VLDB 2026 Research / reviewers in the wild / expert
Abdulrahman Abu Elkhail
dblp:234/3762
· DBLP profile ↗
8ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-6199-6468ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Sniper: Countering Locker Ransomware Attacks Through Natural Language ProcessingabstractMobile systems have evolved into versatile devices that end users depend on for carrying out their daily tasks. Unfortunately, the mobile sector has recently fallen prey to a series of ransomware campaigns designed to lock users out of their devices and extort them for payment. In response to these challenges, we propose a novel runtime system that dynamically restores device access by undoing the effects of locker ransomware. A key observation made by this work is that attackers rely on the display of a ransom note on the victim’s device to demand payment. Based on this observation, we develop a solution that combines the monitoring of mobile app activity with a natural language processing (NLP) unit that harnesses transformers to detect the appearance of ransom notes. We extensively validate the robustness of our solution against more than five thousand ransomware samples and show that our solution reliably recovers from all the malicious samples that we tested, including overlay screen and change pin-code ransomware. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of mobile benchmark applications. Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Seamlessly Safeguarding Data Against Ransomware AttacksabstractEncryption has become an indispensable technology for preserving confidentiality. Unfortunately, cybercriminals have re-purposed this technology to deny users access to their data. This trend has sparked an onslaught of ransomware attacks, that resulted in several victims being extorted to pay ransoms in return for restoring their maliciously encrypted data. In response to these challenges, we propose a novel runtime solution that seamlessly defends against cryptographic ransomware. A key observation made by this work is that maliciously encrypted data is initially buffered in the OS's page cache before it is flushed to the underlying storage device. Based on this observation, we develop a solution that efficiently manages data synchronization between the memory and storage subsystems to prevent maliciously encrypted data from being permanently committed to the underlying storage. We extensively validate the robustness of this approach against more than one thousand ransomware samples and show that our design reliably restores all encrypted files. Furthermore, our solution is resilient to ransomware that employ techniques including master boot record infection and multi-threaded attacks. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of compute and I/O bound applications. Abdulrahman Abu Elkhail, Nada Lachtar, Duha Ibdah, Rustam Aslam, Anys Bacha, Hafiz Malik |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | An Application Agnostic Defense Against the Dark Arts of CryptojackingabstractThe popularity of cryptocurrencies has garnered interest from cybercriminals, spurring an onslaught of cryptojacking campaigns that aim to hijack computational resources for the purpose of mining cryptocurrencies. In this paper, we present a cross-stack cryptojacking defense system that spans the hardware and OS layers. Unlike prior work that is confined to detecting cryptojacking behavior within web browsers, our solution is application agnostic. We show that tracking instructions that are frequently used in cryptographic hash functions serve as reliable signatures for fingerprinting cryptojacking activity. We demonstrate that our solution is resilient to multi-threaded and throttling evasion techniques that are commonly employed by cryptojacking malware. We characterize the robustness of our solution by extensively testing a diverse set of workloads that include real consumer applications. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of benchmark applications. Nada Lachtar, Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik |
DSN | 2 |
| 2021 | Performance evaluation of range-free localization algorithms for wireless sensor networks
Ibrahim A. Nemer, Tarek R. Sheltami, Elhadi M. Shakshuki, Abdulrahman Abu Elkhail, Mumin Adam |
Pers. Ubiquitous Comput. | 4 |
| 2021 | Internet of things for healthcare monitoring applications based on RFID clustering scheme
Abdulrahman Abu Elkhail, Uthman A. Baroudi, Muhammad Wasim Raad, Tarek R. Sheltami |
Wirel. Networks | 1 |
| 2020 | Dark Firmware: A Systematic Approach to Exploring Application Security Risks in the Presence of Untrusted Firmware
Duha Ibdah, Nada Lachtar, Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik |
RAID | 3 |
| 2020 | Optimum bi-level hierarchical clustering for wireless mobile tracking systems
Uthman A. Baroudi, Abdulrahman Abu Elkhail, Hesham K. Alfares |
Wirel. Networks | 2 |
| 2018 | Real-Time Healthcare Monitoring System using SmartphonesabstractMonitoring and tracking healthcare conditions of crowds is a challenging mission. Although, there are several existing techniques to monitor and track crowds, these techniques suffer a number of serious issues such as inaccurate identification, high energy consumption and high infrastructure cost. In this paper, we propose to use a low-cost solution without the need to build any infrastructure by exploiting the availability of Bluetooth and Wi-Fi interfaces in smartphones. We design a Smart Real-Time Healthcare Monitoring and Tracking System based on mobile clustering. This application can be used in large public events such as the annual Muslim pilgrimage (Hajj), festivals, airports, train stations, etc. The monitored crowd are grouped autonomously into small clusters (i.e. piconets). Each cluster collects its members' data via Bluetooth and then delivers it using WiFi/3G/4G. We have evaluated the proposed approach via simulation and a prototype using our developed API under different scenarios. Our approach demonstrates 74% drop in energy consumption compared to a contemporary approach and its ability to detect 96.4% of participants. Abdulrahman Abu Elkhail, Uthman A. Baroudi |
AICCSA | 1 |