Arash Mahboubi

dblp:212/1529 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-0487-0615ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Setup Once, Secure Always: A Single-Setup Secure Federated Learning Aggregation Protocol with Forward and Backward Secrecy for Dynamic Users
abstract
Federated Learning (FL) enables multiple users to collaboratively train a machine learning model without sharing raw data, making it suitable for privacy-sensitive applications. However, local model or weight updates can still leak sensitive information. Secure aggregation protocols mitigate this risk by ensuring that only the aggregated updates are revealed. Among these, single-setup secure aggregation protocols, where key generation and exchange occur only once, are the most efficient due to reduced communication and computation overhead. However, existing single-setup secure aggregation protocols often lack support for dynamic user participation and do not provide strong privacy guarantees such as forward and backward secrecy.
Nazatul Haque Sultan, Yan Bo, Yansong Gao 0001, Seyit Ahmet Çamtepe, Arash Mahboubi, Hang Thanh Bui, Muhammad Aufeef Chauhan, Hamed Aboutorab, Michael Bewong, Praveen Gauravaram, Dinesh Kumar Singh, Md. Rafiqul Islam 0001, Alsharif Abuadbba
AsiaCCS5
2025 Ransomware Encryption Detection: Adaptive File System Analysis Against Evasive Encryption Tactics
Arash Mahboubi, Hamed Aboutorab, Seyit Ahmet Çamtepe, Hang Thanh Bui, Khanh Luong, Keyvan Ansari, Shenlu Wang, Bazara I. A. Barry
ACISP (3)1
2025 Multi-Stage Payload Execution with Fragmented Double-Layer Encoding
abstract
This study provides a comprehensive examination of AtomBombing, a stealthy fileless code injection technique that leverages the Windows Global Atom Table for covert payload storage and execution. Unlike traditional injection strategies that rely on memory manipulation or file-based artifacts, AtomBombing avoids direct memory writes and operates entirely through legitimate Windows APIs, making it exceptionally evasive against modern endpoint detection and response tools. Through our proof-of-concept (PoCs) implementations, we demonstrate how adversaries could exploit atom-based payload fragmentation, double layer encoding, and time-based triggers to execute malicious tasks while minimizing forensic visibility. Building on those PoCs, we introduce ABOMB-FOD, a $\mathbf{1. 2 ~ M B}$ multistage loader that survives reboots, bypasses user account controls, and still fits comfortably within the Atom Table capacity limits ($\leq$ 65,535 entries $+\mathbf{2 5 5} \mathbf{B} \approx \mathbf{1 6} \mathbf{~ M B}$). The AtomBombing Process Orchestrator illustrates the ability to securely store encrypted payloads and orchestrate parallel execution using PowerShell, while the Atom Table Backdoor showcases persistent command-and-control behavior activated under specific system conditions. Our findings underscore the inadequacy of current security solutions in monitoring Atom Table interactions, i.e., critical API functions remain largely overlooked in behavioral analysis, despite their potential for stealthy data injection. Consistent with this blind spot, our evaluation confirms that standard defenses, including Windows Defender with cloud protection enabled, fail to detect or flag AtomBombing activity, even when ABOMBFOD or other payloads are executing and network interactions are in progress. We note that a straightforward heuristic, such as flagging any process that issues more than a certain number of GlobalAddAtomW invocations (e.g., 500) within a short time window (e.g., one minute) and stores high-entropy data, can be effective in identifying candidates for further investigation.
Arash Mahboubi, Keyvan Ansari, Seyit Ahmet Çamtepe
AICCSA1
2025 Social Engineering Attacks: A Systemisation of Knowledge on People Against Humans
Scott Thomson, Michael Bewong, Arash Mahboubi, Tanveer A. Zia
IEEE Big Data3
2025 ConceptUML: Multiphase unsupervised threat detection via latent concept learning, Hidden Markov Models and topic modelling
abstract
Detecting lateral movement threats in large-scale system logs is a critical challenge due to the scarcity of labelled attack data, the presence of imbalanced datasets, and the sophisticated nature of modern adversaries. To address these issues, we propose ConceptUML , a semantic-driven, fully unsupervised threat detection framework designed to automatically identify anomalies related to lateral movement in heterogeneous log data. ConceptUML is structured around a three-phase architecture. In Phase 1 (Latent Semantic Learning) , contextualized embeddings generated by Sentence-BERT are combined with Non-negative Matrix Factorization to extract abstract concepts from system logs and external threat intelligence sources such as MITRE ATT&CK and CAPEC. In Phase 2 (Unsupervised Threat Detection) , a Hidden Markov Model is applied to cluster logs based on learned concepts, and each cluster is scored according to its semantic similarity to known adversarial techniques. Phase 3 (Decision Refinement) uses topic modelling to further isolate malicious event log subsets from within suspicious clusters, enabling high-precision triage. We evaluate ConceptUML using four real-world event log datasets, including Windows Event Logs and multiple subsets of the LMD-23 dataset, encompassing attacks such as exploitation of hashing techniques and remote services. The enhanced model with topic modelling achieves up to 92.54% detection quality and reduces detection error to as low as 8.14%, outperforming several baseline approaches including AutoEncoder, LogAnomaly, LOF, and DBScan. Our results confirm that ConceptUML delivers interpretable, scalable, and highly effective detection of lateral movement threats without requiring labelled training data or extensive manual feature engineering.
Khanh Luong, Arash Mahboubi, Geoff Jarrad, Seyit Ahmet Çamtepe, Michael Bewong, Mohammed Bahutair, Hamed Aboutorab, Hang Thanh Bui
J. Inf. Secur. Appl.2
2025 Lurking in the shadows: Unsupervised decoding of beaconing communication for enhanced cyber threat hunting
abstract
The escalating prevalence of Advanced Persistent Threats (APTs) necessitates the development of more robust solutions capable of effectively thwarting these attacks by monitoring system activities across individual hosts. Existing cloud-native security applications utilize a combination of rule-based and machine learning-based detection techniques to protect digital assets . However, these approaches have limitations. Rule-based detection depends on predefined rules to identify specific attack patterns. Persistent attackers can often evade detection by carefully ensuring that their behavior circumvents these rules. In contrast, machine learning-based detection techniques, which learn attack patterns from data, rely heavily on the availability of labeled data for training. However, labeled data is often unavailable and can be labor-intensive and costly to obtain. In this paper, we address the challenge of detecting APT attacks more holistically by leveraging attackers’ behavior during communication with Command and Control (C2) servers, a critical phase observed in most APT attacks. We aim to reduce false positive alerts for threat hunters by analyzing system network logs to detect potential network beaconing, a common attribute of various malware . We introduce a novel hybrid approach, called NetSpectra Sentinel , which employs a Continuous Time Hidden Markov Model (CT-HMM) to detect hidden states underlying observed patterns within the network logs and Time Series Decomposition (TSD) to model temporal patterns. We evaluate the effectiveness of our approach using 14 benchmark datasets and one synthetic dataset , comparing our method with other state-of-the-art statistical-based and botnet detection techniques. The results demonstrate that our technique achieves significantly higher accuracy in most cases, and even when existing techniques fail, our approach can still detect beaconing post-initial compromise with up to 90% accuracy. Additionally, we achieve up to four times better performance in terms of precision compared to existing statistical-based techniques.
Arash Mahboubi, Khanh Luong, Geoff Jarrad, Seyit Ahmet Çamtepe, Michael Bewong, Mohammed Bahutair, Ganna Pogrebna
J. Netw. Comput. Appl.1
2024 A Graph-Based Approach for Software Functionality Classification on the Web
Yinhao Jiang, Michael Bewong, Arash Mahboubi, Sajal Halder, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, Praveen Gauravaram, Minhui Xue 0001
WISE (5)3
2024 A Lightweight Detection of Sequential Patterns in File System Events During Ransomware Attacks
Arash Mahboubi, Hang Thanh Bui, Hamed Aboutorab, Khanh Luong, Seyit Ahmet Çamtepe, Keyvan Ansari
WISE (5)1
2024 Malicious Package Detection using Metadata Information
abstract
Protecting software supply chains from malicious packages is paramount in the evolving landscape of software development. Attacks on the software supply chain involve attackers injecting harmful software into commonly used packages or libraries in a software repository. For instance, JavaScript uses Node Package Manager (NPM), and Python uses Python Package Index (PyPi) as their respective package repositories. In the past, NPM has had vulnerabilities such as the event-stream incident, where a malicious package was introduced into a popular NPM package, potentially impacting a wide range of projects. As the integration of third-party packages becomes increasingly ubiquitous in modern software development, accelerating the creation and deployment of applications, the need for a robust detection mechanism has become critical. On the other hand, due to the sheer volume of new packages being released daily, the task of identifying malicious packages presents a significant challenge. To address this issue, in this paper, we introduce a metadata-based malicious package detection model, MeMPtec. This model extracts a set of features from package metadata information. These extracted features are classified as either easy-to-manipulate (ETM) or difficult-to-manipulate (DTM) features based on monotonicity and restricted control properties. By utilising these metadata features, not only do we improve the effectiveness of detecting malicious packages, but also we demonstrate its resistance to adversarial attacks in comparison with existing state-of-the-art. Our experiments indicate a significant reduction in both false positives (up to 97.56%) and false negatives (up to 91.86%).
Sajal Halder, Michael Bewong, Arash Mahboubi, Yinhao Jiang, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, M. Ejaz Ahmed, Gowri Sankar Ramachandran, Muhammad Ali Babar 0001
WWW3
2024 Agriculture 4.0 and beyond: Evaluating cyber threat intelligence sources and techniques in smart farming ecosystems
abstract
The digitisation of agriculture, integral to Agriculture 4.0, has brought significant benefits while simultaneously escalating cybersecurity risks. With the rapid adoption of smart farming technologies and infrastructure, the agricultural sector has become an attractive target for cyberattacks. This paper presents a systematic literature review that assesses the applicability of existing cyber threat intelligence (CTI) techniques within smart farming infrastructures (SFIs). We develop a comprehensive taxonomy of CTI techniques and sources, specifically tailored to the SFI context, addressing the unique cyber threat challenges in this domain. A crucial finding of our review is the identified need for a virtual Chief Information Security Officer (vCISO) in smart agriculture. While the concept of a vCISO is not yet established in the agricultural sector, our study highlights its potential significance. The implementation of a vCISO could play a pivotal role in enhancing cybersecurity measures by offering strategic guidance, developing robust security protocols, and facilitating real-time threat analysis and response strategies. This approach is critical for safeguarding the food supply chain against the evolving landscape of cyber threats. Our research underscores the importance of integrating a vCISO framework into smart farming practices as a vital step towards strengthening cybersecurity. This is essential for protecting the agriculture sector in the era of digital transformation, ensuring the resilience and sustainability of the food supply chain against emerging cyber risks.
Hang Thanh Bui, Hamed Aboutorab, Arash Mahboubi, Yansong Gao 0001, Nazatul Haque Sultan, Muhammad Aufeef Chauhan, Mohammad Zavid Parvez, Michael Bewong, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Seyit Ahmet Çamtepe, Praveen Gauravaram, Dinesh Kumar Singh, Muhammad Ali Babar 0001, Shihao Yan
Comput. Secur.3
2024 Shared file protection against unauthorised encryption using a Buffer-Based Signature Verification Method
abstract
Understanding the attributes of critical data and implementing suitable security measures help organisations bolster their data-protection strategies and diminish the potential impacts of ransomware incidents. Unauthorised extraction and acquisition of data are the principal objectives of most cyber invasions. We underscore the severity of this issue using a recent attack by the Clop ransomware group, which exploited the MOVEit Transfer vulnerability and bypassed network-detection mechanisms to exfiltrate data via a Command and Control server. As a countermeasure, we propose a method called Buffer-Based Signature Verification (BBSV). This approach involves embedding 32-byte tags into files prior to their storage in the cloud, thus offering enhanced data protection. The BBSV method can be integrated into software like MOVEit Secure Managed File Transfer, thereby thwarting attempts by ransomware to exfiltrate data. Empirically tested using a BBSV prototype, our approach was able to successfully halt the encryption process for 80 ransomware instances from 70 ransomware families. BBSV not only stops the encryption but also prevents data exfiltration when data are moved or written from the original location by adversaries. We further develop a hypothetical exploit scenario in which an adversary manages to bypass the BBSV, illicitly transmits data to a Command and Control server, and then removes files from the original location. We construct an extended state space, in which each state represents a tuple that integrates user authentication and system components at the filesystem level.
Arash Mahboubi, Seyit Ahmet Çamtepe, Keyvan Ansari, Marcin Piotr Pawlowski, Pawel Morawiecki, Hamed Aboutorab, Josef Pieprzyk, Jaroslaw Duda 0001
J. Inf. Secur. Appl.1
2024 Evolving techniques in cyber threat hunting: A systematic review
abstract
In the rapidly changing cybersecurity landscape, threat hunting has become a critical proactive defense against sophisticated cyber threats. While traditional security measures are essential, their reactive nature often falls short in countering malicious actors’ increasingly advanced tactics. This paper explores the crucial role of threat hunting, a systematic, analyst-driven process aimed at uncovering hidden threats lurking within an organization's digital infrastructure before they escalate into major incidents. Despite its importance, the cybersecurity community grapples with several challenges, including the lack of standardized methodologies, the need for specialized expertise, and the integration of cutting-edge technologies like artificial intelligence (AI) for predictive threat identification. To tackle these challenges, this survey paper offers a comprehensive overview of current threat hunting practices, emphasizing the integration of AI-driven models for proactive threat prediction. Our research explores critical questions regarding the effectiveness of various threat hunting processes and the incorporation of advanced techniques such as augmented methodologies and machine learning. Our approach involves a systematic review of existing practices, including frameworks from industry leaders like IBM and CrowdStrike. We also explore resources for intelligence ontologies and automation tools. The background section clarifies the distinction between threat hunting and anomaly detection, emphasizing systematic processes crucial for effective threat hunting. We formulate hypotheses based on hidden states and observations, examine the interplay between anomaly detection and threat hunting, and introduce iterative detection methodologies and playbooks for enhanced threat detection. Our review encompasses supervised and unsupervised machine learning approaches, reasoning techniques, graph-based and rule-based methods, as well as other innovative strategies. We identify key challenges in the field, including the scarcity of labeled data, imbalanced datasets, the need for integrating multiple data sources, the rapid evolution of adversarial techniques, and the limited availability of human expertise and data intelligence. The discussion highlights the transformative impact of artificial intelligence on both threat hunting and cybercrime, reinforcing the importance of robust hypothesis development. This paper contributes a detailed analysis of the current state and future directions of threat hunting, offering actionable insights for researchers and practitioners to enhance threat detection and mitigation strategies in the ever-evolving cybersecurity landscape.
Arash Mahboubi, Khanh Luong, Hamed Aboutorab, Hang Thanh Bui, Geoff Jarrad, Mohammed Bahutair, Seyit Ahmet Çamtepe, Ganna Pogrebna, Bazara I. A. Barry, Hannah Gately
J. Netw. Comput. Appl.1
2021 Compcrypt-Lightweight ANS-Based Compression and Encryption
abstract
Compression is widely used in Internet applications to save communication time, bandwidth and storage. Recently invented by Jarek Duda asymmetric numeral system (ANS) offers an improved efficiency and a close to optimal compression. The ANS algorithm has been deployed by major IT companies such as Facebook, Google and Apple. Compression by itself does not provide any security (such as confidentiality or authentication of transmitted data). An obvious solution to this problem is an encryption of compressed bitstream. However, it requires two algorithms: one for compression and the other for encryption. In this work, we investigate natural properties of ANS that allow to incorporate authenticated encryption using as little cryptography as possible. We target low-level security communication and storage such as transmission of data from IoT devices/sensors. In particular, we propose three solutions for joint compression and encryption (compcrypt). The solutions offer different tradeoffs between security and efficiency assuming a slight compression deterioration. All of them use a pseudorandom bit generator (PRBG) based on lightweight stream ciphers. The first solution is close to original ANS and applies state jumps controlled by PRBG. The second one employs two copies of ANS, where compression is switched between the copies. The switch is controlled by a PRBG bit. The third compcrypt modifies the encoding function of ANS depending on PRBG bits. Security and efficiency of the proposed compcrypt algorithms are evaluated. The first compcrypt is the most efficient with a slight loss of compression quality. The second one consumes more storage but the loss of compression quality is negligible. The last compcrypt offers the best security but is the least efficient.
Seyit Ahmet Çamtepe, Jaroslaw Duda 0001, Arash Mahboubi, Pawel Morawiecki, Surya Nepal, Marcin Piotr Pawlowski, Josef Pieprzyk
IEEE Trans. Inf. Forensics Secur.3