Abdulrahman Abu Elkhail

dblp:234/3762 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-6199-6468ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Sniper: Countering Locker Ransomware Attacks Through Natural Language Processing
abstract
Mobile systems have evolved into versatile devices that end users depend on for carrying out their daily tasks. Unfortunately, the mobile sector has recently fallen prey to a series of ransomware campaigns designed to lock users out of their devices and extort them for payment. In response to these challenges, we propose a novel runtime system that dynamically restores device access by undoing the effects of locker ransomware. A key observation made by this work is that attackers rely on the display of a ransom note on the victim’s device to demand payment. Based on this observation, we develop a solution that combines the monitoring of mobile app activity with a natural language processing (NLP) unit that harnesses transformers to detect the appearance of ransom notes. We extensively validate the robustness of our solution against more than five thousand ransomware samples and show that our solution reliably recovers from all the malicious samples that we tested, including overlay screen and change pin-code ransomware. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of mobile benchmark applications.
Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik
IEEE Trans. Dependable Secur. Comput.1
2023 Seamlessly Safeguarding Data Against Ransomware Attacks
abstract
Encryption has become an indispensable technology for preserving confidentiality. Unfortunately, cybercriminals have re-purposed this technology to deny users access to their data. This trend has sparked an onslaught of ransomware attacks, that resulted in several victims being extorted to pay ransoms in return for restoring their maliciously encrypted data. In response to these challenges, we propose a novel runtime solution that seamlessly defends against cryptographic ransomware. A key observation made by this work is that maliciously encrypted data is initially buffered in the OS's page cache before it is flushed to the underlying storage device. Based on this observation, we develop a solution that efficiently manages data synchronization between the memory and storage subsystems to prevent maliciously encrypted data from being permanently committed to the underlying storage. We extensively validate the robustness of this approach against more than one thousand ransomware samples and show that our design reliably restores all encrypted files. Furthermore, our solution is resilient to ransomware that employ techniques including master boot record infection and multi-threaded attacks. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of compute and I/O bound applications.
Abdulrahman Abu Elkhail, Nada Lachtar, Duha Ibdah, Rustam Aslam, Anys Bacha, Hafiz Malik
IEEE Trans. Dependable Secur. Comput.1
2021 An Application Agnostic Defense Against the Dark Arts of Cryptojacking
abstract
The popularity of cryptocurrencies has garnered interest from cybercriminals, spurring an onslaught of cryptojacking campaigns that aim to hijack computational resources for the purpose of mining cryptocurrencies. In this paper, we present a cross-stack cryptojacking defense system that spans the hardware and OS layers. Unlike prior work that is confined to detecting cryptojacking behavior within web browsers, our solution is application agnostic. We show that tracking instructions that are frequently used in cryptographic hash functions serve as reliable signatures for fingerprinting cryptojacking activity. We demonstrate that our solution is resilient to multi-threaded and throttling evasion techniques that are commonly employed by cryptojacking malware. We characterize the robustness of our solution by extensively testing a diverse set of workloads that include real consumer applications. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of benchmark applications.
Nada Lachtar, Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik
DSN2
2021 Performance evaluation of range-free localization algorithms for wireless sensor networks
Ibrahim A. Nemer, Tarek R. Sheltami, Elhadi M. Shakshuki, Abdulrahman Abu Elkhail, Mumin Adam
Pers. Ubiquitous Comput.4
2021 Internet of things for healthcare monitoring applications based on RFID clustering scheme
Abdulrahman Abu Elkhail, Uthman A. Baroudi, Muhammad Wasim Raad, Tarek R. Sheltami
Wirel. Networks1
2020 Dark Firmware: A Systematic Approach to Exploring Application Security Risks in the Presence of Untrusted Firmware
Duha Ibdah, Nada Lachtar, Abdulrahman Abu Elkhail, Anys Bacha, Hafiz Malik
RAID3
2020 Optimum bi-level hierarchical clustering for wireless mobile tracking systems
Uthman A. Baroudi, Abdulrahman Abu Elkhail, Hesham K. Alfares
Wirel. Networks2
2018 Real-Time Healthcare Monitoring System using Smartphones
abstract
Monitoring and tracking healthcare conditions of crowds is a challenging mission. Although, there are several existing techniques to monitor and track crowds, these techniques suffer a number of serious issues such as inaccurate identification, high energy consumption and high infrastructure cost. In this paper, we propose to use a low-cost solution without the need to build any infrastructure by exploiting the availability of Bluetooth and Wi-Fi interfaces in smartphones. We design a Smart Real-Time Healthcare Monitoring and Tracking System based on mobile clustering. This application can be used in large public events such as the annual Muslim pilgrimage (Hajj), festivals, airports, train stations, etc. The monitored crowd are grouped autonomously into small clusters (i.e. piconets). Each cluster collects its members' data via Bluetooth and then delivers it using WiFi/3G/4G. We have evaluated the proposed approach via simulation and a prototype using our developed API under different scenarios. Our approach demonstrates 74% drop in energy consumption compared to a contemporary approach and its ability to detect 96.4% of participants.
Abdulrahman Abu Elkhail, Uthman A. Baroudi
AICCSA1