Revital Marbel

dblp:251/6602 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0002-3815-2582ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Cloudy with a Chance of Anomalies: Dynamic Graph Neural Network for Early Detection of Cloud Services' User Anomalies
abstract
In today’s digital landscape, ensuring the security of cloud environments is critical for organizational resilience, growth, and operational efficiency. As cloud services become more prevalent, so do sophisticated attacks targeting cloud users, making early detection essential. This paper introduces a novel time-based embedding approach for Cloud Services Graph-based Anomaly Detection (CS-GAD) that leverages a Graph Neural Network (GNN) to detect anomalous user behavior. We propose a dynamic tripartite graph to model interactions among users, actions, and cloud services over time. Using behavioral patterns, our GNN generates user embeddings to enable early detection of anomalies. We evaluate this approach on a novel dataset simulating five real-world attacks: cryptojacking, billing abuse, lateral movement, monitor exploitation, and service targeting. The dataset comprises 107,116 Application Programming Interface (API) calls over 32 days, tracking 79 AWS services, with attacks embedded within legitimate cloud traffic. Our results demonstrate that the proposed method achieves a lower false positive rate and higher detection accuracy than a prevailing method, as evidenced by improved accuracy, precision, recall, and F1-score.
Revital Marbel, Yanir Cohen, Ran Dubin, Amit Dvir, Chen Hajaj
CCNC1
2026 Uncovering Microservice Faults: A Temporal Graph Approach to Root Cause Analysis
Udi Aharon, Amit Dvir, Ran Dubin, Revital Marbel, Chen Hajaj
ICC4
2026 GraphMux: A graph-based framework for encrypted traffic classification
abstract
The growing dominance of encrypted network traffic and modern encryption protocols (TLS 1.3, QUIC, DoH) poses significant challenges for accurate network classification, particularly as many existing approaches rely on text- or image-based representations, which fail to adequately capture the inherent structural relationships present in network communication—relationships that are more naturally represented as graphs. In this work, we introduce GraphMux, a graph-based framework that leverages line graph transformations to fuse multiple graph views into a unified representation. We also present three graph-based flow representations (TIG+Chain, StarBurst, and 2Chain) designed to capture both temporal burst dynamics and client–server interaction patterns, using only packet time, direction, and length information, without incorporating any unencrypted statistical features. We evaluate our approach on three datasets: two academic datasets (UTMobileNetTraffic2021 and QUIC PCAP) and a commercial dataset (Flash), using four graph embedding architectures. Across all datasets, GraphMux consistently achieves superior performance, and the proposed graph constructions often yield the best results. Additional experiments examining attribute-selection strategies reveal a strong positive relationship between well-aligned feature assignments and classification accuracy, underscoring the importance of principled attribute design when constructing graph representations for encrypted traffic.
Matan Klein, Revital Marbel, Chen Hajaj, Ran Dubin, Amit Dvir
Comput. Networks2
2025 PQClass: Classification of Post-Quantum Encryption Applications in Internet Traffic
abstract
Post-quantum cryptography (PQC) is expected to revolutionize secure communications in next-generation digital ecosystems. Previous and ongoing activities demonstrate that different PQC algorithms significantly impact traffic latency, but they do not yet provide a scheme to assess the existence of the PQC algorithm or its identification when encrypted traffic is analyzed for traffic engineering purposes. Hence, this work is the first to propose a novel PQClass pipeline for classifying encrypted Internet traffic of recently NIST-approved PQC algorithms. Hence, it establishes solid grounds for enabling engineers to optimize their networks and, in parallel, for cybersecurity practitioners to familiarise themselves with PQC algorithmic properties for enhancing or devising security architectures in diverse setups. Our pipeline demonstrates impressive performance on real-world data, achieving 86% accuracy in detecting the presence of a PQC algorithm and 91% and 98% accuracy in identifying the browser and OS, respectively, based on PQC-based traffic.
Angelos K. Marnerides, Chen Hajaj, Revital Marbel, Ran Dubin, Amit Dvir
ICC3
2025 A New D-MAGIC: Dynamic Model for Cybersecurity Attack Detection Using GNNs into Clustering
abstract
The increasing sophistication and frequency of cyberattacks have made Network Intrusion Detection Systems (NIDS) a critical component of modern cybersecurity. This work presents D-MAGIC, a novel real-time NIDS that leverages zero-shot learning and graph-based dynamic clustering to detect known and unknown threats. Unlike traditional systems that rely on labeled datasets and predefined attack signatures, D-MAGIC operates unsupervised, identifying anomalies by detecting deviations from normal network behavior. By embedding the relationships between network flows into a graph structure and dynamically clustering similar patterns, D-MAGIC can detect coordinated attacks and emerging threats with minimal delay. Experimental results on the CIC-IDS-2017 and CSE-CIC-IDS-2018 datasets demonstrate that D-MAGIC achieves an improvement of up to 12 % based on the standard F1 score compared to state-of-the-art methods, while significantly reducing false positives and ensuring rapid, real-time detection with minimal detection latency.
Zohar Simhon, Matan Weiss, Chen Hajaj, Revital Marbel, Ran Dubin, Amit Dvir
ICC4
2024 Extending limited datasets with GAN-like self-supervision for SMS spam detection
Or Haim Anidjar, Revital Marbel, Ran Dubin, Amit Dvir, Chen Hajaj
Comput. Secur.2
2024 Harnessing the power of Wav2Vec2 and CNNs for Robust Speaker Identification on the VoxCeleb and LibriSpeech Datasets
Or Haim Anidjar, Revital Marbel, Roi Yozevitch
Expert Syst. Appl.2