VLDB 2026 Research / reviewers in the wild / expert
Ahmed Bouabdallah
dblp:37/5538
· DBLP profile ↗
19ranked-venue papers
1as first author
7since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 3 since 2021Security and privacy · 3Applied, interdisciplinary, general and emerging computing · 3Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Intent-Based Attack Mitigation through Opportunistic Synchronization of Micro-ServicesabstractThe escalating number of cyberattacks poses a significant threat to digital infrastructures. Defining and deploying accurate countermeasures is challenging because of (1) the variety of threats and their possible evolution over time and (2) the need to enforce them as fast as possible, especially for fast-propagating attacks. Intent-Based Networking (IBN) stands for a promising solution for security management, especially to mitigate attacks through the specification of reaction intents, saving time and avoiding error-prone tasks. Nevertheless, most current IBN solutions rely on centralized architectures performing time-consuming operations, which makes them inappropriate to timely deploy countermeasures, especially in the case of fast-propagating attacks spreading large-scale systems. As a solution to shorten the reaction time while supporting scalability, we first consider fast micro-services technologies (e.g., Unikernels) as the substrate of security functions acting as Policy Enforcement Points (PEP). Second, we propose to enable an opportunistic synchronization of those PEPs to react, at least partially but autonomously, against the ongoing attacks in a decentralized fashion. Such a solution raises challenges related to the consistency and performance of the overall enforced reaction policies. This paper presents the early stage of the PhD, outlining the specific challenges, limitations, and research required to leverage decentralized reaction using opportunistic synchronization of micro-services in an IBN framework for security. Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François |
NetSoft | 4 |
| 2024 | How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetyaabstractMalware attacks pose a critical threat to digital infrastructures particularly given their potential for widespread and fast propagation. Mitigating them involves limiting their expansion, which requires a thorough understanding of their propagation mechanisms. However, few studies have been conducted on their propagation behaviors in large-scale networks. In this paper, we present the results of an empirical study focusing on the propagation strategy of WannaCry and NotPetya, two malware instances leveraging EternalBlue, an exploit developed by the NSA and stolen by The Shadow Brokers hacker group, which has been used to implement rapid spreading in some mal-ware instances. Our experiments qualify the speed of infection, epidemic behavior, and spreading strategies in a local network of 50 VMs. We have especially measured for WannyCry that (1) nearly 20% of infections are processed in less than 50 seconds, and (2) up to 16 hosts are infected in a 100-second period. Our results provide meaningful insights on malware propagation to support the design of effective countermeasures. Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François, Guillaume Doyen |
NetSoft | 4 |
| 2024 | CPU throttling-aware AI-based autoscaling for Kubernetesabstract5G networks are moving towards cloud-native architectures and expect higher performances, customizability, and cost efficiency compared to previous generations. Dynamic scaling of Containerized Network Function (CNF) is a major feature that allows telecom operators to find a good balance between cost and Quality of Service (QoS). By accurately determining the necessary resources for CNFs, operators can minimize operational costs without over-provisioning and simultaneously, maintain satisfactory QoS levels without under-provisioning. However, one of the obstacles we identified that can throw off the balance between cost-QoS trade-off is Central Processing Unit (CPU) throttling, which is an underlying system process. Without proper timing in scaling decision-making, it can negatively impact QoS by increasing service response time during scaling events. In this paper, we propose a novel AI-based autoscaling solution to calculate the precise amount of resources and the optimal timing for decision-making, with an awareness of CPU throttling. The solution employs one deep learning model to proactively determine the right amount of resources and another to predict CPU throttling events, which in turn trigger scaling decisions. Our experimental results demonstrate that our new autoscaling solution outperformed the default Horizontal Pod Autoscaling (HPA) in Kubernetes in terms of balancing cost QoS tradeoff. Menuka Perera Jayasuriya Kuranage, Elisabeth Hanser, Ahmed Bouabdallah, Loutfi Nuaymi, Philippe Bertin |
PIMRC | 3 |
| 2023 | Towards Flexible and Compact encoded DNS Messages using CBOR StructuresabstractThe longevity of the protocols used by Domain Name System (DNS) is a testament to its relevance in establishing an efficient mapping between identifiers. Recent attempts to integrate DNS into the REST (REpresentational State Transfer) paradigm have paved the way for its future evolution. However, this “RESTification” made a reality by protocols such as DNS-over-HTTPS (DoH) or DoQ (DNS-over-QUIC), increases the latency and verbosity of the DNS. We propose to reduce such negative impacts of RESTIfication while maintaining the benefits it brings to the DNS. A new binary format based on the Concise Binary Object Representation (CBOR) called Efficient CBOR (e-CBOR) is introduced making the DNS message representation more compact and flexible. The tests carried out on our implementation show more than 57% reduction for DNS/DNSSEC queries. In the case of responses, we obtain a reduction of up to 16% in the size of messages encoded in the traditional format. Arnol Lemogue, Ivan Martinez, Laurent Toutain, Ahmed Bouabdallah |
IPCCC | 4 |
| 2023 | A Robust Approach for the Detection and Prevention of Conflicts in I2NSF Security PoliciesabstractIn order to maintain a sufficient protection level of their infrastructure, automating security management is at the core of current operators issues. The Interface to Network Security Function (I2NSF) is a framework that takes part of the Intent-Based Networking (IBN) paradigm. It consists of automating the translation of high-level policies into low-level configurations of Network Security Functions (NSF) and appears as a promising way to overcome the complexity of this challenging task. However, if the I2NSF framework provides a comprehensive architectural and data model for such an automation, it provides neither detection nor prevention mechanisms against conflicting security requirements. In this paper, we assess to what extent state-of-the-art mechanisms can shift the initial I2NSF proposal toward a robust framework. As such, we extend (1) the reference architecture to integrate some checking components and (2) the consumer-facing data model to enforce separation constraints and partial ordering relationships. By considering a large set of rules and conflicting situations, we evaluate the performance of our solution within an early implementation of I2NSF achieved in an IETF Hackathon. Do Duc Anh Nguyen, Fabien Autrel, Ahmed Bouabdallah, Guillaume Doyen |
NOMS | 3 |
| 2022 | Deep learning based resource forecasting for 5G core network scaling in Kubernetes environmentabstract5G networks are moving towards cloudification which gives the telecom operators the flexibility to manage their networks efficiently and cost-effectively. Scaling network functions on demand is one of the advantages of using container-based deployment in cloud environments. With the continuously changing network traffic patterns due to the emerging new 5G use cases, there is a need for novel automated network resources management approach in cloud-native environments. Considering the scale and the complexity of the 5G network, managing resources is a challenge. To address this, we propose a deep learning-based resource usage forecasting approach that provides useful insights for decision-making in containerized Network Function (CNF) scaling for the Kubernetes environment. Kubernetes is a container orchestration tool that becoming popular among Telecom operators due to its simplicity. We implemented a testbed in the Kubernetes environment to generate a dataset closer to real-world data for deep learning model training and evaluated the best-performing model for resource usage forecasting. We benchmarked our approach against another deep learning-based resource usage forecasting approach which proved our method can provide a highly accurate forecast for further horizons. Menuka Perera Jayasuriya Kuranage, Loutfi Nuaymi, Ahmed Bouabdallah, Thomas Ferrandiz, Philippe Bertin |
NetSoft | 3 |
| 2022 | Federated IoT Roaming using Private DNS ResolutionsabstractWe are witnessing an exponential increase in IoT applications resting on global mobility of objects. Mobility requires moreover roaming to allow any device to move from one IoT network operator to another. The solutions proposed in the literature are however neither scalable nor secure. The consequences for devices’ owners with large fleets of roaming objects may seriously impact the economic benefits of the involved services. We tackle these issues starting from IoTRoam a compliant open-source implementation of the LoRaWAN roaming architecture. This one based on regular DNS resolutions suffers from the limitations indicated above. We propose to modify IoTRoam by introducing a new entity called DNS Broker responsible for orchestrating in a decentralised fashion roaming between different operators using private and secure DNS resolutions. We experimentally show the feasibility of our approach. A preliminary performance evaluation of our implemented architecture shows equal performances for a more flexible, scalable and secure architecture. Arnol Lemogue, Ivan Martinez, Laurent Toutain, Ahmed Bouabdallah |
NOMS | 4 |
| 2018 | A Privacy Safeguard Framework for a WebRTC/WoT-Based Healthcare ArchitectureabstractIn this paper, an e-health architecture offering secure remote medical services using WebRTC (Web Real-Time Communication) enhanced with contextual health information coming from medical connected sensors, is proposed and analyzed. The goal is to allow patients (injured, elderly, disabled, etc.) to benefit from a medical assistance just by calling a remote medical support (doctors, nurses, etc.) using a real-time communication technology such as WebRTC. Moreover, the advancement of the medical devices, on one side, and the emergence of the Web of Things (WoT), on the other side, makes this approach possible. Hence, granting the users the ability of monitoring their own health status and an awareness of their health condition. However, in such architectures, in order for the users to access these services, they need to provide and exchange personal data, and in particular the health related ones. Therefore, user's private information may be exposed to privacy violation and disclosure. Understanding the privacy holes regarding the protection of the personal health related data, identifying the privacy leakage points and studying the privacy requirements are important in order to propose a privacy safeguard for the proposed healthcare architecture, which is the aim of this paper. Additionally, a risk analysis, the sources of these risks and the possible countermeasures are also conducted during this process. Saad El Jaouhari, Ahmed Bouabdallah |
COMPSAC (2) | 2 |
| 2018 | Dynamic Security Management of Smart WoT Infrastructures Using SDNabstractThe next generation of infrastructures (hospitals, factories, buildings, etc.) will be deeply impacted by the introduction of a huge number of IoT devices which will contribute to a significant improvement of their operations. This follows the trend of the Web of Things (WoT) which projects to seamlessly connect an incredible diversity of IoT devices and IoT frameworks in a novel way, enabling exciting new services and opportunities due to its flexible nature. However, it also means that more and more data need to be protected from external threats and unauthorized accesses. Additional security, privacy and monitoring mechanisms need to be deployed, together with an efficient management of those IoT devices for the new vision of smart infrastructure. This issue becomes more convoluted and hardly tractable when dealing with several smart objects of the infrastructure dispatched over different network locations that we call Smart Spaces (SS), along with evolving management rules which may be specific to each SS. This paper proposes to solve this issue by introducing an architecture based on an Software Defined Networking (SDN) controller for managing the secure access to the different SSs of a smart infrastructure. We argue that a centralized view can greatly simplify and improve the security management of such infrastructures. We illustrate our approach with a use case from the e-Health domain involving the management of the security of different rooms of an hospital where each room is considered as an SS. A Proof of Concept is also provided, with a concrete implementation of all the components together with an analysis of the performance and the security of the new architecture. Saad El Jaouhari, Ahmed Bouabdallah |
VTC Fall | 2 |
| 2018 | A novel approach for generic home emergency management and remote monitoringabstractSummary This paper presents a novel home emergency management system (HEMS) for managing home emergency situations. The proposed solution is a generic and based on normalized technologies. First, we have identified a set of requirements that a robust HEMS should satisfy (interoperability, security, mobility, etc). Then, we have opted for an extended finite‐state machine to detect and manage emergency situations. We also adopted WebRTC to enable communication in an interoperable manner. For securing our HEMS, we have used HTTPS, password, contextual role–based access control, and we have finally installed all the public servers into a protected area. The result obtained from the test‐bed demonstrates that the proposed HEMS fills all the listed requirements. Furthermore, it gives very interesting results in terms of round‐trip delay time and scalability. Allal Tiberkak, Tayeb Lemlouma, Abdelkader Belkhir, Ahmed Bouabdallah, Abdelfetah Hentout |
Softw. Pract. Exp. | 4 |
| 2017 | Competition: Controlled Replication for Higher Reliability and Predictability in Industrial IoT Networks
Zacharie Brodard, Tengfei Chang, Ahmed Bouabdallah, Nicolas Montavont, Géraldine Texier, Pascal Thubert, Thomas Watteyne, Georgios Z. Papadopoulos |
EWSN | 4 |
| 2017 | JACPoL: A Simple but Expressive JSON-Based Access Control Policy Language
Ahmed Bouabdallah |
WISTP | 2 |
| 2017 | Toward a Smart Health-Care Architecture Using WebRTC and WoT
Saad El Jaouhari, Ahmed Bouabdallah, Jean-Marie Bonnin, Tayeb Lemlouma |
WorldCIST (3) | 2 |
| 2016 | A Secure Multi-Tenant Framework for SDNabstractSoftware-Defined Networking (SDN) promises a flexible and programmable solution for future networks. By extracting the control logic out of forwarding devices into a specific entity as the control plane, it dramatically eases the management work of multi-tenant networks, where several customers share same network resources. Depending on the way and the SDN layer that tenants can interact with, they can be allowed to have higher and differentiated levels of control over their own slices of available resources. This paper discusses multi-tenancy in SDN by proposing a framework on SDN northbound that focuses as a matter of priority on isolation and access control. A new network abstraction layer is introduced between the control layer and application layer on top of which tenants are provided unified APIs with abstract views and pre-defined levels of control over their dedicated virtual networks, with no concerning about the underlying type and number of controllers as well as topology of physical networks. A developed PoC finally shows the soundness of our approach by implementing various levels of isolation together with AAA functions. Ahmed Bouabdallah, Amin Aflatoonian, Jean-Marie Bonnin, Karine Guillouard |
SIN | 2 |
| 2015 | BYOC: Bring Your Own Control a new concept to monetize SDN's opennessabstractSoftware Defined Networking (SDN) is supposed to bring flexibility, dynamicity and automation to today's network through a logically centralized network controller. We argue that reaching SDN's full capacities requires however the development of standardized programming capabilities on its top. In this paper we introduce “Bring Your Own Control” (BYOC) as a new concept providing a convenient framework structuring the openness of the SDN on its northbound side. We derive from the lifecycle characterizing the services deployed in an SDN, the parts of services the control of which may be delegated by the operator to external customers through dedicated application programming interfaces (API) located in the northbound interface (NBI). We argue that the exploitation of such services may noticeably be refined by the operator through various business models monetizing the openness of the SDN following the new paradigm of “Earn as Your Bring” (EaYB). We propose an analysis of BYOC and we illustrate our approach with several use cases. Amin Aflatoonian, Ahmed Bouabdallah, Karine Guillouard, Vincent Catros, Jean-Marie Bonnin |
NetSoft | 2 |
| 2014 | KRAMER: New Social Medium Based on Collaborative Recognition of Important SituationsabstractIn modern societies the process of communication is greatly influenced by information technology and computer systems. Social interactions in both real-life and cyber communities are frequently being shaped by two main features of social computing tools: (1) sharing great deal of information with whole groups of consumers and (2) deriving collective intelligence by collaborative information evaluation, discussion, annotation, etc. The latter is further supported by reasoning mechanisms implemented in software to derive more pertinent and synthesized information for its consumers, e.g. recommendations. In consequence, communities are empowered to make more than ever informed conclusions and decisions. In our work, we consider situations that people find themselves in as pieces of information frequently driving decision making in classical human relations. We argue that augmenting social intelligence can be achieved by both (1) facilitating sharing context among community members and (2) encouraging their collaborative effort to learn about the importance of certain situations. We present Kind of Reasoning that Abstracts Meta-situations for Empowering Recommendations, a recommender system that enriches social computing principle with that notion of situation awareness. In this paper, we discuss our system with an emphasis on its social computing mechanisms. We present also its evaluation in the form of a special user test game. Michal Szczerbak, François Toutain, Ahmed Bouabdallah, Jean-Marie Bonnin |
Comput. J. | 3 |
| 2013 | Analysis of synchronization issues for live video-context transmission serviceabstractA promising feature brought along the progressive deployment of LTE concerns the increase of the uplink bandwidth. We exploit this new capability by focusing on an innovative usage defined by the simultaneous transmission of live video and contextual data caught through end user devices like smartphones towards websites or distant spectators. The contextual information may indeed be precious to the spectator for several reasons. On one side, this information cannot be deduced from the video images currently displayed. On the other side, being closely related to the live event, context can be fruitfully exploited by the spectator to complete her understanding of what she is presently watching and to possibly interact with the filming person to influence the rest of the capture. The main property of this new feature can be expressed as a synchronization constraint between the video and the contextual data. Ensuring this property is challenging due to the presence of variable delays in the end-to-end path. We focus on particular contextual data (generated by sensors embedded in Android based smartphones) the specificities of which are analyzed in order to derive a general synchronization solution. We finally propose some optimizations taking in account the characteristics of the devices used to display the contextual data. Houssein Wehbe, Ahmed Bouabdallah, Bruno Stévant, Usama Mir |
CCNC | 2 |
| 2013 | Photovoltaic energy for the fixed and tracking system based on the modeling of solar radiationabstractThe objective of this paper is to estimate the photovoltaic energy on inclined panels for a given site. Its characterization is based on measurements carried out on horizontal plane. A comparison of different models of the diffused radiation released with respect to the monthly and annual energy balance is presented. An optimization of the inclination angle (tilt angle) by maximizing the annual photovoltaic energy is proposed. At the end of this study, energy efficiency of different solar tracking systems is also analyzed. Ahmed Bouabdallah, Salvy Bourguet, Jean-Christophe Olivier, Mohamed Machmoum |
IECON | 1 |
| 1999 | Secure Communications in ATM NetworksabstractThe ATM Forum international consortium recently approved the first version of its security specifications aiming to protect communications over Asynchronous Transfer Mode (ATM) networks by offering data confidentiality, partner authentication, etc. The paper describes the architecture of one of the first ATM Forum compliant security prototypes being currently developed in the European project SCAN (Secure Communications in ATM Networks). Additionally to the security management functions specified by the ATM Forum to exchange encryption keys and negotiate security services, SCAN implements the possibility for end users to modify the data flow encryption algorithm during a connection in progress, and the possibility to keep the encryption algorithm choice confidential. Moreover, a flexible implementation is offered allowing future users to develop their own security protocols and their own ATM security monitoring applications. Maryline Laurent, Ahmed Bouabdallah, Christophe Delahaye, Herbert Leitold, Reinhard Posch, Enrique Areizaga, Juàn Manuel Mateos |
ACSAC | 2 |