Mohammad Hammoudeh

dblp:39/1032 · DBLP profile ↗
← Back
48ranked-venue papers
4as first author
31since 2021 · last 2026
0000-0003-1058-0996ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 2 first-author · 9 since 2021Systems, architecture and hardware · 9 · 3 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Security and privacy · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 SeCI: A Framework for Self-Certified Identity for Autonomous AI Agents
Nehal F. Al-Otaiby, Mohammad Hammoudeh, Jameleddine Hassine
CCGrid2
2026 Permutation-based lightweight mutual authentication and key agreement protocol: A post-quantum secure design with IoD applicability
Farid Binbeshr, Mostefa Kara, Sultan Almuhammadi, Muath AlShaikh, Abdulaziz Al-Helali, Mohammad Hammoudeh
Comput. Networks6
2026 Cyber-attacks: Securing ship navigation systems using multi-layer cross-validation defense
Danish Vasan, Mohammad Hammoudeh, Adel Fadhl Ahmed, Hamad Naeem
Comput. Secur.2
2026 Formal specification and executable analysis of digital twin systems using Maude rewriting logic
Turki Alhazmi, Farag Azzedin, Jameleddine Hassine, Mohammad Hammoudeh
Future Gener. Comput. Syst.4
2026 Behavioral trust management in Digital Twin systems using safe state analysis and virtual validation
Farag Azzedin, Turki Alhazmi, Jemal Abawajy, Mohammad Hammoudeh
Inf. Softw. Technol.4
2025 Navigating water scarcity in arid landscapes: a reinforcement learning environment for wheat irrigation management
Mohammed Nadhir Abid, Mounir Beggas, Abdelkader Laouid, Mohammad Hammoudeh
Expert Syst. Appl.4
2025 Time-series forecasting of Bitcoin prices using high-dimensional features: a machine learning approach
Mohammed Mudassir, Shada Bennbaia, Devrim Unal, Mohammad Hammoudeh
Neural Comput. Appl.4
2024 AI-powered malware detection with Differential Privacy for zero trust security in Internet of Things networks
abstract
The widespread usage of Android-powered devices in the Internet of Things (IoT) makes them susceptible to evolving cybersecurity threats. Most healthcare devices in IoT networks, such as smart watches, smart thermometers, biosensors, and more, are powered by the Android operating system, where preserving the privacy of user-sensitive data is of utmost importance. Detecting Android malware is thus vital for protecting sensitive information and ensuring the reliability of IoT networks. This article focuses on AI-enabled Android malware detection for improving zero trust security in IoT networks, which requires Android applications to be verified and authenticated before providing access to network resources. The zero trust security model requires strict identity verification for every entity trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter. Our proposed solution, DP-RFECV-FNN, an innovative approach to Android malware detection that employs Differential Privacy (DP) within a Feedforward Neural Network (FNN) designed for IoT networks under the zero trust model. By integrating DP, we ensure the confidentiality of data during the detection process, setting a new standard for privacy in cybersecurity solutions. By combining the strengths of DP and zero trust security with the powerful learning capacity of the FNN, DP-RFECV-FNN demonstrates the ability to identify both known and novel malware types and achieves higher accuracy while maintaining strict privacy controls compared with recent papers. DP-RFECV-FNN achieves an accuracy ranging from 97.78% to 99.21% while utilizing static features and 93.49% to 94.36% for dynamic features of Android applications to detect whether it is malware or benign. These results are achieved under varying privacy budgets, ranging from ϵ=0.1 to ϵ=1.0. Furthermore, our proposed feature selection pipeline enables us to outperform the state-of-the-art by significantly reducing the number of selected features and training time while improving accuracy. To the best of our knowledge, this is the first work to categorize Android malware based on both static and dynamic features through a privacy-preserving neural network model.
Faria Nawshin, Devrim Unal, Mohammad Hammoudeh, Ponnuthurai N. Suganthan
Ad Hoc Networks3
2024 Reviewing 25 years of continuous sign language recognition research: Advances, challenges, and prospects
Sarah N. Alyami, Hamzah Luqman, Mohammad Hammoudeh
Inf. Process. Manag.3
2024 An IoMT image crypto-system based on spatial watermarking and asymmetric encryption
Mohammed Elhabib Kahla, Mounir Beggas, Abdelkader Laouid, Muath AlShaikh, Mohammad Hammoudeh
Multim. Tools Appl.5
2024 Isolated Arabic Sign Language Recognition Using a Transformer-based Model and Landmark Keypoints
abstract
Pose-based approaches for sign language recognition provide light-weight and fast models that can be adopted in real-time applications. This article presents a framework for isolated Arabic sign language recognition using hand and face keypoints. We employed MediaPipe pose estimator for extracting the keypoints of sign gestures in the video stream. Using the extracted keypoints, three models were proposed for sign language recognition: Long-Term Short Memory, Temporal Convolution Networks, and Transformer-based models. Moreover, we investigated the importance of non-manual features for sign language recognition systems and the obtained results showed that combining hand and face keypoints boosted the recognition accuracy by around 4% compared with only hand keypoints. The proposed models were evaluated on Arabic and Argentinian sign languages. Using the KArSL-100 dataset, the proposed pose-based Transformer achieved the highest accuracy of 99.74% and 68.2% in signer-dependent and -independent modes, respectively. Additionally, the Transformer was evaluated on the LSA64 dataset and obtained an accuracy of 98.25% and 91.09% in signer-dependent and -independent modes, respectively. Consequently, the pose-based Transformer outperformed the state-of-the-art techniques on both datasets using keypoints from the signer’s hands and face.
Sarah N. Alyami, Hamzah Luqman, Mohammad Hammoudeh
ACM Trans. Asian Low Resour. Lang. Inf. Process.3
2023 A Review of the Progressive Odyssey of AI-Driven Intrusion Detection Within Embedded Systems
Aisha Alansari, Razan Alfaqeer, Mohammad Hammoudeh
CRiSIS3
2023 Pelican Gorilla Troop Optimization Based on Deep Feed Forward Neural Network for Human Activity Abnormality Detection in Smart Spaces
abstract
Healthcare management can be improved using artificial intelligence-powered Internet of Things (IoT) for remotely collecting and analyzing medical data. Home-based IoT healthcare proved its effectiveness in helping the elderly and people with special care needs enjoy safer and more independent living. Deep learning techniques improve the management of healthcare systems through intelligent analysis and real-time tracking of health indicators and auto-administering medication. This article proposes a novel pelican gorilla troop optimization-assisted deep feed-forward neural network for health indicators abnormality detection. As deep learning requires a significant data dimension to provide reliable results, the data augmentation process is carried out through the bootstrapping approach to improve abnormality detection. Furthermore,$Z$-score normalization is used to complete data preprocessing and achieve better detection outcomes. The experimental evaluation results show that the proposed solution realizes a detection performance in terms of accuracy, precision, and recall achieving of 0.879, 0.902, and 0.929, respectively.
Berdjouh Chafik, Meftah Mohammed Charaf Eddine, Abdelkader Laouid, Mohammad Hammoudeh, Akshi Kumar 0001
IEEE Internet Things J.4
2023 A Dominating Tree Based Leader Election Algorithm for Smart Cities IoT Infrastructure
Nabil Kadjouh, Ahcène Bounceur, Madani Bezoui, Mohamed Essaid Khanouche, Reinhardt Euler, Mohammad Hammoudeh, Loïc Lagadec, Sohail Jabbar, Fadi M. Al-Turjman
Mob. Networks Appl.6
2023 Secure and efficient image retrieval through invariant features selection in insecure cloud environments
Arup Kumar Pal, SK Hafizul Islam, Mohammad Hammoudeh
Neural Comput. Appl.4
2023 An Intelligent Approach Based on Cleaning up of Inutile Contents for Extremism Detection and Classification in Social Networks
abstract
Extremism is a growing threat worldwide that presents a significant danger to public safety and national security. Social networks provide extremists with spaces to spread their ideas through commentaries or tweets, often in Asian English. In this paper, we propose an intelligent approach that cleans the text’s content, analyzes its sentiment, and extracts its features after converting it to digital data for machine learning treatments. We apply 16 intelligent machine learning classifiers for extremism detection and classification. The proposed artificial intelligence methods for Asian English language data are used to extract the essential features from the text. Our evaluation of the proposed model with an extremism dataset proves its effectiveness compared to the standard classification models based on various performance metrics. The proposed model achieves 93,6% accuracy for extremism detection and 97,0% for extremism classification.
Adel Berhoum, Meftah Mohammed Charaf Eddine, Abdelkader Laouid, Mohammad Hammoudeh
ACM Trans. Asian Low Resour. Lang. Inf. Process.4
2023 Intelligent Anomaly Detection of Trajectories for IoT Empowered Maritime Transportation Systems
abstract
The convergence of Maritime Transportation Systems (MTS) and Internet of Things (IoT) has led to the promising IoT-empowered MTS (IoT-MTS). However, abnormal trajectories of maritime transportation ships can have highly negative impacts on the management of IoT-MTS. Therefore, anomaly detection of trajectories is important for the successful deployment of IoT-MTS. In this paper, we propose a Transfer Learning based Trajectory Anomaly Detection strategy, named TLTAD, for IoT-MTS. Specifically, a variational autoencoder is used to discover the potential connections between each dimension of the normal trajectory, while a graph variational autoencoder is used to explore the spatial similarity between normal trajectories. Based on internal connection of trajectories, a deep reinforcement learning algorithm, Twin Delayed Deep Deterministic policy gradient (TD3), is employed to train the trajectory anomaly detection model. To reduce the model training time, transfer learning is used to migrate the trained anomaly detection model between different regions of an ocean area or between similar ocean areas. Moreover, an efficient data transformation module is designed to improve the efficiency of model transfer. The experiments were conducted on a real-world automatic identification system (AIS) dataset. The results indicate that the proposed TLTAD can provide accurate anomaly detection on ships’ trajectories in IoT-MTS with reduced model training times.
Jia Hu 0001, Kuljeet Kaur, Hui Lin 0007, Xiaoding Wang 0001, Mohammad Mehedi Hassan, Muhammad Imran Razzak, Mohammad Hammoudeh
IEEE Trans. Intell. Transp. Syst.7
2022 Deep reinforcement learning based transmission policy enforcement and multi-hop routing in QoS aware LoRa IoT networks
Mohammed Saleh Ali Muthanna, Ammar Muthanna, Ahsan Rafiq, Mohammad Hammoudeh, Reem Alkanhel, Stephen Lynch, Ahmed A. Abd El-Latif 0001
Comput. Commun.4
2022 Editorial: The Inaugural Issue of ACM Distributed Ledger Technologies: Research and Practice
abstract
Distributed ledger technologies (DLT; broadly defined to include blockchain, cryptocurrency, and smart contracts) have many applications in diverse domains, e.g., critical infrastructure sectors such as financial services, information technology, transportation systems, and healthcare and public health.The speed and range of DLT developments can, however, be challenging for business leaders, policy-makers, decision-makers, and many other stakeholders, for example in legislation and regulation formulation.This reinforces the importance of having in place a venue where the research and practitioner communities, as well as government agencies, can get together, discuss, and present DLT and related advances, challenges, and opportunities; hence, motivating us to establish this journal as a venue to publish high-quality, interdisciplinary research on the research, real-world deployment, and/or evaluation of DLT in a wide range of sectors, from Fintech and NFT marketplaces to secure data sharing and supply chain and logistics monitoring.We started working on this journal's proposal in April 2020, and throughout the process we were supported by many individuals in different capacities.Without their support, this journal would not have been a reality.First and foremost, we would like to thank the ACM New Publications Committee and the ACM Publications Board for their support and approving the establishment of this journal.We would also like to thank the many individuals from ACM and the DLT research and practitioner communities, who selflessly provided us with invaluable advice during the process.Many of these individuals also accepted our invitations to be part of the journal's editorial board, 1 as listed below.
Kim-Kwang Raymond Choo, Mohammad Hammoudeh
Distributed Ledger Technol. Res. Pract.2
2022 A fully homomorphic encryption based on magic number fragmentation and El-Gamal encryption: Smart healthcare use case
abstract
Abstract Nowadays, cloud computing offers a digital infrastructure for smart city development. Cognitive cities are steadily automating daily urban processes. The ever expanding objective‐driven communities gather and share sensitive data that must be stored securely. Cloud computing offers a suitable platform that allows cognitive smart cities to access and re‐access data to learn from their past to adapt its current behaviour. However, the cloud is an untrusted entity that may expose data when decrypted for processing by systems. In this paper, we treat the issue of encrypted data processing. Often, the data is encrypted prior to transferring it to the cloud, where the cloud must have the data in clear to be able to make calculations which raises security and privacy threats if the cloud is considered untrusted. The scenario of asking users to make the calculations after decrypting the received cloud data and encrypting the obtained results before sending them back to the cloud is not a practical solution in distributed multi‐tenant architectures. Homomorphic encryption allows offers a solution for processing encrypted data. Many existing homomorphic encryption schemes suffer from limitations that hinder their usability. This paper presents an efficient fully homomorphic encryption scheme using twin key encryption and magic number fragmentation. The details of the scheme are presented along with cryptanalytic attacks to assess its effectiveness. The proposed scheme exhibits strong resilience against brute‐force attacks compared to its rivals from the literature. Finally, we illustrate the applicability of the proposed scheme using a cognitive smart city application.
Mostefa Kara, Abdelkader Laouid, Mohammed Amine Yagoub, Reinhardt Euler, Saci Medileh, Mohammad Hammoudeh, Amna Eleyan, Ahcène Bounceur
Expert Syst. J. Knowl. Eng.6
2022 VirtElect: A Peer-to-Peer Trading Platform for Local Energy Transactions
abstract
An average U.K. electricity bill is made up of at least 60% service charge, with approximately 22% related to network characteristics including distance charge. This makes distance and network constraints important factors in matching prosumers on any peer-to-peer energy trading platform as assessed in this article. To realize that, a platform—$VirtElect$, based on a double auction market is developed to support the matching interaction between prosumers. Case studies based on real microgrid data are used to verify the performance of the platform in demonstrating the potential of local energy consumption. The results show that it is possible to balance local energy generation and consumption, with little or no interaction with the utility grid. We also show that local energy trading is not only beneficial to the environment but also leads to a significant amount of cost savings of up to 45%, depending on the number of participants and their ratios on the platform.
Olamide Jogunola, Yakubu Tsado, Bamidele Adebisi, Mohammad Hammoudeh
IEEE Internet Things J.4
2022 Federated Deep Learning for Zero-Day Botnet Attack Detection in IoT-Edge Devices
abstract
Deep learning (DL) has been widely proposed for botnet attack detection in Internet of Things (IoT) networks. However, the traditional centralized DL (CDL) method cannot be used to detect the previously unknown (zero-day) botnet attack without breaching the data privacy rights of the users. In this article, we propose the federated DL (FDL) method for zero-day botnet attack detection to avoid data privacy leakage in IoT-edge devices. In this method, an optimal deep neural network (DNN) architecture is employed for network traffic classification. A model parameter server remotely coordinates the independent training of the DNN models in multiple IoT-edge devices, while the federated averaging (FedAvg) algorithm is used to aggregate local model updates. A global DNN model is produced after a number of communication rounds between the model parameter server and the IoT-edge devices. The zero-day botnet attack scenarios in IoT-edge devices is simulated with the Bot-IoT and N-BaIoT data sets. Experiment results show that the FDL model: 1) detects zero-day botnet attacks with high classification performance; 2) guarantees data privacy and security; 3) has low communication overhead; 4) requires low-memory space for the storage of training data; and 5) has low network latency. Therefore, the FDL method outperformed CDL, localized DL, and distributed DL methods in this application scenario.
Segun I. Popoola, Ruth Ande, Bamidele Adebisi, Guan Gui 0001, Mohammad Hammoudeh, Olamide Jogunola
IEEE Internet Things J.5
2022 IIoT Deep Malware Threat Hunting: From Adversarial Example Detection to Adversarial Scenario Detection
abstract
Protecting widely used deep classifiers against black-box adversarial attacks is a recent research challenge in many security-related areas, including malware classification. This class of attacks relies on optimizing a sequence of highly similar queries to bypass given classifiers. In this article, we leverage this property and propose a history-based method named,stateful query analysis (SQA), which analyzes sequences of queries received by a malware classifier to detect black-box adversarial attacks on an industrial Internet of Things (IIoT). In the SQA pipeline, there are two components, namely the similarity encoder and the classifier, both based on convolutional neural networks. Unlike the state-of-the-art methods, which aim to identify individual adversarial examples, tracking the history of queries allows our method to identify adversarial scenarios and abort attacks before their completion. We optimize SQA using different combinations of hyperparameters on an advanced risc machine (ARM)-based IIoT malware dataset, widely adopted for malware threat hunting in industry 4.0. The use of a novel distance metric in calculating the loss function of the similarity encoder results in more disentangled representations and improves the performance of our method. Our evaluations demonstrate the validity of SQA via a detection rate of 93.1% over a wide range of adversarial examples.
Bardia Esmaeili, Amin Azmoodeh, Ali Dehghantanha, Hadis Karimipour, Behrouz Zolfaghari, Mohammad Hammoudeh
IEEE Trans. Ind. Informatics6
2022 Proof of Chance: A Lightweight Consensus Algorithm for the Internet of Things
abstract
This article is to propose a consensus algorithm, called Proof of Chance (PoCh), which is designed for the industrial Internet of Things (IIoT). The PoCh protocol is designed to be scalable and extensible, with a controllable conformance delay and low hardware and computation requirements. To reach a consensus, PoCh uses chance rather than computing power: “if condition$_{1}$, I am a candidate; if condition$_{2}$, I am the miner.” During every consensus iteration, the condition$_{1}$is updated, and a single miner is chosen using condition$_{2}$. Those conditions are randomized without the node generating any value and without assigning any weight to such value. The fault tolerance of PoCh is$5f/3 + 1$, meaning that PoCh can successfully achieve consensus as long as more than 40% of nodes are functioning properly, compared to 50% in the Proof of Stake (PoS) protocol.
Mostefa Kara, Abdelkader Laouid, Mohammad Hammoudeh, Muath AlShaikh, Ahcène Bounceur
IEEE Trans. Ind. Informatics3
2022 Block Hunter: Federated Learning for Cyber Threat Hunting in Blockchain-Based IIoT Networks
abstract
Nowadays, blockchain-based technologies are being developed in various industries to improve data security. In the context of the Industrial Internet of Things (IIoT), a chain-based network is one of the most notable applications of blockchain technology. IIoT devices have become increasingly prevalent in our digital world, especially in support of developing smart factories. Although blockchain is a powerful tool, it is vulnerable to cyberattacks. Detecting anomalies in blockchain-based IIoT networks in smart factories is crucial in protecting networks and systems from unexpected attacks. In this article, we use federated learning to build a threat hunting framework called block hunter to automatically hunt for attacks in blockchain-based IIoT networks. Block hunter utilizes a cluster-based architecture for anomaly detection combined with several machine learning models in a federated environment. To the best of our knowledge, block hunter is the first federated threat hunting model in IIoT networks that identifies anomalous behavior while preserving privacy. Our results prove the efficiency of the block hunter in detecting anomalous activities with high accuracy and minimum required bandwidth.
Abbas Yazdinejad, Ali Dehghantanha, Reza M. Parizi, Mohammad Hammoudeh, Hadis Karimipour, Gautam Srivastava 0001
IEEE Trans. Ind. Informatics4
2021 Federated Deep Learning for Collaborative Intrusion Detection in Heterogeneous Networks
abstract
In this paper, we propose Federated Deep Learning (FDL) for intrusion detection in heterogeneous networks. Local Deep Neural Network (DNN) models are used to learn the hierarchical representations of the private network traffic data in multiple edge nodes. A dedicated central server receives the parameters of the local DNN models from the edge nodes, and it aggregates them to produce an FDL model using the Fed+ fusion algorithm. Simulation results show that the FDL model achieved an accuracy of 99.27 ± 0.79%, a precision of 97.03 ± 4.22%, a recall of 98.06 ± 1.72%, an F1 score of 97.50 ± 2.55%, and a False Positive Rate (FPR) of 2.40 ± 2.47%. The classification performance and the generalisation ability of the FDL model are better than those of the local DNN models. The Fed+ algorithm outperformed two state-of-the-art fusion algorithms, namely federated averaging (FedAvg) and Coordinate Median (CM). Therefore, the DNN-Fed+ model is preferable for intrusion detection in heterogeneous wireless networks.
Segun I. Popoola, Guan Gui 0001, Bamidele Adebisi, Mohammad Hammoudeh, Haris Gacanin
VTC Fall4
2021 Integration of federated machine learning and blockchain for the provision of secure big data analytics for Internet of Things
Devrim Unal, Mohammad Hammoudeh, Muhammad Asif Khan 0001, Abdelrahman Abuarqoub, Gregory Epiphaniou, Ridha Hamila
Comput. Secur.2
2021 A secure and efficient Internet of Things cloud encryption scheme with forensics investigation compatibility based on identity-based encryption
Devrim Unal, Abdulla K. Al-Ali, Ferhat Özgür Çatak, Mohammad Hammoudeh
Future Gener. Comput. Syst.4
2021 Hybrid Deep Learning for Botnet Attack Detection in the Internet-of-Things Networks
abstract
Deep learning (DL) is an efficient method for botnet attack detection. However, the volume of network traffic data and memory space required is usually large. It is, therefore, almost impossible to implement the DL method in memory-constrained Internet-of-Things (IoT) devices. In this article, we reduce the feature dimensionality of large-scale IoT network traffic data using the encoding phase of long short-term memory autoencoder (LAE). In order to classify network traffic samples correctly, we analyze the long-term inter-related changes in the low-dimensional feature set produced by LAE using deep bidirectional long short-term memory (BLSTM). Extensive experiments are performed with the BoT-IoT data set to validate the effectiveness of the proposed hybrid DL method. Results show that LAE significantly reduced the memory space required for large-scale network traffic data storage by 91.89%, and it outperformed state-of-the-art feature dimensionality reduction methods by 18.92-27.03%. Despite the significant reduction in feature size, the deep BLSTM model demonstrates robustness against model underfitting and overfitting. It also achieves good generalisation ability in binary and multiclass classification scenarios.
Segun I. Popoola, Bamidele Adebisi, Mohammad Hammoudeh, Guan Gui 0001, Haris Gacanin
IEEE Internet Things J.3
2021 Blockchain-enabled supply chain: analysis, challenges, and future directions
abstract
Abstract Managing the integrity of products and processes in a multi-stakeholder supply chain environment is a significant challenge. Many current solutions suffer from data fragmentation, lack of reliable provenance, and diverse protocol regulations across multiple distributions and processes. Amongst other solutions, Blockchain has emerged as a leading technology, since it provides secure traceability and control, immutability, and trust creation among stakeholders in a low cost IT solution. Although Blockchain is making a significant impact in many areas, there are many impediments to its widespread adoption in supply chains. This article is the first survey of its kind, with detailed analysis of the challenges and future directions in Blockchain-enabled supply chains. We review the existing digitalization of the supply chain including the role of GS1 standards and technologies. Current use cases and startups in the field of Blockchain-enabled supply chains are reviewed and presented in tabulated form. Technical and non-technical challenges in the adoption of Blockchain for supply chain applications are critically analyzed, along with the suitability of various consensus algorithms for applications in the supply chain. The tools and technologies in the Blockchain ecosystem are depicted and analyzed. Some key areas as future research directions are also identified which must be addressed to realize mass adoption of Blockchain-based in supply chain traceability. Finally, we propose MOHBSChain, a novel framework for Blockchain-enabled supply chains.
Sohail Jabbar, Huw Lloyd, Mohammad Hammoudeh, Bamidele Adebisi, Umar Raza
Multim. Syst.3
2021 A Flow-based Multi-agent Data Exfiltration Detection Architecture for Ultra-low Latency Networks
abstract
Modern network infrastructures host converged applications that demand rapid elasticity of services, increased security, and ultra-fast reaction times. The Tactile Internet promises to facilitate the delivery of these services while enabling new economies of scale for high fidelity of machine-to-machine and human-to-machine interactions. Unavoidably, critical mission systems served by the Tactile Internet manifest high demands not only for high speed and reliable communications but equally, the ability to rapidly identify and mitigate threats and vulnerabilities. This article proposes a novel Multi-Agent Data Exfiltration Detector Architecture (MADEX), inspired by the mechanisms and features present in the human immune system. MADEX seeks to identify data exfiltration activities performed by evasive and stealthy malware that hides malicious traffic from an infected host in low-latency networks. Our approach uses cross-network traffic information collected by agents to effectively identify unknown illicit connections by an operating system subverted. MADEX does not require prior knowledge of the characteristics or behavior of the malicious code or a dedicated access to a knowledge repository. We tested the performance of MADEX in terms of its capacity to handle real-time data and the sensitivity of our algorithm’s classification when exposed to malicious traffic. Experimental evaluation results show that MADEX achieved 99.97% sensitivity, 98.78% accuracy, and an error rate of 1.21% when compared to its best rivals. We created a second version of MADEX, called MADEX level 2, that further improves its overall performance with a slight increase in computational complexity. We argue for the suitability of MADEX level 1 in non-critical environments, while MADEX level 2 can be used to avoid data exfiltration in critical mission systems. To the best of our knowledge, this is the first article in the literature that addresses the detection of rootkits real-time in an agnostic way using an artificial immune system approach while it satisfies strict latency requirements.
Rafael Salema Marques, Gregory Epiphaniou, Haider M. Al-Khateeb, Carsten Maple, Mohammad Hammoudeh, Paulo André Lima de Castro, Ali Dehghantanha, Kim-Kwang Raymond Choo
ACM Trans. Internet Techn.5
2020 A flexible encryption technique for the internet of things environment
Saci Medileh, Abdelkader Laouid, El Moatez Billah Nagoudi, Reinhardt Euler, Ahcène Bounceur, Mohammad Hammoudeh, Muath AlShaikh, Amna Eleyan, Osama Ahmed Khashan
Ad Hoc Networks6
2020 PROUD: Verifiable Privacy-preserving Outsourced Attribute Based SignCryption supporting access policy Update for cloud assisted IoT applications
Sana Belguith, Nesrine Kaaniche, Mohammad Hammoudeh, Tooska Dargahi
Future Gener. Comput. Syst.3
2020 Millimeter-Wave Communication for Internet of Vehicles: Status, Challenges, and Perspectives
abstract
The Internet of Vehicles has attracted a lot of attention in the automotive industry and academia recently. We are witnessing rapid advances in vehicular technologies that comprise many components, such as onboard units (OBUs) and sensors. These sensors generate a large amount of data, which can be used to inform and facilitate decision making (e.g., navigating through traffic and obstacles). One particular focus is for automotive manufacturers to enhance the communication capability of vehicles to extend their sensing range. However, the existing short-range wireless access, such as dedicated short-range communication (DSRC), and cellular communication, such as 4G, is not capable of supporting the high volume data generated by different fully connected vehicular settings. Millimeter-wave (mmWave) technology can potentially provide terabit data transfer rates among vehicles. Therefore, we present an in-depth survey of the existing research, published in the last decade, and we describe the applications of mmWave communications in vehicular communications. In particular, we focus on MAC and physical layers and discuss related issues, such as sensing-aware MAC protocol, handover algorithms, link blockage, and beamwidth size adaptation. Finally, we highlight various aspects related to smart transportation applications, and we discuss future research directions and limitations.
Kayhan Zrar Ghafoor, Linghe Kong, Sherali Zeadally, Ali Safa Sadiq, Gregory Epiphaniou, Mohammad Hammoudeh, Ali Kashif Bashir, Shahid Mumtaz
IEEE Internet Things J.6
2020 Enhancing and simplifying data security and privacy for multitiered applications
Walid Rjaibi, Mohammad Hammoudeh
J. Parallel Distributed Comput.2
2020 A secure fog-based platform for SCADA-based IoT critical infrastructure
abstract
Summary The rapid proliferation of Internet of things (IoT) devices, such as smart meters and water valves, into industrial critical infrastructures and control systems has put stringent performance and scalability requirements on modern Supervisory Control and Data Acquisition (SCADA) systems. While cloud computing has enabled modern SCADA systems to cope with the increasing amount of data generated by sensors, actuators, and control devices, there has been a growing interest recently to deploy edge data centers in fog architectures to secure low‐latency and enhanced security for mission‐critical data. However, fog security and privacy for SCADA‐based IoT critical infrastructures remains an under‐researched area. To address this challenge, this contribution proposes a novel security “toolbox” to reinforce the integrity, security, and privacy of SCADA‐based IoT critical infrastructure at the fog layer. The toolbox incorporates a key feature: a cryptographic‐based access approach to the cloud services using identity‐based cryptography and signature schemes at the fog layer. We present the implementation details of a prototype for our proposed secure fog‐based platform and provide performance evaluation results to demonstrate the appropriateness of the proposed platform in a real‐world scenario. These results can pave the way toward the development of a more secure and trusted SCADA‐based IoT critical infrastructure, which is essential to counter cyber threats against next‐generation critical infrastructure and industrial control systems. The results from the experiments demonstrate a superior performance of the secure fog‐based platform, which is around 2.8 seconds when adding five virtual machines (VMs), 3.2 seconds when adding 10 VMs, and 112 seconds when adding 1000 VMs, compared to the multilevel user access control platform.
Thar Baker, Muhammad Asim 0001, Áine MacDermott, Farkhund Iqbal, Faouzi Kamoun, Babar Shah, Omar Alfandi, Mohammad Hammoudeh
Softw. Pract. Exp.8
2020 Threats on the horizon: understanding security threats in the era of cyber-physical systems
abstract
Abstract Disruptive innovations of the last few decades, such as smart cities and Industry 4.0, were made possible by higher integration of physical and digital elements. In today’s pervasive cyber-physical systems, connecting more devices introduces new vulnerabilities and security threats. With increasing cybersecurity incidents, cybersecurity professionals are becoming incapable of addressing what has become the greatest threat climate than ever before. This research investigates the spectrum of risk of a cybersecurity incident taking place in the cyber-physical-enabled world using the VERIS Community Database. The findings were that the majority of known actors were from the US and Russia, most victims were from western states and geographic origin tended to reflect global affairs. The most commonly targeted asset was information, with the majority of attack modes relying on privilege abuse. The key feature observed was extensive internal security breaches, most often a result of human error. This tends to show that access in any form appears to be the source of vulnerability rather than incident specifics due to a fundamental trade-off between usability and security in the design of computer systems. This provides fundamental evidence of the need for a major reevaluation of the founding principles in cybersecurity.
Steven Walker-Roberts, Mohammad Hammoudeh, Omar Aldabbas 0001, Mehmet Emin Aydin, Ali Dehghantanha
J. Supercomput.2
2019 Non-interactive zero knowledge proofs for the authentication of IoT devices in reduced connectivity environments
Marcus Walshe, Gregory Epiphaniou, Haider M. Al-Khateeb, Mohammad Hammoudeh, Vasilios Katos, Ali Dehghantanha
Ad Hoc Networks4
2019 Low-Power Wide Area Network Technologies for Internet-of-Things: A Comparative Review
abstract
The rapid growth of Internet-of-Things (IoT) in the current decade has led to the development of a multitude of new access technologies targeted at low-power, wide area networks (LP-WANs). However, this has also created another challenge pertaining to technology selection. This paper reviews the performance of LP-WAN technologies for IoT, including design choices and their implications. We consider Sigfox, LoRaWAN, WavIoT, random phase multiple access (RPMA), narrowband IoT (NB-IoT), as well as LTE-M and assess their performance in terms of signal propagation, coverage and energy conservation. The comparative analyses presented in this paper are based on available data sheets and simulation results. A sensitivity analysis is also conducted to evaluate network performance in response to variations in system design parameters. Results show that each of RPMA, NB-IoT, and LTE-M incurs at least 9 dB additional path loss relative to Sigfox and LoRaWAN. This paper further reveals that with a 10% improvement in receiver sensitivity, NB-IoT 882 MHz and LoRaWAN can increase coverage by up to 398% and 142%, respectively, without adverse effects on the energy requirements. Finally, extreme weather conditions can significantly reduce the active network life of LP-WANs. In particular, the results indicate that operating an IoT device in a temperature of -20 °C can shorten its life by about half; 53% (WavIoT, LoRaWAN, Sigfox, NB-IoT, and RPMA) and 48% in LTE-M compared with environmental temperature of 40 °C.
Augustine Ikpehai, Bamidele Adebisi, Khaled M. Rabie, Kelvin O. O. Anoh, Ruth Ande, Mohammad Hammoudeh, Haris Gacanin, Uche M. Mbanaso
IEEE Internet Things J.6
2018 IoT-based students interaction framework using attention-scoring assessment in eLearning
Sohail Jabbar, Muhammad Aslam 0001, Mohammad Hammoudeh, Mudassar Ahmad 0001, Shehzad Khalid, Murad Khan, Ki Jun Han
Future Gener. Comput. Syst.4
2018 Detection of advanced persistent threat using machine-learning correlation analysis
Ibrahim Ghafir, Mohammad Hammoudeh, Vaclav Prenosil, Liangxiu Han, Robert Hegarty, Khaled M. Rabie, Francisco J. Aparicio-Navarro
Future Gener. Comput. Syst.2
2018 Surveillance of sensitive fenced areas using duty-cycled wireless sensor networks with asymmetrical links
Ali Benzerbadj, Kechar Bouabdellah, Ahcène Bounceur, Mohammad Hammoudeh
J. Netw. Comput. Appl.4
2018 Security threats to critical infrastructure: the human factor
abstract
In the twenty-first century, globalisation made corporate boundaries invisible and difficult to manage. This new macroeconomic transformation caused by globalisation introduced new challenges for critical infrastructure management. By replacing manual tasks with automated decision making and sophisticated technology, no doubt we feel much more secure than half a century ago. As the technological advancement takes root, so does the maturity of security threats. It is common that today’s critical infrastructures are operated by non-computer experts, e.g. nurses in health care, soldiers in military or firefighters in emergency services. In such challenging applications, protecting against insider attacks is often neither feasible nor economically possible, but these threats can be managed using suitable risk management strategies. Security technologies, e.g. firewalls, help protect data assets and computer systems against unauthorised entry. However, one area which is often largely ignored is the human factor of system security. Through social engineering techniques, malicious attackers are able to breach organisational security via people interactions. This paper presents a security awareness training framework, which can be used to train operators of critical infrastructure, on various social engineering security threats such as spear phishing, baiting, pretexting, among others.
Ibrahim Ghafir, Jibran Saleem, Mohammad Hammoudeh, Hanan Faour, Vaclav Prenosil, Sardar F. Jaf, Sohail Jabbar, Thar Baker
J. Supercomput.3
2017 Dynamic clustering and management of mobile wireless sensor networks
Abdelrahman Abuarqoub, Mohammad Hammoudeh, Bamidele Adebisi, Sohail Jabbar, Ahcène Bounceur, Hashem Al-Bashar
Comput. Networks2
2013 Interpolation techniques for building a continuous map from discrete wireless sensor network data
abstract
ABSTRACT Wireless sensor networks (WSNs) typically gather data at a discrete number of locations. However, it is desirable to be able to design applications and reason about the data in more abstract forms than in points of data. By bestowing the ability to predict inter‐node values upon the network, it is proposed that it will become possible to build applications that are unaware of the concrete reality of sparse data. This interpolation capability is realised as a service of the network. In this paper, the ‘map’ style of presentation has been identified as a suitable sense data visualisation format. Although map generation is essentially a problem of interpolation between points, a new WSN service, called the map generation service, which is based on a Shepard interpolation method, is presented. A modified Shepard method that aims to deal with the special characteristics of WSNs is proposed. It requires small storage, can be localised and integrates the information about the application domain to further reduce the map generation cost and improve the mapping accuracy. Empirical analysis has shown that the map generation service is an accurate, a flexible and an efficient method. Copyright © 2011 John Wiley & Sons, Ltd.
Mohammad Hammoudeh, Robert M. Newman, Christopher Dennett, Sarah Mount
Wirel. Commun. Mob. Comput.1
2009 Inductive as a support of deductive data visualisation in Wireless Sensor Networks
abstract
Wireless sensor networks (WSN) have been useful in a variety of domains. These types of networks have an intimate interaction, via sensors, with the physical environment they operate within. The part of the world with which an application is concerned is defined as that application's domain. This paper advocates that the application domain can serve as a supplement to sense data analysis, interpretation, and visualisation methods and tools. To achieve this, we propose a multi-dimensional application domain-driven (M-DAD) information extraction and visualisation framework that uses the application domain to accurately visualise multimodal sense data. M-DAD harnesses the inherent redundancies and relationships among the collected sense data as information about a specific event of interest in a WSN is usually captured in multiple sensed modalities. The proposed mapping framework utilises these correlations, defined in the application domain, to visualise a sense modality, e.g. soil nitrate levels, using other related but independent sense modalities, e.g. temperature and pH, which results in higher accuracy visualisations than visualising from a single sense modality. The primary experimental results demonstrate that the proposed framework performs as well or better than methods without its extended capabilities.
Mohammad Hammoudeh, Robert M. Newman, Christopher Dennett, Sarah Mount
ISCC1
2009 Application Domain Driven Data Visualisation Framework for Wireless Sensor Networks
Mohammad Hammoudeh, Robert M. Newman, Christopher Dennett, Sarah Mount
UIC1
2008 Modelling Clustering of Sensor Networks with Synchronised Hyperedge Replacement
Mohammad Hammoudeh
ICGT1