Ali A. Elghariani

dblp:224/0272 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0002-4307-4021ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-authorSecurity and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2023 PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber Networks
abstract
The increase in scale of cyber networks and the rise in sophistication of cyber-attacks have introduced several challenges in intrusion detection. The primary challenge is the requirement to detect complex multi-stage attacks in realtime by processing the immense amount of traffic produced by present-day networks. In this paper we present PRISM, a hierarchical intrusion detection architecture that uses a novel attacker behavior model-based sampling technique to minimize the realtime traffic processing overhead. PRISM has a unique multi-layered architecture that monitors network traffic distributedly to provide efficiency in processing and modularity in design. PRISM employs a Hidden Markov Model-based prediction mechanism to identify multi-stage attacks and ascertain the attack progression for a proactive response. Furthermore, PRISM introduces a stream management procedure that rectifies the issue of alert reordering when collected from distributed alert reporting systems. To evaluate the performance of PRISM, multiple metrics have been proposed, and various experiments have been conducted on multi-stage attack datasets. The results exhibit up to 7.5x improvement in processing overhead as compared to a standard centralized IDS without the loss of prediction accuracy while demonstrating the ability to predict different attack stages promptly.
Yahya Javed, Mosab Khayat, Ali A. Elghariani, Arif Ghafoor
IEEE Trans. Dependable Secur. Comput.3
2021 Architectures for Detecting Interleaved Multi-Stage Network Attacks Using Hidden Markov Models
abstract
With the growing amount of cyber threats, the need for development of high-assurance cyber systems is becoming increasingly important. The objective of this article is to address the challenges of modeling and detecting sophisticated network attacks, such as multiple interleaved attacks. We present the interleaving concept and investigate how interleaving multiple attacks can deceive intrusion detection systems. Using one of the important statistical machine learning (ML) techniques, Hidden Markov Models (HMM), we develop two architectures that take into account the stealth nature of the interleaving attacks, and that can detect and track the progress of these attacks. These architectures deploy a database of HMM templates of known attacks and exhibit varying performance and complexity. For performance evaluation, in the presence of multiple multi-stage attack scenarios, various metrics are proposed which include (1) attack risk probability, (2) detection error rate, and (3) the number of correctly detected stages. Extensive simulation experiments are used to demonstrate the efficacy of the proposed architectures.
Tawfeeq A. Shawly, Ali A. Elghariani, Jason Kobes, Arif Ghafoor
IEEE Trans. Dependable Secur. Comput.2
2019 On the Information Freshness and Tail Latency Trade-Off in Mobile Networks
abstract
With the advent of emerging mission-critical applications, sampling information updates and scheduling mobile traffic in a timely manner are very challenging. In addition, maintaining fresh information and low latency communication is important to these applications. To that end, in this paper, we first derive closed form expressions for an upper bound on the latency tail probability (LTP) and the average age of information (AoI) in M/G/1 systems, where shifted exponential service time is considered. Different from the majority of existing work in this domain, our analysis is derived under different update size assumption with different priority levels. Next, we have developed novel policies for sampling and scheduling the information updates over the choice of one of the parallel links, e.g., WiFi and LTE links. Then, a joint minimization of AoI and LTP is formulated and efficient algorithms are provided. Our evaluation results show that our proposed approaches outperform the state-of-the-art algorithms and some competitive baselines.
Abubakr O. Al-Abbasi, Ali A. Elghariani, Anis Elgabli, Vaneet Aggarwal
GLOBECOM2
2019 A Proximal Jacobian ADMM Approach for Fast Massive MIMO Signal Detection in Low-Latency Communications
abstract
One of the 5G promises is to provide Ultra Reliable Low Latency Communications (URLLC) which targets an end to end communication latency that is <; 1ms. The very low latency requirement of URLLC entails a lot of work in all networking layers. In this paper, we focus on the physical layer, and in particular, we propose a novel formulation of the massive MIMO uplink detection problem. We introduce an objective function that is a sum of strictly convex and separable functions based on decomposing the received vector into multiple vectors. Each vector represents the contribution of one of the transmitted symbols in the received vector. Proximal Jacobian Alternating Direction Method of Multipliers (PJADMM) is used to solve the new formulated problem in an iterative manner where at every iteration all variables are updated in parallel and in a closed form expression. The proposed algorithm provides a lower complexity and much faster processing time compared to the conventional MMSE detection technique and other iterative-based techniques, especially when the number of single antenna users is close to the number of base station (BS) antennas. This improvement is obtained without any matrix inversion. Simulation results demonstrate the efficacy of the proposed algorithm in reducing detection processing time in the multi-user uplink massive MIMO setting.
Anis Elgabli, Ali A. Elghariani, Vaneet Aggarwal, Mehdi Bennis, Mark R. Bell
ICC2
2018 QoE-Aware Resource Allocation for Small Cells
abstract
In this paper, we study the problem of Quality of Experience (QoE) aware resource allocation in wireless systems. In particular, we consider application-aware joint Bandwidth-Power allocation for a small cell. We optimize a QoE metric for multi-user video streaming in a small cell that maintains a trade-off between maximizing the playback rate of each user and ensuring proportional fairness (PF) among users. We formulate the application-driven joint bandwidth-power allocation as a non-convex optimization problem. However, we develop a polynomial complexity algorithm, and we show that the proposed algorithm achieves the optimal solution of the proposed optimization problem. Simulation results show that the proposed QoE-aware algorithm significantly improves the average QoE. Moreover, it outperforms the weighted sum rate allocation which is the state-of-the-art physical resource allocation scheme.
Anis Elgabli, Ali A. Elghariani, Vaneet Aggarwal, Mark R. Bell
GLOBECOM2
2016 Low Complexity Detection Algorithms in Large-Scale MIMO Systems
abstract
In this contribution, we present low-complexity detection algorithms in large-scale MIMO systems where they achieve significantly better bit error rate (BER) performance than known heuristic algorithms in large-scale MIMO literature, such as local ascent search (LAS) and reactive tabu search (RTS) algorithms, especially at higher-order modulations. The proposed techniques are developed from the conventional quadratic programming (QP) detector. The first one is based on performing two stages of a QP detector with a novel combination of both interference cancellation and shadow area constraints of the constellation. The second one is based on the branch and bound search tree algorithm. The efficacy of the proposed algorithms is investigated at various QAM modulations. Computer simulations show that the proposed algorithms outperform LAS and RTS algorithms in both uncoded and turbo coded BER performance, especially at higher QAM levels, with no significant change in complexity as the modulation level increases. Also, an extension of the QP detector for iterative detection and decoding is developed for the case of QPSK using a low complexity approach.
Ali A. Elghariani, Michael D. Zoltowski
IEEE Trans. Wirel. Commun.1
2015 A quadratic programming-based detector for large-scale MIMO systems
abstract
In this contribution, we present a low complexity detection algorithm that is based on a quadratic programming (QP) formulation. It provides better trade-offs between complexity and performance, especially in large-scale MIMO systems. It also achieves better bit error rate (BER) performance than known heuristic algorithms in large-scale MIMO literature, such as Local Ascent Search and Reactive Tabu Search algorithms, especially at higher-order modulations. This algorithm improves the performance of the conventional QP detectors using two stages of QP with the concept of interference cancellation and also with the concept of shadow area constraints as a measure of symbols reliability. Thus, we call it a Two-stage quadratic programming detector. Computer simulations demonstrate the efficacy of the proposed algorithm in large-scale MIMO systems for both uncoded and turbo coded cases.
Ali A. Elghariani, Michael D. Zoltowski
WCNC1