VLDB 2026 Research / reviewers in the wild / expert
Bander Ali Saleh Al-rimy
dblp:216/8508 · also Bander Ali Saleh Al-Rimy
· DBLP profile ↗
8ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0003-3048-5961ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GraphShield: Advanced dynamic graph-based malware detection using graph neural networks
Eslam Amer, Shaker H. Ali El-Sappagh, Tamer Abuhamed, Bander Ali Saleh Al-rimy, Alaa Mohasseb |
Expert Syst. Appl. | 4 |
| 2025 | An Integrated SEM-ANN Approach to Evaluating Cybersecurity Behaviors in the MetaverseabstractThe Metaverse is rapidly transforming virtual interactions, especially in education, but its growth also attracts cyber threats. Without understanding and addressing users’ cybersecurity behaviors, the Metaverse’s full potential is at risk, making investigating these behaviors a pressing necessity. Grounded on the theory of planned behavior (TPB), technology threat avoidance theory (TTAT), and protection motivation theory (PMT), this research develops an integrated theoretical model to evaluate users’ cybersecurity behaviors in the Metaverse. Data were gathered from 701 Metaverse users and were analyzed using a hybrid structural equation modeling-artificial neural network (SEM-ANN) approach. Of the 11 proposed hypotheses, the Partial Least Squares-Structural Equation Modeling results showed that nine were supported, explaining 63.1% of the variance in cybersecurity behavior. The ANN analysis revealed that avoidance motivation and attitude are the most significant factors influencing cybersecurity behavior. In addition to its theoretical contributions, the findings offer actionable insights for various stakeholders. Rawan A. Alsharida, Bander Ali Saleh Al-rimy, Mostafa Al-Emran, Mohammed A. Al-Sharafi, Anazida Zainal |
Int. J. Hum. Comput. Interact. | 2 |
| 2025 | Strengthening ICS defense: Modbus-NFA behavior model for enhanced anomaly detectionabstractThe rise of the Internet of Things (IoT) has significantly transformed Industrial Control Systems (ICS) by increasing their dependence on interconnected devices for automating processes. This growing integration of IoT technologies within ICS has heightened concerns about security and privacy, underscoring the importance of protecting sensitive data. This paper addresses the challenge of detecting anomalies within ICS environments that utilize the Modbus protocol. Modbus requests are encapsulated in Modbus frames, which direct devices on the specific actions to undertake. Thus, the sequence of Modbus frames in network traffic serves as a comprehensive indicator of device behavior on the network. To tackle this challenge, we introduce a novel approach for anomaly detection by modeling device interactions on the network through the analysis of Modbus frame sequences using a Non-deterministic Finite Automaton (NFA) framework, termed the Modbus-NFA Behavior Distinguisher (MNBD) model. The NFA framework is particularly effective for this purpose as it can represent multiple potential states and transitions within a network, thereby capturing the complexity and variability of network behaviors. This capability allows the MNBD model to detect deviations from normal behavior, identifying potential anomalies with high accuracy. Our MNBD model was evaluated against several existing ICS network traffic datasets. The results demonstrate that the Modbus-NFA approach not only surpasses traditional machine learning models but also outperforms sequence-based deep learning models . Additionally, cross-dataset testing reveals that the MNBD model exhibits superior generalization capabilities compared to deep learning-based approaches. These findings highlight the MNBD model’s potential as a robust tool for anomaly detection, advancing research and development efforts in ICS security. Eslam Amer, Bander Ali Saleh Al-rimy, Shaker H. Ali El-Sappagh |
J. Inf. Secur. Appl. | 2 |
| 2021 | Redundancy Coefficient Gradual Up-weighting-based Mutual Information Feature Selection technique for Crypto-ransomware early detection
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, Mamoun Alazab, Syed Zainudeen Mohd Shaid, Fuad A. Ghaleb, Abdulmohsen Almalawi, Abdullah Marish Ali, Tawfik Al Hadhrami |
Future Gener. Comput. Syst. | 1 |
| 2021 | An Adaptive Protection of Flooding Attacks Model for Complex Network EnvironmentsabstractCurrently, online organizational resources and assets are potential targets of several types of attack, the most common being flooding attacks. We consider the Distributed Denial of Service (DDoS) as the most dangerous type of flooding attack that could target those resources. The DDoS attack consumes network available resources such as bandwidth, processing power, and memory, thereby limiting or withholding accessibility to users. The Flash Crowd (FC) is quite similar to the DDoS attack whereby many legitimate users concurrently access a particular service, the number of which results in the denial of service. Researchers have proposed many different models to eliminate the risk of DDoS attacks, but only few efforts have been made to differentiate it from FC flooding as FC flooding also causes the denial of service and usually misleads the detection of the DDoS attacks. In this paper, an adaptive agent-based model, known as an Adaptive Protection of Flooding Attacks (APFA) model, is proposed to protect the Network Application Layer (NAL) against DDoS flooding attacks and FC flooding traffics. The APFA model, with the aid of an adaptive analyst agent, distinguishes between DDoS and FC abnormal traffics. It then separates DDoS botnet from Demons and Zombies to apply suitable attack handling methodology. There are three parameters on which the agent relies, normal traffic intensity, traffic attack behavior, and IP address history log, to decide on the operation of two traffic filters. We test and evaluate the APFA model via a simulation system using CIDDS as a standard dataset. The model successfully adapts to the simulated attack scenarios’ changes and determines 303,024 request conditions for the tested 135,583 IP addresses. It achieves an accuracy of 0.9964, a precision of 0.9962, and a sensitivity of 0.9996, and outperforms three tested similar models. In addition, the APFA model contributes to identifying and handling the actual trigger of DDoS attack and differentiates it from FC flooding, which is rarely implemented in one model. Bashar Ahmed Khalaf, Salama A. Mostafa, Aida Mustapha, Mazin Abed Mohammed, Moamin A. Mahmoud, Bander Ali Saleh Al-rimy, Shukor Abd Razak, Mohamed Elhoseny, Adam Marks |
Secur. Commun. Networks | 6 |
| 2020 | A system call refinement-based enhanced Minimum Redundancy Maximum Relevance method for ransomware early detection
Yahye Abukar Ahmed, Baris Koçer, Md. Shamsul Huda, Bander Ali Saleh Al-rimy, Mohammad Mehedi Hassan |
J. Netw. Comput. Appl. | 4 |
| 2019 | Crypto-ransomware early detection model using novel incremental bagging with enhanced semi-random subspace selection
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, Syed Zainudeen Mohd Shaid |
Future Gener. Comput. Syst. | 1 |
| 2018 | Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, Syed Zainudeen Mohd Shaid |
Comput. Secur. | 1 |