VLDB 2026 Research / reviewers in the wild / expert
Hosam Alamleh
dblp:261/5345
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0003-3455-6616ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: The Cyber Attack Surface of Unmanned Vehicles (UxVs)
Alessandro Cantelli-Forti, Hosam Alamleh |
EuroS&P | 2 |
| 2026 | Defending against BLE-based covert channels in crowdsourced location networksabstractCrowdsourced location networks turn billions of consumer devices into a global sensor grid for locating lost items, but the same reach enables two systemic abuses: (i) location tracking via beacons that masquerade as “lost tags,” and (ii) data exfiltration by embedding short secrets in Bluetooth Low Energy (BLE) advertisements that are relayed forward without inspection. Using Apple’s Find My as a case study, we show that covert beacons reliably reach the cloud and then the attacker within minutes due to relay density. We also find that basic single-layer countermeasures such as packet dropping, TCP ACK/RST injection, fixed-delay insertion, or traffic flooding fail under realistic operational conditions. We contribute the first end-to-end experimental evaluation of deployable mitigations that require no vendor changes. Our defense-in-depth design combines: endpoint controls that correlate OS location-service access with immediate BLE advertising and enforce per-process advertising limits; a hybrid perimeter detector that correlates on-host BLE advertisement counts with outbound traffic to crowd-location backends; and physical controls for high-security areas, including exclusion zones of 35 m indoors and 200 m outdoors (line of sight), optionally supported by selective, low-duty RF jamming. For the longer term, we outline protocol changes that vendors can adopt, such as basic beacon admission control and authentication, shorter helper-retention timers, and helper-side quotas. While evaluated on Find My , these findings generalize to crowdsourced location systems built under similar design assumptions. Hosam Alamleh, Alessandro Cantelli-Forti |
Comput. Secur. | 1 |
| 2025 | Designing a Maritime Cybersecurity Risk Intelligence Model with Generative AI and Real-Time InterviewsabstractAI has disrupted all sectors, and the maritime industry is undergoing its own transformation. After reviewing 48 academic papers, the authors showed the need for a holistic and engaging cybersecurity risk analysis method and suggested a survey-based method called Cyber Risk Analysis Method for Maritime Transportation Systems (CRAMMTS). This study presents an AI-powered system for conducting risk analysis interviews with maritime entities, developed using LangChain, LangGraph and OpenAI’s GPT-4o in Python. The system uses external sources, such as Maritime Attack Database and CRAMMTS survey results, as a data source, evaluates each question/response pair in real-time, determining the necessity of follow-up questions and ensuring thorough risk coverage. The system stores the interview results, applies basic analysis, and generates recommendation statements for the entity. Retrieval augmented generation is employed to integrate current incidents and risk data into the analysis. Future expansion opportunities include automated analysis and the generation of comprehensive risk analysis documents with actionable recommendations. This approach not only aims to streamline and standardize the maritime risk analysis process but also reduce the cost barrier to cybersecurity resources using advanced language models. Jake Townsend, Bilge Karabacak, Ulku Clark, Kasey Miller, Hosam Alamleh |
LCN | 5 |
| 2024 | Exploring the Security Landscape of Underwater Positioning and Navigation Systems: An Attack Surface AnalysisabstractUnderwater positioning and navigation systems are vital for maritime operations but face significant security threats like spoofing, jamming, interception, sensor manipulation, and algorithm exploitation. This paper categorizes underwater navigation techniques (acoustic, GPS buoys, multi-sensor fusion, vision-based, hybrid) and analyzes their potential attack surfaces. To mitigate these threats, a multi-layered defense strategy is proposed, encompassing cryptographic authentication, secure communications, physical security, sensor redundancy, data validation, image authentication, and algorithm robustness. Specific countermeasures against jamming, spoofing, interception, sensor attacks, and algorithm attacks are discussed. A holistic approach integrating secure software practices, anomaly detection, and fusion technique diversity is emphasized to fortify system resilience against advanced persistent threats, ensuring maritime safety and security. This research contributes to understanding security vulnerabilities and providing a comprehensive mitigation framework for enhancing the resilience of underwater navigation systems. Hosam Alamleh, Bilge Karabacak |
LCN | 1 |