Belhassen Zouari

dblp:29/4999 · DBLP profile ↗
← Back
29ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-9842-0032ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 6 · 3 since 2021Security and privacy · 5Systems, architecture and hardware · 3 · 1 since 2021Artificial intelligence and machine learning · 2Human-computer interaction and ubiquitous computing · 2 · 2 first-authorTheory of computation · 1
YearPublicationVenuePosition
2025 Local Model Checking on an IoT Based System: Use Case of Cellular M2M in Agriculture
Sawsen Khlifa, Chiheb Ameur Abid, Asma Ben Letaifa, Belhassen Zouari
AINA (5)4
2025 A Multi-Device Framework For Continuous Authentication
abstract
The objective of this work-in-progress paper is to present a theoretical framework for a multi-device, multi-modal Continuous Authentication (CA) system that combines behavior biometric data from smartphones, tablets, and laptops. Six different attack scenarios are identified as test benchmarks. We describe the architectural components of the proposed system, including data capture, preprocessing, machine learning-based analysis, and decision fusion. While the paper introduces and describes unimodal, multimodal, and multi-device CA approaches, the primary focus is on outlining a multi-device CA methodology and its potential for real-time threat detection and dynamic security response.
Aidar Gaffarov, Faiza Ajmi, Abir B. Karami, Belhassen Zouari
CoDIT4
2024 Local Model Checking on a Modular System
abstract
In this paper, we propose an approach that allows to limit the verification of an LTL property of a modular system to the parts that it concerns. Given a modular Petri net and a property that concerns one module, the model checking is performed by exploring exclusively an abstract graph that models the behaviors of the module and is enriched with some global information. Thanks to a distributed state space version, named Reduced Distributed State Space (RDSS), of the considered modular system, there is no need to explore graphs of irrelevant modules to the property. We used the SPOT library to implement the suggested model checking in a C++ prototype, and we compared our primary results with those of the LTSmin model checker.
Sawsen Khlifa, Chiheb Ameur Abid, Belhassen Zouari
CoDIT3
2024 Architectural Security and Trust Foundation for RISC-V
abstract
Modern System-on-Chips (SoC) rely on Trusted Execution Environment (TEE) to ensure the integrity and confidentiality of sensitive information by providing a secure environment for data processing. Serval TEE enablement with many mechanisms and architectures has been proposed for ARM-based computing devices, thus, presenting a rich body of literature. In counterpart, RISC-V lacks ratified TEE specifications and hence an effective system-wide security approach. Given an increasing number of vendors and Original Equipment Manufacturers (OEM) now plan to adopt the RISC-V in their products, this paper fills the gap and proposes a reference security and trust architecture enforced by TEE to allow the building of new security solutions and applications. We evaluate the work against current industry security requirements and practices and present comprehensive research with a promising direction. To the best of our knowledge, this is the first work exploring, proposing, analyzing, and evaluating complete security enablement for RISC-V with a final goal of delivering enhanced security at a lower cost to the smart devices market based on RISC-V.
Marouene Boubakri, Belhassen Zouari
ISORC2
2023 A Reduced Distributed Sate Space for Modular Petri Nets
Sawsen Khlifa, Chiheb Ameur Abid, Belhassen Zouari
AINA (1)3
2021 Towards a firmware TPM on RISC-V
abstract
To develop the next generation of Internet of Things, Edge devices and systems which leverage progress in enabling technologies such as 5G, distributed computing and artificial intelligence (AI), several requirements need to be developed and put in place to make the devices smarter. A major requirement for all the above applications is the long-term security and trust computing infrastructure. Trusted Computing requires the introduction inside of the platform of a Trusted Platform Module (TPM). Traditionally, a TPM was a discrete and dedicated module plugged into the platform to give TPM capabilities. Recently, processors manufacturers started integrating trusted computing features into their processors. A significant drawback of this approach is the need for a permanent modification of the processor microarchitecture. In this context, we suggest an analysis and a design of a software-only TPM for RISC-V processors based on seL4 microkernel and OP-TEE.
Marouene Boubakri, Fausto Chiatante, Belhassen Zouari
DATE3
2021 Open Portable Trusted Execution Environment framework for RISC-V
abstract
A Trusted Execution Environment (TEE) is a relatively new technology that provides hardware-enforced isolation within a processor allowing an application to run in a separate execution area called an enclave. It aims to increase the protection level and defenses against the exploitation of software flaws. This way, if the system gets compromised, the attacker cannot access the user's important assets. A recent trend in TEE development is the transition from vendor-controlled, single-purpose TEEs to open TEEs that host Trusted Applications (TAs) from multiple sources with various use-cases in mind. This transition has created a TA ecosystem that provides more robust and customized security to applications and rich operating systems such as Linux and Android. TEEs are widely deployed, especially on consumer devices whose processors are based on the ARM architecture. As an increasing number of vendors now plans to adopt the RISC-V architecture in their products, defining an approach to reuse the existing TAs is needed. This paper aims to port the OP-TEE framework to RISC-V to incorporate various software components, including middle-ware, security stacks, tools, and community support, with the final goal of moving RISC-V forward.
Marouene Boubakri, Fausto Chiatante, Belhassen Zouari
EUC3
2020 Prevention of DDoS Attacks in IoT Networks
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha
AINA3
2020 An ML Behavior-Based Security Control for Smart Home Systems
Noureddine Amraoui, Belhassen Zouari
CRiSIS2
2019 Implicit and Continuous Authentication of Smart Home Users
Noureddine Amraoui, Amine Besrour, Riadh Ksantini, Belhassen Zouari
AINA4
2019 Multi-scale Adaptive Threshold for DDoS Detection
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha
CRiSIS3
2019 Distributed Detection System Using Wavelet Decomposition and Chi-Square Test
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari, Claude Fachkha
CRiSIS3
2019 Formal Approach for Authorization in Distributed Business Process Related Task Document Role Based Access Control
abstract
The business process management is powerful discipline used by the companies in order to improve their performance and increase their productivity and efficiency. The multi-companies aim to enhance their collaborative BPM to make it more flexible, coherent and consistence. Therefore, they interest by the opportunities offered by the Cloud. Nevertheless the benefits of Cloud are shadowed with the lack of security. Thus, the consolidation of business processes and role based access control is recommended. This paper presents a novel extension of Role Based Access Control Model for business process BP, called Task Document Role Based Access Control Model (TDRBAC). The main objective of our model is to protect the access authorization to tasks on-premise and to documents on cloud. The access to documents is not public, thus we use a secure proxy called AIRD-proxy in order to enhance and robust the access and to protect the data aggregated in documents. The proxy is modeled with the main of CPN-tools. Moreover we suggest an algorithm based on internal and external authorization to manage the global authorization of the model based on the attributes and the constraints proposed.
Maroua Nouioua, Belhassen Zouari, Adel Alti
IWCMC2
2018 A New Formal Proxy-Based Approach for Secure Distributed Business Process on the Cloud
abstract
Today, the main focus of multi-site companies is to find a powerful Business Process Management (BPM) and advanced secure communications with the lowest cost possible. The cloud computing as a perfect paradigm for BPM, it offers many characteristics like the elastic-BPM and the pay-per-use business model. To exchange documents and execute various interactions between companies a lot of benefits are offered through the using of cloud. Nevertheless it unfortunately presents many drawbacks that affect the security of BPM, including the mediocre degree of protection. Therefore sensitive Documents may be target of malicious attacks due to the lack of the privacy and confidentiality checking. Unauthorized access to such sensitive documents can cause many problems such as privacy violation. In this paper, we propose the AIRD (Analysis and Interaction, Role, Document) formal proxy-based BPM approach for detecting unauthorized access to sensitive documents and fraudulent transactions on documents. We intend to illustrate our proposal using e-healthcare system.
Maroua Nouioua, Adel Alti, Belhassen Zouari
AINA3
2018 Colored Petri net Model for Secure Document Management in Business Process Systems
abstract
In recent years, more and more challenges concerning the modeling of new and complex business process systems have emerged. E-learning business process is one of those systems which are based on documents. Modeling documents and their interactions with tasks in the same process, called document driven workflows, has not been widely represented. We focus on security issues by modeling time as an extension of such systems and discuss some constraints. There are different approaches for modeling those temporal aspects in workflow systems. Since Petri Nets are known for their capability and flexibility in modeling complex systems, we propose a Colored Petri Net and emphasize the use of Time Petri Nets to model workflow management systems based on documents with time constraints. We illustrate our model on a running example of e-learning process.
Imen Chaouachi Allani, Belhassen Zouari, Chirine Ghedira
CoDIT2
2018 A generic generalized stochastic Petri nets model for the performance analysis of FMS considering the resources failures
abstract
This paper introduces a formal approach allowing the performance evaluation of Flexible Manufacturing Systems (FMS) while considering the whole system behavior (operation, transport and preparation) as well as its possible components failure. The proposed approach is based on a generic Generalized Stochastic Petri nets (GSP-nets) model. The introduced GSP-net model represents the basic operation of the FMS elements (machines and material handling systems) as well as their fail and recovery aspects. The existing formal verification GSP-nets methods are exploited, and especially the state space generation and handling, in order to deduce a set of performance indicators helping the FMS designers when scheduling the production. Extracted indicators allow to enhance the decision process and the system efficiency. An important advantage of the introduced approach is that it is parameterized. Thus, it may be adapted to a large class of existing FMSs. The instantiation of the presented GSP-nets model to the specific features of the studied FMS is made by colored tokens.
Sajeh Zairi, Belhassen Zouari, Hamdi Rahal, Jean-François Pradat-Peyre
CoDIT2
2018 On the Collaborative Inference of DDoS: An Information-theoretic Distributed Approach
abstract
Literature contributions have shown that information theoretic techniques can effectively detect various types of Distributed Denial of Service (DDoS) attacks. However, such techniques are often centralized with a limited measurement vantage point and suffer from the issue of single point of failure. Furthermore, with the flourishing of distributed and cloudbased environments, such techniques ought to adapt to such settings for scalability and performance reasons. In this paper, we address the problem of collaborative DDoS detection using information-theoretic techniques. To this end, we propose an entropy-based detection mechanism that supports collaborative agreement to identify suitable tuning network parameters for distributed DDoS inference in real-time. Empirical evaluations with real DDoS attacks demonstrate that the proposed approach is indeed capable of cooperatively inferring DDoS attacks while achieving resiliency and scalability.
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Elias Bou-Harb, Claude Fachkha, Belhassen Zouari
IWCMC5
2017 On the Collaborative Inference of DDoS: A Multi-scale Distributed Approach
abstract
DDoS attacks are becoming increasingly harmful and destructive, especially when multinational companies and government e-services are targeted. Monitoring large scale networks, naturally, involves the processing of an increasingly large quantity of data. While DDoS attacks are by definition distributed and the hackers have access to many (real and virtual) machines, the majority of defense systems are still centralized. In this paper, we present a solution to the scalability problem in DDoS detection and mitigation systems. We simultaneously allow a distributed inference of DDoS attacks, and solve the, so called, "single point of failure" problem by using the paxos consensus protocol. We also demonstrate that wavelet compression methods allow the collaborating probes to analyse a reduced set of traffic without impacting the overall reliability of our DDoS detection system. The Empirical evaluations based on the Booters dataset 1 demonstrate that the proposed approach is indeed capable to cooperatively infer DDoS attacks while achieving scalability and reliability.
Fatima Ezzahra Ouerfelli, Khaled Barbaria, Belhassen Zouari
AICCSA3
2017 Integrating fuzzy TOPSIS and goal programming for multiple objective integrated procurement-production planning
abstract
In this paper, a four-phase approach for Integrated Procurement-Production (IPP) tactical planning in a multiechelon, multi-product and multi-period Supply Chain (SC) network is proposed. To account for ambiguity and vagueness in some real-world data and preferences, in the first phase of the approach, the Fuzzy Technique for Order Preference by Similarity to Ideal Solution (fuzzy TOPSIS) method is used to obtain the overall performance and risk ratings of the suppliers with regard to a set of qualitative and quantitative criteria. In the second phase, we introduce a novel multi-objective possibilistic mixed integer linear programming model (MOPMILP) for solving an IPP planning considering conflicting goals simultaneously: maximization of the overall performance and minimization of the overall risk. Then, after converting this MOPMILP model into an equivalent crisp multi-objective mixed integer linear programming (MOMILP) model, we use the Goal Programming (GP) approach to solve this MOMILP model in order to find an efficient compromise solution (i.e. an efficient procurement production plan) for the whole SC. The proposed approach and solution methodology are validated through a numerical example.
Rihab Khemiri, Khaoula ElBedoui, Bernard Grabot, Belhassen Zouari
ETFA4
2015 A Simple Erlang API for Handling DDS Data Types and Quality of Service Parameters
abstract
The choice of the programming language impacts the efficiency of the application and the robustness of the code. The characteristics of Erlang as a functional programming language supported distributed real time computing allowed us to propose eDDS: an Erlang based middleware compliant to the Data Distribution Service (DDS) standard that providing a strong Quality of Service (QoS) support. When the performance and the compliance to the norm have been easy achieved in particular on defining and setting QoS parameters, the lack of efficient and user-friendly support for data type management has been noticed. In this paper, we will explain this type checking problem and how we solved it.
Wafa Helali, Khaled Barbaria, Belhassen Zouari
ENASE3
2014 A high-level Petri nets approach for multi-objective optimization in pipeline networks
Hela Kadri, Belhassen Zouari
SIMULTECH2
2013 Local Verification Using a Distributed State Space
abstract
This paper deals with the modular analysis of distributed concurrent systems modelled by Petri nets. The main analysis techniques of such systems suffer from the well-known problem of the combinatory explosion of state space. In order to cope with this problem, we use a modular representation of the state space instead of the ordinary one. The modular representation, namely modular state space, is much smaller than the ordinary state space. We propose to distribute the modular state space on every machine associated with one module. We enhance the modularity of the verification of some local properties of any module by limiting it to the exploration of local and some global information. Once the construction of the distributed state space is performed, there is no communication between modules during the verification.
Chiheb Ameur Abid, Belhassen Zouari
Fundam. Informaticae2
2010 Decentralised Active Controller
Chiheb Ameur Abid, Belhassen Zouari
ICINCO (2)2
2010 The Value of Information Sharing in a Serial Supply Chain with Centralised and Decentralised Decision
Mansour Rached, Zied Bahroun, Belhassen Zouari, Armand Baboli, Jean-Pierre Campagne
ICINCO (1)3
2009 A formal design of secure information systems by using a Formal Secure Data Flow Diagram (FSDFD)
abstract
Data Flow Diagram (DFD) is a methodology which can be applied to design an information system and even the behaviour of a whole organization. It has the advantages of simplicity and popularity by using simple notations. But, it is semi formal which means it lacks representation of semantics. Also, it doesn 't consider security features of the system. In, this paper, we describe our new proposed methodology called FSDFD Formal Secure Data Flow Diagram). The idea of this proposal has been born from an increasing need of organizations to secure their information systems by making a secure and a formal design of each information system component. FSDFD will not only design formally more secured systems but also it will automate some security activities like security audit, risk analysis and vulnerability assessment. Use of FSDFD will so let organizations reduce both supported risk and security costs and improve security and assurance levels of their system.
Nadia Soudani, Bel G. Raggad, Belhassen Zouari
CRiSIS3
2008 A Byzantine solution to early detect massive attacks
abstract
The quality and the timeliness of the detection of massive attacks significantly limit their great danger. In this paper, we describe an existing solution based on a centralized treatment of threat reports generated by probes deployed at the edges of a national Cyber-space. We also propose a more reliable architecture based on a consensus algorithm that solves the interactive consistency problem under the Byzantine assumptions. We prove the correctness of our algorithm and show its contribution to the early detection of massive attacks.
Khaled Barbaria, Belhassen Zouari
CRiSIS2
2007 A formal approach for the specification, verification and control of flexible manufacturing systems
abstract
This paper introduces a formal specification model that covers a large class of real Flexible Manufacturing System (FMS). Using this model, a designer expresses the functional capacities of his system and the product flows. Parallel manufacturing processes, having, transformation, assembly, disassembly, test and storage operations, are considered. FMS specification is automatically transformed into a CP-net model. Hence, the verification and the supervisory control techniques based on CP-nets can be applied to the generated CP-net. Thus, a parameterized solution is defined taking into account the flexibility of the specification model. The present work led to the implementation of a specific tool, called MAC-FMS, allowing graphical specification, supervisory control and verification through its interaction with CPN tools environment (Jensen's tool).
Sajeh Zairi, Belhassen Zouari, Laurent Piétrac
ETFA2
2003 High-level Petri net approach for supervisory control
abstract
This paper presents a supervisor synthesis method based on a High-level Petri net model. The presented method has the two following benefits: first, modeling discrete-event systems with High-level Petri nets naturally leads to concise specifications; secondly, we use a related state graph method which exploits behavior symmetries in order to build reduced graphs. The synthesis method consists in generating a subnet modeling control specification, and which is connected to the uncontrolled system specification leading to an autonomous High-level Petri net.
Belhassen Zouari
SMC1
2003 Parameterized supervisor synthesis for a modular class of discrete event systems
abstract
The presented work is related to the use of structural Petri net techniques in the supervisory control of discrete event systems. A relevant property of the system behavior under supervision is to be behavior controllable (non-blocking), i.e., from any reachable state, it is always possible to reach a desirable state. In this paper, we present a proper supervisor synthesis method based on a purely structural reasoning. This parameterised method is especially well suited for a large class of discrete event systems called G-systems generalising well-known models presented in the literature. The system specification is obtained modularly by composing generic tasks and shared resources. Our main result is to prove that a given G-system is structurally non-blocking. This is achieved by preserving the Petri net property of "controlled siphon" through the composition of the generic tasks and resources.
Belhassen Zouari, Kamel Barkaoui
SMC1