networks. The framework includes two main modules: a two-level privacy module and an anomaly detection module. In the two-level privacy module, an enhanced-proof-of-work-technique-based blockchain is designed to verify data integrity and mitigate data poisoning attacks, and a variational autoencoder is simultaneously applied for transforming data into an encoded format for preventing inference attacks. In the anomaly detection module, a long short-term memory deep learning technique is used for training and validating the outputs of the two-level privacy module using two public datasets. The results highlight that the proposed framework can efficiently protect data of smart power networks and discover abnormal behaviors, in comparison to several state-of-the-art techniques.
Marwa Keshk, Benjamin P. Turnbull, Nour Moustafa, Dinusha Vatsalan, Kim-Kwang Raymond Choo
IEEE Trans. Ind. Informatics1